{"id":267,"date":"2022-07-10T16:39:35","date_gmt":"2022-07-10T08:39:35","guid":{"rendered":"http:\/\/www.aqwu.net\/wp\/?p=267"},"modified":"2022-07-10T16:39:35","modified_gmt":"2022-07-10T08:39:35","slug":"metasploit-%e5%9f%ba%e7%a1%80%e7%9f%a5%e8%af%86%ef%bc%8c%e7%ac%ac-5-%e9%83%a8%e5%88%86%ef%bc%9a%e4%bd%bf%e7%94%a8metasploit%e8%bf%9b%e8%a1%8c%e4%be%a6%e5%af%9f%ef%bc%88nmap%e3%80%81eternalblue","status":"publish","type":"post","link":"https:\/\/www.aqwu.net\/wp\/?p=267","title":{"rendered":"Metasploit \u57fa\u7840\u77e5\u8bc6\uff0c\u7b2c 5 \u90e8\u5206\uff1a\u4f7f\u7528Metasploit\u8fdb\u884c\u4fa6\u5bdf\uff08nmap\u3001EternalBlue\u3001SCADA\u548cMS SQL\uff09"},"content":{"rendered":"\n<p>\u539f\u6587\u94fe\u63a5\uff1a<a href=\"https:\/\/www.hackers-arise.com\/post\/2017\/04\/10\/Metasploit-Basics-Part-5-Using-Metasploit-for-Reconnaissance\">Metasploit Basics, Part 5: Using Metasploit for Reconnaissance (nmap, EternalBlue, SCADA, and MS SQL (hackers-arise.com)<\/a><\/p>\n\n\n\n<p id=\"viewer-225gg\">\u6b22\u8fce\u56de\u6765\uff0c\u6211\u7684\u65b0\u624b\u9ed1\u5ba2\uff01<\/p>\n\n\n\n<p id=\"viewer-2cnkg\">\u5982\u60a8\u6240\u77e5\uff0c\u4fa6\u5bdf\u662f\u9ed1\u5ba2\/\u6e17\u900f\u6d4b\u8bd5\u4eba\u5458\u5de5\u4f5c\u7684\u91cd\u8981\u7ec4\u6210\u90e8\u5206\u3002\u5982\u679c\u6ca1\u6709\u826f\u597d\u7684\u4fa6\u5bdf\uff0c\u4f60\u6240\u6709\u7684\u5de5\u4f5c\u548c\u52aa\u529b\u5f88\u53ef\u80fd\u90fd\u767d\u8d39\u3002\u968f\u7740Metasploit\u4ece\u4e25\u683c\u7684\u5f00\u53d1\u6846\u67b6\u53d1\u5c55\u6210\u4e3a\u591a\u65b9\u9762\u7684\u6e17\u900f\u6d4b\u8bd5\u5de5\u5177\uff0c\u5b83\u589e\u52a0\u4e86\u989d\u5916\u7684\u529f\u80fd\uff0c\u5305\u62ec\u4fa6\u5bdf\u3002\u60a8\u4e0d\u518d\u9700\u8981\u643a\u5e26\u5355\u72ec\u7684\u5de5\u5177\u8fdb\u884c\u4fa6\u5bdf\u548c\u5229\u7528\u3002Metasploit\u53ef\u4ee5\u505a\u5230\u8fd9\u4e00\u5207\u3002<\/p>\n\n\n\n<p id=\"viewer-1030h\">\u6b64\u5916\uff0c\u901a\u8fc7\u5c06<a href=\"http:\/\/www.hackers-arise.com\/single-post\/2017\/03\/29\/Metasploit-Basics-Part-4-Connecting-and-Using-the-postgresql-Database-with-Metasploit\" target=\"_blank\" rel=\"noreferrer noopener\">postgresql\u6570\u636e\u5e93\u9644\u52a0\u5230Metasploit<\/a>\uff0c\u6211\u4eec\u53ef\u4ee5\u5c06\u7aef\u53e3\u626b\u63cf\u548c\u6f0f\u6d1e\u626b\u63cf\u7684\u7ed3\u679c\u4fdd\u5b58\u5230\u6570\u636e\u5e93\u4e2d\uff0c\u7136\u540e\u5728\u6e17\u900f\u6d4b\u8bd5\u7684\u4e0b\u4e00\u9636\u6bb5\u4f7f\u7528\u8fd9\u4e9b\u7ed3\u679c\u3002<\/p>\n\n\n\n<p id=\"viewer-edpkd\"><strong>\u6b65\u9aa4#1 \u542f\u52a8<strong>Metasploit<\/strong><\/strong><\/p>\n\n\n\n<p id=\"viewer-9cm29\">\u5f53\u7136\uff0c\u7b2c\u4e00\u6b65\u662f\u542f\u52a8Kali\u5e76\u542f\u52a8msfconsole\u3002<\/p>\n\n\n\n<p id=\"viewer-sk4g\"><strong>kali>msf<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_900e80b105e34da3a34e5e5c5c4e3afb~mv2.png\/v1\/fill\/w_869,h_368,al_c,lg_1,q_90\/6a4a49_900e80b105e34da3a34e5e5c5c4e3afb~mv2.webp\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-aue36\"><strong>\u6b65\u9aa4 #2 nmap \u548cdb_nmap<\/strong><\/p>\n\n\n\n<p id=\"viewer-2mt1b\">\u901a\u5e38\uff0c\u5728\u5f00\u59cb\u9ed1\u5ba2\u653b\u51fb\u4e4b\u524d\uff0c\u6211\u4eec\u5e0c\u671b\u5c3d\u53ef\u80fd\u591a\u5730\u6536\u96c6\u6709\u5173\u76ee\u6807\u7684\u4fe1\u606f\u3002\u8ba9\u6211\u4eec\u9996\u5148\u627e\u51fa\u54ea\u4e9b\u7aef\u53e3\u662f\u5f00\u653e\u7684\u3002Metasploit\u4f7f\u6211\u4eec\u80fd\u591f\u76f4\u63a5\u4ecemsf\u63d0\u793a\u7b26\u8fd0\u884c<a href=\"https:\/\/www.hackers-arise.com\/nmap-for-recon-and-dos\" target=\"_blank\" rel=\"noreferrer noopener\">nmap<\/a>\u3002\u8ba9\u6211\u4eec\u5c1d\u8bd5\u4f7f\u7528 TCP \u626b\u63cf \uff08-sT\uff09 \u626b\u63cf\u5c40\u57df\u7f51\u4e0a\u7684\u7cfb\u7edf\uff0c\u5bfb\u627e 1 \u5230 1000 \uff08-p1-1000\uff09 \u4e4b\u95f4\u7684\u5f00\u653e\u7aef\u53e3\u3002<\/p>\n\n\n\n<p id=\"viewer-1c8c5\"><strong>msf > nmap -sT 192.168.181.0\/24 -p1-1000<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_c57e776c7d0d41f2b59f4a0c764b55c4~mv2.png\/v1\/fill\/w_874,h_511,al_c,lg_1,q_90\/6a4a49_c57e776c7d0d41f2b59f4a0c764b55c4~mv2.webp\" alt=\"\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_75070aa43f644a75ac9eb39321006b0e~mv2.png\/v1\/fill\/w_870,h_526,al_c,lg_1,q_90\/6a4a49_75070aa43f644a75ac9eb39321006b0e~mv2.webp\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-59lch\">\u5982\u4e0a\u6240\u793a\uff0cnmap \u80fd\u591f\u626b\u63cf\u6211\u4eec\u5185\u90e8\u7f51\u7edc\u4e0a\u7684\u6240\u6709\u8ba1\u7b97\u673a\uff0c\u5e76\u8fd4\u56de\u5f00\u653e\u7aef\u53e3\u7684\u7ed3\u679c\u3002<\/p>\n\n\n\n<p id=\"viewer-9fhd1\">\u6b63\u5982\u6211\u5728<a href=\"http:\/\/www.hackers-arise.com\/single-post\/2017\/03\/29\/Metasploit-Basics-Part-4-Connecting-and-Using-the-postgresql-Database-with-Metasploit\" target=\"_blank\" rel=\"noreferrer noopener\"> Metasploit Basic \u7b2c 4 \u90e8\u5206\u4e2d<\/a>\u6f14\u793a\u7684\u90a3\u6837\uff0c\u60a8\u8fd8\u53ef\u4ee5\u4f7f\u7528 <strong>db-nmap<\/strong> \u547d\u4ee4\u626b\u63cf\u7ed3\u679c\u5e76\u5c06\u5176\u4fdd\u5b58\u5230 Metasploit \u7684 postgresql \u9644\u52a0\u6570\u636e\u5e93\u4e2d\u3002\u8fd9\u6837\uff0c\u60a8\u53ef\u4ee5\u5728\u4ee5\u540e\u7684\u5229\u7528\u9636\u6bb5\u4f7f\u7528\u8fd9\u4e9b\u7ed3\u679c\u3002<\/p>\n\n\n\n<p id=\"viewer-1si8j\">\u8ba9\u6211\u4eec\u7528db_nmap\u626b\u63cf\u6211\u4eec\u7684\u76ee\u6807\u3002<\/p>\n\n\n\n<p id=\"viewer-fijh5\"><strong>msf &gt; db_nmap 192.168.181.0\/24<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_8d34c28f565e4de9b490a2351e1a5104~mv2.png\/v1\/fill\/w_938,h_512,al_c,lg_1,q_90\/6a4a49_8d34c28f565e4de9b490a2351e1a5104~mv2.webp\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-bnfvo\">\u6b63\u5982\u6211\u4eec\u5728\u4e0a\u9762\u770b\u5230\u7684\uff0cMetasploit\u4e2d\u7684nmap\u626b\u63cf\u7a0b\u5e8f\u80fd\u591f\u5bf9\u5b50\u7f51\u4e0a\u7684\u6bcf\u4e2a\u7cfb\u7edf\u8fdb\u884c\u7aef\u53e3\u626b\u63cf\uff0c\u627e\u5230\u5b83\u4eec\u7684\u5f00\u653e\u7aef\u53e3\u5e76\u5c06\u8be5\u4fe1\u606f\u5b58\u50a8\u5230\u6570\u636e\u5e93\u4e2d\u4ee5\u4f9b\u4ee5\u540e\u4f7f\u7528\u3002<\/p>\n\n\n\n<p id=\"viewer-6tllv\"><strong>\u6b65\u9aa4#3\uff1a\u626b\u63cf\u6a21\u5757<\/strong><\/p>\n\n\n\n<p id=\"viewer-4731u\">Metasploit\u5185\u7f6e\u4e86\u5927\u91cf\u626b\u63cf\u6a21\u5757\u3002\u5982\u679c\u6211\u4eec\u6253\u5f00\u53e6\u4e00\u4e2a\u7ec8\u7aef\uff0c\u6211\u4eec\u53ef\u4ee5\u5bfc\u822a\u5230Metasploit\u7684<strong> auxiliary \u6a21\u5757<\/strong>\u5e76\u5217\u51fa\u6240\u6709 <strong>scanner <\/strong>\u6a21\u5757\u3002<\/p>\n\n\n\n<p id=\"viewer-80s6a\"><strong>cd \/usr\/share\/metasploit-framework\/modules\/auxiliary<\/strong><\/p>\n\n\n\n<p id=\"viewer-6t48p\"><strong>kali > ls -l<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_2f82c433ca5c433ca20871fae834a5da~mv2.png\/v1\/fill\/w_936,h_484,al_c,lg_1,q_90\/6a4a49_2f82c433ca5c433ca20871fae834a5da~mv2.webp\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-1tjpc\">\u8bf7\u6ce8\u610f\uff0c\u5728\u4e0a\u9762\u7684\u5c4f\u5e55\u622a\u56fe\u4e2d\uff0c\u5305\u542b\u7528\u4e8e\u5404\u79cd\u8f85\u52a9\u76ee\u7684\u7684\u6a21\u5757\u7684\u4f17\u591a\u76ee\u5f55\u3002\u8ba9\u6211\u4eec\u5bfc\u822a\u5230 scanner \u76ee\u5f55\u5e76\u67e5\u770b\u5185\u90e8\u3002<\/p>\n\n\n\n<p id=\"viewer-4g6no\"><strong>kali> cd scanner<\/strong><\/p>\n\n\n\n<p id=\"viewer-76p9h\"><strong>kali > ls -l<\/strong><\/p>\n\n\n\n<p id=\"viewer-4tg9t\">\u5982\u4e0b\u56fe\u6240\u793a\uff0c\u6bcf\u4e2a\u626b\u63cf\u7a0b\u5e8f\u6a21\u5757\u90fd\u4f4d\u4e8e\u7279\u5b9a\u76ee\u6807\u7c7b\u578b\u7684\u76ee\u5f55\u4e2d\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_a2f87d57908e48d6870e9abcffd2575a~mv2.png\/v1\/fill\/w_787,h_509,al_c,q_90\/6a4a49_a2f87d57908e48d6870e9abcffd2575a~mv2.webp\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-6ukso\">\u4e8c\u5341\u591a\u5e74\u6765\uff0cSMB\u534f\u8bae\u5728\u6240\u6709\u64cd\u4f5c\u7cfb\u7edf\u4e0a\u90fd\u5b58\u5728\u95ee\u9898\u30022017\u5e74\uff0cShadowBrokers\u53d1\u5e03\u4e86\u4e00\u4e2a\u7a83\u53d6\u7684NSA\u6f0f\u6d1e\uff0c\u8be5\u6f0f\u6d1e\u653b\u51fb\u4e86SMB\u5e76\u8d4b\u4e88\u4e86\u653b\u51fb\u7cfb\u7edf\u7ba1\u7406\u5458\u6743\u9650\u3002\u8fd9\u4e2a\u6f0f\u6d1e\u5728\u5fae\u8f6f\u7684\u8bf4\u6cd5\u4e2d\u88ab\u79f0\u4e3aEternalBlue\u6216MS17-010\uff08\u6709\u5173<a href=\"http:\/\/www.hackers-arise.com\/single-post\/2018\/11\/30\/Network-Forensics-Part-2-Packet-Level-Analysis-of-the-EternalBlue-Exploit\" target=\"_blank\" rel=\"noreferrer noopener\">EternalBlue\u7684\u66f4\u591a\u4fe1\u606f\uff0c\u8bf7\u53c2\u9605\u6b64\u5904\u7684\u7f51\u7edc\u53d6\u8bc1\u6587\u7ae0<\/a>\uff09\u3002<\/p>\n\n\n\n<p id=\"viewer-3754n\">\u8981\u786e\u5b9a Windows 7\/Server 2008 \u7cfb\u7edf\u662f\u5426\u5bb9\u6613\u53d7\u5230\u6b64\u653b\u51fb\uff0cMetasploit \u4e2d\u6709\u4e00\u4e2a\u626b\u63cf\u7a0b\u5e8f\u53ef\u4ee5\u786e\u5b9a\u8fd9\u4e00\u70b9\u3002<\/p>\n\n\n\n<p id=\"viewer-7odc7\">\u5982\u679c\u6211\u4eec\u5bfc\u822a\u5230SMB\u5b50\u76ee\u5f55\u5e76\u5728\u5176\u4e0a\u8fdb\u884c\u957f\u5217\u8868\uff0c\u6211\u4eec\u4f1a\u770b\u5230\u4e00\u4e2a\u540d\u4e3a\u201csmb_ms17_010\u201d\u7684\u626b\u63cf\u4eea\u3002<\/p>\n\n\n\n<p id=\"viewer-5sv1\"><strong>kali > cd smb<\/strong><\/p>\n\n\n\n<p id=\"viewer-4ig7d\"><strong>kali > ls -l<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_63fde6c2f6ac4583896894b6015011a3~mv2.png\/v1\/fill\/w_943,h_396,al_c,lg_1,q_90\/6a4a49_63fde6c2f6ac4583896894b6015011a3~mv2.webp\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-ej1vh\">\u8ba9\u6211\u4eec\u5c06\u8be5\u626b\u63cf\u7a0b\u5e8f\u52a0\u8f7d\u5230\u6211\u4eec\u7684\u6846\u67b6\u4e2d\uff0c\u5e76\u5728Windows 7\u7cfb\u7edf\u4e0a\u8fd0\u884c\u5b83\u3002<\/p>\n\n\n\n<p id=\"viewer-as5qa\"><strong>msf5 ><strong>use auxiliary\/scanner\/smb\/smb_ms17_010<\/strong><\/strong><\/p>\n\n\n\n<p id=\"viewer-3pjor\"><strong>msf5 >set RHOSTS 192.168.1.102<\/strong><\/p>\n\n\n\n<p id=\"viewer-6evu\"><strong>msf5 >run<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_48e5aef8e21b47a1897505f3b1a5b140~mv2.png\/v1\/fill\/w_1291,h_198,al_c,lg_1,q_90\/6a4a49_48e5aef8e21b47a1897505f3b1a5b140~mv2.webp\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-6mgab\">\u5982\u4e0a\u6240\u793a\uff0c\u6b64\u626b\u63cf\u7a0b\u5e8f\u5c06\u63a2\u6d4b\u5668\u53d1\u9001\u5230\u76ee\u6807\u7cfb\u7edf\uff0c\u7136\u540e\u8fd4\u56de\u5e76\u62a5\u544a\u5b83\u53ef\u80fd\u5bb9\u6613\u53d7\u5230\u653b\u51fb\uff01\u6211\u4eec\u5c06\u5728 <a href=\"http:\/\/www.hackers-arise.com\/single-post\/2017\/06\/12\/Metasploit-Basics-Part-8-Exploitation-with-EternalBlue\" target=\"_blank\" rel=\"noreferrer noopener\">Metasploit Basics \u7cfb\u5217\u7684\u7b2c 8 \u90e8\u5206\u4e2d<\/a>\u5229\u7528\u8be5\u6f0f\u6d1e\u3002<\/p>\n\n\n\n<p id=\"viewer-4qa4n\">\u63a5\u4e0b\u6765\uff0c\u8ba9\u6211\u4eec\u8f6c\u5230<strong>scada<\/strong>\u76ee\u5f55\u5e76\u67e5\u770b\u5176\u4e2d\u7684\u5185\u90e8\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_f5bd45a7e7ca46ce86e3fcbc05a0e68e~mv2.png\/v1\/fill\/w_938,h_346,al_c,lg_1,q_90\/6a4a49_f5bd45a7e7ca46ce86e3fcbc05a0e68e~mv2.webp\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-d6g5s\">\u5982\u60a8\u6240\u89c1\uff0c\u670911\u4e2ascada\u626b\u63cf\u4eea\u6a21\u5757\u3002<\/p>\n\n\n\n<p id=\"viewer-9hr3n\"><strong>\u6b65\u9aa4#4\u8fdb\u884cSCADA\u626b\u63cf<\/strong><\/p>\n\n\n\n<p id=\"viewer-9a0o\">\u8ba9\u6211\u4eec\u5c1d\u8bd5\u4f7f\u7528\u5176\u4e2d\u4e00\u4e2ascada\u626b\u63cf\u4eea\u6a21\u5757\u5728SCADA\u7cfb\u7edf\u4e0a\u8fdb\u884c\u626b\u63cf\uff08\u6709\u5173SCADA\u9ed1\u5ba2\u7684\u66f4\u591a\u4fe1\u606f\uff0c\u8bf7\u53c2\u9605\u6211\u7684<a href=\"http:\/\/www.hackers-arise.com\/scada-hacking\" target=\"_blank\" rel=\"noreferrer noopener\">SCADA\u7cfb\u5217<\/a>\uff09\u3002<\/p>\n\n\n\n<p id=\"viewer-56m4r\"><strong>msf &gt; use auxiliary\/scanner\/scada\/modbusclient<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_945d3cd097964083a1e31b04ccb9c11e~mv2.png\/v1\/fill\/w_936,h_490,al_c,lg_1,q_90\/6a4a49_945d3cd097964083a1e31b04ccb9c11e~mv2.webp\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-4is3k\">\u6211\u4eec\u9700\u8981\u8bbe\u7f6eRHOST\uff0c\u5373\u8981\u8bfb\u53d6\u7684\u7ebf\u5708\u6570\u91cf\uff0c\u5e76READ_COIL\u53c2\u6570\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_0db3977335044cc38b14ebe10843d5a0~mv2.png\/v1\/fill\/w_937,h_486,al_c,lg_1,q_90\/6a4a49_0db3977335044cc38b14ebe10843d5a0~mv2.webp\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-r49a\">\u6b63\u5982\u60a8\u5728\u4e0a\u9762\u7684\u5c4f\u5e55\u622a\u56fe\u4e2d\u770b\u5230\u7684\uff0c\u6211\u4eec\u4f7f\u7528\u6b64scada\u626b\u63cf\u4eea\u8bfb\u53d6\u8fdc\u7a0bSCADA\u7cfb\u7edf\u4e0a\u7684\u7ebf\u5708\uff08\u7ebf\u5708\u662fSCADA\u8bbe\u65bd\u5185\u7684ON\/OFF\u5f00\u5173\uff09\u3002\u8fd9\u5c06\u662f\u5229\u7528\u6b64\u7cfb\u7edf\u4e4b\u524d\u7684\u7b2c\u4e00\u6b65\u3002<\/p>\n\n\n\n<p id=\"viewer-9gsn0\"><strong>\u6b65\u9aa4 #5 MS SQL \u767b\u5f55\u626b\u63cf<\/strong><\/p>\n\n\n\n<p id=\"viewer-101pc\">\u5728Metasploit\u4e2d\u7684\u4f17\u591a\u626b\u63cf\u4e2d\uff0c\u6709\u4e00\u4e2a\u53ef\u4ee5\u679a\u4e3eMicrosoft\u65d7\u8230\u6570\u636e\u5e93\u670d\u52a1\u5668SQL Server\u4e0a\u7684\u767b\u5f55\u540d\u3002<\/p>\n\n\n\n<p id=\"viewer-fa0ou\">\u6211\u4eec\u53ef\u4ee5\u901a\u8fc7\u952e\u5165\u6765\u4f7f\u7528\u6b64\u6a21\u5757;<\/p>\n\n\n\n<p id=\"viewer-9t81m\"><strong>msf &gt; use auxiliary\/admin\/mssql\/mssql_enum_sql_logins<\/strong><\/p>\n\n\n\n<p id=\"viewer-akqkd\">\u52a0\u8f7d\u6a21\u5757\u540e\uff0c\u6211\u4eec\u901a\u8fc7\u952e\u5165\u4fe1\u606f\u4e86\u89e3\u6709\u5173\u6b64\u626b\u63cf<strong>\u7684\u66f4\u591a\u4fe1\u606f\u3002<\/strong><\/p>\n\n\n\n<p id=\"viewer-ianf\"><strong>msf>info<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_64302757ef1c4b7895ed93f4fa6fc9c5~mv2.png\/v1\/fill\/w_937,h_500,al_c,lg_1,q_90\/6a4a49_64302757ef1c4b7895ed93f4fa6fc9c5~mv2.webp\" alt=\"\"\/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_cdef6eed9d0649b48b26e172575c347e~mv2.png\/v1\/fill\/w_785,h_460,al_c,q_90\/6a4a49_cdef6eed9d0649b48b26e172575c347e~mv2.webp\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-9d88o\">\u6b63\u5982\u60a8\u5728\u63cf\u8ff0\u4e2d\u770b\u5230\u7684\u90a3\u6837\uff0c\u6b64\u6a21\u5757\u53ef\u7528\u4e8e\u6a21\u7cca\u53ef\u7528\u7684SQL Server\u767b\u5f55\u540d\uff0c\u4e3a\u6211\u4eec\u63d0\u4f9b\u767b\u5f55\u540d\uff0c\u7136\u540e\u53ef\u4ee5\u4f7f\u7528\u8bb8\u591a\u4e0d\u540c\u7684\u5bc6\u7801\u7834\u89e3\u5de5\u5177\u4e4b\u4e00\u66b4\u529b\u7834\u89e3\u8fd9\u4e9b\u767b\u5f55\u540d\u3002<\/p>\n\n\n\n<p id=\"viewer-4grqe\">\u4e00\u65e6\u6211\u4eec\u5411\u5b83\u63d0\u4f9bRHOST\uff0c\u5b83\u5c31\u4f1a\u5f00\u59cb\u626b\u63cf\u6570\u636e\u5e93\u670d\u52a1\u5668\u4e0a\u7684\u53ef\u7528\u767b\u5f55\u540d\u3002<\/p>\n\n\n\n<p id=\"viewer-5oes4\"><strong>msf >set RHOST 192.168.181.129<\/strong><\/p>\n\n\n\n<p id=\"viewer-f9a96\"><strong>msf >exploit<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/static.wixstatic.com\/media\/6a4a49_d807189c480e4e8c9325c2c9fe3326a7~mv2.png\/v1\/fill\/w_942,h_332,al_c,lg_1,q_90\/6a4a49_d807189c480e4e8c9325c2c9fe3326a7~mv2.webp\" alt=\"\"\/><\/figure>\n\n\n\n<p id=\"viewer-7mnhb\">\u6b63\u5982\u60a8\u5728\u4e0a\u9762\u770b\u5230\u7684\uff0c\u6b64\u626b\u63cf\u7a0b\u5e8f\u80fd\u591f\u627e\u5230\u767b\u5f55\u201csa\u201d\u5e10\u6237\u6216\u6b64SQL Server\u5b89\u88c5\u7684\u7cfb\u7edf\u7ba1\u7406\u5458\uff01<\/p>\n\n\n\n<p id=\"viewer-1ndv6\"><strong>\u7ed3\u8bba<\/strong><\/p>\n\n\n\n<p id=\"viewer-5po34\">\u4fa6\u5bdf\u662f\u9ed1\u5ba2\/\u6e17\u900f\u6d4b\u8bd5\u8fc7\u7a0b\u7684\u5173\u952e\u9636\u6bb5\u3002Metasploit\u6dfb\u52a0\u4e86\u6570\u767e\u4e2a\u4fa6\u5bdf\u6a21\u5757\uff0c\u56e0\u6b64\u6211\u4eec\u53ef\u4ee5\u76f4\u63a5\u4eceMetasploit\u5b8c\u6210\u5927\u90e8\u5206\u4fa6\u5bdf\u3002\u5728\u8fd9\u91cc\uff0c\u6211\u53ea\u6f14\u793a\u4e86Metasploit\u4e2d\u7684\u51e0\u4e2a\u4fa6\u5bdf\u6a21\u5757\uff0c\u4f46\u5b9e\u9645\u4e0a\u8fd8\u6709\u6570\u767e\u4e2a\uff0c\u6240\u4ee5\u82b1\u4e00\u4e9b\u65f6\u95f4\u63a2\u7d22Metasploit\u4e2d\u7684\u8bb8\u591a\u4fa6\u5bdf\u6a21\u5757\uff0c\u5b83\u53ef\u80fd\u4f1a\u5728\u4f60\u7684\u9ed1\u5ba2\/\u6e17\u900f\u6d4b\u8bd5\u4e2d\u4e3a\u4f60\u8282\u7701\u6570\u767e\u4e2a\u5c0f\u65f6\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u539f\u6587\u94fe\u63a5\uff1aMetasploit Basics, Part 5: Using Metasploit for Re [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[82,43],"tags":[81],"class_list":["post-267","post","type-post","status-publish","format-standard","hentry","category-metasploit","category-infoarticle","tag-metasploit"],"views":2094,"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts\/267","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=267"}],"version-history":[{"count":1,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts\/267\/revisions"}],"predecessor-version":[{"id":268,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts\/267\/revisions\/268"}],"wp:attachment":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=267"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=267"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=267"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}