ms12-020漏洞利用
实验环境
1.kali linux(ip:192.168.131.131)
2.Windows xp(ip:192.168.131.134)(靶机)
漏洞发现
利用nmap工具扫描端口、看其3389端口是否开放;
root@kali:~# nmap 192.168.131.134
Starting Nmap 7.70 ( https://nmap.org ) at 2020-09-10 14:17 CST
Nmap scan report for 192.168.131.134
Host is up (0.00010s latency).
Not shown: 995 closed ports
PORT STATE SERVICE
23/tcp open telnet
135/tcp open msrpc
139/tcp open netbios-ssn
445/tcp open microsoft-ds
3389/tcp open ms-wbt-server
MAC Address: 00:0C:29:B1:96:23 (VMware)
Nmap done: 1 IP address (1 host up) scanned in 3.06 seconds
漏洞利用
1.打开kali的msf;搜索ms12-020;(命令:search ms12-020)
[i] Database already started
[i] The database appears to be already configured, skipping initialization