当前位置:网站首页>Vulnhub tre1
Vulnhub tre1
2022-07-07 20:07:00 【Plum_ Flowers_ seven】
Catalog
3、 ... and 、 Service version discovery
5、 ... and 、 Break through the border
1. Try to make use of mantis Of RCE Loophole
2. Advanced directory explosion , A lot of information collection
3.Pre-Auth Remote Password Reset
6、 ... and 、shell Script authorization
3. Write bounce shell sentence
Be careful : Use as much as possible vmvare To deploy the target aircraft , And network mode selection NAT Pattern .
One 、 The host found
Two 、 Port scanning
3、 ... and 、 Service version discovery
22 ssh
80 8082 All of them are open http The service is different web Server software .
Four 、 information gathering
1.80 and 8082
It's all open http service , And deployed the same site , Same page . There is no information available in the source code .,
2. Catalog explosion
(1)adminer.php
(2)info.php
I know some configuration file path addresses , Website environment, etc .
(3)system
Return code 401, Login is required to access the site , We tried weak password admin/admin Successful entry
(4) Return packet
This one in the response packet is used to verify identity .
Authorization:Basic YWRtaW46YWRtaW4=
5、 ... and 、 Break through the border
1. Try to make use of mantis Of RCE Loophole
cp Come to the local , change exp Of rhost ,lhost,mantisloc , Add validation header , And then execute
nc -nvlp 4444
2. Advanced directory explosion , A lot of information collection
That is to add the verification head and then blast
dirsearch -u url --header="Authorization:Basic YWRtaW46YWRtaW4="
There are many new paths .
(1)config
We got the account and password of the data , name . Before integration adminer.php Interface , Try signing in
(2) Collect information after login
Here we can find the original account and the account we registered , In the previous registration , We didn't enter the password , So it is inferred that the blank column is the password . To try ssh Sign in
(3)ssh Sign in
3.Pre-Auth Remote Password Reset
It is a vulnerability of pre authorized remote password modification
Here is also an introduction to usage , This is the remote password change to hash Verified , But we changed it to empty , Go straight around
Log in to the administrator user state , We can also see the account password , And then through ssh Sign in .
6、 ... and 、shell Script authorization
1.shell grammar
find / -user root -type f -perm -o=rw -ls 2>/dev/null | grep -v "/proc"
check-system It's not the system's own command , Sure , To view the .
2 .check-system
The program started at startup is systemd
, Systems and services Manager control . systemd
Is the first process to run at startup . It always has process ID (PID)1. All other processes running on the computer are controlled by systemd
Starting up , Or by systemd
The process that has been started starts . Combine the above sudo jurisdiction , Guess it may be related to the startup of the boot
3. Write bounce shell sentence
4. Restart triggers
边栏推荐
- R language ggplot2 visualization: use the ggdensity function of ggpubr package to visualize the packet density graph, and use stat_ overlay_ normal_ The density function superimposes the positive dist
- Open source heavy ware! Chapter 9 the open source project of ylarn causal learning of Yunji datacanvas company will be released soon!
- 如何在软件研发阶段落地安全实践
- BI的边界:BI不适合做什么?主数据、MarTech?该如何扩展?
- PMP practice once a day | don't get lost in the exam -7.7
- R language ggplot2 visualization: use the ggqqplot function of ggpubr package to visualize the QQ graph (Quantitative quantitative plot)
- pom. Brief introduction of XML configuration file label function
- PMP對工作有益嗎?怎麼選擇靠譜平臺讓備考更省心省力!!!
- 9 atomic operation class 18 Rohan enhancement
- Ways to improve the utilization of openeuler resources 01: Introduction
猜你喜欢
随机推荐
LeetCode_7_5
力扣 1232.缀点成线
R language ggplot2 visualization: use the ggstripchart function of ggpubr package to visualize the dot strip plot, set the position parameter, and configure the separation degree of different grouped
el-upload上传组件的动态添加;el-upload动态上传文件;el-upload区分文件是哪个组件上传的。
力扣 643. 子数组最大平均数 I
Automatic classification of defective photovoltaic module cells in electroluminescence images-论文阅读笔记
MIT科技评论文章:围绕Gato等模型的AGI炒作可能使人们忽视真正重要的问题
SQL common optimization
pom. Brief introduction of XML configuration file label function
[RT thread env tool installation]
LC: string conversion integer (ATOI) + appearance sequence + longest common prefix
R语言dplyr包mutate_at函数和min_rank函数计算dataframe中指定数据列的排序序号值、名次值、将最大值的rank值赋值为1
LeetCode_ 7_ five
关于自身的一些安排
ASP. Net learning & ASP's one word
Ucloud is a basic cloud computing service provider
ASP. Net gymnasium integrated member management system source code, free sharing
UCloud是基础云计算服务提供商
时间工具类
最多可以参加的会议数目[贪心 + 优先队列]