UnderPass
信息
Difficulty: Easy
Operating System: Linux
ENTRY POINT
10.10.11.48
信息搜集
┌──(randark ㉿ kali)-[~]
└─$ sudo ./tools/fscan-1.8.4/fscan -h 10.10.11.48
start infoscan
10.10.11.48:22 open
10.10.11.48:80 open
[*] alive ports len is: 2
start vulscan
[*] WebTitle http://10.10.11.48 code:200 len:10671 title:Apache2 Ubuntu Default Page: It works
┌──(randark ㉿ kali)-[~]
└─$ sudo nmap -v --min-rate=5000 -A -p- 10.10.11.48
Nmap scan report for bogon (10.10.11.48)
Host is up (0.12s latency).
Not shown: 65533 closed tcp ports (reset)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.10 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 256 48:b0:d2:c7:29:26:ae:3d:fb:b7:6b:0f:f5:4d:2a:ea (ECDSA)
|_ 256 cb:61:64:b8:1b:1b:b5:ba:b8:45:86:c5:16:bb:e2:a2 (ED25519)
80/tcp open http Apache httpd 2.4.52 ((Ubuntu))
|_http-server-header: Apache/2.4.52 (Ubuntu)
| http-methods:
|_ Supported Methods: OPTIONS HEAD GET POST
|_http-title: Apache2 Ubuntu Default Page: It works
Device type: general purpose
Running: Linux 4.X|5.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5
OS details: Linux 4.15 - 5.19
Uptime guess: 41.015 days (since Sat Feb 22 21:51:42 2025)
Network Distance: 2 hops
TCP Sequence Prediction: Difficulty=259 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
┌──(randark ㉿ kali)-[~]
└─$ sudo nmap -v -A -sU --top-ports=50 10.10.11.48
Nmap scan report for bogon (10.10.11.48)
Host is up (0.16s latency).
PORT STATE SERVICE VERSION
7/udp closed echo
53/udp closed domain
67/udp closed dhcps
68/udp closed dhcpc
69/udp closed tftp
80/udp closed http
111/udp closed rpcbind
123/udp closed ntp
135/udp closed msrpc
136/udp closed profile
137/udp closed netbios-ns
138/udp closed netbios-dgm
139/udp closed netbios-ssn
161/udp open snmp SNMPv1 server; net-snmp SNMPv3 server (public)
| snmp-info:
| enterprise: net-snmp
| engineIDFormat: unknown
| engineIDData: c7ad5c4856d1cf6600000000
| snmpEngineBoots: 31
|_ snmpEngineTime: 6m35s
| snmp-sysdescr: Linux underpass 5.15.0-126-generic #136-Ubuntu SMP Wed Nov 6 10:38:22 UTC 2024 x86_64
|_ System uptime: 6m35.53s (39553 timeticks)
162/udp closed snmptrap
445/udp closed microsoft-ds
500/udp closed isakmp
514/udp closed syslog
518/udp closed ntalk
520/udp closed route
593/udp closed http-rpc-epmap
626/udp closed serialnumberd
631/udp closed ipp
996/udp closed vsinet
997/udp closed maitrd
998/udp closed puparp
999/udp closed applix
1025/udp closed blackjack
1026/udp closed win-rpc
1027/udp closed unknown
1433/udp closed ms-sql-s
1434/udp closed ms-sql-m
1645/udp closed radius
1646/udp closed radacct
1701/udp closed L2TP
1812/udp open|filtered radius
1900/udp closed upnp
2048/udp closed dls-monitor
2049/udp closed nfs
2222/udp closed msantipiracy
3283/udp closed netassistant
3456/udp closed IISrpc-or-vat
4500/udp closed nat-t-ike
5060/udp closed sip
5353/udp closed zeroconf
20031/udp closed bakbonenetvault
32768/udp closed omad
49152/udp closed unknown
49153/udp closed unknown
49154/udp closed unknown
Too many fingerprints match this host to give specific OS details
Network Distance: 2 hops
Service Info: Host: UnDerPass.htb is the only daloradius server in the basin!
通过扫描发现,端口 80 只是开放了一个 Ubuntu 的默认 Apache2 服务,没有可利用性
通过 UDP 扫描,发现可能存在有 SNMP 服务的端口,以及一个主机名
尝试添加 hosts 记录,通过 vhost 访问 http 服务,没有新发现