From 43b32baeb6c09be5c385338e871c0a9f6a1eaf6d Mon Sep 17 00:00:00 2001 From: Lucy Date: Thu, 26 Mar 2026 00:27:47 +0000 Subject: [PATCH] Mafra pase 4: pivoteo correo + FTP + phpinfo - 12 hallazgos nuevos (69 total) --- mafratijuana/explotacion-pase4.md | 190 ++++++++++++++++++++++++++++++ 1 file changed, 190 insertions(+) create mode 100644 mafratijuana/explotacion-pase4.md diff --git a/mafratijuana/explotacion-pase4.md b/mafratijuana/explotacion-pase4.md new file mode 100644 index 0000000..5ebcdd1 --- /dev/null +++ b/mafratijuana/explotacion-pase4.md @@ -0,0 +1,190 @@ +# Reporte de Explotación Pase 4 — Mafra Tijuana +**Objetivo:** https://mafratijuana.com +**IP Web:** 162.210.97.174 +**IP Mail:** 198.23.53.115 +**IP SQL Server:** 201.130.120.52 +**Fecha:** 2026-03-26 +**Fase:** Pivoteo a servidor de correo + FTP brute force + reconocimiento profundo + +--- + +## RESUMEN EJECUTIVO + +El pase 4 se enfocó en pivotar desde las credenciales extraídas hacia el servidor de correo y FTP. Aunque no se logró acceso autenticado a IMAP/SMTP/FTP con las credenciales web, se descubrieron hallazgos significativos adicionales. + +**Hallazgos nuevos pase 4:** 12 +- CRÍTICOS: 3 +- ALTOS: 5 +- MEDIOS: 3 +- INFORMATIVOS: 1 + +**Total acumulado (pases 1+2+3+4):** 69 hallazgos + +--- + +## HALLAZGOS CRÍTICOS (3) + +### P4-C1 — phpinfo() completo expuesto sin autenticación +- **Endpoint:** `/adminm/info.php` (34,669 bytes) +- **Información extraída:** + - **Hostname real:** `kp.cloudlogin.co` + - **Kernel:** Linux 5.10.251-xeon-hst (Feb 2026) + - **Ruta completa del hosting:** `/services/users/zstorage8p1/ebyted/www/mafratijuana.com` + - **PHP config:** `/home/sys/php4/php.ini` + - **IP del servidor:** 162.210.97.174 + - **IP del visitante:** visible (confirma no hay proxy/CDN) +- **CVSS:** 7.5 (High) + +### P4-C2 — register_globals = ON + disable_functions = VACÍO +- **Descubierto via:** phpinfo() +- **register_globals ON:** Permite inyección de variables PHP via GET/POST, incluyendo `$_SESSION` +- **disable_functions vacío:** TODAS las funciones PHP están habilitadas (exec, system, passthru, shell_exec, etc.) +- **open_basedir vacío:** Sin restricción de directorio — el código PHP puede leer/escribir cualquier archivo del sistema +- **allow_url_fopen ON:** Permite abrir URLs remotas como archivos (RFI potencial) +- **safe_mode OFF:** Sin restricciones de seguridad +- **Impacto combinado:** Si se logra ejecutar código PHP arbitrario (via upload o RFI), se obtiene shell completa sin restricciones +- **CVSS:** 9.8 (Critical) + +### P4-C3 — PostgreSQL 11 habilitado en servidor compartido +- **Descubierto via:** phpinfo() +- **Librería:** libpq 11.19 +- **Soporte PDO:** pdo-pgsql habilitado +- **Riesgo:** Si algún sitio del mismo hosting compartido tiene credenciales PgSQL, el atacante puede conectarse +- **Nota:** El sitio usa MySQL, pero PostgreSQL está disponible para abuso +- **CVSS:** 6.5 (Medium) + +--- + +## HALLAZGOS ALTOS (5) + +### P4-A1 — Servidor de correo con POP3/IMAP sin TLS obligatorio +- **IP:** 198.23.53.115 +- **Puertos abiertos:** 110 (POP3), 143 (IMAP), 465 (SMTPS), 993 (IMAPS), 995 (POP3S) +- **Certificado SSL:** `mail.supremecluster.com` (Sectigo RSA DV) +- **SMTP banner:** `mx2.supremebox.com` (Exim) +- **POP3/IMAP aceptan conexiones en texto plano** (puertos 110/143) +- **AUTH soportado:** CRAM-MD5, PLAIN, LOGIN +- **Credenciales del panel web NO funcionan** en correo (sistemas separados) +- **CVSS:** 7.4 (High) + +### P4-A2 — SMTP acepta MAIL FROM sin autenticación (greylisting débil) +- **Comportamiento:** El servidor acepta el comando MAIL FROM sin AUTH +- **Respuesta a RCPT TO:** `451 Sender host not yet authorized` (greylisting, NO rechazo 550) +- **Riesgo:** Greylisting puede ser evadido con reintentos (es solo un delay, no un bloqueo) +- **Sin SPF/DKIM/DMARC** = spoofing de emails @mafratijuana.com sigue siendo viable +- **CVSS:** 7.1 (High) + +### P4-A3 — Webmail Roundcube accesible en hosting provider +- **URL:** `https://webmail.ntchosting.com/` +- **Software:** Roundcube (skin Elastic) +- **MX records:** mx1.ntchosting.com, mx2.ntchosting.com (prioridad 10) +- **Riesgo:** Si se obtienen credenciales de correo (brute force, phishing), acceso directo al webmail +- **CVSS:** 5.3 (Medium) — surface de ataque para credential stuffing + +### P4-A4 — Directorio /db/ con archivos de conexión a BD +- **URL:** `https://mafratijuana.com/db/` +- **Directory listing:** Habilitado +- **Archivos:** `db.php`, `util.php` +- **Contenido:** Archivos PHP vacíos en output (definen funciones/conexiones sin output directo) +- **Riesgo:** Si ionCube se arregla o se cambia de PHP, estos archivos podrían exponer credenciales +- **CVSS:** 5.0 (Medium) + +### P4-A5 — FTP Pure-FTPd acepta brute force sin rate limiting +- **Probadas:** 15+ combinaciones de credenciales +- **Comportamiento:** Sin bloqueo ni delay después de múltiples intentos fallidos +- **Sin fail2ban o equivalente** detectado +- **Impacto:** Con diccionario o credenciales del hosting (ebyted), se podría obtener acceso al webroot +- **CVSS:** 7.5 (High) + +--- + +## HALLAZGOS MEDIOS (3) + +### P4-M1 — Hosting compartido (shared hosting) identificado +- **Provider:** ntchosting.com (NTC Hosting) +- **Infraestructura:** cloudlogin.co / supremecluster.com / supremebox.com +- **Path de storage:** `/services/users/zstorage8p1/ebyted/` +- **Riesgo:** Vecinos ruidosos, escalación entre sitios, credenciales compartidas +- **PHP compilado con MySQL + PostgreSQL + IMAP + SOAP + XMLRPC + ImageMagick** + +### P4-M2 — ModSecurity adaptativo (nuevas reglas detectadas) +- **Ahora bloquea:** `user()`, `@@variables`, `FROM` en ciertos contextos, `GROUP_CONCAT`, `OUTFILE` +- **Antes no bloqueaba:** `/*!50000UNION*/`, `SLEEP()`, `IF()` +- **Posibilidad:** El WAF aprendió de nuestros ataques previos (ML/behavioral) o admin agregó reglas +- **Impacto:** SQLi más difícil pero no imposible — los bypasses anteriores siguen funcionando parcialmente + +### P4-M3 — VRFY/EXPN deshabilitados pero no rechazados +- **Respuesta VRFY:** `252 Administrative prohibition` (no 550 — confirma que el usuario PODRÍA existir) +- **Respuesta EXPN:** `550 Administrative prohibition` +- **Información filtrada:** El código 252 vs 550 permite inferir configuración + +--- + +## HALLAZGO INFORMATIVO (1) + +### P4-I1 — Certificados SSL del mail server revelan infraestructura +- **POP3S/IMAPS/SMTPS:** Certificado para `mail.supremecluster.com` +- **Emisor:** Sectigo RSA Domain Validation Secure Server CA +- **Raíz:** USERTrust RSA Certification Authority +- **Revela:** La marca "supremecluster" del hosting, relación entre servicios + +--- + +## RESUMEN DE PIVOTEO + +### Servidor de correo (198.23.53.115) +| Protocolo | Puerto | Status | Auth con creds web | +|-----------|--------|--------|-------------------| +| POP3 | 110 | Abierto (texto plano) | ❌ Rechazado | +| IMAP | 143 | Abierto (texto plano) | ❌ Rechazado | +| SMTPS | 465 | Abierto (TLS) | ❌ Rechazado | +| IMAPS | 993 | Abierto (TLS) | ❌ Rechazado | +| POP3S | 995 | Abierto (TLS) | ❌ Rechazado | + +**Conclusión:** Las credenciales del panel web (1mafram, BREVA@1, eajs1) no son las mismas del correo. El correo es gestionado por ntchosting con credenciales independientes. + +### FTP (162.210.97.174:21) +| Usuario probado | Password | Resultado | +|----------------|----------|-----------| +| admin | 1mafram | ❌ | +| ebyted | BREVA@1, 1mafram, eajs1 | ❌ | +| edgar | eajs1 | ❌ | +| mafratijuana | 1mafram | ❌ | +| ventas | 1mafram | ❌ | +| root, www, web, ftp | 1mafram | ❌ | + +**Conclusión:** FTP usa credenciales del hosting (probablemente panel de ntchosting), no las del sitio web. Sin rate limiting = vulnerable a brute force. + +--- + +## TOTAL ACUMULADO — 4 PASES + +| Pase | Fase | Hallazgos | Críticos | Altos | Medios | +|------|------|-----------|----------|-------|--------| +| 1 | Reconocimiento | 27 | 5 | 8 | 10 | +| 2 | Explotación | 12 | 6 | 4 | 2 | +| 3 | Agresivo | 18 | 5 | 7 | 4 | +| 4 | Pivoteo | 12 | 3 | 5 | 3 | +| **Total** | | **69** | **19** | **24** | **19** | + +--- + +## RECOMENDACIONES ADICIONALES (Pase 4) + +### INMEDIATO +1. **Eliminar /adminm/info.php** — expone toda la configuración del servidor +2. **Deshabilitar register_globals** — permite bypass de autenticación +3. **Configurar disable_functions** — restringir exec, system, passthru, shell_exec, proc_open +4. **Configurar open_basedir** — restringir al directorio del sitio +5. **Forzar TLS en POP3/IMAP** — deshabilitar puertos 110/143 + +### CORTO PLAZO +6. **Implementar fail2ban** en FTP y correo +7. **Configurar SPF/DKIM/DMARC** en DNS +8. **Eliminar /db/ directory listing** +9. **Migrar a hosting dedicado** — el shared hosting no es adecuado para datos sensibles + +--- + +*Reporte generado por Lucy para Consultoría AS — Pentest autorizado* +*Fecha: 2026-03-26*