考点:strcmp漏洞、命令注入、切换目录
靶机链接:https://www.vulnhub.com/entry/potato-1,529/
环境配置
名称 | IP |
---|
Kali Linux | 10.0.2.15 |
POTATO 1 | 10.0.2.16 |
初步打点
端口扫描
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
| $ export rip=10.0.2.16
$ $ sudo nmap -v -A -p- $rip
Scanning localhost (10.0.2.16) [65535 ports]
Discovered open port 80/tcp on 10.0.2.16
Discovered open port 22/tcp on 10.0.2.16
Discovered open port 2112/tcp on 10.0.2.16
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.1 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 3072 ef:24:0e:ab:d2:b3:16:b4:4b:2e:27:c0:5f:48:79:8b (RSA)
| 256 f2:d8:35:3f:49:59:85:85:07:e6:a2:0e:65:7a:8c:4b (ECDSA)
|_ 256 0b:23:89:c3:c0:26:d5:64:5e:93:b7:ba:f5:14:7f:3e (ED25519)
80/tcp open http Apache httpd 2.4.41 ((Ubuntu))
|_http-title: Potato company
| http-methods:
|_ Supported Methods: GET HEAD POST OPTIONS
|_http-server-header: Apache/2.4.41 (Ubuntu)
2112/tcp open ftp ProFTPD
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
| -rw-r--r-- 1 ftp ftp 901 Aug 2 2020 index.php.bak
|_-rw-r--r-- 1 ftp ftp 54 Aug 2 2020 welcome.msg
|
WEB测试
查看2112端口,使用Filezilla匿名登录
data:image/s3,"s3://crabby-images/7c3e7/7c3e74393627890e6070f44ec28ea0deb40f7329" alt="1"
下载index.php.bak内容如下
data:image/s3,"s3://crabby-images/04c8d/04c8d8bfbbfef82e5c0e57e834fdc76f4f7e438c" alt="2"
这里php strcmp()存在漏洞,可使用数组绕过,但是这个登录页需要找一下
dirb
1
2
| $ dirb http://10.0.2.16
==> DIRECTORY: http://10.0.2.16/admin/
|
漏洞发现
利用strcmp()漏洞登录
data:image/s3,"s3://crabby-images/13ecc/13ecc5b790fee33948507cd94aa541e1f239b1b5" alt="3"
查看几个菜单寻找可能存在的漏洞
data:image/s3,"s3://crabby-images/d6bcb/d6bcbaa7f0f21a5afbeb26535db50e299ca1531b" alt="4"
拦截报文
data:image/s3,"s3://crabby-images/de7ae/de7aedc15b5b407bba57bd0eee6858a8fcce6761" alt="5"
修改报文
data:image/s3,"s3://crabby-images/dfa7b/dfa7b52bb0a36f45833905614d4dc501527e29b9" alt="6"
读取dashboard.php代码,发现不光存在任意文件读取,还存在命令注入。
获得权限
靶机测试
继续修改报告,插入反弹shell脚本
data:image/s3,"s3://crabby-images/90c7b/90c7b7995f02857e3059bc33e02dc8e6a4064203" alt="7"
收到反弹shell
data:image/s3,"s3://crabby-images/ba3c4/ba3c440467d36f4b62266e6c963843bc76ece73e" alt="8"
提权
passwd
data:image/s3,"s3://crabby-images/1d14b/1d14b686826e0d847413d02d28c2af8ac7543ab4" alt="9"
data:image/s3,"s3://crabby-images/77bf8/77bf896f924a32cf33245eb5d4584870986c2da2" alt="10"
获得webadmin
的密码是dragon
登录后
1
2
3
4
5
6
7
| $ sudo -l
Matching Defaults entries for webadmin on serv:
env_reset, mail_badpass,
secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin
User webadmin may run the following commands on serv:
(ALL : ALL) /bin/nice /notes/*
|
虽然/notes目录不可写入
可以通过..跳出notes目录
data:image/s3,"s3://crabby-images/2fb19/2fb19981d96e1997573bcbd8660f917ccbdf36c8" alt="11"
data:image/s3,"s3://crabby-images/2a95e/2a95eb420d2937ebbc7eb04cd121135078f64aec" alt="12"
最后修改于 2020-08-02