NullByte
00 min
2024-8-25
Date
Mar 10, 2024 → Mar 17, 2024
Tag
SQLI
Linux
Local privilege escalation
Password Cracking

Scan

Confirm which internal IP
notion image
192.168.56.103
scan this ip, see what port it open and what service running on it.
notion image
scan those port and see what version is the service, what OS system is this PC and try search any we can used script for those service.
notion image
http
80
rpcbind
111
ssh
777

80/http

notion image
try scan this website
notion image
some path contain about phpinfo or others, maybe it is the way.
notion image
we also can access their admin login page.
and we can see what version is for this PHP
notion image
search any vulnerability we can used
notion image
according the result, maybe we can use 35539, although it looks like a DDOS, but the version is most suitable.
after build payload and use it, nothing happened, so chose an other way to try one more time.

After 1 days, i had tied almost every methods in searchsploit, but it doesn’t work, i want to change the target to RPCBIND which is port 111, but i tried search in searchsploit and google, all of them shows me that only included DDOS but i don’t know what is the related between DDOS and get the access.Maybe i need to give up, since i don’t have more knowledge to support me to find out others clue.

Hit 1

After see a hit from redteamnote, i can continue for my journey.
we can see there is a photo in the main website, we can try if any info inside the photo.
wget http://192.168.56.104/main.gif
notion image
after checked, a suspicious info behind of the metadata of the photo.
kzMb5nVYJw
and we can try as password of the phpmyadmin or ssh, but none of them are true one.

Hit 2

Turns out it is a PATH!!!!!!
notion image
Code say the key isn’t difficult, so we can use hydra to have a try.
analyze the request method via burpsuite and struct the command.
Burpsuite
Hydra
sudo hydra 192.168.56.104 http-post-form "/kzMb5nVYJw/index.php:key=^PASS^:invalid key" -P /usr/share/wordlists/rockyou.txt -l null
notion image
POKEMON GETed : elite
use the result see what will happened
notion image
try input something
notion image
only shown success but nothing else, i guess must none of a users are same with my input. so maybe we can BF it again.
notion image
only a sec the answer come out, but diff with my imagined,
input a
notion image
seems like a username search from SQL, maybe we can use SQLI to breakthroughs the situation.

SQLMAP

Oh! won the lottery
but i don’t know what is this, try network power! hash-identify
notion image
OK, Nice one, Base64!
notion image
what next?
notion image
Sure Sure MD5
notion image

omega

here is the password of the username ramses, so what is the platform about this account?
after tried, we can login to the SSH~!
notion image
the most i interested file is
notion image
but after search, none of them i have privilege to edit or run, but i find a file in backup folder.
notion image

Hit 3

I totally don’t know how to raise my privilege,
after see the video, i know, hope next time i can rmb it.
create a link file to link /bin/sh, it will make ps command can make a shell session to me.
notion image
and add the . to $PATH, but i don’t know what is this rig doing.
notion image
and then
notion image
notion image

END

 
上一篇
Target Mechine WriteUP
下一篇
AZ-900