¸´ÏÖ | Metasploit5+NgrokʵÏÖÔ¶³ÌʹÓÃWinRAR´úÂëÖ´ÐÐÎó²î
Ðû²¼Ê±¼ä 2019-03-141¡¢ÇéÐδ
°Ð»ú£ºWin7/192.168.0.100
¹¥»÷»ú£ºKali 2019.1°æ±¾/192.168.0.103
Ê×ÏÈÏÂÔØÎó²îʹÓþ籾
https://github.com/WyAtu/CVE-2018-20250


Ãâ·ÑµÄͨµÀ½ÏÁ¿¿¨£¬Ò»Ö±ÔÚÌí¼Ó£¬¶Ë¿ÚÒ»Ö±±»Õ¼Óã¬ÒÔÊÇ»¨ÁË10¸ö´óÑó¿ªÁËÒ»¸öËíµÀ£º

È»ºóÏÂÔØNgorkµÄ64λ°æ±¾¿Í»§¶Ëµ½ÍâµØ£¬¿ªÆôËíµÀ
./sunny clinetid ÄãµÄËíµÀid

È»ºóʹÓÃMetasploitÌìÉúÃâɱģ¿é¡£ÕâÀï

È»ºó½«ÉÏÊöÌìÉúµÄexeÎļþ¸´ÖƵ½wwwĿ¼Ï£º

ÔÚÎïÀíÇéÐÎÏ»á¼ûkaliµÄweb·þÎñ£º

Õâ¸öʱ¼äÏÂÔØexeÎļþµ½Ö®Ç°ÏÂÔصÄEXPÎļþ¼ÐĿ¼Ï»òÕßÖ±½Ó¸´ÖÆÒÑÍù£º

ÐÞ¸Äexp.pyÖеÄrar_filenameºÍevil_filenameÒÔ¼°Å²ÓÃacefile.pyµÄÃûÏÂÁî²ÎÊýÖµ:

È»ºóÔËÐо籾£¬ÌìÉú¶ñÒâѹËõÎļþ£º

ÕâÀïҪעÖØһϣ¬ÒªÊǾ籾ÔËÐв»Àֳɱ¨´í£¬¿ÉÒÔʵÑ齫Python¸üе½×îеÄ3.7µÄС°æ±¾¡£
½«Ñ¹Ëõ°ü¸´ÖƵ½www¸ùĿ¼ÏÂ

ÔÚwin7Ï·¿ªä¯ÀÀÆ÷ÏÂÔØѹËõ°üÎļþ£º

½âѹÎļþ£º

ÔÚϵͳÆô¶¯Ä¿Â¼ÏÂÓÐÌìÉúµÄ¶ñÒâ³ÌÐò£º

´Ëʱ£¬ÎÒÃÇÔÚkaliÏ¿ªÆômsfµÄ¼àÌýģʽ£¬ÓÃÀ´¼àÌýÈëÕ¾ÅþÁ¬£º


ÖØÆôWin7,ÔÚkaliÖÐÆÚ´ýÉÏÏߣº

½øÈëshellÖм´¿É²Ù×÷win7£º

һ̨È⼦¾ÍÉÏÏßÁË£¬µ½ÕâÀï¸÷ÈË¿ÉÒÔ¸ÐÊܵ½ÕâÒ»Îó²îÓкεȿֲÀ£¡£¡£¡
1. Éý¼¶µ½5.70.2.0°æ±¾
2. ɾ³ýÆä×°ÖÃĿ¼ÏµÄUNACEV2.dllÎļþ
4¡¢ ²Î¿¼
https://www.freebuf.com/articles/network/197025.html
https://github.com/WyAtu/CVE-2018-20250