Mostrando entradas con la etiqueta services. Mostrar todas las entradas
Mostrando entradas con la etiqueta services. Mostrar todas las entradas

domingo, 24 de octubre de 2021

Zeno TryHackMe Writeup

logo

Scanning

We run nmap on all ports with scripts and software versions.

Enumeration

We access the high web port and find an inactive resource.

Launch "dirsearch" and list the directory "rms".

Accessing the directory, we find a website with "Restaurant Management System" displayed.

Control panel

We listed the control panel, but it is out of service.

We create a user and see that it is vulnerable to SQL Injection (Time-Based).

We use the "sqlmap" tool, we manage to enumerate the databases and obtain some credentials, but it does not help us to connect via SSH.

Databases name

Members table

Columns name

Users

Exploitation

We reviewed exploits and found this one for Remote Code Execution (RCE).

Exploit: https://www.exploit-db.com/exploits/47520

The exploit has some faulty lines, we fix the exploit, run it and we have a command shell via PHP.

PoC

We put a Netcat listening and run a reverse shell and gain access to the system.

Reverse shell

We read the "config.php" file of the CMS, but the password is not valid for the user "edward".

We do a quick reconnaissance with the "lse" script, we find two interesting things:

  • A credentials.
  • A service file that we have write permissions.

We use the password on the user "edward" and read the user flag.

Privilege Escalation

We check if we can run any script or binary with SUDO, we see that we can restart the system.

We remember that previously we found a service file that we can modify, we have already done this procedure in other machines, so we modify the file and restart the machine, so we will force the new loading of the service file.

We create a service file with the following content:

[Unit]
Description=root

[Service]
Type=simple
User=root
ExecStart=/bin/bash -c 'echo "edward ALL= (root) NOPASSWD: /usr/bin/sudo " >>/etc/sudoers'

[Install]
WantedBy=multi-user.target

When the machine restarts, it will grant us to use sudo as root, so we can run a bash, become root and read the flag.


About

David Utón is Penetration Tester and security auditor for web and mobiles applications, perimeter networks, internal and industrial corporate infrastructures, and wireless networks.

Contacted on:

David-Uton @David_Uton

viernes, 22 de octubre de 2021

IDE TryHackMe Writeup

logo

Scanning

We run nmap on all ports with scripts and software versions.

Enumeration

We access to website, found Apache default page on server

In addition, we have another website on port 62337 with Codiad 2.8.4 software.

There are exploits for this version, these that we have highlighted require credentials.

Nmap showed us an FTP service with "anonymous" user access. We set up the service with CurlFtpFS and found a text file with two users and the use of a default password.

Exploitation

Knowing the possible users, we could launch a small brute force attack with a basic password dictionary. I manually tested with 5 or 6 classic passwords and one of them worked.

I used this exploit:

Exploit: https://www.exploit-db.com/raw/49705

We receive the connection and have access to the machine.

We see that we do not have visibility to the file "user.txt" being "www-data", but we can read the file ".bash_history", here it is evident a connection with the database and the credentials in plane.

We test if the user reuses passwords, we see that he does and we read the user flag.

Also, we see that we can restart the "vsftpd" service with any user.

Privilege Escalation

We use the tool "linpeas.sh" and it lists a .service file. This reminds me that it is possible to modify or create a .service file where to insert malicious code to be executed when the vsftpd service is restarted.

Let's go! We modify the file and insert our malicious code and save. Now, we will put a netcat on the listener and restart the service on the victim machine.

We will receive a connection in our kali as the root user and read the flag in the file "root.txt".


About

David Utón is Penetration Tester and security auditor for web and mobiles applications, perimeter networks, internal and industrial corporate infrastructures, and wireless networks.

Contacted on:

David-Uton @David_Uton