00:00 - Intro
00:45 - Checking the web page, then running a SecList wordlist for CommonBackdoors
03:30 - GoBuster returned smevk.php
04:15 - Attempting to guess the password, get in with admin:admin
05:55 - Running script prior to my reverse shell to log the output... I forget to check this again but it did work!
07:30 - Reading note.txt which hints at finding a LUA File, using find to hunt for files
09:05 - The reverse shell is misbehaving, lets fix it by setting the the rows/columns
12:10 - Running LinPEAS, discover sudo with luvit; then looking up how to write files with a lua script
16:10 - SSH'ing in with SysAdmin after our key was written
18:50 - Using find some more to hunt for interesting files
23:11 - Using find to search between dates of interest shows an interesting backup directory
25:40 - Running pSpy to search for running processes
30:00 - Puzzled... Probably should have ran find commands to look for files edited within the last day!
32:40 - Changing up our tactic and using find commands to search for writable files
34:10 - Editing MOTD with a reverse shell then SSH'ing in
35:50 - Extra: Running linPeas to see if it would have seen this privesc.
37:40 - Looking at the script.log output
Auf dieser Seite können Sie das Online-Video HackTheBox - Traceback mit der Dauer stunde minuten sekunde in guter Qualität ansehen, das der Benutzer IppSec 15 August 2020 hochgeladen hat, den Link mit Freunden und Bekannten teilen, dieses Video wurde auf Youtube bereits 30,020 Mal angesehen und es wurde von 947 den Zuschauern gefallen. Viel Spaß beim Betrachtenden Zuschauern gefallen!