±¾ÆªÊÇÄÚÍøÉøÍ¸ÏµÁеĵڶþƪ£¬ÎÒÃÇÖ÷ÒªÀ´ÁÄÒ»ÁÄÔÚÄÚÍøÉøÍ¸Öж¼ÓÐÄÄЩ·½·¨¿ÉÒÔ°ïÖúÎÒÃǽøÐкáÏòÒÆ¶¯¡£ÔÚ¿ªÊ¼Ö®Ç°£¬ÎÒÃÇÏȼòµ¥½éÉÜÒ»ÏÂʲôÊǺáÏòÒÆ¶¯£¬ËùνºáÏòÒÆ¶¯¾ÍÊǵ±¹¥»÷Õß»ñµÃÁËij̨ÄÚÍø»úÆ÷µÄ¿ØÖÆÈ¨Ï޺󣬻áÒÔ±»¹¥ÏݵÄÖ÷»úÎªÌø°å£¬¼ÌÐø·ÃÎÊ»ò¿ØÖÆÆäËûÄÚÍø»úÆ÷µÄ¹ý³Ì£¬ÎÒÃdzÆÖ®ÎªºáÏòÒÆ¶¯¡£
Óйظü¶à¸ÅÄî¿ÉÒԲο¼ÄÚÍøÉøÍ¸ÏµÁеÄÉÏһƪÎÄÕ¡¶ÄÚÍøÉøÍ¸¡ª»ñÈ¡WindowsÄÚHashÃÜÂë·½·¨×ܽᡷ£¬»°²»¶à˵£¬Ö±½Ó¿ªÊ¼¡£
01¡¢WindowsÔ¶³ÌÁ¬½ÓÃüÁî½éÉÜ
ÔÚÉÏһƪÎÄÕÂÖУ¬ÎÒÃǽéÉÜÁËÈçºÎ»ñÈ¡Windowsµ¥»úµÄHashÃÜÂ룬ÕâÒ»²½ÊǽøÐкáÏòÒÆ¶¯µÄ»ù´¡£¬½ÓÏÂÀ´ÎÒÃÇ¿ÉÒÔͨ¹ýWindows×Ô´øµÄÔ¶³ÌÁ¬½ÓÃüÁî½øÐвÙ×÷£¬Ò²¿ÉÒÔͨ¹ýһЩPTHµÄ·½·¨£¬½«É¢ÁÐÖµ»òÃ÷ÎÄÃÜÂë½øÐд«µÝ£¬µ±È»ÕâÊǺóÃæµÄÄÚÈÝ»á½éÉܵ½µÄ£¬ÕâÀïÎÒÃÇÏÈÁ˽âÒ»ÏÂÓйØWindows×Ô´øµÄÔ¶³ÌÁ¬½ÓÃüÁî----IPC¡£
IPC$£¨Internet Process Connection£©ÊÇ¡°½ø³Ì¼äͨÐÅ¡±µÄ¼ò³Æ£¬Æä±¾ÖÊÊÇÒ»¸ö¹²ÏíµÄ¡°ÃüÃû¹ÜµÀ¡±×ÊÔ´£¬Ö÷ÒªµÄ×÷ÓÃÊÇΪÁËÈýø³Ì¼äͨÐŶø¿ª·ÅÒ»¸öÃüÃû¹ÜµÀ£¬Í¨¹ýÌṩ¿ÉÐÅÈεÄÓû§ÃûºÍ¿ÚÁ´Ó¶øµ½´ïÁ¬½ÓË«·½¿ÉÒÔ½¨Á¢Ò»¸ö»Æ½ð³Ç¹ÙÍøµÄͨµÀ²¢ÒԴ˽øÐмÓÃÜÊý¾Ý½»»»µÄ¹¦ÄÜ£¬×îÖÕÏÔÏÖ³öÀ´µÄЧ¹û¾ÍÊÇÄܹ»ÊµÏÖ¶ÔÔ¶³Ì¼ÆËã»úµÄ·ÃÎÊ¡£
Æäʵ˵°×ÁËIPC$ÓеãÀàËÆÓÚ¹²ÏíĿ¼£¬µ«¹¦ÄܱÈËû¶àµÃ¶à¡£Í¨¹ýIPC$ÓëÄ¿±ê»ú½¨Á¢Á¬½Ó£¬²»½ö¿ÉÒÔ·ÃÎÊÄ¿±ê»úÆ÷ÖеÄÎļþ£¬½øÐÐÉÏ´«¡¢ÏÂÔØ£¬»¹¿ÉÒÔÔÚÄ¿±ê»úÉÏÔËÐÐÃüÁʹÓÃÏÂÃæµÄÃüÁî¾Í¿ÉÒÔºÜÇáËɵش´½¨Ò»¸öIPC$Á¬½ÓÁË¡£
Net use \<Ä¿±ê»úIP>ipc$ ¡°password¡± /user:¡±username¡±
¿´µ½ÉÏÃæµÄÃüÁÎÒÃÇ¿ÉÒÔÖªµÀ£¬ÒªÏ뽨Á¢IPCÁ¬½Ó±ØÐëÒªÂú×ãÈý¸öÌõ¼þ£º
¢Ù Ä¿±ê»ú¿ªÆôÁË139ºÍ445¶Ë¿Ú£»
¢Ú Ä¿±êÖ÷»ú¹ÜÀíÔ±¿ªÆôÁËipc$ĬÈϹ²Ïí£»
¢Û ÖªµÀÄ¿±ê»úµÄÕË»§ÃÜÂë¡£
¿ÉÄܵ½ÕâÀï»áÓÐһЩÈËÓÐÒÉÎÊ£¬ÎªÊ²Ã´ÎÒ¶¼ÖªµÀÁËÄ¿±ê»úµÄÓû§ÃûºÍÃÜÂ뻹ҪʹÓÃIPC£¿ÒòΪÔÚÕæÊµ»·¾³ÖУ¬²¢²»ÊÇÄÚÍøµÄËùÓлúÆ÷¶¼¿ª·ÅÁË3389£¨Ô¶³Ì×ÀÃæ£©ÈÃÄãµÇ½£¬¶ÔÓÚһЩûÓпªÆô¸Ã·þÎñµÄ»úÆ÷ÏëÒª¿ØÖÆËü¾Í±ØÐëµÃͨ¹ýIPCÁ¬½ÓµÄ·½·¨ÁË¡£¶øÇÒÒªÏëÖ±½Ó»ñȡĿ±ê»úµÄÓû§ÃûºÍÃÜÂëÊDZȽÏÀ§Äѵģ¬ÔÚ²»ÖªµÀ¿ÚÁîµÄÇé¿öÏÂÏëÒªÖ±½Óͨ¹ýÔ¶³Ì×ÀÃæÀ´½øÐб¬ÆÆÊÇÐв»Í¨µÄ£¬µ«ÊÇIPC²»½ö¿ÉÒÔÅúÁ¿±¬ÆÆ£¬»¹ÔÊÐíÄäÃûµÇ½£¬ËùÒÔIPCÁ¬½Ó¾ßÓиüÇ¿µÄÁé»îÐÔ¡£
02¡¢IPC+¼Æ»®ÈÎÎñ½øÐкáÏòÒÆ¶¯
ͨ¹ý¼Æ»®ÈÎÎñ½øÐкáÏòÒÆ¶¯ÆäʵÀàËÆÓÚÎÒÃÇÔÙ½øÐÐLinux·´µ¯shellʱËùÒÀÀµµÄ¼Æ»®ÈÎÎñÒ»Ñù£¬¶¼ÊÇͨ¹ý¼Æ»®ÈÎÎñ»úÖÆ£¬ÈÃÆä×Ô¶¯Ö´Ðй¥»÷ÕßÉÏ´«µÄľÂí£¬´Ó¶ø´ïµ½ÊܿصÄÄ¿µÄ¡£ÔÚWindowsÖУ¬Äܹ»´´½¨»òÐ޸ļƻ®ÈÎÎñµÄÖ÷ÒªÓÐÁ½¸öÃüÁschtasksºÍat¡£ÆäÖÐatÃüÁîÖ÷Òª¹¤×÷ÔÚWindowsServer 2008֮ǰ°æ±¾µÄ²Ù×÷ϵͳÖУ¬ÔÚÖ®ºóµÄ°æ±¾Ö÷Òª¹¤×÷µÄ¶¼ÊÇschtasksÃüÁî¡£
1£©ÀûÓÃschtasksÃüÁî
¾ßÌåµÄ²Ù×÷Á÷³ÌÈçÏ£º
¢Ù ÓëÄ¿±ê»ú½¨Á¢IPCÁ¬½Ó
¢Ú ʹÓÃcopyÃüÁ½«Ä¾Âí¸´ÖÆµ½Ä¿±ê»úÖÐ
¢Û Ä¿±ê»úÉÏ´´½¨¼Æ»®ÈÎÎñ£¬Ê¹Æä×Ô¶¯´¥·¢Ä¾ÂíÎļþ
¹¥»÷»ú£º192.168.210.38£¨KaliLinux£©
Ìø°å»ú£º192.168.20.35£¨Windows10£©
Ä¿±ê»ú£º192.168.210.102£¨Windows 10£©
Ìø°å»úÓëÄ¿±ê»ú´´½¨IPCÁ¬½Ó

¹¥»÷»úÉÏÉú³ÉľÂí

ÔÚÌø°å»úÉÏʹÓÃcopyÃüÁ½«¹¥»÷»úÉÏÉú³ÉµÄľÂíÎļþ¸´ÖƵ½Ä¿±ê»úÖÐ
copy shell.exe \192.168.210.102c$

ÀûÓÃschtasksÃüÁî´´½¨Ò»¸öÃûΪ¡°hack¡±µÄ¼Æ»®ÈÎÎñ£¬¸ÃÈÎÎñÿ·ÖÖÓÖ´ÐÐÒ»´Îshell.exe¡£
schtasks /create /s 192.168.210.102 /uusername /p password /tn hack /sc minute /mo 1 /tr c:shell.exe /ru system /f


³ýÁËÀûÓÃľÂí»ñµÃȨÏÞÍ⣬»¹¿ÉÒÔͨ¹ý¼Æ»®ÈÎÎñÖ±½ÓÖ´ÐÐϵͳÃüÁµ«ÓÉÓÚ½á¹û²»»á»ØÏÔ£¬ËùÒÔÎÒÃÇÐèÒªÏȽ«½á¹û±£´æÔÚÒ»¸öÎļþÖУ¬ÔÙͨ¹ýtypeÖ¸Áî¶ÁÈ¡ÎļþÄÚÈÝ»ñµÃÖ´Ðнá¹û¡£

2£©ÀûÓÃatÃüÁî
ʹÓÃatÃüÁîÓëÉÏÃæµÄschtasksÃüÁîÀàËÆ£¬Î¨Ò»ÓÐËùÇø±ðµÄÊÇÀûÓÃatÃüÁîʱµÄÃüÁî¸ñʽÓëschtasks²»Í¬¡£
¹¥»÷»ú£º192.168.210.38£¨KaliLinux£©
Ä¿±ê»ú£º192.168.210.102£¨Windows 10£©
Ìø°å»ú£º192.168.210.107£¨Windows Server 2008 R2£©
Ìø°å»úÓëÄ¿±ê»ú½¨Á¢IPCÁ¬½Ó

ʹÓÃatÃüÁî´´½¨¼Æ»®ÈÎÎñ£¬ÈÃÄ¿±ê»úÔËÐÐľÂí³ÌÐò

03¡¢IPC+Windows·þÎñÀ´½øÐкáÏòÒÆ¶¯
ʹÓÃWindows·þÎñÀ´½øÐкáÏòÒÆ¶¯ÓеãÀàËÆÓëÉÏÒ»²¿·ÖµÄÀûÓüƻ®ÈÎÎñ½øÐкáÏòÒÆ¶¯£¬ÆäºËÐÄÒ²Êǽ«Ä¾ÂíÎļþ´«ÈëÄ¿±ê»úÖУ¬È»ºóͨ¹ýSCÃüÁî´´½¨Ò»¸öWindows·þÎñÓÃÀ´Ö¸Ïò´«ÈëµÄľÂíÎļþ£¬×îºóÆô¶¯¸Ã·þÎñ»òÕßÖØÆôÄ¿±ê»ú¼´¿É´¥·¢¸ÃľÂí£¬ÊµÏÖºáÏòÒÆ¶¯¡£
¾ßÌåµÄ²Ù×÷Á÷³ÌÈçÏ£º
¢Ù ÓëÄ¿±ê»ú½¨Á¢IPCÁ¬½Ó
¢Ú ʹÓÃcopyÃüÁ½«Ä¾Âí¸´ÖÆµ½Ä¿±ê»úÖÐ
¢Û ÀûÓÃscÃüÁî´´½¨Ò»¸öWindows·þÎñÖ¸ÏòľÂíÎļþ
¢Ü Æô¶¯¸Ã·þÎñ´¥·¢Ä¾Âí
¹¥»÷»ú£º192.168.210.38£¨KaliLinux£©
Ìø°å»ú£º192.168.20.35£¨Windows10£©
Ä¿±ê»ú£º192.168.210.107£¨Windows Server 2008 R2£©
ÏÈÈÃÌø°å»úÓëÄ¿±ê»ú½¨Á¢IPCÁ¬½Ó£¬È»ºóÀûÓÃCopyÃüÁľÂíÎļþshell1.exe¸´ÖƵ½Ä¿±ê»úÖС£

ÀûÓÃSCÃüÁî´´½¨Ò»¸öÃûΪhackerµÄ·þÎñ£¬ÃüÁîÈçÏ£º
sc \ create binpath=¡±¡±
sc \192.168.210.107 create hackerbinpath=¡±c:shell1.exe¡± #´´½¨·þÎñ
sc \192.168.210.107 start hacker #Æô¶¯hacker·þÎñ

04¡¢×ܽá
ÒÔÉϽéÉܵÄÖ»ÊÇÎÒÃÇÔÚÄÚÍøÉøÍ¸ÖнøÐкáÏòÒÆ¶¯µÄ³£¼û·½·¨£¬ÏÂÒ»ÆÚÎÒÃÇ»á½éÉÜÆäËûµÄºáÏòÒÆ¶¯·½·¨£¬ÀýÈçÈçºÎÀûÓÃPTHµÄ·½·¨£¬½«É¢ÁÐÖµ»òÃ÷ÎÄÃÜÂë´«ÈëÄ¿±ê»úÖнøÐкáÏòÒÆ¶¯£¬»òÕßÀûÓÃWindows×Ô´ø¹¤¾ßPsExec¡¢WMI½øÐкáÏòÒÆ¶¯ÒÔ¼°Ñ°ÕÒÓò¿ØµÄ·½·¨¡£