HTB- Intuition
by trevor69000 - Saturday April 27, 2024 at 06:46 PM
#91
(Apr 28, 2024, 03:32 PM)AbsolutelyMadProc Wrote:
(Apr 28, 2024, 03:30 PM)query1338 Wrote: any hints for root?

Got the user hashes from the sqlite db file, but I am unable to crack the hash for adam... If this is the way please tell me how to crack it.

I cracked the hash, but it seems like it is only usable for the reports page

Try it on the ftp. This gives you a program and source.
The auth key can be brute forced easily but the user is missing permissions to the required directories.

Either access to one of the other users is needed or the password for sudo. That's where I'm stuck now.
Reply
#92
So I have dumped

1|admin|sha256$nypGJ02XBnkIQK71$f0e11dc8ad21242b550cc8a3c27baaf1022b6522afaadbfa92bd612513e9b606|admin

2|adam|sha256$Z7bcBO9P43gvdQWp$a67ea5f8722e69ee99258f208dc56a1d5d631f287106003595087cf42189fc43|webdev

how do I crack it? john does not load the hashes.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#93
(Apr 28, 2024, 05:19 PM)query1338 Wrote: So I have dumped

1|admin|sha256$nypGJ02XBnkIQK71$f0e11dc8ad21242b550cc8a3c27baaf1022b6522afaadbfa92bd612513e9b606|admin

2|adam|sha256$Z7bcBO9P43gvdQWp$a67ea5f8722e69ee99258f208dc56a1d5d631f287106003595087cf42189fc43|webdev

how do I crack it? john does not load the hashes.

Hashcat is the way to go.
Reply
#94
(Apr 28, 2024, 05:19 PM)query1338 Wrote: So I have dumped

1|admin|sha256$nypGJ02XBnkIQK71$f0e11dc8ad21242b550cc8a3c27baaf1022b6522afaadbfa92bd612513e9b606|admin

2|adam|sha256$Z7bcBO9P43gvdQWp$a67ea5f8722e69ee99258f208dc56a1d5d631f287106003595087cf42189fc43|webdev

how do I crack it? john does not load the hashes.

hashcat -m 30120 --- for adam pass
Reply
#95
runner program is strange. auth key is only used as an internal check. You can crack, or just recompile without the auth check. Doesn't make a difference either way in its execution. But there is an /opt/runner2 folder, maybe related.

Also there is an identical program /usr/local/bin/runner without the auth key check...
Reply
#96
(Apr 28, 2024, 05:25 PM)xxxbfacc Wrote: runner program is strange. auth key is only used as an internal check. You can crack, or just recompile without the auth check. Doesn't make a difference either way in its execution. But there is an /opt/runner2 folder, maybe related.

Also there is an identical program /usr/local/bin/runner without the auth key check...

I suspect that we somehow need to get access to Lopez or Adam since they both can access the runner2 directory. If the codebase is similar, it may still have the cmd injection vuln.

But as for how to get access, I feel like the access key should be used somehow/somewhere
Reply
#97
For everyone asking about how to get the files from FTP:
              ftp://ftp_admin:u3jai8y71s2@ftp.local/
Then just put the file you want after the /
              ftp://ftp_admin:u3jai8y71s2@ftp.local/{private_key}
Reply
#98
Can we do anything with selenium?
Reply
#99
(Apr 28, 2024, 05:36 PM)MakeFilez Wrote: For everyone asking about how to get the files from FTP:
              ftp://ftp_admin:u3jai8y71s2@ftp.local/
Then just put the file you want after the /
              ftp://ftp_admin:u3jai8y71s2@ftp.local/{private_key}

I can't connect to FTP, any tips or help....
grateful


This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching.
Reply
I got both the hash of adam and admin
please can someone guide what to do next

I got both the hash adam and admin
What is the next step kindly help me
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 603 92,346 5 hours ago
Last Post: 0xnany
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 23 2,724 5 hours ago
Last Post: 0xnany
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 374 93,323 5 hours ago
Last Post: 0xnany
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 8 538 8 hours ago
Last Post: mrmanual
  [FREE] CPTS 12 FLAGS pulsebreaker 70 2,143 9 hours ago
Last Post: neurodot

Forum Jump:


 Users browsing this forum: 1 Guest(s)