Opacity (RFI nullbyte bypass + .kdbx hash crack + pspy64 backup process LPE)
Starting Nmap 7.93 ( https://nmap.org ) at 2023-04-09 10:23 PKT [0/4]
Stats: 0:00:02 elapsed; 0 hosts completed (1 up), 1 undergoing SYN Stealth Scan
SYN Stealth Scan Timing: About 1.33% done; ETC: 10:23 (0:00:00 remaining)
Nmap scan report for 10.10.8.133
Host is up (0.18s latency).
Not shown: 65531 closed tcp ports (reset)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.5 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 3072 0fee2910d98e8c53e64de3670c6ebee3 (RSA)
| 256 9542cdfc712799392d0049ad1be4cf0e (ECDSA)
|_ 256 edfe9c94ca9c086ff25ca6cf4d3c8e5b (ED25519)
80/tcp open http Apache httpd 2.4.41 ((Ubuntu))
|_http-server-header: Apache/2.4.41 (Ubuntu)
| http-title: Login
|_Requested resource was login.php
| http-cookie-flags:
| /:
| PHPSESSID:
|_ httponly flag not set
139/tcp open netbios-ssn Samba smbd 4.6.2
445/tcp open netbios-ssn Samba smbd 4.6.2
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Host script results:
|_nbstat: NetBIOS name: OPACITY, NetBIOS user: <unknown>, NetBIOS MAC: 000000000000 (Xerox)
| smb2-security-mode:
| 311:
|_ Message signing enabled but not required
| smb2-time:
| date: 2023-04-09T05:24:45
|_ start_date: N/A
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 74.52 seconds
WEB ENUMERATION:

Directory Scan
CLOUD

We need to bypass the filter. We can try adding the nullbyte or # to bypass this filter.
Letβs make a shell.php on our attacker. and start a server.


PRIVESC [SYSADMIN]
In the /opt directorywe found something intresting.

On attacker side nc -lnvp 9898 > dataset.kbdx
On victim side run

Letβs crack this file Article
Cracking hash
keepass2john dataset.kdbx > hash

Letβs open this database. 

PRIVESC [ROOT]
Letβs transfer pspy64 to review running processes.

This is a script to tke the backup of the scripts reside in sysadmin. We need to temper the backup.inc.php to trigger a revershell.

Letβs create the backup.inc.php.


Last updated