{"id":160,"date":"2017-07-07T16:45:50","date_gmt":"2017-07-07T08:45:50","guid":{"rendered":"https:\/\/www.espandy.com\/?p=160"},"modified":"2017-07-07T16:49:31","modified_gmt":"2017-07-07T08:49:31","slug":"nishang-powershell%e4%b8%8b%e7%9a%84%e6%94%bb%e5%87%bb%e6%a1%86%e6%9e%b6","status":"publish","type":"post","link":"https:\/\/www.espandy.com\/?p=160","title":{"rendered":"nishang\u2014\u2014PowerShell\u4e0b\u7684\u653b\u51fb\u6846\u67b6"},"content":{"rendered":"<h1>nishang\u2014\u2014PowerShell\u4e0b\u7684\u653b\u51fb\u6846\u67b6<\/h1>\n<h3>\u7b80\u4ecb<\/h3>\n<p><em style=\"line-height: 1.6;\">Nishang\u662f\u4e00\u4e2aPowerShell\u653b\u51fb\u6846\u67b6\uff0c\u5b83\u662fPowerShell\u653b\u51fb\u811a\u672c\u548c\u6709\u6548\u8f7d\u8377\u7684\u4e00\u4e2a\u96c6\u5408\u3002<\/em><br \/>\n<em style=\"line-height: 1.6;\">Powershell\u662fwindows\u4e0b\u9762\u975e\u5e38\u5f3a\u5927\u7684\u547d\u4ee4\u884c\u5de5\u5177\uff0c\u5e76\u4e14\u5728windows\u4e2dPowershell\u53ef\u4ee5\u5229\u7528.NET Framework\u7684\u5f3a\u5927\u529f\u80fd\uff0c\u4e5f\u53ef\u4ee5\u8c03\u7528windows API\uff0c\u5728win7\/server 2008\u4ee5\u540e\uff0cpowershell\u5df2\u88ab\u96c6\u6210\u5728\u7cfb\u7edf\u5f53\u4e2d\u3002<\/em><\/p>\n<ul>\n<li>\u5de5\u5177\u4e0b\u8f7d\u5730\u5740\n<p><em style=\"line-height: 1.6;\"><a href=\"https:\/\/github.com\/samratashok\/nishang\" target=\"_blank\" rel=\"noopener\">https:\/\/github.com\/samratashok\/nishang<\/a><\/em><\/p>\n<p>\u76ee\u5f55\u7ed3\u6784\u5982\u4e0b\uff1a<\/li>\n<\/ul>\n<p><img decoding=\"async\" data-original=\"https:\/\/www.espandy.com\/wp-content\/uploads\/2017\/07\/aadc0624bc0df872a890bd2e74289b53.png\" src=\"https:\/\/www.espandy.com\/wp-content\/themes\/9iphp\/images\/lazy_loading.gif\" \/><\/p>\n<h3>\u7b80\u5355\u7684\u5b89\u88c5<\/h3>\n<ul>\n<li>1.\u76f4\u63a5\u901a\u8fc7git\u547d\u4ee4\u76f4\u63a5\u4e0b\u8f7d\n<p><em style=\"line-height: 1.6;\">\u4f5c\u8005\u8bf4\u9700\u8981PowerShell 3.0\u4ee5\u4e0a\uff0c\u56e0\u4e3awin7\u81ea\u5e26\u7684\u73af\u5883\u662fPowerShell 2.0\uff0c\u53ef\u80fd\u4f1a\u6709\u95ee\u9898\u3002\u672c\u4ebawin8.<\/em><\/p>\n<p><em style=\"line-height: 1.6;\">\u53ef\u4ee5\u901a\u8fc7\u547d\u4ee4Get-Host\u67e5\u770b<\/em><\/li>\n<\/ul>\n<pre><code>Get-Host\r\n<\/code><\/pre>\n<p><img decoding=\"async\" data-original=\"https:\/\/www.espandy.com\/wp-content\/uploads\/2017\/07\/fb821e7d9aecc50408efa486b52ad705.png\" src=\"https:\/\/www.espandy.com\/wp-content\/themes\/9iphp\/images\/lazy_loading.gif\" \/><\/p>\n<ul>\n<li>2.\u5bfc\u5165\u6846\u67b6(\u6ce8\u610f\u8def\u5f84\u95ee\u9898)<\/li>\n<\/ul>\n<pre><code>Import-Module .\\nishang.psm1\r\n<\/code><\/pre>\n<p><em style=\"line-height: 1.6;\">\u5bfc\u5165\u65f6\u9047\u5230\u7684\u7684\u95ee\u9898<\/em><\/p>\n<p><img decoding=\"async\" data-original=\"https:\/\/www.espandy.com\/wp-content\/uploads\/2017\/07\/3a695d448425a0a9bc657d2c22c5a451.png\" src=\"https:\/\/www.espandy.com\/wp-content\/themes\/9iphp\/images\/lazy_loading.gif\" \/><\/p>\n<p>\u89e3\u51b3\u65b9\u6cd5:<\/p>\n<p><em style=\"line-height: 1.6;\">PowerShell\u9ed8\u8ba4\u7684\u6267\u884c\u7b56\u7565\u662fRestricted\uff0c\u4f46\u662fRestricted\u662f\u4e0d\u5141\u8bb8\u8fd0\u884c\u4efb\u4f55\u811a\u672c\u7684\u3002\u4f60\u5728PowerShell\u6267\u884cGet-ExecutionPolicy\u547d\u4ee4\u6765\u67e5\u770b\u9ed8\u8ba4\u7684\u7b56\u7565\u7ec4\u3002\u6211\u4eec\u9700\u8981\u4fee\u6539\u7b56\u7565\u7ec4\uff0c\u5728PowerShell\u4e0b\u6267\u884c<\/em><\/p>\n<pre><code>Set-ExecutionPolicy Bypass\r\n<\/code><\/pre>\n<p><em style=\"line-height: 1.6;\">\u518d\u6b21\u5bfc\u5165\uff0c\u5c31\u5bfc\u5165\u6210\u529f\u4e86\u3002\uff08\u8b66\u544a\u4e0d\u9700\u8981\u7406\u4f1a\uff09<\/em><\/p>\n<p><img decoding=\"async\" data-original=\"https:\/\/www.espandy.com\/wp-content\/uploads\/2017\/07\/17488c7577779e1440d533b1e6820d88.png\" src=\"https:\/\/www.espandy.com\/wp-content\/themes\/9iphp\/images\/lazy_loading.gif\" \/><\/p>\n<p>Policy\u7684\u6709\u6548\u53c2\u6570:<\/p>\n<ul>\n<li>Restricted: \u4e0d\u8f7d\u5165\u4efb\u4f55\u914d\u7f6e\u6587\u4ef6\uff0c\u4e0d\u8fd0\u884c\u4efb\u4f55\u811a\u672c\u3002 \u201cRestricted\u201d \u662f\u9ed8\u8ba4\u7684\u3002<\/li>\n<li>AllSigned: \u53ea\u6709\u88abTrusted publisher\u7b7e\u540d\u7684\u811a\u672c\u6216\u8005\u914d\u7f6e\u6587\u4ef6\u624d\u80fd\u4f7f\u7528\uff0c\u5305\u62ec\u4f60\u81ea\u5df1\u518d\u672c\u5730\u5199\u7684\u811a\u672c<\/li>\n<li>RemoteSigned: \u5bf9\u4e8e\u4eceInternet\u4e0a\u4e0b\u8f7d\u7684\u811a\u672c\u6216\u8005\u914d\u7f6e\u6587\u4ef6\uff0c\u53ea\u6709\u88abTrusted publisher\u7b7e\u540d\u7684\u624d\u80fd\u4f7f\u7528\u3002<\/li>\n<li>Unrestricted: \u53ef\u4ee5\u8f7d\u5165\u6240\u6709\u914d\u7f6e\u6587\u4ef6\uff0c\u53ef\u4ee5\u8fd0\u884c\u6240\u6709\u811a\u672c\u6587\u4ef6. \u5982\u679c\u4f60\u8fd0\u884c\u4e00\u4e2a\u4eceinternet\u4e0b\u8f7d\u5e76\u4e14\u6ca1\u6709\u7b7e\u540d\u7684\u811a\u672c\uff0c\u5728\u8fd0\u884c\u4e4b\u524d\uff0c\u4f60\u4f1a\u88ab\u63d0\u793a\u9700\u8981\u4e00\u5b9a\u7684\u6743\u9650\u3002<\/li>\n<li>Bypass: \u6240\u6709\u4e1c\u897f\u90fd\u53ef\u4ee5\u4f7f\u7528\uff0c\u5e76\u4e14\u6ca1\u6709\u63d0\u793a\u548c\u8b66\u544a.<\/li>\n<li>Undefined: \u5220\u9664\u5f53\u524dscope\u88ab\u8d4b\u4e88\u7684Execution Policy. \u4f46\u662fGroup Policy scope\u7684Execution Policy\u4e0d\u4f1a\u88ab\u5220\u9664.<\/li>\n<\/ul>\n<h3>\u5de5\u5177\u7684\u4f7f\u7528<\/h3>\n<p>\u5148\u770b\u770b\u90fd\u6709\u4ec0\u4e48\u53ef\u7528\u7684\u547d\u4ee4\u5427<\/p>\n<pre><code>Get-Command -Module nishang\r\n<\/code><\/pre>\n<p><img decoding=\"async\" data-original=\"https:\/\/www.espandy.com\/wp-content\/uploads\/2017\/07\/8758659b7b46293435c7c5c2b2777af4.png\" src=\"https:\/\/www.espandy.com\/wp-content\/themes\/9iphp\/images\/lazy_loading.gif\" \/><\/p>\n<ul>\n<li>\u5220\u9664\u8865\u4e01<\/li>\n<\/ul>\n<pre><code>Remove-Update\r\n<\/code><\/pre>\n<p><img decoding=\"async\" data-original=\"https:\/\/www.espandy.com\/wp-content\/uploads\/2017\/07\/34540249794c51bc9a3f35fb6e5857f4.png\" src=\"https:\/\/www.espandy.com\/wp-content\/themes\/9iphp\/images\/lazy_loading.gif\" \/><br \/>\n<em style=\"line-height: 1.6;\">\u5b9e\u4f8b\u4e00: \u5220\u9664\u5168\u90e8\u8865\u4e01<\/em><\/p>\n<p><em style=\"line-height: 1.6;\">\u5b9e\u4f8b\u4e8c: \u5220\u9664\u5168\u90e8\u7684\u5b89\u5168\u8865\u4e01<\/em><\/p>\n<p><em style=\"line-height: 1.6;\">\u5b9e\u4f8b\u4e09: \u5220\u9664\u6307\u5b9a\u7684\u8865\u4e01<\/em><\/p>\n<ul>\n<li>\u5f31\u53e3\u4ee4\u7206\u7834<\/li>\n<\/ul>\n<pre><code>Invoke-BruteForce\r\n<\/code><\/pre>\n<p><em style=\"line-height: 1.6;\">ComputerName \u5bf9\u5e94\u670d\u52a1\u7684\u8ba1\u7b97\u673a\u540d<\/em><\/p>\n<p><em style=\"line-height: 1.6;\">UserList \u7528\u6237\u540d\u5b57\u5178<\/em><\/p>\n<p><em style=\"line-height: 1.6;\">PasswordList \u5bc6\u7801\u5b57\u5178<\/em><\/p>\n<p><em style=\"line-height: 1.6;\">Service \u670d\u52a1\uff08\u9ed8\u8ba4\u4e3a\uff1aSQL\uff09<\/em><\/p>\n<p><em style=\"line-height: 1.6;\">-StopOnSuccess \u5339\u914d\u4e00\u4e2a\u540e\u505c\u6b62<\/em><\/p>\n<p><em style=\"line-height: 1.6;\">Delay \u5ef6\u8fdf\u65f6\u95f4<\/em><\/p>\n<h3>\u6700\u540e<\/h3>\n<p>\u6211\u8fd9\u91cc\u4e5f\u53ea\u662f\u7b80\u5355\u5c1d\u8bd5\u4e86\u4e00\u4e0b\uff0c\u8fd8\u6ca1\u6709\u6df1\u5165\uff0c\u6709\u5174\u8da3\u7684\u670b\u53cb\u53ef\u4ee5\u81ea\u884c\u7814\u7a76\uff0c<\/p>\n<h3>\u9644\u4e0a\u51e0\u4e2a\u66f4\u8be6\u7ec6\u8fde\u63a5\uff0c\u5927\u5bb6\u8d76\u7d27\u8bd5\u8bd5\u5427<\/h3>\n<ul>\n<li>Powershell \u6e17\u900f\u6d4b\u8bd5\u5de5\u5177-Nishang\uff08\u4e00\uff09\n<p><em style=\"line-height: 1.6;\"><a href=\"http:\/\/bobao.360.cn\/learning\/detail\/3182.html\" target=\"_blank\" rel=\"noopener\">http:\/\/bobao.360.cn\/learning\/detail\/3182.html<\/a><\/em><\/p>\n<p>-Powershell \u6e17\u900f\u6d4b\u8bd5\u5de5\u5177-Nishang\uff08\u4e8c\uff09<\/p>\n<p><em style=\"line-height: 1.6;\"><a href=\"http:\/\/bobao.360.cn\/learning\/detail\/3200.html\" target=\"_blank\" rel=\"noopener\">http:\/\/bobao.360.cn\/learning\/detail\/3200.html<\/a><\/em><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>nishang\u2014\u2014PowerShell\u4e0b\u7684\u653b\u51fb\u6846\u67b6<\/p>\n<p>\u7b80\u4ecb<\/p>\n<p>Nishang\u662f\u4e00\u4e2aPowerShell\u653b\u51fb\u6846\u67b6\uff0c\u5b83\u662fPowerShell\u653b\u51fb\u811a\u672c\u548c\u6709\u6548\u8f7d\u8377\u7684\u4e00\u4e2a\u96c6\u5408\u3002<br \/>\n    Powershell\u662fwindows\u4e0b\u9762\u975e\u5e38\u5f3a\u5927\u7684\u547d\u4ee4\u884c\u5de5\u5177\uff0c\u5e76\u4e14\u5728windows\u4e2dPowershell\u53ef\u4ee5\u5229\u7528.NET Framework\u7684\u5f3a\u5927\u529f\u80fd\uff0c\u4e5f\u53ef\u4ee5\u8c03\u7528windows API\uff0c\u5728win7\/server 2008\u4ee5\u540e\uff0cpowershell\u5df2\u88ab\u96c6\u6210\u5728\u7cfb\u7edf\u5f53\u4e2d\u3002<\/p>\n","protected":false},"author":1,"featured_media":154,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[3],"tags":[17,16],"class_list":["post-160","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech","tag-nishang","tag-powershell"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/www.espandy.com\/wp-content\/uploads\/2017\/07\/aadc0624bc0df872a890bd2e74289b53.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.espandy.com\/index.php?rest_route=\/wp\/v2\/posts\/160","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.espandy.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.espandy.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.espandy.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.espandy.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=160"}],"version-history":[{"count":1,"href":"https:\/\/www.espandy.com\/index.php?rest_route=\/wp\/v2\/posts\/160\/revisions"}],"predecessor-version":[{"id":161,"href":"https:\/\/www.espandy.com\/index.php?rest_route=\/wp\/v2\/posts\/160\/revisions\/161"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.espandy.com\/index.php?rest_route=\/wp\/v2\/media\/154"}],"wp:attachment":[{"href":"https:\/\/www.espandy.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=160"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.espandy.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=160"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.espandy.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=160"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}