数学建模社区-数学中国

标题: 对中国先锋网络科技基于SNMP的信息刺探 [打印本页]

作者: 韩冰    时间: 2004-10-5 08:56
标题: 对中国先锋网络科技基于SNMP的信息刺探

作者: Net2k 来自:流星轨迹

8 z' P6 E$ b- k

对中国先锋网络科技基于SNMP的信息刺探

- p0 E& k8 ?0 V9 Q( q) ^5 C 7 G, w, ^+ G/ I% m; E w9 F8 Y. E# `4 r) I# f

得到系统正在运行的程序信息:' L& E1 ^; f9 g9 g2 ~1 n! W ------------------------------------------------------------ 1 g/ N5 g" ]/ T0 GVariable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1 1 q) D- `! R2 `& |Value = String System Idle Process

7 t+ t3 s# C, C* `

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.84 I1 l, d. n) y2 O8 d5 ], C9 d Value = String System

1 o/ K; _* ~2 e

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.172 - d8 K" S+ c: h+ X) GValue = String smss.exe

" V0 z" w1 U1 ?& E

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.196' f4 \% y, J$ I7 m | Value = String winlogon.exe

- n* g5 E& _! i3 S) X& Z

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.200 $ R7 X& o5 B4 m5 w+ B$ p. ~Value = String csrss.exe

, b3 J% j, z4 n4 a

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.2489 J2 ~7 M) Y9 l2 ]. R! i Value = String services.exe

! s/ L+ l& R5 k X- G

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.260, n" x. S5 x0 l4 e Value = String lsass.exe

+ F$ g4 S/ g) ? o/ A

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.296 4 S+ ?' k9 l# G V4 G1 W* s) [! TValue = String wuauclt.exe

2 T8 x8 B9 J. @/ O% Y

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.456/ f8 R/ p8 A+ A* p' r' j& c* L Value = String svchost.exe

* x! q( \4 q# b! S

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.4962 Y' p/ {- m- t/ ]8 T+ Z Value = String spoolsv.exe

7 ~$ t( c2 ?: c& |

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.524" r: I2 l. f# m2 H9 }0 f' E) s Value = String msdtc.exe

2 @% i; Z+ M( b3 L# I, S9 A" J& _

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.656 3 F" ?, H. q' MValue = String DefWatch.exe

0 ]5 B+ q' m% l$ ?, q

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.676 ' ~. H+ `: ]5 A' u. n- c+ \7 k: ?5 pValue = String tcpsvcs.exe

0 m; j& A1 r, @3 [) }9 l

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.692. _) W* H4 T0 N( {3 w1 n' B2 ?. P Value = String svchost.exe

$ z& E4 n, y2 R* B

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.720 % ?; d2 ~8 i' ~* ^2 J7 XValue = String llssrv.exe

: n3 e. F- K$ K4 t" L7 ?

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.764 @; U$ P( D6 U4 i& D. s2 j Value = String Rtvscan.exe

' M/ Z$ @$ N6 E; G" E" Y- ], k( L

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.8724 [: W4 ~3 Z& w. c) p% n9 a Value = String hlds.exe

% H0 v7 ^1 O# j: Z( ^7 ?

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.9247 W; x2 |* [& F0 R9 Q Value = String nvsvc32.exe

! ]5 i4 T: s% Y9 ]6 P# R0 k- c

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.992 6 v2 y& [3 w: `- ?Value = String Explorer.EXE

3 ?& C% y+ Q8 j5 q& @; C

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1000% C+ w3 R. u, M, z) @+ n Value = String regsvc.exe

1 v% W. g) o* x. O* [

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1032 , g6 g7 M+ A2 a) M, n' \% b: y. ]Value = String MSTask.exe

8 m8 O& p' h/ ~) i, b! d f6 {" q# q, V! q

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1072 3 E5 H3 A4 F) \3 e. dValue = String snmp.exe

& j2 `& b0 b/ A* {. u

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.10924 L2 B. E& d' A* d. H3 H) E e4 M Value = String ServUDaemon.exe

4 c9 ?/ Q8 W$ L

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1104) n# _% I' ^! y2 S" N( Q# y0 X( ` W Value = String SMAgent.exe

# t8 [. r. ?& ], x" [

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1140; z* m3 N/ V; u Value = String WinMgmt.exe

# J+ S6 R# D/ I. h i

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1164 ; H4 H6 Q( f2 O8 k+ l I5 nValue = String wins.exe

* ~" T8 V3 k T: ^, t! w2 R8 y$ u' J

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1176. b- k5 f, v' x9 ~+ u) W: ?/ P Value = String svchost.exe

3 S9 C- y1 t, I0 m/ k+ V

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1196! V- F `$ P' [6 G. A: w Value = String xconfserver_t.e

9 `' m0 V" c7 x0 F8 _/ l& M, t

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1228 9 i' ~( c! W, S5 B- CValue = String Dfssvc.exe

8 F; h* F1 g' Z. @/ E

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1248 * |2 y1 `. n$ F& R' [+ C. rValue = String inetinfo.exe

" |; M7 }. r& V- I$ {8 a

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1348 3 C$ D6 H6 i' }; P2 KValue = String dns.exe

- ?7 q' r3 F$ B: W

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1568 % o3 T# i/ h- aValue = String vptray.exe

g$ U. K" X8 S, h: x! \. {! r

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1580 / H4 L9 u8 [7 C7 bValue = String internat.exe

% e7 ]5 x1 {! d! M/ T Z

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1844 5 a& @ z( a+ L( K: C: b3 tValue = String dllhost.exe

; J5 l+ i% {& E! y

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.19520 I u; |" N! Z3 z$ q! u Value = String dllhost.exe

& K0 X! D: r" b6 C$ w: P5 c

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.2060 * n. M; j) N7 RValue = String mdm.exe

& F7 h" D6 p ~6 n/ Q# q* E+ K% d

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.2144 $ c9 K( V3 @2 Y' ]5 _- EValue = String conime.exe

4 Z: x+ \0 k, H

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.2216 . L8 t) m S9 X. Y- y8 c) \Value = String hlds.exe

- |; A3 W1 [9 s A9 o) _

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.23361 ]- `0 I7 a) s& C j( b- \- q Value = String hlds.exe

! v' i4 ]9 j) n& Y, o& c

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.2348+ y$ a3 o# d% t) q' W% ? Value = String svchost.exe

: c# r: f2 T, M' u4 w

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.2424 " D$ C: |- j" i% t) `# s2 ]Value = String hlds.exe

[5 f: @) O) l% L

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.2460 * H- u5 {$ f! c% hValue = String hlds.exe

# A8 y; @5 @9 p9 {" `

End of MIB subtree. * o0 ?) |% r2 v------------------------------------------------------------

7 q0 F8 E, G0 ?2 w2 V% P$ i ?

得到系统信息:8 F1 @" e! I* A ------------------------------------------------------------ % I2 P; }1 b& i8 l: B1 U) JVariable = system.sysDescr.0 7 @/ D- ?+ E) ? C1 VValue = String Hardware: x86 Family 15 Model 2 Stepping 9 AT/AT COMPATIBLE - 5 O8 e* c# S) n; MSoftware: Windows 2000 Version 5.0 (Build 2195 Multiprocessor Free)

% z# Z' M1 }3 z. U0 v6 X

Variable = system.sysObjectID.0 4 i" I$ X3 n6 K; f; FValue = ObjectID 1.3.6.1.4.1.311.1.1.3.1.2

; P+ u) }! L4 y I3 a

Variable = system.sysUpTime.0! h0 J7 E# t: I2 u2 ^9 ^$ V Value = TimeTicks 24725698

( Q a& ^7 b* e- _2 p. O

Variable = system.sysContact.07 N6 t$ t2 m9 h) t5 g& A s4 {6 J$ G4 T Value = String

9 ^. m' B4 H( S

Variable = system.sysName.0 4 y) Q! i; g6 i% J5 D: BValue = String XIAOTOU

# W' W+ I) @1 b; l$ Q) l8 o

Variable = system.sysLocation.0 / C# c: h% h* w( N1 U- tValue = String

1 m3 g3 a2 {9 X5 M) e$ m

Variable = system.sysServices.0 " p7 p0 o6 L- fValue = Integer32 76

& X5 _3 M5 p! Y1 Y. z) K" u

End of MIB subtree.; n1 \8 E6 P4 `2 G+ }% d( Z ------------------------------------------------------------

7 U3 H! Q6 C. w: P7 ?* f5 C8 b

------------------------------------------------------------ n) t6 d0 F& K5 ]2 D& l关于snmputil的语法:6 G# h% L/ i( k- ] ------------------------------------------------------------ 5 v1 f4 l: E& v4 `) y2 v6 l7 Qget,就理解成获取一个信息。

: i) t0 m4 G) Z1 {

getnext,就理解成获取下一个信息。

2 i1 o$ F/ h6 f- s9 D

walk,就理解成获取一堆信息(嗯,应该说所有数据库子树/子目录的信息)

4 q0 Q/ B! X6 x" G0 i, N/ S @

agent,具体某台机器拉。

6 }4 H! n2 y0 ]) }* H) r- x

community,嗯就是那个“community strings”“查询密码”拉。

2 R# R: G2 a% s7 \8 B8 l0 n9 {

oid,这个要多说一下,这个呢,就是物件识别代码(Object Identifier)。 ' @; `; |/ c& N' ~............................................................

( I% r7 F" H0 S/ y% a' M }) h+ L9 \

例:( C0 E3 {1 e4 u4 E4 l/ h. E snmputil.exe walk 对方IP public .1.3.6.1.2.1.25.4.2.1.2 //**进程列表1 f& x$ ?! _( x% d# V snmputil.exe walk 对方IP public .1.3.6.1.4.77.1.2.25.1.1 //**用户列表 7 c" ~; x! z2 M; ]+ [snmputil.exe get 对方IP public .1.3.6.1.4.77.1.4.1.0 //**域名 / a& q) g" o3 @) L V! asnmputil.exe walk 对方IP public .1.3.6.1.2.1.25.6.3.1.2 //**安装的软件 5 Q& F$ f, E3 Jsnmputil.exe walk 对方IP public .1.3.6.1.2.1.1 //**系统信息






欢迎光临 数学建模社区-数学中国 (http://www.madio.net/) Powered by Discuz! X2.5