Giter Site home page Giter Site logo

提个小小的建议 about viper HOT 6 CLOSED

funnywolf avatar funnywolf commented on May 24, 2024
提个小小的建议

from viper.

Comments (6)

FunnyWolf avatar FunnyWolf commented on May 24, 2024 1

有些内网主机出网是通过内部的代理服务器出网的,那么我们生成的木马需要先走内网代理服务器,那么就需要指定代理地址,建议把msf中的HttpProxyHost、HttpProxyPort、HttpProxyUser、HttpProxyPass参数加到自定义参数里面供特殊环境中使用(比如msf payload中windows/x64/meterpreter/reverse_http就有设置这些参数的功能,可以通过show advanced查看)

在使用windows/x64/meterpreter/reverse_https这种载荷时,会自动调用windows的系统代理尝试连接C2,所以msf在鱼叉攻击外企或者大型企业时比CS好用,因为你不用事先了解对方内网的代理服务器是什么.

可以动态获取不同payload的所有参数吗,并动态构建自定义参数列表,而不是硬编码几个固定的参数。

是不是需要在前端UI能动态添加监听的所有参数信息(或者说动态选择),这个功能考虑过添加,但是前端实现起来太麻烦了,所以就没加,其实在msfconsole中建立的监听在UI上也能展示,我加入到TODO里面吧

from viper.

freeAhao avatar freeAhao commented on May 24, 2024

何大佬说的对

from viper.

FunnyWolf avatar FunnyWolf commented on May 24, 2024

有些内网主机出网是通过内部的代理服务器出网的,那么我们生成的木马需要先走内网代理服务器,那么就需要指定代理地址,建议把msf中的HttpProxyHost、HttpProxyPort、HttpProxyUser、HttpProxyPass参数加到自定义参数里面供特殊环境中使用(比如msf payload中windows/x64/meterpreter/reverse_http就有设置这些参数的功能,可以通过show advanced查看)

在使用windows/x64/meterpreter/reverse_https这种载荷时,会自动调用windows的系统代理尝试连接C2,所以msf在鱼叉攻击外企或者大型企业时比CS好用,因为你不用事先了解对方内网的代理服务器是什么.

from viper.

freeAhao avatar freeAhao commented on May 24, 2024

有些内网主机出网是通过内部的代理服务器出网的,那么我们生成的木马需要先走内网代理服务器,那么就需要指定代理地址,建议把msf中的HttpProxyHost、HttpProxyPort、HttpProxyUser、HttpProxyPass参数加到自定义参数里面供特殊环境中使用(比如msf payload中windows/x64/meterpreter/reverse_http就有设置这些参数的功能,可以通过show advanced查看)

在使用windows/x64/meterpreter/reverse_https这种载荷时,会自动调用windows的系统代理尝试连接C2,所以msf在鱼叉攻击外企或者大型企业时比CS好用,因为你不用事先了解对方内网的代理服务器是什么.

可以动态获取不同payload的所有参数吗,并动态构建自定义参数列表,而不是硬编码几个固定的参数。

from viper.

FunnyWolf avatar FunnyWolf commented on May 24, 2024

FunnyWolf/viperjs@f0518ec

from viper.

FunnyWolf avatar FunnyWolf commented on May 24, 2024

权衡了一下,觉得如果把handler的全部参数都放在ui上太乱了,用户也不一定全用上,所以就加了可能有用处的一些参数

from viper.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.