当前位置:网站首页>[try to hack] cobalt strike (I)
[try to hack] cobalt strike (I)
2022-06-28 20:29:00 【Happy star】
Blog home page : Happy star The blog home page of
Series column :Try to Hack
Welcome to focus on the likes collection ️ Leaving a message.
Starting time :2022 year 6 month 28 Japan
The author's level is very limited , If an error is found , Please let me know , thank !
https://www.bilibili.com/video/BV1Zr4y137bW
Navigation assistant
CS Introduction and installation
Cobalt Strike It's a penetration test artifact ,Cobalt Strike No longer in use MSF But as a separate platform , It is divided into client and server , The server is a , The client can have multiple , It can be used by the team for distributed cooperative operation .
function :CS Integrated port forwarding 、 Service scan , Automatic overflow , Multimode port monitoring ,win exe Trojans generate ,win dll Trojans generate ,java Trojans generate ,office Macro virus generation , Horse binding ; Fishing attacks include : Site cloning , Target information acquisition ,java perform , Browser auto attack and so on .
Early versions Cobalt Srtike rely on Metasploit frame , And now Cobalt Strike No longer in use MSF But as a separate platform .
The community version of this tool is well known Armitage( One MSF Graphical interface tools ), and Cobalt Strike You can understand it as Armitage Commercial version of .
Different versions CS The directory structure is different , What I use here is 4.3
cobaltstrike Download link 
Because of startup Cobalt Strike need JDK Support for , So you need to install Java Environmental Science .
kaili By default, it will be installed java Environmental Science java --version
If not, install it
install jdk11
apt-get update
apt-get install openjdk-11-jdk
set default java Program
update-java-alternatives -s java-1.11.0-openjdk-amd64
CS start-up
Start server
The team server is best run on Linux On the platform
└─# ./teamserver
[*] Will use existing X509 certificate and keystore (for SSL)
Picked up _JAVA_OPTIONS: -Dawt.useSystemAAFontSettings=on -Dswing.aatext=true
[*] ./teamserver <host> <password> [/path/to/c2.profile] [YYYY-MM-DD]
<host> is the (default) IP address of this Cobalt Strike team server
<password> is the shared password to connect to this server
[/path/to/c2.profile] is your Malleable C2 profile
[YYYY-MM-DD] is a kill date for Beacon payloads run from this server
chmod +x teamserver // When teamserver When you don't have execute permission , Run the command ./teamserver 192.168.88.132 123456
The default connection port of the team server is 50050
Start client
Linux:./cobaltstrike or java -XX:+AggressiveHeap -XX:+UseParallelGC -jar cobaltstrike.jar
Windows: double-click cobaltstrike.exe
windows
host It's the server side IP Address
port The default open port of the server is 50050
user Customize a user name
password It is the password when opening the server

The first connection will appear hash check , there hash It's equal to the previous startup teamserver At the time of the hash, Just click ‘ yes ’ Connect to the team server .
CS Add listener


Monitor type 
beacon x The series is Cobalt Strike Oneself , Include dns,http,https,smb Four ways of listening
foreign Series is an external listener usually associated with MSF perhaps Armitagel linkage
CS Create a Trojan


Choose a monitor 
You can also generate dll Type of Trojan 
We choose EXE
Generate
Choose a save path
The victim double clicked the exe Program , Can be in CS The client is online
CS Generate office Macro file phishing


After selecting a listener ,Generate
open word(WPS no way ), Create a new blank document 
【 View 】-> 【 macro 】
create 
Ctrl+S preservation 
Victim opens file , That is to say CS The client is online

CS Clone website


clone url For the target site 
visit 
After entering content , Or jump to the real Baidu 
边栏推荐
- 电子科大(申恒涛团队)&京东AI(梅涛团队)提出用于视频问答的结构化双流注意网络,性能SOTA!优于基于双视频表示的方法!...
- grep文本搜索工具
- ThreadLocal原理
- Comparisonchain file name sort
- 大智慧上怎么进行开户啊, 安全吗
- Pyinstaller打包pikepdf失败的问题排查
- 方 差 分 析
- C # connect to the database to complete the operation of adding, deleting, modifying and querying
- 各种类型长
- No module named ‘PyEMD‘ ; Use plt figure()TypeError: ‘module‘ object is not callable
猜你喜欢
随机推荐
大智慧上怎么进行开户啊, 安全吗
【学习笔记】主成分分析法介绍
Lecture 30 linear algebra Lecture 4 linear equations
3. integrate listener
Severity code description project file line suppress status error lnk2038 detected a mismatch of "runtimelibrary": the value "md\u dynamicrelease" does not match the value "mdd\u dynamicde"
【学习笔记】聚类分析
Visualization of neural network structure in different frames
字符和整数
Employee salary management system
Risc-v instruction set
odoo15 Module operations are not possible at this time, please try again later or contact your syste
请允许当下国内ToB的「不完美」
APISIX 助力中东社交软件,实现本地化部署
Input and output real data
30讲 线性代数 第四讲 线性方程组
新形势下的SaaS销售升级|ToB大师课
rsync远程同步
Are you still paying for your thesis? Come and join me
如何添加 logs来debug ANR 问题
522. 最长特殊序列 II(贪心&双指针)









