当前位置:网站首页>Red team attack and defense knowledge sharing - Red Sun security team shooting range 1 - Express version
Red team attack and defense knowledge sharing - Red Sun security team shooting range 1 - Express version
2022-04-22 17:33:00 【beirry】
This version is based on the penetration attack in daily actual combat , If you want to learn , It is suggested to study first edition
In daily site , The server will turn on 3389 port , So I'll open it all here first 3389 Port .
Internet Management
Port scanning

Through the scanning port web The site opens
Directory scanning 
The database used is mysql And a backup file of a site
Get the site through file package splicing url:http://192.168.54.128/yxcms, The use of cms yes yxcms, Version is 1.2.1
know yxcms, Direct Baidu to find known vulnerabilities
Visit the site background , Try the default password admin,123456

Learned through Baidu , The function of editing foreground template can create new php file , Take... Directly webshell

Get path , Directly search the backup package for the existence of the foreground template php file , Then splice to get url:http://192.168.54.128/yxcms/protected/apps/default/view/default/info_search.php
webshell Connect

Turn off firewall
NetSh Advfirewall set allprofiles state off // Turn off firewall

Post penetration
take cs go online

Grab the password

3389 Sign in

Intranet information collection
Collect Intranet Information ( Here steal a lazy , Not to mention the collection method , If you want to see it, you can see here [ Intranet information collection ]
| Intranet IP Network segment | 192.168.52.0/24 |
|---|---|
| Domain | GOD |
| Domain users | Administrator,ligang ,liukaifeng01 |
| Domain host | OWA$(192.168.52.138), ROOT-TVI862UBEH$(192.168.52.141), STU1$( This machine ) |
| Domain control | OWA$ |
| Domain administrator | administrator |
| 3389 | All on |
Possible loopholes :
| OWA$(192.168.52.138) | ROOT-TVI862UBEH$(192.168.52.141) |
|---|---|
| ms17-010 | ms17-010 |
- | ms08-067
Move horizontally
Now that you know that the domain administrator is administrator, So directly 3389 visit 192.168.52.138 and 192.168.52.141, The password follows web The password of the server is the same

Establish reverse connection tunnel

Listen Host Fill in the of the controlled intranet IP, Click on save

Generating Trojan files

Listener Select the monitor we just established reverse_tcp

Here we will generate a 64 and 32 Of payload(138 Yes. 64 position , and 141 yes 32 position ), So we need to generate two Trojan files
Put these two files into the... Of the server we control web Site , Let them visit the site directly http://192.168.52.143/[ Trojan file name .exe] Download Trojan files
138:

141:

Open the Trojan file
Back to cs in , You can see that the two hosts have been online


Trace cleaning
wevtutil cl system Clean up the system log
wevtutil cl application Clean up the application log
wevtutil cl security Clean up the security log
Here I steal a lazy , It's not all cleaned up , But in actual combat, we should clean up all of them

Because it's express version , Some simplification has been made in many places , For example, it opens directly 3389 Function, etc , Just look at the music , If there is any mistake in the content, please point it out in your private letter or comment
版权声明
本文为[beirry]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204221728588196.html
边栏推荐
- 2022年环境影响评价工程师考试技术导则与标准练习题及答案
- How to select ECS
- How does the applet integrate instant messaging with instant messaging
- Comment intégrer les applets et construire la GI pour réaliser le chat de messagerie instantanée
- MATLAB---回归分析
- R language class code record 5
- Prohibit copying content in web pages
- 非线性优化问题---超大对象函数优化问题---MATLAB
- About wechat applet, solve the problem of blank area caused by keyboard bounce when there is tabbar
- 丘成桐已全职加入清华
猜你喜欢

Sequoia China led the team and voted for two female founders

2022年湖南省初级会计职称考试经济法基础练习题及答案

Typical application scenarios of alicloud log service SLS

LCA的离线快速求法

7 interview questions about closure

超赞:不愧是“阿里内部Redis学习笔记”从头到尾,全是精华

小程序如何集成即构IM实现即时通讯发消息聊天

远程终端服务(3389)的安全配置方法,无需公网IP,3步实现外网访问远程桌面

Array object concatenation

怎样高效管理混合云中的数据?
随机推荐
PHP通过FTP上传、下载
Using IP addr to operate the IP of network card
工业互联网创新迭代的推手
Network wide solicitation! Tell me the story between you and Yida
Redis(16) -- Redis集群
2022年03月-电子学会青少年等级考试C语言(二级)真题与解析
Anomaly detection of log sequence based on depth model
非线性优化问题三---MATLAB
Design of wechat applet message board
Regular matching URL
渐变
Detailed explanation of kubernetes (VII) -- service object deployment and Application
LCA的离线快速求法
Matlab --- regression analysis
E-commerce price data monitoring interface / brand commodity price control interface / commodity data analysis interface / price comparison search API interface, ultra detailed interface docking instr
查看论文是否被SCI检索
2022年环境影响评价工程师考试相关法律法规练习题及答案
实现简易计算器
oracle连接失败-ORA-12537
The most expensive new shares in 2022 are coming. Xiaomi and Huawei earn 10 times