RPC
realblackcat@htb[/htb]$ rpcclient -U "" - N 10.129.14.128
Enter WORKGROUP\'s password:
rpcclient $> ์ฟผ๋ฆฌ
์ค๋ช
rpcclient $> srvinfo #์๋ฒ ์ ๋ณด
DEVSMB Wk Sv PrQ Unx NT SNT DEVSM
platform_id : 500
os version : 6.1
server type : 0x809a03
rpcclient $> enumdomains #๋คํธ์ํฌ์ ๋ฐฐํฌ๋ ๋ชจ๋ ๋๋ฉ์ธ ์ด๊ฑฐ
name:[DEVSMB] idx:[0x0]
name:[Builtin] idx:[0x1]
rpcclient $> querydominfo #๋ฐฐํฌ๋ ๋๋ฉ์ธ์ ๋๋ฉ์ธ, ์๋ฒ ๋ฐ ์ฌ์ฉ์ ์ ๋ณด๋ฅผ ์ ๊ณตํฉ๋๋ค.
Domain: DEVOPS
Server: DEVSMB
Comment: DEVSM
Total Users: 2
Total Groups: 0
Total Aliases: 0
Sequence No: 1632361158
Force Logoff: -1
Domain Server State: 0x1
Server Role: ROLE_DOMAIN_PDC
Unknown 3: 0x1
rpcclient $> netshareenumall #์ฌ์ฉ ๊ฐ๋ฅํ ๋ชจ๋ ๊ณต์ ๋ฅผ ์ด๊ฑฐํฉ๋๋ค.
netname: print$
remark: Printer Drivers
path: C:\var\lib\samba\printers
password:
netname: home
remark: INFREIGHT Samba
path: C:\home\
password:
netname: dev
remark: DEVenv
path: C:\home\sambauser\dev\
password:
netname: notes
remark: CheckIT
path: C:\mnt\notes\
password:
netname: IPC$
remark: IPC Service (DEVSM)
path: C:\tmp
password:
rpcclient $> netsharegetinfo notes #ํน์ ๊ณต์ ์ ๋ํ ์ ๋ณด๋ฅผ ์ ๊ณตํฉ๋๋ค.
netname: notes
remark: CheckIT
path: C:\mnt\notes\
password:
type: 0x0
perms: 0
max_uses: -1
num_uses: 1
revision: 1
type: 0x8004: SEC_DESC_DACL_PRESENT SEC_DESC_SELF_RELATIVE
DACL
ACL Num ACEs: 1 revision: 2
---
ACE
type: ACCESS ALLOWED (0) flags: 0x00
Specific bits: 0x1ff
Permissions: 0x101f01ff: Generic all access SYNCHRONIZE_ACCESS WRITE_OWNER_ACCESS WRITE_DAC_ACCESS READ_CONTROL_ACCESS DELETE_ACCESS
SID: S-1-1-0Last updated