CREATIVE
Creative Room TryHackMe - Easy

CREATIVE

Enumeration

Ports 22 and 80 are open
Web App Analysis - Nothing interesting
Let's look for some subdomains - beta.creative.thm
The Tester allows us to check if the URL is alive - Checking
We got a response
Analyzing the request with Burp Suite. It seems that we are facing a SSRF
There's no response
Let's create a numeration file from 1 to 65535 (Number of ports)
Fuzzing the local server we found the port 80 and 1337 are listening
Port 1337 is presenting all the Directories.
We get the user 'saad'
and our first FLAG
We have access to .ssh and we get the private key.
id_rsa is password protected. Let's use John The Ripper.
We got the password.
Finally, we got access to the system as 'saad'.
The first place we checked, was '.bash_history' where we found saad's password.
With the password we are able to check which binaries 'saad' could run as 'root' | Lets use 'sudo -l'
PRIVILEGE ESCALATION --> Reference:
Compiling process.
We got root privileges.
























要查看或添加评论,请登录

Eduardo Cochella的更多文章

  • You Got Mail

    You Got Mail

    Enumeration Let's start this room by running Nmap. We can see the smtp, pop3 and imap are in the server.

  • Lookup - TryHackMe

    Lookup - TryHackMe

    Basic Scan: SSH and HTTP are running. NMAP basic scan Analyzing the Web Application: We had to deal with a login page.

  • Cheese CTF

    Cheese CTF

    NMAP enumeration It seems the all ports are running. Checking port 80, we found that a web application is running.

    1 条评论
  • Attacktive Directory

    Attacktive Directory

    NMAP enumeration shows up an Active Directory environment - Kerberos Port 88 DNS_Domain_Name: spookysec.local User…

  • Injectics

    Injectics

    Enumeration Ports 22 and 80 are open Web Application running on port 80 Checking the source code, we found an…

  • New York Flankees

    New York Flankees

    Enumeration Port 22 and 8080-http are open Checking the request, we found a script function that leaks a token. Custom…

  • CyberLens

    CyberLens

    Enumeration Don't forget to manually define the IP addresses associated with the specific hostname After a deep…

  • Hack Smarter Security

    Hack Smarter Security

    Enumeration Ports 21, 22, 80, 1311, and 3389 are open Checking port 21 we found some Credit Cards and a Stolen Passport…

    1 条评论
  • Crocc Crew

    Crocc Crew

    Enumeration Facing an Active Directory Checking for possible users utilizing xato-net-10-million-usernames.txt from…

  • Pickle Rick - TryHackMe

    Pickle Rick - TryHackMe

    This challenge, inspired by the world of Rick and Morty, tasks you with exploiting a web server to discover three…

社区洞察