SSH


A CLEARTEXT credential of the root account has been disclosed in the service file of the app service

┌──(kali㉿kali)-[~/PEN-200/PG_PRACTICE/levram]
└─$ ssh root@$IP            
root@192.168.206.24's password: 4!m?C%7k@Xb?XNH0!>6K
Welcome to Ubuntu 22.04 LTS (GNU/Linux 5.15.0-73-generic x86_64)
 
 * Documentation:  https://help.ubuntu.com
 * Management:     https://landscape.canonical.com
 * Support:        https://ubuntu.com/advantage
 
  System information as of Fri Apr  4 06:16:53 PM UTC 2025
 
  System load:  0.05712890625     Processes:               217
  Usage of /:   63.8% of 9.75GB   Users logged in:         0
  Memory usage: 17%               IPv4 address for ens160: 192.168.206.24
  Swap usage:   0%
 
 * Strictly confined Kubernetes makes edge and IoT secure. Learn how MicroK8s
   just raised the bar for easy, resilient and secure K8s cluster deployment.
 
   https://ubuntu.com/engage/secure-kubernetes-at-the-edge
 
91 updates can be applied immediately.
To see these additional updates run: apt list --upgradable
 
 
The list of available updates is more than a week old.
To check for new updates run: sudo apt update
 
Last login: Wed Jun 14 10:33:17 2023
root@ubuntu:~# whoami
root
root@ubuntu:~# hostname
ubuntu
root@ubuntu:~# ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host 
       valid_lft forever preferred_lft forever
3: ens160: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
    link/ether 00:50:56:9e:70:6c brd ff:ff:ff:ff:ff:ff
    altname enp3s0
    inet 192.168.206.24/24 brd 192.168.206.255 scope global ens160
       valid_lft forever preferred_lft forever

Validated System level compromise