Sep 16, 23
Hack the Box - wifinetic
Wifinetic is an easy difficulty Linux machine which presents an intriguing network challenge, focusing on wireless security and network monitoring. FTP service has anonymous authentication enabled which allows us to download available files. One of the file being OpenWRT backup which contains Wireless Network configuration that discloses Access Point password. Contents of shadow or passwd files discloses username on the server. With this information, a password reuse attack can be carried out on the SSH service, allowing us to gain a foothold as the netadmin user.. Using standard tools and with the provided wireless interface in monitoring mode we can bruteforce WPS PIN for the Access Point to obtain the PSK. The pass phrase can be reused on SSH service to obtain root access on the server.
I hack things and tweet about things...