当前位置:网站首页>Vulnhub funbox: rookie (funbox2) target penetration
Vulnhub funbox: rookie (funbox2) target penetration
2022-07-24 05:38:00 【Outstanding, outstanding】
Vulnhub-Funbox: Rookie(funbox2) Target penetration
Vulnhub-Funbox: Rookie(funbox2) Penetration test
One . About the target
Running on the Vmware The target cannot be obtained in IP, Try bridging 、NAT、 Only the three modes of the host are fruitless , No choice but to use it VirtualBox, but NAT And bridge mode IP, Only in host-only The target machine can only be obtained in mode IP.
Two . IP And port detection

Found only open 21,22,80 port 
3、 ... and . 21 Port information collection

View above 2 Script , Found to be CVE-2015-3306 Any file copy 

It cannot be directly used after trying , Try another port **
Four . 80 Port information collection

Scan the directory , Find out robots.txt, However, it cannot be used 


There seems to be a deadlock , Can we go back to 21 Port to try ?
5、 ... and . FTP Anonymous logins
It suddenly occurred to me whether I forgot to try anonymous login just now …
user name :anonymous, The password is empty 
Check the directory , I found a bunch of compressed packages with file names very similar to user names , Download to the local decompression try 
It is found that the content of the file is id_rsa, But you need a password to decompress , Start using john Crack , Crack to tom.zip The password for iubire
notes : If you ask me why I don't use fcrackzip Crack , Because currently in host-only Pattern , and fcrackzip Not kali Bring their own , It needs to be installed by hand 
decompression tom.zip obtain id_rsa, Is a private key 
6、 ... and . ssh Key login
Log in with the key obtained above 
Discovery is a limited rbash,ls -la Check the directory 
View history command , It is found that data is written to the database , Much like user name and password (tom/xx11yy22!)
sudo Have a try , Password input xx11yy22!
found sudo Improper configuration , You can execute commands with all user permissions , Try switching root, You don't need a password ~
meaning , Unexpectedly, it's so right …
** summary :**ftp Anonymous logins —— File download —— Password cracking ——ssh Sign in ——sudo Improper allocation of rights
边栏推荐
猜你喜欢

Hurry in!! Take you to understand what is multi file, and easily master the usage of extern and static C language keywords!!!

mysqldump 导出中文乱码

在本地怎么使用phpstudy搭建WordPress网站

动画 效果

Inventory Poka ecological potential project | cross chain characteristics to promote the prosperity of multi track

渗透测试知识---行业术语

MySQL的分页你还在使劲的limit?

响应式页面

canvas - 圆形

【百度地图API】您所使用的地图JS API版本过低,已不再维护,为保证地图基本功能 正常使用,请尽快升级到最新版地图JS API
随机推荐
Why is music NFT popular? Polkadot may become the best choice for developing music NFT
按钮 渐变
JS:为什么 [] == ![] 返回 true ?
The profound meaning of unlimited ecological development in Poka -- Multidimensional Interpretation of parallel chain
php的多选、单选结果怎么在前台显示?
3. Draw a five sided cone with a square bottom on the screen. The bottom of the cone is on the xoz plane and the top of the cone is on the Y axis. Use the following figure to map the texture of the fo
Geoserver自动化上传Shapefile
Substrate technology and ecology June memorabilia | Polkadot decoded came to a successful conclusion, and the hacker song winning project injected new forces into the ecosystem
PyCharm设置代码模板
Function Closure
盘点波卡生态潜力项目 | 跨链特性促进多赛道繁荣
波卡创始人 Gavin Wood:波卡治理 v2 会有哪些变化?
Tabs tab (EL tabs)_ Cause the page to jam
Interpretation of the randomness of POS mechanism, how does poca's randomness principle work?
面向 对象
仿某网站百度地图页面 百度API
special effects - 鼠标移动,出现星星拖尾
Substrate 技术及生态5月大事记 | Square One 计划启动,波卡上线 XCM!
vulnhub-SolidState: 1靶机渗透测试
Three -- orbitcontrols track controller