HTB: Blunder

Posted on 19 Oct 2020 in security • Tagged with security, boot2root, HTB, linux, cewl, bludit, sudo • 6 min read

Blunder Card

This is a writeup about a retired HacktheBox machine: Blunder. This box was created by egotisticalSW and publish on May 30, 2020. The box is rated as an easy box. It implies enumeration, generating a custom wordlist with cewl, using metasploit, cracking a password and a sudo vulnerability.


Continue reading

HTB: Admirer

Posted on 27 Sep 2020 in security • Tagged with security, boot2root, HTB, adminer, Linux, sudo • 5 min read

Admirer card

This is a writeup about a retired HacktheBox machine: Admirer created by polarbearer and GibParadox and publish on May 2, 2020. This box is classified as an easy machine. The user part implied a few enumeration and an adminer vulnerability. The root part implied a sudo permission with SETENV and a python script.


Continue reading

HTB: OpenAdmin

Posted on 04 May 2020 in security • Tagged with security, boot2root, HTB, openAdmin, sudo, nano • 6 min read

OpenAdmin card

This is a writeup about a retired HacktheBox machine: OpenAdmin created by dmw0ng and publish on January 4, 2020. This box is classified as an easy machine. The user part is longer than the root part and involve to find a vulnerable component, exploit it to get a shell, found the creds of an user able to connect using SSH then found another webservice to get the private SSH key of a second user. The root part is simply exploiting a sudo permission on nano to execute command.


Continue reading