This is a write-up for UnderPass, an easy level difficulty vulnerable machine on HackTheBox. Note that at the time of this publication the machine is still active, so big spoilers and hints are to be used with caution. To access the full document with explanation, please download the PDF file from above.
- UDP port scanning
- What is daloRadius and how does it work.
- MD5 hash cracking
- Mosh service, operation, and privilege escalation.
- Kali Linux, and through it:
- nmap
- snmpwalk
- hashcat
- ssh
- scp
- manual PE enumeration
- LinPEAS
- mosh service
- daloRADIUS
- UDP port scanning:
- daloRADIUS login:
- Users list:
- MD5 hash cracking:
- SSH & User flag:
- scp file transfer of LinPEAS:
- LinPEAS result:
- Mosh as sudo:
- Mosh connection:
- Root & the flag