Pandora

We would be attacking the HackTheBox Pandora Machine

image

Definitely starting with an nmap scan

image

Webpage on port 80 looks quite empty, safe some email addresses.

image

Now we do a full nmap scan & udp port scan

image

we find snmp service running on Udp port 161 open;

image

Enumerating udp port 161 with snmpwalk tool;

image

We can get username & password from snmp

now we use found creds to login ssh as daniel user

image

Password here;

image

We get ssh access & we find linpeas to escalate our privileges as daniel to root user;

image

We find the system vulnurable to pwnkit CVE-2021-4034;

changing our directory to the /tmp/dm0220 we find the pwnkit exploit lying around

Exploiting pwnkit CVE-2021-4034 to get root!

image

We become root now & can read both root.txt from root user & user.txt from the user matt

###RESOURCES

https://app.hackthebox.com/machines/Pandora




Enjoy Reading This Article?

Here are some more articles you might like to read next:

  • Google Gemini updates: Flash 1.5, Gemma 2 and Project Astra
  • Displaying External Posts on Your al-folio Blog
  • Statica — Bypassing AI Assistant Secret Masking
  • Ashwick
  • Snobble AI