> For the complete documentation index, see [llms.txt](https://infintesky.gitbook.io/pentesting/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://infintesky.gitbook.io/pentesting/proving-grounds/warm-up/linux/clamav.md).

# ClamAV

Writeup for ClamAV from offsec Proving Grounds

## Information Gathering

`sudo nmapAutomator.sh 192.168.220.42 all`

![](https://1575243701-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mg-SvuygW2bF4zu7kiy%2Fuploads%2F70CUuIPpQ3inILEVOSf6%2Fimage.png?alt=media\&token=d717f0d7-e68d-4dd1-9c2b-a37ac0fc31f2)

### Service Enumeration

### HTTP (Port 80)

We see that there is some binary on the page.

![](https://1575243701-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mg-SvuygW2bF4zu7kiy%2Fuploads%2FPEj2CfkFIr4VA89WVsIk%2Fimage.png?alt=media\&token=7f8f89b7-27e2-45fe-8b69-db3f210a1fe7)

We can use cyberchef to translate it, however, it doesn't seem too useful.

![](https://1575243701-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mg-SvuygW2bF4zu7kiy%2Fuploads%2FJmRHWOBXo2VPgaux3QUi%2Fimage.png?alt=media\&token=87b81e0b-bc59-482a-af2c-f86a891524ae)

We try running `gobuster` on it also, but there isn't anything interesting.

![](https://1575243701-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mg-SvuygW2bF4zu7kiy%2Fuploads%2F3RArIzrDSNKNPXyS5ccC%2Fimage.png?alt=media\&token=5ed55388-2428-4bd1-8d9c-69e2e23a38a2)

### SMB (Port 139,445)

No interesting shares on SMB either.

![](https://1575243701-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mg-SvuygW2bF4zu7kiy%2Fuploads%2F8g7q8aMdmFFnidu16vCS%2Fimage.png?alt=media\&token=e6d70e4b-bda7-4a5d-9e18-542c4b46d9e6)

### SMTP (Port 25)

We search the box name and see that there is a RCE exploit with SMTP.

![](https://1575243701-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mg-SvuygW2bF4zu7kiy%2Fuploads%2FxqwsDdw1cgDeP0SKf4n6%2Fimage.png?alt=media\&token=f9a87d0d-1cb6-4c2c-9a54-aa9b9c79e601)

## Exploit

{% embed url="<https://www.exploit-db.com/exploits/4761>" %}

Notice that the script opens port 31337 and calls a shell there.

![](https://1575243701-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mg-SvuygW2bF4zu7kiy%2Fuploads%2FJ5PbC79Ho9QndefD15JU%2Fimage.png?alt=media\&token=a81ebe4b-da7e-4c4d-b4a0-3ac552491c2f)

We run the script and it executes without any errors.

![](https://1575243701-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mg-SvuygW2bF4zu7kiy%2Fuploads%2F8ggXuFXnpOTrcr9YgRt9%2Fimage.png?alt=media\&token=b37c38fa-38ba-41a3-b08e-859841149ff0)

Checking port 31337, we see that it is closed before running the Perl script and after running the Perl script, the port becomes open.

![](https://1575243701-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mg-SvuygW2bF4zu7kiy%2Fuploads%2FTm1Iq49nG6MpFk56keSR%2Fimage.png?alt=media\&token=3b2fa98e-c59e-4362-873f-994902c07b40)

We can then connect to it and give the flag `-i` to get an interactive shell.

![](https://1575243701-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-Mg-SvuygW2bF4zu7kiy%2Fuploads%2FZuVuOPiJIL68SqmwcwyA%2Fimage.png?alt=media\&token=10c77f58-1e0c-4038-b6e7-583d38c93f16)
