Skip to main content

Command Palette

Search for a command to run...

Keeper

Updated
•2 min read•View as Markdown
Keeper

Enumeration

During enumeration, two available services were discovered: the OpenSSH Server service on port 22 and the Nginx service on port 80.

nmap -sCV -p 22,80 -oN $IP

Enumeration Web

Moving on to web enumeration, it's discovered that this redirects us to a website with the domain "tickets.keeper.htb," so we add it to the "/etc/hosts" file.

http://tickets.keeper.htb/rt/

This redirects us to a site that presents a login form for BestPractical services.

FoodHold

https://www.192-168-1-1-ip.co/router/bestpractical/rt/12338/

If we investigate a bit on the Internet, we can discover that this site uses default credentials.

This redirects us to a control panel.

If we observe the menus, we find one named "Administrator" in which there's a submenu called "Users." Upon selecting this, we are directed straight to a list displaying the registered users on the web platform.

The list contains two users: "root" and "lnorgaard." In the comments of the "lnorgaard" user, we find a password that we can use to authenticate via SSH.

PE

If we list the user's files, we find a compressed file containing a memory dump of the KeePass process, as well as a KeePass database.

CVE-2023-32784

https://www.hackplayers.com/2023/05/extraccion-de-la-contrasena-maestra-de-keepass.html

A vulnerability was discovered that allows retrieving the master password in clear text from a memory dump, even when a workspace is locked or is no longer running.

Therefore, using this proof of concept (PoC), we can obtain the master password.

git clone https://github.com/vdohney/keepass-password-dumper.git

After cloning the repository, we run the "dotnet" command as follows, providing it with a password.

 dotnet run KeePassDumpFull.dmp

If we try this password in the KeePass database and it doesn't work, we then search it on Google and it leads us to a reference that appears to be a dessert. We decide to use it to see if it's the password for the KeePass database.

Apparently, the password is correct. It's an unusual way to obtain a password 😳. Furthermore, we found the password for "root," but it's not valid. However, we discovered a ".ppk" file that indicates it's a "PuTTY User Key File 3" in the PuTTY user key format version 3, related to an RSA key.

https://repost.aws/knowledge-center/ec2-ppk-pem-conversion

Searching on the Internet, we discovered that it's possible to convert a ".ppk" file to ".pem" by following these steps:

puttygen key.ppk -O private-openssh -o id_rsa

With the generated file, we can now connect via SSH as follows, allowing us to escalate to the "root" user.