当前位置:网站首页>内网渗透之内网信息收集(四)
内网渗透之内网信息收集(四)
2022-07-06 09:23:00 【不知名白帽】
目录
Metasploit内网信息收集
攻击机 kali 192.168.0.103
靶机 win7 192.168.0.105
09scraper
run scraper(将目标机器上的常见信息收集起来然后下载保存在本地)
/root/.msf4/logs/scripts/scraper
09winenum
run winenum(收集一些当前系统,用户组相关的信息)
/root/.msf4/logs/scripts/winenum
10msf主机发现
模块位于源码路径的modules/auxiliary/scanner/discovery/
主要有:
arp_sweep
ipv6_mulitcast_ping
ipv6_neighbor
ipv6_neighbor_router_advertisement
udp_probe
udp_sweep
11msf端口扫描
msf> search portscan
auxiliary/scanner/portscan/ack //通过ACK扫描的方式对防火墙上未被屏蔽的端口进行探测
auxiliary/scanner/portscan/ftpbounce //通过FTP bounce攻击的原理对TCP服务进行枚举,一些新的软件能很好的防范此攻击,但在旧的系统上仍可以被利用
auxiliary/scanner/portscan/syn //使用发送TCP SYN标志的方式探测开放端口
auxiliary/scanner/portscan/tcp //通过一次完整的TCP连接来判断端口是否开放,最准确但是最慢
auxiliary/scanner/portscan/xmas //一种更为隐秘的扫描方式,通过发送FIN·PSH·URG标志,能够躲避一些高级的TCP标记检测器的过滤
一般情况下推荐使用syn端口扫描器·速度较快·结果准确·不容易被对方察觉
syn扫描器的使用
use auxiliary/scanner/portscan/syn
set rhosts 192.168.0.105/24
set threads 20
exploit
12服务扫描与查点
确定开放端口后,对相应端口上所运行的服务信息进行挖掘
在Metasploit的Scanner辅助模块中,用于服务扫描和查点的工具常以[service_name]_version和[service_name]_login命名
[service_name]_version 可用于遍历网络中包含了某种服务的主机,并进一步确定服务的版本
[service_name]_login 可对某种服务进行口令探测攻击
在msf终端中可以输入
search name:_version
查看所有可用的服务查点模块
边栏推荐
- Hackmyvm target series (2) -warrior
- 撲克牌遊戲程序——人機對抗
- Renforcer les dossiers de base de l'apprentissage
- Interpretation of iterator related "itertools" module usage
- 7-14 error ticket (PTA program design)
- 简述xhr -xhr的基本使用
- 3. Input and output functions (printf, scanf, getchar and putchar)
- 1. First knowledge of C language (1)
- C language file operation
- Strengthen basic learning records
猜你喜欢
canvas基础2 - arc - 画弧线
网络层—简单的arp断网
Attack and defense world misc practice area (simplerar, base64stego, no matter how high your Kung Fu is, you are afraid of kitchen knives)
强化学习基础记录
Strengthen basic learning records
"Gold, silver and four" job hopping needs to be cautious. Can an article solve the interview?
3. Input and output functions (printf, scanf, getchar and putchar)
. Net6: develop modern 3D industrial software based on WPF (2)
The difference between cookies and sessions
附加简化版示例数据库到SqlServer数据库实例中
随机推荐
Force deduction 152 question multiplier maximum subarray
记一次猫舍由外到内的渗透撞库操作提取-flag
【VMware异常问题】问题分析&解决办法
HackMyvm靶机系列(5)-warez
小程序web抓包-fiddler
Xray and Burp linked Mining
Using qcommonstyle to draw custom form parts
[three paradigms of database] you can understand it at a glance
Callback function ----------- callback
Which is more advantageous in short-term or long-term spot gold investment?
渗透测试学习与实战阶段分析
Programme de jeu de cartes - confrontation homme - machine
实验六 继承和多态
Simply understand the promise of ES6
Strengthen basic learning records
[MySQL table structure and integrity constraint modification (Alter)]
Experiment 8 exception handling
. How to upload XMIND files to Jinshan document sharing online editing?
记一次,修改密码逻辑漏洞实战
canvas基础2 - arc - 画弧线