// 渗透测试
1 nmap 端口扫描

先用nmap探测存活主机和开放端口,识别服务版本,重点关注22/23/80/445/3306。

nmap 信息收集 Kali
2 MS17-010 永恒之蓝

nmap确认445→msfconsole搜索模块→设置IP和payload→Meterpreter shell。

MS17-010 漏洞利用 永恒之蓝
3 Metasploitable3 靶场

WebDAV PUT上传→PHP木马→蚁剑/冰蝎;SSH弱口令→hydra;binwalk隐写;PortScan内网。

Metasploitable3 WebDAV hydra binwalk
// eNSP
4 华为 AC+AP 无线网络配置

三层组网AC+核心+接入交换机,SSID huawei/laibin,VLAN101/102隧道,来宾隔离。

华为AC 无线网络 WEP VLAN
VRP Config — Huawei AC+AP
################ 接入交换机 ################
sysname Access-Switch
vlan batch 100 101 102
interface range GigabitEthernet 0/0/1 to GigabitEthernet 0/0/3
 port link-type trunk
 port trunk allow-pass vlan 100
 port trunk pvid vlan 100
 stp edgedport enable

################ 核心交换机 ################
sysname Core-Switch
vlan batch 10 to 102
dhcp enable
interface Vlanif102
 ip address 192.168.102.1 255.255.255.0
 dhcp select interface
 dhcp server dns-list 8.8.8.8 223.5.5.5

################ AC 无线控制器 ################
sysname AC
vlan batch 100 101 102
dhcp enable
interface Vlanif102
 ip address 192.168.102.254 255.255.255.0
 dhcp select interface
 dhcp server excluded-ip-address 192.168.102.1 192.168.102.100

wlan
 regulatory-domain-profile name domain_yewu
  country-code CN
 regulatory-domain-profile name domain_laibin
  country-code CN
 ap-group name yewu
  regulatory-domain-profile domain_yewu
  ap-id 0
   ap-mac 0000-0000-0001
   ap-name yewu
   ap-area yewu1
 ap-id 0
 ap-group name laibin
  regulatory-domain-profile domain_laibin
  ap-id 1
   ap-mac 0000-0000-0002
   ap-name laibin
   ap-area laibin1
 ap-id 1
 security-profile name security_yewu
  security wep
   wep share-key
   wep key 0 wep-40 pass-phrase a1234
   wep default-key 0
 security-profile name security_laibin
  security wep
   wep share-key
   wep key 0 wep-40 pass-phrase a1234
   wep default-key 0
 ssid-profile name ssid_yewu
  ssid huawei
  max-station 128
  association-timeout 1
  beacon-2g-rate 11
 ssid-profile name ssid_laibin
  ssid laibin
  max-station 128
  association-timeout 1
  beacon-2g-rate 11
 traffic-profile name traffic
  rate-limit client down 4000
  rate-limit client up 4000
  user-isolate layer 2
 vap-profile name vap_yewu
  forward tunnel
  service-vlan vlan-id 101
  ssid-profile ssid_yewu
  security-profile security_yewu
  traffic-profile traffic
  user-isolate 12
  anti-attack arp-flood
   sta-rate-threshold 100
 vap-profile name vap_laibin
  forward tunnel
  service-vlan vlan-id 102
  ssid-profile ssid_laibin
  security-profile security_laibin
  traffic-profile traffic
  user-isolate 12
  anti-attack arp-flood
   sta-rate-threshold 100
 ap-group name yewu
  vap-profile vap_yewu radio all
 ap-group name laibin
  vap-profile vap_laibin radio all
 interface GigabitEthernet 0/0/1
  ip source check user-bind enable
  arp anti-attack check user-bind enable
5 VLAN + TRUNK 实验

交换机VLAN10/20,trunk允许所有VLAN,路由器单臂路由子接口。

VLAN eNSP 路由交换
6 OSPF 动态路由配置

进程内声明网络段,area 0,cost值控制路由选路,DR/BDR选举。

OSPF 动态路由 网络工程
// 工具环境
7 Kali Linux 环境

nmap/msfvenom/msfconsole/hydra/searchsploit/aircrack-ng/Burp Suite。

Kali 工具集
8 VirtualBox 虚拟机

NAT/Host-Only/桥接网络模式。

VirtualBox 虚拟化