Skip to main content

VMW- FristiLeaks: 1.3. base64 encode/decode, search webapp



  1. https://www.scattiscattanti.com/walkthroughs/fristi/  ….using Metasploit
  2. https://reversebrain.wordpress.com/2016/11/24/vulnhub-fristileaks-1-3/ ….show how to convert the base64 encoding using cat, check if the coding is a picture of text..but didn’t work


  1. Scan showed port 80 with Apache httpd 2.2.15 ((CentOS) DAV/2 PHP/5.3.3)
  2. Looked thru website or nikto or dirb didn’t show much except a few dir in robot.txt which didn’t have any text except a picture
    1. So created a custom dictionary to use with dirb to see If there are any webapp that cant be seen
    2.  use cewl www.drchaos.com -w drchaospasswords.txt to create custom dictionary based on the website text. Since there were pictures so add words/text from the picture to the list and than run the dirb http://1.2.3.4 drchaospasswords.txt again. This time found a dir called /firsti
  1. Checked the comments in the source gets you username while the base64 enccoding/decoding gives you pwd. This could be done using echo cmd but didn’t work at this time.
  1. Username: eezeepz & Password: keKkeKKeKKeKkEkkEk
  2. You now have ability to upload a picture fie (lets try to add 112.php.gif) which is a PHP reverse shell file.
  3. Modify the PHP reverse file to change the ip and ports of attacks
  4. Once uploaded, go to the URL Http://ip/fristi/uploads/112.php.gif after you have started nc -np 1234 which will give you reverse shell access. We can only upload gif like files. PHP file type is not allowed to b uploaded
  5. Got access to shell now. Look around. Look notes.txt. The batch file runs as cron job so add
echo "/usr/bin/../../bin/chmod -R 777 /home/admin" > /tmp/runthis OR
echo "/home/chmod -R 777 /home/admin" > /tmp/runthis
to get access to /home/admin. In it we have encoded pwd. Run a  python script to decode the pwd. Didn’t usecryptedpass.txt although it can be decoded.
  1. Spawn tty. Su to fristigod. Than su -fristigod  which will log you in under /var/fristigod. Looking around in bash_history appears we can sudo . use SUID binary for privilege escalation
>sudo -u fristi .secret_admin_stuff/doCom /bin/sh
>sh-4.1# id
>id
>uid=0(root) gid=100(users) groups=100(users),502(fristigod)

Comments

Popular posts from this blog

VM 13 : Basic Pentest 1 csec

Notes: Walkthru: 1. https://medium.com/@evire/basic-pentesting-1-7251fb3e3f9e [ w/metasploi t using Wordpress t] 2. https://prasannakumar.in/infosec/vulnhub-basic-pentesting-1-writeup/ [ w/metasploit using ftp ] 3.  https://www.ceos3c.com/hacking/basic-pentesting-1-walkthrough/ [ by uploading php-reverse-shell in wordpress ] 4. http://k3ramas.blogspot.com/2018/02/basic-pentesting-1-walkthrough.html [  access wordpress config file to get pwd and access the DB ] 5.  https://cowsayroot.com/walkthrough-basic-pentesting-1/ [ Wpscan, ftp metasploit vulnerability, phpbash ] 6.   http://www.hackingarticles.in/hack-the-basic-penetration-vm-boot2root-challenge/    [use msfvenom to create  to create php shell to be uploaded in Wordpress ] 7.   https://d7x.promiselabs.net/2018/01/30/ctf-basic-pentesting-a-guide-for-beginners/ [adding command using using PHP] Notes:  Ports - 21...ProFTPD 1.3.3c - 22 openSSH 7.2p2 ubuntu ...

VM: pWnOS 2.0

Walkthru A. http://defsecurityjam.blogspot.co.uk/2015/07/pwnos-version-2-walkthrough.html [reading source page, Simple PHP Blog Perl exploit, Python revershell using oneliner, looking around ] b. https://blog.g0tmi1k.com/2012/09/pwnos-2-php-web-application/ [metasploit using PHP Blog exploit] c. http://netsec.ws/?p=430 [burpsuite, sql porxy] d. https://blog.g0tmi1k.com/2012/09/pwnos-2-sql-injection/ [sql injection, union. Very good explanation of the process of what is being done. Didnt try cmds] e. https://www.youtube.com/watch?v=ytzZfI27ueU [sql injection, sqlmap read file and upload reverse shell using sqlmap] f. https://ub3rsec.github.io/pages/2016/pwnosv2-sqli.html [sql injection, union using burp Very good . It list all email field that we are passing and modifying thru burp suite/proxy/intercept. One could enter those union statements in the email field but in this case, the field truncates and remove the later part of union statment which is why we...

38 VM : d0not5top: 1.2

https://www.vulnhub.com/?q=D0Not5top&sort=date-des&type=vm Walkthru: A. https://github.com/Hamza-Megahed/CTFs/blob/master/d0not5top/README [  burp proxy, adding hostnames to /etc/host shows following but not working for me. Not showing localhost stuff, $ dirb http://172.16.34.163/control/ -X .txt,.php,.html     + http://172.16.34.163/control/hosts.txt     127.0.0.1 localhost     127.0.0.1 D0Not5top.ctf     #127.0.0.1       MadBroAdN1n.ctf ## AD105 M0F05] B. https://adaywithtape.blogspot.com/2017/04/vulnhub-d0not5top-writeup.html [use nc cmd to get the flag and echo cmd to decode the flag, wfuzz, virtualhost, partially binary string, google language translate, curl  -header  host request, additional domains, OWSAP ZAP, exiftool, HD, hash64,] wfuzz -c -w /usr/share/seclists/Discovery/Web_Content/common.txt --hc 404 192.168.56.102/FUZZ Changing the syntax just a tad to only show html 200...