1.先安裝java環境= =
備注:如果是Kali的話,自帶了Java環境是openjdk,可以先卸載apt-get remove openjdk-8-j*
1. 下載1.8u121的JAVA JDK (新的java JDK不穩定)!!原因:https://blog.cobaltstrike.com/2017/04/26/java-startup-bug-in-java-1-8u131/ (即使你安裝了新的也沒關系接下來你就知道了)
http://www.oracle.com/technetwork/java/javase/downloads/java-archive-javase8-2177648.html#jdk-8u121-oth-JPR
2. 解壓縮文件並移動至/opt
- tar -xzvf jdk-8u91-linux-x64.tar.gz
- mv jdk1.8.0_91 /opt
- cd /opt/jdk1.8.0_91
3. 設置環境變量
執行 gedit ~/.bashrc , 並添加下列內容
- # install JAVA JDK
- export JAVA_HOME=/opt/jdk1.8.0_91
- export CLASSPATH=.:${JAVA_HOME}/lib
- export PATH=${JAVA_HOME}/bin:$PATH
保存退出
執行 source ~/.bashrc
4. 安裝並注冊
執行:
- update-alternatives --install /usr/bin/java java /opt/jdk1.8.0_91/bin/java 1
- update-alternatives --install /usr/bin/javac javac /opt/jdk1.8.0_91/bin/javac 1
- update-alternatives --set java /opt/jdk1.8.0_91/bin/java
- update-alternatives --set javac /opt/jdk1.8.0_91/bin/javac
查看結果:
- update-alternatives --config java
- update-alternatives --config javac
5. 測試
- java -version
#output
java version "1.8.0_91" - Java(TM) SE Runtime Environment (build 1.8.0_91-b14)
- Java HotSpot(TM) 64-Bit Server VM (build 25.91-b14, mixed mode)
以上步驟完成后進行正式開始啟動
一、服務器端啟動:
1.Windows下啟動teamserver
①下載keytool.exe並將其復制到Cobaltstrike文件夾下
下載鏈接:http://www.onlinedown.net/soft/614989.htm
②切換到Cobaltstrike目錄執行如下命令
Keytool.exe -keystore ./cobaltstrike.store -storepass 123456 -keypass 123456 -genkey -keyalg RSA -alias cobaltstrike -dname "CN=Major Cobalt Strike, OU=AdvancedPenTesting, O=cobaltstrike, L=Somewhere, S=Cyberspace, C=Earth"
③執行命令
teamserver.bat ip 123456
④雙擊cobaltstrike.bat,填寫服務器外網IP和teamserver密碼,即可登入
2.Linux下啟動teamserver和客戶端
./teamserver IP(kali的ip) 密碼(默認是123456)
./teamserver 192.168.222.133 123456
客戶端:Linux:./cobaltstrike或 java -XX:+AggressiveHeap -XX:+UseParallelGC -jar cobaltstrike.jar 或
java -Dfile.encoding=UTF-8 -javaagent:CobaltStrikeCN.jar -XX:ParallelGCThreads=4 -XX:+AggressiveHeap -XX:+UseParallelGC -jar cobaltstrike.jar
參考:https://www.bbsmax.com/A/pRdBBlXDdn/ https://blog.csdn.net/weixin_44677409/article/details/102725129