CyberSploit:2 - Walkthrough [Vulnhub]
Here's my solution for CyberSploit:2.
Nmap
Starting with nmap scanning for all TCP open ports.
nmap -sC -sV -p- 192.168.1.103
data:image/s3,"s3://crabby-images/a6708/a6708642df3e7ee7c76881da3e07dc606703e1bb" alt=""
data:image/s3,"s3://crabby-images/fdd2a/fdd2a25bcb92a08472b38fe02a6c790e19244d2c" alt=""
data:image/s3,"s3://crabby-images/34a1b/34a1b60817bba4aff74177e16944fd07827b7973" alt=""
While browsing the website, we see a strange username- D92:=6?5C2 and its associated
From the hint we can guess that the username and password can be ROT47 encoded.
Browsed Decode.fr to decode it, and we get the credentials as-
username: shailendra
password: cybersploit1
data:image/s3,"s3://crabby-images/3551e/3551e7922501d02544ddae613d4dfecdd3670ab4" alt=""
data:image/s3,"s3://crabby-images/543ff/543ff02b16dba1feddc8750e9d54271ab1dec1f4" alt=""
Privilege Escalation
docker run -v /:/mnt --rm -it alpine chroot /mnt sh
data:image/s3,"s3://crabby-images/697b7/697b70af128568b9c4395d87f3d33b2116acd578" alt=""
And we get the flag
data:image/s3,"s3://crabby-images/60aac/60aac5537918967178e238aa52cd573e1a63c365" alt=""
The Machine can be downloaded from here
Nmap
Starting with nmap scanning for all TCP open ports.
nmap -sC -sV -p- 192.168.1.103
data:image/s3,"s3://crabby-images/a6708/a6708642df3e7ee7c76881da3e07dc606703e1bb" alt=""
We find only 2 open ports.
Enumeration
Browsing the website, show list of usernames and passwords.
Browsing the website, show list of usernames and passwords.
data:image/s3,"s3://crabby-images/fdd2a/fdd2a25bcb92a08472b38fe02a6c790e19244d2c" alt=""
Checking the source code reveal us a hint- ROT47.
data:image/s3,"s3://crabby-images/34a1b/34a1b60817bba4aff74177e16944fd07827b7973" alt=""
password as- 4J36CDA=@:E`
Browsed Decode.fr to decode it, and we get the credentials as-
username: shailendra
password: cybersploit1
data:image/s3,"s3://crabby-images/3551e/3551e7922501d02544ddae613d4dfecdd3670ab4" alt=""
Getting Access
Tried ssh with credential, and we get the access.
ssh shailendra@192.168.1.1
password: cybersploit1
ssh shailendra@192.168.1.1
password: cybersploit1
Found a file named as hint.txt, which gives a hint as docker, it can be used for privilege escalation,
also the user is a member of docker group.
also the user is a member of docker group.
data:image/s3,"s3://crabby-images/543ff/543ff02b16dba1feddc8750e9d54271ab1dec1f4" alt=""
docker run -v /:/mnt --rm -it alpine chroot /mnt sh
data:image/s3,"s3://crabby-images/697b7/697b70af128568b9c4395d87f3d33b2116acd578" alt=""
data:image/s3,"s3://crabby-images/60aac/60aac5537918967178e238aa52cd573e1a63c365" alt=""
Comments
Post a Comment