靶机:192.168.11.105
攻击机kail:192.168.11.106
1.在kali中启动setoolkit
setoolkit
2.利用SET构建钓鱼网站
1)选择1 Social-Engineering Attacks (社会工程学攻击)
data:image/s3,"s3://crabby-images/c93eb/c93eb6ca91d344728ede9aeee0cef70af607455f" alt=""
2)选择2 Website Attack Vectors (网站攻击流量)
data:image/s3,"s3://crabby-images/fe1ae/fe1ae00ad1acbf0d521df167df0c31061c632d7c" alt=""
3)选择3 Credential Harvester Attack Method (凭证收集攻击方法)
data:image/s3,"s3://crabby-images/8c35b/8c35bb707a13b0f440e9a0feb548fb707c42cdb0" alt=""
4) 选择1 Web Templates (网站模板)
data:image/s3,"s3://crabby-images/aeee1/aeee13ff5473a282a500ae022a83571dc43d8870" alt=""
5)输入攻击机ip,作为钓鱼网站(凭证收集器)的地址
data:image/s3,"s3://crabby-images/2cd42/2cd42ae75e2b8c1780394e8ff54b0321b7e48d8e" alt=""
6)选择2 Google 建立Google网站模板
data:image/s3,"s3://crabby-images/8199c/8199c8509ccd34f6e3c0e32a55a383a70bfe4129" alt=""
data:image/s3,"s3://crabby-images/83f94/83f9455f4b2fede94258c35e1cbc69e7ecffa8af" alt=""
3、利用靶机访问钓鱼网站,观察操作机能否收集到靶机的登录凭证
在靶机192.168.11.105上访问钓鱼网站:
http://192.168.11.106,输入用户名密码 并登录
data:image/s3,"s3://crabby-images/56fc0/56fc06a90a70225edbcf5df8da288c8d1d654057" alt=""
data:image/s3,"s3://crabby-images/895f0/895f0280c10fcdf9f5fbda4640b7037e87f10d31" alt=""
3.powershell注入攻击
1、生成PowerShell脚本,默认放在
/root/.set/reports/powershell/路径下,我们复制里面的内容
data:image/s3,"s3://crabby-images/fdc83/fdc8300ac6ae9fa07f3f2653bfe95a880e917bcf" alt=""
生成的注入文件:
data:image/s3,"s3://crabby-images/fd9c9/fd9c954b83c28279b3e8bed0cab48e6c9748ffa0" alt=""
2、通过各种途径,在靶机105上面执行PowerShell脚本里的内容-ShellCode代码
通过http协议发送powershell文件,用python打开一个http服务器:
python -m http.server 80008
data:image/s3,"s3://crabby-images/2a18b/2a18bd791ffedeb77d3d1ec173873cd3fa614d1c" alt=""
靶机105上,web访问
http://192.168.11.106:14472,下载powershell注入文件,复制其中内容,执行
data:image/s3,"s3://crabby-images/5fd0e/5fd0ead81f6734b9f3bd08c9350a0dec5f4775a4" alt=""
3、回到Kali,会发现出现了一个会话,使用 sessions -i 查询,上线成功!
data:image/s3,"s3://crabby-images/2d933/2d9337e314985350f999069f1bdcf752bc3db3da" alt=""