Posts

Showing posts with the label shellshock

Hack the Box - Beep - Walkthrough

Image
Introduction Today we're going to be doing a pentest walkthrough of the Beep machine hosted at https://hackthebox.eu . For this pentest, we'll be using a Kali Linux virtual machine as our attacking system and the Beep machine as the victim system. After connecting to the Hack the Box network via VPN, we see that our target is located at 10.129.100.242. Scanning and Enumeration We'll start by scanning for open ports with Nmap : sudo nmap -T4 -p- 10.129.100.242 Now we'll do another Nmap scan, this time specifying the ports and picking up service names and version numbers: nmap -sV -T4 -p22,25,80,110,111,143,443,942,993,995,3306,4190,4445,4559,5038,10000 10.129.100.242 There's a lot of output here, but let's take a look at the HTTP service on port 10000: https://10.129.100.242:10000/  Interesting-looking web-app. Let's take a look at the source: view-source:https://10.129.100.242:10000/ The page references a CGI script. Let's check if the script is di...

Hack the Box - Shocker - Walkthrough

Image
Introduction Today we're going to be doing a pentest walkthrough of the Shocker machine hosted at https://hackthebox.eu. For this pentest, we'll be using a Kali Linux virtual machine as our attacking system and the Shocker machine as the victim system. After connecting to the Hack the Box network via VPN, we see that our target is located at 10.129.1.175. Scanning and Enumeration We'll start by scanning for open ports with Nmap : sudo nmap -T4 -p- 10.129.1.175 Now we'll do another Nmap scan, this time specifying the ports and picking up service names and version numbers: sudo nmap -T4 -p80,2222 10.129.1.175 There's an Apache webserver on port 80, so let's enumerate web directories with Gobuster : gobuster dir -u  http://10.129.1.175/  -w /usr/share/wordlists/dirb/big.txt -x php,txt,html -r -s 200,204,301,302,307,403 An easy win on Linux systems is the Shellshock vulnerability, which requires access to the web server's /cgi-bin directory. ...

Sumo Walkthrough

Image
Introduction Today, we're going to be doing a boot2root walkthough of the Sumo machine, created by the SunCSR Team, and hosted on Vulnhub , at https://www.vulnhub.com/entry/sumo-1,480/ .  We'll be using two virtual machines for this walkthrough, our attacking Kali Linux machine, and the target Sumo machine.  Locating the Target First, let's locate the target machine on the network using netdiscove r : It seems like 10.0.2.7 is out target. Scanning and Enumeration Let's start our scans with a quick Nmap scan to see which TCP ports are open. Just a couple of open ports.  We'll also run the same sort of scan for UDP ports. Nothing there.  Let's do an in-depth scan with Nmap on the open ports that we found. We're able to glean a couple of details from this scan, the web server is Apache 2.2.22 , the SSH being used is OpenSSH 5.9p1 , and the OS is probably Linux, estimated to be Ubuntu. Next, we'll run a Nikto scan against the target's web ...