Tryhackme-UltraTech

UltraTech

Task1 Deploy the machine

Deploy the machine

Task2 It’s enumeration time!

image-20211105143319512

1.Which software is using the port 8081?

Node.js

image-20211105143422583

2.Which other non-standard port is used?

31331

3.Which software using this port?

Apache

4.Which GNU/Linux distribution seems to be used?

Ubuntu

5.The software using the port 8080 is a REST api, how many of its routes are used by the web application?

2

image-20211105143341683

Task3 Let the fun begin

1.There is a database lying around, what is its filename?

utech.db.sqlite

http://ip:8081/ping页面访问无法正常访问,缺少参数运行,在URL添加ip参数即可正常运行;

image-20211105154758976

尝试在ip参数中写入命令,访问http://ip:8081/ping?ip=ls -la ,发现数据库文件utech.db.sqlite

image-20211105170224434

2.What is the first user’s password hash?

f357a0c52799563c7c7b76c1e7543a32

运行http://ip:8081/ping?ip=cat utech.db.sqlite,发现root用户及admin用户hash

image-20211105170445555

3.What is the password associated with this hash?

n100906

image-20211105171159675

Task4 The root of all evil

What are the first 9 characters of the root user’s private SSH key?

MIIEogIBA

r00t用户属于docker组成员,可以利用docker提权

image-20211105174239896

image-20211105174139096

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值