基本命令

1、获取当前组的计算机名(一般remark有Dc可能是域控):

  1. C:\Documents and Settings\Administrator\Desktop>net view
  2. Server Name Remark
  3. -----------------------------------------------------------------------------
  4. \\DC1
  5. \\DM-WINXP
  6. \\DM_WIN03
  7. The command completed successfully.

2、查看所有域

  1. C:\Documents and Settings\Administrator\Desktop>net view /domain
  2. Domain
  3. -----------------------------------------------------------------------------
  4. CENTOSO
  5. The command completed successfully.

3、从计算机名获取ipv4地址

  1. C:\Documents and Settings\Administrator\Desktop>ping -n 1 DC1 -4
  2. Pinging DC1.centoso.com [192.168.206.100] with 32 bytes of data:
  3. Reply from 192.168.206.100: bytes=32 time<1ms TTL=128
  4. Ping statistics for 192.168.206.100:
  5. Packets: Sent = 1, Received = 1, Lost = 0 (0% loss),
  6. Approximate round trip times in milli-seconds:
  7. Minimum = 0ms, Maximum = 0ms, Average = 0ms

Ps:如果计算机名很多的时候,可以利用bat批量ping获取ip

  1. @echo off
  2. setlocal ENABLEDELAYEDEXPANSION
  3. @FOR /F "usebackq eol=- skip=1 delims=\" %%j IN (`net view ^| find "命令成功完成" /v ^|find "The command completed successfully." /v`) DO (
  4. @FOR /F "usebackq delims=" %%i IN (`@ping -n 1 -4 %%j ^| findstr "Pinging"`) DO (
  5. @FOR /F "usebackq tokens=2 delims=[]" %%k IN (`echo %%i`) DO (echo %%k %%j)
  6. )
  7. )

基本命令 - 图1


以下执行命令时候会发送到域控查询,如果渗透的机器不是域用户权限,则会报错

  1. The request will be processed at a domain controller for domain
  2. System error 1326 has occurred.
  3. Logon failure: unknown user name or bad password.

4、查看域中的用户名

  1. dsquery user
  2. 或者:
  3. C:\Users\lemon\Desktop>net user /domain
  4. User accounts for \\DC1
  5. -------------------------------------------------------------------------------
  6. Administrator Guest krbtgt
  7. lemon pentest
  8. The command completed successfully.

5、查询域组名称

  1. C:\Users\lemon\Desktop>net group /domain
  2. Group Accounts for \\DC1
  3. ----------------------------------------------
  4. *DnsUpdateProxy
  5. *Domain Admins
  6. *Domain Computers
  7. *Domain Controllers
  8. *Domain Guests
  9. *Domain Users
  10. *Enterprise Admins
  11. *Enterprise Read-only Domain Controllers
  12. *Group Policy Creator Owners
  13. *Read-only Domain Controllers
  14. *Schema Admins
  15. The command completed successfully.

6、查询域管理员

  1. C:\Users\lemon\Desktop>net group "Domain Admins" /domain
  2. Group name Domain Admins
  3. Comment Designated administrators of the domain
  4. Members
  5. -----------------------------------------------------------
  6. Administrator

7、添加域管理员账号

  1. 添加普通域用户
  2. net user lemon iam@L3m0n /add /domain
  3. 将普通域用户提升为域管理员
  4. net group "Domain Admins" lemon /add /domain

8、查看当前计算机名,全名,用户名,系统版本,工作站域,登陆域

  1. C:\Documents and Settings\Administrator\Desktop>net config Workstation
  2. Computer name \\DM_WIN03
  3. Full Computer name DM_win03.centoso.com
  4. User name Administrator
  5. Workstation active on
  6. NetbiosSmb (000000000000)
  7. NetBT_Tcpip_{6B2553C1-C741-4EE3-AFBF-CE3BA1C9DDF7} (000C2985F6E4)
  8. Software version Microsoft Windows Server 2003
  9. Workstation domain CENTOSO
  10. Workstation Domain DNS Name centoso.com
  11. Logon domain DM_WIN03
  12. COM Open Timeout (sec) 0
  13. COM Send Count (byte) 16
  14. COM Send Timeout (msec) 250

9、查看域控制器(多域控制器的时候,而且只能用在域控制器上)

  1. net group "Domain controllers"

10、查询所有计算机名称

  1. dsquery computer
  2. 下面这条查询的时候,域控不会列出
  3. net group "Domain Computers" /domain

11、net命令

  1. >1、映射磁盘到本地
  2. net use z: \\dc01\sysvol
  3. >2、查看共享
  4. net view \\192.168.0.1
  5. >3、开启一个共享名为app$,在d:\config
  6. >net share app$=d:\config

12、跟踪路由

  1. tracert 8.8.8.8