> For the complete documentation index, see [llms.txt](https://writeups.adityadindi.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://writeups.adityadindi.com/tryhackme/untitled/dav.md).

# Dav

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-McK-sNTjuJlnQv8uez7%2F-McL3Nc85Vjx7PKe8H5e%2Fimage.png?alt=media\&token=a6972bd6-2bd9-4660-b020-66e86c3b5105)

## Reconnaissance

Initial nmap scan to find open ports , using the flag "treat all hosts as alive" (**-Pn**)

```
nmap -Pn 10.10.1.27
```

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-McK-sNTjuJlnQv8uez7%2F-McL3kaNaiUd0TFzCD-e%2Fimage.png?alt=media\&token=d92df5eb-0a40-4b96-86d4-e2e014320d7a)

Detailed Nmap Scan :&#x20;

Command Breakdown:&#x20;

* (**-sV):** Service version
* (**-sC**): Default nmap scripts
* (**-p):** Specifying ports 80
* (**-oN nmap**): Saving it into a file called nmap

```
nmap -sV -sC -p 80 -oN nmap 10.10.1.27
```

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-McK-sNTjuJlnQv8uez7%2F-McL4DfVADBd-ZOakAmx%2Fimage.png?alt=media\&token=aedab3cf-fd5e-43af-a5b3-89e582c4899e)

## Enumeration

Lets visit the site

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-McK-sNTjuJlnQv8uez7%2F-McL4_sRBBjBlDK8Zbzg%2Fimage.png?alt=media\&token=1a756f9c-f1b1-4cd6-abbc-065c2d06c9ca)

Its a default apache2 page, lets run gobuster to find hidden directories.

```
gobuster dir -w /usr/share/wordlists/dirb/common.txt -u http://10.10.1.27/ 
```

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-McL5AnVc9Z8Ah7oPsXn%2F-McL6AE4we71Ln_lj5Kz%2Fimage.png?alt=media\&token=475cddba-106a-4b37-93d4-1cca9d6be563)

We have a directory called `/webdav`, lets go check it out.

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-McL5AnVc9Z8Ah7oPsXn%2F-McL6JkylQ_BziOkSysA%2Fimage.png?alt=media\&token=5d297723-2203-42b6-9142-11358806bf11)

We have to login, we do not have a username or a password, lets go look for default credentials. Looking on google , I found this [article](http://xforeveryman.blogspot.com/2012/01/helper-webdav-xampp-173-default.html), and found a default username and password

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-McL5AnVc9Z8Ah7oPsXn%2F-McL6hROVrJVoxMrrtDv%2Fimage.png?alt=media\&token=25a9e53f-bf78-4bb1-a704-7b37ae252a3e)

Now lets try to login

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-McL5AnVc9Z8Ah7oPsXn%2F-McL6skmUVOSzLhbQfyq%2Fimage.png?alt=media\&token=950a6769-c0cb-40cf-b34b-be72388696df)

We are logged in, lets look at the `password.dav` file.

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-McL5AnVc9Z8Ah7oPsXn%2F-McL6zKeEl1pPNylwKWU%2Fimage.png?alt=media\&token=9a1b40b0-aec4-4591-afb2-a97d1f076075)

We have a username and a password.

## Exploitation

After this I looked for vulnerabilities for webdav and found that we can upload a file and then get a reverse shell if we upload a reverse shell.

We can upload a file using this command, you can find a reverse shell [here](https://github.com/pentestmonkey/php-reverse-shell).

```
curl --user "wampp:xampp" http://10.10.1.27/webdav/ --upload-file /root/shell.php
```

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-McL8QIW5j3aUZufnWAH%2F-McL91Lf32Hx-BgXYgOl%2Fimage.png?alt=media\&token=b5b9cdab-ade4-434f-a2a1-723d427b9c5e)

After uploading it, refresh the page and you should see the file

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-McL8QIW5j3aUZufnWAH%2F-McL9OkAwLOXXLPsl7KN%2Fimage.png?alt=media\&token=afeae58e-1712-4207-8fc4-3dc856dcac8f)

Now lets start a reverse shell listener.

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-McL8QIW5j3aUZufnWAH%2F-McL9UpNcgQ9cqcxAS8i%2Fimage.png?alt=media\&token=ebce7ce8-011e-49f9-b6c5-4cca4b12707c)

Now click the file on the webpage and you should get a reverse shell.

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-McL8QIW5j3aUZufnWAH%2F-McL9dQ0JOW2sp6ISpAM%2Fimage.png?alt=media\&token=bd42eea0-e2dd-4d4e-a442-f6337d427ab5)

Now lets stabilize the shell.

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-McL8QIW5j3aUZufnWAH%2F-McL9vM6fk7c9sYKQJ3z%2Fimage.png?alt=media\&token=b511dac3-712d-4c25-b3ae-91fbf70bba65)

Now you can read the user flag.

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-McL8QIW5j3aUZufnWAH%2F-McLA9Y3zBj4_HQKTVaa%2Fimage.png?alt=media\&token=94f5578a-f584-4fd5-bd68-6e835b21623a)

## Privilege Escalation

Lets run `sudo -l` to see what we can run as other users.

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-McLAETxl0g-xCWyjoE-%2F-McLANo7y8NId4cf_UCb%2Fimage.png?alt=media\&token=58bdd9d4-77a4-4593-a224-d0dfe277b7df)

Looks like we can run /bin/cat, lets read the root.txt file with this

![](https://1569822153-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-Ma_-L-NUkJ1mxbddZG2%2F-McLAETxl0g-xCWyjoE-%2F-McLAY9XWNje8w0_oQFW%2Fimage.png?alt=media\&token=d6dac084-c8bc-48ac-be68-e9a174ea675f)
