Superhuman

Writeup HackMyVM

Superhuman is an easy level Linux box from HackMyVM platfrom! VM Link

Superhuman

Enumeration

>> Starting with by finding ip addresss of target with netdiscover

  • Our Target ip is 192.168.0.140

>> Scan for open Ports and services with nmap

  • Found nothing intresting.

  • On visiting Website also found nothing just blank page!

>> Let's Run ctfenum script

  • Found an intresting comment on web page!

>> Bruteforce directories and files with gobuster

  • Found an intresting file notes-tips.txt

  • By visting the file we'll found this.

>> Try to decrypt this string

cyberchef output
  • Its an Base85 encoded strings

  • We'll get the message from there and get some hints!

  • Like he'll write a poem for her and name it as salome_and_??

  • And save it with a good extension because there is no space left

  • So its maybe extension like zip, 7z, RAR.

>> After a while figured out the file is salome_and_me and the extension is .zip

  • So the file is salome_and_me.zip

  • By visitng this we'll get the password protected zip file!

  • We get password lets extract the zip file

  • Intresting, we found the poem!!

Exploitation

>> Create wordlist from the poem

>> Brute Force SSH with this creds

  • And boom we got the access to machine!

  • If we try to run ls the connection will be terminated! 🙂

  • And we found the user flag!!! 👽

Privilege escalation

>> Exploring binary vulnerabilities for privilege escalation

  • looking around a bit but no luck! 🙁

  • look for ways to escalate privileges and found out about file capabilities

  • Found a file with capabilities permissions.

>> Look at GTFObins for file capabilities

GTFObins
  • And found a way to escalate privileges

  • And BOOM 💥 we got the ROOT shell!!

  • Don't try to run ls it will terminate the shell! 🙂

  • And that's how we got the root flag!!! 👾

Last updated