Posts

Showing posts with the label sudo -l

Hack the Box - OpenAdmin - Walkthrough

Image
Introduction Today we're going to be doing a pentest walkthrough of the OpenAdmin machine hosted at https://hackthebox.eu . For this pentest, we'll be using a Kali Linux virtual machine as our attacking system and the OpenAdmin machine as the victim system. After connecting to the Hack the Box network via VPN, we see that our target is located at 10.129.120.180. Scanning and Enumeration We'll start by scanning for open ports with Nmap : sudo nmap -T4 -p- 10.129.120.180 Now we'll do another Nmap scan, this time specifying the ports and picking up service names and version numbers: sudo nmap -sV -T4 -p22,80,6082 10.129.120.180 There seems to be some strange service running on port 6082, but the port doesn't seem to be open. We'll ignore that, and focus on the available webserver port. We'll do some directory busting with Gobuster : gobuster dir -u http://10.129.120.180 -w /usr/share/wordlists/dirb/big.txt -r -x txt,php,html -s 200,204,301,302,307,401,403 ...

Nahamcon2021 CTF - Banking On It - Writeup

Image
Introduction Today we're doing a CTF writeup for the Banking On It challenge from the NahamCon2021 CTF. Banking On It is a Linux PrivEsc challenge, and after we start the challenge we received a string we can use to interact with the challenge: First, we login to the server as the gus user, using an SSH private key captured from a previous challenge: ssh -i guskey.txt -p 31608 gus@challenge.nahamcon.com First, let's see if our user has any special sudo privileges: sudo -l Our user can run the SETENV command as root without a password when using the bank program in the /opt/banking/ directory. That means that if we're able to create a malicious shared object (.so) file, we can use the SETENV LD_PRELOAD command to activate the malicious .so file and elevate our privileges. First, let's see if there's a compiler on the system we can use to compile our .so file. which gcc That being confirmed, we move to a publicly writable directory and create our malicious...

TryHackMe - Linux PrivEsc - Walkthrough

Image
Introduction Today we're going to be doing a walkthrough for the Liinux PrivEsc room hosted at https://tryhackme.com/room/linuxprivesc . For this walkthrough, we'll be using two virtual machines (VMs), a Kali Linux VM as our attacking machine, and the deployed Debian Linux client as the the victim machine. Task 1 - Deploy the Vulnerable Debian VM Press the green button here: The Debian machine should come online after a minute or two. The IP address of the machine can be found here: Of course, the actual IP address will probably be a different one from the one in the screenshot. For the examples, however, we will use the IP address of 10.10.108.118 Next, connect to the Debian machine via SSH from our Kali Linux machine: ssh user@10.10.108.118 yes Enter password: password321 Questions: Deploy the machine and login to the "user" account using SSH. No answer needed Run the "id" command. What is the result? id uid=1000(user) gid=1000(user) grou...