{"id":62195,"date":"2024-10-13T16:58:16","date_gmt":"2024-10-13T08:58:16","guid":{"rendered":"https:\/\/server.hk\/cnblog\/62195\/"},"modified":"2024-10-13T16:58:16","modified_gmt":"2024-10-13T08:58:16","slug":"kali2%ef%bc%9a%e5%b0%88%e6%a5%ad%e6%aa%a2%e6%b8%ac%e6%95%b8%e6%93%9a%e5%ba%ab%e6%bc%8f%e6%b4%9e%e7%9a%84%e5%bf%85%e5%82%99%e5%88%a9%e5%99%a8-kali2%e6%aa%a2%e6%b8%ac%e6%95%b8%e6%93%9a%e5%ba%ab","status":"publish","type":"post","link":"https:\/\/server.hk\/cnblog\/62195\/","title":{"rendered":"Kali2\uff1a\u5c08\u696d\u6aa2\u6e2c\u6578\u64da\u5eab\u6f0f\u6d1e\u7684\u5fc5\u5099\u5229\u5668 (kali2\u6aa2\u6e2c\u6578\u64da\u5eab\u6f0f\u6d1e)"},"content":{"rendered":"<h1 id=\"kali2%ef%bc%9a%e5%b0%88%e6%a5%ad%e6%aa%a2%e6%b8%ac%e6%95%b8%e6%93%9a%e5%ba%ab%e6%bc%8f%e6%b4%9e%e7%9a%84%e5%bf%85%e5%82%99%e5%88%a9%e5%99%a8-DTtpGpdvYc\">Kali2\uff1a\u5c08\u696d\u6aa2\u6e2c\u6578\u64da\u5eab\u6f0f\u6d1e\u7684\u5fc5\u5099\u5229\u5668<\/h1>\n<p>\u5728\u7576\u4eca\u6578\u4f4d\u5316\u7684\u6642\u4ee3\uff0c\u6578\u64da\u5eab\u7684\u5b89\u5168\u6027\u6210\u70ba\u4f01\u696d\u548c\u500b\u4eba\u7528\u6236\u4e0d\u53ef\u5ffd\u8996\u7684\u91cd\u8981\u8b70\u984c\u3002\u96a8\u8457\u7db2\u7d61\u653b\u64ca\u624b\u6bb5\u7684\u65e5\u76ca\u589e\u591a\uff0c\u5982\u4f55\u6709\u6548\u6aa2\u6e2c\u548c\u4fee\u88dc\u6578\u64da\u5eab\u6f0f\u6d1e\u6210\u70ba\u4e86\u4fe1\u606f\u5b89\u5168\u5c08\u5bb6\u7684\u9996\u8981\u4efb\u52d9\u3002Kali Linux\uff0c\u4f5c\u70ba\u4e00\u6b3e\u5c08\u696d\u7684\u6ef2\u900f\u6e2c\u8a66\u5de5\u5177\uff0c\u63d0\u4f9b\u4e86\u591a\u7a2e\u529f\u80fd\u5f37\u5927\u7684\u5de5\u5177\u4f86\u5354\u52a9\u7528\u6236\u9032\u884c\u6578\u64da\u5eab\u6f0f\u6d1e\u7684\u6aa2\u6e2c\uff0c\u5176\u4e2dKali2\u66f4\u662f\u5176\u6700\u65b0\u7248\u672c\uff0c\u5177\u5099\u4e86\u66f4\u5f37\u7684\u529f\u80fd\u548c\u66f4\u53cb\u597d\u7684\u4f7f\u7528\u754c\u9762\u3002<\/p>\n<h2 id=\"kali2%e7%9a%84%e5%9f%ba%e6%9c%ac%e4%bb%8b%e7%b4%b9-DTtpGpdvYc\">Kali2\u7684\u57fa\u672c\u4ecb\u7d39<\/h2>\n<p>Kali Linux\u662f\u4e00\u500b\u57fa\u65bcDebian\u7684Linux\u767c\u884c\u7248\uff0c\u5c08\u70ba\u6ef2\u900f\u6e2c\u8a66\u548c\u6578\u64da\u5b89\u5168\u800c\u8a2d\u8a08\u3002Kali2\u4f5c\u70ba\u5176\u6700\u65b0\u7248\u672c\uff0c\u96c6\u6210\u4e86\u5927\u91cf\u7684\u5b89\u5168\u6e2c\u8a66\u5de5\u5177\uff0c\u7279\u5225\u662f\u5728\u6578\u64da\u5eab\u5b89\u5168\u65b9\u9762\uff0c\u63d0\u4f9b\u4e86\u591a\u7a2e\u6aa2\u6e2c\u548c\u653b\u64ca\u5de5\u5177\uff0c\u5982SQLMap\u3001Metasploit\u548cBurp Suite\u7b49\u3002<\/p>\n<h2 id=\"%e6%95%b8%e6%93%9a%e5%ba%ab%e6%bc%8f%e6%b4%9e%e7%9a%84%e9%a1%9e%e5%9e%8b-DTtpGpdvYc\">\u6578\u64da\u5eab\u6f0f\u6d1e\u7684\u985e\u578b<\/h2>\n<p>\u5728\u9032\u884c\u6578\u64da\u5eab\u6f0f\u6d1e\u6aa2\u6e2c\u4e4b\u524d\uff0c\u4e86\u89e3\u5e38\u898b\u7684\u6578\u64da\u5eab\u6f0f\u6d1e\u985e\u578b\u662f\u975e\u5e38\u91cd\u8981\u7684\u3002\u4ee5\u4e0b\u662f\u4e00\u4e9b\u5e38\u898b\u7684\u6578\u64da\u5eab\u6f0f\u6d1e\uff1a<\/p>\n<ul>\n<li><strong>SQL\u6ce8\u5165\uff08SQL Injection\uff09<\/strong>\uff1a\u653b\u64ca\u8005\u901a\u904e\u5728SQL\u67e5\u8a62\u4e2d\u63d2\u5165\u60e1\u610f\u4ee3\u78bc\uff0c\u4f86\u64cd\u63a7\u6578\u64da\u5eab\u3002<\/li>\n<li><strong>\u672a\u7d93\u6388\u6b0a\u7684\u8a2a\u554f<\/strong>\uff1a\u653b\u64ca\u8005\u5229\u7528\u5f31\u5bc6\u78bc\u6216\u6f0f\u6d1e\uff0c\u7372\u53d6\u6578\u64da\u5eab\u7684\u7ba1\u7406\u6b0a\u9650\u3002<\/li>\n<li><strong>\u6578\u64da\u6cc4\u9732<\/strong>\uff1a\u7531\u65bc\u914d\u7f6e\u4e0d\u7576\u6216\u6f0f\u6d1e\uff0c\u654f\u611f\u6578\u64da\u88ab\u672a\u7d93\u6388\u6b0a\u7684\u7528\u6236\u8a2a\u554f\u3002<\/li>\n<li><strong>\u8de8\u7ad9\u8173\u672c\uff08XSS\uff09<\/strong>\uff1a\u653b\u64ca\u8005\u5728\u6578\u64da\u5eab\u4e2d\u6ce8\u5165\u60e1\u610f\u8173\u672c\uff0c\u7576\u7528\u6236\u8a2a\u554f\u6642\u57f7\u884c\u3002<\/li>\n<\/ul>\n<h2 id=\"kali2%e4%b8%ad%e7%9a%84%e6%95%b8%e6%93%9a%e5%ba%ab%e6%bc%8f%e6%b4%9e%e6%aa%a2%e6%b8%ac%e5%b7%a5%e5%85%b7-DTtpGpdvYc\">Kali2\u4e2d\u7684\u6578\u64da\u5eab\u6f0f\u6d1e\u6aa2\u6e2c\u5de5\u5177<\/h2>\n<p>Kali2\u63d0\u4f9b\u4e86\u591a\u7a2e\u5de5\u5177\u4f86\u5354\u52a9\u7528\u6236\u6aa2\u6e2c\u6578\u64da\u5eab\u6f0f\u6d1e\uff0c\u4ee5\u4e0b\u662f\u5e7e\u500b\u4e3b\u8981\u5de5\u5177\u7684\u4ecb\u7d39\uff1a<\/p>\n<h3 id=\"1-sqlmap-DTtpGpdvYc\">1. SQLMap<\/h3>\n<p>SQLMap\u662f\u4e00\u500b\u958b\u6e90\u7684\u6ef2\u900f\u6e2c\u8a66\u5de5\u5177\uff0c\u5c08\u9580\u7528\u65bc\u81ea\u52d5\u5316\u6aa2\u6e2c\u548c\u5229\u7528SQL\u6ce8\u5165\u6f0f\u6d1e\u3002\u7528\u6236\u53ea\u9700\u63d0\u4f9b\u76ee\u6a19URL\u548c\u53c3\u6578\uff0cSQLMap\u4fbf\u80fd\u81ea\u52d5\u8b58\u5225\u4e26\u5229\u7528\u6f0f\u6d1e\uff0c\u4e26\u63d0\u4f9b\u8a73\u7d30\u7684\u5831\u544a\u3002<\/p>\n<pre><code>sqlmap -u \"http:\/\/example.com\/vuln.php?id=1\" --dbs<\/code><\/pre>\n<h3 id=\"2-metasploit-DTtpGpdvYc\">2. Metasploit<\/h3>\n<p>Metasploit\u662f\u4e00\u500b\u5f37\u5927\u7684\u6ef2\u900f\u6e2c\u8a66\u6846\u67b6\uff0c\u63d0\u4f9b\u4e86\u591a\u7a2e\u6a21\u584a\u4f86\u9032\u884c\u6578\u64da\u5eab\u653b\u64ca\u3002\u7528\u6236\u53ef\u4ee5\u5229\u7528Metasploit\u4e2d\u7684\u6a21\u584a\u4f86\u9032\u884cSQL\u6ce8\u5165\u3001\u672a\u7d93\u6388\u6b0a\u8a2a\u554f\u7b49\u653b\u64ca\u3002<\/p>\n<pre><code>use exploit\/multi\/http\/struts_code_exec<\/code><\/pre>\n<h3 id=\"3-burp-suite-DTtpGpdvYc\">3. Burp Suite<\/h3>\n<p>Burp Suite\u662f\u4e00\u500b\u96c6\u6210\u7684\u7db2\u7d61\u61c9\u7528\u7a0b\u5e8f\u5b89\u5168\u6e2c\u8a66\u5e73\u53f0\uff0c\u63d0\u4f9b\u4e86\u591a\u7a2e\u5de5\u5177\u4f86\u6aa2\u6e2c\u548c\u5229\u7528\u6578\u64da\u5eab\u6f0f\u6d1e\u3002\u7528\u6236\u53ef\u4ee5\u901a\u904e\u5176\u6514\u622a\u4ee3\u7406\u529f\u80fd\uff0c\u5206\u6790HTTP\u8acb\u6c42\u548c\u97ff\u61c9\uff0c\u5f9e\u800c\u767c\u73fe\u6f5b\u5728\u7684\u6f0f\u6d1e\u3002<\/p>\n<h2 id=\"%e5%a6%82%e4%bd%95%e4%bd%bf%e7%94%a8kali2%e9%80%b2%e8%a1%8c%e6%95%b8%e6%93%9a%e5%ba%ab%e6%bc%8f%e6%b4%9e%e6%aa%a2%e6%b8%ac-DTtpGpdvYc\">\u5982\u4f55\u4f7f\u7528Kali2\u9032\u884c\u6578\u64da\u5eab\u6f0f\u6d1e\u6aa2\u6e2c<\/h2>\n<p>\u4f7f\u7528Kali2\u9032\u884c\u6578\u64da\u5eab\u6f0f\u6d1e\u6aa2\u6e2c\u7684\u904e\u7a0b\u901a\u5e38\u5305\u62ec\u4ee5\u4e0b\u5e7e\u500b\u6b65\u9a5f\uff1a<\/p>\n<ol>\n<li><strong>\u74b0\u5883\u8a2d\u7f6e<\/strong>\uff1a\u5b89\u88ddKali2\u4e26\u914d\u7f6e\u5fc5\u8981\u7684\u5de5\u5177\u3002<\/li>\n<li><strong>\u4fe1\u606f\u6536\u96c6<\/strong>\uff1a\u4f7f\u7528\u5de5\u5177\u5982Nmap\u9032\u884c\u76ee\u6a19\u6383\u63cf\uff0c\u6536\u96c6\u76ee\u6a19\u7684\u6578\u64da\u5eab\u4fe1\u606f\u3002<\/li>\n<li><strong>\u6f0f\u6d1e\u6aa2\u6e2c<\/strong>\uff1a\u4f7f\u7528SQLMap\u7b49\u5de5\u5177\u9032\u884c\u6f0f\u6d1e\u6aa2\u6e2c\u3002<\/li>\n<li><strong>\u6f0f\u6d1e\u5229\u7528<\/strong>\uff1a\u5982\u679c\u767c\u73fe\u6f0f\u6d1e\uff0c\u4f7f\u7528Metasploit\u7b49\u5de5\u5177\u9032\u884c\u5229\u7528\u3002<\/li>\n<li><strong>\u5831\u544a\u751f\u6210<\/strong>\uff1a\u751f\u6210\u8a73\u7d30\u7684\u6aa2\u6e2c\u5831\u544a\uff0c\u4e26\u63d0\u51fa\u4fee\u88dc\u5efa\u8b70\u3002<\/li>\n<\/ol>\n<h2 id=\"%e7%b8%bd%e7%b5%90-DTtpGpdvYc\">\u7e3d\u7d50<\/h2>\n<p>Kali2\u4f5c\u70ba\u4e00\u6b3e\u5c08\u696d\u7684\u6578\u64da\u5eab\u6f0f\u6d1e\u6aa2\u6e2c\u5de5\u5177\uff0c\u70ba\u4fe1\u606f\u5b89\u5168\u5c08\u5bb6\u63d0\u4f9b\u4e86\u5f37\u5927\u7684\u652f\u6301\u3002\u901a\u904e\u4f7f\u7528Kali2\u4e2d\u7684\u5404\u7a2e\u5de5\u5177\uff0c\u4f01\u696d\u548c\u500b\u4eba\u7528\u6236\u53ef\u4ee5\u6709\u6548\u5730\u6aa2\u6e2c\u548c\u4fee\u88dc\u6578\u64da\u5eab\u6f0f\u6d1e\uff0c\u5f9e\u800c\u63d0\u9ad8\u6578\u64da\u5b89\u5168\u6027\u3002\u5c0d\u65bc\u9700\u8981\u9ad8\u6548\u3001\u5b89\u5168\u7684\u6578\u64da\u5eab\u7ba1\u7406\u7684\u7528\u6236\uff0c\u9078\u64c7\u5408\u9069\u7684<code><a href=\"https:\/\/server.hk\">\u9999\u6e2fVPS<\/a><\/code>\u6216<code><a href=\"https:\/\/server.hk\">\u9999\u6e2f\u4f3a\u670d\u5668<\/a><\/code>\u89e3\u6c7a\u65b9\u6848\u4e5f\u662f\u81f3\u95dc\u91cd\u8981\u7684\uff0c\u9019\u6a23\u53ef\u4ee5\u78ba\u4fdd\u6578\u64da\u5eab\u7684\u7a69\u5b9a\u6027\u548c\u5b89\u5168\u6027\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kali2\u662f\u5c08\u696d\u6aa2\u6e2c\u6578\u64da\u5eab\u6f0f\u6d1e\u7684\u5fc5\u5099\u5229\u5668\uff0c\u63d0\u4f9b\u9ad8\u6548\u3001\u6e96\u78ba\u7684\u5b89\u5168\u6e2c\u8a66\uff0c\u4fdd\u969c\u60a8\u7684\u6578\u64da\u5b89\u5168\u3002<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[101],"tags":[],"class_list":["post-62195","post","type-post","status-publish","format-standard","hentry","category-database"],"_links":{"self":[{"href":"https:\/\/server.hk\/cnblog\/wp-json\/wp\/v2\/posts\/62195","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/server.hk\/cnblog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/server.hk\/cnblog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/server.hk\/cnblog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/server.hk\/cnblog\/wp-json\/wp\/v2\/comments?post=62195"}],"version-history":[{"count":1,"href":"https:\/\/server.hk\/cnblog\/wp-json\/wp\/v2\/posts\/62195\/revisions"}],"predecessor-version":[{"id":62196,"href":"https:\/\/server.hk\/cnblog\/wp-json\/wp\/v2\/posts\/62195\/revisions\/62196"}],"wp:attachment":[{"href":"https:\/\/server.hk\/cnblog\/wp-json\/wp\/v2\/media?parent=62195"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/server.hk\/cnblog\/wp-json\/wp\/v2\/categories?post=62195"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/server.hk\/cnblog\/wp-json\/wp\/v2\/tags?post=62195"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}