当前位置:网站首页>Vulnhub narak
Vulnhub narak
2022-07-03 11:47:00 【Plum_ Flowers_ seven】
Catalog
Two 、 Service version detection
3、 ... and 、 information gathering
Four 、dirsearch Catalog explosion
6、 ... and 、cewl Custom dictionary
8、 ... and 、davtest Upload bounce shell
One 、 Full open scan
Two 、 Service version detection
3、 ... and 、 information gathering
No interface is found in the source code comment , Source code leakage , Hide directories, etc
either robots.txt,readme.txt file .
No files contain ,sql Inject ,xss And other common vulnerabilities
Other jump pages also have no information that can help us manage our success
Four 、dirsearch Catalog explosion
1. Default dictionary and status code 401
401 Indicates that the directory exists , But it needs to be verified
403 Indicates that a directory or file exists , But refuse to request resources , Because of the server configuration
404 not found No .
2.dirb Common Dictionaries
dirsearch -u http://192.168.29.135 -f -e html,txt,php -w /usr/share/wordlists/dirb/common.txt
Here is a tips.txt, But this information is useless
5、 ... and 、webdav
webdav effect :
Is based on http1.1 A communication protocol , Be similar to ftp An agreement of , You can upload and download files . This is our breakthrough point , Try admin/admin guest/guest root/root And other common weak passwords . Not successful . We have to blow up , But I don't even know the user name , This blasting is too difficult . So try to customize the dictionary to attack
6、 ... and 、cewl Custom dictionary
working principle : Crawl through the crawler to get the corresponding URL Various resources on , Through analysis and combination , Generate a dictionary .
cewl http://192.168.29.135/ > dict.txt
perhaps
cewl http://192.168.29.135/ -w dict.txt
7、 ... and 、hydra Blast
Successfully logged in
8、 ... and 、davtest Upload bounce shell
1. Test statement
davtest -auth yamdoot:Swarg -url http://192.168.29.135/webdav
Which can be uploaded , What can be executed , Be crystal clear
There is a target here php Running environment
2. Upload php
What we use is kali There is one php rebound shell
davtest -auth yamdoot:Swarg -uploadfile php-reverse-shell.php -uploadloc exp.php -url http://192.168.29.135/webdav
3. Monitor execution
Nine 、0day Raise the right
adopt CVE-2021-3479 Right to come .
The target didn't gcc Compiler tools , Upload and execute after local compilation .
Ten 、 Normal right raising
1. information gathering
Find a subordinate as root, Permissions belong to the master and the group, which can be executed , Other documents that can be written , Find one hell.sh file , Check the content and find that it is a paragraph BF Words of language
find / -user root -type f -perm -ug=x,o=w -exec ls -al {} \; 2>/dev/null
11、 ... and 、BF Language
The full name is brainfuck
This website executes this language , Get a string of characters :chitragupt, Try to get the permission of a normal user as a password ,ssh here we are inferno This user
tio.run/#brainfuck
first flag.txt
Twelve 、modo Inject
1. information gathering
There is one 00-header file , And it's a shell Script
2.motd
motd English full name :message of the day Chinese interpretation : Daily tips , The function is that when we log in , To execute motd file , Achieve the purpose of prompt . The rest of us also have the right to modify , And the owner is root, Can be used to raise rights .
3. modify 00-header file
Add... At the end shell sentence
4.su root
边栏推荐
- Slam mapping and autonomous navigation simulation based on turnlebot3
- 如何将数字字符串转换为整数
- libvirt 中体验容器
- 程序员的创业陷阱:接私活
- ftp登录时,报错“530 Login incorrect.Login failed”
- Asyncio warning deprecationwarning: there is no current event loop
- Capturing and sorting out external Fiddler -- Conversation bar and filter [2]
- Visual Studio 2022下载及配置OpenCV4.5.5
- 同事写了一个责任链模式,bug无数...
- How to get started embedded future development direction of embedded
猜你喜欢
vulnhub之GeminiInc
Kibana - installation and configuration of kibana
【学习笔记】dp 状态与转移
Groovy测试类 和 Junit测试
Software testing weekly (issue 78): the more confident you are about the future, the more patient you are about the present.
Kubernetes 三打探针及探针方式
The uniapp scroll view solves the problems of high adaptability and bullet frame rolling penetration.
ftp登录时,报错“530 Login incorrect.Login failed”
After watching the video, AI model learned to play my world: cutting trees, making boxes, making stone picks, everything is good
How to get started embedded future development direction of embedded
随机推荐
VS2015的下载地址和安装教程
Using onvif protocol to operate the device
previous permutation lintcode51
Web security summary
Cuiyusong, CTO of youzan: the core goal of Jarvis is to make products smarter and more reliable
CSRF
R language uses grid of gridextra package The array function combines multiple visual images of the lattice package horizontally, and the ncol parameter defines the number of columns of the combined g
cgroup简介
量化计算调研
Program process management tool -go Supervisor
Dynamic programming (interval DP)
Uniapp implementation Click to load more
The R language uses the hist function in the native package (basic import package, graphics) to visualize the histogram plot
AOSP ~ NTP ( 网络时间协议 )
优化接口性能
The excel table is transferred to word, and the table does not exceed the edge paper range
The world's most popular font editor FontCreator tool
Kibana - installation and configuration of kibana
Excel快速跨表复制粘贴
FL Studio 20无限试用版水果编曲下载