Skip to main content

27 VM Lin.Security

A. http://www.hackingarticles.in/hack-the-lin-security-vm-boot-to-root/ [login with the user/pwd provided at the vulnhub page to perform priv escalation,  unable to get shell, rpcinfo, showmount, rpcbind, nfs ]



Nmap scan report for 192.168.117.5
Host is up (0.00051s latency).
Not shown: 997 closed ports
PORT     STATE SERVICE VERSION
22/tcp   open  ssh     OpenSSH 7.6p1 Ubuntu 4 (Ubuntu Linux; protocol 2.0)
111/tcp  open  rpcbind 2-4 (RPC #100000)
2049/tcp open  nfs_acl 3 (RPC #100227)

34203/tcp open  nlockmgr 1-4 (RPC #100021)
39865/tcp open  mountd   1-3 (RPC #100005)
50125/tcp open  mountd   1-3 (RPC #100005)
57253/tcp open  mountd   1-3 (RPC #100005)

UDP open                  sunrpc[  111]         from 192.168.117.5  ttl 64
UDP open                   shilp[ 2049]         from 192.168.117.5  ttl 64

MAC Address: 08:00:27:D8:9F:D6 (Oracle VirtualBox virtual NIC)
Device type: general purpose
Running: Linux 3.X|4.X
OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:4
OS details: Linux 3.2 - 4.9
Network Distance: 1 hop
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
00000000000000000000000000000000
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
# Nmap done at Tue Jul 17 21:48:59 2018 -- 1 IP address (1 host up) scanned in 7.99 seconds

00000000000000000000000000000000
root@kali:~/reports/192.168.117.5# showmount -e 192.168.117.5
Export list for 192.168.117.5:
/home/peter *
root@kali:~/reports/192.168.117.5#
00000000000000000000000000000000


root@kali:~# rpcinfo -p 192.168.117.5
   program vers proto   port  service
    100000    4   tcp    111  portmapper
    100000    3   tcp    111  portmapper
    100000    2   tcp    111  portmapper
    100000    4   udp    111  portmapper
    100000    3   udp    111  portmapper
    100000    2   udp    111  portmapper
    100005    1   udp  42010  mountd
    100005    1   tcp  57253  mountd
    100005    2   udp  34061  mountd
    100005    2   tcp  39865  mountd
    100005    3   udp  34234  mountd
    100005    3   tcp  50125  mountd
    100003    3   tcp   2049  nfs
    100003    4   tcp   2049  nfs
    100227    3   tcp   2049
    100003    3   udp   2049  nfs
    100227    3   udp   2049
    100021    1   udp  37189  nlockmgr
    100021    3   udp  37189  nlockmgr
    100021    4   udp  37189  nlockmgr
    100021    1   tcp  34203  nlockmgr
    100021    3   tcp  34203  nlockmgr
    100021    4   tcp  34203  nlockmgr

00000000000000000000000000000000
root@kali:~/reports/192.168.117.5# ls /mnt
root@kali:~/reports/192.168.117.5# mkdir /mnt/peter
root@kali:~/reports/192.168.117.5# mount 192.168.117.5:/home/peter /mnt/peter
root@kali:~/reports/192.168.117.5# ls /mnt/peter
root@kali:~/reports/192.168.117.5# ls -la /mnt/peter
total 32
drwxr-xr-x 5 1001 1005 4096 Jul 10 14:49 .
drwxr-xr-x 3 root root 4096 Jul 17 23:29 ..
-rw-r--r-- 1 1001 1005  220 Jul  9 14:53 .bash_logout
-rw-r--r-- 1 1001 1005 3771 Jul  9 14:53 .bashrc
drwx------ 2 1001 1005 4096 Jul 10 05:04 .cache
-rw-rw-r-- 1 1001 1005    0 Jul 10 05:04 .cloud-locale-test.skip
drwx------ 3 1001 1005 4096 Jul 10 05:04 .gnupg
drwxrwxr-x 3 1001 1005 4096 Jul 10 03:03 .local
-rw-r--r-- 1 1001 1005  807 Jul  9 14:53 .profile

00000000000000000000000000000000

created a user called peter on kali, id was already 1001, changed the group to 1005 (or default). I was able to see content of these dir but no valuable information. Added .ssh/authorized_files root public keys but still couldnt login from kali using keys. Getting following. unable to pass this step



can login using walkthru A

Comments

Popular posts from this blog

VM 13 : Basic Pentest 1 csec

Notes: Walkthru: 1. https://medium.com/@evire/basic-pentesting-1-7251fb3e3f9e [ w/metasploi t using Wordpress t] 2. https://prasannakumar.in/infosec/vulnhub-basic-pentesting-1-writeup/ [ w/metasploit using ftp ] 3.  https://www.ceos3c.com/hacking/basic-pentesting-1-walkthrough/ [ by uploading php-reverse-shell in wordpress ] 4. http://k3ramas.blogspot.com/2018/02/basic-pentesting-1-walkthrough.html [  access wordpress config file to get pwd and access the DB ] 5.  https://cowsayroot.com/walkthrough-basic-pentesting-1/ [ Wpscan, ftp metasploit vulnerability, phpbash ] 6.   http://www.hackingarticles.in/hack-the-basic-penetration-vm-boot2root-challenge/    [use msfvenom to create  to create php shell to be uploaded in Wordpress ] 7.   https://d7x.promiselabs.net/2018/01/30/ctf-basic-pentesting-a-guide-for-beginners/ [adding command using using PHP] Notes:  Ports - 21...ProFTPD 1.3.3c - 22 openSSH 7.2p2 ubuntu ...

VM: pWnOS 2.0

Walkthru A. http://defsecurityjam.blogspot.co.uk/2015/07/pwnos-version-2-walkthrough.html [reading source page, Simple PHP Blog Perl exploit, Python revershell using oneliner, looking around ] b. https://blog.g0tmi1k.com/2012/09/pwnos-2-php-web-application/ [metasploit using PHP Blog exploit] c. http://netsec.ws/?p=430 [burpsuite, sql porxy] d. https://blog.g0tmi1k.com/2012/09/pwnos-2-sql-injection/ [sql injection, union. Very good explanation of the process of what is being done. Didnt try cmds] e. https://www.youtube.com/watch?v=ytzZfI27ueU [sql injection, sqlmap read file and upload reverse shell using sqlmap] f. https://ub3rsec.github.io/pages/2016/pwnosv2-sqli.html [sql injection, union using burp Very good . It list all email field that we are passing and modifying thru burp suite/proxy/intercept. One could enter those union statements in the email field but in this case, the field truncates and remove the later part of union statment which is why we...

38 VM : d0not5top: 1.2

https://www.vulnhub.com/?q=D0Not5top&sort=date-des&type=vm Walkthru: A. https://github.com/Hamza-Megahed/CTFs/blob/master/d0not5top/README [  burp proxy, adding hostnames to /etc/host shows following but not working for me. Not showing localhost stuff, $ dirb http://172.16.34.163/control/ -X .txt,.php,.html     + http://172.16.34.163/control/hosts.txt     127.0.0.1 localhost     127.0.0.1 D0Not5top.ctf     #127.0.0.1       MadBroAdN1n.ctf ## AD105 M0F05] B. https://adaywithtape.blogspot.com/2017/04/vulnhub-d0not5top-writeup.html [use nc cmd to get the flag and echo cmd to decode the flag, wfuzz, virtualhost, partially binary string, google language translate, curl  -header  host request, additional domains, OWSAP ZAP, exiftool, HD, hash64,] wfuzz -c -w /usr/share/seclists/Discovery/Web_Content/common.txt --hc 404 192.168.56.102/FUZZ Changing the syntax just a tad to only show html 200...