Bookworm

10.10.11.215

scan

1
2
3
4
5
6
7
8
9
10
PORT   STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.7 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 3072 81:1d:22:35:dd:21:15:64:4a:1f:dc:5c:9c:66:e5:e2 (RSA)
| 256 01:f9:0d:3c:22:1d:94:83:06:a4:96:7a:01:1c:9e:a1 (ECDSA)
|_ 256 64:7d:17:17:91:79:f6:d7:c4:87:74:f8:a2:16:f7:cf (ED25519)
80/tcp open http nginx 1.18.0 (Ubuntu)
|_http-server-header: nginx/1.18.0 (Ubuntu)
|_http-title: Did not follow redirect to http://bookworm.htb
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

echo "10.10.11.215 bookworm.htb" >> /etc/hosts

http://bookworm.htb/

web-enumeration

./gobuster.sh 148 ⨯ 3 ⚙
which url? http://bookworm.htb/
===============================================================
Gobuster v3.5
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url: http://bookworm.htb/
[+] Method: GET
[+] Threads: 10
[+] Wordlist: /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
[+] Negative Status codes: 404
[+] User Agent: gobuster/3.5
[+] Expanded: true
[+] Timeout: 10s
===============================================================
2023/06/16 23:27:45 Starting gobuster in directory enumeration mode
===============================================================
http://bookworm.htb/login (Status: 200) [Size: 2040]
http://bookworm.htb/register (Status: 200) [Size: 3093]
http://bookworm.htb/profile (Status: 302) [Size: 28] [–> /login]
http://bookworm.htb/shop (Status: 200) [Size: 10778]
http://bookworm.htb/static (Status: 301) [Size: 179] [–> /static/]
http://bookworm.htb/Login (Status: 200) [Size: 2034]
http://bookworm.htb/logout (Status: 302) [Size: 23] [–> /]
http://bookworm.htb/basket (Status: 302) [Size: 28] [–> /login]

register a new account
qwfqwf / qwfqwf

http://bookworm.htb/profile
update avatar has a function to upload picture
file path: http://bookworm.htb/static/img/uploads/14

may be we could try upload a webshell.

getshell

escalation

conclusion

reference