PORT STATE SERVICE 53/tcp open domain 80/tcp open http 88/tcp open kerberos-sec 135/tcp open msrpc 139/tcp open netbios-ssn 389/tcp open ldap 445/tcp open microsoft-ds 464/tcp open kpasswd5 593/tcp open http-rpc-epmap 636/tcp open ldapssl 1433/tcp open ms-sql-s 3268/tcp open globalcatLDAP 3269/tcp open globalcatLDAPssl 3389/tcp open ms-wbt-server 5985/tcp open wsman 8530/tcp open unknown 8531/tcp open unknown 9389/tcp open adws 47001/tcp open winrm 49664/tcp open unknown 49665/tcp open unknown 49666/tcp open unknown 49667/tcp open unknown 49668/tcp open unknown 49671/tcp open unknown 49675/tcp open unknown 49684/tcp open unknown 49685/tcp open unknown 49691/tcp open unknown 49700/tcp open unknown 49701/tcp open unknown 49712/tcp open unknown 49788/tcp open unknown 58538/tcp open unknown
PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 80/tcp open http Microsoft IIS httpd 10.0 |_http-title: IIS Windows Server | http-methods: |_ Potentially risky methods: TRACE |_http-server-header: Microsoft-IIS/10.0 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2025-09-26 08:09:36Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: hokkaido-aerospace.com0., Site: Default-First-Site-Name) | ssl-cert: Subject: commonName=dc.hokkaido-aerospace.com | Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:dc.hokkaido-aerospace.com | Not valid before: 2023-12-07T13:54:18 |_Not valid after: 2024-12-06T13:54:18 |_ssl-date: 2025-09-26T08:10:45+00:00; -3s from scanner time. 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: hokkaido-aerospace.com0., Site: Default-First-Site-Name) |_ssl-date: 2025-09-26T08:10:45+00:00; -3s from scanner time. | ssl-cert: Subject: commonName=dc.hokkaido-aerospace.com | Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:dc.hokkaido-aerospace.com | Not valid before: 2023-12-07T13:54:18 |_Not valid after: 2024-12-06T13:54:18 1433/tcp open ms-sql-s Microsoft SQL Server 2019 15.00.2000.00; RTM | ms-sql-ntlm-info: | 192.168.171.40:1433: | Target_Name: HAERO | NetBIOS_Domain_Name: HAERO | NetBIOS_Computer_Name: DC | DNS_Domain_Name: hokkaido-aerospace.com | DNS_Computer_Name: dc.hokkaido-aerospace.com | DNS_Tree_Name: hokkaido-aerospace.com |_ Product_Version: 10.0.20348 | ms-sql-info: | 192.168.171.40:1433: | Version: | name: Microsoft SQL Server 2019 RTM | number: 15.00.2000.00 | Product: Microsoft SQL Server 2019 | Service pack level: RTM | Post-SP patches applied: false |_ TCP port: 1433 |_ssl-date: 2025-09-26T08:10:45+00:00; -3s from scanner time. | ssl-cert: Subject: commonName=SSL_Self_Signed_Fallback | Not valid before: 2024-08-02T02:13:54 |_Not valid after: 2054-08-02T02:13:54 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: hokkaido-aerospace.com0., Site: Default-First-Site-Name) |_ssl-date: 2025-09-26T08:10:45+00:00; -4s from scanner time. | ssl-cert: Subject: commonName=dc.hokkaido-aerospace.com | Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:dc.hokkaido-aerospace.com | Not valid before: 2023-12-07T13:54:18 |_Not valid after: 2024-12-06T13:54:18 3269/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: hokkaido-aerospace.com0., Site: Default-First-Site-Name) | ssl-cert: Subject: commonName=dc.hokkaido-aerospace.com | Subject Alternative Name: othername: 1.3.6.1.4.1.311.25.1:<unsupported>, DNS:dc.hokkaido-aerospace.com | Not valid before: 2023-12-07T13:54:18 |_Not valid after: 2024-12-06T13:54:18 |_ssl-date: 2025-09-26T08:10:45+00:00; -3s from scanner time. 3389/tcp open ms-wbt-server Microsoft Terminal Services |_ssl-date: 2025-09-26T08:10:45+00:00; -3s from scanner time. | ssl-cert: Subject: commonName=dc.hokkaido-aerospace.com | Not valid before: 2025-09-25T07:58:19 |_Not valid after: 2026-03-27T07:58:19 5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-server-header: Microsoft-HTTPAPI/2.0 |_http-title: Not Found 8530/tcp open http Microsoft IIS httpd 10.0 |_http-title: 403 - Forbidden: Access is denied. |_http-server-header: Microsoft-IIS/10.0 | http-methods: |_ Potentially risky methods: TRACE 8531/tcp open unknown 9389/tcp open mc-nmf .NET Message Framing 47001/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) |_http-title: Not Found |_http-server-header: Microsoft-HTTPAPI/2.0 49664/tcp open msrpc Microsoft Windows RPC 49665/tcp open msrpc Microsoft Windows RPC 49666/tcp open msrpc Microsoft Windows RPC 49667/tcp open msrpc Microsoft Windows RPC 49668/tcp open msrpc Microsoft Windows RPC 49671/tcp open msrpc Microsoft Windows RPC 49675/tcp open msrpc Microsoft Windows RPC 49684/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 49685/tcp open msrpc Microsoft Windows RPC 49691/tcp open msrpc Microsoft Windows RPC 49700/tcp open msrpc Microsoft Windows RPC 49701/tcp open msrpc Microsoft Windows RPC 49712/tcp open msrpc Microsoft Windows RPC 49788/tcp open msrpc Microsoft Windows RPC 58538/tcp open ms-sql-s Microsoft SQL Server 2019 15.00.2000.00; RTM | ms-sql-ntlm-info: | 192.168.171.40:58538: | Target_Name: HAERO | NetBIOS_Domain_Name: HAERO | NetBIOS_Computer_Name: DC | DNS_Domain_Name: hokkaido-aerospace.com | DNS_Computer_Name: dc.hokkaido-aerospace.com | DNS_Tree_Name: hokkaido-aerospace.com |_ Product_Version: 10.0.20348 | ssl-cert: Subject: commonName=SSL_Self_Signed_Fallback | Not valid before: 2024-08-02T02:13:54 |_Not valid after: 2054-08-02T02:13:54 | ms-sql-info: | 192.168.171.40:58538: | Version: | name: Microsoft SQL Server 2019 RTM | number: 15.00.2000.00 | Product: Microsoft SQL Server 2019 | Service pack level: RTM | Post-SP patches applied: false |_ TCP port: 58538 |_ssl-date: 2025-09-26T08:10:46+00:00; -3s from scanner time. Service Info: Host: DC; OS: Windows; CPE: cpe:/o:microsoft:windows
系统为 Windows 域环境,开放有 HTTP、RDP、MSSQL、WINRM 和 Windows 域控的一些默认服务。
域控信息:
1 2 3 4 5
# 域控域名: hokkaido-aerospace.com
# 域控 KDC: dc.hokkaido-aerospace.com
3.2 渗透测试突破边界
3.2.1 域控用户名枚举、弱口令
在 kali 添加靶机域控域名解析。
1
echo"192.168.171.40\tdc.hokkaido-aerospace.com hokkaido-aerospace.com" | sudotee -a /etc/hosts
靶机 SMB、RPC、LDAP 服务枚举过程均未发现有价值信息,用户名枚举得到系统 info 用户,且该用户存在弱口令: info/info 。