[HTB] MonitorsThree
by celsius - Saturday August 24, 2024 at 05:26 PM
#81
(Aug 25, 2024, 12:36 AM)rootme1122 Wrote:
(Aug 25, 2024, 12:34 AM)upl04d3r Wrote:
(Aug 25, 2024, 12:33 AM)olkn00b Wrote: any tip on how to get from www-data to marcus?

find database and hash

 after that????????

ohh really? you have hash user password, maybe try hashcat Wink
Reply
#82
from www-data to marcus: check /var/www/html/cacti/include/config.php where you'll find database connection credentials, connect to mariadb and get the password hash of marcus, crack it and you got your user flag

Any idea on privesc from duplicati to root?

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#83
(Aug 24, 2024, 10:39 PM)mascon Wrote:
(Aug 24, 2024, 10:21 PM)noidontwant Wrote:
(Aug 24, 2024, 10:06 PM)teky Wrote: can somebody drop the hash this shit is taking forever

dont do time-based, other injection methods work too

The only thing that worked was Stacked Query, basically changing the admin password hash to something like md5 of '1234' and using that pw to login, but I don't see anything interesting and the hashes can't be cracked with rockyou and john.

What do you mean it's faster? Elaborate please

(Aug 25, 2024, 12:30 AM)aasdawejkasjdkasd Wrote: They aren't really trolling.
Create a backup from /source/home/marcus to /source/tmp/test1
Restore created backup to /source/tmp/test2

Get id_rsa


I jumped a step. You can do this for the root flag directly without even getting marcus.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#84
(Aug 25, 2024, 12:52 AM)aasdawejkasjdkasd Wrote:
(Aug 24, 2024, 10:39 PM)mascon Wrote:
(Aug 24, 2024, 10:21 PM)noidontwant Wrote:
(Aug 24, 2024, 10:06 PM)teky Wrote: can somebody drop the hash this shit is taking forever

dont do time-based, other injection methods work too

The only thing that worked was Stacked Query, basically changing the admin password hash to something like md5 of '1234' and using that pw to login, but I don't see anything interesting and the hashes can't be cracked with rockyou and john.

What do you mean it's faster? Elaborate please

(Aug 25, 2024, 12:30 AM)aasdawejkasjdkasd Wrote: They aren't really trolling.
Create a backup from /source/home/marcus to /source/tmp/test1
Restore created backup to /source/tmp/test2

Get id_rsa


I jumped a step. You can do this for the root flag directly without even getting marcus.

What are the exact steps you did?

I did create a backup for /root/root.txt and stored it in /tmp/flag
Then everytime I do a restore backup I get ``Failed to connect: No filesets found on remote target``

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#85
(Aug 25, 2024, 12:41 AM)wtfduw Wrote: from www-data to marcus: check /var/www/html/cacti/include/config.php where you'll find database connection credentials, connect to mariadb and get the password hash of marcus, crack it and you got your user flag

Any idea on privesc from duplicati to root?

you don't need to do any of that you can just set marcus password in cacti , but I can't connect to marcus via ssh , it's not allowed with a password.

www-data@monitorsthree:/tmp$ cat /etc/ssh/sshd_config | grep -i PasswordAuthentication
<tc/ssh/sshd_config | grep -i PasswordAuthentication
PasswordAuthentication no
# PasswordAuthentication.  Depending on your PAM configuration,
# PAM authentication, then enable this but set PasswordAuthentication


what am i doing wrong?
Reply
#86
I'm curious to know how you guys got the cacti creds, I found the 4 hashes through SQLi, but none was cracked using hashcat
hashcat -m 0 -a 0 hashes.txt rockyou.txt
Session..........: hashcat
Status...........: Exhausted

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#87
for marcus : 12345678910 don't waste time

after marcus port forward 8200 ... and bypass auth
https://medium.com/@STarXT/duplicati-byp...4d6991e9ee

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Asking for rep is not allowed
Reply
#88
(Aug 25, 2024, 01:25 AM)osamy7593 Wrote: for marcus : 12345678910 don't waste time

after marcus port forward 8200 ... and bypass auth
https://medium.com/@STarXT/duplicati-byp...4d6991e9ee

Thanks, I don't waste time, I just want to take my time to understand.
Having marcus password was easier using the below :
.\hashcat.exe -m 3200 .\marcus.hash .\rockyou.txt

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#89
You need to use -m 0
Reply
#90
i got duplicatti db file and just browsing it, what next? all i see is file:///source/opt/backups/cacti/

em too sleepy maybe. Tell me guys what to do? em dumb rn. wont sleep until i find root flag
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 87 7,970 1 hour ago
Last Post: char0n1507
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 9 562 1 hour ago
Last Post: char0n1507
  CBBH Write Ups hiddenhacker 23 6,340 1 hour ago
Last Post: somecrazykid
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 26 2,795 2 hours ago
Last Post: Neuromanc3r
  [FREE] CPTS 12 FLAGS pulsebreaker 72 2,211 4 hours ago
Last Post: coolguyaroundyou

Forum Jump:


 Users browsing this forum: