首页 > 其他分享 >bullyBox pg walkthrough Intermediate

bullyBox pg walkthrough Intermediate

时间:2025-01-12 10:55:26浏览次数:1  
标签:webshell 发现 登录 bullyBox 写入 walkthrough Intermediate exp 页面

nmap 发现80 和 22端口
访问80 端口发现 跳转 http://bullybox.local/
在/etc/hosts 里面加上这个域名

image

dirsearch 扫描的时候发现了.git泄露
用dunpall工具 获取.git泄露的源码
image

查看源码
我们发现了数据库的密码
'name' => 'boxbilling',
'user' => 'admin',
'password' => 'Playing-Unstylish7-Provided'

image

然后上网搜索到了管理员登录地址
image
更具他的url 我们发现了登录地址确实存在 但是他要的是email 而不是用户名登录 导致我们无法验证 我们刚刚发现的用户名和密码是否能登录

image

同时我们发现左下角 暴露了版本信息
image

上网搜索一下exp
image
发现这个是可行的exp

我找了半天管理员邮箱 没找到 只找到一个大致相关的页面
image
看了这个页面的内容 我就猜测 管理员的邮箱为admin@bullybox.local
嘿 你猜怎么着 真对了
登录成功了
image

发现有文件管理页面
image
尝试写个webshell
image
但是发现我保存报摊 写入的内容保存不下来

于是想到用刚刚的exp
https://www.exploit-db.com/exploits/51108
image
发现能写入成功
image
ok现在我们再来尝试写shell
将webshell写入shell1.php里面
image
尝试执行命令
image
webshell写入成功
尝试反弹shell
反弹成功
image
提权环节
sudo -l 发现我们可以执行任何命令
so easy 直接sudo su
提权成功
image

image

标签:webshell,发现,登录,bullyBox,写入,walkthrough,Intermediate,exp,页面
From: https://www.cnblogs.com/wssw/p/18666773

相关文章

  • flow pg walkthrough Intermediate
    nmapnmap-p--A-T4-sS192.168.114.104StartingNmap7.94SVN(https://nmap.org)at2025-01-0703:03UTCNmapscanreportfor192.168.114.104Hostisup(0.072slatency).Notshown:65533filteredtcpports(no-response)PORTSTATESERVICEVERSION......
  • Access pg walkthrough Intermediate window域渗透
    nampnmap-p--A-sS-T4192.168.200.187StartingNmap7.94SVN(https://nmap.org)at2024-12-2300:24UTCStats:0:02:36elapsed;0hostscompleted(1up),1undergoingScriptScanNSETiming:About98.45%done;ETC:00:26(0:00:00remaining)Nmapscan......
  • Medjed pg walkthrough Intermediate window
    nmapnmap-p--A-sS-T4192.168.219.127StartingNmap7.94SVN(https://nmap.org)at2024-12-2201:22UTCStats:0:02:05elapsed;0hostscompleted(1up),1undergoingServiceScanServicescanTiming:About83.33%done;ETC:01:24(0:00:15remaining)......
  • AuthBy pg walkthrough Intermediate window
    nmap└─#nmap-p--A-sS192.168.226.46StartingNmap7.94SVN(https://nmap.org)at2024-12-2101:01UTCStats:0:01:06elapsed;0hostscompleted(1up),1undergoingSYNStealthScanSYNStealthScanTiming:About52.12%done;ETC:01:04(0:01:00rema......
  • Slort pg walkthrough Intermediate window
    nmap┌──(root㉿kali)-[~]└─#nmap-p--A-sS192.168.226.53StartingNmap7.94SVN(https://nmap.org)at2024-12-2004:30UTCStats:0:01:10elapsed;0hostscompleted(1up),1undergoingServiceScanServicescanTiming:About40.00%done;ETC:04:32......
  • Shenzi pg walkthrough Intermediate window
    nmap└─#nmap-p--A-sS-T5192.168.218.55StartingNmap7.94SVN(https://nmap.org)at2024-12-1623:45UTCStats:0:00:02elapsed;0hostscompleted(1up),1undergoingSYNStealthScanSYNStealthScanTiming:About0.97%doneStats:0:00:03elapsed......
  • Hutch PG walkthrough Intermediate window
    NMAP└─#nmap-p--A-sS192.168.196.122StartingNmap7.94SVN(https://nmap.org)at2024-12-1601:39UTCNmapscanreportfor192.168.196.122Hostisup(0.071slatency).Notshown:65515filteredtcpports(no-response)PORTSTATESERVICEV......
  • Nickel pg walkthrough Intermediate window
    nmap┌──(root㉿kali)-[~]└─#nmap-p--A-sS192.168.196.99StartingNmap7.94SVN(https://nmap.org)at2024-12-1600:19UTCStats:0:01:37elapsed;0hostscompleted(1up),1undergoingSYNStealthScanSYNStealthScanTiming:About98.92%done;ET......
  • Billyboss pg walkthough Intermediate window
    nmap┌──(root㉿kali)-[/home/ftpuserr/nc.exe]└─#nmap-p--A-sS192.168.219.61StartingNmap7.94SVN(https://nmap.org)at2024-12-1507:24UTCNmapscanreportfor192.168.219.61Hostisup(0.071slatency).Notshown:65521closedtcpports(reset)......
  • DVR4 pg walkthrough Intermediate window
    nmap┌──(root㉿kali)-[~/lab]└─#nmap-p--A-sS192.168.219.179StartingNmap7.94SVN(https://nmap.org)at2024-12-1504:22UTCStats:0:00:22elapsed;0hostscompleted(1up),1undergoingSYNStealthScanSYNStealthScanTiming:About34.76%don......