当前位置:网站首页>Att & CK actual combat series - red team actual combat - V
Att & CK actual combat series - red team actual combat - V
2022-07-04 00:20:00 【F。 N hey hey】
ATT&CK Practical series — The red team is fighting -5
nmap sweep , See the open port , notice thinkphp Search directly after the version of payload


Write payload when , because <> Will be in windows Report errors , This want to use `` hold < Cover up , But it's still wrong , will payload Encrypted into base64 Then write to the file , Then decrypt the file into plaintext file 


Intranet channel 192.168.138.137
There is no password caught here ( The reason will be explained later )
Try to go online cs Grab the code 
Turn off firewall 
Turn on 3389

View host information , Prepare for remote login 

stay win7 On the use of fscan Scan host , obtain win2008
hashdump, obtain sid Wait for the information , adopt cs Upper psexec Sign in win2008


There was no migration process before , Lead to msf Of hashdump Failure 
Use wmiexec Sign in win2008, Failed to connect , Then try to connect win7, I found that I could connect , Explain that the agent has problems 
Find out msf There is no route added in ,, As a result, it cannot be connected 2008, Now add the route 
Login successful 
Subsequent operations are similar to win7 be similar , Finally, clean up the traces
边栏推荐
- Actual combat | use composite material 3 in application
- Gossip about redis source code 75
- No qualifying bean of type ‘com. netflix. discovery. AbstractDiscoveryClientOptionalArgs<?>‘ available
- Ningde times and BYD have refuted rumors one after another. Why does someone always want to harm domestic brands?
- 【leetcode】374. Guess the size of the number
- [leetcode] interview question 17.08 Circus tower
- Report on prospects and future investment recommendations of China's assisted reproductive industry, 2022-2028 Edition
- Investment demand and income forecast report of China's building ceramics industry, 2022-2028
- Gossip about redis source code 76
- 2022 chemical automation control instrument examination content and chemical automation control instrument simulation examination
猜你喜欢

SPI based on firmware library

Kubedl hostnetwork: accelerating the efficiency of distributed training communication

leetcode-43. String multiplication
![[GNN] hard core! This paper combs the classical graph network model](/img/a7/2140744ebad9f1dc0a609254cc618e.jpg)
[GNN] hard core! This paper combs the classical graph network model

A Kuan food rushed to the Shenzhen Stock Exchange: with annual sales of 1.1 billion, Hillhouse and Maotai CCB are shareholders
![Docking Alipay process [pay in person, QR code Payment]](/img/30/665580241020ee3adb872e725f0624.jpg)
Docking Alipay process [pay in person, QR code Payment]

Tencent interview: can you pour water?

A method to solve Bert long text matching
![P3371 [template] single source shortest path (weakened version)](/img/c5/bcb22e1ea573253005e56ebbd73bb7.jpg)
P3371 [template] single source shortest path (weakened version)

MySQL winter vacation self-study 2022 12 (1)
随机推荐
Yyds dry goods inventory three JS source code interpretation - getobjectbyproperty method
Solution to the impact of Remote Code Execution Vulnerability of log4j2 component on December 9, 2021
Data storage - interview questions
D29:post Office (post office, translation)
Tencent interview: can you find the number of 1 in binary?
Zipper table in data warehouse (compressed storage)
Advanced C language - pointer 2 - knowledge points sorting
Analysis: misunderstanding of choosing WMS warehouse management system
1214 print diamond
[MySQL] sql99 syntax to realize multi table query
Test the influence of influent swacth on the electromagnetic coil of quartz meter
CSP window
Smart fan system based on stm32f407
Similarities and differences of text similarity between Jaccard and cosine
Kubedl hostnetwork: accelerating the efficiency of distributed training communication
(Video + graphics and text) introduction to machine learning series - Chapter 4 naive Bayes
Joint examination of six provinces 2017
2022 Guangdong Provincial Safety Officer a certificate third batch (main person in charge) simulated examination and Guangdong Provincial Safety Officer a certificate third batch (main person in charg
[PHP basics] cookie basics, application case code and attack and defense
Global and Chinese markets for blood and liquid heating devices 2022-2028: Research Report on technology, participants, trends, market size and share