type
status
date
slug
summary
tags
category
icon
password
Catagory
Materials
Retired
Retired
Due date
Jan 16, 2024 05:32 AM
Status
Belong in

Progress

Scanning the services

notion image
notion image

Brute forcing the website directories

notion image
notion image
notion image
notion image
notion image
notion image
notion image
notion image
notion image
notion image
notion image
notion image
notion image

Initial foothold

login as alice

notion image
notion image
目前權限沒有可執行的
目前權限沒有可執行的
sudo -l 找到可使用rabbit權限使用python來執行/home/alice/walrus_and_the_carpenter.py檔案
sudo -l 找到可使用rabbit權限使用python來執行/home/alice/walrus_and_the_carpenter.py檔案
看一下內容有import random function
看一下內容有import random function
python import會先從當前的目錄開始找檔案,可以在當前目錄新增一個random.py檔案
notion image
sudo -u rabbit /usr/bin/python3.6 /home/alice/walrus_and_the_carpenter.py
sudo -u rabbit /usr/bin/python3.6 /home/alice/walrus_and_the_carpenter.py

login as rabbit

notion image
notion image
解析一下teaParty
notion image
notion image
system() function call date function.
system() function call date function.
notion image
notion image

login as hatter

notion image
notion image
notion image
check the capabilities, then we can set uid to 0 for getting root previlege
notion image

login as root

notion image

Reference

  • ghidra
BFS&DFS Searching the outlook folderTryhackme - Blueprint