基本信息
端口扫描
21,22,80几个端口:
data:image/s3,"s3://crabby-images/dc67f/dc67f0412d7edd36ce90980fd22bda4fbeff4195" alt=""
80
根据扫描结果,robots.txt中得到admin-dir目录,直接访问是403:
data:image/s3,"s3://crabby-images/3768f/3768f5f2ed4ec541ddb5475b95d2bff48b4c38b5" alt=""
扫描目录,这里字典很重要,因为包含敏感信息的credentials.txt,一般字典里没有:
data:image/s3,"s3://crabby-images/d4da9/d4da9a5960e3641b579d9a3bd88cce9a40700c4c" alt=""
credentials.txt
1 | [Internal mail account] |
FTP
使用得到的ftp账号密码登录,发现两个文件:
data:image/s3,"s3://crabby-images/ea122/ea122d2cfe7aae90c7a750b0d099c3cddf3d34d4" alt=""
index.php
下载源码解压,index.php中得到数据库信息,但是数据库没有对外开放端口:
1 | $servername = "localhost"; |
utility-scripts/admin-task.php
根据输入的task id执行脚本:
1 | <?php |
utility-scripts/db-admin.php
也是数据库信息:
1 |
|
里面包含一句提示信息,直接尝试访问 http://10.10.10.187/utility-scripts/db_admin.php 是404,说明作者找到了更好的开源方案,这里需要根据靶机名Admirer想到adminer(以前叫做phpMyAdmin)
adminer.php
data:image/s3,"s3://crabby-images/2c95d/2c95d2ac935e7e4879e4f555c3740af13b6341fb" alt=""
但使用前面得到的那些账号密码无法登录,继续查找信息,注意版本,Adminer 4.6.2, 找到相关漏洞:
- Serious Vulnerability Discovered in Adminer database Administration Tool
https://www.foregenix.com/blog/serious-vulnerability-discovered-in-adminer-tool
mysql client 文件读取
其实就是load data lcoal infidel,我们自己做一个server,让客户端连接,读取客户端的任意文件,直接用bettercap就可以做,因为前面知道index.php中存在密码,就直接读取index.php:
1 | sudo bettercap -iface utun2 -eval "set mysql.server.infile ../index.php; mysql.server on" |
data:image/s3,"s3://crabby-images/10816/10816dcb1ec383262da0af789d029f10f13e2156" alt=""
1 | $servername = "localhost"; |
user flag
这个账号密码可以ssh登录,得到user.txt:
data:image/s3,"s3://crabby-images/bde7e/bde7e1a95d0b32628586a0516eaa4f07be156fe4" alt=""
提权信息
sudo -l发现:
data:image/s3,"s3://crabby-images/0ef9b/0ef9b838642951dd957cafccc539c2b93912e221" alt=""
(ALL) SETENV: /opt/scripts/admin_tasks.sh
admin_task.sh中
1 | backup_web() |
这个函数调用了同目录下的backup.py文件,这个文件使用shutil中的make_archive函数,注意前面我们有SETENV权限,可以考虑做一个恶意函数,并且修改环境变量,这里Python使用的是PYTHONPATH:
data:image/s3,"s3://crabby-images/bf2ff/bf2ffd7d1ba7d8505be3b073c3b4b6d1b5b53c05" alt=""
提权
设置环境变量,运行,触发恶意函数:
data:image/s3,"s3://crabby-images/4c7d6/4c7d6a11e8073de93cc407ee2305910b3d1f0d9f" alt=""
root flag
反弹shell,得到root.txt:
data:image/s3,"s3://crabby-images/9e02e/9e02e06e24f26a46f062b938bc1a98ce3426205b" alt=""
参考资料
- Serious Vulnerability Discovered in Adminer database Administration Tool
https://www.foregenix.com/blog/serious-vulnerability-discovered-in-adminer-tool - https://www.bettercap.org/modules/ethernet/servers/mysql.server/
- Privilege Escalation via Python Library Hijacking | rastating.github.io
https://rastating.github.io/privilege-escalation-via-python-library-hijacking/ - Hack The Box : Admirer - Atsika
https://atsika.info/htb-admirer/