a0d6f3d4755c75778a2ff9b31672cc48.png

Port enumeration

nmap reveals 4 open ports.
da5fe7233ed430078983b6175f35a72a.png
c86b68359c73b43797530ba9c3558adf.png
SSH, HTTP, HTTPS and one unknown service in 6661.

Web enumeration

ca98ddec22c9a31221af6082074c4f3d.png
We need to access using the port 443, and we will see a Mirth Connect instance.
After a short research, I found a RCE for this service.
e220f525c3bd0c7c92df5242d2eaccb3.png
Using one of the public exploit I check and confirm the vulnerability.
dbda1aa548d66012001d3882fc7efefc.png

Initial exploitation

Using this same exploit, I create a reverse shell.
e33e0b6a642ce538b1a3844926b24b39.png

Local enumeration

The first thing who i can see is the name of the user.
35e7fee477f42ccf46732c1f5cf6fc45.png
Also, I found an active MySQL database.
559f28f96bcafca2f46515b56381f676.png
In the config files, I found the database credentials.
a34465afda91e1de0c1dd8fb2bdb7230.png

Database enumeration

Looking the database tables, I found a very interesting one.
938169b4a94e92190593aad61e635795.png

Hash cracking

According of documentation, this hash is using a PBKDF2-HMAC-SHA256 algorithm.
94639276d1e0bf907e2947da7e7960db.png
9d18fe3b206a0b858792ebfd5185b72b.png
This alcorytm is a bit special, to crack it, I need to encode hash and salt in bas64.
6cc96dd02c5373fa350d2c994e977c68.png
Now, to breack it with hashcat, we need to write the hash file in the next format.
36b1741adbbedd73a0715d7087b699c6.png
Now, we use the next command

hashcat -a 0 -m 10900 hash.txt /usr/share/wordlists/rockyou.txt

With that, I am able to crack the password.
a83141933a3be02a96227272e93f17ea.png
With that password, I can log as sedric and take the user password.
101e3d6abe765fb9258c50ba08828c5b.png

Privilege escalation

I found a readable root file, a python script.
900e7aea9eeab84abb3793e01692c5e6.png
It looks like a flask app who runs in 54321 port.
c6d29e01a253c9a88ba1c729b3b84a63.png
This app is vulnerable to RCE due to the use of eval.
30460deb14890b473c372dbf2ce63801.png
And the user running it is root.
ed65763f645ff8be0217943b779f0e90.png
And its running in a local port.
826e79f36a0cd4f8af0ca497a5227541.png

Port forwarding

I use ssh to make this port forwarding.
764a9889c6137c9cadb5df7ababee555.png
Now, i am able to access this page in the attacker machine.
4abafee3e05f47f84b94c27ef37d6dbd.png

RCE

To execute code, we just need to import the library os and use the command popen.
b2b0234854a49ede6334847d761cc00e.png
And, with this, we can obtain the flag.
But, we cant use commands with any type of space, so, I need another way to read the flag.
3bdb5d2b1096fb0907b430714f25d230.png
And with this, its done,
ffe76b444a88bddbcb00120903801c73.png