前言
首先确定终端可以翻墙,测试curl或者wget www.google.com,建议通过proxychains转发终端流量,时间原因我先不写了,网上可以找到很多资料
0x01 Install
1 | apt-get install openvpn |
0x02 Setup
lab.ovpn(从pentestit下载config然后稍加修改)1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50# lab.ovpn
client
dev tun
proto tcp
remote vpn.pentestit.ru 443
auth-user-pass /opt/pentestit/pass.txt
resolv-retry infinite
persist-key
persist-tun
comp-lzo
verb 3
<ca>
-----BEGIN CERTIFICATE-----
MIIDXDCCAsWgAwIBAgIJAJeobwvMxFr5MA0GCSqGSIb3DQEBBQUAMH0xCzAJBgNV
BAYTAlJVMQwwCgYDVQQIEwNNU0sxDzANBgNVBAcTBk1vc2NvdzESMBAGA1UEChMJ
UGVudGVzdElUMRkwFwYDVQQDExBsYWIucGVudGVzdGl0LnJ1MSAwHgYJKoZIhvcN
AQkBFhFpbmZvQHBlbnRlc3RpdC5ydTAeFw0xMzEyMTIxNjU1NTZaFw0yMzEyMTAx
NjU1NTZaMH0xCzAJBgNVBAYTAlJVMQwwCgYDVQQIEwNNU0sxDzANBgNVBAcTBk1v
c2NvdzESMBAGA1UEChMJUGVudGVzdElUMRkwFwYDVQQDExBsYWIucGVudGVzdGl0
LnJ1MSAwHgYJKoZIhvcNAQkBFhFpbmZvQHBlbnRlc3RpdC5ydTCBnzANBgkqhkiG
9w0BAQEFAAOBjQAwgYkCgYEAonx9zXgc6O1Au8PxpoGVRXS2UGn9w6WwYT5O4Ozb
COFNmJCCEg/4zwgRFKHdcrcxEEXNOXnXzQVGFEilJortmXbrUJtDbprv7tzxq6sU
6+WKqYhjOzcS2bC0A2GXqaMPCrs+pG0WRMnZICJjceNg0tlm7tivD9RSu2xwAqBv
rzsCAwEAAaOB4zCB4DAdBgNVHQ4EFgQURIEnvYfSGVQV+fVav271aVU3ck8wgbAG
A1UdIwSBqDCBpYAURIEnvYfSGVQV+fVav271aVU3ck+hgYGkfzB9MQswCQYDVQQG
EwJSVTEMMAoGA1UECBMDTVNLMQ8wDQYDVQQHEwZNb3Njb3cxEjAQBgNVBAoTCVBl
bnRlc3RJVDEZMBcGA1UEAxMQbGFiLnBlbnRlc3RpdC5ydTEgMB4GCSqGSIb3DQEJ
ARYRaW5mb0BwZW50ZXN0aXQucnWCCQCXqG8LzMRa+TAMBgNVHRMEBTADAQH/MA0G
CSqGSIb3DQEBBQUAA4GBAIItdiW5uFjx1p8G4RN3WQxsKA65xgwu2xkUweZOeRoq
UpDQweOosxhXBQc1FX+oSbTOPZ1sBjCT4V4sdXlu6THVEf3RNxUoVPQXeGjl9Jlx
ZvAzKKIeEVzHPu1frOCU1u7P2krXBQvHtlZRQ0zUfF09qz4fBht+r4uNIlgTwLrm
-----END CERTIFICATE-----
</ca>
```
```shell
cd /opt && mkdir pentestit
# Copy files "lab.ovpn"(pentestit下载的配置文件), "pass.txt" and "ovpn.sh" to "/opt/pentestit/.
# pass.txt 格式为:
# username
# password
# ovpn.sh
#!/bin/bash
openvpn --config /opt/pentestit/lab.ovpn &
0x03 run OpenVPN
Start connection:1
2chmod +x /opt/pentestit/ovpn.sh
/opt/pentestit/ovpn.sh
Stop connection:1
killall openvpn