Investigator: 1 Walkthrough
reference | Investigator: 1 |
target ip | 192.168.1.8 |
Scan with nmap
:
data:image/s3,"s3://crabby-images/41518/415184caa7034294f32979a657b234e014265479" alt="nmap"
adb
since it’s an Android box.
1 | adb connect 192.168.1.8:5555 |
spawn a shell, and elevate to root
1 | adb shell |
data:image/s3,"s3://crabby-images/1930e/1930e960310dbbf0233a20a2f2112e3b13bd1b60" alt="adb"
check sms which is located in /data/data/com.android.providers.telephony/databases/mmssms.db
data:image/s3,"s3://crabby-images/4a4b0/4a4b02c3013eae5e53d8ebb59efb196d7d4c6dbe" alt="sms"
Other interesting files/dirs:
- /data/root/flag.txt
data:image/s3,"s3://crabby-images/b653a/b653ac1e49aea26cfd253357aeb12546fca330fa" alt="flag"
- /sdcard/www/public/announce/backdoor.php
data:image/s3,"s3://crabby-images/6e920/6e9208d5ca48226eedaea68967e3ad6f6d482bf4" alt="backdoor"
we can get a reverse shell
- /sdcard/www/public/secret22000/touhid.key
crack with john
1 | /usr/share/john/ssh2john.py ./touhid.key > ./id_rsa.hash |
data:image/s3,"s3://crabby-images/e0a19/e0a19e391b8da15ff8fc4a905a4331460ccfb854" alt="john"
ssh
to the phone with this private key
1 | chmod 400 ./touhid.key |
data:image/s3,"s3://crabby-images/b2d49/b2d49e58cb2ab3f289a5df5d18efb366e775124b" alt="ssh"
/sdcard/DCIM/qr.png
/data/data/com.google.android.gm/cache/sivaneshkumar121@gmail.com