Vulnhub: Funbox: Easy Walkthrough (OSCP PREP) [by dollarboysushil]
data:image/s3,"s3://crabby-images/83253/8325305c6d1f262e8e085c70a06ec4a410a072ec" alt=""
Link to Vulnhub: https://www.vulnhub.com/entry/funbox-easy,526/
You can play this machine free from here: https://portal.offsec.com/labs/play
Difficulty:
Easy
Goal:
Read flag inside /root
Victim IP: 192.168.220.111
Attacker IP (Kali Linux): 192.168.45.165
For any correction / query /suggestion contact on
Instagram dollarboysushil
Twitter (X) dollarboysushil
Youtube dollarboysushil
Reconnaissance
data:image/s3,"s3://crabby-images/d89c3/d89c395c2e06f2a2cc56aedacc92de4ef6d1be42" alt=""
Frist run command nmap 192.168.220.111
to view the open ports. Which reveals two ports 22 adn 80. Then run nmap -sC -sV -p 22,80 192.168.220.111
-sC
for default scripts,-sV
for version enumeration and -p
to specify the ports.
Looking at the result we can see
port 22 ssh
port 80 http
data:image/s3,"s3://crabby-images/1825a/1825a197f8fe6cb84f6a3681f813e6baee704b89" alt=""
Visiting the ip, you can see simple apache default page.
data:image/s3,"s3://crabby-images/e541c/e541cb00160842871414ea9cebdab30f65b3da50" alt=""
Then running gobuster reveals hidden directory,/store
/admin
and /secret
data:image/s3,"s3://crabby-images/a2c3a/a2c3a0d05702f34001f394abc69ce751ce643abe" alt=""
At /store
, we can see online CSE bookstore.
If you do simple search for CSE bookstore we can see it is vulnerable to Unauthenticated Remote Code Execution exploit
I will not be using this exploit. I will do manual process.
data:image/s3,"s3://crabby-images/d0cd3/d0cd33adaa36ff4ac0171657eb7f4e62af692f7b" alt=""
In the CSE backstore login page, I tried to enter some default credentials
and luckly admin:admin
woked
data:image/s3,"s3://crabby-images/f98c1/f98c1c65b27858f259e06f8851ae96989b33c852" alt=""
After successful login, we are greeted with section to add new book and we have option to edit added books.
data:image/s3,"s3://crabby-images/14450/144501d0b018ea09a910f4ce647d9820ff39259e" alt=""
When clicking on edit option, we are greeted with this section. If you look closely, we have option to upload files.
With this option, our next step would be to upload a reverse shell and get ourself a shell.
So lets prepare a reverse shell.
I will be using php reverse shell from pentestmonkey
Download the php script.
data:image/s3,"s3://crabby-images/f351a/f351a37d3678368787d6341831bfdd3726740931" alt=""
Make sure to change the $ip
to your attacker’s machine’s ip. Changing $port
is optional, we will need this later.
After changes are done, save and upload this reverse shell.
We have successfully uploaded the reverse shell, now we need to find the location where it is stored.
data:image/s3,"s3://crabby-images/ca4ae/ca4aeb448662e140aecde08b1c6d0e7e4ead3afe" alt=""
To find the location, I again ran gobuster and found some interesting directories.
Among which /bootstrap
is what we need.
data:image/s3,"s3://crabby-images/51816/518167af556a2a800f83681a7396735a99f28d5f" alt=""
data:image/s3,"s3://crabby-images/b495b/b495b6ea259c2434669757cc9ac1143daf1615c7" alt=""
Under /bootstrap/img
we can see our reverse shell stored.
Before running the reverse shell, we need to make sure netcat listner is ready.
data:image/s3,"s3://crabby-images/4d432/4d4326a50a15ccf07f71ea5926a41da89fd214c0" alt=""
To make netcat listener ready, use command nc -lnvp 443
use same port you used in the reverse shell file.
Now we are ready, simply click the reverse shell from /bootstrap/img
data:image/s3,"s3://crabby-images/e8d41/e8d416dcda57adcb6fe2b63a1f26f9b7994f63fe" alt=""
And we have shell as www-data
data:image/s3,"s3://crabby-images/352d0/352d0b6bf11411d56974bf17703f09b1b8807bf9" alt=""
Under /home
we can see one user tony
under /home/tony
we have jackpot password.txt
ssh: yxcvbnmYYY
gym/admin: asdfghjklXXX
/store: admin@admin.com admin
we now have ssh password, lets try to login.
data:image/s3,"s3://crabby-images/23444/23444c4c64b4c6742a2190d17d09880600901584" alt=""
And we are successfully logged in as user tony
.
Our next step to get root access.
data:image/s3,"s3://crabby-images/efd5e/efd5ecc6118b275c44f6e8262764cdc1642a51b2" alt=""
Running command sudo -l
we can see some interesting things.
User tony can above command as root.
Which we can use to get a root shell.
Lets use GTFOBins
data:image/s3,"s3://crabby-images/7b77e/7b77e7d2dc8cd7cb618eff59a6405cea88399e07" alt=""
From the result of sudo -l
I searched for each entries, and we have some interesting thing for binary pkexec
We can use pkexec
to drop elevated privilges.
data:image/s3,"s3://crabby-images/59100/59100a8975fd6fb71879de38e713016c0fb4d3fb" alt=""
Running sudo pkexec /bin/sh
We have root shell.
data:image/s3,"s3://crabby-images/344b7/344b73e589cd7fb4d95f6251486dd245d50e92b5" alt=""
And we can read the flag proof.txt
7ad87c789be895d7bde85d9216c16e8e
For any correction / query /suggestion contact on
Instagram dollarboysushil
Twitter (X) dollarboysushil
Youtube dollarboysushil