¸´ÏÖ | Metasploit5+NgrokʵÏÖÔ¶³ÌÀûÓÃWinRAR´úÂëÖ´Ðзì϶
°ä²¼¹¦·ò 2019-03-141¡¢»·¾³´î½¨
°Ð»ú£ºWin7/192.168.0.100
¹¥»÷»ú£ºKali 2019.1°æ±¾/192.168.0.103
Ê×ÏÈÏÂÔØ·ì϶ÀûÓþ籾
https://github.com/WyAtu/CVE-2018-20250
Ãâ·ÑµÄͨ·±ÈÁ¦¿¨£¬Ò»ÏòÔÚÔö³¤£¬¶Ë¿ÚÒ»Ïò±»Õ¼Óã¬ËùÒÔ»¨ÁË10¸ö´óÑó¿ªÁËÒ»¸öËí·£º
¶øºóÏÂÔØNgorkµÄ64λ°æ±¾¿Í»§¶Ëµ½±¾µØ£¬¿ªÆôËí·
./sunny clinetid ÄãµÄËí·id
¶øºóʹÓÃMetasploitÌìÉúÃâɱģ¿é¡£ÕâÀï
¶øºó½«ÉÏÊöÌìÉúµÄexeÎļþ¸´Ôìµ½wwwĿ¼Ï£º
ÔÚÎïÀí»·¾³Ï½ӼûkaliµÄweb·þÎñ£º
Õâ¸öʱ³½ÏÂÔØexeÎļþµ½Ö®Ç°ÏÂÔØµÄEXPÎļþ¼ÐĿ¼Ï»òÕßÖ±½Ó¸´Ôì´Óǰ£º
Åú¸Äexp.pyÖеÄrar_filenameºÍevil_filenameÒÔ¼°Å²ÓÃacefile.pyµÄÃûºÅÁî²ÎÊýÖµ:
¶øºóÔËÐо籾£¬ÌìÉú¶ñÒâѹËõÎļþ£º
ÕâÀïÒª°ÑÎÈһϣ¬ÒªÊǾ籾ÔËÐв»³É¹¦±¨´í£¬Äܹ»³¢ÊÔ½«Python¸üе½×îеÄ3.7µÄÓ×°æ±¾¡£
½«Ñ¹Ëõ°ü¸´Ôìµ½www¸ùĿ¼ÏÂ
ÔÚwin7Ï´ò¿ªä¯ÀÀÆ÷ÏÂÔØÑ¹Ëõ°üÎļþ£º
½âѹÎļþ£º
ÔÚϵͳÆô¶¯Ä¿Â¼ÏÂÓÐÌìÉúµÄ¶ñÒⷨʽ£º
´Ëʱ£¬ÎÒÃÇÔÚkaliÏ¿ªÆômsfµÄ¼àÌýģʽ£¬ÓÃÀ´¼àÌýÈëÕ¾Ïνӣº
³ÁÆôWin7,ÔÚkaliÖÐÆÚ´ýÉÏÏߣº
½øÈëshellÖм´¿É²Ù×÷win7£º
һ̨È⼦¾ÍÉÏÏßÁË£¬µ½ÕâÀï¸÷ÈËÄܹ»¸Ð´¥µ½ÕâÒ»·ì϶Óжàô¿ÉÅ£¡£¡£¡
1. Éý¼¶µ½5.70.2.0°æ±¾
2. ɾ³ýÆä×°ÖÃĿ¼ÏµÄUNACEV2.dllÎļþ
4¡¢ ²Î¿¼
https://www.freebuf.com/articles/network/197025.html
https://github.com/WyAtu/CVE-2018-20250


¾©¹«Íø°²±¸11010802024551ºÅ