¸´ÏÖ | Metasploit5+NgrokʵÏÖÔ¶³ÌÀûÓÃWinRAR´úÂëÖ´Ðзì϶

°ä²¼¹¦·ò 2019-03-14
½üÈÕ £¬¿´µ½FreebufÉÏÓÐÎÄÕ½²µ½ÀûÓÃWinRARǰ¼¸ÌìÆØ¹âµÄ¸ßΣ·ì϶ £¬½áºÏMetasploitºÍngrok¹¤¾ßʵÏÖÄÚÍøÉøÈëת·¢µÄÀûÓ᣽ñÌìÎÒÃÇÀ´ÊµÏÖ¸´ÏÖÒ»²¨¹ý³Ì¡£


 1¡¢»·¾³´î½¨ 


°Ð»ú£ºWin7/192.168.0.100
¹¥»÷»ú£ºKali 2019.1°æ±¾/192.168.0.103



2¡¢·ì϶¸´ÏÖ 


Ê×ÏÈÏÂÔØ·ì϶ÀûÓþ籾
https://github.com/WyAtu/CVE-2018-20250

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



´ò¿ªÍøÕ¾https://www.ngrok.cc¿ªÃ÷Ëí· £¬Ã»ÓÐÕ˺ŵϰע²áÒ»¸ö¼´¿É¡ £¿ªÃ÷Ò»¸öÃâ·ÑµÄËí·ת·¢´úÀí £¬°ÑngrokËí·ºÍ̸ÉèÖóÉTCP £¬ÄÚÍøIP¸Ä³ÉÄã×Ô¼ºµÄKaliLinuxµÄÄÚÍøIP £¬ÄÚÍø¶Ë±êÓïËÁÒâÌîд²»Ã¬¶Ü¼´¿É£º

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

Ãâ·ÑµÄͨ·±ÈÁ¦¿¨ £¬Ò»ÏòÔÚÔö³¤ £¬¶Ë¿ÚÒ»Ïò±»Õ¼Óà £¬ËùÒÔ»¨ÁË10¸ö´óÑó¿ªÁËÒ»¸öËí·£º

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

¶øºóÏÂÔØNgorkµÄ64λ°æ±¾¿Í»§¶Ëµ½±¾µØ £¬¿ªÆôËí·
./sunny clinetid ÄãµÄËí·id

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

¶øºóʹÓÃMetasploitÌìÉúÃâɱÄ £¿é¡£ÕâÀï

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

¶øºó½«ÉÏÊöÌìÉúµÄexeÎļþ¸´Ôìµ½wwwĿ¼Ï£º

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

ÔÚÎïÀí»·¾³Ï½ӼûkaliµÄweb·þÎñ£º


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

Õâ¸öʱ³½ÏÂÔØexeÎļþµ½Ö®Ç°ÏÂÔØµÄEXPÎļþ¼ÐĿ¼Ï»òÕßÖ±½Ó¸´Ôì´Óǰ£º

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

Åú¸Äexp.pyÖеÄrar_filenameºÍevil_filenameÒÔ¼°Å²ÓÃacefile.pyµÄÃûºÅÁî²ÎÊýÖµ:

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

¶øºóÔËÐо籾 £¬ÌìÉú¶ñÒâѹËõÎļþ£º

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

ÕâÀïÒª°ÑÎÈһϠ£¬ÒªÊǾ籾ÔËÐв»³É¹¦±¨´í £¬Äܹ»³¢ÊÔ½«Python¸üе½×îеÄ3.7µÄÓ×°æ±¾¡£
½«Ñ¹Ëõ°ü¸´Ôìµ½www¸ùĿ¼ÏÂ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

ÔÚwin7Ï´ò¿ªä¯ÀÀÆ÷ÏÂÔØÑ¹Ëõ°üÎļþ£º

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾
 


½âѹÎļþ£º


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

ÔÚϵͳÆô¶¯Ä¿Â¼ÏÂÓÐÌìÉúµÄ¶ñÒⷨʽ£º

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

´Ëʱ £¬ÎÒÃÇÔÚkaliÏ¿ªÆômsfµÄ¼àÌýģʽ £¬ÓÃÀ´¼àÌýÈëÕ¾Ïνӣº

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


³ÁÆôWin7,ÔÚkaliÖÐÆÚ´ýÉÏÏߣº


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

½øÈëshellÖм´¿É²Ù×÷win7£º

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

һ̨È⼦¾ÍÉÏÏßÁË £¬µ½ÕâÀï¸÷ÈËÄܹ»¸Ð´¥µ½ÕâÒ»·ì϶Óжàô¿ÉÅ£¡£¡£¡



3¡¢·ì϶½¨¸´ 


1. Éý¼¶µ½5.70.2.0°æ±¾
2. ɾ³ýÆä×°ÖÃĿ¼ÏµÄUNACEV2.dllÎļþ
 

4¡¢ ²Î¿¼ 


https://www.freebuf.com/articles/network/197025.html
https://github.com/WyAtu/CVE-2018-20250