duangsues.is_a? SaltedFish
60 subscribers
609 photos
6 videos
91 files
562 links
🌶🐔🐟 duangsuse 的日常
尤其喜欢发些奇奇怪怪的东西
和转载别人的东西
Download Telegram
duangsues.is_a? SaltedFish
[+] WordPress version 4.8.3 (Released on 2017-10-31) identified from meta generator, links opml 从这个开始
LWL12.com 的运维质量一比 🌚
~~萌妹~~ LWL12
[+] URL: https://blog.lwl12.com/
[+] robots.txt available under: 'https://blog.lwl12.com/robots.txt'
[+] Interesting entry from robots.txt: https://blog.lwl12.com/wp-
[+] WordPress version 4.9.5 (Released on 2018-04-03) identified from stylesheets numbers, advanced fingerprinting, links opml
[+] No plugins found
[+] Requests Done: 41
[+] Elapsed time: 00:00:07

对比骗子

[+] robots.txt available under: 'https://mightficent.com/robots.txt'
[+] Interesting entry from robots.txt: https://mightficent.com/wp-admin/admin-ajax.php
[+] WordPress version 4.8.3 (Released on 2017-10-31) identified from meta generator, links opml
[!] 10 vulnerabilities identified from the version number
[!] Title: WordPress 2.3-4.8.3 - Host Header Injection in Password Reset
[!] Title: WordPress 2.8.6-4.9 - Authenticated JavaScript File Upload
[!] Title: WordPress 3.7-4.9.1 - MediaElement Cross-Site Scripting (XSS)
[!] Title: WordPress Slider Revolution Shell Upload
[+] Requests Done: 402
[+] Elapsed time: 00:10:04
duangsues.is_a? SaltedFish
[+] WordPress version 4.8.3 (Released on 2017-10-31) identified from meta generator, links opml 从这个开始
目前对动苏来说只有 shell(拿到虚拟主机控制权) 和 bypass auth(cpanel 的或者 wordpress 的管理) 是有价值的, 即使的确有不少漏洞
我只能换目标
msf auxiliary(scanner/mysql/mysql_version) > run -j
[*] Auxiliary module running as background job 2.
[*] 103.233.0.244:3306 - 103.233.0.244:3306 is running MySQL, but responds with an error: \x04Host '27.27.54.51' is not allowed to connect to this MySQL server
[*] 103.233.0.244:3306 - Scanned 1 of 1 hosts (100% complete)
刚才知道其实 cPanel 是 2018 年最新的
这样所有组件都很难渗透测试,找不到能用的漏洞
或许 XSS 是一种方法,但不好的是我没有能拿来 XSS 的服务器....
比较尴尬了(...
duangsues.is_a? SaltedFish
大概的报告: 45.62.110.178.16clouds.com 80: Apache 2.2.15 bwg,,可以正常访问,收到一份网址列表 Linux 2.6 (CentOS) mmallv2u.net 80:Tengine 443:ssl 843:adobe-crossdomain 1935:tcpwrapped Tiandy NVR (89%), IPCop 2 firewall (Linux 3.4) (87%), Linux 3.2 (87%) 103.208.220.66 22:ssh…
msf auxiliary(scanner/mysql/mysql_login) > set RHOSTS m-darts.com
RHOSTS => m-darts.com
msf auxiliary(scanner/mysql/mysql_login) > run

[+] 110.4.45.141:3306 - 110.4.45.141:3306 - Found remote MySQL version 5.5.58


msf auxiliary(scanner/mysql/mysql_login) > use exploit/linux/mysql/mysql_yassl_hello
msf exploit(linux/mysql/mysql_yassl_hello) > info
Platform: Linux

  This module exploits a stack buffer overflow in the yaSSL (1.7.5 and 
earlier) implementation bundled with MySQL <= 6.0. By sending a
specially crafted Hello packet, an attacker may be able to execute
arbitrary code.

有可能 🌚 — 不行, 他们的版本还是太高 🌑
#INFO #life 这次测试到此结束 🌚
如果以后再有动态重启
明天依旧继续开发 GeekApk
依然保持 0 shell(s) 的成绩, 同时也没有成功利用任何 bypass/越权漏洞
保持 0% 的成功纪录
This media is not supported in your browser
VIEW IN TELEGRAM
This media is not supported in your browser
VIEW IN TELEGRAM
#life 倒霉,昨天中午自己炒了一盘 bian(Fictx 打不出来..) 豆, 夹生了....