当前位置:网站首页>Vulnhub's darkhole_ two
Vulnhub's darkhole_ two
2022-07-05 18:13:00 【Plum_ Flowers_ seven】
Catalog
3、 ... and 、 Service version discovery
3. Generate the latest version of source code
4. Check the version with loopholes
Nine 、losy information gathering
11、 ... and 、hydra Brute force
One 、 The host found
Two 、 Port scanning

3、 ... and 、 Service version discovery
What is worth noting here is .git, This is the source code also put up . The others are the same .

Four 、 information gathering
1. Home page
A picture on the homepage , There is nothing in the source code .

There's a login interface .

2. Scan directory
Most of the useful information points to .git, This is the same as the information we collected above

5、 ... and 、.git
Be careful : It is best to 2021 Version of kali,2022 the latest version git clone Will report a mistake , I don't know why
1. download .git
wget -r http://192.168.0.108/.git/
2. View version history

3. Generate the latest version of source code
git clone . backup
Login in the source code php in , We can see that the input parameters are escaped here , Prevent injection

4. Check the version with loopholes
Here, when converting branches , Sometimes you have to do it first
git stash
Transform branch
git checkout a4d900a8d85e8938d3601f3cef113ee293028e10

Enter the view , Got the account password used in the previous version . It is likely that the account password of the previous version can be used for login in this version

5. Sign in

6、 ... and 、sqlmap Inject
1' No echo results .
1'and+1=1--+ and 1 The output is the same .
Prove that there is sql Inject ,sqlmap Run
burp Grab the bag ,
(1) Run to the library
sqlmap -r ~/Desktop/1 --dbs
Four default libraries , One darkhole_2

(2) Running Watch

(3)dump Come down
ssh:

users:

7、 ... and 、ssh Sign in
1.
Got one jehad Of shell.

In information collection , We see .bash_history There are many tips in . Here is a hint , Make one Port forwarding , Then execute the command .

2.9999 Port service information
Content :

ps -aux | grep 9999
You can see that the program is based on losy Running , We use him to execute the rebound shell And then I got a losy Of shell

8、 ... and 、 Port forwarding
Why do I do this port forwarding , Because we are kali The target target cannot be accessed by the client 9999 Service script for port deployment .
there 127.0.0.1 As a target ( Remote target ) The address of .
Of course, in fact, we can directly use what we get jehad This user , Execute commands locally .
1.kali End
ssh -L 9633:127.0.0.1:9999 [email protected]
After the port forwarding, we can kali The end implements the command execution operation .

2. rebound shell
stay .bash_history In fact, it provides us with several rebounds shell The way , In fact, it is several ways that hackers try to invade , But it seems to be useless

Conduct url code :

Successfully rebound after submission .

Nine 、losy information gathering
upgrade shell, The password has been told to us

Ten 、sudo Raise the right

Use the one given above python Command line
sudo python3 -c 'import os; os.system("/bin/sh")'

11、 ... and 、hydra Brute force
lama Too much authority , The password is too simple .

Log in and use sudo Raise the right
边栏推荐
- LeetCode笔记:Weekly Contest 300
- Memory management chapter of Kobayashi coding
- JVM第三话 -- JVM性能调优实战和高频面试题记录
- Introduction to VC programming on "suggestions collection"
- 瀚升优品app翰林优商系统开发功能介绍
- mybash
- Clickhouse (03) how to install and deploy Clickhouse
- 如何获取飞机穿过雷达两端的坐标
- JVM third talk -- JVM performance tuning practice and high-frequency interview question record
- Can communication of nano
猜你喜欢

Let more young people from Hong Kong and Macao know about Nansha's characteristic cultural and creative products! "Nansha kylin" officially appeared

Sophon Base 3.1 推出MLOps功能,为企业AI能力运营插上翅膀

Star Ring Technology launched transwarp Navier, a data element circulation platform, to help enterprises achieve secure data circulation and collaboration under privacy protection

Nacos distributed transactions Seata * * install JDK on Linux, mysql5.7 start Nacos configure ideal call interface coordination (nanny level detail tutorial)

修复漏洞 - mysql 、es

记录Pytorch中的eval()和no_grad()

使用QT遍历Json文档及搜索子对象

nano的CAN通信

To solve the stubborn problem of Lake + warehouse hybrid architecture, xinghuan Technology launched an independent and controllable cloud native Lake warehouse integrated platform

Fix vulnerability - mysql, ES
随机推荐
buuctf-pwn write-ups (9)
让更多港澳青年了解南沙特色文创产品!“南沙麒麟”正式亮相
在一台服务器上部署多个EasyCVR出现报错“Press any to exit”,如何解决?
通过SOCKS代理渗透整个内网
《力扣刷题计划》复制带随机指针的链表
MATLAB中print函数使用
[performance test] full link voltage test
ConvMAE(2022-05)
Login and connect CDB and PDB
ISPRS2020/云检测:Transferring deep learning models for cloud detection between Landsat-8 and Proba-V
分享:中兴 远航 30 pro root 解锁BL magisk ZTE 7532N 8040N 9041N 刷机 刷面具原厂刷机包 root方法下载
【PaddleClas】常用命令
Introduction to the development function of Hanlin Youshang system of Hansheng Youpin app
破解湖+仓混合架构顽疾,星环科技推出自主可控云原生湖仓一体平台
Image classification, just look at me!
"Xiaodeng in operation and maintenance" is a single sign on solution for cloud applications
Sophon CE Community Edition is online, and free get is a lightweight, easy-to-use, efficient and intelligent data analysis tool
Career advancement Guide: recommended books for people in big factories
第十届全球云计算大会 | 华云数据荣获“2013-2022十周年特别贡献奖”
Numerical calculation method chapter8 Numerical solutions of ordinary differential equations