当前位置:网站首页>HTB-Granpa
HTB-Granpa
2022-07-25 05:35:00 【永远是深夜该多好。】
信息收集
nmap扫描结果如下。
目录扫描结果如下。
开机
没有过多信息,考虑可能是有对应版本的已知漏洞利用。
msf搜索一番,发现以下集中负载。
通过info可以看到更多信息。

成功后发现可能需要提权。
在根目录发现一个目录Documents and Settings

确认没有权限以后,要去问问suggester了。

扫描出来有这四个可以利用。
再利用的时候发现不止一个负载是这样,

怎么回事呢,是不是因为利用的进程没有权限,需要更换有权限的进程利用呢。
在meter看看目标运行的进程。
NT AUTHORITY\NETWORK SERVICE
NT AUTHORITY是个内置账户,主要运行XP服务。
NT AUTHORITY\NETWORK SERVICE(网络服务),它比用户组的成员拥有更多的资源和对象访问权限。
可以参考链接
随便选了一个有NT AUTHORITY\NETWORK SERVICE的进程。

然后再次利用负载就可以了。
边栏推荐
- Typera+picgo+ Alibaba cloud OSS setup and error reporting solution [reprint]
- Game 302 of leetcode
- Win11 how to view the file explorer tab
- Add transition layer to JS page
- 50: Chapter 5: develop admin management service: 3: develop [query whether the admin user name already exists, interface]; (this interface can only be called when logging in; so we have written an int
- 2021 ICPC Shaanxi warm up match b.code (bit operation)
- 编程大杂烩(二)
- 自己实现is_class
- Deep error
- Implement is by yourself_ convertible
猜你喜欢

Microservice gateway component

CCID released the "Lake warehouse integrated technology research report", and Jushan database was selected as a typical representative of domestic enterprises

聊聊 Redis 是如何进行请求处理

VIM search and replacement and the use of regular expressions

Necessary skills for mobile terminal test: ADB command and packet capturing

SystemVerilog中interface(接口)介绍

Working principle and precautions of bubble water level gauge

Arm PWN basic tutorial

Microservice configuration center Nacos

ThreadLocal
随机推荐
Automatic usage in SystemVerilog
Add transition layer to JS page
Introduction to interface in SystemVerilog
Project management tool - Introduction and practice of Alibaba cloud projex
50:第五章:开发admin管理服务:3:开发【查询admin用户名是否已存在,接口】;(这个接口需要登录时才能调用;所以我们编写了拦截器,让其拦截请求,判断用户是否是登录状态;)
OpenFegin远程调用丢失请求头问题
Three schemes for finclip to realize wechat authorized login
Anshi semiconductor management paid a visit to Wentai technology and Gree Electric appliance
Implement is by yourself_ class
The u-collapse component of uniapp mobile uview is highly init
Interface idempotency
2020icpc Jiangxi warm up e.robot sends red packets (DFS)
ZTE's first 5g mobile phone, axon 10 pro, was launched in the first half of this year
Microservice - hystrix fuse
Microservices and related component concepts
What should testers do if they encounter a bug that is difficult to reproduce?
Bug --- redis deserialization failed
编程大杂烩(一)
The difference between $write and $display in SystemVerilog
Microservice - remote invocation (feign component)