Port enumeration

Using nmap, I found port 22/TCP open.

nmap -p- --open -vvv -n -Pn -T5 10.129.238.52 -oG allPorts.txt

854b0870e43daf4dbae677fd130ee337.png And also port 500/UDP.

nmap -p- --open -vvv -sU -n -Pn -T5 10.129.238.52 -oG allPorts.txt

ef2c6737698ed5b722b3a74170e806d2.png

Ike-scan

Using ikes-can I obtained the handshake.

ike-scan -A 10.129.238.52 --pskcrack=handshake.txt

67299a4ee63cb77569ab91b3795fcd46.png 3883f2b8cd1dc1bdceef959d9f5cf786.png Now, using psk-crack I cracked the password.

psk-crack -d /usr/share/wordlists/rockyou.txt hanshake.txt

045c637a822460b5360137eb88f74c8f.png Using this password, I log as ike with ssh. ca262b434ebc564cc900c671c99ce6c2.png

Privilege escalation

I found that the sudo version is vulnerable. 7b6143a20a726166286cbb9fc551c583.png 0889ec9908404ab2d0523d58701ef81f.png Using a exploit, I get a root shell. c9d3e334f0e636055e46ee8f45823bda.png