Funbox : EasyEnum
Machine | |
---|---|
Vulnhub | https://www.vulnhub.com/entry/funbox-easyenum,565/ |
Level | |
Creator |
Description ⤵️
💡 Boot2root in 6 steps for script-kiddies.
Timeframe to root this box: 20 mins to never ever. It is on you.HINTS:
Enum without sense, costs you too many time:
- Use “Daisys best friend” for information gathering.
- Visit “Karla at home”.
- John and Hydra loves only rockyou.txt
- Enum/reduce the users to brute force with or brute force the rest of your life.
This works better with VirtualBox rather than VMware
Let’s find the IP Address first »
1
IP : 10.0.2.18
Port Scan Results ➡️
1
2
3
OPEN PORTS >
22 SSH
80 HTTP
Web Enumeration ⤵️
Lets look into directory or files bruteforcing files / folders →
I uploaded the php_reverse_shell code →
SHELL ➡️
Now lets check /etc/passwd
→
Now I have to crack the password → so lets use hashcat →
1
2
command →
hashcat -m 500 pass.hash /usr/share/wordlists/rockyou.txt
1
oracle : hiphop
Lets recon more on web →
Lets check →
1
phpmyadmin : tgbzhnujm!
Now I tried this password for karla →
And I got in →
It time for root !!
I got one more user credentials →
Another Way to root →
Now lets brute force the password for user goat which contains the shadow.bak file →
I got result after 15-20 min →
1
goat : thebest
If you have any questions or suggestions, please leave a comment below. Thank You !
This post is licensed under CC BY 4.0 by the author.