###### tags: `HTB ACADEMY GETTING STARTED` # GetSimpleCMS ## step1. Information Enumeration  ## step2. Exploit 發現後台,但是經過嘗試之後沒有找到登入帳密,繼續尋找其他突破口  發現當前CMS版本號,先記錄下來待會可以用msfconsole掃看看  msfconsole -> search getsimple 3.3.15  use it! -> show options  設定完RHOST和LHOST跑看看,他這邊不需要設定RPORT  成功進去拿到shell  ## step3. Privilege Escalation ### tool:https://gtfobins.github.io/gtfobins/php/#sudo sudo -l , 發現一個不需要root密碼也能執行的php檔案  嘗試看看能不能透過php來提權 ``` CMD="/bin/sh" sudo php -r "system('$CMD');" ```  成功拿下root shell! 
×
Sign in
Email
Password
Forgot password
or
By clicking below, you agree to our
terms of service
.
Sign in via Facebook
Sign in via Twitter
Sign in via GitHub
Sign in via Dropbox
Sign in with Wallet
Wallet (
)
Connect another wallet
New to HackMD?
Sign up