{"id":247,"date":"2025-05-19T00:32:30","date_gmt":"2025-05-18T22:32:30","guid":{"rendered":"https:\/\/fromkiddietorobot.fr\/?p=247"},"modified":"2025-05-19T00:32:30","modified_gmt":"2025-05-18T22:32:30","slug":"brooklyn-nine-nine","status":"publish","type":"post","link":"https:\/\/fromkiddietorobot.fr\/index.php\/2025\/05\/19\/brooklyn-nine-nine\/","title":{"rendered":"Brooklyn Nine Nine"},"content":{"rendered":"\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>This room is aimed for beginner level hackers but anyone can try to hack this box. There are two main intended ways to root the box.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Phase de reconnaissance<\/h2>\n\n\n\n<p>Je lance la commande Nmap basique pour bien commencer comme d&#8217;habitude :<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"763\" height=\"546\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214035.png\" alt=\"\" class=\"wp-image-250\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214035.png 763w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214035-300x215.png 300w\" sizes=\"auto, (max-width: 763px) 100vw, 763px\" \/><figcaption class=\"wp-element-caption\">Service ftp, http, ssh<\/figcaption><\/figure>\n\n\n\n<p>Je commence par le site qui n&#8217;affiche qu&#8217;une image de la s\u00e9rie Brooklyn Nine Nine :<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"440\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214148-1024x440.png\" alt=\"\" class=\"wp-image-251\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214148-1024x440.png 1024w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214148-300x129.png 300w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214148-768x330.png 768w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214148-1536x661.png 1536w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214148-1200x516.png 1200w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214148.png 1765w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Voyons voir le code source du site :<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"332\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214201-1024x332.png\" alt=\"\" class=\"wp-image-252\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214201-1024x332.png 1024w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214201-300x97.png 300w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214201-768x249.png 768w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214201-1200x389.png 1200w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214201.png 1513w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">&lt;!&#8211; Have you ever heard of steganography? &#8211;&gt;<\/figcaption><\/figure>\n\n\n\n<p>En commentaire du site, nous avons un petit message nous demandant si nous avons d\u00e9j\u00e0 entendu parler de la st\u00e9ganographie. Je vais essayer de voir si je peux r\u00e9cup\u00e9rer l&#8217;image via le serveur FTP.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Phase d&#8217;exploitation<\/h2>\n\n\n\n<p>J&#8217;ai remarqu\u00e9 que le service FTP autorisait la connexion via login anonymous, j&#8217;exploite donc cette faille pour me connecter.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"574\" height=\"164\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214350.png\" alt=\"\" class=\"wp-image-253\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214350.png 574w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214350-300x86.png 300w\" sizes=\"auto, (max-width: 574px) 100vw, 574px\" \/><\/figure>\n\n\n\n<p>Sur le service y est seulement stock\u00e9 un fichier txt pour un certain Jake, je le r\u00e9cup\u00e8re sur ma machine locale pour voir ce qu&#8217;il contient.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"954\" height=\"227\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214521.png\" alt=\"\" class=\"wp-image-254\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214521.png 954w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214521-300x71.png 300w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214521-768x183.png 768w\" sizes=\"auto, (max-width: 954px) 100vw, 954px\" \/><\/figure>\n\n\n\n<p>D&#8217;apr\u00e8s Amy, le mot de passe de Jake serait faible, tentons un brute-force sur son mot de passe pour voir si nous obtenons une concordance avec la liste rockyou.txt<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"847\" height=\"73\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214655.png\" alt=\"\" class=\"wp-image-255\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214655.png 847w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214655-300x26.png 300w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-214655-768x66.png 768w\" sizes=\"auto, (max-width: 847px) 100vw, 847px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"922\" height=\"260\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-220301.png\" alt=\"\" class=\"wp-image-256\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-220301.png 922w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-220301-300x85.png 300w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-220301-768x217.png 768w\" sizes=\"auto, (max-width: 922px) 100vw, 922px\" \/><\/figure>\n\n\n\n<p>Nous avons bien un combo username\/password, connectons-nous :<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"642\" height=\"198\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-220313.png\" alt=\"\" class=\"wp-image-257\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-220313.png 642w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-220313-300x93.png 300w\" sizes=\"auto, (max-width: 642px) 100vw, 642px\" \/><\/figure>\n\n\n\n<p>En me baladant sur le serveur je remarque le user.txt dans le dossier home d&#8217;un autre utilisateur, qui est mon premier flag sur cette box.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"440\" height=\"323\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-220609.png\" alt=\"\" class=\"wp-image-258\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-220609.png 440w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-220609-300x220.png 300w\" sizes=\"auto, (max-width: 440px) 100vw, 440px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"683\" height=\"122\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-220628.png\" alt=\"\" class=\"wp-image-259\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-220628.png 683w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-220628-300x54.png 300w\" sizes=\"auto, (max-width: 683px) 100vw, 683px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Phase d&#8217;\u00e9l\u00e9vation de privil\u00e8ges<\/h2>\n\n\n\n<p>Ayant maintenant un acc\u00e8s &#8220;l\u00e9gitime&#8221; donc un utilisateur sur la machine, voyons voir si nous pouvons \u00e9lever nos privil\u00e8ges sur la machine cible.<\/p>\n\n\n\n<p>Apparemment Jake peut lancer la commande &#8220;less&#8221; en tant qu&#8217;utilisateur privil\u00e9gi\u00e9, servons-en nous pour exploiter le bit SUID.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"750\" height=\"112\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-220823.png\" alt=\"\" class=\"wp-image-260\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-220823.png 750w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-220823-300x45.png 300w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\" \/><\/figure>\n\n\n\n<p>Apr\u00e8s une simple recherche voici comment l&#8217;exploiter :<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"457\" height=\"19\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-221131.png\" alt=\"\" class=\"wp-image-261\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-221131.png 457w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-221131-300x12.png 300w\" sizes=\"auto, (max-width: 457px) 100vw, 457px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"747\" height=\"545\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-221242.png\" alt=\"\" class=\"wp-image-262\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-221242.png 747w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-221242-300x219.png 300w\" sizes=\"auto, (max-width: 747px) 100vw, 747px\" \/><\/figure>\n\n\n\n<p>Et voil\u00e0, nous sommes root, nous pouvons r\u00e9cup\u00e9rer notre dernier flag.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"415\" height=\"176\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-221317.png\" alt=\"\" class=\"wp-image-263\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-221317.png 415w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-221317-300x127.png 300w\" sizes=\"auto, (max-width: 415px) 100vw, 415px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"682\" height=\"109\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-221333.png\" alt=\"\" class=\"wp-image-264\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-221333.png 682w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-221333-300x48.png 300w\" sizes=\"auto, (max-width: 682px) 100vw, 682px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"841\" height=\"287\" src=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-221352.png\" alt=\"\" class=\"wp-image-265\" srcset=\"https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-221352.png 841w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-221352-300x102.png 300w, https:\/\/fromkiddietorobot.fr\/wp-content\/uploads\/2025\/05\/image-2-20250518-221352-768x262.png 768w\" sizes=\"auto, (max-width: 841px) 100vw, 841px\" \/><\/figure>\n\n\n\n<p>GG !<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This room is aimed for beginner level hackers but anyone can try to hack this box. There are two main intended ways to root the box.<\/p>\n","protected":false},"author":3,"featured_media":248,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-247","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ctf"],"_links":{"self":[{"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/posts\/247","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/comments?post=247"}],"version-history":[{"count":2,"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/posts\/247\/revisions"}],"predecessor-version":[{"id":266,"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/posts\/247\/revisions\/266"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/media\/248"}],"wp:attachment":[{"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/media?parent=247"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/categories?post=247"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fromkiddietorobot.fr\/index.php\/wp-json\/wp\/v2\/tags?post=247"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}