¸´ÏÖ | Metasploit5+NgrokʵÏÖÔ¶³ÌʹÓÃWinRAR´úÂëÖ´ÐÐÎó²î
Ðû²¼Ê±¼ä 2019-03-141¡¢ÇéÐδ
°Ð»ú£ºWin7/192.168.0.100
¹¥»÷»ú£ºKali 2019.1°æ±¾/192.168.0.103
Ê×ÏÈÏÂÔØÎó²îʹÓþ籾
https://github.com/WyAtu/CVE-2018-20250
Ãâ·ÑµÄͨµÀ½ÏÁ¿¿¨£¬Ò»Ö±ÔÚÌí¼Ó£¬¶Ë¿ÚÒ»Ö±±»Õ¼Óã¬ÒÔÊÇ»¨ÁË10¸ö´óÑó¿ªÁËÒ»¸öËíµÀ£º
È»ºóÏÂÔØNgorkµÄ64λ°æ±¾¿Í»§¶Ëµ½ÍâµØ£¬¿ªÆôËíµÀ
./sunny clinetid ÄãµÄËíµÀid
È»ºóʹÓÃMetasploitÌìÉúÃâɱģ¿é¡£ÕâÀï
È»ºó½«ÉÏÊöÌìÉúµÄexeÎļþ¸´ÖƵ½wwwĿ¼Ï£º
ÔÚÎïÀíÇéÐÎÏ»á¼ûkaliµÄweb·þÎñ£º
Õâ¸öʱ¼äÏÂÔØexeÎļþµ½Ö®Ç°ÏÂÔØµÄEXPÎļþ¼ÐĿ¼Ï»òÕßÖ±½Ó¸´ÖÆÒÑÍù£º
ÐÞ¸Äexp.pyÖеÄrar_filenameºÍevil_filenameÒÔ¼°Å²ÓÃacefile.pyµÄÃûÏÂÁî²ÎÊýÖµ:
È»ºóÔËÐо籾£¬ÌìÉú¶ñÒâѹËõÎļþ£º
ÕâÀïÒª×¢ÖØÒ»Ï£¬ÒªÊǾ籾ÔËÐв»Àֳɱ¨´í£¬¿ÉÒÔʵÑ齫Python¸üе½×îеÄ3.7µÄС°æ±¾¡£
½«Ñ¹Ëõ°ü¸´ÖƵ½www¸ùĿ¼ÏÂ
ÔÚwin7Ï·¿ªä¯ÀÀÆ÷ÏÂÔØÑ¹Ëõ°üÎļþ£º
½âѹÎļþ£º
ÔÚϵͳÆô¶¯Ä¿Â¼ÏÂÓÐÌìÉúµÄ¶ñÒâ³ÌÐò£º
´Ëʱ£¬ÎÒÃÇÔÚkaliÏ¿ªÆômsfµÄ¼àÌýģʽ£¬ÓÃÀ´¼àÌýÈëÕ¾ÅþÁ¬£º
ÖØÆôWin7,ÔÚkaliÖÐÆÚ´ýÉÏÏߣº
½øÈëshellÖм´¿É²Ù×÷win7£º
һ̨È⼦¾ÍÉÏÏßÁË£¬µ½ÕâÀï¸÷ÈË¿ÉÒÔ¸ÐÊܵ½ÕâÒ»Îó²îÓкεȿֲÀ£¡£¡£¡
1. Éý¼¶µ½5.70.2.0°æ±¾
2. ɾ³ýÆä×°ÖÃĿ¼ÏµÄUNACEV2.dllÎļþ
4¡¢ ²Î¿¼
https://www.freebuf.com/articles/network/197025.html
https://github.com/WyAtu/CVE-2018-20250


¾©¹«Íø°²±¸11010802024551ºÅ