image-20260210115145632

image-20260210125601909

image-20260210130551239

F12

image-20260210130716089

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
┌──(root㉿kali)-[~]
└─# echo "192.168.56.125 coolpgi.hmv">> /etc/hosts

┌──(root㉿kali)-[~]
└─# cat /etc/hosts
192.168.56.125 coolpgi.hmv

┌──(root㉿kali)-[~]
└─# ping coolpgi.hmv
PING coolpgi.hmv (192.168.56.125) 56(84) bytes of data.
64 bytes from coolpgi.hmv (192.168.56.125): icmp_seq=1 ttl=64 time=2.04 ms
64 bytes from coolpgi.hmv (192.168.56.125): icmp_seq=2 ttl=64 time=0.373 ms
^Z
zsh: suspended ping coolpgi.hmv

┌──(root㉿kali)-[~]
└─# ffuf -u http://coolpgi.hmv/FUZZ -w /usr/share/wordlists/dirb/common.txt -fs 1323

/'___\ /'___\ /'___\
/\ \__/ /\ \__/ __ __ /\ \__/
\ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\
\ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/
\ \_\ \ \_\ \ \____/ \ \_\
\/_/ \/_/ \/___/ \/_/

v2.1.0-dev
________________________________________________

:: Method : GET
:: URL : http://coolpgi.hmv/FUZZ
:: Wordlist : FUZZ: /usr/share/wordlists/dirb/common.txt
:: Follow redirects : false
:: Calibration : false
:: Timeout : 10
:: Threads : 40
:: Matcher : Response status: 200-299,301,302,307,401,403,405,500
:: Filter : Response size: 1323
________________________________________________

login [Status: 302, Size: 189, Words: 18, Lines: 6, Duration: 52ms]
panel [Status: 200, Size: 1273, Words: 196, Lines: 34, Duration: 5ms]
search [Status: 200, Size: 944, Words: 146, Lines: 30, Duration: 23ms]
:: Progress: [4614/4614] :: Job [1/1] :: 956 req/sec :: Duration: [0:00:05] :: Errors: 0 ::

image-20260210131621250

直接提示支持union select

手动测试一下

image-20260210132106346

直接sqlmap跑了

image-20260210132348361

ssh连接

image-20260210132455900

简单看一眼

看一下suid然后sudo -l发现个脚本

有点容易的过头了

image-20260210132635229