<p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255);"><span style="font-weight: 700; box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(255, 0, 0);">之前的一篇<a href="http://www.freebuf.com/vuls/135549.html" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239);">Intel产品AMT本地及远程提权漏洞（CVE-2017-5689）复现</a>，只是简单的复现了该漏洞，在文章最后提及到了如果进一步对该漏洞进行利用。但是有些大佬们看了一眼后觉得搞了几个并不知道如何利用。一直到有位私信我的，说用工具不能连vnc，好吧。都私信了，我这么热心肠的人怎么能拒绝呢，所以有了这篇更为详细的利用过程。</span></p><blockquote style="box-sizing: border-box; padding: 10px 20px; margin: 0px 0px 20px; font-size: 14px; border-left: 5px solid rgb(238, 238, 238); background: rgb(247, 247, 247); color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal;"><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;">工具：<a href="http://www.meshcommander.com/open-manageability" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239);">Open MDTK（需梯子）</a>和&nbsp;<a href="http://www.uvnc.com/downloads/ultravnc.html" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239);">UltraVNC</a></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;">攻击机：win7</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 0px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word;">靶机：一台韩国思密达的服务器，在shodan上面随便找的</p></blockquote><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255);">步骤：首先找到一台存在漏洞的服务器，利用上一篇的方法，是用默认的admin/admin账号登陆截包删除response里的内容，发包添加管理员账号。</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255); text-align: center;"><a href="http://image.3001.net/images/20180130/15172841202463.png" class="highslide-image" target="_blank" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239);"><img alt="image.png" src="http://image.3001.net/images/20180130/15172841202463.png!small" width="683"/></a></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255);">MDTK需要安装，安装后有很多图标，运行Manageability Automation Tool。</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255);">右键空白处添加“被管理设备”，需要输入IP地址和刚刚设置的那个复杂的密码。</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255); text-align: center;"><a href="http://image.3001.net/images/20180130/15172845481632.png" class="highslide-image" target="_blank" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239);"><img alt="111.png" src="http://image.3001.net/images/20180130/15172845481632.png!small" width="420"/></a></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255);">添加后，右键点击刚刚添加的那行，选择Manage Computer。</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255);">软件会自动开始连接，当左侧出现目录时，即表示连接成功</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255); text-align: center;"><a href="http://image.3001.net/images/20180130/15172847003836.png" class="highslide-image" target="_blank" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239);"><img alt="22.png" src="http://image.3001.net/images/20180130/15172847003836.png!small" width="690"/></a></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255);">这里的远程连接，其实相当于KVM，能方便的控制服务器</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255); text-align: center;"><a href="http://image.3001.net/images/20180130/15172847594073.png" class="highslide-image" target="_blank" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239);"><img alt="image.png" src="http://image.3001.net/images/20180130/15172847594073.png!small" width="690"/></a></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255);">这里要开启端口重定向，不然是无法点亮托管那个按钮的</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255); text-align: center;"><a href="http://image.3001.net/images/20180130/15172849009011.png" class="highslide-image" target="_blank" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239);"><img alt="33.png" src="http://image.3001.net/images/20180130/15172849009011.png!small" width="530"/></a></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255);">开启vnc的话这里还需要设置 Remote Desktop，点击Remote Desktop Settings，开启Redirection Port (16993/16995)。</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255); text-align: center;"><a href="http://image.3001.net/images/20180130/15172850065345.png" class="highslide-image" target="_blank" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239);"><img alt="44.png" src="http://image.3001.net/images/20180130/15172850065345.png!small" width="387"/></a></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255);">点击Remote Desktop Viewer，这里的Viewer Type选择UltraVNC，Viewer Path 选择刚刚下载本机的vncviewer.exe</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255); text-align: center;"><a href="http://image.3001.net/images/20180130/15172851327417.png" class="highslide-image" target="_blank" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239);"><img alt="55.png" src="http://image.3001.net/images/20180130/15172851327417.png!small" width="387"/></a></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255); text-align: center;"><a href="http://image.3001.net/images/20180130/15172852503088.png" class="highslide-image" target="_blank" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239);"><img alt="image.png" src="http://image.3001.net/images/20180130/15172852503088.png!small" width="683"/></a></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255);">这样设置后，Launch Viewer就可以点击了，跟windows下的3389一样，没敢登录，，，还有域？思密达看不懂2333</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255); text-align: center;"><a href="http://image.3001.net/images/20180130/15172853447400.png" class="highslide-image" target="_blank" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239);"><img alt="66.png" src="http://image.3001.net/images/20180130/15172853447400.png!small" width="690"/></a></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255);">点击上面的托管，能实现远程开关机，并且在开机后自动进入BIOS</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255); text-align: center;"><a href="http://image.3001.net/images/20180201/15174793952395.png" class="highslide-image" target="_blank" style="box-sizing: border-box; background: 0px 0px; color: rgb(6, 154, 239);"><img alt="77.png" src="http://image.3001.net/images/20180201/15174793952395.png!small" width="660"/></a></p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255);">以上为本漏洞利用的详细步骤，大佬轻喷~</p><p style="box-sizing: border-box; margin-top: 0px; margin-bottom: 10px; font-size: 15px; line-height: 26px; word-wrap: break-word; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑; white-space: normal; background-color: rgb(255, 255, 255);"><span style="box-sizing: border-box; font-weight: 700; color: rgb(255, 255, 255);">*本文作者：test124，转载请注明来自FreeBuf.COM</span></p><p><br/></p>