Funbox: 1 Walkthrough
reference | Funbox: 1 |
target ip | 192.168.1.8 |
Scan with nmap
:
data:image/s3,"s3://crabby-images/20fa2/20fa293eea08a506c1096be3d1d24cbedaef4d64" alt="nmap"
Add the domain funbox.fritz.box
to /etc/hosts
, since curl
redirected from ip to domain:
data:image/s3,"s3://crabby-images/1c708/1c708a4878b4b1663b0e1201088d4cef14b72f6d" alt="domain"
http://funbox.fritz.box
hosts a wordpress, with the username admin
.
Brute force with wpscan
:
1 | wpscan --url http://funbox.fritz.box --no-banner -U admin -P /usr/share/wordlists/rockyou.txt |
data:image/s3,"s3://crabby-images/37070/37070c01d61600d577f63f04a402f7009a3d0db3" alt="wordpress"
Login into wordpress.
There’s another user:
data:image/s3,"s3://crabby-images/f7522/f75221fecbb6c98ea4a8e8fc8d6fbe7bf3ca7b6f" alt="wordpress_users"
Brute force with hydra
to FTP service:
1 | hydra -l joe -P /usr/share/seclists/Passwords/Common-Credentials/best1050.txt ftp://192.168.1.8 -e nsr -I -V |
data:image/s3,"s3://crabby-images/56646/566466cc0db3b82eedf8adf5da19be10d99241f3" alt="ftp"
This is also the SSH credential.
data:image/s3,"s3://crabby-images/1b2d9/1b2d9319261321c46a23ab72612e0e7290284e26" alt="ssh"
Rbash:
data:image/s3,"s3://crabby-images/00642/00642d63ddff9b0e0e860b2d37fb6de875ef1f1a" alt="rbash"
Escape from rbash:
data:image/s3,"s3://crabby-images/db618/db61865a6990d58c1a2956ad5422964ea3af066e" alt="rbash_escape"
There’s a cron-like script in /home/funny
:
data:image/s3,"s3://crabby-images/97a51/97a51048fcc9998727f01073dc7f05aaf1b1f4ee" alt="funny"
Escalate to root
:
data:image/s3,"s3://crabby-images/01feb/01feb34a69e948f59c298815c61e8af2b4000cfd" alt="backup.sh"
/root/flag.txt
:
data:image/s3,"s3://crabby-images/5bb68/5bb685b37691d556472abdaa1f9bd8bec503e70a" alt="flag"
/home/joe/mbox
data:image/s3,"s3://crabby-images/8bd00/8bd00e769c207336addc307b192cb94d155a8f77" alt="mbox"