[HTB] Resource
by UnkownWombat - Saturday August 3, 2024 at 06:05 PM
#91
thinkphp is patched
This forum account is currently banned. Ban Length: (Permanent)
Ban Reason:
Asking for rep is not allowed
Reply
#92
(08-04-2024, 01:52 PM)orwell1984 Wrote: I'm stuck on support user on the host, any hint on what to do next?

How did you get there? Did you use the sign_key_api.sh ?
Reply
#93
(08-04-2024, 02:11 PM)orwell1984 Wrote:
(08-04-2024, 02:06 PM)a44857437 Wrote:
(08-04-2024, 01:52 PM)orwell1984 Wrote: I'm stuck on support user on the host, any hint on what to do next?

How did you get there? Did you use the sign_key_api.sh ?

yes

How ? You have a pub key signed from another CA... how can you use that ?
Reply
#94
(08-04-2024, 01:52 PM)orwell1984 Wrote: I'm stuck on support user on the host, any hint on what to do next?

cat /etc/ssh/auth_principals/zzinter
zzinter_temp

try zzinter_temp principals
Reply
#95
guys ,what is the user flag step ?T_T
This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: Leeching | http://breachddyfwvcp4kzccos5oxtdbssmfbp...an-Appeals if you feel this is incorrect.
Reply
#96
(08-04-2024, 02:13 PM)x1rx Wrote:
(08-04-2024, 01:52 PM)orwell1984 Wrote: I'm stuck on support user on the host, any hint on what to do next?

cat /etc/ssh/auth_principals/zzinter
zzinter_temp

try zzinter_temp principals

And then use the sudo privs for signing another one?
Reply
#97
(08-04-2024, 03:01 PM)a44857437 Wrote:
(08-04-2024, 02:13 PM)x1rx Wrote:
(08-04-2024, 01:52 PM)orwell1984 Wrote: I'm stuck on support user on the host, any hint on what to do next?

cat /etc/ssh/auth_principals/zzinter
zzinter_temp

try zzinter_temp principals

And then use the sudo privs for signing another one?

mine says empty principal name btw
Reply
#98
Has anyone managed to escape from docker?
Reply
#99
(08-04-2024, 03:06 PM)Unbutton8074 Wrote:
(08-04-2024, 03:01 PM)a44857437 Wrote:
(08-04-2024, 02:13 PM)x1rx Wrote:
(08-04-2024, 01:52 PM)orwell1984 Wrote: I'm stuck on support user on the host, any hint on what to do next?

cat /etc/ssh/auth_principals/zzinter
zzinter_temp

try zzinter_temp principals

And then use the sudo privs for signing another one?

mine says empty principal name btw

I think the sudo script as zzinter on the host (Not the docker) is a rabbit hole. It doesn't work, as the variable names in the script are all wrong.

I feel there is some way to bypass the restriction of signing as the root_user principal on the fast_api site
Reply
Do we need to use the Signing API to sign using the /etc/ssh/ca_users_key.pub? If yes - what are user/principals to use? Can't seem to find a combination that will let me SSH into other port without password prompt.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [MEGALEAK] HackTheBox ProLabs, Fortress, Endgame - Alchemy, 250 Flags, leak htb-bot htb-bot 91 7,551 7 hours ago
Last Post: ukaugse
  [FREE] 300+ Writeups PDF HackTheBox/HTB premium retired Tamarisk 364 88,800 Yesterday, 07:41 PM
Last Post: napo22
  [FREE] HTB-ProLabs APTLABS Just Flags kewlsunny 23 2,356 03-28-2026, 03:30 AM
Last Post: lulaladrow
  HTB Eloquia User and Root Flags - Insane Box 69646B 13 355 03-27-2026, 06:14 PM
Last Post: vlxw
  HTB - ALL Challenges you Stuck in osamy7593 2 652 03-27-2026, 04:24 PM
Last Post: catsweet



 Users browsing this thread: