当前位置:网站首页>Vulnhub-dc9 learning notes
Vulnhub-dc9 learning notes
2022-07-18 15:13:00 【Zhaohg720】
Vulnhub-DC9 Learning notes
1.Fping + Nmap Probe host port

2. test 80 port http service
Find out search.php Page will use post Method to find the data content , Try to use sqlmap post Methods to inject 


Injection obtained admin The encrypted password of the user
Let's find one md5 Declassified web Get the plaintext password 
After logging in, there is a post Upload information page , I haven't found a way to use it for the time being , But the footer indicates that the file does not exist 

After all kinds of attempts , It is found that the file contains parameters file, You can read some files of the system , Found some user names that can log in to the system
We have another one when we inject user library , There are user names and passwords 

22 Port utilization
We got something that can ssh Login username and password , however ssh You will be prompted that the port refuses access .
Here we use it again nmap Scan and find that the port status is filtered No open
After reading the introduction of other big guys, here is a name Knockd Of ssh protective .
Knockd The configuration file is located in /etc/knockd.conf
So we got knock Needed 3 Port number .
We use it according to the instruction manual Nmap Knock at the door 
After knocking on the door, we found 22 The status of the port changes to open
Then we can use ssh Sign in , Let's sort out the user name and password into a dictionary , And then use hydra To try which users can log in 
We are janitor A hidden folder with some passwords was found in the user's home directory , We update the password dictionary and reuse hydra Blast 
We found again fredf User's password , We see this on the website fredf It's the system administrator , So we are not far from success 
We found that fredf The user has a root Orders of authority 
We run test, Prompt reading test.py, Search for test.py The path of , And then look at the content , Judge test.py yes test Source code , You can take two parameters later , The parameters are two files , The script will splice the first file to the end of the second .
So we can follow /etc/passwd File format , Create a root Privileged user
Where the password is openssl passwd -1 Generate encrypted ciphertext 

边栏推荐
- 2022 a special equipment related management (elevator) operation certificate examination questions and online simulation examination
- Implementation of thread pool
- C#使用Marshal.SizeOf计算结构体大小返回错误
- 03 gulimall development environment configuration
- 【通信】【1】幅度调制,频率调制,双边带与单边带,IQ与PSK与QAM——采样一定要满足奈奎斯特定理吗
- RMAN detailed tutorial (II) -- backup, inspection, maintenance, recovery
- STM32 application development practice tutorial: multi computer communication application development based on RS-485 bus
- 2022 R2 mobile pressure vessel filling test questions and answers
- Tensorflow2.0 advanced learning RNN generated audio (12)
- MIPI CSI、DSI、UFS、C-PHY、D-PHY、M-PHY概念理解
猜你喜欢

Select statement if else

Vulnhub-DC7学习笔记

架构基础篇

ZYNQ PL中断脉冲多久可以被CPU捕获到

Writing is more natural and comparable to the original factory experience. Nanka pencil capacitive pen is handy

【成像】【8】太赫兹光学——波束耦合,高阶高斯波束模型

VS2019 16.8 “消失“的团队资源管理器

Go 原生插件使用问题全解析
![[daily training] 515 Find the maximum value in each tree row](/img/84/51ceab335f933846934ed2523f31f3.png)
[daily training] 515 Find the maximum value in each tree row

86触摸开关/台扇/空调/智能家居/家电等,低功耗高抗干扰3键3路3通触摸IC-VK3603 ESOP8,性能稳定,灵敏度可调
随机推荐
Redis is configured to save RDB snapshots, but it is currently not able to persist
Xiaomi mobile safely uninstalls built-in applications
Information retrieval summit sigir2022 best paper award came out, Melbourne Institute of technology best paper, UMass University and other best short papers
[untitled]
Symbolic naming analysis in reinforcement learning
2022 a special equipment related management (elevator) operation certificate examination questions and online simulation examination
How much does it cost for lazada, express and shopee to evaluate self-supporting numbers?
The difference between arrayslist and LinkedList
Sudo cannot find the command command not found solution
【成像】【8】太赫兹光学——波束耦合,高阶高斯波束模型
The first jd.com technology partnership conference was held, and Boyun joined hands with jd.com technology to create new digital growth in the industry
德银天下港交所上市:市值39亿港元 陕汽集团是大股东
Uninstall cuda11.1
GooglePhoto设置壁纸----壁纸裁剪界面配置
Vulnhub-dc5学习笔记
Advanced pointer (V) -- callback function
Gee (6): set the number of decimal places reserved for the calculated value / image
[applet] attribute description and example of input box (text + code)
指针进阶(五)——回调函数
Exception: Unexpected end of ZLIB input stream