發表文章

目前顯示的是有「union select」標籤的文章

Proving Grounds Practice : Hawat Walkthrough

圖片
 Proving Grounds Practice : Hawat Walkthrough Foothold : 這一台靶機要應用的地方很多,共有三個網站 17445、30445 & 50080 一開始透過較大字典檔在 50080 發現 /cloud 路徑,使用常用帳號密碼 admin:admin 登入 CMS 枚舉獲得一個 ZIP 檔,發現 SQL Injection 的路徑與字串(Query String) 在 17445 確認可以注入,注入在 30445 枚舉到的路徑 /srv/http 並使用 UNION Select 語法注入成功 接著在 30445 存取注入的 cmd.php 網頁,執行 bash 指令獲取 Reverse Shell PE : 不用 PE,拿到 Reverse Shell 即為 root Rustscan,└─$ rustscan -a 192.168.223.147 --scripts none --ulimit 5000 | tee rustscan snmp check,└─$ sudo nmap -sU -p 161 192.168.223.147 | tee snmp nmap 22/tcp    open  ssh     OpenSSH 8.4 (protocol 2.0) 17445/tcp open  unknown 30455/tcp open  http    nginx 1.18.0 50080/tcp open  http    Apache httpd 2.4.46 ((Unix) PHP/7.4.15) 17445 / 17445 /robots.txt 註冊與登入 建立 Issues,使用 {{7*7}} 沒有運算結果 gobuster 17445 / 30455 / 30455 /robots.txt gobuster 30455 / gobuster 30455 /4 30455 /phpinfo.php 得知 Web 根目錄路徑放在 /srv/http 50080 / 50080 /robots.txt gobuster 50080 / 50080 /4 ...

Proving Grounds Play : DC-9 Walkthrough

圖片
 Proving Grounds Play : DC-9 Walkthrough Foothold : 80 Web 的 Search 發現 SQLi ,使用 sqlmap 讀取 DB 發現網站密碼 網站帳號密碼登入列舉使用者 sqlmap 在另一個資料庫讀取到多組密碼 hydra 測試得到多組憑證,其中一組 SSH 登入後發現某個密碼檔 再次 hydra 得到新的憑證,SSH 登入後獲取第一階段 flag PE : sudo -l 有個特別的檔案,有告知 Usage 用法 參考內容是讀取第一個檔案內容寫入第二個檔案 標準利用在 /etc/passwd 建立使用者後 su 切換該使用者成功提權 Rustscan,└─$ rustscan -a 192.168.151.209 --scripts none --ulimit 5000 | tee rustscan 一開始只有出現 80 Port,多掃了幾次出現了 22 Port snmp check,└─$ sudo nmap -sU -p 161 192.168.151.209 | tee snmp nmap,└─$ sudo nmap -sCV -A -p 22,80 192.168.151.209 | tee nmap 22/tcp open  ssh     OpenSSH 7.9p1 Debian 10+deb10u1 (protocol 2.0) 80/tcp open  http    Apache httpd 2.4.38 ((Debian)) whatweb,└─$ whatweb http://192.168.151.209 | tee whatweb 80 / 80 /robots.txt 80 /index.php 80 /display.php 獲得一堆使用者帳號 80 /search.php 先製作使用者帳號清單 80 /search.php 輸入 monica 顯示出 Monica 相關資訊,網頁是 /results.php 80 /manage.php 需要帳號密碼驗證 測試常用的帳號密碼組合,與網頁上列舉到的使用者帳號密碼一只都沒有用 gobuster 80 /,└─$ gobuster -w ./dirfu...