当前位置:网站首页>Momentum of vulnhub
Momentum of vulnhub
2022-07-03 11:47:00 【Plum_ Flowers_ seven】
Catalog
Two 、 Service version detection
3、 ... and 、 information gathering
3. Online front-end code editing website
Four 、ssh Login to break the border
5、 ... and 、 Internal information collection
6、 ... and 、redis Unauthorized access
One 、nmap Full port scanning
nmap -sT ip

Two 、 Service version detection

3、 ... and 、 information gathering
1. Source code check
There is a note , It's about AES Encrypted .
function viewDetails(str) {
window.location.href = "opus-details.php?id="+str;
}/*
var CryptoJS = require("crypto-js");
var decrypted = CryptoJS.AES.decrypt(encrypted, "SecretPassphraseMomentum");
console.log(decrypted.toString(CryptoJS.enc.Utf8));
*/
2. There is xss
And in cookie Next, I saw a string of encrypted characters , Obviously, he wants us to use AES Decrypt him

3. Online front-end code editing website
codepen.io
Use what has been written crypto-js modular , Make a slight change AES Decrypt 
Get this , It should be an account - password .
auxerre-alienum##
Four 、ssh Login to break the border
account number : auxerre
password : auxerre-alienum##

Got one flag.txt

5、 ... and 、 Internal information collection
1.、etc/passwd
Yes redis This account , Yes redis Non relational database

2. View port services
Confirm that the local is enabled redis database , Not open to the Internet .
ss -pantu
6、 ... and 、redis Unauthorized access
1. Open client
redis_cli
perform info Confirm whether there is unauthorized access vulnerability .
2.redis In the database root password

3. Switch to root
su
Just enter the password

7、 ... and 、scp command
Download a picture to this computer
scp -r ip: route ./
边栏推荐
- ArcGIS应用(二十一)Arcmap删除图层指定要素的方法
- 软件测试周刊(第78期):你对未来越有信心,你对现在越有耐心。
- Gut | Yu Jun group of the Chinese University of Hong Kong revealed that smoking changes intestinal flora and promotes colorectal cancer (do not smoke)
- Double linked list of linear list
- Technical experts from large factories: how can engineers improve their communication skills?
- 软考中级软件设计师该怎么备考
- 用了这么久线程池,你真的知道如何合理配置线程数吗?
- 一些常用术语
- 金额计算用 BigDecimal 就万无一失了?看看这五个坑吧~~
- Excel快速跨表复制粘贴
猜你喜欢

PHP基础

DS90UB949

解决msvcp120d.dll和msvcr120d.dll缺失

鸿蒙第四次培训

Kibana - installation and configuration of kibana

STL教程9-容器元素深拷贝和浅拷贝问题

银泰百货点燃城市“夜经济”

How to get started embedded future development direction of embedded

机器学习 3.2 决策树模型 学习笔记(待补)

Gut | Yu Jun group of the Chinese University of Hong Kong revealed that smoking changes intestinal flora and promotes colorectal cancer (do not smoke)
随机推荐
软考中级软件设计师该怎么备考
JGG专刊征稿:时空组学
多维度监控:智能监控的数据基础
vulnhub之narak
Nestjs配置服务,配置Cookie和Session
R语言使用gridExtra包的grid.arrange函数将ggplot2包的多个可视化图像横向组合起来,ncol参数自定义组合图列数、nrow参数自定义组合图行数
Go语言实现静态服务器
DS90UB949
rxjs Observable filter Operator 的实现原理介绍
R语言使用gridExtra包的grid.arrange函数将lattice包的多个可视化图像横向组合起来,ncol参数自定义组合图列数、nrow参数自定义组合图行数
The excel table is transferred to word, and the table does not exceed the edge paper range
ORACLE进阶(一) 通过EXPDP IMPDP命令实现导dmp
鸿蒙第四次培训
How should intermediate software designers prepare for the soft test
2022 northeast four provinces match VP record / supplementary questions
解决msvcp120d.dll和msvcr120d.dll缺失
2022年中南大学夏令营面试经验
Hongmeng third training (project training)
基于turtlebot3实现SLAM建图及自主导航仿真
ASP.NET-酒店管理系统