┌──(kali㉿kali)-[~] └─$ nmap -sV -sT -sC -o nmapinitial 192.168.33.130 Starting Nmap 7.92 ( https://nmap.org ) at 2022-09-2611:54 EDT Nmap scan report for192.168.33.130 Host is up (0.00056s latency). Not shown: 998 filtered tcp ports (no-response) PORT STATE SERVICE VERSION 80/tcp open http Apache httpd 2.4.23 ((Win32) OpenSSL/1.0.2j PHP/5.4.45) |_http-title: phpStudy \xE6\x8E\xA2\xE9\x92\x88 2014 |_http-server-header: Apache/2.4.23 (Win32) OpenSSL/1.0.2j PHP/5.4.45 3306/tcp open mysql MySQL (unauthorized)
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in23.42 seconds
mysql 有个未授权
直接连没成功
1 2 3
┌──(kali㉿kali)-[~] └─$ mysql -h 192.168.33.130 -P 3306 -u root ERROR 1130 (HY000): Host '192.168.33.133' is not allowed to connect to this MySQL server
先打80吧
扫一波目录
1
gobuster dir -u http://192.168.33.133/ -w /usr/share/wordlists/dirb/common.txt -t 100