1. winexe
winexe -U HOME/Administrator%Pass123 //192.168.0.10 "ipconfig /all"
winexe -U HOME/Administrator%Pass123 //host 'cmd /C dir C:\'
winexe -U HOME/Administrator%Pass123 //host.com 'cmd /C net stop wuauserv && net start wuauserv && echo AutoUpdates service restarted'
cat | winexe -U HOME/Administrator%Pass123 //host cmd <<EOF
net stop wuauserv
net start wuauserv
echo AutoUpdates service restarted
exit
EOF
2. pass the hash
[img]http://dl2.iteye.com/upload/attachment/0102/1794/071667c6-c55d-3074-83fd-e36a4cae7aca.png[/img]
3. pass the hash
apt-get update
apt-get install freerdp-x11
[img]http://dl2.iteye.com/upload/attachment/0102/1796/fd75cb66-b18f-3388-a979-be675921953e.png[/img]
winexe -U HOME/Administrator%Pass123 //192.168.0.10 "ipconfig /all"
winexe -U HOME/Administrator%Pass123 //host 'cmd /C dir C:\'
winexe -U HOME/Administrator%Pass123 //host.com 'cmd /C net stop wuauserv && net start wuauserv && echo AutoUpdates service restarted'
cat | winexe -U HOME/Administrator%Pass123 //host cmd <<EOF
net stop wuauserv
net start wuauserv
echo AutoUpdates service restarted
exit
EOF
2. pass the hash
[img]http://dl2.iteye.com/upload/attachment/0102/1794/071667c6-c55d-3074-83fd-e36a4cae7aca.png[/img]
3. pass the hash
apt-get update
apt-get install freerdp-x11
[img]http://dl2.iteye.com/upload/attachment/0102/1796/fd75cb66-b18f-3388-a979-be675921953e.png[/img]

本文介绍通过Winexe工具实现远程执行Windows命令的方法,包括查看网络配置、文件目录操作及服务重启等,并展示了如何利用pass-the-hash技术提升权限。
443

被折叠的 条评论
为什么被折叠?



