Underpass - Linux - Easy
by StingEm - Saturday December 21, 2024 at 03:32 PM
#11
(Dec 21, 2024, 08:28 PM)0xdaniii Wrote:
(Dec 21, 2024, 08:10 PM)StingEm Wrote:
(Dec 21, 2024, 08:08 PM)maggi Wrote: http://underpass.htb/daloradius/app/oper...e-main.php

daloradius/app/operators/home-main.php

administrator:radius

Yes and from config db creds:

steve:testing123

-------------------FOUND----------
on http://10.129.52.94/daloradius/app/opera...st-all.php

svcMosh hash, crack it and ssh in for User.txt


Hash Crack = underwaterfriends
how you found hash?

hash is here
http://10.10.xx.xx/daloradius/app/operat...st-all.php
Hack the Box Season 8

https://t.me/+u1sCX38Xneo3OGM1
Reply
#12
Finish to Root at:

https://breachforums.bf/Thread-Underpass...#pid983250

-----
That was fun and its all here to follow - so don't let someone take your credits. You all got this! Cool
Reply
#13
(Dec 21, 2024, 08:44 PM)LostGem Wrote:
(Dec 21, 2024, 08:28 PM)0xdaniii Wrote:
(Dec 21, 2024, 08:10 PM)StingEm Wrote:
(Dec 21, 2024, 08:08 PM)maggi Wrote: http://underpass.htb/daloradius/app/oper...e-main.php

daloradius/app/operators/home-main.php

administrator:radius

Yes and from config db creds:

steve:testing123

-------------------FOUND----------
on http://10.129.52.94/daloradius/app/opera...st-all.php

svcMosh hash, crack it and ssh in for User.txt


Hash Crack = underwaterfriends
how you found hash?

hash is here
http://10.10.xx.xx/daloradius/app/operat...st-all.php



yeah i got it thanks buddy
Reply
#14
i had a hard time for this machine so yeah thankss

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#15
Hidden Content
You must register or login to view this content.

root id_rsa only

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#16
UDP Nmap scan > snmpwalk > feroxbuster with the directory found from one of the strings > default creds on login page > Find hash in daloradius/app/operators/mng-list-all.php > Crack hash and SSH in > sudo /usr/bin/mosh-server > Read the manual page for mosh-server > MOSH_KEY=XXXXXXX mosh-client 127.0.0.1 6000X > Root.
Just a few simple steps, can finish this box quickly

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#17
Yeah, this is really a simple easy box if you look carefully into the information revealed by snmp tool.
Reply
#18
awesome. works like a charm.
mosh --server="sudo /usr/bin/mosh-server" localhost

From docs
https://linux.die.net/man/1/mosh

Its also possible to connect as Ritualist says
Reply
#19
I want to study the blogger's articles carefully
Reply
#20
fun ways to learn new things keep it up guys

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] HackTheBox Dante - complete writeup written by Tamarisk Tamarisk 602 91,758 5 hours ago
Last Post: sabero_exe
  [FREE] CPTS 12 FLAGS pulsebreaker 68 1,959 Yesterday, 09:54 AM
Last Post: VictorPipeau
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 371 92,893 Yesterday, 08:48 AM
Last Post: phannguyenbaouy1
  [FREE] HackTheBox Academy - CBBH CDSA CPTS All Modules Flags Techtom 21 2,621 Yesterday, 05:08 AM
Last Post: popoler
  Hack the box Pro Labs, VIP, VIP+ 1 month free Method RedBlock 23 2,271 Apr 30, 2026, 02:10 PM
Last Post: kkkato

Forum Jump:


 Users browsing this forum: 1 Guest(s)