Not shown: 65533 closed tcp ports (reset) PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.4p1 Debian 5+deb11u3 (protocol 2.0) 80/tcp open http Apache httpd 2.4.62 ((Debian)) MAC Address: 08:00:27:A2:03:15 (PCS Systemtechnik/Oracle VirtualBox virtual NIC) Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
www-data@Plugin:/home/yi$ ls -al total 32 drwxr-xr-x 2 yi yi 4096 Jul 23 21:14 . drwxr-xr-x 3 root root 4096 Jul 23 01:49 .. -rw------- 1 yi yi 29 Jul 23 21:14 .bash_history -rw-r--r-- 1 yi yi 220 Jul 23 01:49 .bash_logout -rw-r--r-- 1 yi yi 3526 Jul 23 01:49 .bashrc -rw-r--r-- 1 yi yi 807 Jul 23 01:49 .profile -rw-r--r-- 1 root root 44 Jul 23 01:49 user.txt -rw-r--r-- 1 root root 2286 Jul 23 02:09 yiyi.sh www-data@Plugin:/home/yi$ cat user.txt flag{root-058e8f474511327e5aeed4efa793033a}
3 Root
在 /home/yi 目录下,还发现了给yiyi.sh 但是运行不了,估计是得换到yi才能用
于是继续看看,发现Wordpress也有一个yi用户
看着非常像ssh密码,连下试试
1 2
yi@Plugin:~$ whoami yi
也是成功连上了,然后再看看sudo -l
1 2 3 4 5 6 7 8 9 10
yi@Plugin:~$ ls -al total 32 drwxr-xr-x 2 yi yi 4096 Jul 23 21:14 . drwxr-xr-x 3 root root 4096 Jul 23 01:49 .. -rw------- 1 yi yi 29 Jul 23 21:14 .bash_history -rw-r--r-- 1 yi yi 220 Jul 23 01:49 .bash_logout -rw-r--r-- 1 yi yi 3526 Jul 23 01:49 .bashrc -rw-r--r-- 1 yi yi 807 Jul 23 01:49 .profile -rw-r--r-- 1 root root 44 Jul 23 01:49 user.txt -rw-r--r-- 1 root root 2286 Jul 23 02:09 yiyi.sh
1 2 3 4 5 6
yi@Plugin:~$ sudo -l Matching Defaults entries for yi on Plugin: env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin User yi may run the following commands on Plugin: (ALL) NOPASSWD: /bin/bash /home/yi/yiyi.sh