靶场名称: DC: 5
靶场发布时间:2019-4-21
靶场地址:https://www.vulnhub.com/entry/dc-5,314/
靶场描述:
DC-5 is another purposely built vulnerable lab with the intent of gaining experience in the world of penetration testing.
The plan was for DC-5 to kick it up a notch, so this might not be great for beginners, but should be ok for people with intermediate or better experience. Time will tell (as will feedback).
As far as I am aware, there is only one exploitable entry point to get in (there is no SSH either). This particular entry point may be quite hard to identify, but it is there. You need to look for something a little out of the ordinary (something that changes with a refresh of a page). This will hopefully provide some kind of idea as to what the vulnerability might involve.
And just for the record, there is no phpmailer exploit involved. :-)
The ultimate goal of this challenge is to get root and to read the one and only flag.
Linux skills and familiarity with the Linux command line are a must, as is some experience with basic penetration testing tools.
For beginners, Google can be of great assistance, but you can always tweet me at @DCAU7 for assistance to get you going again. But take note: I won't give you the answer, instead, I'll give you an idea about how to move forward.
But if you're really, really stuck, you can watch this video which shows the first step.
VMware虚拟机(桥接模式)
获取靶机的IP
nmap -sn 192.168.3.0/24
使用nmap来查看靶机的端口信息和系统信息等等
首先去查看80端口的web服务
没有什么明显的信息就 一个留言框,使用dirb扫描一下目录
没有扫描到什么有用的页面,一些说明文件尝试也没有
继续尝试留言框
提交后年份就变了
gcc -fPIC -shared -ldl -o libhax.so libhax.c
报错,但是程序出来了
第二步:创建rootshell并编译文件(攻击机编译即可)
gcc -o rootshell rootshell.c
第三步:修改.sh文件
#!/bin/bash # screenroot.sh # setuid screen v4.5.0 local root exploit # abuses ld.so.preload overwriting to get root. # bug: https://lists.gnu.org/archive/html/screen-devel/2017-01/msg00025.html # HACK THE PLANET # ~ infodox (25/1/2017) echo "~ gnu/screenroot ~" echo "[+] First, we create our shell and library..."
screen -ls # screen itself is setuid,so...
/tmp/rootshell
在保存文件的时候 需要执行运行环境 不然会报错的
把这三个文件上传到靶机中
直接下载libhax.so (apache服务下载不下来)
使用 python -m http.server port 既可以下载 chmod777 权限后 就获取到root权限
孕妇肚子胀气怎么办 腹部按摩 从右下腹开始,以轻柔力道做顺时钟方向按摩,每次10~20圈,一天2~3次,可助舒缓腹胀感。 服用胃散 胀气状况严重时,可服用一些市售的胃散(服用前请先向医师询问)...
圣诞节老人的由来(圣诞节老人的由来是什么?) 今天是圣诞节,这是西方最重要的传统节日,相当于中国的春节。 圣诞节其实就是西方纪念耶稣的诞生日子,人们感激上帝让他的儿子耶稣到人间来拯救人类。...
六年级英语教学工作总结(小学六年级上学期英语教学工作总结) 一、基本情况 本学期我担任六( 1)班,六(2)班,六(3)班,六(4)班四个班的英语教学工作。 六(1)班共有53人,其中19人基础...
武汉市垃圾分类回收从上年说要推行,遭受肺炎疫情的危害武汉市垃圾分类回收2020年又拥有新的进度,现在武汉的垃圾分类回收工作中早已拥有有关要求。武汉市垃圾分类回收何时逐渐推行 武汉市生活垃圾处理如何归...
本文导读目录: 1、手机被监控了要怎样处理? 2、手机被黑客攻击了,怎么办? 3、请问华为手机被人远程控制如何解除? 4、手机被黑客定跟踪了怎么办 5、苹果手机被黑客远程控制怎么办?...