当前位置:网站首页>Vulnhub pyexp
Vulnhub pyexp
2022-07-03 11:52:00 【Plum_ Flowers_ seven】
banner Information :Banner Information , Welcome , stay banner Information can be obtained from software developers , Software name 、 edition 、 Service type, etc
Catalog
3、 ... and 、 Service version discovery
2. Database information disclosure
6、 ... and 、python Of fernet Decrypt
8、 ... and 、 information gathering
One 、 The host found
Two 、 Port scanning
3、 ... and 、 Service version discovery
It is found that there are only two ports . They are open ssh and mysql.
Four 、hydra Brute force
No, web application , Only from ssh Or is it mysql Break through the border . From the collection of information ,ssh and mysql All support remote login .
1.mysql Exhausting
The burst password is :prettywoman
2.ssh Exhausting
It didn't explode , It can be seen that the password is complex or the dictionary is not good .
5、 ... and 、mysql attack
1. Attack server system
(1)\!
If it is the default configuration , In order to open mysql Execute commands within the sovereignty of the user process
The attempt failed , We carry out orders , Back to our own bash.
(2) Execute functions with commands
select do_system('id')
Show that there is no , Failure
(3) Try reading system files
select load_file('/etc/passwd')
Know a message , Can pass shell Only root and lucy
2. Database information disclosure
Now that they have logged in , Of course, it depends on the database information , stay data Under database , We can see a fernet(python encryption algorithm ), There is a string of encrypted information in it .
6、 ... and 、python Of fernet Decrypt
1.python The official manual
2.key and value analysis
We're on this key and value The format of , Combined with the values obtained in the database , To decrypt .
3. Decrypt
Successfully solved lucy Password
7、 ... and 、 Sign in lucy
8、 ... and 、 information gathering
1.sudo To configure
2.exp.py
It is used to execute commands py file
Nine 、 Raise the right
import pty;pty.spawn('/bin/bash')
边栏推荐
- Vulnhub geminiinc
- R语言使用aggregate函数计算dataframe数据分组聚合的均值(sum)、不设置na.rm计算的结果、如果分组中包含缺失值NA则计算结果也为NA
- 优化接口性能
- Qt OpenGL 旋转、平移、缩放
- OpenGL 着色器使用
- Phpcms prompt message page Jump to showmessage
- 鸿蒙第四次培训
- C language utf8toutf16 (UTF-8 characters are converted to hexadecimal encoding)
- "Jianzhi offer 04" two-dimensional array search
- R语言使用gridExtra包的grid.arrange函数将ggplot2包的多个可视化图像横向组合起来,ncol参数自定义组合图列数、nrow参数自定义组合图行数
猜你喜欢
Groovy test class and JUnit test
【学习笔记】dp 状态与转移
Xiaopeng P7 hit the guardrail and the airbag did not pop up. The official responded that the impact strength did not meet the ejection requirements
STL Tutorial 9 deep copy and shallow copy of container elements
Viewing binary bin files with notepad++ editor
uniapp scroll view 解决高度自适应、弹框滚动穿透等问题。
Machine learning 3.2 decision tree model learning notes (to be supplemented)
Numpy np. Max and np Maximum implements the relu function
错排问题 (抽奖,发邮件)
Vulnhub geminiinc
随机推荐
vulnhub之raven2
Duplicate numbers in the array of sword finger offer 03
STL教程9-容器元素深拷贝和浅拷贝问题
Groovy test class and JUnit test
R语言使用gridExtra包的grid.arrange函数将ggplot2包的多个可视化图像横向组合起来,ncol参数自定义组合图列数、nrow参数自定义组合图行数
STL tutorial 10 container commonalities and usage scenarios
Nestjs configuration service, configuring cookies and sessions
《剑指offer 04》二维数组查找
R language uses grid of gridextra package The array function combines multiple visual images of the ggplot2 package horizontally, and the ncol parameter defines the number of columns of the combined g
R语言使用原生包(基础导入包、graphics)中的hist函数可视化直方图(histogram plot)
Groovy测试类 和 Junit测试
Capturing and sorting out external Fiddler -- Conversation bar and filter [2]
OpenGL 索引缓存对象EBO和线宽模式
vulnhub之cereal
The tutor put forward 20 pieces of advice to help graduate students successfully complete their studies: first, don't plan to take a vacation
repo ~ 常用命令
PHP server interacts with redis with a large number of close_ Wait analysis
Go language to realize static server
previous permutation lintcode51
Use typora to draw flow chart, sequence diagram, sequence diagram, Gantt chart, etc. for detailed explanation