基本信息
- https://www.hackthebox.com/home/machines/profile/416
- 10.10.11.125
data:image/s3,"s3://crabby-images/9a6e1/9a6e1d84dcbd9072107cdbab7ff9604684496347" alt=""
端口扫描
22,80:
1 | nmap -sV -sC 10.10.11.125 |
80
加hosts,wordpress:
1 | 10.10.11.125 backdoor.htb |
data:image/s3,"s3://crabby-images/e8fd2/e8fd2ab173431d056e6d8ca84cac78de4bd0e076" alt=""
wordpress
wpscan没什么东西,手动访问插件目录发现目录遍历,ebook-download 1.1版本:
data:image/s3,"s3://crabby-images/b91c0/b91c009ef89f6bdd7e9c98dda011f2dd6701748c" alt=""
eBook Download
搜到这个插件漏洞:
- WordPress Plugin eBook Download 1.1 - Directory Traversal - PHP webapps Exploit
https://www.exploit-db.com/exploits/39575
data:image/s3,"s3://crabby-images/b027a/b027a2134de8831259e382fa7b6db54d7fe52a86" alt=""
wp-config
1 | define( 'DB_NAME', 'wordpress' ); |
proc
Lfi enum,proc cmdline发现枚举到gdbserver在1337端口:
data:image/s3,"s3://crabby-images/70b16/70b167465461a78b2165f6ae3b10da05eb70f4f0" alt=""
gdbserver & user flag
根据这个:
- Turning arbitrary GDBserver sessions into RCE | Development & Security
http://jbremer.org/turning-arbitrary-gdbserver-sessions-into-rce/
也可以直接msf
data:image/s3,"s3://crabby-images/a8f0b/a8f0bcb8e4603a0ed909a2d484c568037a6999e0" alt=""
user flag
data:image/s3,"s3://crabby-images/32b98/32b9838c03dca0b9359c904ef235ac61790b0c9a" alt=""
提权信息
ps可以看到root screen session:
data:image/s3,"s3://crabby-images/abf12/abf12fa9013b4a58ac798ffdc8806fabbc748da3" alt=""
提权 & root flag
直接attach到root session:
- screen Cheat Sheet - Kapeli
https://kapeli.com/cheat_sheets/screen.docset/Contents/Resources/Documents/index
1 | export TERM=xterm |
data:image/s3,"s3://crabby-images/580ea/580eae978e950a2ea78d99007a501e67e005fb72" alt=""
参考资料
- WordPress Plugin eBook Download 1.1 - Directory Traversal - PHP webapps Exploit
https://www.exploit-db.com/exploits/39575 - mthbernardes/LFI-Enum: Scripts to execute enumeration via LFI
https://github.com/mthbernardes/LFI-Enum - Turning arbitrary GDBserver sessions into RCE | Development & Security
http://jbremer.org/turning-arbitrary-gdbserver-sessions-into-rce/ - screen Cheat Sheet - Kapeli
https://kapeli.com/cheat_sheets/screen.docset/Contents/Resources/Documents/index - HTB Backdoor [Discussion] | RaidForums
https://raidforums.com/Thread-Tutorial-HTB-Backdoor-Discussion