Photographer:1 - Walkthrough [Vulnhub]
Here's my solution for Photographer:1.
The machine can be downloaded from here.
Nmap
Scanning for all TCP ports.
nmap -sC -sV -p- 192.168.1.107
nmap -sC -sV -p- 192.168.1.107
data:image/s3,"s3://crabby-images/5c1fb/5c1fbd73e23fb263655daded39f2ed5cdeb3e607" alt=""
We find 4 open ports.
Enumerating SMB shares, we find that we have access to share named as- sambashare.
data:image/s3,"s3://crabby-images/6355c/6355c06ba784be00b6619ca4e58046ef13f2a8a7" alt=""
Lets get the smbshell.
data:image/s3,"s3://crabby-images/54293/54293f32157dabdb5598dc773b01ff546fa4accd" alt=""
Download the file- mailsent.txt
data:image/s3,"s3://crabby-images/11aff/11aff2bc47278e238c82525decfb28a968c71438" alt=""
Reading the contents in mailsent.txt, gives us the hint as-
User/Email: daisa@photographer.com
Password: babygirl
User/Email: daisa@photographer.com
Password: babygirl
data:image/s3,"s3://crabby-images/c7cf9/c7cf96aac357376ace4f2f4ab9e6a42119e9e3a9" alt=""
Browsing the web hosted on port 8000.
Using dirb for scanning directories.
dirb http://192.168.1.107:8000/ -f
dirb http://192.168.1.107:8000/ -f
data:image/s3,"s3://crabby-images/25dde/25dde72b33fc8ff7ab48e6970b65fd3d8f13e067" alt=""
We find an /admin directory.
We browse the /admin directory, if we observe the title and the logo it says- Koken, which is a CMS.
Here we use those credentials which we have found in file- mailsent.txt
Here we use those credentials which we have found in file- mailsent.txt
data:image/s3,"s3://crabby-images/9c9c3/9c9c32057989d9161a418caf1b87ccaf149c25e4" alt=""
Navigating to Settings Tab, displays the version- 0.22.24
data:image/s3,"s3://crabby-images/a1110/a111098488f472e39e77961db60e64be034f095f" alt=""
We search for the exploit and we found it here.
It seems that the author of the exploit and the box is- v1n1v131r4.
Now we upload a php reverse shell file with double extension as- rshell.php.jpeg, by navigating to
Library > Import content Button.
data:image/s3,"s3://crabby-images/35d71/35d7164f0034f876eedc02eb434be8653b2a023b" alt=""
Intercept the request and change the extension-
rshell.php.jpeg > rshell.php
rshell.php.jpeg > rshell.php
data:image/s3,"s3://crabby-images/f1d64/f1d641caa5f157dc1d837dbd7ceb60f1c90e5d3e" alt=""
data:image/s3,"s3://crabby-images/ae23c/ae23c771975c3b662e671f5db42fc7580faea883" alt=""
To run the exploit, we can get the URL, By right click on Download File > Copy Link Location.
data:image/s3,"s3://crabby-images/db635/db6355393566057618d9be510fd29f642fd58db7" alt=""
We browse the URL-
http://192.168.1.107:8000/storage/originals/31/01/rshell.php
And on the other hand we start our netcat listener.
And on the other hand we start our netcat listener.
data:image/s3,"s3://crabby-images/8aff9/8aff9a810536617f1dcee71592071175c1a17067" alt=""
We get the reverse shell.
User Flag.
data:image/s3,"s3://crabby-images/9644b/9644b4504e3b2135429e594ea2f013f8f11063b6" alt=""
Privilege Escalation
We check for SUID permission.
We check for SUID permission.
data:image/s3,"s3://crabby-images/fc047/fc047feba2ca769e5f5ede43d9c2d9ff13559200" alt=""
Root Flag.
data:image/s3,"s3://crabby-images/92d44/92d443d1c83507a1aefe423e696c09bcebe3416b" alt=""
Comments
Post a Comment