Lame
Simple Linux machine with Samba exploit using Metasploit.
Last updated
Simple Linux machine with Samba exploit using Metasploit.
Last updated
This box can be found .
Initial nmap scan:
SMB port 445 seems open. Let's scan this port further.
I will open Metasploit and use this exploit.
I will then configure my options and run the exploit.
And we directly have a root shell!
There is not much else to do now apart from finding the flags. After a bit of searching I found the user flag in /home/makis
and the root flag in /root
(obviously).
We have Samba version 3.0.20. After searching Exploit DB, it looks like it is vulnerable to . Also, the page tells us the exploit is available in Metasploit.
And we have both flags!