当前位置:网站首页>Record a phpcms9.6.3 vulnerability to use the getshell to the intranet domain control
Record a phpcms9.6.3 vulnerability to use the getshell to the intranet domain control
2022-06-26 12:58:00 【"Iron body cell"】
information gathering
The first use of nmap Scan the network segment and collect it to the host ip Address :
nmap -sP 192.168.31.0/24

Scan host information :


The discovery could be win7 Operating system and open 80 port
getshell
Because of openness 80 port , Go directly to the website :
obtain :

Scan directory and find administrator login :

obtain :

Weak password :admin admin12345
phpcms9.6.3 backstage getshell A loophole in the , There are many online references to this blog :
https://blog.csdn.net/weixin_42433470/article/details/112409431
What I'm using here is :
user -> Administrator module -> Add member model

obtain shell:

Access permissions
Connect with an ant sword shell

And then use it cs go online :
The modules used are :
First create a listener :

The attack module used is :
attack–>web DRIVE-BY -->scripted web delivery

Generate :

Copy to ant sword to run :

cs It's online here :

CS Sniffing
shell systeminfo

obtain :



Collect to : Domain is god.org
There is an address :192.168.52.143
Raise the right


obtain system jurisdiction :
cs obtain hash
Access–>Run Minikatz


CS View the domain environment :
net view

CS Get the list of hosts in the domain :

CS Get host in domain win2008


Start to get :

Carry out orders :

CS Get host in domain WindowsServer2003

Start to get :

Execute the command to get :
shell ipconfig see ip Address

边栏推荐
- 7-1 数的范围
- 文件远程同步、备份神器rsync
- Tiger DAO VC产品正式上线,Seektiger生态的有力补充
- ES6模块
- 【网络是怎么连接的】第二章(中):一个网络包的发出
- 四类线性相位 FIR滤波器设计 —— MATLAB源码全集
- 一个快速切换一个底层实现的思路分享
- Laravel uses find_ IN_ The set() native MySQL statement accurately queries whether a special string exists in the specified string to solve the problem that like cannot be accurately matched. (resolve
- 单例的常用创建和使用方式
- PHP generate order number
猜你喜欢

Laravel+gatewayworker completes the im instant messaging and file transfer functions (Chapter 4: server debugging errors)

.NET MAUI 性能提升

别乱用 FULL_CASE 和 PARALLEL_CASE

PHP laravel+gatewayworker completes im instant messaging and file transfer (Chapter 1: basic configuration)

A must for programmers, an artifact utools that can improve your work efficiency n times

初识-软件测试

软件测试 - 概念篇
![Vivado 错误代码 [DRC PDCN-2721] 解决](/img/de/ce1a72f072254ae227fdcb307641a2.png)
Vivado 错误代码 [DRC PDCN-2721] 解决

Processsing 鼠标交互 学习
RSS rendering of solo blog system failed
随机推荐
7-1 数的范围
软件测试 - 概念篇
openlayers 绘制动态迁徙线、曲线
Several rare but useful JS techniques
美学心得(第二百三十八集) 罗国正
[极客大挑战 2019]RCE ME 1
Msvcr110 not found DLL, unable to continue code execution Solution for startup
Adobe Acrobat prevents 30 security software from viewing PDF files or there are security risks
Solution of Splunk iowait alarm
自动化测试的局限性你知道吗?
Ubuntu安装配置PostgreSQL(18.04)
PHP laravel+gatewayworker completes im instant messaging and file transfer (Chapter 1: basic configuration)
Less than 40 lines of code to create a blocprovider
power designer - 自定义注释按钮
EasyGBS如何解决对讲功能使用异常?
手把手带你学会Odoo OWL组件开发(7):OWL项目实战使用
[esp32-c3][rt-thread] run RT-Thread BSP minimum system based on esp32c3
Tiger Dao VC products are officially launched, a powerful supplement to seektiger ecology
BigInt:处理大数字(任意长度的整数)
Less than 40 lines of code to create a blocprovider