# Windows-based弱點利用 ## [Nessus](/xCfvTL4NRPG3BNgHDmUjbg) - to scan vulnerabillities of the target host . ![](https://i.imgur.com/tdUI2LH.png) ## Windows - bluekeep ![](https://i.imgur.com/zg83Jzq.png) #### A Classtic example that is "Bluekeep" windows [SMB](https://www.cisco.com/c/dam/m/zh_tw/products/security/offers/threat-of-the-month/smb-and-the-return-of-the-worm.pdf)(server message block ) 上面有洞 可鑽 ### Exploit-db ![](https://i.imgur.com/977hKvn.png) https://www.exploit-db.com/exploits/47416 --- ### Exploit ![](https://i.imgur.com/Li2Zdul.png) - auxillary (Check programes) - exploit (The Attacking module) ![](https://i.imgur.com/9Tm9jE2.png) ![](https://i.imgur.com/fooqotd.png) ![](https://i.imgur.com/xREkIVd.png) ![](https://i.imgur.com/Rs6WFVg.png) ![](https://i.imgur.com/KEQ4vi8.png) ## Eternalblue ![](https://i.imgur.com/Gi2kzaC.png) ### check ![](https://i.imgur.com/2FkjcXj.png) ### Write Resource fill ![](https://i.imgur.com/EoVnoWi.png) ### Exploit ![](https://i.imgur.com/ugrZJZx.png) ## 壞壞的commends XD(help ### sysinfo ![](https://i.imgur.com/g0Xg5CY.png) ### hashdump ![](https://i.imgur.com/NmHFwgx.png) ### screemshoot ![](https://i.imgur.com/g2TeFeI.png) ### webcam~ ![](https://i.imgur.com/gllgblV.png) ### upload