{"id":52,"date":"2022-03-31T00:14:21","date_gmt":"2022-03-31T00:14:21","guid":{"rendered":"https:\/\/cyberlorenzo.tech\/?p=52"},"modified":"2022-05-12T22:42:49","modified_gmt":"2022-05-12T22:42:49","slug":"project-one-continued","status":"publish","type":"post","link":"https:\/\/cyberlorenzo.tech\/?p=52","title":{"rendered":"Enumerating and Exploiting SMB &#8211; Continued"},"content":{"rendered":"\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/Screenshot-36-1024x719.png\" alt=\"\" class=\"wp-image-53\" width=\"711\" height=\"498\" srcset=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/Screenshot-36-1024x719.png 1024w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/Screenshot-36-300x211.png 300w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/Screenshot-36-768x539.png 768w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/Screenshot-36.png 1072w\" sizes=\"auto, (max-width: 711px) 100vw, 711px\" \/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Here we opened the ssh directory and found a list of keys. The most important key here that we want to download and copy is the &#8220;id_rsa&#8221; key. This is our private key. We want to grab this key instead of the other because this key is used to authenticate oneself when coming in contact with the public key data creating a key pair. Essentially as long as we have the private key we can authenticate in whichever parts of the SMB we would like.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"146\" src=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/Screenshot-37-1024x146.png\" alt=\"\" class=\"wp-image-56\" srcset=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/Screenshot-37-1024x146.png 1024w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/Screenshot-37-300x43.png 300w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/Screenshot-37-768x109.png 768w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/Screenshot-37.png 1032w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Here we are changing the permissions in order to write the id_rsa file into our .ssh folder using <code><mark style=\"background-color:#db4f3d\" class=\"has-inline-color\">chmod 600 [file]<\/mark><\/code><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"451\" src=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/Screenshot-38-1024x451.png\" alt=\"\" class=\"wp-image-55\" srcset=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/Screenshot-38-1024x451.png 1024w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/Screenshot-38-300x132.png 300w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/Screenshot-38-768x338.png 768w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/Screenshot-38-1536x676.png 1536w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/Screenshot-38.png 1758w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Next, using the <code><mark style=\"background-color:#db4f3d\" class=\"has-inline-color\">cp -b [file] \/root\/.ssh<\/mark> <\/code>we copied our private key to our local ssh directory. <\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"995\" height=\"754\" src=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/Screenshot-39.png\" alt=\"\" class=\"wp-image-57\" srcset=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/Screenshot-39.png 995w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/Screenshot-39-300x227.png 300w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/Screenshot-39-768x582.png 768w\" sizes=\"auto, (max-width: 995px) 100vw, 995px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Using the last name of the employee John Cactus during the enumeration phase we were able to gain access to his account.  <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This goes to show that proper configurations must be made or bits and pieces of information can be put together to exploit these systems. <\/p>\n\n\n<div class=\"is-default-size wp-block-site-logo\"><a href=\"https:\/\/cyberlorenzo.tech\/\" class=\"custom-logo-link\" rel=\"home\"><img loading=\"lazy\" decoding=\"async\" width=\"512\" height=\"413\" src=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/cropped-cropped-cropped-cropped-logo-large.png\" class=\"custom-logo\" alt=\"\" srcset=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/cropped-cropped-cropped-cropped-logo-large.png 512w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2022\/03\/cropped-cropped-cropped-cropped-logo-large-300x242.png 300w\" sizes=\"auto, (max-width: 512px) 100vw, 512px\" \/><\/a><\/div>","protected":false},"excerpt":{"rendered":"<p>Here we opened the ssh directory and found a list of keys. The most important key here that we want to download and copy is the &#8220;id_rsa&#8221; key. This is our private key. We want to grab this key instead of the other because this key is used to authenticate oneself when coming in contact [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":236,"comment_status":"open","ping_status":"open","sticky":false,"template":"templates\/right-sidebar.php","format":"standard","meta":{"saved_in_kubio":false,"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[4],"tags":[],"class_list":["post-52","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-project-one"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=\/wp\/v2\/posts\/52","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=52"}],"version-history":[{"count":4,"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=\/wp\/v2\/posts\/52\/revisions"}],"predecessor-version":[{"id":139,"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=\/wp\/v2\/posts\/52\/revisions\/139"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=\/wp\/v2\/media\/236"}],"wp:attachment":[{"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=52"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=52"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=52"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}