当前位置:网站首页>Cobaltstrike builds an intranet tunnel
Cobaltstrike builds an intranet tunnel
2022-07-05 22:03:00 【Global variable Global】
Through detailed explanation CobaltStrike Tools , A deeper grasp of CobaltStrike usage ; The content of the text is compiled by personal understanding , If there is any mistake , Bosses do not spray , Personal skills are not good ; Any technique mentioned in this article comes from range practice , For reference only , Do not use the related technology in the article to engage in illegal testing , If all the adverse consequences caused by this have nothing to do with the author of the article .
CobaltStrike Build an intranet tunnel
Establish intranet tunnel network card
When we need to access the internal network on the attacker , Not established in sockes5 Under the circumstances , You can also build intranet tunnels :
covertvpn phear6 10.10.10.145 # Establish intranet tunnel network card

When it's done , Can be in Cobalt Strike Check the network card in the menu , After use, there will be traffic at this location :
Create a virtual network card
Then we need to establish a virtual network card in the attacker :
ifconfig phear6 10.10.10.0/24 # establish phear6 network card

Access internal network
In this way, we can directly access the internal network through the attacker 10.10.10.138 Or our domain controller IP10.10.10.142:
It can also be used nmap To scan their 445 port , This ratio socks More convenient and faster .
And it can be seen from the figure that the flow is from CS go :
边栏推荐
- EL与JSTL注意事项汇总
- Official clarification statement of Jihu company
- K210学习笔记(四) K210同时运行多个模型
- The simple problem of leetcode is to split a string into several groups of length K
- Did you brush the real title of the blue bridge cup over the years? Come here and teach you to counter attack!
- 让开发效率提升的跨端方案
- Codeforces 12D Ball 树形阵列模拟3排序元素
- Installation of VMware Workstation
- The real situation of programmers
- Tips for using SecureCRT
猜你喜欢

EBS Oracle 11g cloning steps (single node)

ICMP introduction

Two stage locking protocol for concurrency control

The simple problem of leetcode is to split a string into several groups of length K

Ad637 notes d'utilisation

Huawei game multimedia service calls the method of shielding the voice of the specified player, and the error code 3010 is returned

Common interview questions of redis factory

Leetcode simple question: the minimum cost of buying candy at a discount

Defect detection - Halcon surface scratch detection

Performance monitoring of database tuning solutions
随机推荐
The simple problem of leetcode is to split a string into several groups of length K
MySQL disconnection reports an error MySQL ldb_ exceptions. OperationalError 4031, The client was disconnected by the server
Lightweight dynamic monitorable thread pool based on configuration center - dynamictp
AD637使用筆記
Interview questions for basic software testing
Matlab | app designer · I used Matlab to make a real-time editor of latex formula
Countdown to 92 days, the strategy for the provincial preparation of the Blue Bridge Cup is coming~
他们主动布局(autolayout)环境的图像编辑器
Reptile practice
数据泄露怎么办?'华生·K'7招消灭安全威胁
Livelocks and deadlocks of concurrency control
Getting started with microservices (resttemplate, Eureka, Nacos, feign, gateway)
Pl/sql basic case
Overview of database recovery
An exception occurred in Huawei game multimedia calling the room switching method internal system error Reason:90000017
Summarize the reasons for 2XX, 3xx, 4xx, 5xx status codes
The solution to the problem that Oracle hugepages are not used, causing the server to be too laggy
poj 3237 Tree(树链拆分)
1.3 years of work experience, double non naked resignation agency face-to-face experience [already employed]
Huawei cloud modelarts text classification - takeout comments