Posts: 96
Threads: 2
Joined: Feb 2024
Does anyone have a hint / nudge for the last flag we need, "There is always another way" ?
It's the lautering PLC and we found the password, but need to bypass the write restrictions... (and yes, I now about pymodbustcp, but still stumped)
Posts: 14
Threads: 0
Joined: Dec 2024
(Nov 15, 2024, 05:46 AM)HTBcracker Wrote: (Nov 14, 2024, 08:32 AM)a44857437 Wrote: (Nov 13, 2024, 10:13 PM)UVB76 Wrote: If anyone still reading this topic..a nudge on WEB01 would be nice. Tried to scp an exploit to the system I have ssh creds for but nothing. Tried a few things w/ msfconsole as well but no luck.
Is that the initial foothold machine? If so, look for a request with a special parameter you can manipulate and try to 'respond' to it from your kali machine
(Nov 01, 2024, 07:27 PM)qwaz Wrote: (Oct 22, 2024, 02:48 PM)notluken Wrote: Hint for WS02 -> list shares, maybe there are something you can do with the permission you have.
can u give a hint more precisely? I see there is development folder with write permission, then I don't have idea
See if you have permissions on that share, and maybe you can change that one file so it reaches out to you?
(Nov 12, 2024, 10:41 AM)HTBcracker Wrote: (Oct 22, 2024, 10:20 PM)Heilel Wrote: Need a hint on The secret is out! flag for ALCHEMY-LAUTERING-PLC . It seems that need look something related to inkate process. But strugling to understand what need to search and what we should to do.
how did you connect to the PLC's network? i couldn't find the subnet?
There's a client.ovpn on the EW machine for that
(Nov 13, 2024, 10:13 PM)UVB76 Wrote: If anyone still reading this topic..a nudge on WEB01 would be nice. Tried to scp an exploit to the system I have ssh creds for but nothing. Tried a few things w/ msfconsole as well but no luck.
Quickly checked my notes...
As you already have SSH access, you can escalate to root (I used linux exploit suggester) and find another flag, then run ligolo-ng, chisel or whatever to tunnel to the internal network
before i didn't pwn the printer box so i couldn't find the right subnet, but now do you have any hints for the PLC's part? i've never work with this technology before
Can you please point me to the printer box or EW? I only found one subnet 172.x.x.x and the initial subnet 10.x.x.x. Is there something that I am missing?
Posts: 6
Threads: 0
Joined: Oct 2023
Dec 30, 2024, 03:01 PM
(This post was last modified: Dec 30, 2024, 03:02 PM by fayeA.)
for SCADA( 0.20) root
hxxps://www.hackingarticles.in/lxd-privilege-escalation/
this is the way
Posts: 14
Threads: 0
Joined: Dec 2024
(Dec 30, 2024, 03:01 PM)fayeA Wrote: for SCADA( 0.20) root
hxxps://www.hackingarticles.in/lxd-privilege-escalation/
this is the way
Did you figure out anything related to PLC?
Posts: 6
Threads: 0
Joined: Oct 2023
(Jan 02, 2025, 02:44 AM)anthony123 Wrote: (Dec 30, 2024, 03:01 PM)fayeA Wrote: for SCADA( 0.20) root
hxxps://www.hackingarticles.in/lxd-privilege-escalation/
this is the way
Did you figure out anything related to PLC?
No clue, sry
Posts: 161
Threads: 1
Joined: Dec 2024
(Sep 24, 2024, 12:16 PM)kewlcat002 Wrote: Lets keep the thread as a learning opportunity and not aimlessly spoil content, future reference.
good mercii go testerrr caa
Posts: 3
Threads: 0
Joined: Jan 2025
Lets keep the thread as a learning opportunity and not aimlessly spoil content, future reference.
Posts: 5
Threads: 0
Joined: Oct 2024
Can any one give a hins for PLC parts area 100 i have guest access for HMI and try with pymodbus and multiple way but no value return, I don't know the right way I should take.
Posts: 96
Threads: 2
Joined: Feb 2024
(Jan 07, 2025, 09:36 PM)Bogyeman Wrote: Can any one give a hins for PLC parts area 100 i have guest access for HMI and try with pymodbus and multiple way but no value return, I don't know the right way I should take.
Which IP addresses are you looking for? There are 2 area100 (a and b) IIRC...
Posts: 5
Threads: 0
Joined: Oct 2024
(Jan 08, 2025, 04:58 PM)a44857437 Wrote: (Jan 07, 2025, 09:36 PM)Bogyeman Wrote: Can any one give a hins for PLC parts area 100 i have guest access for HMI and try with pymodbus and multiple way but no value return, I don't know the right way I should take.
Which IP addresses are you looking for? There are 2 area100 (a and b) IIRC...
A x.2 , x.3
|