HTB Linux Easy: Cap
Cap is an Easy rated Linux machine on HTB.
HTB Linux Easy: Cap
Nmap scan
Initial Foothold
Visiting the webpage we find a tab that allows us to download Wireshark captures, the data number in the URL can be changed to get Wireshark captures for other users (IDOR). 
Only 0 gives us a different result. We can download this capture using the download button and open it in Wireshark, looking through the data we find a username and password in plain text format: nathan:Buck3tH4TF0RM3! 
Even though the credentials were used to login to FTP, we will try to log in to SSH using the same credentials. 
Priv Esc
Linpeas reveals a priv esc using Python capabilities. 
User.txt
Root.txt
You have PWNED
Sources
This post is licensed under CC BY 4.0 by the author.




