PICKLE RICK

 

PICKLE RICK

I'm going to realize the resolution of the machine Level Easy from Tryhackme called Pickle Rick which is a machine so easy to realize.



First of all, we can observe that in the picture bellow we have some inforamtion and I'm going to execute control +u and we can see in the second picture below that we've obtained a Username.


I'm going to gathering information about machine and I have to enter in the Linux terminal and I must introduce this command which you canobserve in the picture below:
  •  gobuster dir -u(url) http://10.10.99.188/ -w(password dictionary)  /usr/share/wordlist/dirb/common.txt -x (formato que quereos que busque) .txt*, .php, .login, 
In this case, we can observe that scan has discovered this 4 webpages:
  1. /assests
  2. /denied.php
  3. /index.html
  4. /login.php
  5. /robots.txt



Now, we can see such as the web page from /robots.txt  it seems the password in the picture below.


Now, we've discovered this login web page /login.php and now, we should introduce  Username and  la Password which you can observe in the picture bellow.


In addition, we've discovered C&C and we're going to introduce some command because we'd like to find out all the ingredients.
First of all, I'm going to execute a typical command such as ls -la to see whatever I can discover that you can see in the second picture bellow where I've obtain the first ingredient:
  • Sup3r3ScretPick13Ingred.txt 



Let's go to execute the cat command cat Sup3r3ScretPick13Ingred.txt but I've obained an error which you can see in the picture below.

So I have to try other command such as  tac:
  • tac Sup3r3ScretPick13Ingred.txt
Definitely, we have discovered the first ingredient  which you can observe in the second picture bellow.





Right now, I have to execute the command ls/home because I want listing folders or directories there, but in this case, has been listed two users  Ubuntu and Rick and I must to introduce in the Rick user and seeing whatever I can discover  and you can observe at the second bottom of picture.

Also, let's go to listing the files in the Rick user with the command in the picture bellow:
  • ls -la /home/rick/
If you have introduce well the command before, you'll be able to discover the second ingredient whose name is second ingredients.

To listing we've going to execute the command (less  '/home/rick/second ingredients') and we can see that the second ingredient has been obtained succesful in the picture bellow.

Perphaps the end ingredients is the most difficult in machine, because in this type of challenges we have to find out the root flag that is the same to root user and now we must see the privilegies from root user  and we have to introduce this command:
  • sudo -l

Moreover, we can see  that we have root perms without any problem.

Now, as we've seen that we are root, right now we have to execute this command:
  • sudo ls -la /root/
Finally, we can observe that we've be able to disover the 3 ingredient that is 3rd.txt.

To sum up this challenge, we have to execute this command because we have to see the end ingredient in the picture below.




Thank you very much for reading the article 
I hope you liked it and learned  something new
Good hack

Comments

Entradas Populares

INTERNAL

TOR WEB BROWSER

activedirectory

Metasploit Framework

HOSTING

LOVE

CHANGE MACHINE