当前位置:网站首页>Vulnhub | dc: 6 | [actual combat]
Vulnhub | dc: 6 | [actual combat]
2022-07-25 20:26:00 【sayo.】
Write it at the front
Range link :
https://www.vulnhub.com/entry/dc-6,315/
Some knowledge points are DC:1 I mentioned , You can flip through
DC:1
Information gathering
Survival scan 
here 61 It's the gateway 141 It's a physical machine 164 Target machine 115 For the attacker
Port scanning 
Try to view , But somehow I jumped to a wordy The web page of 
But packet capturing can respond and the response code is 200
Here is how to modify the configuration file , By modifying the apache Of htaccess file 
The principle is pseudo static , It's not going to redirect 301 or 302, But it is also a kind of redirection .
By modifying the hosts file , You can access it through the browser , Of course , If you want to , Just look at the bag 

obviously , Here is wordpress The fingerprints of , Use as before wpscan To scan , The options used are -e, Enumerate user name options .
For more details , and wpscan Tool information , You can click here DC_2
adopt api The following user name is obtained by interface explosion 
Follow the usual line of thinking , Here you can start blasting , But I didn't react for a long time at first . I found out later , There are the following clues 
Use this command
cat /usr/share/wordlists/rockyou.txt | grep k01 > passwords.txt
The order is to kali Carry out screening with your own big dictionary , Filter keywords k01 write in passwords.txt file , Note the new passwords.txt Dictionaries
Password found 
Get the account password , Try... Separately ssh、 Website backstage 
ssh Unable to enter .
Backstage access 
Click casually to have a look , Nothing special , Installed a activity monitor plug-in unit , The breakthrough point should be here
Number :CVE-2018-15877
Look for , can RCE
Call this directly poc Script , Successful entry , But at this time, it is a low authority user 
It is inconvenient to execute commands in scripts , First bounce out and have a look , Use the following command directly nc Connect
nc 192.168.201.115 10050 -c /bin/bash

lookup suid file I haven't seen anything that can obviously raise the right for the time being 
Query the home directory under the logged in user
Find a similar memo txt file ,cat once , Find sensitive information , There's a user graham GSo7isUM1D4
Also try logging in to this user ssh You can log in 
see suid file , Obviously, there is a script that doesn't need a password 
View the script , It's writable , Append the script , Let it bounce 
After the rebound jens The account of , Keep looking at suid file , Here you are nmap classic suid Raise the right 
nmap The right point of is , It can run scripts with current permissions , Here's a getroot.sh Use nmap The option to --script To run 
Mention right to success , find flag file 
边栏推荐
- 飞行器pid控制(旋翼飞控)
- How to ensure the quality of customized slip rings
- Proxy实现mysql读写分离
- FanoutExchange交换机代码教程
- Web crawler principle analysis "suggestions collection"
- QQ是32位还是64位软件(在哪看电脑是32位还是64位)
- Kubernetes进阶部分学习笔记
- Docker builds redis cluster
- Arrow 之 Parquet
- Technology cloud report: what is the difference between zero trust and SASE? The answer is not really important
猜你喜欢

Difference Between Accuracy and Precision
![[tensorrt] dynamic batch reasoning](/img/59/42ed0074de7162887bfe2c81891e20.png)
[tensorrt] dynamic batch reasoning

当AI邂逅生命健康,华为云为他们搭建三座桥

【高等数学】【5】定积分及应用

Introduction and construction of consul Registration Center

Cloud native guide: what is cloud native infrastructure
![[today in history] July 15: Mozilla foundation was officially established; The first operation of Enigma cipher machine; Nintendo launches FC game console](/img/7d/7a01c8c6923077d6c201bf1ae02c8c.png)
[today in history] July 15: Mozilla foundation was officially established; The first operation of Enigma cipher machine; Nintendo launches FC game console

增加 swap 空间

【高等数学】【4】不定积分

Do you still have certificates to participate in the open source community?
随机推荐
[Infographics Show] 248 Public Domain Name
QML combines qsqltablemodel to dynamically load data MVC "recommended collection"
【ONNX】pytorch模型导出成ONNX格式:支持多参数与动态输入
Link list of sword finger offer question bank summary (III) (C language version)
Clickhouse notes 02 -- installation test clickvisual
网络协议:TCP Part2
What is cluster analysis? Categories of cluster analysis methods [easy to understand]
【高等数学】【1】函数、极限、连续
Go language go language built-in container
MySQL 日期【加号/+】条件筛选问题
数据库清空表数据并让主键从1开始
FanoutExchange交换机代码教程
4. Server startup of source code analysis of Nacos configuration center
RF、GBDT、XGboost特征选择方法「建议收藏」
"Share" devaxpress asp Net v22.1 latest version system environment configuration requirements
Stock software development
Technology cloud report: what is the difference between zero trust and SASE? The answer is not really important
[advanced mathematics] [5] definite integral and its application
wallys//IPQ5018/IPQ6010/PD-60 802.3AT Input Output 10/100/1000M
JVM (XXIII) -- JVM runtime parameters