Heist(Eazy, Windows)

Nmap : 80, 135, 445, 5985

http/80

  • Cisco

    • ios-1/ stealth1agent

    • rout3r/$uperP@ssword

    • admin/Q4)sJu\Y8qz*A3?d

  • user/password

    • Hazard

    • SUPPORTDESK

    • ios-1/ stealth1agent

    • rout3r/$uperP@ssword

    • admin/Q4)sJu\Y8qz*A3?d

  • SMB ๋ฌด์ฐจ๋ณ„๋Œ€์ž…์‹œ๋„ -> ์„ฑ๊ณต

    • Hazard:stealth1agent

    • but smb ์—ด๊ฑฐ ๋ถˆ๊ฐ€๋Šฅ Why? ์˜ค๋กœ์ง€ IPC$์—์„œ๋งŒ ์ฝ๊ธฐ ๊ถŒํ•œ์žˆ์Œ

  • Winrm ๋ฌด์ฐจ๋ณ„ ๋Œ€์ž… ์‹œ๋„ - ์‹คํŒจ

    • ๋‚ด๊ฐ€ ๊ฐ€์ง„ ์ •๋ณด : SMB ํฌ๋ž˜๋”ง ์ •๋ณด๋ฟ, ์›น์‚ฌ์ดํŠธ ๋กœ๊ทธ์ธ ๋ถˆ๊ฐ€, winrm ๋กœ๊ทธ์ธ ๋ถˆ๊ฐ€, 135ํฌํŠธ๋Š” ์ง€๊ธˆ ์ƒํ™ฉ์—์„  ์“ธ๋ชจ๊ฐ€ ์—†์Œ

    • SMB ํฌ๋ž˜๋”ง์„ ๊ฐ€์ง€๊ณ  SID ๊ณต๊ฒฉ or rpcclient ์—ด๊ฑฐ

      • SMB SID ์—ด๊ฑฐ๋ฅผ ํ†ตํ•ด ๋กœ์ปฌ ์‚ฌ์šฉ์ž ๋ชฉ๋ก ํš๋“

      • rpcclient๋กœ๋„ ์‚ฌ์šฉ์ž ๋ชฉ๋ก ํš๋“ ๊ฐ€๋Šฅ

    • ์–ป์€ ์‚ฌ์šฉ์ž ๋ชฉ๋ก์œผ๋กœ smb login, winrm login ๋กœ๊ทธ์ธ ์‹œ๋„

      • Chase:Q4)sJu\Y8qz*A3?d ์„ฑ๊ณต

  • Winrm ์—ด๊ฑฐ

    • user.txt ํš๋“

    • todo.txt

      • Stuff to-do:

        1. Keep checking the issues list.

        2. Fix the router config.

        Done:

        1. Restricted access for guest user.

    • vmware ํˆด ์กด์žฌ

    • Hazard, Public, Administrator ํด๋” ์กด์žฌ but ์•ก์„ธ์Šค ๊ถŒํ•œ ์—†์Œ

    • inetpub ํด๋” ๋ฐœ๊ฒฌ but ๊ถŒํ•œ ์—†์Œ

    • firefox๊ฐ€ ํ˜„์žฌ ์‹คํ–‰์ค‘์ž„์„ ๋ฐœ๊ฒฌ (Get-Process : ์‹คํ–‰์ค‘์ธ ํ”„๋กœ๊ทธ๋žจ ํ™•์ธ)

    • sysinternalsuit/procdump4.exe๋ฅผ ์‚ฌ์šฉํ•ด์„œ ํŒŒ์ด์–ดํญ์Šค ๋คํ”„ (winrm์— sysinternalsuit ์—…๋กœ๋“œ ํ›„ "./procdump64.exe -ma 3652)

  • ์“ธ๋ชจ์žˆ๋Š” ๊ฒฝ๋กœ : /usr/share/doc/python3-impoacket/examples

Last updated