没有外网IP是痛苦的,各种反弹啊,灰鸽子啊,metasploit, Cobalt strike的啥都用不了,
当然你可以做端口映射,但是如果没有路由器管理权限的话可以用下面我的方法了。
1.Vpn
这边我使用的是centos系统装vpn,这边提供一个安装vpn脚本,一键开启vpn有木有
#!/bin/bash
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
export PATH
# Check if user is root
if [ $(id -u) != "0" ]; then
echo "Error: You must be root to run this script, please use root to install pptpd"
exit 1
fi
clear
echo "========================================================================="
echo "Pptpd Installer for CentOS/RadHat Linux VPS Written by myrte"
echo "========================================================================="
echo "A tool to auto-compile & install VPN service for vps "
echo ""
echo "For more information please visit http://www.vpsyou.com/"
echo "========================================================================="
echo "==========================="
get_char()
{
SAVEDSTTY=`stty -g`
stty -echo
stty cbreak
dd if=/dev/tty bs=1 count=1 2> /dev/null
stty -raw
stty echo
stty $SAVEDSTTY
}
echo ""
echo "Press any key to start..."
char=`get_char`
yum remove -y pptpd ppp
iptables --flush POSTROUTING --table nat
rm -rf /etc/pptpd.conf
rm -rf /etc/ppp
wget http://www.vpsyou.com/sources/dkms-2.0.17.5-1.noarch.rpm
wget http://www.vpsyou.com/sources/kernel_ppp_mppe-1.0.2-3dkms.noarch.rpm
wget http://www.vpsyou.com/sources/pptpd-1.3.4-1.rhel5.1.i386.rpm
wget http://www.vpsyou.com/sources/ppp-2.4.4-9.0.rhel5.i386.rpm
yum -y install make libpcap iptables gcc-c++ logrotate tar cpio perl pam tcp_wrappers
rpm -ivh dkms-2.0.17.5-1.noarch.rpm
rpm -ivh kernel_ppp_mppe-1.0.2-3dkms.noarch.rpm
rpm -qa kernel_ppp_mppe
rpm -Uvh ppp-2.4.4-9.0.rhel5.i386.rpm
rpm -ivh pptpd-1.3.4-1.rhel5.1.i386.rpm
mknod /dev/ppp c 108 0
echo 1 > /proc/sys/net/ipv4/ip_forward
echo "mknod /dev/ppp c 108 0" >> /etc/rc.local
echo "echo 1 > /proc/sys/net/ipv4/ip_forward" >> /etc/rc.local
echo "localip 192.168.9.1" >> /etc/pptpd.conf
echo "remoteip 192.168.9.2-254" >> /etc/pptpd.conf
echo "ms-dns 8.8.8.8" >> /etc/ppp/options.pptpd
echo "ms-dns 8.8.4.4" >> /etc/ppp/options.pptpd
pass=`openssl rand 6 -base64`
if [ "$1" != "" ]
then pass=$1
fi
echo "vpn pptpd ${pass} *" >> /etc/ppp/chap-secrets
iptables -t nat -A POSTROUTING -s 192.168.9.0/255.255.255.0 -j SNAT --to-source `ifconfig | grep 'inet addr:'| grep -v '127.0.0.1' | cut -d: -f2 | awk 'NR==1 { print $1}'`
service iptables save
chkconfig iptables on
chkconfig pptpd on
service iptables start
service pptpd start
echo "VPN service is installed, your VPN username is vpn, VPN password is ${pass}"
2 iptables 端口映射
iptables -t nat -A PREROUTING -d vpn外网IP -p tcp -m tcp –dport 12666 -j DNAT –to-destination 192.168.9.2:12666
iptables -t nat -A POSTROUTING -s 192.168.9.0/255.255.255.0 -d 192.168.9.2 -p tcp -m tcp –dport 12666 -j SNAT –to-source 192.168.9.1

本机连接vpn,默认第一个连接vpn分配的是192.168.9.2,当然你也可以把你vpn分配的其它ip映射到vpn外网某端口上


以后想使用外网IP只要连上vpn,然后使用你vpn上映射的12666端口就可以,什么灰鸽子啊,msf啥都行。
转载请注明:jinglingshu的博客 » 基于vpn的另类端口映射

