|
@@ -0,0 +1,37 @@
|
|
|
+# evil-winrm
|
|
|
+
|
|
|
+> ์นจํฌ ํ
์คํธ๋ฅผ ์ํ WinRM(Windows ์๊ฒฉ ๊ด๋ฆฌ ์).
|
|
|
+> ์ฐ๊ฒฐ๋๋ฉด, ๋์ ํธ์คํธ์ PowerShell ํ๋กฌํํธ๊ฐ ํ์๋จ.
|
|
|
+> ๋ ๋ง์ ์ ๋ณด: <https://github.com/Hackplayers/evil-winrm>.
|
|
|
+
|
|
|
+- ํธ์คํธ์ ์ฐ๊ฒฐ:
|
|
|
+
|
|
|
+`evil-winrm --ip {{์์ดํผ}} --user {{์ฌ์ฉ์}} --password {{๋น๋ฐ๋ฒํธ}}`
|
|
|
+
|
|
|
+- ๋น๋ฐ๋ฒํธ ํด์๋ฅผ ์ ๋ฌํ์ฌ ํธ์คํธ์ ์ฐ๊ฒฐ:
|
|
|
+
|
|
|
+`evil-winrm --ip {{์์ดํผ}} --user {{์ฌ์ฉ์}} --hash {{nt_hash}}`
|
|
|
+
|
|
|
+- ์คํฌ๋ฆฝํธ ๋ฐ ์คํ ํ์ผ์ ๋ํ ๋๋ ํฐ๋ฆฌ๋ฅผ ์ง์ ํ์ฌ ํธ์คํธ์ ์ฐ๊ฒฐ:
|
|
|
+
|
|
|
+`evil-winrm --ip {{์์ดํผ}} --user {{์ฌ์ฉ์}} --password {{๋น๋ฐ๋ฒํธ}} --scripts {{๊ฒฝ๋ก/๋์/์คํฌ๋ฆฝํธ}} --executables {{๊ฒฝ๋ก/๋์/์คํํ์ผ}}`
|
|
|
+
|
|
|
+- SSL์ ์ฌ์ฉํ์ฌ ํธ์คํธ์ ์ฐ๊ฒฐ:
|
|
|
+
|
|
|
+`evil-winrm --ip {{์์ดํผ}} --user {{์ฌ์ฉ์}} --password {{๋น๋ฐ๋ฒํธ}} --ssl --pub-key {{๊ฒฝ๋ก/๋์/๊ณต๊ฐํค}} --priv-key {{๊ฒฝ๋ก/๋์/๊ฐ์ธํค}}`
|
|
|
+
|
|
|
+- ํธ์คํธ์ ํ์ผ ์
๋ก๋:
|
|
|
+
|
|
|
+`PS > upload {{๊ฒฝ๋ก/๋์/๋ก์ปฌ/ํ์ผ}} {{๊ฒฝ๋ก/๋์/์๊ฒฉ/ํ์ผ}}`
|
|
|
+
|
|
|
+- ๋ก๋๋ ๋ชจ๋ PowerShell ํจ์๋ฅผ ๋์ด:
|
|
|
+
|
|
|
+`PS > menu`
|
|
|
+
|
|
|
+- `--scripts` ๋๋ ํฐ๋ฆฌ์์ PowerShell ์คํฌ๋ฆฝํธ๋ฅผ ๋ก๋:
|
|
|
+
|
|
|
+`PS > {{์คํฌ๋ฆฝํธ.ps1}}`
|
|
|
+
|
|
|
+- `--executables` ๋๋ ํฐ๋ฆฌ์์ ํธ์คํธ์ ๋ฐ์ด๋๋ฆฌ๋ฅผ ํธ์ถ:
|
|
|
+
|
|
|
+`PS > Invoke-Binary {{๋ฐ์ด๋๋ฆฌ.exe}}`
|