4th Street Bar Hive-Bar

Hive-Bar Powered by Hive beta-fdb5b5b

Community post

Vulnhub: Troll 1 Walkthrough

This time I decided to try with another website i.e. vulnhub. This platform does not require to get the invite code and connect to it's VPN. It's simple, just download the .vmdk file and install it in virtual player (VMware workstation or virtual box)

As usual, start with nmap scan

![01.png](https://cdn.steemitimages.com/DQmRqq914PmxXpWQkDNwrUMdacQbRRqLfuezvLcgV2o2Lqx/01.png)

We can clearly see that 3 ports are open. The FTP (21), SSH (22) and HTTP (80).

ftp to the machine and you'll find the "lol.pcap" file
ftp://192.168.97.143

On analyzing via the WireShark I found a text

![04.png](https://cdn.steemitimages.com/DQmTkPaVx8mfyNWdj6TNWst7b32SFJuMVHzW5b4SsxH5QK2/04.png)

If you open the http page you'll find the image

![02.png](https://cdn.steemitimages.com/DQmPXvUUnYFJns5GUkfzbLBoLAo8gy9DcmbAVBnJzEbvjPt/02.png)

Run dirb on the http port you'll find the "secret" folder
dirb http://192.168.97.143

![03.png](https://cdn.steemitimages.com/DQmXH8USm2J3PxLcysrXYUZ1hdUUsJ2wb8zzGMfiDiHjPLQ/03.png)

Looks like we got trolled again.

After some cursing and banging my head, I finally tried the directory name in the browser

![05.png](https://cdn.steemitimages.com/DQmUMkhw96PkciZeUVjHVsg6j8RifFgoipcAcnNNYQcTdXU/05.png)

Let’s download it and analyze it.

![06.png](https://cdn.steemitimages.com/DQmVh9P52GmWHpqy1bdeS1fKRHyu5gxmQsxXWhxHfDXN2ta/06.png)
![07.png](https://cdn.steemitimages.com/DQmP5rsUjuEWUzjZbyZ2ML718ncC6NFQmi27C8MmatBbsn8/07.png)

So we found the address to proceed

![08.png](https://cdn.steemitimages.com/DQmaGJ9QnwcM2iqmHDRD6BgoPAwxCR1xgQ8AgpMQLhZnAMY/08.png)

The Good Luck folder contains a txt file.

![09.png](https://cdn.steemitimages.com/DQmW74FnY331GtS1yc7jLRZ3b95iZJGW4LVgLyNdeYTNugz/09.png)

Seems to be the usernames or passwords. This might be useful in ssh

![10.png](https://cdn.steemitimages.com/DQmcemP37CF5gqJERmKusuoV57qpFhio1hQjKL8D7hfycJ1/10.png)

The second folder seems to contain passwords.

![11.png](https://cdn.steemitimages.com/DQmbXTvkuMViAZ3STasLtXnepLiWsp7rM9EwSSgEa3LjCAu/11.png)
![12.png](https://cdn.steemitimages.com/DQmU9j9AqjYC8dNao6juJFX1WS3fMz43QwuJTgABDUTYkyo/12.png)

It seems that we are trolled again.

With which_one_lol.txt, I tried to brute force the ssh to see if I could get into any of the accounts, but no luck there

After a bunch of time, attempts, and anger I realized that what I thought was a password didn't work with any of the usernames, so I looked at the last two folder structures and decided to see if "Pass.txt" was the password as opposed to "Good_job_:)" since the folder did say, "this_folder_contains_the_password". Sticking with the trolling theme, that password worked with one of the accounts (overflow).

I must admit that "Pass.txt" was very intelligent password

![13.png](https://cdn.steemitimages.com/DQmeUazvkFsLNCX8MJy96pP8dwfG8hqTYHNJk4nq8HL1eE7/13.png)

ssh [email protected]

Note: if you get error while connecting to ssh "specify the port no"

Now it’s time to enumerate the OS. Download the below script using wget

wget https://raw.githubusercontent.com/mzet-/linux-exploit-suggester/master/linux-exploit-suggester.sh -O les.sh

https://github.com/mzet-/linux-exploit-suggester

![14.png](https://cdn.steemitimages.com/DQmd8iywmevDTNt6VvumZ8f7ozmXEht3rwnvLWwpiTbNeSU/14.png)

Do a chmod on les.sh and make it executable and run it

![15.png](https://cdn.steemitimages.com/DQmYZgWE4K5Lat8sfKu9putmR4DNKBRhbzZuWyHXniEwJ5P/15.png)

You'll get list of all exploits. I tried "dirtycow" but somehow it didn't work, so I moved to "dirty cow 2" exploit, but that required installation of g++ (since it a .cpp file) which was not possible. So I tried with overlayfs. There's also CVE number attached, if you want to learn more about the exploit.

![16.png](https://cdn.steemitimages.com/DQmbNwdXTD5Q9XDCeuDF5fccr1uFYgSFmfiJsFi7U3KtXt7/16.png)

I tried with "ovl_setattr", but that prompted me to create another user.

Note: There are many other exploits available for Ubuntu 14.04.1, you can try anyone you like.

![17.png](https://cdn.steemitimages.com/DQmeAUzzkUHqEP6evQCnCjhzKDB7VS5GKoxHG6L8tpkQQb3/17.png)
![18.png](https://cdn.steemitimages.com/DQmPa6i5xhrBdEiowaMTudT7sozFagPk6WEzVNiPx2uCn2q/18.png)

Overall this was a pretty easy one (except for a part or two)

![kali.png](https://cdn.steemitimages.com/DQmd3D4gxHg42Jrw26t5k7T6VyaVdgYJMgBseNmgraMSR5X/kali.png)
3 upvotes $0.00

Replies (2)

Review before signing

Posting as . Signing with . Keychain permission: Posting. Hive Keychain will ask you to approve this action next.


  
Technical details

Operation fingerprint: