Overpass
What happens when some broke CompSci students make a password manager?
Scanning (IP : 10.10.233.36)
1. NMAP
> sudo nmap -sC -sV 10.10.233.36
Starting Nmap 7.91 ( https://nmap.org ) at 2021-09-09 06:30 EDT
Nmap scan report for 10.10.233.36
Host is up (0.19s latency).
Not shown: 998 closed ports
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 2048 37:96:85:98:d1:00:9c:14:63:d9:b0:34:75:b1:f9:57 (RSA)
| 256 53:75:fa:c0:65:da:dd:b1:e8:dd:40:b8:f6:82:39:24 (ECDSA)
|_ 256 1c:4a:da:1f:36:54:6d:a6:c6:17:00:27:2e:67:75:9c (ED25519)
80/tcp open http Golang net/http server (Go-IPFS json-rpc or InfluxDB API)
|_http-title: Overpass
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 39.57 seconds2. GoBuster
Bypass the Login page.
Welcome to the Overpass Administrator area
A secure password manager with support for Windows, Linux, MacOS and more
Decoding the SSH Private Key
Login to SSH and get user.txt
Privileges escalations (root.txt)
buildscript.sh
THANK YOU FOR READING :)
Last updated