当前位置:网站首页>Record a phpcms9.6.3 vulnerability to use the getshell to the intranet domain control
Record a phpcms9.6.3 vulnerability to use the getshell to the intranet domain control
2022-06-26 12:58:00 【"Iron body cell"】
information gathering
The first use of nmap Scan the network segment and collect it to the host ip Address :
nmap -sP 192.168.31.0/24

Scan host information :


The discovery could be win7 Operating system and open 80 port
getshell
Because of openness 80 port , Go directly to the website :
obtain :

Scan directory and find administrator login :

obtain :

Weak password :admin admin12345
phpcms9.6.3 backstage getshell A loophole in the , There are many online references to this blog :
https://blog.csdn.net/weixin_42433470/article/details/112409431
What I'm using here is :
user -> Administrator module -> Add member model

obtain shell:

Access permissions
Connect with an ant sword shell

And then use it cs go online :
The modules used are :
First create a listener :

The attack module used is :
attack–>web DRIVE-BY -->scripted web delivery

Generate :

Copy to ant sword to run :

cs It's online here :

CS Sniffing
shell systeminfo

obtain :



Collect to : Domain is god.org
There is an address :192.168.52.143
Raise the right


obtain system jurisdiction :
cs obtain hash
Access–>Run Minikatz


CS View the domain environment :
net view

CS Get the list of hosts in the domain :

CS Get host in domain win2008


Start to get :

Carry out orders :

CS Get host in domain WindowsServer2003

Start to get :

Execute the command to get :
shell ipconfig see ip Address

边栏推荐
- Vivado 错误代码 [DRC PDCN-2721] 解决
- Laravel+gatewayworker completes the im instant messaging and file transfer functions (Chapter 4: server debugging errors)
- power designer - 自定义注释按钮
- The laravel dingo API returns a custom error message
- Redis learning - 06 drifting bottle case
- PHP get directory size
- 环形队列php
- Software testing - Fundamentals
- processsing 函数random
- NoSQL mongodb - 01 introduction to NoSQL and mongodb
猜你喜欢

第十章 设置结构化日志记录(二)

Deeply analyze the differences between dangbei box B3, Tencent Aurora 5S and Xiaomi box 4S

openlayers 绘制动态迁徙线、曲线

.NET MAUI 性能提升

手把手带你学会Odoo OWL组件开发(7):OWL项目实战使用

Websocket and socket IO case practice

【网络是怎么连接的】第二章(上): 建立连接,传输数据,断开连接

Php+laravel5.7 use Alibaba oss+ Alibaba media to process and upload image / video files

Configuring Apache digest authentication

Fengshentai old shooting range Kali series
随机推荐
深度解析当贝盒子B3、腾讯极光5S、小米盒子4S之间的区别
Echart堆叠柱状图:色块之间添加白色间距效果设置
Configuring Apache digest authentication
机组实践实验8——使用CMStudio设计基于基本模型机微程序指令(1)
[esp32-C3][RT-THREAD] 基于ESP32C3运行RT-THREAD bsp最小系统
Solution of Splunk iowait alarm
Mysql8 master-slave replication
JS get the current screen height method and listen for DOM elements to enter the viewport
别乱用 FULL_CASE 和 PARALLEL_CASE
7-2 大盗阿福
processing 函数translate(mouseX, mouseY)学习
不到40行代码手撸一个BlocProvider
KVM video card transparent transmission -- the road of building a dream
Photoshop 2022 23.4.1增加了哪些功能?有知道的吗
Sharing ideas for a quick switch to an underlying implementation
PHP laravel+gatewayworker completes im instant messaging and file transfer (Chapter 1: basic configuration)
Nodejs framework express and KOA
计组实践实验9——使用CMStudio设计基于分段模型机微程序指令(2)
自动化测试的局限性你知道吗?
imagecopymerge