-
Notifications
You must be signed in to change notification settings - Fork 1
/
Copy pathIP [hostname].jex
819 lines (717 loc) · 45 KB
/
IP [hostname].jex
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
0c895516e3d2486589e141106e918903.md 000644 0000001435 13711251247 012113 0 ustar 00 000000 000000 Host Information (Post-Exploit Local Enum)
**Operating System:**
**Architecture:**
**Domain:**
**Users & Groups:**
**Installed Updates:**
***
See also: [Host Information (Pre-Exploit)](:/821c633f37534051babed2b4a8f6d217)
id: 0c895516e3d2486589e141106e918903
parent_id: a4b2704674904dc3b903d8255b30b78b
created_time: 2020-08-01T01:30:29.341Z
updated_time: 2020-08-01T01:43:13.715Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T01:30:29.341Z
user_updated_time: 2020-08-01T01:43:13.715Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 11dbf360c8684843bee0d0eff209829f.md 000644 0000001136 13711251247 012621 0 ustar 00 000000 000000 Running Processes
**Process List:**
id: 11dbf360c8684843bee0d0eff209829f
parent_id: a4b2704674904dc3b903d8255b30b78b
created_time: 2020-08-01T01:19:47.831Z
updated_time: 2020-08-01T01:20:05.767Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T01:19:47.831Z
user_updated_time: 2020-08-01T01:20:05.767Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 11e51517c41c4bc1a7dc398dad75f8cf.md 000644 0000001075 13711251247 012751 0 ustar 00 000000 000000 139
id: 11e51517c41c4bc1a7dc398dad75f8cf
parent_id: 77d4003a8fc84c4cb083dc9a7d8e0b78
created_time: 2020-08-01T00:02:45.204Z
updated_time: 2020-08-01T01:55:30.435Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 1
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T00:02:45.204Z
user_updated_time: 2020-08-01T01:55:30.435Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 13be4938ef354b4f82a955b5f751a88d.md 000644 0000000452 13711251247 012554 0 ustar 00 000000 000000 IP [hostname]
id: 13be4938ef354b4f82a955b5f751a88d
created_time: 2020-07-31T23:54:54.794Z
updated_time: 2020-08-01T11:31:20.399Z
user_created_time: 2020-07-31T23:54:54.794Z
user_updated_time: 2020-07-31T23:54:54.794Z
encryption_cipher_text:
encryption_applied: 0
parent_id:
is_shared: 0
type_: 2 33f2bca05abe4b9988b8396502df7f93.md 000644 0000001105 13711251247 012624 0 ustar 00 000000 000000 Credentials
id: 33f2bca05abe4b9988b8396502df7f93
parent_id: 868cd31d84a1407dbea572cd5a61ac2b
created_time: 2020-08-01T01:58:45.165Z
updated_time: 2020-08-01T01:58:51.244Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T01:58:45.165Z
user_updated_time: 2020-08-01T01:58:51.244Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 34d7a2d621fb4b91bf3497c02fce5f04.md 000644 0000001460 13711251247 012664 0 ustar 00 000000 000000 Attack surface questions
- What are our vulnerable services?
- What seems most likely or most straightforward to leverage and why?
- What does this service give us access to?
- Do we have all the correct files / versions / access to exploit?
id: 34d7a2d621fb4b91bf3497c02fce5f04
parent_id: 7fbb0ce03a4d499fa21108e7c6243e2e
created_time: 2020-08-01T01:26:36.902Z
updated_time: 2020-08-01T02:21:34.396Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T01:26:36.902Z
user_updated_time: 2020-08-01T02:21:34.396Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 39562a127a164d34add283f47939d685.md 000644 0000001075 13711251247 012331 0 ustar 00 000000 000000 445
id: 39562a127a164d34add283f47939d685
parent_id: 77d4003a8fc84c4cb083dc9a7d8e0b78
created_time: 2020-08-01T00:03:35.376Z
updated_time: 2020-08-01T00:03:38.229Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 1
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T00:03:35.376Z
user_updated_time: 2020-08-01T00:03:38.229Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 41fe390a9c0a438799a8a93ebdec7339.md 000644 0000002134 13711251247 012631 0 ustar 00 000000 000000 Exploitation
**Service Exploited:**
**Vulnerability Type:**
**Exploit POC:**
**Description:**
**Discovery of Vulnerability:**
**Exploit Code:**
If wasn't modified, paste link:
If was modified, provide the code:
```
<code>
```
**Flag:**
- [ ] Shell is interactive
- [ ] Machine IP is visible
- [ ] Absolute path to the flag file is visible
- [ ] Flag is visible
- [ ] Screenshot
- [ ] Submit low-priv flag to the control panel
- [ ] Paste low-priv flag here:
***
See also: [Privilege Escalation](:/e95b45481a9447d3bec4043f27f8c2e6)
id: 41fe390a9c0a438799a8a93ebdec7339
parent_id: f018ed5a45534ca488b0451e963dfc2a
created_time: 2020-08-01T01:49:11.695Z
updated_time: 2020-08-01T02:20:09.778Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T01:49:11.695Z
user_updated_time: 2020-08-01T02:20:09.778Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 575f83b958ea45fab4cc7faa39350b9f.md 000644 0000001261 13711251247 012770 0 ustar 00 000000 000000 http(s) port
- [ ] WhatWeb
- [ ] Check source code
- [ ] gobuster
- [ ] nikto
- [ ] CMS scanner
- [ ] WebDAV
- [ ] ZAP
id: 575f83b958ea45fab4cc7faa39350b9f
parent_id: 89ffe79eefb74c07a57629cb6627c79f
created_time: 2020-08-01T00:01:14.114Z
updated_time: 2020-08-01T02:23:15.229Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 1
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T00:01:14.114Z
user_updated_time: 2020-08-01T02:23:15.229Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 6493ec4250c5400795880d2c7a7e3a26.md 000644 0000001126 13711251247 012313 0 ustar 00 000000 000000 21
- [ ] Anonymous access?
id: 6493ec4250c5400795880d2c7a7e3a26
parent_id: 89ffe79eefb74c07a57629cb6627c79f
created_time: 2020-08-01T00:00:59.453Z
updated_time: 2020-08-01T00:08:15.734Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 1
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T00:00:59.453Z
user_updated_time: 2020-08-01T00:08:15.734Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 702c120bf24e4c238949327319bd1b20.md 000644 0000001200 13711251247 012261 0 ustar 00 000000 000000 File System
**Writeable Files/Directories:**
**Directory List:**
id: 702c120bf24e4c238949327319bd1b20
parent_id: a4b2704674904dc3b903d8255b30b78b
created_time: 2020-08-01T01:16:58.976Z
updated_time: 2020-08-01T01:59:56.949Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T01:16:58.976Z
user_updated_time: 2020-08-01T01:59:56.949Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 748d02509b1b4b43b89e25c8f72f5972.md 000644 0000001135 13711251247 012407 0 ustar 00 000000 000000 Scheduled jobs
**Sheduled Tasks:**
id: 748d02509b1b4b43b89e25c8f72f5972
parent_id: a4b2704674904dc3b903d8255b30b78b
created_time: 2020-08-01T01:46:10.547Z
updated_time: 2020-08-01T01:53:50.234Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T01:46:10.547Z
user_updated_time: 2020-08-01T01:53:50.234Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 77d4003a8fc84c4cb083dc9a7d8e0b78.md 000644 0000000500 13711251247 012673 0 ustar 00 000000 000000 UDP
id: 77d4003a8fc84c4cb083dc9a7d8e0b78
created_time: 2020-08-01T00:00:28.634Z
updated_time: 2020-08-01T00:00:31.742Z
user_created_time: 2020-08-01T00:00:28.634Z
user_updated_time: 2020-08-01T00:00:28.634Z
encryption_cipher_text:
encryption_applied: 0
parent_id: 7fbb0ce03a4d499fa21108e7c6243e2e
is_shared: 0
type_: 2 7a08a3139972423885560f06a8ef6353.md 000644 0000000524 13711251247 012166 0 ustar 00 000000 000000 4. Privilege Escalation
id: 7a08a3139972423885560f06a8ef6353
created_time: 2020-08-01T01:47:49.811Z
updated_time: 2020-08-01T02:04:10.824Z
user_created_time: 2020-08-01T01:47:49.811Z
user_updated_time: 2020-08-01T02:04:10.824Z
encryption_cipher_text:
encryption_applied: 0
parent_id: 13be4938ef354b4f82a955b5f751a88d
is_shared: 0
type_: 2 7fbb0ce03a4d499fa21108e7c6243e2e.md 000644 0000000513 13711251247 012657 0 ustar 00 000000 000000 1. Enumeration
id: 7fbb0ce03a4d499fa21108e7c6243e2e
created_time: 2020-07-31T23:58:12.285Z
updated_time: 2020-08-01T02:03:46.969Z
user_created_time: 2020-07-31T23:58:12.285Z
user_updated_time: 2020-08-01T02:03:46.969Z
encryption_cipher_text:
encryption_applied: 0
parent_id: 13be4938ef354b4f82a955b5f751a88d
is_shared: 0
type_: 2 821c633f37534051babed2b4a8f6d217.md 000644 0000001435 13711251247 012520 0 ustar 00 000000 000000 Host Information (Pre-Exploit)
**Operating System:**
**Architecture:**
**Domain:**
**Users & Groups:**
**Installed Updates:**
***
See also: [Host Information (Post-Exploit Local Enum)](:/0c895516e3d2486589e141106e918903)
id: 821c633f37534051babed2b4a8f6d217
parent_id: 937cdd78c9da4953910fbcb9a1e21cfa
created_time: 2020-08-01T01:13:02.314Z
updated_time: 2020-08-01T01:43:26.025Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T01:13:02.314Z
user_updated_time: 2020-08-01T01:43:26.025Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 868cd31d84a1407dbea572cd5a61ac2b.md 000644 0000000501 13711251247 012730 0 ustar 00 000000 000000 Loot
id: 868cd31d84a1407dbea572cd5a61ac2b
created_time: 2020-08-01T01:58:19.673Z
updated_time: 2020-08-01T02:03:23.904Z
user_created_time: 2020-08-01T01:58:19.673Z
user_updated_time: 2020-08-01T02:03:23.904Z
encryption_cipher_text:
encryption_applied: 0
parent_id: 13be4938ef354b4f82a955b5f751a88d
is_shared: 0
type_: 2 89ffe79eefb74c07a57629cb6627c79f.md 000644 0000000500 13711251247 012735 0 ustar 00 000000 000000 TCP
id: 89ffe79eefb74c07a57629cb6627c79f
created_time: 2020-08-01T00:00:18.243Z
updated_time: 2020-08-01T00:00:20.784Z
user_created_time: 2020-08-01T00:00:18.243Z
user_updated_time: 2020-08-01T00:00:18.243Z
encryption_cipher_text:
encryption_applied: 0
parent_id: 7fbb0ce03a4d499fa21108e7c6243e2e
is_shared: 0
type_: 2 8e8dd10ed0f941bfb9d5952f60a8ad6f.md 000644 0000001105 13711251247 013042 0 ustar 00 000000 000000 Nmap output
id: 8e8dd10ed0f941bfb9d5952f60a8ad6f
parent_id: 77d4003a8fc84c4cb083dc9a7d8e0b78
created_time: 2020-08-01T00:03:42.183Z
updated_time: 2020-08-01T00:03:49.104Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T00:03:42.183Z
user_updated_time: 2020-08-01T00:03:49.104Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 9042ab6559714de3995bef73afd96a41.md 000644 0000001221 13711251247 012545 0 ustar 00 000000 000000 Network
**ipconfig/ifconfig:**
**Network Processes:**
**ARP:**
**DNS:**
**Route:**
id: 9042ab6559714de3995bef73afd96a41
parent_id: a4b2704674904dc3b903d8255b30b78b
created_time: 2020-08-01T01:44:35.541Z
updated_time: 2020-08-01T02:00:03.825Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T01:44:35.541Z
user_updated_time: 2020-08-01T02:00:03.825Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 937cdd78c9da4953910fbcb9a1e21cfa.md 000644 0000000515 13711251247 013040 0 ustar 00 000000 000000 Host Information
id: 937cdd78c9da4953910fbcb9a1e21cfa
created_time: 2020-08-01T01:13:59.309Z
updated_time: 2020-08-01T01:14:13.815Z
user_created_time: 2020-08-01T01:13:59.309Z
user_updated_time: 2020-08-01T01:13:59.309Z
encryption_cipher_text:
encryption_applied: 0
parent_id: 7fbb0ce03a4d499fa21108e7c6243e2e
is_shared: 0
type_: 2 944da959be4740e0b379f3bd08a63304.md 000644 0000001252 13711251247 012455 0 ustar 00 000000 000000 Local Enum Script Output
- [ ] Did you run the script with thorough option?
**Script Output:**
```
<code>
```
id: 944da959be4740e0b379f3bd08a63304
parent_id: a4b2704674904dc3b903d8255b30b78b
created_time: 2020-08-01T00:34:49.174Z
updated_time: 2020-08-01T01:53:27.638Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T00:34:49.174Z
user_updated_time: 2020-08-01T01:53:27.638Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 958ba25d36b24afe9ca0149abc242bbe.md 000644 0000001155 13711251247 013015 0 ustar 00 000000 000000 Installed Applications
**Installed Applications:**
id: 958ba25d36b24afe9ca0149abc242bbe
parent_id: a4b2704674904dc3b903d8255b30b78b
created_time: 2020-08-01T01:43:55.590Z
updated_time: 2020-08-01T01:54:18.768Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T01:43:55.590Z
user_updated_time: 2020-08-01T01:54:18.768Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 9c348e407f3740fdbe3c7c9d4f8c2456.md 000644 0000001332 13711251247 012632 0 ustar 00 000000 000000 Flags
See the last step in the following notes:
[Exploitation](:/41fe390a9c0a438799a8a93ebdec7339)
[Privilege Escalation](:/e95b45481a9447d3bec4043f27f8c2e6)
id: 9c348e407f3740fdbe3c7c9d4f8c2456
parent_id: 868cd31d84a1407dbea572cd5a61ac2b
created_time: 2020-08-01T02:05:16.527Z
updated_time: 2020-08-01T02:40:12.283Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T02:05:16.527Z
user_updated_time: 2020-08-01T02:40:12.283Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 a4b2704674904dc3b903d8255b30b78b.md 000644 0000000521 13711251247 012360 0 ustar 00 000000 000000 3. Post Exploitation
id: a4b2704674904dc3b903d8255b30b78b
created_time: 2020-08-01T00:34:36.414Z
updated_time: 2020-08-01T02:04:04.321Z
user_created_time: 2020-08-01T00:34:36.414Z
user_updated_time: 2020-08-01T02:04:04.321Z
encryption_cipher_text:
encryption_applied: 0
parent_id: 13be4938ef354b4f82a955b5f751a88d
is_shared: 0
type_: 2 a8f69f4cfd1d4322804d88f8fe7c6574.md 000644 0000001100 13711251247 012636 0 ustar 00 000000 000000 Hashes
id: a8f69f4cfd1d4322804d88f8fe7c6574
parent_id: 868cd31d84a1407dbea572cd5a61ac2b
created_time: 2020-08-01T01:58:32.342Z
updated_time: 2020-08-01T01:58:36.383Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T01:58:32.342Z
user_updated_time: 2020-08-01T01:58:36.383Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 b0f8c29102384ffc99c78b4d835e66e1.md 000644 0000001077 13711251247 012561 0 ustar 00 000000 000000 Other
id: b0f8c29102384ffc99c78b4d835e66e1
parent_id: 868cd31d84a1407dbea572cd5a61ac2b
created_time: 2020-08-01T01:59:09.583Z
updated_time: 2020-08-01T01:59:13.197Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T01:59:09.583Z
user_updated_time: 2020-08-01T01:59:13.197Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 de103dda13f840bf91d197c383f6be39.md 000644 0000001105 13711251247 012670 0 ustar 00 000000 000000 Nmap output
id: de103dda13f840bf91d197c383f6be39
parent_id: 89ffe79eefb74c07a57629cb6627c79f
created_time: 2020-08-01T00:02:05.844Z
updated_time: 2020-08-01T00:02:13.753Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T00:02:05.844Z
user_updated_time: 2020-08-01T00:02:13.753Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 de39a7f2b7114dc4903e762a205817d3.md 000644 0000003466 13711251247 012457 0 ustar 00 000000 000000 Stuck? Things to consider
- [ ] Do you need a break?
- [ ] Have you confirmed the service on the port manually and googled all the things (the SSH string, the banner text, the source)?
- [ ] Is there a service that will allow you to enumerate something useful (i.e. usernames) but maybe doesn't make that obvious (e.g. RID brute-force through SMB with crackmapexec or lookupsid.py)?
- [ ] Have you used the best wordlist possible for your tasks (is there a better/bigger directory list? Is there a SecLists cred list for this service?)
- [ ] Have you fuzzed the directories you have found for a) more directories, or b) common filetypes -x php,pl,sh,etc
- [ ] Have you tried some manual testing (MySQL, Wireshark inspections)
- [ ] Have you collected all the hashes and cracked them?
- [ ] Have you tried ALL COMBINATIONS of the username/passwords and not just the pairs given? Have you tried them across all services/apps?
- [ ] Do the version numbers tell you anything about the host?
- [ ] Have you tried bruteforce (cewl, patator)?
- [ ] Can you think of a way to find more information: More credentials, more URLs, more files, more ports, more access?
- [ ] Do you need to relax some of the terms used for searching? Instead of v2.8 maybe we check for anything under 3.
id: de39a7f2b7114dc4903e762a205817d3
parent_id: 7fbb0ce03a4d499fa21108e7c6243e2e
created_time: 2020-08-01T01:23:41.134Z
updated_time: 2020-08-01T01:59:39.314Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T01:23:41.134Z
user_updated_time: 2020-08-01T01:59:39.314Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 e95b45481a9447d3bec4043f27f8c2e6.md 000644 0000002145 13711251247 012547 0 ustar 00 000000 000000 Privilege Escalation
**Service Exploited:**
**Vulnerability Type:**
**Exploit POC:**
**Description:**
**Discovery of Vulnerability:**
**Exploit Code:**
If wasn't modified, paste link:
If was modified, provide the code:
```
<code>
```
**Flag:**
- [ ] Shell is interactive
- [ ] Machine IP is visible
- [ ] Absolute path to the flag file is visible
- [ ] Flag is visible
- [ ] Screenshot
- [ ] Submit flag to the control panel
- [ ] Paste root / Adminstrator / SYSTEM flag here:
***
See also: [Exploitation](:/41fe390a9c0a438799a8a93ebdec7339)
id: e95b45481a9447d3bec4043f27f8c2e6
parent_id: 7a08a3139972423885560f06a8ef6353
created_time: 2020-08-01T00:13:01.564Z
updated_time: 2020-08-01T02:20:26.026Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author:
source_url:
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data:
order: 0
user_created_time: 2020-08-01T00:13:01.564Z
user_updated_time: 2020-08-01T02:20:26.026Z
encryption_cipher_text:
encryption_applied: 0
markup_language: 1
is_shared: 0
type_: 1 f018ed5a45534ca488b0451e963dfc2a.md 000644 0000000514 13711251247 012606 0 ustar 00 000000 000000 2. Exploitation
id: f018ed5a45534ca488b0451e963dfc2a
created_time: 2020-08-01T00:12:52.588Z
updated_time: 2020-08-01T02:03:54.008Z
user_created_time: 2020-08-01T00:12:52.588Z
user_updated_time: 2020-08-01T02:03:54.008Z
encryption_cipher_text:
encryption_applied: 0
parent_id: 13be4938ef354b4f82a955b5f751a88d
is_shared: 0
type_: 2