当前位置:网站首页>Vulnhub funbox: rookie (funbox2) target penetration
Vulnhub funbox: rookie (funbox2) target penetration
2022-07-24 05:38:00 【Outstanding, outstanding】
Vulnhub-Funbox: Rookie(funbox2) Target penetration
Vulnhub-Funbox: Rookie(funbox2) Penetration test
One . About the target
Running on the Vmware The target cannot be obtained in IP, Try bridging 、NAT、 Only the three modes of the host are fruitless , No choice but to use it VirtualBox, but NAT And bridge mode IP, Only in host-only The target machine can only be obtained in mode IP.
Two . IP And port detection

Found only open 21,22,80 port 
3、 ... and . 21 Port information collection

View above 2 Script , Found to be CVE-2015-3306 Any file copy 

It cannot be directly used after trying , Try another port **
Four . 80 Port information collection

Scan the directory , Find out robots.txt, However, it cannot be used 


There seems to be a deadlock , Can we go back to 21 Port to try ?
5、 ... and . FTP Anonymous logins
It suddenly occurred to me whether I forgot to try anonymous login just now …
user name :anonymous, The password is empty 
Check the directory , I found a bunch of compressed packages with file names very similar to user names , Download to the local decompression try 
It is found that the content of the file is id_rsa, But you need a password to decompress , Start using john Crack , Crack to tom.zip The password for iubire
notes : If you ask me why I don't use fcrackzip Crack , Because currently in host-only Pattern , and fcrackzip Not kali Bring their own , It needs to be installed by hand 
decompression tom.zip obtain id_rsa, Is a private key 
6、 ... and . ssh Key login
Log in with the key obtained above 
Discovery is a limited rbash,ls -la Check the directory 
View history command , It is found that data is written to the database , Much like user name and password (tom/xx11yy22!)
sudo Have a try , Password input xx11yy22!
found sudo Improper configuration , You can execute commands with all user permissions , Try switching root, You don't need a password ~
meaning , Unexpectedly, it's so right …
** summary :**ftp Anonymous logins —— File download —— Password cracking ——ssh Sign in ——sudo Improper allocation of rights
边栏推荐
猜你喜欢
随机推荐
网页播放rtsp视频流
微信小程序map的使用
6. Draw a Bezier curve and a Bezier surface on the screen
根据数组中对象的某个属性值进行排序
canvas - 填充
动画 效果
Moonbeam orbiters program: provides a new way for collectors to participate in moonbeam and Moonriver
umi之define属性
Canvas - rotate
盘点波卡生态潜力项目 | 跨链特性促进多赛道繁荣
助力传统游戏转型GameFi,Web3Games推动游戏发展新航向
登录 页面 + 总结心得
Canvas - round
C document reading and writing plus linked list addition, deletion, modification and query
Array_ 01return in foreach
项目免费部署到公网(内网穿透)
自定义MVC 2.0
网页内嵌B站视频,隐藏相关控件
盘点波卡生态潜力项目 | 跨链特性促进多赛道繁荣
Scarcity in Web3: how to become a winner in a decentralized world









