Summary
OpenAdmin,a Linux box created by HackTheBox user dmw0ng, was an overall easy difficulty box.Initial Enumeration shows that only port 22 and port 80 to be opened.On Web we see that OpenNetAdmin
, searching the exploit we see an shell-script on exploitdb,using that we get a shell as www-data
. Enumerating we find a credentials for database checking if we have a password reuse on ssh
we try with both usernames and we get a hit as jimmy
and enumerating we find an internal service which was cating the id_rsa for joanna
and port-forwarding and getting the password,Cracking the passphrase we get user
. Root was pretty simple using nano