当前位置:网站首页>vulnhub之pyexp
vulnhub之pyexp
2022-07-03 11:05:00 【梅_花_七】
banner信息:Banner信息,欢迎语,在banner信息中可以得到软件开发商,软件名称、版本、服务类型等信息
目录
一、主机发现

二、端口扫描

三、服务版本发现
发现只有两个端口。分别是开放了ssh和mysql。

四、hydra暴力破解
没有web应用,只能从ssh或者是mysql突破边界。从信息的收集来看,ssh和mysql都是支持远程登录的。
1.mysql穷举
爆破出来密码是:prettywoman

2.ssh穷举
没有爆破出来,可见密码复杂或者是字典不行。
五、mysql攻击
1.攻击服务器系统
(1)\!
如果是默认配置的话,以开启mysql用户进程的属主权限来执行命令
尝试失败,我们进行命令执行,返回了我们自己的bash。

(2)利用命令执行函数
select do_system('id')
显示不存在,失败

(3)尝试读取系统文件
select load_file('/etc/passwd')
知道一个信息,能通过shell登录的只有root和lucy

2.数据库信息泄露
既然都登陆进来了,当然要看数据库信息,在data数据库下,我们可以看到一个fernet(python加密算法),里面存着一串加密信息。


六、python的fernet解密
1.python官方手册

2.key和value分析
我们对这个key和value的格式进行了分析,结合数据库中获取的值,来进行解密。

3.解密
成功解出lucy的密码
七、登录lucy

八、信息收集
1.sudo配置
2.exp.py
就是用来执行命令的一个py文件

九、提权
import pty;pty.spawn('/bin/bash')

边栏推荐
- PHP server interacts with redis with a large number of close_ Wait analysis
- How to make others fear you
- How should intermediate software designers prepare for the soft test
- 2022 东北四省赛 VP记录/补题
- 《剑指offer 04》二维数组查找
- STL教程9-容器元素深拷贝和浅拷贝问题
- This article explains the complex relationship between MCU, arm, MCU, DSP, FPGA and embedded system
- Mysql根据时间搜索常用方法整理
- After watching the video, AI model learned to play my world: cutting trees, making boxes, making stone picks, everything is good
- 同事写了一个责任链模式,bug无数...
猜你喜欢

Gut | Yu Jun group of the Chinese University of Hong Kong revealed that smoking changes intestinal flora and promotes colorectal cancer (do not smoke)

How to clean up v$rman_ backup_ job_ Details view reports error ora-02030

FL Studio 20 unlimited trial fruit arranger Download

Yintai department store ignites the city's "night economy"

After using the thread pool for so long, do you really know how to reasonably configure the number of threads?

软件测试周刊(第78期):你对未来越有信心,你对现在越有耐心。

vulnhub之GeminiInc

Understand go language context in one article

C语言 AES加解密

2022 northeast four provinces match VP record / supplementary questions
随机推荐
Slam mapping and autonomous navigation simulation based on turnlebot3
. \vmware-vdiskmanager. exe -k “c:\\xxxxx.vmdk”
P3250 [hnoi2016] Network + [necpc2022] f.tree path tree section + segment tree maintenance heap
R language uses data The table package performs data aggregation statistics, calculates window statistics, calculates the median of sliding groups, and merges the generated statistical data into the o
CSRF
Understand go language context in one article
简单工厂和工厂方法模式
2022 东北四省赛 VP记录/补题
Stm32hal library upgrades firmware based on flash analog U disk (detailed explanation)
Cacti监控Redis实现过程
2022年中南大学夏令营面试经验
软考中级软件设计师该怎么备考
Asyncio warning deprecationwarning: there is no current event loop
(database authorization - redis) summary of unauthorized access vulnerabilities in redis
vulnhub之Ripper
How to get started embedded future development direction of embedded
The excel table is transferred to word, and the table does not exceed the edge paper range
R语言使用原生包(基础导入包、graphics)中的hist函数可视化直方图(histogram plot)
一文搞懂Go语言Context
uniapp scroll view 解决高度自适应、弹框滚动穿透等问题。