最新消息:

基于vpn的另类端口映射

技术 admin 2647浏览 0评论

没有外网IP是痛苦的,各种反弹啊,灰鸽子啊,metasploit, Cobalt strike的啥都用不了,
当然你可以做端口映射,但是如果没有路由器管理权限的话可以用下面我的方法了。
1.Vpn
这边我使用的是centos系统装vpn,这边提供一个安装vpn脚本,一键开启vpn有木有

#!/bin/bash
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
export PATH

# Check if user is root
if [ $(id -u) != "0" ]; then
    echo "Error: You must be root to run this script, please use root to install pptpd"
    exit 1
fi

clear
echo "========================================================================="
echo "Pptpd Installer for CentOS/RadHat Linux VPS  Written by myrte"
echo "========================================================================="
echo "A tool to auto-compile & install VPN service for vps "
echo ""
echo "For more information please visit http://www.vpsyou.com/"
echo "========================================================================="

echo "==========================="
        get_char()
        {
        SAVEDSTTY=`stty -g`
        stty -echo
        stty cbreak
        dd if=/dev/tty bs=1 count=1 2> /dev/null
        stty -raw
        stty echo
        stty $SAVEDSTTY
        }
echo ""
echo "Press any key to start..."
char=`get_char`

yum remove -y pptpd ppp
iptables --flush POSTROUTING --table nat
rm -rf /etc/pptpd.conf
rm -rf /etc/ppp

wget http://www.vpsyou.com/sources/dkms-2.0.17.5-1.noarch.rpm
wget http://www.vpsyou.com/sources/kernel_ppp_mppe-1.0.2-3dkms.noarch.rpm
wget http://www.vpsyou.com/sources/pptpd-1.3.4-1.rhel5.1.i386.rpm
wget http://www.vpsyou.com/sources/ppp-2.4.4-9.0.rhel5.i386.rpm

yum -y install make libpcap iptables gcc-c++ logrotate tar cpio perl pam tcp_wrappers
rpm -ivh dkms-2.0.17.5-1.noarch.rpm
rpm -ivh kernel_ppp_mppe-1.0.2-3dkms.noarch.rpm
rpm -qa kernel_ppp_mppe
rpm -Uvh ppp-2.4.4-9.0.rhel5.i386.rpm
rpm -ivh pptpd-1.3.4-1.rhel5.1.i386.rpm

mknod /dev/ppp c 108 0 
echo 1 > /proc/sys/net/ipv4/ip_forward 
echo "mknod /dev/ppp c 108 0" >> /etc/rc.local
echo "echo 1 > /proc/sys/net/ipv4/ip_forward" >> /etc/rc.local
echo "localip 192.168.9.1" >> /etc/pptpd.conf
echo "remoteip 192.168.9.2-254" >> /etc/pptpd.conf
echo "ms-dns 8.8.8.8" >> /etc/ppp/options.pptpd
echo "ms-dns 8.8.4.4" >> /etc/ppp/options.pptpd

pass=`openssl rand 6 -base64`
if [ "$1" != "" ]
then pass=$1
fi

echo "vpn pptpd ${pass} *" >> /etc/ppp/chap-secrets

iptables -t nat -A POSTROUTING -s 192.168.9.0/255.255.255.0 -j SNAT --to-source `ifconfig  | grep 'inet addr:'| grep -v '127.0.0.1' | cut -d: -f2 | awk 'NR==1 { print $1}'`
service iptables save

chkconfig iptables on
chkconfig pptpd on

service iptables start
service pptpd start

echo "VPN service is installed, your VPN username is vpn, VPN password is ${pass}"

212UG561-0
212UI5K-1
默认分配vpn接入地址192.168.9.2-254

2 iptables 端口映射
iptables -t nat -A PREROUTING -d vpn外网IP -p tcp -m tcp –dport 12666 -j DNAT –to-destination 192.168.9.2:12666

iptables -t nat -A POSTROUTING -s 192.168.9.0/255.255.255.0 -d 192.168.9.2 -p tcp -m tcp –dport 12666 -j SNAT –to-source 192.168.9.1
212UM923-2
本机连接vpn,默认第一个连接vpn分配的是192.168.9.2,当然你也可以把你vpn分配的其它ip映射到vpn外网某端口上
212UG561-01
212UI5K-11
以后想使用外网IP只要连上vpn,然后使用你vpn上映射的12666端口就可以,什么灰鸽子啊,msf啥都行。

转载请注明:jinglingshu的博客 » 基于vpn的另类端口映射

发表我的评论
取消评论

表情

Hi,您需要填写昵称和邮箱!

  • 昵称 (必填)
  • 邮箱 (必填)
  • 网址