r0ckyzzz's Blog.

Vulnhub靶机DeRPnStiNK通关笔记

Word count: 214Reading time: 1 min
2020/03/21 Share

Vulnhub靶机DeRPnStiNK通关笔记

前言

下载地址:https://www.vulnhub.com/entry/derpnstink-1,221/

upload successful

开始

三个端口

upload successful

weblog有线索 要改hosts
http://derpnstink.local

upload successful

是个wordpress

upload successful

爆出了一个用户名密码

upload successful

看插件的版本

upload successful

有漏洞

upload successful

upload successful

传了一个weevely马

upload successful
记录一下mysql账号密码
root:mysql

upload successful
尝试udf提权 不行

进数据库拿密码哈希

upload successful

爆出来了一个 不要用john自带的字典 要用rockyou

upload successful

unclestinky:wedgie57

不能登陆ssh

upload successful
但是可以登陆ftp

upload successful

不知道进入了多少个ssh目录之后拿到了key

upload successful

拿到了flag3 但是前面两个flag不知道在哪里 不管了

upload successful

upload successful
有个流量包下载下来分析流量

这里找到了derp的密码

upload successful
derp:derpderpderpderpderpderpderp

upload successful
切换到了mrderp

在这个文件夹下面可以用sudo来执行提权

upload successful

提权成功

upload successful
拿到flag

upload successful

CATALOG
  1. 1. Vulnhub靶机DeRPnStiNK通关笔记
    1. 1.1. ¶前言
    2. 1.2. ¶开始