Skyfall - HTB
by paven - Saturday February 3, 2024 at 02:10 PM
#61
(Feb 04, 2024, 11:43 AM)peRd1 Wrote: Path to root is vault unseal command that sudo -l gives you. You need to grab the master token and use that to connect to the vault exactly same way as you did for the user.

Then try some other commands that you have privs to runand gain root access in a similar fashion as for the user.

And yes, that prd23 backend domain can be found out via 302 bypassing, try tab, or other chars, in hex, to bypass.

Also use vault instead of vlt of hashicorp, the first one has problems...  downloading the binary and unzipping is sufficient.

how to get master token? debugfile not readable..

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#62
I am using the dev role, because admin is denied, but how do you specify the username to login with, I am getting nobody, as user and my connection is closed.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#63
could please somebody explain the way from getting the API_ADDR and VAULT_TOKEN to logging in at ssh via the OTP?
I tried several things but am completely stuck now...log in at vault works and i even got some OTP for "something" but they all dont work for askyy...
Reply
#64
whenever i trie to add some params to mc command im getting error example :
mc ls --versions myminio/askyy/home_backup.tar.gz
Failed to run:
Unknown option --versions
Reply
#65
(Feb 04, 2024, 12:53 PM)U2t5d2lu Wrote: whenever i trie to add some params to mc command im getting error  example :
mc ls --versions myminio/askyy/home_backup.tar.gz
Failed to run:
Unknown option --versions

try
"mc ls --versions myminio" or

"mc ls -r --versions myminio"
Reply
#66
mc alias set myminio http://prd23-s3-backend.skyfall.htb 5G**** Gkp***
maybe its something wrong with alias?

(Feb 04, 2024, 01:23 PM)GWTW Wrote:
(Feb 04, 2024, 12:53 PM)U2t5d2lu Wrote: whenever i trie to add some params to mc command im getting error  example :
mc ls --versions myminio/askyy/home_backup.tar.gz
Failed to run:
Unknown option --versions

try
"mc ls --versions myminio" or

"mc ls -r --versions myminio"

exactly same result
Reply
#67
(Feb 04, 2024, 10:54 AM)GWTW Wrote:
(Feb 04, 2024, 10:53 AM)berlik Wrote:
(Feb 04, 2024, 09:36 AM)N4v4S Wrote: Hi guys. I am trying to understand how the `prd23-s3-backend.skyfall.htb` was discovered. Was it via fetch feature or some bypass technique had been used? Thank you in advance.

http://demo.skyfall.htb/metrics%0a

nice finding it is bro.
its not working for me
Reply
#68
finally had time to work on the box and got user.
It wasn't that insane.
going for root now
Reply
#69
(Feb 04, 2024, 03:13 PM)bsbsmaster Wrote: guys i need  help pls  # bash +o history mc alias set s3 http://prd23-s3-backend.skyfall.htb/mini...cs/cluster 5GrE1B2YGGyZzNHZaIww GkpjkmiVmpFuL2d3oRx0 bash -o history
/usr/bin/mc: /usr/bin/mc: cannot execute binary file
how i can fixit ?

had same issue was due to wrong version
Reply
#70
Can anyone please advice where can I find vault token? checked all source can not see it.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] CPTS 12 FLAGS pulsebreaker 68 1,935 7 hours ago
Last Post: VictorPipeau
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 601 91,582 7 hours ago
Last Post: VictorPipeau
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 371 92,797 8 hours ago
Last Post: phannguyenbaouy1
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 21 2,614 11 hours ago
Last Post: popoler
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,268 Yesterday, 02:10 PM
Last Post: kkkato

Forum Jump:


 Users browsing this forum: 1 Guest(s)