Home Topology Report
Post
Cancel

Topology Report

Information gathering



Scope: 10.10.11.217/32 (Linux)

TCP Nmap scan: 65,535 ports

Vulnerability Assesment



  • Latext In/Out math Mode
    • Input: $ (Out math mode error)
    • Input: $normalmode$\frac{x+5}{y-3} (not errors)
  • http://dev.topology.htb (/var/www/dev)
    • Read .htpasswd (file to password-protect a directory on an Apache server)

Exploitation



  • Crack Hash (vdaisley:calculus20)
    • Vajramani Daisley, PhD (Post-doctoral researcher, software developer)
      • Reuse Credentials (SSH access)

Post-exploitation



  • Daisley Enumeration
    • Listing system process (basic pspy.sh)
      • Gnuplot: (command-line and GUI program)
      • Create .plt file with reverse shell, move file to /opt/gnuplot directory (write access), wait one minute aprox and gain access

Lateral movement



Proof of concept



  • Latex injection (Read files)
    • Input: $\lstinputlisting{/etc/issue}$ (Out math mode and in math mode again to bypass errors)
  • Gnuplot remote command execution
This post is licensed under CC BY 4.0 by the author.