> For the complete documentation index, see [llms.txt](https://rodgar.gitbook.io/rodgar/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://rodgar.gitbook.io/rodgar/plataformas/the-hackers-labs/the-hackers-labs-offensive.md).

# The Hackers Labs Offensive

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2F2838BD3sbXrO3FuCTGWl%2F1.png?alt=media&amp;token=00f16f86-96df-4682-ac13-c8101e772341" alt=""><figcaption></figcaption></figure>

Iniciamos como siempre observando los puertos abiertos en la maquina.

***

```javascript
 nmap -sCV -p80,8080 172.16.241.216 -oN target.txt
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-12-31 15:57 EST
Nmap scan report for offensive.thl (172.16.241.216)
Host is up (0.00070s latency).

PORT     STATE SERVICE VERSION
80/tcp   open  http    Apache httpd 2.4.62 ((Debian))
|_http-generator: WordPress 6.7.1
|_http-server-header: Apache/2.4.62 (Debian)
|_http-title: rodgar
8080/tcp open  http    Node.js Express framework
|_http-title: Error
MAC Address: 00:0C:29:6E:9D:15 (VMware)
```

Versiones y servicios que corren para cada uno de los puertos.

***

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2FaqtJRvJ9k1rLMoeoToUW%2F2.png?alt=media&amp;token=5ad15fbd-b8d6-4234-8bb8-f4692fbd74ab" alt=""><figcaption></figcaption></figure>

Si vamos a la web observamos un servicio simple.

```javascript
whatweb -v http://offensive.thl/
WhatWeb report for http://offensive.thl/
Status    : 200 OK
Title     : rodgar
IP        : 172.16.241.216
Country   : RESERVED, ZZ

Summary   : Apache[2.4.62], HTML5, HTTPServer[Debian Linux][Apache/2.4.62 (Debian)], MetaGenerator[WordPress 6.7.1], Script, UncommonHeaders[link], WordPress[6.7.1]

Detected Plugins:
[ Apache ]
	The Apache HTTP Server Project is an effort to develop and 
	maintain an open-source HTTP server for modern operating 
	systems including UNIX and Windows NT. The goal of this 
	project is to provide a secure, efficient and extensible 
	server that provides HTTP services in sync with the current 
	HTTP standards. 

	Version      : 2.4.62 (from HTTP Server Header)
	Google Dorks: (3)
	Website     : http://httpd.apache.org/

[ HTML5 ]
	HTML version 5, detected by the doctype declaration 


[ HTTPServer ]
	HTTP server header string. This plugin also attempts to 
	identify the operating system from the server header. 

	OS           : Debian Linux
	String       : Apache/2.4.62 (Debian) (from server string)

[ MetaGenerator ]
	This plugin identifies meta generator tags and extracts its 
	value. 

	String       : WordPress 6.7.1

[ Script ]
	This plugin detects instances of script HTML elements and 
	returns the script language/type. 


[ UncommonHeaders ]
	Uncommon HTTP server headers. The blacklist includes all 
	the standard headers and many non standard but common ones. 
	Interesting but fairly common headers should have their own 
	plugins, eg. x-powered-by, server and x-aspnet-version. 
	Info about headers can be found at www.http-stats.com 

	String       : link (from headers)

[ WordPress ]
	WordPress is an opensource blogging system commonly used as 
	a CMS. 

	Version      : 6.7.1
	Aggressive function available (check plugin file or details).
	Google Dorks: (1)
	Website     : http://www.wordpress.org/

HTTP Headers:
	HTTP/1.1 200 OK
	Date: Tue, 31 Dec 2024 21:01:00 GMT
	Server: Apache/2.4.62 (Debian)
	Link: <http://offensive.thl/index.php/wp-json/>; rel="https://api.w.org/"
	Vary: Accept-Encoding
	Content-Encoding: gzip
	Content-Length: 8864
	Connection: close
	Content-Type: text/html; charset=UTF-8

```

Si hacemos un whatweb observamos que hay un CMS wordpress en especifico.

***

```javascript
 wfuzz -c -t 200 --hc=403,404 -w /usr/share/wordlists/dirb/common.txt -u 'http://offensive.thl/FUZZ'
 /usr/lib/python3/dist-packages/wfuzz/__init__.py:34: UserWarning:Pycurl is not compiled against Openssl. Wfuzz might not work correctly when fuzzing SSL sites. Check Wfuzz's documentation for more information.
********************************************************
* Wfuzz 3.1.0 - The Web Fuzzer                         *
********************************************************

Target: http://offensive.thl/FUZZ
Total requests: 4614

=====================================================================
ID           Response   Lines    Word       Chars       Payload                                                                                      
=====================================================================

000001991:   301        9 L      28 W       315 Ch      "images"                                                                                     
000002021:   301        0 L      0 W        0 Ch        "index.php"                                                                                  
000002145:   301        9 L      28 W       319 Ch      "javascript"                                                                                 
000004485:   301        9 L      28 W       317 Ch      "wp-admin"                                                                                   
000004501:   301        9 L      28 W       320 Ch      "wp-includes"                                                                                
000004495:   301        9 L      28 W       319 Ch      "wp-content"                                                                                 
000000001:   200        213 L    1261 W     38827 Ch    "http://offensive.thl/"                                                                      

```

Si hacemos una enumeracion de sub/directorios pues llegamos a ellos pero el unico que nos muestra contenido es images los demas no tenemos directory listen o directamente un 404.

***

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2FBnqRbj6hHx5CmR89aAkF%2F3.png?alt=media&amp;token=287a25f9-bfec-4c12-b95f-631af07a61a1" alt=""><figcaption></figcaption></figure>

La imagen ahora vamos a descargarla y haber si hay algo.

***

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2Fca8A9S8wNf3T1y0bEQip%2F4.png?alt=media&amp;token=845396a0-c044-4706-ad78-f27d1055997f" alt=""><figcaption></figcaption></figure>

Vamos por punto.

* Primero intentamos extraer el contenido que haya usando steghide, tiene contraseña.
* Asi que usamos esta segunda herramienta llamada stegseek que es para hacer fuerza bruta directamente.
* Ultimo punto obtenemos credenciales para extraer el contenido, lo extraemos y tenemos una contraseña que debido al nombre de la imagen es para el panel de autenticacion del wordpress.

***

```javascript
wpscan --url http://offensive.thl --enumerate u

[i] User(s) Identified:

[+] administrator
 | Found By: Rss Generator (Passive Detection)
 | Confirmed By:
 |  Wp Json Api (Aggressive Detection)
 |   - http://offensive.thl/index.php/wp-json/wp/v2/users/?per_page=100&page=1
 |  Author Id Brute Forcing - Author Pattern (Aggressive Detection)
```

Tenemos un usario y una contraseña pero no podemos acceder al panel, vamos a ver el puerto 8080 haber que hay por ahi.

***

## Puerto 8080

```javascript
 wfuzz -c -t 200 --hc=403,404 -w /usr/share/wordlists/dirb/common.txt -u 'http://offensive.thl:8080/FUZZ'
 /usr/lib/python3/dist-packages/wfuzz/__init__.py:34: UserWarning:Pycurl is not compiled against Openssl. Wfuzz might not work correctly when fuzzing SSL sites. Check Wfuzz's documentation for more information.
********************************************************
* Wfuzz 3.1.0 - The Web Fuzzer                         *
********************************************************

Target: http://offensive.thl:8080/FUZZ
Total requests: 4614

=====================================================================
ID           Response   Lines    Word       Chars       Payload                                                                                      
=====================================================================

000001887:   200        0 L      17 W       203 Ch      "Help"                                                                                       
000001886:   200        0 L      17 W       203 Ch      "help"                                                                                       
000002376:   200        0 L      1 W        176 Ch      "ls"                                                                                         
000000777:   500        0 L      3 W        31 Ch       "cat"          
```

Tenemos 4 directorios observaremos el help, que suena a panel de ayuda.

***

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2FeiVeJkuK0HvCr9sLznUk%2F5.png?alt=media&amp;token=d8f4af20-3881-443e-bc14-d40a02fda7b4" alt=""><figcaption></figcaption></figure>

Help nos muestra este panel.&#x20;

***

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2Froa7ifxOhX1dNfGkX08t%2F6.png?alt=media&amp;token=6beb260d-076f-4293-9eb5-79146f5deef9" alt=""><figcaption></figcaption></figure>

Con el parametro ls, nos dirigimos a la ruta plugins del wordpress que corre para observar que plugins hay y asi observar que nos puede estar impidiendo llegar al panel del wordpress.&#x20;

WPS Hide Login es un complemento ligero que te permite cambiar de forma fácil y segura la URL de la página del formulario de inicio de sesión a lo que desees.

Esto nos esta bloqueando.

***

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2FieHEuJYZbItdJhIEOwPA%2F7.png?alt=media&amp;token=1965ee68-ff8a-435d-8210-e8e91e5296d4" alt=""><figcaption></figcaption></figure>

Borramos el plugins con la funcion que tenemos rm. Ahora ya deberiamos poder acceder al panel administrativo del wordpress.

***

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2FP5Oqps4d1gxv142a3CP7%2F8.png?alt=media&amp;token=cd8223aa-a3dc-4aec-82cb-98d310da4dbc" alt=""><figcaption></figcaption></figure>

Ya podemos llegar y iniciamos session con las credenciales que tenemos.

***

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2FnqRxwgKDjKfHf0vLCyQ7%2F9.png?alt=media&amp;token=317b93fe-f67e-4370-9ed1-2c962a9c171b" alt=""><figcaption></figcaption></figure>

Nos enviamos una revshell usando el plugin que hay ahi.

***

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2FfkOzGr44gWHugGMbMCr1%2F10.png?alt=media&amp;token=b3be9b10-9325-45f6-ae6c-887b72a03823" alt=""><figcaption></figcaption></figure>

Buscando la forma de escalar privilegios, encontramos un servicio que corre interno en el puerto 5000 puerto que desde fuera no logramos ver pero internamente si.

Vamos a hacer un portfor usando chisel, yo useo chisel.

***

En estos articulos explico lo que vamos a hacer acontinuacion.

{% embed url="<https://rodgar.gitbook.io/rodgar/ctf-writeups/pivoting>" %}

***

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2FkRfsCt1fRKXQ2p9YhNUQ%2F11.png?alt=media&amp;token=1d30c5e2-037f-4ac7-9477-0712a34400d6" alt=""><figcaption></figcaption></figure>

* Como punto numero uno nos ponemos como cliente desde nuestra maquina atacante.
* Y como segundo nos conectamos como cliente.

***

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2F12co7ZFTLkoo0NJm6zyt%2F12.png?alt=media&amp;token=a1f62e1e-a0d0-4162-8e82-92428643063c" alt=""><figcaption></figcaption></figure>

Ahora que podemos llegar al puerto observamos este panel donde debemos averigurar la combinacion correcta ya que ya tenemos las credenciales.

***

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2FlBz0rkvbZgzblbKU8KVZ%2F13.png?alt=media&amp;token=9991206b-1e87-48b7-b53b-c1104231807b" alt=""><figcaption></figcaption></figure>

Interceptamos la peticion con Burp y ahora nos creamos una lista de posibles pings usando seq.

***

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2FI8wbAhGxq5uUMLxQStFo%2F14.png?alt=media&amp;token=8f1b601b-acda-4fee-aa20-e025e5e8e940" alt=""><figcaption></figcaption></figure>

Ok lo tenemos listo fijado ya.

***

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2FznsXcCRTwa3dTEYKIXp5%2F15.png?alt=media&amp;token=1d91dedf-fed6-4ca3-b369-fcdaf88d3b16" alt=""><figcaption></figcaption></figure>

Este codigo ping  es diferente con su codigo de estado a los demas lo probaremos.

***

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2FfgDwYOpRbf5tBRHvwUGD%2F16.png?alt=media&amp;token=36fb609a-7185-4d06-a74e-5659a3bd33d7" alt=""><figcaption></figcaption></figure>

Entramos a un panel que lo ejecuta maria.

***

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2F0ATklcyaArstAGtRg7xu%2F17.png?alt=media&amp;token=b225c42b-e360-49d0-95a5-7fc52f515508" alt=""><figcaption></figcaption></figure>

Nos enviamos una revshell.

***

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2FrVhYzwVBj9N0hIRWuHAo%2F18.png?alt=media&amp;token=09346a2a-b45e-44dc-997e-747aa8c10366" alt=""><figcaption></figcaption></figure>

* Primer punto podemos ejecutar una aplicacion en el directorio de maria,  que hace un cat del /etc/shadow donde no me lo muestra todo si no que solo las primeras lineas lo que podria ser un indicativo que se esta usando head para hacerlo.
* Y segundo tenemos la flag de user.

***

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2FIQrhmEgcwUH3PtWhH0a0%2F19.png?alt=media&amp;token=86a99952-5f1b-4593-9bce-99844f8ac40e" alt=""><figcaption></figcaption></figure>

Si hacemos un strings para ver las cadenas imprimibles filtrando por head observamos que lo estan empleando dos veces de manera relativa y absoluta para catear las primeras lineas del etc/shadow.

Esto lo podemos deribar a un PATH Hijaking.

***

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2FuTCDQRAPbjkis5elCsvd%2F20.png?alt=media&amp;token=d2ed21bf-548b-47b5-a863-84feae72ea8b" alt=""><figcaption></figcaption></figure>

* Punto uno nuestro directorio actual /home/maria.
* Segundo observamos donde inicia el recorrido.
* Tercero exportamos el PATH para que el recorrido no inicie por /usr/ si no por /home/maria.
* Observamos que ahora inica en /home y no en /usr.

***

<figure><img src="https://1827363921-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEGJvvgIusdsLKeoExX1C%2Fuploads%2F8jJVjheween7K6ATOJS0%2F21.png?alt=media&amp;token=964ad032-db95-4527-a4fd-dfebee22778c" alt=""><figcaption></figcaption></figure>

Somos root maquina resuelta.
