当前位置:网站首页>MSF横向之MSF端口转发+路由表+SOCKS5+proxychains
MSF横向之MSF端口转发+路由表+SOCKS5+proxychains
2022-07-06 10:01:00 【西湖第一剑】
MSF后渗透的一些操作
端口转发
meterpreter > portfwd add -l 2222 -r 172.16.1.156 -p 3389 #将目标机172.16.1.156的3389端口转发到本地2222端口
meterpreter > portfwd list #查看转发列表
meterpreter > portfwd flush #清空转发列表
rdesktop 127.0.0.1:2222 #kali远程桌面使用2222端口
添加路由,横向渗透(跨网段攻击)
run autoroute -s 172.16.2.0/24 #添加到目标环境网络
run autoroute –p #查看添加的路由
route print #打印路由
run post/windows/gather/arp_scanner RHOSTS=172.16.2.0/24 #扫描整个段存活主机
run auxiliary/scanner/portscan/tcp RHOSTS=172.16.2.11 PORTS=3389 #检查IP是否开放3389
利用arp扫描内网主机
use post/windows/gather/arp_scanner
set rhosts 172.16.2.0/24
set session 1
exploit
Socks代理篇
新版的msf和老版的不一样,代理模块也不一样。
auxiliary/server/socks_proxy
msf6 auxiliary(server/socks_proxy) > set srvport 7777
srvport => 7777
msf6 auxiliary(server/socks_proxy) > run
[*] Auxiliary module running as background job 0.
[*] Starting the SOCKS proxy server
配置proxychains
用代理软件去连接建立好的socks隧道,便可以成功访问内网。
vi /etc/proxychains.conf #添加 socks5 127.0.0.1 7777
proxychains+nmap扫描主机是否存在漏洞
proxychains nmap -sT -Pn -p445 --script=vuln 192.168.52.141
proxychains使用msf框架
proxychains msfconsole
边栏推荐
- OliveTin能在网页上安全运行shell命令(上)
- FlutterWeb瀏覽器刷新後無法回退的解决方案
- OpenEuler 会长久吗
- The art of Engineering (1): try to package things that do not need to be exposed
- Compile and build, from the bottom to the top
- TCP connection is more than communicating with TCP protocol
- Remote code execution penetration test - B module test
- 《ASP.NET Core 6框架揭秘》样章发布[200页/5章]
- FlutterWeb浏览器刷新后无法回退的解决方案
- Video fusion cloud platform easycvr adds multi-level grouping, which can flexibly manage access devices
猜你喜欢

面试突击62:group by 有哪些注意事项?

Pytest learning ----- pytest confitest of interface automation test Py file details

sql语句优化,order by desc速度优化

Unity小技巧 - 绘制瞄准准心

Kivy tutorial: support Chinese in Kivy to build cross platform applications (tutorial includes source code)

Alibaba brand data bank: introduction to the most complete data bank

Distributed (consistency protocol) leader election (dotnext.net.cluster implements raft election)

78 岁华科教授逐梦 40 载,国产数据库达梦冲刺 IPO

Unity particle special effects series - treasure chest of shining stars

OpenCV中如何使用滚动条动态调整参数
随机推荐
Quick start of Hongmeng system
FlutterWeb瀏覽器刷新後無法回退的解决方案
Is it meaningful for 8-bit MCU to run RTOS?
In terms of byte measurement with an annual salary of 30W, automated testing can be learned in this way
Appium automated test scroll and drag_ and_ Drop slides according to element position
在一台服务器上部署多个EasyCVR出现报错“Press any to exit”,如何解决?
TCP connection is more than communicating with TCP protocol
Xin'an Second Edition: Chapter 12 network security audit technology principle and application learning notes
Zen integration nails, bugs, needs, etc. are reminded by nails
Summary of Android interview questions of Dachang in 2022 (II) (including answers)
Xin'an Second Edition: Chapter 26 big data security demand analysis and security protection engineering learning notes
RB157-ASEMI整流桥RB157
connection reset by peer
Wechat applet obtains mobile number
Interview shock 62: what are the precautions for group by?
微信小程序获取手机号
Pytest learning ----- pytest operation mode and pre post packaging of interface automation testing
10 advanced concepts that must be understood in learning SQL
中移动、蚂蚁、顺丰、兴盛优选技术专家,带你了解架构稳定性保障
[rapid environment construction] openharmony 10 minute tutorial (cub pie)