發表文章

目前顯示的是有「Monitorr」標籤的文章

Proving Grounds Play : ICMP Walkthrough

圖片
 Proving Grounds Play : ICMP Walkthrough Foothold : 80 發現 CMS Monitorr 1.7.6m searchsploit 發現  Unauthenticated RCE 48980 直接利用後拿到 Reverse Shell PE : 使用者 fox Home 目錄下有個特別的檔案 reminder 裡面描述了 crypt.php 之後一樣在 Home 目錄的 devel 使用提示讀取到 crypt.php 檔案,並獲得的一組密碼 使用新獲得的憑證登入機器發現可以 sudo 使用 hping3 依據 GTFO 的 sudo 利用說明,讀取 /root/.ssh/id_rsa 檔案內容 使用 id_rsa with root 登入成功 Rustscan,└─$ rustscan -a 192.168.223.218 --scripts none --ulimit 5000 | tee rustscan nmap check,└─$ sudo nmap -sU -p 161 192.168.223.218 | tee snmp             nmap,└─$ sudo nmap -sCV -A -p 22,80 192.168.223.218 | tee nmap 22/tcp open  ssh     OpenSSH 7.9p1 Debian 10+deb10u2 (protocol 2.0) 80/tcp open  http    Apache httpd 2.4.38 ((Debian)) whatweb,└─$ whatweb http://192.168.223.218 | tee whatweb 80 / 轉 /mon 下方顯示 Monitorr 1.7.6m searchsploit 看看└─$ searchsploit Monitorr 發現 RCE 而且還是 Unauthenticated,有這麼容易中大獎.....               ...