当前位置:网站首页>Momentum of vulnhub
Momentum of vulnhub
2022-07-03 11:47:00 【Plum_ Flowers_ seven】
Catalog
Two 、 Service version detection
3、 ... and 、 information gathering
3. Online front-end code editing website
Four 、ssh Login to break the border
5、 ... and 、 Internal information collection
6、 ... and 、redis Unauthorized access
One 、nmap Full port scanning
nmap -sT ip
Two 、 Service version detection
3、 ... and 、 information gathering
1. Source code check
There is a note , It's about AES Encrypted .
function viewDetails(str) {
window.location.href = "opus-details.php?id="+str;
}/*
var CryptoJS = require("crypto-js");
var decrypted = CryptoJS.AES.decrypt(encrypted, "SecretPassphraseMomentum");
console.log(decrypted.toString(CryptoJS.enc.Utf8));
*/
2. There is xss
And in cookie Next, I saw a string of encrypted characters , Obviously, he wants us to use AES Decrypt him
3. Online front-end code editing website
codepen.io
Use what has been written crypto-js modular , Make a slight change AES Decrypt
Get this , It should be an account - password .
auxerre-alienum##
Four 、ssh Login to break the border
account number : auxerre
password : auxerre-alienum##
Got one flag.txt
5、 ... and 、 Internal information collection
1.、etc/passwd
Yes redis This account , Yes redis Non relational database
2. View port services
Confirm that the local is enabled redis database , Not open to the Internet .
ss -pantu
6、 ... and 、redis Unauthorized access
1. Open client
redis_cli
perform info Confirm whether there is unauthorized access vulnerability .
2.redis In the database root password
3. Switch to root
su
Just enter the password
7、 ... and 、scp command
Download a picture to this computer
scp -r ip: route ./
边栏推荐
- 如何将数字字符串转换为整数
- Hongmeng third training (project training)
- Mmc5603nj geomagnetic sensor (Compass example)
- 软件测试周刊(第78期):你对未来越有信心,你对现在越有耐心。
- Repo ~ common commands
- How to get started embedded future development direction of embedded
- Yintai department store ignites the city's "night economy"
- P3250 [hnoi2016] Network + [necpc2022] f.tree path tree section + segment tree maintenance heap
- AI模型看看视频,就学会了玩《我的世界》:砍树、造箱子、制作石镐样样不差...
- Program process management tool -go Supervisor
猜你喜欢
The tutor put forward 20 pieces of advice to help graduate students successfully complete their studies: first, don't plan to take a vacation
一文搞懂Go语言Context
MCDF实验1
金额计算用 BigDecimal 就万无一失了?看看这五个坑吧~~
银泰百货点燃城市“夜经济”
vulnhub之raven2
GCC compilation process and dynamic link library and static link library
AOSP ~ NTP ( 网络时间协议 )
Web security summary
Modular programming of single chip microcomputer
随机推荐
How to make others fear you
ASP. Net hotel management system
按键切换:按F1-F12都需要按Fn
PHP server interacts with redis with a large number of close_ Wait analysis
动态规划(区间dp)
Understand go language context in one article
CSRF
Nestjs配置服务,配置Cookie和Session
Numpy np. Max and np Maximum implements the relu function
Programmers' entrepreneurial trap: taking private jobs
This article explains the complex relationship between MCU, arm, MCU, DSP, FPGA and embedded system
Modular programming of single chip microcomputer
Program process management tool -go Supervisor
Xml的(DTD,xml解析,xml建模)
R language ggplot2 visualization: gganimate package creates dynamic line graph animation (GIF) and uses transition_ The reveal function displays data step by step along a given dimension in the animat
MySQL uses the method of updating linked tables with update
R language uses grid of gridextra package The array function combines multiple visual images of the ggplot2 package horizontally, and the ncol parameter defines the number of columns of the combined g
The world's most popular font editor FontCreator tool
The LINQ expression node type 'ArrayIndex' is not supported in LINQ to Entities
FL Studio 20无限试用版水果编曲下载