FristiLeaks - VulnHub CTF Challenge Walkthrough

Words
309
Reading
2 min
Listen
Play
8y


FristiLeaks is available at VulnHub. It requires a lot of enumeration to root this VM. This VM is intended for beginners.

In this walkthrough, I'll be using Parrot Security OS but you can use any other Linux distro.

alt

Now, edit your "/etc/hosts" file to register this IP in your local DNS.

alt

Run a full Nmap Scan

alt

HTTP Server's default webpage,

alt

Nothing useful found in the source code, let's check "robots.txt".

alt

The files in "robots.txt" contain nothing. Now, check "/fristi/".

alt

The source code of this page reveals a base64 encoded text.

alt

Save this text to a file and then decode it and store it as an image file.

cat base64enc | base64 --decode > output.png
alt

Now, open the image file.

alt

This text looks like a password. For username, try "eezeepz".

alt

Try these credentials on the login page.

alt

We're successfully logged in. Now, try uploading a PHP reverse shell (from pentest monkey).

alt

Edit your reverse shell extension and change it from ".php" to ".php.png" and then upload and alter the http request

alt

Now, access this file "/fristi/uploads/php-reverse-shell.php".

alt

We got a reverse shell. After some enumeration, there is a file named notes.txt that contains something interesting.

alt

Now, change permissions of "/home/admin/" using "runthis".

echo "/home/admin/chmod -R 7777 /home/admin" > /tmp/runthis
alt

Spawn a pty shell.

alt

"whoisyourgodnow.txt" and "cryptedpass.txt" contains an encrypted password and "cryptpass.py" which is used to encrypt these files. Now, try creating a reverse algorithm of "cryptpass.py" on the attacker machine.

import base64,codecs,sys

string="=RFn0AKnlMHMPIzpyuTI0ITG"
def encodeString(str):
decoded = codecs.decode(str[::-1], 'rot13')
return base64.b64decode(decoded)

print encodeString(string)


alt

Now, run this.

alt

Try this as a password for "fristigod".

alt

File "/var/fristigod/.secret_admin_stuff/doCom" can be run as root. Now, try running BASH using this file.

alt

And finally, we got our ROOT Flag.


Posted from my blog with SteemPress : https://latesthackingnews.com/2018/09/02/fristileaks-vulnhub-ctf-challenge-walkthrough/

FristiLeaks - VulnHub CTF Challenge Walkthrough | Ecency