Addicted
Bounce Rate Optimizer
2
MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1
300 XP
Hello friends! Today we are going to take another boot2root challenge known as “unknowndevice64: 1”. The credit for making this VM machine goes to “Ajay Verma” and it is another boot2root challenge in which our goal is to get root access to complete the challenge. You can download this VM here.
Security Level: Beginner
Penetrating Methodology:
Walkthrough
Let’s start off with scanning the network to find our target.
We found our target –> 192.168.1.104
Our next step is to scan our target with nmap.
The NMAP output shows us that there are 2 ports open: 1337(SSH), 31337(HTTP)
We find that port 31337 is running HTTP, so we open the IP in our browser. Here we find a string “h1dd3n” that might bea hintor a password for something.
We take a look at the source code of the web page and inside acomment, we find a string called “key_is_h1dd3n.jpg”.
We open the image in our browser and download it in our system.
After downloading the image, we use steghide to extract any hidden file from the image. When we try to extract files using steghide, it prompts for a password. We use the password “h1dd3n” we found earlier on the webpage and were successfully able to extract a text file. We take a look at the content of the text file and find a brain fuck encoded string.
We decode the brainfuck encoded string using this site and find a username and password.
As port 1337 is running SSH, we use the credentials we found above tolog in. After logging in through SSH we find that we have a restricted shell, and PATH and SHELL environment variable areread-only.
After pressing the “tab” button twice, we find the commands we can run using the restricted shell. Amongthat command, we find that we can use the Vi editor. We use Vi editor to escape the restricted shell.
After escaping the restricted shell, we export “/bin/bash” as our SHELL environment variable and “/usr/bin” as our PATH environment variable so that we can run Linux commands properly. Now we check sudoers list and find we can run “/usr/bin/sysud64” as root withouta password.
On checkingthe helpfor “sysud64”, we find that it is actually executingstrace.
As we can run sysud64 as root and sysud64areactually runningthe stracecommand. We can spawn a shell as root user using “sysud64”. After spawninga shellasthe rootuser, we switch to the root directory and read our final flag.
Author: Sayantan Bera is a technical writer at hacking articles and cybersecurity enthusiast. Contact Here
Security Level: Beginner
Penetrating Methodology:
- IP Discovery using netdiscover
- Network scanning (Nmap)
- Surfing HTTP service port
- Finding image File
- Extractingthe hiddenfile fromthe image
- Logging in through SSH
- Escaping restricted shell
- Finding binary in sudoers list
- Gettingthe rootshell and findingthe flag
Walkthrough
Let’s start off with scanning the network to find our target.
Code:
netdiscover
data:image/s3,"s3://crabby-images/984ad/984ad71392a6b455c28be5498ae72c8ada66bd93" alt="1.png"
We found our target –> 192.168.1.104
Our next step is to scan our target with nmap.
Code:
nmap -p- -sV 192.168.1.104
data:image/s3,"s3://crabby-images/b510c/b510c130ec64aa07dc45cdbfe4f4224faab70233" alt="2.png"
The NMAP output shows us that there are 2 ports open: 1337(SSH), 31337(HTTP)
We find that port 31337 is running HTTP, so we open the IP in our browser. Here we find a string “h1dd3n” that might bea hintor a password for something.
data:image/s3,"s3://crabby-images/8454a/8454a7cb5063611356cb5d713aa79d986f96b698" alt="3.png"
We take a look at the source code of the web page and inside acomment, we find a string called “key_is_h1dd3n.jpg”.
data:image/s3,"s3://crabby-images/87aa1/87aa1f3b0173fa32a66547f1a65c4934df8d58c6" alt="4.png"
We open the image in our browser and download it in our system.
data:image/s3,"s3://crabby-images/6dbc0/6dbc0db3d0c39009839498d171a7a7960faef25e" alt="5.png"
After downloading the image, we use steghide to extract any hidden file from the image. When we try to extract files using steghide, it prompts for a password. We use the password “h1dd3n” we found earlier on the webpage and were successfully able to extract a text file. We take a look at the content of the text file and find a brain fuck encoded string.
Code:
steghide extract -sf key_is_h1dd3n.jpg
data:image/s3,"s3://crabby-images/f887c/f887cc6054ebb07f0209ef2b5f8ffd42d3622ec9" alt="6.png"
We decode the brainfuck encoded string using this site and find a username and password.
Code:
Username: ud64
Password: 1M!#64@ud
data:image/s3,"s3://crabby-images/82b51/82b51f1a193997e8b5c2019355e63c5cecb0bcbe" alt="7.png"
As port 1337 is running SSH, we use the credentials we found above tolog in. After logging in through SSH we find that we have a restricted shell, and PATH and SHELL environment variable areread-only.
Code:
ssh [email protected] -p 1337
data:image/s3,"s3://crabby-images/acc1b/acc1b22d3242c3170d0f71023cf93dcd55d9eb57" alt="8.png"
After pressing the “tab” button twice, we find the commands we can run using the restricted shell. Amongthat command, we find that we can use the Vi editor. We use Vi editor to escape the restricted shell.
Code:
:!/bin/bash
data:image/s3,"s3://crabby-images/88ba9/88ba9eaffb0cf5e3ff7dc6b041474d726e530e7b" alt="10.png"
After escaping the restricted shell, we export “/bin/bash” as our SHELL environment variable and “/usr/bin” as our PATH environment variable so that we can run Linux commands properly. Now we check sudoers list and find we can run “/usr/bin/sysud64” as root withouta password.
Code:
export PATH=/usr/bin:$PATH
export SHELL=/bin/bash:$SHELL
sudo -l
data:image/s3,"s3://crabby-images/a20b3/a20b3fff28f85aa0ecef8697726ec7c58f9293fa" alt="11.png"
On checkingthe helpfor “sysud64”, we find that it is actually executingstrace.
Code:
sudo sysud64 -h | less
data:image/s3,"s3://crabby-images/d139e/d139eb182ceb74f08b79f5359364a834f2be6d13" alt="12.png"
As we can run sysud64 as root and sysud64areactually runningthe stracecommand. We can spawn a shell as root user using “sysud64”. After spawninga shellasthe rootuser, we switch to the root directory and read our final flag.
Code:
sudo sysud64 -o /dev/null /bin/sh
data:image/s3,"s3://crabby-images/5339b/5339b6fa543f8e7fbddc208b6e8686d8cb7dd37c" alt="14.png"
Author: Sayantan Bera is a technical writer at hacking articles and cybersecurity enthusiast. Contact Here