当前位置:网站首页>Alfa: 1 vulnhub walkthrough
Alfa: 1 vulnhub walkthrough
2022-08-02 03:59:00 【xdeclearn】
Information Page: http://www.vulnhub.com/entry/alfa-1,655/
Keywords: Enumeration | Web Application | Brute Force |Privilege Escalation
0x01 port scan
PORT STATE SERVICE21/tcp open ftp80/tcp open http139/tcp open netbios-ssn445/tcp open microsoft-ds65111/tcp open unknown
0x02 get the first flag
Use anonymous to access ftp and get a picture named milo.jpg.
Access port 80, traverse through the directory, on the page http://192.168.56.157/alfa-support/
get the prompt information: So use the previous picture name to build a password dictionary through crunch, and hydra blasts to get the password
milo666
.
[email protected]:~$ crunch 7 7 -t milo%%% > 1.txtCrunch will now generate the following number of lines: [email protected]:~$ hydra -l thomas -P 1.txt ssh://192.168.56.157:65111[65111][ssh] host: 192.168.56.157 login: thomas password: milo666
Use ssh to log in and get the first flag.
0x03 get the second flag
After obtaining the shell, a routine operation, such as suid, sudo, crontab, backup password file, etc., all ended in failure, and in turn returned to the beginning, there is a sensitive file in the user directory .remote_secret
.
At the same time, vncserver exists in the process.It is estimated that the above password file is used to log in to vnc, but since vncserver is limited to local login, so here we use ssh as a socks5 proxy, and use vncview to load the password file under kali to achieve root access, and get the second flag.
边栏推荐
- 13.JS输出内容和语法
- js预编译 GO 和AO
- 4. PHP array and array sorting
- Query the indexes of all tables in the database and parse them into sql
- [mikehaertl/php-shellcommand] A library for invoking external command operations
- 批量替换文件字体,简体->繁体
- PHP Foundation March Press Announcement Released
- Scrapy爬虫遇见重定向301/302问题解决方法
- Orasi: 1 vulnhub walkthrough
- PHP有哪些杀手级超厉害框架或库或应用?
猜你喜欢
(6) 学生信息管理系统设计
[sebastian/diff] A historical change extension library for comparing two texts
js eventLoop 事件循环机制
ES6数组的扩展方法map、filter、reduce、fill和数组遍历for…in for…of arr.forEach
SQL:DDL、DML、DQL、DCL相应介绍以及演示
hackmyvm-hopper walkthrough
(1)Thinkphp6入门、安装视图、模板渲染、变量赋值
hackmyvm: juggling walkthrough
VIKINGS: 1 vulnhub walkthrough
DVWA drone installation tutorial
随机推荐
TCP communications program
阿里云设置域名解析重定向后,无法使用Chrome访问
PHP入门(自学笔记)
About the apache .htaccess file of tp
hackmyvm-bunny walkthrough
AES加密的各种蛋疼方式方式
Add a full image watermark to an image in PHP
PHP image compression to specified size
QR code generation API interface, which can be directly connected as an A tag
ES6数组的扩展方法map、filter、reduce、fill和数组遍历for…in for…of arr.forEach
4.表单与输入
批量替换文件字体,简体->繁体
When PHP initiates Alipay payment, the order information is garbled and solved
阿里云服务器如何使用admin账户登录
(1) print()函数、转义字符、二进制与字符编码 、变量、数据类型、input()函数、运算符
kali安装IDEA
13. JS output content and syntax
1. Beginning with PHP
查询数据库中所有表的索引,并且解析成sql
[campo/random-user-agent]随机伪造你的User-Agent