

  参考:Metasploit set rhosts file

msf > use auxiliary/scanner/smb/smb_ms17_010
msf auxiliary(smb_ms17_010) > show optionsModule options (auxiliary/scanner/smb/smb_ms17_010):Name        Current Setting  Required  Description----        ---------------  --------  -----------CHECK_DOPU  true             yes       Check for DOUBLEPULSAR on vulnerable hostsRHOSTS                       yes       The target address range or CIDR identifierRPORT       445              yes       The SMB service port (TCP)SMBDomain   .                no        The Windows domain to use for authenticationSMBPass                      no        The password for the specified usernameSMBUser                      no        The username to authenticate asTHREADS     1                yes       The number of concurrent threads



msf auxiliary(smb_ms17_010) > set rhosts file:/root/pentest/10-all.txt      # 设置读取的文件
rhosts => file:/root/pentest/10-all.txt
msf auxiliary(smb_ms17_010) > show optionsModule options (auxiliary/scanner/smb/smb_ms17_010):Name        Current Setting                Required  Description----        ---------------                --------  -----------CHECK_DOPU  true                           yes       Check for DOUBLEPULSAR on vulnerable hostsRHOSTS      file:/root/pentest/10-all.txt  yes       The target address range or CIDR identifierRPORT       445                            yes       The SMB service port (TCP)SMBDomain   .                              no        The Windows domain to use for authenticationSMBPass                                    no        The password for the specified usernameSMBUser                                    no        The username to authenticate asTHREADS     1                              yes       The number of concurrent threadsmsf auxiliary(smb_ms17_010) > set threads 10
threads => 10
msf auxiliary(smb_ms17_010) > show optionsModule options (auxiliary/scanner/smb/smb_ms17_010):Name        Current Setting                Required  Description----        ---------------                --------  -----------CHECK_DOPU  true                           yes       Check for DOUBLEPULSAR on vulnerable hostsRHOSTS      file:/root/pentest/10-all.txt  yes       The target address range or CIDR identifierRPORT       445                            yes       The SMB service port (TCP)SMBDomain   .                              no        The Windows domain to use for authenticationSMBPass                                    no        The password for the specified usernameSMBUser                                    no        The username to authenticate asTHREADS     10                             yes       The number of concurrent threads


msf auxiliary(smb_ms17_010) > spool ms17-010.txt         # 输出记录写入到文件
[*] Spooling to file ms17-010.txt...
msf auxiliary(smb_ms17_010) > exploit                    # 执行检测[-]         - An SMB Login Error occurred while connecting to the IPC$ tree.
[-]         - Host does NOT appear vulnerable.
[-]         - Host does NOT appear vulnerable.
[-]          - Host does NOT appear vulnerable.
[-]         - Host does NOT appear vulnerable.[-]         - Host does NOT appear vulnerable.
[-]        - Host does NOT appear vulnerable.
[-]        - Host does NOT appear vulnerable.
[-]          - An SMB Login Error occurred while connecting to the IPC$ tree.
[-]         - Host does NOT appear vulnerable.
[-]         - Host does NOT appear vulnerable.
[-]         - Host does NOT appear vulnerable.
[+]         - Host is likely VULNERABLE to MS17-010!  (Windows Server 2012 R2 Standard 9600)

  扫描结束之后,使用spool off,即可停止记录。




