Starting Nmap 7.60 ( https://nmap.org ) at 2024-01-28 08:35 GMT Nmap scan report for ip-10-10-47-106.eu-west-1.compute.internal (10.10.47.106) Host is up (0.028s latency). Not shown: 998 closed ports PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 2048 8e:ee:fb:96:ce:ad:70:dd:05:a9:3b:0d:b0:71:b8:63 (RSA) | 256 7a:92:79:44:16:4f:20:43:50:a9:a8:47:e2:c2:be:84 (ECDSA) |_ 256 00:0b:80:44:e6:3d:4b:69:47:92:2c:55:14:7e:2a:c9 (EdDSA) 80/tcp open http Golang net/http server (Go-IPFS json-rpc or InfluxDB API) |_http-title: Follow the white rabbit. MAC Address: 02:EA:67:5B:75:21 (Unknown) Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 13.45 seconds
drwxr-x--- 2 rabbit rabbit 4096 May 25 2020 . drwxr-xr-x 6 root root 4096 May 25 2020 .. lrwxrwxrwx 1 root root 9 May 25 2020 .bash_history -> /dev/null -rw-r--r-- 1 rabbit rabbit 220 May 25 2020 .bash_logout -rw-r--r-- 1 rabbit rabbit 3771 May 25 2020 .bashrc -rw-r--r-- 1 rabbit rabbit 807 May 25 2020 .profile -rwsr-sr-x 1 root root 16816 May 25 2020 teaParty
这个elf文件是有suid权限的
teaParty,晚上来逆一下
voidmain(void)
{ setuid(0x3eb); setgid(0x3eb); puts("Welcome to the tea party!\nThe Mad Hatter will be here soon."); system("/bin/echo -n \'Probably by \' && date --date=\'next hour\' -R"); puts("Ask very nicely, and I will give you some tea while you wait for him"); getchar(); puts("Segmentation fault (core dumped)"); return; }