SolarLab|HackTheBox

SolarLab|HackTheBox

nmap:

image-20240514123324430

扫目录:

image-20240514101047759

访问网页

image-20240514125510133

最下面有个contact,没用

image-20240514125522374

Designed by & Developed by Jewel Theme,有个新洞CVE-2024-33595但好像没啥用

image-20240514125834969

查看6791端口,是个登陆界面,应该没注入

image-20240514130931731

看下445端口,存在SMB匿名访问

image-20240514132620765

下载全部文件

image-20240514134050104

脑洞

image-20240514142917297

1
2
username: blakeb
password: ThisCanB3typedeasily1@

搜索ReportLab,找到c53elyas/CVE-2023-33733: CVE-2023-33733 reportlab RCE (github.com)

将Poc中的touch /tmp/exploited改成windows反弹shell命令

image-20240514143203297

image-20240514143221367

image-20240514143239653

flag在../../Desktop/user.txt

netstat -a查看本地其他端口

image-20240514144949894

9090端口有东西

image-20240514145052221