当前位置:网站首页>HTB-Shocker
HTB-Shocker
2022-08-01 14:04:00 【How good is always late at night.】
Information Collection
- ssh
- http
There is very little information collected, the directory should be scanned for additional extensions, dirbuster only has the php extension by default.
Take a look at user.txt
, I found that I don't seem to understand it.
Go search to see what is the relationship between the twoWhat conditions do these two meet?
I got something and found Shellshock
Power On
Elevation of Privilege
How to create a /bin/bash session through perl, I found the parameter for one-time code execution by searching -e
Also searched for perl commands to execute system commands
No accident exec
also works
边栏推荐
- D - Draw Your Cards(模拟)
- 让程序员早点下班的效率工具
- gpio analog serial communication
- 制售假劣农资、非法占用耕地……公安部公布十起危害粮食生产安全犯罪典型案例
- A Beginner's Guide to Performance Testing
- 灵魂发问:MySQL是如何解决幻读的?
- 免费使用高性能的GPU和TPU—谷歌Colab使用教程
- tensorflow2.0 handwritten digit recognition (tensorflow handwriting recognition)
- iPhone难卖,被欧洲反垄断的服务业务也难赚钱了,苹果的日子艰难
- PAT1165 Block Reversing(25)
猜你喜欢
[LiteratureReview]Optimal and Robust Category-level Perception: Object Pose and Shape Estimation f
The basic knowledge of scripting language Lua summary
如何使用OpenCV测量图像中物体之间的距离
【二叉树】路径总和II
消息中间件解析 | 如何正确理解软件应用系统中关于系统通信的那些事?
Multi-threaded cases - blocking queue
Gradle series - Gradle tests, Gradle life cycle, settings.gradle description, Gradle tasks (based on Groovy documentation 4.0.4) day2-3
postgresql之page分配管理(一)
易优压双驱挖掘机压路机器类网站源码 v1.5.8
PAT1166 Summit(25)
随机推荐
PIR人体感应AC系列感应器投光灯人体感应开关等应用定制方案
datetime64[ns]转化为datetime
NebulaGraph v3.2.0 Performance Report
28uA待机8米距离低压保护单片机探头太阳能灯人体PIR定制方案
【每日一题】952. 按公因数计算最大组件大小
Why does the maximum plus one equal the minimum
【无标题】
数据挖掘-04
经纬信息IPO过会:年营收3.5亿 叶肖华控制46.3%股权
直播系统聊天技术(八):vivo直播系统中IM消息模块的架构实践
DDL和DML的含义与区别「建议收藏」
高仿项目协作工具【Worktile】,从零带你一步步实现组织架构、网盘、消息、项目、审批等功能
Programmer's Romantic Tanabata
魔众文档管理系统 v5.0.0
分布式中的远程调用
Istio投入生产的障碍以及如何解决这些问题
iframe标签属性说明 详解[通俗易懂]
iPhone难卖,被欧洲反垄断的服务业务也难赚钱了,苹果的日子艰难
【无标题】
MBI5020 LED驱动