Relayer是一个SMB中继攻击脚本,可自动化扫描系统中SMB签名禁用情况,并将身份验证请求中继到这些系统,以获取shell。非常适合在执行渗透测试时使用。
Relayer利用多种工具创建和交付payload,用户可以选择最适合的方法或工具:
来自trustedsec的Unicorn,请参见 https://github.com/trustedsec/unicorn
Ps1encode (https://github.com/CroweCybersecurity/ps1encode) 用于生成并编码基于PowerShell的metasploit payload,使用sct(COM Scriptlet)文件。 Relayer将自动使用Python创建Web服务器来托管payload。
PowerSploit (https://github.com/PowerShellMafia/PowerSploit)
运行install_req.sh以验证依赖关系并安装缺失的组件。
一切就绪后,用法很简单,只需以root身份运行:
./relayer.sh
脚本执行以下步骤:
请仅在获得授权的情况下运行此工具。