❯ nmap -A 10.10.11.53 Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-17 17:19 CST Nmap scan report for 10.10.11.53 Host is up (0.31s latency). Not shown: 998 closed tcp ports (reset) PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.11 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 3072 96:2d:f5:c6:f6:9f:59:60:e5:65:85:ab:49:e4:76:14 (RSA) | 256 9e:c4:a4:40:e9:da:cc:62:d1:d6:5a:2f:9e:7b:d4:aa (ECDSA) |_ 256 6e:22:2a:6a:6d:eb:de:19:b7:16:97:c2:7e:89:29:d5 (ED25519) 80/tcp open http Apache httpd 2.4.41 ((Ubuntu)) |_http-server-header: Apache/2.4.41 (Ubuntu) |_http-title: Did not follow redirect to http://cat.htb/ Device type: general purpose Running: Linux 4.X|5.X OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 OS details: Linux 4.15 - 5.19 Network Distance: 2 hops Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
TRACEROUTE (using port 3389/tcp) HOP RTT ADDRESS 1 141.25 ms 10.10.16.1 2 141.44 ms 10.10.11.53
rosa@cat:~$ cat /etc/passwd | grep sh root:x:0:0:root:/root:/bin/bash fwupd-refresh:x:111:116:fwupd-refresh user,,,:/run/systemd:/usr/sbin/nologin sshd:x:113:65534::/run/sshd:/usr/sbin/nologin axel:x:1000:1000:axel:/home/axel:/bin/bash rosa:x:1001:1001:,,,:/home/rosa:/bin/bash git:x:114:119:Git Version Control,,,:/home/git:/bin/bash jobert:x:1002:1002:,,,:/home/jobert:/bin/bash
rosa@cat:~$ groups rosa adm rosa@cat:~$ groups axel axel : axel rosa@cat:~$ groups jobert jobert : jobert mail www-data
1 2
rosa@cat:~$ id uid=1001(rosa) gid=1001(rosa) groups=1001(rosa),4(adm)
1 2 3 4 5 6 7
╔══════════╣ Mails (limit 50) 3839 4 -rw-rw---- 1 axel mail 1961 Jan 14 16:49 /var/mail/axel 3872 0 -rw-rw---- 1 jobert mail 0 Jan 14 16:54 /var/mail/jobert 29987 36 -rw------- 1 root mail 32535 Feb 17 11:59 /var/mail/root 3839 4 -rw-rw---- 1 axel mail 1961 Jan 14 16:49 /var/spool/mail/axel 3872 0 -rw-rw---- 1 jobert mail 0 Jan 14 16:54 /var/spool/mail/jobert 29987 36 -rw------- 1 root mail 32535 Feb 17 11:59 /var/spool/mail/root
axel@cat:/var/mail$ cat * From rosa@cat.htb Sat Sep 28 04:51:50 2024 Return-Path: <rosa@cat.htb> Received: from cat.htb (localhost [127.0.0.1]) by cat.htb (8.15.2/8.15.2/Debian-18) with ESMTP id 48S4pnXk001592 for <axel@cat.htb>; Sat, 28 Sep 2024 04:51:50 GMT Received: (from rosa@localhost) by cat.htb (8.15.2/8.15.2/Submit) id 48S4pnlT001591 for axel@localhost; Sat, 28 Sep 2024 04:51:49 GMT Date: Sat, 28 Sep 2024 04:51:49 GMT From: rosa@cat.htb Message-Id: <202409280451.48S4pnlT001591@cat.htb> Subject: New cat services
Hi Axel,
We are planning to launch new cat-related web services, including a cat care website and other projects. Please send an email to jobert@localhost with information about your Gitea repository. Jobert will check if it is a promising service that we can develop.
Important note: Be sure to include a clear description of the idea so that I can understand it properly. I will review the whole repository.
From rosa@cat.htb Sat Sep 28 05:05:28 2024 Return-Path: <rosa@cat.htb> Received: from cat.htb (localhost [127.0.0.1]) by cat.htb (8.15.2/8.15.2/Debian-18) with ESMTP id 48S55SRY002268 for <axel@cat.htb>; Sat, 28 Sep 2024 05:05:28 GMT Received: (from rosa@localhost) by cat.htb (8.15.2/8.15.2/Submit) id 48S55Sm0002267 for axel@localhost; Sat, 28 Sep 2024 05:05:28 GMT Date: Sat, 28 Sep 2024 05:05:28 GMT From: rosa@cat.htb Message-Id: <202409280505.48S55Sm0002267@cat.htb> Subject: Employee management
We are currently developing an employee management system. Each sector administrator will be assigned a specific role, while each employee will be able to consult their assigned tasks. The project is still under development and is hosted in our private Gitea. You can visit the repository at: http://localhost:3000/administrator/Employee-management/. In addition, you can consult the README file, highlighting updates and other important details, at: http://localhost:3000/administrator/Employee-management/raw/branch/main/README.md.
说人话是后面的admin会检测你的项目,然后你利用xss欺骗点击页面即可~
记得要发邮件给它,才会知道点击哪个仓库
1 2
echo -e "Subject: Re: New cat services & Employee management\nHi Rosa,\n\nThanks for the info. I’ll send Jobert the details of my Gitea repository shortly.\n\nRegarding the employee management system, you can check out the repository here: http://localhost:3000/axel/hello and review the README.\n\nBest, Axel" | sendmail jobert@cat.htb