The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.
|
[Challenge] Gain shell on server [/Challenge]
filter_list
|
|
|
Thirteen Years of Service
Posts: 529
Threads: 60
[Challenge] Gain shell on server [/Challenge] 07-13-2014, 07:26 AM
#1
Website:
http://www.scorpion.ne.jp
Objective: Gain a fully interactive command line based shell on the server
Method: RCE
Difficulty: Medium-hardish
Proof -
Post a screenshot in the same way I did for proof
Good luck
This was done using a public vulnerability just so everyone knows. I just thought it'd be a good challenge.
Solvers -
Dyme
Arthur Curry
Oni
•
Thirteen Years of Service
Posts: 2,723
Threads: 223
RE: [Challenge] Gain shell on server [/Challenge] 07-13-2014, 08:10 AM
#2
There's supposed to be a 404 right?
•
Thirteen Years of Service
Posts: 529
Threads: 60
RE: [Challenge] Gain shell on server [/Challenge] 07-13-2014, 08:23 AM
#3
(07-13-2014, 08:10 AM)Adorapuff Wrote: There's supposed to be a 404 right?
Not sure what you mean but the way I did it, I didn't encounter any 404s.
•
Thirteen Years of Service
Posts: 4,425
Threads: 308
RE: [Challenge] Gain shell on server [/Challenge] 07-13-2014, 08:49 AM
#4
(07-13-2014, 08:23 AM)Crypt Wrote: Not sure what you mean but the way I did it, I didn't encounter any 404s.
The index page has a 404.
Code:
Not Found
The requested URL / was not found on this server.
•
Thirteen Years of Service
Posts: 954
Threads: 26
RE: [Challenge] Gain shell on server [/Challenge] 07-13-2014, 02:41 PM
#5
I applaud you for posting something that actually retains my interest.
I see that your id differs from mine... perhaps we utilized a different vulnerability on the server? Mine was command injection as well.
(07-13-2014, 08:10 AM)Adorapuff Wrote: There's supposed to be a 404 right?
(07-13-2014, 08:49 AM)Aurora Wrote: The index page has a 404.
I don't know if it's 'supposed to', but the vulnerable software is completely independent of the index page.
•
Thirteen Years of Service
Posts: 529
Threads: 60
RE: [Challenge] Gain shell on server [/Challenge] 07-13-2014, 04:25 PM
#6
(07-13-2014, 02:41 PM)Dyme Wrote: I applaud you for posting something that actually retains my interest.
![[Image: OZIL3hP.png]](http://i.imgur.com/OZIL3hP.png)
I see that your id differs from mine... perhaps we utilized a different vulnerability on the server? Mine was command injection as well.
I don't know if it's 'supposed to', but the vulnerable software is completely independent of the index page.
Nice, added you to the solvers list. I'll try to create more challenges like these.
•
Thirteen Years of Service
Posts: 2,723
Threads: 223
RE: [Challenge] Gain shell on server [/Challenge] 07-13-2014, 04:37 PM
#7
(07-13-2014, 02:41 PM)Dyme Wrote: I applaud you for posting something that actually retains my interest.
![[Image: OZIL3hP.png]](http://i.imgur.com/OZIL3hP.png)
I see that your id differs from mine... perhaps we utilized a different vulnerability on the server? Mine was command injection as well.
I don't know if it's 'supposed to', but the vulnerable software is completely independent of the index page.
Thanks. I'll try the challenge when I get back home on the 17th
•
Thirteen Years of Service
Posts: 4,425
Threads: 308
RE: [Challenge] Gain shell on server [/Challenge] 07-13-2014, 06:52 PM
#8
(07-13-2014, 02:41 PM)Dyme Wrote: I don't know if it's 'supposed to', but the vulnerable software is completely independent of the index page.
I see.
(07-13-2014, 04:37 PM)Adorapuff Wrote: Thanks. I'll try the challenge when I get back home on the 17th
As will I. Hopefully my laptop'll turn on. :/
•
Thirteen Years of Service
Posts: 4,425
Threads: 308
RE: [Challenge] Gain shell on server [/Challenge] 07-14-2014, 05:08 PM
#9
May I ask how old this vulnerability is? I'm using a fairly old verstion of the msf.
•
Thirteen Years of Service
Posts: 954
Threads: 26
RE: [Challenge] Gain shell on server [/Challenge] 07-14-2014, 05:17 PM
#10
(07-14-2014, 05:08 PM)Aurora Wrote: May I ask how old this vulnerability is? I'm using a fairly old verstion of the msf.
Exploiting the vulnerability has nothing to do with msf... If you're referring to my post - all I did was execute a meterpreter shell to meet the op's requirements (an interactive shell of some kind). I did not use a metasploit module to exploit the bug itself.
On a completely off topic note: I would recommend re installing metasploit using git.
•
Users browsing this thread: