Scanning and Enum3ration
First thing I do is find the ip address and port scan, after that I find the active Apache server on port 13370.
data:image/s3,"s3://crabby-images/39bfc/39bfc13f70dae14d89ed34c9a9477e74473c41fa" alt=""
arp-scan -l
nmap 192.168.2.102
After going to a webpage, I see a web site running on joomla.
data:image/s3,"s3://crabby-images/76a5f/76a5f94593959dd4bba6c83c970f2e7ee209b6b9" alt=""
Getting shell
In source code of page you can find the version of joomla.
data:image/s3,"s3://crabby-images/aa3ad/aa3ad02138bea87d19b762b1e68c7e555f923804" alt=""
Yeah, this version of joomla has many vulnerabilities, but in this case I need an exploit for changing the administrator password (Joomla! 1.5.x - 'Token' Remote Admin Change Password).
data:image/s3,"s3://crabby-images/393a9/393a957ae721d55b22dfae38a207ddbf1016e116" alt=""
searchsploit joomla 1.5
After changing the administrator password, I successfully login into the site control panel.
data:image/s3,"s3://crabby-images/4fd76/4fd769c6f7bcbfc8d0573b5e6a040f132bc297e8" alt=""
After loading php reverse shell i get www-data.
data:image/s3,"s3://crabby-images/5214b/5214b7c90ccd5dac60ff6f9699d3e01b2d208e18" alt=""
Privil3ge escalation
In running processes you can see running Chkrootkit 0.49
data:image/s3,"s3://crabby-images/18c43/18c434ceec3b8f81b1d72423eb309393299fdac4" alt=""
ps -aux
data:image/s3,"s3://crabby-images/ddb8f/ddb8f1c027375ab77fd59b52613973e92bf84c47" alt=""
After analyzing the vulnerability on exploitdb, I realized that I needed to create a file in the / tmp directory that should change the administrator password.
data:image/s3,"s3://crabby-images/9f25b/9f25b84b4889f1db456103be6d76ff6abb3ed77c" alt=""
Now connect via ssh and get root.
data:image/s3,"s3://crabby-images/f5823/f5823e5554c7f76bd03c2ff857126099770f000e" alt=""