一,搭建环境
本次测试使用hackme的靶机
data:image/s3,"s3://crabby-images/0914c/0914c1b82bd7679e73f3f0bdfd489dae68a45897" alt=""
攻击为kali(192.168.30.130)与物理机
二,信息收集
1.确定IP
先确定mac信息,再搭配主机扫描确定靶机的IP地址
00:0C:29:D0:F5:74
data:image/s3,"s3://crabby-images/8dea8/8dea8b591de2ccf0837da6c1c08d1efe2801795b" alt=""
确定靶机地址为 192.168.30.133
2.扫描靶机的端口
data:image/s3,"s3://crabby-images/a15b2/a15b233d5a4b72469754a5a7b49f089f143a1ef7" alt=""
22 80端口开放
尝试访问
data:image/s3,"s3://crabby-images/515d2/515d28876e89bb07afb93f8bbf8b74f04f740694" alt=""
默认端口是登录页面
3.目录信息收集
使用dirb扫描
data:image/s3,"s3://crabby-images/ffc0f/ffc0f6cf9afd41f2c49df1703775ac02eba40958" alt=""
尝试访问这三个目录
data:image/s3,"s3://crabby-images/e2db6/e2db617a33edc091a5716da1198f3f7e4af72f33" alt=""
第二个为登录页面
第三个为一个上传页面(没找到上传按钮)
data:image/s3,"s3://crabby-images/bde97/bde974be18f2db942345b7047c7f2b1d3c434f76" alt=""
三,漏洞挖掘
1.登录页面
首先尝试弱口令破解
没有成功
data:image/s3,"s3://crabby-images/3b749/3b74991e04ef0acdce9c6da9b2798952a18f4e2f" alt=""
先注册登录
data:image/s3,"s3://crabby-images/aa3cb/aa3cb179181c45565cf7f1df98039415697b5188" alt=""
2.用户页面
登录后发现有搜索框 尝试sql注入
data:image/s3,"s3://crabby-images/82c8b/82c8bb4964ad56b48d8b58e8fe529a887bdf22dc" alt=""
data:image/s3,"s3://crabby-images/12fdb/12fdb8f6c655cc5b736a801c92e355bbf7890b10" alt=""
data:image/s3,"s3://crabby-images/77a44/77a444d09676fe259edfa87577ae3b6f5f6d4ed7" alt=""
确认存在sql注入
显而易见字段数为3
查看数据库 名称为webapphacking
data:image/s3,"s3://crabby-images/251ce/251ce685356221ecd9572fd34baaa5834b0e713c" alt=""
查看表 -1' union select group_concat(table_name),2,3 from information_schema.tables where table_schema='webapphacking'#
data:image/s3,"s3://crabby-images/f644a/f644a4f6b909aed9a54197db254318aa5455ea3d" alt=""
查看user表中的数据
-1' union select group_concat(user),group_concat(pasword),3 from users#
data:image/s3,"s3://crabby-images/d1d54/d1d544e95695f8107cf24d8d665bcc4c985dc886" alt=""
密码为MD5加密 解密
登录其中的 superadmin Uncrackable
data:image/s3,"s3://crabby-images/5936c/5936c31bc0609dd1bcb100bca24564d95024b6db" alt=""
发现文件上传
尝试上传phpinfo
上传后回到该页面 尝试访问
data:image/s3,"s3://crabby-images/1eaa9/1eaa9c8e6580cb9de94627b8c5847914a1e5a554" alt=""
成功访问
data:image/s3,"s3://crabby-images/b585a/b585ace3d6cb2f95c66cbcb72497c12dfc6bef85" alt=""
四,漏洞利用
依据上面上传phpinfo的步骤,上传一句话木马
data:image/s3,"s3://crabby-images/a0ce2/a0ce20b1f8e6b79f573dfaa56b6603af307b60f4" alt=""
尝试连接
data:image/s3,"s3://crabby-images/33f4d/33f4de412716ff8fd2a8f598b9e79b5165fb1e2d" alt=""
连接成功 拿到shell
data:image/s3,"s3://crabby-images/2a107/2a10750892db87031f79c2fa823d2e7048722f89" alt=""