Clicker
Gaining Access
$ nmap -p- --min-rate 3000 10.129.70.56
Starting Nmap 7.93 ( https://nmap.org ) at 2023-09-24 23:35 +08
Nmap scan report for 10.129.70.56
Host is up (0.043s latency).
Not shown: 65526 closed tcp ports (conn-refused)
PORT STATE SERVICE
22/tcp open ssh
80/tcp open http
111/tcp open rpcbind
2049/tcp open nfs
38863/tcp open unknown
41469/tcp open unknown
43433/tcp open unknown
47485/tcp open unknown
58185/tcp open unknown$ nmap -p 22,80,111,2049,38863,41469,43433,47485,58185 -sC -sV --min-rate 3000 10.129.70.56
Starting Nmap 7.93 ( https://nmap.org ) at 2023-09-24 23:35 +08
Nmap scan report for 10.129.70.56
Host is up (0.011s latency).
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.4 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 256 89d7393458a0eaa1dbc13d14ec5d5a92 (ECDSA)
|_ 256 b4da8daf659cbbf071d51350edd81130 (ED25519)
80/tcp open http Apache httpd 2.4.52 ((Ubuntu))
|_http-title: Did not follow redirect to http://clicker.htb/
|_http-server-header: Apache/2.4.52 (Ubuntu)
111/tcp open rpcbind 2-4 (RPC #100000)
| rpcinfo:
| program version port/proto service
| 100000 2,3,4 111/tcp rpcbind
| 100000 2,3,4 111/udp rpcbind
| 100000 3,4 111/tcp6 rpcbind
| 100000 3,4 111/udp6 rpcbind
| 100003 3,4 2049/tcp nfs
| 100003 3,4 2049/tcp6 nfs
| 100005 1,2,3 37311/udp mountd
| 100005 1,2,3 47485/tcp mountd
| 100005 1,2,3 51863/udp6 mountd
| 100005 1,2,3 53445/tcp6 mountd
| 100021 1,3,4 34639/udp nlockmgr
| 100021 1,3,4 37758/udp6 nlockmgr
| 100021 1,3,4 43025/tcp6 nlockmgr
| 100021 1,3,4 43433/tcp nlockmgr
| 100024 1 38863/tcp status
| 100024 1 46781/tcp6 status
| 100024 1 49246/udp status
| 100024 1 52153/udp6 status
| 100227 3 2049/tcp nfs_acl
|_ 100227 3 2049/tcp6 nfs_acl
2049/tcp open nfs_acl 3 (RPC #100227)
38863/tcp open status 1 (RPC #100024)
41469/tcp open mountd 1-3 (RPC #100005)
43433/tcp open nlockmgr 1-4 (RPC #100021)
47485/tcp open mountd 1-3 (RPC #100005)
58185/tcp open mountd 1-3 (RPC #100005)NFS -> Source Code
Web Enumeration + Source Code Review



Admin Takeover

Export RCE



Privilege Escalation
RE SUID Binary -> Arbitrary Read




Sudo Privileges -> Root


Last updated