Stage - eloise

flag - 21



# MISSION 0x22 #

## EN ##
User lucia has been creative in saving her password.


ls -lah
total 36K
drwxr-x--- 2 root eloise 4.0K Jul 26 2023 .
drwxr-xr-x 1 root root 4.0K Jul 26 2023 ..
-rw-r--r-- 1 eloise eloise 220 Apr 23 2023 .bash_logout
-rw-r--r-- 1 eloise eloise 3.5K Apr 23 2023 .bashrc
-rw-r--r-- 1 eloise eloise 807 Apr 23 2023 .profile
-rw-r----- 1 root eloise 31 Jul 26 2023 flagz.txt
-rw-r----- 1 root eloise 50 Jul 26 2023 hi
-rw-r----- 1 root eloise 194 Jul 26 2023 mission.txt
xxd -r hi

Stage - lucia

flag - 22



# MISSION 0x23 #

## EN ##
The user isabel has left her password in a file in the /etc/xdg folder but she does not remember the name, however she has dict.txt that can help her to remember.


ls -lah
total 36K
drwxr-x--- 2 root lucia 4.0K Jul 26 2023 .
drwxr-xr-x 1 root root 4.0K Jul 26 2023 ..
-rw-r--r-- 1 lucia lucia 220 Apr 23 2023 .bash_logout
-rw-r--r-- 1 lucia lucia 3.5K Apr 23 2023 .bashrc
-rw-r--r-- 1 lucia lucia 807 Apr 23 2023 .profile
-rw-r----- 1 root lucia 2.0K Jul 26 2023 dict.txt
-rw-r----- 1 root lucia 31 Jul 26 2023 flagz.txt
-rw-r----- 1 root lucia 397 Jul 26 2023 mission.txt
while IFS= read -r line; do readlink -e /etc/xdg/$line ; done < dict.txt ; cat /etc/xdg/readme

Stage - isabel

flag - 23



# MISSION 0x24 #

## EN ##
The password of the user freya is the only string that is not repeated in different.txt


ls -lah
total 180K
drwxr-x--- 2 root isabel 4.0K Jul 26 2023 .
drwxr-xr-x 1 root root 4.0K Jul 26 2023 ..
-rw-r--r-- 1 isabel isabel 220 Apr 23 2023 .bash_logout
-rw-r--r-- 1 isabel isabel 3.5K Apr 23 2023 .bashrc
-rw-r--r-- 1 isabel isabel 807 Apr 23 2023 .profile
-rw-r----- 1 root isabel 148K Jul 26 2023 different.txt
-rw-r----- 1 root isabel 31 Jul 26 2023 flagz.txt
-rw-r----- 1 root isabel 245 Jul 26 2023 mission.txt
uniq -u different.txt

Stage - freya

flag - 24



# MISSION 0x25 #

## EN ##
User alexa puts her password in a .txt file in /free every minute and then deletes it.


ls -lah
total 32K
drwxr-x--- 2 root freya 4.0K Jul 26 2023 .
drwxr-xr-x 1 root root 4.0K Jul 26 2023 ..
-rw-r--r-- 1 freya freya 220 Apr 23 2023 .bash_logout
-rw-r--r-- 1 freya freya 3.5K Apr 23 2023 .bashrc
-rw-r--r-- 1 freya freya 807 Apr 23 2023 .profile
-rw-r----- 1 root freya 31 Jul 26 2023 flagz.txt
-rw-r----- 1 root freya 262 Jul 26 2023 mission.txt
false; while [$? -ne 0]; do cat /free/* ; done 2>/dev/null

Stage - alexa

flag - 25



# MISSION 0x26 #

## EN ##
The password of the user ariel is online! (HTTP)


ls -lah
total 32K
drwxr-x--- 2 root alexa 4.0K Jul 26 2023 .
drwxr-xr-x 1 root root 4.0K Jul 26 2023 ..
-rw-r--r-- 1 alexa alexa 220 Apr 23 2023 .bash_logout
-rw-r--r-- 1 alexa alexa 3.5K Apr 23 2023 .bashrc
-rw-r--r-- 1 alexa alexa 807 Apr 23 2023 .profile
-rw-r----- 1 root alexa 31 Jul 26 2023 flagz.txt
-rw-r----- 1 root alexa 172 Jul 26 2023 mission.txt
curl http://localhost

Stage - ariel

flag - 26



# MISSION 0x27 #

## EN ##
Seems that ariel dont save the password for lola, but there is a temporal file.


ls -lah
total 44K
drwxr-x--- 2 root ariel 4.0K Jul 26 2023 .
drwxr-xr-x 1 root root 4.0K Jul 26 2023 ..
-rw-r--r-- 1 ariel ariel 220 Apr 23 2023 .bash_logout
-rw-r--r-- 1 ariel ariel 3.5K Apr 23 2023 .bashrc
-rw-r----- 1 root ariel 12K Jul 26 2023 .goas.swp
-rw-r--r-- 1 ariel ariel 807 Apr 23 2023 .profile
-rw-r----- 1 root ariel 31 Jul 26 2023 flagz.txt
-rw-r----- 1 root ariel 254 Jul 26 2023 mission.txt
vim -r .goas.swp

使用 hydra 进行爆破,得到密码为


Stage - lola

flag - 27



# MISSION 0x28 #

## EN ##
The user celeste has left a list of names of possible .html pages where to find her password.


ls -lah
total 36K
drwxr-x--- 2 root lola 4.0K Jul 26 2023 .
drwxr-xr-x 1 root root 4.0K Jul 26 2023 ..
-rw-r--r-- 1 lola lola 220 Apr 23 2023 .bash_logout
-rw-r--r-- 1 lola lola 3.5K Apr 23 2023 .bashrc
-rw-r--r-- 1 lola lola 807 Apr 23 2023 .profile
-rw-r----- 1 root lola 31 Jul 26 2023 flagz.txt
-rw-r----- 1 root lola 272 Jul 26 2023 mission.txt
-rw-r----- 1 root lola 1.5K Jul 26 2023 pages.txt
# 创建一个 SSH 隧道(tunnel),将远程服务器 venus.hackmyvm.eu 上的 80 端口转发到本地计算机的 9001 端口。
$ ssh -L 9001: lola@venus.hackmyvm.eu -p 5000
# 然后再扫描目录
$ dirb ./pages.txt -X .html
# 或者 gobuster dir -w pages.txt -u -x html
# 可以得到一个网页
$ curl
# VLSNMTKwSV2o8Tn // 得到了 celeste 的密码 VLSNMTKwSV2o8Tn

Stage - celeste

flag - 28


flag - hidden - 0xH

celeste@venus:~$ mysql -uceleste -pVLSNMTKwSV2o8Tn
Welcome to the MariaDB monitor. Commands end with ; or \g.
Your MariaDB connection id is 261
Server version: 10.11.3-MariaDB-1 Debian 12

Copyright (c) 2000, 2018, Oracle, MariaDB Corporation Ab and others.

Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.

MariaDB [(none)]> use venus;
Reading table information for completion of table and column names
You can turn off this feature to get a quicker startup with -A

Database changed
MariaDB [venus]> select * from people;
| 35 | haha | 8===xKmPDsJSKpHLzkqKXyjx===D~~ |


# MISSION 0x29 #

## EN ##
The user celeste has access to mysql but for what?


ls -lah
total 32K
drwxr-x--- 2 root celeste 4.0K Jul 26 2023 .
drwxr-xr-x 1 root root 4.0K Jul 26 2023 ..
-rw-r--r-- 1 celeste celeste 220 Apr 23 2023 .bash_logout
-rw-r--r-- 1 celeste celeste 3.5K Apr 23 2023 .bashrc
-rw-r--r-- 1 celeste celeste 807 Apr 23 2023 .profile
-rw-r----- 1 root celeste 31 Jul 26 2023 flagz.txt
-rw-r----- 1 root celeste 179 Jul 26 2023 mission.txt
mysql -uceleste -pVLSNMTKwSV2o8Tn -e''use venus;select * from people where length(pazz)=15;'
| id_people | uzer | pazz |
| 16 | sfdfdsml | ixpeqdsfsdfdsfW |
| 44 | yuio | ixpgbvcbvcbeqdW |
| 54 | crom | ixpefdbvvcbrqdW |
| 58 | bael | ixpesdvsdvsdqdW |
| 74 | nina | ixpeqdWuvC5N9kG |
| 77 | dsar | ixpeF43F3F34qdW |
| 78 | yop | ixpeqdWCSDFDSFD |
| 79 | loco | ixpeF43F34F3qdW |

根据 /etc/passwd 的记录,可以定位到 nina 这个用户

Stage - nina

flag - 29



# MISSION 0x30 #

## EN ##
The user kira is hidding something in http://localhost/method.php


ls -lah
total 32K
drwxr-x--- 2 root nina 4.0K Jul 26 2023 .
drwxr-xr-x 1 root root 4.0K Jul 26 2023 ..
-rw-r--r-- 1 nina nina 220 Apr 23 2023 .bash_logout
-rw-r--r-- 1 nina nina 3.5K Apr 23 2023 .bashrc
-rw-r--r-- 1 nina nina 807 Apr 23 2023 .profile
-rw-r----- 1 root nina 31 Jul 26 2023 flagz.txt
-rw-r----- 1 root nina 197 Jul 26 2023 mission.txt
curl -XPUT http://localhost/method.php

Stage - kira

flag - 30



# MISSION 31 #

## EN ##
The user veronica visits a lot http://localhost/waiting.php


ls -lah
total 32K
drwxr-x--- 2 root kira 4.0K Jul 26 2023 .
drwxr-xr-x 1 root root 4.0K Jul 26 2023 ..
-rw-r--r-- 1 kira kira 220 Apr 23 2023 .bash_logout
-rw-r--r-- 1 kira kira 3.5K Apr 23 2023 .bashrc
-rw-r--r-- 1 kira kira 807 Apr 23 2023 .profile
-rw-r----- 1 root kira 31 Jul 26 2023 flagz.txt
-rw-r----- 1 root kira 191 Jul 26 2023 mission.txt
curl -A PARADISE http://localhost/waiting.php