> For the complete documentation index, see [llms.txt](https://hacking-3.gitbook.io/barre/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-3.gitbook.io/barre/write-up/dockerlabs/medio/mapache2.md).

# Mapache2

## Máquina

<figure><img src="/files/05RMGJMY6PPQxWv44JYq" alt=""><figcaption></figcaption></figure>

## Reconocimiento

### Nmap

```bash
sudo nmap -p- --open -sSCV --min-rate 5000 -vvv -n -Pn 172.17.0.2 -oN nmap.txt
```

```
PORT     STATE SERVICE REASON         VERSION
22/tcp   open  ssh     syn-ack ttl 64 OpenSSH 9.6p1 Ubuntu 3ubuntu13.5 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   256 2e:9e:60:04:ea:da:48:98:7a:e3:eb:f5:8e:25:83:33 (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBPh6UqEY++e9Kf6SVPV8+FwzeSzn1Sb0a5BjOpOhmjfJq4/cPpz7ZuUzWpqkjPx71va69nLnOVJ9eLaCuIq8hi4=
|   256 64:0a:26:78:24:8e:1a:75:54:5a:58:bc:f4:18:ce:4e (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIADa8Dt31nScLWTk1pM77PTDusyfx57GAuWtGyGFGRpA
80/tcp   open  http    syn-ack ttl 64 Apache httpd 2.4.58 ((Ubuntu))
| http-methods: 
|_  Supported Methods: GET POST OPTIONS HEAD
|_http-title: Hackerspace - Welcome
|_http-server-header: Apache/2.4.58 (Ubuntu)
3306/tcp open  mysql?  syn-ack ttl 64
| fingerprint-strings: 
|   NULL: 
|_    We have to change this, I told Medusa to protect this more.
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
SF-Port3306-TCP:V=7.94SVN%I=7%D=9/10%Time=66E080CF%P=x86_64-pc-linux-gnu%r
SF:(NULL,3C,"We\x20have\x20to\x20change\x20this,\x20I\x20told\x20Medusa\x2
SF:0to\x20protect\x20this\x20more\.\n");
MAC Address: 02:42:AC:11:00:02 (Unknown)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

### Gobuster

{% code overflow="wrap" %}

```bash
sudo gobuster dir -u 172.17.0.2 -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php,html,js,txt,zip,rar,tar,gz,css,xml,json,rb,py,jpg,jpeg,png,gif,svg,ico,pdf,sql,log,ini,conf,config,backup,sh,bash | tee gobusterExt.txt
```

{% endcode %}

```
===============================================================
Gobuster v3.6
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url:                     http://172.17.0.2
[+] Method:                  GET
[+] Threads:                 10
[+] Wordlist:                /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
[+] Negative Status codes:   404
[+] User Agent:              gobuster/3.6
[+] Extensions:              rar,gif,ico,js,py,jpeg,log,rb,tar,pdf,sql,zip,css,jpg,backup,html,config,sh,png,svg,bash,xml,gz,ini,conf,txt,json,php
[+] Timeout:                 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
/.html                (Status: 403) [Size: 275]
/.php                 (Status: 403) [Size: 275]
/index.html           (Status: 200) [Size: 3481]
/login.php            (Status: 200) [Size: 883]
/db.php               (Status: 200) [Size: 0]
/style.css            (Status: 200) [Size: 5859]
/logout.php           (Status: 302) [Size: 0] [--> index.html]
/.php                 (Status: 403) [Size: 275]
/.html                (Status: 403) [Size: 275]
/server-status        (Status: 403) [Size: 275]
Progress: 6396240 / 6396269 (100.00%)
===============================================================
Finished
===============================================================
```

### Web

<figure><img src="/files/Oe9a1t1GNE2dBKTD0gHZ" alt=""><figcaption></figcaption></figure>

Tenemos un panel de login el cual si probamos a hacer SQLi nos daremos cuenta de que no es vulnerable

<figure><img src="/files/VZLtQCjuohB1YKB0A02m" alt=""><figcaption></figcaption></figure>

Si ponemos el puerto 3306, encontraremos lo mismo que ya habíamos sacado anteriormente con nmap, el usuario medusa, el cual podemos intentar usar para hacer un ataque de brute force contra el login encontrado anteriormente.

<figure><img src="/files/DMaHqyX5kDJPoMdlD8ZX" alt=""><figcaption></figcaption></figure>

## Explotación

Hay 2 formas faciles de realizar un ataque de fuerza bruta a un login

### Burp Suite

Interceptamos la petición con Burp Suite para poder realizar un ataque de fuerza bruta ([Video](https://www.youtube.com/watch?v=3qN-DmxpokM))

<figure><img src="/files/4mNZaBif8v8imTn8TVpD" alt=""><figcaption></figcaption></figure>

Presionamos `CTRL + i` o click derecho sobre la petición y le damos a "`Send to Intruder`"

Una vez en la pestaña de `Intruder`, hay que seleccionar el campo en el cual queremos que se realicen las pruebas, y añadirlo, en este caso es el de password, ya que tenemos el usuario *medusa*

<figure><img src="/files/4rfSz71cfGtbWlzDp1yq" alt=""><figcaption></figcaption></figure>

A continuación, en el apartado Payloads, seleccionaremos el tipo de payload, en este caso Runetime file ya que le vamos a pasar el rockyou y ocupa demasiado para poder meterlo como una lista simple.&#x20;

<figure><img src="/files/jjIVVwUNwGbtWMVbPdt5" alt=""><figcaption></figcaption></figure>

Por ultimo cogeremos el mensaje de error al iniciar sesión que nos aparece en el panel de login y lo introduciremos en el apartado de Grep - Match, permitiéndonos filtrar por el campo que no tenga error&#x20;

<figure><img src="/files/BeoZ7iBeLxqJByTTENTo" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/DK8Iu9pU8MXjq8vQ7Gxg" alt=""><figcaption></figcaption></figure>

De esta manera ya estaría todo preparado para poder lanzar un ataque de fuerza bruta

<figure><img src="/files/cZw26QmIdI2TsfmOZQu9" alt=""><figcaption></figcaption></figure>

### Hydra

Para poder realizar este ataque hay que indicarle a *hydra* el método de envió, la ruta donde encontrar el panel de login, los campos para el payload y el mensaje de error que aparece al realizar un inicio de sesión incorrecto. ([Video](https://www.youtube.com/watch?v=XAlcVyx5FMA))

* Método -> POST
* Ruta -> /login.php
* Campos -> username=medusa\&password=`^PASS^`
* Mensaje de error -> Invalid credentials

{% code overflow="wrap" %}

```bash
hydra -l medusa -P /usr/share/wordlists/rockyou.txt 172.17.0.2 -t 64 http-post-form "/login.php:user=medusa&password=^PASS^:Invalid credentials"
```

{% endcode %}

{% hint style="info" %}
Con ^PASS^ indicamos el campo donde queremos que ejecute el payload&#x20;
{% endhint %}

<figure><img src="/files/fZgnGfS703MKVcZ0vW80" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
De la petición interceptada sacamos Método, Ruta y Campos y del login sacamos el mensaje de error
{% endhint %}

### Diccionario

{% hint style="danger" %}
Con el rockyou no hay forma de sacarlo o por lo menos tardas muchísimo
{% endhint %}

Usaremos la herramienta [`cewl`](#user-content-fn-1)[^1], que es una herramienta para extraer palabra de una web y generar una lista con estas palabras que pueden ser usadas como diccionario para descifrar la contraseña.

[Más información](https://esgeeks.com/como-utilizar-cewl/)

```bash
cewl http://172.17.0.2/ > cewl.txt
```

{% hint style="success" %}
Sustituyendo **rockyou** por este diccionario sacaremos con facilidad la contraseña
{% endhint %}

<figure><img src="/files/tiIf1hXYnWq2JrYCFzgs" alt=""><figcaption><p>Contraseña: enthusiasts</p></figcaption></figure>

Ahora podemos iniciar sesión y ver a donde nos lleva

<figure><img src="/files/pWPEtP0Brn7sgoflu8vR" alt=""><figcaption></figcaption></figure>

Si revisamos el código encontraremos este mensaje:

<figure><img src="/files/dhHFwEjOuoflFjFDG0Fe" alt=""><figcaption></figcaption></figure>

El cual nos dará el usuario kinder, por el que mediante fuerza bruta sacaremos su contraseña para acceder por ssh

```bash
hydra -l Kinder -P /usr/share/wordlist/rockyou.txt 172.17.0.2 ssh -t 64
```

<figure><img src="/files/srzj8XBUPSPwk6I5cenY" alt=""><figcaption></figcaption></figure>

Entramos por ssh

{% hint style="warning" %}
Es importante poner el usuario con la K en mayúscula
{% endhint %}

<figure><img src="/files/9kmozOJTDEY5uRJHgkJa" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Flag de user: 497686fad25d7b5464ac8fd745ad1b17
{% endhint %}

## Escalado de privilegios

Miramos los privilegios de este usuario

<figure><img src="/files/6IrsdfD2LFxW1lgaPAmd" alt=""><figcaption></figcaption></figure>

Vemos que podemos hacer restar del servicio de Apache, por lo que podemos mirar si podemos modificar el archivo del servicio&#x20;

<figure><img src="/files/JKd5z2GIpeCPnuAWtdsD" alt=""><figcaption></figcaption></figure>

Como podemos modificarlo, añadimos la siguiente línea al archivo

<figure><img src="/files/8h4aBkRbl8s6V8EUdWb4" alt=""><figcaption></figcaption></figure>

A continuación escribimos `bash -p` y ya seriamos **root**

<figure><img src="/files/tonO5PGaSHpC9goa0jwx" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Flag de root: e180269a01be15fc0b889bd34fd93c5c
{% endhint %}

## Conclusión

Una maquina interesante, con una explotación entretenía y un escalado de privilegios algo difícil de entender.

[^1]: He visto que es la que usan en el resto de  WriteUps de esta máquina
