Apr 20, 2024, 05:42 PM
Hello everyone ! 1h and 20 min untill the launch of the runner machine [Linux - medium]
Good luck & have fun !
Good luck & have fun !
|
S5 First Machine - Runner
by itsBlackNight - Saturday April 20, 2024 at 05:42 PM
|
|
Apr 20, 2024, 05:42 PM
Hello everyone ! 1h and 20 min untill the launch of the runner machine [Linux - medium]
Good luck & have fun !
Apr 20, 2024, 07:22 PM
(This post was last modified: Apr 20, 2024, 07:50 PM by itsBlackNight.)
nmap -sS -p- $ip
PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 8000/tcp open http-alt dirsearch showed /assets on port 80 with 403 response && http://runner.htb:8000/version ->0.0.0-src teamcity.runner.htb maybe this is interesting /api/swagger-ui.html
Apr 20, 2024, 08:10 PM
(Apr 20, 2024, 07:22 PM)itsBlackNight Wrote: nmap -sS -p- $ip ow the heck did you get this teamcity, wasn't in any of my lists xDD
Apr 20, 2024, 08:11 PM
(This post was last modified: Apr 20, 2024, 08:28 PM by itsBlackNight.)
Apr 20, 2024, 09:05 PM
$2a$07$q.m8WQP8niXODv55lJVovOmxGtg6K/YPHbD48/JQsdGLulmeVo.Em:piper123
Apr 20, 2024, 10:02 PM
how can access container? any hints?
Apr 20, 2024, 10:17 PM
(Apr 20, 2024, 10:04 PM)3thic4lh4ck3r Wrote:(Apr 20, 2024, 09:05 PM)itsBlackNight Wrote: $2a$07$q.m8WQP8niXODv55lJVovOmxGtg6K/YPHbD48/JQsdGLulmeVo.Em:piper123 I just smoked a blunt & came back , So I got this with a couple of other hashes through the backups , I tried to ssh with it at first before just forgetting about it and finding id_rsa in the backups file I ran linpeas but nothing too much interesting But couple of ports running 5005 9433 and couples of other ones , found a password #BindPasswd: secret in the /etc/debconf.conf idk if its important here
Apr 21, 2024, 12:03 AM
(Apr 20, 2024, 10:20 PM)3thic4lh4ck3r Wrote:(Apr 20, 2024, 10:17 PM)itsBlackNight Wrote:(Apr 20, 2024, 10:04 PM)3thic4lh4ck3r Wrote:(Apr 20, 2024, 09:05 PM)itsBlackNight Wrote: $2a$07$q.m8WQP8niXODv55lJVovOmxGtg6K/YPHbD48/JQsdGLulmeVo.Em:piper123 apparently it's disabled, i tried the api https://docs.docker.com/engine/api/v1.41...tainerList and got the response {"message":"Unable to proxy the request via the Docker socket","details":"forbidden to use privileged mode"} idk if i'm doing something wrong or the whole thing is hard af
Apr 21, 2024, 12:48 AM
I'm actually going on the console path , got a stable revshella nd found some interesting directories , you can try linpeas on it too
Apr 21, 2024, 04:15 AM
Rooted. The last bit was pretty tricky if you arent very familiar with docker, and none of the portainer documentation so much as mentions this. You need to add driver options to the volume, specifically . Then you should be able to access it within the container
|
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| [FREE] CPTS 12 FLAGS | 66 | 1,774 |
3 hours ago Last Post: vlka |
||
| [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired | 370 | 92,502 |
8 hours ago Last Post: lifolifo007 |
||
| Hack the box Pro Labs, VIP, VIP+ 1 month free Method | 23 | 2,210 |
11 hours ago Last Post: kkkato |
||
| [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags | 20 | 2,523 |
Apr 29, 2026, 11:06 PM Last Post: op334 |
||
|
|
[FREE] HackTheBox All Cheatsheets | 3 | 414 |
Apr 29, 2026, 10:36 PM Last Post: op334 |
|