当前位置:网站首页>Intranet information collection of Intranet penetration (4)
Intranet information collection of Intranet penetration (4)
2022-07-06 14:17:00 【Unknown white hat】
Catalog
Metasploit Intranet information collection
12 Service scanning and checking
Metasploit Intranet information collection
attack kali 192.168.0.103
Drone aircraft win7 192.168.0.105
09scraper
run scraper( Collect the common information on the target machine, download and save it locally )
/root/.msf4/logs/scripts/scraper
09winenum
run winenum( Collect some current systems , User group related information )
/root/.msf4/logs/scripts/winenum
10msf The host found
The module is located in the source code path modules/auxiliary/scanner/discovery/
There are mainly :
arp_sweep
ipv6_mulitcast_ping
ipv6_neighbor
ipv6_neighbor_router_advertisement
udp_probe
udp_sweep
11msf Port scanning
msf> search portscan
auxiliary/scanner/portscan/ack // adopt ACK Scan the way on the firewall is not shielded port detection
auxiliary/scanner/portscan/ftpbounce // adopt FTP bounce The principle of attack is right TCP Services , Some new software can prevent this attack well , But it can still be used on the old system
auxiliary/scanner/portscan/syn // Use send TCP SYN Flag to detect open ports
auxiliary/scanner/portscan/tcp // Through a complete TCP Connect to determine whether the port is open , The most accurate but the slowest
auxiliary/scanner/portscan/xmas // A more secretive scanning method , By sending FIN·PSH·URG sign , Can avoid some advanced TCP Filtering of tag detector
In general, it is recommended to use syn Port scanner · Faster · The results are accurate · Not easy to be noticed by the other party
syn The use of scanners
use auxiliary/scanner/portscan/syn
set rhosts 192.168.0.105/24
set threads 20
exploit
12 Service scanning and checking
After determining the open port , Mining the service information running on the corresponding port
stay Metasploit Of Scanner In auxiliary module , Tools for service scanning and enumeration are often used in [service_name]_version and [service_name]_login name
[service_name]_version It can be used to traverse hosts that contain certain services in the network , And further determine the version of the service
[service_name]_login Password detection attacks can be carried out on certain services
stay msf The terminal can input
search name:_version
View all available service enumeration modules
边栏推荐
- Package bedding of components
- 强化学习基础记录
- 强化學習基礎記錄
- The difference between layer 3 switch and router
- Programme de jeu de cartes - confrontation homme - machine
- A complete collection of papers on text recognition
- captcha-killer验证码识别插件
- 7-14 error ticket (PTA program design)
- Feature extraction and detection 14 plane object recognition
- Attach the simplified sample database to the SQLSERVER database instance
猜你喜欢
Yugu p1012 spelling +p1019 word Solitaire (string)
Record a penetration of the cat shed from outside to inside. Library operation extraction flag
搭建域环境(win)
强化学习基础记录
Meituan dynamic thread pool practice ideas, open source
captcha-killer验证码识别插件
HackMyvm靶机系列(7)-Tron
Only 40% of the articles are original? Here comes the modification method
Ucos-iii learning records (11) - task management
[VMware abnormal problems] problem analysis & Solutions
随机推荐
[data processing of numpy and pytoch]
XSS之冷门事件
Experiment 7 use of common classes (correction post)
A complete collection of papers on text recognition
Strengthen basic learning records
Yugu p1012 spelling +p1019 word Solitaire (string)
JDBC看这篇就够了
msf生成payload大全
Experiment 4 array
7-5 走楼梯升级版(PTA程序设计)
7-4 hash table search (PTA program design)
7-8 7104 Joseph problem (PTA program design)
Detailed explanation of network foundation routing
[experiment index of educator database]
Which is more advantageous in short-term or long-term spot gold investment?
Detailed explanation of three ways of HTTP caching
实验八 异常处理
HackMyvm靶机系列(7)-Tron
The United States has repeatedly revealed that the yield of interest rate hiked treasury bonds continued to rise
Hackmyvm target series (2) -warrior