┌──(root㉿kakeru)-[~/tmp] └─# nmap -A 192.168.240.53 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-0220:18 CST Nmap scan report for 192.168.240.53 Host is up (0.0020s latency). Not shown:998 closed tcp ports (reset) PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 7.9p1 Debian 10+deb10u2 (protocol 2.0) | ssh-hostkey: | 204812:f6:55:5f:c6:fa:fb:14:15:ae:4a:2b:38:d8:4a:30 (RSA) | 256 b7:ac:87:6d:c4:f9:e3:9a:d4:6e:e0:4f:da:aa:22:20 (ECDSA) |_ 256 fe:e8:05:af:23:4d:3a:82:2a:64:9b:f7:35:e4:44:4a (ED25519) 80/tcp open http nginx 1.14.2 |_http-server-header: nginx/1.14.2 |_http-title: RELAX MAC Address:56:BD:76:3F:EB:82 (Unknown) Device type: general purpose Running: Linux 4.X|5.X OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 OS details: Linux 4.15-5.19, OpenWrt 21.02 (Linux 5.4) Network Distance:1 hop Service Info:OS: Linux; CPE: cpe:/o:linux:linux_kernel
TRACEROUTE HOP RTT ADDRESS 12.03 ms 192.168.240.53
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done:1 IP address (1 host up) scanned in8.43 seconds
┌──(root㉿kakeru)-[~/tmp] └─# ssh paul@192.168.240.53 The authenticity of host '192.168.240.53 (192.168.240.53)' can't be established. ED25519 key fingerprint is SHA256:y4b6laUdkY6jY95p0UousHuja503C9EIqNNrMD5hoqA. This keyisnot known by any other names. Are you sure you want tocontinue connecting (yes/no/[fingerprint])? yes Warning: Permanently added '192.168.240.53' (ED25519) to the list of known hosts. paul@192.168.240.53's password: Permission denied, please try again. paul@192.168.240.53's password: Linux helium 4.19.0-12-amd64 #1 SMP Debian 4.19.152-1 (2020-10-18) x86_64
The programs included with the Debian GNU/Linux system are free software; the exact distribution terms foreach program are described in the individual files in /usr/share/doc/*/copyright.
Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent permitted by applicable law. Last login: Sun Nov 2214:31:512020from192.168.1.58 paul@helium:~$
提权
有一个sudo权限 可以执行一个程序
1 2 3 4 5 6 7 8
paul@helium:~$ sudo -l MatchingDefaults entries for paul on helium: env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin
User paul may run the following commands on helium: (ALL : ALL) NOPASSWD: /usr/bin/ln paul@helium:~$ file /usr/bin/ln /usr/bin/ln:ELF64-bit LSB pie executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, forGNU/Linux3.2.0, BuildID[sha1]=90900bc68d91aa5931e338d6445b520777431a02, stripped