Reconnaissance
First, I added the new host to my known ones:
Then, I performed a Nmap scan:
As you can see above, anonymous login is enabled, so I tried it:
But I didnโt find anything, so I decided to check the port 139 (related to SMB):
It also had anonymous login, and 3 disk are seen. First, I connected to /tmp
and perform a ls
:
Then I downloaded vgauthsvclog.txt.0
:
Didnโt give me anything interesting, so I decided to take a look at the Samba version previously found.
Weaponization
I searched for โSamba 3.0.20 exploitโ and found CVE-2007-2447
Explotation
I had to read the exploit (because it didnโt work with the msfconsole). This is basically the vulnerability:
This can be applied to the moment we establish a connection to bypass login (username parameter):
We directly become root!
Now we can see the user and root flag:
Machine pwned!