没有外网IP是痛苦的,各种反弹啊,灰鸽子啊,metasploit, Cobalt strike的啥都用不了,
当然你可以做端口映射,但是如果没有路由器管理权限的话可以用下面我的方法了。
1.Vpn
这边我使用的是centos系统装vpn,这边提供一个安装vpn脚本,一键开启vpn有木有
#!/bin/bash PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin export PATH # Check if user is root if [ $(id -u) != "0" ]; then echo "Error: You must be root to run this script, please use root to install pptpd" exit 1 fi clear echo "=========================================================================" echo "Pptpd Installer for CentOS/RadHat Linux VPS Written by myrte" echo "=========================================================================" echo "A tool to auto-compile & install VPN service for vps " echo "" echo "For more information please visit http://www.vpsyou.com/" echo "=========================================================================" echo "===========================" get_char() { SAVEDSTTY=`stty -g` stty -echo stty cbreak dd if=/dev/tty bs=1 count=1 2> /dev/null stty -raw stty echo stty $SAVEDSTTY } echo "" echo "Press any key to start..." char=`get_char` yum remove -y pptpd ppp iptables --flush POSTROUTING --table nat rm -rf /etc/pptpd.conf rm -rf /etc/ppp wget http://www.vpsyou.com/sources/dkms-2.0.17.5-1.noarch.rpm wget http://www.vpsyou.com/sources/kernel_ppp_mppe-1.0.2-3dkms.noarch.rpm wget http://www.vpsyou.com/sources/pptpd-1.3.4-1.rhel5.1.i386.rpm wget http://www.vpsyou.com/sources/ppp-2.4.4-9.0.rhel5.i386.rpm yum -y install make libpcap iptables gcc-c++ logrotate tar cpio perl pam tcp_wrappers rpm -ivh dkms-2.0.17.5-1.noarch.rpm rpm -ivh kernel_ppp_mppe-1.0.2-3dkms.noarch.rpm rpm -qa kernel_ppp_mppe rpm -Uvh ppp-2.4.4-9.0.rhel5.i386.rpm rpm -ivh pptpd-1.3.4-1.rhel5.1.i386.rpm mknod /dev/ppp c 108 0 echo 1 > /proc/sys/net/ipv4/ip_forward echo "mknod /dev/ppp c 108 0" >> /etc/rc.local echo "echo 1 > /proc/sys/net/ipv4/ip_forward" >> /etc/rc.local echo "localip 192.168.9.1" >> /etc/pptpd.conf echo "remoteip 192.168.9.2-254" >> /etc/pptpd.conf echo "ms-dns 8.8.8.8" >> /etc/ppp/options.pptpd echo "ms-dns 8.8.4.4" >> /etc/ppp/options.pptpd pass=`openssl rand 6 -base64` if [ "$1" != "" ] then pass=$1 fi echo "vpn pptpd ${pass} *" >> /etc/ppp/chap-secrets iptables -t nat -A POSTROUTING -s 192.168.9.0/255.255.255.0 -j SNAT --to-source `ifconfig | grep 'inet addr:'| grep -v '127.0.0.1' | cut -d: -f2 | awk 'NR==1 { print $1}'` service iptables save chkconfig iptables on chkconfig pptpd on service iptables start service pptpd start echo "VPN service is installed, your VPN username is vpn, VPN password is ${pass}"
2 iptables 端口映射
iptables -t nat -A PREROUTING -d vpn外网IP -p tcp -m tcp –dport 12666 -j DNAT –to-destination 192.168.9.2:12666
iptables -t nat -A POSTROUTING -s 192.168.9.0/255.255.255.0 -d 192.168.9.2 -p tcp -m tcp –dport 12666 -j SNAT –to-source 192.168.9.1
本机连接vpn,默认第一个连接vpn分配的是192.168.9.2,当然你也可以把你vpn分配的其它ip映射到vpn外网某端口上
以后想使用外网IP只要连上vpn,然后使用你vpn上映射的12666端口就可以,什么灰鸽子啊,msf啥都行。
转载请注明:jinglingshu的博客 » 基于vpn的另类端口映射