Wonderland

Fall down the rabbit hole and enter wonderland.

Scanning

Nmap

$ nmap -sV -sC 10.10.59.87       

Starting Nmap 7.60 ( https://nmap.org ) at 2021-10-02 00:02 BST
Nmap scan report for ip-10-10-59-87.eu-west-1.compute.internal (10.10.59.87)
Host is up (0.0012s latency).
Not shown: 998 closed ports
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   2048 8e:ee:fb:96:ce:ad:70:dd:05:a9:3b:0d:b0:71:b8:63 (RSA)
|   256 7a:92:79:44:16:4f:20:43:50:a9:a8:47:e2:c2:be:84 (ECDSA)
|_  256 00:0b:80:44:e6:3d:4b:69:47:92:2c:55:14:7e:2a:c9 (EdDSA)
80/tcp open  http    Golang net/http server (Go-IPFS json-rpc or InfluxDB API)
|_http-title: Follow the white rabbit.
MAC Address: 02:F4:A0:15:1D:53 (Unknown)
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 13.11 seconds

Enumeration

Gobuster

/img & /poem nothing interesting no binaries ...

check /r

we will use same command of gobuster and add new directory to the url

in this case we will use alphabet wordlist

the end ... no where to go

openhttp://10.10.59.87/r/a/b/b/i/t on in browser

view source

Initial Access

ssh target using these credentials

Privilege Escalation

Horizontal Escalation to Rabbit

check if alice have any sudo privilege

alice can run this script walrus_and_the_carpenter.py with rabbit privilege

check walrus_and_the_carpenter this code use python library called random

so lets hijack this library

know more about python library hijack article

create fake library with same name

run walrus_and_the_carpenter with rabbit privilege

Horizontal Escalation to Hatter

check home directory teaparty here

run it

it seems to trigger $ date command

  • write a command you wanna to execute in file with same name

  • export the path to path_variable

  • run script

in this directory you can find password.txt

login using ssh as hatter

Vertical Escalate to Root

check capabilities

we can cap_setuid+ep Perl

check GTFOBins

Last updated