vulnhub-BBS (CUTE): 1.0.1-cute

http://blog.yutian233.xyz/index.php/archives/63/

靶机描述

Machine name: BBS (Bulletin Board System)

Level: Easy->Intermediate

flags: user, root

Description: really technical machine, if you are ready for certifications it will be a good tool to test yourself. You will find a very rare final exploit technique, which you have hardly seen before!

Author: foxlox

About VM: VirtualBox ready, the adapter is currently Bridged, DHCP active

You can contact me by email (fox at thebrain dot net) or Discord foxlox#1089

Machine hint: don't let your eyes confuse you, Try Harder!

This works better with VirtualBox rather than with VMware ## Changelog v1.0.1 - 2020-09-23 v1.0.0 - 2020-09-21

下载 https://www.vulnhub.com/entry/bbs-cute-101,567/

清单

  • 信息搜集

    • netdiscover
    • nmap
    • dirb
  • 提权

    • CuteNews 2.1.2 - Remote Code Execution(CVE-2019-11447)
    • sudo -l (hping3)

信息搜集

靶机IP

image-20200925123352149

端口扫描

nmap -sS -sV -p- 192.168.34.152

PORT    STATE SERVICE  VERSION
22/tcp  open  ssh      OpenSSH 7.9p1 Debian 10+deb10u2 (protocol 2.0)
80/tcp  open  http     Apache httpd 2.4.38 ((Debian))
88/tcp  open  http     nginx 1.14.2
110/tcp open  pop3     Courier pop3d
995/tcp open  ssl/pop3 Courier pop3d

目录扫描

img-yz35adio-1601010496100

来到 index.php

image-20200925123511389

相关版本为 CuteNews 2.1.2

搜索相关漏洞

image-20200925123559101

修改exp

image-20200925123648025

可以看到 exp 的请求连接拼接为 CuteNews

由于网站没有 CuteNews 所以需要替换

验证

image-20200925123933646

现在来获取shell

Kali

image-20200925123905045

image-20200925125855873

修改shell.php文件

靶机

image-20200925125924967

下载 shell.php

访问 shell.php

image-20200925125957851

得到shell

image-20200925130025095

得到user.txt flag

获取root

image-20200925130314765

  • 0
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值