NahamCon0212 CTF - Sensible - Writeup
Introduction Today we're doing a CTF writeup for the Sensible challenge from the NahamCon2021 CTF. Sensible is a Linux PrivEsc challenge, and after we start the challenge we received a string we can use to interact with the challenge: First, we authenticate into the system using leo's credentials which we captured in a previous challenge: ssh -p 30010 leo@challenge.nahamcon.com input password: constelleorising After some enumeration, we find that there is an interesting file in the /opt/playbooks directory: cd /opt/playbooks ls This file, and the /playbooks directory's presence on the system points to this system running the Ansible configuration management program. We will try to confirm this: which ansible This implies that Ansible is indeed installed on this system. Let's take a look at the getinfo.yaml file: cat getinfo.yaml We see that there is a hash for the Ansible vault here. We can crack this hash after converting it into a format that John the Ripper...