web信息
一般来说靶机都需要进行常规的目录扫描
python3 tools/dirsearch/dirsearch.py -w /usr/share/seclists/Discovery/Web-Content/directory-list-lowercase-2.3-big.txt -t 50 -e * -u http://192.168.1.137/
192.168.1.137/test/
从结果来看,没有看到任何有用的信息
端口信息
http://192.168.1.137/upload.php
base64信息:
<!-- Not everything you see is real , maybe it&