> For the complete documentation index, see [llms.txt](https://1nuxg33k.gitbook.io/1nuxg33k-sec/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://1nuxg33k.gitbook.io/1nuxg33k-sec/vulnhub-walkthroughs/dc-series/dc-2.md).

# DC-2

https\://www\.vulnhub.com/entry/dc-2,311/

As usual we start with an nmap scan.

<figure><img src="https://2271353664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mc4yoWnnXV8DO0WadPB%2Fuploads%2FMdjAKqgqHb8VmUXBxL8b%2F314-1.png?alt=media&amp;token=fa281483-3ac8-4714-a143-5291eb9333a7" alt=""><figcaption><p>Port 80 and 7744 are open.</p></figcaption></figure>

SSH on 7744? Interesting. Lets check out the website on port 80 first.

<figure><img src="https://2271353664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mc4yoWnnXV8DO0WadPB%2Fuploads%2F5kTZYcLxMHbaT80PTlld%2F315-1.png?alt=media&amp;token=21674fc6-7ad6-4dc4-bccd-55b7d01011d7" alt=""><figcaption></figcaption></figure>

Pretty standard looking site. Hmm whats that Flag directory?

<figure><img src="https://2271353664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mc4yoWnnXV8DO0WadPB%2Fuploads%2FDrFdcT1zbdRDmpxgbHwo%2F317-1.png?alt=media&amp;token=9e0ef678-9664-4055-9e22-1a14d8a9ac74" alt=""><figcaption></figcaption></figure>

Found the first Flag! Like DC-1 there are five flags to be had.&#x20;

"you need to be cewl" hmm.&#x20;

cewl is a custom wordlist generator that is install in kali.

I'm not going to put the output of cewl as it is lengthy, I will simply put the command I ran though.

`cewl -w plist.txt dc-2`

So we have a password list, Now we need users.

Back to nmap!

`nmap -A -p 80,7744 10.6.6.19 --script=vuln`

This command gave me 3 usernames. I put the usernames in users.txt

I also ran a `dirb http://10.6.6.1`to see what directories there are and wp-admin came up so that is our way in.

Next I ran `wpscan -U users.txt -P plist.txt --url http://dc-2/` to match up usernames and passwords.

<figure><img src="https://2271353664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mc4yoWnnXV8DO0WadPB%2Fuploads%2FPa96Jlyy5KaSQCeA1p5E%2F111.png?alt=media&amp;token=e032af95-f009-4508-955f-e93a377feb02" alt=""><figcaption><p>Well I can't give everything away!</p></figcaption></figure>

Now we can login to wp-admin.

I first logged in with tom but didn't find any flags. I then logged in with jerry and found flag 2.

<figure><img src="https://2271353664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mc4yoWnnXV8DO0WadPB%2Fuploads%2FW3WQ7JR8qsQ1AP0GhRtM%2F318-2.png?alt=media&amp;token=100e186b-6f25-4bab-84b5-d895af5445b8" alt=""><figcaption></figcaption></figure>

Ok lets startup msf and get flag3. Well wait....another entry point? ssh was open. Password reuse perhaps?

Tried jerry and he is not reusing passwords.

Did get in with `ssh tom@10.6.6.19 -p 7744` though. Nice! We have a shell.

So first thing I tried was to cat flag3.txt. Well cat isn't installed. Good'ol vi it is then.

<figure><img src="https://2271353664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mc4yoWnnXV8DO0WadPB%2Fuploads%2Fhqcujh6Gq40Sfn9OX6Fe%2F319-1.png?alt=media&amp;token=31c3f57f-1e41-4290-b6f8-86aa3f914a80" alt=""><figcaption><p>Flag 3</p></figcaption></figure>

Whats interesting about this machine is that you are in a restricted shell.&#x20;

After doing a bit of research on restricted shells I found that tom can run the less command. Tom can also read jerrys home directory which contains flag4.txt

<figure><img src="https://2271353664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mc4yoWnnXV8DO0WadPB%2Fuploads%2FBufaxFozEWUxiOfTAUoI%2F319-2.png?alt=media&amp;token=dc3f0933-35a0-43a4-8086-0821366c518f" alt=""><figcaption><p>Flag 4</p></figcaption></figure>

Alright all on my own! To gtfobins we go.&#x20;

vi is a little tricky for beginners so I will walk through what I did and the commands I ran.

<figure><img src="https://2271353664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mc4yoWnnXV8DO0WadPB%2Fuploads%2FzW1ZJnbeSLiQq9XKEEZJ%2F319-3.png?alt=media&amp;token=9ba1cd31-2b10-4023-a943-916977a30768" alt=""><figcaption><p><a href="https://gtfobins.github.io/gtfobins/vi/">https://gtfobins.github.io/gtfobins/vi/</a></p></figcaption></figure>

First run&#x20;

```
vi -c ':!/bin/sh' /dev/null
```

and press Enter.

Then type&#x20;

```
:set shell=/bin/sh
```

Press enter and then type `:shell`

You should now see a $ and a flashing cursor.&#x20;

After running these commands we need to export the path:

`export PATH=/bin:/usr/bin:$PATH`

Now we should be able to `su jerry`as flag3 suggested and read flag4.

<figure><img src="https://2271353664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mc4yoWnnXV8DO0WadPB%2Fuploads%2FPXtJQUhv8uaZF3232BF3%2F320-1.png?alt=media&amp;token=2876c88e-46da-4952-9e5e-95c58e5b1adf" alt=""><figcaption><p>Flag4</p></figcaption></figure>

git outta here? Another hint!

&#x20;run `sudo -l`

<figure><img src="https://2271353664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mc4yoWnnXV8DO0WadPB%2Fuploads%2FRUf2NOz8iow6RxwSJjk9%2F319-5.png?alt=media&amp;token=2a03cc89-92cd-492d-bfd5-e59d0dc0f1a1" alt=""><figcaption></figcaption></figure>

Hmm looks like we can run /usr/bin/git without a password. Lets check out gtfobins again.

{% embed url="<https://gtfobins.github.io/gtfobins/git/>" %}

Since we can run git without a password we can exploit the binary and gain a root shell.

```
sudo git -p help config
!/bin/sh
```

<figure><img src="https://2271353664-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mc4yoWnnXV8DO0WadPB%2Fuploads%2Fr3oi2SA2bsd1yhcBJZyV%2F321-4.png?alt=media&amp;token=066c6066-df57-465e-8598-07e74d2a03fc" alt=""><figcaption></figcaption></figure>

Nice!

For more on restricted shells see <https://www.gnu.org/software/bash/manual/html_node/The-Restricted-Shell.html>

To learn more about vi there are a lot of great videos on youtube or see this website <https://vitux.com/working-with-vi-editor-in-linux/>

I suggest learning at least the basics of vi as that may be the only text editor on a linux machine.
