RandomUser888dda
Static Analysis Expert
2
MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1
100 XP
data:image/s3,"s3://crabby-images/7a837/7a83793c5086f9c985e2a3dba24488714c13e171" alt="2-17.png"
Hey Folks, today we are going to solve another boot2root challenge vulnerable VM machine called “CyberSploit: 2“. This machine is made by Cyberspace which is an easy level lab. There is no flag
data:image/s3,"s3://crabby-images/709f8/709f87e145eec9c0f67b84857342a4ace8ba030e" alt="Triangular flag :triangular_flag_on_post: 🚩"
Machine Details
Author: CyberSploit
Series: CyberSploit
Lets do it
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Slightly smiling face :slight_smile: 🙂"
Reconnaissance
Like always, first we will find the host IP address of vulnerable machine by using the “netdiscover” command.
netdiscover1netdiscover
data:image/s3,"s3://crabby-images/320d9/320d9bc472f392aacb0bb96ba8d2291006edbfa0" alt="1-se-phele-1.png"
We got target IP address and now our next step is to find open ports using the Namp tool.
nmap -p- -A 192.168.0.1051nmap-p--A192.168.0.105
data:image/s3,"s3://crabby-images/70622/70622003cf4cba6e38238e534ad7439d287269b7" alt="1-13.png"
The port 80 is running on that machine. After browse the IP address we got a multiple credentails but lets check the page source.
data:image/s3,"s3://crabby-images/9eea0/9eea05682a04f220674a1634bc284592777e9908" alt="2-16.png"
Alright ! We found a ROT47 hint in the page source. Now we will decrypt the credentials in ROT47 which are given on the front page.
data:image/s3,"s3://crabby-images/3e370/3e3705a2c589291fa01dd765e2cb06aa30b89a8e" alt="3-12.png"
We uses the cyber chef github project for this kind of challengers. After decrypts the code we got a user and password.
data:image/s3,"s3://crabby-images/8aca1/8aca1aa327eea2acdac3a4395ab563811baba2fe" alt="4-12-1024x450.png"
username – shailendra
password – cybersploit1
We access the ssh service with the obtained username and password.
ssh [email protected] [email protected]
data:image/s3,"s3://crabby-images/83a9a/83a9a7a5b8598a8746646efcc24c9d86564fa9fc" alt="5-12-1024x185.png"
After login we get another hint which has dcoker written in it.
data:image/s3,"s3://crabby-images/77472/7747220902d332167f511969dbc92f1a02b24afa" alt="6-11.png"
Privilege Escalation
After search we found a docker shell on gfobins website that can be used to break out from restricted environments by spawning an interactive system shell.
data:image/s3,"s3://crabby-images/48e4e/48e4eda6e29a0112e30ed48a45cdbbe65481e899" alt="7-9.png"
After executing this we get final flag in the root directory.
docker run -v /:/mnt --rm -it alpine chroot /mnt sh1docker run-v/:/mnt--rm-it alpine chroot/mnt sh
data:image/s3,"s3://crabby-images/507e0/507e0cd60c16dfe26c5c786cdd9a5b5b07e71ee4" alt="8-8.png"