{"id":313,"date":"2020-11-10T12:31:52","date_gmt":"2020-11-10T11:31:52","guid":{"rendered":"https:\/\/mikadmin.fr\/blog\/?p=313"},"modified":"2021-07-28T17:22:20","modified_gmt":"2021-07-28T15:22:20","slug":"tryhackme-brute-it","status":"publish","type":"post","link":"https:\/\/mikadmin.fr\/blog\/tryhackme-brute-it\/","title":{"rendered":"[TryHackMe] \u2013 Brute It"},"content":{"rendered":"<span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\"><\/span> <span class=\"rt-time\"> 4<\/span> <span class=\"rt-label rt-postfix\">min read<\/span><\/span><p>Views: 785<\/p>\n<div style=\"height:28px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"443\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_1-1024x443.png\" alt=\"brute it\" class=\"wp-image-316\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_1-1024x443.png 1024w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_1-300x130.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_1-150x65.png 150w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_1-768x332.png 768w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_1.png 1200w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\" style=\"font-size:17px\"><strong>Lien : <a href=\"https:\/\/tryhackme.com\/room\/bruteit\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/tryhackme.com\/room\/bruteit<\/a><\/strong><\/p>\n\n\n\n<p class=\"has-text-align-center has-normal-font-size\">La room <strong>brute it<\/strong> est de niveau <span style=\"color:#00d084\" class=\"tadv-color\">facile<\/span>.<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"block-7747ba92-7743-41d0-9875-16dfdb578133\">[Task 2]<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center\" style=\"font-size:18px\">Dans un premier, nous allons effectuer un scan avec <strong><span style=\"color:#00d084\" class=\"tadv-color\">nmap<\/span><\/strong> :<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"249\" height=\"93\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image.png\" alt=\"\" class=\"wp-image-330\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image.png 249w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-150x56.png 150w\" sizes=\"auto, (max-width: 249px) 100vw, 249px\" \/><\/figure><\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"747\" height=\"267\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_8.png\" alt=\"\" class=\"wp-image-331\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_8.png 747w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_8-300x107.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_8-150x54.png 150w\" sizes=\"auto, (max-width: 747px) 100vw, 747px\" \/><\/figure>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center\" style=\"font-size:18px\">Ce dernier permet donc de r\u00e9pondre aux <strong>4 premi\u00e8res questions<\/strong> :<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"290\" height=\"72\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_2-1.png\" alt=\"\" class=\"wp-image-321\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_2-1.png 290w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_2-1-150x37.png 150w\" sizes=\"auto, (max-width: 290px) 100vw, 290px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\"><strong><span style=\"color:#2cd213\" class=\"tadv-color\">2<\/span><\/strong><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"262\" height=\"46\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_3-2.png\" alt=\"\" class=\"wp-image-322\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_3-2.png 262w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_3-2-150x26.png 150w\" sizes=\"auto, (max-width: 262px) 100vw, 262px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\"><strong><span style=\"color:#e0d615\" class=\"tadv-color\">OpenSSH 7.6p1<\/span><\/strong><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"275\" height=\"51\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_4-1.png\" alt=\"\" class=\"wp-image-323\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_4-1.png 275w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_4-1-150x28.png 150w\" sizes=\"auto, (max-width: 275px) 100vw, 275px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\"><strong><span style=\"color:#d546e8\" class=\"tadv-color\">2.4.29<\/span><\/strong><\/p>\n\n\n\n<div class=\"wp-block-image is-style-rounded\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"275\" height=\"37\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_5-1.png\" alt=\"\" class=\"wp-image-324\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_5-1.png 275w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_5-1-150x20.png 150w\" sizes=\"auto, (max-width: 275px) 100vw, 275px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\"><strong><span style=\"color:#ff6900\" class=\"tadv-color\">Ubuntu<\/span><\/strong><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_6-1.png\" alt=\"\" class=\"wp-image-325\" width=\"352\" height=\"64\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_6-1.png 352w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_6-1-300x55.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_6-1-150x27.png 150w\" sizes=\"auto, (max-width: 352px) 100vw, 352px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\"><strong><span style=\"color:#c2140e\" class=\"tadv-color\">\/admin<\/span><\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p class=\"has-text-align-center\" style=\"font-size:18px\">Pour la derni\u00e8re question de cette partie, nous allons utiliser <strong><span style=\"color:#0693e3\" class=\"tadv-color\">gobuster<\/span><\/strong> :<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"744\" height=\"116\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-1.png\" alt=\"\" class=\"wp-image-335\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-1.png 744w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-1-300x47.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-1-150x23.png 150w\" sizes=\"auto, (max-width: 744px) 100vw, 744px\" \/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"541\" height=\"224\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_9.png\" alt=\"\" class=\"wp-image-336\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_9.png 541w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_9-300x124.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_9-150x62.png 150w\" sizes=\"auto, (max-width: 541px) 100vw, 541px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"block-7747ba92-7743-41d0-9875-16dfdb578133\">[Task 3]<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p style=\"font-size:18px\">Le dossier <strong><span style=\"color:#e10e1f\" class=\"tadv-color\">admin<\/span><\/strong> trouv\u00e9 plus haut cache en r\u00e9alit\u00e9 un<strong> panel admin<\/strong> prot\u00e9g\u00e9 par un <strong>formulaire de connexion<\/strong>.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"357\" height=\"297\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_10.png\" alt=\"\" class=\"wp-image-350\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_10.png 357w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_10-300x250.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_10-150x125.png 150w\" sizes=\"auto, (max-width: 357px) 100vw, 357px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"372\" height=\"50\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-2.png\" alt=\"\" class=\"wp-image-348\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-2.png 372w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-2-300x40.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-2-150x20.png 150w\" sizes=\"auto, (max-width: 372px) 100vw, 372px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center\" style=\"font-size:18px\">L&rsquo;<strong>utilisateur<\/strong> n&rsquo;est pas bien difficile \u00e0 trouver :<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"506\" height=\"107\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_11.png\" alt=\"\" class=\"wp-image-352\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_11.png 506w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_11-300x63.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_11-150x32.png 150w\" sizes=\"auto, (max-width: 506px) 100vw, 506px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center\" style=\"font-size:18px\">Pour r\u00e9cup\u00e9rer le <strong>mot de passe admin<\/strong>, nous allons utiliser <strong><span style=\"color:#fcb900\" class=\"tadv-color\">Hydra<\/span><\/strong> :<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"743\" height=\"116\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-3.png\" alt=\"\" class=\"wp-image-354\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-3.png 743w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-3-300x47.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-3-150x23.png 150w\" sizes=\"auto, (max-width: 743px) 100vw, 743px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\" style=\"font-size:18px\"><em>Pour mieux comprendre cette commande : <a href=\"https:\/\/mikadmin.fr\/blog\/?p=33\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/mikadmin.fr\/blog\/?p=33<\/a><\/em><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"601\" height=\"61\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_12.png\" alt=\"\" class=\"wp-image-355\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_12.png 601w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_12-300x30.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_12-150x15.png 150w\" sizes=\"auto, (max-width: 601px) 100vw, 601px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\" style=\"font-size:18px\">La r\u00e9ponse est donc : <strong>admin:xavier<\/strong><\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center\" style=\"font-size:18px\">Nous avons \u00e0 pr\u00e9sent acc\u00e8s au panel admin :<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"142\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_13-1024x142.png\" alt=\"\" class=\"wp-image-358\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_13-1024x142.png 1024w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_13-300x42.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_13-150x21.png 150w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_13-768x106.png 768w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_13.png 1200w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\" style=\"font-size:18px\">Nous obtenons donc le flag pour la r\u00e9ponse n\u00b04 mais aussi une cl\u00e9 priv\u00e9e !<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_14.png\" alt=\"\" class=\"wp-image-361\" width=\"356\" height=\"355\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_14.png 496w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_14-300x300.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_14-150x150.png 150w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_14-50x50.png 50w\" sizes=\"auto, (max-width: 356px) 100vw, 356px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"343\" height=\"67\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-4.png\" alt=\"\" class=\"wp-image-360\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-4.png 343w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-4-300x59.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-4-150x29.png 150w\" sizes=\"auto, (max-width: 343px) 100vw, 343px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center\" style=\"font-size:18px\">Pour cette t\u00e2che, nous faisons appel \u00e0 <strong><span style=\"color:#0693e3\" class=\"tadv-color\">John<\/span><\/strong> :<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"542\" height=\"117\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_15.png\" alt=\"\" class=\"wp-image-364\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_15.png 542w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_15-300x65.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_15-150x32.png 150w\" sizes=\"auto, (max-width: 542px) 100vw, 542px\" \/><\/figure><\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"735\" height=\"217\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_16.png\" alt=\"\" class=\"wp-image-365\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_16.png 735w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_16-300x89.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_16-150x44.png 150w\" sizes=\"auto, (max-width: 735px) 100vw, 735px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\" style=\"font-size:18px\">Le mot de passe est donc : <strong>rockinroll<\/strong><\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"89\" height=\"54\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-5.png\" alt=\"\" class=\"wp-image-367\"\/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\" style=\"font-size:18px\">Nous pouvons donc \u00e0 pr\u00e9sent nous <strong>connecter \u00e0 la machine<\/strong> et r\u00e9cup\u00e9rer le <strong>flag user<\/strong> !<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"634\" height=\"203\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_17.png\" alt=\"\" class=\"wp-image-369\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_17.png 634w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_17-300x96.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_17-150x48.png 150w\" sizes=\"auto, (max-width: 634px) 100vw, 634px\" \/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"466\" height=\"276\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_18.png\" alt=\"\" class=\"wp-image-370\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_18.png 466w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_18-300x178.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_18-150x89.png 150w\" sizes=\"auto, (max-width: 466px) 100vw, 466px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"block-7747ba92-7743-41d0-9875-16dfdb578133\">[Task 4]<\/h2>\n\n\n\n<p class=\"has-text-align-center\" style=\"font-size:18px\"><em>C&rsquo;est le moment de la privesc !<\/em><\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"344\" height=\"272\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-6.png\" alt=\"\" class=\"wp-image-373\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-6.png 344w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-6-300x237.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-6-150x119.png 150w\" sizes=\"auto, (max-width: 344px) 100vw, 344px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center\" style=\"font-size:18px\">Il semblerait que nous ayons les droits de lancer la commande <strong>cat<\/strong> en tant que <strong>root<\/strong> :<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"425\" height=\"158\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_19.png\" alt=\"\" class=\"wp-image-374\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_19.png 425w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_19-300x112.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_19-150x56.png 150w\" sizes=\"auto, (max-width: 425px) 100vw, 425px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\" style=\"font-size:18px\">Ce qui nous permet donc de pouvoir <strong>lire les fichiers en tant que root<\/strong>, ici afin de r\u00e9cup\u00e9rer le <strong>flag <span style=\"color:#cf2e2e\" class=\"tadv-color\">root<\/span><\/strong> nous pouvons simplement :<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"329\" height=\"74\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_20.png\" alt=\"\" class=\"wp-image-376\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_20.png 329w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_20-300x67.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_20-150x34.png 150w\" sizes=\"auto, (max-width: 329px) 100vw, 329px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p class=\"has-text-align-center\" style=\"font-size:18px\">Cependant il nous reste une \u00e9tape qui est de trouver le<strong> mot de passe<\/strong> <strong><span style=\"color:#cf2e2e\" class=\"tadv-color\">root<\/span><\/strong> !<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center\" style=\"font-size:18px\">Dans ce cas l\u00e0, nous pouvons donc gr\u00e2ce \u00e0 <strong>cat<\/strong> lire le contenu du fichier <strong><span style=\"color:#f78da7\" class=\"tadv-color\">\/etc\/passwd<\/span><\/strong> &amp; <strong><span style=\"color:#9b51e0\" class=\"tadv-color\">\/etc\/shadow<\/span><\/strong> et tenter de r\u00e9cup\u00e9rer le mot de passe gr\u00e2ce \u00e0 <strong><span style=\"color:#0693e3\" class=\"tadv-color\">John<\/span><\/strong>.<\/p>\n\n\n\n<div style=\"height:34px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center\" style=\"font-size:18px\">Nous copions donc sur notre machine ces derniers dans le fichier <strong><span style=\"color:#f78da7\" class=\"tadv-color\">passwd<\/span><\/strong> et <strong><span style=\"color:#9b51e0\" class=\"tadv-color\">shadow<\/span><\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"552\" height=\"116\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_23.png\" alt=\"\" class=\"wp-image-377\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_23.png 552w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_23-300x63.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_23-150x32.png 150w\" sizes=\"auto, (max-width: 552px) 100vw, 552px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"609\" height=\"182\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_24.png\" alt=\"\" class=\"wp-image-379\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_24.png 609w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_24-300x90.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_24-150x45.png 150w\" sizes=\"auto, (max-width: 609px) 100vw, 609px\" \/><\/figure>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center\" style=\"font-size:18px\">Le mot de passe est donc : <strong>football<\/strong><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"330\" height=\"83\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_25.png\" alt=\"\" class=\"wp-image-381\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_25.png 330w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_25-300x75.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_25-150x38.png 150w\" sizes=\"auto, (max-width: 330px) 100vw, 330px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n","protected":false},"excerpt":{"rendered":"<p><span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\"><\/span> <span class=\"rt-time\"> 4<\/span> <span class=\"rt-label rt-postfix\">min read<\/span><\/span>Learn how to brute, hash cracking and escalate privileges in this box! <a href=\"https:\/\/mikadmin.fr\/blog\/tryhackme-brute-it\/\" class=\"more-link\">Continuer la lecture <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":45,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"footnotes":""},"categories":[4],"tags":[7,21,6,24,23,22,63],"class_list":["post-313","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-infosec","tag-bruteforce","tag-ctf","tag-hydra","tag-john","tag-privesc","tag-tryhackme","tag-writeup"],"aioseo_notices":[],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/posts\/313","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/comments?post=313"}],"version-history":[{"count":0,"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/posts\/313\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/media\/45"}],"wp:attachment":[{"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/media?parent=313"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/categories?post=313"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/tags?post=313"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}