• Stars
    star
    108
  • Rank 314,161 (Top 7 %)
  • Language
    C
  • License
    MIT License
  • Created over 4 years ago
  • Updated about 4 years ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

Huorong Internet Security vulnerabilities 火绒安全软件漏洞

火绒安全软件漏洞

描述

火绒安全软件的名声一直挺不错的(至少我看来),并且以查杀准确、快速而收到不少好评。但是我在测试的时候发现其自我防护还尚有欠缺,还望尽快修复。值得一提的是,这个仓库里面涉及到的技术并不深奥,并且有些漏洞甚至不需要管理员权限就能被利用。

警告

创建该仓库的目的是测试及学习用途。对于您如何使用这个仓库里的内容,本人概不负责。请不要把该仓库里的内容用于任何不正当的用途。您只应该在自己的设备上或者自己的虚拟机中测试该仓库里面涉及到的技术。

测试环境

火绒安全软件版本: 5.0.39.7

操作系统: Windows 10 1909 x64

官方回应

2020年3月17日: 将漏洞反馈给火绒官方

2020年3月19日: 官方确认漏洞

2020年3月31日: 官方指除了PromptBypass1以外的漏洞均在火绒安全5.0.41.0修复。对于PromptBypass1,官方指“窗口程序无法知道消息来源,所以无法过滤” (请见帖子)。

帖子: http://bbs.huorong.cn/thread-67135-1-1.html

漏洞

请进入文件夹查看对应漏洞的详情

文件夹 需要管理员权限 描述 已修复
KillHipsDaemon 火绒防护程序HipsDaemon.exe的自我保护漏洞 ×
KillTray1 火绒托盘程序HipsTray.exe的自我保护漏洞 ×
KillTray2 火绒托盘程序HipsTray.exe的自我保护漏洞
PromptBypass1 火绒的防护弹窗的漏洞 ×
PromptBypass2 火绒防护程序的通讯漏洞

Huorong Internet Security Vulnerabilities

Description

Huorong Internet Security has a good reputation (at least in my opinion) and it received a lot of praise for its accuracy and rapidity. However, during my testing, I found that there are still some flaws in its self-protection. I hope they can be repaired as soon as possible. It is worth mentioning that the technology involved in this repository is not difficult, and some vulnerability can be exploited even without administrative privilege.

Warning

This repository is created for testing and educational purposes. I do not take any responsibility for what you do with the contents in this repository. Do not use the contents of this repository for any improper purpose. You should only test the technology involved in this repository on your own equipment or in your virtual machine.

Testing Environment

Huorong Internet Security Version: 5.0.39.7

Operating System: Windows 10 1909 x64

Official Response

2020 Mar 17: Vulnerabilities reported to the official

2020 Mar 19: Vulnerabilities confirmed officially

2020 Mar 31: The official says that all vulnerabilities except PromptBypass1 are fixed in Huorong Internet Security version 5.0.41.0. As for PromptBypass1, the official says that "The window cannot detect the source of the message, thus it cannot be filtered" (Please see the post).

The post: http://bbs.huorong.cn/thread-67135-1-1.html

Vulnerabilities

Please enter the folders to see corresponding vulnerability details

Folder Administrative Privilege Required Description Repaired
KillHipsDaemon Yes Self-protection vulnerability of Huorong Internet Security daemon process HipsDaemon.exe ×
KillTray1 Yes Self-protection vulnerability of Huorong Internet Security Tray process HipsTray.exe ×
KillTray2 No Self-protection vulnerability of Huorong Internet Security Tray process HipsTray.exe
PromptBypass1 No Huorong popup prompt vulnerability ×
PromptBypass2 No Communication vulnerability of Huorong Internet Security

More Repositories

1

Prevent_Process_Creation

Record & prevent process creation in kernel mode
C
37
star
2

Prevent_File_Deletion

Record & prevent file deletion in kernel mode
C
36
star
3

Kernel_Mode_Process_Protection

My first kernel-mode process protection driver!
C
26
star
4

DragControlsIDE-v2

拖控件大法第二版!第一版:https://github.com/SweetIceLolly/DragControlsIDE
VBA
24
star
5

arp_bomber

A program that sends a lot of fake ARP packets to the router. This may kick everyone out of the network!
C++
18
star
6

Disable_Ctrl_Alt_Del

Disable Ctrl+Alt+Del hotkey
C++
16
star
7

DragControlsIDE

一个使用VB6开发的简易IDE,以VB6开发的形式来开发C++程序,让C++对GUI的编写更加香甜~
C
14
star
8

youtube-playlist-manager

YouTube playlist manager
JavaScript
13
star
9

RemoteControl

A remote control written in VB6
Visual Basic
10
star
10

Github_Friends

Github_Friends
Python
10
star
11

multithreaded-http-server

A good performance multithreaded HTTP REST server
C++
10
star
12

VB6-MemoryDC

A memory DC class written in VB6
Visual Basic
9
star
13

Multithread-Screen-Streaming

VB6 多线程屏幕串流
Visual Basic
7
star
14

BackgroundServer

A background server that allows you to manage your computer via a browser. Written in VB6.
Visual Basic
7
star
15

SocketTester

A very simple tool to test sockets. Useful when doing socket programming. Capable for both TCP and UDP connections.
Visual Basic
7
star
16

IceWallet

A very simple Personal Finance App
TypeScript
7
star
17

Sao_Title_Bot

一个生成骚论文题目的机器人
Python
6
star
18

My_First_Driver

Hello world from kernel!
C
5
star
19

mongoStat

用来监视MongoDB操作数的小服务器
JavaScript
4
star
20

QQ_MsDoc_Bot

从微软官方文档里搜索资料的QQ聊天机器人
Python
4
star
21

Bingy

Bingy 机器人
C++
3
star
22

Hello_WebSocket

My first websocket practice!
JavaScript
3
star
23

sweeticelolly.github.io

My blog
HTML
3
star
24

Hello_PHP

My first PHP practice!
PHP
2
star
25

my-blog-backend

The back-end source code of my blog
JavaScript
2
star
26

Hello_React

My first React practice!
JavaScript
2
star
27

QQ_StackOverflow_Bot

从StackOverflow上搜索资料的QQ聊天机器人
Python
2
star
28

Crack-Me

很久之前群里兴起一股破解风,然后我用VB6写了这个“来破解呀”。现在也发上来吧233
Visual Basic
2
star
29

MusicStatus

一个小服务器 别人访问的时候会返回当前正在YouTube播放的歌
Visual Basic
1
star
30

ParkingSystem

Parking system solution
C++
1
star
31

pthread_win

pthread library for Windows (incomplete)
C++
1
star