PageSourceSearch

https://cybernotes.netlify.app/assets/js/95139fef.4f4a2133.js

js cybernotes.netlify.app collected 2026-10-03 10:40:09 UTC 14,917 bytes, 1 lines download raw bytes

1"use strict";(globalThis.webpackChunkcybernotes=globalThis.webpackChunkcybernotes||[]).push([[9717],{987:(e,n,t)=>{t.r(n),t.d(n,{assets:()=>l,contentTitle:()=>r,default:()=>d,frontMatter:()=>i,metadata:()=>s,toc:()=>c});var s=t(2165),a=t(4848),o=t(8453);const i={slug:"Sequel",title:"Hack The Box - Sequel",authors:["mariosdaskalas"],tags:["hackthebox"],date:new Date("2025-03-06T00:00:00.000Z")},r=void 0,l={authorsImageUrls:[void 0]},c=[{value:"Task 1",id:"task-1",level:2},{value:"Task 2",id:"task-2",level:2},{value:"Task 3",id:"task-3",level:2},{value:"Task 4",id:"task-4",level:2},{value:"Task 5",id:"task-5",level:2},{value:"Task 6",id:"task-6",level:2},{value:"Task 7",id:"task-7",level:2},{value:"Submit Flag",id:"submit-flag",level:2},{value:"Submit root flag",id:"submit-root-flag",level:2}];function h(e){const n={a:"a",code:"code",h2:"h2",img:"img",p:"p",pre:"pre",...(0,o.R)(),...e.components};return(0,a.jsxs)(a.Fragment,{children:[(0,a.jsx)(n.p,{children:(0,a.jsx)(n.img,{src:t(6562).A+"",title:"Hack The Box",width:"4267",height:"2560"})}),"\n",(0,a.jsx)(n.p,{children:"Howdy my fellow Cyber Enthusiasts! Welcome to the first Starting Point Hack The Box offers. I am excited to embark on this journey with you. So, without further ado, let\u2019s dive in! :)"}),"\n",(0,a.jsxs)(n.p,{children:["Need to embark on an exciting journey on Hack The Box? Sign up now using the following ",(0,a.jsx)(n.a,{href:"https://hacktheboxltd.sjv.io/aOVxxb",children:"Link"}),"."]}),"\n",(0,a.jsx)(n.p,{children:"Remember to change the IP adress to your allocated one! :)"}),"\n",(0,a.jsx)(n.p,{children:"There are 2 options available to connect to our machine. First using Pwnbox or secondly using OpenVPN."}),"\n",(0,a.jsx)(n.p,{children:"I need to mention that if you are using the first option (Pwnbox) you can follow this guide, regardless if you are using Windows, Mac OS or Linux. This is the case, because a new tab will open in your web browser and there you can interact with the target machine."}),"\n",(0,a.jsx)(n.p,{children:"Now, if you are using Ubuntu-based distros, you can following this guide using the second option as well, but it will not work with a Windows OS for example."}),"\n",(0,a.jsx)(n.p,{children:(0,a.jsx)(n.img,{src:t(3081).A+"",title:"Hack The Box Connect",width:"1848",height:"646"})}),"\n",(0,a.jsx)(n.p,{children:"If you want to use the first option, it is very simple. Just click on the option and follow the instructions (Start Pwnbox). A new tab will open up and there you can interact with the machine."}),"\n",(0,a.jsx)(n.p,{children:(0,a.jsx)(n.img,{src:t(6498).A+"",title:"Hack The Box Connect",width:"733",height:"1038"})}),"\n",(0,a.jsx)(n.p,{children:"For the second option, things are a bit more complicated. You click on the \u201cConnect using OpenVPN\u201d and the follow section appears. Click on \u201cDownload VPN\u201d and save the file on your desired folder."}),"\n",(0,a.jsx)(n.p,{children:(0,a.jsx)(n.img,{src:t(7003).A+"",title:"Hack The Box Connect",width:"748",height:"959"})}),"\n",(0,a.jsx)(n.p,{children:"Then open up the terminal and navigate to the folder that you\u2019ve downloaded the .ovpn file. Then, type the following command (change the filename accordingly)."}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-shell",children:"sudo openvpn root.ovpn\n"})}),"\n",(0,a.jsx)(n.p,{children:"To make sure you are connected to the Hack The Box network type the following command in the terminal."}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-shell",children:"ip a s\n"})}),"\n",(0,a.jsx)(n.p,{children:"You should see a new connection under the tun0 section. For example, I got a inet 10.10.15.55/23."}),"\n",(0,a.jsx)(n.p,{children:"Next, you click on the \u201cSpawn the target machine and the IP will show here\u201c. Wait for a couple of seconds and a target machine IP address will appear. To make sure you can interact with the machine, you can ping it using the terminal to make sure it responds back."}),"\n",(0,a.jsx)(n.p,{children:(0,a.jsx)(n.img,{src:t(7092).A+"",title:"Hack The Box Connect",width:"1833",he
1ight:"321"})}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-shell",children:"ping -c 3 10.129.13.30\n\nPING 10.129.13.30 (10.129.13.30) 56(84) bytes of data.\n64 bytes from 10.129.13.30: icmp_seq=1 ttl=63 time=57.6 ms\n64 bytes from 10.129.13.30: icmp_seq=2 ttl=63 time=57.8 ms\n64 bytes from 10.129.13.30: icmp_seq=3 ttl=63 time=57.4 ms\n\n--- 10.129.13.30 ping statistics ---\n3 packets transmitted, 3 received, 0% packet loss, time 2002ms\nrtt min/avg/max/mdev = 57.387/57.608/57.847/0.188 ms\n"})}),"\n",(0,a.jsx)(n.h2,{id:"task-1",children:"Task 1"}),"\n",(0,a.jsx)(n.p,{children:"During our scan, which port do we find serving MySQL?"}),"\n",(0,a.jsx)(n.p,{children:"Let\u2019s scan our target to answer this question. We are going to use a tool named Nmap to do that."}),"\n",(0,a.jsx)(n.p,{children:"Nmap (Network Mapper) is a network scanner created by Gordon Lyon. Nmap is used to discover hosts and services on a computer network by sending packets and analyzing the responses. Nmap provides a number of features for probing computer networks, including host discovery and service and operating system detection."}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-shell",children:"sudo nmap -sV 10.129.13.30\n\nStarting Nmap 7.80 ( https://nmap.org ) at 2025-09-09 16:36 EEST\nNmap scan report for 10.129.13.30\nHost is up (0.18s latency).\nNot shown: 999 closed ports\nPORT     STATE SERVICE VERSION\n3306/tcp open  mysql?\n\nService detection performed. Please report any incorrect results at https://nmap.org/submit/ .\nNmap done: 1 IP address (1 host up) scanned in 165.49 seconds\n"})}),"\n",(0,a.jsx)(n.p,{children:"SERVICE/VERSION DETECTION:"}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-shell",children:"-sV: Probe open ports to determine service/version info\n"})}),"\n",(0,a.jsx)(n.p,{children:"Here, the portion of the output that we need to anwser our question."}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-shell",children:"PORT     STATE SERVICE VERSION\n3306/tcp open  mysql?\n"})}),"\n",(0,a.jsx)(n.h2,{id:"task-2",children:"Task 2"}),"\n",(0,a.jsx)(n.p,{children:"What community-developed MySQL version is the target running?"}),"\n",(0,a.jsx)(n.p,{children:"Sometimes -sV is not enough and we need to use -sC to gain more information about versions."}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-shell",children:"sudo nmap -sV -sC 10.129.13.30\n\nStarting Nmap 7.80 ( https://nmap.org ) at 2025-09-09 16:44 EEST\nNmap scan report for 10.129.13.30\nHost is up (0.091s latency).\nNot shown: 999 closed ports\nPORT     STATE SERVICE VERSION\n3306/tcp open  mysql?\n| mysql-info: \n|   Protocol: 10\n|   Version: 5.5.5-10.3.27-MariaDB-0+deb10u1\n|   Thread ID: 96\n|   Capabilities flags: 63486\n|   Some Capabilities: Speaks41ProtocolNew, SupportsLoadDataLocal, Support41Auth, FoundRows, ConnectWithDatabase, SupportsTransactions, LongColumnFlag, ODBCClient, Speaks41ProtocolOld, InteractiveClient, SupportsCompression, IgnoreSpaceBeforeParenthesis, DontAllowDatabaseTableColumn, IgnoreSigpipes, SupportsAuthPlugins, SupportsMultipleResults, SupportsMultipleStatments\n|   Status: Autocommit\n|   Salt: OO!Sbo*!cTZE-O&o!OMu\n|_  Auth Plugin Name: mysql_native_password\n\nService detection performed. Please report any incorrect results at https://nmap.org/submit/ .\nNmap done: 1 IP address (1 host up) scanned in 185.36 seconds\n"})}),"\n",(0,a.jsx)(n.h2,{id:"task-3",children:"Task 3"}),"\n",(0,a.jsx)(n.p,{children:"When using the MySQL command line client, what switch do we need to use in order to specify a login username?"}),"\n",(0,a.jsx)(n.p,{children:(0,a.jsx)(n.img,{src:t(8221).A+"",title:"MySQL --user",width:"728",height:"142"})}),"\n",(0,a.jsx)(n.p,{children:"You can read more about MySQL in the following source."}),"\n",(0,a.jsxs)(n.p,{children:["Source: ",(0,a.jsx)(n.a,{href:"https://linux.die.net/man/1/mysql",children:"MySQL Man Page"})]}),"\n",(0,a.jsx)(n.h2,{id:"task-4",children:"Task 4"}),"\n",(0,a.jsx)(n.p,{children:"Which username allows us to log into this MariaDB instance without providing a password?"}),"\n",(0,a.jsx)(n.p,{children:"Well, that one you must know. It is root."}),"\n",(0,a.jsx)(n.h2,{id:"task-5",children:"Task 5"}),"\n",(0,a.jsx)(n.p,{children:"In SQL, what symbol can we use to specify within the query that we want to display everything inside a table?"}),"\n",(0,a.jsx)(n.p,{children:"Let\u2019s see a SQL statement."}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-shell",children:"SELECT * FROM users;\n"})}),"\n",(0,a.jsx)(n.p,{children:"This will display all records (* character) from the users table."}),"\n",(0,a.jsx)(n.h2,{id:"task-6",children:"Task 6"}),"\n",(0,a.jsx)(n.p,{children:"In SQL, what symbol do we need to end each query with?"}),"\n",(0,a.jsx)(n.p,{children:"We\u2019ve seen this in the previous statement."}),"\n",(0,a.jsx)(n.h2,{id:"task-7",children:"Task 7"}),"\n",(0,a.jsx)(n.p,{children:"There are three databases in this MySQL instance that are common across all MySQL instances. What is the name of the fourth that's unique to this host?"}),"\n",(0,a.jsx)(n.p,{children:"Let\u2019s use the following command to connect to the MySQL instance of our target machine."}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-shell",children:"mysql -u root -h 10.129.13.30\n\nWelcome to the MySQL monitor.  Commands end with ; or \\g.\nYour MySQL connection id is 99\nServer version: 5.5.5-10.3.27-MariaDB-0+deb10u1 Debian 10\n\nCopyright (c) 2000, 2023, Oracle and/or its affiliates.\n\nOracle is a registered trademark of Oracle Corporation and/or its\naffiliates. Other names may be trademarks of their respective\nowners.\n\nType 'help;' or '\\h' for help. Type '\\c' to clear the current input statement.\n\nmysql>\n"})}),"\n",(0,a.jsx)(n.p,{children:"Use the following statement when you are inside the database. The first database is the answer."}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-shell",children:"mysql> show databases;\n+--------------------+\n| Database           |\n+--------------------+\n| ( )                |\n| information_schema |\n| mysql              |\n| performance_schema |\n+--------------------+\n4 rows in set 
1(0,08 sec)\n"})}),"\n",(0,a.jsx)(n.h2,{id:"submit-flag",children:"Submit Flag"}),"\n",(0,a.jsx)(n.h2,{id:"submit-root-flag",children:"Submit root flag"}),"\n",(0,a.jsx)(n.p,{children:"You can use the following statements inside mysql to select a database, show all tables and select all records of a given table."}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-shell",children:"mysql> show databases;\n+--------------------+\n| Database           |\n+--------------------+\n| htb                |\n| information_schema |\n| mysql              |\n| performance_schema |\n+--------------------+\n4 rows in set (0,08 sec)\n\nmysql> USE htb;\nReading table information for completion of table and column names\nYou can turn off this feature to get a quicker startup with -A\n\nDatabase changed\nmysql> SHOW TABLES;\n+---------------+\n| Tables_in_htb |\n+---------------+\n| config        |\n| users         |\n+---------------+\n2 rows in set (0,06 sec)\n\nmysql> SELECT * FROM config;\n+----+-----------------------+----------------------------------+\n| id | name                  | value                            |\n+----+-----------------------+----------------------------------+\n|  1 | timeout               | 60s                              |\n|  2 | security              | default                          |\n|  3 | auto_logon            | false                            |\n|  4 | max_size              | 2M                               |\n|  5 | flag                  | (omitted)                        |\n|  6 | enable_uploads        | false                            |\n|  7 | authentication_method | radius                           |\n+----+-----------------------+----------------------------------+\n7 rows in set (0,05 sec)\n\nmysql> SELECT * FROM users;\n+----+----------+------------------+\n| id | username | email            |\n+----+----------+------------------+\n|  1 | admin    | [email protected] |\n|  2 | lara     | [email protected]  |\n|  3 | sam      | [email protected]   |\n|  4 | mary     | [email protected]  |\n+----+----------+------------------+\n4 rows in set (0,11 sec)\n"})}),"\n",(0,a.jsx)(n.p,{children:"Congratulations! You have solved this machine! \ud83c\udf89 \ud83c\udf89 \ud83c\udf89"})]})}function d(e={}){const{wrapper:n}={...(0,o.R)(),...e.components};return n?(0,a.jsx)(n,{...e,children:(0,a.jsx)(h,{...e})}):h(e)}},2165:e=>{e.exports=JSON.parse('{"permalink":"/blog/Sequel","source":"@site/blog/2025/03/06/Sequel/index.md","title":"Hack The Box - Sequel","description":"Howdy my fellow Cyber Enthusiasts! Welcome to the first Starting Point Hack The Box offers. I am excited to embark on this journey with you. So, without further ado, let\u2019s dive in! :)","date":"2025-03-06T00:00:00.000Z","tags":[{"inline":true,"label":"hackthebox","permalink":"/blog/tags/hackthebox"}],"readingTime":6.05,"hasTruncateMarker":true,"authors":[{"name":"Marios Daskalas","title":"Cyber Security Specialist","url":"#","page":{"permalink":"/blog/authors/mariosdaskalas"},"imageURL":"https://github.com/mariosdaskalas.png","key":"mariosdaskalas"}],"frontMatter":{"slug":"Sequel","title":"Hack The Box - Sequel","authors":["mariosdaskalas"],"tags":["hackthebox"],"date":"2025-03-06T00:00:00.000Z"},"unlisted":false,"prevItem":{"title":"Hack The Box - Crocodile","permalink":"/blog/Crocodile"},"nextItem":{"title":"Hack The Box - Appointment","permalink":"/blog/Appointment"}}')},3081:(e,n,t)=>{t.d(n,{A:()=>s});const s=t.p+"assets/images/img1-c258a2d889baa0c89a5468a11e29abf1.png"},6498:(e,n,t)=>{t.d(n,{A:()=>s});const s=t.p+"assets/images/img2-31fc12431dc80edd12c236ced77fa6f0.png"},6562:(e,n,t)=>{t.d(n,{A:()=>s});const s=t.p+"assets/images/htb-1679e3e71fb2adfecb95e1de92d501f1.png"},7003:(e,n,t)=>{t.d(n,{A:()=>s});const s=t.p+"assets/images/img3-ea0fe201990386318961c06a4871b0c9.png"},7092:(e,n,t)=>{t.d(n,{A:()=>s});const s=t.p+"assets/images/img4-6386f1aeb99900b9659a8862bf113bd2.png"},8221:(e,n,t)=>{t.d(n,{A:()=>s});const s=t.p+"assets/images/img5-0826a5f13efb2c4891aac815a7cd451b.png"},8453:(e,n,t)=>{t.d(n,{R:()=>i,x:()=>r});var s=t(6540);const a={},o=s.createContext(a);function i(e){const n=s.useContext(o);return s.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function r(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(a):e.components||a:i(e.components),s.createElement(o.Provider,{value:n},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.