Sitemap

Shenron: 1 Vulnhub Writeup

3 min readMar 8, 2021

Difficulty: Easy/Medium

NMAP:

Press enter or click to view image in full size

Default port 22 and 80 let’s enumerate with gobuster you will find /test/password and we got the user and password for the website, enumerate more with gobuster and you will find /joomla/administrator

Press enter or click to view image in full size

Insert the credentials

Press enter or click to view image in full size

Navigate on “templates”

Press enter or click to view image in full size

And type on “Protonstar”

Press enter or click to view image in full size

Go in index.php

Press enter or click to view image in full size

And now we can upload our reverse shell. In you terminal type: locate php-reverse-shell.php and copy it in you folder

Press enter or click to view image in full size

Now put in, and instert your ip and your port and listen with netcat! Click on save.

Now click on Template review and we are in!!!

Press enter or click to view image in full size

Now enumerate more in www-data! Navigate in /var/www/html/joomla and there is a file called “configuration.php” , this file contain Mysql credential, but if you try to enter in Mysql there is a Rabbit hole!

Press enter or click to view image in full size

This are the simple credential for user jenny, so enter in jenny!

HORIZONTAL PRIVILEGE ESCALATION:

Now we are in jenny and we notice that sudo -l , shenron have privilege

Press enter or click to view image in full size

Now create our RSA key

Press enter or click to view image in full size

Copy out key and put in /tmp of jenny’s shell.

Press enter or click to view image in full size

Now we can cp our RSA in shenron .ssh folder, let’s try!

Press enter or click to view image in full size

Nice , now we can login with shenron, so in our shell type:

Now type: find / -type -iname “password.txt” 2>/dev/null and you will find the password for shenron and type sudo -l , you will find /usr/bin/apt

VERTICAL PRIVILEGE ESCALATION:

And! we are ROOT!

I hope this is usefull!

-0xJin

--

--

N0t0d4y
N0t0d4y

Written by N0t0d4y

CPTS | OSCP | OSWP | eCPTX | eWPTX | C|EH Master | CompTIA Security + | eJPT | CISM |

No responses yet