LINUX - SAMBA
- Layout for this exercise:
data:image/s3,"s3://crabby-images/9d2f1/9d2f17072c3cef0075a8ade1ad8cd184500f22b1" alt=""
- The attacker scans possible open ports and servicies at the victim's machine using NMAP:
data:image/s3,"s3://crabby-images/cc51a/cc51a06be5b5dcc75fd991e8c336e201c938c6f8" alt=""
- On port 139 the victim is running Samba, service used for File Sharing that in this case suffers from a vulnerability. Metasploit provides the usermap_script exploit to take advantage of that vulnerability:
data:image/s3,"s3://crabby-images/e0b17/e0b17077def1544ae559961ff6228ef1bed0a8f4" alt=""
- Let's set the payload to cmd/unix/reverse:
data:image/s3,"s3://crabby-images/0f5bf/0f5bff08eb39f8ad4d89925e5f977dd89db0ca37" alt=""
- Required options include remote host (victim) and local host (attacker):
data:image/s3,"s3://crabby-images/8544a/8544aa36d9b061886d9a6ec2fc9a73b82ce64e9e" alt=""
- Setting remote host's IP:
data:image/s3,"s3://crabby-images/29a1e/29a1ea662711cafbf2553ed84a3512882df0e503" alt=""
- Setting attacker's IP:
data:image/s3,"s3://crabby-images/aeaa8/aeaa8bb38ec421921eeeff7e46e8501e3ad17fec" alt=""
- Launching the exploit, the result is a remote shell that allow postexplotaition of the victim:
data:image/s3,"s3://crabby-images/57421/57421ef6d13dd0ff70a8d6da881131154dcf4a2d" alt=""
- For instance, from the remote shell both /etc/passwd and /etc/shadow content can be discovered:
data:image/s3,"s3://crabby-images/053a4/053a48693ae4f4fe07e50c7e1346398b80dd664c" alt=""
data:image/s3,"s3://crabby-images/0bae5/0bae5e3bca8db492147ff50cb363530e21a034e6" alt=""