当前位置:网站首页>Vulnhub's funfox2
Vulnhub's funfox2
2022-07-07 20:06:00 【Plum_ Flowers_ seven】
Catalog
3、 ... and 、zip Password cracking
2.john Crack the decompression password
One 、nmap Routine scanning
Scan out ftp service , And can be accessed anonymously
also 22 and 80
This range is from 80 Port did not find a breakthrough , The main page is apache The default page for , There is no hidden directory .
Two 、FTP Anonymous access
1.mget
mget *
mget Download all the files .
get Download the two hidden files
2. View hidden files
It probably means that the password is hidden zip In file . And the password of the compressed file is older
3、 ... and 、zip Password cracking
1. Transform first hash
2.john Crack the decompression password
(1)cathtine success
(2)tom success
3. Private key id_rsa Sign in
tom Can successfully login
Four 、sudo Raise the right
Can execute all sudo command , And in mysql_history The password was leaked in .
Direct use of sudo -s Mention right to success
But this is rbash One is limited shell
5、 ... and 、rbash The escape
Conditions 1: There is mysql 3306
Conditions 2:sudo Can execute all commands
1. With root function mysql
adopt mysql Directly execute operating system commands . Achieve a rebound root The powers of the shell.
边栏推荐
- Interpretation of transpose convolution theory (input-output size analysis)
- 注解。。。
- LeetCode力扣(剑指offer 36-39)36. 二叉搜索树与双向链表37. 序列化二叉树38. 字符串的排列39. 数组中出现次数超过一半的数字
- MIT科技评论文章:围绕Gato等模型的AGI炒作可能使人们忽视真正重要的问题
- YoloV6:YoloV6+Win10---训练自己得数据集
- 力扣 643. 子数组最大平均数 I
- 力扣674. 最长连续递增序列
- 毕业季|遗憾而又幸运的毕业季
- Force buckle 88 Merge two ordered arrays
- Le PGR est - il utile au travail? Comment choisir une plate - forme fiable pour économiser le cœur et la main - d'œuvre lors de la préparation de l'examen!!!
猜你喜欢
Introduction to bit operation
The state cyberspace Office released the measures for data exit security assessment: 100000 information provided overseas needs to be declared
干货分享|DevExpress v22.1原版帮助文档下载集合
YoloV6:YoloV6+Win10---训练自己得数据集
最多可以参加的会议数目[贪心 + 优先队列]
模拟实现string类
LeetCode力扣(剑指offer 36-39)36. 二叉搜索树与双向链表37. 序列化二叉树38. 字符串的排列39. 数组中出现次数超过一半的数字
开源OA开发平台:合同管理使用手册
【STL】vector
9 atomic operation class 18 Rohan enhancement
随机推荐
力扣 1232.缀点成线
Cloud 组件发展升级
vulnhub之school 1
The DBSCAN function of FPC package of R language performs density clustering analysis on data, checks the clustering labels of all samples, and the table function calculates the two-dimensional contin
编译器优化那些事儿(4):归纳变量
mysql 的一些重要知识
Semantic SLAM源码解析
Interpretation of transpose convolution theory (input-output size analysis)
831. KMP string
openEuler 有奖捉虫活动,来参与一下?
吞吐量Throughout
LeetCode_7_5
pom.xml 配置文件标签作用简述
Equals method
A pot of stew, a collection of common commands of NPM and yarn cnpm
CUDA versions are inconsistent, and errors are reported when compiling apex
Kubernetes——kubectl命令行工具用法详解
Force buckle 599 Minimum index sum of two lists
Force buckle 674 Longest continuous increasing sequence
PMP對工作有益嗎?怎麼選擇靠譜平臺讓備考更省心省力!!!