發表文章

目前顯示的是有「Kernel Exploit」標籤的文章

Proving Grounds Play : DriftingBlues6 Walkthrough

圖片
 Proving Grounds Play : DriftingBlues6 Walkthrough Foothold : 網站 robots.txt 告訴你要去找 *.zip 檔 使用很大的字典檔後發現一組憑證 使用該組憑證成功登入 CMS textpattern 成功登入後上傳 webshell.php 檔案利用後拿到 Reverse Shell PE : kernel 太舊,利用 Exploit 建立一個 root 使用者 su 切換使用者成功 root 備註 : 標準的漏洞 dirtycow (髒牛) Rustscan,└─$ rustscan -a 192.168.151.219 --scripts none --ulimit 5000 | tee rustscan snmp check nmap whatweb 80 / 叫你不要駭它 80 /robots.txt 很親切的告訴你要加上 .zip 副檔名 80 /textpattern/textpattern textpattern CMS searchsploit 看一下發現 RCE 都要 Authenticated 所以有可能在某個 *.zip 檔案中可以發現 先嘗試測試一些常用帳號密碼發現都失敗 gobuster / gobuster /textpattern 80 /textpattern/files 80 /textpattern/images 80 /textpattern/rpc 80 /textpattern/themes gobuster /textpattern/textpattern 又發現一堆路徑 後續持續枚舉依舊沒有發現任何 *.zip 檔案,與相關可以利用的地方 換了一個字典檔從頭再開始爬一次,直接在根目錄發現了 zip 檔案 spammer.zip 將檔案抓回來解開看看發現要密碼,直接用 john 破解得到解壓縮密碼 myspace4 解開後發現一個 creds.txt 檔案內容寫了一個憑證 mayer:lionheart 透過拿到的憑證登入 textpattern 確認可以登入 發現可以上傳檔案的地方 上傳最愛的 webshell.php 但跳出告警,告警寫不要修改系統時間 也不知道有沒有上傳成功 點了 OK 後發現上傳成功 在 admin --> ...