1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155
| PORT STATE SERVICE 445/tcp open microsoft-ds
Host script results: | smb-enum-users: | LAME\backup (RID: 1068) | Full name: backup | Flags: Account disabled, Normal user account | LAME\bin (RID: 1004) | Full name: bin | Flags: Account disabled, Normal user account | LAME\bind (RID: 1210) | Flags: Account disabled, Normal user account | LAME\daemon (RID: 1002) | Full name: daemon | Flags: Account disabled, Normal user account | LAME\dhcp (RID: 1202) | Flags: Account disabled, Normal user account | LAME\distccd (RID: 1222) | Flags: Account disabled, Normal user account | LAME\ftp (RID: 1214) | Flags: Account disabled, Normal user account | LAME\games (RID: 1010) | Full name: games | Flags: Account disabled, Normal user account | LAME\gnats (RID: 1082) | Full name: Gnats Bug-Reporting System (admin) | Flags: Account disabled, Normal user account | LAME\irc (RID: 1078) | Full name: ircd | Flags: Account disabled, Normal user account | LAME\klog (RID: 1206) | Flags: Account disabled, Normal user account | LAME\libuuid (RID: 1200) | Flags: Account disabled, Normal user account | LAME\list (RID: 1076) | Full name: Mailing List Manager | Flags: Account disabled, Normal user account | LAME\lp (RID: 1014) | Full name: lp | Flags: Account disabled, Normal user account | LAME\mail (RID: 1016) | Full name: mail | Flags: Account disabled, Normal user account | LAME\man (RID: 1012) | Full name: man | Flags: Account disabled, Normal user account | LAME\msfadmin (RID: 3000) | Full name: msfadmin,,, | Flags: Normal user account | LAME\mysql (RID: 1218) | Full name: MySQL Server,,, | Flags: Account disabled, Normal user account | LAME\news (RID: 1018) | Full name: news | Flags: Account disabled, Normal user account | LAME\nobody (RID: 501) | Full name: nobody | Flags: Account disabled, Normal user account | LAME\postfix (RID: 1212) | Flags: Account disabled, Normal user account | LAME\postgres (RID: 1216) | Full name: PostgreSQL administrator,,, | Flags: Account disabled, Normal user account | LAME\proftpd (RID: 1226) | Flags: Account disabled, Normal user account | LAME\proxy (RID: 1026) | Full name: proxy | Flags: Account disabled, Normal user account | LAME\root (RID: 1000) | Full name: root | Flags: Account disabled, Normal user account | LAME\service (RID: 3004) | Full name: ,,, | Flags: Account disabled, Normal user account | LAME\sshd (RID: 1208) | Flags: Account disabled, Normal user account | LAME\sync (RID: 1008) | Full name: sync | Flags: Account disabled, Normal user account | LAME\sys (RID: 1006) | Full name: sys | Flags: Account disabled, Normal user account | LAME\syslog (RID: 1204) | Flags: Account disabled, Normal user account | LAME\telnetd (RID: 1224) | Flags: Account disabled, Normal user account | LAME\tomcat55 (RID: 1220) | Flags: Account disabled, Normal user account | LAME\user (RID: 3002) | Full name: just a user,111,, | Flags: Normal user account | LAME\uucp (RID: 1020) | Full name: uucp | Flags: Account disabled, Normal user account | LAME\www-data (RID: 1066) | Full name: www-data |_ Flags: Account disabled, Normal user account
# 些用户是指在某个计算机系统或网络中创建的用户帐户。每个用户帐户都有一个唯一的标识符(RID),通常有一个用户名和一些其他信息,如全名或描述。用户帐户可以用来登录系统、执行特定任务或访问特定资源,具体取决于其权限和角色。
Account disabled" 意味着该用户帐户已被禁用或停用。
| smb-enum-shares: | account_used: <blank> | \\10.10.10.3\ADMIN$: | Type: STYPE_IPC | Comment: IPC Service (lame server (Samba 3.0.20-Debian)) | Users: 1 | Max Users: <unlimited> | Path: C:\tmp | Anonymous access: <none> | \\10.10.10.3\IPC$: | Type: STYPE_IPC | Comment: IPC Service (lame server (Samba 3.0.20-Debian)) | Users: 1 | Max Users: <unlimited> | Path: C:\tmp | Anonymous access: READ/WRITE | \\10.10.10.3\opt: | Type: STYPE_DISKTREE | Comment: | Users: 1 | Max Users: <unlimited> | Path: C:\tmp | Anonymous access: <none> | \\10.10.10.3\print$: | Type: STYPE_DISKTREE | Comment: Printer Drivers | Users: 1 | Max Users: <unlimited> | Path: C:\var\lib\samba\printers | Anonymous access: <none> | \\10.10.10.3\tmp: | Type: STYPE_DISKTREE | Comment: oh noes! | Users: 1 | Max Users: <unlimited> | Path: C:\tmp |_ Anonymous access: READ/WRITE
解析: - `\\10.10.10.3\ADMIN$`: 这是一个 IPC(Interprocess Communication)服务,允许管理员通过网络管理远程系统。它的路径是 `C:\tmp`,并且没有匿名访问权限。 - `\\10.10.10.3\IPC$`: 同样是一个 IPC 服务,路径也是 `C:\tmp`,但是允许匿名用户读写访问。 - `\\10.10.10.3\opt`: 这是一个磁盘树类型的共享资源,没有设置注释,路径是 `C:\tmp`,并且没有匿名访问权限。 - `\\10.10.10.3\print$`: 这是一个用于打印机驱动程序的共享资源,路径是 `C:\var\lib\samba\printers`,没有匿名访问权限。 - `\\10.10.10.3\tmp`: 这是一个磁盘树类型的共享资源,注释是 "oh noes!",路径是 `C:\tmp`,并且允许匿名用户读写访问。
|