惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

宝玉的分享
宝玉的分享
NISL@THU
NISL@THU
E
Exploit-DB.com RSS Feed
L
LINUX DO - 热门话题
L
Lohrmann on Cybersecurity
K
Kaspersky official blog
Project Zero
Project Zero
Cisco Talos Blog
Cisco Talos Blog
T
The Exploit Database - CXSecurity.com
P
Palo Alto Networks Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
T
Threatpost
S
Schneier on Security
G
GRAHAM CLULEY
The Hacker News
The Hacker News
T
Threat Research - Cisco Blogs
Scott Helme
Scott Helme
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
P
Privacy & Cybersecurity Law Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
Cyberwarzone
Cyberwarzone
C
CERT Recently Published Vulnerability Notes
T
Tor Project blog
AWS News Blog
AWS News Blog
Simon Willison's Weblog
Simon Willison's Weblog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
爱范儿
爱范儿
P
Privacy International News Feed
云风的 BLOG
云风的 BLOG
P
Proofpoint News Feed
S
Securelist
G
Google Developers Blog
The Last Watchdog
The Last Watchdog
Google Online Security Blog
Google Online Security Blog
美团技术团队
F
Fortinet All Blogs
小众软件
小众软件
Recorded Future
Recorded Future
V
Visual Studio Blog
B
Blog RSS Feed
H
Help Net Security
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Google DeepMind News
Google DeepMind News
Blog — PlanetScale
Blog — PlanetScale
博客园 - 聂微东
Stack Overflow Blog
Stack Overflow Blog
Martin Fowler
Martin Fowler
Latest news
Latest news
Spread Privacy
Spread Privacy
H
Heimdal Security Blog

博客园 - ghostandgods

智能ABC漏洞使用 Microsoft 基准安全分析器 Rootkit Detector Windows的自启动方式 简明批处理教程 关闭“磁盘空间不足”的提示 - ghostandgods - 博客园 安装SP2 v.2149后,IE就无法直接在新窗口中打开连接 - ghostandgods - 博客园 反病毒引擎设计之实时监控篇 反病毒引擎设计之虚拟机查毒篇 - ghostandgods - 博客园 反病毒引擎设计之绪论篇 BT 关于隐藏模式 深层病毒防护指南 基础知识-如何查看MAC地址 sysinfo 嘉年华 基础知识-如何分辨自己处于内网还是外网(公网)?是否有网络防火墙?是否支持UPnP? 基础知识-什么是广域网(WAN、公网、外网),什么是局域网(LAN、私网、内网)? 清理
regshell
ghostandgods · 2004-07-20 · via 博客园 - ghostandgods

简介:命令行下注册表查询工具,像用DOS命令一样方便.
http://samba.vernstok.nl/4.0/htmldocs/regshell.1.html

使用简介:

Name
regshell — Windows registry file browser using readline

Synopsis
regshell [--help] [--backend=BACKEND] [--credentials=CREDENTIALS] [location]

DESCRIPTION
regshell is a utility that lets you browse thru a Windows registry file as if you were using a regular unix shell to browse thru a file system.

OPTIONS
--help
Show list of available options.

--backend BACKEND
Name of backend to load. Possible values are: w95, nt4, gconf, dir and rpc. The default is dir.

--credentials=CREDENTIALS
Credentials to use, if any. Password should be separated from user name by a percent sign.

COMMANDS
ck|cd <keyname>
Go to the specified subkey.

ch|hive [hivename]
Go to the specified hive. If no hive is specified, lists all available hives.

list|ls
List subkeys and values of the current key.

mkkey|mkdir <keyname>
Create a key with the specified keyname as a subkey of the current key.

rmval|rm <valname>
Delete the specified value.

rmkey|rmdir <keyname>
Delete the specified subkey recursively.

pwd|pwk
Print the full name of the current key.

set|update
Update the value of a key value. Not implemented at the moment.

help|?
Print a list of available commands.

exit|quit
Leave regshell.

BACKENDS
rpc
Connect to a remote host using the specified credentials (username and password separated by a percent sign). The host name should be specified as a DCERPC binding string (in most cases: ncacn_np:hostname).

nt4
Load the specified NT4 registry file (such as NTUSER.DAT).

w95
Load the specified Windows '95 Registry file (such as USER.DAT).

gconf
Map the current users' gconf database to a registry.

dir
Map the specified directory to a registry (dirs become keys, files become values).

EXAMPLES
Browsing thru a nt4 registry file

regshell -b nt4 NTUSER.DAT
$$$PROTO.HIV> ls
K AppEvents
K Console
K Control Panel
K Environment
K Identities
K Keyboard Layout
K Network
K Printers
K Software
K UNICODE Program Groups
K Windows 3.1 Migration Status
$$$PROTO.HIV> exit

Listing the subkeys of HKEY_CURRENT_USER\AppEvents on a remote computer:

regshell -b rpc -c "jelmer%secret" ncacn_np:aurelia
HKEY_CURRENT_MACHINE> hive HKEY_CURRENT_USER
HKEY_CURRENT_USER> cd AppEvents
Current path is: HKEY_CURRENT_USER\AppEvents
HKEY_CURRENT_USER\AppEvents> ls
K EventLabels
K Schemes
HKEY_CURRENT_USER\AppEvents> exit

VERSION
This man page is correct for version 4.0 of the Samba suite.

SEE ALSO
regtree, regdiff, regpatch, gregedit, samba

AUTHOR
The original Samba software and related utilities were created by Andrew Tridgell. Samba is now developed by the Samba Team as an Open Source project similar to the way the Linux kernel is developed.

This manpage and regshell were written by Jelmer Vernooij.