Lame

Overview

Initial Foothold : SMB Exploit ( CVE-2007-2447 )

Privilege Escation : No Need

Enumeration

Port Scanning

Run Full Nmap Scan with script scan

Nmap script scan got us some results. Lets Start with smb because version is looking old and there can be vulnerbility

SMB Service Enumeration

We got version of smb i.e. smbd 3.0.20 Debain

lets enumrate shares and thier permissions using nmap scripts

From the above scripts results we got that there is tmp directory which has anonymous access along with write permissions

Lets find out is the service vulnerable

After Searching for the above smb service we got many exploits from metasploit hence we can conclude that the service is vulnerable

Summary

We got exploit for smb service

we also got tmp directory on which we have full rights to access

Exploitation

Manual way

We can use exploit from github for exploiting this service

Lets Exploit this

Boom !! We got root shell

No Neded For Privilege Escation

Last updated