当前位置:网站首页>Vulnhub range - the planes:venus
Vulnhub range - the planes:venus
2022-06-25 19:12:00 【Czheisenberg】
THE PLANETS: VENUS
Get ready
attack : kali
Drone aircraft : THE PLANETS: VENUS NAT 192.168.91.0 Network segment
Download link :
https://www.vulnhub.com/entry/the-planets-venus,705/

Information collection and utilization
The host found
python3 ping.py -H 192.168.91.0/24
Get the target as shown in the figure IP Address :192.168.91.173
Port scanning
nmap -sV -p- -sS -A 192.168.91.173 -oN venus_nmap.txt

As shown above, only 22,8080 port , among 8080 Like the previous two, it is made up of python Composed of web page .
HTTP
http://192.168.91.173:8080/
As shown in the figure above , Show Use guest:guest To log in to the guest account , After testing ( guess ) I found that when the user name and password are entered as : venus:venus You can also log in when .

Directory scanning
python3 dirsearch.py -u http://192.168.91.173:8080/
Sweep out a lot 302 Redirect , It's not shown here .
Generally speaking python Page written by , Either Flask frame , Or Django frame , These two frameworks are common , Generally speaking, there are admin Background page , Only when you log in can you go further .
http://192.168.91.173:8080/admin/login/?next=/admin/

As shown in the figure , yes Django . That's right . Try to open it DEBUG Pattern , If the error message is displayed and all routes are displayed, it is proved that it is enabled , If only Not Found It proves that it is closed DEBUG Pattern . After testing, it is found that it is closed .
Try to log in to the background with a weak password , Failure !
Return to the first landing page again , Now we know that there are two user names and passwords :
guest:guest
venus:venus( Guess from the name of the target )
Is there any other user name ? So now we need to blast .

Enter the correct user name at the login, and the wrong password will be displayed : invalid password.
When you enter any user name, it will display : invalid username.
So by returning information : invalid username To blast the user name .
But there is another problem , How to ensure that the correct user name is in our dictionary ??? The two known user names are useless , Can not ssh land .
I saw wp : https://medium.com/@mcl0x90/the-planets-venus-vulnhub-write-up-f6727d08bafb
Got a username and password :
magellan:venusiangeology1989 ( It was blasted by foreign leaders .)
flag 1

Raise the right
Method 1 :
SUID Raise the right
find / -perm -u=s -type f 2>/dev/null

As shown in the figure, it is found that polkit-1/polkit-agent-helper-1 With the previous target : MECURY( mercury ) As like as two peas . We try the same method to exp Download to the target , Note that there is no git command . We use it wget download


then unzip cve-2021-4034 Decompression can be .
then make

Generated Executable file cve-2021-4034
function :
./cve-2021-4034

As shown in the figure, we get root jurisdiction .
flag 2

This method is similar to that of the previous target aircraft in this series The method of raising rights is the same . It should be said that the focus of this target plane is not this .
Method 2 :
Refer to those of foreign leaders wp, Personally, I find it difficult . Gave up .
summary
- It can be used as the previous mercury target cev-2021-4034 Right to come ( Simple , It suits my kind of chicken !)
- Blasting passwords require a powerful Dictionary , Here I looked directly at wp The answer .
边栏推荐
- Network security detection and prevention test questions (I)
- Google cloud SSH enable root password login
- Detailed explanation of oauth2 - Introduction (I)
- Network security detection and prevention test questions (4)
- Analysis of China's road freight volume, market scale and competition pattern in 2020 [figure]
- Idea common plug-ins
- Sorting out the latest data mining competition scheme!
- 广州华锐互动VR全景为各行各业带来发展
- QQ机器人闪照转发/撤回消息转发【最新beta2版本】
- 解决sublime Text3 package control 无法安装插件问题
猜你喜欢

Svn introduction and Usage Summary

为什么生命科学企业都在陆续上云?

Apifox simple understanding -- the integrator of web side testing

Divine reversion EA
![2021 development status of China's cloud game industry and analysis of major service providers: Although cloud games are still in their infancy, the market prospect is huge [figure]](/img/82/84072a7b125f81363fb26ac56e9d27.jpg)
2021 development status of China's cloud game industry and analysis of major service providers: Although cloud games are still in their infancy, the market prospect is huge [figure]

Combing the latest Data Mining Event Scheme!
![Overview and trend analysis of China's CT examination equipment industry in 2021 [figure]](/img/e0/d4ed9a9d91534be0d956414f6abaaa.jpg)
Overview and trend analysis of China's CT examination equipment industry in 2021 [figure]

Does GoogleSEO need to change the friend chain? (e6zzseo)

wooyun-2014-065513

Embark on a new journey and reach the world with wisdom
随机推荐
SQL is used for field data types in various databases
On location and scale in CNN
JS some small problems about adding and accessing values to arrays
QQ机器人闪照转发/撤回消息转发【最新beta2版本】
IDEA常用插件
TCP/IP 测试题(三)
R语言plotly可视化:plotly可视化二维直方图等高线图(Basic 2D Histogram Contour)
Shell jump loop shift parameter left use of function
[elt.zip] openharmony paper Club - memory compression for data intensive applications
云上弹性高性能计算,支持生命科学产业高速发展、降本增效
Current situation and trend analysis of China's glass packaging containers in 2021: the revenue of glass packaging containers increases year by year [figure]
一、HikariCP获取连接流程源码分析一
Sorting out the latest data mining competition scheme!
Redis cache preheating & avalanche & breakdown & penetration
QQ机器人:群成员自我禁言管理【最新beta2版本】
Analysis of China's road freight volume, market scale and competition pattern in 2020 [figure]
TCP/IP 测试题(四)
【历史上的今天】6 月 25 日:笔记本之父诞生;Windows 98 发布;通用产品代码首次商用
Google cloud SSH enable root password login
English name of each stage of software version