Cysec: 1 Walkthrough
reference | Cysec: 1 |
target ip | 192.168.1.29 |
Scan with nmap
:
data:image/s3,"s3://crabby-images/5511a/5511af6aabfebdf6ecd9bf3b92c46de9491c6edd" alt="nmap"
FTP allows anonymous login, but:
data:image/s3,"s3://crabby-images/dbea5/dbea5ca0f7ee2451004e80bda9e1bd40dd10b468" alt="ftp"
OpenSSH < 7.7 - User Enumeration (2):
data:image/s3,"s3://crabby-images/88fa1/88fa1150626535aae457edd3d95e6892468e0215" alt="enum_ssh"
Try to hydra
FTP/SSH password as user cysec/anonymous/root, but failed.
data:image/s3,"s3://crabby-images/105d5/105d59613f61477089239f6f2f7d811cc254fcbf" alt="hydra"
/home/anonymouse/readme.txt
:
data:image/s3,"s3://crabby-images/b193e/b193ec5b3ee77a847c20066d79cc2598f72b8310" alt="readme.txt"
Decode /home/anonymouse/ICMPReq.PNG
with https://hpd.gasmi.net/:
data:image/s3,"s3://crabby-images/f6786/f6786432e5ab147b6b610dc63a26184ab210a159" alt="icmpreq"
md5sum
:
data:image/s3,"s3://crabby-images/a4fc4/a4fc47261580d94ffad9ba0fa7ea743e834c6323" alt="md5sum"
http://192.168.1.29/a8f64cea84bc654f4769c483876c08e7/
:
data:image/s3,"s3://crabby-images/d6b40/d6b40677a9c138aa2de4ad4d7fe2bb27a7653bfe" alt="a8f64cea84bc654f4769c483876c08e7"
wget --recusive
:
data:image/s3,"s3://crabby-images/7fde7/7fde75417c838f873140ec312e9e05f6585f80d1" alt="wget"
HoldOn13.jpg
:
data:image/s3,"s3://crabby-images/845c2/845c2aff0918f31aeb5e2220a274b5089114ac1d" alt="HoldOn13.jpg"
Download http://192.168.1.29/flag.bz2
, which is actually a gzip file:
data:image/s3,"s3://crabby-images/02769/0276946be5315af3f7f30cf4388944fe74275aa8" alt="flag.bz2"
tar zxvf
, then binwalk
:
data:image/s3,"s3://crabby-images/063ba/063baba5db83106d9b1278c6201dfa6a5c980a17" alt="binwalk"
Extract with binwalk
:
data:image/s3,"s3://crabby-images/e2ae1/e2ae1d60604f6f0d6113b0598974aca725758964" alt="binwalk_extract"
Decode ROT13 with CyberChef:
data:image/s3,"s3://crabby-images/3f2dc/3f2dcd1a0855eb0ed67b7e2001551be424153c59" alt="rot13"
http://192.168.1.29/gn483gfuner98g
:
data:image/s3,"s3://crabby-images/34577/34577defa660724e1fb50e55b8fc03fc5e42355c" alt="gn483gfuner98g"
Generate username/password according to http://192.168.1.29/passwordlist.txt
and /etc/passwd
:
data:image/s3,"s3://crabby-images/477c5/477c56aa6a702c85c32065100baa58106afcec2b" alt="passwordlist"
hydra
:
data:image/s3,"s3://crabby-images/fa780/fa78013a1649c33d0b1b38b452d6cbe42681c282" alt="hydra_cysec"
Load /home/cysec/use_scapy_with_your_attack_analyze_me_to_understand.pcapng
with wireshark
:
data:image/s3,"s3://crabby-images/0a7ff/0a7ffbd530638f2602c45c681af78a17f580ec16" alt="answer.txt"
Enumerate ports:
data:image/s3,"s3://crabby-images/71618/716183388d576fa4c19c6db21b2ef58e5e2422cd" alt="ports"
nc
8889
with answer.txt
:
data:image/s3,"s3://crabby-images/6e45f/6e45fd5342324922a91cfebefcc79ff9b391fcd9" alt=""
Login as user root:
data:image/s3,"s3://crabby-images/8b1fa/8b1faaeedafbcb521c465f01d86473d878280da5" alt="ssh_root"
http://192.168.1.29/index.html
:
data:image/s3,"s3://crabby-images/d1aa3/d1aa3f3d42929bf081bf72c0007568647f91d7c8" alt="index.html"
/home/cysec/ftp/upload/file.txt
:
data:image/s3,"s3://crabby-images/65668/65668e9fa0a24c57f8fe4b5c529bb1e3268af66e" alt="file.txt"
/root/udpserver/udp_server.py
:
data:image/s3,"s3://crabby-images/da532/da5326da21e4698ac11b57866d313e4bcd535151" alt="udp_server.py"