Nmap output
We have ubuntu default page on port 80
After fuzzing we found thta Jorani v1.0.0 is installed
Found https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/CVE_Jorani.py this unauthenticated RCE & ran the exploit
Got command execution
Got reverse shell using busybox nc
Got local.txt (86154fd72458f7180fee669a6d178ab6)
We have sudo privilege on env
Ran sudo env /bin/bash & got root
Got proof.txt (9ee1703c6446b8245fa8e78416602fe8)
More walkthroughs
Full walkthrough of the BitForge box on Offensive Security Proving Grounds (Linux). Enumeration across 22/ssh, 80/http, 3306/mysql. Foothold to root using evil-winrm, kerberoasting, linpeas.
Full walkthrough of the CLUE box on Offensive Security Proving Grounds (Linux). Enumeration across 22/ssh, 80/http, 139/netbios-ssn, 445/netbios-ssn, 3000/http. Foothold to root using evil-winrm, kerberoasting, linpeas.
Full walkthrough of the Cockpit box on Offensive Security Proving Grounds (Linux). Enumeration across 22/ssh, 80/http, 9090/http. Foothold to root using evil-winrm, kerberoasting, linpeas.
Full walkthrough of the Access box on Offensive Security Proving Grounds (Active Directory). Enumeration across 53/domain, 80/http, 88/kerberos-sec, 135/msrpc, 139/netbios-ssn. Foothold to root using evil-winrm, kerberoasting, linpeas.
Full walkthrough of the Heist box on Offensive Security Proving Grounds (Active Directory). Enumeration across 53/domain, 135/msrpc, 139/netbios-ssn, 389/ldap, 445/microsoft-ds?. Foothold to root using evil-winrm, kerberoasting, linpeas.
Full walkthrough of the Hokkaido box on Offensive Security Proving Grounds (Active Directory). Enumeration across 53/domain, 80/http, 88/kerberos-sec, 135/msrpc, 139/netbios-ssn. Foothold to root using evil-winrm, kerberoasting, linpeas.







