challenges-anssi-ecsc-web-php-sandbox
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revision | |||
| challenges-anssi-ecsc-web-php-sandbox [2019/05/16 13:28] – didzkovitchz | challenges-anssi-ecsc-web-php-sandbox [2020/12/15 21:20] (current) – removed didzkovitchz | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | ====== ANSSI ECSC ~~ Challenges web ~~ PHP Sandbox ====== | ||
| - | [[anssi-ecsc|Retour]] | ||
| - | ===== Présentation ===== | ||
| - | |||
| - | À vous de trouver les bons arguments pour lui parler. | ||
| - | |||
| - | http:// | ||
| - | |||
| - | ''< | ||
| - | |||
| - | |||
| - | ===== 1 - cURL ===== | ||
| - | |||
| - | '' | ||
| - | |||
| - | < | ||
| - | * Expire in 0 ms for 6 (transfer 0x7fffd075a090) | ||
| - | * Expire in 1 ms for 1 (transfer 0x7fffd075a090) | ||
| - | * Expire in 0 ms for 1 (transfer 0x7fffd075a090) | ||
| - | * Expire in 2 ms for 1 (transfer 0x7fffd075a090) | ||
| - | * Expire in 1 ms for 1 (transfer 0x7fffd075a090) | ||
| - | * Expire in 1 ms for 1 (transfer 0x7fffd075a090) | ||
| - | * Expire in 4 ms for 1 (transfer 0x7fffd075a090) | ||
| - | * Expire in 4 ms for 1 (transfer 0x7fffd075a090) | ||
| - | * Expire in 4 ms for 1 (transfer 0x7fffd075a090) | ||
| - | * Expire in 5 ms for 1 (transfer 0x7fffd075a090) | ||
| - | * | ||
| - | * TCP_NODELAY set | ||
| - | * Expire in 149990 ms for 3 (transfer 0x7fffd075a090) | ||
| - | * Expire in 200 ms for 4 (transfer 0x7fffd075a090) | ||
| - | * Connected to challenges.ecsc-teamfrance.fr (51.91.7.35) port 8000 (#0) | ||
| - | > GET / HTTP/1.1 | ||
| - | > Host: challenges.ecsc-teamfrance.fr: | ||
| - | > User-Agent: curl/7.64.0 | ||
| - | > Accept: */* | ||
| - | > | ||
| - | < HTTP/1.1 200 OK | ||
| - | < Date: Tue, 14 May 2019 11:42:19 GMT | ||
| - | < Server: Apache/ | ||
| - | < Content-Length: | ||
| - | < Content-Type: | ||
| - | < | ||
| - | * Connection #0 to host challenges.ecsc-teamfrance.fr left intact | ||
| - | < | ||
| - | </ | ||
| - | |||
| - | '' | ||
| - | |||
| - | < | ||
| - | HTTP/1.1 200 OK | ||
| - | Date: Tue, 14 May 2019 11:43:50 GMT | ||
| - | Server: Apache/ | ||
| - | Content-Length: | ||
| - | Content-Type: | ||
| - | </ | ||
| - | |||
| - | Pas grand chose de mieux en changeant la version de HTTP (1.0 et 2.0). | ||
| - | |||
| - | ===== 2 - dirb (directory buster) ===== | ||
| - | |||
| - | '' | ||
| - | |||
| - | < | ||
| - | ----------------- | ||
| - | DIRB v2.22 | ||
| - | By The Dark Raver | ||
| - | ----------------- | ||
| - | |||
| - | START_TIME: Tue May 14 14:08:11 2019 | ||
| - | URL_BASE: http:// | ||
| - | WORDLIST_FILES: | ||
| - | |||
| - | ----------------- | ||
| - | |||
| - | GENERATED WORDS: 4612 | ||
| - | |||
| - | ---- Scanning URL: http:// | ||
| - | + http:// | ||
| - | + http:// | ||
| - | |||
| - | ----------------- | ||
| - | END_TIME: Tue May 14 14:13:27 2019 | ||
| - | DOWNLOADED: 4612 - FOUND: 2 | ||
| - | </ | ||
| - | |||
| - | Nous avons donc 2 URL identifiées : | ||
| - | * http:// | ||
| - | * http:// | ||
| - | |||
| - | |||
| - | ===== 3 - nikto ===== | ||
| - | |||
| - | '' | ||
| - | |||
| - | < | ||
| - | - Nikto v2.1.6 | ||
| - | --------------------------------------------------------------------------- | ||
| - | + Target IP: 51.83.96.75 | ||
| - | + Target Hostname: | ||
| - | + Target Port: 8000 | ||
| - | + Message: | ||
| - | + Start Time: | ||
| - | --------------------------------------------------------------------------- | ||
| - | + Server: Apache/ | ||
| - | + The anti-clickjacking X-Frame-Options header is not present. | ||
| - | + The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS | ||
| - | + The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type | ||
| - | + No CGI Directories found (use '-C all' to force check all possible dirs) | ||
| - | + Apache/ | ||
| - | + Web Server returns a valid response with junk HTTP methods, this may cause false positives. | ||
| - | |||
| - | |||
| - | + OSVDB-3233: / | ||
| - | |||
| - | + 7865 requests: 0 error(s) and 6 item(s) reported on remote host | ||
| - | + End Time: | ||
| - | --------------------------------------------------------------------------- | ||
| - | + 1 host(s) tested | ||
| - | </ | ||
| - | |||
| - | 1 URL trouvée : http:// | ||
| - | |||
| - | Il y a la liste des icônes accessibles dans '' | ||
| - | |||
| - | 1 ancienne version d' | ||
challenges-anssi-ecsc-web-php-sandbox.1558006100.txt.gz · Last modified: 2019/05/16 13:28 by didzkovitchz
