S5 First Machine - Runner
by itsBlackNight - Saturday April 20, 2024 at 05:42 PM
#1
Hello everyone ! 1h and 20 min untill the launch of the runner machine [Linux - medium]
Good luck & have fun !
Reply
#2
nmap -sS -p- $ip

PORT    STATE SERVICE
22/tcp  open  ssh
80/tcp  open  http
8000/tcp open  http-alt

dirsearch showed /assets on port 80 with 403 response
&& http://runner.htb:8000/version ->0.0.0-src

teamcity.runner.htb

maybe this is interesting /api/swagger-ui.html
Reply
#3
(Apr 20, 2024, 07:22 PM)itsBlackNight Wrote: nmap -sS -p- $ip

PORT    STATE SERVICE
22/tcp  open  ssh
80/tcp  open  http
8000/tcp open  http-alt

dirsearch showed /assets on port 80 with 403 response
&& http://runner.htb:8000/version ->0.0.0-src

teamcity.runner.htb

maybe this is interesting /api/swagger-ui.html

ow the heck did you get this teamcity, wasn't in any of my lists xDD
Reply
#4
https://github.com/H454NSec/CVE-2023-42793

Reply
#5
$2a$07$q.m8WQP8niXODv55lJVovOmxGtg6K/YPHbD48/JQsdGLulmeVo.Em:piper123
Reply
#6
how can access container? any hints?
Reply
#7
(Apr 20, 2024, 10:04 PM)3thic4lh4ck3r Wrote:
(Apr 20, 2024, 09:05 PM)itsBlackNight Wrote: $2a$07$q.m8WQP8niXODv55lJVovOmxGtg6K/YPHbD48/JQsdGLulmeVo.Em:piper123

ya i got this too together with user saps, from here i use chisel to visit port 9000 - portainer service and then matthew credential to login, from here got no idea how to proceed next for priv esc

I just smoked a blunt & came back , So I got this with a couple of other hashes through the backups , I tried to ssh with it at first before just forgetting about it and finding id_rsa in the backups file 

I ran linpeas but nothing too much interesting But couple of ports running 5005 9433 and couples of other ones , found a password #BindPasswd: secret
in the /etc/debconf.conf idk if its important here
Reply
#8
(Apr 20, 2024, 10:20 PM)3thic4lh4ck3r Wrote:
(Apr 20, 2024, 10:17 PM)itsBlackNight Wrote:
(Apr 20, 2024, 10:04 PM)3thic4lh4ck3r Wrote:
(Apr 20, 2024, 09:05 PM)itsBlackNight Wrote: $2a$07$q.m8WQP8niXODv55lJVovOmxGtg6K/YPHbD48/JQsdGLulmeVo.Em:piper123

ya i got this too together with user saps, from here i use chisel to visit port 9000 - portainer service and then matthew credential to login, from here got no idea how to proceed next for priv esc

I just smoked a blunt & came back , So I got this with a couple of other hashes through the backups , I tried to ssh with it at first before just forgetting about it and finding id_rsa in the backups file 

I ran linpeas but nothing too much interesting But couple of ports running 5005 9433 and couples of other ones , found a password #BindPasswd: secret
in the /etc/debconf.conf idk if its important here

not sure never check till there was busy with portainer using this method
https://rioasmara.com/2021/08/15/use-por...scalation/

apparently it's disabled, i tried the api https://docs.docker.com/engine/api/v1.41...tainerList and got the response


{"message":"Unable to proxy the request via the Docker socket","details":"forbidden to use privileged mode"}

idk if i'm doing something wrong or the whole thing is hard af
Reply
#9
I'm actually going on the console path , got a stable revshella nd found some interesting directories , you can try linpeas on it too
Reply
#10
Rooted. The last bit was pretty tricky if you arent very familiar with docker, and none of the portainer documentation so much as mentions this. You need to add driver options to the volume, specifically
Hidden Content
You must register or login to view this content.
. Then you should be able to access it within the container
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] CPTS 12 FLAGS pulsebreaker 66 1,774 3 hours ago
Last Post: vlka
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 370 92,502 8 hours ago
Last Post: lifolifo007
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,210 11 hours ago
Last Post: kkkato
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 20 2,523 Apr 29, 2026, 11:06 PM
Last Post: op334
Heart [FREE] HackTheBox All Cheatsheets Tamarisk 3 414 Apr 29, 2026, 10:36 PM
Last Post: op334

Forum Jump:


 Users browsing this forum: 1 Guest(s)