远程下载文件
1 | linux: |
提权
后渗透模块:POST
漏洞探测:
应用漏洞{版本漏洞,应用本身的缺陷….}
服务漏洞{基于端口、基于系统服务…}
系统内核漏洞{提权,cve-2018-8120}
后渗透模块:
show post 查看post模块
run windows/manage/killav 关闭杀软
windows/manage/enable_rdp 开放3389,(需要特权)
….
提权:
uac提权: user account control 用户账户控制
exploit/windows/local/ask
参数:name,session
bypassuac:
exploit/windows/local/bypassuac_eventvwr
exploit/windows/local/bypassuac_comhijack
exploit/windows/local/bypassuac_injection
exploit/windows/local/bypassuac_windows_store_filesys
本地提权漏洞:
cve-2018-8120:exploit/windows/local/ms18_8120_win32k_privesc