As soon as possible, I used IPC $ invading. By writing some gadgets

xiaoxiao2021-03-06  62

OpenTLS, modify the NTLM settings of Telnet, which can remotely log in to Jockey, service management, mainly to provide general operations for services, such as adding, deleting, etc. PS, process management, listing all processes, can also kill Process HTTP, HTTP operation tool, GET, and HeadeReventlog, log operation clearance tool Warder, scanning tool, if you forget your password, you can use this to come back, // Todo

This is some IPC $ security tools, giving those confused programmers for remote installation firewalls. Although IPC is far away, I just knew that there were IPC $ invading things, beginner development. Huh.

Cherub is assisting the management tool, which is to write this tool because I have a remote installation of the firewall, helpless, I have to write a tool to kill the firewall.

As for the scan password. Oh. Everyone is going to find it, I have not provided yet.

Basic ideas:

First, the target machine wants to open an account IPC $ (I don't want to use IPC $, but WMI SDK has no patience to download), generally use the scanning tool to get the administrator's password, and use Telnet to log in. So, if you can scan your administrator password , Huh, you are already a master, basically don't need this tool.

The default authentication method for Window's Telnet service is NTLM authentication. So you need to upload a tool to modify.

Thus, you should copy a share on the other party to copy the file and then start this program. Because some machines have only opened IPC $ sharing, they do not open the folder sharing, but you can access service management, so .. .. Hey. Just add a command to "Net Use Share Admin = C: / WinNT" to run again (although it will prompt 1503's error, but there is no matter). Because this command has already run .btw: Remember to clear these logs. Service startup errors will also be recorded.

This allows OpenTLs to be uploaded to the target machine. Of course, use COPY. If you have other methods, you can do it.

Then use Jockey to add a service, start, delete.

OK. Start Telnet service with Jockey. This allows you to log in with Telnet. You can then use the HTTP tool to download the file (or .... Test some website SQL injection ...: d), PS to manage the process (except System Can not kill, basically kill it), log to clear the log

I will listed basic methods. Good luck.

Declaration, if all the relevant responsibilities arising from this software, a summary is independent of this software and the author, I just hope that I will encounter the remote machine to install the firewall and forget the password, and I don't want to sit in the room. It can be easily maintained. The business trip is a very painful thing.

Add sharing: jockey //127.0.0.1 "User" "PWD" / install: "net" / param: "Share" / param: "TestDir = C: / Winnt" / auto first connects to each other's machine NET USE //// 127.0.0.1 "PWD" / user: "User" copies OpenTLS.exe to the target machine Copy OpenTLS.exe //127.0.0.1/testdir Delete the shared directory Jockey //127.0.0.1 "User" "PWD" / Install: "Net" / param: "Share" / param: "TestDir" / param: "/ d" / auto

Start OpenTLSJockey //127.0.0.1 "User" "PWD" / Install: "OpenTLS" / auto boot TelnetJockey //127.0.0.1 "User" "PWD" / service: "TLNTSVR" / Start

Telnet 127.0.0.1

For specific methods, please see the help of each program.

Although some friends remind me that if you scan your password, you can use your computer management -> Connect the remote computer. But I often like to use Telnet-> Telnet. So if you want to connect on the target machine When the third machine is, it is not easy to worry. And use the command line. Some people like the machine of others. Some people like to use the agent. I still like the machine of others, because my Internet speed is too slow. -_- # In addition, Jockey is very easy to use. Especially if I can delete some erroneous service, PS can kill the Apache boot error CGI process (Win2000 does not tell me: "Unable to complete the operation, refusal to access,", really depressed), HTTP can get an HTTP head. These tools are still very convenient to programmers.: P Download the address to my personal website to find: http://unixgod.zj.comup. God

转载请注明原文地址:https://www.9cbs.com/read-84272.html

New Post(0)