当前位置:网站首页>Cobaltstrike builds an intranet tunnel
Cobaltstrike builds an intranet tunnel
2022-07-05 22:03:00 【Global variable Global】
Through detailed explanation CobaltStrike Tools , A deeper grasp of CobaltStrike usage ; The content of the text is compiled by personal understanding , If there is any mistake , Bosses do not spray , Personal skills are not good ; Any technique mentioned in this article comes from range practice , For reference only , Do not use the related technology in the article to engage in illegal testing , If all the adverse consequences caused by this have nothing to do with the author of the article .
CobaltStrike Build an intranet tunnel
Establish intranet tunnel network card
When we need to access the internal network on the attacker , Not established in sockes5 Under the circumstances , You can also build intranet tunnels :
covertvpn phear6 10.10.10.145 # Establish intranet tunnel network card
When it's done , Can be in Cobalt Strike Check the network card in the menu , After use, there will be traffic at this location :
Create a virtual network card
Then we need to establish a virtual network card in the attacker :
ifconfig phear6 10.10.10.0/24 # establish phear6 network card
Access internal network
In this way, we can directly access the internal network through the attacker 10.10.10.138 Or our domain controller IP10.10.10.142:
It can also be used nmap To scan their 445 port , This ratio socks More convenient and faster .
And it can be seen from the figure that the flow is from CS go :
边栏推荐
- Talking about MySQL index
- Implementing Lmax disruptor queue from scratch (IV) principle analysis of multithreaded producer multiproducersequencer
- Oracle hint understanding
- 数据泄露怎么办?'华生·K'7招消灭安全威胁
- boundary IoU 的计算方式
- An exception occurred in Huawei game multimedia calling the room switching method internal system error Reason:90000017
- Poj3414广泛搜索
- Defect detection - Halcon surface scratch detection
- A trip to Suzhou during the Dragon Boat Festival holiday
- Storage optimization of performance tuning methodology
猜你喜欢
深信服X计划-网络协议基础 DNS
Oracle advanced query
A number of ventilator giants' products have been recalled recently, and the ventilator market is still in incremental competition
A trip to Suzhou during the Dragon Boat Festival holiday
matlab绘制hsv色轮图
The real situation of programmers
Daily question brushing record (XIV)
Official clarification statement of Jihu company
Two stage locking protocol for concurrency control
Learning of mall permission module
随机推荐
Serializability of concurrent scheduling
资深电感厂家告诉你电感什么情况会有噪音电感噪音是比较常见的一种电感故障情况,如果使用的电感出现了噪音大家也不用着急,只需要准确查找分析出什么何原因,其实还是有具体的方法来解决的。作为一家拥有18年品牌
等到产业互联网时代真正发展成熟,我们将会看待一系列的新产业巨头的出现
Livelocks and deadlocks of concurrency control
Bitbucket installation configuration
让开发效率提升的跨端方案
如何向mongoDB中添加新的字段附代码(全)
MySQL连接断开报错MySQLdb._exceptions.OperationalError 4031, The client was disconnected by the server
HDU 4391 paint the wall segment tree (water
Oracle views the data size of a table
How to organize an actual attack and defense drill
Blocking protocol for concurrency control
Getting started with microservices (resttemplate, Eureka, Nacos, feign, gateway)
了解 Android Kotlin 中 DataStore 的基本概念以及为什么应该停止在 Android 中使用 SharedPreferences
Blocking of concurrency control
深信服X计划-网络协议基础 DNS
Meituan dynamic thread pool practice ideas, open source
The real situation of programmers
Codeforces 12D ball tree array simulation 3 sorting elements
Common interview questions of JVM manufacturers