PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 7.4p1 Debian 10+deb9u6 (protocol 2.0) | ssh-hostkey: | 20483e:52:ce:ce:01:b6:94:eb:7b:03:7d:be:08:7f:5f:fd (RSA) | 2563c:83:65:71:dd:73:d7:23:f8:83:0d:e3:46:bc:b5:6f (ECDSA) |_ 25641:89:9e:85:ae:30:5b:e0:8f:a4:68:71:06:b4:15:ee (ED25519) 80/tcp open http Apache httpd 2.4.25 ((Debian)) |_http-title: Wordy – Just another WordPress site |_http-generator: WordPress 5.1.1 |_http-server-header: Apache/2.4.25 (Debian) MAC Address:08:00:27:AA:DF:23 (Oracle VirtualBox virtual NIC) Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port Device type: general purpose Running: Linux 3.X|4.X OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:4 OS details: Linux 3.2-4.14 Network Distance:1 hop Service Info:OS: Linux; CPE: cpe:/o:linux:linux_kernel
- Restore full functionality for the hyperdrive (need to speak to Jens) - Buy present for Sarah's farewell party - Add new user: graham - GSo7isUM1D4 - done - Apply for the OSCP course - Buy new laptop for Sarah's replacement
得到另一组凭据
1
graham:GSo7isUM1D4
ssh登录
backups.sh横向
在/home/jens发现备份脚本backups.sh,且graham用户sudo权限为
1
(jens) NOPASSWD: /home/jens/backups.sh
用户 graham 可以在不输入密码的情况下,以用户 jens 的身份执行 /home/jens/backups.sh 这个脚本
Hope you enjoyed DC-6. Just wanted to send a big thanks out there to all those who have provided feedback, and who have taken time to complete these little challenges.
If you enjoyed this CTF, send me a tweet via @DCAU7.