当前位置:网站首页>BSides-Vancouver-2018-Workshop靶机渗透测试
BSides-Vancouver-2018-Workshop靶机渗透测试
2022-04-22 01:10:00 【小王先森&】
环境
kali攻击机192。168.1.105
靶机192.168.1.100
工具
brupsuite nmap
dirb
python
nc
流程
netdiscover对目标网段进行扫描做到主机发现发现目标ip192.168.1.100

nmap对该主机镜像端口扫描

访问80端口啥也没有
dirb爆目录
在robot.txt目录下发现东西

访问http://192.168.1.100/backup_wordpress/得到一博客创建界面

发现有个管理员用户john发表了一篇文章就用john作为用户名爆破后台
用brupsuite截断爆破


爆出密码
enigma

登录成功
然后把kali自带的脚本放在404页面
注意修改ip和端口
本地开启监听‘

然后访问一个不存在的页面使服务器执行脚本反弹shell(由于是john所以一定先进john的界面然后再访问一个不存在的页面http://192.168.1.100/backup_wordpress/?author=222 否则不会反弹成功)成功反弹



优化终端python -c ' import pty; pty.spawn("/bin/bash")'
cat /etc/crontab查看日志发现/usr/local/bin/cleanup这个文件有root权限

那么就可以在里面放脚本反弹shell
通过脚本把本地当前目录开放在8000然后靶机wget下载本地的shell脚本
**
**
把执行py脚本的命令写入到cleanup文件然后开启本地监听

等待一会计划执行后成功拿到shell权限为root

版权声明
本文为[小王先森&]所创,转载请带上原文链接,感谢
https://blog.csdn.net/weixin_49340699/article/details/118196344
边栏推荐
- kubernetes+prometheus+grafana
- 安装包签名检测
- R language generalized linear model function GLM and GLM function are used to construct logistic regression model, and chi square test is used to verify whether the two logistic regression models are
- Cloud security daily 220421: Cisco virtualization infrastructure manager software found a privilege upgrade vulnerability and needs to be upgraded as soon as possible
- Wonderful review | deepnova x iceberg meetup online "building a real-time data Lake based on iceberg"
- Detailed explanation of network model LSTM model content
- Simple understanding of variable structure assignment
- 腾讯安卓开发面试经验,HR的话扎心了
- The middle order traversal of binary tree
- Boutique: thousand word long text hand-in-hand teaches you to use the byte beating volcanic engine veimagex
猜你喜欢

Pytorch安装及GroupSpatialSoftmax报错解决
![[audio and video] RTCP](/img/47/7d8c227d685d87b68763b3665256e5.png)
[audio and video] RTCP

Finally, wechat scanning code login is completed. It's really fragrant..

Why is the video exported by PR purple?

华为云云主机体验有感:你的软件收纳专家

EventBridge 集成云服务实践

Spring recruit high frequency interview question: how to design the second kill system?

Probe architecture of open source project kindling based on ebpf Technology

如果在安装 32 位 Oracle 客户端组件的情况下以 64 位模式运行,将出现此问题

PR如何对裁剪之后的视频进行resize,指定到期望大小?
随机推荐
Pytorch安装及GroupSpatialSoftmax报错解决
2022年年金险有哪些好的产品呢?
JS find array subscript
How can zhiting connect Huawei smart speakers?
【PraNet】主要架构解读-------wmilk
kubernetes+prometheus+grafana
【PraNet】论文代码解读(损失函数部分)——Blank
Wonderful review | deepnova x iceberg meetup online "building a real-time data Lake based on iceberg"
3D 沙盒游戏之人物的点击行走移动
R language uses lmperm package to apply to the replacement method of linear model (replacement test, permutation tests), one-way covariance analysis (one-way ANCOVA) on the same data set, and one-way
投资对情绪的把控
js查找数组下标
Solve the problem that the idea web project does not have small blue dots
[high concurrency] Why is there a strange bug problem when writing long variables on a 32-bit multi-core CPU? After reading this article, I understand!
【音视频】RTCP
Huawei cloud hosting experience: your software storage expert
Error message of "this file does not be long to any project, code insight features might not work properly" in clion
2022年Redis最新面试题第1篇 - Redis基础知识
Boutique: thousand word long text teaches you to use byte beating volcanic engine imagex
2022年4月21日,第14天