@echo OFF if %~n0==arp exit if %~n0==Arp exit if %~n0==ARP exit echo 正在獲取本機信息..... :IP FOR /f "skip=13 tokens=15 usebackq " %%i in (`ipconfig /all`) do Set IP=%%i && GOTO MAC :MAC echo IP:%IP% FOR /f "skip=13 tokens=12 usebackq " %%i in (`ipconfig /all`) do Set MAC=%%i && GOTO GateIP :GateIP echo MAC:%MAC% arp -s %IP% %MAC% echo 正在獲取網關信息..... FOR /f "skip=17 tokens=13 usebackq " %%i in (`ipconfig /all`) do Set GateIP=%%i && GOTO GateMac :GateMac echo IP:%GateIP% FOR /f "skip=3 tokens=2 usebackq " %%i in (`arp -a %GateIP%`) do Set GateMAC=%%i && GOTO Start :Start echo MAC:%GateMAC% arp -d arp -s %GateIP% %GateMAC% echo 操作完成!!! exit
下面附上詳細的說明: 這段腳本是 反ARP攻擊,手工添加本機ip、mac和網關ip、mac的程序
if %~n0==arp exit if %~n0==Arp exit if %~n0==ARP exit //判斷如果已被感染退出
echo 正在獲取本機信息..... :IP FOR /f "skip=13 tokens=15 usebackq " %%i in (`ipconfig /all`) do Set IP=%%i && GOTO MAC :MAC echo IP:%IP% FOR /f "skip=13 tokens=12 usebackq " %%i in (`ipconfig /all`) do Set MAC=%%i && GOTO GateIP :GateIP echo MAC:%MAC% arp -s %IP% %MAC% //如上面提示的,獲取本機IP和mac. 其中arp -s %IP% %MAC% 為將本機ip/mac加入本機ip/mac對應表.
echo 正在獲取網關信息..... FOR /f "skip=17 tokens=13 usebackq " %%i in (`ipconfig /all`) do Set GateIP=%%i && GOTO GateMac :GateMac echo IP:%GateIP% FOR /f "skip=3 tokens=2 usebackq " %%i in (`arp -a %GateIP%`) do Set GateMAC=%%i && GOTO Start :Start echo MAC:%GateMAC% arp -d arp -s %GateIP% %GateMAC% //這段是獲取網關的ip/mac地址,其中arp -s %GateIP% %GateMAC% 是將網關的ip和mac加載到本機對應表.