type
status
date
slug
summary
tags
category
icon
password
Status
Due date
Sep 18, 2023 04:17 AM
Progress
Task1:Besides SSH and HTTP, what other service is hosted on this box?
ftp

Task2:This service can be configured to allow login with any password for specific username. What is that username?
Anonymous

Task3:What is the name of the file downloaded over this service?
backup.zip


Task4:What script comes with the John The Ripper toolset and generates a hash from a password protected zip archive in a format to allow for cracking attempts?
zip2john



Task5:What is the password for the admin user on the website?
qwerty789



Task6:What option can be passed to sqlmap to try to get command execution via the sql injection?
—os-shell

3個db:information_schema、pg_catalog、public




取得reverse shell


Task7:What program can the postgres user run as root using sudo?



Submit user flag

Submit root flag
Reference
- 作者:ji3g4gp
- 連結:https://gpblog.vercel.app//article/HTB-Vaccine
- 著作權:本文採用 CC BY-NC-SA 4.0 許可協議,轉載請註明出處。