小談RADMIN的幾個(gè)小技巧
更新時(shí)間:2007年10月08日 22:46:30 作者:
轉(zhuǎn)載請(qǐng)保留版權(quán)信息!謝謝合作!
by NetPatch
welcome www.nspcn.org and www.icehack.com
最近做滲透測(cè)試時(shí)常碰到RADMIN一類的東西..
一碰到此類的程序,一般我都會(huì)先看下對(duì)方把RADMIN的端口配置成什么..以及相應(yīng)的PASS(加密過(guò)的)
HKEY_LOCAL_MACHINE\SYSTEM\RAdmin\v2.0\Server\Parameters\Parameter //默認(rèn)密碼注冊(cè)表位置
HKEY_LOCAL_MACHINE\SYSTEM\RAdmin\v2.0\Server\Parameters\Port //默認(rèn)端口注冊(cè)表位置
//把海陽(yáng)讀出來(lái)的,用逗號(hào)格開(kāi),然后用下面的代碼轉(zhuǎn)換就可以了
[Copy to clipboard] [ - ]CODE:
Dim theStr
theStr = InputBox( "請(qǐng)輸入要轉(zhuǎn)換的密碼:", "輸入", "44,41,43,32,43,5,45,64,43,24,31,53,46,57,64,86" )
If theStr <> "" Then
Call InputBox("請(qǐng)復(fù)制已經(jīng)轉(zhuǎn)換好的密碼",,zpass(theStr))
End If
Function zpass(pass)
tpass=""
MyArray = Split(pass, ",", -1, 1)
For each thepass in MyArray
if len(thepass) = 1 then
tpass=tpass+"0"
end if
tpass=tpass+hex(thepass)
Next
zpass=tpass
End Function
//轉(zhuǎn)換后的,就可以拿爆破工具去跑了....
端口讀出后類似這樣 223,34,0,0
//用下面代碼轉(zhuǎn)換即可
[Copy to clipboard] [ - ]CODE:
Dim theStr
theStr = InputBox( "請(qǐng)輸入要轉(zhuǎn)換的端口:", "輸入", "223,34,0,0," )
da = Split(thestr, ",", -1, 1)
If theStr <> "" Then
Call InputBox("請(qǐng)復(fù)制已經(jīng)轉(zhuǎn)換好的端口",,Hex2Dec(Dec2Hex(da(3))&Dec2Hex(da(2))&Dec2Hex(da(1))&Dec2Hex(da(0))))
End If
Function Hex2Dec(Hex)
Hex = UCase(Hex)
For i = 1 To Len(Hex)
Select Case Mid(Hex, Len(Hex) - i + 1, 1)
Case "0": B = B + 16 ^ (i - 1) * 0
Case "1": B = B + 16 ^ (i - 1) * 1
Case "2": B = B + 16 ^ (i - 1) * 2
Case "3": B = B + 16 ^ (i - 1) * 3
Case "4": B = B + 16 ^ (i - 1) * 4
Case "5": B = B + 16 ^ (i - 1) * 5
Case "6": B = B + 16 ^ (i - 1) * 6
Case "7": B = B + 16 ^ (i - 1) * 7
Case "8": B = B + 16 ^ (i - 1) * 8
Case "9": B = B + 16 ^ (i - 1) * 9
Case "A": B = B + 16 ^ (i - 1) * 10
Case "B": B = B + 16 ^ (i - 1) * 11
Case "C": B = B + 16 ^ (i - 1) * 12
Case "D": B = B + 16 ^ (i - 1) * 13
Case "E": B = B + 16 ^ (i - 1) * 14
Case "F": B = B + 16 ^ (i - 1) * 15
End Select
Next
Hex2Dec = B
End Function
Function Dec2Hex(Dec)
Dec2Hex = ""
Do While Dec > 0
a = CStr(Dec Mod 16)
Select Case a
Case "10": a = "A"
Case "11": a = "B"
Case "12": a = "C"
Case "13": a = "D"
Case "14": a = "E"
Case "15": a = "F"
End Select
Dec2Hex = a & Dec2Hex
Dec = Dec \ 16
Loop
End Function
by NetPatch
welcome www.nspcn.org and www.icehack.com
最近做滲透測(cè)試時(shí)常碰到RADMIN一類的東西..
一碰到此類的程序,一般我都會(huì)先看下對(duì)方把RADMIN的端口配置成什么..以及相應(yīng)的PASS(加密過(guò)的)
HKEY_LOCAL_MACHINE\SYSTEM\RAdmin\v2.0\Server\Parameters\Parameter //默認(rèn)密碼注冊(cè)表位置
HKEY_LOCAL_MACHINE\SYSTEM\RAdmin\v2.0\Server\Parameters\Port //默認(rèn)端口注冊(cè)表位置
//把海陽(yáng)讀出來(lái)的,用逗號(hào)格開(kāi),然后用下面的代碼轉(zhuǎn)換就可以了
[Copy to clipboard] [ - ]CODE:
Dim theStr
theStr = InputBox( "請(qǐng)輸入要轉(zhuǎn)換的密碼:", "輸入", "44,41,43,32,43,5,45,64,43,24,31,53,46,57,64,86" )
If theStr <> "" Then
Call InputBox("請(qǐng)復(fù)制已經(jīng)轉(zhuǎn)換好的密碼",,zpass(theStr))
End If
Function zpass(pass)
tpass=""
MyArray = Split(pass, ",", -1, 1)
For each thepass in MyArray
if len(thepass) = 1 then
tpass=tpass+"0"
end if
tpass=tpass+hex(thepass)
Next
zpass=tpass
End Function
//轉(zhuǎn)換后的,就可以拿爆破工具去跑了....
端口讀出后類似這樣 223,34,0,0
//用下面代碼轉(zhuǎn)換即可
[Copy to clipboard] [ - ]CODE:
Dim theStr
theStr = InputBox( "請(qǐng)輸入要轉(zhuǎn)換的端口:", "輸入", "223,34,0,0," )
da = Split(thestr, ",", -1, 1)
If theStr <> "" Then
Call InputBox("請(qǐng)復(fù)制已經(jīng)轉(zhuǎn)換好的端口",,Hex2Dec(Dec2Hex(da(3))&Dec2Hex(da(2))&Dec2Hex(da(1))&Dec2Hex(da(0))))
End If
Function Hex2Dec(Hex)
Hex = UCase(Hex)
For i = 1 To Len(Hex)
Select Case Mid(Hex, Len(Hex) - i + 1, 1)
Case "0": B = B + 16 ^ (i - 1) * 0
Case "1": B = B + 16 ^ (i - 1) * 1
Case "2": B = B + 16 ^ (i - 1) * 2
Case "3": B = B + 16 ^ (i - 1) * 3
Case "4": B = B + 16 ^ (i - 1) * 4
Case "5": B = B + 16 ^ (i - 1) * 5
Case "6": B = B + 16 ^ (i - 1) * 6
Case "7": B = B + 16 ^ (i - 1) * 7
Case "8": B = B + 16 ^ (i - 1) * 8
Case "9": B = B + 16 ^ (i - 1) * 9
Case "A": B = B + 16 ^ (i - 1) * 10
Case "B": B = B + 16 ^ (i - 1) * 11
Case "C": B = B + 16 ^ (i - 1) * 12
Case "D": B = B + 16 ^ (i - 1) * 13
Case "E": B = B + 16 ^ (i - 1) * 14
Case "F": B = B + 16 ^ (i - 1) * 15
End Select
Next
Hex2Dec = B
End Function
Function Dec2Hex(Dec)
Dec2Hex = ""
Do While Dec > 0
a = CStr(Dec Mod 16)
Select Case a
Case "10": a = "A"
Case "11": a = "B"
Case "12": a = "C"
Case "13": a = "D"
Case "14": a = "E"
Case "15": a = "F"
End Select
Dec2Hex = a & Dec2Hex
Dec = Dec \ 16
Loop
End Function
相關(guān)文章
入侵ASP.net網(wǎng)站的經(jīng)驗(yàn)附利用代碼
愛(ài)好入侵的可以用下面的方法,做網(wǎng)站的朋友就需要了解下面的asp.net的利用代碼,最好來(lái)測(cè)試下2008-06-06創(chuàng)建c:\con.txt嗎?windows文件系統(tǒng)漏洞
2008-01-01