redis主从复制/smb扫描备忘

redis主从复制rce版本要求redis4.x或者5.x,6.x不可以。
msf利用smb漏洞时出现

1
2
[-] Exploit failed: RubySMB::Error::EncryptionError Communication error with the remote host: Socket read returned nil. The server supports encryption but was not able to handle the encrypted request.
[*] Exploit completed, but no session was created.

时可调整参数

1
2
set SMB::AlwaysEncrypt false
set SMB::ProtocolVersion 1

MSF搜索参数:-S 指定字符串 比如scanner, type指定模块类型。paste image
SMB漏洞利用:扫描端口,获得版本,利用漏洞。