HTB BoardLight
BoardLight (Linux · Easy)
CVE-2023-30253 + CVE-2022-37706
枚举
nmap
1 | nmap -A -Pn -v -T4 10.10.11.11 |
添加hosts
1 | echo "10.10.11.11 board.htb" | sudo tee -a /etc/hosts |
gobuster
1 | gobuster vhost -u http://board.htb --append-domain -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt |
添加hosts
1 | echo "10.10.11.11 crm.board.htb" | sudo tee -a /etc/hosts |
dirsearch
1 | dirsearch -u http://board.htb |
board.htb
crm.board.htb
弱口令
1 | admin:admin |
google search
利用 CVE-2023-30253 反弹shell
1 | cat /var/www/html/crm.board.htb/htdocs/conf/conf.php |
1 | dolibarr_main_db_user='dolibarrowner'; |
数据库里基本都是关于网站的信息,猜测密码重用,查下有bash权限的用户,连ssh
权限提升
enlightenment,查看下版本
google search
scp 传过去
1 | scp exploit.sh larissa@board.htb:/tmp |
赋权执行