FishyMail:1 - Walkthrough [Vulnhub]
Here's my solution for FishyMail:1
The machine can be downloaded from here.
Port Scanning
Using nmap to scan all TCP ports.
$ nmap -sC -sV -p- 192.168.1.106
data:image/s3,"s3://crabby-images/6e3c6/6e3c6aa734f5b14cbe670601909ae98a9171fa3a" alt=""
We find 3 ports open.
Enumeration
Browsing the web hosted on port 8080. Checking the source page did not reveal any useful information/hint.
data:image/s3,"s3://crabby-images/644d9/644d9c64b787c02f937ce180be791ce0d5054886" alt=""
Using dirb to scan directories.
$ dirb http://192.168.1.106:8080 -r
data:image/s3,"s3://crabby-images/f4806/f480652fc01bba4b71ddcd9329a525bda84a184e" alt=""
Having a look at /robots.txt
Interesting, browsing /dataentry.
data:image/s3,"s3://crabby-images/29320/29320a34f02371f5b09830933a1d46fa05e97890" alt=""
Again using dirb to brute force /dataentry directory.
$ dirb http://192.168.1.106:8080/dataentry/
data:image/s3,"s3://crabby-images/12c37/12c37aff78386bb65994ef6b37a6f0a5f8777b2b" alt=""
Browsing /dataentry/backup/admin/files, still no any useful information.
Again we try to brute force but this time with some extension.
$ gobuster dir -u http://192.168.1.106:8080/dataentry/backup/admin/files/ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php,html,txt
Interesting, Browsing the /dir.txt
After decoding the double base64 encoded data the output seems to be like credentials. We can try these over ssh.
Getting Access
Accessing SSH.
$ ssh squidward@192.168.1.106 -p 2600
Password: 0ctopus
We move 1 directory back and we find a file with .sql extension.
By observing its content, it seems to be base64 encoded.
After decoding and observing the contents we see user names and their associated passwords in hashes.
data:image/s3,"s3://crabby-images/b5523/b5523d861bd35b0cc052d7dcdf04a7ce9e2e321b" alt=""
We browse Crackstation to find the values.
data:image/s3,"s3://crabby-images/cc0b7/cc0b72a3f7d375db0cdad32f6937be699b3f38ad" alt=""
Privilege Escalation
Accessing SSH and grabbing the user flag.
$ ssh dirtysalmon@192.168.1.106 -p 2600
Password: crabby4eva
data:image/s3,"s3://crabby-images/05b9d/05b9d48ffbff019d150c664a5004871a6dd5dcec" alt=""
We check for kernel version.
data:image/s3,"s3://crabby-images/60e71/60e7193e2829aa7b0bced684cf3fe2226c345d69" alt=""
Searching for kernel exploit.
We transfer the exploit on the target machine and give full permission to the file.
We run the exploit and grab the root flag.
Comments
Post a Comment