{"id":17942,"date":"2020-02-04T15:05:26","date_gmt":"2020-02-04T07:05:26","guid":{"rendered":"http:\/\/4563.org\/?p=17942"},"modified":"2020-02-04T15:05:26","modified_gmt":"2020-02-04T07:05:26","slug":"%e5%a4%a7%e5%a9%b6%e4%bb%ac%e5%b8%ae%e5%bf%99%e5%88%86%e6%9e%90%e4%b8%8b%e8%bf%99%e4%b8%aa%e6%97%a5%e5%bf%97%e5%91%97-%e6%9c%89%e7%82%b9%e6%85%8c","status":"publish","type":"post","link":"http:\/\/4563.org\/?p=17942","title":{"rendered":"\u5927\u5a76\u4eec\u5e2e\u5fd9\u5206\u6790\u4e0b\u8fd9\u4e2a\u65e5\u5fd7\u5457 \u6709\u70b9\u614c"},"content":{"rendered":"\n<p>  \t\t\t\t\t<strong>lna<\/strong>  \t\t\t\t\u5927\u4f6c\u6709\u8bdd\u8bf4 : \t<\/p>\n<h3>\u5927\u5a76\u4eec\u5e2e\u5fd9\u5206\u6790\u4e0b\u8fd9\u4e2a\u65e5\u5fd7\u5457 \u6709\u70b9\u614c<\/h3>\n<p>  \t\t\u8fd9\u4e2a\u662f\u4ec0\u4e48\u767b\u9646\u5440\uff1f\u662f\u4e0d\u662f\u88ab\u5165\u4fb5\u4e86\uff1f<\/p>\n<p>  \u65e5\u5fd7\u540d\u79f0:&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; &nbsp; Security<br \/>  \u6765\u6e90:&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;Microsoft-Windows-Security-Auditing<br \/>  \u65e5\u671f:&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;2020\/2\/4 11:08:05<br \/>  \u4e8b\u4ef6 ID:&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;4624<br \/>  \u4efb\u52a1\u7c7b\u522b:&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; &nbsp; \u767b\u5f55<br \/>  \u7ea7\u522b:&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;\u4fe1\u606f<br \/>  \u5173\u952e\u5b57:&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;\u5ba1\u6838\u6210\u529f<br \/>  \u7528\u6237:&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;\u6682\u7f3a<br \/>  \u8ba1\u7b97\u673a:&nbsp; &nbsp;&nbsp; &nbsp;&nbsp; &nbsp;WIN-1GIDUT4AGV9<br \/>  \u63cf\u8ff0:<br \/>  \u5df2\u6210\u529f\u767b\u5f55\u5e10\u6237\u3002<\/p>\n<p>  \u4f7f\u7528\u8005:<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; \u5b89\u5168 ID:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; SYSTEM<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; \u5e10\u6237\u540d:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; WIN-1GIDUT4AGV9$<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; \u5e10\u6237\u57df:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; WORKGROUP<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; \u767b\u5f55 ID:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0x3E7<\/p>\n<p>  \u767b\u5f55\u7c7b\u578b:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 5<\/p>\n<p>  \u6a21\u62df\u7ea7\u522b:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; \u6a21\u62df<\/p>\n<p>  \u65b0\u767b\u5f55:<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; \u5b89\u5168 ID:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; SYSTEM<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; \u5e10\u6237\u540d:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; SYSTEM<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; \u5e10\u6237\u57df:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; NT AUTHORITY<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; \u767b\u5f55 ID:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0x3E7<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; \u767b\u5f55 GUID:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; {00000000-0000-0000-0000-000000000000}<\/p>\n<p>  \u8fdb\u7a0b\u4fe1\u606f:<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; \u8fdb\u7a0b ID:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0x2ac<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; \u8fdb\u7a0b\u540d:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; C:WindowsSystem32services.exe<\/p>\n<p>  \u7f51\u7edc\u4fe1\u606f:<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; \u5de5\u4f5c\u7ad9\u540d:&nbsp; &nbsp; &nbsp; &nbsp; &#8211;<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; \u6e90\u7f51\u7edc\u5730\u5740:&nbsp; &nbsp; &nbsp; &nbsp; &#8211;<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; \u6e90\u7aef\u53e3:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &#8211;<\/p>\n<p>  \u8be6\u7ec6\u8eab\u4efd\u9a8c\u8bc1\u4fe1\u606f:<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; \u767b\u5f55\u8fdb\u7a0b:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Advapi<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; \u8eab\u4efd\u9a8c\u8bc1\u6570\u636e\u5305:&nbsp; &nbsp; &nbsp; &nbsp; Negotiate<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; \u4f20\u9012\u7684\u670d\u52a1:&nbsp; &nbsp; &nbsp; &nbsp; &#8211;<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; \u6570\u636e\u5305\u540d(\u4ec5\u9650 NTLM):&nbsp; &nbsp; &nbsp; &nbsp; &#8211;<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; \u5bc6\u94a5\u957f\u5ea6:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0<\/p>\n<p>  \u521b\u5efa\u767b\u5f55\u4f1a\u8bdd\u540e\uff0c\u5728\u88ab\u8bbf\u95ee\u7684\u8ba1\u7b97\u673a\u4e0a\u751f\u6210\u6b64\u4e8b\u4ef6\u3002<\/p>\n<p>  \u201c\u4f7f\u7528\u8005\u201d\u5b57\u6bb5\u6307\u660e\u672c\u5730\u7cfb\u7edf\u4e0a\u8bf7\u6c42\u767b\u5f55\u7684\u5e10\u6237\u3002\u8fd9\u901a\u5e38\u662f\u4e00\u4e2a\u670d\u52a1(\u4f8b\u5982 Server \u670d\u52a1)\u6216\u672c\u5730\u8fdb\u7a0b(\u4f8b\u5982 Winlogon.exe \u6216 Services.exe)\u3002<\/p>\n<p>  \u201c\u767b\u5f55\u7c7b\u578b\u201d\u5b57\u6bb5\u6307\u660e\u53d1\u751f\u7684\u767b\u5f55\u79cd\u7c7b\u3002\u6700\u5e38\u89c1\u7684\u7c7b\u578b\u662f 2 (\u4ea4\u4e92\u5f0f)\u548c 3 (\u7f51\u7edc)\u3002<\/p>\n<p>  \u201c\u65b0\u767b\u5f55\u201d\u5b57\u6bb5\u6307\u660e\u65b0\u767b\u5f55\u662f\u4e3a\u54ea\u4e2a\u5e10\u6237\u521b\u5efa\u7684\uff0c\u5373\u767b\u5f55\u7684\u5e10\u6237\u3002<\/p>\n<p>  \u201c\u7f51\u7edc\u201d\u5b57\u6bb5\u6307\u660e\u8fdc\u7a0b\u767b\u5f55\u8bf7\u6c42\u6765\u81ea\u54ea\u91cc\u3002\u201c\u5de5\u4f5c\u7ad9\u540d\u201d\u5e76\u975e\u603b\u662f\u53ef\u7528\uff0c\u800c\u4e14\u5728\u67d0\u4e9b\u60c5\u51b5\u4e0b\u53ef\u80fd\u4f1a\u7559\u4e3a\u7a7a\u767d\u3002<\/p>\n<p>  \u6a21\u62df\u7ea7\u522b\u5b57\u6bb5\u6307\u660e\u767b\u5f55\u4f1a\u8bdd\u4e2d\u7684\u8fdb\u7a0b\u53ef\u4ee5\u6a21\u62df\u7684\u7a0b\u5ea6\u3002<\/p>\n<p>  \u201c\u8eab\u4efd\u9a8c\u8bc1\u4fe1\u606f\u201d\u5b57\u6bb5\u63d0\u4f9b\u5173\u4e8e\u6b64\u7279\u5b9a\u767b\u5f55\u8bf7\u6c42\u7684\u8be6\u7ec6\u4fe1\u606f\u3002<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; -\u201c\u767b\u5f55 GUID\u201d\u662f\u53ef\u7528\u4e8e\u5c06\u6b64\u4e8b\u4ef6\u4e0e KDC \u4e8b\u4ef6\u5173\u8054\u8d77\u6765\u7684\u552f\u4e00\u6807\u8bc6\u7b26\u3002<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; -\u201c\u4f20\u9012\u7684\u670d\u52a1\u201d\u6307\u660e\u54ea\u4e9b\u4e2d\u95f4\u670d\u52a1\u53c2\u4e0e\u4e86\u6b64\u767b\u5f55\u8bf7\u6c42\u3002<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; &#8211; \u201c\u6570\u636e\u5305\u540d\u201d\u6307\u660e\u5728 NTLM \u534f\u8bae\u4e4b\u95f4\u4f7f\u7528\u4e86\u54ea\u4e9b\u5b50\u534f\u8bae\u3002<br \/>  &nbsp; &nbsp; &nbsp; &nbsp; -\u201c\u5bc6\u94a5\u957f\u5ea6\u201d\u6307\u660e\u751f\u6210\u7684\u4f1a\u8bdd\u5bc6\u94a5\u7684\u957f\u5ea6\u3002\u5982\u679c\u6ca1\u6709\u8bf7\u6c42\u4f1a\u8bdd\u5bc6\u94a5\uff0c\u5219\u6b64\u5b57\u6bb5\u4e3a 0\u3002<br \/>  \u4e8b\u4ef6 Xml:<br \/>  &lt;Event xmlns=&quot;http:\/\/schemas.microsoft.com\/win\/2004\/08\/events\/event&quot;&gt;<br \/>  &lt;System&gt;<br \/>  &nbsp; &nbsp; &lt;Provider Name=&quot;Microsoft-Windows-Security-Auditing&quot; Guid=&quot;{54849625-5478-4994-A5BA-3E3B0328C30D}&quot; \/&gt;<br \/>  &nbsp; &nbsp; &lt;EventID&gt;4624&lt;\/EventID&gt;<br \/>  &nbsp; &nbsp; &lt;Version&gt;1&lt;\/Version&gt;<br \/>  &nbsp; &nbsp; &lt;Level&gt;0&lt;\/Level&gt;<br \/>  &nbsp; &nbsp; &lt;Task&gt;12544&lt;\/Task&gt;<br \/>  &nbsp; &nbsp; &lt;Opcode&gt;0&lt;\/Opcode&gt;<br \/>  &nbsp; &nbsp; &lt;Keywords&gt;0x8020000000000000&lt;\/Keywords&gt;<br \/>  &nbsp; &nbsp; &lt;TimeCreated SystemTime=&quot;2020-02-04T03:08:05.531779300Z&quot; \/&gt;<br \/>  &nbsp; &nbsp; &lt;EventRecordID&gt;7949&lt;\/EventRecordID&gt;<br \/>  &nbsp; &nbsp; &lt;Correlation \/&gt;<br \/>  &nbsp; &nbsp; &lt;Execution ProcessID=&quot;692&quot; ThreadID=&quot;6800&quot; \/&gt;<br \/>  &nbsp; &nbsp; &lt;Channel&gt;Security&lt;\/Channel&gt;<br \/>  &nbsp; &nbsp; &lt;Computer&gt;WIN-1GIDUT4AGV9&lt;\/Computer&gt;<br \/>  &nbsp; &nbsp; &lt;Security \/&gt;<br \/>  &lt;\/System&gt;<br \/>  &lt;EventData&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;SubjectUserSid&quot;&gt;S-1-5-18&lt;\/Data&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;SubjectUserName&quot;&gt;WIN-1GIDUT4AGV9$&lt;\/Data&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;SubjectDomainName&quot;&gt;WORKGROUP&lt;\/Data&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;SubjectLogonId&quot;&gt;0x3e7&lt;\/Data&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;TargetUserSid&quot;&gt;S-1-5-18&lt;\/Data&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;TargetUserName&quot;&gt;SYSTEM&lt;\/Data&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;TargetDomainName&quot;&gt;NT AUTHORITY&lt;\/Data&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;TargetLogonId&quot;&gt;0x3e7&lt;\/Data&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;LogonType&quot;&gt;5&lt;\/Data&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;LogonProcessName&quot;&gt;Advapi&lt;\/Data&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;AuthenticationPackageName&quot;&gt;Negotiate&lt;\/Data&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;WorkstationName&quot;&gt;-&lt;\/Data&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;LogonGuid&quot;&gt;{00000000-0000-0000-0000-000000000000}&lt;\/Data&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;TransmittedServices&quot;&gt;-&lt;\/Data&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;LmPackageName&quot;&gt;-&lt;\/Data&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;KeyLength&quot;&gt;0&lt;\/Data&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;ProcessId&quot;&gt;0x2ac&lt;\/Data&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;ProcessName&quot;&gt;C:WindowsSystem32services.exe&lt;\/Data&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;IpAddress&quot;&gt;-&lt;\/Data&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;IpPort&quot;&gt;-&lt;\/Data&gt;<br \/>  &nbsp; &nbsp; &lt;Data Name=&quot;ImpersonationLevel&quot;&gt;%%1833&lt;\/Data&gt;<br \/>  &lt;\/EventData&gt;<br \/>  &lt;\/Event&gt;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>lna \u5927\u4f6c\u6709\u8bdd\u8bf4 : \u5927\u5a76\u4eec\u5e2e\u5fd9&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[],"tags":[],"_links":{"self":[{"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/posts\/17942"}],"collection":[{"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17942"}],"version-history":[{"count":0,"href":"http:\/\/4563.org\/index.php?rest_route=\/wp\/v2\/posts\/17942\/revisions"}],"wp:attachment":[{"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17942"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17942"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/4563.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17942"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}