PORT STATE SERVICE 80/tcp open http 135/tcp open msrpc 139/tcp open netbios-ssn 445/tcp open microsoft-ds 3389/tcp open ms-wbt-server 3573/tcp open tag-ups-1 49152/tcp open unknown 49153/tcp open unknown 49154/tcp open unknown 49155/tcp open unknown 49158/tcp open unknown 49159/tcp open unknown
PORT STATE SERVICE VERSION 80/tcp open http GoAhead WebServer |_http-server-header: GoAhead-Webs | http-title: HP Power Manager |_Requested resource was http://192.168.143.45/index.asp 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 445/tcp open microsoft-ds Windows 7 Ultimate N 7600 microsoft-ds (workgroup: WORKGROUP) 3389/tcp open tcpwrapped | rdp-ntlm-info: | Target_Name: KEVIN | NetBIOS_Domain_Name: KEVIN | NetBIOS_Computer_Name: KEVIN | DNS_Domain_Name: kevin | DNS_Computer_Name: kevin | Product_Version: 6.1.7600 |_ System_Time: 2025-09-09T15:44:32+00:00 | ssl-cert: Subject: commonName=kevin | Not valid before: 2025-09-08T15:37:52 |_Not valid after: 2026-03-10T15:37:52 |_ssl-date: 2025-09-09T15:44:47+00:00; -1s from scanner time. 3573/tcp open tag-ups-1? 49152/tcp open msrpc Microsoft Windows RPC 49153/tcp open msrpc Microsoft Windows RPC 49154/tcp open msrpc Microsoft Windows RPC 49155/tcp open msrpc Microsoft Windows RPC 49158/tcp open msrpc Microsoft Windows RPC 49159/tcp open msrpc Microsoft Windows RPC Service Info: Host: KEVIN; OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results: | smb-os-discovery: | OS: Windows 7 Ultimate N 7600 (Windows 7 Ultimate N 6.1) | OS CPE: cpe:/o:microsoft:windows_7::- | Computer name: kevin | NetBIOS computer name: KEVIN\x00 | Workgroup: WORKGROUP\x00 |_ System time: 2025-09-09T08:44:32-07:00 |_nbstat: NetBIOS name: KEVIN, NetBIOS user: <unknown>, NetBIOS MAC: 00:50:56:ab:95:9e (VMware) | smb2-time: | date: 2025-09-09T15:44:32 |_ start_date: 2025-09-09T15:38:41 | smb2-security-mode: | 2:1:0: |_ Message signing enabled but not required | smb-security-mode: | account_used: guest | authentication_level: user | challenge_response: supported |_ message_signing: disabled (dangerous, but default) |_clock-skew: mean: 1h23m58s, deviation: 3h07m49s, median: -1s
系统为 Windows 环境,开放有 HTTP 和一些 Windows 默认服务。
3.2 渗透测试突破边界
3.2.1 HP Power Manager 缓冲区溢出得到系统 system 权限(CVE-2009-2685)
靶机 HTTP 80 端口可通过弱口令 admin/admin 进入系统后台,点击后台 help 得知应用版本信息:HP Power Manager 4.2 (Build 7)。