Nebula – Level05

In this level the only hint that we have is the weak directory permissions.

I listed ls -al /home/flag05, then i found a folder named .backup in which there is a tar.gz file and also another folder named .ssh. So i tried to extract the tar.gz file there itself, but it didn’t work due to permission problems. Then i copied that file to /tmp and then extracted it there. And i found the .ssh directory again. Then i copied that directory to /home/level05 and then ssh’d to flag05@localhost and it didn’t ask any credentials since the public key of flag05 was there in .ssh directory which we already extracted!
I ran getflag to complete this level.

Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s