QQ登录

只需要一步,快速开始

 注册地址  找回密码
查看: 2640|回复: 0
打印 上一主题 下一主题

对中国先锋网络科技基于SNMP的信息刺探

[复制链接]
字体大小: 正常 放大
韩冰        

823

主题

3

听众

4048

积分

我的地盘我做主

该用户从未签到

发帖功臣 元老勋章

跳转到指定楼层
1#
发表于 2004-10-5 08:56 |只看该作者 |倒序浏览
|招呼Ta 关注Ta

作者: Net2k 来自:流星轨迹

$ ~- v' Y* r; z9 y$ g& q! j3 I7 Q

对中国先锋网络科技基于SNMP的信息刺探

" ~+ O- D, ~. e* G. b+ k# e5 f/ n o4 J' G1 @ W$ N& e 5 d; y! `; Q9 n0 |, n: D$ J& J$ Z

得到系统正在运行的程序信息:. ^% K" H Q2 r* T ------------------------------------------------------------ - x; O$ O: J: c& C" _Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1 ) p8 N1 s9 f K* b0 ~9 K; l- vValue = String System Idle Process

! I7 l' \ E$ @- s: \, M( K

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.8# `/ C3 N5 f4 k' X2 [, V2 f. B ` Value = String System

4 r" K. m% D- W( I3 c, w4 ^

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.172 1 {& k0 c7 _* |3 ~3 _2 ]Value = String smss.exe

, E! T4 s2 P7 L Q/ i

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.196# F0 m- q, f& g' j6 V; S) b/ D1 X$ R Value = String winlogon.exe

- ~( p1 N" F$ U- z, Z( x* @

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.200 8 M& ]" N; C6 K! ~# ZValue = String csrss.exe

) Y! f1 m* c E6 n. V. W K. ]

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.248" M: ~* ?; ` ~+ x- V# t Value = String services.exe

* c, c( g# U; H

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.2605 E* B1 b: C- f& i Value = String lsass.exe

2 @0 a& s. K+ |+ j/ u$ I5 X

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.296 3 D6 [! D+ k a4 u$ AValue = String wuauclt.exe

- Y. V1 g' F/ `4 O4 c

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.456 , ?& U8 X8 e& b2 a0 y* e7 e; A mValue = String svchost.exe

: A* a# v% I) R3 p: Z8 b

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.496 % o, `# \: j/ a# k: |1 [+ sValue = String spoolsv.exe

3 i- b+ M2 a- U

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.524 4 @; r" s7 w: G% E( vValue = String msdtc.exe

( K& i8 l f" a; p% w! R9 W! p

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.656 & b' h: k' {! xValue = String DefWatch.exe

" B8 J9 ]' M# d& G9 f7 g

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.6761 \* H' H1 Z" B0 o$ R Value = String tcpsvcs.exe

/ x9 X( E+ s/ Y; B" u4 J

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.6920 A0 |4 K5 b. B4 ~: ^ W Value = String svchost.exe

& E: }5 P, B C1 v3 ?5 M! }: U

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.720 ! a" |2 P0 q' B. h/ C; }' L' DValue = String llssrv.exe

8 c% \! K& Y( H3 ?( W6 o$ y$ h) p

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.764 ' w4 ` |; L+ _3 w B' C; ~Value = String Rtvscan.exe

8 U! R! A; @+ B9 J' @# H2 W% I

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.872 ! g y& j2 d6 _4 B0 C7 OValue = String hlds.exe

" C! y5 G7 b, v# q' @: i% v

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.9242 u5 a1 S1 W* Y! h Value = String nvsvc32.exe

. O8 P& o" P" q2 K' l4 \/ ?

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.992 ; o8 O0 D& \; c" HValue = String Explorer.EXE

" e7 K- ?- P7 r+ n. o F1 x0 Y( G

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1000* u$ f# s& n/ h2 v Value = String regsvc.exe

* N p6 }, y; i* r

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.10325 s5 M( P7 i) k1 \' h3 ^" C Value = String MSTask.exe

% j. P& m* A$ k! x8 W; S

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.10721 E/ r* Z3 m6 S Value = String snmp.exe

* }% O0 F, w- ~) x

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1092" J+ ^; G) t3 B C# X Value = String ServUDaemon.exe

. h& b) [9 L$ Y/ ^

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1104 0 y1 M, K3 N$ {Value = String SMAgent.exe

" t% W: A9 i' |! D9 S1 i3 N

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1140 q4 e5 i! t7 W- g& M Value = String WinMgmt.exe

$ |1 x5 z( k6 J3 D

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.11648 g8 J! y. c0 Q$ b) t8 \: l Value = String wins.exe

7 B" J+ R8 m* y, k' [8 Y7 ^

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1176 T! L3 p- p8 V' N Value = String svchost.exe

& j6 t! F2 ?3 Y) E7 R

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1196 ; ?8 I4 o+ I7 n% m' I; o( uValue = String xconfserver_t.e

9 a# J8 o, V+ E* D4 S! @$ y# X

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1228 ! G; P. d7 }+ P- @9 IValue = String Dfssvc.exe

- l5 c. K2 l8 v4 N9 N: G

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1248 / V9 W/ |. E! B4 \Value = String inetinfo.exe

_# ?" n3 a" s* R8 l

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1348' S' S% Y7 W+ H! \ Value = String dns.exe

% \' Z) h! z- g

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.15682 X0 ^/ s! |+ F' S% z0 j6 l0 H0 R; C Value = String vptray.exe

8 v6 d( ~5 v) R. Z( t9 h

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1580 . F9 ?) a+ M% ^# r: D& N wValue = String internat.exe

1 K( f7 @# x3 L. V

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.1844 6 `: P# h( ]0 B5 d0 x4 y0 x! GValue = String dllhost.exe

( K" N, ~! I) {7 y* U) d- p/ ?

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.19528 ^/ J4 O) I0 j Value = String dllhost.exe

]+ y) x9 G) n* \; l( \# F* l

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.20605 i8 u) M8 H- J2 H. \5 A* n0 ?; \ Value = String mdm.exe

; D1 z/ j& U# e8 l) }% x

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.2144$ [( _4 Y( |! ^) Y( q# i Value = String conime.exe

: K6 C2 A' v1 ?+ V

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.2216 : ?9 l' I4 r. b- ]0 F1 ^Value = String hlds.exe

% e2 J' R: R- r! j) o% \

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.2336 ) C" h; p3 g: _* w6 [( RValue = String hlds.exe

2 _' U2 D8 X. X! u& {, f5 U

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.23489 [5 [( s5 C! V( E7 | Value = String svchost.exe

* g! B& r8 s- F) `( ?3 o

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.2424; O2 @* U% ]5 K' d' g8 A$ j Value = String hlds.exe

8 d( {1 ]# q6 A: K5 q* @* ^9 ^" G2 t

Variable = host.hrSWRun.hrSWRunTable.hrSWRunEntry.hrSWRunName.24603 n. W2 o# L- K7 j0 A Value = String hlds.exe

0 Q9 c$ D' S% V! f

End of MIB subtree.0 p! D4 P5 B0 r ------------------------------------------------------------

+ _7 z* G" b6 V: }: Y* r

得到系统信息: ( q$ t \9 Q) o- e------------------------------------------------------------ : X# g2 i3 b4 SVariable = system.sysDescr.0 . L+ W0 N, E& }$ R3 X) i7 q1 [( ` RValue = String Hardware: x86 Family 15 Model 2 Stepping 9 AT/AT COMPATIBLE - . r- ^3 |5 Q' GSoftware: Windows 2000 Version 5.0 (Build 2195 Multiprocessor Free)

; \4 I8 r3 @( P( t

Variable = system.sysObjectID.0; m0 k+ Z- T6 p' F Value = ObjectID 1.3.6.1.4.1.311.1.1.3.1.2

4 O7 Q) e9 A2 n

Variable = system.sysUpTime.0& t6 q* R: j) x0 u# s( i Value = TimeTicks 24725698

" o0 S* ~# u \( `: i; _# }+ a

Variable = system.sysContact.0 : w6 ^* }( @ l6 r# ?Value = String

, Y( q9 U% o2 [( ?

Variable = system.sysName.0 , q5 A+ o( D! kValue = String XIAOTOU

{$ l: c, [! \. s6 U

Variable = system.sysLocation.02 t( |9 Q1 w: D Value = String

2 A, j9 v# F# r( C

Variable = system.sysServices.0 9 _, D6 ]( |: A7 {" o7 NValue = Integer32 76

; X* Z; q% E _- C9 D: t2 C: r- M

End of MIB subtree.$ e1 r* k6 u' T$ }, L. [9 I* j ------------------------------------------------------------

* |8 |0 v- ?; n/ c% R. U4 f$ V0 f. R

------------------------------------------------------------6 {, N$ x# Z2 z% [$ y4 H 关于snmputil的语法: ' m- k' k( M& t; u8 d------------------------------------------------------------% g, S* d: X' j0 E* A get,就理解成获取一个信息。

/ a2 x! q9 ]& H0 ]! b2 x

getnext,就理解成获取下一个信息。

7 X9 u( X5 y5 O( k% v2 c/ e4 e

walk,就理解成获取一堆信息(嗯,应该说所有数据库子树/子目录的信息)

- s! h6 J2 }8 \& Q W6 E g

agent,具体某台机器拉。

6 X }& N0 M7 X6 s9 u

community,嗯就是那个“community strings”“查询密码”拉。

6 y1 Q3 a( ^" |( U0 h: B) S8 s

oid,这个要多说一下,这个呢,就是物件识别代码(Object Identifier)。 u7 i) r7 _7 q* O ............................................................

( r5 u4 ^+ H1 a' n% [* j/ |/ [1 W) L/ t

例:8 E! ]8 {, P( I snmputil.exe walk 对方IP public .1.3.6.1.2.1.25.4.2.1.2 //**进程列表) e& W5 q, K5 a% j3 x9 V snmputil.exe walk 对方IP public .1.3.6.1.4.77.1.2.25.1.1 //**用户列表 - E) W0 w# Y6 v, a' ]* O& P- _3 b$ vsnmputil.exe get 对方IP public .1.3.6.1.4.77.1.4.1.0 //**域名 " s7 m/ k9 e3 O, F# |- a* O8 _snmputil.exe walk 对方IP public .1.3.6.1.2.1.25.6.3.1.2 //**安装的软件9 l+ t: s# @; |' l6 E7 v snmputil.exe walk 对方IP public .1.3.6.1.2.1.1 //**系统信息

zan
转播转播0 分享淘帖0 分享分享0 收藏收藏0 支持支持0 反对反对0 微信微信
您需要登录后才可以回帖 登录 | 注册地址

qq
收缩
  • 电话咨询

  • 04714969085
fastpost

关于我们| 联系我们| 诚征英才| 对外合作| 产品服务| QQ

手机版|Archiver| |繁體中文 手机客户端  

蒙公网安备 15010502000194号

Powered by Discuz! X2.5   © 2001-2013 数学建模网-数学中国 ( 蒙ICP备14002410号-3 蒙BBS备-0002号 )     论坛法律顾问:王兆丰

GMT+8, 2026-6-11 22:44 , Processed in 0.415478 second(s), 52 queries .

回顶部