Brute It CTF (THM)
BRUTE IT
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
SCANNING AND ENUMERATION
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
NMAP SCAN

This machine has a ssh server running on port 22 and a web server running at port 80
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
GOBUSTER SCAN
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
I found a hidden directory with name ββadminββ

ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Enumerating the website
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ


Looking at the source code we found out that the username is ββadminββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
EXPLOITATION
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
BRUTE-FORCING INTO ADMIN
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
USING HYDRA
Using the following command I found the password for user ββadminββ on the admin page

ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
LOGGING IN AS ADMIN
Using the username and password I logged in into the website and found a private key

ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
USING PRIVATE KEY TO LOG INTO SSH
I needed to change the privileges of the key and got the passphrase using ssh to John

ββββββββββββββββββββββββββββββββββββββββββββββββββββββ

ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
I logged in into SSH using the private key and found out the user flag.

ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
PRIVESC
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
I ran ββsudo -lββ command I found out that I can run ββcatββ command as a superuser.
Therefore, I used βcatβ to get the /etc/shadow/ file with the password hash for root.

ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Using John I cracker the password hash and finally switched to root user

ββββββββββββββββββββββββββββββββββββββββββββββββββββββ

ββββββββββββββββββββββββββββββββββββββββββββββββββββββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββ