Windows
ç®æ¬¡ ç®æ¬¡ åµå¯ï¼ã¹ãã£ã³ ã¢ã¯ã»ã¹åå¾ æ¨©éææ ¼ (adsbygoogle = window.adsbygoogle || []).push({}); åµå¯ï¼ã¹ãã£ã³ nmapã§ã¹ãã£ã³ãã¾ãã -p-ã§ã¹ãã£ã³ãã確èªã§ãããã¼ãã«è©³ç´°ãªã¹ãã£ã³ãè¡ãã¾ãã âââ(kaliã¿kali)-[~/htb/manager] ââ$ sudo â¦
ç®æ¬¡ ç®æ¬¡ åµå¯ï¼ã¹ãã£ã³ TCP/80ã®èª¿æ» SMBã®èª¿æ» ã¢ã¯ã»ã¹åå¾ æ¨©éææ ¼ (adsbygoogle = window.adsbygoogle || []).push({}); åµå¯ï¼ã¹ãã£ã³ nmapã§ã¹ãã£ã³ãã¾ãã -p-ã§ã¹ãã£ã³ãã確èªã§ãããã¼ãã«è©³ç´°ãªã¹ãã£ã³ãè¡ãã¾ãã âââ(kaliã¿kali)-[~â¦
ç®æ¬¡ ç®æ¬¡ åµå¯ï¼ã¹ãã£ã³ TCP/80ã®èª¿æ» TCP/443ã®èª¿æ» ã¢ã¯ã»ã¹åå¾ æ¨©éææ ¼ åèã«ããã¦ããã ãããµã¤ã (adsbygoogle = window.adsbygoogle || []).push({}); åµå¯ï¼ã¹ãã£ã³ nmapã§ã¹ãã£ã³ãã¾ãã ãnmap -p- 10.10.11.158ãã®çµæããããã¤ãã®ãâ¦
ç®æ¬¡ ç®æ¬¡ åµå¯ï¼ã¹ãã£ã³ SMBã®èª¿æ» HTTPã®èª¿æ» ã¢ã¯ã»ã¹åå¾ æ¨©éææ ¼ (adsbygoogle = window.adsbygoogle || []).push({}); åµå¯ï¼ã¹ãã£ã³ nmapã§ã¹ãã£ã³ãã¾ãã ãnmap -p- 10.10.11.108ãã®çµæããããã¤ãã®ãã¼ããéãã¦ãããã¨ã確èªã§ãã¾ãâ¦
ç®æ¬¡ ç®æ¬¡ åµå¯ï¼ã¹ãã£ã³ SMBã®èª¿æ» MySQLã®èª¿æ» ä¸æãªãã¼ãã®èª¿æ» HTTPSã®èª¿æ» HTTPã®èª¿æ» SSRFã«ã¤ã㦠ã¢ã¯ã»ã¹åå¾ æ¨©éææ ¼ (adsbygoogle = window.adsbygoogle || []).push({}); åµå¯ï¼ã¹ãã£ã³ nmapã§ã¹ãã£ã³ãã¾ãã ãnmap -p- 10.10.10.239ãâ¦
ç®æ¬¡ ç®æ¬¡ åµå¯ï¼ã¹ãã£ã³ ã¢ã¯ã»ã¹åå¾ æ¨©éææ ¼ (adsbygoogle = window.adsbygoogle || []).push({}); åµå¯ï¼ã¹ãã£ã³ nmapã§ã¹ãã£ã³ãã¾ãã âââ(kaliã¿kali)-[~/htb/bounty] ââ$ sudo nmap -A -p- 10.10.10.93 Starting Nmap 7.94SVN ( https://nmap.orâ¦
SharePointã¨ã¯ SharePointã¯Microsoftãæä¾ããä¼æ¥åãã®ãµã¼ãã¹ã§ããã¡ã¤ã«çãä¿åãæ´çãå ±æããããã®Webãµã¤ããä½æãããã¨ãã§ãããµã¼ãã¹ã§ãã Sharepointã¯Microsoftã®ä»ã®ãµã¼ãã¹ï¼TeamsãOneDriveï¼ã¨ãé¢é£ãã¦ãããTeamsã§ã¯ããã¼â¦
æ¦è¦ ãPass the Hashãæ»æã¯ãWindows端æ«ã«å¯¾ãããªã¢ã¼ãã¢ã¯ã»ã¹æã®èªè¨¼ã®éã«ãä¸æ£ã«åå¾ããNTLMããã·ã¥ãLMããã·ã¥ã使ç¨ãã¦ãèªè¨¼ãçªç ´ããæ»æææ³ã§ãã ãã®è¨äºã§ã¯ãæ»æç¨ã®Kaliã¨æ¨çã¨ãªãWindows端æ«ãç¨æããå®éã«KaliããSYSTEMâ¦
æ¦è¦ ãSMB2ã¨SMB3ã®ã²ã¹ãã¢ã¯ã»ã¹ã¯ãWindowsã§ã¯æ¢å®ã§ç¡å¹ã«ãªã£ã¦ãã¾ããã¨ããè¨äºã§åãä¸ãããã¦ããããAllowInsecureGuestAuthãã®è¨å®å¤ã«ããæåã«ã¤ãã¦æ¤è¨¼ããæ©ä¼ããã£ãã®ã§ã確èªããå 容ãã¾ã¨ãã¦ã¿ã¾ããã (adsbygoogle = window.â¦
æ¦è¦ PCã使ç¨ãã¦ããããç»é¢å³ä¸ã«ä»¥ä¸ã®ãããªã¡ãã»ã¼ã¸ã表示ãããããã«ãªãã¾ããã ã¡ãã»ã¼ã¸ã«æ¸ããã¦ããEFSã«ã¤ãã¦èª¿ã¹ããã¨ãã¾ã¨ãã¾ãã çªç¶è¡¨ç¤ºãããããã«ãªã£ãéç¥ â»ãªããèªåã®å ´åã¯ä¸è¨ã®ã¡ãã»ã¼ã¸ãåºãã®ã¯Outlookãè¨å®ãâ¦
æ¦è¦ å æ¥ããã¸ã«ã¡ã®SDã«ã¼ãã«ä¿åããã大äºãªåçã誤ã£ã¦åé¤ãã¦ãã¾ãã¢ã¯ã·ãã³ããçºçãã¾ããã ãã®éã«èª¿ã¹ããWindows File Recoveryãã¨ãããã¼ã«ã«ãããã¡ã¤ã«å¾©æ§æ¹æ³ãã¾ã¨ãã¾ãã (adsbygoogle = window.adsbygoogle || []).push({})â¦
æ¦è¦ MiniTool社ã®æä¾ãã¦ãããMiniTool ShadowMakerãã«ã¤ãã¦ãã¤ã³ã¹ãã¼ã«ãããã¡ã¤ã«ã®ããã¯ã¢ããã¾ã§ã®æµããã¾ã¨ãã¾ãã (adsbygoogle = window.adsbygoogle || []).push({}); 対象ã®ã½ããã¦ã§ã¢ MiniTool Softwareã¯ãã£ã¹ã¯ããã¼ãã£ã·ã§ã³â¦
æ¦è¦ Microsoft 365ã«ã¤ãã¦èª¿ã¹ããã¨ãã¾ã¨ãã¾ãã Microsoft 365ã¨ã¯ WordãExcelçã®Officeã¢ããªã±ã¼ã·ã§ã³ãTeamsçãããã±ã¼ã¸ãããã¯ã©ã¦ãåã®çµ±åã½ãªã¥ã¼ã·ã§ã³ã§ãã 代表çãªæ©è½ã¨ãã¦ä»¥ä¸ã®ãããªãã®ãããã¾ãã æ©è½å æ¦è¦ SharePointâ¦
æ¦è¦ ä¸å¯©ãªãã¡ã¤ã«ãåä¿¡ããã¨ãã«VirusTotalçã§ãã¡ã¤ã«ã®ã¹ãã£ã³ãè¡ãå ´åãããã¾ããã対象ãã¡ã¤ã«ããã®ã¾ã¾ã¢ãããã¼ããããã¨ãã§ããªãå ´åãããã¾ãã ãã®ãããªå ´åã¯ããã¡ã¤ã«ã®hashå¤ãåå¾ãã¦èª¿æ»ããæ¹æ³ãããã¾ãã ãã®è¨äºã¯â¦
æ¦è¦ Accessã®æä½ããã¦ãããããã¤ããã£ã¦ãããã¼ã¿ãã¼ã¹ã®ã¤ã³ãã¼ãï¼ã¨ã¯ã¹ãã¼ãæä½ãWindows Defenderã«æ¢ãããã¦ãã¾ãã¾ããã Windows Defenderã«ãããããã¯ã¡ãã»ã¼ã¸ è¨äºã®å 容ã¯çãã§ãããä¸è¨ã®å¯¾å¦æ¹æ³ãã¾ã¨ãã¾ãã (adsbygooglâ¦
ã©ã³ãã³ã°åå ä¸ã¬ã¸ã§ãã ã©ã³ãã³ã°åå ä¸èªä½PCé¢ä¿ãªãä½ã§ãOKï¼ PCèªä½ã«è³ã£ãçµç·¯ Windows11ãç»å ´ããã¨ãã話é¡ã2021å¹´6æã«ããã¾ããã ãã ãWindows10ããWindows11ã¸ç§»è¡ã§ããPCã«ã¯ãã¼ãã¦ã§ã¢è¦ä»¶ããããããã¾ã§ä½¿ã£ã¦ããPCã¯ãã®â¦
ããã¯ã¢ããã¨ã¯ ããã¯ã¢ããã¨ããè¨èã¯ãã使ãã¾ãããããã¯ã¢ããã«ã¯ãããããªç¨®é¡ãããã¾ãã以ä¸ã«ããã¯ã¢ããã®ç¨®é¡ãã¾ã¨ãã¾ãã ã·ã¹ãã ããã¯ã¢ãã ã·ã¹ãã ããã¯ã¢ããã¨ã¯ãOSãã¢ããªã±ã¼ã·ã§ã³ãªã©ãå«ãã·ã¹ãã å ¨ä½ãããã¯ã¢ãâ¦
ãåæãHDDã«é¢é£ããåºæ¬çãªç¨èªã«ã¤ã㦠HDDã®ãã¼ãã£ã·ã§ã³æä½ãããåã«é¢ä¿ããç¨èªã«ã¤ãã¦ã¾ã¨ãã¾ãã â»ä»¥ä¸ã¯åºæ¬çãªå 容ã¨ãªãã¾ãããåç¥ã®æ¹ã§è¡¨é¡ã«ãããMiniTool Partition Wizardãã®ä½¿ãæ¹ãåç §ãããå ´åã¯ãã¡ããã¯ãªãã¯ãã¦ãâ¦
æ¦è¦ Widnowsã«ã¯æ§ã ãªããã»ã¹ãåä½ãã¦ãã¾ãã tasklistå®è¡ä¾ ãã®è¨äºã§ã¯ããã»ã¹ã®å 容ã«ã¤ãã¦ã¾ã¨ãã¾ãã // ããã»ã¹ã¨ã¯ï¼ ããã»ã¹ã¯ã¡ã¢ãªä¸ã«ä½ãããããã°ã©ã ã®å®ä½ã§ããWindowsã®ããã»ã¹ã¯ãããã°ã©ã ã®å®è¡ãã¡ã¤ã«ããã¡ã¢ãªä¸ã«â¦
WMIã¨ã¯ WMIï¼Windows Management Instrumentationï¼ã¯ãWindows OSã管çãããã¨ãç®çã«Microsoftãéçºããæè¡ã§ããWMIãæ´»ç¨ãããã¨ã§ãWindowsã·ã¹ãã ã®ç¶æ ã示ãæ å ±ãåå¾ã§ãã¾ãã wmicï¼Windows Management Instrumentation Command-lineï¼â¦
Windows 10ã®ç¨®é¡ Windows 10ã«ã¯ããã¤ãã®ã¨ãã£ã·ã§ã³ãããã¾ããå人å©ç¨åãã®ãHomeãããä¼æ¥ã¦ã¼ã¶åãã®ãProãããEnterpriseãã¨ãã£ãä¸è¬çã«æ®æ®µä½¿ãæ©ä¼ã®å¤ããã®ããçµè¾¼ã¿æ©å¨çç¹æ®ç¨éã®ãIoTãã¨ãã£ãã¨ãã£ã·ã§ã³ãããã¾ããä»åã¯â¦
dllã¨ã¯ dllãã¡ã¤ã«ã¯Dynaminc Link Libraryã®ç¥ã§ãåä½ã§å®è¡ãããã¨ã¯ã§ãããexeçã®ããã°ã©ã å®è¡æã«ãªã³ã¯ãããã¡ã¢ãªä¸ã«å±éããããã¨ã§å©ç¨ããã¾ããdllãã¡ã¤ã«ã«ã¯å¤ãã®ããã°ã©ã ãå ±éãã¦å¿ è¦ã¨ããæ©è½ãåãããã¦ãã¾ãã // dllãâ¦
ADSã¨ã¯ Windows NTã®æ¨æºãã¡ã¤ã«ã·ã¹ãã ã§ããNTFSï¼NT File Systemï¼ã§ç®¡çãããã¡ã¤ã«ããã©ã«ãã«ã¯ã代æ¿ãã¼ã¿ã¹ããªã¼ã ï¼Alternate Data StreamãADSï¼ã¨ããããã¡ã¤ã«ããã©ã«ãã®ä»å æ å ±ãè¨é²ããé åãããã¾ãã // ADSã«ã¯ãã»ãã¥ãªãã£â¦
ã©ã³ãã³ã°åå ä¸ã»ãã¥ãªã㣠æ¦è¦ ActiveDirectoryã管çãããã¼ã«ã¨ãã¦ãdsã³ãã³ãããããã¾ããçµç¹ã«ããã¦æ°å ¥ç¤¾å¡ãç»é²ããæçã大éã®ã¦ã¼ã¶ãä¸æ¬ç»é²ã¨ãã£ãä½æ¥ã§æ´»ç¨ããã¾ããdsã³ãã³ãã«ã¯ä»¥ä¸ã®ãã®ãããã¾ãã ãã£ã¬ã¯ããªãµã¼ãâ¦
ã©ã³ãã³ã°åå ä¸ã»ãã¥ãªã㣠Windowsã®èªåå®è¡æ©è½ï¼Autorunï¼ã«ã¤ã㦠Windowsã«ã¯èªåå®è¡ã®æ©è½ãããã¾ããWindowsã®èªåå®è¡ã¨ã¯ãCD-ROMãDVDãUSBã¡ã¢ãªãå¤ä»ããã¼ããã£ã¹ã¯ããããã¯ãããã¯ã¼ã¯ãã©ã¤ããªã©ããã½ã³ã³ã«æ¿å ¥ï¼æ¥ç¶ããããâ¦
éå»è¨äºã§Express5800ã«Windows 10ãã¤ã³ã¹ãã¼ã«ããã¨ãã®ä½æ¥ãã¾ã¨ãã¾ããã www.iestudy.work ããã¾ã§ã¯ãªã³ãã¼ãã®RAIDã³ã³ããã¼ã©ã使ç¨ããããã¼ãã¦ã§ã¢RAIDã使ç¨ãã¦ãã¾ããããWindows 10Proã§ã¯ãã½ããã¦ã§ã¢RAIDãçµããã¨ãã§ãã¾ãâ¦
追è¨å æè¿(2020/04)ã«ãªã£ã¦ãWindowsã®ãã¼ã¸ã§ã³ã1909ã®ã¾ã¾ã§ãããã¨ã«æ°ã¥ãã¾ããã1909ã®ãµãã¼ãã¯2021/5/11ã¾ã§ãªã®ã§ããµãã¼ãæéããããã®ç¶æ ã§ããWindows Updateãä½åº¦å®è¡ãã¦ãæ°ãããã¼ã¸ã§ã³ãé©ç¨ãããã åå ã調ã¹ã¦ã¿ãã¨ããâ¦
ã©ã³ãã³ã°åå ä¸ãã¯ããã¸ã¼ ãã¡ã¤ã³åå ã¨ã¯ 端æ«ãWindowsãã¡ã¤ã³ã«åå ããããã¨ã§ããã¡ã¤ã³åå ãã端æ«ã¯ãã¡ã¤ã³ã³ã³ããã¼ã©ã«æ ¼ç´ããã¦ããã¦ã¼ã¶ãªãã¸ã§ã¯ãã¸ã®ã¢ã¯ã»ã¹ãå¯è½ã«ãªãã¾ããã¾ããGPOã«ããã»ãã¥ãªãã£è¨å®ãå©ç¨ã§ãã¾ãâ¦