¸´ÏÖ | Metasploit5+NgrokʵÏÖÔ¶³ÌÀûÓÃWinRAR´úÂëÖ´ÐЩ¶´

Ðû²¼Ê±¼ä 2019-03-14
½üÈÕ£¬¿´µ½FreebufÉÏÓÐÎÄÕ½²µ½ÀûÓÃWinRARÇ°¼¸ÌìÆعâµÄ¸ßΣ©¶´£¬½áºÏMetasploitºÍngrok¹¤¾ßʵÏÖÄÚÍøÉø͸ת·¢µÄÀûÓ᣽ñÌìÎÒÃÇÀ´ÊµÏÖ¸´ÏÖÒ»²¨¹ý³Ì¡£


 1¡¢»·¾³´î½¨ 


°Ð»ú£ºWin7/192.168.0.100
¹¥»÷»ú£ºKali 2019.1°æ±¾/192.168.0.103



2¡¢Â©¶´¸´ÏÖ 


Ê×ÏÈÏÂÔØ©¶´ÀûÓýű¾
https://github.com/WyAtu/CVE-2018-20250

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



´ò¿ªÍøÕ¾https://www.ngrok.cc¿ªÍ¨ËíµÀ£¬Ã»ÓÐÕ˺ŵĻ°×¢²áÒ»¸ö¼´¿É¡£¿ªÍ¨Ò»¸öÃâ·ÑµÄËíµÀת·¢ÊðÀí£¬°ÑngrokËíµÀЭÒéÉèÖóÉTCP£¬ÄÚÍøIP¸Ä³ÉÄã×Ô¼ºµÄKaliLinuxµÄÄÚÍøIP£¬ÄÚÍø¶Ë¿ÚºÅÈÎÒâÌîд²»³åÍ»¼´¿É£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Ãâ·ÑµÄͨµÀ±ÈÁ¦¿¨£¬Ò»Ö±ÔÚÌí¼Ó£¬¶Ë¿ÚÒ»Ö±±»Õ¼Óã¬ËùÒÔ»¨ÁË10¸ö´óÑó¿ªÁËÒ»¸öËíµÀ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

È»ºóÏÂÔØNgorkµÄ64λ°æ±¾¿Í»§¶Ëµ½µ±µØ£¬¿ªÆôËíµÀ
./sunny clinetid ÄãµÄËíµÀid

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

È»ºóʹÓÃMetasploitÉú³ÉÃâɱÄ£¿é¡£ÕâÀï

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

È»ºó½«ÉÏÊöÉú³ÉµÄexeÎļþ¸´ÖƵ½wwwĿ¼Ï£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÔÚÎïÀí»·¾³Ï·ÃÎÊkaliµÄweb·þÎñ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Õâ¸öʱºòÏÂÔØexeÎļþµ½Ö®Ç°ÏÂÔصÄEXPÎļþ¼ÐĿ¼Ï»òÕßÖ±½Ó¸´ÖƹýÈ¥£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÐÞ¸Äexp.pyÖеÄrar_filenameºÍevil_filenameÒÔ¼°µ÷ÓÃacefile.pyµÄÃûÃüÁî²ÎÊýÖµ:

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

È»ºóÔËÐнű¾£¬Éú³É¶ñÒâѹËõÎļþ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÕâÀïҪעÒâһϣ¬ÒªÊǽű¾ÔËÐв»Àֳɱ¨´í£¬¿ÉÒÔʵÑ齫Python¸üе½×îеÄ3.7µÄС°æ±¾¡£
½«Ñ¹Ëõ°ü¸´ÖƵ½www¸ùĿ¼ÏÂ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÔÚwin7Ï´ò¿ªä¯ÀÀÆ÷ÏÂÔØѹËõ°üÎļþ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾
 


½âѹÎļþ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÔÚϵͳÆô¶¯Ä¿Â¼ÏÂÓÐÉú³ÉµÄ¶ñÒⷨʽ£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

´Ëʱ£¬ÎÒÃÇÔÚkaliÏ¿ªÆômsfµÄ¼àÌýģʽ£¬ÓÃÀ´¼àÌýÈëÕ¾Á¬½Ó£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÖØÆôWin7,ÔÚkaliÖÐÆÚ´ýÉÏÏߣº


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

½øÈëshellÖм´¿É²Ù×÷win7£º

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

һ̨È⼦¾ÍÉÏÏßÁË£¬µ½ÕâÀï¸÷ÈË¿ÉÒÔ¸ÐÊܵ½Õâһ©¶´ÓкεȿÉÅ£¡£¡£¡



3¡¢Â©¶´ÐÞ¸´ 


1. Éý¼¶µ½5.70.2.0°æ±¾
2. ɾ³ýÆ䰲װĿ¼ÏµÄUNACEV2.dllÎļþ
 

4¡¢ ²Î¿¼ 


https://www.freebuf.com/articles/network/197025.html
https://github.com/WyAtu/CVE-2018-20250