發表文章

目前顯示的是有「Algernon」標籤的文章

Proving Grounds Practice : Algernon Walkthrough

圖片
Proving Grounds Practice : Algernon Walkthrough  Foothole (立足點 ) : 掃完搜尋套件關鍵字 smartermail 發現 RCE Exploit 修改 python code 內容 IP 後直接利用連線成功 PE ( 提權 ) : 無須 PE,進入就是管理者了 注意事項 : 學到 SmarterMail 套件漏洞利用 SmarterMail 9998 Port Exploit-DB 49216 RCE Kali IP : 192.168.45.166 靶機 IP : 192.168.175.65 第一步掃描 Port 資訊, └─$ rustscan -a 192.168.175.65 --scripts none --ulimit 5000 | tee rustscan snmp 掃描,└─$ sudo nmap -sU -p 162 192.168.175.65 | tee snmp,關閉沒戲 nmap,└─$ sudo nmap -sCV -A -Pn -p 21,80,135,139,445,5040,9998,17001,49664,49666,49665,49667,49668,49669 192.168.175.65 | tee nmap            21 FTP 可以匿名登入 80 IIS 網站 445 網路芳鄰 9998 IIS 網站 看來是一台 Windows XP 工作站 21 FTP 匿名登入列舉,有四個目錄 /Logs 底下有一堆 xampp、smtpLog、delivery、profileer、popLog、imapLog 名稱開頭的 Log 看來是 xampp 網站與郵件系統的 Log 集中處 抓了幾個回來看,發現 ClamAV database xampp Log 顯示 5222 Port 服務起不來,但 IP 看來不是 靶機 的 IP 其他 Log 來沒有甚麼有用的資訊 enum4linux --> nothing whatweb 80 80 / 是 IIS Default Page 80 /robots.txt --> nothing gobuster 甚麼都沒有發現,└─$ go...