'Windows'에 해당되는 글 34건
- 2011/09/09 POST EXPLOITATION COMMAND LISTS
- 2011/04/19 윈도우 커멘드라인 명령 패킷 스니퍼 RawCap
- 2011/04/16 Windows XP DEP(데이터 실행 방지)
I've had a private list of commands that I run on Windows or Linux when I pop a shell, as I'm sure most pentesters do. It isn't so much a thing of hoarding as much it is just jumbled notes that are 'not worth posting'
Well, I made two (now 3) public google docs (anyone can edit) *don't be a dick clause
Linux/Unix/BSD Post Exploitation:
https://docs.google.com/document/d/1ObQB6hmVvRPCgPTRZM5NMH034VDM-1N-EWPRz2770K4/edit?hl=en_US
Windows Post Exploitation:
https://docs.google.com/document/d/1U10isynOpQtrIK6ChuReu-K1WHTJm4fgG3joiuz43rw/edit?hl=en_US
and newly added OSX Post Exploitation:
https://docs.google.com/document/d/10AUm_zUdAQGgoHNo_eS0SO1K-24VVYnulUD2x3rJD3k/edit?hl=en_US
Both have filled out A LOT since I first posted them but if you have that one trick command you'd like to share or just want to copy/print the list for your own uses, thats fine too. I plan to keep these publicly editable as long as people obey the DBAD clause.
If you don't know any cool commands but happen to be a tech writer and can make it look beautiful, then great! Please do. There are tables at the bottom that I want to move everything to, or something like it, but if you can do it better...
Anyways, look forward to seeing how this thing grows.
RawCap is a free command line network sniffer for Windows that uses raw sockets.
Properties of RawCap:
- Can sniff any interface that has got an IP address, including 127.0.0.1 (localhost/loopback)
- RawCap.exe is just 17 kB
- No external libraries or DLL's needed other than .NET Framework 2.0
- No installation required, just download RawCap.exe and sniff
- Can sniff most interface types, including WiFi and PPP interfaces
- Minimal memory and CPU load
- Reliable and simple to use
Usage
You will need to have administrator privileges to run RawCap.
NETRESEC RawCap version 0.1.2.0
http://www.netresec.com
Usage: RawCap.exe <interface_nr> <target_pcap_file>
0. IP : 192.168.0.17
NIC Name : Local Area Connection
NIC Type : Ethernet
1. IP : 192.168.0.47
NIC Name : Wireless Network Connection
NIC Type : Wireless80211
2. IP : 90.130.211.54
NIC Name : 3G UMTS Internet
NIC Type : Ppp
3. IP : 192.168.111.1
NIC Name : VMware Network Adapter VMnet1
NIC Type : Ethernet
4. IP : 192.168.222.1
NIC Name : VMware Network Adapter VMnet2
NIC Type : Ethernet
5. IP : 127.0.0.1
NIC Name : Loopback Pseudo-Interface
NIC Type : Loopback
Example: RawCap.exe 0 dumpfile.pcap
An alternative to supplying the interface number is to supply the IP address of the prefered interface instead, i.e. like this:
Interactive Console Dialog
You can also start RawCap without any arguments, this will leave you with an interactive dialog:
Network interfaces:
0. 192.168.0.17 Local Area Connection
1. 192.168.0.47 Wireless Network Connection
2. 90.130.211.54 3G UMTS Internet
3. 192.168.111.1 VMware Network Adapter VMnet1
4. 192.168.222.1 VMware Network Adapter VMnet2
5. 127.0.0.1 Loopback Pseudo-Interface
Select network interface to sniff [default '0']: 1
Output path or filename [default 'dumpfile.pcap']:
Sniffing IP : 192.168.0.47
File : dumpfile.pcap
Packets : 1337
Raw sockets limitations in Vista and Win7
Due to current limitations in the raw sockets implementations for Windows Vista and Windows 7 we suggest running RawCap on Windows XP. The main problem with raw socket sniffing in Vista and Win7 is that you might not receive either incoming packets (Win7) or outgoing packets (Vista).
Download RawCap
You can download RawCap.exe here.
데이터 실행 방지 이해
데이터 실행 방지(DEP)를 사용하면
DEP는 방화벽이나 바이러스 백신 프로그램과는 달리 컴퓨터에 해로운 프로그램이 설치되는 것을 방지해 주지는 않습니다. 대신, 프로그램을 모니터링하여 시스템 메모리가 안전하게 사용되고 있는지 확인합니다. 이 작업을 수행하기 위해 DEP 소프트웨어는 단독으로 또는 호환 가능한 마이크로프로세서와 함께 작동하여 일부 메모리 위치를 "실행 불가능"한 것으로 표시합니다. 프로그램이 코드를 보호된 위치에서 실행하려 할 경우 DEP는 해당 프로그램을 닫고 사용자에게 알려 줍니다.
DEP는 소프트웨어 및 하드웨어에서 지원되는 기능입니다. DEP 기능을 사용하려면 컴퓨터에서
DEP에서 닫은 프로그램을 다시 실행해도 안전합니까?
참고
- 기본적으로 DEP는 필수
Windows 운영 체제 프로그램 및 서비스에서만 설정됩니다. DEP를 사용하여 다른 프로그램을 보호하려면 데이터 실행 방지(DEP)를 사용자가 직접 선택한 항목을 제외한 모든 프로그램 및 서비스에 사용을 선택하십시오.
timeout=30
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional"
/Execute /fastdetect
timeout=30
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optout /fastdetect
* OptOut 적용할 경우 많은 악성파일의 권한상승 및 실행이 제한될 수 있어 안전성을 높혀준다! (권장)

Prev

Facebook

