¸´ÏÖ | Metasploit5+NgrokʵÏÖÔ¶³ÌʹÓÃWinRAR´úÂëÖ´ÐÐÎó²î

Ðû²¼Ê±¼ä 2019-03-14
¿ËÈÕ£¬ £¬£¬£¬£¬£¬£¬¿´µ½FreebufÉÏÓÐÎÄÕ½²µ½Ê¹ÓÃWinRARǰ¼¸ÌìÆØ¹âµÄ¸ßΣÎó²î£¬ £¬£¬£¬£¬£¬£¬Á¬ÏµMetasploitºÍngrok¹¤¾ßʵÏÖÄÚÍøÉøÍ¸×ª·¢µÄʹÓᣡ£¡£¡£¡£¡£¡£¡£½ñÌìÎÒÃÇÀ´ÊµÏÖ¸´ÏÖÒ»²¨Àú³Ì¡£¡£¡£¡£¡£¡£¡£¡£


 1¡¢ÇéÐδ 


°Ð»ú£ºWin7/192.168.0.100
¹¥»÷»ú£ºKali 2019.1°æ±¾/192.168.0.103



2¡¢Îó²î¸´ÏÖ 


Ê×ÏÈÏÂÔØÎó²îʹÓþ籾
https://github.com/WyAtu/CVE-2018-20250

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



·­¿ªÍøÕ¾https://www.ngrok.cc¿ªÍ¨ËíµÀ£¬ £¬£¬£¬£¬£¬£¬Ã»ÓÐÕ˺ŵϰע²áÒ»¸ö¼´¿É¡£¡£¡£¡£¡£¡£¡£¡£¿ £¿£¿£¿£¿£¿£¿£¿ªÍ¨Ò»¸öÃâ·ÑµÄËíµÀת·¢ÊðÀí£¬ £¬£¬£¬£¬£¬£¬°ÑngrokËíµÀЭÒéÉèÖóÉTCP£¬ £¬£¬£¬£¬£¬£¬ÄÚÍøIP¸Ä³ÉÄã×Ô¼ºµÄKaliLinuxµÄÄÚÍøIP£¬ £¬£¬£¬£¬£¬£¬ÄÚÍø¶Ë¿ÚºÅí§ÒâÌîд²»³åÍ»¼´¿É£º

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

Ãâ·ÑµÄͨµÀ½ÏÁ¿¿¨£¬ £¬£¬£¬£¬£¬£¬Ò»Ö±ÔÚÌí¼Ó£¬ £¬£¬£¬£¬£¬£¬¶Ë¿ÚÒ»Ö±±»Õ¼Ó㬠£¬£¬£¬£¬£¬£¬ÒÔÊÇ»¨ÁË10¸ö´óÑó¿ªÁËÒ»¸öËíµÀ£º

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

È»ºóÏÂÔØNgorkµÄ64λ°æ±¾¿Í»§¶Ëµ½ÍâµØ£¬ £¬£¬£¬£¬£¬£¬¿ªÆôËíµÀ
./sunny clinetid ÄãµÄËíµÀid

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

È»ºóʹÓÃMetasploitÌìÉúÃâɱģ¿ £¿£¿£¿£¿£¿£¿£¿é¡£¡£¡£¡£¡£¡£¡£¡£ÕâÀï

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

È»ºó½«ÉÏÊöÌìÉúµÄexeÎļþ¸´ÖƵ½wwwĿ¼Ï£º

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

ÔÚÎïÀíÇéÐÎÏ»á¼ûkaliµÄwebЧÀÍ£º


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

Õâ¸öʱ¼äÏÂÔØexeÎļþµ½Ö®Ç°ÏÂÔØµÄEXPÎļþ¼ÐĿ¼Ï»òÕßÖ±½Ó¸´ÖÆÒÑÍù£º

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

ÐÞ¸Äexp.pyÖеÄrar_filenameºÍevil_filenameÒÔ¼°Å²ÓÃacefile.pyµÄÃûÏÂÁî²ÎÊýÖµ:

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

È»ºóÔËÐо籾£¬ £¬£¬£¬£¬£¬£¬ÌìÉú¶ñÒâѹËõÎļþ£º

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

ÕâÀïÒª×¢ÖØÒ»Ï£¬ £¬£¬£¬£¬£¬£¬ÒªÊǾ籾ÔËÐв»Àֳɱ¨´í£¬ £¬£¬£¬£¬£¬£¬¿ÉÒÔʵÑ齫Python¸üе½×îеÄ3.7µÄС°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£
½«Ñ¹Ëõ°ü¸´ÖƵ½www¸ùĿ¼ÏÂ

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

ÔÚwin7Ï·­¿ªä¯ÀÀÆ÷ÏÂÔØÑ¹Ëõ°üÎļþ£º

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾
 


½âѹÎļþ£º


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

ÔÚϵͳÆô¶¯Ä¿Â¼ÏÂÓÐÌìÉúµÄ¶ñÒâ³ÌÐò£º

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

´Ëʱ£¬ £¬£¬£¬£¬£¬£¬ÎÒÃÇÔÚkaliÏ¿ªÆômsfµÄ¼àÌýģʽ£¬ £¬£¬£¬£¬£¬£¬ÓÃÀ´¼àÌýÈëÕ¾ÅþÁ¬£º

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


ÖØÆôWin7,ÔÚkaliÖÐÆÚ´ýÉÏÏߣº


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

½øÈëshellÖм´¿É²Ù×÷win7£º

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

һ̨È⼦¾ÍÉÏÏßÁË£¬ £¬£¬£¬£¬£¬£¬µ½ÕâÀï¸÷ÈË¿ÉÒÔ¸ÐÊܵ½ÕâÒ»Îó²îÓкεȿֲÀ£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡



3¡¢Îó²îÐÞ¸´ 


1. Éý¼¶µ½5.70.2.0°æ±¾
2. ɾ³ýÆä×°ÖÃĿ¼ÏµÄUNACEV2.dllÎļþ
 

4¡¢ ²Î¿¼ 


https://www.freebuf.com/articles/network/197025.html
https://github.com/WyAtu/CVE-2018-20250