vulhub / vulhub

Pre-Built Vulnerable Environments Based on Docker-Compose
https://vulhub.org
MIT License
17.74k stars 4.47k forks source link

个问题请教大佬 #24

Closed x7peeps closed 6 years ago

x7peeps commented 6 years ago

what happened

想知道weblogic_ssrf 探测redis服务器172.19.0网段的时候,探测的172.19.0的这些主机,在vulhub环境下是归属于网上还是归属于本地虚拟环境的?

what did i do

我在做weblogic_ssrf实验的过程中,做到了redis反弹shell的这一步,需要探测`172.19.0网段中redis服务器位置。 其中我的目标是探测出内网中redis服务器。

what should happend

这里实际上将会探测出一大堆172.18.0的主机。

......
172.19.0.24
[!]172.19.0.16:443
[!]172.19.0.20:53
[!]172.19.0.10:445
[!]172.19.0.4:1080
[!]172.19.0.6:1521
[!]172.19.0.21:22
[!]172.19.0.9:3389
[!]172.19.0.13:1080
[!]172.19.0.18:80
[!]172.19.0.15:443
 [!]172.19.0.17:135
[!]172.19.0.19:53
[!]172.19.0.12:135
[!]172.19.0.11:139
[!]172.19.0.8:1080
172.19.0.25
[!]172.19.0.16:445
[!]172.19.0.24:21
[!]172.19.0.10:1080
[!]172.19.0.7:3306
[!]172.19.0.4:1433
[!]172.19.0.6:3306
[!]172.19.0.9:4899
[!]172.19.0.13:1433
[!]172.19.0.22:22
[!]172.19.0.17:139
[!]172.19.0.19:80
......
x7peeps commented 6 years ago

误报,脚本问题。 实际check其他host时会发现无法route host。

......
<p>An error has occurred<BR>
weblogic.uddi.client.structures.exception.XML_SoapException: No route to host
        </table>
    </td>
......