Lame Walkthrough
仅供安全学习,环境均为本地虚拟机或 CTF 靶场。请勿用于未授权目标。
介绍
- HTB
- 难度:Easy
- OS: Linux
- writeup:已解锁
Lame is an easy Linux machine, requiring only one exploit to obtain root access.1
分析
侦察
nmap -A htb
- FTP: 21/TCP, vsftpd 2.3.4
- SSH: 22/TCP, OpenSSH 4.7p1
- OS: Linux
- SMB: 445/TCP, Samba smbd 3.0.20-Debian
注意到 vsftpd 2.3.4 存在后门:
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.2
Samba 3.0.20 存在 RCE 漏洞:
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands via shell metacharacters involving the (1) SamrChangePassword function, when the “username map script” smb.conf option is enabled, and allows remote authenticated users to execute commands via shell metacharacters involving other MS-RPC functions in the (2) remote printer and (3) file share management.3
User Flag
msfconsole -q发现 vsftpd 的后门没法利用,试试 Samba 的 RCE:
search samba 3.0.20
python -c "import pty; pty.spawn('/bin/bash')"注意到 user flag:

Root Flag
root flag:

后记
虽然成功得到了两个 flag,但是最开始的 vsftpd 利用失败了。
netstat -ntpl注意到有很多端口监听 0.0.0.0,但是外部只扫描到 4 个端口:

推测有防火墙,验证:

因此即便触发后门,6200 端口也无法连接。

