LEGACY
- Layout for this exercise:
data:image/s3,"s3://crabby-images/01bc5/01bc5353c45a278196b81cb3465cedce6c85dc20" alt=""
1 - INTRODUCTION
- The goal of this exercise is to develop a hacking process for the vulnerable machine Legacy, what is a retired machine from the Hack The Box pentesting platform:
https://www.hackthebox.eu
2 - ENUMERATION
- Legacy's IP is 10.10.10.4:
data:image/s3,"s3://crabby-images/d91d2/d91d2393d0fd93df8d67fc0ecdb5bce70376565b" alt=""
- Scanning with Nmap we learn that a Windows XP system is running SMB service at ports 139 and 445:
data:image/s3,"s3://crabby-images/d1dcd/d1dcdfa1e19035dd94d6fbf9c491e7233087f638" alt=""
- Scanning deeper those two ports:
data:image/s3,"s3://crabby-images/92a28/92a283b8394f4edb6716be09fda3595b6fcbe71b" alt=""
- Looking for vulnerabilities on port 139:
data:image/s3,"s3://crabby-images/1527d/1527de0e1719a7a4f43e1807db502367d6c1500c" alt=""
- Looking for vulnerabilities on port 445:
data:image/s3,"s3://crabby-images/b03d0/b03d0fcc3cd4623b471e54e4ca4f31e762107aff" alt=""
- To sum it up, we have discovered these potential vulnerabilities:
- CVE-2008-4250
- CVE-2017-0143
- CVE-2009-3103
3 - EXPLOITATION
- There are several Metasploit modules associated to these vulnerabilities.
- For instance ms08_067_netapi is able to exploit CVE-2008-4250:
data:image/s3,"s3://crabby-images/ec1c3/ec1c3f30df1d7105a917a749154e0d880b8b5e27" alt=""
data:image/s3,"s3://crabby-images/b65e3/b65e3fc2ccb90d4d133585dde9d3029ab38ece6f" alt=""
- Launching Metasploit and taking the module ms08_067_netapi:
data:image/s3,"s3://crabby-images/4fb03/4fb03ef81d4060ab567113bf286bd2ae63b06b78" alt=""
data:image/s3,"s3://crabby-images/ee341/ee3413cb035c0ba2ece2dd2f678f12d50dcba886" alt=""
- Once we get a System privileged Meterpreter session it is easy to spawn a shell:
data:image/s3,"s3://crabby-images/f9760/f97603f4b626ad466e0d35a3754d147af9c3389a" alt=""
4 - CAPTURING THE FLAGS
- Reading user.txt:
data:image/s3,"s3://crabby-images/3e6b9/3e6b9c79956437e2e9711e1e66d0d113b2e1f17c" alt=""
- Reading root.txt:
data:image/s3,"s3://crabby-images/59021/5902131598bd3fdb146a5425477b9aabfdb167cf" alt=""