Relevant:1 - Walkthrough [Vulnhub]
Here's my solution for Relevant:1.
The machine can be downloaded from here.
Nmap
Scanning for all TCP ports.
$ nmap -sC -sV -p- 192.168.1.109
data:image/s3,"s3://crabby-images/0775f/0775fa606ffdc255495b946edf8c6391f93739cf" alt=""
We find 2 port open.
Enumeration
Browsing website, the web page presents us with 3 links, seems some kind of hints, lets check it out.
data:image/s3,"s3://crabby-images/96414/964140774abbe1adb256d4fa1cd35485b4f90a8f" alt=""
Browsing the 1st link- https://rb.gy/g5prrv, gets redirect to youtube.
data:image/s3,"s3://crabby-images/60185/601854c3badcbbe8916318f4b895ea3e8103e1fb" alt=""
Browsing the 2nd link- https://pastebin.com/sGzQSQXu, seems like a list of credentials.
Just a thought, the home page says- because we hax0r3d your webz!, meaning the hacker has compromised the website.
So, may be they have leaked the credentials here.
data:image/s3,"s3://crabby-images/62b6d/62b6d76d01b0a826d962e69ec9493cd902d6fae9" alt=""
Tried brute forcing the ssh but no result.
Browsing the 3rd link- https://ibb.co/JtTY0Md, the QR code.
We can browse Zxing, and decode it.
data:image/s3,"s3://crabby-images/176ad/176ad54c4bb0c18da241ac272f77d62282d52686" alt=""
Interesting, we keep it we may require at further stages.
Lets scan for directories.
$ dirb -u http://192.168.1.109 -r
data:image/s3,"s3://crabby-images/70101/70101abbd0b456ef2c6179866749741fb1442346" alt=""
Seems like the website is built on CMS- Wordpress. We can use wpscan to enumerate it further.
$ wpscan --url http://192.168.1.109 -e ap,u
data:image/s3,"s3://crabby-images/badc9/badc9bc5f6ab6684eea94511ce6b8ff0c3b64b05" alt=""
The wpscan did not recognize the wordpress so we rescan using- force flag.
$ wpscan --url http://192.168.1.109 --force -e ap,u
data:image/s3,"s3://crabby-images/fd5e0/fd5e03e22a4a2a75be713bda1f555d1fdc9afd00" alt=""
Still not useful result, now we change the detection mode to- aggressive.
$ wpscan --url http://192.168.1.109 --force --plugins-detection aggressive
data:image/s3,"s3://crabby-images/2edd2/2edd2d62d9397d42e92019f697135560c23270ca" alt=""
We search the exploit for plugin- wp-file-manager and found it here.
Getting Access
After downloading the exploit we run it.
The exploits requires a file- payload.php where we place the php reverse shell payload.
Now to execute the payload we browse- http://192.168.1.109/wp-content/plugins/wp-file-manager/lib/files/payload.php
And on the other hand we start the netcat listener.
data:image/s3,"s3://crabby-images/82fcc/82fcc2da9836d99c043c9c8c0f9a408cacfac7ca" alt=""
data:image/s3,"s3://crabby-images/1cdb5/1cdb57ae0b0ffa1265fddf158718329b2f14cec6" alt=""
We get the reverse shell.
Privilege Escalation
From www-data>news
We find an interesting directory with name- ... (Triple Dots, very confusing name), under /home/h4x0r, let us navigate to it.
data:image/s3,"s3://crabby-images/00ba8/00ba86ba3547a5804172f9473b01726be34091aa" alt=""
A note, let us see what's in it.
data:image/s3,"s3://crabby-images/b6a86/b6a861ccab2e32db1b49750694eaaed5f0685e4b" alt=""
Looks like a credential. We verify by checking the /etc/passwd file, the user- news is present.
The password seems to be in hash.
We can browse Crackstation for cracking the hash.
data:image/s3,"s3://crabby-images/52009/520094d62c52656015c70b5fd9e2c287c252ec46" alt=""
Lets switch to user- news.
$ su news
Password: backdoorlover
data:image/s3,"s3://crabby-images/34120/341201bac6e139cdeffb7169c5a90382f1eb81d8" alt=""
From news>root
We check for SUDO rights.
Lets escalate and get the root flag.
Comments
Post a Comment