Healthcare: 1 Walkthrough
reference | Healthcare: 1 |
target ip | 192.168.1.26 |
Scan with nmap
:
data:image/s3,"s3://crabby-images/c0948/c09486140e9cda057cd2901cfd355591720eed5e" alt="nmap"
Enumerate HTTP with gobuster
:
data:image/s3,"s3://crabby-images/51eaf/51eaff25b334c3a9e296babfc9b155e3e50e8215" alt="gobuster"
Combine these two exploits together:
- CVE-2015-4453 - Authentication bypass in OpenEMR
- CVE-2014-5462 - Multiple Authenticated SQL Injections In OpenEMR
Save the request:
data:image/s3,"s3://crabby-images/8d572/8d5729440f713d42644fd4c16fd4de6cb1de913a" alt="sqli.req"
SQLi with sqlmap
to extract table openemr.users:
data:image/s3,"s3://crabby-images/512c0/512c09ed8d49f9774a06282aaaf3dd87a20e3748" alt="sqlmap"
Crack with john
:
data:image/s3,"s3://crabby-images/9a961/9a961424fc1b7e0d8c974c1af5d52ce73b89bc4f" alt="users"
Login into FTP to upload a reverse shell on /var/www/html/openemr
:
data:image/s3,"s3://crabby-images/6223e/6223e8aa5fa592dec53e2ad9c8c6e7b171c53c54" alt="rs.php"
Reverse shell:
data:image/s3,"s3://crabby-images/20065/200658a43210390fc53ce9a933a60a57c9c4fdf6" alt="rs"
Escalate from user apache to user medical:
data:image/s3,"s3://crabby-images/d781a/d781aaa6961ac3a1b6ff56343efa145a14b0941c" alt="medical"
Escalate from user medical to user almirant.
Download /var/backups/shadow
:
data:image/s3,"s3://crabby-images/28813/288131a2380aac406f59603e6de23d04c28239c5" alt="ftp_shadow"
Crack with john
:
data:image/s3,"s3://crabby-images/c51a3/c51a3234ce1423712d036bb3bbed8be0f6ef890e" alt="shadow"
/home/almirant/user.txt
:
data:image/s3,"s3://crabby-images/c5015/c5015992a6f9b5d6450e95a9bf769b99879d0f83" alt="user.txt"
Escalate from user almirant (or medical) to user root.
/usr/bin/healthcheck
:
data:image/s3,"s3://crabby-images/93d60/93d609e3ff5b924201071674d1d991910fb3f842" alt="healthcheck"
Privilege escalation:
data:image/s3,"s3://crabby-images/6682f/6682f620a81131da850b08fa54d327fad534bec9" alt="root"
/root/root.txt
:
data:image/s3,"s3://crabby-images/38505/38505a43e3165318a0a2a36052a226fabd52b4c6" alt="root.txt"