The VM calls the remote path to execute cmd Privilege Escalation)

Source: Internet
Author: User

Recently, we have discussed that remote invocation of CMD is quite popular, so I want to write some summary about using remote invocation of CMD.

Download (53.53 KB)

5 hours ago

For more information, see http://lcx.cc /? I = 3221.
I used Windows 2003 for demonstration.
1. Activate the local guest account

Download (54.68 KB)

5 hours ago

2. Set network access in the Group Policy: Change the Sharing and security model of the local account to classic (2003 the system uses Classic mode by default and does not need to be modified)

Download (79.62 KB)

5 hours ago

3. Enable the Server Service. The server service refers to the service needed for network sharing. There is no Server Service locally (please note this)

Download (3.69 KB)

5 hours ago

Let's add the printer protocol to the network.

Download (65.57 KB)

5 hours ago

Download (56.7 KB)

5 hours ago

Download (14.43 KB)

5 hours ago

Now the installation is successful.

Download (66.4 KB)

5 hours ago

The server service is automatically started by default after the installation is successful.

Download (3.91 KB)

5 hours ago


4. Create a shared folder

Download (58.7 KB)

5 hours ago


Download (56.14 KB)

5 hours ago


Download (6.36 KB)

5 hours ago

Download (7.61 KB)

5 hours ago

Download (45.56 KB)

5 hours ago

Download (10.36 KB)

5 hours ago

All the preparations have been completed. Put in a cmd. Let's test it.

Download (2.52 KB)

5 hours ago

conclusion: (mandatory) 1. why do I still find the network path when I execute the above command on my shell? explanation: the port 445 in China is basically blocked by the MS08-067. Generally, port 445 only allows mutual access within the man. 2. What should I do? explanation: it is not necessary to win a server in the target c segment as a zombie, all servers in the man can be used, such as machines in a data center. 3. What if I cannot connect to the C-segment server on a daily basis? explanation: Find the CIDR block, and the port 445 of the CIDR block is not blocked.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.