↓Skip to main content

HYDRA

OFFSEC - Proving Grounds - NULLBYTE
·2634 words·13 mins
OFFSEC PG PRACTICE EXIFTOOL HYDRA SQLMAP DIRTYCOW CVE-2016-5195
Exiftool reveals a hidden directory. Hydra bypasses the key, SQL injection dumps a hash, which is cracked for SSH access. DirtyCow (CVE-2016-5195) is exploited to gain root.
OFFSEC - Proving Grounds - BORN2ROOT
·1871 words·9 mins
OFFSEC PG PRACTICE HYDRA
Initial access is gained via an SSH key in icons. A cronjob is abused for a jimmy shell, then Hydra finds hadi’s reused password, enabling root access.
OFFSEC - Proving Grounds - FOWSNIFF
·2734 words·13 mins
OFFSEC PG PRACTICE POP3 HYDRA MOTD
GitHub credentials enable POP3 access to retrieve an SSH password. Hydra finds valid credentials for SSH access. A writable cube.sh used by the MOTD is abused to gain root.
OFFSEC - Proving Grounds - POSTFISH
·3193 words·15 mins
OFFSEC PG PRACTICE SMTP-USER-ENUM USERNAME_GENERATOR HYDRA IMAP IMAPS SENDEMAIL PWNKIT
Website PostFish on port 80 and SMTP on port 25 reveal usernames. Hydra finds credentials, sending an email with a reset link grants brian access. Pwnkit (CVE-2021-4034) escalates to root.
OFFSEC - Proving Grounds - BANZAI
·2971 words·14 mins
OFFSEC PG PRACTICE HYDRA GOBUSTER MYSQL MYSQL UDF GCC
FTP on port 21 with weak credentials holds web dirirectory for port 8295. Upload PHP shell to gain initial access. MySQL UDF exploit sets SUID on bash and allows us to escalates to root.