mirror of
https://github.com/AbdullahRizwan101/CTF-Writeups
synced 2025-02-26 03:47:12 +00:00
1.2 KiB
1.2 KiB
echoCTF - Cretin
We can find the first flag by printing the environmental variable env
after connecting with nc
data:image/s3,"s3://crabby-images/e2466/e2466bb60b6eff740b3e873fd3a4c8f010efeabe" alt=""
Privilege Escalation (dribble)
Running sudo -l
we can see that this user can runed
binary as dribble
user
data:image/s3,"s3://crabby-images/74244/74244106ea03983ee9a457147a5d9efae91359d9" alt=""
So looking at GTFOBINS
data:image/s3,"s3://crabby-images/24866/24866352cda7586a0373f9227f0dc075afb9f788" alt=""
data:image/s3,"s3://crabby-images/37095/37095f40b96dac55fa07cd025a6854dfc73d5872" alt=""
Privilege Escalation (scribble)
Again running sudo -l we can see this user can now run capsh
binary as scribble
user
data:image/s3,"s3://crabby-images/991af/991afa7dc2991781c071ef5358ed0232e016b06b" alt=""
data:image/s3,"s3://crabby-images/a7359/a735972164c2a756da7fe5d997124b5a6f944da4" alt=""
Privilege Escalation (ETSCTF)
This is the last priv esc that we need to do , we can run whiptail
as ETSCTF
user
data:image/s3,"s3://crabby-images/4257b/4257b27a973a1355ca7b47f4b19f2565066ec50b" alt=""
data:image/s3,"s3://crabby-images/638df/638df1db18ba796f62d330940ea7d7696a1e9ea5" alt=""
Running that we will get ambiguous redirect , so this isn't actually a binary but a script which is running the actual whiptail binary
data:image/s3,"s3://crabby-images/efc1a/efc1a1f3a6db357f2c1da957db87e6d776a4692e" alt=""
We just need to specify the file name to read as the privesc is already included here
data:image/s3,"s3://crabby-images/81d1a/81d1a1c56b5e50aaa9ecb79aedbe744a247442b3" alt=""
data:image/s3,"s3://crabby-images/2ded9/2ded9fd893bb61597475500b72f9ae8cce59e5ff" alt=""