基本信息
lab地址:https://www.hackthebox.eu/home/machines/profile/220
端口扫描
data:image/s3,"s3://crabby-images/fa470/fa47046c2b40759c423ed33679553e24d26e012d" alt=""
是一个Windows服务器,没有web
enum4linux
使用enum4linux收集信息:
data:image/s3,"s3://crabby-images/f0dc5/f0dc5d6e63645a9257a76c98633d90bc370cc0e8" alt=""
这里能够看到一条信息,其中是一个账号密码:
1 | index: 0x10a9 RID: 0x457 acb: 0x00000210 Account: marko Name: Marko Novak Desc: Account created. Password set to Welcome123! |
但直接使用这个账号密码尝试登录,失败:
data:image/s3,"s3://crabby-images/2ce1f/2ce1f8f83533c7e04aec5c679f7f03a8fc92724f" alt=""
这里可以整理出得到的所有用户名:
1 | user:[Administrator] rid:[0x1f4] |
smb_login
使用得到的用户名字典和前面的密码尝试登录,得到一个正确的账号:
data:image/s3,"s3://crabby-images/35283/3528326e9e1a807f21e92ce7c1d0970b04efbafd" alt=""
1 | melanie:Welcome123! |
user flag
使用这个账号密码登录,得到user.txt:
data:image/s3,"s3://crabby-images/ebcfd/ebcfd31013c17be22713adf210fec859d76916fc" alt=""
搜集信息
1 | dir -force = ls -a |
data:image/s3,"s3://crabby-images/9bb04/9bb04c4a7d398a4a9b242d81b01499b3781eb502" alt=""
data:image/s3,"s3://crabby-images/901b6/901b6069586ca3e3df658235b0c2c643522bd142" alt=""
在这个文件中发现了另一个账号的密码:
1 | cmd /c net use X: \\fs01\backups ryan Serv3r4Admin4cc123! |
note.txt
使用ryan账号登录,在桌面发现一个note.txt:
data:image/s3,"s3://crabby-images/5faea/5faea456c383c1db3fb793d70e79859adf6d95bd" alt=""
任何系统更改都会在1分钟内恢复,除了管理员账号做的更改
使用whoami /all
查看信息的话,能够发现ryan这个账号在DnsAdmins中:
data:image/s3,"s3://crabby-images/04c2f/04c2f31cc36e98d359765d174304dd072ec38e1e" alt=""
DNSAdmins to Domain Admins
搜索能够得到:
Windows Privilege Escalation: DNSAdmins to Domain Admins - Server Level DLL Injection
https://www.abhizer.com/windows-privilege-escalation-dnsadmin-to-domaincontroller/
基本就这个流程,参数自己改下
1 | Attack: |
root flag
得到system权限,在Administrator用户桌面得到root.txt:
data:image/s3,"s3://crabby-images/9f675/9f6750b817d61dae39607923156e34600baf4328" alt=""
参考资料
- https://github.com/portcullislabs/enum4linux
- Windows Privilege Escalation: DNSAdmins to Domain Admins - Server Level DLL Injection
https://www.abhizer.com/windows-privilege-escalation-dnsadmin-to-domaincontroller/ - Hackthebox Resolute - YouTube
https://www.youtube.com/watch?v=WydBNOR51_o&t=1s