??一、Kali簡介&下載
Kali linux是基于Debian的Linux的發(fā)行版,高級(jí)滲透測試及安全審核的工具。
?
kali linux:
1、包含600+滲透測試工具
2、完全免費(fèi)
3、多語言
Kali linux鏡像下載地址:
http://old.kali.org/kali-images/
?? 二、VMware安裝Kali
?? 2.1 新建虛擬機(jī)
選擇稍后安裝操作系統(tǒng),?下一步
選擇Linux, Debian 10.X 64位,?下一步
重命名虛擬機(jī)名稱為Kali,?下一步
處理器配置,根據(jù)個(gè)人需求,?下一步
???下一步,創(chuàng)建新磁盤
將虛擬磁盤存儲(chǔ)為單個(gè)文件,?下一步
??下一步,完成創(chuàng)建
?下一步,編輯虛擬機(jī)設(shè)置
?下一步,選擇Kali鏡像文件
?? 2.2 開始安裝Kali
??continue,至如下頁面
??網(wǎng)絡(luò)主機(jī)名
??配置用戶&密碼
??磁盤分區(qū)
??軟件選擇
??漫長的安裝
?? 2.3 更換apt源為國內(nèi)源
┌──(root?kali)-[/home/seal/Desktop]
└─# vi /etc/apt/sources.list
*********************源地址*****************************
#aliyun 阿里云
deb http://mirrors.aliyun.com/kali kali-rolling main non-free contrib
deb-src http://mirrors.aliyun.com/kali kali-rolling main non-free contrib
#ustc 中科大
deb http://mirrors.ustc.edu.cn/kali kali-rolling main non-free contrib
deb-src http://mirrors.ustc.edu.cn/kali kali-rolling main non-free contrib
#deb http://mirrors.ustc.edu.cn/kali-security kali-current/updates main contrib non-free
#deb-src http://mirrors.ustc.edu.cn/kali-security kali-current/updates main contrib non-free
#kali 官方源
deb http://http.kali.org/kali kali-rolling main non-free contrib
deb-src http://http.kali.org/kali kali-rolling main non-free contrib
#deb http://security.kali.org/kali-security kali-rolling/updates main contrib non-free
#deb-src http://security.kali.org/kali-security kali-rolling/updates main contrib non-free
更新軟件列表
┌──(root?kali)-[/home/seal/Desktop]
└─# apt-get update
?? 2.4 啟動(dòng)mysql-這里使用自帶的maridb
┌──(root?kali)-[/home/seal/Desktop]
└─# systemctl start mariadb
┌──(root?kali)-[/home/seal/Desktop]
└─# systemctl status mariadb
###開機(jī)自啟####
┌──(root?kali)-[/home/seal/Desktop]
└─# systemctl enable mariadb
?? 2.5 安裝web服務(wù)器-apache2 & 啟動(dòng)
┌──(root?kali)-[/home/seal/Desktop]
└─# apt install apache2 -y
┌──(root?kali)-[/home/seal/Desktop]
└─# service apache2 status
###開機(jī)自啟####
┌──(root?kali)-[/home/seal/Desktop]
└─# systemctl enable apache2
┌──(root?kali)-[/home/seal/Desktop]
└─# service apache2 restart
?? 2.6 LAMP安裝DVWA漏洞靶場
DVWA(Damn Vulnerable Web App)是用PHP+MySQL編寫的一個(gè)用于常規(guī)Web漏洞教學(xué)的測試網(wǎng)站,包含了SQL注入、命令執(zhí)行、文件上傳等常見的一些安全漏洞。
?? 2.6.1 DVWA上傳解壓
DVWA下載地址:
鏈接:https://pan.baidu.com/s/1QT2HXBCMKUxkDpO0sLnf2w
提取碼:dvwa
┌──(root?kali)-[/home/seal/Desktop]
└─# unzip DVWA-master.zip
移動(dòng)DVWA-master 至 /var/www/html/dvwa
┌──(root?kali)-[/home/seal/Desktop]
└─# mv DVWA-master /var/www/html/dvwa
┌──(root?kali)-[/home/seal/Desktop]
└─# cd /var/www/html/dvwa
?? 2.6.2 重命名config.inc.php.dist為config.inc.php
┌──(root?kali)-[/var/www/html/dvwa]
└─# cd config
┌──(root?kali)-[/var/www/html/dvwa/config]
└─# ll
total 4
-rw-r--r-- 1 root root 1857 Sep 1 2020 config.inc.php.dist
┌──(root?kali)-[/var/www/html/dvwa/config]
└─# mv config.inc.php.dist config.inc.php
┌──(root?kali)-[/var/www/html/dvwa/config]
└─#
訪問靶場:http://localhost/dvwa/setup.php
?? 2.6.3 根據(jù)紅色報(bào)錯(cuò)做相應(yīng)配置
PHP function display_errors: Disabled
PHP function display_startup_errors: Disabled
┌──(root?kali)-[/etc/php]
└─# vi /etc/php/8.2/apache2/php.ini
PHP module gd: Missing - Only an issue if you want to play with captchas
┌──(root?kali)-[/etc/php]
└─# apt install php-gd
修改配置和安裝 php-gd之后,重啟apache2
t?kali)-[/etc/php]
└─# service apache2 restart
reCAPTCHA key: Missing
public:
6LdJJlUUAAAAAH1Q6cTpZRQ2Ah8VpyzhnffD0mBb
private:
6LdJJlUUAAAAAM2a3HrgzLczqdYp4g05EqDs-W4K
更改mysql配置信息,創(chuàng)建dvwa用戶和密碼,授權(quán)
MariaDB [(none)]> create user'dvwa'@'localhost'identified by 'dvwa';
Query OK, 0 rows affected (0.014 sec)
MariaDB [(none)]> grant all privileges on *.* to 'dvwa'@'%' identified by 'dvwa';
Query OK, 0 rows affected (0.001 sec)
MariaDB [(none)]> flush privileges;
Query OK, 0 rows affected (0.001 sec)
MariaDB [(none)]>
編輯config.inc.php 配置
┌──(root?kali)-[/var/www/html/dvwa/config]
└─# vi /var/www/html/dvwa/config/config.inc.php
uploads 文件夾 & config 文件夾賦權(quán)——chmod 777
[User: root] Writable folder /var/www/html/dvwa/hackable/uploads/: No
┌──(root?kali)-[/var/www/html/dvwa]
└─# cd hackable
┌──(root?kali)-[/var/www/html/dvwa/hackable]
└─# ll
total 12
drwxr-xr-x 2 root root 4096 Sep 1 2020 flags
drwxr-xr-x 2 root root 4096 Sep 1 2020 uploads
drwxr-xr-x 2 root root 4096 Sep 1 2020 users
┌──(root?kali)-[/var/www/html/dvwa/hackable]
└─# chmod 777 uploads
┌──(root?kali)-[/var/www/html/dvwa/hackable]
└─#
[User: root] Writable folder /var/www/html/dvwa/config: No
┌──(root?kali)-[/var/www/html/dvwa]
└─# chmod 777 config
┌──(root?kali)-[/var/www/html/dvwa]
└─#
?? 2.6.4 重啟apache2 和mysql
┌──(root?kali)-[/var/www/html/dvwa/config]
└─# service apache2 restart
┌──(root?kali)-[/var/www/html/dvwa/config]
└─# systemctl restart mariadb
┌──(root?kali)-[/var/www/html/dvwa/config]
└─#
?? 2.6.5 創(chuàng)建數(shù)據(jù)庫
DVWA默認(rèn)登陸的用戶名:admin ,默認(rèn)密碼:password文章來源:http://www.zghlxwxcb.cn/news/detail-656182.html
文章來源地址http://www.zghlxwxcb.cn/news/detail-656182.html
到了這里,關(guān)于網(wǎng)絡(luò)安全-01-VMware安裝Kali&部署DVWA的文章就介紹完了。如果您還想了解更多內(nèi)容,請(qǐng)?jiān)谟疑辖撬阉鱐OY模板網(wǎng)以前的文章或繼續(xù)瀏覽下面的相關(guān)文章,希望大家以后多多支持TOY模板網(wǎng)!