Silver Platter
- ๐ Website: TryHackMe
- ๐ฅ Level: Easy
- ๐ฅ๏ธ OS: Linux
- ๐ Link: Silver Platter
โQuestion¶
What is the user flag?
๐ Walkthrough¶
We start with a port scan and find three open ports:
Visiting the website on port 80, we find the name:
We start enumerating directories on the main web server:
gobuster dir \
-w=/usr/share/seclists/Discovery/Web-Content/DirBuster-2007_directory-list-2.3-medium.txt \
--url=http://10.112.136.163
We only find:
/images (Status: 301) [Size: 178] [--> http://10.112.136.163/images/]
/assets (Status: 301) [Size: 178] [--> http://10.112.136.163/assets/]
Nothing particularly useful, so we try directory enumeration on port 8080 as well:
gobuster dir \
-w=/usr/share/seclists/Discovery/Web-Content/DirBuster-2007_directory-list-2.3-medium.txt \
--url http://10.112.136.163:8080/
This gives us:
/website (Status: 302) [Size: 0] [--> http://10.112.136.163:8080/website/]
/console (Status: 302) [Size: 0] [--> /noredirect.html]
These paths do not immediately lead anywhere useful.
Going back to the main website and checking the Contact page, we find:
If you'd like to get in touch with us, please reach out to our project manager on Silverpeas. His username is "scr1ptkiddy".
This gives us both the application name and a username:
We try using silverpeas as a path on port 8080:
and find the Silverpeas login page.
By intercepting the login request, we can see the following parameters being sent:
We modify the request and completely remove the Password parameter:
This allows us to bypass authentication and access the account.
Once logged in, we start enumerating the messages available to the user.
While browsing the Silverpeas mail functionality, we notice that messages are identified using an ID parameter:
Changing the message ID allows us to access another message.
Inside message 6, we find:
Dude how do you always forget the SSH password? Use a password manager and quit using your silly sticky notes.
The message contains SSH credentials:
We use them to connect through SSH:
After logging in as tim, we can retrieve the user flag.
Answer
THM{c4ca4238a0b923820dcc509a6f75849b}
โQuestion¶
What is the root flag?
๐ Walkthrough¶
Once logged in as tim, we start enumerating the system.
Checking the current user and groups:
returns:
The interesting part is that tim belongs to the adm group.
This group can read several log files under:
We start searching the logs for interesting information, especially commands executed by other users.
Eventually, we find a Docker command used to start the Silverpeas container:
/usr/bin/docker run --name silverpeas -p 8080:8000 -d \
-e DB_NAME=Silverpeas \
-e DB_USER=silverpeas \
-e DB_PASSWORD=_Zd_zx7N823/ \
-v silverpeas-log:/opt/silverpeas/log \
-v silverpeas-data:/opt/silvepeas/data \
--link postgresql:database \
silverpeas:6.3.1
The command exposes a database password directly in the environment variables:
Since the system also has a local user called tyler, we try reusing the password:
The password works, showing that it was reused for the local tyler account.
From the tyler account, we complete the privilege escalation and retrieve the root flag.
Answer
THM{098f6bcd4621d373cade4e832627b4f6}