Proving Grounds Practice : Craft Walkthrough
Proving Grounds Practice : Craft Walkthrough Foothole (立足點 ) : 只有一個 80 Port 且可以上傳 ODT 檔案 建立內涵 Marco 指令執行的 ODT 檔案,使用 Powershell Oneliner 執行拿到 Reverse Shell PE ( 提權 ) : C:\users 發現有 apache 帳號,網站的根目錄有寫入權限 上傳 webshell.php 切換使用者後發現有 SeImpersonatePrivilege 權限 SeImpersonatePrivilege 標準作業提權成功 注意事項 : Kali 使用 libreoffice 建立 Marco 文件檔,ODT 檔案 Powershell Oneliner 永遠是最好的選擇 看到使用者目錄有其他使用者可以先想著切換使用者搞不好就有權限 第一步 Rustscan,└─$ rustscan -a 192.168.205.169 --scripts none --ulimit 5000 | tee rustscan 只有一個 80 Port snmp filtered 沒戲,└─$ sudo nmap -sU -Pn -p 161 192.168.205.169 | tee snmp nmap,└─$ sudo nmap -sCV -A -Pn -p 80 192.168.205.169 | tee nmap 80/tcp open http Apache httpd 2.4.48 ((Win64) OpenSSL/1.1.1k PHP/8.0.7) whatweb,└─$ whatweb http://192.168.205.169 | tee whatweb 既然只有一個 80 Port,那就 nikto 先下去掃掃看,└─$ nikto -h 192.168.205.169 沒甚麼發現 80 / 好熟悉的畫面,這個在 Craft2 靶機有看過 參考 : https://your-it-note.blogspot.com/2024/02/proving-grounds-practice-craft2.html 網頁下方一樣有個履歷檔案上傳的功能 一樣先丟一個 ...