{"id":3993,"date":"2024-03-29T01:26:42","date_gmt":"2024-03-28T17:26:42","guid":{"rendered":"http:\/\/www.ccwifi.cc\/blogs\/?p=3993"},"modified":"2024-03-29T01:26:42","modified_gmt":"2024-03-28T17:26:42","slug":"%e4%bd%bf%e7%94%a8powershell%e8%84%9a%e6%9c%ac%e6%89%a7%e8%a1%8c%e5%91%bd%e4%bb%a4%e5%b9%b6%e7%bb%954164","status":"publish","type":"post","link":"https:\/\/www.ccwifi.cc\/blogs\/2024\/03\/29\/%e4%bd%bf%e7%94%a8powershell%e8%84%9a%e6%9c%ac%e6%89%a7%e8%a1%8c%e5%91%bd%e4%bb%a4%e5%b9%b6%e7%bb%954164\/","title":{"rendered":"\u4f7f\u7528PowerShell\u811a\u672c\u6267\u884c\u547d\u4ee4\u5e76\u7ed5\u8fc7AppLocker;Ruby CVE"},"content":{"rendered":"<div>\n<p>\u5728\u7ebfwifi\u8dd1\u5305 \u91d1\u521a\u5305\u8dd1\u5305 cap\u8dd1\u5305 hccapx ewsa\u5728\u7ebf \u5c31\u6765 <strong><a href=\"https:\/\/ccwifi.cc\" target=\"_blank\" rel=\"noopener\">\u63e1\u624b\u5305\u8dd1\u5305<\/a><\/strong><\/p>\n<p>\u5404\u4f4d\u597d \u53c8\u89c1\u9762\u4e86 \u6211\u662f\u66f9\u64cd \u4eca\u5929\u7ed9\u5927\u5bb6\u5e26\u6765\u4e00\u7bc7\u65b0\u7684\u6559\u7a0b<\/p>\n<p>\u5e0c\u671b\u5404\u4f4d\u7ec6\u5fc3\u5b66\u4e60 \u4f4e\u8c03\u7528\u7f51<\/p>\n<\/div>\n<p><img decoding=\"async\" src=\"http:\/\/www.ccwifi.cc\/blogs\/wp-content\/uploads\/2024\/03\/1711646796176_0.jpg\" alt=\"hashcat\u4f7f\u7528\u547d\u4ee4\"><\/p>\n<p>\u59ff\u52bf 1.\u5728MACOS\u4e0a\u4f7f\u7528OSQUERY\u68c0\u6d4b\u53cd\u5411SHELL\u3002\u5927\u591a\u6570\u8fdb\u7a0b\u90fd\u8fde\u63a5\u5230TTY\uff0c\u800c\u6ca1\u6709\u8fd0\u884c\u7684\u8fdb\u7a0b\u53ef\u80fd\u503c\u5f97\u8fdb\u4e00\u6b65\u7814\u7a76\u3002\u901a\u8fc7\u5bf9\u8fdb\u7a0b\u8fd0\u884ctty\u67e5\u8be2\uff0c\u53ef\u4ee5\u53d1\u73b0\u53ef\u80fd\u5b58\u5728\u53cd\u5411shell\u3002\u53c2\u8003\u94fe\u63a5\uff1a<\/p>\n<pre style=\"font-size: inherit;color: inherit;line-height: inherit;margin-top: 0px;margin-bottom: 0px;padding: 0px\"><p style=\"line-height: 15px;font-size: 11px;letter-spacing: 0px;font-family: Consolas, Inconsolata, Courier, monospace;border-radius: 0px;padding: 0.5em;margin-left: 16px;margin-right: 16px;overflow: auto !important\"><span class=\"linenum hljs-number\" style=\"font-size: inherit;line-height: inherit;padding-right: 20px\">1<\/span>mshta.exe VBScript:Close(<span class=\"hljs-keyword\" style=\"font-size: inherit;line-height: inherit\">Execute<\/span>(<span class=\"hljs-string\" style=\"font-size: inherit;line-height: inherit\">\"Set S=CreateObject(\"\"WScript.Shell\"\"):If S.AppActivate(\"\"maybe-Run\"\")=False Then:S.Run(\"\"C:Windowssystem32Calc.exe\"\"):End If\"<\/span>))<br><\/p><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.ccwifi.cc\/blogs\/wp-content\/uploads\/2024\/03\/1711646796176_2.png\" alt=\"hashcat\u4f7f\u7528\u547d\u4ee4\"><\/p>\n<p>\u53c2\u8003\u94fe\u63a5\uff1a2.\u4f7f\u7528Outlook\u7684CreateObject\u8fdb\u884c\u6a2a\u5411\u79fb\u52a8\u3002\u5229\u7528Outlook\u7684CreateObject\u548cDotNetToJScript\uff0c\u5728Windows\u4e0b\u542f\u52a8Outlook\u5e76\u6267\u884cpayload\u3002 <\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.ccwifi.cc\/blogs\/wp-content\/uploads\/2024\/03\/1711646796176_3.jpg\" alt=\"hashcat\u4f7f\u7528\u547d\u4ee4\"><img decoding=\"async\" src=\"http:\/\/www.ccwifi.cc\/blogs\/wp-content\/uploads\/2024\/03\/1711646796176_4.jpg\" alt=\"hashcat\u4f7f\u7528\u547d\u4ee4\"><\/p>\n<p>\u53c2\u8003\u94fe\u63a5\uff1a3.\u5229\u7528mshta.exe\u6267\u884c\u7cfb\u7edf\u547d\u4ee4\u3002 <\/p>\n<p>\u53c2\u8003\u94fe\u63a5\uff1a4.Hash\u91cd\u653e\u3002\u901a\u8fc7\u8df3\u8fc7\u7834\u89e3\u54c8\u5e0c\u5e76\u8fdb\u884chash\u7684\u91cd\u653e\uff0c\u5229\u7528\u901a\u5e38\u914d\u7f6e\u9519\u8bef\u7684Windows\u73af\u5883\uff0c\u4e0d\u5b9e\u65bdSMB\u7b7e\u540d\uff0c\u8fdb\u884cSMB\u4e2d\u95f4\u4eba\u653b\u51fb\u3002\u53c2\u8003\u94fe\u63a5\uff1a<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.ccwifi.cc\/blogs\/wp-content\/uploads\/2024\/03\/1711646796176_5.jpg\" alt=\"hashcat\u4f7f\u7528\u547d\u4ee4\"><\/p>\n<p>\u53c2\u8003\u94fe\u63a5\uff1a5.\u9664\u4e86\u5728c:WINDOWSsystem32driversetchosts\u53ef\u4ee5\u67e5\u770bdns\u89e3\u91ca\u5916\uff0c\u8fd8\u53ef\u4ee5\u5728c:WINDOWSsystem32driversetchosts.ics\u8fdb\u884c\u67e5\u8be2\u3002<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.ccwifi.cc\/blogs\/wp-content\/uploads\/2024\/03\/1711646796176_6.jpg\" alt=\"hashcat\u4f7f\u7528\u547d\u4ee4\"><\/p>\n<p>\u53c2\u8003\u94fe\u63a5\uff1a6.\u5982\u4f55\u7f16\u8bd1\u3001\u5206\u6790\u548c\u8c03\u8bd5\u57fa\u4e8eMIPS\u67b6\u6784\u7684\u4e8c\u8fdb\u5236\u6587\u4ef6\u3002\u6f14\u793a\u4e86\u5982\u4f55\u5728x86\u7cfb\u7edf\u4e0a\u7f16\u8bd1\u3001\u8fd0\u884c\u3001\u5206\u6790\u548c\u8c03\u8bd5\u7528C\u8bed\u8a00\u7f16\u5199\u7684\u793a\u4f8bMIPS\u7a0b\u5e8f\u3002\u53c2\u8003\u94fe\u63a5\uff1a<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.ccwifi.cc\/blogs\/wp-content\/uploads\/2024\/03\/1711646796176_7.jpg\" alt=\"hashcat\u4f7f\u7528\u547d\u4ee4\"><img decoding=\"async\" src=\"http:\/\/www.ccwifi.cc\/blogs\/wp-content\/uploads\/2024\/03\/1711646796176_8.jpg\" alt=\"hashcat\u4f7f\u7528\u547d\u4ee4\"><\/p>\n<p>\u53c2\u8003\u94fe\u63a5\uff1a\u795e\u56681.BadMod\uff1a\u81ea\u52a8\u5316\u626b\u63cf\u5de5\u5177\u3002\u81ea\u52a8\u53d1\u73b0\u5e76\u83b7\u53d6\u6240\u6709\u670d\u52a1\u5668\u7ad9\u70b9\u548c\u4ee3\u7406\u670d\u52a1\u5668\u3002\u53c2\u8003\u94fe\u63a5\uff1a<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.ccwifi.cc\/blogs\/wp-content\/uploads\/2024\/03\/1711646796176_9.jpg\" alt=\"hashcat\u4f7f\u7528\u547d\u4ee4\"><\/p>\n<p>\u53c2\u8003\u94fe\u63a5\uff1a3.Pyfiscan\uff1aweb\u6f0f\u6d1e\u626b\u63cf\u5668\u3002\u514d\u8d39\u7684\u5e94\u7528\u7a0b\u5e8f\u6f0f\u6d1e\u548c\u7248\u672c\u626b\u63cf\u7a0b\u5e8f\uff0c\u7528\u4e8e\u5728Linux\u670d\u52a1\u5668\u4e2d\u67e5\u627e\u5e38\u89c1Web\u5e94\u7528\u7a0b\u5e8f\u3002\u53c2\u8003\u94fe\u63a5\uff1a<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.ccwifi.cc\/blogs\/wp-content\/uploads\/2024\/03\/1711646796176_10.jpg\" alt=\"hashcat\u4f7f\u7528\u547d\u4ee4\"><\/p>\n<p>\u53c2\u8003\u94fe\u63a5\uff1a5.bleah:BLE\u626b\u63cf\u5668\u3002\u7528\u4e8e\u653b\u51fb\u667a\u80fd\u8bbe\u5907\u7684BLE\u626b\u63cf\u5668\uff0c\u57fa\u4e8ebluepy\u5e93\u3002\u53c2\u8003\u94fe\u63a5\uff1a<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.ccwifi.cc\/blogs\/wp-content\/uploads\/2024\/03\/1711646796176_11.jpg\" alt=\"hashcat\u4f7f\u7528\u547d\u4ee4\"><\/p>\n<p>\u53c2\u8003\u94fe\u63a5\uff1a6.Moloch\uff1a\u5168\u5305\u5f0f\u6355\u6349\uff0c\u7d22\u5f15\u7684\u6570\u636e\u5e93\u7cfb\u7edf\u3002\u5f00\u6e90\u7684\u5168\u5305\u6355\u83b7\uff0c\u7d22\u5f15\u7684\u6570\u636e\u5e93\u7cfb\u7edf\uff0c\u63d0\u4f9b\u5feb\u901f\u7684\u7d22\u5f15\u8bbf\u95ee\u548c\u76f4\u89c2\u7b80\u5355\u7684Web\u754c\u9762\u3002\u53c2\u8003\u94fe\u63a5\uff1a<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.ccwifi.cc\/blogs\/wp-content\/uploads\/2024\/03\/1711646796176_12.jpg\" alt=\"hashcat\u4f7f\u7528\u547d\u4ee4\"><img decoding=\"async\" src=\"http:\/\/www.ccwifi.cc\/blogs\/wp-content\/uploads\/2024\/03\/1711646796176_13.jpg\" alt=\"hashcat\u4f7f\u7528\u547d\u4ee4\"><\/p>\n<p>\u53c2\u8003\u94fe\u63a5\uff1a7.Arpag\uff1a\u81ea\u52a8\u5316\u653b\u51fb\u5de5\u5177\u3002\u53c2\u8003\u94fe\u63a5\uff1a<\/p>\n<pre style=\"font-size: inherit;color: inherit;line-height: inherit;margin-top: 0px;margin-bottom: 0px;padding: 0px\"><p style=\"line-height: 15px;font-size: 11px;letter-spacing: 0px;font-family: Consolas, Inconsolata, Courier, monospace;border-radius: 0px;padding: 0.5em;margin-left: 16px;margin-right: 16px;overflow: auto !important\"><span class=\"hljs-number\" style=\"font-size: inherit;line-height: inherit\">1.<\/span>\u626b\u63cfJoomla CMS\u7f51\u7ad9\u641c\u7d22\u7ec4\u4ef6\/\u6269\u5c55\uff08\u8d85\u8fc7<span class=\"hljs-number\" style=\"font-size: inherit;line-height: inherit\">600<\/span>\u4e2a\u7ec4\u4ef6\u7684\u6570\u636e\u5e93\uff09;<br><span class=\"hljs-number\" style=\"font-size: inherit;line-height: inherit\">2.<\/span>\u627e\u5230\u7ec4\u4ef6\u7684\u53ef\u6d4f\u89c8\u6587\u4ef6\u5939\uff08Index <span class=\"hljs-keyword\" style=\"font-size: inherit;line-height: inherit\">of<\/span> ...\uff09;<br><span class=\"hljs-number\" style=\"font-size: inherit;line-height: inherit\">3.<\/span>\u627e\u5230\u7981\u7528\u6216\u4fdd\u62a4\u7684\u7ec4\u4ef6<br><span class=\"hljs-number\" style=\"font-size: inherit;line-height: inherit\">4.<\/span>\u627e\u5230\u6bcf\u4e2a\u6709\u52a9\u4e8e\u8bc6\u522b\u7ec4\u4ef6\u7248\u672c\u7684\u6587\u4ef6\uff08\u81ea\u8ff0\u6587\u4ef6\uff0c\u6e05\u5355\uff0c\u8bb8\u53ef\u8bc1\uff0c\u66f4\u65b0\u65e5\u5fd7\uff09<br><span class=\"hljs-number\" style=\"font-size: inherit;line-height: inherit\">5.<\/span>\u627e\u5230robots.txt\u6587\u4ef6\u6216error_log\u6587\u4ef6<br><span class=\"hljs-number\" style=\"font-size: inherit;line-height: inherit\">6.<\/span>\u652f\u6301HTTP\u6216HTTPS\u8fde\u63a5<br><span class=\"hljs-number\" style=\"font-size: inherit;line-height: inherit\">7.<\/span>\u8fde\u63a5\u8d85\u65f6<br><\/p><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.ccwifi.cc\/blogs\/wp-content\/uploads\/2024\/03\/1711646796176_14.jpg\" alt=\"hashcat\u4f7f\u7528\u547d\u4ee4\"><\/p>\n<p>\u53c2\u8003\u94fe\u63a5\uff1a9.JoomlaScan\uff1aJoomla CMS\u7ec4\u4ef6\u626b\u63cf\u548c\u6f0f\u6d1e\u626b\u63cf\u3002\u627e\u5230\u5b89\u88c5\u5728Joomla CMS\u4e2d\u7684\u7ec4\u4ef6\u7684\u5de5\u5177\u3002\u53c2\u8003\u94fe\u63a5\uff1a<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.ccwifi.cc\/blogs\/wp-content\/uploads\/2024\/03\/1711646796176_15.jpg\" alt=\"hashcat\u4f7f\u7528\u547d\u4ee4\"><img decoding=\"async\" src=\"http:\/\/www.ccwifi.cc\/blogs\/wp-content\/uploads\/2024\/03\/1711646796176_16.jpg\" alt=\"hashcat\u4f7f\u7528\u547d\u4ee4\"><\/p>\n<p>\u53c2\u8003\u94fe\u63a5\uff1a11.Diggy &#8211; \u4eceAPK\u6587\u4ef6\u4e2d\u63d0\u53d6URL\u3002\u4eceapk\u6587\u4ef6\u4e2d\u63d0\u53d6\u7aef\u70b9\/URL\uff0c\u4fdd\u5b58\u5230txt\u6587\u4ef6\u4e2d\u3002\u53c2\u8003\u94fe\u63a5\uff1a<\/p>\n<p>\u8d44\u8baf1.\u6700\u597d\u8bb0\u7684\u516c\u5171DNS\uff1a1.1.1.1\u3002Cloudflare\u63a8\u51fa\u65b0\u7684DNS\u670d\u52a1\uff0c\u5ba3\u79f0\u662f\u4e92\u8054\u7f51\u6700\u5feb\uff0c\u9996\u5148\u4fdd\u62a4\u9690\u79c1\u7684\u6d88\u8d39\u8005DNS\u670d\u52a1\u3002\u53c2\u8003\u94fe\u63a5\uff1a<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.ccwifi.cc\/blogs\/wp-content\/uploads\/2024\/03\/1711646796176_17.jpg\" alt=\"hashcat\u4f7f\u7528\u547d\u4ee4\"><\/p>\n<p>\u53c2\u8003\u94fe\u63a5\uff1a3.\u5fae\u8f6f\u53d1\u5e03Windows7 sp1 x64\u548cWindows Server 2008 R2\u9ad8\u5371\u5185\u6838\u63d0\u6743\u6f0f\u6d1e\u7684\u5b89\u5168\u8865\u4e01(CVE-2018-1038)\u3002\u53c2\u8003\u94fe\u63a5\uff1a<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.ccwifi.cc\/blogs\/wp-content\/uploads\/2024\/03\/1711646796176_18.jpg\" alt=\"hashcat\u4f7f\u7528\u547d\u4ee4\"><\/p>\n<p>\u53c2\u8003\u94fe\u63a5\uff1a5.Spring\u6f0f\u6d1e\u3002Spring Development Framework\u4e2d\u5b58\u5728\u4e09\u4e2a\u6f0f\u6d1e\uff0c\u5176\u4e2d\u4e4b\u4e00\u662f\u4e00\u4e2a\u4e25\u91cd\u7684\u8fdc\u7a0b\u4ee3\u7801\u6267\u884c\u6f0f\u6d1e\u3002\u53c2\u8003\u6587\u7ae0\uff1a<\/p>\n<p><!-- \u6587\u7ae0\u6765\u6e90:http:\/\/mp.weixin.qq.com\/s?src=11&amp;timestamp=1711646766&amp;ver=5166&amp;signature=7Utb75uQJB02kKtBLvReKlgYAmsEcnyQCq2*CgtZ9BOdCo1hj9bcpqzw5A2dGBehuN7h2KsdQx37Bccp8qmPYv*LImWtPcMaUPHsZH8AiVCxn9H7EzVUXShrkgkVoq7c&amp;new=1 --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u4f7f\u7528PowerShell\u811a\u672c\u6267\u884c\u547d\u4ee4\u5e76\u7ed5\u8fc7AppLocker;Ruby CVE\u59ff\u52bf1.\u4f7f\u7528OSQUERY\u5728MACOS\u4e0a\u68c0\u6d4b\u53cd\u5411SHELL\u5927\u591a\u6570\u8fdb\u7a0b\u90fd\u8fde\u63a5\u5230TTY\uff0c\u800c\u6ca1\u6709\u8fd0\u884c\u7684\u4efb\u4f55\u8fdb\u7a0b\u90fd\u53ef\u80fd\u503c\u5f97\u8fdb\u4e00\u6b65\u7814\u7a76\u3002\u5f53\u6211\u4eec\u5bf9\u8fdb\u7a0b\u8fd0\u884ctty\u67e5\u8be2\u7684\u65f6\u5019\uff0c\u5c31\u6709\u53ef\u80fd\u662f\u53cd\u5411shell\u7684\u5b58\u5728\u3002<\/p>\n","protected":false},"author":1,"featured_media":3994,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"topic":[],"class_list":["post-3993","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-1"],"_links":{"self":[{"href":"https:\/\/www.ccwifi.cc\/blogs\/wp-json\/wp\/v2\/posts\/3993","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ccwifi.cc\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ccwifi.cc\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ccwifi.cc\/blogs\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ccwifi.cc\/blogs\/wp-json\/wp\/v2\/comments?post=3993"}],"version-history":[{"count":0,"href":"https:\/\/www.ccwifi.cc\/blogs\/wp-json\/wp\/v2\/posts\/3993\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.ccwifi.cc\/blogs\/wp-json\/wp\/v2\/media\/3994"}],"wp:attachment":[{"href":"https:\/\/www.ccwifi.cc\/blogs\/wp-json\/wp\/v2\/media?parent=3993"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ccwifi.cc\/blogs\/wp-json\/wp\/v2\/categories?post=3993"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ccwifi.cc\/blogs\/wp-json\/wp\/v2\/tags?post=3993"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/www.ccwifi.cc\/blogs\/wp-json\/wp\/v2\/topic?post=3993"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}