HTB Linux Easy: Blocky
Blocky is an Easy rated Linux machine on HTB.
HTB Linux Easy: Blocky
Nmap
Add the blocky.htb domain name to the hosts file. 
Initial Foothold
Enumerate HTTP (port 80)
Perform directory busting using Dirsearch: 
In the plugins directory we find 2 jar files, we can check the content of these files by decompiling them. 
Credentials were found in the BlockyCore.jar file: root:8YsqfCTnvxAUeduzjNSXe22 
Use WPScan to enumerate users since the root login doesn’t work: notch

Shell
SSH as notch using the password found in the jar file: notch:8YsqfCTnvxAUeduzjNSXe22. 
Priv Esc
Notch is part of the sudoers group which gives us an easy Priv Esc vector. 
User.txt
Root.txt
You have PWNED
Sources
This post is licensed under CC BY 4.0 by the author.



