
tryhackme
文章平均质量分 92
XingHe_0
但行好事,莫问前程。
展开
-
tryhackme--Overpass
tryhackme–Overpass用nmap扫描主机,因为前面我已经简单扫过开放的端口了,所以我现在直接放上详细扫描的贴图和命令nmap -T4 -sS -sV 10.10.220.203 -sC -p 22,80扫描得到的目录各种扫描,注入,爆破都试过了,也没有历史漏洞,看了wp才知道是js代码逻辑漏洞,这方面练的太少了,以至于没有找到切入点async function login() { const usernameBox = document.querySelector("原创 2020-11-16 23:17:31 · 471 阅读 · 0 评论 -
tryhackme--Ignite
tryhackme–Ignite用nmap扫描nmap -T4 -sS -sV 10.10.214.254 -sC发现CMS及版本搜索本地漏洞库,发现一个远程代码执行漏洞,不要问我为什么不选sql的,系统命令执行和数据库那个香自己掂量查看脚本里面的payload用法修改一下paylaod,执行查看源码%27%2b%70%69%28%70%72%69%6e%74%28%24%61%3d%27%73%79%73%74%65%6d%27%29%29%2b%24%61%28%27"id"%2原创 2020-11-15 23:48:54 · 258 阅读 · 0 评论 -
tryhackme--Blog
tryhackme–Tony the Tiger原创 2020-11-15 19:51:50 · 445 阅读 · 0 评论 -
tryhackme--OWASP Top 10
tryhackme-- OWASP Top 10Task 5 [Severity 1] Command Injection PracticalWhat strange text file is in the website root directory?How many non-root/non-service/non-daemon users are there?What user is this app running as?What is the user's shell set as?What v原创 2020-11-13 00:07:42 · 1809 阅读 · 0 评论 -
tryhackme--Injection
tryhackme--InjectionTask 3 Blind Command InjectionPing the box with 10 packets. What is this command (without IP address)?Redirect the box's Linux Kernel Version to a file on the web server. What is the Linux Kernel Version?Enter "root" into the input a原创 2020-11-12 11:08:40 · 414 阅读 · 0 评论 -
tryhackme--Overpass 2 - Hacked
tryhackme--Overpass 2 - HackedTask 1 -Forensics - Analyse the PCAP#1 What was the URL of the page they used to upload a reverse shell?#2 What payload did the attacker use to gain access?#3 What password did the attacker use to privesc?#4 How did the attack原创 2020-11-05 15:03:59 · 779 阅读 · 0 评论 -
tryhackme--Wgel CTF
tryhackme--Wgel CTFnmapid_rsa信息泄漏wget的sudo提权nmap简单扫描靶机的服务nmap -T4 -sS -sV 10.10.247.24深度扫描也没没有什么可以直接利用的漏洞目标机器为linux主机,并且目标主机开放了两个端口:22、80。端口服务22ssh80httpid_rsa信息泄漏访问80端口,发现为apache的默认页面,查看页面源代码,发现一句很有趣的话,其中 Jessie 可能为用户名用dirsear原创 2020-10-23 23:18:01 · 485 阅读 · 0 评论 -
tryhackme-Bolt
tryhackme--Boltnmap注:tryhackme的第二个靶机nmap原创 2020-10-02 22:05:29 · 463 阅读 · 0 评论