{"id":16,"date":"2025-03-27T17:05:36","date_gmt":"2025-03-27T16:05:36","guid":{"rendered":"https:\/\/fromkiddietorobot.fr\/?p=16"},"modified":"2025-03-27T19:34:19","modified_gmt":"2025-03-27T18:34:19","slug":"lazyadmin","status":"publish","type":"post","link":"https:\/\/fromkiddietorobot.fr\/index.php\/2025\/03\/27\/lazyadmin\/","title":{"rendered":"LazyAdmin"},"content":{"rendered":"\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><a href=\"https:\/\/tryhackme.com\/room\/lazyadmin\">https:\/\/tryhackme.com\/room\/lazyadmin<\/a><\/p>\n\n\n\n<p>Easy linux machine to practice your skills<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Phase d&#8217;\u00e9num\u00e9ration<\/h2>\n\n\n\n<p>nmap &lt;ip_address> :<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"514\" height=\"205\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-18.png\" alt=\"\" class=\"wp-image-68\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-18.png 514w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-18-300x120.png 300w\" sizes=\"auto, (max-width: 514px) 100vw, 514px\" \/><\/figure>\n\n\n\n<p>On voit qu&#8217;il y a les ports 22:ssh et 80:http. Voyons voir ce qui se trouve sur le serveur web.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"671\" height=\"479\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-21.png\" alt=\"\" class=\"wp-image-71\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-21.png 671w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-21-300x214.png 300w\" sizes=\"auto, (max-width: 671px) 100vw, 671px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"701\" height=\"190\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-16.png\" alt=\"\" class=\"wp-image-66\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-16.png 701w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-16-300x81.png 300w\" sizes=\"auto, (max-width: 701px) 100vw, 701px\" \/><figcaption class=\"wp-element-caption\">contenu du sous dossier \/content<\/figcaption><\/figure>\n\n\n\n<p>On apprend sur le site qu&#8217;il est g\u00e9r\u00e9 par un CMS du nom de SweetRice.<br>Voyons voir si nous pouvons exploiter ce CMS gr\u00e2ce au site exploit-db.com<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"268\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-22-1024x268.png\" alt=\"\" class=\"wp-image-72\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-22-1024x268.png 1024w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-22-300x79.png 300w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-22-768x201.png 768w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-22-1536x403.png 1536w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-22-1200x315.png 1200w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-22.png 1797w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Nous allons nous pencher sur une exploitation sp\u00e9cifique: SweetRice 1.5.1 &#8211; Backup Disclosure<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"636\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-23-1024x636.png\" alt=\"\" class=\"wp-image-74\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-23-1024x636.png 1024w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-23-300x186.png 300w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-23-768x477.png 768w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-23-1200x745.png 1200w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-23.png 1304w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Elle nous indique que nous pouvons acc\u00e9der librement au fichier de backup de la base de donn\u00e9es du site. Tentons de la r\u00e9cup\u00e9rer sur notre site afin de voir si des informations pourraient nous \u00eatre utile \u00e0 r\u00e9cup\u00e9rer des identifiants par exemple.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"617\" height=\"225\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-24.png\" alt=\"\" class=\"wp-image-75\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-24.png 617w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-24-300x109.png 300w\" sizes=\"auto, (max-width: 617px) 100vw, 617px\" \/><\/figure>\n\n\n\n<p>Nous pouvons bien t\u00e9l\u00e9charger la backup mysql ! <\/p>\n\n\n\n<p>Regardons maintenant \u00e0 l&#8217;int\u00e9rieur :<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"954\" height=\"241\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-25.png\" alt=\"\" class=\"wp-image-76\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-25.png 954w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-25-300x76.png 300w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-25-768x194.png 768w\" sizes=\"auto, (max-width: 954px) 100vw, 954px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Phase d&#8217;exploitation<\/h2>\n\n\n\n<p>On finit bien par trouver un login\/mdp dans le fichier MySQL, testons de nous connecter au CMS:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1600\" height=\"876\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-26-edited-1.png\" alt=\"\" class=\"wp-image-79\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-26-edited-1.png 1600w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-26-edited-1-300x164.png 300w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-26-edited-1-1024x561.png 1024w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-26-edited-1-768x420.png 768w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-26-edited-1-1536x841.png 1536w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-26-edited-1-1200x657.png 1200w\" sizes=\"auto, (max-width: 1600px) 100vw, 1600px\" \/><\/figure>\n\n\n\n<p>La connexion est faite. <br>Notre but est maintenant de mettre un reverse shell en place sur le site, pour cela je me sers du site : revshells.com<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"662\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-27-1024x662.png\" alt=\"\" class=\"wp-image-80\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-27-1024x662.png 1024w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-27-300x194.png 300w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-27-768x497.png 768w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-27.png 1124w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>On vient placer notre code dans le dossier &#8220;Ads&#8221; afin de le lancer apr\u00e8s.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"767\" height=\"573\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-28.png\" alt=\"\" class=\"wp-image-81\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-28.png 767w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-28-300x224.png 300w\" sizes=\"auto, (max-width: 767px) 100vw, 767px\" \/><\/figure>\n\n\n\n<p>Dans un terminal, on \u00e9coute le port 31337 (port dont je d\u00e9cide moi-m\u00eame le nombre dans mon reverse shell) gr\u00e2ce \u00e0 la commande Netcat afin de r\u00e9cup\u00e9rer le shell quand notre exploit aura \u00e9t\u00e9 lanc\u00e9<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"234\" height=\"63\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-29.png\" alt=\"\" class=\"wp-image-82\"\/><\/figure>\n\n\n\n<p>Et une fois dans le dossier, on peut lancer notre reverse shell:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"544\" height=\"280\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-31.png\" alt=\"\" class=\"wp-image-84\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-31.png 544w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-31-300x154.png 300w\" sizes=\"auto, (max-width: 544px) 100vw, 544px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"644\" height=\"207\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-32.png\" alt=\"\" class=\"wp-image-85\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-32.png 644w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-32-300x96.png 300w\" sizes=\"auto, (max-width: 644px) 100vw, 644px\" \/><figcaption class=\"wp-element-caption\">TIENS ! Nous avons acc\u00e8s \u00e0 la machine.<\/figcaption><\/figure>\n\n\n\n<p>Ensuite, on vient mettre en place un full TTY sur le shell en lan\u00e7ant les commandes suivantes :<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>python3 -c 'import pty; pty.spawn(\"\/bin\/bash\")'\n\nstty raw -echo; fg; ls; export SHELL=\/bin\/bash; export TERM=screen; stty rows 38 columns 116;<\/code><\/pre>\n\n\n\n<p>On a maintenant un vrai shell :<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"645\" height=\"254\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-33.png\" alt=\"\" class=\"wp-image-86\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-33.png 645w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-33-300x118.png 300w\" sizes=\"auto, (max-width: 645px) 100vw, 645px\" \/><\/figure>\n\n\n\n<p>On obtient le flag user.txt :<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"631\" height=\"257\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-34.png\" alt=\"\" class=\"wp-image-87\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-34.png 631w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-34-300x122.png 300w\" sizes=\"auto, (max-width: 631px) 100vw, 631px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Phase d&#8217;\u00e9l\u00e9vation de privil\u00e8ges<\/h2>\n\n\n\n<p>Pour \u00e9lever nos privil\u00e8ges voyons les commandes que nous pouvons lancer en compte root :<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"743\" height=\"125\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-35.png\" alt=\"\" class=\"wp-image-89\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-35.png 743w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-35-300x50.png 300w\" sizes=\"auto, (max-width: 743px) 100vw, 743px\" \/><\/figure>\n\n\n\n<p>Voyons voir ce fichier&#8230;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"240\" height=\"59\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-36.png\" alt=\"\" class=\"wp-image-90\"\/><\/figure>\n\n\n\n<p>Un shell qui se lance avec du perl via le fichier copy.sh, creusons.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"656\" height=\"43\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-37.png\" alt=\"\" class=\"wp-image-91\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-37.png 656w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-37-300x20.png 300w\" sizes=\"auto, (max-width: 656px) 100vw, 656px\" \/><\/figure>\n\n\n\n<p>Un netcat qui pointe vers l&#8217;adresse 192.168.0.190 et pointe sur le port 5554, essayons de changer cela pour le tirer \u00e0 notre avantage :<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"626\" height=\"23\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-38.png\" alt=\"\" class=\"wp-image-92\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-38.png 626w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-38-300x11.png 300w\" sizes=\"auto, (max-width: 626px) 100vw, 626px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"394\" height=\"23\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-39.png\" alt=\"\" class=\"wp-image-93\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-39.png 394w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-39-300x18.png 300w\" sizes=\"auto, (max-width: 394px) 100vw, 394px\" \/><\/figure>\n\n\n\n<p>On a plus qu&#8217;\u00e0 lancer le fichier en sudo avec une \u00e9coute sur un autre terminal et le tour sera jou\u00e9!<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"591\" height=\"25\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-40.png\" alt=\"\" class=\"wp-image-94\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-40.png 591w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-40-300x13.png 300w\" sizes=\"auto, (max-width: 591px) 100vw, 591px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"504\" height=\"218\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-41.png\" alt=\"\" class=\"wp-image-95\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-41.png 504w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-41-300x130.png 300w\" sizes=\"auto, (max-width: 504px) 100vw, 504px\" \/><\/figure>\n\n\n\n<p>Et voil\u00e0, nous sommes pass\u00e9s root sur la machine et pouvons r\u00e9cup\u00e9rer le flag correspondant!<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1025\" height=\"567\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-42.png\" alt=\"\" class=\"wp-image-96\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-42.png 1025w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-42-300x166.png 300w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/03\/image-42-768x425.png 768w\" sizes=\"auto, (max-width: 1025px) 100vw, 1025px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;Easy linux machine to practice your skills.&#8221;<\/p>\n","protected":false},"author":3,"featured_media":60,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-16","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ctf"],"_links":{"self":[{"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/posts\/16","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/comments?post=16"}],"version-history":[{"count":9,"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/posts\/16\/revisions"}],"predecessor-version":[{"id":97,"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/posts\/16\/revisions\/97"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/media\/60"}],"wp:attachment":[{"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/media?parent=16"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/categories?post=16"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/tags?post=16"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}