当前位置:网站首页>Vulnhub's funfox2
Vulnhub's funfox2
2022-07-07 20:06:00 【Plum_ Flowers_ seven】
Catalog
3、 ... and 、zip Password cracking
2.john Crack the decompression password
One 、nmap Routine scanning
Scan out ftp service , And can be accessed anonymously
also 22 and 80
This range is from 80 Port did not find a breakthrough , The main page is apache The default page for , There is no hidden directory .

Two 、FTP Anonymous access
1.mget
mget *
mget Download all the files .
get Download the two hidden files
2. View hidden files
It probably means that the password is hidden zip In file . And the password of the compressed file is older


3、 ... and 、zip Password cracking
1. Transform first hash

2.john Crack the decompression password
(1)cathtine success

(2)tom success

3. Private key id_rsa Sign in
tom Can successfully login

Four 、sudo Raise the right
Can execute all sudo command , And in mysql_history The password was leaked in .
Direct use of sudo -s Mention right to success
But this is rbash One is limited shell


5、 ... and 、rbash The escape
Conditions 1: There is mysql 3306
Conditions 2:sudo Can execute all commands
1. With root function mysql
adopt mysql Directly execute operating system commands . Achieve a rebound root The powers of the shell.


边栏推荐
- 剑指 Offer II 013. 二维子矩阵的和
- Visual Studio 插件之CodeMaid自动整理代码
- tp6 实现佣金排行榜
- ASP. Net learning & ASP's one word
- JVM class loading mechanism
- Semantic SLAM源码解析
- Dynamic addition of El upload upload component; El upload dynamically uploads files; El upload distinguishes which component uploads the file.
- pom.xml 配置文件标签:dependencies 和 dependencyManagement 区别
- Automatic classification of defective photovoltaic module cells in electroluminescence images-论文阅读笔记
- 如何在软件研发阶段落地安全实践
猜你喜欢

Welcome to the markdown editor

BI的边界:BI不适合做什么?主数据、MarTech?该如何扩展?
Make this crmeb single merchant wechat mall system popular, so easy to use!

Force buckle 599 Minimum index sum of two lists

vulnhub之tre1

Detailed explanation of Flink parallelism and slot
![最多可以参加的会议数目[贪心 + 优先队列]](/img/f3/e8e939e0393efc404cc159d7d33364.png)
最多可以参加的会议数目[贪心 + 优先队列]

Vulnhub tre1

国家网信办公布《数据出境安全评估办法》:累计向境外提供10万人信息需申报

项目经理『面试八问』,看了等于会了
随机推荐
时间工具类
Force buckle 1037 Effective boomerang
JVM GC garbage collection brief
力扣 912.排序数组
The DBSCAN function of FPC package of R language performs density clustering analysis on data, checks the clustering labels of all samples, and the table function calculates the two-dimensional contin
使用高斯Redis实现二级索引
Cloud 组件发展升级
Mysql, sqlserver Oracle database connection mode
PMP practice once a day | don't get lost in the exam -7.7
Equals method
openEuler 有奖捉虫活动,来参与一下?
Time tools
Force buckle 2319 Judge whether the matrix is an X matrix
TS快速入门-泛型
Visual Studio 插件之CodeMaid自动整理代码
8 CAS
LeetCode_ 7_ five
多个线程之间如何协同
JVM GC垃圾回收简述
Welcome to the markdown editor