Skyfall - HTB
by paven - Saturday February 3, 2024 at 02:10 PM
video write up https://www.youtube.com/watch?v=pQtAk9OeC0k

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
I faced the issue with "mc alias set myminio http://prd23-s3-backend.skyfall.htb 5GrE1B2YGGyZzNHZaIww GkpjkmiVmpFuL2d3oRx0"

How can I use mc in just command line, not GUI
Reply
(Feb 07, 2024, 06:45 AM)hieule89 Wrote: I faced the issue with "mc alias set myminio http://prd23-s3-backend.skyfall.htb 5GrE1B2YGGyZzNHZaIww GkpjkmiVmpFuL2d3oRx0"

How can I use mc in just command line, not GUI

u are using midnight commander not minio...

./mc cp myminio/askyy/home_backup.tar.gz
./mc not mc

(Feb 05, 2024, 01:33 PM)sanish1 Wrote: give assky password

token for login
hvs.CAESIJlU9JMYEhOPYv4igdhm9PnZDrabYTobQ4Ymnlq1qYLGh4KHGh2cy43OVRNMnZhakZDRlZGdGVzN09xYkxTQVE

(Feb 05, 2024, 07:53 AM)GWTW Wrote:
(Feb 05, 2024, 06:40 AM)KillerWhale Wrote: any ideas for root flag? I'm searching but no luck

For the root flag,

Dig master token according to the sudo -l (Hint: debug mode)
and generate OTP just like user OTP with vault.

There you go...

You can DM me for certain points.
Good luck!

intended path to root is:
create a symbolic link from debug.log to /etc/update-motd.d/00-header , create a .yml file and write a command ;command; in the vault_nodes field and finally log in to ssh as askyy and run the command from 00-header

also, ctrlzero mentioned that the unintended paths will be patched today
HackTheBox - 99% Done - Get any flags or pwn you need
https://xan6.mysellix.io/
Reply
(Feb 07, 2024, 09:14 AM)xa6 Wrote:
(Feb 07, 2024, 06:45 AM)hieule89 Wrote: I faced the issue with "mc alias set myminio http://prd23-s3-backend.skyfall.htb 5GrE1B2YGGyZzNHZaIww GkpjkmiVmpFuL2d3oRx0"

How can I use mc in just command line, not GUI

u are using midnight commander not minio...

./mc cp myminio/askyy/home_backup.tar.gz
./mc not mc

(Feb 05, 2024, 01:33 PM)sanish1 Wrote: give assky password

token for login
hvs.CAESIJlU9JMYEhOPYv4igdhm9PnZDrabYTobQ4Ymnlq1qYLGh4KHGh2cy43OVRNMnZhakZDRlZGdGVzN09xYkxTQVE

(Feb 05, 2024, 07:53 AM)GWTW Wrote:
(Feb 05, 2024, 06:40 AM)KillerWhale Wrote: any ideas for root flag? I'm searching but no luck

For the root flag,

Dig master token according to the sudo -l (Hint: debug mode)
and generate OTP just like user OTP with vault.

There you go...

You can DM me for certain points.
Good luck!

intended path to root is:
create a symbolic link from debug.log to /etc/update-motd.d/00-header , create a .yml file and write a command ;command; in the vault_nodes field and finally log in to ssh as askyy and run the command from 00-header

also, ctrlzero mentioned that the unintended paths will be patched today

where should the yaml file be located and how would the command in the yaml be executed if we execute /etc/update-motd.d/00-header
Reply
(Apr 09, 2024, 06:30 AM)hcker01 Wrote:
(Feb 07, 2024, 09:14 AM)xa6 Wrote:
(Feb 07, 2024, 06:45 AM)hieule89 Wrote: I faced the issue with "mc alias set myminio http://prd23-s3-backend.skyfall.htb 5GrE1B2YGGyZzNHZaIww GkpjkmiVmpFuL2d3oRx0"

How can I use mc in just command line, not GUI

u are using midnight commander not minio...

./mc cp myminio/askyy/home_backup.tar.gz
./mc not mc

(Feb 05, 2024, 01:33 PM)sanish1 Wrote: give assky password

token for login
hvs.CAESIJlU9JMYEhOPYv4igdhm9PnZDrabYTobQ4Ymnlq1qYLGh4KHGh2cy43OVRNMnZhakZDRlZGdGVzN09xYkxTQVE

(Feb 05, 2024, 07:53 AM)GWTW Wrote:
(Feb 05, 2024, 06:40 AM)KillerWhale Wrote: any ideas for root flag? I'm searching but no luck

For the root flag,

Dig master token according to the sudo -l (Hint: debug mode)
and generate OTP just like user OTP with vault.

There you go...

You can DM me for certain points.
Good luck!

intended path to root is:
create a symbolic link from debug.log to /etc/update-motd.d/00-header , create a .yml file and write a command ;command; in the vault_nodes field and finally log in to ssh as askyy and run the command from 00-header

also, ctrlzero mentioned that the unintended paths will be patched today

where should the yaml file be located and how would the command in the yaml be executed if we execute /etc/update-motd.d/00-header

yes pwned i did in a different way you should search for symlink race condition
https://hackmd.io/@bachtam2001/BkZkudoLq
Reply
still trying to root it anyone help?

(Apr 14, 2024, 11:59 PM)hcker01 Wrote:
(Apr 09, 2024, 06:30 AM)hcker01 Wrote:
(Feb 07, 2024, 09:14 AM)xa6 Wrote:
(Feb 07, 2024, 06:45 AM)hieule89 Wrote: I faced the issue with "mc alias set myminio http://prd23-s3-backend.skyfall.htb 5GrE1B2YGGyZzNHZaIww GkpjkmiVmpFuL2d3oRx0"

How can I use mc in just command line, not GUI

u are using midnight commander not minio...

./mc cp myminio/askyy/home_backup.tar.gz
./mc not mc

(Feb 05, 2024, 01:33 PM)sanish1 Wrote: give assky password

token for login
hvs.CAESIJlU9JMYEhOPYv4igdhm9PnZDrabYTobQ4Ymnlq1qYLGh4KHGh2cy43OVRNMnZhakZDRlZGdGVzN09xYkxTQVE

(Feb 05, 2024, 07:53 AM)GWTW Wrote:
(Feb 05, 2024, 06:40 AM)KillerWhale Wrote: any ideas for root flag? I'm searching but no luck

For the root flag,

Dig master token according to the sudo -l (Hint: debug mode)
and generate OTP just like user OTP with vault.

There you go...

You can DM me for certain points.
Good luck!

intended path to root is:
create a symbolic link from debug.log to /etc/update-motd.d/00-header , create a .yml file and write a command ;command; in the vault_nodes field and finally log in to ssh as askyy and run the command from 00-header

also, ctrlzero mentioned that the unintended paths will be patched today

where should the yaml file be located and how would the command in the yaml be executed if we execute /etc/update-motd.d/00-header

yes pwned i did in a different way you should search for symlink race condition
https://hackmd.io/@bachtam2001/BkZkudoLq
Reply
(Apr 14, 2024, 11:59 PM)hcker01 Wrote:
(Apr 09, 2024, 06:30 AM)hcker01 Wrote:
(Feb 07, 2024, 09:14 AM)xa6 Wrote:
(Feb 07, 2024, 06:45 AM)hieule89 Wrote: I faced the issue with "mc alias set myminio http://prd23-s3-backend.skyfall.htb 5GrE1B2YGGyZzNHZaIww GkpjkmiVmpFuL2d3oRx0"

How can I use mc in just command line, not GUI

u are using midnight commander not minio...

./mc cp myminio/askyy/home_backup.tar.gz
./mc not mc

(Feb 05, 2024, 01:33 PM)sanish1 Wrote: give assky password

token for login
hvs.CAESIJlU9JMYEhOPYv4igdhm9PnZDrabYTobQ4Ymnlq1qYLGh4KHGh2cy43OVRNMnZhakZDRlZGdGVzN09xYkxTQVE

(Feb 05, 2024, 07:53 AM)GWTW Wrote:
(Feb 05, 2024, 06:40 AM)KillerWhale Wrote: any ideas for root flag? I'm searching but no luck

For the root flag,

Dig master token according to the sudo -l (Hint: debug mode)
and generate OTP just like user OTP with vault.

There you go...

You can DM me for certain points.
Good luck!

intended path to root is:
create a symbolic link from debug.log to /etc/update-motd.d/00-header , create a .yml file and write a command ;command; in the vault_nodes field and finally log in to ssh as askyy and run the command from 00-header

also, ctrlzero mentioned that the unintended paths will be patched today

where should the yaml file be located and how would the command in the yaml be executed if we execute /etc/update-motd.d/00-header

yes pwned i did in a different way you should search for symlink race condition
https://hackmd.io/@bachtam2001/BkZkudoLq
Can you help me to get a root?
Reply
Guys I think they just fixed some vulns on the box.


I need ROOT access.
But the command creates the log file with root permissions.
In case I create the file before I run the command, and set it's rights with chmod it's not working. Maybe it's deleting it before it writes the debug informations.
In case I try to append the new log file location at the end fo the command It's asking for askyy's password. Which isn't working because it's OTP. I think it's becuse did not match with the exact command from the sudo config.

There are some sites which leaching the master token, guess it. It's not working! I think they changed it.

HELP! Smile
Reply
Hello.
Did anyone get root after all the patches? Seems like symlink race is not the way, but I don't understand the intended way, can anyone provide hints?
Reply
Anyone? Noone at all?
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 602 91,778 9 hours ago
Last Post: sabero_exe
  [FREE] CPTS 12 FLAGS pulsebreaker 68 1,968 Yesterday, 09:54 AM
Last Post: VictorPipeau
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 371 92,977 Yesterday, 08:48 AM
Last Post: phannguyenbaouy1
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 21 2,627 Yesterday, 05:08 AM
Last Post: popoler
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,275 Apr 30, 2026, 02:10 PM
Last Post: kkkato

Forum Jump:


 Users browsing this forum: 1 Guest(s)