Difficulty = Easy
Running our nmap scan, looks like we have only 1 port opened
# Nmap 7.94 scan initiated Thu Oct 19 09:28:07 2023 as: nmap -p- -sCV -T4 -v --min-rate=1000 -oN nmap.txt
Nmap scan report for
Host is up (0.14s latency).
Not shown: 65534 closed tcp ports (conn-refused)
80/tcp open http Apache httpd 2.4.18 ((Ubuntu))
| http-robots.txt: 1 disallowed entry
|_http-title: Welcome to FUEL CMS
|_http-server-header: Apache/2.4.18 (Ubuntu)
| http-methods:
|_ Supported Methods: GET HEAD POST OPTIONS
Navigating to port 80/HTTP
we have the version boldly written 😄
Enumerating this version we have a Remote Code Execution Exploit, we can there for run this script and get our shell
Change directory to /tmp
and send a tool called linpeas to target machine
Navigating to /var/www/html/fuel/application/config
we found a username and password
We can then switch user to root
Bankai 🎎