Findings Log
Username: "R1ckRul3s"
Password: "Wubbalubbadubdub"
Ports open:
22 --> OpenSSH 7.2p2 Ubuntu 4ubuntu2.6 (Ubuntu Linux; protocol 2.0)
80 --> Apache httpd 2.4.18 ((Ubuntu))
Backend uses PHP
Login Page: /login.php
First Ingredient --> mr. meeseek hair
In the /portal.php source code, there is a base64 encrypted comment that doesn't decrypt to anything:
I went down the rabbit hole. Seriously. F*** them.
This decrypts to
rabbit hole
if you base64 encrypt it like 10 times. I literally sat there and kept decrypting it wondering if I would get something juicy.
From Command Console you can gain RCE with:
you can find the second ingredient 1 jerry tearUse
sudu su
to become root without needing a password.The third ingredient is located in
fleeb juice
