Alchemy - HTB Lab
by kewlcat002 - Monday September 23, 2024 at 12:21 PM
#41
(Oct 20, 2024, 07:05 PM)Heilel Wrote: Look closely to git commits... You will find credentials for SSH

Tried to clone repo, search all branches, trufflehog, git-secrets, tried to search commits via the platform itself... nothing literally no ssh creds Sad
What am I missing?
Reply
#42
(Oct 23, 2024, 10:30 AM)hTR7R5 Wrote:
(Oct 20, 2024, 07:05 PM)Heilel Wrote: Look closely to git commits... You will find credentials for SSH

Tried to clone repo, search all branches, trufflehog, git-secrets, tried to search commits via the platform itself... nothing literally no ssh creds Sad
What am I missing?

Look at the commits in all the projects. Make a filter "Password" haha.

Guys i'm open to help anyone who needs in this ProLab. The part i'm missing now it's the PLCs, and i'm currently studying for that. Feel free to DM.
Reply
#43
Can some please give me nudge for DC PrivEsc...I am having difficulties to find a path for PrivEsc
Reply
#44
The OT part is so confusing. im stuck at the PLCs.
Reply
#45
(Oct 22, 2024, 02:48 PM)notluken Wrote: Hint for WS02 -> list shares, maybe there are something you can do with the permission you have.

can u give a hint more precisely? I see there is development folder with write permission, then I don't have idea
Reply
#46
I am new to HTB so perhaps not following how they do flags properly.

I am working around R**ty portion, attempting to get it going and see if I can do something laterally.

I have not yet found a flag though - have I missed one at this point?

Captured the responder creds already. Am suspecting should have looked more through the gogs/gits but...am very unsure how these HTB things go.
Reply
#47
Do you recommend this pro lab?
Reply
#48
(Nov 10, 2024, 11:02 PM)Art10n Wrote: Do you recommend this pro lab?

Not sure who you are talking to, but for me its hard to say. I am struggling pretty bigly. Probably not my best choice for a first pro lab.
Reply
#49
(Oct 22, 2024, 10:20 PM)Heilel Wrote: Need a hint on The secret is out!  flag for ALCHEMY-LAUTERING-PLC . It seems that need look something related to  inkate process. But strugling to understand what need to search and what we should to do.

how did you connect to the PLC's network? i couldn't find the subnet?

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Malware. /Thread-Shellter-Pro-v4-7-x86-NOT-WORKING-crack
Reply
#50
If anyone still reading this topic..a nudge on WEB01 would be nice. Tried to scp an exploit to the system I have ssh creds for but nothing. Tried a few things w/ msfconsole as well but no luck.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 2 324 2 hours ago
Last Post: hibreackignos
  CBBH Write Ups hiddenhacker 22 6,182 4 hours ago
Last Post: Usercomplex
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 368 91,379 4 hours ago
Last Post: Usercomplex
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 86 7,769 11 hours ago
Last Post: my4ri0d0
  rev_dudidudida cavour13 1 245 Yesterday, 12:25 AM
Last Post: 0xcreep

Forum Jump:


 Users browsing this forum: 1 Guest(s)