如何解决PowerShell双跳问题并远程执行Get-DomainSID?
从Kali通过PowerShell远程会话(PSSession)连接到目标系统attacker-win10(server A),该服务器已安装PowerSploit模块。需要运行Get-DomainSID命令(该命令通过LDAP与域控制器**hacklab-dc(server B)**通信获取域SID,在server A本地执行正常),但遇到双跳认证问题,测试两种方案均失败:
Case #1:嵌套Invoke-Command
$cred = Get-Credential hacklab.local\administrator [192.168.0.102]: PS C:\Users\administrator\Documents> Invoke-Command -ComputerName attacker-win10 -Credential $cred -ScriptBlock { Invoke-Command -ComputerName hacklab-dc -Credential $Using:cred -ScriptBlock {hostname}} # 返回结果:HACKLAB-DC [192.168.0.102]: PS C:\Users\administrator\Documents> Invoke-Command -ComputerName attacker-win10 -Credential $cred -ScriptBlock { Invoke-Command -ComputerName hacklab-dc -Credential $Using:cred -ScriptBlock {Get-DomainSID}}
执行hostname成功返回域控制器名称,但Get-DomainSID提示未识别:
The term 'Get-DomainSID' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the spelling of the name, or if a path was included, verify that the path is correct and try again. + CategoryInfo : ObjectNotFound: (Get-DomainSID:String) [], CommandNotFoundException + FullyQualifiedErrorId : CommandNotFoundException + PSComputerName : attacker-win10
Case #2:注册PSSession配置
[192.168.0.102]: PS C:\Users\administrator\Documents> Invoke-Command -ComputerName hacklab-dc -ScriptBlock { Register-PSSessionConfiguration -Name Demo -RunAsCredential 'hacklab.local\administrator' -Force }
输入凭据后报错:
[hacklab-dc] Connecting to remote server hacklab-dc failed with the following error message : A specified logon session does not exist. It may already have been terminated. For more information, see the about_Remote_Troubleshooting Help topic. + CategoryInfo : OpenError: (hacklab-dc:String) [], PSRemotingTransportException + FullyQualifiedErrorId : 1312,PSSessionStateBroken
更新:后台作业尝试
按建议修改命令后创建了后台作业,但无法获取输出:
┌──(asad㉿Yah-Aleemo)-[/home/asad] └─PS> Invoke-Command -Session $offsecsession -ScriptBlock &{Invoke-Command -ComputerName hacklab-dc -Credential hacklab.local\administrator -ScriptBlock &{Get-DomainSID} }
返回作业信息:
Id Name PSJobTypeName State HasMoreData Location Command -- ---- ------------- ----- ----------- -------- ------- 14 Job14 BackgroundJob Running True localhost Microsoft.PowerShell.Man… Invoke-Command -ComputerName hacklab-dc -Credential hacklab.local\administrator -ScriptBlock &{Get-DomainSID}
尝试获取输出失败:
└─PS> Invoke-Command -Session $offsecsession -ScriptBlock {Receive-job 14}
报错:
Receive-Job: The command cannot find a job with the job ID 14. Verify the value of the Id parameter and then try the command again.
1. 修复Case#1的核心问题
Get-DomainSID是PowerSploit模块专属命令,仅在server A(attacker-win10)上存在。Case#1中内层Invoke-Command是在server B(hacklab-dc)上执行命令,自然找不到该命令。正确逻辑是在server A上运行Get-DomainSID,让它直接与域控制器建立LDAP连接,同时解决双跳认证问题:
# 从Kali执行,先获取域凭据 $cred = Get-Credential hacklab.local\administrator # 连接到server A,在会话中执行操作 Invoke-Command -Session $offsecsession -Credential $cred -ScriptBlock { # 手动导入PowerSploit的Recon模块(若未自动加载) Import-Module .\PowerSploit\Recon\Recon.psm1 # 将凭据传递给Get-DomainSID,让server A用该凭据访问域控制器LDAP Get-DomainSID -Credential $Using:cred }
2. 解决后台作业输出问题
后台作业是在server A的会话中创建的,单独调用Receive-Job无法跨会话识别作业ID,需在同一个脚本块内完成作业创建与结果接收:
# 从Kali执行,在同一脚本块中处理作业 Invoke-Command -Session $offsecsession -Credential $cred -ScriptBlock { # 若需远程到server B执行命令,在同一脚本块内接收结果 $job = Invoke-Command -ComputerName hacklab-dc -Credential $Using:cred -ScriptBlock {hostname} -AsJob Receive-Job $job -Wait -AutoRemoveJob }
注意:若目标是获取域SID,仍推荐直接在server A上运行Get-DomainSID并传入凭据,无需远程到server B。
3. 长期双跳解决方案:Kerberos约束委派
若需长期解决双跳认证问题,可在AD中配置server A的约束委派,允许它代表用户访问域控制器的LDAP服务。此操作需要域管理员权限,适合持久化场景。
内容的提问来源于stack exchange,提问作者catchabyte

