The ip address if the machine is `192.168.1.139` ## Scans #### Initial Nmap Scan ```bash # Nmap 7.95 scan initiated Tue Feb 11 12:58:08 2025 as: /usr/lib/nmap/nmap -T4 -A -v -oN initial 192.168.1.139 Nmap scan report for 192.168.1.139 Host is up (0.0073s latency). Not shown: 994 closed tcp ports (reset) PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 2.9p2 (protocol 1.99) |_sshv1: Server supports SSHv1 | ssh-hostkey: | 1024 b8:74:6c:db:fd:8b:e6:66:e9:2a:2b:df:5e:6f:64:86 (RSA1) | 1024 8f:8e:5b:81:ed:21:ab:c1:80:e1:57:a3:3c:85:c4:71 (DSA) |_ 1024 ed:4e:a9:4a:06:14:ff:15:14:ce:da:3a:80:db:e2:81 (RSA) 80/tcp open http Apache httpd 1.3.20 ((Unix) (Red-Hat/Linux) mod_ssl/2.8.4 OpenSSL/0.9.6b) | http-methods: | Supported Methods: GET HEAD OPTIONS TRACE |_ Potentially risky methods: TRACE |_http-title: Test Page for the Apache Web Server on Red Hat Linux |_http-server-header: Apache/1.3.20 (Unix) (Red-Hat/Linux) mod_ssl/2.8.4 OpenSSL/0.9.6b 111/tcp open rpcbind 2 (RPC #100000) | rpcinfo: | program version port/proto service | 100000 2 111/tcp rpcbind | 100000 2 111/udp rpcbind | 100024 1 32768/tcp status |_ 100024 1 32768/udp status 139/tcp open netbios-ssn Samba smbd (workgroup: MYGROUP) 443/tcp open ssl/https Apache/1.3.20 (Unix) (Red-Hat/Linux) mod_ssl/2.8.4 OpenSSL/0.9.6b | http-methods: |_ Supported Methods: GET HEAD POST | ssl-cert: Subject: commonName=localhost.localdomain/organizationName=SomeOrganization/stateOrProvinceName=SomeState/countryName=-- | Issuer: commonName=localhost.localdomain/organizationName=SomeOrganization/stateOrProvinceName=SomeState/countryName=-- | Public Key type: rsa | Public Key bits: 1024 | Signature Algorithm: md5WithRSAEncryption | Not valid before: 2009-09-26T09:32:06 | Not valid after: 2010-09-26T09:32:06 | MD5: 78ce:5293:4723:e7fe:c28d:74ab:42d7:02f1 |_SHA-1: 9c42:91c3:bed2:a95b:983d:10ac:f766:ecb9:8766:1d33 |_ssl-date: 2025-02-11T17:58:32+00:00; +16h00m04s from scanner time. |_http-title: 400 Bad Request | sslv2: | SSLv2 supported | ciphers: | SSL2_RC4_128_WITH_MD5 | SSL2_RC2_128_CBC_EXPORT40_WITH_MD5 | SSL2_RC4_128_EXPORT40_WITH_MD5 | SSL2_RC2_128_CBC_WITH_MD5 | SSL2_DES_64_CBC_WITH_MD5 | SSL2_DES_192_EDE3_CBC_WITH_MD5 |_ SSL2_RC4_64_WITH_MD5 |_http-server-header: Apache/1.3.20 (Unix) (Red-Hat/Linux) mod_ssl/2.8.4 OpenSSL/0.9.6b 32768/tcp open status 1 (RPC #100024) MAC Address: 2C:9C:58:8B:9A:A7 (Cloud Network Technology Singapore PTE.) Device type: general purpose Running: Linux 2.4.X OS CPE: cpe:/o:linux:linux_kernel:2.4 OS details: Linux 2.4.9 - 2.4.18 (likely embedded) Uptime guess: 0.004 days (since Tue Feb 11 12:52:03 2025) Network Distance: 1 hop TCP Sequence Prediction: Difficulty=200 (Good luck!) IP ID Sequence Generation: All zeros Host script results: |_clock-skew: 16h00m03s | nbstat: NetBIOS name: KIOPTRIX, NetBIOS user: <unknown>, NetBIOS MAC: <unknown> (unknown) | Names: | KIOPTRIX<00> Flags: <unique><active> | KIOPTRIX<03> Flags: <unique><active> | KIOPTRIX<20> Flags: <unique><active> | \x01\x02__MSBROWSE__\x02<01> Flags: <group><active> | MYGROUP<00> Flags: <group><active> | MYGROUP<1d> Flags: <unique><active> |_ MYGROUP<1e> Flags: <group><active> |_smb2-time: Protocol negotiation failed (SMB2) TRACEROUTE HOP RTT ADDRESS 1 7.31 ms 192.168.1.139 ``` We can see there are 6 port opened on the machine. Since port *80* is open, we can visit it from a browser and see what is hosted. #### Nikto Scan A Nikto scan of the webserver resulted in the following output. There are several vulnerabilities found in the server. ```bash $ nikto -h http://192.168.1.139 - Nikto v2.5.0 --------------------------------------------------------------------------- + Target IP: 192.168.1.139 + Target Hostname: 192.168.1.139 + Target Port: 80 + Start Time: 2025-02-11 13:27:58 (GMT11) --------------------------------------------------------------------------- + Server: Apache/1.3.20 (Unix) (Red-Hat/Linux) mod_ssl/2.8.4 OpenSSL/0.9.6b + /: Server may leak inodes via ETags, header found with file /, inode: 34821, size: 2890, mtime: Thu Sep 6 13:12:46 2001. See: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1418 + /: The anti-clickjacking X-Frame-Options header is not present. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options + /: The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type. See: https://www.netsparker.com/web-vulnerability-scanner/vulnerabilities/missing-content-type-header/ + mod_ssl/2.8.4 appears to be outdated (current is at least 2.9.6) (may depend on server version). + Apache/1.3.20 appears to be outdated (current is at least Apache/2.4.54). Apache 2.2.34 is the EOL for the 2.x branch. + OpenSSL/0.9.6b appears to be outdated (current is at least 3.0.7). OpenSSL 1.1.1s is current for the 1.x branch and will be supported until Nov 11 2023. + /: Apache is vulnerable to XSS via the Expect header. See: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3918 + OPTIONS: Allowed HTTP Methods: GET, HEAD, OPTIONS, TRACE . + /: HTTP TRACE method is active which suggests the host is vulnerable to XST. See: https://owasp.org/www-community/attacks/Cross_Site_Tracing + Apache/1.3.20 - Apache 1.x up 1.2.34 are vulnerable to a remote DoS and possible code execution. + Apache/1.3.20 - Apache 1.3 below 1.3.27 are vulnerable to a local buffer overflow which allows attackers to kill any process on the system. + Apache/1.3.20 - Apache 1.3 below 1.3.29 are vulnerable to overflows in mod_rewrite and mod_cgi. + mod_ssl/2.8.4 - mod_ssl 2.8.7 and lower are vulnerable to a remote buffer overflow which may allow a remote shell. + ///etc/hosts: The server install allows reading of any system file by adding an extra '/' to the URL. + /usage/: Webalizer may be installed. Versions lower than 2.01-09 vulnerable to Cross Site Scripting (XSS). See: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0835 + /manual/: Directory indexing found. + /manual/: Web server manual found. + /icons/: Directory indexing found. + /icons/README: Apache default file found. See: https://www.vntweb.co.uk/apache-restricting-access-to-iconsreadme/ + /test.php: This might be interesting. + /wp-content/themes/twentyeleven/images/headers/server.php?filesrc=/etc/hosts: A PHP backdoor file manager was found. + /wordpress/wp-content/themes/twentyeleven/images/headers/server.php?filesrc=/etc/hosts: A PHP backdoor file manager was found. + /wp-includes/Requests/Utility/content-post.php?filesrc=/etc/hosts: A PHP backdoor file manager was found. + /wordpress/wp-includes/Requests/Utility/content-post.php?filesrc=/etc/hosts: A PHP backdoor file manager was found. + /wp-includes/js/tinymce/themes/modern/Meuhy.php?filesrc=/etc/hosts: A PHP backdoor file manager was found. + /wordpress/wp-includes/js/tinymce/themes/modern/Meuhy.php?filesrc=/etc/hosts: A PHP backdoor file manager was found. + /assets/mobirise/css/meta.php?filesrc=: A PHP backdoor file manager was found. + /login.cgi?cli=aa%20aa%27cat%20/etc/hosts: Some D-Link router remote command execution. + /shell?cat+/etc/hosts: A backdoor was identified. + /#wp-config.php#: #wp-config.php# file found. This file contains the credentials. + 8908 requests: 0 error(s) and 30 item(s) reported on remote host + End Time: 2025-02-11 13:30:51 (GMT11) (173 seconds) --------------------------------------------------------------------------- + 1 host(s) tested ``` It shows the default apache web page, which is not a good practice. Furthermore, the 404 page gives additional information such as the hostname and port number. This can give an attacker an idea of the naming structure. ![[Kioptrix_404.png]] ## Enumeration #### Dirbuster ![[Kipotrix_Dirbuster.png]] A scan of the server directories using dirbuster comes up with the above folder structure. There seems to be a `test.php` file that has nothing to do with production. Which hints as poor hygiene. ## Information Disclosure #### Server Headers ![[Kioptrix_Server_Header.png]] #### Default Web Page ![[Kioptrix_Default_web_page.png]] ## Vulnerabilities #### SMB From a metasploit scan we found out the version running on this machine is `Samba 2.2.1a`. ```bash msf6 auxiliary(scanner/smb/smb_version) > run [*] 192.168.1.139:139 - Host could not be identified: Unix (Samba 2.2.1a) [*] 192.168.1.139: - Scanned 1 of 1 hosts (100% complete) [*] Auxiliary module execution completed ``` We can use `smbclient` to connect to the file share and see whether we can access anything. ```bash $ smbclient -L \\192.168.1.139\\ Server does not support EXTENDED_SECURITY but 'client use spnego = yes' and 'client ntlmv2 auth = yes' is set Anonymous login successful Sharename Type Comment --------- ---- ------- IPC$ IPC IPC Service (Samba Server) ADMIN$ IPC IPC Service (Samba Server) Reconnecting with SMB1 for workgroup listing. Server does not support EXTENDED_SECURITY but 'client use spnego = yes' and 'client ntlmv2 auth = yes' is set Anonymous login successful Server Comment --------- ------- KIOPTRIX Samba Server Workgroup Master --------- ------- MYGROUP KIOPTRIX ``` It seems like there are **2** shares available in the system and we can try to connect to them next. ```bash $ smbclient \\\\192.168.1.139\\ADMIN$ Server does not support EXTENDED_SECURITY but 'client use spnego = yes' and 'client ntlmv2 auth = yes' is set Anonymous login successful tree connect failed: NT_STATUS_WRONG_PASSWORD $ smbclient \\\\192.168.1.139\\IPC$ Server does not support EXTENDED_SECURITY but 'client use spnego = yes' and 'client ntlmv2 auth = yes' is set Anonymous login successful Try "help" to get a list of possible commands. smb: \> ls NT_STATUS_NETWORK_ACCESS_DENIED listing \* ``` We cannot access the `ADMIN
share since it requires a password but can access the `IPC
share. However, we cannot list anything in that share since listing is denied. > [!bug] Trans2Open > This exploits the buffer overflow found in Samba versions 2.2.0 to 2.2.8. This particular module is capable of exploiting the flaw on x86 Linux systems that do not have the noexec stack option set. NOTE: Some older versions of RedHat do not seem to be vulnerable since they apparently do not allow anonymous access to IPC. [link](https://www.rapid7.com/db/modules/exploit/linux/samba/trans2open/) #### mod_ssl > [!bug] OpenFuck This machine is running the mod_ssl 2.8.4 version, which is vulnerable to the 'OpenFuck' exploit. [link](https://www.exploit-db.com/exploits/764) We can either use a [GitHub](https://github.com/heltonWernik/OpenLuck) implementation or the Metasploit framework to exploit this vulnerability. ![[Screenshot 2025-02-11 at 9.42.09 pm.png]]