Proving Grounds Practice : Medjed Walkthrough
Proving Grounds Practice : Medjed Walkthrough Foothole (立足點 ) : 8000 是 BarracudaDrive 網站可以上傳檔案,上傳至 XAMPP htdocs 路徑下 在 45332、45443 發現是 XAMPP 網站,執行 webshell.php 建立 reverse shell 登入 PE ( 提權 ) : BarracudaDrive Exploit-DB 48789 標準利用,bd.exe 程式替換成 payload 重開機拿到管理者 shell 注意事項 : 標準梗 : A 網站上傳的東西在 B 網站利用 BarracudaDrive 的利用學習 第一步 Rustscan, └─$ rustscan -a 192.168.244.127 --scripts none --ulimit 5000 | tee rustscan snmp closed,└─$ sudo nmap -sU -p 161 192.168.244.127 | tee snmp nmap,└─$ sudo nmap -sCV -A -p 135,139,445,3306,5040,8000,30021,33033,44330,45332,45443,49664,49665,49667,49666,49669,49668 192.168.244.127 | tee nmap 8000 http | WebDAV type: Unknown 30021 FileZilla | ftp-anon: Anonymous FTP login allowed (FTP code 230) 33033 HTTP 45332 HTTP 45443 HTTP enum4linux,└─$ enum4linux -a 192.168.244.127 8000 / Web-File-Server BarracudaDrive 6.5 設定 admin:admin123 searchsploit BarracudaDrive 看了一下是登入系統後的利用,暫時用不到 cadaver 測試 8000 Port 也報錯 看網站的 Web-File-Server ...