囤书有点多,一本都没看完过,今天开始准备抽时间啃书了,记录下学习。
黑客秘笈-渗透测试实用指南(第二版)
下载地址:https://pan.baidu.com/s/1PaQ5V67HLC6lTFIokcONmQ 密码:uqch
解压密码:www.linuxprobe.com
工具下载
metasploitable
https://sourceforge.net/projects/metasploitable/
owaspbwa
https://sourceforge.net/projects/owaspbwa/
![](https://img.haomeiwen.com/i11757893/7796612e5e3e1296.png)
![](https://img.haomeiwen.com/i11757893/cb04c52c501ac07c.png)
![](https://img.haomeiwen.com/i11757893/aee939cf997ff7cf.png)
![](https://img.haomeiwen.com/i11757893/07669e1f0dde7488.png)
![](https://img.haomeiwen.com/i11757893/b416bb2c176a92b6.png)
![](https://img.haomeiwen.com/i11757893/29637e6df251621c.png)
![](https://img.haomeiwen.com/i11757893/f273821c8bc61167.png)
工具太多就不截图了。
打开metasploitable虚拟机
安装kali虚拟机
设置虚拟机在同一网段内,使用nmap扫描网段IP
![](https://img.haomeiwen.com/i11757893/320ccdae23a199be.png)
使用vsftpd漏洞
使用metasploit
命令:msfconsole
search vsftpd
![](https://img.haomeiwen.com/i11757893/33a86ebf5eb33ca0.png)
![](https://img.haomeiwen.com/i11757893/1f6adfc017070c9b.png)
成功反弹shell
网友评论