machine downloaded from https://hackmyvm.eu/
difficulty: Easy
OS: Linux
The IP address is 192.168.5.61
I’m trying to enumerate urls but I can’t find anything.
We have a username alexia, and in an FTP scan it’s interesting that we can load with anonymous.
Inside the ftp server we found a new hide folder .web with an index.html, we can upload files but the Apache server doesn’t run php and we can’t run web-reverse-shells.
We can see the TFTP service.
Trivial_File_Transfer_Protocol
We can connect to this service, but we don’t have any commands to list the content. We can try to download the id_rsa file, which is the reference in the web page.
If we investigate about the file, it’s an executable file, with command string we can see that execute a command cat with variable HOME, if we change variable HOME for of the root user we can see private sshkey of this user.