This repository has been archived by the owner on Aug 10, 2021. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathindex.htm
375 lines (259 loc) · 17.4 KB
/
index.htm
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
<html>
<head>
<meta http-equiv=Content-Type content="text/html; charset=gb2312">
<meta name=Generator content="Microsoft Word 12 (filtered)">
<style>
<!--
/* Font Definitions */
@font-face
{font-family:宋体;
panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
{font-family:"Cambria Math";
panose-1:0 0 0 0 0 0 0 0 0 0;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:"\@宋体";
panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0cm;
margin-bottom:.0001pt;
text-align:justify;
text-justify:inter-ideograph;
font-size:10.5pt;
font-family:"Calibri","sans-serif";}
p.MsoHeader, li.MsoHeader, div.MsoHeader
{mso-style-link:"页眉 Char";
margin:0cm;
margin-bottom:.0001pt;
text-align:center;
layout-grid-mode:char;
border:none;
padding:0cm;
font-size:9.0pt;
font-family:"Calibri","sans-serif";}
p.MsoFooter, li.MsoFooter, div.MsoFooter
{mso-style-link:"页脚 Char";
margin:0cm;
margin-bottom:.0001pt;
layout-grid-mode:char;
font-size:9.0pt;
font-family:"Calibri","sans-serif";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
{mso-style-link:"批注框文本 Char";
margin:0cm;
margin-bottom:.0001pt;
text-align:justify;
text-justify:inter-ideograph;
font-size:9.0pt;
font-family:"Calibri","sans-serif";}
span.Char
{mso-style-name:"页眉 Char";
mso-style-link:页眉;}
span.Char0
{mso-style-name:"页脚 Char";
mso-style-link:页脚;}
span.Char1
{mso-style-name:"批注框文本 Char";
mso-style-link:批注框文本;}
/* Page Definitions */
@page Section1
{size:595.3pt 841.9pt;
margin:72.0pt 90.0pt 72.0pt 90.0pt;
layout-grid:15.6pt;}
div.Section1
{page:Section1;}
-->
</style>
</head>
<body lang=ZH-CN style='text-justify-trim:punctuation'>
<div class=Section1 style='layout-grid:15.6pt'>
<p class=MsoNormal><span lang=EN-US>StingArp 4.0 </span><span style='font-family:
"宋体","sans-serif"'>对于</span><span lang=EN-US> 3.0 </span><span
style='font-family:"宋体","sans-serif"'>版本的改进。</span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>编译环境使用</span><span
lang=EN-US>VC8.0</span><span style='font-family:"宋体","sans-serif"'>,非</span><span
lang=EN-US>.Net</span><span style='font-family:"宋体","sans-serif"'>。无需安装</span><span
lang=EN-US>.Net Framework</span><span style='font-family:"宋体","sans-serif"'>框架。</span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>增加了</span><span
lang=EN-US>B/S</span><span style='font-family:"宋体","sans-serif"'>消息的通知模式,通知到一台计算机(服务端)上。</span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span lang=EN-US>StringArp</span><span style='font-family:
"宋体","sans-serif"'>主要功能:</span></p>
<p class=MsoNormal><span lang=EN-US> </span><span style='font-family:
"宋体","sans-serif"'>提供一个程序保护一个网段,工作在任何</span><span lang=EN-US>802.1x IPv4 </span><span
style='font-family:"宋体","sans-serif"'>网络上。适用于家庭及企业网络。</span></p>
<p class=MsoNormal><span lang=EN-US> </span><span style='font-family:
"宋体","sans-serif"'>独特的不发送任何数据监测功能及算法有效的发现可疑计算机并且不消耗任何网络带宽。</span></p>
<p class=MsoNormal><span lang=EN-US> </span><span style='font-family:
"宋体","sans-serif"'>无需改变当前的网络结构,利用</span><span lang=EN-US>TCP/IP</span><span
style='font-family:"宋体","sans-serif"'>协议进行监控和控制。只需要在局域网中任何一台电脑运行即可。网络更改成本为</span><span
lang=EN-US>0</span><span style='font-family:"宋体","sans-serif"'>。</span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>编译环境</span></p>
<p class=MsoNormal><span lang=EN-US><img width=552 height=346 id="图片 1"
src="StringARP4.files/image001.jpg"></span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>程序界面</span></p>
<p class=MsoNormal><span lang=EN-US><img width=489 height=225 id="图片 2"
src="StringARP4.files/image002.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>程序菜单</span></p>
<p class=MsoNormal><span lang=EN-US><img width=205 height=156 id="图片 3"
src="StringARP4.files/image003.jpg"></span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>选择要保护的局域网的网卡</span></p>
<p class=MsoNormal><span lang=EN-US><img width=460 height=99 id="图片 4"
src="StringARP4.files/image004.jpg"></span></p>
<p class=MsoNormal><span lang=EN-US>B/S</span><span style='font-family:"宋体","sans-serif"'>结构的消息通知的服务端,开启后会显示有客户端的登陆的计算机</span></p>
<p class=MsoNormal><span lang=EN-US><img width=441 height=276 id="图片 5"
src="StringARP4.files/image005.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>客户端配置参数</span></p>
<p class=MsoNormal><span lang=EN-US><img width=411 height=208 id="图片 6"
src="StringARP4.files/image006.jpg"><img width=268 height=191 id="图片 7"
src="StringARP4.files/image007.jpg"></span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span lang=EN-US><img width=553 height=134 id="图片 8"
src="StringARP4.files/image008.jpg"><img width=554 height=392 id="图片 9"
src="StringARP4.files/image009.jpg"></span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>可以随系统启动。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=127 height=117 id="图片 10"
src="StringARP4.files/image010.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>选择安装后</span></p>
<p class=MsoNormal><span lang=EN-US><img width=216 height=128 id="图片 11"
src="StringARP4.files/image011.jpg"></span></p>
<p class=MsoNormal><span lang=EN-US>Windows</span><span style='font-family:
"宋体","sans-serif"'>服务管理器中出现服务。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=407 height=431 id="图片 12"
src="StringARP4.files/image012.jpg"></span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>不再需要时可以卸载服务。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=229 height=132 id="图片 13"
src="StringARP4.files/image013.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>服务端的</span><span
lang=EN-US> Windows</span><span style='font-family:"宋体","sans-serif"'>中</span> <span
style='font-family:"宋体","sans-serif"'>管理工具</span><span lang=EN-US> </span><span
style='font-family:"宋体","sans-serif"'>中</span> <span style='font-family:"宋体","sans-serif"'>事件查看器会纪录所有信息。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=453 height=297 id="图片 14"
src="StringARP4.files/image014.jpg"></span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>比如刚开启接收消息的服务端</span></p>
<p class=MsoNormal><span lang=EN-US><img width=553 height=457 id="图片 15"
src="StringARP4.files/image015.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>回到客户端,选择菜单中的高级,显示附加功能。这里面所有的功能都是双刃剑</span></p>
<p class=MsoNormal><span lang=EN-US><img width=553 height=131 id="图片 16"
src="StringARP4.files/image016.jpg"></span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>出现所有功能的界面。这里面的攻击功能和断开计算机目标网络功能非常强大。</span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>不会被所有</span><span
lang=EN-US>ARP</span><span style='font-family:"宋体","sans-serif"'>防火墙拦截。现有的</span><span
lang=EN-US>ARP</span><span style='font-family:"宋体","sans-serif"'>防火墙对其无能为力。</span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>这是其一大特点,并且不会被任何人发现。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=554 height=393 id="图片 17"
src="StringARP4.files/image017.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>任务栏中会显示当前状态,第一个图标是客户端的。表示工作中。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=284 height=41 id="图片 18"
src="StringARP4.files/image018.jpg"></span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>假设选择网卡前选择了“记录数据”,那么,关闭程序后,所有</span><span
lang=EN-US>ARP</span><span style='font-family:"宋体","sans-serif"'>报文会呈现</span><span
lang=EN-US>TXT</span><span style='font-family:"宋体","sans-serif"'>格式并打开,展现在屏幕上。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=554 height=313 id="图片 19"
src="StringARP4.files/image019.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>现在开始防护测试。假设不使用自动防护,仅报告。(注意,发现可疑计算机的过程,程序是不发送任何数据的,一个包都不发送。利用算法实现。不会对网络造成任何影响)</span></p>
<p class=MsoNormal><span lang=EN-US><img width=288 height=47 id="图片 20"
src="StringARP4.files/image020.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>打开“聚生网管”程序。客户端的可疑信息中立即显示出可疑的计算机。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=476 height=113 id="图片 21"
src="StringARP4.files/image021.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>多种信息格式表示。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=553 height=91 id="图片 22"
src="StringARP4.files/image022.jpg"></span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>聚生网管的界面。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=554 height=170 id="图片 23"
src="StringARP4.files/image023.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>现在,去掉禁用的自动防护。开始用一个程序保护整个局域网。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=264 height=79 id="图片 24"
src="StringARP4.files/image024.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>聚生网管中电脑立即被干扰。(保护过程可以防护任何</span><span
lang=EN-US>ARP</span><span style='font-family:"宋体","sans-serif"'>扫描以及</span><span
lang=EN-US>ARP</span><span style='font-family:"宋体","sans-serif"'>病毒!会自动隔离病毒源电脑,不对其他网络中电脑造成影响</span>
<span style='font-family:"宋体","sans-serif"'>。注意,是任何</span><span lang=EN-US>ARP</span><span
style='font-family:"宋体","sans-serif"'>病毒)。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=554 height=427 id="图片 25"
src="StringARP4.files/image025.jpg"></span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>客户端程序动态闪烁,提示有信息。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=36 height=42 id="图片 26"
src="StringARP4.files/image026.jpg"><img width=35 height=36 id="图片 27"
src="StringARP4.files/image027.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>来到服务端,可以看到事件查看器中有消息记录。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=553 height=576 id="图片 29"
src="StringARP4.files/image028.jpg"></span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>详细的</span><span
lang=EN-US>Windows</span><span style='font-family:"宋体","sans-serif"'>事件记录。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=391 height=327 id="图片 30"
src="StringARP4.files/image029.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>现在尝试控制主机。即开始欺骗。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=525 height=63 id="图片 31"
src="StringARP4.files/image030.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>如果使用攻击软件检测,无法发现。完全被扰乱。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=481 height=258 id="图片 33"
src="StringARP4.files/image031.jpg"></span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>当前界面。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=484 height=222 id="图片 34"
src="StringARP4.files/image032.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>服务端会自动接收客户端的消息,并报告可疑信息。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=297 height=266 id="图片 36"
src="StringARP4.files/image033.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>扫描一次全网段,就被记录一次。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=553 height=284 id="图片 37"
src="StringARP4.files/image034.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>刚才开启聚生网管监控模拟</span><span
lang=EN-US>ARP</span><span style='font-family:"宋体","sans-serif"'>病毒欺骗。客户端就显示出数据。(扩展界面里)</span></p>
<p class=MsoNormal><span lang=EN-US><img width=244 height=146 id="图片 39"
src="StringARP4.files/image035.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>服务端程序开始报警。显示被欺骗的信息。并且可以自动获得欺骗方的真实</span><span
lang=EN-US>IP</span><span style='font-family:"宋体","sans-serif"'>。(任何</span><span
lang=EN-US>ARP</span><span style='font-family:"宋体","sans-serif"'>病毒)</span></p>
<p class=MsoNormal><span lang=EN-US><img width=311 height=236 id="图片 40"
src="StringARP4.files/image036.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>事件日至里以错误的类型消息报告欺骗活动。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=392 height=332 id="图片 41"
src="StringARP4.files/image037.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>服务端发现欺骗或者病毒后冲突后,会自动记录到</span><span
lang=EN-US>windows</span><span style='font-family:"宋体","sans-serif"'>事件日志中。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=553 height=275 id="图片 42"
src="StringARP4.files/image038.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>高级功能中可以对特定的计算机进行隔离或者恶意操作者攻击操作。</span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>隔离功能可以使其与局域网通信中端。无论其安装了多少防火墙或者安全措施。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=476 height=181 id="图片 43"
src="StringARP4.files/image039.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>要操作的目标计算机。详细操作步骤请参见</span><span
lang=EN-US>3.0</span><span style='font-family:"宋体","sans-serif"'>的说明文档。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=274 height=125 id="图片 44"
src="StringARP4.files/image040.jpg"></span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span lang=EN-US> </span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>自动防护功能使</span><span
lang=EN-US>ARP</span><span style='font-family:"宋体","sans-serif"'>类型的恶意程序无法定位局域网计算机,最后导致恶意计算机程序崩溃。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=554 height=428 id="图片 45"
src="StringARP4.files/image041.jpg"></span></p>
<p class=MsoNormal><span style='font-family:"宋体","sans-serif"'>刷新后显示客户端状态。如果客户机电源或者系统崩溃,可以第一时间发现。</span></p>
<p class=MsoNormal><span lang=EN-US><img width=436 height=276 id="图片 46"
src="StringARP4.files/image042.jpg"></span></p>
</div>
</body>
</html>