How to analyze the loophole of CTF shooting range
This article introduces how to analyze the loopholes in CTF shooting range. The content is very detailed. Interested friends can use it for reference. I hope it will be helpful to you.
Actual combat exercise
Use the netdiscover command to find the IP of the target machine.
Use nmap to view the open ports of the target machine
Open the browser
There is a CVE-2007-1860 vulnerability in this target, http://192.168.0.103/examples/jsp/%252e%252e/%252e%252e/manager/html.
After opening it, the browser will pop up an input box, enter admin for the account, and log in successfully if the password is empty.
Then upload the war Trojan to get the permission.
On how to carry out CTF range loophole analysis is shared here, I hope that the above content can be of some help to you, can learn more knowledge. If you think the article is good, you can share it for more people to see.