> For the complete documentation index, see [llms.txt](https://twentysick.gitbook.io/twentysick/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://twentysick.gitbook.io/twentysick/sharing/series-phat-minh-lai-cai-banh-xe/iis-native-module-nhung-la-backdoor/references.md).

# References

## Các bài blog, research, tool toy,...

* [*https://cicada-8.medium.com/from-http-to-rce-how-to-leave-backdoor-in-iis-cbef8249eba9*](https://cicada-8.medium.com/from-http-to-rce-how-to-leave-backdoor-in-iis-cbef8249eba9)
* [*https://github.com/0x09AL/IIS-Raid/tree/master*](https://github.com/0x09AL/IIS-Raid/tree/master)
* [*https://web-assets.esetstatic.com/wls/2021/08/eset\_anatomy\_native\_iis\_malware.pdf*](https://web-assets.esetstatic.com/wls/2021/08/eset_anatomy_native_iis_malware.pdf)
* [*https://www.mdsec.co.uk/2020/02/iis-raid-backdooring-iis-using-native-modules/*](https://www.mdsec.co.uk/2020/02/iis-raid-backdooring-iis-using-native-modules/)
* [*https://github.com/PwCUK-CTO/iis-helper-plugin*](https://github.com/PwCUK-CTO/iis-helper-plugin)
* [*https://github.com/x64dbg/ScyllaHide*](https://github.com/x64dbg/ScyllaHide)

## Docs từ Microsoft

* [*https://learn.microsoft.com/vi-vn/iis/web-development-reference/native-code-api-reference/chttpmodule-onsendresponse-method*](https://learn.microsoft.com/vi-vn/iis/web-development-reference/native-code-api-reference/chttpmodule-onsendresponse-method)
* [*https://learn.microsoft.com/vi-vn/iis/web-development-reference/native-code-api-reference/chttpmodule-class*](https://learn.microsoft.com/vi-vn/iis/web-development-reference/native-code-api-reference/chttpmodule-class)
