My CMSMS: 1 Walkthrough
reference | My CMSMS: 1 |
target ip | 192.168.1.19 |
Scan with nmap
:
data:image/s3,"s3://crabby-images/7d9da/7d9daf4b138b1c6abe77609452c6206ec86fa6ad" alt="nmap"
Scan with nmap
ssh-auth-methods
:
data:image/s3,"s3://crabby-images/d697f/d697f75fc508cbeab1227113232b4213e26c0703" alt="nmap_ssh"
Try MySQL password with hydra
:
data:image/s3,"s3://crabby-images/d54bf/d54bf4c837b9b05cf55be8170ab4327a27ec4ea6" alt="hydra_mysql"
Login into MySQL, enumerate cmsms_db.cms_users
:
data:image/s3,"s3://crabby-images/ff151/ff151a52dec55ada9a7ba5c0b7a611f6d5dcae56" alt="mysql"
Update the password instead of cracking.
This sql is from this thread.
data:image/s3,"s3://crabby-images/cd23a/cd23a70ad95894898f049ae0360866b31f339831" alt="cms_users"
Login into CMS Made Simple.
Upload reverse shell by renaming from php to phtml:
data:image/s3,"s3://crabby-images/75e73/75e7306e9f2fa2209ed3167650b75630d1a6338f" alt="rs.phtml"
Request http://192.168.1.19/uploads/images/rs.phtml
to get a reverse shell.
Escalate from user www-data to user root.
Readable /var/backups/shadow.bak
:
data:image/s3,"s3://crabby-images/528d2/528d230d37ebbc5d1f796f74d788e33b0c02d7f5" alt="shadow.bak"
unshadow
, then crack with john
:
data:image/s3,"s3://crabby-images/95e73/95e734c5dac8c0a13442c19b6a8b5779ee520415" alt="root"
/root/proof.txt
:
data:image/s3,"s3://crabby-images/70044/7004416131c2975f9e25fbd68751710db725254b" alt="proof.txt"
/home/armour/binary.sh