2017年12月26日 星期二
windows 7 右下角有顯示小喇叭的圖示,測試亦有聲音輸出,但點選圖示無法調整音量大小
在命令中執行 regedit 開啟登錄編輯程式,點選
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run,接著在Run項的右側窗格中,新
建“字符串值”,命名為Systray。然後雙擊打開Systray鍵值,再將其編輯為
c:windowssystem32Systray.exe。退出編輯程式後,再重啟系統。點選右下角音量小圖示,已可正常調整聲 音音量。
遇到比較少見的影片格式,可能無法順利使用一般的影音播放器來播放影片內容K-Lite Codec Pack
K-Lite v13.7.5 影音編/解碼器
K-Lite Codec Pack裡面包含了一些常用的影音解碼器與相關工具程式。
2017年12月3日 星期日
Windows 10中沒有【中華民國曆】
Windows 10中沒有【中華民國曆】
https://social.technet.microsoft.com/Forums/zh-TW/b6b269c5-2624-417c-b143-87caa48f03af/windows-10?forum=win10itprogeneralTW
Solution:
http://ismallchu.blogspot.tw/2015/08/windows-10.html
2017年11月1日 星期三
2017年9月28日 星期四
利用 dir 發現可疑檔案
method 1: (利用 find)
dir /tc malware
2017/01/01 下午 01:32 malware
dir /a /s /tc /od c:\ | find "2017/01/01 下午 01:3" (time range)
dir /a /s /tc /o-d c:\windows\system32 |more
*************************************************
use wce.exe and PwDump7.exe
wce.exe
wce.exe -w
PwDump7.exe
Administrator:500:xxxx
wce.exe -s Administrator:test:xxxx
net use \\test\c$
Windows Credentials Editor (WCE) is a security tool to list logon sessions and add, change, list and delete associated credentials (ex.: LM/NT hashes, plaintext passwords and Kerberos tickets).
We have developed a new password dumper for windows named PWDUMP7. The main difference between pwdump7 and other pwdump tools is that our tool runs by extracting the binary SAM and SYSTEM File from the Filesystem and then the hashes are extracted. For that task Rkdetector NTFS and FAT32 filesystem drivers are used.

Pwdump7 is also able to extract passwords offline by selecting the target files.
*************************************************
cfc.exe is a product CompFileChecker with H.KINOSHITA company,it version is 0.0.2.0,size is 609792. cfc.exe virus or errors should be disabled and removed if it was attacked and brought you windows xp/vista/7/windows 10 errors.
cfc.exe algx.exe c:\windows\winhelp.exe
dir /tc malware
2017/01/01 下午 01:32 malware
dir /a /s /tc /od c:\ | find "2017/01/01 下午 01:3" (time range)
dir /a /s /tc /o-d c:\windows\system32 |more
*************************************************
use wce.exe and PwDump7.exe
wce.exe
wce.exe -w
PwDump7.exe
Administrator:500:xxxx
wce.exe -s Administrator:test:xxxx
net use \\test\c$
Windows Credentials Editor (WCE) is a security tool to list logon sessions and add, change, list and delete associated credentials (ex.: LM/NT hashes, plaintext passwords and Kerberos tickets).
We have developed a new password dumper for windows named PWDUMP7. The main difference between pwdump7 and other pwdump tools is that our tool runs by extracting the binary SAM and SYSTEM File from the Filesystem and then the hashes are extracted. For that task Rkdetector NTFS and FAT32 filesystem drivers are used.

*************************************************
cfc.exe is a product CompFileChecker with H.KINOSHITA company,it version is 0.0.2.0,size is 609792. cfc.exe virus or errors should be disabled and removed if it was attacked and brought you windows xp/vista/7/windows 10 errors.
cfc.exe algx.exe c:\windows\winhelp.exe
2017年9月13日 星期三
graylog splunk search user key word
查詢使用者登入密碼錯誤
訊息:
user="s0116" group="N/A" authproto="HTTPS(10.10.66.216)" action="authentication" status="failure" reason="invalue username/password" msg="User s0116 failed in authentication"
查詢: "s0116" && "invalue username/password"
或
使用 splunk (只記錄登入登出紀錄)
查詢: "s0116"
******************************************************
search mail keyword
search keyword:
"zxcv2020123@outlook.com" AND source:mg
mg postfix/cleanup[5592]: 08BBE132: warning: header Subject:? =?gb2312?B?1sK437LNtPPIq9Cj0KOE1c6vhlSjrNPQ6lDQo4TVlf7XaNDCyM7Qo+lM33g=?=? =?gb2312?B?xWWV/tdo1vfPr7C4?= from mail-db8eur05olkn2075.outbound.protection.outlook.com[40.92.89.75]; from=<zxcv2020123@outlook.com> to=<ej@mail.nkuht.edu.tw> proto=ESMTP helo=<EUR05-DB8-obe.outbound.protection.outlook.com>
mg
2019-12-30T08:50:51.000Z
*************************************************
date=2017-09-14 time=00:27:44 devname=FG1K5D devid=FG1K5D3I15802166 logid=0102043008 type=event subtype=user level=notice vd="root" logdesc="Authentication success" srcip=192.168.202.158 dstip=192.168.250.86 policyid=0 user="A0411018" group="auth_user_group" authproto="HTTP(192.168.202.158)" action=authentication status=success reason="N/A" msg="User A0411018 succeeded in authentication"
search keyword:
192.168.202.158 AND success
192.168.12.150 AND authentication
***************************************************
search keyword: nf_src_address:192.168.30.148
訂閱:
文章 (Atom)
