After penetration - within the network to forward the use EarthWorm and proxifier set up forward proxy server

EarthWorm is used to open a SOCKS v5 proxy services tools, standards-based C development, providing multi-platform communication between the adapter for data in complex network environments forwarding.
Proxifier is a very powerful socks5 client, allowing the network does not support the program through a proxy server to work through HTTPS or SOCKS proxy or proxy chain.

Forward
Victims of the Win2008
ew.exe ssocksd the -l -s 8000

Here Insert Picture Description

lab environment:

  • Windows Server 2008 R2 x64(192.168.70.128、10.1.1.1)
  • Windows Server 2003(10.1.1.2)
  • IIS server
  • EarthWorm
  • proxifier

Here Insert Picture Description

Environment to build:

Is win2008 add a network card, ip 10.1.1.1 set
Here Insert Picture Description
Here Insert Picture Description
Here Insert Picture Description

Win2003 network will choose to VM1
Here Insert Picture Description
will set ip 10.1.1.2
Here Insert Picture Description
Here Insert Picture Description
will win2003 IIS server to write web content, and can be accessed to ensure win2008
Here Insert Picture Description

Both machines are turned open the Remote Desktop
Here Insert Picture Description
Here Insert Picture Description
will be uploaded to the win2008 EarthWorm
Here Insert Picture Description

Here Insert Picture Description

Simulation:

Ew into the directory where the cd C:\Users\Administrator\Desktop\ew
Here Insert Picture Description
input on win2008ew.exe -s ssocksd -l 8000
Here Insert Picture Description

Then open proxifier software add proxy
Here Insert Picture Description
ip is win2008 the
Here Insert Picture Description
input win2003ip can access the web browser
Here Insert Picture Description
Remote Desktop can also be connected
Here Insert Picture Description
Here Insert Picture Description

Published 99 original articles · won praise 949 · Views 150,000 +

Guess you like

Origin blog.csdn.net/weixin_45728976/article/details/104952486