当前位置:网站首页>Vulnhub narak
Vulnhub narak
2022-07-03 11:47:00 【Plum_ Flowers_ seven】
Catalog
Two 、 Service version detection
3、 ... and 、 information gathering
Four 、dirsearch Catalog explosion
6、 ... and 、cewl Custom dictionary
8、 ... and 、davtest Upload bounce shell
One 、 Full open scan

Two 、 Service version detection

3、 ... and 、 information gathering
No interface is found in the source code comment , Source code leakage , Hide directories, etc
either robots.txt,readme.txt file .
No files contain ,sql Inject ,xss And other common vulnerabilities
Other jump pages also have no information that can help us manage our success
Four 、dirsearch Catalog explosion
1. Default dictionary and status code 401
401 Indicates that the directory exists , But it needs to be verified
403 Indicates that a directory or file exists , But refuse to request resources , Because of the server configuration
404 not found No .

2.dirb Common Dictionaries
dirsearch -u http://192.168.29.135 -f -e html,txt,php -w /usr/share/wordlists/dirb/common.txt

Here is a tips.txt, But this information is useless

5、 ... and 、webdav
webdav effect :
Is based on http1.1 A communication protocol , Be similar to ftp An agreement of , You can upload and download files . This is our breakthrough point , Try admin/admin guest/guest root/root And other common weak passwords . Not successful . We have to blow up , But I don't even know the user name , This blasting is too difficult . So try to customize the dictionary to attack

6、 ... and 、cewl Custom dictionary
working principle : Crawl through the crawler to get the corresponding URL Various resources on , Through analysis and combination , Generate a dictionary .
cewl http://192.168.29.135/ > dict.txt
perhaps
cewl http://192.168.29.135/ -w dict.txt
7、 ... and 、hydra Blast

Successfully logged in

8、 ... and 、davtest Upload bounce shell
1. Test statement
davtest -auth yamdoot:Swarg -url http://192.168.29.135/webdav
Which can be uploaded , What can be executed , Be crystal clear
There is a target here php Running environment

2. Upload php
What we use is kali There is one php rebound shell
davtest -auth yamdoot:Swarg -uploadfile php-reverse-shell.php -uploadloc exp.php -url http://192.168.29.135/webdav

3. Monitor execution

Nine 、0day Raise the right
adopt CVE-2021-3479 Right to come .
The target didn't gcc Compiler tools , Upload and execute after local compilation .

Ten 、 Normal right raising
1. information gathering
Find a subordinate as root, Permissions belong to the master and the group, which can be executed , Other documents that can be written , Find one hell.sh file , Check the content and find that it is a paragraph BF Words of language
find / -user root -type f -perm -ug=x,o=w -exec ls -al {} \; 2>/dev/null

11、 ... and 、BF Language
The full name is brainfuck
This website executes this language , Get a string of characters :chitragupt, Try to get the permission of a normal user as a password ,ssh here we are inferno This user
tio.run/#brainfuck

first flag.txt

Twelve 、modo Inject
1. information gathering
There is one 00-header file , And it's a shell Script


2.motd
motd English full name :message of the day Chinese interpretation : Daily tips , The function is that when we log in , To execute motd file , Achieve the purpose of prompt . The rest of us also have the right to modify , And the owner is root, Can be used to raise rights .
3. modify 00-header file
Add... At the end shell sentence

4.su root

边栏推荐
- vulnhub之momentum
- Based on MCU, how to realize OTA differential upgrade with zero code and no development?
- phpcms 提示信息頁面跳轉showmessage
- After watching the video, AI model learned to play my world: cutting trees, making boxes, making stone picks, everything is good
- How to clean up v$rman_ backup_ job_ Details view reports error ora-02030
- 利用Zabbix动态监控磁盘I/O
- Gut | Yu Jun group of the Chinese University of Hong Kong revealed that smoking changes intestinal flora and promotes colorectal cancer (do not smoke)
- 在CoreOS下部署WordPress实例教程
- Kubernetes 三打探针及探针方式
- Linear table sequence table comprehensive application problem p18
猜你喜欢

同事写了一个责任链模式,bug无数...

Kibana - installation and configuration of kibana

Excel快速跨表复制粘贴

Numpy np.max和np.maximum实现relu函数

鸿蒙第三次培训(项目实训)

C语言 AES加解密

This article explains the complex relationship between MCU, arm, MCU, DSP, FPGA and embedded system

PHP Basics

Use typora to draw flow chart, sequence diagram, sequence diagram, Gantt chart, etc. for detailed explanation

多维度监控:智能监控的数据基础
随机推荐
POI excel cell wrap
This article explains the complex relationship between MCU, arm, MCU, DSP, FPGA and embedded system
Repo ~ common commands
金额计算用 BigDecimal 就万无一失了?看看这五个坑吧~~
银泰百货点燃城市“夜经济”
Extrapolated scatter data
Capturing and sorting out external Fiddler -- Conversation bar and filter [2]
. \vmware-vdiskmanager. exe -k “c:\\xxxxx.vmdk”
Dynamic programming (interval DP)
动态规划(区间dp)
How should intermediate software designers prepare for the soft test
The LINQ expression node type 'ArrayIndex' is not supported in LINQ to Entities
程序员的创业陷阱:接私活
导师对帮助研究生顺利完成学业提出了20条劝告:第一,不要有度假休息的打算.....
鸿蒙第四次培训
Software testing weekly (issue 78): the more confident you are about the future, the more patient you are about the present.
Mmc5603nj geomagnetic sensor (Compass example)
Web安全总结
Cadence background color setting
ORACLE进阶(一) 通过EXPDP IMPDP命令实现导dmp