Sunset : Midnight
Description ⤵️
💡 sunset: midnight ⤵️
Difficulty: Intermediate
Important!: Before auditing this machine make sure you add the host “sunset-midnight” to your /etc/hosts file, otherwise it may not work as expected.
It is recommended to run this machine in Virtualbox.
This works better with ViritualBox rather than VMware
Let’s find the IP Address first »
1
IP : 10.0.2.5
Port Scan Results ➡️
1
2
3
4
OPEN PORTS >
22 SSH
80 HTTP
3306 mysql
Web Enumeration ⤵️
After wpscan →
lets try to brute force the password for sql →
1
2
mysql credentials →
root : robert
from wordpress_db database
→
1
2
3
username → admin
password → $P$BaWk4oeAmrdn453hR6O6BvDqoF9yy6/
from mysql database →
As I was not able to crack the password so lets change it →
1
2
3
Command →
update wp_users set user_pass="5f4dcc3b5aa765d61d832
Now my password is password , Lets try it out →
Finally after uploading the shell I got reverse shell →
Credentials Time →
1
jose : 645dc5a8871d2a4269d4cbe23f6ae103
1
user.txt → 956a9564aa5632edca7b745c696f6575
Lets check the SUIDs and GUIDs files →
Now I have to Abuse the SUID commands →
1
root.txt → db2def9d4ddcb83902b884de39d426e6
If you have any questions or suggestions, please leave a comment below. Thank You !