duangsues.is_a? SaltedFish
60 subscribers
609 photos
6 videos
91 files
562 links
🌶🐔🐟 duangsuse 的日常
尤其喜欢发些奇奇怪怪的东西
和转载别人的东西
Download Telegram
duangsues.is_a? SaltedFish
megahashill.txt
[i] WordPress version can not be detected

Name: wp-maintenance-mode - v1.8.3
The version is out of date, the latest version is 2.1.2
duangsues.is_a? SaltedFish
menbridges.txt
[+] WordPress version 4.8.3 (Released on 2017-10-31) identified from links opml
duangsues.is_a? SaltedFish
menpasar.txt
[+] WordPress version 4.9.4 (Released on 2018-02-06) identified from links opml
duangsues.is_a? SaltedFish
mightficent.txt
[+] WordPress version 4.8.3 (Released on 2017-10-31) identified from meta generator, links opml

从这个开始
duangsues.is_a? SaltedFish
[+] WordPress version 4.8.3 (Released on 2017-10-31) identified from meta generator, links opml 从这个开始
LWL12.com 的运维质量一比 🌚
~~萌妹~~ LWL12
[+] URL: https://blog.lwl12.com/
[+] robots.txt available under: 'https://blog.lwl12.com/robots.txt'
[+] Interesting entry from robots.txt: https://blog.lwl12.com/wp-
[+] WordPress version 4.9.5 (Released on 2018-04-03) identified from stylesheets numbers, advanced fingerprinting, links opml
[+] No plugins found
[+] Requests Done: 41
[+] Elapsed time: 00:00:07

对比骗子

[+] robots.txt available under: 'https://mightficent.com/robots.txt'
[+] Interesting entry from robots.txt: https://mightficent.com/wp-admin/admin-ajax.php
[+] WordPress version 4.8.3 (Released on 2017-10-31) identified from meta generator, links opml
[!] 10 vulnerabilities identified from the version number
[!] Title: WordPress 2.3-4.8.3 - Host Header Injection in Password Reset
[!] Title: WordPress 2.8.6-4.9 - Authenticated JavaScript File Upload
[!] Title: WordPress 3.7-4.9.1 - MediaElement Cross-Site Scripting (XSS)
[!] Title: WordPress Slider Revolution Shell Upload
[+] Requests Done: 402
[+] Elapsed time: 00:10:04
duangsues.is_a? SaltedFish
[+] WordPress version 4.8.3 (Released on 2017-10-31) identified from meta generator, links opml 从这个开始
目前对动苏来说只有 shell(拿到虚拟主机控制权) 和 bypass auth(cpanel 的或者 wordpress 的管理) 是有价值的, 即使的确有不少漏洞
我只能换目标
msf auxiliary(scanner/mysql/mysql_version) > run -j
[*] Auxiliary module running as background job 2.
[*] 103.233.0.244:3306 - 103.233.0.244:3306 is running MySQL, but responds with an error: \x04Host '27.27.54.51' is not allowed to connect to this MySQL server
[*] 103.233.0.244:3306 - Scanned 1 of 1 hosts (100% complete)
刚才知道其实 cPanel 是 2018 年最新的
这样所有组件都很难渗透测试,找不到能用的漏洞
或许 XSS 是一种方法,但不好的是我没有能拿来 XSS 的服务器....
比较尴尬了(...