๐ŸŽ’Backfire

https://app.hackthebox.com/machines/643

Recon

PORT     STATE    SERVICE  REASON              VERSION
22/tcp   open     ssh      syn-ack ttl 63      OpenSSH 9.2p1 Debian 2+deb12u4 (protocol 2.0)
| ssh-hostkey:                                                                                                        
|   256 7d:6b:ba:b6:25:48:77:ac:3a:a2:ef:ae:f5:1d:98:c4 (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBJuxaL9aCVxiQGLRxQPezW3dkgouskvb/BcBJR16VYjHElq7F8C2ByzUTNr0OMeiwft8X5vJaD9GBqoEul4D1QE=
|   256 be:f3:27:9e:c6:d6:29:27:7b:98:18:91:4e:97:25:99 (ED25519)          
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIA2oT7Hn4aUiSdg4vO9rJIbVSVKcOVKozd838ZStpwj8
443/tcp  open     ssl/http syn-ack ttl 63      nginx 1.22.1                
| ssl-cert: Subject: commonName=127.0.0.1/organizationName=ACME/stateOrProvinceName=Florida/countryName=US/streetAddress=/localityName=Miami/postalCode=8900
| Subject Alternative Name: IP Address:127.0.0.1                                                                      
| Issuer: commonName=127.0.0.1/organizationName=ACME/stateOrProvinceName=Florida/countryName=US/streetAddress=/localityName=Miami/postalCode=8900
| Public Key type: rsa                                                                                                
| Public Key bits: 2048                                                                                               
| Signature Algorithm: sha256WithRSAEncryption
| Not valid before: 2025-01-17T16:08:55
| Not valid after:  2028-01-17T16:08:55                   
| MD5:   fc03:9065:d59a:f2ae:cd85:bb78:f710:d5c7
| SHA-1: 7799:55d3:c2b6:aa58:41e5:7cb6:7055:078d:a463:2081
| -----BEGIN CERTIFICATE-----       
| MIID1TCCAr2gAwIBAgIRAJdMN/B3DeQBkzcvuShP3uYwDQYJKoZIhvcNAQELBQAw
| bDELMAkGA1UEBhMCVVMxEDAOBgNVBAgTB0Zsb3JpZGExDjAMBgNVBAcTBU1pYW1p
| MQkwBwYDVQQJEwAxDTALBgNVBBETBDg5MDAxDTALBgNVBAoTBEFDTUUxEjAQBgNV
| BAMTCTEyNy4wLjAuMTAeFw0yNTAxMTcxNjA4NTVaFw0yODAxMTcxNjA4NTVaMGwx
| CzAJBgNVBAYTAlVTMRAwDgYDVQQIEwdGbG9yaWRhMQ4wDAYDVQQHEwVNaWFtaTEJ
| MAcGA1UECRMAMQ0wCwYDVQQREwQ4OTAwMQ0wCwYDVQQKEwRBQ01FMRIwEAYDVQQD
| EwkxMjcuMC4wLjEwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDbduCd
| d7U+Dv8PevbWHSpsGW3894nCxGBQKXLm4S0vCC5Q+m0nWEiyjXAKSfgR+OVpbF8Z
| 5PWTZG+aUbuRiB3UR2jja1vTUm7ZOAQwfYSeq9wHZtjsT3njrZarHJzhnULLOvK1
| sGCKi7yNM1nHfxsaN6WHbruTw0iMPxc2zKWTbQcf/Zhl6m5uhLoDwoDC7RawM1fa
| OxKgCaKPdXclPZqo0fRPcdeXj7IHe/o0RUTBoBZUd5T6kSyOeTHWfStG4lCcmkmT
| 4jbaomjTvlenDj6qk3ptYXs+GOzuABrnfXiOkKtNPryqu8gskXjQHo2yPAWq3wbt
| 5F/QbGiVHe9OY3qxAgMBAAGjcjBwMA4GA1UdDwEB/wQEAwICpDAdBgNVHSUEFjAU
| BggrBgEFBQcDAQYIKwYBBQUHAwIwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQU
| 0C235ZzG59nldU14DMSAaR+jgPIwDwYDVR0RBAgwBocEfwAAATANBgkqhkiG9w0B
| AQsFAAOCAQEAXybFqYKaF3+cQA4rS97DkW6yekPAv+sGuGewLQIYRNc2EKjaKz44
| bzJipUbvwQsQqqtGYeNQxf0Qt9hIsN8JUAK9poplap9XCpeyTOmdR7+A8ojoJv+/
| M3ii0fuNfOMJnnjdaQoZG04+mMe+X0OCulNcR6H8Whz1YJEF5t9HV41caSPs4cM0
| /Yf1hUKwQMt2tFDX5hPv+tsuiw2nn8PTuntDvkcnlQxipQTcek1jjvgFTGvWdRO2                                   
| WcVuaiEScZq85Cy+fRHHZXGz4lL3tQQ3CPAZOZ/WiY5Y13xPbbYrvC1EwJaSUlv5
| ncklkNFnxyBoBEAdOS0xQsTcaTfqI2Qi7g==                                                                                
|_-----END CERTIFICATE-----
|_http-title: 404 Not Found
| tls-alpn:                                     
|   http/1.1                                        
|   http/1.0                                     
|_  http/0.9                       
|_http-server-header: nginx/1.22.1   
|_ssl-date: TLS randomness does not represent time
5000/tcp filtered upnp     port-unreach ttl 63
8000/tcp open     http     syn-ack ttl 63      nginx 1.22.1 
| http-methods: 
|_  Supported Methods: GET HEAD POST
|_http-server-header: nginx/1.22.1
| http-ls: Volume /
| SIZE  TIME               FILENAME
| 1559  17-Dec-2024 11:31  disable_tls.patch
| 875   17-Dec-2024 11:34  havoc.yaotl
|_
|_http-title: Index of /
|_http-open-proxy: Proxy might be redirecting requests

User

Replace IP+PORT

Root

Login on 7096 as sth_pentest and get a shell as sergej via terminal

https://www.shielder.com/blog/2024/09/a-journey-from-sudo-iptables-to-local-privilege-escalation/

Last updated