Maiyadi.com penetration notes

Source: Internet
Author: User

Maiyadi.com penetration notes
0x00 is a few days ago. For some reason, OS X broke the Machook Trojan. A friend posted the Trojan on V2EX, called "a social engineering tour of Machook Trojan". A few days later, Livid posted a letter indicating that he had received the lawyer's letter and deleted it.
Well, the malts style is indeed unpleasant, and I am also bored and will penetrate the malts website. The Penetration Process is recorded as follows.
0x01 first detects the malt site and its subdomain names. The query results contain the following domain names:

61.147.80.69www.maiyadi.combbs.maiyadi.comnews.maiyadi.com182.18.31.71image.maiyadi.comweb.maiyadi.com61.147.80.73app.maiyadi.comadmin.app.maiyadi.com

The first two groups have no vulnerabilities. One is Discuz and the other is not clear. In group 3, admin.app.maiyadi.com belongs to PHPCMS, and registration is not allowed. If a few exp entries are entered, there is no information. You can only read app.maiyadi.com on your scalp.

I randomly read several PHP files and found a blind note.

Http://app.maiyadi.com/data.php? Tid = 136 & cid = 3 & num = 5 is a typical blind injection. After manually testing select user (), we found that it was root @ localhost, So we wrote a script for blind injection (I was so excited that I forgot to use sqlmap 233333 ).

Then I ran slowly and ran slowly. I also took a bath in the middle. Finally, I ran all the databases. Then I ran the password ..

I am glad that I successfully entered the background and then getshell, using the PHPCMS hole.

The funny thing is that someone got the shell two hours earlier than me. It seems that many people are eyeing it ~

Then I took some information, such as the database password:

return array (    'default' => array (        'hostname' => '192.168.1.121',        'database' => 'cms',        'username' => 'root',        'password' => 'aQuoo0aaDB',        // ...);

At that time, I ran the Database Name and looked at it a little. The visual test showed that all the user tables were on the ucenter and connected. In another query, 120 million users almost cried out OAQ.

The administrator password cannot be broken, and then the administrator password is updated to log in.

I searched for the mailbox password configuration for half a day in the database, but I was disappointed that the Login Failed (ry

0x02

I want to continue to win server permissions in depth, but the information is seriously insufficient. The social engineering library does not have administrator information, and there are no other private things. The password queried in the malt database cannot be cracked.

Well, password fishing is a problem. Although I don't have the main site shell, We can insert JavaScript in the Discuz statistics code, and we can also control a subdomain, so a very evil idea...> w <



It is difficult to find that the subdomain name will not be suspected by Introducing JavaScript here later.
Two days later, I finally caught the Administrator's password. _ (: 3

So it's pleasant ..


And subsequent penetration is just starting (
Next, I can continue with the passwords of other social engineering administrators and find who controls the server, domain name registration mailbox, and DNSPod mailbox.
Time-consuming and unsuccessful. Based on the bad mood and lots of things to do ..

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.