公众号:泷羽Sec-尘宇安全
前言
oscp备考,oscp系列——FALL靶场,LFI漏洞+读取.ssh/id_rsa密钥文件,sudo提权
难度简单
- 对于低权限shell获取涉及:LFI漏洞+读取
.ssh/id_rsa密钥文件 - 对于提权:sudo提权
下载地址:
https://www.vulnhub.com/entry/digitalworldlocal-fall,726/
nmap
主机发现
└─# nmap -sn 192.168.56.0/24
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-02-18 16:31 CST
Nmap scan report for 192.168.56.1
Host is up (0.00045s latency).
MAC Address: 0A:00:27:00:00:16 (Unknown)
Nmap scan report for 192.168.56.100
Host is up (0.00040s latency).
MAC Address: 08:00:27:EB:66:6C (Oracle VirtualBox virtual NIC)
Nmap scan report for 192.168.56.103
Host is up (0.0012s latency).
MAC Address: 08:00:27:0D:87:DA (Oracle VirtualBox virtual NIC)
Nmap scan report for 192.168.56.104
Host is up.
Nmap done: 256 IP addresses (4 hosts up) scanned in 2.02 seconds
端口扫描
└─# nmap --min-rate 10000 -p- 192.168.56.103
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-02-18 16:45 CST
Nmap scan report for 192.168.56.103
Host is up (0.00096s latency).
Not shown: 65500 filtered tcp ports (no-response), 22 filtered tcp ports (host-prohibited)
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
111/tcp closed rpcbind
139/tcp open netbios-ssn
443/tcp open https
445/tcp open microsoft-ds
3306/tcp open mysql
8000/tcp closed http-alt
8080/tcp closed http-proxy
8443/tcp closed https-alt
9090/tcp open zeus-admin
10080/tcp closed amanda
10443/tcp closed cirrossp
MAC Address: 08:00:27:0D:87:DA (Oracle VirtualBox virtual NIC)
Nmap done: 1 IP address (1 host up) scanned in 16.73 seconds
└─# nmap --min-rate 10000 -p- 192.168.56.103 -sU
Starting Nmap 7.94SVN ( https://nmap.org ) at 2025-02-18 16:48 CST
Warning: 192.168.56.103 giving up on port because retransmission cap hit (10).
Nmap scan report for 192.168.56.103
Host is up (0.0013s latency).
All 65535 scanned ports on 192.168.56.103 are in ignored states.
Not shown: 65454 open|filtered udp ports (no-response), 81 filtered udp ports (host-prohibited)
M

最低0.47元/天 解锁文章
459

被折叠的 条评论
为什么被折叠?



