{"id":742,"date":"2021-01-17T20:29:00","date_gmt":"2021-01-17T19:29:00","guid":{"rendered":"https:\/\/mikadmin.fr\/blog\/?p=742"},"modified":"2021-09-20T11:54:31","modified_gmt":"2021-09-20T09:54:31","slug":"tryhackme-overpass-3","status":"publish","type":"post","link":"https:\/\/mikadmin.fr\/blog\/tryhackme-overpass-3\/","title":{"rendered":"[TryHackme] \u2013 Overpass 3"},"content":{"rendered":"<span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\"><\/span> <span class=\"rt-time\"> 4<\/span> <span class=\"rt-label rt-postfix\">min read<\/span><\/span><p>Views: 1988<\/p>\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/neDyNc2.png\" alt=\"tryhackme\" class=\"wp-image-744\" width=\"241\" height=\"241\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/neDyNc2.png 512w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/neDyNc2-300x300.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/neDyNc2-150x150.png 150w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/neDyNc2-50x50.png 50w\" sizes=\"auto, (max-width: 241px) 100vw, 241px\" \/><\/figure><\/div>\n\n\n\n<p><\/p>\n\n\n\n<p class=\"has-text-align-center\" id=\"block-be1c4520-f299-4c4b-9d03-1400ebbcabb9\" style=\"font-size:19px\"><strong>Lien : <\/strong><a href=\"https:\/\/tryhackme.com\/room\/overpass3hosting\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/tryhackme.com\/room\/overpass3hosting<\/a><\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<h2 class=\"has-text-align-center wp-block-heading\" id=\"block-d4beac4a-482c-467a-ba27-b0b34ad79a88\" style=\"font-size:35px\">[Web]<\/h2>\n\n\n\n<div style=\"height:24px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\" id=\"block-ddbdaead-227b-43a9-a775-98e3fdee8669\">Dans un premier temps, nous allons effectuer un scan <strong><span style=\"color:#cf2e2e\" class=\"tadv-color\">nmap<\/span><\/strong> :<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"585\" height=\"307\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-12.png\" alt=\"tryhackme\" class=\"wp-image-752\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-12.png 585w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-12-300x157.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-12-150x79.png 150w\" sizes=\"auto, (max-width: 585px) 100vw, 585px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"621\" height=\"697\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-13.png\" alt=\"tryhackme\" class=\"wp-image-756\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-13.png 621w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-13-267x300.png 267w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-13-134x150.png 134w\" sizes=\"auto, (max-width: 621px) 100vw, 621px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Rien \u00e0 signaler de particulier du c\u00f4t\u00e9 du site web nous allons donc \u00e9num\u00e9rer ce dernier avec l&rsquo;outil <strong><span style=\"color:#00d084\" class=\"tadv-color\">ffuf<\/span><\/strong> :<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<pre class=\"wp-block-prismatic-blocks\"><code class=\"language-bash\" data-line=\"\">ffuf -u http:\/\/10.10.126.177\/FUZZ -c -w \/usr\/share\/seclists\/Discovery\/Web-Content\/common.txt<\/code><\/pre>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"837\" height=\"515\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-14.png\" alt=\"\" class=\"wp-image-757\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-14.png 837w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-14-300x185.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-14-150x92.png 150w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-14-768x473.png 768w\" sizes=\"auto, (max-width: 837px) 100vw, 837px\" \/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"520\" height=\"326\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-15.png\" alt=\"\" class=\"wp-image-760\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-15.png 520w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-15-300x188.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-15-150x94.png 150w\" sizes=\"auto, (max-width: 520px) 100vw, 520px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Le fichier <strong>CustomerDetails.xlsx.gpg<\/strong> semble contenir des informations cruciales pour la suite.<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"658\" height=\"192\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-16.png\" alt=\"\" class=\"wp-image-761\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-16.png 658w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-16-300x88.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-16-150x44.png 150w\" sizes=\"auto, (max-width: 658px) 100vw, 658px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Pour ce faire, nous d\u00e9chiffrons ce dernier \u00e0 l&rsquo;aide des commandes suivantes :<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<pre class=\"wp-block-prismatic-blocks\"><code class=\"language-bash\" data-line=\"\">gpg --import priv.key\ngpg --decrypt CustomerDetails.xlsx.gpg &gt; customer.xlsx<\/code><\/pre>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"771\" height=\"286\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-17.png\" alt=\"\" class=\"wp-image-764\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-17.png 771w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-17-300x111.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-17-150x56.png 150w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-17-768x285.png 768w\" sizes=\"auto, (max-width: 771px) 100vw, 771px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Afin de lire ce fichier sans outil :<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<pre class=\"wp-block-prismatic-blocks\"><code class=\"language-http\" data-line=\"\">https:\/\/sheet.zoho.com\/sheet\/excelviewer<\/code><\/pre>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"823\" height=\"188\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-18.png\" alt=\"\" class=\"wp-image-767\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-18.png 823w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-18-300x69.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-18-150x34.png 150w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-18-768x175.png 768w\" sizes=\"auto, (max-width: 823px) 100vw, 823px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">N&rsquo;oublions pas que nous avons un service <strong><span style=\"color:#cf2e2e\" class=\"tadv-color\">FTP<\/span><\/strong> qui tourne sur la machine <strong><a href=\"https:\/\/tryhackme.com\/room\/overpass3hosting\" target=\"_blank\" rel=\"noreferrer noopener\">TryHackMe<\/a><\/strong> !<\/p>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">En testant les <strong><span style=\"color:#0693e3\" class=\"tadv-color\">credentials<\/span><\/strong> trouv\u00e9s plus haut nous avons donc un acc\u00e8s au <strong><span style=\"color:#cf2e2e\" class=\"tadv-color\">FTP<\/span><\/strong> avec <strong>paradox:password<\/strong> !<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"576\" height=\"312\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-19.png\" alt=\"\" class=\"wp-image-772\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-19.png 576w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-19-300x163.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-19-150x81.png 150w\" sizes=\"auto, (max-width: 576px) 100vw, 576px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">\u00c0 ce stade l\u00e0 nous pouvons simplement <strong>upload<\/strong> sur le <span style=\"color:#cf2e2e\" class=\"tadv-color\"><strong>FTP<\/strong> <\/span>notre<strong> <span style=\"color:#00d084\" class=\"tadv-color\">reverse shell<\/span><\/strong> :<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center\"><a href=\"https:\/\/raw.githubusercontent.com\/pentestmonkey\/php-reverse-shell\/master\/php-reverse-shell.php\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/raw.githubusercontent.com\/pentestmonkey\/php-reverse-shell\/master\/php-reverse-shell.php<\/a><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"595\" height=\"326\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-20.png\" alt=\"\" class=\"wp-image-773\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-20.png 595w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-20-300x164.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-20-150x82.png 150w\" sizes=\"auto, (max-width: 595px) 100vw, 595px\" \/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"736\" height=\"403\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/bababa.png\" alt=\"\" class=\"wp-image-830\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/bababa.png 736w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/bababa-300x164.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/bababa-150x82.png 150w\" sizes=\"auto, (max-width: 736px) 100vw, 736px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Nous avons donc un acc\u00e8s \u00e0 la machine en tant qu&rsquo;utilisateur <strong><span style=\"color:#fcb900\" class=\"tadv-color\">apache<\/span><\/strong>, ce qui nous permet de r\u00e9cup\u00e9rer le <strong>premier flag<\/strong> :<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"351\" height=\"136\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-22.png\" alt=\"\" class=\"wp-image-780\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-22.png 351w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-22-300x116.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-22-150x58.png 150w\" sizes=\"auto, (max-width: 351px) 100vw, 351px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<h2 class=\"has-text-align-center wp-block-heading\" id=\"block-58a618ba-88b2-4eec-8e4d-e3d48380284c\" style=\"font-size:35px\"><strong>[User]<\/strong><\/h2>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">En <strong>r\u00e9utilisant le mot de passe<\/strong> trouv\u00e9 plus haut nous sommes d\u00e9sormais <strong>paradox<\/strong> !<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"464\" height=\"110\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-25.png\" alt=\"\" class=\"wp-image-788\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-25.png 464w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-25-300x71.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-25-150x36.png 150w\" sizes=\"auto, (max-width: 464px) 100vw, 464px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Apr\u00e8s <strong>\u00e9num\u00e9ration<\/strong>, on peut voir que le r\u00e9pertoire courant de l&rsquo;utilisateur <strong><span style=\"color:#9b51e0\" class=\"tadv-color\">James<\/span><\/strong> est partag\u00e9 avec l&rsquo;argument <strong>no_root_squash<\/strong>.<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"763\" height=\"82\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-23.png\" alt=\"\" class=\"wp-image-783\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-23.png 763w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-23-300x32.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-23-150x16.png 150w\" sizes=\"auto, (max-width: 763px) 100vw, 763px\" \/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"442\" height=\"66\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-24.png\" alt=\"\" class=\"wp-image-784\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-24.png 442w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-24-300x45.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-24-150x22.png 150w\" sizes=\"auto, (max-width: 442px) 100vw, 442px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:16px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Cependant nous avons un soucis ! <strong><span style=\"color:#fcb900\" class=\"tadv-color\">NFS<\/span><\/strong> \u00e9coute <strong>seulement en local<\/strong> sur la machine cible mais pas de panique nous allons utiliser la m\u00e9thode du <strong><a href=\"http:\/\/reznok.com\/ssh-tunneling-magic\/\" target=\"_blank\" rel=\"noreferrer noopener\">SSH Tunneling<\/a><\/strong>.<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Petit hic ! La connexion<strong> <span style=\"color:#0693e3\" class=\"tadv-color\">SSH<\/span><\/strong> pour l&rsquo;utilisateur <strong>paradox<\/strong> n&rsquo;est pas disponible par mot de passe mais nous pouvons <strong>g\u00e9n\u00e9rer les cl\u00e9s<\/strong> :<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\"><strong>Sur votre machine :<\/strong><\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<pre class=\"wp-block-prismatic-blocks\"><code class=\"language-bash\" data-line=\"\">ssh-keygen -f key_paradox<\/code><\/pre>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"494\" height=\"371\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-26.png\" alt=\"\" class=\"wp-image-794\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-26.png 494w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-26-300x225.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-26-150x113.png 150w\" sizes=\"auto, (max-width: 494px) 100vw, 494px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Sur la <strong>machine cible<\/strong> il vous suffit de copier\/coller le contenu de <strong>key_paradox.pub<\/strong> dans <strong>\/home\/paradox\/.ssh\/authorized_keys<\/strong> :<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-27-1024x161.png\" alt=\"\" class=\"wp-image-796\" width=\"716\" height=\"112\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-27-1024x161.png 1024w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-27-300x47.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-27-150x24.png 150w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-27-768x121.png 768w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-27.png 1200w\" sizes=\"auto, (max-width: 716px) 100vw, 716px\" \/><\/figure><\/div>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">La connexion est d\u00e9sormais possible  :<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<pre class=\"wp-block-prismatic-blocks\"><code class=\"language-bash\" data-line=\"\">ssh -i key_paradox paradox@10.10.126.177<\/code><\/pre>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"450\" height=\"81\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-29.png\" alt=\"\" class=\"wp-image-800\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-29.png 450w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-29-300x54.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-29-150x27.png 150w\" sizes=\"auto, (max-width: 450px) 100vw, 450px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">C&rsquo;est l&rsquo;heure de <strong>forward le <span style=\"color:#cf2e2e\" class=\"tadv-color\">port 2049<\/span><\/strong> de notre c\u00f4t\u00e9.<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">La commande est la suivante :<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<pre class=\"wp-block-prismatic-blocks\"><code class=\"language-bash\" data-line=\"\">ssh -i key_paradox paradox@10.10.126.177 -L 2049:127.0.0.1:2049<\/code><\/pre>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"569\" height=\"86\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-30.png\" alt=\"\" class=\"wp-image-803\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-30.png 569w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-30-300x45.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-30-150x23.png 150w\" sizes=\"auto, (max-width: 569px) 100vw, 569px\" \/><\/figure><\/div>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Parfait ! C&rsquo;est l&rsquo;heure d&rsquo;utiliser la technique sur le <strong>partage<\/strong> de l&rsquo;utilisateur <strong><span style=\"color:#9b51e0\" class=\"tadv-color\">James<\/span><\/strong>.<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<blockquote class=\"wp-block-quote has-text-align-center is-style-default is-layout-flow wp-block-quote-is-layout-flow\"><p><em><span style=\"color:#cf2e2e\" class=\"tadv-color\">Attention dans cette room nous avons affaire \u00e0 du nfs4 !<\/span><\/em><\/p><\/blockquote>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">La proc\u00e9dure est la suivante :<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<pre class=\"wp-block-prismatic-blocks\"><code class=\"language-bash\" data-line=\"\">mkdir \/tmp\/mikadmin.fr\nmount -v -t nfs4 127.0.0.1:\/ \/tmp\/mikadmin.fr\ncp \/bin\/bash .\nchmod +s bash<\/code><\/pre>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"685\" height=\"259\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-31.png\" alt=\"\" class=\"wp-image-808\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-31.png 685w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-31-300x113.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-31-150x57.png 150w\" sizes=\"auto, (max-width: 685px) 100vw, 685px\" \/><\/figure><\/div>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Bingo, le <strong>flag user<\/strong> est \u00e0 nous et par la m\u00eame occasion nous avons un acc\u00e8s direct \u00e0 la machine gr\u00e2ce au <strong>cl\u00e9s <a href=\"https:\/\/mikadmin.fr\/blog\/how-to-change-the-default-ssh-port\/\" target=\"_blank\" rel=\"noreferrer noopener\">ssh<\/a><\/strong> disponibles dans le <strong>dossier courant<\/strong> de <strong><span style=\"color:#9b51e0\" class=\"tadv-color\">James<\/span><\/strong> :<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"617\" height=\"479\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-33.png\" alt=\"\" class=\"wp-image-812\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-33.png 617w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-33-300x233.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-33-150x116.png 150w\" sizes=\"auto, (max-width: 617px) 100vw, 617px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<h2 class=\"has-text-align-center wp-block-heading\" id=\"block-58a618ba-88b2-4eec-8e4d-e3d48380284c\" style=\"font-size:35px\">[Root]<\/h2>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Il est d\u00e9sormais temps de se connecter en tant que <span style=\"color:#9b51e0\" class=\"tadv-color\"><strong>James<\/strong> <\/span>:<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"457\" height=\"262\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-35.png\" alt=\"\" class=\"wp-image-817\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-35.png 457w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-35-300x172.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-35-150x86.png 150w\" sizes=\"auto, (max-width: 457px) 100vw, 457px\" \/><\/figure><\/div>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"has-text-align-center has-medium-font-size\">Afin d&rsquo;achever cette <strong>privesc<\/strong> de la machine Overpass3 de <strong><a href=\"https:\/\/tryhackme.com\/room\/overpass3hosting\" target=\"_blank\" rel=\"noreferrer noopener\">TryHackMe<\/a><\/strong>, il suffit simplement d&rsquo;ex\u00e9cuter le<strong> binaire <span style=\"color:#cf2e2e\" class=\"tadv-color\">bash<\/span> <\/strong>que nous avons pr\u00e9par\u00e9 un peu plus haut !<\/p>\n\n\n\n<div style=\"height:15px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<pre class=\"wp-block-prismatic-blocks\"><code class=\"language-bash\" data-line=\"\">.\/bash -p<\/code><\/pre>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"687\" height=\"158\" src=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-37.png\" alt=\"\" class=\"wp-image-820\" srcset=\"https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-37.png 687w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-37-300x69.png 300w, https:\/\/mikadmin.fr\/blog\/wp-content\/uploads\/2021\/01\/image-37-150x34.png 150w\" sizes=\"auto, (max-width: 687px) 100vw, 687px\" \/><\/figure><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p><span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\"><\/span> <span class=\"rt-time\"> 4<\/span> <span class=\"rt-label rt-postfix\">min read<\/span><\/span>You know them, you love them, your favourite group of broke computer science students have another business venture! Show them that they probably should hire someone for security&#8230; <a href=\"https:\/\/mikadmin.fr\/blog\/tryhackme-overpass-3\/\" class=\"more-link\">Continuer la lecture <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":45,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"footnotes":""},"categories":[4],"tags":[44,39,48,43,45,22,63],"class_list":["post-742","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-infosec","tag-centos","tag-forwarding","tag-gpg","tag-nfs","tag-pentest","tag-tryhackme","tag-writeup"],"aioseo_notices":[],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/posts\/742","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/comments?post=742"}],"version-history":[{"count":0,"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/posts\/742\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/media\/45"}],"wp:attachment":[{"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/media?parent=742"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/categories?post=742"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mikadmin.fr\/blog\/wp-json\/wp\/v2\/tags?post=742"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}