当前位置:网站首页>Att & CK actual combat series - red team actual combat - V
Att & CK actual combat series - red team actual combat - V
2022-07-04 00:20:00 【F。 N hey hey】
ATT&CK Practical series — The red team is fighting -5
nmap sweep , See the open port , notice thinkphp Search directly after the version of payload


Write payload when , because <> Will be in windows Report errors , This want to use `` hold < Cover up , But it's still wrong , will payload Encrypted into base64 Then write to the file , Then decrypt the file into plaintext file 


Intranet channel 192.168.138.137
There is no password caught here ( The reason will be explained later )
Try to go online cs Grab the code 
Turn off firewall 
Turn on 3389

View host information , Prepare for remote login 

stay win7 On the use of fscan Scan host , obtain win2008
hashdump, obtain sid Wait for the information , adopt cs Upper psexec Sign in win2008


There was no migration process before , Lead to msf Of hashdump Failure 
Use wmiexec Sign in win2008, Failed to connect , Then try to connect win7, I found that I could connect , Explain that the agent has problems 
Find out msf There is no route added in ,, As a result, it cannot be connected 2008, Now add the route 
Login successful 
Subsequent operations are similar to win7 be similar , Finally, clean up the traces
边栏推荐
- SQL data update
- The frost peel off the purple dragon scale, and the xiariba people will talk about database SQL optimization and the principle of indexing (primary / secondary / clustered / non clustered)
- P1656 bombing Railway
- D30:color tunnels (color tunnels, translation)
- Axure resources and prototype tool Axure RP 9 download
- What is the potential of pocket network, which is favored by well-known investors?
- A method to solve Bert long text matching
- Enter MySQL in docker container by command under Linux
- Joint examination of six provinces 2017
- How to make icons easily
猜你喜欢

Ningde times and BYD have refuted rumors one after another. Why does someone always want to harm domestic brands?

(Video + graphics and text) introduction to machine learning series - Chapter 4 naive Bayes

It is forbidden to splice SQL in code

The interviewer's biggest lie to deceive you, bypassing three years of less struggle

STM32 GPIO CSDN creative punch in

It is the most difficult to teach AI to play iron fist frame by frame. Now arcade game lovers have something

2022 free examination questions for hoisting machinery command and hoisting machinery command theory examination

How will the complete NFT platform work in 2022? How about its core functions and online time?
![[2021]NeRF in the Wild: Neural Radiance Fields for Unconstrained Photo Collections](/img/c6/3dc7d01600f6713afdbb4cf3df5238.jpg)
[2021]NeRF in the Wild: Neural Radiance Fields for Unconstrained Photo Collections

Research Report on the scale prediction of China's municipal engineering industry and the prospect of the 14th five year plan 2022-2028
随机推荐
STM32 GPIO CSDN creative punch in
Similarities and differences of text similarity between Jaccard and cosine
Gossip about redis source code 73
Private project practice sharing populate joint query in mongoose makes the template unable to render - solve the error message: syntaxerror: unexpected token r in JSON at
Global and Chinese market of underwater bags 2022-2028: Research Report on technology, participants, trends, market size and share
2022 free examination questions for hoisting machinery command and hoisting machinery command theory examination
Kubedl hostnetwork: accelerating the efficiency of distributed training communication
Actual combat | use composite material 3 in application
IO flow principle and classification
Yyds dry goods inventory three JS source code interpretation - getobjectbyproperty method
2022 a special equipment related management (elevator) examination questions and a special equipment related management (elevator) examination contents
SPI based on firmware library
D27:mode of sequence (maximum, translation)
Double efficiency. Six easy-to-use pychar plug-ins are recommended
It is the most difficult to teach AI to play iron fist frame by frame. Now arcade game lovers have something
Advanced C language - pointer 2 - knowledge points sorting
D25:sequence search (sequence search, translation + problem solving)
Ramble 72 of redis source code
Enter MySQL in docker container by command under Linux
Tencent interview: can you find the number of 1 in binary?