从web到内网的一些思路及工具

admin 2022年6月18日10:04:58评论16 views字数 5617阅读18分43秒阅读模式

 

 

1

https://www.qcc.com

https://www.tianyancha.com

https://aiqicha.baidu.com

https://tool.chinaz.com/

  IPip

2

  

https://ruo.me

one for all

https://github.com/shmilylty/OneForAll

ksubdomain

https://github.com/knownsec/ksubdoma

3ip

访CDNPingCDN

Ping

https://www.wepcc.com/

CDN

https://myssl.com/

Nslookup

nslookup XXXX.com

SSL

sslscan

https://github.com/rbsec/sslscan

4

  使cmscms

wappalyzer

whatweb

https://github.com/urbanadventurer/whatweb

5

   访访

dirsearch

https://github.com/maurosoria/dirsearch

5

   xraygobyNessus

   nmap

https://github.com/nmap/nmap

   xray

https://xray.cool/

   goby

https://gobies.org/

5WAF

   WAFWAFwafWAFbypass

   wafw00f

https://github.com/EnableSecurity/wafw00f

  whatwaf

https://github.com/Ekultek/WhatWaf

   waf

https://blog.csdn.net/weixin_57567655/article/details/124766026

6webshell

 webshellwebshell便webshell

 

https://github.com/rebeyond/Behinder

 

https://github.com/BeichenDream/Godzilla

 

https://github.com/AntSwordProject/antSword

7

 

 zscan

https://github.com/zyylhn/zscanfSingleSessionPerUser /t REG_DWORD /d 0 /f

 fscan

https://github.com/shadow1ng/fscan

neo-regeorg

 https://github.com/L-codes/Neo-reGeorg

Proxifier

https://www.proxifier.com/

idwhoamiipconfig /allifconfig /allnet time /domainnet view /domainnet group /domainnet froup <span data-raw-text="" "="" data-textnode-index-1655475471064="134" data-index-1655475471064="2194" class="character">"doamin computers<span data-raw-text="" "="" data-textnode-index-1655475471064="134" data-index-1655475471064="2211" class="character">" /domainnet group <span data-raw-text="" "="" data-textnode-index-1655475471064="137" data-index-1655475471064="2243" class="character">"domain controllers<span data-raw-text="" "="" data-textnode-index-1655475471064="137" data-index-1655475471064="2262" class="character">" /domainnet group <span data-raw-text="" "="" data-textnode-index-1655475471064="140" data-index-1655475471064="2288" class="character">"domain admins<span data-raw-text="" "="" data-textnode-index-1655475471064="140" data-index-1655475471064="2302" class="character">" /domainnet accounts /domainnltest /domain_trustsnltest /DCLIST:hackeNslookup -type=SRV_LDAP._tcpquery user线systeminforoute print/arp -aARPnet sessionnet config workstationnet accounts /domainwhoami /userSIDSIDcat /etc/hosts  type c:Windowssystem32driversetchostslinuxwindowshostswmic startup get command,captionschtasks /query /fo LIST /vnet statistics workstationnetstat -anowmic qfe get Caption,Description,HotFixID,Installedonnet share/wmic share get name,path,statusnetsh firewall show confignetsh advfirewall firewall add rule name=<span data-raw-text="" "="" data-textnode-index-1655475471064="198" data-index-1655475471064="3049" class="character">"Remote Desktop<span data-raw-text="" "="" data-textnode-index-1655475471064="198" data-index-1655475471064="3064" class="character">" protocol=TCP dir=in localport=3389 action=allow3389wmic path win32_terminalservicesetting where (_CLASS !=<span data-raw-text="" "="" data-textnode-index-1655475471064="201" data-index-1655475471064="3179" class="character">"<span data-raw-text="" "="" data-textnode-index-1655475471064="201" data-index-1655475471064="3180" class="character">") call setallowtsconnections 1200333892008/20123389wmic /namespace:rootcimv2terminalservice path win32_terminalservicesetting where (_CLASS !=<span data-raw-text="" "="" data-textnode-index-1655475471064="205" data-index-1655475471064="3335" class="character">"<span data-raw-text="" "="" data-textnode-index-1655475471064="205" data-index-1655475471064="3336" class="character">") call setallowtsconnections 1wmic /namespace:rootcimv2terminalservices path win32_tsgeneralsetting where (TeminalName='RDP-Tcp') call setuserauthenticationrequired 1reg add <span data-raw-text="" "="" data-textnode-index-1655475471064="211" data-index-1655475471064="3515" class="character">"HKLMSYSTEMCURRENTCONTROLSETCONTROLTERMINAL SERVER<span data-raw-text="" "="" data-textnode-index-1655475471064="211" data-index-1655475471064="3570" class="character">" /v

8

 

https://sr.xljtj.com/

9

  WindowsLiunxdirty-pipe

   windows

https://github.com/xiaoy-sec/Pentest_Note/blob/master/wiki/%E6%9D%83%E9%99%90%E6%8F%90%E5%8D%87/Windows%E6%8F%90%E6%9D%83/README.md

  linux

https://github.com/xiaoy-sec/Pentest_Note/blob/master/wiki/%E6%9D%83%E9%99%90%E6%8F%90%E5%8D%87/Linux%E6%8F%90%E6%9D%83/README.md

  ...西

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
admin
  • 本文由 发表于 2022年6月18日10:04:58
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   从web到内网的一些思路及工具https://cn-sec.com/archives/1125831.html

发表评论

匿名网友 填写信息