[HTB] Resource
by UnkownWombat - Saturday August 3, 2024 at 06:05 PM
#91
thinkphp is patched

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Asking for rep is not allowed
Reply
#92
(Aug 04, 2024, 01:52 PM)orwell1984 Wrote: I'm stuck on support user on the host, any hint on what to do next?

How did you get there? Did you use the sign_key_api.sh ?
Reply
#93
(Aug 04, 2024, 02:11 PM)orwell1984 Wrote:
(Aug 04, 2024, 02:06 PM)a44857437 Wrote:
(Aug 04, 2024, 01:52 PM)orwell1984 Wrote: I'm stuck on support user on the host, any hint on what to do next?

How did you get there? Did you use the sign_key_api.sh ?

yes

How ? You have a pub key signed from another CA... how can you use that ?
Reply
#94
(Aug 04, 2024, 01:52 PM)orwell1984 Wrote: I'm stuck on support user on the host, any hint on what to do next?

cat /etc/ssh/auth_principals/zzinter
zzinter_temp

try zzinter_temp principals
Reply
#95
guys ,what is the user flag step ?T_T

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#96
(Aug 04, 2024, 02:13 PM)x1rx Wrote:
(Aug 04, 2024, 01:52 PM)orwell1984 Wrote: I'm stuck on support user on the host, any hint on what to do next?

cat /etc/ssh/auth_principals/zzinter
zzinter_temp

try zzinter_temp principals

And then use the sudo privs for signing another one?
Reply
#97
(Aug 04, 2024, 03:01 PM)a44857437 Wrote:
(Aug 04, 2024, 02:13 PM)x1rx Wrote:
(Aug 04, 2024, 01:52 PM)orwell1984 Wrote: I'm stuck on support user on the host, any hint on what to do next?

cat /etc/ssh/auth_principals/zzinter
zzinter_temp

try zzinter_temp principals

And then use the sudo privs for signing another one?

mine says empty principal name btw
Reply
#98
Has anyone managed to escape from docker?
Reply
#99
(Aug 04, 2024, 03:06 PM)Unbutton8074 Wrote:
(Aug 04, 2024, 03:01 PM)a44857437 Wrote:
(Aug 04, 2024, 02:13 PM)x1rx Wrote:
(Aug 04, 2024, 01:52 PM)orwell1984 Wrote: I'm stuck on support user on the host, any hint on what to do next?

cat /etc/ssh/auth_principals/zzinter
zzinter_temp

try zzinter_temp principals

And then use the sudo privs for signing another one?

mine says empty principal name btw

I think the sudo script as zzinter on the host (Not the docker) is a rabbit hole. It doesn't work, as the variable names in the script are all wrong.

I feel there is some way to bypass the restriction of signing as the root_user principal on the fast_api site
Reply
Do we need to use the Signing API to sign using the /etc/ssh/ca_users_key.pub? If yes - what are user/principals to use? Can't seem to find a combination that will let me SSH into other port without password prompt.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 602 92,016 Yesterday, 06:48 PM
Last Post: sabero_exe
  [FREE] CPTS 12 FLAGS pulsebreaker 68 1,998 Yesterday, 09:54 AM
Last Post: VictorPipeau
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 371 93,053 Yesterday, 08:48 AM
Last Post: phannguyenbaouy1
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 21 2,642 Yesterday, 05:08 AM
Last Post: popoler
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,292 Apr 30, 2026, 02:10 PM
Last Post: kkkato

Forum Jump:


 Users browsing this forum: 1 Guest(s)