GreenOptic: 1 Walkthrough
reference | GreenOptic: 1 |
target ip | 192.168.1.136 |
Scan with nmap
:
data:image/s3,"s3://crabby-images/fda66/fda6619cc23156e199a9f8be28e585e73bd0c303" alt="nmap"
Enumerate with gobuster
:
data:image/s3,"s3://crabby-images/15452/15452351e3acf882f7eb54096083af79a36c520b" alt="gobuster"
Enumerate /etc/passwd
with LFI:
data:image/s3,"s3://crabby-images/06a02/06a02756159d7dfdbd2ba79aefa520d74848685f" alt="lfi_passwd"
Enumerate Apache configurations with LFI./etc/httpd/conf/httpd.conf
since Apache in CentOS:
1 | curl -s "http://192.168.1.136/account/index.php?include=../../../../etc/httpd/conf/httpd.conf" | egrep -v "^$|^\s*#" |
data:image/s3,"s3://crabby-images/c187b/c187bc1bb926bc1093ed1409f42544c8501ec117" alt="lfi_httpd"
/etc/httpd/conf.d/vhosts.conf
:
1 | curl -s "http://192.168.1.136/account/index.php?include=../../../../etc/httpd/conf.d/vhosts.conf |
data:image/s3,"s3://crabby-images/cb2ca/cb2ca894b1059a7b3d5613acb8b618a8704e3a07" alt="lfi_vhosts"
Add websrv01.greenoptic.vm
to /etc/hosts
:
data:image/s3,"s3://crabby-images/e470a/e470a6424e82b5d658b3548b087f0767d276f353" alt=""
data:image/s3,"s3://crabby-images/b150d/b150d4332ff2b3813a67048e83dc28da956c6292" alt="hosts"
DNS zone transfer since there’s a DNS service:
1 | dig AXFR greenoptic.vm @192.168.1.136 |
data:image/s3,"s3://crabby-images/095e4/095e4fcf61080b0163e68669f3b0caed797cd426" alt="dig"
Request http://recoveryplan.greenoptic.vm
, 401:
data:image/s3,"s3://crabby-images/d1bd5/d1bd504d3c4df1c73eaa0a63246b87264404d011" alt=""
Enumerate /var/www/.htpasswd
with LFI:
data:image/s3,"s3://crabby-images/d51c8/d51c8cd57da4bfac64ecef61c7735431aae4d4e9" alt="htpasswd"
Crack with john
:
data:image/s3,"s3://crabby-images/8c24c/8c24cb77ccd54b49349b7c53a8cec6fa35b24610" alt="john"
Request http://recoveryplan.greenoptic.vm
with HTTP basic auth:
data:image/s3,"s3://crabby-images/18ad7/18ad7f3a7b28fa76e0f7ef0c71dfb35315bd5a9b" alt="recoveryplan"
Terry has already mailed sam the password:
data:image/s3,"s3://crabby-images/2c6f4/2c6f451e7a52569faf30763e30910190a26b35d5" alt="phpbb"
Enumerate /var/mail/sam
with LFI.
data:image/s3,"s3://crabby-images/8eb98/8eb98b1af5252bf0a41a0c9a700d559d9aceddd2" alt="mail_sam"
Extract dpi.zip
:
data:image/s3,"s3://crabby-images/bcd1b/bcd1b3bda5de203b315daeeaa576f7da0f2b6bf0" alt="dpi.zip"
Load the pcap file with wireshark
, and filter FTP packets:
data:image/s3,"s3://crabby-images/475de/475de14004e2f229d072cd48e24a40b804df17e9" alt="dpi.pcap"
Login into FTP as user alex:
data:image/s3,"s3://crabby-images/0cf4d/0cf4d85203fc3c28d903954eca713c872a3cc992" alt="ftp"
This credential can be also used for SSH:
data:image/s3,"s3://crabby-images/3ba3a/3ba3ade1e4f3d8126e6012e8a69177fbe0dadf90" alt="ssh_alex"
/home/alex/user.txt
:
data:image/s3,"s3://crabby-images/5a3b6/5a3b68ef1f9bfdea8f2793ce912a720a242394d7" alt="user.txt"
User alex is in group wireshark:
data:image/s3,"s3://crabby-images/76396/763963276e221c3b78295364cf75340d484100e0" alt="groups"
Monitor with pspy64
reveals there’s something wrong with SMTP:
data:image/s3,"s3://crabby-images/3d673/3d6732a78c24258f0211a44278bc93078c9ea4a1" alt="pspy"
Monitor with /usr/sbin/dumpcap
:
data:image/s3,"s3://crabby-images/7c5c9/7c5c925fdbb85fb34a304430f8588c0c529d7205" alt="dumpcap"
Base64 encoded username/password:
data:image/s3,"s3://crabby-images/5da86/5da86d58d8dc408f7697a4f78295c94a6717e357" alt="smtp"
Escalate from user alex to user root:
data:image/s3,"s3://crabby-images/19b6d/19b6d91c5183cc823dbb40787660ee47da0718a7" alt="root"
/root/root.txt
:
data:image/s3,"s3://crabby-images/bec3b/bec3be4dbd864ca0293723c648bb9d7371109090" alt="root.txt"
http://192.168.1.136/img/testdisk.log
:
data:image/s3,"s3://crabby-images/571c6/571c66edee873c0f4f04cd6b3fe219c8bd9b7aa6" alt="testdisk.log"
http://192.168.1.136/img/image.dd
:
btrfs filesystem? But I failed to mount it..
data:image/s3,"s3://crabby-images/92c71/92c71ddda8d0190ade77d1d0552926447638b1a3" alt="image.dd"
/var/mail/terry
:
data:image/s3,"s3://crabby-images/e3c8c/e3c8cf3cb097051177cf6e680890a8bc14f234f3" alt="mail_terry"