Tags:htb,hacking Related to:practice,htb,write-up,rce,pfsense,
First things First!
Quick fast scan on top 100 ports
Starting Nmap 7.93 ( https://nmap.org ) at 2023-08-02 22:12 EDT
Nmap scan report for
Host is up (0.047s latency).
Not shown: 98 filtered tcp ports (no-response)
80/tcp open http
443/tcp open https
Nmap done: 1 IP address (1 host up) scanned in 15.23 seconds
We have port 80 and 443 Open
Same result for top 1k ports scan and all port scan
Default scripts scan and Version scan on Port 443 and 80
We have - lighttpd 1.4.35 - server Nothing interesting (no interesting vulns)
Tried to browse the page and I get a login page.
Lets dirbust and also think of sign in bypass
Found this endpoint during dirbusting
Found version: SilverStripe Tree Control: v0.1,
https://www.exploit-db.com/exploits/34113 - Possible vuln
Changes made
Exploit doesn’t seem to work
Dirbusting reveals changelog.txt & system-users.txt.
Creds Rohit:pfsense
pfsense is default password for pfsense firewall
We can see the version of pfsense is 2.1.3
We copy exploit to our directory
On checking exploit we see that it takes the arguments and runs a python reverse shell
We get a direct root shell
Root flag🚩 in /root/root.txt User flag 🚩 in /home/rohit/user.txt