Photographer: 1 Walkthrough
reference | Photographer: 1 |
target ip | 192.168.1.7 |
Scan with nmap
:
data:image/s3,"s3://crabby-images/3e687/3e68745b5213f36e5062839408624bfe07c7c0e1" alt="nmap"
smb-enum-shares
:
data:image/s3,"s3://crabby-images/2d51e/2d51e764f49da4dd763ffc2f6b85b458a0843e20" alt="shares"
There’re two files in sambashare
:
data:image/s3,"s3://crabby-images/7a5a1/7a5a130f9b5e4b93cbadd13d8c2c1693cbd0b6d7" alt="sambashare"
mailsent.txt
:
data:image/s3,"s3://crabby-images/64f23/64f23b8e75278109168819ae445b4afdd75f2f55" alt="mailsent"
There’s a Koken
hosted on http://192.168.1.7:8000
, with an existed exploit (The author of the exploit and the box is the same one).
After a little bit guess work, I can login with username daisa@photographer.com
and password babygirl
to Koken
.
Replace the original shell.php to a new one:
data:image/s3,"s3://crabby-images/b1457/b1457902624265d09fb1b8bfb9a61eeaf63cd6ff" alt="replace"
reverse shell:
data:image/s3,"s3://crabby-images/e4738/e4738e2831452ba00e396a61b6370757b44c1ad9" alt="rs"
/home/daisa/user.txt
:
data:image/s3,"s3://crabby-images/e1744/e17442bcb1675ecff792206c2544a62287d744cf" alt="user.txt"
Privilege escalation is straightforward.
/usr/bin/php7.2
has setuid.
data:image/s3,"s3://crabby-images/54a95/54a95770d12d9205f532a232193051ca2cec0655" alt="pe"
/root/root.txt
:
data:image/s3,"s3://crabby-images/4899e/4899e56da2a188757160d037ec4445ab09f7eb50" alt="root.txt"
- original shell1.php, 192.168.1.7 -> 192.168.56.106:443
data:image/s3,"s3://crabby-images/6af62/6af62de38163fc2c873a7eed940fd3301f4d5a94" alt="pcap"
- database.php
data:image/s3,"s3://crabby-images/5b935/5b935a49e8e0726dfbcecf2917f8d6147671b526" alt="database"