After Authenticating Menu Asks for Password Again Battlenet
data:image/s3,"s3://crabby-images/1e116/1e1162a05036a10049b3349d4b361dced70c2ed5" alt=""
In this article, I tried to gear up a write-up for the "CC: Pen Testing" room ontryhackme.
[Task ane] Introduction
The idea backside this room is to provide an introduction to various tools and concepts usually encountered in penetration testing.
#ane Read the in a higher place.
Respond: No respond needed
[Job 2] [Section 1 – Network Utilities] – nmap
nmap is one of the almost important tools for pentesting.
#1 What does nmap stand for?
ANSWER: Network Mapper
#2 How do you specify which port(southward) to scan?
Answer: -p
#three How do you lot do a "ping scan"(just tests if the host(s) is up)?
ANSWER: -sn
#4 What is the flag for a UDP scan?
Answer: -sU
#5 How do you run default scripts?
Answer: -sC
#vi How practice you enable "ambitious mode"?
Reply: -A
#vii What flag enables Os detection
Respond: -O
#eight How do you get the versions of services running on the target machine
ANSWER: -sV
#ix Deploy the machine
After deploy the automobile, yous can run this nmap command:
nmap -A -sC -sV -O <IP Accost>
Yous can see my nmap result. All answer can be seen.
data:image/s3,"s3://crabby-images/92677/92677db9a7ad4208c26253886c5ea9ed3daaffc8" alt=""
Reply: No answer needed
#ten How many ports are open on the machine?
Reply: one
#11 What service is running on the auto?
Respond: Apache
#12 What is the version of the service?
ANSWER: two.4.18
#13 What is the output of the http-title script(included in default scripts)
Answer: Apache2 Ubuntu Default Page: It Works
[Task 3] [Section 1 – Network Utilities] – Netcat
You can see netcat help folio:
data:image/s3,"s3://crabby-images/87296/8729677bdf2a7617fddabc5066f03462aa696f6d" alt=""
#1 How practice you listen for connections?
ANSWER: -l
#2 How exercise you enable verbose way(allows you to see who connected to you)?
ANSWER: -v
#3 How do y'all specify a port to listen on
ANSWER: -p
#4 How do you specify which programme to execute after y'all connect to a host(One of the most infamous)?
ANSWER: -eastward
#five How do you connect to udp ports
Respond: -u
[Job four] [Section 2 – Spider web Enumeration] – gobuster
You tin see gobuster help page :
data:image/s3,"s3://crabby-images/f07c1/f07c1ab06962a97be6199967d9d4121a55258f8e" alt=""
#1 How practice you lot specify directory/file brute forcing mode?
ANSWER: dir
#2 How do you specify dns bruteforcing mode?
ANSWER: dns
#3 What flag sets extensions to be used?
ANSWER: -10
#4 What flag sets a wordlist to be used?
ANSWER: -w
#5 How do you set the Username for basic authentication?
ANSWER: -U
#6 How exercise you set the password for bones authentication?
ANSWER: -P
#vii How do you set which status codes gobuster volition translate as valid?
ANSWER: -s
#eight How do you skip ssl certificate verification?
Reply: -k
#9 How do you specify a User-Amanuensis?
ANSWER: -a
#x How do you specify a HTTP header?
Answer: -H
#eleven What flag sets the URL to bruteforce?
ANSWER: -u
#12 Deploy the car
After deploy the machine, you lot can run this command:
gobuster dir -u http://<Motorcar IP> -w /usr/share/wordlists/dirb/common.txt -t 64
data:image/s3,"s3://crabby-images/141ad/141ad27f292bd92766ee637a00409a85063b54d4" alt=""
#xiii What is the name of the subconscious directory
Yous tin can see the answer above motion picture.
Respond: cloak-and-dagger
#14 What is the proper name of the hidden file with the extension xxa
Y'all can run into my reply:
data:image/s3,"s3://crabby-images/e81bc/e81bc53ca5467ffe0d8929336eb816002b67432b" alt=""
Respond: password
[Task 5] [Section 2 – Spider web Enumeration] – nikto
You tin can employ nikto help page:
data:image/s3,"s3://crabby-images/ddf9e/ddf9e9dfe5ae22a6cb06ccf89a18d0a941bdb2b8" alt=""
#1 How do you specify which host to use?
ANSWER: -h
#ii What flag disables ssl?
Reply: -nossl
#3 How practice you force ssl?
ANSWER: -ssl
#4 How practice y'all specify authentication(username + pass)?
ANSWER: -id
#5 How exercise y'all select which plugin to employ?
Answer: -plugins
#half dozen Which plugin checks if you can enumerate apache users?
You have to run this command:
Then you tin can show the answer:
data:image/s3,"s3://crabby-images/5e305/5e305d8651dda2d7e0bb443520f57239678f7a5f" alt=""
ANSWER: apacheusers
#7 How exercise yous update the plugin listing ?
Reply: -update
#8 How exercise you list all possible plugins to use?
Respond: –list-plugins
[Chore vi] [Section 3 – Metasploit]: Intro
#1
ANSWER: No reply needed
[Task vii] [Department 3 Metasploit]: Setting Upwards
#i What command allows you to search modules?
Reply: search
#two How do you select a module?
ANSWER: apply
#iii How practice you display information near a specific module?
ANSWER: info
#iv How do y'all list options that you can prepare?
Answer: options
#five What control lets y'all view avant-garde options for a specific module?
Respond: advanced
#vi How do you show options in a specific category
ANSWER: bear witness
[Task eight] [Section 3 – Metasploit]: – Selecting a module
This task will take yous through selecting and setting options for i of the most popular metasploit modules "eternalblue". All bones commands that could exist run before selecting a module can besides be done while a module is selected.
#one How practise you select the eternalblue module?
data:image/s3,"s3://crabby-images/f637c/f637c5399adb6aff8f60cd04fad8033a41a092b5" alt=""
Respond: use exploit/windows/smb/ms17_010_eternalblue
#2 What pick allows y'all to select the target host(s)?
data:image/s3,"s3://crabby-images/77a32/77a329461840589ea5f0d4329ea27b6459b88540" alt=""
ANSWER: RHOSTS
#3 How practise you set the target port?
Reply: RPORT
#4 What command allows you to set options?
ANSWER: set
#5 How would yous set SMBPass to "username"?
ANSWER: set SMBPass username
#6 How would you lot set the SMBUser to "password"?
ANSWER: prepare SMBUser password
#7 What selection sets the architecture to be exploited?
ANSWER: curvation
#viii What pick sets the payload to be sent to the target machine?
Reply: payload
#nine Once you lot've finished setting all the required options, how practice you run the exploit?
ANSWER: exploit
#x What flag do y'all fix if yous want the exploit to run in the background?
ANSWER: -j
#xi How do you list all current sessions?
ANSWER: sessions
#12 What flag allows you to become into interactive way with a session?
Answer: -i
[Task ix] [Section iii – Metasploit]: meterpreter
#1 What command allows you to download files from the machine?
Respond: download
#2 What command allows you to upload files to the car?
ANSWER: upload
#iii How do y'all listing all running processes?
Respond: ps
#4 How do you modify processes on the victim host?
Answer: drift
#5 What control lists files in the current directory on the remote auto?
Answer: ls
#six How do you execute a command on the remote host?
Respond: execute
#7 What command starts an interactive vanquish on the remote host?
ANSWER: shell
#8 How do you find files on the target host?
Respond: search
#9 How practice you become the output of a file on the remote host?
ANSWER: true cat
#10 How do you put a meterpreter shell into "groundwork mode"
ANSWER: background
[Task 10] [Section 3 – Metasploit]: Final Walkthrough
Allow's select the "exploit/multi/http/nostromo_code_exec" module and list the options:
data:image/s3,"s3://crabby-images/405a9/405a9f64909587d60036c46bf706a14ffe5a608e" alt=""
#1 Select the module that needs to exist exploited
Reply: use exploit/multi/http/nostromo_code_exec
#two What variable practise y'all demand to set, to select the remote host
ANSWER: rhosts
#3 How do you set the port to fourscore
Answer: set rport fourscore
#4 How do you set listening address(Your motorcar)
Reply: lhost
#5 Exploit the machine!
Let'due south prepare the parameters then exploit this machine 🙂
data:image/s3,"s3://crabby-images/489f5/489f56dc029cbca79c82b65a79336ade98d3c9e8" alt=""
#six What is the name of the secret directory in the /var/nostromo/htdocs directory?
Y'all can do similar me:
data:image/s3,"s3://crabby-images/68e3e/68e3e9c7262342796e37c7872edea930fea3ed76" alt=""
Answer: s3cretd1r
#seven What are the contents of the file inside of the directory?
data:image/s3,"s3://crabby-images/80f1c/80f1c23840e7b71a304889020ff050e55c3aeb22" alt=""
ANSWER: Woohoo!
[Task 11] [Department four – Hash Cracking]: Intro
#i
Reply: No answer needed
[Job 12] [Section 4 – Hash Cracking]: Salting and Formatting
#i
ANSWER: No reply needed
[Task 13] [Section 4 – Hash Keen]: hashcat
data:image/s3,"s3://crabby-images/0d7f8/0d7f88905ac12983f0c29807b27b316176626b6c" alt=""
#i What flag sets the mode.
ANSWER: -m
#2 What flag sets the "assault mode"
Respond: -a
#three What is the attack mode number for Brute-force
data:image/s3,"s3://crabby-images/63627/6362705ba5c4346d444802cf1aeeaafcf55d3e5a" alt=""
Answer: 3
#4 What is the way number for SHA3-512
data:image/s3,"s3://crabby-images/0c9a5/0c9a524705f9914841abac4663850c8cf38bd822" alt=""
ANSWER: 17600
#v Fissure This Hash:56ab24c15b72a457069c5ea42fcfc640
Yous can use this web site .
data:image/s3,"s3://crabby-images/0304c/0304cd2a4fc800c791b819a2717e1377aaf1eff3" alt=""
ANSWER: happy
#6 Crack this hash: 4bc9ae2b9236c2ad02d81491dcb51d5f
Y'all can use this web site .
data:image/s3,"s3://crabby-images/c9aef/c9aef386ece71c890bae96b40db7d82b694afa34" alt=""
ANSWER: nootnoot
[Chore fourteen] [Section 4 – Hash Cracking]: John The Ripper
#one What flag let'southward y'all specify which wordlist to use?
Respond: –wordlist
#2 What flag lets you lot specify which hash format(Ex: MD5,SHA1 etc.) to employ?
Reply: –format
#iii How do you lot specify which dominion to use?
ANSWER: –rules
#4 Crack this hash: 5d41402abc4b2a76b9719d911017c592
You lot can use this command in "/root/Desktop" directory.
data:image/s3,"s3://crabby-images/68d09/68d09bf78bff8ee03cc17278d1a79d09b899bb6c" alt=""
Respond: hello
#five Crevice this hash: 5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8
You lot can use this command in "/root/Desktop" directory.
data:image/s3,"s3://crabby-images/8df34/8df3465c6ebbc55528bd7b552c733ee47a0950fa" alt=""
ANSWER: password
[Chore xv] [Section 5 – SQL Injection]: Intro
#1
Answer: No reply needed
[Task 16] [Department 5 – SQL Injection]: sqlmap
Sqlmap is arguably the about popular automated SQL injection tool out there.
You can see the sqlmap assist menü:
data:image/s3,"s3://crabby-images/12fc9/12fc9f6ca5ed7f34f87cdb246c7464f079a57fb3" alt=""
#i How do you specify which url to check?
You lot can see the reply above the picture.
ANSWER: -u
#ii What well-nigh which google dork to use?
You lot tin run across the reply higher up the picture
ANSWER: -g
#three How do you select(lol) which parameter to use?
data:image/s3,"s3://crabby-images/8dd7a/8dd7a62e2a043e3de3f990c4572d05fd35c25e38" alt=""
Respond: -p
#4 What flag sets which database is in the target host's backend?
You tin run into the answer previous moving-picture show 🙂
ANSWER: –dbms
#v How exercise y'all select the level of depth sqlmap should utilise
Respond: –level
#6 How practise you lot dump the table entries of the database?
data:image/s3,"s3://crabby-images/c3148/c3148e6e1a1fa67446204ec301362a8039e8dcb8" alt=""
ANSWER: –dump
#7 Which flag sets which db to enumerate?
You can see the answer previous picture 🙂
ANSWER: -D
#eight Which flag sets which table to enumerate?
You tin run across the answer previous picture 🙂
ANSWER: -T
#nine Which flag sets which column to enumerate?
Yous tin can see the answer previous flick 🙂
ANSWER: -C
#10 How practice you ask sqlmap to effort to become an interactive os-beat out?
data:image/s3,"s3://crabby-images/85a6b/85a6b91945a19eaa86e002fcaa030f9d0ecd9bfe" alt=""
Respond: –os-shell
#eleven What flag dumps all data from every table
Respond: –dump-all
[Task 17] [Section five – SQL Injection]: A Note on Transmission SQL Injection
#one
Answer: No answer needed
[Chore 18] [Section five – SQL Injection]: Vulnerable Spider web Application
To demonstrate how to use sqlmap to check for vulnerabilities and dump table data, I volition exist walking you through an example web app. Deploy the automobile and let'southward become started!
#1 Fix the url to the motorcar ip, and run the command
ANSWER: No answer needed
#two How many types of sqli is the site vulnerable too?
ANSWER: 3
#3 Dump the database.
Yous can use this control: You should answer all question with "Y".
data:image/s3,"s3://crabby-images/34d78/34d78bc8e92e7e3c03d32150a4a40ee18555e68b" alt=""
Answer: No answer needed
#iv What is the name of the database?
data:image/s3,"s3://crabby-images/5408d/5408da075e3994ddfe382e64dba37d6bbdf2ff5e" alt=""
Reply: tests
#v How many tables are in the database?
data:image/s3,"s3://crabby-images/3bdaa/3bdaade322bdbf1e1af7c851528604aeecb0f1aa" alt=""
Their names are "msg" and "flag".
Answer: 2
#six What is the value of the flag?
data:image/s3,"s3://crabby-images/d66a6/d66a60e74c16d9f76dce055a93db866af4f096ce" alt=""
ANSWER: found_me
[Task 19] [Department six – Samba]: Intro
#ane
ANSWER: No answer needed
[Chore twenty] [Section 6 – Samba]: smbmap
Y'all can use the help menu.
data:image/s3,"s3://crabby-images/62ec1/62ec1aea989196b0613bd0a5df372df68bb03662" alt=""
#1 How do yous fix the username to authenticate with?
Respond: -u
#2 What near the password?
Answer: -p
#three How exercise y'all set up the host?
Respond: -H
#4 What flag runs a control on the server?
Respond: -x
#5 How do you specify the share to enumerate?
ANSWER: -due south
#6 How do you set which domain to enumerate?
ANSWER: -d
#vii What flag downloads a file?
Respond: –download
#8 What about uploading i?
ANSWER: –upload
#9 Given the username "admin", the password "password", and the ip "10.10.10.ten", how would you run ipconfig on that automobile
ANSWER: smbmap -u "admin" -p "password" -H 10.10.x.x -x "ipconfig"
[Task 21] [Department 6 – Samba]: smbclient
You can use the help card.
data:image/s3,"s3://crabby-images/ee2d2/ee2d2cc3c692ddb73502398f07d31e4c0dd77df4" alt=""
#one How do you specify which domain(workgroup) to employ when connecting to the host?
ANSWER: -w
#2 How practise you specify the ip address of the host?
Reply: -I
#3 How do yous run the command "ipconfig" on the target car?
ANSWER: -c "ipconfig"
#4 How do you specify the username to authenticate with?
ANSWER: -U
#five How do yous specify the password to cosign with?
Answer: -P
#6 What flag is set to tell smbclient to not use a password?
ANSWER: -N
#7 While in the interactive prompt, how would you download the file exam, assuming it was in the current directory?
Answer: go test
#8 In the interactive prompt, how would you upload your /etc/hosts file
ANSWER: put /etc/hosts
[Task 22] [Section 6 – Samba]: A annotation about impacket
#ane
ANSWER: No answer needed
[Task 23] [Miscellaneous]: A notation on privilege escalation
#ane
ANSWER: No reply needed
Chore 24 [Section vii – Concluding Exam]: Good Luck 😀
Commencement, y'all take to utilise search the directory with "gobuster". I used the "directory-list-2.3-medium.txt" wordlist.
data:image/s3,"s3://crabby-images/d1b5b/d1b5b11e979cd02646c9edc29f918f6a92409b78" alt=""
I constitute the "/secret" directory. Then again I searched the this directory with ".txt, .php, .html" extensions.
data:image/s3,"s3://crabby-images/12435/12435d29e6ae52b0972f7a09fd783c652462240f" alt=""
I constitute the "surreptitious.txt" directory.
data:image/s3,"s3://crabby-images/f031c/f031c2e0e66caa9f6205673b1ec66215fb042aa6" alt=""
I got some information. I tried to scissure the hash value.
data:image/s3,"s3://crabby-images/6705a/6705adc1188875d3fccdfb352d58c2135c2f2909" alt=""
Then I connected with ssh.
User proper name: nyan
Countersign: nyan
data:image/s3,"s3://crabby-images/5b0bb/5b0bb5ff971eb5b4c8cdd9f2662f8bef98c4bd47" alt=""
#1 What is the user.txt
Answer: supernootnoot
#2 What is the root.txt
data:image/s3,"s3://crabby-images/04ee9/04ee9796444309668cacee46535b216ff19bf951" alt=""
ANSWER: congratulations!!!!
So far, I have tried to explain the solutions of the questions every bit detailed as I can. I promise information technology helped you lot. See you lot in my next write-up.
After Authenticating Menu Asks for Password Again Battlenet
Source: https://fthcyber.com/2020/10/14/cc-pen-testing-writeup-tryhackme/