Posts

Showing posts with the label process enum

Hack The Box - Heist - Walkthrough

Image
Introduction Today we're going to be doing a pentest walkthrough of the Heist machine hosted at https://hackthebox.eu.  For this pentest, we'll be using a Kali Linux virtual machine as our attacking system and the Heist machine as the victim system.  After connecting to the Hack the Box network via VPN, we see that our target is located at 10.129.118.120. Scanning and Enumeration We'll start by scanning for open ports with Nmap: nmap -T4 -p- 10.129.118.120 Now we'll do another Nmap scan, this time specifying the ports and picking up service names and version numbers: nmap -sV -T4 -p80,135,445,5985,49669 10.129.118.120 This seems mostly typical for Windows systems, but we notice that port 5985 is open, which is associated with WinRM , so we'll keep in mind as we continue with our enumeration.  For now, we'll take a look at the webpage: http://10.129.118.120 If we don't have credentials for the page, we might as well try enumerating as a guest user: http://10...

Nahamcon2021 CTF - Internal - Writeup

Image
Introduction Today we're doing a CTF writeup for the Internal challenge from the NahamCon2021 CTF. Internal is a Linux PrivEsc challenge, and after we start the challenge we received a string we can use to interact with the challenge: The first thing we do is log in to the system as the orion user using captured SSH credentials we obtained from a a previous challenge: ssh -p 30718 orion@challenge.nahamcon.com input password: stars4love4life While enumerating running processes, we find some interesting stuff: ps -aux The root user is running MySQL as well as a Bash script that references MySQL . Let's take a look at that Bash script: cat /create_mysql_admin_user.sh The information in the script indicates that the root account in MySQL is setup without a password. Let's login to MySQL as root now: mysql -uroot -p input a blank password Using MySQL as the root user, we can read any files in the system that we are aware of. Because the common location of the flag.tx...