Lampiao

Hey we are targeting lampiao machine

Starting with an nmap scan (full scan took a million years to finish, i loked at a writeup to get the full scan result)

image

Looking at the webpage on port 1898, we can find 2 users has comments on the page (2 users) quickly

image

Try to create an account & we wait for admin approval, which isn’t playing nice with us

looking at /robots.txt we find a lot of stuff on there

image

visiting different endpoints found from /robots.txt & we find interesting stuff from /CHANGELOG.txt also /web.config

Here we see the cms runs drupal 7, looking around & we can see it’s associated with a lot of vulnurabilities, you can get foothold by exploiting drupal 7

What i did here was generate a wordlist using cewl & password spray the found usernames with generated wordlist & i got a valid password used to ssh as Tiago

image

Using found valid password to login ssh as tiago user & we can read local.txt

Also checking for sudo permisson shows that the user tiago may not run commands as sudo

image

Now getting linpeas & linux exploit suggester on target machine looking for privilege escalation means & there are a lot

I decided to exploit pwnkit A.K.A CVE-2021-4034 & become root!

image

####RESOURCES

https://portal.offensive-security.com/proving-grounds/play




Enjoy Reading This Article?

Here are some more articles you might like to read next:

  • Google Gemini updates: Flash 1.5, Gemma 2 and Project Astra
  • Displaying External Posts on Your al-folio Blog
  • Statica — Bypassing AI Assistant Secret Masking
  • Ashwick
  • Snobble AI