The essence of penetration testing is information collection. We can roughly divide the intranet information collection into five steps, namely local information collection, domain information collection, login credential theft, survival host detection, and intranet port scanning. The two most common questions are:
When we gain administrator privileges on a host, we are always eager to learn more. Local information collection 1. Query account information: Understand the user role and user permissions of the current host to determine whether permissions need to be further enhanced.
2. Query network and port information Confirm the connected network status based on the IP address/network connection/related network address of the destination host.
3. Query the process list Check all processes running locally and confirm the status of local software, with a focus on security software.
4. Query system and patch information Get the system version and patch update status of the current host, which can be used to assist in escalating permissions.
5. Credentials Collection Sensitive information is stored on the server side, and various login credentials are collected to expand the results.
Information collection within the domain After collecting the relevant information of the local machine, it is necessary to determine whether the current host is in the domain. If it is in the domain, it is necessary to further collect information in the domain. 1. Determine whether there is a domain Generally, domain servers will also serve as time servers, so use the following command to determine the primary domain
2. Find the domain administrator
3. Find the domain controller Generally speaking, the domain controller server IP address is the DNS server address. By finding the DNS server address, you can locate the domain controller.
|
In 2019, we often heard the industry say that 201...
3GPP Release (Rel) 17, due in mid-2022, introduce...
On April 12-13, 2017, the 2017 Asia Pacific CDN S...
[[435189]] Hello everyone, I am Fei Ge! Nowadays,...
BriskServers was founded in 2021 by a group of ga...
The whois query of the domain name Servervy.com s...
At the beginning of 2020, edge computing seemed t...
In July 2021, Gartner, a global authoritative IT ...
Verizon, the US telecom operator, recently announ...
As the pandemic shapes a new normal, value chains...
[51CTO.com Quick Translation] Is the messaging pl...
According to the latest report released by market...
[[427165]] Learn more about BeautifulSoup Scrapin...
Last week we shared RAKsmart's year-end VPS h...
[[428410]] WebSocket is a full-duplex communicati...