当前位置:网站首页>vulfocus入门靶机
vulfocus入门靶机
2022-06-30 07:52:00 【sec0nd_】
命令执行漏洞
漏洞描述:
命令执行(Command Execution)漏洞即黑客可以直接在Web应用中执行系统命令,从而获取敏感信息或者拿下shell权限
命令执行漏洞可能造成的原因是Web服务器对用户输入命令安全检测不足,导致恶意代码被执行
打开漏洞地址,直接把命令执行的参数写出来了
访问该地址,返回flag

目录遍历漏洞
漏洞描述:
目录浏览漏洞属于目录遍历漏洞的一种,目录浏览漏洞是由于网站存在配置缺陷,存在目录可浏览漏洞,这会导致网站很多隐私文件与目录泄露,比如数据库备份文件、配置文件等,攻击者利用该信息可以更容易得到网站权限,导致网站被黑。
风险:攻击者通过访问网站某一目录时,该目录没有默认首页文件或没有正确设置默认首页文件,将会把整个目录结构列出来,将网站结构完全暴露给攻击者;
攻击者可能通过浏览目录结构,访问到某些隐秘文件(如PHPINFO文件、服务器探针文件、网站管理员后台访问地址、数据库连接文件等)。
打开漏洞地址,是类似ftp站点的页面
来到tmp目录下,有个flag(本来以为这可能是个假的flag,提交试了下成功了,有点侮辱智商)
边栏推荐
- November 22, 2021 [reading notes] - bioinformatics and functional genomics (Section 5 of Chapter 5 uses a comparison tool similar to blast to quickly search genomic DNA)
- Network security and data in 2021: collection of new compliance review articles (215 pages)
- 深度学习——Bounding Box预测
- 【笔记】Polygon mesh processing 学习笔记(10)
- Efga design open source framework fabulous series (I) establishment of development environment
- Bingbing learning notes: quick sorting
- C language operators
- Personal blog one article multi post tutorial - basic usage of openwriter management tool
- Deep learning -- Realization of convolution by sliding window
- November 9, 2020 [wgs/gwas] - whole genome analysis (association analysis) process (Part 2)
猜你喜欢

多快好省,低门槛AI部署工具FastDeploy测试版来了!

Permutation and combination of probability

CRM能为企业带来哪些管理提升

鲸探NFT数字臧品系统开发技术分享

Deep learning - residual networks resnets

期末复习-PHP学习笔记1

Use of nested loops and output instances

【花雕体验】13 搭建ESP32C3之PlatformIO IDE开发环境

Commands and permissions for directories and files

Self study notes -- use of 74h573
随机推荐
Final review -php learning notes 2-php language foundation
2021 private equity fund market report (62 pages)
深度学习——LSTM
Calculate Euler angle according to rotation matrix R yaw, pitch, roll source code
Disk space, logical volume
Why don't you know what to do after graduation from university?
回文子串、回文子序列
December 4, 2021 [metagenome] - sorting out the progress of metagenome process construction
December 19, 2021 [reading notes] - bioinformatics and functional genomics (Chapter 5 advanced database search)
Global digital industry strategy and policy observation in 2021 (China Academy of ICT)
Final review -php learning notes 4-php custom functions
深度学习——卷积的滑动窗口实现
全栈最全性能测试理论-总结
深度学习——目标定位
深度学习——GRU单元
Cadence physical library lef file syntax learning [continuous update]
Deep learning - LSTM
Armv8 (coretex-a53) debugging based on openocd and ft2232h
Combinatorial mathematics Chapter 2 Notes
Recurrence relation (difference equation) -- Hanoi problem