Enumeration
As usual, let's start with our nmap
nmap -sV -sC IP
-sV : service detection
-sC : performs a script scan
Replace IP by the IP of the target machine (Sequel)
Note: The IP of the target machines are always changing so make sure you type the correct one. You can find it on your Hack The Box account.
data:image/s3,"s3://crabby-images/23231/232315a9ebedfc2e79057663ef78b4124de874d2" alt=""
Port 3306 is usually associated with MySQL protocol. MySQL is a service used for database management such as creating, modifying or deleting databases.
Foothold
Type this command to get more info on how to use the command sql
mysql --help
We find that we need to add -u followed by the username:
data:image/s3,"s3://crabby-images/8a392/8a392914b25395d6faad5396218975e402afa275" alt=""
We find that we need to add -h followed my the hostname or IP:
data:image/s3,"s3://crabby-images/4488e/4488ed5f85b18d85f3ce405a232ed31e1bbdbf59" alt=""
We don't know any username but we can try our luck with the user root.
mysql -u root -h 10.129.231.168
data:image/s3,"s3://crabby-images/067d9/067d93ea37f1ce7e1dbb2a272c21d9e8e4f613a2" alt=""
Notice that we were not even asked for a password, meaning that the administrator forgot to set up a password. We are in luck!
Now that we are in the database, let's type:
show databases;
This command lists all the databases available.
data:image/s3,"s3://crabby-images/36e1d/36e1d4f0dcd653fcec445d617a947dcc42dced4e" alt=""
use htb;
This command advises that we want to use the database called htb
data:image/s3,"s3://crabby-images/51d6e/51d6e124b59eead0a934791487746b8a7b77cff9" alt=""
show tables;
This command is used to show us all the tables available in the database htb
data:image/s3,"s3://crabby-images/535dc/535dca76e5f2cb7504d7fd6805322ace75ea7652" alt=""
SELECT * from config;
This means we want to select and show everything (rows and columns) that is in the table config
data:image/s3,"s3://crabby-images/0646b/0646b0158e9b50ce215ace3e51ce18e5f02e86d6" alt=""
Congratulations! You got the flag!
Comments