Kioptrix Level 1
Kioptrix Level 1 Walkthrough
Tools:
Nmap, Nikto, Dirb, Enum4Linux, Metasploit, Searchsploit, Github
data:image/s3,"s3://crabby-images/970af/970afdb065ef8ee640035e5639b221704fd4c95b" alt=""
Lab set up
Vulnerable Kioptrix VM
Check IP and discover Kioptrix IP in our virtual lab.
data:image/s3,"s3://crabby-images/d1de1/d1de1fb22e51ade07349d6bec5e1f9b43af86cfc" alt=""
data:image/s3,"s3://crabby-images/3d2a8/3d2a81a813ad21b18958a1c9b9f57c8c6507f76f" alt=""
Recon
Nmap -sV -T4 -p- <IP> -vv
A quick scan to identify all possible open ports
data:image/s3,"s3://crabby-images/d6894/d6894370d9bf42f9c18dba4bfc41f74a39b702da" alt=""
Nmap -A -T4 -p22, 80, 111, 139, 443, 32768 <IP> -vv
Quick aggressive scan to grab more information from open ports identified in the previous scan.
data:image/s3,"s3://crabby-images/881fb/881fbfa7e4a6d99786195e77da5481ddc95733d1" alt=""
data:image/s3,"s3://crabby-images/2747a/2747a0e2c33132a167d9a9ea4efa52dbf83ed885" alt=""
data:image/s3,"s3://crabby-images/b4ef1/b4ef1771127a88595bec1ca0e9fef45948632ed5" alt=""
Nikto
Nikto scan to find more information from the web app running on port 80.
data:image/s3,"s3://crabby-images/da5b6/da5b6774497984a7267b94f9a1dda2e1d6178697" alt=""
Dirb
Brute-forcing directories in our target
data:image/s3,"s3://crabby-images/09889/09889028f9af693c6168fa98994c2dba5c201a32" alt=""
data:image/s3,"s3://crabby-images/456d2/456d24c836fad56a68efc4255822f5cbf73f8fc2" alt=""
Enum4Linux
Enumerating SMB identified from our nmap scans (port 139)our target machine.
data:image/s3,"s3://crabby-images/e3d22/e3d22bd1412f9f7b2c411161f28fd3d17eeee6fa" alt=""
Enumerating SMB/Connecting to our target machine (anonymous login)
data:image/s3,"s3://crabby-images/f37d0/f37d06d2734a1a6d6082d3d7438d7f0f53a1179a" alt=""
Metasploit exploiting SMB
Running Metasploit scan to grab SMB port version
data:image/s3,"s3://crabby-images/7c90c/7c90c5a71e86456f5d1e7423bcb30ecdc723661f" alt=""
Samba 2.2.1a version identified.
Searchsploit
Finding information about samba 2.2/trans2open
data:image/s3,"s3://crabby-images/41530/41530d70d0b856d24568ada9c685523c736e68a1" alt=""
Exploit
Metasploit/Searchsploit
Looking for exploits in the Metasploit database
data:image/s3,"s3://crabby-images/b1089/b10895dbd584cdc20fb9cfa099934fc088631e0b" alt=""
Setting up the exploit
data:image/s3,"s3://crabby-images/a1503/a1503e306aff32d166aed1a11dc4003b0d81d6ab" alt=""
In order to make this exploit work, it is important to set up the correct payload:
data:image/s3,"s3://crabby-images/9a907/9a9071821e5cb4415881a9406bed85c27fde2678" alt=""
Correct payload option
data:image/s3,"s3://crabby-images/6fb0e/6fb0e15bbcaa464aad09923b51834838dd5ed120" alt=""
Shelling the target/Exploiting vulnerable Samba.
data:image/s3,"s3://crabby-images/c3672/c36724ac2e61cbee77146b6ad84be0d4a6f29ed1" alt=""
Metasploit exploiting Apache
Quick scan port 443 with Nmap
data:image/s3,"s3://crabby-images/ee50e/ee50e7d4ae8ac9d3ea187d66da7ed4c4b9adaeb3" alt=""
Searchsploit
data:image/s3,"s3://crabby-images/3790f/3790faa87dddcca814985d5cf81a17022ec32145" alt=""
In order to make this exploit works download the updated version from GitHub and follow the instructions:
Exploitation/Shelling the target
data:image/s3,"s3://crabby-images/f3605/f3605f0a979f5da98037aedec9a21e0062da34e5" alt=""