FunBox:1 - Walkthrough [Vulnhub]
Here's my solution for FunBox:1.
The machine can be downloaded from here.
Nmap
Scanning for all TCP ports.
$ nmap -sC -sV -p- 192.168.1.106
We find 4 ports open.
Lets map the ip to domain, by editing the file- /etc/hosts.
data:image/s3,"s3://crabby-images/c79a9/c79a9161e9f52fd2f5cdd3069ab7fd0f68e8e7c2" alt=""
Enumeration
Browsing the web, checking the source did not reveal any hint but we find that it is built on CMS- Wordpress.
data:image/s3,"s3://crabby-images/34235/34235c9b5b307b19e394acbbff6fec782f09b30b" alt=""
Using wpscan to enumerate all plugins and users.
$ wpscan --url http://funbox.fritz.box/ -e ap,u
data:image/s3,"s3://crabby-images/032aa/032aa70c525fbd17f3f0ff4f86ead90fa5c64645" alt=""
No plugins we found, but we find 2 users- admin and joe.
Using hydra to brute force the password for user- joe, on ssh.
$ hydra -l joe -P /usr/share/wordlists/rockyou.txt funbox.fritz.box ssh
data:image/s3,"s3://crabby-images/de487/de4877c1cb3d225cf1e34924da141eff0280ec88" alt=""
We get the password as- 12345.
Getting Access
Accessing SSH.
$ ssh joe@funbox.fritz.box
Password: 12345
We see that we are in restricted bash, lets escape it.
Connecting again.
$ ssh joe@funbox.fritz.box -t "bash --noprofile"
Password: 12345
data:image/s3,"s3://crabby-images/46b7d/46b7d7a895e34f3624f8bd31b17f5fa0b0c0ff68" alt=""
We get a hint in file- mbox
data:image/s3,"s3://crabby-images/52c68/52c68a6b52e2a3520324309f3bfece656c8b2d62" alt=""
Privilege Escalation
We find a hint in a hidden file- .reminder.sh, under /home/funny directory.
data:image/s3,"s3://crabby-images/36742/367422639d4c62bbf3b122ff446b5fff09c8e985" alt=""
We see that, we have full permission on a hidden file- .backup.sh
We place the bash reverse shell payload in it and on the other hand we start the netcat listener.
data:image/s3,"s3://crabby-images/832c3/832c3c86f75bc28b121a561bcc4b865469f98bb5" alt=""
We wait for while, and we get the reverse shell.
data:image/s3,"s3://crabby-images/3b939/3b939579bff9fdfe53e766d5b23a382b7eda0d82" alt=""
Root Flag.
data:image/s3,"s3://crabby-images/06f76/06f767cbd6e09b7a98391b14030b7bf33794ceac" alt=""
Comments
Post a Comment