Hack The Box : NetMon WriteUp
Netmon IP Address : 10.10.10.152
# Basic Port Scan
nmap -F 10.10.10.152
data:image/s3,"s3://crabby-images/291fc/291fce761ea5141e508bf0edb59797b0de3cdb11" alt=""
Since FTP port is open we can try Anonymous login...
# username : anonymous
# password : anonymous
ftp 10.10.10.152
data:image/s3,"s3://crabby-images/a43a9/a43a930d81e2ae8fb6db96b07d6b6df3fefda2db" alt=""
Anonymous Login Successful!!
Now lets dig in deeper...
data:image/s3,"s3://crabby-images/a3d10/a3d10d7f995f9fde1df7b255891ca3bf7e088ab4" alt=""
Inside C:\Users\Public we find user.txt which can be downloaded using get command and inside user.txt we have our first hash.
Now Lets proceed to find the root hash...
Earlier I found out that port 80 is open. On visiting via browser we have a PRTG NETMON Login Page...
data:image/s3,"s3://crabby-images/f0b89/f0b898643686edeeb67a292ffa332098257cb271" alt=""
Default Username/Password for PRTG NETMON are prtgadmin:prtgadmin but these did not work...
On inspecting the page source I didn't find anything interesting, so lets head back to ftp and look for something related to PRTG NETMON
PRTG Default Installation Path is C:/Users/Program Files (x86)/PRTG Network Monitor/ but there are no configuration files in this path, later on I found another path where configuration files are stored :
C:\ProgramData\Paessler\PRTG Network Monitor\
inside there are multiple files but the password is in PRTG Configuration.old.bak
data:image/s3,"s3://crabby-images/e0b79/e0b799905dcd99f4cb21595566846b273c635136" alt=""
After reading Configuration.old.bak i found the password and username :
username : prtgadmin
password : PrTg@dmin2018
data:image/s3,"s3://crabby-images/82784/8278482e13a2f77b68b62981fd1627ecdee391a3" alt=""
I tried logging in with these credentials but login failed, but its year 2019 right now so I modified the password as PrTg@dmin2019 and tried again and Login Successful!!
data:image/s3,"s3://crabby-images/495bb/495bbd01a646325e75aeb6374e9845cd02b2942b" alt=""
After some poking around in the dashboard I discovered Notification Settings under Account Settings...
data:image/s3,"s3://crabby-images/c09be/c09be00388ee9f932830e415afcc402947ec89b3" alt=""
Here we can Add a new Trigger which will execute a command of our choice...
# Set a custom notification name
# Enable Execute Program option
# In Parameter enter :
test.txt;more C:\Users\Administrator\Desktop\root.txt > C:\hash.txt
After saving the new trigger, we can go back and check our new notification trigger, we can launch the trigger using the small play button on the right...
After a while I got hash.txt in C:\ and that is the root hash.