ããæ¥ãäžåžãããªãäžéšã®äººã¯è¿œå ã®äœ¿çšèš±å¯ãååŸããã«è·å Žã®ã³ã³ãã¥ãŒã¿ã«ãªã¢ãŒã ã¢ã¯ã»ã¹ã§ããã®ã§ãããã?ããšãã質åããããšããŸãã
æãç©Žããéããããšãã課é¡ãçããŸãã
ãããã¯ãŒã¯çµç±ã§ãªã¢ãŒãå¶åŸ¡ããããã®ã¢ããªã±ãŒã·ã§ã³ã¯æ°å€ããããŸã: Chrome ãªã¢ãŒã ãã¹ã¯ããããAmmyAdminãLiteManagerãTeamViewerãAnyplace Control ãªã©ãChrome ãªã¢ãŒã ãã¹ã¯ãããã«ãµãŒãã¹ãžã®ã¢ã¯ã»ã¹ãé»æ¢ããããã®å
¬åŒããã¥ã¢ã«ãããå ŽåãTeamViewer ã«ã¯æéããªã¯ãšã¹ãã«å¯Ÿããã©ã€ã»ã³ã¹å¶éããããŸãããããã¯ãŒã¯ããé®æããããŠãŒã¶ãŒã¯äœããã®åœ¢ã§ç®¡çè
ã«ãæ¯ãé£ããã°ããããšã§ãå人䜿çšãšããŠå€ãã®äººã«æçšãããŠããŸãããAnyDesk ã¯äŸç¶ãšããŠç¹å¥ãªæ³šæãå¿
èŠãšããŸããç¹ã«äžåžããããŒ!ããšèšã£ãå Žåã«ã¯ãªãããã§ãã
å
容ã«ãã£ãŠãããã¯ãŒã¯ ãã±ããããããã¯ããå
容ãããããããã«æºè¶³ããŠããå Žåã¯ãæ®ãã®å
容ãç解ããŠãã ããã
æå³ããŠããŸãã ããªãã®ããã«ã
å®ã¯éããè¡ãããšããŠã
ãã€ãŠãç§ã¯ãæªãããœãããŠã§ã¢ãšãšãã«ãã£ãŠæ¥ããAnyplace Controlãããããã¯ããåé¡ã解決ããŸããããã»ãã®æ°åã® IP ããããã¯ããããšã§è§£æ±ºããŸãã (ãŠã€ã«ã¹å¯Ÿçãœãããããã¯ã¢ããããŸãã)ã AnyDesk ã®åé¡ã¯ãåæ°åã® IP ã¢ãã¬ã¹ãæåã§åéããåŸã ç§ãæçºãã æ¥åžžçãªèäœåŽåããæãåºãã
ãŸãããC:ProgramDataAnyDeskãã«ã¯èšå®ãªã©ãæžããããã¡ã€ã«ãå€æ°ååšããŠããããã®ãã¡ã€ã«å ã« ad_svc.ãã¬ãŒã¹ æ¥ç¶ããã³é害ã«é¢ããã€ãã³ããåéãããŸãã
1ã 芳å¯
ãã§ã«è¿°ã¹ãããã«ã*.anydesk.com ããããã¯ããŠãããã°ã©ã ã®åäœã«ã¯äœã®çµæãçããªãã£ããããåæããããšã決å®ãããŸããã ã¹ãã¬ã¹ã®å€ãç¶æ³ã«ãããããã°ã©ã ã®åäœã Sysinternals ã® TCPView ãæã«ããŠãããã«äœ¿ããŸããã!
1.1. ç§ãã¡ã«ãšã£ãŠé¢å¿ã®ããããã€ãã®ããã»ã¹ãããã³ã°ãããŠãããå€éšããã¢ãã¬ã¹ãšéä¿¡ããããã»ã¹ã ããç§ãã¡ã«ãšã£ãŠé¢å¿ãããããšãããããŸãã æ¥ç¶å
ã®ããŒãã¯ãç§ãèŠããšããã80ã443ã6568 ãéžæãããŠããŸãã ð 80 ãš 443 ããããã¯ããããšã¯çµ¶å¯Ÿã«ã§ããŸããã
1.2. ã«ãŒã¿ãŒãéããŠã¢ãã¬ã¹ããããã¯ããåŸãå¥ã®ã¢ãã¬ã¹ãéãã«éžæãããŸãã
1.3. ç§ãã¡ã®ã³ã³ãœãŒã«ããã¹ãŠã§ãïŒ PID ãç¹å®ãããšãå°ã幞éã ã£ãã®ã¯ãAnyDesk ããµãŒãã¹ã«ãã£ãŠã€ã³ã¹ããŒã«ãããŠãããããæ¢ããŠãã PID ãå¯äžã®ãã®ã ã£ããšããããšã§ãã
1.4. ããã»ã¹ PID ãããµãŒãã¹ ãµãŒããŒã® IP ã¢ãã¬ã¹ã決å®ããŸãã
2.æºå
IPã¢ãã¬ã¹ãç¹å®ããããã°ã©ã ã¯ããããç§ã®PCã§ããåããªãã®ã§ã䟿å©ãæ ããå¶éããªãã®ã§C#ã§ãã
2.1. å¿ èŠãª IP ã¢ãã¬ã¹ãèå¥ããããã®ãã¹ãŠã®æ¹æ³ã¯ãã§ã«ç¥ãããŠããŸãããå®è£ ãããã®ã¯ãŸã å ã®ããšã§ãã
string pid1_;//ÑзМаеЌ PID ÑеÑвОÑа AnyDesk
using (var p = new Process())
{p.StartInfo.FileName = "cmd.exe";
p.StartInfo.Arguments = " /c "tasklist.exe /fi "imagename eq AnyDesk.exe" /NH /FO CsV | findstr "Services""";
p.StartInfo.UseShellExecute = false;
p.StartInfo.RedirectStandardOutput = true;
p.StartInfo.CreateNoWindow = true;
p.StartInfo.StandardOutputEncoding = Encoding.GetEncoding("CP866");
p.Start();
string output = p.StandardOutput.ReadToEnd();
string[] pid1 = output.Split(',');//пеÑевПЎОЌ ПÑÐ²ÐµÑ Ð² ЌаÑÑОв
pid1_ = pid1[1].Replace(""", "");//беÑеЌ 2й ÑÐ»ÐµÐŒÐµÐœÑ Ð±ÐµÐ· кавÑÑек
}
åæ§ã«ãæ¥ç¶ã確ç«ãããµãŒãã¹ãèŠã€ããŸããäž»åç·ã®ã¿ã瀺ããŸã
p.StartInfo.Arguments = "/c " netstat -n -o | findstr /I " + pid1_ + " | findstr "ESTABLISHED""";
ãã®çµæã¯æ¬¡ã®ããã«ãªããŸãã
åã®æé ãšåæ§ã«ããã®è¡ãã 3 åç®ãæœåºããã:ã以éããã¹ãŠåé€ããŸãã ãã®çµæãç®çã® IP ãåŸãããŸããã
2.2. Windows ã§ã® IP ãããã¯ã Linux ã« Blackhole ãš iptables ãããå ŽåãWindows ã§ãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããã« XNUMX è¡ã§ IP ã¢ãã¬ã¹ããããã¯ããæ¹æ³ã¯çããããšãå€æããŸããã
ã§ããã©ããªéå
·ããã£ããã ããâŠ
route add МаÑ_МайЎеММÑй_IP_аЎÑÐµÑ mask 255.255.255.255 10.113.113.113 if 1 -p
ããŒãã©ã¡ãŒã¿ã1ã®å Žå" ã«ãŒããã«ãŒãããã¯ã«éä¿¡ããŸã (route print ãå®è¡ãããšãå©çšå¯èœãªã€ã³ã¿ãŒãã§ã€ã¹ã衚瀺ã§ããŸã)ããããŠéèŠ! ããã§ããã°ã©ã ãèµ·åããå¿ èŠããããŸãã 管çè æš©éãæã€ãã«ãŒããå€æŽããã«ã¯é«åºŠãäžããå¿ èŠãããããã§ãã
2.3. èå¥ããã IP ã¢ãã¬ã¹ã®è¡šç€ºãšä¿åã¯ç°¡åãªäœæ¥ã§ããã説æããå¿ èŠã¯ãããŸããã èããŠã¿ãã°ããã¡ã€ã«ãåŠçã§ããŸã ad_svc.ãã¬ãŒã¹ AnyDesk èªäœã§ãããããã«ã¯æãã€ããŸããã§ãããããããå¶éãããã®ã§ãããã
2.4. ããã°ã©ã ã®å¥åŠãªäžåäžãªåäœã¯ãWindows 10 ã§ã¯ãµãŒãã¹ ããã»ã¹ããã¿ã¹ã¯ãã«ããããšèªåçã«åèµ·åããŸãããWindows 8 ã§ã¯çµäºããã³ã³ãœãŒã« ããã»ã¹ã®ã¿ãæ®ããåæ¥ç¶ãããŸãããäžè¬ã«ãããã¯éè«ççã§ãããäžæ£ç¢ºã§ãã
ãµãŒããŒã«æ¥ç¶ããŠããããã»ã¹ãåé€ãããšã次ã®ã¢ãã¬ã¹ã«ã匷å¶çã«ãåæ¥ç¶ã§ããããã«ãªããŸãã ããã¯åã®ã³ãã³ããšåãæ¹æ³ã§å®è£ ãããããã次ã®ããã«æå®ããŸãã
p.StartInfo.Arguments = "/c taskkill /PID " + pid1_ + " /F";
ããã«ãAnyDesk ããã°ã©ã ãèµ·åããŸãã
//запÑÑкаеЌ пÑПгÑÐ°ÐŒÐŒÑ ÐºÐŸÑПÑÐ°Ñ ÑаÑпПлПжеМа пП пÑÑО path_pro
if (File.Exists(path_pro)){
Process p1 = Process.Start(path_pro);}
2.5. AnyDesk ã®ã¹ããŒã¿ã¹ã 1 åã« XNUMX å (ãŸãã¯ãã以äžã®é »åºŠã§?) ãã§ãã¯ããæ¥ç¶ãããŠãããã©ããã確èªããŸãã æ¥ç¶ã確ç«ãããŸãã - ãã® IP ããããã¯ããããäžåºŠæåããããçŽããŸã - æ¥ç¶ãããŸã§åŸ ã¡ããããã¯ããŠåŸ ã¡ãŸãã
3. æ»æ
ã³ãŒãããã¹ã±ãããããããã»ã¹ãèŠèŠåããããšã«ããŸããã+" ã¯ãèŠã€ãã£ãŠãããã¯ããã IP ã瀺ããŸãã"." - AnyDesk ããã®ãã€ããŒæ¥ç¶ãæåããªãå Žåã¯ãã§ãã¯ãç¹°ãè¿ããŸãã
â
çµæãšããŠâŠ
ãã®ããã°ã©ã ã¯ãAnyDesk 5 ããã³ 6 ã®ããŒãžã§ã³ãåãããç°ãªã Windows OS ãæèŒããè€æ°ã®ã³ã³ãã¥ãŒã¿ã§åäœããŸããã500 å以äžç¹°ãè¿ããçŽ 80 åã®ã¢ãã¬ã¹ãåéãããŸããã 2500 - 87ãªã©...
æéã®çµéãšãšãã«ããããã¯ããã IP ã®æ°ã¯ 100 以äžã«éããŸããã
æçµåãžã®ãªã³ã¯ ããã¹ããã¡ã€ã« ã¢ãã¬ã¹ä»ã:
ãããŠãããŸãïŒ IP ã¢ãã¬ã¹ã®ããŒã«ã¯ã¹ã¯ãªãããéããŠã¡ã€ã³ ã«ãŒã¿ãŒã®ã«ãŒã«ã«è¿œå ããããããAnyDesk ã¯å€éšæ¥ç¶ãäœæã§ããŸããã
å¥åŠãªç¹ããããŸããæåã®ãã°ããããã®ã¢ãã¬ã¹ãæ å ±ã®è»¢éã«é¢äžããŠããããšã¯æããã§ãã boot-01.net.anydesk.comã ãã¡ãããååãšããŠãã¹ãŠã® *.net.anydesk.com ãã¹ãããããã¯ããŸããããããã¯äžæè°ãªããšã§ã¯ãããŸããã ç°ãªãã³ã³ãã¥ãŒã¿ããéåžžã® ping ãå®è¡ãããã³ã«ããã®ãã¡ã€ã³åã¯ç°ãªã IP ãäžããŸãã Linux ã§ã®ç¢ºèª:
host boot-01.net.anydesk.com
DNSLookup ã®ããã«ãIP ã¢ãã¬ã¹ã¯ XNUMX ã€ã ãäžããããŸããããã®ã¢ãã¬ã¹ã¯å¯å€ã§ãã TCPView æ¥ç¶ãåæãããšã次ã®ã¿ã€ãã® IP ã¢ãã¬ã¹ã® PTR ã¬ã³ãŒããè¿ãããŸãã ãªã¬ãŒ-*.net.anydesk.com.
çè«äž: ping ã¯ãããã¯ãããŠããªãæªç¥ã®ãã¹ãã«éä¿¡ãããå Žåããããã boot-01.net.anydesk.com ãããã® IP ãèŠã€ããŠãããã¯ãããã®å®è£ ã Linux OS ã§ã®éåžžã®ã¹ã¯ãªããã«ããããšãã§ããŸããããã§ã¯ AnyDesk ãã€ã³ã¹ããŒã«ããå¿ èŠã¯ãããŸããã åæã®çµæããããã® IP ã¯ã亀差ããããªã¹ãããèŠã€ãã£ããã®ã䜿çšããŸãããããããããã°ã©ã ãæ¢ç¥ã® IP ã®ãåé¡ããéå§ããåã«æ¥ç¶ããã®ã¯ããã®ãã¹ãã ãã§ãããããããåŸã»ã©ãã¹ãæ€çŽ¢ã® 2 çªç®ã®éšåã§èšäºãè£è¶³ããäºå®ã§ãããçŸæç¹ã§ã¯ãéåžžãããã°ã©ã èªäœã¯ãããã¯ãŒã¯å€éšçµåå ã«ã¯ã€ã³ã¹ããŒã«ãããŸããã
äžèšã«éæ³ãªãã®ãå«ãŸããŠããªãããšãé¡ã£ãŠããŸããAnyDesk ã®äœæè
ã¯ç§ã®è¡åãã¹ããŒããã³ãããæ
床ã§æ±ã£ãŠãããã§ãããã
åºæïŒ habr.com